Skip to content

Agentic SQA

Verification that shows its work

Agentic SQA investigates pull requests in C codebases, finds likely defects and reports each one with evidence: the suspected failure mode, the affected code and the next step. Delivered through Foundry Verify in GitHub, with local verification through the uok CLI.

Security and data handling

Anatomy of a finding

Every finding answers four questions. What part of the change is risky. How it is likely to fail. Exactly which code is affected. And the evidence for it, claim by claim, tied to the exact lines.

ir-labs-foundry-verify Bot left a comment

Foundry Verify — updated for commit 1974591

Caution

This change likely introduces a bug. If it does, the bug would be reachable now.

Summary

The change introduces an off-by-one bounds check in the rocket power_profile sysfs handler. A write of profile value 3 passes profile > ARRAY_SIZE(rocket_power_profiles) and then indexes rocket_power_profiles[3], even though the array has valid indices 0 through 2. This can read out of bounds when applying the profile and can leave an invalid profile stored for later show or core-init consumers if execution continues.

What would trigger it

  1. A rocket device successfully initializes and exposes its device sysfs attributes.
  2. A writer stores the unsigned integer value 3 to the power_profile sysfs attribute.
Evidence and checks
ClaimEvidenceSource
The bounds check allows index 3. lines 15-28 define rocket_power_profiles with valid indices 0, 1, and 2, but profile value 3 equals ARRAY_SIZE(rocket_power_profiles) and passes before indexing rocket_power_profiles[profile]. rocket_sysfs.c:15-28
The reported profile indices exclude 3. lines 41-52 define the invariant profile < ARRAY_SIZE(rocket_power_profiles), so ARRAY_SIZE(rocket_power_profiles) is not a valid power_profile index. rocket_sysfs.c:41-52
User input reaches the off-by-one index. lines 70-87 parse unsigned power_profile input and pass it to rocket_power_profile_apply, so writing "3" reaches cfg = &rocket_power_profiles[3]. rocket_sysfs.c:70-87

Have feedback? Put it in a reply.

Where investigation ends and verification begins

The agent investigates every change probabilistically. It reads the diff in the context of your codebase, its structure and its history, then forms a hypothesis about what could fail. That part is judgment, and we treat it as judgment: every finding carries its reasoning and its exact scope, so a maintainer can accept or reject it on the merits.

Generic review bots stop there. A general model can produce a plausible remark about any code, but the tools generating the code cannot credibly referee their own output. Plausible is not the bar in systems code.

That is why the next layer is deterministic. uok takes eligible claims from a review and checks them against the exact revision in the developer's own environment. Not every claim can be mechanically decided. When one can, uok returns PROVEN or REFUTED with supporting evidence. When one cannot, the verdict is NOT PROVABLE.

And when nothing clears the bar, the product says nothing. Calibrated silence is a design decision. Noise is a tax and we do not charge it.

What's live and what's next

Pull request

Your C change

Agent review

Reads the diff and context

Finding

Risk, failure mode, next steps

Local verification

Checks eligible claims with uok

Live today

Live today: agentic investigation, findings with evidence, check-run statuses, PR commands and local verification of eligible claims through the uok CLI.

Verify locally with uok

uok is the Agentic SQA command-line tool for checking concrete review claims against the exact code revision in your own environment. Run it from a developer checkout, CI job or coding-agent workflow and get PROVEN, REFUTED or NOT PROVABLE verdicts with supporting evidence.

curl -LsSf https://get.irlabs.ai/uok/install.sh | sh

Linux x86-64 and arm64, with Docker for other platforms. The CLI docs have the full matrix.

Manage it from one place

Every workspace includes a management console. Watch usage in real time, enable and disable repositories without touching GitHub, manage billing through Stripe and reach support directly. Reviews respect your plan limits and tell you when they pause.

The workspace console showing the current plan and review usage The workspace console repositories card showing a connected private repository with reviews enabled

Made for the hard layer

Kernel modules, device drivers, firmware, embedded targets and the C libraries everything else stands on. If your world has hardware targets, real-time constraints or a kernel tree in it, this was built for you.

Connect a repository in minutes. Reviews start on your next pull request.