Files
msd-core/tests/continuation-grammar-parity.test.cjs
JusticeWay 77374cfc32 fix(#2528): resolve digit-leading phase directories by bare number (#2559)
* fix(#2528): resolve digit-slug phase dirs by bare number — tokenizer rewind, shared bare-integer fallback, resolution-path parity gate

extractPhaseToken welded 2-digit slug words onto the phase token (phase 10
named "24/7 Autonomy" -> dir 10-24-7 -> token 10-24), making digit-prefixed
phase names unresolvable by bare number across every phase verb.

- phase-id: continuation segments must be the PURE 2-digit zero-padded form
  the write side emits; a 1-digit terminator rewinds the absorbed run
  (10-24-7 -> 10) while >=2-digit terminators keep the locked #2232
  round-trip (14-06-2026-photos -> 14-06).
- phase-id: new matchPhaseDirs owner — primary exact-token match plus a
  bare-integer leading-digit-run fallback for shapes the tokenizer cannot
  rewind (05-80-20-cleanup); collisions stay #2237-loud.
- locator/find-phase/phase-plan-index all delegate selection to the owner;
  plan-index gains the previously missing multi-match guard.
- tests: #2528 unit + fast-check metamorphic blocks; new 9-scenario
  resolution-path parity gate across all three paths.

Fixes #2528

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* chore(#2528): add changeset for PR #2559

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(#2528): align validation token grammar

* fix: address phase token review

* fix: restore phase grammar parity for numeric slugs

* docs: document digit-leading phase resolution

* docs: clarify ambiguous phase resolution behavior

* docs: register canonical phase directory selectors

* fix: align prefixed deep phase token parsing

* fix(#2528): route the fourth resolution site through matchPhaseDirs

Review BLOCKER. smart-entry.cts::detectVerifyFailed resolved the current
phase's directory with its own `.find(phaseTokenMatches)` and never
reached the shared selection, so the bare-integer-fallback family the
issue names — `05-80-20-cleanup`, `30-12-factor-refactor` — resolved
nowhere. The miss is silent by construction: an unresolved phase reports
"not failed", which is byte-identical to a healthy one, so a failed
verification simply never surfaced in /gsd or /gsd:progress.

`entries` is already sorted and matchPhaseDirs filters without
reordering, so matches[0] reproduces the previous selection exactly
wherever the old code resolved at all.

Wiring it into phase-resolution-parity.test.cjs as a fourth path then
exposed a second, older defect in the same function: phaseTokenFromDirName
shape-probed the UNSTRIPPED token, so a project-code-prefixed directory
(`MEM-05-…`, tokenizing to `MEM-05-80-20`) failed the leading-digit test
and was dropped before any resolution ran — every phase in a
project-coded plan was invisible to this check. The probe now runs on the
stripped token; the returned value is unchanged, so the comparePhaseNum
sort is untouched.

Path 4 has no JSON surface to compare, so the gate observes selection
indirectly: plant the failing artifact in exactly one directory and a
passing one everywhere else, then read the boolean. Reverting either fix
turns 5 of the 10 corpus scenarios red.

* refactor(#2528): collapse the duplicated extractCanonicalPlanId

Review MAJOR. The function existed as two independent, byte-identical
copies — src/core-utils.cts and src/phase.cts — and this PR had to patch
BOTH with the same single-digit-slug rewind rule. That is the generative
fix divergence CLAUDE.md names, and only the core-utils copy was under
test, so a future one-sided patch would have silently split plan-id
canonicalization between the plan listing and everything else.

Removed rather than parity-tested: core-utils was already the leaf owner
and already exported it, and phase.cts already imported that module, so
there is no second surface left for a parity test to police.

* test(#2528): pin matchPhaseDirs at the digit-width boundaries

Review MAJOR. The bare-integer fallback's correctness rests entirely on
capturing each directory's whole leading digit run before the zero-strip
compare; a regex that stopped short would turn every query into a prefix
match, and "1" would claim 10, 100, and 12 alike. The existing coverage
was example-based and never touched that boundary.

Adds the explicit 9/10 and 1/10/100 cases — including the forms where
only the wider directories exist, so an exact-width neighbour cannot
satisfy the assertion — plus a fast-check property over arbitrary
distinct leading runs. The property is stated as an invariant on the
result (every returned directory's leading run IS the query) rather than
an expected list, so it covers primary and fallback matches alike and
cannot be satisfied by reimplementing the selection in the test.

Both fail when the fallback regex is degraded to a prefix match.

* fix(#2528): route the remaining eight consumers through matchPhaseDirs

phaseTokenMatches had eight consumers left that each rebuilt the directory
selection around it by hand: phases-list, next-decimal, phase-remove, the
W021 milestone-consistency check, schema-drift, the init-manager overview,
milestone-complete's disk check, and roadmap analyze. Every one of them
reproduced the reported symptom in full after the tokenizer was fixed.

None of them derives a displayed phase number from the matched directory,
so none needs phaseNumberForMatch; the change at each site is the
selection and nothing else. matchPhaseDirs filters without reordering, so
matches[0] reproduces the prior .find() choice wherever the old code
resolved at all.

phaseTokenMatches now has no call sites outside phase-id.cts. It stays
exported as the primitive matchPhaseDirs is built from and as a pinned
canonical surface, but no consumer reaches past the owner to it.

* test(#2528): extend the parity gate to the migrated consumers

Each of the eight is observed through the surface a user sees, not
through the matcher, with a no-directory control so the assertions cannot
be satisfied by a consumer that resolves unconditionally. init-manager
and roadmap-analyze are additionally asserted to agree with each other.

* refactor(#2528): own the case-flexible phase grammar and the leading-digit-run fragment

validate.cts derived its case-flexible regex sources by running
`replaceAll('A-Z', 'A-Za-z')` over two constants exported by phase-id.cts.
That passes lint-phase-id-drift.cjs — there is no literal copy of the
grammar — but it depends on the owner rendering that exact substring. The
day phase-id.cts expresses the same class any other way the replaceAll
silently no-ops and validate.cts narrows to uppercase-only. The failure
mode is a NON-match, so nothing throws and no uppercase-only fixture
notices. Both variants are now derived once, beside the sources they
widen, and imported.

Also names the leading digit run the bare-integer fallback selects on.
It was spelled `/^(\d+)(?:-|$)/` where the fallback filters and `/^\d+/`
where phaseNumberForMatch reads the number back off the winner; selecting
on one run and displaying another would resolve a directory and then label
it with a number that never matched it.

* fix(#2528): refuse to remove a phase when two directories claim its number

cmdPhaseRemove was the only migrated site taking matches[0] with no
multi-match guard. Every sibling resolution path returns ambiguous_matches
and refuses to choose; this one is the DESTRUCTIVE path, so choosing
silently is strictly worse than anywhere else. With 05-80-20-a and
05-90-till-late on disk, `phase remove 5 --force` deleted one of them and
renumbered every phase after it — where the base resolved nothing, deleted
nothing, and the corpus in tests/phase-resolution-parity.test.cjs already
declared that exact input ambiguous.

The refusal is emitted before any file is touched and carries both
candidates. CONSUMER_SCENARIOS could not express the case — every row is
binary, resolving to one directory or to none — so the gate gains a
dedicated ambiguous test. It asserts on the filesystem, not only on the
reported directory_deleted: a null printed after an rmSync would satisfy
every other check.

* fix(#2528): pair digit-leading phase directories with their roadmap phase in validate health

W006/W007 are the ninth site of this bug class and the one a
`phaseTokenMatches` grep could never surface: they resolve roadmap↔disk by
intersecting TOKEN SETS, which is a dir→token labelling rather than the
query→dir selection matchPhaseDirs owns. On the canonical fixture the
label is wrong in both directions at once, so `validate health` reported
"Phase 5 in ROADMAP.md but no directory on disk" AND "Phase 05-80-20
exists on disk but not in ROADMAP.md" for the same directory.

collectDiskPhases now keeps the directory names behind each token, so
W006 can ask the canonical matcher whether a roadmap phase resolves to a
real directory, and W007 — which iterates directories and therefore has no
query to resolve — gets the inverse mapping it never had: a directory is
claimed when some roadmap phase resolves to it.

Both checks are additive: the token intersection still decides every shape
it already decided, and the resolution can only REMOVE a warning. The
regression test carries controls in the other direction — a roadmap phase
with no directory must still raise W006, an unclaimed directory must still
raise W007 — so it cannot be satisfied by a check that stopped reporting.

* docs(#2528): state and pin the directory-side scope of the bare-integer fallback

The matchPhaseDirs docblock claimed deep-decomposition lookups were
untouched. That is true of the QUERY side only — no non-bare query enters
the fallback — but the DIRECTORY side is what changed classification: a
bare `5` now reaches a lone `05-01-auth` and resolves it (phase_number
"05", phase_name "01-auth") where the base found nothing.

The widening is irreducible from directory names alone. `05-01-auth`
(sub-phase 5.1) and `30-12-factor-refactor` (phase 30 named "12-Factor
Refactor") are the same `NN-NN-<slug>` shape, and the discriminator that
would separate them — "is the second segment a valid decimal sub-phase" —
accepts `5.1` and `30.12` equally. Any rule strong enough to exclude the
first excludes the second, which is the defect #2528 exists to fix. So the
tie is broken in favour of resolving, the docblock now says so, and the
consequence is bounded where it matters: two such directories are two
matches, and every caller (including phase remove) refuses to choose.

Pins both directions, since nothing observed the directory side before.

* fix(#2528): count surviving phases by identity in phase remove's STATE resync

#2640 landed on `next` while this branch was open. Its STATE.md phase-count
resync re-derives "which directory was removed" from the query with
`phaseTokenMatches`, which is the tenth site of this issue's defect: the
bare-integer fallback resolves `05-80-20-cleanup` for query `5`, but the
token predicate does not, so the just-deleted directory is counted as still
present and the written `Total Phases` is one too high.

`targetDir` already IS the directory that was removed, and the block is gated
on it being non-null, so identity answers the question exactly — which is also
what the comment above the filter already claimed it did. This keeps
`phaseTokenMatches` out of `phase.cts` rather than re-importing it to satisfy
one call site: the module's public surface should not grow for a question that
does not need re-derivation.

Pinned in the parity gate with a control on a directory the tokenizer reads
correctly, so the assertion is about the digit-leading shape and not about the
counting rule changing for everything.

* fix(#2528): let the resolution layer own the digit-leading slug family alone

The tokenizer rewind this fix carried — pop the last absorbed continuation when
the segment that stopped the scan is a bare single digit — reads
"10-24-7-autonomy" (phase 10 named "24/7 Autonomy") correctly and silently
re-reads "10-24-7-zip" (sub-phase 10.24 named "7-Zip Integration") from "10-24"
to "10". The two names are string-identical in shape, so no local signal
separates them; the rule traded the reported ambiguity for the symmetric one a
level down, on a 15-caller chokepoint whose output also feeds query-less
derivations (STATE.md phase counts, W007, the #2562 key surface). A well-formed
sub-phase directory became unresolvable by its own id — the very symptom #2528
was filed about.

It also bought nothing. The bare-integer fallback in matchPhaseDirs already
resolves "10-24-7-autonomy" for query "10" whatever the token is: no primary
match, bare query, leading digit run "10". The reported case was covered twice,
by two rules, and the two disagreed about the case nobody reported.

So the rewind is removed rather than narrowed, in the tokenizer and in the five
surfaces kept in lockstep with it (BRACKET_PHASE_TOKEN_SOURCE,
PHASE_TOKEN_FROM_DIR_RE, canonicalPlanStem's pair grammar and its collision
branch, roadmap-parser's numericRe, extractCanonicalPlanId), together with the
SINGLE_DIGIT_RUN_SEGMENT_SOURCE owner constant they shared. Disambiguation now
lives only where a QUERY exists to disambiguate against, which is the same
bounded mechanism the "05-80-20-cleanup" shape already used.

Measured, not argued: over 29800 generated directory names, extractPhaseToken is
byte-identical to `next` on every input except the lowercase-continuation class
("01-20a", "05-80-20-25abc") — a rule about the segment itself, not a guess about
its neighbour.

Both readings now stay reachable by their own ids:
  matchPhaseDirs(['10-24-7-autonomy'], '10')    -> the dir   (fallback)
  matchPhaseDirs(['10-24-7-zip'],      '10')    -> the dir   (fallback)
  matchPhaseDirs(['10-24-7-zip'],      '10-24') -> the dir   (primary)

* test(#2528): pin the one-continuation boundary the rewind had no coverage for

The regressing shape was invisible to the suite by construction, not by luck:
the deep-rewind property built its cases from `continuationArb` with
`minLength: 2`, so it never exercised the single-continuation case — exactly one
genuine sub-phase level before a digit-leading slug — and every hand-written
fixture used the ambiguous shape only where "phase-plus-slug" was the intended
reading.

`continuationArb` is now `minLength: 1` and the property states the invariant
instead of the old rule: for any prefix, phase, 1-5 continuations and any
one-digit terminator, the token equals the FULL continuation run on both the
imperative and the regex surface, and `matchPhaseDirs([dir], token)` returns that
dir. That third assertion is the one that catches the class on its own — the old
behaviour made a well-formed directory unresolvable by its own id, which is a
property, not a fixture.

Around it: "10-24-7-zip" and "10-24-3d-printer" now sit beside
"10-24-7-autonomy" everywhere the family is pinned, so the two readings can never
diverge again; the 24/7 metamorphic property asserts the RESOLUTION result rather
than the token (the token is precisely the part no surface may decide); the
end-to-end parity corpus gains "a sub-phase with a digit-leading slug resolves by
its full id" across all four resolution paths; and the milestone-scoping residual
is pinned in three directions rather than left to prose.

Mutation: re-inserting the rewind and rebuilding turns 9 tests red, the
`minLength: 1` property first, and nothing else. Build success checked separately
(build:lib reports 0 `error TS`), so the mutation reached the artifact under test.

* test(#2528): pin the #2946 guard against digit-leading phase directories

The #2946 fix makes the milestone-complete unstarted-phase guard run
unconditionally, so whether it fires now rides entirely on the
directory-resolution owner this PR replaces. Two cases, both with STATE.md
carrying no `milestone:` field so the #2946 path is the one exercised:

  - ROADMAP Phase 5, disk `05-80-20-cleanup` → guard must stay silent.
    RED on next (fail-closed: the guard blocks a legitimate one-way-door
    operation because phaseTokenMatches resolves neither 05 nor 80 for
    that directory).
  - ROADMAP Phase 80, same directory → guard must still fire. Green on
    both sides; it pins the fail-open direction against a future widening
    of the matcher.

* fix(#3175): stop the injection scanner reading RegExp.exec as code execution

The apostrophe fix in 27aa40f6 replaced ["\x27] with a real ["'] class.
The old class never contained an apostrophe at all (POSIX bracket
expressions do not honour backslash escapes, so it was the set ", \, x,
2, 7), so only exec(" matched. Single-quoted method calls now match for
the first time, and RegExp.prototype.exec takes a subject string, not
code: any PR touching a file that tests a regex goes red. On next, six
files match the scanner's own pattern across 16 method calls.

A plain [^[:alnum:]] boundary cannot separate the two forms because . is
not alnum, so exec gets [^[:alnum:].] and the command-execution vector
moves to a dedicated member-call pattern. Bare exec('rm -rf /'),
cp.exec(...) and child_process.exec(...) all still fire.

Mutation: reverting the boundary reds 1 test and only it; removing the
member-call pattern reds the 2 non-weakening tests and only them.

Co-Authored-By: Claude <noreply@anthropic.com>

* fix(#2528): keep exec( detection receiver-blind, allowlist the two grammar suites

The left boundary [^[:alnum:].] added in 58a7b560 excluded a preceding dot,
which dropped every member-position .exec('…') from the scanner. The follow-up
receiver pattern only restored three literal spellings (child_process,
childProcess, cp), so require('child_process').exec('…') — the most common Node
spelling of the vector this pattern exists to catch — became invisible, along
with any opaque receiver (conn.exec, shelljs.exec).

Revert the pattern to its receiver-blind form and handle the RegExp.prototype
.exec false positive where the script already handles this class: per-file
ALLOWLIST entries for the two phase-token grammar suites. Mutation-checked —
removing the two entries reds exactly those two files and nothing else.

The four assertions written around the old patterns are replaced by a
table-driven set covering all six spellings, including the three the narrowed
pattern silently lost.

Co-Authored-By: Claude <noreply@anthropic.com>

* docs(#2528): pin the three undeclared grammar edges, correct the ambiguity claim

Review round 10 asked for declaration, not behavior change, on four items. All
four have zero production consumers or preserve their caller's prior rule, so
each is pinned as a test or corrected in prose rather than reverted.

- BRACKET_PHASE_TOKEN_SOURCE: the (?=-|$) terminator is what keeps the bracket
  read path in step with the other surfaces, and it costs the display shapes
  (`05.03: Title`, `12A: X`, `05.03]` no longer tokenize). Pinned so widening
  the terminator class is a deliberate act rather than a lookahead deletion.
- canonicalPlanStem: uppercase plan suffixes still strip, lowercase and dotted
  sub-plans now fall through. Dead export; pinned as a decision on record.
- getMilestonePhaseFilter: `12A-01-foo` now yields `12A-01`, matching what
  `12-01-foo` has always yielded. The letter suffix was the only reason a
  sub-phase directory folded into its parent phase's milestone window; the two
  shapes now agree. Not named in the review — found auditing the same commit.
- matchPhaseDirs docblock claimed every caller refuses on multi-match. Four do;
  five take matches[0]. Replaced the claim with the actual two-tier policy and
  the honest caveat that the bare fallback makes multi-match newly reachable
  for queries that previously found nothing.

Co-Authored-By: Claude <noreply@anthropic.com>

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Tom Boucher <trekkie@nomorestars.com>
2026-08-12 20:45:04 -04:00

470 lines
23 KiB
JavaScript

'use strict';
/**
* continuation-grammar-parity.test.cjs — DEFECT.GENERATIVE-FIX parity gate (#2232)
*
* Proves that the phase-token CONTINUATION-segment grammar has a single owner
* (`phase-id.cjs: PHASE_CONTINUATION_SEGMENT_SOURCE` / `isPhaseContinuationSegment`)
* and that every consuming surface agrees with it on a shared digit-width corpus.
*
* Why this gate exists: #2043 fixed the same class of bug by hand-editing five
* independent `/^\d{2,}/` copies; #2232 is the residual that survived because a
* later reader could not tell the five copies were one rule. The rule is now
* single-sourced, but a regex literal is easy to re-introduce and
* `scripts/lint-phase-id-drift.cjs` only guards the OTHER constant
* (`PHASE_NUMBER_TOKEN_SOURCE`) — a bare `\d{2,}` re-derivation would pass lint
* and CI silently. This test is the behavioral backstop: it fails the moment any
* consuming surface disagrees with the owner about which continuation widths are
* absorbed.
*
* Contract: for every digit-width in the corpus, each surface's notion of
* "is this segment absorbed as a continuation?" MUST equal
* `isPhaseContinuationSegment(segment)`.
*
* Surfaces covered (the five #2043 sites, plus the #612 bracket read path):
* 1. phase-id.cjs extractPhaseToken
* 2. validate.cjs PHASE_TOKEN_FROM_DIR_RE
* 3. validate.cjs canonicalPlanStem
* 4. core-utils.cjs extractCanonicalPlanId (paired plan component)
* 5. roadmap-parser.cjs getMilestonePhaseFilter → isDirInMilestone (hyphenated mode)
* 6. phase-id.cjs BRACKET_PHASE_TOKEN_SOURCE (slug-adjacent position only —
* see the divergence block at the foot of this file)
*/
const { test, describe } = require('node:test');
const assert = require('node:assert/strict');
const fs = require('node:fs');
const path = require('node:path');
const fc = require('fast-check');
const phaseId = require('../gsd-core/bin/lib/phase-id.cjs');
const validate = require('../gsd-core/bin/lib/validate.cjs');
const coreUtils = require('../gsd-core/bin/lib/core-utils.cjs');
const { getMilestonePhaseFilter } = require('../gsd-core/bin/lib/roadmap-parser.cjs');
const { createTempProject, cleanup } = require('./helpers.cjs');
// The shared digit-width corpus. `absorbed` is stated independently of the
// implementation (it is the LOCKED POLICY, not a mirror of the regex): a
// continuation is exactly the 2-digit zero-padded form getPhaseDirFromPhaseId
// emits. 1-digit is a slug word (#2043); ≥3-digit is a slug word (#2232 — a
// year/count/version).
const WIDTH_CORPUS = [
{ width: 1, seg: '6', absorbed: false, note: '#2043 single-digit slug word' },
{ width: 2, seg: '02', absorbed: true, note: 'the zero-padded sub-phase — the cap' },
{ width: 3, seg: '100', absorbed: false, note: '#2232 limit+1 (policy: ≥100 out of grammar)' },
{ width: 4, seg: '2026', absorbed: false, note: '#2232 the reported case (a year)' },
{ width: 5, seg: '12345', absorbed: false, note: '#2232 far side of the cap' },
];
describe('#2232 continuation-grammar parity — owner vs. corpus', () => {
test('the owner (isPhaseContinuationSegment) matches the locked policy', () => {
for (const { seg, absorbed, note } of WIDTH_CORPUS) {
assert.strictEqual(
phaseId.isPhaseContinuationSegment(seg),
absorbed,
`isPhaseContinuationSegment(${JSON.stringify(seg)}) must be ${absorbed} — ${note}`,
);
}
});
test('PHASE_CONTINUATION_SEGMENT_SOURCE is exported and is the exactly-2 grammar', () => {
assert.strictEqual(typeof phaseId.PHASE_CONTINUATION_SEGMENT_SOURCE, 'string');
// Anchored at both ends so a consuming site can embed it verbatim.
const re = new RegExp(`^${phaseId.PHASE_CONTINUATION_SEGMENT_SOURCE}$`);
assert.ok(re.test('02'), 'the 2-digit form must match');
assert.ok(!re.test('2026'), 'a 4-digit run must not match');
assert.ok(!re.test('6'), 'a 1-digit run must not match');
assert.ok(!re.test('10x'), 'a digit-plus-letter slug word must not match');
});
});
describe('#2232 continuation-grammar parity — every consuming surface agrees', () => {
for (const { seg, absorbed, note } of WIDTH_CORPUS) {
test(`width ${seg.length} (${JSON.stringify(seg)}): all surfaces agree absorbed=${absorbed} — ${note}`, () => {
const owner = phaseId.isPhaseContinuationSegment(seg);
assert.strictEqual(owner, absorbed, 'precondition: owner matches policy');
// ── Surface 1: extractPhaseToken ────────────────────────────────────
const dir = `14-${seg}-photos-performance`;
assert.strictEqual(
phaseId.extractPhaseToken(dir) === `14-${seg}`,
owner,
`extractPhaseToken(${JSON.stringify(dir)}) diverged from the owner`,
);
// ── Surface 2: validate PHASE_TOKEN_FROM_DIR_RE ─────────────────────
const reToken = validate.PHASE_TOKEN_FROM_DIR_RE.exec(dir)?.[1];
assert.strictEqual(
reToken === `14-${seg}`,
owner,
`PHASE_TOKEN_FROM_DIR_RE on ${JSON.stringify(dir)} gave ${JSON.stringify(reToken)} — diverged from the owner`,
);
// ── Surface 3: validate canonicalPlanStem ───────────────────────────
const stem = `14-${seg}-photos-performance`;
assert.strictEqual(
validate.canonicalPlanStem(stem) === `14-${seg}`,
owner,
`canonicalPlanStem(${JSON.stringify(stem)}) diverged from the owner`,
);
// ── Surface 4: core-utils extractCanonicalPlanId (paired component) ──
const planFile = `14-${seg}-photos-performance-PLAN.md`;
