* feat(#3970): per-task external-tracker content-resolution seam Implements ADR-3646 (Phase 1, #3970): a `<task tracker-id="...">` attribute plus a new optional `taskContentResolver` capability-manifest field let a capability resolve a task's action/verify/acceptance-criteria/read_first/done content from an external issue tracker instead of PLAN.md's inline body. - src/plan-document.cts: parses the `tracker-id` attribute into `PlanTask.trackerId` - src/task-content-resolution.cts: new leaf module — split/find/build/resolve, with a hard-halt (throw) contract on ambiguous/failed/timeout/malformed resolution, never a silent fallback to possibly-stale inline text - src/task-command-router.cts: new `task resolve-content --plan --task-id --raw` CLI verb wiring the module into a real process exit code - gsd-core/bin/lib/capability-validator.cjs: validates the new `taskContentResolver` manifest field (feature-role only, cross-capability trackerPrefix uniqueness) - gsd-core/workflows/execute-plan.md, gsd-core/references/loop-hook-dispatch.md, docs/reference/capability-manifest.md: wire the seam into the per-task loop and document it as a new `execute:task` point outside the existing contribution/step/gate vocabulary (unconditional in autonomous mode) Closes #3970 * fix(#3970): gate checkpoint tasks out of content resolution, close trackerPrefix grammar parity gap, cover path-traversal guard Standards/Spec code-review pass on the task-content-resolution seam (ADR-3646 Phase 1) found three defects: 1. execute-plan.md's task-content-resolution bullet fired on any tracker-id-bearing task with no check that it wasn't type="checkpoint:*", contradicting ADR-3646 Decision 1 (a checkpoint task must never enter resolve-content). plan-document.cts already parses trackerId: null unconditionally for checkpoint tasks; only the workflow prose needed the fix, so the bullet now explicitly excludes checkpoint tasks. 2. task-content-resolution.cts's parseResolverDeclaration accepted any non-empty trackerPrefix with no grammar check, while capability- validator.cjs's KEBAB_RE enforces kebab-case at install time — a Generative Fix Divergence gap. Added the same grammar (as a literal regex, documented as intentionally not shared across the .cts/.cjs build boundary) plus a parity test asserting the two surfaces agree across a valid/invalid trackerPrefix table. 3. task-command-router.cts's routeResolveContent path-traversal guard on --plan had zero test coverage. Added a test exercising a ../../../etc/passwit-shaped path and asserting the USAGE rejection names the offending path. * fix(#3970): sanitize resolver diagnostics and cap resolver timeoutMs Two findings caught by an isolated security-review pass on the task content resolution seam: - ResolverFailedError/ResolverMalformedOutputError embedded raw, unsanitized subprocess stderr/stdout (attacker/model-influenced via the tracker-id argv token) into .message. A hostile or buggy resolver could smuggle a newline plus a forged "Error: " line, or terminal escape sequences, into a diagnostic io.cjs's error() writes verbatim to stderr. Fixed at the constructor (task-content-resolution.cts) via io.cjs's existing formatDiagnosticToken(), so every caller of resolveTaskContent gets a safe .message by construction. - capability-validator.cjs's validateTaskContentResolverFields had no upper bound on taskContentResolver.invoke.timeoutMs, letting a manifest declare an effectively unbounded value and defeat the "bounded subprocess" design intent. Added a 120000ms ceiling specific to this field, without touching the shared isPositiveIntegerMs() helper (still used unbounded by the reviewer lane's timeoutFloorMs and probe timeoutMs). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * fix(#3970): fix gsd-test failures — stale prose allowlist line and stderr-vs-message assertion gsd-test (remote dockerized matrix) came back red with 5 failures on this PR; all five are real defects, fixed here. - tests/no-bare-gsd-tools-command-position.test.cjs: PROSE_ALLOWLIST's execute-plan.md entry pointed at line 415, which ffc190df4's checkpoint-exclusion caveat (added near line 221) shifted down by one line. The actual "validated downstream by gsd-tools uat classify-coverage" descriptive mention now sits at line 416. Updated the allowlist entry's line number to match. - tests/task-command-router-resolve-content.test.cjs: the path-traversal test asserted the outside-project-scope diagnostic against the thrown ExitError's own .message. io.cts's error() (ADR-3889) writes its human-readable message to fd 2 via writeAllSync and then throws a bare `new ExitError(1)` with no message argument — by design, so the exception carries no duplicate text and the thrown ExitError's message defaults to "process exit 1" (cli-exit.cts's ExitError constructor). Root cause was the test, not the source: task-command-router.cjs's outside-project-scope rejection already calls error() correctly and the diagnostic text is genuinely emitted, just on fd 2, not on the exception. Fixed the test to capture fd-2 writes (mirroring tests/estimate-calibrate.test.cjs's runCalibrateExpectError and this same file's own captureStdout for fd 1) and assert against the captured stderr text instead of err.message. This was masked locally because a manual `node -e` sanity check that only inspects the caught exception's .message cannot see what the real node:test run actually failed on. Emitted-Drift-Ack-Growth: execute-plan.md — adds the ADR-3646 task-content-resolution bullet and checkpoint-exclusion caveat to the per-task execute loop; a real behavioral prose addition, not incidental bloat. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * docs(#3970): backfill changeset PR number (pr:0 -> pr:4000) --------- Co-authored-by: sim <sim@local> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
280 lines
9.6 KiB
JavaScript
280 lines
9.6 KiB
JavaScript
'use strict';
|
|
|
|
/**
|
|
* Tests for `task resolve-content` (ADR-3646 Decision 2, issue #3970).
|
|
* Covers test matrix rows 17-19:
|
|
* 17 — plan exists, task-id not found in it -> USAGE, non-zero exit.
|
|
* 18 — end-to-end happy path via injected `resolveTaskContentFn`.
|
|
* 19 — missing --plan and/or --task-id -> USAGE, before any filesystem access.
|
|
* Plus the hard-halt path: a thrown resolver-error class must surface as a
|
|
* non-zero CLI exit, never a swallowed `{resolved:false}` JSON answer.
|
|
*
|
|
* In-process style (routeResolveContent's own `_`-prefixed-equivalent
|
|
* `deps` injection seam), mirroring `refactor-trigger-command-router.cts`'s
|
|
* injection convention — no subprocess spawn needed for these rows.
|
|
*/
|
|
|
|
const { test, describe, mock } = require('node:test');
|
|
const assert = require('node:assert/strict');
|
|
const fs = require('node:fs');
|
|
const path = require('node:path');
|
|
|
|
const { createTempDir, cleanup } = require('./helpers.cjs');
|
|
|
|
const { routeResolveContent } = require('../gsd-core/bin/lib/task-command-router.cjs');
|
|
const { ExitError } = require('../gsd-core/bin/lib/cli-exit.cjs');
|
|
const {
|
|
ResolverFailedError,
|
|
} = require('../gsd-core/bin/lib/task-content-resolution.cjs');
|
|
|
|
function writePlan(dir, taskXml) {
|
|
const planPath = path.join(dir, '01-PLAN.md');
|
|
fs.writeFileSync(planPath, `# Plan\n\n${taskXml}\n`, 'utf8');
|
|
return planPath;
|
|
}
|
|
|
|
/**
|
|
* `io.cjs`'s `output()` writes to fd 1 via `fs.writeSync` directly (never
|
|
* `process.stdout.write`) — see `writeAllSync` in
|
|
* `gsd-core/bin/lib/io.cjs`. Capture fd-1 writes by mocking `fs.writeSync`
|
|
* itself; every other fd passes through to the real implementation
|
|
* unmocked (so the plan-file reads and any other fs traffic inside a test
|
|
* body still work).
|
|
*/
|
|
function captureStdout(fn) {
|
|
const chunks = [];
|
|
const origWriteSync = fs.writeSync.bind(fs);
|
|
const writeMock = mock.method(fs, 'writeSync', (fd, buffer, ...rest) => {
|
|
if (fd === 1) {
|
|
chunks.push(Buffer.isBuffer(buffer) ? buffer.toString('utf8') : String(buffer));
|
|
return Buffer.isBuffer(buffer) ? buffer.length : Buffer.byteLength(String(buffer));
|
|
}
|
|
return origWriteSync(fd, buffer, ...rest);
|
|
});
|
|
try {
|
|
fn();
|
|
} finally {
|
|
writeMock.mock.restore();
|
|
}
|
|
return chunks.join('');
|
|
}
|
|
|
|
/**
|
|
* `io.cjs`'s `error()` (ADR-3889) writes its human-readable message to fd 2
|
|
* via `writeAllSync`, then throws a bare `new ExitError(1)` with NO message
|
|
* — the stderr write already happened, so the thrown Error's own `.message`
|
|
* defaults to `"process exit ${code}"` (see `cli-exit.cjs`'s `ExitError`
|
|
* constructor) and never carries the diagnostic text. Asserting against
|
|
* `err.message` therefore can never see the "outside project scope" text;
|
|
* the diagnostic must be read off the captured fd-2 bytes instead. Mirrors
|
|
* the same fd-mock idiom `captureStdout` above uses for fd 1, and the
|
|
* established repo pattern in `tests/estimate-calibrate.test.cjs`'s
|
|
* `runCalibrateExpectError`.
|
|
*/
|
|
function captureStderr(fn) {
|
|
const chunks = [];
|
|
const origWriteSync = fs.writeSync.bind(fs);
|
|
const writeMock = mock.method(fs, 'writeSync', (fd, buffer, ...rest) => {
|
|
if (fd === 2) {
|
|
chunks.push(Buffer.isBuffer(buffer) ? buffer.toString('utf8') : String(buffer));
|
|
return Buffer.isBuffer(buffer) ? buffer.length : Buffer.byteLength(String(buffer));
|
|
}
|
|
return origWriteSync(fd, buffer, ...rest);
|
|
});
|
|
try {
|
|
fn();
|
|
} finally {
|
|
writeMock.mock.restore();
|
|
}
|
|
return chunks.join('');
|
|
}
|
|
|
|
const RESOLVABLE_TASK = '<task type="auto" tracker-id="test:1"><name>x</name><action>do the thing</action></task>';
|
|
|
|
describe('task resolve-content (rows 17-19)', () => {
|
|
test('row 19: missing --plan and --task-id -> USAGE, no filesystem access', (t) => {
|
|
const dir = createTempDir('gsd-resolve-content-19-');
|
|
t.after(() => cleanup(dir));
|
|
const readMock = require('node:test').mock.method(fs, 'readFileSync', () => {
|
|
throw new Error('must not read the filesystem before usage validation');
|
|
});
|
|
t.after(() => readMock.mock.restore());
|
|
|
|
assert.throws(
|
|
() => routeResolveContent({ args: ['task', 'resolve-content'], cwd: dir, raw: false }),
|
|
ExitError,
|
|
);
|
|
});
|
|
|
|
test('row 19: missing --task-id only -> USAGE', (t) => {
|
|
const dir = createTempDir('gsd-resolve-content-19b-');
|
|
t.after(() => cleanup(dir));
|
|
writePlan(dir, RESOLVABLE_TASK);
|
|
assert.throws(
|
|
() =>
|
|
routeResolveContent({
|
|
args: ['task', 'resolve-content', '--plan', '01-PLAN.md'],
|
|
cwd: dir,
|
|
raw: false,
|
|
}),
|
|
ExitError,
|
|
);
|
|
});
|
|
|
|
test('row 17: plan exists, task-id not found -> USAGE, non-zero exit', (t) => {
|
|
const dir = createTempDir('gsd-resolve-content-17-');
|
|
t.after(() => cleanup(dir));
|
|
writePlan(dir, RESOLVABLE_TASK);
|
|
|
|
assert.throws(
|
|
() =>
|
|
routeResolveContent({
|
|
args: ['task', 'resolve-content', '--plan', '01-PLAN.md', '--task-id', 'nope:999'],
|
|
cwd: dir,
|
|
raw: false,
|
|
}),
|
|
(err) => {
|
|
assert.ok(err instanceof ExitError, `expected ExitError, got ${err}`);
|
|
assert.strictEqual(err.code, 1);
|
|
return true;
|
|
},
|
|
);
|
|
});
|
|
|
|
test('row 18: end-to-end happy path, resolved:true content shape', (t) => {
|
|
const dir = createTempDir('gsd-resolve-content-18-');
|
|
t.after(() => cleanup(dir));
|
|
writePlan(dir, RESOLVABLE_TASK);
|
|
|
|
const fakeCapabilities = [
|
|
{
|
|
id: 'fake-tracker',
|
|
taskContentResolver: {
|
|
trackerPrefix: 'test',
|
|
invoke: { binary: 'fake-cli', args: ['show', '{{id}}'], timeoutMs: 5000 },
|
|
},
|
|
},
|
|
];
|
|
|
|
let capturedInvocation = null;
|
|
const resolveTaskContentFn = (input) => {
|
|
capturedInvocation = input;
|
|
return {
|
|
kind: 'resolved',
|
|
content: {
|
|
action: 'do the resolved thing',
|
|
verify: 'run the resolved verify',
|
|
acceptanceCriteria: ['criterion a'],
|
|
readFirst: ['README.md'],
|
|
done: 'done marker',
|
|
},
|
|
};
|
|
};
|
|
|
|
const stdout = captureStdout(() => {
|
|
routeResolveContent(
|
|
{
|
|
args: ['task', 'resolve-content', '--plan', '01-PLAN.md', '--task-id', 'test:1'],
|
|
cwd: dir,
|
|
raw: true,
|
|
},
|
|
{ loadCapabilities: () => fakeCapabilities, resolveTaskContentFn },
|
|
);
|
|
});
|
|
|
|
assert.strictEqual(capturedInvocation.trackerId, 'test:1');
|
|
assert.deepStrictEqual(capturedInvocation.capabilities, fakeCapabilities);
|
|
|
|
const printed = JSON.parse(stdout);
|
|
assert.strictEqual(printed.resolved, true);
|
|
assert.strictEqual(printed.content.action, 'do the resolved thing');
|
|
assert.strictEqual(printed.content.verify, 'run the resolved verify');
|
|
assert.deepStrictEqual(printed.content.acceptanceCriteria, ['criterion a']);
|
|
assert.deepStrictEqual(printed.content.readFirst, ['README.md']);
|
|
assert.strictEqual(printed.content.done, 'done marker');
|
|
});
|
|
|
|
test('hard-halt: a thrown ResolverFailedError becomes a non-zero exit, never {resolved:false}', (t) => {
|
|
const dir = createTempDir('gsd-resolve-content-hardhalt-');
|
|
t.after(() => cleanup(dir));
|
|
writePlan(dir, RESOLVABLE_TASK);
|
|
|
|
const fakeCapabilities = [
|
|
{
|
|
id: 'fake-tracker',
|
|
taskContentResolver: {
|
|
trackerPrefix: 'test',
|
|
invoke: { binary: 'fake-cli', args: ['show', '{{id}}'], timeoutMs: 5000 },
|
|
},
|
|
},
|
|
];
|
|
|
|
let thrown = null;
|
|
const stdout = captureStdout(() => {
|
|
try {
|
|
routeResolveContent(
|
|
{
|
|
args: ['task', 'resolve-content', '--plan', '01-PLAN.md', '--task-id', 'test:1'],
|
|
cwd: dir,
|
|
raw: true,
|
|
},
|
|
{
|
|
loadCapabilities: () => fakeCapabilities,
|
|
resolveTaskContentFn: () => {
|
|
throw new ResolverFailedError('fake-cli', 1, 'boom');
|
|
},
|
|
},
|
|
);
|
|
} catch (err) {
|
|
thrown = err;
|
|
}
|
|
});
|
|
assert.ok(thrown instanceof ExitError, `expected ExitError, got ${thrown}`);
|
|
assert.strictEqual(stdout, '', 'resolver failure must never write a JSON {resolved:false} answer to stdout');
|
|
});
|
|
|
|
test('path traversal: --plan escaping the project root -> USAGE, non-zero exit, no filesystem read', (t) => {
|
|
const dir = createTempDir('gsd-resolve-content-traversal-');
|
|
t.after(() => cleanup(dir));
|
|
|
|
const escapingPath = '../../../etc/passwit';
|
|
let thrown = null;
|
|
const stderr = captureStderr(() => {
|
|
try {
|
|
routeResolveContent({
|
|
args: ['task', 'resolve-content', '--plan', escapingPath, '--task-id', 'test:1'],
|
|
cwd: dir,
|
|
raw: false,
|
|
});
|
|
} catch (err) {
|
|
thrown = err;
|
|
}
|
|
});
|
|
assert.ok(thrown instanceof ExitError, `expected ExitError, got ${thrown}`);
|
|
assert.strictEqual(thrown.code, 1);
|
|
assert.ok(
|
|
stderr.includes('outside project scope') && stderr.includes(escapingPath),
|
|
`expected an outside-project-scope rejection naming the path on stderr, got: ${stderr}`,
|
|
);
|
|
});
|
|
|
|
test('not-applicable: task-id with no ":" -> {resolved:false}, no reason field', (t) => {
|
|
const dir = createTempDir('gsd-resolve-content-na-');
|
|
t.after(() => cleanup(dir));
|
|
writePlan(dir, '<task type="auto" tracker-id="notrackerprefix"><name>y</name></task>');
|
|
|
|
const stdout = captureStdout(() => {
|
|
routeResolveContent(
|
|
{
|
|
args: ['task', 'resolve-content', '--plan', '01-PLAN.md', '--task-id', 'notrackerprefix'],
|
|
cwd: dir,
|
|
raw: true,
|
|
},
|
|
{ loadCapabilities: () => [] },
|
|
);
|
|
});
|
|
const printed = JSON.parse(stdout);
|
|
assert.deepStrictEqual(printed, { resolved: false });
|
|
});
|
|
});
|