Documentation
¶
Index ¶
- Variables
- func BindUncertifiedPipelineRange(sctx *StepContext) error
- func FilterDeferredPipelineOwnedDeliveryFindings(findings types.Findings) (types.Findings, int)
- func PersistUncertifiedPipelineRange(sctx *StepContext, fromSHA, toSHA string) error
- func PersistUncertifiedPipelineRangeWithRollback(sctx *StepContext, fromSHA, toSHA string) (func() error, error)
- func ReconcileReviewFindings(findings types.Findings, priorRaw string) (types.Findings, int, error)
- func RemapUncertifiedPipelineRangeAfterRebase(sctx *StepContext, oldHead, newHead string) (func() error, error)
- func ValidateRecoveredRun(database *db.DB, run *db.Run, steps []Step) error
- type ApprovalGateReconciler
- type Capacity
- type EventFunc
- type Executor
- func (e *Executor) Execute(ctx context.Context, run *db.Run, repo *db.Repo, workDir string) error
- func (e *Executor) Respond(step types.StepName, action types.ApprovalAction, findingIDs []string) error
- func (e *Executor) RespondWithOverrides(step types.StepName, action types.ApprovalAction, findingIDs []string, ...) error
- func (e *Executor) Resume(ctx context.Context, run *db.Run, repo *db.Repo, workDir string) error
- func (e *Executor) SetCapacity(c *Capacity)
- func (e *Executor) SetGateDir(gateDir string)
- func (e *Executor) SetGateReconcileTimings(interval, timeout time.Duration)
- func (e *Executor) SetOnPRMerged(fn func(context.Context, string))
- func (e *Executor) SetSkippedSteps(steps []types.StepName)
- type HousekeepingLintResult
- type RunSessions
- type RunShared
- type ScopeLimitedFindingsStep
- type SessionRole
- type Step
- type StepContext
- type StepOutcome
Constants ¶
This section is empty.
Variables ¶
var ErrFatalGateReconciliation = errors.New("fatal gate reconciliation")
Functions ¶
func BindUncertifiedPipelineRange ¶
func BindUncertifiedPipelineRange(sctx *StepContext) error
BindUncertifiedPipelineRange copies a persisted uncertified recovery boundary onto the review step context when this run's head is that range's tip or a descendant of it. Unreadable commit ancestry or persisted review truth blocks replacement review.
func PersistUncertifiedPipelineRange ¶
func PersistUncertifiedPipelineRange(sctx *StepContext, fromSHA, toSHA string) error
PersistUncertifiedPipelineRange records a post-review commit span until a review of the new head completes.
func PersistUncertifiedPipelineRangeWithRollback ¶
func PersistUncertifiedPipelineRangeWithRollback(sctx *StepContext, fromSHA, toSHA string) (func() error, error)
func ReconcileReviewFindings ¶
func RemapUncertifiedPipelineRangeAfterRebase ¶
func RemapUncertifiedPipelineRangeAfterRebase(sctx *StepContext, oldHead, newHead string) (func() error, error)
RemapUncertifiedPipelineRangeAfterRebase rewrites a persisted uncertified range onto the new head when rebase replaced a head that contained it.
Types ¶
type ApprovalGateReconciler ¶
type ApprovalGateReconciler interface {
ReconcileApprovalGate(sctx *StepContext) (resolved bool, err error)
}
ApprovalGateReconciler is implemented by a step whose parked approval gate can become obsolete when an external source of truth changes. The executor invokes it with a bounded context while also waiting for an approval. A true result completes the step through the normal success path; false or an error leaves the gate parked. Implementations must be read-only and fail closed.
type Capacity ¶ added in v1.55.0
type Capacity struct {
// contains filtered or unexported fields
}
Capacity is shared by every executor in a host daemon. Review and suite execution occupy independent pools; approval waits occupy neither. Release closes a notification channel, so admission never depends on a polling timer.
func NewCapacity ¶ added in v1.55.0
func NewCapacity(limits config.Concurrency) *Capacity
func (*Capacity) Configure ¶ added in v1.55.0
func (c *Capacity) Configure(limits config.Concurrency)
Configure applies the operator config on run admission, including recovery. Lowering a cap drains existing holders; it never interrupts their work.
type Executor ¶
type Executor struct {
// contains filtered or unexported fields
}
Executor runs pipeline steps sequentially and coordinates approval interactions.
func NewExecutor ¶
func NewExecutor(database *db.DB, p *paths.Paths, cfg *config.Config, ag agent.Agent, steps []Step, onEvent EventFunc) *Executor
NewExecutor creates a pipeline executor.
func (*Executor) Execute ¶
Execute runs the pipeline steps sequentially for a given run. The workDir is the directory where steps execute (typically a git worktree). If the context is cancelled with a cause (via context.WithCancelCause), the cause message is preserved as the run's error in the DB.
func (*Executor) Respond ¶
func (e *Executor) Respond(step types.StepName, action types.ApprovalAction, findingIDs []string) error
Respond sends a user approval action to the currently waiting step. The step parameter must match the step currently awaiting approval. Returns an error if no step is awaiting approval or if the step name doesn't match.
func (*Executor) RespondWithOverrides ¶
func (e *Executor) RespondWithOverrides(step types.StepName, action types.ApprovalAction, findingIDs []string, instructions map[string]string, addedFindings []types.Finding) error
RespondWithOverrides is like Respond but also carries per-finding user instructions and user-authored findings. Both are merged into the round's findings on a fix action before the fix agent runs.
func (*Executor) Resume ¶
Resume restores a run that was durably parked at an approval gate when the daemon stopped. It only accepts a fully recorded gate and otherwise returns an error so startup recovery can fail the run rather than guessing.
func (*Executor) SetCapacity ¶ added in v1.55.0
func (*Executor) SetGateDir ¶
SetGateDir identifies the managed bare mirror where reviewed-tree evidence refs are retained. It is separate from the step worktree so developer refs are never polluted by gate custody metadata.
func (*Executor) SetGateReconcileTimings ¶
SetGateReconcileTimings overrides the interval between approval-gate reconciliation checks and the deadline for each check. It is primarily used by deterministic tests and specialized embeddings; non-positive values keep the production defaults.
func (*Executor) SetOnPRMerged ¶
SetOnPRMerged registers a best-effort hook invoked after a merged PR state is persisted. The pipeline never fails the run if the hook errors.
func (*Executor) SetSkippedSteps ¶
SetSkippedSteps configures steps that should be marked skipped without running.
type HousekeepingLintResult ¶
type HousekeepingLintResult struct {
// FindingsJSON holds the lint-category findings (possibly an empty set)
// in the same JSON shape the lint step produces itself.
FindingsJSON string
// Summary is the housekeeping pass's one-line lint summary.
Summary string
}
HousekeepingLintResult is the lint assessment produced by the combined document+lint housekeeping pass: the document step performs both duties in one agent invocation and hands the lint half to the lint step so it does not pay a second cold agent pass.
type RunSessions ¶
type RunSessions struct {
// contains filtered or unexported fields
}
RunSessions manages the per-run, per-role durable agent sessions of the review loop. It is strictly scoped to one run: identities are keyed by (run, role), persisted as minimum resume metadata (run, role, agent, session id - never prompts or transcripts), and never shared across runs, branches, repositories, or roles.
Correctness always wins over reuse: adapters without session support run cold, a failed resume drops the identity and re-runs the same turn in a fresh same-role session, and any persistence failure degrades to cold invocations. A nil *RunSessions runs everything cold, preserving the pre-session behavior for steps outside the review loop and for tests.
func NewRunSessions ¶
func NewRunSessions(database *db.DB, runID string, sessionAgent agent.Agent, enabled bool) *RunSessions
NewRunSessions creates the manager for one run, loading any persisted session identities recorded by a previous process for the same run and agent. Identities stored for a different adapter are ignored: a session id is only meaningful to the adapter that minted it.
func (*RunSessions) Run ¶
func (rs *RunSessions) Run(ctx context.Context, a agent.Agent, role SessionRole, opts agent.RunOpts, logf func(string)) (*agent.Result, error)
Run executes one turn of the given role, reusing the role's durable session when the adapter supports it. logf (optional) receives operator- visible notes about session reuse and fallbacks.
type RunShared ¶
type RunShared struct {
// contains filtered or unexported fields
}
RunShared carries in-memory run-scoped results one step hands to a later step in the same run. It lives on the executor for the run's lifetime and is never persisted: on any process boundary the consuming step simply falls back to doing its own work.
func (*RunShared) ClearHousekeepingLint ¶
func (s *RunShared) ClearHousekeepingLint()
ClearHousekeepingLint discards a previous combined-pass lint assessment before a document pass starts, so a later lint step never consumes stale findings.
func (*RunShared) SetHousekeepingLint ¶
func (s *RunShared) SetHousekeepingLint(result HousekeepingLintResult)
SetHousekeepingLint records the combined pass's lint assessment for the lint step. It replaces any previous assessment (a document fix round re-runs the combined pass and re-stashes a fresh result).
func (*RunShared) TakeHousekeepingLint ¶
func (s *RunShared) TakeHousekeepingLint() (HousekeepingLintResult, bool)
TakeHousekeepingLint returns and consumes the combined pass's lint assessment. The second call returns false so a lint fix round re-assesses with its own agent pass instead of trusting a stale result.
type ScopeLimitedFindingsStep ¶
type ScopeLimitedFindingsStep interface {
FindingsMayBeScopeLimited() bool
}
ScopeLimitedFindingsStep marks a step whose later rounds may reassess only the work selected for that round. For such a step, silence in a later round cannot retract an unresolved finding that the operator was already shown.
type SessionRole ¶
type SessionRole string
SessionRole identifies which durable review-loop session an invocation belongs to. The fixer role spans every review-fix turn of a run and is the only role that resumes a session. Review turns deliberately run session-free: a rereview certifies fixes implementing the previous review turn's findings, so resuming any review session would seat the prescriber of those fixes as their certifier and degrade the rereview into checking that its own prescription was implemented.
const ( // SessionRoleReviewer is legacy: review turns no longer create or resume // sessions. The constant remains so crash recovery keeps accepting // persisted rows written by earlier versions (see // validateRecoveredSessionProviders); such rows are never resumed. SessionRoleReviewer SessionRole = "reviewer" SessionRoleFixer SessionRole = "review-fixer" )
type Step ¶
type Step interface {
// Name returns the step's identity in the fixed pipeline sequence.
Name() types.StepName
// Execute runs the step logic and returns an outcome.
// A step that returns NeedsApproval=true will pause the pipeline
// until the user responds with an approval action.
Execute(sctx *StepContext) (*StepOutcome, error)
}
Step is the interface that each pipeline step implements.
type StepContext ¶
type StepContext struct {
Ctx context.Context
Run *db.Run
Repo *db.Repo
WorkDir string
Agent agent.Agent
Config *config.Config
DB *db.DB
Log func(string) // discrete log line (newline-terminated, user-visible + file)
LogChunk func(string) // raw streaming chunk (user-visible + file)
LogFile func(string) // file-only log callback (not shown to user)
Fixing bool // true when re-executing after a "fix" action
SkipFixExecution bool // replay an already-completed fix round's review turn only
ReviewStartingHeadSHA string
PreviousFindings string // JSON findings from the previous execution (set during fix loop)
KnownReviewLineages string
// StepResultID is the DB row ID of the current step's step_results record.
// Steps use it to query their own round history for multi-round prompts.
StepResultID string
// EvidenceDir is where this run's test-evidence artifacts belong, always
// outside the worktree. The executor resolves it once from the app root
// (honoring test.evidence.local_root) so every consumer - the test step's
// prompt and the PR step's publisher - names the same directory. Empty only
// in embeddings that never gather evidence.
EvidenceDir string
Env []string // extra environment variables for subprocesses (used in tests)
// UserIntent is a short, possibly-empty summary of what the change author
// was trying to accomplish. It's surfaced in step prompts so agents have
// context beyond the diff. Its authority depends on IntentSource: an
// explicit `--intent` is the author's own goal statement, while an
// inferred summary comes from a local agent transcript.
UserIntent string
// IntentSource records the provenance of UserIntent so steps can weigh
// its authority. db.RunIntentSourceAgent ("agent") means the driving
// agent supplied it explicitly via `axi run --intent`; db.RunIntentSourceRerun
// ("rerun") means that authoritative intent was inherited. Both are
// authoritative acceptance criteria; an agent name ("claude", "codex", ...)
// means it was inferred from a transcript (a hint). Empty when no intent exists.
IntentSource string
// UncertifiedFromSHA/ToSHA/SourceRunID name a previous run's fixer
// commits on this branch whose re-review did not complete. They are set
// on a later run's initial review (Fixing==false) so that review still
// receives fix-round provenance. Empty when no such range applies.
UncertifiedFromSHA string
UncertifiedToSHA string
UncertifiedSourceRunID string
// UncertifiedPriorRounds are review rounds from the source run that left
// the uncertified range. Nil when none apply.
UncertifiedPriorRounds []*db.StepRound
UncertifiedPriorFindings string
UncertifiedPriorLineages string
// UncertifiedSelectedFindings is the selected subset a recovered
// review-only round must verify. It is kept separate from carried findings:
// silence may resolve it after a real review, but an ignored-only delta must
// return it to the gate instead of silently approving.
UncertifiedSelectedFindings string
// Sessions manages the run's durable review-fixer session. The session
// machinery remains role-generic for legacy recovery; nil runs every
// invocation cold.
Sessions *RunSessions
// Shared carries in-memory run-scoped results one step hands to a later
// step in the same run (e.g. the combined document+lint pass).
CIReadinessChanged func(ready, declaredNoCI bool)
// OnPRMerged is a best-effort hook after a merged PR state is persisted.
// Eval uses it to relabel auto-fix/shipped-unfixed gold; nil is a no-op.
OnPRMerged func(ctx context.Context, runID string)
}
StepContext provides shared resources to pipeline steps during execution.
func (*StepContext) RunAgentSession ¶
func (sctx *StepContext) RunAgentSession(role SessionRole, opts agent.RunOpts) (*agent.Result, error)
RunAgentSession executes one turn of a durable review-loop role session, running cold when sessions are unavailable. Only the review step's fixer turns use this; every other agent invocation - including every review turn, which must stay independent of the session that prescribed the fixes under review - goes through sctx.Agent.Run directly and stays session-isolated.
type StepOutcome ¶
type StepOutcome struct {
NeedsApproval bool // whether the step pauses for user action
AutoFixable bool
Findings string // JSON findings for TUI display (optional)
FindingsNormalized bool
ExitCode int // process exit code (0 = success)
PRURL string // PR/MR URL if this step created or found one
Skipped bool // mark the step as skipped without failing the run
SkipRemaining bool // skip all subsequent steps (e.g. empty diff after rebase)
// RestartFrom asks the executor to re-run validation from this earlier step.
// CI repairs use it to send the new local head back through review before push.
RestartFrom types.StepName
// FixSummary, when non-empty, is the agent's one-line commit summary for
// the fix attempt performed during this round. Steps populate it in fix
// mode so the executor can persist it on the round record and later
// rounds can reference what was previously attempted.
FixSummary string
// ReviewApprovedHeadSHA is set only by a successfully executed full review
// round. The executor durably records it only when the review step actually
// completes, never while that outcome is parked or after a failed round.
ReviewApprovedHeadSHA string
// DurationOverrideMS, when positive, replaces the wall-clock duration
// reported for this step. Used by demo mode to show realistic durations
// without actually waiting.
DurationOverrideMS int64
}
StepOutcome is the result of executing a pipeline step.