mirror of
https://github.com/microsoft/BCQuality.git
synced 2026-10-06 07:06:54 +01:00
Harden findings-report producer constraints (#218)
Reject fragment-bearing finding IDs and cap uncited confidence and severity in the shared schema. Require final-source verification before emission and cover leaf/root compatibility and fail-closed source bounds. Co-authored-by: wenjiefan <wenjiefan@microsoft.com> Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
This commit is contained in:
parent
4cd53eac64
commit
7726d5d8d8
3 changed files with 153 additions and 5 deletions
24
skills/do.md
24
skills/do.md
|
|
@ -128,8 +128,8 @@ source-scope locations, and article-body retrieval.
|
|||
"message": "string",
|
||||
"location": {
|
||||
"file": "string",
|
||||
"line": 0,
|
||||
"range": { "start-line": 0, "end-line": 0 }
|
||||
"line": 1,
|
||||
"range": { "start-line": 1, "end-line": 1 }
|
||||
},
|
||||
"references": [
|
||||
{ "path": "string", "sha": "string" }
|
||||
|
|
@ -165,6 +165,26 @@ The emitted document MUST be strict, valid JSON per [RFC 8259](https://www.rfc-e
|
|||
|
||||
AL source is the common failure case. Quoted identifiers (for example `Rec."No."`) and multi-line snippets routinely appear in `message`, `suggested-code`, and `suggested-code-omission-reason`, and each embedded quote or newline MUST be escaped when placed in a string value. A `suggested-code` payload that spans several lines is a single JSON string with `\n` separators, not a literal multi-line block. Emit the document as one JSON value with no trailing commentary, and do not rely on the consumer to repair unescaped output.
|
||||
|
||||
### Producer pre-emission checklist
|
||||
|
||||
Before emitting each leaf report or super-skill rollup:
|
||||
|
||||
1. Copy every citation-based `findings[].id` verbatim from
|
||||
`references[0].path`, with no `#` fragment or other suffix. Apply the
|
||||
reference-integrity gate below.
|
||||
2. For `references: []`, emit only `confidence: "medium"` or `"low"` and
|
||||
`severity: "minor"` or `"info"`. Preserve the role-specific agent ID
|
||||
prefixes defined below.
|
||||
3. Open the final source snapshot for every `location.file`. Verify `line`
|
||||
and any inclusive range bounds are 1-based final-file line numbers within
|
||||
that file's length, never diff/patch-relative line numbers. If the source
|
||||
snapshot cannot be verified, return `outcome: "failed"` with an
|
||||
`outcome-reason`, not unverified locations.
|
||||
|
||||
Validate the complete document against the schema and semantic rules before
|
||||
returning it. Consumers MUST NOT strip ID suffixes, downgrade agent findings,
|
||||
or clamp locations to make an invalid report pass the acceptance gate.
|
||||
|
||||
### Consumer acceptance gate
|
||||
|
||||
Capture the exact Task return as the immutable raw audit payload and primary
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue