Board Program LEARN context, ruff 0.16, and verb-rejection observability (#700)

* fix(board): LEARN decisions name the item, not its per-cycle index

A cycle's reject reasons are rendered into the NEXT cycle's exploration
prompt, but the ref recorded alongside each reason was the item's stored
id (item-0/item-1) — a per-cycle index that means something different
every cycle and appears nowhere the explorer can resolve. The reason
survived the loop; what it was about did not.

Record the item's title instead, via a shared learn_ref() helper (falls
back to the id when title-less, and reads target_task_title for Scales,
whose items name the live task they mutate).

* chore(lint): satisfy ruff 0.16 — keyword-only signatures and markdown formatting

The dev toolchain resolved ruff 0.16.0, which stabilises PLR0917 (too many
positional arguments) and formats python code blocks inside markdown. Both
fired repo-wide and neither had anything to do with the code they flagged.

- 36 signatures gain a `*` so their tail arguments are keyword-only, and
  the 104 call sites that passed them positionally are converted. mypy was
  the safety net for the static ones; the full suite caught nine more that
  only bind at runtime (the MCP tool functions, whose real callers already
  pass named JSON arguments).
- 28 markdown files reformatted by 0.16's code-block formatter.
- One RUF036 (`None` mid-union) autofixed in the GitLab provider.

* fix(gateway): log the reason when a verb rejects

A rejected envelope rides an HTTP 200, its body is never logged, and there
is no trace table — so in the access log a verb an agent could not satisfy
looks identical to one that worked. On 2026-07-25 four Board Programs
(Periscope, Sentinel, Scales, Barfly) each POSTed their propose verb three
or four times, persisted nothing, and left their exploration tasks PENDING;
the reason was unrecoverable afterwards, from the logs or from the agents'
own transcripts.

Log error/message/remediate/missing plus the calling agent at
envelope_to_response — the one chokepoint every v1 flow and do route
returns through. Success envelopes stay silent.

---------

Co-authored-by: Renn F <rennf93@users.noreply.github.com>
This commit is contained in:
Renzo F
2026-07-26 15:07:28 +02:00
committed by GitHub
co-authored by Renn F
parent 401f8a2cc9
commit 879afc14a4
84 changed files with 932 additions and 567 deletions
+4 -4
View File
@@ -33,12 +33,11 @@ All functions MUST have type hints:
```python
# Good
async def fetch_user(user_id: UUID) -> User | None:
...
async def fetch_user(user_id: UUID) -> User | None: ...
# Bad - no type hints
def fetch_user(user_id):
...
def fetch_user(user_id): ...
```
## Naming Conventions
@@ -79,6 +78,7 @@ ALL I/O operations must be async:
async def fetch_user(user_id: str) -> User:
return await db.users.get(user_id)
# Bad - blocking
def fetch_user(user_id: str) -> User:
return db.users.get(user_id) # Blocks!
+5
View File
@@ -29,12 +29,15 @@ Define domain-specific exceptions:
class TaskError(Exception):
"""Base exception for task operations."""
class TaskNotFoundError(TaskError):
"""Task does not exist."""
class TaskAlreadyClaimedError(TaskError):
"""Task is already claimed."""
# Usage
if task is None:
raise TaskNotFoundError(f"Task {task_id} not found")
@@ -62,6 +65,7 @@ Use structlog, NEVER print:
```python
import structlog
logger = structlog.get_logger(__name__)
# Good
@@ -86,6 +90,7 @@ async def create_task(request: TaskCreate) -> TaskResponse:
# Pydantic validates automatically
...
# Internal service - trust validated data
async def process_task(task: Task) -> None:
# No need to re-validate
+6 -4
View File
@@ -12,6 +12,7 @@ DATABASE_URL = "postgresql://user:password@host/db"
# Good - environment variables
from pydantic_settings import BaseSettings
class Settings(BaseSettings):
api_key: str
database_url: str
@@ -27,9 +28,7 @@ NEVER use string concatenation for SQL:
query = f"SELECT * FROM users WHERE id = '{user_id}'"
# Good - parameterized query
result = await session.execute(
select(User).where(User.id == user_id)
)
result = await session.execute(select(User).where(User.id == user_id))
```
## Command Injection Prevention
@@ -39,10 +38,12 @@ NEVER pass user input directly to shell:
```python
# Bad - command injection
import os
os.system(f"process_file {filename}")
# Good - use subprocess with list
import subprocess
subprocess.run(["process_file", filename], check=True)
```
@@ -56,6 +57,7 @@ result = eval(user_input)
# Good - safe parsing
import ast
result = ast.literal_eval(user_input) # Only literals
```
@@ -68,7 +70,7 @@ import hashlib
content_hash = hashlib.md5(
content.encode(),
usedforsecurity=False # Required flag
usedforsecurity=False, # Required flag
).hexdigest()[:12]
```
+7 -4
View File
@@ -16,6 +16,7 @@ Use pytest-asyncio:
```python
import pytest
@pytest.mark.asyncio
async def test_fetch_user() -> None:
user = await fetch_user("test-123")
@@ -48,11 +49,12 @@ Use factory-boy for test data:
```python
from factory import Factory, Faker, LazyAttribute
class TaskFactory(Factory):
class Meta:
model = Task
title = Faker('sentence')
title = Faker("sentence")
status = TaskStatus.PENDING
created_at = LazyAttribute(lambda _: datetime.now(UTC))
```
@@ -84,7 +86,7 @@ When you assign `None` to an attribute inside a test function, mypy narrows that
def test_example() -> None:
t = _Task()
t.notes = None # mypy narrows type to None
process(t) # Even though process may write to t.notes
process(t) # Even though process may write to t.notes
assert t.notes is not None # [unreachable] — mypy sees this as always False
```
@@ -94,11 +96,12 @@ def test_example() -> None:
# ✅ GOOD: Annotation-typed class preserves union type
class _TaskWithNoNotes:
"""Variant where notes starts as None (no prior state)."""
def __init__(self) -> None:
self.id = uuid4()
self.notes: dict[str, Any] | None = None # Declared as union, not narrowed
def test_example() -> None:
t = _TaskWithNoNotes() # Use the helper instead
process(t)