Repository navigation
fix(capability-index): a non-file <name>.md is one unknown capability, not a dead index (PHARN-08) - #202
Merged
Conversation
…, not a dead index (PHARN-08) `existsSync` is true for a DIRECTORY at `<subtree>/<name>/<name>.md`, and `readFileSync` then threw EISDIR — not a ManifestValidationError, so the per-capability tolerance re-threw it and one oddly-shaped upstream capability would abort init/add/update/status in every deployed CLI at once. The markdown path is now lstat'ed and must be a regular file: a directory, a symlink (never followed — it could point outside the clone) or a FIFO (a read would block forever) is reported as `unknown` like any other per-capability shape problem. Genuine I/O errors still propagate. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TvcuVhk8hTeDskp5pAJhnc
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
…ptor CodeQL flagged the lstat-then-readFileSync pair as a file-system race. The markdown is now opened once (O_NOFOLLOW: a symlink is ELOOP; O_NONBLOCK: a FIFO cannot block the open), fstat'ed on that descriptor, and read from the same descriptor — no window between the type check and the read. Same refusals and messages as before. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TvcuVhk8hTeDskp5pAJhnc
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this changes
Each capability is expected to have a markdown file at
<subtree>/<name>/<name>.md. The index parser only checked that something existed at that path withexistsSync, which is also true for a directory.readFileSyncthen threwEISDIR. That error is not aManifestValidationError, so the per-capability loop re-threw it instead of skipping the capability. The result: one oddly-shaped capability in upstreampharn-ossmadeinit,add,updateandstatusexit 1 for every released CLI at once, with an error that did not name the path. Reproduced on the upstream tree85bdaa37plus anewcap/newcap.md/directory. The shape has never occurred in upstream history, so this is protection against a future break.The parser now uses
lstatand requires a regular file. A directory, a symlink or a FIFO at that path is reported like any other malformed capability: it is added tounknownwith the reason "…/.md is not a regular file", and the other capabilities still parse.Built with
/pharn-dev-ship; stage artifacts are in.dev/features/capability-index-nonfile-md/. Results:no-regressionsPASSThe first verify run failed because the new symlink test wrote a file outside its own temp directory. I fixed the test before pushing.
Type of change
feat— new stack option, wizard step, or command capabilityfix— bug fixdocs— docs-only changechore/refactor— tooling or internal restructure, no behavior changeArea(s) touched
lib/capability-index
Checklist
.js-extension import convention.EISDIR. The FIFO test was not run against the old code, because the read would hang.LIMITS.md§3e already promises this behavior.Quality gates
npm run checkpasses locally (1338/1338; non-root user, node 22).npm run build/npm run test:coverage(left to CI).🤖 Generated with Claude Code
https://claude.ai/code/session_01TvcuVhk8hTeDskp5pAJhnc
Generated by Claude Code