Files
agenticCode/prompts/wgeagb0s-deep-api-audit.md
Ingo Schnabel 0dfc85a11b Fixes
2026-07-19 10:34:15 +02:00

3.8 KiB

Deep API Audit — WGEAGB0S + all subprograms

Preconditions: The agentic server is up (http://localhost:8787) and a deep refresh of project upms has completed. If the server is unreachable, stop and ask the human to run ./manage-ac.sh deploy — never start Docker yourself.

Task

Perform a very deep analysis of all agentic API endpoints, in two tiers:

  1. Deep dive — WGEAGB0S (worked example): ingest module WGEAGB0S and, for each endpoint, determine whether the response is correct by manually reading the Natural source and comparing it against the API output, field-by-field.
  2. Broad sweep — every subprogram in upms: verify the same endpoints across all subprograms, not just WGEAGB0S. Manual reading of every source is infeasible at that scale, so drive the sweep with automated cross-checks (below) that catch whole classes of defects, and escalate any module that fails a check to a manual, source-level deep dive like tier 1.

How to work

  1. Use the REST API (GET /api/projects/upms/modules/{name}/...), falling back to the ac CLI for quick manual checks. Do not use MCP for this audit. For WGEAGB0S (and any escalated module) pull every relevant endpoint: callees, callers, db-accesses, functions, data-structures, dispatch-table, digest, context, call-tree, sql-statements, graph.
  2. Read the Natural source manually (the module plus its USING data areas / copycodes) and verify each response field-by-field: call graph, DB accesses (READ/WRITE mode), variable reads/writes, field/placeholder resolution, dispatch table. Note the sources are ISO-8859 encoded — use grep -a / an encoding-aware reader.
  3. Broad-sweep cross-checks (all subprograms). Enumerate every subprogram (GET /modules?..., or the generated_src/user_exit/manual subprogram/ dirs) and assert API-derivable invariants that need no per-module reading, e.g.:
    • No MODULE self-loop: callers/callees never list a module as its own caller/callee.
    • callers default is external-only: the default view lists incoming CALLNAT/inheritance only — never the module's own subroutines (those belong to scope=internal).
    • Callee resolution matches source: every callees CALLNAT target appears as a real CALLNAT '<name>' in the module or one of its INCLUDEd copycodes (grep-verifiable), with correct viaCopycode/includedAt provenance — and no phantom targets.
    • Function count parity: digest.functionCount == the number of DEFINE SUBROUTINE in the source; every performed subroutine exists as a FUNCTION.
    • DB access sanity: modules with no READ/FIND/STORE/UPDATE/DELETE report empty db-accesses/sql-statements; those with them resolve to real DB_TABLEs. Rank modules by check failures; the worst offenders get a tier-1 manual deep dive.
  4. Report every discrepancy you find. For each: the endpoint and exact wrong value, the ground truth from the source (with line references), and the suspected root cause in the parser/enricher/Cypher. For sweep findings, report the failing invariant, the count and list of affected modules, and a representative worked example.
  5. Propose a concrete fix for each error.
  6. Write failing characterization tests first (Testcontainers ITs with minimal Natural fixtures that reproduce the bug), then confirm they go green after the fix.

Output

A structured report:

  • Per-endpoint for WGEAGB0S: PASS or the list of discrepancies with ground-truth evidence, root-cause hypothesis, fix proposal, and the test that covers it.
  • Broad sweep: per invariant, PASS or the affected-module count + list + a worked example, with the same root-cause/fix/test treatment for each distinct defect class.