fix(kyberforge): stop the content mirror amputating a shipped template asset
The mirror's `tests/` exclusion was depth-agnostic, so it deleted `skill-author/assets/templates/tests/` — a template the skill scaffolds FROM — alongside the depth-2 dev fixtures it was meant to drop. Since ADR-0017 makes the mirror the installed content, the shipped scaffolder was broken: the mirror copy of `new-skill.sh` exited 2 on `sed: can't read .../tests/README.md`, leaving a half-written skill, while the byte-identical `.apm/` copy exited 0. `--check` was green about it. Check mode was restructured rather than patched because `diff -x` matches a basename at any depth and cannot express the depth-2 scoping the fix needs — the two modes could not be made to agree by construction. Check mode now runs the real `sync_dir` into a throwaway root and diffs with no exclusions, leaving the exclusion rule and the hooks destination each in exactly one place. Also fixed here, all previously invisible to `--check`: - Merged hooks were written to `<plugin>/hooks.json`, which Claude Code does not convention-scan, while ADR-0017 itself quoted `hooks/hooks.json` as the contract. Moved, with the legacy path cleaned up as stale. No `hooks` pointer is added to `plugin.json`, so this does not reopen the option ADR-0017 rejected. - Only the first drift per plugin was reported: `diff | sed` returns 1 under `pipefail`, and `set -e` killed the subshell before the remaining checks and before `FAIL=1`. - File-mode and symlink drift were invisible, so `--check` and a real sync disagreed; a find-based type/mode manifest now covers both. The tests pinned almost none of this — the stale-skill wipe, the check-mode stale branch, three `MIRROR_DIRS` entries and the hooks newline normalization could each be deleted with the suite still green. All are now mutation-tested. Refs: #90 ADR: 0017 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01X7GvKuJfy2WrdBmUttV4DT
This commit is contained in:
@@ -14,14 +14,27 @@ if ! command -v apm &>/dev/null; then
|
||||
exit 77
|
||||
fi
|
||||
|
||||
# Minimal fixture: one skill (with a tests/ fixture that must NOT be mirrored), one
|
||||
# agent, one hooks.json -- enough to exercise every mirrored category
|
||||
# (scripts/sync-plugin-content.sh's MIRROR_DIRS plus hooks.json) without needing
|
||||
# network access (no apm.yml dependencies).
|
||||
# Minimal fixture exercising every mirrored category -- all five of
|
||||
# scripts/sync-plugin-content.sh's MIRROR_DIRS (agents, skills, commands,
|
||||
# instructions, extensions) plus the merged hooks file -- without needing network
|
||||
# access (no apm.yml dependencies). Two deliberately-shaped skill subdirectories:
|
||||
#
|
||||
# skills/hello/tests/ -- a dev-time fixture that must NOT be mirrored
|
||||
# skills/hello/assets/templates/tests/ -- a template asset that MUST be mirrored
|
||||
#
|
||||
# Those two are the same basename at different depths. The exclusion is depth-scoped
|
||||
# for exactly this reason: the real skill-author skill ships a template tree it
|
||||
# scaffolds from, and a depth-agnostic strip amputated it.
|
||||
#
|
||||
# skills/hello/scripts/run.sh is executable so the mode/symlink drift checks have a
|
||||
# real executable to tamper with.
|
||||
make_fixture() {
|
||||
local dir
|
||||
dir="$(mktemp -d)"
|
||||
mkdir -p "$dir/.apm/skills/hello/tests" "$dir/.apm/agents" "$dir/.apm/hooks"
|
||||
mkdir -p "$dir/.apm/skills/hello/tests" "$dir/.apm/skills/hello/scripts" \
|
||||
"$dir/.apm/skills/hello/assets/templates/tests" "$dir/.apm/agents" \
|
||||
"$dir/.apm/hooks" "$dir/.apm/commands" "$dir/.apm/instructions" \
|
||||
"$dir/.apm/extensions"
|
||||
cat > "$dir/apm.yml" <<'YAML'
|
||||
name: fixture
|
||||
version: 0.0.1
|
||||
@@ -48,12 +61,35 @@ EOF
|
||||
cat > "$dir/.apm/skills/hello/tests/sample.bats" <<'EOF'
|
||||
@test "dummy" { true; }
|
||||
EOF
|
||||
cat > "$dir/.apm/skills/hello/assets/templates/tests/README.md" <<'EOF'
|
||||
Template asset: scaffolded into a new skill, not a dev fixture of this one.
