Files
msd-core/gsd-core/workflows/ingest-docs.md
Tom Boucher 1110c3b4ee fix(#4709): stop minting the retired gemini runtime id in shipped surfaces (#4711)
* test(#4709): assert no shipped surface mints a retired runtime id

Extends the #1928 removal guard to the surfaces it structurally could not
reach. Its own docblock scopes it to the installer CLI contract and the
runtime-name-policy exports; it spawns the installer and inspects module
exports, and never reads gsd-core/workflows/**, commands/** or skills/**.

Four structural assertions, all RED on next:
- every RUNTIME= assignment must name a canonical runtime
- the runtime->model-tier table must name only model-catalog runtimes
- runtime selection menus must offer only canonical runtimes
- config-set runtime / model_profile_overrides examples must be canonical

Structural, not textual: each asserts the literal is canonical or the runtime
exists as a catalog key, never that the string "gemini" is absent. That string
is load-bearing across Antigravity's real on-disk contract, so a fifth test
pins that contract from the descriptor (not from a resolved path, which would
read $ANTIGRAVITY_CONFIG_DIR and the real $HOME -- the #4312 defect class).
An over-broad gemini -> antigravity replacement fails there rather than ships.

The menu assertion is scoped by the nearest preceding `question:` matching
/runtime/i, because the same file carries a provider menu (anthropic, openai)
and a budget menu (high, medium, low) whose labels are single lowercase tokens
too and name neither a runtime nor anything the policy should judge.

Refs #4709

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix(#4709): stop minting the retired gemini runtime id in workflow text

#1928 removed the gemini runtime after Google sunset Gemini CLI on 2026-06-18,
but the removal stopped at the installer boundary. Runtime-loaded workflow text
kept assigning the id, and the name policy's unknown-id fallbacks then applied a
default designed for a never-known FUTURE runtime to an id GSD itself retired:
getRuntimeLabel('gemini') is 'Claude Code', getProjectInstructionFile('gemini')
is 'AGENTS.md', getGlobalConfigDir('gemini') is ~/.claude. A stale id produced a
plausible wrong answer instead of an error.

Those fallbacks are DELIBERATE and are left untouched here -- four docblocks
document them, src/runtime-name-policy.cts:220-222 calls the label default "the
always-safe default, fail-closed", and an existing test in this very suite pins
getProjectInstructionFile('gemini') === 'AGENTS.md'. This commit removes the
REACHABILITY of the retired id instead:

- new-project.md, ingest-docs.md: the runtime-detection cascade mapped
  /.gemini/ and $GEMINI_CONFIG_DIR to RUNTIME=gemini. Both now map
  /.gemini/antigravity{,-ide,-cli}/ and $ANTIGRAVITY_CONFIG_DIR to
  RUNTIME=antigravity, the documented successor. ingest-docs.md was not in the
  original report; the new structural test found it.
- settings-advanced.md: dropped the `gemini` row from the runtime->model-tier
  table. The model catalog has no gemini runtime (runtimeTierDefaults has 18
  keys, none of them gemini), so the row advertised built-in defaults for a
  runtime whose config key is ignored. Its three model IDs were copied from the
  `google` PROVIDER preset -- a provider axis rendered as a runtime axis.
- settings-advanced.md: removed the `gemini` / "Gemini CLI." runtime menu
  option and its group listing, so no menu offers a runtime GSD cannot install.
- settings-advanced.md: repointed the config examples from `runtime gemini` to
  `runtime antigravity`, which ships no built-in tier defaults and is therefore
  the case those overrides actually exist for.
- reapply-patches.md: $GEMINI_CONFIG_DIR -> $ANTIGRAVITY_CONFIG_DIR,
  ~/.gemini/gsd-local-patches -> ~/.gemini/antigravity/gsd-local-patches, and
  the local scan's bare .gemini -> .agents (Antigravity's localConfigDir). This
  file is hand-written, so `npm run sync:launcher` never reached it.
- update.md: bare ~/.gemini and ./.gemini as GSD config dirs -> the real
  ~/.gemini/antigravity and ./.agents.

Antigravity's own Gemini-family surfaces are untouched by design: ~/.gemini as
its configHome parent, ~/.gemini/config for global skills/agents (#3738),
hookEvents "gemini", GEMINI.md as its projectInstructionFile, the
~/.gemini/antigravity{,-ide,-cli} ambiguity probes (#1441), and every gemini-*
model ID. The launcher's own GEMINI_CONFIG_DIR arm is left to #4632, which
absorbed #4347 for it.

Refs #4709

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* docs(#4709): record the Gemini -> Antigravity migration research

Primary-source research note behind #4709: the sense taxonomy that separates a
runtime-axis `gemini` (stale) from Antigravity's on-disk contract, Google's
model IDs, and release history (all load-bearing); the PRESERVE table; the
guard-gap analysis; and the per-file inventory with file:line citations.

Refs #4709

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix(#4709): keep the legacy patches probe, and stop tripping two lint gates

Three review findings, fixed inline.

1. Dropping the global ~/.gemini/gsd-local-patches probe was a regression: a
   pre-#1928 Gemini CLI install put patches there, and a stranded patches dir is
   still the user's work. Restored as an explicitly-labelled legacy arm probed
   AFTER Antigravity, so a live install always wins. This is a directory probe,
   not a runtime home -- it assigns no runtime id, so it does not reintroduce
   the defect this PR closes. The $GEMINI_CONFIG_DIR env probe is deliberately
   NOT restored: that names a runtime config home, which
   tests/declarative-reference-antigravity.test.cjs:307 pins as ignored.

2. The comment added in (1) originally contained the literal string that the new
   structural test matches, so the test flagged its own fix's comment as a mint.
   Reworded. The test was right; a comment in shipped workflow text is as
   readable to a matcher as code is.

3. docs/research/gemini-to-antigravity-migration.md used the colon slash-form
   inside a quoted manifest description. lint-docs-command-form rejects it:
   docs are never passed through the install-time converters, so the colon form
   names a command no runtime registers. Normalised to the hyphen form.

Also verified, rather than assumed: the local scan's .agents entry is
unambiguous. Antigravity is the ONLY runtime declaring localConfigDir '.agents'
across all 19 capability manifests; grok and codex use ~/.agents as a GLOBAL
home, and this scan is local (./$dir).

Refs #4709

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix(#4709): retire Gemini CLI from the PR templates, and close two review gaps

Adversarial review findings, all fixed inline.

1. All three .github/PULL_REQUEST_TEMPLATE/*.md still offered "Gemini CLI" under
   "Runtimes tested", and none offered Antigravity. #1928's follow-up dropped
   Gemini CLI from .github/ISSUE_TEMPLATE/*.yml but missed the PR templates, so
   every contributor opening a fix/feature/enhancement PR has been asked for two
   releases which runtime they tested and offered a retired one. Now Antigravity.
   Guarded by a new assertion: runtime checklist labels in the PR templates must
   appear in the runtime label table. Proven non-vacuous by reverting one
   template line and watching the probe report the offender.

2. The #4709 scanning corpus excluded agents/, which also ships runtime-loaded
   markdown including .compact.md variants. Widened: 318 -> 382 files (+64), zero
   new offenders, so the gap was coverage rather than a live defect.

3. gsd-core/workflows/sync-skills.md said "grok and gemini have no dedicated
   installer flag — they alias the codex and claude skills roots respectively."
   The gemini half is wrong twice over: the runtime is retired, and it never
   aliased claude -- canonicalizeRuntimeName returns null for it and the caller's
   fail-closed default merely happens to be claude. Describing that as designed
   aliasing is exactly the confusion this issue is about. Reduced to grok, which
   genuinely does alias the codex skills root.

4. The changeset said the runtime was removed in 1.11. It shipped in 1.8.0
   (CHANGELOG.md:1023 is the enclosing release heading for the #1928 entry at
   :1124). Corrected.

Refs #4709

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* test(#4709): follow the corrected sync-skills prose, and refresh the compact baseline

Three GREEN-run failures, all caused by this PR's own edits.

1. tests/sync-skills-cross-runtime-refuse.test.cjs pinned the literal phrase
   "grok and gemini have no dedicated installer flag" — a test REQUIRING shipped
   text to name a runtime retired in 1.8.0, which is the exact class #4709
   exists to remove. The assertion and its rationale comment now track the
   corrected prose ("grok has no dedicated installer flag"), and the docblock's
   runtime list drops gemini. The remaining assertions in that file — the
   guard's exit, the installer pointer, the $DEST reference, guard-before-copy
   ordering — are untouched, so #3025's contract is otherwise intact.

2. tests/fixtures/compact-content-benchmark-baseline.json drifted because the
   new-project.md edits changed its compacted size (split "new-project": off
   14279 -> 14308, on 12335 -> 12364; aggregate off 107411 -> 107440).
   Refreshed with `node scripts/benchmark-compact-content.cjs --write`, which
   is that script's own documented remedy.

3. emitted-attribution reported four grown workflow files with no
   acknowledgment. Acked below as commit trailers per ADR-3942, which moved the
   acknowledgment out of tests/emitted-drift-acks/*.json fragments and into the
   PR's own commit range (read with three-dot base...head). Exactly the four
   files the gate named are acked — settings-advanced.md and sync-skills.md
   shrank and are deliberately absent, since a trailer no delta consumed is a
   staleAcks error.

Refs #4709

Emitted-Drift-Ack-Growth: ingest-docs.md — the runtime-detection cascade now names Antigravity's three real directories (/.gemini/antigravity{,-ide,-cli}/) and $ANTIGRAVITY_CONFIG_DIR in place of the single retired /.gemini/ arm and $GEMINI_CONFIG_DIR; three correct paths cost more bytes than the one wrong path they replace.
Emitted-Drift-Ack-Growth: new-project.md — same runtime-detection correction as ingest-docs.md, plus dropping "gemini/" from the two GEMINI.md instruction-file sentences so the prose stops contradicting getProjectInstructionFile, which returns AGENTS.md for that retired id.
Emitted-Drift-Ack-Growth: reapply-patches.md — restores the legacy ~/.gemini/gsd-local-patches probe as an explicitly-labelled arm after an adversarial-review finding that dropping it stranded a pre-#1928 user's patches, and repoints the env/global probes at Antigravity; the four-line comment is load-bearing, since a bare retired-runtime path with no explanation is exactly what the next reader would delete.
Emitted-Drift-Ack-Growth: update.md — bare ~/.gemini and ./.gemini as GSD config dirs are replaced by the real ~/.gemini/antigravity and ./.agents, which are longer strings; no content was added beyond the corrected paths.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* chore(#4709): backfill the changeset PR number

pr: 0 -> 4711, now that the PR exists. Never guessed ahead of the number.

Refs #4709

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

---------

Co-authored-by: sim <sim@local>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-09-13 23:08:20 -04:00

20 KiB
Raw Blame History

Ingest Docs Workflow

Scan a repo for mixed planning documents (ADR, PRD, SPEC, DOC), synthesize them into a consolidated context, and bootstrap or merge into .planning/.

  • [path] — optional target directory to scan (defaults to repo root)
  • --mode new|merge — override auto-detect (defaults: new if .planning/ absent, merge if present)
  • --manifest <file> — YAML file listing {path, type, precedence?} per doc; overrides heuristic classification
  • --resolve auto|interactive — conflict resolution (v1: only auto is supported; interactive is reserved)

Display the stage banner:

### GSD ► INGEST DOCS

Parse $ARGUMENTS:

  • First positional token (if not a flag) → SCAN_PATH (default: .)
  • --mode new|merge → MODE (default: auto-detect)
  • --manifest <file> → MANIFEST_PATH (optional)
  • --resolve auto|interactive → RESOLVE_MODE (default: auto; reject interactive in v1 with message "interactive resolution is planned for a future release")

Validate paths:

case "{SCAN_PATH}" in *..*) echo "SECURITY_ERROR: path contains traversal sequence"; exit 1 ;; esac
test -d "{SCAN_PATH}" || echo "PATH_NOT_FOUND"
if [ -n "{MANIFEST_PATH}" ]; then
  case "{MANIFEST_PATH}" in *..*) echo "SECURITY_ERROR: manifest path contains traversal"; exit 1 ;; esac
  test -f "{MANIFEST_PATH}" || echo "MANIFEST_NOT_FOUND"
fi

Containment (required): After resolving SCAN_PATH and MANIFEST_PATH relative to the repo root, canonicalize each with realpath (or platform equivalent) and assert the result is under realpath("$REPO_ROOT"). Reject absolute paths outside the repo (e.g. /tmp, C:\Windows) even when they do not contain ...

If PATH_NOT_FOUND or MANIFEST_NOT_FOUND: display error and exit.

Run the init query:

_GSD_SHIM_NAME="gsd-tools.cjs"; _GSD_RUNTIME_ROOT="${RUNTIME_DIR:-$(git rev-parse --show-toplevel 2>/dev/null || pwd)}"; GSD_TOOLS="${_GSD_RUNTIME_ROOT}/gsd-core/bin/${_GSD_SHIM_NAME}"; _gsd_at() { for _p; do if [ -f "$_p" ]; then GSD_TOOLS="$_p"; return 0; fi; done; return 1; }; if _gsd_at "${_GSD_RUNTIME_ROOT}/gsd-core/bin/${_GSD_SHIM_NAME}" "${_GSD_RUNTIME_ROOT}/.claude/gsd-core/bin/${_GSD_SHIM_NAME}" "${_GSD_RUNTIME_ROOT}/.codex/gsd-core/bin/${_GSD_SHIM_NAME}"; then gsd_run() { node "$GSD_TOOLS" "$@"; }; elif unset -f gsd_run; _G="$(command -v gsd_run)"; then GSD_TOOLS="$_G"; gsd_run() { "$GSD_TOOLS" "$@"; }; elif _gsd_at "${CLAUDE_CONFIG_DIR:-$HOME/.claude}/gsd-core/bin/${_GSD_SHIM_NAME}" "${HERMES_HOME:-$HOME/.hermes}/gsd-core/bin/${_GSD_SHIM_NAME}" "${CURSOR_CONFIG_DIR:-$HOME/.cursor}/gsd-core/bin/${_GSD_SHIM_NAME}" "${CODEX_HOME:-$HOME/.codex}/gsd-core/bin/${_GSD_SHIM_NAME}" "${GEMINI_CONFIG_DIR:-$HOME/.gemini}/gsd-core/bin/${_GSD_SHIM_NAME}" "${COPILOT_CONFIG_DIR:-$HOME/.copilot}/gsd-core/bin/${_GSD_SHIM_NAME}" "${WINDSURF_CONFIG_DIR:-$HOME/.codeium/windsurf}/gsd-core/bin/${_GSD_SHIM_NAME}" "${AUGMENT_CONFIG_DIR:-$HOME/.augment}/gsd-core/bin/${_GSD_SHIM_NAME}" "${TRAE_CONFIG_DIR:-$HOME/.trae}/gsd-core/bin/${_GSD_SHIM_NAME}" "${QWEN_CONFIG_DIR:-$HOME/.qwen}/gsd-core/bin/${_GSD_SHIM_NAME}" "${CODEBUDDY_CONFIG_DIR:-$HOME/.codebuddy}/gsd-core/bin/${_GSD_SHIM_NAME}" "${CLINE_CONFIG_DIR:-$HOME/.cline}/gsd-core/bin/${_GSD_SHIM_NAME}" "${GROK_AGENTS_HOME:-$HOME/.agents}/gsd-core/bin/${_GSD_SHIM_NAME}" "${ANTIGRAVITY_CONFIG_DIR:-$HOME/.gemini/antigravity}/gsd-core/bin/${_GSD_SHIM_NAME}" "${OPENCODE_CONFIG_DIR:-${XDG_CONFIG_HOME:-$HOME/.config}/opencode}/gsd-core/bin/${_GSD_SHIM_NAME}" "${KILO_CONFIG_DIR:-${XDG_CONFIG_HOME:-$HOME/.config}/kilo}/gsd-core/bin/${_GSD_SHIM_NAME}"; then gsd_run() { node "$GSD_TOOLS" "$@"; }; else echo "ERROR: gsd-tools.cjs not found at $GSD_TOOLS and gsd_run is not on PATH. Run: npx -y @opengsd/gsd-core@latest --claude --local" >&2; exit 1; fi; GSD_IDENTITY_STATUS=unverified; case "$(gsd_run runtime-identity --raw 2>/dev/null || true)" in '{"packageName":"@opengsd/gsd-core"'*'}') GSD_IDENTITY_STATUS=ok;; esac; export GSD_IDENTITY_STATUS; [ "$GSD_IDENTITY_STATUS" = ok ] || echo "WARNING: \"$GSD_TOOLS\" did not prove it is @opengsd/gsd-core - it is either a different package or an @opengsd/gsd-core older than the runtime-identity verb. See docs/how-to/diagnose-a-foreign-gsd-tools.md" >&2; if [ -n "${CLAUDE_ENV_FILE:-}" ] && [ -n "${GSD_TOOLS:-}" ]; then printf "export PATH='%s':\"\$PATH\"\n" "${GSD_TOOLS%/*}" >> "$CLAUDE_ENV_FILE" 2>/dev/null || true; fi
RESPONSE_LANGUAGE=$(gsd_run query config-get response_language --raw --default "" 2>/dev/null || echo "")
INIT=$(gsd_run init ingest-docs)
if [[ "$INIT" == @file:* ]]; then INIT=$(cat "${INIT#@file:}"); fi
CLASSIFIER_MODEL=$(gsd_run query resolve-model gsd-doc-classifier --raw)
SYNTHESIZER_MODEL=$(gsd_run query resolve-model gsd-doc-synthesizer --raw)
ROADMAPPER_MODEL=$(gsd_run query resolve-model gsd-roadmapper --raw)

If response_language is set: All user-facing output of this workflow — narration between tool calls, status updates, progress notes, findings, questions, prompts, and explanations — MUST be presented in {response_language}. Technical terms, code, file paths, and subagent prompts stay in English — only user-facing output is translated.

Parse project_exists, planning_exists, has_git, git_worktree_root, in_nested_subdir, project_path from INIT.

Absolute path fields (#2376): INIT also carries requirements_path, roadmap_path, state_path, intel_dir, and conflicts_path — all anchored on project_root, not the orchestrator's own cwd. Use these (not bare .planning/... literals) whenever building <required_reading>/output paths for a spawned subagent, since that subagent's own cwd may differ from the orchestrator's.

Auto-detect MODE if not set:

  • planning_exists: true → MODE=merge
  • planning_exists: false → MODE=new

If user passed --mode new but .planning/ already exists: display warning and require explicit confirm via AskUserQuestion (approve-revise-abort from gsd-core/references/gate-prompts.md) before overwriting.

Git initialisation (Bug #3491 — never create a nested .git inside an existing worktree):

  • If has_git: true and in_nested_subdir: true: do NOT run git init. Surface a warning that planning files will be tracked by the outer repo at git_worktree_root.
  • If has_git: true and in_nested_subdir: false: already at a worktree root, skip git init.
  • If has_git: false and MODE=new: initialize git:
git init

Detect runtime using the same pattern as new-project.md:

  • execution_context path /.codex/ → RUNTIME=codex
  • /.gemini/antigravity/, /.gemini/antigravity-ide/ or /.gemini/antigravity-cli/ → RUNTIME=antigravity
  • /.opencode/ or /.config/opencode/ → RUNTIME=opencode
  • /.trae/ → RUNTIME=trae
  • else → RUNTIME=claude

Fall back to env vars (CODEX_HOME, ANTIGRAVITY_CONFIG_DIR, OPENCODE_CONFIG_DIR, TRAE_CONFIG_DIR) if execution_context is unavailable.

Build the doc list from three sources, in order:

1. Manifest (if provided) — authoritative:

Read MANIFEST_PATH. Expected YAML shape:

docs:
  - path: docs/adr/0001-db.md
    type: ADR
    precedence: 0   # optional, lower = higher precedence
  - path: docs/prd/auth.md
    type: PRD

Each entry provides path (required, relative to repo root) + type (required, one of ADR|PRD|SPEC|DOC) + precedence (optional integer).

2. Directory conventions (skipped when manifest is provided):

# ADRs
find {SCAN_PATH} -type f \( -path '*/adr/*' -o -path '*/adrs/*' -o -name 'ADR-*.md' -o -regex '.*/[0-9]\{4\}-.*\.md' \) 2>/dev/null

# PRDs
find {SCAN_PATH} -type f \( -path '*/prd/*' -o -path '*/prds/*' -o -name 'PRD-*.md' \) 2>/dev/null

# SPECs / RFCs
find {SCAN_PATH} -type f \( -path '*/spec/*' -o -path '*/specs/*' -o -path '*/rfc/*' -o -path '*/rfcs/*' -o -name 'SPEC-*.md' -o -name 'RFC-*.md' \) 2>/dev/null

# Generic docs (fall-through candidates)
find {SCAN_PATH} -type f -path '*/docs/*' -name '*.md' 2>/dev/null

De-duplicate the union (a file matched by multiple patterns is one doc).

3. Content heuristics (run during classification, not here) — the classifier handles frontmatter type: and H1 inspection for docs that didn't match a convention.

Cap: hard limit of 50 docs per invocation (documented v1 constraint). If the discovered set exceeds 50:

GSD > Discovered {N} docs, which exceeds the v1 cap of 50.
      Use --manifest to narrow the set to ≤ 50 files, or run
      /gsd:ingest-docs again with a narrower <path>.

Exit without proceeding.

Display discovered set and request approval (see gsd-core/references/gate-prompts.md — yes-no-pick pattern works; or approve-revise-abort):

Discovered {N} documents:
  {N} ADR | {N} PRD | {N} SPEC | {N} DOC | {N} unclassified

  docs/adr/0001-architecture.md       [ADR]    (from manifest|directory|heuristic)
  docs/adr/0002-database.md           [ADR]    (directory)
  docs/prd/auth.md                    [PRD]    (manifest)
  ...

Text mode: apply the same --text/text_mode rule as other workflows — replace AskUserQuestion with a numbered list.

Use AskUserQuestion (approve-revise-abort):

  • question: "Proceed with classification of these {N} documents?"
  • header: "Approve?"
  • options: Approve | Revise | Abort

On Abort: exit cleanly with "Ingest cancelled." On Revise: exit with guidance to re-run with --manifest or a narrower path.

Create staging directory:

mkdir -p .planning/intel/classifications/

For each discovered doc, spawn gsd-doc-classifier in parallel. In Claude Code, issue all Task calls in a single message with multiple tool uses so the harness runs them concurrently. For Copilot / sequential runtimes, fall back to sequential dispatch.

Model omission (#2517). Omit the model parameter entirely when the value it would carry (CLASSIFIER_MODEL, SYNTHESIZER_MODEL, ROADMAPPER_MODEL) is "inherit" or empty. An empty value 404s on runtimes without native tier aliases — the default on non-Claude runtimes. Omitting it inherits the orchestrator's model. See @gsd-core/references/model-profile-resolution.md.

Per-spawn prompt fields:

  • FILEPATH — absolute path to the doc
  • OUTPUT_DIR — {intel_dir}/classifications (absolute — from init ingest-docs; #2376: a spawned classifier's own cwd may differ from the orchestrator's)
  • MANIFEST_TYPE — the type from the manifest if present, else omit
  • MANIFEST_PRECEDENCE — the precedence integer from the manifest if present, else omit
  • <required_reading> — agents/gsd-doc-classifier.md (the agent definition itself)

Model on every classifier spawn (#3602): model="{CLASSIFIER_MODEL}" is a parameter of each Task/Agent call — not a prompt field, never folded into the prompt text — so dynamic_routing/model_profile tiers apply instead of the caller's session model. Omit the parameter per the rule above when the value is "inherit" or empty.

Collect the one-line confirmations from each classifier. If any classifier errors out, surface the error and abort without touching .planning/ further.

Spawn gsd-doc-synthesizer once (runs in a subagent — no output until it returns, ~1–5 min; expected, not a freeze):

Runtime-aware dispatch (#2508 Phase 4). GSD workflows dispatch specialized subagents by role. Before dispatching on a built-in-only runtime (kimi-code — three built-ins only), resolve the role to a built-in via gsd_run query resolve-dispatch-type --requested <role> --raw. On named-dispatch runtimes (Claude/OpenCode/…) the role is returned unchanged; on kimi-code it maps to coder/explore/plan by role-suffix. The persona rides ${AGENT_SKILLS_<ROLE>} (Phase 3) regardless. See @gsd-core/references/runtime-aware-dispatch.md.

Agent({
  subagent_type: "gsd-doc-synthesizer",
  model: "{SYNTHESIZER_MODEL}",
  prompt: "
    CLASSIFICATIONS_DIR: {intel_dir}/classifications
    INTEL_DIR: {intel_dir}
    CONFLICTS_PATH: {conflicts_path}
    MODE: {MODE}
    EXISTING_CONTEXT: {paths to existing .planning files if MODE=merge, else empty}
    PRECEDENCE: {array from manifest defaults or default ['ADR','SPEC','PRD','DOC']}

    <required_reading>
    - agents/gsd-doc-synthesizer.md
    - gsd-core/references/doc-conflict-engine.md
    </required_reading>
  "
})

ORCHESTRATOR RULE — CODEX RUNTIME: After calling Agent() above, stop working on this task immediately. Do not read or synthesize any classified documents independently while the subagent is active. Wait for the subagent to return its result. This prevents duplicate work, conflicting edits, and wasted context. Only resume when the subagent result is available.

The synthesizer writes:

  • .planning/intel/decisions.md, .planning/intel/requirements.md, .planning/intel/constraints.md, .planning/intel/context.md
  • .planning/intel/SYNTHESIS.md
  • .planning/INGEST-CONFLICTS.md

Read .planning/INGEST-CONFLICTS.md. Count entries in each bucket (the synthesizer always writes the three-bucket header; parse the ### BLOCKERS ({N}), ### WARNINGS ({N}), ### INFO ({N}) lines).

Apply the safety semantics from gsd-core/references/doc-conflict-engine.md. Operation noun: ingest.

If BLOCKERS > 0:

Render the report to the user, then display:

GSD > BLOCKED: {N} blockers must be resolved before ingest can proceed.

Exit WITHOUT writing PROJECT.md, REQUIREMENTS.md, ROADMAP.md, or STATE.md. The staging intel files remain for inspection. The safety gate holds — no destination files are written when blockers exist.

If WARNINGS > 0 and BLOCKERS = 0:

Render the report, then ask via AskUserQuestion (approve-revise-abort):

  • question: "Review the competing variants above. Resolve manually and proceed, or abort?"
  • header: "Approve?"
  • options: Approve | Abort

On Abort: exit cleanly with "Ingest cancelled. Staged intel preserved at .planning/intel/."

If BLOCKERS = 0 and WARNINGS = 0:

Optionally display GSD > No conflicts. Auto-resolved: {N}. Absence of conflicts is not authorization to write: proceed to the routing gate for the active mode — new mode's routing gate (next step) or merge mode's merge-diff approve-revise-abort gate — which decides whether destination files are created.

Applies only when MODE=new.

Audit PROJECT.md field requirements that gsd-roadmapper expects. For fields derivable from .planning/intel/SYNTHESIS.md (project scope, goals/non-goals, constraints, locked decisions), synthesize from the intel. For fields NOT derivable (project name, developer-facing success metric, target runtime), prompt via AskUserQuestion one at a time — minimal question set, no interrogation.

Routing gate (#3827): approval to classify documents is not approval to write the planning scaffold. Before delegating, display the exact destinations and require an explicit choice:

Routing — create the planning setup now?

  .planning/PROJECT.md        (new)
  .planning/REQUIREMENTS.md   (new)
  .planning/ROADMAP.md        (new)
  .planning/STATE.md          (new)

Use AskUserQuestion:

  • question: "Routing — create the planning setup now?"
  • header: "Routing"
  • options: Create planning setup | Keep synthesized intel only | Abort

Text mode: numbered list (1/2/3) with the same three choices.

On Create planning setup: continue to the gsd-roadmapper delegation below.

On Keep synthesized intel only: analysis-only ingest. Do NOT invoke gsd-roadmapper; write no destination files. The staged intel under .planning/intel/ is preserved and committed by finalize (substitute its actual file set — no PROJECT.md/REQUIREMENTS.md/ROADMAP.md/STATE.md lines). Display the completion banner with mode new (intel only).

On Abort: exit cleanly with "Ingest cancelled. Staged intel preserved at .planning/intel/."

Any other response (freeform/"Other"): re-ask once; if still ambiguous, treat as Abort. Never infer Create from an ambiguous answer.

Delegate to gsd-roadmapper (runs in a subagent — no output until it returns, ~1–5 min; expected, not a freeze):

Agent({
  subagent_type: "gsd-roadmapper",
  model: "{ROADMAPPER_MODEL}",
  prompt: "
    Mode: new-project-from-ingest
    Intel: {intel_dir}/SYNTHESIS.md (entry point)
    Per-type intel: {intel_dir}/decisions.md, {intel_dir}/requirements.md, {intel_dir}/constraints.md, {intel_dir}/context.md
    User-supplied fields: {collected in previous step}

    Produce:
    - {project_path}
    - {requirements_path}
    - {roadmap_path}
    - {state_path}

    Treat ADR-locked decisions as locked in PROJECT.md <decisions> blocks.
  "
})

ORCHESTRATOR RULE — CODEX RUNTIME: After calling Agent() above, stop working on this task immediately. Do not read more intel files, write planning artifacts, or create ROADMAP.md independently while the subagent is active. Wait for the subagent to return its result. This prevents duplicate work, conflicting edits, and wasted context. Only resume when the subagent result is available.

Applies only when MODE=merge.

Load existing .planning/ROADMAP.md, .planning/PROJECT.md, .planning/REQUIREMENTS.md, all CONTEXT.md files under .planning/phases/.

The synthesizer has already hard-blocked on any LOCKED-in-ingest vs LOCKED-in-existing contradiction; if we reach this step, no such blockers remain.

Plan the merge:

  • New requirements from synthesized .planning/intel/requirements.md that do not overlap existing REQUIREMENTS.md entries → append to REQUIREMENTS.md
  • New decisions from synthesized .planning/intel/decisions.md that do not overlap existing CONTEXT.md <decisions> blocks → write to a new phase's CONTEXT.md or append to the next milestone's requirements
  • New scope → derive phase additions following the new-milestone.md pattern; append phases to .planning/ROADMAP.md

Preview the merge diff to the user and gate via approve-revise-abort before writing.

Commit the ingest results:

gsd_run commit \
  "docs: ingest {N} docs from {SCAN_PATH} (#2387)" --files \
  .planning/PROJECT.md \
  .planning/REQUIREMENTS.md \
  .planning/ROADMAP.md \
  .planning/STATE.md \
  .planning/intel/ \
  .planning/INGEST-CONFLICTS.md

(For merge mode, substitute the actual set of modified files.)

Display completion:

### GSD ► INGEST DOCS COMPLETE

Show:

  • Mode ran (new, new (intel only), or merge)
  • Docs ingested (count + type breakdown)
  • Decisions locked, requirements created, constraints captured
  • Conflict report path (.planning/INGEST-CONFLICTS.md)
  • Next step: /gsd:plan-phase 1 (new) or /gsd:plan-phase N (merge, pointing at the first newly-added phase); for intel-only runs there is no roadmap yet — point at /gsd:new-project (or a later re-run with --mode merge once scaffold files exist), never /gsd:plan-phase

Anti-Patterns

Do NOT:

  • Violate the shared conflict-engine contract in gsd-core/references/doc-conflict-engine.md (no markdown tables, no new severity labels, no bypass of the BLOCKER gate)
  • Write PROJECT.md, REQUIREMENTS.md, ROADMAP.md, or STATE.md when BLOCKERs exist in the conflict report
  • Skip the 50-doc cap — larger sets must use --manifest to narrow the scope
  • Auto-resolve LOCKED-vs-LOCKED ADR contradictions — those are BLOCKERs in both modes
  • Merge competing PRD acceptance variants into a combined criterion — preserve all variants for user resolution
  • Bypass the discovery approval gate — users must see the classified doc list before classifiers spawn
  • Skip path validation on SCAN_PATH or MANIFEST_PATH
  • Implement --resolve interactive in this v1 — the flag is reserved; reject with a future-release message