feat(planner): add reachability_check step (#1606)

* feat(planner): add reachability_check step to prevent unreachable code

Closes #1495

* fix: trim gsd-planner.md below 50000-char limit after rebase

The reachability_check addition pushed the file to 50,275 chars when
merged with the assign_waves additions from #1600. Condense both sections
while preserving all logic; file is now 49,859 chars.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix(security): normalize CRLF before prompt-stuffing length check

On Windows, git checks out files with CRLF line endings. JavaScript's
String.length counts \r characters, so a 49,859-byte file measures as
51,126 chars on Windows — falsely tripping the 50,000-char security
scanner. Normalize CRLF → LF before measuring in security.cjs and in
the reachability-check test.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix: trim gsd-planner.md to stay under 50000-char limit after merge with main

After rebasing onto main (which added mcp_tool_usage block), combined content
reached 50031 chars. Remove suggested log format from assign_waves rule to
bring file to 49972 chars, well under the 50000-char security scanner limit.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
Tom Boucher
2026-04-03 13:00:41 -04:00
committed by GitHub
parent 0a9ce8c975
commit 3078279a9a
3 changed files with 68 additions and 8 deletions

View File

@@ -1232,11 +1232,7 @@ for each plan B in plan_order:
waves[B.id] = B.wave
```
**Rule:** Any two plans in the same wave MUST have zero `files_modified` overlap — even if
no explicit `depends_on` was set. After computing all wave numbers, verify every wave group:
collect the union of `files_modified` per wave; if any file appears in two or more plans
within the same wave, bump the later plan to the next wave and repeat until clean.
Log each bump: `"Plan {B} moved to wave {N+1}: files_modified overlap with Plan {A} on {file}"`
**Rule:** Same-wave plans must have zero `files_modified` overlap. After assigning waves, scan each wave; if any file appears in 2+ plans, bump the later plan to the next wave and repeat.
</step>
<step name="group_into_plans">
@@ -1256,6 +1252,15 @@ Apply goal-backward methodology (see goal_backward section):
5. Identify key links (critical connections)
</step>
<step name="reachability_check">
For each must-have artifact, verify a concrete path exists:
- Entity → in-phase or existing creation path
- Workflow → user action or API call triggers it
- Config flag → default value + consumer
- UI → route or nav link
UNREACHABLE (no path) → revise plan.
</step>
<step name="estimate_scope">
Verify each plan fits context budget: 2-3 tasks, ~50% target. Split if necessary. Check granularity setting.
</step>

View File

@@ -181,9 +181,11 @@ function scanForInjection(text, opts = {}) {
findings.push('Contains suspicious zero-width or invisible Unicode characters');
}
// Check for extremely long strings that could be prompt stuffing
if (text.length > 50000) {
findings.push(`Suspicious text length: ${text.length} chars (potential prompt stuffing)`);
// Check for extremely long strings that could be prompt stuffing.
// Normalize CRLF → LF before measuring so Windows checkouts don't inflate the count.
const normalizedLength = text.replace(/\r\n/g, '\n').replace(/\r/g, '\n').length;
if (normalizedLength > 50000) {
findings.push(`Suspicious text length: ${normalizedLength} chars (potential prompt stuffing)`);
}
}

View File

@@ -0,0 +1,53 @@
const { test, describe } = require('node:test');
const assert = require('node:assert');
const fs = require('fs');
const path = require('path');
describe('gsd-planner reachability_check step', () => {
const plannerPath = path.join(__dirname, '..', 'agents', 'gsd-planner.md');
let content;
test('planner file exists', () => {
assert.ok(fs.existsSync(plannerPath));
content = fs.readFileSync(plannerPath, 'utf-8');
});
test('contains reachability_check step', () => {
content = content || fs.readFileSync(plannerPath, 'utf-8');
assert.ok(content.includes('<step name="reachability_check">'), 'Missing reachability_check step');
});
test('reachability_check appears after derive_must_haves', () => {
content = content || fs.readFileSync(plannerPath, 'utf-8');
const mustHavesIdx = content.indexOf('derive_must_haves');
const reachabilityIdx = content.indexOf('reachability_check');
assert.ok(mustHavesIdx > -1, 'derive_must_haves step not found');
assert.ok(reachabilityIdx > -1, 'reachability_check step not found');
assert.ok(reachabilityIdx > mustHavesIdx, 'reachability_check must come after derive_must_haves');
});
test('reachability_check appears before estimate_scope', () => {
content = content || fs.readFileSync(plannerPath, 'utf-8');
const reachabilityIdx = content.indexOf('reachability_check');
const estimateIdx = content.indexOf('estimate_scope');
assert.ok(estimateIdx > -1, 'estimate_scope step not found');
assert.ok(reachabilityIdx < estimateIdx, 'reachability_check must come before estimate_scope');
});
test('reachability_check includes creation path check', () => {
content = content || fs.readFileSync(plannerPath, 'utf-8');
assert.ok(content.includes('creation path') || content.includes('creation_path') || content.includes('reachable'),
'Missing creation path verification logic');
});
test('reachability_check includes UNREACHABLE marker', () => {
content = content || fs.readFileSync(plannerPath, 'utf-8');
assert.ok(content.includes('UNREACHABLE'), 'Missing UNREACHABLE marker for failed checks');
});
test('file stays under 50000 char limit (CRLF-normalized)', () => {
content = content || fs.readFileSync(plannerPath, 'utf-8');
const normalized = content.replace(/\r\n/g, '\n').replace(/\r/g, '\n');
assert.ok(normalized.length < 50000, `File is ${normalized.length} chars, over the 50000 limit`);
});
});