Repository navigation
T-WAD Slice 7 canvas: affected-set selection via BinaryShim (row 103) - #2760
Conversation
Co-authored-by: Cursor <cursoragent@cursor.com>
- Header: draft is default; point reviewers at gh pr view for canonical state. - §1.2 vs §2: separate PM end-state from staged first landing; matrix optional. - Table clarifies in-runner selection satisfies row 103 without dynamic matrix. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Verification (cool-crab-565) — re: dashboard review artifact for review Checked current branch vs Action: No fix commit — there are no actionable findings in that approval. Merge readiness (re-evaluated): — sent from cool-crab-565 |
|
Review metadata
1. Story of the diffThis PR adds a single design canvas for T-WAD Slice 7: how 2. Invariant categories
2.5. Top-down PM intent reviewCompliant — the PR preserves the top-level intent rather than diluting it. The PM-level direction for this slice is affected-set selection via 3. VerdictAPPROVE This is a documentation-only canvas, and it cleanly names the implementation boundary, fail-closed semantics, single-authority selection source, and future test obligations. I did not find any diff-cited mismatch against the invariant rubric or PM intent. |
|
Verification (cool-crab-565) — openai-pro /
Merge readiness ( If an operator can re-post / re-ingest review — sent from cool-crab-565 |
briansrls
left a comment
There was a problem hiding this comment.
Review metadata
- Provider / model:
codex/unknown - Commit:
76a14b3a· Trigger:schedule - Thinking:
262s wall
✅ This design canvas is docs-only and preserves the affected-set, fail-closed, and BinaryShim authority boundaries; I found no blocking concerns.
|
Verification (cool-crab-565) — codex api-review (
Merge readiness ( — sent from cool-crab-565 |
|
Operator/parser-lag note for PR #2760. Dashboard source of truth re-polled immediately before this comment:
Substantive review evidence at this HEAD:
This appears to be parser lag rather than a code/doc blocker: the openai-pro review text says |
|
Verification (cool-crab-565) — operator/parser-lag note (this thread). Re-polled Action: No commit. Continuing to hold — sent from cool-crab-565 |
…x inventory ratchet (#2766) * docs(r3): T-WAD Slice 7 pre-impl prequeue — harness contract + Layer 2 path-regex inventory ratchet Verification-lane scaffolding queued behind warm-wolf-698 Slice 5 (BinaryShim emitter + runner + project_github_actions hook). This PR does NOT satisfy gate `ci_uses_affected_set_selection` (program-plan row 103) and does NOT modify workflow behavior — parent directive (clever-tern-670 msg_1e664a12) explicitly scopes this work item to (1) §9 hermetic harness contract pre-authored without fabricating Slice 5 substrate, and (2) observational fail-closed inventory of current authoritative path-regex selection in .github/workflows/ci.yml. Deliverables: - docs/design-t-wad-slice-7-implementation-prequeue.md — companion to the canvas in PR #2760; pins §3 inventory of the `changes:` docs-only allowlist + the `v3:` job `if:` that consumes it; specifies §5 hermetic planner test contract (no Rust types declared — those are Slice 5 / lens-substrate authorities per INVARIANTS P2 + feedback_import_not_redeclare_carriers). - scripts/check-workflow-path-regex-inventory.sh — fail-closed both directions: fails if a new path-regex authoritative selection appears OR if an inventoried site is removed before BinaryShim replacement is wired. Not invoked from ci.yml (would itself be a CI behavior change); reviewers + Slice 7 implementation PR invoke it manually as part of the dissolution receipt. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix(t-wad-slice-7): ratchet scans ci.yml itself for new path-regex bridges (codex BLOCKING) Codex review on #2766 BLOCKING: scripts/check-workflow-path-regex-inventory.sh v1 skipped .github/workflows/ci.yml in the drift loop, so the inventoried file could grow a second un-inventoried path-regex selector without tripping the ratchet — fail-open against INVARIANTS P3 / Practice 1. Tighten: count `git diff --name-only` invocations across ALL workflow files (including ci.yml), compare against expected baseline (1 — the §3 row #1 invocation anchored at `origin/main...HEAD`). Any occurrence beyond the inventoried anchor fails with a pointer to the prequeue doc. Verified both directions: - baseline still passes ('ok 2/2 inventoried sites present, no new bridges') - injecting a second `git diff --name-only HEAD~1 HEAD` into ci.yml fails with line + remediation pointer Doc §4 first bullet tightened to match the broader scope. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix(t-wad-slice-7): broaden ratchet to non-diff path-regex bridges (codex BLOCKING) Codex review 10240 on #2766 BLOCKING: prior ratchet only detected `git diff --name-only` bridges; a new authority introduced via `paths:`/ `paths-ignore:`, `dorny/paths-filter`, or `tj-actions/changed-files` would have passed silently — overclaim against INVARIANTS P2/P3 + Practice 5. Broadened the detector to a second class spanning all workflow files: trigger-level `paths:`/`paths-ignore:`, `dorny/paths-filter` use, `tj-actions/ changed-files` use, and `paths-filter@` uses-clause substring. Current baseline across all .github/workflows/*.yml is zero occurrences for the non-diff class, so the default stance is fail-closed (any introduction fails). Future event-orthogonal use must be documented in §3 + allowlisted in the script. Doc §4 first bullet rewritten to spell out both detector classes explicitly, matching what the script enforces. Verified all 4 mechanisms fail-closed on injected fixtures (paths, paths-ignore, dorny/paths-filter, tj-actions/changed-files); baseline still passes after restore. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix(t-wad-slice-7): close duplicate-anchor count-overflow gap in ratchet (cursor APPROVE_WITH_COMMENTS) Cursor review 10250 NON-BLOCKING but accurate: when actual_diff_count > expected_diff_count but every overflow line still matches the inventoried anchor verbatim (e.g. a copy-paste of the §3 row #1 invocation), the prior loop iterated zero times and no failure fired — fail-open against the §4 / INVARIANTS P3 contract. Now: when count exceeds baseline and extra_locations is empty (all overflow lines are duplicates of the anchor), emit a dedicated duplicate-anchor diagnostic with same remediation pointer. Verified: baseline still passes; injecting a second verbatim `git diff --name-only origin/main...HEAD` line into ci.yml now fails with the duplicate-anchor message. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix(t-wad-slice-7): scan both .yml and .yaml workflow files (briansrls BLOCKING) Operator BLOCKING review on #2766: prior ratchet narrowed the workflow-file universe to `*.yml`, so a new path-regex bridge introduced via a `*.yaml` file would have passed silently — fail-open extension gap. Factor the workflow-file glob into a single `workflow_files_nul` helper used by BOTH detector pipelines (diff-bridge count + non-diff mechanisms). The helper covers `.github/workflows/{*.yml,*.yaml}` — both extensions are honored by GitHub Actions. New extensions cannot create another fail-open gap because every detector consumes the same source-of-truth helper. Doc §1 / §2 / §4 references to `*.yml` widened to `{*.yml,*.yaml}` with an explicit note that the helper is the single source of truth. Verified: baseline still passes; injecting a new `*.yaml` workflow with a fresh `git diff --name-only HEAD~1 HEAD` line is detected with file:line and remediation pointer. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix(t-wad-slice-7): add raw-literal authoritative-text block to §3 (cursor 10260) Cursor review 10260 NON-BLOCKING (APPROVE_WITH_COMMENTS) — accurate: §3 table cell quoted the docs-only allowlist regex with markdown table-escape `\|` so the raw markdown source string did not match the live ci.yml literal nor the ratchet's PATH_REGEX_FILTER pin. Reviewers told to "treat as inventory truth" could not grep the doc and hit the same string. Add a non-table fenced code block above the table holding the three authoritative literals verbatim (docs-only allowlist filter, the inventoried `git diff --name-only` anchor, the if-gate substring fingerprint). Table cells now reference "literal above" instead of duplicating the escaped form. Three-way grep verifies: - docs/design-t-wad-slice-7-implementation-prequeue.md L69 - .github/workflows/ci.yml L238 - scripts/check-workflow-path-regex-inventory.sh L64 (PATH_REGEX_FILTER) all carry the same literal `grep -vE '^(docs/.*|[^/]+\.md)$'`. INVARIANTS P1 ("Documentation Describes Live State") preserved. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix(t-wad-slice-7): close anchor-host + underflow gaps in ratchet (cursor 10271) Cursor review 10271 NON-BLOCKING but accurate: §4 promised fail-closed in both directions, but the count branch silently passed in two cases: (a) actual_diff_count == 1 with the sole match OUTSIDE ci.yml — neither `>` nor `<` branch fired and the earlier PATH_REGEX_FILTER pin (different literal) did not catch a refactor that kept the docs-only allowlist regex but moved the diff anchor elsewhere. (b) actual_diff_count < expected_diff_count and inventoried_present == 0 — the branch ran `:` and exited success. Tightened: - Anchor-host invariant: independently fail if the §3 row #1 anchor `git diff --name-only origin/main...HEAD` is not present in ci.yml, regardless of count or extra_locations. This closes case (a). - Count underflow: fail if actual_diff_count < expected_diff_count (anchor removed before BinaryShim replacement is wired). This closes case (b). Verified: - Baseline still passes. - Case (a) (anchor moved to sibling .yml): fails with anchor-host message. - Case (b) (anchor deleted entirely): fails with BOTH anchor-host AND count-underflow messages (defense-in-depth). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix(t-wad-slice-7): narrow paths:/paths-ignore: detector to trigger-level only (codex 10280) Codex review 10280 NON-BLOCKING (APPROVE_WITH_COMMENTS) — accurate doc-vs-impl mismatch (INVARIANTS P2 / Practice 5 single-authority): Prior detector greped `^[[:space:]]*paths(-ignore)?:` anywhere in a workflow file. The prequeue doc §4 scopes this to trigger-level `paths:` / `paths-ignore:` under on.push/on.pull_request. Step-input `paths:` keys (e.g., under a `with:` block of `dorny/paths-filter` itself, or other step inputs) would have triggered the ratchet despite not being authoritative path-regex selection. Replaced the regex with an awk state-machine that only flags `paths:` / `paths-ignore:` keys appearing under `on:` → `push:` / `pull_request:` / `pull_request_target:`. Step inputs and unrelated YAML blocks are no longer flagged. Split the action-name detection (dorny/paths-filter, tj-actions/changed-files, `paths-filter@`) into its own clearly-scoped loop with a distinct message, since those are step uses-clauses with no false-positive risk. Verified scoping: - trigger-level `paths:` under on.pull_request → fails (correct) - trigger-level `paths-ignore:` under on.push → fails (correct) - `paths:` inside a step `with:` block → passes (correct, no false positive) - dorny/paths-filter step use → fails via action-name detector (correct) - baseline still passes Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Summary
Adds
docs/design-t-wad-slice-7-binary-shim-affected-set-selection-canvas.md— the Verification-lane design canvas for T-WAD Slice 7 /docs/r3-program-plan.mdrow 103 (ci_uses_affected_set_selection). The doc specifies: howBinaryShimconsumes PR #2713 affected-set lens output; staged first landing (in-runner selection, no required GitHub dynamic matrix) vs end-state (optional matrix fan-out); fail-closed superset rules; dimension ∪TestClaim/ job metadata mapping; YAML path-regex selection non-authoritative; PM sequencing (Slice 4 first; Slices 5 ∥ 8); hard dependency on warm-wolf-698 Slice 5; §9 skeleton for future hermetic tests (feedback_lenses_not_passes,TESTING.md). Canvas only — no emitter, nogunbc-cibinary, no workflow edits.Scope
project_github_actionsimplementation, Rust CI binary,.github/workflows/ci.ymlTest plan
docs/design-ci-workflow-emitter-dispatch.md§5.2–§6,docs/design-affected-set-lens.md§2 / §5,docs/r3-structure.mdgateci_uses_affected_set_selection.gh pr ready 2760 --repo gunb-ai/gunbc) when intentionally opting into default GitHub auto-coverage.Worker attestation
Closes #/Fixes #: N/A — work item is internal (dashboard); this PR does not close a GitHub issue by design.