Skip to content

docs(#244): govern registered specification artifacts - #246

Merged
JohnStrunk merged 8 commits into
mainfrom
agent/244-govern-registered-artifacts
Oct 9, 2026
Merged

JohnStrunk merged 8 commits into
mainfrom
agent/244-govern-registered-artifacts

Conversation

@fullsend-ai-coder

Copy link
Copy Markdown
Contributor

Summary

AGENTS.md told agents to keep every docs/ file in sync, including docs/architecture.md and docs/vision.md. Those two files are registered specification artifacts: their registry digests are recorded in .protobot/project.yaml, and a hand edit fails ears-manager check with artifact.digest_mismatch. That gap is what forced the #238 implementation to revert docs/architecture.md and leave it stale.

This change:

  • Labels docs/vision.md and docs/architecture.md as registered specification artifacts in the Specification document hierarchy.
  • Adds author Rule 5: never edit a registered specification artifact or .protobot/project.yaml by hand; apply updates exclusively via ears-manager artifact put within an active change set, after formatters and linters, and verify with ears-manager check.
  • Adds review Rule 6: check change-set manifest artifact_operations, refuse hand edits, require ears-manager check without artifact.digest_mismatch, and do not treat a registered specification artifact edited by hand as the required fix for staleness.
  • Adds the same verification step to .agents/skills/review-pr/SKILL.md.

The review-pr skill change implements Rule 6. Issue #244 documents the incorrect prior behavior (hand edits of registered specification artifacts, then reverting them to keep the store digest valid) and the impact on CI and review false positives. That issue is the skill-rule justification; no separate issue was needed.

.skillsaw-baseline.json is refreshed only for the new AGENTS.md path-reference and section-length info findings. CLAUDE.md is a symlink to AGENTS.md and inherits the hierarchy and rule text.

Testing

  • python3 scripts/lint.py --files AGENTS.md .agents/skills/review-pr/SKILL.md .skillsaw-baseline.json
  • python3 scripts/check_spec_hierarchy.py
  • bash tests/lint/test_violations.sh
  • go run ./cmd/ears-manager check from ears-manager/ (specification store still valid)

Notes

pre-commit run could not fetch hook repositories (TLS certificate verification failed). Equivalent hooks were run through python3 scripts/lint.py.


Closes #244

Post-script verification

  • Branch is not main/master (agent/244-govern-registered-artifacts)
  • Secret scan passed (gitleaks — cfdbd4a2535ca622ebee24b537ddb017b7c6979a..HEAD)
  • PR body secret scan passed (gitleaks — no-git)

AGENTS.md treated every docs/ file as a homogeneous hierarchy
member, so agents following Rule 4 hand-edited
docs/architecture.md and docs/vision.md. Those paths are
registered specification artifacts whose registry digests live
in .protobot/project.yaml; a hand edit fails ears-manager check
with artifact.digest_mismatch.

Label the two registered artifacts in the hierarchy list. Add
author Rule 5 (updates go through ears-manager artifact put in
an active change set; never edit the artifacts or project.yaml
by hand) and review Rule 6 (check artifact_operations, refuse
hand edits, require ears-manager check without
artifact.digest_mismatch). Teach review-pr the same checks so
review agents do not treat a missing hand edit as the fix.

Refresh the skillsaw baseline for the new AGENTS.md path
references and section-length info findings.

Note: pre-commit could not fetch remote hook repositories (TLS
certificate verification failed). Equivalent hooks were run via
python scripts/lint.py and passed.

Closes #244
@fullsend-ai-coder
fullsend-ai-coder Bot requested a review from a team October 8, 2026 16:01
@fullsend-ai-coder fullsend-ai-coder Bot added the ready-for-review Triggers review agent dispatch label Oct 8, 2026
@coderabbitai

coderabbitai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Repository: redhat-et/ProtoBot/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 1760d766-cf55-4595-908a-1d8c8f1278c8

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@fullsend-ai-review

Copy link
Copy Markdown

🤖 Review · ⚠️ Cancelled · Ended 4:03 PM UTC

Commit: d0c514e · View workflow run →

@fullsend-ai-review fullsend-ai-review Bot added the risk/moderate PR risk: moderate label Oct 8, 2026
@fullsend-ai-review

fullsend-ai-review Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Risk Assessment: moderate (2/5)

Details

Moderate risk driven by high recent churn and regression history on AGENTS.md (a protected path), balanced by low file count, bot authorship, and close alignment with linked issue #244.

Previous run

Risk Assessment: moderate (2/5)

Details

Moderate risk driven by high recent churn and regression history on AGENTS.md (a protected path), balanced by low file count, bot authorship, and close alignment with linked issue #244.

Previous run (2)

Risk Assessment: moderate (2/5)

Details

Moderate risk driven by high recent churn and regression history on AGENTS.md (a protected path), balanced by low file count, bot authorship, and close alignment with linked issue #244.

Previous run (3)

Risk Assessment: moderate (2/5)

Details

Moderate risk driven by high recent churn and regression history on AGENTS.md (a protected path), balanced by low file count, bot authorship, and close alignment with linked issue #244.

Previous run (4)

Risk Assessment: moderate (2/5)

Details

Moderate risk driven by high recent churn and regression history on AGENTS.md (a protected path), balanced by low file count, bot authorship, and close alignment with linked issue #244.

Previous run (5)

Risk Assessment: moderate (2/5)

Details

Moderate risk driven by high recent churn and regression history on AGENTS.md (a protected path), balanced by low file count, bot authorship, and close alignment with linked issue #244.

Previous run (6)

Risk Assessment: moderate (2/5)

Details

Moderate risk driven by high recent churn and regression history on AGENTS.md (a protected path), balanced by low file count, bot authorship, and close alignment with linked issue #244.

Previous run (7)

Risk Assessment: moderate (2/5)

Details

Moderate risk driven by high recent churn and regression history on AGENTS.md (a protected path), balanced by low file count, bot authorship, and close alignment with linked issue #244.

@fullsend-ai-review

fullsend-ai-review Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Review

Findings

High

  • [sub-agent-failure] N/A — The correctness sub-agent did not return findings: sub-agent timed out after 900s
    Remediation: Re-run the correctness review dimension or increase the timeout budget.

Medium

Low

  • [sub-agent-failure] N/A — The challenger sub-agent did not return findings: empty adjudicated_findings array returned for non-empty input set. Using pre-challenger finding set.
    Remediation: Inspect challenger sub-agent execution logs.

Next steps:

  • /fs-fix — agent addresses review findings automatically
  • /fs-fix <your instruction> — agent fixes with your specific guidance
  • Push commits directly — review re-runs automatically on push
  • /fs-fix-stop — disable automatic fix runs for this PR
Previous run

Review

Findings

Medium

  • [logic-error] AGENTS.md:182 — Rule 6 requires ears-manager check to pass without artifact.digest_mismatch but does not bind that invocation to the recorded PR head. The PR-head checkout is scoped only to working-tree change-set show (no --at); the same rule explicitly allows change-set show --at <pr-head> without a checkout, then treats a separate working-tree check as sufficient. runCheck parses only --change-set and loads the working tree (checkState/loadState → specvalidation.Load(root)); usage is ears-manager check [--change-set CS-ID]. Target grammar lists check [--at FULL-SHA] but docs/architecture/ears-manager-cli.md defers --at on analysis commands other than change-set show. A reviewer who uses the allowed --at show path and stays on the default branch therefore runs check against base artifacts whose digests still match, so a PR-head artifact.digest_mismatch (for example a formatter or hand edit after artifact put) is treated as a pass. The review-pr skill added an explicit PR-head checkout before both change-set show and check; Rule 6 did not.
    Remediation: Bind ears-manager check to the PR head the same way working-tree change-set show is bound: require a checkout or worktree of the recorded PR head before check, and state that a working-tree check on the base branch is not evidence. Do not prescribe check --at; that option is not implemented.

  • [protected-path] AGENTS.md — PR modifies protected governance file: AGENTS.md. Human approval is always required for protected-path changes, regardless of context.


