Files
msd-core/tests/workstream-scoped-paths.test.cjs
Tom Boucher c6df4e1e46 fix(#4455): autonomous.md and complete-milestone.md resolve STATE/ROADMAP/MILESTONES/PROJECT/REQUIREMENTS through the workstream-scoped init fields (#4542)
* fix(#4455): thread workstream-scoped paths through autonomous and complete-milestone workflows

autonomous.md and complete-milestone.md read/wrote hardcoded literal
`.planning/STATE.md` / `.planning/ROADMAP.md` / `.planning/milestones/...`
paths in their shell fences, bypassing workstream scoping entirely. With
GSD_WORKSTREAM=alpha set, planningDir(cwd) correctly resolves into
workstreams/alpha/, but a literal `cat .planning/STATE.md` still read the
ROOT file (or silently returned empty if root state was absent) --
reproduced deterministically in the issue's own repro.

Root cause: each workflow step's bash fence is a separate shell
invocation, and cmdInitManager/cmdInitCompleteMilestone's JSON payloads
never carried resolved state_path/roadmap_path/archive_dir fields for the
workflows to extract -- unlike cmdInitPlanPhase, which already does this
correctly and is the pattern this fix mirrors.

- src/init.cts: cmdInitManager and cmdInitCompleteMilestone now emit
  state_path/roadmap_path (workstream-scoped via planningDir(cwd),
  existence-checked, toPosixPath'd, null when absent -- identical to
  cmdInitPlanPhase's existing contract) and archive_dir (the milestone
  archive directory, composed the same way milestone.cts's already-correct
  archive helper does per #1911).
- autonomous.md: discover_phases and iterate now extract state_path via
  the already-fetched INIT_MANAGER payload instead of hardcoding
  `.planning/STATE.md`; iterate's second, previously-separate hardcoded
  read is folded into the same fence (no double-fetch); lifecycle step 5b
  checks the resolved archive_dir instead of a hardcoded milestones path.
- complete-milestone.md's reorganize_roadmap_and_delete_originals step
  (which previously called no init command at all) now fetches
  init.complete-milestone and uses the resolved roadmap_path/state_path/
  archive_dir for the backlog read, the write-guard sentinel's armed
  content, the Write-tool target for the reorganized ROADMAP.md (the
  sentinel fence now echoes the resolved path so the executing agent can
  see it), and the safety-commit --files list. `.planning/MILESTONES.md`
  and `.planning/PROJECT.md` stay literal root paths -- documented shared
  files, per the issue's explicit "not a blanket replacement" scope.

Regression tests extract and execute the real bash fences (with a stubbed
gsd_run) rather than string-matching the markdown, covering flat mode
(unaffected), an active workstream (the issue's own repro shape, now
correctly resolving), the no-double-fetch requirement, and a dedicated
guard locking MILESTONES.md/PROJECT.md as shared.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* docs(#4455): add changeset for workstream-scoped autonomous/complete-milestone fix

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* fix(#4455): close write-guard gap on workstream-scoped curated paths

Isolated security review of the #4455 fix (workstream-scoped STATE/
ROADMAP/milestone-archive path resolution in autonomous.md and
complete-milestone.md) flagged that hooks/gsd-write-guard.js's
CURATED_PATTERNS only matched root-level .planning/ paths, never
.planning/[<project>/]workstreams/<ws>/... — meaning the catastrophic-
shrink guard silently never engaged for a workstream-scoped write.
This is directly relevant here: the #4455 change makes a workstream-
scoped ROADMAP.md Write reachable via complete-milestone.md's own
explicit sentinel-hatch instructions, which assume guard protection
that did not actually exist for that path shape. Extended
CURATED_PATTERNS with the three workstream-scoped equivalents;
consumeSentinelFor's own path-derivation logic needed no change since
it derives from the actual write target. Verified empirically (a
293->16 line workstream ROADMAP.md shrink now correctly returns
exit 2 / decision:"block") and with 5 new regression tests.

Also addressed a code-review nit on the core #4455 fix:
cmdInitCompleteMilestone called planningDir(cwd) three separate
times instead of caching it once.

Accepted as-is (not fixed): complete-milestone.md's
reorganize_roadmap_and_delete_originals step re-fetches
`gsd_run query init.complete-milestone` three times across its
fences rather than merging the first two (no state-changing Write
between them, unlike autonomous.md's iterate step which does merge).
This is an efficiency nit, not a correctness bug — merging risks
disrupting the step's prose flow and its existing binding test for a
non-functional gain.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* docs(#4455): add changeset for the write-guard workstream-scope fix

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* fix(#4455): fix gsd-test-surfaced regressions from workstream-path fix

Running gsd-test against the full #4455 diff (including the write-guard
security fix and the cmdInitCompleteMilestone caching nit) surfaced four
real, non-flaky failures, all direct consequences of editing
gsd-core/workflows/autonomous.md and complete-milestone.md:

1. tests/autonomous-converge.test.cjs pinned the OLD hardcoded
   `STATE_CONTENT=$(cat .planning/STATE.md ...)` read in both
   discover_phases and iterate. That is exactly the literal-path
   behavior #4455 fixes, so the test needed updating to assert the new
   init.manager-resolved `STATE_PATH` read instead (with an explicit
   doesNotMatch guard against regressing to the old literal).

2. tests/workstream-scoped-paths.test.cjs's own "no-double-fetch" test
   counted gsd_run invocations via a shell variable incremented inside
   the stub function — but `INIT_MANAGER=$(gsd_run ...)` runs gsd_run
   inside the command-substitution SUBSHELL, so that increment never
   survives back to the parent shell and the counter always read 0.
   Switched to a file-based call log (one byte appended per call),
   which survives the subshell boundary.

3. tests/compact-content-partition-guard.test.cjs's disjointness check
   flagged the reorganize_roadmap_and_delete_originals step's new
   `INIT_CM=$(gsd_run query init.complete-milestone)` fetch (added 3x,
   per the accepted-as-is disposition in the prior commit) as
   byte-identical to a pre-existing, unrelated fetch already present in
   complete-milestone/detail/elaboration.md's handle_branches section
   (§2). Same idiom, same conventional variable name, coincidentally
   colliding across the spine/detail split boundary. Renamed the new
   step's local variable to INIT_REORG — a distinct, purpose-specific
   name is arguably better practice anyway for two logically unrelated
   fetches, and it removes the literal collision honestly rather than
   restructuring the split.

4. tests/benchmark-compact-content.test.cjs reported real byte-count
   drift in the committed baseline (autonomous.md and
   complete-milestone.md both grew from the #4455 content). Refreshed
   via `node scripts/benchmark-compact-content.cjs --write`.

Verified: node scripts/benchmark-compact-content.cjs --check now
reports the baseline up to date; a standalone invocation of
checkDisjointness() against the real repo state now reports zero
violations across all 6 registered splits; manual bash-fence execution
of both the autonomous.md iterate fence (call count = 1) and the
complete-milestone.md backlog fence (with INIT_REORG) confirms correct
behavior.

Emitted-Drift-Ack-Growth: autonomous.md — #4455 workstream-scoped STATE.md path resolution replaces hardcoded literal reads
Emitted-Drift-Ack-Growth: complete-milestone.md — #4455 workstream-scoped STATE/ROADMAP/archive path resolution replaces hardcoded literal reads
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* fix(#4455): MILESTONES.md/PROJECT.md/REQUIREMENTS.md are workstream-scoped too, and so is project-only mode

Fresh isolated code-review and security-review passes against the full
diff (run after the previous gsd-test-surfaced fixups landed) each
found one real, confirmed defect:

Code review: the safety-commit `--files` list and the REQUIREMENTS.md
`git rm` step both hardcoded `.planning/MILESTONES.md`,
`.planning/PROJECT.md`, and `.planning/REQUIREMENTS.md` as literal
root paths — but src/milestone.cts's cmdMilestoneComplete writes
MILESTONES.md via `planningPaths(cwd).planning` (the workstream base)
and PROJECT.md/REQUIREMENTS.md resolve the same way through
`planningPaths().project`/`.requirements` (src/planning-workspace.cts).
Only `todos` is the documented root-scoped exception (#4256); an
earlier version of this fix wrongly generalized that exception to
MILESTONES.md/PROJECT.md too, and the now-corrected test previously
enshrined that wrong behavior as intended. Under an active workstream,
the safety commit would have silently missed the actual files
`milestone complete` just wrote, and the git-rm step would have
targeted the wrong (root) REQUIREMENTS.md entirely. Fixed by exposing
`milestones_path`/`project_path`/`requirements_path` from
init.complete-milestone (src/init.cts) and resolving all three through
them, the same pattern already used for state_path/roadmap_path/
archive_dir. The four remaining literal MILESTONES.md/PROJECT.md
mentions elsewhere in complete-milestone.md (lines ~12-13, ~441, ~607,
~662) are display-only prose in status/summary message templates, not
actual file operations — left as-is; they are a cosmetic path-display
inaccuracy under an active workstream, not a data-integrity bug like
the two fixed here.

Security review: confirmed the write-guard fix from the prior commit
is correct and complete for workstream scoping, and independently
surfaced the same project-only gap the code-review pass above also
caught structurally: `CURATED_PATTERNS` had no pattern for
`.planning/<project>/...` (GSD_PROJECT set, GSD_WORKSTREAM unset) —
planningDir(cwd) supports that shape independently of workstream
nesting, so it is reachable, not hypothetical. Fixed by adding three
more patterns, verified empirically (a project-scoped 292->16 line
ROADMAP.md shrink now correctly returns exit 2 / decision:"block")
and with 6 new regression tests.

Verified: manual bash-fence execution of the corrected commit-files
and requirements-rm fences (both flat mode and GSD_WORKSTREAM=alpha)
resolves to the right paths in both cases; a standalone invocation of
checkDisjointness() against the real repo state still reports zero
violations; the benchmark baseline was refreshed again for the further
size change (already covered by the existing Emitted-Drift-Ack-Growth
trailer on complete-milestone.md two commits back — that trailer is
read over the whole merge-base..HEAD range, not per-commit, so it
still applies here).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* docs(#4455): backfill changeset PR numbers and correct final scope

pr: 0 -> pr: 4542 for both fragments, and updated both bodies to
reflect the final fix scope (MILESTONES/PROJECT/REQUIREMENTS are
workstream-scoped too, not shared-root exceptions; the write-guard fix
also covers project-only scoping, not just workstream nesting).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* fix(#4455): lifecycle-5b archive-path assertions use the fence's own separator, not path.join

PR CI's windows-latest shard 3/3 failed: "expected ls to find the root
archive file, got: ...\milestones-root/v1.0-ROADMAP.md". The
autonomous.md lifecycle step 5b fence composes the checked path with a
literal bash `/` (`"${ARCHIVE_DIR}/v${milestone_version}-ROADMAP.md"`),
which on Windows yields a MIXED-separator path — Windows backslashes
from archiveDir plus one trailing `/`. My test's assertion used
path.join(archiveDir, 'v1.0-ROADMAP.md') instead, which on a Windows
Node process produces an all-backslash path that never matches the
fence's mixed-separator output. Both assertions in that describe block
now mirror the fence's own literal `/` concatenation
(`${archiveDir}/v1.0-ROADMAP.md`) instead of path.join — matching the
style the other two describe blocks in this same file (safety-commit
--files list) already used correctly for the identical archive-dir
pattern, so this brings the one outlier into line rather than
introducing a new idiom.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* fix(#4455): write-guard sentinel comparison now realpath-resolves the token, not just the target

PR CI's macos-latest full-test shard 2/3 failed a #4455 test: "the
sentinel hatch ... unblocks a workstream ROADMAP.md write" got status
2 (still blocked) instead of 0.

Root cause, unrelated to the Windows fix in the previous commit:
hooks/gsd-write-guard.js's main flow realpath-resolves the Write
TARGET before the curated-pattern match (round 9 Minor 1's
symlink-before-match fix, `filePath = fs.realpathSync(filePath)`), but
consumeSentinelFor resolved the sentinel TOKEN's absolute path via
plain path.resolve() with no realpath step. On macOS, os.tmpdir()
resolves through a /var -> /private/var symlink, so a test's cwd
(lexically under /var/folders/...) and its realpath'd target
(/private/var/folders/...) diverge — an armed, correct sentinel then
never matches the realpath'd target string, and the guard stays
incorrectly blocked. This is not macOS-specific in principle: ANY cwd
sitting under a symlink (a symlinked project checkout, a symlinked
worktree) hits the same asymmetry — gsd-test's Linux bench runs never
caught it because /tmp there is not a symlink.

Fixed by applying the same fs.realpathSync (with the same
keep-lexical-on-failure fallback the caller already uses) to the
token's resolved path before comparing. The named file is already
known to exist at this point (the caller only reaches consumeSentinelFor
after successfully reading the target), so realpath is expected to
succeed in the legitimate case; a garbage/mismatched token still fails
safe (verified — falls back to the lexical path, still mismatches,
stays blocked).

Verified: reproduced the exact bug locally (macOS) via os.tmpdir()
before the fix, confirmed it resolves after; the negative case
(sentinel armed for a DIFFERENT file) still correctly blocks; the
pre-existing relative-token sentinel tests (predating #4455) still
pass; a garbage/non-existent token still fails safe. Added a
deterministic, cross-platform regression test using an explicit
symlink (skipped on Windows, matching the existing round-9 symlink
test's own skip condition) so this class of bug is caught by
gsd-test's Linux bench too, not only by a real macOS CI run.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

---------

Co-authored-by: sim <sim@local>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-08 04:56:11 -04:00

386 lines
22 KiB
JavaScript

// allow-test-rule: source-text-is-the-product see #4455
// Workflow .md files — their text IS what the runtime loads. Testing text
// content (as extracted, executed bash fences) tests the deployed contract.
// Per CONTRIBUTING.md exception matrix.
/**
* GSD Tools Tests - autonomous.md and complete-milestone.md workstream-scoped
* STATE/ROADMAP/archive paths (#4455)
*
* Both workflows used to read/write hardcoded literal `.planning/STATE.md` /
* `.planning/ROADMAP.md` / `.planning/milestones/...` paths in their shell
* fences — bypassing workstream scoping entirely. When GSD_WORKSTREAM is set,
* `init.manager`/`init.complete-milestone` resolve `state_path`/`roadmap_path`/
* `archive_dir` into the workstream, but the literal reads/writes still hit
* root `.planning/` (or silently returned empty).
*
* These tests extract the real bash fences from the workflow files and
* execute them (with a stubbed `gsd_run`) rather than string-matching the
* markdown — the same idiom tests/new-milestone-clear-phases.test.cjs uses.
*
* One file (not two) per scripts/lint-test-file-count.cjs's per-module cap —
* tests/workstream.test.cjs already owns the "workstream" module name, so
* this is the second and last slot; the two workflows are kept apart via
* top-level describe blocks instead of separate files.
*/
const { test, describe, beforeEach, afterEach } = require('node:test');
const assert = require('node:assert/strict');
const fs = require('fs');
const path = require('path');
const os = require('os');
const { runHook: runHookSeam } = require('./helpers/process-seam.cjs');
const { throwIfFailed } = require('./helpers/git-fixture.cjs');
const { scanFencedBlocks } = require('../gsd-core/bin/lib/markdown-sectionizer.cjs');
const { cleanup } = require('./helpers.cjs');
/** Return the raw text of every ```bash fenced block in `text`. */
function extractBashBlocks(text) {
const lines = text.split(/\r?\n/);
const blocks = [];
for (const block of scanFencedBlocks(lines)) {
if (block.closeLineIdx === -1) continue;
if ((block.infoString || '').trim() !== 'bash') continue;
blocks.push(lines.slice(block.openLineIdx + 1, block.closeLineIdx).join('\n'));
}
return blocks;
}
// Locate the first ```bash fence strictly between two boundary strings.
function extractFenceBetween(markdown, startMarker, endMarker) {
const startIdx = markdown.indexOf(startMarker);
const endIdx = markdown.indexOf(endMarker);
assert.ok(startIdx !== -1, `marker not found: ${startMarker}`);
assert.ok(endIdx !== -1, `marker not found: ${endMarker}`);
assert.ok(startIdx < endIdx, `${startMarker} must precede ${endMarker}`);
const section = markdown.slice(startIdx, endIdx);
const bashBlocks = extractBashBlocks(section);
assert.ok(bashBlocks.length > 0, `no bash fence found between "${startMarker}" and "${endMarker}"`);
return bashBlocks[0];
}
// Locate the ```bash fence containing `marker`, between two boundary strings.
function extractFenceContaining(markdown, startMarker, endMarker, marker) {
const startIdx = markdown.indexOf(startMarker);
const endIdx = markdown.indexOf(endMarker);
assert.ok(startIdx !== -1 && endIdx !== -1 && startIdx < endIdx, 'boundary markers not found in order');
const section = markdown.slice(startIdx, endIdx);
for (const block of extractBashBlocks(section)) {
if (block.includes(marker)) return block;
}
assert.fail(`no bash fence containing "${marker}" found between "${startMarker}" and "${endMarker}"`);
return null;
}
describe('autonomous.md workstream-scoped paths (#4455)', () => {
const WORKFLOW_PATH = path.join(__dirname, '..', 'gsd-core', 'workflows', 'autonomous.md');
const content = fs.readFileSync(WORKFLOW_PATH, 'utf8');
const discoverPhasesFence = extractFenceBetween(content, '## 2. Discover Phases', '## 3. Execute Phase');
const iterateFence = extractFenceBetween(content, '## 4. Iterate', '## 5. Lifecycle');
const lifecycle5bFence = extractFenceContaining(content, '## 5. Lifecycle', '## 6. Handle Blocker', 'ARCHIVE_DIR');
let tmpDir;
beforeEach(() => {
tmpDir = fs.mkdtempSync(path.join(os.tmpdir(), 'gsd-autonomous-ws-'));
});
afterEach(() => {
cleanup(tmpDir);
});
/**
* Write a canned init.manager-shaped JSON payload and a gsd_run stub that
* returns it verbatim. Each call also appends one byte to a call-log file
* — NOT a shell variable increment, because `INIT_MANAGER=$(gsd_run ...)`
* runs gsd_run inside the command-substitution SUBSHELL, so a variable
* mutated there never survives back into the caller's shell.
*/
function stubGsdRun(jsonPayload) {
const jsonPath = path.join(tmpDir, 'init-manager.json');
const callLogPath = path.join(tmpDir, 'gsd-run-calls.log');
fs.writeFileSync(jsonPath, JSON.stringify(jsonPayload));
fs.writeFileSync(callLogPath, '');
return `gsd_run() { printf 'x' >> "${callLogPath}"; cat "${jsonPath}"; }\n`;
}
/** Number of gsd_run invocations recorded by the most recent stubGsdRun-backed script. */
function gsdRunCallCount() {
return fs.readFileSync(path.join(tmpDir, 'gsd-run-calls.log'), 'utf8').length;
}
describe('discover_phases step: reads STATE.md from init.manager state_path, not a hardcoded literal', () => {
test('flat mode: no GSD_WORKSTREAM — resolves the root STATE.md path (regression guard)', () => {
const statePath = path.join(tmpDir, 'STATE-root.md');
fs.writeFileSync(statePath, '# Root State\n');
const script = `${stubGsdRun({ state_path: statePath })}${discoverPhasesFence}\nprintf 'STATE_CONTENT=[%s]\\n' "$STATE_CONTENT"`;
const r = runHookSeam('-c', [script], { interpreter: 'bash', cwd: tmpDir });
throwIfFailed(r, 'bash <discover_phases fence>');
assert.ok(r.stdout.includes('STATE_CONTENT=[# Root State'),
`expected root STATE.md content, got: ${r.stdout}`);
});
test('GSD_WORKSTREAM=alpha: reads the workstream-scoped STATE.md, not the root one (#4455 regression)', () => {
const rootStatePath = path.join(tmpDir, 'STATE-root.md');
fs.writeFileSync(rootStatePath, '# Root State — must not be read\n');
const wsStatePath = path.join(tmpDir, 'STATE-alpha.md');
fs.writeFileSync(wsStatePath, '# Workstream Alpha State\n');
const script = `${stubGsdRun({ state_path: wsStatePath })}${discoverPhasesFence}\nprintf 'STATE_CONTENT=[%s]\\n' "$STATE_CONTENT"`;
const r = runHookSeam('-c', [script], { interpreter: 'bash', cwd: tmpDir });
throwIfFailed(r, 'bash <discover_phases fence>');
assert.ok(r.stdout.includes('STATE_CONTENT=[# Workstream Alpha State'),
`expected workstream STATE.md content, got: ${r.stdout}`);
assert.ok(!r.stdout.includes('Root State'),
`must not have read the root STATE.md, got: ${r.stdout}`);
});
});
describe('iterate step: single init.manager fetch backs both the re-filter and the fresh re-read', () => {
test('flat mode: resolves the root STATE.md path (regression guard)', () => {
const statePath = path.join(tmpDir, 'STATE-root.md');
fs.writeFileSync(statePath, '# Root State\n');
const script = `${stubGsdRun({ state_path: statePath })}${iterateFence}`;
const r = runHookSeam('-c', [script], { interpreter: 'bash', cwd: tmpDir });
throwIfFailed(r, 'bash <iterate fence>');
// The fence's own `cat "$STATE_PATH"` line prints the raw re-read to stdout.
assert.ok(r.stdout.includes('# Root State'), `expected root STATE.md content, got: ${r.stdout}`);
});
test('GSD_WORKSTREAM=alpha: re-reads the workstream STATE.md, not root (#4455 regression)', () => {
const rootStatePath = path.join(tmpDir, 'STATE-root.md');
fs.writeFileSync(rootStatePath, '# Root State — must not be read\n');
const wsStatePath = path.join(tmpDir, 'STATE-alpha.md');
fs.writeFileSync(wsStatePath, '# Workstream Alpha State\n');
const script = `${stubGsdRun({ state_path: wsStatePath })}${iterateFence}`;
const r = runHookSeam('-c', [script], { interpreter: 'bash', cwd: tmpDir });
throwIfFailed(r, 'bash <iterate fence>');
assert.ok(r.stdout.includes('# Workstream Alpha State'),
`expected workstream STATE.md content, got: ${r.stdout}`);
assert.ok(!r.stdout.includes('Root State'),
`must not have read the root STATE.md, got: ${r.stdout}`);
});
test('does not double-fetch init.manager within the iterate fence (no-double-fetch requirement)', () => {
const statePath = path.join(tmpDir, 'STATE-root.md');
fs.writeFileSync(statePath, '# Root State\n');
const script = `${stubGsdRun({ state_path: statePath })}${iterateFence}`;
const r = runHookSeam('-c', [script], { interpreter: 'bash', cwd: tmpDir });
throwIfFailed(r, 'bash <iterate fence>');
assert.strictEqual(gsdRunCallCount(), 1,
`iterate fence must call gsd_run exactly once (no double-fetch), got ${gsdRunCallCount()}; stdout: ${r.stdout}`);
});
});
describe('lifecycle step 5b: archive existence check uses init.manager archive_dir, not a hardcoded literal', () => {
test('flat mode: checks the root milestones/ archive dir (regression guard)', () => {
const archiveDir = path.join(tmpDir, 'milestones-root');
fs.mkdirSync(archiveDir, { recursive: true });
fs.writeFileSync(path.join(archiveDir, 'v1.0-ROADMAP.md'), '# Archived Roadmap\n');
const script = `milestone_version="1.0"\n${stubGsdRun({ archive_dir: archiveDir })}${lifecycle5bFence}`;
const r = runHookSeam('-c', [script], { interpreter: 'bash', cwd: tmpDir });
throwIfFailed(r, 'bash <lifecycle 5b fence>');
// The fence concatenates with a literal bash `/` ("${ARCHIVE_DIR}/v...-ROADMAP.md"),
// never path.join — on Windows that yields a MIXED-separator path (backslashes
// from archiveDir + one trailing `/`), which path.join's all-backslash output
// does not match. Mirror the fence's own concatenation instead (#4455 CI finding).
assert.ok(r.stdout.includes(`${archiveDir}/v1.0-ROADMAP.md`),
`expected ls to find the root archive file, got: ${r.stdout}`);
});
test('GSD_WORKSTREAM=alpha: checks the workstream-scoped archive dir, not root (#4455 regression)', () => {
const rootArchiveDir = path.join(tmpDir, 'milestones-root');
fs.mkdirSync(rootArchiveDir, { recursive: true });
fs.writeFileSync(path.join(rootArchiveDir, 'v1.0-ROADMAP.md'), '# Root Archived Roadmap — must not be found\n');
const wsArchiveDir = path.join(tmpDir, 'milestones-alpha');
fs.mkdirSync(wsArchiveDir, { recursive: true });
fs.writeFileSync(path.join(wsArchiveDir, 'v1.0-ROADMAP.md'), '# Workstream Archived Roadmap\n');
const script = `milestone_version="1.0"\n${stubGsdRun({ archive_dir: wsArchiveDir })}${lifecycle5bFence}`;
const r = runHookSeam('-c', [script], { interpreter: 'bash', cwd: tmpDir });
throwIfFailed(r, 'bash <lifecycle 5b fence>');
// See the flat-mode test above for why this is a literal `/` join, not path.join.
assert.ok(r.stdout.includes(`${wsArchiveDir}/v1.0-ROADMAP.md`),
`expected ls to find the workstream archive file, got: ${r.stdout}`);
assert.ok(!r.stdout.includes(rootArchiveDir),
`must not have checked the root archive dir, got: ${r.stdout}`);
});
});
});
describe('complete-milestone.md workstream-scoped paths (#4455)', () => {
const WORKFLOW_PATH = path.join(__dirname, '..', 'gsd-core', 'workflows', 'complete-milestone.md');
const content = fs.readFileSync(WORKFLOW_PATH, 'utf8');
const STEP_START = '<step name="reorganize_roadmap_and_delete_originals">';
const STEP_END = '<step name="write_retrospective">';
const backlogFence = extractFenceContaining(content, STEP_START, STEP_END, 'BACKLOG_SECTION');
const sentinelFence = extractFenceContaining(content, STEP_START, STEP_END, '.gsd-allow-shrink');
const commitFilesFence = extractFenceContaining(content, STEP_START, STEP_END, 'gsd_run query commit');
const requirementsRmFence = extractFenceContaining(content, STEP_START, STEP_END, 'git rm');
let tmpDir;
beforeEach(() => {
tmpDir = fs.mkdtempSync(path.join(os.tmpdir(), 'gsd-complete-milestone-ws-'));
});
afterEach(() => {
cleanup(tmpDir);
});
/**
* Write a canned init.complete-milestone-shaped JSON payload and a gsd_run
* stub that returns it for the `query init.complete-milestone` fetch, and
* echoes `gsd_run_call:<argv>` for every OTHER call (e.g. `query commit
* ...`) — the same recording-stub idiom tests/new-milestone-clear-phases.
* test.cjs uses, so the commit `--files` list can be asserted on directly.
*/
function stubGsdRun(jsonPayload) {
const jsonPath = path.join(tmpDir, 'init-cm.json');
fs.writeFileSync(jsonPath, JSON.stringify(jsonPayload));
return `gsd_run() { if [ "$1" = "query" ] && [ "$2" = "init.complete-milestone" ]; then cat "${jsonPath}"; else printf 'gsd_run_call:%s\\n' "$*"; fi; }\n`;
}
describe('backlog extraction: reads ROADMAP.md from init.complete-milestone roadmap_path', () => {
test('flat mode: no GSD_WORKSTREAM — resolves the root ROADMAP.md path (regression guard)', () => {
const roadmapPath = path.join(tmpDir, 'ROADMAP-root.md');
fs.writeFileSync(roadmapPath, '# Roadmap\n\n## Backlog\n\n- 999.1 Root backlog item\n');
const script = `${stubGsdRun({ roadmap_path: roadmapPath })}${backlogFence}\nprintf 'BACKLOG=[%s]\\n' "$BACKLOG_SECTION"`;
const r = runHookSeam('-c', [script], { interpreter: 'bash', cwd: tmpDir });
throwIfFailed(r, 'bash <backlog fence>');
assert.ok(r.stdout.includes('Root backlog item'),
`expected root ROADMAP.md backlog content, got: ${r.stdout}`);
});
test('GSD_WORKSTREAM=alpha: reads the workstream-scoped ROADMAP.md, not root (#4455 regression)', () => {
const rootRoadmapPath = path.join(tmpDir, 'ROADMAP-root.md');
fs.writeFileSync(rootRoadmapPath, '# Roadmap\n\n## Backlog\n\n- 999.1 Root backlog item — must not be read\n');
const wsRoadmapPath = path.join(tmpDir, 'ROADMAP-alpha.md');
fs.writeFileSync(wsRoadmapPath, '# Roadmap\n\n## Backlog\n\n- 999.1 Workstream Alpha backlog item\n');
const script = `${stubGsdRun({ roadmap_path: wsRoadmapPath })}${backlogFence}\nprintf 'BACKLOG=[%s]\\n' "$BACKLOG_SECTION"`;
const r = runHookSeam('-c', [script], { interpreter: 'bash', cwd: tmpDir });
throwIfFailed(r, 'bash <backlog fence>');
assert.ok(r.stdout.includes('Workstream Alpha backlog item'),
`expected workstream ROADMAP.md backlog content, got: ${r.stdout}`);
assert.ok(!r.stdout.includes('Root backlog item'),
`must not have read the root ROADMAP.md, got: ${r.stdout}`);
});
});
describe('write-guard sentinel: arms with init.complete-milestone roadmap_path', () => {
test('flat mode: sentinel names the root ROADMAP.md path (regression guard)', () => {
const roadmapPath = path.join(tmpDir, 'ROADMAP-root.md');
fs.mkdirSync(path.join(tmpDir, '.planning'), { recursive: true });
const script = `${stubGsdRun({ roadmap_path: roadmapPath })}${sentinelFence}`;
const r = runHookSeam('-c', [script], { interpreter: 'bash', cwd: tmpDir });
throwIfFailed(r, 'bash <sentinel fence>');
const sentinelContent = fs.readFileSync(path.join(tmpDir, '.planning', '.gsd-allow-shrink'), 'utf8').trim();
assert.strictEqual(sentinelContent, roadmapPath);
});
test('GSD_WORKSTREAM=alpha: sentinel names the workstream ROADMAP.md, not root (#4455 regression)', () => {
const wsRoadmapPath = path.join(tmpDir, 'ROADMAP-alpha.md');
fs.mkdirSync(path.join(tmpDir, '.planning'), { recursive: true });
const script = `${stubGsdRun({ roadmap_path: wsRoadmapPath })}${sentinelFence}`;
const r = runHookSeam('-c', [script], { interpreter: 'bash', cwd: tmpDir });
throwIfFailed(r, 'bash <sentinel fence>');
const sentinelContent = fs.readFileSync(path.join(tmpDir, '.planning', '.gsd-allow-shrink'), 'utf8').trim();
assert.strictEqual(sentinelContent, wsRoadmapPath);
assert.notStrictEqual(sentinelContent, path.join(tmpDir, '.planning', 'ROADMAP.md'));
});
});
describe('safety commit --files list: STATE/ROADMAP/archive/MILESTONES/PROJECT paths all scoped together', () => {
function runCommitFence(cmJson) {
const script = `${stubGsdRun(cmJson)}${commitFilesFence}`;
const r = runHookSeam('-c', [script], { interpreter: 'bash', cwd: tmpDir });
throwIfFailed(r, 'bash <commit --files fence>');
return r.stdout;
}
test('flat mode: --files lists root STATE/ROADMAP/archive/MILESTONES/PROJECT paths (regression guard)', () => {
const statePath = path.join(tmpDir, 'STATE-root.md');
const roadmapPath = path.join(tmpDir, 'ROADMAP-root.md');
const archiveDir = path.join(tmpDir, 'milestones-root');
const milestonesPath = path.join(tmpDir, 'MILESTONES-root.md');
const projectPath = path.join(tmpDir, 'PROJECT-root.md');
const out = runCommitFence({
state_path: statePath, roadmap_path: roadmapPath, archive_dir: archiveDir,
milestones_path: milestonesPath, project_path: projectPath,
});
assert.ok(out.includes('gsd_run_call:query commit'), `expected the commit call to be recorded, got: ${out}`);
assert.ok(out.includes(statePath), `expected root STATE.md in --files, got: ${out}`);
assert.ok(out.includes(roadmapPath), `expected root ROADMAP.md in --files, got: ${out}`);
assert.ok(out.includes(`${archiveDir}/v[X.Y]-ROADMAP.md`), `expected root archive ROADMAP in --files, got: ${out}`);
assert.ok(out.includes(milestonesPath), `expected root MILESTONES.md in --files, got: ${out}`);
assert.ok(out.includes(projectPath), `expected root PROJECT.md in --files, got: ${out}`);
});
test('GSD_WORKSTREAM=alpha: --files lists workstream-scoped STATE/ROADMAP/archive/MILESTONES/PROJECT paths, not root (#4455 regression)', () => {
const wsStatePath = path.join(tmpDir, 'STATE-alpha.md');
const wsRoadmapPath = path.join(tmpDir, 'ROADMAP-alpha.md');
const wsArchiveDir = path.join(tmpDir, 'milestones-alpha');
const wsMilestonesPath = path.join(tmpDir, 'MILESTONES-alpha.md');
const wsProjectPath = path.join(tmpDir, 'PROJECT-alpha.md');
const out = runCommitFence({
state_path: wsStatePath, roadmap_path: wsRoadmapPath, archive_dir: wsArchiveDir,
milestones_path: wsMilestonesPath, project_path: wsProjectPath,
});
assert.ok(out.includes(wsStatePath), `expected workstream STATE.md in --files, got: ${out}`);
assert.ok(out.includes(wsRoadmapPath), `expected workstream ROADMAP.md in --files, got: ${out}`);
assert.ok(out.includes(`${wsArchiveDir}/v[X.Y]-ROADMAP.md`), `expected workstream archive ROADMAP in --files, got: ${out}`);
// MILESTONES.md and PROJECT.md are workstream-scoped too — cmdMilestoneComplete
// (src/milestone.cts) writes MILESTONES.md via planningPaths(cwd).planning (the
// workstream base), and PROJECT.md resolves the same way (planningPaths().project).
// An earlier version of this fix wrongly pinned both as shared root files, which
// would have made this safety commit silently miss the actual files
// `milestone complete` just wrote under an active workstream (#4455 follow-up,
// caught by isolated code review).
assert.ok(out.includes(wsMilestonesPath), `expected workstream MILESTONES.md in --files, got: ${out}`);
assert.ok(out.includes(wsProjectPath), `expected workstream PROJECT.md in --files, got: ${out}`);
assert.ok(!out.includes(path.join(tmpDir, '.planning', 'STATE.md')),
`must not fall back to the flat root STATE.md path, got: ${out}`);
assert.ok(!out.includes(path.join(tmpDir, '.planning', 'ROADMAP.md')),
`must not fall back to the flat root ROADMAP.md path, got: ${out}`);
assert.ok(!out.includes(path.join(tmpDir, '.planning', 'MILESTONES.md')),
`must not fall back to the flat root MILESTONES.md path, got: ${out}`);
assert.ok(!out.includes(path.join(tmpDir, '.planning', 'PROJECT.md')),
`must not fall back to the flat root PROJECT.md path, got: ${out}`);
});
});
describe('REQUIREMENTS.md removal: git rm uses init.complete-milestone requirements_path, not a hardcoded literal', () => {
test('flat mode: removes the root REQUIREMENTS.md path (regression guard)', () => {
const requirementsPath = path.join(tmpDir, 'REQUIREMENTS-root.md');
fs.writeFileSync(requirementsPath, '# Requirements\n');
fs.mkdirSync(path.join(tmpDir, '.git'), { recursive: true }); // git rm needs a repo; the stub below intercepts it
const script = `git() { printf 'git_call:%s\\n' "$*"; }\n${stubGsdRun({ requirements_path: requirementsPath })}${requirementsRmFence}`;
const r = runHookSeam('-c', [script], { interpreter: 'bash', cwd: tmpDir });
throwIfFailed(r, 'bash <requirements rm fence>');
assert.ok(r.stdout.includes(`git_call:rm ${requirementsPath}`),
`expected git rm to target the root REQUIREMENTS.md, got: ${r.stdout}`);
});
test('GSD_WORKSTREAM=alpha: removes the workstream-scoped REQUIREMENTS.md, not root (#4455 follow-up regression)', () => {
const wsRequirementsPath = path.join(tmpDir, 'REQUIREMENTS-alpha.md');
fs.writeFileSync(wsRequirementsPath, '# Requirements\n');
const script = `git() { printf 'git_call:%s\\n' "$*"; }\n${stubGsdRun({ requirements_path: wsRequirementsPath })}${requirementsRmFence}`;
const r = runHookSeam('-c', [script], { interpreter: 'bash', cwd: tmpDir });
throwIfFailed(r, 'bash <requirements rm fence>');
assert.ok(r.stdout.includes(`git_call:rm ${wsRequirementsPath}`),
`expected git rm to target the workstream REQUIREMENTS.md, got: ${r.stdout}`);
assert.ok(!r.stdout.includes('git_call:rm .planning/REQUIREMENTS.md'),
`must not have targeted the literal root REQUIREMENTS.md path, got: ${r.stdout}`);
});
});
});