Skip to content

Type-check this package as a ratchet - #6

Merged
exploitintel merged 2 commits into
mainfrom
chore/mypy
Aug 18, 2026
Merged

exploitintel merged 2 commits into
mainfrom
chore/mypy

Conversation

@exploitintel

Copy link
Copy Markdown
Owner

Nothing type-checked this code. mypy finds 22 errors across 7 of 14 modules.

A ratchet, not an allowlist

Everything is checked by default and the 7 failing modules are listed as exemptions, never the inverse. Listing what is checked leaves every new module unchecked by default, so debt accumulates silently and the list is the same size in a year. This way new code is checked without anyone deciding to check it, and the list can only shrink.

Why exempt rather than fixed

The errors are narrowing failures in query, cursor and rendering paths. Fixing them belongs in deliberate per-module changes with their own test evidence, not bundled into a tooling PR where a mistake would be invisible.

The list cannot go stale

warn_unused_configs reports an exemption matching nothing, but mypy prints that as a note and still exits 0, so the CI step pipes the output and greps for it. Verified on another repository in this campaign with the insertion confirmed and a warm cache.

Verification

PASS  ruff check / ruff format --check
PASS  mypy
      pytest  ->  unchanged

Gate proven: a new module containing def probe(x: int) -> str: return x fails.

Nothing type-checked this code. mypy finds 22 errors across 7 of 14 modules.

Everything is checked by default and the 7 failing modules are listed as
exemptions, never the inverse. Listing what is checked would leave every new
module unchecked by default, so debt would accumulate silently and the list would
be the same size in a year. This way new code is checked without anyone deciding
to check it, the list reads as a debt register rather than an achievement, and it
can only shrink.

The errors are narrowing failures in query, cursor and rendering paths. Fixing
them belongs in deliberate per-module changes with their own test evidence, not
bundled into a tooling PR where a mistake would be invisible. Removing a module
from the list plus fixing its errors is the unit of progress.

warn_unused_configs reports an exemption that matches nothing, but mypy prints
that as a note and still exits 0, so the CI step pipes the output and fails on
it. Without that a fixed module could quietly keep its exemption.

Verified rather than assumed: the current tree passes, and a new module with a
deliberate type error fails, confirming new code is checked. Behaviour unchanged.
@claude

claude Bot commented Aug 18, 2026

Copy link
Copy Markdown

Reviewed as an API client / hostile-terminal-data boundary change. This PR is tooling-only: it adds a mypy CI step, a [tool.mypy] ratchet config in pyproject.toml (7 of 14 modules exempted via ignore_errors), a mypy==2.3.1 dev dependency, and .gitignore entries. It does not touch src/ — no changes to filters/sorts/cursors, rendering, corpus text handling, PoC token flow, archive extraction, pagination, or JSON-mode output.

The CI gate logic checks out: the default GitHub Actions bash shell already runs with -e -o pipefail, so a real mypy failure in one of the 7 checked modules exits the step immediately via the pipe before the grep runs; the grep -q 'unused section' check only fires when mypy itself exits 0, correctly catching a stale exemption (an override matching no files) without masking genuine type errors.

No findings in the categories this review covers (opaque cursors, page-local re-ranking, exploit/lab safety claims, terminal escaping, token leakage, archive/extraction safety, stdout contamination, unbounded pagination/concurrency, scope creep into corpus/offline storage). Nothing to flag.

The verification block listed ruff check and pytest. CI now also runs
ruff format --check and mypy, added by this campaign, so the list was two gates
short of the truth.
@claude

claude Bot commented Aug 18, 2026

Copy link
Copy Markdown

Reviewed against the API-client / hostile-terminal-data security checklist for this repo. This PR is CI/tooling-only — it adds a mypy pyproject.toml config (ratchet-style: everything checked by default, 7 modules listed as temporary exemptions), a CI step, .gitignore entries, and doc/dev-requirements updates. No file under src/ is modified, so none of the in-scope categories apply here: no filter/sort/cursor changes, no corpus-text rendering, no PoC/token handling, no archive extraction, no JSON-mode or pagination/concurrency code.

No findings.

(Side note, not a finding: the new CI gate in .github/workflows/quality.yml correctly preserves mypy's exit code through tee via set -o pipefail, and separately fails the build if warn_unused_configs reports a stale exemption. Logic looks sound.)

@exploitintel
exploitintel merged commit f75f7f5 into main Aug 18, 2026
4 checks passed
@exploitintel
exploitintel deleted the chore/mypy branch August 18, 2026 21:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant