Files
msd-core/tests/check-gap-analysis-plan-post-e2e.test.cjs
Tom Boucher b10e56818b feat(#1169): complete ADR-857 phase 6 — migrate features to Capabilities, revive dead gates, harden conformance gate (#1183)
* test(#1168): make phase-6 gate un-gameable — reject empty stubs + require loop shrink

The migration assertion previously checked only role==feature, so a registration-only stub (empty hooks, logic left inline) would turn the gate green while phase 6 stayed incomplete — the exact false-completion pattern this gate exists to prevent. Strengthen it: each ADR-named feature must OWN its behavior (>=1 hook, or a command family); and plan-phase.md/execute-phase.md must shrink strictly below their frozen pre-phase-6 sizes (94519/93166 LF bytes), which also defeats double-run gaming (declare a hook but keep the inline block -> file does not shrink -> red).

Gate now 5 pass / 4 fail (orphaned execute:wave:post, empty/unregistered features, config-key leaks, no shrink). Green is now reachable only by REAL migration. Refs #1168, #1169.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* feat(#1169): migrate gap-analysis to a Capability (plan:post gate)

First real ADR-857 phase-6 migration (pattern-defining tracer). gap-analysis moves from an inline post_planning_gaps branch in plan-phase.md to a real plan:post gate Capability:

- capabilities/gap-analysis/capability.json: role:feature, plan:post gate (when=workflow.post_planning_gaps, blocking:false advisory), OWNS workflow.post_planning_gaps (federated out of central schema). - plan-phase.md: inline config-get + gsd_run gap-analysis block replaced with a plan:post render-hooks call site dispatching the gate; file shrinks 94519->93279. - src/check-command-router.cts: cmdGapAnalysisPlanPost runs the real gap analysis via gap-checker. - post_planning_gaps removed from central manifest; resolves via federated config (default true preserved). - tests/post-planning-gaps-2493: re-pointed to assert capability ownership.

Verified: gate 5 pass / 4 fail (gap-analysis cleared from migration, plan:post-orphan, config-leak, and plan-phase shrink checks); loadConfig still returns post_planning_gaps=true; check command runs real analysis; 392/392 in the config/registry/federation/router net. Refs #1169.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* feat(#1169): migrate profile-pipeline to a command-family Capability

ADR-857 Decision 7: profile-pipeline becomes a command-family Capability (like audit/intel/graphify). capabilities/profile-pipeline/capability.json declares an 8-command family (scan-sessions, extract-messages, profile-sample, write-profile, profile-questionnaire, generate-dev-preferences, generate-claude-profile, generate-claude-md) backed by a new gsd-core/bin/lib/profile-pipeline-command-router.cjs; the inline case arms are removed from gsd-tools.cjs. Owns profile-pipeline.enabled (federated).

Verified: registry shows role:feature with commands.length=8; scan-sessions/profile-sample run live via the family; gate cleared profile-pipeline from the empty-stub failure (only tdd/schema-gate/drift remain); 296/296 registry+inventory+gsd-tools tests; lint 0 errors. Refs #1169.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* fix(#1167): wire execute:wave:post + implement ui.safety-gate check

Revives the second dead gate from #1167: ui.gates@execute:wave:post was declared but never dispatched AND its check.query (ui.safety-gate) was unimplemented. Adds the per-wave execute:wave:post render-hooks call site in execute-phase.md (fires after each wave's merge/cleanup, before the next forks) and implements cmdUiSafetyGate (frontend + UI-SPEC aware, mirrors cmdUiPlanGate) in check-command-router. +17 regression tests.

Verified: phase-6 orphaned-points conformance test now PASSES (gate 6 pass / 3 fail); ui-safety-gate routable in dot+hyphen forms; check-ui-safety-gate 17/17, check-ui-plan-gate 18/18; lint 0 errors. Refs #1167, #1168.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* feat(#1169): migrate drift (schema + codebase) to execute:wave:post gates

Removes the inline schema_drift_gate + codebase_drift_gate steps (77 lines) from execute-phase.md; drift becomes a Capability with two execute:wave:post gates (verify.schema-drift blocking, verify.codebase-drift advisory) dispatched via the per-wave render-hooks call site. check-command-router routes verify.schema-drift / verify.codebase-drift to the real detectors. Federates workflow.drift_threshold / drift_action / schema_drift_gate out of central.

Also fixes the execute:wave:post dispatch prose to run NON-blocking (advisory) gates too — the prior version only ran blocking gates, which would have silently dropped the codebase-drift advisory after its inline step was removed. Behavior preserved.

Verified: gate 7 pass / 2 fail (drift cleared from stub + config-leak; execute-phase.md 92297 < 93166 frozen -> shrink passes); both drift checks run real detection; loadConfig defaults preserved (threshold=3, action=warn, gate=true); drift-detection 56/56 + schema-drift 34/34; lint 0 errors. Refs #1169.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* feat(#1169): migrate tdd to a Capability (plan:pre contribution + execute:post gate)

tdd becomes a real Capability: a plan:pre contribution injects the <tdd_mode_active> planner guidance (rendered from PLAN_PRE_HOOKS_JSON like security's contribution), and an execute:post gate (tdd.review-checkpoint, advisory) runs the real end-of-phase RED/GREEN review via a new check-command handler. Inline tdd_mode reads + the inline planner block + the tdd_review_checkpoint step are removed; workflow.tdd_mode is federated out of central. The MVP+TDD per-task RED-commit gate is preserved — TDD_MODE is now derived from the execute:post hooks (capId==tdd active), not an inline config-get.

BEHAVIOR CHANGE (documented, not silent): the --tdd CLI flag now persists workflow.tdd_mode=true via config-set instead of being per-invocation. Rationale: tdd is now a config-toggled Capability, and env vars do not persist across the workflow's separate bash blocks (config does), so an ephemeral override isn't cleanly achievable; --tdd therefore enables the tdd capability, consistent with how all capabilities are toggled.

Verified: gate 7 pass / 2 fail (tdd cleared from stub + config-leak; plan-phase + execute-phase both < frozen sizes); contribution injection + execute:post gate dispatch wired; MVP+TDD gate preserved; tdd.review-checkpoint runs real review; full unit suite 556/0; lint 0 errors. Refs #1169.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* feat(#1169): migrate schema-gate to a plan:pre contribution Capability

The plan-time schema-push detection (former plan-phase.md §5.7) becomes a schema-gate Capability: a plan:pre contribution (into:planner, when:workflow.schema_push_detection) whose fragment carries the full ORM-detection + [BLOCKING] schema-push-task injection logic, rendered into the planner via the existing plan:pre render-hooks dispatch. The inline §5.7 block is removed (plan-phase.md 94519->90445). workflow.schema_push_detection is a new capability-owned (federated) key, default true. (The execute-side schema-drift gate was migrated separately into the drift capability.)

Verified: registry inlines the fragment (len 2704) so it is actually delivered at plan:pre; gate 8 pass / 1 fail — all 5 ADR-named features now real Capabilities, only the config-leak test remains (intel/security, next unit). Refs #1169.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* feat(#1169): close the 3 capability config-key leaks — phase-6 gate now GREEN

Removes the last inline config-get reads of capability-owned keys from plan-phase.md. security_asvs_level/security_block_on now flow through the security plan:pre contribution via a new loop-resolver configValues mechanism (resolves declared config keys with the same 4-level precedence as activation and attaches them to the rendered hook); the §5.55 banner reads them from PLAN_PRE_HOOKS_JSON. intel.enabled becomes a real intel plan:pre step (ref.command: intel api-surface) dispatched via render-hooks; the inline intel branch is gone. gen-capability-registry now validates ref.command as a third dispatch shape.

Verified: phase-6 capstone conformance gate is FULLY GREEN (9/0); 3 leaks gone (grep=0); security configValues resolve to {2,medium}/default {1,high}; intel step present only when enabled; loop-render-hooks 62/0, capability-registry 287/0, capability-state/federated-config 113/0; lint 0 errors. Closes the migration half of #1169. Refs #1139, #1167, #1168.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* fix(#1169): address adversarial review — restore schema-drift block, generic planner injection, uniform gate contract

Adversarial review caught 2 real regressions the green gate missed: (1) schema-drift no longer blocked — the execute:wave:post dispatch read GATE_RESULT.block but verify.schema-drift emitted drift_detected/blocking, and onError:skip wrongly bypassed positive blocks; (2) only tdd's plan:pre contribution was injected into the planner, dropping schema-gate's schema-push detection and security's threat-model guidance.

Fixes: (A) every gate check returns a uniform boolean 'block' under --raw (the dispatch form), with advisory gates (tdd/gap) carrying their report in 'message'; (B) gate-dispatch contract corrected at all sites — onError governs command errors only, a blocking gate's positive block always halts; (C) generic planner injection of all plan:pre contributions where into=='planner' (tdd + schema-gate + security incl configValues); (D) two new conformance assertions: planner contributions injected generically + every gate check.query returns boolean block under --raw.

Verified: gate 11/11; all 6 gate checks return boolean block under --raw; full suite 595/0; lint 0 errors. Refs #1167, #1168, #1169.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* fix(#1169): restore MVP+TDD end-of-phase blocking escalation (2nd adversarial pass)

The migrated tdd execute:post gate is statically blocking:false, but the contract (references/execute-mvp-tdd.md + CONTEXT.md) requires the end-of-phase TDD review to ESCALATE from advisory to blocking when MVP_MODE && TDD_MODE && a TDD plan misses a RED/GREEN commit. The migration prose had downgraded this to a 'strong advisory recommendation' — silent loss of the blocking escalation. Restore it: the tdd-gate dispatch now refuses to mark the phase complete (Phase blocked message) under MVP+TDD when GATE_RESULT.block is true; advisory otherwise.

Also strengthen tests/execute-mvp-tdd-gate.test.cjs: hasBlockingEscalation previously matched any line with 'blocking'+'mvp+tdd' (so 'advisory (blocking: false) ... under MVP+TDD' was a false green); now it requires the real refusal semantics ('refuse to mark the phase complete' / 'phase blocked'). Caught by 2nd adversarial review pass.

Verified: execute-phase.md 92702 < 93166 frozen; mvp-tdd-gate + phase-6 gate 19/0; full suite green; lint 0 errors. Refs #1169.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* fix(#1169): restore MVP+TDD proceed-block, codebase auto-remap, schema skip-flag (3rd adversarial pass)

3rd adversarial pass found 4 more silent regressions: (1) the tdd MVP+TDD 'refuse to mark complete' was nullified by a downstream 'ALWAYS proceed regardless of gate results' line — proceed is now conditional (stops on an active MVP+TDD block); (2) the test now asserts the proceed is NOT an unconditional override; (3) codebase-drift auto-remap (spawn gsd-codebase-mapper when drift_action=auto-remap) was dropped — the execute:wave:post advisory dispatch now consumes spawn_mapper/directive; (4) GSD_SKIP_SCHEMA_CHECK bypass was lost from the gate path — cmdVerifySchemaDrift now honors the env var (block:false when set).

Verified: no unconditional proceed; GSD_SKIP_SCHEMA_CHECK=true -> block:false; gate 11/11 + mvp-tdd 9/9; full suite 569/0; lint 0; execute-phase.md 93109 < 93166. Refs #1169.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* fix(#1169): init.cts reads federated config keys from nested path (4th adversarial pass)

Config federation moved tdd_mode/research/nyquist_validation from flat config.<key> to nested config.workflow.<key>, but src/init.cts still read them flat — so init.plan-phase/init.execute-phase emitted tdd_mode:false / research_enabled:undefined / nyquist:undefined regardless of config (a public command-contract regression; the migrated loops use render-hooks so enforcement was unaffected). Read via config.workflow (type-safe Record cast). Now init reflects the same resolved values + federated defaults (research/nyquist default true) as the render-hooks path.

Verified: build clean; init.plan-phase emits tdd_mode:true/research:false/nyquist:false for set config, defaults true for empty; full suite 591/0; lint 0. Refs #1169.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* docs(#1169): add changeset for ADR-857 phase-6 completion (PR #1183)

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* fix(#1169): complete phase-6 migration fallout — restore TEXT_MODE, fix registry .claude leak, re-point stale workflow-contract tests

The capability migration left real regressions and stale consumer tests that
the per-module unit suite missed but the full cross-platform suite caught (27
failing tests):

Real source regressions (fixed):
- execute-phase.md lost its AskUserQuestion TEXT_MODE plain-text fallback when
  the inline schema_drift_gate step was removed — non-Claude runtimes would
  stall. Restored, and the execute:post gate-dispatch prose de-duplicated to
  cite the execute:wave:post contract (loop body shrinks below the frozen
  pre-phase-6 ceiling while keeping every onError/blocking nuance).
- capabilities/tdd inline fragment hardcoded `@~/.claude/gsd-core/references/tdd.md`,
  baked verbatim into the committed capability-registry.cjs and leaked the
  install path on 11 non-Claude runtimes (registry .cjs is copied, not
  path-converted). Made the fragment path-free; regenerated the registry. The
  phase-6 conformance gate now guards this (no ~/.claude install path in any
  capability source or the generated registry).
- plan-phase.md: removed a §5.7 stub re-added in error and routed Branch 2 to
  step 6 (schema-gate is a plan:pre capability, §5.7 is gone).

Stale workflow-contract tests re-pointed to the capability dispatch they now
must assert (behavior verified preserved in source first, assertions kept
equal-or-stronger): bug-621 + bug-2851 (gap-analysis via gsd_run render-hooks
plan:post + registry binding), feat-2527 (tdd_mode federated out of central),
phase6-planning + plan-phase-ui-redirect (§5.6 bounded by ## 6.),
plan-phase-drift-guard (intel when:intel.enabled skip branch).

profile-pipeline-command-router.cjs un-ignored from eslint (hand-written, no
TS source) + stale disable comments removed. Size baseline regenerated.

Verified: full suite 15140 tests / 0 fail; lint 0 errors; conformance gate green
legitimately. Refs #1139, #1167, #1168, #1169.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* test(#1169): add ADR-857 E2E content-test coverage for the 12 loop points + capability deliverables

Grounds the capability engine in behavioral E2E tests (drive the real
render-hooks/check CLI + the real registry, assert typed result content — no
source-grep), structured around what ADR-857 says to deliver. 207 tests; each
genuineness-checked (flip the expectation, confirm it fails).

Per-loop-point dispatch (7 files): empty-point negative-space across the 6
no-hook points; verify:post 3-step resolution+ordering+onError; plan:pre
contribution/configValues + ui.plan-gate + intel; plan:post gap-analysis;
execute:wave:post drift+ui gates via the check route (schema-drift block/skip,
codebase-drift threshold BVA, auto-remap); execute:post tdd.review-checkpoint
RED/GREEN; ship:pre security gate resolution + frontmatter-get predicate pieces.

ADR-deliverable coverage (4 files): predicate boundary held (edge/prohibition
probes stay core, not off-by-default Feature Capabilities — phase-6 exception);
core loop runs with zero capabilities (all 12 points empty, init bundles
resolve); contribution merge (multiple ordered <contribution from=> blocks);
federated-config key removal on uninstall.

federated-config allowlisted for its 3-file split (unit + integration +
lifecycle). Refs #1139, #1167, #1168, #1169.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* fix(#1169): remove dead drifted converter dups + address adversarial review

Lint cleanup (root-caused, not waved off): src/runtime-artifact-conversion.cts
carried 11 agent-converter functions (+5 orphaned consts/helpers) that were
never exported, never called, and had silently DRIFTED from the live
hand-authored copies in bin/install.js (one even referenced an undefined
`claudeToCopilotTools`). Deleted the dead duplicates; install.js's live copies
are untouched (it never imported these). Lint now 0 errors / 0 warnings.

Adversarial-review (Codex) findings fixed:
- HIGH: execute-phase.md TDD_MODE used `jq ... || echo false`, silently
  disabling the MVP+TDD blocking gate on jq-less runtimes. Reverted to the
  `node -e` form (node is guaranteed; matches the file's other node-e usages) so
  a missing optional tool can no longer fail-open a blocking safety path.
- MEDIUM: federated-config-key-removal orphan-key test was vacuous (it skipped
  the orphan assertion). Now asserts the removed capability's key is genuinely
  not surfaced/validated after uninstall.
- LOW: phase-6 conformance leak regex broadened to catch absolute-home and
  Windows-backslash `.claude/(gsd-core|commands|agents|hooks)` paths, not only
  `~`/`$HOME` forward-slash forms.
- LOW: bug-2851 plan:post dispatch assertion now requires `--raw` (matched its
  stated contract).
- nit: plan-pre intel-step test duplicate assertion replaced with a distinct
  structured-output check.

Size baseline regenerated (execute-phase.md 93089 < 93166 frozen). Refs #1167, #1169.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* test(#1169): make runtime-homes-descriptor-drive titles environment-independent

The descriptor-equivalence test embedded the absolute golden config path
(`os.homedir()`-derived) directly in each `test(...)` title, so titles differed
between macOS (`/Users/x/.claude`) and Docker (`/home/gsdtest/.claude`). Every
test PASSES on both platforms (15885/0 leaf tests each), but gsd-test-summary
compares results by title and reported 29+29 false "only in Mac / only in
Docker" discrepancies for tests that actually pass everywhere.

Move the golden path out of the title and into the assertion message (still
shown on failure); titles are now byte-identical across platforms so the
cross-platform comparator matches them. No assertion logic or golden values
changed. Refs #1169.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* fix(#1169): derive TDD_MODE via gsd_run --active-cap, not node -e (fix prompt-injection CI gate)

The prior fix reverted execute-phase.md:181 from jq to `node -e` to close a
Codex HIGH (jq||echo-false silently disabling the MVP+TDD blocking gate on
jq-less runtimes) — but the CI prompt-injection scanner BLOCKS new `node -e` in
workflow markdown (inline code-exec = injection vector), turning the security
gate red. Both forms were wrong: node -e fails the scanner; jq fail-opens a
blocking safety gate; `config-get workflow.tdd_mode` is forbidden by the
conformance leak gate (tdd_mode is capability-owned).

Correct fix (what Codex recommended): a gsd_run-native boolean. Add an
`--active-cap <capId>` flag to `loop render-hooks <point>` that resolves hooks
the normal way and prints exactly `true`/`false` for whether a capId is active
— scanner-safe (canonical launcher, no inline code), node-reliable (no optional
jq to fail-open), and leak-free (render-hooks resolution, not config-get).
execute-phase.md:181 now `TDD_MODE=$(gsd_run loop render-hooks execute:post
--active-cap tdd)`. +5 behavioral tests for the flag.

Verified: prompt-injection-scan --diff origin/next → 0 findings; conformance
gate 13/13 (execute-phase.md 92934 < 93166); execute-mvp-tdd + tdd-mode +
loop-render-hooks 87/0; lint 0/0. Refs #1167, #1169.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-13 21:07:55 -04:00

508 lines
24 KiB
JavaScript

'use strict';
/**
* E2E content tests for plan:post hook — gap-analysis gate.
*
* ADR-857 phase 6 backlog: check-gap-analysis-plan-post-e2e.test.cjs
*
* Tests exercise:
* - loop render-hooks plan:post (gate discovery)
* - check gap-analysis.plan-post (advisory gate check)
*
* HARD RULES enforced here:
* - Every test runs a real CLI subprocess or the real resolver + real registry.
* - No readFileSync + .includes() source-grep on workflow files.
* - Asserts TYPED CONTENT (JSON fields, counts, booleans, strings).
* - Each test fully isolated (own fixture), cleanup in afterEach.
*/
const { describe, test, beforeEach, afterEach } = require('node:test');
const assert = require('node:assert/strict');
const fs = require('fs');
const path = require('path');
const { spawnSync } = require('child_process');
const { runGsdTools, createTempProject, cleanup } = require('./helpers.cjs');
const GSD_TOOLS = path.join(__dirname, '..', 'gsd-core', 'bin', 'gsd-tools.cjs');
// ─── Shared helpers ───────────────────────────────────────────────────────────
/**
* Write REQUIREMENTS.md with REQ-IDs in checkbox format.
* @param {string} planningDir
* @param {string[]} ids
*/
function writeRequirements(planningDir, ids) {
const lines = ids.map((id, i) => `- [ ] **${id}** Requirement ${i + 1} description`);
fs.writeFileSync(
path.join(planningDir, 'REQUIREMENTS.md'),
`# Requirements\n\n${lines.join('\n')}\n`
);
}
/**
* Write CONTEXT.md with a <decisions> block containing decisions.
* @param {string} phaseDir
* @param {{id: string, text: string}[]} decisions
*/
function writeContext(phaseDir, decisions) {
const dLines = decisions.map(d => `- **${d.id}:** ${d.text}`).join('\n');
fs.writeFileSync(
path.join(phaseDir, 'CONTEXT.md'),
`# Phase Context\n\n<decisions>\n## Implementation Decisions\n\n${dLines}\n</decisions>\n`
);
}
/**
* Write a PLAN.md with the given body.
* @param {string} phaseDir
* @param {string} name e.g. '01'
* @param {string} body
*/
function writePlan(phaseDir, name, body) {
fs.writeFileSync(path.join(phaseDir, `${name}-PLAN.md`), body);
}
/**
* Run loop render-hooks via spawnSync for low-level exit-code control.
* @param {string} point
* @param {string} cwd
* @returns {{ status: number, stdout: string, stderr: string }}
*/
function spawnRenderHooks(point, cwd) {
const result = spawnSync(process.execPath, [GSD_TOOLS, 'loop', 'render-hooks', point, '--raw'], {
cwd,
encoding: 'utf8',
timeout: 60000,
env: { ...process.env, GSD_SESSION_KEY: '', CODEX_THREAD_ID: '', CLAUDE_SESSION_ID: '' },
});
return {
status: result.status,
stdout: (result.stdout || '').trim(),
stderr: (result.stderr || '').trim(),
};
}
/**
* Run check gap-analysis.plan-post via CLI with controlled args.
* @param {string[]} extraArgs args after 'gap-analysis.plan-post'
* @param {string} cwd
* @returns {{ success: boolean, output: string, error: string, exitCode: number }}
*/
function runGapCheck(extraArgs, cwd) {
return runGsdTools(['check', 'gap-analysis.plan-post', ...extraArgs, '--raw'], cwd);
}
// ─── Section 1: render-hooks plan:post ───────────────────────────────────────
describe('render-hooks plan:post — gate discovery', () => {
let tmpDir;
let phaseDir;
beforeEach(() => {
tmpDir = createTempProject();
phaseDir = path.join(tmpDir, '.planning', 'phases', '01-test');
fs.mkdirSync(phaseDir, { recursive: true });
// Initialize a valid config so schema defaults apply
const init = runGsdTools('config-ensure-section', tmpDir);
assert.ok(init.success, `config-ensure-section failed: ${init.error}`);
});
afterEach(() => cleanup(tmpDir));
test('[happy] render-hooks plan:post returns gap-analysis gate hook with correct typed shape when workflow.post_planning_gaps=true (default)', () => {
// Default config → post_planning_gaps=true (schema default)
const r = spawnRenderHooks('plan:post', tmpDir);
assert.strictEqual(r.status, 0, `exit non-zero: ${r.stderr}`);
const envelope = JSON.parse(r.stdout);
assert.strictEqual(envelope.point, 'plan:post');
assert.ok(Array.isArray(envelope.activeHooks), 'activeHooks must be array');
assert.strictEqual(envelope.activeHooks.length, 1, 'exactly one active hook expected');
const hook = envelope.activeHooks[0];
assert.strictEqual(hook.capId, 'gap-analysis', 'capId must be gap-analysis');
assert.strictEqual(hook.kind, 'gate', 'kind must be gate');
assert.strictEqual(hook.blocking, false, 'blocking must be false (advisory)');
assert.strictEqual(hook.onError, 'skip', 'onError must be skip');
assert.strictEqual(hook.when, 'workflow.post_planning_gaps', 'when must be workflow.post_planning_gaps');
assert.deepStrictEqual(hook.check, { query: 'gap-analysis.plan-post' }, 'check.query must be gap-analysis.plan-post');
// rendered must mention the gate
assert.ok(typeof envelope.rendered === 'string', 'rendered must be string');
assert.ok(envelope.rendered.includes('gap-analysis'), 'rendered must mention gap-analysis');
assert.ok(envelope.rendered.includes('gap-analysis.plan-post'), 'rendered must include check query');
});
test('[negative] render-hooks plan:post returns empty activeHooks when workflow.post_planning_gaps=false (gate deactivated)', () => {
fs.writeFileSync(
path.join(tmpDir, '.planning', 'config.json'),
JSON.stringify({ workflow: { post_planning_gaps: false } })
);
const r = spawnRenderHooks('plan:post', tmpDir);
assert.strictEqual(r.status, 0, `exit non-zero: ${r.stderr}`);
const envelope = JSON.parse(r.stdout);
assert.strictEqual(envelope.point, 'plan:post');
// GENUINE check: must be EMPTY, not length 1
assert.deepStrictEqual(envelope.activeHooks, [], 'activeHooks must be empty when gate disabled');
assert.strictEqual(envelope.rendered, '_No active hooks at plan:post._',
'rendered placeholder must match exactly when no hooks active');
});
test('[happy] render-hooks plan:post with explicit post_planning_gaps=true in config returns same hook as default', () => {
fs.writeFileSync(
path.join(tmpDir, '.planning', 'config.json'),
JSON.stringify({ workflow: { post_planning_gaps: true } })
);
const r = spawnRenderHooks('plan:post', tmpDir);
assert.strictEqual(r.status, 0, `exit non-zero: ${r.stderr}`);
const envelope = JSON.parse(r.stdout);
assert.strictEqual(envelope.activeHooks.length, 1, 'exactly one hook with explicit true');
assert.strictEqual(envelope.activeHooks[0].capId, 'gap-analysis');
assert.strictEqual(envelope.activeHooks[0].blocking, false);
});
test('[bva] render-hooks plan:post envelope has exactly 3 keys (point, activeHooks, rendered) — Hyrum\'s law shape pin', () => {
const r = spawnRenderHooks('plan:post', tmpDir);
assert.strictEqual(r.status, 0, `exit non-zero: ${r.stderr}`);
const envelope = JSON.parse(r.stdout);
const keys = Object.keys(envelope).sort();
assert.deepStrictEqual(keys, ['activeHooks', 'point', 'rendered'],
`envelope must have exactly 3 keys, got: ${keys.join(',')}`);
});
});
// ─── Section 2: check gap-analysis.plan-post — content tests ─────────────────
describe('check gap-analysis.plan-post — gate content E2E', () => {
let tmpDir;
let phaseDir;
beforeEach(() => {
tmpDir = createTempProject();
phaseDir = path.join(tmpDir, '.planning', 'phases', '01-test');
fs.mkdirSync(phaseDir, { recursive: true });
const init = runGsdTools('config-ensure-section', tmpDir);
assert.ok(init.success, `config-ensure-section failed: ${init.error}`);
});
afterEach(() => cleanup(tmpDir));
// ── Coverage table tests ────────────────────────────────────────────────────
test('[happy] check gap-analysis.plan-post returns block:false with coverage table when phaseDir has plans covering some REQ-IDs', () => {
writeRequirements(path.join(tmpDir, '.planning'), ['REQ-01', 'REQ-02']);
writePlan(phaseDir, '01', '# Plan 1\n\nImplements REQ-01 only.\n');
const r = runGapCheck([phaseDir, 'REQ-01,REQ-02'], tmpDir);
assert.ok(r.success, `check failed: ${r.error}`);
const out = JSON.parse(r.output);
// GENUINE typed field assertions
assert.strictEqual(out.block, false, 'block must be false (gap-analysis is always advisory)');
assert.strictEqual(out.passed, true);
assert.strictEqual(out.enabled, true);
assert.strictEqual(out.counts.total, 2, 'total must be 2');
assert.strictEqual(out.counts.covered, 1, 'covered must be 1 (REQ-01 only)');
assert.strictEqual(out.counts.uncovered, 1, 'uncovered must be 1 (REQ-02 not in plan)');
// Table content — assert specific coverage rows
assert.ok(out.table.includes('REQ-01'), 'table must include REQ-01');
assert.ok(out.table.includes('REQ-02'), 'table must include REQ-02');
assert.ok(out.table.includes('✓ Covered'), 'table must show covered row');
assert.ok(out.table.includes('✗ Not covered'), 'table must show not-covered row');
});
test('[happy] check gap-analysis.plan-post returns block:false with all-covered summary when all REQ-IDs and D-IDs are in plans', () => {
writeRequirements(path.join(tmpDir, '.planning'), ['REQ-01']);
writeContext(phaseDir, [{ id: 'D-01', text: 'Use pattern X for consistency' }]);
writePlan(phaseDir, '01', '# Plan 1\n\nImplements REQ-01 and D-01.\n');
const r = runGapCheck([phaseDir], tmpDir);
assert.ok(r.success, `check failed: ${r.error}`);
const out = JSON.parse(r.output);
assert.strictEqual(out.block, false);
assert.strictEqual(out.enabled, true);
assert.strictEqual(out.counts.total, 2, 'total must be 2 (1 req + 1 decision)');
assert.strictEqual(out.counts.covered, 2, 'both items must be covered');
// GENUINE: uncovered must be 0, not 1
assert.strictEqual(out.counts.uncovered, 0, 'uncovered must be 0 when all covered');
assert.ok(/all 2 items covered/i.test(out.summary), `summary must say "all 2 items covered", got: ${out.summary}`);
});
test('[empty-resolution] check gap-analysis.plan-post returns block:false with empty rows when no REQUIREMENTS.md and no CONTEXT.md exist', () => {
// No REQUIREMENTS.md, no CONTEXT.md — only a PLAN.md
writePlan(phaseDir, '01', '# Plan\n\nSome content.\n');
const r = runGapCheck([phaseDir], tmpDir);
assert.ok(r.success, `check failed: ${r.error}`);
const out = JSON.parse(r.output);
assert.strictEqual(out.block, false);
assert.strictEqual(out.enabled, true);
// GENUINE: total must be 0 (nothing to check)
assert.strictEqual(out.counts.total, 0, 'total must be 0 with no requirements/decisions');
assert.strictEqual(out.counts.uncovered, 0);
assert.ok(/no requirements or decisions/i.test(out.summary),
`summary must mention "no requirements or decisions", got: ${out.summary}`);
});
// ── Disabled gate tests ─────────────────────────────────────────────────────
test('[negative] check gap-analysis.plan-post returns enabled:false with block:false when workflow.post_planning_gaps=false', () => {
fs.writeFileSync(
path.join(tmpDir, '.planning', 'config.json'),
JSON.stringify({ workflow: { post_planning_gaps: false } })
);
writeRequirements(path.join(tmpDir, '.planning'), ['REQ-01']);
writePlan(phaseDir, '01', '# Plan\n\nImplements REQ-01.\n');
const r = runGapCheck([phaseDir], tmpDir);
assert.ok(r.success, `check failed: ${r.error}`);
const out = JSON.parse(r.output);
assert.strictEqual(out.block, false, 'block must be false when disabled');
assert.strictEqual(out.passed, true);
// GENUINE: enabled must be FALSE when gate is disabled
assert.strictEqual(out.enabled, false, 'enabled must be false when post_planning_gaps=false');
assert.strictEqual(out.table, '', 'table must be empty string when disabled');
assert.ok(/disabled/i.test(out.summary), `summary must mention disabled, got: ${out.summary}`);
assert.strictEqual(out.counts.total, 0);
});
// ── Missing arg tests ───────────────────────────────────────────────────────
test('[negative] check gap-analysis.plan-post exits non-zero with error string when phaseDir argument is omitted', () => {
// Pass only --raw, no phaseDir
const r = runGsdTools(['check', 'gap-analysis.plan-post', '--raw'], tmpDir);
// GENUINE: must fail, not succeed
assert.strictEqual(r.success, false, 'must fail when phaseDir omitted');
assert.strictEqual(r.exitCode, 1, 'exit code must be 1');
assert.ok(r.error.includes('requires a phase-dir argument'),
`stderr must say "requires a phase-dir argument", got: ${r.error}`);
// Output should NOT be valid JSON (it's an error message, not JSON)
let parsed;
try { parsed = JSON.parse(r.output); } catch (_) { parsed = null; }
assert.strictEqual(parsed, null, 'output must not be valid JSON when phase-dir is missing');
});
// ── BVA: phaseReqIds=TBD ────────────────────────────────────────────────────
test('[bva] check gap-analysis.plan-post with phaseReqIds=TBD returns zero requirement rows but still reports CONTEXT.md decisions', () => {
writeRequirements(path.join(tmpDir, '.planning'), ['OTHER-01', 'OTHER-02']);
writeContext(phaseDir, [{ id: 'D-01', text: 'Use canonical pattern for this module' }]);
writePlan(phaseDir, '01', '# Plan\n\nNo decisions addressed here.\n');
// TBD means: skip requirements, but still report CONTEXT.md decisions
const r = runGapCheck([phaseDir, 'TBD'], tmpDir);
assert.ok(r.success, `check failed: ${r.error}`);
const out = JSON.parse(r.output);
assert.strictEqual(out.enabled, true);
// GENUINE: only D-01 (from CONTEXT.md) — OTHER-01/OTHER-02 must be excluded
assert.strictEqual(out.counts.total, 1, 'total must be 1 (only D-01 from CONTEXT.md)');
// REQUIREMENTS.md rows must not appear
assert.ok(!out.table.includes('OTHER-01'), 'OTHER-01 must not appear in table when phaseReqIds=TBD');
assert.ok(!out.table.includes('OTHER-02'), 'OTHER-02 must not appear in table when phaseReqIds=TBD');
// D-01 must appear
assert.ok(out.table.includes('D-01'), 'D-01 from CONTEXT.md must still appear');
});
// ── BVA: mapped REQ-ID absent from REQUIREMENTS.md ─────────────────────────
test('[bva] check gap-analysis.plan-post with mapped REQ-ID absent from REQUIREMENTS.md emits Missing-from-REQUIREMENTS.md status in table', () => {
// REQUIREMENTS.md has only REQ-01, but phaseReqIds includes REQ-99 (absent)
writeRequirements(path.join(tmpDir, '.planning'), ['REQ-01']);
writePlan(phaseDir, '01', '# Plan\n\nImplements REQ-01.\n');
const r = runGapCheck([phaseDir, 'REQ-01,REQ-99'], tmpDir);
assert.ok(r.success, `check failed: ${r.error}`);
const out = JSON.parse(r.output);
assert.strictEqual(out.enabled, true);
// GENUINE: uncovered must be 1 (REQ-99 is "missing" which counts as uncovered)
assert.strictEqual(out.counts.uncovered, 1, 'uncovered must be 1 for missing REQ-99');
assert.strictEqual(out.counts.total, 2, 'total must be 2 (REQ-01 + REQ-99)');
assert.ok(out.table.includes('REQ-99'), 'table must include REQ-99');
// GENUINE: the status row for REQ-99 must say "Missing from REQUIREMENTS.md"
assert.ok(out.table.includes('Missing from REQUIREMENTS.md'),
`table must contain "Missing from REQUIREMENTS.md" for REQ-99, got table: ${out.table}`);
// REQ-01 must still be covered
assert.ok(out.table.includes('✓ Covered'), 'REQ-01 must show as covered');
});
});
// ─── Section 3: Full pipeline — render-hooks → check dispatch ─────────────────
describe('Full pipeline: render-hooks plan:post discovers gate, then check dispatched', () => {
let tmpDir;
let phaseDir;
beforeEach(() => {
tmpDir = createTempProject();
phaseDir = path.join(tmpDir, '.planning', 'phases', '01-test');
fs.mkdirSync(phaseDir, { recursive: true });
const init = runGsdTools('config-ensure-section', tmpDir);
assert.ok(init.success, `config-ensure-section failed: ${init.error}`);
});
afterEach(() => cleanup(tmpDir));
test('[happy] Full pipeline: render-hooks plan:post discovers gate hook, then check dispatched with hook.check.query returns advisory table — gate never blocking', () => {
writeRequirements(path.join(tmpDir, '.planning'), ['REQ-01', 'REQ-02']);
writePlan(phaseDir, '01', '# Plan 1\n\nImplements REQ-01 only.\n');
// Step 1: discover the gate hook via render-hooks
const hookResult = spawnRenderHooks('plan:post', tmpDir);
assert.strictEqual(hookResult.status, 0, `render-hooks exited non-zero: ${hookResult.stderr}`);
const envelope = JSON.parse(hookResult.stdout);
assert.strictEqual(envelope.activeHooks.length, 1, 'must discover exactly 1 gate hook');
const hook = envelope.activeHooks[0];
// GENUINE: gate must be advisory (blocking=false)
assert.strictEqual(hook.blocking, false, 'gap-analysis gate must be non-blocking');
assert.strictEqual(hook.check.query, 'gap-analysis.plan-post', 'check.query must be gap-analysis.plan-post');
// Step 2: dispatch the check using the discovered query
const checkResult = runGapCheck([phaseDir], tmpDir);
assert.ok(checkResult.success, `check failed: ${checkResult.error}`);
const out = JSON.parse(checkResult.output);
// GENUINE: the check result must also say block:false
assert.strictEqual(out.block, false, 'check must return block:false (advisory gate)');
assert.strictEqual(out.counts.uncovered, 1, 'one uncovered item: REQ-02');
assert.ok(out.table.length > 0, 'table must be non-empty');
assert.ok(out.table.includes('REQ-01'), 'table must show REQ-01');
assert.ok(out.table.includes('REQ-02'), 'table must show REQ-02');
});
test('[happy] Full pipeline: when post_planning_gaps=true and all items covered, check returns zero uncovered', () => {
writeRequirements(path.join(tmpDir, '.planning'), ['REQ-01']);
writePlan(phaseDir, '01', '# Plan\n\nImplements REQ-01.\n');
// Confirm hook exists via render-hooks
const hookResult = spawnRenderHooks('plan:post', tmpDir);
assert.strictEqual(hookResult.status, 0);
const envelope = JSON.parse(hookResult.stdout);
assert.strictEqual(envelope.activeHooks.length, 1);
// Run the check
const checkResult = runGapCheck([phaseDir], tmpDir);
assert.ok(checkResult.success, `check failed: ${checkResult.error}`);
const out = JSON.parse(checkResult.output);
assert.strictEqual(out.block, false);
assert.strictEqual(out.enabled, true);
assert.strictEqual(out.counts.total, 1);
assert.strictEqual(out.counts.covered, 1);
assert.strictEqual(out.counts.uncovered, 0);
});
test('[negative] Full pipeline: when post_planning_gaps=false, render-hooks returns empty and check returns enabled:false — dual contract agreement', () => {
fs.writeFileSync(
path.join(tmpDir, '.planning', 'config.json'),
JSON.stringify({ workflow: { post_planning_gaps: false } })
);
writeRequirements(path.join(tmpDir, '.planning'), ['REQ-01']);
writePlan(phaseDir, '01', '# Plan\n\nSome content.\n');
// Step 1: render-hooks must return empty (gate suppressed)
const hookResult = spawnRenderHooks('plan:post', tmpDir);
assert.strictEqual(hookResult.status, 0);
const envelope = JSON.parse(hookResult.stdout);
// GENUINE: both render-hooks and check must agree on suppression
assert.deepStrictEqual(envelope.activeHooks, [],
'render-hooks must return empty activeHooks when gate disabled');
assert.strictEqual(envelope.rendered, '_No active hooks at plan:post._');
// Step 2: check must return enabled:false, confirming dual-contract agreement
writePlan(phaseDir, '01', '# Plan\n\nSome content.\n');
const checkResult = runGapCheck([phaseDir], tmpDir);
assert.ok(checkResult.success, `check failed: ${checkResult.error}`);
const out = JSON.parse(checkResult.output);
// GENUINE: enabled must be false (both surfaces agree gate is suppressed)
assert.strictEqual(out.enabled, false,
'check must return enabled:false when render-hooks also shows empty — dual contract parity');
});
});
// ─── Section 4: Pure resolver tests against real registry ────────────────────
describe('resolveLoopHooks plan:post — pure function against real registry', () => {
const { resolveLoopHooks, renderLoopHooks } = require('../gsd-core/bin/lib/loop-resolver.cjs');
const realRegistry = require('../gsd-core/bin/lib/capability-registry.cjs');
test('[happy] resolveLoopHooks plan:post with post_planning_gaps=true returns one gap-analysis gate', () => {
const result = resolveLoopHooks({
point: 'plan:post',
registry: realRegistry,
config: { workflow: { post_planning_gaps: true } },
});
assert.strictEqual(result.point, 'plan:post');
assert.ok(Array.isArray(result.activeHooks));
assert.strictEqual(result.activeHooks.length, 1, 'must be exactly 1 hook with post_planning_gaps=true');
const hook = result.activeHooks[0];
assert.strictEqual(hook.capId, 'gap-analysis');
assert.strictEqual(hook.kind, 'gate');
assert.strictEqual(hook.blocking, false);
assert.strictEqual(hook.onError, 'skip');
});
test('[negative] resolveLoopHooks plan:post with post_planning_gaps=false returns empty activeHooks', () => {
const result = resolveLoopHooks({
point: 'plan:post',
registry: realRegistry,
config: { workflow: { post_planning_gaps: false } },
});
assert.strictEqual(result.point, 'plan:post');
// GENUINE: must be empty array (not length-1)
assert.deepStrictEqual(result.activeHooks, [],
'activeHooks must be empty when post_planning_gaps=false');
});
test('[happy] renderLoopHooks plan:post with empty activeHooks returns exact placeholder string', () => {
const result = resolveLoopHooks({
point: 'plan:post',
registry: realRegistry,
config: { workflow: { post_planning_gaps: false } },
});
const rendered = renderLoopHooks(result);
// GENUINE: must be exact placeholder, not a hook string
assert.strictEqual(rendered, '_No active hooks at plan:post._',
'rendered must be exact placeholder when no active hooks');
});
test('[bva] resolveLoopHooks plan:post with absent config uses schema default (post_planning_gaps=true)', () => {
// No workflow key in config → schema default should be true → hook active
const result = resolveLoopHooks({
point: 'plan:post',
registry: realRegistry,
config: {},
});
// GENUINE: schema default=true means the hook should activate even with empty config
assert.strictEqual(result.activeHooks.length, 1,
'schema default for post_planning_gaps is true — hook must activate with empty config');
assert.strictEqual(result.activeHooks[0].capId, 'gap-analysis');
});
test('[happy] real registry byLoopPoint plan:post has exactly one gate and no steps or contributions', () => {
const entry = realRegistry.byLoopPoint['plan:post'];
assert.ok(entry, 'plan:post must exist in byLoopPoint');
assert.ok(Array.isArray(entry.steps), 'steps must be an array');
assert.ok(Array.isArray(entry.contributions), 'contributions must be an array');
assert.ok(Array.isArray(entry.gates), 'gates must be an array');
assert.strictEqual(entry.steps.length, 0, 'plan:post must have zero steps');
assert.strictEqual(entry.contributions.length, 0, 'plan:post must have zero contributions');
assert.strictEqual(entry.gates.length, 1, 'plan:post must have exactly one gate');
assert.strictEqual(entry.gates[0].capId, 'gap-analysis');
});
});