Skip to content

Add a read-only metrics report over the ledger and git (vision step 2b) - #33

Merged
dsnger merged 5 commits into
mainfrom
passive-metrics
Oct 2, 2026
Merged

dsnger merged 5 commits into
mainfrom
passive-metrics

Conversation

@dsnger

@dsnger dsnger commented Oct 1, 2026 •

Copy link
Copy Markdown
Owner

What

scripts/ledger-metrics.py is a read-only report over docs/hardening-log.md and the review-cycle records in commit bodies. It is dark-factory vision step 2b. It shows:

  • which fingerprints recur, and how each rung was followed;
  • every cycle's provenance line, curve and skip record, beside the fic2 baseline;
  • the evidence for the floor-1 checkpoint;
  • a list of what the report cannot answer.

It computes no shares or verdicts, writes nothing, and is not shipped in the plugin.

Run it with: python3 scripts/ledger-metrics.py [<ref>]

scripts/ledger-metrics.test.sh is its POSIX-sh suite: 31 cases. It is now part of the quality row, the lint row and CI. AGENTS.md, README.md and the CI comments count it. CLAUDE.md no longer says the metrics consumer "does not exist yet".

Spec: docs/superpowers/specs/2026-10-01-passive-metrics-design.md · Plan: docs/superpowers/plans/2026-10-01-passive-metrics.md · Story: docs/superpowers/stories/2026-08-04-passive-metrics-over-the-ledger-story.md (profile confirmed 2026-10-01: standard / none / battery+check)

Review record

  • Gate A spec, cycle mbu2nfkahz: 4 passes for the awk revision, Majors 14→0 (c60b78b).
  • Gate A plan pass 1 found that awk could not parse the quoted §5 records. Daniel chose Python.
  • Gate A spec, cycle p9yvzn4fvi: 3 passes for the Python revision (49b90f8).
  • Gate A plan, cycle mtf7ua7qze: 6 passes, Majors 16,5,1,1,3,0 (9230e4f).
  • Gate B, cycle 08x02c2od1: pass 1 had one Minor, which got a new test; pass 2 had no findings in either branch.

What no check covers

  • The curves are author-written and unchecked, and the report says so.
  • An undecodable byte and a transient shallow boundary are stated limits, printed in the report.
  • CI is the first run under Ubuntu's python3.

Summary by CodeRabbit

  • New Features
    • Added a read-only report summarizing recurring hardening findings, progress through hardening levels, and review-cycle trends against a baseline. The report can also flag irregular records and incomplete history.
  • Documentation
    • Added guidance on the report and its checks, including the Python version required to run its regression suite.
  • Tests
    • Added automated regression checks for report output and error handling.

dsnger added 4 commits October 1, 2026 15:54
…the story

Dark-factory vision step 2b. A repo-local, read-only script reports
fingerprint recurrence and rung holding from docs/hardening-log.md, and the
review-cycle records (provenance line, curve, skip record) from commit
bodies, side by side with the fic2 baseline. It computes no shares or
verdicts. The story header now carries the profile Daniel confirmed on
2026-10-01 (standard / none / battery+check) and the placement decision
(repo-local script, not shipped).

Gate-A spec cycle closed. Pass 4 is clean at the derived floor: 0 Blockers
and 0 Majors, and every earlier Major was resolved by a repair the next pass
confirmed. Pass 4's six Minors and one Nit are collected, not iterated. The
committed spec is byte-identical to the text pass 4 reviewed (sha256
60d108d30adcbe09c6dafcd8c0bb00389d94e98bd4d2d7f47aa0bd925d3eb039).
Two earlier calls for pass 1 failed because the Codex app had set an
unsupported model (gpt-6.1-sol). They were discarded and are not counted.

Docs-only change (docs/**.md): Gate B is N/A per CLAUDE.md §5.

cycle mbu2nfkahz; floor 3 per {docs/superpowers/stories/2026-08-04-passive-metrics-over-the-ledger-story.md (level 1)}; hook reminder threshold absent
cycle mbu2nfkahz; Gate-A spec (passes 1-4, gpt-6-astra): Findings 24,19,13,7. Blockers 0,0,0,0. Majors 14,6,3,0.
…wk unfit

Gate-A plan pass 1 found 16 Majors, most of them awk failing to parse the
quoted, escaped §5 record grammar. Daniel chose Python (3.8+, standard
library); the suite stays POSIX sh. This revision changes the language and
records the narrowings the implementation needed, marked (revision): one
resolved SHA read with --no-replace-objects, UTF-8-forced log output, a
literal column-2 fingerprint compare, a skip-reason excerpt bounded by a
blank line or the next record, one ordering rule, control characters shown
as \xNN, a conflict-only empty state, and suite isolation from the caller's
git config.

Gate-A spec cycle closed. Pass 3 is clean at the derived floor (0 Blockers,
0 Majors); pass 1's one Major (log output encoding) was repaired and pass 2
confirmed it. Passes 2 and 3 reviewed the same text. Their Minors are
collected, not iterated, and the plan carries the ones that affect the
implementation. The committed spec is byte-identical to the text pass 3
reviewed (sha256 4e6d08282a25005517bf691b9b528397a13b9bf7d2359874419e4592de0ba5a7).

Docs-only change (docs/**.md): Gate B is N/A per CLAUDE.md §5.

cycle p9yvzn4fvi; floor 3 per {docs/superpowers/stories/2026-08-04-passive-metrics-over-the-ledger-story.md (level 1)}; hook reminder threshold absent
cycle p9yvzn4fvi; Gate-A spec (passes 1-3, gpt-6-astra): Findings 12,12,16. Blockers 0,0,0. Majors 1,0,0.
Gate-A plan cycle closed on a zero-finding pass 6. Pass 1 reviewed the
earlier awk plan; its 16 Majors led to the Python revision of the spec
(49b90f8). Passes 2-5 found 5, 1, 1 and 3 Majors in the Python plan, each
repaired and confirmed by the next pass. The committed plan is byte-identical
to the text pass 6 reviewed (sha256
c0965410c3f0519fc3a8625c2003ca43532fe3726cc9ba2b9a23c9a7ead06c56). Its
embedded script and suite were run as a prototype before every pass; the
suite stands at 30/30 under sh and dash.

Docs-only change (docs/**.md): Gate B is N/A per CLAUDE.md §5.

cycle mtf7ua7qze; floor 3 per {docs/superpowers/stories/2026-08-04-passive-metrics-over-the-ledger-story.md (level 1)}; hook reminder threshold absent
cycle mtf7ua7qze; Gate-A plan (passes 1-6, gpt-6-astra): Findings 34,19,9,4,4,0. Blockers 0,0,0,0,0,0. Majors 16,5,1,1,3,0.
scripts/ledger-metrics.py (Python 3.8+, standard library) reads
docs/hardening-log.md and the commit bodies at one resolved commit and
prints which fingerprints recur, how rungs were followed, and every
review-cycle record (provenance line, curve, skip record) beside the fic2
baseline. It computes no shares or verdicts, writes nothing, and prints
what it cannot answer. scripts/ledger-metrics.test.sh is its POSIX-sh suite:
31 cases on config-isolated fixture repositories with fixed dates, a
no-write check around every run, a prior-state case and a negative control.
The suite joins the quality row, the lint row and CI. AGENTS.md, README.md
and the CI comments now count it; CLAUDE.md no longer says the metrics
consumer does not exist. The scaffolded template keeps that sentence,
because consumer projects get no script. Not shipped, so no plugin bump.

Executed natively from the plan. One deviation, ruled: Gate-B pass 1's
quality Minor (the empty checkpoint lists were not asserted) was fixed by
one added suite case (mutation-checked), so the suite has 31 cases where
the plan has 30.

Evidence — docs/superpowers/stories/2026-08-04-passive-metrics-over-the-ledger-story.md
Battery: AGENTS.md quality row, exit 0 at d33b2424eee6e69a664a4343d24f0c7278c5337d.
Check (counterfactual): at c60b78b no metrics script exists (git ls-tree prints
nothing), and the suite's first case observes that an absent script produces no
report. Negative control: a copy whose fingerprint count is off by one runs to
completion, and the same comparison every golden case uses rejects its report
(suite case 2). Suite 31/31 under sh (in the quality row) and under dash.

cycle 08x02c2od1; floor 3 per {docs/superpowers/stories/2026-08-04-passive-metrics-over-the-ledger-story.md (level 1)}; hook reminder threshold absent
cycle 08x02c2od1; Gate B (passes 1-2, gpt-6-astra): Findings 1,0. Blockers 0,0. Majors 0,0.

Each Gate-B pass was one logical pass run as two calls (reviewType spec,
then quality) against the same baseSha 9230e4f
and the headSha resolved before each call (pass 1:
0a1304454a285a4e00ea4738e612aba0bcca1a35; pass 2:
d33b2424eee6e69a664a4343d24f0c7278c5337d). Pass 2 found nothing in either
branch, so the cycle closed on the zero-finding exit below the floor.

Human exceptions: none
@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 26 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: b8805021-38a8-47d4-b5b1-b394d436e16e

📥 Commits

Reviewing files that changed from the base of the PR and between 0d3da0a and 33f23d9.

📒 Files selected for processing (4)
  • docs/hardening-log.md
  • docs/superpowers/plans/2026-10-01-passive-metrics.md
  • docs/superpowers/specs/2026-10-01-passive-metrics-design.md
  • scripts/ledger-metrics.test.sh

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 2b238683-90b7-436e-9863-e1e2daf21dd6

📥 Commits

Reviewing files that changed from the base of the PR and between 81787b7 and 0d3da0a.

📒 Files selected for processing (9)
  • .github/workflows/ci.yml
  • AGENTS.md
  • CLAUDE.md
  • README.md
  • docs/superpowers/plans/2026-10-01-passive-metrics.md
  • docs/superpowers/specs/2026-10-01-passive-metrics-design.md
  • docs/superpowers/stories/2026-08-04-passive-metrics-over-the-ledger-story.md
  • scripts/ledger-metrics.py
  • scripts/ledger-metrics.test.sh

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

This change adds a read-only Python report for hardening-ledger and Git review-cycle data. It includes a shell regression suite, CI execution and linting for that suite, and updates to repository documentation and planning records.

Changes

Passive Metrics Report

Layer / File(s) Summary
Report inputs and record parsing
scripts/ledger-metrics.py, docs/superpowers/specs/*, docs/superpowers/plans/*, docs/superpowers/stories/*
Defines the report’s input and record formats. The script parses provenance, skip, and curve records and handles invalid inputs.
Metrics aggregation and report output
scripts/ledger-metrics.py, docs/superpowers/specs/*, docs/superpowers/plans/*
The script reports ledger recurrence and rung counts, aggregates review-cycle records, identifies conflicts and shallow history, and writes results for a resolved commit.
Regression checks and repository integration
scripts/ledger-metrics.test.sh, .github/workflows/ci.yml, AGENTS.md, CLAUDE.md, README.md, docs/superpowers/*
Adds fixture-based regression checks and runs them in CI. Updates repository guidance and records the report’s design, test coverage, and implementation profile.

Priority: ⬇️ Low

Estimated code review effort: 4 (Complex) | ~45 minutes

Change: Feature

Sequence Diagram(s)

sequenceDiagram
  participant Report as ledger-metrics.py
  participant Git
  participant Output as stdout
  Report->>Git: Resolve ref and read ledger blob
  Report->>Git: Read reachable commit bodies
  Git-->>Report: Return ledger and commit data
  Report->>Output: Write assembled report
Loading

Merge Risk: ⚪ Minimal · up to 0d3da

The change adds a repository-local, read-only report and integrates its regression suite into CI. No actionable merge-blocking issue is established; merge after normal checks pass.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 0d3da

The report does not grant new permissions or execute ledger and commit text as commands. Risk is bounded by the invoking user's repository access, but Git can still write or fetch because of caller configuration, so this is not an enforced side-effect-free sandbox.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The inspected report's data exposure is bounded by the repository selected through the invoking process's Git context: its committed ledger and reachable review-cycle records are summarized to stdout. No tenant, service, or environment-wide authority expansion was established.

Security Findings and Attack Paths

  • inferred — No source-to-command execution path was established for ref arguments, ledger text, or commit-body records. Git is invoked without a shell, and record content is parsed and rendered as data. This conclusion does not establish safety for arbitrary inherited Git configuration.

Trust Boundaries and Controls

  • observed — Repository-content controls include disabling replacement objects and grafts, rejecting non-regular ledger entries, separating Git log revisions from paths, suppressing signature output, and escaping control characters in displayed content.
  • observed — The report inherits most of the process environment and explicitly warns that Git tracing or partial-clone fetches can cause writes. The workflow does not persist checkout credentials, but actual caller tracing, remotes, and credential-helper configuration were not supplied.

Resilience and Maintainability Implications

  • observed — Each suite invocation creates a fresh temporary root, refuses an invalid root, isolates Git configuration and repository variables, and confines generated fixture writes beneath that root. Cleanup is registered for EXIT only; signal-interruption cleanup is not established, although the stranded state would be synthetic fixtures rather than a demonstrated insecure checkout transition.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 50.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 30 functions across 2 files. (7 skipped: … Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely identifies the main change: adding a read-only metrics report over the ledger and Git data.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Docstring Coverage

Explanation

Docstring coverage is 50.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 30 functions across 2 files. (7 skipped: 7 unsupported.)

✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit reads the ledger lines,
Then counts the rungs and cycle signs.
Git’s old commit notes pass by,
A tidy report hops into view.
The test burrow checks each clue.

Comment @coderabbitai help to get the list of available commands.

@greptile-apps

greptile-apps Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

RetriggerConfidence Score: 5/5

[Medium risk] Adds a read-only metrics report script and its test suite.

The PR appears safe to merge; no outstanding finding or new actionable issue remains.

Summary

The PR adds a read-only report over the hardening ledger and commit-body cycle records, with a fixture-based regression suite and CI wiring. Since the previous review, it has added header coverage to the suite and clarified the spec and plan; the previous findings are resolved.

Diagram

%%{init: {'theme': 'neutral'}}%%
flowchart LR
  A[Resolved commit] --> B[Ledger blob]
  A --> C[Reachable commit bodies]
  B --> D[Read-only metrics report]
  C --> D
Loading

Reviews (2) · Last reviewed commit: "Fix PR #33 review findings: spec pass ru..."

Comment thread docs/superpowers/specs/2026-10-01-passive-metrics-design.md Outdated
Comment thread docs/superpowers/plans/2026-10-01-passive-metrics.md
Comment thread scripts/ledger-metrics.test.sh
dsnger added a commit that referenced this pull request Oct 1, 2026
Greptile found three true claims on PR #33:
- The spec still described a 10000-pass limit that plan ruling 1 had
  removed. The grammar paragraph now states the implemented rule, marked
  as updated after implementation.
- The executed plan still expected 30 suite cases. It now carries a dated
  note: its counts describe the suite as approved, the committed suite has
  32, and "the spec is not edited" was the planning-time decision.
- The suite never compared the report header. A golden five-line header
  case was added; it was mutation-checked by changing the history line.
docs/hardening-log.md records the ninth docs-drift occurrence.

Evidence — docs/superpowers/stories/2026-08-04-passive-metrics-over-the-ledger-story.md
Battery: AGENTS.md quality row, exit 0 at d5e9dcb4bcd4af13964c6c08b508f4a35eab3062.
Check (counterfactual): the new header case fails against a copy whose history line is changed, and passes against the real script. Suite 32/32 under sh (in the quality row) and under dash.

cycle p4hht73863; floor 3 per {docs/superpowers/stories/2026-08-04-passive-metrics-over-the-ledger-story.md (level 1)}; hook reminder threshold absent
cycle p4hht73863; Gate B (passes 1-2, gpt-6-astra): Findings 3,0. Blockers 0,0. Majors 0,0.

Each Gate-B pass was one logical pass run as two calls (spec, then quality)
against baseSha 0d3da0a and the headSha
resolved before each call (pass 1: 8f2a4b741b06dc0649203ce538756380065b76ee;
pass 2: d5e9dcb4bcd4af13964c6c08b508f4a35eab3062). Pass 1's spec branch found
3 findings and its quality branch found 2 of the same; the pass counts 3. Pass 2
found nothing in either branch, so the cycle closed on the zero-finding exit.

Human exceptions: none
Greptile found three true claims on PR #33:
- The spec still described a 10000-pass limit that plan ruling 1 had
  removed. The grammar paragraph now states the implemented rule, marked
  as updated after implementation.
- The executed plan still expected 30 suite cases. It now carries a dated
  note: its counts describe the suite as approved, the committed suite has
  32, and "the spec is not edited" was the planning-time decision.
- The suite never compared the report header. A golden five-line header
  case was added; it was mutation-checked by changing the history line.
docs/hardening-log.md records the ninth docs-drift occurrence.

Evidence — docs/superpowers/stories/2026-08-04-passive-metrics-over-the-ledger-story.md
Battery: AGENTS.md quality row, exit 0 at d5e9dcb4bcd4af13964c6c08b508f4a35eab3062.
Check (counterfactual): the new header case fails against a copy whose history line is changed, and passes against the real script. Suite 32/32 under sh (in the quality row) and under dash.

cycle p4hht73863; floor 3 per {docs/superpowers/stories/2026-08-04-passive-metrics-over-the-ledger-story.md (level 1)}; hook reminder threshold absent
cycle p4hht73863; Gate B (passes 1-2, gpt-6-astra): Findings 5,0. Blockers 0,0. Majors 0,0.

Each Gate-B pass was one logical pass run as two calls (spec, then quality)
against baseSha 0d3da0a and the headSha
resolved before each call (pass 1: 8f2a4b741b06dc0649203ce538756380065b76ee;
pass 2: d5e9dcb4bcd4af13964c6c08b508f4a35eab3062). Pass 1's spec branch found
3 findings and its quality branch 2, two of them the same complaints; per
§5 the branches are summed, so the pass records 5. Pass 2
found nothing in either branch, so the cycle closed on the zero-finding exit.

Human exceptions: none
@dsnger
dsnger merged commit dc6d2cb into main Oct 2, 2026
3 checks passed
@dsnger
dsnger deleted the passive-metrics branch October 2, 2026 07:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant