Files
msd-core/tests/autonomous-converge.test.cjs
Tom Boucher c6df4e1e46 fix(#4455): autonomous.md and complete-milestone.md resolve STATE/ROADMAP/MILESTONES/PROJECT/REQUIREMENTS through the workstream-scoped init fields (#4542)
* fix(#4455): thread workstream-scoped paths through autonomous and complete-milestone workflows

autonomous.md and complete-milestone.md read/wrote hardcoded literal
`.planning/STATE.md` / `.planning/ROADMAP.md` / `.planning/milestones/...`
paths in their shell fences, bypassing workstream scoping entirely. With
GSD_WORKSTREAM=alpha set, planningDir(cwd) correctly resolves into
workstreams/alpha/, but a literal `cat .planning/STATE.md` still read the
ROOT file (or silently returned empty if root state was absent) --
reproduced deterministically in the issue's own repro.

Root cause: each workflow step's bash fence is a separate shell
invocation, and cmdInitManager/cmdInitCompleteMilestone's JSON payloads
never carried resolved state_path/roadmap_path/archive_dir fields for the
workflows to extract -- unlike cmdInitPlanPhase, which already does this
correctly and is the pattern this fix mirrors.

- src/init.cts: cmdInitManager and cmdInitCompleteMilestone now emit
  state_path/roadmap_path (workstream-scoped via planningDir(cwd),
  existence-checked, toPosixPath'd, null when absent -- identical to
  cmdInitPlanPhase's existing contract) and archive_dir (the milestone
  archive directory, composed the same way milestone.cts's already-correct
  archive helper does per #1911).
- autonomous.md: discover_phases and iterate now extract state_path via
  the already-fetched INIT_MANAGER payload instead of hardcoding
  `.planning/STATE.md`; iterate's second, previously-separate hardcoded
  read is folded into the same fence (no double-fetch); lifecycle step 5b
  checks the resolved archive_dir instead of a hardcoded milestones path.
- complete-milestone.md's reorganize_roadmap_and_delete_originals step
  (which previously called no init command at all) now fetches
  init.complete-milestone and uses the resolved roadmap_path/state_path/
  archive_dir for the backlog read, the write-guard sentinel's armed
  content, the Write-tool target for the reorganized ROADMAP.md (the
  sentinel fence now echoes the resolved path so the executing agent can
  see it), and the safety-commit --files list. `.planning/MILESTONES.md`
  and `.planning/PROJECT.md` stay literal root paths -- documented shared
  files, per the issue's explicit "not a blanket replacement" scope.

Regression tests extract and execute the real bash fences (with a stubbed
gsd_run) rather than string-matching the markdown, covering flat mode
(unaffected), an active workstream (the issue's own repro shape, now
correctly resolving), the no-double-fetch requirement, and a dedicated
guard locking MILESTONES.md/PROJECT.md as shared.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* docs(#4455): add changeset for workstream-scoped autonomous/complete-milestone fix

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* fix(#4455): close write-guard gap on workstream-scoped curated paths

Isolated security review of the #4455 fix (workstream-scoped STATE/
ROADMAP/milestone-archive path resolution in autonomous.md and
complete-milestone.md) flagged that hooks/gsd-write-guard.js's
CURATED_PATTERNS only matched root-level .planning/ paths, never
.planning/[<project>/]workstreams/<ws>/... — meaning the catastrophic-
shrink guard silently never engaged for a workstream-scoped write.
This is directly relevant here: the #4455 change makes a workstream-
scoped ROADMAP.md Write reachable via complete-milestone.md's own
explicit sentinel-hatch instructions, which assume guard protection
that did not actually exist for that path shape. Extended
CURATED_PATTERNS with the three workstream-scoped equivalents;
consumeSentinelFor's own path-derivation logic needed no change since
it derives from the actual write target. Verified empirically (a
293->16 line workstream ROADMAP.md shrink now correctly returns
exit 2 / decision:"block") and with 5 new regression tests.

Also addressed a code-review nit on the core #4455 fix:
cmdInitCompleteMilestone called planningDir(cwd) three separate
times instead of caching it once.

Accepted as-is (not fixed): complete-milestone.md's
reorganize_roadmap_and_delete_originals step re-fetches
`gsd_run query init.complete-milestone` three times across its
fences rather than merging the first two (no state-changing Write
between them, unlike autonomous.md's iterate step which does merge).
This is an efficiency nit, not a correctness bug — merging risks
disrupting the step's prose flow and its existing binding test for a
non-functional gain.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* docs(#4455): add changeset for the write-guard workstream-scope fix

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* fix(#4455): fix gsd-test-surfaced regressions from workstream-path fix

Running gsd-test against the full #4455 diff (including the write-guard
security fix and the cmdInitCompleteMilestone caching nit) surfaced four
real, non-flaky failures, all direct consequences of editing
gsd-core/workflows/autonomous.md and complete-milestone.md:

1. tests/autonomous-converge.test.cjs pinned the OLD hardcoded
   `STATE_CONTENT=$(cat .planning/STATE.md ...)` read in both
   discover_phases and iterate. That is exactly the literal-path
   behavior #4455 fixes, so the test needed updating to assert the new
   init.manager-resolved `STATE_PATH` read instead (with an explicit
   doesNotMatch guard against regressing to the old literal).

2. tests/workstream-scoped-paths.test.cjs's own "no-double-fetch" test
   counted gsd_run invocations via a shell variable incremented inside
   the stub function — but `INIT_MANAGER=$(gsd_run ...)` runs gsd_run
   inside the command-substitution SUBSHELL, so that increment never
   survives back to the parent shell and the counter always read 0.
   Switched to a file-based call log (one byte appended per call),
   which survives the subshell boundary.

3. tests/compact-content-partition-guard.test.cjs's disjointness check
   flagged the reorganize_roadmap_and_delete_originals step's new
   `INIT_CM=$(gsd_run query init.complete-milestone)` fetch (added 3x,
   per the accepted-as-is disposition in the prior commit) as
   byte-identical to a pre-existing, unrelated fetch already present in
   complete-milestone/detail/elaboration.md's handle_branches section
   (§2). Same idiom, same conventional variable name, coincidentally
   colliding across the spine/detail split boundary. Renamed the new
   step's local variable to INIT_REORG — a distinct, purpose-specific
   name is arguably better practice anyway for two logically unrelated
   fetches, and it removes the literal collision honestly rather than
   restructuring the split.

4. tests/benchmark-compact-content.test.cjs reported real byte-count
   drift in the committed baseline (autonomous.md and
   complete-milestone.md both grew from the #4455 content). Refreshed
   via `node scripts/benchmark-compact-content.cjs --write`.

Verified: node scripts/benchmark-compact-content.cjs --check now
reports the baseline up to date; a standalone invocation of
checkDisjointness() against the real repo state now reports zero
violations across all 6 registered splits; manual bash-fence execution
of both the autonomous.md iterate fence (call count = 1) and the
complete-milestone.md backlog fence (with INIT_REORG) confirms correct
behavior.

Emitted-Drift-Ack-Growth: autonomous.md — #4455 workstream-scoped STATE.md path resolution replaces hardcoded literal reads
Emitted-Drift-Ack-Growth: complete-milestone.md — #4455 workstream-scoped STATE/ROADMAP/archive path resolution replaces hardcoded literal reads
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* fix(#4455): MILESTONES.md/PROJECT.md/REQUIREMENTS.md are workstream-scoped too, and so is project-only mode

Fresh isolated code-review and security-review passes against the full
diff (run after the previous gsd-test-surfaced fixups landed) each
found one real, confirmed defect:

Code review: the safety-commit `--files` list and the REQUIREMENTS.md
`git rm` step both hardcoded `.planning/MILESTONES.md`,
`.planning/PROJECT.md`, and `.planning/REQUIREMENTS.md` as literal
root paths — but src/milestone.cts's cmdMilestoneComplete writes
MILESTONES.md via `planningPaths(cwd).planning` (the workstream base)
and PROJECT.md/REQUIREMENTS.md resolve the same way through
`planningPaths().project`/`.requirements` (src/planning-workspace.cts).
Only `todos` is the documented root-scoped exception (#4256); an
earlier version of this fix wrongly generalized that exception to
MILESTONES.md/PROJECT.md too, and the now-corrected test previously
enshrined that wrong behavior as intended. Under an active workstream,
the safety commit would have silently missed the actual files
`milestone complete` just wrote, and the git-rm step would have
targeted the wrong (root) REQUIREMENTS.md entirely. Fixed by exposing
`milestones_path`/`project_path`/`requirements_path` from
init.complete-milestone (src/init.cts) and resolving all three through
them, the same pattern already used for state_path/roadmap_path/
archive_dir. The four remaining literal MILESTONES.md/PROJECT.md
mentions elsewhere in complete-milestone.md (lines ~12-13, ~441, ~607,
~662) are display-only prose in status/summary message templates, not
actual file operations — left as-is; they are a cosmetic path-display
inaccuracy under an active workstream, not a data-integrity bug like
the two fixed here.

Security review: confirmed the write-guard fix from the prior commit
is correct and complete for workstream scoping, and independently
surfaced the same project-only gap the code-review pass above also
caught structurally: `CURATED_PATTERNS` had no pattern for
`.planning/<project>/...` (GSD_PROJECT set, GSD_WORKSTREAM unset) —
planningDir(cwd) supports that shape independently of workstream
nesting, so it is reachable, not hypothetical. Fixed by adding three
more patterns, verified empirically (a project-scoped 292->16 line
ROADMAP.md shrink now correctly returns exit 2 / decision:"block")
and with 6 new regression tests.

Verified: manual bash-fence execution of the corrected commit-files
and requirements-rm fences (both flat mode and GSD_WORKSTREAM=alpha)
resolves to the right paths in both cases; a standalone invocation of
checkDisjointness() against the real repo state still reports zero
violations; the benchmark baseline was refreshed again for the further
size change (already covered by the existing Emitted-Drift-Ack-Growth
trailer on complete-milestone.md two commits back — that trailer is
read over the whole merge-base..HEAD range, not per-commit, so it
still applies here).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* docs(#4455): backfill changeset PR numbers and correct final scope

pr: 0 -> pr: 4542 for both fragments, and updated both bodies to
reflect the final fix scope (MILESTONES/PROJECT/REQUIREMENTS are
workstream-scoped too, not shared-root exceptions; the write-guard fix
also covers project-only scoping, not just workstream nesting).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* fix(#4455): lifecycle-5b archive-path assertions use the fence's own separator, not path.join

PR CI's windows-latest shard 3/3 failed: "expected ls to find the root
archive file, got: ...\milestones-root/v1.0-ROADMAP.md". The
autonomous.md lifecycle step 5b fence composes the checked path with a
literal bash `/` (`"${ARCHIVE_DIR}/v${milestone_version}-ROADMAP.md"`),
which on Windows yields a MIXED-separator path — Windows backslashes
from archiveDir plus one trailing `/`. My test's assertion used
path.join(archiveDir, 'v1.0-ROADMAP.md') instead, which on a Windows
Node process produces an all-backslash path that never matches the
fence's mixed-separator output. Both assertions in that describe block
now mirror the fence's own literal `/` concatenation
(`${archiveDir}/v1.0-ROADMAP.md`) instead of path.join — matching the
style the other two describe blocks in this same file (safety-commit
--files list) already used correctly for the identical archive-dir
pattern, so this brings the one outlier into line rather than
introducing a new idiom.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* fix(#4455): write-guard sentinel comparison now realpath-resolves the token, not just the target

PR CI's macos-latest full-test shard 2/3 failed a #4455 test: "the
sentinel hatch ... unblocks a workstream ROADMAP.md write" got status
2 (still blocked) instead of 0.

