Conversation
|
Code Mower preflight at Root authorized one same-Claude repair for the two causes: reject zero/bool/invalid PR numbers in the pure episode constructor, and correctly register the standalone dataclass module during the vendored import tests. The scope stays pure, within 15 files / 250 KB; no live adapter or consumer activation. Source cap: $5 / 15 minutes. Fresh focused checks precede broader tests and independent review. This PR remains draft and unqualified. |
ff40338 to
fe45c12
Compare
Codex audit (merge-authority lane)Head SHA: Codex Audit: BLOCKED Summary: Independent Code Mower Codex static review of the complete 219,026-byte stage-1 diff against db4506d confirmed six P2 contract defects. All 19 indexed diff parts were read in full across 12 changed files, with byte-for-byte read coverage verified. The review is limited to the pure contract, tests and required package support; it does not require deferred publication or consumer activation. No repository code or tests were executed by this audit. Findings:
|
|
Root-authorized stage 1 API revision after the independent exact-head BLOCKED verdict. The same Claude writer will make one coherent revision: separate strict exact-target/evidence resolution from explicit identity-only use; normalize identity aliases once; validate and bound raw evidence before a single resolver owns deduplication; reject invalid or excessive whole chains before marker rendering; and add actual isolated init-materialized import/parse/resolve proof with an unchanged compatibility-helper control. Preserve 32 cumulative snapshots plus private overlap, ordinary explicit no-context controls, configured branch conflicts, all prior parser and identity-floor protections, canonical/tool parity, and the pure stage 1 boundary. The unused history selector compatibility and live adapters remain unchanged. The dedicated guard continues to enforce the deferred tools/decisions.py exclusion and the 15-file / 250,000-byte envelope. If a coherent revision cannot fit, stop before push for decomposition. Bounded source authorization: $20 / 30 minutes, one writer and existing lease. No follow-up source round is automatically authorized. After clean delivery: focused unittest/guards and canonical manifest equality, then sole full unittest discovery and independent complete-artifact exact-head review. The PR stays draft; root owns merge. |
fe45c12 to
329b37c
Compare
|
Code Mower notice: previously audited head |
|
Root-authorized minimal same-Claude correction after canonical preflight on Cap: $3 / 10 minutes, same writer and lease, no broader scope or follow-up round automatically authorized. Root separately authorized a byte-only 2 percent tolerance (255,000 bytes, still at most 15 files); the dedicated guard adjustment was recorded and the deferred-adapter exclusion remains intact. The current diff is below the original 250,000-byte cap. After clean delivery, rerun focused/guards/manifest before full unittest discovery and independent exact-head review. Keep draft. |
A pull request can be built by more than one Code Mower builder lane. The opener, the branch prefix and the single active `builder:*` label each describe at most one of those lanes, so consumers that each composed those signals slightly differently stopped agreeing about who wrote the current diff -- and a lane was admitted to review its own work. This stage ships only the shared decision, as a pure contract. Nothing imports it yet; producers, stores, publication, reconciliation and consumer activation are later stages, so accepted main behaviour is unchanged. * `code_mower.builder_lineage` -- immutable contribution episodes bound to repository, pull request, branch, source lane, destination lane, expected head and resulting head; ordered handoff and same-writer continuation; one current writer and the full contributor set; exact-head resolution that waits rather than guessing; strict announced-marker grammar; raw comment, slurped-page and selected-history validation before any normalization. * `code_mower.lineage_identity` -- the canonical own-reviewer label/account floor, the configured-authority marker trust predicate, and the bounded published-episode and admission contracts later stages consume. * `tools/builder_lineage.py` -- the vendored copy a generated product gate imports, plus its materialization and package-manifest entries. The API is organised around five invariants rather than per-call checks: 1. Exact-target resolution and reviewer admission require the complete repository, positive non-boolean bounded pull request number, nonempty valid branch and full head, through one `require_exact_target` contract. Incomplete target data is a `target_invalid` conflict, never a quiet downgrade to identity-only -- that downgrade skipped branch binding, so evidence from another branch resolved as evidence about this one. Identity-only is a route callers select on purpose (`resolve_configured_identity`, which takes no evidence argument), and a context that is partially populated or carries episodes is never absent. 2. `canonical_identity` normalizes account aliases and branch prefixes once; lane naming, branch lookup, the complete resolver, the carried context and the reviewer floor all consume that one representation. Compatible spellings collapse and contradictory ones refuse regardless of insertion order, and longest-prefix matching now looks values up on the canonical key, so trimming a key no longer strands its lookup. 3. `bounded_arrivals` enforces the documented 560 raw-arrival budget (528 cumulative public entries plus 32 private) while the input is walked, so an oversized source is never materialised and a lazy one is not consumed past the first refused arrival. Collectors and the composer preserve validated raw arrivals uncollapsed; only the owning resolver deduplicates, where it can also refuse a contradiction. Malformed members are the documented contract error, not an incidental attribute failure. 4. `lineage_comment_marker` validates the whole chain through the resolver's own walk and refuses zero, malformed, conflicting or unchained input. Slicing to the bound turned an over-long chain into a successful publication that had quietly lost its newest episodes. 5. The owning packaging test materializes a real product tree through `init` and runs a clean subprocess that can only see the generated `tools/` directory, asserting module origins and exercising marker parsing, exact resolution and an unchanged compatibility helper there. tools/decisions.py is untouched; its environment-reading parity is stage 3. Refs #963 Closes #990 Builder-Provider: claude Builder-Executor: claude_cli
329b37c to
fb22be3
Compare
|
Code Mower notice: previously audited head |
1 similar comment
|
Code Mower notice: previously audited head |
Codex audit (merge-authority lane)Head SHA: Codex Audit: BLOCKED Summary: Independent Code Mower Codex static review of the complete 252,278-byte stage-1 diff against db4506d confirmed three P2 contract defects. All 22 indexed diff parts were read in full across 12 changed files, with byte-for-byte read coverage verified. The review covers the pure contract and its owning tests/package support, including the isolated materialized import-and-call regression; no deferred publication or consumer activation is required. No repository code or tests were executed by this audit. Findings:
|
This unaccepted prototype is superseded by fresh Codex-source PR #994 for #990. Refs #963; it must not close either outcome or satisfy release prerequisites.
Preserved head:
fb22be35d74583be4d4332e5f5c87d5836175c47. The complete independent audit is BLOCKED on three P2s: surviving falsey-history convenience paths, noncanonical direct episode storage, and renderer chains lacking one immutable target. Its passing focused/full tests and CI do not override that verdict. Source is clean/quiescent, writer exited, and the broker lease was released with absent readback.The replacement uses a deliberately small typed core with no legacy optional-context, generic composer or REST-history convenience APIs. Stage #990 remains additive with no live activation; #991 trusted publication and #992 atomic consumer activation follow only after independent acceptance. #915 retains candidate and published-artifact qualification.
This PR closes without merge. Historical source, reviews, discarded findings and complete-coverage evidence remain preserved. No new hosted Devin create allowance.