package: reject orphan lock entries

This commit is contained in:
Hermes Agent
2026-09-03 12:42:34 +00:00
parent fd28ee7ec1
commit 7450c306be
6 changed files with 17 additions and 5 deletions
+11
View File
@@ -111,6 +111,17 @@ def main():
if phrase not in out:
fail(f"package doctor output missing {phrase!r}:\n{out}")
(work / "claro.lock").write_text(
lock + "package: ghost\nchecksum: 12345678\n",
encoding="utf-8",
)
rc, out = run([str(EXE), "package", "doctor"], work)
if rc == 0:
fail("package doctor must reject lockfile packages that are not listed in claro.project")
if "BAD lock package not in claro.project: ghost" not in out:
fail(f"package doctor orphan-lock diagnostic was unclear:\n{out}")
(work / "claro.lock").write_text(lock, encoding="utf-8")
rc, out = run([str(EXE), "package", "add", "../bad"], work)
if rc == 0:
fail("Unsafe package names with path separators must be rejected")