Files
msd-core/tests/frontmatter-cli.test.cjs
Tom Boucher 9a76ca6783 fix(#1882): distinguish unterminated frontmatter from absent frontmatter (#2712)
* fix(#1882): distinguish unterminated frontmatter from absent frontmatter

extractFrontmatter returned {} both for a document with no frontmatter and for
one whose fence was opened and never closed, so a file truncated mid-write was
byte-identical to a legitimate no-metadata file. Verified live through
`gsd-tools frontmatter get`: both printed {} with exit 0 and nothing on stderr.

Per ADR-1411's "corrupt is not absent" amendment the {} return is preserved
exactly -- no caller may break -- and the cause is surfaced out-of-band as a
deduplicated, unconditional stderr diagnostic. That mechanism lands as a shared
leaf module rather than a per-site copy because three sibling findings in the
same epic need it identically; four hand-rolled copies of one behaviour is the
generative-fix-divergence defect class.

The discriminator is deliberately not "opened but never closed". A Markdown
document whose first line is a thematic break takes that exact branch, so
flagging on the missing fence alone reports corruption on good Markdown -- the
failure mode this class of check has shipped with before. The unterminated
region is instead run through extractFrontmatter's own parser (extracted as
parseYamlRegion so the probe and the real parse can never diverge) and reported
only when it yields at least one key.

Also folds an inline defect found while working: src/config-loader.cts carried
two NUL bytes in the JSDoc added by this epic's Phase 1 (3eb1cede2), making it
the only non-text file under src. file(1) reported it as data and text tools
silently skipped it, defeating the audit rule that says to search the authored
source; tsc passed because the bytes sat inside a comment, so no gate caught it.
It is live on next.

Refs #1879

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* test(#1882): pin unterminated-frontmatter detection and its negative space

Covers the discriminator on both sides. The positive rows are the issue's own
repro (LF and CRLF) plus the key-count boundary 0/1/2 around the ">= 1 parsed
key" threshold. The negative rows are the documents that reach the same branch
and must stay silent -- above all a Markdown thematic break at byte 0, which is
how this class of check has previously shipped a false positive on valid
Markdown.

Deduplication is tested on both halves of the composite key: a repeat of the
same (path, cause) is suppressed, a genuine second failure in a different file
is not, and a Windows and POSIX spelling of one path resolve to a single key.
The reset seam is asserted to actually clear -- #2674 is the precedent where a
reset that silently failed to clear made every later dedup assertion a vacuous
pass, and the cases only passed because each happened to pick an unused key, so
every case here uses a path unique to itself.

Assertions are on typed surfaces throughout -- the frozen reason enum and the
dedup-set size -- never on diagnostic prose. The one CLI-level case asserts a
differential between two runs (whether stderr is empty) rather than matching a
message, and is the wired user-reachable surface for this fix. Stream failure is
injected by overriding process.stderr.write and restoring it, never chmod 0o000,
which root bypasses.

Two properties guard the ~50 call sites of the changed function: the new
optional path argument is inert with respect to the parsed value, and LF/CRLF
spellings of a document still parse identically.

Refs #1879

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix(#1882): raise the truncation threshold and repair the dedup key

Isolated adversarial review found the one-key discriminator false-positives on
ordinary Markdown: a thematic break above a single labelled line -- `Note:`,
`Author:`, `TODO:`, `See:` -- parses as exactly one key and was reported as
corruption, which is the precise failure the design claimed to prevent and the
changeset promised was fixed. The threshold is now two keys. A file truncated
after exactly one key becomes a false negative; that is the same
precision-over-recall direction already taken at zero keys, and every GSD
artefact this guards carries two or more frontmatter keys.

Three dedup-key defects, each of which could silently swallow a real diagnostic:

- Backslash normalization is removed. A backslash is a legal filename character
  on Linux and macOS, so folding it to a forward slash made two genuinely
  different files share one key. Two spellings of one Windows path may now
  report twice; two distinct files can never silence each other. Lost signal is
  the worse failure.
- The key namespaces are tagged so a file literally named like the unnamed
  digest fallback can no longer collide with a path-less caller whose content
  hashes to that digest -- computable for any predictable content, no brute
  force needed.
- The source identity is computed once rather than hashed twice per emission.

Corrects the previous commit. The two NUL bytes in src/config-loader.cts were
NOT in a JSDoc comment as that message claimed; they were deliberate separators
in the live dedup key, and stripping them degraded it to bare concatenation.
They are restored as escape sequences -- byte-identical runtime string, and the
file is text again so grep can see it. The diagnostic script that misled me
indexed a character-offset string with a byte offset.

Also threads sourcePath through the STATE.md and PLAN.md readers so the two
artefacts epic #1879 is actually about name their file rather than reporting
under a content digest.

Refs #1879

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* test(#1882): correct fixtures and assertions left behind by the review fixes

The previous commit changed two behaviours deliberately and the suite still
encoded the old ones, so gsd-test came back red with six failures across both
lanes -- all of them mine.

Fixtures carrying a single frontmatter key no longer clear the two-key
truncation threshold, so the CLI differential and the two path-less dedup cases
were asserting a diagnostic that is now correctly withheld. They now carry two
keys, which is what a real interrupted write of a GSD artefact looks like.

