Commit Graph

4525 Commits

Author SHA1 Message Date
Tom Boucher
e6f4bf3e77 fix(#2150): line-anchor + word-boundary the UI hint regex (review L1/L2)
Review found the hint value (yes|no) matched prefixes ('nope'/'not' read as
'no') and the hint regex was unanchored, so a mid-line prose mention like 'see
**UI hint**: no above' was treated as the authoritative metadata line. Line-
anchor (^ + m flag) so only a real hint line counts; word-boundary on the value
so nope/not do not mean no. Adds coverage for hint:yes over a pure-backend body
and the nope fall-through.
2026-07-12 16:22:47 -04:00
Tom Boucher
81ffd12967 docs(#2150): add changeset fragment for UI hint authority fix 2026-07-12 16:22:47 -04:00
Tom Boucher
0e59e9f05b fix(#2150): treat the UI hint yes/no line as authoritative in checkUiPresence
checkUiPresence ran UI_TOKENS (which includes the bare token 'UI') over the raw
phase-section text, so GSD's own '**UI hint**: no' metadata line matched the 'UI'
token and reported hasUI=true — blocking non-frontend phases that explicitly
declare themselves non-frontend via the documented convention (the plan-phase
UI-SPEC gate fired under the default workflow.ui_safety_gate=true).

- An explicit '**UI hint**: yes|no' line is now authoritative (mirrors how
  progress.md / new-project.md already parse it via 'UI hint.*yes'). hint:no ->
  hasUI=false; hint:yes -> hasUI=true.
- Any '**UI hint**:' line is stripped before token-sniffing, so a hint without a
  recognised yes/no cannot false-positive on the bare 'UI' token.
- With no hint line, behaviour is unchanged (token-sniffing on the rest).

Closes #2150
2026-07-12 16:22:47 -04:00
Tom Boucher
578a7fbc17 test(#2150): cover UI hint yes/no authority in checkUiPresence
Adds the divergent input the green suite lacked: the documented `**UI hint**:
no` metadata line. Asserts hint:no is authoritative non-frontend (no false
positive), hint:yes is authoritative frontend, a malformed hint is stripped so
its bare UI token does not fire, and hint:no overrides genuine UI language.
2026-07-12 16:22:47 -04:00
Tom Boucher
4c9fde8aa5 docs(#2140): backfill PR number in changeset fragment 2026-07-12 16:06:29 -04:00
Tom Boucher
b94f8754fa fix(#2140): scope hasRow to traceability-row shape (review L2)
hasRow keyed on a bare '| ID |' which could match the ID as the first cell of a
non-traceability table elsewhere in REQUIREMENTS.md, suppressing a real
table_unmatched signal. Require a second cell ('| ID | <phase> |') so only a
traceability-row shape counts as a row.
2026-07-12 16:06:29 -04:00
Tom Boucher
32b5262f7b docs(#2140): add changeset fragment for requirements mark-complete fix 2026-07-12 16:06:29 -04:00
Tom Boucher
87ab4a4896 fix(#2140): distinguish checkbox-only reconcile from full in requirements mark-complete
cmdRequirementsMarkComplete OR-ed its two write surfaces (the - [ ] checkbox and
the | ID | ... | Pending | traceability row) into one 'found' flag. When the
checkbox matched and no table row did, it reported the same 'updated: true,
marked_complete: [ID]' payload as a full reconcile — while the traceability row
stayed Pending. The already_complete branch used OR (checkbox done OR row done),
so re-running on the half-written file classified the drift as already_complete
and moved on. audit-milestone (which reads the table) still saw Pending.

- Track the two surfaces separately (checkboxHit / tableHit).
- Add a 'table_unmatched' bucket: an ID whose checkbox reconciled (this run or
  before) but whose traceability table has no row for it — only when a table
  actually exists (a table-less REQUIREMENTS.md is legitimate).
- Fix the already_complete predicate: fully reconciled requires the row Complete,
  OR the checkbox done with NO table — a [x] checkbox with an absent/Pending row
  is partial, not done.
- A table-less REQUIREMENTS.md stays a clean success (the OR's legitimate use).

The invariant: a not-fully-applied requirement no longer returns a payload
indistinguishable from a fully-applied one.

Closes #2140
2026-07-12 16:06:29 -04:00
Tom Boucher
cee8d7d723 test(#2140): cover checkbox/table divergence in requirements mark-complete
Adds the fixture the green suite lacked: an ID with a checkbox and a traceability
table that does NOT mention it. Asserts (1) a checkbox-only reconcile surfaces
table_unmatched instead of a silent full-success payload, (2) re-run on the
half-written file does NOT mask the drift as already_complete, and (3) a
REQUIREMENTS.md with no traceability table stays a clean success.
2026-07-12 16:06:29 -04:00
Tom Boucher
9208c40127 docs(#2138): backfill PR number in changeset fragment 2026-07-12 15:55:39 -04:00
Tom Boucher
924ff6822e fix(#2138): surface track_shipping push failures (review)
Review (MEDIUM): `git push ... 2>&1` did not check exit code, so a silent push
failure (auth-token expiry, network blip, non-fast-forward) would proceed to the
report step and declare success — silently reproducing the exact #2138 defect.
Add a fallback warning naming the rerun command so a failed push is visible
(best-effort: the PR already exists, so we still report it rather than abort).
Recaptures goldens + size baseline.
2026-07-12 15:55:39 -04:00
Tom Boucher
7837d67362 docs(#2138): add changeset fragment for ship-note push fix 2026-07-12 15:55:39 -04:00
Tom Boucher
aaf74878f7 fix(#2138): push the track_shipping ship-note onto the PR branch [ci skip]
track_shipping committed the STATE ship-note ('Phase N shipped — PR #N') AFTER
create_pr and never pushed it, so the commit stayed local-only. When the GitHub
PR merged (especially fast/auto-merge) the ship-note was not in the source branch
and never reached the default branch — STATE's ship-status was silently lost,
recoverable only by STATE self-heal on the next /gsd-start.

Push the ship-note commit onto the PR branch with a [ci skip] trailer. GitHub
honors [ci skip]/[skip ci], so this lands the note on merge without triggering a
redundant pipeline, and preserves the PR number in STATE.

Recaptures the 18 golden-install-parity fixtures + the workflow-size baseline
(only the ship.md entry changed in each).

Closes #2138
2026-07-12 15:55:39 -04:00
Tom Boucher
69ac4d0aa7 test(#2138): guard track_shipping pushes the ship-note (source-text contract)
ship.md IS the product the runtime loads. Assert its track_shipping step pushes
the committed ship-note onto the PR branch and carries a [ci skip] trailer, so a
regression to the local-only commit (the #2138 bug) is caught.
2026-07-12 15:55:39 -04:00
Tom Boucher
b145ff6177 docs(#2136): backfill PR number in changeset fragment 2026-07-12 15:34:59 -04:00
Tom Boucher
58b20c31f8 fix(#2136): migrate ALL operator-facing date sites to localToday (anti-pattern elimination)
The UTC-slice anti-pattern (deriving a calendar day a human reads by slicing a
UTC instant) remained in several operator-facing sites beyond the original
seamed last_activity set. Eliminate it everywhere a human reads the value as a
calendar day — do not leave known bad code in place:

- commands.cts cmdTodoComplete + cmdScaffold: completion/scaffold dates.
- gsd2-import.cts: migrated STATE.md 'Last activity' / 'Last session'.
- template.cts: plan frontmatter 'completed:' date.
- verify.cts: health --repair session-log date + '(Backfilled: <date>)' header.
- workstream.cts: workstream-create 'Last Activity' / 'created' + archive dirname.
- init.cts: JSON-bundle 'date' (-> localToday) + 'timestamp' (-> nowIso) at all
  three sites; drop the now-dead 'const now = new Date()' in cmdInitTodos /
  cmdInitMapCodebase (cmdInitQuick keeps it for the local branch-id derivation).
- state.cts: prune-archive '## Pruned <date>' header.
- state-transition.cts: the 7 seamed last_activity writes (prior commit).

No realClock.today() / .clock.today() / raw new Date().toISOString().split('T')
operator-facing sites remain in src/. Rebuilds the tracked
bin/lib/state-transition.cjs artifact to match.
2026-07-12 15:34:59 -04:00
Tom Boucher
9ab328917b docs(#2136): add changeset fragment for local calendar day fix 2026-07-12 15:34:59 -04:00
Tom Boucher
71edb27fe1 fix(#2136): route operator-facing date fields through local clock day
clock.today() derived the calendar day by slicing a UTC ISO instant
(nowIso().split('T')[0]), so in any negative-UTC-offset zone during UTC's early
hours last_activity named a day the operator had not reached yet — ahead of
last_updated's local date, written by the same call.

- Add Clock.localToday(): host-local YYYY-MM-DD via getMonth/getDate/
  getFullYear, honoring the same GSD_NOW_MS pin as today()/nowIso().
- Route operator-facing date-only fields through localToday(): last_activity
  (state-transition ×7, state.cts), roadmap 'completed <date>' (phase.cts,
  roadmap.cts), milestone completion date (milestone.cts), todo/scaffold
  completion (commands.cts — now threaded through the realClock seam).
- Leave today() (UTC) as the source for internal/cosmetic stamps.

Closes #2136
2026-07-12 15:34:59 -04:00
Tom Boucher
51b6e3c35c test(#2136): add localToday regression + mirror fake/inline clock stubs
Adds a dedicated regression (tests/fix-2136-clock-local-today.test.cjs):
- realClock.localToday() returns the LOCAL calendar day under a pinned instant
  + TZ (America/Chicago → 2020-06-14, the issue's repro instant).
- realClock.today() is unchanged (UTC) — internal/cosmetic stamps stay UTC.
- localToday === today on a UTC host (no spurious divergence).
- makeFakeClock mirrors localToday (drop-in Clock substitute).
- field-level: a 'sync' transition with a split clock (today≠localToday)
  writes the LOCAL day into Last Activity, proving the wiring uses localToday.

Mirrors localToday() in the fake clock helper and the inline fixedClock stubs
in state-transition.test.cjs / state-rebuild.test.cjs (the Clock interface now
requires it).
2026-07-12 15:34:59 -04:00
Tom Boucher
09a7cc9fea Merge pull request #2215 from open-gsd/fix/2135-milestone-name-clobber
fix(#2135): anchor milestone heading regex + strip delimiter, widen preserve guard
2026-07-12 14:21:50 -04:00
Tom Boucher
58b2aa1985 Merge branch 'next' into fix/2135-milestone-name-clobber 2026-07-12 12:59:02 -04:00
Tom Boucher
a02fe1213c Merge pull request #2214 from open-gsd/fix/2133-fast-md-log-to-state-schema-gate
fix(#2133): correct fast.md log_to_state column-count gate (NF-2)
2026-07-12 12:58:46 -04:00
Tom Boucher
a5110c4b8c Merge branch 'next' into fix/2133-fast-md-log-to-state-schema-gate 2026-07-12 12:42:15 -04:00
Tom Boucher
d474b5010d docs(#2135): backfill PR number in changeset fragment 2026-07-12 11:59:51 -04:00
Tom Boucher
af8d650da9 docs(#2135): add changeset fragment for milestone_name clobber fix 2026-07-12 11:41:14 -04:00
Tom Boucher
3bc53c8116 fix(#2135): anchor milestone heading regex + strip delimiter, widen preserve guard
getMilestoneInfo's `##` heading regex was unanchored (no `^`/`m`), so it
matched a `##` quoted mid-line inside a Milestones bullet and captured a
delimiter-led fragment into milestone_name — clobbering the curated name on
every phase transition.

roadmap-parser.cts (load-bearing):
- Consult the 🚧 name-bearing marker FIRST (reorder; it already existed but was
  shadowed by a spuriously-successful heading match).
- Anchor the `##` regex to line start (`^` + `m` flag) so a heading quoted
  in backticks/prose can no longer match.
- stripLeadingDelimiter removes a leading em/en-dash/colon/hyphen run that
  .trim() cannot (the `## vX.Y — Name` convention).

state.cts (defense in depth):
- Widen the #948 preserve guard from 'derived equals placeholder' to
  'derived does not look like a name' (non-empty, not placeholder, not
  punctuation-led), so a future bad derive preserves the curated name instead
  of silently overwriting it.

Closes #2135
2026-07-12 11:39:59 -04:00
Tom Boucher
5cbe250f36 test(#2135): add 5-case regression for getMilestoneInfo name derive
Adds the issue's verification matrix (cases A-E): a 🚧 bullet quoting a
nameless ## heading in backticks (the corruption), a nameless heading plus a
🚧 sub-heading carrying the name, canonical colon/em-dash shapes (no
regression), a 🚧 bullet only, and an anchored-regex guard proving a ##
heading quoted mid-line in backticks never matches.
2026-07-12 11:39:59 -04:00
Tom Boucher
f5370ef9c0 docs(#2133): backfill PR number in changeset fragment 2026-07-12 11:26:24 -04:00
Tom Boucher
cb48b2b48f test(#2133): drop no-op try/finally in runAgainst helper (review) 2026-07-12 11:13:48 -04:00
Tom Boucher
30469ba751 test(#2133): drop unused os import (lint clean) 2026-07-12 11:08:20 -04:00
Tom Boucher
c6b4304bab test(#2133): regenerate golden + workflow-size baselines for fast.md
The fast.md log_to_state fix changes an installed workflow file, so the per-
runtime golden-install-parity fixtures (18 runtimes) and the workflow-size
baseline are recaptured. Diff is exactly one entry per fixture (the fast.md
hash) and one baseline byte count — no spurious drift.
2026-07-12 10:48:43 -04:00
Tom Boucher
dca8bd9daa test(#2133): scope NF-2 assertion to the executable awk formula
The first draft banned the literal /NF-1/ anywhere in the block, but the
explanatory comment legitimately references 'NF-1' to document the off-by-one
root cause. Match the COL_COUNT awk assignment specifically so the structural
guard targets the executable formula, not the prose.
2026-07-12 10:48:43 -04:00
Tom Boucher
6504afa843 Merge pull request #2213 from open-gsd/fix/2116-surface-bare-require
fix(#2116): use resolvable paths in surface.md require + correct package name
2026-07-12 10:41:41 -04:00
Tom Boucher
1153eefedd Merge branch 'next' into fix/2116-surface-bare-require 2026-07-12 10:33:02 -04:00
Tom Boucher
c59a4a7abb docs(#2133): add changeset fragment for fast.md log_to_state fix 2026-07-12 10:28:40 -04:00
Tom Boucher
78b9b04f1d fix(#2133): correct fast.md log_to_state column-count gate (NF-2)
The guard used `awk -F'|' '{print NF-1}'` but a markdown header has a leading
and trailing pipe, so NF counts (real columns + 2); NF-1 is always one too
high. The `-eq 5` test was therefore unsatisfiable for the very 5-column
header quick.md writes, so /gsd-fast has never appended a Quick Task row since
PR #85 (regression closing #27).

- Count real columns with NF-2 (5 for the 5-col header, 6 for the 6-col).
- Accept 5 OR 6 columns (quick.md Step 7b writes both shapes).
- Select the appended row template by the detected count so its cell count
  always matches the header — keeps #27 fixed for the validate-mode table.

Closes #2133
2026-07-12 10:27:55 -04:00
Tom Boucher
e30f9370d3 test(#2133): execute fast.md log_to_state guard against both schemas
Replaces the removed prose-regex test (bug-3805-*) that let the off-by-one
ship green. Extracts the actual bash block deployed in fast.md's log_to_state
step and EXECUTES it against real STATE.md fixtures, asserting on the
filesystem result: a row is appended with a cell count matching the header for
both the 5-column (non-validate) and 6-column (validate) schemas, and an
unrecognized schema still skips with a warning.
2026-07-12 10:27:55 -04:00
Tom Boucher
87d1d5ac67 chore(#2116): correct changeset type and regenerate gsd-surface SKILL.md
The .changeset fragment used type "Documentation", which is not in the
allowed Added|Changed|Deprecated|Removed|Fixed|Security set — corrected
to Fixed (this fragment describes a bug fix). Regenerated
skills/gsd-surface/SKILL.md via gen:plugin-skills so it reflects the
resolvable require-path fix already applied to commands/gsd/surface.md,
clearing the stale-generated lint failure.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-12 09:54:23 -04:00
Tom Boucher
d221d0f830 docs(#2116): backfill PR number in changeset 2026-07-12 01:42:01 -04:00
Tom Boucher
872bb5b94d Merge pull request #2212 from open-gsd/chore/sync-next-version-1.7.0-rc.6
chore: sync next package version to 1.7.0-rc.6
2026-07-12 01:40:52 -04:00
github-actions[bot]
27f69cc489 chore: sync next package version to 1.7.0-rc.6 2026-07-12 05:40:45 +00:00
Tom Boucher
64c4a105f6 fix(#2116): use resolvable paths in surface.md require + correct package name
Four require() examples in commands/gsd/surface.md used bare
'gsd-core/...' specifiers that Node cannot resolve (wrong package
name + runtime-mirror layout off module path). Now derives the path
from runtimeConfigDir. Also fixes reinstall hint from
'npm i -g gsd-core' to 'npm i -g @opengsd/gsd-core'.
2026-07-12 01:32:12 -04:00
Tom Boucher
e6aef86cc7 Merge pull request #2211 from open-gsd/fix/2198-security-dead-scan-exports
fix(#2198): remove dead scan exports, correct injection-scan docs
2026-07-12 01:06:02 -04:00
Tom Boucher
1efa05b861 Merge branch 'next' into fix/2198-security-dead-scan-exports 2026-07-12 00:51:23 -04:00
Tom Boucher
dff6245de9 docs(#2198): backfill PR number in changeset 2026-07-12 00:37:55 -04:00
Tom Boucher
8022c5c864 fix(#2198): remove dead scan exports, correct injection-scan docs
scanEntropyAnomalies + shannonEntropy were dead exports with zero
production callers — the live hooks (gsd-prompt-guard.js,
gsd-read-injection-scanner.js) inline their own pattern subsets for
hook independence and never called these functions.

Changes:
- Remove scanEntropyAnomalies + shannonEntropy from src/security.cts
- Remove scanEntropyAnomalies test block from tests/security.test.cjs
- Correct REQ-SCAN-INJ-02/-03 in FEATURES.md (EN/zh-CN/ja-JP) to
  describe what actually runs live (injection patterns, invisible
  Unicode) vs CI-only (base64-decode, codebase scan)
- Correct docs/security/baseline.md §2.4 to clarify live hooks inline
  patterns, not import from security.cts
- Add regression test asserting the corrected contract
- scanForInjection retained: it serves as the CI codebase-scanner engine
2026-07-12 00:27:31 -04:00
Tom Boucher
89f991e9fc Merge pull request #2209 from open-gsd/fix/2117-audit-milestone-not-validated
fix(#2117): distinguish not-yet-validated phase from validated failure in audit-milestone
2026-07-12 00:25:55 -04:00
Tom Boucher
14b755d928 Merge branch 'next' into fix/2117-audit-milestone-not-validated 2026-07-12 00:03:52 -04:00
Tom Boucher
7252807194 Merge pull request #2210 from open-gsd/feat/2103-eos-vscode
feat(#2103): drive VS Code through the Embeddable Orchestration System (ADR-1239)
2026-07-11 23:39:21 -04:00
Tom Boucher
a0fafedfa0 feat(#2103): drive VS Code through the Embeddable Orchestration System (ADR-1239)
VS Code is a net-new EoS runtime that — unlike every prior migration — is NOT
CLI-installed (Marketplace/VSIX extension). It has zero runtime==='vscode'
branches in bin/install.js and stays that way (regression-guarded); it is driven
entirely through the negotiated imperative Host-Integration adapter.

Registry + validator (the hard part):
- capabilities/vscode/capability.json (role:runtime): full hostIntegration block
  (imperative / palette / active vscode.lm model / engine hook bus /
  sandboxed-storage / mcp transport / sandboxed-web runtime; dispatch nested,
  maxDepth 5 per VS Code's documented subagent depth).
- capability-validator.cjs extended so a role:runtime capability can legitimately
  declare "extension-distributed, no config directory": new configHome.kind:'none'
  + installSurface:'none' (+ GATE-A pairing + the parity maps), with localConfigDir
  and configHome.name made conditional on kind!=='none'. All 18 runtimes still
  validate; getDirName returns a distinct sentinel (not '.claude') for a no-config
  runtime.
- The add-a-registry-runtime tax: NON_INSTALLABLE_RUNTIMES exemption in the
  runtime-flags drift guard, vscode added to global-config-home SPECIAL_CASED,
  EXPECTED_PROFILES.vscode='ide', and the config-adapter/derivation/pin-count
  guards updated. No golden-install fixture, model-catalog, or CONFIGURATION rows
  (vscode never enters allRuntimes).

Dispatch + extension surface:
- Fixed vscode/extension.js's createHub()-no-args bug (every dispatch was
  UnknownCommand, masked by a vacuous reachability test) — now reuses the shared
  dispatchGsdCommand subprocess-shim (Node/desktop); the reachability test is
  tightened to assert real dispatch.
- Promoted the #1933 host binding to a shipped vscode/host-binding.js; activate()
  now composes the model/hookBus/stateIO seams through it. Corrected the model
  seam to VS Code's real API (vscode.lm.selectChatModels() -> model.sendRequest();
  vscode.lm.sendRequest does not exist) so the binding actually composes on real
  desktop VS Code instead of throwing.
- New vscode/browser.js Web Extension entry with ZERO Node APIs (the engine's
  config/capability loading is Node-bound, so the web entry registers the surface
  and directs full dispatch to the native MCP server — honestly documented).
- UPGRADE 1: GSD skills as native Language Model Tools (contributes.languageModelTools
  + vscode.lm.registerTool), invoke() dispatching through the hub.
- UPGRADE 2: native subagent dispatch wired onto #runSubagent /
  chat.subagents.allowInvocationsFromSubagents (fail-soft on API availability,
  maxDepth 5 enforced).
- vscode/package.json: browser entry, engines.vscode ^1.105, chatParticipants +
  languageModelTools contributions; fixed a stale activationPoints->activationEvents
  manifest key. Added "vscode" to the package files array.

Docs (## vscode matrix section) + changeset (Added).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-11 23:24:42 -04:00