Skip to content

feat(fleet): cover agentic consumers and fail on uncovered ones - #48

Merged
hseshadr merged 2 commits into
mainfrom
feat/fleet-coverage
Sep 27, 2026
Merged

hseshadr merged 2 commits into
mainfrom
feat/fleet-coverage

Conversation

@hseshadr

Copy link
Copy Markdown
Owner

Claim touched: the fleet scan covers every repository that consumes hseshadr/ci Dagger modules.

Why

The fleet scan only checked repositories listed by hand in repository_expectations. agentic-saga and agentic-context-service both pin github.com/hseshadr/ci/modules/*, but neither was listed. So no fleet rule ran on them: not the pin floor, not the pin format, nothing.

What

  • Both repos are added to repository_expectations with the full consumer contract: sole Dagger check, conversation resolution, no linear-history requirement, no rollout exception. Both already declare shared foundation, which is why there is no grandfather date. The values come from their live dagger.json and branch protection.
  • New .dagger/src/ci/fleet_coverage.py. Each hosted scan lists every public hseshadr repo (users/hseshadr/repos, paginated) and reads its default-branch dagger.json. Any active repo that pins a github.com/hseshadr/ci module but is not in the list gets an uncovered-consumer finding, and the scan fails. If the listing or a config read fails with anything other than a 404, the scan fails closed.
  • scan_repository now turns a FleetAccessError into an evidence-unreadable finding. Before this, one unreadable repo aborted the whole scan and hid every result after it. The scan still fails.
  • Docs: the docs/dagger-modules.md#fleet-coverage section, plus README and CHANGELOG.

This touches fleet.py and adds new files only. It does not touch fleet_policy.py or github_fleet.py, so there is no textual overlap with #47. I merged it with feat/fleet-minimum-pin locally: 245 passed, poe gate exit 0.

Evidence

Check Result
RED (guard) test_should_cover_every_known_ci_consumer_in_reviewed_expectations: Left contains 2 more items, first extra item: 'agentic-context-service'. The consumer-set test and both expectation tests were also red.
GREEN uv run poe gate exit 0: 231 passed, fleet.py and fleet_coverage.py at 100% line and branch coverage, xenon A
M1: drop agentic-saga from expectations 3 red
M2: scan skips coverage results 1 red (hosted-scan wiring test)
M3: fail open on an unreadable dagger.json 1 red
M4: include archived repos 2 red
M5: stop after the first listing page 1 red
M6: match only hseshadr/ci@ and miss module-path pins 3 red
M7: abort the scan on an unreadable repo 2 red
Live discovery (read-only) exactly agentic-context-service, agentic-saga, almamesh, aml-filter, assay, edge-proc, edge-reco, edgeproc-core, privacy-core, which equals KNOWN_CONSUMERS

New live findings this surfaces (intended, the scan is meant to fail on them)

Repo Code Detail
agentic-context-service evidence-unreadable branches/main/protection returns 404: main has no branch protection or ruleset at all
agentic-saga explicit-source source is a caller-supplied ci(source=...) argument, not a module-owned Directory field built from Workspace or DefaultPath

Both are consumer-side fixes. They are tracked separately and are not changed here. The scheduled Dagger fleet policy run is already red on main because of edge-proc, edgeproc-core and privacy-core.

🤖 Generated with Claude Code

https://claude.ai/code/session_015oBArfm762nN1r4F4Fst5a

The fleet scan only checked repositories listed by hand in
repository_expectations. agentic-saga and agentic-context-service pin
hseshadr/ci modules but were never listed, so no fleet rule ran on them.

- Add both to repository_expectations with the full consumer contract
  (sole Dagger check, conversation resolution, no rollout exception;
  both already declare shared foundation).
- New fleet_coverage module: list every public hseshadr repository, read
  its default-branch dagger.json, and report uncovered-consumer for any
  active repository that pins a github.com/hseshadr/ci module but is
  missing from the list. Listing or config read errors fail closed.
- scan_repository now turns FleetAccessError into an evidence-unreadable
  finding, so one unreadable repository (agentic-context-service has no
  branch protection on main) no longer hides every later result.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015oBArfm762nN1r4F4Fst5a
hseshadr added a commit that referenced this pull request Sep 26, 2026
Brings in #47 -> #48 -> #50 -> #52 so this PR merges last without
conflicts. Their README lines move to the new layout: the consumer list
(now with agentic-context-service and agentic-saga), the uncovered-consumer
failure and the required-minimum pin floor go to docs/ARCHITECTURE.md
"What dagger call fleet checks", with plain one-line versions in the README
intro. Publisher lineage and the dagger-args-expression rule are noted there too.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015oBArfm762nN1r4F4Fst5a
@hseshadr
hseshadr merged commit d2edf2c into main Sep 27, 2026
3 checks passed
@hseshadr
hseshadr deleted the feat/fleet-coverage branch September 27, 2026 22:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant