ci: scope every expensive job to a classifier capability vector (#1152) - #1155
Merged
Conversation
) The job declared needs: classify but never read the verdict, so it built a .deb and signed updater on every PR (20/20 in the last-20 audit, ~41 min). It now runs only when the classifier says either scaffold tier runs, short-circuiting to the scaffold-static skipped-by-policy pattern otherwise so it stays eligible as a required check. Fail-closed: a failed classify still forces a full run; a dedicated needs_desktop signal is #1152 scope. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PVEZJ1CBtRYNXzGQRZrTat
… + plan for #1152) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PVEZJ1CBtRYNXzGQRZrTat
Owner
Author
|
[PHASE: PLAN] Capability-vector plan committed ( Locked decisions
Open questions for PLAN-EVAL / owner
Next
|
This was referenced Aug 3, 2026
…1152 S1+S2) decide() now emits needs_deno/needs_docker/needs_desktop/needs_docs/ needs_surface alongside run_static/run_runtime. Only the tier-defining workflows (e2e-cli.yml, ci.yml) escalate the scaffold tiers; a root deno.json diff touching only tasks is a script alias, not a toolchain change. Unrecognised paths force the ENTIRE vector true, root deno test discovery keeps .llm/tools code on needs_deno, and every output carries positive and negative unit coverage (50 tests). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PVEZJ1CBtRYNXzGQRZrTat
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PVEZJ1CBtRYNXzGQRZrTat
…S3) desktop-native-linux swaps the #1151 run_static||run_runtime proxy for the dedicated needs_desktop output (packages/cli is the whole .deb surface); scaffold-runtime is documented as the docker tier; classify extracts root deno.json base/head for the tasks-only discrimination and lane visibility reports the desktop selection directly. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PVEZJ1CBtRYNXzGQRZrTat
ci.yml gains its own classify job (same script, same fail-closed rule). check-test reads needs_deno; quality reads needs_deno || needs_docs so docs-only PRs still get fmt/docs-accuracy. Both required checks always start and report SUCCESS via the scaffold-static skipped-by-policy pattern; push events classify as run-everything; close-gate and deps-report stay ungated. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PVEZJ1CBtRYNXzGQRZrTat
…1152 S5) The workflow-level paths filter meant no status report on non-package PRs, blocking required-check promotion. needs_surface mirrors the old filter; the job now always starts and short-circuits to skipped-by-policy. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PVEZJ1CBtRYNXzGQRZrTat
checkout v4->v5, upload-artifact v4->v5, download-artifact v4->v5, setup-dotnet v4->v5, upload-pages-artifact v3->v5, deploy-pages v4->v5, configure-pages v5->v6 — the smallest majors whose runtime is node24 for the release-critical actions. SHA-pinned third-party actions are left as pinned; denoland/setup-deno@v2 is already the latest major. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PVEZJ1CBtRYNXzGQRZrTat
This was referenced Aug 3, 2026
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PVEZJ1CBtRYNXzGQRZrTat
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PVEZJ1CBtRYNXzGQRZrTat
Owner
Author
|
[PHASE: IMPL] All six slices landed and live-verified. The two measured waste classes from the audit are now proven skips:
The positive case is this PR's own CI (tier-workflow edit → full run). Acceptance evidence
Next
|
7 tasks
rickylabs
marked this pull request as ready for review
August 3, 2026 15:42
23 tasks
rickylabs
added a commit
that referenced
this pull request
Aug 3, 2026
Evidence-base definition widened with per-claim citations instead of silent promotion; note-accumulation and the #1142 mitigation downgraded to [asserted] with gaps stated; identity derivation re-anchored on the release-canary.yml wiring; drift-gate section reduced to its observable contract; quota/transport gates given a recorded-output proof form; stage-C operability wired to tooling.md/agent-handoff.md and codex-watch turn interception; D2 tension (#1153/#1155 pre-ratification merges) surfaced rather than claimed away. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01ReZGc3KP8xvEuruz1io7Pq
rickylabs
added a commit
that referenced
this pull request
Aug 3, 2026
…gates; escalate C9, M1/M2 The two previously undemonstrated gates now carry real negative cases (gate-demos.md): check 3 fires RED on a synthetic new-ignore diff and stays GREEN on excluded-path quotes; the #1142 selection rule recovers PR #1155's true pre-merge verdict from a live rollup containing a post-merge FAILURE. D2 evidence box unticked pending the owner's ruling; the [observed] source-of-record dispute is recorded in drift.md for the owner. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01ReZGc3KP8xvEuruz1io7Pq
11 tasks
rickylabs
added a commit
that referenced
this pull request
Aug 3, 2026
…ile, rolling canary cadence (#1161) * chore(harness): bootstrap milestone-orchestrator authoring run + locked outline Run dir + supervisor identity + plan of record for the three #1120 artifacts. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01ReZGc3KP8xvEuruz1io7Pq * docs(harness): rolling canary cadence — trigger, membership, D3 identity, note, drift gate The schedule artifact of #1120. Wave boundary as the canary point and content-derived membership are [observed] from the 0.0.4 trace; open questions stay [asserted] and owner-undecided. Wires to the shipped release:canary-label surface (#1121/#1122); publish mechanics remain with netscript-release; #1119's collision is disambiguated, not deepened. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01ReZGc3KP8xvEuruz1io7Pq * docs(harness): milestone-run profile — stage contracts, pre-merge gate, cut checklist, DoD The run artifact of #1120. Every gate carries its observed firing evidence and a stated did-not-run signature; the honesty rule (#1092/#1146 precedents) and the #1142 false-red trap are encoded. Role judgement stays in the orchestrator skill; canary schedule in canary-cadence.md; publish mechanics in netscript-release. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01ReZGc3KP8xvEuruz1io7Pq * feat(harness): agent-milestone-orchestrator skill + regenerated .claude/skills mirror The role artifact of #1120: clustering, wave sequencing, re-planning absorption, delegation judgement, merge authority, canary-point decisions, honesty rules, and supervision pitfalls — every rule marked [observed] (0.0.4 trace) or [asserted]. Gate lists, run artifacts, label mechanism, and routing are referenced, never restated. Mirror regenerated via agentic:sync-claude (incl. aspire and netscript-release mirrors that were stale on main); agentic:check-claude green. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01ReZGc3KP8xvEuruz1io7Pq * chore(harness): close out authoring run — S4 evidence + status flip recorded Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01ReZGc3KP8xvEuruz1io7Pq * fix(harness): apply Sol adversarial review findings C1-C9, M1-M6 Evidence-base definition widened with per-claim citations instead of silent promotion; note-accumulation and the #1142 mitigation downgraded to [asserted] with gaps stated; identity derivation re-anchored on the release-canary.yml wiring; drift-gate section reduced to its observable contract; quota/transport gates given a recorded-output proof form; stage-C operability wired to tooling.md/agent-handoff.md and codex-watch turn interception; D2 tension (#1153/#1155 pre-ratification merges) surfaced rather than claimed away. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01ReZGc3KP8xvEuruz1io7Pq * fix(harness): Sol cycle-2 — fix C3-residue/C10/M7, demonstrate C7+M4 gates; escalate C9, M1/M2 The two previously undemonstrated gates now carry real negative cases (gate-demos.md): check 3 fires RED on a synthetic new-ignore diff and stays GREEN on excluded-path quotes; the #1142 selection rule recovers PR #1155's true pre-merge verdict from a live rollup containing a post-merge FAILURE. D2 evidence box unticked pending the owner's ruling; the [observed] source-of-record dispute is recorded in drift.md for the owner. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01ReZGc3KP8xvEuruz1io7Pq * chore(harness): record owner rulings — D2 orchestrated-delivery reading; [observed] definition ratified Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01ReZGc3KP8xvEuruz1io7Pq * fix(harness): Sol cycle-3 residues — C10 tag-existence implication dropped, M8 stale acceptance row Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01ReZGc3KP8xvEuruz1io7Pq * chore(harness): record Sol cycle-4 PASS — eval loop closed green Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01ReZGc3KP8xvEuruz1io7Pq * chore(harness): note mirror/label event race; retrigger CI with ready-merge label present Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01ReZGc3KP8xvEuruz1io7Pq --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Promotes
.github/scripts/ci-classify-changes.tsfrom a two-output e2e-cli gate to a capabilityvector (
needs_deno/needs_docker/needs_desktop/needs_docs/needs_surface) consumedby
e2e-cli.yml,ci.ymlandsurface-diff.yml, with the two #1122 precision fixes: only thetier-defining workflows (
e2e-cli.yml,ci.yml) escalate the scaffold tiers, and atasks-onlyroot
deno.jsonedit is a script alias, not a toolchain change. Paths decide, the frozen threeci:*labels override, every gated job still starts and reports SUCCESS(scaffold-static's skipped-by-policy pattern), and an unrecognised path forces the whole vector
true. Also bumps all version-tagged actions to Node-24 majors (owner request).
Scope
.github/scripts; nopackages//plugins/source)Slices
feat(ci): classifier emits a capability vectore2e-cli.yml: desktop→needs_desktop, runtime=docker tier, root-config extractionci.yml: classify job;check-test←needs_deno,quality←needs_deno || needs_docssurface-diff.yml:paths:filter folded intoneeds_surfaceValidation
deno test .github/scripts/ci-classify-changes.test.ts— 50 passed, 0 failed (every vectoroutput has positive AND negative cases; safety property pinned)
run-deno-lint.ts --root .github/scripts) — 0 findings;deno fmt --checkcleanscaffold-static,scaffold-runtime,desktop-native-linuxall SUCCESS with only"Skipped by policy"
release-canary.yml-only diff) → run 30827782060:same — all three expensive jobs skipped by policy
ci.ymlrun exercises the new classify job live (base=main runs the merge-ref workflow)
Definition of Done
ci-classify-changes.tsemits the capability vector, unit-tested per output incl. negativescheck-test/qualityconsultneeds_denoand report skipped-by-policy when falsescaffold-runtimegated as the docker tier;scaffold-staticis the deno-only default tier(owner-ratified D5: no third suite)
ci:full,ci:skip-scaffold,ci:skip-e2e)post-merge sample observation continues on the issue)
Harness
.llm/runs/ci-scope-expensive-jobs--1152/drift.md); formal PLAN-EVAL superseded by owner authority.Drift / Debt
qualitygate widened toneeds_deno || needs_docs(docs PRs still need fmt/docs-accuracy);needs_docsexcludes agent-context Markdown so the docs(release): a failed canary is fixed forward, not yanked #1055 class skips everything. See drift.md.needs_dockerpackage-set tightening against observed green history; sqlite runtimetier tracked separately.