* feat(spec-phase): spec-completeness edge-probe (#550) — relocated to gsd-core/
Rebased onto current next and relocated the whole feature from get-shit-done/ to
gsd-core/ per #615 (trek-e re-review #4, option 1). The artifact now builds to
gsd-core/bin/lib/edge-probe.cjs; all hard-coded path strings (tests, workflow
@-refs, run-tests.cjs sentinel, eslint ADR-457 ignore, .gitignore) updated.
Content conflicts in .gitignore / eslint.config.mjs / run-tests.cjs resolved.
Feature: Step 5.5 edge-completeness probe walks each SPEC requirement against a
closed 8-category edge taxonomy, proposes applicable candidate edges, and resolves
each (covered/dismissed/backstop/unresolved). covered/backstop criteria are lifted
by plan-phase into must_haves.truths, extending the goal-backward verifier's reach
to boundary edges no requirement was written for. Engine authored as strict TS
(src/edge-probe.cts, ADR-457), compiled to the gitignored gsd-core/bin/lib/edge-probe.cjs.
Folds in every prior review round on PR #584:
- RR-01..03: plan-phase resolves the phase *-SPEC.md and injects {SPEC_PATH} into the
planner; must_haves<->Edge-Coverage quality_gate; held-out planner-contract test.
- RR-04/11: Step 5.5 invokes the compiled engine at runtime (npm --prefix-pinned,
source-checkout-gated build fallback) instead of LLM re-derivation; the engine
capture is exit-checked and the report JSON-validated before use (fail closed).
- RR-05..10: all six fixtures embedded + count-equality; backstop/covered require a
resolution; Array.isArray(shapes); duplicate-resolution rejection; CLI JSON exit(2);
per-artifact build sentinel.
- Authored-shape validation: invalid (non-empty) shapes fail closed (VALID_SHAPES).
- Adversarial-review hardening: orphan/typo resolution rejection, requirement input
validation (id/text/shapes, duplicate id, non-array), zero-applicable guard.
Full suite 0 failures; npm run lint 0 errors; edge-probe suite 72/72.
* test(#550): RED — status×verification re-cut + probe-core engine specs
Re-cut the edge-probe resolution model onto two orthogonal axes per
ADR-550 Decision 7 (trek-e #644 comments 2026-06-03 14:36 + 14:44):
status: resolved | dismissed | unresolved (lifecycle, shared)
verification: explicit | backstop | null (only when resolved)
- tests/probe-core.test.cjs (new): behavioral specs for the generic engine
to be extracted — validateResolution(r, validators), validateRequirement,
analyzeCoverage(items, resolutions?, validators), byVerification rollup,
runProbeCli I/O scaffold (injected-io unit tests).
- tests/edge-probe.test.cjs: covered→{resolved,explicit}, backstop→
{resolved,backstop}; coverage gains byVerification.{explicit,backstop};
proposeEdges items gain verification:null.
- 6 fixtures re-genned + re-embedded in edge-probe.md; coverage.resolved
COUNT preserved on every fixture (closed set = resolved+dismissed; doc
line: 'adjacency=covered + ordering=dismissed' -> 2). edge-probe.md prose
rewritten to the two-axis model.
Fails as expected: probe-core.cjs has no source yet; edge-probe still
emits the old covered/backstop enum (27/61 edge specs red).
* feat(#550): extract probe-core seam + refactor edge-probe onto it (ADR-550 D7)
Extract the generic resolution model into src/probe-core.cts (the shared
seam the prohibition probe #644 is born on) and refactor edge-probe.cts
into its first adapter.
probe-core owns (probe-agnostic):
- the status×verification re-cut: status: resolved|dismissed|unresolved ×
verification: <probe-defined>|null
- validateResolution(r, validators) / validateRequirement (generic id+text)
- analyzeCoverage(items, resolutions?, validators) over ALREADY-PROPOSED
items[] (core never assumes propose is deterministic — edge resolves via
LLM, #644 proposes via LLM), with merge / dup-reject / orphan-reject
- byVerification rollup; coverage.resolved = closed set (resolved+dismissed),
count-preserved from the pre-re-cut engine
- runProbeCli I/O scaffold (injected io; one bin per probe)
- hybrid typing: generic params + injected runtime validators
{categories, verification, requiredFieldsByVerification} (ADR-550 #5)
edge-probe keeps ONLY the edge cluster: Shape/SHAPE_CUES/VALID_SHAPES/
classifyShape/TAXONOMY/applicableCategories/proposeEdges + EDGE_VALIDATORS
{explicit,backstop}; delegates merge/rollup/CLI to probe-core. Every shipped
#584 guarantee preserved (fail-closed shapes, orphan/dup rejection, input
validation, CLI exit 2). 104/104 edge+probe-core+docs+contract specs green.
* chore(#550): register probe-core.cjs artifact in ledgers + inventory
New gitignored build artifact gsd-core/bin/lib/probe-core.cjs (compiled
from src/probe-core.cts) needs registering in every artifact ledger:
- .gitignore + eslint.config.mjs ADR-457 ignore: lint the .cts source,
never the emitted .cjs.
- scripts/run-tests.cjs per-artifact build sentinel: build if probe-core.cjs
is missing on a clean checkout.
- docs/INVENTORY.md: CLI Modules 83 -> 84, new probe-core.cjs row, and the
edge-probe.cjs row updated to reflect it is now the first probe-core adapter.
- docs/INVENTORY-MANIFEST.json: regenerated (gen-inventory-manifest.cjs --write).
probe-core.test.cjs is a single test file (under the 2-file cap), so no
lint-test-file-count allowlist entry is needed.
* docs(adr-550): spec-phase probe pattern + prohibition contract [Accepted]
trek-e's final ADR-550 body, verbatim (open-gsd/gsd-core#644 comment
2026-06-03T15:23Z), Accepted by both maintainer and #550 author. Lands on
PR #584 alongside the probe-core extraction (Decision 7) it governs, so the
contract and its first implementation arrive together.
Decisions: probe packaging (3 layers); recall->precision protocol;
prohibition home = SPEC acceptance criteria + optional must_haves.prohibitions:
(truths untouched, no polarity); tiered verification test|judgment
(judgment = mode-dependent soft-gate-with-flags, never silent pass / never
hard-halt); CI tests the contract not the classifier; secure-phase ownership
seam; and Decision 7 — probe-core seam + status×verification re-cut (7a-7e),
which this PR implements.
* feat(#550): fail-closed probe-core across full status×verification + runProbeCli structural guard
Re-review #5 (trek-e) seam-hardening on the generic probe-core contract #644 inherits:
- validateResolution now enforces the 'verification is null unless resolved'
invariant for EVERY status (not just resolved): a dismissed/unresolved
resolution carrying a verification tier is rejected instead of merging verbatim.
- An unresolved resolution carrying a resolution/reason payload is rejected
(was silently dropped into the unresolved count).
- runProbeCli structurally validates the report an adapter returns before writing
it (was: any malformed object stringified as green output) — fails closed → exit 2.
- coverage.resolved kept count-preserved (closed set) per the blessed migration
contract; a new test locks that an all-dismissed run is NOT affirmatively covered
(byVerification is the honest gate).
Tests: probe-core 37/37; full edge-probe suite 113/113; full suite 1816/1816; lint 0.
* docs(adr-550): annotate Decision 5 #584/#644 scope + correct 7a coverage.resolved semantics
Re-review #5 (trek-e) clarity edits:
- Decision 5: annotate that only contract item (a) ships on #584 (the edge
adapter's parse+validate test); (b)–(d) are #644 scope, matching Consequences.
- Decision 7a: correct the 'coverage.resolved is preserved (status === resolved)'
parenthetical — the blessed/implemented semantics are count-preserved = the
CLOSED set (resolved + dismissed = applicable − unresolved), with byVerification
carrying the per-tier resolved-status breakdown. The old parenthetical
contradicted the shipped count.
* test(#550): cover runProbeCli structural-guard numeric-count branch
Second-pass coverage audit found the 'coverage object present but counts
non-numeric' branch of isValidReport (built probe-core.cjs:60-61) unexercised —
the {nope:true} malformed test fails earlier at the items[] check. Add a report
with well-formed items[] + a coverage object carrying non-numeric counts so the
numeric branch is hit. No source change; closes the line gap.
* fix(#550): reject edge requirement with missing/empty text when no shapes override (M2)
The edge adapter's `text` is the classification signal and a required field, but
core `validateRequirement` left it optional, so a `{ id }` requirement classified to
zero shapes -> zero edges -> was silently DROPPED from coverage with no signal -- the
exact fail-open this feature exists to eliminate. Reject missing/empty text unless an
authored `shapes` override (incl. `[]`) opts out of prose classification.
* fix(#550): validate verbatim items in analyzeCoverage shared seam (m1)
A proposed item with no matching author resolution is rolled up VERBATIM, but its own
status/fields were never validated -- an item carrying an out-of-enum status (the dropped
"covered") or `dismissed` without a reason would be counted closed. The edge adapter only
proposes `unresolved` items, but the prohibition adapter (#644) proposes LLM-generated
items that arrive populated. An Item is structurally a superset of a Resolution, so reuse
validateResolution to fail closed. ADR-550 Decision 5 hardens this shared seam.
