* enhance(#4139): Phase 7 — the agent-skill seam picks the payload in code ADR-4139 stream 2. The non-Claude `#2454` persona fallback in cmdAgentSkills (src/init.cts) now selects between a canonical agents/<name>.md and a token-minimized agents/<name>.compact.md sibling based on workflow.compact_content, resolved in code (a real function call with a real exit code) rather than a prose config-get gate — the same precedent stream 1's spine/detail split established for a load-bearing seam, applied here because this seam already runs through TypeScript instead of an eager @-include. A missing compact sibling falls back to the canonical persona and discloses the fallback in the served payload itself (a leading HTML-comment provenance line), so the Done-when contract — compact when on, canonical when off, never silent or empty — holds even for an agent nobody has compacted yet. Authored a .compact.md sibling for all 35 shipped agents (agents/gsd-*.md), each an independent, complete rewrite (not an extraction — nothing is "moved" the way spine/detail moves text) that preserves frontmatter, every @-include, every output-format contract, and every guardrail verbatim while cutting restatement and verbose framing. Verified mechanically: every pair registers (a canonical sibling exists), every compact file is strictly smaller, and the full @-include set matches canonical's — including which references are standalone eager-load lines versus inline prose mentions, since demoting one to inline changes what the host actually substitutes. Traced the install path before writing any code (.gsd/phase/.../40-design.md): stageAgentsForRuntimeWithConverter glob-copies every agents/*.md file with no stem filtering under the default full profile, so the new .compact.md files install for free with zero installer changes — matching issue #4407's stated scope. A tiered agent profile that doesn't stage a compact sibling degrades through the same fallback-with-provenance path already required for an unauthored one, so no installer change is needed there either. Extends tests/helpers/compact-content-variant.cjs with an AGENTS_ROOT export (deliberately not folded into DEFAULT_VARIANT_ROOTS, since agent variants are reached by a generic code construction rather than a literal path in prose, and checkReachability's markdown-search shape has nothing to find there). Reachability is instead proven behaviorally: tests/agent-skills.test.cjs's new "#4407 compact payload selection" describe block spawns gsd_run agent-skills against real compact/canonical fixture pairs and asserts on the served payload, which can only pass if the seam genuinely wires through. Fixed a pre-existing test whose agents/*.md glob incidentally matched the new .compact.md siblings (tests/agent-skills.test.cjs's Skill-frontmatter drift guard) and added the 35 new agents/*.compact.md entries to docs/INVENTORY.md's roster, both real, unrelated-to-content defects the new files' mere existence surfaced. Regenerated: install-tree fixtures (19 runtimes now ship 35 more agent files under the full profile), INVENTORY-MANIFEST.json, and the variant-swap token benchmark baseline (npm run benchmark:compact-content-variants --write). Closes #4407. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * fix(#4407): apply orthogonal review findings from the compact-payload seam Standards axis of /code-review: extracted readNonEmptyFileOrNull(filePath) to collapse the duplicated read-and-empty-check shape between the compact and canonical branches in cmdAgentSkills, and updated the adjacent comment enumerating flat JSON extras to name agent_payload_variant alongside source/degraded (added by the prior commit, comment left stale). Security review and the Spec axis found no defects requiring a code change; their non-blocking observations (a pre-existing, unmodified path-construction pattern; the reasoned, documented substitution of a behavioral test for the literal reachability check) are recorded in .gsd/phase/enhance-4407-agent-skill-seam/60-review.json. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * fix(#4407): repo-wide roster/cap fixes surfaced by shipping .compact.md agents Root-caused via a real gsd-test run (93 failures) rather than guessing which tests glob agents/ naively. Two classes of defect, both genuine: 1. Identity-roster confusion (11 files/areas): many tests and one production script derive "the set of GSD agents" from `readdirSync(agentsDir).filter(f => f.endsWith('.md'))`, which incidentally matched the new .compact.md variant siblings too — a compact file is a rendering of an EXISTING agent identity, not a new one. Fixed at the shared root (tests/helpers/agent-roster.cjs's listAgentFiles, which several tests already consolidated on) and at each independent glob that didn't use it: agent-size-budget.test.cjs (tier-cap lookup now strips the .compact suffix before checking XL/LARGE membership, so a compact file inherits its canonical sibling's tier instead of silently falling through to DEFAULT), agent-skills-bootstrap.test.cjs, check-contract-drift.test.cjs (the actual script, not just its test), codex-config.test.cjs (confirmed directly against generateCodexAgentToml that a compact role's derived sandbox_mode is byte-identical to its canonical sibling's before excluding it — not assumed), and copilot-install.test.cjs (two counts that legitimately DO need both files — an installed-file count and a full-conversion smoke test — fixed to expect 70, not stay pinned to 35). no-bare-gsd-tools-command-position.test.cjs needed the opposite kind of fix: two compact files reproduce descriptive prose already allowlisted at their canonical file's line number; added matching entries at the compact files' own line numbers rather than excluding them from the scan (a genuine bare gsd-tools command-position bug in a compact file would be as real a defect as in canonical). 2. A hard, non-ackable cap (found via emitted-attribution.test.cjs's real-tree run): six agents' compact renditions (gsd-debugger, gsd-executor, gsd-phase-researcher, gsd-plan-checker, gsd-planner, gsd-verifier) exceed the 32,768-byte NEW_FILE_CAP (ADR-1610) even after aggressive compaction — confirmed structural, not a compaction-quality gap: each is dominated by content this phase's own rules require verbatim (the ~2.6 KB gsd_run bootstrap preamble runtime-launcher-parity.test.cjs requires inlined in every agent that calls gsd_run, output-format contracts, guardrails). ADR-4139's prescribed remedy (spine + lazily-read parts) has no landing spot in cmdAgentSkills's single-file synchronous read. Removed these 6 compact files rather than ship an over-cap file or invent a multi-part read mechanism out of scope for this phase; recorded by name with the reason in .gsd/phase/enhance-4407-agent-skill-seam/40-design.md and 50-test-matrix.md, per #4407's own "or explicitly recorded as not worth covering" allowance. Their canonical personas are served correctly today via the fallback-with-disclosed-provenance path this phase's own Done-when #2 already requires — 29 of 35 agents now have a compact variant. Also fixes an unrelated, genuinely pre-existing defect this gsd-test run surfaced: gsd-core/workflows/execute-plan.md sat 21 bytes over its own DEFAULT-tier hard cap (40,960 bytes) at the branch point, before any change in this PR touched it — confirmed via `git show <merge-base>:...execute-plan.md | wc -c`. Per CLAUDE.md's no-deferral rule, fixed inline rather than filed: two meaning-preserving trims in the <success_criteria> block (a repeated parenthetical replaced with a same-exception reference; one redundant qualifier dropped) bring it to 40,940 bytes. Regenerated install-tree fixtures, INVENTORY-MANIFEST.json, and the variant benchmark baseline to reflect the 6 removed files. Docs/INVENTORY.md's 6 now-orphaned roster rows removed alongside them. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * fix(#4407): make .compact.md-aware roster checks resilient to partial coverage Round 2 of the gsd-test-driven roster fixes: two checks assumed every agent has a compact sibling (true for 29 of 35 after the NEW_FILE_CAP exception), breaking once 6 stems legitimately have none. - tests/agent-classification-parity.test.cjs: the INVENTORY.md parser was picking up the "### Compact Payload Variants" subsection's rows as phantom/uncounted entries in the primary/advanced/inventory-only classification this test validates — a compact row documents an existing agent's alternate rendition and never gets its own AGENTS.md heading, so it was never meant to participate in that classification. Excluded at the parser, not per-assertion. - tests/copilot-install.test.cjs: the derived expected-file-list generator assumed every listAgentFiles() stem has a .compact.md source sibling; checks disk per stem now instead. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * docs(#4407): backfill changeset PR number Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> --------- Co-authored-by: sim <sim@local> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
220 lines
12 KiB
JavaScript
220 lines
12 KiB
JavaScript
// allow-test-rule: source-text-is-the-product (#2751)
|
|
'use strict';
|
|
|
|
// Regression guard for #2751: agents/*.md and gsd-core/workflows/*.md must not
|
|
// instruct an agent to invoke a BARE `gsd-tools <verb> <args>` command. The bare
|
|
// word fails with "command not found" on a shim-only install (no `gsd-tools`
|
|
// binary on PATH) — every such instruction must use the `gsd_run` resolver the
|
|
// same files already define. #725 fixed this only for the Codex install-
|
|
// conversion pipeline; the Claude-facing SOURCE shipped the bare calls verbatim
|
|
// until #2751 normalized them.
|
|
//
|
|
// A pure regex cannot perfectly distinguish an imperative ("Use `gsd-tools query
|
|
// commit` to commit") from a descriptive mention ("`gsd-tools query commit`
|
|
// returns an envelope") — both contain the same command phrase. So this guard
|
|
// scans for `gsd-tools <verb> <arg>` (the operative shape — a verb followed by
|
|
// its arguments) and subtracts a documented ALLOWLIST of known descriptive
|
|
// mentions that NAME the command without instructing literal invocation. Any
|
|
// site NOT in the allowlist is a new operative bare call and fails the gate.
|
|
//
|
|
// Verb coverage is derived LIVE from the gsd-tools host-command router
|
|
// (`gsd-core/bin/gsd-tools.cjs`) by reading the `'verb': routeHandler` / `verb:
|
|
// routeHandler` entries. This is deliberate — the original #2751 guard used a
|
|
// hand-maintained 6-verb list that silently false-passed `verify-summary` (the
|
|
// `verify` branch matched the prefix, then died on the hyphen), and missed
|
|
// `windows`, `worktree`, `smart-entry`, and `quick-tasks-append` entirely.
|
|
// Deriving the set from the router means a new verb registered there is covered
|
|
// here the moment it lands — no second list to keep in sync.
|
|
//
|
|
// Source-text guard: the deployed contract IS the markdown text the runtime
|
|
// loads. Scans FULL file text (the real hits lived in inline prose/table cells,
|
|
// not fenced bash blocks).
|
|
|
|
const { test } = require('node:test');
|
|
const assert = require('node:assert/strict');
|
|
const fs = require('node:fs');
|
|
const path = require('node:path');
|
|
|
|
const ROOT = path.resolve(__dirname, '..');
|
|
const ROUTER_PATH = path.join(ROOT, 'gsd-core', 'bin', 'gsd-tools.cjs');
|
|
// #3809 widened this from agents/ + workflows/ to include gsd-core/references/,
|
|
// which was carrying 37 bare calls the guard simply never looked at.
|
|
//
|
|
// commands/ is deliberately NOT here, and that is a finding rather than an
|
|
// oversight. Its files cannot use the shared launcher the way workflows and agents
|
|
// do: tests/graphify-visualization.test.cjs extracts individual Step-3 shell chains
|
|
// and runs them standalone, so each fenced block needs its OWN preamble —
|
|
// graphify.md carries five on purpose, and collapsing them to one produces
|
|
// `gsd_run: command not found` (exit 127). tests/gsd-tools-path-refs.test.cjs
|
|
// (#1766) separately pins commands/gsd/workstreams.md to the literal string
|
|
// `gsd-tools query workstream.list`. Bringing commands/ under this guard therefore
|
|
// needs those two contracts reconciled first; it is not a scan-set widening.
|
|
//
|
|
// skills/ is absent for a different reason: it is generated from commands/ by
|
|
// scripts/gen-plugin-skills.cjs and pinned by lint:generated-sync, so guarding the
|
|
// source guards both, and scanning the generated mirror would double-report every
|
|
// future offender.
|
|
const SCAN_DIRS = [
|
|
'agents',
|
|
path.join('gsd-core', 'workflows'),
|
|
path.join('gsd-core', 'references'),
|
|
];
|
|
|
|
// Derive the verb set the bare-call guard matches against. Most top-level
|
|
// verbs live in the host-command router table (`HOST_COMMAND_ROUTERS`, ~70
|
|
// entries, exported by gsd-tools.cjs for exactly this kind of test); this
|
|
// reads that real exported object directly so new router verbs are covered
|
|
// the moment they land. A handful of verbs are dispatched as FAMILIES (their
|
|
// own `command === 'verb'` arm, not a route-table entry): `query` (line
|
|
// ~2876), `intel`, `verify`, and `graphify`. These are stable, documented
|
|
// families, so they are supplemented explicitly here rather than parsed from
|
|
// the help string (whose prose mixes real verbs with English words like
|
|
// "for"/"output"/"working", producing noise). If a family verb is ever
|
|
// promoted into the route table the union dedupes harmlessly; if a NEW
|
|
// family verb is added it must be added here.
|
|
//
|
|
// Sorted longest-first so a hyphenated verb (`verify-summary`) is preferred over
|
|
// its prefix (`verify`) — the exact ordering bug that let `verify-summary` slip
|
|
// past a fixed 6-verb list during the first #2751 pass.
|
|
const FAMILY_DISPATCHED_VERBS = ['query', 'intel', 'verify', 'graphify'];
|
|
function readRouterVerbs() {
|
|
const { HOST_COMMAND_ROUTERS } = require(ROUTER_PATH);
|
|
const verbs = new Set(FAMILY_DISPATCHED_VERBS);
|
|
for (const verb of Object.keys(HOST_COMMAND_ROUTERS)) verbs.add(verb);
|
|
return [...verbs].sort((a, b) => b.length - a.length);
|
|
}
|
|
|
|
const VERBS = readRouterVerbs();
|
|
|
|
// Operative shape: `gsd-tools <known-verb>` followed by whitespace and a real
|
|
// argument (the verb is NOT the close of a code span — there is a real arg
|
|
// after it). Restricting to KNOWN verbs (vs any `[a-z-]+` token) avoids
|
|
// false-flagging English prose like "gsd-tools through the ...".
|
|
const BARE_COMMAND_RE = new RegExp(
|
|
String.raw`(?:^|[^./A-Za-z0-9_-])gsd-tools\s+(` + VERBS.join('|') + String.raw`)\s+[^\s` + '`' + String.raw`]`
|
|
);
|
|
|
|
// Lines that legitimately embed `gsd-tools <verb> <arg>` but are descriptive, not
|
|
// command-position: they NAME the command (in prose / parenthetical examples /
|
|
// return-envelope descriptions) rather than instructing an agent to run the bare
|
|
// word. Keyed `file:line` so a rewording that moves the mention forces a conscious
|
|
// allowlist update rather than silently passing.
|
|
//
|
|
// Each entry MUST carry a one-line reason; the test prints the allowlist on
|
|
// failure so a reviewer can see exactly what is sanctioned.
|
|
const PROSE_ALLOWLIST = [
|
|
{ file: 'agents/gsd-executor.md', line: 823, reason: 'describes the SDK return envelope of `gsd-tools query commit`; not an instruction to run the bare word' },
|
|
{ file: 'agents/gsd-phase-researcher.md', line: 33, reason: 'package-legitimacy provenance rule names the command as the source of an OK verdict; descriptive' },
|
|
{ file: 'agents/gsd-roadmapper.md', line: 660, reason: 'parenthetical "e.g." naming SDK queries a user *could* run; not an agent instruction (#4134 shifted it from 647: the H1 template section added above moved the line, the mention is unchanged)' },
|
|
{ file: 'agents/gsd-intel-updater.md', line: 40, reason: 'cross-platform note names the `gsd-tools intel <subcommand>` CLI surface descriptively ("CLI invocations go through..."); not an agent instruction' },
|
|
{ file: 'gsd-core/workflows/execute-plan.md', line: 419, reason: 'describes the downstream SDK validation step (`validated downstream by ...`); names the mechanism, does not instruct the agent to type it' },
|
|
// #4407: .compact.md variant siblings carry the same descriptive prose as
|
|
// their already-allowlisted canonical line above, at a different line
|
|
// number in a different file.
|
|
{ file: 'agents/gsd-intel-updater.compact.md', line: 32, reason: 'compact variant of the already-allowlisted gsd-intel-updater.md:40 cross-platform note; same descriptive mention' },
|
|
{ file: 'agents/gsd-roadmapper.compact.md', line: 363, reason: 'compact variant of the already-allowlisted gsd-roadmapper.md:660 parenthetical; same descriptive mention' },
|
|
];
|
|
|
|
// Resolver-snippet definition lines / probes that must never be flagged. A line
|
|
// is a resolver/probe definition when it assigns the shim name, probes PATH, or
|
|
// assigns GSD_TOOLS / defines the gsd_run function — NOT merely when it contains
|
|
// the substring `gsd-tools.cjs` (which would blanket-exempt any prose that
|
|
// happens to name the file).
|
|
const EXCLUSION_RE = /_GSD_SHIM_NAME\s*=|command -v gsd-tools|\bGSD_TOOLS\s*=|gsd_run\s*\(\)\s*\{/;
|
|
|
|
function collectMdFiles(dir) {
|
|
const results = [];
|
|
let entries;
|
|
try { entries = fs.readdirSync(dir, { withFileTypes: true }); } catch { return results; }
|
|
for (const entry of entries) {
|
|
const full = path.join(dir, entry.name);
|
|
if (entry.isDirectory()) {
|
|
results.push(...collectMdFiles(full));
|
|
} else if (entry.isFile() && entry.name.endsWith('.md')) {
|
|
results.push(full);
|
|
}
|
|
}
|
|
return results;
|
|
}
|
|
|
|
function findBareCommandPositionCalls() {
|
|
const offenders = [];
|
|
for (const scanDir of SCAN_DIRS) {
|
|
const abs = path.join(ROOT, scanDir);
|
|
for (const file of collectMdFiles(abs)) {
|
|
// Normalize to forward slashes so the file:line PROSE_ALLOWLIST keys match
|
|
// identically on every OS — path.relative() returns backslash separators on
|
|
// Windows, which would defeat the allowlist lookup and false-flag the 6
|
|
// descriptive mentions (#2751 Windows CI failure).
|
|
const rel = path.relative(ROOT, file).split(path.sep).join('/');
|
|
const lines = fs.readFileSync(file, 'utf8').split(/\r?\n/);
|
|
for (let i = 0; i < lines.length; i += 1) {
|
|
const line = lines[i];
|
|
if (EXCLUSION_RE.test(line)) continue;
|
|
const match = line.match(BARE_COMMAND_RE);
|
|
if (!match) continue;
|
|
const loc = `${rel}:${i + 1}`;
|
|
const allowed = PROSE_ALLOWLIST.find((a) => a.file === rel && a.line === i + 1);
|
|
if (allowed) continue;
|
|
offenders.push({ loc, verb: match[1], text: line.trim() });
|
|
}
|
|
}
|
|
}
|
|
return offenders;
|
|
}
|
|
|
|
test('verb set was derived from the router (guards against a silent extraction regression)', () => {
|
|
// If the router is refactored so the `routeHandler` pattern no longer matches,
|
|
// VERBS would be empty and the bare-call guard below would false-pass
|
|
// everything. Sanity-bound it: a healthy router exposes many host verbs.
|
|
assert.ok(
|
|
VERBS.length > 40,
|
|
`Expected to derive >40 verbs from ${path.relative(ROOT, ROUTER_PATH)}, got ${VERBS.length}. ` +
|
|
'If the router table changed shape, update readRouterVerbs() so the guard keeps coverage.'
|
|
);
|
|
// Longest-first ordering is what lets verify-summary win over verify.
|
|
const sample = ['verify-summary', 'verify', 'query', 'intel', 'graphify', 'windows', 'worktree', 'smart-entry', 'commit', 'check'];
|
|
for (const v of sample) {
|
|
assert.ok(VERBS.includes(v), `expected verb '${v}' in derived set (router/family drift?)`);
|
|
}
|
|
});
|
|
|
|
test('no command-position bare gsd-tools <verb> survives in agents/ or workflows/ (#2751)', () => {
|
|
const offenders = findBareCommandPositionCalls();
|
|
assert.strictEqual(
|
|
offenders.length,
|
|
0,
|
|
'Bare `gsd-tools <verb> <args>` command-position calls must use the `gsd_run` ' +
|
|
'resolver (they fail with "command not found" on a shim-only install — #2751). ' +
|
|
`Found ${offenders.length} offender(s):\n` +
|
|
offenders.map((o) => ` ${o.loc} [${o.verb}] ${o.text}`).join('\n') +
|
|
'\n\nIf a hit is a descriptive prose mention (not an instruction to run the bare ' +
|
|
'word), add it to PROSE_ALLOWLIST in this test with a reason.'
|
|
);
|
|
});
|
|
|
|
test('every PROSE_ALLOWLIST entry still matches a real gsd-tools mention (no stale allowlist entries)', () => {
|
|
// An allowlist entry that no longer matches anything is stale — it was either
|
|
// fixed (remove it) or the line moved (update it). Either way it must not linger.
|
|
const stale = [];
|
|
for (const entry of PROSE_ALLOWLIST) {
|
|
const file = path.join(ROOT, entry.file);
|
|
let lines;
|
|
try { lines = fs.readFileSync(file, 'utf8').split(/\r?\n/); } catch (e) {
|
|
stale.push({ ...entry, problem: 'file missing' });
|
|
continue;
|
|
}
|
|
const line = lines[entry.line - 1];
|
|
if (!line || !BARE_COMMAND_RE.test(line) || EXCLUSION_RE.test(line)) {
|
|
stale.push({ ...entry, problem: 'line no longer matches a bare gsd-tools mention', actual: line ? line.trim() : '(line absent)' });
|
|
}
|
|
}
|
|
assert.strictEqual(
|
|
stale.length,
|
|
0,
|
|
'PROSE_ALLOWLIST has stale entries (the mentioned line no longer carries a bare ' +
|
|
'`gsd-tools <verb> <arg>` mention). Remove or update them:\n' +
|
|
stale.map((s) => ` ${s.file}:${s.line} — ${s.problem}${s.actual ? ` (actual: ${s.actual.slice(0, 80)})` : ''}`).join('\n')
|
|
);
|
|
});
|