Repository navigation
fix: preserve analyzer source identities and locked local packages - #27
ifuri-validator-agent[bot] merged 2 commits into
Conversation
Co-authored-by: Koru Agent <agent@coru.dev>
Co-authored-by: Koru Agent <agent@coru.dev>
There was a problem hiding this comment.
Validator approval after policy checks for exact head 18691f504e182c088a5e6ec1c4f05f9b28db6a8f.
Ticket: PLF-212
Correlation ID: local-semcod-code2llm-pr-27-PLF-212
Model: openai/cursor-auto
Reviewed diff chunks: 2
Advisory LLM verdict: APPROVE
Advisory summary: Reviewed all 2 diff chunk(s). The PR correctly addresses module name collisions by assigning deterministic, path-based hashed identities when aliases share a logical import name. Cache validity conditions have been updated to check these resolved names, preventing silent overwrites. New comprehensive tests verify both collision handling and cache invalidation. Monorepo dependencies (code2graph, code2toon, code2flow, code2llm-rust) are correctly added via uv workspace sources and accurately locked. | This diff chunk modifies the uv.lock file to bind the local monorepo package code2toon as an editable source, consistent with the PR body description about binding existing monorepo packages.
Advisory findings: none
The LLM output above is advisory and was not used as the approval trust root.
Semantic review prerequisite: not_required; policy 676cb4516bbfed2a000e40b9b1b6e4a430ecc761ec546aeb53d721a1905cfdd7.
Actual PR impact radar
Exact range: 3aecce74b6838d5f493a34a7d4c4f9ca14558383...18691f504e182c088a5e6ec1c4f05f9b28db6a8f
Change digest: 3a9031bf35396b7e3106472161c081e83079bddba8ea2a73ec7b7fa199c28247
Score: 76/100 (L), estimated 103 min, split recommended: true
Affected services/components: repository-wide/unclassified
Machine-readable radar JSONL and SVG
{"actual_change":{"additions":172,"base_sha":"3aecce74b6838d5f493a34a7d4c4f9ca14558383","binary_files":0,"categories":{"code":2,"configuration":1,"tests":1},"change_digest":"3a9031bf35396b7e3106472161c081e83079bddba8ea2a73ec7b7fa199c28247","comparison":"3aecce74b6838d5f493a34a7d4c4f9ca14558383...18691f504e182c088a5e6ec1c4f05f9b28db6a8f","deletions":6,"file_count":4,"files":["code2llm/core/analyzer.py","pyproject.toml","tests/test_analyzer.py","uv.lock"],"head_sha":"18691f504e182c088a5e6ec1c4f05f9b28db6a8f","service_count":0,"services":[]},"assessment_mode":"observed-pr","axes":{"coupling":5,"delivery":4,"scope":5,"uncertainty":3,"validation":2},"complexity":"L","confidence":0.9,"diagnostics":["RADAR-ACCEPTANCE-MISSING","RADAR-BUDGET-EXCEEDED"],"estimate":{"budget_minutes":30,"minutes":103,"within_budget":false},"impact":{"components":["File","add","code2llm","focused","repository-root","retains178","symbols","tests","than175"],"files":["File/package","add/remove","code2llm/core/analyzer.py","focused/cache","pyproject.toml","retains178/178","symbols/CFG","tests/test_analyzer.py","than175/178","uv.lock"],"public_interfaces":[],"runtime_dependencies":1},"schema":"subactor.ticket-radar/v1","score":76,"split":{"parts":[{"estimated_minutes":11,"name":"Implement File","scope":["File"]},{"estimated_minutes":11,"name":"Implement add","scope":["add"]},{"estimated_minutes":11,"name":"Implement code2llm","scope":["code2llm"]},{"estimated_minutes":11,"name":"Implement focused","scope":["focused"]},{"estimated_minutes":11,"name":"Implement repository-root","scope":["repository-root"]},{"estimated_minutes":15,"name":"Validate and project to trackers","scope":["tests","planfile","github/gitlab/jira projections"]}],"reason":"estimated_minutes_exceed_budget","recommended":true},"standards":[{"id":"wellmanifest/dsl","revision":"6c60fc4e0dd1f1bb74f46a7745e28019908d1203","version":"0.1.0-dev"},{"id":"wellmanifest/ticket-lifecycle","revision":"5bf581907a87b46a13a73e6c033d3abe4d9a306f","version":"0.1.0-dev"},{"id":"wellmanifest/git-lifecycle","revision":"7d77d4b7af57e69bc75c3a0290b3a4805c5c4438","version":"0.2.0-dev"},{"id":"wellmanifest/logs","revision":"48c284ef7a069055c0bcb6b900147ce5e65f8b43","version":"0.3.0"}],"ticket_ref":"PLF-212"}<svg xmlns="http://www.w3.org/2000/svg" width="128" height="128" viewBox="0 0 128 128" role="img"><title>PLF-212: fix: preserve analyzer source identities and locked local packages</title><rect width="128" height="128" rx="12" fill="#f8fafc"/><g stroke-width="1"><polygon points="64,55 72,61 69,71 59,71 56,61" fill="none" stroke="#d7dde5"/><polygon points="64,47 80,59 74,78 54,78 48,59" fill="none" stroke="#d7dde5"/><polygon points="64,38 89,56 79,85 49,85 39,56" fill="none" stroke="#d7dde5"/><polygon points="64,30 97,53 84,92 44,92 31,53" fill="none" stroke="#d7dde5"/><polygon points="64,21 105,51 89,99 39,99 23,51" fill="none" stroke="#d7dde5"/><line x1="64" y1="64" x2="64" y2="21" stroke="#aab4c0"/><line x1="64" y1="64" x2="105" y2="51" stroke="#aab4c0"/><line x1="64" y1="64" x2="89" y2="99" stroke="#aab4c0"/><line x1="64" y1="64" x2="39" y2="99" stroke="#aab4c0"/><line x1="64" y1="64" x2="23" y2="51" stroke="#aab4c0"/></g><polygon points="64,21 105,51 79,85 54,78 31,53" fill="#fb923c" fill-opacity="0.45" stroke="#c2410c" stroke-width="2"/><circle cx="64" cy="64" r="3" fill="#c2410c"/><g font-family="sans-serif" font-size="7" fill="#334155"><text x="64" y="11" text-anchor="middle">SCO</text><text x="114" y="48" text-anchor="middle">COU</text><text x="95" y="107" text-anchor="middle">UNC</text><text x="33" y="107" text-anchor="middle">VAL</text><text x="14" y="48" text-anchor="middle">DEL</text></g><text x="64" y="124" text-anchor="middle" font-family="sans-serif" font-size="8" fill="#0f172a">L · 103m</text></svg>DECISION D-212-4060
TICKET PLF-212
HEAD_SHA 18691f504e182c088a5e6ec1c4f05f9b28db6a8f
CORRELATION_ID local-semcod-code2llm-pr-27-PLF-212
ACTOR agent:ifuri-validator-agent[bot]
APPLIED_RULE P-CORE-015
INPUT author_login = "tom-sapletta-com"
INPUT observed_checks = ["test (3.13)=PASS","test (3.10)=PASS","freshness=PASS"]
INPUT required_checks = ["test (3.10)","test (3.13)"]
INPUT required_checks_source = "protected registry (env/request)"
INPUT reviewer_login = "ifuri-validator-agent[bot]"
INPUT semantic_review_assessment = {"schema":"subactor.validator/semantic-review-assessment/v1","subject":{"repository":"semcod/code2llm","pull_request":27,"head_sha":"18691f504e182c088a5e6ec1c4f05f9b28db6a8f","base_sha":"3aecce74b6838d5f493a34a7d4c4f9ca14558383","diff_sha256":"9f5d20edb8579efe96a5de4c65ab3cb1ef7f7039ec0bd3e86a58059e8ec78958"},"policy":{"policy_schema":"subactor.validator/semantic-review-policy/v1","policy_version":1,"policy_sha256":"676cb4516bbfed2a000e40b9b1b6e4a430ecc761ec546aeb53d721a1905cfdd7","required":false,"critical_paths":[],"observed_paths":["code2llm/core/analyzer.py","pyproject.toml","tests/test_analyzer.py","uv.lock"]},"grounding":"full-diff-not-per-finding-proof","execution_authority":false,"status":"not_required","reason":null,"review_sha256":null,"unresolved":[]}
INPUT superseded_checks = []
INPUT ticket_radar_receipt = {"schema":"subactor.ticket-radar/v1","base_sha":"3aecce74b6838d5f493a34a7d4c4f9ca14558383","head_sha":"18691f504e182c088a5e6ec1c4f05f9b28db6a8f","change_digest":"3a9031bf35396b7e3106472161c081e83079bddba8ea2a73ec7b7fa199c28247","score":76,"complexity":"L","estimated_minutes":103,"split_recommended":true,"services":[],"authority":"ADVISORY","promotion":"FORBIDDEN"}
VERDICT APPROVE AUTHORITY DETERMINISTIC
REJECTED REQUEST_CHANGES BECAUSE NO_UNSAFE_CHANGE_REASON_FOUND
ADVISORY llm_verdict = "APPROVE" MODEL "openai/cursor-auto"
ASSERT VERDICT_AUTHORITY != "ADVISORY"
File/package aliases sharing a logical module name silently overwrote modules, symbols and CFG identities. Assign deterministic source identities to collisions on both walkers, preserve unique names, and refresh warm caches when a sibling changes identity. The required locked CI installation also referenced unpublished local packages; bind the four existing monorepo packages through uv sources and reconcile the lock without upgrading unrelated dependencies.
Validation:358 full tests passed on each isolated locked Python3.10 and3.13 environment, including the Rust backend;51 focused/cache tests passed. Before-fix fixtures lose source identities; corrected actual Planfile analysis retains178/178 modules, rather than175/178. Tests cover walker order, reserved natural names, symbols/CFG ownership and cache add/remove behavior. Existing lint findings remain unchanged.
NativePLF-212; operationalPLF-130 andPLF-131. Required test (3.10) and test (3.13) checks remain mandatory; no CI workflow, policy, PyPI release or production analyzer pin update. Fresh protected Validator approval is required for the final HEAD.