* test(#1168): make phase-6 gate un-gameable — reject empty stubs + require loop shrink The migration assertion previously checked only role==feature, so a registration-only stub (empty hooks, logic left inline) would turn the gate green while phase 6 stayed incomplete — the exact false-completion pattern this gate exists to prevent. Strengthen it: each ADR-named feature must OWN its behavior (>=1 hook, or a command family); and plan-phase.md/execute-phase.md must shrink strictly below their frozen pre-phase-6 sizes (94519/93166 LF bytes), which also defeats double-run gaming (declare a hook but keep the inline block -> file does not shrink -> red). Gate now 5 pass / 4 fail (orphaned execute:wave:post, empty/unregistered features, config-key leaks, no shrink). Green is now reachable only by REAL migration. Refs #1168, #1169. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * feat(#1169): migrate gap-analysis to a Capability (plan:post gate) First real ADR-857 phase-6 migration (pattern-defining tracer). gap-analysis moves from an inline post_planning_gaps branch in plan-phase.md to a real plan:post gate Capability: - capabilities/gap-analysis/capability.json: role:feature, plan:post gate (when=workflow.post_planning_gaps, blocking:false advisory), OWNS workflow.post_planning_gaps (federated out of central schema). - plan-phase.md: inline config-get + gsd_run gap-analysis block replaced with a plan:post render-hooks call site dispatching the gate; file shrinks 94519->93279. - src/check-command-router.cts: cmdGapAnalysisPlanPost runs the real gap analysis via gap-checker. - post_planning_gaps removed from central manifest; resolves via federated config (default true preserved). - tests/post-planning-gaps-2493: re-pointed to assert capability ownership. Verified: gate 5 pass / 4 fail (gap-analysis cleared from migration, plan:post-orphan, config-leak, and plan-phase shrink checks); loadConfig still returns post_planning_gaps=true; check command runs real analysis; 392/392 in the config/registry/federation/router net. Refs #1169. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * feat(#1169): migrate profile-pipeline to a command-family Capability ADR-857 Decision 7: profile-pipeline becomes a command-family Capability (like audit/intel/graphify). capabilities/profile-pipeline/capability.json declares an 8-command family (scan-sessions, extract-messages, profile-sample, write-profile, profile-questionnaire, generate-dev-preferences, generate-claude-profile, generate-claude-md) backed by a new gsd-core/bin/lib/profile-pipeline-command-router.cjs; the inline case arms are removed from gsd-tools.cjs. Owns profile-pipeline.enabled (federated). Verified: registry shows role:feature with commands.length=8; scan-sessions/profile-sample run live via the family; gate cleared profile-pipeline from the empty-stub failure (only tdd/schema-gate/drift remain); 296/296 registry+inventory+gsd-tools tests; lint 0 errors. Refs #1169. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * fix(#1167): wire execute:wave:post + implement ui.safety-gate check Revives the second dead gate from #1167: ui.gates@execute:wave:post was declared but never dispatched AND its check.query (ui.safety-gate) was unimplemented. Adds the per-wave execute:wave:post render-hooks call site in execute-phase.md (fires after each wave's merge/cleanup, before the next forks) and implements cmdUiSafetyGate (frontend + UI-SPEC aware, mirrors cmdUiPlanGate) in check-command-router. +17 regression tests. Verified: phase-6 orphaned-points conformance test now PASSES (gate 6 pass / 3 fail); ui-safety-gate routable in dot+hyphen forms; check-ui-safety-gate 17/17, check-ui-plan-gate 18/18; lint 0 errors. Refs #1167, #1168. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * feat(#1169): migrate drift (schema + codebase) to execute:wave:post gates Removes the inline schema_drift_gate + codebase_drift_gate steps (77 lines) from execute-phase.md; drift becomes a Capability with two execute:wave:post gates (verify.schema-drift blocking, verify.codebase-drift advisory) dispatched via the per-wave render-hooks call site. check-command-router routes verify.schema-drift / verify.codebase-drift to the real detectors. Federates workflow.drift_threshold / drift_action / schema_drift_gate out of central. Also fixes the execute:wave:post dispatch prose to run NON-blocking (advisory) gates too — the prior version only ran blocking gates, which would have silently dropped the codebase-drift advisory after its inline step was removed. Behavior preserved. Verified: gate 7 pass / 2 fail (drift cleared from stub + config-leak; execute-phase.md 92297 < 93166 frozen -> shrink passes); both drift checks run real detection; loadConfig defaults preserved (threshold=3, action=warn, gate=true); drift-detection 56/56 + schema-drift 34/34; lint 0 errors. Refs #1169. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * feat(#1169): migrate tdd to a Capability (plan:pre contribution + execute:post gate) tdd becomes a real Capability: a plan:pre contribution injects the <tdd_mode_active> planner guidance (rendered from PLAN_PRE_HOOKS_JSON like security's contribution), and an execute:post gate (tdd.review-checkpoint, advisory) runs the real end-of-phase RED/GREEN review via a new check-command handler. Inline tdd_mode reads + the inline planner block + the tdd_review_checkpoint step are removed; workflow.tdd_mode is federated out of central. The MVP+TDD per-task RED-commit gate is preserved — TDD_MODE is now derived from the execute:post hooks (capId==tdd active), not an inline config-get. BEHAVIOR CHANGE (documented, not silent): the --tdd CLI flag now persists workflow.tdd_mode=true via config-set instead of being per-invocation. Rationale: tdd is now a config-toggled Capability, and env vars do not persist across the workflow's separate bash blocks (config does), so an ephemeral override isn't cleanly achievable; --tdd therefore enables the tdd capability, consistent with how all capabilities are toggled. Verified: gate 7 pass / 2 fail (tdd cleared from stub + config-leak; plan-phase + execute-phase both < frozen sizes); contribution injection + execute:post gate dispatch wired; MVP+TDD gate preserved; tdd.review-checkpoint runs real review; full unit suite 556/0; lint 0 errors. Refs #1169. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * feat(#1169): migrate schema-gate to a plan:pre contribution Capability The plan-time schema-push detection (former plan-phase.md §5.7) becomes a schema-gate Capability: a plan:pre contribution (into:planner, when:workflow.schema_push_detection) whose fragment carries the full ORM-detection + [BLOCKING] schema-push-task injection logic, rendered into the planner via the existing plan:pre render-hooks dispatch. The inline §5.7 block is removed (plan-phase.md 94519->90445). workflow.schema_push_detection is a new capability-owned (federated) key, default true. (The execute-side schema-drift gate was migrated separately into the drift capability.) Verified: registry inlines the fragment (len 2704) so it is actually delivered at plan:pre; gate 8 pass / 1 fail — all 5 ADR-named features now real Capabilities, only the config-leak test remains (intel/security, next unit). Refs #1169. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * feat(#1169): close the 3 capability config-key leaks — phase-6 gate now GREEN Removes the last inline config-get reads of capability-owned keys from plan-phase.md. security_asvs_level/security_block_on now flow through the security plan:pre contribution via a new loop-resolver configValues mechanism (resolves declared config keys with the same 4-level precedence as activation and attaches them to the rendered hook); the §5.55 banner reads them from PLAN_PRE_HOOKS_JSON. intel.enabled becomes a real intel plan:pre step (ref.command: intel api-surface) dispatched via render-hooks; the inline intel branch is gone. gen-capability-registry now validates ref.command as a third dispatch shape. Verified: phase-6 capstone conformance gate is FULLY GREEN (9/0); 3 leaks gone (grep=0); security configValues resolve to {2,medium}/default {1,high}; intel step present only when enabled; loop-render-hooks 62/0, capability-registry 287/0, capability-state/federated-config 113/0; lint 0 errors. Closes the migration half of #1169. Refs #1139, #1167, #1168. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * fix(#1169): address adversarial review — restore schema-drift block, generic planner injection, uniform gate contract Adversarial review caught 2 real regressions the green gate missed: (1) schema-drift no longer blocked — the execute:wave:post dispatch read GATE_RESULT.block but verify.schema-drift emitted drift_detected/blocking, and onError:skip wrongly bypassed positive blocks; (2) only tdd's plan:pre contribution was injected into the planner, dropping schema-gate's schema-push detection and security's threat-model guidance. Fixes: (A) every gate check returns a uniform boolean 'block' under --raw (the dispatch form), with advisory gates (tdd/gap) carrying their report in 'message'; (B) gate-dispatch contract corrected at all sites — onError governs command errors only, a blocking gate's positive block always halts; (C) generic planner injection of all plan:pre contributions where into=='planner' (tdd + schema-gate + security incl configValues); (D) two new conformance assertions: planner contributions injected generically + every gate check.query returns boolean block under --raw. Verified: gate 11/11; all 6 gate checks return boolean block under --raw; full suite 595/0; lint 0 errors. Refs #1167, #1168, #1169. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * fix(#1169): restore MVP+TDD end-of-phase blocking escalation (2nd adversarial pass) The migrated tdd execute:post gate is statically blocking:false, but the contract (references/execute-mvp-tdd.md + CONTEXT.md) requires the end-of-phase TDD review to ESCALATE from advisory to blocking when MVP_MODE && TDD_MODE && a TDD plan misses a RED/GREEN commit. The migration prose had downgraded this to a 'strong advisory recommendation' — silent loss of the blocking escalation. Restore it: the tdd-gate dispatch now refuses to mark the phase complete (Phase blocked message) under MVP+TDD when GATE_RESULT.block is true; advisory otherwise. Also strengthen tests/execute-mvp-tdd-gate.test.cjs: hasBlockingEscalation previously matched any line with 'blocking'+'mvp+tdd' (so 'advisory (blocking: false) ... under MVP+TDD' was a false green); now it requires the real refusal semantics ('refuse to mark the phase complete' / 'phase blocked'). Caught by 2nd adversarial review pass. Verified: execute-phase.md 92702 < 93166 frozen; mvp-tdd-gate + phase-6 gate 19/0; full suite green; lint 0 errors. Refs #1169. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * fix(#1169): restore MVP+TDD proceed-block, codebase auto-remap, schema skip-flag (3rd adversarial pass) 3rd adversarial pass found 4 more silent regressions: (1) the tdd MVP+TDD 'refuse to mark complete' was nullified by a downstream 'ALWAYS proceed regardless of gate results' line — proceed is now conditional (stops on an active MVP+TDD block); (2) the test now asserts the proceed is NOT an unconditional override; (3) codebase-drift auto-remap (spawn gsd-codebase-mapper when drift_action=auto-remap) was dropped — the execute:wave:post advisory dispatch now consumes spawn_mapper/directive; (4) GSD_SKIP_SCHEMA_CHECK bypass was lost from the gate path — cmdVerifySchemaDrift now honors the env var (block:false when set). Verified: no unconditional proceed; GSD_SKIP_SCHEMA_CHECK=true -> block:false; gate 11/11 + mvp-tdd 9/9; full suite 569/0; lint 0; execute-phase.md 93109 < 93166. Refs #1169. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * fix(#1169): init.cts reads federated config keys from nested path (4th adversarial pass) Config federation moved tdd_mode/research/nyquist_validation from flat config.<key> to nested config.workflow.<key>, but src/init.cts still read them flat — so init.plan-phase/init.execute-phase emitted tdd_mode:false / research_enabled:undefined / nyquist:undefined regardless of config (a public command-contract regression; the migrated loops use render-hooks so enforcement was unaffected). Read via config.workflow (type-safe Record cast). Now init reflects the same resolved values + federated defaults (research/nyquist default true) as the render-hooks path. Verified: build clean; init.plan-phase emits tdd_mode:true/research:false/nyquist:false for set config, defaults true for empty; full suite 591/0; lint 0. Refs #1169. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * docs(#1169): add changeset for ADR-857 phase-6 completion (PR #1183) Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * fix(#1169): complete phase-6 migration fallout — restore TEXT_MODE, fix registry .claude leak, re-point stale workflow-contract tests The capability migration left real regressions and stale consumer tests that the per-module unit suite missed but the full cross-platform suite caught (27 failing tests): Real source regressions (fixed): - execute-phase.md lost its AskUserQuestion TEXT_MODE plain-text fallback when the inline schema_drift_gate step was removed — non-Claude runtimes would stall. Restored, and the execute:post gate-dispatch prose de-duplicated to cite the execute:wave:post contract (loop body shrinks below the frozen pre-phase-6 ceiling while keeping every onError/blocking nuance). - capabilities/tdd inline fragment hardcoded `@~/.claude/gsd-core/references/tdd.md`, baked verbatim into the committed capability-registry.cjs and leaked the install path on 11 non-Claude runtimes (registry .cjs is copied, not path-converted). Made the fragment path-free; regenerated the registry. The phase-6 conformance gate now guards this (no ~/.claude install path in any capability source or the generated registry). - plan-phase.md: removed a §5.7 stub re-added in error and routed Branch 2 to step 6 (schema-gate is a plan:pre capability, §5.7 is gone). Stale workflow-contract tests re-pointed to the capability dispatch they now must assert (behavior verified preserved in source first, assertions kept equal-or-stronger): bug-621 + bug-2851 (gap-analysis via gsd_run render-hooks plan:post + registry binding), feat-2527 (tdd_mode federated out of central), phase6-planning + plan-phase-ui-redirect (§5.6 bounded by ## 6.), plan-phase-drift-guard (intel when:intel.enabled skip branch). profile-pipeline-command-router.cjs un-ignored from eslint (hand-written, no TS source) + stale disable comments removed. Size baseline regenerated. Verified: full suite 15140 tests / 0 fail; lint 0 errors; conformance gate green legitimately. Refs #1139, #1167, #1168, #1169. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * test(#1169): add ADR-857 E2E content-test coverage for the 12 loop points + capability deliverables Grounds the capability engine in behavioral E2E tests (drive the real render-hooks/check CLI + the real registry, assert typed result content — no source-grep), structured around what ADR-857 says to deliver. 207 tests; each genuineness-checked (flip the expectation, confirm it fails). Per-loop-point dispatch (7 files): empty-point negative-space across the 6 no-hook points; verify:post 3-step resolution+ordering+onError; plan:pre contribution/configValues + ui.plan-gate + intel; plan:post gap-analysis; execute:wave:post drift+ui gates via the check route (schema-drift block/skip, codebase-drift threshold BVA, auto-remap); execute:post tdd.review-checkpoint RED/GREEN; ship:pre security gate resolution + frontmatter-get predicate pieces. ADR-deliverable coverage (4 files): predicate boundary held (edge/prohibition probes stay core, not off-by-default Feature Capabilities — phase-6 exception); core loop runs with zero capabilities (all 12 points empty, init bundles resolve); contribution merge (multiple ordered <contribution from=> blocks); federated-config key removal on uninstall. federated-config allowlisted for its 3-file split (unit + integration + lifecycle). Refs #1139, #1167, #1168, #1169. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * fix(#1169): remove dead drifted converter dups + address adversarial review Lint cleanup (root-caused, not waved off): src/runtime-artifact-conversion.cts carried 11 agent-converter functions (+5 orphaned consts/helpers) that were never exported, never called, and had silently DRIFTED from the live hand-authored copies in bin/install.js (one even referenced an undefined `claudeToCopilotTools`). Deleted the dead duplicates; install.js's live copies are untouched (it never imported these). Lint now 0 errors / 0 warnings. Adversarial-review (Codex) findings fixed: - HIGH: execute-phase.md TDD_MODE used `jq ... || echo false`, silently disabling the MVP+TDD blocking gate on jq-less runtimes. Reverted to the `node -e` form (node is guaranteed; matches the file's other node-e usages) so a missing optional tool can no longer fail-open a blocking safety path. - MEDIUM: federated-config-key-removal orphan-key test was vacuous (it skipped the orphan assertion). Now asserts the removed capability's key is genuinely not surfaced/validated after uninstall. - LOW: phase-6 conformance leak regex broadened to catch absolute-home and Windows-backslash `.claude/(gsd-core|commands|agents|hooks)` paths, not only `~`/`$HOME` forward-slash forms. - LOW: bug-2851 plan:post dispatch assertion now requires `--raw` (matched its stated contract). - nit: plan-pre intel-step test duplicate assertion replaced with a distinct structured-output check. Size baseline regenerated (execute-phase.md 93089 < 93166 frozen). Refs #1167, #1169. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * test(#1169): make runtime-homes-descriptor-drive titles environment-independent The descriptor-equivalence test embedded the absolute golden config path (`os.homedir()`-derived) directly in each `test(...)` title, so titles differed between macOS (`/Users/x/.claude`) and Docker (`/home/gsdtest/.claude`). Every test PASSES on both platforms (15885/0 leaf tests each), but gsd-test-summary compares results by title and reported 29+29 false "only in Mac / only in Docker" discrepancies for tests that actually pass everywhere. Move the golden path out of the title and into the assertion message (still shown on failure); titles are now byte-identical across platforms so the cross-platform comparator matches them. No assertion logic or golden values changed. Refs #1169. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * fix(#1169): derive TDD_MODE via gsd_run --active-cap, not node -e (fix prompt-injection CI gate) The prior fix reverted execute-phase.md:181 from jq to `node -e` to close a Codex HIGH (jq||echo-false silently disabling the MVP+TDD blocking gate on jq-less runtimes) — but the CI prompt-injection scanner BLOCKS new `node -e` in workflow markdown (inline code-exec = injection vector), turning the security gate red. Both forms were wrong: node -e fails the scanner; jq fail-opens a blocking safety gate; `config-get workflow.tdd_mode` is forbidden by the conformance leak gate (tdd_mode is capability-owned). Correct fix (what Codex recommended): a gsd_run-native boolean. Add an `--active-cap <capId>` flag to `loop render-hooks <point>` that resolves hooks the normal way and prints exactly `true`/`false` for whether a capId is active — scanner-safe (canonical launcher, no inline code), node-reliable (no optional jq to fail-open), and leak-free (render-hooks resolution, not config-get). execute-phase.md:181 now `TDD_MODE=$(gsd_run loop render-hooks execute:post --active-cap tdd)`. +5 behavioral tests for the flag. Verified: prompt-injection-scan --diff origin/next → 0 findings; conformance gate 13/13 (execute-phase.md 92934 < 93166); execute-mvp-tdd + tdd-mode + loop-render-hooks 87/0; lint 0/0. Refs #1167, #1169. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
751 lines
39 KiB
JavaScript
751 lines
39 KiB
JavaScript
'use strict';
|
|
/**
|
|
* E2E content tests for the GSD capability engine — ADR-857 phase 6
|
|
*
|
|
* Hook points tested: discuss:pre, discuss:post, execute:pre, execute:wave:pre,
|
|
* verify:pre, ship:post
|
|
*
|
|
* All 6 points have zero hooks in the real registry by design.
|
|
* Tests pin: exact envelope shape, placeholder string contract (Hyrum's Law),
|
|
* resolver-filter mechanics (schema default / config-override / capabilityStatesById),
|
|
* CLI contract (missing-arg, invalid-point), and Postel-leniency (malformed config).
|
|
*
|
|
* Rules:
|
|
* - Every test drives a real command (CLI subprocess or real resolver + real registry).
|
|
* - No readFileSync(...).includes() source-grep.
|
|
* - Negative/BVA cases assert the SPECIFIC differing value so regression is caught.
|
|
* - Each test is independently isolated with its own temp dir.
|
|
*/
|
|
|
|
const { describe, it, before, after } = require('node:test');
|
|
const assert = require('node:assert/strict');
|
|
const fs = require('node:fs');
|
|
const os = require('node:os');
|
|
const path = require('node:path');
|
|
const { spawnSync } = require('node:child_process');
|
|
|
|
const { cleanup } = require('./helpers.cjs');
|
|
|
|
const GSD_TOOLS = path.join(__dirname, '..', 'gsd-core', 'bin', 'gsd-tools.cjs');
|
|
const realRegistry = require('../gsd-core/bin/lib/capability-registry.cjs');
|
|
const { resolveLoopHooks, renderLoopHooks } = require('../gsd-core/bin/lib/loop-resolver.cjs');
|
|
|
|
// ─── Fixture helpers ──────────────────────────────────────────────────────────
|
|
|
|
/** Create a bare temp dir with .planning/ layout (no config.json) */
|
|
function makeTempProject() {
|
|
const dir = fs.mkdtempSync(path.join(os.tmpdir(), 'gsd-loop-e2e-'));
|
|
fs.mkdirSync(path.join(dir, '.planning', 'phases'), { recursive: true });
|
|
return dir;
|
|
}
|
|
|
|
/** Create a temp dir with .planning/config.json set to the given object */
|
|
function makeTempProjectWithConfig(configObj) {
|
|
const dir = makeTempProject();
|
|
fs.writeFileSync(path.join(dir, '.planning', 'config.json'), JSON.stringify(configObj));
|
|
return dir;
|
|
}
|
|
|
|
/** Create a bare temp dir with no .planning directory at all */
|
|
function makeBareDir() {
|
|
return fs.mkdtempSync(path.join(os.tmpdir(), 'gsd-loop-bare-'));
|
|
}
|
|
|
|
/** Spawn gsd-tools via raw spawnSync; returns { status, stdout, stderr } */
|
|
function spawnGsd(args, cwd) {
|
|
return spawnSync(process.execPath, [GSD_TOOLS, ...args], {
|
|
cwd: cwd || os.tmpdir(),
|
|
encoding: 'utf8',
|
|
timeout: 60000,
|
|
});
|
|
}
|
|
|
|
/**
|
|
* Build a synthetic registry that has ALL 12 canonical byLoopPoint keys
|
|
* (required so resolveLoopHooks does not reject valid canonical points),
|
|
* with a single step at `targetPoint` that activates on `when` config key.
|
|
*/
|
|
function buildSyntheticRegistry({ targetPoint, when, schemaDefault }) {
|
|
const allPoints = [
|
|
'discuss:pre', 'discuss:post', 'plan:pre', 'plan:post',
|
|
'execute:pre', 'execute:wave:pre', 'execute:wave:post', 'execute:post',
|
|
'verify:pre', 'verify:post', 'ship:pre', 'ship:post',
|
|
];
|
|
const byLoopPoint = {};
|
|
for (const p of allPoints) {
|
|
byLoopPoint[p] = { steps: [], contributions: [], gates: [] };
|
|
}
|
|
// Add the step (or gate) at the target point
|
|
byLoopPoint[targetPoint] = {
|
|
steps: [{
|
|
capId: 'future-cap',
|
|
when,
|
|
ref: { skill: 'future-skill' },
|
|
}],
|
|
contributions: [],
|
|
gates: [],
|
|
};
|
|
const configSchema = {};
|
|
if (when !== undefined && schemaDefault !== undefined) {
|
|
configSchema[when] = { default: schemaDefault };
|
|
}
|
|
return { byLoopPoint, configSchema };
|
|
}
|
|
|
|
// ─── Shared all-caps-on config (used by multiple tests) ──────────────────────
|
|
const ALL_CAPS_ON_CONFIG = {
|
|
workflow: {
|
|
ui_phase: true,
|
|
ui_review: true,
|
|
ui_safety_gate: true,
|
|
security_enforcement: true,
|
|
tdd_mode: true,
|
|
code_review: true,
|
|
nyquist_validation: true,
|
|
schema_drift_gate: true,
|
|
post_planning_gaps: true,
|
|
intel: { enabled: true },
|
|
},
|
|
};
|
|
|
|
// ─────────────────────────────────────────────────────────────────────────────
|
|
// SECTION 1: discuss:pre
|
|
// ─────────────────────────────────────────────────────────────────────────────
|
|
|
|
describe('discuss:pre — real registry empty-resolution', () => {
|
|
let tmpDir;
|
|
before(() => { tmpDir = makeTempProject(); });
|
|
after(() => { cleanup(tmpDir); });
|
|
|
|
it('[happy] discuss:pre with real registry returns exact 3-key envelope with empty activeHooks (Gall\'s Law E2E pin)', () => {
|
|
const result = spawnGsd(['loop', 'render-hooks', 'discuss:pre', '--cwd', tmpDir, '--raw'], tmpDir);
|
|
assert.strictEqual(result.status, 0, `expected exit 0, got ${result.status}. stderr: ${result.stderr}`);
|
|
const envelope = JSON.parse(result.stdout.trim());
|
|
assert.strictEqual(envelope.point, 'discuss:pre');
|
|
assert.deepEqual(envelope.activeHooks, []);
|
|
assert.strictEqual(envelope.rendered, '_No active hooks at discuss:pre._');
|
|
assert.deepEqual(Object.keys(envelope).sort(), ['activeHooks', 'point', 'rendered'], 'envelope must have exactly 3 keys');
|
|
});
|
|
|
|
it('[bva] discuss:pre with all capability config keys enabled still returns activeHooks:[] — config does not activate phantom hooks', () => {
|
|
const configDir = makeTempProjectWithConfig(ALL_CAPS_ON_CONFIG);
|
|
try {
|
|
const result = spawnGsd(['loop', 'render-hooks', 'discuss:pre', '--cwd', configDir, '--raw'], configDir);
|
|
assert.strictEqual(result.status, 0);
|
|
const envelope = JSON.parse(result.stdout.trim());
|
|
assert.deepEqual(envelope.activeHooks, [], 'No capability config should activate hooks at discuss:pre');
|
|
assert.strictEqual(envelope.rendered, '_No active hooks at discuss:pre._');
|
|
} finally {
|
|
cleanup(configDir);
|
|
}
|
|
});
|
|
|
|
it('[happy] discuss:pre with real registry pure-function resolveLoopHooks returns empty activeHooks', () => {
|
|
const resolved = resolveLoopHooks({ point: 'discuss:pre', registry: realRegistry, config: {} });
|
|
assert.strictEqual(resolved.point, 'discuss:pre');
|
|
assert.deepEqual(resolved.activeHooks, []);
|
|
});
|
|
|
|
it('[happy] renderLoopHooks for discuss:pre empty state pins the exact Hyrum\'s-Law contract string', () => {
|
|
const rendered = renderLoopHooks({ point: 'discuss:pre', activeHooks: [] });
|
|
assert.strictEqual(rendered, '_No active hooks at discuss:pre._');
|
|
});
|
|
|
|
it('[negative] discuss:pre missing-point argument to CLI exits non-zero with clear message', () => {
|
|
const result = spawnGsd(['loop', 'render-hooks', '--raw'], tmpDir);
|
|
assert.notStrictEqual(result.status, 0, 'must exit non-zero when point arg is missing');
|
|
const combined = (result.stdout + result.stderr);
|
|
assert.match(combined, /render-hooks requires a .point. argument/i);
|
|
});
|
|
|
|
it('[bva] discuss:pre close-typo "discuss:pre " (trailing space) exits non-zero — boundary for point name validation', () => {
|
|
const result = spawnGsd(['loop', 'render-hooks', 'discuss:pre ', '--raw'], tmpDir);
|
|
assert.notStrictEqual(result.status, 0, 'must exit non-zero for invalid point');
|
|
const combined = (result.stdout + result.stderr);
|
|
assert.match(combined, /Invalid loop point/i);
|
|
// Must list valid points so callers know what to use
|
|
assert.match(combined, /discuss:pre[,\s]/);
|
|
});
|
|
});
|
|
|
|
// ─────────────────────────────────────────────────────────────────────────────
|
|
// SECTION 2: discuss:post — resolution + synthetic mechanics
|
|
// ─────────────────────────────────────────────────────────────────────────────
|
|
|
|
describe('discuss:post — E2E empty envelope + synthetic resolver mechanics', () => {
|
|
let tmpDir;
|
|
before(() => { tmpDir = makeTempProjectWithConfig({}); });
|
|
after(() => { cleanup(tmpDir); });
|
|
|
|
it('[empty-resolution] discuss:post E2E subprocess returns exact empty envelope — activeHooks:[], 3-key shape, placeholder string pinned', () => {
|
|
const result = spawnGsd(['loop', 'render-hooks', 'discuss:post', '--raw', '--cwd', tmpDir], tmpDir);
|
|
assert.strictEqual(result.status, 0, `expected exit 0. stderr: ${result.stderr}`);
|
|
const envelope = JSON.parse(result.stdout.trim());
|
|
assert.strictEqual(envelope.point, 'discuss:post');
|
|
assert.deepEqual(envelope.activeHooks, []);
|
|
assert.strictEqual(envelope.rendered, '_No active hooks at discuss:post._');
|
|
assert.deepEqual(Object.keys(envelope).sort(), ['activeHooks', 'point', 'rendered']);
|
|
assert.ok(!Object.prototype.hasOwnProperty.call(envelope, 'warnings'), 'must not have spurious warnings field');
|
|
});
|
|
|
|
it('[happy] discuss:post E2E with no .planning directory returns empty hooks (Postel leniency path)', () => {
|
|
const bareDir = makeBareDir();
|
|
try {
|
|
const result = spawnGsd(['loop', 'render-hooks', 'discuss:post', '--raw', '--cwd', bareDir], bareDir);
|
|
assert.strictEqual(result.status, 0, `expected exit 0 even with no .planning dir. stderr: ${result.stderr}`);
|
|
const envelope = JSON.parse(result.stdout.trim());
|
|
assert.strictEqual(envelope.activeHooks.length, 0);
|
|
assert.strictEqual(envelope.rendered, '_No active hooks at discuss:post._');
|
|
} finally {
|
|
cleanup(bareDir);
|
|
}
|
|
});
|
|
|
|
it('[happy] discuss:post with real registry resolveLoopHooks returns activeHooks:[] (real registry, not synthetic)', () => {
|
|
const resolved = resolveLoopHooks({ point: 'discuss:post', registry: realRegistry, config: {} });
|
|
assert.strictEqual(resolved.point, 'discuss:post');
|
|
assert.strictEqual(resolved.activeHooks.length, 0, 'Real registry must have 0 hooks at discuss:post');
|
|
});
|
|
|
|
it('[bva] discuss:post with synthetic capability, schema default=false + config absent → hook absent (schema default=false suppresses hook)', () => {
|
|
const reg = buildSyntheticRegistry({
|
|
targetPoint: 'discuss:post',
|
|
when: 'workflow.testcap_on',
|
|
schemaDefault: false,
|
|
});
|
|
const resolved = resolveLoopHooks({ point: 'discuss:post', registry: reg, config: {} });
|
|
assert.strictEqual(resolved.activeHooks.length, 0, 'schema default=false must suppress hook when config absent');
|
|
});
|
|
|
|
it('[bva] discuss:post with synthetic capability, schema default=true + config absent → hook active; explicit config=false overrides → hook absent (BVA at config-wins threshold)', () => {
|
|
const reg = buildSyntheticRegistry({
|
|
targetPoint: 'discuss:post',
|
|
when: 'workflow.testcap_on',
|
|
schemaDefault: true,
|
|
});
|
|
|
|
// Sub-case a: schema default=true, no config → active
|
|
const resolvedA = resolveLoopHooks({ point: 'discuss:post', registry: reg, config: {} });
|
|
assert.strictEqual(resolvedA.activeHooks.length, 1, 'schema default=true must activate hook when config absent');
|
|
|
|
// Sub-case b: explicit config=false → overrides schema default → inactive
|
|
const resolvedB = resolveLoopHooks({
|
|
point: 'discuss:post',
|
|
registry: reg,
|
|
config: { workflow: { testcap_on: false } },
|
|
});
|
|
assert.strictEqual(resolvedB.activeHooks.length, 0, 'explicit config=false must override schema default=true');
|
|
});
|
|
|
|
it('[bva] discuss:post with synthetic capability, capabilityStatesById enabled=false → hook absent even when config=true', () => {
|
|
const reg = buildSyntheticRegistry({
|
|
targetPoint: 'discuss:post',
|
|
when: 'workflow.testcap_on',
|
|
schemaDefault: true,
|
|
});
|
|
const resolved = resolveLoopHooks({
|
|
point: 'discuss:post',
|
|
registry: reg,
|
|
config: { workflow: { testcap_on: true } },
|
|
capabilityStatesById: new Map([['future-cap', { enabled: false }]]),
|
|
});
|
|
assert.strictEqual(resolved.activeHooks.length, 0, 'capabilityStatesById enabled=false must suppress hook even when config=true');
|
|
});
|
|
|
|
it('[negative] discuss:post with invalid point name "discuss:past" exits non-zero and lists valid points', () => {
|
|
const result = spawnGsd(['loop', 'render-hooks', 'discuss:past', '--raw', '--cwd', tmpDir], tmpDir);
|
|
assert.notStrictEqual(result.status, 0, 'must exit non-zero for typo point name');
|
|
const combined = (result.stdout + result.stderr);
|
|
assert.match(combined, /discuss:past|Invalid loop point/i);
|
|
assert.match(combined, /discuss:pre/);
|
|
});
|
|
|
|
it('[negative] discuss:post E2E with malformed config.json → still exits 0 with empty hooks (Postel)', () => {
|
|
const malformedDir = makeTempProject();
|
|
fs.writeFileSync(path.join(malformedDir, '.planning', 'config.json'), '{invalid json');
|
|
try {
|
|
const result = spawnGsd(['loop', 'render-hooks', 'discuss:post', '--raw', '--cwd', malformedDir], malformedDir);
|
|
assert.strictEqual(result.status, 0, `must not crash on malformed config. stderr: ${result.stderr}`);
|
|
const envelope = JSON.parse(result.stdout.trim());
|
|
assert.strictEqual(envelope.activeHooks.length, 0);
|
|
assert.strictEqual(envelope.rendered, '_No active hooks at discuss:post._');
|
|
} finally {
|
|
cleanup(malformedDir);
|
|
}
|
|
});
|
|
});
|
|
|
|
// ─────────────────────────────────────────────────────────────────────────────
|
|
// SECTION 3: execute:pre
|
|
// ─────────────────────────────────────────────────────────────────────────────
|
|
|
|
describe('execute:pre — real registry empty-resolution + synthetic resolver mechanics', () => {
|
|
it('[happy] execute:pre with real registry + all capability flags enabled returns 0 active hooks and exact placeholder', () => {
|
|
const allOnDir = makeTempProjectWithConfig(ALL_CAPS_ON_CONFIG);
|
|
try {
|
|
const result = spawnGsd(['loop', 'render-hooks', 'execute:pre', '--raw', '--cwd', allOnDir], allOnDir);
|
|
assert.strictEqual(result.status, 0, `expected exit 0. stderr: ${result.stderr}`);
|
|
const parsed = JSON.parse(result.stdout.trim());
|
|
assert.strictEqual(parsed.point, 'execute:pre');
|
|
assert.strictEqual(parsed.activeHooks.length, 0);
|
|
assert.strictEqual(parsed.rendered, '_No active hooks at execute:pre._');
|
|
} finally {
|
|
cleanup(allOnDir);
|
|
}
|
|
});
|
|
|
|
it('[empty-resolution] execute:pre with no config.json returns 0 active hooks (empty-project negative space)', () => {
|
|
const emptyDir = makeTempProject();
|
|
try {
|
|
const result = spawnGsd(['loop', 'render-hooks', 'execute:pre', '--raw', '--cwd', emptyDir], emptyDir);
|
|
assert.strictEqual(result.status, 0);
|
|
const parsed = JSON.parse(result.stdout.trim());
|
|
assert.strictEqual(parsed.activeHooks.length, 0);
|
|
assert.strictEqual(parsed.rendered, '_No active hooks at execute:pre._');
|
|
} finally {
|
|
cleanup(emptyDir);
|
|
}
|
|
});
|
|
|
|
it('[happy] execute:pre with synthetic step+contribution+gate registered and when-flag=true → all 3 hooks activated', () => {
|
|
const allPoints = [
|
|
'discuss:pre', 'discuss:post', 'plan:pre', 'plan:post',
|
|
'execute:pre', 'execute:wave:pre', 'execute:wave:post', 'execute:post',
|
|
'verify:pre', 'verify:post', 'ship:pre', 'ship:post',
|
|
];
|
|
const byLoopPoint = {};
|
|
for (const p of allPoints) {
|
|
byLoopPoint[p] = { steps: [], contributions: [], gates: [] };
|
|
}
|
|
byLoopPoint['execute:pre'] = {
|
|
steps: [{ capId: 'future-cap', when: 'workflow.future_enabled', ref: { skill: 'step-skill' } }],
|
|
contributions: [{ capId: 'future-cap', when: 'workflow.future_enabled', into: 'context' }],
|
|
gates: [{ capId: 'future-cap', when: 'workflow.future_enabled', check: { query: 'future.gate' }, blocking: true, onError: 'halt' }],
|
|
};
|
|
const syntheticReg = {
|
|
byLoopPoint,
|
|
configSchema: { 'workflow.future_enabled': { default: false } },
|
|
};
|
|
|
|
const resolved = resolveLoopHooks({
|
|
point: 'execute:pre',
|
|
registry: syntheticReg,
|
|
config: { workflow: { future_enabled: true } },
|
|
});
|
|
assert.strictEqual(resolved.activeHooks.length, 3, 'All 3 hooks (step, contribution, gate) must be active when when-flag=true');
|
|
assert.strictEqual(resolved.activeHooks[0].kind, 'step');
|
|
assert.strictEqual(resolved.activeHooks[1].kind, 'contribution');
|
|
assert.strictEqual(resolved.activeHooks[2].kind, 'gate');
|
|
});
|
|
|
|
it('[negative] execute:pre with synthetic hook registered but when-flag=false → hook filtered, activeHooks=[], rendered is placeholder', () => {
|
|
const reg = buildSyntheticRegistry({ targetPoint: 'execute:pre', when: 'workflow.future_enabled', schemaDefault: false });
|
|
const resolved = resolveLoopHooks({
|
|
point: 'execute:pre',
|
|
registry: reg,
|
|
config: { workflow: { future_enabled: false } },
|
|
});
|
|
assert.strictEqual(resolved.activeHooks.length, 0, 'when-flag=false must filter hook');
|
|
const rendered = renderLoopHooks(resolved);
|
|
assert.strictEqual(rendered, '_No active hooks at execute:pre._');
|
|
});
|
|
|
|
it('[negative] execute:pre with synthetic unconditional hook but capability disabled via capabilityStatesById → hook filtered', () => {
|
|
const allPoints = [
|
|
'discuss:pre', 'discuss:post', 'plan:pre', 'plan:post',
|
|
'execute:pre', 'execute:wave:pre', 'execute:wave:post', 'execute:post',
|
|
'verify:pre', 'verify:post', 'ship:pre', 'ship:post',
|
|
];
|
|
const byLoopPoint = {};
|
|
for (const p of allPoints) {
|
|
byLoopPoint[p] = { steps: [], contributions: [], gates: [] };
|
|
}
|
|
// No `when` = unconditional hook
|
|
byLoopPoint['execute:pre'] = {
|
|
steps: [{ capId: 'future-cap', ref: { skill: 'future-skill' } }],
|
|
contributions: [],
|
|
gates: [],
|
|
};
|
|
const syntheticReg = { byLoopPoint, configSchema: {} };
|
|
|
|
const resolved = resolveLoopHooks({
|
|
point: 'execute:pre',
|
|
registry: syntheticReg,
|
|
config: {},
|
|
capabilityStatesById: new Map([['future-cap', { enabled: false }]]),
|
|
});
|
|
assert.strictEqual(resolved.activeHooks.length, 0, 'capabilityStatesById disabled must filter unconditional hook');
|
|
});
|
|
|
|
it('[bva] execute:pre with schema default=true synthetic hook and NO config → hook activates (schema default boundary)', () => {
|
|
const reg = buildSyntheticRegistry({
|
|
targetPoint: 'execute:pre',
|
|
when: 'workflow.future_enabled',
|
|
schemaDefault: true,
|
|
});
|
|
const resolved = resolveLoopHooks({ point: 'execute:pre', registry: reg, config: {} });
|
|
assert.strictEqual(resolved.activeHooks.length, 1, 'schema default=true must activate hook even with absent config');
|
|
});
|
|
|
|
it('[negative] real registry has exactly 0 hooks at execute:pre — guard against accidental registration', () => {
|
|
const entry = realRegistry.byLoopPoint['execute:pre'];
|
|
assert.ok(entry, 'execute:pre must be present in real registry byLoopPoint');
|
|
assert.strictEqual(entry.steps.length, 0, 'execute:pre must have 0 steps in real registry');
|
|
assert.strictEqual(entry.contributions.length, 0, 'execute:pre must have 0 contributions in real registry');
|
|
assert.strictEqual(entry.gates.length, 0, 'execute:pre must have 0 gates in real registry');
|
|
});
|
|
});
|
|
|
|
// ─────────────────────────────────────────────────────────────────────────────
|
|
// SECTION 4: execute:wave:pre
|
|
// ─────────────────────────────────────────────────────────────────────────────
|
|
|
|
describe('execute:wave:pre — real registry empty-resolution + synthetic mechanics', () => {
|
|
it('[empty-resolution] execute:wave:pre with real registry returns empty activeHooks and exact placeholder text', () => {
|
|
const result = spawnGsd(['loop', 'render-hooks', 'execute:wave:pre', '--raw'], os.tmpdir());
|
|
assert.strictEqual(result.status, 0, `expected exit 0. stderr: ${result.stderr}`);
|
|
const envelope = JSON.parse(result.stdout.trim());
|
|
assert.strictEqual(envelope.point, 'execute:wave:pre');
|
|
assert.ok(Array.isArray(envelope.activeHooks), 'activeHooks must be an array');
|
|
assert.strictEqual(envelope.activeHooks.length, 0);
|
|
assert.strictEqual(envelope.rendered, '_No active hooks at execute:wave:pre._');
|
|
});
|
|
|
|
it('[happy] execute:wave:pre with synthetic registry containing a gate hook resolves it correctly', () => {
|
|
const allPoints = [
|
|
'discuss:pre', 'discuss:post', 'plan:pre', 'plan:post',
|
|
'execute:pre', 'execute:wave:pre', 'execute:wave:post', 'execute:post',
|
|
'verify:pre', 'verify:post', 'ship:pre', 'ship:post',
|
|
];
|
|
const byLoopPoint = {};
|
|
for (const p of allPoints) {
|
|
byLoopPoint[p] = { steps: [], contributions: [], gates: [] };
|
|
}
|
|
byLoopPoint['execute:wave:pre'] = {
|
|
steps: [],
|
|
contributions: [],
|
|
gates: [{
|
|
capId: 'future-cap',
|
|
// no `when` = unconditional
|
|
check: { query: 'future.gate' },
|
|
blocking: true,
|
|
onError: 'halt',
|
|
}],
|
|
};
|
|
const syntheticReg = { byLoopPoint, configSchema: {} };
|
|
|
|
const resolved = resolveLoopHooks({ point: 'execute:wave:pre', registry: syntheticReg, config: {} });
|
|
assert.strictEqual(resolved.activeHooks.length, 1);
|
|
const gate = resolved.activeHooks[0];
|
|
assert.strictEqual(gate.kind, 'gate');
|
|
assert.strictEqual(gate.capId, 'future-cap');
|
|
assert.deepEqual(gate.check, { query: 'future.gate' });
|
|
assert.strictEqual(gate.blocking, true);
|
|
assert.strictEqual(gate.onError, 'halt');
|
|
});
|
|
|
|
it('[negative] execute:wave:pre with synthetic step hook and when=false config → hook filtered → empty', () => {
|
|
const reg = buildSyntheticRegistry({
|
|
targetPoint: 'execute:wave:pre',
|
|
when: 'workflow.wave_pre_enabled',
|
|
schemaDefault: true,
|
|
});
|
|
|
|
// BVA: schema default=true without override → active
|
|
const resolvedDefault = resolveLoopHooks({ point: 'execute:wave:pre', registry: reg, config: {} });
|
|
assert.strictEqual(resolvedDefault.activeHooks.length, 1, 'schema default=true with no config override must activate');
|
|
|
|
// BVA: config override false → inactive
|
|
const resolvedOff = resolveLoopHooks({
|
|
point: 'execute:wave:pre',
|
|
registry: reg,
|
|
config: { workflow: { wave_pre_enabled: false } },
|
|
});
|
|
assert.strictEqual(resolvedOff.activeHooks.length, 0, 'explicit config=false must override schema default=true');
|
|
});
|
|
|
|
it('[bva] execute:wave:pre BVA: schema default=true → active (threshold=on), schema default=false → inactive (threshold=off)', () => {
|
|
const regA = buildSyntheticRegistry({ targetPoint: 'execute:wave:pre', when: 'workflow.flag', schemaDefault: true });
|
|
const regB = buildSyntheticRegistry({ targetPoint: 'execute:wave:pre', when: 'workflow.flag', schemaDefault: false });
|
|
|
|
const resolvedA = resolveLoopHooks({ point: 'execute:wave:pre', registry: regA, config: {} });
|
|
assert.strictEqual(resolvedA.activeHooks.length, 1, 'registry A (default=true) must activate hook');
|
|
|
|
const resolvedB = resolveLoopHooks({ point: 'execute:wave:pre', registry: regB, config: {} });
|
|
assert.strictEqual(resolvedB.activeHooks.length, 0, 'registry B (default=false) must NOT activate hook');
|
|
});
|
|
});
|
|
|
|
// ─────────────────────────────────────────────────────────────────────────────
|
|
// SECTION 5: verify:pre
|
|
// ─────────────────────────────────────────────────────────────────────────────
|
|
|
|
describe('verify:pre — real registry empty-resolution + synthetic extension-point readiness', () => {
|
|
let tmpEmptyProjectDir;
|
|
let tmpProjectDirAllOn;
|
|
before(() => {
|
|
tmpEmptyProjectDir = makeTempProject();
|
|
tmpProjectDirAllOn = makeTempProjectWithConfig(ALL_CAPS_ON_CONFIG);
|
|
});
|
|
after(() => {
|
|
cleanup(tmpEmptyProjectDir);
|
|
cleanup(tmpProjectDirAllOn);
|
|
});
|
|
|
|
it('[empty-resolution] verify:pre with real registry and no config yields empty activeHooks and exact placeholder (Gall\'s Law)', () => {
|
|
const resolved = resolveLoopHooks({ point: 'verify:pre', registry: realRegistry, config: {} });
|
|
assert.strictEqual(resolved.activeHooks.length, 0);
|
|
assert.strictEqual(renderLoopHooks(resolved), '_No active hooks at verify:pre._');
|
|
});
|
|
|
|
it('[happy] verify:pre E2E subprocess returns well-formed 3-key JSON envelope with empty activeHooks (Hyrum\'s Law contract pin)', () => {
|
|
const result = spawnGsd(['loop', 'render-hooks', 'verify:pre', '--cwd', tmpEmptyProjectDir, '--raw'], tmpEmptyProjectDir);
|
|
assert.strictEqual(result.status, 0, `expected exit 0. stderr: ${result.stderr}`);
|
|
const envelope = JSON.parse(result.stdout.trim());
|
|
assert.strictEqual(envelope.point, 'verify:pre');
|
|
assert.deepEqual(envelope.activeHooks, []);
|
|
assert.strictEqual(envelope.rendered, '_No active hooks at verify:pre._');
|
|
assert.deepEqual(Object.keys(envelope).sort(), ['activeHooks', 'point', 'rendered']);
|
|
});
|
|
|
|
it('[negative] verify:pre with all capability config keys set to true still yields empty activeHooks — no leakage from other points', () => {
|
|
const resolved = resolveLoopHooks({
|
|
point: 'verify:pre',
|
|
registry: realRegistry,
|
|
config: { workflow: { ui_phase: true, ui_review: true, ui_safety_gate: true } },
|
|
});
|
|
assert.strictEqual(resolved.activeHooks.length, 0, 'UI and other capabilities must not bleed through to verify:pre');
|
|
});
|
|
|
|
it('[bva] Synthetic step at verify:pre with configSchema default=true fires correctly — extension point readiness', () => {
|
|
const reg = buildSyntheticRegistry({ targetPoint: 'verify:pre', when: 'workflow.future_enabled', schemaDefault: true });
|
|
const resolved = resolveLoopHooks({ point: 'verify:pre', registry: reg, config: {} });
|
|
assert.strictEqual(resolved.activeHooks.length, 1, 'synthetic step at verify:pre with default=true must activate');
|
|
assert.strictEqual(resolved.activeHooks[0].capId, 'future-cap');
|
|
assert.strictEqual(resolved.activeHooks[0].kind, 'step');
|
|
const rendered = renderLoopHooks(resolved);
|
|
assert.match(rendered, /future-skill/);
|
|
assert.match(rendered, /future-cap/);
|
|
});
|
|
|
|
it('[bva] Synthetic step at verify:pre with when=false (config override) filters correctly — activation logic applies at this point', () => {
|
|
const reg = buildSyntheticRegistry({ targetPoint: 'verify:pre', when: 'workflow.future_enabled', schemaDefault: true });
|
|
const resolved = resolveLoopHooks({
|
|
point: 'verify:pre',
|
|
registry: reg,
|
|
config: { workflow: { future_enabled: false } },
|
|
});
|
|
assert.strictEqual(resolved.activeHooks.length, 0, 'config explicit false must beat schema default=true');
|
|
});
|
|
|
|
it('[negative] verify:pre with malformed config.json in .planning/ degrades leniently (Postel\'s Law at this point)', () => {
|
|
const malformedDir = makeTempProject();
|
|
fs.writeFileSync(path.join(malformedDir, '.planning', 'config.json'), '{invalid json');
|
|
try {
|
|
const result = spawnGsd(['loop', 'render-hooks', 'verify:pre', '--cwd', malformedDir, '--raw'], malformedDir);
|
|
assert.strictEqual(result.status, 0, `must not crash on malformed config. stderr: ${result.stderr}`);
|
|
const envelope = JSON.parse(result.stdout.trim());
|
|
assert.deepEqual(envelope.activeHooks, []);
|
|
} finally {
|
|
cleanup(malformedDir);
|
|
}
|
|
});
|
|
});
|
|
|
|
// ─────────────────────────────────────────────────────────────────────────────
|
|
// SECTION 6: ship:post
|
|
// ─────────────────────────────────────────────────────────────────────────────
|
|
|
|
describe('ship:post — real registry empty-resolution + resilience to registry edge-cases', () => {
|
|
it('[happy] ship:post E2E subprocess returns typed envelope: point=\'ship:post\', activeHooks=[], rendered=placeholder, no extra keys', () => {
|
|
const tmpDir = makeTempProject();
|
|
try {
|
|
const result = spawnGsd(['loop', 'render-hooks', 'ship:post', '--raw', '--cwd', tmpDir], tmpDir);
|
|
assert.strictEqual(result.status, 0, `expected exit 0. stderr: ${result.stderr}`);
|
|
const envelope = JSON.parse(result.stdout.trim());
|
|
assert.strictEqual(envelope.point, 'ship:post');
|
|
assert.deepEqual(envelope.activeHooks, []);
|
|
assert.strictEqual(envelope.rendered, '_No active hooks at ship:post._');
|
|
assert.deepEqual(Object.keys(envelope).sort(), ['activeHooks', 'point', 'rendered']);
|
|
assert.ok(!Object.prototype.hasOwnProperty.call(envelope, 'warnings'), 'must not have warnings key');
|
|
} finally {
|
|
cleanup(tmpDir);
|
|
}
|
|
});
|
|
|
|
it('[bva] ship:post returns empty activeHooks regardless of any capability config being enabled — no config leaks hooks into this point', () => {
|
|
const allOnDir = makeTempProjectWithConfig(ALL_CAPS_ON_CONFIG);
|
|
try {
|
|
const result = spawnGsd(['loop', 'render-hooks', 'ship:post', '--raw', '--cwd', allOnDir], allOnDir);
|
|
assert.strictEqual(result.status, 0);
|
|
const envelope = JSON.parse(result.stdout.trim());
|
|
assert.deepEqual(envelope.activeHooks, [], 'Maximum capability activation must still produce zero hooks at ship:post');
|
|
} finally {
|
|
cleanup(allOnDir);
|
|
}
|
|
});
|
|
|
|
it('[happy] resolveLoopHooks with real capability-registry at ship:post returns empty activeHooks and well-formed byLoopPoint entry', () => {
|
|
const resolved = resolveLoopHooks({ point: 'ship:post', registry: realRegistry, config: {} });
|
|
assert.strictEqual(resolved.point, 'ship:post');
|
|
assert.ok(Array.isArray(resolved.activeHooks));
|
|
assert.strictEqual(resolved.activeHooks.length, 0);
|
|
|
|
const entry = realRegistry.byLoopPoint['ship:post'];
|
|
assert.ok(entry, 'ship:post must be present in real registry byLoopPoint');
|
|
assert.strictEqual(entry.steps.length, 0, 'ship:post must have 0 steps');
|
|
assert.strictEqual(entry.contributions.length, 0, 'ship:post must have 0 contributions');
|
|
assert.strictEqual(entry.gates.length, 0, 'ship:post must have 0 gates');
|
|
});
|
|
|
|
it('[negative] ship:post E2E exits 0 and returns empty envelope when project has no .planning directory at all', () => {
|
|
const bareDir = makeBareDir();
|
|
try {
|
|
const result = spawnGsd(['loop', 'render-hooks', 'ship:post', '--raw', '--cwd', bareDir], bareDir);
|
|
assert.strictEqual(result.status, 0, `expected exit 0 even with no .planning dir. stderr: ${result.stderr}`);
|
|
const envelope = JSON.parse(result.stdout.trim());
|
|
assert.strictEqual(envelope.activeHooks.length, 0);
|
|
assert.strictEqual(envelope.rendered, '_No active hooks at ship:post._');
|
|
} finally {
|
|
cleanup(bareDir);
|
|
}
|
|
});
|
|
|
|
it('[negative] resolveLoopHooks does not throw and returns empty hooks when byLoopPoint[\'ship:post\'] is null', () => {
|
|
const allPoints = [
|
|
'discuss:pre', 'discuss:post', 'plan:pre', 'plan:post',
|
|
'execute:pre', 'execute:wave:pre', 'execute:wave:post', 'execute:post',
|
|
'verify:pre', 'verify:post', 'ship:pre', 'ship:post',
|
|
];
|
|
const byLoopPoint = {};
|
|
for (const p of allPoints) {
|
|
byLoopPoint[p] = { steps: [], contributions: [], gates: [] };
|
|
}
|
|
byLoopPoint['ship:post'] = null;
|
|
const syntheticReg = { byLoopPoint, configSchema: {} };
|
|
|
|
const resolved = resolveLoopHooks({ point: 'ship:post', registry: syntheticReg, config: {} });
|
|
assert.strictEqual(resolved.activeHooks.length, 0, 'null byLoopPoint entry must not throw and must return 0 hooks');
|
|
});
|
|
|
|
it('[negative] resolveLoopHooks does not throw when byLoopPoint[\'ship:post\'] exists but has no steps/contributions/gates keys', () => {
|
|
const allPoints = [
|
|
'discuss:pre', 'discuss:post', 'plan:pre', 'plan:post',
|
|
'execute:pre', 'execute:wave:pre', 'execute:wave:post', 'execute:post',
|
|
'verify:pre', 'verify:post', 'ship:pre', 'ship:post',
|
|
];
|
|
const byLoopPoint = {};
|
|
for (const p of allPoints) {
|
|
byLoopPoint[p] = { steps: [], contributions: [], gates: [] };
|
|
}
|
|
byLoopPoint['ship:post'] = {}; // No arrays at all
|
|
const syntheticReg = { byLoopPoint, configSchema: {} };
|
|
|
|
const resolved = resolveLoopHooks({ point: 'ship:post', registry: syntheticReg, config: {} });
|
|
assert.strictEqual(resolved.activeHooks.length, 0, 'missing arrays in byLoopPoint entry must not throw');
|
|
});
|
|
|
|
it('[bva] ship:post returns empty activeHooks even when security_enforcement=true — security gate lives at ship:pre not ship:post', () => {
|
|
const securityOnDir = makeTempProjectWithConfig({ workflow: { security_enforcement: true } });
|
|
try {
|
|
// ship:post must be empty
|
|
const postResult = spawnGsd(['loop', 'render-hooks', 'ship:post', '--raw', '--cwd', securityOnDir], securityOnDir);
|
|
assert.strictEqual(postResult.status, 0);
|
|
const postEnvelope = JSON.parse(postResult.stdout.trim());
|
|
assert.deepEqual(postEnvelope.activeHooks, [], 'ship:post must be empty even with security_enforcement=true');
|
|
|
|
// ship:pre must have the security gate (proves the config actually works and the difference is real)
|
|
const preResult = spawnGsd(['loop', 'render-hooks', 'ship:pre', '--raw', '--cwd', securityOnDir], securityOnDir);
|
|
assert.strictEqual(preResult.status, 0);
|
|
const preEnvelope = JSON.parse(preResult.stdout.trim());
|
|
const secGate = preEnvelope.activeHooks.find(h => h.capId === 'security');
|
|
assert.ok(secGate, 'ship:pre must have a security gate when security_enforcement=true');
|
|
} finally {
|
|
cleanup(securityOnDir);
|
|
}
|
|
});
|
|
|
|
it('[empty-resolution] ship:post byLoopPoint entry exists in the real registry with all three arrays empty — no capability has silently self-registered here', () => {
|
|
const entry = realRegistry.byLoopPoint['ship:post'];
|
|
assert.ok(entry, 'ship:post must be present in real registry byLoopPoint');
|
|
assert.strictEqual(entry.steps.length, 0, 'ship:post must have 0 steps — accidental registration guard');
|
|
assert.strictEqual(entry.contributions.length, 0, 'ship:post must have 0 contributions — accidental registration guard');
|
|
assert.strictEqual(entry.gates.length, 0, 'ship:post must have 0 gates — accidental registration guard');
|
|
});
|
|
});
|
|
|
|
// ─────────────────────────────────────────────────────────────────────────────
|
|
// SECTION 7: CLI contract (shared across all 6 points)
|
|
// ─────────────────────────────────────────────────────────────────────────────
|
|
|
|
describe('CLI contract — missing/invalid point argument (shared across all 6 empty points)', () => {
|
|
it('[negative] missing point argument exits non-zero and includes render-hooks syntax in error message', () => {
|
|
const result = spawnGsd(['loop', 'render-hooks', '--raw'], os.tmpdir());
|
|
assert.notStrictEqual(result.status, 0, 'must exit non-zero when point arg is missing');
|
|
const combined = (result.stdout + result.stderr);
|
|
assert.match(combined, /render-hooks requires a .point. argument/i);
|
|
});
|
|
|
|
it('[bva] "discuss:post " with trailing space exits non-zero — boundary: trailing whitespace makes point invalid', () => {
|
|
const result = spawnGsd(['loop', 'render-hooks', 'discuss:post ', '--raw'], os.tmpdir());
|
|
assert.notStrictEqual(result.status, 0, 'must reject point with trailing space');
|
|
const combined = (result.stdout + result.stderr);
|
|
assert.match(combined, /Invalid loop point/i);
|
|
});
|
|
|
|
it('[bva] "execute:pre." with trailing period exits non-zero — boundary: period suffix makes point invalid', () => {
|
|
const result = spawnGsd(['loop', 'render-hooks', 'execute:pre.', '--raw'], os.tmpdir());
|
|
assert.notStrictEqual(result.status, 0, 'must reject point with trailing period');
|
|
const combined = (result.stdout + result.stderr);
|
|
assert.match(combined, /Invalid loop point/i);
|
|
});
|
|
|
|
it('[negative] error message for invalid point includes list of valid points so callers can self-correct', () => {
|
|
const result = spawnGsd(['loop', 'render-hooks', 'verify:future', '--raw'], os.tmpdir());
|
|
assert.notStrictEqual(result.status, 0);
|
|
const combined = (result.stdout + result.stderr);
|
|
// Must include at least several valid points in the error message
|
|
assert.match(combined, /discuss:pre/);
|
|
assert.match(combined, /ship:post/);
|
|
assert.match(combined, /verify:pre/);
|
|
});
|
|
});
|
|
|
|
// ─────────────────────────────────────────────────────────────────────────────
|
|
// SECTION 8: Parametric empty-point sweep across all 6 points (E2E regression guard)
|
|
// ─────────────────────────────────────────────────────────────────────────────
|
|
|
|
describe('Parametric E2E sweep — all 6 empty points return correct envelope shape via real registry', () => {
|
|
const EMPTY_POINTS = [
|
|
'discuss:pre',
|
|
'discuss:post',
|
|
'execute:pre',
|
|
'execute:wave:pre',
|
|
'verify:pre',
|
|
'ship:post',
|
|
];
|
|
|
|
for (const point of EMPTY_POINTS) {
|
|
it(`[parametric] ${point} — E2E subprocess exits 0 with {point, activeHooks:[], rendered:placeholder}`, () => {
|
|
const tmpDir = makeTempProject();
|
|
try {
|
|
const result = spawnGsd(['loop', 'render-hooks', point, '--raw', '--cwd', tmpDir], tmpDir);
|
|
assert.strictEqual(result.status, 0, `${point}: expected exit 0. stderr: ${result.stderr}`);
|
|
const envelope = JSON.parse(result.stdout.trim());
|
|
assert.strictEqual(envelope.point, point, `${point}: envelope.point mismatch`);
|
|
assert.ok(Array.isArray(envelope.activeHooks), `${point}: activeHooks must be an array`);
|
|
assert.strictEqual(envelope.activeHooks.length, 0, `${point}: activeHooks must be empty`);
|
|
assert.strictEqual(envelope.rendered, `_No active hooks at ${point}._`, `${point}: rendered placeholder mismatch`);
|
|
} finally {
|
|
cleanup(tmpDir);
|
|
}
|
|
});
|
|
|
|
it(`[parametric] ${point} — pure-function resolveLoopHooks with real registry returns 0 activeHooks`, () => {
|
|
const resolved = resolveLoopHooks({ point, registry: realRegistry, config: {} });
|
|
assert.strictEqual(resolved.point, point);
|
|
assert.strictEqual(resolved.activeHooks.length, 0, `${point}: real registry must have 0 hooks at this point`);
|
|
});
|
|
}
|
|
});
|