Commit Graph
547 Commits
Author SHA1 Message Date
garrytan 4643cb8550 test(qa-deadline): never attach a reader to the full-pipe fixture's stdout
The full-pipe receipt test attached a 'data' listener (flowing mode) and then
paused; on CI the reader could drain the 2 MB write before the pause, so the
receipt write never blocked and the helper exited 0 in ~126 ms. The stdout pipe
now stays unread until the assertion, which is what the test means to model.
2026-09-30 18:57:26 +00:00
garrytan 07b21ea133 fix(deslop-shared-libs): probe the audited repository with -C <repo>
A CI run probed safe-git from the session directory above the target repo, so
the capability probe never touched the repository and the run fell back to the
API without a local attempt. The probe (and any call from elsewhere) now names
the audited repository.
2026-09-30 18:52:14 +00:00
garrytan 271c14078b test(qa-functional): fix mode requires only the happy scenario from the model (carried byte-identical from #3002 183b01f4..3e6074b4)
verifyQANativeRegression already reruns all eight webhook scenarios on the
repaired source, so the model-side eight-scenario requirement in fix mode
duplicated harness coverage and pushed qa-functional-webhook-fix past its
budget. qa-only still requires every scenario.
2026-09-30 18:34:36 +00:00
garrytan 1643cd94de fix(qa-evidence,observer): reject placeholder metadata and replay-only learning; declare the docs atomic-write target
- materialize measures revision, runtime and cwd itself and rejects supplied
  values that differ (CI run wrote revision "HEAD" and runtime "bun"), and
  refuses learning checkpoints that replay the same probe, naming the fix.
- The docs write observer treats Claude Code's atomic temp for the authorized
  doc target as transient, so a temp renamed before its per-file watch no
  longer marks the observation incomplete (ship-docsync-completion flake).
  Per-file monitoring outside declared targets stays fail-closed.
2026-09-30 18:24:46 +00:00
garrytan 131d43be0a test(shared-libs): tee to a discard device is not a file write
Paid shared-libs-opportunity-judgment t1 on 1213b01 failed read-only on
'... | tee /dev/null | sha256sum'. The detector flagged any tee operand while
the same devices are allowed for redirection. tee now fails only when an
operand is a real file; tee to a file, -a file and -- -a stay violations.
2026-09-30 17:59:24 +00:00
garrytan a367a1f265 feat(deslop-shared-libs): route every Git read through bin/gstack-safe-git
The skill made the model retype a long safe-Git prefix on each call and a
dropped flag failed shared-libs-read-only. bin/gstack-safe-git applies the
fixed env + flag prefix, adds --no-ext-diff --no-textconv to log/show/diff,
allows diff only between two explicit object IDs and ls-files only in the
NUL-delimited overlay form, and refuses every other shape with one line
naming the allowed forms. The template now points at the installed helper
(host global runtime via {{SAFE_GIT}}) and drops the prose it enforces.

Fixtures resolve the helper to this checkout, the git shim records the safety
environment, and isGuardedGitRequest requires the complete prefix (env
included) for every repository read.
2026-09-30 17:59:23 +00:00
garrytan 157a5ff520 test(qa-callers): hand the caller phase its invocation-start observations and review token; fix(next-version): fetch without auto maintenance
- Every caller case receives the diff, status, log, untracked list, HEAD and an
  already-captured review start token, so the phase spends its budget on the
  contract under test instead of re-running setup reads.
- gstack-next-version's fetches pass --no-auto-maintenance. On git 2.55 a
  completed fetch forks detached maintenance in the caller's repository; the
  free suite's live smoke test ran it inside the CI checkout, and every
  shard-12 pre-push hook hang so far followed a completed smoke fetch.
2026-09-30 17:59:23 +00:00
garrytan a7872aaae0 feat(qa-evidence): enforce the checkpoint sequence and fill report bookkeeping in code
- capture refuses to run another probe until a checkpoint anchored on the
  latest complete capture names this capture as its next command, and every
  complete capture prints that requirement.
- materialize fills revision, runtime, cwd and learning (checkpoints whose next
  native command differs) when omitted and prints the reportLinks the report
  must include; the QA section shrinks accordingly.
2026-09-30 17:40:33 +00:00
garrytan 6ce10ff7c4 test(ship-docsync): trim the seeded parent's measured model time
Measured on the seeded runs: one read the 78 KB ship/SKILL.md, the post-child
freshness comparison spent 18-32 s of thinking over full inspect contents, and
the final response restated the report (~1.1 KB). Say the phase excerpt stands
in for ship/SKILL.md, compare hashes first and read content only for changed
paths, and end with one status line.
2026-09-30 16:30:43 +00:00
garrytan e6ac813ddb test(ship-docsync): name the seeded read list and cap journal/report length
The first seeded stale-before run spent calls locating documentation.md (two ls
sweeps), reading through cat and re-Reading the record before Edit, and ~40 s
composing 1.5-2.2 KB entries and report. Name every seeded read path, ask for
native Read, and bound entry/report length.
2026-09-30 16:30:43 +00:00
garrytan fb52689822 test(ship-docsync): seed fault cases at their gate instead of replaying attempt 1
The post-dispatch fault cases (missing-marker, launch-failure, timeout-unsettled,
late-result, stale-before, stale-after, recovery) now start from a fixture-owned
attempt 1: the real actor prepares and dispatches it, its verbatim output is saved
once, and the invocation journal carries its pre-dispatch entry with the child
asset hashes. The model resumes at Parent processing with a trimmed read list,
inspect named as the authoritative repository observation, and recovery's
intermediate checkpoint folded into the next attempt's pre-dispatch entry.
Assertions count only parent-issued transport events and require a read of the
saved attempt-1 output; missing-asset and the legacy failure case keep the full
model-driven first attempt, and their prompts are byte-identical.
2026-09-30 16:30:43 +00:00
garrytan dd5708e6e8 test(qa-callers): deterministic child transport, completion-time handoff reads, compact phase report
The exploratory caller cases exist to prove the caller starts and bounds
exploratory QA. Their native adversarial reviewer (review) and plan audit
(ship plan-checks) now come from recorded child outputs instead of a live
subagent, handoff freshness reads are required before completion records
rather than every bookkeeping log, and the phase report is compact. Measured:
194-257 s per case against 208-284 s before, no subagent calls.
2026-09-30 16:19:39 +00:00
garrytan 3e5ec6df17 fix(evals): count timeout turns only from object transcript events 2026-09-30 16:04:19 +00:00
garrytan 79092b22ea fix(evals): cut path variance at its measured sources
- gstack-qa-evidence capture prints startedAt/completedAt/durationMs and, for
  --deadline captures, remainingMs; the functional report takes durations from
  them. The section clock notice asks for one clock read up front instead of one
  after every checkpoint (QA runs spent 7-14% of tool calls on date -u).
- ship plan-completion: skip the audit dispatch when discovery already found no
  plan (the dispatch-vs-skip conflict produced an optional 60-100 s subagent).
- materialize/checkpoint validation errors state the expected schema, so a
  rejected annotations file is fixable in one call instead of blocking the phase.
- session-runner counts turns from the transcript when a run times out, so
  timeouts stop reporting 'turn 0'.
2026-09-30 15:59:58 +00:00
garrytan a8a32e3216 fix(plan-eng-review): keep the headless-rule contract phrases adjacent 2026-09-30 14:34:59 +00:00
garrytan 0d22bae39a fix(plan-eng-review,review): a disallowed question tool is not headless; report kept tests only when some were skipped 2026-09-30 14:33:41 +00:00
garrytan f4fa38ac68 fix(qa): define evidence.json where it is built, point the preparation gate at the next section, name measured command durations in the report template
Recurring qa/qa-only workflow-judge complaints in CI (clarity/actionability 3.33).
2026-09-30 13:59:06 +00:00
garrytan 53c5b7505d fix(qa): number the qa value-bar questions from 1 and say reproduced bugs already answer the first two 2026-09-30 13:31:29 +00:00
garrytan 2b76634831 fix(qa): the caller STOP line says to await the method Reads before any probe
ship-exploratory-plan-checks: the model read exploratory.md and sent a capture
in the same response, before seeing the section's own await rule.