* fix(#550): move edge-coverage lift instruction to runtime planner surface (M1)
templates/planner-subagent-prompt.md is loaded by nothing at runtime (no @-import in
agents/gsd-planner.md; plan-phase.md spawns the planner from its own inline
<planning_context>), so the precise covered/backstop -> must_haves.truths lift instruction
this PR added there never reached the planner -- and the RR-02 contract test asserted it in
that dead file, giving false green. Move the instruction into plan-phase.md's runtime
<downstream_consumer> block (where the rest of the wire already lives), revert the dead-template
edit, and retarget RR-02 to the loaded surface with a guard against re-orphaning.
* test(#550): lock machine<->SPEC vocabulary mapping against drift (m2)
The machine contract uses orthogonal status x verification; the SPEC table renders a flat
covered/dismissed/backstop/unresolved. The migration map (ADR-550 Decision 7a) was prose-only
with no test, so the layers could silently drift. The SPEC table is LLM-rendered (no JS
renderer to round-trip), so pin the canonical bijection as code AND ground it in every doc
surface that renders the vocabulary (ADR migration clause, spec.md legend, reference mapping
table) -- a rename or remap now fails the suite.
* docs(#550): add how-to for resolving edge-coverage findings (B1)
Feature shipped reference coverage (FEATURES.md, COMMANDS.md, references/edge-probe.md) but
no how-to -- reference-only does not satisfy the Diataxis docs standard for a user-facing
capability. Add a single-mode how-to (imperative, goal-directed) walking each resolution
state (specify/dismiss/backstop/defer), the soft gate, and --auto, with taxonomy/concepts
linked out to the reference. Register it in the docs/how-to index.
* docs(#550): add Probe Core + Edge Probe glossary entries to CONTEXT.md (N1)
trek-e re-review #7 N1 (Major): adding probe-core/edge-probe as src/*.cts-derived
seam modules (ADR-550 Decision 7) requires CONTEXT.md Domain-terms glossary entries
per the maintainer-enforced new-seam gate. Adds '### Probe Core Module' and
'### Edge Probe Module' with exports, generated source paths, and the ADR-550 seam
contract, placed beside the Research Module feature-seam entries.
* test(#550): add fast-check property suite for probe-core analyzeCoverage (N2)
trek-e re-review #7 N2 (RULESET.TESTS.property-based-testing): analyzeCoverage is a
transformation/rollup module, the class the property-testing predicate covers, and
fast-check is already a dependency with an established *.property.test.cjs pattern.
Adds 5 properties over the algebraic invariants: closed-set identity
(applicable === resolved + unresolved), byVerification sums ≤ resolved, per-tier
recount + resolved-status-only counting, rollup determinism, and stable orphan
rejection. 200 runs/seed 42 via helpers/fast-check-setup.cjs.
* test(#550): align allow-test-rule tokens to canonical runtime-contract-is-the-product (N3)
trek-e re-review #7 N3 (Nit): the // allow-test-rule: tokens (source-text-is-the-product,
docs-parity) differed from CONTEXT.md's canonical exemption category
'runtime-contract-is-the-product' (RULESET.TESTS.no-source-grep.exemption, CONTEXT.md:240).
All three tests assert deployed runtime-contract surfaces (spec-phase.md Step 5.5, the
plan-phase.md planner prompt, the rendered reference/SPEC/ADR vocabulary), so the canonical
category fits; each now carries a one-line justification per the ruleset format. Free-text
reason — lint behavior unchanged.
* test(#550): re-baseline plan-phase + spec-phase byte sizes for edge-probe
Rebased onto next (e4f0910d), which replaced the line-based tier-max
size ratchet (#597) with the byte-based per-file baseline guard (#1074).
The edge-probe feature legitimately grows two workflows:
- spec-phase.md 15131 -> 23094 (+7963): Step 5.5 Edge-Completeness Probe
- plan-phase.md 93135 -> 94253 (+1118): covered/backstop edge lift into
must_haves.truths (the live <downstream_consumer> block)
Both remain under their tier hard caps (plan-phase XL 98304, ~4KB
headroom; spec-phase DEFAULT 40960). Growth is real inline workflow
content the feature requires at that step — not eager @-import proxy
gaming. Drops the obsolete line-based XL_BUDGET 93000->94000 bump
(superseded by the byte baseline) via rebase.
* chore(#550): reconcile INVENTORY headline counts after rebase onto next
Rebase onto current next dropped the prior reconcile commit (stale counts
refs 68 / CLI 107). Current next + the edge-probe additions yield:
- References (68 -> 69 shipped): + gsd-core/references/edge-probe.md
- CLI Modules (107 -> 109 shipped): + edge-probe.cjs + probe-core.cjs
Rows for all three already present; only the headline counts were stale.
Caught by tests/inventory-counts.test.cjs (CI ubuntu-24 leg).
336 lines
18 KiB
JavaScript
336 lines
18 KiB
JavaScript
/**
|
||
* probe-core reference-model unit tests (ADR-550 Decision 7).
|
||
*
|
||
* probe-core is the GENERIC spec-phase probe resolution model extracted from the
|
||
* edge-probe (the first adapter): the resolution lifecycle, the two-axis
|
||
* status×verification re-cut, `validateResolution`/`validateRequirement`, the
|
||
* `analyzeCoverage(items, resolutions?, validators)` merge/rollup/orphan-reject
|
||
* engine, the `byVerification` rollup, and the `runProbeCli` I/O scaffold.
|
||
*
|
||
* Asserts the LOCKED export surface against the BUILT artifact
|
||
* (`gsd-core/bin/lib/probe-core.cjs`), which `npm run build:lib` (run by pretest /
|
||
* the run-tests sentinel) emits from `src/probe-core.cts`.
|
||
*
|
||
* The injected runtime validators are the enforcement contract (ADR-550 #5): the
|
||
* CLI runs over JSON where TS types are erased, so `analyzeCoverage` is told its
|
||
* probe's closed vocabularies — `{ categories, verification, requiredFieldsByVerification }`
|
||
* — rather than relying on the type system. These tests pin the validators' behavior.
|
||
*/
|
||
'use strict';
|
||
process.env.GSD_TEST_MODE = '1';
|
||
|
||
const { test, describe } = require('node:test');
|
||
const assert = require('node:assert/strict');
|
||
const path = require('node:path');
|
||
|
||
const BUILT_SCRIPT = path.join(__dirname, '..', 'gsd-core', 'bin', 'lib', 'probe-core.cjs');
|
||
const pc = require(BUILT_SCRIPT);
|
||
|
||
// A representative validators bundle — the shape the edge adapter injects, used here
|
||
// to exercise the generic engine independent of any one probe.
|
||
const VALIDATORS = {
|
||
categories: ['adjacency', 'empty', 'ordering'],
|
||
verification: ['explicit', 'backstop'],
|
||
requiredFieldsByVerification: { explicit: ['resolution'], backstop: ['resolution'] },
|
||
};
|
||
|
||
function item(category, overrides = {}) {
|
||
return {
|
||
requirement_id: 'R1',
|
||
category,
|
||
status: 'unresolved',
|
||
verification: null,
|
||
resolution: null,
|
||
reason: null,
|
||
probe: `probe-for-${category}`,
|
||
...overrides,
|
||
};
|
||
}
|
||
|
||
const UNRESOLVED_ITEMS = [item('adjacency'), item('empty'), item('ordering')];
|
||
|
||
describe('probe-core: VALID_STATUS is the re-cut lifecycle enum', () => {
|
||
test('exposes exactly resolved | dismissed | unresolved (no covered/backstop)', () => {
|
||
assert.deepEqual([...ep_sorted(pc.VALID_STATUS)], ['dismissed', 'resolved', 'unresolved']);
|
||
assert.ok(!pc.VALID_STATUS.includes('covered'), 'covered must not survive the re-cut as a status');
|
||
assert.ok(!pc.VALID_STATUS.includes('backstop'), 'backstop must not survive the re-cut as a status');
|
||
});
|
||
});
|
||
|
||
function ep_sorted(arr) {
|
||
return [...arr].sort();
|
||
}
|
||
|
||
describe('probe-core: validateResolution (status×verification)', () => {
|
||
const v = (r) => pc.validateResolution(r, VALIDATORS);
|
||
test('rejects an unknown status', () => {
|
||
assert.throws(() => v({ requirement_id: 'R1', category: 'adjacency', status: 'maybe' }), /invalid status/i);
|
||
});
|
||
test('rejects a former covered status (re-cut: no longer a valid status)', () => {
|
||
assert.throws(() => v({ requirement_id: 'R1', category: 'adjacency', status: 'covered', resolution: 'x' }), /invalid status/i);
|
||
});
|
||
test('rejects dismissed without a reason', () => {
|
||
assert.throws(() => v({ requirement_id: 'R1', category: 'adjacency', status: 'dismissed', reason: '' }), /dismissed requires a reason/i);
|
||
});
|
||
test('accepts dismissed with a reason', () => {
|
||
assert.equal(v({ requirement_id: 'R1', category: 'adjacency', status: 'dismissed', reason: 'bounded enum' }), true);
|
||
});
|
||
test('rejects resolved with a missing verification tier', () => {
|
||
assert.throws(() => v({ requirement_id: 'R1', category: 'adjacency', status: 'resolved', resolution: 'AC' }), /verification/i);
|
||
});
|
||
test('rejects resolved with an unknown verification tier', () => {
|
||
assert.throws(() => v({ requirement_id: 'R1', category: 'adjacency', status: 'resolved', verification: 'judgment', resolution: 'AC' }), /invalid verification/i);
|
||
});
|
||
test('rejects resolved/explicit with empty resolution text', () => {
|
||
assert.throws(() => v({ requirement_id: 'R1', category: 'adjacency', status: 'resolved', verification: 'explicit', resolution: ' ' }), /explicit requires a resolution/i);
|
||
});
|
||
test('rejects resolved/backstop with missing resolution note', () => {
|
||
assert.throws(() => v({ requirement_id: 'R1', category: 'adjacency', status: 'resolved', verification: 'backstop' }), /backstop requires a resolution/i);
|
||
});
|
||
test('accepts resolved/explicit with a resolution', () => {
|
||
assert.equal(v({ requirement_id: 'R1', category: 'adjacency', status: 'resolved', verification: 'explicit', resolution: 'AC#6' }), true);
|
||
});
|
||
test('accepts resolved/backstop with a resolution note', () => {
|
||
assert.equal(v({ requirement_id: 'R1', category: 'adjacency', status: 'resolved', verification: 'backstop', resolution: 'held-out PBT suite' }), true);
|
||
});
|
||
// Re-review #5 Medium — fail closed across the FULL status×verification model, not just
|
||
// `resolved`. The invariant (probe-core header): verification is null unless status is
|
||
// resolved. A dismissed/unresolved resolution carrying a tier otherwise merges verbatim
|
||
// (analyzeCoverage line ~189), breaking the model for the second adapter (#644) that
|
||
// inherits this seam.
|
||
test('rejects a dismissed resolution carrying a verification tier (null unless resolved)', () => {
|
||
assert.throws(() => v({ requirement_id: 'R1', category: 'adjacency', status: 'dismissed', reason: 'n/a', verification: 'explicit' }), /verification must be null/i);
|
||
});
|
||
test('rejects an unresolved resolution carrying a verification tier', () => {
|
||
assert.throws(() => v({ requirement_id: 'R1', category: 'adjacency', status: 'unresolved', verification: 'backstop' }), /verification must be null/i);
|
||
});
|
||
// An unresolved resolution is an UNACTED item — a populated resolution/reason payload is an
|
||
// authoring mistake (the author meant resolved/dismissed) that today is silently dropped into
|
||
// the unresolved count with no error pointing at it. Reject the payload.
|
||
test('rejects an unresolved resolution carrying a resolution payload', () => {
|
||
assert.throws(() => v({ requirement_id: 'R1', category: 'adjacency', status: 'unresolved', resolution: 'AC#1' }), /unresolved must not carry/i);
|
||
});
|
||
test('rejects an unresolved resolution carrying a reason payload', () => {
|
||
assert.throws(() => v({ requirement_id: 'R1', category: 'adjacency', status: 'unresolved', reason: 'because' }), /unresolved must not carry/i);
|
||
});
|
||
test('accepts a bare unresolved resolution (no payload — a harmless no-op merge)', () => {
|
||
assert.equal(v({ requirement_id: 'R1', category: 'adjacency', status: 'unresolved' }), true);
|
||
});
|
||
});
|
||
|
||
describe('probe-core: validateRequirement (generic id/text only)', () => {
|
||
test('rejects a missing id', () => {
|
||
assert.throws(() => pc.validateRequirement({ text: 'x' }), /requirement id must be a non-empty string/i);