assert.strictEqual(
coreUtils.extractCanonicalPlanId(planFile) === `14-${seg}`,
owner,
`extractCanonicalPlanId(${JSON.stringify(planFile)}) diverged from the owner`,
);
// ── Surface 6: #612 BRACKET_PHASE_TOKEN_SOURCE (slug-adjacent position) ──
// The bracket run is MM-PP[.SS][-LL]; `-LL` is the only position a slug
// word can collide with, so it is the position #2232 owns. Same shape as
// surface 1 with the bracket's extra milestone level: `01-14-<seg>-slug…`
// puts <seg> at dash-2, exactly where a year over-collected before.
const bracketDir = `01-14-${seg}-photos-performance`;
const bracketToken = bracketDir.match(new RegExp(phaseId.BRACKET_PHASE_TOKEN_SOURCE))?.[0];
assert.strictEqual(
bracketToken === `01-14-${seg}`,
owner,
`BRACKET_PHASE_TOKEN_SOURCE on ${JSON.stringify(bracketDir)} collected ` +
`${JSON.stringify(bracketToken)} — diverged from the owner at the slug-adjacent position`,
);
});
}
test('#2528: regex token extraction agrees on the literal reading at slug boundaries', () => {
const cases = [
// The reported shape and its indistinguishable twin read IDENTICALLY: no
// surface may guess which of the two a `NN-NN-<digit>-…` name is, because
// nothing in the name says. Phase 10 named "24/7 Autonomy" is reached by
// the resolution-layer fallback (see phase-id.test.cjs), NOT by the
// tokenizer re-reading its name.
['10-24-7-autonomy', '10-24'],
['10-24-7-zip', '10-24'],
['05-80-20-25abc', '05-80-20'],
['14-06-2026-photos-and-performance', '14-06'],
['14-10x-growth', '14'],
];
for (const [dir, expected] of cases) {
assert.strictEqual(phaseId.extractPhaseToken(dir), expected);
assert.strictEqual(
validate.PHASE_TOKEN_FROM_DIR_RE.exec(dir)?.[1],
expected,
`PHASE_TOKEN_FROM_DIR_RE diverged from extractPhaseToken for ${dir}`,
);
}
});
test('#2528: a one-digit terminator does not re-tokenize the name on any non-I/O surface', () => {
// Every surface below is QUERY-LESS — it sees a name and nothing else — so
// none of them may resolve the "24 is a sub-phase" / "24 is a slug word"
// ambiguity. They agree on the literal reading, and the disambiguation is
// left to matchPhaseDirs, which does have a query.
for (const dir of ['10-24-7-autonomy', '10-24-7-zip']) {
assert.strictEqual(phaseId.extractPhaseToken(dir), '10-24');
assert.strictEqual(validate.PHASE_TOKEN_FROM_DIR_RE.exec(dir)?.[1], '10-24');
assert.strictEqual(validate.canonicalPlanStem(dir), '10-24');
assert.strictEqual(
coreUtils.extractCanonicalPlanId(`${dir}-PLAN.md`),
'10-24',
);
}
const bracketDir = '01-10-24-7-autonomy';
assert.strictEqual(
bracketDir.match(new RegExp(phaseId.BRACKET_PHASE_TOKEN_SOURCE))?.[0],
'01-10-24',
);
});
test('letter-suffixed plan components and dotted sub-phases keep their established grammar', () => {
assert.strictEqual(phaseId.isPhaseContinuationSegment('01A'), true);
assert.strictEqual(validate.PHASE_TOKEN_FROM_DIR_RE.exec('10-01A-auth')?.[1], '10-01A');
assert.strictEqual(validate.canonicalPlanStem('10-01A-auth-setup'), '10-01');
assert.strictEqual(
coreUtils.extractCanonicalPlanId('10-01A-auth-setup-PLAN.md'),
'10-01A',
);
assert.strictEqual(phaseId.extractPhaseToken('10-01.2-auth'), '10-01.2');
assert.strictEqual(
phaseId.phaseTokenMatches('10-01.2-auth', phaseId.normalizePhaseName('10')),
false,
);
});
test('#2528: digit-plus-letter slug words preserve owner/regex parity', () => {
fc.assert(
fc.property(
fc.integer({ min: 1, max: 99 }),
fc.integer({ min: 10, max: 99 }),
fc.string({
unit: fc.constantFrom(...'abcdefghijklmnopqrstuvwxyz'),
minLength: 1,
maxLength: 8,
}),
(phase, digits, letters) => {
const expected = String(phase).padStart(2, '0');
const dir = `${expected}-${digits}${letters}-growth`;
assert.strictEqual(phaseId.extractPhaseToken(dir), expected);
assert.strictEqual(
validate.PHASE_TOKEN_FROM_DIR_RE.exec(dir)?.[1],
expected,
`PHASE_TOKEN_FROM_DIR_RE diverged from extractPhaseToken for ${dir}`,
);
},
),
);
});
test('property: prefixed deep tokens stay identical across imperative and regex readers', () => {
const prefixArb = fc.constantFrom('', 'CK-', 'M1-', 'v2-', 'APP1-', 'APP_1-', 'phase-');
const phaseArb = fc.integer({ min: 0, max: 999 }).map(String);
const continuationArb = fc.array(
fc.integer({ min: 0, max: 99 }).map((n) => String(n).padStart(2, '0')),
{ minLength: 2, maxLength: 5 },
);
fc.assert(
fc.property(prefixArb, phaseArb, continuationArb, (prefix, phase, continuations) => {
const token = `${prefix}${phase}-${continuations.join('-')}`;
const dir = `${token}-feature`;
assert.strictEqual(
validate.PHASE_TOKEN_FROM_DIR_RE.exec(dir)?.[1],
phaseId.extractPhaseToken(dir),
`prefixed/deep grammar diverged for ${dir}`,
);
assert.strictEqual(phaseId.extractPhaseToken(dir), token);
}),
);
});
// #2528 re-review: the boundary the earlier revision of this fix had no
// coverage for. `minLength: 1` is the case that matters — EXACTLY one genuine
// sub-phase level followed by a slug that starts with a bare digit ("10-24-7-zip",
// sub-phase 10.24 named "7-Zip Integration"). A tokenizer that treats a
// one-digit terminator as evidence that the preceding continuation was a slug
// word cannot see the difference between that and "10-24-7-autonomy" (phase 10
// named "24/7 Autonomy") — so it silently makes the well-formed sub-phase
// unresolvable by its own id. The token therefore keeps EVERY absorbed
// continuation regardless of what terminates the scan, at one level and at five.
test('property: a digit-leading slug never shortens the absorbed continuation run', () => {
const prefixArb = fc.constantFrom('', 'CK-', 'M1-', 'v2-', 'APP1-', 'APP_1-', 'phase-');
const phaseArb = fc.integer({ min: 0, max: 999 }).map(String);
const continuationArb = fc.array(
fc.integer({ min: 0, max: 99 }).map((n) => String(n).padStart(2, '0')),
{ minLength: 1, maxLength: 5 },
);
const terminatorArb = fc.integer({ min: 0, max: 9 }).map(String);
fc.assert(
fc.property(
prefixArb,
phaseArb,
continuationArb,
terminatorArb,
(prefix, phase, continuations, terminator) => {
const expected = `${prefix}${phase}-${continuations.join('-')}`;
const dir = `${prefix}${phase}-${continuations.join('-')}-${terminator}-feature`;
assert.strictEqual(phaseId.extractPhaseToken(dir), expected);
assert.strictEqual(
validate.PHASE_TOKEN_FROM_DIR_RE.exec(dir)?.[1],
expected,
`deep continuation grammar diverged for ${dir}`,
);
// …and the directory stays reachable by that very token.
assert.deepStrictEqual(
phaseId.matchPhaseDirs([dir], expected).matches,
[dir],
`${dir} became unresolvable by its own id ${expected}`,
);
},
),
);
});
});
// Surface 5 needs a real ROADMAP/STATE on disk, so it gets its own block.
describe('#2232 continuation-grammar parity — roadmap isDirInMilestone (hyphenated mode)', () => {
let tmpDir;
function writeProject(roadmapLines) {
tmpDir = createTempProject();
const planning = path.join(tmpDir, '.planning');
fs.mkdirSync(planning, { recursive: true });
fs.writeFileSync(path.join(planning, 'STATE.md'), '---\nmilestone: v1.0\n---\n');
fs.writeFileSync(path.join(planning, 'ROADMAP.md'), roadmapLines.join('\n'));
return tmpDir;
}
for (const { seg, absorbed, note } of WIDTH_CORPUS) {
test(`width ${seg.length} (${JSON.stringify(seg)}): isDirInMilestone agrees — ${note}`, () => {
// A hyphenated phase id in the roadmap switches the filter into the
// hyphenated-mode regex — the branch #2043/#2232 both live in.
writeProject([
'## v1.0: Current',
'### Phase 2-01: Alpha',
'**Goal:** first alpha phase',
'',
'### Phase 14: 2026 Photos And Performance',
'**Goal:** the year-leading slug case',
]);
const filter = getMilestonePhaseFilter(tmpDir);
// When the segment is NOT absorbed, the dir's token is "14" → matches
// roadmap Phase 14. When it IS absorbed (width 2), the token is "14-02",
// which the roadmap does not list → correctly excluded.
assert.strictEqual(
filter(`14-${seg}-photos-performance`),
!absorbed,
`isDirInMilestone("14-${seg}-photos-performance") diverged from the owner ` +
`(absorbed=${absorbed} → token ${absorbed ? `"14-${seg}" (not in roadmap)` : '"14" (Phase 14)'})`,
);
// Control: the genuine milestone-prefixed dir always matches.
assert.strictEqual(filter('02-01-alpha'), true, '02-01-alpha must match Phase 2-01');
cleanup(tmpDir);
tmpDir = null;
});
}
// #2528 RESIDUAL, pinned rather than left to prose. This filter is one of the
// query-less surfaces: it compares a directory's own token against the roadmap
// set, and the #2232 contract above already fixes what happens when that token
// is an absorbed continuation the roadmap does not list — the dir is excluded.
// A phase named "24/7 Autonomy" produces exactly that shape, so it is excluded
// for the same reason and by the same rule as the width-2 case above, and
// identically to the "05-80-20-cleanup" shape this fix documents. Widening the
// filter would contradict the #2232 pin one screen up; the bare-integer
// fallback lives where a query exists (matchPhaseDirs), and every phase-verb
// path that takes a phase number resolves this directory correctly — see
// tests/phase-resolution-parity.test.cjs.
test('#2528 residual: a digit-leading phase NAME is scoped by its literal token', () => {
writeProject([
'## v1.0: Current',
'### Phase 2-01: Alpha',
'**Goal:** force hyphenated mode',
'',
'### Phase 10: Autonomy',
'**Goal:** the 24/7 name',
]);
const filter = getMilestonePhaseFilter(tmpDir);
// Token "10-24" — not a roadmap id, so out of milestone scope…
assert.strictEqual(filter('10-24-7-autonomy'), false);
// …exactly like the other member of the family, and unlike the plain form.
assert.strictEqual(filter('05-80-20-cleanup'), false);
assert.strictEqual(filter('10-autonomy'), true);
cleanup(tmpDir);
tmpDir = null;
});
});
// ─── #612: the DELIBERATE divergence, pinned ────────────────────────────────
// Surface 6 consumes the owner at the slug-adjacent position (above), but is
// deliberately WIDER at the other positions. That is a divergence, so per the
// Generative Fix Divergence rule it gets pinned here rather than left to a
// comment: if someone later "unifies" the bracket run onto the exactly-2 cap,
// or re-widens the slug-adjacent position back to `\d+`, one of these fails and
// points them at the rationale in phase-id.cts.
//
// The policy is stated independently of the regex: bracket's non-slug-adjacent
// positions are DELIMITER-disambiguated (a grammar-required field separator; a
// dot no slug can contain), not heuristically recognized, so they carry the
// canonical width toDir emits — while #2232's cap defends the one position that
// sits against a slug.
describe('#612 bracket divergence — wider only where the delimiter disambiguates', () => {
const tokenOf = (s) => s.match(new RegExp(phaseId.BRACKET_PHASE_TOKEN_SOURCE))?.[0];
test('the #2232 repro cannot reopen on the bracket path', () => {
// The review's scenario: roadmap phase "2026 Photos & Performance" at
// phase 14 → slug leads with a year. The token is the phase, not the year.
assert.strictEqual(tokenOf('01-14-2026-photos-performance'), '01-14');
assert.strictEqual(tokenOf('01-14.03-2026-photos-performance'), '01-14.03');
});
test('3+-digit phase and sub-phase — widths toDir emits — stay recognized', () => {
// Both are rejected by a verbatim exactly-2 cap; both are canonical per
// CANONICAL_NUMERIC_RE, so under-collecting them would break the read path
// against ids the emit path produces.
assert.strictEqual(tokenOf('02-105-slug'), '02-105', '3-digit phase (dash-1)');
assert.strictEqual(tokenOf('05.100'), '05.100', '3-digit sub-phase (dot)');
assert.strictEqual(tokenOf('01-2026-photos'), '01-2026', 'a 4-digit phase is unambiguous at dash-1');
});
test('the divergence is bounded: a PLAN >=100 is out of the grammar (#2232 policy verbatim)', () => {
// The accepted trade-off. Stated as a test so it is a decision on record,
// not an accident: the slug-adjacent position cannot be widened without
// reopening the year collision.
assert.strictEqual(tokenOf('02-05-100'), '02-05', 'a 3-digit plan is not absorbed');
assert.strictEqual(tokenOf('02-05-01'), '02-05-01', 'a canonical 2-digit plan is absorbed');
});
test('an over-padded field is not canonical, so it is not collected', () => {
// `014` matches neither canonical branch (leading zero + 3 digits), which is
// what parsePhaseId rejects too — the read side under-collects rather than
// inventing a field the parser would refuse.
assert.strictEqual(tokenOf('01-014-slug'), '01');
});
// The `(?=-|$)` terminator this PR adds is what keeps surface 6 in step with
// the others: without it the run would stop mid-field and report a prefix.
// It also costs something, and the cost is pinned rather than left implicit —
// a token followed by any OTHER delimiter no longer tokenizes at all. No
// production caller reads this constant (its consumers are this file and
// adr-612-bracket-grammar.test.cjs), so the loss is confined to the display
// shapes below. Anyone restoring them must widen the terminator class
// deliberately, not by deleting the lookahead.
test('the terminator is dash-or-end, and display punctuation is not in it', () => {
assert.strictEqual(tokenOf('05.03-slug'), '05.03', 'dash terminates');
assert.strictEqual(tokenOf('05.03'), '05.03', 'end-of-string terminates');
assert.strictEqual(tokenOf('05.03: Title'), undefined, 'a colon does not');
assert.strictEqual(tokenOf('12A: X'), undefined, 'nor after a letter suffix');
assert.strictEqual(tokenOf('05.03]'), undefined, 'nor a closing bracket');
});
});
// ─── #2528: two more grammar edges this PR moves, pinned ────────────────────
// Neither has a production consumer today, so neither can break a caller — they
// are pinned so the change is a decision on record rather than a silent drift a
// future reader has to reconstruct from a diff.
describe('#2528 grammar edges without production consumers', () => {
test('canonicalPlanStem only strips an UPPERCASE plan suffix', () => {
// The `i` flag is gone and the lookahead is uppercase-only, so a lowercase
// suffix — and a dotted sub-plan — now fall through unchanged instead of
// being reduced to the stem. Uppercase, the shape `toDir` actually emits,
// is unaffected. If a production caller ever appears, this is the line to
// revisit.
assert.strictEqual(validate.canonicalPlanStem('10-01A-auth'), '10-01', 'uppercase: stripped');
assert.strictEqual(validate.canonicalPlanStem('10-01a-auth'), '10-01a-auth', 'lowercase: unchanged');
assert.strictEqual(validate.canonicalPlanStem('10-01.2-auth'), '10-01.2-auth', 'dotted sub-plan: unchanged');
});
test('a letter-suffixed phase with a sub-phase windows like its plain-numeric twin', () => {
// Before this PR `12A-01-foo` yielded `12A` while `12-01-foo` yielded
// `12-01` — the letter suffix was the only reason a sub-phase directory
// folded into its PARENT phase's milestone. That asymmetry is the defect;
// the two shapes now agree. The visible consequence is that a milestone
// declaring `12A` no longer absorbs `12A-01-foo`, exactly as one declaring
// `12` has never absorbed `12-01-foo`.
const tmpDir = createTempProject();
try {
const planning = path.join(tmpDir, '.planning');
fs.mkdirSync(planning, { recursive: true });
fs.writeFileSync(path.join(planning, 'STATE.md'), '---\nmilestone: v1.0\n---\n');
fs.writeFileSync(path.join(planning, 'ROADMAP.md'), [
'## v1.0: Current',
'### Phase 2-01: Alpha',
'**Goal:** puts the filter in hyphenated mode',
'',
'### Phase 12A: Letter Suffixed',
'**Goal:** the shape under test',
].join('\n'));
const filter = getMilestonePhaseFilter(tmpDir);
assert.strictEqual(filter('12-01-foo'), false, 'plain numeric: unchanged');
assert.strictEqual(filter('12A-01-foo'), false, 'letter-suffixed: now agrees');
assert.strictEqual(filter('12A-foo'), true, 'the phase itself still windows');
} finally {
cleanup(tmpDir);
}
});
});