The Windows/POSIX case asserted that two spellings of one path collapse to a
single key -- the exact folding that was removed because it also collapsed
genuinely distinct POSIX files whose names contain a backslash. Inverted to
assert they now report separately, with the reasoning recorded inline so the
trade is not silently reversed later: mild duplicate noise on one Windows path
is acceptable, a swallowed diagnostic is not.

Refs #1879

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix(#1882): name the file at every read site, and report each file once

The diagnostic reached only the four frontmatter CLI verbs, so ~47 of 53 call
sites reported a truncated file under an anonymous content digest instead of
naming it. Since naming the file is the whole point -- it is what an operator
can act on -- that was a gap in the deliverable, not a scoping choice. 43 of 53
sites now pass the resolved path.

Closing it surfaced a defect the original design missed. A single truncated
STATE.md is parsed twice in a normal run: once by the read wrapper, which holds
the path, and again by a pure core downstream, which is handed only the string
and cannot know it. Those two parses keyed separately, so one file produced two
diagnostics -- and wiring more sites made the collision more likely, not less.
Every emission now registers both identities the input could be known by and
checks both before writing, so whichever caller arrives first speaks and the
other is suppressed. Distinct files with distinct content still report
separately, which is the property ADR-1411 actually requires; two files whose
truncated content is byte-identical collapse to one report, which stays the
documented limit.

Ten call sites deliberately keep no path. Two are frontmatter's own round-trip
checks during set and merge, where passing a path would report on every write.
The other eight are the state-transition pure cores, which ADR-1769 defines as
(content, intent, deps) -> newContent with injected I/O; threading a path
through them would contradict that recorded decision, so it is surfaced rather
than taken unilaterally. With the widened key they no longer double-report, and
in the normal flow the named parse runs first, so the file is still named.

Refs #1879

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix(#1882): inject the STATE.md path into the transition cores

The six state-transition cores parsed STATE.md frontmatter without knowing
which file it came from, so a truncated STATE.md reached the operator as an
anonymous content digest on exactly the artefact epic #1879 is named for.

ADR-1769 section 3 shapes these as (content, intent, deps) -> newContent with
injected deps, and deps is the seam for precisely this: something the core
cannot derive without doing I/O. It already carries roadmapProvider and a
phase-inventory provider on that basis, each documented as injected rather than
imported so the core stays pure and testable without disk access. A resolved
path is data, not I/O, so an optional sourcePath member extends the established
pattern rather than contradicting it, and every existing stub keeps compiling
because the member is optional.

updateCore and reconcileCurrentPosition take no deps and are left alone. With
the widened dedup key they cannot double-report, and in the normal flow the read
wrapper has already named the file by the time they run.

Also regenerates gsd-core/bin/lib/state-transition.cjs. That artifact is tracked
rather than gitignored, unlike most of its siblings, so leaving it stale would
have shipped a runtime without this change to anyone reading the repo without
building. tsc had skipped the re-emit because its incremental build info still
recorded an emit that had since been reverted, so the stale output survived a
clean build; clearing tsconfig.build.tsbuildinfo forced it. The
compiled-artifact-sync gate is what surfaced the drift and now reports all nine
tracked artifacts matching their source.

Refs #1879

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix(#1882): stop the widened dedup key from hiding a second file

The previous commit widened the dedup guard so one file parsed twice -- once by
a read wrapper holding the path, once by a pure core holding only the string --
reported once instead of twice. It did that by checking BOTH keys before
emitting, which silently traded one defect for a worse one: two DIFFERENT files
whose truncated content happened to be byte-identical now collided on the shared
content digest, and the second file's diagnostic was swallowed. That is the
over-coarse keying ADR-1411 explicitly forbids, reintroduced while fixing
something else.

The guard now checks only the key matching what the caller actually knows -- a
named read checks its path key, a path-less read checks its digest key -- while
still recording every key the input could later be identified by. The redundant
path-less re-parse of an already-named file stays silent, and two distinct files
always both report.

Verified across all six orderings: same file named-then-anonymous reports once;
two different files with identical content report twice; two different files
with different content report twice; the same path twice reports once; two
path-less parses of identical content report once; two path-less parses of
different content report twice.

The suite caught this -- twenty failures, all in the unusable-input tests that
reuse one truncated fixture across different paths. The local probe written
alongside the broken change did not, because it compared two files with
different content and could therefore only confirm the expected behaviour.

Refs #1879

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* test(#1882): count diagnostics emitted, not identities interned

The suite measured the size of the dedup set as a stand-in for "how many
diagnostics were emitted". That held only while one emission recorded exactly
one key. Once an emission began recording every identity the input could later
be matched by -- a path key and a content key for the same file -- the set grew
by two per write and twenty assertions read 2 where they expected 1.

The production behaviour was correct throughout; the proxy was not. Set size
counts identities, which is an implementation detail of the guard. The
behavioural claim these tests exist to make is how many diagnostics an operator
actually saw, so the module now exposes that directly as an emission counter and
the suite asserts on it. The set-size accessor stays for assertions genuinely
about key shape.

The local probe written alongside the change did not catch this because it
counted process.stderr.write calls -- the right thing -- while the suite counted
set growth. Verification now asserts both and requires them to agree, so a
future divergence between the counter and real writes fails immediately rather
than being discovered a bench run later.

Refs #1879

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* test(#1882): retire two assertions that outlived the behaviour they described

Both tests encoded assumptions the dedup fix invalidated, and both were caught
by the suite rather than by the probe written alongside the change.