|
||
});
|
||
test('rejects an empty id', () => {
|
||
assert.throws(() => pc.validateRequirement({ id: ' ', text: 'x' }), /requirement id must be a non-empty string/i);
|
||
});
|
||
test('rejects a non-string text', () => {
|
||
assert.throws(() => pc.validateRequirement({ id: 'R1', text: 42 }), /text must be a string/i);
|
||
});
|
||
test('accepts a valid requirement', () => {
|
||
assert.doesNotThrow(() => pc.validateRequirement({ id: 'R1', text: 'a testable statement' }));
|
||
});
|
||
});
|
||
|
||
describe('probe-core: analyzeCoverage (merge · rollup · byVerification)', () => {
|
||
test('no resolutions → every item unresolved; resolved 0; byVerification zeroed per tier', () => {
|
||
const rep = pc.analyzeCoverage(UNRESOLVED_ITEMS, [], VALIDATORS);
|
||
assert.deepEqual(rep.coverage, {
|
||
applicable: 3, resolved: 0, unresolved: 3, byVerification: { explicit: 0, backstop: 0 },
|
||
});
|
||
});
|
||
test('merges a resolved/explicit resolution and counts byVerification.explicit', () => {
|
||
const rep = pc.analyzeCoverage(UNRESOLVED_ITEMS, [
|
||
{ requirement_id: 'R1', category: 'adjacency', status: 'resolved', verification: 'explicit', resolution: 'AC#6: touching intervals merge' },
|
||
], VALIDATORS);
|
||
const adj = rep.items.find((i) => i.category === 'adjacency');
|
||
assert.equal(adj.status, 'resolved');
|
||
assert.equal(adj.verification, 'explicit');
|
||
assert.equal(adj.resolution, 'AC#6: touching intervals merge');
|
||
assert.equal(rep.coverage.resolved, 1);
|
||
assert.equal(rep.coverage.unresolved, 2);
|
||
assert.deepEqual(rep.coverage.byVerification, { explicit: 1, backstop: 0 });
|
||
});
|
||
test('a dismissed item counts toward coverage.resolved (closed set) but NOT byVerification', () => {
|
||
// coverage.resolved preserves the pre-re-cut "closed" semantic = applicable - unresolved
|
||
// (covered + dismissed + backstop), per edge-probe.md and the migration contract.
|
||
const rep = pc.analyzeCoverage(UNRESOLVED_ITEMS, [
|
||
{ requirement_id: 'R1', category: 'ordering', status: 'dismissed', reason: 'canonically sorted; no tie' },
|
||
], VALIDATORS);
|
||
assert.equal(rep.coverage.resolved, 1);
|
||
assert.equal(rep.coverage.unresolved, 2);
|
||
assert.deepEqual(rep.coverage.byVerification, { explicit: 0, backstop: 0 });
|
||
const ord = rep.items.find((i) => i.category === 'ordering');
|
||
assert.equal(ord.status, 'dismissed');
|
||
assert.equal(ord.verification, null);
|
||
assert.equal(ord.reason, 'canonically sorted; no tie');
|
||
});
|
||
test('mixed resolved/explicit + backstop + dismissed: resolved = closed = applicable - unresolved', () => {
|
||
const rep = pc.analyzeCoverage(UNRESOLVED_ITEMS, [
|
||
{ requirement_id: 'R1', category: 'adjacency', status: 'resolved', verification: 'explicit', resolution: 'AC#6' },
|
||
{ requirement_id: 'R1', category: 'empty', status: 'resolved', verification: 'backstop', resolution: 'held-out empty-input PBT' },
|
||
{ requirement_id: 'R1', category: 'ordering', status: 'dismissed', reason: 'canonically sorted' },
|
||
], VALIDATORS);
|
||
assert.equal(rep.coverage.applicable, 3);
|
||
assert.equal(rep.coverage.unresolved, 0);
|
||
assert.equal(rep.coverage.resolved, 3); // 2 resolved-status + 1 dismissed
|
||
assert.deepEqual(rep.coverage.byVerification, { explicit: 1, backstop: 1 });
|
||
});
|
||
test('an all-dismissed run is CLOSED but NOT affirmatively covered (byVerification is the honest gate)', () => {
|
||
// Re-review #5 Medium — coverage.resolved is the closed set (resolved + dismissed), kept
|
||
// count-preserved per the blessed migration contract. So an all-dismissed spec has
|
||
// resolved === applicable while NOTHING was affirmatively resolved/backstopped. A CI gate
|
||
// keying on `resolved === applicable` would read green here; the honest signal is
|
||
// byVerification (all tiers zero). This test locks that distinction.
