Skip to content

PR #652 follow-ups: the third digest fixture (web_app routing class), the standalone-verify stdout lane's dropped attacker_model, and two pinned nits #653

Description

@gadievron

Filed from the merge-side astra deep-refute seat on PR #652's final bytes (approve-with-fixes; the MED and LOWs are bounded residuals, recorded here rather than blocking the merge — the same convention as #646/#648).

1. The digest's third frozen fixture — the web_app routing class (MED)

_builtin_persona_digest_renders / _builtin_context_digest_renders freeze two fixture classes (the all-trusted CLI tool, the untrusted-input library). There is no web_app fixture: a future discriminator/routing edit that moves ONLY the web_app class leaves every digest member unchanged → templates_sha unchanged → a resumed scan adopts verdicts rendered under a superseded routing for web_app contexts — the FN-direction half of exactly the class #621 closed, for the uncovered class. Today's web_app routing (browser persona retained) is behavior-pinned (test_issue621_verification_persona.py:189-196) and the covered classes are mutation-fenced (d4/d5/d6) — the hole is forward-guard coverage only. Fix shape: a third frozen fixture over the web_app class.

2. VerifyResult.to_dict drops attacker_model on the standalone-verify stdout lane (LOW)

schemas.py:410-424 — the build-output/report lanes carry the descriptor (PR #652's claim holds there), but the standalone openant verify stdout lane omits it. Additive present-only; same shape as the #600 discovery precedent.

3. The degenerate class web_app + requires_remote_trigger=False (LOW)

Renders the REMOTE_ONLY persona + a remote_only descriptor that mislabels a web app as a CLI tool/library in the methodology line — honest to the persona, pre-existing type mislabel. Unpinned; worth a fixture row when (1) lands.

4. The stale "ten fields since #302" docstring count (LOW)

The docstring count is stale (11 unconditional keys) — in a function #652 touched (report/schema.py). One-line fix.

5. Records note (not code)

The #652 walk's hunt receipt records the base full-suite run as "4262 / 34 / 15 failed" — irreconcilable with the walk's own disclosed 16 RED rows + 2 pre-existing SDK-pin failures (18 reconciles the collected-totals ledger 4311 vs 4314). The authoring session's receipt-side arithmetic; no code impact.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions