fix(gateway): bounded fail-open evidence assembly + PM decision transient-failure bypass

Evidence-assembly git legs (diff, changed-files, branch fetch, advisory
conventions run) ran unbounded inside claim_review / claim_doc_task /
claim_gate_review / evidence() / i_am_done's envelope build, so a slow
clone turned the whole verb into a silent 120s FlowVerbTimeout 504.
Each leg now runs through run_bounded_leg under a shared LegBudget
(evidence_assembly_timeout_seconds, 45s total): a timed-out leg — both
asyncio TimeoutError and git's own GitTimeoutError — degrades into an
evidence_gaps note on the envelope instead of hanging the verb, while
non-timeout git errors still propagate. The advisory conventions run
gets an inner-only timeout (conventions_validator_advisory_timeout_
seconds, 30s) threaded down to the subprocess so it is never orphaned
by an outer cancel; the fail-closed i_am_done/pr_pass conventions
gates keep their hardcoded 120s.

_ensure_pm_decision now reports a PmDecisionOutcome: a transient DB
failure recording the PM's decision journal (e.g. lock timeout under
load) no longer launders into a journal:decision gate rejection that
escalates and BLOCKS the task — the verb's own rationale satisfies the
gate with a structured warning, across all seven PM verbs.

Also: repo-wide ruff realignment to the lockfile-pinned ruff (8
format-only diffs, 14 UP038 isinstance conversions) that a transiently
newer venv ruff had masked.

Gate: 15474 passed, 459 skipped; ruff/mypy/xenon/vulture/bandit/
pip-audit/deptry/import-linter/foundation-check all green.
This commit is contained in:
Renn F
2026-07-31 13:56:19 +02:00
parent ef8849b0cd
commit ce4d02b3c2
41 changed files with 2160 additions and 138 deletions
@@ -31,7 +31,12 @@ async def test_findings_surfaced_when_flag_on(monkeypatch: pytest.MonkeyPatch) -
monkeypatch.setattr(settings, "conventions_enabled", True)
findings = [{"file": "x.py", "line": 1, "level": "warn", "fix_hint": "h"}]
c = _make_choreographer(check_result={"findings": findings, "could_not_run": False})
assert await c._qa_convention_findings(uuid4(), MagicMock()) == findings
gaps: list[str] = []
assert (
await c._qa_convention_findings(uuid4(), MagicMock(), timeout=30.0, gaps=gaps)
== findings
)
assert gaps == []
@pytest.mark.asyncio
@@ -40,21 +45,32 @@ async def test_empty_when_flag_off(monkeypatch: pytest.MonkeyPatch) -> None:
c = _make_choreographer(
check_result={"findings": [{"file": "x"}], "could_not_run": False}
)
assert await c._qa_convention_findings(uuid4(), MagicMock()) == []
gaps: list[str] = []
assert (
await c._qa_convention_findings(uuid4(), MagicMock(), timeout=30.0, gaps=gaps)
== []
)
assert gaps == []
@pytest.mark.asyncio
async def test_could_not_run_surfaced_as_single_entry(
monkeypatch: pytest.MonkeyPatch,
) -> None:
"""A non-timeout could_not_run reason ("boom") stays fail-open in
convention_findings but must NOT also spam evidence_gaps — only a
detected timeout does (see test_claim_review_conventions_timeout_
degrades_with_gap in test_evidence_assembly_bounded_legs.py)."""
monkeypatch.setattr(settings, "conventions_enabled", True)
c = _make_choreographer(
check_result={"findings": [], "could_not_run": True, "reason": "boom"}
)
out = await c._qa_convention_findings(uuid4(), MagicMock())
gaps: list[str] = []
out = await c._qa_convention_findings(uuid4(), MagicMock(), timeout=30.0, gaps=gaps)
assert len(out) == 1
assert out[0]["could_not_run"] is True
assert out[0]["reason"] == "boom"
assert gaps == []
def _stub_task() -> MagicMock: