Sitelet https://github.com/brianonbased-dev/HoloScript/pull/470
Skip to content

test(mcp-server): the premium census counts code, not comments, so a comment cannot hide a new ungated read - #470

Open
brianonbased-dev wants to merge 2 commits into
mainfrom
claude1/census-ignores-comments
Open

brianonbased-dev wants to merge 2 commits into
mainfrom
claude1/census-ignores-comments

Conversation

@brianonbased-dev

@brianonbased-dev brianonbased-dev commented Sep 29, 2026 •

Copy link
Copy Markdown
Owner

Board: task_1790076280813_v7c1 (P2, security). It asked for four things, and this does them:

  • each drifted census entry classified as a real read or a comment;
  • real reads gated;
  • comments no longer counted, proven by a comment that does not fire;
  • green on the current head, with an added ungated read still red.

What was wrong

premium-exit-guard.test.ts guards against the next premium-leak exit. It counts every place in three servers that reads knowledge rows and compares the counts with a reviewed list. It counted text, so comments counted as reads. #390 (6f2504d94) made it green on main by listing those comment mentions as rows, for example "the path appears in a comment". The census itself still counted comments, and that cut three ways:

  1. False alarm. A new comment quoting a call shape turned the census red.
  2. A hole. Swap such a comment for a real, ungated read in the same file, and the count stays the same, so the census stays green. That is exactly the new exit it exists to catch.
  3. A second hole. A gate named only in a comment passed "every listed gate is really there".

What changes

  • Comments are blanked before counting. withoutComments does this with the TypeScript parser:
    • a // inside a string, a template, a regex, or JSX text (what a page shows) stays code;
    • line numbers are kept, so a failure still points at the right line.
  • A gate must be named in code as a whole identifier (namesSymbol). A comment, or a longer name such as premiumTeaserCache, no longer counts.
  • The Studio proxy checks read the proxy's code, not its comments.
  • The file stays fast. Only files that one of the read patterns could match at all are parsed.

The list. 25 mentions stop counting, and every one was checked by hand to sit in a comment. Each is a // or * line, such as route doc headers and "Mirrors HoloMesh ... POST /api/holomesh/quickstart". No real read was lost: for example, knowledge/query/route.ts:6 (a URL string) still counts.

  • 14 counts go down.
  • 6 comment-only rows are removed: marketplace rate and ratings, the knowledge/query route's HoloMesh row, the knowledge/sync route, studio/quickstart, and the db/schema HoloMesh row.

Verified

The census on real source. 10/10: the 5 existing checks plus 5 new tests that pin the blanking.

Before and after, on a scratch copy of the scanned trees (PREMIUM_EXIT_GUARD_ROOT), one planted change at a time:

planted census before census after
a comment quoting a read, in a file with no reads fired (false alarm) green
that kind of comment in Studio's knowledge/sync route swapped for a real ungated fetch(.../api/knowledge/query) green (the hole) fired
premiumTeaser renamed away in absorb's codebase-tools.ts, and named only in a comment green (the hole) fired
a real ungated read in a quiet file fired fired

The new tests, watched failing, one break at a time:

break red
nothing blanked (comments count again) 6
a text-pattern stripper instead of the parser (eats // in strings) 3
JSX text not protected 1
the gate check back to a substring of raw text 1
  • tsc is clean (pre-commit gate).
  • Prettier: the file had 5 formatting differences on main (the one-row-per-line SITES layout), and it still has exactly those 5. This change adds none.

Round 2: the pre-review (head 0fbb60a)

The same seat's pre-review (not the distinct-seat review) found no P0 or P1. Its independent recount agrees with the blanking on all 107 file/read keys across 2,031 files, and found no over-blanking in real source. Its four smaller points are fixed:

  • P2: the JSDoc skip was untested. Without it, /** Uses {@link Y} // note */ const g = () => queryKnowledge(x); counted 0. A test now expects 1.
  • P3: a read with a block comment inside it (queryKnowledge/* why */(q)) was never parsed, because the filter read the raw text. The filter now also tries the text with block comments removed. A test reads such a file through codeOf and expects 1.
  • P3: the whole-name rule for gates was untested. old_premiumTeaser(x) must not name premiumTeaser, and the gate test now asserts it.
  • P3: the count was wrong. The census drops 25 comment mentions, not 30 (18 from the 14 lowered counts, 7 from the 6 removed rows). Corrected above.

Watched failing, one break at a time:

break red
JSDoc skip removed 1
parse filter back to raw text 1
gate lookbehind removed 1

The real code passes 12/12. Prettier leaves this file with the same 5 differences it has on main.

Review

A distinct seat is needed. The author is claude1 / claudecode-claude-x402. The census was last changed by #390, from this same seat, so a reviewer from another seat is wanted: claude3 or claude2 (mcp-server).

🤖 Generated with Claude Code

claudecode-claude-x402 and others added 2 commits September 28, 2026 23:19
…comment cannot hide a new ungated read

Task v7c1. premium-exit-guard.test.ts counts text. 6f2504d (#390) made it
green on main by listing comment mentions as rows ("the path appears in a
comment"), but the census itself still counted comments. That cut both ways:
- a new comment quoting a call shape raised a false alarm;
- swapping such a comment for a real, ungated read left the count unchanged,
  so the census stayed green on exactly the new exit it exists to catch;
- a gate symbol named only in a comment passed "every listed gate is really
  there".

The census now reads each file with its comments blanked. It uses the
TypeScript parser, so a // inside a string, a regex or JSX text stays code,
and line numbers are kept. A gate must now be named in code as a whole
identifier. 30 mentions stop counting, and each was checked to sit in a
comment. SITES: 14 counts lowered, 6 comment-only rows removed.

Watched red. On a scratch copy of the scanned trees (PREMIUM_EXIT_GUARD_ROOT),
before -> after:
- a comment quoting a read: fired -> green;
- that comment swapped for a real ungated read (Studio's knowledge/sync
  route): green -> FIRED;
- a gate named only in a comment (premiumTeaser in absorb's codebase-tools):
  green -> FIRED;
- a real ungated read in a quiet file: fired -> fired.
Five new tests pin the blanking. Breaking it four ways (no blanking, a
text-pattern stripper, JSX text unprotected, a substring gate check) turns
6, 3, 1 and 1 tests red. Real code 10/10.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… comment inside it, and whole-name gates

Answers the same-seat pre-review of #470 (not the distinct-seat review, which
is still owed).

- P2: the JSDoc skip mattered but nothing tested it. Without it,
  `/** Uses {@link Y} // note */ const g = () => queryKnowledge(x);` counted 0,
  because the scan from a JSDoc text node treated the `//` as a line
  comment. A new test expects 1.
- P3: the parse filter read the raw text, so a file whose only read is
  `queryKnowledge/* why */(q)` was never parsed and counted 0. The filter
  now also tries the text with block comments removed; that only decides
  whether to parse. A new test reads such a file through codeOf and expects 1.
- P3: the whole-identifier rule for gates was untested.
  `old_premiumTeaser(x)` must not name `premiumTeaser`; the gate test now
  asserts it.
- P3, a correction to 7d405be's message and the PR body: the census drops
  25 comment mentions, not 30 (18 from the 14 lowered counts, 7 from the 6
  removed rows).

Watched red, one break at a time: JSDoc skip removed -> 1 red; filter back
to raw text -> 1 red; lookbehind removed -> 1 red. Real code 12/12.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

Copy link
Copy Markdown
Owner Author

triage 2026-10-05: open-cap ≤5; recreate from main if needed

Copy link
Copy Markdown
Owner Author

reopened 2026-10-05: Joseph GO — security/hosted-server triage restore

@brianonbased-dev

Copy link
Copy Markdown
Owner Author

HoloCI verdict: FAIL

HoloCI checked the head commit of this pull request with the quick profile.

  • Failed: secrets, lint, python-honesty, type-check
  • Passed (8 of 12): cross-platform-paths, doctrine-slots, docker-core-entries, frozen-lockfile, publish-surface, dockerfile-static-check, render-surface, mcp-gate-coverage
  • Could not run: none
  • Commit: 0fbb60a92a0c1291236e9e233982bad99f9becde
  • Receipt: fdff810b7caf54d7af3d4f304dd511a892b294844b4d58f1339b118a5021763b (workload ci-0fbb60a9-muxwefy0)

Fix the failed gates and push. HoloCI checks the new head commit on its own.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant