Skip to content

ci(fullsend): activate validated native gate judge - #328

Merged
mrizzi merged 1 commit into
RHEcosystemAppEng:mainfrom
mrizzi:TC-6768
Oct 7, 2026
Merged

mrizzi merged 1 commit into
RHEcosystemAppEng:mainfrom
mrizzi:TC-6768

Conversation

@mrizzi

@mrizzi mrizzi commented Oct 7, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Implements TC-6768, the trusted source activation sub-task of TC-6726.

Changes one line in .github/workflows/eval-pr-run.yml: the immutable native suite pin moves from c7ca8495f1a83c51d191f55e391b17c5b29e97da to 91698d4dca24bc199e763dc6462dc54523e473c0, already pushed to PR #299.

No native suite files are added to main. Approval, WIF, sandbox isolation, immutable tested-source checks, reporting and the PR #299 bootstrap restriction are unchanged.

Reviewed source delta

The complete old-pin/new-pin delta contains three files:

  • evals/fullsend/triage-security/judge.md: the 11-line TC-6764 clarification of expected absent/empty stopping boundaries. Genuine Skill invocation, plugin binding and real gate results remain required; actual bootstrap failures still fail.
  • .github/scripts/run-native-fullsend-evals.sh: explicit Opus 4.8 judge selection, already merged into main through PR fix(ci): use Opus 4.8 for native eval judging #327. The workflow runs its trusted main wrapper.
  • plugins/sdlc-workflow/scripts/test_native_fullsend_eval_ci.py: the corresponding Opus 4.8 contract test, already merged through PR fix(ci): use Opus 4.8 for native eval judging #327.

All native cases and 21 assertion texts remain unchanged. Dependencies, adapter, schema, product Skill and credential preparation are unchanged between these source pins.

Validation

  • Baseline and post-change main test suites: 114 passed.
  • Skillsaw: 0 errors, 7 existing warnings.
  • Claude plugin validation and git diff --check: passed.
  • Saved actual native evidence with the new judge: absent/empty passed in three repeats (6/6 Boolean true); both actual no-Skill bootstrap controls remained false. Original evidence hashes unchanged; no agents rerun.

The malformed verdict/rationale inconsistency and separate hosted valid-case failure remain unresolved; this PR does not claim hosted 21/21.

Merge and execution sequence

  1. Human reviews the immutable source delta and merges this pin-only PR.
  2. Rerun PR [DRAFT] verify-pr fullsend CI deployment (TC-6180) #299's existing Eval PR trigger so its consumer uses updated trusted main and resolves the current approved PR head/base/merge.
  3. Inspect the source-bound native and ordinary results before deciding the next fix or merging PR [DRAFT] verify-pr fullsend CI deployment (TC-6180) #299.

No paid native eval was run for this pin-only PR before merge.

Summary by Sourcery

CI:

  • Activate the validated native fullsend evaluation suite by updating the immutable trusted source revision used by the Eval PR workflow.

Pin the reviewed PR299 source containing the expected absent/empty gate judge clarification.

Implements TC-6768

Assisted-by: Claude Code
@sourcery-ai

sourcery-ai Bot commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor
Reviewer's guide (collapsed on small PRs)

Reviewer's Guide

This pin-only change switches the CI workflow to the validated native fullsend suite source, whose reviewed delta preserves the existing evaluation cases and controls while incorporating the clarified stopping-boundary behavior and Opus 4.8 judge contract. Review the immutable source delta and then rerun PR #299’s existing trigger; no paid native evaluation was run for this PR.

Sequence diagram for rerunning PR #299 with the validated native source

sequenceDiagram
    actor Reviewer
    participant EvalWorkflow as eval_pr_run
    participant TrustedSource as ValidatedNativeSource
    participant NativeRunner as run_native_fullsend_evals_sh
    Reviewer->>EvalWorkflow: Rerun PR 299 trigger
    EvalWorkflow->>TrustedSource: NATIVE_EVAL_SOURCE_SHA
    TrustedSource-->>EvalWorkflow: Reviewed source at 91698d4dca24bc199e763dc6462dc54523e473c0
    EvalWorkflow->>NativeRunner: run-native-fullsend-evals.sh
    NativeRunner-->>EvalWorkflow: Native evaluation results
Loading

File-Level Changes

Change Details Files
Activates the reviewed native fullsend suite by updating the immutable trusted source pin.
  • Replace the prior native suite commit SHA with the validated commit containing the reviewed judge clarification and Opus 4.8 judge selection.
  • Keep workflow approval, WIF, sandbox isolation, source verification, reporting, and PR [DRAFT] verify-pr fullsend CI deployment (TC-6180) #299 bootstrap protections unchanged.
.github/workflows/eval-pr-run.yml

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've reviewed your changes and they look great!

Sourcery assessment

Approved.


Sourcery is free for open source - if you like our reviews please consider sharing them ✨

@mrizzi

mrizzi commented Oct 7, 2026

Copy link
Copy Markdown
Collaborator Author

Verification Report for TC-6768 (commit 6d04139)

Check Result Details
Review Feedback N/A No inline comments or substantive review bodies (only a Sourcery APPROVED + reviewer's guide)
Root-Cause Investigation N/A No sub-tasks created
Scope Containment PASS Sole changed file matches the task's one Files-to-Modify entry exactly
Diff Size PASS +1/-1 across 1 file — proportionate to a one-line SHA re-pin
Commit Traceability PASS Commit 6d04139 body references TC-6768 (Implements TC-6768)
Sensitive Patterns PASS No secrets in the added line (value is a 40-hex git commit SHA)
CI Status PASS All 4 head-SHA checks success (Sourcery review, Plugin Validation, Skill Lint, Trigger Eval Dispatch)
Acceptance Criteria PASS 5 of 5 criteria met
Test Quality N/A No test files and no eval result reviews in this PR
Test Change Classification N/A No test files added/modified/deleted
Verification Commands PASS pytest 111 passed, claude plugin validate ✔, git diff --check clean, skillsaw grade A (0 errors)

Overall: PASS

Pin-only activation of the validated native gate judge source. The sole main diff is one line in .github/workflows/eval-pr-run.yml (NATIVE_EVAL_SOURCE_SHA c7ca8495 → 91698d4d). The new pin is a clean descendant of the old (ahead 5, behind 0); its host-executed delta touches only PR #299-side files (run-native-fullsend-evals.sh Opus 4.8 judge, judge.md +11 expected-stop clarification, test_native_fullsend_eval_ci.py +14 tests) and none land on main. No review feedback required action; no sub-tasks created.

Next steps (not performed by this skill): human merge of this PR, then the post-merge hosted eval re-run of PR #299 against the updated trusted main. No paid inference was run for this pin-only PR.

Note: under the local Bash sandbox one pytest case (test_multiline_credentials_register_individual_nonempty_masks) fails spuriously due to macOS bash 3.2 herestring temp-file writes being sandbox-denied; it passes (111/111) outside the sandbox and on Ubuntu CI, and is unaffected by this one-line change.


This comment was AI-generated by sdlc-workflow/verify-pr v0.13.9.

@mrizzi
mrizzi merged commit ab0c65a into RHEcosystemAppEng:main Oct 7, 2026
5 checks passed
@mrizzi
mrizzi deleted the TC-6768 branch October 7, 2026 11:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant