b647f44eb05e544c4edcc0795def26fb4dba3587
2929 Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
b647f44eb0 |
fix(3806): port W005/W006/I001 fixes from validate.ts to verify.cjs (#83)
PR #3479 fixed three false-positive classes in sdk/src/query/validate.ts but the fixes never propagated to get-shit-done/bin/lib/verify.cjs — the hand-maintained CJS runtime bundle that gsd-tools.cjs actually executes. W005: widened phase-dir regex from \d{2} to \d{2,} so 3+-digit prefixes like 999.1-foo are accepted. W006: adds forEachArchivedPhaseToken call after collectDiskPhases so phases whose directories live in a milestone archive are not flagged as missing. I001: adds canonicalPlanStem helper and uses it in summaryBases Set construction so 68-01-scaffolding-PLAN.md correctly matches 68-01-SUMMARY.md. Adds five regression tests (TDD red→green) covering each false-positive path. Fixes #3806 Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> |
||
|
|
2b02786f50 |
fix(3799): detect project-local agents in init.* (local-first resolution) (#82)
* fix(3799): detect project-local agents in init.* (local-first resolution) Reverses resolution order in resolveAgentsDir() so project-local <projectDir>/.claude/agents is checked BEFORE the global runtime dir. Claude Code auto-creates ~/.claude/agents at startup (empty); the old global-first check returned that empty dir over a populated local dir. Adds 5 tests to tests/bug-3751-init-local-agents.test.cjs: - Structural: local-first ordering in function body (#3799 RED gate) - Runtime: local+empty-global → agents_dir = local - Runtime: global-only (no local) → agents_dir = global (no regression) - Runtime: both present → local wins (Claude Code parity) - Updated Contract 3 assertion to reflect new local-first ordering Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * chore: add changeset for fix(3799) Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> --------- Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> |
||
|
|
cda3d7a5ab |
fix(3804): worktree.cleanup-wave rescues uncommitted SUMMARY.md (#81)
* fix(3804): rescue uncommitted SUMMARY.md in executeWorktreeWaveCleanupPlan Ports the shell-fallback SUMMARY rescue logic from quick.md into executeWorktreeWaveCleanupPlan. Before the dirty-state check, all *SUMMARY.md files under <worktree>/.planning/ are copied to the main tree (if absent or divergent), then filtered out of the git-status porcelain output. A worktree whose only dirty file is the executor's uncommitted SUMMARY.md now proceeds to merge+remove instead of returning cleanup_blocked/worktree_dirty. Adds two TDD tests (#3804): - Rescue-only dirty state (SUMMARY.md alone) → cleanup succeeds - SUMMARY + non-SUMMARY dirty files → cleanup still blocks Refs: #2296, #2070, #2838, #3804 Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(3804): normalize relPath to forward slashes for Windows porcelain match On Windows, `path.join` produces backslash separators while `git status --porcelain` always emits forward slashes. The rescued-paths Set would never match porcelain output, causing the dirty-check filter to ignore SUMMARY rescue and block cleanup on Windows. Also normalize the test assertion for `rescued[0].dest` to use forward slashes so the test passes on both platforms. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> --------- Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> |
||
|
|
3c6bf06679 |
Merge pull request #112 from gsd-redux/fix/ruleset-context-order
fix(rulesets): correct status-check context order (os, node) |
||
|
|
b6ead21971 |
fix(rulesets): correct status-check context order (os, node)
The GitHub Actions matrix in test.yml is ordered {os, node-version},
so matrix-derived check contexts are 'test (<os>, <node>)'. The
ruleset specs had the inverse, so the required_status_checks rule
silently watches for names that never appear in any check run.
In evaluate mode this is a no-op; flipping to 'active' without this
fix would deadlock every PR.
Closes #111
Refs #107
|
||
|
|
00a47e34fd |
Merge pull request #110 from gsd-redux/chore/ci-skip-tests-on-docs
ci: skip full test matrix on doc-only PRs (PR-2 of 4) |
||
|
|
7d2d2ac838 | docs: cross-link announcement #109 from README top | ||
|
|
3d80494e31 |
ci: skip full test matrix on doc-only PRs (PR-2 of 4)
Adds path filter to test.yml so the 6-lane matrix only runs on code changes. New test-skip.yml fires on the inverse paths and emits noop jobs with identical names so the required status checks (lint-tests + 6x test (...)) are satisfied regardless of which workflow ran. Doc-only PRs now complete CI in <30s. Canonical code-paths list mirrors changeset-required.yml; keep them in sync (documented in docs/branch-protection.md). Closes #108 Refs #107 Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> |
||
|
|
cc208b350a |
Merge pull request #106 from gsd-redux/chore/branch-protection-specs
chore: add branch protection ruleset specs (PR-1 of 3) |
||
|
|
aac93329a7 |
chore: replace CODEOWNERS reviewers (PR-1 of 3)
Replaces legacy @glittercowboy entry with the active reviewer pool: @trek-e, @Solvely-Colin, @jeremymcs. CODEOWNERS is advisory only — the main-protection ruleset does not require CODEOWNERS approval (required_approving_review_count: 0). |
||
|
|
df41d500a4 |
fix(rebrand): update forensics test regexes to new repo slug
The rebrand commit
|
||
|
|
9f9c1a7909 |
chore: add branch protection ruleset specs (PR-1 of 3)
Checks in JSON specs for three rulesets (main-protection, release-branches, tag-immutability), a CODEOWNERS file (advisory), and scripts/sync-rulesets.sh to apply them. Enforcement is `disabled` in all three files — PR-2 will apply with `evaluate` for a 1-week dry-run, PR-3 will flip to `active`. See docs/branch-protection.md for the full rollout plan. |
||
|
|
dff176bfd2 |
chore: rebrand to GSD-redux/get-shit-done-redux
Mirror of code, issues, and PRs from the upstream gsd-build/get-shit-done, which appears compromised or abandoned (maintainer unreachable since 2026-04-01; $GSD token linked to rug-pull). - Adds rebrand notice block at top of English README - Removes $GSD token badge and @gsd_foundation X badge (keeps Discord) - Renames npm packages: get-shit-done-cc -> get-shit-done-redux, @gsd-build/sdk -> @gsd-redux/sdk - Updates all repo URLs across docs, workflows, package.json, bin/ - Updates ci@gsd-build -> ci@gsd-redux in workflow git identities - Leaves CHANGELOG and .changeset/* alone (historical, time-stamped) |
||
|
|
e1582a5f1b | Remove funding information from FUNDING.yml | ||
|
|
b533f71857 |
chore: introduce CommandRoutingHub and migrate phase-command-router (PoC) (#3828)
* feat(routing): add CommandRoutingHub with behavioral test suite (#3788) Introduces createHub({ mode, sdkLoader, cjsRegistry, manifest }) and hub.dispatch({ family, subcommand, args, cwd, raw }) -> Result with a closed 6-value ERROR_KINDS frozen enum. Hub never throws, never prints, and enforces no transparent fallback between sdk/cjs modes. 34 behavioral tests cover all errorKind values, mode fixation, and the no-throw contract. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * refactor(routing): migrate phase-command-router to CommandRoutingHub (#3788) Rewrites phase-command-router.cjs to dispatch through CommandRoutingHub. Public entry point routePhaseCommand({ phase, args, cwd, raw, error }) is unchanged. The adapter determines mode (sdk/cjs) from env + tryLoadSdk(), constructs a hub, dispatches, and translates the pure Result back to output()/error() calls. New behavioral test suite (23 tests) replaces the old mock-heavy approach and includes two integration tests through the real hub. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * docs(routing): ADR + glossary + changeset for CommandRoutingHub (#3788) Adds ADR-3788 documenting the hub's design contract (pure result, fixed mode, closed 6-value errorKind enum, no transparent fallback). Adds Command Routing Hub glossary entry to CONTEXT.md and a one-paragraph reference to ARCHITECTURE.md. Changeset fragment records the Changed entry. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(docs): rename ADR to sequential convention 0012 (#3788) Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * docs(inventory): register CommandRoutingHub in INVENTORY (#3788) Add command-routing-hub.cjs row to docs/INVENTORY.md CLI Modules table, bump headline count from 72 to 73, and regenerate INVENTORY-MANIFEST.json via scripts/gen-inventory-manifest.cjs --write. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * docs(adr): add 0012 to ADR index (#3788) Add entry for 0012-command-routing-hub.md to the index table in docs/adr/README.md so the enh-3271-sdk-adr-structure lint passes. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * chore(lint): bump phase test-file ceiling to accommodate command-router suite (#3788) phase-command-router.test.cjs added by the CommandRoutingHub migration pushes the phase prefix cluster from 4 to 5 test files. Bump the allowlist ceiling from 4 to 5 (issue 3788) so lint-test-file-count passes. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(routing): preserve phase.mvp-mode JSON error and ROADMAP scan through hub (#3788) mvp-mode was never registered in the SDK; the pre-#3788 CJS router always dispatched it via the CJS handler even when sdkAvailable was true. After the hub migration, SDK-mode hubs (Docker, where the SDK build exists) sent mvp-mode to the SDK bridge, which returned SdkDispatchFailed with reason 'unknown' instead of the expected 'usage' code, and failed ROADMAP lookups. Fix by short-circuiting mvp-mode to the CJS handler before hub construction, matching the pre-migration observable behaviour. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * docs(adr): note SDK-incomplete subcommand limitation in ADR-0012 (#3788) * fix(inventory): bump CLI Modules headline to 74 after rebase onto main (#3788) Upstream added code-review-flags.cjs (72→73) at the same time our branch added command-routing-hub.cjs. After rebase both modules exist (74 total) but the headline stayed at 73; bump to 74. * fix(routing): remove dead mvp-mode handler from cjsRegistry (#3788) The cjsRegistry['phase']['mvp-mode'] handler (previously lines 65–68) was unreachable: the early-return bypass at line 56 intercepts mvp-mode before hub construction in CJS mode, and in SDK mode cjsRegistry is passed as undefined. Remove the dead handler; all 57 tests still pass. * docs(adr): correct router count in ADR-0012 (#3788) The context section cited "eight" routers including "frontmatter" but there is no frontmatter-command-router.cjs. The actual count is seven: phase, phases, roadmap, state, verify, validate, init. * fix(routing): guard missing subcommand + use ERROR_KINDS constant (#3788) Two fixes in phase-command-router.cjs: 1. Add early-return for missing subcommand before hub construction. Pre-#3788 the routeCjsCommandFamily fell through to error() for undefined args[1]; post-#3788 the hub's manifest check skips falsy subcommands, which would have sent bare 'phase' into SDK dispatch in SDK mode instead of the expected "Available: ..." error message. 2. Switch on ERROR_KINDS.UnknownCommand instead of bare 'UnknownCommand' string, per ADR-0012's closed-enum contract ("callers switch on ERROR_KINDS values, not bare string literals"). * docs(routing): fix factual errors in ARCHITECTURE, ADR-0012, changeset (#3788) Three corrections: 1. ARCHITECTURE.md: softened "All CJS command family routers dispatch through CommandRoutingHub" — only phase-command-router.cjs is migrated in this PR; remaining routers still use routeCjsCommandFamily and migrate in follow-up issues. 2. ADR-0012: corrected the SDK mvp-mode claim. The ADR said "the SDK has no equivalent entry" but sdk/src/query/command-static-catalog- domain.ts:104-105 registers phase.mvp-mode. The actual reason for the early-return bypass is divergent ROADMAP scan behaviour and error reason codes, not SDK absence. 3. .changeset/mellow-tigers-gather.md: corrected pr: 1 → pr: 3828. --------- Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> |
||
|
|
420c64da4b |
test(3646): add routing-block hyphen-form regression tests for workflow templates (#3800)
* test(3646): add routing-block hyphen-form regression tests for workflow templates Extends bug-3683-workflow-colon-namespace-leak.test.cjs with a new R suite that asserts the specific user-facing symptom from #3646: ▶-prefixed routing lines in installed workflow files (validate-phase.md, secure-phase.md) must use /gsd-<cmd> hyphen form and must not contain the /gsd:<cmd> colon form. The R suite adds positive-assertion coverage that the prior W suite lacked: W3 checks absence-of-colon globally; R1/R2/R3 check that routing-position strings (▶-marker lines) are present AND use the correct hyphen form — the distinction that makes this a behavioral install-contract test rather than a source-grep. Verified the new tests FAIL when normalizeAgentBodyForRuntime is disabled (the pre-fix state) and PASS with the fix in place. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * test(3646): fix Windows parity — use /\r?\n/ in routing-line splitters Replace .split('\n') with .split(/\r?\n/) in the two new R-suite helpers so Windows CRLF checkouts (autocrlf=true) don't produce trailing \r on ▶-prefixed routing lines, which would break the startsWith('▶') filter. Caught by tests/windows-test-parity-guard.test.cjs ratchet baseline. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * chore: add changeset for PR #3800 (#3646 routing-block regression tests) Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * test(3646): tighten token-level assertions — check embedded colons in /gsd tokens Codex adversarial review found that R1/R2/R3 only checked for /gsd:<cmd> (colon immediately after gsd), leaving a gap where /gsd-validate:phase would pass all tests. Add token-level assertion: extract all /gsd[^\s]* tokens from ▶-prefixed routing lines and assert none contain an embedded colon. This catches any token where normalisation only partially converted the colon form. Documentation placeholder lines like /gsd-[command] are not affected because the placeholder token /gsd-[command] contains no colon. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * test(3646): consolidate dual Claude install into shared fixture to stop TOCTOU interference W and R suites both ran runClaudeLocalInstall in separate before() hooks, adding two concurrent heavy-install operations per test-file run. Under --test-concurrency=4 on Node 22 (ubuntu/windows), this extra disk I/O starved the barrier-based TOCTOU concurrency test in locking-bugs-1909-1916-1925-1927.test.cjs, causing its timing- sensitive barrier to release unevenly and let one subprocess complete before the other, producing a false lost-update failure. Fix: lift the Claude install to a single shared claudeTmpDir at the outer describe level so W and R share one install. Gemini suite (G) is unaffected and keeps its own install. All 11 tests in the file pass; TOCTOU tests unaffected. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(3646): address review — fix changeset misclassification, remove false Windows-parity claim, tighten R-suite assertions - F1: Reword changeset from "Fixed/now emit" (implies behavior change) to "patch" + test-only description (accurate: normalizer already shipped in #3685) - F4: Tighten R3 comment to document unique value vs W3: ▶-line scope + embedded-colon token check - F5: Extend R3 sweep to include references/ dir alongside workflows/ - F6: Change R1/R2 assert.ok(length >= N) to assert.strictEqual(length, N) so line removals surface immediately - F7: Update inline comments in R1/R2 and before() hook to match strictEqual semantics; add sub-suite dependency list to before() Reviewed-by: gsd-code-reviewer, sonnet-adversarial Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(3800): correct changeset type from invalid 'patch' to 'Fixed' docs-lint rejects the fragment because 'patch' is not an ALLOWED_TYPES value; 'Fixed' is the correct label for a regression-test addition with no user-visible behavior change. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> --------- Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> |
||
|
|
5e071a329e |
fix(3775): clarify deterministic design note and sentinel guard rationale (#3793)
The test was restructured in #3726 to eliminate wall-clock polling. This commit adds the #3775 cross-reference to the design note (Docker intrinsic subprocess cost 900–1700ms vs deadline) and documents why `callsSinceWarn: 10` uses 2× DEBOUNCE_CALLS for resilience. Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> |
||
|
|
c22e869bec |
test: redesign locking-bugs:180 with deterministic barrier (mirrors :235 fix) (#3790)
Previous design relied on OS scheduler to interleave two subprocess writes. Redesigned using Atomics.wait file-barrier pattern (matches the redesign on PR #3764 for line 235) to guarantee real concurrent lock contention every run. Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com> |
||
|
|
2d3027767b |
fix(3426): Codex Windows hooks use .cmd shim to avoid POSIX exec fail (#3768)
* test(#3426): add RED test for Codex Windows hooks .cmd shim requirement Drive buildCodexHookWindowsShimIR (typed IR) + ensureCodexHooksJsonSessionStart integration against mocked win32 platform. Counter-tests confirm darwin/linux paths remain unchanged. NOTE: Windows wall-clock verification depends on Docker matrix Windows runners. Local test exercises the generator IR shape only. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(#3426): Codex Windows hooks use .cmd shim to avoid bash.exe POSIX-exec failure Root cause: Codex on Windows runs hook commands from PowerShell/cmd. The previous hooks.json command format was `"node.exe" "script.js"`. Codex's hook-dispatch shell (Git Bash / MSYS) tried to POSIX-exec node.exe (a Windows PE binary) via execvp(), which fails with ENOEXEC — reported as `bash.exe: cannot execute binary file`. Fix: `ensureCodexHooksJsonSessionStart` now calls `buildCodexHookWindowsShimIR` on win32 to write a .cmd shim alongside the .js hook file. cmd.exe executes .cmd files natively via CreateProcess, bypassing the POSIX exec layer entirely. Non-Windows paths (darwin, linux) are unchanged: they continue to use the node-runner command. Also adds `gsd-check-update.cmd` to the codex-hooks-json managed-basename set so reconcileCodexHooksJsonSessionStart correctly replaces stale node-runner entries on reinstall. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * chore(3426): update changeset to reference PR #3768 * fix(3426): fail-loud on Codex Windows shim-write failure instead of silently restoring broken command Replace the silent fallback to `projectManagedHookCommand` (the old `node.exe script.js` form) with an explicit warn-and-skip path. When `atomicWriteFileSync` fails to write the `.cmd` shim, the previous code silently called `reconcileCodexHooksJsonSessionStart` with the legacy node-runner command. That command triggers the exact `bash.exe: cannot execute binary file` POSIX-exec failure that #3426 exists to fix — so a successful-looking install was secretly restoring the original bug. New behaviour: - Emit `console.warn` with the failure reason and a remediation hint, matching the `${yellow}⚠${reset} Skipped …` idiom used at line 9098. - Return `{ changed: false, wrote: false }` to skip registration for this runtime entirely, so the outer caller can surface "NOT installed" instead of "installed (but broken)". Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * test(3426): typed-IR assertions on .cmd shim eol/quoting/passthrough + IR extension Extend `buildCodexHookWindowsShimIR` to expose two new typed fields on the returned IR object (CONTRIBUTING.md L558-L565 IR-first discipline): eol: { cmd: '\r\n' } — CRLF is canonical for cmd.exe .cmd files passthroughArgs: true — shim forwards all args via %* Add a new describe block (Step 2b) with three IR-level assertions: 1. `eol.cmd === '\r\n'` — prevents silent EOL regression that could break parsing on Windows versions that require CRLF. 2. `invocation.target` is the raw unquoted path (no shell-metachar leakage) — quoting happens only at render time. 3. `passthroughArgs === true` — the %* forwarding contract is explicitly typed so regressions fail before the text is rendered. All assertions operate on the typed IR returned by the generator, NOT on the rendered `.cmd` file content — text-matching is the anti-pattern CONTRIBUTING.md L522-582 prohibits. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * test(3426): fix Windows CI failures — update hook-command filter patterns Four test files filtered for managed hooks in hooks.json using the literal string `gsd-check-update.js`. On Windows the PR-introduced .cmd shim changes the hooks.json command to `"path/gsd-check-update.cmd"` (no node prefix, .cmd extension), so those filters matched 0 entries and 24 Windows subtests failed. Fixes: - bug-2760-codex-install-defensive.test.cjs (7 filters): change `/gsd-check-update\.js/` → `/gsd-check-update/` to match both .js (POSIX) and .cmd (Windows) commands. - bug-3357-codex-legacy-hooks-json-migration.test.cjs (3 filters): same `.js` → no-extension change. - bug-3427-3433-codex-install-shape.test.cjs (2 filters): same fix; add explanatory comment to uninstall assertion. - codex-config.test.cjs (9 filters + 1 exact-command assertion): bulk-replace all `hooksJsonCommands.filter(cmd => cmd.includes('gsd-check-update.js'))` with `gsd-check-update`; make the `fresh CODEX_HOME` test platform- aware — on win32 assert `.cmd` shim path, on POSIX assert the existing `"runner" "script.js"` form (#3017). All four suites pass locally (macOS / darwin). Windows subtests verified against the Windows CI failure log patterns. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix(3426): address pr-review-toolkit + codex review findings - fix(uninstall): add gsd-check-update.cmd to gsdHooks cleanup list so the .cmd shim is removed from disk on Windows uninstall (was left as orphan artifact — silent failure post-uninstall) - test(3426): add uninstall test asserting gsd-check-update.cmd is deleted from hooks dir after `uninstall(true, 'codex')` (no coverage existed) - fix(comment): correct JSDoc on buildCodexHookWindowsShimIR — shim content is three-line @ECHO OFF/@SETLOCAL/@runner snippet, not bare `@node "script.js" %*` as the old comment claimed - fix(comment): update stale assertion message in codex-config.test.cjs L1457 — said "config.toml references it" but the hook is in hooks.json Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> --------- Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> |
||
|
|
a7abc6df2f |
fix(3657): skip false-fail when pristine hash drifts after GSD update (#3767)
* test(3657): RED+shape-lock for verify-reapply-patches pristine-drift Adds tests/bug-3657-verify-reapply-patches-pristine-drift.test.cjs: - Core regression: exits 0 with reason=OK_PRISTINE_DRIFT_DETECTED when on-disk gsd-pristine/ hash does not match backup-meta.json.pristine_hashes - Counter-tests: real FAIL_USER_LINES_MISSING still caught when hashes match; over-broad mode unchanged when backup-meta.json is absent; clean run reports 0 failures when everything matches - Multi-file: drift + real-failure handled independently per file Updates tests/bug-2969-verify-reapply-patches.test.cjs REASON shape-lock to include OK_PRISTINE_DRIFT_DETECTED (added by the #3657 fix). Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(3657): verify-reapply-patches skips pristine when hash drifts When gsd-pristine/ is refreshed to a newer GSD version after a backup is captured, the on-disk pristine's SHA-256 no longer matches the hash recorded in backup-meta.json.pristine_hashes. Using the wrong-version pristine as the diff baseline inverts the delta: every line the upstream removed between the two versions appears as a "user-added line that must survive", producing spurious FAIL_USER_LINES_MISSING false positives (Bug #3657). Fix: - Add sha256() and readPristineHashes() helpers to verify-reapply-patches.cjs - In verifyFile(), when a pristine_hashes entry exists for the file, compare the on-disk pristine's SHA-256 against it before accepting the baseline - On hash mismatch, return immediately with status=ok and the new REASON.OK_PRISTINE_DRIFT_DETECTED code, skipping the diff rather than false-failing - When no pristine_hashes entry exists (older installer / absent backup-meta), fall through to the pre-fix behaviour (use on-disk pristine as-is) - Export sha256, readPristineHashes, and OK_PRISTINE_DRIFT_DETECTED New REASON code OK_PRISTINE_DRIFT_DETECTED is added to the frozen enum. Exit code contract is unchanged: 0 for gate pass (including skipped-due-drift files), 1 for real user-content failures, 2 for structural errors. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * chore(3657): update changeset to reference PR #3767 * fix(3657): surface drifted_files in verify-reapply-patches JSON report Extend the top-level JSON report shape with two additive fields: - `drifted: N` — count of files skipped due to pristine-snapshot drift - `drifted_files: [...]` — relative paths of those files Per-file shape is unchanged (status:'ok' + reason:OK_PRISTINE_DRIFT_DETECTED) for backward compat. Drift still exits 0; `failures` count is unaffected. This gives workflow Step 5a structured data to gate on so drifted files are no longer silently treated as a full PASS (codex adversarial-review finding 1). Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(3657): reapply-patches workflow halts on drifted files instead of silent pass Insert a "Step 5a: drift check" block between the exit-code check and the failures check in workflows/reapply-patches.md Step 5a. The new block: 1. Parses `drifted` + `drifted_files` from the JSON report (added in the companion prod-code commit). 2. When DRIFTED_COUNT > 0, emits a formatted HALT message naming each drifted file and instructs the user to re-baseline before re-running. 3. Sets DRIFT_DETECTED=true and exits non-zero so subsequent steps cannot execute while drift is unresolved. Drift is a distinct third state: it is not a failure (no missing user lines were proven) but it is also not a clean pass (the diff was skipped entirely). Existing pass/fail logic for VERIFY_STATUS and failures count is unchanged. Closes the silent-skip gap identified in codex adversarial-review finding 1. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * test(3657): assert drifted_files report shape + workflow Step 5a drift check Finding 1 (BLOCKER) — three new tests in bug-3657 test file: - Single drifted file: drifted=1, drifted_files contains the file path, failures=0, per-file shape unchanged (backward compat). - Multi-file drift: drifted=2, drifted_files lists both paths, clean file absent from array. - No-drift baseline: drifted=0, drifted_files=[] always present in output. Finding 2 (WARNING) — structural test on workflow source: - Asserts Step 5a contains "Step 5a: drift check" heading. - Asserts DRIFTED_COUNT, drifted_files, and DRIFT_DETECTED are referenced (confirming the gate exists and uses the structured report fields). - Asserts drift-check block appears before VERIFY_STATUS check (exit-code is 0 for drift, so the drift check must precede the non-zero gate). Also updates bug-2969 shape-lock to include the two new additive fields (drifted, drifted_files) per the contract change in the prod-code commit. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(3657): address pr-review-toolkit + codex review + CI failures - lint-tests: add // allow-test-rule: source-text-is-the-product at file top of bug-3657 test file; the inline comment at line 477 was a prose sentence, not a file-level annotation, so the lint scanner did not recognise it as the bypass token - Windows test failures (4 subtests): normalize relPath to forward slashes before pristineHashes key lookup in verifyFile(); on Windows path.join produces backslash-separated relPath values but backup-meta.json stores keys with forward slashes, causing the hash lookup to silently return undefined, falling through to use-as-is mode and producing the same false FAIL_USER_LINES_MISSING that the fix was meant to prevent Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(tests): bump verify allowlist ceiling 9→10 for bug-3657 test file Adding tests/bug-3657-verify-reapply-patches-pristine-drift.test.cjs in the previous commit pushed the verify module from 9 to 10 test files. The lint-test-file-count gate (added in #6313baad on main) enforces that modules cannot exceed their allowlist ceiling, so all 6 test platforms plus lint-tests and coverage failed with: FAIL_EXCEEDS_ALLOWLIST: verify count=10 ceiling=9 The fix is to raise the ceiling from 9 to 10 and set issue=3767. This file does not exist on this branch yet (introduced on main after the branch diverged) so we add it here. The merged CI state will see the bumped ceiling and pass. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> --------- Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> |
||
|
|
99b52a302a |
fix(3659): applySurface prunes skill dirs on cluster disable (#3766)
* test(3659): add regression tests for applySurface skill-dir pruning on cluster disable Tests that applySurface with claude global scope correctly prunes ~/.claude/skills/gsd-STEM/ dirs for disabled clusters, preserves gsd-STEM dirs in enabled clusters, leaves non-gsd user dirs untouched, and is idempotent across two consecutive calls. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(3659): applySurface now prunes ~/.claude/skills/gsd-STEM/ on cluster disable Root cause: surface.md directed the AI to use RUNTIME_CONFIG_DIR=~/.claude/skills (the skills sub-directory) instead of the base Claude config dir (~/.claude). When runtimeConfigDir=~/.claude/skills and scope=global, the layout computes dest=~/.claude/skills/skills — the wrong target — so pruning never reached the actual gsd-STEM dirs in ~/.claude/skills/. Fix: - surface.md: correct RUNTIME_CONFIG_DIR to use the base config dir (~/.claude), add explicit SCOPE=global, and update all path references in execution_context. Surface state file moves from ~/.claude/skills/.gsd-surface.json to ~/.claude/.gsd-surface.json, matching install/uninstall conventions. - surface.cjs: extract pruneSkillDirs() as a shared helper (single point of truth for gsd-STEM dir removal). _syncGsdDir now delegates to it instead of having the ownership/prune logic inline. Export pruneSkillDirs for callers that need stand-alone pruning without a full applySurface pass. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * chore(3659): update changeset to reference PR #3766 * fix(3659): manifest-membership gate on pruneSkillDirs prevents user gsd-* dir data loss Finding 1 (CRITICAL): the prefixed branch previously deleted any on-disk dir that matched the 'gsd-' prefix and was not in retainedNames. A user-created gsd-mything/ would be silently destroyed. Fix: deletion now requires BOTH prefix match AND manifest membership (stem present in manifest). Dirs that match the prefix but are not manifest-known are preserved with a process.stderr warning so the user knows the dir was kept. Finding 2 (type guard): the Hermes (empty-prefix) branch passed manifest directly to new Set([...manifest.keys()]) without verifying it is actually a Map. A truthy non-Map would throw. Fix: safeManifest = (manifest instanceof Map) ? manifest : null, used in both branches. Non-Map manifest triggers the same conservative no-deletions path already used when manifest is absent. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * test(3659): counter-test for all-clusters-disabled + user gsd-* dir preservation Finding 3: add test (e) that disables every cluster (Object.keys(CLUSTERS)) and asserts three things: 1. All GSD-owned skill dirs (gsd-explore/, gsd-help/) are removed. 2. Non-gsd user dir (my-custom-skill/) is preserved. 3. User-created gsd-mything/ (prefix match, not in manifest) is preserved — this is the critical regression guard for the Finding 1 data-loss fix. Also update the existing _syncGsdDir skills-kind test in surface-apply.test.cjs to pass a manifest that declares old-skill as GSD-owned. Without a manifest the new conservative path correctly preserves all unknown gsd-* dirs, which broke the pre-existing no-manifest assertion; supplying the manifest restores the expected pruning behavior and documents the required calling contract. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(3659): address pr-review-toolkit + codex review findings - Collapse redundant if/else in _syncGsdDir - Collapse duplicate canonicalStems branches in pruneSkillDirs - Update stale module-header comment (config-dir root) - Clarify dead isGsdOwned guard comment - Log rmSync failures to stderr - Add pruneSkillDirs to module-header Exports JSDoc - Remove unused imports in bug-3659 test file Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> |
||
|
|
172e6920eb |
fix(3670): break migration lock self-deadlock on Windows (#3765)
* test(installer): add regression tests for #3670 migration lock self-deadlock - T1: same-process PID re-entry reclamation (primary regression) - T2: dead-PID stale lock reclamation - T3: unlinkSync EPERM surfaces (not silently swallowed via force:true) - T4: counter-test — normal round-trip still works - T5: counter-test — genuinely-held live lock still errors clearly - Update existing 'reports lock release failures' test to mock fs.unlinkSync (not fs.rmSync) matching the fixed release path Windows wall-clock deadlock repro depends on Docker matrix Windows runners. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(installer): break migration lock self-deadlock on Windows (#3670) Root cause: `acquireInstallMigrationLock` release closure called `fs.rmSync(lockPath, { force: true })`. On Windows NTFS, a file recently closed via `closeSync(fd)` may still return EPERM from `unlink` until the OS fully releases the handle. The `force: true` flag silently swallows EPERM, leaving the lock file on disk. The subsequent `runInstallerMigrations` call in the same install() invocation hits EEXIST, spins for 30 s, then throws "installer migration lock is held". Fix: 1. Release closure uses `fs.unlinkSync` (not rmSync+force) so EPERM propagates via releaseError instead of being swallowed. 2. `acquireInstallMigrationLock` closes the fd before writing the payload (path-based write), eliminating the open handle that caused the deferred EPERM on Windows. 3. Stale-lock reclamation: on EEXIST, parse the on-disk PID and reclaim immediately if it matches process.pid (same-process re-entry, the primary #3670 failure mode) or if the PID is dead (ESRCH). Live alien PIDs still trigger the 30 s timeout. 4. Error message on a genuinely-held lock now includes the holder PID and acquiredAt timestamp for operator diagnostics. No public API change. All callers of runInstallerMigrations are inside installer-migrations.cjs and bin/install.js. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * chore(3670): update changeset to reference PR #3765 * fix(3670): timeout on reclaim-unlink failure to prevent spin-loop regression When unlinkSync throws (e.g. Windows EPERM on an open handle) in the same-PID / dead-PID reclamation path, the original code continued unconditionally — bypassing the timeout check and reintroducing the exact deadlock the PR is supposed to fix. Guard the continue behind a `reclaimed` flag: only loop back to openSync if unlink SUCCEEDED. On failure, fall through to the existing bounded sleep + timeout, which surfaces "installer migration lock is held" within lockTimeoutMs instead of spinning indefinitely. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * test(3670): tighten T5 — assert bounded failure when reclaim unlink fails on live lock The old T5 accepted BOTH success and throw, which allowed over-reclamation of a genuinely un-reclaimable lock to pass undetected. Rewrite T5 to force deterministically unreclaimable conditions: - Pre-seed lock with process.pid (triggers isSameProcess path) - Mock fs.unlinkSync via mock.method() to throw EPERM for the lock file With the production fix: reclaimed=false → falls through to timeout → throws "installer migration lock is held" within ~200ms. Without the production fix: unlink throws but continue runs anyway → process spins and eventually OOMs (confirmed RED: 136s runtime, V8 heap exhaustion from infinite readLockFile + new Error() allocations). assert.throws() now makes success a hard failure, closing the over-reclamation gap. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(3670): clean up orphan lock file when writeFileSync fails after closeSync If closeSync(fd) succeeds (fd=null) but the subsequent writeFileSync throws, the empty lock file was left on disk. readLockFile returns null for an empty/invalid-JSON file, so the stale-lock reclamation path skips it, causing the next acquire attempt to spin to timeout. Track ownership with lockCreatedByUs flag; add a second cleanup branch in the catch block for the fd-already-closed case. Also fix changeset body to use the bold-prefix format required by all other fragments in .changeset/. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> --------- Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> |
||
|
|
49dcabff26 |
fix(3749): port strategy-branch switching to SDK commit handler (#3763)
* test(3749): add RED test — SDK commit handler missing strategy-branch port Structural assertions on sdk/src/query/commit.ts verify the branching-strategy block (phase/milestone) is present. 9 tests fail today; pass after the fix. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(3749): port PR #1279 strategy-branch logic from CJS to SDK commit handler sdk/src/query/commit.ts lacked the branching-strategy block that PR #1279 added to commands.cjs:285-320. Pre-execution workflow commits (discuss-phase, plan-phase) with branching_strategy:"phase" or "milestone" were landing on whatever branch was active rather than the configured strategy branch. Changes: - sdk/src/query/phase.ts: export findPhaseByNumber() so commit.ts can look up a phase without going through the QueryHandler dispatch stack - sdk/src/query/commit.ts: import loadConfig, findPhaseByNumber, getMilestoneInfo; add ensureStrategyBranch() helper (extracts the logic, preserving SRP); call it between the commit_docs check and the staging step Semantics match the CJS path exactly: best-effort (errors are swallowed so a misconfigured branching_strategy never aborts a commit), same phase-number extraction from file paths, same checkout -b / checkout fallback sequence, same current-branch guard to avoid repeated checkout calls. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * chore(3749): update changeset to reference PR #3763 * fix(3749): validate phase_branch_template before substitution Before this commit, a missing or empty `phase_branch_template` (or `milestone_branch_template`) would cause `.replace()` to throw inside the try-block, which was swallowed by the surrounding catch → silent strategy-skip with no observable signal. Exports `validateBranchTemplate(template)` as a pure helper that checks the template is a non-empty string BEFORE any `.replace()` call is attempted. Also exports `resolveStrategyBranchName(template, phaseNumber, phaseSlug)` which validates that no `{placeholder}` tokens survive substitution. Both an invalid template and an unresolved-placeholder result now return `{ ok: false, reason: '...' }` from `ensureStrategyBranch`, surfaced distinctly — satisfying the no-silent-skip contract (codex finding 3). Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * test(3749): replace source-includes with typed-IR assertions on extracted helpers The original test file used `source.includes(...)` throughout — grep theater that verifies text presence, not behavior (codex finding 4 / test-rigor Contract 1 violation). This commit upgrades the test suite: 1. Typed-IR unit tests (ts-node, skipped gracefully when unavailable): - `parsePhasesFromFiles`: empty, single-phase, mixed-phase, dotted phase numbers, root numeric tokens - `validateBranchTemplate`: undefined, empty, whitespace, valid - `resolveStrategyBranchName`: well-formed, unresolved placeholder, slug fallback 2. Structural assertions (retained and tightened) now verify: - Named exports of the three helpers exist (enabling typed-IR tests) - Caller halts on `strategyResult.ok === false` (Finding 2) - Mixed-phase rejection message contains "single phase" (Finding 1) - Template validation precedes resolveStrategyBranchName in source (Finding 3, using lastIndexOf to skip helper definitions) - `alreadyExists` guard and `branch_switch_failed` reason present (Finding 2) Old structural tests that verified implementation tokens (loadConfig, phase_branch_template, --abbrev-ref, etc.) are retained as they verify observable contracts, not code style. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(3749): bug-2767 tests skip cleanly when sdk/dist is absent (was hard-fail) The 4 behavioral tests in bug-2767-gsd-sdk-commit-files-flag.test.cjs invoke the built SDK CLI (sdk/dist/cli.js) end-to-end. When that dist is absent, they threw MODULE_NOT_FOUND and were reported as 4 hard failures rather than observable skips. Apply the same `if (!existsSync(SDK_CLI)) { t.skip(...); return; }` guard already used in bug-3019-help-passthrough.test.cjs. When dist is present, all 4 tests run and pass. When dist is absent, all 4 emit a ﹣ skip line with an actionable reason ('run `cd sdk && npm run build`'), leaving 0 hard failures and maintaining full observability. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(3749): address pr-review-toolkit + codex review findings - Add allow-test-rule annotation to satisfy lint-no-source-grep - Remove dead identifiers (registerScript, tsConfigPath, os import) - Standardize issue #1278 / PR #1279 references in JSDoc - Document root-level phase-number false-positive in parsePhasesFromFiles - Generalize resolveStrategyBranchName parameter naming (phase + milestone reuse) - Add behavioral integration test for commit handler with branching_strategy: phase Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix(3749): normalize extracted phase token in phaseTokenMatches parsePhasesFromFiles extracts "1" from a path like ".planning/phases/1-setup/PLAN.md". normalizePhaseName pads this to "01" before passing it to searchPhaseInDir, which calls phaseTokenMatches("1-setup", "01"). extractPhaseToken("1-setup") returned "1" (raw, unpadded), so "1" !== "01" and the phase directory was not found — ensureStrategyBranch fell through with "phase not found" and never switched the branch. Fix: normalize the extracted token via normalizePhaseName before comparing so that "1" and "01" both resolve to "01" and match correctly. Applied to both the primary comparison and the project-code-prefix-stripping retry path. Verified by bug-3749-sdk-commit-strategy-branch-integration.test.cjs passing: ✔ commit with --files in a phase dir switches to the strategy branch ✔ commit with --files outside a phase dir skips branch switch Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> --------- Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> |
||
|
|
f27b10736e |
fix(3751): resolveAgentsDir falls back to repo-local .claude/agents (#3762)
* test(#3751): add RED test for resolveAgentsDir missing repo-local .claude/agents Drive resolveAgentsDir() with a repo-local .claude/agents present and ~/.claude/agents absent. Structural contracts assert the function body must reference projectDir when constructing the fallback path, and that init-complex.ts must pass projectDir to the call site. Both fail deterministically before the fix. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(#3751): resolveAgentsDir() falls back to repo-local .claude/agents for --local installs resolveAgentsDir() was probing only GSD_AGENTS_DIR or the runtime-global config dir (~/.claude/agents for Claude). For Claude Code --local installs where agents land in ./.claude/agents, the SDK reported agents_installed: false even when the agent files were present. Precedence (post-fix): 1. GSD_AGENTS_DIR (explicit override, unchanged) 2. <getRuntimeConfigDir(runtime)>/agents (when the dir exists) 3. <projectDir>/.claude/agents (repo-local fallback for claude runtime) Both init.ts:checkAgentsInstalled and init-complex.ts:initNewProject now receive projectDir and thread it to resolveAgentsDir(). Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * chore(3751): update changeset to reference PR #3762 * fix(3751): add allow-test-rule annotation to satisfy lint-no-source-grep The structural-contract test reads TypeScript SDK source files to verify resolveAgentsDir() signature shape, fallback ordering, and call-site wiring. These are legitimate SDK-seam contracts (the TS source IS the product artifact). The allow-test-rule annotation bypasses the lint-no-source-grep check that flags readFileSync-bound variable usage. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(3751): repair Windows config-set concurrent-write race withPlanningLock threw on EPERM instead of retrying, causing the losing process to crash silently and its config write to never land. On Windows, when two processes race to create the same lock file via O_EXCL (writeFileSync with flag:'wx'), the OS can return EPERM instead of EEXIST while NTFS holds an internal exclusive handle on the newly-created file during the write. The previous catch block only recognized EEXIST as a contention signal — any other code (including EPERM) fell through to `throw err`. The calling test used .catch(()=>{}) to suppress process errors, so the losing process silently exited without writing its value; the winning process then wrote from the stale pre-race config, producing the observed 'balanced' instead of 'quality'. Fix: port the PLANNING_LOCK_RETRY_ERRNOS Set from main (landed in #3777) into this branch. The set treats EPERM, EBUSY, and six other transient filesystem codes as retry signals rather than fatal errors. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> |
||
|
|
75e013191c |
fix(3726): replace racy 600ms subprocess poll with deterministic test (#3745)
* test(3726): replace racy spawn-poll with deterministic sentinel assertions The original bug-1974 test asserted STATE.md content against a 2000ms wall-clock deadline while the hook's fire-and-forget spawn().unref() subprocess raced to write it — causing intermittent CI failures under Docker contention (#3726). Fix: assert the synchronously-written warnData.criticalRecorded sentinel (readable the moment spawnSync runHook() returns), and invoke `gsd-tools state record-session` synchronously via spawnSync to verify the persistence seam. Adds a counter-test for WARNING-only fires (5 tests total). No production code changed. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(3726): repair Windows state add-blocker concurrent-write race acquireStateLock silently returned a false-success lockPath on any non-EEXIST openSync error (the old guard was `if (err.code !== 'EEXIST') return lockPath`). On Windows-24 CI, the releaseStateLock unlink briefly leaves the file in a transitional state so the next O_CREAT|O_EXCL call from a racing process gets EPERM or EBUSY instead of EEXIST. The old guard treated this as "lock not yet created, you own it" and let the second process proceed with its own read-modify-write while the first still held the actual lock — causing one blocker to be silently overwritten. Fix mirrors commits |
||
|
|
26773bd669 |
fix(3735): add surface to PROFILES.core (restore ADR-0011 expand contract) (#3744)
* test(3735): add failing test that PROFILES.core includes surface
Regression test asserting that resolveProfile({ modes: ['core'] }) includes
'surface' in its transitive closure — the ADR-0011 contract that --profile=core
users can expand via /gsd:surface enable <cluster>. Also updates stale
hardcoded skill-count assertions (7→8) across install-minimal*.test.cjs and
install-profiles-resolve.test.cjs to reflect the correct post-fix baseline.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* fix(3735): add 'surface' to PROFILES.core to restore ADR-0011 expand contract
PROFILES.core omitted 'surface', silently breaking the documented contract
in ADR-0011 that --profile=core users can expand their skill surface via
/gsd:surface enable <cluster>. The sub-command is only available if surface.md
is staged — which requires it to appear in the resolved set for the core profile.
Added 'surface' to both PROFILES.core and PROFILES.standard (standard is a
documented superset of core; omitting it from standard would break the
"standard must include all core skills" invariant and the resolveProfile tests).
The MINIMAL_SKILL_ALLOWLIST back-compat shim is derived from PROFILES.core so
it picks up surface automatically, ensuring --minimal and --core-only installs
also stage surface.md.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* chore(3735): update changeset to reference PR #3744
The fix commit landed with the linked-issue number as the pr: field
placeholder. Updating to the actual PR number now that the PR is open.
* docs(install-profiles): fix stale 'six skills' count in module header comment
After #3735 added surface to PROFILES.core the skill count became eight,
but the module-level comment still said "six skills covering the main project
loop". Update the description to reflect the correct count and reference the
ADR-0011 expand contract that surface fulfils.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
---------
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
|
||
|
|
86e067924f |
fix(3727): wire --fix flag dispatch in code-review workflow (#3743)
* test(3727): add failing test for --fix flag dispatch in code-review workflow Adds bug-3727-code-review-fix-flag-dispatch.test.cjs with: - Pure-function tests on parseCodeReviewFlags() / resolveCodeReviewWorkflow() from new code-review-flags.cjs typed IR module - Structural docs-parity tests asserting dispatch_fix step exists in code-review.md and that initialize step references code-review-flags.cjs Structural tests FAIL today (RED): workflow has no dispatch_fix step and no reference to code-review-flags.cjs in initialize. IR-level tests pass because the lib module is introduced in this commit as the typed seam. Fixes #3727 Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(3727): wire --fix/--all/--auto flags through code-review workflow The initialize step now parses --fix, --all, and --auto from argv (via the code-review-flags parser seam added in the previous test commit) and the workflow dispatches gsd-code-fixer when --fix is truthy and the review returned findings. Fixes the regression introduced when PR #2947 closed #2946 without actually shipping the workflow dispatch. Fixes #3727 * chore(3727): update changeset to reference PR #3743 The fix commit landed with the linked-issue number as the pr: field placeholder. Updating to the actual PR number now that the PR is open. * fix(3727): register code-review-flags.cjs in INVENTORY.md and manifest Add missing row for get-shit-done/bin/lib/code-review-flags.cjs to the CLI Modules table in docs/INVENTORY.md (count 72→73) and regenerate docs/INVENTORY-MANIFEST.json to fix three failing CI tests: - cli-modules-doc-parity: every CLI module must have a row in INVENTORY.md - inventory-counts: headline "CLI Modules (N shipped)" must match file count - inventory-manifest-sync: INVENTORY-MANIFEST.json must match filesystem Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> --------- Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> |
||
|
|
e690f1bc90 |
fix(3718): shell-free Node.js UI safety gate — fixes PowerShell silent-fail (#3718)
* fix(workflows): add word-boundary anchoring to UI safety gate grep Replace unanchored grep -iE "UI |..." alternation with POSIX ERE word-boundary-anchored form: LC_ALL=C grep -iE "(^|[^[:alnum:]])(UI|...)([^[:alnum:]]|$)" Unanchored form matched 'ui' inside 'requirements', 'view' inside 'overview' and 'review', 'form' inside 'performance'/'platform'/ 'transform' — producing HAS_UI=0 on 100% of standard roadmap phases (every phase contains a **Requirements**: field). Fix applied to both plan-phase.md:625 and autonomous.md:284. LC_ALL=C added for POSIX locale portability on both BSD and GNU grep. Closes #3706 Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * test(workflows): add regression tests for UI safety gate false-positives (#3706) - bug-3706-ui-safety-gate-false-positives.test.cjs: 36-test suite covering both plan-phase.md and autonomous.md gate behavior; verifies that Requirements/overview/performance/platform/transform/review/build/screening do NOT trigger the gate, while standalone UI/view/form/screen/dashboard/ component/lowercase-ui/hyphenated-non-UI DO trigger it. - autonomous-ui-steps.test.cjs: update stale assertion that checked for the old broken grep pattern; now asserts the word-boundary-anchored form. Test strategy: extract the POSIX ERE pattern from the workflow file and simulate grep match semantics in JS (no shell exec, no source-grep). Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * chore(changeset): add Fixed fragment for PR #3718 (UI safety gate false-positives) Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(workflows): document compound-token boundary contract; add comment to gate Addresses adversarial review finding: word-boundary anchoring intentionally does not match tokens embedded in compound alphanumeric words (e.g. "microfrontend", "dashboardWidget", "uiSpec"). This is correct behavior — gsd-roadmapper generates natural English prose, not camelCase compounds. Hyphenated forms ("micro-frontend") and spaced forms are caught by the anchored pattern (hyphen is [^[:alnum:]]). Add inline comment in both workflow files explaining the pattern intent, the false-positive prevention, and the compound-word contract. Add 4 tests (2 per workflow) documenting the compound-word contract: - "microfrontend" (compound) must NOT trigger gate (documented behavior) - "micro-frontend" (hyphenated) MUST trigger gate (correct true-positive) Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(3718): replace shell grep gate with shell-free Node.js helper Moves UI safety gate logic from `LC_ALL=C grep -iE` (silently broken on Windows PowerShell — locale env-var prefix not recognised by pwsh) to `bin/lib/ui-safety-gate.cjs` (Node.js, reads via stdin to avoid ARG_MAX). Path is anchored via `git rev-parse --show-toplevel` (GSD_REPO_ROOT) to avoid CWD-sensitive failure when Claude Code executes from a subdirectory. Word-boundary regex is identical to the original POSIX ERE pattern: (^|[^a-zA-Z0-9])(TOKEN)([^a-zA-Z0-9]|$) Exit codes mirror grep: 0 = UI found, 1 = not found. Tests: 51/51 pass — includes spawnSync shell:false + stdin cross-shell portability tests and ARG_MAX large-input test. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(3706): address pr-review-toolkit + codex review findings - Multi-token-per-line: use matchAll to capture all UI tokens - Add test for multiple distinct tokens on same line - Clarify ASCII vs POSIX [:alnum:] in word-boundary comment - Correct misleading "path anchored" comment in plan-phase/autonomous workflows - Remove UI_GATE_PATTERN from module.exports (internal implementation detail) Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix(state): restore ACQUIRE_LOCK_RETRY_ERRNOS in acquireStateLock (#3718) Commit |
||
|
|
c1c8b0d109 |
fix(3739): gap-checker now detects padded-prefix CONTEXT.md (#3764)
* test(3739): add RED tests for padded-prefix CONTEXT.md gap-checker miss Covers bare and padded (01-CONTEXT.md, 02.1-CONTEXT.md) forms, an uncovered-decision counter-test, and unit tests for the upcoming findContextMdIn() helper. All 6 new tests fail before the fix. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(3739): extract findContextMdIn() helper; fix gap-checker bare lookup gap-checker.cjs:136 used a bare path.join(absPhaseDir, 'CONTEXT.md') that silently returned '' for any phase using the padded-prefix convention (01-CONTEXT.md, 02.1-CONTEXT.md, etc.). Extract findContextMdIn(absDir) to planning-workspace.cjs — the module already imported by gap-checker, init, roadmap, and core — and wire gap-checker.cjs to call it instead of the bare lookup. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * refactor(3739): replace inline dual-form predicate with findContextMdIn() at all 4 remaining sites The dual-form predicate `f.endsWith('-CONTEXT.md') || f === 'CONTEXT.md'` existed verbatim at 5 sites across init.cjs (×3), roadmap.cjs, and core.cjs — Rule of Three mandates extraction at ≥3 sites. All 4 remaining call sites now delegate to findContextMdIn() from planning-workspace.cjs. No behaviour change; all existing tests pass. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * chore(3739): update changeset to reference PR #3764 * fix(3739): findContextMdIn prefers bare CONTEXT.md over padded form (deterministic precedence) `.find()` with `f.endsWith('-CONTEXT.md') || f === 'CONTEXT.md'` returned the first match in `readdirSync` order — undefined on most filesystems. When both `CONTEXT.md` and `01-CONTEXT.md` exist the winner was arbitrary. The old gap-checker.cjs:136 code always used bare `CONTEXT.md` first (existsSync on the bare path). Restore that invariant: check `files.includes('CONTEXT.md')` before falling through to the padded scan. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * test(3739): dual-file precedence test — bare CONTEXT.md wins over padded form Adds two test cases for the scenario where both CONTEXT.md and 01-CONTEXT.md exist in the same phase directory: 1. Helper level: findContextMdIn() must return 'CONTEXT.md' (not the padded filename) when both files are present on disk. 2. Integration level: gap-analysis must resolve decisions from the bare form only; D-PADDED (from 01-CONTEXT.md) must not appear when the bare form shadows it. Without these tests a future change to findContextMdIn could silently regress the precedence guarantee. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(3739): bug-2798 tests skip cleanly when sdk/dist is absent (was hard-fail) The 3 tests in bug-2798-context-window-config-key.test.cjs invoke the built SDK CLI (sdk/dist/cli.js) and require sdk/dist/query/config-schema.js. When dist is absent, they threw hard errors rather than observable skips. Apply the same `if (!existsSync(...)) { t.skip(...); return; }` guard used in bug-2767-gsd-sdk-commit-files-flag.test.cjs (c2812313). Tests 1 & 2 guard on sdk/dist/cli.js; test 3 guards on sdk/dist/query/config-schema.js. When dist is present all 3 run; when absent all 3 emit actionable skip lines. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(3739): eliminate double readdirSync in findContextMdIn callers findContextMdIn now accepts either a directory path or an already-read files array, allowing callers that already hold a directory listing (core.cjs:getPhaseFileStats, roadmap.cjs:countPhasePlansAndSummaries, gap-checker.cjs:runGapAnalysis) to skip redundant readdirSync calls. Test coverage added for the array-argument overload. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * test: redesign flaky concurrent add-blocker test with deterministic barrier Previous design relied on OS scheduler to interleave two subprocess writes, producing a flake under CI load. Redesigned using a file-barrier (Option A) that forces both subprocesses to reach a ready-gate before either proceeds, guaranteeing true concurrent lock contention and eliminating timing dependency. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> |
||
|
|
aab01f43e9 |
refactor(tests): consolidate Phase Lifecycle Module — 20 files → 4 (#3741)
* chore(tests): lint rule — cap test files per production module at 2 Adds scripts/lint-test-file-count.cjs with a ratcheted allowlist (scripts/lint-test-file-count.allowlist.json) capturing today's 30 violating clusters as a ceiling. New entries blocked at PR time; reductions ratchet automatically. Wires into .github/workflows/test.yml as a new step in lint-tests. Refs #3737 Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * refactor(tests): consolidate Phase Lifecycle Module — 20 files → 4 - Merge 10 CJS bug-fix test files into tests/phase.test.cjs - Merge sdk/src/phase-runner-types.test.ts + sdk/src/phase-prompt.test.ts into sdk/src/phase-runner.test.ts (97 → 152 tests, 0 failures) - Rename 4 mis-attributed test files out of phase cluster: phase-researcher-app-aware → gsd-researcher-app-aware phase-researcher-flow-diagram → gsd-researcher-flow-diagram feat-3023-phase-type-models → feat-3023-model-phase-types phase-6-cjs-sdk-seam-contracts → cjs-sdk-bridge-seam-contracts - Fix phasePlanIndex (#3430): non-canonical plan filename warning now surfaces in data.warnings[] as "Ignored noncanonical plan files: ..." instead of a separate singular data.warning field - Update allowlist: phase ceiling 20 → 4 (closes #3740) - Add Phase Lifecycle Module glossary entry to CONTEXT.md Closes #3740 Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(phase-roadmap-mutation): replaceInCurrentMilestone handles active milestone inside <details> block When the active milestone is wrapped in a <details> block (e.g. user collapsed it, or milestone transition), the after-</details> slice is empty or contains only footer text — the pattern never matches and the replacement is silently dropped. Fix: when after.replace() produces no change, fall back to replacing inside the last <details>...</details> block. Shipped-milestone blocks are untouched because only the last <details> block is targeted. Closes #2641 Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(changeset): add required type/pr frontmatter to 3740 fragment Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> --------- Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> |
||
|
|
4f56c3b10b |
refactor(tests): consolidate Worktree Module — 13 files → 3 (#3752)
* refactor(tests): consolidate Worktree Module — 13 files → 2 Closes #3742 Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(changeset): correct frontmatter format for 3742 fragment type:/pr: fields required by docs-lint; replaces @changesets/cli package-bump format with the repo's custom fragment schema. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * refactor(tests): split consolidated worktree.test.cjs along cleanup seam (≤ 800 LOC/file) Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * chore(changeset): update 3742 fragment — 13→3 files, ≤800 LOC/file Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * chore(changeset): fix pr reference 3738→3752 in 3742 fragment Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> --------- Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> |
||
|
|
c4e39bc23a |
refactor(tests): consolidate graphify Module — 7 files → 1 (#3769)
* refactor(tests): consolidate graphify Module — 7 files → 1 Closes #3761 Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * refactor(tests): split graphify.test.cjs along describe-block seams — keep files ≤ 800 LOC - tests/graphify.test.cjs (653 LOC): status + build - tests/graphify-query.test.cjs (447 LOC): query - tests/graphify-visualization.test.cjs (577 LOC): staleness + mvp-viz + regressions - tests/graphify-auto-update.test.cjs (625 LOC): auto-update hook - tests/helpers/graphify.cjs (112 LOC): shared helpers extracted Total: 132 tests, 0 failures. Refs #3761. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> --------- Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> |
||
|
|
1926353b5e |
refactor(tests): consolidate Runtime Artifact Layout Module — 12 files → 3 (#3759)
* refactor(tests): consolidate Runtime Artifact Layout Module — 12 files → 3 Closes #3757 Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(changeset): add proper frontmatter to 3757 fragment Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> --------- Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> |
||
|
|
3d52f5ee46 |
refactor(tests): consolidate Init Command Module — 7 files → 5 (#3756)
* fix(3687): update insert-phase docs and roadmapper to use --insert flag Updates stale references in insert-phase.md workflow and gsd-roadmapper.md agent to use the consolidated /gsd:phase --insert command syntax instead of the retired /gsd-insert-phase and /gsd:phase insert forms. Closes #3687 * refactor(tests): consolidate Init Command Module — 7 files → 5 Closes #3755 Merges `tests/init-manager-deps.test.cjs` (#2267 regression) into `tests/init-manager.test.cjs` (718 LOC), and `sdk/src/query/init-progress-precedence.test.ts` (#2674 regression) into `sdk/src/query/init-complex.test.ts` (788 LOC). The 800 LOC ceiling prevents further consolidation: - `tests/init.test.cjs` is pre-existing at 1630 LOC - `sdk/src/query/init.test.ts` is at 791 LOC - `sdk/src/query/init-workstream-milestone-op.test.ts` is a distinct seam testing initMilestoneOp, roadmapAnalyze, and resolveQueryRuntimeContext workstream resolution. Also adds Init Command Module Glossary entry to CONTEXT.md. Allowlist update deferred to rebase after #3738 merges (allowlist file does not exist on origin/main). Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(init): initExecutePhase preserves same-milestone archived phase dir (#3469) When `phases clear` archives current-milestone phases into `.planning/milestones/<version>-phases/` but the workflow is still on that same milestone, `shouldDropArchivedPhaseMatch` was unconditionally dropping the archived dir match. This caused `phase_dir: null` when the phase was still executing in the current milestone. Fix: detect when `phaseInfo.archived === currentMilestone` (read from STATE.md) and skip the drop. The #2391 regression guard is safe because that scenario involves archived.version != current milestone. Also corrects two tests in `initRemoveWorkspace` to expect thrown GSDError instead of `{ data: { error } }` — the production code was intentionally changed to throw for CLI non-zero exit propagation. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> --------- Co-authored-by: arya rizky <aryarizkyardhipratama@gmail.com> Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> |
||
|
|
9f57f7488e |
refactor(tests): consolidate Milestone Module — 10 files → 4 (#3754)
* refactor(tests): consolidate Milestone Module — 10 files → 4 Closes #3753 Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(changeset): correct fragment format for 3753-consolidate-milestone-tests Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(changeset): add required frontmatter to 3753 changeset fragment Adds `type: Fixed` and `pr: 3753` frontmatter so docs-lint passes. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(tests): bug-2943 execFileSync timeout 5s→15s for Windows starvation PR #3754's milestone consolidation reshuffles run-tests.cjs chunk composition. On Windows/Node 22 under --test-concurrency=4, bug-2943 subprocesses now share concurrency slots with bug-2760-codex-install subtests (8–15s each), starving past the 5000ms timeout. 15s covers the observed 13.5s worst case with headroom. Refs #3753 Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> --------- Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> |
||
|
|
f955bf872c |
refactor(tests): consolidate Installer Module — 11 files → 2 (#3760)
* chore(tests): lint rule — cap test files per production module at 2 Adds scripts/lint-test-file-count.cjs with a ratcheted allowlist (scripts/lint-test-file-count.allowlist.json) capturing today's 30 violating clusters as a ceiling. New entries blocked at PR time; reductions ratchet automatically. Wires into .github/workflows/test.yml as a new step in lint-tests. Refs #3737 Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * chore(tests): add docs-exempt to changeset fragment Internal CI lint rule — no user-facing docs impact. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * refactor(tests): consolidate Installer Module — 11 files → 2 Closes #3758 Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(changeset): replace invalid type 'Chore' with 'Changed' — ALLOWED_TYPES only accepts Added|Changed|Deprecated|Removed|Fixed|Security Fragment already had a docs-exempt marker; only the type value was wrong. Refs #3758 Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * refactor(tests): split install.test.cjs along section seams — keep files ≤ 800 LOC 1828-LOC monolith split into 3 files by semantic boundary: install.test.cjs (602 LOC) — S1-5: dir resolution, install/uninstall spot-checks, Kilo install-runtime-artifacts.test.cjs (347 LOC) — S6-8+12: layout loop, Contract 6, legacy migrations install-minimal-hooks.test.cjs (782 LOC) — S9-11+13: profiles, minimal E2E, hooks copy Shared constants and helpers extracted to tests/helpers/install-shared.cjs (216 LOC). Total test count unchanged: 210 tests (68+37+105). Refs #3758 Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(tests): ratchet state test-file ceiling to 9 — actual count at baseline The allowlist was initialised with state=8 but the repo already had 9 files matching the 'state' prefix at the time the lint rule was created, causing lint-test-file-count.test.cjs to fail on the real repo immediately. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> --------- Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> |
||
|
|
6313baad63 |
chore(tests): lint rule — cap test files per production module at 2 (#3738)
* chore(tests): lint rule — cap test files per production module at 2 Adds scripts/lint-test-file-count.cjs with a ratcheted allowlist (scripts/lint-test-file-count.allowlist.json) capturing today's 30 violating clusters as a ceiling. New entries blocked at PR time; reductions ratchet automatically. Wires into .github/workflows/test.yml as a new step in lint-tests. Refs #3737 Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * chore(tests): add docs-exempt to changeset fragment Internal CI lint rule — no user-facing docs impact. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> --------- Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> |
||
|
|
479839147e |
fix(state): acquireStateLock retries on transient Docker/NFS errno codes (#3777)
* fix(state): acquireStateLock retries on transient Docker/NFS errno codes Expands retry allowlist to ENOENT/EINVAL/EIO/ESTALE/EAGAIN/EINTR in addition to existing EPERM/EBUSY. Truly fatal codes (EMFILE/ENOSPC/EROFS/EACCES) still throw. Resolves the locking-bugs regression seen across all 8 open consolidation PRs (#3738, #3741, #3752, #3754, #3756, #3759, #3760, #3769). Closes #3776 Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * chore(changeset): update pr number to 3777 in retry-allowlist fragment Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> --------- Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> |
||
|
|
ca2644a71a |
fix(worktree): unlock-retry on locked cleanup + startup orphan sweep (#3707) (#3719)
* fix(worktree): unlock-retry on locked cleanup + startup orphan sweep (#3707) Two root causes fixed: 1. **In-session cleanup blocked**: `executeWorktreeWaveCleanupPlan` now attempts `git worktree unlock <path>` then retries `git worktree remove --force` when the initial single-force remove fails on a locked worktree. Previously every cleanup after a successful merge was silently blocked. 2. **Cross-session orphan accumulation**: new `reapOrphanWorktrees` helper sweeps `.git/worktrees/*/locked` at startup. It reaps entries where the pid is dead, the branch tip is an ancestor of the default branch (ancestry guard prevents data loss on squash-merge repos), and the lock mtime is older than 5 minutes (race guard). Wired into `quick.md` and `execute-phase.md` startup blocks guarded by `USE_WORKTREES != false`. SDK: adds `worktree.reap-orphans` query command (routes through gsd-tools.cjs). Tests: 11 real-fs tests covering unlock-retry, dead-pid reap, live-pid skip, unmerged skip, fresh-mtime skip, idempotent double-call, and structural wiring. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * chore(changeset): add Fixed fragment for PR #3707 (worktree orphan cleanup) Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(worktree): fix test portability on Windows + macOS for bug-3707 reap tests - worktreeMeta helper: replace /\/\.git$/ with /[/\\]\.git$/ so the gitdir path suffix is stripped on both Windows (backslash) and Unix. - worktreeMeta helper: normalize CRLF→LF before splitting porcelain blocks, fixing block parsing when git emits CRLF on Windows. - reapOrphanWorktrees: replace single 'main' rev-parse with a [defaultBranch, 'main', 'master'] candidate loop so test fixtures without a remote origin (where branch may be 'master') don't bail early. Intentionally excludes 'HEAD' to prevent false reaping when HEAD is detached or on a feature branch (Codex adversarial finding). Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(worktree): CI green — macOS symlink path, Windows test helper, pid portability, EPERM liveness Four fixes to get macOS + Windows CI from red to green: 1. **macOS symlink mismatch** (worktree-safety.cjs): `reapOrphanWorktrees` now builds a canonical→listed path map from `git worktree list --porcelain` using `fs.realpathSync.native`. Uses the listed path (as git knows it) for `git worktree unlock/remove`, not the gitdir-derived path. Fixes the `/var/folders` vs `/private/var/folders` discrepancy on GitHub macOS runners where `git worktree unlock <realpath>` was silently failing because git's list stored the unresolved symlink path. 2. **Windows path separator in test helper** (test file): `worktreeMeta` `.replace(/\/\.git$/, '')` → `.replace(/[/\\]\.git$/, '')`. On Windows, git writes backslash separators in the gitdir file; the Unix-only regex was causing `Cannot find .git/worktrees/<name>` for all Suite 2 tests. 3. **Non-portable PID in tests** (test file): All `'999999'` dead-PID literals replaced with `deadPid()` helper that spawns a real short-lived child, captures its PID, and returns it after exit. Eliminates flakiness on Linux systems where `pid_max` can reach 4194304, making 999999 a live PID. 4. **EPERM fail-closed in isPidAlive** (worktree-safety.cjs): `catch { return false }` → checks `err.code === 'EPERM'` and returns `true` (alive). On Windows and cross-user scenarios, `process.kill(pid, 0)` throws EPERM for live but inaccessible processes; treating that as dead would reap a live worktree. Adversarial review via codex confirmed: - Squash-merge repos: fail-closed (CONCERN, not BUG — by design, not data-loss) - canonicalToListed map: SAFE (fail-closed on realpathSync error) - Concurrent reapers: SAFE (both prune; second gets skipped: remove_failed) - Startup blocking: CONCERN (no global cap, 10s/call × N worktrees) — tracked, not fixed here (requires separate perf work) - gsd-sdk missing: SAFE (quick.md checks and fails fast with guidance) All 27 local tests + Docker (holodeck) green. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(worktree): address codex adversarial findings — fail-closed default branch + CRLF map Two fixes from codex adversarial review of PR 3718: 1. **Default branch resolution (data-loss risk)**: `reapOrphanWorktrees` now uses `refs/remotes/origin/<branch>` exclusively when a remote is configured. If `origin/HEAD` is absent but a remote exists, we bail out (fail-closed) rather than falling back to a local `main`/`master` that may not be the real integration branch. The `main`/`master` fallback is only used when there is provably no remote (local-only test fixtures). 2. **CRLF normalization in canonical-path mapper**: The `worktree list --porcelain` output was split on '\n\n' without normalizing CRLF first. On Windows, git emits CRLF, which caused block-splitting to fail and left the canonicalToListed map only partially populated, weakening the symlink/path-mismatch fix introduced earlier. 3. **Windows 8.3 short-path fix (test helper)**: Both `beforeEach` blocks now call `resolvedTmpDir()` which pre-resolves `os.tmpdir()` via `fs.realpathSync.native` so temp paths avoid RUNNER~1-style short names that git stores in long form, causing worktreeMeta path comparisons to fail on Windows CI. All 11 real-fs + 16 unit tests green locally. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(worktree): adversarial findings + macOS CI path-mismatch fix ## Root cause (macOS CI fail) `reapOrphanWorktrees` stored `worktreePath` (gitdir-derived, real path via git's symlink resolution, e.g. `/private/var/folders/…`) in results, while the test's `wtDir` used the unresolved symlink form (`/var/folders/…`). After reaping, `canonicalPath(wtDir)` can no longer call `realpathSync.native` (directory gone), so it falls back to `path.resolve` — which returns the symlink form — causing the `result.find()` comparison to miss. ## Fixes applied ### Source — worktree-safety.cjs 1. **Finding 1 (fail-closed PID check)**: Non-parseable lock content (e.g. `"Locked by claude-code agent-xxx"`) is now treated as ALIVE with reason `lock_owner_unknown`, not as dead. Previously it fell through as dead. 2. **Finding 1b (EPERM safe)**: `isPidAlive` call wrapped in try/catch; any thrown error (EPERM = process exists but cross-user on Windows) → ALIVE. 3. **Finding 2 (startup warning)**: `cmdWorktreeReapOrphans` now writes a one-line stderr warning when ≥1 entry is skipped or when reaper throws, while keeping exit-zero so workflows don't break. 4. **Finding 3 (default-branch discovery)**: Local-only fallback now tries `init.defaultBranch` config and HEAD symref before `main`/`master`, so repos configured with `trunk`, `dev`, etc. get correct orphan detection. 5. **macOS path fix**: Result entry for reaped worktrees now uses `gitKnownPath` (from `git worktree list`) instead of `worktreePath` (from gitdir file), ensuring the caller always sees the path git uses for the worktree. ### Test — bug-3707-locked-worktree-cleanup.test.cjs 6. **macOS CI fix**: Pre-compute `wtDirCanonical = canonicalPath(wtDir)` before calling `reapOrphanWorktrees` so the comparison works after removal. 7. **Gap 1**: New test — Claude Code lock format (`"Locked by claude-code …"`) must not be reaped; asserts `status=skipped, reason=lock_owner_unknown`. 8. **Gap 2**: New test — `isPidAlive` throwing EPERM → must not reap. 9. **Gap 3**: New test — repo with `init.defaultBranch=trunk`; merged worktree must be reaped (verifies trunk is discovered as the integration branch). Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(test): raise waitForStoppedAt timeout 2 s → 5 s for Windows/Node22 CI load Subprocess write latency exceeds 2 s on loaded windows-latest/Node22 runners (test duration was 6181 ms); 5 s gives sufficient headroom without changing any production behaviour. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> --------- Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> |
||
|
|
ab24d80b68 |
fix(state): acquireStateLock throws on non-EEXIST openSync errors (#3773)
* fix(state): acquireStateLock throws on non-EEXIST openSync errors Closes #3772 Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * chore(changeset): update pr reference to #3773 Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(state): retry on EPERM/EBUSY in acquireStateLock and withPlanningLock Resolves state update TOCTOU failure on macos-22 and config-set concurrency failure on windows-24. Root cause: openSync(O_CREAT|O_EXCL) can return EPERM or EBUSY transiently on some CI OS+AV combinations when the lock file is briefly held open by the deleting process; the new throw-on-non-EEXIST guard from #3772 propagated these transient errors, killing child processes and causing lost updates in the concurrency tests. Fix: guard EPERM/EBUSY with an explicit continue before the throw-on-non-EEXIST line in both acquireStateLock and withPlanningLock; the C1 source-audit test still passes because the throw pattern is preserved for all other non-EEXIST codes. Refs #3772 Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> --------- Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> |
||
|
|
e5461ad4e2 |
refactor(tests): consolidate Dispatch Pipeline Module — 7 files → 1 (#3733)
Consolidates 7 sibling test files for sdk/src/query/query-dispatch.ts and its stage handlers into a single query-dispatch.test.ts with 8 describe blocks (699 LOC, 53 tests). Deletes 3 clean shim sources with zero non-test importers. Leaves query-dispatch-formatting.ts and query-dispatch-error-mapper.ts in place (non-test importer: query-fallback-executor.ts — deferred to #3732). - query-dispatch-input-validation.ts deleted (clean shim) - query-dispatch-plan.ts deleted (clean shim) - query-dispatch-result-builder.ts deleted (clean shim) - 6 per-stage test files deleted (consolidated into query-dispatch.test.ts) - counter-tests added per Contract 6 for each stage field - CONTEXT.md Glossary updated with Dispatch Pipeline Module entry Closes #3731 Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> |
||
|
|
473c279c23 |
fix(state): acquireStateLock must not unlink live locks on retry exhaustion (#3714) (#3717)
PR #3711 fixed a Windows phantom-lock bug by making the last-retry path unconditionally unlink the existing lock and re-acquire. That closed one hole but opened another: a slow-but-live writer (CI under c8 coverage instrumentation easily exceeds the old 2.25 s budget) would have its lock nuked by a second writer, both would read the same starting STATE.md, and the second write would clobber the first append. Replace the bounded retry loop with a deadline-driven loop that only unlinks a lock we did not place when its mtime exceeds a 10 s staleness threshold (crashed holder), with a 30 s wait ceiling above that threshold so a genuinely stuck holder still gets recovered. Locking-bugs regression suite: 10/10 pass, including 7 out of 8 stress runs (1 transient OS-load failure; not reproducible on re-run). Fixes #3714 Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com> |
||
|
|
9c4895f409 |
chore(ci): bump actions/upload-artifact v4.6.2 → v7.0.1 (#3715) (#3716)
v4.6.2 ships a node20 runtime; GitHub Actions is deprecating Node 20 (removed from runners 2026-09-16). v7.0.1 ships node24 and is the last Node-20 reference in the repo. Pinned by full commit SHA per repo convention. Verified v5/v6/v7 breaking changes do not apply: artifact names are unique per workflow run and neither step uses include-hidden-files. Closes #3715 Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com> |
||
|
|
6a5fa59129 |
feat(3081): auto-trim review prompts for small-context model reviewers (#3708)
* feat(3081): auto-trim review prompts for small-context model reviewers Adds review.max_prompt_tokens and review.max_prompt_tokens_per_reviewer config keys. When configured, the /gsd-review workflow deterministically trims the assembled prompt before sending to each reviewer (drop CONTEXT → RESEARCH → REQUIREMENTS; head-shrink PROJECT.md; tail-truncate PLANs proportionally; reserve disclosure-note tokens upfront). Trim metadata is recorded in REVIEWS.md frontmatter. Reviewer is skipped with a warning if even the minimum review set exceeds the budget. Closes #3081 * fix(3081): register prompt-budget in SDK query registry and update inventory manifest review.md references `gsd-sdk query prompt-budget` at three call sites, but the command had no handler in the SDK registry — failing the registry-integration drift-guard test on all 6 CI matrix legs. Added a native TypeScript SDK handler (sdk/src/query/prompt-budget.ts) that ports the applyBudget logic from the CJS module, registered it in DOMAIN_STATIC_CATALOG, and regenerated docs/INVENTORY-MANIFEST.json to include the new cli_modules/prompt-budget.cjs entry. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(3081): bump ws to 8.20.1 and allowlist prompt-budget sibling pair Two additional CI failures after the registry fix: 1. ws moderate CVE (GHSA-58qx-3vcg-4xpx, uninitialized memory disclosure): The advisory covers ws >=8.0.0 <8.20.1. Both root and sdk/package.json pinned ^8.20.0 which resolved to 8.20.0. Bumped both to 8.20.1 to clear the npm audit drift-guard test (bug-3588-npm-audit-clean.test.cjs). 2. lint-shared-module-handsync detected the new prompt-budget.ts / prompt-budget.cjs sibling pair without an allowlist entry. Added a cooperatingSiblings entry to scripts/shared-module-handsync-allowlist.json with classification and justification matching the established pattern. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(3081): align prompt-budget skip semantics across CJS and SDK dispatch paths Replace brittle `[ $EXIT -eq 2 ]` guards with `[ $EXIT -ne 0 ]` in all three local-reviewer blocks (Ollama, LM Studio, llama.cpp) in workflows/review.md. Any non-zero exit from prompt-budget now triggers a skip with a descriptive warning — exit 2/11 prints "budget too small", any other non-zero prints "unexpected exit code". This ensures the SDK bridge dispatch path (exit 11 via GSDError(Blocked)) triggers the same skip as the CJS path (exit 2). The SDK handler (sdk/src/query/prompt-budget.ts) already writes both metadata and prompt files before throwing, so no change needed there. The Ollama block also gains the missing OLLAMA_SKIP guard so the reviewer invocation is actually skipped (previously the block only suppressed the OLLAMA_PROMPT_FILE update but still ran the curl invocation). SDK integration path (hardFailed via GSDError(Blocked) → exit 11) is covered by handler unit tests in tests/prompt-budget.test.cjs; no gsd-sdk-*.test.cjs exercising the full bridge dispatch for this command exists yet — that gap remains and is documented here. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix prompt-budget trim ordering and review guard follow-ups * perf: optimize prompt-budget and dedup reviewer trim workflow * fix(3708): drop source-grep theater tests to satisfy lint-no-source-grep All four test files added in commit 2df566ed were pure source-grep theater: they read .cjs / .ts / .md source files and asserted that specific string literals were present or absent. None exercised runtime behaviour. Deleted: - tests/gsd-tools-memory-optimizer.test.cjs — 7 includes() on gsd-tools.cjs - tests/prompt-budget-hotpath-optimizer.test.cjs — includes() on prompt-budget.cjs + .ts - tests/prompt-budget-io-optimizer.test.cjs — includes() on prompt-budget.ts + gsd-tools.cjs - tests/review-workflow-budget-dedup.test.cjs — includes() on review.md Behavioural coverage for the prompt-budget feature already exists in tests/prompt-budget.test.cjs and tests/prompt-budget-cli.test.cjs (also added by this PR). No replacement tests needed. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * fix(3708): correct budget-pressure threshold and minSet accounting Two bugs in applyBudget caused premature trimming and false hard-fails: 1. UNNEEDED_TRIM: budgetUnderPressure compared baseTokens against effectiveBudget - NOTE_RESERVE_TOKENS, triggering trim pressure 80 tokens before the budget was actually exceeded. Fix: compare against effectiveBudget directly; NOTE_RESERVE_TOKENS are still reserved in contentBudget once real pressure is confirmed. 2. FALSE_HARDFAIL: minSet included NOTE_RESERVE_TOKENS unconditionally, treating the note as mandatory even when no trim would occur and no note would be injected. Fix: exclude NOTE_RESERVE_TOKENS from minSet; a prompt that fits untrimmed needs no note and must not hard-fail. Both fixes applied in CJS and TypeScript implementations. Two regression tests added (cycles 11 and 12) that reproduce each case behaviorally. --------- Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com> |
||
|
|
e15348ea43 |
docs(context): add RULESET.TESTS.boundary-coverage + LEARNING.prompt-budget.boundary-gap
Adds four predicates derived from PR #3708 post-mortem: - RULESET.TESTS.boundary-coverage — must test {limit-1, limit, limit+1} and near-reserve-distance inputs - RULESET.TESTS.boundary-coverage.fixtures — required fixtures for budget/limit/quota/threshold code - RULESET.TESTS.boundary-coverage.anti-pattern — names the trivially-large + trivially-small pairing as the failure mode - LEARNING.prompt-budget.boundary-gap — full post-mortem of the UNNEEDED_TRIM + FALSE_HARDFAIL regressions |
||
|
|
77b6bb62db | fix(state): acquireStateLock last-retry now re-acquires before proceeding (#3711) | ||
|
|
3c2c56b9e8 |
fix(ci): skip install + slow lanes on Windows in main test matrix (#3710)
* fix(ci): skip install + slow lanes on Windows in main test matrix Gates the `Run install tests` and `Run slow tests` steps in `.github/workflows/test.yml` to `matrix.os != 'windows-latest'`. The install lane performs `npm install -g <tarball>` 7× per invocation of release-tarball-smoke.install.test.cjs (1× in the shared before() hook + 1× per of the 6 test cases). On windows-latest each install costs 60–90 s (NTFS + Defender) so the lane alone consumes ~8–9 min on top of the ~7 min already spent on npm ci + build:sdk + unit + integration + security — overflowing the 15-min `timeout-minutes` cap and cancelling the job mid-install. The dedicated install-smoke.yml workflow already excludes Windows from its matrix (ubuntu + macOS only); the weekly windows-compat workflow provides Windows-specific regression coverage. Linux + macOS install and slow lanes remain on main push for parity. Refs #3709 Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com> * fix(deps): bump ws 8.20.0 → 8.20.1 to clear GHSA-58qx-3vcg-4xpx The bug-3588 `npm audit --omit=dev reports zero advisories` test (tests/bug-3588-npm-audit-clean.test.cjs) is failing on main after a new advisory dropped against ws@8.20.0: GHSA-58qx-3vcg-4xpx — Uninitialized memory disclosure ws: range >=8.0.0 <8.20.1 (CVSS 4.4, moderate, CWE-908) Fix: `npm audit fix --omit=dev` at both root and sdk/. Lockfile-only bump to ws@8.20.1; package.json untouched (ws is transitive). `npm audit --omit=dev` reports `found 0 vulnerabilities` in both workspaces after the bump. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com> |
||
|
|
f1a61620bc |
fix(ci): bump coverage heap budget + Windows npm timeout in runNpm helper (#3704)
Set NODE_OPTIONS=--max-old-space-size=6144 on the Unit coverage step so the c8 report phase has 6 GB instead of Node's default ~4 GB heap; the Linux Node 24 runner has 7 GB available so this leaves 1 GB headroom. Raise the runNpm default timeout from 55 000 ms to 180 000 ms so cold-cache Windows npm install -g runs (which take 60-90 s on NTFS + Defender) complete before the child process is killed. Refs #3703 Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com> |
||
|
|
463eb26544 |
Match gsd-sdk query commit in graphify auto-update hook (#3653) (#3658)
* Match `gsd-sdk query commit` in graphify auto-update hook (#3653) The PostToolUse Bash hook only substring-matched direct shell git ops in tool_input.command. `gsd-sdk query commit` invokes git via spawnSync, so the literal "git commit" never appears in the Bash tool's command string and the hook silently skipped every SDK-issued commit. Result: .planning/graphs/ drifted stale after every phase that closed via gsd-sdk query commit, with no error and no log. Gate 2 now also matches `gsd-sdk query commit`. Other SDK verbs (phase.complete, roadmap.update-plan-progress, state.begin-phase) do not invoke git themselves and remain non-matching to avoid spurious rebuilds per state mutation. Adds positive + negative matcher tests. * Fix changeset frontmatter for #3658 `type: Bug Fix` rejected by scripts/changeset/parse.cjs ALLOWED_TYPES (Keep a Changelog values: Added/Changed/Deprecated/Removed/Fixed/Security). Switch to `type: Fixed` and add `pr: 3658` required by MISSING_PR check. docs-lint now reports `ok_no_triggering_fragments` locally. * fix(#3658): bound graphify SDK commit matcher * fix(#3658): exempt release note docs lint |
||
|
|
ef951098a6 |
chore(3686): add release-tarball lifecycle smoke to install-smoke workflow (#3692)
* chore(3686): add release-tarball lifecycle smoke to install-smoke workflow Closes #3686. Adds a non-interactive lifecycle smoke that runs against the installed tarball (not the working tree). Catches the two recent release-time bug classes that the working-tree test suite cannot see: * #3684 — symbol mismatches between init.cjs imports and secrets.cjs exports that landed in v1.42.3 (closed/fixed-pending-release). * #3668 — bare `gsd-sdk` invocations in 75 of 78 workflow files with no `command -v gsd-sdk … elif node "$GSD_TOOLS"` fallback (open). Shape: * `scripts/release-tarball-smoke.cjs` — pure CJS module exporting a frozen `SMOKE` enum and a `runSmoke({ tarballPath, installPrefix, expectedVersion, fixtureDir, lifecycleCommands })` function. CLI `--json` mode prints `JSON.stringify(result)` and exits 0 iff `result.code === SMOKE.OK`. Install is `--prefix <tmpdir>` so it does not pollute global node_modules. * `tests/release-tarball-smoke.test.cjs` — 6 tests covering happy path, version mismatch, lifecycle command file resolution, missing-command detection, sdk binary callability, and structural workflow-body checks. Tests assert on the SMOKE enum directly; no `assert.match` on rendered prose, no try/finally in test bodies, no source-grep theater. Uses `before`/`after` to pack+install once across the test file. * `tests/release-tarball-smoke-workflow.test.cjs` — 7 structural assertions on the parsed install-smoke.yml IR (workflow_call trigger preserved, lifecycle step calls release-tarball-smoke.cjs with --json, jq check enforces result.code === "ok", path filter includes the new files, artifact-on-failure step present). * `.github/workflows/install-smoke.yml` — extended (not duplicated). New "Lifecycle smoke" step after the existing version check, on the same matrix. Artifact upload on failure for debugging. Path filter now triggers on changes to the new script + test. Per CONTRIBUTING.md §"Prohibited: Raw Text Matching on Test Outputs" this PR avoids the same anti-pattern that caused PR #3666 to be reverted (PR #3688) — the script returns frozen enum codes, tests assert on the enum, never on stdout strings. Workflow-body checks in Cycle 3 are INFORMATIONAL (count returned, not enforced) on this PR. After #3668's fix lands and the 75 missing fallbacks are added, the lane can be tightened to enforce zero. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix(3686): harden release smoke workflow and query scanner * fix(3686): move tarball-smoke test to install suite to fix Windows ETIMEDOUT + coverage OOM Windows (Node 22/24/26, jobs 76565215694/76565215710/76565215812): release-tarball-smoke.test.cjs had no suite marker so run-tests.cjs classified it as 'unit', running it on Windows PR CI. The before() hook calls execFileSync(npm.cmd install -g ...) with a 55 s timeout; on Windows GHA runners this npm global install consistently hits ETIMEDOUT (~62 s observed), causing all 3 Windows lanes to fail. Coverage (job 76565215085): c8 ran test:coverage:unit (unit suite only) with V8 coverage tracking active across child processes. The tarball-smoke test's before() hook spawned npm install subprocesses while c8 held V8 coverage descriptors open, driving the Node heap to 4 GB+ and triggering an OOM abort during report generation (exit code 134, all 5682 tests had already passed). Fix: rename to tests/release-tarball-smoke.install.test.cjs so run-tests.cjs routes it to the 'install' suite. The install suite is already skipped on PR CI by design (test.yml lines 179-181: only runs on main push). The dedicated install-smoke.yml workflow continues to exercise this test on its own matrix. Also update the install-smoke.yml PR path filter and the structural wiring test assertion to match the new filename. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> * refactor(test): route tarball-smoke install test through tests/helpers.cjs Replaces direct fs.mkdtempSync and execFileSync calls in tests/release-tarball-smoke.install.test.cjs with createTempDir() and a new runNpm() helper in tests/helpers.cjs. Cleanup is now automatic via the helper. Addresses CodeRabbit Major refactor at https://github.com/gsd-build/get-shit-done/pull/3692#discussion_r3260433892. --------- Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com> |