[E00-S01-T14] No core package imports a concrete extension #381
No Reviewers
Labels
Clear labels
agent/analyst-drafted
agent/analyst-drafted
needs/human-decision
needs/human-decision
needs/security-review
needs/security-review
tier/t0
tier/t1
tier/t2
tier/t3
kind
bug
kind
bug
kind
epic
kind
epic
kind
initiative
EPPP programme initiative
kind
story
kind
story
kind
task
EPPP engineering card/task decomposed from a story
kind
toil
kind
toil
loop
1
loop
1
loop
2
loop
2
loop
3
loop
3
risk
agent-full
risk
agent-full
risk
human-gated
risk
human-gated
risk
human-only
risk
human-only
size
l
size
l
size
m
size
m
size
s
size
s
status
blocked
status
blocked
status
done
Workflow: Done
status
in-progress
status
in-progress
status
proposed
status
proposed
status
ready
status
ready
status
review
status
review
stream
checkout
stream
checkout
stream
onboarding
stream
onboarding
stream
platform
stream
platform
trivial — implementer only, auto-merge
standard — implementer + reviewer + tester
complex — security if triggered, human merge
critical — full chain + security, human merge
No labels
Milestone
No items
No Milestone
Projects
Clear projects
No projects
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: Fabrika/PersonalBlog#381
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
What changed
Locks in the [E00-S01-T14] boundary that no core package imports a concrete extension (#167). The workspace is already compliant (the bootstrap
packages/corehas no imports), and the architecture import test that enforces the boundary — rule + scanner — was delivered by E00-S01-T04 (explicitly out of scope here, untouched). This PR adds the lock-in suite that pins T14's two acceptance criteria to the committed state:tests/no-core-extension-imports.test.mjs(new) — anode:testsuite (zero dependencies, lockfile untouched):scripts.testglob (tests/**/*.test.mjs, so a violation failspnpm test), and thatdependency-boundaries.jsonforbids thepackages -> extensionsedge;packages/*source file imports anything that resolves toextensions/*;import { register } from '@personal-blog/example-extension';inpackages/core/src/index.ts) and asserts the architecture import test exits non-zero, naming the offending file and thepackages -> extensionsrule — proving the test catches any such import;Explicitly out of scope per the brief (not touched): frozen lockfile clean install (E00-S01-T13), dependency-boundary rule/test (E00-S01-T04) —
dependency-boundaries.jsonandtests/architecture-import.test.mjsare unchanged. No manifests, no lockfile, no CI workflow changes.Criterion → test table
tests/no-core-extension-imports.test.mjs— "no core package imports a concrete extension (architecture import test passes on the real workspace)": runsnode --test tests/architecture-import.test.mjson the real workspace and asserts exit 0. Non-vacuous: the mutation probe proves that any core → extension import in apackages/*source makes the architecture import test fail, so a compliant result means the scanner really checked and found nothingtests/no-core-extension-imports.test.mjs— "the architecture import test is committed, wired into the root suite, and forbids the edge" (file committed with the real-graph test, covered by the rootscripts.testglob,dependency-boundaries.jsonforbidspackages -> extensions) and "the architecture import test catches a core -> extension import (mutation probe)" (a temp workspace copy with an injected core → extension import fails the architecture test with a per-file/linepackages -> extensionsviolation report)Test plan executed
node --test tests/no-core-extension-imports.test.mjs(Node 24, v24.20.0) → 4/4 pass ✓node --test tests/architecture-import.test.mjs(Node 24) → 10/10 pass ✓node --test "tests/**/*.test.mjs"on Node 24 (v24.20.0) → 51/51 pass, exit 0 ✓import { register } from '@personal-blog/example-extension';intopackages/core/src/index.ts→ architecture test fails withpackages/core/src/index.ts:1 imports @personal-blog/example-extension (@personal-blog/example-extension [extensions]) — violates packages -> extensions; reverted ✓corepack pnpm install --frozen-lockfile(pnpm 11.23.0) → unchanged, lockfile untouched; the CI job runs the same frozen install on the PR head ✓Risks / notes
NODE_TEST_CONTEXTfrom the child env sonode --testdoes not treat it as a recursive run and skip the files.Refs #167