fix(mrl): bind and revalidate Tier 1 budget policy - #301
Conversation
|
ⓘ Qodo reviews are paused because your trial has ended. Ask your workspace admin to add credits to resume reviews. Manage billing |
|
Warning Review limit reachedNext included review available in 57 minutes. View limit detailsLimit details: You’ve used the included review currently available. Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. Review configuration: ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Free Run ID: 📒 Files selected for processing (2)
Note 🎁 Summarized by CodeRabbit FreeYour organization is on the Free plan. CodeRabbit will generate a high-level summary and a walkthrough for each pull request. For a comprehensive line-by-line review, please upgrade your subscription to CodeRabbit Pro by visiting https://app.coderabbit.ai/settings/billing. Comment |
|
Exact-head qualification blocker update for
No workflow step executed on this exact candidate head, so these red jobs are pre-execution hosted-runner/account-capacity evidence, not Ruff, formatting, mypy, pytest/coverage, machine-state, |
|
Superseded first by PR #306's reconciliation path and now by canonical |
Summary
Harden MRL-0302 Tier 1 adaptive-budget policy and usage state against malformed post-construction mutation and coordinated mutation that remains syntactically valid.
Manual semantic review identified a remaining budget-integrity defect after the earlier negative-counter repair: a caller could mutate a legitimate
Tier1ExposureUsage(queries_used=5)toqueries_used=0and restore consumed capacity because the altered value remained non-negative and within the frozen ceiling.Repair
TierEvaluationContract.content_sha256forTier1ExposurePolicyoutside reachable object state(queries_used, exposures_used)pair for everyTier1ExposureUsageoutside mutable dataclass fieldsRegression coverage
Canonical base
bf92dd2977d24aa597d2442decabc215f7bd3dbfExact candidate head
17dd2d3a51d4df3a75a733fca1acbfcaffff7d8cLive compare:
behind_by=0, 10 commits ahead, exactly two intended files:src/medscale/mesc/_mrl_tier1_exposure_v1.pytests/test_mesc_mrl_tier1_exposure_v1.pyAll qualification/review evidence for earlier heads, including
c13261cf0d426eb12c06cbcea99f38c55ebac164, is stale.Current exact-head qualification blocker
Fresh automatic workflows terminate before any workflow step executes:
3330119890099229566629:failure,steps=null99229566717:failure,steps=null3330119889599229566462:failure,steps=nullThese are external pre-execution hosted-runner blocker results only. They are not Ruff, formatting, strict mypy, pytest/coverage, MRL machine-state,
medscale check, or CodeQL-analysis results and do not authorize merge.Boundary
This is fail-closed budget-integrity hardening. It grants no new budget, execution, model/data/network/GPU, training, promotion, deployment, release, or clinical authority.
Fresh exact-head CI, CodeQL/security qualification, intended-scope verification, review,
behind_by=0, mergeability, and zero unresolved material findings/threads remain required before guarded merge. After MRL-0301 hardening in PR #304 becomes canonical, this branch must be reconciled against that exact canonical implementation and fully requalified. No force-push, rebase, destructive history rewrite, governance bypass, provider spend, or real-asset access is used.