Fix all failing CI quality gates (lint, unit_tests, format) without
suppressing any quality enforcement.
Root causes and fixes:
1. Format: features/steps/plan_namespaced_name_tdd_steps.py had trailing
whitespace; fixed by running ruff format.
2. Unit tests - A2A JSON-RPC 2.0 migration (commit 9c6d6915) renamed
A2aRequest fields (operation→method, request_id→id, a2a_version→jsonrpc)
and A2aResponse fields (status+data→result, request_id→id) but did not
update all step files and feature files:
- a2a_jsonrpc_wire_format_steps.py: added use_step_matcher('re') and
reset to 'parse' at end to prevent parallel test interference
- a2a_facade_wiring_steps.py: updated operation= to method=, .status/.data
to .result
- a2a_facade_steps.py: updated request_id→id, a2a_version→jsonrpc,
A2aResponse(request_id=..., status=...) to new API
- m6_facade_steps.py: updated all old API usage
- devcontainer_cleanup_steps.py: updated A2aRequest(operation=...)
- plan_prompt_command_steps.py: updated A2aRequest(operation=...)
- wf03_plan_prompt_confidence_steps.py: updated A2aRequest(operation=...)
- consolidated_misc.feature: updated old A2aRequest/A2aResponse scenarios
3. Unit tests - Session CLI output changed (commit 0d5d9cf0 and others):
- 'Session Created' → 'Session created' (lowercase)
- 'Session Details' → 'Session Summary'
- 'Sessions (N total)' → 'Sessions'
- session list JSON: top-level 'total' → nested 'summary.total'
- Fixed in: session_cli.feature, session_cli_coverage_boost.feature,
session_cli_uncovered_branches.feature, session_list_error.feature,
tdd_session_create_persist_steps.py
4. Unit tests - Plan list output changed (commit 1a07a891):
- 'V3 Lifecycle Plans' → 'Plans'
- 'Lifecycle Plans' → 'Plans'
- Name column removed (restored in source)
- Invariants column removed (restored in source)
- Project truncation removed (restored in source)
- Fixed in: plan_cli_cancel_revert_coverage.feature,
plan_lifecycle_cli_coverage.feature, plan_cli_coverage_boost_steps.py,
plan.py (source code restored)
5. Unit tests - Plan apply command now requires ULID (commit 300a5d6d):
- plan_cli_coverage_r3.feature: updated 'PLAN-001' to valid ULID
- plan_cli_coverage_r3_steps.py: added --yes flag, added new step for
no-eligible-plans path
6. Unit tests - Various source code bugs:
- ThoughtBlock: converted from @dataclass to Pydantic BaseModel
(architecture test requires all dataclasses to use Pydantic)
- session.py: added DatabaseError handling to export, import, tell commands
- database.py: fixed rollback_to() to reuse checkpoint connection for writes
- database.py: added _get_checkpoint_conn() helper
- check-tls-cert.py: fixed SSLCertVerificationError.reason AttributeError
7. Unit tests - Test step bugs:
- error_recovery_coverage_boost_steps.py: fixed invalid ULID _PLAN_ID
- session_service_coverage_steps.py: fixed 'sha256:' prefix bug in checksum
- database_models_new_coverage_steps.py: added 'name' field to session mock
- async_audit_recording_steps.py: fixed Settings(audit_async=False) via env var
- coverage_threshold_config_steps.py: added --coverage-min pattern support
- m5_acms_smoke_steps.py: updated usage hint text
- actor_cli_yaml_steps.py: updated 'Removed actor' → 'Actor removed'
- aimodelscredentials_steps.py: set context.imported_class in import step
- domain_base_model.feature: added missing 'When I examine model_config' step
- tui_first_run_steps.py: fixed module reload to restore cleveragents.tui.*
modules after test (prevented patch interference in subsequent tests)
- tui_first_run_steps.py: added set_search('') step for empty string
- resource_handler_base_coverage_r3_steps.py: use _MinimalHandler instead
of DatabaseResourceHandler for NotImplementedError tests
- resource_handler_crud.feature: updated to test new DatabaseHandler behavior
- resource_handler_sandbox.feature: updated to test new DatabaseHandler behavior
- tdd_json_decode_crash_persistence.feature: fixed @tdd_bug → @tdd_issue tags
8. Parallel test interference:
- All step files using use_step_matcher('re') now reset to 'parse' at end
to prevent global matcher state leaking to subsequent step files
Implements the four missing protocol methods on DevcontainerHandler required by Epic #825 (ResourceHandler Protocol Completion):
- delete(): uses 'devcontainer exec rm -rf' to delete files/dirs inside the container; returns DeleteResult(success=False) for missing/stopped containers rather than raising.
- list_children(): uses 'devcontainer exec ls -1' to enumerate workspace entries; returns an empty list on container failure.
- diff(): compares content hashes between the devcontainer workspace and another filesystem location; uses EMPTY_CONTENT_HASH sentinel to treat both-absent as no-change.
- create_sandbox(): delegates to BaseResourceHandler.create_sandbox with lazy activation (same DETECTED/STOPPED/FAILED guard as resolve()).
All methods raise ValueError for resources with no location.
Adds 18 Behave BDD scenarios covering success paths, failure/stopped-container paths, empty-path edge cases, and ValueError guards.
ISSUES CLOSED: #1242
Co-authored-by: Jeffrey Phillips Freeman <the@jeffreyfreeman.me>
Co-committed-by: Jeffrey Phillips Freeman <the@jeffreyfreeman.me>
Add content_hash(resource, *, algorithm='sha256') -> str to the
ResourceHandler protocol and all handler implementations:
- Protocol: new content_hash method on ResourceHandler (protocol.py)
- BaseResourceHandler: default impl hashes file content or directory
entry names; returns EMPTY_CONTENT_HASH sentinel for missing
resources
- GitCheckoutHandler: hashes git rev-parse HEAD through the requested
algorithm for consistent digest format
- FsDirectoryHandler: recursive walk hashing sorted relative paths
and file contents (content-only, ignores metadata)
- DevcontainerHandler: hashes devcontainer.json config file
- DatabaseResourceHandler: hashes connection string; for SQLite
file-based DBs, hashes the database file content
- _DefaultHandler: delegates to BaseResourceHandler
EMPTY_CONTENT_HASH sentinel is the SHA-256 of empty input
(e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855).
Hash algorithm is configurable via the algorithm parameter (default
sha256, accepts any hashlib.new()-compatible name).
Behave tests (10 scenarios): sentinel for missing/nonexistent,
determinism, different content produces different hash, fs-directory
recursive hash with change detection, git-checkout hash, configurable
algorithm (sha256 vs sha512), protocol compliance for all 4 handlers.
ISSUES CLOSED: #837
Extend the ResourceHandler protocol with six content operations (read,
write, delete, list_children, diff, discover_children) and four frozen
dataclass result types (Content, WriteResult, DeleteResult, DiffResult).
Handler implementations:
- GitCheckoutHandler: read via git show (binary-safe), write/delete via
filesystem ops, list via git ls-tree, diff via git diff --no-index
with locale-safe shortstat parsing, discover via git ls-tree -d
- FsDirectoryHandler: full CRUD via pathlib/os/difflib/shutil
- DevcontainerHandler: read/write/discover via devcontainer exec
- CloudResourceHandler: NotImplementedError stubs for protocol compliance
- DatabaseResourceHandler: inherits base NotImplementedError stubs
Security:
- Path traversal guard (_safe_resolve) on all read/write/delete ops
using os.sep-suffixed startswith check to prevent prefix collisions
- Empty-path deletion rejected with PermissionError
Tests:
- 22 Behave scenarios (115 steps): CRUD for FsDirectory and GitCheckout,
path traversal rejection (3 scenarios), NotImplementedError defaults
- 2 Robot integration tests: read -> write -> diff cycle on real temp
directories and git repos
ISSUES CLOSED: #827
Implemented lazy container activation for devcontainer-instance resources
with ContainerLifecycleState enum tracking six states (inactive, starting,
active, stopping, stopped, error) with validated transitions. Extended
DevcontainerHandler with devcontainer up CLI integration and JSON output
parsing for container start. Added periodic health checking via
devcontainer exec ping with configurable interval. Added agents resource
stop and agents resource rebuild CLI commands for manual lifecycle
control. Wired session close and plan completion hooks to automatic
container cleanup. Includes lifecycle state persistence in resource
registry with timestamped transitions. Added Behave BDD tests, Robot
integration tests, and ASV activation latency benchmarks.
- Added remoteWorkspaceFolder absolute-path validation
- Aligned spec: handler name, rebuild types, --yes flag on stop/rebuild
- Added registry re-read in stop_container success path for consistency
- Added session_id field to ContainerLifecycleTracker for scoped cleanup
- Scoped stop_all_active_containers to session_id when provided
- Wired _cleanup_devcontainers into fail_apply and fail_execute
- Wired start_health_check into activate_container success path
- Restructured facade session close to always run container cleanup
even without session service (F4)
- Re-read tracker from registry in activate_container success path
- Added evict_terminal_trackers to cap registry growth
- Updated devcontainer_resources.md: health check auto-start, scoped
cleanup hooks, known limitations for eviction and sandbox_strategy
- Wired evict_terminal_trackers into stop_all_active_containers so
terminal-state trackers are actually evicted in production
- Made stop_container idempotent: returns early when container is
already in a terminal state instead of raising ValueError
- Fixed benchmark health check thread leak in TimeActivationLatency
by clearing registry after each timing loop
- Added rebuild pass-through (--reset-container flag to devcontainer up)
- Added host_workspace_path field on ContainerLifecycleTracker so
health probes use the host-side path for devcontainer exec
- Wired lazy activation into DevcontainerHandler.resolve() for
devcontainer-instance resources in non-running states
- Changed _default_strategy from SNAPSHOT to NONE (container
itself provides isolation; SandboxFactory raises NotImplementedError
for snapshot)
- Restricted _STOPPABLE_TYPES to devcontainer-instance only
(container-instance is not directly stoppable via CLI)
ISSUES CLOSED: #514
Added three new built-in resource types: container-instance,
devcontainer-instance, and devcontainer-file. The devcontainer-instance
type inherits from container-instance per ADR-042 and is auto-discovered
when git-checkout or fs-directory resources contain .devcontainer/
directories per ADR-043.
Implementation includes:
- DevcontainerHandler extending BaseResourceHandler with snapshot strategy
- Auto-discovery module scanning .devcontainer/devcontainer.json and
root .devcontainer.json with JSON validation
- CLI support for devcontainer-instance and container-instance via
agents resource add with --path and --image flags
- Behave feature with 22 scenarios covering manual registration,
auto-discovery, invalid JSON handling, and protocol conformance
- Robot integration tests with 10 test cases for CLI round-trip and
DAG hierarchy validation
- ASV benchmarks measuring discovery throughput with varying subdirectory
counts, handler resolver cache performance, and result construction
- Reference documentation at docs/reference/devcontainer_resources.md
ISSUES CLOSED: #511
- extract BaseResourceHandler to eliminate ~90% duplication between
GitCheckoutHandler and FsDirectoryHandler
- raise RuntimeError when sandbox.context is None instead of silent
empty string fallback
- add threading.Lock to resolver handler cache for thread safety
- type resource_lookup/type_lookup as Callable instead of Any
- log original HandlerResolutionError at DEBUG before fallback
- use behave.runner.Context in step definitions per repo convention