fix(ploeg): never read a current Run's verification from agent prose #204
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "ryangr0/ploeg-verification-provenance"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Stacked on #195. It touches the same
RoundReportsselect andRunReportfields. The three commits from #195 come first; this PR's own change is the last commit (4d79debc). Merge #195 first. Implements VIK-1780 (handoff EXEC-03), the remainder of VIK-1733 / #152.Problem
Since #152, a structured verification record beats prose. But
parseEvidencestill treats every writing Run without a record as a Run from an older worker, and parses its summary marker[Ploeg verification passed]and its### Ploeg verificationsection.A current Run with no configured checks, or with checks skipped because it was cancelled or opened no pull request, also has no record. Its summary and findings are the agent's to write. So the usage report on the pull request showed
Verification: passedandCommit verified: \``.TestACurrentRunWithoutAWorkerRecordNeverShowsAPassreproduces this through the real store. Ondevelopmentit renderspassedwith the agent's invented commit.Invariant
Change
Migration 0036. It adds
agent_runs.evidence_version(nullableSMALLINT, ≥ 1).ReportOutcomesets it tostore.CurrentEvidenceVersion(1) for every reported outcome. Existing rows stayNULL; nothing infers provenance from their text.parseEvidence. A record always wins. With no record, a stamped Run is "not recorded". Only an unstamped Run goes throughlegacyEvidence, which now marks its resultHistorical.Usage report. A historical result reads
Verification (historical prose, not a worker record): passed, unverifiedandCommit named in that prose (unverified): …, neverCommit verified.Verification.Validate(applied byhandleOutcometo every record; it refuses the report) now also refuses:passedrecord with zero checks;not_runcheck that carries an exit code or times.This is the chosen contract: these records are rejected, not normalised. Only a broken or forged worker sends one. It is documented in the schema description and on
Validate.Docs.
docs/how-to/review-an-agent-pr.mdand the outcome schema describe "not recorded" and the historical label.Acceptance criteria → tests
TestACurrentRunWithoutAWorkerRecordNeverShowsAPass. It fails ondevelopment.TestAnAgentCannotClaimTheWorkersVerification).TestAStructuredFailureSurvivesAnyNarrative.TestVerificationValidateRejectsInconsistentRecords, all of which validated ondevelopment, plus 2 API cases inTestValidateOutcomeReport.TestProseOfARunStoredBeforeTheDistinctionIsUnverifiedHistory; the legacy fixture inTestUsageReportEvidenceParsesVerificationAndCommitnow expects the historical label.TestRoundReportsCarryTheWorkersVerification.Test fixtures with zero timestamps were updated to real ones: the worker's
incompleterecord and the API'sverification passedcase.Commands (at
4d79debc, Go 1.27.1, Node 24.21.0)mise exec -- go test ./pkg/harness/ ./pkg/shiftengine/ ./pkg/store/ ./pkg/httpapi/ ./pkg/worker/ -count=1 -v: 600 passed, 0 failed, 4 skipped (the operator qualification tests, whichmise run integrationruns)mise exec -- go test ./... -count=1in apps/ploeg: 34 packages okmise run verify: all gates passed (vloer 7, demo-replay 1, vloer-extension 4, ploeg 7, brand 1, site 5, site-demo 1, helm 15, release 3, integration 1, docs 1)Migration and rollback
Additive column. An old binary ignores it. Rolling back the binary leaves the column in place and harmless. Migration number 0036: if another branch also adds 0036, renumber whichever merges second.
Not in scope
Refs VIK-1780
🤖 Generated with Claude Code
Pull request closed