* docs(#3881): answer §8.1's open question and correct three wrong premises ADR-3473 §8.1 carries a blocking open question with a forcing function: it must be answered before any implementation PR for the rule opens. Answered here as (a), a string-coercing adapter, with the measurement that settles it. The sequencing note bet that §8.8's schema would make (b) tractable. Measured against merged reality it does not: only 33 of extractFrontmatter's 78 non-test call sites read STATE.md, and two of the five compensating mechanisms §8.1 lists survive real types, leaving ~31 lines across 3 call sites as the actual prize. Also corrects three claims verified false while answering it. §8.1's justifying sentence names #3349 and #3360 as defects a real parser would fix; both are already fixed on next, confirmed by executing the compiled parser rather than reading it. The guard roster calls lint-frontmatter-scalar-broad-grep.cjs an expected casualty of this rule, but it guards shell grep idioms in workflow bash fences and never touches our parser. The same roster calls lint-vendored-deps.cjs reusable as-is; it is hardcoded to re2js throughout. The last two were caught by applying the rule this amendment records -- a factual claim in this ADR is a hypothesis until the implementing phase executes it -- on its first use. Refs #3881 * docs(#3881): record that §8.1's fork is ill-posed and (a) is not implementable An adversarial pass on the Phase 4 design established by execution that extractFrontmatter is not a YAML parser but a line-oriented scanner whose output is a function of raw source text. Four spellings of the same value collapse to one js-yaml tree but produce four distinct legacy strings, one of them mangled. No adapter over a tree can choose among outputs the tree does not distinguish, so fork (a) -- keep a string-coercing adapter so the existing contract holds -- cannot be built. For any document with a non-scalar value, (a) collapses into (b); about 26 percent of frontmatter-carrying documents have one. Also records three design defects and one new attack surface, all confirmed by execution: catching a parse failure and returning {} would delete the frontmatter block on the next write at eight call sites that conflate empty with unparseable; an empty value yields null where legacy yields {}, and reconstructFrontmatter omits null-valued keys, so the shipped state template's empty progress key would vanish; the #1882 truncation probe is parseYamlRegion itself rather than a pre-parse heuristic, so it cannot both stay unchanged and survive that deletion; and FAILSAFE_SCHEMA still resolves aliases, expanding seven lines to 22.8 MB. The rule is not deferred. The measurement is the deliverable and the re-scoping is recorded as an open question with a forcing function, per section 8's own rule. Refs #3881 * test(#3881): failing-first rows for block scalars, unicode keys and the missing #3594 matrix Creates tests/feat-3594-parser-adversarial-frontmatter.test.cjs, the file the fixture README instructs contributors to register fixtures in but which never existed. Section C: table-driven ownership check over tests/fixtures/adversarial/frontmatter/ so a fixture with no matrix entry fails loudly; six existing fixtures (duplicate-keys, crlf-mixed, unclosed-block, unicode-keys-and-values, null-byte-value, huge-bounded) each get the invariant its README states. B1 blockScalarValueIsNotTheBlockIndicator: parsing commands/gsd/add-tests.md must give argument-instructions the instruction text, not the literal '|'. RED today. B2 blockScalarDoesNotInventATopLevelKey: same parse must not produce a top-level Example key scraped from inside the block body. RED today. B3 unicodeKeyRoundTripsAsIs: the 相 key in unicode-keys-and-values.md must survive parsing; today it is silently dropped. RED today. Refs #3881 * chore(#3881): vendor js-yaml and generalize the vendored-deps guard to a manifest Packaging step for ADR-3473 §8.1: makes js-yaml available to gsd-core/bin/** without promoting it out of devDependencies (promoting broke every installed tree, #3496). gsd-core/bin/lib/vendor/js-yaml.cjs is a verbatim copy of node_modules/js-yaml/dist/js-yaml.js (the self-contained UMD dist bundle, not index.js), exposing load/dump/FAILSAFE_SCHEMA/YAMLException with zero require() calls of its own. src/vendor/js-yaml.d.cts is hand-authored, not copied, because js-yaml ships no upstream .d.ts and @types/js-yaml is not installed. It is deliberately narrow, declaring only the four symbols in use, so anchors/aliases/custom types/loadAll are unreachable from typed code -- a compile-time enforcement of ADR-3473 §8.1's refusal to expand alias resolution for security reasons. Because it has no upstream counterpart it is excluded from the byte-compare. scripts/lint-vendored-deps.cjs is refactored from a script hardcoded to re2js into a table-driven VENDORED manifest (one row per package: upstream/vendored .cjs paths, optional .d.cts paths, twin kind upstream-verbatim vs hand-authored) so a second vendored package does not require a second hardcoded check block, per ADR-3473 §8.3 'one implementation per rule'. The four existing re2js checks (vendored .cjs vs node_modules, vendored .d.cts vs node_modules, src/vendor twin vs bin-side twin, devDependency version pin vs installed version) are preserved unchanged; verified pass/fail identical before and after the refactor, and the guard's ability to fail was re-proven with a deliberate one-byte append to both re2js.cjs and js-yaml.cjs, then restored. docs/INVENTORY.md and docs/INVENTORY-MANIFEST.json (via gen-inventory-manifest.cjs --write, run after build:lib) register vendor/js-yaml.cjs. gsd-core/bin/lib/vendor/README.md documents both vendored packages and the two twin kinds. Refs #3881 * feat(#3881): parse .planning frontmatter with the vendored js-yaml ADR-3473 §8.1: extractFrontmatter's read path is no longer a hand-rolled line scanner. parseYamlRegion, escapeDoubleQuoted, unescapeDoubleQuoted and parseQuotedScalar are deleted (not patched); parsing now goes through the vendored js-yaml (./vendor/js-yaml.cjs) under { schema: FAILSAFE_SCHEMA, json: true }. Everything js-yaml does not do is layered on top, in one place, carrying the seven design-doc consequences: 1. Empty value: a null js-yaml value is coerced to {} (matching legacy's own empty-value contract) so reconstructFrontmatter — which omits null-valued keys — still round-trips a bare `key:` line instead of deleting it. Verified live: progress: with no value survives parse -> reconstruct -> re-parse. 2. Unparseable no longer collapses to a bare {}: a new FRONTMATTER_UNPARSEABLE Symbol (exported), keyed exactly like the existing #3257 FULL_LINE_COMMENTS channel, is carried on the {} returned for malformed/refused YAML. Invisible to Object.keys/entries/JSON.stringify/for-in, so the 70 call sites that never inspect it are unaffected; wiring the 8 hasFrontmatter sites to consult it is a separate change, not done here. 3. Non-scalar object-list items (the four spellings of `- test: a b` that js-yaml collapses into one tree shape) are rendered as a canonical `key: value[, key2: value2]` string per item, keeping the existing array-of-strings value SHAPE. A full corpus differential over all 1702 tracked markdown files found 11 residual divergences from the legacy parser (enumerated in the PR/report), most of them the parser now being MORE correct (a dropped quoted top-level key, the block-scalar/phantom-key defect, a dropped Unicode key). 4. The #1882 truncation probe still runs the one real parser, but derives its key count from js-yaml's own thrown error and mark.line when the whole region doesn't parse cleanly (the dominant real truncation shape: fence opened, well-formed keys, no closing fence). Verified against both the clean-parse and the exception-fallback path. 5. The #3257 comment channel now attributes each pending column-0 comment against js-yaml's own parsed top-level key list (matched by literal key text, in document order) instead of the legacy ASCII-only key regex, so a comment above a Unicode key attaches correctly. 6. Anchors, aliases and merge keys are refused outright (a raw-text pre-scan, since FAILSAFE_SCHEMA still resolves them) — corpus occurrences today: zero. A 7-line billion-laughs fixture is verified refused rather than expanded. 7. A literal U+0000 is swapped for a private-use sentinel before the parse and restored in every resulting string afterward, since js-yaml rejects NUL unconditionally under every schema. escapeDoubleQuoted is deleted and reimplemented via js-yaml's dump() (forced double-quoted style), with control-char hex escapes lowercased to keep serialized output byte-stable (#1779 emitted lowercase); it keeps its exported name and signature for its two other call sites (commands.cts, runtime-artifact-conversion.cts), which need no change. frontmatterDeepEqual, the comment channel, sliceTopLevelFrontmatterSegments, regenerateFrontmatterKey's guard, noOpObjectListSetError and parseMustHavesBlock are all unchanged — retiring them is fork (b) and is not this phase. Refs #3881 * fix(#3881): quote template placeholders and preserve unparseable frontmatter SECURITY.md/UI-SPEC.md/VALIDATION.md wrote frontmatter placeholders as bare {N}/{phase-slug}/{date}, which is valid YAML flow-mapping syntax under the vendored js-yaml parser, not the literal placeholder text intended. Quote them so they parse as strings. Wire the FRONTMATTER_UNPARSEABLE Symbol (exported but unused) at the 8 call sites in state.cts/state-transition.cts that compute hasFrontmatter via Object.keys(extractFrontmatter(...)).length > 0 and reassemble the document without a frontmatter block when false. That check conflated 'no frontmatter' with 'unparseable frontmatter' (both parse to {}), so a document with a merge-conflict marker or refused alias in its frontmatter had that block silently dropped on write. Each site now preserves the exact raw bytes stripFrontmatter removed when the marker is set, leaving the genuinely-empty case unchanged. Refs #3881 * test(#3881): consequence and boundary coverage for the js-yaml migration Rows: A1 emptyValuedKeySurvivesAWrite, A2 unparseableDocumentKeepsItsFrontmatterBlock, A3 unparseableIsDistinguishableFromEmpty, A4 nonScalarValuesCanonicalize, A5 truncationProbeStillFiresOnAnOpenFence, A6 commentsStayOnTheirOwnKey, A7 anchorsAndAliasesAreRefused, A8 aliasExpansionCannotExhaustMemory, F1 UNTERMINATED_KEY_THRESHOLD boundary, F2 alias/nesting refusal bound, F3 frontmatter size boundary (huge-bounded.md + larger). Adds tests/fixtures/adversarial/frontmatter/anchor-alias-bomb.md and its entry in the feat-3594 fixture matrix. Refs #3881 * docs(#3881): document the vendored parser, correct a stale rationale, add a vendoring how-to Refs #3881 * docs(#3881): correct the frontmatter glossary entry Two errors in the entry as first written: it named parseYamlRegion as part of the read path when that function is deleted, and it recorded the eight hasFrontmatter call sites as unwired follow-on work when they were wired in e35ac2a2c. Also records the scope caveat that the CLI write path rebuilds the frontmatter block independently, so the marker binds at the transform layer. Refs #3881 * docs(#3881): record the semantic-migration decision and the counted guard ledger The maintainer chose the full semantic migration over splitting the rule into its own epic or patching the scanner, so section 8.1 is answered as "the fork was ill-posed and the migration is semantic" rather than as (a) or (b). Also replaces the pre-implementation guess that this phase would shrink the guard surface with the counted result: excluding vendored third-party lines the hand-maintained surface is net +307, and frontmatter.cts grew by 68 lines despite four functions being deleted, because the compatibility layer over js-yaml is larger than the scanner it replaced. Section 8.1's stated benefit is therefore not delivered as written; what improved is the kind of code maintained, not the amount. Decision 6 requires recording that rather than netting it away. Refs #3881 * chore(#3881): changeset for the vendored YAML parser migration Refs #3881 * test(#3881): golden parity, round-trip property and packaging coverage Refs #3881 * fix(#3881): refuse anchors structurally and fold in review findings ADR-3473 §8.1 review findings, addressed inline: Finding 1 (BLOCKER): refuseAnchorsAndAliases was a raw-line regex that matched only the bare-key spelling (key: &x). A quoted key ("a": &x), a flow mapping ({b: &x}) and a flow sequence ([&x, *x]) all define/use the SAME anchor mechanics while never matching that line shape, so the exact expansion the guard exists to stop went straight through unrefused (a 303-byte quoted-key bomb expanded to ~35.8MB). Replaced with js-yaml's own `load` `listener` callback, which reports `state.anchor` for every event belonging to an anchored node in every spelling, and throws from inside the callback to abort before any expansion (~1-2ms vs full expand-then-discard). A merge key with an alias is still refused (merge always requires a previously anchored node, so the alias itself trips the listener); a bare merge key with NO alias is no longer separately refused, documented as intentional: FAILSAFE_SCHEMA never resolves `!!merge`, so it carries no expansion risk. Table-driven tests added for all four bypass spellings + merge key, plus a quoted-key-spelled billion-laughs fixture registered in the adversarial matrix and README. Finding 2: src/vendor/js-yaml.d.cts's docblock falsely claimed anchors/ aliases were "simply UNREACHABLE from typed code" through the twin. Corrected to state the truth: anchor/alias resolution is document-level `load` mechanics reachable through exactly the declared surface, and refusal is enforced at RUNTIME (Finding 1's listener), not by the type surface. Finding 3 (MAJOR): the null-byte sentinel (U+E000) round-trip was non-injective — restoreNullBytesDeep rewrote every U+E000 in the parsed tree back to NUL, including one the document author legitimately wrote, silently corrupting it. Now refuses outright whenever the raw region already contains U+E000 (consistent with the existing anchor/merge-key refusal path), making the substitution provably injective. Tests added for a real NUL alone (preserved), a pre-existing U+E000 alone (refused, not corrupted), and both together (refused, not merged into one byte). Finding 4 (MAJOR): scripts/lint-vendored-deps.cjs's `srcTwin` field was dead for a hand-authored row (only read inside the upstream-verbatim branch) — exactly how Finding 2's stale docblock drifted unnoticed. Added checkHandAuthoredTwin: every value-level export the twin DECLARES must be an actual own property of the vendored runtime module at require-time. Tests added, including a sensor that a declared-but-nonexistent export IS caught. Finding 5: the existingFm/hasFrontmatter/stripFrontmatter/fmPrefix/ unparseableFm/reassemble preamble, copy-pasted at 7 sites in state-transition.cts plus a sixth hand-inlined copy in state.cts's cmdStateCompletePhase, is now one exported helper (beginFrontmatterReassembly) every site routes through, including the hand-inlined one. Three call sites (beginPhaseCore, patchCore, updateCore) keep a literal `body = stripFrontmatter(content)` assignment alongside the helper call so scripts/lint-state-write-path-drift.cjs's single-hop backward scan (which does not chase aliases) still sees the strip; stripFrontmatter is pure/idempotent so the extra call changes nothing observable. Finding 6: corrected the frontmatter.cts docblock's stale "wiring is a separate change" claim (the 8 call sites are wired on this branch) and the changeset's backlink from (#3473) to (#3881). Finding 7: fixed the lint:ci failures blocking the gate — an @typescript-eslint/only-throw-error violation from throwing a bare Symbol as the anchor-detected signal (now a real Error subclass), unused-var warnings left over from the Finding 5 refactor, a lint-test-file-count cap exceeded by two migration-specific test files (allowlisted with justification), and the lint-state-write-path-drift false positive from Finding 5's helper (fixed above). tests/frontmatter-golden-parity.test.cjs:117's execFileSync already carried an explicit timeout; no change was needed there. Golden fixture: added a golden entry for the new anchor-alias-bomb-quoted.md fixture ({} — matches what the legacy line scanner would also produce, since it independently dropped every quoted top-level key). No other corpus document diverges: real .planning/ documents carry zero anchors/aliases/merge keys/U+E000 today. Refs #3881 * fix(#3881): fold in second-round review findings Finding 1 (BLOCKER): tests/frontmatter.test.cjs pinned the pre-migration ASCII-only key regex for the Unicode fixture; updated to require the 相 key's value now that js-yaml has no such restriction. Audited the rest of the file for other pre-migration pins (block scalars, quoted keys, flattened values, empty values, duplicate keys, unclosed blocks, null bytes) by execution against real fixtures; found none regressed. Finding 2: parseYamlRegion and escapeDoubleQuoted renamed to parseGuardedYamlRegion and escapeDoubleQuotedScalar in src/frontmatter.cts so no function still answers to the deleted hand-rolled scanner's name (ADR-3473 §8.1 "deleted, not patched"). escapeDoubleQuotedScalar's three external call sites (src/commands.cts, src/runtime-artifact-conversion.cts) updated in the same change — a mechanical rename, not an ADR-amendment matter. Finding 3 (BLOCKER): fixed a real crash and a silent data-loss bug found by execution. A top-level key named constructor/__proto__/toString/ valueOf/hasOwnProperty crashed reconstructFrontmatter (bracket read resolving an inherited Object.prototype member); a key literally named __proto__ was silently DROPPED entirely (bracket assignment on an ordinary {} invoked the inherited __proto__ setter instead of creating a data property). Fixed by building every parsed Frontmatter object with Object.create(null), and replacing an `in` check with hasOwnProperty.call in propagateCommentChannel. Added round-trip tests for all five hostile keys, each with its own leading comment. Finding 4 (MAJOR): escapeDoubleQuotedScalar's docstring falsely claimed full byte-stability across the migration. Verified by execution: BEL/NUL/ NEL/NBSP/LS/PS/BOM now emit YAML-named escapes instead of the old hex/raw- literal forms. Proved round-trip equivalence (each escape re-parses to the exact source codepoint) and corrected the docstring. Found and fixed a related real defect while verifying: a lone UTF-16 surrogate was emitted BARE (scalarNeedsDoubleQuoting didn't trigger), producing genuinely unparseable YAML that silently collapsed to {} on re-read — extended scalarNeedsDoubleQuoting to route surrogates through the quoted+escaped path. Finding 5 (MAJOR): countKeysBeforeTruncation went silent on 4 real truncation shapes (unquoted colon, open flow collection, mis-indented sibling key, refused anchor). Root cause: the mark-based prefix recovery excluded the very line whose key needed counting, and a mark-less refusal never entered the recovery branch at all. Fixed by taking the max of two lower bounds: the longest parser-verified line-prefix, and a raw-text count of key-shaped lines (reusing the same key-shape pattern this file already uses for isFrontmatterShaped). Extended test-matrix row A5 table-driven over all 4 regressed shapes. Finding 6: the design doc's claim that no test owned the #3594 adversarial fixture corpus was false — consolidation epic #1969 had already folded it into tests/frontmatter.test.cjs. An earlier commit on this branch re-created a standalone duplicate under that false premise; folded its genuinely-new coverage (fixture-ownership check, anchor-bomb fixtures, block-scalar B1/B2 rows) into frontmatter.test.cjs and deleted the duplicate file. Corrected the false claims in 40-design.md §3.3.1 and the ADR's §8.1 note, including the roadmap-sibling claim (no such file exists). Finding 7: the golden serializer sorted object keys, making it structurally blind to the key-order-parity invariant ADR-3473 §8.1 actually claims. Made it order-preserving and regenerated the golden fixture from a standalone compile of the legacy (pre-#3881) parser at ddde001af; the current parser matches it with zero undocumented divergences, confirming key-order parity genuinely holds. Extended row A2 table-driven across 6 of the remaining 7 transitionCore kinds (all pass) plus documented, by execution, a newly-discovered 8th-site regression: state.cts's cmdStateCompletePhase calls the same preservation helper but its result is clobbered by a later unconditional resync — filed as a distinct finding rather than fixed here (touches syncAndPreserveStateMd, outside this change's verified scope). Refs #3881 * fix(#3881): preserve unparseable frontmatter through the CLI write path Characterization (executed, before/after shown): case (b), not (a). The frontmatter FENCE survives — `state complete-phase` on a conflict-marked STATE.md returns success and a well-formed, freshly-derived frontmatter block, not a document with no frontmatter at all. But the block's actual content (the merge-conflict markers, and with them any signal to a human that the document was in conflict) is silently discarded and replaced. Root cause was two clobber sites, not one: 1. syncStateFrontmatter (src/state.cts) re-parses the already-preserved `transformedContent` from readModifyWriteStateMd, finds {} + the FRONTMATTER_UNPARSEABLE marker, and unconditionally rebuilt a fresh frontmatter block from the body anyway. 2. Even after (1) is fixed, applyPostSyncPreservation's own postFm/applyStatePreservation/authoritativeFm-reassertion machinery re-extracts frontmatter from syncedContent, restores curated fields from the pre-write snapshot, and reconstructs a NEW block again — confirmed live via `state begin-phase`, which still lost the markers after fixing (1) alone. Both are now guarded by the same predicate (isUnparseableFrontmatter, checking FRONTMATTER_UNPARSEABLE): when the ORIGINAL frontmatter did not parse and the caller is not on ADR-3408 §8.3's closed "body wins" list, both functions return their input content unchanged rather than re-deriving over it. The closed list (cmdStateSync #905, /gsd-health --repair's REGENERATE_STATE, both routed only through writeStateMd, which never reaches applyPostSyncPreservation and passes sanctionedPermanentEmptyFallback=true to syncStateFrontmatter) is untouched — neither widened nor narrowed; verified by execution that `state sync` still overwrites the conflict-marked block exactly as before. Other verbs sharing the same readModifyWriteStateMd path were checked and were equally affected before this fix: state update, query state.patch, and state begin-phase all lost the conflict markers (RED, shown by execution), and all three now preserve them (GREEN). Covered table-driven in tests/feat-3881-yaml-parser-consequences.test.cjs's new A2b describe block, which drives the real CLI verbs via runGsdTools — not just the pure transitionCore layer the earlier A2 rows exercised — plus a control asserting state sync's body-wins contract is unchanged. Refs #3881 * fix(#3881): restore the parse surface's prototype and fix remote-runner failures Root cause of the bulk of the 88 remote-runner failures: extractFrontmatter/parseGuardedYamlRegion handed back Object.create(null) trees for prototype-pollution safety, but assert.deepStrictEqual compares prototypes, so every assertion against a plain object literal failed (57 frontmatter.unit.test.cjs + 5 frontmatter.test.cjs + others). Fixed by keeping the internal construction null-prototype (unchanged) and converting to a plain-prototype tree via Object.defineProperty (never bracket assignment, so __proto__/constructor/toString keys stay safe) at the parseGuardedYamlRegion/unparseableResult return boundary only; the internal FULL_LINE_COMMENTS Symbol channel is copied by reference, not recursed, so its own __proto__-safety is untouched. Per-class fixes: (1) bomAcrossArtifactTypes was the same prototype bug, no separate code change needed. (2) frontmatter-cli #1660: added objectListFieldWouldLoseData, a broader lossy-field detector alongside the existing byte-identical noOpObjectListSetError -- js-yaml's flattenObjectListItem now correctly includes every sub-key of an object-list item (a real bug fix over the legacy scanner, which silently dropped every field but the first), so a set that drops that now-included data is no longer byte-identical to the original and needs its own guard. (3) uat.test.cjs: updated the pinned expectation for the human_verification quote-stripping artifact -- js-yaml resolves quoting correctly where the legacy regex left an unbalanced quote; documented as an intentional, non-lossy behavior change. (4) smart-entry: added a fallback-only loadWithAmbiguousColonRepair so a column-0 key: value line whose value itself contains an unquoted colon (the #2571 hand-edited-STATE.md shape) round-trips instead of failing the whole frontmatter block closed. (5) frontmatter.unit.test.cjs bracket-array leniency: added a second fallback, repairMalformedInlineArrays, restoring the legacy scanner's tolerant inline-array handling (consecutive/blank commas, unclosed bracket) -- both repairs run ONLY after the primary parse already threw, so well-formed documents are unaffected. (6) prompt-injection-scan: src/frontmatter.cts had a literal U+FEFF BOM embedded in a comment illustrating the #2977 fix; replaced with the U+FEFF text escape. (7) eslint-glob-coverage: allowlisted the new src/vendor/js-yaml.d.cts vendored type declaration, same precedent as the existing re2js.d.cts entry. (8) frontmatter-golden-parity: git ls-files *.md now runs with -c safe.directory=* (process-scoped) so it survives the remote runner's dubious-ownership check without a persistent git config write. Refs #3881 * chore(#3881): backfill changeset PR number Refs #3881 * test(#3881): make golden parity resistant to unrelated tree churn A corpus-wide snapshot keyed to every tracked *.md file was coupled to mutable-by-design files: .changeset/*.md's pr:0 -> real-PR-number backfill is a required workflow step, not a parser change, yet it turned this suite red. Training people to 'just regenerate the golden' on that kind of failure defeats the point of the snapshot. Exclude .changeset/** from the golden corpus entirely, tolerate tracked *.md files with no golden entry (they postdate the capture) instead of failing on them, keep hard failures for a golden entry whose file has vanished from the tree and for any real parity divergence, and add a coverage floor so the enumeration cannot quietly degrade to comparing a handful of files. Golden regenerated by recompiling the legacy pre-migration parser (git show ddde001af:src/frontmatter.cts) standalone, independent of the current parser, over the same non-changeset corpus. Refs #3881 * test(#3881): make the parser golden hermetic instead of tree-keyed This repo merges ~21 commits/day; a 14-day sample measured 937 touches of the exact files (commands/gsd/*.md, gsd-core/workflows/*.md, agents/*.md, docs/*.md) the prior golden pinned by tracked path. Any PR editing one of those files' frontmatter for reasons unrelated to the parser (an argument-hint addition, an allowed-tools tweak) turned the suite red, and the reflex fix -- "regenerate the golden" -- overwrote the very snapshot meant to catch a real regression. Excluding .changeset/** was not enough; the design itself was wrong: a regression fixture must not be keyed to mutable repo paths, and a single 376-entry JSON every such PR touches is also a guaranteed merge-conflict surface. Rebuilt the fixture to carry its own documents: each of 51 entries stores a stable id, literal documentText (shrunk from a real ddde001af-era corpus document), and an expectedParse captured independently from the pre-migration legacy parser (git show ddde001af:src/frontmatter.cts, compiled standalone against its byte-identical sibling modules). The test reads no tracked path, shells out to no git command, and enumerates no tree -- a PR editing commands/gsd/help.md cannot affect it. Every entry's reconstruction was verified at capture time to reproduce both the current and legacy parser's output on the original document; 0 of 51 candidates were dropped by that check (1, the deliberately-unterminated unclosed-block.md adversarial fixture, has no closing fence to truncate at and is stored unshrunk). Kept the 5 documented DIVERGENCES rows (now diverges:true entries) and the D2 order-preserving structural serializer that keeps the comparison from passing vacuously; dropped the tree-enumeration helpers, the coverage floor, the post-capture-skip logic, and the vanished-file check -- all artifacts of the path-keyed design. Refs #3881 * fix(#3881): resolve vendored-deps paths independently of cwd shape Five rows in tests/lint-vendored-deps-manifest.test.cjs failed on windows-latest CI: the test passed absolute scratch-file paths into compareFiles()/checkRow(), whose helpers joined every input onto ROOT via path.join(ROOT, rel), producing garbage when the input was already absolute. It surfaced on windows-latest specifically because GitHub's Windows runners checkout the repo on a different drive than TEMP, so path.relative(REPO_ROOT, tmpFile) returned the absolute path unchanged (no relative traversal is representable across drives) rather than the relative form the test assumed. The remote gsd-test runner this repo gates pushes on is Linux-only and could never have caught this; GitHub CI's windows-latest job is the only signal that does, and it did. Fixed the helper itself (scripts/lint-vendored-deps.cjs's new resolvePath()) to treat an already-absolute input as absolute-in, absolute-out instead of silently mis-joining it, and updated the test to pass the scratch file's absolute path directly rather than relying on a relative conversion that is not always representable. Kept every mutation-sensor assertion intact and added coverage proving resolvePath is a no-op for relative inputs and correctly passes absolute ones through unchanged. Refs #3881 * fix(#3881): warn when state sync regenerates over unparseable frontmatter state sync (ADR-3408 §8.3's sanctioned regenerate path) correctly overwrites an unparseable frontmatter block per its 'body wins' contract — that overwrite behavior is unchanged here. The defect was the silence: synced:true/exit 0 gave no signal that the existing block (including git merge-conflict markers) could not be parsed and was destroyed, per ADR-3473 §8.5 ('a derived conclusion may not be reported as authoritative when the derivation dropped input it could not resolve') and §8.4 ('failure is a value'). Adds a gsd: warning — ... (#3881) line on stderr, matching the existing #3573 precedent, and surfaces the same disclosure in the JSON result's existing changes[] array so a machine consumer sees it too. Exit code and synced:true are left unchanged — sync did what its contract says. REGENERATE_STATE (/gsd-health --repair's sibling on the same sanctioned-regenerate list) is DESTRUCTIVE-risk and unconditionally refused by applyRepairs's dispatcher before runRepairAction ever runs (src/health-diagnostic.cts), so it is not a live path today and is not in scope for this fix. Refs #3881 * fix(#3881): exit non-zero when a state command returns an error Refs #3881 * chore(#3881): changeset for the state exit-code fix Refs #3881 * fix(#3881): honor the documented --project-dir flag Refs #3881 * revert(#3881): restore exit-0 result envelopes for state errors Reverts 9638f2936 and its changeset. The change was wrong and the revert is the correction. This repo distinguishes two error mechanisms deliberately. error() in src/io.cts writes to stderr and calls process.exit(1) -- the hard-failure path. output({error: ...}) writes a JSON result envelope to stdout and returns normally with exit 0. The reverted commit converted 23 result-envelope sites into hard failures, which is a different contract, not a bug fix. tests/state-contract.test.cjs's errorPathDoesNotPublish asserts the envelope contract directly -- a failing command exits 0 with a JSON error envelope and must not publish state.json -- and the remote matrix run caught it along with four cases in the QA scenario walk. Thirteen tests in tests/state.test.cjs that the original commit rewrote were encoding that real contract, not the bug it claimed; they are restored. Whether an error envelope on stdout with exit 0 is the right CLI design is a genuine question, and it is section 8.4's rule ('failure is a value') with its own phase. It is not something to flip inside this PR. Refs #3881 * chore(#3881): backfill changeset PR number for the project-dir fix Refs #3881 * test(#3881): keep the frontmatter mutation shard inside its time budget The Stryker (frontmatter) shard hit the documented 15-minute (900s) shard cap. Root cause is NOT row-level spawn overhead (contrast the #2790/ core-utils precedent): the three shard test files' own logic runs in ~413ms total (356+30+27ms) with all 392 assertions passing. Instead, src/frontmatter.cts grew from ~825 to 1496 lines (+671/-187) migrating to the vendored YAML parser, proportionally growing the mutant count Stryker generates for gsd-core/bin/lib/frontmatter.cjs. Stryker's command runner bills the full 'node --test <3 files>' invocation once per mutant, and node:test's default per-file process isolation forks a child process for each of the three files on every one of those invocations — pure fork overhead multiplied by a much larger mutant population. Fix: scripts/mutation-matrix.cjs COVERED.frontmatter now declares isolation: 'none', and .github/workflows/mutation.yml passes --test-isolation=${{ matrix.isolation }} (defaulting to 'process' — i.e. unchanged behavior — for the other 8 shards, which were not individually audited for cross-file state leakage under shared-process execution). Measured locally via node:test's run() API on the exact 3-file set: isolation:'process' took ~593ms vs isolation:'none' ~478ms for the same 392 passing assertions. The true CI-shard number can only be confirmed on the GitHub Actions run (Stryker cannot run locally, and 'node --test' is hard-blocked in this environment). Refs #3881 * test(#3881): register the vendored-parser tests in the frontmatter mutation shard stryker.config.mjs's own rule ("Keep this list in sync with the tests arrays in scripts/mutation-matrix.cjs COVERED") was violated: #3881 grew src/frontmatter.cts from ~825 to 1496 lines but its new tests (tests/feat-3881-yaml-parser-consequences.test.cjs, tests/frontmatter-golden-parity.test.cjs, tests/frontmatter-roundtrip.property.test.cjs, and +167 lines in tests/frontmatter.test.cjs) were never added to the frontmatter shard's tests array, so Stryker's mutants in the new vendored-js-yaml adapter had nothing constraining them. PR #3888 measured 55.8% against the 65 floor (748 killed / 593 survived / 17 timeout) and the shard was separately cancelled at 15m04s against the 15-minute per-shard cap. Registers all four files (each earns its slot on evidence of a unique constraining assertion, documented inline), gives the shard a measured/projected 180-minute budget via a new per-module timeoutMinutes field threaded through mutation.yml's job-level timeout-minutes the same way isolation is threaded, and removes the prior isolation:'none' override (re-measured at this file-set size, its savings are within run-to-run noise, not worth the unaudited cross-file-state-leakage risk). Refs #3881 * feat(#3881): derive the mutation test list and ratchet the score floor Refs #3881 * test(#3881): ratchet five stale mutation floors and close the frontmatter gap Raised five module minScore floors per CI run 33012034388 (floor(achieved)-1): config-schema 75.51%->74, prompt-budget 88.95%->87, context-composer 79.92%->78, context-utilization 92.31%->91, active-workstream-store 87.42%->86. Updated both scripts/mutation-matrix.cjs COVERED entries and tests/mutation-matrix-ratchet.test.cjs RATCHET_BASELINE in the same diff per the ratchet's own contract. Closed the frontmatter shard's 63.03%-vs-65 gap with new behavioral tests in tests/feat-3881-yaml-parser-consequences.test.cjs, each paired with a documented near-miss: frontmatterDeepEqual's array-order/length/type-mismatch/key-order semantics (via spliceFrontmatter's no-op guard), scalarNeedsDoubleQuoting's leading/trailing-whitespace and dash/surrogate triggers (via reconstructFrontmatter), repairAmbiguousColonValues' already-quoted vs ambiguous-colon repair paths (via extractFrontmatter), and the null-byte sentinel round-trip surviving at region offset 1. Did not lower minScore. Refs #3881 * test(#3881): decouple the ratchet test from real module floors The CLI end-to-end rows in tests/mutation-score-ratchet.test.cjs hardcoded config-schema's real floor (52), which commit 973321541 legitimately ratcheted to 74 -- breaking a test pinned to the exact value the mechanism under test exists to change. Add an injectable --matrix seam to scripts/check-mutation-score-ratchet.cjs and point the CLI rows at a synthetic module + synthetic floor built via a temp fixture, so the rows are indifferent to any real module's floor moving while still exercising the same fail/pass behaviour. Refs #3881 * refactor(#3881): parse must_haves with the vendored parser and drop re-implemented leniency Refs #3881 * fix(#3881): restore the ambiguous-colon repair its hand-edited-STATE.md contract needs A tracked-document sweep of 910 *.md files cannot see this dependent: repairAmbiguousColonValues's one real caller is user hand-edited STATE.md content that never lives in this repo's tree, only on end users' machines, and is pinned by tests/smart-entry.unit.test.cjs. Restores the function plus its post-throw fallback path (loadWithAmbiguousColonRepair) only; repairMalformedInlineArrays and splitLegacyInlineArrayItems stay deleted, reverified against the full frontmatter test shard. Adds a frontmatter-level regression row in tests/feat-3881-yaml-parser-consequences.test.cjs so the dependency is visible where the function lives. Closes #2571 Refs #3881 --------- Co-authored-by: sim <sim@local>
538 lines
24 KiB
JavaScript
538 lines
24 KiB
JavaScript
/**
|
|
* GSD Tools Tests - Dispatcher
|
|
*
|
|
* Tests for gsd-tools.cjs dispatch routing and error paths.
|
|
* Covers: no-command, unknown command, unknown subcommands for every command group,
|
|
* --cwd parsing, and previously untouched routing branches.
|
|
*
|
|
* Requirements: DISP-01, DISP-02
|
|
*/
|
|
|
|
const { test, describe, beforeEach, afterEach } = require('node:test');
|
|
const assert = require('node:assert/strict');
|
|
const fs = require('fs');
|
|
const path = require('path');
|
|
const { runGsdTools, createTempProject, cleanup } = require('./helpers.cjs');
|
|
|
|
// ─── Dispatcher Error Paths ──────────────────────────────────────────────────
|
|
|
|
describe('dispatcher error paths', () => {
|
|
let tmpDir;
|
|
|
|
beforeEach(() => {
|
|
tmpDir = createTempProject();
|
|
});
|
|
|
|
afterEach(() => {
|
|
cleanup(tmpDir);
|
|
});
|
|
|
|
// No command
|
|
test('no-command invocation prints usage and exits non-zero', () => {
|
|
const result = runGsdTools('', tmpDir);
|
|
assert.strictEqual(result.success, false, 'Should exit non-zero');
|
|
assert.ok(result.error.includes('Usage:'), `Expected "Usage:" in stderr, got: ${result.error}`);
|
|
});
|
|
|
|
// Unknown command
|
|
test('unknown command produces clear error and exits non-zero', () => {
|
|
const result = runGsdTools('nonexistent-cmd', tmpDir);
|
|
assert.strictEqual(result.success, false, 'Should exit non-zero');
|
|
assert.ok(result.error.includes('Unknown command'), `Expected "Unknown command" in stderr, got: ${result.error}`);
|
|
});
|
|
|
|
// --cwd= form with valid directory
|
|
test('--cwd= form overrides working directory', () => {
|
|
// Create STATE.md in tmpDir so state load can find it
|
|
fs.writeFileSync(
|
|
path.join(tmpDir, '.planning', 'STATE.md'),
|
|
'# Project State\n\n## Current Position\n\nPhase: 1 of 1 (Test)\n'
|
|
);
|
|
const result = runGsdTools(['--cwd=' + tmpDir, 'state', 'load'], process.cwd());
|
|
assert.strictEqual(result.success, true, `Should succeed with --cwd=, got: ${result.error}`);
|
|
});
|
|
|
|
// --cwd= with empty value
|
|
test('--cwd= with empty value produces error', () => {
|
|
const result = runGsdTools('--cwd= state load', tmpDir);
|
|
assert.strictEqual(result.success, false, 'Should exit non-zero');
|
|
assert.ok(result.error.includes('Missing value for --cwd'), `Expected "Missing value for --cwd" in stderr, got: ${result.error}`);
|
|
});
|
|
|
|
// --cwd with nonexistent path
|
|
test('--cwd with invalid path produces error', () => {
|
|
const result = runGsdTools('--cwd /nonexistent/path/xyz state load', tmpDir);
|
|
assert.strictEqual(result.success, false, 'Should exit non-zero');
|
|
assert.ok(result.error.includes('Invalid --cwd'), `Expected "Invalid --cwd" in stderr, got: ${result.error}`);
|
|
});
|
|
|
|
// Unknown subcommand: state
|
|
test('state unknown subcommand errors', () => {
|
|
const result = runGsdTools('state bogus', tmpDir);
|
|
assert.strictEqual(result.success, false, 'Should exit non-zero');
|
|
assert.ok(result.error.includes('Unknown state subcommand'), `Expected "Unknown state subcommand" in stderr, got: ${result.error}`);
|
|
// Pin the enumerated subcommand list. If a future refactor reformats the
|
|
// error string and silently drops 'complete-phase' from the available list,
|
|
// this test fails loudly rather than passing on the substring above.
|
|
// CodeRabbit nitpick on PR #2761.
|
|
assert.ok(
|
|
result.error.includes('complete-phase'),
|
|
`Expected enumerated subcommands to include "complete-phase", got: ${result.error}`,
|
|
);
|
|
});
|
|
|
|
// Unknown subcommand: template
|
|
test('template unknown subcommand errors', () => {
|
|
const result = runGsdTools('template bogus', tmpDir);
|
|
assert.strictEqual(result.success, false, 'Should exit non-zero');
|
|
assert.ok(result.error.includes('Unknown template subcommand'), `Expected "Unknown template subcommand" in stderr, got: ${result.error}`);
|
|
});
|
|
|
|
// Unknown subcommand: frontmatter
|
|
test('frontmatter unknown subcommand errors', () => {
|
|
const result = runGsdTools('frontmatter bogus file.md', tmpDir);
|
|
assert.strictEqual(result.success, false, 'Should exit non-zero');
|
|
assert.ok(result.error.includes('Unknown frontmatter subcommand'), `Expected "Unknown frontmatter subcommand" in stderr, got: ${result.error}`);
|
|
});
|
|
|
|
// Unknown subcommand: verify
|
|
test('verify unknown subcommand errors', () => {
|
|
const result = runGsdTools('verify bogus', tmpDir);
|
|
assert.strictEqual(result.success, false, 'Should exit non-zero');
|
|
assert.ok(result.error.includes('Unknown verify subcommand'), `Expected "Unknown verify subcommand" in stderr, got: ${result.error}`);
|
|
});
|
|
|
|
// Unknown subcommand: phases
|
|
test('phases unknown subcommand errors', () => {
|
|
const result = runGsdTools('phases bogus', tmpDir);
|
|
assert.strictEqual(result.success, false, 'Should exit non-zero');
|
|
assert.ok(result.error.includes('Unknown phases subcommand'), `Expected "Unknown phases subcommand" in stderr, got: ${result.error}`);
|
|
});
|
|
|
|
// Unknown subcommand: roadmap
|
|
test('roadmap unknown subcommand errors', () => {
|
|
const result = runGsdTools('roadmap bogus', tmpDir);
|
|
assert.strictEqual(result.success, false, 'Should exit non-zero');
|
|
assert.ok(result.error.includes('Unknown roadmap subcommand'), `Expected "Unknown roadmap subcommand" in stderr, got: ${result.error}`);
|
|
});
|
|
|
|
// Unknown subcommand: requirements
|
|
test('requirements unknown subcommand errors', () => {
|
|
const result = runGsdTools('requirements bogus', tmpDir);
|
|
assert.strictEqual(result.success, false, 'Should exit non-zero');
|
|
assert.ok(result.error.includes('Unknown requirements subcommand'), `Expected "Unknown requirements subcommand" in stderr, got: ${result.error}`);
|
|
});
|
|
|
|
// Unknown subcommand: phase
|
|
test('phase unknown subcommand errors', () => {
|
|
const result = runGsdTools('phase bogus', tmpDir);
|
|
assert.strictEqual(result.success, false, 'Should exit non-zero');
|
|
assert.ok(result.error.includes('Unknown phase subcommand'), `Expected "Unknown phase subcommand" in stderr, got: ${result.error}`);
|
|
});
|
|
|
|
// Unknown subcommand: milestone
|
|
test('milestone unknown subcommand errors', () => {
|
|
const result = runGsdTools('milestone bogus', tmpDir);
|
|
assert.strictEqual(result.success, false, 'Should exit non-zero');
|
|
assert.ok(result.error.includes('Unknown milestone subcommand'), `Expected "Unknown milestone subcommand" in stderr, got: ${result.error}`);
|
|
});
|
|
|
|
// Unknown subcommand: validate
|
|
test('validate unknown subcommand errors', () => {
|
|
const result = runGsdTools('validate bogus', tmpDir);
|
|
assert.strictEqual(result.success, false, 'Should exit non-zero');
|
|
assert.ok(result.error.includes('Unknown validate subcommand'), `Expected "Unknown validate subcommand" in stderr, got: ${result.error}`);
|
|
});
|
|
|
|
// Unknown subcommand: todo
|
|
test('todo unknown subcommand errors', () => {
|
|
const result = runGsdTools('todo bogus', tmpDir);
|
|
assert.strictEqual(result.success, false, 'Should exit non-zero');
|
|
assert.ok(result.error.includes('Unknown todo subcommand'), `Expected "Unknown todo subcommand" in stderr, got: ${result.error}`);
|
|
});
|
|
|
|
test('uat unknown subcommand errors', () => {
|
|
const result = runGsdTools('uat bogus', tmpDir);
|
|
assert.strictEqual(result.success, false, 'Should exit non-zero');
|
|
assert.ok(result.error.includes('Unknown uat subcommand'), `Expected "Unknown uat subcommand" in stderr, got: ${result.error}`);
|
|
});
|
|
|
|
// Unknown subcommand: init
|
|
test('init unknown workflow errors', () => {
|
|
const result = runGsdTools('init bogus', tmpDir);
|
|
assert.strictEqual(result.success, false, 'Should exit non-zero');
|
|
assert.ok(result.error.includes('Unknown init workflow'), `Expected "Unknown init workflow" in stderr, got: ${result.error}`);
|
|
});
|
|
});
|
|
|
|
// ─── --project-dir (#3881) ────────────────────────────────────────────────────
|
|
//
|
|
// docs/CONFIGURATION.md's "Project-Root Resolution in Multi-Repo Workspaces"
|
|
// section documents an explicit `--project-dir /path/to/workspace` flag that
|
|
// is "idempotent under this resolution" — i.e. it names the project root
|
|
// directly and skips findProjectRoot's ancestor walk-up entirely. Before this
|
|
// fix the flag was documented but wired nowhere: `state json --project-dir
|
|
// <abs>` run from an unrelated cwd silently resolved from cwd instead and
|
|
// returned `{"error":"STATE.md not found"}`.
|
|
|
|
const MARKER_3881 = 'PROJECT-B-MARKER-3881';
|
|
|
|
function writeMarkedState3881(projectDir, marker) {
|
|
fs.writeFileSync(
|
|
path.join(projectDir, '.planning', 'STATE.md'),
|
|
`---
|
|
gsd_state_version: 1.0
|
|
current_phase: 01
|
|
status: paused
|
|
stopped_at: ${marker}
|
|
---
|
|
|
|
# Project State
|
|
|
|
**Current Phase:** 01
|
|
**Status:** Paused
|
|
`
|
|
);
|
|
}
|
|
|
|
describe('#3881: --project-dir honors the documented explicit override', () => {
|
|
test('absolute --project-dir from an unrelated cwd operates on the named project', () => {
|
|
const projectA = createTempProject('fix-3881-a-'); // unrelated cwd; no STATE.md
|
|
const projectB = createTempProject('fix-3881-b-');
|
|
writeMarkedState3881(projectB, MARKER_3881);
|
|
|
|
try {
|
|
const result = runGsdTools(['state', 'json', '--project-dir', projectB], projectA);
|
|
assert.ok(result.success, `expected success, got: ${result.error || result.output}`);
|
|
const output = JSON.parse(result.output);
|
|
assert.strictEqual(
|
|
output.stopped_at,
|
|
MARKER_3881,
|
|
"must read STATE.md from --project-dir's project, not from cwd (projectA has no STATE.md at all)"
|
|
);
|
|
} finally {
|
|
cleanup(projectA);
|
|
cleanup(projectB);
|
|
}
|
|
});
|
|
|
|
test('relative --project-dir resolves against cwd', () => {
|
|
const projectA = createTempProject('fix-3881-a-');
|
|
// createTempProject mkdtemps under os.tmpdir(), so projectA and projectB
|
|
// are siblings — a relative path from A to B is well-formed.
|
|
const projectB = createTempProject('fix-3881-b-');
|
|
writeMarkedState3881(projectB, MARKER_3881);
|
|
|
|
try {
|
|
const relative = path.relative(projectA, projectB);
|
|
const result = runGsdTools(['state', 'json', '--project-dir', relative], projectA);
|
|
assert.ok(result.success, `expected success, got: ${result.error || result.output}`);
|
|
const output = JSON.parse(result.output);
|
|
assert.strictEqual(output.stopped_at, MARKER_3881, 'relative --project-dir must resolve against cwd (projectA)');
|
|
} finally {
|
|
cleanup(projectA);
|
|
cleanup(projectB);
|
|
}
|
|
});
|
|
|
|
test('nonexistent --project-dir path errors with non-zero exit', () => {
|
|
const projectA = createTempProject('fix-3881-a-');
|
|
try {
|
|
const nonexistent = path.join(projectA, 'does-not-exist-3881');
|
|
const result = runGsdTools(['state', 'json', '--project-dir', nonexistent], projectA);
|
|
assert.strictEqual(result.success, false, 'a nonexistent --project-dir must be a non-zero exit, not a silent fallback');
|
|
assert.match(result.error || '', /Invalid --project-dir/, 'error must name the invalid flag/path');
|
|
} finally {
|
|
cleanup(projectA);
|
|
}
|
|
});
|
|
|
|
test('--project-dir path with no .planning/ errors with non-zero exit', () => {
|
|
const projectA = createTempProject('fix-3881-a-');
|
|
const bareDir = fs.mkdtempSync(path.join(require('node:os').tmpdir(), 'fix-3881-bare-'));
|
|
try {
|
|
const result = runGsdTools(['state', 'json', '--project-dir', bareDir], projectA);
|
|
assert.strictEqual(result.success, false, 'a --project-dir with no .planning/ must be a non-zero exit, not a silent wrong-project resolve');
|
|
assert.match(result.error || '', /Invalid --project-dir/, 'error must name the invalid flag/path');
|
|
} finally {
|
|
cleanup(projectA);
|
|
cleanup(bareDir);
|
|
}
|
|
});
|
|
|
|
test('without --project-dir, behavior is unchanged (cwd-relative resolution still applies)', () => {
|
|
const projectB = createTempProject('fix-3881-b-');
|
|
writeMarkedState3881(projectB, MARKER_3881);
|
|
try {
|
|
const result = runGsdTools(['state', 'json'], projectB);
|
|
assert.ok(result.success, `expected success, got: ${result.error || result.output}`);
|
|
const output = JSON.parse(result.output);
|
|
assert.strictEqual(output.stopped_at, MARKER_3881, 'no-flag invocation must still resolve from cwd exactly as before');
|
|
} finally {
|
|
cleanup(projectB);
|
|
}
|
|
});
|
|
});
|
|
|
|
// ─── Dispatcher Routing Branches ─────────────────────────────────────────────
|
|
|
|
describe('dispatcher routing branches', () => {
|
|
let tmpDir;
|
|
|
|
beforeEach(() => {
|
|
tmpDir = createTempProject();
|
|
});
|
|
|
|
afterEach(() => {
|
|
cleanup(tmpDir);
|
|
});
|
|
|
|
// find-phase
|
|
test('find-phase locates phase directory by number', () => {
|
|
const phaseDir = path.join(tmpDir, '.planning', 'phases', '01-test-phase');
|
|
fs.mkdirSync(phaseDir, { recursive: true });
|
|
|
|
const result = runGsdTools('find-phase 01', tmpDir);
|
|
assert.strictEqual(result.success, true, `find-phase failed: ${result.error}`);
|
|
assert.ok(result.output.includes('01-test-phase'), `Expected output to contain "01-test-phase", got: ${result.output}`);
|
|
});
|
|
|
|
// init resume
|
|
test('init resume returns valid JSON', () => {
|
|
fs.writeFileSync(
|
|
path.join(tmpDir, '.planning', 'STATE.md'),
|
|
'# Project State\n\n## Current Position\n\nPhase: 1 of 1 (Test)\nPlan: 01-01 complete\nStatus: Ready\nLast activity: 2026-01-01\n\nProgress: [##########] 100%\n\n## Session Continuity\n\nLast session: 2026-01-01\nStopped at: Test\nResume file: None\n'
|
|
);
|
|
|
|
const result = runGsdTools('init resume', tmpDir);
|
|
assert.strictEqual(result.success, true, `init resume failed: ${result.error}`);
|
|
const parsed = JSON.parse(result.output);
|
|
assert.ok(typeof parsed === 'object', 'Output should be valid JSON object');
|
|
});
|
|
|
|
// init verify-work
|
|
test('init verify-work returns valid JSON', () => {
|
|
// Create STATE.md
|
|
fs.writeFileSync(
|
|
path.join(tmpDir, '.planning', 'STATE.md'),
|
|
'# Project State\n\n## Current Position\n\nPhase: 1 of 1 (Test)\nPlan: 01-01 complete\nStatus: Ready\nLast activity: 2026-01-01\n\nProgress: [##########] 100%\n\n## Session Continuity\n\nLast session: 2026-01-01\nStopped at: Test\nResume file: None\n'
|
|
);
|
|
|
|
// Create ROADMAP.md with phase section
|
|
fs.writeFileSync(
|
|
path.join(tmpDir, '.planning', 'ROADMAP.md'),
|
|
'# Roadmap\n\n## Milestone: v1.0 Test\n\n### Phase 1: Test Phase\n**Goal**: Test goal\n**Depends on**: None\n**Requirements**: TEST-01\n**Success Criteria**:\n 1. Tests pass\n**Plans**: 1 plan\nPlans:\n- [x] 01-01-PLAN.md\n\n## Progress\n\n| Phase | Plans | Status | Date |\n|-------|-------|--------|------|\n| 1 | 1/1 | Complete | 2026-01-01 |\n'
|
|
);
|
|
|
|
// Create phase dir
|
|
const phaseDir = path.join(tmpDir, '.planning', 'phases', '01-test');
|
|
fs.mkdirSync(phaseDir, { recursive: true });
|
|
|
|
const result = runGsdTools('init verify-work 01', tmpDir);
|
|
assert.strictEqual(result.success, true, `init verify-work failed: ${result.error}`);
|
|
const parsed = JSON.parse(result.output);
|
|
assert.ok(typeof parsed === 'object', 'Output should be valid JSON object');
|
|
});
|
|
|
|
// roadmap update-plan-progress
|
|
test('roadmap update-plan-progress updates phase progress', () => {
|
|
// Create ROADMAP.md with progress table
|
|
fs.writeFileSync(
|
|
path.join(tmpDir, '.planning', 'ROADMAP.md'),
|
|
'# Roadmap\n\n## Milestone: v1.0 Test\n\n### Phase 1: Test Phase\n**Goal**: Test goal\n**Depends on**: None\n**Requirements**: TEST-01\n**Success Criteria**:\n 1. Tests pass\n**Plans**: 1 plan\nPlans:\n- [ ] 01-01-PLAN.md\n\n## Progress\n\n| Phase | Plans | Status | Date |\n|-------|-------|--------|------|\n| 1 | 0/1 | Not Started | - |\n'
|
|
);
|
|
|
|
// Create phase dir with PLAN and SUMMARY
|
|
const phaseDir = path.join(tmpDir, '.planning', 'phases', '01-test-phase');
|
|
fs.mkdirSync(phaseDir, { recursive: true });
|
|
fs.writeFileSync(
|
|
path.join(phaseDir, '01-01-PLAN.md'),
|
|
'---\nphase: 01-test-phase\nplan: "01"\n---\n\n# Plan\n'
|
|
);
|
|
fs.writeFileSync(
|
|
path.join(phaseDir, '01-01-SUMMARY.md'),
|
|
'---\nphase: 01-test-phase\nplan: "01"\n---\n\n# Summary\n'
|
|
);
|
|
|
|
const result = runGsdTools('roadmap update-plan-progress 1', tmpDir);
|
|
assert.strictEqual(result.success, true, `roadmap update-plan-progress failed: ${result.error}`);
|
|
});
|
|
|
|
// state (no subcommand) — default load
|
|
test('state with no subcommand calls cmdStateLoad', () => {
|
|
fs.writeFileSync(
|
|
path.join(tmpDir, '.planning', 'STATE.md'),
|
|
'# Project State\n\n## Current Position\n\nPhase: 1 of 1 (Test)\nPlan: 01-01 complete\nStatus: Ready\nLast activity: 2026-01-01\n\nProgress: [##########] 100%\n\n## Session Continuity\n\nLast session: 2026-01-01\nStopped at: Test\nResume file: None\n'
|
|
);
|
|
|
|
const result = runGsdTools('state', tmpDir);
|
|
assert.strictEqual(result.success, true, `state load failed: ${result.error}`);
|
|
const parsed = JSON.parse(result.output);
|
|
assert.ok(typeof parsed === 'object', 'Output should be valid JSON object');
|
|
});
|
|
|
|
// summary-extract
|
|
test('summary-extract parses SUMMARY.md frontmatter', () => {
|
|
const phaseDir = path.join(tmpDir, '.planning', 'phases', '01-test');
|
|
fs.mkdirSync(phaseDir, { recursive: true });
|
|
|
|
const summaryContent = `---
|
|
phase: 01-test
|
|
plan: "01"
|
|
subsystem: testing
|
|
tags: [node, test]
|
|
duration: 5min
|
|
completed: "2026-01-01"
|
|
key-decisions:
|
|
- "Used node:test"
|
|
requirements-completed: [TEST-01]
|
|
---
|
|
|
|
# Phase 1 Plan 01: Test Summary
|
|
|
|
**Tests added for core module**
|
|
`;
|
|
|
|
const summaryPath = path.join(phaseDir, '01-01-SUMMARY.md');
|
|
fs.writeFileSync(summaryPath, summaryContent);
|
|
|
|
// Use relative path from tmpDir
|
|
const result = runGsdTools(`summary-extract .planning/phases/01-test/01-01-SUMMARY.md`, tmpDir);
|
|
assert.strictEqual(result.success, true, `summary-extract failed: ${result.error}`);
|
|
const parsed = JSON.parse(result.output);
|
|
assert.ok(typeof parsed === 'object', 'Output should be valid JSON object');
|
|
assert.strictEqual(parsed.path, '.planning/phases/01-test/01-01-SUMMARY.md', 'Path should match input');
|
|
assert.deepStrictEqual(parsed.requirements_completed, ['TEST-01'], 'requirements_completed should contain TEST-01');
|
|
});
|
|
});
|
|
|
|
|
|
// ────────────────────────────────────────────────────────────────────────
|
|
// Folded from tests/bug-3019-help-passthrough.test.cjs — consolidation epic #1969 (B6 #1975)
|
|
// ────────────────────────────────────────────────────────────────────────
|
|
{
|
|
const { describe: __foldDescribe } = require('node:test');
|
|
__foldDescribe("folded:bug-3019-help-passthrough (consolidation epic #1969 B6 #1975)", () => {
|
|
/**
|
|
* Regression test for bug #3019.
|
|
*
|
|
* `gsd-sdk query <subcommand> --help` returned the top-level SDK USAGE
|
|
* instead of contextual help for the subcommand. The query argv parser
|
|
* harvested --help as a global flag and main() short-circuited dispatch
|
|
* before the registry handler / gsd-tools.cjs fallback could render
|
|
* useful help.
|
|
*
|
|
* Two-layer fix:
|
|
* 1. sdk/src/cli.ts — leave --help in queryArgv so it travels to the
|
|
* handler/fallback. Only honor the global help flag when there is
|
|
* no subcommand to dispatch to.
|
|
* 2. gsd-core/bin/gsd-tools.cjs — render the top-level usage on
|
|
* --help instead of erroring. Anti-hallucination invariant from
|
|
* #1818 is preserved (the destructive command never executes).
|
|
*
|
|
* Tests the integration: invoke gsd-tools.cjs the same way the SDK
|
|
* dispatcher does and assert structured-IR (success flag + usage shape)
|
|
* rather than raw substring matches.
|
|
*/
|
|
|
|
'use strict';
|
|
|
|
const { describe, test } = require('node:test');
|
|
const assert = require('node:assert/strict');
|
|
const { runGsdTools, isUsageOutput } = require('./helpers.cjs');
|
|
|
|
// #3026 CR (Major outside-diff): the SDK fallback wraps gsd-tools.cjs.
|
|
// When gsd-tools emits plain-text help (exit 0), the SDK previously
|
|
// JSON.parsed stdout and threw "Unexpected token 'U'". Verify the fix
|
|
// by invoking the built SDK end-to-end and asserting:
|
|
// - exit 0
|
|
// - stdout contains the gsd-tools usage
|
|
// - stderr does NOT contain a JSON parse error
|
|
const path = require('node:path');
|
|
const { spawnSync } = require('node:child_process');
|
|
const SDK_CLI = path.join(__dirname, '..', 'sdk', 'dist', 'cli.js');
|
|
const fs = require('node:fs');
|
|
|
|
describe('bug #3026 (CR Major outside-diff): SDK forwards plain-text help from gsd-tools fallback', () => {
|
|
test('gsd-sdk query phase --help (fallback path) returns usage, not a JSON parse error', (t) => {
|
|
if (!fs.existsSync(SDK_CLI)) {
|
|
// CR feedback (#3026): a bare `return` here silent-passes the test
|
|
// when sdk/dist/cli.js is absent (CI checkouts that haven't run
|
|
// `npm run build`), giving no signal that the integration check
|
|
// was skipped. Use t.skip() so the omission is visible in the
|
|
// test report. The unit-level fix is covered by vitest on
|
|
// sdk/src/cli.ts; this integration test only runs when the
|
|
// built SDK is on disk.
|
|
t.skip('sdk/dist/cli.js not built — run `npm run build` in sdk/ to enable this integration test');
|
|
return;
|
|
}
|
|
// `query phase --help` (no further subcommand) is NOT in the native
|
|
// registry, so it routes through the gsd-tools.cjs fallback. That is
|
|
// the path that JSON.parsed the help text and threw before this fix.
|
|
const result = spawnSync(process.execPath, [SDK_CLI, 'query', 'phase', '--help'], {
|
|
encoding: 'utf8',
|
|
stdio: ['ignore', 'pipe', 'pipe'],
|
|
timeout: 10000,
|
|
});
|
|
// The fallback gsd-tools.cjs emits exit 0 with usage on stdout.
|
|
assert.strictEqual(result.status, 0,
|
|
`must exit 0 — got ${result.status}\nstdout: ${result.stdout}\nstderr: ${result.stderr}`);
|
|
// Negative: must NOT see the JSON parse error that was the regression.
|
|
assert.ok(!/Unexpected token|not valid JSON/i.test(result.stderr),
|
|
`must NOT JSON.parse the help text (stderr): ${result.stderr}`);
|
|
// Positive: the usage should reach the user via stdout.
|
|
assert.ok(/Usage:\s*gsd-tools/.test(result.stdout) && /Commands:/.test(result.stdout),
|
|
`usage must reach stdout: ${result.stdout}`);
|
|
});
|
|
});
|
|
|
|
describe('bug #3019: gsd-tools renders usage on --help instead of erroring', () => {
|
|
test('bare gsd-tools (no args) renders usage', () => {
|
|
const result = runGsdTools([]);
|
|
// No args path: error() helper emits to stderr and exits non-zero,
|
|
// but the message body is the usage.
|
|
assert.strictEqual(result.success, false);
|
|
assert.ok(/Usage:\s*gsd-tools/.test(result.error));
|
|
assert.ok(/Commands:/.test(result.error));
|
|
});
|
|
|
|
test('gsd-tools --help renders usage on stdout, exits 0', () => {
|
|
const result = runGsdTools(['--help']);
|
|
assert.strictEqual(result.success, true, '--help should not be an error');
|
|
assert.ok(isUsageOutput(result.output), `expected usage on stdout, got: ${result.output}`);
|
|
});
|
|
|
|
test('gsd-tools -h renders usage on stdout, exits 0', () => {
|
|
const result = runGsdTools(['-h']);
|
|
assert.strictEqual(result.success, true);
|
|
assert.ok(isUsageOutput(result.output));
|
|
});
|
|
|
|
test('gsd-tools <subcommand> --help renders usage (does not run subcommand)', () => {
|
|
// The classic #3019 surface: the user types a subcommand expecting
|
|
// contextual help. We render the top-level usage — strictly better
|
|
// than the previous unhelpful "Unknown flag --help" error.
|
|
const result = runGsdTools(['phase', 'add', '--help']);
|
|
assert.strictEqual(result.success, true);
|
|
assert.ok(isUsageOutput(result.output));
|
|
});
|
|
|
|
test('usage hint mentions how to discover argument requirements', () => {
|
|
// The usage now points users at the discovery method that actually works
|
|
// (run without args → error message names required arguments). Asserting
|
|
// on the parsed shape of the usage rather than substring-matching prose:
|
|
const result = runGsdTools(['--help']);
|
|
assert.strictEqual(result.success, true);
|
|
// Structural check: split into sections.
|
|
const lines = result.output.split('\n');
|
|
const hasUsageLine = lines.some((l) => l.startsWith('Usage:'));
|
|
const hasCommandsLine = lines.some((l) => l.startsWith('Commands:'));
|
|
const hasDiscoveryHint = lines.some((l) => /argument requirements|without args|invoke the command/i.test(l));
|
|
assert.ok(hasUsageLine, 'first section: Usage');
|
|
assert.ok(hasCommandsLine, 'second section: Commands');
|
|
assert.ok(hasDiscoveryHint, 'third section: how to discover per-command args');
|
|
});
|
|
});
|
|
});
|
|
}
|