Skip to content

build(repo): fail lint on any inline suppression comment - #80

Merged
ryanleecode merged 1 commit into
mainfrom
lint/no-inline-suppression
Oct 9, 2026
Merged

ryanleecode merged 1 commit into
mainfrom
lint/no-inline-suppression

Conversation

@systemfsoftware-maker

@systemfsoftware-maker systemfsoftware-maker commented Oct 9, 2026 •

Copy link
Copy Markdown
Collaborator

Unit U6 of docs/plans/2026-10-08-0705-feat-gates-bind-and-inline-suppression-plan.md (C3, R26, AE11), conductor ruling 18. The starter picks up systemfsoftware #676's no-inline-suppression bin, and pnpm lint fails on any inline suppression comment.

Change

  • flake.lock: systemfsoftware moves from 8a4b543 to c6eafec (#676, the current systemfsoftware main). Its oxlint-plugin-test-discipline-5.0.0.tgz ships dist/no-inline-suppression.mjs, published as the no-inline-suppression bin.
  • pnpm-lock.yaml: re-resolved by pnpm 12.9.0 (pnpm install --lockfile-only --update-checksums, run in the sandbox with registry.npmjs.org egress). The bump changes:
    • Integrity, same version: four tarballs changed content without a version bump: effect-gherkin-spec-7.0.1, oxlint-config-dmmf-2.0.0, oxlint-config-recommended-4.0.0 and oxlint-plugin-test-discipline-5.0.0. pnpm recorded their new integrity.
    • hasBin: oxlint-plugin-test-discipline now has hasBin: true and a new oxc-parser: 0.150.0 dependency, already in the lockfile.
    • @effect/tsgo: oxlint-config-recommended now asks for @effect/tsgo ^0.50.0, resolved to 0.50.0 (was 0.45.0).
    • Root importer: gains @systemfsoftware/oxlint-plugin-test-discipline.
    • No other entry changes. No catalog version changed; every file:.sfs-deps/*.tgz name is the same.
  • package.json:
    • Adds @systemfsoftware/oxlint-plugin-test-discipline (catalog:) to the root devDependencies, so the root has the bin.
    • Adds lint:suppressions: ./bin/sandboxed -- no-inline-suppression. With no arguments the bin scans every git-tracked .ts/.tsx/.mts/.cts/.js/.jsx/.mjs/.cjs file under the repo root. No path argument, no filter, no || true.
    • lint runs turbo lint lint:suppressions, and gate:tasks adds lint:suppressions. CI's check (lint) runs pnpm lint, and check:ci runs gate:tasks, so all three fail on a suppression.
  • turbo.json: //#lint:suppressions is a root task with cache: false, so every run rescans every tracked file and a cached pass can't hide a new directive.

Judgment surfaces changed (GATE1, conductor Q7): package.json (lint, gate:tasks, lint:suppressions), turbo.json.

Scope (item 3)

The bin scans 62 git-tracked files: 34 in apps/, 18 in repos/, 5 in scripts/, 1 in sandbox-proofs/, and 4 root config files. bin/ holds only shell scripts, which the bin doesn't scan. pnpm lint:suppressions on this head exits 0, so it finds nothing anywhere, repos/ included. Nothing is excluded, filtered or allow-listed.

The three matches git grep finds for these directive words are prose in Markdown (docs/brainstorms/…-state-of-the-art-plan.md:173 and docs/plans/…-inline-suppression-plan.md:51,102). The bin doesn't scan Markdown.

AE11

The run used a scratch linked worktree of this head (git worktree add --detach /tmp/ae11-scratch HEAD, offline pnpm bootstrap), removed afterwards. I added // oxlint-disable-next-line no-unused-vars above const name = Str.trim(raw) in apps/site/src/features/guestbook/sign-guestbook.workflow.ts, so the comment sits on line 53.

$ pnpm lint        # with the directive
//:lint:suppressions: $ ./bin/sandboxed -- no-inline-suppression
//:lint:suppressions: apps/site/src/features/guestbook/sign-guestbook.workflow.ts:53:3: oxlint-disable-next-line is forbidden. Expected: code that passes lint and type-check with no inline suppression. Actual: a comment opening with oxlint-disable-next-line. Fix: delete the comment and fix what it silenced; no comment or setting inside the file exempts it.
//:lint:suppressions: no-inline-suppression: 1 finding(s) in 62 scanned file(s).
 Tasks:    0 successful, 4 total
Failed:    //#lint:suppressions
 ERROR  run failed: command  exited (1)
exit 1

$ pnpm lint        # line removed
   • Running lint, lint:suppressions in 3 packages
 Tasks:    5 successful, 5 total
exit 0

No throwaway file is in the branch.

Evidence

  • Local, in the dev shell on this head: pnpm format:check, pnpm lint, pnpm typecheck, pnpm test and pnpm check:ci all exit 0. check:ci includes the sandbox proofs, whose git-hooks proof does a fresh offline install of this lockfile from the new Nix pnpm store.
  • The commit went in with the hooks on. No stryker locally.
  • No change to the ruleset, the required checks, CI workflows or any lint threshold.

View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

systemfsoftware moves to c6eafec (#676), whose oxlint-plugin-test-discipline
tarball ships the no-inline-suppression bin. The root takes that package as a
dev dependency, and lint and gate:tasks run a new uncached root turbo task,
lint:suppressions, that runs the bin in the sandbox over every git-tracked
TypeScript and JavaScript file. No comment can exempt a file.

The relock records the new content of the four tarballs that changed at the
same versions (effect-gherkin-spec, oxlint-config-dmmf,
oxlint-config-recommended, oxlint-plugin-test-discipline) and resolves
oxlint-config-recommended's @effect/tsgo ^0.50.0 to 0.50.0, per conductor
ruling 18 (U6, R26)
@ryanleecode
ryanleecode merged commit 5d735f5 into main Oct 9, 2026
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants