Skip to content

fix(floor): the AC gate — a PLAN cannot scope the test infrastructure it is judged by; unrelated test anomalies no longer void the record (6.31.0) - #291

Merged
PrzemekGalarowicz merged 7 commits into
mainfrom
ac-gate-plan-scope
Sep 27, 2026
Merged

PrzemekGalarowicz merged 7 commits into
mainfrom
ac-gate-plan-scope

Conversation

@PrzemekGalarowicz

@PrzemekGalarowicz PrzemekGalarowicz commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Two holes in the AC gate, both from the review's findings H2 and M6. Released as SKILLS_VERSION 6.31.0 (minor), planned as
6.29.0 and renumbered twice: #290 released 6.29.0 and #292 released 6.30.0 first.

H2 — a PLAN could scope the test infrastructure it is judged by

A build scoped to AC-TESTS.lock.json re-pinned its own change with every check green. A PLAN-scoped build also wrote the
pharn-json reporter a level gate's script names, and the pin did not cover it.

  • check-ac-tests.mjs gains the kind ac-artifact-in-plan: this feature's AC-TESTS.md or lock in PLAN.md ## Files is RED.

  • test-infra-in-plan widens to cover root package-manager configs (.npmrc/.yarnrc/.yarnrc.yml) and every file a level
    gate's script names.

  • The test-infra pin moves to lock schema ac-tests-lock/4; /3, /2 and /1 are still read. It now covers:

    • the scripts a pinned value chains to (transitively, own-property only, refused past 8 hops);
    • the regular files a pinned value names;
    • package.json's jest key, as a canonical digest;
    • the root package-manager configs, hash only.

    All of it comes from one closed literal token pass (test-infra-core.mjs), never a shell parse.

  • A /3 lock is judged by what it pinned. Whatever only /4 pins reads unpinned: --check is RED and the AC gate reports
    test-infra-unpinned. A pre-6.31.0 floor reads a /4 lock as lock-unusable / ac-tests-modified, never GREEN.

M6 — one anomaly anywhere voided the whole AC record

  • A flaky test or expected failure the report marks, or a duplicate test id, is now a per-test anomaly in the record
    (anomalies[]). It is no longer a record refusal.
  • It makes an AC UNMEASURED only when it sits in a file mapped to that AC at one of its level gates. Every other anomaly is
    reported in unmapped_anomalies, in the red run, the ac_gate block, VERIFY.md and RUN-REPORT.md. No verdict reads it.

Bounds, stated where the contract lists them

  • The in-process bound comes first: code the build writes runs inside the test process and can switch assertions or the
    reporter off there. A green pin never means the build could not forge the AC gate.
  • The rest of the NOT-caught list is in test-infra-core.mjs's header and is restated in ac-tests.md.
  • verify-rechecks-test-stage (F4) is a named follow-up, stated as a bound.

Human-only edit (optional, not blocking)

.dev/features/ac-gate-plan-scope/proposed/ stages a LIMITS.md §9 patch. The agent cannot write that file. It is optional,
can be applied after this merges on its own branch (APPLY.md), and no gate waits on it.

Verdicts (floor)

Run records: .dev/features/ac-gate-plan-scope/ (PLAN, GRILL, BUILD, REGRESSION, VERIFY, REVIEW, SHIP).

🤖 Generated with Claude Code

PrzemekGalarowicz and others added 4 commits September 27, 2026 22:12
… it is judged by; unrelated test anomalies no longer void the record

H2: check-ac-tests.mjs gains ac-artifact-in-plan and widens test-infra-in-plan to
package-manager configs and script-named files; the lock pin (ac-tests-lock/4) covers
chained scripts, script-named files, the jest key and .npmrc/.yarnrc via one closed
literal token pass. M6: per-test anomalies no longer refuse the whole record; they
decide only the ACs whose mapped files hold them and are reported otherwise.
Lesson L65 promoted (accept delegated to the orchestrating model).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…released 6.29.0)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… SHIP.md

Regress on the merged tree (base c1bf663): no-regressions. Verify: every
gate exits 0 but reconcile, whose 50 escapes are exactly files origin/main
changed after the build's anchor (set difference empty; VERIFY.md).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 7aa39015-bfee-4106-808f-0b17b300b5b8


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

…e-insensitive volume

On ext4 a case variant of the lock is a different, new file: the guard allows
it and it opens nothing, so the APFS-measured 'opens' column read true on CI.
The table now keeps the filesystem-independent fact (the build may write a
file it is judged by, decided by dev+inode) apart from the raw guard reading,
which follows a run-time case-sensitivity probe of the temp volume. The four
case-variant rows are the probe-dependent ones; isRed stays unconditional
(the fold is fail-closed). A pure test injects both probe results. Measured
on APFS and on a case-sensitive APFS image: 60/60 on both.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
PrzemekGalarowicz added a commit that referenced this pull request Sep 27, 2026
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
PrzemekGalarowicz added a commit that referenced this pull request Sep 27, 2026
…ll line before tested code validates it (6.30.0) (#292)

* fix(product): no model-typed value from untrusted input reaches a shell line before tested code validates it

A feature name derived from the user's description is now written with the Write tool to
.pharn/feature-name/candidate.txt and printed back only as a FEATURE_SLUG_RE member by the new
pharn/floor/feature-name.mjs, before any shell line carries it (/pharn-spec Step 0, /pharn-loop S1/S2).
The seven name-taking commands ask for a missing name or resolve it only through the CLI.
/pharn-loop Step 6d returns with the constant `git checkout - --`, and /pharn-ship --quick item 7 no
longer takes a base ref from the description. SHELL-SINK pins in command-hygiene.test.mjs close the
shell-value and name-origin tables both ways and execute the committed lines on hostile names.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* chore: renumber shell-sink-validation to 6.30.0 (merges ahead of #291)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
PrzemekGalarowicz and others added 2 commits September 27, 2026 23:10
…released 6.30.0)

Only lines this branch adds against origin/main move (plus SKILLS_VERSION and
the README badge); main's ## [6.30.0] section stays byte-for-byte below
## [6.31.0]. The first renumber's history lines are kept, and the version
parentheticals now name both renumbers. SHIP.md records the merge and this
commit.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@PrzemekGalarowicz PrzemekGalarowicz changed the title fix(floor): the AC gate — a PLAN cannot scope the test infrastructure it is judged by; unrelated test anomalies no longer void the record (6.30.0) fix(floor): the AC gate — a PLAN cannot scope the test infrastructure it is judged by; unrelated test anomalies no longer void the record (6.31.0) Sep 27, 2026
@PrzemekGalarowicz
PrzemekGalarowicz merged commit 17dda60 into main Sep 27, 2026
8 checks passed
@PrzemekGalarowicz
PrzemekGalarowicz deleted the ac-gate-plan-scope branch September 28, 2026 11:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant