ORB-261: canonicalize the API pr-review contract - #463
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 7208afb882
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
DEGRADED: same-vendor review Independent pr-review: CLEAN
This review ran in a separate session that did not write the change. It is same-vendor review; the bias direction is known and its magnitude in this PR loop is unmeasured. EvidenceThe complete diff changes only
No API runtime, product contract, dependency, feature, or data surface changes. Rubric dimensions
Artifact: A machine never merges. |
|
@codex review |
|
DEGRADED: same-vendor review Independent pr-review: CLEAN
This review ran independently from the session that wrote the change. It is same-vendor review; the bias direction is known and its magnitude in this PR loop is unmeasured. EvidenceThe complete current-main diff changes only
The three Codex-thread fixes were inspected directly. Dimension 13 now requires complete live or installed-source evidence and makes guessed correctness-path fields Blocking. The sibling-repository exception is limited to dimension 7, cited contract symbols, the sibling primary No API runtime, product contract, dependency, feature, or data surface changes. Rubric dimensions
Artifact: A machine never merges. |
|
Codex Review: Didn't find any major issues. 👍 Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
|
@codex review |
|
DEGRADED: same-vendor review Independent pr-review: CLEAN
This review ran independently from the session that wrote the change. It is same-vendor review; the bias direction is known and its magnitude in this PR loop is unmeasured. EvidenceThe complete live current-main diff changes only
The bounded sibling-contract evidence rule, round-two admitted-blocker retention, and external-interface evidence dimension remain present and internally complete. No API runtime, product contract, dependency, feature, or data surface changes. Rubric dimensions
Artifact: A machine never merges. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 47b49a3ef2
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 225f5348cf
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
DEGRADED: same-vendor review Independent pr-review: BLOCKING (round 1)
Blocking findingsF1, High,
The diff directs reviewers to read GitHub base/head OIDs and the other selected PR fields, while the PR body's External-interface evidence section says the change adds no structured reads and supplies no complete selected key/type shape. That contradicts the root Fix: replace that PR-body claim with the complete redacted selected shape and the exact reproduction command below. Also refresh the stale current-head and canonical-hash statements in the same body-only update. Reproduce without exposing a credential: $env:GH_TOKEN = '<THOMAS_GITHUB_TOKEN>'
gh pr view 463 --repo thomasluizon/orbit-api --json number,title,body,baseRefName,baseRefOid,headRefName,headRefOid,files,labels
Remove-Item Env:GH_TOKENFollow-up ticketsNone. N/A dimensions
This review did not modify code and does not merge the PR. Round 2 is limited to closing frozen F1 if the base and head remain exact. |
|
DEGRADED: same-vendor review Independent pr-review: CLEAN (round 2, final)
Frozen finding disposition
VerdictNo frozen or admitted Blocking finding remains open. No new finding was admitted; the body-only correction did not change the PR diff line set. The final verdict for exact head This review did not modify code and does not merge the PR. The same-vendor direction-of-bias risk is acknowledged; its magnitude for this review is unmeasured. |
|
@codex review |
|
DEGRADED: same-vendor review Independent pr-review: CLEAN (round 1)
Full-diff verdictBoth changed files were reviewed against the base-pinned rubric: No Critical or High candidate survived. There are zero Blocking findings and no follow-up tickets. Evidence checked
N/A dimensions
The final verdict for exact head |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: c9c7b4b043
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
DEGRADED: same-vendor review Independent pr-review: CLEAN (round 1)
Full-diff verdictBoth changed files were reviewed against the newly base-pinned rubric: No Critical or High candidate survived. There are zero Blocking findings and no follow-up tickets. Evidence checked
N/A dimensions
The final verdict for exact head |
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: ed16d40b9b
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 1457c0dde5
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
DEGRADED: same-vendor review Independent pr-review: CLEAN (round 1)
Full-diff verdictBoth changed files were reviewed against the rubric materialized from the exact captured base: No Critical or High candidate survived. There are zero Blocking findings and no follow-up tickets. Evidence checked
N/A dimensions from the captured-base rubric
The final verdict for exact head |
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 76cbc8930b
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 6a01b6f70c
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 7f0cfcb285
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
DEGRADED: same-vendor review Verdict: BLOCKING Blocking findings
Follow-up tickets
Dimensions marked N/A
|
|
@codex review |
|
DEGRADED: same-vendor review Verdict: BLOCKING Round 2 of 2 — final cap; no round-three path exists. Frozen Blocking findings
Admitted round-two Blocking findings
Follow-up tickets
Dimensions marked N/A
|
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 773bea2d81
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
|
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 45a1c1e586
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| line the fixer's own round-2 diff touched**. That line set is computed as `git diff <r1>..<r2> | ||
| --unified=0` and handed to the reviewer as data it cannot widen. |
There was a problem hiding this comment.
Include deletions in the round-two carve-out
When a fixer introduces a blocker by deleting a line, the new-side range contains no touched line: a real Git 2.43 zero-context deletion produces @@ -2 +1,0 @@. The reviewer therefore cannot admit a newly removed authorization check, validator, or shipped DTO field because there is no round-two line to satisfy this carve-out, allowing a breaking deletion to be reported CLEAN. Represent deleted old-side ranges explicitly and permit blockers anchored to them.
AGENTS.md reference: AGENTS.md:L93-L95
Useful? React with 👍 / 👎.
| gh pr view {N} --repo {OWNER/REPO} --json number,title,body,baseRefName,baseRefOid,headRefName,headRefOid,files,labels | ||
| gh pr diff {N} --repo {OWNER/REPO} > <scratchpad>/pr-{N}.diff | ||
| gh pr view {N} --repo {OWNER/REPO} --json baseRefOid,headRefOid |
There was a problem hiding this comment.
Bind mutable PR evidence to the receipt
When the author edits the PR body between these calls, the second query still succeeds because it compares only base and head OIDs, which body edits do not change. The review can consequently issue a clean receipt using external-interface evidence that has since been removed or altered, even though the required evidence must be present in the PR body. Capture a digest of the reviewed body in the receipt and revalidate it during posting/readiness, or otherwise restart when it changes.
AGENTS.md reference: AGENTS.md:L104-L108
Useful? React with 👍 / 👎.
|
DEGRADED: same-vendor review Verdict: BLOCKING Blocking findings
Follow-up tickets
Changed-file coverage
Dimensions marked N/A
|



DEGRADED: same-vendor review
Summary
Makes the API pr-review skill and rubric byte-identical to the UI canonical contract so API reviews cannot silently load an obsolete or weaker workflow. Linked Linear issue: ORB-261. Harness implementation and parity enforcement: thomasluizon/orbit-ui-mobile#694 (ORB-262).
The branch was updated from API
mainwith a normal merge after base advancement. The PR diff against currentmainremains the two canonical review files. No product/API runtime code is changed by this PR.Observed failure -> fix -> red-capable regression
pr-review parity failed.maincheckout and a linked paired contract PR. It explicitly forbids unrelated browsing.status: OPEN, included in the open list, and prevents CLEAN. No round three is added.findings: [].frozenFindingIds; round 2 never changes it, and UI readiness mechanically validates the list.src/andtests/paths, so the priororbit-api/src/classifier could skip backend-only dimensions.baseRefOidandheadRefOid, and the receipt carries the reviewed head/base.baseRefOid; the receipt stores its OID/path, round 2 reuses it, and a head/base change starts a fresh round 1.ui#N,api#N, or a full PR URL; blank and bare-number scope remain refused.git diff r1..r2.todayplus a boundary-hour unit test and classifies server-local/global-timezone behavior as P1.Verification
SKILL.mdSHA-256:3FBF6D133B4A7BAFBE8DA8345EA10D45FF96AC6B83D6C78F348651FA3C830059in both worktrees.rubric.mdSHA-256:672F14194F2BC7834828D434BABDAD152D5B361B2059B75F34F5B0D370BE72B6in both worktrees.git diff origin/main...HEAD --check: pass.node .claude/hooks/test-hooks.mjs: pass, including all canonical-contract regressions.node tools/test-tools.mjs: pass, including API-primary-cwd and deliberate parity drift.Reproduce byte parity:
External-interface evidence
The updated skill reads this complete selected
gh pr viewresponse. Values are redacted while literal formats and every selected key/type are retained:{ "baseRefName": "<string>", "baseRefOid": "<40-character lowercase hexadecimal SHA>", "body": "<string>", "files": [{"additions": 29, "changeType": "<string; observed MODIFIED>", "deletions": 15, "path": "<string>"}], "headRefName": "<string>", "headRefOid": "<40-character lowercase hexadecimal SHA>", "labels": [], "number": 463, "title": "<string>" }Reproduce with a process-scoped credential:
Observed top-level types are
string,string,string,array,string,string,array,number,stringin the key order above; eachfiles[]object has the complete key setadditions:number,changeType:string,deletions:number,path:string. No response field is inferred from a fixture.Because PR #463 has no labels, a second live invocation used API PR #448 with the same selected query.
Its nonempty
labels[]item has the complete key setcolor:string,description:string,id:string,name:string; two items were observed and no key waselided. Reproduce by substituting
448in the command above.The review's sole diff input was also confirmed from a live invocation rather than inferred from
--help:The complete redacted structural response is one UTF-8 unified-diff string with exactly these
headers and hunk coordinates; only source/content lines are replaced:
Observed whole stdout: 1,201 lines, two
diff --gitfile headers, two hunks, 369 added lines,477 removed lines, and 73 space-prefixed context lines. The tool consumes the response as opaque
unified-diff text; it reads no JSON field from
gh pr diff.Round two depends only on these Git commands' exit status and diff text, not an inferred response field:
Real invocation from the API primary
maincheckout used R176cbc8930bc0789218e0d709bcdbd940fa770adcand R26a01b6f70ca836a35c4fcc3036f632401f32bea2.git fetch origin <R1> <R2>exited 0 and its complete output contained exactly the remote URL plus one<OID> -> FETCH_HEADline for each OID. Each quotedgit cat-file -e '<OID>^{commit}'invocation exited 0 with empty stdout and stderr, confirming both the subcommand's consumed success status and that both objects are commits. The quoted form is the exact PowerShell reproduction; credentials are supplied by the configured Git remote and none are printed.The exact round-one rubric command
git show '50b187835f2d0f98b3b0b0ebf8b435610c8c0678:.claude/skills/pr-review/rubric.md'was run from the API primarymaincheckout and exited 0. Its complete stdout was the 22,813-byte rubric blobc893598592eae90743f6d5b2d8885c1faeeef531, beginning# Orbit Review Rubricand ending with the Self-review note; stderr was empty.git rev-parse '<base>:<path>'andgit cat-file -s '<base>:<path>'independently returned that exact blob OID and22813. The round-one artifact atC:/Users/thoma/AppData/Local/Temp/orbit-api-pr-review-463-7f0cfcb2/pr-463-rubric.mdis the preserved response.The independent reviewer then ran the prescribed process-scoped
gh pr comment 463 --repo <OWNER/REPO> --body-file <REPORT_PATH>posting interface. It exited 0 and its complete stdout was the single URLhttps://github.com/thomasluizon/orbit-api/pull/463#issuecomment-5224015621; the comment contains the exact BLOCKING receipt and remains live. No response field is parsed: exit 0 plus the returned URL proves the report was posted.Cross-repo round-one registration is invoked from the canonical UI primary checkout as
node <UI_PRIMARY_MAIN>/tools/record-readiness.mjs --repo api --pr 463 --review <ROUND_ONE_PATH> --register-round-one. The real initial invocation and an identical idempotency recheck both exited 0. The complete redacted returned key/type shape is{verdict:string,idempotent?:boolean,ledgerPath:string,repositoryKey:string,prNumber:number,baseSha:string,reviewedHeadOid:string,artifactPath:string,artifactSha256:string,frozenFindingIds:string[]}; observed verdict isROUND_ONE_REGISTERED, repository keyapi, PR463, and one frozen ID. The exact response builder is companion UItools/record-readiness.mjs:128-133; the live ledger is under API repository Git state and its stored artifact hash is the round-one receipt SHA-256 already recorded above.Complete zero-context diff structure observed from installed Git 2.52.0 for the actual
ed16d40b..1457c0ddskill change (content values redacted, structural lines retained):The touched-line set reads only the
@@ -old[,count] +new[,count] @@hunk coordinates; it does notinfer line ranges from file content.
Codex findings addressed
Restore external-interface evidence checks: fixed incd09d70e; replied with hook/hash evidence and resolved.Permit shipped-client lookup during contract review: fixed incd09d70e; replied with bounded-scope evidence and resolved.Keep new round-two blockers in the verdict: fixed incd09d70e; replied with open-list/verdict evidence and resolved.Recognize repository-relative API source paths: fixed in41b38e06; replied with parity-test evidence and resolved.Suppress findings below the repository review floor: fixed in41b38e06; replied with the P0/P1-floor regression and resolved.Request and evidence the OIDs required by the receipt: fixed in41b38e06; replied with the selected live query evidence and resolved.Load the rubric snapshot from PR-open time: fixed in41b38e06by replacing the unmechanized promise with a captured-base blob snapshot; replied and resolved.Preserve round one across the fixer head update: fixed in1457c0ddwith a single receipt-and-two-OID transition; replied and resolved.Support the advertised blank PR selector: fixed in1457c0ddby removing ambiguous blank/bare-number scope from the public contract; replied and resolved.Fetch both reviewed heads before diffing round two: fixed in1457c0dd; replied with hook evidence and resolved.Restore background-job timezone review: fixed in1457c0dd; replied with rubric/hook evidence and resolved.Preserve the frozen blocker list in round two: fixed in companion UI commitd9bb423eand API parity commit76cbc893; the canonical receipt now persists exact frozen IDs and UI readiness rejects their removal.Keep the round-one blocker list independently verifiable: fixed in6a01b6f7; round one is immutable, round two writes a new artifact that points to the original artifact and SHA-256, and readiness compares the exact ordered Blocking IDs. Companion UI red tests reject a changed hash or a dropped blocker.Prove gh pr diff response shape: this body now records the complete observed unified-diff structural output, exact redacted reproduction command, line/header/hunk counts, and the fact that the skill parses no JSON field from the command.Preserve the immutable round-one receipt: fixed in7f0cfcb2; every round-two instruction now consistently requires a separate receipt and explicitly keeps the round-one file byte-for-byte immutable.Cover every external-interface read in the blocking rule: fixed in7f0cfcb2; the canonical rubric now specifies proof formats and High/Blocking treatment for fields, shapes, enums, values, flags, subcommands, exit codes, and event arguments, matching the repository gate without narrowing it.Verify the Git commands before relying on their exit status: fixed in this body and7f0cfcb2; the real primary-checkout fetch/cat-file invocations, exact OIDs, exit statuses, and complete consumed output are recorded above.Prove review command interfaces: fixed in this body on773bea2d; the exact livegit showblob identity/size/output contract and the successfulgh pr comment --body-fileinvocation/URL are recorded above.Require fleet-safe proof before exempting removed fields: fixed in773bea2d; optional response-field removal is exempt only with version-indexed proof across every still-supported shipped client build. A current-main grep alone is explicitly insufficient.Register round one before the fixer: fixed in canonical parity commit773bea2dand UI implementation6627da40; the orchestrator stores the exact immutable receipt identity in repository Git state before round two and final readiness refuses caller-only replacement hashes.Prove and locate readiness registration: fixed in45a1c1e5and this body; the API contract names the UI-primary executable, while the complete real response shape, invocation, success result, and response-builder lines are recorded above.Bind the downloaded diff to captured OIDs: fixed in45a1c1e5; the reviewer rereads base/head immediately aftergh pr diff, compares both byte-for-byte to the first capture, and discards/restarts on any change.The current head after synchronizing the updated canonical review contract is
45a1c1e58602ccfba1801b01216088c588388014; the current base is50b187835f2d0f98b3b0b0ebf8b435610c8c0678. All earlier CI, connector, and independent-review receipts are stale and are reacquired on this exact pair.Deliberately deferred