From aacd1bd0397c7439b8f03017697c5ef9270c7260 Mon Sep 17 00:00:00 2001 From: busya Date: Fri, 2 Oct 2026 11:04:41 +0300 Subject: [PATCH] docs(dashboard-testing): retain Luna semantic audit of bcc69f4b --- ...mantic-audit-luna-bcc69f4b-2026-10-02.json | 480 ++++++++++++++++++ 1 file changed, 480 insertions(+) create mode 100644 specs/050-mcp-interface/evidence/semantic-audit-luna-bcc69f4b-2026-10-02.json diff --git a/specs/050-mcp-interface/evidence/semantic-audit-luna-bcc69f4b-2026-10-02.json b/specs/050-mcp-interface/evidence/semantic-audit-luna-bcc69f4b-2026-10-02.json new file mode 100644 index 000000000..3729206f6 --- /dev/null +++ b/specs/050-mcp-interface/evidence/semantic-audit-luna-bcc69f4b-2026-10-02.json @@ -0,0 +1,480 @@ +{ + "commit": "bcc69f4bbe02be9fab8e922c7d6b52cf0c43ded5", + "parent": "3406433b8f47e0834bbbe5895a49e9e433f0f705", + "model": "gpt-6-luna", + "scope": "Read-only audit of immutable commit vs parent; no worktree/index/staging edits. Source bytes obtained with git show COMMIT:path.", + "checks": { + "changed_paths": 766, + "changed_code_files_inventory": 311, + "test_code_files": 103, + "production_and_tool_code_files": 208, + "exact_region_pair_scan": "all 311 touched .py/.svelte/.ts/.js files; one nested test mismatch containing 3 mismatched closures", + "production_python_ruff_C901": "commit and parent snapshots; isolated ruff, C901, max-complexity=10; 52 commit findings vs 38 parent findings; introduced over-limit functions 17; existing over-limit functions worsened 14", + "production_module_size": "all touched code modules inventoried; 15 production modules >=400 LOC; all already >=400 in parent", + "svelte_UX_STATE": "all changed Svelte files checked against parent and commit; 2 existing components still lack @UX_STATE, with new UX states introduced in this commit", + "test_file_size": "touched test inventory checked against 600 LOC guidance and Testcontainers exception", + "configuration_anchor_review": "docker/full-flow/superset_config.py is a simple C2 configuration module with paired matching region markers; no missing-anchor or complex-module finding recorded" + }, + "counts": { + "findings": 55, + "introduced_C901_functions": 17, + "strengthened_C901_functions": 14, + "introduced_anchorless_modules": 3, + "anchor_pair_mismatch_groups": 1, + "new_Svelte_components_missing_UX_STATE": 0, + "new_overlong_test_files": 1, + "inherited_overlong_production_modules": 15, + "worsened_Svelte_components_missing_UX_STATE": 2 + }, + "findings": [ + { + "path": "backend/tests/services/dashboard_testing/scenario/test_registered_editor_authority.py", + "line": 83, + "invariant": "INV3", + "introduced_or_inherited": "introduced", + "severity": "high", + "evidence": "New nested Storage test helper opens Init, store, retrieve contracts but closes Init at line 84, store at 89, retrieve at 92; stack pairing mismatches all three IDs." + }, + { + "path": "docker/full-flow/seed_superset.py", + "line": 1, + "invariant": "INV1", + "introduced_or_inherited": "introduced", + "severity": "high", + "evidence": "New executable Python module has no #region/#endregion contract anywhere in commit blob." + }, + { + "path": "scripts/full-flow-env.py", + "line": 1, + "invariant": "INV1", + "introduced_or_inherited": "introduced", + "severity": "high", + "evidence": "New executable Python module has no #region/#endregion contract anywhere in commit blob." + }, + { + "path": "scripts/full-flow-ready.py", + "line": 1, + "invariant": "INV1", + "introduced_or_inherited": "introduced", + "severity": "high", + "evidence": "New executable Python module has no #region/#endregion contract anywhere in commit blob." + }, + { + "path": "frontend/src/lib/components/scenario-run/AgentEvaluationCard.svelte", + "line": 1, + "invariant": "INV4 / Svelte UX_STATE contract", + "introduced_or_inherited": "inherited omission; worsened by new UX states", + "severity": "medium", + "evidence": "Component existed in parent with no @UX_STATE; omission persists in commit. This diff adds localized verdict variants (pass/fail/inconclusive/unknown) and collapsible technical details/criterion IDs, creating new visual states that should be captured in the component FSM contract." + }, + { + "path": "frontend/src/lib/components/scenario-run/ScenarioResultView.svelte", + "line": 1, + "invariant": "INV4 / Svelte UX_STATE contract", + "introduced_or_inherited": "inherited omission; worsened by new UX states", + "severity": "medium", + "evidence": "Component existed in parent with no @UX_STATE; omission persists in commit. This diff adds selectable failure/metric steps, selected-step inspector behavior, metric evidence branches, and collapsible provenance/technical detail, creating new visual states that should be captured in the component FSM contract." + }, + { + "path": "backend/src/api/routes/git/_repo_routes.py", + "line": 66, + "invariant": "INV7 C901 <= 10", + "introduced_or_inherited": "introduced", + "severity": "high", + "evidence": "Ruff C901 reports init_repository complexity 12; repo setting backend/ruff.toml max-complexity=10." + }, + { + "path": "backend/src/mcp_server/tools_scenario.py", + "line": 676, + "invariant": "INV7 C901 <= 10", + "introduced_or_inherited": "introduced", + "severity": "high", + "evidence": "Ruff C901 reports register_draft_pack_tool complexity 23; repo setting backend/ruff.toml max-complexity=10." + }, + { + "path": "backend/src/plugins/git_fingerprint.py", + "line": 41, + "invariant": "INV7 C901 <= 10", + "introduced_or_inherited": "introduced", + "severity": "high", + "evidence": "Ruff C901 reports _compute_content_hash complexity 11; repo setting backend/ruff.toml max-complexity=10." + }, + { + "path": "backend/src/services/dashboard_testing/editor/apply.py", + "line": 85, + "invariant": "INV7 C901 <= 10", + "introduced_or_inherited": "introduced", + "severity": "high", + "evidence": "Ruff C901 reports apply_ops complexity 11; repo setting backend/ruff.toml max-complexity=10." + }, + { + "path": "backend/src/services/dashboard_testing/execution/evaluation_browser_scope.py", + "line": 13, + "invariant": "INV7 C901 <= 10", + "introduced_or_inherited": "introduced", + "severity": "high", + "evidence": "Ruff C901 reports validate_retained_browser_scope complexity 12; repo setting backend/ruff.toml max-complexity=10." + }, + { + "path": "backend/src/services/dashboard_testing/execution/evaluation_text.py", + "line": 27, + "invariant": "INV7 C901 <= 10", + "introduced_or_inherited": "introduced", + "severity": "high", + "evidence": "Ruff C901 reports _owned_receipts complexity 13; repo setting backend/ruff.toml max-complexity=10." + }, + { + "path": "backend/src/services/dashboard_testing/execution/evaluation_text_transport.py", + "line": 31, + "invariant": "INV7 C901 <= 10", + "introduced_or_inherited": "introduced", + "severity": "high", + "evidence": "Ruff C901 reports submit_recipe_text complexity 13; repo setting backend/ruff.toml max-complexity=10." + }, + { + "path": "backend/src/services/dashboard_testing/execution/metric_actual.py", + "line": 25, + "invariant": "INV7 C901 <= 10", + "introduced_or_inherited": "introduced", + "severity": "high", + "evidence": "Ruff C901 reports scalar_from_wire complexity 11; repo setting backend/ruff.toml max-complexity=10." + }, + { + "path": "backend/src/services/dashboard_testing/execution/providers/browser_readonly_flows_nav.py", + "line": 150, + "invariant": "INV7 C901 <= 10", + "introduced_or_inherited": "introduced", + "severity": "high", + "evidence": "Ruff C901 reports extract_table_flow complexity 11; repo setting backend/ruff.toml max-complexity=10." + }, + { + "path": "backend/src/services/dashboard_testing/execution/providers/browser_scoped_filter.py", + "line": 106, + "invariant": "INV7 C901 <= 10", + "introduced_or_inherited": "introduced", + "severity": "high", + "evidence": "Ruff C901 reports apply_scoped_native_filter complexity 12; repo setting backend/ruff.toml max-complexity=10." + }, + { + "path": "backend/src/services/dashboard_testing/execution/runner_plan.py", + "line": 151, + "invariant": "INV7 C901 <= 10", + "introduced_or_inherited": "introduced", + "severity": "high", + "evidence": "Ruff C901 reports derive_runner_plan complexity 12; repo setting backend/ruff.toml max-complexity=10." + }, + { + "path": "backend/src/services/dashboard_testing/scenario/metric_admission.py", + "line": 40, + "invariant": "INV7 C901 <= 10", + "introduced_or_inherited": "introduced", + "severity": "high", + "evidence": "Ruff C901 reports validate_metric_admission complexity 11; repo setting backend/ruff.toml max-complexity=10." + }, + { + "path": "backend/src/services/dashboard_testing/scenario/metric_binding.py", + "line": 88, + "invariant": "INV7 C901 <= 10", + "introduced_or_inherited": "introduced", + "severity": "high", + "evidence": "Ruff C901 reports validate_metric_graph complexity 13; repo setting backend/ruff.toml max-complexity=10." + }, + { + "path": "scripts/full_flow/profile.py", + "line": 13, + "invariant": "INV7 C901 <= 10", + "introduced_or_inherited": "introduced", + "severity": "high", + "evidence": "Ruff C901 reports profile complexity 11; repo setting backend/ruff.toml max-complexity=10." + }, + { + "path": "scripts/stage6_soak/audit.py", + "line": 40, + "invariant": "INV7 C901 <= 10", + "introduced_or_inherited": "introduced", + "severity": "high", + "evidence": "Ruff C901 reports assess complexity 15; repo setting backend/ruff.toml max-complexity=10." + }, + { + "path": "scripts/stage6_soak/audit.py", + "line": 101, + "invariant": "INV7 C901 <= 10", + "introduced_or_inherited": "introduced", + "severity": "high", + "evidence": "Ruff C901 reports retained_run complexity 13; repo setting backend/ruff.toml max-complexity=10." + }, + { + "path": "scripts/stage6_soak/collector.py", + "line": 129, + "invariant": "INV7 C901 <= 10", + "introduced_or_inherited": "introduced", + "severity": "high", + "evidence": "Ruff C901 reports collect complexity 15; repo setting backend/ruff.toml max-complexity=10." + }, + { + "path": "backend/src/api/routes/git/_repo_lifecycle_routes.py", + "line": 228, + "invariant": "INV7 C901 <= 10", + "introduced_or_inherited": "strengthened inherited violation", + "severity": "medium", + "evidence": "Ruff C901 complexity increased 11 -> 13; remains above repository max 10." + }, + { + "path": "backend/src/core/utils/llm_http.py", + "line": 436, + "invariant": "INV7 C901 <= 10", + "introduced_or_inherited": "strengthened inherited violation", + "severity": "medium", + "evidence": "Ruff C901 complexity increased 16 -> 19; remains above repository max 10." + }, + { + "path": "backend/src/mcp_server/tools_authoring.py", + "line": 61, + "invariant": "INV7 C901 <= 10", + "introduced_or_inherited": "strengthened inherited violation", + "severity": "medium", + "evidence": "Ruff C901 complexity increased 36 -> 37; remains above repository max 10." + }, + { + "path": "backend/src/mcp_server/tools_scenario.py", + "line": 328, + "invariant": "INV7 C901 <= 10", + "introduced_or_inherited": "strengthened inherited violation", + "severity": "medium", + "evidence": "Ruff C901 complexity increased 41 -> 58; remains above repository max 10." + }, + { + "path": "backend/src/services/dashboard_testing/execution/providers/browser.py", + "line": 100, + "invariant": "INV7 C901 <= 10", + "introduced_or_inherited": "strengthened inherited violation", + "severity": "medium", + "evidence": "Ruff C901 complexity increased 37 -> 38; remains above repository max 10." + }, + { + "path": "backend/src/services/dashboard_testing/execution/providers/browser.py", + "line": 114, + "invariant": "INV7 C901 <= 10", + "introduced_or_inherited": "strengthened inherited violation", + "severity": "medium", + "evidence": "Ruff C901 complexity increased 35 -> 36; remains above repository max 10." + }, + { + "path": "backend/src/services/dashboard_testing/execution/providers/browser_admission.py", + "line": 69, + "invariant": "INV7 C901 <= 10", + "introduced_or_inherited": "strengthened inherited violation", + "severity": "medium", + "evidence": "Ruff C901 complexity increased 19 -> 21; remains above repository max 10." + }, + { + "path": "backend/src/services/dashboard_testing/execution/providers/browser_native_filter.py", + "line": 408, + "invariant": "INV7 C901 <= 10", + "introduced_or_inherited": "strengthened inherited violation", + "severity": "medium", + "evidence": "Ruff C901 complexity increased 11 -> 12; remains above repository max 10." + }, + { + "path": "backend/src/services/dashboard_testing/registry/create.py", + "line": 96, + "invariant": "INV7 C901 <= 10", + "introduced_or_inherited": "strengthened inherited violation", + "severity": "medium", + "evidence": "Ruff C901 complexity increased 18 -> 19; remains above repository max 10." + }, + { + "path": "backend/src/services/dashboard_testing/scenario/chain_emission.py", + "line": 59, + "invariant": "INV7 C901 <= 10", + "introduced_or_inherited": "strengthened inherited violation", + "severity": "medium", + "evidence": "Ruff C901 complexity increased 11 -> 12; remains above repository max 10." + }, + { + "path": "backend/src/services/dashboard_testing/scenario/handles.py", + "line": 379, + "invariant": "INV7 C901 <= 10", + "introduced_or_inherited": "strengthened inherited violation", + "severity": "medium", + "evidence": "Ruff C901 complexity increased 25 -> 30; remains above repository max 10." + }, + { + "path": "backend/src/services/git/_merge.py", + "line": 245, + "invariant": "INV7 C901 <= 10", + "introduced_or_inherited": "strengthened inherited violation", + "severity": "medium", + "evidence": "Ruff C901 complexity increased 15 -> 18; remains above repository max 10." + }, + { + "path": "backend/src/services/git/_status.py", + "line": 61, + "invariant": "INV7 C901 <= 10", + "introduced_or_inherited": "strengthened inherited violation", + "severity": "medium", + "evidence": "Ruff C901 complexity increased 11 -> 13; remains above repository max 10." + }, + { + "path": "backend/src/services/git/_sync.py", + "line": 77, + "invariant": "INV7 C901 <= 10", + "introduced_or_inherited": "strengthened inherited violation", + "severity": "medium", + "evidence": "Ruff C901 complexity increased 18 -> 19; remains above repository max 10." + }, + { + "path": "backend/tests/test_mcp_scenario_e2e.py", + "line": 1, + "invariant": "semantics-testing test file <= 600 LOC", + "introduced_or_inherited": "introduced", + "severity": "medium", + "evidence": "Grew from 459 parent LOC to 603 commit LOC; not under tests/integration and no Testcontainers exception identified." + }, + { + "path": "backend/src/api/routes/git/_helpers.py", + "line": 1, + "invariant": "INV7 module < 400 LOC", + "introduced_or_inherited": "inherited; expanded in commit", + "severity": "medium", + "evidence": "Module is 427 LOC at commit (parent 425); already >=400 in parent, so not a new threshold crossing." + }, + { + "path": "backend/src/api/routes/git/_repo_lifecycle_routes.py", + "line": 1, + "invariant": "INV7 module < 400 LOC", + "introduced_or_inherited": "inherited; expanded in commit", + "severity": "medium", + "evidence": "Module is 690 LOC at commit (parent 676); already >=400 in parent, so not a new threshold crossing." + }, + { + "path": "backend/src/api/routes/git/_repo_operations_routes.py", + "line": 1, + "invariant": "INV7 module < 400 LOC", + "introduced_or_inherited": "inherited; expanded in commit", + "severity": "medium", + "evidence": "Module is 504 LOC at commit (parent 498); already >=400 in parent, so not a new threshold crossing." + }, + { + "path": "backend/src/api/routes/git_schemas.py", + "line": 1, + "invariant": "INV7 module < 400 LOC", + "introduced_or_inherited": "inherited; expanded in commit", + "severity": "medium", + "evidence": "Module is 612 LOC at commit (parent 600); already >=400 in parent, so not a new threshold crossing." + }, + { + "path": "backend/src/core/utils/llm_http.py", + "line": 1, + "invariant": "INV7 module < 400 LOC", + "introduced_or_inherited": "inherited; expanded in commit", + "severity": "medium", + "evidence": "Module is 735 LOC at commit (parent 695); already >=400 in parent, so not a new threshold crossing." + }, + { + "path": "backend/src/mcp_server/rbac_server.py", + "line": 1, + "invariant": "INV7 module < 400 LOC", + "introduced_or_inherited": "inherited; expanded in commit", + "severity": "medium", + "evidence": "Module is 506 LOC at commit (parent 503); already >=400 in parent, so not a new threshold crossing." + }, + { + "path": "backend/src/mcp_server/tools_authoring.py", + "line": 1, + "invariant": "INV7 module < 400 LOC", + "introduced_or_inherited": "inherited; expanded in commit", + "severity": "medium", + "evidence": "Module is 436 LOC at commit (parent 425); already >=400 in parent, so not a new threshold crossing." + }, + { + "path": "backend/src/mcp_server/tools_scenario.py", + "line": 1, + "invariant": "INV7 module < 400 LOC", + "introduced_or_inherited": "inherited; expanded in commit", + "severity": "medium", + "evidence": "Module is 945 LOC at commit (parent 841); already >=400 in parent, so not a new threshold crossing." + }, + { + "path": "backend/src/services/agent_authoring_workspace/service.py", + "line": 1, + "invariant": "INV7 module < 400 LOC", + "introduced_or_inherited": "inherited; expanded in commit", + "severity": "medium", + "evidence": "Module is 1004 LOC at commit (parent 1001); already >=400 in parent, so not a new threshold crossing." + }, + { + "path": "backend/src/services/dashboard_testing/execution/providers/browser_native_filter.py", + "line": 1, + "invariant": "INV7 module < 400 LOC", + "introduced_or_inherited": "inherited; expanded in commit", + "severity": "medium", + "evidence": "Module is 482 LOC at commit (parent 473); already >=400 in parent, so not a new threshold crossing." + }, + { + "path": "backend/src/services/dashboard_testing/execution/walker.py", + "line": 1, + "invariant": "INV7 module < 400 LOC", + "introduced_or_inherited": "inherited; expanded in commit", + "severity": "medium", + "evidence": "Module is 465 LOC at commit (parent 427); already >=400 in parent, so not a new threshold crossing." + }, + { + "path": "backend/src/services/dashboard_testing/query_model.py", + "line": 1, + "invariant": "INV7 module < 400 LOC", + "introduced_or_inherited": "inherited; expanded in commit", + "severity": "medium", + "evidence": "Module is 466 LOC at commit (parent 448); already >=400 in parent, so not a new threshold crossing." + }, + { + "path": "backend/src/services/dashboard_testing/scenario/handles.py", + "line": 1, + "invariant": "INV7 module < 400 LOC", + "introduced_or_inherited": "inherited; expanded in commit", + "severity": "medium", + "evidence": "Module is 589 LOC at commit (parent 525); already >=400 in parent, so not a new threshold crossing." + }, + { + "path": "backend/src/services/git/_branch.py", + "line": 1, + "invariant": "INV7 module < 400 LOC", + "introduced_or_inherited": "inherited; not expanded", + "severity": "low", + "evidence": "Module is 519 LOC at commit (parent 525); already >=400 in parent, so not a new threshold crossing." + }, + { + "path": "backend/src/services/git/_merge.py", + "line": 1, + "invariant": "INV7 module < 400 LOC", + "introduced_or_inherited": "inherited; expanded in commit", + "severity": "medium", + "evidence": "Module is 471 LOC at commit (parent 468); already >=400 in parent, so not a new threshold crossing." + }, + { + "path": "backend/tests/test_mcp_server.py", + "line": 1, + "invariant": "semantics-testing test file <= 600 LOC", + "introduced_or_inherited": "inherited", + "severity": "low", + "evidence": "1150 LOC at commit, 1145 in parent; oversize is inherited. Not counted as a new commit violation." + }, + { + "path": "backend/tests/services/git/test_git_status.py", + "line": 1, + "invariant": "semantics-testing test file <= 600 LOC", + "introduced_or_inherited": "inherited", + "severity": "low", + "evidence": "686 LOC at commit and parent; oversize is inherited." + } + ], + "limits": [ + "No behavioral or integration tests run, per audit scope.", + "The ~76 MB JSON/JSONL/PNG/log evidence payloads were treated as data and not read wholesale.", + "Contiguous metadata/contracts-first was structurally sampled on candidates rather than manually traced for all contracts; no complete claim for every nested definition or all semantic relations.", + "INV5 authority-override and INV6 incoming/history preservation were checked as audit concerns but not exhaustively graph-resolved: no Axiom MCP/index snapshot available; source-level diff scan is not proof of global incoming edges.", + "The complete C901 run covers touched production Python modules and tooling scripts from commit snapshot, excluding test files; Ruff isolated mode was used with the repository max complexity 10.", + "No source, index, staging area, or commit was modified; report written only under /tmp.", + "Svelte omissions on AgentEvaluationCard and ScenarioResultView predate this commit; classified as inherited omissions worsened by new interactions/presentation states introduced here, not as new components." + ] +}