CI / build (push) Has been cancelled
Batch 1 (High severity): - Bug 1: --audit cat3 now checks .automaton/tasks/ paths - Bug 4: Verdict PASS/FAIL uses structured ## Status: line parsing - Bug 5: register-guards.sh checks .json/.jsonc, writes plugin key, strips comments - Bug 7: --can-edit/--scope-check path prefix uses os.sep boundary Batch 2 (Medium/Low severity): - Bug 2: migrate-project.sh find command parentheses for -prune binding - Bug 3: vram_detect model prefix matching with known-suffix whitelist - Bug 6: dashboard reads .state file before artifact heuristic fallback - Bug 8: removed wildcard CORS, added security headers (nosniff, DENY) - Bug 9: stale-task detection uses .state.lastedit instead of .state mtime - Bug 10: TEST_PLAN.md maps to test_design (was implement) 249 tests pass (up from 235). All 10 tasks driven through full workflow to completion.
1.3 KiB
1.3 KiB
Code Review: fix-register-guards
Summary
Fixes three compounding bugs that prevented OpenCode guard registration.
Findings
- Config detection (5a): Correctly checks
.jsonfirst, then.jsonc. Theforloop withbreakensures the first match wins. - Config key (5b): Now writes to
plugin(singular), preserving existing entries viacfg.setdefault('plugin', []).append(...). This matches the actual opencode config schema. - JSONC parsing (5c): The
re.sub(r'//.*?$', '', text)regex strips//comments. This is a simple approach that works for line comments but does NOT handle/* */block comments or//inside string values. However, opencode config files typically only use line comments, so this is sufficient. A more robust approach would usejson5if available. - Manual hint: Updated to use
plugin(singular) — consistent with the actual fix.
Minor Note
The comment-stripping regex could incorrectly strip // inside string values (e.g., a URL like "http://..."). However, the opencode config is unlikely to contain such values, and this is strictly better than the previous behavior (complete failure on any comment).
Verdict
APPROVED — no blocking issues. The comment-stripping limitation is noted but acceptable for this use case.