Skip to content

fix(audit): align history contracts and isolate model fixtures - #198

Merged
DorianZheng merged 1 commit into
mainfrom
fix/auditor-contract-and-fixtures
Sep 27, 2026
Merged

DorianZheng merged 1 commit into
mainfrom
fix/auditor-contract-and-fixtures

Conversation

@DorianZheng

Copy link
Copy Markdown
Member

TL;DR

Align auditor history IDs with runtime checks and keep verdict tests independent of installed model CLIs.

Design: #180
Fixes #180. Fixes #149.

How it works

The output schema now constrains finding, disposition, and conflict IDs to the runtime contract. Auditor instructions derive reviewed/unread coverage from the current snapshot keys. Verdict fixtures use controlled utilities and explicit model stubs; sentinels detect unintended CLI calls while deliberate fallback cases retain their own fakes.

Documentation: audit history and test isolation.

Verification

  • bash plugins/boxlite-agent-tooling/scripts/audit-reconciliation.test.sh → schema/runtime mismatch with all production changes reverted; passed with the complete fix restored.
  • bash plugins/boxlite-agent-tooling/.agents/hooks/audit/run-verdict-audit.test.sh → passed with installed CLIs available and with a utility-only PATH lacking model CLIs and ripgrep. Before isolation, the cancellation fixture invoked a sentinel model CLI.
  • Repository checks passed. All plugin suites were exercised before rebasing; the release fixed three existing failures, and all eight affected suites passed after rebasing. Execution was verified on macOS; Linux and Windows remain unverified.

The output schema accepted descriptive finding IDs that reconciliation rejected.
Match the runtime ID contract and describe coverage using snapshot keys.

Verdict fixtures could fall through to installed model CLIs. Use controlled
utilities, explicit stubs, and invocation sentinels while retaining CLI tests.
@coderabbitai

coderabbitai Bot commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration

Configuration used: Organization UI

Review profile: QUIET

Plan: Advanced

Run ID: 956532e4-7856-4c69-bd0f-da95d230eee4

📥 Commits

Reviewing files that changed from the base of the PR and between d21c34f and 3011ad8.

📒 Files selected for processing (6)
  • plugins/boxlite-agent-tooling/.agents/hooks/audit/commit-push-audit.schema.json
  • plugins/boxlite-agent-tooling/.agents/hooks/audit/run-verdict-audit.test.sh
  • plugins/boxlite-agent-tooling/.agents/prompts/audit/audit-reflection.md
  • plugins/boxlite-agent-tooling/ARCHITECTURE.md
  • plugins/boxlite-agent-tooling/CONTRIBUTING.md
  • plugins/boxlite-agent-tooling/scripts/audit-reconciliation.test.sh

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown
Contributor

TL;DR

The PR author must acknowledge the current diff and description before requesting review.

Author review acknowledgment

Awaiting the PR author's acknowledgment.

@DorianZheng: read the current diff and description, then check:

Apply boxlite-writing. Does How it works explain the diff's mechanism or rationale?

Verify design research against sources; evidence gaps block approval.

Use the form best suited to the change. Check drafts too, and repeat this review
after description edits. Post this as a new PR comment:

/reviewed 3011ad85464bffd9367dc30cf4cce955c9d33919

Unacknowledged PRs are converted to draft. After this check passes, click Ready for review when you want reviews.
Only a new, unedited comment from the PR author counts. A new commit requires a new acknowledgment.
This records the author's acknowledgment of the commit, not an automated judgment of the description; maintainer approval is separate.

@DorianZheng
DorianZheng marked this pull request as ready for review September 27, 2026 09:38
Copilot AI lite review requested due to automatic review settings September 27, 2026 09:38
@DorianZheng
DorianZheng merged commit 13a5811 into main Sep 27, 2026
6 of 7 checks passed
@DorianZheng
DorianZheng deleted the fix/auditor-contract-and-fixtures branch September 27, 2026 09:38

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Align auditor history schema and instructions with runtime checks test: isolate verdict audit fixtures from installed model CLIs

2 participants