Root cause, unrelated to the Windows fix in the previous commit:
hooks/gsd-write-guard.js's main flow realpath-resolves the Write
TARGET before the curated-pattern match (round 9 Minor 1's
symlink-before-match fix, `filePath = fs.realpathSync(filePath)`), but
consumeSentinelFor resolved the sentinel TOKEN's absolute path via
plain path.resolve() with no realpath step. On macOS, os.tmpdir()
resolves through a /var -> /private/var symlink, so a test's cwd
(lexically under /var/folders/...) and its realpath'd target
(/private/var/folders/...) diverge — an armed, correct sentinel then
never matches the realpath'd target string, and the guard stays
incorrectly blocked. This is not macOS-specific in principle: ANY cwd
sitting under a symlink (a symlinked project checkout, a symlinked
worktree) hits the same asymmetry — gsd-test's Linux bench runs never
caught it because /tmp there is not a symlink.

Fixed by applying the same fs.realpathSync (with the same
keep-lexical-on-failure fallback the caller already uses) to the
token's resolved path before comparing. The named file is already
known to exist at this point (the caller only reaches consumeSentinelFor
after successfully reading the target), so realpath is expected to
succeed in the legitimate case; a garbage/mismatched token still fails
safe (verified — falls back to the lexical path, still mismatches,
stays blocked).

Verified: reproduced the exact bug locally (macOS) via os.tmpdir()
before the fix, confirmed it resolves after; the negative case
(sentinel armed for a DIFFERENT file) still correctly blocks; the
pre-existing relative-token sentinel tests (predating #4455) still
pass; a garbage/non-existent token still fails safe. Added a
deterministic, cross-platform regression test using an explicit
symlink (skipped on Windows, matching the existing round-9 symlink
test's own skip condition) so this class of bug is caught by
gsd-test's Linux bench too, not only by a real macOS CI run.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

---------

Co-authored-by: sim <sim@local>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-08 04:56:11 -04:00

349 lines
16 KiB
JavaScript

// allow-test-rule: source-text-is-the-product
// The autonomous command and workflow markdown are runtime-loaded contracts.
// Checking their text verifies the shipped slash-command behavior.
'use strict';
const { describe, test } = require('node:test');
const assert = require('node:assert/strict');
const fs = require('node:fs');
const path = require('node:path');
const { runNode } = require('./helpers/process-seam.cjs');
const { throwIfFailed } = require('./helpers/git-fixture.cjs');
const { PROBE_TIMEOUT_MS } = require('./helpers/timeouts.cjs');
const REPO_ROOT = path.join(__dirname, '..');
const COMMAND_PATH = path.join(REPO_ROOT, 'commands', 'gsd', 'autonomous.md');
const WORKFLOW_PATH = path.join(REPO_ROOT, 'gsd-core', 'workflows', 'autonomous.md');
const COMMANDS_DOC_PATH = path.join(REPO_ROOT, 'docs', 'COMMANDS.md');
const HOW_TO_PATH = path.join(REPO_ROOT, 'docs', 'how-to', 'run-phases-autonomously.md');
const TOOLS = path.join(REPO_ROOT, 'gsd-core', 'bin', 'gsd-tools.cjs');
// #2994: fragmentization moved the five converge-gated regions out of the host
// autonomous.md into dedicated step files (state:plan-strategy-converge) —
// see docs/reference/workflow-fragments.md. Tests that assert on this moved
// content read the step file directly rather than the host.
const STEP_FAIL_FAST_PATH = path.join(REPO_ROOT, 'gsd-core', 'workflows', 'autonomous', 'steps', 'converge-fail-fast.md');
const STEP_DISPATCH_BG_PATH = path.join(REPO_ROOT, 'gsd-core', 'workflows', 'autonomous', 'steps', 'converge-dispatch-bg.md');
const STEP_DISPATCH_INLINE_PATH = path.join(REPO_ROOT, 'gsd-core', 'workflows', 'autonomous', 'steps', 'converge-dispatch-inline.md');
const STEP_LOOP_PATH = path.join(REPO_ROOT, 'gsd-core', 'workflows', 'autonomous', 'steps', 'converge-loop.md');
function read(filePath) {
return fs.readFileSync(filePath, 'utf8');
}
describe('autonomous --converge flag (#711)', () => {
test('command advertises --converge and documents --cross-ai as alias', () => {
const command = read(COMMAND_PATH);
assert.match(
command,
/^argument-hint:.*--converge/m,
'autonomous command should advertise --converge in argument-hint',
);
assert.match(command, /--cross-ai/, 'autonomous command should document --cross-ai alias');
assert.match(
command,
/workflow\.plan_review_convergence=true/,
'autonomous command should mention the existing convergence feature gate',
);
});
test('workflow parses converge aliases into a plan strategy', () => {
const workflow = read(WORKFLOW_PATH);
assert.match(workflow, /PLAN_STRATEGY="local"/, 'workflow should default to local planning');
assert.match(workflow, /PLAN_STRATEGY="converge"/, 'workflow should opt into converge planning');
assert.match(workflow, /converge\|cross-ai/, 'workflow should accept --converge and --cross-ai');
});
test('workflow fails fast when convergence is requested but disabled', () => {
// #2994: this check lives in the converge-fail-fast step file now
// (state:plan-strategy-converge) — the host only carries the gated
// conditional-read stub.
const workflow = read(WORKFLOW_PATH);
const step = read(STEP_FAIL_FAST_PATH);
assert.match(
workflow,
/gsd:section id="converge-fail-fast" when="state:plan-strategy-converge"/,
'workflow should gate the fail-fast check behind state:plan-strategy-converge',
);
assert.match(
step,
/config-get workflow\.plan_review_convergence/,
'converge-fail-fast step should check workflow.plan_review_convergence before planning',
);
assert.match(
step,
/gsd config-set workflow\.plan_review_convergence true/,
'converge-fail-fast step should print the enable command instead of silently downgrading',
);
});
test('workflow routes planning through plan-review-convergence when enabled', () => {
// #2994: the converge dispatch/loop bodies live in dedicated step files
// now (state:plan-strategy-converge) — only the local-planning fallback
// remains inline in the host.
const workflow = read(WORKFLOW_PATH);
const dispatchInline = read(STEP_DISPATCH_INLINE_PATH);
const loop = read(STEP_LOOP_PATH);
const dispatchBg = read(STEP_DISPATCH_BG_PATH);
assert.match(
dispatchInline,
/Skill\(skill="gsd-plan-review-convergence", args="\$\{PHASE_NUM\} \$\{CONVERGENCE_ARGS\}"\)/,
'inline converge dispatch step should call gsd-plan-review-convergence',
);
assert.match(
loop,
/Skill\(skill="gsd-plan-review-convergence", args="\$\{PHASE_NUM\} \$\{CONVERGENCE_ARGS\}"\)/,
'default converge loop step should call gsd-plan-review-convergence',
);
assert.match(
dispatchBg,
/Run plan convergence for phase \$\{PHASE_NUM\}: Skill\(skill=\\"gsd-plan-review-convergence\\"/,
'interactive converge mode should dispatch plan convergence in the background agent',
);
assert.match(
workflow,
/Skill\(skill="gsd-plan-phase", args="\$\{PHASE_NUM\}"\)/,
'local planning path should remain available for default autonomous runs',
);
});
test('workflow forwards reviewer flags and max cycles to convergence', () => {
const workflow = read(WORKFLOW_PATH);
// Non-lane convergence controls remain hand-written literals in the workflow.
const convergenceControls = ['--all', '--text'];
// Reviewer lane flags that were formerly hand-enumerated in the workflow text.
// They must now be DERIVED at runtime via `gsd_run review-lane flags`, not listed.
const formerlyHardcodedLaneFlags = [
'--codex',
'--gemini',
'--claude',
'--opencode',
'--ollama',
'--lm-studio',
'--llama-cpp',
];
// The literal-absence guard below excludes '--claude': the runtime-launcher
// preamble legitimately contains an unrelated "npx ... --claude --local"
// install-runtime flag, so a substring match on '--claude' would false-positive
// against that literal, not against a re-added reviewer-flag list.
const antiParityLaneFlags = formerlyHardcodedLaneFlags.filter((flag) => flag !== '--claude');
assert.match(workflow, /CONVERGENCE_ARGS/, 'workflow should build convergence pass-through args');
assert.match(
workflow,
/gsd_run review-lane flags/,
'workflow should derive reviewer flags from the review-lane roster instead of hand-listing them',
);
for (const flag of convergenceControls) {
assert.ok(workflow.includes(flag), `workflow should pass through ${flag}`);
}
assert.match(workflow, /--max-cycles/, 'workflow should pass through --max-cycles N');
// Anti-parity guard (deliberately inverted polarity): the whole point of the
// review-lane-flags derivation is that reviewer lane flags are declared ONCE
// (in the review-lane roster) and never hand-listed again in workflow prose.
// If a future edit re-adds a hardcoded reviewer-flag list here, that is the
// regression this test exists to catch — so this assertion must FAIL when
// any of these flags reappear as literals in the workflow text.
for (const flag of antiParityLaneFlags) {
assert.ok(
!workflow.includes(flag),
`workflow should NOT hand-enumerate reviewer lane flag ${flag}; it must be derived via review-lane flags`,
);
}
// Behavioral coverage: prove the roster the workflow derives from actually
// yields the flags this test used to hardcode, so the derivation is not vacuous.
const laneFlagsResult = runNode([TOOLS, 'review-lane', 'flags'], { timeoutMs: PROBE_TIMEOUT_MS });
throwIfFailed(laneFlagsResult, `node ${TOOLS} review-lane flags`);
const laneFlags = laneFlagsResult.stdout.split('\n').filter(Boolean);
for (const flag of formerlyHardcodedLaneFlags) {
assert.ok(laneFlags.includes(flag), `review-lane flags should include ${flag}`);
}
});
test('docs show autonomous convergence usage', () => {
const commandsDoc = read(COMMANDS_DOC_PATH);
const howTo = read(HOW_TO_PATH);
assert.match(commandsDoc, /--converge/, 'COMMANDS.md should document --converge');
assert.match(commandsDoc, /--cross-ai/, 'COMMANDS.md should document --cross-ai alias');
assert.match(howTo, /\/gsd-autonomous --only 4 --converge/, 'how-to should show single-phase converge usage');
});
});
describe('autonomous verification deferral contract', () => {
test('workflow records explicit deferred states instead of silently advancing (#1525)', () => {
const workflow = read(WORKFLOW_PATH);
assert.match(workflow, /verification_deferred_human/);
assert.match(workflow, /verification_deferred_gaps/);
assert.match(workflow, /Deferred Verification/);
assert.match(workflow, /gsd:verify-work \$\{PHASE_NUM\}/);
assert.match(workflow, /gsd:plan-phase \$\{PHASE_NUM\} --gaps/);
assert.match(
workflow,
/\| \$\{PHASE_NUM\} \| verification_deferred_human \| \/gsd:verify-work \$\{PHASE_NUM\} \|/,
'human deferral must persist the exact deferred STATE row',
);
assert.match(
workflow,
/\| \$\{PHASE_NUM\} \| verification_deferred_gaps \| \/gsd:plan-phase \$\{PHASE_NUM\} --gaps \|/,
'gap deferral must persist the exact deferred STATE row',
);
assert.doesNotMatch(
workflow,
/Human validation deferred` and proceed to iterate step/,
'human-needed deferral must not silently proceed to the next phase',
);
assert.doesNotMatch(
workflow,
/Gaps deferred` and proceed to iterate step/,
'gap deferral must not silently proceed to the next phase',
);
assert.match(
workflow,
/Skip deferred phases on autonomous re-entry/,
'reruns must explicitly skip deferred verification phases',
);
assert.match(
workflow,
/Deferred Verification \(Skipped on Re-entry\)/,
'workflow should surface skipped deferred phases and their resume commands',
);
});
test('workflow runs normal transition post-processing after passed verification (#1526)', () => {
const workflow = read(WORKFLOW_PATH);
const passedIdx = workflow.indexOf('**If `passed`:**');
const transitionIdx = workflow.indexOf('transition.md', passedIdx);
const iterateIdx = workflow.indexOf('Proceed to iterate step', passedIdx);
assert.ok(transitionIdx > passedIdx, 'passed verification must invoke transition.md');
assert.ok(
transitionIdx < iterateIdx,
'normal transition post-processing must run before autonomous iterates',
);
});
test('workflow reads canonical verification status before human-needed promotion (#1522)', () => {
const workflow = read(WORKFLOW_PATH);
const waitIdx = workflow.indexOf('After execute, read canonical verification');
const humanNeededIdx = workflow.indexOf('**If `human_needed`:**', waitIdx);
const promoteIdx = workflow.indexOf('set VERIFICATION frontmatter `status: passed`', humanNeededIdx);
const section = workflow.slice(waitIdx, humanNeededIdx);
assert.ok(waitIdx !== -1, 'workflow must document the post-execution verification read');
assert.ok(humanNeededIdx > waitIdx, 'human_needed branch must follow verification status read');
assert.ok(promoteIdx > humanNeededIdx, 'human_needed branch must contain the promotion action');
// #2589: the verification read uses the native --pick flag (no jq dependency).
// String-based check (not a regex literal) so the assertion stays robust to
// shell metacharacters in the snippet and parses cleanly under espree.
assert.ok(
section.includes('VERIFY_STATUS=$(gsd_run query verification.status "${PHASE_DIR}" --pick status 2>/dev/null || true)'),
'autonomous must route human validation through canonical verification.status via the native --pick flag',
);
assert.doesNotMatch(
section,
/grep "\^status:"/,
'autonomous must not route stale human_needed reports from raw frontmatter',
);
});
test('workflow discovers incomplete phases from canonical verification projection (#1522)', () => {
const workflow = read(WORKFLOW_PATH);
const discoverStart = workflow.indexOf('<step name="discover_phases">');
const discoverEnd = workflow.indexOf('</step>', discoverStart);
const iterateStart = workflow.indexOf('<step name="iterate">');
const iterateEnd = workflow.indexOf('</step>', iterateStart);
const discoverStep = workflow.slice(discoverStart, discoverEnd);
const iterateStep = workflow.slice(iterateStart, iterateEnd);
assert.match(discoverStep, /INIT_MANAGER=\$\(gsd_run query init\.manager\)/);
assert.ok(
discoverStep.includes('if [[ "$INIT_MANAGER" == @file:* ]]; then INIT_MANAGER=$(cat "${INIT_MANAGER#@file:}"); fi'),
'autonomous discovery must dereference large init.manager payloads before parsing',
);
assert.match(discoverStep, /phase_complete !== true/);
assert.match(discoverStep, /verification_status !== "passed"/);
// #4455: STATE.md is read through the workstream-resolved path from
// init.manager (state_path), not a hardcoded .planning/STATE.md literal —
// a GSD_WORKSTREAM run must read its own workstream's STATE.md.
assert.ok(
discoverStep.includes('STATE_PATH=$(_gsd_field "$INIT_MANAGER" state_path)'),
'autonomous discovery must resolve STATE.md through init.manager, not a hardcoded path',
);
assert.match(discoverStep, /STATE_CONTENT=\$\(cat "\$STATE_PATH" 2>\/dev\/null \|\| true\)/);
assert.doesNotMatch(
discoverStep,
/STATE_CONTENT=\$\(cat \.planning\/STATE\.md 2>\/dev\/null \|\| true\)/,
'autonomous discovery must not regress to a hardcoded root .planning/STATE.md read (#4455)',
);
assert.match(discoverStep, /drop any phase whose number appears in the deferred-phase map/);
assert.doesNotMatch(discoverStep, /ROADMAP=\$\(gsd_run query roadmap\.analyze\)/);
assert.doesNotMatch(discoverStep, /disk_status !== "complete"/);
assert.match(iterateStep, /INIT_MANAGER=\$\(gsd_run query init\.manager\)/);
assert.ok(
iterateStep.includes('if [[ "$INIT_MANAGER" == @file:* ]]; then INIT_MANAGER=$(cat "${INIT_MANAGER#@file:}"); fi'),
'autonomous iteration must dereference large init.manager payloads before parsing',
);
assert.match(iterateStep, /phase_complete !== true/);
assert.match(iterateStep, /verification_status !== "passed"/);
assert.ok(
iterateStep.includes('STATE_PATH=$(_gsd_field "$INIT_MANAGER" state_path)'),
'autonomous iteration must resolve STATE.md through init.manager, not a hardcoded path',
);
assert.match(iterateStep, /STATE_CONTENT=\$\(cat "\$STATE_PATH" 2>\/dev\/null \|\| true\)/);
assert.doesNotMatch(
iterateStep,
/STATE_CONTENT=\$\(cat \.planning\/STATE\.md 2>\/dev\/null \|\| true\)/,
'autonomous iteration must not regress to a hardcoded root .planning/STATE.md read (#4455)',
);
assert.match(iterateStep, /drop deferred phases from the autonomous queue/);
});
});
// ─── Issue #3210: bounded blocker retries, needs_human escalation ────────────
//
// handle_blocker's "Fix and retry" path had no attempt ceiling across
// invocations and no automatic escalation to a terminal needs_human state, so
// a non-converging blocker (e.g. an operator gate the executor cannot satisfy)
// looped indefinitely. Regression coverage lives here because this file owns
// the autonomous.md host-workflow contract.
describe('issue #3210: autonomous handle_blocker has a retry ceiling with needs_human escalation', () => {
function stepOf(content, name) {
const open = `<step name="${name}">`;
const from = content.indexOf(open);
assert.ok(from !== -1, `step "${name}" not found`);
const to = content.indexOf('</step>', from);
assert.ok(to !== -1, `step "${name}" has no closing tag`);
return content.slice(from, to);
}
test('handle_blocker bounds "Fix and retry" attempts per phase step', () => {
const step = stepOf(read(WORKFLOW_PATH), 'handle_blocker');
assert.match(
step,
/\b3\b.*retr|\bretr.*\b3\b|RETRY_COUNT|retry (ceiling|limit|count)/i,
'handle_blocker must track a bounded retry count for the same phase step instead of ' +
're-presenting "Fix and retry" indefinitely (#3210)'
);
});
test('handle_blocker auto-escalates to a terminal needs_human halt once the ceiling is exceeded', () => {
const step = stepOf(read(WORKFLOW_PATH), 'handle_blocker');
assert.match(
step,
/needs_human/,
'once the retry ceiling is exceeded, handle_blocker must halt autonomously in a terminal ' +
'needs_human state (surfacing the unmet items) instead of looping or asking again (#3210)'
);
});
});