Modernization: history de-dup (#20), tooling hygiene (#39), package-content validator (#22, T02) - #41
Merged
Merged
Conversation
CommandHistoryTests.cs, TerminalKeyboardControllerTests.cs, and TryEatArgumentTests.cs were the last LF-stored C# files (50 of 52 are CRLF per .editorconfig end_of_line=crlf). csharpier normalizes them on next touch anyway; sweep the stragglers explicitly so future logic commits carry no eol churn. No content changes.
Next/Previous(skipSameCommands) now skip any entry already shown during the current traversal direction, so non-adjacent repeats are no longer re-displayed within one sweep (previously only adjacent runs were skipped). The seen set resets on Push, Clear, Resize, and direction flips, so sweeping back replays the passed entries like a fresh pass. skipSameCommands=false traversal is byte-for-byte unchanged. Data: red evidence - 2 new tests failed pre-change (16/18), full PlayMode suite 98/98 green post-change (96 baseline + 2 new), live Unity 6000.4.6f1 editor.
The npm project (package.json scripts/devDependencies/engines) and the repo tooling under scripts/ now live under tooling~/ (tilde-suffixed), which Unity never imports. Opening the repository as a local package no longer imports node_modules or tooling scripts, and the 21 tracked scripts/**/*.meta files are gone (Unity-invisible paths must not carry metas; unity-meta-lint stays green at 1613 files, 0 problems). Root package.json keeps the UPM manifest fields plus delegating npm scripts (npm --prefix tooling~), so documented commands like npm run unity:mcp:probe and npm test are unchanged from the repo root. CI/devcontainer/linter/skills/docs updated to the new paths; the devcontainer node_modules cache mount now targets tooling~/node_modules. Path-resolution fixes: generate-skills-index/lint-* RepoRoot now walks two levels from the script (tooling~/scripts), unity-mcp REPO_ROOT and captureScriptSourcePath point at tooling~/scripts/mcp, and the env-and-capture test computes its repo root accordingly. Data: node --test 32/32 green under tooling~ and via root wrapper; llm-instructions lint, skill-sizes lint, unity-meta lint all pass; pwsh test suites 21+8+7 and ai-backends suite 106/106 green.
actions/checkout and actions/setup-node are pinned to the exact v6 commit SHAs with version comments in all three workflows, per the supply-chain hardening candidate in #39. Dependabot's github-actions ecosystem updates SHA-pinned refs and preserves inline version comments; the policy is documented in dependabot.yml so future bumps keep the comment in sync.
Since discovery filters to assemblies whose metadata references the terminal assembly (session-001, issue #36), Rider plugin assemblies are skipped before any type reflection and the IgnoredTypes sentinel can no longer fire for its designed target. The conservative fail-open scan path is unaffected. The filtered==legacy equivalence sweep (FilteredDiscoveryMatchesUnfilteredDiscovery, 5/5 green on live editor) continues to pin filter behavior.
New tooling~/scripts/release/validate-package-contents.mjs packs the package exactly as npm/UPM consumers receive it (npm pack + tar listing, node stdlib only) and asserts: manifest identity matches package.json, required artifacts ship (README/LICENSE/CHANGELOG with metas, all three asmdefs), no tooling/repo-internal files leak (tooling~, .github, .devcontainer, dotfiles, doc.md, agent pointers), and every shipped file carries its .meta with no orphan metas (directory targets inferred from file paths since npm tarballs omit dir entries). Root package.json gains an npm files allowlist so npm pack ships only the Unity package content - before this change the tarball shipped tooling~/, .devcontainer/, .github/ and dotfiles (red evidence: 100+ content errors). Green: 1440 entries checked, all content checks pass. Wired as an always-on Unity-free package-content CI job.
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 3 potential issues.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 78e9476. Configure here.
- post-start.sh/post-create.sh/devcontainer.json pointed at tooling~/tooling~/scripts/mcp/unity-mcp.mjs (a duplicated sed substitution); post-start runs under set -e so container start would abort. Paths corrected. - The image Dockerfile baked /opt/dxt-mcp deps from the root package.json, which no longer carries devDependencies after the tooling~ relocation; COPY now sources tooling~/package.json and the 3-dependency length guard still passes. .dockerignore gains tooling~/node_modules. - npm files allowlist now includes the top-level folder metas (Runtime.meta, Editor.meta, ...), which npm pack drops when only directories are allowlisted; the validator now also asserts every shipped directory carries its folder meta (1447 entries, all checks pass).
…-equality - Root delegating npm scripts now end in a trailing '--' so user flags reach the inner script verbatim. Without it, the inner npm consumed flag names as its own config (verified: 'npm run unity:mcp:probe -- --project /p' delivered [] to the script; now forwards ['--project','/p']). - .gitattributes: scripts/** eol=lf rule updated to tooling~/** so Windows autocrlf=true checkouts keep tooling (incl. bash fixtures) LF. - Validator now compares tarball entries against git ls-files filtered by the allowlist: a tracked file missing from the tarball, or an untracked file shipping, both fail (previously only required files were pinned, so subtree loss would pass). - package.json trailing blank lines removed.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Summary
Aggregated session-002 work advancing PLAN.md (local modernization action plan; session log:
progress/session-002-history-dedup-tooling-hygiene-package-validator.md, local-only). Six coherent commits on top of #37.1. Issue #20 — better history traversal de-duplication
CommandHistory.Next/Previous(skipSameCommands)now skip any entry already shown during the current traversal direction, so non-adjacent repeats are no longer re-displayed within one sweep ([a, b, a]yieldsa, binstead ofa, b, a). The seen set resets onPush/Clear/Resizeand on direction flips, so sweeping back replays the passed entries bash-style.skipSameCommands=falsetraversal is byte-for-byte unchanged. Data-driven red→green: 2 new tests failed pre-change (16/18); full PlayMode suite 98/98 post-change on the live editor.2. Issue #39 — npm tooling under Unity-hidden
tooling~/Opening the repo as a local/embedded package no longer imports
node_modulesor tooling scripts:scripts/moved wholesale totooling~/(tilde-suffixed = invisible to Unity); 21 trackedscripts/**/*.metadropped.package.jsonkeeps UPM fields plus delegating npm scripts (npm --prefix tooling~), sonpm run unity:mcp:probe/npm testetc. are unchanged from the repo root.unity-mcp.mjsREPO_ROOT+captureScriptSourcePath,test-ai-backends.shfixtures,env-and-capturetest, devcontainer npm install +dxt-node-modulescache mount target,.editorconfigLF group.3. Issue #39 — action SHA pinning + IgnoredTypes removal
actions/checkout+actions/setup-nodepinned to exact v6 SHAs with version comments (Dependabot policy documented independabot.yml).CommandShell.IgnoredTypes(JetBrains.Rider sentinel) removed — unreachable since the session-001 assembly-reference filter skips Rider assemblies before any type reflection; equivalence sweep stays green.4. Issue #22 + T02 — package-content validator (clean-install guard)
New Unity-free
tooling~/scripts/release/validate-package-contents.mjspacks the package exactly as npm/UPM consumers receive it and asserts: manifest identity, required artifacts (README/LICENSE/CHANGELOG + metas, all 3 asmdefs), no tooling/repo-internal leaks, and complete.metacoverage with no orphans.npm packshippedtooling~/,.devcontainer/,.github/, dotfiles,doc.md, agent pointers (100+ errors).package.jsongains the npmfilesallowlist → 1440 entries, all checks pass. Wired as an always-onpackage-contentCI job.System.Collections.Immutable.dllwas already removed by Various bug fixes #32; the validator guards the general clean-install property, not the stale diagnosis.5. PR dispositions (issue #40)
#27 (typed parsers/completers/backend decomposition, rc24.7-era) and #29 (quick-launch bar) predate the approved plan and overlap plan tasks T06/T08/T09/T10; both recorded in #40 with inventories. Not closed — closing requires wallstop's confirmation (plan §2: no auto-close).
Validation matrix
tooling~and root wrapper)Notes for review
filesallowlist is now the shipping truth fornpm pack; the new CI job catches drift (also feeds T14's release pipeline).dxt-node-modulesvolume now targetstooling~/node_modules— takes effect on next container rebuild.Note
Medium Risk
Touches terminal history UX and command discovery error handling; the
tooling~/relocation and npmfilesallowlist change how the package is built and what ships—CI mitigates but devcontainer rebuilds need the newnode_modulespath.Overview
Runtime:
CommandHistorywithskipSameCommandsnow tracks commands already shown in the current up/down sweep and skips all repeats (not only adjacent duplicates), resetting when direction flips or history mutates.CommandShelldrops the JetBrains.RiderIgnoredTypesexception swallowing during command discovery.Packaging & tooling: Repo npm/Node scripts move under Unity-hidden
tooling~/(with its ownpackage.json); rootpackage.jsonkeeps UPM fields, adds an npmfilesallowlist, and delegates scripts vianpm --prefix tooling~. Oldscripts/**Unity.metafiles are removed. Devcontainer, pre-commit, CI path filters, and docs/skills point attooling~/.CI & release guard: GitHub Actions
checkout/setup-nodepin to commit SHAs (Dependabot note). Tooling Tests installs/tests undertooling~; newpackage-contentjob runspackage:validate, whichnpm packs the UPM artifact and asserts allowlist coverage, required files/asmdefs, no repo-internal leaks, and complete.metahygiene.Reviewed by Cursor Bugbot for commit abb8fc8. Bugbot is set up for automated code reviews on this repo. Configure here.