Files
msd-core/docs/INVENTORY-MANIFEST.json
Tom Boucher d16a66479a feat(#1950): broken-windows ledger — cross-phase defect register gating ship (#2441)
* feat(#1950): broken-windows ledger — cross-phase defect register gating ship

Adds a new  capability (#1950) that operationalizes GSD's
no-defer discipline as a tracked, enforced artifact:
accumulates stubs, TODOs, skipped tests, unrun verifies, and unmet truths
across phases, and /gsd-ship blocks while any entry is open.

Implementation:
- src/broken-windows.cts → gsd-core/bin/lib/broken-windows.cjs: typed IR +
  I/O entry points (parseLedger/renderLedger/appendWindow/markWaived/markFixed
  + cmdWindowsStatus/Append/Waive/MarkFixed). Frozen REASON enum for typed
  error assertions. Windows-safe atomic rename with retry on transient
  EPERM/EBUSY/EACCES.
- gsd-tools.cjs: new  subcommand (status | append | waive | fixed),
  wired via routeWindows + HOST_COMMAND_ROUTERS.windows.
- capabilities/broken-windows/capability.json: one ship:pre gate with
  artifact-frontmatter-equals predicate on WINDOWS.md open_count == 0.
  activationKey windows.enabled (default true) + sibling windows.enforce
  (default true, separate so tracking can precede enforcement).
- gsd-core/workflows/ship.md: capId==broken-windows branch in preflight,
  sibling to security — reads gsd_run windows status --raw, fails closed
  on open_count > 0 or unreadable ledger.
- agents/gsd-executor.md: extends the existing ## Known Stubs instruction
  to also append to WINDOWS.md via gsd_run windows append (best-effort,
  never blocks execution).
- agents/gsd-verifier.md: new Step 8b — record unmet truths + human-verify
  items in WINDOWS.md.
- gsd-core/workflows/progress.md: surfaces open + waived counts.
- docs/COMMANDS.md + CONTEXT.md glossary entry + docs/INVENTORY.md:
  document the gate, waiver mechanism, and new module.
- tests/broken-windows.test.cjs: pure + CLI behavioral coverage + fast-check
  roundtrip property; fail-closed on malformed ledger; security boundary on
  path traversal in --file.

Backward-compatible: a project with no .planning/WINDOWS.md reports
open_count: 0 and ships cleanly. Disable enforcement per-project with
gsd config-set windows.enforce false (tracking continues, gate stays open).

* chore(#1950): ratchet size baselines, defer verifier integration

- Workflow size baseline: ship.md 25575→27928, progress.md 31789→32632
  (broken-windows preflight branch + open-windows surface).
- Agent size baseline: gsd-executor.md 46644→47951 (Known Stubs → also
  appends to WINDOWS.md). gsd-verifier.md unchanged.
- LARGE_CAP (49152) preempted the planned verifier integration
  (gsd-verifier.md was at 49140 pre-PR — 12 bytes of headroom, not the
  documented 'real headroom'). Verifier integration deferred to a follow-up
  PR that extracts the VERIFICATION.md template (lines 739-859) to
  gsd-core/references/ — a pre-existing cap-tightness defect this PR
  exposed but does not expand scope to fix. Verifier integration is not in
  the issue's acceptance criteria (executor writes is; unmet-truths
  recording was an enhancement, not a gate).

* fix(#1950): gate default-off, rename to workflow.windows_enforce, regen goldens

Test-failure-driven fixes after first gsd-test run on db8733c8f failed 44
cases (pre-existing structural tests encoded 'ship:pre has 1 gate' / 'all
caps off → empty hooks'):

- capability manifest: rename windows.enabled+windows.enforce (default
  true) → single federated key workflow.windows_enforce (default FALSE,
  opt-in). Matches security's workflow.security_enforce convention and
  makes the adr857 all-caps-off test pass without modification (the test's
  buildAllFalseConfig handles workflow.* out of the box). Default-OFF keeps
  the gate out of the registry's default ship:pre resolution so existing
  loop-hooks-ship-pre-e2e structural assertions (exactly 1 gate, capId
  'security') stay valid; users opt in via
  gsd config-set workflow.windows_enforce true.
- drop activationKey (security doesn't have one either; workflow.* key
  doubles as the activation toggle).
- regenerate docs/reference/capability-matrix.md to include broken-windows
  (capability-matrix-sync test).
- regenerate tests/fixtures/golden-install-parity/*.json (18 runtimes) —
  installer now emits the new capability + lib file.
- update CONTEXT.md, docs/COMMANDS.md, docs/FEATURES.md, ship.md,
  agents/gsd-executor.md to use the new key name and /gsd:colon slash
  syntax (slash-command-namespace test).
- restore accidentally-regressed /gsd:capture in progress.md.

Tracking-only by default; enforcement is opt-in. Acceptance criterion
'/gsd-ship fails while any ledger entry is open' is met when
workflow.windows_enforce=true (test fixture enables it).

* test(#1950): update ship:pre structural invariants for 2-gate registry

- loop-hooks-ship-pre-e2e: the registry now declares 2 gates at ship:pre
  (security + broken-windows), regardless of activation. Activation tests
  above still pin security-only or empty behavior via fixtures; these
  structural tests pin the REGISTRY shape, which has 2 gates as of #1950.
- workflow-size-baseline: ship.md 27928→27945 (workflow.windows_enforce
  rename added 17 bytes).

* fix(#1950): review H1+H2+M1+M2+M3 — fence-injection, EACCES fail-closed, cleanup, strict line, stryker

Adversarial isolated review (Step 6.3) found 2 HIGH findings that block
the PR and 3 mediums. All addressed:

H1 (HIGH): description containing the markdown 3-backtick fence would
terminate the ledger's JSON code block early inside JSON.stringify output
(JSON doesn't escape backticks), corrupting the file and bricking the
next parse. Fix: use a 4-backtick fence (json ... ) which
JSON.stringify cannot produce on its own, AND validate that no entry
text field contains a 4-backtick run (reject at append time with new
WINDOWS_INVALID_TEXT reason code). Locked by a regression test.

H2 (HIGH): readLedgerOrNull swallowed ALL fs errors as 'no ledger',
silently returning open_count:0 on EACCES/EPERM/EIO. The ship gate
would then pass on an unreadable ledger — the precise vector the
workflow doc claims is impossible. Fix: only ENOENT returns null;
every other fs error propagates as WINDOWS_LEDGER_MALFORMED so the
gate blocks and the operator sees a real diagnostic. Locked by a
regression test that chmod 000s a ledger with open_count=1 and
asserts the result is never a false-green 0.

M1: writeLedgerAtomic left an orphaned .tmp file on rename failure.
Wrapped renameWithRetry in try/catch with best-effort unlink.

M2: validateLine silently coerced 'abc' → NaN → null, hiding type
drift. Removed the line === 0 special case (was undocumented) and
made the error message match the strict check. Now any non-positive-
integer line value throws, including strings.

M3: tests/broken-windows.test.cjs (with its fast-check property test)
was not in stryker.config.mjs DEFAULT_TEST_CMD — Stryker would mutate
src/broken-windows.cts but no test would catch the mutations,
producing false surviving-mutant scores. Added to the list.

L1 (dead throw e after error()), L7 (line boundary tests, H1/H2
regression tests, 4-backtick CLI test) also addressed.

* docs(#1950): inline concurrency + busy-wait notes (review L2+L3)

* fix(#1950): regen goldens against latest gsd-tools; correct --line 0 boundary test

gsd-test v4 caught two issues:
- goldens I regenerated earlier (commit 526682084) predated the L1
  routeWindows catch-block cleanup (commit dd844d565). Regenerated
  via 'npm run gen:golden' against current HEAD so the install
  parity hash for gsd-tools.cjs matches.
- 'append --line boundary' test expected --line 0 to succeed with
  null entry.line, but the M2 fix correctly rejects 0 (lines are
  1-indexed; 0 is not a valid source line). Updated the boundary
  test to assert --line 0 fails alongside -1 and 'abc'.

* chore(#1950): regen goldens after rebase onto next

* chore(#1950): quick.md baseline 50699→50993 (correct resolution from next rebase)

* chore(changeset): backfill pr:2441 in .changeset/broken-windows-ledger.md

* fix(#1950): renderTable escapes backslash before pipe (CodeQL incomplete-sanitization)

CodeQL flagged the markdown-table cell escaper:
  String(s ?? '').replace(/\|/g, '\\|')
— it escapes pipe but not backslash first. A description containing '\|'
would render as '\\|' which markdown parses as 'literal backslash' +
'cell separator', splitting the column.

Fix: escape backslash FIRST (each \ → \\), then pipe (each | → \|).
Now a description with '\|' renders as '\\\\|' (literal '\\' + escaped
pipe), which markdown renders as a single '\|' inside the cell. The JSON
code block (the parse source-of-truth) was already correctly escaped via
JSON.stringify; only the display-only table was affected.

Locked by a regression test that:
1. Verifies the JSON block reparses with the description intact.
2. Walks the rendered table row counting unescaped pipes — must be
   exactly 11 (the row separators for 10 cells), proving no in-cell
   pipe added a split.
2026-07-19 20:24:21 -04:00

492 lines
13 KiB
JSON

{
"families": {
"agents": [
"gsd-advisor-researcher",
"gsd-ai-researcher",
"gsd-assumptions-analyzer",
"gsd-code-fixer",
"gsd-code-reviewer",
"gsd-codebase-mapper",
"gsd-debug-session-manager",
"gsd-debugger",
"gsd-doc-classifier",
"gsd-doc-synthesizer",
"gsd-doc-verifier",
"gsd-doc-writer",
"gsd-domain-researcher",
"gsd-eval-auditor",
"gsd-eval-planner",
"gsd-executor",
"gsd-framework-selector",
"gsd-integration-checker",
"gsd-intel-updater",
"gsd-mempalace-curator",
"gsd-nyquist-auditor",
"gsd-pattern-mapper",
"gsd-phase-researcher",
"gsd-plan-checker",
"gsd-planner",
"gsd-project-researcher",
"gsd-research-synthesizer",
"gsd-roadmapper",
"gsd-security-auditor",
"gsd-ui-auditor",
"gsd-ui-checker",
"gsd-ui-researcher",
"gsd-user-profiler",
"gsd-verifier"
],
"commands": [
"/gsd-add-tests",
"/gsd-ai-integration-phase",
"/gsd-audit-fix",
"/gsd-audit-milestone",
"/gsd-audit-uat",
"/gsd-autonomous",
"/gsd-capture",
"/gsd-cleanup",
"/gsd-code-review",
"/gsd-complete-milestone",
"/gsd-config",
"/gsd-debug",
"/gsd-discuss-phase",
"/gsd-docs-update",
"/gsd-eval-review",
"/gsd-execute-phase",
"/gsd-explore",
"/gsd-extract-learnings",
"/gsd-fast",
"/gsd-forensics",
"/gsd-graphify",
"/gsd-health",
"/gsd-help",
"/gsd-import",
"/gsd-inbox",
"/gsd-ingest-docs",
"/gsd-manager",
"/gsd-map-codebase",
"/gsd-mempalace-capture",
"/gsd-mempalace-recall",
"/gsd-milestone-summary",
"/gsd-mvp-phase",
"/gsd-new-milestone",
"/gsd-new-project",
"/gsd-next",
"/gsd-ns-context",
"/gsd-ns-ideate",
"/gsd-ns-manage",
"/gsd-ns-project",
"/gsd-ns-review",
"/gsd-ns-workflow",
"/gsd-onboard",
"/gsd-pause-work",
"/gsd-phase",
"/gsd-plan-phase",
"/gsd-plan-review-convergence",
"/gsd-pr-branch",
"/gsd-profile-user",
"/gsd-progress",
"/gsd-quick",
"/gsd-resume-work",
"/gsd-review",
"/gsd-review-backlog",
"/gsd-secure-phase",
"/gsd-settings",
"/gsd-ship",
"/gsd-sketch",
"/gsd-spec-phase",
"/gsd-spike",
"/gsd-stats",
"/gsd-surface",
"/gsd-thread",
"/gsd-ui-phase",
"/gsd-ui-review",
"/gsd-ultraplan-phase",
"/gsd-undo",
"/gsd-update",
"/gsd-validate-phase",
"/gsd-verify-work",
"/gsd-workspace",
"/gsd-workstreams"
],
"workflows": [
"add-backlog.md",
"add-phase.md",
"add-tests.md",
"add-todo.md",
"ai-integration-phase.md",
"analyze-dependencies.md",
"audit-fix.md",
"audit-milestone.md",
"audit-uat.md",
"autonomous.md",
"check-todos.md",
"cleanup.md",
"code-review-fix.md",
"code-review.md",
"complete-milestone.md",
"debug.md",
"diagnose-issues.md",
"discovery-phase.md",
"discuss-phase-assumptions.md",
"discuss-phase-power.md",
"discuss-phase.md",
"do.md",
"docs-update.md",
"edit-phase.md",
"eval-review.md",
"execute-phase.md",
"execute-plan.md",
"explore.md",
"extract-learnings.md",
"fast.md",
"forensics.md",
"graduation.md",
"health.md",
"help.md",
"import.md",
"inbox.md",
"ingest-docs.md",
"insert-phase.md",
"list-phase-assumptions.md",
"list-seeds.md",
"list-workspaces.md",
"manager.md",
"map-codebase.md",
"milestone-summary.md",
"mvp-phase.md",
"new-milestone.md",
"new-project.md",
"new-workspace.md",
"next.md",
"node-repair.md",
"note.md",
"onboard.md",
"pause-work.md",
"plan-milestone-gaps.md",
"plan-phase.md",
"plan-review-convergence.md",
"plant-seed.md",
"pr-branch.md",
"profile-user.md",
"progress.md",
"quick.md",
"reapply-patches.md",
"remove-phase.md",
"remove-workspace.md",
"resume-project.md",
"review.md",
"scan.md",
"secure-phase.md",
"session-report.md",
"settings-advanced.md",
"settings-integrations.md",
"settings.md",
"ship.md",
"sketch-wrap-up.md",
"sketch.md",
"smart-entry.md",
"spec-phase.md",
"spike-wrap-up.md",
"spike.md",
"stats.md",
"sync-skills.md",
"thread.md",
"transition.md",
"ui-phase.md",
"ui-review.md",
"ultraplan-phase.md",
"undo.md",
"update.md",
"validate-phase.md",
"verify-phase.md",
"verify-work.md"
],
"references": [
"agent-contracts.md",
"agent-skills-bootstrap.md",
"ai-evals.md",
"ai-frameworks.md",
"api-coverage.md",
"artifact-types.md",
"autonomous-smart-discuss.md",
"checkpoints.md",
"common-bug-patterns.md",
"context-budget.md",
"continuation-format.md",
"debugger-bug-taxonomy.md",
"debugger-fix-acceptance.md",
"debugger-philosophy.md",
"debugger-prevention.md",
"debugger-rca-branching.md",
"debugger-repro-hardening.md",
"debugger-sbfl.md",
"debugger-semantic-recall.md",
"decimal-phase-calculation.md",
"doc-conflict-engine.md",
"domain-probes.md",
"edge-probe.md",
"execute-mvp-tdd.md",
"execute-phase-between-wave-reset.md",
"execute-phase-context-guard.md",
"execute-phase-requirement-revert.md",
"execute-phase-wave-guard.md",
"executor-examples.md",
"gate-prompts.md",
"gates.md",
"git-integration.md",
"git-planning-commit.md",
"gsd-run-resolver.md",
"honest-verifier.md",
"ios-scaffold.md",
"loop-hook-dispatch.md",
"mandatory-initial-read.md",
"model-profile-resolution.md",
"model-profiles.md",
"mvp-concepts.md",
"phase-argument-parsing.md",
"planner-antipatterns.md",
"planner-chunked.md",
"planner-gap-closure.md",
"planner-graphify-auto-update.md",
"planner-guidance.md",
"planner-human-verify-mode.md",
"planner-interface-context.md",
"planner-load-graph-context.md",
"planner-mvp-mode.md",
"planner-preconditions.md",
"planner-reviews.md",
"planner-revision.md",
"planner-source-audit.md",
"planning-config.md",
"prohibition-probe.md",
"project-skills-discovery.md",
"questioning.md",
"research-documentation-lookup.md",
"research-philosophy.md",
"research-verification-protocol.md",
"reviewer-instances.md",
"revision-loop.md",
"scout-codebase.md",
"security-asvs-levels.md",
"skeleton-template.md",
"sketch-interactivity.md",
"sketch-theme-system.md",
"sketch-tooling.md",
"sketch-variant-patterns.md",
"specless-probe-fallback.md",
"spidr-splitting.md",
"tdd.md",
"thinking-models-debug.md",
"thinking-models-execution.md",
"thinking-models-planning.md",
"thinking-models-research.md",
"thinking-models-verification.md",
"thinking-partner.md",
"ui-brand.md",
"ui-consideration-probe.md",
"universal-anti-patterns.md",
"untrusted-input-boundary.md",
"user-profiling.md",
"user-story-template.md",
"verification-overrides.md",
"verification-patterns.md",
"verify-mvp-mode.md",
"workstream-flag.md",
"worktree-branch-check.md",
"worktree-path-safety.md"
],
"cli_modules": [
"active-workstream-store.cjs",
"adapter-declarative.cjs",
"adapter-imperative.cjs",
"adr-parser.cjs",
"agent-command-router.cjs",
"agent-install-check.cjs",
"api-coverage.cjs",
"artifacts.cjs",
"assumption-delta.cjs",
"audit-command-router.cjs",
"audit.cjs",
"broken-windows.cjs",
"capability-activation.cjs",
"capability-command-router.cjs",
"capability-consent.cjs",
"capability-ledger.cjs",
"capability-lifecycle.cjs",
"capability-loader.cjs",
"capability-lock.cjs",
"capability-registry.cjs",
"capability-source.cjs",
"capability-state.cjs",
"capability-trust.cjs",
"capability-validator.cjs",
"capability-writer.cjs",
"check-command-router.cjs",
"cjs-command-router-adapter.cjs",
"claude-orchestration-command-router.cjs",
"claude-orchestration.cjs",
"cli-exit.cjs",
"cli-skew-check.cjs",
"clock.cjs",
"clusters.cjs",
"code-review-flags.cjs",
"command-aliases.cjs",
"command-arg-projection.cjs",
"command-roster.cjs",
"command-routing-hub.cjs",
"commands.cjs",
"config-loader.cjs",
"config-schema.cjs",
"config-types.cjs",
"config.cjs",
"configuration.cjs",
"context-utilization.cjs",
"core-utils.cjs",
"coverage.cjs",
"decisions.cjs",
"docs.cjs",
"drift.cjs",
"edge-probe.cjs",
"embedding-adapter.cjs",
"eval-command-router.cjs",
"eval.cjs",
"external-descriptor-trust.cjs",
"external-job.cjs",
"fallow-runner.cjs",
"federated-config.cjs",
"frontmatter.cjs",
"gap-checker.cjs",
"gate-predicate-evaluator.cjs",
"git-base-branch.cjs",
"graphify-command-router.cjs",
"graphify.cjs",
"gsd2-import.cjs",
"handshake-serialized.cjs",
"hook-bus.cjs",
"host-integration-sdk.cjs",
"host-integration.cjs",
"init-command-router.cjs",
"init.cjs",
"install-effort-resolver.cjs",
"install-engine.cjs",
"install-profiles.cjs",
"installer-migration-authoring.cjs",
"installer-migration-report.cjs",
"installer-migrations.cjs",
"intel-command-router.cjs",
"intel.cjs",
"io.cjs",
"learnings.cjs",
"legacy-cleanup.cjs",
"loop-host-contract.cjs",
"loop-resolver.cjs",
"markdown-sectionizer.cjs",
"markdown-table.cjs",
"mcp-server.cjs",
"milestone.cjs",
"model-adapter.cjs",
"model-catalog.cjs",
"model-profiles.cjs",
"model-resolver.cjs",
"normalize-test-command.cjs",
"onboard-projection.cjs",
"package-identity.cjs",
"package-legitimacy.cjs",
"phase-command-router.cjs",
"phase-id.cjs",
"phase-lifecycle.cjs",
"phase-locator.cjs",
"phase.cjs",
"phases-command-router.cjs",
"plan-drift-guard.cjs",
"plan-scan.cjs",
"planning-workspace.cjs",
"probe-core.cjs",
"profile-output.cjs",
"profile-pipeline-command-router.cjs",
"profile-pipeline.cjs",
"prohibition-enforcement.cjs",
"project-root.cjs",
"prompt-budget.cjs",
"research-provider.cjs",
"research-store.cjs",
"resolution.cjs",
"review-reviewer-selection.cjs",
"roadmap-command-router.cjs",
"roadmap-parser.cjs",
"roadmap-upgrade.cjs",
"roadmap.cjs",
"runtime-artifact-conversion.cjs",
"runtime-artifact-install-plan.cjs",
"runtime-artifact-layout.cjs",
"runtime-config-adapter-registry.cjs",
"runtime-homes.cjs",
"runtime-hooks-surface.cjs",
"runtime-name-policy.cjs",
"runtime-slash.cjs",
"schema-detect.cjs",
"secrets.cjs",
"security.cjs",
"semver-compare.cjs",
"shell-command-projection.cjs",
"smart-entry.cjs",
"spec-section.cjs",
"stale-bake-guard.cjs",
"state-command-router.cjs",
"state-document.cjs",
"state-io.cjs",
"state-transition.cjs",
"state.cjs",
"surface.cjs",
"task-command-router.cjs",
"teams-status.cjs",
"template.cjs",
"uat-predicate.cjs",
"uat.cjs",
"ui-consideration-probe.cjs",
"ui-safety-gate.cjs",
"update-context.cjs",
"validate-command-router.cjs",
"validate.cjs",
"verification-command-router.cjs",
"verification.cjs",
"verify-command-router.cjs",
"verify.cjs",
"workstream-inventory-builder.cjs",
"workstream-inventory.cjs",
"workstream-name-policy.cjs",
"workstream.cjs",
"worktree-base-ref.cjs",
"worktree-safety.cjs",
"write-set.cjs"
],
"hooks": [
"gsd-check-update-worker.js",
"gsd-check-update.js",
"gsd-config-reload.js",
"gsd-context-monitor.js",
"gsd-cursor-post-tool.js",
"gsd-cursor-pre-tool.js",
"gsd-cursor-session-start.js",
"gsd-cursor-stop.js",
"gsd-cursor-subagent-start.js",
"gsd-cursor-subagent-stop.js",
"gsd-ensure-canonical-path.js",
"gsd-graphify-update.sh",
"gsd-phase-boundary.sh",
"gsd-prompt-guard.js",
"gsd-read-guard.js",
"gsd-read-injection-scanner.js",
"gsd-session-state.sh",
"gsd-statusline.js",
"gsd-update-banner.js",
"gsd-validate-commit.sh",
"gsd-windsurf-pre-command.js",
"gsd-windsurf-pre-write.js",
"gsd-workflow-guard.js",
"gsd-worktree-path-guard.js"
]
}
}