feat(qa): helpers answer --help, and the QA eval interfaces declare it

Approved by Garry: asking gstack-qa-evidence or gstack-qa-deadline for usage
is read-only, so both helpers print usage and exit 0 on --help (the evidence
usage now names the annotation shape), and the functional and caller command
allowlists accept exactly 'bun <path>/bin/gstack-qa-{evidence,deadline} --help'.
Two CI runs failed only on that call.
This commit is contained in:
garrytan committed 2026-09-30 19:14:59 +00:00
1 parent 4643cb8550
commit ee929ff710
5 files changed
+37 -3

No files matched your search

+6
View File
@@ -281,7 +281,13 @@ export function qaWriteVerdict(observation: QAWriteObservation, mode: QAMode): s
return failures;
}
/** Asking an installed gstack QA helper for its own usage text is read-only and always declared. */
export function qaHelperUsageCommand(command: string): boolean {
return /^bun (?:[\w./-]+\/)?bin\/gstack-qa-(?:evidence|deadline) --help$/.test(command.trim());
}
export function qaCommandAllowed(command: string, root?: string): boolean {
if (qaHelperUsageCommand(command)) return true;
const producer = root ? qaEvidenceCommand(command, { cwd: root, reportRoot: path.join(root, 'qa-reports'), executable: path.join(root, 'bin/gstack-qa-evidence') }) : undefined;
if (producer) {
try { ownedPath(root!, 'bin/gstack-qa-evidence'); } catch { return false; }