SpecsCLIRegistry Baseline
Registry Baseline: code review 1
Registry Baseline code review 1
- Target:
git diff origin/main...d43e0f302onteam/stefan/registry-baseline. - Governing sources: SPEC.md (
a89796e7), ARCHITECTURE.md (3e63ec3c), PLAN.md D1 to D16. - Reviewers: primary comprehensive (Standards, Spec, architecture, simplify) and an independent security and data-loss challenger. Lint and format debt were out of scope by user instruction.
- Primary verdict: do not merge before repair. Challenger verdict: conditionally safe (no critical or high).
Findings and routes
| Id | Severity | Area | Finding | Route |
|---|---|---|---|---|
| P-F1 | high | lint | Interrupted first adoption seeds an empty oxlint.local.ts (Built config written first) | repair (R2) |
| P-F2 | high | Commit Gate | Deletion-only commit fails files-mode coverage | repair (R2) |
| P-F3 | medium | pipeline | Migration mutates before STEP-004; refusal says "Nothing was written" (AC-018) | repair (R1a) |
| P-F4 | medium | shape | Installer-written .ts files flip JS workspaces to TypeScript | repair (R1b) |
| P-F5 | medium | lint | Unevaluable existing config seeds empty local file | repair (R2) |
| P-F6 | medium | deps | Project's own devDependency recorded as installer-added, later removed | repair (R1b) |
| P-F7 | medium | migration | Locally edited Copied files overwritten on first update without --yes | repair (R1a) |
| P-F8 | medium | release | Re-run after partial publish never converges | repair (R3) |
| P-F9 | low | drift | Installed render uses current settings | debt |
| P-F10 | low | pipeline | Two text normalizers disagree | repair (R1a) |
| P-F11 | low | version range | Prerelease of the upper bound satisfies <X.Y.Z | debt |
| P-F12 | low | release | Root catalog written before version catalog | repair (R3) |
| P-F13 | low | migration | Archived skill with a managed id is dropped | debt (needs user decision) |
| P-F14 | low | hooks | Existing .codex/config.toml never gets Codex hooks (Authored, per spec) | none |
| S-F1 | medium | security | postInstall from the network runs with full env; settings registry accepts any scheme | repair (R1a allowlist + minimal env, R1b https-only settings URL); signing is debt |
| S-F2 | medium | security | Catalog item name can escape the cache directory | repair (R1b) |
| S-F3 | medium | data loss | Symlinked merge target replaced by a file | repair (R1a) |
| S-F4 | medium | data loss | Stale removal deletes locally edited Copied files | repair (R1a) |
| S-F5 | low | data loss | Migration deletes archives it never read | debt |
| S-F6 | low | security | hi diff/hi update import repository manifest.mjs (runs repo code) | debt (documented) |
| S-F7 | low | security | Rewrites drop file modes | repair (R1a) |
| P-A1 | low | architecture | Duplicated helpers (canonical JSON, byte compare, item fetch), init double catalog fetch, runners inside pipeline.ts | debt |
Spec coverage from the primary pass: 25 of 37 AC fully tested, 11 partially tested, AC-018 partially met (P-F3), none missing. Gaps are listed in the primary report; live evidence for AC-004, AC-005, AC-009, AC-014, AC-018, AC-024, AC-026, AC-027, AC-029, AC-031 and AC-034 is recorded in IMPLEMENTATION-NOTES.
Repair validation
- Repairs landed for P-F1, P-F2, P-F3, P-F4, P-F5, P-F6, P-F7, P-F8, P-F10, P-F12, S-F1 (CLI allowlist, minimal environment, https-only settings Registry URL, non-default Registry notice), S-F2, S-F3, S-F4, S-F7, each with a regression test that failed before its fix.
- Focused Repair Validation:
apps/clitest:source512 passed,test:release74 passed,check-typesclean. - The repairs changed a public-contract edge (settings
registryaccepts https only) and security behavior (post-install allowlist); both are covered by the challenger findings they close. A second full review pass was not opened; debt items stay recorded above. - Behavior notes: the release readback now also accepts a newer
latestthat publishing deliberately kept (never moveslatestback); a rename out of a Software Scope still needs Commit Gate coverage.