Skip to content

feat(context-engine): D3 P1 — fail-closed CI-status resolver (sha → tests_green) - #45

Merged
ProtocolWarden merged 1 commit into
mainfrom
feat/d3-p1-ci-status
Jul 17, 2026
Merged

ProtocolWarden merged 1 commit into
mainfrom
feat/d3-p1-ci-status

Conversation

@ProtocolWarden

Copy link
Copy Markdown
Owner

What

A small, read-only, fail-closed CI-status resolver: given owner/repo + a commit sha, resolve_ci_status(...) reports whether that commit's CI is green as the verbatim True | False | "unknown" value cold.py stores.

New module: src/context_lifecycle/context_engine/ci_status.py.

Why

consolidate._is_real_sha documents itself as "a v1 stand-in … does NOT yet resolve the sha against the repo … the deferred §9 attribution item." The cold-store item (cold.py:66-67) already declares the target fields acted_on_commit and tests_green (true | false | "unknown", stored verbatim). This PR resolves the CI half of that §9 item, to feed the future D3 consequence-writer's tests_green field.

Fail-closed rules (the whole point — never True on doubt)

  • Queries GitHub's commits/{sha}/check-runs via gh api (matches CL's subprocess idiom — no new dependency), behind an injectable _run_gh seam so tests never touch the network. Rollup (dedupe by name, keep newest run id) mirrors OperationsCenter's get_failed_checks / get_incomplete_checks.
  • tests_green = True iff ≥1 check run AND every run completed AND none failing/incomplete/doubtful.
  • tests_green = False on any failing conclusion (failure/timed_out/cancelled/action_required/stale).
  • tests_green = "unknown" on: no runs, a still-running run, a completed run with an unmodelled/null conclusion, an unknown sha, a missing token, a non-zero gh exit, malformed JSON, or any exception. The call is wrapped so it never raises to the caller.
  • The caller supplies the token (its own config/env layer); the module reads no env key of its own.

Scope

  • No caller wires it yet — ships standalone + fully unit-tested (tests/test_ci_status.py, full doubt matrix). A later PR feeds the D3 consequence-writer.
  • No change to the promotion gate (consolidate.gate_promotions / _is_real_sha).
  • .custodian/config.yaml: the module's single os.environ.copy() is the process-spawn layer for gh (inherits PATH/HOME, injects the caller's token as GH_TOKEN) — added to c13_allowed_paths with the same spawn-layer rationale already granted to pseudo_operator/sessions.py.

Full suite green (429 passed); ruff check . clean; custodian pre-push audit clean (0 findings).

🤖 Generated with Claude Code

…ests_green)

Resolve the CI half of consolidate.py's deferred §9 attribution item: given
owner/repo + a commit sha, report whether that commit's CI is green as the
verbatim True | False | "unknown" contract cold.py stores. Queries GitHub's
check-runs API via `gh api` (CL's subprocess idiom, no new dependency) behind
an injectable seam so tests never touch the network; rollup mirrors
OperationsCenter's get_failed_checks/get_incomplete_checks.

Fail-closed: True only when >=1 run AND all completed cleanly; False on any
failing conclusion; "unknown" on no runs, in-flight, unknown sha, missing
token, non-zero exit, malformed JSON, or ANY exception — never raises, never
True on doubt. Standalone + fully unit-tested; no caller wires it yet and the
promotion gate is unchanged.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@ProtocolWarden
ProtocolWarden merged commit 57fd670 into main Jul 17, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant