Tom Boucher
288b3b4170
fix(3259): non-mutating --help guard for native query handlers ( #3272 )
...
* fix(3259): non-mutating --help guard for native query handlers; reject --help as milestone version
Adds a dispatcher-level guard in query-dispatch.ts that short-circuits
to a non-mutating help stub whenever --help/-h appears in args destined
for a native mutating handler (fail-closed by default). Adds defense-
in-depth in milestoneComplete to reject --help/-h as a version value
before any disk write. Regression tests cover: per-handler --help guard,
registry-driven invariant across all mutating commands, handler-level
GSDError for both flags, and preservation of the #3019 CJS fallback
contract.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
* chore: add changeset fragment for #3272
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com >
---------
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com >
2026-05-08 23:53:27 -04:00
Tom Boucher
abf7779088
test: cover typed timeout mapping in query dispatch
2026-05-04 21:49:39 -04:00
Tom Boucher
5e21bf7567
Deepen query dispatch seam with Command Topology Module ( #3078 )
...
* Deepen query dispatch seam with command topology module
* Stabilize SDK parity defaults and integration test gating
* docs(architecture): record pre-project config policy and e2e gate
* refactor(query): stop injecting native adapter in CLI dispatch path
* fix(config): align workflow auto-chain typing and docs
2026-05-03 18:11:38 -04:00
Tom Boucher
f104dab332
refactor(query): deepen dispatch policy seam with structured result contract ( #3066 )
...
* refactor(query): deepen dispatch policy seam with structured result contract
Closes #3065 .
- unify query dispatch outcome as typed success/failure union
- include error kind/details + final exit_code in failure path
- align native and fallback paths under one dispatch policy seam
- make CLI query path consume seam result (thin adapter)
- add ADR + context term for Dispatch Policy Module
* refactor(query): strengthen dispatch seam with shared error mapper and typed details
- add query-dispatch-error-mapper module shared by native/fallback paths
- remove ad-hoc inline mapping in dispatch/fallback executors
- lock error-details schema in mapper + dispatch tests
- document structured dispatch contract in QUERY-HANDLERS.md
* fix(query): return structured fallback failure when path resolution throws
- guard resolveGsdToolsPath in cjs dispatch path
- map thrown resolution errors to fallback_failure result
- add regression test for structured failure contract
2026-05-03 14:30:27 -04:00
Tom Boucher
5975f06b6a
refactor(query): extract command catalog seam for registry wiring ( #3060 )
...
* refactor(sdk): extract gsdtools transport seam with per-command policy
* refactor(query): centralize registry command catalog wiring
* refactor(query): unify command resolution seam across sdk callers
* fix(sdk): address CodeRabbit transport policy and timeout findings
* refactor(query): extract mutation event mapper seam
* refactor(query): converge mutation and transport policy data
* refactor(query): share fallback orchestration across cli and sdk
* refactor(query): split static registry catalog by domain clusters
* refactor(query): extract mutation event emission decorator seam
* refactor(query): extract alias-family handler catalog module
* refactor(query): extract cjs fallback execution adapter
* refactor(query): deepen command semantics seam
* refactor(query): extract deep dispatch seam
* refactor(query): deepen cjs fallback execution seam
* refactor(query): merge routing plan into dispatch seam
* fix(query): address CodeRabbit review findings on PR #3060
Critical: prevent double-execution race by checking timeout errors
before subprocess fallback (gsd-transport.ts).
Major: fix execRaw() to respect transport policy outputMode instead
of hardcoding 'raw' (gsd-tools.ts).
Major: add explicit 30s timeout to subprocess fallback execution
(query-fallback-executor.ts).
Major: remove raw args from stderr banner to prevent secret leakage
(query-fallback-executor.ts).
Minor: ensure native text output has trailing newline for CLI parity
(query-dispatch.ts).
Update gsd-tools.test.ts to match new execRaw() behavior.
* fix(tests): update CLI integration tests for catalog-based registration
The refactoring moved handler registration from inline registry.register()
calls to catalog-based registration (registerStaticCatalog/registerAliasCatalog).
- gsd-sdk-query-registry-integration.test.cjs: collectRegisteredNames() now
also scans catalog files for handler names registered via the new system.
- bug-2492-context-coverage-gate.test.cjs: checks for catalog-based
registration (DECISION_ROUTING_STATIC_CATALOG) instead of inline strings.
- bug-2524-sdk-query-ws-flag.test.cjs: checks for dispatchNative callback
pattern instead of direct registry.dispatch() call.
* fix(query): address remaining CodeRabbit review findings
- query-command-semantics.ts: guard stats/progress rewrite so option
tokens (e.g. --pick) are not turned into subcommands, preserving the
top-level handler dispatch.
- query-dispatch.ts: formatOutput now skips --pick for text-format
responses (matching CJS fallback behavior) and surfaces a proper error
when extractField returns undefined instead of silently producing
'undefined'.
- query-dispatch.ts: fix backwards error message — 'registered' is the
restrictive policy that disables fallback, not enables it.
- tests/bug-2492-context-coverage-gate.test.cjs: check
VERIFY_DECISION_STATIC_CATALOG (the correct catalog for plan-gate
handlers) instead of DECISION_ROUTING_STATIC_CATALOG.
- tests/gsd-sdk-query-registry-integration.test.cjs: resolve catalog
variable before loading entries so the drift guard checks each
referenced catalog individually.
* refactor(query): deepen registry assembly module with strict invariants
- extract registry assembly into dedicated module
- split build vs mutation decoration internals
- add strict assembly invariants:
1) no duplicate keys
2) alias canonicals must have handlers
3) mutation commands must be registered
4) raw-output policy commands must be registered
- slim query index to thin re-export seam
- add focused registry assembly tests
- update drift-guard tests to target new seam
* test(query): add thin-seam coverage for query index re-exports
* fix(query): return structured native dispatch errors + tighten decisions.parse guard
- runQueryDispatch native path now catches adapter errors and returns
QueryDispatchResult.error instead of throwing.
- preserve legacy CLI exit contract by using code=1 for native dispatch
failures.
- strengthen bug-2492 guard: decisions.parse assertion now checks
VERIFY_DECISION_STATIC_CATALOG OR explicit command token.
2026-05-03 13:57:32 -04:00