The forged-path case asserted that a file named like the anonymous digest
fallback must not suppress a later path-less report. That premise is gone: an
emission now records every identity its input could be matched by, so ANY named
report of some content silences the anonymous re-parse of that same content --
which is the same-file guard working as intended, and has nothing to do with the
crafted name. The property still worth defending is that a crafted filename can
never silence a real file reported under its own path, so that is what the test
now asserts, with the deliberate suppression documented beside it.

The reset-seam case ended by reading the size of the dedup set and expecting 1.
Set size counts interned identities, not diagnostics written, and one emission
now interns two. It asserts the emission counter for the event and keeps a
weaker set-size check for the interning.

Refs #1879

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix(#1882): close the review findings on the discriminator, dry-run and counter

Three orthogonal review passes ran against the final diff. Their findings:

A labelled preamble under a leading rule was still misreported. Raising the key
threshold to two only moved the boundary, because two colon-labelled lines are
as common in ordinary prose as one -- a document opening with a rule over an
Author and a Reviewed-by line, then prose, was called corrupt. Key count alone
cannot separate the two. What does is what follows: a write interrupted part way
through a frontmatter block ends mid-block, so every line of the region is still
frontmatter-shaped, whereas a document merely opening with a rule goes on to
prose. Both conditions are now required, and each closes a false-positive class
the other leaves open. Nested list values and indented continuations stay
frontmatter-shaped, so legitimate truncations are unaffected.

`state rebuild --dry-run` reported a truncated STATE.md anonymously. The write
path is named only because readModifyWriteStateMd parses with the path first;
the dry-run branch reads the file directly and never did. Dry-run is the
read-only mode an operator reaches for first when they suspect corruption, so it
is the one that most needed to name the file. reconcileCurrentPosition takes the
path as an optional argument now and rebuildCore passes it down. That function
was previously left alone on the grounds that a read wrapper always names the
file first -- this is the flow that disproves it.

The emission counter counted write attempts rather than writes, so on a broken
stderr it claimed a diagnostic had reached the operator when nothing had. It is
incremented only after a write that completed, and the broken-stderr test now
asserts the count as well as the return value.

Two documentation defects. The module described a guarantee it does not keep:
one file yields one diagnostic only when the named read comes first. The reverse
ordering emits twice, and that is deliberate -- a path-less caller cannot
identify its file, so suppressing the later named report would also suppress a
genuine second failure in a different file whenever two files share identical
truncated bytes, which ADR-1411 ranks the worse failure. The comment now states
the asymmetric guarantee and a test pins it. Separately, the CONTEXT.md glossary
entry still described backslash normalization that a later commit removed, and
asserted the opposite of what the tests pin; no lint checks prose against code,
so nothing caught it.

Also converts three body-level try/finally blocks to t.after(), per
CONTRIBUTING.md's rule that try/finally belongs only in helpers with no test
context -- the file's own emissionsDuring helper already did this correctly.

Refs #1879

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* docs(#1882): tell the operator what the truncated-frontmatter warning means

A user who has just seen the new warning is acting, not studying, so this lands
in the How-To quadrant beside the other "if you see X" branches in
debug-a-failed-execution, not in reference or explanation. It gives them what
the warning means for this run, three steps to restore the file, and the fact
that the warning changes no return value or exit code.

It also states the case that matters more than the warning itself: silence does
not prove the file is intact. GSD says nothing when the partial block carries
fewer than two fields or reads as prose, because a Markdown document opening
with a horizontal rule is indistinguishable from one of those. A reader chasing
missing metadata needs to know not to treat quiet as clean. Why that threshold
exists is explanation and deliberately stays out of a how-to.

Refs #1879

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* chore(#1882): backfill changeset pr number to 2712

* test(#1882): constrain each branch of the frontmatter-shape check

CI's mutation gate came in at 61.56 against a threshold of 62, and the surviving
mutants were concentrated in isFrontmatterShaped -- the function added last, in
response to review, and the only one never given tests of its own. It was
exercised solely through extractFrontmatter, which covers the composite decision
but leaves each branch of the predicate unconstrained: drop the blank-line
filter, or any one of the three shape alternatives, and every existing assertion
still passed.

Four cases now pin the halves independently. A blank line inside an interrupted
block must not disqualify it, which constrains the filter and its comparison. An
unindented list item and an indented folded-scalar continuation each exercise one
shape alternative that no other case reaches on its own -- the folded line is
neither a key nor a list item, so it is the only input that distinguishes the
indented branch. And two keys followed by prose must stay silent, which is the
negative half: it fails if the predicate is ever mutated to accept everything,
and it is the case that proves key count alone was never sufficient.

Refs #1879

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* test(#1882): register the unusable-input suite with the frontmatter mutation shard

The mutation gate reported an identical 61.56 across two runs whose only
difference was four added tests. That is the tell: the tests were never
executed. The frontmatter shard runs a fixed file list in stryker.config.mjs and
scripts/mutation-matrix.cjs, and tests/unusable-input.test.cjs was in neither, so
the entire suite covering the new unterminated-fence branch was invisible to the
gate while passing perfectly well in the normal run.

So the score was not measuring weak tests, it was measuring absent ones: #1882
added mutants to frontmatter.cjs and no test in the shard covered them. Both
lists gain the file; the config already notes they must stay in sync.

