Skip to content

test(release-verify-rc): grade Step 6b paste recipes by their rules, not one reference text - #1536

Merged
potiuk merged 1 commit into
apache:mainfrom
potiuk:fix-6b-eval-grading
Oct 5, 2026
Merged

potiuk merged 1 commit into
apache:mainfrom
potiuk:fix-6b-eval-grading

Conversation

@potiuk

@potiuk potiuk commented Oct 5, 2026

Copy link
Copy Markdown
Member

Summary

  • The release-verify-rc Step 6b eval suite flaked 1–2 of 6 cases on paste_recipe, on main as well: the grader compared each candidate recipe with one reference recipe word for word, so correct answers failed for quoting the gpg --verify arguments differently or for adding the companion verification lines.
  • The exact paste_recipe values are replaced by structural checks in a new assertions.json that encode the output-spec rule: the recipe invokes maven-artifact-verify on the staged directory, sets --digests sha512, and passes --podling only when the source artefact ships a DISCLAIMER. Every original reference recipe satisfies them.
  • Same treatment the Step 6c suite got in feat(tools): add asf-nexus and wire Nexus staging check into verify-rc #1505.

Type of change

  • Skill change (.claude/skills/<name>/) — eval fixtures updated below
  • Tool / bridge contract (tools/<system>/*.md)
  • Python package (tools/*/ with pyproject.toml)
  • Groovy reference impl
  • Cross-cutting (RFC, AGENTS.md, sandbox, privacy-LLM)
  • Documentation (docs/, README.md, CONTRIBUTING.md)
  • Project template (projects/_template/)
  • CI / dev loop (prek, workflows, validators)
  • Other: eval fixtures only (tools/skill-evals/evals/release-verify-rc/step-6b-jvm-artefacts/)

Test plan

  • Every original reference paste_recipe satisfies the new has_* checks (checked with the runner's own evaluate_deterministic_assertion)
  • Step 6b suite with claude -p: 6/6 (a first run was 5/6 only because the grader returned no verdict for the prose observations field — unrelated to paste_recipe)
  • Baseline on main before this change: 5/6, failing case-5 on paste_recipe exactness
  • Pre-commit hooks pass

RFC-AI-0004 compliance

No principle touched — eval fixtures only.

Linked issues

Follow-up to #1505.


Generated-by: Claude Opus 5 (assisted; reviewed by the PR author)

🤖 Generated with Claude Code

…not one reference text

The Step 6b suite flaked 1-2 of 6 cases on `paste_recipe`, on `main` too:
the grader compared each candidate recipe with one reference recipe word
for word, so correct answers failed for quoting the `gpg --verify`
arguments differently or for adding the companion verification lines.

Replace the exact `paste_recipe` in every case with structural checks in
a new `assertions.json`, encoding the output-spec rule: the recipe invokes
`maven-artifact-verify` on the staged directory, sets `--digests sha512`
(the digest set every case configures), and passes `--podling` only when
the source artefact ships a `DISCLAIMER`. Every original reference recipe
satisfies them. Same treatment as the Step 6c suite in apache#1505.

Generated-by: Claude Opus 5
@github-actions github-actions Bot added capability:triage Sweep + classify + propose disposition family:release-management release-* skills labels Oct 5, 2026
@potiuk
potiuk merged commit 6c1f38c into apache:main Oct 5, 2026
10 checks passed
potiuk added a commit that referenced this pull request Oct 6, 2026
#1542)

* test(release-verify-rc): grade step 2/3/6 paste recipes by their rules

The last three release-verify-rc suites still grade `paste_recipe`
against one reference recipe: Step 2 (signatures), Step 3 (checksums)
and Step 6 (binary exclusion). Correct answers fail for quoting the
gpg arguments differently, importing the already-downloaded KEYS file,
passing `-c` for `--check`, or splitting the binary scan across several
find calls, while the step only requires properties of the recipe.

Replace the exact `paste_recipe` in every case with structural checks
in a new `assertions.json`, encoding the output-spec rules: Step 2 - a
gpg key import and a `gpg --verify` of the staged `.asc` signatures;
Step 3 - `sha512sum`/`sha256sum` in check mode (`-c` accepted for
`--check`); Step 6 - a `find` whose globs cover the eight-entry fixed
baseline. Every original reference recipe satisfies them.

Same treatment as the Step 6c suite in PR #1505 and the Step 6b suite
in PR #1536.

Generated-by: ZCode (GLM-5.3-Flash)

* test(release-verify-rc): accept looped and wrapped gpg --verify in step 2

has_sig_verify required `--verify` and `.asc` on one line in that order,
so a `for f in *.asc; do gpg --verify "$f"; done` loop or a
backslash-continued `gpg --verify` still failed. Check the verify call
and the `.asc` signature as two separate assertions.

Generated-by: Claude Opus 5

---------

Co-authored-by: Jarek Potiuk <potiuk@apache.org>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

capability:triage Sweep + classify + propose disposition family:release-management release-* skills

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant