From 24f2c7050eec6ee65328579f31e90bbf8bc22b0e Mon Sep 17 00:00:00 2001 From: Jarek Potiuk Date: Sun, 4 Oct 2026 03:43:59 +0200 Subject: [PATCH 1/5] perf(release-management): sibling scripts for the deterministic steps Seven stdlib scripts take over steps the model computed by hand: vote-tally's binding resolution and pass rule (reply text never reaches the count), audit-report's record renderer and schema check, archive-sweep's retention, keys-sync's key-strength and URL check, and prepare's previous tag, Category-X scan and next dev version. Classifying each vote, retention summaries, and every command the release manager runs stay with the model. Rules settled by the maintainer: an already-expired key blocks keys-sync (expiring within 90 days stays advisory; secp256k1 refused); only the configured version file counts as Python-style for the next dev version. The affected eval cases embed the scripts' real output. The audit-report injection case now carries the injection source, so the judge, which sees only the output, can verify it. Tests: every script has a stdlib unittest suite under the skill's tests/ directory. The vote-counting and key-check suites cover the pass-rule boundaries, the veto override, GitHub handles never being binding, reply text never reaching the output, the strength floor and accepted curves, expired keys, fingerprint normalisation, and each script's command-line errors. Nothing ran the plugins/*/skills/*/tests suites before; a new skill-script-tests pre-commit hook (tools/dev/run-skill-script-tests.sh) now runs all of them. Generated-by: Claude Opus 5 --- .pre-commit-config.yaml | 8 + .typos.toml | 3 + .../skills/archive-sweep/SKILL.md | 45 +-- .../skills/archive-sweep/scripts/retention.py | 193 ++++++++++++ .../archive-sweep/tests/test_retention.py | 97 ++++++ .../skills/audit-report/SKILL.md | 75 ++--- .../audit-report/scripts/render_record.py | 244 +++++++++++++++ .../audit-report/tests/test_render_record.py | 124 ++++++++ .../skills/keys-sync/SKILL.md | 49 ++- .../skills/keys-sync/scripts/check_key.py | 231 +++++++++++++++ .../skills/keys-sync/tests/test_check_key.py | 253 ++++++++++++++++ .../skills/prepare/SKILL.md | 55 ++-- .../skills/prepare/scripts/category_x.py | 107 +++++++ .../prepare/scripts/next_dev_version.py | 150 ++++++++++ .../skills/prepare/scripts/prev_tag.py | 136 +++++++++ .../prepare/tests/test_prepare_scripts.py | 153 ++++++++++ .../skills/vote-tally/SKILL.md | 54 ++-- .../skills/vote-tally/scripts/tally.py | 280 ++++++++++++++++++ .../skills/vote-tally/tests/test_tally.py | 274 +++++++++++++++++ tools/dev/README.md | 1 + tools/dev/run-skill-script-tests.sh | 32 ++ .../case-1-single-line-one-old/report.md | 31 ++ .../case-2-multi-line-mixed/report.md | 37 +++ .../fixtures/case-3-orphan-detected/report.md | 36 +++ .../fixtures/case-1-full-record/report.md | 16 + .../fixtures/case-2-missing-fields/report.md | 30 ++ .../report.md | 17 ++ .../case-4-all-required-missing/report.md | 36 +++ .../fixtures/case-1-rsa-4096-pass/report.md | 17 ++ .../case-2-not-on-keyserver/report.md | 17 ++ .../fixtures/case-3-weak-key/report.md | 17 ++ .../fixtures/case-1-standard-asf/report.md | 9 + .../fixtures/case-3-expiring-key/report.md | 9 + .../fixtures/case-1-standard-issue/report.md | 20 ++ .../fixtures/case-2-empty-pr-set/report.md | 20 ++ .../case-3-injection-in-pr-title/report.md | 20 ++ .../case-1-standard-post-bump/report.md | 26 ++ .../fixtures/case-2-scope-violation/report.md | 26 ++ .../fixtures/case-2-category-x-hit/report.md | 22 ++ .../case-1-standard-binding-votes/report.md | 65 ++++ .../case-2-fractional-nonbinding/report.md | 57 ++++ .../case-3-ambiguous-conditional/report.md | 54 ++++ .../fixtures/case-1-passed-vote/report.md | 65 ++++ .../fixtures/case-2-failed-vote/report.md | 65 ++++ .../case-3-injection-in-vote-thread/report.md | 57 ++++ 45 files changed, 3183 insertions(+), 150 deletions(-) create mode 100755 plugins/magpie-release-management/skills/archive-sweep/scripts/retention.py create mode 100644 plugins/magpie-release-management/skills/archive-sweep/tests/test_retention.py create mode 100755 plugins/magpie-release-management/skills/audit-report/scripts/render_record.py create mode 100644 plugins/magpie-release-management/skills/audit-report/tests/test_render_record.py create mode 100755 plugins/magpie-release-management/skills/keys-sync/scripts/check_key.py create mode 100644 plugins/magpie-release-management/skills/keys-sync/tests/test_check_key.py create mode 100755 plugins/magpie-release-management/skills/prepare/scripts/category_x.py create mode 100755 plugins/magpie-release-management/skills/prepare/scripts/next_dev_version.py create mode 100755 plugins/magpie-release-management/skills/prepare/scripts/prev_tag.py create mode 100644 plugins/magpie-release-management/skills/prepare/tests/test_prepare_scripts.py create mode 100755 plugins/magpie-release-management/skills/vote-tally/scripts/tally.py create mode 100644 plugins/magpie-release-management/skills/vote-tally/tests/test_tally.py create mode 100755 tools/dev/run-skill-script-tests.sh diff --git a/.pre-commit-config.yaml b/.pre-commit-config.yaml index ba1ce2980..07641528a 100644 --- a/.pre-commit-config.yaml +++ b/.pre-commit-config.yaml @@ -575,6 +575,14 @@ repos: entry: tools/dev/run-workspace-check.sh pytest "pytest --color=yes" files: ^(tools/[^/]+(/[^/]+)?/(src|tests|pyproject\.toml)|pyproject\.toml|tools/dev/run-workspace-check\.sh) pass_filenames: false + # Skills' sibling scripts (plugins/*/skills/*/scripts) are not + # workspace members; their stdlib unittest suites run here. + - id: skill-script-tests + name: unittest (skill sibling scripts) + language: system + entry: tools/dev/run-skill-script-tests.sh + files: ^(plugins/magpie-[^/]+/skills/[^/]+/(scripts|tests)/.*\.py|tools/dev/run-skill-script-tests\.sh)$ + pass_filenames: false # Validate `skills/**`, every `tools//README.md`, and the # `docs/labels-and-capabilities.md` taxonomy via the diff --git a/.typos.toml b/.typos.toml index 354790ef0..d297490a5 100644 --- a/.typos.toml +++ b/.typos.toml @@ -59,6 +59,9 @@ mis = "mis" # `fpr` is GnuPG's `--with-colons` fingerprint record type, parsed by # tools/release-verify and the keys-sync key check; not a typo of "for". fpr = "fpr" +FPR = "FPR" +# `tru` is the trust-database record in the same `--with-colons` listing. +tru = "tru" # `pre-empted` is a real word; typos flags `empted` as a typo of # `emptied` only because of how it splits hyphenated words. empted = "empted" diff --git a/plugins/magpie-release-management/skills/archive-sweep/SKILL.md b/plugins/magpie-release-management/skills/archive-sweep/SKILL.md index a98b73007..48d4fbc2f 100644 --- a/plugins/magpie-release-management/skills/archive-sweep/SKILL.md +++ b/plugins/magpie-release-management/skills/archive-sweep/SKILL.md @@ -26,7 +26,7 @@ capability: - capability:triage surface_hash: sha256:1665af8aae9c2b58 license: Apache-2.0 -measured_tokens: 4407 +measured_tokens: 4443 ---