* refactor(core): move the command descriptor registry into its own package
`src/core/command-descriptor/`, `src/command-catalog.ts`, `src/core/wait-positionals.ts`
and `src/core/parse-timeout.ts` move as git renames into a new private package
`@agent-device/command-registry` (deps: contracts, selectors). One subpath per module
points straight at the moved file; no `index.ts`, no re-export at the old path. Every
consumer switches to the owning specifier.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Jqfa11D8QsCMuL17SsLvDz
* test(host-kit): pin the command-registry package inside the daemon code graph
The daemon reaches the registry and its catalog only by workspace specifier. A walk
that stopped at the package boundary would report an unchanged signature after a
descriptor edit, and the client would keep reusing a daemon running the superseded
policy. The manifest is asserted beside the sources because its `exports` map is what
chose them. The cache doc comment quoting the old ~800-module graph is corrected.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Jqfa11D8QsCMuL17SsLvDz
* chore(gates): point the descriptor-registry gates at the package path
R66's `COMMAND_DESCRIPTOR_MODULE`, R16's record-runtime join subject and the Fallow
`AssertTrue` totality-guard key follow the registry to its package. The two descriptor
hubs leave `HUB_ENTRY_FILES` because the package manifest now publishes them, so the
eager-closure gate discovers them as facades and one entry gets one rule; this also
flips `denyPlatformImplementations` from false (hub) to true (package entry) for both,
which is intentional and stricter. `command-registry` joins the ranked spine at rank 1.
No `APPROVED_OVER_CEILING` row: rename detection carries every moved entry's merge-base
baseline, so all twelve fall under the no-growth rule rather than a ceiling.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Jqfa11D8QsCMuL17SsLvDz
---------
Co-authored-by: Claude <noreply@anthropic.com>
* test(fuzz): structured CLI/Maestro generators that reach command validation and assert error codes (#1781 B2)
* test(fuzz): pin the rediscovered #1433 excess-positional case and keep numeric flag samples inside their range
* style: apply oxfmt to the new fuzz modules
* perf(fuzz): derive the CLI validation surface lazily so unrelated harness paths keep their startup
* test(fuzz): resolve validation generators in the run path so corpus replay keeps its small module graph
* test(fuzz): weight the CLI budget toward command validation, pin the finite classes as seeds, guard lazy surface derivation
* docs(testing): describe the validation lane's layer split, seed-pinned classes, and PR-time gates
* refactor(fuzz): split the validation generator into CLI and Maestro modules, mirrored in tests
* refactor(fuzz): collapse the flag-shaped mutation classes and seed literals, derive class coverage from declarations
* fix(fuzz): hash every case-generation module in configHash, guarded by an import-closure test
* test(fuzz): assert CLI command and flag-key coverage against the registry, and close the six gaps it found