fix(floor): the AC gate — a PLAN cannot scope the test infrastructure it is judged by; unrelated test anomalies no longer void the record (6.31.0) - #291
Merged
Conversation
… it is judged by; unrelated test anomalies no longer void the record H2: check-ac-tests.mjs gains ac-artifact-in-plan and widens test-infra-in-plan to package-manager configs and script-named files; the lock pin (ac-tests-lock/4) covers chained scripts, script-named files, the jest key and .npmrc/.yarnrc via one closed literal token pass. M6: per-test anomalies no longer refuse the whole record; they decide only the ACs whose mapped files hold them and are reported otherwise. Lesson L65 promoted (accept delegated to the orchestrating model). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
# Conflicts: # CHANGELOG.md
…released 6.29.0) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… SHIP.md Regress on the merged tree (base c1bf663): no-regressions. Verify: every gate exits 0 but reconcile, whose 50 escapes are exactly files origin/main changed after the build's anchor (set difference empty; VERIFY.md). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
…e-insensitive volume On ext4 a case variant of the lock is a different, new file: the guard allows it and it opens nothing, so the APFS-measured 'opens' column read true on CI. The table now keeps the filesystem-independent fact (the build may write a file it is judged by, decided by dev+inode) apart from the raw guard reading, which follows a run-time case-sensitivity probe of the temp volume. The four case-variant rows are the probe-dependent ones; isRed stays unconditional (the fold is fail-closed). A pure test injects both probe results. Measured on APFS and on a case-sensitive APFS image: 60/60 on both. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
PrzemekGalarowicz
added a commit
that referenced
this pull request
Sep 27, 2026
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
PrzemekGalarowicz
added a commit
that referenced
this pull request
Sep 27, 2026
…ll line before tested code validates it (6.30.0) (#292) * fix(product): no model-typed value from untrusted input reaches a shell line before tested code validates it A feature name derived from the user's description is now written with the Write tool to .pharn/feature-name/candidate.txt and printed back only as a FEATURE_SLUG_RE member by the new pharn/floor/feature-name.mjs, before any shell line carries it (/pharn-spec Step 0, /pharn-loop S1/S2). The seven name-taking commands ask for a missing name or resolve it only through the CLI. /pharn-loop Step 6d returns with the constant `git checkout - --`, and /pharn-ship --quick item 7 no longer takes a base ref from the description. SHELL-SINK pins in command-hygiene.test.mjs close the shell-value and name-origin tables both ways and execute the committed lines on hostile names. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * chore: renumber shell-sink-validation to 6.30.0 (merges ahead of #291) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
# Conflicts: # CHANGELOG.md
…released 6.30.0) Only lines this branch adds against origin/main move (plus SKILLS_VERSION and the README badge); main's ## [6.30.0] section stays byte-for-byte below ## [6.31.0]. The first renumber's history lines are kept, and the version parentheticals now name both renumbers. SHIP.md records the merge and this commit. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Two holes in the AC gate, both from the review's findings H2 and M6. Released as
SKILLS_VERSION6.31.0 (minor), planned as6.29.0 and renumbered twice: #290 released 6.29.0 and #292 released 6.30.0 first.
H2 — a PLAN could scope the test infrastructure it is judged by
A build scoped to
AC-TESTS.lock.jsonre-pinned its own change with every check green. A PLAN-scoped build also wrote thepharn-jsonreporter a level gate's script names, and the pin did not cover it.check-ac-tests.mjsgains the kindac-artifact-in-plan: this feature'sAC-TESTS.mdor lock in PLAN.md## Filesis RED.test-infra-in-planwidens to cover root package-manager configs (.npmrc/.yarnrc/.yarnrc.yml) and every file a levelgate's script names.
The test-infra pin moves to lock schema
ac-tests-lock/4;/3,/2and/1are still read. It now covers:jestkey, as a canonical digest;All of it comes from one closed literal token pass (
test-infra-core.mjs), never a shell parse.A
/3lock is judged by what it pinned. Whatever only/4pins readsunpinned:--checkis RED and the AC gate reportstest-infra-unpinned. A pre-6.31.0 floor reads a/4lock aslock-unusable/ac-tests-modified, never GREEN.M6 — one anomaly anywhere voided the whole AC record
(
anomalies[]). It is no longer a record refusal.reported in
unmapped_anomalies, in the red run, theac_gateblock, VERIFY.md and RUN-REPORT.md. No verdict reads it.Bounds, stated where the contract lists them
reporter off there. A green pin never means the build could not forge the AC gate.
test-infra-core.mjs's header and is restated inac-tests.md.verify-rechecks-test-stage(F4) is a named follow-up, stated as a bound.Human-only edit (optional, not blocking)
.dev/features/ac-gate-plan-scope/proposed/stages aLIMITS.md §9patch. The agent cannot write that file. It is optional,can be applied after this merges on its own branch (
APPLY.md), and no gate waits on it.Verdicts (floor)
validate: GREEN (36 capabilities)./pharn-dev-regress(basec1bf663, after merging main):no-regressions./pharn-dev-verify(after merging main):FAILonreconcilealone; the other six gates exit 0 (4170/4170 tests).origin/mainchanged (70cb51c..c1bf663: fix(floor): the stage scripts' git calls no longer die past 1 MiB of output (6.28.3) #286, docs: audit gaps — Node floor version, command budget, SECURITY 6.24.0 #287, fix(floor): a cost ledger counts only its own run's requests (6.29.0) #290) after this buildanchored its reconcile epoch. Escapes minus that list is the empty set (
VERIFY.md).PASS, reconcileCLEAN.check:changelog-entry: GREEN againstorigin/mainat109a4af; this PR opens## [6.31.0] - 2026-09-27.BUILD.md, "GATE 2 —the FIX round").
model, not human approvals.
Run records:
.dev/features/ac-gate-plan-scope/(PLAN, GRILL, BUILD, REGRESSION, VERIFY, REVIEW, SHIP).🤖 Generated with Claude Code