fix: reject invalid strategy input before validation and TODO writes - #66
Conversation
There was a problem hiding this comment.
Deterministic Validator approval for exact head 0eb496d779a461430d6a24cd18ef381db4754eb7.
Ticket: ticket-065
Correlation ID: local-semcod-planfile-pr-66-ticket-065
Model: zai/glm-5.3
Advisory LLM review: LLM_UNAVAILABLE
Reason: litellm.RateLimitError: RateLimitError: ZaiException - Weekly/Monthly Limit Exhausted. Your limit will reset at 2026-09-11 15:27:59
This approval rests on the deterministic checks alone; no advisory opinion was recorded for this head.
Actual PR impact radar
Exact range: bfc2db12d4e7bf30fe1402dfbf81c1b638576bd5...0eb496d779a461430d6a24cd18ef381db4754eb7
Change digest: 4c4cabcaba62688738bc9498a71229e6ce52becf0b1a268a23e8bcf9cd7cffd6
Score: 72/100 (L), estimated 80 min, split recommended: true
Affected services/components: repository-wide/unclassified
Machine-readable radar JSONL and SVG
{"actual_change":{"additions":128,"base_sha":"bfc2db12d4e7bf30fe1402dfbf81c1b638576bd5","binary_files":0,"categories":{"code":3,"configuration":1,"docs":2,"tests":1},"change_digest":"4c4cabcaba62688738bc9498a71229e6ce52becf0b1a268a23e8bcf9cd7cffd6","comparison":"bfc2db12d4e7bf30fe1402dfbf81c1b638576bd5...0eb496d779a461430d6a24cd18ef381db4754eb7","deletions":23,"file_count":7,"files":["docs/information/python-api.md","planfile/strategy_input.py","planfile/ticket_validation.py","planfile/todo_sync.py","project/ticket-065/README.md","project/ticket-065/intent.json","tests/test_strategy_input.py"],"head_sha":"0eb496d779a461430d6a24cd18ef381db4754eb7","service_count":0,"services":[]},"assessment_mode":"observed-pr","axes":{"coupling":5,"delivery":4,"scope":4,"uncertainty":3,"validation":2},"complexity":"L","confidence":0.9,"diagnostics":["RADAR-ACCEPTANCE-MISSING","RADAR-BUDGET-EXCEEDED"],"estimate":{"budget_minutes":30,"minutes":80,"within_budget":false},"impact":{"components":["Missing","docs","planfile","project","subactor","tests"],"files":["Missing/unreadable","docs/information/python-api.md","planfile/strategy_input.py","planfile/ticket_validation.py","planfile/todo_sync.py","project/ticket-065/README.md","project/ticket-065/intent.json","subactor/doctor-agent","tests/test_strategy_input.py"],"public_interfaces":[],"runtime_dependencies":0},"schema":"subactor.ticket-radar/v1","score":72,"split":{"parts":[{"estimated_minutes":12,"name":"Implement Missing","scope":["Missing"]},{"estimated_minutes":12,"name":"Implement docs","scope":["docs"]},{"estimated_minutes":12,"name":"Implement planfile","scope":["planfile"]},{"estimated_minutes":12,"name":"Implement project","scope":["project"]},{"estimated_minutes":12,"name":"Implement subactor","scope":["subactor"]},{"estimated_minutes":15,"name":"Validate and project to trackers","scope":["tests","planfile","github/gitlab/jira projections"]}],"reason":"estimated_minutes_exceed_budget","recommended":true},"standards":[{"id":"wellmanifest/dsl","revision":"6c60fc4e0dd1f1bb74f46a7745e28019908d1203","version":"0.1.0-dev"},{"id":"wellmanifest/ticket-lifecycle","revision":"5bf581907a87b46a13a73e6c033d3abe4d9a306f","version":"0.1.0-dev"},{"id":"wellmanifest/git-lifecycle","revision":"7d77d4b7af57e69bc75c3a0290b3a4805c5c4438","version":"0.2.0-dev"},{"id":"wellmanifest/logs","revision":"48c284ef7a069055c0bcb6b900147ce5e65f8b43","version":"0.3.0"}],"ticket_ref":"ticket-065"}<svg xmlns="http://www.w3.org/2000/svg" width="128" height="128" viewBox="0 0 128 128" role="img"><title>ticket-065: fix: reject invalid strategy input before validation and TODO writes</title><rect width="128" height="128" rx="12" fill="#f8fafc"/><g stroke-width="1"><polygon points="64,55 72,61 69,71 59,71 56,61" fill="none" stroke="#d7dde5"/><polygon points="64,47 80,59 74,78 54,78 48,59" fill="none" stroke="#d7dde5"/><polygon points="64,38 89,56 79,85 49,85 39,56" fill="none" stroke="#d7dde5"/><polygon points="64,30 97,53 84,92 44,92 31,53" fill="none" stroke="#d7dde5"/><polygon points="64,21 105,51 89,99 39,99 23,51" fill="none" stroke="#d7dde5"/><line x1="64" y1="64" x2="64" y2="21" stroke="#aab4c0"/><line x1="64" y1="64" x2="105" y2="51" stroke="#aab4c0"/><line x1="64" y1="64" x2="89" y2="99" stroke="#aab4c0"/><line x1="64" y1="64" x2="39" y2="99" stroke="#aab4c0"/><line x1="64" y1="64" x2="23" y2="51" stroke="#aab4c0"/></g><polygon points="64,30 105,51 79,85 54,78 31,53" fill="#fb923c" fill-opacity="0.45" stroke="#c2410c" stroke-width="2"/><circle cx="64" cy="64" r="3" fill="#c2410c"/><g font-family="sans-serif" font-size="7" fill="#334155"><text x="64" y="11" text-anchor="middle">SCO</text><text x="114" y="48" text-anchor="middle">COU</text><text x="95" y="107" text-anchor="middle">UNC</text><text x="33" y="107" text-anchor="middle">VAL</text><text x="14" y="48" text-anchor="middle">DEL</text></g><text x="64" y="124" text-anchor="middle" font-family="sans-serif" font-size="8" fill="#0f172a">L · 80m</text></svg>DECISION D-065-9567
TICKET ticket-065
HEAD_SHA 0eb496d779a461430d6a24cd18ef381db4754eb7
CORRELATION_ID local-semcod-planfile-pr-66-ticket-065
ACTOR agent:ifuri-validator-agent[bot]
APPLIED_RULE P-CORE-015
INPUT author_login = "tom-sapletta-com"
INPUT observed_checks = ["notify=PASS","ci-loop=PASS","test (3.10)=PASS","test (3.13)=PASS"]
INPUT required_checks = ["ci-loop","notify"]
INPUT required_checks_source = "protected registry (env/request)"
INPUT reviewer_login = "ifuri-validator-agent[bot]"
INPUT superseded_checks = []
INPUT ticket_radar_receipt = {"schema":"subactor.ticket-radar/v1","base_sha":"bfc2db12d4e7bf30fe1402dfbf81c1b638576bd5","head_sha":"0eb496d779a461430d6a24cd18ef381db4754eb7","change_digest":"4c4cabcaba62688738bc9498a71229e6ce52becf0b1a268a23e8bcf9cd7cffd6","score":72,"complexity":"L","estimated_minutes":80,"split_recommended":true,"services":[],"authority":"ADVISORY","promotion":"FORBIDDEN"}
VERDICT APPROVE AUTHORITY DETERMINISTIC
REJECTED REQUEST_CHANGES BECAUSE NO_UNSAFE_CHANGE_REASON_FOUND
ADVISORY llm_verdict = "" MODEL "zai/glm-5.3"
ASSERT VERDICT_AUTHORITY != "ADVISORY"
Invalid strategy input used to become an empty mapping in ticket validation and TODO synchronization. This could report zero tickets or process result markers despite a failed configuration read.
Both APIs now share a loader that requires a readable UTF-8 YAML mapping. Missing/unreadable files, invalid encoding, malformed YAML and non-mapping documents raise stable ValueError messages without including YAML contents. An explicit empty mapping remains valid. TODO loading completes before any checkbox writes.
Validation: reproduced 10 failing cases before the fix; all 486 project tests passed after it (6 skipped). The pinned documentation checker passed with no findings or warnings. Python API documentation is updated to version 2 and binds the implementation revision.
Closes #65. Qualifies and repairs Doctor diagnoses subactor/doctor-agent#381 / PLF-13741 and #382 / PLF-13742. Source merge alone does not assert deployment or close those diagnostic records.