Skip to content

chore(ci): ratchet Coverage Gate floors + add per-PR delta gate (ADR-0922) — recovery of #421 - #469

Merged
lusoris merged 2 commits into
masterfrom
chore/coverage-ratchet-aggressive-v2
May 31, 2026
Merged

lusoris merged 2 commits into
masterfrom
chore/coverage-ratchet-aggressive-v2

Conversation

@lusoris

@lusoris lusoris commented May 31, 2026 •

Copy link
Copy Markdown
Contributor

Recovery of PR #421 (force-pushed to master SHA by a broken auto-rebase script). Ratchets Coverage Gate floors aggressively + adds per-PR delta gate.

Absolute-floor ratchet (scripts/ci/coverage-check.sh):

  • OVERALL_MIN: 37 → 70 (raised from PR's original 60 because master already measures above 70%)
  • CRITICAL_MIN: 85 → 90
  • PER_FILE_MIN[core/src/dnn/ort_backend.c]: 78 → 83
  • PER_FILE_MIN[core/src/dnn/dnn_api.c]: 78 → 83
  • PER_FILE_MIN[core/src/dnn/tiny_extractor_template.h]: 10 → 15

New per-PR delta gate (scripts/ci/coverage-delta-check.sh): fails any PR that drops overall coverage by more than 0.5pp OR drops any touched file by more than 0.5pp vs the merge-base. Wired into the Coverage Gate job.

no state delta: coverage gate ratchet; no bug tracker entry; pure floor-hardening.

ADR-0108 deliverables checklist

🤖 Generated with Claude Code

@lusoris
lusoris marked this pull request as ready for review May 31, 2026 07:25
@lusoris
lusoris enabled auto-merge (squash) May 31, 2026 07:25
@lusoris
lusoris force-pushed the chore/coverage-ratchet-aggressive-v2 branch from 0728209 to e9b078b Compare May 31, 2026 07:33
@lusoris
lusoris marked this pull request as draft May 31, 2026 09:01
auto-merge was automatically disabled May 31, 2026 09:01

Pull request was converted to draft

@lusoris
lusoris marked this pull request as ready for review May 31, 2026 11:56
@lusoris
lusoris force-pushed the chore/coverage-ratchet-aggressive-v2 branch from e9b078b to 6dccc69 Compare May 31, 2026 11:56
@lusoris
lusoris merged commit f0eee51 into master May 31, 2026
@lusoris
lusoris deleted the chore/coverage-ratchet-aggressive-v2 branch May 31, 2026 11:57
lusoris added a commit that referenced this pull request May 31, 2026
…oors (#508)

PR #469 ratcheted the Coverage Gate floors:
  - OVERALL_MIN: 37% -> 70%
  - CRITICAL_MIN: 85% -> 90%
  - PER_FILE_MIN[dnn_api.c]: 78% -> 83%
  - PER_FILE_MIN[ort_backend.c]: 78% -> 83%
  - PER_FILE_MIN[tiny_extractor_template.h]: 10% -> 15%
  + new per-PR delta gate (scripts/ci/coverage-delta-check.sh)

The last successful master CI run (21597ff, 2026-05-31 10:53) reported
read_json_model.c at 88.4% and model_loader.c at 86.9% — both now below
the new 90% critical floor. This PR adds 31 unit tests targeting the
under-floor paths.

After this PR (unit-test-only measurement, container build matches CI
flags: -Db_coverage=true -Denable_float=true -Denable_avx512=true
-Denable_dnn=enabled -Dc_args=-fprofile-update=atomic):

  core/src/read_json_model.c       88.00% -> 92.00%  (+4.00pp)  PASS
  core/src/dnn/model_loader.c      87.20% -> 90.00%  (+2.80pp)  PASS
  core/src/dnn/dnn_api.c           83.40%             (unchanged) PASS
  core/src/dnn/dnn_attach_api.c    92.00%             (unchanged) PASS
  core/src/dnn/ort_backend.c       78.90%             (unchanged) FAIL (*)
  core/src/dnn/onnx_scan.c         93.40%             (unchanged) PASS
  core/src/dnn/op_allowlist.c     100.00%             (unchanged) PASS
  core/src/dnn/tensor_io.c         99.30%             (unchanged) PASS
  core/src/opt.c                  100.00%             (unchanged) PASS

(*) ort_backend.c's remaining uncovered lines are ORT-API error-status
branches and non-CPU execution-provider success branches. On CPU-only
ORT builds (current CI runner) the EP try_append_{cuda,openvino,coreml,
rocm} calls all return non-zero and the conditional `sess->ep_name = ...`
assignments are unreachable; the GetTensorElementType-failure / calloc-
failure branches require ORT-API mock injection. The structural
ceiling on this configuration is ~79%. Pushing above 83% needs either:
  (a) ORT-API mocking via the ort_backend_internal.h test hook, or
  (b) a working CUDA / OpenVINO EP on the CI runner.

New tests by file:

  core/test/test_model.c (+17 tests):
    test_json_model_slopes_not_array
    test_json_model_intercepts_not_array
    test_json_model_feature_names_not_array
    test_json_model_feature_opts_dicts_not_array
    test_json_model_model_payload_not_string
    test_json_model_chroma_correction_not_number
    test_json_model_score_clip_min_not_number
    test_json_model_score_clip_max_not_number
    test_json_model_score_transform_poly_null_disables
    test_json_model_score_transform_knots_null_disables
    test_json_model_score_transform_bool_str_not_string
    test_json_model_unrecognised_model_dict_key
    test_json_model_intercepts_mid_not_number
    test_json_model_score_transform_poly_number_sets_value
    test_json_model_score_transform_poly_string_rejects
    test_json_model_score_transform_knots_array_walks

  core/test/dnn/test_model_loader.c (+13 tests):
    test_sidecar_encoder_vocab_malformed_no_leak
    test_sidecar_empty_arrays_are_valid
    test_sidecar_encoder_vocab_over_max_returns_erange
    test_sidecar_array_trailing_junk_wipes
    test_sidecar_array_non_string_element_wipes
    test_sidecar_opset_overflow_returns_default
    test_sidecar_feature_mean_trailing_junk
    test_sidecar_quant_mode_static
    test_sidecar_quant_mode_qat
    test_sidecar_kind_filter
    test_codec_block_fill_aliases_hevc_av1_vp9_vvc
    test_codec_block_fill_preset_slower
    test_codec_block_fill_null_vocab_entry_is_skipped

  core/test/dnn/test_ort_internals.c (+1 test):
    test_ort_run_multi_output_smoke

Verification:
  meson test -C core/build-coverage --num-processes 1
  -> 85/85 PASS (including all 31 new tests)

Each new test exercises at least one previously-uncovered branch
identified from the CI master-tip gcovr txt summary (run 26710610282,
sha 21597ff). No production code changed; no golden assertions or
places= tolerances touched.

This PR does NOT close the OVERALL 70% floor (current unit-test-only
measurement at 47.6%). CI's overall measurement is higher because the
Coverage Gate job also runs the full Python test suite under the
instrumented libvmaf.so / vmaf CLI. Pushing the unit-test-only overall
above 70% would require porting ~300 Python tests into native C tests
— out of scope for a single PR. The last successful master CI showed
overall at 45.6% — the new 70% floor will trip on master itself until
the per-file ratchet's measurement assumptions are reconciled.

Closes part of the PR #469 ratchet gap; ort_backend.c + overall remain
follow-ups.

Co-authored-by: Lusoris <lusoris@pm.me>
Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
@lusoris lusoris added this to the 1.0.0 — First release milestone Sep 4, 2026
lusoris added a commit that referenced this pull request Sep 16, 2026
`scripts/ci/check-state-md-rows.sh` enforces ADR-0165's "every bug id
appears exactly once" rule, and reported a file carrying 33 duplicated
rows as clean. It matched only `| **T-ID**`:

- non-bold ids hid 95 of 576 id-bearing rows (17%), among them a
  byte-identical duplicate of `T-CUDA-MUL24-AUDIT-2026-05-28`;
- `Netflix#NNN` rows were never matched at all — 34 rows carrying 13
  duplicate pairs;
- `**T6-1**` / `**T7-16**` tranche ids added four more;
- ~143 rows open with prose and carry no id, so no id-based check can
  reach them; 13 of those were duplicated too.

The reporting path had a second, independent bug: it located hits with a
bold-only pattern, so every non-bold duplicate printed "appears on
lines:" followed by nothing. Detection and reporting now share one awk
extraction rule, which is what made that divergence possible.

Added a shape-independent verbatim-row check for the prose-led rows. It
normalises away the `_(verified YYYY-MM-DD: ...)_` annotation a later
verification sweep appends to one copy — without that, a row and its own
annotated duplicate compare unequal and the check reports clean. Column
headers repeat once per section by design and are excluded; counting
them was a false positive that this gate's own test fixture caught.

All 33 duplicates are resolved. **The resolution direction is not
uniform.** Most pairs keep the later copy, which carries the
verification annotation and in two cases resolves "this PR" to the real
PR number. But `T6-2` keeps the *earlier* copy — it says PR #469 is
merged where the later says it is still in flight — and
`Netflix/vmaf#1494` keeps the earlier copy, which records ADR-1191 as
closed where the later does not. A blanket "delete the first occurrence"
would have silently reverted two bugs to an older state. Every pair was
read before either copy was deleted, and each deletion was verified to
leave its twin byte-identical in the file.

No ADR: the gate's contract is unchanged, ADR-0165 already states it.
This is the implementation catching up with it.

Six new cases cover the four id shapes, the prose-led-plus-suffix shape
and the header false positive; all twelve pass, shellcheck is clean, and
`pre-commit run --all-files` is green.

Closes ledger L-05.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant