Skip to content

docs(archdev-skill): publish a sealed code-region assessment per focus range - #32

Merged
rafael-archastro merged 1 commit into
mainfrom
docs/archdev-skill-region-seals
Sep 25, 2026
Merged

rafael-archastro merged 1 commit into
mainfrom
docs/archdev-skill-region-seals

Conversation

@rafael-archastro

@rafael-archastro rafael-archastro commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Review on ArchCode

Problem and author intent

Since firstlanding#15317 (deployed 2026-09-25), ArchDev grades a hunk from the sealed risk.code-region assessment that covers it: rail card, callout, toolbar badge, risk filter and index all read the seal's combined grade, with the seal named on the badge hover. Without a seal they fall back to the annotation producer's own risk label, which is not a graded assessment under Rob's definitions. The CLI has had the write path since firstlanding#15315 (extract finalize risk.code-region <file> --publish <pull>, released in v0.46.5), but no agent runs it: the skill never mentions it, so every head today has zero region seals and the review shows only unsealed labels.

Seals are rows per exact head in github_pr_risk_assessments, so they vanish on every push exactly as annotations do. The session that stores the annotations is the one that has the focus list in hand, so it is the one that should publish the seals.

What changed

  • archdev/references/monitor.md, new Focus range seals section after PR review annotations. For each range in the stored row's summary.focus: collect with extract context code-region.risk "<owner/repo>#<num>;<path>:<side>:<start>-<end>" --json (changed lines only, split around context, several ranges of one behavior in one call by repeating the selector, nontext files with file=<path>); author {input, assessment} with input taken from the collected packet (its subject with locations already set and the pull URL as source, which --publish accepts); seal and store with extract finalize risk.code-region … --publish <owner/repo>#<num>; mitigate and recompute as for other seals, at most two rounds; verify with inspect metadata <num> --sha <head> --json, whose assessments lists every stored seal. Refusal rules (other pull, risk.pr seal), idempotent repeat, and non-zero exit on store failure are stated.
  • The Risk assessments section says code-region is published per focus range rather than posted, and orders a PR's steps as annotations, then focus seals, then the PR seal and post. The PR review annotations section's step 5 and its verify paragraph point at the new section and at assessments in inspect metadata.
  • archdev/SKILL.md: minimum CLI 0.46.5 with the reason; Monitor beat 3's stopping-point check also confirms each focus range on a pushed head has a seal.
  • archdev/scripts/bootstrap.sh and bootstrap.ps1: min_version 0.46.5, and supports_skill / Test-Skill probe extract finalize --help for --publish <pull>, so an install that predates the flag is upgraded by bootstrap instead of failing at the publish step. references/bootstrap.md and the old-CLI fallback bullet in monitor.md name the new minimum.

Not changed: whether unsealed ranges should still show the producer's label (firstlanding#14994 task 5, Rafael's call), and the backend assessor that would publish seals without an agent (follow-up issue).

Testing

Docs plus two probe scripts.

  • The exact flow was run on 2026-09-25 against firstlanding#15317 at head 9708072e8a with CLI 0.46.5: extract context code-region.risk "ArchAstro/firstlanding#15317;services/go/archdev/web/src/review-metadata.ts:modified:935-1022" --json collected a 225 KB packet with subject.locations set; a judgment built from the untrimmed packet passed extract finalize risk.code-region … --publish ArchAstro/firstlanding#15317 (combined low, published block with head, digest, locations); inspect metadata 15317 --sha 9708072e8a --json returns the row under assessments. This establishes that the 64 KB cap applies to log post attachments only, which the section states. That seal is a real row on a merged PR; it is harmless and can be left or removed.
  • The multi-range and file= selector syntax was checked against the CLI source (extract/subjects/risk.ts, ref.split(";"), file= prefix) rather than run.
  • bash -n archdev/scripts/bootstrap.sh passes; running it against the installed 0.46.5 prints the binary path and attempts no upgrade. bootstrap.ps1 mirrors the bash change line for line but was not executed (no pwsh on this machine); the repo's installer smoke test workflow is the automated check.

Risk

Low. Instruction text and two probe scripts. The probe change is the only behavioral edit: an agent on 0.46.0 to 0.46.4 now gets upgraded by bootstrap, which is the intended effect and the same path every earlier minimum bump used.

…s range

ArchDev grades a hunk from the risk.code-region seal covering it
(firstlanding#15317); without one it shows the annotation producer's
unsealed label. The skill now owns the step that produces those seals:
right after the annotation row is stored, collect each focus range with
extract context code-region.risk, judge it from the collected packet,
and store it with extract finalize --publish. The stopping-point check
confirms every focus range on a pushed head has a seal.

The minimum CLI rises to 0.46.5, the release that carries --publish
(firstlanding#15315), and both bootstrap scripts probe for the flag so
older installs upgrade instead of failing at the publish step.
@rafael-archastro
rafael-archastro merged commit f1f606d into main Sep 25, 2026
5 checks passed
@rafael-archastro
rafael-archastro deleted the docs/archdev-skill-region-seals branch September 25, 2026 16:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant