पाठ 3 / 25

The Safe Fix Pipeline

Reproduce, localise, patch, verify, review.

Stages with gates

A safe pipeline has explicit stages: (1) reproduce the bug with a failing test; (2) localise the cause using traces, logs or bisect; (3) generate one or more minimal candidate patches in a sandbox; (4) verify each candidate in isolation: the new test passes, the full suite passes, nothing protected is touched, no secrets, small diff, static checks pass; (5) open a pull request with evidence for human review; (6) monitor after merge and revert quickly if needed. Each gate can stop the run.

The pipeline with its gates

Any failed gate stops the run.

issue / failing CI
 -> reproduce: failing test committed to a branch        [gate: test fails before fix]
 -> localise: trace, logs, git bisect                   [gate: suspect files identified]
 -> patch: candidates in a sandbox                      [gate: diff size, allowed files]
 -> verify: new test + full suite + lint/types          [gate: all green, no tampering, no secrets]
 -> PR with evidence -> human review                    [gate: approval]
 -> merge -> monitor -> revert if needed

Make the failing test the contract

If you cannot write a test that fails before and passes after, the problem is not ready for automated fixing.

त्वरित जाँच: What should come first in a safe fix pipeline?

  • Rewriting the module
  • Merging a patch
  • Deleting old tests
  • Reproducing the bug with a failing test
Answer

Reproducing the bug with a failing test — Reproduce before fixing.