--- phase: 04 slug: cli-scaffolding-i18n-and-mail status: draft nyquist_compliant: false wave_0_complete: false created: 2026-09-18 --- # Phase 4 — Validation Strategy ## Test Infrastructure | Property | Value | |---|---| | Framework | Go 1.27 `testing`; existing `testcontainers-go` convention for Docker integration | | Config | Root `go.mod`, `go.work`, and `examples/hello/go.mod` | | Quick run | `go test ./internal/build ./cmd/summer ./phrasebook ./postcard -short` after those packages exist | | Full suite | `go vet ./... && go test ./...` followed by focused Mailpit SMTP integration and `go test -race ./internal/build ./phrasebook ./postcard` | | Estimated runtime | Measure at implementation; require focused checks to stay under 60 seconds on a warm cache | ## Sampling Rate - After every task commit: run the affected package's focused test, or the generated-plugin build/vet test for scaffold changes. - After every plan wave: run root `go vet ./... && go test ./...` and, once generation exists, the temporary hello-plugin compile/vet test. - Before `$gsd-verify-work`: run the full suite including Mailpit SMTP receipt; Docker absence is a failure outside `-short`. - Maximum feedback latency: 60 seconds for focused tests on a warm cache; Mailpit starts only at the full gate. ## Per-Task Verification Map | Task ID | Plan | Wave | Requirement | Threat Ref | Secure Behavior | Test Type | Automated Command | File Exists | Status | |---|---|---|---|---|---|---|---|---|---| | 04-01-01 | 01 | 1 | CLI-02 | T-04-01 | Plugin paths stay under the app root | compile smoke | `go test ./internal/build -run TestScaffoldPluginSmoke -short -count=1` | ❌ W0 | ⬜ pending | | 04-01-02 | 01 | 1 | CLI-02 | T-04-01, T-04-03 | Model, migration and command registry is deterministic | compile smoke | `go test ./internal/build ./cmd/summer -short -count=1` | ❌ W0 | ⬜ pending | | 04-01-03 | 01 | 1 | CLI-02 | T-04-02 | All artifacts compile and sibling model imports fail | compile smoke | `go test ./internal/build ./cmd/summer -short -count=1` | ❌ W0 | ⬜ pending | | 04-02-01 | 02 | 2 | I18N-01 | T-04-04 | Embedded catalog has bounded namespace and valid YAML | unit/hello | `go test ./phrasebook -run TestTranslationSmoke -short -count=1 && go -C examples/hello test ./...` | ❌ W0 | ⬜ pending | | 04-02-02 | 02 | 2 | I18N-01 | T-04-04, T-04-05 | Invalid plurals fail and CLDR forms select correctly | unit | `go test ./phrasebook -short -count=1` | ❌ W0 | ⬜ pending | | 04-02-03 | 02 | 2 | I18N-01 | T-04-06 | Missing-key logs exclude parameters | unit/hello | `go test ./phrasebook -short -count=1 && go -C examples/hello test ./...` | ❌ W0 | ⬜ pending | | 04-03-01 | 03 | 3 | I18N-03 | T-04-08, T-04-09 | Memory send renders safe subject, text and HTML | unit | `go test ./postcard -run TestMailRenderSmoke -short -count=1` | ❌ W0 | ⬜ pending | | 04-03-02 | 03 | 3 | I18N-03 | T-04-07 | Invalid template/layout fails named boot | unit/hello | `go test ./postcard -short -count=1 && go -C examples/hello test ./...` | ❌ W0 | ⬜ pending | | 04-03-03 | 03 | 3 | I18N-03 | T-04-10, T-04-11 | Explicit SMTP policy and driver errors | unit | `go test ./postcard -short -count=1` | ❌ W0 | ⬜ pending | | 04-04-01 | 04 | 4 | CLI-02 | T-04-12 | Public make/build flow rejects traversal and import violations | regression | `go test ./internal/build ./cmd/summer -short -count=1` | ❌ W0 | ⬜ pending | | 04-04-02 | 04 | 4 | I18N-01 | T-04-13 | Catalog, plural and fallback edge cases hold at activation | regression/hello | `go test ./phrasebook ./party -short -count=1 && go -C examples/hello test ./...` | ❌ W0 | ⬜ pending | | 04-04-03 | 04 | 4 | I18N-03 | T-04-14, T-04-15 | Rendered HTML and SMTP receipt pass full gate | integration | `./scripts/check-phase4.sh` | ❌ W0 | ⬜ pending | *Status: ⬜ pending · ✅ green · ❌ red · ⚠️ flaky* ## Wave 0 Requirements - [ ] Add an `internal/build` test that generates all six artifacts into a temporary copy of `examples/hello` and runs `go build` plus `go vet` there. - [ ] Add `phrasebook` fixture plugin assets for pl/en YAML, nested keys, map and pipe plurals, and fallback tests. - [ ] Add `postcard` memory-driver rendering tests, malicious-variable cases, and a Mailpit testcontainer fixture with SMTP and HTTP ports. No new test framework is needed. These fixtures should be created by the first implementation task that uses them. ## Manual-Only Verifications All phase behaviors have automated verification. Production SMTP credentials and transport are deployment configuration, so the phase uses Mailpit for a real SMTP receipt without a live external account. ## Validation Sign-Off - [ ] Every plan task has an automated `` command or a Wave 0 dependency. - [ ] No three consecutive tasks lack automated verification. - [ ] Generated plugin compiles and vets; pl/en catalog and Mailpit send pass. - [ ] No watch-mode flags in verification commands. - [x] Fill task IDs from the four approved plans; measure runtime after implementation evidence exists. - [ ] Set `nyquist_compliant: true` only after the full gate passes. **Approval:** pending.