Files
msd-core/scripts/lib/macos-conformance-tier.generated.cjs
Tom Boucher db4d8a9bae fix(#4619): execute-phase computes decimal/N-segment phase numbers without breaking shell arithmetic (#4644)
* fix(#4619): execute-phase computes decimal/N-segment phase numbers without breaking shell arithmetic

$((10#${PHASE_NUMBER})) is a hard bash/zsh syntax error when PHASE_NUMBER is
decimal (01.1, from an inserted phase) or N-segment (23.1.2) — neither is
valid shell-arithmetic syntax at all, and the failed expansion aborts the
rest of the snippet in a non-interactive shell. safe_resume_gate runs
unconditionally before trusting STATE.md or dispatching any executor, so
execute-phase failed at its own gate before the first executor on any
decimal phase, regardless of workflow.tdd_mode. Regression from #4194.

Fixes all 4 sites: safe_resume_gate and the TDD gate in
workflows/execute-phase.md, the completion-signal spot-check fallback in
workflows/execute-phase/steps/completion-reconciliation.md, and the
executor gate validation example in references/tdd.md. Each now zero-strips
only the leading integer segment into a *_INT variable (via %%.* / #
parameter expansion — always valid shell syntax regardless of what follows)
and keeps the remainder as an escaped-dot string for the anchored commit-
scope regex, exactly as issue #4619 verified in both bash and zsh. A plain
integer phase (12, 01) computes byte-identically to before.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* test(#4619): pin the decimal/N-segment fix and characterize the pre-fix bug

Behavioral coverage via real bash execution: the old $((10#01.1)) form
throws (characterizes the bug, matching the issue's own reproduction); the
new form resolves 01.1 -> 1\.1 and 23.1.2 -> 23\.1\.2, unchanged for plain
integers (12 -> 12, 01 -> 1); the resulting anchored ERE matches
feat(01.1-03):/test(1.1-3): and correctly rejects feat(01-03):,
feat(01.2-03):, feat(011-03):, feat(12-03): for a decimal phase — mirroring
issue #4619's own verified table exactly. Updates
safe-resume-gate-anchoring.test.cjs's 4 existing source-text assertions
(one per site) to the new fixed text.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* chore(#4634): refine the shell-arith drift detector to distinguish safe from unsafe arithmetic

With #4619's fix in place, the guard's original "ban $((10#... outright,
match any occurrence" was too blunt: it flagged a comment merely mentioning
the pattern in prose, the now-safe $((10#$PHASE_INT)) arithmetic on an
already-%%.*-stripped integer, and the always-safe plan-id arithmetic
(plan ids are plain integers, never decimal). Refines the detector to skip
full-line comments and to only flag a captured variable/placeholder name
that contains "phase" and does NOT end in _INT/_int — the naming convention
the #4619 fix establishes at all four sites for "already reduced to a safe
integer." A plan-id variable was never phase-number arithmetic in the first
place and is excluded on the same basis.

This closes epic #4634's D6 ("lint-phase-id-drift... passes with no new
exemptions") and D7 ("a decimal and N-segment phase id survive an
end-to-end execute-phase selection without error") for real — the guard now
reports zero violations across all five .cts/.md rules.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* chore: regenerate conformance-tier manifests for the new test file

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* test(#4619): cover the plain-padded-integer near-miss matrix too

Review found the anchored-ERE near-miss coverage only exercised the
decimal case (PHASE_NUMBER=01.1); issue #4619's own worked table also
verifies the plain padded-integer case (01 -> PHASE_N=1) against its own
near-miss set (matches 01-03, rejects 01.1-03/011-03/12-03). Adds the
missing assertion.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* docs(#4619): add Fixed changeset

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* fix(#4619): correct JS backslash-escaping in safe-resume-gate anchoring test

The test's string-literal assertions for the PHASE_FRAC//./\\.} pattern wrote
only 2 backslash characters in JS source, which single-quoted-string parsing
collapses to 1 real backslash at runtime -- but the workflow/reference files
actually contain 2 raw backslash bytes at that position (needed so bash's
${var//pattern/replacement} produces the correct single-backslash output).
Write 4 backslash characters in the JS source at all 4 occurrences so the
runtime string matches the files' real bytes.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* chore(#4619): refresh the committed compact-content benchmark baseline

The new PHASE_INT/PHASE_FRAC arithmetic lines added to
gsd-core/workflows/execute-phase.md shifted its committed compaction-ratio
baseline. Regenerate via `node scripts/benchmark-compact-content.cjs --write`.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* docs(#4619): note the safe_resume_gate arithmetic growth in the test header

The emitted-attribution gate flags execute-phase.md growing 91253 -> 91846
bytes (593 bytes). The growth is the fix: the safe_resume_gate and TDD RED
block now derive PHASE_INT/PHASE_FRAC before computing PHASE_N, so a
decimal/N-segment phase number (e.g. 01.1, 2.3.1) zero-strips its leading
integer segment via base-10 arithmetic instead of forcing the whole value
through $((10#...)) and hitting a hard shell syntax error on the first dot.

A blank line previously separated the Emitted-Drift-Ack-Growth trailer from
the Co-Authored-By trailer below it, which splits git's trailer-block
detection: only the last contiguous non-blank run of Key: Value lines at the
end of a commit message is recognized as trailers, so the growth ack was
silently read as ordinary body text and the differential-attribution gate
failed with the growth unacknowledged. Joining the two trailers into one
contiguous block fixes it.

Emitted-Drift-Ack-Growth: execute-phase.md — adds PHASE_INT/PHASE_FRAC derivation to the safe_resume_gate and TDD RED commit-scope grep so a decimal/N-segment phase number zero-strips its leading integer segment via base-10 arithmetic instead of failing on a non-numeric value (#4619)
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* test(#4208): replace chmod-based restore-failure injection with a root-proof git shim

`tests/commit-files-deletion.test.cjs`'s two restore-failure tests simulated
an unwritable index via a `post-index-change` hook running `chmod a-w` on
the git dir. That relies on the OS enforcing the *owner's own* permission
bits against itself, which uid 0 (a routine identity inside this repo's
Docker-based gsd-test benches) does not: every DAC check short-circuits true
for root, so the write the chmod meant to block silently succeeds, the
restore comes back clean, and the disclosure/rollback behavior under test
never actually gets exercised.

This is CLAUDE.md's own named anti-pattern for I/O-failure injection
("Cross-platform test IO-failure injection" — chmod tricks fail under root
Docker/CI). It is confirmed as the actual root cause here, not a production
defect: `src/commands.cts`'s `restoreRemovedEntries`/rollback-disclosure
logic (added by #4253, merged just before this run) was hand-traced and
manually reproduced end to end on an unprivileged workstation against a
freshly built `gsd-core/bin/lib/commands.cjs`, and it already produces
exactly the `staging_failed` + "could not be restored" / "could NOT be
restored during rollback" results both tests assert. The other
`post-index-change`-based tests in this file (a `sleep` to force a timeout;
a real `update-index` to flip a restored entry's mode) are unaffected
because neither depends on a permission check — consistent with only the
two chmod-based tests failing on the real remote run.

Replaces the chmod fixture with a fake `git` placed ahead of the real one on
PATH that fails only `update-index --add --cacheinfo` — the one call the
restore makes — unconditionally, regardless of privilege level. Every other
git invocation execs straight through to the real binary, so the rest of
each scenario (`rm --cached`, the restore's own `ls-files` verification,
etc.) is exercised exactly as before.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* chore(#4619): backfill changeset pr number to 4644

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* fix(#4619): feed the bash fixture script via stdin, not argv, to fix Windows CI

Passing the script as a `-c "<script>"` argv element made it subject to
Windows' CreateProcess command-line argument encoding, which silently
dropped the escaped-dot backslashes before bash ever saw them (observed on
PR #4644's windows-latest CI shard: `1\.1` came back as `1.1`). Feeding the
same script via stdin instead removes argv entirely from the transport, so
there is nothing for Windows to re-encode. POSIX behavior is unchanged.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

---------

Co-authored-by: sim <sim@local>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-11 15:47:14 -04:00

