Files
msd-core/tests/bug-2636-gsd-sdk-query-silent-swallow.test.cjs
Tom Boucher 334a64168e chore(npm): rebrand packages to @opengsd scope (#127)
* chore(npm): rebrand packages to @opengsd scope

Rename:
- get-shit-done-redux → @opengsd/get-shit-done-redux
- @gsd-redux/sdk → @opengsd/gsd-sdk

Add publishConfig.access=public for first-time scoped publish.
CLI binary names (get-shit-done-redux, gsd-sdk, gsd-tools) unchanged.

Sweeps install commands, npx invocations, CI publish/version-check
workflows, tests, docs, READMEs (all translations), and the
PACKAGE_NAME constant in check-latest-version.

Bumps qs 6.15.1 → 6.15.2 to clear a moderate advisory surfaced by
the audit-clean test (GHSA-q8mj-m7cp-5q26).

Closes #126

* chore: pin 2.0.0 release + remove canary workflow

- Bump both packages 1.50.0-canary.0 → 2.0.0 for first @opengsd publish
- Remove .github/workflows/canary.yml and canary dist-tag handling in
  release.yml / release-sdk.yml
- Drop canary section from VERSIONING.md

Refs #126

* chore: address review findings + harden tarball-smoke timeout

- .changeset/opengsd-org-rename.md: match project's custom
  parse.cjs frontmatter (type: Changed / pr: 127); the scoped
  @changesets/cli keys were silently rejected.
- CONTEXT.md: drop two canary-stream policy lines and a dangling
  DEFECT.CANARY-VERSION-LEAK.cross-ref now that canary.yml is gone.
- tests/release-tarball-smoke.install.test.cjs: pass
  timeout: 600_000 for npm pack + global install; the 3-minute
  runNpm default was timing out on slower Docker hosts (cartographer).

Refs #126

* fix(sdk): add missing type/runtime devDependencies for build

prepublishOnly invokes tsc which couldn't resolve @types/node,
@types/ws, or synckit. They had been hoisted from root but were
not declared in sdk/'s own package.json — first publish from a
clean SDK tree failed.

Refs #126

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix(ci): use npm pack stdout instead of glob to find tarball

`npm pack --silent` for a scoped package (@opengsd/get-shit-done-redux)
produces `opengsd-get-shit-done-redux-*.tgz`, not `get-shit-done-redux-*.tgz`.
Capture the filename from stdout instead of a hardcoded glob so the step
works regardless of package name format.

Fixes smoke (ubuntu-latest, 22, false) CI failure.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* ci: treat workflow-file changes as test-skip eligible

`.github/workflows/install-smoke.yml` (and other workflow files)
were in neither `test.yml` paths nor `test-skip.yml` paths-ignore,
so neither workflow ran on a workflow-only commit — leaving the
required test-skip check perpetually missing.

Refs #126

* chore: reset version to 1.0.0 for first @opengsd publish

Nothing has been published yet under the @opengsd scope, so the
inaugural release uses 1.0.0 rather than 2.0.0. The "major bump"
in the changeset reflects the breaking install-command change for
users migrating from the prior unscoped `get-shit-done-redux`, not
a numeric continuation from a 1.x line under the new identity.

Refs #126

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-22 16:22:41 -04:00

74 lines
2.9 KiB
JavaScript

/**
* Regression guard for #2636 — `gsd-sdk query agent-skills <slug>` calls in
* workflows must NOT silently swallow failures via a bare `2>/dev/null`.
*
* Root cause of #2636: when the installed npm `@opengsd/gsd-sdk` was stale and
* the `agent-skills` handler was missing, every workflow line of the form
* AGENT_SKILLS_X=$(gsd-sdk query agent-skills <slug> 2>/dev/null)
* resolved to empty string, and the `agent_skills.<slug>` config was never
* injected into spawn prompts. No error ever surfaced.
*
* Fix: remove `2>/dev/null` from `agent-skills` calls so any SDK failure
* (stale binary, unregistered handler, runtime error) prints to the
* workflow's stderr and is visible to the user.
*
* Test scope: ONLY `gsd-sdk query agent-skills …` (the exact noun implicated
* in #2636). Other `gsd-sdk query config-get …` patterns commonly use
* `2>/dev/null || echo "default"` which IS exit-code aware (the `||` branch
* only runs on non-zero exit) and is a documented fallback pattern.
*
* Scans: get-shit-done/workflows/**\/*.md and commands/**\/*.md
*/
const { describe, test } = require('node:test');
const assert = require('node:assert/strict');
const fs = require('fs');
const path = require('path');
const REPO_ROOT = path.join(__dirname, '..');
const SCAN_ROOTS = [
path.join(REPO_ROOT, 'get-shit-done', 'workflows'),
path.join(REPO_ROOT, 'commands'),
path.join(REPO_ROOT, 'agents'),
];
function walk(dir, out) {
let entries;
try { entries = fs.readdirSync(dir, { withFileTypes: true }); } catch { return; }
for (const entry of entries) {
if (entry.name === 'node_modules' || entry.name === '.git') continue;
const full = path.join(dir, entry.name);
if (entry.isDirectory()) walk(full, out);
else if (entry.isFile() && entry.name.endsWith('.md')) out.push(full);
}
}
describe('bug #2636 — agent-skills query must not silently swallow failures', () => {
test('no `gsd-sdk query agent-skills ... 2>/dev/null` in workflows', () => {
const files = [];
for (const root of SCAN_ROOTS) walk(root, files);
assert.ok(files.length > 0, 'expected to scan some workflow/command files');
// Match `gsd-sdk query agent-skills <slug>` followed (on the same line)
// by `2>/dev/null` — the silent-swallow anti-pattern.
const ANTI = /gsd-sdk\s+query\s+agent-skills\b[^\n]*2>\/dev\/null/;
const offenders = [];
for (const file of files) {
const lines = fs.readFileSync(file, 'utf8').split('\n');
for (let i = 0; i < lines.length; i++) {
if (ANTI.test(lines[i])) {
offenders.push(path.relative(REPO_ROOT, file) + ':' + (i + 1) + ': ' + lines[i].trim());
}
}
}
assert.strictEqual(
offenders.length, 0,
'Found `gsd-sdk query agent-skills ... 2>/dev/null` (silent swallow — ' +
'root cause of #2636). Remove `2>/dev/null` so SDK failures surface.\n\n' +
offenders.join('\n'),
);
});
});