* test(#3909): failing-first suite for the fabricated probe fallbacks
Binds the four fabrication sites found by executing the surfaces (ADR-3889
failure class (c)), each with a positive control so an over-firing fix goes red:
- the blocking api-coverage.verify-pre gate certifying "no external-API
integration" from a zero-byte phase scope
- the assumption-delta query route scanning an unresolvable phase section as
the empty string and reporting it as an examined negative
- both capability fragments' probe fallbacks, which append a fabricated
verdict rather than replacing, and fire on the legitimate exit-1 negative
Verification runs on the remote runner.
Refs #3909
* enhance(#3909): a probe that could not run no longer asserts a verdict
ADR-3889 Phase 5. Four sites turned a failed or unexamined probe into a
confident negative; each now reports what it could not establish.
- check api-coverage.verify-pre: a phase with no plan body and no roadmap
section ran detection over zero bytes and PASSED the blocking seal gate,
certifying "no external-API integration" from input it never read. It now
holds with scope_unavailable. The discriminator is bytes examined, never
signals found, so a phase whose plans are real and simply carry no API
vocabulary passes exactly as before.
- query assumption-delta scan: an unresolvable phase section was scanned as
the empty string and reported as an examined negative. It now returns
{skipped, reason: phase_unresolved}, still at exit 0 — an ADR-2980 degraded
result in the payload, leaving the gsd-tools exit projection to P8.
- both capability fragments: `|| echo '{"detected":false}'` appended rather
than replaced, and fired on the legitimate exit-1 negative, so a correct
answer and an honest skip both arrived as two concatenated objects. They now
keep the probe's own payload and manufacture only an explicit
probe_unavailable skip when the probe produced nothing at all.
Every registered outcome is more restrictive on a blocking gate, so this can
turn a false green red and never a red green.
Docs: FEATURES 156, CONFIGURATION (both keys), references/api-coverage.md
seal-time outcome table, and a new how-to for the reason-code vocabulary.
Verification runs on the remote runner.
Closes#3909
* test(#3909): correct the stale unknown-phase assertion
`unknown phase → detected:false, no throw (graceful)` scanned phase 999
against a two-phase roadmap and asserted `detected === false`. That pinned
the fabrication as intended behavior: the phase does not exist, so the
detector was handed the empty string and its "no core assumption changed"
answer described nothing that was ever read.
It now asserts the skipped-with-reason shape. The graceful-degradation
contract the test was actually protecting — the query succeeds and does not
throw on an unknown phase — is unchanged.
Found by code review, not by the author.
Refs #3909
* docs(#3909): author the FEATURES entry in its generator source
`docs/FEATURES.md` is generated by `scripts/gen-features.cjs` from the
per-feature fragments in `docs/features/`. The API-coverage entry was edited
in the generated file, so the next regeneration silently dropped it.
The text now lives in `docs/features/api-coverage-gate.md` and
`docs/FEATURES.md` is regenerated from it, leaving the shipped file
byte-identical and its content actually derivable.
Caught by `lint:generated-sync`.
Refs #3909
* test(#3909): bind the skip to "not found", and pin the discriminator
The first verification run went red on one case, and the case was wrong
rather than the code.
`getRoadmapPhaseWithFallback` returns `null` for an unknown phase and for a
missing ROADMAP.md, but for a section whose body is whitespace-only it returns
the heading line alone — which is not empty. So a body-less section WAS found,
and reporting `detected:false` over its heading is a real negative, not a
fabrication. The test had assumed the resolver yielded `''` there.
Correcting the test rather than the resolver keeps `skipped` bound to the
distinction the issue asks for — found versus not found — and avoids diverging
`assumption-delta scan` from `roadmap.get-phase`, which the fragment documents
as sharing one resolver.
Also adds the seeded property the test matrix had promised: for any plan body,
the scope read back is whitespace-only exactly when the body was. That pins the
gate's discriminator to bytes examined, so it cannot quietly become "no signals
found", across unicode whitespace and CRLF.
`docs/INVENTORY.md` picks up the reference doc's new seal-time outcome table —
surfaced by the co-change gate, not by a lint failure.
Refs #3909
* chore(#3909): backfill the changeset PR number
Refs #3909
---------
Co-authored-by: sim <sim@local>