--- phase: 01-framework-kernel-foundation plan: 04 type: execute wave: 4 depends_on: ["01-03"] files_modified: - compass/config_test.go - party/registry_test.go - backpack/services_test.go - festival/bus_test.go - towel/context_test.go - bonfire/output_test.go - bonfire/prompts_test.go - internal/build/build_test.go - internal/dev/watch_test.go - examples/hello/hello_test.go - scripts/check-phase1.sh - .planning/phases/01-framework-kernel-foundation/01-VALIDATION.md autonomous: true requirements: [KERN-01, KERN-02, KERN-03, KERN-04, KERN-05, KERN-06, KERN-07, KERN-08, KERN-09, CLI-01] must_haves: truths: - "Every KERN-01 through KERN-09 and CLI-01 contract has a behavioral test, including failure and non-TTY paths." - "The final check runs `go vet`, `go test`, and `go test -race` in the framework, hello app and each hello plugin module." - "A temporary app can run `summer build` and its generated binary; source edit under `summer dev` records measured rebuild time and restarts the child." artifacts: - path: scripts/check-phase1.sh provides: Repeatable phase-wide verification command - path: compass/config_test.go provides: Config precedence regression tests - path: festival/bus_test.go provides: Event dispatch regression tests - path: examples/hello/hello_test.go provides: Built-app integration test key_links: - from: scripts/check-phase1.sh to: examples/hello/go.mod via: Checks nested app and plugin modules independently - from: examples/hello/hello_test.go to: cmd/summer/main.go via: Builds and executes a generated app binary --- As a framework maintainer, I can run one repeatable check that proves the Phase 1 kernel and development loop before Phase 3 depends on them. Purpose: Add the phase's dedicated unit and integration test plan, with broad behavior and failure coverage. Output: Focused Go tests, a nested-module check script, a generated-binary smoke and completed Nyquist validation map. @$HOME/.codex/get-shit-done/workflows/execute-plan.md @$HOME/.codex/get-shit-done/templates/summary.md @.planning/PROJECT.md @.planning/ROADMAP.md @.planning/REQUIREMENTS.md @.planning/phases/01-framework-kernel-foundation/01-CONTEXT.md @.planning/phases/01-framework-kernel-foundation/01-RESEARCH.md @.planning/phases/01-framework-kernel-foundation/01-VALIDATION.md @.planning/phases/01-framework-kernel-foundation/01-03-SUMMARY.md Task 1: Cover config, lifecycle, services, events and context behavior compass/config_test.go, party/registry_test.go, backpack/services_test.go, festival/bus_test.go, towel/context_test.go compass/config.go, compass/env.go, compass/persist.go, party/registry.go, backpack/app.go, backpack/services.go, festival/bus.go, towel/context.go, compass/config_test.go, party/registry_test.go, backpack/services_test.go, festival/bus_test.go, towel/context_test.go, .planning/phases/01-framework-kernel-foundation/01-CONTEXT.md Expand earlier smoke tests into table-driven behavioral tests for all config precedence levels, malformed YAML, snake_case env keys, `.env` non-override, dotted plugin namespace, typed section decode, Set/Persist/Reload and concurrent reads. Test plugin duplicate/missing/cycle errors, reordered manifest inputs, all-Register-before-any-Boot, HasConfig/HasCommands assertions, absent/present HasPlugin and typed service lookup with two separate App instances. Test three typed event dispatch modes, priority and stable ties, partial collect payload, joined errors, stop-on-error, owner-labelled panic recovery and concurrent independent app buses. Test actor/organization/collection/locale context accessors and nested context isolation. Fix any production defect exposed by these tests in the same task, keeping API behavior from D-01–D-13 intact. Report per-package coverage for these packages; cover contract branches rather than chasing an arbitrary percentage. go test -race ./compass ./party ./backpack ./festival ./towel ./pact - Each KERN-01/02/03/05/06/07/08 behavior above has at least one source-to-observable assertion. - `go test -race ./compass ./party ./backpack ./festival ./towel ./pact` exits 0. - No test asserts only implementation structure when a behavior can be observed. The kernel's core behavioral and failure contracts are regression tested. Task 2: Cover tool, output, watch loop and every workspace module bonfire/output_test.go, bonfire/prompts_test.go, internal/build/build_test.go, internal/dev/watch_test.go, examples/hello/hello_test.go, scripts/check-phase1.sh, .planning/phases/01-framework-kernel-foundation/01-VALIDATION.md bonfire/root.go, bonfire/output.go, bonfire/widgets.go, bonfire/prompts.go, internal/build/build.go, internal/build/manifest.go, internal/build/scaffold.go, internal/dev/watch.go, cmd/summer/main.go, examples/hello/summer.yaml, bonfire/output_test.go, bonfire/prompts_test.go, internal/build/build_test.go, internal/dev/watch_test.go, examples/hello/hello_test.go, scripts/check-phase1.sh, .planning/phases/01-framework-kernel-foundation/01-VALIDATION.md Test namespaced command discovery and flag/argument parsing, injected output capture, all non-TTY widget/prompt fallbacks, `NO_COLOR`/`FORCE_COLOR`/`TERM=dumb` policy and closed stdin. In a temporary copied hello workspace, assert `make:plugin` minimal files, `plugin:add` idempotence, stable generated bytes, malicious ID/path rejection, `summer build` success, built hello command output and non-zero failure on invalid Requires. Use deterministic build/process hooks for debounce/cancellation tests, plus a real fsnotify temp-workspace edit for one successful rebuild/restart; capture and assert a `rebuild: ` line without assuming a threshold. Add `scripts/check-phase1.sh` that runs `go vet ./...`, `go test ./...` and `go test -race ./...` from root, `examples/hello`, and each nested plugin module; include built-binary integration. Update VALIDATION.md's per-task map/status and set `nyquist_compliant: true` only when every planned automated check exists and passes. Fix production defects the tests expose, while keeping this plan focused on verification. bash scripts/check-phase1.sh - `bash scripts/check-phase1.sh` exits 0 and names root, hello app, base, greeter and optional plugin modules. - Test suite observes `summer build` and a separately executed hello binary, not only package compilation. - Watch test observes a source-change rebuild, restart and measured latency line; generated-file edits do not loop. - Non-TTY spinner/progress/table/prompt and color policy assertions run without a terminal. - VALIDATION.md records passing automated checks and `nyquist_compliant: true` only after the full script passes. The phase has a repeatable, race-enabled verification command and completed validation evidence. ## Trust Boundaries | Boundary | Description | |---|---| | Test fixture input → tool/process | Malformed manifests and source edits should fail safely during local tooling. | ## STRIDE Threat Register | Threat ID | Category | Component | Disposition | Mitigation Plan | |---|---|---|---|---| | T-01-09 | Tampering | Manifest and scaffold inputs | mitigate | Add negative tests for invalid IDs, duplicate modules and path traversal. | | T-01-10 | Denial of service | Watch loop | mitigate | Test debounce, ignored outputs, failed build and child cleanup. | | T-01-11 | Information disclosure | CLI secret and config | mitigate | Assert secret prompt answer and config values do not leak into captured error/output streams. | - Run `bash scripts/check-phase1.sh` and inspect its per-module output. - Confirm `go test -race` passes in all five modules and `go vet` is green. - Record measured single-plugin rebuild time in 01-04-SUMMARY.md. - All ten phase requirement IDs have automated behavioral evidence. - The final testing plan runs after implementation and passes across all workspace modules. - VALIDATION.md can be signed off without missing tests or broken Wave 0 references. Create `.planning/phases/01-framework-kernel-foundation/01-04-SUMMARY.md` after completion.