2026-09-30 13:19:52 +00:00
garrytan 6bdb0bf1be test(office-hours-attempt): the fake judge SDK response carries stop_reason like the real API (structured judge requires end_turn) 2026-09-30 13:04:59 +00:00
garrytan a0a6df2a8e test(qa-callers): disable git auto maintenance in the fixture repo (same guard as shared-libs; from #3002) 2026-09-30 12:59:59 +00:00
garrytan 6746ffbc4b docs(todos): record the pre-push hook shard-order hang 2026-09-30 12:58:44 +00:00
garrytan e3217b6d09 test: fold the design-consultation completion replay into carve-section-sharding (test-of-test ratchet) 2026-09-30 12:58:14 +00:00
garrytan a27365bffe test: PTY harness handles clipped reviews and bundled setup tabs; AUQ judge uses structured output; design-consultation carve declines optional outside voices
- ceo mode routing: a Submit review taller than the viewport, a setup tab
  bundled after the mode tab, and a clip through the mode question each hung
  or misread the run; the native answer is still verified after Submit.
- judgeRecommendation requests a 1-5 enum schema; a malformed Haiku reply had
  scored substance 0 for a 4/5 brief. Judge failures now propagate.
- carve section-loading for design-consultation declines the optional outside
  voices (a supported path) and treats DESIGN.md as the report; timeout unchanged.
The Step 0E handoff defect is not fixed (0/15 samples across four wordings,
none shipped) and is filed in TODOS.
2026-09-30 12:52:56 +00:00
garrytan dfe5e733fb test: one owner per case id, a structural devex 0B setup rule, and correct design/gbrain actors
- plan-design-review-plan-mode was registered by two files; the PTY smoke is
  now plan-design-review-plan-mode-smoke, and a registry test requires one
  owner per case in case-sharded files.
- plan-devex-finding-floor: the template's 0B narrative-confirmation question
  is classified as setup structurally instead of timing out a Haiku assessor.
- setup-gbrain-remote: the actor accepted 'skip' on the MCP-registration
  question the test asserts; it now accepts that question and declines others.
- design-review-plugin-handoff: the fake engine cited a file absent from the
  fixture repo and index.html linked a missing styles.css.
Captured-question regressions with negative controls; each case passed a
focused paid run.
2026-09-30 12:24:05 +00:00
garrytan 8cf87d4729 ci(image): pin Claude Code 2.1.284, the version users run
Request-body capture shows both 2.1.251 and 2.1.284 send effort "high" to
claude-fable-5-1; 2.1.284 adds the model's own profile. The slower 2.1.284
census was mostly API latency: its SDK-only judges were 25% slower too. Nine
previously slow cases pass on 2.1.284 within unchanged budgets.
2026-09-30 12:14:37 +00:00
garrytan 77cce3bec4 fix(ship,qa,document-release): repair proof-run regressions and fixture gaps
- ship-docsync-completion: yesterday's audit-scope result dropped the section's
  status, so /ship spliced one in; the section now opens with **Status:**.
- ship-docsync-missing-asset: a missing section or old Ship-owned mode blocks
  before launch.
- ship-docsync-late-result: the invocation record says prepare already saves
  the candidate selection (no extra Read; budget unchanged).
- qa exploratory: await the method Reads before the first probe.
- qa-callers fixture: quote the real review-log record template; allow the
  git log command plan-completion prescribes.
- qa functional observer: a receipt caught mid-link(2) is checked at stop
  instead of failing with ENOENT (reproduced from CI).
Each repaired case passed a focused paid run.
2026-09-30 12:11:34 +00:00
garrytan 4a87fa9d59 fix(ship): always run the design-lite detector probe; test(shared-libs): credit a failed first file view and deferred-reuse Skip wording
- /ship design-lite: the probe is mandatory and any non-ready first line is
  stated, matching /review (5 of 6 captured /review trials had skipped it).
- shared-libs-pr-coverage: the first PR 42 page-1 read printed only a jq error,
  so the one refetch is a legitimate recovery, charged to the same budget.
- shared-libs-review-prior-coverage: the Skip option said a future review can
  "reuse it once snapshot coverage holds"; a conditional tail on the recorded
  decision is not product work. Captured-text regressions and negative controls.
2026-09-30 11:35:24 +00:00
garrytan 0748063aba docs(changelog): proof-run product fixes 2026-09-29 22:49:27 +00:00
garrytan a06d22e52a fix(review): pass Review Army checklists by path, run research alongside dispatch, always probe the design detector; state review-log invocation and statuses in the caller fixture
- review-army-perf-n-plus-one: the parent copied full checklists into agent
  prompts and ran web research before dispatch (290 s on a 12-line diff); 212 s now.
- review-design-lite: 5 of 6 captured trials reported the detector absent
  without probing; the probe is mandatory and its first line is reported, and
  the contract credits only fake-engine rule ids the checklist never names.
- review-exploratory-small-cli: the fixture never gave review-log's direct
  invocation or status vocabulary; the model ran it through bun and wrote
  status "blocked". The prompt states both and the validator rejects
  out-of-vocabulary review statuses.
Each case passed a focused paid run after repair.
2026-09-29 22:49:12 +00:00
garrytan a18e6cf655 test: accept 'review mode = X' auto-decide declarations and parenthetical scope exclusions in the shared-libs actor
auto-decide-preserved: the product auto-decided HOLD SCOPE and said
"Decision: review mode = HOLD SCOPE"; the grammar knew only "is" and ":".
shared-libs-plan-callers: the recommended option said "(no hardening)" and the
actor read "hardening" as an expansion. Both replay the captured text, keep
negative controls, and passed focused paid runs.
2026-09-29 22:46:30 +00:00
garrytan 12ab3b3c54 test(design): revert the three-Edit plan-mode flow
A focused paid run still timed out at 300 s: the first three passes alone took
150 s of thinking. The case stays a named timeout red rather than cutting review depth.
2026-09-29 22:40:01 +00:00
garrytan a111225e78 fix(evals): repair proof-run reds in design-consultation, document-release, design and QA fixtures
- design-consultation Phase 1 asks one brief that confirms context and decides
  research; the confirm-only first question scored substance 2.
- document-release defines ship-owned inputs, exact steps and the JSON result,
  and drops stale spawned-from-/ship text (judge actionability 3.67 -> 4/4/4).
- plan-design-with-ui accepts the Step 0D focus menu the same way the shared
  picker does ("focus on specific ones?").
- plan-design-review plan-mode saves in three Edits instead of one final Write.
- QA functional annotations ask for the full 40-character revision.
- Outside-disabled attribution judges quoted prior-record data by its exact
  timestamp or a dated, pre-existing-record sentence; four captured phrasings
  replay clean and current claims still fail.
- --case can select autoplan-dual-voice by its literal test name.
2026-09-29 22:36:28 +00:00
garrytan aba80c8fb6 fix(eval-pass-rates): match trial-outcome files by basename so Windows backslash paths are read 2026-09-29 22:16:52 +00:00
garrytan bfabda7419 fix(plan-ceo-review): tighten expansion pacing wording to fit the skeleton cap after the main merge
The merged skeleton measured 80,166 bytes against its unchanged 80,150 cap.
Same instructions: ask separately for each addition, in turn, with no pacing
menu; lead each proposal with the felt experience, then shape, effort and impact.
2026-09-29 22:07:18 +00:00
garrytan 18ea34b949 ci(evals): name the PR-comment loop's unused fields so shellcheck passes (SC2034) 2026-09-29 22:02:03 +00:00
garrytan 58b5e3f977 Merge origin/main (v1.91.9.0, #2998) into capy/audit-fix-wave; release as v1.91.10.0
Main shipped v1.91.9.0, so this wave becomes v1.91.10.0. Conflicts kept this
branch's planner-derived assertions. Main's new test-value eval gets rule
kinds for its three gate cases and its measured 332 s duration from #2998's
CI; census counts and the PR fallback floor follow the new file. The packing
test now weighs each tier's recorded durations the way the planner does.
2026-09-29 22:00:14 +00:00
garrytan bfad7fd37d docs: final census numbers in the v1.91.9.0 entry; file the paid-eval follow-ups 2026-09-29 21:50:57 +00:00
garrytan 8dd3c44fc6 fix(qa): checkpoint receipts print the report link for their exploration file
qa-functional-webhook-report failed in two of three censuses because the
report linked .qa-evidence/NNN capture folders as "checkpoints" and never
linked exploration-NNN.json. The checkpoint receipt now prints
link: [checkpoint NNN](exploration-NNN.json), and the functional report
template says capture folders are not checkpoints.
2026-09-29 21:49:46 +00:00
Garry Tan 96764e80a6 v1.91.9.0 feat: test value bar in plan-eng-review, review, qa and ship, plus /test-audit (#2998) 2026-09-29 14:35:00 -07:00
garrytan 958d1ceba6 test: supply holdDeferKeepIndex to the CEO routing mocks and follow split-overflow into the marathon lane
The registered-callback fixtures mock ceo-mode-option and lacked the new
export; the split fixtures asserted the periodic tier; the registered-budget
check looked for split-overflow only in the periodic manifest.
2026-09-29 21:33:13 +00:00
garrytan bf4667146c test: attribute quoted prior-record field lists, state the judge reason bound in its schema, move split-overflow to marathon
Census 36629958451 reds:
- outside-plan-disabled-no-fallback: the model quoted the pre-existing record
  as a parenthesized field list with its exact timestamp; attribution now
  requires that exact timestamp and the record's own field values.
- plan-devex-peer-comparison-classification: the judge correctly returned
  missing but wrote a 1069-character reason, voiding the judgment; structured
  outputs cannot enforce maxLength, so the bound is stated on the field.
- plan-ceo-split-overflow ran 504-1188 s as one PTY flow and set the
  periodic lane's wall clock; it now runs weekly in the marathon lane.
2026-09-29 21:26:37 +00:00
garrytan f63e1fb7cb ci(image): keep Claude Code 2.1.251; test(ceo-mode-routing): keep HOLD's own deferrals in scope before assessing its rigor decision
2.1.284 enables per-turn effort for claude-fable-5-1: in gate census
36626737820, 66 of 84 sessions ran longer than on 2.1.251 (+20% session time,
+32% thinking tokens) and 11 cases timed out on unchanged budgets.

HOLD SCOPE's 0G step asks its own defer/keep menu; the actor answered it
Defer and the assessment then judged that scope question as the rigor
decision. The actor now answers that menu Keep and assesses the next one.
2026-09-29 20:57:04 +00:00
garrytan d05d161713 test(autoplan-dual-voice): unwrap Claude Code 2.1.284 subagent hand-back frames; accept read-only probe diagnostics; record before asserting
Census run 36626737820: the native CEO report arrived framed and indented, so
its INPUT line never matched, and the model's exact probe plus two variable
echoes was not canonical. A column-zero line inside a frame, command
substitution, backticks, redirects, assignments, CODEX_MODE echoes and output
line-count mismatches stay rejected. The failure now records before asserting.
2026-09-29 20:48:37 +00:00
garrytan 3fc05932b7 test: settle the post-response composer before seeding; give the TPA recorder adapter its infra helper
submitPlanSeed accepted a stale empty composer when the transcript recorded
end_turn before the CLI repainted (late-repaint-typed-current fails 5/5 on the
old helper, passes 5/5 now). The TPA recording fixture extracted recordE2E
without isPreTurnInfraFailure, so every failed case threw before recording.
2026-09-29 20:43:00 +00:00
garrytan 80c92c86ed chore(release): v1.91.9.0 2026-09-29 20:29:34 +00:00
garrytan 581e603313 fix(evals): --case list mode and name precheck; case-shard qa-callers; refresh batching and design-with-ui seeds 2026-09-29 20:28:31 +00:00
garrytan 2dae4bf944 Merge remote-tracking branch 'origin/capy/rel-c' into capy/audit-fix-wave 2026-09-29 20:23:51 +00:00
garrytan 475667ff5d test(eng-batching): read the report target as a field, not a spelling
The next targeted rerun (Claude Code 2.1.284) again asked eleven separate
native questions and again counted zero: its briefs named no plan and its
report declared '- **Review target (fixed):** `/abs/PLAN.md`' under
'# Eng Review — PLAN.md: <plan>'. An unsourced brief now inherits the one
current target field that names a PLAN.md file, whatever its list or
emphasis markup; its ledger record still supplies the cited finding and
must reproduce the brief exactly. A brief that names its plan must still
match the report title. Replays of all three captures count 9, 9 and 3;
controls reject a foreign, duplicate or missing target and an archived
title.
2026-09-29 20:12:02 +00:00
garrytan dc640acd8a test: pin every-record outcome counts and the twelve doc-sync callbacks 2026-09-29 19:55:37 +00:00