|
12 | 12 | ], |
13 | 13 | "filesScanned": 85, |
14 | 14 | "summary": { |
15 | | - "sites": 196, |
| 15 | + "sites": 198, |
16 | 16 | "byOrigin": { |
17 | 17 | "frozen-adapter": 101, |
18 | | - "pipeline": 95 |
| 18 | + "pipeline": 97 |
19 | 19 | }, |
20 | 20 | "byClassification": { |
21 | 21 | "defect": 5, |
22 | | - "refusal": 141, |
| 22 | + "refusal": 143, |
23 | 23 | "unclassified": 50 |
24 | 24 | }, |
25 | 25 | "byStage": { |
|
31 | 31 | "build": 9, |
32 | 32 | "era-cell": 9, |
33 | 33 | "ingest": 17, |
34 | | - "install": 11, |
| 34 | + "install": 13, |
35 | 35 | "license-at-pin": 4, |
36 | 36 | "not-reached": 69, |
37 | 37 | "plan": 24, |
|
41 | 41 | "witness": 1, |
42 | 42 | "witness-synthesize": 2 |
43 | 43 | }, |
44 | | - "distinctCodes": 196, |
| 44 | + "distinctCodes": 198, |
45 | 45 | "recordedRefusalSites": 99 |
46 | 46 | }, |
47 | 47 | "entries": [ |
|
876 | 876 | "stage": "arguments", |
877 | 877 | "stageBasis": "the command surface parses and validates arguments here before any stage runs.", |
878 | 878 | "file": "packages/cli/src/operator/flows.ts", |
879 | | - "line": 399, |
| 879 | + "line": 403, |
880 | 880 | "enclosing": "parseOperatorArguments" |
881 | 881 | }, |
882 | 882 | { |
|
894 | 894 | "stage": "arguments", |
895 | 895 | "stageBasis": "the command surface parses and validates arguments here before any stage runs.", |
896 | 896 | "file": "packages/cli/src/operator/flows.ts", |
897 | | - "line": 407, |
| 897 | + "line": 411, |
898 | 898 | "enclosing": "parseOperatorArguments" |
899 | 899 | }, |
900 | 900 | { |
|
909 | 909 | "stage": "arguments", |
910 | 910 | "stageBasis": "the command surface parses and validates arguments here before any stage runs.", |
911 | 911 | "file": "packages/cli/src/operator/flows.ts", |
912 | | - "line": 421, |
| 912 | + "line": 425, |
913 | 913 | "enclosing": "parseOperatorArguments" |
914 | 914 | }, |
915 | 915 | { |
|
927 | 927 | "stage": "arguments", |
928 | 928 | "stageBasis": "the command surface parses and validates arguments here before any stage runs.", |
929 | 929 | "file": "packages/cli/src/operator/flows.ts", |
930 | | - "line": 434, |
| 930 | + "line": 438, |
931 | 931 | "enclosing": "parseOperatorArguments" |
932 | 932 | }, |
933 | 933 | { |
|
944 | 944 | "stage": "arguments", |
945 | 945 | "stageBasis": "the command surface parses and validates arguments here before any stage runs.", |
946 | 946 | "file": "packages/cli/src/operator/flows.ts", |
947 | | - "line": 441, |
| 947 | + "line": 445, |
948 | 948 | "enclosing": "parseOperatorArguments" |
949 | 949 | }, |
950 | 950 | { |
|
961 | 961 | "stage": "arguments", |
962 | 962 | "stageBasis": "the command surface parses and validates arguments here before any stage runs.", |
963 | 963 | "file": "packages/cli/src/operator/flows.ts", |
964 | | - "line": 448, |
| 964 | + "line": 452, |
965 | 965 | "enclosing": "parseOperatorArguments" |
966 | 966 | }, |
967 | 967 | { |
|
978 | 978 | "stage": "arguments", |
979 | 979 | "stageBasis": "the command surface parses and validates arguments here before any stage runs.", |
980 | 980 | "file": "packages/cli/src/operator/flows.ts", |
981 | | - "line": 456, |
| 981 | + "line": 460, |
982 | 982 | "enclosing": "parseOperatorArguments" |
983 | 983 | }, |
984 | 984 | { |
|
1312 | 1312 | "stage": "install", |
1313 | 1313 | "stageBasis": "the install stage resolves the lane closure through this module.", |
1314 | 1314 | "file": "packages/cli/src/operator/install.ts", |
1315 | | - "line": 271, |
| 1315 | + "line": 403, |
1316 | 1316 | "enclosing": "planLaneInstall" |
1317 | 1317 | }, |
1318 | 1318 | { |
|
1329 | 1329 | "stage": "install", |
1330 | 1330 | "stageBasis": "the install stage resolves the lane closure through this module.", |
1331 | 1331 | "file": "packages/cli/src/operator/install.ts", |
1332 | | - "line": 279, |
| 1332 | + "line": 411, |
1333 | 1333 | "enclosing": "planLaneInstall" |
1334 | 1334 | }, |
1335 | 1335 | { |
|
1348 | 1348 | "stage": "install", |
1349 | 1349 | "stageBasis": "the install stage resolves the lane closure through this module.", |
1350 | 1350 | "file": "packages/cli/src/operator/install.ts", |
1351 | | - "line": 305, |
| 1351 | + "line": 437, |
1352 | 1352 | "enclosing": "planLaneInstall" |
1353 | 1353 | }, |
1354 | 1354 | { |
|
1368 | 1368 | "stage": "install", |
1369 | 1369 | "stageBasis": "the install stage resolves the lane closure through this module.", |
1370 | 1370 | "file": "packages/cli/src/operator/install.ts", |
1371 | | - "line": 332, |
| 1371 | + "line": 464, |
1372 | 1372 | "enclosing": "planLaneInstall" |
1373 | 1373 | }, |
1374 | 1374 | { |
|
1386 | 1386 | "stage": "install", |
1387 | 1387 | "stageBasis": "the install stage resolves the lane closure through this module.", |
1388 | 1388 | "file": "packages/cli/src/operator/install.ts", |
1389 | | - "line": 340, |
| 1389 | + "line": 472, |
1390 | 1390 | "enclosing": "planLaneInstall" |
1391 | 1391 | }, |
1392 | 1392 | { |
|
1404 | 1404 | "stage": "install", |
1405 | 1405 | "stageBasis": "the install stage resolves the lane closure through this module.", |
1406 | 1406 | "file": "packages/cli/src/operator/install.ts", |
1407 | | - "line": 357, |
| 1407 | + "line": 489, |
1408 | 1408 | "enclosing": "planLaneInstall" |
1409 | 1409 | }, |
1410 | 1410 | { |
|
1424 | 1424 | "stage": "install", |
1425 | 1425 | "stageBasis": "the install stage resolves the lane closure through this module.", |
1426 | 1426 | "file": "packages/cli/src/operator/install.ts", |
1427 | | - "line": 365, |
| 1427 | + "line": 497, |
1428 | 1428 | "enclosing": "planLaneInstall" |
1429 | 1429 | }, |
1430 | 1430 | { |
|
1443 | 1443 | "stage": "install", |
1444 | 1444 | "stageBasis": "the install stage resolves the lane closure through this module.", |
1445 | 1445 | "file": "packages/cli/src/operator/install.ts", |
1446 | | - "line": 376, |
| 1446 | + "line": 508, |
1447 | 1447 | "enclosing": "planLaneInstall" |
1448 | 1448 | }, |
1449 | 1449 | { |
1450 | | - "code": "install.script-wrote-outside-lane", |
1451 | | - "message": "Install: the closure's install scripts wrote outside the lane. ${String(writes.length)} watched path(s) under ${path.resolve(boundaryRoot)} moved while `${plan.command.join(' ')}` ran: ${writes.join('; ')}. The install ran with the install-script allowance, which permits a package's own build to run inside the lane; it does not permit it to write into the checkout that acquired it. The child was given a lane-owned HOME and a lane cwd, so this write reached the checkout by naming it rather than by inheriting it. The lane is not accepted as installed and the paths above are left as they are, so an operator can read what was attempted.", |
| 1450 | + "code": "install.peer-resolution-policy-not-declared", |
| 1451 | + "message": "Install: npm refused the lane closure with ERESOLVE — a peer dependency conflict between the application's own era pins and the build toolchain the lane now declares. Declare --allow-peer-conflicts to install through it, which is a decision about what the lane's closure may be, or change what the lane declares. This flow does not take that decision on an operator's behalf.", |
| 1452 | + "messageForm": "static", |
| 1453 | + "staticSegments": [ |
| 1454 | + "Install: npm refused the lane closure with ERESOLVE — a peer dependency conflict between the application's own era pins and the build toolchain the lane now declares. Declare --allow-peer-conflicts to install through it, which is a decision about what the lane's closure may be, or change what the lane declares. This flow does not take that decision on an operator's behalf." |
| 1455 | + ], |
| 1456 | + "classification": "refusal", |
| 1457 | + "condition": "detail.includes('ERESOLVE') && !policy.allowPeerConflicts", |
| 1458 | + "conditionForm": "if-consequent", |
| 1459 | + "origin": "pipeline", |
| 1460 | + "stage": "install", |
| 1461 | + "stageBasis": "the install stage resolves the lane closure through this module.", |
| 1462 | + "file": "packages/cli/src/operator/install.ts", |
| 1463 | + "line": 1191, |
| 1464 | + "enclosing": "refuseNamedNpmFailure" |
| 1465 | + }, |
| 1466 | + { |
| 1467 | + "code": "install.git-dependency-policy-not-declared", |
| 1468 | + "message": "Install: npm refused the lane closure with EALLOWGIT — the closure resolves ${String(reading.refusedSpecs.length)} dependency(ies) from a git reference${reading.refusedSpecs.length === 0 ? '' : `, first ${reading.refusedSpecs[0] ?? ''}`}, and npm fetches none of those by default. Declare --${GIT_DEPENDENCY_POLICY} to carry that policy, which is a decision about what the lane's closure may be: a git dependency is fetched by running git against a remote repository rather than by resolving a registry version, so the registry's version pin, integrity hash and provenance do not apply to it. This flow does not take that decision on an operator's behalf. ${verbatim(reading)}", |
1452 | 1469 | "messageForm": "composed", |
1453 | 1470 | "staticSegments": [ |
1454 | | - "Install: the closure's install scripts wrote outside the lane.", |
1455 | | - "watched path(s) under", |
1456 | | - "moved while `", |
1457 | | - "` ran:", |
1458 | | - ". The install ran with the install-script allowance, which permits a package's own build to run inside the lane; it does not permit it to write into the checkout that acquired it. The child was given a lane-owned HOME and a lane cwd, so this write reached the checkout by naming it rather than by inheriting it. The lane is not accepted as installed and the paths above are left as they are, so an operator can read what was attempted." |
| 1471 | + "Install: npm refused the lane closure with EALLOWGIT — the closure resolves", |
| 1472 | + "dependency(ies) from a git reference", |
| 1473 | + ", and npm fetches none of those by default. Declare --", |
| 1474 | + "to carry that policy, which is a decision about what the lane's closure may be: a git dependency is fetched by running git against a remote repository rather than by resolving a registry version, so the registry's version pin, integrity hash and provenance do not apply to it. This flow does not take that decision on an operator's behalf." |
1459 | 1475 | ], |
1460 | 1476 | "classification": "refusal", |
1461 | | - "condition": "writes.length > 0", |
| 1477 | + "condition": "reading.code === 'EALLOWGIT' && !policy.allowGitDependencies", |
1462 | 1478 | "conditionForm": "if-consequent", |
1463 | 1479 | "origin": "pipeline", |
1464 | 1480 | "stage": "install", |
1465 | 1481 | "stageBasis": "the install stage resolves the lane closure through this module.", |
1466 | 1482 | "file": "packages/cli/src/operator/install.ts", |
1467 | | - "line": 983, |
1468 | | - "enclosing": "runLaneInstall" |
| 1483 | + "line": 1205, |
| 1484 | + "enclosing": "refuseNamedNpmFailure" |
1469 | 1485 | }, |
1470 | 1486 | { |
1471 | | - "code": "install.peer-resolution-policy-not-declared", |
1472 | | - "message": "Install: npm refused the lane closure with ERESOLVE — a peer dependency conflict between the application's own era pins and the build toolchain the lane now declares. Declare --allow-peer-conflicts to install through it, which is a decision about what the lane's closure may be, or change what the lane declares. This flow does not take that decision on an operator's behalf.", |
1473 | | - "messageForm": "static", |
| 1487 | + "code": "install.closure-registry-unreachable", |
| 1488 | + "message": "Install: this closure pins ${reading.request.host}, and npm could not reach it — ${reading.code}, requesting ${reading.request.url}. There is no policy to declare here and this flow offers none: no allowance makes an unreachable registry answer, and a closure that resolves through a registry that is gone cannot be installed as recorded. What this establishes is that this run did not reach ${reading.request.host}; whether that host is retired or momentarily unreachable is not established here, and neither is what it would have served. The remedy is re-pinning the closure onto a registry that answers, which changes what the application declares and is therefore a migration decision rather than an install policy. ${verbatim(reading)}", |
| 1489 | + "messageForm": "composed", |
1474 | 1490 | "staticSegments": [ |
1475 | | - "Install: npm refused the lane closure with ERESOLVE — a peer dependency conflict between the application's own era pins and the build toolchain the lane now declares. Declare --allow-peer-conflicts to install through it, which is a decision about what the lane's closure may be, or change what the lane declares. This flow does not take that decision on an operator's behalf." |
| 1491 | + "Install: this closure pins", |
| 1492 | + ", and npm could not reach it —", |
| 1493 | + ", requesting", |
| 1494 | + ". There is no policy to declare here and this flow offers none: no allowance makes an unreachable registry answer, and a closure that resolves through a registry that is gone cannot be installed as recorded. What this establishes is that this run did not reach", |
| 1495 | + "; whether that host is retired or momentarily unreachable is not established here, and neither is what it would have served. The remedy is re-pinning the closure onto a registry that answers, which changes what the application declares and is therefore a migration decision rather than an install policy." |
1476 | 1496 | ], |
1477 | 1497 | "classification": "refusal", |
1478 | | - "condition": "detail.includes('ERESOLVE') && !policy.allowPeerConflicts", |
| 1498 | + "condition": "reading.code !== null && REGISTRY_UNREACHABLE_CODES.includes(reading.code) && reading.request !== null && reading.request.host !== DEFAULT_REGISTRY_HOST", |
| 1499 | + "conditionForm": "if-consequent", |
| 1500 | + "origin": "pipeline", |
| 1501 | + "stage": "install", |
| 1502 | + "stageBasis": "the install stage resolves the lane closure through this module.", |
| 1503 | + "file": "packages/cli/src/operator/install.ts", |
| 1504 | + "line": 1230, |
| 1505 | + "enclosing": "refuseNamedNpmFailure" |
| 1506 | + }, |
| 1507 | + { |
| 1508 | + "code": "install.script-wrote-outside-lane", |
| 1509 | + "message": "Install: the closure's install scripts wrote outside the lane. ${String(writes.length)} watched path(s) under ${path.resolve(boundaryRoot)} moved while `${plan.command.join(' ')}` ran: ${writes.join('; ')}. The install ran with the install-script allowance, which permits a package's own build to run inside the lane; it does not permit it to write into the checkout that acquired it. The child was given a lane-owned HOME and a lane cwd, so this write reached the checkout by naming it rather than by inheriting it. The lane is not accepted as installed and the paths above are left as they are, so an operator can read what was attempted.", |
| 1510 | + "messageForm": "composed", |
| 1511 | + "staticSegments": [ |
| 1512 | + "Install: the closure's install scripts wrote outside the lane.", |
| 1513 | + "watched path(s) under", |
| 1514 | + "moved while `", |
| 1515 | + "` ran:", |
| 1516 | + ". The install ran with the install-script allowance, which permits a package's own build to run inside the lane; it does not permit it to write into the checkout that acquired it. The child was given a lane-owned HOME and a lane cwd, so this write reached the checkout by naming it rather than by inheriting it. The lane is not accepted as installed and the paths above are left as they are, so an operator can read what was attempted." |
| 1517 | + ], |
| 1518 | + "classification": "refusal", |
| 1519 | + "condition": "writes.length > 0", |
1479 | 1520 | "conditionForm": "if-consequent", |
1480 | 1521 | "origin": "pipeline", |
1481 | 1522 | "stage": "install", |
1482 | 1523 | "stageBasis": "the install stage resolves the lane closure through this module.", |
1483 | 1524 | "file": "packages/cli/src/operator/install.ts", |
1484 | | - "line": 1000, |
| 1525 | + "line": 1287, |
1485 | 1526 | "enclosing": "runLaneInstall" |
1486 | 1527 | }, |
1487 | 1528 | { |
|
1499 | 1540 | "stage": "install", |
1500 | 1541 | "stageBasis": "the install stage resolves the lane closure through this module.", |
1501 | 1542 | "file": "packages/cli/src/operator/install.ts", |
1502 | | - "line": 1027, |
| 1543 | + "line": 1323, |
1503 | 1544 | "enclosing": "runLaneInstall" |
1504 | 1545 | }, |
1505 | 1546 | { |
|
1785 | 1826 | "stage": "arguments", |
1786 | 1827 | "stageBasis": "the run flow composes every stage in order here; what it raises of its own is about the chaining, before any stage decides anything.", |
1787 | 1828 | "file": "packages/cli/src/operator/run.ts", |
1788 | | - "line": 542, |
| 1829 | + "line": 543, |
1789 | 1830 | "enclosing": "applied" |
1790 | 1831 | }, |
1791 | 1832 | { |
|
0 commit comments