refactor: hard-fork GSD -> MSD (Make Software Done)

Mechanical rename produced by scripts/msd-rename.cjs: gsd/Gsd/GSD -> msd/Msd/MSD
across contents and paths, upstream package/repo coordinates -> @golem15/msd-core
and golem15com/msd-core. Deep links into upstream history, sibling upstream
packages, the GSD-2 import feature, CHANGELOG.md and .changeset/ are kept as-is.

Hand edits on top: MSD block-letter banner and logos, LICENSE copyright line,
package/plugin identity, regenerated lockfile, install-tree fixtures, derived
registries and benchmark baseline; migration checksum baseline re-locked
(MSD keeps its own install state, so no install had applied the old sums);
sort-order and regex-escaped expectations in tests adjusted.
This commit is contained in:
Jakub Zych
2026-10-06 01:47:40 +02:00
parent fe069b2a56
commit a9a7a328e6
2763 changed files with 78465 additions and 78434 deletions

View File

@@ -4,7 +4,7 @@
* Unit tests for host-integration.cjs (ADR-1239 Phase A).
* Pure, additive, no-I/O module — no temp dirs needed.
* Uses node:test + node:assert/strict.
* Requires the COMPILED artifact: ../gsd-core/bin/lib/host-integration.cjs
* Requires the COMPILED artifact: ../msd-core/bin/lib/host-integration.cjs
*/
const { describe, test } = require('node:test');
@@ -13,7 +13,7 @@ const fs = require('node:fs');
const path = require('node:path');
const fc = require('fast-check');
const hi = require('../gsd-core/bin/lib/host-integration.cjs');
const hi = require('../msd-core/bin/lib/host-integration.cjs');
const {
PROTOCOL_VERSION,
HOST_INTEGRATION_AXES,
@@ -34,9 +34,9 @@ const {
const {
_HOST_INTEGRATION_VOCAB,
validateCapability,
} = require('../gsd-core/bin/lib/capability-validator.cjs');
} = require('../msd-core/bin/lib/capability-validator.cjs');
const { cleanup, readFileNormalized } = require('./helpers.cjs');
const { scanFencedBlocks } = require('../gsd-core/bin/lib/markdown-sectionizer.cjs');
const { scanFencedBlocks } = require('../msd-core/bin/lib/markdown-sectionizer.cjs');
const REPO_ROOT = path.resolve(__dirname, '..');
@@ -1500,7 +1500,7 @@ describe('#3673 dispatch.maxConcurrency — validator', () => {
}
test('every shipped runtime descriptor with a maxConcurrency value passes validateCapability', () => {
const registry = require('../gsd-core/bin/lib/capability-registry.cjs');
const registry = require('../msd-core/bin/lib/capability-registry.cjs');
for (const [id, cap] of Object.entries(registry.runtimes)) {
const mc = cap && cap.runtime && cap.runtime.hostIntegration && cap.runtime.hostIntegration.dispatch
&& cap.runtime.hostIntegration.dispatch.maxConcurrency;
@@ -1559,7 +1559,7 @@ describe('#2584 dispatch.isolation — validator', () => {
});
test('every shipped runtime descriptor with an isolation value passes validateCapability', () => {
const registry = require('../gsd-core/bin/lib/capability-registry.cjs');
const registry = require('../msd-core/bin/lib/capability-registry.cjs');
for (const [id, cap] of Object.entries(registry.runtimes)) {
const iso = cap && cap.runtime && cap.runtime.hostIntegration && cap.runtime.hostIntegration.dispatch
&& cap.runtime.hostIntegration.dispatch.isolation;
@@ -2096,7 +2096,7 @@ describe('#2584 orchestratorExec — validator', () => {
// `resolveOrchestratorExec` currently takes NO `model` argument at all, so
// codex's argv never carries `--model` regardless of any configured
// model_overrides. THESE TESTS ARE FAILING-FIRST against today's code — do
// not "fix" resolveOrchestratorExec or gsd-tools.cjs to make them pass here;
// not "fix" resolveOrchestratorExec or msd-tools.cjs to make them pass here;
// that is a separate change. See issue #3714.
//
// THE FIX THIS PINS (not yet implemented):
@@ -2110,8 +2110,8 @@ describe('#2584 orchestratorExec — validator', () => {
// 'unsafe_leading_dash_model' exactly like the existing
// unsafe_leading_dash_prompt / unsafe_leading_dash_cwd guards.
// 3. Policy (which model, if any, to pass) lives at the CALLER
// (bin/gsd-tools.cjs), via:
// resolveAgentModelOverride('gsd-executor', readGsdEffectiveModelOverrides(cwd), null)
// (bin/msd-tools.cjs), via:
// resolveAgentModelOverride('msd-executor', readMsdEffectiveModelOverrides(cwd), null)
// then dropping the 'inherit' sentinel. Passing null as the runtime
// resolver is what makes "no tier routing" structural (ADR-2313) — the
// seam itself decides no policy.
@@ -2291,9 +2291,9 @@ describe('#3714 resolveOrchestratorExec — modelFlag/model seam (mechanical, RE
});
// ---------------------------------------------------------------------------
// #3714 — end-to-end policy: the caller (bin/gsd-tools.cjs) decides WHETHER
// #3714 — end-to-end policy: the caller (bin/msd-tools.cjs) decides WHETHER
// to pass a model at all, via
// resolveAgentModelOverride('gsd-executor', readGsdEffectiveModelOverrides(cwd), null)
// resolveAgentModelOverride('msd-executor', readMsdEffectiveModelOverrides(cwd), null)
// then dropping the 'inherit' sentinel. Every row below is a MEASURED FACT
// (verified by direct execution against this repo's current code) about what
// that function returns for a given .planning/config.json shape — these
@@ -2308,7 +2308,7 @@ describe('#3714 dispatch-isolation CLI — model policy end-to-end (RED pre-fix
const { PROBE_TIMEOUT_MS } = require('./helpers/timeouts.cjs');
const { createTempProject, cleanup, TEST_HOME_SANDBOX_MARKER } = require('./helpers.cjs');
const os = require('node:os');
const GSD_TOOLS = path.join(REPO_ROOT, 'gsd-core', 'bin', 'gsd-tools.cjs');
const MSD_TOOLS = path.join(REPO_ROOT, 'msd-core', 'bin', 'msd-tools.cjs');
function writeConfig(projectDir, config) {
fs.writeFileSync(
@@ -2320,7 +2320,7 @@ describe('#3714 dispatch-isolation CLI — model policy end-to-end (RED pre-fix
// Hermeticity: `queryCodexJson` used to inherit the DEVELOPER's real
// HOME/USERPROFILE with no override, so any row that writes no
// `model_overrides` key at all was silently reading (and could red
// against) the operator's own ~/.gsd/defaults.json — exactly the surface
// against) the operator's own ~/.msd/defaults.json — exactly the surface
// the BLOCKER regression test below needs to control precisely. Every
// call now gets a fresh, per-call temp HOME (removed synchronously after
// the CLI returns, since the call is a blocking spawn). USERPROFILE is
@@ -2329,19 +2329,19 @@ describe('#3714 dispatch-isolation CLI — model policy end-to-end (RED pre-fix
// satisfies the same passwd-less-host fallback installSpawnEnv documents.
// `beforeSpawn`, when provided, is called with the sandbox HOME dir path
// BEFORE the CLI spawns — the seam a caller needs to seed a GLOBAL
// ~/.gsd/defaults.json (see writeGlobalDefaults below) for a
// ~/.msd/defaults.json (see writeGlobalDefaults below) for a
// global-only-pin row.
function queryCodexJson(projectDir, extraEnv = {}, beforeSpawn = null) {
const sandboxHomeDir = fs.mkdtempSync(path.join(os.tmpdir(), 'gsd-3714-home-'));
const sandboxHomeDir = fs.mkdtempSync(path.join(os.tmpdir(), 'msd-3714-home-'));
try {
if (typeof beforeSpawn === 'function') beforeSpawn(sandboxHomeDir);
const r = runNode(
[GSD_TOOLS, 'query', 'dispatch-isolation', '--json', '--cwd-target', '/tmp/wt', '--prompt', 'do the thing'],
[MSD_TOOLS, 'query', 'dispatch-isolation', '--json', '--cwd-target', '/tmp/wt', '--prompt', 'do the thing'],
{
cwd: projectDir,
env: {
...process.env,
GSD_RUNTIME: 'codex',
MSD_RUNTIME: 'codex',
HOME: sandboxHomeDir,
USERPROFILE: sandboxHomeDir,
[TEST_HOME_SANDBOX_MARKER]: sandboxHomeDir,
@@ -2350,32 +2350,32 @@ describe('#3714 dispatch-isolation CLI — model policy end-to-end (RED pre-fix
timeoutMs: PROBE_TIMEOUT_MS,
},
);
throwIfFailed(r, 'gsd-tools query dispatch-isolation --json (codex, model policy)');
throwIfFailed(r, 'msd-tools query dispatch-isolation --json (codex, model policy)');
return { json: JSON.parse(r.stdout), stderr: r.stderr };
} finally {
cleanup(sandboxHomeDir);
}
}
// Writes ~/.gsd/defaults.json (the GLOBAL model_overrides store) into the
// Writes ~/.msd/defaults.json (the GLOBAL model_overrides store) into the
// per-call sandbox HOME so a test can exercise "global-only pin, no
// per-project override" — the exact shape the BLOCKER describes.
function writeGlobalDefaults(homeDir, defaults) {
const gsdDir = path.join(homeDir, '.gsd');
fs.mkdirSync(gsdDir, { recursive: true });
fs.writeFileSync(path.join(gsdDir, 'defaults.json'), JSON.stringify(defaults));
const msdDir = path.join(homeDir, '.msd');
fs.mkdirSync(msdDir, { recursive: true });
fs.writeFileSync(path.join(msdDir, 'defaults.json'), JSON.stringify(defaults));
}
function hasModelFlag(execArgs) {
return execArgs.includes('--model');
}
// MATRIX row 1: an explicit real-Codex gsd-executor override reaches argv
// MATRIX row 1: an explicit real-Codex msd-executor override reaches argv
// as --model.
test('row 1: explicit model_overrides["gsd-executor"] -> exec.args contains ["--model","gpt-5.6-terra"] at the correct position', () => {
const dir = createTempProject('gsd-3714-row1-');
test('row 1: explicit model_overrides["msd-executor"] -> exec.args contains ["--model","gpt-5.6-terra"] at the correct position', () => {
const dir = createTempProject('msd-3714-row1-');
try {
writeConfig(dir, { model_overrides: { 'gsd-executor': 'gpt-5.6-terra' } });
writeConfig(dir, { model_overrides: { 'msd-executor': 'gpt-5.6-terra' } });
const { json: result } = queryCodexJson(dir);
assert.equal(result.isolation, 'orchestrator-worktree');
assert.deepEqual(result.exec.args, ['exec', '--model', 'gpt-5.6-terra', '--cd', '/tmp/wt', 'do the thing']);
@@ -2388,7 +2388,7 @@ describe('#3714 dispatch-isolation CLI — model policy end-to-end (RED pre-fix
// particular the resolve-model tier value ("sonnet") must NEVER leak onto
// codex's argv (that is the #2310/#2311 400 ADR-2313 exists to prevent).
test('row 2 CONTROL: no override -> exec.args contains NO --model and no "sonnet" anywhere', () => {
const dir = createTempProject('gsd-3714-row2-');
const dir = createTempProject('msd-3714-row2-');
try {
writeConfig(dir, {});
const { json: result } = queryCodexJson(dir);
@@ -2402,10 +2402,10 @@ describe('#3714 dispatch-isolation CLI — model policy end-to-end (RED pre-fix
});
// MATRIX row 3 [CONTROL]: the 'inherit' sentinel must never reach argv.
test('row 3 CONTROL: model_overrides["gsd-executor"] === "inherit" -> no --model (sentinel never on the wire)', () => {
const dir = createTempProject('gsd-3714-row3-');
test('row 3 CONTROL: model_overrides["msd-executor"] === "inherit" -> no --model (sentinel never on the wire)', () => {
const dir = createTempProject('msd-3714-row3-');
try {
writeConfig(dir, { model_overrides: { 'gsd-executor': 'inherit' } });
writeConfig(dir, { model_overrides: { 'msd-executor': 'inherit' } });
const { json: result } = queryCodexJson(dir);
assert.deepEqual(result.exec.args, ['exec', '--cd', '/tmp/wt', 'do the thing']);
assert.ok(!hasModelFlag(result.exec.args));
@@ -2416,10 +2416,10 @@ describe('#3714 dispatch-isolation CLI — model policy end-to-end (RED pre-fix
});
// MATRIX row 4 [CONTROL]: an empty-string override resolves to null, same as no override.
test('row 4 CONTROL: model_overrides["gsd-executor"] === "" -> no --model', () => {
const dir = createTempProject('gsd-3714-row4-');
test('row 4 CONTROL: model_overrides["msd-executor"] === "" -> no --model', () => {
const dir = createTempProject('msd-3714-row4-');
try {
writeConfig(dir, { model_overrides: { 'gsd-executor': '' } });
writeConfig(dir, { model_overrides: { 'msd-executor': '' } });
const { json: result } = queryCodexJson(dir);
assert.deepEqual(result.exec.args, ['exec', '--cd', '/tmp/wt', 'do the thing']);
assert.ok(!hasModelFlag(result.exec.args));
@@ -2433,7 +2433,7 @@ describe('#3714 dispatch-isolation CLI — model policy end-to-end (RED pre-fix
// tier routing to codex entirely; passing `null` as the runtimeResolver
// (per the fix design) is what makes this structural rather than incidental.
test('row 5 CONTROL: model_profile:"balanced" only (no per-agent override) -> no --model (tier routing forbidden, ADR-2313)', () => {
const dir = createTempProject('gsd-3714-row5-');
const dir = createTempProject('msd-3714-row5-');
try {
writeConfig(dir, { runtime: 'codex', model_profile: 'balanced' });
const { json: result } = queryCodexJson(dir);
@@ -2445,32 +2445,32 @@ describe('#3714 dispatch-isolation CLI — model policy end-to-end (RED pre-fix
}
});
// BLOCKER regression test: a GLOBAL (~/.gsd/defaults.json) Anthropic-flavored
// BLOCKER regression test: a GLOBAL (~/.msd/defaults.json) Anthropic-flavored
// pin must NOT reach codex's argv, and must produce a stderr warning. Before
// this fix, presence-only gating let this straight through to
// `codex exec --model sonnet` — the documented #2310/#2311 400.
test('BLOCKER: global-only model_overrides["gsd-executor"]="sonnet" -> NO --model, and a stderr warning', () => {
const dir = createTempProject('gsd-3714-blocker-global-anthropic-');
test('BLOCKER: global-only model_overrides["msd-executor"]="sonnet" -> NO --model, and a stderr warning', () => {
const dir = createTempProject('msd-3714-blocker-global-anthropic-');
try {
writeConfig(dir, {});
const { json: result, stderr } = queryCodexJson(dir, {}, (homeDir) => {
writeGlobalDefaults(homeDir, { model_overrides: { 'gsd-executor': 'sonnet' } });
writeGlobalDefaults(homeDir, { model_overrides: { 'msd-executor': 'sonnet' } });
});
assert.deepEqual(result.exec.args, ['exec', '--cd', '/tmp/wt', 'do the thing']);
assert.ok(!hasModelFlag(result.exec.args));
assert.ok(!result.exec.args.join(' ').includes('sonnet'));
assert.match(stderr, /gsd-executor.*sonnet.*Anthropic/i);
assert.match(stderr, /msd-executor.*sonnet.*Anthropic/i);
} finally {
cleanup(dir);
}
});
test('global-only model_overrides["gsd-executor"]="gpt-5.6-terra" (real Codex pin) -> IS emitted', () => {
const dir = createTempProject('gsd-3714-global-real-');
test('global-only model_overrides["msd-executor"]="gpt-5.6-terra" (real Codex pin) -> IS emitted', () => {
const dir = createTempProject('msd-3714-global-real-');
try {
writeConfig(dir, {});
const { json: result, stderr } = queryCodexJson(dir, {}, (homeDir) => {
writeGlobalDefaults(homeDir, { model_overrides: { 'gsd-executor': 'gpt-5.6-terra' } });
writeGlobalDefaults(homeDir, { model_overrides: { 'msd-executor': 'gpt-5.6-terra' } });
});
assert.deepEqual(result.exec.args, ['exec', '--model', 'gpt-5.6-terra', '--cd', '/tmp/wt', 'do the thing']);
assert.equal(stderr, '');
@@ -2480,9 +2480,9 @@ describe('#3714 dispatch-isolation CLI — model policy end-to-end (RED pre-fix
});
test('whitespace-only override " " -> no --model, no warning', () => {
const dir = createTempProject('gsd-3714-ws-');
const dir = createTempProject('msd-3714-ws-');
try {
writeConfig(dir, { model_overrides: { 'gsd-executor': ' ' } });
writeConfig(dir, { model_overrides: { 'msd-executor': ' ' } });
const { json: result, stderr } = queryCodexJson(dir);
assert.deepEqual(result.exec.args, ['exec', '--cd', '/tmp/wt', 'do the thing']);
assert.equal(stderr, '');
@@ -2493,9 +2493,9 @@ describe('#3714 dispatch-isolation CLI — model policy end-to-end (RED pre-fix
test('"Inherit" and " inherit " (case/whitespace-insensitive sentinel) -> no --model', () => {
for (const value of ['Inherit', ' inherit ']) {
const dir = createTempProject('gsd-3714-inherit-ci-');
const dir = createTempProject('msd-3714-inherit-ci-');
try {
writeConfig(dir, { model_overrides: { 'gsd-executor': value } });
writeConfig(dir, { model_overrides: { 'msd-executor': value } });
const { json: result, stderr } = queryCodexJson(dir);
assert.deepEqual(result.exec.args, ['exec', '--cd', '/tmp/wt', 'do the thing'], `value=${JSON.stringify(value)}`);
assert.equal(stderr, '');
@@ -2514,14 +2514,14 @@ describe('#3714 dispatch-isolation CLI — model policy end-to-end (RED pre-fix
'gpt-5HOST_INJECTED',
];
for (const value of injectionValues) {
const dir = createTempProject('gsd-3714-injection-');
const dir = createTempProject('msd-3714-injection-');
try {
writeConfig(dir, { model_overrides: { 'gsd-executor': value } });
writeConfig(dir, { model_overrides: { 'msd-executor': value } });
const { json: result, stderr } = queryCodexJson(dir);
assert.deepEqual(result.exec.args, ['exec', '--cd', '/tmp/wt', 'do the thing'],
`value=${JSON.stringify(value)} must never reach argv`);
assert.ok(!hasModelFlag(result.exec.args));
assert.match(stderr, /gsd-executor/, `value=${JSON.stringify(value)} must warn`);
assert.match(stderr, /msd-executor/, `value=${JSON.stringify(value)} must warn`);
} finally {
cleanup(dir);
}
@@ -2530,9 +2530,9 @@ describe('#3714 dispatch-isolation CLI — model policy end-to-end (RED pre-fix
test('legitimate real-Codex ids survive: "gpt-5.6-terra" and "synthetic/hf:zai-org/GLM-5.2"', () => {
for (const value of ['gpt-5.6-terra', 'synthetic/hf:zai-org/GLM-5.2']) {
const dir = createTempProject('gsd-3714-legit-');
const dir = createTempProject('msd-3714-legit-');
try {
writeConfig(dir, { model_overrides: { 'gsd-executor': value } });
writeConfig(dir, { model_overrides: { 'msd-executor': value } });
const { json: result, stderr } = queryCodexJson(dir);
assert.deepEqual(result.exec.args, ['exec', '--model', value, '--cd', '/tmp/wt', 'do the thing']);
assert.equal(stderr, '');
@@ -2548,9 +2548,9 @@ describe('#3714 dispatch-isolation CLI — model policy end-to-end (RED pre-fix
// kept adjacent so the anchor LEADING_DASH_RE still enforces is visibly
// still live even after widening the charset.
