Files
msd-core/docs
Tom Boucher 55fba5f7ce feat(#4917): add the PlanningDoc parse → mutate → serialize seam — Phase 1 of #4906 (#4918)
* feat(#4917): add the PlanningDoc parse -> mutate -> serialize seam

Phase 1 of epic #4906, implementing ADR-4910 and its 2026-09-21 amendment. Net-new
leaf module; NO call site is migrated, so nothing in the twelve absorbed issues
changes behavior yet.

src/planning-document.cts composes the seams that already exist rather than
reimplementing them: markdown-sectionizer for structure (fences and code spans
come from stripFencedCode / scanInlineCodeSpans, never a second scanner),
markdown-table for tables, frontmatter for frontmatter, write-set for Result<T>.

What is structural rather than conventional:

- A field node carries labelSpan, valueSpan and trailingSpan separately, and the
  only write entry point takes a node id and writes into valueSpan. trailingSpan
  is readable and has no exported writer, so the #2853/#3584/#4852 rule ("the verb
  owns the count token ONLY") stops depending on an author remembering a third
  capture group.
- Mutation is node-addressed. A handle is minted by the parser, so a caller cannot
  name a node the parser did not find. No path strings — a path is a grammar, and a
  grammar needs a parser.
- serialize splices staged spans into the ORIGINAL buffer. A no-edit serialize is
  byte-identical, which is what eliminates the #4499 defect without a targeted fix, and which also
  makes an already-escaped table cell impossible to double-escape on a round trip.
- A node that fails to parse carries its own error and span; siblings stay readable.
- Per the ADR amendment, serialize REFUSES whenever any node carries a parse error,
  even with zero staged edits, naming the offender.

One defect was found while building and fixed in place rather than deferred:
PLANNING_ARTIFACTS first derived from isCanonicalPlanningFile unfiltered, so
config.json, state.json, milestone.lock and skill-manifest.json were accepted and
returned {ok:true, nodes:[]} — "this document records nothing" when the truth was
"I have no grammar for this file". That is the exact empty-vs-error confusion this
epic exists to remove (#4899, #4900), reproduced inside the seam built to prevent
it. The registry now filters to .md while still DERIVING from
isCanonicalPlanningFile, because hand-writing a second list is the divergence this
epic is about, and parsePlanningDoc refuses a non-markdown kind at the document
level per ADR-4910 section 5.

New bin/lib module bookkeeping: .gitignore, eslint.config.mjs ignore (ADR-457 —
lint the .cts, not the emitted .cjs), docs/INVENTORY.md row, regenerated
docs/INVENTORY-MANIFEST.json, and the CONTEXT.md glossary entry.

Refs #4906

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* test(#4917): cover the PlanningDoc seam across 28 input classes

30 cases in 14 describe blocks, one per row of the phase test matrix.

The two load-bearing tests are the fast-check properties (seed 20260921,
numRuns 200):

- a single node mutation leaves every byte outside that node's valueSpan
  identical to the source
- serialize with zero staged edits is the identity function

Both are DOCUMENT-SHAPED per CONTRIBUTING.md fixture provenance (#2371): the
generator assembles arbitrary frontmatter, heading, label and value text with
join(), and never calls serialize or any other function from the module under
test to build a fixture. Seeding the generator from the module's own writer
would make the document shape a constant, and the property could then never
explore a document the writer would not itself emit.

Verified the byte-range assertion is not vacuous with a control run: it passes
against the real writer and FAILS against a simulated #4852 writer (one capture
group, replace-to-end-of-line), which visibly drops the trailing annotation.

Boundary coverage is zero / one / two staged edits. Negative space carries its
own rows — bold emphasis in prose, a field-shaped line inside a fenced block,
the same inside an inline code span, and a horizontal rule mid-body all
correctly mint no node. Row 24 is the Generative-Fix-Divergence parity
assertion: PLANNING_ARTIFACTS must not diverge from isCanonicalPlanningFile.
Row 28 covers the non-markdown canonical file found during the build.

Assertions are structural throughout — a typed Result / NodeRead /
SerializeOutcome shape, or a byte range computed from the node's own Span.
Full-string equality appears only where the contract IS byte equality.

Refs #4906

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix(#4917): apply review findings — refuse unrepresentable values, compose the layers the seam claimed

Three review passes ran against this branch: /security-review, an isolated
adversarial pass, and a standards+spec pass. Five findings, all fixed here. Every
one is the epic's own failure class reproduced inside the seam built to end it,
which is the thing worth noticing.

1. setFieldValue accepted a value containing a newline. It survived serialization
   and reparsed as a REAL sibling field — one write to Plans forged a second
   Owner into a document that already had one. Content became structure, which
   defeats ADR-4910 Decision 2's "cannot reach past its own token by
   construction": the token boundary is a LINE boundary.

2. setFieldValue accepted a value containing the trailing separator and SILENTLY
   TRUNCATED it. Staged "sneaky - annotation", read back "sneaky", with the
   remainder reclassified as trailing prose. No error, nothing unreadable, both
   resulting nodes parsing perfectly. Worse than (1) because it loses the
   caller's own value rather than adding something visible.

   Both are fixed by ONE general check, deliberately not a blacklist:
   setFieldValue rebuilds the candidate line, re-parses it through the same field
   grammar, and refuses unless the value reads back identical. Blacklisting the
   separator would close this instance and leave the class open for whatever
   separator the grammar grows next. The round-trip check is ADR-4910 Decision 4
   stated executably.

3. The module reimplemented two layers it claims to compose. Checklist detection
   hand-rolled a checkbox regex that markdown-sectionizer's iterateBullets
   already owns. Frontmatter span detection re-derived fence handling because
   frontmatter.cts's frontmatterRegion was module-private — so ADR-4910 section 1's
   stated layering was UNREACHABLE as written, and the first implementation
   routed around it silently instead of surfacing the gap.

   frontmatterRegion is now exported (additive only; ADR-2143 section 2's
   extend-never-mutate lock is inherited) and both layers are consumed.

4. The CONTEXT.md glossary entry asserted "the Frontmatter Module supplies
   frontmatter" while zero frontmatter.cts code was invoked. That was a false
   claim in the repo's vocabulary of record, written by me, and it is now true
   rather than edited away.

5. Adopting iterateBullets narrowed GFM coverage: it classifies only
   dash-prefixed task items as checkboxes, so "* [ ] x" and "+ [x] y" stopped
   becoming checklist nodes. Widening the sectionizer is forbidden by the
   inherited lock, so the task-list MARKER is interpreted in this module while
   bullet STRUCTURE still comes from the sectionizer.

The sharpest finding was not a defect. The fast-check generator constrained
values to [A-Za-z0-9 .,!?], so it could not emit an em-dash, newline, backtick,
pipe or asterisk — precisely where (1) and (2) lived. The property was real,
seeded and non-vacuous, and structurally blind to the module's actual bug class.
The generator now spans the grammar's own metacharacters, and a new property
asserts that every value setFieldValue ACCEPTS round-trips identically. Proven
able to fail: against a scratch copy with the guard stripped it fails after 7
cases on newValue "\n".

Recorded as a measured boundary, not fixed: a bare CR inside a field line leaves
that field unrecognised. Measured — sibling fields still parse, no error node,
and serialize stays byte-identical, so the worst case is an unreadable field and
never a damaged document. Flagged for Phase 4's empty-vs-error census.

Refs #4906

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* chore(#4917): backfill changeset pr number to 4918

Refs #4906

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

---------

Co-authored-by: sim <sim@local>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-09-21 11:17:58 -04:00
..

GSD Core documentation

Documentation is organised into four quadrants: tutorials help you learn by doing, how-to guides solve specific tasks, reference states authoritative facts, and explanation explores concepts and design decisions.

Language versions: English · Português (pt-BR) · 日本語 · 简体中文


Tutorials


How-to guides


Reference

  • Commands — every command with flags and examples
  • Configuration — full config schema, model profiles, git branching strategies
  • CLI tools — gsd-tools.cjs programmatic API for workflows and agents
  • JSON error mode — gsd-tools failure channels: faults (stderr, exit 1) vs degraded results (stdout, exit 0), and the reason-code taxonomy
  • Features — complete feature index
  • Inventory — installed skills and surface map
  • STATE.md schema — field-by-field reference for .planning/STATE.md
  • CONTEXT.md schema — field-by-field reference for .planning/phases/<N>/CONTEXT.md
  • PLAN.md schema — field-by-field reference for .planning/phases/<N>/PLAN.md
  • Planning artifacts — all .planning/ files and their roles
  • Review and verification capabilities — code review, security, and Nyquist capability ownership and hook contracts
  • Gate predicates — canonical specification of the phase-gate predicate vocabulary
  • Capability matrix — generated catalogue of every capability's role, tier, extension points, hook kinds, and engines.gsd
  • Exit code reference — generated catalogue of every registered process exit code, its name, meaning, and owning module, plus the reserved bands and the v1/v2 exit contract
  • Capability manifest — the full capability.json schema and validation rules
  • gsd capability command — install / update / remove / list reference for third-party capabilities
  • Workflow fragments — in-file <!-- gsd:section --> marker grammar for fragmentizing workflow markdown at emission time
  • Partition rules for compact-content splits — the protected-content list, sentinel syntax, and the five CI checks a workflow.compact_content spine/detail split must obey
  • Reviewer Lane Registry — generated catalogue of third-party reviewer lanes, with their flags, transport, and install commands

Explanation