Converge self-review on a blocking boundary; gate PR opening - #238
Merged
Conversation
P0/P1 findings block convergence; P2/P3 are residuals recorded with the round. Convergence, stall, and round bounds run over the blocking measure so verdict wording and residual churn can neither converge past an open P1 nor keep the loop alive on nits. The blocking boundary joins the program fingerprint; the admitted prompt scopes deep durable-contract checks to diffs that touch such surfaces and turns nearby pre-existing issues into carried notes. Skills fix blocking findings only and report residual titles for the user to decide.
A branch that changes the policy assets previously sealed an attestation whose program fingerprint CI could never recompute, because the loop admitted the worktree policy while verification re-admits from the base revision. Both sides now admit from the base revision: the changed policy governs after merge, and resolve surfaces a policy note when the worktree assets drift from the admitted ones.
A solve run whose fix commit changes the reviewer's own code previously kept driving the binary built at run start. The prelude now rebuilds from the current tree before every command (a cached no-op when nothing changed), so mid-run repairs take effect for the next resolve, submit, and seal.
Opening a pull request becomes a governed workflow: skills/open-pr refuses unless the committed attestation verifies for the exact head tree (the check CI performs), then assembles a fixed-structure description — agent-drafted Boundary, Transition, and Evidence plus workflow-gathered facts (commits, attestation binding, residual findings) — pushes the branch, and creates the pull request. Fixture tests drive the whole flow against a scratch repo with a local bare remote and a stub gh.
A local go build artifact entered the tree with the open-pr skill; compiled skill binaries are never repository content, so the three skill output paths join .gitignore.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Boundary
This change crosses the convergence boundary of the self-review control program: the rule deciding when a reviewed head may become trusted, mergeable state. Previously that rule was the proposer's verdict string — an untrusted sentence. It is now a deterministic law over finding priorities, hashed into the program identity, and the same boundary gains a second consumer: opening a pull request itself becomes a governed transition that only fires for a head whose converged review attestation verifies.
Transition
Before: a review saying "patch is correct" converged even with an open P1, a review saying "patch is incorrect" over nothing but nits looped until stall, and any change to the review policy sealed an attestation CI could never verify, because the local loop admitted the worktree policy while CI re-admits from the base revision. After: convergence happens exactly when no blocking (P0/P1) finding remains, regardless of verdict wording; P2/P3 findings are residuals that are recorded and reported but can neither demand rounds nor trigger stall escalation; an incorrect verdict with zero findings is refused as incoherent; both the local loop and CI admit the policy from the base revision, so a policy-changing branch still seals a verifiable attestation and the new policy governs after merge; the review prompt scopes deep durable-contract checks to diffs that touch such surfaces; skill runs rebuild the reviewer per command so mid-run repairs take effect immediately; and pull requests open only through the new open-pr workflow, which refuses unless the committed attestation verifies for the exact head tree before pushing anything.
Evidence
The reviewer suite adds tests proving each side of the law: residual-only reviews converge under either verdict wording and land their priorities in the sealed round record; an open P1 refuses convergence despite a correct verdict; incorrect-with-zero-findings is invalid; shrinking residuals cannot mask a flat blocking measure (escalates on the third submission); and a branch that edits the prompt seals an attestation that verifies against the base admission while the worktree-fingerprinted inverse refuses. The full reviewer suite, go vet, and the 69-test repository contract suite pass. All three Yield skills pass fixture tests, with the open-pr fixture driving the real gate end to end: it seals a real attestation in a scratch repository, pushes to a local bare remote, and creates the pull request through a stub gh. The base-admission defect this description mentions was found by the new review program reviewing this very change: round 1 recorded it as a blocking P1, the fix landed, and round 2 converged — the attestation on this branch is the output of that loop.
Commits
Self-review attestation
638048ded4504ed3df431637e803348cc2100340ddbd77f1cbc842b3dffcb8e54b53ddcc624a998fb9c5a9ace15028580ab87967