Skip to content

Final beta-readiness pass: enable publication, Gemini-safe rate limiting, CI stabilization - #64

Merged
kadireren7 merged 7 commits into
mainfrom
stabilize/beta-readiness
Sep 23, 2026
Merged

kadireren7 merged 7 commits into
mainfrom
stabilize/beta-readiness

Conversation

@kadireren7

Copy link
Copy Markdown
Owner

Summary

Final beta-readiness pass before AA, covering four goals:

  • Publication: .patchfrog.yml with publish.enabled: true -- this repo had no config at all, so publish.enabled fell back to its safe-by-default False and every run logged review_publish_disabled_by_config.
  • Gemini free-tier safety: new patchfrog/review/rate_limiter.py -- an opt-in, process-wide sliding-window requests-per-minute limiter wrapping real provider construction (production and CLI paths), gated by a new PATCHFROG_PROVIDER_RATE_LIMIT_RPM operator setting (unset = unthrottled, today's behavior unchanged). call_with_retry now honors a provider-reported retry-after hint (Gemini's RetryInfo.retryDelay, Anthropic/OpenAI's Retry-After header) instead of blind exponential backoff, capped at 65s.
  • CI stabilization: audited and re-ran every gate for real (ruff, semgrep presence, mypy --strict, Alembic single-head migration against a real Postgres, full pytest suite, both Docker image builds, Celery task registration, oracle-provider eval sanity) -- all green, 2523 tests passed, 0 skipped, 0 real product regressions found. One local-only false-failure mode diagnosed and documented (a developer's own .env leaking real provider keys into Settings() via env_file=".env", defeating "credential absent" test assumptions -- never reproducible in CI, which has no .env).
  • GitHub publication lifecycle proof: audited existing deterministic (fake-provider/fake-GitHub) test coverage across all 11 required scenarios; found and closed the one real gap -- nothing previously proved publish.enabled=false in PUBLISH mode produces an explicit SKIPPED_DISABLED result rather than a silent no-op.

Full audit, findings, and scope notes: validation/final_beta_readiness/latest-summary.md.

patchfrog-cloud was not touched -- every change here is review-behavior config or engine code that determines how PatchFrog reviews code, not hosted-SaaS lifecycle.

Test plan

  • ruff check . clean
  • mypy . --strict clean (663 source files)
  • alembic upgrade head against real Postgres; alembic heads shows exactly one head
  • pytest -q -- 2523 passed, 0 skipped, 0 failed
  • Both Docker images (api, worker) build clean
  • Celery task registration inside the built worker image reports the expected 9 tasks
  • Oracle-provider eval sanity subset (no live LLM calls): precision 1.0 / recall 1.0 / f1 1.0
  • New unit tests for the rate limiter (sliding-window correctness, no busy-loop, registry keying) and retry-after handling (exponential-backoff fallback, capping, per-provider extraction)
  • New integration test proving publish.enabled=false in PUBLISH mode is an explicit skip, never a silent success

Not merging automatically -- awaiting review per project workflow.

🤖 Generated with Claude Code

kadireren7 and others added 7 commits September 21, 2026 17:50
…ling

Production evidence: PatchFrog's own specialist-role fan-out and bounded
retries can exceed Gemini's free-tier per-minute quota on their own, with
no external traffic. Adds an opt-in, process-wide sliding-window
requests-per-minute limiter (patchfrog/review/rate_limiter.py) wrapping
real provider construction in both the production (routing/router.py) and
CLI (review/provider_factory.py) paths, gated by a new operator-only
PATCHFROG_PROVIDER_RATE_LIMIT_RPM setting (unset = unthrottled, unchanged
default). Also teaches call_with_retry to honor a provider-reported
retry-after hint (Gemini's RetryInfo.retryDelay, Anthropic/OpenAI's
Retry-After header) instead of blind exponential backoff, capped so one
delay can't consume a whole run's elapsed-time budget.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
No .patchfrog.yml existed in this repo, so publish.enabled fell back to
its safe-by-default False (patchfrog/publishing/config.py) -- production
logged review_publish_disabled_by_config on every run. Adds .patchfrog.yml
with publish.enabled: true and nothing else (no other publication control
weakened). Closes the one gap found while auditing GitHub-publication test
coverage: nothing previously exercised PUBLISH mode with publication
disabled by config and asserted the explicit SKIPPED_DISABLED outcome
(never a silent success) against a fake GitHub publisher.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
CI run 35781841389 failed at "Verify required static analyzers":
`semgrep --version` crashed with ModuleNotFoundError: pkg_resources.

Newer semgrep releases pin mcp==1.29.0. Once mcp 1.30.0 was published,
pip kept the newest mcp allowed by our own `mcp>=1.29,<2.0` and
backtracked semgrep from 1.177.0 to 1.136.0, the last pre-mcp release.
That release depends on opentelemetry-instrumentation 0.46b0, which
imports pkg_resources; setuptools 84 (pulled in via `setuptools>=16`)
no longer ships it (removed in 82). The Docker images install the same
dependency set, so the runtime semgrep analyzer was broken there too.

Raise the semgrep floor to 1.173 (opentelemetry 0.58b0, no
pkg_resources) so the resolver can no longer select the broken line.
The analyzer verification step is unchanged.
@kadireren7
kadireren7 merged commit 989567c into main Sep 23, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant