Files
msd-core/tests/phase6-review-capabilities.test.cjs
Jakub Zych a9a7a328e6 refactor: hard-fork GSD -> MSD (Make Software Done)
Mechanical rename produced by scripts/msd-rename.cjs: gsd/Gsd/GSD -> msd/Msd/MSD
across contents and paths, upstream package/repo coordinates -> @golem15/msd-core
and golem15com/msd-core. Deep links into upstream history, sibling upstream
packages, the GSD-2 import feature, CHANGELOG.md and .changeset/ are kept as-is.

Hand edits on top: MSD block-letter banner and logos, LICENSE copyright line,
package/plugin identity, regenerated lockfile, install-tree fixtures, derived
registries and benchmark baseline; migration checksum baseline re-locked
(MSD keeps its own install state, so no install had applied the old sums);
sort-order and regex-escaped expectations in tests adjusted.
2026-10-06 01:47:40 +02:00

217 lines
10 KiB
JavaScript

'use strict';
const { describe, test } = require('node:test');
const assert = require('node:assert/strict');
const fs = require('node:fs');
const path = require('node:path');
const ROOT = path.resolve(__dirname, '..');
const registry = require('../msd-core/bin/lib/capability-registry.cjs');
function workflow(name) {
return fs.readFileSync(path.join(ROOT, 'msd-core', 'workflows', name), 'utf8');
}
function doc(name) {
return fs.readFileSync(path.join(ROOT, 'docs', name), 'utf8');
}
function sectionBetween(content, startNeedle, endNeedle) {
const start = content.indexOf(startNeedle);
assert.ok(start !== -1, `${startNeedle} section must exist`);
const end = endNeedle ? content.indexOf(endNeedle, start) : -1;
return content.slice(start, end === -1 ? undefined : end);
}
function hookAt(point, kind, capId) {
return registry.byLoopPoint[point][kind].find((hook) => hook.capId === capId);
}
describe('ADR-857 phase 6 verification and review capability migration', () => {
test('registry declares code-review, security, and nyquist feature capabilities', () => {
for (const capId of ['code-review', 'security', 'nyquist']) {
assert.ok(registry.capabilities[capId], `${capId} capability must exist`);
assert.equal(registry.capabilities[capId].role, 'feature');
}
});
test('code-review capability owns review skills, agents, config, and execute hook', () => {
assert.equal(registry.bySkill['code-review'], 'code-review');
assert.equal(registry.byAgent['msd-code-reviewer'], 'code-review');
assert.equal(registry.byAgent['msd-code-fixer'], 'code-review');
assert.equal(registry.configKeys['workflow.code_review'], 'code-review');
assert.equal(registry.configKeys['workflow.code_review_depth'], 'code-review');
const hook = hookAt('execute:post', 'steps', 'code-review');
assert.ok(hook, 'code-review must register an execute:post step');
assert.deepEqual(hook.ref, { skill: 'code-review' });
assert.equal(hook.when, 'workflow.code_review');
assert.deepEqual(hook.produces, ['REVIEW.md']);
assert.ok(hook.consumes.includes('SUMMARY.md'));
});
test('security capability owns secure-phase wiring and blocking ship gate', () => {
assert.equal(registry.bySkill['secure-phase'], 'security');
assert.equal(registry.byAgent['msd-security-auditor'], 'security');
assert.equal(registry.configKeys['workflow.security_enforcement'], 'security');
assert.equal(registry.configKeys['workflow.security_asvs_level'], 'security');
assert.equal(registry.configKeys['workflow.security_block_on'], 'security');
const step = hookAt('verify:post', 'steps', 'security');
assert.ok(step, 'security must register a verify:post step');
assert.deepEqual(step.ref, { skill: 'secure-phase' });
assert.equal(step.when, 'workflow.security_enforcement');
assert.equal(step.onError, 'halt');
const gate = hookAt('ship:pre', 'gates', 'security');
assert.ok(gate, 'security must register a blocking ship:pre gate');
assert.equal(gate.blocking, true);
assert.equal(gate.onError, 'halt');
const planContribution = hookAt('plan:pre', 'contributions', 'security');
assert.ok(planContribution, 'security must register a plan:pre contribution for threat-model guidance');
assert.equal(planContribution.into, 'planner');
assert.equal(planContribution.when, 'workflow.security_enforcement');
});
test('nyquist capability owns validate-phase wiring and config', () => {
assert.equal(registry.bySkill['validate-phase'], 'nyquist');
assert.equal(registry.byAgent['msd-nyquist-auditor'], 'nyquist');
assert.equal(registry.configKeys['workflow.nyquist_validation'], 'nyquist');
const hook = hookAt('verify:post', 'steps', 'nyquist');
assert.ok(hook, 'nyquist must register a verify:post step');
assert.deepEqual(hook.ref, { skill: 'validate-phase' });
assert.equal(hook.when, 'workflow.nyquist_validation');
assert.deepEqual(hook.produces, ['VALIDATION.md']);
assert.ok(hook.consumes.includes('SUMMARY.md'));
});
test('autonomous code review resolves execute:post hooks instead of inlining code_review config', () => {
const content = workflow('autonomous.md');
const section = sectionBetween(
content,
'**3c.5. Code Review and Fix**',
'**3d. Post-Execution Routing**',
);
assert.ok(section.includes('loop render-hooks execute:post'));
assert.ok(section.includes('msd-${ref.skill}'));
assert.ok(!section.includes('config-get workflow.code_review'));
});
test('execute-phase code-review gate resolves execute:post hooks instead of inlining code_review config', () => {
const content = workflow('execute-phase.md');
// close_parent_artifacts was extracted to
// msd-core/workflows/execute-phase/steps/gap-closure-artifacts.md; the parent now
// marks that boundary with a <!-- msd:section id="gap-closure-artifacts" --> comment
// immediately after code_review_gate's closing </step>, so it remains the correct
// end-of-step delimiter for isolating this step's body.
const section = sectionBetween(content, '<step name="code_review_gate"', '<!-- msd:section id="gap-closure-artifacts"');
assert.ok(section.includes('loop render-hooks execute:post'));
assert.ok(section.includes('msd-${ref.skill}'));
assert.ok(!section.includes('config-get workflow.code_review'));
});
test('quick full-mode code review resolves execute:post hooks instead of inlining code_review config', () => {
const content = workflow('quick.md');
// #2994 fragmentization moved Step 6.5 (Verification) out of quick.md into
// msd-core/workflows/quick/steps/quick-verification.md; the parent now marks
// that boundary with a `<!-- msd:section id="quick-verification" -->` comment
// immediately after Step 6.25's content, so it remains the correct
// end-of-step delimiter (mirrors the execute-phase.md gap-closure-artifacts
// pattern above) instead of bleeding to end-of-file.
const section = sectionBetween(content, '**Step 6.25: Code review (auto)**', '<!-- msd:section id="quick-verification"');
assert.ok(section.includes('loop render-hooks execute:post'));
assert.ok(section.includes('msd-code-reviewer'));
assert.ok(!section.includes('config-get workflow.code_review'));
});
test('code-review command self-gates via workflow.code_review config directly, not execute:post hooks (#3661: manual invocation must work regardless of which automatic point — execute:post or execute:wave:post — is configured)', () => {
const content = workflow('code-review.md');
const section = sectionBetween(content, '<step name="check_config_gate">', '<step name="resolve_depth">');
assert.ok(section.includes('msd_run query config-get workflow.code_review --raw'));
assert.ok(!section.includes('loop render-hooks execute:post'));
assert.ok(!section.includes('ref.skill == "code-review"'));
});
test('code-review-fix command self-gates through execute:post hooks', () => {
const content = workflow('code-review-fix.md');
const section = sectionBetween(content, '<step name="check_config_gate">', '<step name="check_review_exists">');
assert.ok(section.includes('loop render-hooks execute:post'));
assert.ok(section.includes('ref.skill == "code-review"'));
assert.ok(!section.includes('config-get workflow.code_review'));
});
test('verify-work resolves verify:post security hooks instead of inlining security_enforcement config', () => {
const content = workflow('verify-work.md');
const transitionStart = content.indexOf('If issues == 0:');
assert.ok(transitionStart !== -1, 'verify-work transition block must exist');
const section = content.slice(transitionStart, content.indexOf('</step>', transitionStart));
assert.ok(section.includes('loop render-hooks verify:post'));
assert.ok(section.includes('msd-${ref.skill}'));
assert.ok(!section.includes('config-get workflow.security_enforcement'));
});
test('plan-phase threat model gate resolves plan:pre security capability hooks', () => {
const content = workflow('plan-phase.md');
const section = sectionBetween(content, '## 5.55. Security Threat Model Gate', '## 5.6. UI Design Contract Gate');
assert.ok(section.includes('loop render-hooks plan:pre'));
assert.ok(section.includes('capId == "security"'));
assert.ok(!section.includes('config-get workflow.security_enforcement'));
});
test('secure-phase command self-gates through verify:post hooks', () => {
const content = workflow('secure-phase.md');
const initFence = ['```bash', 'AUDITOR_MODEL='].join('\n');
const section = sectionBetween(content, initFence, 'Display banner:');
assert.ok(section.includes('loop render-hooks verify:post'));
assert.ok(section.includes('ref.skill == "secure-phase"'));
assert.ok(!section.includes('config-get workflow.security_enforcement'));
});
test('validate-phase command self-gates through verify:post hooks', () => {
const content = workflow('validate-phase.md');
const initFence = ['```bash', 'AUDITOR_MODEL='].join('\n');
const section = sectionBetween(content, initFence, 'Display banner:');
assert.ok(section.includes('loop render-hooks verify:post'));
assert.ok(section.includes('ref.skill == "validate-phase"'));
assert.ok(!section.includes('config-get workflow.nyquist_validation'));
});
test('documentation covers migrated review and verification capability hooks', () => {
const content = doc('reference/review-verification-capabilities.md');
const manual = doc('how-to/develop-a-capability.md');
const index = doc('README.md');
for (const term of [
'`code-review`',
'`security`',
'`nyquist`',
'`execute:post`',
'`verify:post`',
'`ship:pre`',
'msd-tools loop render-hooks <point>',
]) {
assert.ok(content.includes(term), `capability reference must document ${term}`);
}
assert.ok(
index.includes('reference/review-verification-capabilities.md'),
'docs index must link the review and verification capabilities reference',
);
assert.ok(
manual.includes('`security` registers a `plan:pre` contribution, a `verify:post` step, and a blocking `ship:pre` gate.'),
'capability developer manual must mention review/verification hook examples',
);
});
});