ci: require exact-head production coverage evidence - #156
Conversation
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Follow-up exact head 25b3e42 fixes the behavioral root cause exposed by the new stale-delete contract: disconnect now deletes stale legacy credentials before the canonical credential. If a stale delete fails, the canonical refresh credential remains available for retry; the durable document is still rolled back. The existing unit and integration contracts now assert legacy-before-canonical ordering. |
|
Exact-head coverage evidence at 25b3e42 failed for the measured repository scope, not for the OAuth change: cargo llvm-cov reported regions 86.2368%, branches 72.5630%, functions 75.3830%, and lines 86.9174%. The bounded diagnostic lists existing gaps across commands.rs, cloud.rs, provider_oauth.rs, and other binaries. I am leaving the draft fail-closed rather than weakening the 100% gate or claiming readiness; the next repair must add real coverage or explicitly narrow the measured product boundary with a documented ADR. |
|
Scheduled review-feedback autofix for this PR head.
|
|
Scheduled review-feedback autofix for this PR head.
|
|
Scheduled review-feedback autofix for this PR head.
|
|
Scheduled review-feedback autofix for this PR head.
|
|
Inheritance ledger update (2026-09-04): latest RED |
|
Scheduled review-feedback autofix for this PR head.
|
|
2026-09-04 current-owner inheritance update: old exact #337 coverage run |
|
Coverage inheritance ledger update — 2026-09-04 Current canonical coverage owner #337 advanced from Why this donor is still current-compatible: the present This step is driven by the latest trustworthy coverage RED on #337 predecessor Classification: |
|
Next donor review finding — Do not copy historical blob The valid successor path is a minimal current-shape adaptation ( |
|
Scheduled review-feedback autofix for this PR head.
|
|
Coverage inheritance update (2026-09-04): |
|
Coverage inheritance update (current owner #337): measured RED |
|
2026-09-05 inheritance classification: historical |
Purpose
Enforce fail-closed exact-head owned-production coverage, trustworthy Rust test evidence, reproducible release evidence, and realistic production-boundary regressions. This historical branch is an evidence donor only: thresholds and owned-production scope are not weakened, predecessor evidence never transfers, and superseded product history must not be mechanically rebased onto current main.
Exact current state — 2026-09-05 KST
a3803fced0bdbb4f8eb9d19d07a623b1422e5204;main:0e90f9cebadbd7f59606baaec4ca1d2f178c899a(#343);3e33229b4157a084a1985a1c7e952f98a64f25e3;eb255b92a0c63f44947a5d932694bf1df0678914;7d9d5040941650bf8ed8678b15092cffc439415a, non-force restacked parent-first through fix(ci): repair contract-doc path filtering #338/fix: verify Windows release artifact namespace #264;42c89e253f07b4c0bfe4ea75c47bcaa790e95a85, downstream of reusable publication owner security: restore object-bound private evidence publication #3442a23a1d7de5b929a76b432c192d2b9e537fbbbdd;72665604821994b1f396c57e7a0ee271bea76de1;Verified inheritance into current owners
#337 carries the bounded coverage-diagnostic fallback, exact-head Test/coverage infrastructure, command/environment, cloud, minimally adapted iCloud-health, and real Git-worktree coverage fixtures. The adopted Git-worktree fixtures use real temporary Git repositories and preserve dirty retained worktrees; stale/prunable registration is diagnostic evidence only and never deletion authority.
Provider-OAuth domain evidence remains #339-owned and consumes #344's object-bound private-publication foundation; shipped CLI/process/platform-host evidence remains #212-owned. Release-specific Cargo/Tauri binary isolation, stable artifact identity, rerun/verifier and provenance contracts are #264-owned. Re-copying current-owner contracts into this historical line is rejected.
Coverage evidence boundary
The last usable current-stack predecessor measurement recorded on #337 before its latest restack was:
64,391 / 80,218 = 80.270014%;5,292 / 8,991 = 58.858859%;3,357 / 4,924 = 68.176280%;42,867 / 53,111 = 80.712094%.Those numbers are diagnostic predecessor evidence only. #337 current exact head
7d9d504...must produce its own hosted compile/runtime and repository-wide measurement before any coverage progress or GREEN claim. Thresholds remain exact 100%; exclusions or denominator reduction are not acceptable substitutes.The older historical #156 measurement (
55,501/64,352regions,5,098/7,023branches,2,903/3,851functions,36,792/42,326lines) remains historical diagnostic evidence only and does not transfer.Remaining inheritance work
#156 stays open until every still-useful unique test, fixture, contract, and evidence delta has either a verified canonical current owner/current-lineage implementation or an exact technical rejection because the assertion is duplicate, superseded, unrealistic, or no longer describes current behavior. Do not close merely to reduce PR count. Do not force-rebase or blindly overlay this historical product branch onto current main.
Required before closure
Closure is valid only after every useful delta is demonstrably inherited or technically rejected. Every current owner still requires its own unchanged-head live policy, exact non-vacuous coverage where applicable, Test/Release/Security/SAST/OSV/Scorecard/central workflows, zero valid unresolved findings, fresh ancestry, and package/SBOM/provenance/release evidence. Pending, queued, skipped-required, failed, stale-head, predecessor, diagnostic-only, status-only, model-only, author-only, no-source-scanner, infrastructure-only, or resource-exhausted evidence is non-passing.