Skip to content

test(agentic-engineering): guard surveyor review contracts upstream - #206

Merged
devantler merged 2 commits into
mainfrom
codex/surveyor-contract-guards-95
Sep 6, 2026
Merged

test(agentic-engineering): guard surveyor review contracts upstream#206
devantler merged 2 commits into
mainfrom
codex/surveyor-contract-guards-95

Conversation

@devantler

@devantler devantler commented Sep 6, 2026

Copy link
Copy Markdown
Contributor

🤖 Generated by the Agentic Engineer

The shared surveyor carries review and pagination rules that were guarded only in its consuming monorepo. This adds an upstream CI suite for 53 operative clauses, including head matching before recency, abbreviated markers, same-head findings, check-run identity, newest-review counting, and incomplete queries.

Every clause has a removal control and a whitespace-reflow control. A copy elsewhere in the document cannot rescue a missing operative rule, and missing, repeated or reversed section boundaries are rejected. The coverage guide maps the original 31 checks and identifies the concrete identities, paths, policies, and three overlay-loading checks that remain consumer-owned. It also provides 13 independent scenarios for separate model evaluation.

Agentic-engineering moves to 5.0.2 because the bundle gains test resources. Agent definitions, synced skills, and desired-state resources retain their existing bytes. These are structural drift guards, not proof of model compliance; consumer overlay removal still requires its own parity review.

Validation: all existing helper, manifest, version and digest suites pass. The new suite proves all 53 removal/reflow pairs, four malformed-boundary cases and empty input; an independent evaluator matched all 13 scenario outcomes without receiving the answer key. Exact evidence and limits, boundary-fix evidence.

Fixes #95

@devantler

Copy link
Copy Markdown
Contributor Author

🤖 Generated by the Agentic Engineer

Validation at 45cc31f:

  • The 53-clause suite passes all removal and reflow controls. An independent direct probe removed the minimum ten-character rule but left its wording in a later example; --check failed specifically at R03. The unmodified definition passed.
  • Existing suites pass: manifests 202, forge guard 393, adapter 35, classifier 18, version suites 15 and 13, digest suite 25, plus the existing surveyor suites. ShellCheck, manifest validation, digest parity and the exact base-to-head version gate pass.
  • A separate evaluator received only the consumer contract, the 13 cases, and the surveyor definition, without the answer key. All 13 outcomes agreed on the requested dimension: head-before-recency→current green; same-head-unresolved→findings; resolved-and-rereviewed→green; short marker→none with evidence; nonmatching valid marker→stale; spoofed author→discarded; shared-login approval→no check-run green; neutral error→error/no green; neutral findings→findings; newest empty review→zero body findings; failed pagination→candidate UNKNOWN while retaining other evidence; fresh unassigned writer claim→live claim; classifier exit 2→UNKNOWN/no exemption.

The evaluated surveyor Git blob is 481b11fc19aeefaab6a11b622a69d5a03b8a7fd6, unchanged from the base. Evaluator: the independent skills_survey agent in this Codex task, 2026-09-06. This is one bounded model-behavior sample; it is separate from CI's structural checks and does not establish application discovery or fleet-wide compliance. No runtime plugin was updated.

@devantler

Copy link
Copy Markdown
Contributor Author

🤖 Generated by the Agentic Engineer

@coderabbitai full review

Please review the complete change at 45cc31f. All required CI checks pass. Focus on whether each section-scoped removal control detects its intended missing rule, whether reflow controls remain valid, and whether the 31-check ownership mapping preserves consumer-specific obligations. Independent behavior evaluation and validation are recorded here.

@coderabbitai

coderabbitai Bot commented Sep 6, 2026

Copy link
Copy Markdown

@devantler I will review the complete change at 45cc31ff8bd6d6416a074bd32b4ffa5cf13838cf.

I will check the section-scoped removal controls, whitespace-reflow controls, and the 31-check ownership mapping. I will verify that consumer-specific obligations remain consumer-owned.

✅ Action performed

Full review finished.

@coderabbitai

coderabbitai Bot commented Sep 6, 2026

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

Next included review available in 43 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Team

Run ID: 5f1c7e21-40a4-4c3b-9c43-907973d4b2cd

📥 Commits

Reviewing files that changed from the base of the PR and between 6c62e1f and 1520b5b.

📒 Files selected for processing (8)
  • .claude-plugin/marketplace.json
  • .github/plugin/marketplace.json
  • docs/surveyor-contract-coverage.md
  • plugins/agentic-engineering/.claude-plugin/plugin.json
  • plugins/agentic-engineering/README.md
  • plugins/agentic-engineering/plugin.json
  • plugins/agentic-engineering/scripts/fixtures/surveyor-review.json
  • plugins/agentic-engineering/scripts/surveyor-review-contract.test.sh

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Team

Run ID: df8483d7-0ceb-43e9-a4d4-0469962db051

📥 Commits

Reviewing files that changed from the base of the PR and between 6c62e1f and 45cc31f.

📒 Files selected for processing (8)
  • .claude-plugin/marketplace.json
  • .github/plugin/marketplace.json
  • docs/surveyor-contract-coverage.md
  • plugins/agentic-engineering/.claude-plugin/plugin.json
  • plugins/agentic-engineering/README.md
  • plugins/agentic-engineering/plugin.json
  • plugins/agentic-engineering/scripts/fixtures/surveyor-review.json
  • plugins/agentic-engineering/scripts/surveyor-review-contract.test.sh

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.

📜 Recent review details
🧰 Additional context used
📓 Path-based instructions (2)
Any change to the plugin set updates both manifests in the same PR Edit both together.

📄 CodeRabbit inference engine (AGENTS.md)

Files:

  • .claude-plugin/marketplace.json
  • .github/plugin/marketplace.json
README and manifests stay in lockstep.

📄 CodeRabbit inference engine (AGENTS.md)

Files:

  • .claude-plugin/marketplace.json
  • .github/plugin/marketplace.json
🔇 Additional comments (8)
docs/surveyor-contract-coverage.md (1)

1-108: LGTM!

plugins/agentic-engineering/README.md (1)

222-224: LGTM!

plugins/agentic-engineering/scripts/surveyor-review-contract.test.sh (1)

1-178: LGTM!

plugins/agentic-engineering/scripts/fixtures/surveyor-review.json (1)

1-81: LGTM!

.claude-plugin/marketplace.json (1)

30-30: LGTM!

.github/plugin/marketplace.json (1)

30-30: LGTM!

plugins/agentic-engineering/.claude-plugin/plugin.json (1)

4-4: LGTM!

plugins/agentic-engineering/plugin.json (1)

4-4: LGTM!


📝 Walkthrough

Walkthrough

The change adds structural contract tests for the bundled portfolio-surveyor agent, including section-scoped clause validation and mutation checks. It adds synthetic model-behavior cases with expected classifications and evidence. New documentation describes test usage, coverage ownership, and evaluation boundaries. Plugin manifests and marketplace entries update the agentic-engineering version from 5.0.1 to 5.0.2.

Merge Risk: ⚪ Minimal · up to 45cc3

This release adds surveyor contract coverage, evaluation fixtures, and ownership documentation while preserving the shipped surveyor behavior. The version metadata is synchronized, and no merge-blocking current-head risk remains.


Important

Pre-merge checks failed

Please resolve all errors before merging. Addressing warnings is optional.

❌ Failed checks (1 error)

Check name Status Explanation Resolution
Docstring Coverage ❌ Error Docstring coverage is 66.67% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 6 functions across 1 files. (7 skipped: 7… Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed The changes satisfy issue #95: they add section-scoped surveyor contract tests, prove removal and whitespace-reflow controls, document generic versus consumer-owned coverage, and provide independent e…
Out of Scope Changes check ✅ Passed The documentation, fixture, README update, and version changes support the surveyor contract test suite and its distribution. No unrelated code or runtime behavior changes are identified.
Title check ✅ Passed The title clearly identifies the agentic-engineering package and the main change: adding upstream guards for surveyor review contracts.
Description check ✅ Passed The description directly explains the new 53-clause CI suite, coverage documentation, evaluation scenarios, version update, validation results, and consumer-owned checks.
Full details: Docstring Coverage

Explanation

Docstring coverage is 66.67% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 6 functions across 1 files. (7 skipped: 7 unsupported.)


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@devantler

Copy link
Copy Markdown
Contributor Author

🤖 Generated by the Agentic Engineer

Fixed at 1520b5b:

  • Independent review reproduced a scope escape: an end heading moved before its start made extraction continue through EOF, so a removed R03 clause could be rescued by a later example. The extractor now requires unique boundaries in order. New controls reject reversed boundaries both with and without a rescued clause, as well as missing and repeated end markers. The new suite failed on the reversed-boundary case before the fix and now passes all 53 clause controls plus these four cases. An independent recheck also rejects the original exploit fixture.
  • The ancillary helper-documentation feedback is addressed with explicit contracts for the failure reporter, requirement emitter, and definition checker. The extractor comment now accurately states its final-section behavior.

ShellCheck and the complete new suite pass. The evaluated role and 13 scenario inputs retain their previous bytes, so the separate model-evaluation evidence remains bound to the same definition. Fresh CI and review are required at this new head.

@devantler

Copy link
Copy Markdown
Contributor Author

🤖 Generated by the Agentic Engineer

@coderabbitai full review

Please review the complete PR at 1520b5b. Required CI is green. The resolution addresses helper documentation and the independently reproduced reversed-section escape. All 53 clause controls, four malformed-boundary cases and the independent reproduction pass.

@coderabbitai

coderabbitai Bot commented Sep 6, 2026

Copy link
Copy Markdown
🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo '=== changed files against PR base ==='
git diff --name-status "$(git merge-base HEAD origin/main)" HEAD 2>/dev/null || git diff --name-status HEAD~1 HEAD

echo '=== complete diff for review ==='
git diff --find-renames "$(git merge-base HEAD origin/main)" HEAD 2>/dev/null || git diff --find-renames HEAD~1 HEAD

echo '=== script outline ==='
ast-grep outline plugins/agentic-engineering/scripts/surveyor-review-contract.test.sh --items all || true

echo '=== documentation headings and tables ==='
rg -n -C 2 '^(#|##|###)|\| O[0-9]+|R[0-9]+|ownership|consumer|generic' docs/surveyor-contract-coverage.md

echo '=== target agent section headings and requirement IDs ==='
rg -n -C 2 '^(#|##|###)|R[0-9]{2}|portfolio-surveyor|review' plugins/agentic-engineering/agents/portfolio-surveyor.agent.md

echo '=== fixture structure ==='
python3 - <<'PY'
import json
p='plugins/agentic-engineering/scripts/fixtures/surveyor-review.json'
data=json.load(open(p))
print('top-level:', ', '.join(data))
for key, value in data.items():
    if isinstance(value, list):
        print(f'{key}: {len(value)} entries')
PY

Length of output: 71514


🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo '=== shell test discovery and lint workflow references ==='
rg -n -C 4 --glob '*.yml' --glob '*.yaml' --glob '*.sh' \
  '(lint-scripts|scripts/.*test\.sh|find .*test\.sh|fd .*test\.sh|ShellCheck|shellcheck)' \
  .github plugins README.md 2>/dev/null || true

echo '=== contract script: extraction, boundary mutations, and clause loop ==='
nl -ba plugins/agentic-engineering/scripts/surveyor-review-contract.test.sh | sed -n '15,210p'

echo '=== exact section boundary occurrences in shipped definition ==='
for marker in \
  '### 0. Budget sample' \
  '### 1. Open PRs' \
  '### 2. Claim branches' \
  '### 3. Short-circuit' \
  '### 3a. Maintainer-login' \
  '### 3b. Hygiene pentad' \
  '### 3c. (e) Green-review' \
  '**Connector lane.**' \
  '**Check-run lane.**' \
  '**`self@<sha>`**' \
  '### 3d. Programmed-bot' \
  '### 3e. Review coordination' \
  '### 6. Reconcile the repo set' \
  '## Return —' \
  '## Survey digest —' \
  '### Operate' \
  '### Advance' \
  '### Digest rules'
do
  printf '%s\t' "$marker"
  grep -Fxc "$marker" plugins/agentic-engineering/agents/portfolio-surveyor.agent.md || true
done

echo '=== duplicates of requirement literals within their assigned normalized source sections ==='
python3 - <<'PY'
import re
from pathlib import Path
script = Path("plugins/agentic-engineering/scripts/surveyor-review-contract.test.sh").read_text()
agent = Path("plugins/agentic-engineering/agents/portfolio-surveyor.agent.md").read_text().splitlines()
clauses = re.search(r"cat <<'CLAUSES'\n(.*?)\nCLAUSES", script, re.S).group(1).splitlines()
scopes = {
"budget": ("### 0. Budget sample","### 1. Open PRs"),
"claims": ("### 2. Claim branches","### 3. Short-circuit"),
"automation": ("### 3. Short-circuit","### 3a. Maintainer-login"),
"hygiene": ("### 3b. Hygiene pentad","### 3c. (e) Green-review"),
"connector": ("**Connector lane.**","**Check-run lane.**"),
"check_run": ("**Check-run lane.**","**`self@<sha>`**"),
"exemption": ("### 3d. Programmed-bot","### 3e. Review coordination"),
"pagination": ("### 6. Reconcile the repo set","## Return —"),
"reporting": ("## Return —","## Survey digest —"),
"digest_budget": ("## Survey digest —","### Operate"),
"digest_operate": ("### Operate","### Advance"),
"digest_advance": ("### Advance","### Digest rules"),
"digest_rules": ("### Digest rules",""),
}
for row in clauses:
    ident, group, literal = row.split("|", 2)
    start, end = scopes[group]
    s = next(i for i,x in enumerate(agent) if x.startswith(start))
    e = next((i for i,x in enumerate(agent[s+1:],s+1) if x.startswith(end)), len(agent)) if end else len(agent)
    normalized = re.sub(r"\s+", " ", " ".join(agent[s:e]))
    count = normalized.count(literal)
    if count != 1:
        print(f"{ident}\t{group}\tcount={count}")
PY

echo '=== consumer test lines for O01–O31 at documented revision ==='
gh api repos/devantler-tech/monorepo/contents/.claude/scripts/portfolio-surveyor.test.sh \
  -f ref=f8fe925dd1c8c623606af7d8e5bdd554b6a46f37 \
  --jq .content \
  | base64 -d \
  | nl -ba \
  | sed -n '60,200p;760,790p'

Length of output: 22296


🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo '=== lint-scripts bundled test execution ==='
sed -n '115,155p' .github/workflows/ci.yaml

echo '=== contract script source with line numbers ==='
awk '{ printf "%5d  %s\n", NR, $0 }' \
  plugins/agentic-engineering/scripts/surveyor-review-contract.test.sh \
  | sed -n '15,210p'

echo '=== exact section boundary occurrence counts ==='
for marker in \
  '### 0. Budget sample' '### 1. Open PRs' \
  '### 2. Claim branches' '### 3. Short-circuit' \
  '### 3a. Maintainer-login' '### 3b. Hygiene pentad' \
  '### 3c. (e) Green-review' '**Connector lane.**' \
  '**Check-run lane.**' '**`self@<sha>`**' \
  '### 3d. Programmed-bot' '### 3e. Review coordination' \
  '### 6. Reconcile the repo set' '## Return —' \
  '## Survey digest —' '### Operate' '### Advance' '### Digest rules'
do
  count=$(grep -Fxc "$marker" plugins/agentic-engineering/agents/portfolio-surveyor.agent.md || :)
  printf '%s => %s\n' "$marker" "${count:-0}"
done

echo '=== requirement literals whose assigned source section does not contain exactly one copy ==='
python3 - <<'PY'
import re
from pathlib import Path
script = Path("plugins/agentic-engineering/scripts/surveyor-review-contract.test.sh").read_text()
agent = Path("plugins/agentic-engineering/agents/portfolio-surveyor.agent.md").read_text().splitlines()
clauses = re.search(r"cat <<'CLAUSES'\n(.*?)\nCLAUSES", script, re.S).group(1).splitlines()
scopes = {
"budget": ("### 0. Budget sample","### 1. Open PRs"), "claims": ("### 2. Claim branches","### 3. Short-circuit"),
"automation": ("### 3. Short-circuit","### 3a. Maintainer-login"), "hygiene": ("### 3b. Hygiene pentad","### 3c. (e) Green-review"),
"connector": ("**Connector lane.**","**Check-run lane.**"), "check_run": ("**Check-run lane.**","**`self@<sha>`**"),
"exemption": ("### 3d. Programmed-bot","### 3e. Review coordination"), "pagination": ("### 6. Reconcile the repo set","## Return —"),
"reporting": ("## Return —","## Survey digest —"), "digest_budget": ("## Survey digest —","### Operate"),
"digest_operate": ("### Operate","### Advance"), "digest_advance": ("### Advance","### Digest rules"),
"digest_rules": ("### Digest rules",""),
}
problems = []
for row in clauses:
    ident, group, literal = row.split("|", 2)
    start, end = scopes[group]
    start_at = [i for i,line in enumerate(agent) if line.startswith(start)]
    end_at = [i for i,line in enumerate(agent) if end and line.startswith(end)]
    if len(start_at) != 1 or (end and len(end_at) != 1) or (end and end_at[0] <= start_at[0]):
        problems.append(f"{ident}: boundary count/order invalid")
        continue
    scoped = agent[start_at[0]:(end_at[0] if end else len(agent))]
    text = re.sub(r"\s+", " ", " ".join(scoped))
    if text.count(literal) != 1:
        problems.append(f"{ident}: literal count={text.count(literal)}")
print("\n".join(problems) if problems else "all 53 requirement literals occur exactly once in their assigned section")
PY

echo '=== consumer test lines from cited revision ==='
tmp=$(mktemp)
trap 'rm -f "$tmp"' EXIT
gh api 'repos/devantler-tech/monorepo/contents/.claude/scripts/portfolio-surveyor.test.sh?ref=f8fe925dd1c8c623606af7d8e5bdd554b6a46f37' \
  --jq .content | base64 -d > "$tmp"
awk 'NR >= 60 && NR <= 200 { printf "%5d  %s\n", NR, $0 }
     NR >= 760 && NR <= 790 { printf "%5d  %s\n", NR, $0 }' "$tmp"

Length of output: 31257


@devantler Full review completed for 1520b5be9577c5c718721703ac5b433fc503623b.

I found no blocking issues.

The revised extractor requires unique, ordered boundaries. The malformed-boundary controls reject the previous reversed-boundary scope escape and its out-of-scope R03 rescue case.

Each of the 53 requirement literals occurs exactly once in its assigned operative section. Each removal control checks the expected missing ID. Each reflow control accepts normalized whitespace-only content.

The lint-scripts workflow discovers and runs this new *.test.sh file automatically.

The O01–O31 mapping preserves consumer ownership for deployment-specific paths, identities, writer namespaces, lease policy, compatibility-overlay loading, provider wiring, and product-specific tests.

⚠️ Action not completed

Review rate limited.


Your included review limit is currently reached under our Fair Usage Limits Policy. This review may still proceed through usage-based billing if eligible. Your next included review will be available in 43 minutes.

@devantler

Copy link
Copy Markdown
Contributor Author

🤖 Generated by the Agentic Engineer

@codex review

Please review the complete current diff at 1520b5be9577c5c718721703ac5b433fc503623b. CodeRabbit terminated this head's review with an explicit rate-limit response, so this is the sequential Codex fallback: #206 (comment).

All 41 checks have passed. The final boundary repair, its RED-to-GREEN evidence, and the helper documentation resolution are recorded at #206 (comment). The 53 structural clauses and independent 13-case evaluation are covered by this PR; the role definition itself is unchanged.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 6, 2026

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review Completed 2026-09-06T18:24:47.820579Z 1520b5b Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Breezy!

Reviewed commit: 1520b5be95

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@devantler

Copy link
Copy Markdown
Contributor Author

🤖 Generated by the Agentic Engineer

Readiness verified at 1520b5be9577c5c718721703ac5b433fc503623b against reviewed main 6c62e1f2cb1009aa42d17299814580a5609e6fbb.

I exercised the documented suite as its CI user: all 53 clause removals were rejected, all 53 whitespace reflows were accepted, and all four malformed-boundary cases plus empty input were rejected. Manifest validation, the base-to-head version gate, desired-state digest verification, ShellCheck, and whitespace checks pass. The historical O01–O31 mapping was checked against its cited consumer revision. An independent full-diff review found no actionable defect or weakened control; all four manifests consistently select 5.0.2.

The authenticated Codex verdict names this head and reports no major issues. All 40 hosted checks are terminal (38 successful, two intentional skips), the additional status is successful, and there are no unresolved threads, current-head findings, maintainer prohibitions, or active foreign work. The latest foreign push was at 18:10:10 UTC and its activity window has expired.

The suite measures structural drift; the separately recorded 13-case model evaluation remains a bounded sample. This change does not remove the consumer overlay or claim runtime enforcement. Promoting this reviewed head under the normal merge gate.

@devantler
devantler marked this pull request as ready for review September 6, 2026 20:26
@devantler
devantler merged commit 4a75194 into main Sep 6, 2026
41 checks passed
@devantler
devantler deleted the codex/surveyor-contract-guards-95 branch September 6, 2026 20:27
@github-project-automation github-project-automation Bot moved this from 🫴 Ready to ✅ Done in 🌊 Project Board Sep 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: ✅ Done

Development

Successfully merging this pull request may close these issues.

test(agentic-engineering): port the surveyor contract guards upstream

1 participant