* test(#3866): pin that verify:pre must dispatch every hook kind verify-work.md's verify_pre_hooks step dispatches only `kind == "gate"`, so getWiredKinds reports verify:pre -> {gate} and gen-capability-registry rejects any capability declaring a step or contribution there. The verify lane is therefore closed to capabilities that want to contribute to what UAT covers rather than refuse to let it start. Failing-first: the step, contribution, and exact-kind-set rows are RED; the pre-existing gate row is a green regression pin so the new arms cannot orphan the arm verify:pre already had. Refs #3866 * feat(#3866): dispatch step and contribution hooks at verify:pre verify_pre_hooks dispatched `kind == "gate"` only, so getWiredKinds reported verify:pre -> {gate} and gen-capability-registry's validateHooksWired rejected any capability declaring a step or contribution there. A capability could refuse to let UAT start; it could not contribute to what UAT covers. Add contribution and step arms mirroring execute:wave:post, deferring to references/loop-hook-dispatch.md and carrying its ref.command in-context validation guard ahead of any shell-use prose. A verify:pre step is advisory: it never blocks the start of UAT and an erroring step is routed by its own onError. The gate arm and its check guard are untouched. Give extract_tests an additive consumption seam for the artefacts those steps declare via the existing steps[].produces field -- no new registry field, no new ordering, no invented filename. Manifest-supplied artefact names are validated in-context against an allowlist and resolved only inside PHASE_DIR. With no producing step the derivation is unchanged, pinned by test rather than asserted in prose. Review findings folded in: the artefact-name allowlist (isolated adversarial pass), the artefact-shape contract and the seam-inertness tests (spec axis), and the reference/how-to split so one constraint has one source of truth (standards axis). Closes #3866 * chore(#3866): backfill changeset PR number --------- Co-authored-by: sim <sim@local>
452 lines
21 KiB
JavaScript
452 lines
21 KiB
JavaScript
'use strict';
|
|
|
|
const { describe, test } = require('node:test');
|
|
const assert = require('node:assert/strict');
|
|
const fs = require('node:fs');
|
|
const path = require('node:path');
|
|
const { execFileSync } = require('node:child_process');
|
|
const { cleanup } = require('./helpers.cjs');
|
|
|
|
const ROOT = path.join(__dirname, '..');
|
|
const { HOST_LOOP_FILES, scanWiredPoints } = require('../scripts/gen-loop-host-contract.cjs');
|
|
const { lfByteCount } = require('../scripts/workflow-size.cjs');
|
|
|
|
const CORE_SUBSTRATE_TERMS = [
|
|
'Verification substrate',
|
|
'verifier↔predicate contract',
|
|
'Probe Core Module',
|
|
'Edge Probe Module',
|
|
];
|
|
|
|
const registry = require('../gsd-core/bin/lib/capability-registry.cjs');
|
|
const { isCentralConfigKey } = require('../gsd-core/bin/lib/config-schema.cjs');
|
|
const { escapeRegex: escapeRegExp } = require('../gsd-core/bin/lib/pattern.cjs');
|
|
|
|
function readRepoFile(relativePath) {
|
|
return fs.readFileSync(path.join(ROOT, relativePath), 'utf8');
|
|
}
|
|
|
|
function activeWhenKeys() {
|
|
const keys = new Set();
|
|
for (const cap of Object.values(registry.capabilities)) {
|
|
for (const group of ['steps', 'gates', 'contributions']) {
|
|
for (const hook of cap[group] || []) {
|
|
if (hook.when) keys.add(hook.when);
|
|
}
|
|
}
|
|
}
|
|
return [...keys].sort();
|
|
}
|
|
|
|
describe('ADR-857 Phase 6 capstone conformance (#1139)', () => {
|
|
test('first-party optional feature capabilities are declared in the generated registry', () => {
|
|
const expectedFeatureCapabilities = [
|
|
'ai-integration',
|
|
'audit',
|
|
'code-review',
|
|
'graphify',
|
|
'intel',
|
|
'nyquist',
|
|
'pattern-mapper',
|
|
'research',
|
|
'security',
|
|
'ui',
|
|
];
|
|
|
|
for (const capId of expectedFeatureCapabilities) {
|
|
assert.equal(registry.capabilities[capId]?.role, 'feature', `${capId} must be a feature Capability`);
|
|
}
|
|
});
|
|
|
|
test('core verification substrate is documented as deliberately not capability-owned', () => {
|
|
const context = readRepoFile('CONTEXT.md');
|
|
for (const term of CORE_SUBSTRATE_TERMS) {
|
|
assert.match(context, new RegExp(escapeRegExp(term)), `${term} must be documented in CONTEXT.md`);
|
|
}
|
|
});
|
|
|
|
test('host loop files do not read capability hook activation keys directly', () => {
|
|
const forbiddenKeys = activeWhenKeys();
|
|
assert.ok(forbiddenKeys.length > 0, 'registry must expose hook activation keys');
|
|
|
|
for (const relativePath of HOST_LOOP_FILES) {
|
|
const content = readRepoFile(relativePath);
|
|
for (const key of forbiddenKeys) {
|
|
assert.doesNotMatch(
|
|
content,
|
|
new RegExp(`\\bconfig-get\\s+${escapeRegExp(key)}\\b`),
|
|
`${relativePath} must resolve ${key} through Capability hooks/state, not direct config-get`,
|
|
);
|
|
}
|
|
}
|
|
});
|
|
|
|
test('capability-owned config keys are not reintroduced into the central schema', () => {
|
|
for (const key of Object.keys(registry.configKeys).sort()) {
|
|
assert.equal(
|
|
isCentralConfigKey(key),
|
|
false,
|
|
`${key} is owned by capability ${registry.configKeys[key]} and must stay out of central config schema`,
|
|
);
|
|
}
|
|
});
|
|
|
|
test('host loop workflow files have a measurable, non-empty byte size', () => {
|
|
// Was asserted against the committed tests/workflow-size-baseline.json snapshot;
|
|
// #2724 (ADR-2719 Phase 4) deletes that file — the differential attribution
|
|
// check's size ratchet (tests/emitted-attribution.test.cjs) is the replacement
|
|
// anti-creep mechanism, but this test's actual intent was narrower: prove these
|
|
// host-loop files are real, tracked, non-empty workflow docs. Asserting the
|
|
// live byte count via the same shared counter the size guards use preserves
|
|
// that intent without depending on a committed snapshot.
|
|
for (const relativePath of HOST_LOOP_FILES) {
|
|
const fileName = path.basename(relativePath);
|
|
const bytes = lfByteCount(path.join(ROOT, relativePath));
|
|
assert.ok(bytes > 0, `${fileName} must be a non-empty workflow file`);
|
|
}
|
|
});
|
|
|
|
// ─── Phase-6 conformance: RED BY DESIGN until phase 6 is actually complete ──────
|
|
//
|
|
// #1139 closed (via #1158) with a green "capstone conformance gate" while the
|
|
// ADR-857 phase-6 acceptance criteria were unmet — a false green. The three
|
|
// tests below assert the real criteria with NO paper-over allowlist, so the
|
|
// gate stays RED until the work lands. Green here must mean "phase 6 conformant,"
|
|
// not "no new regression." Fixes tracked in #1167 / #1168 / #1169.
|
|
|
|
test('every declared capability hook point has a render-hooks call site in the host loop (#1168)', () => {
|
|
// No allowlist: every point a capability declares a hook at MUST have a
|
|
// `render-hooks` call site in the host loop, or those hooks can never fire.
|
|
const declaredPoints = new Set();
|
|
for (const cap of Object.values(registry.capabilities)) {
|
|
for (const group of ['steps', 'gates', 'contributions']) {
|
|
for (const hook of cap[group] || []) {
|
|
if (hook.point) declaredPoints.add(hook.point);
|
|
}
|
|
}
|
|
}
|
|
|
|
// Scan only the host loop files (a `render-hooks` mention in a non-host
|
|
// workflow must not mask a lost host call site).
|
|
const callSites = new Set();
|
|
for (const relativePath of HOST_LOOP_FILES) {
|
|
const content = readRepoFile(relativePath);
|
|
for (const pt of scanWiredPoints(content)) callSites.add(pt);
|
|
}
|
|
|
|
const orphaned = [...declaredPoints].sort().filter((p) => !callSites.has(p));
|
|
assert.deepEqual(
|
|
orphaned, [],
|
|
`ADR-857 phase 6 is NOT complete: capability hooks declare these extension points ` +
|
|
`but no host-loop workflow calls \`gsd_run loop render-hooks <point>\`, so the hooks ` +
|
|
`can never fire: ${orphaned.join(', ')}. Wire each call site (#1167/#1169).`,
|
|
);
|
|
});
|
|
|
|
test('all ADR-857-named optional features are real Capabilities, not empty stubs (#1169)', () => {
|
|
// ADR-857 §53 + Decision 7 enumerate these optional, non-loop modules as
|
|
// Capabilities. "Migrated" means the feature OWNS its behavior: hook-based
|
|
// features (tdd/schema-gate/drift/gap-analysis) must declare >=1 hook;
|
|
// command-family features (profile-pipeline) must declare a command family.
|
|
// A registration-only stub (role:feature but no hooks/commands) games this
|
|
// gate while the logic stays welded into the loop — rejected here.
|
|
const REQUIRED = ['tdd', 'schema-gate', 'drift', 'gap-analysis', 'profile-pipeline'];
|
|
const problems = [];
|
|
for (const id of REQUIRED) {
|
|
const cap = registry.capabilities[id];
|
|
if (!cap) { problems.push(`${id}: not registered`); continue; }
|
|
if (cap.role !== 'feature') { problems.push(`${id}: role="${cap.role}", must be "feature"`); continue; }
|
|
const hookCount = (cap.steps?.length || 0) + (cap.contributions?.length || 0) + (cap.gates?.length || 0);
|
|
const isCommandFamily = (cap.commands?.length || 0) > 0;
|
|
if (hookCount === 0 && !isCommandFamily) {
|
|
problems.push(`${id}: EMPTY STUB (no hooks, no command family) — inline logic was not migrated; declare the real hooks/commands and remove the inline branch`);
|
|
}
|
|
}
|
|
assert.deepEqual(
|
|
problems, [],
|
|
`ADR-857 phase 6 is NOT complete:\n ${problems.join('\n ')}\n` +
|
|
`Each feature must OWN its behavior via hooks or a command family — not exist as a registration-only stub (#1169).`,
|
|
);
|
|
});
|
|
|
|
test('host loop reads no capability-owned config key inline (#1169)', () => {
|
|
// Phase 6 requires the loop to resolve capability behavior via render-hooks,
|
|
// not by reading capability-owned keys directly. Any inline `config-get` of a
|
|
// registry-owned key is an incomplete migration (the loop still owns the
|
|
// feature's params).
|
|
const leaks = [];
|
|
for (const relativePath of HOST_LOOP_FILES) {
|
|
const content = readRepoFile(relativePath);
|
|
for (const key of Object.keys(registry.configKeys)) {
|
|
if (new RegExp(`\\bconfig-get\\s+${escapeRegExp(key)}\\b`).test(content)) {
|
|
leaks.push(`${path.basename(relativePath)} → ${key} (owned by ${registry.configKeys[key]})`);
|
|
}
|
|
}
|
|
}
|
|
leaks.sort();
|
|
assert.deepEqual(
|
|
leaks, [],
|
|
`ADR-857 phase 6 is NOT complete: the host loop reads capability-owned config keys ` +
|
|
`inline:\n ${leaks.join('\n ')}\nThe owning capability must render/consume these (#1169).`,
|
|
);
|
|
});
|
|
|
|
test('host loop bodies are materially smaller than the pre-phase-6 baseline (#1168)', () => {
|
|
// #1139 AC: plan-phase.md / execute-phase.md must shrink as optional features
|
|
// extract to capabilities. Frozen pre-phase-6 sizes (LF bytes); the files must
|
|
// drop strictly below these. This also defeats double-run gaming — declaring a
|
|
// hook while leaving the inline block keeps the file from shrinking -> red.
|
|
//
|
|
// #1298: the execute-phase.md ceiling was raised from 93166 to accommodate
|
|
// wiring the mandatory `worktree record-agent` writer verb into the per-agent
|
|
// wave-manifest append. That verb is privileged host machinery (ADR-857
|
|
// Decision #1) — NOT the optional-feature inline logic this budget ratchets
|
|
// toward capabilities — so its footprint legitimately raises the host-loop
|
|
// ceiling rather than signalling an un-extracted optional feature.
|
|
const { lfByteCount } = require('../scripts/workflow-size.cjs');
|
|
const PRE_PHASE6 = { 'plan-phase.md': 94519, 'execute-phase.md': 93600 };
|
|
const notShrunk = [];
|
|
for (const [file, frozen] of Object.entries(PRE_PHASE6)) {
|
|
const now = lfByteCount(path.join(ROOT, 'gsd-core', 'workflows', file));
|
|
if (now >= frozen) notShrunk.push(`${file}: ${now} bytes (must be < pre-phase-6 ${frozen})`);
|
|
}
|
|
assert.deepEqual(
|
|
notShrunk, [],
|
|
`ADR-857 phase 6 is NOT complete: host loop bodies have not shrunk — the optional ` +
|
|
`feature logic has not actually been extracted:\n ${notShrunk.join('\n ')}`,
|
|
);
|
|
});
|
|
|
|
describe('ADR-857 phase 6 — capabilities must not bake install paths into the registry', () => {
|
|
// Matches GSD install paths that LEAK when copied verbatim to non-Claude runtimes.
|
|
// (~/.claude/projects is a legit runtime feature and is intentionally NOT matched.)
|
|
const LEAK = /\.claude[/\\](?:gsd-core|commands|agents|hooks)\b/;
|
|
|
|
test('no capability source (capability.json or fragment) embeds a ~/.claude install path', () => {
|
|
const capsDir = path.join(__dirname, '..', 'capabilities');
|
|
const offenders = [];
|
|
for (const id of fs.readdirSync(capsDir)) {
|
|
const dir = path.join(capsDir, id);
|
|
if (!fs.statSync(dir).isDirectory()) continue;
|
|
const cj = path.join(dir, 'capability.json');
|
|
if (fs.existsSync(cj) && LEAK.test(fs.readFileSync(cj, 'utf8'))) {
|
|
offenders.push(`capabilities/${id}/capability.json`);
|
|
}
|
|
const fragDir = path.join(dir, 'fragments');
|
|
if (fs.existsSync(fragDir)) {
|
|
for (const f of fs.readdirSync(fragDir)) {
|
|
if (LEAK.test(fs.readFileSync(path.join(fragDir, f), 'utf8'))) {
|
|
offenders.push(`capabilities/${id}/fragments/${f}`);
|
|
}
|
|
}
|
|
}
|
|
}
|
|
assert.deepEqual(offenders, [],
|
|
`capability sources embed ~/.claude install paths — these leak into the verbatim-copied capability-registry.cjs on non-Claude runtimes. Make the fragment path-free. Offenders: ${offenders.join(', ')}`);
|
|
});
|
|
|
|
test('generated capability-registry.cjs contains no ~/.claude install path', () => {
|
|
const reg = fs.readFileSync(path.join(__dirname, '..', 'gsd-core', 'bin', 'lib', 'capability-registry.cjs'), 'utf8');
|
|
// allow-test-rule: source-text-is-the-product
|
|
const leakLines = reg.split(/\r?\n/).map((l, i) => [i + 1, l]).filter(([, l]) => LEAK.test(l)).map(([n]) => n);
|
|
assert.deepEqual(leakLines, [],
|
|
`capability-registry.cjs leaks ~/.claude install paths at line(s) ${leakLines.join(', ')} — the registry is copied verbatim to non-Claude runtimes (only workflow .md files are path-converted at install). Make the source capability fragment path-free.`);
|
|
});
|
|
});
|
|
|
|
test('every plan:pre planner contribution is injected generically (not per-capId hardcode)', () => {
|
|
// FIX C regression guard: plan-phase.md must inject planner contributions
|
|
// generically (by into == "planner") rather than only injecting a single
|
|
// hardcoded capId (e.g. "tdd"). A generic injection ensures any active
|
|
// plan:pre contribution with into=="planner" reaches the planner — including
|
|
// tdd, schema-gate, and security contributions.
|
|
//
|
|
// Heuristic: the planner prompt section must reference injecting where
|
|
// into == "planner" (or iterate contributions), AND must NOT rely solely
|
|
// on a single capId == "tdd" injection as the only planner contribution
|
|
// delivery mechanism.
|
|
const planPhase = readRepoFile('gsd-core/workflows/plan-phase.md');
|
|
|
|
// The file must contain a generic reference to into == "planner" contribution injection.
|
|
assert.match(
|
|
planPhase,
|
|
/into\s*==\s*["']planner["']/,
|
|
'plan-phase.md must inject planner contributions generically via into == "planner" ' +
|
|
'(not just a single hardcoded capId). Fix C regression: all active planner contributions must reach the planner.',
|
|
);
|
|
|
|
// Verify the file does NOT rely SOLELY on a hardcoded capId == "tdd" injection
|
|
// for the planner contribution. If only a tdd-specific injection exists (old form),
|
|
// the schema-gate and security contributions are silently dropped.
|
|
// We check: every occurrence of 'capId == "tdd"' contribution injection must be
|
|
// accompanied somewhere by a generic into=="planner" dispatch (already verified above).
|
|
// Additionally, the old exact tdd-only injection prose must not be the only delivery.
|
|
const onlyTddInjection = /\bRead from `PLAN_PRE_HOOKS_JSON` where `kind == "contribution"` and `capId == "tdd"`\b/;
|
|
// If the old tdd-only prose still exists WITHOUT the generic into=="planner" prose,
|
|
// that's a regression. Since we already asserted into=="planner" exists, we just
|
|
// confirm the tdd-only prose is no longer the sole injection mechanism.
|
|
if (onlyTddInjection.test(planPhase)) {
|
|
// Old prose still present: acceptable only if generic prose is ALSO present (already asserted).
|
|
// Verify the into=="planner" injection appears NEAR the planner prompt (within 5000 chars of it).
|
|
const plannerPromptIdx = planPhase.indexOf('into == "planner"');
|
|
assert.ok(
|
|
plannerPromptIdx >= 0,
|
|
'plan-phase.md has tdd-only injection prose but no generic into=="planner" injection. ' +
|
|
'Remove the tdd-only injection and replace with generic contribution dispatch.',
|
|
);
|
|
}
|
|
});
|
|
|
|
// ─── #3866: the verify:pre produced-artefact seam must be strictly additive ──
|
|
//
|
|
// The lane opened at verify:pre lets a capability step produce an artefact that
|
|
// extract_tests consumes. The contract that makes that safe is that the seam is
|
|
// INERT when nothing is produced: derivation must be unchanged for every project
|
|
// that has no such capability — which is every project on `next` today. These
|
|
// assert the workflow prose an executing agent actually reads (verify-work.md is
|
|
// Markdown, not a source path, so local/no-source-grep does not apply).
|
|
|
|
test('the verify:pre produced-artefact seam is conditional, and the pre-existing derivation paths are not nested inside it (#3866)', () => {
|
|
const wf = readRepoFile('gsd-core/workflows/verify-work.md');
|
|
|
|
const seamIdx = wf.indexOf('Verify:pre produced-artefact seam');
|
|
assert.ok(seamIdx > 0, 'verify-work.md must carry the verify:pre produced-artefact seam');
|
|
|
|
// The seam must open with its own skip-when-absent guard, so an agent reading
|
|
// it top-down never falls into the merge on a project with no producing step.
|
|
const seamHead = wf.slice(seamIdx, seamIdx + 400);
|
|
assert.match(
|
|
seamHead, /VERIFY_PRE_PRODUCED/,
|
|
'the seam must name the variable it is conditional on',
|
|
);
|
|
assert.match(
|
|
seamHead, /empty or absent/,
|
|
'the seam must state the empty/absent case before describing any merge',
|
|
);
|
|
|
|
// Both pre-existing derivation paths must still exist, and must sit OUTSIDE the
|
|
// seam: the coverage classifier before it, the legacy prose fallback after it.
|
|
// If either migrated inside the seam it would become conditional on a producing
|
|
// step existing — the exact regression "byte-identical when no artefact exists"
|
|
// rules out.
|
|
const coverageIdx = wf.indexOf('uat.classify-coverage');
|
|
const legacyIdx = wf.indexOf('Extract testable deliverables from SUMMARY.md');
|
|
assert.ok(coverageIdx > 0, 'the #1602 coverage classifier must still be invoked');
|
|
assert.ok(legacyIdx > 0, 'the legacy prose-extraction fallback must still exist');
|
|
assert.ok(
|
|
coverageIdx < seamIdx,
|
|
'coverage classification must run before the seam, not inside it',
|
|
);
|
|
assert.ok(
|
|
legacyIdx > seamIdx,
|
|
'the legacy fallback must follow the seam and stay unguarded by it',
|
|
);
|
|
});
|
|
|
|
test('the verify:pre produced-artefact seam validates manifest-supplied artefact names in-context (#3866)', () => {
|
|
const wf = readRepoFile('gsd-core/workflows/verify-work.md');
|
|
const seamIdx = wf.indexOf('Verify:pre produced-artefact seam');
|
|
assert.ok(seamIdx > 0, 'verify-work.md must carry the verify:pre produced-artefact seam');
|
|
const seam = wf.slice(seamIdx, legacyEnd(wf, seamIdx));
|
|
|
|
// `produces` names come from a third-party capability manifest. The seam must
|
|
// carry an explicit in-context allowlist, the same shape loop-hook-dispatch.md
|
|
// requires of `ref.command` — not a vague "it is a name, not a path".
|
|
assert.match(
|
|
seam, /\^\[A-Za-z0-9\]\[A-Za-z0-9\._-\]\*\$/,
|
|
'the seam must pin an explicit allowlist regex for artefact names',
|
|
);
|
|
assert.match(
|
|
seam, /never\*{0,2}\s*by pasting it into a\s*\n?\s*shell command|never\*{0,2} by pasting it into a shell/,
|
|
'the seam must forbid shell-side validation of the manifest value',
|
|
);
|
|
assert.match(
|
|
seam, /\$PHASE_DIR/,
|
|
'the seam must confine resolution to the phase directory',
|
|
);
|
|
});
|
|
|
|
/** End of the seam region: the next top-level bold heading after it. */
|
|
function legacyEnd(wf, seamIdx) {
|
|
const next = wf.indexOf('**Extract testable deliverables', seamIdx);
|
|
return next > seamIdx ? next : Math.min(wf.length, seamIdx + 3000);
|
|
}
|
|
|
|
test('every declared gate check.query returns a uniform boolean `block` field', () => {
|
|
// FIX A regression guard: every gate check command must return a top-level
|
|
// boolean `block` field so the host-loop dispatch can read a single consistent
|
|
// field regardless of which capability owns the gate.
|
|
//
|
|
// For each unique check.query declared in the registry's gate hooks, invoke
|
|
// the check command against a temp directory and assert the JSON output
|
|
// contains `block` as a boolean. Uses a minimal temp dir so the command
|
|
// returns quickly without real project state.
|
|
const os = require('node:os');
|
|
const tmpDir = fs.mkdtempSync(path.join(os.tmpdir(), 'gate-block-contract-'));
|
|
|
|
// Collect unique gate check.queries from the registry
|
|
const queries = new Set();
|
|
for (const cap of Object.values(registry.capabilities)) {
|
|
for (const gate of cap.gates || []) {
|
|
if (gate.check && gate.check.query) queries.add(gate.check.query);
|
|
}
|
|
}
|
|
assert.ok(queries.size > 0, 'Registry must declare at least one gate check.query');
|
|
|
|
const gsdTools = path.join(ROOT, 'gsd-core', 'bin', 'gsd-tools.cjs');
|
|
const failures = [];
|
|
|
|
for (const query of [...queries].sort()) {
|
|
let rawOut = '';
|
|
try {
|
|
// Invoke with --raw (the real dispatch form used by the host loop).
|
|
// Most commands accept a phase number and return valid JSON even when
|
|
// no real project state exists.
|
|
rawOut = execFileSync(
|
|
process.execPath,
|
|
[gsdTools, 'check', query, '1', '--raw'],
|
|
{ cwd: tmpDir, encoding: 'utf-8', timeout: 10000 },
|
|
);
|
|
const parsed = JSON.parse(rawOut.trim());
|
|
if (typeof parsed.block !== 'boolean') {
|
|
failures.push(
|
|
`check ${query}: returned JSON without a boolean \`block\` field ` +
|
|
`(got: ${JSON.stringify(parsed.block)}, type: ${typeof parsed.block}). ` +
|
|
`Add \`block\` to the command's output per the uniform gate contract.`,
|
|
);
|
|
}
|
|
} catch (err) {
|
|
// If it threw because the command required a different arg shape, try with a path
|
|
try {
|
|
rawOut = execFileSync(
|
|
process.execPath,
|
|
[gsdTools, 'check', query, tmpDir, '--raw'],
|
|
{ cwd: tmpDir, encoding: 'utf-8', timeout: 10000 },
|
|
);
|
|
const parsed = JSON.parse(rawOut.trim());
|
|
if (typeof parsed.block !== 'boolean') {
|
|
failures.push(
|
|
`check ${query}: returned JSON without a boolean \`block\` field ` +
|
|
`(got: ${JSON.stringify(parsed.block)}, type: ${typeof parsed.block}).`,
|
|
);
|
|
}
|
|
} catch (err2) {
|
|
failures.push(
|
|
`check ${query}: command failed or returned non-JSON output. ` +
|
|
`Error: ${err2 instanceof Error ? err2.message : String(err2)}. ` +
|
|
`Stdout: ${rawOut.slice(0, 200)}`,
|
|
);
|
|
}
|
|
}
|
|
}
|
|
|
|
// Clean up temp dir
|
|
cleanup(tmpDir);
|
|
|
|
assert.deepEqual(
|
|
failures, [],
|
|
`Gate check commands must all return a top-level boolean \`block\` field:\n ${failures.join('\n ')}`,
|
|
);
|
|
});
|
|
});
|