This is a registration ripple a new test file carries when it covers a
mutation-tracked module, alongside the .gitignore, eslint, inventory, glossary
and size-baseline ripples a new module carries. Nothing warned about it, which
is why two runs were spent before the identical score gave it away.

Refs #1879

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-07-27 16:50:12 -04:00

574 lines
26 KiB
JavaScript

// allow-test-rule: source-text-is-the-product
// Workflow .md / agent .md / command .md / reference .md files — their text
// IS what the runtime loads. Testing text content tests the deployed contract.
// Per CONTRIBUTING.md exception matrix.
/**
* GSD Tools Tests - frontmatter CLI integration
*
* Integration tests for the 4 frontmatter subcommands (get, set, merge, validate)
* exercised through gsd-tools.cjs via execSync.
*
* Each test creates its own temp file, runs the CLI command, asserts output,
* and cleans up in afterEach (per-test cleanup with individual temp files).
*/
const { test, describe, afterEach } = require('node:test');
const assert = require('node:assert/strict');
const fs = require('fs');
const path = require('path');
const os = require('os');
const cp = require('node:child_process');
const { runGsdTools, parseFrontmatter } = require('./helpers.cjs');
// Track temp files for cleanup
let tempFiles = [];
function writeTempFile(content) {
const tmpFile = path.join(os.tmpdir(), `gsd-fm-test-${Date.now()}-${Math.random().toString(36).slice(2)}.md`);
fs.writeFileSync(tmpFile, content, 'utf-8');
tempFiles.push(tmpFile);
return tmpFile;
}
afterEach(() => {
for (const f of tempFiles) {
try { fs.unlinkSync(f); } catch { /* already cleaned */ }
}
tempFiles = [];
});
// ─── frontmatter get ────────────────────────────────────────────────────────
describe('frontmatter get', () => {
test('returns all fields as JSON', () => {
const file = writeTempFile('---\nphase: 01\nplan: 01\ntype: execute\n---\nbody text');
const result = runGsdTools(['frontmatter', 'get', file]);
assert.ok(result.success, `Command failed: ${result.error}`);
const parsed = JSON.parse(result.output);
assert.strictEqual(parsed.phase, '01');
assert.strictEqual(parsed.plan, '01');
assert.strictEqual(parsed.type, 'execute');
});
test('returns specific field with --field', () => {
const file = writeTempFile('---\nphase: 01\nplan: 02\ntype: tdd\n---\nbody');
const result = runGsdTools(['frontmatter', 'get', file, '--field', 'phase']);
assert.ok(result.success, `Command failed: ${result.error}`);
const parsed = JSON.parse(result.output);
assert.strictEqual(parsed.phase, '01');
});
test('returns error for missing field', () => {
const file = writeTempFile('---\nphase: 01\n---\n');
const result = runGsdTools(['frontmatter', 'get', file, '--field', 'nonexistent']);
// The command succeeds (exit 0) but returns an error object in JSON
assert.ok(result.success, 'Command should exit 0');
const parsed = JSON.parse(result.output);
assert.ok(parsed.error, 'Should have error field');
assert.ok(parsed.error.includes('Field not found'), 'Error should mention "Field not found"');
});
test('returns error for missing file', () => {
const result = runGsdTools('frontmatter get /nonexistent/path/file.md');
assert.ok(result.success, 'Command should exit 0 with error JSON');
const parsed = JSON.parse(result.output);
assert.ok(parsed.error, 'Should have error field');
});
test('handles file with no frontmatter', () => {
const file = writeTempFile('Plain text with no frontmatter delimiters.');
const result = runGsdTools(['frontmatter', 'get', file]);
assert.ok(result.success, `Command failed: ${result.error}`);
const parsed = JSON.parse(result.output);
assert.deepStrictEqual(parsed, {}, 'Should return empty object for no frontmatter');
});
});
// ─── frontmatter set ────────────────────────────────────────────────────────
describe('frontmatter set', () => {
test('updates existing field', () => {
const file = writeTempFile('---\nphase: 01\ntype: execute\n---\nbody');
const result = runGsdTools(['frontmatter', 'set', file, '--field', 'phase', '--value', '02']);
assert.ok(result.success, `Command failed: ${result.error}`);
// Read back and verify
const content = fs.readFileSync(file, 'utf-8');
const { extractFrontmatter } = require('../gsd-core/bin/lib/frontmatter.cjs');
const fm = extractFrontmatter(content);
assert.strictEqual(fm.phase, '02');
});
test('adds new field', () => {
const file = writeTempFile('---\nphase: 01\n---\nbody');
const result = runGsdTools(['frontmatter', 'set', file, '--field', 'status', '--value', 'active']);
assert.ok(result.success, `Command failed: ${result.error}`);
const content = fs.readFileSync(file, 'utf-8');
const { extractFrontmatter } = require('../gsd-core/bin/lib/frontmatter.cjs');
const fm = extractFrontmatter(content);
assert.strictEqual(fm.status, 'active');
});
test('handles JSON array value', () => {
const file = writeTempFile('---\nphase: 01\n---\nbody');
const result = runGsdTools(['frontmatter', 'set', file, '--field', 'tags', '--value', '["a","b"]']);
assert.ok(result.success, `Command failed: ${result.error}`);
const content = fs.readFileSync(file, 'utf-8');
const { extractFrontmatter } = require('../gsd-core/bin/lib/frontmatter.cjs');
const fm = extractFrontmatter(content);
assert.ok(Array.isArray(fm.tags), 'tags should be an array');
assert.deepStrictEqual(fm.tags, ['a', 'b']);
});
test('returns error for missing file', () => {
const result = runGsdTools('frontmatter set /nonexistent/file.md --field phase --value "01"');
assert.ok(result.success, 'Command should exit 0 with error JSON');
const parsed = JSON.parse(result.output);
assert.ok(parsed.error, 'Should have error field');
});
test('preserves body content after set', () => {
const bodyText = '\n\n# My Heading\n\nSome paragraph with special chars: $, %, &.';
const file = writeTempFile('---\nphase: 01\n---' + bodyText);
runGsdTools(['frontmatter', 'set', file, '--field', 'phase', '--value', '02']);
const content = fs.readFileSync(file, 'utf-8');
assert.ok(content.includes('# My Heading'), 'heading should be preserved');
assert.ok(content.includes('Some paragraph with special chars: $, %, &.'), 'body content should be preserved');
});
});
// ─── frontmatter merge ──────────────────────────────────────────────────────
describe('frontmatter merge', () => {
test('merges multiple fields into frontmatter', () => {
const file = writeTempFile('---\nphase: 01\n---\nbody');
const result = runGsdTools(['frontmatter', 'merge', file, '--data', '{"plan":"02","type":"tdd"}']);
assert.ok(result.success, `Command failed: ${result.error}`);
const content = fs.readFileSync(file, 'utf-8');
const { extractFrontmatter } = require('../gsd-core/bin/lib/frontmatter.cjs');
const fm = extractFrontmatter(content);
assert.strictEqual(fm.phase, '01', 'original field should be preserved');
assert.strictEqual(fm.plan, '02', 'merged field should be present');
assert.strictEqual(fm.type, 'tdd', 'merged field should be present');
});
test('overwrites existing fields on conflict', () => {
const file = writeTempFile('---\nphase: 01\ntype: execute\n---\nbody');
const result = runGsdTools(['frontmatter', 'merge', file, '--data', '{"phase":"02"}']);
assert.ok(result.success, `Command failed: ${result.error}`);
const content = fs.readFileSync(file, 'utf-8');
const { extractFrontmatter } = require('../gsd-core/bin/lib/frontmatter.cjs');
const fm = extractFrontmatter(content);
assert.strictEqual(fm.phase, '02', 'conflicting field should be overwritten');
assert.strictEqual(fm.type, 'execute', 'non-conflicting field should be preserved');
});
test('returns error for missing file', () => {
const result = runGsdTools(`frontmatter merge /nonexistent/file.md --data '{"phase":"01"}'`);
assert.ok(result.success, 'Command should exit 0 with error JSON');
const parsed = JSON.parse(result.output);
assert.ok(parsed.error, 'Should have error field');
});
test('returns error for invalid JSON data', () => {
const file = writeTempFile('---\nphase: 01\n---\nbody');
const result = runGsdTools(['frontmatter', 'merge', file, '--data', 'not json']);
// cmdFrontmatterMerge calls error() which exits with code 1
assert.ok(!result.success, 'Command should fail with non-zero exit code');
assert.ok(result.error.includes('Invalid JSON'), 'Error should mention invalid JSON');
});
});
// ─── frontmatter validate ───────────────────────────────────────────────────
describe('frontmatter validate', () => {
test('reports valid for complete plan frontmatter', () => {
const content = `---
phase: 01
plan: 01
type: execute
wave: 1
depends_on: []
files_modified: [src/auth.ts]
autonomous: true
must_haves:
truths:
- "All tests pass"
---
body`;
const file = writeTempFile(content);
const result = runGsdTools(['frontmatter', 'validate', file, '--schema', 'plan']);
assert.ok(result.success, `Command failed: ${result.error}`);
const parsed = JSON.parse(result.output);
assert.strictEqual(parsed.valid, true, 'Should be valid');
assert.deepStrictEqual(parsed.missing, [], 'No fields should be missing');
assert.strictEqual(parsed.schema, 'plan');
});
test('reports invalid with missing fields', () => {
const file = writeTempFile('---\nphase: 01\n---\nbody');
const result = runGsdTools(['frontmatter', 'validate', file, '--schema', 'plan']);
assert.ok(result.success, `Command failed: ${result.error}`);
const parsed = JSON.parse(result.output);
assert.strictEqual(parsed.valid, false, 'Should be invalid');
assert.ok(parsed.missing.length > 0, 'Should have missing fields');
// plan schema requires: phase, plan, type, wave, depends_on, files_modified, autonomous, must_haves
// phase is present, so 7 should be missing
assert.strictEqual(parsed.missing.length, 7, 'Should have 7 missing required fields');
assert.ok(parsed.missing.includes('plan'), 'plan should be in missing');
assert.ok(parsed.missing.includes('type'), 'type should be in missing');
assert.ok(parsed.missing.includes('must_haves'), 'must_haves should be in missing');
});
test('validates against summary schema', () => {
const content = `---
phase: 01
plan: 01
subsystem: testing
tags: [unit-tests, yaml]
duration: 5min
completed: 2026-02-25
---
body`;
const file = writeTempFile(content);
const result = runGsdTools(['frontmatter', 'validate', file, '--schema', 'summary']);
assert.ok(result.success, `Command failed: ${result.error}`);
const parsed = JSON.parse(result.output);
assert.strictEqual(parsed.valid, true, 'Should be valid for summary schema');
assert.strictEqual(parsed.schema, 'summary');
});
test('validates against verification schema', () => {
const content = `---
phase: 01
verified: 2026-02-25
status: passed
score: 5/5
---
body`;
const file = writeTempFile(content);
const result = runGsdTools(['frontmatter', 'validate', file, '--schema', 'verification']);
assert.ok(result.success, `Command failed: ${result.error}`);
const parsed = JSON.parse(result.output);
assert.strictEqual(parsed.valid, true, 'Should be valid for verification schema');
assert.strictEqual(parsed.schema, 'verification');
});
test('returns error for unknown schema', () => {
const file = writeTempFile('---\nphase: 01\n---\n');
const result = runGsdTools(['frontmatter', 'validate', file, '--schema', 'unknown']);
// cmdFrontmatterValidate calls error() which exits with code 1
assert.ok(!result.success, 'Command should fail with non-zero exit code');
assert.ok(result.error.includes('Unknown schema'), 'Error should mention unknown schema');
});
test('returns error for missing file', () => {
const result = runGsdTools('frontmatter validate /nonexistent/file.md --schema plan');
assert.ok(result.success, 'Command should exit 0 with error JSON');
const parsed = JSON.parse(result.output);
assert.ok(parsed.error, 'Should have error field');
});
});
// ─── frontmatter set/merge: must_haves object-list preservation (#1572) ──────
// `frontmatter set`/`merge` round-tripped the WHOLE frontmatter through the lossy
// extractFrontmatter → reconstructFrontmatter pair, which flattens must_haves
// object-list items ({path, provides} maps) to scalar strings and re-emits them as a
// malformed inline array — destroying `provides:` whenever an UNRELATED field changed.
// The fix preserves the original raw text for any structurally-unchanged top-level key.
const { parseMustHavesBlock } = require('../gsd-core/bin/lib/frontmatter.cjs');
describe('frontmatter set/merge preserves must_haves object-lists (#1572)', () => {
const ARTIFACTS_PLAN = [
'---',
'phase: 1',
'wave: 1',
'plan: 01-01',
'type: implementation',
'depends_on: []',
'files_modified: []',
'autonomous: true',
'must_haves:',
' artifacts:',
' - path: src/foo.ts',
' provides: the foo',
' - path: src/bar.ts',
' provides: the bar',
'---',
'# body',
'',
].join('\n');
const PROHIBITIONS_PLAN = [
'---',
'phase: 1',
'wave: 1',
'must_haves:',
' prohibitions:',
' - statement: no direct DB calls',
' status: enforced',
' - statement: no print statements',
' status: pending',
'---',
'# body',
'',
].join('\n');
function runAndParse(plan, cmdArgsForFile) {
const file = writeTempFile(plan);
runGsdTools(cmdArgsForFile(file));
const after = fs.readFileSync(file, 'utf-8');
return after;
}
test('set on an unrelated scalar preserves every must_haves.artifacts entry (path + provides)', () => {
const after = runAndParse(ARTIFACTS_PLAN, f => ['frontmatter', 'set', f, '--field', 'wave', '--value', '2']);
assert.deepEqual(
parseMustHavesBlock(after, 'artifacts'),
[
{ path: 'src/foo.ts', provides: 'the foo' },
{ path: 'src/bar.ts', provides: 'the bar' },
],
'must_haves.artifacts object-list must survive a set on an unrelated field (#1572)',
);
});
test('merge of an unrelated field preserves every must_haves.artifacts entry', () => {
const after = runAndParse(ARTIFACTS_PLAN, f => ['frontmatter', 'merge', f, '--data', JSON.stringify({ wave: 2 })]);
assert.deepEqual(
parseMustHavesBlock(after, 'artifacts'),
[
{ path: 'src/foo.ts', provides: 'the foo' },
{ path: 'src/bar.ts', provides: 'the bar' },
],
'must_haves.artifacts object-list must survive a merge of an unrelated field (#1572)',
);
});
test('must_haves.prohibitions object-list is preserved on an unrelated set (same code path)', () => {
const after = runAndParse(PROHIBITIONS_PLAN, f => ['frontmatter', 'set', f, '--field', 'wave', '--value', '2']);
assert.deepEqual(
parseMustHavesBlock(after, 'prohibitions'),
[
{ statement: 'no direct DB calls', status: 'enforced' },
{ statement: 'no print statements', status: 'pending' },
],
'must_haves.prohibitions object-list must survive a set on an unrelated field (#1572)',
);
});
test('round-trip is stable: setting wave twice still preserves artifacts (per-key preservation is idempotent)', () => {
const file = writeTempFile(ARTIFACTS_PLAN);
runGsdTools(['frontmatter', 'set', file, '--field', 'wave', '--value', '2']);
runGsdTools(['frontmatter', 'set', file, '--field', 'wave', '--value', '3']);
const after = fs.readFileSync(file, 'utf-8');
assert.deepEqual(
parseMustHavesBlock(after, 'artifacts'),
[
{ path: 'src/foo.ts', provides: 'the foo' },
{ path: 'src/bar.ts', provides: 'the bar' },
],
'must_haves.artifacts must survive repeated sets on an unrelated field',
);
});
test('directly setting must_haves to a new object-list fails closed instead of emitting [object Object] (#1572 codex review)', () => {
// A CHANGED key whose value is an object-list cannot be faithfully serialized by the
// lossy writer (it would emit "[object Object]"). Rather than silently destroy the
// data, spliceFrontmatter throws — the command fails and the file is left unchanged.
const file = writeTempFile(ARTIFACTS_PLAN);
const result = runGsdTools([
'frontmatter', 'set', file, '--field', 'must_haves',
'--value', JSON.stringify({ artifacts: [{ path: 'src/new.ts', provides: 'new thing' }] }),
]);
assert.ok(
!result.success,
'frontmatter set of a must_haves object-list must fail closed (refuse to emit "[object Object]")',
);
const after = fs.readFileSync(file, 'utf-8');
assert.ok(!/\[object Object\]/.test(after), 'the file must not contain "[object Object]" after a refused set');
assert.deepEqual(
parseMustHavesBlock(after, 'artifacts'),
[
{ path: 'src/foo.ts', provides: 'the foo' },
{ path: 'src/bar.ts', provides: 'the bar' },
],
'the original must_haves.artifacts must be intact after the refused set',
);
});
});
// Bug #1660 — frontmatter set of an object-list field (e.g. must_haves) is a silent no-op
// when the new value's lossy parse projection equals the original's. Folded into the owning
// frontmatter-cli test (no new top-level bug-NNNN file).
describe('Bug #1660: frontmatter set of an object-list field fails closed instead of a silent no-op', () => {
const PLAN_WITH_MUST_HAVES = [
'---', 'phase: 1', 'wave: 1',
'must_haves:', ' artifacts:', ' - path: src/foo.ts', ' provides: the foo',
'---', '# body', '',
].join('\n');
test('setting must_haves to a value that flattens to the original projection fails closed (no silent no-op)', () => {
const file = writeTempFile(PLAN_WITH_MUST_HAVES);
const before = fs.readFileSync(file, 'utf-8');
// New value {artifacts:["path: src/foo.ts"]} — its extractFrontmatter projection equals
// the original's flattened projection, so the set would otherwise be a silent no-op.
const result = runGsdTools(['frontmatter', 'set', file, '--field', 'must_haves', '--value', JSON.stringify({ artifacts: ['path: src/foo.ts'] })]);
const parsed = JSON.parse(result.output);
assert.ok(parsed.error, 'a no-op set of an object-list field must surface an error, not silent {updated:true}');
const after = fs.readFileSync(file, 'utf-8');
assert.equal(after, before, 'the file must be unchanged when the set is refused (no silent partial write)');
});
test('an idempotent set of a scalar (wave, same value) still reports updated (no false positive)', () => {
const file = writeTempFile('---\nphase: 1\nwave: 1\n---\n# body\n');
const result = runGsdTools(['frontmatter', 'set', file, '--field', 'wave', '--value', '1']);
const parsed = JSON.parse(result.output);
assert.equal(parsed.updated, true, 'an idempotent SCALAR set must still report {updated:true} (not fail-closed)');
assert.ok(!parsed.error, 'an idempotent scalar set must not produce an error');
});
test('an idempotent set of a scalar array (tags, same value) still reports updated (no false positive)', () => {
const file = writeTempFile('---\nphase: 1\ntags: ["a","b"]\n---\n# body\n');
const result = runGsdTools(['frontmatter', 'set', file, '--field', 'tags', '--value', '["a","b"]']);
const parsed = JSON.parse(result.output);
assert.equal(parsed.updated, true, 'an idempotent scalar-ARRAY set must still report {updated:true} (arrays round-trip; not fail-closed)');
assert.ok(!parsed.error, 'an idempotent scalar-array set must not produce an error');
});
});
// ─── #1778: thread workflow must use the 1.6 named-flag frontmatter.set form ─
//
// The thread workflow's CLOSE and RESUME branches previously invoked the
// pre-1.6 positional shape (frontmatter.set <file> <field> <value>). Since 1.6
// the dispatcher (gsd-tools.cjs) reads field/value from the named --field/
// --value flags via parseNamedArgs; the positional form leaves field/value
// undefined, cmdFrontmatterSet errors `file, field, and value required`, and
// the status/updated writes are silently skipped — so closing a thread never
// marked it status: resolved and resuming never marked it status: in_progress.
describe('#1778: thread workflow uses the 1.6 named-flag frontmatter.set form', () => {
test('behavioral: named-flag form writes the field; positional form errors and does not mutate', () => {
// 1.6 named-flag form — must succeed and write status: resolved.
const goodFile = writeTempFile('---\nstatus: open\nupdated: "2025-01-01"\n---\n\n# thread body\n');
const good = runGsdTools(['frontmatter', 'set', goodFile, '--field', 'status', '--value', 'resolved']);
assert.ok(good.success, `named-flag form must succeed; stderr: ${good.error}`);
assert.strictEqual(
parseFrontmatter(fs.readFileSync(goodFile, 'utf-8')).status,
'resolved',
'named-flag form must write status: resolved into the file',
);
// Pre-1.6 positional form — must fail with the documented message and NOT mutate.
const badFile = writeTempFile('---\nstatus: open\nupdated: "2025-01-01"\n---\n\n# thread body\n');
const bad = runGsdTools(['frontmatter', 'set', badFile, 'status', 'resolved']);
assert.ok(!bad.success, 'positional form must fail (it is the bug being guarded against)');
assert.ok(
(bad.error + bad.output).includes('file, field, and value required'),
`positional form must error with the documented message; got:\n${bad.error}${bad.output}`,
);
assert.strictEqual(
parseFrontmatter(fs.readFileSync(badFile, 'utf-8')).status,
'open',
'positional form must NOT mutate the file (the silent-failure bug)',
);
});
test('workflow parity: no gsd-core/workflows/*.md emits the positional frontmatter.set form', () => {
const workflowsDir = path.join(__dirname, '..', 'gsd-core', 'workflows');
const files = fs.readdirSync(workflowsDir).filter((f) => f.endsWith('.md'));
assert.ok(files.length > 0, 'expected at least one workflow under gsd-core/workflows/');
const offenders = [];
for (const name of files) {
const full = path.join(workflowsDir, name);
const lines = fs.readFileSync(full, 'utf-8').split(/\r?\n/);
lines.forEach((line, i) => {
// Match any frontmatter.set invocation (dot or space form, with or
// without the `gsd_run query` prefix). The 1.6 contract requires
// --field AND --value on every set call; a set line missing --field
// is the pre-1.6 positional form (#1778).
if (!/frontmatter[.\s]+set\b/.test(line)) return;
if (!/--field\b/.test(line) || !/--value\b/.test(line)) {
offenders.push(`${name}:${i + 1}: ${line.trim()}`);
}
});
}
assert.deepStrictEqual(
offenders,
[],
`These workflow frontmatter.set invocations are missing the 1.6 --field/--value named flags (the #1778 positional-form bug):\n ${offenders.join('\n ')}\n\nUse: gsd_run query frontmatter.set <file> --field <field> --value <value>`,
);
});
test('thread workflow CLOSE writes status: resolved and RESUME writes status: in_progress via named flags', () => {
const src = fs.readFileSync(path.join(__dirname, '..', 'gsd-core', 'workflows', 'thread.md'), 'utf-8');
// CLOSE mode: status resolved + updated, both via named flags.
assert.ok(
/frontmatter\.set\s+\S*\.planning\/threads\/\{SLUG\}\.md\s+--field\s+status\s+--value\s+resolved\b/.test(src),
'CLOSE mode must invoke: frontmatter.set .planning/threads/{SLUG}.md --field status --value resolved',
);
assert.ok(
/frontmatter\.set\s+\S*\.planning\/threads\/\{SLUG\}\.md\s+--field\s+updated\s+--value\s+YYYY-MM-DD\b/.test(src),
'CLOSE mode must invoke: frontmatter.set .planning/threads/{SLUG}.md --field updated --value YYYY-MM-DD',
);
// RESUME mode: status in_progress + updated, both via named flags.
assert.ok(
/frontmatter\.set\s+\S*\.planning\/threads\/\{SLUG\}\.md\s+--field\s+status\s+--value\s+in_progress\b/.test(src),
'RESUME mode must invoke: frontmatter.set .planning/threads/{SLUG}.md --field status --value in_progress',
);
});
});
// ─── #1882: the user-reachable surface actually distinguishes the two cases ───
describe('frontmatter get — truncated vs absent frontmatter (#1882)', () => {
const TOOLS = path.join(__dirname, '..', 'gsd-core', 'bin', 'gsd-tools.cjs');
function runCapturingStderr(file) {
const r = cp.spawnSync(process.execPath, [TOOLS, 'frontmatter', 'get', file, '--raw'], {
encoding: 'utf8',
env: { ...process.env, GSD_TEST_MODE: '1' },
});
return { status: r.status, stdout: (r.stdout || '').trim(), stderr: (r.stderr || '').trim() };
}
// This is the wired keystone for #1882: the diagnostic is only "delivered" if it reaches
// the surface a user actually invokes. The assertion is a DIFFERENTIAL between two runs —
// whether stderr is empty — which is a behavioural claim, not a match against the message
// wording, so it stays inside CONTRIBUTING.md's ban on raw text matching.
test('a truncated file is reported while an absent-frontmatter file stays silent', () => {
const truncated = writeTempFile('---\nphase: 01\nplan: half-written\n');
const absent = writeTempFile('plain body with no frontmatter\n');
const bad = runCapturingStderr(truncated);
const good = runCapturingStderr(absent);
// The contract every one of the ~50 callers depends on is unchanged for both.
assert.strictEqual(bad.status, 0, 'truncated file must not change the exit code');
assert.strictEqual(good.status, 0);
assert.deepStrictEqual(JSON.parse(bad.stdout), {}, 'return value must be preserved');
assert.deepStrictEqual(JSON.parse(good.stdout), {});
// ...and the only difference is that corruption is no longer silent.
assert.notStrictEqual(bad.stderr, '', 'a truncated frontmatter must be reported');
assert.strictEqual(good.stderr, '', 'a file with no frontmatter is not corrupt');
});
test('a Markdown thematic break at byte 0 is not reported as corruption', () => {
const thematicBreak = writeTempFile('---\nSome heading text\n\nA paragraph, no more dashes.\n');
const r = runCapturingStderr(thematicBreak);
assert.strictEqual(r.status, 0);
assert.deepStrictEqual(JSON.parse(r.stdout), {});
assert.strictEqual(r.stderr, '', 'a horizontal rule is valid Markdown, not a truncated file');
});
});