Merge main after Job Queue sample link fix

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 76eb42c4-2acd-4f9c-a898-f4a44f9d46f7
This commit is contained in:
dayland 2026-09-15 09:34:05 +02:00
commit 0a018fd9fb
48 changed files with 1145 additions and 49 deletions

View file

@ -167,13 +167,49 @@ AL source is the common failure case. Quoted identifiers (for example `Rec."No."
### Consumer acceptance gate
The exact action-skill return is the primary report transport. Before accepting
it as a findings-report, a coordinator or host MUST validate it
deterministically:
Capture the exact Task return as the immutable raw audit payload and primary
transport. Preserve it unchanged in private run artifacts or host logs before
creating any derived value. The accepted findings-report is either that exact
return or the bounded normalized candidate described below; the raw audit
payload never changes.
1. Parse the exact return as strict JSON and validate every required field,
enum, type, conditional requirement, summary count, coverage value, and
leaf/super-skill constraint against this output contract.
Before the full acceptance gate, a coordinator MAY create a normalized
candidate copy only through this deterministic procedure:
1. Parse the exact return as strict JSON and provisionally check the complete
report without mutating it. Every acceptance rule below MUST already pass
except for one or more findings whose optional `location.range` has
`start-line != line`.
2. Each such finding is eligible only when `location.line`,
`location.range.start-line`, and `location.range.end-line` are positive
integers, `start-line <= line <= end-line`, and the finding does not contain
the `suggested-code` field. Field presence disqualifies normalization even
if its value is empty because suggested code may be bound to the reported
range.
3. Deep-copy the complete parsed report. In the candidate copy, remove only
`location.range` from every eligible finding. Retain `location.line` and
every other value unchanged. Do not add normalization metadata to the
findings-report.
4. Record each removed range separately in private run telemetry or artifacts,
associated with the immutable raw audit payload. This record is
runner-owned and is not part of the declared report schema.
5. Validate the entire normalized candidate with the existing full consumer
acceptance gate below. Only a candidate that passes every rule becomes the
accepted copy used for rollup. If any other validation defect exists, or
full validation fails, discard the candidate, preserve the raw payload, and
fail the complete leaf as before.
This exception does not infer missing fields, alter references or paths, clamp
line numbers, repair JSON, normalize a reversed or out-of-bounds range, remove
a range from a finding containing `suggested-code`, or salvage arbitrary
individual findings.
Before accepting either the exact return or an eligible normalized candidate
as a findings-report, a coordinator or host MUST validate it deterministically:
1. Validate every required field, enum, type, conditional requirement, summary
count, coverage value, and leaf/super-skill constraint against this output
contract.
2. For every knowledge-backed finding, verify each `references[].path` is an
exact repo-relative knowledge path that exists in the live BCQuality
snapshot, and verify `findings[].id` exactly equals
@ -189,11 +225,10 @@ deterministically:
Validation failure invalidates the complete return; consumers MUST NOT salvage
individual findings, infer missing fields, reconstruct JSON, clamp ranges,
rewrite paths, or otherwise silently repair model output. Preserve the invalid
raw payload unchanged in private run artifacts or host logs. Record a separate
failed validation result for that leaf with no findings, and derive the
super-skill outcome as `partial` or `failed` using the normal rollup rules.
Worker-side report-file persistence is optional and never replaces validation
of the exact return.
raw payload unchanged. Record a separate failed validation result for that leaf
with no findings, and derive the super-skill outcome as `partial` or `failed`
using the normal rollup rules. Worker-side report-file persistence is optional
and never replaces validation of the accepted exact or normalized copy.
### Field semantics