Files
msd-core/gsd-core/workflows/autonomous.md
Tom Boucher c6df4e1e46 fix(#4455): autonomous.md and complete-milestone.md resolve STATE/ROADMAP/MILESTONES/PROJECT/REQUIREMENTS through the workstream-scoped init fields (#4542)
* fix(#4455): thread workstream-scoped paths through autonomous and complete-milestone workflows

autonomous.md and complete-milestone.md read/wrote hardcoded literal
`.planning/STATE.md` / `.planning/ROADMAP.md` / `.planning/milestones/...`
paths in their shell fences, bypassing workstream scoping entirely. With
GSD_WORKSTREAM=alpha set, planningDir(cwd) correctly resolves into
workstreams/alpha/, but a literal `cat .planning/STATE.md` still read the
ROOT file (or silently returned empty if root state was absent) --
reproduced deterministically in the issue's own repro.

Root cause: each workflow step's bash fence is a separate shell
invocation, and cmdInitManager/cmdInitCompleteMilestone's JSON payloads
never carried resolved state_path/roadmap_path/archive_dir fields for the
workflows to extract -- unlike cmdInitPlanPhase, which already does this
correctly and is the pattern this fix mirrors.

- src/init.cts: cmdInitManager and cmdInitCompleteMilestone now emit
  state_path/roadmap_path (workstream-scoped via planningDir(cwd),
  existence-checked, toPosixPath'd, null when absent -- identical to
  cmdInitPlanPhase's existing contract) and archive_dir (the milestone
  archive directory, composed the same way milestone.cts's already-correct
  archive helper does per #1911).
- autonomous.md: discover_phases and iterate now extract state_path via
  the already-fetched INIT_MANAGER payload instead of hardcoding
  `.planning/STATE.md`; iterate's second, previously-separate hardcoded
  read is folded into the same fence (no double-fetch); lifecycle step 5b
  checks the resolved archive_dir instead of a hardcoded milestones path.
- complete-milestone.md's reorganize_roadmap_and_delete_originals step
  (which previously called no init command at all) now fetches
  init.complete-milestone and uses the resolved roadmap_path/state_path/
  archive_dir for the backlog read, the write-guard sentinel's armed
  content, the Write-tool target for the reorganized ROADMAP.md (the
  sentinel fence now echoes the resolved path so the executing agent can
  see it), and the safety-commit --files list. `.planning/MILESTONES.md`
  and `.planning/PROJECT.md` stay literal root paths -- documented shared
  files, per the issue's explicit "not a blanket replacement" scope.

Regression tests extract and execute the real bash fences (with a stubbed
gsd_run) rather than string-matching the markdown, covering flat mode
(unaffected), an active workstream (the issue's own repro shape, now
correctly resolving), the no-double-fetch requirement, and a dedicated
guard locking MILESTONES.md/PROJECT.md as shared.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* docs(#4455): add changeset for workstream-scoped autonomous/complete-milestone fix

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* fix(#4455): close write-guard gap on workstream-scoped curated paths

Isolated security review of the #4455 fix (workstream-scoped STATE/
ROADMAP/milestone-archive path resolution in autonomous.md and
complete-milestone.md) flagged that hooks/gsd-write-guard.js's
CURATED_PATTERNS only matched root-level .planning/ paths, never
.planning/[<project>/]workstreams/<ws>/... — meaning the catastrophic-
shrink guard silently never engaged for a workstream-scoped write.
This is directly relevant here: the #4455 change makes a workstream-
scoped ROADMAP.md Write reachable via complete-milestone.md's own
explicit sentinel-hatch instructions, which assume guard protection
that did not actually exist for that path shape. Extended
CURATED_PATTERNS with the three workstream-scoped equivalents;
consumeSentinelFor's own path-derivation logic needed no change since
it derives from the actual write target. Verified empirically (a
293->16 line workstream ROADMAP.md shrink now correctly returns
exit 2 / decision:"block") and with 5 new regression tests.

Also addressed a code-review nit on the core #4455 fix:
cmdInitCompleteMilestone called planningDir(cwd) three separate
times instead of caching it once.

Accepted as-is (not fixed): complete-milestone.md's
reorganize_roadmap_and_delete_originals step re-fetches
`gsd_run query init.complete-milestone` three times across its
fences rather than merging the first two (no state-changing Write
between them, unlike autonomous.md's iterate step which does merge).
This is an efficiency nit, not a correctness bug — merging risks
disrupting the step's prose flow and its existing binding test for a
non-functional gain.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* docs(#4455): add changeset for the write-guard workstream-scope fix

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* fix(#4455): fix gsd-test-surfaced regressions from workstream-path fix

Running gsd-test against the full #4455 diff (including the write-guard
security fix and the cmdInitCompleteMilestone caching nit) surfaced four
real, non-flaky failures, all direct consequences of editing
gsd-core/workflows/autonomous.md and complete-milestone.md:

1. tests/autonomous-converge.test.cjs pinned the OLD hardcoded
   `STATE_CONTENT=$(cat .planning/STATE.md ...)` read in both
   discover_phases and iterate. That is exactly the literal-path
   behavior #4455 fixes, so the test needed updating to assert the new
   init.manager-resolved `STATE_PATH` read instead (with an explicit
   doesNotMatch guard against regressing to the old literal).

2. tests/workstream-scoped-paths.test.cjs's own "no-double-fetch" test
   counted gsd_run invocations via a shell variable incremented inside
   the stub function — but `INIT_MANAGER=$(gsd_run ...)` runs gsd_run
   inside the command-substitution SUBSHELL, so that increment never
   survives back to the parent shell and the counter always read 0.
   Switched to a file-based call log (one byte appended per call),
   which survives the subshell boundary.

3. tests/compact-content-partition-guard.test.cjs's disjointness check
   flagged the reorganize_roadmap_and_delete_originals step's new
   `INIT_CM=$(gsd_run query init.complete-milestone)` fetch (added 3x,
   per the accepted-as-is disposition in the prior commit) as
   byte-identical to a pre-existing, unrelated fetch already present in
   complete-milestone/detail/elaboration.md's handle_branches section
   (§2). Same idiom, same conventional variable name, coincidentally
   colliding across the spine/detail split boundary. Renamed the new
   step's local variable to INIT_REORG — a distinct, purpose-specific
   name is arguably better practice anyway for two logically unrelated
   fetches, and it removes the literal collision honestly rather than
   restructuring the split.

4. tests/benchmark-compact-content.test.cjs reported real byte-count
   drift in the committed baseline (autonomous.md and
   complete-milestone.md both grew from the #4455 content). Refreshed
   via `node scripts/benchmark-compact-content.cjs --write`.

Verified: node scripts/benchmark-compact-content.cjs --check now
reports the baseline up to date; a standalone invocation of
checkDisjointness() against the real repo state now reports zero
violations across all 6 registered splits; manual bash-fence execution
of both the autonomous.md iterate fence (call count = 1) and the
complete-milestone.md backlog fence (with INIT_REORG) confirms correct
behavior.

Emitted-Drift-Ack-Growth: autonomous.md — #4455 workstream-scoped STATE.md path resolution replaces hardcoded literal reads
Emitted-Drift-Ack-Growth: complete-milestone.md — #4455 workstream-scoped STATE/ROADMAP/archive path resolution replaces hardcoded literal reads
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* fix(#4455): MILESTONES.md/PROJECT.md/REQUIREMENTS.md are workstream-scoped too, and so is project-only mode

Fresh isolated code-review and security-review passes against the full
diff (run after the previous gsd-test-surfaced fixups landed) each
found one real, confirmed defect:

Code review: the safety-commit `--files` list and the REQUIREMENTS.md
`git rm` step both hardcoded `.planning/MILESTONES.md`,
`.planning/PROJECT.md`, and `.planning/REQUIREMENTS.md` as literal
root paths — but src/milestone.cts's cmdMilestoneComplete writes
MILESTONES.md via `planningPaths(cwd).planning` (the workstream base)
and PROJECT.md/REQUIREMENTS.md resolve the same way through
`planningPaths().project`/`.requirements` (src/planning-workspace.cts).
Only `todos` is the documented root-scoped exception (#4256); an
earlier version of this fix wrongly generalized that exception to
MILESTONES.md/PROJECT.md too, and the now-corrected test previously
enshrined that wrong behavior as intended. Under an active workstream,
the safety commit would have silently missed the actual files
`milestone complete` just wrote, and the git-rm step would have
targeted the wrong (root) REQUIREMENTS.md entirely. Fixed by exposing
`milestones_path`/`project_path`/`requirements_path` from
init.complete-milestone (src/init.cts) and resolving all three through
them, the same pattern already used for state_path/roadmap_path/
archive_dir. The four remaining literal MILESTONES.md/PROJECT.md
mentions elsewhere in complete-milestone.md (lines ~12-13, ~441, ~607,
~662) are display-only prose in status/summary message templates, not
actual file operations — left as-is; they are a cosmetic path-display
inaccuracy under an active workstream, not a data-integrity bug like
the two fixed here.

Security review: confirmed the write-guard fix from the prior commit
is correct and complete for workstream scoping, and independently
surfaced the same project-only gap the code-review pass above also
caught structurally: `CURATED_PATTERNS` had no pattern for
`.planning/<project>/...` (GSD_PROJECT set, GSD_WORKSTREAM unset) —
planningDir(cwd) supports that shape independently of workstream
nesting, so it is reachable, not hypothetical. Fixed by adding three
more patterns, verified empirically (a project-scoped 292->16 line
ROADMAP.md shrink now correctly returns exit 2 / decision:"block")
and with 6 new regression tests.

Verified: manual bash-fence execution of the corrected commit-files
and requirements-rm fences (both flat mode and GSD_WORKSTREAM=alpha)
resolves to the right paths in both cases; a standalone invocation of
checkDisjointness() against the real repo state still reports zero
violations; the benchmark baseline was refreshed again for the further
size change (already covered by the existing Emitted-Drift-Ack-Growth
trailer on complete-milestone.md two commits back — that trailer is
read over the whole merge-base..HEAD range, not per-commit, so it
still applies here).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* docs(#4455): backfill changeset PR numbers and correct final scope

pr: 0 -> pr: 4542 for both fragments, and updated both bodies to
reflect the final fix scope (MILESTONES/PROJECT/REQUIREMENTS are
workstream-scoped too, not shared-root exceptions; the write-guard fix
also covers project-only scoping, not just workstream nesting).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* fix(#4455): lifecycle-5b archive-path assertions use the fence's own separator, not path.join

PR CI's windows-latest shard 3/3 failed: "expected ls to find the root
archive file, got: ...\milestones-root/v1.0-ROADMAP.md". The
autonomous.md lifecycle step 5b fence composes the checked path with a
literal bash `/` (`"${ARCHIVE_DIR}/v${milestone_version}-ROADMAP.md"`),
which on Windows yields a MIXED-separator path — Windows backslashes
from archiveDir plus one trailing `/`. My test's assertion used
path.join(archiveDir, 'v1.0-ROADMAP.md') instead, which on a Windows
Node process produces an all-backslash path that never matches the
fence's mixed-separator output. Both assertions in that describe block
now mirror the fence's own literal `/` concatenation
(`${archiveDir}/v1.0-ROADMAP.md`) instead of path.join — matching the
style the other two describe blocks in this same file (safety-commit
--files list) already used correctly for the identical archive-dir
pattern, so this brings the one outlier into line rather than
introducing a new idiom.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* fix(#4455): write-guard sentinel comparison now realpath-resolves the token, not just the target

PR CI's macos-latest full-test shard 2/3 failed a #4455 test: "the
sentinel hatch ... unblocks a workstream ROADMAP.md write" got status
2 (still blocked) instead of 0.

Root cause, unrelated to the Windows fix in the previous commit:
hooks/gsd-write-guard.js's main flow realpath-resolves the Write
TARGET before the curated-pattern match (round 9 Minor 1's
symlink-before-match fix, `filePath = fs.realpathSync(filePath)`), but
consumeSentinelFor resolved the sentinel TOKEN's absolute path via
plain path.resolve() with no realpath step. On macOS, os.tmpdir()
resolves through a /var -> /private/var symlink, so a test's cwd
(lexically under /var/folders/...) and its realpath'd target
(/private/var/folders/...) diverge — an armed, correct sentinel then
never matches the realpath'd target string, and the guard stays
incorrectly blocked. This is not macOS-specific in principle: ANY cwd
sitting under a symlink (a symlinked project checkout, a symlinked
worktree) hits the same asymmetry — gsd-test's Linux bench runs never
caught it because /tmp there is not a symlink.

Fixed by applying the same fs.realpathSync (with the same
keep-lexical-on-failure fallback the caller already uses) to the
token's resolved path before comparing. The named file is already
known to exist at this point (the caller only reaches consumeSentinelFor
after successfully reading the target), so realpath is expected to
succeed in the legitimate case; a garbage/mismatched token still fails
safe (verified — falls back to the lexical path, still mismatches,
stays blocked).

Verified: reproduced the exact bug locally (macOS) via os.tmpdir()
before the fix, confirmed it resolves after; the negative case
(sentinel armed for a DIFFERENT file) still correctly blocks; the
pre-existing relative-token sentinel tests (predating #4455) still
pass; a garbage/non-existent token still fails safe. Added a
deterministic, cross-platform regression test using an explicit
symlink (skipped on Windows, matching the existing round-9 symlink
test's own skip condition) so this class of bug is caught by
gsd-test's Linux bench too, not only by a real macOS CI run.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

---------

Co-authored-by: sim <sim@local>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-08 04:56:11 -04:00

38 KiB
Raw Blame History

@~/.claude/gsd-core/references/response-language-directive.md

Drive milestone phases autonomously — all remaining phases, a range via --from N/--to N, or a single phase via --only N. For each incomplete phase: discuss → plan → execute using Skill() flat invocations. When --converge or --cross-ai is set, route the planning step through plan-review convergence before execution. Pauses only for explicit user decisions (grey area acceptance, blockers, validation requests). Re-reads ROADMAP.md after each phase to catch dynamically inserted phases.

<required_reading>

Read all files referenced by the invoking prompt's execution_context before starting.

</required_reading>

1. Initialize

Parse $ARGUMENTS for --from N, --to N, --only N, --interactive, --converge/--cross-ai, reviewer selector flags, and --max-cycles N:

FROM_PHASE=""
if echo "$ARGUMENTS" | grep -qE '\-\-from\s+[0-9]'; then
  FROM_PHASE=$(echo "$ARGUMENTS" | grep -oE '\-\-from\s+[0-9]+\.?[0-9]*' | awk '{print $2}')
fi

TO_PHASE=""
if echo "$ARGUMENTS" | grep -qE '\-\-to\s+[0-9]'; then
  TO_PHASE=$(echo "$ARGUMENTS" | grep -oE '\-\-to\s+[0-9]+\.?[0-9]*' | awk '{print $2}')
fi

ONLY_PHASE=""
if echo "$ARGUMENTS" | grep -qE '\-\-only\s+[0-9]'; then
  ONLY_PHASE=$(echo "$ARGUMENTS" | grep -oE '\-\-only\s+[0-9]+\.?[0-9]*' | awk '{print $2}')
  FROM_PHASE="$ONLY_PHASE"
fi

INTERACTIVE=""
if echo "$ARGUMENTS" | grep -q '\-\-interactive'; then
  INTERACTIVE="true"
fi

PLAN_STRATEGY="local"
if echo "$ARGUMENTS" | grep -qE '(^|[[:space:]])\-\-(converge|cross-ai)([[:space:]]|$)'; then
  PLAN_STRATEGY="converge"
fi

CONVERGE_PARAM=""
if echo "$ARGUMENTS" | grep -qE '(^|[[:space:]])\-\-converge([[:space:]]|$)'; then
  CONVERGE_PARAM="--converge"
fi
CROSS_AI_PARAM=""
if echo "$ARGUMENTS" | grep -qE '(^|[[:space:]])\-\-cross-ai([[:space:]]|$)'; then
  CROSS_AI_PARAM="--cross-ai"
fi

When --only is set, also set FROM_PHASE to the same value so existing filter logic applies.

When --interactive is set, discuss stays inline. If dispatch-should-flatten returns false, dispatch plan and execute as background agents; if it returns true, run them inline and keep phases sequential. Preserve user input on all design decisions.

When PLAN_STRATEGY=converge, the planning step MUST invoke the plan-review convergence workflow instead of gsd-plan-phase. --cross-ai is an alias for --converge. Forward CONVERGENCE_ARGS exactly as parsed so reviewer flags and --max-cycles N retain the same meaning as they have on /gsd:plan-review-convergence.

Bootstrap via milestone-level init:

_GSD_SHIM_NAME="gsd-tools.cjs"; _GSD_RUNTIME_ROOT="${RUNTIME_DIR:-$(git rev-parse --show-toplevel 2>/dev/null || pwd)}"; GSD_TOOLS="${_GSD_RUNTIME_ROOT}/gsd-core/bin/${_GSD_SHIM_NAME}"; _gsd_at() { for _p; do if [ -f "$_p" ]; then GSD_TOOLS="$_p"; return 0; fi; done; return 1; }; if _gsd_at "${_GSD_RUNTIME_ROOT}/gsd-core/bin/${_GSD_SHIM_NAME}" "${_GSD_RUNTIME_ROOT}/.claude/gsd-core/bin/${_GSD_SHIM_NAME}" "${_GSD_RUNTIME_ROOT}/.codex/gsd-core/bin/${_GSD_SHIM_NAME}"; then gsd_run() { node "$GSD_TOOLS" "$@"; }; elif unset -f gsd_run; _G="$(command -v gsd_run)"; then GSD_TOOLS="$_G"; gsd_run() { "$GSD_TOOLS" "$@"; }; elif _gsd_at "${CLAUDE_CONFIG_DIR:-$HOME/.claude}/gsd-core/bin/${_GSD_SHIM_NAME}" "${HERMES_HOME:-$HOME/.hermes}/gsd-core/bin/${_GSD_SHIM_NAME}" "${CURSOR_CONFIG_DIR:-$HOME/.cursor}/gsd-core/bin/${_GSD_SHIM_NAME}" "${CODEX_HOME:-$HOME/.codex}/gsd-core/bin/${_GSD_SHIM_NAME}" "${GEMINI_CONFIG_DIR:-$HOME/.gemini}/gsd-core/bin/${_GSD_SHIM_NAME}" "${COPILOT_CONFIG_DIR:-$HOME/.copilot}/gsd-core/bin/${_GSD_SHIM_NAME}" "${WINDSURF_CONFIG_DIR:-$HOME/.codeium/windsurf}/gsd-core/bin/${_GSD_SHIM_NAME}" "${AUGMENT_CONFIG_DIR:-$HOME/.augment}/gsd-core/bin/${_GSD_SHIM_NAME}" "${TRAE_CONFIG_DIR:-$HOME/.trae}/gsd-core/bin/${_GSD_SHIM_NAME}" "${QWEN_CONFIG_DIR:-$HOME/.qwen}/gsd-core/bin/${_GSD_SHIM_NAME}" "${CODEBUDDY_CONFIG_DIR:-$HOME/.codebuddy}/gsd-core/bin/${_GSD_SHIM_NAME}" "${CLINE_CONFIG_DIR:-$HOME/.cline}/gsd-core/bin/${_GSD_SHIM_NAME}" "${GROK_AGENTS_HOME:-$HOME/.agents}/gsd-core/bin/${_GSD_SHIM_NAME}" "${ANTIGRAVITY_CONFIG_DIR:-$HOME/.gemini/antigravity}/gsd-core/bin/${_GSD_SHIM_NAME}" "${OPENCODE_CONFIG_DIR:-${XDG_CONFIG_HOME:-$HOME/.config}/opencode}/gsd-core/bin/${_GSD_SHIM_NAME}" "${KILO_CONFIG_DIR:-${XDG_CONFIG_HOME:-$HOME/.config}/kilo}/gsd-core/bin/${_GSD_SHIM_NAME}"; then gsd_run() { node "$GSD_TOOLS" "$@"; }; else echo "ERROR: gsd-tools.cjs not found at $GSD_TOOLS and gsd_run is not on PATH. Run: npx -y @opengsd/gsd-core@latest --claude --local" >&2; exit 1; fi; GSD_IDENTITY_STATUS=unverified; case "$(gsd_run runtime-identity --raw 2>/dev/null || true)" in '{"packageName":"@opengsd/gsd-core"'*'}') GSD_IDENTITY_STATUS=ok;; esac; export GSD_IDENTITY_STATUS; [ "$GSD_IDENTITY_STATUS" = ok ] || echo "WARNING: \"$GSD_TOOLS\" did not prove it is @opengsd/gsd-core - it is either a different package or an @opengsd/gsd-core older than the runtime-identity verb. See docs/how-to/diagnose-a-foreign-gsd-tools.md" >&2; if [ -n "${CLAUDE_ENV_FILE:-}" ] && [ -n "${GSD_TOOLS:-}" ]; then printf "export PATH='%s':\"\$PATH\"\n" "${GSD_TOOLS%/*}" >> "$CLAUDE_ENV_FILE" 2>/dev/null || true; fi
INIT=$(gsd_run query init.milestone-op)
if [[ "$INIT" == @file:* ]]; then INIT=$(cat "${INIT#@file:}"); fi
INIT_AUTONOMOUS=$(gsd_run query init.autonomous $CONVERGE_PARAM $CROSS_AI_PARAM)
if [[ "$INIT_AUTONOMOUS" == @file:* ]]; then INIT_AUTONOMOUS=$(cat "${INIT_AUTONOMOUS#@file:}"); fi

Extract section_manifest from INIT_AUTONOMOUS (used by the converge-* sections below and in step 3).

If PLAN_STRATEGY is converge, fail fast unless the existing convergence feature gate is enabled:

# Lane flags derived from the declared roster (#2800/#2272); --all and --text are convergence
# controls, not reviewer lanes, so they stay literal.
# This block must stay AFTER the launcher preamble (above) because it calls `gsd_run` —
# do not move it back above the preamble in a future edit.
CONVERGENCE_ARGS=""
for REVIEW_FLAG in $(gsd_run review-lane flags) --all --text; do
  if echo "$ARGUMENTS" | grep -qE "(^|[[:space:]])${REVIEW_FLAG}([[:space:]]|$)"; then
    CONVERGENCE_ARGS="${CONVERGENCE_ARGS} ${REVIEW_FLAG}"
  fi
done

MAX_CYCLES_ARG=""
if echo "$ARGUMENTS" | grep -qE '\-\-max-cycles\s+[0-9]+'; then
  MAX_CYCLES_ARG=$(echo "$ARGUMENTS" | grep -oE '\-\-max-cycles\s+[0-9]+' | awk '{print $2}')
  CONVERGENCE_ARGS="${CONVERGENCE_ARGS} --max-cycles ${MAX_CYCLES_ARG}"
fi

If section_manifest is null or "converge-fail-fast" is in its included list: read and execute gsd-core/workflows/autonomous/steps/converge-fail-fast.md. Otherwise skip — do not read the file.

Parse JSON for: milestone_version, milestone_name, phase_count, completed_phases, roadmap_exists, state_exists, commit_docs.

If roadmap_exists is false: Error — "No ROADMAP.md found. Run /gsd:new-milestone first." If state_exists is false: Error — "No STATE.md found. Run /gsd:new-milestone first."

Display startup banner:

### GSD ► AUTONOMOUS

 Milestone: {milestone_version} — {milestone_name}
 Phases: {phase_count} total, {completed_phases} complete

If ONLY_PHASE is set, display: Single phase mode: Phase ${ONLY_PHASE} Else if FROM_PHASE is set, display: Starting from phase ${FROM_PHASE} If TO_PHASE is set, display: Stopping after phase ${TO_PHASE} If INTERACTIVE is set, display: Mode: Interactive (discuss inline, plan+execute inline — background on Codex only)

If section_manifest is null or "converge-banner" is in its included list: read and execute gsd-core/workflows/autonomous/steps/converge-banner.md. Otherwise skip — do not read the file.

Agent skills (delegated agents self-load): This workflow delegates plan/execute/review via flat Skill() invocations rather than resolving agent_skills itself. Each consumer agent (gsd-planner, gsd-executor, gsd-plan-checker, gsd-verifier, …) self-loads its configured .planning/config.json agent_skills in its own mandatory init step per @~/.claude/gsd-core/references/agent-skills-bootstrap.md. This is the durable path that works on every runtime — including Cursor, where Skill()-delegated workflow bash init does not reliably execute. No per-delegation injection is needed here. See open-gsd/gsd-core#1866.

2. Discover Phases

Run phase discovery:

INIT_MANAGER=$(gsd_run query init.manager)
if [[ "$INIT_MANAGER" == @file:* ]]; then INIT_MANAGER=$(cat "${INIT_MANAGER#@file:}"); fi
_gsd_field() { node -e "const o=JSON.parse(process.argv[1]); const v=o[process.argv[2]]; process.stdout.write(v==null?'':String(v))" "$1" "$2"; }
STATE_PATH=$(_gsd_field "$INIT_MANAGER" state_path)
STATE_CONTENT=$(cat "$STATE_PATH" 2>/dev/null || true)

Parse the JSON phases array.

Parse the optional ## Deferred Verification table from STATE_CONTENT into a phase-number map:

  • verification_deferred_human -> /gsd:verify-work <phase>
  • verification_deferred_gaps -> /gsd:plan-phase <phase> --gaps

Skip deferred phases on autonomous re-entry: drop any phase whose number appears in the deferred-phase map from this run's queue; resume it only through the recorded command.

Filter to incomplete phases: Keep phase_complete !== true, including implemented phases with verification_status !== "passed".

Apply --from N: If set, filter out phases where number < FROM_PHASE (numeric compare; handles "5.1").

Apply --to N: If set, filter out phases where number > TO_PHASE (numeric compare).

Apply --only N: If set, filter out phases where number != ONLY_PHASE.

If TO_PHASE is set and no phases remain (all phases up to N are already completed):

All phases through ${TO_PHASE} are already completed. Nothing to do.

Exit cleanly.

If ONLY_PHASE is set and no phases remain (phase already complete):

Phase ${ONLY_PHASE} is already complete. Nothing to do.

Exit cleanly.

Sort by number in numeric ascending order.

If no incomplete phases remain:

### GSD ► AUTONOMOUS ▸ COMPLETE 🎉

 All phases complete! Nothing left to do.

Exit cleanly.

Display phase plan:

## Phase Plan

| # | Phase | Status |
|---|-------|--------|
| 5 | Skill Scaffolding & Phase Discovery | In Progress |
| 6 | Smart Discuss | Not Started |
| 7 | Auto-Chain Refinements | Not Started |
| 8 | Lifecycle Orchestration | Not Started |

If any deferred phases were skipped: display ## Deferred Verification (Skipped on Re-entry) with the skipped rows and resume commands, then omit them from this run's queue.

Fetch details for each phase:

DETAIL=$(gsd_run query roadmap.get-phase ${PHASE_NUM})

Extract phase_name, goal, success_criteria from each. Store for use in execute_phase and transition messages.

3. Execute Phase

For the current phase, display the progress banner:

### GSD ► AUTONOMOUS ▸ Phase {N}/{T}: {Name} [████░░░░] {P}%

Where N is the ROADMAP phase number, T is the milestone phase_count, and P = completed milestone phases / T × 100. Use phase_count, not remaining phases: phase 63 in a 7-phase milestone is Phase 63/7, not Phase 63/3. If N > T, render Phase {N} ({position}/{T}). Use an 8-character bar with █ and ░.

3a. Smart Discuss

Check if CONTEXT.md already exists for this phase:

PHASE_STATE=$(gsd_run query init.phase-op ${PHASE_NUM})

Parse has_context from JSON.

If has_context is true: Skip discuss — context already gathered. Display:

Phase ${PHASE_NUM}: Context exists — skipping discuss.

Proceed to 3b.

If has_context is false: Check if discuss is disabled via settings:

SKIP_DISCUSS=$(gsd_run query config-get workflow.skip_discuss --raw 2>/dev/null || echo "false")

If SKIP_DISCUSS is true: Skip discuss entirely — the ROADMAP phase description is the spec. Display:

Phase ${PHASE_NUM}: Discuss skipped (workflow.skip_discuss=true) — using ROADMAP phase goal as spec.

Write a minimal CONTEXT.md so downstream plan-phase has valid input. Get phase details:

DETAIL=$(gsd_run query roadmap.get-phase ${PHASE_NUM})

Extract goal and requirements from JSON. Write ${phase_dir}/${padded_phase}-CONTEXT.md with:

# Phase {PHASE_NUM}: {Phase Name} - Context

**Gathered:** {date}
**Status:** Ready for planning
**Mode:** Auto-generated (discuss skipped via workflow.skip_discuss)

<domain>
## Phase Boundary

{goal from ROADMAP phase description}

</domain>

<decisions>
## Implementation Decisions

### Claude's Discretion
All implementation choices are at Claude's discretion — discuss phase was skipped per user setting. Use ROADMAP phase goal, success criteria, and codebase conventions to guide decisions.

</decisions>

<code_context>
## Existing Code Insights

Codebase context will be gathered during plan-phase research.

</code_context>

<specifics>
## Specific Ideas

No specific requirements — discuss phase skipped. Refer to ROADMAP phase description and success criteria.

</specifics>

<deferred>
## Deferred Ideas

None — discuss phase skipped.

</deferred>

Commit the minimal context:

gsd_run query commit "docs(${PADDED_PHASE}): auto-generated context (discuss skipped)" --files "${phase_dir}/${padded_phase}-CONTEXT.md"

Proceed to 3b.

If SKIP_DISCUSS is false (or unset):

IMPORTANT — Discuss must be single-pass in autonomous mode. The discuss step in --auto mode MUST NOT loop. If CONTEXT.md already exists after discuss completes, do NOT re-invoke discuss for the same phase. The has_context check below is authoritative — once true, discuss is done for this phase regardless of perceived "gaps" in the context file.

If INTERACTIVE is set: Run the standard discuss-phase skill inline (asks interactive questions, waits for user answers). This preserves user input on all design decisions while keeping plan+execute out of the main context:

Skill(skill="gsd-discuss-phase", args="${PHASE_NUM}")

If INTERACTIVE is NOT set: Execute the smart_discuss step for this phase (batch table proposals, auto-optimized).

After discuss completes (either mode), verify context was written:

PHASE_STATE=$(gsd_run query init.phase-op ${PHASE_NUM})

Check has_context. If false → go to handle_blocker: "Discuss for phase ${PHASE_NUM} did not produce CONTEXT.md."

3a.5. UI Design Contract (Frontend Phases)

Full instructions are in gsd-core/references/autonomous-ui-design-contract.md. Read that file now and follow it exactly.

Inputs: PHASE_NUM, PHASE_DIR from execute_phase. Resolves whether the phase needs a UI-SPEC.md generated before planning via active plan:pre step hooks. Always non-blocking — proceeds to 3b regardless of outcome.

Read and execute: $HOME/.claude/gsd-core/references/autonomous-ui-design-contract.md

3b. Plan

If INTERACTIVE is set: Background dispatch is only safe on a runtime where a backgrounded agent can still nest the pipeline's subagents (plan-checker / worktree executors / verifier). This is determined from the documentation-sourced dispatch capability in the registry (#1708); Claude Code's backgrounded agents have no Agent/Task tool, and every other runtime either prohibits nested subagents or disables them by default. So run inline everywhere except where dispatch-should-flatten returns false. Resolve first:

FLATTEN=$(gsd_run query dispatch-should-flatten --raw 2>/dev/null || echo "true")
  • If FLATTEN is false: Dispatch plan as a background agent to keep the main context lean. While plan runs, the workflow can immediately start discussing the next phase (see step 4).

    If section_manifest is null or "converge-dispatch-bg" is in its included list: read and execute gsd-core/workflows/autonomous/steps/converge-dispatch-bg.md. Otherwise skip — do not read the file.

    • Otherwise, print: ◆ Spawning background planner for phase ${PHASE_NUM}... (runs in a subagent — no output until it returns, ~1–5 min; expected, not a freeze)
    Agent(
      description="Plan phase ${PHASE_NUM}: ${PHASE_NAME}",
      run_in_background=true,
      prompt="Run plan-phase for phase ${PHASE_NUM}: Skill(skill=\"gsd-plan-phase\", args=\"${PHASE_NUM}\")"
    )
    

    Store the agent task_id. After discuss for the next phase completes (or if no next phase), wait for the plan agent to finish before proceeding to execute.

  • Otherwise (FLATTEN is true — run inline): Run plan inline (do NOT background) so the plan-checker runs. The next phase's discuss does not overlap planning here — correctness over overlap.

    If section_manifest is null or "converge-dispatch-inline" is in its included list: read and execute gsd-core/workflows/autonomous/steps/converge-dispatch-inline.md. Otherwise skip — do not read the file.

    • Otherwise (local planning):
    Skill(skill="gsd-plan-phase", args="${PHASE_NUM}")
    

If INTERACTIVE is NOT set (default): Run plan inline.

If section_manifest is null or "converge-loop" is in its included list: read and execute gsd-core/workflows/autonomous/steps/converge-loop.md. Otherwise skip — do not read the file.

If PLAN_STRATEGY=local, run the regular planner:

Skill(skill="gsd-plan-phase", args="${PHASE_NUM}")

Verify plan produced output — re-run init phase-op and check has_plans. If false → go to handle_blocker: "Plan phase ${PHASE_NUM} did not produce any plans."

3c. Execute

If INTERACTIVE is set: Wait for the plan agent to complete (if not already) and verify plans exist. Background dispatch is only safe on a runtime where a backgrounded agent can still nest the pipeline's subagents (plan-checker / worktree executors / verifier). This is determined from the documentation-sourced dispatch capability in the registry (#1708); Claude Code's backgrounded agents have no Agent/Task tool, and every other runtime either prohibits nested subagents or disables them by default. So run inline everywhere except where dispatch-should-flatten returns false. Resolve first:

FLATTEN=$(gsd_run query dispatch-should-flatten --raw 2>/dev/null || echo "true")
  • If FLATTEN is false: Dispatch execute as a background agent:
Agent(
  description="Execute phase ${PHASE_NUM}: ${PHASE_NAME}",
  run_in_background=true,
  prompt="Run execute-phase for phase ${PHASE_NUM}: Skill(skill=\"gsd-execute-phase\", args=\"${PHASE_NUM} --no-transition\")"
)

Store the agent task_id. The workflow can now start discussing the next phase while this phase executes in the background. Before starting post-execution routing for this phase, wait for the execute agent to complete.

  • Otherwise (FLATTEN is true — run inline): Run execute inline (do NOT background) so worktree isolation and verification run:
Skill(skill="gsd-execute-phase", args="${PHASE_NUM} --no-transition")

If INTERACTIVE is NOT set (default): Run execute inline as before.

Skill(skill="gsd-execute-phase", args="${PHASE_NUM} --no-transition")

3c.5. Code Review and Fix

Auto-invoke code review and fix chain. Autonomous mode chains both review and fix (unlike execute-phase/quick which only suggest fix).

Capability dispatch:

EXECUTE_POST_HOOKS_JSON=$(gsd_run loop render-hooks execute:post --raw)

Resolve active step hooks from EXECUTE_POST_HOOKS_JSON where kind == "step" and ref.skill == "code-review".

If no active code-review step hook exists: display "Code review skipped (code-review capability inactive)" and proceed to 3d. This covers workflow.code_review=false through the Capability Registry; do not query the code-review toggle directly here.

For each active code-review step hook, dispatch the skill using the registry-provided stem:

Skill(skill="gsd-${ref.skill}", args="${PHASE_NUM}")

Parse status from REVIEW.md frontmatter. If "clean" or "skipped": proceed to 3d. If findings found after the capability-dispatched review, auto-invoke the consolidated fix entry point:

Skill(skill="gsd-code-review", args="${PHASE_NUM} --fix --auto")

Error handling: If either Skill fails, catch the error, display as non-blocking, and proceed to 3d.

3d. Post-Execution Routing

After execute, read canonical verification:

VERIFY_STATUS=$(gsd_run query verification.status "${PHASE_DIR}" --pick status 2>/dev/null || true)

If PHASE_DIR is absent, re-fetch init.phase-op ${PHASE_NUM} and parse phase_dir.

If VERIFY_STATUS is empty, handle_blocker: "No verification results for phase ${PHASE_NUM}."

If passed:

Display Phase ${PHASE_NUM} ✅ ${PHASE_NAME} — Verification passed, run @~/.claude/gsd-core/workflows/transition.md, then Proceed to iterate step.

If stale: handle_blocker: "Stale verification for phase ${PHASE_NUM}."

If human_needed:

Read human_verification items. In text mode (--text or init text_mode=true), replace AskUserQuestion with a plain-text numbered list. Otherwise ask whether to validate now or continue without validation. If validating now, present items, then ask Validation result? with All good — continue / Found issues.

On "All good — continue": set VERIFICATION frontmatter status: passed, display Phase ${PHASE_NUM} ✅ Human validation passed, run @~/.claude/gsd-core/workflows/transition.md, then iterate.

On "Found issues": Go to handle_blocker with the user's reported issues as the description.

On "Continue without validation": record an explicit deferred state and stop autonomous mode:

## Deferred Verification

| Phase | State | Resume |
|-------|-------|--------|
| ${PHASE_NUM} | verification_deferred_human | /gsd:verify-work ${PHASE_NUM} |

Append/update this STATE.md section, display Phase ${PHASE_NUM} ⏭ verification_deferred_human — resume with /gsd:verify-work ${PHASE_NUM}, then handle_blocker: "Human verification deferred for phase ${PHASE_NUM}."

If gaps_found:

Read gap score/items from VERIFICATION.md. Display:

⚠ Phase ${PHASE_NUM}: ${PHASE_NAME} — Gaps Found
Score: {N}/{M} must-haves verified

Ask how to proceed: Run gap closure / Continue without fixing / Stop autonomous mode.

On "Run gap closure": one gap-closure attempt:

Skill(skill="gsd-plan-phase", args="${PHASE_NUM} --gaps")

Re-run init phase-op ${PHASE_NUM}; if has_plans is false, handle_blocker: "Gap closure planning for phase ${PHASE_NUM} did not produce plans."

Re-execute:

Skill(skill="gsd-execute-phase", args="${PHASE_NUM} --no-transition")

Re-read verification status:

VERIFY_STATUS=$(gsd_run query verification.status "${PHASE_DIR}" --pick status 2>/dev/null || true)

If passed or human_needed: route normally.

If stale: handle_blocker: "Stale verification for phase ${PHASE_NUM}."

If still gaps_found after this retry, display Gaps persist after closure attempt. and ask Continue anyway / Stop autonomous mode.

On "Continue anyway": record verification_deferred_gaps using the table below, display Phase ${PHASE_NUM} ⏭ verification_deferred_gaps — resume with /gsd:plan-phase ${PHASE_NUM} --gaps, then handle_blocker: "Verification gaps deferred for phase ${PHASE_NUM}." On "Stop autonomous mode": Go to handle_blocker.

This limits gap closure to 1 retry.

On "Continue without fixing": record an explicit deferred state and stop autonomous mode:

## Deferred Verification

| Phase | State | Resume |
|-------|-------|--------|
| ${PHASE_NUM} | verification_deferred_gaps | /gsd:plan-phase ${PHASE_NUM} --gaps |

Append/update this STATE.md section, display Phase ${PHASE_NUM} ⏭ verification_deferred_gaps — resume with /gsd:plan-phase ${PHASE_NUM} --gaps, then handle_blocker: "Verification gaps deferred for phase ${PHASE_NUM}."

On "Stop autonomous mode": Go to handle_blocker with "User stopped — gaps remain in phase ${PHASE_NUM}".

3d.5. UI Review (Frontend Phases)

Run only after passed or human verification was updated to passed.

Resolve the active post-verification hooks and the UI-SPEC gate:

UI_SPEC_FILE=$(ls "${PHASE_DIR}"/*-UI-SPEC.md 2>/dev/null | head -1)
HOOKS_JSON=$(gsd_run loop render-hooks verify:post --raw)

Read the activeHooks array directly from the HOOKS_JSON value already in context (do not invoke a shell jq pipeline — parse as the JSON object it is). If activeHooks is empty or absent: skip silently to the iterate step.

For each entry in activeHooks in array order where kind == "step" and ref.skill is set:

  • Honor consumes: if the hook's consumes array includes "UI-SPEC.md" and UI_SPEC_FILE is empty (no *-UI-SPEC.md exists in PHASE_DIR) → skip that hook (onError: skip). Hooks that do not declare "UI-SPEC.md" in their consumes proceed normally regardless of UI_SPEC_FILE.
  • Invoke:
Skill(skill="gsd-${ref.skill}", args="${PHASE_NUM}")

(i.e. prepend gsd- to ref.skill — so ui-review → gsd-ui-review.)

Display the review result summary and score from UI-REVIEW.md if produced. Continue to iterate step regardless of result — hooks at this point are advisory, not blocking.

Smart Discuss

Full instructions are in gsd-core/references/autonomous-smart-discuss.md. Read that file now and follow it exactly.

Smart discuss is an autonomous-optimized variant of gsd-discuss-phase. It proposes grey area answers in batch tables — the user accepts or overrides per area — and writes an identical CONTEXT.md to what discuss-phase produces.

Inputs: PHASE_NUM from execute_phase.

Read and execute: $HOME/.claude/gsd-core/references/autonomous-smart-discuss.md

4. Iterate

If ONLY_PHASE is set: Do not iterate. Proceed directly to lifecycle step (which exits cleanly per single-phase mode).

If TO_PHASE is set and current phase number >= TO_PHASE: The target phase has been reached. Do not iterate further. Display:

### GSD ► AUTONOMOUS ▸ --to ${TO_PHASE} REACHED

 Completed through phase ${TO_PHASE} as requested.
 Remaining phases were not executed.

 Resume with: /gsd:autonomous --from ${next_incomplete_phase}

Proceed to lifecycle step (partial completion skips audit/complete/cleanup). Exit cleanly.

Otherwise: After each phase, re-read manager projection, then read STATE.md fresh (same fence — a single gsd_run query init.manager fetch backs both the JSON re-filter below and the raw re-read, no double-fetch):

INIT_MANAGER=$(gsd_run query init.manager)
if [[ "$INIT_MANAGER" == @file:* ]]; then INIT_MANAGER=$(cat "${INIT_MANAGER#@file:}"); fi
_gsd_field() { node -e "const o=JSON.parse(process.argv[1]); const v=o[process.argv[2]]; process.stdout.write(v==null?'':String(v))" "$1" "$2"; }
STATE_PATH=$(_gsd_field "$INIT_MANAGER" state_path)
STATE_CONTENT=$(cat "$STATE_PATH" 2>/dev/null || true)
cat "$STATE_PATH"

Re-filter incomplete phases using discover_phases logic: keep phases where phase_complete !== true or verification_status !== "passed", drop deferred phases from the autonomous queue, re-apply --from / --to, then sort by number ascending.

Check for blockers in the Blockers/Concerns section. If blockers are found, go to handle_blocker with the blocker description.

If incomplete phases remain: proceed to next phase, loop back to execute_phase.

If no runnable phases remain but deferred phases were skipped, display Autonomous run stopped with deferred verification phases still pending. Resume them with the commands listed in Deferred Verification. Proceed to lifecycle only if every non-deferred phase is complete; otherwise go to handle_blocker.

Interactive mode overlap: When INTERACTIVE is set, Codex can overlap discuss for Phase N+1 with background plan+execute for Phase N. Other runtimes keep plan/execute inline, so phases stay sequential:

  1. After discuss completes for Phase N, dispatch plan+execute as background agents
  2. Immediately start discuss for Phase N+1 (the next incomplete phase) while Phase N builds
  3. Before starting plan for Phase N+1, wait for Phase N's execute agent to complete and handle its post-execution routing (verification, gap closure, etc.)

The main context only accumulates discuss conversations; background plan/execute work stays isolated in its agents.

If all phases complete, proceed to lifecycle step.

5. Lifecycle

If ONLY_PHASE is set: Skip lifecycle. A single phase does not trigger audit/complete/cleanup. Display:

### GSD ► AUTONOMOUS ▸ PHASE ${ONLY_PHASE} COMPLETE ✓

 Phase ${ONLY_PHASE}: ${PHASE_NAME} — Done
 Mode: Single phase (--only)

 Lifecycle skipped — run /gsd:autonomous without --only
 after all phases complete to trigger audit/complete/cleanup.

Exit cleanly.

Otherwise: After all phases complete, run the milestone lifecycle sequence: audit → complete → cleanup.

Display lifecycle transition banner:

### GSD ► AUTONOMOUS ▸ LIFECYCLE

 All phases complete → Starting lifecycle: audit → complete → cleanup
 Milestone: {milestone_version} — {milestone_name}

5a. Audit

Skill(skill="gsd-audit-milestone")

After audit completes, detect the result:

AUDIT_FILE=".planning/v${milestone_version}-MILESTONE-AUDIT.md"
AUDIT_STATUS=$(grep "^status:" "${AUDIT_FILE}" 2>/dev/null | head -1 | cut -d: -f2 | tr -d ' ')

If AUDIT_STATUS is empty (no audit file or no status field):

Go to handle_blocker: "Audit did not produce results — audit file missing or malformed."

If passed:

Display:

Audit ✅ passed — proceeding to complete milestone

Proceed to 5b (no user pause — per CTRL-01).

If gaps_found:

Read the gaps summary from the audit file. Display:

⚠ Audit: Gaps Found

Ask user via AskUserQuestion:

  • question: "Milestone audit found gaps. How to proceed?"
  • options: "Continue anyway — accept gaps" / "Stop — fix gaps manually"

On "Continue anyway": Display Audit ⏭ Gaps accepted — proceeding to complete milestone and proceed to 5b.

On "Stop": Go to handle_blocker with "User stopped — audit gaps remain. Run /gsd:audit-milestone to review, then /gsd:complete-milestone when ready."

If tech_debt:

Read the tech debt summary from the audit file. Display:

⚠ Audit: Tech Debt Identified

Show the summary, then ask user via AskUserQuestion:

  • question: "Milestone audit found tech debt. How to proceed?"
  • options: "Continue with tech debt" / "Stop — address debt first"

On "Continue with tech debt": Display Audit ⏭ Tech debt acknowledged — proceeding to complete milestone and proceed to 5b.

On "Stop": Go to handle_blocker with "User stopped — tech debt to address. Run /gsd:audit-milestone to review details."

5b. Complete Milestone

Skill(skill="gsd-complete-milestone", args="${milestone_version}")

After complete-milestone returns, verify it produced output:

INIT_MANAGER=$(gsd_run query init.manager)
if [[ "$INIT_MANAGER" == @file:* ]]; then INIT_MANAGER=$(cat "${INIT_MANAGER#@file:}"); fi
_gsd_field() { node -e "const o=JSON.parse(process.argv[1]); const v=o[process.argv[2]]; process.stdout.write(v==null?'':String(v))" "$1" "$2"; }
ARCHIVE_DIR=$(_gsd_field "$INIT_MANAGER" archive_dir)
ls "${ARCHIVE_DIR}/v${milestone_version}-ROADMAP.md" 2>/dev/null || true

If the archive file does not exist, go to handle_blocker: "Complete milestone did not produce expected archive files."

5c. Cleanup

Skill(skill="gsd-cleanup")

Cleanup shows its own dry-run and asks user for approval internally — this is an acceptable pause per CTRL-01 since it's an explicit decision about file deletion.

5d. Final Completion

Display final completion banner:

### GSD ► AUTONOMOUS ▸ COMPLETE 🎉

 Milestone: {milestone_version} — {milestone_name}
 Status: Complete ✅
 Lifecycle: audit ✅ → complete ✅ → cleanup ✅

 Ship it! 🚀

6. Handle Blocker

When any phase operation fails or a blocker is detected, present 3 options via AskUserQuestion:

Prompt: "Phase {N} ({Name}) encountered an issue: {description}"

Options:

  1. "Fix and retry" — Re-run the failed step (discuss, plan, or execute) for this phase
  2. "Skip this phase" — Mark phase as skipped, continue to the next incomplete phase
  3. "Stop autonomous mode" — Display summary of progress so far and exit cleanly

On "Fix and retry": Loop back to the failed step within execute_phase. Track the retry count per phase + step (RETRY_COUNT, kept in memory for the run). If the same step fails again after retry, re-present these options. Retry ceiling (#3210): once the same phase step has failed 3 "Fix and retry" attempts, do NOT re-present the options — escalate to a terminal needs_human halt: display Phase {N} ⛔ {Name} — needs_human, list the unmet items (the blocker description from each attempt), append/update a ## Needs Human section in STATE.md (| ${PHASE_NUM} | needs_human | resolve blocker, then /gsd:autonomous --from ${PHASE_NUM} |), and stop autonomous mode with the standard stopped-summary banner. A blocker that survives 3 fix attempts is an operator gate, not an executable gap — retrying it again just burns hours.

On "Skip this phase": Log Phase {N} ⏭ {Name} — Skipped by user and proceed to iterate.

On "Stop autonomous mode": Display progress summary:

### GSD ► AUTONOMOUS ▸ STOPPED

 Completed: {list of completed phases}
 Skipped: {list of skipped phases}
 Remaining: {list of remaining phases}

 Resume with: /gsd:autonomous ${ONLY_PHASE ? "--only " + ONLY_PHASE : "--from " + next_phase}${TO_PHASE ? " --to " + TO_PHASE : ""}

<success_criteria>

  • All incomplete phases executed in order (smart discuss → ui-phase → plan → execute → ui-review each)
  • Smart discuss proposes grey area answers in tables, user accepts or overrides per area
  • Progress banners displayed between phases
  • Execute-phase invoked with --no-transition (autonomous manages transitions)
  • Post-execution verification reads VERIFICATION.md and routes on status
  • Passed verification → automatic continue to next phase
  • Human-needed verification → user prompted to validate or skip
  • Gaps-found → user offered gap closure, continue, or stop
  • Gap closure limited to 1 retry (prevents infinite loops)
  • Plan-phase and execute-phase failures route to handle_blocker
  • ROADMAP.md re-read after each phase (catches inserted phases)
  • STATE.md checked for blockers before each phase
  • Blockers handled via user choice (retry / skip / stop)
  • Final completion or stop summary displayed
  • After all phases complete, lifecycle step is invoked (not manual suggestion)
  • Lifecycle transition banner displayed before audit
  • Audit invoked via Skill(skill="gsd-audit-milestone")
  • Audit result routing: passed → auto-continue, gaps_found → user decides, tech_debt → user decides
  • Audit technical failure (no file/no status) routes to handle_blocker
  • Complete-milestone invoked via Skill() with ${milestone_version} arg
  • Cleanup invoked via Skill() — internal confirmation is acceptable (CTRL-01)
  • Final completion banner displayed after lifecycle
  • Progress bar uses phase number / total milestone phases (not position among incomplete), with fallback display when phase numbers exceed total
  • Smart discuss documents relationship to discuss-phase with CTRL-03 note
  • Frontend phases get UI-SPEC generated before planning (step 3a.5) if not already present
  • Frontend phases get UI review audit after successful execution (step 3d.5) if UI-SPEC exists
  • UI phase and UI review respect workflow.ui_phase and workflow.ui_review config toggles
  • UI review is advisory (non-blocking) — phase proceeds to iterate regardless of score
  • --only N restricts execution to exactly one phase
  • --only N skips lifecycle step (audit/complete/cleanup)
  • --only N exits cleanly after single phase completes
  • --only N on already-complete phase exits with message
  • --only N handle_blocker resume message uses --only flag
  • --to N stops execution after phase N completes (halts at iterate step)
  • --to N filters out phases with number > N during discovery
  • --to N displays "Stopping after phase N" in startup banner
  • --to N on already completed target exits with "already completed" message
  • --to N compatible with --from N (run phases from M to N)
  • --to N handle_blocker resume message preserves --to flag
  • --to N skips lifecycle when not all milestone phases complete
  • --interactive runs discuss inline via gsd-discuss-phase (asks questions, waits for user)
  • --interactive dispatches plan and execute as background agents on Codex (the only runtime where a backgrounded agent can nest subagents); runs them inline on all other runtimes
  • --interactive enables pipeline parallelism (discuss Phase N+1 while Phase N builds) on Codex; phases run sequentially on all other runtimes
  • --interactive main context only accumulates discuss conversations on Codex (on all other runtimes, inline plan/execute also accumulate)
  • --interactive waits for background agents before post-execution routing
  • --interactive compatible with --only, --from, and --to flags
  • --converge routes planning through gsd-plan-review-convergence
  • --cross-ai is accepted as an alias for --converge
  • --converge fails fast with enable instructions when workflow.plan_review_convergence=false
  • --converge forwards reviewer selector flags and --max-cycles N
  • Default autonomous planning remains gsd-plan-phase when convergence is not requested </success_criteria>