feat(notes): a note's check is writable through both doors, and empty means empty (#3164, milestone 317 step 2)
CI & Build / Python lint (push) Successful in 3s
CI & Build / Plugin hooks (push) Successful in 14s
CI & Build / TypeScript typecheck (push) Successful in 38s
CI & Build / integration (push) Successful in 32s
CI & Build / Python tests (push) Failing after 49s
CI & Build / Build & push image (push) Skipped

The rules path's three lessons (#3096), inherited:

EMPTY MEANS NULL. The sweep's whole signal is `verify_with IS NULL` = "this is
a decision, there is nothing to go and check". A "" that is not NULL makes a
norm look like a constraint nobody has verified — and never-checked sorts
FIRST, so it would sit at the top of the sweep forever.

CLEARING IS EXPLICIT. At the MCP door "" means "leave this alone", so an agent
updating a body does not wipe a check it was never asked about — which leaves
no value meaning "remove it". `clear` names the field, and naming it cannot
happen by accident. The REST door, where a cleared form input arrives as "",
reaches the same place through normalisation: two idioms, one outcome.

THE STAMP CERTIFIES A CHECK, NOT A RECORD. Rewrite or clear `verify_with` and
`verified_at` is dropped, so the note re-enters the sweep. A note wrongly
listed as due costs one look; a note wrongly vouched for costs exactly what
the sweep exists to catch. `verified_at` is also no longer settable through an
ordinary edit — a stamp says somebody performed THIS check, and minting one
from a write that ran no check is the one thing that would make the sweep lie.

And one this path adds: not every record may carry a check. A task's decay is
its status — a done issue records what happened rather than asserting
something that can go false — and a snippet already has verify_snippet, which
compares its recorded location and code against the repo and expires its own
verdict. Both are refused with a message naming the alternative, never dropped
silently (minted_kind's reasoning, #3129), and the gate lives at the service
so the two doors cannot come to disagree.

Written as an INVARIANT over the resulting record, not a filter on which
fields were passed. That is what catches the sideways route — a checked note
being turned into a task, a write that names no check at all and would sail
past any per-field gate.

The MCP docstrings carry the norm-vs-constraint test, because at that door the
docstring IS the contract and a field described only as "how to verify this"
gets filled in on every note. Step 5 does this properly across the instruction
surfaces; this is the minimum that stops the field being misused on arrival.

tests/helpers gains `drive_update_note` — the patch stack for driving
update_note, written twice before this and now once. The note-shaped fakes
gain the trio explicitly, for fake_note's own stated reason: an unset
attribute is a truthy MagicMock, and a truthy verify_with reads as a check
that is there.
This commit is contained in:
2026-08-28 15:42:12 -04:00
parent b134fe9aa1
commit 700ef20eb0
7 changed files with 398 additions and 25 deletions
+33 -1
View File
@@ -9,7 +9,33 @@ from __future__ import annotations
from contextlib import contextmanager
from datetime import datetime, timezone
from types import SimpleNamespace
from unittest.mock import AsyncMock, MagicMock
from unittest.mock import AsyncMock, MagicMock, patch
async def drive_update_note(note, **kwargs):
"""Run `services/notes.update_note` against a stand-in row.
The patch stack is the point: update_note reaches for a version snapshot,
an embedding refresh and a project reactivation on its way out, none of
which a unit test has. Written twice — once for the snippet mirror
(#3128) and once for the verification fields (#3182/317) — before being
consolidated here.
Returns whatever update_note returned; assert on the `note` you passed in.
"""
from unittest.mock import AsyncMock as _AsyncMock
session = make_mock_session()
result = MagicMock()
result.scalars.return_value.first.return_value = note
session.execute = _AsyncMock(return_value=result)
with patch("scribe.services.notes.async_session") as cls, \
patch("scribe.services.notes.embed_note", MagicMock()), \
patch("scribe.services.notes._maybe_reactivate_project", _AsyncMock()), \
patch("scribe.services.note_versions.create_version", _AsyncMock()):
cls.return_value = session
from scribe.services.notes import update_note
return await update_note(user_id=7, note_id=note.id, **kwargs)
def compiled_sql(element) -> str:
@@ -102,6 +128,9 @@ def fake_note(**attrs) -> MagicMock:
"id": 1, "title": "t", "body": "", "tags": [], "user_id": 7,
"note_type": "note", "is_task": False, "task_kind": "work",
"data": None, "deleted_at": None,
# Milestone 317: a truthy mock here reads as "this note carries a
# check", which trips the guard on records that may not have one.
"verify_with": None, "expires_when": None, "verified_at": None,
}, attrs)
@@ -111,6 +140,7 @@ def fake_task(**attrs) -> MagicMock:
"id": 1, "title": "t", "body": "", "status": "todo", "priority": "none",
"tags": [], "parent_id": None, "project_id": None, "is_task": True,
"task_kind": "work", "user_id": 7, "deleted_at": None,
"verify_with": None, "expires_when": None, "verified_at": None,
}, attrs)
@@ -122,6 +152,8 @@ def fake_snippet(**attrs) -> MagicMock:
"body": "```js\nreturn 1\n```\n", "tags": ["js", "snippet"],
"note_type": "snippet", "is_task": False, "task_kind": "work",
"user_id": 7, "data": None, "deleted_at": None,
"status": None,
"verify_with": None, "expires_when": None, "verified_at": None,
}, attrs)
+41 -3
View File
@@ -214,17 +214,53 @@ async def test_create_note_project_zero_becomes_none():
@pytest.mark.asyncio
async def test_update_note_only_sends_non_default_fields():
"""Omitted (default) fields must NOT reach the service — otherwise they'd
overwrite real data with empty strings."""
overwrite real data with empty strings.
`clear` is always forwarded and is not a field: it is how this door says
"unset these", and an empty one says "unset nothing". Same shape the rules
door took in #3096, and the same test that had to learn about it there."""
fake = fake_note()
mock = AsyncMock(return_value=fake)
with patch("scribe.mcp.tools.notes.notes_svc.update_note", mock):
await update_note(note_id=1, title="new title")
# Service got user_id, note_id positional + only the title kwarg
args, kwargs = mock.call_args
assert args == (7, 1)
assert kwargs.pop("clear") == (), "nothing was asked to be cleared"
assert kwargs == {"title": "new title"}
@pytest.mark.asyncio
async def test_update_note_forwards_a_check_but_not_an_empty_one():
""""" means "leave this alone" at this door — an agent updating a body must
not wipe a check it was never asked about (milestone 317)."""
mock = AsyncMock(return_value=fake_note())
with patch("scribe.mcp.tools.notes.notes_svc.update_note", mock):
await update_note(note_id=1, verify_with="curl the docs")
assert mock.call_args.kwargs["verify_with"] == "curl the docs"
with patch("scribe.mcp.tools.notes.notes_svc.update_note", mock):
await update_note(note_id=1, title="t")
assert "verify_with" not in mock.call_args.kwargs
@pytest.mark.asyncio
async def test_update_note_forwards_clear_so_a_check_can_be_removed():
"""The only way to unset a field at a door where "" means "leave alone"."""
mock = AsyncMock(return_value=fake_note())
with patch("scribe.mcp.tools.notes.notes_svc.update_note", mock):
await update_note(note_id=1, clear=["verify_with"])
assert mock.call_args.kwargs["clear"] == ["verify_with"]
@pytest.mark.asyncio
async def test_create_note_forwards_the_check_fields():
mock = AsyncMock(return_value=fake_note())
with patch("scribe.mcp.tools.notes.notes_svc.create_note", mock):
await create_note(title="t", verify_with="curl", expires_when="AMO changes")
assert mock.call_args.kwargs["verify_with"] == "curl"
assert mock.call_args.kwargs["expires_when"] == "AMO changes"
@pytest.mark.asyncio
async def test_update_note_empty_tags_clears_explicitly():
"""tags=[] is an explicit clear, distinct from tags=None (omit)."""
@@ -232,7 +268,9 @@ async def test_update_note_empty_tags_clears_explicitly():
mock = AsyncMock(return_value=fake)
with patch("scribe.mcp.tools.notes.notes_svc.update_note", mock):
await update_note(note_id=1, tags=[])
assert mock.call_args.kwargs == {"tags": []}
kwargs = dict(mock.call_args.kwargs)
kwargs.pop("clear")
assert kwargs == {"tags": []}
@pytest.mark.asyncio
+172
View File
@@ -0,0 +1,172 @@
"""A note's own check — verify_with / expires_when (milestone 317 step 2).
Three behaviours the rules path (#3096) had to get right and this one inherits:
empty means NULL, clearing is explicit, and rewriting the check drops the
stamp. Plus one this path adds: not every record may carry a check, and the
rule is an INVARIANT over the record rather than a filter on the write.
"""
from unittest.mock import AsyncMock, MagicMock, patch
import pytest
from tests.helpers import drive_update_note as _update
from tests.helpers import fake_note, make_mock_session
def _checkable(**over):
"""A plain note — no status, no snippet type, no check. `fake_note` is a
MagicMock, so every one of these must be set explicitly: an unset
attribute is a truthy mock, which would look like a check that is there."""
base = dict(
status=None, note_type="note",
verify_with=None, expires_when=None, verified_at=None,
project_id=None,
)
base.update(over)
return fake_note(**base)
async def _create(**kwargs):
session = make_mock_session()
captured = {}
session.add = MagicMock(side_effect=lambda obj: captured.update(
verify_with=getattr(obj, "verify_with", "MISSING"),
expires_when=getattr(obj, "expires_when", "MISSING"),
))
with patch("scribe.services.notes.async_session") as cls, \
patch("scribe.services.notes.embed_note", MagicMock()), \
patch("scribe.services.notes._maybe_reactivate_project", AsyncMock()):
cls.return_value = session
from scribe.services.notes import create_note
await create_note(user_id=1, title="t", **kwargs)
return captured
# ── empty means empty ────────────────────────────────────────────────────────
@pytest.mark.asyncio
async def test_an_empty_check_is_stored_as_null_not_as_a_blank():
"""The sweep's whole signal is `verify_with IS NULL` = "this is a decision,
there is nothing to check". A "" that is not NULL makes a norm look like a
constraint nobody has verified — and never-checked sorts FIRST, so it would
sit at the top of the sweep forever."""
assert (await _create(verify_with="", expires_when=""))["verify_with"] is None
note = _checkable(verify_with="curl the docs")
await _update(note, verify_with="")
assert note.verify_with is None
@pytest.mark.asyncio
async def test_a_check_is_stored_when_given():
captured = await _create(verify_with="curl the AMO docs", expires_when="AMO allows re-signing")
assert captured["verify_with"] == "curl the AMO docs"
assert captured["expires_when"] == "AMO allows re-signing"
# ── clearing is explicit ─────────────────────────────────────────────────────
@pytest.mark.asyncio
async def test_clear_unsets_a_field_the_mcp_door_cannot_empty():
"""At the MCP door "" means "leave this alone", so an agent updating a body
does not wipe a check it was never asked about. That leaves no value
meaning "remove it" — hence naming the field, which cannot happen by
accident."""
note = _checkable(verify_with="a check", expires_when="a state")
await _update(note, clear=["verify_with"])
assert note.verify_with is None
assert note.expires_when == "a state", "clearing one must not clear the other"
@pytest.mark.asyncio
async def test_clear_ignores_a_field_that_is_not_clearable():
note = _checkable(title="keep me", verify_with="a check")
await _update(note, clear=["title"])
assert note.title == "keep me"
# ── the stamp certifies a check, not a record ────────────────────────────────
@pytest.mark.asyncio
async def test_rewriting_the_check_drops_the_stamp():
note = _checkable(verify_with="the old check", verified_at="2026-01-01")
await _update(note, verify_with="a different check")
assert note.verified_at is None
@pytest.mark.asyncio
async def test_clearing_the_check_drops_the_stamp():
note = _checkable(verify_with="the old check", verified_at="2026-01-01")
await _update(note, clear=["verify_with"])
assert note.verified_at is None
@pytest.mark.asyncio
async def test_an_unchanged_check_keeps_its_stamp():
"""Only a CHANGE invalidates it — otherwise every unrelated edit would
re-enter the note into the sweep and the signal would mean nothing."""
note = _checkable(verify_with="the same check", verified_at="2026-01-01")
await _update(note, title="a new title", verify_with="the same check")
assert note.verified_at == "2026-01-01"
@pytest.mark.asyncio
async def test_a_stamp_cannot_be_set_through_an_ordinary_edit():
"""A stamp says somebody performed THIS check. Minting one from a write
that ran no check is the one thing that would make the sweep lie."""
note = _checkable(verify_with="a check", verified_at=None)
await _update(note, verified_at="2026-08-28")
assert note.verified_at is None
# ── the invariant: which records may carry a check ───────────────────────────
@pytest.mark.asyncio
async def test_a_task_is_refused_a_check():
with pytest.raises(ValueError, match="task"):
await _create(status="todo", verify_with="a check")
@pytest.mark.asyncio
async def test_a_snippet_is_refused_and_told_where_to_go():
"""The message has to name the alternative, or the caller is left with a
refusal and no route."""
with pytest.raises(ValueError, match="verify_snippet"):
await _create(note_type="snippet", verify_with="a check")
@pytest.mark.asyncio
async def test_turning_a_checked_note_into_a_task_is_refused():
"""THE reason this is an invariant over the resulting record and not a
filter on which fields were passed. This write names no check at all, and
would sail past any per-field gate."""
note = _checkable(verify_with="a check")
with pytest.raises(ValueError, match="task"):
await _update(note, status="todo")
@pytest.mark.asyncio
async def test_an_unchecked_note_can_still_become_a_task():
"""The invariant must not make ordinary promotion impossible."""
note = _checkable()
await _update(note, status="todo")
assert note.status == "todo"
@pytest.mark.asyncio
async def test_clearing_the_check_in_the_same_write_lets_it_become_a_task():
"""The error tells the caller to clear the check first; doing both at once
has to actually work, or the advice is wrong."""
note = _checkable(verify_with="a check")
await _update(note, status="todo", clear=["verify_with"])
assert note.status == "todo"
assert note.verify_with is None
@pytest.mark.asyncio
async def test_an_ordinary_note_write_is_untouched_by_any_of_this():
"""The common case: no check, nothing to guard, nothing to reset."""
note = _checkable(title="before")
await _update(note, title="after")
assert note.title == "after"
assert note.verify_with is None
assert note.verified_at is None
+2 -18
View File
@@ -13,10 +13,9 @@ reverse lookup and to prior-art recall while displaying its new body — a recor
surfaced with full authority and wrong, which the drift-check docstring calls
worse than having no record at all (#3128).
"""
from unittest.mock import AsyncMock, MagicMock, patch
import pytest
from tests.helpers import fake_note, fake_snippet, make_mock_session
from tests.helpers import drive_update_note as _update
from tests.helpers import fake_note, fake_snippet
OLD_MIRROR = {
"name": "debounce",
@@ -33,21 +32,6 @@ MOVED_BODY = (
)
async def _update(note, **fields):
session = make_mock_session()
result = MagicMock()
result.scalars.return_value.first.return_value = note
session.execute = AsyncMock(return_value=result)
with patch("scribe.services.notes.async_session") as cls, \
patch("scribe.services.notes.embed_note", MagicMock()), \
patch("scribe.services.notes._maybe_reactivate_project", AsyncMock()), \
patch("scribe.services.note_versions.create_version", AsyncMock()):
cls.return_value = session
from scribe.services.notes import update_note
await update_note(user_id=7, note_id=note.id, **fields)
return note
@pytest.mark.asyncio
async def test_a_body_write_moves_the_mirror_with_it():
note = fake_snippet(data=dict(OLD_MIRROR), project_id=None)