Jakub Zych
a9a7a328e6
refactor: hard-fork GSD -> MSD (Make Software Done)
...
Mechanical rename produced by scripts/msd-rename.cjs: gsd/Gsd/GSD -> msd/Msd/MSD
across contents and paths, upstream package/repo coordinates -> @golem15/msd-core
and golem15com/msd-core. Deep links into upstream history, sibling upstream
packages, the GSD-2 import feature, CHANGELOG.md and .changeset/ are kept as-is.
Hand edits on top: MSD block-letter banner and logos, LICENSE copyright line,
package/plugin identity, regenerated lockfile, install-tree fixtures, derived
registries and benchmark baseline; migration checksum baseline re-locked
(MSD keeps its own install state, so no install had applied the old sums);
sort-order and regex-escaped expectations in tests adjusted.
2026-10-06 01:47:40 +02:00
Tom Boucher
9219af3360
feat( #1433 ): capability trust gate + upgrade/compat (ADR-1244 Phase 4) ( #1449 )
...
ADR-1244 Phase 4 (D5 trust + D6 upgrade/compat). capability-trust.cjs (disclosure/consent, strict_known_registries, engines+compatVersions, reserved namespace) + capability-lifecycle.cjs (install/upgrade/remove/reconcile; ledger-as-commit-point _pending intent; atomic stage-then-swap; surgical marker-isolated shared-edit strip; owner-token lock) + capability-source promote/skipEnginesGate seams + loader pending-skip + config keys. No sandbox re-derived (consent+integrity+reversibility). 6 Codex adversarial rounds + /security-review (no HIGH) + /code-review; gsd-test green both platforms; CI green. Phase 5 (#1434 ) wires the CLI dispatch.
Closes #1433 .
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com >
2026-06-18 21:40:37 -04:00
Tom Boucher
1abb0d3427
feat( #1432 ): capability source resolver + ledger (ADR-1244 Phase 3) ( #1443 )
...
* feat(#1432 ): capability source resolver + ledger (ADR-1244 Phase 3)
ADR-1244 D3 + D4 — additive, testable-in-isolation modules (the /gsd:capability
install command + consent gate are Phase 4). NEW modules only; not yet wired into
bin/install.js.
- src/capability-source.cts → resolveCapabilitySource(spec, opts): one seam, one
adapter per source kind — local (fs copy), git (execGit clone+checkout, https/ssh/
git transports only), npm (execNpm pack --ignore-scripts + tar, NEVER npm install),
tarball (https download + sha512 integrity-before-extraction + tar), registry (stub).
SECURITY: install never executes capability code (copy/extract only, --ignore-scripts);
integrity verified before staging; symlink members rejected at interior, source-root,
AND tar-member (verbose-listing) layers; tar-slip member paths rejected pre-extraction;
npm specs with shell metacharacters (incl %) rejected (execNpm uses a Windows shell);
git ext::/file:// transports + leading-dash/metachar refs rejected; atomic staging
(.staging→rename, restore-on-failure); full Phase 1/2 validator suite + engines.gsd
pre-check on the fetched manifest. Test seam _setCapabilitySourceHttpGet.
- src/capability-ledger.cts → per-runtime .gsd-capabilities.json install manifest:
readLedger/writeLedger (atomic via platformWriteSync)/recordInstall (idempotent,
prototype-pollution-guarded)/removeEntry/reconcile (orphan report, hardened against
hostile/non-string/'..' files[] members — never throws, never oracles outside runtimeDir).
- 48 new tests (34 source incl. the full security matrix, 14 ledger). Two Codex
adversarial rounds; all 12 findings fixed + regression-tested.
- .gitignore + eslint.config.mjs: built capability-source/ledger.cjs git+eslint-ignored
(ADR-457 #551 migration coverage); CONTEXT glossary + INVENTORY rows + manifest regen.
Closes #1432
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com >
* docs(#1432 ): add changeset for capability source resolver + ledger
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com >
---------
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com >
2026-06-18 16:23:20 -04:00