feat(fleet): cover agentic consumers and fail on uncovered ones - #48
Merged
Merged
Conversation
The fleet scan only checked repositories listed by hand in repository_expectations. agentic-saga and agentic-context-service pin hseshadr/ci modules but were never listed, so no fleet rule ran on them. - Add both to repository_expectations with the full consumer contract (sole Dagger check, conversation resolution, no rollout exception; both already declare shared foundation). - New fleet_coverage module: list every public hseshadr repository, read its default-branch dagger.json, and report uncovered-consumer for any active repository that pins a github.com/hseshadr/ci module but is missing from the list. Listing or config read errors fail closed. - scan_repository now turns FleetAccessError into an evidence-unreadable finding, so one unreadable repository (agentic-context-service has no branch protection on main) no longer hides every later result. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015oBArfm762nN1r4F4Fst5a
This was referenced Sep 25, 2026
Open
hseshadr
added a commit
that referenced
this pull request
Sep 26, 2026
Brings in #47 -> #48 -> #50 -> #52 so this PR merges last without conflicts. Their README lines move to the new layout: the consumer list (now with agentic-context-service and agentic-saga), the uncovered-consumer failure and the required-minimum pin floor go to docs/ARCHITECTURE.md "What dagger call fleet checks", with plain one-line versions in the README intro. Publisher lineage and the dagger-args-expression rule are noted there too. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015oBArfm762nN1r4F4Fst5a
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Claim touched: the fleet scan covers every repository that consumes
hseshadr/ciDagger modules.Why
The fleet scan only checked repositories listed by hand in
repository_expectations.agentic-sagaandagentic-context-serviceboth pingithub.com/hseshadr/ci/modules/*, but neither was listed. So no fleet rule ran on them: not the pin floor, not the pin format, nothing.What
repository_expectationswith the full consumer contract: soleDaggercheck, conversation resolution, no linear-history requirement, no rollout exception. Both already declare shared foundation, which is why there is no grandfather date. The values come from their livedagger.jsonand branch protection..dagger/src/ci/fleet_coverage.py. Each hosted scan lists every publichseshadrrepo (users/hseshadr/repos, paginated) and reads its default-branchdagger.json. Any active repo that pins agithub.com/hseshadr/cimodule but is not in the list gets anuncovered-consumerfinding, and the scan fails. If the listing or a config read fails with anything other than a 404, the scan fails closed.scan_repositorynow turns aFleetAccessErrorinto anevidence-unreadablefinding. Before this, one unreadable repo aborted the whole scan and hid every result after it. The scan still fails.docs/dagger-modules.md#fleet-coveragesection, plus README and CHANGELOG.This touches
fleet.pyand adds new files only. It does not touchfleet_policy.pyorgithub_fleet.py, so there is no textual overlap with #47. I merged it withfeat/fleet-minimum-pinlocally: 245 passed,poe gateexit 0.Evidence
test_should_cover_every_known_ci_consumer_in_reviewed_expectations:Left contains 2 more items, first extra item: 'agentic-context-service'. The consumer-set test and both expectation tests were also red.uv run poe gateexit 0: 231 passed,fleet.pyandfleet_coverage.pyat 100% line and branch coverage, xenon Aagentic-sagafrom expectationsdagger.jsonhseshadr/ci@and miss module-path pinsagentic-context-service, agentic-saga, almamesh, aml-filter, assay, edge-proc, edge-reco, edgeproc-core, privacy-core, which equalsKNOWN_CONSUMERSNew live findings this surfaces (intended, the scan is meant to fail on them)
branches/main/protectionreturns 404:mainhas no branch protection or ruleset at allsourceis a caller-suppliedci(source=...)argument, not a module-ownedDirectoryfield built fromWorkspaceorDefaultPathBoth are consumer-side fixes. They are tracked separately and are not changed here. The scheduled
Dagger fleet policyrun is already red on main because of edge-proc, edgeproc-core and privacy-core.🤖 Generated with Claude Code
https://claude.ai/code/session_015oBArfm762nN1r4F4Fst5a