|
||||
EOF
|
||||
cat > "$dir/.apm/skills/hello/scripts/run.sh" <<'EOF'
|
||||
#!/usr/bin/env bash
|
||||
echo hi
|
||||
EOF
|
||||
chmod +x "$dir/.apm/skills/hello/scripts/run.sh"
|
||||
cat > "$dir/.apm/agents/foo.agent.md" <<'EOF'
|
||||
---
|
||||
name: foo
|
||||
description: foo
|
||||
---
|
||||
Foo.
|
||||
EOF
|
||||
cat > "$dir/.apm/commands/mycmd.md" <<'EOF'
|
||||
---
|
||||
description: mycmd
|
||||
---
|
||||
Do a thing.
|
||||
EOF
|
||||
cat > "$dir/.apm/instructions/style.instructions.md" <<'EOF'
|
||||
---
|
||||
applyTo: "**"
|
||||
---
|
||||
Be consistent.
|
||||
EOF
|
||||
cat > "$dir/.apm/extensions/thing.md" <<'EOF'
|
||||
Extension content.
|
||||
EOF
|
||||
cat > "$dir/.apm/hooks/hooks.json" <<'EOF'
|
||||
{"hooks": {"PreToolUse": []}}
|
||||
@@ -119,16 +155,45 @@ fi
|
||||
|
||||
# --- 2. A real sync creates the flat mirror and exits 0 ---
|
||||
echo ""
|
||||
echo "--- real sync creates skills/, agents/, hooks.json ---"
|
||||
echo "--- real sync creates every MIRROR_DIRS category plus hooks/hooks.json ---"
|
||||
if bash "$SCRIPT" "$FIXTURE" > /dev/null 2>&1 \
|
||||
&& [[ -f "$FIXTURE/skills/hello/SKILL.md" ]] \
|
||||
&& [[ -f "$FIXTURE/agents/foo.agent.md" ]] \
|
||||
&& [[ -f "$FIXTURE/hooks.json" ]]; then
|
||||
pass "sync creates the expected flat mirror"
|
||||
&& [[ -f "$FIXTURE/commands/mycmd.md" ]] \
|
||||
&& [[ -f "$FIXTURE/instructions/style.instructions.md" ]] \
|
||||
&& [[ -f "$FIXTURE/extensions/thing.md" ]] \
|
||||
&& [[ -f "$FIXTURE/hooks/hooks.json" ]]; then
|
||||
pass "sync creates the expected flat mirror for all five MIRROR_DIRS plus hooks/hooks.json"
|
||||
else
|
||||
fail "sync did not create the expected flat mirror"
|
||||
fi
|
||||
|
||||
# --- 2b. The merged hooks file goes to hooks/hooks.json, never the plugin root ---
|
||||
# Claude Code convention-scans `hooks/hooks.json` at the plugin root (see
|
||||
# plugins/kyberforge/docs/research/docs/claude-code-plugins/configuration.md's
|
||||
# "Plugin Directory Layout" table, quoted in ADR-0017), and the compiled plugin.json
|
||||
# carries no `hooks` pointer that could redirect it. A root-level hooks.json is read
|
||||
# by nothing.
|
||||
echo ""
|
||||
echo "--- the merged hooks file is not left at the plugin root ---"
|
||||
if [[ ! -e "$FIXTURE/hooks.json" ]]; then
|
||||
pass "no root-level hooks.json after a sync"
|
||||
else
|
||||
fail "sync wrote hooks.json to the plugin root — Claude Code scans hooks/hooks.json"
|
||||
fi
|
||||
|
||||
# --- 2c. hooks/hooks.json is newline-terminated ---
|
||||
# normalize_trailing_newline() exists so pre-commit's end-of-file-fixer does not
|
||||
# re-dirty the tree on every sync: apm's bundle exporter emits hooks.json with no
|
||||
# trailing newline, the committed file has one.
|
||||
echo ""
|
||||
echo "--- the synced hooks file ends in a newline ---"
|
||||
if [[ -n "$(tail -c 1 "$FIXTURE/hooks/hooks.json")" ]]; then
|
||||
fail "hooks/hooks.json has no trailing newline — end-of-file-fixer will re-dirty it every sync"
|
||||
else
|
||||
pass "hooks/hooks.json is newline-terminated"
|
||||
fi
|
||||
|
||||
# --- 3. tests/ fixtures are excluded from the mirror ---
|
||||
echo ""
|
||||
echo "--- tests/ subdirectories are not mirrored ---"
|
||||
@@ -138,6 +203,20 @@ else
|
||||
fail "skills/hello/tests/ was copied into the mirror — should be excluded"
|
||||
fi
|
||||
|
||||
# --- 3b. ...but a deeper tests/ that is a template ASSET must survive ---
|
||||
# The exclusion above is depth-scoped to <category>/<name>/tests. Stripping every
|
||||
# directory named tests at any depth also deletes template trees a skill ships for
|
||||
# its own scaffolder to copy from — which is what broke the mirrored
|
||||
# skills/skill-author/scripts/new-skill.sh (`sed: can't read .../tests/README.md`,
|
||||
# half-written scaffold left behind) while the .apm/ original still worked.
|
||||
echo ""
|
||||
echo "--- a tests/ directory nested under assets/templates/ is preserved ---"
|
||||
if [[ -f "$FIXTURE/skills/hello/assets/templates/tests/README.md" ]]; then
|
||||
pass "skills/hello/assets/templates/tests/ survived the sync"
|
||||
else
|
||||
fail "skills/hello/assets/templates/tests/ was stripped — template assets are not dev fixtures"
|
||||
fi
|
||||
|
||||
# --- 4. --check is clean immediately after a real sync ---
|
||||
echo ""
|
||||
echo "--- --check is clean right after syncing ---"
|
||||
@@ -277,29 +356,186 @@ else
|
||||
fi
|
||||
fi
|
||||
|
||||
# --- 13. --check detects an orphaned hooks.json after .apm/hooks/ is removed ---
|
||||
# --- 13. --check detects an orphaned hooks file after .apm/hooks/ is removed ---
|
||||
echo ""
|
||||
echo "--- --check detects an orphaned hooks.json when .apm/hooks/ is removed ---"
|
||||
echo "--- --check detects an orphaned hooks/hooks.json when .apm/hooks/ is removed ---"
|
||||
FIXTURE13="$(make_fixture)"; track "$FIXTURE13"
|
||||
bash "$SCRIPT" "$FIXTURE13" > /dev/null 2>&1
|
||||
if [[ ! -f "$FIXTURE13/hooks.json" ]]; then
|
||||
fail "initial sync did not create hooks.json -- can't test the orphan case"
|
||||
if [[ ! -f "$FIXTURE13/hooks/hooks.json" ]]; then
|
||||
fail "initial sync did not create hooks/hooks.json -- can't test the orphan case"
|
||||
fi
|
||||
rm -rf "$FIXTURE13/.apm/hooks"
|
||||
if bash "$SCRIPT" --check "$FIXTURE13" > /dev/null 2>&1; then
|
||||
fail "no drift reported for an orphaned hooks.json after .apm/hooks/ removal"
|
||||
fail "no drift reported for an orphaned hooks/hooks.json after .apm/hooks/ removal"
|
||||
else
|
||||
pass "orphaned hooks.json is detected as drift"
|
||||
pass "orphaned hooks/hooks.json is detected as drift"
|
||||
bash "$SCRIPT" "$FIXTURE13" > /dev/null 2>&1
|
||||
if [[ ! -e "$FIXTURE13/hooks.json" ]]; then
|
||||
pass "re-sync removes the orphaned hooks.json"
|
||||
if [[ ! -e "$FIXTURE13/hooks/hooks.json" ]]; then
|
||||
pass "re-sync removes the orphaned hooks/hooks.json"
|
||||
else
|
||||
fail "re-sync left the orphaned hooks.json in place"
|
||||
fail "re-sync left the orphaned hooks/hooks.json in place"
|
||||
fi
|
||||
if bash "$SCRIPT" --check "$FIXTURE13" > /dev/null 2>&1; then
|
||||
pass "re-sync clears the orphaned-hooks.json drift"
|
||||
pass "re-sync clears the orphaned-hooks drift"
|
||||
else
|
||||
fail "re-sync did not clear the orphaned-hooks.json drift"
|
||||
fail "re-sync did not clear the orphaned-hooks drift"
|
||||
fi
|
||||
fi
|
||||
|
||||
# --- 14. A legacy root-level hooks.json is stale output, not content ---
|
||||
# Every plugin synced by an earlier revision of this script carries one. Nothing
|
||||
# reads it (no `hooks` pointer in the compiled plugin.json, and Claude Code's
|
||||
# convention scan looks at hooks/hooks.json), so --check must flag it and a real
|
||||
# sync must delete it.
|
||||
echo ""
|
||||
echo "--- a legacy root-level hooks.json is reported as drift and removed by a sync ---"
|
||||
FIXTURE14="$(make_fixture)"; track "$FIXTURE14"
|
||||
bash "$SCRIPT" "$FIXTURE14" > /dev/null 2>&1
|
||||
printf '{"hooks": {"PreToolUse": []}}\n' > "$FIXTURE14/hooks.json"
|
||||
if bash "$SCRIPT" --check "$FIXTURE14" > /dev/null 2>&1; then
|
||||
fail "no drift reported for a leftover root-level hooks.json"
|
||||
else
|
||||
pass "a leftover root-level hooks.json is reported as drift"
|
||||
bash "$SCRIPT" "$FIXTURE14" > /dev/null 2>&1
|
||||
if [[ ! -e "$FIXTURE14/hooks.json" ]] && [[ -f "$FIXTURE14/hooks/hooks.json" ]]; then
|
||||
pass "re-sync deletes the root-level hooks.json and keeps hooks/hooks.json"
|
||||
else
|
||||
fail "re-sync did not clean up the root-level hooks.json"
|
||||
fi
|
||||
fi
|
||||
|
||||
# --- 15. Deleting a skill from .apm/ leaves a stale mirror a re-sync must clear ---
|
||||
# Without sync_dir()'s rm -rf of the destination before recopying, --check would
|
||||
# report a drift that no amount of re-syncing could ever clear -- a permanently
|
||||
# unfixable pre-push failure. This is the assertion that pins that wipe.
|
||||
echo ""
|
||||
echo "--- a skill deleted from .apm/ is removed from the mirror by a re-sync ---"
|
||||
FIXTURE15="$(make_fixture)"; track "$FIXTURE15"
|
||||
mkdir -p "$FIXTURE15/.apm/skills/doomed"
|
||||
cat > "$FIXTURE15/.apm/skills/doomed/SKILL.md" <<'EOF'
|
||||
---
|
||||
name: doomed
|
||||
description: doomed
|
||||
---
|
||||
Doomed.
