Repository navigation
feat(plan): growth guards, trim enforcement, and contract slimming - #154
Merged
Merged
Conversation
Oracle pre-write byte-estimate rule and bounded Smith loop (max 3 iterations, removals-only past 90 percent of cap). plan-write-guard refuses consecutive growing over-cap writes with trim_required while still persisting shrinking writes. QA guidance externalized to docs/plan-qa-scenarios.md; Must NOT do and Parallelization optional. ONE PLAN doctrine and Branch 3 unchanged.
Resolves conflicts after PR 153 merge: keeps configurable cap plumbing, unifies the duplicated resolvePlanCap seam into the config-based resolver, and threads the resolved cap through trim_required diagnostics. Full CI 7/7 green.
102400 proved too tight in practice (Ariadne review plan stalled at 102307 bytes). 140000 was chosen over 128000 because 128000 already denotes the unrelated non-Anthropic context fallback in src/, which would have tripped the single-cap-literal locked test. Over-cap test fixtures moved from 120000 to 150000 to stay above the new cap.
The review ceiling introduced for this branch conflated two different
things and produced a loop that neither improved plans nor bounded burn.
Three defects:
1. Off-by-one. Rule 3 said "third rejection -> fix and resubmit" while the
fence was `round <= 3`, so round 3's fixes were never re-reviewed. The
delivered plan was an un-reviewed rejected revision presented as passed.
2. A fixed round count is the wrong stopping rule. Rounds are only worth
spending while they are still finding new problems. The loop now exits
on convergence - a round that introduces no new issue category - with the
ceiling demoted to pure burn control.
3. The SIZE GATE instructed *Smith's verdicts* to demand removals-only.
Smith is a separate agent with no plan-byte context and cannot honor it,
and enforcement already lives in plan-write-guard as `trim_required`.
That sentence is removed; the Oracle-side half is kept.
Four exits are now distinguished instead of one implicit bound:
OKAY approved
CONVERGED no new issue category this round - shipping is correct
STALL identical category set twice - author and reviewer disagree,
so stop and ask the user rather than loop again
CEILING budget exhausted; unresolved blockers must be recorded and
named, never quietly shipped
Classification is Oracle-side. Each of Smith's free-text blockers is
bucketed into the same three categories Smith already checks - reference,
executability, blocker - and the sets are compared across rounds. Smith
itself is untouched.
Smith is deliberately NOT modified. `src/agents/smith.ts` is byte-frozen by
a mission guardrail (task11-locked-decisions.test.ts, plus two
doc-coverage sweeps that fail if the freeze is lifted). Smith is the
pre-execution gate that blocks plan delivery; Auditor is the post-execution
scorer with veto powers deliberately withheld. Merging their concerns would
delete one of the two capabilities, so the edit belongs on the Oracle side.
`plans.smith_max_review_rounds` makes the ceiling configurable (default 8,
min 2, max 20). This required converting ORACLE_SYSTEM_PROMPT into a
factory to reach config at all; it is preserved as the default instance so
the existing importers keep passing untouched.
Verified: bash script/run-ci.sh 7/7 green, 3836 pass / 0 fail.
Regression fence for the reported failure: Oracle could not create or update a plan because the size limits refused the writes. Drives the real plan tool factories over a plan built from the actual renderPlanSkeleton(), so the guard is exercised through the same entry points production uses rather than enforcePlanCap in isolation. 11 cases covering: a plan in the 102400..140000 band the cap raise opened (and its refusal at the old cap), plan_tasks manifest, plan_update check-off round-trip, the lowered max_plan_file_bytes knob, contract slimming, trim_required escalation with byte-identical refusals, recovery via a shrinking write, ceiling-not-wall reads, and the UTF-8 byte ruler. Verified by mutation: reverting the pre-154 cap literal collapses the band and fails 5 of the 11 cases. Lives in script/ (not scripts/) because CI discovers tests with 'find tests script -name *.test.ts'.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Breaks the Oracle near-cap stall loop (Ariadne: plan crept 102186 to 102307 of 102400 bytes via unbounded Smith revisions) without touching the ONE PLAN doctrine or Branch 3.
Changes
Verification
Notes