refactor(e2e): an excluded section predicts at no grade - #120
Conversation
Template checkIntegrityPassed - this repository matches the state it was stamped with. FreshnessThis repository is behind the build branch by 17 commit(s). The next sync PR updates the managed files; nothing to do here. |
File size check23 over a hard cap (fails), 108 warning(s).
Split the file, wrap the line, shorten or exempt the comment, or list the path in 8 managed file(s) skipped; repo-platform owns them. |
876ad86 to
f5ad329
Compare
…mers stop special-casing it
In test/e2e/oracle.ts an excluded section (declared, but outside the sections allowlist) carried mask-derived grades, and three consumers compensated with allowed.has("excluded") checks: preflightDeniable, the fullyGranted fold in predictOutcomes, and writeDeniedSections through writeGranted.
predictSectionAt, the owner PR #114 chose for the personal-account no-op, now mints the excluded prediction whole: grades [], allowed {excluded}, mayWrite false, before the mask is consulted. The section runs at no grade (orchestrate.ts filters it out of the preflight list and the section loop skips it before any read), so every fold over its grades is vacuous by construction: preflightDeniable finds no none grade, writeGranted is vacuously true, and fullyGranted and writeDeniedSections follow. The three consumer-side checks are deleted.
Tests pin the whole SectionPrediction for an excluded plain section (beside its unrestricted control), an excluded org-only section on a personal account (exclusion wins), and an excluded NO_READ section in check mode, plus the whole RunPrediction for an excluded denied section beside an active one, with the same meta active as the negative control that predicts the preflight abort.
The branch includes a merge of origin/main so it sits on top of PR #114's oracle fix.
The previous commit said "runs at no grade, so every fold is vacuous" in six places in test/e2e/oracle.ts. The one statement now lives on SectionPrediction.grades, with the orchestrate.ts disposition cross-reference and the list of folds it makes vacuous; the predictSectionAt docs point there, and the fullyGranted, writeGranted, and preflightDeniable docs drop their local copies. writeGranted's doc now says "every effective grade is write", which is what the code computes for an empty grade list too.
f5ad329 to
fe8b505
Compare
There was a problem hiding this comment.
🟢 Approval recommended
The implementation matches engine behavior and has focused coverage for affected predictions.
Pull request overview
Refactors the E2E oracle so excluded sections predict no execution grades, simplifying downstream folds.
Changes:
- Returns empty grades for excluded sections before permission evaluation.
- Removes redundant exclusion checks from run-level calculations.
- Adds whole-object regression tests for exclusion behavior.
File summaries
| File | Description |
|---|---|
test/e2e/oracle.ts |
Centralizes excluded-section prediction and simplifies consumers. |
test/e2e/oracle.test.ts |
Expands regression coverage for excluded sections. |
Review details
- Files reviewed: 2/2 changed files
- Comments generated: 0
- Review effort level: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Before / After
Before, an excluded section (declared in settings.yml, but outside the
sectionsallowlist) carried mask-derivedgrades, and three consumers intest/e2e/oracle.tscompensated with anallowed.has("excluded")check:preflightDeniableallowedhad "excluded"fullyGranted(inpredictOutcomes)writeDeniedSectionswriteGrantedover grades the section never ran atAfter, one owner.
predictSectionAtmints the excluded prediction whole, before the mask is consulted:How
["write"]).Proof
bun run checkgreen; fuzz 30/30 ok (master seed 2385354755); four whole-object oracle tests added.Technical details
Mechanism
src/engine/orchestrate.tsclassifies a section excluded in itsdispositionfilter, which feeds both the preflight list and the section loop. Preflight never probes it and the loop skips it before any read, so no grade can matter.preflightDeniablefinds nononegrade (so "no"),writeGrantedis[].every(...)(true), andfullyGrantedandwriteDeniedSectionsfollow.test/e2e/fuzz.tswas checked for other readers ofgradesorallowedon excluded sections: the comparison loop still requires an "excluded" summary row, and only its mismatch diagnostic prints the grade list.Tests (
test/e2e/oracle.test.ts, whole-object)failed)[]RunPrediction; negative control with the same meta active predictspreflightAborts: "yes"and exit 1Gates and review
bun run checkbun test/e2e/fuzz.ts --iterations 0bun test/e2e/fuzz.ts --iterations 30