docs: say a Run's verification comes only from the worker's record #208
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "ryangr0/replace/204-verification-provenance"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Replaces #204 (fix(ploeg): never read a current Run's verification from agent prose) after the Ploeg separation in #206. Its Ploeg part is ploeg-hq/ploeg#53; this PR moves Unfold's pin to that branch and carries the rest.
Stacked on the replacement for #195. Merge that one first; this PR then shows only its own two commits.
Commits
0f65ecf1build(ploeg): pin ploeg-hq/ploeg#53 to keep verification provenance1b288205docs: say a Run's verification comes only from the worker's record (from4d79debc13)Merge order
build(ploeg)commit to the merge commit on Ploeg'smain, then merge. Until then theploeg-pincheck is red by design: it requires the pinned commit on Ploeg'smain.Verification (local, at
1b288205with Ploege57d7e17)mise run verifywith the result cache, as a pull request runs it: all gates passed. That includes the Ploeg group (its ownscripts/verify.shat the pin), Vloer, the extension, the demo replay check, integration (managed qualification) and docs.What happened to each commit of #204
bb9b3861fa146cf69feec2ced7378a4d79debc131b288205("docs: say a Run's verification comes only from the worker's record")The original had no reviews or comments. Its checks were red because
developmentitself failed atmise install --locked; #206 fixes that lock. No earlier check result carries over.Original description of #204
Stacked on #195. It touches the same
RoundReportsselect andRunReportfields. The three commits from #195 come first; this PR's own change is the last commit (4d79debc). Merge #195 first. Implements VIK-1780 (handoff EXEC-03), the remainder of VIK-1733 / #152.Problem
Since #152, a structured verification record beats prose. But
parseEvidencestill treats every writing Run without a record as a Run from an older worker, and parses its summary marker[Ploeg verification passed]and its### Ploeg verificationsection.A current Run with no configured checks, or with checks skipped because it was cancelled or opened no pull request, also has no record. Its summary and findings are the agent's to write. So the usage report on the pull request showed
Verification: passedandCommit verified: \``.TestACurrentRunWithoutAWorkerRecordNeverShowsAPassreproduces this through the real store. Ondevelopmentit renderspassedwith the agent's invented commit.Invariant
Change
Migration 0036. It adds
agent_runs.evidence_version(nullableSMALLINT, ≥ 1).ReportOutcomesets it tostore.CurrentEvidenceVersion(1) for every reported outcome. Existing rows stayNULL; nothing infers provenance from their text.parseEvidence. A record always wins. With no record, a stamped Run is "not recorded". Only an unstamped Run goes throughlegacyEvidence, which now marks its resultHistorical.Usage report. A historical result reads
Verification (historical prose, not a worker record): passed, unverifiedandCommit named in that prose (unverified): …, neverCommit verified.Verification.Validate(applied byhandleOutcometo every record; it refuses the report) now also refuses:passedrecord with zero checks;not_runcheck that carries an exit code or times.This is the chosen contract: these records are rejected, not normalised. Only a broken or forged worker sends one. It is documented in the schema description and on
Validate.Docs.
docs/how-to/review-an-agent-pr.mdand the outcome schema describe "not recorded" and the historical label.Acceptance criteria → tests
TestACurrentRunWithoutAWorkerRecordNeverShowsAPass. It fails ondevelopment.TestAnAgentCannotClaimTheWorkersVerification).TestAStructuredFailureSurvivesAnyNarrative.TestVerificationValidateRejectsInconsistentRecords, all of which validated ondevelopment, plus 2 API cases inTestValidateOutcomeReport.TestProseOfARunStoredBeforeTheDistinctionIsUnverifiedHistory; the legacy fixture inTestUsageReportEvidenceParsesVerificationAndCommitnow expects the historical label.TestRoundReportsCarryTheWorkersVerification.Test fixtures with zero timestamps were updated to real ones: the worker's
incompleterecord and the API'sverification passedcase.Commands (at
4d79debc, Go 1.27.1, Node 24.21.0)mise exec -- go test ./pkg/harness/ ./pkg/shiftengine/ ./pkg/store/ ./pkg/httpapi/ ./pkg/worker/ -count=1 -v: 600 passed, 0 failed, 4 skipped (the operator qualification tests, whichmise run integrationruns)mise exec -- go test ./... -count=1in apps/ploeg: 34 packages okmise run verify: all gates passed (vloer 7, demo-replay 1, vloer-extension 4, ploeg 7, brand 1, site 5, site-demo 1, helm 15, release 3, integration 1, docs 1)Migration and rollback
Additive column. An old binary ignores it. Rolling back the binary leaves the column in place and harmless. Migration number 0036: if another branch also adds 0036, renumber whichever merges second.
Not in scope
Refs VIK-1780
🤖 Generated with Claude Code
🤖 Generated with Claude Code
1b28820551e8ec7ba335e8ec7ba3358c32a31bbd