209 lines
8.4 KiB
JavaScript

// GENERATED FILE — do not hand-edit. Run `node scripts/gen-platform-conformance-tier.cjs --target macos --write` to regenerate.
// macOS-specific conformance tier (#4593), separate from and narrower than the general/
// Windows-oriented tier in platform-conformance-tier.generated.cjs — see
// docs/adr/4593-macos-conformance-tier-architecture.md for the full rationale.
'use strict';
module.exports = {
MACOS_CONFORMANCE_TIER_FILES: [
"tests/adr-index-gate.test.cjs",
"tests/adr-parser.property.test.cjs",
"tests/adr-parser.unit.test.cjs",
"tests/agent-classification-parity.test.cjs",
"tests/agent-install-check.test.cjs",
"tests/agent-skills.test.cjs",
"tests/api-coverage-gate-e2e.test.cjs",
"tests/api-coverage.test.cjs",
"tests/ask-user-questions-fallback.test.cjs",
"tests/audit-command-cutover.test.cjs",
"tests/broken-windows.test.cjs",
"tests/capability-cli.test.cjs",
"tests/capability-command-dispatch.test.cjs",
"tests/capability-consent.test.cjs",
"tests/capability-ledger.test.cjs",
"tests/capability-lifecycle.test.cjs",
"tests/capability-loader.test.cjs",
"tests/capability-lock-mkdir-failure-3987.test.cjs",
"tests/capability-registry.test.cjs",
"tests/capability-source.test.cjs",
"tests/capability-state.test.cjs",
"tests/capability-trust.test.cjs",
"tests/changeset-parse.test.cjs",
"tests/check-contract-drift.test.cjs",
"tests/check-ui-safety-gate.test.cjs",
"tests/check-update-config-dir.test.cjs",
"tests/chunked-planning-parallel.test.cjs",
"tests/ci-docs-guard-registry.test.cjs",
"tests/ci-test-scope.test.cjs",
"tests/cline-install.test.cjs",
"tests/code-review-pipeline-regression.test.cjs",
"tests/codex-config-agents.test.cjs",
"tests/codex-config-hooks.test.cjs",
"tests/codex-config-install.test.cjs",
"tests/codex-config.test.cjs",
"tests/commands.test.cjs",
"tests/commit-docs-bypass.test.cjs",
"tests/commit-files-deletion.test.cjs",
"tests/commit-files-pathspec.test.cjs",
"tests/commonjs-marker.test.cjs",
"tests/completion-ratio-scope-withholding.test.cjs",
"tests/config-loader.test.cjs",
"tests/config-schema.property.test.cjs",
"tests/config.test.cjs",
"tests/contributor-standards.test.cjs",
"tests/core-utils.test.cjs",
"tests/cursor-subagent-isolation.test.cjs",
"tests/debugger-semantic-recall.test.cjs",
"tests/default-flip-documentation-lint.test.cjs",
"tests/discuss-phase-power.test.cjs",
"tests/docs-parity-live-registry.test.cjs",
"tests/effort-surface-axis.test.cjs",
"tests/effort-sync-installed-runtime.test.cjs",
"tests/emitted-attribution.test.cjs",
"tests/ensure-runtime-build.test.cjs",
"tests/execute-phase-decimal-arithmetic.test.cjs",
"tests/executed-plan.test.cjs",
"tests/executor-mvp-tdd-section.test.cjs",
"tests/external-job.test.cjs",
"tests/failing-direction.test.cjs",
"tests/fallow-runner.test.cjs",
"tests/feat-2483-review-claude-mds-guard.test.cjs",
"tests/features-index-gate.test.cjs",
"tests/frontmatter.unit.test.cjs",
"tests/gap-checker.property.test.cjs",
"tests/gen-context-index.test.cjs",
"tests/gen-section-manifest.test.cjs",
"tests/git-base-branch.test.cjs",
"tests/graphify-query.test.cjs",
"tests/graphify-visualization.test.cjs",
"tests/gsd-secret-read-guard.test.cjs",
"tests/gsd-settings-advanced.test.cjs",
"tests/gsd-statusline.test.cjs",
"tests/gsd-tools-path-refs.test.cjs",
"tests/gsd-validate-commit-crash-policy.test.cjs",
"tests/gsd-write-guard.test.cjs",
"tests/health-diagnostic-rules/worktree-health.test.cjs",
"tests/health-diagnostic.test.cjs",
"tests/helpers-cleanup.test.cjs",
"tests/helpers-process-isolation.test.cjs",
"tests/hooks-crash-policy.test.cjs",
"tests/hooks-opt-in.test.cjs",
"tests/host-integration.test.cjs",
"tests/init-manager.test.cjs",
"tests/init.test.cjs",
"tests/install-minimal-hooks.test.cjs",
"tests/install-path-detection.test.cjs",
"tests/install-regressions.test.cjs",
"tests/install-runtime-artifacts.test.cjs",
"tests/install-write-confinement.test.cjs",
"tests/install.test.cjs",
"tests/installer-migration-antigravity-retire-confighome-artifacts.test.cjs",
"tests/installer-migration-config-root-marker.test.cjs",
"tests/installer-migration-pi-retire-hooks-dir.test.cjs",
"tests/installer-migration-prune-stale-pristine.test.cjs",
"tests/installer-migration-rename-gsd-core.test.cjs",
"tests/installer-migrations.test.cjs",
"tests/intel.test.cjs",
"tests/inventory-nested-families.test.cjs",
"tests/isolation-sentinel.test.cjs",
"tests/issue-version-gate.test.cjs",
"tests/kimi-upgrades.test.cjs",
"tests/lint-docs-command-form.test.cjs",
"tests/lint-workflow-shellcheck-fetch.test.cjs",
"tests/list-seeds.test.cjs",
"tests/markdown-sectionizer.test.cjs",
"tests/mcp-catalog.test.cjs",
"tests/milestone-archive.test.cjs",
"tests/milestone-window-single-owner.test.cjs",
"tests/model-catalog.unit.test.cjs",
"tests/model-resolver.test.cjs",
"tests/no-exact-case-env-access.rule.test.cjs",
"tests/no-pending-3212-markers.test.cjs",
"tests/no-phantom-issue-refs.test.cjs",
"tests/no-posix-mode-bit-assert.rule.test.cjs",
"tests/no-private-binary-resolution.rule.test.cjs",
"tests/no-unguarded-nonportable-exec.rule.test.cjs",
"tests/observability/event.test.cjs",
"tests/onboard-command.test.cjs",
"tests/opencode-plugin-adapter.test.cjs",
"tests/pause-work-context-detection.test.cjs",
"tests/pause-work-improvements.test.cjs",
"tests/perf-317-context-monitor-fs.test.cjs",
"tests/phase-completion-single-owner.test.cjs",
"tests/phase-estimation.test.cjs",
"tests/phase-id-drift-guard.test.cjs",
"tests/phase-id.test.cjs",
"tests/phase-locator.test.cjs",
"tests/phase.test.cjs",
"tests/plan-count-single-owner.test.cjs",
"tests/plan-phase-stall-detection.test.cjs",
"tests/plan-review-convergence.test.cjs",
"tests/planning-inspect.test.cjs",
"tests/planning-inspect.unit.test.cjs",
"tests/planning-lock-mkdir-failure-1884.test.cjs",
"tests/planning-snapshot.test.cjs",
"tests/planning-workspace.test.cjs",
"tests/platform-conformance-tier.test.cjs",
"tests/plugin-manifest.test.cjs",
"tests/policy-shell-pinning.test.cjs",
"tests/portability-rule-disable-ban.test.cjs",
"tests/precommit-alias-drift-hook.test.cjs",
"tests/prepush-enterprise-email-hook.test.cjs",
"tests/process-seam.test.cjs",
"tests/profile-output.test.cjs",
"tests/profile-pipeline.test.cjs",
"tests/quick-batch.test.cjs",
"tests/quick-branching.test.cjs",
"tests/quick-research.test.cjs",
"tests/reapply-verify-hunks.test.cjs",
"tests/refactor-1390-t3-characterization.test.cjs",
"tests/require-issue-link-policy.test.cjs",
"tests/response-language-coverage.test.cjs",
"tests/retired-artifact-cleanup.test.cjs",
"tests/review-build-prompt-optional-sections.test.cjs",
"tests/review-lane-runner.test.cjs",
"tests/review-lane-windows-spawn-resolution.test.cjs",
"tests/review-parallel-lanes.test.cjs",
"tests/review-plan-coverage-manifest.test.cjs",
"tests/review-reviewer-selection.test.cjs",
"tests/reviewer-manifest-body.test.cjs",
"tests/reviewer-step-dispatch.test.cjs",
"tests/roadmap-mode-field.test.cjs",
"tests/roadmap-parser.test.cjs",
"tests/roadmap-phase-fallback.test.cjs",
"tests/roadmap.test.cjs",
"tests/runtime-artifact-layout.test.cjs",
"tests/runtime-identity.test.cjs",
"tests/runtime-launcher-parity.test.cjs",
"tests/security.test.cjs",
"tests/settings-jsonc.test.cjs",
"tests/shared-hooks-dir-resolution.test.cjs",
"tests/shell-command-projection-dispatch.test.cjs",
"tests/spawn-liveness-banner.test.cjs",
"tests/state-document.test.cjs",
"tests/state-transition.test.cjs",
"tests/state.test.cjs",
"tests/todos-workstream-scope.test.cjs",
"tests/tracer-bullet.test.cjs",
"tests/uat.test.cjs",
"tests/ui-safety-gate.test.cjs",
"tests/ui-spec-inventory-provenance.test.cjs",
"tests/unreachable-guard-drift.test.cjs",
"tests/unreachable-shell-guard.test.cjs",
"tests/unusable-input.test.cjs",
"tests/update-custom-backup.test.cjs",
"tests/user-artifact-staging.test.cjs",
"tests/verification-overrides.test.cjs",
"tests/verification-status.test.cjs",
"tests/verify-archive-dirs-live-path.test.cjs",
"tests/verify-command-grounding.test.cjs",
"tests/verify.test.cjs",
"tests/workflow-fragments.test.cjs",
"tests/workflow-shell-pinning.test.cjs",
"tests/workstream-inventory.test.cjs",
"tests/workstream.test.cjs",
"tests/worktree-safety.test.cjs",
"tests/worktree.test.cjs",
],
};