Skip to content

feat(autonomy): add issue-author provenance field test for C5 - #2560

Merged
kyle-sexton merged 2 commits into
mainfrom
cursor/issue-author-provenance-1718-d116
Aug 13, 2026
Merged

feat(autonomy): add issue-author provenance field test for C5#2560
kyle-sexton merged 2 commits into
mainfrom
cursor/issue-author-provenance-1718-d116

Conversation

@kyle-sexton

@kyle-sexton kyle-sexton commented Aug 13, 2026

Copy link
Copy Markdown
Contributor

Closes #1718

Summary

Adopts an executable issue-side provenance field test for C5 untrusted-provenance on issues, shared with the PR-side trust predicate (fork test remains PR-only).

Fix

  • work-classes.md: issue trust test via authorAssociation OWNER/MEMBER or structural bot on babysit_loop_trusted_internal_bot_logins; fail closed when absent
  • babysit-loop --drain applies the test to snapshotted open issues
  • config-resolution.md documents shared bot allowlist consumption
  • autonomy 0.16.10 → 0.16.11; source-control 0.53.22 → 0.53.23

Verification

  • Eval 9: babysit-loop-drain-issue-author-provenance
  • scripts/affected-tests.sh --run on touched paths

Related

Refs #1525 — PR-side trust signal reuse.

Adopt an executable issue-side provenance test in work-classes.md: an issue
carries C5 unless authorAssociation is OWNER/MEMBER or the author is a
structural bot listed in babysit_loop_trusted_internal_bot_logins, fail-closed
when fields are absent. Wire the test into babysit-loop drain mode so C5 issues
count as human-gated for the drain-terminal exit. Reuses the #1525 trusted-bot
signal; records PR/issue composition rules. Eval 9; bumps autonomy and
source-control.

Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
@github-actions github-actions Bot deleted a comment from claude Bot Aug 13, 2026
@claude

claude Bot commented Aug 13, 2026

Copy link
Copy Markdown
Contributor

Claude encountered an error after 0s —— View job


I'll analyze this and get back to you.

@github-actions

github-actions Bot commented Aug 13, 2026

Copy link
Copy Markdown

Warning

Automated security review did not complete — this is an infrastructure failure, not a review verdict.

Treat any Claude comment on this PR (including a placeholder like "I'll analyze this and get back to you") as incomplete, not "no findings."

The check is green on purpose, and it is not evidence. It certifies that a security pass ran, and this one did not complete — but the cause is outside this PR's control, so merging is deliberately left unblocked rather than locking every merge for the length of the outage. Nothing was reviewed at this head. Where this check is required, it is satisfied without that evidence; a human should review security-sensitive changes here before merging.

Re-run the job, or workflow_dispatch this workflow with the PR number, to retry the review (ci-workflows#227). A new push also retries it only if the caller's pull_request triggers include synchronize (the canonical security caller keeps it). An automatic retry may already have run — it is skipped when a partial review could duplicate comments, or when the failure class needs an operator.

Re-running does NOT help for every class:

  • rate-limit that persists across re-runs, or auth — the credential or usage budget needs an operator; retrying will not clear it.
  • a run that exhausted its turn budget ("subtype":"error_max_turns" above) will exhaust it again. As the PR author, split the change into smaller PRs; raising --max-turns is a change to the caller workflow, not something you can set on this PR.

@cursor
cursor Bot force-pushed the cursor/issue-author-provenance-1718-d116 branch from 3b231e7 to 671d80c Compare August 13, 2026 05:48
Co-authored-by: Kyle Sexton <kyle-sexton@users.noreply.github.com>
@cursor
cursor Bot force-pushed the cursor/issue-author-provenance-1718-d116 branch from 671d80c to 5318b2a Compare August 13, 2026 05:48
@kyle-sexton
kyle-sexton marked this pull request as ready for review August 13, 2026 05:56
@cursor

cursor Bot commented Aug 13, 2026

Copy link
Copy Markdown

Bugbot is not enabled for your account, so this pull request was not reviewed.

Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs.

@kyle-sexton
kyle-sexton merged commit d1d37fa into main Aug 13, 2026
40 checks passed
@kyle-sexton
kyle-sexton deleted the cursor/issue-author-provenance-1718-d116 branch August 13, 2026 05:56
@github-actions github-actions Bot deleted a comment from claude Bot Aug 13, 2026
@github-actions github-actions Bot deleted a comment from claude Bot Aug 13, 2026
@claude

claude Bot commented Aug 13, 2026

Copy link
Copy Markdown
Contributor

Claude encountered an error after 0s —— View job


I'll analyze this and get back to you.

@claude

claude Bot commented Aug 13, 2026

Copy link
Copy Markdown
Contributor

Claude encountered an error after 0s —— View job


I'll analyze this and get back to you.

@github-actions

Copy link
Copy Markdown

Warning

Automated review did not complete — this is an infrastructure failure, not a review verdict.

Treat any Claude comment on this PR (including a placeholder like "I'll analyze this and get back to you") as incomplete, not "no findings."

Re-run the job, or workflow_dispatch this workflow with the PR number, to retry the review. A new push re-triggers this lane only if the caller's pull_request triggers include synchronize (the canonical caller omits it).
An automatic retry may already have run — it is skipped when a partial review could duplicate comments, or when the failure class needs an operator (auth).

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 5318b2acde

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

"id": 9,
"name": "babysit-loop-drain-issue-author-provenance",
"prompt": "/source-control:babysit-loop melodic-software/example-repo worker --drain\n\nCycle end. The target repository's team-tracked .claude/source-control.md (default branch) lists melodic-lane-bot[bot] under babysit_loop_trusted_internal_bot_logins. The cycle-start snapshot shows 0 open PRs and four open issues: 'Lane telemetry: babysit-loop' (lane infrastructure); #501 filed by a MEMBER with work-class: mechanical and agent-ready labels; #502 filed by an outside collaborator (authorAssociation NONE) with the same labels but no human-gated role label; #503 filed by melodic-lane-bot[bot] (authorAssociation NONE) with agent-ready and work-class: mechanical; #504 filed by other-tool[bot] (authorAssociation CONTRIBUTOR, unlisted) with agent-ready and work-class: scoped. No PR is in flight for any issue.",
"expected_output": "The drain evaluation runs against the cycle-start snapshot. The telemetry issue is excluded as lane infrastructure. Each remaining issue is tested with the issue-author provenance field test from work-classes.md — the same trust arms and babysit_loop_trusted_internal_bot_logins binding as the PR trust test, fail-closed when a field is absent. #501 passes on the OWNER/MEMBER arm and is actionable backlog — it blocks both drain exits (0-open-issues and drain-terminal) because it is neither human-gated, escalated, nor C5 on author provenance. #502 fails the test (NONE association, unlisted human author) and counts as human-gated for the drain-terminal limb even without a human-gated role label: the lane never works it. #503 passes on the listed-bot arm despite NONE association. #504 fails (unlisted structural bot). With #501 still open and actionable, the drain does not exit. Had #501 been closed leaving only #502–#504, the drain-terminal state applies: every remaining issue is either C5 on author provenance (#502, #504) or would still block if #503 alone remained without the others — but with only #502 and #504 open, both C5 on author provenance and no PR in flight, the lane stops cleanly with a final report rather than idling. The test is on provider metadata only — never a lookup of issue body text.",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Do not stop while the trusted-bot issue remains

In the counterfactual where closing #501 leaves issues #502#504 open, #503 is still neither C5 (it passed the listed-bot trust arm), human-gated, nor escalated, so the documented drain-terminal predicate requires the loop to continue. The expected output instead says that state is terminal and then silently switches to a different state containing only #502 and #504; this contradictory oracle can reward an implementation that exits prematurely when actionable trusted-bot intake remains. Split these into two explicit counterfactuals and reserve the clean exit for the state after #503 is also closed.

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

autonomy: no field-tested provenance signal exists for an issue's author

2 participants