fix: pre-landing review fixes for the v2 port wave

Review army (checklist + 5 specialists) + coverage/plan audits on the
assembled branch. Genuine correctness/security/hygiene fixes:

- test-paid-shards: strictTestExitCode now receives expectedFiles on the
  real bun path, so a shard that runs fewer files than planned (harness
  crash, nothing loaded) with exit 0 is no longer recorded 'passed' — the
  invisible-non-execution class the runner exists to kill. Pinned by the
  new test/strict-output.test.ts (also covers the chunk-boundary classifier).
- test-paid-shards: EVALS_TIER env is validated (gate|periodic) like the
  --tier flag, so a typo can't self-skip every test and exit 0 green.
- package.json: test:periodic:sharded sets EVALS_ALL=1, restoring the
  full-tier semantics the pre-shard script had (CI already set it; local
  eval:bg:periodic silently under-measured without it).
- brain-sync.test: run() pins HOME to the temp home so gstack-artifacts-init
  stops writing/clobbering the operator's real ~/.gstack-artifacts-remote.txt
  every free-suite run; afterEach now also scrubs the current filename.
- egress-receipt: cap each receipt field at 512B so a serialized line always
  fits the 4KB tail-read window — a longer line would make the next append
  hash a truncated prior line and verifyLedger report a permanent false
  TAMPER. warnLedgerSize short-circuits before statSync once fired (append
  hot path).
- gstack-egress: import.meta.dir (Windows-safe) instead of new URL().pathname
  so grants doesn't silently report defaults on Windows; strip control chars
  from ledger-derived fields on render so a crafted receipt can't spoof the
  auditor's view.
- extension/background.js + CLAUDE.md: renumber the identity-pin migration
  refs v1.62 -> v1.63 (main claimed 1.62.0.0; this wave queue-advances).
- egress-receipt-wiring: pin lib/context-bill.ts unconditionally (both land
  together now); drop the dead RunShardsOptions.tier field.

All fix-affected test files green; gate failures triaged as external-env
(codex/gemini CLI drift) or pre-existing (hermetic-canary fails identically
on base). Deferred polish tracked in the PR body + decision store.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Garry Tan
2026-08-12 16:02:11 -07:00
co-authored by Claude Fable 5
parent ea7ba921ce
commit ccb91c3afb
9 changed files with 156 additions and 27 deletions
+7 -7
View File
@@ -588,24 +588,24 @@ chrome.tabs.onUpdated.addListener((_id, changeInfo) => {
}
});
// ─── v1.62 identity-pin migration notice ────────────────────────
// ─── v1.63 identity-pin migration notice ────────────────────────
//
// The manifest "key" added in v1.62 pins the extension ID, which changes
// The manifest "key" added in v1.63 pins the extension ID, which changes
// the ID for existing installs — chrome.storage.local is keyed by
// extension ID, so panel-local state (saved port, snoozes) resets once.
// Explain that in-product, one time.
async function announceIdentityPinOnce() {
try {
const data = await chrome.storage.local.get('gstack_id_migrated_v162');
if (data.gstack_id_migrated_v162) return;
console.log('[gstack] gstack sidebar: extension identity pinned in v1.62 — panel state reset once.');
const data = await chrome.storage.local.get('gstack_id_migrated_v163');
if (data.gstack_id_migrated_v163) return;
console.log('[gstack] gstack sidebar: extension identity pinned in v1.63 — panel state reset once.');
chrome.runtime.sendMessage({
type: 'gstack-migration-notice',
message: 'gstack sidebar: extension identity pinned in v1.62 — panel state reset once.',
message: 'gstack sidebar: extension identity pinned in v1.63 — panel state reset once.',
}).catch(() => {
// Expected: panel not open. The console line above still lands.
});
await chrome.storage.local.set({ gstack_id_migrated_v162: true });
await chrome.storage.local.set({ gstack_id_migrated_v163: true });
} catch (err) {
console.debug('[gstack] identity-pin notice failed (non-fatal):', err.message);
}