fix(coverage): materialize requirements-directory locks - #785
fix(coverage): materialize requirements-directory locks#785seonghobae wants to merge 40 commits into
Conversation
|
Important Review skippedDraft detected. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
@opencode-agent @cwl-noema-review Perform an independent formal exact-head review of The final diff contains only the permanent five-file product change; all transient repair workflows and transformers are absent. Recompute current-head coverage and public-docstring evidence; verify that only direct |
|
@coderabbitai review @opencode-agent @cwl-noema-review Independently review exact current head The exact head is workflow-free and all direct current-head security, supply-chain, and Trusted uv Materializer Quality checks are successful. Verify the narrow direct-child |
|
Tip For best results, initiate chat on the files or code changes. 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
base='f070c504c1cb06891b800d7ab0cf6ac7d3cf8eae'
head='ed33253e5d6f93f2e71d80b24e27b301f96efb88'
printf '\n== Exact commits ==\n'
git cat-file -e "${base}^{commit}"
git cat-file -e "${head}^{commit}"
git show -s --format='base=%H%nbase-subject=%s%nbase-date=%cI' "$base"
git show -s --format='head=%H%nhead-subject=%s%nhead-date=%cI' "$head"
printf '\n== Changed files and stat ==\n'
git diff --name-status "$base" "$head"
git diff --stat "$base" "$head"
printf '\n== Full product diff ==\n'
git diff --find-renames --find-copies --no-ext-diff "$base" "$head"
printf '\n== Candidate source maps for changed Python files ==\n'
git diff --name-only "$base" "$head" -- '*.py' |
while IFS= read -r file; do
[ -n "$file" ] || continue
echo "--- $file"
ast-grep outline "$file" --items all --view compact || true
done
printf '\n== Candidate discovery and provenance references at exact head ==\n'
rg -n -C 4 --glob '*.py' \
'(requirements|require-hashes|materiali[sz]|manifest|symlink|git\s+cat-file|ls-tree|blob|traversal)' .
printf '\n== Workflow inventory and write-capable workflow references ==\n'
fd -t f -e yml -e yaml .github 2>/dev/null || true
rg -n -i -C 3 --glob '*.yml' --glob '*.yaml' \
'(contents:\s*write|pull-requests:\s*write|actions/github-script|git\s+push|force-with-lease|workflow_dispatch)' \
.github 2>/dev/null || true
printf '\n== Relevant tests and documentation references ==\n'
rg -n -C 3 --glob '*test*.py' --glob '*.md' \
'(requirements/|requirements\*\.txt|require-hashes|materiali[sz]|manifest|symlink|nested|PR-only)' .
printf '\n== PR metadata, checks, and review state ==\n'
gh pr view 785 --repo ContextualWisdomLab/.github \
--json number,state,isDraft,headRefOid,baseRefOid,mergeStateStatus,reviewDecision,statusCheckRollup,reviews \
|| trueLength of output: 202327 🏁 Script executed: #!/bin/bash
set -euo pipefail
base='f070c504c1cb06891b800d7ab0cf6ac7d3cf8eae'
head='ed33253e5d6f93f2e71d80b24e27b301f96efb88'
printf '\n== Exact changed files ==\n'
git diff --name-status "$base" "$head"
printf '\n== Exact changed-file diff ==\n'
git diff --no-ext-diff --unified=80 "$base" "$head"
printf '\n== Materializer complete source map ==\n'
ast-grep outline scripts/ci/materialize_base_python_requirements.py --items all --view expanded
printf '\n== Materializer candidate and base-lock implementation ==\n'
rg -n -C 12 \
'def (_is_candidate_lock_name|_is_candidate_lock_path|_is_hash_pinned|base_hash_locks|materialize|_regular|_git|_lock_blob)|manifest' \
scripts/ci/materialize_base_python_requirements.py
printf '\n== Materializer full source, bounded ==\n'
cat -n scripts/ci/materialize_base_python_requirements.py
printf '\n== New requirements-directory regression test ==\n'
cat -n tests/test_requirements_directory_lock_materialization.py
printf '\n== Existing Python materializer boundary tests: relevant regions ==\n'
rg -n -C 10 \
'(regular|symlink|traversal|nested|PR-modified|hash.pinned|manifest|base_hash_locks|require-hashes)' \
tests/test_materialize_base_python_requirements.py
printf '\n== Install closure preflight implementation and tests ==\n'
fd -t f 'install_base_python_locks.py|test_install_base_python_locks.py' . -x sh -c '
echo "--- $1"
cat -n "$1"
' sh {} \;
printf '\n== Exact-head workflow files changed by this diff, if any ==\n'
git diff --name-only "$base" "$head" -- .github/workflows |
while IFS= read -r file; do
[ -n "$file" ] && { echo "--- $file"; cat -n "$file"; }
done
printf '\n== Workflow writers introduced by the exact diff ==\n'
git diff --no-ext-diff "$base" "$head" -- .github |
rg -n -i -C 3 '(contents:\s*write|git\s+push|force-with-lease|gh\s+(api|pr|workflow)|workflow_dispatch)' || true
printf '\n== Current PR check summary, grouped ==\n'
gh pr checks 785 --repo ContextualWisdomLab/.github || trueLength of output: 127039 🏁 Script executed: #!/bin/bash
set -euo pipefail
repo='ContextualWisdomLab/.github'
head='ed33253e5d6f93f2e71d80b24e27b301f96efb88'
printf '\n== Exact-head materializer and installer calls in coverage workflows ==\n'
rg -n -C 8 --glob '*.yml' --glob '*.yaml' \
'(materialize_base_python_requirements\.py|install_base_python_locks\.py|base-python-requirements|--base-sha|--requirements-root)' \
.github/workflows
printf '\n== Candidate-status hash-pin regression coverage ==\n'
rg -n -C 8 --glob 'test*.py' \
'(--require-hashes.*(unpinned|>=)|_is_hash_pinned|requirements/ci\.txt|requirements/nested|symlink|PR-modified)' \
tests
printf '\n== Exact quality workflow runs and their logs ==\n'
gh run list --repo "$repo" --commit "$head" --workflow 'Trusted uv Materializer Quality CI' \
--limit 10 --json databaseId,headSha,status,conclusion,createdAt,updatedAt,url \
|| true
for run_id in $(gh run list --repo "$repo" --commit "$head" --workflow 'Trusted uv Materializer Quality CI' \
--limit 10 --json databaseId --jq '.[].databaseId' 2>/dev/null); do
echo "--- quality run $run_id"
gh run view "$run_id" --repo "$repo" --log 2>&1 | rg -n -C 4 \
'(passed|failed|FAIL|TOTAL|100%|coverage|interrogate|docstring|Python 3\.10|Python 3\.14)' \
|| true
done
printf '\n== Current Strix and failed-status details ==\n'
gh pr checks 785 --repo "$repo" --json name,state,link,bucket \
| jq -r '.[] | select(.name == "strix" or .name == "publish-manual-pr-evidence-status")' \
|| true
printf '\n== Branch protection / rulesets for main ==\n'
gh api "repos/${repo}/branches/main/protection" 2>&1 | jq '{required_status_checks,required_pull_request_reviews,enforce_admins,required_linear_history,allow_force_pushes,allow_deletions}' \
|| true
gh api "repos/${repo}/rulesets" 2>&1 | jq '.[] | {name,enforcement,target,conditions,rules}' \
|| trueLength of output: 207047
I reviewed Finding — P1: Do not materialize an unpinned direct-child lockIn
The existing test at Therefore, a base-owned This violates the stated boundary that only complete hash-pinned locks gain candidate status. It also conflicts with the new doctoring document, which says that candidate content must be hash-pinned. Update candidate validation so an unpinned direct-child Verified controls
You are interacting with an AI system. |
|
@opencode-agent @cwl-noema-review @coderabbitai review Review-only request for exact current head |
|
Tip For best results, initiate chat on the files or code changes. 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
base='f070c504c1cb06891b800d7ab0cf6ac7d3cf8eae'
head='ed33253e5d6f93f2e71d80b24e27b301f96efb88'
repo='ContextualWisdomLab/.github'
printf '%s\n' '== Exact commits =='
git cat-file -e "${base}^{commit}"
git cat-file -e "${head}^{commit}"
git show -s --format='base %H%n%cs %s' "$base"
git show -s --format='head %H%n%cs %s' "$head"
printf '%s\n' '== Exact changed files =='
git diff --name-status --find-renames "$base" "$head"
git diff --stat "$base" "$head"
printf '%s\n' '== Exact diff =='
git diff --no-ext-diff --find-renames --unified=60 "$base" "$head"
printf '%s\n' '== Changed Python file outlines =='
git diff --name-only "$base" "$head" -- '*.py' |
while IFS= read -r file; do
test -n "$file" || continue
printf '\n--- %s ---\n' "$file"
ast-grep outline "$file" --items all --view expanded || true
done
printf '%s\n' '== Materializer candidate, content-validation, tree, and manifest regions =='
rg -n -C 12 --glob 'materialize_base_python_requirements.py' \
'def (_is_candidate_lock_name|_is_candidate_lock_path|_is_hash_pinned|_.*regular.*|_.*tree.*|materialize)|require-hashes|hash|manifest|ls-tree|cat-file|symlink|traversal' .
printf '%s\n' '== Installer preflight regions =='
rg -n -C 10 --glob 'install_base_python_locks.py' \
'require-hashes|preflight|manifest|pip|closure|defer|skip|install' .
printf '%s\n' '== Relevant regression-test regions =='
rg -n -C 10 --glob 'test*.py' \
'requirements/ci\.txt|requirements/nested|require-hashes|unpinned|hash-pinned|symlink|traversal|PR-only|manifest|base_hash_locks' tests
printf '%s\n' '== Workflow inventory and exact-diff write capability scan =='
fd -t f -e yml -e yaml .github 2>/dev/null || true
git diff --no-ext-diff "$base" "$head" -- .github |
rg -n -i -C 3 'contents:\s*write|pull-requests:\s*write|git\s+push|force-with-lease|workflow_dispatch|actions/github-script' || true
printf '%s\n' '== Current PR and check metadata =='
gh pr view 785 --repo "$repo" \
--json state,isDraft,headRefOid,baseRefOid,mergeStateStatus,reviewDecision,statusCheckRollup,reviews
gh pr checks 785 --repo "$repo" || trueLength of output: 202643
I reviewed P1 — Reject incomplete direct-child locks before materialization
This file has no hash for The new direct-child rule accepts The later independent Update the candidate validation to require a hash for every requirement before materialization. Add a regression test for Verified controls
The PR is still blocked and requires review according to current GitHub metadata. I cannot approve while the incomplete-lock candidate path remains. You are interacting with an AI system. |
|
@jules Replace the current self-removing repair workflow with ordinary reviewed source commits on this branch. The product diff must contain only the permanent requirements-directory lock discovery, coverage/workflow contract, tests, doctoring, and CHANGELOG changes; no temporary writer, force-with-lease publisher, self-delete mechanism, or expected-RED artifact may remain. Implement the narrow direct-child rule for regular base-owned |
|
@coderabbitai review Review exact current head |
|
Tip For best results, initiate chat on the files or code changes. 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
base='f070c504c1cb06891b800d7ab0cf6ac7d3cf8eae'
head='ed33253e5d6f93f2e71d80b24e27b301f96efb88'
repo='ContextualWisdomLab/.github'
printf '\n== Exact commits ==\n'
git cat-file -e "${base}^{commit}"
git cat-file -e "${head}^{commit}"
git show -s --format='base=%H%n%s%n%cs' "$base"
git show -s --format='head=%H%n%s%n%cs' "$head"
printf '\n== Changed files ==\n'
git diff --name-status --find-renames "$base" "$head"
git diff --stat "$base" "$head"
printf '\n== Exact diff ==\n'
git diff --no-ext-diff --find-renames --unified=50 "$base" "$head"
printf '\n== Materializer outline ==\n'
materializer="$(fd -t f '^materialize_base_python_requirements\.py$' . | head -n1)"
test -n "$materializer"
ast-grep outline "$materializer" --items all --view expanded
printf '\n== Materializer validation, tree, and manifest code ==\n'
rg -n -C 14 \
'def (_is_candidate_lock_name|_is_candidate_lock_path|_is_hash_pinned|_.*tree.*|_.*regular.*|materialize)|--require-hashes|--hash|manifest|ls-tree|cat-file|symlink|traversal|base_hash_locks' \
"$materializer"
printf '\n== Installer preflight code ==\n'
fd -t f '^install_base_python_locks\.py$' . -x sh -c '
ast-grep outline "$1" --items all --view expanded
rg -n -C 12 "require-hashes|preflight|manifest|pip|closure|skip|defer|install" "$1"
' sh {}
printf '\n== Relevant test code ==\n'
fd -t f -e py . tests -x sh -c '
if rg -q "requirements/ci\.txt|requirements/nested|_is_hash_pinned|--require-hashes|base_hash_locks|symlink|PR-only|manifest" "$1"; then
echo "--- $1"
rg -n -C 10 "requirements/ci\.txt|requirements/nested|_is_hash_pinned|--require-hashes|base_hash_locks|symlink|PR-only|manifest" "$1"
fi
' sh {}
printf '\n== Workflow files changed by exact diff ==\n'
git diff --name-only "$base" "$head" -- .github/workflows |
while IFS= read -r file; do
test -n "$file" || continue
echo "--- $file"
git show "${head}:${file}" | nl -ba
done
printf '\n== Write-capability scan in exact workflow diff ==\n'
git diff --no-ext-diff "$base" "$head" -- .github |
rg -n -i -C 3 'contents:\s*write|pull-requests:\s*write|git\s+push|force-with-lease|workflow_dispatch|actions/github-script' || true
printf '\n== Current PR metadata and checks ==\n'
gh pr view 785 --repo "$repo" \
--json state,isDraft,headRefOid,baseRefOid,mergeStateStatus,reviewDecision,statusCheckRollup,reviews
gh pr checks 785 --repo "$repo" || true
printf '\n== Current unresolved review threads ==\n'
gh api graphql -F owner='ContextualWisdomLab' -F name='.github' -F number=785 -f query='
query($owner: String!, $name: String!, $number: Int!) {
repository(owner: $owner, name: $name) {
pullRequest(number: $number) {
reviewThreads(first: 100) { nodes { isResolved } }
}
}
}' | jq '[.data.repository.pullRequest.reviewThreads.nodes[] | select(.isResolved == false)] | length'Length of output: 130146 🏁 Script executed: #!/bin/bash
set -euo pipefail
base='f070c504c1cb06891b800d7ab0cf6ac7d3cf8eae'
head='ed33253e5d6f93f2e71d80b24e27b301f96efb88'
repo='ContextualWisdomLab/.github'
printf '\n== Exact changed workflow at requested head ==\n'
git show "${head}:.github/workflows/trusted-uv-materializer-quality-ci.yml" | sed -n '1,240p'
printf '\n== Write-capability tokens in the exact workflow diff ==\n'
git diff --no-ext-diff "$base" "$head" -- .github/workflows |
rg -n -i -C 3 'contents:\s*write|pull-requests:\s*write|issues:\s*write|id-token:\s*write|git\s+push|force-with-lease|workflow_dispatch|actions/github-script' || true
printf '\n== PR exact-head metadata and check rollup ==\n'
gh pr view 785 --repo "$repo" \
--json state,isDraft,headRefOid,baseRefOid,mergeStateStatus,reviewDecision,statusCheckRollup,reviews
printf '\n== Current check summary ==\n'
gh pr checks 785 --repo "$repo" || true
printf '\n== Current unresolved review-thread count ==\n'
gh api graphql -F owner='ContextualWisdomLab' -F name='.github' -F number=785 -f query='
query($owner: String!, $name: String!, $number: Int!) {
repository(owner: $owner, name: $name) {
pullRequest(number: $number) {
reviewThreads(first: 100) { nodes { isResolved } }
}
}
}' | jq '[.data.repository.pullRequest.reviewThreads.nodes[] | select(.isResolved == false)] | length'
printf '\n== Requested head workflow runs ==\n'
gh run list --repo "$repo" --commit "$head" --limit 100 \
--json name,headSha,status,conclusion,url \
--jq '.[] | select(.headSha == "'"$head"'") | [.name,.status,.conclusion,.url] | `@tsv`' \
|| trueLength of output: 45429
I reviewed P1 — Reject incomplete direct-child locks before materializationIn The existing test in
The later This behavior conflicts with the stated boundary that a candidate must be completely hash-pinned before materialization. Update the candidate-content validation so every requirement has a valid hash before the materializer emits the manifest entry. Add a regression test for Verified controls
The PR remains You are interacting with an AI system. |
|
@opencode-agent review Review exact head |
|
@opencode-agent review Re-evaluate exact current head |
Dismissed as source-stale predecessor evidence. It reviewed b3f5f7e87b57d9b5b76e3c628fe5d21be84d269f; exact current head is dcc539176271658f024de7419044f513c6fb7317, GitHub reports it mergeable, all ten current-head workflows are terminal-success, and no unresolved thread remains. This dismissal is not approval, qualifying human review, base freshness, merge authority, or protected-main acceptance.
|
@opencode-agent review Perform a fresh read-only semantic review of exact current head |
|
Exact-current-head review request for Review the bounded six-file requirements-directory lock repair: only direct-child Keep the exact head unchanged. Do not transfer predecessor review evidence, synthesize author approval, broaden candidate trust, skip closure validation, update the branch, merge, release, or bypass protection. @coderabbitai review |
|
Tip For best results, initiate chat on the files or code changes. 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
repo='ContextualWisdomLab/.github'
pr='785'
expected_head='edbe8d35b16c6f0a7041fefc476513e160cadb10'
expected_base='6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba'
printf '%s\n' '== Live PR identity, reviews, and checks =='
pr_json="$(gh pr view "$pr" --repo "$repo" \
--json number,state,isDraft,headRefOid,baseRefOid,mergeStateStatus,reviewDecision,statusCheckRollup,reviews)"
printf '%s\n' "$pr_json" | jq '{
number, state, isDraft, headRefOid, baseRefOid, mergeStateStatus, reviewDecision,
checks: [.statusCheckRollup[] | {name, status, conclusion, workflowName}],
reviews: [.reviews[] | {author: .author.login, state, commit: .commit.oid}]
}'
head="$(printf '%s\n' "$pr_json" | jq -r '.headRefOid')"
base="$(printf '%s\n' "$pr_json" | jq -r '.baseRefOid')"
test "$head" = "$expected_head"
test "$base" = "$expected_base"
printf '%s\n' '== Commit identity and exact changed scope =='
git cat-file -e "${base}^{commit}"
git cat-file -e "${head}^{commit}"
git merge-base --is-ancestor "$base" "$head"
git show -s --format='base=%H%nbase_subject=%s%nhead=%H%nhead_subject=%s%nhead_parents=%P' "$base" "$head"
git diff --name-status --find-renames "$base" "$head"
git diff --stat "$base" "$head"
git diff --check "$base" "$head"
printf '%s\n' '== Exact product diff =='
git diff --no-ext-diff --find-renames --unified=35 "$base" "$head" -- \
.github/workflows/trusted-uv-materializer-quality-ci.yml \
CHANGELOG.md \
docs/doctoring/trusted-requirements-directory-lock-discovery.md \
scripts/ci/materialize_base_python_requirements.py \
tests/test_materialize_base_python_requirements.py \
tests/test_requirements_directory_lock_materialization.py
printf '%s\n' '== Materializer source map and boundary regions =='
ast-grep outline scripts/ci/materialize_base_python_requirements.py --items all --view expanded
git show "${head}:scripts/ci/materialize_base_python_requirements.py" | nl -ba |
sed -n '1,300p;400,620p'
printf '%s\n' '== Installer closure-preflight regions =='
git show "${head}:scripts/ci/install_base_python_locks.py" | nl -ba |
rg -n -C 12 -- 'require-hashes|preflight|manifest|pip|closure|skip|defer|install' || true
printf '%s\n' '== Relevant regression evidence =='
for file in \
tests/test_materialize_base_python_requirements.py \
tests/test_requirements_directory_lock_materialization.py; do
printf '%s\n' "--- ${file}"
git show "${head}:${file}" | nl -ba |
rg -n -C 8 -- \
'requirements/ci\.txt|requirements/nested|require-hashes|--hash=|--requirement|-r |manifest|unpinned|invalid|absolute|traversal|symlink|query|fragment|backslash|PR-only|regular blob' || true
done
printf '%s\n' '== Exact-diff workflow writer scan =='
git diff --no-ext-diff "$base" "$head" -- .github |
rg -n -i -C 3 \
'contents:\s*write|pull-requests:\s*write|issues:\s*write|id-token:\s*write|git\s+push|force-with-lease|workflow_dispatch|actions/github-script|encoded' || true
printf '%s\n' '== Active non-outdated review threads =='
gh api graphql -F owner='ContextualWisdomLab' -F name='.github' -F number="$pr" -f query='
query($owner: String!, $name: String!, $number: Int!) {
repository(owner: $owner, name: $name) {
pullRequest(number: $number) {
reviewThreads(first: 100) {
nodes {
isResolved
isOutdated
comments(first: 1) { nodes { author { login } body path line } }
}
}
}
}
}' | jq '[.data.repository.pullRequest.reviewThreads.nodes[] |
select(.isResolved == false and .isOutdated == false)]'
printf '%s\n' '== Protected base rules and required checks =='
gh api "repos/${repo}/branches/main/protection" 2>&1 |
jq '{required_status_checks,required_pull_request_reviews,enforce_admins,required_linear_history,allow_force_pushes,allow_deletions}' || trueLength of output: 58628 🏁 Script executed: #!/bin/bash
set -euo pipefail
repo='ContextualWisdomLab/.github'
pr='785'
head='edbe8d35b16c6f0a7041fefc476513e160cadb10'
base='6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba'
current_head="$(gh pr view "$pr" --repo "$repo" --json headRefOid --jq '.headRefOid')"
test "$current_head" = "$head"
printf '%s\n' '== Include predicate and control-character tests =='
git show "${head}:scripts/ci/materialize_base_python_requirements.py" |
sed -n '118,190p'
git show "${head}:tests/test_requirements_directory_lock_materialization.py" |
sed -n '55,190p'
git show "${head}:tests/test_materialize_base_python_requirements.py" |
rg -n -C 6 -- 'control|NUL|\\x00|include|_is_hash_pinned|manifest|requirements/' || true
printf '%s\n' '== Installer preflight implementation =='
git show "${head}:scripts/ci/install_base_python_locks.py" |
rg -n -C 14 -- 'require-hashes|preflight|manifest|pip|closure|skip|defer|install' || true
printf '%s\n' '== Authentication and materialization implementation =='
git show "${head}:scripts/ci/materialize_base_python_requirements.py" |
sed -n '460,545p'
printf '%s\n' '== Workflow content and introduced writer scan =='
git show "${head}:.github/workflows/trusted-uv-materializer-quality-ci.yml" |
sed -n '1,190p'
git diff --no-ext-diff "$base" "$head" -- .github |
rg -n -i -C 3 \
'contents:\s*write|pull-requests:\s*write|issues:\s*write|id-token:\s*write|git\s+push|force-with-lease|workflow_dispatch|actions/github-script|encoded' || true
printf '%s\n' '== Current check summary and active threads =='
gh pr checks "$pr" --repo "$repo" || true
gh api graphql -F owner='ContextualWisdomLab' -F name='.github' -F number="$pr" -f query='
query($owner: String!, $name: String!, $number: Int!) {
repository(owner: $owner, name: $name) {
pullRequest(number: $number) {
reviewThreads(first: 100) {
nodes {
isResolved
isOutdated
comments(first: 1) { nodes { author { login } body path line } }
}
}
}
}
}' | jq '[.data.repository.pullRequest.reviewThreads.nodes[] |
select(.isResolved == false and .isOutdated == false)]'
printf '%s\n' '== Branch protection and live PR state =='
gh api "repos/${repo}/branches/main/protection" |
jq '{required_status_checks,required_pull_request_reviews,enforce_admins,required_linear_history,allow_force_pushes,allow_deletions}' || true
gh pr view "$pr" --repo "$repo" \
--json headRefOid,baseRefOid,mergeStateStatus,reviewDecision,isDraft,reviews |
jq .Length of output: 50734
I reviewed P1 — Reject NUL and control characters in requirement include targetsIn For example, this direct-child candidate is accepted: The line has two fields. Its target is not absolute. It contains no The later Reject NUL and all control characters in the include target. Add predicate and manifest-exclusion regressions for at least Verified controls
🧠 Learnings usedYou are interacting with an AI system. |
Record that a global --require-hashes directive is not integrity evidence and cannot authorize download of unpinned code. Force the trusted-uv installer tests onto the linux x86_64 runner path and add the control-plane architecture diagram.
Bounded -r/--requirement includes may only name requirements*.txt, requirements.lock, or a direct .txt child of requirements/. A notes file next to a lock cannot enter the trusted image.
|
@cwl-noema-review Please review this exact current head ( |
A current-directory prefix or doubled slash still named a candidate requirements lock after path-kind checks. Include targets must now equal their normalized relative POSIX form so ./ and // cannot enter the image.
|
Exact-current-head read-only review request for All ten directly observed exact-head workflows are terminal-success: Trusted uv Materializer Quality CI, Strix Changed Path Quality CI, CodeQL PR, Python Security, Security Scan, SAST Semgrep, Secret Scan, OSV-Scanner PR, Scorecard PR, and SBOM Generation. Prior conflict and fail-open findings are predecessor-head evidence; current GitHub metadata reports mergeable. Submit a current-head verdict only. Do not mutate the branch, self-approve, weaken protection, or merge. @coderabbitai review |
|
Tip For best results, initiate chat on the files or code changes. 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
repo='ContextualWisdomLab/.github'
pr='785'
head='a212e3e2943b8d9bfef8bf90ac91b17d10cd3f67'
base='6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba'
printf '%s\n' '== Live PR identity, review decision, and checks =='
pr_json="$(gh pr view "$pr" --repo "$repo" \
--json number,state,isDraft,headRefOid,baseRefOid,mergeStateStatus,reviewDecision,statusCheckRollup,reviews)"
printf '%s\n' "$pr_json" | jq '{
number, state, isDraft, headRefOid, baseRefOid, mergeStateStatus, reviewDecision,
checks: [.statusCheckRollup[] | {name, status, conclusion, workflowName}],
reviews: [.reviews[] | {author: .author.login, state, commit: .commit.oid}]
}'
live_head="$(printf '%s\n' "$pr_json" | jq -r '.headRefOid')"
live_base="$(printf '%s\n' "$pr_json" | jq -r '.baseRefOid')"
test "$live_head" = "$head"
test "$live_base" = "$base"
printf '%s\n' '== Commit relationship and changed paths =='
git cat-file -e "${base}^{commit}"
git cat-file -e "${head}^{commit}"
git merge-base --is-ancestor "$base" "$head"
git show -s --format='base=%H%nbase_subject=%s%nhead=%H%nhead_subject=%s%nhead_parents=%P' "$base" "$head"
git diff --name-status --find-renames "$base" "$head"
git diff --stat "$base" "$head"
git diff --check "$base" "$head"
printf '%s\n' '== Exact product diff =='
git diff --no-ext-diff --find-renames --unified=40 "$base" "$head" -- \
.github/workflows/trusted-uv-materializer-quality-ci.yml \
CHANGELOG.md \
docs/doctoring/trusted-requirements-directory-lock-discovery.md \
scripts/ci/materialize_base_python_requirements.py \
scripts/ci/install_base_python_locks.py \
tests/test_materialize_base_python_requirements.py \
tests/test_requirements_directory_lock_materialization.py
printf '%s\n' '== Materializer structure and trust-boundary implementation =='
git show "${head}:scripts/ci/materialize_base_python_requirements.py" > /tmp/materializer.py
ast-grep outline /tmp/materializer.py --items all --view expanded
nl -ba /tmp/materializer.py | sed -n '1,330p;400,640p'
printf '%s\n' '== Installer closure preflight =='
git show "${head}:scripts/ci/install_base_python_locks.py" | nl -ba |
rg -n -C 14 -- 'require-hashes|preflight|manifest|pip|closure|skip|defer|install' || true
printf '%s\n' '== Current-head regression tests =='
for file in \
tests/test_materialize_base_python_requirements.py \
tests/test_requirements_directory_lock_materialization.py; do
printf '%s\n' "--- ${file}"
git show "${head}:${file}" | nl -ba |
rg -n -C 8 -- \
'requirements/ci\.txt|requirements/nested|require-hashes|--hash=|--requirement|-r |manifest|unpinned|invalid|absolute|traversal|symlink|query|fragment|backslash|control|NUL|PR-only|regular blob' || true
done
printf '%s\n' '== Exact-diff workflow writer scan =='
git diff --no-ext-diff "$base" "$head" -- .github |
rg -n -i -C 3 \
'contents:\s*write|pull-requests:\s*write|issues:\s*write|id-token:\s*write|git\s+push|force-with-lease|workflow_dispatch|actions/github-script|encoded' || true
printf '%s\n' '== Active non-outdated review threads =='
gh api graphql -F owner='ContextualWisdomLab' -F name='.github' -F number="$pr" -f query='
query($owner: String!, $name: String!, $number: Int!) {
repository(owner: $owner, name: $name) {
pullRequest(number: $number) {
reviewThreads(first: 100) {
nodes {
isResolved
isOutdated
comments(first: 1) {
nodes { author { login } body path line }
}
}
}
}
}
}' | jq '[.data.repository.pullRequest.reviewThreads.nodes[] |
select(.isResolved == false and .isOutdated == false)]'Length of output: 64251 🏁 Script executed: #!/bin/bash
set -euo pipefail
repo='ContextualWisdomLab/.github'
pr='785'
head='a212e3e2943b8d9bfef8bf90ac91b17d10cd3f67'
base='6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba'
printf '%s\n' '== Include admission implementation and regex definitions =='
git show "${head}:scripts/ci/materialize_base_python_requirements.py" |
cat -n | sed -n '25,205p'
printf '%s\n' '== Authenticated base-tree discovery and manifest implementation =='
git show "${head}:scripts/ci/materialize_base_python_requirements.py" |
cat -n | sed -n '470,570p'
printf '%s\n' '== Exact current-head requirement-directory regression file =='
git show "${head}:tests/test_requirements_directory_lock_materialization.py" |
cat -n
printf '%s\n' '== Related predicate tests in the existing materializer suite =='
git show "${head}:tests/test_materialize_base_python_requirements.py" |
cat -n |
grep -n -E -C 6 \
'(_is_hash_pinned|_is_bounded_requirement_include|control|NUL|\\x00|requirements/|manifest|symlink|traversal)' \
|| true
printf '%s\n' '== Previous two commits: control-character repair evidence =='
git log --format='%H %s' -3 "$head"
for commit in "$head^" "$head^^"; do
printf '%s\n' "--- ${commit}"
git show --no-ext-diff --format= --unified=25 "$commit" -- \
scripts/ci/materialize_base_python_requirements.py \
tests/test_requirements_directory_lock_materialization.py
done
printf '%s\n' '== Installer independent closure-preflight implementation =='
git show "${head}:scripts/ci/install_base_python_locks.py" |
cat -n |
grep -n -E -C 14 'require-hashes|preflight|manifest|pip|closure|skip|defer|install' \
|| true
printf '%s\n' '== Exact workflow diff and write-capability scan =='
git diff --no-ext-diff --unified=25 "$base" "$head" -- \
.github/workflows/trusted-uv-materializer-quality-ci.yml
git diff --no-ext-diff "$base" "$head" -- .github |
grep -n -E -i -C 3 \
'contents:[[:space:]]*write|pull-requests:[[:space:]]*write|issues:[[:space:]]*write|id-token:[[:space:]]*write|git[[:space:]]+push|force-with-lease|workflow_dispatch|actions/github-script|encoded' \
|| true
printf '%s\n' '== Active non-outdated review threads and live identity recheck =='
gh api graphql -F owner='ContextualWisdomLab' -F name='.github' -F number="$pr" -f query='
query($owner: String!, $name: String!, $number: Int!) {
repository(owner: $owner, name: $name) {
pullRequest(number: $number) {
reviewThreads(first: 100) {
nodes {
isResolved
isOutdated
comments(first: 1) {
nodes { author { login } body path line }
}
}
}
}
}
}' | jq '[.data.repository.pullRequest.reviewThreads.nodes[] |
select(.isResolved == false and .isOutdated == false)]'
gh pr view "$pr" --repo "$repo" \
--json headRefOid,baseRefOid,mergeStateStatus,reviewDecision,isDraft |
jq .Length of output: 57382
I reviewed P1 — Reject NUL and control characters in requirement include targetsIn This input is accepted:
As a result, Reject NUL and all control characters in include targets before Verified controls
GitHub currently reports You are interacting with an AI system. |
|
@coderabbitai review Review only exact current head |
|
Tip For best results, initiate chat on the files or code changes. 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
repo='ContextualWisdomLab/.github'
pr='785'
head='a212e3e2943b8d9bfef8bf90ac91b17d10cd3f67'
base='6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba'
printf '%s\n' '== Live identity, check state, and review state =='
gh pr view "$pr" --repo "$repo" \
--json state,isDraft,headRefOid,baseRefOid,mergeStateStatus,reviewDecision,statusCheckRollup,reviews |
jq '{
state, isDraft, headRefOid, baseRefOid, mergeStateStatus, reviewDecision,
checks: [.statusCheckRollup[] | {name, status, conclusion, workflowName}],
reviews: [.reviews[] | {author: .author.login, state, commit: .commit.oid}]
}'
live_head="$(gh pr view "$pr" --repo "$repo" --json headRefOid --jq '.headRefOid')"
test "$live_head" = "$head"
git cat-file -e "${head}^{commit}"
git cat-file -e "${base}^{commit}"
printf '%s\n' '== Exact changed paths and whitespace =='
git diff --name-status --find-renames "$base" "$head"
git diff --check "$base" "$head"
printf '%s\n' '== Materializer candidate and include validation =='
git show "${head}:scripts/ci/materialize_base_python_requirements.py" |
nl -ba | sed -n '25,230p;450,570p'
printf '%s\n' '== Materializer test map and control-character cases =='
for file in \
tests/test_materialize_base_python_requirements.py \
tests/test_requirements_directory_lock_materialization.py; do
printf '%s\n' "--- ${file}"
git show "${head}:${file}" | nl -ba |
rg -n -C 8 -- \
'(_is_hash_pinned|_is_bounded_requirement_include|requirements/ci\.txt|requirements/nested|NUL|control|\\x00|\\x01|manifest|--requirement|-r |--hash=|traversal|symlink)' || true
done
printf '%s\n' '== Installer closure preflight =='
git show "${head}:scripts/ci/install_base_python_locks.py" |
nl -ba | rg -n -C 10 -- 'require-hashes|preflight|manifest|pip|closure|skip|defer' || true
printf '%s\n' '== Exact workflow writer scan =='
git diff --no-ext-diff "$base" "$head" -- .github |
rg -n -i -C 3 \
'contents:\s*write|pull-requests:\s*write|issues:\s*write|id-token:\s*write|git\s+push|force-with-lease|workflow_dispatch|actions/github-script|encoded' || true
printf '%s\n' '== Active non-outdated threads =='
gh api graphql -F owner='ContextualWisdomLab' -F name='.github' -F number="$pr" -f query='
query($owner: String!, $name: String!, $number: Int!) {
repository(owner: $owner, name: $name) {
pullRequest(number: $number) {
reviewThreads(first: 100) {
nodes {
isResolved
isOutdated
comments(first: 1) { nodes { author { login } body path line } }
}
}
}
}
}' | jq '[.data.repository.pullRequest.reviewThreads.nodes[] |
select(.isResolved == false and .isOutdated == false)]'Length of output: 11551 🏁 Script executed: #!/bin/bash
set -euo pipefail
repo='ContextualWisdomLab/.github'
pr='785'
head='a212e3e2943b8d9bfef8bf90ac91b17d10cd3f67'
base='6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba'
current_head="$(gh pr view "$pr" --repo "$repo" --json headRefOid --jq '.headRefOid')"
test "$current_head" = "$head"
number_lines() {
awk '{ printf "%6d\t%s\n", NR, $0 }'
}
printf '%s\n' '== Candidate and include predicates =='
git show "${head}:scripts/ci/materialize_base_python_requirements.py" |
number_lines | sed -n '25,240p'
printf '%s\n' '== Base tree discovery and manifest materialization =='
git show "${head}:scripts/ci/materialize_base_python_requirements.py" |
number_lines | sed -n '440,590p'
printf '%s\n' '== Requirements-directory regression tests =='
git show "${head}:tests/test_requirements_directory_lock_materialization.py" |
number_lines
printf '%s\n' '== Existing materializer tests for predicate and manifest boundaries =='
git show "${head}:tests/test_materialize_base_python_requirements.py" |
number_lines |
rg -n -C 8 -- \
'(_is_hash_pinned|_is_bounded_requirement_include|requirements/ci\.txt|requirements/nested|NUL|control|\\x00|\\x01|manifest|--requirement|-r |--hash=|traversal|symlink)' || true
printf '%s\n' '== Installer closure preflight =='
git show "${head}:scripts/ci/install_base_python_locks.py" |
number_lines |
rg -n -C 10 -- 'require-hashes|preflight|manifest|pip|closure|skip|defer' || true
printf '%s\n' '== Exact workflow writer scan =='
git diff --no-ext-diff "$base" "$head" -- .github |
rg -n -i -C 3 \
'contents:\s*write|pull-requests:\s*write|issues:\s*write|id-token:\s*write|git\s+push|force-with-lease|workflow_dispatch|actions/github-script|encoded' || true
printf '%s\n' '== Active non-outdated threads =='
gh api graphql -F owner='ContextualWisdomLab' -F name='.github' -F number="$pr" -f query='
query($owner: String!, $name: String!, $number: Int!) {
repository(owner: $owner, name: $name) {
pullRequest(number: $number) {
reviewThreads(first: 100) {
nodes {
isResolved
isOutdated
comments(first: 1) { nodes { author { login } body path line } }
}
}
}
}
}' | jq '[.data.repository.pullRequest.reviewThreads.nodes[] |
select(.isResolved == false and .isOutdated == false)]'Length of output: 52193
I reviewed P1 — Reject NUL and control characters in include targets
For example, this line passes the current checks: At Line 141 through Line 147, the predicate rejects option-like prefixes, backslashes, colons, queries, and fragments. It does not reject control characters. At Line 188 through Line 192, The installer preflight does not enforce this pre-materialization boundary. Reject NUL and all Unicode control characters in Verified controls
GitHub still reports You are interacting with an AI system. |
Pull request was converted to draft
There was a problem hiding this comment.
Comment on #785 at 49e0c867a7a16c5ffd320aa018ff6ef0caa0385d.
Path-aware _is_candidate_lock_path discovery is the right collector, but this head still publishes through _is_hash_pinned. That admits a bounded -r / --requirement file, then renames it to requirements-000.txt and drops the include target. Consumer coverage then fails before tests start.
#1020 already collects requirements/ci.txt and service/requirements/package.txt, then applies _is_flat_materializable_lock so only a standalone SHA-256 closure is renamed. Keep #785 closed behind that landing head.
Next action: do not merge this branch. After #1020 reaches protected main, rebase only if a unique workflow or doctoring hunk remains; otherwise close this pull request as superseded.
Sent by Cursor Automation: Fix Issues


Buyer and review problem
Central OpenCode coverage historically discovered conventional
requirements*.txtlocks but ignored complete base-owned locks stored as direct children such asrequirements/ci.txt. The first implementation also exposed a trust-boundary defect: path eligibility could be confused with dependency integrity before an independent closure proof.Bounded implementation
.txtchildren of repository-relativerequirements/directories.==pin with at least one complete SHA-256 hash.--require-hashesdirective as configuration, never integrity evidence.-r/--requirementincludes...,./, doubled slashes, URL/scheme syntax, home expansion, backslashes, query/fragment syntax, option-like operands, extra inline options, version ranges, malformed hashes, and unrelated pip option lines.pip --require-hashesclosure preflight.Exact identity and scope correction
49e0c867a7a16c5ffd320aa018ff6ef0caa0385d;main@6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba;The final protected-base diff is limited to:
.github/workflows/trusted-uv-materializer-quality-ci.ymlscripts/ci/materialize_base_python_requirements.pytests/test_materialize_base_python_requirements.pytests/test_requirements_directory_lock_materialization.pydocs/doctoring/trusted-requirements-directory-lock-discovery.mdCHANGELOG.mdOverlapping
AGENTS.md,CLAUDE.md, and rootARCHITECTURE.mdchanges were removed because PR #896 owns the canonical central documentation graph. The focused doctoring remains the durable design and APA 7 evidence for this bounded implementation.Test-first lineage
RED head
4914e124c339f93bac5da42aeaf649ed893315d4established failures for range pins, malformed hashes, option lines, unsafe include forms, and incorrect manifest admission. Later review-driven tests fixed dotted and doubled-separator include paths. Those predecessor results prove lineage only.Merge gate
The scope correction changed the exact head, so every prior check and review is historical. Keep Draft until the unchanged current head completes the trusted-materializer/full-suite, exact 100% owned statement/branch coverage, public-docstring, security, SAST, dependency/SBOM, and semantic-review cycle with zero valid unresolved findings. Then mark Ready and require qualifying non-author exact-head approvals plus normal protected-main last-push semantics. No self-approval, stale evidence, temporary writer, administrative bypass, or weakened gate is authorized.
After protected integration, rerun affected leaf-repository coverage/review paths; protected-main consumer evidence remains required before operational closure.