Repository navigation
fix(sieve): stop classing every undeclared exec exit as network (#562) - #564
Merged
mlieberman85 merged 2 commits intoOct 7, 2026
Merged
Conversation
…its (darnitdevorg#562) An exec step whose command exits with a code the step does not declare was classed network whenever stderr matched no rate-limit or auth pattern, though most such exits (grep on a missing directory, git outside a repository) never touch the network. framework-design 3.3 now gives the decision table: rate_limit, auth, missing_tool (exit 127 or command not found), network only for a connection error on stderr, and otherwise the new class unexpected_exit; the step's message names the exit code, command, and start of stderr. Section 5.2 lists the class. The feature 036 contract gets an addendum recording the change. Assisted-by: Claude:claude-opus-5-5 Signed-off-by: Michael Lieberman <mlieberman85@gmail.com>
…itdevorg#562) _classify_exec_failure now takes the exit code and executable. After the rate-limit and auth patterns (auth also matches "not logged in"), exit 127, "command not found", or a stderr line ending "<executable>: not found" is missing_tool; a connection error on stderr (name resolution, refused/reset/timed-out connection, unreachable host, TLS or certificate failure, git "unable to access" without an HTTP status) is network; anything else is the new ErrorClass unexpected_exit. The step's message carries the exit code, the command, and the first 200 characters of stderr on one ASCII line. The step stays INCONCLUSIVE as before. Reports, SARIF, JSON, CLI text, and the attestation predicate render the class name they are given; tests pin that for unexpected_exit. The test that expected network for git exiting 128 now expects unexpected_exit. Assisted-by: Claude:claude-opus-5-5 Signed-off-by: Michael Lieberman <mlieberman85@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
When an
execstep's command exited with an undeclared code,_classify_exec_failurelabelled iterror_class=networkunless stderr matched an auth or rate-limit pattern. Local failures read as network problems as a result. In one full test run, 232 of 242error_class=networkwarnings came from this path. The most common causes were:grepfinding no.github/workflows/(105);fatal: not a git repository(35).With this change:
unexpected_exit: a command exited with a code its step did not declare, and nothing in its output identified the cause.rate_limit;auth;<executable>: not found->missing_tool;network. These are DNS, refused or reset connections, unreachable hosts, connection timeouts, and TLS or certificate errors. An HTTP status reply such as git's "The requested URL returned error: 404" is excluded, because the server answered;unexpected_exit.gh_api, timeouts, and crashes.After the change, the same test run has 10
error_class=networkwarnings, all from MCP.Spec changes were made first:
docs/architecture/framework-design.md: section 3.3 gains a decision table and a scenario; section 5.2 adds the class to the list.specs/036-tier2-error-class/contracts/error-class-addendum-562.md:unexpected_exitreplacesnetworkas the catch-all for undeclared exec exits.Closes #562
Type of Change
Anything that filtered on
error_class == "network"for undeclared exec exits seesunexpected_exitnow; the CHANGELOG notes this under Changed.Framework Changes Checklist
docs/architecture/framework-design.md) if behavior changeduv run python scripts/validate_sync.py --verboseand it passesTesting
uv run pytest tests/ -v): 5210 passed, 29 skippeduv run ruff check .)New tests:
Also passing: the corpus gates, and the integration tests with GitHub Actions environment variables set (334 passed).
AI assistance
Claude (Claude Code, claude-opus-5-5) made this change: spec, code, and tests. This description was also drafted with Claude. Commits carry an
Assisted-by: Claude:claude-opus-5-5trailer.Additional Notes
An undeclared exit keeps the step INCONCLUSIVE. When nothing else concludes, the control ends WARN with the generic message. The new cause is in the WARN log line and the step's pass history.
🤖 Generated with Claude Code