fix(meta): PR #175 review round — all 14 findings addressed

H1 godot-cold-parse exit-code guard (+bonus: import-pass for cold checkouts, found live); H2 pr-watchlist-diff loud registry failure; H3/T1 deny list :* normalization (add-only) + uniform allow syntax; H4/T7 helper-script allows; H5 get_api_key env-only (config.json is tracked — no secret fallback); H6 TEAM.md active/standby split; H7 troblum solo-profiling note; H8 pr-review frontmatter Task->Agent; H9 conventions doc taxonomies fixed vs real tree; T2 ask-gate leash files (settings/hooks) in tracked settings; T3 R-013 cross-reference; T4 governance README index regenerated (pql decisions sync); T5 dudley briefing ACTIVE; T6 pr-process step 7 run-from-main.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
2026-07-13 22:11:36 +02:00
co-authored by Claude Fable 5
parent c9d9b56933
commit 6c078fbec4
12 changed files with 121 additions and 32 deletions
+13 -12
View File
@@ -75,24 +75,25 @@ def get_base_url(key: str, default: str) -> str:
return load_config().get(key, default)
def get_api_key(env_var: str, config_key: str) -> str:
"""Get an API key from the environment or config.json.
def get_api_key(env_var: str, config_key: str = "") -> str:
"""Get an API key from the environment — environment-only, by design.
Checks the ``env_var`` environment variable first, then ``config_key`` in
config.json. Prints a JSON error and exits 1 if neither is set — connector
scripts emit machine-readable JSON on all paths.
``tooling/db/config.json`` is a *tracked* file and holds endpoints only;
it must never carry secrets, so there is deliberately no config.json
fallback here (the old one steered users toward committing paid API keys).
``config_key`` is retained in the signature for caller compatibility but
is ignored. Prints a JSON error and exits 1 if the variable is unset —
connector scripts emit machine-readable JSON on all paths.
"""
key = os.environ.get(env_var)
if key:
return key
try:
with open(CONFIG_PATH) as f:
config = json.load(f)
return config.get(config_key, "")
except Exception:
pass
print(json.dumps({
"ok": False,
"error": f"No {env_var} found in environment or config.json"
"error": (
f"{env_var} not set. Export it in your shell or add it to the "
"machine-local .claude/settings.local.json env block (untracked). "
"Never put keys in tooling/db/config.json — it is tracked."
)
}, indent=2))
sys.exit(1)
+36 -1
View File
@@ -28,15 +28,50 @@ RUN_MENU=false
rm -f "$REPO_ROOT/client/.godot/global_script_class_cache.cfg"
# A truly cold checkout (fresh clone or worktree — .godot/ is gitignored) has
# no resource-import cache, and every imported asset (fonts, ogg) then "fails
# loading" during the parse run: a wall of false positives. Seed the cache
# with an import pass first; source assets are tracked, so this is always
# reconstructible. (Found live: first run in a fresh worktree, 2026-07-13.)
if [ ! -d "$REPO_ROOT/client/.godot/imported" ] || [ -z "$(ls -A "$REPO_ROOT/client/.godot/imported" 2>/dev/null)" ]; then
echo "godot-cold-parse: no import cache — running one-time import pass..." >&2
set +e
IMPORT_OUT=$(godot --headless --path "$REPO_ROOT/client" --import 2>&1)
IMPORT_EXIT=$?
set -e
if [ "$IMPORT_EXIT" -ne 0 ]; then
echo "godot-cold-parse: import pass exited $IMPORT_EXIT" >&2
printf '%s\n' "$IMPORT_OUT" | tail -20 >&2
exit "$IMPORT_EXIT"
fi
fi
FILTER='^(SCRIPT )?ERROR|Parse Error|Export type'
MATCHES=$(godot --headless --path "$REPO_ROOT/client" --quit 2>&1 \
# Capture the godot run separately from the filter pipeline: with the
# trailing `|| true` on the greps, a nonzero exit from godot itself (crash,
# missing binary, corrupted install) would otherwise report "clean". Nothing
# downstream re-reads the raw output now that this is scripted, so fail loud.
set +e
RAW=$(godot --headless --path "$REPO_ROOT/client" --quit 2>&1)
GODOT_EXIT=$?
set -e
if [ "$GODOT_EXIT" -ne 0 ]; then
echo "godot-cold-parse: godot itself exited $GODOT_EXIT — not a parse verdict" >&2
printf '%s\n' "$RAW" | tail -20 >&2
exit "$GODOT_EXIT"
fi
MATCHES=$(printf '%s\n' "$RAW" \
| grep -iE "$FILTER" \
| grep -v "Failed loading resource: res://assets" \
| grep -v "Cannot infer the type" \
| grep -vE '(Messagepack|LocalBridge|ServerProcess|Constants)" not declared' || true)
if [ "$RUN_MENU" = true ]; then
# Deliberately no exit-code check here: `timeout` kills the menu after
# 10s by design (exit 124 is the expected shutdown path); only the
# scraped error lines carry signal for this bounded run.
MENU_MATCHES=$(timeout 10 godot --path "$REPO_ROOT/client" res://scenes/main_menu.tscn 2>&1 \
| grep -iE "$FILTER" || true)
if [ -n "$MENU_MATCHES" ]; then
+10 -1
View File
@@ -17,7 +17,16 @@ set -euo pipefail
BASE="${1:?usage: tooling/pr-watchlist-diff <base> <head>}"
HEAD="${2:?usage: tooling/pr-watchlist-diff <base> <head>}"
mapfile -t GENERATOR_SOURCES < <(python3 tooling/generator_sources.py --list)
# Load the registry via plain assignment (set -e sees its failure), not
# `mapfile < <(...)` — a failed process substitution is invisible to set -e
# and would silently yield an empty watch list, disabling the DB-staleness
# net exactly when the shared registry breaks. Guard the empty case too.
SOURCES_RAW="$(python3 tooling/generator_sources.py --list)"
if [ -z "$SOURCES_RAW" ]; then
echo "pr-watchlist-diff: generator_sources.py --list returned nothing" >&2
exit 1
fi
mapfile -t GENERATOR_SOURCES <<< "$SOURCES_RAW"
git diff --name-only "$BASE...$HEAD" -- \
"${GENERATOR_SOURCES[@]}" \