|
||||
EOF
|
||||
bash "$SCRIPT" "$FIXTURE15" > /dev/null 2>&1
|
||||
if [[ ! -f "$FIXTURE15/skills/doomed/SKILL.md" ]]; then
|
||||
fail "initial sync did not mirror skills/doomed -- can't test the stale-skill case"
|
||||
else
|
||||
rm -rf "$FIXTURE15/.apm/skills/doomed"
|
||||
if bash "$SCRIPT" --check "$FIXTURE15" > /dev/null 2>&1; then
|
||||
fail "no drift reported for a mirrored skill deleted from .apm/"
|
||||
else
|
||||
pass "a mirrored skill deleted from .apm/ is reported as drift"
|
||||
bash "$SCRIPT" "$FIXTURE15" > /dev/null 2>&1
|
||||
if [[ ! -e "$FIXTURE15/skills/doomed" ]]; then
|
||||
pass "re-sync removes the stale skills/doomed/ from the mirror"
|
||||
else
|
||||
fail "re-sync left the stale skills/doomed/ behind — this drift would be unfixable"
|
||||
fi
|
||||
if bash "$SCRIPT" --check "$FIXTURE15" > /dev/null 2>&1; then
|
||||
pass "re-sync clears the stale-skill drift"
|
||||
else
|
||||
fail "re-sync did not clear the stale-skill drift"
|
||||
fi
|
||||
fi
|
||||
fi
|
||||
|
||||
# --- 16. Drift in each of the less-obvious MIRROR_DIRS is detected ---
|
||||
# agents/ and skills/ are exercised everywhere above; commands/, instructions/, and
|
||||
# extensions/ were previously unreachable by the fixture, so dropping them from
|
||||
# MIRROR_DIRS entirely still passed the suite.
|
||||
echo ""
|
||||
echo "--- drift in commands/, instructions/, and extensions/ is detected ---"
|
||||
for CATEGORY_PATH in commands/mycmd.md instructions/style.instructions.md extensions/thing.md; do
|
||||
FIXTURE16="$(make_fixture)"; track "$FIXTURE16"
|
||||
bash "$SCRIPT" "$FIXTURE16" > /dev/null 2>&1
|
||||
if [[ ! -f "$FIXTURE16/$CATEGORY_PATH" ]]; then
|
||||
fail "sync did not mirror $CATEGORY_PATH at all — is its category still in MIRROR_DIRS?"
|
||||
continue
|
||||
fi
|
||||
printf 'tampered\n' >> "$FIXTURE16/$CATEGORY_PATH"
|
||||
if bash "$SCRIPT" --check "$FIXTURE16" > /dev/null 2>&1; then
|
||||
fail "no drift reported after tampering with $CATEGORY_PATH"
|
||||
else
|
||||
pass "drift in $CATEGORY_PATH is detected"
|
||||
fi
|
||||
done
|
||||
|
||||
# --- 17. --check reports every drift in one run, not just the first ---
|
||||
# The DRIFT-detail `diff | sed` pipelines return non-zero under `set -o pipefail`;
|
||||
# without an explicit `|| true` guard, `set -e` aborts the per-plugin subshell after
|
||||
# the first reported drift, turning one push into N fix/re-push cycles.
|
||||
echo ""
|
||||
echo "--- --check reports all independent drifts in a single run ---"
|
||||
FIXTURE17="$(make_fixture)"; track "$FIXTURE17"
|
||||
bash "$SCRIPT" "$FIXTURE17" > /dev/null 2>&1
|
||||
printf 'tampered\n' >> "$FIXTURE17/agents/foo.agent.md"
|
||||
printf 'tampered\n' >> "$FIXTURE17/skills/hello/SKILL.md"
|
||||
printf 'tampered\n' >> "$FIXTURE17/commands/mycmd.md"
|
||||
printf 'tampered\n' >> "$FIXTURE17/instructions/style.instructions.md"
|
||||
mkdir -p "$FIXTURE17/hooks"
|
||||
printf '{"hooks": {"PreToolUse": [], "tampered": true}}\n' > "$FIXTURE17/hooks/hooks.json"
|
||||
CHECK17="$(bash "$SCRIPT" --check "$FIXTURE17" 2>&1 || true)"
|
||||
MISSED=""
|
||||
for CATEGORY_PATH in agents skills commands instructions hooks/hooks.json; do
|
||||
case "$CHECK17" in
|
||||
*"DRIFT $FIXTURE17/$CATEGORY_PATH"*) ;;
|
||||
*) MISSED="$MISSED $CATEGORY_PATH" ;;
|
||||
esac
|
||||
done
|
||||
if [[ -z "$MISSED" ]]; then
|
||||
pass "all five independent drifts are reported in one --check run"
|
||||
else
|
||||
fail "--check stopped early — never reported drift for:$MISSED"
|
||||
fi
|
||||
|
||||
# --- 18. --check sees a mode change on a mirrored executable ---
|
||||
# `diff -r` compares content only, so a chmod -x left --check at exit 0 while a real
|
||||
# sync silently restored the bit — check and sync disagreeing.
|
||||
echo ""
|
||||
echo "--- --check detects a mode change on a mirrored executable ---"
|
||||
FIXTURE18="$(make_fixture)"; track "$FIXTURE18"
|
||||
bash "$SCRIPT" "$FIXTURE18" > /dev/null 2>&1
|
||||
if [[ ! -x "$FIXTURE18/skills/hello/scripts/run.sh" ]]; then
|
||||
fail "sync did not preserve the executable bit on skills/hello/scripts/run.sh"
|
||||
else
|
||||
pass "sync preserves the executable bit on a mirrored script"
|
||||
chmod -x "$FIXTURE18/skills/hello/scripts/run.sh"
|
||||
if bash "$SCRIPT" --check "$FIXTURE18" > /dev/null 2>&1; then
|
||||
fail "no drift reported after chmod -x on a mirrored executable"
|
||||
else
|
||||
pass "a mode change on a mirrored executable is detected as drift"
|
||||
bash "$SCRIPT" "$FIXTURE18" > /dev/null 2>&1
|
||||
if [[ -x "$FIXTURE18/skills/hello/scripts/run.sh" ]]; then
|
||||
pass "re-sync restores the executable bit"
|
||||
else
|
||||
fail "re-sync did not restore the executable bit"
|
||||
fi
|
||||
fi
|
||||
fi
|
||||
|
||||
# --- 19. --check sees a mirrored file replaced by a symlink ---
|
||||
# `diff -r` dereferences symlinks, so a symlink to byte-identical content reads as
|
||||
# no drift while a real sync replaces it with a regular file.
|
||||
echo ""
|
||||
echo "--- --check detects a mirrored file swapped for a symlink ---"
|
||||
FIXTURE19="$(make_fixture)"; track "$FIXTURE19"
|
||||
bash "$SCRIPT" "$FIXTURE19" > /dev/null 2>&1
|
||||
SYMLINK_TARGET="$FIXTURE19/decoy-agent.md"
|
||||
cp "$FIXTURE19/agents/foo.agent.md" "$SYMLINK_TARGET"
|
||||
rm -f "$FIXTURE19/agents/foo.agent.md"
|
||||
ln -s "$SYMLINK_TARGET" "$FIXTURE19/agents/foo.agent.md"
|
||||
if bash "$SCRIPT" --check "$FIXTURE19" > /dev/null 2>&1; then
|
||||
fail "no drift reported after replacing a mirrored file with a symlink to identical content"
|
||||
else
|
||||
pass "a mirrored file replaced by a symlink is detected as drift"
|
||||
bash "$SCRIPT" "$FIXTURE19" > /dev/null 2>&1
|
||||
if [[ -f "$FIXTURE19/agents/foo.agent.md" ]] && [[ ! -L "$FIXTURE19/agents/foo.agent.md" ]]; then
|
||||
pass "re-sync restores it to a regular file"
|
||||
else
|
||||
fail "re-sync did not restore the symlinked mirror entry to a regular file"
|
||||
fi
|
||||
fi
|
||||
|
||||
|
||||
Reference in New Issue
Block a user