* test(#4660): pin the letter-axis parity defect across all 6 shell/markdown phase-id sites Extends tests/nsegment-phase-grammar.test.cjs (#4568) one axis over: for each of the six sites, reads the live regex off disk and asserts it agrees with src/phase-id.cts's PHASE_NUMBER_TOKEN_SOURCE on the letter axis in BOTH directions — accepts `12A` / `3A` / `03A` / `23A.1.2`, still rejects `3a`, `3AB`, `A3` and the other canonical-invalid shapes — and that the two extracting sites return the full letter-suffixed token rather than its digit prefix (or nothing). Negative control against the unfixed tree: 22 failures, exactly the "(fails before the fix)" cases; every reject-parity case already green. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NLtEbRc1Qfbe95HRMNqwp3 * fix(#4660): widen the 6 shell/markdown phase-id mirrors to the canonical grammar's letter axis Adds `[A-Z]?` after the leading digit run at all six sites #4568 widened — the ERE translation of src/phase-id.cts's `\d+[A-Z]?(?:\.\d+)*` — so a documented, canonical-valid id like `12A` or `23A.1.2` is no longer refused by the four validating sites (code-review.md, code-review-fix.md, gsd-code-fixer.md, gsd-code-fixer.compact.md) or truncated to its digit prefix by the two extracting sites (execute-plan.md's plan-filename grep, plan-phase.md's --research-phase capture). Behaviour is byte-identical for every id that matched before; the adjacent comment and error-message text now names the grammar it mirrors. Driven: `init code-review 3A` on a fixture with a `03A-slug/` directory and a `### Phase 3A:` heading emits `padded_phase: "03A"`, which the old regex rejects and the widened one accepts — nothing upstream of the validator mangles the id. At execute-plan.md the trailing `-[0-9]+` is the PLAN number and stays digit-only; plan and milestone dimensions are out of scope per the brief. `CASE_FLEXIBLE_PHASE_NUMBER_TOKEN_SOURCE` derives from the canonical source by a literal `.replaceAll('A-Z', 'A-Za-z')`, so src/phase-id.cts is deliberately untouched. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NLtEbRc1Qfbe95HRMNqwp3 * chore(#4634): extend lint-phase-id-drift to ban a letter-less phase-id mirror in workflows/ and agents/ Adds findLetterlessPhaseMirrorDrift — the letter-axis twin of the #4568 single-segment rule — flagging the unbounded-segment shape `[0-9]+(\.[0-9]+)*` (and its \d / doubled-backslash near-variants) whose digit run is NOT followed by the `[A-Z]?` class, on any phase-carrying line across gsd-core/workflows/**/*.md, gsd-core/references/**/*.md and agents/**/*.md. Sanctioned the same way (`<!-- phase-id-owner: ... -->`), tolerates the case-flexible `[A-Za-z]?` directory-scanning variant so it cannot force that separate axis to narrow, and is wired into scanAll. Confirmed zero violations against the real tree post-#4660 fix, and one violation when a single site is reverted. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NLtEbRc1Qfbe95HRMNqwp3 * docs(#4660): add Fixed changeset Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NLtEbRc1Qfbe95HRMNqwp3 * chore: regenerate conformance-tier manifests for the extended grammar test tests/nsegment-phase-grammar.test.cjs now requires the compiled gsd-core/bin/lib/phase-id.cjs (to assert the canonical grammar agrees with each site's live regex), which moves it to a different platform-conformance tier; `gen-platform-conformance-tier.cjs --check` in lint:ci flagged the macOS manifest as stale. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NLtEbRc1Qfbe95HRMNqwp3 * test(#4660): reword a comment that tripped lint-docs-guard-registration The comment mentioned `docs/CONFIGURATION.md` between two backticked tokens, which the lint's template-literal detector read as a docs/ path expression. The test reads no docs/ file. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NLtEbRc1Qfbe95HRMNqwp3 * chore(#4660): refresh the compact-content benchmark baseline and acknowledge emitted growth plan-phase.md grew by 4 bytes (`[A-Z]?`), which moves the committed compact-content benchmark; refreshed with `benchmark-compact-content.cjs --write`. The six shipped files below grew by the widened regex literal plus the comment and error-message text that now names the canonical grammar. Emitted-Drift-Ack-Growth: code-review.md — #4660: `[A-Z]?` at the PADDED_PHASE validator plus a comment/error message naming the canonical grammar and the `12A` example Emitted-Drift-Ack-Growth: code-review-fix.md — #4660: `[A-Z]?` at the PADDED_PHASE validator plus a comment/error message naming the canonical grammar and the `12A` example Emitted-Drift-Ack-Growth: gsd-code-fixer.md — #4660: `[A-Z]?` at the padded_phase sink validator plus the defense-in-depth comment and error message updated to the canonical grammar Emitted-Drift-Ack-Growth: gsd-code-fixer.compact.md — #4660: `[A-Z]?` at the padded_phase sink validator plus the comment and error message updated to the canonical grammar Emitted-Drift-Ack-Growth: execute-plan.md — #4660: `[A-Z]?` in the plan-filename phase extraction (6 bytes) Emitted-Drift-Ack-Growth: plan-phase.md — #4660: `[A-Z]?` in the --research-phase capture (6 bytes) Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NLtEbRc1Qfbe95HRMNqwp3 * chore(#4660): set changeset fragment pr to 4744 * chore: re-trigger Validate Branch Name The required check-branch context was cancelled on this head by the workflow's cancel-in-progress group when the changeset pr-field backfill push landed three seconds after the PR opened; no completed run exists for the current head, and a fork contributor cannot re-run it. Empty commit to re-run it. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01NLtEbRc1Qfbe95HRMNqwp3 --------- Co-authored-by: CI Rebase Check <ci@gsd-redux> Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com> Co-authored-by: Tom Boucher <trekkie@nomorestars.com>
321 lines
13 KiB
JavaScript
321 lines
13 KiB
JavaScript
'use strict';
|
|
|
|
/**
|
|
* #4568 (epic #4634) — six shell snippets embedded in workflow/agent markdown
|
|
* validate or extract phase numbers with the regex shape `[0-9]+(\.[0-9]+)?`
|
|
* (or its `\d` near-variant) — an optional SINGLE dotted segment. Any
|
|
* three-or-more-segment phase id (e.g. `23.1.2`, produced by a nested `phase
|
|
* insert`) is either hard-rejected or silently truncated to the wrong value.
|
|
* The canonical grammar in src/phase-id.cts already uses the unbounded form
|
|
* (`\d+(?:\.\d+)*`) — shell cannot import that module, so the fix is textual
|
|
* parity: widen `?` to `*` at each site.
|
|
*
|
|
* These tests are BEHAVIORAL: for each site, the actual regex/extraction
|
|
* line is read live off disk (via a narrow, anchored string search) and
|
|
* executed in a real bash subprocess — never hand-retyped — so the test
|
|
* breaks loudly if a future edit changes a site's shape instead of silently
|
|
* drifting from the real file.
|
|
*/
|
|
|
|
const { test, describe } = require('node:test');
|
|
const assert = require('node:assert/strict');
|
|
const fs = require('node:fs');
|
|
const path = require('node:path');
|
|
const { execFileSync } = require('node:child_process');
|
|
|
|
const TIMEOUT = 5000;
|
|
|
|
const CODE_REVIEW = path.join(__dirname, '..', 'gsd-core', 'workflows', 'code-review.md');
|
|
const CODE_REVIEW_FIX = path.join(__dirname, '..', 'gsd-core', 'workflows', 'code-review-fix.md');
|
|
const CODE_FIXER = path.join(__dirname, '..', 'agents', 'gsd-code-fixer.md');
|
|
const CODE_FIXER_COMPACT = path.join(__dirname, '..', 'agents', 'gsd-code-fixer.compact.md');
|
|
const EXECUTE_PLAN = path.join(__dirname, '..', 'gsd-core', 'workflows', 'execute-plan.md');
|
|
const PLAN_PHASE = path.join(__dirname, '..', 'gsd-core', 'workflows', 'plan-phase.md');
|
|
|
|
/**
|
|
* Pure: find the line containing `anchor` and pull the regex substring
|
|
* between `=~ ` and ` ]]` on it. Throws loudly if either the anchor or the
|
|
* pattern shape is not found, so a future rewrite of the site's surrounding
|
|
* code breaks this test instead of silently testing stale text.
|
|
*/
|
|
function extractAnchoredRegex(fileText, anchor) {
|
|
const lines = fileText.split('\n');
|
|
const line = lines.find((l) => l.includes(anchor));
|
|
assert.ok(line, `anchor not found: ${anchor}`);
|
|
const m = line.match(/=~\s+(\S+)\s+\]\]/);
|
|
assert.ok(m, `no "=~ <pattern> ]]" shape found on anchor line: ${line}`);
|
|
return m[1];
|
|
}
|
|
|
|
/**
|
|
* Pure: find the line containing `anchor` and pull the single-quoted
|
|
* `grep -oE '...'` pattern off it.
|
|
*/
|
|
function extractGrepPattern(fileText, anchor) {
|
|
const lines = fileText.split('\n');
|
|
const line = lines.find((l) => l.includes(anchor));
|
|
assert.ok(line, `anchor not found: ${anchor}`);
|
|
const m = line.match(/grep -oE '([^']+)'/);
|
|
assert.ok(m, `no grep -oE '...' shape found on anchor line: ${line}`);
|
|
return m[1];
|
|
}
|
|
|
|
/** Run a validating-site regex (bash `[[ =~ ]]`) against `value`, returning true/false. */
|
|
function matchesValidatingRegex(pattern, value) {
|
|
const script = `if [[ "$TEST_INPUT" =~ ${pattern} ]]; then echo MATCH; else echo NOMATCH; fi`;
|
|
const out = execFileSync('bash', [], {
|
|
input: script,
|
|
encoding: 'utf8',
|
|
timeout: TIMEOUT,
|
|
env: { ...process.env, TEST_INPUT: value },
|
|
}).trim();
|
|
return out === 'MATCH';
|
|
}
|
|
|
|
describe('#4568 — validating sites accept N-segment phase ids and still reject injection', () => {
|
|
const sites = [
|
|
{ name: 'code-review.md', file: CODE_REVIEW, anchor: 'if ! [[ "$PADDED_PHASE" =~ ' },
|
|
{ name: 'code-review-fix.md', file: CODE_REVIEW_FIX, anchor: 'if ! [[ "$PADDED_PHASE" =~ ' },
|
|
{ name: 'gsd-code-fixer.md', file: CODE_FIXER, anchor: 'if ! [[ "$padded_phase" =~ ' },
|
|
{ name: 'gsd-code-fixer.compact.md', file: CODE_FIXER_COMPACT, anchor: 'if ! [[ "$padded_phase" =~ ' },
|
|
];
|
|
|
|
for (const site of sites) {
|
|
describe(site.name, () => {
|
|
const text = fs.readFileSync(site.file, 'utf8');
|
|
const pattern = extractAnchoredRegex(text, site.anchor);
|
|
|
|
test('regression control: 1-segment id (6) matches', () => {
|
|
assert.equal(matchesValidatingRegex(pattern, '6'), true);
|
|
});
|
|
|
|
test('regression control: 2-segment id (36.14) matches', () => {
|
|
assert.equal(matchesValidatingRegex(pattern, '36.14'), true);
|
|
});
|
|
|
|
test('N-segment id (23.1.2) matches (fails before the fix)', () => {
|
|
assert.equal(matchesValidatingRegex(pattern, '23.1.2'), true);
|
|
});
|
|
|
|
test('path-traversal injection (../1) is rejected', () => {
|
|
assert.equal(matchesValidatingRegex(pattern, '../1'), false);
|
|
});
|
|
|
|
test('shell-metacharacter injection (1; rm -rf /) is rejected', () => {
|
|
assert.equal(matchesValidatingRegex(pattern, '1; rm -rf /'), false);
|
|
});
|
|
|
|
test('empty string is rejected', () => {
|
|
assert.equal(matchesValidatingRegex(pattern, ''), false);
|
|
});
|
|
});
|
|
}
|
|
});
|
|
|
|
describe('#4568 — execute-plan.md extracts the full N-segment phase from a plan filename', () => {
|
|
const text = fs.readFileSync(EXECUTE_PLAN, 'utf8');
|
|
const pattern = extractGrepPattern(text, 'grep -oE');
|
|
|
|
function extractPhase(planPath) {
|
|
const script = `echo "$PLAN_PATH" | grep -oE '${pattern}'`;
|
|
let out;
|
|
try {
|
|
out = execFileSync('bash', [], {
|
|
input: script,
|
|
encoding: 'utf8',
|
|
timeout: TIMEOUT,
|
|
env: { ...process.env, PLAN_PATH: planPath },
|
|
}).trim();
|
|
} catch {
|
|
out = '';
|
|
}
|
|
return out;
|
|
}
|
|
|
|
test('regression control: 1-segment plan filename extracts correctly', () => {
|
|
assert.equal(extractPhase('/x/06-01-PLAN.md'), '06-01');
|
|
});
|
|
|
|
test('regression control: 2-segment plan filename extracts correctly', () => {
|
|
assert.equal(extractPhase('/x/36.14-01-PLAN.md'), '36.14-01');
|
|
});
|
|
|
|
test('N-segment plan filename extracts the FULL phase, not a truncated one (fails before the fix)', () => {
|
|
assert.equal(extractPhase('/x/23.1.2-01-PLAN.md'), '23.1.2-01');
|
|
});
|
|
});
|
|
|
|
describe('#4568 — plan-phase.md captures the full N-segment --research-phase value', () => {
|
|
const text = fs.readFileSync(PLAN_PHASE, 'utf8');
|
|
const pattern = extractAnchoredRegex(text, '=~ --research-phase[[:space:]]+(');
|
|
|
|
function captureResearchPhase(args) {
|
|
const script = [
|
|
'if [[ "$ARGUMENTS" =~ ' + pattern + ' ]]; then',
|
|
' echo "${BASH_REMATCH[1]}"',
|
|
'else',
|
|
' echo NOMATCH',
|
|
'fi',
|
|
].join('\n');
|
|
return execFileSync('bash', [], {
|
|
input: script,
|
|
encoding: 'utf8',
|
|
timeout: TIMEOUT,
|
|
env: { ...process.env, ARGUMENTS: args },
|
|
}).trim();
|
|
}
|
|
|
|
test('regression control: 1-segment --research-phase captures correctly', () => {
|
|
assert.equal(captureResearchPhase('--research-phase 6'), '6');
|
|
});
|
|
|
|
test('regression control: 2-segment --research-phase captures correctly', () => {
|
|
assert.equal(captureResearchPhase('--research-phase 36.14'), '36.14');
|
|
});
|
|
|
|
test('N-segment --research-phase captures the FULL value, not a truncated one (fails before the fix)', () => {
|
|
assert.equal(captureResearchPhase('--research-phase 23.1.2'), '23.1.2');
|
|
});
|
|
});
|
|
|
|
// ---------------------------------------------------------------------------
|
|
// #4660 — the LETTER axis. #4568 widened the six sites on the segment-count
|
|
// axis only; the canonical grammar also admits an optional single uppercase
|
|
// letter after the leading digits (`12A`, `3A`, `23A.1.2` — a documented
|
|
// phase-number shape in CONFIGURATION.md, relied on by renameIntegerPhases in
|
|
// src/phase.cts). These tests prove each site's live pattern and the canonical
|
|
// source AGREE on that axis, in both directions, rather than each merely
|
|
// "looking right" in isolation.
|
|
// ---------------------------------------------------------------------------
|
|
|
|
// The canonical grammar is read from the committed bin/lib mirror the other
|
|
// grammar tests use (shell cannot import it; the test can).
|
|
const { PHASE_NUMBER_TOKEN_SOURCE } = require('../gsd-core/bin/lib/phase-id.cjs');
|
|
const CANONICAL_ANCHORED = new RegExp('^(?:' + PHASE_NUMBER_TOKEN_SOURCE + ')$');
|
|
|
|
// Inputs the canonical grammar ACCEPTS. `03A` is what `normalizePhaseName('3A')`
|
|
// emits, i.e. the real `padded_phase` the four validating sites receive from
|
|
// `init`; the bare forms are what a user types or names a directory with.
|
|
const LETTER_ACCEPT = ['12A', '3A', '03A', '23A.1.2'];
|
|
// Inputs the canonical grammar REJECTS on the same axis — a parity test that
|
|
// only checks accepts would pass against `.*`. Lowercase is refused because
|
|
// the canonical source is case-sensitive `[A-Z]` (the case-flexible variant
|
|
// is a separate, deliberately distinct axis — see phase-id.cts).
|
|
const LETTER_REJECT = ['3a', '3AB', 'A3', '3A.', '3.A', '3A-1'];
|
|
|
|
describe('#4660 — canonical grammar fixture agrees with the inputs this file uses', () => {
|
|
for (const v of LETTER_ACCEPT) {
|
|
test(`canonical accepts ${v}`, () => {
|
|
assert.equal(CANONICAL_ANCHORED.test(v), true);
|
|
});
|
|
}
|
|
for (const v of LETTER_REJECT) {
|
|
test(`canonical rejects ${v}`, () => {
|
|
assert.equal(CANONICAL_ANCHORED.test(v), false);
|
|
});
|
|
}
|
|
});
|
|
|
|
describe('#4660 — validating sites agree with the canonical grammar on the letter axis', () => {
|
|
const sites = [
|
|
{ name: 'code-review.md', file: CODE_REVIEW, anchor: 'if ! [[ "$PADDED_PHASE" =~ ' },
|
|
{ name: 'code-review-fix.md', file: CODE_REVIEW_FIX, anchor: 'if ! [[ "$PADDED_PHASE" =~ ' },
|
|
{ name: 'gsd-code-fixer.md', file: CODE_FIXER, anchor: 'if ! [[ "$padded_phase" =~ ' },
|
|
{ name: 'gsd-code-fixer.compact.md', file: CODE_FIXER_COMPACT, anchor: 'if ! [[ "$padded_phase" =~ ' },
|
|
];
|
|
|
|
for (const site of sites) {
|
|
describe(site.name, () => {
|
|
const text = fs.readFileSync(site.file, 'utf8');
|
|
const pattern = extractAnchoredRegex(text, site.anchor);
|
|
|
|
for (const v of LETTER_ACCEPT) {
|
|
test(`letter-suffixed id ${v} matches (fails before the fix)`, () => {
|
|
assert.equal(matchesValidatingRegex(pattern, v), true);
|
|
assert.equal(matchesValidatingRegex(pattern, v), CANONICAL_ANCHORED.test(v));
|
|
});
|
|
}
|
|
|
|
for (const v of LETTER_REJECT) {
|
|
test(`canonical-invalid ${v} is still rejected (parity, not a blanket widening)`, () => {
|
|
assert.equal(matchesValidatingRegex(pattern, v), false);
|
|
assert.equal(matchesValidatingRegex(pattern, v), CANONICAL_ANCHORED.test(v));
|
|
});
|
|
}
|
|
});
|
|
}
|
|
});
|
|
|
|
describe('#4660 — execute-plan.md extracts the full letter-suffixed phase from a plan filename', () => {
|
|
const text = fs.readFileSync(EXECUTE_PLAN, 'utf8');
|
|
const pattern = extractGrepPattern(text, 'grep -oE');
|
|
|
|
function extractPhase(planPath) {
|
|
const script = `echo "$PLAN_PATH" | grep -oE '${pattern}'`;
|
|
let out;
|
|
try {
|
|
out = execFileSync('bash', [], {
|
|
input: script,
|
|
encoding: 'utf8',
|
|
timeout: TIMEOUT,
|
|
env: { ...process.env, PLAN_PATH: planPath },
|
|
}).trim();
|
|
} catch {
|
|
out = '';
|
|
}
|
|
return out;
|
|
}
|
|
|
|
// Before the fix a letter-suffixed filename either extracts NOTHING (the
|
|
// digit run is followed by the letter, so `-[0-9]+` never attaches) or the
|
|
// wrong tail (`23A.1.2-01` → `1.2-01`). Both are silent mis-extractions.
|
|
for (const [planPath, expected] of [
|
|
['/x/12A-01-PLAN.md', '12A-01'],
|
|
['/x/03A-02-PLAN.md', '03A-02'],
|
|
['/x/23A.1.2-01-PLAN.md', '23A.1.2-01'],
|
|
]) {
|
|
test(`${planPath} extracts ${expected} (fails before the fix)`, () => {
|
|
const got = extractPhase(planPath);
|
|
assert.equal(got, expected);
|
|
// The phase half of the extraction is canonical-valid — parity with src/phase-id.cts.
|
|
assert.equal(CANONICAL_ANCHORED.test(got.replace(/-\d+$/, '')), true);
|
|
});
|
|
}
|
|
|
|
test('regression control: the letter class is admitted at the PHASE position only (plan numbers stay digit-only)', () => {
|
|
// `12A-B1`: the plan half must start with a digit, so nothing attaches to
|
|
// `12A-` and the digit-only tail `1` has no `-[0-9]+` after it either.
|
|
assert.equal(extractPhase('/x/12A-B1-PLAN.md'), '');
|
|
});
|
|
});
|
|
|
|
describe('#4660 — plan-phase.md captures the full letter-suffixed --research-phase value', () => {
|
|
const text = fs.readFileSync(PLAN_PHASE, 'utf8');
|
|
const pattern = extractAnchoredRegex(text, '=~ --research-phase[[:space:]]+(');
|
|
|
|
function captureResearchPhase(args) {
|
|
const script = [
|
|
'if [[ "$ARGUMENTS" =~ ' + pattern + ' ]]; then',
|
|
' echo "${BASH_REMATCH[1]}"',
|
|
'else',
|
|
' echo NOMATCH',
|
|
'fi',
|
|
].join('\n');
|
|
return execFileSync('bash', [], {
|
|
input: script,
|
|
encoding: 'utf8',
|
|
timeout: TIMEOUT,
|
|
env: { ...process.env, ARGUMENTS: args },
|
|
}).trim();
|
|
}
|
|
|
|
// Before the fix the capture stops at the digit boundary: `12A` → `12`.
|
|
for (const v of ['12A', '3A', '23A.1.2']) {
|
|
test(`--research-phase ${v} captures ${v}, not its digit prefix (fails before the fix)`, () => {
|
|
const got = captureResearchPhase(`--research-phase ${v}`);
|
|
assert.equal(got, v);
|
|
assert.equal(CANONICAL_ANCHORED.test(got), true);
|
|
});
|
|
}
|
|
});
|