'use strict'; // allow-test-rule: reads markdown product files (gsd-executor.md, worktree-path-safety.md) to verify structural protocol — not source-grep // Regression guards for bug #3097 and #3099. // // #3097: gsd-executor's worktree HEAD guard used `if [ -f .git ]` to detect // worktree mode. After a Bash `cd` out of the worktree into the main repo, // `.git` is a DIRECTORY (not a file), so the test is false and the entire // HEAD safety block is silently skipped. Commits then land on whatever branch // the main repo has checked out — not the per-agent worktree branch. // // #3099: Executor agents construct absolute paths from `pwd` captured in the // orchestrator context (main repo root). Edit/Write calls using these paths // resolve to the main repo, not the worktree. git commit from the worktree // sees a clean tree; the work is silently lost or leaks to main. const { describe, test } = require('node:test'); const assert = require('node:assert/strict'); const fs = require('node:fs'); const path = require('node:path'); const ROOT = path.join(__dirname, '..'); const executorSrc = fs.readFileSync( path.join(ROOT, 'agents', 'gsd-executor.md'), 'utf8', ); const executePhaseSrc = fs.readFileSync( path.join(ROOT, 'gsd-core', 'workflows', 'execute-phase.md'), 'utf8', ); describe('bug #3097: cwd-drift sentinel in gsd-executor.md', () => { test('task_commit_protocol has cwd-drift assertion step (0a)', () => { const protocolIdx = executorSrc.indexOf(''); const protocolEnd = executorSrc.indexOf(''); assert.ok(protocolIdx !== -1 && protocolEnd !== -1, 'task_commit_protocol block not found'); const protocol = executorSrc.slice(protocolIdx, protocolEnd); assert.ok( protocol.includes('cwd') || protocol.includes('drift') || protocol.includes('gsd-spawn-toplevel'), 'task_commit_protocol missing cwd-drift assertion step — #3097 fix not applied', ); }); test('sentinel uses git rev-parse --git-dir to detect worktree', () => { const protocolIdx = executorSrc.indexOf(''); const protocolEnd = executorSrc.indexOf(''); const protocol = executorSrc.slice(protocolIdx, protocolEnd); assert.ok( protocol.includes('rev-parse --git-dir') || protocol.includes('worktrees/'), 'cwd-drift detection does not use git rev-parse --git-dir or .git/worktrees/ pattern', ); }); test('cwd-drift check precedes HEAD assertion', () => { const protocolIdx = executorSrc.indexOf(''); const protocolEnd = executorSrc.indexOf(''); const protocol = executorSrc.slice(protocolIdx, protocolEnd); const driftIdx = protocol.search(/cwd.drift|gsd-spawn-toplevel|drift.*assertion/i); const headIdx = protocol.indexOf('Pre-commit HEAD safety assertion'); assert.ok(driftIdx !== -1, 'cwd-drift assertion not found'); assert.ok(headIdx !== -1, 'HEAD assertion not found'); assert.ok(driftIdx < headIdx, 'cwd-drift assertion must precede HEAD assertion (step 0a before step 0)'); }); }); describe('bug #3099: absolute-path safety guidance in gsd-executor.md', () => { test('task_commit_protocol documents absolute-path safety', () => { const protocolIdx = executorSrc.indexOf(''); const protocolEnd = executorSrc.indexOf(''); const protocol = executorSrc.slice(protocolIdx, protocolEnd); assert.ok( (protocol.includes('absolute') || protocol.includes('absolute-path')) && (protocol.includes('worktree') || protocol.includes('WT_ROOT')), 'task_commit_protocol missing absolute-path safety guidance — #3099 fix not applied', ); }); test('execute-phase.md parallel_execution block references path safety', () => { const parallelIdx = executePhaseSrc.indexOf(''); assert.ok(parallelIdx !== -1, 'parallel_execution block not found in execute-phase.md'); // Verify the worktree-path-safety.md reference is present in the execution_context // (loaded via @ reference rather than inlined — the safe extract pattern) assert.ok( executePhaseSrc.includes('worktree-path-safety.md'), 'execute-phase.md does not reference worktree-path-safety.md in execution_context', ); }); test('execute-phase prompt anchors subagent file paths to project_root before files_to_read (#280)', () => { const filesIdx = executePhaseSrc.indexOf(''); assert.ok(filesIdx !== -1, 'files_to_read block not found in execute-phase.md'); const dispatchSnippet = executePhaseSrc.slice(filesIdx, filesIdx + 1800); assert.ok( dispatchSnippet.includes('PROJECT_ROOT=$(git rev-parse --show-toplevel'), 'executor dispatch must compute PROJECT_ROOT in the prompt before file reads', ); assert.ok( dispatchSnippet.includes('${PROJECT_ROOT}/'), 'executor files_to_read paths must be anchored to ${PROJECT_ROOT}/', ); }); test('worktree-path-safety.md reference file exists', () => { assert.ok( fs.existsSync(path.join(ROOT, 'gsd-core', 'references', 'worktree-path-safety.md')), 'gsd-core/references/worktree-path-safety.md does not exist', ); }); test('worktree-path-safety.md contains cwd-drift and absolute-path guards', () => { const safetySrc = fs.readFileSync( path.join(ROOT, 'gsd-core', 'references', 'worktree-path-safety.md'), 'utf8', ); assert.ok(safetySrc.includes('gsd-spawn-toplevel') || safetySrc.includes('cwd-drift'), 'worktree-path-safety.md missing cwd-drift sentinel content'); assert.ok(safetySrc.includes('WT_ROOT') || safetySrc.includes('absolute'), 'worktree-path-safety.md missing absolute-path guard content'); }); });