Files
msd-core/tests/bug-3290-intel-updater-layout-block.test.cjs
Tom Boucher 334a64168e chore(npm): rebrand packages to @opengsd scope (#127)
* chore(npm): rebrand packages to @opengsd scope

Rename:
- get-shit-done-redux → @opengsd/get-shit-done-redux
- @gsd-redux/sdk → @opengsd/gsd-sdk

Add publishConfig.access=public for first-time scoped publish.
CLI binary names (get-shit-done-redux, gsd-sdk, gsd-tools) unchanged.

Sweeps install commands, npx invocations, CI publish/version-check
workflows, tests, docs, READMEs (all translations), and the
PACKAGE_NAME constant in check-latest-version.

Bumps qs 6.15.1 → 6.15.2 to clear a moderate advisory surfaced by
the audit-clean test (GHSA-q8mj-m7cp-5q26).

Closes #126

* chore: pin 2.0.0 release + remove canary workflow

- Bump both packages 1.50.0-canary.0 → 2.0.0 for first @opengsd publish
- Remove .github/workflows/canary.yml and canary dist-tag handling in
  release.yml / release-sdk.yml
- Drop canary section from VERSIONING.md

Refs #126

* chore: address review findings + harden tarball-smoke timeout

- .changeset/opengsd-org-rename.md: match project's custom
  parse.cjs frontmatter (type: Changed / pr: 127); the scoped
  @changesets/cli keys were silently rejected.
- CONTEXT.md: drop two canary-stream policy lines and a dangling
  DEFECT.CANARY-VERSION-LEAK.cross-ref now that canary.yml is gone.
- tests/release-tarball-smoke.install.test.cjs: pass
  timeout: 600_000 for npm pack + global install; the 3-minute
  runNpm default was timing out on slower Docker hosts (cartographer).

Refs #126

* fix(sdk): add missing type/runtime devDependencies for build

prepublishOnly invokes tsc which couldn't resolve @types/node,
@types/ws, or synckit. They had been hoisted from root but were
not declared in sdk/'s own package.json — first publish from a
clean SDK tree failed.

Refs #126

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix(ci): use npm pack stdout instead of glob to find tarball

`npm pack --silent` for a scoped package (@opengsd/get-shit-done-redux)
produces `opengsd-get-shit-done-redux-*.tgz`, not `get-shit-done-redux-*.tgz`.
Capture the filename from stdout instead of a hardcoded glob so the step
works regardless of package name format.

Fixes smoke (ubuntu-latest, 22, false) CI failure.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* ci: treat workflow-file changes as test-skip eligible

`.github/workflows/install-smoke.yml` (and other workflow files)
were in neither `test.yml` paths nor `test-skip.yml` paths-ignore,
so neither workflow ran on a workflow-only commit — leaving the
required test-skip check perpetually missing.

Refs #126

* chore: reset version to 1.0.0 for first @opengsd publish

Nothing has been published yet under the @opengsd scope, so the
inaugural release uses 1.0.0 rather than 2.0.0. The "major bump"
in the changeset reflects the breaking install-command change for
users migrating from the prior unscoped `get-shit-done-redux`, not
a numeric continuation from a 1.x line under the new identity.

Refs #126

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-22 16:22:41 -04:00

188 lines
7.5 KiB
JavaScript

// allow-test-rule: source-text-is-the-product — agents/gsd-intel-updater.md IS
// the deployed agent instruction set. Asserting its text content tests the
// deployed behaviour contract, not internal implementation.
'use strict';
/**
* Regression tests for bug #3290.
*
* The "Runtime layout detection" block in gsd-intel-updater.md ran
* unconditionally on every project analysed, emitting:
*
* Layout detection returned "unknown" — this project is not a GSD-system
* installation (no `.claude/get-shit-done/` or `.kilo/` runtime root).
*
* for every ordinary (non-GSD-framework) user project. The verdict was already
* ignored by Steps 2-6 on non-GSD projects. The block was dead-but-noisy.
*
* Fix: gate the runtime bash detection on a positive "is-this-the-framework-
* repo" check (package.json name === "@opengsd/get-shit-done-redux") so it runs ONLY when
* analysing the GSD framework's own repo, OR remove the block entirely if no
* downstream consumers exist.
*
* Group A — gating contract:
* The unconditional bash detection invocation must be absent OR wrapped in a
* framework-repo guard. A bare `ls -d .kilo ... || echo "unknown"` with no
* surrounding gate is the defect signature.
*
* Group B — no orphan consumers:
* Confirm no other agent, command, or workflow file reads/consumes the layout-
* detection verdict emitted by this block.
*/
const { describe, test } = require('node:test');
const assert = require('node:assert/strict');
const fs = require('node:fs');
const path = require('node:path');
const ROOT = path.join(__dirname, '..');
const AGENT_PATH = path.join(ROOT, 'agents', 'gsd-intel-updater.md');
// ─── helpers ─────────────────────────────────────────────────────────────────
/** Walk a directory recursively and return absolute paths of all .md files. */
function walkMd(dir) {
const results = [];
if (!fs.existsSync(dir)) return results;
for (const entry of fs.readdirSync(dir, { withFileTypes: true })) {
const abs = path.join(dir, entry.name);
if (entry.isDirectory()) {
results.push(...walkMd(abs));
} else if (entry.isFile() && entry.name.endsWith('.md')) {
results.push(abs);
}
}
return results;
}
// ─── Group A — gating contract ───────────────────────────────────────────────
describe('bug #3290 — Group A: layout-detection block must be gated or absent', () => {
let content;
test('agent file exists', () => {
assert.ok(fs.existsSync(AGENT_PATH), 'agents/gsd-intel-updater.md must exist');
content = fs.readFileSync(AGENT_PATH, 'utf-8');
});
test(
'bare unconditional detection invocation is absent — ' +
'the "ls -d .kilo ... || echo unknown" must not appear outside a framework-repo gate',
() => {
content = content || fs.readFileSync(AGENT_PATH, 'utf-8');
// The defect signature: the bash block runs unconditionally.
// We look for the exact shell one-liner that emits the verdict.
const bareDetectionPattern =
/ls -d \.kilo\b.*\|\|.*echo "?unknown"?/;
const hasBareDetection = bareDetectionPattern.test(content);
if (!hasBareDetection) {
// Block is fully removed — option B — pass.
return;
}
// Block is still present. Verify it is surrounded by a framework-repo gate.
// A valid gate checks package.json name or an equivalent positive signal
// that the current project IS the GSD framework's own repo.
const hasFrameworkGate =
content.includes('@opengsd/get-shit-done-redux') ||
content.includes('is-this-the-framework') ||
content.includes('framework repo') ||
content.includes('Only run') ||
/if.*package\.json.*get-shit-done/i.test(content) ||
/Only.*layout detection.*GSD framework/i.test(content) ||
/Only.*layout detection.*framework/i.test(content);
assert.ok(
hasFrameworkGate,
'agents/gsd-intel-updater.md contains a bare unconditional layout-detection ' +
'bash block (`ls -d .kilo ... || echo unknown`) with no surrounding ' +
'framework-repo gate (#3290). ' +
'Either remove the block entirely, or wrap it in a check like:\n' +
' if [[ "$(jq -r \'.name // ""\' package.json 2>/dev/null)" == "@opengsd/get-shit-done-redux" ]]; then\n' +
' # ... detection block ...\n' +
' fi'
);
}
);
});
// ─── Group B — no orphan downstream consumers ────────────────────────────────
describe('bug #3290 — Group B: layout-detection verdict has no downstream consumers', () => {
const SOURCE_DIRS = [
path.join(ROOT, 'agents'),
path.join(ROOT, 'commands', 'gsd'),
path.join(ROOT, 'get-shit-done', 'workflows'),
];
/**
* Lines that reference the three possible verdict values emitted by the
* detection block: "claude", "kilo", "unknown" — ONLY as the verdict output
* of the gsd-intel-updater layout detection (not general runtime references).
*
* We look for the specific phrase "Layout detection returned" which is the
* sentinel the noisy output line uses.
*/
test('no file contains "Layout detection returned" (the noisy verdict phrase)', () => {
const matches = [];
for (const dir of SOURCE_DIRS) {
const files = walkMd(dir);
for (const file of files) {
const rel = path.relative(ROOT, file);
const src = fs.readFileSync(file, 'utf-8');
if (src.includes('Layout detection returned')) {
// Collect matching lines for the error message
const lines = src.split('\n')
.map((l, i) => ({ line: l, n: i + 1 }))
.filter(({ line }) => line.includes('Layout detection returned'));
matches.push({ rel, lines });
}
}
}
assert.strictEqual(
matches.length,
0,
'Expected zero files to contain "Layout detection returned" (the noisy verdict ' +
'phrase from the gsd-intel-updater layout-detection block). Found:\n' +
matches.map(({ rel, lines }) =>
` ${rel}:\n${lines.map(({ n, line }) => ` L${n}: ${line.trim()}`).join('\n')}`
).join('\n')
);
});
test('no agent or workflow instructs reading the layout-detection verdict output', () => {
// The verdict was: echo "kilo" | echo "claude" | echo "unknown"
// If any file references "Layout detection returned unknown" as an instruction
// to consume, that would be a consumer. We verify none exist outside of
// the producing file (gsd-intel-updater.md).
const verdictConsumerPattern = /Layout detection returned.*(unknown|claude|kilo)/i;
const consumers = [];
for (const dir of SOURCE_DIRS) {
const files = walkMd(dir);
for (const file of files) {
// Exclude the producer itself — it defines the message, not consumes it
if (path.basename(file) === 'gsd-intel-updater.md') continue;
const src = fs.readFileSync(file, 'utf-8');
if (verdictConsumerPattern.test(src)) {
consumers.push(path.relative(ROOT, file));
}
}
}
assert.deepStrictEqual(
consumers,
[],
'Expected no downstream consumer of the layout-detection verdict. Found:\n' +
consumers.map((f) => ` ${f}`).join('\n') +
'\nIf a consumer exists, use option A (gate) not option B (remove).'
);
});
});