Skip to content

test(docs): keep CodeGraph agent guidance code-current - #333

Draft
seonghobae wants to merge 3 commits into
mainfrom
codex/codegraph-guidance-current-20260912
Draft

test(docs): keep CodeGraph agent guidance code-current#333
seonghobae wants to merge 3 commits into
mainfrom
codex/codegraph-guidance-current-20260912

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 11, 2026

Copy link
Copy Markdown
Contributor

Finding

Fresh protected-main inventory found an executable documentation drift: the repository contains .codegraph/, but protected AGENTS.md still stated that no .codegraph/ index existed and directed agents to fall back to plain text search. That contradicted the live repository capability and the standing code-exploration contract.

This is a bounded Wardnet-owned developer-operability/documentation correction. It does not change gateway/SOC policy, Agent Artifact Admission, quarantine, egress, LLM orchestration, appguardrail, Context Graph or EA authority.

Hosted hostile RED

Exact test-only head ae89b6f510bbeb4fc21c8ef0161e22779ece2fe8 added one architecture-fitness regression while production/runtime source remained unchanged from protected main@f8260f1e03836039ff9463dd99fa982e4e270c4b.

Hosted CI 34639380286, rust job 103395055797, acquired GitHub-hosted Ubuntu 24.04, completed checkout/toolchain/formatting and all 142 existing library tests, then failed exactly in codegraph_guidance_matches_repository_state because AGENTS.md denied the live .codegraph/ capability. This is the intended documentation-contract RED, not runner/bootstrap noise.

Minimum causal repair

3ecb054ac9d4f30fcad888b6f0a926baafdbcb2e changed only the stale Code exploration paragraph in AGENTS.md: it now records the live .codegraph/ index, directs agents to prefer CodeGraph/code-review-graph for caller/callee/impact exploration, and retains ordinary grep/ripgrep/Cargo/editor navigation only when the index cannot answer the query.

The first post-fix CI 34639598846, rust job 103395771168, exposed a test-oracle defect rather than a product defect: the assertion looked for case-sensitive prefer CodeGraph while the repaired prose correctly began the sentence with Prefer CodeGraph. All existing runtime tests passed. Exact successor 7a12973c9d844abb2bf91b1aabf0cbee0de75272 makes only that regression assertion case-stable by normalizing the guidance text before matching; product/documentation semantics are unchanged.

Exact-current evidence

Current head is exact 7a12973c9d844abb2bf91b1aabf0cbee0de75272 on unchanged protected base main@f8260f1e03836039ff9463dd99fa982e4e270c4b; GitHub reports the Draft mechanically mergeable.

  • CI 34639707970SUCCESS.
  • Security Scan 34639707972SUCCESS.
  • SAST Semgrep 34639707971SUCCESS.
  • CodeQL PR 34639707968non-passing central settlement, with clean exact-head scan. Initial compatibility job 103396322555 failed closed pending. One bounded rerun only (103397206132, attempt 2) also failed closed before terminal central evidence was visible. The later exact central identity run .github@34640269326, job 103397993301, proves the Wardnet scan itself is clean: CodeQL initialize/analyze and the SARIF gate succeeded with exact log CODEQL_SARIF files=1 results=0 medium_plus=0, and SARIF artifact codeql-dispatch-actions-34640269326-1 / id 10279782945 was preserved. The central job becomes FAILURE only afterward: target-head status publication is rejected with HTTP 403 for both available credentials, and Wake exact CodeQL required job fails because GH_TOKEN is empty and WAKE_TOKEN_SOURCE=unavailable (Actions-capable CodeQL wake credential is unavailable.). This is central .github control-plane settlement, not a Wardnet source finding. Exact root cause/acceptance is handed to .github#1929 comment 5639822896; no further leaf rerun or source churn is justified until central settlement advances.
  • submitted reviews: 0.
  • inline review threads: 0.

Keep Draft until every then-live exact-head required gate is terminal-valid and live governance permits ordinary protected integration. No source churn solely to redispatch, central-workflow copy, synthetic status, force update, destructive rebase, self/model approval, gate weakening, predecessor-evidence promotion, or routine administrator bypass.

@coderabbitai

coderabbitai Bot commented Sep 11, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working priority: high High-priority or P1 work

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant