Files
msd-core/tests/loop-render-hooks.test.cjs
Tom Boucher b10e56818b feat(#1169): complete ADR-857 phase 6 — migrate features to Capabilities, revive dead gates, harden conformance gate (#1183)
* test(#1168): make phase-6 gate un-gameable — reject empty stubs + require loop shrink

The migration assertion previously checked only role==feature, so a registration-only stub (empty hooks, logic left inline) would turn the gate green while phase 6 stayed incomplete — the exact false-completion pattern this gate exists to prevent. Strengthen it: each ADR-named feature must OWN its behavior (>=1 hook, or a command family); and plan-phase.md/execute-phase.md must shrink strictly below their frozen pre-phase-6 sizes (94519/93166 LF bytes), which also defeats double-run gaming (declare a hook but keep the inline block -> file does not shrink -> red).

Gate now 5 pass / 4 fail (orphaned execute:wave:post, empty/unregistered features, config-key leaks, no shrink). Green is now reachable only by REAL migration. Refs #1168, #1169.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* feat(#1169): migrate gap-analysis to a Capability (plan:post gate)

First real ADR-857 phase-6 migration (pattern-defining tracer). gap-analysis moves from an inline post_planning_gaps branch in plan-phase.md to a real plan:post gate Capability:

- capabilities/gap-analysis/capability.json: role:feature, plan:post gate (when=workflow.post_planning_gaps, blocking:false advisory), OWNS workflow.post_planning_gaps (federated out of central schema). - plan-phase.md: inline config-get + gsd_run gap-analysis block replaced with a plan:post render-hooks call site dispatching the gate; file shrinks 94519->93279. - src/check-command-router.cts: cmdGapAnalysisPlanPost runs the real gap analysis via gap-checker. - post_planning_gaps removed from central manifest; resolves via federated config (default true preserved). - tests/post-planning-gaps-2493: re-pointed to assert capability ownership.

Verified: gate 5 pass / 4 fail (gap-analysis cleared from migration, plan:post-orphan, config-leak, and plan-phase shrink checks); loadConfig still returns post_planning_gaps=true; check command runs real analysis; 392/392 in the config/registry/federation/router net. Refs #1169.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* feat(#1169): migrate profile-pipeline to a command-family Capability

ADR-857 Decision 7: profile-pipeline becomes a command-family Capability (like audit/intel/graphify). capabilities/profile-pipeline/capability.json declares an 8-command family (scan-sessions, extract-messages, profile-sample, write-profile, profile-questionnaire, generate-dev-preferences, generate-claude-profile, generate-claude-md) backed by a new gsd-core/bin/lib/profile-pipeline-command-router.cjs; the inline case arms are removed from gsd-tools.cjs. Owns profile-pipeline.enabled (federated).

Verified: registry shows role:feature with commands.length=8; scan-sessions/profile-sample run live via the family; gate cleared profile-pipeline from the empty-stub failure (only tdd/schema-gate/drift remain); 296/296 registry+inventory+gsd-tools tests; lint 0 errors. Refs #1169.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* fix(#1167): wire execute:wave:post + implement ui.safety-gate check

Revives the second dead gate from #1167: ui.gates@execute:wave:post was declared but never dispatched AND its check.query (ui.safety-gate) was unimplemented. Adds the per-wave execute:wave:post render-hooks call site in execute-phase.md (fires after each wave's merge/cleanup, before the next forks) and implements cmdUiSafetyGate (frontend + UI-SPEC aware, mirrors cmdUiPlanGate) in check-command-router. +17 regression tests.

Verified: phase-6 orphaned-points conformance test now PASSES (gate 6 pass / 3 fail); ui-safety-gate routable in dot+hyphen forms; check-ui-safety-gate 17/17, check-ui-plan-gate 18/18; lint 0 errors. Refs #1167, #1168.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* feat(#1169): migrate drift (schema + codebase) to execute:wave:post gates

Removes the inline schema_drift_gate + codebase_drift_gate steps (77 lines) from execute-phase.md; drift becomes a Capability with two execute:wave:post gates (verify.schema-drift blocking, verify.codebase-drift advisory) dispatched via the per-wave render-hooks call site. check-command-router routes verify.schema-drift / verify.codebase-drift to the real detectors. Federates workflow.drift_threshold / drift_action / schema_drift_gate out of central.

Also fixes the execute:wave:post dispatch prose to run NON-blocking (advisory) gates too — the prior version only ran blocking gates, which would have silently dropped the codebase-drift advisory after its inline step was removed. Behavior preserved.

Verified: gate 7 pass / 2 fail (drift cleared from stub + config-leak; execute-phase.md 92297 < 93166 frozen -> shrink passes); both drift checks run real detection; loadConfig defaults preserved (threshold=3, action=warn, gate=true); drift-detection 56/56 + schema-drift 34/34; lint 0 errors. Refs #1169.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* feat(#1169): migrate tdd to a Capability (plan:pre contribution + execute:post gate)

tdd becomes a real Capability: a plan:pre contribution injects the <tdd_mode_active> planner guidance (rendered from PLAN_PRE_HOOKS_JSON like security's contribution), and an execute:post gate (tdd.review-checkpoint, advisory) runs the real end-of-phase RED/GREEN review via a new check-command handler. Inline tdd_mode reads + the inline planner block + the tdd_review_checkpoint step are removed; workflow.tdd_mode is federated out of central. The MVP+TDD per-task RED-commit gate is preserved — TDD_MODE is now derived from the execute:post hooks (capId==tdd active), not an inline config-get.

BEHAVIOR CHANGE (documented, not silent): the --tdd CLI flag now persists workflow.tdd_mode=true via config-set instead of being per-invocation. Rationale: tdd is now a config-toggled Capability, and env vars do not persist across the workflow's separate bash blocks (config does), so an ephemeral override isn't cleanly achievable; --tdd therefore enables the tdd capability, consistent with how all capabilities are toggled.

Verified: gate 7 pass / 2 fail (tdd cleared from stub + config-leak; plan-phase + execute-phase both < frozen sizes); contribution injection + execute:post gate dispatch wired; MVP+TDD gate preserved; tdd.review-checkpoint runs real review; full unit suite 556/0; lint 0 errors. Refs #1169.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* feat(#1169): migrate schema-gate to a plan:pre contribution Capability

The plan-time schema-push detection (former plan-phase.md §5.7) becomes a schema-gate Capability: a plan:pre contribution (into:planner, when:workflow.schema_push_detection) whose fragment carries the full ORM-detection + [BLOCKING] schema-push-task injection logic, rendered into the planner via the existing plan:pre render-hooks dispatch. The inline §5.7 block is removed (plan-phase.md 94519->90445). workflow.schema_push_detection is a new capability-owned (federated) key, default true. (The execute-side schema-drift gate was migrated separately into the drift capability.)

Verified: registry inlines the fragment (len 2704) so it is actually delivered at plan:pre; gate 8 pass / 1 fail — all 5 ADR-named features now real Capabilities, only the config-leak test remains (intel/security, next unit). Refs #1169.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* feat(#1169): close the 3 capability config-key leaks — phase-6 gate now GREEN

Removes the last inline config-get reads of capability-owned keys from plan-phase.md. security_asvs_level/security_block_on now flow through the security plan:pre contribution via a new loop-resolver configValues mechanism (resolves declared config keys with the same 4-level precedence as activation and attaches them to the rendered hook); the §5.55 banner reads them from PLAN_PRE_HOOKS_JSON. intel.enabled becomes a real intel plan:pre step (ref.command: intel api-surface) dispatched via render-hooks; the inline intel branch is gone. gen-capability-registry now validates ref.command as a third dispatch shape.

Verified: phase-6 capstone conformance gate is FULLY GREEN (9/0); 3 leaks gone (grep=0); security configValues resolve to {2,medium}/default {1,high}; intel step present only when enabled; loop-render-hooks 62/0, capability-registry 287/0, capability-state/federated-config 113/0; lint 0 errors. Closes the migration half of #1169. Refs #1139, #1167, #1168.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* fix(#1169): address adversarial review — restore schema-drift block, generic planner injection, uniform gate contract

Adversarial review caught 2 real regressions the green gate missed: (1) schema-drift no longer blocked — the execute:wave:post dispatch read GATE_RESULT.block but verify.schema-drift emitted drift_detected/blocking, and onError:skip wrongly bypassed positive blocks; (2) only tdd's plan:pre contribution was injected into the planner, dropping schema-gate's schema-push detection and security's threat-model guidance.

Fixes: (A) every gate check returns a uniform boolean 'block' under --raw (the dispatch form), with advisory gates (tdd/gap) carrying their report in 'message'; (B) gate-dispatch contract corrected at all sites — onError governs command errors only, a blocking gate's positive block always halts; (C) generic planner injection of all plan:pre contributions where into=='planner' (tdd + schema-gate + security incl configValues); (D) two new conformance assertions: planner contributions injected generically + every gate check.query returns boolean block under --raw.

Verified: gate 11/11; all 6 gate checks return boolean block under --raw; full suite 595/0; lint 0 errors. Refs #1167, #1168, #1169.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* fix(#1169): restore MVP+TDD end-of-phase blocking escalation (2nd adversarial pass)

The migrated tdd execute:post gate is statically blocking:false, but the contract (references/execute-mvp-tdd.md + CONTEXT.md) requires the end-of-phase TDD review to ESCALATE from advisory to blocking when MVP_MODE && TDD_MODE && a TDD plan misses a RED/GREEN commit. The migration prose had downgraded this to a 'strong advisory recommendation' — silent loss of the blocking escalation. Restore it: the tdd-gate dispatch now refuses to mark the phase complete (Phase blocked message) under MVP+TDD when GATE_RESULT.block is true; advisory otherwise.

Also strengthen tests/execute-mvp-tdd-gate.test.cjs: hasBlockingEscalation previously matched any line with 'blocking'+'mvp+tdd' (so 'advisory (blocking: false) ... under MVP+TDD' was a false green); now it requires the real refusal semantics ('refuse to mark the phase complete' / 'phase blocked'). Caught by 2nd adversarial review pass.

Verified: execute-phase.md 92702 < 93166 frozen; mvp-tdd-gate + phase-6 gate 19/0; full suite green; lint 0 errors. Refs #1169.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* fix(#1169): restore MVP+TDD proceed-block, codebase auto-remap, schema skip-flag (3rd adversarial pass)

3rd adversarial pass found 4 more silent regressions: (1) the tdd MVP+TDD 'refuse to mark complete' was nullified by a downstream 'ALWAYS proceed regardless of gate results' line — proceed is now conditional (stops on an active MVP+TDD block); (2) the test now asserts the proceed is NOT an unconditional override; (3) codebase-drift auto-remap (spawn gsd-codebase-mapper when drift_action=auto-remap) was dropped — the execute:wave:post advisory dispatch now consumes spawn_mapper/directive; (4) GSD_SKIP_SCHEMA_CHECK bypass was lost from the gate path — cmdVerifySchemaDrift now honors the env var (block:false when set).

Verified: no unconditional proceed; GSD_SKIP_SCHEMA_CHECK=true -> block:false; gate 11/11 + mvp-tdd 9/9; full suite 569/0; lint 0; execute-phase.md 93109 < 93166. Refs #1169.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* fix(#1169): init.cts reads federated config keys from nested path (4th adversarial pass)

Config federation moved tdd_mode/research/nyquist_validation from flat config.<key> to nested config.workflow.<key>, but src/init.cts still read them flat — so init.plan-phase/init.execute-phase emitted tdd_mode:false / research_enabled:undefined / nyquist:undefined regardless of config (a public command-contract regression; the migrated loops use render-hooks so enforcement was unaffected). Read via config.workflow (type-safe Record cast). Now init reflects the same resolved values + federated defaults (research/nyquist default true) as the render-hooks path.

Verified: build clean; init.plan-phase emits tdd_mode:true/research:false/nyquist:false for set config, defaults true for empty; full suite 591/0; lint 0. Refs #1169.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* docs(#1169): add changeset for ADR-857 phase-6 completion (PR #1183)

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* fix(#1169): complete phase-6 migration fallout — restore TEXT_MODE, fix registry .claude leak, re-point stale workflow-contract tests

The capability migration left real regressions and stale consumer tests that
the per-module unit suite missed but the full cross-platform suite caught (27
failing tests):

Real source regressions (fixed):
- execute-phase.md lost its AskUserQuestion TEXT_MODE plain-text fallback when
  the inline schema_drift_gate step was removed — non-Claude runtimes would
  stall. Restored, and the execute:post gate-dispatch prose de-duplicated to
  cite the execute:wave:post contract (loop body shrinks below the frozen
  pre-phase-6 ceiling while keeping every onError/blocking nuance).
- capabilities/tdd inline fragment hardcoded `@~/.claude/gsd-core/references/tdd.md`,
  baked verbatim into the committed capability-registry.cjs and leaked the
  install path on 11 non-Claude runtimes (registry .cjs is copied, not
  path-converted). Made the fragment path-free; regenerated the registry. The
  phase-6 conformance gate now guards this (no ~/.claude install path in any
  capability source or the generated registry).
- plan-phase.md: removed a §5.7 stub re-added in error and routed Branch 2 to
  step 6 (schema-gate is a plan:pre capability, §5.7 is gone).

Stale workflow-contract tests re-pointed to the capability dispatch they now
must assert (behavior verified preserved in source first, assertions kept
equal-or-stronger): bug-621 + bug-2851 (gap-analysis via gsd_run render-hooks
plan:post + registry binding), feat-2527 (tdd_mode federated out of central),
phase6-planning + plan-phase-ui-redirect (§5.6 bounded by ## 6.),
plan-phase-drift-guard (intel when:intel.enabled skip branch).

profile-pipeline-command-router.cjs un-ignored from eslint (hand-written, no
TS source) + stale disable comments removed. Size baseline regenerated.

Verified: full suite 15140 tests / 0 fail; lint 0 errors; conformance gate green
legitimately. Refs #1139, #1167, #1168, #1169.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* test(#1169): add ADR-857 E2E content-test coverage for the 12 loop points + capability deliverables

Grounds the capability engine in behavioral E2E tests (drive the real
render-hooks/check CLI + the real registry, assert typed result content — no
source-grep), structured around what ADR-857 says to deliver. 207 tests; each
genuineness-checked (flip the expectation, confirm it fails).

Per-loop-point dispatch (7 files): empty-point negative-space across the 6
no-hook points; verify:post 3-step resolution+ordering+onError; plan:pre
contribution/configValues + ui.plan-gate + intel; plan:post gap-analysis;
execute:wave:post drift+ui gates via the check route (schema-drift block/skip,
codebase-drift threshold BVA, auto-remap); execute:post tdd.review-checkpoint
RED/GREEN; ship:pre security gate resolution + frontmatter-get predicate pieces.

ADR-deliverable coverage (4 files): predicate boundary held (edge/prohibition
probes stay core, not off-by-default Feature Capabilities — phase-6 exception);
core loop runs with zero capabilities (all 12 points empty, init bundles
resolve); contribution merge (multiple ordered <contribution from=> blocks);
federated-config key removal on uninstall.

federated-config allowlisted for its 3-file split (unit + integration +
lifecycle). Refs #1139, #1167, #1168, #1169.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* fix(#1169): remove dead drifted converter dups + address adversarial review

Lint cleanup (root-caused, not waved off): src/runtime-artifact-conversion.cts
carried 11 agent-converter functions (+5 orphaned consts/helpers) that were
never exported, never called, and had silently DRIFTED from the live
hand-authored copies in bin/install.js (one even referenced an undefined
`claudeToCopilotTools`). Deleted the dead duplicates; install.js's live copies
are untouched (it never imported these). Lint now 0 errors / 0 warnings.

Adversarial-review (Codex) findings fixed:
- HIGH: execute-phase.md TDD_MODE used `jq ... || echo false`, silently
  disabling the MVP+TDD blocking gate on jq-less runtimes. Reverted to the
  `node -e` form (node is guaranteed; matches the file's other node-e usages) so
  a missing optional tool can no longer fail-open a blocking safety path.
- MEDIUM: federated-config-key-removal orphan-key test was vacuous (it skipped
  the orphan assertion). Now asserts the removed capability's key is genuinely
  not surfaced/validated after uninstall.
- LOW: phase-6 conformance leak regex broadened to catch absolute-home and
  Windows-backslash `.claude/(gsd-core|commands|agents|hooks)` paths, not only
  `~`/`$HOME` forward-slash forms.
- LOW: bug-2851 plan:post dispatch assertion now requires `--raw` (matched its
  stated contract).
- nit: plan-pre intel-step test duplicate assertion replaced with a distinct
  structured-output check.

Size baseline regenerated (execute-phase.md 93089 < 93166 frozen). Refs #1167, #1169.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* test(#1169): make runtime-homes-descriptor-drive titles environment-independent

The descriptor-equivalence test embedded the absolute golden config path
(`os.homedir()`-derived) directly in each `test(...)` title, so titles differed
between macOS (`/Users/x/.claude`) and Docker (`/home/gsdtest/.claude`). Every
test PASSES on both platforms (15885/0 leaf tests each), but gsd-test-summary
compares results by title and reported 29+29 false "only in Mac / only in
Docker" discrepancies for tests that actually pass everywhere.

Move the golden path out of the title and into the assertion message (still
shown on failure); titles are now byte-identical across platforms so the
cross-platform comparator matches them. No assertion logic or golden values
changed. Refs #1169.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* fix(#1169): derive TDD_MODE via gsd_run --active-cap, not node -e (fix prompt-injection CI gate)

The prior fix reverted execute-phase.md:181 from jq to `node -e` to close a
Codex HIGH (jq||echo-false silently disabling the MVP+TDD blocking gate on
jq-less runtimes) — but the CI prompt-injection scanner BLOCKS new `node -e` in
workflow markdown (inline code-exec = injection vector), turning the security
gate red. Both forms were wrong: node -e fails the scanner; jq fail-opens a
blocking safety gate; `config-get workflow.tdd_mode` is forbidden by the
conformance leak gate (tdd_mode is capability-owned).

Correct fix (what Codex recommended): a gsd_run-native boolean. Add an
`--active-cap <capId>` flag to `loop render-hooks <point>` that resolves hooks
the normal way and prints exactly `true`/`false` for whether a capId is active
— scanner-safe (canonical launcher, no inline code), node-reliable (no optional
jq to fail-open), and leak-free (render-hooks resolution, not config-get).
execute-phase.md:181 now `TDD_MODE=$(gsd_run loop render-hooks execute:post
--active-cap tdd)`. +5 behavioral tests for the flag.

Verified: prompt-injection-scan --diff origin/next → 0 findings; conformance
gate 13/13 (execute-phase.md 92934 < 93166); execute-mvp-tdd + tdd-mode +
loop-render-hooks 87/0; lint 0/0. Refs #1167, #1169.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-13 21:07:55 -04:00

966 lines
42 KiB
JavaScript

'use strict';
/**
* loop-render-hooks.test.cjs — behavioral tests for loop-resolver.cjs.
*
* ADR-857 phase 3c.
* Uses node:test + node:assert/strict.
* Pure-function tests (resolveLoopHooks, renderLoopHooks) pass registry+config
* directly — no I/O. End-to-end tests use cmdLoopRenderHooks + a temp project.
*/
const { describe, test, before, after } = require('node:test');
const assert = require('node:assert/strict');
const fs = require('node:fs');
const os = require('node:os');
const path = require('node:path');
const { cleanup } = require('./helpers.cjs');
const {
resolveLoopHooks,
renderLoopHooks,
_getNestedConfigValue,
_resolveActivationValue,
_readRawConfigKey,
CANONICAL_POINTS_FALLBACK,
CANONICAL_POINTS,
} = require('../gsd-core/bin/lib/loop-resolver.cjs');
// The real registry for integration tests
const realRegistry = require('../gsd-core/bin/lib/capability-registry.cjs');
// ─── Synthetic registry fixtures ─────────────────────────────────────────────
/**
* Build a minimal synthetic registry with a single step hook at a given point.
* Optionally include a configSchema for testing default-based activation.
*/
function makeRegistry({ point = 'plan:pre', steps = [], contributions = [], gates = {}, configSchema = {} } = {}) {
const byLoopPoint = {};
for (const p of CANONICAL_POINTS_FALLBACK) {
byLoopPoint[p] = { steps: [], contributions: [], gates: [] };
}
if (steps.length) byLoopPoint[point].steps = steps;
if (contributions.length) byLoopPoint[point].contributions = contributions;
if (gates[point]) byLoopPoint[point].gates = gates[point];
return { byLoopPoint, configSchema };
}
// ─── Temp project helpers ─────────────────────────────────────────────────────
let tmpProjectDir;
// A project with NO .planning/config.json — relies on schema defaults
let tmpEmptyProjectDir;
// A project where ui_phase is explicitly false in root config
let tmpFalseConfigProjectDir;
// Runtime config dir whose surface disables the UI capability
let tmpUiDisabledConfigDir;
before(() => {
tmpProjectDir = fs.mkdtempSync(path.join(os.tmpdir(), 'loop-resolver-test-'));
const planningDir = path.join(tmpProjectDir, '.planning');
fs.mkdirSync(planningDir, { recursive: true });
// Write minimal config.json with all UI flags enabled
fs.writeFileSync(
path.join(planningDir, 'config.json'),
JSON.stringify({ workflow: { ui_phase: true, ui_review: true, ui_safety_gate: true } }),
'utf8',
);
// Empty project — no config.json: schema defaults drive activation
tmpEmptyProjectDir = fs.mkdtempSync(path.join(os.tmpdir(), 'loop-resolver-empty-'));
fs.mkdirSync(path.join(tmpEmptyProjectDir, '.planning'), { recursive: true });
// False config project — ui_phase explicitly false in root config
tmpFalseConfigProjectDir = fs.mkdtempSync(path.join(os.tmpdir(), 'loop-resolver-false-'));
const falseConfigPlanningDir = path.join(tmpFalseConfigProjectDir, '.planning');
fs.mkdirSync(falseConfigPlanningDir, { recursive: true });
fs.writeFileSync(
path.join(falseConfigPlanningDir, 'config.json'),
JSON.stringify({ workflow: { ui_phase: false, ui_review: false, ui_safety_gate: false } }),
'utf8',
);
tmpUiDisabledConfigDir = fs.mkdtempSync(path.join(os.tmpdir(), 'loop-resolver-ui-disabled-'));
fs.writeFileSync(
path.join(tmpUiDisabledConfigDir, '.gsd-surface.json'),
JSON.stringify({
baseProfile: 'full',
disabledClusters: ['ui'],
explicitAdds: [],
explicitRemoves: [],
}, null, 2),
'utf8',
);
});
after(() => {
if (tmpProjectDir) cleanup(tmpProjectDir);
if (tmpEmptyProjectDir) cleanup(tmpEmptyProjectDir);
if (tmpFalseConfigProjectDir) cleanup(tmpFalseConfigProjectDir);
if (tmpUiDisabledConfigDir) cleanup(tmpUiDisabledConfigDir);
});
// ─── 1. Canonical-point validation ───────────────────────────────────────────
describe('canonical point validation', () => {
test('all 12 canonical points are accepted by resolveLoopHooks with empty registry', () => {
const emptyRegistry = makeRegistry();
const config = {};
for (const p of CANONICAL_POINTS_FALLBACK) {
const result = resolveLoopHooks({ point: p, registry: emptyRegistry, config });
assert.strictEqual(result.point, p);
assert.deepEqual(result.activeHooks, []);
}
});
test('12 canonical points total', () => {
assert.strictEqual(CANONICAL_POINTS_FALLBACK.length, 12);
});
test('invalid point throws with a clear message', () => {
const emptyRegistry = makeRegistry();
assert.throws(
() => resolveLoopHooks({ point: 'plan:mid', registry: emptyRegistry, config: {} }),
(err) => {
assert.ok(err instanceof Error);
assert.match(err.message, /Invalid loop point/);
assert.match(err.message, /plan:mid/);
return true;
},
);
});
test('empty string point throws', () => {
const emptyRegistry = makeRegistry();
assert.throws(
() => resolveLoopHooks({ point: '', registry: emptyRegistry, config: {} }),
/Invalid loop point/,
);
});
test('close typo throws', () => {
const emptyRegistry = makeRegistry();
assert.throws(
() => resolveLoopHooks({ point: 'plan:pre ', registry: emptyRegistry, config: {} }),
/Invalid loop point/,
);
});
// FIX 2: non-canonical point rejected even if the registry has it as a byLoopPoint key
test('non-canonical point in registry byLoopPoint is still rejected', () => {
// Craft a registry that has a synthetic non-canonical key in byLoopPoint
const registry = {
byLoopPoint: {
// All canonical points (needed so the registry is well-formed)
...Object.fromEntries(CANONICAL_POINTS_FALLBACK.map(p => [p, { steps: [], contributions: [], gates: [] }])),
// A non-canonical key that a malformed registry might inject
'inject:arbitrary': { steps: [{ capId: 'evil', ref: { skill: 'bad' } }], contributions: [], gates: [] },
},
};
assert.throws(
() => resolveLoopHooks({ point: 'inject:arbitrary', registry, config: {} }),
/Invalid loop point/,
);
});
// FIX 2: all 12 canonical points are listed in the error message
test('invalid point error lists the canonical 12', () => {
const emptyRegistry = makeRegistry();
assert.throws(
() => resolveLoopHooks({ point: 'not:real', registry: emptyRegistry, config: {} }),
(err) => {
assert.ok(err instanceof Error);
for (const p of CANONICAL_POINTS_FALLBACK) {
assert.ok(err.message.includes(p), `Expected "${p}" in error message: ${err.message}`);
}
return true;
},
);
});
// CANONICAL_POINTS is derived from LOOP_HOST_CONTRACT, not from registry keys
test('CANONICAL_POINTS and CANONICAL_POINTS_FALLBACK are the same 12 points', () => {
assert.deepEqual(CANONICAL_POINTS, CANONICAL_POINTS_FALLBACK);
assert.strictEqual(CANONICAL_POINTS.length, 12);
});
});
// ─── 2. Activation tests ─────────────────────────────────────────────────────
describe('activation filter', () => {
test('hook with no "when" is always active', () => {
const registry = makeRegistry({
steps: [{ capId: 'test-cap', point: 'plan:pre', ref: { skill: 'my-skill' } }],
});
const result = resolveLoopHooks({ point: 'plan:pre', registry, config: {} });
assert.strictEqual(result.activeHooks.length, 1);
assert.strictEqual(result.activeHooks[0].capId, 'test-cap');
});
test('hook with when="mytool.on", config{mytool:{on:true}} → active', () => {
const registry = makeRegistry({
steps: [{ capId: 'test-cap', point: 'plan:pre', ref: { skill: 'my-skill' }, when: 'mytool.on' }],
});
const config = { mytool: { on: true } };
const result = resolveLoopHooks({ point: 'plan:pre', registry, config });
assert.strictEqual(result.activeHooks.length, 1);
assert.strictEqual(result.activeHooks[0].kind, 'step');
});
test('hook with when="mytool.on", config{mytool:{on:false}} → filtered', () => {
const registry = makeRegistry({
steps: [{ capId: 'test-cap', point: 'plan:pre', ref: { skill: 'my-skill' }, when: 'mytool.on' }],
});
