Skip to content

Restore StewardCheck and integrate task defaults, safer IO, and repository CI - #3

Merged
Afloat16 merged 2 commits into
mainfrom
feat/stewardcheck-integration-20260930
Sep 30, 2026
Merged

Afloat16 merged 2 commits into
mainfrom
feat/stewardcheck-integration-20260930

Conversation

@Afloat16

@Afloat16 Afloat16 commented Sep 30, 2026 •

Copy link
Copy Markdown
Owner

Summary

Keep StewardCheck in this repository as the independently installable companion at tools/stewardcheck, restoring the removed package without rewriting history. The existing skill remains v1.1.0; StewardCheck advances to 0.2.0 alpha.

Improvements

  • Explicit start --config PATH: schema-1 TOML defaults, strict bounded parsing, no automatic discovery or execution, documented CLI replacement precedence, and policies pinned at task start.
  • Reject non-regular state/config files before opening. Bound actual reads and use POSIX nonblocking open to prevent FIFO hangs; detect concurrent replacement/edit cases without claiming a filesystem sandbox.
  • Compare full metadata within each stat API to handle Windows timestamp/permission representations, retaining cross-API file identity, type, size, mtime, and read-length checks.
  • Avoid retaining source-text maps for start/check/report while preserving file hashes, scan metadata, and fingerprints. Context packets still collect text.
  • Add producing version to receipts, malformed-envelope checks, SPDX package metadata, and a distributable TOML example.
  • Integrate English/Chinese repository entry points and maintenance guidance. Preserve the original skill scripts, version, playbook, examples, and existing regression tests.
  • Expand CI to two original-skill/integration jobs and six installed-CLI jobs across Linux, macOS, and Windows.

Validation

Final head: 7829ea0c092551272adec5a550f7b125476677f2.

Repository CI run 36692673869: all eight jobs completed successfully.

  • Original skill and repository integration: 69 tests on Linux Python 3.10 and 3.13.
  • StewardCheck: 125 tests on Linux Python 3.11–3.14 and macOS Python 3.13.
  • Windows Python 3.13: 125 discovered tests, 113 passed and 12 expected platform-specific skips; installation, entrypoints, and end-to-end demo also passed.
  • The first Windows run exposed a stat-API representation mismatch. It was fixed with seven new regression tests, not hidden by disabling tests. The failed run and follow-up commit remain visible.

Local Linux, CPython 3.13.5, Git 2.47.3:

  • All 125 package tests passed against source and the final wheel installed without runtime dependencies in a clean virtual environment.
  • Coverage.py recorded 94% rounded combined statement/branch coverage: 719 statements, 34 missed, 284 branches, 25 partial. This is not a correctness/security guarantee.
  • Both the existing demo and an explicit-TOML/subdirectory-root workflow ran real unittest checks, verified a valid result, and detected a subsequent stale receipt.
  • Live 0.1.0-to-0.2.0 compatibility check preserved the old task contract/hash, read its existing receipt, and produced a fresh 0.2.0 receipt successfully.
  • Synthetic 128-file/8-MiB snapshot comparison preserved fingerprints: peak Python-traced allocation was about 8.6 MB with retained text versus 0.36 MB without. This is not RSS, timing, or a production benchmark.
  • Verified all 46 uploaded file hashes and the final full tree against local files: 2f85c5c23dd7e679e0ff4f2cda13360034deb599. Original skill code and existing tests remain unchanged.
  • Final wheel and source distributions checked against local package files, including license notices and configuration example.

Compatibility and boundaries

Existing schema-1 task records keep their pinned policies. Skill Python support remains 3.10+; CLI remains 3.11+. No model integration, automatic source edits, cleanup, rollback, or command approval is added. Explicit check programs still inherit user permissions and environment. Existing package license/attribution scope is preserved; no license change is imposed on unrelated repository material.

Retain StewardCheck in tools/stewardcheck and advance the companion CLI
to 0.2.0 with explicit TOML task defaults, bounded regular-file reads,
nonblocking POSIX opens, and metadata-only task verification snapshots.

Unify English and Chinese repository entry points and contribution guidance.
Expand CI to test the original skill on Python 3.10/3.13 and the installed
CLI across Linux, macOS, and Windows. Preserve the original skill scripts,
version, playbook, examples, and regression tests.

Validated locally: 118 package tests pass against the final installed wheel;
94% rounded combined statement/branch coverage; bounded-context demo passes.
The synthetic allocation benchmark preserves snapshot fingerprints while
avoiding retained text outside context generation. Full uploaded tree hashes
match the local files. Preserve history with the removal commit as parent.
Windows pathname stat and descriptor stat may differ in ctime semantics
and synthesized permissions. Compare full metadata within each API while
retaining cross-API file identity, type, size, mtime, and read-length checks.

Add seven regression tests for legitimate representation differences and
rejected mutations without skipping the failing Windows behavior. Document
the first CI failure, implementation references, and updated validation.

All 125 local tests passed against source and a clean installed wheel;
combined statement/branch coverage remains 94%. Verify uploaded full tree
2f85c5c against tested local files.
@Afloat16
Afloat16 merged commit b47072c into main Sep 30, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant