refactor(gates): source the boundary resolver into skill-size-check
Why: scripts/skill-size-check.sh embedded a byte-identical 1,061-line copy
of the ADR-0020 boundary resolver only because it was also exported
through .pre-commit-hooks.yaml, whose consumers could not reach a file
inside the plugin. 4de5b6b retired that export, so the hook now runs only
in this repo and can source factory-audit's lib-boundary-resolver.sh like
validate.sh does. One copy removes the edit-one-paste-the-other hazard.
Implementation Notes:
- The hook's Python program is assembled from its own preamble, the
library's resolver and its own checks, read from quoted here-docs. The
assembled program matches the old one line for line except one comment,
and the hook's stdout, stderr and exit code are identical over every
corpus SKILL.md and the 26 differential-suite fixtures.
- The hook fails closed, naming the library, when it is missing or
defines no resolver.
- test-adr0020-contract.sh assertion 1 now pins the single copy: one
marker pair in the library, none in the hook, fail-closed on a missing
or gutted library, and a sentinel planted in a copied library that must
appear in the hook's output. 1a expects exactly one authority. 27 -> 29
passes.
- ADR-0020 and ADR-0025 carry dated amendments; gates.md and the
library, hook and mode-library comments no longer describe two copies.
- factory-audit is new on this branch, so the version-bump gate exempts
it; kyberforge is already at 2.0.0 against main's 1.6.2.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -69,9 +69,9 @@ import yaml
|
||||
# resolver block below pins the reads; this pins the writes.
|
||||
#
|
||||
# Deliberately OUTSIDE the ADR-0020 shared boundary resolver block: the two
|
||||
# validate.sh copies print findings, skill-size-check.sh has its own top-level
|
||||
# equivalent, and tests/test-adr0020-contract.sh hashes that block for
|
||||
# byte-identity across all three.
|
||||
# validate.sh modes print findings, skill-size-check.sh has its own top-level
|
||||
# equivalent, and the block is one sourced copy all three share, so each
|
||||
# consumer's own startup stays in its own preamble.
|
||||
for _stream in (sys.stdout, sys.stderr):
|
||||
try:
|
||||
_stream.reconfigure(encoding='utf-8')
|
||||
@@ -145,9 +145,11 @@ COPILOT_BODY_LIMIT = 30000
|
||||
# every session exactly like a skill's, so agents take the SAME description
|
||||
# gates. These two constants are DUPLICATED in three places:
|
||||
# scripts/skill-size-check.sh, lib-checks-skill.sh beside this file, and here.
|
||||
# The repo-root hook's copy cannot be shared with this skill — a cache-installed
|
||||
# plugin's scripts cannot read files outside their own plugin directory, and the
|
||||
# hook cannot reach inside the plugin. The two copies INSIDE this skill could be
|
||||
# The repo-root hook's copy cannot be sourced FROM this skill — a cache-installed
|
||||
# plugin's scripts cannot read files outside their own plugin directory. (The
|
||||
# hook could now read these from the plugin, as it already sources
|
||||
# lib-boundary-resolver.sh, but they sit in its Python preamble; hoisting them
|
||||
# is a separate change.) The two copies INSIDE this skill could be
|
||||
# shared (ADR-0025: two files in one skill may source a third), and are not only
|
||||
# because each mode library is a verbatim lift of the pre-merge suite whose
|
||||
# constants sit in its Python preamble; hoisting them is a separate change.
|
||||
|
||||
Reference in New Issue
Block a user