const config = { mytool: { on: false } };
const result = resolveLoopHooks({ point: 'plan:pre', registry, config });
assert.strictEqual(result.activeHooks.length, 0);
});
test('hook with when="mytool.on", config{} (absent key) → filtered', () => {
const registry = makeRegistry({
steps: [{ capId: 'test-cap', point: 'plan:pre', ref: { skill: 'my-skill' }, when: 'mytool.on' }],
});
const result = resolveLoopHooks({ point: 'plan:pre', registry, config: {} });
assert.strictEqual(result.activeHooks.length, 0);
});
test('hook with when="mytool.on", config{mytool:{}} → filtered (key absent)', () => {
const registry = makeRegistry({
steps: [{ capId: 'test-cap', point: 'plan:pre', ref: { skill: 'my-skill' }, when: 'mytool.on' }],
});
const config = { mytool: {} };
const result = resolveLoopHooks({ point: 'plan:pre', registry, config });
assert.strictEqual(result.activeHooks.length, 0);
});
// FIX 3: non-string `when` → INACTIVE (not always-active)
test('hook with when=true (boolean) → inactive (FIX 3: malformed non-string when)', () => {
const registry = makeRegistry({
steps: [{ capId: 'test-cap', point: 'plan:pre', ref: { skill: 'my-skill' }, when: true }],
});
const result = resolveLoopHooks({ point: 'plan:pre', registry, config: {} });
assert.strictEqual(result.activeHooks.length, 0, 'non-string when=true must be treated as inactive');
});
test('hook with when=42 (number) → inactive (FIX 3)', () => {
const registry = makeRegistry({
steps: [{ capId: 'test-cap', point: 'plan:pre', ref: { skill: 'my-skill' }, when: 42 }],
});
const result = resolveLoopHooks({ point: 'plan:pre', registry, config: {} });
assert.strictEqual(result.activeHooks.length, 0, 'non-string when=42 must be inactive');
});
test('hook with when={} (object) → inactive (FIX 3)', () => {
const registry = makeRegistry({
steps: [{ capId: 'test-cap', point: 'plan:pre', ref: { skill: 'my-skill' }, when: {} }],
});
const result = resolveLoopHooks({ point: 'plan:pre', registry, config: {} });
assert.strictEqual(result.activeHooks.length, 0, 'non-string when={} must be inactive');
});
// FIX 4: configSchema default=true → active with absent config (no cwd → level 4 applies)
test('configSchema default=true + absent config → active', () => {
const registry = makeRegistry({
steps: [{ capId: 'test-cap', point: 'plan:pre', ref: { skill: 'my-skill' }, when: 'mytool.on' }],
configSchema: {
'mytool.on': { type: 'boolean', default: true, description: 'Enable mytool.' },
},
});
const result = resolveLoopHooks({ point: 'plan:pre', registry, config: {} });
assert.strictEqual(result.activeHooks.length, 1, 'schema default=true should activate the hook');
assert.strictEqual(result.activeHooks[0].capId, 'test-cap');
});
// FIX 4: configSchema default=false → inactive with absent config
test('configSchema default=false + absent config → inactive', () => {
const registry = makeRegistry({
steps: [{ capId: 'test-cap', point: 'plan:pre', ref: { skill: 'my-skill' }, when: 'mytool.on' }],
configSchema: {
'mytool.on': { type: 'boolean', default: false, description: 'Disabled by default.' },
},
});
const result = resolveLoopHooks({ point: 'plan:pre', registry, config: {} });
assert.strictEqual(result.activeHooks.length, 0, 'schema default=false should keep hook inactive');
});
// FIX 4: configSchema default=true but explicit config override=false → inactive (config wins)
test('configSchema default=true but config override false → inactive (config wins)', () => {
const registry = makeRegistry({
steps: [{ capId: 'test-cap', point: 'plan:pre', ref: { skill: 'my-skill' }, when: 'mytool.on' }],
configSchema: {
'mytool.on': { type: 'boolean', default: true, description: 'Enabled by default.' },
},
});
const config = { mytool: { on: false } };
const result = resolveLoopHooks({ point: 'plan:pre', registry, config });
assert.strictEqual(result.activeHooks.length, 0, 'explicit config=false overrides schema default=true');
});
});
// ─── 3. UI pilot integration tests ───────────────────────────────────────────
describe('UI pilot integration', () => {
test('plan:pre with workflow.ui_phase=true → ui-phase step active', () => {
const config = { workflow: { ui_phase: true, ui_review: true, ui_safety_gate: true } };
const result = resolveLoopHooks({ point: 'plan:pre', registry: realRegistry, config });
const uiStep = result.activeHooks.find(h => h.capId === 'ui' && h.kind === 'step');
assert.ok(uiStep, 'Expected ui step at plan:pre');
assert.deepEqual(uiStep.ref, { skill: 'ui-phase' });
assert.ok(Array.isArray(uiStep.produces));
assert.ok(uiStep.produces.includes('UI-SPEC.md'));
});
test('plan:pre with workflow.ui_phase=false → ui-phase step filtered', () => {
const config = { workflow: { ui_phase: false, ui_review: true, ui_safety_gate: true } };
const result = resolveLoopHooks({ point: 'plan:pre', registry: realRegistry, config });
const uiStep = result.activeHooks.find(h => h.capId === 'ui' && h.kind === 'step');
assert.strictEqual(uiStep, undefined, 'Expected ui step to be filtered');
});
// FIX 4 INVERSION: empty config + real registry → ui-phase IS active (schema default=true)
test('plan:pre with empty config + real registry → ui-phase step active by default (FIX 4)', () => {
// realRegistry has configSchema['workflow.ui_phase'].default === true
// So with no config and no cwd, the schema default kicks in → active
const result = resolveLoopHooks({ point: 'plan:pre', registry: realRegistry, config: {} });
const uiStep = result.activeHooks.find(h => h.capId === 'ui' && h.kind === 'step');
assert.ok(
uiStep,
'Expected ui step to be active by default (configSchema.default=true). Got: ' +
JSON.stringify(result.activeHooks),
);
assert.strictEqual(uiStep.when, 'workflow.ui_phase');
});
test('execute:wave:post with workflow.ui_safety_gate=true → ui gate active', () => {
const config = { workflow: { ui_phase: true, ui_review: true, ui_safety_gate: true } };
const result = resolveLoopHooks({ point: 'execute:wave:post', registry: realRegistry, config });
const uiGate = result.activeHooks.find(h => h.capId === 'ui' && h.kind === 'gate');
assert.ok(uiGate, 'Expected ui gate at execute:wave:post');
assert.strictEqual(uiGate.blocking, true);
assert.strictEqual(uiGate.onError, 'halt');
});
test('execute:wave:post with workflow.ui_safety_gate=false → ui gate filtered', () => {
const config = { workflow: { ui_phase: true, ui_review: true, ui_safety_gate: false } };
const result = resolveLoopHooks({ point: 'execute:wave:post', registry: realRegistry, config });
const uiGate = result.activeHooks.find(h => h.capId === 'ui' && h.kind === 'gate');
assert.strictEqual(uiGate, undefined, 'Expected ui gate to be filtered');
});
// FIX 4: execute:wave:post with empty config → ui gate active by schema default
test('execute:wave:post with empty config → ui gate active by schema default', () => {
const result = resolveLoopHooks({ point: 'execute:wave:post', registry: realRegistry, config: {} });
const uiGate = result.activeHooks.find(h => h.capId === 'ui' && h.kind === 'gate');
assert.ok(uiGate, 'Expected ui gate active by default (configSchema.default=true)');
assert.strictEqual(uiGate.blocking, true);
});
});
// ─── 4. Ordering tests ────────────────────────────────────────────────────────
describe('hook ordering', () => {
test('steps appear before contributions before gates', () => {
const registry = makeRegistry({
point: 'plan:pre',
steps: [{ capId: 'c1', point: 'plan:pre', ref: { skill: 'sk1' } }],
contributions: [{ capId: 'c2', point: 'plan:pre', into: 'planner' }],
gates: { 'plan:pre': [{ capId: 'c3', point: 'plan:pre', check: { query: 'some-gate' }, blocking: false }] },
});
const config = {};
const result = resolveLoopHooks({ point: 'plan:pre', registry, config });
assert.strictEqual(result.activeHooks.length, 3);
assert.strictEqual(result.activeHooks[0].kind, 'step');
assert.strictEqual(result.activeHooks[1].kind, 'contribution');
assert.strictEqual(result.activeHooks[2].kind, 'gate');
});
test('within steps, registry order is preserved', () => {
const registry = makeRegistry({
point: 'plan:pre',
steps: [
{ capId: 'cap-a', point: 'plan:pre', ref: { skill: 'a' } },
{ capId: 'cap-b', point: 'plan:pre', ref: { skill: 'b' } },
{ capId: 'cap-c', point: 'plan:pre', ref: { skill: 'c' } },
],
});
const result = resolveLoopHooks({ point: 'plan:pre', registry, config: {} });
assert.deepEqual(result.activeHooks.map(h => h.capId), ['cap-a', 'cap-b', 'cap-c']);
});
});
// ─── 5. Envelope shape ────────────────────────────────────────────────────────
describe('envelope shape', () => {
test('envelope has point, activeHooks, rendered from renderLoopHooks', () => {
const registry = makeRegistry({
steps: [{ capId: 'cap-a', point: 'plan:pre', ref: { skill: 'my-skill' }, produces: ['A.md'], consumes: ['B.md'] }],
});
const resolved = resolveLoopHooks({ point: 'plan:pre', registry, config: {} });
const rendered = renderLoopHooks(resolved);
assert.strictEqual(resolved.point, 'plan:pre');
assert.ok(Array.isArray(resolved.activeHooks));
assert.strictEqual(typeof rendered, 'string');
});
test('empty activeHooks → rendered is non-empty placeholder string', () => {
const registry = makeRegistry(); // all empty
const resolved = resolveLoopHooks({ point: 'plan:pre', registry, config: {} });
const rendered = renderLoopHooks(resolved);
assert.strictEqual(resolved.activeHooks.length, 0);
assert.ok(rendered.length > 0, 'rendered should be a non-empty placeholder');
assert.match(rendered, /plan:pre/);
});
test('rendered contains hook content when hooks are active', () => {
const registry = makeRegistry({
steps: [{ capId: 'ui', point: 'plan:pre', ref: { skill: 'ui-phase' }, produces: ['UI-SPEC.md'], consumes: ['CONTEXT.md'], when: 'workflow.ui_phase', onError: 'skip' }],
});
const config = { workflow: { ui_phase: true } };
const resolved = resolveLoopHooks({ point: 'plan:pre', registry, config });
const rendered = renderLoopHooks(resolved);
assert.match(rendered, /ui-phase/);
assert.match(rendered, /ui/);
assert.match(rendered, /UI-SPEC\.md/);
});
test('rendered for UI pilot at plan:pre with all flags on', () => {
const config = { workflow: { ui_phase: true, ui_review: true, ui_safety_gate: true } };
const resolved = resolveLoopHooks({ point: 'plan:pre', registry: realRegistry, config });
const rendered = renderLoopHooks(resolved);
assert.match(rendered, /ui-phase/);
assert.match(rendered, /UI-SPEC\.md/);
});
});
// ─── 6. Malformed registry resilience ────────────────────────────────────────
describe('malformed registry resilience', () => {
test('missing byLoopPoint → no throw, empty activeHooks', () => {
const badRegistry = {}; // no byLoopPoint
// No throw — but point validation falls back to CANONICAL_POINTS_FALLBACK
const result = resolveLoopHooks({ point: 'plan:pre', registry: badRegistry, config: {} });
assert.strictEqual(result.activeHooks.length, 0);
});
test('null hook in steps array → skipped', () => {
const registry = makeRegistry({
steps: [null, { capId: 'ok', point: 'plan:pre', ref: { skill: 'ok-skill' } }, undefined],
});
const result = resolveLoopHooks({ point: 'plan:pre', registry, config: {} });
assert.strictEqual(result.activeHooks.length, 1);
assert.strictEqual(result.activeHooks[0].capId, 'ok');
});
test('byLoopPoint[point] missing arrays → no throw, empty result', () => {
const registry = { byLoopPoint: { 'plan:pre': {} } }; // no steps/contributions/gates keys
const result = resolveLoopHooks({ point: 'plan:pre', registry, config: {} });
assert.strictEqual(result.activeHooks.length, 0);
});
test('byLoopPoint[point] has non-array steps → treated as empty', () => {
const registry = { byLoopPoint: { 'plan:pre': { steps: 'bad', contributions: [], gates: [] } } };
const result = resolveLoopHooks({ point: 'plan:pre', registry, config: {} });
assert.strictEqual(result.activeHooks.length, 0);
});
test('byLoopPoint[point] is null → no throw, empty result', () => {
const registry = { byLoopPoint: { 'plan:pre': null } };
const result = resolveLoopHooks({ point: 'plan:pre', registry, config: {} });
assert.strictEqual(result.activeHooks.length, 0);
});
});
// ─── 7. Prototype-pollution guard ────────────────────────────────────────────
describe('prototype-pollution guard', () => {
test('when="__proto__.x" does not pollute Object.prototype', () => {
const registry = makeRegistry({
steps: [{ capId: 'attacker', point: 'plan:pre', ref: { skill: 'evil' }, when: '__proto__.x' }],
});
const config = { x: 'injected' };
// Should not throw and should not activate (guard returns found:false)
const result = resolveLoopHooks({ point: 'plan:pre', registry, config });
assert.strictEqual(result.activeHooks.length, 0);
// Object.prototype must not be polluted
assert.strictEqual(({}).x, undefined);
});
test('when="constructor.x" does not pollute', () => {
const registry = makeRegistry({
steps: [{ capId: 'attacker', point: 'plan:pre', ref: { skill: 'evil' }, when: 'constructor.x' }],
});
const result = resolveLoopHooks({ point: 'plan:pre', registry, config: {} });
assert.strictEqual(result.activeHooks.length, 0);
});
test('when="prototype.x" does not pollute', () => {
const registry = makeRegistry({
steps: [{ capId: 'attacker', point: 'plan:pre', ref: { skill: 'evil' }, when: 'prototype.x' }],
});
const result = resolveLoopHooks({ point: 'plan:pre', registry, config: {} });
assert.strictEqual(result.activeHooks.length, 0);
});
test('_getNestedConfigValue: __proto__ segment returns found:false', () => {
const r = _getNestedConfigValue({}, '__proto__.x');
assert.strictEqual(r.found, false);
});
test('_getNestedConfigValue: constructor segment returns found:false', () => {
const r = _getNestedConfigValue({}, 'constructor.toString');
assert.strictEqual(r.found, false);
});
test('_getNestedConfigValue: normal dotted key traversal works', () => {
const config = { workflow: { ui_phase: true } };
const r = _getNestedConfigValue(config, 'workflow.ui_phase');
assert.strictEqual(r.found, true);
assert.strictEqual(r.value, true);
});
// FIX 4: raw config.json with __proto__ key does not pollute via _readRawConfigKey
test('raw config.json with "__proto__" key does not pollute Object.prototype', () => {
const tmpDir = fs.mkdtempSync(path.join(os.tmpdir(), 'loop-resolver-proto-'));
try {
// Write a raw config.json containing __proto__ at top level and nested
// (JSON.parse of {"__proto__":{"x":"polluted"}} does NOT set prototype in modern Node,
// but we verify our guarded traversal returns found:false for such keys)
const maliciousConfig = '{"__proto__":{"x":"polluted"},"workflow":{"ui_phase":true}}';
fs.writeFileSync(path.join(tmpDir, 'config.json'), maliciousConfig, 'utf8');
// _readRawConfigKey with '__proto__.x' should return found:false (guard)
const r1 = _readRawConfigKey(path.join(tmpDir, 'config.json'), '__proto__.x');
assert.strictEqual(r1.found, false, '__proto__ lookup must be guarded');
// Normal key should work
const r2 = _readRawConfigKey(path.join(tmpDir, 'config.json'), 'workflow.ui_phase');
assert.strictEqual(r2.found, true);
assert.strictEqual(r2.value, true);
// Object.prototype must not be polluted
assert.strictEqual(({}).x, undefined);
} finally {
cleanup(tmpDir);
}
});
// FIX 4: _resolveActivationValue with cwd pointing to project with __proto__ config key
test('_resolveActivationValue: raw config with __proto__ key does not pollute', () => {
const tmpDir = fs.mkdtempSync(path.join(os.tmpdir(), 'loop-resolver-proto2-'));
try {
const planningDir = path.join(tmpDir, '.planning');
fs.mkdirSync(planningDir, { recursive: true });
fs.writeFileSync(
path.join(planningDir, 'config.json'),
'{"__proto__":{"y":"polluted2"}}',
'utf8',
);
const registry = makeRegistry({
steps: [{ capId: 'test', point: 'plan:pre', ref: { skill: 'sk' }, when: '__proto__.y' }],
});
const result = resolveLoopHooks({ point: 'plan:pre', registry, config: {}, cwd: tmpDir });
assert.strictEqual(result.activeHooks.length, 0, '__proto__ when must be inactive');
assert.strictEqual(({}).y, undefined, 'Object.prototype.y must not be polluted');
} finally {
cleanup(tmpDir);
}
});
});
// ─── 7b. Raw config.json override paths (FIX 4) ──────────────────────────────
describe('raw config.json override paths (FIX 4)', () => {
// FIX 4: user sets workflow.ui_phase=false in root config.json → hook filtered
test('root config.json with ui_phase=false overrides schema default=true → inactive', () => {
// tmpFalseConfigProjectDir has .planning/config.json { workflow: { ui_phase: false } }
const result = resolveLoopHooks({
point: 'plan:pre',
registry: realRegistry,
config: {}, // empty loadConfig result (simulating pre-cutover)
cwd: tmpFalseConfigProjectDir,
});
const uiStep = result.activeHooks.find(h => h.capId === 'ui' && h.kind === 'step');
assert.strictEqual(
uiStep,
undefined,
'root config.json override false must beat schema default=true',
);
});
// FIX 4: root config.json with ui_phase=true (explicit) → hook active
test('root config.json with ui_phase=true → active (raw config read path)', () => {
// tmpProjectDir has .planning/config.json { workflow: { ui_phase: true } }
const result = resolveLoopHooks({
point: 'plan:pre',
registry: realRegistry,
config: {}, // empty loadConfig result (simulating pre-cutover)
cwd: tmpProjectDir,
});
const uiStep = result.activeHooks.find(h => h.capId === 'ui' && h.kind === 'step');
assert.ok(uiStep, 'root config.json ui_phase=true should activate hook');
});
// FIX 4: no config.json at all → falls through to schema default=true → active
test('no config.json → schema default=true → hook active', () => {
// tmpEmptyProjectDir has .planning/ directory but no config.json
const result = resolveLoopHooks({
point: 'plan:pre',
registry: realRegistry,
config: {}, // empty loadConfig result
cwd: tmpEmptyProjectDir,
});
const uiStep = result.activeHooks.find(h => h.capId === 'ui' && h.kind === 'step');
assert.ok(uiStep, 'no config.json → schema default=true → hook should be active');
});
// FIX 4: _readRawConfigKey returns found:false for missing file (ENOENT — silent)
test('_readRawConfigKey: missing file → found:false, no throw', () => {
const result = _readRawConfigKey('/nonexistent/path/config.json', 'workflow.ui_phase');
assert.strictEqual(result.found, false);
});
// FIX 4: _readRawConfigKey returns found:false for malformed JSON, warns once
test('_readRawConfigKey: malformed JSON → found:false, no throw', () => {
const tmpDir = fs.mkdtempSync(path.join(os.tmpdir(), 'loop-resolver-malformed-'));
try {
const malformedPath = path.join(tmpDir, 'config.json');
fs.writeFileSync(malformedPath, '{ invalid json }', 'utf8');
const result = _readRawConfigKey(malformedPath, 'workflow.ui_phase');
assert.strictEqual(result.found, false, 'malformed JSON should return found:false');
} finally {
cleanup(tmpDir);
}
});
});
// ─── 8. Renderer tests ────────────────────────────────────────────────────────
describe('renderLoopHooks', () => {
test('step hook renders skill ref, capId, produces, consumes', () => {
const resolved = {
point: 'plan:pre',
activeHooks: [{
capId: 'ui',
kind: 'step',
ref: { skill: 'ui-phase' },
when: 'workflow.ui_phase',
produces: ['UI-SPEC.md'],
consumes: ['CONTEXT.md'],
onError: 'skip',
}],
};
const rendered = renderLoopHooks(resolved);
assert.match(rendered, /Step 1/);
assert.match(rendered, /skill:ui-phase/);
assert.match(rendered, /\(ui\)/);
assert.match(rendered, /UI-SPEC\.md/);
assert.match(rendered, /CONTEXT\.md/);
assert.match(rendered, /workflow\.ui_phase/);
assert.match(rendered, /skip/);
});
test('step hook renders agent ref and inline prompt fragment', () => {
const registry = makeRegistry({
point: 'plan:pre',
steps: [{
capId: 'research',
point: 'plan:pre',
ref: { agent: 'gsd-phase-researcher' },
fragment: { inline: 'Research the phase before planning.' },
produces: ['RESEARCH.md'],
consumes: ['CONTEXT.md'],
onError: 'skip',
}],
});
const resolved = resolveLoopHooks({ point: 'plan:pre', registry, config: {} });
assert.deepEqual(resolved.activeHooks[0].fragment, { inline: 'Research the phase before planning.' });
const rendered = renderLoopHooks(resolved);
assert.match(rendered, /agent:gsd-phase-researcher/);
assert.match(rendered, /Research the phase before planning\./);
});
test('contribution hook renders into role', () => {
const resolved = {
point: 'plan:pre',
activeHooks: [{
capId: 'contrib-cap',
kind: 'contribution',
into: 'planner',
fragment: { inline: 'Apply the project-specific planning guardrails.' },
}],
};
const rendered = renderLoopHooks(resolved);
assert.match(rendered, /contribution/);
assert.match(rendered, /contrib-cap/);
assert.match(rendered, /planner/);
assert.match(rendered, /Apply the project-specific planning guardrails\./);
assert.match(rendered, /<contribution from="contrib-cap" into="planner">/);
assert.match(rendered, /<\/contribution>/);
assert.doesNotMatch(rendered, /<contribution[^>]+\/>/);
});
test('resolveLoopHooks preserves contribution fragment data', () => {
const registry = makeRegistry({
point: 'plan:pre',
contributions: [{
capId: 'contrib-cap',
point: 'plan:pre',
into: 'planner',
fragment: { inline: 'Use artifact-backed evidence.' },
produces: ['PLAN-NOTES.md'],
consumes: ['CONTEXT.md'],
when: 'workflow.contrib',
onError: 'halt',
}],
configSchema: {
'workflow.contrib': { type: 'boolean', default: true, description: 'Enable test contribution.' },
},
});
const resolved = resolveLoopHooks({ point: 'plan:pre', registry, config: {} });
assert.strictEqual(resolved.activeHooks.length, 1);
assert.deepEqual(resolved.activeHooks[0].fragment, { inline: 'Use artifact-backed evidence.' });
assert.deepEqual(resolved.activeHooks[0].produces, ['PLAN-NOTES.md']);
assert.deepEqual(resolved.activeHooks[0].consumes, ['CONTEXT.md']);
assert.strictEqual(resolved.activeHooks[0].onError, 'halt');
});
test('gate hook renders check, blocking, onError', () => {
const resolved = {
point: 'execute:wave:post',
activeHooks: [{
capId: 'ui',
kind: 'gate',
check: { query: 'ui.safety-gate' },
blocking: true,
onError: 'halt',
}],
};
const rendered = renderLoopHooks(resolved);
assert.match(rendered, /Gate/);
assert.match(rendered, /ui/);
assert.match(rendered, /blocking=true/);
assert.match(rendered, /halt/);
});
test('multiple hooks in order render with correct ordinals', () => {
const resolved = {
point: 'plan:pre',
activeHooks: [
{ capId: 'cap-a', kind: 'step', ref: { skill: 'a' }, produces: ['A.md'], consumes: [] },
{ capId: 'cap-b', kind: 'step', ref: { skill: 'b' }, produces: ['B.md'], consumes: ['A.md'] },
],
};
const rendered = renderLoopHooks(resolved);
assert.match(rendered, /Step 1/);
assert.match(rendered, /Step 2/);
const idx1 = rendered.indexOf('Step 1');
const idx2 = rendered.indexOf('Step 2');
assert.ok(idx1 < idx2, 'Step 1 should appear before Step 2');
});
test('empty hooks returns placeholder containing the point name', () => {
const rendered = renderLoopHooks({ point: 'ship:post', activeHooks: [] });
assert.match(rendered, /ship:post/);
assert.ok(rendered.length > 0);
});
test('rendered is deterministic (same input → same output)', () => {
const config = { workflow: { ui_phase: true, ui_review: true, ui_safety_gate: true } };
const resolved = resolveLoopHooks({ point: 'plan:pre', registry: realRegistry, config });
const r1 = renderLoopHooks(resolved);
const r2 = renderLoopHooks(resolved);
assert.strictEqual(r1, r2);
});
});
// ─── 9. End-to-end cmdLoopRenderHooks (via gsd-tools subprocess) ─────────────
const { spawnSync } = require('node:child_process');
const ROOT = path.resolve(__dirname, '..');
const GSD_TOOLS = path.join(ROOT, 'gsd-core', 'bin', 'gsd-tools.cjs');
describe('cmdLoopRenderHooks end-to-end (via gsd-tools)', () => {
test('loop render-hooks plan:pre returns JSON envelope with ui-phase step active', () => {
const result = spawnSync(
process.execPath,
[GSD_TOOLS, 'loop', 'render-hooks', 'plan:pre', '--cwd', tmpProjectDir],
{ cwd: ROOT, encoding: 'utf8' },
);
assert.strictEqual(result.status, 0, 'Expected exit 0. stderr: ' + (result.stderr || ''));
const envelope = JSON.parse(result.stdout.trim());
assert.strictEqual(envelope.point, 'plan:pre');
assert.ok(Array.isArray(envelope.activeHooks));
assert.strictEqual(typeof envelope.rendered, 'string');
// With ui_phase=true in tmpProjectDir config, ui-phase step should be active
const uiStep = envelope.activeHooks.find(h => h.capId === 'ui' && h.kind === 'step');
assert.ok(uiStep, 'Expected ui step in activeHooks. Got: ' + JSON.stringify(envelope.activeHooks));
assert.match(envelope.rendered, /ui-phase/);
});
// FIX 4: schema-default activation — no config.json in project → ui-phase step active by default
test('loop render-hooks plan:pre with no config.json → ui-phase step active by schema default', () => {
const result = spawnSync(
process.execPath,
[GSD_TOOLS, 'loop', 'render-hooks', 'plan:pre', '--cwd', tmpEmptyProjectDir],
{ cwd: ROOT, encoding: 'utf8' },
);
assert.strictEqual(result.status, 0, 'Expected exit 0. stderr: ' + (result.stderr || ''));
const envelope = JSON.parse(result.stdout.trim());
const uiStep = envelope.activeHooks.find(h => h.capId === 'ui' && h.kind === 'step');
assert.ok(
uiStep,
'Expected ui step active by default. Got: ' + JSON.stringify(envelope.activeHooks),
);
assert.match(envelope.rendered, /ui-phase/);
});
test('loop render-hooks plan:pre with ui capability disabled in surface → ui hooks absent', () => {
const result = spawnSync(
process.execPath,
[
GSD_TOOLS,
'loop',
'render-hooks',
'plan:pre',
'--cwd',
tmpEmptyProjectDir,
'--config-dir',
tmpUiDisabledConfigDir,
],
{ cwd: ROOT, encoding: 'utf8' },
);
assert.strictEqual(result.status, 0, 'Expected exit 0. stderr: ' + (result.stderr || ''));
const envelope = JSON.parse(result.stdout.trim());
const uiHooks = envelope.activeHooks.filter(h => h.capId === 'ui');
assert.deepStrictEqual(
uiHooks,
[],
'UI hooks must be absent when the UI capability is disabled at the runtime surface',
);
});
// FIX 4: explicit false in config.json overrides schema default
test('loop render-hooks plan:pre with ui_phase=false in config.json → ui-phase step absent', () => {
const result = spawnSync(
process.execPath,
[GSD_TOOLS, 'loop', 'render-hooks', 'plan:pre', '--cwd', tmpFalseConfigProjectDir],
{ cwd: ROOT, encoding: 'utf8' },
);
assert.strictEqual(result.status, 0, 'Expected exit 0. stderr: ' + (result.stderr || ''));
const envelope = JSON.parse(result.stdout.trim());
const uiStep = envelope.activeHooks.find(h => h.capId === 'ui' && h.kind === 'step');
assert.strictEqual(
uiStep,
undefined,
'ui-phase step should be absent when config.json sets ui_phase=false',
);
});
test('loop render-hooks invalid-point exits non-zero', () => {
const result = spawnSync(
process.execPath,
[GSD_TOOLS, 'loop', 'render-hooks', 'plan:mid', '--cwd', tmpProjectDir],
{ cwd: ROOT, encoding: 'utf8' },
);
assert.notStrictEqual(result.status, 0, 'Expected non-zero exit for invalid point');
assert.match(result.stderr, /plan:mid|Invalid loop point/);
});
});
// ─── 10. --active-cap flag (scanner-safe boolean derivation) ──────────────────
describe('--active-cap flag (loop render-hooks)', () => {
// Temp project with tdd_mode=true in config
let tddOnDir;
// Temp project with tdd_mode=false in config
let tddOffDir;
before(() => {
tddOnDir = fs.mkdtempSync(path.join(os.tmpdir(), 'loop-active-cap-tdd-on-'));
const planOn = path.join(tddOnDir, '.planning');
fs.mkdirSync(planOn, { recursive: true });
fs.writeFileSync(
path.join(planOn, 'config.json'),
JSON.stringify({ workflow: { tdd_mode: true } }),
'utf8',
);
tddOffDir = fs.mkdtempSync(path.join(os.tmpdir(), 'loop-active-cap-tdd-off-'));
const planOff = path.join(tddOffDir, '.planning');
fs.mkdirSync(planOff, { recursive: true });
fs.writeFileSync(
path.join(planOff, 'config.json'),
JSON.stringify({ workflow: { tdd_mode: false } }),
'utf8',
);
});
after(() => {
if (tddOnDir) cleanup(tddOnDir);
if (tddOffDir) cleanup(tddOffDir);
});
test('--active-cap tdd with tdd_mode=true → stdout trimmed === "true", exit 0', () => {
const result = spawnSync(
process.execPath,
[GSD_TOOLS, 'loop', 'render-hooks', 'execute:post', '--active-cap', 'tdd', '--cwd', tddOnDir],
{ cwd: ROOT, encoding: 'utf8' },
);
assert.strictEqual(result.status, 0, 'Expected exit 0. stderr: ' + (result.stderr || ''));
assert.strictEqual(result.stdout.trim(), 'true', 'Expected stdout "true" when tdd_mode=true');
});
test('--active-cap tdd with tdd_mode=false → stdout trimmed === "false", exit 0', () => {
const result = spawnSync(
process.execPath,
[GSD_TOOLS, 'loop', 'render-hooks', 'execute:post', '--active-cap', 'tdd', '--cwd', tddOffDir],
{ cwd: ROOT, encoding: 'utf8' },
);
assert.strictEqual(result.status, 0, 'Expected exit 0. stderr: ' + (result.stderr || ''));
assert.strictEqual(result.stdout.trim(), 'false', 'Expected stdout "false" when tdd_mode=false');
});
test('--active-cap <nonexistent-cap> → stdout trimmed === "false", exit 0', () => {
const result = spawnSync(
process.execPath,
[GSD_TOOLS, 'loop', 'render-hooks', 'execute:post', '--active-cap', 'no-such-capability-xyz', '--cwd', tddOffDir],
{ cwd: ROOT, encoding: 'utf8' },
);
assert.strictEqual(result.status, 0, 'Expected exit 0 for unknown capId. stderr: ' + (result.stderr || ''));
assert.strictEqual(result.stdout.trim(), 'false', 'Expected stdout "false" for unknown capId');
});
test('--active-cap with no value → non-zero exit and error message', () => {
const result = spawnSync(
process.execPath,
[GSD_TOOLS, 'loop', 'render-hooks', 'execute:post', '--active-cap', '--cwd', tddOffDir],
{ cwd: ROOT, encoding: 'utf8' },
);
assert.notStrictEqual(result.status, 0, 'Expected non-zero exit when --active-cap has no value');
assert.match(result.stderr, /active-cap/i, 'Expected error message referencing --active-cap');
});
test('--active-cap output is exactly "true" or "false" (no JSON envelope, clean for shell capture)', () => {
// The entire stdout must be just "true" or "false" + newline — no envelope object
const result = spawnSync(
process.execPath,
[GSD_TOOLS, 'loop', 'render-hooks', 'execute:post', '--active-cap', 'tdd', '--cwd', tddOnDir],
{ cwd: ROOT, encoding: 'utf8' },
);
assert.strictEqual(result.status, 0, 'Expected exit 0. stderr: ' + (result.stderr || ''));
// Must be exactly "true" or "false" — not a JSON object/envelope
const trimmed = result.stdout.trim();
assert.ok(
trimmed === 'true' || trimmed === 'false',
`stdout must be "true" or "false", got: ${JSON.stringify(result.stdout)}`,
);
// Must not be a JSON object (no envelope with point/activeHooks/rendered keys)
let parsed;
try { parsed = JSON.parse(trimmed); } catch { parsed = null; }
assert.ok(
typeof parsed !== 'object' || parsed === null,
'stdout must not be a JSON object/envelope when --active-cap is used',
);
});
});