/** * Doc-sync gate: require every workspace package README to explain its exact * model-visible context surface and token behavior. Most packages require the * canonical context-surface blocks with optional nested verbatim H4 blocks. * Direct system-prompt surfaces must contain exact `markdown` blocks, * tool-schema surfaces must link generated catalog sections, local subsection * links are rejected, and an audited allowlist uses one concise sentence. * * Run: `tsx scripts/verify-package-readme-model-experience.ts`. */ import { existsSync, globSync, readFileSync } from 'node:fs' import { relative, resolve } from 'node:path' const root = resolve(import.meta.dirname, '..') const HEADING = '## Model Experience' const LIMITATIONS_HEADING = '## Known Limitations and Deferred Work' const MODEL_VIEW_LABEL = '**What the model sees**' const TOKEN_EFFECT_LABEL = '**Token effect**' const H2_HEADING = /^## .+$/ type SentenceKind = 'none' | 'indirect' interface SentenceContract { kind: SentenceKind reason: string } /** * Packages whose Model Experience is simple enough for one gated sentence. * Every other package must carry canonical context-surface blocks. A package * moves on or off this list with the change to its context behavior. */ const SENTENCE_MODEL_EXPERIENCE: Readonly> = { 'packages/bash/bash': { kind: 'indirect', reason: 'The service interface delegates all model rendering to dsh-tool-bash.' }, 'packages/bash/bash-local': { kind: 'indirect', reason: 'The executor backend delegates model rendering to dsh-tool-bash.' }, 'packages/code-runtime/code-runtime': { kind: 'indirect', reason: 'The service interface delegates model rendering to Code Mode in dsh-tools.' }, 'packages/code-runtime/code-runtime-worker': { kind: 'indirect', reason: 'The worker backend delegates model rendering to Code Mode in dsh-tools.' }, 'packages/core/agent-core': { kind: 'indirect', reason: 'The bundle only mounts model-facing child plugins.' }, 'packages/core/scope': { kind: 'none', reason: 'The routing primitive emits no model-bound content.' }, 'packages/fs/fs': { kind: 'indirect', reason: 'The service interface delegates model rendering to dsh-tool-fs.' }, 'packages/fs/fs-local': { kind: 'indirect', reason: 'The provider backend delegates model rendering to dsh-tool-fs.' }, 'packages/hooks/hook-protocol': { kind: 'indirect', reason: 'Only the hook bridge plugins render decoded hook output to a model.' }, 'packages/llm/llm': { kind: 'none', reason: 'The adapter registry forwards already-assembled requests unchanged.' }, 'packages/sandbox/sandbox': { kind: 'indirect', reason: 'Sandbox consumers render enforcement and availability facts.' }, 'packages/sandbox/sandbox-local': { kind: 'indirect', reason: 'The provider backend delegates model rendering to dsh-bash-sandbox and dsh-tool-bash.' }, 'packages/skill/skill': { kind: 'indirect', reason: 'The provider registry delegates model rendering to dsh-tool-skill.' }, 'packages/skill/skill-local': { kind: 'indirect', reason: 'The provider backend delegates model rendering to dsh-tool-skill.' }, 'packages/subagent/subagent': { kind: 'indirect', reason: 'The provider registry delegates parent-model rendering to dsh-tool-subagent.' }, 'packages/subagent/subagent-subprocess': { kind: 'indirect', reason: 'Only process-based subagent backends compose a child model request.' }, 'packages/support/acp-snapshot': { kind: 'none', reason: 'The test harness observes and normalizes transcripts without changing live requests.' }, 'packages/support/invariants': { kind: 'none', reason: 'The observer validates requests but never rewrites their context.' }, 'packages/support/llm-replay': { kind: 'none', reason: 'The keyless adapter invokes no provider model.' }, 'packages/support/subagent-mock': { kind: 'indirect', reason: 'Only dsh-tool-subagent renders its configured test outcome.' }, 'packages/ui/acp-agent': { kind: 'indirect', reason: 'The app bundle delegates request composition to dsh-agent-core and dsh-acp.' }, 'packages/ui/app-boot': { kind: 'indirect', reason: 'Only the loaded plugin tree contributes model context.' }, 'packages/ui/user-interaction': { kind: 'indirect', reason: 'Model-facing consumers render provider answers and seam errors.' }, 'packages/util/brand': { kind: 'none', reason: 'The type-only primitive is erased at compile time.' }, 'packages/util/timeout': { kind: 'indirect', reason: 'Only timeout consumers render timeout outcomes.' }, 'packages/web/web': { kind: 'indirect', reason: 'The provider registry delegates model rendering to dsh-tool-web.' }, 'packages/web/web-fetch-local': { kind: 'indirect', reason: 'The provider backend delegates model rendering to dsh-tool-web.' }, 'packages/web/web-search-exa': { kind: 'indirect', reason: 'The provider backend delegates model rendering to dsh-tool-web.' }, 'packages/workflow/workflow': { kind: 'indirect', reason: 'The service delegates parent and child model rendering to its consumer and engine.' }, } interface Failure { path: string message: string } interface Line { index: number raw: string } interface ContextSurface { heading: Line modelView: Line tokenEffect: Line title: string verbatimBlocks: number } /** Split Markdown into prose lines, excluding fenced code that may quote the contract. */ function proseLines(text: string): Line[] { let fence: { marker: '`' | '~'; length: number } | undefined const kept: Line[] = [] text.split('\n').forEach((raw, i) => { const token = /^ {0,3}(`{3,}|~{3,})/.exec(raw)?.[1] if (token !== undefined) { const marker = token[0] as '`' | '~' if (fence === undefined) { fence = { marker, length: token.length } } else if (marker === fence.marker && token.length >= fence.length) { fence = undefined } return } if (fence === undefined) kept.push({ index: i + 1, raw }) }) return kept } /** Validate H4-plus-markdown literals nested after one context surface's fields. */ function validateNestedVerbatim(raw: readonly string[]): { blocks: number; error?: string } { let cursor = 0 while (raw[cursor]?.trim().length === 0) cursor += 1 if (cursor === raw.length) return { blocks: 0 } let blocks = 0 const fragments = new Set() while (true) { while (raw[cursor]?.trim().length === 0) cursor += 1 if (cursor === raw.length) break if (!/^#### \S/.test(raw[cursor] ?? '')) { return { blocks, error: 'content after Token effect must be a titled H4 verbatim block' } } const title = (raw[cursor] as string).slice('#### '.length) const fragment = headingFragment(title) if (fragment.length === 0) return { blocks, error: 'verbatim H4 title must be non-empty' } if (fragments.has(fragment)) { return { blocks, error: `verbatim H4 title ${JSON.stringify(title)} is duplicated within its context surface` } } fragments.add(fragment) cursor += 1 while (raw[cursor]?.trim().length === 0) cursor += 1 if (raw[cursor] !== '```markdown') { return { blocks, error: 'each nested verbatim H4 requires an exact ```markdown fence' } } cursor += 1 const contentStart = cursor while (cursor < raw.length && raw[cursor] !== '```') cursor += 1 if (cursor === raw.length) return { blocks, error: 'unterminated nested ```markdown fence' } if (cursor === contentStart) return { blocks, error: 'nested ```markdown fence must not be empty' } cursor += 1 blocks += 1 } return { blocks } } /** GitHub-style fragment for the simple ASCII H4 titles allowed by this contract. */ function headingFragment(title: string): string { return title.toLowerCase().replaceAll('`', '').replaceAll(/[^a-z0-9 _-]/g, '').trim().replaceAll(/\s+/g, '-') } /** A direct stable system-prompt contribution, as named by the README contract. */ function isDirectSystemPromptSurface(title: string): boolean { return /\bsystem prompt\b/i.test(title) } /** Anchored generated-catalog links in one model-view field. */ function toolCatalogLinkFragments(text: string): string[] { return [...text.matchAll(/\]\(\.\.\/\.\.\/\.\.\/docs\/tool-catalog\.md#([a-z0-9_-]+)\)/g)] .map(match => match[1] as string) } const toolCatalogFragments = new Set() for (const line of readFileSync(resolve(root, 'docs/tool-catalog.md'), 'utf8').split('\n')) { const title = /^## (.+)$/.exec(line)?.[1] if (title !== undefined) toolCatalogFragments.add(headingFragment(title)) } const failures: Failure[] = [] const packageJsons = globSync('packages/*/*/package.json', { cwd: root }).sort() const scannedPackages = new Set(packageJsons.map(path => path.slice(0, -'/package.json'.length))) let structuredCount = 0 let contextSurfaceCount = 0 let noneCount = 0 let indirectCount = 0 let verbatimBlockCount = 0 let systemPromptSurfaceCount = 0 let toolSchemaSurfaceCount = 0 for (const [pkg, contract] of Object.entries(SENTENCE_MODEL_EXPERIENCE)) { if (!scannedPackages.has(pkg)) { failures.push({ path: `${pkg}/README.md`, message: 'sentence allowlist entry does not name a scanned package' }) } if (contract.reason.trim().length === 0) { failures.push({ path: `${pkg}/README.md`, message: 'sentence allowlist entry must justify why structured context surfaces are unnecessary' }) } } for (const packageJson of packageJsons) { const pkg = packageJson.slice(0, -'/package.json'.length) const readme = packageJson.replace(/package\.json$/, 'README.md') const abs = resolve(root, readme) if (!existsSync(abs)) { failures.push({ path: readme, message: `missing package README; add one with ${HEADING}` }) continue } const text = readFileSync(abs, 'utf8') const rawLines = text.split('\n') const lines = proseLines(text) const h2Headings = lines.filter(line => H2_HEADING.test(line.raw)) const modelHeadings = h2Headings.filter(line => line.raw === HEADING) if (modelHeadings.length !== 1) { failures.push({ path: readme, message: modelHeadings.length === 0 ? `missing ${HEADING}` : `contains ${modelHeadings.length} copies of ${HEADING}`, }) continue } const modelHeading = modelHeadings[0] as Line const modelH2Index = h2Headings.indexOf(modelHeading) const limitationsH2Index = h2Headings.findIndex(heading => heading.raw === LIMITATIONS_HEADING) if (limitationsH2Index >= 0) { if (modelH2Index !== h2Headings.length - 2 || limitationsH2Index !== h2Headings.length - 1) { failures.push({ path: readme, message: `${HEADING} and ${LIMITATIONS_HEADING} must be the final two H2 sections, in that order`, }) continue } } else if (modelH2Index !== h2Headings.length - 1) { failures.push({ path: readme, message: `${HEADING} must be the final H2 when ${LIMITATIONS_HEADING} is absent` }) continue } const body = lines.slice(lines.indexOf(modelHeading) + 1) const nextH2 = body.findIndex(line => H2_HEADING.test(line.raw)) const section = nextH2 < 0 ? body : body.slice(0, nextH2) const nextH2Line = nextH2 < 0 ? rawLines.length + 1 : (body[nextH2] as Line).index const rawSection = rawLines.slice(modelHeading.index, nextH2Line - 1) const content = section.filter(line => line.raw.trim().length > 0) const sentenceContract = SENTENCE_MODEL_EXPERIENCE[pkg] if (sentenceContract !== undefined) { const pattern = sentenceContract.kind === 'none' ? /^None, as .+\.$/ : /^Indirectly, through .+\.$/ const rawContent = rawSection.filter(line => line.trim().length > 0) if (content.length !== 1 || rawContent.length !== 1 || !pattern.test(content[0]?.raw ?? '')) { const prefix = sentenceContract.kind === 'none' ? 'None, as ' : 'Indirectly, through ' failures.push({ path: readme, message: `must contain exactly one sentence beginning ${JSON.stringify(prefix)} and ending with a period` }) continue } if (sentenceContract.kind === 'none') noneCount += 1 else indirectCount += 1 continue } const shortSentence = content.find(line => /^None, as |^Indirectly, through /.test(line.raw)) if (shortSentence !== undefined) { failures.push({ path: readme, message: `line ${shortSentence.index}: short Model Experience form requires an audited entry in SENTENCE_MODEL_EXPERIENCE` }) continue } const surfaceStarts = content .map((line, index) => ({ line, index })) .filter(entry => /^### \S/.test(entry.line.raw)) if (surfaceStarts.length === 0 || surfaceStarts[0]?.index !== 0) { failures.push({ path: readme, message: 'must contain one or more complete context-surface blocks' }) continue } const surfaces: ContextSurface[] = [] const surfaceFragments = new Set() let surfaceError = false for (let surfaceIndex = 0; surfaceIndex < surfaceStarts.length; surfaceIndex += 1) { const start = surfaceStarts[surfaceIndex] as { line: Line; index: number } const end = surfaceStarts[surfaceIndex + 1]?.index ?? content.length const entries = content.slice(start.index, end) const heading = entries[0] as Line const modelView = entries[1] const tokenEffect = entries[2] const title = heading.raw.slice('### '.length) const fragment = headingFragment(title) if (fragment.length === 0) { failures.push({ path: readme, message: `line ${heading.index}: each context surface requires a non-empty H3 heading` }) surfaceError = true break } if (surfaceFragments.has(fragment)) { failures.push({ path: readme, message: `line ${heading.index}: duplicate context-surface link fragment ${JSON.stringify(fragment)}` }) surfaceError = true break } if (modelView === undefined || !modelView.raw.startsWith(`${MODEL_VIEW_LABEL}: `) || modelView.raw.slice(`${MODEL_VIEW_LABEL}: `.length).trim().length === 0) { failures.push({ path: readme, message: `line ${modelView?.index ?? heading.index}: context surface requires non-empty ${MODEL_VIEW_LABEL}: text` }) surfaceError = true break } if (tokenEffect === undefined || !tokenEffect.raw.startsWith(`${TOKEN_EFFECT_LABEL}: `) || tokenEffect.raw.slice(`${TOKEN_EFFECT_LABEL}: `.length).trim().length === 0) { failures.push({ path: readme, message: `line ${tokenEffect?.index ?? heading.index}: context surface requires non-empty ${TOKEN_EFFECT_LABEL}: text` }) surfaceError = true break } if ((surfaceIndex === 0 && heading.index !== modelHeading.index + 2) || rawLines[heading.index - 2]?.trim().length !== 0 || modelView.index !== heading.index + 2 || tokenEffect.index !== modelView.index + 2) { failures.push({ path: readme, message: `line ${heading.index}: context-surface heading and fields require one blank line between each element` }) surfaceError = true break } const unexpected = entries.slice(3).find(line => !/^#### \S/.test(line.raw)) if (unexpected !== undefined) { failures.push({ path: readme, message: `line ${unexpected.index}: content after ${TOKEN_EFFECT_LABEL} must be a titled H4 plus \`markdown\` fence inside this context surface` }) surfaceError = true break } const nextHeadingLine = surfaceStarts[surfaceIndex + 1]?.line.index ?? nextH2Line const verbatim = validateNestedVerbatim(rawLines.slice(tokenEffect.index, nextHeadingLine - 1)) if (verbatim.error !== undefined) { failures.push({ path: readme, message: `line ${tokenEffect.index}: ${verbatim.error}` }) surfaceError = true break } if (entries.length - 3 !== verbatim.blocks) { failures.push({ path: readme, message: `line ${tokenEffect.index}: every nested H4 must own exactly one \`markdown\` fence` }) surfaceError = true break } if (/\]\(#[^)]+\)/.test(modelView.raw) || /\]\(#[^)]+\)/.test(tokenEffect.raw)) { failures.push({ path: readme, message: `line ${heading.index}: Model Experience fields must not link between local subsections; nest the H4 in its owning H3` }) surfaceError = true break } surfaceFragments.add(fragment) surfaces.push({ heading, modelView, tokenEffect, title, verbatimBlocks: verbatim.blocks }) } if (surfaceError) continue const promptWithoutVerbatim = surfaces.find(surface => isDirectSystemPromptSurface(surface.title) && surface.verbatimBlocks === 0) if (promptWithoutVerbatim !== undefined) { failures.push({ path: readme, message: `line ${promptWithoutVerbatim.heading.index}: system-prompt surface must contain a titled H4 plus verbatim \`markdown\` block` }) continue } const hasConcreteLiteral = surfaces.some(surface => surface.verbatimBlocks > 0 || surface.modelView.raw.includes('`') || surface.tokenEffect.raw.includes('`') || toolCatalogLinkFragments(surface.modelView.raw).length > 0) if (!hasConcreteLiteral) { failures.push({ path: readme, message: 'structured Model Experience must ground at least one surface with inline code, a nested `markdown` block, or an anchored tool-catalog link' }) continue } let catalogError = false for (const surface of surfaces) { if (!/\bschemas?\b/i.test(surface.title)) continue const fragments = toolCatalogLinkFragments(surface.modelView.raw) if (fragments.length === 0) { failures.push({ path: readme, message: `line ${surface.heading.index}: tool-schema surface must link an anchored section of ../../../docs/tool-catalog.md` }) catalogError = true break } const invalid = fragments.find(fragment => !toolCatalogFragments.has(fragment)) if (invalid !== undefined) { failures.push({ path: readme, message: `line ${surface.modelView.index}: tool-catalog link fragment ${JSON.stringify(invalid)} does not name an H2 section` }) catalogError = true break } } if (catalogError) continue verbatimBlockCount += surfaces.reduce((total, surface) => total + surface.verbatimBlocks, 0) contextSurfaceCount += surfaces.length systemPromptSurfaceCount += surfaces.filter(surface => isDirectSystemPromptSurface(surface.title)).length toolSchemaSurfaceCount += surfaces.filter(surface => /\bschemas?\b/i.test(surface.title)).length structuredCount += 1 } if (failures.length === 0) { console.log(`verify-package-readme-model-experience: ${packageJsons.length} README(s) checked (${structuredCount} structured, ${contextSurfaceCount} context surfaces, ${systemPromptSurfaceCount} fenced system-prompt surfaces, ${toolSchemaSurfaceCount} catalog-linked tool-schema surfaces, ${noneCount} none, ${indirectCount} indirect, ${verbatimBlockCount} verbatim markdown blocks), all conform.`) process.exit(0) } console.error('verify-package-readme-model-experience failed:') for (const failure of failures) { console.error(` ${relative(root, resolve(root, failure.path))}: ${failure.message}`) } process.exit(1)