Repository navigation
feat(adr): forbid embedded raw benchmark/spike data in ADR bodies (T7, #1925) - #2020
Conversation
Incident-shaped heuristics, synthetic good/bad fixtures, staged + lines scan, corpus must stay clean.
Incident-shaped heuristics, synthetic good/bad fixtures, staged + lines scan, corpus must stay clean.
Markdown-prefixed operator decision lines; case-sensitive runner tokens; tighten measurement cells; probe table parametrized.
ADR-0000 pointer, adr-trigger bullet, PLAN_ADR_GOVERNANCE_ENFORCEMENT, inventory regen; clarify staged table scope.
|
bugbot run |
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using default effort and found 2 potential issues.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 07e020b. Configure here.
| measurement_rows = sum( | ||
| 1 for row in data_rows if BENCHMARK_TABLE_CELL_RE.search(row) | ||
| ) | ||
| return measurement_rows >= 3 |
There was a problem hiding this comment.
Staged table scan drops data rows
Medium Severity
_table_data_rows always discards the first two pipe-lines as header and separator. The staged T7 gate then runs that parser on concatenated + lines only, so adding or replacing three measurement rows on an existing table never meets the 3-row threshold and is not flagged.
Additional Locations (2)
Reviewed by Cursor Bugbot for commit 07e020b. Configure here.
| r"\d[\d.,]*\s*(?:ms|µs|us|sec|×|x\s*slower|req/s|MB/s)" | ||
| r"|(?:\d+\.\d+|\d+)\s*×", | ||
| re.IGNORECASE, | ||
| ) |
There was a problem hiding this comment.
Unit regex matches English prefixes
Low Severity
BENCHMARK_TABLE_CELL_RE matches sec, ms, and us without a trailing boundary, so ordinary words such as seconds, messages, or users after a number count as measurement cells. A timeout or options table written in English can then fail the T7 gate.
Reviewed by Cursor Bugbot for commit 07e020b. Configure here.
Regenerate via inv-adr.ps1 after item 9 staged-scope edit (no -RatifiedBy).
Only skip header+separator when line 2 is a --- row; staged + chunks may be data-only.
Require digit before measurement units; (?:ms|µs|us|sec) not followed by letters; extend parametrized probes.


What changes
.cursor/rules/adr-trigger.mdc— bullet: link evidence, do not paste tables/logs/Operator decision (YYYY-MM-DD).tests/adr_governance_support.py(embedded_experimental_data_violations).tests/test_adr_governance_phase1.py(T7 corpus, staged+lines, synthetic fixtures, auditor probe table).docs/plans/PLAN_ADR_GOVERNANCE_ENFORCEMENT.md.docs/adr/INVENTORY.txt— regenerated viainv-adr.ps1(body hash drift on ADR-0045).What the detector flags
Operator decision (YYYY-MM-DD)with optional Markdown prefixes (bullet, blockquote, bold).ms,µs/us,×,x slower,req/s,MB/s).PASSED,FAILED, or pytest-styleN passed/passed in Ns).What it does not flag
status: failedinside a YAML sample block (no case-insensitive barefailedmatch).%coverage splits or timeout tables with5 s/30 s(generic%/ baresare out of scope).Transparency (required)
docs/adr/ADR-*.mdfiles.µs/call) that the table heuristic would flag.check_tables=False, so legacy Accepted ADRs are not retroactively charged; the table rule applies only to added lines in new or amended ADRs (pre-commit staged diff).grandfather.json.Fixtures
tests/fixtures/adr_t7_*— no text copied from private repos.Ratification
INVENTORY.txtwas regenerated without-RatifiedBy; ADR-0045 SSHSIG ratification remains pending operator per ADR-0056.Test plan
./scripts/check-all.shexit 0Closes #1925
Note
Low Risk
Documentation and pre-commit governance tests only; no runtime, auth, or data-path changes.
Overview
Adds ADR governance T7 (#1925): ADRs must record decisions in prose and link versioned evidence instead of embedding raw spikes, benchmark tables, or test-runner logs.
ADR-0045 gains Decision item 9 (forbidden shapes + allowed pinned paths) with a Status history amendment; ADR-0000 and
.cursor/rules/adr-trigger.mdctell agents to follow the same rule when materializing ADRs.embedded_experimental_data_violationsintests/adr_governance_support.pydetectsOperator decision (YYYY-MM-DD)lines, fenced pytest-style output, and (on staged+lines only) markdown tables with three or more measurement-like rows; the full-corpus check usescheck_tables=Falseso legacy Accepted ADRs are not retroactively blocked. Phase 1 tests and synthetic good/bad fixtures exercise the detector; the enforcement plan and regeneratedINVENTORY.txtreflect the ADR body edits.Reviewed by Cursor Bugbot for commit 07e020b. Bugbot is set up for automated code reviews on this repo. Configure here.