Repository navigation
hardening: fault-inject CLI generation and filesystem updates #159
Description
Activity
- addedenhancementNew feature or requestNew feature or requestpriority-p1Required for the 0.5.0 milestoneRequired for the 0.5.0 milestone
on Oct 2, 2026 The implemented failure matrix is documented at the merged hardening review, with links to the actual assertions and recovery workers. Delivery spans #176, #177, #178, #179, #180, #181 and #182. Every confirmed defect retains its reproducer/regression; the immutable pre-fix evidence is archived in the consolidated 0.5.0 review packet.
- Covered: failed multi-file writes/replacement/rollback/cleanup with original-byte preservation and retained recovery copies; directory publication recovery at three actual process-termination checkpoints; generator/create destination ownership and concurrent publication.
- Covered: stale-owner/reaper/release races, ambiguous records, legacy recovery, junctions, preparation/cleanup failures, bounded Windows read observations and 200 contended publications. Native Windows failures on earlier merged commits remain recorded and are resolved by the later fixes.
- Covered: malformed manifest/config/workspace inputs with exact-tree preservation and zero registry calls; local/remote path pivots, source limits, redirects, status/encoding errors, aborts and body deadlines. Five real local HTTPS rejection probes now close their sockets without further body writes.
- Covered: real local installer processes for missing command, exit 23, external installer termination, CLI termination and success. Injected
ETIMEDOUTresult handling is also exercised. No automatic installer timeout exists or is claimed. - Partial, explicit recovery boundary: abrupt file-update termination retains originals for manual restoration; killing the CLI during installation retains unpublished private preparation for manual cleanup. Process checkpoints do not establish power-loss durability or cooperation with older recursive-lock implementations.
Final source has 455 unit cases (450 plus five POSIX skips on Windows), normal packed imports under actual TypeScript 6.0.3/7.0.2, five normally installed starters, the peer floor, production audit, and all 22 unchanged performance gates. Parent-process coverage is 86.02% statements, 78.89% branches and 87.79% lines; lock-helper lines are 98.76%. Child-process fault assertions are separate from those coverage percentages. Initial #182 Windows fixture-cleanup
EBUSYwas corrected by awaiting inherited process handles; production source was unchanged by that correction.Closing this package hardening pass after exact PR and merged CI/CodeQL acceptance. The complete 0.5.0 package graph, examples/site, version/changelog preparation and maintainer full review remain separate release gates. No release tags or npm publication are authorized before that review.
Exact acceptance: PR CI 38025715612, merged CI 38025888482, and merged CodeQL. PR and merge source trees are identical.
Goal
Run a deeper, contract-driven edge-case pass for 0.5.0. The cases below are probes, not claims that defects are currently present.
Probe targets
Probe interrupted generation/update, failed directory swaps and rollback, pre-existing destinations, symlink and path traversal boundaries, malformed package/config input, and subprocess failures/timeouts. Verify the tool never leaves a partial project or deletes unrelated files when a staged operation fails.
Required outcome
A broad checklist without executed tests or source-backed findings does not complete this issue.
Initial invariant and test-gap assessment (2026-10-02)
Baseline: static inventory of test paths, scripts, and named cases on origin/develop. No suites were run and not every assertion body was inspected. Named tests are evidence signals, not proof of coverage; candidate gaps must be checked against assertions before being called missing.
Invariants and evidence
Candidate gaps to verify
Abrupt process termination between backup and publish, and failures during rollback/temporary-file cleanup. Probe platform-specific rename/permission behavior only where supported; do not repeat the current injected replacement and symlink cases.
Closure evidence: inspect and run the relevant assertions, then mark each invariant covered, partial, not evidenced, or not run. Add a minimal regression reproducer for every confirmed defect; record the exact command and outcome for a no-defect probe.