Files
msd-core/tests/debugger-fix-acceptance.test.cjs
Tom Boucher 5e52350736 feat(#1958): add multi-signal fix-acceptance guardrail to gsd-debugger (#2396)
* test(#1958): add failing-first guardrail contract tests

Epic #1957 Phase 1A. Adds source-text-is-the-product tests asserting the
5-signal fix-acceptance guardrail contract (target test, mutation check,
no-op/deletion detector, adjacent tests, revert-and-reconfirm), graceful
degradation, FIX REJECTED BY GUARDRAIL return path, per-signal debug-file
recording, and subprocess bounding.

Failing-first: reference file and agent sections do not yet exist.

* feat(#1958): add multi-signal fix-acceptance guardrail to gsd-debugger

Epic #1957 Phase 1A. Prevents accepting a fix that merely greens the test
(Goodhart defense / APR overfitting). Adds a 5-signal gate run before fix
acceptance: target test, mutation check (Stryker), no-op/behavior-deleting
detector, adjacent/held-out tests, revert-and-reconfirm. Degrades gracefully
when Stryker or a test suite is absent (each skip logged, never a silent pass),
records per-signal results under Resolution.verification, and returns a
FIX REJECTED BY GUARDRAIL outcome the session-manager surfaces for
revise / accept-as-debt / abandon.

Full rules extracted to gsd-core/references/debugger-fix-acceptance.md (slim
routing kept in the agent to respect the agent-size cap). Debug template +
INVENTORY + manifest + agent-size baseline + AGENTS.md updated.

* test(#1958): correct newline-tolerant assertion + regen install-parity goldens

The revert-and-reconfirm assertion collapsed whitespace before matching so
markdown line-wrapping does not break it. Regenerated the golden-install-parity
and install-tree fixtures (npm run gen:golden) to absorb the intentional
gsd-debugger.md / gsd-debug-session-manager.md / DEBUG.md / new reference-file
changes to the installed artifact tree.

* fix(#1958): tighten guardrail per orthogonal review

Addresses the isolated reviewer's findings:
- signal 5 now states its recorded-repro dependency and routes the no-repro
  case to the degradation row; revert mechanism specified (git stash / git
  revert -n); minimality flag tied to diff structure, not revert-ability.
- bounded-subprocesses section now bounds the git subprocess (5-30s) too,
  requires argv-array argument passing, and scopes Stryker to the driving
  regression test (a mutant killed only by a non-driving test is a finding).
- new test-provenance (security) clause: the driving test must be
  agent-authored; bug-report repro scripts are DATA, never executed verbatim.
- tightened 3 contract assertions to bind to specific clauses
  (guardrail_verdict field, deletion-reject-unless-RCA, 60s+git bounding).
- Goodhart framing softened to 'partially-independent'; DEBUG.md template
  verification field notes the nested map shape.

* chore(#1958): backfill changeset pr number (PR #2396)

* fix(#1958): add issue ref to allow-test-rule annotation (ADR-456)

CI lint-allow-test-rule-refs requires every allow-test-rule exemption to
carry a 'see #NNN' issue ref per ADR-456. The new test file's annotation
lacked it; this adds (see #1958).
2026-07-18 00:39:28 -04:00

125 lines
6.0 KiB
JavaScript

// allow-test-rule: source-text-is-the-product (see #1958)
// Agent .md + reference .md + template .md files — their text IS what the
// runtime loads. Testing text content tests the deployed guardrail contract.
// Per CONTRIBUTING.md exception matrix. Covers epic #1957 Phase 1A (#1958).
'use strict';
const { describe, test } = require('node:test');
const assert = require('node:assert/strict');
const fs = require('node:fs');
const path = require('node:path');
const ROOT = process.cwd();
const AGENT = path.join(ROOT, 'agents/gsd-debugger.md');
const SESSION_MGR = path.join(ROOT, 'agents/gsd-debug-session-manager.md');
const REFERENCE = path.join(ROOT, 'gsd-core/references/debugger-fix-acceptance.md');
const DEBUG_TEMPLATE = path.join(ROOT, 'gsd-core/templates/DEBUG.md');
describe('fix-acceptance guardrail (#1958, epic #1957 Phase 1A)', () => {
describe('reference extract exists and is wired into the agent', () => {
test('gsd-core/references/debugger-fix-acceptance.md exists', () => {
assert.ok(fs.existsSync(REFERENCE), 'debugger-fix-acceptance.md reference must exist');
});
test('gsd-debugger.md @-includes the fix-acceptance reference', () => {
const content = fs.readFileSync(AGENT, 'utf8');
assert.ok(
content.includes('@~/.claude/gsd-core/references/debugger-fix-acceptance.md'),
'gsd-debugger.md must @-include the fix-acceptance reference'
);
});
});
describe('all five guardrail signals are documented (Goodhart defense)', () => {
test('reference names every signal', () => {
assert.ok(fs.existsSync(REFERENCE), 'reference must exist before signal checks');
const content = fs.readFileSync(REFERENCE, 'utf8');
assert.ok(/target test/i.test(content), 'signal 1: target test greens');
assert.ok(/mutation/i.test(content), 'signal 2: mutation check');
assert.ok(/no-op|deletion|behavior-deleting/i.test(content), 'signal 3: no-op/deletion detector');
assert.ok(/adjacent|held-out/i.test(content), 'signal 4: adjacent/held-out tests');
assert.ok(/revert[\s-]*and[\s-]*reconfirm/i.test(content), 'signal 5: revert-and-reconfirm');
});
});
describe('graceful degradation (Gall — each signal degrades onto the working agent)', () => {
test('mutation check skips when Stryker is unavailable', () => {
const content = fs.readFileSync(REFERENCE, 'utf8');
assert.ok(
/no Stryker|stryker (?:is )?(?:absent|unavailable|not configured)/i.test(content),
'must document skip when Stryker is absent'
);
});
test('guardrail reduces when no test suite exists', () => {
const content = fs.readFileSync(REFERENCE, 'utf8');
assert.ok(/no test suite/i.test(content), 'must document the no-suite reduction path');
});
test('a skipped signal is logged, never silently passed', () => {
const content = fs.readFileSync(REFERENCE, 'utf8');
assert.ok(/skipped.*log|log.*skip|recorded.*skip|skip.*record/i.test(content),
'skipped signals must be logged/recorded in the debug file');
});
});
describe('FIX REJECTED BY GUARDRAIL return path (independence — any signal can reject)', () => {
test('gsd-debugger.md defines the FIX REJECTED BY GUARDRAIL structured return', () => {
const content = fs.readFileSync(AGENT, 'utf8');
assert.ok(content.includes('FIX REJECTED BY GUARDRAIL'),
'gsd-debugger.md must define the guardrail-rejection structured return');
});
test('gsd-debug-session-manager.md handles the guardrail-rejection return', () => {
const content = fs.readFileSync(SESSION_MGR, 'utf8');
assert.ok(content.includes('FIX REJECTED BY GUARDRAIL'),
'session-manager must handle the FIX REJECTED BY GUARDRAIL return in its continuation loop');
});
});
describe('per-signal results recorded to the debug file (Kernighan — auditable)', () => {
test('reference documents the per-signal verification schema', () => {
const content = fs.readFileSync(REFERENCE, 'utf8');
assert.ok(/guardrail_verdict/.test(content),
'reference must define the guardrail_verdict field in Resolution.verification');
assert.ok(/target_test|mutation_check|no_op_deletion|adjacent_tests|revert_and_reconfirm/.test(content),
'reference must enumerate the per-signal verification keys');
});
test('DEBUG.md template acknowledges structured per-signal verification', () => {
const content = fs.readFileSync(DEBUG_TEMPLATE, 'utf8');
assert.ok(/per-signal|guardrail|fix-acceptance/i.test(content),
'DEBUG.md Resolution.verification must note structured per-signal recording');
});
});
describe('acceptance criteria from #1958', () => {
test('a surviving mutant at the fix site rejects the fix', () => {
const content = fs.readFileSync(REFERENCE, 'utf8');
assert.ok(/surviv\w+ mutant|mutant.*surviv/i.test(content),
'must state that a surviving mutant rejects the fix');
});
test('a deletion-only diff is rejected unless the RCA justifies removal', () => {
const flat = fs.readFileSync(REFERENCE, 'utf8').replace(/\s+/g, ' ');
assert.ok(/delet[^]*?(?:reject|justif|rca|root cause)/i.test(flat),
'deletion-only diffs must be rejected unless RCA justifies removal');
});
test('revert-and-reconfirm must run before a fix is accepted', () => {
const flat = fs.readFileSync(REFERENCE, 'utf8').replace(/\s+/g, ' ');
assert.ok(/before.*accept|accept.*after.*revert|prior to accept/i.test(flat),
'revert-and-reconfirm must run before fix acceptance');
});
});
describe('subprocess bounding (CLAUDE.md gauntlet — unbounded subprocess)', () => {
test('the mutation and git subprocesses are bounded', () => {
const content = fs.readFileSync(REFERENCE, 'utf8');
assert.ok(/timeout/i.test(content), 'must mention a timeout');
assert.ok(/60s|60.?second/i.test(content), 'must state the 60s npm/Stryker bound');
assert.ok(/git/i.test(content), 'must bound the git subprocess (signal 5) too');
});
});
});