Repository navigation
test(arch): adapter-privilege ratchet over endpoints, CLI, jobs and seeders (#846) - #878
Conversation
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Local Codex review round on 29b8c48 (CodeRabbit is rate-limited across the four open PRs; its round for this PR is scheduled for 22:35 UTC). Three findings, all confirmed and fixed in 71f40a1, each with a regression test:
Stopping the local review loop here, deliberately; the CodeRabbit round still lands and will be handled. Verification: |
|
Codex (gpt-5.6-sol) review of record on 71f40a1, in lieu of the CodeRabbit bot per the owner's decision: the three earlier fixes verified present; three findings, all confirmed and fixed in 2891b3d with regression tests:
Verification: |
|
Codex (sol) round 2 on 2891b3d: the three fixes verified complete; one new finding, that same-path routes under different verbs shared one top-level adapter symbol so one handler's allowance covered the other. Fixed in a67a461: the symbol now includes the mapping method ( |
|
Codex (sol) round 3 on a67a461: fix complete, no regression. Merge order: after #877 (its base); retarget to |
2ae22dc to
89fd87d
Compare
a67a461 to
a0c1eca
Compare
89fd87d to
0c2bd14
Compare
a0c1eca to
94bc574
Compare
…eeders (#846) Walk 397 adapters with 147 generated non-empty reach rows. Share the module ledger's owner resolution and parse options. Apply the persistence hard failure only to endpoints; CLI verbs, jobs and seeders retain their Platform-side persistence access. Real-tree mutations, each reverted with git checkout -- src: - Mutation 1 RED: ExpenseEndpoints.ListExpenses -> Commerce through Cluckwork.Application.Features.Catalog.IProductRepository. - Mutation 2 RED: forbidden persistence type Cluckwork.Infrastructure.Persistence.AppDbContext in ExpenseEndpoints.ListExpenses. - Mutation 3 GREEN: removing IFlockRepository from ListExpenses leaves Loosenable: ExpenseEndpoints.ListExpenses -> FlockManagement. - Mutation 4 RED: MigrateCliCommand.RunAsync -> FlockManagement through Cluckwork.Application.Features.Flocks.CreateFlock.CreateFlockHandler. Logs: /tmp/514/mutations-846/{1-commerce-parameter,2-endpoint-dbcontext, 3-remove-flock-parameter,4-cli-flock-service}.txt Validation: dotnet build Cluckwork.sln, zero warnings and errors; dotnet test tests/Cluckwork.Application.Tests, 406 passed.
…rule (#846) Record the ceiling, endpoint-only persistence ban, deliberate adapter over-approximation, syntax resolution limits and four mutation results. Link the rule under Application shape and index the decision record.
…tion in the adapter ratchet (#846) Attribute typed inline lambda parameters to their enclosing adapter and inspect typeof arguments of service resolutions. Recognize optional keyed service calls alongside required keyed calls. Add 14 temp-tree regression cases: 12 red before the scanner fix, with both untyped-lambda cases already green. Regenerate three new mapping-method rows for Products, Egg Grades and Inventory: 147 -> 150 rows, 397 adapters. Update the decision record and AGENTS.md coverage description. Mutation 5 RED: forbidden persistence type Cluckwork.Infrastructure.Persistence.AppDbContext in Cluckwork.Api.Endpoints.EggGrades.EggGradeEndpoints.MapEggGradeEndpoints at src/Cluckwork.Api/Endpoints/EggGrades/EggGradeEndpoints.cs:37. Output: /tmp/514/mutations-846/5-lambda-dbcontext.txt. Reverted with git checkout -- src. Validation: dotnet build Cluckwork.sln, zero warnings and errors; dotnet test tests/Cluckwork.Application.Tests, 420 passed.
… every resolver API in the adapter ratchet (#846) Select direct routes from ledger-listed top-level programs and attribute handler reach to the route literal or method-group name. Resolve local functions and source method groups without scanning unrelated composition. Collect nested local-function and anonymous-method parameters alongside lambda parameters. Use one resolver table for generic and typeof calls, including collection, keyed collection and ActivatorUtilities resolvers. The real Program.cs has three adapters; all have empty module reach. The walk now counts 400 adapters. Regeneration leaves all 150 rows unchanged. Add 29 temp-tree regression cases and update the coverage decision record. Mutation 5 RED: forbidden AppDbContext in EggGradeEndpoints.MapEggGradeEndpoints at EggGradeEndpoints.cs:37. Mutation 6 RED: forbidden AppDbContext in Cluckwork.Api.Program./probe at src/Cluckwork.Api/Program.cs:573. Outputs: /tmp/514/mutations-846/5-lambda-dbcontext.txt and /tmp/514/mutations-846/6-program-mapget-dbcontext.txt. Revert each mutation with git checkout -- src. Validation: dotnet build Cluckwork.sln, zero warnings and errors; dotnet test tests/Cluckwork.Application.Tests, 449 passed.
…846) Separate GET and POST reach allowances for the same route. Include literal HTTP method lists for MapMethods and retain method-group names after the route. Normalize literal method sets independently of source formatting. Add regression cases proving that an allowance for one verb, method list or handler does not excuse another. Update existing route-key assertions and the documented identity. Regeneration produces the same 150 ledger rows: all three real Program.cs adapters still have no module reach. No src change. Validation: dotnet build Cluckwork.sln, zero warnings and errors; dotnet test tests/Cluckwork.Application.Tests, 455 passed.
94bc574 to
6b9c8ef
Compare
…e walks (#848) (#879) Closes #848 Slice 6 of #514 (modular monolith), Track B. **Enforcement only.** No `src/` file, no CI change, no package. **Stacked on #878** (base `chore/846-adapter-ratchet`), which stacks on #877 and #872. Retarget after those merge; until then CI does not run here and the closing link is inert, so the guards were run locally (below). ## What this adds - `Architecture/CouplingMatrix.cs`: a pure generator that renders the coupling matrix from the ledger plus the three walks (module edges, table census, adapter reach). A module-to-module cell is the ledger's kind letter with the live symbol count (`W (8)`), plus `fk:<n>` when the table census has cross-owner foreign keys in that direction; the Platform column is `P` (free hub); the Platform row is `A (n)`, the number of adapters reaching that module. `E` and `Q` are not syntactically observable and the file says so. - `Architecture/Data/coupling-matrix.md`: the committed output, generated and checked like `docs/schema/` (#417). `RealTree_CommittedMatrixMatchesRegeneration` regenerates from the real tree and asserts byte equality (unified diff on mismatch; `CLUCKWORK_REGENERATE_MATRIX=1` rewrites it). `RealTree_GeneratedModuleCellCensusMatchesLedgerEdges` pins that the generated cells and the ledger's edge set cannot drift. - The generator carries the design's 2026-08 §3.4 values as a constant purely to print the differences table, which is the last copy of the hand-written matrix anywhere in the repo. - `docs/decisions/848-generated-coupling-matrix.md` and one AGENTS.md bullet under Application shape. ## What the generated matrix says that the hand-written one did not Seven cells differ: five the hand-written matrix marked as no coupling (Access → Commerce `W`, Access → EggOperations `W`, Farm → Commerce `R`, Commerce → Access `R`, GeneralInventory → EggOperations `R fk:2`) and two whose letter was wrong (Access → Farm is `W`, Finance → Farm is `R`), each established and reasoned in #872's review rounds. ## Mutation evidence (each recorded red, then reverted before commit) | # | Mutation | Red line | |---|---|---| | 1 | `kind` removed from one ledger edge cell | `module-ledger registry error(s): 1` | | 2 | one cell of the committed matrix hand-edited | `coupling matrix differs:` followed by the unified diff | | 3 | the live Finance → FlockManagement ledger cell deleted | `undeclared cross-owner edge Finance -> FlockManagement …` and the census/ratchet drift assertion | ## Verification (local, since the stacked PR gets no CI) - `dotnet build Cluckwork.sln`: 0 warnings. - `Cluckwork.Application.Tests`: 424 passed. - `Documentation` tests and `SchemaDocsTests` green on the new markdown (run before opening). <details><summary>Mutation outputs</summary> **1-missing-kind.txt** ``` Cluckwork.Domain -> /home/mforce/.cluckwork-slices/848/src/Cluckwork.Domain/bin/Debug/net10.0/Cluckwork.Domain.dll Cluckwork.Application -> /home/mforce/.cluckwork-slices/848/src/Cluckwork.Application/bin/Debug/net10.0/Cluckwork.Application.dll Cluckwork.Infrastructure -> /home/mforce/.cluckwork-slices/848/src/Cluckwork.Infrastructure/bin/Debug/net10.0/Cluckwork.Infrastructure.dll Cluckwork.Application.Tests -> /home/mforce/.cluckwork-slices/848/tests/Cluckwork.Application.Tests/bin/Debug/net10.0/Cluckwork.Application.Tests.dll Test run for /home/mforce/.cluckwork-slices/848/tests/Cluckwork.Application.Tests/bin/Debug/net10.0/Cluckwork.Application.Tests.dll (.NETCoreApp,Version=v10.0) VSTest version 18.0.2 (x64) Starting test execution, please wait... A total of 1 test files matched the specified pattern. [xUnit.net 00:00:00.00] xUnit.net VSTest Adapter v4.0.0+05679a7ab5 (64-bit .NET 10.0.12) [xUnit.net 00:00:00.09] Discovering: Cluckwork.Application.Tests [xUnit.net 00:00:00.19] Discovered: Cluckwork.Application.Tests [xUnit.net 00:00:00.21] Starting: Cluckwork.Application.Tests [xUnit.net 00:00:02.53] Cluckwork.Application.Tests.Architecture.ModuleLedgerRealT ``` **2-hand-edited-matrix.txt** ``` Cluckwork.Domain -> /home/mforce/.cluckwork-slices/848/src/Cluckwork.Domain/bin/Debug/net10.0/Cluckwork.Domain.dll Cluckwork.Application -> /home/mforce/.cluckwork-slices/848/src/Cluckwork.Application/bin/Debug/net10.0/Cluckwork.Application.dll Cluckwork.Infrastructure -> /home/mforce/.cluckwork-slices/848/src/Cluckwork.Infrastructure/bin/Debug/net10.0/Cluckwork.Infrastructure.dll Cluckwork.Application.Tests -> /home/mforce/.cluckwork-slices/848/tests/Cluckwork.Application.Tests/bin/Debug/net10.0/Cluckwork.Application.Tests.dll Test run for /home/mforce/.cluckwork-slices/848/tests/Cluckwork.Application.Tests/bin/Debug/net10.0/Cluckwork.Application.Tests.dll (.NETCoreApp,Version=v10.0) VSTest version 18.0.2 (x64) Starting test execution, please wait... A total of 1 test files matched the specified pattern. [xUnit.net 00:00:00.00] xUnit.net VSTest Adapter v4.0.0+05679a7ab5 (64-bit .NET 10.0.12) [xUnit.net 00:00:00.09] Discovering: Cluckwork.Application.Tests [xUnit.net 00:00:00.18] Discovered: Cluckwork.Application.Tests [xUnit.net 00:00:00.21] Starting: Cluckwork.Application.Tests [xUnit.net 00:00:03.57] Cluckwork.Application.Tests.Architecture.CouplingMatrixRea ``` **3-deleted-finance-flock-edge.txt** ``` Cluckwork.Domain -> /home/mforce/.cluckwork-slices/848/src/Cluckwork.Domain/bin/Debug/net10.0/Cluckwork.Domain.dll Cluckwork.Application -> /home/mforce/.cluckwork-slices/848/src/Cluckwork.Application/bin/Debug/net10.0/Cluckwork.Application.dll Cluckwork.Infrastructure -> /home/mforce/.cluckwork-slices/848/src/Cluckwork.Infrastructure/bin/Debug/net10.0/Cluckwork.Infrastructure.dll Cluckwork.Application.Tests -> /home/mforce/.cluckwork-slices/848/tests/Cluckwork.Application.Tests/bin/Debug/net10.0/Cluckwork.Application.Tests.dll Test run for /home/mforce/.cluckwork-slices/848/tests/Cluckwork.Application.Tests/bin/Debug/net10.0/Cluckwork.Application.Tests.dll (.NETCoreApp,Version=v10.0) VSTest version 18.0.2 (x64) Starting test execution, please wait... A total of 1 test files matched the specified pattern. [xUnit.net 00:00:00.00] xUnit.net VSTest Adapter v4.0.0+05679a7ab5 (64-bit .NET 10.0.12) [xUnit.net 00:00:00.10] Discovering: Cluckwork.Application.Tests [xUnit.net 00:00:00.19] Discovered: Cluckwork.Application.Tests [xUnit.net 00:00:00.22] Starting: Cluckwork.Application.Tests [xUnit.net 00:00:01.99] Cluckwork.Application.Tests.Architecture.CouplingMatrixRea ``` </details>
Closes #846
Slice 4 of #514 (modular monolith), Track B. Enforcement only. No
src/file, no CI change, no package.Stacked on #877 (base
chore/845-table-owners), which stacks on #872. Retarget after those merge; until then CI does not run here and the closing link is inert, so the guards were run locally (below).What this adds
module-ledger.jsongainsadapterRoots(the namespaces and types that count as adapters:Cluckwork.Api.Endpoints,Cluckwork.Api.Cli,Cluckwork.Infrastructure.Jobs, the two seeders; and the namespaces where persistence types are forbidden outright:Cluckwork.Api.Endpoints) andadapters, one row per adapter with a non-empty reach: 147 rows today over 397 walked adapters (116 endpoint members, 25 seeder members, 6 CLI verbs).Architecture/AdapterReachScanner.cs: a syntax-only Roslyn walk. An adapter is every method, constructor or primary constructor declared in a type under the adapter roots (a private helper counts too: over-approximation only raises the ceiling). Its reach is the set of module owners resolved from its parameter types, their generic arguments, and the type arguments ofGetRequiredService<T>(),GetService<T>(),GetRequiredKeyedService<T>()andActivatorUtilities.CreateInstance<T>()in its body, resolving fully qualified, imported, aliased, relative and same-file names; Platform is excluded. An unmatched simple name is reported as unresolved, never guessed.AppDbContext,DbContext,DbSet<>orIQueryablein an endpoint is a hard failure; in CLI verbs, jobs and seeders they are Platform infrastructure and not counted.AdapterReachTests.cs(temp trees, one assertion per rule) andAdapterReachRealTreeTests.cs(the gate plus a floor of 40 adapters).docs/decisions/846-adapter-reach-ratchet.mdand one AGENTS.md bullet under Application shape.What the walk found
ListExpensesreaches Farm, Finance, FlockManagement and Insights: the audit repository interface lives inApplication.Features.Audit, which the ledger assigns to Insights.AppDbContextfor migrate, sweeps and seeding, which is why the persistence ban is endpoint-only (agent question during the build, answered and recorded in the decision record).Mutation evidence (each recorded, then reverted before commit)
IProductRepositoryparameter added toListExpensesundeclared adapter reach …ExpenseEndpoints.ListExpenses -> CommerceAppDbContextparameter added to an endpoint handlerforbidden persistence type … in …IFlockRepositoryparameter removed fromListExpensesFlockManagementlisted as loosenable (the ratchet proof)GetRequiredService<CreateFlockHandler>()added toMigrateCliCommand.RunAsync…MigrateCliCommand.RunAsync -> FlockManagementVerification (local, since the stacked PR gets no CI)
dotnet build Cluckwork.sln: 0 warnings.Cluckwork.Application.Tests: 406 passed.Documentationtests andSchemaDocsTestsgreen on the new markdown (run before opening).Mutation outputs
1-commerce-parameter.txt
2-endpoint-dbcontext.txt
3-remove-flock-parameter.txt
4-cli-flock-service.txt