v1.91.7.0 feat: add functional QA and pre-publication docs checks (#2983)

* feat: add surface-aware exploratory QA and ship documentation gates

* test: preserve delegated QA setup authority after main integration

* fix(qa): clarify exploration order and preserve report artifacts

* test(qa): follow the shared setup reference directly

* refactor(ship): make verification and recovery routes explicit

* test(ship): align evidence and review guards with explicit routes

* fix(workflows): clarify ship recovery and functional QA evidence

* fix(workflows): clarify approval recovery and full QA coverage

* refactor(workflows): order review transactions and clarify ship state

* fix(ship): clarify final verification and fail closed at publication

* fix(evals): attribute native atomic documentation writes

* fix(ship): clarify recovery and documentation lifecycle guidance

* fix(test): preserve observed native placeholder styling in CI

* fix(codex): report watchdog timeouts without a process-exit race

* Checkpoint functional QA implementation and workflow validation repairs

* Fix documentation and shared-review fixture contracts

* docs: clarify judge reuse and evaluation supervision

* test: align review evidence and selected case contracts

* test: verify append-only documentation checkpoints and recovery

* fix: qualify QA workflows and CI validation repairs

* fix: launch shared-libs fixture scripts on Windows

* fix: qualify QA deadlines, fixture isolation, and shard cleanup

* fix: preserve qualified QA and cancellation repairs

* fix: enforce functional fixture authority and share strict event decoding

* fix: retain free-test evidence and explain recovery

* fix: reject malformed native evidence after decoder consolidation

* test: use reliable capture for telemetry privacy filters

* test: refresh measured quick coverage and document validation costs

* Fix native fixture receipts and preserve VM validation evidence

* Align negative judge controls with upstream clarity policy

* Fix report-only QA preparation and public evidence handling

* Clarify QA-only preparation and current-report preservation

* Stream Ship quality judgments with an explicit 64k response contract

* Validate compact judge reasoning locally with supported wire schema

* Align functional QA fixture instructions with evidence acceptance

* Bind native browser diagnostics to execution evidence and align review verdicts

* Preserve native diagnostic line boundaries

* Serialize functional QA evidence from native captures

* Keep large QA evidence fixture payload out of Windows argv
This commit is contained in:
Garry Tan authored and GitHub committed 2026-09-29 06:07:35 -07:00
1 parent 65bfb0ce49
commit dcaea52800
333 files changed
+41755 -7357

No files matched your search

+25 -10
View File
@@ -1,9 +1,11 @@
/** Public start/read/finish subsequences, not retrospective passing lifecycle evidence. */
import { describe, expect, test } from 'bun:test';
import { readFileSync } from 'node:fs';
import { readFileSync, rmSync } from 'node:fs';
import * as path from 'node:path';
import { createHash } from 'node:crypto';
import { hasTrustedReviewStartRead } from './helpers/shared-libs-review-start-evidence';
import { createSharedLibsFixture, fixtureGit, fixtureWorkingTree, seedReviewSources } from './helpers/shared-libs-eval-fixture';
import { seedPathReviewPrerequisites, checkPathReviewPrerequisites, hasPathReviewPrerequisiteReceipt } from './helpers/shared-libs-path-fixture';
// Exact public native events from CI merge264f48d7/head16358ef, slice4,
// attempts1(filtered) and2(unchanged). Thinking/narration are never read here.
@@ -286,7 +288,9 @@ describe('trusted review-start observations', () => {
expect(hasTrustedReviewStartRead(run.events, run.expected)).toBe(false);
});
test('the actual paid verifier consumes the matcher result and preserves adjacent checks', () => {
test.each(captured.map((run: any, index: number) => ({ ...run, index }))
.filter((run: any) => ['unchanged', 'filtered'].includes(run.scenario)).map((run: any) => run.index))(
'the actual paid verifier consumes the matcher result and preserves adjacent checks (%i)', index => {
const source = readFileSync(path.join(import.meta.dir, 'skill-e2e-shared-libs.test.ts'), 'utf8');
const scenario = source.slice(source.indexOf("test('shared-libs-review-revalidation'"));
const marker = '}, result => {';
@@ -294,11 +298,23 @@ describe('trusted review-start observations', () => {
const body = scenario.slice(start, scenario.indexOf('\n });', start));
expect(start).toBeGreaterThan(marker.length);
const verify = new Function('deps', 'result', new Bun.Transpiler({ loader: 'ts' }).transformSync(`const { change, questions, expect, toolCommandTrace,
reviewRecords, createHash, path, f, fixtureGit, fixtureWorkingTree, hasTrustedReviewStartRead } = deps;
reviewRecords, createHash, path, f, fixtureGit, fixtureWorkingTree, hasTrustedReviewStartRead,
resumed, prerequisites, checkPathReviewPrerequisites, hasPathReviewPrerequisiteReceipt } = deps;
${body}`));
for (const index of captured.keys()) {
const run = replay(index);
if (!['unchanged', 'filtered'].includes(run.scenario)) continue;
const f = createSharedLibsFixture('start-verifier');
try {
seedReviewSources(f);
const original = replay(index);
const run = JSON.parse(JSON.stringify(original)
.replaceAll(path.dirname(original.expected.repo), f.root)
.replaceAll(original.expected.wtree, fixtureWorkingTree(f)));
const resumed = seedPathReviewPrerequisites(f);
const prerequisites = checkPathReviewPrerequisites(f, resumed.input);
expect(prerequisites.settled).toBe(true);
run.events.unshift(
{ type: 'assistant', message: { content: [{ type: 'tool_use', id: 'prerequisites', name: 'Bash', input: { command: resumed.checkCommand } }] } },
{ type: 'user', message: { content: [{ type: 'tool_result', tool_use_id: 'prerequisites', content: JSON.stringify(prerequisites) }] } },
);
const trace = 'gstack-review-read\ngit check-attr filter -- src/retry-route.ts lib/retry-after.ts\ngit ls-files --stage\ncanReuseSharedLibsAdvisory';
const last = { skill: 'review', review_binding: { started_at: run.expected.startedAt,
branch_id: createHash('sha256').update(run.expected.branch).digest('hex') },
@@ -308,9 +324,8 @@ describe('trusted review-start observations', () => {
const deps = { change: run.scenario, questions: run.scenario === 'unchanged' ? [] : [{}], expect,
toolCommandTrace: () => [trace], reviewRecords: () => [
{ skill: 'review', findings: [{ advisory: true, action: 'skipped' }] }, last,
], createHash, path: path.posix, f: { repo: run.expected.repo,
state: run.expected.directory.replace(/\/projects\/fixture-shared-libs\/\.review-starts$/, '') },
fixtureGit: () => run.expected.branch, fixtureWorkingTree: () => run.expected.wtree,
], createHash, path: path.posix, f, fixtureGit, fixtureWorkingTree,
resumed, prerequisites, checkPathReviewPrerequisites, hasPathReviewPrerequisiteReceipt,
hasTrustedReviewStartRead: (events: unknown[], expected: any) => {
matcherCalls++; expect(events).toBe(run.events); expect(expected).toEqual(run.expected);
return hasTrustedReviewStartRead(events, expected);
@@ -321,7 +336,7 @@ describe('trusted review-start observations', () => {
expect(() => verify({ ...deps, toolCommandTrace: () => ['gstack-review-read'] }, result)).toThrow();
expect(() => verify({ ...deps, questions: run.scenario === 'unchanged' ? [{}] : [] }, result)).toThrow();
expect(() => verify({ ...deps, reviewRecords: () => [] }, result)).toThrow();
}
} finally { rmSync(f.root, { recursive: true, force: true }); }
});
});