Next steps:

  • /fs-fix — agent addresses review findings automatically
  • /fs-fix <your instruction> — agent fixes with your specific guidance
  • Push commits directly — review re-runs automatically on push
  • /fs-fix-stop — disable automatic fix runs for this PR
Previous run (2)

Review

Findings

Medium

  • [logic-error] AGENTS.md:171 — Rule 6's hand-edit detector claims that ears-manager change-set show reporting proposed is equivalent to the manifest path being absent from the default-branch tree. That is true only for a working-tree show, which treats a change set as approved when any default-branch ref holds the path (changeSetApprovedAt / git cat-file -e ref:path). It is false for change-set show --at, which derives status from whether the named commit is on the default branch (commitOnDefaultBranch). At an unmerged PR head, already-approved cs-00001.yaml is therefore proposed even though the path exists on main (see TestChangeSetShowAtDerivesApprovalFromTheDefaultBranch vs working-tree approval). The same parenthetical then says never to treat a path that already exists on the default branch as evidence of artifact put, which contradicts the claimed equivalence rather than matching it. Reviewers who follow the adjacent review-pr step (record head SHA, then run show) can get conflicting answers from the two tests the rule presents as the same predicate.
    Remediation: Drop 'equivalently'. Specify that working-tree change-set show (no --at), after the PR head is checked out, reports proposed iff the manifest path is absent from the default-branch tree. If show --at <pr-head> is used, require path-absence in addition to proposed; do not treat --at status alone as evidence of artifact put. Keep the existing ban on counting a modified in-tree cs-00001.yaml. Apply the same wording in the findings restatement later in Rule 6.

  • [logic-error] .agents/skills/review-pr/SKILL.md:35 — The new Process step copies Rule 6's false equivalence (change-set show → proposed iff path absent from the default-branch tree) and then tells reviewers to confirm ears-manager check passes without artifact.digest_mismatch, without pinning either command to the PR head. The skill's first step only fetches via gh pr view / gh pr diff. Working-tree check does not accept --at (implementation parses only --change-set; docs/architecture/ears-manager-cli.md still defers --at on check). A reviewer who runs the commands in a base-branch or unrelated worktree will validate the wrong tree: check can pass on main while the PR hand-edits a registered artifact, and show --at <head SHA> will mark in-tree CS-00001 as proposed. The mechanism therefore does not reliably distinguish artifact put from a hand edit at the revision under review.
    Remediation: Require a checkout or worktree of the recorded PR head before working-tree change-set show and ears-manager check. Align the proposed-change-set test with AGENTS.md after the equivalence is fixed: count a change set only when the manifest path is absent from the default-branch tree (working-tree proposed), never when show --at reports proposed for a path that already exists on the default branch. Do not treat a check pass on the base branch as evidence.

  • [protected-path] AGENTS.md — PR modifies AGENTS.md, which is a protected path in governance configuration. Human approval is required for changes to governance and infrastructure files regardless of context.

Low

  • [doc-style] .agents/skills/review-pr/SKILL.md:27 — File references to AGENTS.md are left unquoted as plain text (in AGENTS.md) at lines 27, 32, 48, and 51, whereas repository and skill convention (as well as Rule 1 of 'Rules for creating or modifying skill files' in AGENTS.md) requires backtick-quoting file paths and refs (e.g. AGENTS.md), matching other paths in this block such as docs/vision.md and .protobot/project.yaml.
    Remediation: Wrap references to AGENTS.md in backticks (AGENTS.md) across all four occurrences in .agents/skills/review-pr/SKILL.md.

Labels: PR modifies governance rules and specification review skills


Next steps:

  • /fs-fix — agent addresses review findings automatically
  • /fs-fix <your instruction> — agent fixes with your specific guidance
  • Push commits directly — review re-runs automatically on push
  • /fs-fix-stop — disable automatic fix runs for this PR
Previous run (3)

Review

Findings

Medium

  • [logic-error] AGENTS.md:170 — Rule 6 still does not give an executable test for a proposed change-set. It tells reviewers to require a manifest the PR 'adds or modifies' under .protobot/change-sets/ with '(status proposed — not an already-approved file that merely happens to sit in that directory)'. Change-set YAML has no status field (ChangeSet in ears-manager/internal/records/records.go:199-216). Proposed vs approved is derived: a change set is approved when its manifest path is in the default-branch tree (docs/architecture/ears-manager-cli.md 'Approved and proposed change sets'); ears-manager artifact put refuses an approved id via proposedChangeSet with change_set.not_proposed. Against the default branch, a legitimate artifact put adds a new cs-NNNNN.yaml; a modified path that already exists on the default branch is an approved historical manifest. Reviewers who grep for status: proposed can reject every valid put; reviewers who treat 'in the PR diff' as 'proposed' can accept a hand-edited approved cs-00001.yaml that gained a forged artifact_operations[] entry. The same underspecified phrase is restated in the findings clause (AGENTS.md:185-187). .agents/skills/review-pr/SKILL.md (lines 32-35) has the same gap: it says 'the PR's proposed cs-*.yaml' and 'already-approved' without defining either.
    Remediation: Replace 'adds or modifies ... (status proposed — not an already-approved file that merely happens to sit in that directory)' with the approval rule: count a change-set only when ears-manager change-set show reports proposed, equivalently when its manifest path is absent from the default-branch tree. Never treat a path that already exists on the default branch (including a modified cs-00001.yaml) as evidence of artifact put. Use that same test in the findings restatement and in .agents/skills/review-pr/SKILL.md.

  • [protected-path] AGENTS.md — Modifies protected governance file AGENTS.md. Although the change is documented and linked to issue Govern registered specification artifacts in AGENTS.md to prevent digest mismatches during cross-document updates #244, human approval is always required for protected-path changes, regardless of context.


Next steps:

  • /fs-fix — agent addresses review findings automatically
  • /fs-fix <your instruction> — agent fixes with your specific guidance
  • Push commits directly — review re-runs automatically on push
  • /fs-fix-stop — disable automatic fix runs for this PR
Previous run (4)

Review

Findings

Medium / Low / Info

  • [logic-error] AGENTS.md:170 — Rule 6's verification procedure cannot be executed as written and will false-fail legitimate ears-manager artifact put work. Proposed change-set manifests live only under .protobot/change-sets/ (see stores.change_sets in .protobot/project.yaml and FilenameFor producing cs-NNNNN.yaml). artifact put records the put as a list entry on that YAML file (artifact_operations: [{action, artifact_id}] per ADR-0002 and records.ChangeSet.ArtifactOperations). Rule 6 instead tells reviewers to require 'the PR's proposed change-set manifest, not any file under .protobot/change-sets/' and to look for an 'artifact_operations object whose artifact_id equals that registry id'. Literally, that excludes the only on-disk evidence and describes a mapping rather than a list. The findings restatement at lines 182–184 repeats both errors. This also contradicts .agents/skills/review-pr/SKILL.md, which correctly requires a proposed .protobot/change-sets/cs-*.yaml artifact_operations[] entry and forbids treating an already-approved manifest as evidence. A reviewer following AGENTS.md would flag a correct put as a missing operation / hand edit.
    Remediation: Rewrite Rule 6's check clause and the matching findings clause to match ADR-0002 and the review-pr skill: for each registered path the PR creates/modifies or that Rule 4 found stale, resolve artifacts[].id for that path in .protobot/project.yaml; require a change-set manifest the PR adds or modifies under .protobot/change-sets/ (status proposed — not an already-approved file that merely happens to sit in that directory) to contain an artifact_operations[] entry whose artifact_id equals that registry id; treat a digest-only or content change without that proposed operation as a hand edit.

  • [protected-path] AGENTS.md — Modifies protected governance file AGENTS.md. Sufficient context is provided via linked issue Govern registered specification artifacts in AGENTS.md to prevent digest mismatches during cross-document updates #244 and PR description, but human approval is always required for protected-path changes, regardless of context.
    Remediation: Obtain human reviewer approval for changes to AGENTS.md.


Next steps:

  • /fs-fix — agent addresses review findings automatically
  • /fs-fix <your instruction> — agent fixes with your specific guidance
  • Push commits directly — review re-runs automatically on push
  • /fs-fix-stop — disable automatic fix runs for this PR
Previous run (5)

Review

Findings

Medium / Low / Info

  • [logic-error] AGENTS.md:168 — Rule 6's authorship check is still not a procedure that can distinguish this PR's ears-manager artifact put from a hand edit. It requires 'a change-set manifest entry under .protobot/change-sets/ whose artifact_id matches each registered specification artifact'. That does not match the schema or the registry: artifact_id is a field of each object in artifact_operations (ADR-0002), not of the manifest file; those values are registry IDs such as vision / architecture (see .protobot/project.yaml), while Rule 5 defines a registered specification artifact as a path (docs/vision.md, docs/architecture.md); and any historical cs-*.yaml under .protobot/change-sets/ may later contain a matching artifact_id after a prior put merges. A later PR that hand-edits the artifact and the artifacts[].digest in .protobot/project.yaml would then satisfy this check (and ears-manager check would not report artifact.digest_mismatch). The findings clause at line 178 restates the same broken matcher. 'Field presence alone is not enough' does not close the hole unless the matcher is the proposed change set's artifact_operations joined through the registry id.
    Remediation: Replace the matcher in both the check clause and the findings clause with: for each registered path the PR creates/modifies or that Rule 4 found stale, resolve artifacts[].id for that path in .protobot/project.yaml, then require the PR's proposed change-set manifest (not any file under .protobot/change-sets/) to contain an artifact_operations object whose artifact_id equals that registry id. Treat a digest-only / content change without that proposed operation as a hand edit.

  • [logic-error] .agents/skills/review-pr/SKILL.md:31 — The review-pr Process step copies the same incorrect authorship check as AGENTS.md Rule 6: 'a change-set manifest entry under .protobot/change-sets/ whose artifact_id matches each registered specification artifact'. Reviewers following this skill will look for artifact_id as if it identified the path-form artifacts listed two bullets above (docs/vision.md, docs/architecture.md) on a manifest file, skip artifact_operations, and accept a hit in any historical change-set file. That cannot verify that this PR's changes were authored through ears-manager artifact put in the active proposed change set, which is the mechanism the skill claims to enforce.
    Remediation: Align the step with the ADR-0002 layout: require the PR's proposed .protobot/change-sets/cs-*.yaml to include, for each created/modified/stale registered path, an artifact_operations[] entry whose artifact_id equals that path's artifacts[].id in .protobot/project.yaml. Do not treat a matching artifact_id in an already-approved manifest as evidence.

  • [protected-path] AGENTS.md — Modifies protected governance file AGENTS.md. Sufficient context is provided via linked issue Govern registered specification artifacts in AGENTS.md to prevent digest mismatches during cross-document updates #244 and PR description, but human approval is always required for protected-path changes, regardless of context.
    Remediation: Obtain human reviewer approval for changes to AGENTS.md.

  • [code-organization] .agents/skills/review-pr/SKILL.md:24 — Under '## Process', the registered specification artifact check (lines 24-46) is structured as a single 22-line bullet point combining trigger conditions, change-set manifest validation, verification commands, defect definitions, and remediation instructions. In sibling skills (e.g. '.agents/skills/pull-request/SKILL.md'), multi-part checks and procedures are broken down into nested sub-bullets for readability, rather than formatted as a single monolithic paragraph.
    Remediation: Decompose the 22-line bullet into a concise top-level workflow step with nested sub-bullets for the individual verification rules and defect criteria.

  • [pattern-violation] .agents/skills/review-pr/SKILL.md:26 — Single quotes are used to cite the section title 'Rules for creating or modifying specification documents' (lines 26-27, 33-34, 40-41, and 42-43). The established convention in '.agents/skills/review-pr/SKILL.md' (e.g. lines 5, 11, 52, 82, 91) and across repository skill files is to use double quotes ("...") when quoting phrases and section titles in markdown prose.
    Remediation: Replace single quotes with double quotes: "Rules for creating or modifying specification documents".


Next steps:

  • /fs-fix — agent addresses review findings automatically
  • /fs-fix <your instruction> — agent fixes with your specific guidance
  • Push commits directly — review re-runs automatically on push
  • /fs-fix-stop — disable automatic fix runs for this PR
Previous run (6)

Review

Findings

Medium

  • [logic-error] AGENTS.md:176 — Rule 6’s consequence clause treats a missing change-set artifact_operations field as the mechanical provenance signal for ears-manager artifact put. ADR-0002 defines that field as a list of {action, artifact_id} operations, and it is optional. Presence of the key, an empty list, or an operation for a different artifact does not prove the registered specification artifact this PR created, modified, or that specification-document Rule 4 found stale was written through artifact put. git-integration.md records that a fail-open write which also rewrites the digest in .protobot/project.yaml is not caught by pre-stage comparison or ears-manager check; PR review is the remaining check. A change set that already records e.g. a Vision revise can still hand-edit docs/architecture.md and the matching registry digest, and both the documented ‘missing artifact_operations’ finding and ears-manager check without artifact.digest_mismatch still pass. The review-pr skill’s ‘Inspect the change-set manifest artifact_operations’ step has the same hole.
    Remediation: Require a change-set manifest entry under .protobot/change-sets/ whose artifact_id matches each registered specification artifact the PR creates or modifies and each registered specification artifact specification-document Rule 4 found stale. Field presence alone is not enough. Mirror the same per-artifact_id check in .agents/skills/review-pr/SKILL.md (the Inspect artifact_operations bullet).

  • [protected-path] AGENTS.md — The PR modifies protected governance file AGENTS.md. Although the change links to issue Govern registered specification artifacts in AGENTS.md to prevent digest mismatches during cross-document updates #244 and explains the rationale, human approval is always required for protected-path changes, regardless of context.

Low

  • [pattern-violation] AGENTS.md:168 — Rule 6’s review checklist requires verifying that formatters and linters ran prior to ears-manager artifact put (AGENTS.md:168-169). That ordering is not observable from a PR: no timestamp, manifest field, or CI signal records it. The invariant the author rule is protecting is already covered by ears-manager check without artifact.digest_mismatch — if a formatter rewrote the file after put, the registry digest would not match. Asking reviewers to assert formatter order produces guessed pass/fail. Author-side Rule 5 guidance to run formatters before put remains correct. Dropping the unobservable check from the review checklist keeps Rule 6 focused on observable invariants and avoids adding an unobservable defect type to the findings list.
    Remediation: Drop the formatter/linter ordering clause from Rule 6’s review checklist; keep it only as author guidance in Rule 5. Do not add formatter-order omission to Rule 6’s ‘Findings should include’ list. Keep ears-manager check without artifact.digest_mismatch as the reviewable digest invariant.

  • [code-organization] .agents/skills/review-pr/SKILL.md:26 — The added Process bullet refers to ‘Rule 4’ four times without naming the AGENTS.md list. AGENTS.md has four distinct Rule 4s (sibling-entry restatement, specification-document staleness, skill linked-issue, skill machine-separable fields). While ‘identifies staleness’ points to specification-document Rule 4, a reader of SKILL.md has no explicit pointer to that list.
    Remediation: Qualify each ‘Rule 4’ as Rule 4 of ‘Rules for creating or modifying specification documents’ in AGENTS.md.


Next steps:

  • /fs-fix — agent addresses review findings automatically
  • /fs-fix <your instruction> — agent fixes with your specific guidance
  • Push commits directly — review re-runs automatically on push
  • /fs-fix-stop — disable automatic fix runs for this PR
Previous run (7)

Review

Findings

Medium

  • [logic-error] AGENTS.md:154 — Rules 5 and 6 require ears-manager artifact put (and treat a missing put / missing change-set artifact_operations as a finding) not only when a registered artifact-registry file is created or modified, but whenever a PR 'changes behavior, interfaces, or constraints described in' docs/vision.md, docs/architecture.md, or any other artifacts[] entry. That is a different, broader trigger than Rule 4, which only requires a follow-on update when other docs/ prose no longer matches. docs/architecture.md inventories CLI commands, stores, interfaces, and constraints that many implementation or sibling-spec PRs touch; under Rules 5–6 those PRs would be required to run artifact put and to carry artifact_operations even when the registered artifact text is still accurate. Rule 6's findings list (lines 175–176) makes this explicit: missing put is a finding 'when behavior described in a registered specification artifact changes', with no 'and the registered artifact is actually stale/modified' qualifier. The closing sentence of Rule 6 ('Do not raise a staleness finding whose required fix is a registered specification artifact edited by hand') can also be read as dropping the Rule 4 staleness flag instead of requiring artifact put as the fix, which re-creates the Govern registered specification artifacts in AGENTS.md to prevent digest mismatches during cross-document updates #244 failure mode.
    Remediation: Scope Rules 5 and 6 to (a) diffs that create or modify an artifact-registry path (docs/vision.md, docs/architecture.md, or another artifacts[].path in .protobot/project.yaml) and (b) Rule 4 staleness hits on those same paths. Require that any such update go through ears-manager artifact put in a proposed change set, with artifact_operations present and ears-manager check free of artifact.digest_mismatch. Do not treat missing put/artifact_operations as a defect when the registered artifact text does not need to change. Replace Rule 6's last sentence so reviewers still raise registered-artifact staleness but prescribe artifact put, not a hand edit.

  • [logic-error] .agents/skills/review-pr/SKILL.md:24 — The new review-pr step copies Rule 6's over-broad trigger: it fires when a PR 'changes behavior, interfaces, or constraints described in' a registered specification artifact, and it states that a missing ears-manager artifact put in that situation is a finding. Reviewers following this bullet will flag implementation PRs and sibling-spec edits that leave docs/vision.md / docs/architecture.md unchanged and still correct. ears-manager check passing without artifact.digest_mismatch does not suppress that finding. Unlike AGENTS.md Rule 6, this bullet correctly says not to treat a hand edit as the required fix, but it still requires a put that should not run.
    Remediation: Gate the put/artifact_operations check on the PR actually creating or modifying a registered artifact-registry path, or on Rule 4 identifying that path as stale. Keep the hand-edit prohibition and the ears-manager check / artifact.digest_mismatch confirmation for those cases only.

  • [terminology-consistency] AGENTS.md:175 — Rule 6 restates its triggering condition ('changes behavior, interfaces, or constraints described in one', lines 164–166) in the enforcement/findings clause as 'when behavior described in a registered specification artifact changes', omitting 'interfaces, or constraints'. Under AGENTS.md sibling-entry Rule 4 ('Match intra-entry restatement terminology'), an omitted term in a restatement is a defect.
    Remediation: Update the enforcement clause in Rule 6 to match the requirement statement: 'missing ears-manager artifact put when behavior, interfaces, or constraints described in a registered specification artifact change'.

  • [terminology-consistency] .agents/skills/review-pr/SKILL.md:34 — The process bullet introduces the requirement as applying when the PR 'changes behavior, interfaces, or constraints described in one' (lines 26–27), but restates the finding clause as 'when the PR changes behavior described in a registered specification artifact' (lines 34–35), omitting 'interfaces, or constraints'. Under AGENTS.md sibling-entry Rule 4, restatements must use identical terminology without omitted terms.
    Remediation: Update the finding clause to match the opening requirement: 'A missing ears-manager artifact put, when the PR changes behavior, interfaces, or constraints described in a registered specification artifact, is a finding; do not treat a registered specification artifact edited by hand as the required fix.'

  • [protected-path] AGENTS.md — The PR modifies protected governance file AGENTS.md. Although the change links to issue Govern registered specification artifacts in AGENTS.md to prevent digest mismatches during cross-document updates #244 and explains the rationale, human approval is always required for protected-path changes, regardless of context.


Labels: PR modifies AGENTS.md specification governance and review skill procedures.


Next steps:

  • /fs-fix — agent addresses review findings automatically
  • /fs-fix <your instruction> — agent fixes with your specific guidance
  • Push commits directly — review re-runs automatically on push
  • /fs-fix-stop — disable automatic fix runs for this PR

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review fullsend-ai-review Bot added documentation Improvements or additions to documentation component:specification-toolkit Harness-agnostic skills, prompts, tool definitions, and interaction guidance. labels Oct 8, 2026
@fullsend-ai-review

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 4:04 PM UTC · Completed 4:21 PM UTC

Commit: d0c514e · View workflow run →

Runtime: pi · Model: google-vertex/gemini-3.8-flash → gemini-3.8-flash · Effort: high · Cost: $2.60

Scope Rules 5 and 6 and the review-pr skill to PRs that create or
modify a registered specification artifact, or when Rule 4 identifies
staleness in one. Ensure intra-entry restatements match the triggering
condition identically. Replace the closing staleness sentence to
prescribe ears-manager artifact put rather than editing by hand.
Preserve human approval requirement for protected path AGENTS.md.

Addresses #246
@fullsend-ai-coder

Copy link
Copy Markdown
Contributor Author

🔧 Fix agent — iteration 1 (bot-triggered)

Scoped registered specification artifact rules and review skill to artifact modifications and Rule 4 staleness, matched intra-entry restatement terminology, and preserved protected-path merge gate.

Fixed (4):

  1. AGENTS.md:154 — Rules 5 and 6 require ears-manager artifact put whenever a PR changes behavior, interfaces, or constraints described in a registered specification artifact, which is over-broad (AGENTS.md): Scoped Rules 5 and 6 to PRs creating or modifying registered specification artifacts or Rule 4 staleness hits, and replaced closing sentence to prescribe artifact put rather than editing by hand
  2. .agents/skills/review-pr/SKILL.md:24 — The new review-pr step copies Rule 6 over-broad trigger requiring artifact put when changing behavior, interfaces, or constraints described in a registered specification artifact (.agents/skills/review-pr/SKILL.md): Gated the put and artifact_operations check on the PR creating or modifying a registered artifact-registry path or Rule 4 identifying that path as stale
  3. AGENTS.md:175 — Rule 6 restates its triggering condition in the enforcement/findings clause omitting interfaces, or constraints (AGENTS.md): Matched intra-entry restatement terminology in Rule 6 to identical phrasing across requirement and findings clauses
  4. .agents/skills/review-pr/SKILL.md:34 — The process bullet restates the finding clause omitting interfaces, or constraints (.agents/skills/review-pr/SKILL.md): Matched intra-entry restatement terminology in the review-pr skill to identical phrasing across requirement and findings clauses

Disagreed (1):

  1. AGENTS.md — Protected governance file AGENTS.md modified: Protected-path findings enforce a mandatory human approval merge gate and do not prescribe a content edit

Tests: passed

CI inspections (6):

  1. CI Workflow / Pre-commit checks (passing, success): Pre-commit checks passed on PR head.
  2. CI Workflow / Specification store check (passing, success): Specification store check passed on PR head.
  3. CI Workflow / Go foundation checks (passing, success): Go foundation checks passed on PR head.
  4. CI Workflow / WMS validation and in-memory adapter checks (passing, success): WMS validation passed on PR head.
  5. CI Workflow / Source Control Manager checks (passing, success): Source Control Manager checks passed on PR head.
  6. CI Workflow / CI Workflow - Success (passing, success): CI workflow overall success.
Decision points
  • Scope of Rules 5 and 6 and review-pr skill triggers (alternatives: Trigger artifact put on any change to behavior, interfaces, or constraints described in a registered artifact, Scope artifact put exclusively to diffs creating or modifying registered artifact paths or Rule 4 staleness hits; rationale: Only diffs that actually create, modify, or render registered specification artifacts stale require ears-manager artifact put and change-set artifact_operations)
  • Handling of protected-path finding for AGENTS.md (alternatives: Revert changes to AGENTS.md, Record disagreement noting protected-path merge gate requires human approval; rationale: AGENTS.md is the central governance document modified by this PR per issue Govern registered specification artifacts in AGENTS.md to prevent digest mismatches during cross-document updates #244; protected-path findings represent merge gates requiring human review, not defects to be edited away)

Next steps:

  • /fs-review — request a re-review of the changes
  • /fs-fix <your instruction> — run another fix pass with specific guidance
  • Push commits directly — review re-runs automatically on push
    Updated by fullsend fix agent

@fullsend-ai-coder

Copy link
Copy Markdown
Contributor Author

🤖 Finished Fix · ✅ Success · Started 4:22 PM UTC · Completed 4:43 PM UTC

Commit: d0c514e · View workflow run →

Runtime: pi · Model: google-vertex/gemini-3.8-flash → gemini-3.8-flash · Effort: high · Cost: $0.71

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 4:44 PM UTC · Completed 5:06 PM UTC

Commit: 002eb9c · View workflow run →

Runtime: pi · Model: google-vertex/gemini-3.8-flash → gemini-3.8-flash · Effort: high · Cost: $4.73

Require a change-set manifest entry under .protobot/change-sets/
whose artifact_id matches each created, modified, or stale registered
specification artifact in AGENTS.md Rule 6 and the review-pr skill,
rather than checking only artifact_operations field presence.

Drop unobservable formatter/linter ordering check from Rule 6 review
checklist while retaining it as author guidance in Rule 5.

Qualify each Rule 4 reference in the review-pr skill as Rule 4 of
'Rules for creating or modifying specification documents' in AGENTS.md.

Refresh skillsaw baseline for section-length and shifted line numbers.
Note: AGENTS.md is a protected governance path requiring human approval
merge gate. Pre-commit hooks were run via python3 scripts/lint.py due to
pre-commit TLS certificate verification failure in sandbox.

Addresses #246
@fullsend-ai-coder

Copy link
Copy Markdown
Contributor Author

🔧 Fix agent — iteration 2 (bot-triggered)

Addressed review findings by requiring matching artifact_id manifest entries in AGENTS.md Rule 6 and review-pr skill, dropping unobservable formatter ordering from review checklist, qualifying Rule 4 references in review-pr skill, and updating skillsaw baseline.

Fixed (3):

  1. AGENTS.md:176 — Rule 6's consequence clause treats a missing change-set artifact_operations field as the mechanical provenance signal for ears-manager artifact put (AGENTS.md): Require a change-set manifest entry under .protobot/change-sets/ whose artifact_id matches each registered specification artifact the PR creates or modifies and each registered specification artifact Rule 4 found stale in both AGENTS.md Rule 6 and .agents/skills/review-pr/SKILL.md
  2. AGENTS.md:168 — Rule 6's review checklist requires verifying that formatters and linters ran prior to ears-manager artifact put (AGENTS.md): Drop the unobservable formatter/linter ordering check from Rule 6's review checklist and findings list while retaining it as author guidance in Rule 5
  3. .agents/skills/review-pr/SKILL.md:26 — The added Process bullet refers to 'Rule 4' four times without naming the AGENTS.md list (.agents/skills/review-pr/SKILL.md): Qualify each Rule 4 reference in the review-pr process bullet as Rule 4 of 'Rules for creating or modifying specification documents' in AGENTS.md

Disagreed (1):

  1. AGENTS.md — The PR modifies protected governance file AGENTS.md. Human approval is always required for protected-path changes: AGENTS.md is a protected governance path requiring a human reviewer approval merge gate; no code modification is prescribed by this finding

Tests: passed

CI inspections (6):

  1. Pre-commit checks (passing, success): Pre-commit checks passed.
  2. Specification store check (passing, success): Specification store check passed.
  3. Go foundation checks (passing, success): Go foundation checks passed.
  4. Source Control Manager checks (passing, success): Source Control Manager checks passed.
  5. WMS validation and in-memory adapter checks (passing, success): WMS validation and in-memory adapter checks passed.
  6. CI Workflow - Success (passing, success): CI Workflow - Success passed.
Decision points
  • Retain formatter/linter ordering guidance in Rule 5 author instructions while dropping it from Rule 6 review checks (alternatives: Keep formatter ordering in both author and review rules, Remove formatter ordering from author rules as well, Drop from Rule 6 review checks and preserve in Rule 5 author guidance; rationale: Author guidance helps prevent unformatted commits before put, whereas reviewers cannot observe execution order from a PR and rely on digest verification instead)

Next steps:

  • /fs-review — request a re-review of the changes
  • /fs-fix <your instruction> — run another fix pass with specific guidance
  • Push commits directly — review re-runs automatically on push
    Updated by fullsend fix agent

@fullsend-ai-coder

Copy link
Copy Markdown
Contributor Author

🤖 Finished Fix · ✅ Success · Started 5:07 PM UTC · Completed 5:23 PM UTC

Commit: 002eb9c · View workflow run →

Runtime: pi · Model: google-vertex/gemini-3.8-flash → gemini-3.8-flash · Effort: high · Cost: $0.70

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 5:24 PM UTC · Completed 5:39 PM UTC

Commit: 29b2214 · View workflow run →

Runtime: pi · Model: google-vertex/gemini-3.8-flash → gemini-3.8-flash · Effort: high · Cost: $2.20

Replace change-set manifest matcher in AGENTS.md Rule 6 with
a check requiring the PR's proposed manifest to contain an
artifact_operations entry whose artifact_id matches each
registered path's artifacts[].id in .protobot/project.yaml.

Decompose the registered specification artifact check in
review-pr skill into a top-level step with nested sub-bullets,
align with ADR-0002 artifact_operations layout, and use double
quotes for section title citations.

Refresh skillsaw baseline for updated line numbers and tokens.
Note: AGENTS.md is a protected governance path requiring human
approval merge gate. Pre-commit hooks were run via python3
scripts/lint.py due to pre-commit TLS certificate verification
failure in sandbox.

Addresses #246
@fullsend-ai-coder

Copy link
Copy Markdown
Contributor Author

🔧 Fix agent — iteration 3 (bot-triggered)

Addressed all review feedback on PR #246 by replacing the change-set manifest matcher in AGENTS.md Rule 6 and the review-pr skill with an artifact_operations check resolved against .protobot/project.yaml, decomposing the review-pr process step into nested sub-bullets, standardizing section title citations to double quotes, and refreshing the skillsaw baseline.

Fixed (4):

  1. Rule 6 change-set manifest matcher does not resolve artifact registry ID (AGENTS.md): Updated Rule 6 in AGENTS.md to resolve artifacts[].id in .protobot/project.yaml for each registered path created, modified, or found stale, and require the PR's proposed change-set manifest to contain an artifact_operations object whose artifact_id equals that registry ID.
  2. review-pr skill manifest check does not inspect ADR-0002 artifact_operations (.agents/skills/review-pr/SKILL.md): Aligned review-pr skill with ADR-0002 layout by requiring the proposed change-set manifest to contain an artifact_operations entry matching the resolved registry ID from .protobot/project.yaml, rejecting historical change-set matches, and treating missing operations as hand edits.
  3. Monolithic 22-line bullet in review-pr Process section (.agents/skills/review-pr/SKILL.md): Decomposed the monolithic 22-line bullet into a concise top-level workflow step with nested sub-bullets for manifest validation, hand edit inspection, verification command, defect definition, and staleness remediation.
  4. Single quotes used to cite section title in review-pr skill (.agents/skills/review-pr/SKILL.md): Replaced single quotes with double quotes for all citations of "Rules for creating or modifying specification documents" to match repository skill markdown conventions.

Disagreed (1):

  1. Protected governance file AGENTS.md requires human approval: Human approval is a required merge gate for protected-path modifications to AGENTS.md and cannot be granted autonomously by the fix agent; left for human reviewer sign-off.

Tests: passed

CI inspections (5):

  1. Pre-commit checks (passing, success): Pre-commit checks passed on PR head.
  2. Specification store check (passing, success): Specification store check passed on PR head.
  3. Go foundation checks (passing, success): Go foundation checks passed on PR head.
  4. WMS validation and in-memory adapter checks (passing, success): WMS validation checks passed on PR head.
  5. Source Control Manager checks (passing, success): Source Control Manager checks passed on PR head.

Conflict update: skipped; strategy none; forge MERGEABLE; target main@cfdbd4a2535ca622ebee24b537ddb017b7c6979a

Decision points
  • Resolve artifact_operations through .protobot/project.yaml registry ID (alternatives: Check for artifact path directly in change-set manifest, Resolve artifact path to registry ID via .protobot/project.yaml artifacts[].id; rationale: In ADR-0002, change-set manifests record artifact_id matching registry IDs like vision/architecture rather than file paths.)

Next steps:

  • /fs-review — request a re-review of the changes
  • /fs-fix <your instruction> — run another fix pass with specific guidance
  • Push commits directly — review re-runs automatically on push
    Updated by fullsend fix agent

@fullsend-ai-coder

Copy link
Copy Markdown
Contributor Author

🤖 Finished Fix · ✅ Success · Started 5:40 PM UTC · Completed 5:56 PM UTC

Commit: 29b2214 · View workflow run →

Runtime: pi · Model: google-vertex/gemini-3.8-flash → gemini-3.8-flash · Effort: high · Cost: $0.99

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 5:57 PM UTC · Completed 6:16 PM UTC

Commit: a3b4d9a · View workflow run →

Runtime: pi · Model: google-vertex/gemini-3.8-flash → gemini-3.8-flash · Effort: high · Cost: $2.71

Align AGENTS.md Rule 6 check clause and findings clause with ADR-0002
and review-pr skill by requiring proposed change-set manifest added
or modified under .protobot/change-sets/ to include an
artifact_operations[] entry matching the registry id.

Refresh skillsaw baseline for updated AGENTS.md line numbers and
section token counts.

Note: AGENTS.md is a protected governance path requiring human
reviewer approval merge gate. Pre-commit hooks were run via python3
scripts/lint.py due to pre-commit TLS certificate verification failure
in sandbox.

Addresses #246
@fullsend-ai-coder

Copy link
Copy Markdown
Contributor Author

🔧 Fix agent — iteration 4 (bot-triggered)

Addressed review feedback on AGENTS.md Rule 6 by rewriting the check clause and findings clause to require a proposed change-set manifest added or modified under .protobot/change-sets/ containing an artifact_operations[] entry whose artifact_id equals the registry id, matching ADR-0002 and the review-pr skill. Disagreed on the protected-path finding which requires human reviewer approval as a merge gate.

Fixed (1):

  1. Rule 6 verification procedure cannot be executed as written and will false-fail legitimate ears-manager artifact put work (AGENTS.md): Rewrote AGENTS.md Rule 6 check clause and matching findings clause to require a change-set manifest added or modified under .protobot/change-sets/ (status proposed — not an already-approved file) to contain an artifact_operations[] entry matching the registry id, aligning with ADR-0002 and the review-pr skill.

Disagreed (1):

  1. Modifies protected governance file AGENTS.md: Protected-path merge gate requires human reviewer approval; no content edit prescribed.

Tests: passed

CI inspections (7):

  1. CI Workflow - Success (passing, success): CI Workflow completed successfully on PR head.
  2. Source Control Manager checks (passing, success): Source Control Manager checks passed.
  3. Specification store check (passing, success): ears-manager check passed without artifact.digest_mismatch.
  4. WMS validation and in-memory adapter checks (passing, success): WMS validation and in-memory adapter checks passed.
  5. Pre-commit checks (passing, success): Pre-commit checks passed in CI.
  6. Go foundation checks (passing, success): Go foundation checks (fmt, lint, vet, test, build) passed.
  7. CodeRabbit (passing, success): CodeRabbit check passed.

Conflict update: skipped; strategy none; forge MERGEABLE; target main@cfdbd4a2535ca622ebee24b537ddb017b7c6979a

Strategy change: Escalated strategy at iteration 4: reconciled AGENTS.md Rule 6 check and findings clauses directly with ADR-0002 and the review-pr skill rather than adjusting the previous iteration's phrasing.

Decision points
  • Align Rule 6 change-set manifest requirement directly with ADR-0002 and review-pr skill (alternatives: Retain proposed manifest check outside change-sets directory, Require artifact_operations[] list entry under .protobot/change-sets/ status proposed; rationale: Change-set manifests only live under .protobot/change-sets/, and artifact_operations is a list of operation entries per ADR-0002. Aligning Rule 6 with review-pr resolves the contradiction and prevents false-positive review failures.)

Next steps:

  • /fs-review — request a re-review of the changes
  • /fs-fix <your instruction> — run another fix pass with specific guidance
  • Push commits directly — review re-runs automatically on push
    Updated by fullsend fix agent

@fullsend-ai-coder fullsend-ai-coder Bot added the needs-human Agent loop needs human intervention label Oct 8, 2026
fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 6:43 PM UTC · Completed 6:56 PM UTC

Commit: ea5325e · View workflow run →

Runtime: pi · Model: google-vertex/gemini-3.8-flash → gemini-3.8-flash · Effort: high · Cost: $1.65

Define proposed change-set test in AGENTS.md Rule 6 and review-pr
skill using the approval rule: count a change-set only when
ears-manager change-set show reports proposed (equivalently when its
manifest path is absent from the default-branch tree) and never treat
a path that already exists on the default branch as evidence of
artifact put.

Refresh skillsaw baseline for updated line numbers and section tokens.

Note: AGENTS.md is a protected governance path requiring human
reviewer approval merge gate. Pre-commit hooks were run via python3
scripts/lint.py due to pre-commit TLS certificate verification failure
in sandbox.

Addresses #246
@fullsend-ai-coder

Copy link
Copy Markdown
Contributor Author

🔧 Fix agent — iteration 5 (bot-triggered)

Addressed review feedback on PR #246 by replacing the underspecified change-set check in AGENTS.md Rule 6 (requirement and findings clauses) and the review-pr skill with the canonical approval rule: counting change sets only when ears-manager change-set show reports proposed (manifest path absent from default-branch tree) and disallowing existing default-branch paths as evidence of artifact put. Updated skillsaw baseline accordingly.

Fixed (1):

  1. Rule 6 executable test for proposed change-set (AGENTS.md): Defined proposed change-set test in AGENTS.md Rule 6 requirement and findings clauses, and in review-pr skill, requiring change sets to report proposed in ears-manager change-set show (equivalently manifest path absent from default branch tree) and disallowing existing default-branch paths as evidence of artifact put.

Disagreed (1):

  1. Modifies protected governance file AGENTS.md: Protected path merge gate requires human reviewer approval; the finding is an informational governance check rather than a prescriptive code change.

Tests: passed

CI inspections (6):

  1. Pre-commit checks (passing, success): Pre-commit checks passed successfully in CI.
  2. Go foundation checks (passing, success): Go foundation checks passed successfully in CI.
  3. Specification store check (passing, success): Specification store check passed successfully in CI.
  4. Source Control Manager checks (passing, success): Source Control Manager checks passed successfully in CI.
  5. WMS validation and in-memory adapter checks (passing, success): WMS validation and in-memory adapter checks passed successfully in CI.
  6. CI Workflow - Success (passing, success): Overall CI workflow completed successfully.

Conflict update: skipped; strategy none; forge MERGEABLE; target main@cfdbd4a2535ca622ebee24b537ddb017b7c6979a

Strategy change: Shifted from describing proposed change-set manifests using file diff heuristics or status field assumptions to using the canonical ears-manager approval rule: verifying change-set status via ears-manager change-set show reporting proposed, or equivalently verifying that the manifest path is absent from the default-branch tree.

Decision points
  • Ground proposed change-set validation on ears-manager cli approval semantics rather than file presence in PR diff (alternatives: Check whether the change-set file is added or modified in the PR diff, Rely on ears-manager change-set show reporting proposed status and absence from default-branch tree; rationale: Change-set YAML has no status field and an approved historical change set can be modified in a PR. The only sound test is checking whether the manifest path is absent from the default-branch tree, matching ears-manager change-set show.)

Next steps:

  • /fs-review — request a re-review of the changes
  • /fs-fix <your instruction> — run another fix pass with specific guidance
  • Push commits directly — review re-runs automatically on push
    Updated by fullsend fix agent

@fullsend-ai-coder

Copy link
Copy Markdown
Contributor Author

🤖 Finished Fix · ✅ Success · Started 6:58 PM UTC · Completed 7:18 PM UTC

Commit: ea5325e · View workflow run →

Runtime: pi · Model: google-vertex/gemini-3.8-flash → gemini-3.8-flash · Effort: high · Cost: $0.82

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 7:19 PM UTC · Completed 7:41 PM UTC

Commit: c8f98ce · View workflow run →

Runtime: pi · Model: google-vertex/gemini-3.8-flash → gemini-3.8-flash · Effort: high · Cost: $3.96

@fullsend-ai-coder

Copy link
Copy Markdown
Contributor Author

🤖 Finished Fix · ❌ Failure (running pre-script: exit status 1: Fix iteration 6 exceeds bot cap of 5. Escalating to human. The review→fix loop has run 6 times without converging. A human can still direct the agent with /fs-fix (u…) · Started 7:42 PM UTC · Completed 7:42 PM UTC

Commit: c8f98ce · View workflow run →

Effort: high

@JohnStrunk

Copy link
Copy Markdown
Member

/fs-fix

Update proposed change-set test in AGENTS.md Rule 6 and review-pr
skill: distinguish working-tree change-set show from show --at,
require path absence from default branch in addition to proposed for
show --at, and require checkout or worktree of PR head before
working-tree show and check commands. Wrap AGENTS.md references in
backticks across review-pr skill. Refresh skillsaw baseline.

Note: AGENTS.md is a protected governance path requiring human
reviewer approval merge gate. Pre-commit hooks were run via python3
scripts/lint.py due to pre-commit TLS certificate verification failure
in sandbox.

Addresses #246
@fullsend-ai-coder

Copy link
Copy Markdown
Contributor Author

🔧 Fix agent — iteration 6 (human-triggered)

Addressed review findings by distinguishing working-tree change-set show from show --at, requiring default-branch path absence in addition to proposed for show --at, requiring a checkout or worktree of the PR head before working-tree show and check commands, backtick-quoting AGENTS.md references in review-pr skill, and refreshing skillsaw baseline.

Fixed (3):

  1. Rule 6 hand-edit detector claims change-set show 'proposed' is equivalent to default-branch absence (AGENTS.md): Dropped 'equivalently'. Specified that working-tree change-set show (no --at), after the PR head is checked out, reports proposed iff the manifest path is absent from the default-branch tree. For show --at , required path-absence in addition to proposed and forbade treating --at status alone as evidence of artifact put. Preserved ban on counting a modified in-tree cs-00001.yaml. Applied identical wording across the check clause and findings restatement in Rule 6.
  2. Review-pr skill copies false equivalence and runs working-tree check without pinning to PR head (.agents/skills/review-pr/SKILL.md): Required a checkout or worktree of the recorded PR head before running working-tree change-set show and ears-manager check, and noted that a check pass on the base branch must not be treated as evidence. Aligned the proposed-change-set test with AGENTS.md Rule 6.
  3. File references to AGENTS.md unquoted in review-pr skill Process section (.agents/skills/review-pr/SKILL.md): Wrapped all four references to AGENTS.md in backticks (AGENTS.md) in the review-pr skill Process section.

Disagreed (1):

  1. PR modifies AGENTS.md protected governance file: Modifications to AGENTS.md are governance changes authorized by issue Govern registered specification artifacts in AGENTS.md to prevent digest mismatches during cross-document updates #244 and addressing review feedback on Rule 6. Human approval is a merge gate requirement that must be satisfied by human reviewer approval on GitHub PR merge rather than an automated code modification.

Tests: passed

CI inspections (7):

  1. CI Workflow - Success (passing, success): Overall CI workflow passed.
  2. WMS validation and in-memory adapter checks (passing, success): WMS validation and in-memory adapter checks passed.
  3. Specification store check (passing, success): Specification store check passed.
  4. Source Control Manager checks (passing, success): Source Control Manager checks passed.
  5. Pre-commit checks (passing, success): Pre-commit checks passed.
  6. Go foundation checks (passing, success): Go foundation checks passed.
  7. CodeRabbit (passing, success): CodeRabbit check passed.
Decision points
  • Align change-set show status derivation between AGENTS.md and review-pr skill (alternatives: Only update AGENTS.md without updating review-pr skill, Update both AGENTS.md Rule 6 and review-pr skill with identical proposed change-set test and require checkout of PR head; rationale: Reviewers follow review-pr skill steps when evaluating PRs; both must define identical, executable criteria to avoid false positives on legitimate artifact put operations)

Next steps:

  • /fs-review — request a re-review of the changes
  • /fs-fix <your instruction> — run another fix pass with specific guidance
  • Push commits directly — review re-runs automatically on push
    Updated by fullsend fix agent

@fullsend-ai-coder

Copy link
Copy Markdown
Contributor Author

🤖 Finished Fix · ✅ Success · Started 8:30 PM UTC · Completed 8:48 PM UTC

Commit: c8f98ce · View workflow run →

Runtime: pi · Model: google-vertex/gemini-3.8-flash → gemini-3.8-flash · Effort: high · Cost: $0.86

fullsend-ai-review[bot]

This comment was marked as outdated.

@fullsend-ai-review

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 8:50 PM UTC · Completed 9:11 PM UTC

Commit: 48fcfcd · View workflow run →

Runtime: pi · Model: google-vertex/gemini-3.8-flash → gemini-3.8-flash · Effort: high · Cost: $3.26

@fullsend-ai-coder

Copy link
Copy Markdown
Contributor Author

🤖 Finished Fix · ❌ Failure (running pre-script: exit status 1: Fix iteration 7 exceeds bot cap of 5. Escalating to human. The review→fix loop has run 7 times without converging. A human can still direct the agent with /fs-fix (u…) · Started 9:12 PM UTC · Completed 9:12 PM UTC

Commit: 48fcfcd · View workflow run →

Effort: high

@JohnStrunk

Copy link
Copy Markdown
Member

/fs-fix

Bind ears-manager check to the PR head in AGENTS.md Rule 6: require a
checkout or worktree of the recorded PR head before check, and state
that a working-tree check on the base branch is not evidence. Refresh
skillsaw baseline.

Note: AGENTS.md is a protected governance path requiring human
reviewer approval merge gate. Pre-commit hooks were run via python3
scripts/lint.py due to pre-commit TLS certificate verification failure
in sandbox.

Addresses #246
@fullsend-ai-coder

Copy link
Copy Markdown
Contributor Author

🔧 Fix agent — iteration 7 (human-triggered)

Addressed review feedback on AGENTS.md Rule 6 by binding ears-manager check to the recorded PR head via a required checkout or worktree, and noted that a working-tree check on the base branch is not evidence. Refreshed skillsaw baseline.

Fixed (1):

  1. Rule 6 requires ears-manager check to pass without artifact.digest_mismatch but does not bind that invocation to the recorded PR head. (AGENTS.md): Bound ears-manager check to the PR head in AGENTS.md Rule 6 by requiring a checkout or worktree of the recorded PR head before check, and stating that a working-tree check on the base branch is not evidence.

Disagreed (1):

  1. PR modifies protected governance file: AGENTS.md. Human approval is always required for protected-path changes, regardless of context.: Protected-path finding serves as a merge-gate reminder requiring human reviewer approval rather than prescribing a code edit.

Tests: passed

CI inspections (5):

  1. Pre-commit checks (passing, success): Pre-commit checks completed successfully on commit 48fcfcd.
  2. Go foundation checks (passing, success): Go foundation checks completed successfully on commit 48fcfcd.
  3. Specification store check (passing, success): Specification store check completed successfully on commit 48fcfcd.
  4. WMS validation and in-memory adapter checks (passing, success): WMS validation checks completed successfully on commit 48fcfcd.
  5. Source Control Manager checks (passing, success): Source Control Manager checks completed successfully on commit 48fcfcd.

Conflict update: skipped; strategy none; forge MERGEABLE; target main@dacb3bbf7e546a8d9307b93d43e9b802a9b2dc47

Decision points
  • Bind ears-manager check to PR head in AGENTS.md Rule 6 via explicit checkout requirement (alternatives: Prescribe check --at , Require a checkout or worktree of the recorded PR head before check and state that a working-tree check on the base branch is not evidence; rationale: ears-manager check does not implement --at. Requiring a checkout or worktree of the recorded PR head aligns Rule 6 with review-pr skill and working-tree change-set show.)

Next steps:

  • /fs-review — request a re-review of the changes
  • /fs-fix <your instruction> — run another fix pass with specific guidance
  • Push commits directly — review re-runs automatically on push
    Updated by fullsend fix agent

@fullsend-ai-coder

Copy link
Copy Markdown
Contributor Author

🤖 Finished Fix · ✅ Success · Started 1:41 PM UTC · Completed 1:55 PM UTC

Commit: 48fcfcd · View workflow run →

Runtime: pi · Model: google-vertex/gemini-3.8-flash → gemini-3.8-flash · Effort: high · Cost: $0.83

@fullsend-ai-review fullsend-ai-review Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

See the review comment for full details.

Comment thread AGENTS.md
- `docs/vision.md` — project Vision (purpose, users, outcomes).
- `docs/architecture.md` — Architecture artifact (external
interfaces, persistent state, environmental constraints).
- `docs/vision.md` — registered Vision artifact (purpose, users,

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[medium] protected-path

This PR modifies protected governance file AGENTS.md. While the PR links to issue #244 and provides context for the changes, human approval is always required for protected-path changes, regardless of context.

Suggested fix: Request human review and approval from repository maintainers for AGENTS.md modifications.

@fullsend-ai-review

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 1:56 PM UTC · Completed 2:30 PM UTC

Commit: f0cd1b4 · View workflow run →

Runtime: pi · Model: google-vertex/gemini-3.8-flash → gemini-3.8-flash · Effort: high · Cost: $1.30

@fullsend-ai-coder

Copy link
Copy Markdown
Contributor Author

🤖 Finished Fix · ❌ Failure (running pre-script: exit status 1: Fix iteration 8 exceeds bot cap of 5. Escalating to human. The review→fix loop has run 8 times without converging. A human can still direct the agent with /fs-fix (u…) · Started 2:31 PM UTC · Completed 2:32 PM UTC

Commit: f0cd1b4 · View workflow run →

Effort: high

@JohnStrunk
JohnStrunk added this pull request to the merge queue Oct 9, 2026
Merged via the queue into main with commit bbdc5fa Oct 9, 2026
42 of 43 checks passed
@JohnStrunk
JohnStrunk deleted the agent/244-govern-registered-artifacts branch October 9, 2026 15:06
@fullsend-ai-retro

Copy link
Copy Markdown

Workflow Retrospective: PR #246 (docs(#244): govern registered specification artifacts)

1. Workflow Timeline & Rework Analysis

  • Origin: PR docs(#244): govern registered specification artifacts #246 implemented Issue Govern registered specification artifacts in AGENTS.md to prevent digest mismatches during cross-document updates #244 to govern registered specification artifacts (docs/vision.md, docs/architecture.md) in AGENTS.md and .agents/skills/review-pr/SKILL.md to prevent digest mismatches during cross-document updates.
  • Rework & Iterations: The PR underwent 8 review runs and 7 fix iterations (8 total commits) across ~23 hours before maintainer @JohnStrunk manually approved and merged:
    • Commit d0c514e (Initial): Code agent implemented Issue Govern registered specification artifacts in AGENTS.md to prevent digest mismatches during cross-document updates #244, introducing over-broad triggers, unobservable checks (asserting formatters ran before artifact put), and terminology drift in AGENTS.md Rule 6.
    • Commits 002eb9c to ea5325e (Fixes 1–4): The review and fix agents thrashed on the exact operational verification criteria for artifact_operations[], registry IDs vs. file paths, and manifest locations under .protobot/change-sets/.
    • Commits c8f98ce to f0cd1b4 (Fixes 5–7): Further thrashing over Git-derived status semantics (status: proposed does not exist in YAML), working-tree ears-manager change-set show vs. show --at <pr-head>, and binding ears-manager check to a required checkout of the PR head.
    • Bot Cap Escalations: Fix iterations 6, 7, and 8 were blocked by the automated bot iteration cap of 5 (pre-fix.sh exited with Fix iteration N exceeds bot cap of 5. Escalating to human.), requiring maintainer @JohnStrunk to unblock with /fs-fix at iterations 6 and 7.
    • Review Run 8 (Commit f0cd1b4): All substantive rule defects had been resolved, but the review agent posted CHANGES_REQUESTED because the correctness sub-agent (xai/grok-4.6) timed out at 900s, generating a high-severity [sub-agent-failure] finding. The challenger subagent exonerated the PR, but the review orchestrator's empty-set fallback restored the timeout finding.
    • Resolution: Maintainer @JohnStrunk approved the PR at 2026-10-09T15:04:17Z and merged it into main.

2. Autonomy Readiness

  • Maintainer @JohnStrunk submitted a manual APPROVED review without comments and merged the PR. Per the autonomy-readiness evaluation protocol, silent approvals are classified as inconclusive; absence of human review comments cannot be treated as zero gaps or as evidence of agent review success.

3. Evidence for Existing Issues (Mandatory Filter Notes)

Analysis of PR #246 provides concrete evidence supporting several open upstream issues; per retro guidelines, separate proposals were withheld to avoid duplicate issue tracking:

  • fullsend-ai/agents#1412 (Make retry-before-escalate deterministic for timed-out correctness/security review sub-agents): On Review Run 37940324985 (Commit f0cd1b4), correctness (xai/grok-4.6) timed out at 900s, forcing a merge-blocking CHANGES_REQUESTED verdict even though all code defects were resolved and ~10 minutes of overall run budget remained.
  • fullsend-ai/fullsend#7263 (Sub-agent dispatch consistently hits hardcoded 900s ceiling for xai-vertex/grok-4.6): Review Run 37940324985 hit the hardcoded [fullsend-agent] #1 done 900020ms timeout after completing only 4 conversational turns due to high model latency.
  • fullsend-ai/agents#1399 (Review agent keeps auto-dispatching Fix runs after the fix pre-script's iteration cap is already exceeded): Fix runs 37833773078 (iter 6), 37845039988 (iter 7), and 37944742674 (iter 8) were automatically dispatched by bot CHANGES_REQUESTED reviews and immediately failed at pre-fix.sh because the bot cap was exceeded.
  • fullsend-ai/fullsend#8139 / fullsend-ai/agents#1110 (Skip fix dispatch when review findings are human-gate-only / Review agent should use COMMENT verdict when all findings are human-only): Every review run on PR docs(#244): govern registered specification artifacts #246 raised [protected-path] on AGENTS.md, an unresolvable human merge gate that forced the fix agent to repeatedly record disagreements (type: "disagree") across all 7 fix iterations.
  • fullsend-ai/agents#675 (Closed via PR #1594): The challenger in Review Run 8 cleared the timeout finding, but the empty-findings fallback restored it; upstream PR #1594 already resolved this by withholding sub-agent-failure findings from challenger dispatch.

4. New Proposals

  • redhat-et/ProtoBot: Enforce registered specification artifact change-set operations in ears-manager check — Replaces the fragile, 50-line natural language verification procedure in AGENTS.md Rule 6 with deterministic validation in ears-manager check, preventing future review-fix thrashing and ensuring CI fails fast when registered artifacts are modified without an active change set operation.

Proposals filed

@fullsend-ai-retro

Copy link
Copy Markdown

🤖 Finished Retro · ✅ Success · Started 3:07 PM UTC · Completed 3:30 PM UTC

Commit: f0cd1b4 · View workflow run →

Runtime: pi · Model: google-vertex/gemini-3.8-flash → gemini-3.8-flash · Effort: high · Cost: $2.89

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

component:specification-toolkit Harness-agnostic skills, prompts, tool definitions, and interaction guidance. documentation Improvements or additions to documentation needs-human Agent loop needs human intervention ready-for-review Triggers review agent dispatch risk/moderate PR risk: moderate

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Govern registered specification artifacts in AGENTS.md to prevent digest mismatches during cross-document updates

1 participant