Faithful package acceptance
Tracked by pm-gh1391, pm-aiqmgj, and pm-dqej6b, with scratch ancestry protection tracked by pm-runner-ancestor-tracker.
Package tests that create their own disposable projects need an unset PM_PATH.
Otherwise a nested pm init follows the inherited tracker override and writes
outside the intended fixture. Use the shared SDK linked-test runner with a
disposable source snapshot:
pm test <item-id> --add-json '{"command":"npm run release:check","pm_context_mode":"none","workspace_context_mode":"snapshot","timeout_seconds":900}'
pm test <item-id> --run --progress
The same fields are supported by the SDK's runTest and MCP. See
Testing for trust acknowledgements, assertions and run receipts.
Snapshots copy the current source files and keep root and nested node_modules
at their original relative paths. A Git workspace additionally receives an
independent clone of commit and tag objects, so release-tag checks and dependency
resolution work together. The clone uses no shared objects or source hooks,
does not inherit source-local Git configuration, and has no origin remote.
The internal remote name is explicit even with a custom clone.defaultRemoteName.
Its Git objects remain readable after the source checkout is removed.
The working tree excludes tracker and generated build/report directories. Git objects contain repository history, including any historically tracked files; a snapshot is an execution-isolation boundary, not a redaction mechanism. Source aliases remain subject to containment checks. Installed dependency directories are shared, so dependency-mutating tests need a separate installation. Tests that depend on absolute checkout paths, source-local Git configuration, submodule configuration, or exact dirty-status output must declare those requirements separately. Cloning failures fail the linked run rather than silently certifying a partial Git identity.
PM_GLOBAL_PATH remains isolated. none with a live source workspace and direct
PM commands remains refused. Existing command provenance and clone-local trust
checks still apply. The runner records the effective workspace and tracker
context on each execution so a green linked receipt identifies its boundary.
Repository acceptance also refuses scratch roots beneath any initialized
ancestor tracker before allocating fixtures, including external roots and
root-layout trackers. Choose a temporary hierarchy without workspace ancestry.
The optional SQLite accelerator filters Node's exact experimental announcement only during synchronous native loading. Every other warning retains its original arguments, and normal warning delivery is restored immediately, including after a failed optional load. JSON refusals and clean mutation stderr therefore remain usable on Node 22 and Node 24 without disabling application diagnostics.
The repository's scratch lifecycle keeps its original 15-second latency and 3,000-token output limits. Vitest schedules it in a separate project after the parallel contract suite. Functional assertions and the all-source coverage denominator stay intact; a real latency regression still fails admission.
来自 pm 2026.10.10 中的 docs/PACKAGE_GATE_ACCEPTANCE.md。 在 GitHub 上查看