Repository navigation
feat(context-engine): D3 P2 — pure attribution planner (Context-Used trailer → consequence plan) - #47
Merged
Conversation
…trailer → consequence plan)
The heart of D3: plan_attribution(root, ...) decides which merged commit
proves which injected cold-memory item useful, precision over recall —
every ambiguity resolves to do-not-attribute.
The §4.1 link predicate (ALL must hold, else a machine-readable rejection):
1. explicit Context-Used: <slug> git trailer (never inferred from
temporal proximity — §3.1);
2. ≥1 changed file matches ≥1 of the item's paths globs, with
surface_cold's EXACT matcher semantics (cited-but-no-overlap ⇒
cited_no_path_overlap, a probable mis-cite — §3.2);
3. existence + reachability by construction: candidates come only from
git log origin/<default> (bounded --since/--grep) — §3.6;
4. author-date ≥ the slug's earliest injection ts from the P0
cold_slugs ledger; a never-injected slug can NEVER attribute — §3.1;
5. same repo/anchor: only root's own git + ledger are consulted — §3.7.
Scope guards: cold-tier candidates only (§3.3 — no promoted-item feedback
loop) and write-once (already-attributed items skipped). Multiple
qualifying commits ⇒ the earliest (author-date, then sha) wins — first
proof of usefulness, deterministic on append-only merged history. One
commit citing many slugs evaluates each slug independently.
tests_green is resolved for the attributed sha via an injectable seam
over P1 ci_status.resolve_ci_status (caller-supplied github_repo/token;
either absent ⇒ verbatim "unknown" — the valid Phase-A value; nonstandard
seam values degrade to "unknown", NEVER True, never coerced).
ZERO writes: pure planner + dry-run-only CLI (no --apply at all; no
--token on argv). Never raises — any unexpected failure ⇒ empty plan
(plan_consolidation's fail-soft idiom). All evidence gathering sits
behind injectable seams (git log/diff-tree bounded like
pseudo_operator/committed.py; no env reads) so tests never touch a repo
or network. No caller wired; P3 dispatches the plan through
cold.write_item under the reviewed --apply boundary.
tests/test_attribution.py runs the §3 red-team as the matrix: temporal
coincidence, cited-before-injection, confounding (both halves),
never_injected, forged-sha seam contract, racing CI ⇒ "unknown",
write-once, warm-tier out of scope, earliest-commit determinism,
throwing seams ⇒ empty plan, byte-identical-tree purity. 31 tests; full
suite 463 pass; ruff clean.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
ProtocolWarden
force-pushed
the
feat/d3-p2-attribution-planner
branch
from
July 17, 2026 01:45
8152831 to
3c7d169
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
context_engine/attribution.py— the D3 P2 pure, dry-run-only attribution planner:plan_attribution(root, ...) -> AttributionPlan, deciding which merged commit proves which injected cold-memory item useful. Precision over recall: every ambiguity resolves to do-not-attribute.The §4.1 link predicate (ALL must hold, else a machine-readable rejection)
Context-Used: <slug>git trailer (exact match). Attribution is never inferred from temporal proximity.pathsglobs, withsurface_cold's EXACT matcher semantics (route._glob_to_regex+ the same leading-./normalization). Cited-but-no-overlap ⇒cited_no_path_overlap(probable mis-cite).git log origin/<default>(bounded--sincethe earliest injection ts,--grepprefilter), so every candidate sha resolves and is an ancestor of the merged default branch.cold_slugsledger (feat(context-engine): D3 P0-A — surface cold-item slug + record injected slugs (attribution substrate) #44). A slug never recorded as injected can NEVER attribute (never_injected).root's own git repo and ledger are ever consulted.Scope guards: cold-tier candidates only (§3.3 — no promoted-item feedback loop; warm/hot citations reject
not_cold_tier) and write-once (already_attributed). Multiple qualifying commits ⇒ the earliest (author-date, then sha) wins — first proof of usefulness, deterministic on append-only merged history. One commit citing many slugs evaluates each slug independently.tests_greenis resolved for the attributed sha via an injectable seam over P1ci_status.resolve_ci_status(#45);github_repo/tokenare caller-supplied — either absent ⇒ verbatim"unknown"(the valid §3.5 Phase-A value). Recorded exactly as returned:True | False | "unknown", never coerced, never defaulted True; nonstandard seam values degrade to"unknown", never True.Guarantees
--applyexists here at all; no--tokenon argv). P3 wires the writer throughcold.write_itemunder the reviewed--applyboundary.plan_consolidation's fail-soft idiom).pseudo_operator/committed.py.Red-team test matrix (
tests/test_attribution.py, 31 tests, all seams faked)test_happy_path_plans_slug_sha_greentest_same_window_commit_without_trailer_attributes_nothingtest_cited_before_injection_rejectedtest_unparseable_commit_date_rejected_fail_closedtest_earliest_injection_ts_is_the_time_guardtest_commit_citing_one_of_two_injected_slugs_credits_only_ittest_commit_citing_both_but_overlapping_one_credits_only_ittest_glob_matching_uses_surface_cold_semanticstest_cited_but_never_injected_rejected,test_empty_ledger_never_queries_commitstest_default_git_seam_parses_only_wellformed_cited_records,test_default_git_seams_fail_closed_on_git_error,test_planner_only_sees_commits_the_merged_default_listing_returnedtest_pending_ci_plans_unknown,test_nonstandard_ci_value_degrades_to_unknown_never_true,test_default_ci_seam_without_repo_or_token_is_unknowntest_ci_false_recorded_verbatimtest_already_attributed_item_skippedtest_warm_tier_cited_item_is_out_of_scope,test_cited_slug_with_no_item_rejected_unknown_slugtest_multiple_qualifying_commits_earliest_wins,test_equal_author_dates_break_ties_on_sha,test_earliest_nonqualifying_commit_does_not_block_later_qualifiertest_planner_never_raises_throwing_{commit,files,ci}_seam_yields_empty_plantest_malformed_ledger_lines_are_skipped_not_fataltest_planning_writes_nothing,test_missing_context_dir_yields_calm_empty_plantest_main_dry_run_prints_and_exits_zero,test_render_lists_attributions_and_rejectionsVerification
Full suite 463 pass (432 base + 31 new);
ruff check .clean; custodian audit 0 findings.🤖 Generated with Claude Code