Skip to content

Harden the v2.2 research contract - #8

Merged
almondsun merged 7 commits into
mainfrom
agent/v2.2-contract-hardening
Jul 16, 2026
Merged

almondsun merged 7 commits into
mainfrom
agent/v2.2-contract-hardening

Conversation

@almondsun

Copy link
Copy Markdown
Owner

Summary

  • enforce approved date, source, plan, evidence, and staged-corpus contracts throughout the research workflow
  • preserve exact retrieval provenance and invalidate stale evidence, answers, and dossiers when their inputs change
  • harden Ollama disclosure, structured-output repair, workspace/export writes, parser limits, and symlink handling
  • add the sealed three-arm evaluation workflow and fail-closed v2.2 release gates
  • consolidate current Python and GitHub Actions maintenance and group future Dependabot updates

Why

RAGdoll's original end-to-end workflow was credible, but important user-approved constraints and derived-state relationships were not service invariants. The repository also allowed seven one-update Dependabot pull requests to accumulate. This change makes the research contract enforceable and auditable while reducing future maintenance noise.

User and maintainer impact

  • research results now remain bound to approved scope, sources, dates, evidence consent, and the exact staged corpus
  • local versus remote model destinations are disclosed accurately
  • provenance, filesystem writes, parsing, evaluation, and release evidence are substantially more defensive
  • future monthly dependency maintenance should normally produce no more than one grouped Python PR and one grouped Actions PR
  • package metadata advances to the v2.2.0 release candidate; tagging remains blocked until the sealed benchmark is freshly captured and human-adjudicated against the merged revision

Validation

  • uv sync --frozen --extra dev --extra docs
  • uv run make check — 96 tests passed, 90.87% branch-aware coverage, strict mypy and Ruff passed, source and wheel builds succeeded
  • uv run pip-audit — no known dependency vulnerabilities (the unpublished local package itself is not on PyPI)
  • uv run mkdocs build --strict
  • YAML parse check for Dependabot and all workflows
  • git diff --check

@almondsun
almondsun marked this pull request as ready for review July 16, 2026 20:11
Copilot AI review requested due to automatic review settings July 16, 2026 20:11
@almondsun
almondsun merged commit 06cdbdb into main Jul 16, 2026
4 checks passed

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants