Repository navigation
test(mcp-server): the premium census counts code, not comments, so a comment cannot hide a new ungated read - #470
Open
brianonbased-dev wants to merge 2 commits into
Open
brianonbased-dev wants to merge 2 commits into
brianonbased-dev wants to merge 2 commits into
Conversation
…comment cannot hide a new ungated read Task v7c1. premium-exit-guard.test.ts counts text. 6f2504d (#390) made it green on main by listing comment mentions as rows ("the path appears in a comment"), but the census itself still counted comments. That cut both ways: - a new comment quoting a call shape raised a false alarm; - swapping such a comment for a real, ungated read left the count unchanged, so the census stayed green on exactly the new exit it exists to catch; - a gate symbol named only in a comment passed "every listed gate is really there". The census now reads each file with its comments blanked. It uses the TypeScript parser, so a // inside a string, a regex or JSX text stays code, and line numbers are kept. A gate must now be named in code as a whole identifier. 30 mentions stop counting, and each was checked to sit in a comment. SITES: 14 counts lowered, 6 comment-only rows removed. Watched red. On a scratch copy of the scanned trees (PREMIUM_EXIT_GUARD_ROOT), before -> after: - a comment quoting a read: fired -> green; - that comment swapped for a real ungated read (Studio's knowledge/sync route): green -> FIRED; - a gate named only in a comment (premiumTeaser in absorb's codebase-tools): green -> FIRED; - a real ungated read in a quiet file: fired -> fired. Five new tests pin the blanking. Breaking it four ways (no blanking, a text-pattern stripper, JSX text unprotected, a substring gate check) turns 6, 3, 1 and 1 tests red. Real code 10/10. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… comment inside it, and whole-name gates Answers the same-seat pre-review of #470 (not the distinct-seat review, which is still owed). - P2: the JSDoc skip mattered but nothing tested it. Without it, `/** Uses {@link Y} // note */ const g = () => queryKnowledge(x);` counted 0, because the scan from a JSDoc text node treated the `//` as a line comment. A new test expects 1. - P3: the parse filter read the raw text, so a file whose only read is `queryKnowledge/* why */(q)` was never parsed and counted 0. The filter now also tries the text with block comments removed; that only decides whether to parse. A new test reads such a file through codeOf and expects 1. - P3: the whole-identifier rule for gates was untested. `old_premiumTeaser(x)` must not name `premiumTeaser`; the gate test now asserts it. - P3, a correction to 7d405be's message and the PR body: the census drops 25 comment mentions, not 30 (18 from the 14 lowered counts, 7 from the 6 removed rows). Watched red, one break at a time: JSDoc skip removed -> 1 red; filter back to raw text -> 1 red; lookbehind removed -> 1 red. Real code 12/12. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Owner
Author
|
triage 2026-10-05: open-cap ≤5; recreate from main if needed |
Owner
Author
|
reopened 2026-10-05: Joseph GO — security/hosted-server triage restore |
Owner
Author
HoloCI verdict: FAILHoloCI checked the head commit of this pull request with the
Fix the failed gates and push. HoloCI checks the new head commit on its own. |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Board:
task_1790076280813_v7c1(P2, security). It asked for four things, and this does them:What was wrong
premium-exit-guard.test.tsguards against the next premium-leak exit. It counts every place in three servers that reads knowledge rows and compares the counts with a reviewed list. It counted text, so comments counted as reads. #390 (6f2504d94) made it green on main by listing those comment mentions as rows, for example "the path appears in a comment". The census itself still counted comments, and that cut three ways:What changes
withoutCommentsdoes this with the TypeScript parser://inside a string, a template, a regex, or JSX text (what a page shows) stays code;namesSymbol). A comment, or a longer name such aspremiumTeaserCache, no longer counts.The list. 25 mentions stop counting, and every one was checked by hand to sit in a comment. Each is a
//or*line, such as route doc headers and "Mirrors HoloMesh ... POST /api/holomesh/quickstart". No real read was lost: for example,knowledge/query/route.ts:6(a URL string) still counts.rateandratings, theknowledge/queryroute's HoloMesh row, theknowledge/syncroute,studio/quickstart, and thedb/schemaHoloMesh row.Verified
The census on real source. 10/10: the 5 existing checks plus 5 new tests that pin the blanking.
Before and after, on a scratch copy of the scanned trees (
PREMIUM_EXIT_GUARD_ROOT), one planted change at a time:knowledge/syncroute swapped for a real ungatedfetch(.../api/knowledge/query)premiumTeaserrenamed away in absorb'scodebase-tools.ts, and named only in a commentThe new tests, watched failing, one break at a time:
//in strings)Round 2: the pre-review (head 0fbb60a)
The same seat's pre-review (not the distinct-seat review) found no P0 or P1. Its independent recount agrees with the blanking on all 107 file/read keys across 2,031 files, and found no over-blanking in real source. Its four smaller points are fixed:
/** Uses {@link Y} // note */ const g = () => queryKnowledge(x);counted 0. A test now expects 1.queryKnowledge/* why */(q)) was never parsed, because the filter read the raw text. The filter now also tries the text with block comments removed. A test reads such a file throughcodeOfand expects 1.old_premiumTeaser(x)must not namepremiumTeaser, and the gate test now asserts it.Watched failing, one break at a time:
The real code passes 12/12. Prettier leaves this file with the same 5 differences it has on main.
Review
A distinct seat is needed. The author is claude1 / claudecode-claude-x402. The census was last changed by #390, from this same seat, so a reviewer from another seat is wanted: claude3 or claude2 (mcp-server).
🤖 Generated with Claude Code