Commit graph

1108 commits

Author SHA1 Message Date
Jeremy McSpadden
f5e9b00f47 fix: wire continue-here context-pressure monitor to send wrap-up signal at 70% (#916) 2026-03-17 11:44:12 -06:00
Tom Boucher
25292f8840 fix: missing STATE.md in fresh worktree deadlocks pre-dispatch health gate (#889) (#895) 2026-03-17 11:09:25 -06:00
Tom Boucher
2dd8f481a3 fix: clean stale runtime unit files for completed milestones on startup (#887) (#896) 2026-03-17 11:08:58 -06:00
Juan Francisco Lebrero
bdbe739ebc feat: headless orchestration skill + supervised mode (#905) 2026-03-17 11:08:15 -06:00
TÂCHES
1dd32c635f feat(M001): Verification Enforcement (#891)
* docs: project plan — 4 milestones

* chore(M001): record integration branch

* chore(M001/S01): auto-commit after research-slice

* docs(S01): add slice plan

* chore: update state to S01 execution

* chore(M001/S01/T01): auto-commit after execute-task

* chore(M001/S01/T02): auto-commit after execute-task

* chore(M001/S01/T03): auto-commit after execute-task

* chore(M001/S01): auto-commit after complete-slice

* chore(M001/S01): auto-commit after reassess-roadmap

* chore(M001/S02): auto-commit after research-slice

* docs(S02): add slice plan

* chore(M001/S02/T01): auto-commit after execute-task

* chore(M001/S02/T02): auto-commit after execute-task

* test(S02/T03): Added evidence_block_missing and evidence_block_placehol…

- src/resources/extensions/gsd/observability-validator.ts
- src/resources/extensions/gsd/tests/verification-evidence.test.ts

* chore(M001/S02): auto-commit after complete-slice

* chore(M001/S02): auto-commit after reassess-roadmap

* chore(M001/S03): auto-commit after research-slice

* docs(S03): add slice plan

* fix(S03/T01): Added `formatFailureContext` pure function and retry meta…

- src/resources/extensions/gsd/verification-gate.ts
- src/resources/extensions/gsd/verification-evidence.ts
- src/resources/extensions/gsd/tests/verification-gate.test.ts
- src/resources/extensions/gsd/tests/verification-evidence.test.ts

* fix(S03/T02): Wired verification gate auto-fix retry loop into auto.ts…

- src/resources/extensions/gsd/auto.ts

* chore(M001/S03): auto-commit after complete-slice

* chore(M001/S03): auto-commit after reassess-roadmap

* chore(M001/S04): auto-commit after research-slice

* docs(S04): add slice plan

* test(S04/T01): Added RuntimeError interface and captureRuntimeErrors()…

- src/resources/extensions/gsd/types.ts
- src/resources/extensions/gsd/verification-gate.ts
- src/resources/extensions/gsd/tests/verification-gate.test.ts

* test(S04/T02): Integrated captureRuntimeErrors() into auto.ts gate bloc…

- src/resources/extensions/gsd/auto.ts
- src/resources/extensions/gsd/verification-evidence.ts
- src/resources/extensions/gsd/tests/verification-evidence.test.ts

* chore(M001/S04): auto-commit after complete-slice

* chore(M001/S04): auto-commit after reassess-roadmap

* chore(M001/S05): auto-commit after research-slice

* docs(S05): add slice plan

* test(S05/T01): Added AuditWarning type, runDependencyAudit() with git d…

- "src/resources/extensions/gsd/types.ts"
- "src/resources/extensions/gsd/verification-gate.ts"
- "src/resources/extensions/gsd/tests/verification-gate.test.ts"

* feat(S05/T02): Wired runDependencyAudit() into the verification gate pi…

- src/resources/extensions/gsd/verification-evidence.ts
- src/resources/extensions/gsd/auto.ts
- src/resources/extensions/gsd/tests/verification-evidence.test.ts

* chore(M001/S05): auto-commit after complete-slice

* chore(M001): auto-commit after validate-milestone

* chore(M001): auto-commit after complete-milestone

* feat(M001): Verification Enforcement

Completed slices:
- S01: Built-in Verification Gate
- S02: Structured Evidence Format
- S03: Auto-Fix Retry Loop
- S04: Runtime Error Capture
- S05: Dependency Security Scan

Branch: milestone/M001

* chore(M002): record integration branch

* chore(M003): record integration branch

* chore(M004): record integration branch

* fix(M001): Address verification gate review feedback

1. Add 120s default timeout to spawnSync in runVerificationGate (configurable
   via commandTimeoutMs) — prevents hanging commands from deadlocking the system
2. Sanitize taskPlanVerify commands — reject strings containing ;, |, backticks,
   or $() shell injection patterns
3. Clear verificationRetryCount in pauseAuto — previously only
   pendingVerificationRetry was cleared, leaving stale retry state on resume

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix(ci): remove .gsd/ and .audits/ from tracking

These directories were accidentally included via M001 milestone
auto-commits. Both are already in .gitignore. The no-gsd-dir CI
check correctly catches this.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-17 09:47:12 -06:00
Jeremy McSpadden
23b89c64c9 fix: detect broken install and add Windows symlink fallback (#890)
Fixes #882 — npm install -g gsd-pi installing a broken version where
@gsd/pi-coding-agent cannot be resolved, causing ERR_MODULE_NOT_FOUND.

Root causes addressed:
1. On Windows without Developer Mode or admin rights, symlinkSync fails
   even for NTFS junctions, leaving node_modules/@gsd/ empty and causing
   a cryptic ERR_MODULE_NOT_FOUND instead of a usable error message.
2. If npm latest dist-tag is stale (pointing to an old version that
   predates the packages/ directory), users get the same failure.

Changes:
- src/loader.ts: after symlinking, validate @gsd/pi-coding-agent exists;
  emit a clear actionable error with reinstall instructions instead of
  letting Node throw ERR_MODULE_NOT_FOUND deep inside cli.js. Also adds
  cpSync fallback when symlinkSync fails (Windows without elevated perms).
- scripts/link-workspace-packages.cjs: same cpSync fallback — ensures
  postinstall succeeds on restricted Windows environments.
- scripts/validate-pack.js: verify @gsd/* packages are resolvable after
  the isolated install test, and run `gsd -v` to confirm end-to-end
  resolution before declaring the pack valid.
- .github/workflows/build-native.yml: add post-publish dist-tag
  verification step that confirms npm dist-tags.latest matches the
  published version for stable releases, catching stale-tag regressions
  in CI before users encounter them.
2026-03-17 09:35:57 -06:00
Tom Boucher
01a6294b23 feat: auto-restart headless mode on crash with exponential backoff (#886) (#897)
When the headless child process crashes or errors out, auto-restart
with exponential backoff (5s, 10s, 15s... up to 30s) instead of
exiting immediately. This enables overnight 'fire and forget' runs.

- --max-restarts N (default 3, 0 to disable): controls restart budget
- Only restarts on crashes (exit code !== 0), not on success or blocked
- SIGINT/SIGTERM bypasses restart (user intent to stop)
- Restart count shown in summary output
- Backoff prevents rapid crash loops from burning API credits

The inner loop function (runHeadlessOnce) returns exit status instead
of calling process.exit, letting the outer loop decide whether to
restart or terminate.

This is the first step toward the 'absolute autonomy' goal described
in #886 — process-level resilience for long-running sessions.
2026-03-17 09:35:33 -06:00
Lex Christopherson
d804c759bd 2.26.0 2026-03-17 09:15:58 -06:00
Lex Christopherson
8a566f85c8 docs: update changelog for v2.26.0
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-17 09:15:43 -06:00
Tom Boucher
ea9c5f7ee2 fix: headless mode exits early on progress notifications containing 'complete' (#879) (#888)
isTerminalNotification() used broad substring matching against
['complete', 'stopped', 'blocked']. Any notification containing these
words triggered early exit — including progress messages like:
  'All slices are complete — nothing to discuss.'
  'Override(s) resolved — rewrite-docs completed.'
  'Skipped 5+ completed units. Yielding to UI before continuing.'

Fix: Replace substring matching with prefix matching against the actual
stop signals emitted by stopAuto():
  'Auto-mode stopped...'
  'Step-mode stopped...'

These are the ONLY notifications that indicate auto-mode has genuinely
terminated. All other notifications (slice completion, override
resolution, skip yielding) are progress events and must not trigger
exit.

Also tighten isBlockedNotification to match 'blocked:' (with colon)
instead of bare 'blocked' to avoid false positives from unrelated
messages.

Added 15 regression tests covering:
- All real terminal notification variants
- 6 false-positive cases from the issue report
- Non-notify event rejection
- Blocked detection with and without colon
2026-03-17 09:11:34 -06:00
Tom Boucher
3542b17c97 fix: normalize Windows paths in LLM-visible text to prevent bash failures (#874) (#884)
On Windows, process.cwd() returns backslash paths (C:\Users\name\...).
When these paths are injected into system prompts, worktree context
blocks, or tool results, the model copies them into bash commands.
Bash interprets backslashes as escape characters, silently stripping
them — producing invalid paths like 'C:Usersnamedevelopmentapp-name'.

This is not a regex hack — it's a proper cross-platform boundary:
- Filesystem operations (fs, path.join, spawn cwd) use native paths
  unchanged. Node handles both separators correctly for I/O.
- LLM-visible text (prompts, tool results, extension messages) uses
  toPosixPath() to normalize to forward slashes. C:/Users/name/...
  is valid in Git Bash, WSL bash, PowerShell, and Node.js.

Changes:

- utils/path-display.ts: New toPosixPath() utility in pi-coding-agent
  package (for system prompt) and shared extension module (for
  extensions that can't import from the compiled package at dev time)

- system-prompt.ts: Normalize resolvedCwd before injecting into the
  'Current working directory' line

- gsd/index.ts: Normalize all process.cwd() and originalBase paths in
  worktree context blocks injected into the system prompt

- bg-shell/index.ts: Normalize cwd in tool result text (start, env
  actions) that the model reads and may reference in commands

- path-display.test.ts: 9 regression tests covering toPosixPath
  behavior and system prompt output verification. Includes a scanner
  that fails if any Windows absolute paths with backslashes appear in
  buildSystemPrompt() output.

Audit scope: Checked all process.cwd() usage across pi-coding-agent
and all bundled extensions. Filesystem-only paths (join, readFile,
spawn cwd, existsSync) are correct and left unchanged. Only paths
entering LLM text are normalized.
2026-03-17 09:02:23 -06:00
Tom Boucher
7a26d27e94 feat: add model type, provider, and API docs fields to bug report template (#877) 2026-03-17 08:42:25 -06:00
Tom Boucher
7e1fcd3549 fix: don't trigger LLM turns on async_bash job completion (#875) (#880) 2026-03-17 08:30:13 -06:00
Tom Boucher
62bbaa8e8e feat: integrate hashline edit mode into active workflow (#870) (#872) 2026-03-17 08:23:53 -06:00
Jeremy McSpadden
a8eb66b8b3 feat: group /model selector by provider (#871) 2026-03-17 08:23:29 -06:00
Tom Boucher
ae8b8eeca3 fix: limit native web_search to max_uses:5 per response (#817) (#869) 2026-03-17 08:23:05 -06:00
Tom Boucher
4c7c64f7f5 fix: completed milestone with summary re-entered as active on resume (#864) (#868) 2026-03-17 08:22:16 -06:00
Gary Trakhman
9fe046d3fa Revert PR #744 - symlink-based development workflow (#867) 2026-03-17 08:21:55 -06:00
Jeremy McSpadden
c66ad3485e fix: add replan-slice artifact verification to break infinite replanning-slice loop (#858) (#865) 2026-03-17 08:20:24 -06:00
Jeremy McSpadden
d06e9ca12e fix: auto-heal STATE.md missing in preDispatchHealthGate (#862) 2026-03-17 08:20:10 -06:00
Jeremy McSpadden
c209dd1118 fix: replace orphaned invalidateStateCache() calls with invalidateAllCaches() (#861) 2026-03-17 08:19:55 -06:00
Tom Boucher
16bda686a1 fix: sync project root artifacts into worktree before deriveState to prevent stale DB loop (#853) (#855) 2026-03-17 08:19:37 -06:00
Tom Boucher
0abc61987d fix: add Alt+V as clipboard image paste shortcut on macOS and document it (#852) (#854) 2026-03-17 08:19:13 -06:00
Tom Boucher
ac585908fa docs: add explicit Gemini OAuth ToS warning to README (#850) (#851) 2026-03-17 08:17:48 -06:00
Tom Boucher
8872c9095e fix: mark transient network errors as retriable in Anthropic provider (#833) (#849) 2026-03-17 08:17:25 -06:00
Tom Boucher
9175eb0aa3 fix: treat needs-remediation as terminal validation verdict to prevent hard loop (#832) (#848) 2026-03-17 08:03:06 -06:00
Tom Boucher
11d0b26858 fix: use fixLevel 'all' in post-hook doctor after complete-slice to fix roadmap checkboxes (#839) (#847) 2026-03-17 08:01:10 -06:00
Tom Boucher
1868aaeb02 feat: show discussion status indicators in /gsd discuss slice picker (#782) (#846) 2026-03-17 08:00:56 -06:00
Tom Boucher
33fff7bab0 feat: add require_slice_discussion option to pause auto-mode before each slice (#789) (#845) 2026-03-17 08:00:41 -06:00
Tom Boucher
84e772f086 fix: invalidate caches before initial state derivation in startAuto (#800) (#843) 2026-03-17 08:00:24 -06:00
Tom Boucher
1f67ce250b fix: make task_done_missing_summary fixable in doctor to prevent validate-milestone skip loop (#820) (#842) 2026-03-17 08:00:10 -06:00
Tom Boucher
d593b2e367 fix: handle BMP clipboard images on WSL2 via wl-paste PNG conversion or ImageMagick (#813) (#841) 2026-03-17 07:59:56 -06:00
Tom Boucher
a706b4bd96 fix: extend idle timeout for headless new-milestone to prevent premature exit (#808) (#840) 2026-03-17 07:59:40 -06:00
Tom Boucher
0873961550 fix: handle EPIPE in LSP sendNotification and wait for process exit on reload (#815) (#837) 2026-03-17 07:59:25 -06:00
Tom Boucher
4a43679bc0 fix: add debug logging to silent early-return paths in dispatchNextUnit (#823) (#836) 2026-03-17 07:59:13 -06:00
Tom Boucher
a7453719f5 fix: add fallback parser for prose-style roadmaps without ## Slices section (#807) (#835)
When the LLM writes freeform prose roadmaps with `## Slice S01: Title`
headers instead of the machine-readable `## Slices` checklist,
parseRoadmapSlices() returned zero slices, causing deriveState() to
permanently block with 'No slice eligible'.

Add a fallback parser that detects prose-style `## Slice SXX:` headers
(and variants like `## S01:`, `## S01 —`) and extracts slice IDs,
titles, and dependencies from the prose. Also parses `Depends on:`
text patterns. All fallback slices default to risk:medium and done:false.
2026-03-17 07:49:50 -06:00
Tom Boucher
2f459b5d03 fix: remove untracked .gsd/ state files before milestone merge checkout (#827) (#834)
When merging a milestone back to main, `git checkout main` fails if
untracked .gsd/ state files (STATE.md, completed-units.json, auto.lock)
in the working tree conflict with tracked files on the branch.

Remove these known GSD-managed state files before checkout. They are
runtime artifacts regenerated by doctor/rebuildState and are not
meaningful in the main working tree — the worktree had the real state.
2026-03-17 07:49:26 -06:00
Tom Boucher
d94728aa7e fix: prevent crash when cancelling OAuth provider login dialog (#821) (#831)
OAuthSelectorComponent calls its onSelect callback synchronously (no
await), but the callback was async — calling showLoginDialog which
throws 'Login cancelled' on Escape. The unhandled rejection bubbled
up to the uncaughtException handler and crashed GSD.

Wrap the async work in a named function with .catch() so cancellation
errors are swallowed gracefully. showLoginDialog already handles its
own error display internally.
2026-03-17 07:49:09 -06:00
Tom Boucher
776a8800d8 fix: include STATE.md, KNOWLEDGE.md, OVERRIDES.md in worktree artifact copy (#809) (#830)
Worktree initialization only copied DECISIONS.md, REQUIREMENTS.md,
PROJECT.md, and QUEUE.md. The missing STATE.md caused the pre-dispatch
health check in doctor-proactive.ts to block dispatch with
'STATE.md missing'.

Add STATE.md, KNOWLEDGE.md, and OVERRIDES.md to the copy list so
worktrees start with complete planning state.
2026-03-17 07:48:53 -06:00
Tom Boucher
c6d1bdd1cc fix: compare gsdVersion instead of syncedAt for resource staleness check (#804) (#829)
Every new pi session writes a fresh syncedAt timestamp to
managed-resources.json, causing a running auto-mode session to falsely
detect a GSD update and stop. The actual version (gsdVersion) only
changes on real upgrades.

Switch the staleness check from syncedAt (timestamp) to gsdVersion
(semver string) so that launching a second session no longer triggers
a false positive.
2026-03-17 07:48:38 -06:00
Tom Boucher
ef706726c8 fix: use unique temp paths in saveFile() to prevent parallel write collisions (#810) (#828)
When multiple tool calls (e.g. concurrent gsd_save_decision) target the
same markdown file, the deterministic .tmp suffix caused ENOENT on
rename() because one caller consumed the temp file before another could
rename it.

Replace the static `.tmp` suffix with a per-call random suffix so each
concurrent writer gets its own temp file. Also clean up orphaned temp
files on rename failure.
2026-03-17 07:48:18 -06:00
Tom Boucher
b44896e187 fix: generate validation and summary files for completed milestones during migration (#819) (#838)
The .planning → .gsd migration creates roadmaps and summaries but not
VALIDATION files. deriveState() requires a terminal validation file
(verdict: pass) to consider a milestone complete. Without it, every
migrated milestone enters validating-milestone phase, blocking progress
to the actual current milestone.

For milestones where all slices are done, write a pass-through
VALIDATION.md (verdict: pass, migrated: true) and SUMMARY.md so
deriveState() skips them correctly.

Updated integration test to verify VALIDATION/SUMMARY files are written
and deriveState returns 'complete' phase with activeMilestone pointing
to the last completed entry (expected behavior).
2026-03-17 07:47:57 -06:00
Tom Boucher
1aebc06c46 docs: update documentation for v2.24 release features (#825)
- README: add parallel orchestration link, update loop diagram with validate-milestone phase
- architecture: add lazy provider loading, memory-extractor/store modules, update module table to v2.24
- auto-mode: add rate limit recovery section, parallel worker status in dashboard
- commands: add headless new-milestone command with --context/--context-text/--auto flags
- getting-started: add update check notification note
- troubleshooting: update rate limit recovery guidance
- visualizer: add task counts, discussion status to progress tab
2026-03-17 07:47:28 -06:00
Adam Dry
68edb39f9e fix: add gsd_generate_milestone_id tool for multi-milestone unique ID generation (#818)
When unique_milestone_ids is enabled, the LLM cannot generate random
suffixes itself. Previously only the first milestone got a correct ID
(pre-generated in TS), while subsequent milestones in multi-milestone
projects got bare M002/M003 without suffixes.

Added a gsd_generate_milestone_id tool that the LLM calls to get each
milestone ID. The tool scans disk for existing milestones and respects
the unique_milestone_ids preference, making it impossible to produce
wrong-format IDs.

Updated discuss, discuss-headless, and queue prompts to instruct the
LLM to use the tool instead of inventing milestone IDs.
2026-03-17 07:47:11 -06:00
deseltrus
7c449b8b73 feat: worker NDJSON monitoring + budget enforcement for parallel orchestration (#814)
* feat: worker NDJSON monitoring, budget enforcement, PID-based stop fallback

Closes three gaps in parallel orchestration:

1. **Worker stdout monitoring** — Workers now run with `--mode json` so
   they emit NDJSON events. The coordinator parses stdout line-by-line,
   extracting cost/token data from `message_end` events. This keeps
   per-worker cost tracking in sync with actual API spend and updates
   session status files for live dashboard visibility.

2. **Budget enforcement before spawn** — `startParallel()` now checks
   `isBudgetExceeded()` before each worker spawn. When the aggregate
   cost across all workers reaches the configured ceiling, no new
   workers are started.

3. **PID-based stop fallback** — `stopParallel()` now falls back to
   `process.kill(pid, "SIGTERM")` when the ChildProcess handle is null
   (e.g., after coordinator restart when handles aren't available).
   Previously, orphaned workers could not be stopped.

Includes 11 new tests covering NDJSON format validation, cost
aggregation, budget ceiling comparison, and PID-based kill patterns.
All 54 existing parallel-orchestration tests still pass.

Relates to #672

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: currentUnit type must match SessionStatus interface (object | null, not string)

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-17 07:46:52 -06:00
Lex Christopherson
4883ed1e99 2.25.0
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-16 23:47:17 -06:00
Lex Christopherson
8c9b40cb5e docs: update changelog for v2.25.0
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-16 23:46:58 -06:00
TÂCHES
440e6e878f feat: render native web search in TUI + PREFER_BRAVE_SEARCH toggle (#806)
* feat: render native web search tool calls in TUI

The Anthropic streaming parser silently dropped server_tool_use and
web_search_tool_result content blocks, making native web search
invisible. Add ServerToolUseContent and WebSearchResultContent types,
handle both block types in the streaming parser and conversation replay,
and render them as ToolExecutionComponent in the interactive TUI.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* feat: add PREFER_BRAVE_SEARCH env var to bypass native web search

Set PREFER_BRAVE_SEARCH=1 to keep Brave/custom search tools active
on Anthropic models instead of injecting native server-side web search.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: skip non-toolCall blocks in Mistral provider conversation replay

The ServerToolUseContent and WebSearchResultContent types added for
native web search don't have id/name/arguments properties, causing
TypeScript errors when the Mistral provider tried to push them as
tool calls.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-16 23:35:20 -06:00
TÂCHES
3adacf3ff5 feat: meaningful commit messages from task summaries (#803)
* feat: meaningful commit messages from task summaries (#785, #784)

Post-task commits now derive messages from the task summary one-liner,
inferred type, and key files. Planning prompts respect commit_docs: false.
Commit type inference expanded with perf type and oneLiner parameter.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: replace invalidateStateCache with invalidateAllCaches in crash recovery

PR #799 reintroduced invalidateStateCache() calls in the phantom skip
loop crash recovery paths. These should use invalidateAllCaches() which
is the renamed function.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: resolve CI failures from main merge conflicts

- Replace invalidateStateCache() → invalidateAllCaches() in crash
  recovery paths (reintroduced by PR #799 merge)
- Expand smart-entry-draft test chunk window from 3000 to 4000 chars
  to accommodate commitInstruction additions

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-16 23:30:33 -06:00
TÂCHES
28bb77b999 Merge pull request #805 from jeremymcs/test/expand-e2e-smoke-tests
test: expand E2E smoke tests with 14 new CLI verification tests
2026-03-16 23:18:25 -06:00