docs(lefthook-powershell): correct the PSScriptAnalyzer failure mechanism - #628
Conversation
…nism The runner header, worker header, READMEs and test comment described a cross-target engine-state leak that process isolation fixes. The failure is a CommandInfo race between rules running in parallel inside one Invoke-ScriptAnalyzer call, and it reproduces on one file in a fresh process. Name the real cause, state that the per-target worker only keeps one failure from masking others, and document the triggers to remove until PowerShell/PSScriptAnalyzer#2206 ships. Closes #598 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LCEBhuXxZAT8K619tC6T5f
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Claude finished @kyle-sexton's task in 32s —— View job Security review complete
No security issues found. This PR is documentation-only: it edits PowerShell comment-based help blocks, a test-file comment, and two
No injection surfaces, authorization logic, secrets/token handling, or GitHub Actions workflow changes are touched by this diff, so there's no security-relevant surface to review here. |
|
Claude finished @kyle-sexton's task in 2m 37s —— View job Code review — PR #628
This is a docs/comment-only correction (no One finding posted inline on Author-claimed verification (test run, markdownlint, pre-commit) was not independently re-run by this review; it's reported as-is from the PR description, not confirmed. No security, architecture, or test-coverage concerns beyond the above — this is a low-risk, well-scoped documentation correction otherwise. Branch: |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: e3d847be9b
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…rop it from the fixture The README advice now covers aliases and says what a module with private members does instead. The get-command regression fixture exported its one function explicitly, which is the race trigger the README tells consumers to remove; without the call the module exports the same function. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LCEBhuXxZAT8K619tC6T5f
|
Claude finished @kyle-sexton's task in 39s —— View job Security review complete
No security issues found. This PR is documentation/comment-only plus one test-fixture tweak:
No injection surfaces, authorization logic, secrets/token handling, or GitHub Actions workflow changes are touched by this diff, so there's no security-relevant surface to review here. |
|
Claude finished @kyle-sexton's task in 2m 21s —— View job Code review — PR #628
Reviewed Both previously-open review threads are resolved by the latest commit (
Verification performed this pass:
Author-claimed verification (the No new correctness, maintainability, or documentation-accuracy issues found. Nothing to flag inline. |
…ockstep-drift (#634) Closes #633 ## Summary `pr-convention-lockstep` failed on every open PR with `drift: hook validator: KEYWORD_ERE / NO_ISSUE_ERE declarations not found`. melodic-software/claude-code-plugins#4636 rewrote the hook validator around a per-line `scan_linkage` and renamed its closing pattern to `CLOSING_ERE`, so `parseValidatorPatterns` could not find it. The validator and the ci-workflows `pr-contract` composite still agree, so this was a parse failure, not drift. ## Fix - `parseValidatorPatterns` reads `CLOSING_ERE` (plus the unchanged `NO_ISSUE_ERE`) and translates `[[:blank:]]` as well as `[[:space:]]`. - The new EREs are lowercase with no `i` flag, matched against `${line,,}`. The parser now asserts that lowercasing is present and the probes lowercase their input, the same way the composite check already asserts `lower = tolower(line)`. - The test fixture takes the new validator shape; a new test fails when the validator stops lowercasing. - `policy.json` is unchanged. Every closing keyword and no-issue marker it lists is still accepted by both the composite (`run.sh` `scan_line` and the `no-issue` test) and the validator. The new `Refs:` / `Relates to:` acceptance and negated-closer rejection are enforced by both, but `policy.json` has no field for them and `pr-convention-policy.mjs` and the pinned reusables do not implement them, so recording them would be a separate change. ## Verification - `npm run test:pr-convention-lockstep`: 40/40 pass. - `npm run test:pr-convention-policy`: 11/11 pass. - `npm run lint:pr-convention-lockstep` against live sources with a token: `pr-convention lockstep: all copies and consumer pins match policy.json`, exit 0. - `biome check` on both touched files: clean. ## Related - melodic-software/claude-code-plugins#4636 (the validator rewrite) - melodic-software/ci-workflows#544 (the `pr-contract` negation and `Refs:` change the validator mirrors) - Unblocks #628, #630, #631, #632 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01LCEBhuXxZAT8K619tC6T5f --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
|
Claude finished @kyle-sexton's task in 33s —— View job Security review complete
No security issues found.
No injection surfaces, authorization logic, secrets/token handling, or GitHub Actions workflow changes are touched by this diff, so there's no security-relevant surface to review here. This matches the two prior clean passes on this branch ( Branch: |
Closes #598
Summary
The lefthook-powershell runner, worker, both READMEs and the test comment said PSScriptAnalyzer 1.25.0 leaks engine state between targets and that process isolation fixes it. dotfiles#774 showed the failure on one file in a fresh process. The cause is the CommandInfo race between rules running in parallel (PowerShell/PSScriptAnalyzer#1867, #1708).
Fix
PSUseCorrectCasingdisabled; dropExport-ModuleMemberfrom a.psm1that exports every function).No behavior change. No retry was added, per the maintainer decision on #598.
Verification
pwsh -NoProfile -File components/lefthook-powershell/psscriptanalyzer-staged.test.ps1: "PSScriptAnalyzer staged adapter regressions passed."Related
🤖 Generated with Claude Code
https://claude.ai/code/session_01LCEBhuXxZAT8K619tC6T5f