mirror of
https://github.com/rennf93/roboco.git
synced 2026-08-03 07:23:24 +02:00
Board Program LEARN context, ruff 0.16, and verb-rejection observability (#700)
* fix(board): LEARN decisions name the item, not its per-cycle index A cycle's reject reasons are rendered into the NEXT cycle's exploration prompt, but the ref recorded alongside each reason was the item's stored id (item-0/item-1) — a per-cycle index that means something different every cycle and appears nowhere the explorer can resolve. The reason survived the loop; what it was about did not. Record the item's title instead, via a shared learn_ref() helper (falls back to the id when title-less, and reads target_task_title for Scales, whose items name the live task they mutate). * chore(lint): satisfy ruff 0.16 — keyword-only signatures and markdown formatting The dev toolchain resolved ruff 0.16.0, which stabilises PLR0917 (too many positional arguments) and formats python code blocks inside markdown. Both fired repo-wide and neither had anything to do with the code they flagged. - 36 signatures gain a `*` so their tail arguments are keyword-only, and the 104 call sites that passed them positionally are converted. mypy was the safety net for the static ones; the full suite caught nine more that only bind at runtime (the MCP tool functions, whose real callers already pass named JSON arguments). - 28 markdown files reformatted by 0.16's code-block formatter. - One RUF036 (`None` mid-union) autofixed in the GitLab provider. * fix(gateway): log the reason when a verb rejects A rejected envelope rides an HTTP 200, its body is never logged, and there is no trace table — so in the access log a verb an agent could not satisfy looks identical to one that worked. On 2026-07-25 four Board Programs (Periscope, Sentinel, Scales, Barfly) each POSTed their propose verb three or four times, persisted nothing, and left their exploration tasks PENDING; the reason was unrecoverable afterwards, from the logs or from the agents' own transcripts. Log error/message/remediate/missing plus the calling agent at envelope_to_response — the one chokepoint every v1 flow and do route returns through. Success envelopes stay silent. --------- Co-authored-by: Renn F <rennf93@users.noreply.github.com>
This commit is contained in:
@@ -68,8 +68,8 @@ async def test_off_mode_ceo_header_spoof_still_works(
|
||||
new=AsyncMock(return_value=(aid, "ceo")),
|
||||
):
|
||||
ctx = await get_agent_context(
|
||||
MagicMock(),
|
||||
MagicMock(),
|
||||
db=MagicMock(),
|
||||
response=MagicMock(),
|
||||
x_agent_id=CEO_AGENT_ID,
|
||||
x_agent_role="ceo",
|
||||
)
|
||||
@@ -89,8 +89,8 @@ async def test_off_mode_developer_header_trust_unchanged(
|
||||
new=AsyncMock(return_value=(aid, "be-dev-1")),
|
||||
):
|
||||
ctx = await get_agent_context(
|
||||
MagicMock(),
|
||||
MagicMock(),
|
||||
db=MagicMock(),
|
||||
response=MagicMock(),
|
||||
x_agent_id="be-dev-1",
|
||||
x_agent_role="developer",
|
||||
x_agent_team="backend",
|
||||
@@ -111,8 +111,8 @@ async def test_on_mode_spoofed_ceo_header_without_token_or_session_401(
|
||||
monkeypatch.setattr(settings, "cloud_auth_enabled", True)
|
||||
with pytest.raises(HTTPException) as exc:
|
||||
await get_agent_context(
|
||||
MagicMock(),
|
||||
MagicMock(),
|
||||
db=MagicMock(),
|
||||
response=MagicMock(),
|
||||
x_agent_id=CEO_AGENT_ID,
|
||||
x_agent_role="ceo",
|
||||
)
|
||||
@@ -127,7 +127,7 @@ async def test_on_mode_no_headers_no_cookie_401(
|
||||
401s without a valid session — never silently falls back to anything."""
|
||||
monkeypatch.setattr(settings, "cloud_auth_enabled", True)
|
||||
with pytest.raises(HTTPException) as exc:
|
||||
await get_agent_context(MagicMock(), MagicMock())
|
||||
await get_agent_context(db=MagicMock(), response=MagicMock())
|
||||
assert exc.value.status_code == _HTTP_401
|
||||
|
||||
|
||||
@@ -154,9 +154,7 @@ async def test_on_mode_valid_session_yields_ceo_context_and_slides_cookie(
|
||||
response = Response()
|
||||
|
||||
ctx = await get_agent_context(
|
||||
db_session,
|
||||
response,
|
||||
roboco_session=token,
|
||||
db=db_session, response=response, roboco_session=token
|
||||
)
|
||||
|
||||
assert ctx.role == AgentRole.CEO
|
||||
@@ -174,7 +172,9 @@ async def test_on_mode_invalid_session_cookie_401(
|
||||
) -> None:
|
||||
monkeypatch.setattr(settings, "cloud_auth_enabled", True)
|
||||
with pytest.raises(HTTPException) as exc:
|
||||
await get_agent_context(db_session, Response(), roboco_session="not-a-real-jwt")
|
||||
await get_agent_context(
|
||||
db=db_session, response=Response(), roboco_session="not-a-real-jwt"
|
||||
)
|
||||
assert exc.value.status_code == _HTTP_401
|
||||
|
||||
|
||||
@@ -192,8 +192,8 @@ async def test_on_mode_agent_hmac_still_works(
|
||||
new=AsyncMock(return_value=(aid, "be-dev-1")),
|
||||
):
|
||||
ctx = await get_agent_context(
|
||||
MagicMock(),
|
||||
MagicMock(),
|
||||
db=MagicMock(),
|
||||
response=MagicMock(),
|
||||
x_agent_id=str(aid),
|
||||
x_agent_role="developer",
|
||||
x_agent_team="backend",
|
||||
@@ -212,8 +212,8 @@ async def test_on_mode_system_self_patch_still_works(
|
||||
monkeypatch.setenv("ROBOCO_AGENT_AUTH_SECRET", _SECRET)
|
||||
token = issue_agent_token(_SYSTEM_AGENT_ID, "system", "")
|
||||
ctx = await get_agent_context(
|
||||
MagicMock(),
|
||||
MagicMock(),
|
||||
db=MagicMock(),
|
||||
response=MagicMock(),
|
||||
x_agent_id=_SYSTEM_AGENT_ID,
|
||||
x_agent_role="system",
|
||||
x_agent_token=token,
|
||||
@@ -228,8 +228,8 @@ async def test_on_mode_forged_agent_token_401(monkeypatch: pytest.MonkeyPatch) -
|
||||
monkeypatch.setenv("ROBOCO_AGENT_AUTH_SECRET", _SECRET)
|
||||
with pytest.raises(HTTPException) as exc:
|
||||
await get_agent_context(
|
||||
MagicMock(),
|
||||
MagicMock(),
|
||||
db=MagicMock(),
|
||||
response=MagicMock(),
|
||||
x_agent_id="be-dev-1",
|
||||
x_agent_role="developer",
|
||||
x_agent_token="forged",
|
||||
@@ -248,8 +248,8 @@ async def test_on_mode_spoofed_non_ceo_role_without_token_401(
|
||||
monkeypatch.setattr(settings, "cloud_auth_enabled", True)
|
||||
with pytest.raises(HTTPException) as exc:
|
||||
await get_agent_context(
|
||||
MagicMock(),
|
||||
MagicMock(),
|
||||
db=MagicMock(),
|
||||
response=MagicMock(),
|
||||
x_agent_id="main-pm",
|
||||
x_agent_role="main_pm",
|
||||
)
|
||||
|
||||
Reference in New Issue
Block a user