diff --git a/.gitignore b/.gitignore index 2a291a0..c47579c 100644 --- a/.gitignore +++ b/.gitignore @@ -43,4 +43,4 @@ luac.out build/ # Personal language-server config; typecheck pins its own via --configpath -.luarc.json +.luarc.json* diff --git a/.luarc-typecheck.json b/.luarc-typecheck.json index 0ced7ac..dece3fc 100644 --- a/.luarc-typecheck.json +++ b/.luarc-typecheck.json @@ -1,6 +1,9 @@ { "runtime": { - "version": "LuaJIT" + "version": "LuaJIT", + "special": {}, + "plugin": "", + "pluginArgs": [] }, "workspace": { "useGitIgnore": false, @@ -15,12 +18,21 @@ "build", "dist", "node_modules" - ] + ], + "maxPreload": 5000, + "preloadFileSize": 500 }, "diagnostics": { "enable": true, "disable": [], "severity": {}, - "globals": [] + "globals": [], + "globalsRegex": [], + "neededFileStatus": {}, + "groupFileStatus": {}, + "groupSeverity": {}, + "enableScheme": [ + "file" + ] } } diff --git a/CLAUDE.md b/CLAUDE.md index 60793cd..b1ca9bc 100644 --- a/CLAUDE.md +++ b/CLAUDE.md @@ -72,12 +72,48 @@ deprecation check the moment the server assumes a newer language. Libraries with such shims, lua-noiseprotocol and lua-bthome-ble, are indifferent to the key. `--configpath` displaces each individual setting the committed config declares, -not each table, so a suppression knob is only closed if it is named. `diagnostics` -therefore declares four: `enable`, `disable`, `severity` and `globals`. Each was -measured as a live bypass with a planted probe, `enable: false` silencing the check -entirely and the rest suppressing individual codes, and each is a no-op on a clean -tree. Anything under `diagnostics` not in that list is still reachable from a local -`.luarc.json`, so add it here rather than assume the list is complete. +not each table, so a knob is only closed if it is named. Suppression keys can be +enumerated from the diagnostics read sites: + + grep -rhoE "config\.get\([^,]*, *'Lua\.[A-Za-z.]+'" \ + script/core/diagnostics/*.lua script/provider/diagnostic.lua + +Treat that as a floor, not a ceiling: its file scope is the shape of its blind +spot. Anything that gates file loading or rewrites source before analysis is read +elsewhere, and has to be enumerated separately from `script/plugin.lua` and +`script/workspace.lua`. `runtime.plugin` is the case that matters, and the grep +cannot surface it by construction. `check_worker.lua` does `require 'plugin'`, so +an `OnSetText` returning an empty edit blanks every file in the repo and the check +passes having analysed nothing. + +Two traps decide how a key gets declared, and neither is answered by the key's +type: + +Empty is not always inert, so read the read site. `neededFileStatus` and +`groupFileStatus` are per-key lookups that fall back to the built-in default, so +`{}` leaves behaviour untouched. `enableScheme` defaults to `["file"]`, which makes +`[]` silence the whole check exactly as a local `["git"]` would. It is declared as +`["file"]` for that reason. + +Immunity is per-code, so one planted probe does not measure a key. +`check_worker.lua`'s `downgrade_checks_to_opened` force-overwrites only codes whose +default status is `Any`, leaving everything defaulting to `Opened` under local +control, which is precisely the type-check group this gate exists for. An +`undefined-global` probe therefore reports `neededFileStatus` as inert while a +`return-type-mismatch` probe shows it silencing the check. Probe with a type-check +code. + +Declared here as measured live bypasses: `enable`, `disable`, `severity`, +`globals`, `globalsRegex`, `enableScheme`, `neededFileStatus` and `groupFileStatus` +under `diagnostics`, plus `special` and `plugin` under `runtime`. `pluginArgs`, +`groupSeverity`, `maxPreload` and `preloadFileSize` are declared as belt and +braces rather than measured bypasses: `groupSeverity` relabels a finding that is +still counted and still exits non-zero, and `preloadFileSize: 0` fails loud rather +than hiding anything. Declaring them costs nothing and saves re-deriving that. + +Any setting this file does not name, under any table, is still reachable from a +local `.luarc.json`. Re-run both enumerations when upgrading the server rather than +assuming this list stayed complete. The server version is not pinned locally, though. `install-deps` takes whatever Homebrew has while CI pins 3.19.0, so compare the version the target prints if a