diff --git a/.changeset/2107-orchestrator-honors-blocking-human-gate.md b/.changeset/2107-orchestrator-honors-blocking-human-gate.md new file mode 100644 index 000000000..a4d745e9b --- /dev/null +++ b/.changeset/2107-orchestrator-honors-blocking-human-gate.md @@ -0,0 +1,5 @@ +--- +type: Security +pr: 2113 +--- +**`gate="blocking-human"` checkpoints are no longer auto-approved by the execute-phase orchestrator** — the package-legitimacy gate (#2827) spans two layers: `gsd-executor` refuses to auto-approve a `gate="blocking-human"` checkpoint and escalates it via `checkpoint_return_format` so a human can vet the package, and `execute-phase`'s `checkpoint_handling` step decides what happens next. That step dispatched purely on checkpoint *type* and never read `gate`, so under `--auto` / `--chain` it immediately auto-approved the very checkpoint the executor had just refused to auto-approve (`human-verify → {user_response} = "approved"`). The slopsquatting defence was therefore inert in exactly the unattended mode where nobody is watching: an `[ASSUMED]`/`[SUS]` package reached install with no human ever seeing the verification prompt. `checkpoint_handling` now carves out `gate="blocking-human"` (and the package-legitimacy `what-built` markers) ahead of every auto-mode branch, routing those checkpoints to the standard present-to-user flow regardless of type. `references/checkpoints.md` documents the `gate` attribute and its two values for the first time — previously `blocking-human` appeared nowhere outside `agents/gsd-executor.md`, so no planner had a documented way to author a checkpoint that auto-mode could not bypass. The existing regression test asserted the executor half only; it now asserts the orchestrator half too, which is why it stayed green while the gate was open. (#2107) diff --git a/agents/gsd-executor.md b/agents/gsd-executor.md index 6f4ecc5fd..f3f57169e 100644 --- a/agents/gsd-executor.md +++ b/agents/gsd-executor.md @@ -315,7 +315,7 @@ For full automation-first patterns, server lifecycle, CLI handling: **Auto-mode checkpoint behavior** (when `AUTO_CFG` is `"true"`): - **checkpoint:human-verify** → Auto-approve **except package-legitimacy checkpoints**. If checkpoint has `gate="blocking-human"` OR its purpose indicates package legitimacy verification (`what-built` mentions `Package verification required before install` or `Package install failed — human verification required`), do **not** auto-approve. STOP and return checkpoint_return_format for explicit human confirmation. -- **checkpoint:decision** → Auto-select first option (planners front-load the recommended choice). Log `⚡ Auto-selected: [option name]`. Continue to next task. +- **checkpoint:decision** → If checkpoint has `gate="blocking-human"`, do **not** auto-select — STOP and return checkpoint_return_format for an explicit human decision (a `blocking-human` decision exists because its default answer would be wrong to assume). Otherwise auto-select first option (planners front-load the recommended choice), log `⚡ Auto-selected: [option name]`, continue to next task. - **checkpoint:human-action** → STOP normally. Auth gates cannot be automated — return structured checkpoint message using checkpoint_return_format. **Standard checkpoint behavior** (when `AUTO_CFG` is not `"true"`): @@ -340,6 +340,7 @@ When hitting checkpoint or auth gate, return this structure: ## CHECKPOINT REACHED **Type:** [human-verify | decision | human-action] +**Gate:** [blocking | blocking-human] — copy the task's `gate` attribute verbatim so the orchestrator's carve-out sees it **Plan:** {phase}-{plan} **Progress:** {completed}/{total} tasks complete diff --git a/gsd-core/references/checkpoints.md b/gsd-core/references/checkpoints.md index d63f06707..2fd6bbb69 100644 --- a/gsd-core/references/checkpoints.md +++ b/gsd-core/references/checkpoints.md @@ -9,6 +9,18 @@ Plans execute autonomously. Checkpoints formalize interaction points where human 3. **User only does what requires human judgment** - Visual checks, UX evaluation, "does this feel right?" 4. **Secrets come from user, automation comes from Claude** - Ask for API keys, then Claude uses them via CLI 5. **Auto-mode bypasses verification/decision checkpoints** — When `workflow._auto_chain_active` or `workflow.auto_advance` is true in config: human-verify auto-approves, decision auto-selects first option, human-action still stops (auth gates cannot be automated) +6. **`gate="blocking-human"` is never auto-approved** — a checkpoint carrying this gate stops for a human in *every* mode, including auto-mode, regardless of its type. Rule 5 does not apply to it. + +**The `gate` attribute:** + +| Value | Auto-mode behavior | Use for | +|-------|--------------------|---------| +| `gate="blocking"` | Bypassed per rule 5 (human-verify auto-approves, decision auto-selects) | The default. Post-hoc verification and implementation choices that are safe to take the recommended path on when unattended. | +| `gate="blocking-human"` | **Never bypassed.** Stops for a human in auto-mode too. | Irreversible or trust-establishing steps a human must actually see: package-legitimacy verification before install, and any decision whose default answer would be wrong to assume. | + +Reach for `gate="blocking-human"` whenever auto-approving the checkpoint would defeat its purpose. If the checkpoint exists because a human must *decide* something, `blocking` is the wrong gate — auto-mode will decide it for them. + +The gate spans two layers, and both must honor it. `gsd-executor` refuses to auto-approve a `gate="blocking-human"` checkpoint and escalates it via `checkpoint_return_format` precisely so a human sees it; `execute-phase`'s `checkpoint_handling` step then decides what the user is actually shown. An orchestrator that dispatches on checkpoint *type* alone would auto-approve the very checkpoint the executor just refused to auto-approve, nullifying that refusal one layer up and letting an unattended `--auto` / `--chain` run install a package no human ever vetted. diff --git a/gsd-core/workflows/execute-phase.md b/gsd-core/workflows/execute-phase.md index 212b5c293..667bbccd5 100644 --- a/gsd-core/workflows/execute-phase.md +++ b/gsd-core/workflows/execute-phase.md @@ -1056,11 +1056,13 @@ AUTO_MODE=$(gsd_run query check auto-mode --pick active 2>/dev/null || echo "fal ``` When executor returns a checkpoint AND `AUTO_MODE` is `true`: -- **human-verify** → Auto-spawn continuation agent with `{user_response}` = `"approved"`. Log `⚡ Auto-approved checkpoint`. -- **decision** → Auto-spawn continuation agent with `{user_response}` = first option from checkpoint details. Log `⚡ Auto-selected: [option]`. +- **human-verify** → Auto-spawn continuation agent with `{user_response}` = `"approved"`. Log `⚡ Auto-approved checkpoint`. **Except `blocking-human`.** +- **decision** → Auto-spawn continuation agent with `{user_response}` = first option from checkpoint details. Log `⚡ Auto-selected: [option]`. **Except `blocking-human`.** - **human-action** → Present to user (existing behavior below). Auth gates cannot be automated. -**Standard flow (not auto-mode, or human-action type):** +**Carve-out — overrides all branches above.** If the returned `Gate:` is `blocking-human`, or its `` mentions `Package verification required before install` or `Package install failed — human verification required`, never auto-approve or auto-select, regardless of type. Present to user (standard flow below). Log `⛔ blocking-human gate — auto-mode suspended`. + +**Standard flow (not auto-mode, human-action, or blocking-human):** 1. Spawn agent for checkpoint plan 2. Agent runs until checkpoint task or auth gate → returns structured state diff --git a/tests/agent-size-baseline.json b/tests/agent-size-baseline.json index 5044c3856..84ec93622 100644 --- a/tests/agent-size-baseline.json +++ b/tests/agent-size-baseline.json @@ -14,7 +14,7 @@ "gsd-domain-researcher.md": 7032, "gsd-eval-auditor.md": 12496, "gsd-eval-planner.md": 7008, - "gsd-executor.md": 43607, + "gsd-executor.md": 43973, "gsd-framework-selector.md": 6778, "gsd-integration-checker.md": 15238, "gsd-intel-updater.md": 18166, diff --git a/tests/fixtures/golden-install-parity/antigravity.json b/tests/fixtures/golden-install-parity/antigravity.json index fc15df65d..5b607fd97 100644 --- a/tests/fixtures/golden-install-parity/antigravity.json +++ b/tests/fixtures/golden-install-parity/antigravity.json @@ -16,7 +16,7 @@ "agents/gsd-domain-researcher.md": "1db46cac3f4d9889", "agents/gsd-eval-auditor.md": "1b8391f1aafb067f", "agents/gsd-eval-planner.md": "3d10fd11147f6857", - "agents/gsd-executor.md": "152ca51a10b99ff8", + "agents/gsd-executor.md": "6b7b461429de7d35", "agents/gsd-framework-selector.md": "daa62c79619c76bf", "agents/gsd-integration-checker.md": "0643cd2d779b131c", "agents/gsd-intel-updater.md": "26c1f1e028c6346a", @@ -55,7 +55,7 @@ "gsd-core/references/api-coverage.md": "205a43c5fa7c221c", "gsd-core/references/artifact-types.md": "e176817364a7cbf4", "gsd-core/references/autonomous-smart-discuss.md": "efd80aca449032ad", - "gsd-core/references/checkpoints.md": "2de680837faa9752", + "gsd-core/references/checkpoints.md": "509700508de43306", "gsd-core/references/common-bug-patterns.md": "780145be56352626", "gsd-core/references/context-budget.md": "177520ead2ae3a23", "gsd-core/references/continuation-format.md": "580287399ad3ba68", @@ -233,7 +233,7 @@ "gsd-core/workflows/docs-update.md": "8e986e26d0e6e1a0", "gsd-core/workflows/edit-phase.md": "fc932e82ba1f585a", "gsd-core/workflows/eval-review.md": "eb4040eaa5b8497f", - "gsd-core/workflows/execute-phase.md": "82beafd82b24210c", + "gsd-core/workflows/execute-phase.md": "894d0e9efed72258", "gsd-core/workflows/execute-phase/steps/codebase-drift-gate.md": "55d0706e80a2554a", "gsd-core/workflows/execute-phase/steps/per-plan-worktree-gate.md": "7ebb7d1af6082028", "gsd-core/workflows/execute-phase/steps/post-merge-gate.md": "9b7107b31b60a3b9", diff --git a/tests/fixtures/golden-install-parity/augment.json b/tests/fixtures/golden-install-parity/augment.json index 120386618..4db1c9c1f 100644 --- a/tests/fixtures/golden-install-parity/augment.json +++ b/tests/fixtures/golden-install-parity/augment.json @@ -16,7 +16,7 @@ "agents/gsd-domain-researcher.md": "671c9ea949889c4a", "agents/gsd-eval-auditor.md": "fcaec7b00f94c435", "agents/gsd-eval-planner.md": "a4a5b4b3f7828ba3", - "agents/gsd-executor.md": "46f911cd211034b0", + "agents/gsd-executor.md": "ed2c39fa8c03d056", "agents/gsd-framework-selector.md": "4b77eebbe9288d80", "agents/gsd-integration-checker.md": "fa53e2d78be1de74", "agents/gsd-intel-updater.md": "fa40e685d7441ace", @@ -126,7 +126,7 @@ "gsd-core/references/api-coverage.md": "66264d41dfd9154a", "gsd-core/references/artifact-types.md": "a6d2e1f9453ffbf5", "gsd-core/references/autonomous-smart-discuss.md": "2fc710cde0ec7785", - "gsd-core/references/checkpoints.md": "6aa620c6ca38bdf0", + "gsd-core/references/checkpoints.md": "b1530628d693fc85", "gsd-core/references/common-bug-patterns.md": "780145be56352626", "gsd-core/references/context-budget.md": "f1ce57bf418824af", "gsd-core/references/continuation-format.md": "ce73e57d053ab8a7", @@ -304,7 +304,7 @@ "gsd-core/workflows/docs-update.md": "f35922d15b7061c9", "gsd-core/workflows/edit-phase.md": "966a3eadd1bebc04", "gsd-core/workflows/eval-review.md": "f898936e2cfe4130", - "gsd-core/workflows/execute-phase.md": "1b2d0b868f574e80", + "gsd-core/workflows/execute-phase.md": "7d42e81188b3613a", "gsd-core/workflows/execute-phase/steps/codebase-drift-gate.md": "4e265392b3f2ba0e", "gsd-core/workflows/execute-phase/steps/per-plan-worktree-gate.md": "7ebb7d1af6082028", "gsd-core/workflows/execute-phase/steps/post-merge-gate.md": "811b6d8489571581", diff --git a/tests/fixtures/golden-install-parity/claude-local.json b/tests/fixtures/golden-install-parity/claude-local.json index de6f1260e..6cc6844b6 100644 --- a/tests/fixtures/golden-install-parity/claude-local.json +++ b/tests/fixtures/golden-install-parity/claude-local.json @@ -15,7 +15,7 @@ "agents/gsd-domain-researcher.md": "f1e03df842ddfb95", "agents/gsd-eval-auditor.md": "d0f45fff7370bb0b", "agents/gsd-eval-planner.md": "9cc049b82897daa4", - "agents/gsd-executor.md": "bf1de739df0c9245", + "agents/gsd-executor.md": "62f37fae936e0d2f", "agents/gsd-framework-selector.md": "85005d716f9d98f7", "agents/gsd-integration-checker.md": "17a8ee731986564d", "agents/gsd-intel-updater.md": "4953a465db9dadc1", @@ -125,7 +125,7 @@ "gsd-core/references/api-coverage.md": "205a43c5fa7c221c", "gsd-core/references/artifact-types.md": "251040866a3a1818", "gsd-core/references/autonomous-smart-discuss.md": "2fc710cde0ec7785", - "gsd-core/references/checkpoints.md": "6aa620c6ca38bdf0", + "gsd-core/references/checkpoints.md": "b1530628d693fc85", "gsd-core/references/common-bug-patterns.md": "780145be56352626", "gsd-core/references/context-budget.md": "6bfac08025ea3106", "gsd-core/references/continuation-format.md": "580287399ad3ba68", @@ -303,7 +303,7 @@ "gsd-core/workflows/docs-update.md": "cd753783ab95da00", "gsd-core/workflows/edit-phase.md": "dbbb6191f5a8b65e", "gsd-core/workflows/eval-review.md": "086a1f2b3c11462c", - "gsd-core/workflows/execute-phase.md": "d7d8ac751aa2915e", + "gsd-core/workflows/execute-phase.md": "e5bc721629beaa01", "gsd-core/workflows/execute-phase/steps/codebase-drift-gate.md": "6d38bfd540030da4", "gsd-core/workflows/execute-phase/steps/per-plan-worktree-gate.md": "7ebb7d1af6082028", "gsd-core/workflows/execute-phase/steps/post-merge-gate.md": "611b2be3bd133eb1", diff --git a/tests/fixtures/golden-install-parity/claude.json b/tests/fixtures/golden-install-parity/claude.json index 278315fb6..d79453924 100644 --- a/tests/fixtures/golden-install-parity/claude.json +++ b/tests/fixtures/golden-install-parity/claude.json @@ -15,7 +15,7 @@ "agents/gsd-domain-researcher.md": "5f7d366251b957fe", "agents/gsd-eval-auditor.md": "fea2759beff0a642", "agents/gsd-eval-planner.md": "112f6730f23854e3", - "agents/gsd-executor.md": "22fc2f17098a4d14", + "agents/gsd-executor.md": "d1750d26580daa7f", "agents/gsd-framework-selector.md": "c350ee693cb1aa4e", "agents/gsd-integration-checker.md": "c8b4e65dee89c8ea", "agents/gsd-intel-updater.md": "5b41e05f90ce89d9", @@ -54,7 +54,7 @@ "gsd-core/references/api-coverage.md": "205a43c5fa7c221c", "gsd-core/references/artifact-types.md": "8bd01fd75a2ba70e", "gsd-core/references/autonomous-smart-discuss.md": "2fc710cde0ec7785", - "gsd-core/references/checkpoints.md": "6aa620c6ca38bdf0", + "gsd-core/references/checkpoints.md": "b1530628d693fc85", "gsd-core/references/common-bug-patterns.md": "780145be56352626", "gsd-core/references/context-budget.md": "533eae480bfc4bb8", "gsd-core/references/continuation-format.md": "580287399ad3ba68", @@ -232,7 +232,7 @@ "gsd-core/workflows/docs-update.md": "63082608d3ae92be", "gsd-core/workflows/edit-phase.md": "8323bfe10faa0c0a", "gsd-core/workflows/eval-review.md": "f59e8329dae1e528", - "gsd-core/workflows/execute-phase.md": "4aa35e8cb9d68cde", + "gsd-core/workflows/execute-phase.md": "5231186012da87a2", "gsd-core/workflows/execute-phase/steps/codebase-drift-gate.md": "facb0e816d87a0c7", "gsd-core/workflows/execute-phase/steps/per-plan-worktree-gate.md": "7ebb7d1af6082028", "gsd-core/workflows/execute-phase/steps/post-merge-gate.md": "811b6d8489571581", diff --git a/tests/fixtures/golden-install-parity/cline.json b/tests/fixtures/golden-install-parity/cline.json index d1151047b..960882cc5 100644 --- a/tests/fixtures/golden-install-parity/cline.json +++ b/tests/fixtures/golden-install-parity/cline.json @@ -19,7 +19,7 @@ "agents/gsd-domain-researcher.md": "0fecdaea86466a56", "agents/gsd-eval-auditor.md": "36c44303085df2f8", "agents/gsd-eval-planner.md": "3ddea88a69b4da3f", - "agents/gsd-executor.md": "441e624e9685e505", + "agents/gsd-executor.md": "2ca77ad7d9909f82", "agents/gsd-framework-selector.md": "564669d479433f15", "agents/gsd-integration-checker.md": "1bbbdd3d420b994e", "agents/gsd-intel-updater.md": "42c40fffbc720d0b", @@ -58,7 +58,7 @@ "gsd-core/references/api-coverage.md": "66264d41dfd9154a", "gsd-core/references/artifact-types.md": "a6d2e1f9453ffbf5", "gsd-core/references/autonomous-smart-discuss.md": "2fc710cde0ec7785", - "gsd-core/references/checkpoints.md": "9a7ba3a17ece1698", + "gsd-core/references/checkpoints.md": "4919e8aa1130fb04", "gsd-core/references/common-bug-patterns.md": "780145be56352626", "gsd-core/references/context-budget.md": "c154ba00dbbf4477", "gsd-core/references/continuation-format.md": "ce73e57d053ab8a7", @@ -236,7 +236,7 @@ "gsd-core/workflows/docs-update.md": "39f288623a8f6f32", "gsd-core/workflows/edit-phase.md": "9c9fadc047c61d74", "gsd-core/workflows/eval-review.md": "3e1d7829ed2ed494", - "gsd-core/workflows/execute-phase.md": "ae12e044fb2f3b57", + "gsd-core/workflows/execute-phase.md": "0d9ff2faecb72225", "gsd-core/workflows/execute-phase/steps/codebase-drift-gate.md": "67ebc93f51968cb6", "gsd-core/workflows/execute-phase/steps/per-plan-worktree-gate.md": "7ebb7d1af6082028", "gsd-core/workflows/execute-phase/steps/post-merge-gate.md": "82e6cfe1e1b1ec0e", diff --git a/tests/fixtures/golden-install-parity/codebuddy.json b/tests/fixtures/golden-install-parity/codebuddy.json index 7468c5bbf..4c2dfb970 100644 --- a/tests/fixtures/golden-install-parity/codebuddy.json +++ b/tests/fixtures/golden-install-parity/codebuddy.json @@ -16,7 +16,7 @@ "agents/gsd-domain-researcher.md": "1c1a800108a2b225", "agents/gsd-eval-auditor.md": "99012004b14ea602", "agents/gsd-eval-planner.md": "4ebdd7fe9cbb0cfe", - "agents/gsd-executor.md": "d0bfc88c01a63181", + "agents/gsd-executor.md": "d61e084540bb6ee2", "agents/gsd-framework-selector.md": "7726fccc86bfeb50", "agents/gsd-integration-checker.md": "2d8339790bbb2dc3", "agents/gsd-intel-updater.md": "c51339956197cbd3", @@ -126,7 +126,7 @@ "gsd-core/references/api-coverage.md": "66264d41dfd9154a", "gsd-core/references/artifact-types.md": "a6d2e1f9453ffbf5", "gsd-core/references/autonomous-smart-discuss.md": "2fc710cde0ec7785", - "gsd-core/references/checkpoints.md": "6aa620c6ca38bdf0", + "gsd-core/references/checkpoints.md": "b1530628d693fc85", "gsd-core/references/common-bug-patterns.md": "780145be56352626", "gsd-core/references/context-budget.md": "f1ce57bf418824af", "gsd-core/references/continuation-format.md": "ce73e57d053ab8a7", @@ -304,7 +304,7 @@ "gsd-core/workflows/docs-update.md": "f35922d15b7061c9", "gsd-core/workflows/edit-phase.md": "966a3eadd1bebc04", "gsd-core/workflows/eval-review.md": "f898936e2cfe4130", - "gsd-core/workflows/execute-phase.md": "cf72b6db051f9189", + "gsd-core/workflows/execute-phase.md": "f17719f6b780cd2b", "gsd-core/workflows/execute-phase/steps/codebase-drift-gate.md": "4e265392b3f2ba0e", "gsd-core/workflows/execute-phase/steps/per-plan-worktree-gate.md": "7ebb7d1af6082028", "gsd-core/workflows/execute-phase/steps/post-merge-gate.md": "811b6d8489571581", diff --git a/tests/fixtures/golden-install-parity/codex.json b/tests/fixtures/golden-install-parity/codex.json index 1ddaf96c1..cc6bbab50 100644 --- a/tests/fixtures/golden-install-parity/codex.json +++ b/tests/fixtures/golden-install-parity/codex.json @@ -102,8 +102,8 @@ "agents/gsd-eval-auditor.toml": "9b81d61b3c5f722d", "agents/gsd-eval-planner.md": "73f2ad2ff2797a51", "agents/gsd-eval-planner.toml": "09468ad1a34ac468", - "agents/gsd-executor.md": "93a05c1436bc4458", - "agents/gsd-executor.toml": "f5a55d4eacd8613c", + "agents/gsd-executor.md": "0393e5f72e932127", + "agents/gsd-executor.toml": "cdb7bdc04d3b6651", "agents/gsd-framework-selector.md": "ebae32430887d2e0", "agents/gsd-framework-selector.toml": "637e4e021b7ec380", "agents/gsd-integration-checker.md": "9cc875676cf7d741", @@ -161,7 +161,7 @@ "gsd-core/references/api-coverage.md": "524382216a8e713f", "gsd-core/references/artifact-types.md": "3218cafb0c92dc32", "gsd-core/references/autonomous-smart-discuss.md": "4156025334411073", - "gsd-core/references/checkpoints.md": "9feb961f644afa96", + "gsd-core/references/checkpoints.md": "afc6933d99f73358", "gsd-core/references/common-bug-patterns.md": "780145be56352626", "gsd-core/references/context-budget.md": "0b67ea1d5db4bc08", "gsd-core/references/continuation-format.md": "e64c0da2b3d0f2f0", @@ -339,7 +339,7 @@ "gsd-core/workflows/docs-update.md": "e255317df939e302", "gsd-core/workflows/edit-phase.md": "e592a4d85ce5380f", "gsd-core/workflows/eval-review.md": "63d0d0670b54c244", - "gsd-core/workflows/execute-phase.md": "e62b664cf4db4d55", + "gsd-core/workflows/execute-phase.md": "b15bbe2f8a8d8d02", "gsd-core/workflows/execute-phase/steps/codebase-drift-gate.md": "f4cacd27d37bac65", "gsd-core/workflows/execute-phase/steps/per-plan-worktree-gate.md": "7ebb7d1af6082028", "gsd-core/workflows/execute-phase/steps/post-merge-gate.md": "811b6d8489571581", diff --git a/tests/fixtures/golden-install-parity/copilot.json b/tests/fixtures/golden-install-parity/copilot.json index 2aab090d5..a39d2d9ae 100644 --- a/tests/fixtures/golden-install-parity/copilot.json +++ b/tests/fixtures/golden-install-parity/copilot.json @@ -16,7 +16,7 @@ "agents/gsd-domain-researcher.agent.md": "d603239b3e9fe428", "agents/gsd-eval-auditor.agent.md": "3c03009564de55c8", "agents/gsd-eval-planner.agent.md": "14751876fc2b5f16", - "agents/gsd-executor.agent.md": "0058082fef5a4985", + "agents/gsd-executor.agent.md": "2ee1020062d8d800", "agents/gsd-framework-selector.agent.md": "cafeec0b3489be45", "agents/gsd-integration-checker.agent.md": "30439b804927acc7", "agents/gsd-intel-updater.agent.md": "238c1a886f35a25c", @@ -56,7 +56,7 @@ "gsd-core/references/api-coverage.md": "205a43c5fa7c221c", "gsd-core/references/artifact-types.md": "f992de8b2b1a4420", "gsd-core/references/autonomous-smart-discuss.md": "efd80aca449032ad", - "gsd-core/references/checkpoints.md": "c70b323dcb1583d5", + "gsd-core/references/checkpoints.md": "53ca1c205dda8b65", "gsd-core/references/common-bug-patterns.md": "780145be56352626", "gsd-core/references/context-budget.md": "435474d5e10be65a", "gsd-core/references/continuation-format.md": "580287399ad3ba68", @@ -234,7 +234,7 @@ "gsd-core/workflows/docs-update.md": "9292cfa3c52c434e", "gsd-core/workflows/edit-phase.md": "8667c28b22b1599f", "gsd-core/workflows/eval-review.md": "81c8e72ba3862856", - "gsd-core/workflows/execute-phase.md": "6f7aa92705d3527e", + "gsd-core/workflows/execute-phase.md": "80a1e0722f72dbb1", "gsd-core/workflows/execute-phase/steps/codebase-drift-gate.md": "63b712920f21a40f", "gsd-core/workflows/execute-phase/steps/per-plan-worktree-gate.md": "7ebb7d1af6082028", "gsd-core/workflows/execute-phase/steps/post-merge-gate.md": "1b73ab2fc47c9dbf", diff --git a/tests/fixtures/golden-install-parity/cursor.json b/tests/fixtures/golden-install-parity/cursor.json index 41ddd34a1..a6afd63ea 100644 --- a/tests/fixtures/golden-install-parity/cursor.json +++ b/tests/fixtures/golden-install-parity/cursor.json @@ -16,7 +16,7 @@ "agents/gsd-domain-researcher.md": "56395dbdabf076f6", "agents/gsd-eval-auditor.md": "ad2840fd5cd76172", "agents/gsd-eval-planner.md": "2049dac060d00eda", - "agents/gsd-executor.md": "1fb2c778178cfa1c", + "agents/gsd-executor.md": "e416f9c48fb44c75", "agents/gsd-framework-selector.md": "4b77eebbe9288d80", "agents/gsd-integration-checker.md": "5da30584d06b878c", "agents/gsd-intel-updater.md": "b8971c5d96e63b38", @@ -126,7 +126,7 @@ "gsd-core/references/api-coverage.md": "205a43c5fa7c221c", "gsd-core/references/artifact-types.md": "8bd01fd75a2ba70e", "gsd-core/references/autonomous-smart-discuss.md": "273b371c5751f35a", - "gsd-core/references/checkpoints.md": "3001eeccb319781b", + "gsd-core/references/checkpoints.md": "f852c96c5fe25015", "gsd-core/references/common-bug-patterns.md": "780145be56352626", "gsd-core/references/context-budget.md": "304dcdab82a27623", "gsd-core/references/continuation-format.md": "580287399ad3ba68", @@ -304,7 +304,7 @@ "gsd-core/workflows/docs-update.md": "e86d7d7e2e3dac6d", "gsd-core/workflows/edit-phase.md": "8323bfe10faa0c0a", "gsd-core/workflows/eval-review.md": "a86279dd98dd5c03", - "gsd-core/workflows/execute-phase.md": "cf1b15f505b519d8", + "gsd-core/workflows/execute-phase.md": "b3267f23af6444b2", "gsd-core/workflows/execute-phase/steps/codebase-drift-gate.md": "facb0e816d87a0c7", "gsd-core/workflows/execute-phase/steps/per-plan-worktree-gate.md": "7ebb7d1af6082028", "gsd-core/workflows/execute-phase/steps/post-merge-gate.md": "811b6d8489571581", diff --git a/tests/fixtures/golden-install-parity/hermes.json b/tests/fixtures/golden-install-parity/hermes.json index fe439f057..a3b083743 100644 --- a/tests/fixtures/golden-install-parity/hermes.json +++ b/tests/fixtures/golden-install-parity/hermes.json @@ -16,7 +16,7 @@ "agents/gsd-domain-researcher.md": "412cdbb05ba252ea", "agents/gsd-eval-auditor.md": "4ffb265063c318e5", "agents/gsd-eval-planner.md": "03448fc9c5774b56", - "agents/gsd-executor.md": "18365948be7c2dff", + "agents/gsd-executor.md": "9c00261ee92596bb", "agents/gsd-framework-selector.md": "ea9981d65d6b3429", "agents/gsd-integration-checker.md": "35b4f2969d279871", "agents/gsd-intel-updater.md": "5fe5edfae2719cb8", @@ -55,7 +55,7 @@ "gsd-core/references/api-coverage.md": "205a43c5fa7c221c", "gsd-core/references/artifact-types.md": "8bd01fd75a2ba70e", "gsd-core/references/autonomous-smart-discuss.md": "2fc710cde0ec7785", - "gsd-core/references/checkpoints.md": "db8a7425ed808e24", + "gsd-core/references/checkpoints.md": "36b2de4768b228af", "gsd-core/references/common-bug-patterns.md": "780145be56352626", "gsd-core/references/context-budget.md": "b93e9f47aa1b1753", "gsd-core/references/continuation-format.md": "580287399ad3ba68", @@ -233,7 +233,7 @@ "gsd-core/workflows/docs-update.md": "4d6c06e611d83b6d", "gsd-core/workflows/edit-phase.md": "7f27003f20e88fb8", "gsd-core/workflows/eval-review.md": "f510e5762212dc6f", - "gsd-core/workflows/execute-phase.md": "f36c7b810285838c", + "gsd-core/workflows/execute-phase.md": "371ab0a4dae7a049", "gsd-core/workflows/execute-phase/steps/codebase-drift-gate.md": "ceb8758c22660c1a", "gsd-core/workflows/execute-phase/steps/per-plan-worktree-gate.md": "7ebb7d1af6082028", "gsd-core/workflows/execute-phase/steps/post-merge-gate.md": "c9ad17d6cc6dfe45", diff --git a/tests/fixtures/golden-install-parity/kilo.json b/tests/fixtures/golden-install-parity/kilo.json index 8f387eb90..017d2705c 100644 --- a/tests/fixtures/golden-install-parity/kilo.json +++ b/tests/fixtures/golden-install-parity/kilo.json @@ -16,7 +16,7 @@ "agents/gsd-domain-researcher.md": "a3874d80bcbc7380", "agents/gsd-eval-auditor.md": "630d4cd3bd6ea195", "agents/gsd-eval-planner.md": "3db12cde12aeb2c1", - "agents/gsd-executor.md": "c9aca9129bd4cab3", + "agents/gsd-executor.md": "24a1c8c8e829d2d1", "agents/gsd-framework-selector.md": "ad5f2c6b9bec6270", "agents/gsd-integration-checker.md": "c503e2f4a3d8ec05", "agents/gsd-intel-updater.md": "231393da62a45b2e", @@ -126,7 +126,7 @@ "gsd-core/references/api-coverage.md": "205a43c5fa7c221c", "gsd-core/references/artifact-types.md": "8bd01fd75a2ba70e", "gsd-core/references/autonomous-smart-discuss.md": "3986d58011bf9006", - "gsd-core/references/checkpoints.md": "9feb961f644afa96", + "gsd-core/references/checkpoints.md": "afc6933d99f73358", "gsd-core/references/common-bug-patterns.md": "780145be56352626", "gsd-core/references/context-budget.md": "533eae480bfc4bb8", "gsd-core/references/continuation-format.md": "580287399ad3ba68", @@ -304,7 +304,7 @@ "gsd-core/workflows/docs-update.md": "79afaaf19fd527cc", "gsd-core/workflows/edit-phase.md": "8323bfe10faa0c0a", "gsd-core/workflows/eval-review.md": "926eda8bbee28b23", - "gsd-core/workflows/execute-phase.md": "ec448a1e25854abf", + "gsd-core/workflows/execute-phase.md": "43c8c218f8933cc8", "gsd-core/workflows/execute-phase/steps/codebase-drift-gate.md": "facb0e816d87a0c7", "gsd-core/workflows/execute-phase/steps/per-plan-worktree-gate.md": "7ebb7d1af6082028", "gsd-core/workflows/execute-phase/steps/post-merge-gate.md": "811b6d8489571581", diff --git a/tests/fixtures/golden-install-parity/kimi.json b/tests/fixtures/golden-install-parity/kimi.json index 5da5f0f58..0a0c46cfc 100644 --- a/tests/fixtures/golden-install-parity/kimi.json +++ b/tests/fixtures/golden-install-parity/kimi.json @@ -61,7 +61,7 @@ "agents/subagents/gsd-eval-auditor.yaml": "e3d868bd5fefe938", "agents/subagents/gsd-eval-planner.md": "70f8c5727bfb9876", "agents/subagents/gsd-eval-planner.yaml": "df8499f7af297ec2", - "agents/subagents/gsd-executor.md": "278a569a7306244c", + "agents/subagents/gsd-executor.md": "d3b2806c227c6a27", "agents/subagents/gsd-executor.yaml": "e29422986636fd64", "agents/subagents/gsd-framework-selector.md": "a15b7aa1e0576e16", "agents/subagents/gsd-framework-selector.yaml": "fb52c31cde27b0e3", @@ -119,7 +119,7 @@ "gsd-core/references/api-coverage.md": "66264d41dfd9154a", "gsd-core/references/artifact-types.md": "a6d2e1f9453ffbf5", "gsd-core/references/autonomous-smart-discuss.md": "2fc710cde0ec7785", - "gsd-core/references/checkpoints.md": "6aa620c6ca38bdf0", + "gsd-core/references/checkpoints.md": "b1530628d693fc85", "gsd-core/references/common-bug-patterns.md": "780145be56352626", "gsd-core/references/context-budget.md": "f1ce57bf418824af", "gsd-core/references/continuation-format.md": "ce73e57d053ab8a7", @@ -297,7 +297,7 @@ "gsd-core/workflows/docs-update.md": "f35922d15b7061c9", "gsd-core/workflows/edit-phase.md": "966a3eadd1bebc04", "gsd-core/workflows/eval-review.md": "f898936e2cfe4130", - "gsd-core/workflows/execute-phase.md": "91fe17be2d178f24", + "gsd-core/workflows/execute-phase.md": "39def0423fb4eb45", "gsd-core/workflows/execute-phase/steps/codebase-drift-gate.md": "4e265392b3f2ba0e", "gsd-core/workflows/execute-phase/steps/per-plan-worktree-gate.md": "7ebb7d1af6082028", "gsd-core/workflows/execute-phase/steps/post-merge-gate.md": "811b6d8489571581", diff --git a/tests/fixtures/golden-install-parity/opencode.json b/tests/fixtures/golden-install-parity/opencode.json index aa6842369..5bae80a00 100644 --- a/tests/fixtures/golden-install-parity/opencode.json +++ b/tests/fixtures/golden-install-parity/opencode.json @@ -16,7 +16,7 @@ "agents/gsd-domain-researcher.md": "71250e759ca9e723", "agents/gsd-eval-auditor.md": "c88890105f32ace6", "agents/gsd-eval-planner.md": "60bddb70a937f796", - "agents/gsd-executor.md": "b091b0126895ae03", + "agents/gsd-executor.md": "cad2c28464d535df", "agents/gsd-framework-selector.md": "1c0a10355e787675", "agents/gsd-integration-checker.md": "a9de5928e5a5c649", "agents/gsd-intel-updater.md": "493e07482fa6198a", @@ -126,7 +126,7 @@ "gsd-core/references/api-coverage.md": "205a43c5fa7c221c", "gsd-core/references/artifact-types.md": "218c55caf8aff6df", "gsd-core/references/autonomous-smart-discuss.md": "3986d58011bf9006", - "gsd-core/references/checkpoints.md": "9feb961f644afa96", + "gsd-core/references/checkpoints.md": "afc6933d99f73358", "gsd-core/references/common-bug-patterns.md": "780145be56352626", "gsd-core/references/context-budget.md": "355826e667f9ccd1", "gsd-core/references/continuation-format.md": "580287399ad3ba68", @@ -304,7 +304,7 @@ "gsd-core/workflows/docs-update.md": "850366c2ef8fb780", "gsd-core/workflows/edit-phase.md": "1876c855fb0a0a39", "gsd-core/workflows/eval-review.md": "5394694d29ad7543", - "gsd-core/workflows/execute-phase.md": "9026c312d564381f", + "gsd-core/workflows/execute-phase.md": "2a1c33e0bda26211", "gsd-core/workflows/execute-phase/steps/codebase-drift-gate.md": "1804215577f1ad35", "gsd-core/workflows/execute-phase/steps/per-plan-worktree-gate.md": "7ebb7d1af6082028", "gsd-core/workflows/execute-phase/steps/post-merge-gate.md": "baa2c401af10a80a", diff --git a/tests/fixtures/golden-install-parity/pi.json b/tests/fixtures/golden-install-parity/pi.json index 2cd30cb92..753308586 100644 --- a/tests/fixtures/golden-install-parity/pi.json +++ b/tests/fixtures/golden-install-parity/pi.json @@ -22,7 +22,7 @@ "gsd-core/references/api-coverage.md": "66264d41dfd9154a", "gsd-core/references/artifact-types.md": "a6d2e1f9453ffbf5", "gsd-core/references/autonomous-smart-discuss.md": "2fc710cde0ec7785", - "gsd-core/references/checkpoints.md": "6aa620c6ca38bdf0", + "gsd-core/references/checkpoints.md": "b1530628d693fc85", "gsd-core/references/common-bug-patterns.md": "780145be56352626", "gsd-core/references/context-budget.md": "f1ce57bf418824af", "gsd-core/references/continuation-format.md": "ce73e57d053ab8a7", @@ -200,7 +200,7 @@ "gsd-core/workflows/docs-update.md": "f35922d15b7061c9", "gsd-core/workflows/edit-phase.md": "966a3eadd1bebc04", "gsd-core/workflows/eval-review.md": "f898936e2cfe4130", - "gsd-core/workflows/execute-phase.md": "8f6c2443655aceb1", + "gsd-core/workflows/execute-phase.md": "8f6dc95cc8030259", "gsd-core/workflows/execute-phase/steps/codebase-drift-gate.md": "4e265392b3f2ba0e", "gsd-core/workflows/execute-phase/steps/per-plan-worktree-gate.md": "7ebb7d1af6082028", "gsd-core/workflows/execute-phase/steps/post-merge-gate.md": "811b6d8489571581", diff --git a/tests/fixtures/golden-install-parity/qwen.json b/tests/fixtures/golden-install-parity/qwen.json index ccd12a98c..b26a125e8 100644 --- a/tests/fixtures/golden-install-parity/qwen.json +++ b/tests/fixtures/golden-install-parity/qwen.json @@ -16,7 +16,7 @@ "agents/gsd-domain-researcher.md": "bd054bb27beed2a7", "agents/gsd-eval-auditor.md": "57cc7458ab5de6b7", "agents/gsd-eval-planner.md": "01b665728dde4ccf", - "agents/gsd-executor.md": "b50d53e45df6431c", + "agents/gsd-executor.md": "72c02583b569a25f", "agents/gsd-framework-selector.md": "82ba6abea84226b7", "agents/gsd-integration-checker.md": "90835dbc7dfa1691", "agents/gsd-intel-updater.md": "3cc4f6ddd04676ec", @@ -55,7 +55,7 @@ "gsd-core/references/api-coverage.md": "205a43c5fa7c221c", "gsd-core/references/artifact-types.md": "8bd01fd75a2ba70e", "gsd-core/references/autonomous-smart-discuss.md": "2fc710cde0ec7785", - "gsd-core/references/checkpoints.md": "046171320f816346", + "gsd-core/references/checkpoints.md": "83c7ac100419e9e0", "gsd-core/references/common-bug-patterns.md": "780145be56352626", "gsd-core/references/context-budget.md": "a1351dd40ef8691f", "gsd-core/references/continuation-format.md": "580287399ad3ba68", @@ -233,7 +233,7 @@ "gsd-core/workflows/docs-update.md": "45d2f0d173c84e07", "gsd-core/workflows/edit-phase.md": "0fb5e0123cfc6f36", "gsd-core/workflows/eval-review.md": "6dee8a1e40ececd4", - "gsd-core/workflows/execute-phase.md": "60deeb0a791c3cd5", + "gsd-core/workflows/execute-phase.md": "b6d1f7dbc3c81a4f", "gsd-core/workflows/execute-phase/steps/codebase-drift-gate.md": "36af8d91e4ae8b9c", "gsd-core/workflows/execute-phase/steps/per-plan-worktree-gate.md": "7ebb7d1af6082028", "gsd-core/workflows/execute-phase/steps/post-merge-gate.md": "98db1ba4c39cd784", diff --git a/tests/fixtures/golden-install-parity/trae.json b/tests/fixtures/golden-install-parity/trae.json index 25b84997c..ec33c7022 100644 --- a/tests/fixtures/golden-install-parity/trae.json +++ b/tests/fixtures/golden-install-parity/trae.json @@ -16,7 +16,7 @@ "agents/gsd-domain-researcher.md": "b80f76874c04e515", "agents/gsd-eval-auditor.md": "470bf16303ec4d2e", "agents/gsd-eval-planner.md": "22334fde85723c9d", - "agents/gsd-executor.md": "45eeb443a6e6dbe8", + "agents/gsd-executor.md": "e5b96a52bd3c96c8", "agents/gsd-framework-selector.md": "7726fccc86bfeb50", "agents/gsd-integration-checker.md": "7cd2072984411c7f", "agents/gsd-intel-updater.md": "83de6ba9172891c3", @@ -55,7 +55,7 @@ "gsd-core/references/api-coverage.md": "205a43c5fa7c221c", "gsd-core/references/artifact-types.md": "8bd01fd75a2ba70e", "gsd-core/references/autonomous-smart-discuss.md": "2fc710cde0ec7785", - "gsd-core/references/checkpoints.md": "4b8c645ffa695067", + "gsd-core/references/checkpoints.md": "610690dba4d600c1", "gsd-core/references/common-bug-patterns.md": "780145be56352626", "gsd-core/references/context-budget.md": "b7e9640063775c98", "gsd-core/references/continuation-format.md": "580287399ad3ba68", @@ -233,7 +233,7 @@ "gsd-core/workflows/docs-update.md": "f13571f08e083356", "gsd-core/workflows/edit-phase.md": "7facd0faa33c8cad", "gsd-core/workflows/eval-review.md": "37d545d4f0db4927", - "gsd-core/workflows/execute-phase.md": "aa5abb8c77a00153", + "gsd-core/workflows/execute-phase.md": "80ffe75fda2a90ba", "gsd-core/workflows/execute-phase/steps/codebase-drift-gate.md": "c985a30317a1aa6b", "gsd-core/workflows/execute-phase/steps/per-plan-worktree-gate.md": "7ebb7d1af6082028", "gsd-core/workflows/execute-phase/steps/post-merge-gate.md": "0a9e915170c7121c", diff --git a/tests/fixtures/golden-install-parity/windsurf.json b/tests/fixtures/golden-install-parity/windsurf.json index 48e41a345..92066bebf 100644 --- a/tests/fixtures/golden-install-parity/windsurf.json +++ b/tests/fixtures/golden-install-parity/windsurf.json @@ -16,7 +16,7 @@ "agents/gsd-domain-researcher.md": "56395dbdabf076f6", "agents/gsd-eval-auditor.md": "fb64fc5acf359747", "agents/gsd-eval-planner.md": "2049dac060d00eda", - "agents/gsd-executor.md": "406fdcc0597bea77", + "agents/gsd-executor.md": "1eb9f58c5e9da94d", "agents/gsd-framework-selector.md": "4b77eebbe9288d80", "agents/gsd-integration-checker.md": "4ffb37fb230c2b90", "agents/gsd-intel-updater.md": "a81d77c143c02108", @@ -55,7 +55,7 @@ "gsd-core/references/api-coverage.md": "205a43c5fa7c221c", "gsd-core/references/artifact-types.md": "8bd01fd75a2ba70e", "gsd-core/references/autonomous-smart-discuss.md": "273b371c5751f35a", - "gsd-core/references/checkpoints.md": "808e4fcaa2fda15c", + "gsd-core/references/checkpoints.md": "de9f3b7bd86a44ac", "gsd-core/references/common-bug-patterns.md": "780145be56352626", "gsd-core/references/context-budget.md": "ff843cd6139c8564", "gsd-core/references/continuation-format.md": "580287399ad3ba68", @@ -233,7 +233,7 @@ "gsd-core/workflows/docs-update.md": "70f73cc8c27e0ca0", "gsd-core/workflows/edit-phase.md": "c0ae7d0063f3e789", "gsd-core/workflows/eval-review.md": "b28be79ef29f16fd", - "gsd-core/workflows/execute-phase.md": "1dac1bdda0696dc0", + "gsd-core/workflows/execute-phase.md": "d6bf589fb0370bc7", "gsd-core/workflows/execute-phase/steps/codebase-drift-gate.md": "47ae5482f8e64100", "gsd-core/workflows/execute-phase/steps/per-plan-worktree-gate.md": "7ebb7d1af6082028", "gsd-core/workflows/execute-phase/steps/post-merge-gate.md": "15bca39a75c664be", diff --git a/tests/fixtures/golden-install-parity/zcode.json b/tests/fixtures/golden-install-parity/zcode.json index 790d628ad..935b04b5f 100644 --- a/tests/fixtures/golden-install-parity/zcode.json +++ b/tests/fixtures/golden-install-parity/zcode.json @@ -16,7 +16,7 @@ "agents/gsd-domain-researcher.md": "049f588663814fa2", "agents/gsd-eval-auditor.md": "54870d3b07433525", "agents/gsd-eval-planner.md": "552e9fa164c51ce8", - "agents/gsd-executor.md": "7bc50a045cb23811", + "agents/gsd-executor.md": "fdd9635cee849c82", "agents/gsd-framework-selector.md": "8a795f230436ad2e", "agents/gsd-integration-checker.md": "c1760a0bbd4f7bf5", "agents/gsd-intel-updater.md": "944f1d903e2e9e09", @@ -126,7 +126,7 @@ "gsd-core/references/api-coverage.md": "66264d41dfd9154a", "gsd-core/references/artifact-types.md": "a6d2e1f9453ffbf5", "gsd-core/references/autonomous-smart-discuss.md": "2fc710cde0ec7785", - "gsd-core/references/checkpoints.md": "6aa620c6ca38bdf0", + "gsd-core/references/checkpoints.md": "b1530628d693fc85", "gsd-core/references/common-bug-patterns.md": "780145be56352626", "gsd-core/references/context-budget.md": "f1ce57bf418824af", "gsd-core/references/continuation-format.md": "ce73e57d053ab8a7", @@ -304,7 +304,7 @@ "gsd-core/workflows/docs-update.md": "f35922d15b7061c9", "gsd-core/workflows/edit-phase.md": "966a3eadd1bebc04", "gsd-core/workflows/eval-review.md": "f898936e2cfe4130", - "gsd-core/workflows/execute-phase.md": "bb4f1120804c5a90", + "gsd-core/workflows/execute-phase.md": "55c0e6f659e27ff2", "gsd-core/workflows/execute-phase/steps/codebase-drift-gate.md": "4e265392b3f2ba0e", "gsd-core/workflows/execute-phase/steps/per-plan-worktree-gate.md": "7ebb7d1af6082028", "gsd-core/workflows/execute-phase/steps/post-merge-gate.md": "811b6d8489571581", diff --git a/tests/package-legitimacy-gate.test.cjs b/tests/package-legitimacy-gate.test.cjs index 5d0a3e051..858363d4b 100644 --- a/tests/package-legitimacy-gate.test.cjs +++ b/tests/package-legitimacy-gate.test.cjs @@ -5,6 +5,12 @@ * * Verifies that the three agents (researcher, planner, executor) contain the * interlocking instruction text that forms the slopsquatting defence gate. + * + * The gate spans TWO layers. The executor stops at a `gate="blocking-human"` + * checkpoint and hands it up; the execute-phase orchestrator then decides + * whether the human ever sees it. Asserting only the executor half leaves the + * orchestrator free to auto-approve the checkpoint the executor just refused + * to auto-approve. */ const { describe, test, before } = require('node:test'); @@ -17,6 +23,9 @@ const RESEARCHER = path.join(AGENTS, 'gsd-phase-researcher.md'); const PLANNER = path.join(AGENTS, 'gsd-planner.md'); const EXECUTOR = path.join(AGENTS, 'gsd-executor.md'); +const WORKFLOWS = path.join(__dirname, '..', 'gsd-core', 'workflows'); +const EXECUTE_PHASE = path.join(WORKFLOWS, 'execute-phase.md'); + function parseSections(md) { const lines = md.split(/\r?\n/); const sections = []; @@ -475,4 +484,134 @@ describe('gsd-executor.md — package installs excluded from RULE 3 auto-fix', ( 'executor auto mode must explicitly block auto-approval for package-legitimacy checkpoints' ); }); + + // #2107 harm, one checkpoint type over: the executor auto-resolves a decision + // checkpoint itself (auto-selects the first option and continues) without ever + // returning it, so a blocking-human decision must be carved out HERE — the + // orchestrator's carve-out never runs for a checkpoint the executor swallowed. + test('auto mode does not auto-select a blocking-human decision checkpoint', () => { + const autoModeLine = lineIndexes(model.lines, (line) => hasAllTokens(line, ['auto-mode', 'checkpoint', 'behavior']))[0]; + assert.notEqual(autoModeLine, undefined, 'executor must define auto-mode checkpoint behavior'); + + const window = model.lines.slice(autoModeLine, autoModeLine + 25); + + const decisionLines = window.filter((line) => hasAllTokens(line, ['checkpoint:decision'])); + assert.ok(decisionLines.length > 0, 'executor auto-mode must document the checkpoint:decision branch'); + + const gatesDecision = decisionLines.some( + (line) => + hasAllTokens(line, ['blocking-human']) && + (hasAllTokens(line, ['stop']) || hasAllTokens(line, ['not', 'auto-select'])) + ); + + assert.ok( + gatesDecision, + 'checkpoint:decision must carve out gate="blocking-human" (STOP + return) instead of auto-selecting the first option' + ); + }); + + test('checkpoint_return_format transports the gate across the executor→orchestrator boundary', () => { + const fmt = extractXmlElement(model.text, 'checkpoint_return_format'); + assert.ok(fmt.length > 0, 'executor must define checkpoint_return_format'); + + const fmtLines = fmt.split(/\r?\n/); + const hasGateField = fmtLines.some((line) => hasAllTokens(line, ['gate:', 'blocking-human'])); + + assert.ok( + hasGateField, + 'checkpoint_return_format must carry a **Gate:** field so blocking-human reaches the orchestrator carve-out' + ); + }); +}); + +describe('execute-phase.md — orchestrator honors the blocking-human gate', () => { + let model; + + before(() => { + model = readModel(EXECUTE_PHASE); + }); + + // The executor refuses to auto-approve a gate="blocking-human" checkpoint and + // returns it via checkpoint_return_format. The orchestrator's auto-mode branch + // is what runs next. If that branch dispatches purely on checkpoint *type*, it + // auto-approves the checkpoint the executor just escalated — nullifying the + // slopsquatting gate in exactly the unattended mode where it matters. + test('auto-mode checkpoint handling excludes blocking-human checkpoints', () => { + // NB: normalizeTokens keeps ':' as a word character, so the heading + // "**Auto-mode checkpoint handling:**" yields the token `handling:`, not + // `handling`. Anchor on the two tokens that survive intact. + const autoModeLine = lineIndexes(model.lines, (line) => + hasAllTokens(line, ['auto-mode', 'checkpoint']) + )[0]; + + assert.notEqual( + autoModeLine, + undefined, + 'execute-phase.md must define auto-mode checkpoint handling' + ); + + const window = model.lines.slice(autoModeLine, autoModeLine + 20); + + const honorsGate = + anyLineHasAll(window, ['blocking-human']) || + anyLineHasAll(window, ['except', 'package-legitimacy']); + + assert.ok( + honorsGate, + 'execute-phase auto-mode must not auto-approve gate="blocking-human" checkpoints — ' + + 'the executor escalates them precisely so a human sees them' + ); + }); + + test('auto-approve rule for human-verify is conditional, not unconditional', () => { + const autoApproveLines = lineIndexes(model.lines, (line) => + hasAllTokens(line, ['human-verify', 'auto-spawn', 'approved']) + ); + + assert.ok( + autoApproveLines.length > 0, + 'anchor drift: no human-verify auto-approve line matched — the conditional carve-out would pass vacuously' + ); + + for (const idx of autoApproveLines) { + const line = model.lines[idx]; + const isConditional = + hasAllTokens(line, ['unless']) || + hasAllTokens(line, ['except']) || + hasAllTokens(line, ['blocking-human']) || + hasAllTokens(line, ['if', 'not']); + + assert.ok( + isConditional, + `execute-phase.md:${idx + 1} auto-approves human-verify unconditionally; ` + + 'it must carve out gate="blocking-human"' + ); + } + }); + + test('auto-select rule for decision is conditional, not unconditional', () => { + const autoSelectLines = lineIndexes(model.lines, (line) => + hasAllTokens(line, ['decision', 'auto-spawn', 'first', 'option']) + ); + + assert.ok( + autoSelectLines.length > 0, + 'anchor drift: no decision auto-select line matched — the conditional carve-out would pass vacuously' + ); + + for (const idx of autoSelectLines) { + const line = model.lines[idx]; + const isConditional = + hasAllTokens(line, ['unless']) || + hasAllTokens(line, ['except']) || + hasAllTokens(line, ['blocking-human']) || + hasAllTokens(line, ['if', 'not']); + + assert.ok( + isConditional, + `execute-phase.md:${idx + 1} auto-selects a decision unconditionally; ` + + 'it must carve out gate="blocking-human"' + ); + } + }); }); diff --git a/tests/workflow-size-baseline.json b/tests/workflow-size-baseline.json index b91272241..4446e82b6 100644 --- a/tests/workflow-size-baseline.json +++ b/tests/workflow-size-baseline.json @@ -24,7 +24,7 @@ "docs-update.md": 55706, "edit-phase.md": 12927, "eval-review.md": 9967, - "execute-phase.md": 93132, + "execute-phase.md": 93583, "execute-plan.md": 32655, "explore.md": 10541, "extract-learnings.md": 12893,