Repository navigation
fix(audit): pass p1-flag-existence only when the help declares a gate flag - #172
Open
brettdavies wants to merge 1 commit into
Open
brettdavies wants to merge 1 commit into
brettdavies wants to merge 1 commit into
Conversation
… flag `p1-flag-existence` searched the whole `--help` text for each non-interactive gate flag, bounded by non-name characters. That stopped `--print-json` from answering for `--print`, but it still passed a flag shown only in a usage line (`Usage: tool [-y] <file>`), in a sentence, or in another flag's wrapped description. It also missed Go `flag` help, where `-batch` is the only spelling printed. The audit now asks the definition query for its gate flags, and `contains_flag` is removed. A single letter such as `-p` or `-y` answers only when declared as that letter, and a single-dash word answers for its double-dash spelling in a help that declares no double-dash name. A warn says what was searched and where: `no option definition in --help declares a non-interactive flag (one of: ...); usage lines are not read.` `run()` and the tests share one core helper. The test-only copy of the audit's logic is gone.
brettdavies
added this pull request to stack #166
October 8, 2026 21:52
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
p1-flag-existenceasks whether a tool that blocks on a bare call advertises a non-interactive gate flag (--no-interactive,--batch,-y,--yes,-p,--printand four more). It searched the whole--helptext for each one, bounded by non-name characters. The bound stopped--print-jsonfrom answering for--print, but the search still passed a flag that the help only mentions:Usage: tool [-y] [--batch] <file>Run with --no-input in CI.It also missed Go
flaghelp, where-batchis the only spelling printed.The audit now asks the definition query for its gate flags, and
contains_flagis removed.-pand-yanswer only when declared as those letters. A single-dash word answers for its double-dash spelling in a help that declares no double-dash name, and beside double-dash names the warn says why it does not count. A warn names what was searched and where.The audit's flag list is unchanged. So is the skip for a target that prints usage or exits on a bare call, which is why most tools never reach the lookup.
Changelog
Fixed
p1-flag-existencepassing when a non-interactive flag such as-yor--batchappears only in a usage line, a sentence, or another flag's description. It passes when an option definition declares one.p1-flag-existencemissing a gate flag in Goflaghelp, where-batchis printed with one dash.Changed
p1-flag-existencewarn evidence now readsno option definition in --help declares a non-interactive flag (one of: ...); usage lines are not read.Type of Change
fix: Bug fix (non-breaking change which fixes an issue)Related Issues/Stories
docs/plans/2026-10-06-0034-fix-help-flag-names-across-frameworks-plan.md(unit U10, theflag_existence.rsPR)p7-quiet), fix(audit): match a declared confirm flag against the definitions the help declares #170, fix(audit): find flag definitions at column 0, in box tables, and behind brackets #169, fix(audit): stop reading wrapped description lines as flag definitions #168, fix(audit): read names from a second column and descriptions after a marker #167, fix(audit): read every flag name a help declares whole #165, refactor(audit): look flags up through one model and one query #164, test(audit): pin what the flag parser reads from a capture of every help layout #163, feat(docker/score): compare two anc builds over the registry in one pinned image agentnative-site#455 (the corpus harness)Testing
Test Summary:
flag_existence.rs, all through the helperrun()calls.contains_flag's boundary cases carry over as negatives against the query (--print-jsonand--batchingare not--printand--batch;-pris not-p), beside the usage-line, sentence and wrapped-description cases. A Go-style-batchpasses in a help with no double-dash name. A find-style help that declares--helpbeside-printwarns and says-printdoes not count as--print. The warn evidence is asserted whole.cargo test --test dogfoodpasses.Negatives observed failing. The new tests, run against the base (#171) with the audit restructured around one helper and
contains_flagstill doing the match:The boundary cases (
--print-json,--batching,-pr) passed at the base, as the old matcher already rejected them.Expected moves. Written before the corpus run. Two rows, evidence only:
p1-must-no-interactivep1-flag-existenceno non-interactive flag found in --help; expected one of: ...to the search-scope sentencep1-must-no-interactivep1-flag-existenceNo status moves, so no derived field moves. How the prediction was made:
human-tuiprofile. The flag lookup runs for datasette and opencode alone, whose bare calls block.--helpand hang on a bare call, audited with the base and head builds: both warn under both builds, with the old and new evidence.p1-flag-existenceis not one of the fouraudiencesignals and is no row's antecedent.Corpus before/after. Run after the table above was written. Base
682c69ed3ac3, head972b5b34f5aa. Imagesha256:05db16cf226cd14a93a2682aea41b72d3e6b4d240cadba006f2881d3ffa996b3, networkbridge. 98 tools selected, 95 scored under both builds, 3 rerun three times (datasette, mods, opencode).Moved rows (2)
p1-must-no-interactivep1-flag-existencehead: no option definition in --help declares a non-interactive flag (one of: --no-interactive, --non-interactive, -p, --print, --no-input, --batch, --headless, -y, --yes, --assume-yes); usage lines are not read.
p1-must-no-interactivep1-flag-existencehead: no option definition in --help declares a non-interactive flag (one of: --no-interactive, --non-interactive, -p, --print, --no-input, --batch, --headless, -y, --yes, --assume-yes); usage lines are not read.
Derived fields moved (0)
None.
The two moved rows are the two expected, evidence only, and no derived field moved. Each returned the same result in all four runs of each build. No row is unstable, no harness bug is flagged, and no tool failed to score under one build only.
modsp3-should-about-long-about, the one row on the A/A noise list, is reported as noise: both builds returned pass and warn for it (base runs pass, warn, warn, warn; head runs pass, warn, pass, pass). The row compares the tool's-hand--helpoutput and reads no flag.cursor,nvidia-smiandxai-grok-buildare absent from the image and ran under neither build.Files Modified
Modified:
src/audits/behavioral/flag_existence.rs:audit_flag_existenceasks the definition query and is the helperrun()calls;contains_flagand the test-only copy of the audit removed.Created:
Renamed:
Deleted:
Breaking Changes
Two registry rows carry new evidence text. The scorecard schema and JSON shape are unchanged.
Deployment Notes
Checklist