docs(archdev-skill): publish a sealed code-region assessment per focus range - #32
Merged
Merged
Conversation
…s range ArchDev grades a hunk from the risk.code-region seal covering it (firstlanding#15317); without one it shows the annotation producer's unsealed label. The skill now owns the step that produces those seals: right after the annotation row is stored, collect each focus range with extract context code-region.risk, judge it from the collected packet, and store it with extract finalize --publish. The stopping-point check confirms every focus range on a pushed head has a seal. The minimum CLI rises to 0.46.5, the release that carries --publish (firstlanding#15315), and both bootstrap scripts probe for the flag so older installs upgrade instead of failing at the publish step.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Review on ArchCode
Problem and author intent
Since firstlanding#15317 (deployed 2026-09-25), ArchDev grades a hunk from the sealed
risk.code-regionassessment that covers it: rail card, callout, toolbar badge, risk filter and index all read the seal's combined grade, with the seal named on the badge hover. Without a seal they fall back to the annotation producer's ownrisklabel, which is not a graded assessment under Rob's definitions. The CLI has had the write path since firstlanding#15315 (extract finalize risk.code-region <file> --publish <pull>, released in v0.46.5), but no agent runs it: the skill never mentions it, so every head today has zero region seals and the review shows only unsealed labels.Seals are rows per exact head in
github_pr_risk_assessments, so they vanish on every push exactly as annotations do. The session that stores the annotations is the one that has the focus list in hand, so it is the one that should publish the seals.What changed
archdev/references/monitor.md, new Focus range seals section after PR review annotations. For each range in the stored row'ssummary.focus: collect withextract context code-region.risk "<owner/repo>#<num>;<path>:<side>:<start>-<end>" --json(changed lines only, split around context, several ranges of one behavior in one call by repeating the selector, nontext files withfile=<path>); author{input, assessment}withinputtaken from the collected packet (itssubjectwithlocationsalready set and the pull URL as source, which--publishaccepts); seal and store withextract finalize risk.code-region … --publish <owner/repo>#<num>; mitigate and recompute as for other seals, at most two rounds; verify withinspect metadata <num> --sha <head> --json, whoseassessmentslists every stored seal. Refusal rules (other pull,risk.prseal), idempotent repeat, and non-zero exit on store failure are stated.code-regionis published per focus range rather than posted, and orders a PR's steps as annotations, then focus seals, then the PR seal and post. The PR review annotations section's step 5 and its verify paragraph point at the new section and atassessmentsininspect metadata.archdev/SKILL.md: minimum CLI 0.46.5 with the reason; Monitor beat 3's stopping-point check also confirms each focus range on a pushed head has a seal.archdev/scripts/bootstrap.shandbootstrap.ps1:min_version0.46.5, andsupports_skill/Test-Skillprobeextract finalize --helpfor--publish <pull>, so an install that predates the flag is upgraded by bootstrap instead of failing at the publish step.references/bootstrap.mdand the old-CLI fallback bullet in monitor.md name the new minimum.Not changed: whether unsealed ranges should still show the producer's label (firstlanding#14994 task 5, Rafael's call), and the backend assessor that would publish seals without an agent (follow-up issue).
Testing
Docs plus two probe scripts.
extract context code-region.risk "ArchAstro/firstlanding#15317;services/go/archdev/web/src/review-metadata.ts:modified:935-1022" --jsoncollected a 225 KB packet withsubject.locationsset; a judgment built from the untrimmed packet passedextract finalize risk.code-region … --publish ArchAstro/firstlanding#15317(combined low,publishedblock with head, digest, locations);inspect metadata 15317 --sha 9708072e8a --jsonreturns the row underassessments. This establishes that the 64 KB cap applies tolog postattachments only, which the section states. That seal is a real row on a merged PR; it is harmless and can be left or removed.file=selector syntax was checked against the CLI source (extract/subjects/risk.ts,ref.split(";"),file=prefix) rather than run.bash -n archdev/scripts/bootstrap.shpasses; running it against the installed 0.46.5 prints the binary path and attempts no upgrade.bootstrap.ps1mirrors the bash change line for line but was not executed (no pwsh on this machine); the repo's installer smoke test workflow is the automated check.Risk
Low. Instruction text and two probe scripts. The probe change is the only behavioral edit: an agent on 0.46.0 to 0.46.4 now gets upgraded by bootstrap, which is the intended effect and the same path every earlier minimum bump used.