test('ITEM 1: "text-bison@002" (Vertex model-version pin) survives — "@" is a legitimate model-id character', () => {
const dir = createTempProject('gsd-3714-vertex-at-');
const dir = createTempProject('msd-3714-vertex-at-');
try {
writeConfig(dir, { model_overrides: { 'gsd-executor': 'text-bison@002' } });
writeConfig(dir, { model_overrides: { 'msd-executor': 'text-bison@002' } });
const { json: result, stderr } = queryCodexJson(dir);
assert.deepEqual(result.exec.args, ['exec', '--model', 'text-bison@002', '--cd', '/tmp/wt', 'do the thing']);
assert.equal(stderr, '');
@@ -2560,43 +2560,43 @@ describe('#3714 dispatch-isolation CLI — model policy end-to-end (RED pre-fix
});
test('ITEM 1 anchor control: a leading dash still drops even though "@" is now permitted ("-@bad" -> no --model, a warning)', () => {
const dir = createTempProject('gsd-3714-vertex-at-leading-dash-');
const dir = createTempProject('msd-3714-vertex-at-leading-dash-');
try {
writeConfig(dir, { model_overrides: { 'gsd-executor': '-@bad' } });
writeConfig(dir, { model_overrides: { 'msd-executor': '-@bad' } });
const { json: result, stderr } = queryCodexJson(dir);
assert.deepEqual(result.exec.args, ['exec', '--cd', '/tmp/wt', 'do the thing']);
assert.ok(!hasModelFlag(result.exec.args));
assert.match(stderr, /gsd-executor/);
assert.match(stderr, /msd-executor/);
} finally {
cleanup(dir);
}
});
// MATRIX row 8: the dispatch predicate (what gsd-tools.cjs's caller decides
// MATRIX row 8: the dispatch predicate (what msd-tools.cjs's caller decides
// to pass) must agree, on every config shape below, with what the shared
// resolveAgentModelOverride('gsd-executor', overrides, null) function
// resolveAgentModelOverride('msd-executor', overrides, null) function
// returns (dropping only the 'inherit' sentinel). This row is a resolver
// TAUTOLOGY — it agrees with the presence-only predicate and does not
// exercise the VALUE policy (Anthropic-flavored / charset) at all. It is
// kept as a presence-level regression guard; the real divergence guard is
// the CROSS-SURFACE PARITY test below.
test('row 8: dispatch predicate agrees with resolveAgentModelOverride(..., null) on every config shape', () => {
const installModelOverrideResolver = require('../gsd-core/bin/lib/install-model-override-resolver.cjs');
const installModelOverrideResolver = require('../msd-core/bin/lib/install-model-override-resolver.cjs');
const shapes = [
{ name: 'explicit pin', config: { model_overrides: { 'gsd-executor': 'gpt-5.6-terra' } } },
{ name: 'explicit pin', config: { model_overrides: { 'msd-executor': 'gpt-5.6-terra' } } },
{ name: 'no override', config: {} },
{ name: 'override "inherit"', config: { model_overrides: { 'gsd-executor': 'inherit' } } },
{ name: 'override ""', config: { model_overrides: { 'gsd-executor': '' } } },
{ name: 'override "inherit"', config: { model_overrides: { 'msd-executor': 'inherit' } } },
{ name: 'override ""', config: { model_overrides: { 'msd-executor': '' } } },
{ name: 'model_profile only', config: { runtime: 'codex', model_profile: 'balanced' } },
];
for (const shape of shapes) {
const dir = createTempProject('gsd-3714-row8-');
const dir = createTempProject('msd-3714-row8-');
try {
writeConfig(dir, shape.config);
// The predicate the fix's caller must implement: explicit override,
// no runtime-tier resolver (null), with 'inherit' dropped.
const overrides = installModelOverrideResolver.readGsdEffectiveModelOverrides(dir);
const resolved = installModelOverrideResolver.resolveAgentModelOverride('gsd-executor', overrides, null);
const overrides = installModelOverrideResolver.readMsdEffectiveModelOverrides(dir);
const resolved = installModelOverrideResolver.resolveAgentModelOverride('msd-executor', overrides, null);
const expectedModel = (resolved && resolved !== 'inherit') ? resolved : null;
const expectedHasModel = expectedModel !== null;
@@ -2621,10 +2621,10 @@ describe('#3714 dispatch-isolation CLI — model policy end-to-end (RED pre-fix
// NOT reachable in-process here — it lives in the generated installer
// module and is exercised only via `npm run build` / the install test
// suite) would reach the SAME emit-vs-drop decision for the identical
// model_overrides["gsd-executor"] value.
// model_overrides["msd-executor"] value.
//
// What is asserted DIRECTLY (real code path, in-process): the dispatch
// side, via the real `gsd-tools query dispatch-isolation` CLI spawn.
// side, via the real `msd-tools query dispatch-isolation` CLI spawn.
// What is MIRRORED (not independently re-executed): the install-side half
// is derived from `isAnthropicFlavoredModel` (the single-sourced #3241
// predicate, imported for real from bin/lib/model-catalog.cjs — so THAT
@@ -2637,7 +2637,7 @@ describe('#3714 dispatch-isolation CLI — model policy end-to-end (RED pre-fix
// change without a matching update here, this comment is the thing that
// goes stale, not a shared executable — that is the acknowledged limit.
test('DIVERGENCE GUARD: dispatch model-pin decision matches install-side Codex .toml policy for the same value', () => {
const { isAnthropicFlavoredModel } = require('../gsd-core/bin/lib/model-catalog.cjs');
const { isAnthropicFlavoredModel } = require('../msd-core/bin/lib/model-catalog.cjs');
function installSideWouldEmit(rawValue) {
if (typeof rawValue !== 'string') return false;
const trimmed = rawValue.trim();
@@ -2659,9 +2659,9 @@ describe('#3714 dispatch-isolation CLI — model policy end-to-end (RED pre-fix
'gpt-5 -c approval_policy=never',
];
for (const value of table) {
const dir = createTempProject('gsd-3714-parity-');
const dir = createTempProject('msd-3714-parity-');
try {
writeConfig(dir, { model_overrides: { 'gsd-executor': value } });
writeConfig(dir, { model_overrides: { 'msd-executor': value } });
const { json: result } = queryCodexJson(dir);
const dispatchEmitted = hasModelFlag(result.exec.args);
// Dispatch additionally drops 'inherit' (case/whitespace-insensitive)
@@ -2703,15 +2703,15 @@ describe('#3714 dispatch-isolation CLI — model policy end-to-end (RED pre-fix
test('DEFECT 1: leading-dash pins ("-c", "--config", "-", "--") -> no --model, a warning, exec NOT null (argv == no-model argv)', () => {
const leadingDashValues = ['-c', '--config', '-', '--'];
for (const value of leadingDashValues) {
const dir = createTempProject('gsd-3714-leading-dash-');
const dir = createTempProject('msd-3714-leading-dash-');
try {
writeConfig(dir, { model_overrides: { 'gsd-executor': value } });
writeConfig(dir, { model_overrides: { 'msd-executor': value } });
const { json: result, stderr } = queryCodexJson(dir);
assert.notEqual(result.exec, null, `value=${JSON.stringify(value)}: exec must not be null`);
assert.deepEqual(result.exec.args, ['exec', '--cd', '/tmp/wt', 'do the thing'],
`value=${JSON.stringify(value)}: argv must equal the no-model argv exactly`);
assert.ok(!hasModelFlag(result.exec.args));
assert.match(stderr, /gsd-executor/, `value=${JSON.stringify(value)} must warn`);
assert.match(stderr, /msd-executor/, `value=${JSON.stringify(value)} must warn`);
} finally {
cleanup(dir);
}
@@ -2729,13 +2729,13 @@ describe('#3714 dispatch-isolation CLI — model policy end-to-end (RED pre-fix
// policy never runs at all for a host that was never going to emit
// --model.
test('DEFECT 1 REGRESSION: "-c" pin under kimi-code (no modelFlag host) -> argv byte-identical to no-pin, exec NOT null, stderr EMPTY', () => {
const noPinDir = createTempProject('gsd-3714-kimi-nopin-');
const pinnedDir = createTempProject('gsd-3714-kimi-pinned-');
const noPinDir = createTempProject('msd-3714-kimi-nopin-');
const pinnedDir = createTempProject('msd-3714-kimi-pinned-');
try {
writeConfig(noPinDir, {});
writeConfig(pinnedDir, { model_overrides: { 'gsd-executor': '-c' } });
const { json: noPinResult } = queryCodexJson(noPinDir, { GSD_RUNTIME: 'kimi-code' });
const { json: pinnedResult, stderr } = queryCodexJson(pinnedDir, { GSD_RUNTIME: 'kimi-code' });
writeConfig(pinnedDir, { model_overrides: { 'msd-executor': '-c' } });
const { json: noPinResult } = queryCodexJson(noPinDir, { MSD_RUNTIME: 'kimi-code' });
const { json: pinnedResult, stderr } = queryCodexJson(pinnedDir, { MSD_RUNTIME: 'kimi-code' });
assert.notEqual(noPinResult.exec, null, 'kimi-code no-pin: exec must not be null');
assert.notEqual(pinnedResult.exec, null, 'kimi-code "-c" pin: exec must not be null (this is the regression)');
assert.deepEqual(pinnedResult.exec.args, noPinResult.exec.args,
@@ -2763,14 +2763,14 @@ describe('#3714 dispatch-isolation CLI — model policy end-to-end (RED pre-fix
test('DEFECT 2: case variants of Anthropic-flavored pins ("Sonnet", "OPUS", "Claude-Sonnet-4-5") -> no --model + warning', () => {
const caseVariants = ['Sonnet', 'OPUS', 'Claude-Sonnet-4-5'];
for (const value of caseVariants) {
const dir = createTempProject('gsd-3714-case-flavor-');
const dir = createTempProject('msd-3714-case-flavor-');
try {
writeConfig(dir, { model_overrides: { 'gsd-executor': value } });
writeConfig(dir, { model_overrides: { 'msd-executor': value } });
const { json: result, stderr } = queryCodexJson(dir);
assert.deepEqual(result.exec.args, ['exec', '--cd', '/tmp/wt', 'do the thing'],
`value=${JSON.stringify(value)} must never reach argv`);
assert.ok(!hasModelFlag(result.exec.args));
assert.match(stderr, /gsd-executor/, `value=${JSON.stringify(value)} must warn`);
assert.match(stderr, /msd-executor/, `value=${JSON.stringify(value)} must warn`);
} finally {
cleanup(dir);
}
@@ -2778,13 +2778,13 @@ describe('#3714 dispatch-isolation CLI — model policy end-to-end (RED pre-fix
});
test('DEFECT 2 CONTROL: lowercase "sonnet" still drops (unchanged behavior)', () => {
const dir = createTempProject('gsd-3714-case-flavor-control-');
const dir = createTempProject('msd-3714-case-flavor-control-');
try {
writeConfig(dir, { model_overrides: { 'gsd-executor': 'sonnet' } });
writeConfig(dir, { model_overrides: { 'msd-executor': 'sonnet' } });
const { json: result, stderr } = queryCodexJson(dir);
assert.deepEqual(result.exec.args, ['exec', '--cd', '/tmp/wt', 'do the thing']);
assert.ok(!hasModelFlag(result.exec.args));
assert.match(stderr, /gsd-executor/);
assert.match(stderr, /msd-executor/);
} finally {
cleanup(dir);
}
@@ -2799,13 +2799,13 @@ describe('#3714 dispatch-isolation CLI — model policy end-to-end (RED pre-fix
const ESC = String.fromCharCode(27);
const BEL = String.fromCharCode(7);
const hostileValue = `x${ESC}]0;PWNED${BEL}y`;
const dir = createTempProject('gsd-3714-defect3-hostile-');
const dir = createTempProject('msd-3714-defect3-hostile-');
try {
writeConfig(dir, { model_overrides: { 'gsd-executor': hostileValue } });
writeConfig(dir, { model_overrides: { 'msd-executor': hostileValue } });
const { json: result, stderr } = queryCodexJson(dir);
assert.deepEqual(result.exec.args, ['exec', '--cd', '/tmp/wt', 'do the thing']);
assert.ok(!hasModelFlag(result.exec.args));
assert.match(stderr, /gsd-executor/);
assert.match(stderr, /msd-executor/);
const stderrBody = stderr.endsWith('\n') ? stderr.slice(0, -1) : stderr;
// eslint-disable-next-line no-control-regex -- asserting the ABSENCE of raw control bytes is the point of this test
assert.doesNotMatch(stderrBody, /[\x00-\x1f\x7f]/,
@@ -2822,9 +2822,9 @@ describe('#3714 dispatch-isolation CLI — model policy end-to-end (RED pre-fix
test('DEFECT 3: a long ESC-bearing pin (> 64 chars) is sanitized before truncation — no raw control survives', () => {
const ESC = String.fromCharCode(27);
const hostileValue = `${'x'.repeat(80)}${ESC}[31mHOSTILE`;
const dir = createTempProject('gsd-3714-defect3-long-');
const dir = createTempProject('msd-3714-defect3-long-');
try {
writeConfig(dir, { model_overrides: { 'gsd-executor': hostileValue } });
writeConfig(dir, { model_overrides: { 'msd-executor': hostileValue } });
const { json: result, stderr } = queryCodexJson(dir);
assert.deepEqual(result.exec.args, ['exec', '--cd', '/tmp/wt', 'do the thing']);
const stderrBody = stderr.endsWith('\n') ? stderr.slice(0, -1) : stderr;
@@ -2845,13 +2845,13 @@ describe('#3714 dispatch-isolation CLI — model policy end-to-end (RED pre-fix
// the resolved runtime's orchestratorExec declaring a non-empty modelFlag.
// ---------------------------------------------------------------------------
test('ITEM 2: a "sonnet" pin under kimi-code -> argv byte-identical to no-pin, stderr EMPTY (no modelFlag declared)', () => {
const noPinDir = createTempProject('gsd-3714-item2-kimicode-nopin-');
const pinnedDir = createTempProject('gsd-3714-item2-kimicode-pinned-');
const noPinDir = createTempProject('msd-3714-item2-kimicode-nopin-');
const pinnedDir = createTempProject('msd-3714-item2-kimicode-pinned-');
try {
writeConfig(noPinDir, {});
writeConfig(pinnedDir, { model_overrides: { 'gsd-executor': 'sonnet' } });
const { json: noPinResult, stderr: noPinStderr } = queryCodexJson(noPinDir, { GSD_RUNTIME: 'kimi-code' });
const { json: pinnedResult, stderr: pinnedStderr } = queryCodexJson(pinnedDir, { GSD_RUNTIME: 'kimi-code' });
writeConfig(pinnedDir, { model_overrides: { 'msd-executor': 'sonnet' } });
const { json: noPinResult, stderr: noPinStderr } = queryCodexJson(noPinDir, { MSD_RUNTIME: 'kimi-code' });
const { json: pinnedResult, stderr: pinnedStderr } = queryCodexJson(pinnedDir, { MSD_RUNTIME: 'kimi-code' });
assert.deepEqual(pinnedResult.exec.args, noPinResult.exec.args,
'kimi-code argv with a "sonnet" pin must be byte-identical to the no-pin argv');
assert.equal(noPinStderr, '');
@@ -2863,13 +2863,13 @@ describe('#3714 dispatch-isolation CLI — model policy end-to-end (RED pre-fix
});
test('ITEM 2: a "sonnet" pin under opencode -> argv byte-identical to no-pin, stderr EMPTY (no modelFlag declared)', () => {
const noPinDir = createTempProject('gsd-3714-item2-opencode-nopin-');
const pinnedDir = createTempProject('gsd-3714-item2-opencode-pinned-');
const noPinDir = createTempProject('msd-3714-item2-opencode-nopin-');
const pinnedDir = createTempProject('msd-3714-item2-opencode-pinned-');
try {
writeConfig(noPinDir, {});
writeConfig(pinnedDir, { model_overrides: { 'gsd-executor': 'sonnet' } });
const { json: noPinResult, stderr: noPinStderr } = queryCodexJson(noPinDir, { GSD_RUNTIME: 'opencode' });
const { json: pinnedResult, stderr: pinnedStderr } = queryCodexJson(pinnedDir, { GSD_RUNTIME: 'opencode' });
writeConfig(pinnedDir, { model_overrides: { 'msd-executor': 'sonnet' } });
const { json: noPinResult, stderr: noPinStderr } = queryCodexJson(noPinDir, { MSD_RUNTIME: 'opencode' });
const { json: pinnedResult, stderr: pinnedStderr } = queryCodexJson(pinnedDir, { MSD_RUNTIME: 'opencode' });
assert.deepEqual(pinnedResult.exec.args, noPinResult.exec.args,
'opencode argv with a "sonnet" pin must be byte-identical to the no-pin argv');
assert.equal(noPinStderr, '');
@@ -2881,13 +2881,13 @@ describe('#3714 dispatch-isolation CLI — model policy end-to-end (RED pre-fix
});
test('ITEM 2 CONTROL: a "sonnet" pin under codex (declares modelFlag) -> still dropped, WITH the warning', () => {
const dir = createTempProject('gsd-3714-item2-codex-control-');
const dir = createTempProject('msd-3714-item2-codex-control-');
try {
writeConfig(dir, { model_overrides: { 'gsd-executor': 'sonnet' } });
writeConfig(dir, { model_overrides: { 'msd-executor': 'sonnet' } });
const { json: result, stderr } = queryCodexJson(dir);
assert.deepEqual(result.exec.args, ['exec', '--cd', '/tmp/wt', 'do the thing']);
assert.ok(!hasModelFlag(result.exec.args));
assert.match(stderr, /gsd-executor.*sonnet.*Anthropic/i);
assert.match(stderr, /msd-executor.*sonnet.*Anthropic/i);
} finally {
cleanup(dir);
}
@@ -2897,7 +2897,7 @@ describe('#3714 dispatch-isolation CLI — model policy end-to-end (RED pre-fix
// ---------------------------------------------------------------------------
// #2627 Phase 3 — the `dispatch-isolation` CLI route.
//
// Behavioral: each case SPAWNS the real gsd-tools CLI and asserts on its actual
// Behavioral: each case SPAWNS the real msd-tools CLI and asserts on its actual
// stdout, rather than inspecting the route's source. This is the scheduler
// consumer's only entry point — execute-phase branches on exactly this output.
// ---------------------------------------------------------------------------
@@ -2905,14 +2905,14 @@ describe('#2627 dispatch-isolation CLI route', () => {
const { runNode } = require('./helpers/process-seam.cjs');
const { throwIfFailed } = require('./helpers/git-fixture.cjs');
const { PROBE_TIMEOUT_MS } = require('./helpers/timeouts.cjs');
const GSD_TOOLS = path.join(REPO_ROOT, 'gsd-core', 'bin', 'gsd-tools.cjs');
const MSD_TOOLS = path.join(REPO_ROOT, 'msd-core', 'bin', 'msd-tools.cjs');
function query(runtimeId, extraArgs = []) {
const r = runNode(
[GSD_TOOLS, 'query', 'dispatch-isolation', ...extraArgs],
{ cwd: REPO_ROOT, env: { ...process.env, GSD_RUNTIME: runtimeId }, timeoutMs: PROBE_TIMEOUT_MS },
[MSD_TOOLS, 'query', 'dispatch-isolation', ...extraArgs],
{ cwd: REPO_ROOT, env: { ...process.env, MSD_RUNTIME: runtimeId }, timeoutMs: PROBE_TIMEOUT_MS },
);
throwIfFailed(r, `gsd-tools query dispatch-isolation ${extraArgs.join(' ')}`);
throwIfFailed(r, `msd-tools query dispatch-isolation ${extraArgs.join(' ')}`);
return r.stdout;
}
const queryJson = (runtimeId, extraArgs = []) => JSON.parse(query(runtimeId, ['--json', ...extraArgs]));
@@ -2936,7 +2936,7 @@ describe('#2627 dispatch-isolation CLI route', () => {
const claude = queryJson('claude');
assert.equal(claude.isolation, 'harness-worktree');
assert.equal(claude.harnessFlag, 'isolation="worktree"');
assert.equal(claude.exec, null, 'GSD runs no git on the harness path — there is nothing to spawn');
assert.equal(claude.exec, null, 'MSD runs no git on the harness path — there is nothing to spawn');
assert.equal(queryJson('cursor').harnessFlag, '--worktree');
});
@@ -2999,23 +2999,23 @@ describe('#3673 dispatch-capacity CLI route', () => {
const { runNode } = require('./helpers/process-seam.cjs');
const { throwIfFailed } = require('./helpers/git-fixture.cjs');
const { PROBE_TIMEOUT_MS } = require('./helpers/timeouts.cjs');
const GSD_TOOLS = path.join(REPO_ROOT, 'gsd-core', 'bin', 'gsd-tools.cjs');
const MSD_TOOLS = path.join(REPO_ROOT, 'msd-core', 'bin', 'msd-tools.cjs');
// `maxConcurrencyEnv === undefined` means "unset" — GSD_DISPATCH_MAX_CONCURRENCY
// `maxConcurrencyEnv === undefined` means "unset" — MSD_DISPATCH_MAX_CONCURRENCY
// is deliberately deleted from the child's env rather than passed as the
// literal string "undefined", so the "env absent" test cases are genuinely
// absent, not present-with-a-bogus-value.
function query(runtimeId, extraArgs = [], maxConcurrencyEnv) {
const env = { ...process.env, GSD_RUNTIME: runtimeId };
delete env.GSD_DISPATCH_MAX_CONCURRENCY;
const env = { ...process.env, MSD_RUNTIME: runtimeId };
delete env.MSD_DISPATCH_MAX_CONCURRENCY;
if (maxConcurrencyEnv !== undefined) {
env.GSD_DISPATCH_MAX_CONCURRENCY = maxConcurrencyEnv;
env.MSD_DISPATCH_MAX_CONCURRENCY = maxConcurrencyEnv;
}
const r = runNode(
[GSD_TOOLS, 'query', 'dispatch-capacity', ...extraArgs],
[MSD_TOOLS, 'query', 'dispatch-capacity', ...extraArgs],
{ cwd: REPO_ROOT, env, timeoutMs: PROBE_TIMEOUT_MS },
);
throwIfFailed(r, `gsd-tools query dispatch-capacity ${extraArgs.join(' ')}`);
throwIfFailed(r, `msd-tools query dispatch-capacity ${extraArgs.join(' ')}`);
return r.stdout;
}
const queryJson = (runtimeId, extraArgs = [], maxConcurrencyEnv) =>
@@ -3097,13 +3097,13 @@ describe('#3673 dispatch-capacity CLI route', () => {
// site reintroduces a runtime-name test around its isolation decision.
// ---------------------------------------------------------------------------
// Scan workflows AND the reference fragments they inline: scheduler branches that
// mutate USE_WORKTREES live in gsd-core/references/ too (execute-phase-wave-guard,
// mutate USE_WORKTREES live in msd-core/references/ too (execute-phase-wave-guard,
// execute-phase-between-wave-reset), and a workflows-only scan misses them.
// Shared by both #2652 and #2728 suites below — a second, hand-listed copy is how
// the degrade scan silently narrowed to three files (round-7 review, Major 6).
const SCAN_ROOTS = [
path.join(REPO_ROOT, 'gsd-core', 'workflows'),
path.join(REPO_ROOT, 'gsd-core', 'references'),
path.join(REPO_ROOT, 'msd-core', 'workflows'),
path.join(REPO_ROOT, 'msd-core', 'references'),
];
function collectMarkdown(dir) {
@@ -3174,10 +3174,10 @@ describe('#2652 dispatch-site parity — isolation gates on capability, not runt
// Assert identities, not just a count: a count survives the scan silently
// drifting off the files that actually matter.
for (const required of [
'gsd-core/workflows/quick.md',
'gsd-core/workflows/diagnose-issues.md',
'gsd-core/workflows/execute-plan.md',
'gsd-core/workflows/execute-phase/steps/executor-isolation-dispatch.md',
'msd-core/workflows/quick.md',
'msd-core/workflows/diagnose-issues.md',
'msd-core/workflows/execute-plan.md',
'msd-core/workflows/execute-phase/steps/executor-isolation-dispatch.md',
]) {
assert.ok(rel.includes(required), `dispatch-site scan must cover ${required}; found ${rel.length} files`);
}
@@ -3186,7 +3186,7 @@ describe('#2652 dispatch-site parity — isolation gates on capability, not runt
// #2652 review: executor-isolation-dispatch.md declared
// references/dispatch-isolation-gate.md canonical while keeping the OLDER
// collapsing resolver inline — `|| echo "none"`, no ISOLATION_RESOLVED — so a
// transient shim failure aborted /gsd:execute-phase telling a Claude or
// transient shim failure aborted /msd:execute-phase telling a Claude or
// Cursor user their runtime "declares no executor-isolation primitive". Still
// fail-closed, so not an unsafe-dispatch hole, but the correction this PR is
// about was unwired at one of the five sites. Nothing caught it: the emitted
@@ -3196,12 +3196,12 @@ describe('#2652 dispatch-site parity — isolation gates on capability, not runt
// dispatch sites @-reference the gate and merely re-record a degrade
// (`--force-isolation …` with no assignment), which carries no verdict of
// its own — matching those too would flag files that have nothing to fix.
const INLINE_RESOLVE = /\w+=\$\(gsd_run query dispatch-isolation --raw/;
const INLINE_RESOLVE = /\w+=\$\(msd_run query dispatch-isolation --raw/;
// Dedupe: SCAN_ROOTS already yields the gate reference, so appending it
// again made `length >= 2` satisfiable by the gate alone — the executor
// site could drop out of the predicate entirely and this would still pass.
const candidates = [...new Set(
[...dispatchSites, path.join(REPO_ROOT, 'gsd-core', 'references', 'dispatch-isolation-gate.md')]
[...dispatchSites, path.join(REPO_ROOT, 'msd-core', 'references', 'dispatch-isolation-gate.md')]
.filter(f => fs.existsSync(f))
.map(f => path.resolve(f)),
)];
@@ -3214,8 +3214,8 @@ describe('#2652 dispatch-site parity — isolation gates on capability, not runt
assert.deepEqual(
inliners.map(i => i.rel).sort(),
[
'gsd-core/references/dispatch-isolation-gate.md',
'gsd-core/workflows/execute-phase/steps/executor-isolation-dispatch.md',
'msd-core/references/dispatch-isolation-gate.md',
'msd-core/workflows/execute-phase/steps/executor-isolation-dispatch.md',
],
'the set of files inlining the resolver changed — a new inliner needs the same treatment, and a missing one means the predicate stopped seeing it',
);
@@ -3226,7 +3226,7 @@ describe('#2652 dispatch-site parity — isolation gates on capability, not runt
// in the file, so a name-specific pattern passes on a broken block.
assert.doesNotMatch(
text,
/\w+=\$\(gsd_run query dispatch-isolation --raw[^\n]*\|\|[^\n]*echo/,
/\w+=\$\(msd_run query dispatch-isolation --raw[^\n]*\|\|[^\n]*echo/,
`${rel}: collapses a resolver failure straight to none — that reports "declares no primitive" for a host that simply could not be queried`,
);
assert.match(
@@ -3311,7 +3311,7 @@ describe('#2652 dispatch-site parity — isolation gates on capability, not runt
});
test('a RUNTIME read with no isolation decision nearby is NOT flagged (no false positive)', () => {
const benign = 'RUNTIME=$(gsd_run query config-get runtime --raw)\necho "runtime is $RUNTIME"';
const benign = 'RUNTIME=$(msd_run query config-get runtime --raw)\necho "runtime is $RUNTIME"';
assert.deepEqual(isolationGateOffenders(benign, 'benign'), []);
});
@@ -3328,8 +3328,8 @@ describe('#2652 dispatch-site parity — isolation gates on capability, not runt
assert.deepEqual(
offenders,
[],
'isolation must be resolved from `gsd_run query dispatch-isolation` (see ' +
'gsd-core/references/dispatch-isolation-gate.md), never from a RUNTIME comparison:\n' +
'isolation must be resolved from `msd_run query dispatch-isolation` (see ' +
'msd-core/references/dispatch-isolation-gate.md), never from a RUNTIME comparison:\n' +
offenders.join('\n'),
);
});
@@ -3401,7 +3401,7 @@ describe('#2652 dispatch-site parity — isolation gates on capability, not runt
test('quick.md post-dispatch bookkeeping keys on the negotiated ISOLATION value', () => {
const quick = fs.readFileSync(
path.join(REPO_ROOT, 'gsd-core', 'workflows', 'quick.md'), 'utf-8',
path.join(REPO_ROOT, 'msd-core', 'workflows', 'quick.md'), 'utf-8',
);
assert.match(
quick,
@@ -3437,18 +3437,18 @@ describe('#2652 dispatch-site parity — isolation gates on capability, not runt
// variable is precisely what let this class through. `$ISOLATION` was already
// correct at all three sites — `none` — and the defect was entirely in what
// reached the sentinel. So these tests execute each workflow's own degrade
// block under a `gsd_run` stub that captures every call, and assert on the
// block under a `msd_run` stub that captures every call, and assert on the
// value the workflow PUSHED THROUGH THE WRITE PATH.
// ---------------------------------------------------------------------------
describe('#2728 B1 — isolation degrades re-record through the single write path', () => {
const { runHook } = require('./helpers/process-seam.cjs');
// Class-norm timeout, not a local literal (CONTRIBUTING: class-norm
// timeouts live in tests/helpers/timeouts.cjs). This harness is a short
// shell probe against a gsd_run stub — exactly the PROBE class.
// shell probe against a msd_run stub — exactly the PROBE class.
const { PROBE_TIMEOUT_MS } = require('./helpers/timeouts.cjs');
const os = require('node:os');
const WORKFLOWS = path.join(REPO_ROOT, 'gsd-core', 'workflows');
const WORKFLOWS = path.join(REPO_ROOT, 'msd-core', 'workflows');
/**
* Pull the fenced ```bash block containing `marker` out of a workflow.
@@ -3473,18 +3473,18 @@ describe('#2728 B1 — isolation degrades re-record through the single write pat
}
/**
* Run a degrade block with the base-check forced to fire, under a `gsd_run`
* Run a degrade block with the base-check forced to fire, under a `msd_run`
* stub that logs its argv. Returns every `dispatch-isolation` call the block
* made, in order — i.e. the writes that would have hit the sentinel.
*/
function recordedWrites(block) {
const dir = fs.mkdtempSync(path.join(os.tmpdir(), 'gsd-degrade-'));
const dir = fs.mkdtempSync(path.join(os.tmpdir(), 'msd-degrade-'));
const log = path.join(dir, 'calls.log');
// The stub answers the base-check `true` so the degrade path is TAKEN;
// every other query returns empty. It logs the full argv of each call.
const harness = [
'set -u',
`gsd_run() { printf '%s\\n' "$*" >> ${JSON.stringify(log)};`,
`msd_run() { printf '%s\\n' "$*" >> ${JSON.stringify(log)};`,
' case "$*" in',
' *"worktree.base-check"*"shouldDegrade"*) printf true ;;',
' *"worktree.base-check"*"message"*) printf "base diverged" ;;',
@@ -3504,7 +3504,7 @@ describe('#2728 B1 — isolation degrades re-record through the single write pat
// "Spawning a subprocess: use the process seam"). `runHook` documents
// `interpreter: 'bash'` for running a shell script, so the harness is
// written to a file rather than passed as `-c`. Bounded by construction
// (DEFECT.UNBOUNDED-SUBPROCESS): pure shell against a `gsd_run` stub — no
// (DEFECT.UNBOUNDED-SUBPROCESS): pure shell against a `msd_run` stub — no
// git, no network, no real CLI — so it completes in milliseconds.
const scriptPath = path.join(dir, 'degrade-harness.sh');
fs.writeFileSync(scriptPath, harness);
@@ -3601,8 +3601,8 @@ describe('#2728 B1 — isolation degrades re-record through the single write pat
// these two are exempt. The exemption is ASSERTED below rather than assumed,
// so deleting the delegate fails this test instead of silently widening a hole.
const DELEGATED_TO_PER_PLAN_GATE = new Set([
'gsd-core/references/execute-phase-wave-guard.md',
'gsd-core/references/execute-phase-between-wave-reset.md',
'msd-core/references/execute-phase-wave-guard.md',
'msd-core/references/execute-phase-between-wave-reset.md',
]);
const perPlanGate = readFileNormalized(
path.join(WORKFLOWS, 'execute-phase', 'steps', 'per-plan-worktree-gate.md'),