* test(#1168): make phase-6 gate un-gameable — reject empty stubs + require loop shrink The migration assertion previously checked only role==feature, so a registration-only stub (empty hooks, logic left inline) would turn the gate green while phase 6 stayed incomplete — the exact false-completion pattern this gate exists to prevent. Strengthen it: each ADR-named feature must OWN its behavior (>=1 hook, or a command family); and plan-phase.md/execute-phase.md must shrink strictly below their frozen pre-phase-6 sizes (94519/93166 LF bytes), which also defeats double-run gaming (declare a hook but keep the inline block -> file does not shrink -> red). Gate now 5 pass / 4 fail (orphaned execute:wave:post, empty/unregistered features, config-key leaks, no shrink). Green is now reachable only by REAL migration. Refs #1168, #1169. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * feat(#1169): migrate gap-analysis to a Capability (plan:post gate) First real ADR-857 phase-6 migration (pattern-defining tracer). gap-analysis moves from an inline post_planning_gaps branch in plan-phase.md to a real plan:post gate Capability: - capabilities/gap-analysis/capability.json: role:feature, plan:post gate (when=workflow.post_planning_gaps, blocking:false advisory), OWNS workflow.post_planning_gaps (federated out of central schema). - plan-phase.md: inline config-get + gsd_run gap-analysis block replaced with a plan:post render-hooks call site dispatching the gate; file shrinks 94519->93279. - src/check-command-router.cts: cmdGapAnalysisPlanPost runs the real gap analysis via gap-checker. - post_planning_gaps removed from central manifest; resolves via federated config (default true preserved). - tests/post-planning-gaps-2493: re-pointed to assert capability ownership. Verified: gate 5 pass / 4 fail (gap-analysis cleared from migration, plan:post-orphan, config-leak, and plan-phase shrink checks); loadConfig still returns post_planning_gaps=true; check command runs real analysis; 392/392 in the config/registry/federation/router net. Refs #1169. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * feat(#1169): migrate profile-pipeline to a command-family Capability ADR-857 Decision 7: profile-pipeline becomes a command-family Capability (like audit/intel/graphify). capabilities/profile-pipeline/capability.json declares an 8-command family (scan-sessions, extract-messages, profile-sample, write-profile, profile-questionnaire, generate-dev-preferences, generate-claude-profile, generate-claude-md) backed by a new gsd-core/bin/lib/profile-pipeline-command-router.cjs; the inline case arms are removed from gsd-tools.cjs. Owns profile-pipeline.enabled (federated). Verified: registry shows role:feature with commands.length=8; scan-sessions/profile-sample run live via the family; gate cleared profile-pipeline from the empty-stub failure (only tdd/schema-gate/drift remain); 296/296 registry+inventory+gsd-tools tests; lint 0 errors. Refs #1169. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * fix(#1167): wire execute:wave:post + implement ui.safety-gate check Revives the second dead gate from #1167: ui.gates@execute:wave:post was declared but never dispatched AND its check.query (ui.safety-gate) was unimplemented. Adds the per-wave execute:wave:post render-hooks call site in execute-phase.md (fires after each wave's merge/cleanup, before the next forks) and implements cmdUiSafetyGate (frontend + UI-SPEC aware, mirrors cmdUiPlanGate) in check-command-router. +17 regression tests. Verified: phase-6 orphaned-points conformance test now PASSES (gate 6 pass / 3 fail); ui-safety-gate routable in dot+hyphen forms; check-ui-safety-gate 17/17, check-ui-plan-gate 18/18; lint 0 errors. Refs #1167, #1168. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * feat(#1169): migrate drift (schema + codebase) to execute:wave:post gates Removes the inline schema_drift_gate + codebase_drift_gate steps (77 lines) from execute-phase.md; drift becomes a Capability with two execute:wave:post gates (verify.schema-drift blocking, verify.codebase-drift advisory) dispatched via the per-wave render-hooks call site. check-command-router routes verify.schema-drift / verify.codebase-drift to the real detectors. Federates workflow.drift_threshold / drift_action / schema_drift_gate out of central. Also fixes the execute:wave:post dispatch prose to run NON-blocking (advisory) gates too — the prior version only ran blocking gates, which would have silently dropped the codebase-drift advisory after its inline step was removed. Behavior preserved. Verified: gate 7 pass / 2 fail (drift cleared from stub + config-leak; execute-phase.md 92297 < 93166 frozen -> shrink passes); both drift checks run real detection; loadConfig defaults preserved (threshold=3, action=warn, gate=true); drift-detection 56/56 + schema-drift 34/34; lint 0 errors. Refs #1169. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * feat(#1169): migrate tdd to a Capability (plan:pre contribution + execute:post gate) tdd becomes a real Capability: a plan:pre contribution injects the <tdd_mode_active> planner guidance (rendered from PLAN_PRE_HOOKS_JSON like security's contribution), and an execute:post gate (tdd.review-checkpoint, advisory) runs the real end-of-phase RED/GREEN review via a new check-command handler. Inline tdd_mode reads + the inline planner block + the tdd_review_checkpoint step are removed; workflow.tdd_mode is federated out of central. The MVP+TDD per-task RED-commit gate is preserved — TDD_MODE is now derived from the execute:post hooks (capId==tdd active), not an inline config-get. BEHAVIOR CHANGE (documented, not silent): the --tdd CLI flag now persists workflow.tdd_mode=true via config-set instead of being per-invocation. Rationale: tdd is now a config-toggled Capability, and env vars do not persist across the workflow's separate bash blocks (config does), so an ephemeral override isn't cleanly achievable; --tdd therefore enables the tdd capability, consistent with how all capabilities are toggled. Verified: gate 7 pass / 2 fail (tdd cleared from stub + config-leak; plan-phase + execute-phase both < frozen sizes); contribution injection + execute:post gate dispatch wired; MVP+TDD gate preserved; tdd.review-checkpoint runs real review; full unit suite 556/0; lint 0 errors. Refs #1169. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * feat(#1169): migrate schema-gate to a plan:pre contribution Capability The plan-time schema-push detection (former plan-phase.md §5.7) becomes a schema-gate Capability: a plan:pre contribution (into:planner, when:workflow.schema_push_detection) whose fragment carries the full ORM-detection + [BLOCKING] schema-push-task injection logic, rendered into the planner via the existing plan:pre render-hooks dispatch. The inline §5.7 block is removed (plan-phase.md 94519->90445). workflow.schema_push_detection is a new capability-owned (federated) key, default true. (The execute-side schema-drift gate was migrated separately into the drift capability.) Verified: registry inlines the fragment (len 2704) so it is actually delivered at plan:pre; gate 8 pass / 1 fail — all 5 ADR-named features now real Capabilities, only the config-leak test remains (intel/security, next unit). Refs #1169. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * feat(#1169): close the 3 capability config-key leaks — phase-6 gate now GREEN Removes the last inline config-get reads of capability-owned keys from plan-phase.md. security_asvs_level/security_block_on now flow through the security plan:pre contribution via a new loop-resolver configValues mechanism (resolves declared config keys with the same 4-level precedence as activation and attaches them to the rendered hook); the §5.55 banner reads them from PLAN_PRE_HOOKS_JSON. intel.enabled becomes a real intel plan:pre step (ref.command: intel api-surface) dispatched via render-hooks; the inline intel branch is gone. gen-capability-registry now validates ref.command as a third dispatch shape. Verified: phase-6 capstone conformance gate is FULLY GREEN (9/0); 3 leaks gone (grep=0); security configValues resolve to {2,medium}/default {1,high}; intel step present only when enabled; loop-render-hooks 62/0, capability-registry 287/0, capability-state/federated-config 113/0; lint 0 errors. Closes the migration half of #1169. Refs #1139, #1167, #1168. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * fix(#1169): address adversarial review — restore schema-drift block, generic planner injection, uniform gate contract Adversarial review caught 2 real regressions the green gate missed: (1) schema-drift no longer blocked — the execute:wave:post dispatch read GATE_RESULT.block but verify.schema-drift emitted drift_detected/blocking, and onError:skip wrongly bypassed positive blocks; (2) only tdd's plan:pre contribution was injected into the planner, dropping schema-gate's schema-push detection and security's threat-model guidance. Fixes: (A) every gate check returns a uniform boolean 'block' under --raw (the dispatch form), with advisory gates (tdd/gap) carrying their report in 'message'; (B) gate-dispatch contract corrected at all sites — onError governs command errors only, a blocking gate's positive block always halts; (C) generic planner injection of all plan:pre contributions where into=='planner' (tdd + schema-gate + security incl configValues); (D) two new conformance assertions: planner contributions injected generically + every gate check.query returns boolean block under --raw. Verified: gate 11/11; all 6 gate checks return boolean block under --raw; full suite 595/0; lint 0 errors. Refs #1167, #1168, #1169. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * fix(#1169): restore MVP+TDD end-of-phase blocking escalation (2nd adversarial pass) The migrated tdd execute:post gate is statically blocking:false, but the contract (references/execute-mvp-tdd.md + CONTEXT.md) requires the end-of-phase TDD review to ESCALATE from advisory to blocking when MVP_MODE && TDD_MODE && a TDD plan misses a RED/GREEN commit. The migration prose had downgraded this to a 'strong advisory recommendation' — silent loss of the blocking escalation. Restore it: the tdd-gate dispatch now refuses to mark the phase complete (Phase blocked message) under MVP+TDD when GATE_RESULT.block is true; advisory otherwise. Also strengthen tests/execute-mvp-tdd-gate.test.cjs: hasBlockingEscalation previously matched any line with 'blocking'+'mvp+tdd' (so 'advisory (blocking: false) ... under MVP+TDD' was a false green); now it requires the real refusal semantics ('refuse to mark the phase complete' / 'phase blocked'). Caught by 2nd adversarial review pass. Verified: execute-phase.md 92702 < 93166 frozen; mvp-tdd-gate + phase-6 gate 19/0; full suite green; lint 0 errors. Refs #1169. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * fix(#1169): restore MVP+TDD proceed-block, codebase auto-remap, schema skip-flag (3rd adversarial pass) 3rd adversarial pass found 4 more silent regressions: (1) the tdd MVP+TDD 'refuse to mark complete' was nullified by a downstream 'ALWAYS proceed regardless of gate results' line — proceed is now conditional (stops on an active MVP+TDD block); (2) the test now asserts the proceed is NOT an unconditional override; (3) codebase-drift auto-remap (spawn gsd-codebase-mapper when drift_action=auto-remap) was dropped — the execute:wave:post advisory dispatch now consumes spawn_mapper/directive; (4) GSD_SKIP_SCHEMA_CHECK bypass was lost from the gate path — cmdVerifySchemaDrift now honors the env var (block:false when set). Verified: no unconditional proceed; GSD_SKIP_SCHEMA_CHECK=true -> block:false; gate 11/11 + mvp-tdd 9/9; full suite 569/0; lint 0; execute-phase.md 93109 < 93166. Refs #1169. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * fix(#1169): init.cts reads federated config keys from nested path (4th adversarial pass) Config federation moved tdd_mode/research/nyquist_validation from flat config.<key> to nested config.workflow.<key>, but src/init.cts still read them flat — so init.plan-phase/init.execute-phase emitted tdd_mode:false / research_enabled:undefined / nyquist:undefined regardless of config (a public command-contract regression; the migrated loops use render-hooks so enforcement was unaffected). Read via config.workflow (type-safe Record cast). Now init reflects the same resolved values + federated defaults (research/nyquist default true) as the render-hooks path. Verified: build clean; init.plan-phase emits tdd_mode:true/research:false/nyquist:false for set config, defaults true for empty; full suite 591/0; lint 0. Refs #1169. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * docs(#1169): add changeset for ADR-857 phase-6 completion (PR #1183) Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * fix(#1169): complete phase-6 migration fallout — restore TEXT_MODE, fix registry .claude leak, re-point stale workflow-contract tests The capability migration left real regressions and stale consumer tests that the per-module unit suite missed but the full cross-platform suite caught (27 failing tests): Real source regressions (fixed): - execute-phase.md lost its AskUserQuestion TEXT_MODE plain-text fallback when the inline schema_drift_gate step was removed — non-Claude runtimes would stall. Restored, and the execute:post gate-dispatch prose de-duplicated to cite the execute:wave:post contract (loop body shrinks below the frozen pre-phase-6 ceiling while keeping every onError/blocking nuance). - capabilities/tdd inline fragment hardcoded `@~/.claude/gsd-core/references/tdd.md`, baked verbatim into the committed capability-registry.cjs and leaked the install path on 11 non-Claude runtimes (registry .cjs is copied, not path-converted). Made the fragment path-free; regenerated the registry. The phase-6 conformance gate now guards this (no ~/.claude install path in any capability source or the generated registry). - plan-phase.md: removed a §5.7 stub re-added in error and routed Branch 2 to step 6 (schema-gate is a plan:pre capability, §5.7 is gone). Stale workflow-contract tests re-pointed to the capability dispatch they now must assert (behavior verified preserved in source first, assertions kept equal-or-stronger): bug-621 + bug-2851 (gap-analysis via gsd_run render-hooks plan:post + registry binding), feat-2527 (tdd_mode federated out of central), phase6-planning + plan-phase-ui-redirect (§5.6 bounded by ## 6.), plan-phase-drift-guard (intel when:intel.enabled skip branch). profile-pipeline-command-router.cjs un-ignored from eslint (hand-written, no TS source) + stale disable comments removed. Size baseline regenerated. Verified: full suite 15140 tests / 0 fail; lint 0 errors; conformance gate green legitimately. Refs #1139, #1167, #1168, #1169. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * test(#1169): add ADR-857 E2E content-test coverage for the 12 loop points + capability deliverables Grounds the capability engine in behavioral E2E tests (drive the real render-hooks/check CLI + the real registry, assert typed result content — no source-grep), structured around what ADR-857 says to deliver. 207 tests; each genuineness-checked (flip the expectation, confirm it fails). Per-loop-point dispatch (7 files): empty-point negative-space across the 6 no-hook points; verify:post 3-step resolution+ordering+onError; plan:pre contribution/configValues + ui.plan-gate + intel; plan:post gap-analysis; execute:wave:post drift+ui gates via the check route (schema-drift block/skip, codebase-drift threshold BVA, auto-remap); execute:post tdd.review-checkpoint RED/GREEN; ship:pre security gate resolution + frontmatter-get predicate pieces. ADR-deliverable coverage (4 files): predicate boundary held (edge/prohibition probes stay core, not off-by-default Feature Capabilities — phase-6 exception); core loop runs with zero capabilities (all 12 points empty, init bundles resolve); contribution merge (multiple ordered <contribution from=> blocks); federated-config key removal on uninstall. federated-config allowlisted for its 3-file split (unit + integration + lifecycle). Refs #1139, #1167, #1168, #1169. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * fix(#1169): remove dead drifted converter dups + address adversarial review Lint cleanup (root-caused, not waved off): src/runtime-artifact-conversion.cts carried 11 agent-converter functions (+5 orphaned consts/helpers) that were never exported, never called, and had silently DRIFTED from the live hand-authored copies in bin/install.js (one even referenced an undefined `claudeToCopilotTools`). Deleted the dead duplicates; install.js's live copies are untouched (it never imported these). Lint now 0 errors / 0 warnings. Adversarial-review (Codex) findings fixed: - HIGH: execute-phase.md TDD_MODE used `jq ... || echo false`, silently disabling the MVP+TDD blocking gate on jq-less runtimes. Reverted to the `node -e` form (node is guaranteed; matches the file's other node-e usages) so a missing optional tool can no longer fail-open a blocking safety path. - MEDIUM: federated-config-key-removal orphan-key test was vacuous (it skipped the orphan assertion). Now asserts the removed capability's key is genuinely not surfaced/validated after uninstall. - LOW: phase-6 conformance leak regex broadened to catch absolute-home and Windows-backslash `.claude/(gsd-core|commands|agents|hooks)` paths, not only `~`/`$HOME` forward-slash forms. - LOW: bug-2851 plan:post dispatch assertion now requires `--raw` (matched its stated contract). - nit: plan-pre intel-step test duplicate assertion replaced with a distinct structured-output check. Size baseline regenerated (execute-phase.md 93089 < 93166 frozen). Refs #1167, #1169. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * test(#1169): make runtime-homes-descriptor-drive titles environment-independent The descriptor-equivalence test embedded the absolute golden config path (`os.homedir()`-derived) directly in each `test(...)` title, so titles differed between macOS (`/Users/x/.claude`) and Docker (`/home/gsdtest/.claude`). Every test PASSES on both platforms (15885/0 leaf tests each), but gsd-test-summary compares results by title and reported 29+29 false "only in Mac / only in Docker" discrepancies for tests that actually pass everywhere. Move the golden path out of the title and into the assertion message (still shown on failure); titles are now byte-identical across platforms so the cross-platform comparator matches them. No assertion logic or golden values changed. Refs #1169. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * fix(#1169): derive TDD_MODE via gsd_run --active-cap, not node -e (fix prompt-injection CI gate) The prior fix reverted execute-phase.md:181 from jq to `node -e` to close a Codex HIGH (jq||echo-false silently disabling the MVP+TDD blocking gate on jq-less runtimes) — but the CI prompt-injection scanner BLOCKS new `node -e` in workflow markdown (inline code-exec = injection vector), turning the security gate red. Both forms were wrong: node -e fails the scanner; jq fail-opens a blocking safety gate; `config-get workflow.tdd_mode` is forbidden by the conformance leak gate (tdd_mode is capability-owned). Correct fix (what Codex recommended): a gsd_run-native boolean. Add an `--active-cap <capId>` flag to `loop render-hooks <point>` that resolves hooks the normal way and prints exactly `true`/`false` for whether a capId is active — scanner-safe (canonical launcher, no inline code), node-reliable (no optional jq to fail-open), and leak-free (render-hooks resolution, not config-get). execute-phase.md:181 now `TDD_MODE=$(gsd_run loop render-hooks execute:post --active-cap tdd)`. +5 behavioral tests for the flag. Verified: prompt-injection-scan --diff origin/next → 0 findings; conformance gate 13/13 (execute-phase.md 92934 < 93166); execute-mvp-tdd + tdd-mode + loop-render-hooks 87/0; lint 0/0. Refs #1167, #1169. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
451 lines
22 KiB
JavaScript
451 lines
22 KiB
JavaScript
/**
|
|
* ADR-857 deliverable A — predicate-boundary conformance gate.
|
|
*
|
|
* Amended 2026-06-12: "Verification substrate vs. plug-in tier (the predicate boundary)"
|
|
* + Rollout §6 exception: predicate-generation is CORE substrate, NOT an off-by-default
|
|
* Feature Capability.
|
|
*
|
|
* Key ADR assertions tested here:
|
|
* - "The probe family that generates must-NOT-have and edge predicates is core
|
|
* verification substrate, not an off-by-default Feature Capability."
|
|
* - "no capabilities/edge-probe/ Feature Capability may remove it."
|
|
* - "phase 6 does not migrate predicate-generation to an off-by-default Capability."
|
|
* - "The substrate must be available even when all Feature Capabilities are off."
|
|
*
|
|
* Tests do NOT read source files (.md/.cjs) and .includes() on them.
|
|
* All assertions drive the real exported functions and inspect typed return values.
|
|
*/
|
|
'use strict';
|
|
process.env.GSD_TEST_MODE = '1';
|
|
|
|
const { test, describe } = require('node:test');
|
|
const assert = require('node:assert/strict');
|
|
const path = require('node:path');
|
|
const fs = require('node:fs');
|
|
|
|
// ── Paths ─────────────────────────────────────────────────────────────────────
|
|
const REPO_ROOT = path.join(__dirname, '..');
|
|
const LIB = path.join(REPO_ROOT, 'gsd-core', 'bin', 'lib');
|
|
const PROBE_CORE_PATH = path.join(LIB, 'probe-core.cjs');
|
|
const EDGE_PROBE_PATH = path.join(LIB, 'edge-probe.cjs');
|
|
const CAPABILITIES_DIR = path.join(REPO_ROOT, 'capabilities');
|
|
|
|
// ── Helpers ───────────────────────────────────────────────────────────────────
|
|
|
|
/** Collect ids of all capability.json files under capabilities/. */
|
|
function collectCapabilityIds() {
|
|
const dirs = fs.readdirSync(CAPABILITIES_DIR, { withFileTypes: true });
|
|
const ids = [];
|
|
for (const d of dirs) {
|
|
if (!d.isDirectory()) continue;
|
|
const capFile = path.join(CAPABILITIES_DIR, d.name, 'capability.json');
|
|
if (fs.existsSync(capFile)) {
|
|
const parsed = JSON.parse(fs.readFileSync(capFile, 'utf8'));
|
|
ids.push({ id: parsed.id, role: parsed.role });
|
|
}
|
|
}
|
|
return ids;
|
|
}
|
|
|
|
/** Minimal valid item for probe-core analyzeCoverage. */
|
|
function makeItem(category, overrides = {}) {
|
|
return {
|
|
requirement_id: 'REQ-1',
|
|
category,
|
|
status: 'unresolved',
|
|
verification: null,
|
|
resolution: null,
|
|
reason: null,
|
|
probe: `probe-${category}`,
|
|
...overrides,
|
|
};
|
|
}
|
|
|
|
/** Minimal validators bundle (mirrors edge adapter shape). */
|
|
const REPRESENTATIVE_VALIDATORS = {
|
|
categories: ['boundary', 'adjacency', 'empty'],
|
|
verification: ['explicit', 'backstop'],
|
|
requiredFieldsByVerification: {
|
|
explicit: ['resolution'],
|
|
backstop: ['resolution'],
|
|
},
|
|
};
|
|
|
|
// ── [happy] ADR-857 §"Verification substrate vs. plug-in tier": substrate loads and
|
|
// functions as CORE regardless of capability config with NO capabilities active ───
|
|
describe('ADR-857 predicate boundary: substrate loads as core (no capabilities active)', () => {
|
|
test('probe-core.cjs resolves from gsd-core/bin/lib (core path)', () => {
|
|
// Confirm the module is loadable from the core lib path, not capabilities/
|
|
assert.ok(
|
|
fs.existsSync(PROBE_CORE_PATH),
|
|
`probe-core.cjs must exist at core path ${PROBE_CORE_PATH}`
|
|
);
|
|
const pc = require(PROBE_CORE_PATH);
|
|
assert.ok(pc != null, 'probe-core.cjs must export a non-null module');
|
|
});
|
|
|
|
test('edge-probe.cjs resolves from gsd-core/bin/lib (core path)', () => {
|
|
assert.ok(
|
|
fs.existsSync(EDGE_PROBE_PATH),
|
|
`edge-probe.cjs must exist at core path ${EDGE_PROBE_PATH}`
|
|
);
|
|
const ep = require(EDGE_PROBE_PATH);
|
|
assert.ok(ep != null, 'edge-probe.cjs must export a non-null module');
|
|
});
|
|
|
|
test('probe-core exports the locked VALID_STATUS set — substrate contract is present', () => {
|
|
const pc = require(PROBE_CORE_PATH);
|
|
// ADR: the contract is a stability contract — its shape must be consistent
|
|
assert.ok(Array.isArray(pc.VALID_STATUS), 'VALID_STATUS must be an array');
|
|
assert.deepEqual(
|
|
[...pc.VALID_STATUS].sort(),
|
|
['dismissed', 'resolved', 'unresolved'],
|
|
'VALID_STATUS must contain exactly resolved|dismissed|unresolved (the locked re-cut)'
|
|
);
|
|
});
|
|
|
|
test('probe-core exports all four required contract functions', () => {
|
|
const pc = require(PROBE_CORE_PATH);
|
|
// The four deterministic substrate functions defined in probe-core
|
|
assert.strictEqual(typeof pc.validateRequirement, 'function', 'validateRequirement must be a function');
|
|
assert.strictEqual(typeof pc.validateResolution, 'function', 'validateResolution must be a function');
|
|
assert.strictEqual(typeof pc.analyzeCoverage, 'function', 'analyzeCoverage must be a function');
|
|
assert.strictEqual(typeof pc.runProbeCli, 'function', 'runProbeCli must be a function');
|
|
});
|
|
|
|
test('probe-core.validateRequirement accepts a valid requirement with NO capability config', () => {
|
|
const pc = require(PROBE_CORE_PATH);
|
|
// No capability config passed — function must work unconditionally (non-toggleable substrate)
|
|
assert.doesNotThrow(
|
|
() => pc.validateRequirement({ id: 'REQ-42', text: 'the system rounds values to two decimal places' }),
|
|
'validateRequirement must not throw for a valid requirement when no capabilities are active'
|
|
);
|
|
});
|
|
|
|
test('probe-core.analyzeCoverage returns a contract-shaped coverage report with NO capability config', () => {
|
|
const pc = require(PROBE_CORE_PATH);
|
|
// Drive the core merge/rollup engine with a minimal item set and NO capability config
|
|
const items = [makeItem('boundary'), makeItem('adjacency')];
|
|
const report = pc.analyzeCoverage(items, [], REPRESENTATIVE_VALIDATORS);
|
|
|
|
// Contract shape: { items[], coverage: { applicable, resolved, unresolved, byVerification } }
|
|
assert.ok(Array.isArray(report.items), 'report.items must be an array');
|
|
assert.strictEqual(report.items.length, 2, 'report.items must contain both proposed items');
|
|
assert.ok(report.coverage != null && typeof report.coverage === 'object', 'report.coverage must be an object');
|
|
assert.strictEqual(typeof report.coverage.applicable, 'number', 'coverage.applicable must be a number');
|
|
assert.strictEqual(typeof report.coverage.resolved, 'number', 'coverage.resolved must be a number');
|
|
assert.strictEqual(typeof report.coverage.unresolved, 'number', 'coverage.unresolved must be a number');
|
|
assert.ok(report.coverage.byVerification != null, 'coverage.byVerification must be present');
|
|
|
|
// Exact values for genuineness
|
|
assert.strictEqual(report.coverage.applicable, 2, 'applicable must equal item count (2)');
|
|
assert.strictEqual(report.coverage.unresolved, 2, 'unresolved must be 2 (no resolutions provided)');
|
|
assert.strictEqual(report.coverage.resolved, 0, 'resolved must be 0 (no resolutions provided)');
|
|
assert.strictEqual(report.coverage.byVerification.explicit, 0, 'explicit count must be 0');
|
|
assert.strictEqual(report.coverage.byVerification.backstop, 0, 'backstop count must be 0');
|
|
});
|
|
|
|
test('edge-probe exports the locked shape vocabulary (VALID_SHAPES, TAXONOMY, EDGE_VALIDATORS)', () => {
|
|
const ep = require(EDGE_PROBE_PATH);
|
|
// VALID_SHAPES: exactly 5 shape names
|
|
assert.ok(ep.VALID_SHAPES instanceof Set, 'VALID_SHAPES must be a Set');
|
|
assert.strictEqual(ep.VALID_SHAPES.size, 5, 'VALID_SHAPES must have exactly 5 entries');
|
|
for (const s of ['numeric-range', 'collection', 'text', 'stateful', 'io']) {
|
|
assert.ok(ep.VALID_SHAPES.has(s), `VALID_SHAPES must contain "${s}"`);
|
|
}
|
|
// TAXONOMY: exactly 8 edge categories
|
|
assert.ok(Array.isArray(ep.TAXONOMY), 'TAXONOMY must be an array');
|
|
assert.strictEqual(ep.TAXONOMY.length, 8, 'TAXONOMY must have exactly 8 categories');
|
|
// EDGE_VALIDATORS: verification tiers must be exactly explicit|backstop
|
|
assert.deepEqual(
|
|
[...ep.EDGE_VALIDATORS.verification].sort(),
|
|
['backstop', 'explicit'],
|
|
'EDGE_VALIDATORS.verification must be ["explicit","backstop"]'
|
|
);
|
|
});
|
|
|
|
test('edge-probe.classifyShape returns a typed array result with NO capability config', () => {
|
|
const ep = require(EDGE_PROBE_PATH);
|
|
// ADR: substrate available without any capability toggling.
|
|
// Text chosen to trigger multiple concrete shapes:
|
|
// "save" (word-boundary match in SHAPE_CUES.stateful) → stateful
|
|
// "file" (SHAPE_CUES.io) → io
|
|
// "maximum count limit" (SHAPE_CUES['numeric-range']) → numeric-range
|
|
const shapes = ep.classifyShape('the system must save a file with a maximum count limit');
|
|
assert.ok(Array.isArray(shapes), 'classifyShape must return an array');
|
|
assert.ok(shapes.includes('numeric-range'), 'classifyShape must detect numeric-range from "maximum count limit"');
|
|
assert.ok(shapes.includes('stateful'), 'classifyShape must detect stateful from "save" (word-boundary cue)');
|
|
assert.ok(shapes.includes('io'), 'classifyShape must detect io from "file"');
|
|
});
|
|
|
|
test('edge-probe.proposeEdges returns unresolved items with contract shape with NO capability config', () => {
|
|
const ep = require(EDGE_PROBE_PATH);
|
|
const edges = ep.proposeEdges({ id: 'R-num', text: 'the score must stay within a numeric range between 0 and 100' });
|
|
assert.ok(Array.isArray(edges), 'proposeEdges must return an array');
|
|
assert.ok(edges.length > 0, 'proposeEdges must propose at least one edge for a numeric-range requirement');
|
|
// Every proposed edge must be unresolved with null verification
|
|
for (const edge of edges) {
|
|
assert.strictEqual(edge.requirement_id, 'R-num', 'edge.requirement_id must match input id');
|
|
assert.strictEqual(edge.status, 'unresolved', 'proposed edge status must be unresolved');
|
|
assert.strictEqual(edge.verification, null, 'proposed edge verification must be null');
|
|
assert.strictEqual(typeof edge.category, 'string', 'edge.category must be a string');
|
|
assert.strictEqual(typeof edge.probe, 'string', 'edge.probe must be a string');
|
|
}
|
|
// Specific: "numeric range between 0 and 100" => boundary category expected
|
|
const cats = edges.map(e => e.category);
|
|
assert.ok(cats.includes('boundary'), 'proposeEdges must include boundary category for numeric-range text');
|
|
});
|
|
});
|
|
|
|
// ── [negative] No off-by-default Feature Capability owns predicate-generation ──
|
|
describe('ADR-857 predicate boundary: no capabilities/edge-probe or prohibition-probe Feature Capability exists', () => {
|
|
test('capabilities/edge-probe directory does NOT exist (ADR-857: not an off-by-default plug-in)', () => {
|
|
const edgeProbeCap = path.join(CAPABILITIES_DIR, 'edge-probe');
|
|
assert.strictEqual(
|
|
fs.existsSync(edgeProbeCap),
|
|
false,
|
|
'capabilities/edge-probe must not exist — ADR-857 forbids predicate-generation as an off-by-default Capability'
|
|
);
|
|
});
|
|
|
|
test('capabilities/prohibition-probe directory does NOT exist (ADR-857: not an off-by-default plug-in)', () => {
|
|
const prohibitionProbeCap = path.join(CAPABILITIES_DIR, 'prohibition-probe');
|
|
assert.strictEqual(
|
|
fs.existsSync(prohibitionProbeCap),
|
|
false,
|
|
'capabilities/prohibition-probe must not exist — ADR-857 forbids predicate-generation as an off-by-default Capability'
|
|
);
|
|
});
|
|
|
|
test('real capability registry has NO entry with id "edge-probe" or "prohibition-probe" with role "feature"', () => {
|
|
const { capabilities } = require(path.join(LIB, 'capability-registry.cjs'));
|
|
const ids = Object.keys(capabilities);
|
|
|
|
// Assert no edge-probe feature capability
|
|
const hasEdgeProbeFeature = ids.some(
|
|
id => id === 'edge-probe' && capabilities[id].role === 'feature'
|
|
);
|
|
assert.strictEqual(
|
|
hasEdgeProbeFeature,
|
|
false,
|
|
'registry must NOT contain a feature capability with id "edge-probe"'
|
|
);
|
|
|
|
// Assert no prohibition-probe feature capability
|
|
const hasProhibitionProbeFeature = ids.some(
|
|
id => id === 'prohibition-probe' && capabilities[id].role === 'feature'
|
|
);
|
|
assert.strictEqual(
|
|
hasProhibitionProbeFeature,
|
|
false,
|
|
'registry must NOT contain a feature capability with id "prohibition-probe"'
|
|
);
|
|
|
|
// Also verify neither id exists at all (not even as a different role)
|
|
assert.ok(
|
|
!ids.includes('edge-probe'),
|
|
'registry must not contain any capability with id "edge-probe"'
|
|
);
|
|
assert.ok(
|
|
!ids.includes('prohibition-probe'),
|
|
'registry must not contain any capability with id "prohibition-probe"'
|
|
);
|
|
});
|
|
|
|
test('capability.json files on disk contain no id matching edge-probe or prohibition-probe with role feature', () => {
|
|
const allCaps = collectCapabilityIds();
|
|
const probeFeatures = allCaps.filter(
|
|
c => (c.id === 'edge-probe' || c.id === 'prohibition-probe') && c.role === 'feature'
|
|
);
|
|
assert.deepEqual(
|
|
probeFeatures,
|
|
[],
|
|
`No capability.json on disk may declare id "edge-probe" or "prohibition-probe" with role "feature"; found: ${JSON.stringify(probeFeatures)}`
|
|
);
|
|
});
|
|
});
|
|
|
|
// ── [happy] Predicate substrate lives in core (bin/lib), not in capabilities/ ──
|
|
describe('ADR-857 predicate boundary: substrate lives in core, not in capabilities/', () => {
|
|
test('probe-core.cjs is resolvable from gsd-core/bin/lib — the core module tier', () => {
|
|
// Must resolve from core lib, not from any capability folder
|
|
const resolved = require.resolve(PROBE_CORE_PATH);
|
|
assert.ok(
|
|
resolved.includes(path.join('gsd-core', 'bin', 'lib')),
|
|
`probe-core.cjs must resolve from gsd-core/bin/lib (got: ${resolved})`
|
|
);
|
|
assert.ok(
|
|
!resolved.includes('capabilities'),
|
|
`probe-core.cjs must NOT resolve from any capabilities/ folder (got: ${resolved})`
|
|
);
|
|
});
|
|
|
|
test('edge-probe.cjs is resolvable from gsd-core/bin/lib — the core module tier', () => {
|
|
const resolved = require.resolve(EDGE_PROBE_PATH);
|
|
assert.ok(
|
|
resolved.includes(path.join('gsd-core', 'bin', 'lib')),
|
|
`edge-probe.cjs must resolve from gsd-core/bin/lib (got: ${resolved})`
|
|
);
|
|
assert.ok(
|
|
!resolved.includes('capabilities'),
|
|
`edge-probe.cjs must NOT resolve from any capabilities/ folder (got: ${resolved})`
|
|
);
|
|
});
|
|
|
|
test('no capabilities/*/capability.json declares id "edge-probe" or "prohibition-probe" as a feature', () => {
|
|
// Scan all capability.json files on disk and confirm none are probe features
|
|
const allCaps = collectCapabilityIds();
|
|
const featureIds = allCaps.filter(c => c.role === 'feature').map(c => c.id);
|
|
|
|
assert.ok(
|
|
!featureIds.includes('edge-probe'),
|
|
`Feature capability ids must not include "edge-probe"; found: ${JSON.stringify(featureIds)}`
|
|
);
|
|
assert.ok(
|
|
!featureIds.includes('prohibition-probe'),
|
|
`Feature capability ids must not include "prohibition-probe"; found: ${JSON.stringify(featureIds)}`
|
|
);
|
|
});
|
|
});
|
|
|
|
// ── [negative/BVA] Toggling ALL capability config keys off does NOT change substrate
|
|
// availability or output — substrate is non-toggleable ─────────────────────────
|
|
describe('ADR-857 predicate boundary: substrate is non-toggleable (all-off config does not affect it)', () => {
|
|
test('probe-core functions return identical output before and after constructing an all-off config', () => {
|
|
const ep = require(EDGE_PROBE_PATH);
|
|
const { configKeys } = require(path.join(LIB, 'capability-registry.cjs'));
|
|
|
|
// Build a config object with every known workflow.* and intel/profile key set to false
|
|
const allOffConfig = {};
|
|
for (const key of Object.keys(configKeys)) {
|
|
allOffConfig[key] = false;
|
|
}
|
|
|
|
// "Before": call analyzeCoverage with a representative set
|
|
const reqText = 'the API endpoint accepts a list of items with a maximum count threshold and stores each one';
|
|
const BEFORE_shapes = ep.classifyShape(reqText);
|
|
const BEFORE_edges = ep.proposeEdges({ id: 'R-bva', text: reqText });
|
|
const BEFORE_report = ep.analyzeCoverage([{ id: 'R-bva', text: reqText }], []);
|
|
|
|
// Simulate "all capabilities off" by confirming the config object is fully false
|
|
// (The substrate does not accept a config parameter — this BVA tests that the
|
|
// probe functions are unconditionally available regardless of config state)
|
|
const allOff = Object.values(allOffConfig).every(v => v === false);
|
|
assert.strictEqual(allOff, true, 'all config keys must be set to false in the all-off config');
|
|
|
|
// "After all-off config": call the same functions again — results must be identical
|
|
const AFTER_shapes = ep.classifyShape(reqText);
|
|
const AFTER_edges = ep.proposeEdges({ id: 'R-bva', text: reqText });
|
|
const AFTER_report = ep.analyzeCoverage([{ id: 'R-bva', text: reqText }], []);
|
|
|
|
// ADR-857: the substrate is non-toggleable — output must not change
|
|
assert.deepEqual(
|
|
AFTER_shapes,
|
|
BEFORE_shapes,
|
|
'classifyShape must return identical output regardless of capability config state'
|
|
);
|
|
assert.deepEqual(
|
|
AFTER_edges,
|
|
BEFORE_edges,
|
|
'proposeEdges must return identical output regardless of capability config state'
|
|
);
|
|
assert.deepEqual(
|
|
AFTER_report,
|
|
BEFORE_report,
|
|
'analyzeCoverage must return identical output regardless of capability config state'
|
|
);
|
|
|
|
// Specific value assertion to prevent vacuous-truth: shapes must include at least two types
|
|
assert.ok(AFTER_shapes.length >= 2, `classifyShape must detect at least 2 shapes for complex text (got ${AFTER_shapes.length})`);
|
|
assert.ok(AFTER_edges.length >= 2, `proposeEdges must propose at least 2 edges for this requirement (got ${AFTER_edges.length})`);
|
|
});
|
|
|
|
test('probe-core.validateResolution rejects an invalid status regardless of all-off config (BVA: status boundary)', () => {
|
|
const pc = require(PROBE_CORE_PATH);
|
|
|
|
// BVA: exact boundary — 'unresolved' (valid, limit case) vs 'covered' (was valid pre-re-cut, now invalid)
|
|
// Valid status (limit): must NOT throw
|
|
assert.doesNotThrow(
|
|
() => pc.validateResolution(
|
|
{ requirement_id: 'R1', category: 'boundary', status: 'unresolved', verification: null, resolution: null, reason: null },
|
|
REPRESENTATIVE_VALIDATORS
|
|
),
|
|
'validateResolution must accept status="unresolved" (the valid boundary case)'
|
|
);
|
|
|
|
// Invalid status (just outside the locked set): must throw with a message naming the bad status
|
|
assert.throws(
|
|
() => pc.validateResolution(
|
|
{ requirement_id: 'R1', category: 'boundary', status: 'covered', verification: null, resolution: null, reason: null },
|
|
REPRESENTATIVE_VALIDATORS
|
|
),
|
|
(err) => {
|
|
assert.ok(err instanceof Error, 'must throw an Error');
|
|
assert.ok(
|
|
err.message.includes('covered'),
|
|
`error message must name the invalid status "covered"; got: "${err.message}"`
|
|
);
|
|
return true;
|
|
},
|
|
'validateResolution must reject status="covered" (the pre-re-cut status that is now outside the locked set)'
|
|
);
|
|
});
|
|
|
|
test('probe-core.analyzeCoverage rejects a resolved item missing verification tier (BVA: verification null boundary)', () => {
|
|
const pc = require(PROBE_CORE_PATH);
|
|
|
|
// BVA: resolved + null verification is INVALID (one step below the minimum)
|
|
const badItems = [
|
|
makeItem('boundary', { status: 'resolved', verification: null, resolution: 'AC text' }),
|
|
];
|
|
assert.throws(
|
|
() => pc.analyzeCoverage(badItems, [], REPRESENTATIVE_VALIDATORS),
|
|
(err) => {
|
|
assert.ok(err instanceof Error, 'must throw an Error');
|
|
assert.ok(
|
|
err.message.toLowerCase().includes('verification'),
|
|
`error message must mention "verification"; got: "${err.message}"`
|
|
);
|
|
return true;
|
|
},
|
|
'analyzeCoverage must reject a resolved item with verification=null (verification required at this boundary)'
|
|
);
|
|
|
|
// BVA: resolved + valid verification tier is VALID (at the minimum)
|
|
const goodItems = [
|
|
makeItem('boundary', { status: 'resolved', verification: 'explicit', resolution: 'acceptance criterion text' }),
|
|
];
|
|
const report = pc.analyzeCoverage(goodItems, [], REPRESENTATIVE_VALIDATORS);
|
|
assert.strictEqual(report.coverage.resolved, 1, 'resolved count must be 1 for a valid resolved item');
|
|
assert.strictEqual(report.coverage.byVerification.explicit, 1, 'byVerification.explicit must be 1');
|
|
});
|
|
|
|
test('all capability config keys being false does not prevent probe-core from loading or exporting VALID_STATUS', () => {
|
|
// This test confirms the substrate is non-conditionally loaded (not behind any
|
|
// capability gate) — if probe-core depended on a capability config, VALID_STATUS
|
|
// would differ or throw when the underlying capability was off.
|
|
const pc = require(PROBE_CORE_PATH);
|
|
const { configKeys } = require(path.join(LIB, 'capability-registry.cjs'));
|
|
|
|
// With every key false, VALID_STATUS must remain the locked set
|
|
const allOffConfig = {};
|
|
for (const key of Object.keys(configKeys)) {
|
|
allOffConfig[key] = false;
|
|
}
|
|
|
|
// probe-core does not accept a config — it must be unconditional
|
|
// Exact value check (genuineness: flipping one would fail)
|
|
assert.deepEqual(
|
|
[...pc.VALID_STATUS].sort(),
|
|
['dismissed', 'resolved', 'unresolved'],
|
|
'VALID_STATUS must be identical regardless of all-off config (substrate is non-toggleable)'
|
|
);
|
|
|
|
// Also verify configKeys has at least some keys (ensures the all-off scenario is meaningful)
|
|
assert.ok(
|
|
Object.keys(configKeys).length > 0,
|
|
'configKeys must be non-empty (all-off scenario must be meaningful)'
|
|
);
|
|
});
|
|
});
|