|
||
const rep = pc.analyzeCoverage(UNRESOLVED_ITEMS, [
|
||
{ requirement_id: 'R1', category: 'adjacency', status: 'dismissed', reason: 'bounded enum' },
|
||
{ requirement_id: 'R1', category: 'empty', status: 'dismissed', reason: 'guaranteed non-empty' },
|
||
{ requirement_id: 'R1', category: 'ordering', status: 'dismissed', reason: 'canonically sorted' },
|
||
], VALIDATORS);
|
||
assert.equal(rep.coverage.unresolved, 0);
|
||
assert.equal(rep.coverage.resolved, 3); // closed set counts the dismissals
|
||
assert.deepEqual(rep.coverage.byVerification, { explicit: 0, backstop: 0 }); // nothing affirmatively verified
|
||
});
|
||
test('rejects a duplicate (requirement_id, category) resolution', () => {
|
||
assert.throws(() => pc.analyzeCoverage(UNRESOLVED_ITEMS, [
|
||
{ requirement_id: 'R1', category: 'adjacency', status: 'resolved', verification: 'explicit', resolution: 'AC#1' },
|
||
{ requirement_id: 'R1', category: 'adjacency', status: 'resolved', verification: 'explicit', resolution: 'AC#2' },
|
||
], VALIDATORS), /duplicate resolution/i);
|
||
});
|
||
test('rejects an orphan resolution (no matching proposed item)', () => {
|
||
assert.throws(() => pc.analyzeCoverage(UNRESOLVED_ITEMS, [
|
||
{ requirement_id: 'R1', category: 'boundary', status: 'resolved', verification: 'explicit', resolution: 'AC' },
|
||
], VALIDATORS), /unknown resolution|no matching proposed/i);
|
||
});
|
||
test('propagates an invalid-resolution throw from validateResolution', () => {
|
||
assert.throws(() => pc.analyzeCoverage(UNRESOLVED_ITEMS, [
|
||
{ requirement_id: 'R1', category: 'empty', status: 'dismissed' },
|
||
], VALIDATORS), /dismissed requires a reason/i);
|
||
});
|
||
test('rejects items that is not an array', () => {
|
||
assert.throws(() => pc.analyzeCoverage('nope', [], VALIDATORS), /items must be an array/i);
|
||
});
|
||
test('rejects a proposed item whose category is not in validators.categories', () => {
|
||
// Adapter self-consistency: an item carrying a category outside the probe's closed
|
||
// vocabulary is an adapter bug, caught here rather than silently rolled up.
|
||
assert.throws(() => pc.analyzeCoverage([item('bogus-category')], [], VALIDATORS), /unknown category/i);
|
||
});
|
||
|
||
// m1: a verbatim item (no matching author resolution) is rolled up as-is, so its OWN
|
||
// status/fields must also be validated. The edge adapter only proposes `unresolved` items, but
|
||
// the prohibition adapter (#644) proposes LLM-generated items that arrive already populated —
|
||
// an out-of-enum status or a `dismissed` with no reason must fail closed, not count as closed.
|
||
test('m1: rejects a verbatim item carrying an out-of-enum status (e.g. the dropped "covered")', () => {
|
||
assert.throws(
|
||
() => pc.analyzeCoverage([item('adjacency', { status: 'covered' })], [], VALIDATORS),
|
||
/invalid status/i,
|
||
);
|
||
});
|
||
test('m1: rejects a verbatim item dismissed without a reason', () => {
|
||
assert.throws(
|
||
() => pc.analyzeCoverage([item('adjacency', { status: 'dismissed' })], [], VALIDATORS),
|
||
/dismissed requires a reason/i,
|
||
);
|
||
});
|
||
test('m1: rejects a verbatim resolved item missing its verification tier', () => {
|
||
assert.throws(
|
||
() => pc.analyzeCoverage([item('adjacency', { status: 'resolved', resolution: 'AC' })], [], VALIDATORS),
|
||
/requires a verification tier/i,
|
||
);
|
||
});
|
||
test('m1: a matching resolution still governs — item validation targets VERBATIM items only', () => {
|
||
// When a resolution matches, the item is rebuilt from the (already-validated) resolution, so a
|
||
// pre-populated item status is irrelevant and must NOT cause a throw. Guards against the m1
|
||
// fix over-reaching into the merge path.
|
||
const rep = pc.analyzeCoverage([item('adjacency', { status: 'covered' })], [
|
||
{ requirement_id: 'R1', category: 'adjacency', status: 'resolved', verification: 'explicit', resolution: 'AC#6' },
|
||
], VALIDATORS);
|
||
const adj = rep.items.find((i) => i.category === 'adjacency');
|
||
assert.equal(adj.status, 'resolved');
|
||
assert.equal(adj.verification, 'explicit');
|
||
assert.equal(rep.coverage.resolved, 1);
|
||
});
|
||
});
|
||
|
||
describe('probe-core: runProbeCli (generic I/O scaffold, injected io)', () => {
|
||
const report = { items: [], coverage: { applicable: 0, resolved: 0, unresolved: 0, byVerification: {} } };
|
||
test('no requirements path → writes usage to stderr and exits 2', () => {
|
||
let code; let err = '';
|
||
pc.runProbeCli(() => report, {
|
||
usage: 'demo-probe.cjs <requirements.json> [resolutions.json]',
|
||
argv: ['node', 'demo'], writeErr: (s) => { err += s; }, exit: (c) => { code = c; },
|
||
});
|
||
assert.equal(code, 2);
|
||
assert.match(err, /usage: demo-probe\.cjs/);
|
||
});
|
||
test('valid requirements path → calls analyze and prints the report as JSON', () => {
|
||
let out = '';
|
||
pc.runProbeCli((reqs, res) => {
|
||
assert.deepEqual(reqs, [{ id: 'R1', text: 'x' }]);
|
||
assert.deepEqual(res, []);
|
||
return report;
|
||
}, {
|
||
usage: 'demo', argv: ['node', 'demo', '/fake/req.json'],
|
||
readFile: () => '[{"id":"R1","text":"x"}]', write: (s) => { out += s; }, exit: () => {},
|
||
});
|
||
assert.deepEqual(JSON.parse(out), report);
|
||
});
|
||
test('reads the optional resolutions file when a second path is given', () => {
|
||
let seenRes;
|
||
pc.runProbeCli((reqs, res) => { seenRes = res; return report; }, {
|
||
usage: 'demo', argv: ['node', 'demo', '/req.json', '/res.json'],
|
||
readFile: (p) => (p === '/res.json' ? '[{"requirement_id":"R1"}]' : '[{"id":"R1"}]'),
|
||
write: () => {}, exit: () => {},
|
||
});
|
||
assert.deepEqual(seenRes, [{ requirement_id: 'R1' }]);
|
||
});
|
||
test('invalid requirements JSON → exits 2 (handled, not an uncaught throw)', () => {
|
||
let code;
|
||
pc.runProbeCli(() => report, {
|
||
usage: 'demo', argv: ['node', 'demo', '/req.json'],
|
||
readFile: () => 'not json {{{', writeErr: () => {}, exit: (c) => { code = c; },
|
||
});
|
||
assert.equal(code, 2);
|
||
});
|
||
test('an analyze throw → exits 2 (the engine fail-closed surfaces, never silently passes)', () => {
|
||
let code;
|
||
pc.runProbeCli(() => { throw new Error('boom'); }, {
|
||
usage: 'demo', argv: ['node', 'demo', '/req.json'],
|
||
readFile: () => '[]', writeErr: () => {}, exit: (c) => { code = c; },
|
||
});
|
||
assert.equal(code, 2);
|
||
});
|
||
// Re-review #5 Low — the scaffold trusts each adapter's `as` cast for the returned report.
|
||
// A future adapter (#644) that forgets to validate inside its closure would otherwise have a
|
||
// structurally-broken report written as green output. Guard the report shape structurally.
|
||
test('a structurally-invalid report from analyze → exits 2 and writes nothing (no silent malformed output)', () => {
|
||
let code; let out = '';
|
||
pc.runProbeCli(() => ({ nope: true }), {
|
||
usage: 'demo', argv: ['node', 'demo', '/req.json'],
|
||
readFile: () => '[]', write: (s) => { out += s; }, writeErr: () => {}, exit: (c) => { code = c; },
|
||
});
|
||
assert.equal(code, 2);
|
||
assert.equal(out, '');
|
||
});
|
||
test('a report whose coverage object carries non-numeric counts → exits 2 (partial-guard case)', () => {
|
||
// items[] is well-formed and `coverage` IS an object, so the cheaper checks pass — this
|
||
// exercises the numeric-count branch of the structural guard specifically.
|
||
let code; let out = '';
|
||
pc.runProbeCli(() => ({ items: [], coverage: { applicable: 'x', resolved: null, unresolved: undefined, byVerification: {} } }), {
|
||
usage: 'demo', argv: ['node', 'demo', '/req.json'],
|
||
readFile: () => '[]', write: (s) => { out += s; }, writeErr: () => {}, exit: (c) => { code = c; },
|
||
});
|
||
assert.equal(code, 2);
|
||
assert.equal(out, '');
|
||
});
|
||
test('a well-formed report still writes and does not trip the structural guard', () => {
|
||
let out = '';
|
||
pc.runProbeCli(() => report, {
|
||
usage: 'demo', argv: ['node', 'demo', '/req.json'],
|
||
readFile: () => '[]', write: (s) => { out += s; }, exit: () => {},
|
||
});
|
||
assert.deepEqual(JSON.parse(out), report);
|
||
});
|
||
});
|