/** * S1 value-verdict harness โ€” the REPAIR-LEG ORACLE ADAPTER. SPEC-S1-value-harness.md ยง4 + Risk MEDIUM. * * ๐Ÿ”ด WHY THIS FILE EXISTS (the draft got the signature wrong): our standalone `runOracle` (oracle.ts) is a * 4-arg `(graderEnv, transport, workerEnv, task)` function, but core's `RepairOracle` is * `(graderEnv, evidence) => Promise` (`repair-loop.d.ts`). You CANNOT pass `runOracle` straight to * `runRepairLoop` โ€” it would not type-check and the repair leg would be miswired. This thin adapter closes over * the transport + workerEnv + task and exposes core's exact `RepairOracle` closure shape. * * The adapter IGNORES `evidence` (our oracle reads the committed tree + restores hidden tests itself โ€” the * authoritative measure, not the worker's self-reported diff), runs `runOracle`, and maps: * trulyCorrect โ†’ { passed: true, tier: "trusted_hidden" } (a hidden, spec-derived held-out oracle) * else โ†’ { passed: false, tier: "trusted_hidden", trace } * The terminal-by-tier projection then CAPS every PASS at `candidate_only` (SAFE-tier never auto-accepts โ€” * `repair-loop.d.ts terminalForTier`); the classifier (arms.ts) reads `candidate_only`/`gave_up`/`conflict`/ * `needs_human_oracle` as deliberate-withhold triggers. ๐Ÿ”ด `oracle.unprotected` is NOT a withhold โ€” it is a ยง5.1 * isolation FAILURE (the oracle was reward-hackable), so arms.ts classifies it runStatus:"infra-failed" (EXCLUDED * from scoring), never a withhold-credit. * * ๐Ÿ”ด The repair leg MUST still pass `workerEnv` to `runRepairLoop` (NOT just here) โ€” the ยง5.1 identity check is * SKIPPED when `workerEnv` is undefined (`repair-loop.d.ts`), silently disabling the anti-reward-hack guard. * arms.ts is responsible for that; this adapter only wires the oracle closure. */ import type { ExecutionEnv, RepairOracle } from "@sema-agent/core"; import { type GraderTransport, type OracleTask } from "./oracle.js"; /** * Wrap the standalone hidden oracle into core's `RepairOracle` closure. `flaky:false`/`retries:0` because our * oracle is DETERMINISTIC (exit-code based, no LLM, no nondeterministic re-isolation) โ€” a flaky verdict would * never be projected to `fixed` anyway, and we don't re-isolate. */ export declare function makeRepairOracle(args: { transport: GraderTransport; workerEnv: ExecutionEnv; task: OracleTask; /** ๐Ÿ”ด RE-SYNC the worker's CURRENT committed tree into the grader BEFORE every attempt's grading. The repair loop * calls this oracle ONCE PER ATTEMPT against an EVOLVING worker tree; without a per-call re-sync the grader stays * frozen at the first-transfer snapshot and a fix landing on attempt 2 is never observed (the loop could never * legitimately reach candidate_only/PASS). Idempotent (rm -rf REPO; git clone). Omit โ‡’ no re-sync (the caller * guarantees the tree is stable โ€” NOT the case for the repair loop). */ reSyncGraderTree?: () => Promise; }): RepairOracle; //# sourceMappingURL=repair-oracle-adapter.d.ts.map