test(#1168): make phase-6 conformance gate fail on real incompleteness

The phase-6 capstone gate (#1139/#1158) passed green while ADR-857's acceptance criteria were unmet — a false green that let phase 6 read as complete. Drop the paper-over (the call-site allowlist) and assert the real criteria with no exemptions, so green means 'phase 6 conformant', not 'no new regression'.

RED by design until the work lands: (1) every declared hook point must have a render-hooks call site → execute:wave:post (ui_safety_gate) is dead; (2) every ADR-857-named optional feature must be a Capability → tdd/schema-gate/drift/gap-analysis/profile-pipeline un-migrated; (3) the host loop must read no capability-owned config key inline → intel.enabled/security_asvs_level/security_block_on leak in plan-phase.md.

Refs #1139, #1168, #1169.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
Tom Boucher
2026-06-13 11:01:39 -04:00
parent 70f35ebc7a
commit 8b037fe1e3

View File

@@ -106,12 +106,17 @@ describe('ADR-857 Phase 6 capstone conformance (#1139)', () => {
}
});
test('every declared capability hook point has a render-hooks call site in the host loop (#1169)', () => {
// Points whose host call site is intentionally not yet wired, mapped to the
// issue tracking the gap. execute:wave:post (ui.gates / ui_safety_gate) also
// needs its `ui.safety-gate` check implemented before it can be wired — #1169.
const KNOWN_UNWIRED = { 'execute:wave:post': '#1169' };
// ─── Phase-6 conformance: RED BY DESIGN until phase 6 is actually complete ──────
//
// #1139 closed (via #1158) with a green "capstone conformance gate" while the
// ADR-857 phase-6 acceptance criteria were unmet — a false green. The three
// tests below assert the real criteria with NO paper-over allowlist, so the
// gate stays RED until the work lands. Green here must mean "phase 6 conformant,"
// not "no new regression." Fixes tracked in #1167 / #1168 / #1169.
test('every declared capability hook point has a render-hooks call site in the host loop (#1168)', () => {
// No allowlist: every point a capability declares a hook at MUST have a
// `render-hooks` call site in the host loop, or those hooks can never fire.
const declaredPoints = new Set();
for (const cap of Object.values(registry.capabilities)) {
for (const group of ['steps', 'gates', 'contributions']) {
@@ -121,8 +126,8 @@ describe('ADR-857 Phase 6 capstone conformance (#1139)', () => {
}
}
// Scan only the host loop files (not every workflow): a `render-hooks`
// mention in a non-host workflow must not mask a lost host call site.
// Scan only the host loop files (a `render-hooks` mention in a non-host
// workflow must not mask a lost host call site).
const callSites = new Set();
const reCall = /loop render-hooks\s+([a-z:]+)/g;
for (const relativePath of HOST_LOOP_FILES) {
@@ -131,18 +136,48 @@ describe('ADR-857 Phase 6 capstone conformance (#1139)', () => {
while ((m = reCall.exec(content))) callSites.add(m[1]);
}
for (const point of [...declaredPoints].sort()) {
if (point in KNOWN_UNWIRED) {
assert.ok(
!callSites.has(point),
`${point} is listed in KNOWN_UNWIRED (${KNOWN_UNWIRED[point]}) but now HAS a render-hooks call site — remove it from the allowlist.`,
);
continue;
const orphaned = [...declaredPoints].sort().filter((p) => !callSites.has(p));
assert.deepEqual(
orphaned, [],
`ADR-857 phase 6 is NOT complete: capability hooks declare these extension points ` +
`but no host-loop workflow calls \`gsd_run loop render-hooks <point>\`, so the hooks ` +
`can never fire: ${orphaned.join(', ')}. Wire each call site (#1167/#1169).`,
);
});
test('all ADR-857-named optional features are migrated to Capabilities (#1169)', () => {
// ADR-857 §53 + Decision 7 enumerate these optional, non-loop modules as
// Capabilities. Until each is a registered feature capability (or documented
// as core substrate), phase 6 is incomplete and the capstone is a false green.
const REQUIRED = ['tdd', 'schema-gate', 'drift', 'gap-analysis', 'profile-pipeline'];
const unmigrated = REQUIRED.filter((id) => registry.capabilities[id]?.role !== 'feature');
assert.deepEqual(
unmigrated, [],
`ADR-857 phase 6 is NOT complete: these ADR-named optional features are not yet ` +
`feature Capabilities (still inline in plan-phase.md / execute-phase.md): ` +
`${unmigrated.join(', ')}. Migrate each, or document it as core substrate (#1169).`,
);
});
test('host loop reads no capability-owned config key inline (#1169)', () => {
// Phase 6 requires the loop to resolve capability behavior via render-hooks,
// not by reading capability-owned keys directly. Any inline `config-get` of a
// registry-owned key is an incomplete migration (the loop still owns the
// feature's params).
const leaks = [];
for (const relativePath of HOST_LOOP_FILES) {
const content = readRepoFile(relativePath);
for (const key of Object.keys(registry.configKeys)) {
if (new RegExp(`\\bconfig-get\\s+${escapeRegExp(key)}\\b`).test(content)) {
leaks.push(`${path.basename(relativePath)} → ${key} (owned by ${registry.configKeys[key]})`);
}
}
assert.ok(
callSites.has(point),
`Capability hooks declare point "${point}" but no workflow calls \`gsd_run loop render-hooks ${point}\` — hooks at that point can never fire (#1169). Wire a call site or add the point to KNOWN_UNWIRED with its tracking issue.`,
);
}
leaks.sort();
assert.deepEqual(
leaks, [],
`ADR-857 phase 6 is NOT complete: the host loop reads capability-owned config keys ` +
`inline:\n ${leaks.join('\n ')}\nThe owning capability must render/consume these (#1169).`,
);
});
});