Skip to content

fix(capability-index): strict frontmatter fence + refuse duplicate keys (PHARN-14) - #208

Merged
PrzemekGalarowicz merged 1 commit into
mainfrom
claude/bold-archimedes-5czyyn
Sep 24, 2026
Merged

PrzemekGalarowicz merged 1 commit into
mainfrom
claude/bold-archimedes-5czyyn

Conversation

@PrzemekGalarowicz

Copy link
Copy Markdown
Contributor

Problem

  • extractFrontmatter used the lazy regex /^---\n([\s\S]*?)\n---/. With an empty block (---\n---), it read role/applies from the document body.
  • readField took the first occurrence of a duplicated key, while pharn-oss's validator takes the last. A capability could therefore install with an applies that the upstream gate never checked.

Fix

  • The fence is now read line by line. The first line must be exactly ---, and the block ends at the next --- line (trailing whitespace is allowed).
  • A role or applies key that appears more than once raises ManifestValidationError. The capability then lands in unknown: it is named in a warning and never installed. An already-installed one is KEPT and re-checked (PHARN-13).

Tests

  • Four new SKIP cases: empty block, unterminated fence, duplicate applies, duplicate role. Three of them fail on the old code; the unterminated-fence case already failed there too.
  • One positive case: a closing fence with trailing whitespace, and look-alike keys (roles:, indented applies:) stay ignored.
  • Local gates, run as a non-root user on node 22: all green. 1389/1389 tests pass and statement coverage is 97.18%.
  • Pipeline artifacts are in .dev/features/strict-frontmatter-fence/.

🤖 Generated with Claude Code

https://claude.ai/code/session_01TvcuVhk8hTeDskp5pAJhnc


Generated by Claude Code

…fuse duplicate keys (PHARN-14)

The lazy fence regex skipped an empty block (`---\n---`) and read role/applies
from the document body. And the first-match field reader could disagree with
pharn-oss's validator (last match) when a key was duplicated. Both shapes now
land in `unknown` — named, never installed.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TvcuVhk8hTeDskp5pAJhnc
@coderabbitai

coderabbitai Bot commented Sep 24, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 974fc94c-8c6e-42d5-982b-19630ba450b2


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@PrzemekGalarowicz
PrzemekGalarowicz merged commit 6b82dc9 into main Sep 24, 2026
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants