fix(build): harden build.sh (verify gate, derived deps, dev bench) - #835

Merged
Chemaclass merged 3 commits into
mainfrom
feat/834-harden-build-sh
Jul 19, 2026
Merged

fix(build): harden build.sh (verify gate, derived deps, dev bench)#835
Chemaclass merged 3 commits into
mainfrom
feat/834-harden-build-sh

Conversation

@Chemaclass

Copy link
Copy Markdown
Member

🤔 Background

Related #834

An audit of build.sh found that --verify never propagated a failing suite to CI, a missing embed marker could silently corrupt the artifact, and the hand-maintained deps list had drifted from the entrypoint — shipping benchmark.sh in the binary while ./bashunit bench crashed in dev mode.

💡 Changes

  • Fail the build when verification fails, when embed markers are missing, or when the artifact fails bash -n; run under set -euo pipefail
  • Derive the embed list from the entrypoint's source order (single source of truth), guard duplicate embeds, drop eval
  • Source src/benchmark.sh from the dev entrypoint and add an acceptance regression test for bashunit bench
  • set -u exposed dead code: Windows checksum skip compared the long-gone $_OS; now uses initialised $_BASHUNIT_OS

https://claude.ai/code/session_01JSeB8UzLCpqst55hAK6dED

- ./build.sh --verify now exits non-zero when the built binary fails
the suite; previously CI saw green on a red verification run
- build.sh runs under set -euo pipefail; missing embed markers abort
instead of silently corrupting the artifact, and every build is
gated behind bash -n
- the embed list is derived from the entrypoint's source order (single
source of truth) instead of a hand-maintained array; src/dev/ stays
excluded and duplicate embeds are guarded by a visited list
- drop eval when resolving $BASHUNIT_ROOT_DIR in sourced paths; anchor
the source-line strip; unique temp file per build
- set -u exposed dead code: the Windows checksum skip compared long-gone
$_OS; check_os is now initialised and compares $_BASHUNIT_OS
- the dev entrypoint never sourced src/benchmark.sh, so ./bashunit bench
crashed with 'command not found' from a checkout while the built
binary worked; source it and add an acceptance regression test
Closes#834
Claude-Session: https://claude.ai/code/session_01JSeB8UzLCpqst55hAK6dED
@ChemaclassChemaclass added the enhancement New feature or request label Jul 19, 2026
@ChemaclassChemaclass self-assigned this Jul 19, 2026
The new --verify gate exposed that verification had been silently
crashing since 2025-06: six test files resolved repo resources through
$BASHUNIT_ROOT_DIR, which points at the build output folder (no src/,
no tools/) when the built binary runs the suite.
- benchmark_test: drop the src source entirely; the entrypoint and the
built binary both provide the module now
- check_os_test / learn_test: resolve src/ relative to the test file
- helpers_test / coverage_percent_test: use repo-cwd-relative paths,
matching how the same helpers already source globals.sh
- globals_test: observe caller_filename through a helper in the test
file so the asserted frame no longer depends on the framework layout
Verified green via BASHUNIT_BUILD_DIR runs on macOS bash 3.2 and
ubuntu:24.04 (docker) — first fully passing verification since the gap
opened.
Closes#834
Claude-Session: https://claude.ai/code/session_01JSeB8UzLCpqst55hAK6dED
--stop-on-failure and the report flags (--log-junit, --report-html,
--report-tap, --report-json) were exported, so any nested bashunit run
— bashunit's own acceptance tests under build.sh --verify, or a user's
script under test that calls bashunit — inherited them. Nested runs
aborted before rerun::persist wrote .bashunit/last-failed, overwrote
the parent's report files, and blew the per-run awk fork budget: the
exact three failures the new verify gate surfaced on ubuntu CI.
These flags are this-process-only (parallel stop uses a flag file,
sync stop uses exit codes, reports are written by the main shell after
aggregation), so assign without export; export -n also strips the
export attribute a `set -o allexport` .env load may have applied.
Verified: official ./build.sh --verify green on macOS bash 3.2 and
ubuntu:24.04 (docker, runner-like tooling), plus a leak-probe
acceptance regression test that fails on the previous behaviour.
Closes#834
Claude-Session: https://claude.ai/code/session_01JSeB8UzLCpqst55hAK6dED
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancementNew feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@Chemaclass
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix(build): harden build.sh (verify gate, derived deps, dev bench) - #835

Merged
Chemaclass merged 3 commits into
mainfrom
feat/834-harden-build-sh
Jul 19, 2026
Merged

fix(build): harden build.sh (verify gate, derived deps, dev bench)#835
Chemaclass merged 3 commits into
mainfrom
feat/834-harden-build-sh

Conversation

@Chemaclass

Copy link
Copy Markdown
Member

🤔 Background

Related #834

An audit of build.sh found that --verify never propagated a failing suite to CI, a missing embed marker could silently corrupt the artifact, and the hand-maintained deps list had drifted from the entrypoint — shipping benchmark.sh in the binary while ./bashunit bench crashed in dev mode.

💡 Changes

  • Fail the build when verification fails, when embed markers are missing, or when the artifact fails bash -n; run under set -euo pipefail
  • Derive the embed list from the entrypoint's source order (single source of truth), guard duplicate embeds, drop eval
  • Source src/benchmark.sh from the dev entrypoint and add an acceptance regression test for bashunit bench
  • set -u exposed dead code: Windows checksum skip compared the long-gone $_OS; now uses initialised $_BASHUNIT_OS

https://claude.ai/code/session_01JSeB8UzLCpqst55hAK6dED

- ./build.sh --verify now exits non-zero when the built binary fails
the suite; previously CI saw green on a red verification run
- build.sh runs under set -euo pipefail; missing embed markers abort
instead of silently corrupting the artifact, and every build is
gated behind bash -n
- the embed list is derived from the entrypoint's source order (single
source of truth) instead of a hand-maintained array; src/dev/ stays
excluded and duplicate embeds are guarded by a visited list
- drop eval when resolving $BASHUNIT_ROOT_DIR in sourced paths; anchor
the source-line strip; unique temp file per build
- set -u exposed dead code: the Windows checksum skip compared long-gone
$_OS; check_os is now initialised and compares $_BASHUNIT_OS
- the dev entrypoint never sourced src/benchmark.sh, so ./bashunit bench
crashed with 'command not found' from a checkout while the built
binary worked; source it and add an acceptance regression test
Closes#834
Claude-Session: https://claude.ai/code/session_01JSeB8UzLCpqst55hAK6dED
@ChemaclassChemaclass added the enhancement New feature or request label Jul 19, 2026
@ChemaclassChemaclass self-assigned this Jul 19, 2026
The new --verify gate exposed that verification had been silently
crashing since 2025-06: six test files resolved repo resources through
$BASHUNIT_ROOT_DIR, which points at the build output folder (no src/,
no tools/) when the built binary runs the suite.
- benchmark_test: drop the src source entirely; the entrypoint and the
built binary both provide the module now
- check_os_test / learn_test: resolve src/ relative to the test file
- helpers_test / coverage_percent_test: use repo-cwd-relative paths,
matching how the same helpers already source globals.sh
- globals_test: observe caller_filename through a helper in the test
file so the asserted frame no longer depends on the framework layout
Verified green via BASHUNIT_BUILD_DIR runs on macOS bash 3.2 and
ubuntu:24.04 (docker) — first fully passing verification since the gap
opened.
Closes#834
Claude-Session: https://claude.ai/code/session_01JSeB8UzLCpqst55hAK6dED
--stop-on-failure and the report flags (--log-junit, --report-html,
--report-tap, --report-json) were exported, so any nested bashunit run
— bashunit's own acceptance tests under build.sh --verify, or a user's
script under test that calls bashunit — inherited them. Nested runs
aborted before rerun::persist wrote .bashunit/last-failed, overwrote
the parent's report files, and blew the per-run awk fork budget: the
exact three failures the new verify gate surfaced on ubuntu CI.
These flags are this-process-only (parallel stop uses a flag file,
sync stop uses exit codes, reports are written by the main shell after
aggregation), so assign without export; export -n also strips the
export attribute a `set -o allexport` .env load may have applied.
Verified: official ./build.sh --verify green on macOS bash 3.2 and
ubuntu:24.04 (docker, runner-like tooling), plus a leak-probe
acceptance regression test that fails on the previous behaviour.
Closes#834
Claude-Session: https://claude.ai/code/session_01JSeB8UzLCpqst55hAK6dED
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancementNew feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@Chemaclass
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(build): harden build.sh (verify gate, derived deps, dev bench) - #835

Merged
Chemaclass merged 3 commits into
mainfrom
feat/834-harden-build-sh
Jul 19, 2026
Merged

fix(build): harden build.sh (verify gate, derived deps, dev bench)#835
Chemaclass merged 3 commits into
mainfrom
feat/834-harden-build-sh

Conversation

@Chemaclass

Copy link
Copy Markdown
Member

🤔 Background

Related #834

An audit of build.sh found that --verify never propagated a failing suite to CI, a missing embed marker could silently corrupt the artifact, and the hand-maintained deps list had drifted from the entrypoint — shipping benchmark.sh in the binary while ./bashunit bench crashed in dev mode.

💡 Changes

  • Fail the build when verification fails, when embed markers are missing, or when the artifact fails bash -n; run under set -euo pipefail
  • Derive the embed list from the entrypoint's source order (single source of truth), guard duplicate embeds, drop eval
  • Source src/benchmark.sh from the dev entrypoint and add an acceptance regression test for bashunit bench
  • set -u exposed dead code: Windows checksum skip compared the long-gone $_OS; now uses initialised $_BASHUNIT_OS

https://claude.ai/code/session_01JSeB8UzLCpqst55hAK6dED

- ./build.sh --verify now exits non-zero when the built binary fails
the suite; previously CI saw green on a red verification run
- build.sh runs under set -euo pipefail; missing embed markers abort
instead of silently corrupting the artifact, and every build is
gated behind bash -n
- the embed list is derived from the entrypoint's source order (single
source of truth) instead of a hand-maintained array; src/dev/ stays
excluded and duplicate embeds are guarded by a visited list
- drop eval when resolving $BASHUNIT_ROOT_DIR in sourced paths; anchor
the source-line strip; unique temp file per build
- set -u exposed dead code: the Windows checksum skip compared long-gone
$_OS; check_os is now initialised and compares $_BASHUNIT_OS
- the dev entrypoint never sourced src/benchmark.sh, so ./bashunit bench
crashed with 'command not found' from a checkout while the built
binary worked; source it and add an acceptance regression test
Closes#834
Claude-Session: https://claude.ai/code/session_01JSeB8UzLCpqst55hAK6dED
@ChemaclassChemaclass added the enhancement New feature or request label Jul 19, 2026
@ChemaclassChemaclass self-assigned this Jul 19, 2026
The new --verify gate exposed that verification had been silently
crashing since 2025-06: six test files resolved repo resources through
$BASHUNIT_ROOT_DIR, which points at the build output folder (no src/,
no tools/) when the built binary runs the suite.
- benchmark_test: drop the src source entirely; the entrypoint and the
built binary both provide the module now
- check_os_test / learn_test: resolve src/ relative to the test file
- helpers_test / coverage_percent_test: use repo-cwd-relative paths,
matching how the same helpers already source globals.sh
- globals_test: observe caller_filename through a helper in the test
file so the asserted frame no longer depends on the framework layout
Verified green via BASHUNIT_BUILD_DIR runs on macOS bash 3.2 and
ubuntu:24.04 (docker) — first fully passing verification since the gap
opened.
Closes#834
Claude-Session: https://claude.ai/code/session_01JSeB8UzLCpqst55hAK6dED
--stop-on-failure and the report flags (--log-junit, --report-html,
--report-tap, --report-json) were exported, so any nested bashunit run
— bashunit's own acceptance tests under build.sh --verify, or a user's
script under test that calls bashunit — inherited them. Nested runs
aborted before rerun::persist wrote .bashunit/last-failed, overwrote
the parent's report files, and blew the per-run awk fork budget: the
exact three failures the new verify gate surfaced on ubuntu CI.
These flags are this-process-only (parallel stop uses a flag file,
sync stop uses exit codes, reports are written by the main shell after
aggregation), so assign without export; export -n also strips the
export attribute a `set -o allexport` .env load may have applied.
Verified: official ./build.sh --verify green on macOS bash 3.2 and
ubuntu:24.04 (docker, runner-like tooling), plus a leak-probe
acceptance regression test that fails on the previous behaviour.
Closes#834
Claude-Session: https://claude.ai/code/session_01JSeB8UzLCpqst55hAK6dED
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancementNew feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@Chemaclass
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(build): harden build.sh (verify gate, derived deps, dev bench) - #835

Merged
Chemaclass merged 3 commits into
mainfrom
feat/834-harden-build-sh
Jul 19, 2026
Merged

fix(build): harden build.sh (verify gate, derived deps, dev bench)#835
Chemaclass merged 3 commits into
mainfrom
feat/834-harden-build-sh

Conversation

@Chemaclass

Copy link
Copy Markdown
Member

🤔 Background

Related #834

An audit of build.sh found that --verify never propagated a failing suite to CI, a missing embed marker could silently corrupt the artifact, and the hand-maintained deps list had drifted from the entrypoint — shipping benchmark.sh in the binary while ./bashunit bench crashed in dev mode.

💡 Changes

  • Fail the build when verification fails, when embed markers are missing, or when the artifact fails bash -n; run under set -euo pipefail
  • Derive the embed list from the entrypoint's source order (single source of truth), guard duplicate embeds, drop eval
  • Source src/benchmark.sh from the dev entrypoint and add an acceptance regression test for bashunit bench
  • set -u exposed dead code: Windows checksum skip compared the long-gone $_OS; now uses initialised $_BASHUNIT_OS

https://claude.ai/code/session_01JSeB8UzLCpqst55hAK6dED

- ./build.sh --verify now exits non-zero when the built binary fails
the suite; previously CI saw green on a red verification run
- build.sh runs under set -euo pipefail; missing embed markers abort
instead of silently corrupting the artifact, and every build is
gated behind bash -n
- the embed list is derived from the entrypoint's source order (single
source of truth) instead of a hand-maintained array; src/dev/ stays
excluded and duplicate embeds are guarded by a visited list
- drop eval when resolving $BASHUNIT_ROOT_DIR in sourced paths; anchor
the source-line strip; unique temp file per build
- set -u exposed dead code: the Windows checksum skip compared long-gone
$_OS; check_os is now initialised and compares $_BASHUNIT_OS
- the dev entrypoint never sourced src/benchmark.sh, so ./bashunit bench
crashed with 'command not found' from a checkout while the built
binary worked; source it and add an acceptance regression test
Closes#834
Claude-Session: https://claude.ai/code/session_01JSeB8UzLCpqst55hAK6dED
@ChemaclassChemaclass added the enhancement New feature or request label Jul 19, 2026
@ChemaclassChemaclass self-assigned this Jul 19, 2026
The new --verify gate exposed that verification had been silently
crashing since 2025-06: six test files resolved repo resources through
$BASHUNIT_ROOT_DIR, which points at the build output folder (no src/,
no tools/) when the built binary runs the suite.
- benchmark_test: drop the src source entirely; the entrypoint and the
built binary both provide the module now
- check_os_test / learn_test: resolve src/ relative to the test file
- helpers_test / coverage_percent_test: use repo-cwd-relative paths,
matching how the same helpers already source globals.sh
- globals_test: observe caller_filename through a helper in the test
file so the asserted frame no longer depends on the framework layout
Verified green via BASHUNIT_BUILD_DIR runs on macOS bash 3.2 and
ubuntu:24.04 (docker) — first fully passing verification since the gap
opened.
Closes#834
Claude-Session: https://claude.ai/code/session_01JSeB8UzLCpqst55hAK6dED
--stop-on-failure and the report flags (--log-junit, --report-html,
--report-tap, --report-json) were exported, so any nested bashunit run
— bashunit's own acceptance tests under build.sh --verify, or a user's
script under test that calls bashunit — inherited them. Nested runs
aborted before rerun::persist wrote .bashunit/last-failed, overwrote
the parent's report files, and blew the per-run awk fork budget: the
exact three failures the new verify gate surfaced on ubuntu CI.
These flags are this-process-only (parallel stop uses a flag file,
sync stop uses exit codes, reports are written by the main shell after
aggregation), so assign without export; export -n also strips the
export attribute a `set -o allexport` .env load may have applied.
Verified: official ./build.sh --verify green on macOS bash 3.2 and
ubuntu:24.04 (docker, runner-like tooling), plus a leak-probe
acceptance regression test that fails on the previous behaviour.
Closes#834
Claude-Session: https://claude.ai/code/session_01JSeB8UzLCpqst55hAK6dED
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancementNew feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@Chemaclass
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix(build): harden build.sh (verify gate, derived deps, dev bench) - #835

Merged
Chemaclass merged 3 commits into
mainfrom
feat/834-harden-build-sh
Jul 19, 2026
Merged

fix(build): harden build.sh (verify gate, derived deps, dev bench)#835
Chemaclass merged 3 commits into
mainfrom
feat/834-harden-build-sh

Conversation

@Chemaclass

Copy link
Copy Markdown
Member

🤔 Background

Related #834

An audit of build.sh found that --verify never propagated a failing suite to CI, a missing embed marker could silently corrupt the artifact, and the hand-maintained deps list had drifted from the entrypoint — shipping benchmark.sh in the binary while ./bashunit bench crashed in dev mode.

💡 Changes

  • Fail the build when verification fails, when embed markers are missing, or when the artifact fails bash -n; run under set -euo pipefail
  • Derive the embed list from the entrypoint's source order (single source of truth), guard duplicate embeds, drop eval
  • Source src/benchmark.sh from the dev entrypoint and add an acceptance regression test for bashunit bench
  • set -u exposed dead code: Windows checksum skip compared the long-gone $_OS; now uses initialised $_BASHUNIT_OS

https://claude.ai/code/session_01JSeB8UzLCpqst55hAK6dED

- ./build.sh --verify now exits non-zero when the built binary fails
the suite; previously CI saw green on a red verification run
- build.sh runs under set -euo pipefail; missing embed markers abort
instead of silently corrupting the artifact, and every build is
gated behind bash -n
- the embed list is derived from the entrypoint's source order (single
source of truth) instead of a hand-maintained array; src/dev/ stays
excluded and duplicate embeds are guarded by a visited list
- drop eval when resolving $BASHUNIT_ROOT_DIR in sourced paths; anchor
the source-line strip; unique temp file per build
- set -u exposed dead code: the Windows checksum skip compared long-gone
$_OS; check_os is now initialised and compares $_BASHUNIT_OS
- the dev entrypoint never sourced src/benchmark.sh, so ./bashunit bench
crashed with 'command not found' from a checkout while the built
binary worked; source it and add an acceptance regression test
Closes#834
Claude-Session: https://claude.ai/code/session_01JSeB8UzLCpqst55hAK6dED
@ChemaclassChemaclass added the enhancement New feature or request label Jul 19, 2026
@ChemaclassChemaclass self-assigned this Jul 19, 2026
The new --verify gate exposed that verification had been silently
crashing since 2025-06: six test files resolved repo resources through
$BASHUNIT_ROOT_DIR, which points at the build output folder (no src/,
no tools/) when the built binary runs the suite.
- benchmark_test: drop the src source entirely; the entrypoint and the
built binary both provide the module now
- check_os_test / learn_test: resolve src/ relative to the test file
- helpers_test / coverage_percent_test: use repo-cwd-relative paths,
matching how the same helpers already source globals.sh
- globals_test: observe caller_filename through a helper in the test
file so the asserted frame no longer depends on the framework layout
Verified green via BASHUNIT_BUILD_DIR runs on macOS bash 3.2 and
ubuntu:24.04 (docker) — first fully passing verification since the gap
opened.
Closes#834
Claude-Session: https://claude.ai/code/session_01JSeB8UzLCpqst55hAK6dED
--stop-on-failure and the report flags (--log-junit, --report-html,
--report-tap, --report-json) were exported, so any nested bashunit run
— bashunit's own acceptance tests under build.sh --verify, or a user's
script under test that calls bashunit — inherited them. Nested runs
aborted before rerun::persist wrote .bashunit/last-failed, overwrote
the parent's report files, and blew the per-run awk fork budget: the
exact three failures the new verify gate surfaced on ubuntu CI.
These flags are this-process-only (parallel stop uses a flag file,
sync stop uses exit codes, reports are written by the main shell after
aggregation), so assign without export; export -n also strips the
export attribute a `set -o allexport` .env load may have applied.
Verified: official ./build.sh --verify green on macOS bash 3.2 and
ubuntu:24.04 (docker, runner-like tooling), plus a leak-probe
acceptance regression test that fails on the previous behaviour.
Closes#834
Claude-Session: https://claude.ai/code/session_01JSeB8UzLCpqst55hAK6dED
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancementNew feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@Chemaclass
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(build): harden build.sh (verify gate, derived deps, dev bench) - #835

Merged
Chemaclass merged 3 commits into
mainfrom
feat/834-harden-build-sh
Jul 19, 2026
Merged

fix(build): harden build.sh (verify gate, derived deps, dev bench)#835
Chemaclass merged 3 commits into
mainfrom
feat/834-harden-build-sh

Conversation

@Chemaclass

Copy link
Copy Markdown
Member

🤔 Background

Related #834

An audit of build.sh found that --verify never propagated a failing suite to CI, a missing embed marker could silently corrupt the artifact, and the hand-maintained deps list had drifted from the entrypoint — shipping benchmark.sh in the binary while ./bashunit bench crashed in dev mode.

💡 Changes

  • Fail the build when verification fails, when embed markers are missing, or when the artifact fails bash -n; run under set -euo pipefail
  • Derive the embed list from the entrypoint's source order (single source of truth), guard duplicate embeds, drop eval
  • Source src/benchmark.sh from the dev entrypoint and add an acceptance regression test for bashunit bench
  • set -u exposed dead code: Windows checksum skip compared the long-gone $_OS; now uses initialised $_BASHUNIT_OS

https://claude.ai/code/session_01JSeB8UzLCpqst55hAK6dED

- ./build.sh --verify now exits non-zero when the built binary fails
the suite; previously CI saw green on a red verification run
- build.sh runs under set -euo pipefail; missing embed markers abort
instead of silently corrupting the artifact, and every build is
gated behind bash -n
- the embed list is derived from the entrypoint's source order (single
source of truth) instead of a hand-maintained array; src/dev/ stays
excluded and duplicate embeds are guarded by a visited list
- drop eval when resolving $BASHUNIT_ROOT_DIR in sourced paths; anchor
the source-line strip; unique temp file per build
- set -u exposed dead code: the Windows checksum skip compared long-gone
$_OS; check_os is now initialised and compares $_BASHUNIT_OS
- the dev entrypoint never sourced src/benchmark.sh, so ./bashunit bench
crashed with 'command not found' from a checkout while the built
binary worked; source it and add an acceptance regression test
Closes#834
Claude-Session: https://claude.ai/code/session_01JSeB8UzLCpqst55hAK6dED
@ChemaclassChemaclass added the enhancement New feature or request label Jul 19, 2026
@ChemaclassChemaclass self-assigned this Jul 19, 2026
The new --verify gate exposed that verification had been silently
crashing since 2025-06: six test files resolved repo resources through
$BASHUNIT_ROOT_DIR, which points at the build output folder (no src/,
no tools/) when the built binary runs the suite.
- benchmark_test: drop the src source entirely; the entrypoint and the
built binary both provide the module now
- check_os_test / learn_test: resolve src/ relative to the test file
- helpers_test / coverage_percent_test: use repo-cwd-relative paths,
matching how the same helpers already source globals.sh
- globals_test: observe caller_filename through a helper in the test
file so the asserted frame no longer depends on the framework layout
Verified green via BASHUNIT_BUILD_DIR runs on macOS bash 3.2 and
ubuntu:24.04 (docker) — first fully passing verification since the gap
opened.
Closes#834
Claude-Session: https://claude.ai/code/session_01JSeB8UzLCpqst55hAK6dED
--stop-on-failure and the report flags (--log-junit, --report-html,
--report-tap, --report-json) were exported, so any nested bashunit run
— bashunit's own acceptance tests under build.sh --verify, or a user's
script under test that calls bashunit — inherited them. Nested runs
aborted before rerun::persist wrote .bashunit/last-failed, overwrote
the parent's report files, and blew the per-run awk fork budget: the
exact three failures the new verify gate surfaced on ubuntu CI.
These flags are this-process-only (parallel stop uses a flag file,
sync stop uses exit codes, reports are written by the main shell after
aggregation), so assign without export; export -n also strips the
export attribute a `set -o allexport` .env load may have applied.
Verified: official ./build.sh --verify green on macOS bash 3.2 and
ubuntu:24.04 (docker, runner-like tooling), plus a leak-probe
acceptance regression test that fails on the previous behaviour.
Closes#834
Claude-Session: https://claude.ai/code/session_01JSeB8UzLCpqst55hAK6dED
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancementNew feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@Chemaclass
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(build): harden build.sh (verify gate, derived deps, dev bench) - #835

Merged
Chemaclass merged 3 commits into
mainfrom
feat/834-harden-build-sh
Jul 19, 2026
Merged

fix(build): harden build.sh (verify gate, derived deps, dev bench)#835
Chemaclass merged 3 commits into
mainfrom
feat/834-harden-build-sh

Conversation

@Chemaclass

Copy link
Copy Markdown
Member

🤔 Background

Related #834

An audit of build.sh found that --verify never propagated a failing suite to CI, a missing embed marker could silently corrupt the artifact, and the hand-maintained deps list had drifted from the entrypoint — shipping benchmark.sh in the binary while ./bashunit bench crashed in dev mode.

💡 Changes

  • Fail the build when verification fails, when embed markers are missing, or when the artifact fails bash -n; run under set -euo pipefail
  • Derive the embed list from the entrypoint's source order (single source of truth), guard duplicate embeds, drop eval
  • Source src/benchmark.sh from the dev entrypoint and add an acceptance regression test for bashunit bench
  • set -u exposed dead code: Windows checksum skip compared the long-gone $_OS; now uses initialised $_BASHUNIT_OS

https://claude.ai/code/session_01JSeB8UzLCpqst55hAK6dED

- ./build.sh --verify now exits non-zero when the built binary fails
the suite; previously CI saw green on a red verification run
- build.sh runs under set -euo pipefail; missing embed markers abort
instead of silently corrupting the artifact, and every build is
gated behind bash -n
- the embed list is derived from the entrypoint's source order (single
source of truth) instead of a hand-maintained array; src/dev/ stays
excluded and duplicate embeds are guarded by a visited list
- drop eval when resolving $BASHUNIT_ROOT_DIR in sourced paths; anchor
the source-line strip; unique temp file per build
- set -u exposed dead code: the Windows checksum skip compared long-gone
$_OS; check_os is now initialised and compares $_BASHUNIT_OS
- the dev entrypoint never sourced src/benchmark.sh, so ./bashunit bench
crashed with 'command not found' from a checkout while the built
binary worked; source it and add an acceptance regression test
Closes#834
Claude-Session: https://claude.ai/code/session_01JSeB8UzLCpqst55hAK6dED
@ChemaclassChemaclass added the enhancement New feature or request label Jul 19, 2026
@ChemaclassChemaclass self-assigned this Jul 19, 2026
The new --verify gate exposed that verification had been silently
crashing since 2025-06: six test files resolved repo resources through
$BASHUNIT_ROOT_DIR, which points at the build output folder (no src/,
no tools/) when the built binary runs the suite.
- benchmark_test: drop the src source entirely; the entrypoint and the
built binary both provide the module now
- check_os_test / learn_test: resolve src/ relative to the test file
- helpers_test / coverage_percent_test: use repo-cwd-relative paths,
matching how the same helpers already source globals.sh
- globals_test: observe caller_filename through a helper in the test
file so the asserted frame no longer depends on the framework layout
Verified green via BASHUNIT_BUILD_DIR runs on macOS bash 3.2 and
ubuntu:24.04 (docker) — first fully passing verification since the gap
opened.
Closes#834
Claude-Session: https://claude.ai/code/session_01JSeB8UzLCpqst55hAK6dED
--stop-on-failure and the report flags (--log-junit, --report-html,
--report-tap, --report-json) were exported, so any nested bashunit run
— bashunit's own acceptance tests under build.sh --verify, or a user's
script under test that calls bashunit — inherited them. Nested runs
aborted before rerun::persist wrote .bashunit/last-failed, overwrote
the parent's report files, and blew the per-run awk fork budget: the
exact three failures the new verify gate surfaced on ubuntu CI.
These flags are this-process-only (parallel stop uses a flag file,
sync stop uses exit codes, reports are written by the main shell after
aggregation), so assign without export; export -n also strips the
export attribute a `set -o allexport` .env load may have applied.
Verified: official ./build.sh --verify green on macOS bash 3.2 and
ubuntu:24.04 (docker, runner-like tooling), plus a leak-probe
acceptance regression test that fails on the previous behaviour.
Closes#834
Claude-Session: https://claude.ai/code/session_01JSeB8UzLCpqst55hAK6dED
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancementNew feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@Chemaclass
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix(build): harden build.sh (verify gate, derived deps, dev bench) - #835

Merged
Chemaclass merged 3 commits into
mainfrom
feat/834-harden-build-sh
Jul 19, 2026
Merged

fix(build): harden build.sh (verify gate, derived deps, dev bench)#835
Chemaclass merged 3 commits into
mainfrom
feat/834-harden-build-sh

Conversation

@Chemaclass

Copy link
Copy Markdown
Member

🤔 Background

Related #834

An audit of build.sh found that --verify never propagated a failing suite to CI, a missing embed marker could silently corrupt the artifact, and the hand-maintained deps list had drifted from the entrypoint — shipping benchmark.sh in the binary while ./bashunit bench crashed in dev mode.

💡 Changes

  • Fail the build when verification fails, when embed markers are missing, or when the artifact fails bash -n; run under set -euo pipefail
  • Derive the embed list from the entrypoint's source order (single source of truth), guard duplicate embeds, drop eval
  • Source src/benchmark.sh from the dev entrypoint and add an acceptance regression test for bashunit bench
  • set -u exposed dead code: Windows checksum skip compared the long-gone $_OS; now uses initialised $_BASHUNIT_OS

https://claude.ai/code/session_01JSeB8UzLCpqst55hAK6dED

- ./build.sh --verify now exits non-zero when the built binary fails
the suite; previously CI saw green on a red verification run
- build.sh runs under set -euo pipefail; missing embed markers abort
instead of silently corrupting the artifact, and every build is
gated behind bash -n
- the embed list is derived from the entrypoint's source order (single
source of truth) instead of a hand-maintained array; src/dev/ stays
excluded and duplicate embeds are guarded by a visited list
- drop eval when resolving $BASHUNIT_ROOT_DIR in sourced paths; anchor
the source-line strip; unique temp file per build
- set -u exposed dead code: the Windows checksum skip compared long-gone
$_OS; check_os is now initialised and compares $_BASHUNIT_OS
- the dev entrypoint never sourced src/benchmark.sh, so ./bashunit bench
crashed with 'command not found' from a checkout while the built
binary worked; source it and add an acceptance regression test
Closes#834
Claude-Session: https://claude.ai/code/session_01JSeB8UzLCpqst55hAK6dED
@ChemaclassChemaclass added the enhancement New feature or request label Jul 19, 2026
@ChemaclassChemaclass self-assigned this Jul 19, 2026
The new --verify gate exposed that verification had been silently
crashing since 2025-06: six test files resolved repo resources through
$BASHUNIT_ROOT_DIR, which points at the build output folder (no src/,
no tools/) when the built binary runs the suite.
- benchmark_test: drop the src source entirely; the entrypoint and the
built binary both provide the module now
- check_os_test / learn_test: resolve src/ relative to the test file
- helpers_test / coverage_percent_test: use repo-cwd-relative paths,
matching how the same helpers already source globals.sh
- globals_test: observe caller_filename through a helper in the test
file so the asserted frame no longer depends on the framework layout
Verified green via BASHUNIT_BUILD_DIR runs on macOS bash 3.2 and
ubuntu:24.04 (docker) — first fully passing verification since the gap
opened.
Closes#834
Claude-Session: https://claude.ai/code/session_01JSeB8UzLCpqst55hAK6dED
--stop-on-failure and the report flags (--log-junit, --report-html,
--report-tap, --report-json) were exported, so any nested bashunit run
— bashunit's own acceptance tests under build.sh --verify, or a user's
script under test that calls bashunit — inherited them. Nested runs
aborted before rerun::persist wrote .bashunit/last-failed, overwrote
the parent's report files, and blew the per-run awk fork budget: the
exact three failures the new verify gate surfaced on ubuntu CI.
These flags are this-process-only (parallel stop uses a flag file,
sync stop uses exit codes, reports are written by the main shell after
aggregation), so assign without export; export -n also strips the
export attribute a `set -o allexport` .env load may have applied.
Verified: official ./build.sh --verify green on macOS bash 3.2 and
ubuntu:24.04 (docker, runner-like tooling), plus a leak-probe
acceptance regression test that fails on the previous behaviour.
Closes#834
Claude-Session: https://claude.ai/code/session_01JSeB8UzLCpqst55hAK6dED
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancementNew feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@Chemaclass