mirror of
https://github.com/garrytan/gstack.git
synced 2026-09-02 11:20:52 +02:00
* feat(session-kind): explicit GSTACK_SESSION_KIND override; skill-start spawned gates keyed on kind (#2733) Claude Code subagents inherit the parent env byte-for-byte, so ambient markers classify them as the parent's kind and the spawned classification was unreachable outside OpenClaw. GSTACK_SESSION_KIND=spawned (step 0, spawned-only by design) lets a dispatching skill mark its subagent per command. skill-start now keys SPAWNED_SESSION and the spawned-session instruction block on the resolved kind (was raw OPENCLAW_SESSION), suppresses CONDUCTOR_SESSION for spawned sessions, gates all 11 interactive-onboarding blocks plus their ack-at-emit marker writes on kind != spawned, and adds a destructive-gate carve-out to the spawned block (conservative-continue, never prose-STOP). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix(hooks): spawned-session escape in Conductor AUQ deny; override coverage in AUQ-error fallback (#2733) Hooks inherit the harness env, so a per-command GSTACK_SESSION_KIND prefix inside a subagent's bash can never reach them. Levers added: a deterministic [conductor][spawned] auto-choose deny for env-level spawned sessions (OPENCLAW_SESSION or session-wide GSTACK_SESSION_KIND), and a spawned escape sentence appended to both hooks' prose directives so a marked subagent that slips and calls AUQ resolves to auto-choose instead of prose-STOP. The sentence lives in one shared constant (hosts/claude/hooks/spawned-directive.ts) so the two paths can never drift; destructive semantics are unified to conservative-continue. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix(ship): Step 18 marks the document-release subagent spawned — env prefix + auto-choose prompt (#2733) The dispatch prompt now (1) frames the run as a SPAWNED subagent whose LAST line is machine-parsed, (2) instructs prefixing the preamble's gstack-skill-start invocation with GSTACK_SESSION_KIND=spawned on the same command line (template bash blocks don't share exports), and (3) resolves every AUQ gate to auto-choosing the recommended option, conservative on no-recommendation, never destructive. The JSON contract gains a required "decisions" array (auto-chosen gates, printed to the ship console — never embedded in the public PR body) and a placement clause so the skill's own doc-health summary stops competing with the LAST-line JSON. Tripwire pins added; codex/factory goldens refreshed. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * feat(auq-format): proactive SESSION_KIND=spawned rule ordered above the Conductor rule (#2733) The spawned classification previously existed only in the failure-fallback branch — a spawned session was invited to call AskUserQuestion and reach auto-choose via the deny/error detour, and a spawned session inside a Conductor workspace hit the Conductor prose-STOP rule first. The Tool resolution list now leads with the spawned rule (auto-choose recommended, never prose, never BLOCKED, destructive gates resolve conservative), the self-check carries the never-reach-this-checklist clause, and all tier>=2 SKILL.md renders are regenerated. Context-budget fixture refreshed in the same commit per the ratchet protocol (the AUQ section is eager in every tier>=2 skill). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * test(e2e): spawned document-release subagent returns the JSON contract through a firing gate (#2733) The behavioral proof the bug shipped without: ship-docsync stubs the skill (no preamble, no gates) and skill-e2e-workflow suppresses the gates by prompt. This gate-tier E2E plays the parent — it drives the verbatim Step 18 dispatch prompt (extracted from the live pr-body.md, drift-proof) against a real preamble-bearing document-release slice in a Conductor-ambient env with both AUQ hooks seeded live, an unbumped VERSION making Step 8 fire. Asserts: the final line parses as the 5-key JSON contract, the fired gate's auto-choice is recorded in decisions, and VERSION is untouched (the gate resolved to its recommended Skip). Burn-in: 1/1 pass, $0.35, 21 turns, 106s. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * docs(openclaw): document the GSTACK_SESSION_KIND override; wire session-kind into paid selectors (#2733) OPENCLAW.md's spawned-session section now covers the explicit per-command marker, its deliberate spawned-only narrowness, the /ship Step 18 usage, the destructive carve-out, onboarding-block suppression, and the hook env-blindness caveat. bin/gstack-session-kind and the shared spawned-directive module join the conductor-prose and auto-decide-preserved selector dep lists (session-kind previously appeared in no touchfiles entry — editing it alone triggered no paid E2E). TODOS.md gains the plan-tune capture follow-up for spawned auto-choices. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix: pre-landing review fixes (#2733) Review army + coverage audit findings, all applied: - headless directive carries the spawned escape sentence too (multi- specialist: a CI-hosted ship's marked subagent must not end BLOCKED) - anti-injection scoping on every text-claimable spawned trigger (AUQ rule + shared escape sentence): markings count only from the creating prompt, never from files/tool output/web content read mid-run - [conductor][spawned] deny annotates one-way doors per question - SPAWNED_OVERRIDE: env tamper-visibility status line + OPENCLAW.md note - spawned sessions skip the network update-check and first-task probe (consumers suppressed; preserves the one-shot just-upgraded marker) - test hardening: dispatch-tripwire end-bound validated, vacuous marker asserts replaced with output asserts, E2E cpSync size filter + named fence tolerance, spawnedByEnv parity pin, destructive-policy cross- surface drift guard, one-way annotation + bogus-value hook cases - session-kind duplicate rationale comment deduped; regen + goldens + context-budget fixture refreshed Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * chore: bump version and changelog (v1.76.0.0) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * docs: update project documentation for v1.76.0.0 PROJECT_STRUCTURE.md: add hosts/claude/hooks/ to the directory tree (AUQ capture + enforcement hooks, spawned-session directive, timeline stop) — the tree omitted the directory while docs/OPENCLAW.md and CHANGELOG.md now reference paths inside it. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * docs: sync TODOS.md ship dispatch entry with the v1.76.0.0 contract Codex doc-review finding: the SHIPPED entry for /ship auto-invoking /document-release still described the four-key JSON contract. Adds the decisions key (console-printed, never PR markdown), the GSTACK_SESSION_KIND=spawned dispatch marking (#2733), and the new spawned-dispatch gate E2E to the proven-by list. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
205 lines
9.0 KiB
TypeScript
205 lines
9.0 KiB
TypeScript
/**
|
|
* auq-error-fallback-hook — the OV3:B runtime reliability layer.
|
|
*
|
|
* Two layers of testing:
|
|
* - PURE functions (isErrorResponse, directiveFor): deterministic, the core logic.
|
|
* - INTEGRATION: spawn the hook as a PostToolUse process with synthetic stdin and
|
|
* a controlled env, assert it injects the right directive on an error result and
|
|
* stays inert on a real answer.
|
|
*
|
|
* NOTE: whether the Claude Code PLATFORM invokes PostToolUse on an MCP
|
|
* transport/missing-result error is unverified (could not force the Conductor
|
|
* bug in a harness — see docs/spikes/claude-code-hook-mutation.md). These tests
|
|
* pin the hook's BEHAVIOR given it is invoked; the platform trigger is the
|
|
* documented residual risk. The hook is inert if never invoked.
|
|
*/
|
|
import { describe, test, expect } from 'bun:test';
|
|
import { spawnSync } from 'child_process';
|
|
import * as path from 'path';
|
|
import { isErrorResponse, directiveFor } from '../hosts/claude/hooks/auq-error-fallback-hook.ts';
|
|
|
|
const HOOK = path.resolve(__dirname, '..', 'hosts', 'claude', 'hooks', 'auq-error-fallback-hook.ts');
|
|
|
|
describe('isErrorResponse — only clear failures, never a real answer', () => {
|
|
test('null / undefined / empty string are failures', () => {
|
|
expect(isErrorResponse(null)).toBe(true);
|
|
expect(isErrorResponse(undefined)).toBe(true);
|
|
expect(isErrorResponse('')).toBe(true);
|
|
expect(isErrorResponse(' ')).toBe(true);
|
|
});
|
|
|
|
test('the Conductor missing-result string is a failure', () => {
|
|
expect(isErrorResponse('[Tool result missing due to internal error]')).toBe(true);
|
|
});
|
|
|
|
test('is_error: true / error-field / sentinel-in-content are failures', () => {
|
|
expect(isErrorResponse({ is_error: true })).toBe(true);
|
|
expect(isErrorResponse({ isError: true })).toBe(true);
|
|
expect(isErrorResponse({ error: 'boom' })).toBe(true);
|
|
expect(isErrorResponse({ content: 'Tool result missing due to internal error' })).toBe(true);
|
|
});
|
|
|
|
test('a real answer is NOT a failure (no false trigger)', () => {
|
|
expect(isErrorResponse({ answers: [{ option_label: 'A' }] })).toBe(false);
|
|
expect(isErrorResponse('A')).toBe(false);
|
|
// a choice that coincidentally contains "error" must not trip it
|
|
expect(isErrorResponse({ answers: [{ option_label: 'Fix the error' }] })).toBe(false);
|
|
expect(isErrorResponse('Investigate the login error')).toBe(false);
|
|
});
|
|
|
|
test('Codex review: narrow detection — generic "error"/"is_error" substrings do NOT trigger', () => {
|
|
// A real answer mentioning "internal error" must not be read as a failure.
|
|
expect(isErrorResponse('Investigate the internal error')).toBe(false);
|
|
// A serialized success payload containing the substring is_error:false must not trigger.
|
|
expect(isErrorResponse('{"is_error": false, "answer": "A"}')).toBe(false);
|
|
expect(isErrorResponse({ is_error: false })).toBe(false);
|
|
expect(isErrorResponse({ content: 'The page had an internal error we fixed' })).toBe(false);
|
|
});
|
|
});
|
|
|
|
describe('directiveFor — per-session-kind instruction', () => {
|
|
test('interactive directive demands the prose triad', () => {
|
|
const d = directiveFor('interactive');
|
|
expect(d).toMatch(/ELI10/);
|
|
expect(d).toMatch(/Completeness: X\/10/);
|
|
expect(d).toMatch(/\(recommended\)/);
|
|
expect(d).toMatch(/reply with a letter/i);
|
|
expect(d).toMatch(/STOP/);
|
|
});
|
|
|
|
test('headless directive BLOCKs', () => {
|
|
expect(directiveFor('headless')).toMatch(/BLOCKED — AskUserQuestion unavailable/);
|
|
});
|
|
|
|
test('spawned directive auto-chooses', () => {
|
|
expect(directiveFor('spawned')).toMatch(/auto-choose/i);
|
|
});
|
|
|
|
test('spawned directive carries a self-contained destructive carve-out (#2733 review)', () => {
|
|
// The "Spawned session block" it defers to exists only when a gstack
|
|
// preamble ran; an AUQ error outside a skill still needs the exception.
|
|
const d = directiveFor('spawned');
|
|
expect(d).toMatch(/never auto-choose a destructive or irreversible option/i);
|
|
expect(d).toMatch(/conservative non-destructive/);
|
|
});
|
|
|
|
test('interactive directive carries the spawned escape sentence (#2733)', () => {
|
|
// The sessionKind() shell-out runs in the HARNESS env, so a subagent
|
|
// marked spawned via a per-command prefix classifies interactive here —
|
|
// the directive text is the only lever for that topology.
|
|
const d = directiveFor('interactive');
|
|
expect(d).toMatch(/spawned subagent[\s\S]*auto-choose the recommended option/i);
|
|
expect(d).toMatch(/destructive or irreversible gate[\s\S]*conservative/i);
|
|
});
|
|
|
|
test('headless directive ALSO carries the spawned escape sentence (#2733 review, multi-specialist)', () => {
|
|
// A spawned-marked subagent under a headless-classified parent env
|
|
// (CI/eval-hosted /ship) hits the headless branch — the self-gating
|
|
// escape keeps the JSON contract alive; plain headless still BLOCKs.
|
|
const d = directiveFor('headless');
|
|
expect(d).toMatch(/BLOCKED — AskUserQuestion unavailable/);
|
|
expect(d).toMatch(/spawned subagent[\s\S]*auto-choose the recommended option/i);
|
|
});
|
|
|
|
test('escape sentence scopes spawned claims to the creating prompt (anti-injection)', () => {
|
|
const d = directiveFor('interactive');
|
|
expect(d).toMatch(/NEVER qualify[\s\S]*prompt injection/i);
|
|
});
|
|
});
|
|
|
|
/** Spawn the hook with synthetic stdin + controlled env; parse its JSON stdout. */
|
|
function runHook(stdin: object, env: Record<string, string>): { additionalContext?: string } {
|
|
const res = spawnSync('bun', [HOOK], {
|
|
input: JSON.stringify(stdin),
|
|
encoding: 'utf-8',
|
|
env: { PATH: process.env.PATH ?? '/usr/bin:/bin', ...env },
|
|
});
|
|
const parsed = JSON.parse(res.stdout || '{}');
|
|
return parsed.hookSpecificOutput ?? {};
|
|
}
|
|
|
|
describe('hook integration — invoked as PostToolUse', () => {
|
|
test('error result + headless env → injects BLOCK directive', () => {
|
|
const out = runHook(
|
|
{ tool_name: 'mcp__conductor__AskUserQuestion', tool_response: '[Tool result missing due to internal error]' },
|
|
{ GSTACK_HEADLESS: '1' },
|
|
);
|
|
expect(out.additionalContext).toMatch(/BLOCKED — AskUserQuestion unavailable/);
|
|
});
|
|
|
|
test('error result + interactive env → injects prose-triad directive', () => {
|
|
const out = runHook(
|
|
{ tool_name: 'AskUserQuestion', tool_response: null },
|
|
{ CONDUCTOR_PORT: '55010' },
|
|
);
|
|
expect(out.additionalContext).toMatch(/render the decision as a PROSE message/i);
|
|
expect(out.additionalContext).toMatch(/Completeness: X\/10/);
|
|
});
|
|
|
|
test('error result + spawned env → injects auto-choose directive', () => {
|
|
const out = runHook(
|
|
{ tool_name: 'AskUserQuestion', tool_response: { is_error: true } },
|
|
{ OPENCLAW_SESSION: '1' },
|
|
);
|
|
expect(out.additionalContext).toMatch(/auto-choose/i);
|
|
});
|
|
|
|
test('error result + GSTACK_SESSION_KIND=spawned env → override beats Conductor-interactive (#2733)', () => {
|
|
const out = runHook(
|
|
{ tool_name: 'AskUserQuestion', tool_response: { is_error: true } },
|
|
{ GSTACK_SESSION_KIND: 'spawned', CONDUCTOR_PORT: '55010' },
|
|
);
|
|
expect(out.additionalContext).toMatch(/SESSION_KIND=spawned/);
|
|
expect(out.additionalContext).toMatch(/auto-choose/i);
|
|
});
|
|
|
|
test('SUCCESSFUL answer → no injection (inert on real answers)', () => {
|
|
const out = runHook(
|
|
{ tool_name: 'AskUserQuestion', tool_response: { answers: [{ option_label: 'A' }] } },
|
|
{ GSTACK_HEADLESS: '1' },
|
|
);
|
|
expect(out.additionalContext).toBeUndefined();
|
|
});
|
|
|
|
test('non-AUQ tool → defers (no injection)', () => {
|
|
const out = runHook(
|
|
{ tool_name: 'Bash', tool_response: null },
|
|
{ GSTACK_HEADLESS: '1' },
|
|
);
|
|
expect(out.additionalContext).toBeUndefined();
|
|
});
|
|
});
|
|
|
|
// ----------------------------------------------------------------------
|
|
// Registration + teardown wiring (static). Setup registers this hook under
|
|
// its own source tag (sharing plan-tune-cathedral would overwrite the
|
|
// question-log entry — same event+matcher); both teardown surfaces
|
|
// (--no-team, uninstall) must remove it, which pre-v1.67.2 neither did.
|
|
// ----------------------------------------------------------------------
|
|
|
|
import * as fs from 'fs';
|
|
|
|
describe('setup registration + teardown wiring (static)', () => {
|
|
const ROOT = path.resolve(__dirname, '..');
|
|
const setupSrc = fs.readFileSync(path.join(ROOT, 'setup'), 'utf-8');
|
|
const uninstallSrc = fs.readFileSync(path.join(ROOT, 'bin', 'gstack-uninstall'), 'utf-8');
|
|
|
|
test('setup registers the hook via the canonical resolver under --source auq-error-fallback', () => {
|
|
expect(setupSrc).toMatch(
|
|
/AUQ_ERROR_FALLBACK_HOOK="\$\(_hook_command_path hosts\/claude\/hooks\/auq-error-fallback-hook/,
|
|
);
|
|
expect(setupSrc).toContain('--source auq-error-fallback');
|
|
});
|
|
|
|
test('--no-team tears the hook down', () => {
|
|
const idx = setupSrc.indexOf('# Also tear down plan-tune');
|
|
expect(idx).toBeGreaterThan(-1);
|
|
const slice = setupSrc.slice(idx, idx + 900);
|
|
expect(slice).toContain('remove-source --source auq-error-fallback');
|
|
});
|
|
|
|
test('gstack-uninstall tears the hook down', () => {
|
|
expect(uninstallSrc).toContain('remove-source --source auq-error-fallback');
|
|
});
|
|
});
|