Skip to content

fix(detect): bounded package.json read, BOM strip, skip non-JS trees (PHARN-15) - #209

Merged
PrzemekGalarowicz merged 1 commit into
mainfrom
claude/bold-archimedes-5czyyn
Sep 24, 2026
Merged

PrzemekGalarowicz merged 1 commit into
mainfrom
claude/bold-archimedes-5czyyn

Conversation

@PrzemekGalarowicz

Copy link
Copy Markdown
Contributor

Problem

Archetype detection read package.json via existsSync + readFileSync, which caused four failures:

  • a FIFO at that path hung init;
  • a symlink to /dev/zero was read without any limit;
  • a UTF-8 BOM made JSON.parse fail, so a Next.js app was detected as lib;
  • a large .venv used up the scan budget before the walk reached src/.

Fix

  • package.json is opened once with O_NONBLOCK and checked with fstat().isFile() on that same descriptor.
  • At most 4 MiB is read into a fixed buffer, and a leading BOM is stripped.
  • Every failure still means packageJsonFound: false, and nothing throws.
  • A symlink to a regular file is still followed, since it is the user's own project.
  • SKIP_DIRS now also skips .venv, venv, __pycache__, vendor, target and .yarn.
  • Docs updated: docs/commands/init.md and docs/troubleshooting.md.

Tests

  • New tests that fail on the old code: BOM, over the size cap, and the 6 new skipped directories. The FIFO test hangs on the old code.
  • Also covered: a directory at package.json, a symlink that is still followed, and /dev/zero.
  • Local gates, run as a non-root user on node 22: all green. 1437/1437 tests pass and statement coverage is 97.2%.
  • Pipeline artifacts are in .dev/features/bounded-package-json/.

🤖 Generated with Claude Code

https://claude.ai/code/session_01TvcuVhk8hTeDskp5pAJhnc


Generated by Claude Code

…on-JS trees (PHARN-15)

Archetype detection read package.json with existsSync + readFileSync: a FIFO
hung init, a symlink to /dev/zero read without bound, and a UTF-8 BOM made
JSON.parse fail so a Next.js app detected as `lib`. It now opens once
(O_NONBLOCK), requires a regular file, reads at most 4 MiB, and strips a
leading BOM. SKIP_DIRS gains .venv, venv, __pycache__, vendor, target and
.yarn so a large non-JS tree cannot exhaust the walk budget.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TvcuVhk8hTeDskp5pAJhnc
@coderabbitai

coderabbitai Bot commented Sep 24, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: e808ce89-0509-4a3c-843f-f09d264cba0a


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@PrzemekGalarowicz
PrzemekGalarowicz merged commit 6920b79 into main Sep 24, 2026
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants