3.8 KiB
3.8 KiB
Deep API Audit — WGEAGB0S + all subprograms
Preconditions: The agentic server is up (http://localhost:8787) and a deep refresh of
project upms has completed. If the server is unreachable, stop and ask the human to run
./manage-ac.sh deploy — never start Docker yourself.
Task
Perform a very deep analysis of all agentic API endpoints, in two tiers:
- Deep dive — WGEAGB0S (worked example): ingest module WGEAGB0S and, for each endpoint, determine whether the response is correct by manually reading the Natural source and comparing it against the API output, field-by-field.
- Broad sweep — every subprogram in
upms: verify the same endpoints across all subprograms, not just WGEAGB0S. Manual reading of every source is infeasible at that scale, so drive the sweep with automated cross-checks (below) that catch whole classes of defects, and escalate any module that fails a check to a manual, source-level deep dive like tier 1.
How to work
- Use the REST API (
GET /api/projects/upms/modules/{name}/...), falling back to theacCLI for quick manual checks. Do not use MCP for this audit. For WGEAGB0S (and any escalated module) pull every relevant endpoint:callees,callers,db-accesses,functions,data-structures,dispatch-table,digest,context,call-tree,sql-statements,graph. - Read the Natural source manually (the module plus its
USINGdata areas / copycodes) and verify each response field-by-field: call graph, DB accesses (READ/WRITE mode), variable reads/writes, field/placeholder resolution, dispatch table. Note the sources are ISO-8859 encoded — usegrep -a/ an encoding-aware reader. - Broad-sweep cross-checks (all subprograms). Enumerate every subprogram (
GET /modules?..., or thegenerated_src/user_exit/manualsubprogram/dirs) and assert API-derivable invariants that need no per-module reading, e.g.:- No
MODULEself-loop:callers/calleesnever list a module as its own caller/callee. callersdefault is external-only: the default view lists incoming CALLNAT/inheritance only — never the module's own subroutines (those belong toscope=internal).- Callee resolution matches source: every
calleesCALLNATtarget appears as a realCALLNAT '<name>'in the module or one of itsINCLUDEd copycodes (grep-verifiable), with correctviaCopycode/includedAtprovenance — and no phantom targets. - Function count parity:
digest.functionCount== the number ofDEFINE SUBROUTINEin the source; every performed subroutine exists as aFUNCTION. - DB access sanity: modules with no
READ/FIND/STORE/UPDATE/DELETEreport emptydb-accesses/sql-statements; those with them resolve to realDB_TABLEs. Rank modules by check failures; the worst offenders get a tier-1 manual deep dive.
- No
- Report every discrepancy you find. For each: the endpoint and exact wrong value, the ground truth from the source (with line references), and the suspected root cause in the parser/enricher/Cypher. For sweep findings, report the failing invariant, the count and list of affected modules, and a representative worked example.
- Propose a concrete fix for each error.
- Write failing characterization tests first (Testcontainers ITs with minimal Natural fixtures that reproduce the bug), then confirm they go green after the fix.
Output
A structured report:
- Per-endpoint for WGEAGB0S: PASS or the list of discrepancies with ground-truth evidence, root-cause hypothesis, fix proposal, and the test that covers it.
- Broad sweep: per invariant, PASS or the affected-module count + list + a worked example, with the same root-cause/fix/test treatment for each distinct defect class.