fix(noema): expose structured failure kind - #1898
Conversation
Signed-off-by: Seongho Bae <me@seonghobae.me>
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Warning Review limit reachedNext included review available in 34 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Team Run ID: 📒 Files selected for processing (10)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Coordination note, no action needed from anyone right now: this PR and Generated by Claude Code |
Preserve PR #1898 runtime behavior and extend the existing HTTP error test across malformed values and length/control-character boundaries. Both the public annotation and raised diagnostic must obey the same field contract. The exact original head passed 123 tests with hash-locked tooling. Removing only failure-kind extraction/formatting reproduced 3 failures and 13 passing rejection cases; restoring it passed all 138 focused tests. No provider call, review approval, PR closure, or gate change is claimed. Co-Authored-By: Codex <noreply@openai.com> Signed-off-by: Seongho Bae <me@seonghobae.me>
Keep the existing failure_kind delta. Preserve bounded error.code from the protected gateway envelope in both failed-call diagnostics; do not infer failure cause from the HTTP exception label. The expanded field regression reproduced four failures before the fix; focused Noema and declared-pip environment regression: 159 passed. Co-Authored-By: Codex <noreply@openai.com> Signed-off-by: Seongho Bae <me@seonghobae.me>
Address the independent sparse-envelope finding while retaining the existing error telemetry implementation. Removing code extraction reproduced 8 failed/43 passed; restored field matrix 51 passed and focused Noema/edge/environment tests 176 passed. Remove one unused test import found by Ruff. Record the protected-source contract, unknown historical 502 cause, logging limits, separate verification stages, and APA logging guidance in the existing doctoring and gap baseline. Co-Authored-By: Codex <noreply@openai.com> Signed-off-by: Seongho Bae <me@seonghobae.me>
Non-force merge current protected main into #1641. Reject model-authored runtime, command-output, toolchain-help, and authoritative external-source claims unless a typed out-of-band receipt is explicitly cited. Preserve source-only reasoning, verification directions, exact-line evidence, and fail-closed findings. Grounded by ConceptWeave #35 review 5120903874 and Noema run 33938445009/job 101256294197, which executed no Cargo or documentation lookup. Removed both purpose-complete temporary writer workflows. Validation: 268 Noema tests; full 2,922 passed, 1 skipped, 21 subtests.
Resolve the remaining valid #1641 review findings. One unified-diff state machine now emits both exact source text and accepted coordinates. Bounded truncation drops the incomplete final line instead of manufacturing +/- source, so a genuine line equal to the historical omission marker remains reviewable. Focused RED reproduced both failures before the repair. GREEN: focused 3 passed; Noema 268 passed; full 2,922 passed, 1 skipped, 21 subtests; py_compile and diff checks clean.
|
Dependency-order restack (2026-09-05 UTC) #1641 and #1898 both modified the canonical Noema validator from protected
The provenance receipt boundary, unified diff parser, whitespace-only evidence guard, and bounded |
|
Writer handoff — source writer released The bounded source integration and local verification for this PR are complete. There is no active #1898 source-writing process or verification command in this automation.
Those results belong to this local execution only. They do not transfer predecessor coverage or replace fresh exact-head hosted checks/review. The originating read-only audit may safely continue without treating this automation as an active competing writer. No source, rerun, model call, approval, or merge was performed in this handoff. |
|
Ordinary non-force integration of the updated #1641 dependency root is complete. Exact #1898 head:
Fresh checkout GREEN on that exact combined head:
This integrates strict outbound-schema/local-validator parity and the corrected invalid-location telemetry fixture without transferring the predecessor |
|
Protected main adoption is now included through the current #1641 dependency root. Current #1898 exact head: Fresh exact-head results:
No predecessor GREEN, historical review, or prior coverage was transferred. No rerun, model call, self-approval, bypass, or protected merge was issued. #1898 source/verification writer is released at |
Current integration receipt — 2026-09-05
Exact head:
a7afb39d8c9e6b1b20857e378a236f566c94ff36; tree:fdf57270e965050f7c781ef40303af48d5e6dd3c; protected base:f250638827f8252b0d9e5cb2601f4d333f96162f. The existingdf0f735f42adbb44d45f3c3a4e503e400b47ed79failure-kind delta and the merged #1922 prerequisite are preserved by ordinary merges. This same PR branch was pushed without force; no closure, approval, ruleset change, or merge was performed.Causal repair and evidence boundary
The original patch handles optional
error.detail.failure_kind. Protected contextual-orchestratora080297d2546bb61e89520d637cabc202db331ecalready returnserror.code=invalid_structured_outputfor a structured-response error but that path has no failure kind, model, or attempt list. The consumer was discarding this existing classification. It now retains canonicalerror.codeindependently, using the same bounded reader and identifier validator in both the single failure annotation and the raised diagnostic.CO #1004's typed exhaustion detail remains proposed, not a released dependency or proof of the cause of Naruon #1244's historical 502. Noema still makes one gateway request and fails on the returned error; no provider routing, paid fallback, retry, timeout, or semantic-approval rule changed. Identifier format checking is not arbitrary secret detection. Free-form messages, request identifiers, and unrelated body fields remain excluded.
The existing doctoring record and G-02/G-03 baseline carry exact producer/API/log links, alternatives, OWASP APA 7 grounding, regression history, ownership, and remaining delivery gates. CHANGELOG records the observable maintenance benefit without claiming incident resolution.
Verification on the unchanged candidate
GITHUB_ACTIONS=truefull suite: 2940 passed, 1 skipped, 21 subtests passed (141.22 s). Five measured modules: 1512 statements / 606 branches, 100%; Noema alone: 854 statements / 384 branches, 100%.pip==26.2.1tool. The initial missing-pip failure was corrected in the environment, not hidden or converted into a source change. This is not claimed as a fully hash-locked clean install or hosted Python 3.14 execution.Commands (repository root, task-local environment):
JUnit SHA-256: normal
9cec553a5a503cbf1ba529eafdb79f8b82951aa978c2fa232816ede3d44608a5; CIbe8f30f2c08c451c747f3a2c3def264674cd47c8fb6fc3eca7f77d7ae136c881. Coverage JSON SHA-256:3ccad4837f674d8028e4ce83cbe83e1a95ea12eb45f283fb0d11ee3ac7e4df7e.Remaining protected-delivery work
New exact-head quality run 33962985324, Noema run 33962984599, security scans, and independent review are queued/pending after the push. Preserve those handles and re-fetch terminal evidence; do not repeat dispatches or borrow old-head passes. The separate maintainer exception reported for #1922 does not authorize bypass for this PR. Local checks do not prove protected merge, release, real PostgreSQL/browser operation, or a deployed gateway fix.
Historical original receipt
The text below describes the original
df0f735proposal and its 123-test run. Its mention of CO #1004 is proposed-contract context, not a claim that the current protected structured-error path already emits that field.문제
contextual-orchestrator가 안전한 HTTP 오류 detail에
failure_kind=structured_output_exhausted를 제공해도 중앙 Noema는 해당 필드를 allowlist하지 않아 Actions 로그에서 구조화 응답 실패 원인을 버렸습니다.수정
failure_kind를 수용합니다.structured_output_exhausted전달과 비밀 비노출을 검증합니다.검증
uv run pytest -q tests/test_noema_review_gate.py tests/test_noema_model_output_edge_coverage.pygit diff --check#1004가 제공하는 typed structured-output detail과 중앙 Noema telemetry를 연결합니다.