Skip to content

fix(coverage): materialize requirements-directory locks - #785

Open
seonghobae wants to merge 35 commits into
mainfrom
fix/coverage-materialize-requirements-directory-locks
Open

fix(coverage): materialize requirements-directory locks#785
seonghobae wants to merge 35 commits into
mainfrom
fix/coverage-materialize-requirements-directory-locks

Conversation

@seonghobae

@seonghobae seonghobae commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Buyer and review problem

Central OpenCode coverage historically discovered conventional requirements*.txt locks but ignored complete base-owned locks stored as direct children such as requirements/ci.txt. The first implementation then exposed a trust-boundary defect: candidate qualification treated the presence of --hash= or a requirement-include prefix as sufficient trust before independent dependency-closure validation.

Exact current identity

  • source head: edbe8d35b16c6f0a7041fefc476513e160cadb10;
  • PR-base snapshot: 6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba;
  • independently resolved live protected base: 6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba;
  • state: Ready since 2026-08-12, GitHub mergeable; the transition started a fresh exact-head hosted and semantic-review cycle;
  • pre-transition current-head workflows: 10 terminal successes; the newly queued/running Ready cycle is not passing evidence;
  • formal current-head approval: none;
  • unresolved review threads: 0.

Detailed test counts previously recorded for dcc539176271658f024de7419044f513c6fb7317 are predecessor-head evidence and do not transfer. The current hosted quality run and security/supply-chain runs are the authoritative evidence for edbe8d35b16c6f0a7041fefc476513e160cadb10.

Accepted trust boundary

A direct child .txt file under a directory named requirements may become a candidate in addition to conventional lock names, but path eligibility never grants dependency trust.

  • source must be a regular blob in the authenticated base commit;
  • candidate paths are relative, traversal-free, and non-symlink Git blobs;
  • every substantive package line is an exact == pin with at least one complete SHA-256 --hash= value;
  • a global --require-hashes directive is not trust evidence;
  • includes are limited to bounded relative two-token -r / --requirement forms;
  • absolute paths, .., URL/scheme syntax, home expansion, backslashes, query/fragment syntax, option-like operands, extra inline options, ranges, malformed hashes, and pip option lines fail before materialization;
  • the trusted source path is retained in the manifest;
  • each candidate still undergoes an independent complete pip --require-hashes closure preflight.

Unpinned inputs, notes, deeper descendants, unrelated files, PR-only content, malformed Git trees, and unsafe includes remain excluded.

Test-first lineage

At RED head 4914e124c339f93bac5da42aeaf649ed893315d4, the permanent quality gate reported 12 intended failures and 77 passes for range pins, malformed hashes, option lines, unsafe includes, and manifest admission. The production repair made those same contracts green without weakening the downstream closure proof.

The current exact head has successful:

  • Trusted uv Materializer Quality CI;
  • Strix Changed Path Quality CI;
  • CodeQL PR and Python Security;
  • Security Scan, SAST Semgrep, and Secret Scan;
  • OSV-Scanner PR, Scorecard PR, and SBOM Generation.

The predecessor OpenCode/CodeRabbit findings about merge conflicts and fail-open candidate admission were dismissed after their source-backed defects were repaired. They are neither current-head approvals nor transferable merge authority.

Downstream activation and merge gate

After protected integration, affected product PRs such as fast-mlsirm#546, #549, #550, and #556 must rerun the central exact-head coverage/review path.

Keep unmerged until the Ready-cycle current-head gates are terminal-success, semantic review has no valid finding, qualifying independent non-author human approval exists, live-base compatibility and branch protection are revalidated, and expected-head merge authority succeeds. Protected-main operational acceptance remains required after integration.

@coderabbitai

coderabbitai Bot commented Aug 5, 2026

Copy link
Copy Markdown

Warning

Review limit reached

@seonghobae, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 37 minutes

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: aecc3fe0-c96f-459a-bb69-fc919b9f6c48

📥 Commits

Reviewing files that changed from the base of the PR and between 6eb06cd and edbe8d3.

📒 Files selected for processing (6)
  • .github/workflows/trusted-uv-materializer-quality-ci.yml
  • CHANGELOG.md
  • docs/doctoring/trusted-requirements-directory-lock-discovery.md
  • scripts/ci/materialize_base_python_requirements.py
  • tests/test_materialize_base_python_requirements.py
  • tests/test_requirements_directory_lock_materialization.py

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@seonghobae seonghobae closed this Aug 5, 2026
@seonghobae seonghobae reopened this Aug 5, 2026
@seonghobae seonghobae closed this Aug 5, 2026
@seonghobae seonghobae reopened this Aug 5, 2026
@seonghobae seonghobae closed this Aug 5, 2026
@seonghobae seonghobae reopened this Aug 5, 2026
Comment thread .github/workflows/reopen-requirements-directory-locks.yml Fixed
Comment thread .github/workflows/repair-requirements-directory-locks.yml Fixed
@seonghobae
seonghobae marked this pull request as ready for review August 6, 2026 04:54
@seonghobae
seonghobae enabled auto-merge (squash) August 6, 2026 04:55

Copy link
Copy Markdown
Contributor Author

@opencode-agent @cwl-noema-review

Perform an independent formal exact-head review of ed33253e5d6f93f2e71d80b24e27b301f96efb88 against protected main f070c504c1cb06891b800d7ab0cf6ac7d3cf8eae. Do not reuse predecessor-head verdicts.

The final diff contains only the permanent five-file product change; all transient repair workflows and transformers are absent. Recompute current-head coverage and public-docstring evidence; verify that only direct .txt children of a directory named requirements gain candidate status, while regular authenticated-base blobs, traversal/path safety, complete hash pinning, independently installable closure preflight, exact source receipts, and rejection of symlinks, PR-only files, nested descendants, .in files, and unpinned notes remain fail-closed. The verified materialization run passed 70 focused tests, 898 complete tests, production statement/branch coverage 100%, and docstrings 100%. Submit a formal exact-head verdict only; a qualifying independent non-author approval and branch protection remain mandatory.

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

@opencode-agent @cwl-noema-review Independently review exact current head ed33253e5d6f93f2e71d80b24e27b301f96efb88 against protected main at f070c504c1cb06891b800d7ab0cf6ac7d3cf8eae.

The exact head is workflow-free and all direct current-head security, supply-chain, and Trusted uv Materializer Quality checks are successful. Verify the narrow direct-child requirements/*.txt candidate rule, authenticated-base regular-blob requirement, traversal/deeper-path/symlink/PR-only rejection, complete hash-locked closure preflight, exact manifest provenance, Python 3.10/3.14 compatibility, 100% production statement/branch/docstring evidence, and removal of every temporary branch writer. Submit actionable findings or an exact-head formal review; independent approval and branch protection remain mandatory.

@coderabbitai

coderabbitai Bot commented Aug 6, 2026

Copy link
Copy Markdown

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

base='f070c504c1cb06891b800d7ab0cf6ac7d3cf8eae'
head='ed33253e5d6f93f2e71d80b24e27b301f96efb88'

printf '\n== Exact commits ==\n'
git cat-file -e "${base}^{commit}"
git cat-file -e "${head}^{commit}"
git show -s --format='base=%H%nbase-subject=%s%nbase-date=%cI' "$base"
git show -s --format='head=%H%nhead-subject=%s%nhead-date=%cI' "$head"

printf '\n== Changed files and stat ==\n'
git diff --name-status "$base" "$head"
git diff --stat "$base" "$head"

printf '\n== Full product diff ==\n'
git diff --find-renames --find-copies --no-ext-diff "$base" "$head"

printf '\n== Candidate source maps for changed Python files ==\n'
git diff --name-only "$base" "$head" -- '*.py' |
while IFS= read -r file; do
  [ -n "$file" ] || continue
  echo "--- $file"
  ast-grep outline "$file" --items all --view compact || true
done

printf '\n== Candidate discovery and provenance references at exact head ==\n'
rg -n -C 4 --glob '*.py' \
  '(requirements|require-hashes|materiali[sz]|manifest|symlink|git\s+cat-file|ls-tree|blob|traversal)' .

printf '\n== Workflow inventory and write-capable workflow references ==\n'
fd -t f -e yml -e yaml .github 2>/dev/null || true
rg -n -i -C 3 --glob '*.yml' --glob '*.yaml' \
  '(contents:\s*write|pull-requests:\s*write|actions/github-script|git\s+push|force-with-lease|workflow_dispatch)' \
  .github 2>/dev/null || true

printf '\n== Relevant tests and documentation references ==\n'
rg -n -C 3 --glob '*test*.py' --glob '*.md' \
  '(requirements/|requirements\*\.txt|require-hashes|materiali[sz]|manifest|symlink|nested|PR-only)' .

printf '\n== PR metadata, checks, and review state ==\n'
gh pr view 785 --repo ContextualWisdomLab/.github \
  --json number,state,isDraft,headRefOid,baseRefOid,mergeStateStatus,reviewDecision,statusCheckRollup,reviews \
  || true

Length of output: 202327


🏁 Script executed:

#!/bin/bash
set -euo pipefail

base='f070c504c1cb06891b800d7ab0cf6ac7d3cf8eae'
head='ed33253e5d6f93f2e71d80b24e27b301f96efb88'

printf '\n== Exact changed files ==\n'
git diff --name-status "$base" "$head"
printf '\n== Exact changed-file diff ==\n'
git diff --no-ext-diff --unified=80 "$base" "$head"

printf '\n== Materializer complete source map ==\n'
ast-grep outline scripts/ci/materialize_base_python_requirements.py --items all --view expanded

printf '\n== Materializer candidate and base-lock implementation ==\n'
rg -n -C 12 \
  'def (_is_candidate_lock_name|_is_candidate_lock_path|_is_hash_pinned|base_hash_locks|materialize|_regular|_git|_lock_blob)|manifest' \
  scripts/ci/materialize_base_python_requirements.py

printf '\n== Materializer full source, bounded ==\n'
cat -n scripts/ci/materialize_base_python_requirements.py

printf '\n== New requirements-directory regression test ==\n'
cat -n tests/test_requirements_directory_lock_materialization.py

printf '\n== Existing Python materializer boundary tests: relevant regions ==\n'
rg -n -C 10 \
  '(regular|symlink|traversal|nested|PR-modified|hash.pinned|manifest|base_hash_locks|require-hashes)' \
  tests/test_materialize_base_python_requirements.py

printf '\n== Install closure preflight implementation and tests ==\n'
fd -t f 'install_base_python_locks.py|test_install_base_python_locks.py' . -x sh -c '
  echo "--- $1"
  cat -n "$1"
' sh {} \;

printf '\n== Exact-head workflow files changed by this diff, if any ==\n'
git diff --name-only "$base" "$head" -- .github/workflows |
while IFS= read -r file; do
  [ -n "$file" ] && { echo "--- $file"; cat -n "$file"; }
done

printf '\n== Workflow writers introduced by the exact diff ==\n'
git diff --no-ext-diff "$base" "$head" -- .github |
rg -n -i -C 3 '(contents:\s*write|git\s+push|force-with-lease|gh\s+(api|pr|workflow)|workflow_dispatch)' || true

printf '\n== Current PR check summary, grouped ==\n'
gh pr checks 785 --repo ContextualWisdomLab/.github || true

Length of output: 127039


🏁 Script executed:

#!/bin/bash
set -euo pipefail

repo='ContextualWisdomLab/.github'
head='ed33253e5d6f93f2e71d80b24e27b301f96efb88'

printf '\n== Exact-head materializer and installer calls in coverage workflows ==\n'
rg -n -C 8 --glob '*.yml' --glob '*.yaml' \
  '(materialize_base_python_requirements\.py|install_base_python_locks\.py|base-python-requirements|--base-sha|--requirements-root)' \
  .github/workflows

printf '\n== Candidate-status hash-pin regression coverage ==\n'
rg -n -C 8 --glob 'test*.py' \
  '(--require-hashes.*(unpinned|>=)|_is_hash_pinned|requirements/ci\.txt|requirements/nested|symlink|PR-modified)' \
  tests

printf '\n== Exact quality workflow runs and their logs ==\n'
gh run list --repo "$repo" --commit "$head" --workflow 'Trusted uv Materializer Quality CI' \
  --limit 10 --json databaseId,headSha,status,conclusion,createdAt,updatedAt,url \
  || true
for run_id in $(gh run list --repo "$repo" --commit "$head" --workflow 'Trusted uv Materializer Quality CI' \
  --limit 10 --json databaseId --jq '.[].databaseId' 2>/dev/null); do
  echo "--- quality run $run_id"
  gh run view "$run_id" --repo "$repo" --log 2>&1 | rg -n -C 4 \
    '(passed|failed|FAIL|TOTAL|100%|coverage|interrogate|docstring|Python 3\.10|Python 3\.14)' \
    || true
done

printf '\n== Current Strix and failed-status details ==\n'
gh pr checks 785 --repo "$repo" --json name,state,link,bucket \
  | jq -r '.[] | select(.name == "strix" or .name == "publish-manual-pr-evidence-status")' \
  || true

printf '\n== Branch protection / rulesets for main ==\n'
gh api "repos/${repo}/branches/main/protection" 2>&1 | jq '{required_status_checks,required_pull_request_reviews,enforce_admins,required_linear_history,allow_force_pushes,allow_deletions}' \
  || true
gh api "repos/${repo}/rulesets" 2>&1 | jq '.[] | {name,enforcement,target,conditions,rules}' \
  || true

Length of output: 207047


@seonghobae Exact-head review verdict: changes requested.

I reviewed ed33253e5d6f93f2e71d80b24e27b301f96efb88 against f070c504c1cb06891b800d7ab0cf6ac7d3cf8eae.

Finding — P1: Do not materialize an unpinned direct-child lock

In scripts/ci/materialize_base_python_requirements.py at Line 100, the new direct-child rule delegates content validation to _is_hash_pinned().

_is_hash_pinned() returns True for this content:

--require-hashes
demo==1

The existing test at tests/test_materialize_base_python_requirements.py Line 153 confirms this behavior. The file has no hashes for demo==1.

Therefore, a base-owned requirements/ci.txt with this content gains candidate status and is written into manifest.json. The later pip --require-hashes preflight detects the incomplete closure, but the installer classifies this failure as deferable and skips the candidate.

This violates the stated boundary that only complete hash-pinned locks gain candidate status. It also conflicts with the new doctoring document, which says that candidate content must be hash-pinned.

Update candidate validation so an unpinned direct-child .txt file is rejected before materialization. Add a regression case for requirements/ci.txt with a global --require-hashes directive and an unpinned requirement. Assert that it is absent from the materialization manifest.

Verified controls

  • The diff contains exactly five permanent product files.
  • The changed quality workflow has contents: read.
  • The exact diff introduces no write-capable repair workflow or branch writer.
  • The direct-child predicate accepts only .txt files whose immediate parent is named requirements.
  • Nested descendants such as requirements/nested/ci.txt remain rejected.
  • Exact-base Git tree parsing admits regular 100* blobs only.
  • The materializer rejects symlinks, non-blob entries, absolute paths, and traversal paths.
  • The materializer reads selected content from the authenticated base SHA.
  • PR-only content cannot enter the base materialization result.
  • The manifest records the exact source path.
  • The coverage image runs the trusted installer with independent pip --require-hashes preflight.
  • The quality workflow checked out the requested exact head.
  • The quality run passed 70 focused tests and 898 complete tests.
  • Focused and complete statement/branch coverage were 100%.
  • The docstring gate reported 100%.
  • Python 3.10 and Python 3.14 checks passed.

strix was still in progress during verification. The branch-protection API response was inconclusive. These merge-gate items remain unverified.

You are interacting with an AI system.

Copy link
Copy Markdown
Contributor Author

@opencode-agent @cwl-noema-review @coderabbitai review

Review-only request for exact current head ed33253e5d6f93f2e71d80b24e27b301f96efb88 against protected main f070c504c1cb06891b800d7ab0cf6ac7d3cf8eae. Trusted uv Materializer Quality CI and every exact-head security/supply-chain workflow are successful; the final diff is workflow-free, all prior token-permission threads are resolved/outdated, and unresolved threads are zero. Validate direct-child requirements/*.txt discovery, authenticated-base regular-file and hash-pin boundaries, independent pip --require-hashes closure preflight, manifest provenance, 100% statement/branch/docstring evidence, and absence of transient writer machinery. Do not mutate the branch or merge; submit actionable findings or a formal exact-head review.

@coderabbitai

coderabbitai Bot commented Aug 6, 2026

Copy link
Copy Markdown

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

base='f070c504c1cb06891b800d7ab0cf6ac7d3cf8eae'
head='ed33253e5d6f93f2e71d80b24e27b301f96efb88'
repo='ContextualWisdomLab/.github'

printf '%s\n' '== Exact commits =='
git cat-file -e "${base}^{commit}"
git cat-file -e "${head}^{commit}"
git show -s --format='base %H%n%cs %s' "$base"
git show -s --format='head %H%n%cs %s' "$head"

printf '%s\n' '== Exact changed files =='
git diff --name-status --find-renames "$base" "$head"
git diff --stat "$base" "$head"

printf '%s\n' '== Exact diff =='
git diff --no-ext-diff --find-renames --unified=60 "$base" "$head"

printf '%s\n' '== Changed Python file outlines =='
git diff --name-only "$base" "$head" -- '*.py' |
while IFS= read -r file; do
  test -n "$file" || continue
  printf '\n--- %s ---\n' "$file"
  ast-grep outline "$file" --items all --view expanded || true
done

printf '%s\n' '== Materializer candidate, content-validation, tree, and manifest regions =='
rg -n -C 12 --glob 'materialize_base_python_requirements.py' \
  'def (_is_candidate_lock_name|_is_candidate_lock_path|_is_hash_pinned|_.*regular.*|_.*tree.*|materialize)|require-hashes|hash|manifest|ls-tree|cat-file|symlink|traversal' .

printf '%s\n' '== Installer preflight regions =='
rg -n -C 10 --glob 'install_base_python_locks.py' \
  'require-hashes|preflight|manifest|pip|closure|defer|skip|install' .

printf '%s\n' '== Relevant regression-test regions =='
rg -n -C 10 --glob 'test*.py' \
  'requirements/ci\.txt|requirements/nested|require-hashes|unpinned|hash-pinned|symlink|traversal|PR-only|manifest|base_hash_locks' tests

printf '%s\n' '== Workflow inventory and exact-diff write capability scan =='
fd -t f -e yml -e yaml .github 2>/dev/null || true
git diff --no-ext-diff "$base" "$head" -- .github |
  rg -n -i -C 3 'contents:\s*write|pull-requests:\s*write|git\s+push|force-with-lease|workflow_dispatch|actions/github-script' || true

printf '%s\n' '== Current PR and check metadata =='
gh pr view 785 --repo "$repo" \
  --json state,isDraft,headRefOid,baseRefOid,mergeStateStatus,reviewDecision,statusCheckRollup,reviews
gh pr checks 785 --repo "$repo" || true

Length of output: 202643


@seonghobae Exact-head review verdict: changes requested.

I reviewed ed33253e5d6f93f2e71d80b24e27b301f96efb88 against f070c504c1cb06891b800d7ab0cf6ac7d3cf8eae.

P1 — Reject incomplete direct-child locks before materialization

tests/test_materialize_base_python_requirements.py Line 153 proves that _is_hash_pinned() accepts this content:

--require-hashes
demo==1

This file has no hash for demo==1.

The new direct-child rule accepts requirements/ci.txt. The materializer uses _is_hash_pinned() to grant candidate status. Therefore, a base-owned requirements/ci.txt with the content above can enter manifest.json.

The later independent pip --require-hashes preflight detects the missing hash. That preflight is necessary, but it occurs after candidate selection. It does not satisfy the required boundary that candidate status requires a complete hash-pinned lock.

Update the candidate validation to require a hash for every requirement before materialization. Add a regression test for requirements/ci.txt containing a global --require-hashes directive and an unhashed requirement. Assert that the file is absent from the materialization manifest.

Verified controls

  • The direct-child rule accepts requirements/ci.txt.
  • The direct-child rule rejects requirements/nested/ci.txt.
  • The materializer uses authenticated-base Git content.
  • The materializer has regular-file, path-safety, and symlink rejection controls.
  • The installer has an independent pip --require-hashes preflight.
  • The exact-head quality checks report successful Python 3.10 compatibility and Python 3.14 quality gates.
  • The current security and supply-chain check runs report success.
  • The current OpenCode coverage evidence reports success.

The PR is still blocked and requires review according to current GitHub metadata. I cannot approve while the incomplete-lock candidate path remains.

You are interacting with an AI system.

Copy link
Copy Markdown
Contributor Author

@jules Replace the current self-removing repair workflow with ordinary reviewed source commits on this branch. The product diff must contain only the permanent requirements-directory lock discovery, coverage/workflow contract, tests, doctoring, and CHANGELOG changes; no temporary writer, force-with-lease publisher, self-delete mechanism, or expected-RED artifact may remain.

Implement the narrow direct-child rule for regular base-owned requirements/*.txt locks while preserving traversal, symlink, malformed tree, unpinned input, and full pip --require-hashes closure failures. Add exact tests proving requirements/ci.txt is discovered for fast-mlsirm, deeper/unrelated files are excluded, and the workflow installs the authenticated base-owned lock in the isolated sandbox. Keep Draft until the branch is workflow-free and exact-head quality, coverage, docstrings, security, OpenCode/Noema/CodeRabbit, and independent approval gates pass.

Copy link
Copy Markdown
Contributor Author

@coderabbitai review
@opencode-agent review
@cwl-noema-review review
@strix review

Review exact current head ed33253e5d6f93f2e71d80b24e27b301f96efb88. The branch is workflow-free and contains only the permanent direct-child requirements/*.txt materializer rule, focused tests, trusted quality-workflow coverage, doctoring, and CHANGELOG. Trusted uv Quality, Python Security, Security Scan, CodeQL, Semgrep, Secret Scan, OSV, Scorecard, and SBOM are successful on this head; unresolved current-head threads are zero. Review only—do not update, self-approve, bypass protections, or merge.

@coderabbitai

coderabbitai Bot commented Aug 6, 2026

Copy link
Copy Markdown

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

base='f070c504c1cb06891b800d7ab0cf6ac7d3cf8eae'
head='ed33253e5d6f93f2e71d80b24e27b301f96efb88'
repo='ContextualWisdomLab/.github'

printf '\n== Exact commits ==\n'
git cat-file -e "${base}^{commit}"
git cat-file -e "${head}^{commit}"
git show -s --format='base=%H%n%s%n%cs' "$base"
git show -s --format='head=%H%n%s%n%cs' "$head"

printf '\n== Changed files ==\n'
git diff --name-status --find-renames "$base" "$head"
git diff --stat "$base" "$head"

printf '\n== Exact diff ==\n'
git diff --no-ext-diff --find-renames --unified=50 "$base" "$head"

printf '\n== Materializer outline ==\n'
materializer="$(fd -t f '^materialize_base_python_requirements\.py$' . | head -n1)"
test -n "$materializer"
ast-grep outline "$materializer" --items all --view expanded

printf '\n== Materializer validation, tree, and manifest code ==\n'
rg -n -C 14 \
  'def (_is_candidate_lock_name|_is_candidate_lock_path|_is_hash_pinned|_.*tree.*|_.*regular.*|materialize)|--require-hashes|--hash|manifest|ls-tree|cat-file|symlink|traversal|base_hash_locks' \
  "$materializer"

printf '\n== Installer preflight code ==\n'
fd -t f '^install_base_python_locks\.py$' . -x sh -c '
  ast-grep outline "$1" --items all --view expanded
  rg -n -C 12 "require-hashes|preflight|manifest|pip|closure|skip|defer|install" "$1"
' sh {}

printf '\n== Relevant test code ==\n'
fd -t f -e py . tests -x sh -c '
  if rg -q "requirements/ci\.txt|requirements/nested|_is_hash_pinned|--require-hashes|base_hash_locks|symlink|PR-only|manifest" "$1"; then
    echo "--- $1"
    rg -n -C 10 "requirements/ci\.txt|requirements/nested|_is_hash_pinned|--require-hashes|base_hash_locks|symlink|PR-only|manifest" "$1"
  fi
' sh {}

printf '\n== Workflow files changed by exact diff ==\n'
git diff --name-only "$base" "$head" -- .github/workflows |
while IFS= read -r file; do
  test -n "$file" || continue
  echo "--- $file"
  git show "${head}:${file}" | nl -ba
done

printf '\n== Write-capability scan in exact workflow diff ==\n'
git diff --no-ext-diff "$base" "$head" -- .github |
  rg -n -i -C 3 'contents:\s*write|pull-requests:\s*write|git\s+push|force-with-lease|workflow_dispatch|actions/github-script' || true

printf '\n== Current PR metadata and checks ==\n'
gh pr view 785 --repo "$repo" \
  --json state,isDraft,headRefOid,baseRefOid,mergeStateStatus,reviewDecision,statusCheckRollup,reviews
gh pr checks 785 --repo "$repo" || true

printf '\n== Current unresolved review threads ==\n'
gh api graphql -F owner='ContextualWisdomLab' -F name='.github' -F number=785 -f query='
query($owner: String!, $name: String!, $number: Int!) {
  repository(owner: $owner, name: $name) {
    pullRequest(number: $number) {
      reviewThreads(first: 100) { nodes { isResolved } }
    }
  }
}' | jq '[.data.repository.pullRequest.reviewThreads.nodes[] | select(.isResolved == false)] | length'

Length of output: 130146


🏁 Script executed:

#!/bin/bash
set -euo pipefail

base='f070c504c1cb06891b800d7ab0cf6ac7d3cf8eae'
head='ed33253e5d6f93f2e71d80b24e27b301f96efb88'
repo='ContextualWisdomLab/.github'

printf '\n== Exact changed workflow at requested head ==\n'
git show "${head}:.github/workflows/trusted-uv-materializer-quality-ci.yml" | sed -n '1,240p'

printf '\n== Write-capability tokens in the exact workflow diff ==\n'
git diff --no-ext-diff "$base" "$head" -- .github/workflows |
  rg -n -i -C 3 'contents:\s*write|pull-requests:\s*write|issues:\s*write|id-token:\s*write|git\s+push|force-with-lease|workflow_dispatch|actions/github-script' || true

printf '\n== PR exact-head metadata and check rollup ==\n'
gh pr view 785 --repo "$repo" \
  --json state,isDraft,headRefOid,baseRefOid,mergeStateStatus,reviewDecision,statusCheckRollup,reviews

printf '\n== Current check summary ==\n'
gh pr checks 785 --repo "$repo" || true

printf '\n== Current unresolved review-thread count ==\n'
gh api graphql -F owner='ContextualWisdomLab' -F name='.github' -F number=785 -f query='
query($owner: String!, $name: String!, $number: Int!) {
  repository(owner: $owner, name: $name) {
    pullRequest(number: $number) {
      reviewThreads(first: 100) { nodes { isResolved } }
    }
  }
}' | jq '[.data.repository.pullRequest.reviewThreads.nodes[] | select(.isResolved == false)] | length'

printf '\n== Requested head workflow runs ==\n'
gh run list --repo "$repo" --commit "$head" --limit 100 \
  --json name,headSha,status,conclusion,url \
  --jq '.[] | select(.headSha == "'"$head"'") | [.name,.status,.conclusion,.url] | `@tsv`' \
  || true

Length of output: 45429


@seonghobae Exact-head review verdict: changes requested.

I reviewed ed33253e5d6f93f2e71d80b24e27b301f96efb88 against f070c504c1cb06891b800d7ab0cf6ac7d3cf8eae.

P1 — Reject incomplete direct-child locks before materialization

In scripts/ci/materialize_base_python_requirements.py at Line 139, _is_hash_pinned() returns True when any line is exactly --require-hashes.

The existing test in tests/test_materialize_base_python_requirements.py at Line 153 confirms that this content is accepted:

--require-hashes
demo==1

demo==1 has no hash. A direct-child path such as requirements/ci.txt passes the new path rule. The materializer then writes this file into manifest.json.

The later pip --require-hashes preflight detects the missing hash. However, scripts/ci/install_base_python_locks.py classifies this failure as deferable and skips an unrecovered candidate. The coverage image can therefore continue without the intended dependency closure.

This behavior conflicts with the stated boundary that a candidate must be completely hash-pinned before materialization.

Update the candidate-content validation so every requirement has a valid hash before the materializer emits the manifest entry. Add a regression test for requirements/ci.txt containing --require-hashes and an unhashed requirement. Assert that the file is absent from the materialization result and manifest.json.

Verified controls

  • The diff contains five permanent product files.
  • The direct-child rule accepts requirements/ci.txt and services/.../requirements/package.txt.
  • The direct-child rule rejects requirements/nested/ci.txt and docs/ci.txt.
  • The materializer reads regular blobs from the authenticated base commit.
  • The tree parser rejects non-blob entries, non-regular modes, absolute paths, and traversal paths.
  • The materializer records exact source paths in the manifest.
  • The changed quality workflow has contents: read.
  • The exact workflow diff introduces no write-capability token or branch-writing command.
  • The requested-head quality, OpenCode, Noema, security, and supply-chain checks are successful.
  • The current unresolved-thread count is zero.

The PR remains BLOCKED with REVIEW_REQUIRED. I cannot approve until the incomplete-lock materialization path is fixed.

You are interacting with an AI system.

Copy link
Copy Markdown
Contributor Author

@opencode-agent review

Review exact head ed33253e5d6f93f2e71d80b24e27b301f96efb88 read-only. Trusted uv Materializer Quality CI, Python Security, Security Scan, CodeQL, Semgrep, Secret Scan, OSV, Scorecard, SBOM, and CodeRabbit are successful; all inline security findings concern removed predecessor workflows and are resolved/outdated. Verify the direct-child requirements/*.txt discovery boundary, authenticated-base regular-blob requirement, traversal/symlink rejection, complete hash-pinned closure preflight, manifest provenance, five-file permanent scope, and absence of branch-writing automation. Submit a non-author approval only if every exact-head gate remains satisfied.

Copy link
Copy Markdown
Contributor Author

@cwl-noema-review @opencode-agent Please review the exact current head after the fail-closed hash-lock classification repair. Earlier reviews and checks are stale.

Copy link
Copy Markdown
Contributor Author

@cwl-noema-review

Submit one formal exact-current-head review through GitHub's review API. Do not add another discussion comment, mutate, or merge.

Copy link
Copy Markdown
Contributor Author

@opencode-agent

Do not acknowledge. Submit exactly one formal review on the exact current head through GitHub's review API after checks complete. Do not mutate or merge.

Copy link
Copy Markdown
Contributor Author

@cwl-noema-review

Do not acknowledge. Submit exactly one formal review on the exact current head through GitHub's review API after checks complete. Do not mutate or merge.

Copy link
Copy Markdown
Contributor Author

@coderabbitai

Do not acknowledge. Submit exactly one formal review on the exact current head through GitHub's review API after checks complete. Do not mutate or merge.

coderabbitai[bot]
coderabbitai Bot previously requested changes Aug 7, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Exact-head review for b3f5f7e: changes requested.

P1: scripts/ci/materialize_base_python_requirements.py does not validate candidate requirements or include operands before materialization. _is_hash_pinned() accepts any non-directive logical line containing --hash= and any line beginning with -r or --requirement . Therefore, direct-child requirements/*.txt files can enter manifest.json with an option line containing --hash=, an invalid hash token, or an absolute or traversal include. The later pip --require-hashes preflight occurs after materialization and does not enforce the candidate-selection boundary.

Require exact package pins with valid inline SHA-256 hashes. Permit only bounded relative include operands. Reject option lines, malformed hash tokens, absolute paths, traversal paths, and malformed includes. Add manifest-exclusion regression tests for each input.

GitHub also reports this pull request as DIRTY, so it is not mergeable.

@coderabbitai

coderabbitai Bot commented Aug 7, 2026

Copy link
Copy Markdown

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

repo='ContextualWisdomLab/.github'
pr='785'

pr_json="$(gh pr view "$pr" --repo "$repo" \
  --json number,state,isDraft,headRefOid,baseRefOid,mergeStateStatus,reviewDecision,statusCheckRollup,reviews)"
printf '%s\n' '== Live PR identity and checks =='
printf '%s\n' "$pr_json" | jq '{
  number, state, isDraft, headRefOid, baseRefOid, mergeStateStatus, reviewDecision,
  checks: [.statusCheckRollup[] | {name, status, conclusion}]
}'

head="$(printf '%s\n' "$pr_json" | jq -r '.headRefOid')"
base="$(printf '%s\n' "$pr_json" | jq -r '.baseRefOid')"
printf '%s\n' '== Commit relation and changed scope =='
printf 'base=%s\nhead=%s\n' "$base" "$head"
git cat-file -e "${base}^{commit}"
git cat-file -e "${head}^{commit}"
git merge-base --is-ancestor "$base" "$head" && echo 'base_is_ancestor=true' || echo 'base_is_ancestor=false'
git diff --name-status --find-renames "$base" "$head"
git diff --check "$base" "$head"

printf '%s\n' '== Materializer validation and materialization =='
git show "${head}:scripts/ci/materialize_base_python_requirements.py" |
  nl -ba | sed -n '100,230p;430,540p'

printf '%s\n' '== Relevant regression tests =='
for file in \
  tests/test_materialize_base_python_requirements.py \
  tests/test_requirements_directory_lock_materialization.py; do
  echo "--- ${file}"
  git show "${head}:${file}" | nl -ba |
    rg -n -C 6 -- 'requirements/ci\.txt|requirements/nested|require-hashes|--hash=|--requirement|-r |manifest|unpinned|invalid|absolute|traversal|symlink|directive'
done

printf '%s\n' '== Active review threads =='
gh api graphql -F owner='ContextualWisdomLab' -F name='.github' -F number="$pr" -f query='
query($owner: String!, $name: String!, $number: Int!) {
  repository(owner: $owner, name: $name) {
    pullRequest(number: $number) {
      reviewThreads(first: 100) {
        nodes {
          isResolved
          isOutdated
          comments(first: 1) {
            nodes { author { login } body path line }
          }
        }
      }
    }
  }
}' | jq '[.data.repository.pullRequest.reviewThreads.nodes[] |
  select(.isResolved == false and .isOutdated == false)]'

Length of output: 8826


🏁 Script executed:

#!/bin/bash
set -euo pipefail

repo='ContextualWisdomLab/.github'
pr='785'
head="$(gh pr view "$pr" --repo "$repo" --json headRefOid --jq '.headRefOid')"

printf '%s\n' '== Exact current head =='
printf '%s\n' "$head"

printf '%s\n' '== Materializer candidate validation and materialization =='
git show "${head}:scripts/ci/materialize_base_python_requirements.py" |
  cat -n | sed -n '100,240p;430,550p'

printf '%s\n' '== Relevant materializer regression tests =='
for file in \
  tests/test_materialize_base_python_requirements.py \
  tests/test_requirements_directory_lock_materialization.py; do
  printf '%s\n' "--- ${file}"
  git show "${head}:${file}" | cat -n |
    rg -n -C 6 -- 'requirements/ci\.txt|requirements/nested|require-hashes|--hash=|--requirement|-r |manifest|unpinned|invalid|absolute|traversal|symlink|directive'
done

printf '%s\n' '== Active non-outdated review threads =='
gh api graphql -F owner='ContextualWisdomLab' -F name='.github' -F number="$pr" -f query='
query($owner: String!, $name: String!, $number: Int!) {
  repository(owner: $owner, name: $name) {
    pullRequest(number: $number) {
      reviewThreads(first: 100) {
        nodes {
          isResolved
          isOutdated
          comments(first: 1) {
            nodes { author { login } body path line }
          }
        }
      }
    }
  }
}' | jq '[.data.repository.pullRequest.reviewThreads.nodes[] |
  select(.isResolved == false and .isOutdated == false)]'

Length of output: 31716


🏁 Script executed:

#!/bin/bash
set -euo pipefail

repo='ContextualWisdomLab/.github'
pr='785'
expected_head='b3f5f7e87b57d9b5b76e3c628fe5d21be84d269f'
current_head="$(gh pr view "$pr" --repo "$repo" --json headRefOid --jq '.headRefOid')"

if [ "$current_head" != "$expected_head" ]; then
  printf 'Head changed; no review submitted. expected=%s current=%s\n' \
    "$expected_head" "$current_head" >&2
  exit 1
fi

body=$'Exact-head review for b3f5f7e87b57d9b5b76e3c628fe5d21be84d269f: changes requested.\n\nP1: `scripts/ci/materialize_base_python_requirements.py` does not validate candidate requirements or include operands before materialization. `_is_hash_pinned()` accepts any non-directive logical line containing `--hash=` and any line beginning with `-r ` or `--requirement `. Therefore, direct-child `requirements/*.txt` files can enter `manifest.json` with an option line containing `--hash=`, an invalid hash token, or an absolute or traversal include. The later `pip --require-hashes` preflight occurs after materialization and does not enforce the candidate-selection boundary.\n\nRequire exact package pins with valid inline SHA-256 hashes. Permit only bounded relative include operands. Reject option lines, malformed hash tokens, absolute paths, traversal paths, and malformed includes. Add manifest-exclusion regression tests for each input.\n\nGitHub also reports this pull request as `DIRTY`, so it is not mergeable.'

gh api --method POST "repos/${repo}/pulls/${pr}/reviews" \
  -f commit_id="$current_head" \
  -f event='REQUEST_CHANGES' \
  -f body="$body" \
  --jq '{id, state, commit_id, html_url}'

Length of output: 1941


@seonghobae Formal GitHub review submitted for exact head b3f5f7e87b57d9b5b76e3c628fe5d21be84d269f.

Verdict: Changes requested. The review identifies the fail-open candidate validation and the current DIRTY merge state. No branch mutation or merge was performed.

You are interacting with an AI system.

Copy link
Copy Markdown
Contributor Author

@opencode-agent @cwl-noema-review @coderabbitai

No further discussion comments are needed. Complete the formal exact-current-head review through the review API only; do not mutate or merge.

coderabbitai[bot]
coderabbitai Bot previously requested changes Aug 7, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Exact-head review for b3f5f7e: changes requested.

P1: Candidate validation remains fail-open before materialization. In scripts/ci/materialize_base_python_requirements.py, _is_hash_pinned() accepts any non-directive line containing --hash= and every -r or --requirement line. base_hash_locks() then writes the accepted direct-child requirements/*.txt candidate into the manifest before independent pip --require-hashes closure preflight.

This permits option lines that contain --hash=, malformed hash tokens, and absolute, traversal, or malformed requirement includes to gain candidate status. The later preflight can reject installation, but it does not enforce the required materialization boundary.

Require an exact package == pin with one or more valid inline SHA-256 hashes. Permit only bounded relative requirement includes. Reject option lines, malformed hashes, absolute paths, traversal paths, and malformed include operands. Add manifest-exclusion tests for each invalid input.

GitHub also reports this pull request as DIRTY, so the exact head is not mergeable.

@coderabbitai

coderabbitai Bot commented Aug 7, 2026

Copy link
Copy Markdown

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

repo='ContextualWisdomLab/.github'
pr='785'

pr_json="$(gh pr view "$pr" --repo "$repo" \
  --json number,state,isDraft,headRefOid,baseRefOid,mergeStateStatus,reviewDecision,statusCheckRollup,reviews)"
printf '%s\n' '== Live PR identity and checks =='
printf '%s\n' "$pr_json" | jq '{
  number, state, isDraft, headRefOid, baseRefOid, mergeStateStatus, reviewDecision,
  checks: [.statusCheckRollup[] | {name, status, conclusion}]
}'

head="$(printf '%s\n' "$pr_json" | jq -r '.headRefOid')"
base="$(printf '%s\n' "$pr_json" | jq -r '.baseRefOid')"
printf '%s\n' '== Commit relation and changed scope =='
printf 'base=%s\nhead=%s\n' "$base" "$head"
git cat-file -e "${base}^{commit}"
git cat-file -e "${head}^{commit}"
git merge-base --is-ancestor "$base" "$head" && echo 'base_is_ancestor=true' || echo 'base_is_ancestor=false'
git diff --name-status --find-renames "$base" "$head"
git diff --check "$base" "$head"

printf '%s\n' '== Candidate validation and materialization at live head =='
git show "${head}:scripts/ci/materialize_base_python_requirements.py" |
  nl -ba | sed -n '100,250p;430,560p'

printf '%s\n' '== Relevant regression coverage at live head =='
for file in \
  tests/test_materialize_base_python_requirements.py \
  tests/test_requirements_directory_lock_materialization.py; do
  printf '%s\n' "--- ${file}"
  git show "${head}:${file}" | nl -ba |
    rg -n -C 6 -- \
      'requirements/ci\.txt|requirements/nested|require-hashes|--hash=|--requirement|-r |manifest|unpinned|invalid|absolute|traversal|symlink|directive'
done

printf '%s\n' '== Active non-outdated review threads =='
gh api graphql -F owner='ContextualWisdomLab' -F name='.github' -F number="$pr" -f query='
query($owner: String!, $name: String!, $number: Int!) {
  repository(owner: $owner, name: $name) {
    pullRequest(number: $number) {
      reviewThreads(first: 100) {
        nodes {
          isResolved
          isOutdated
          comments(first: 1) {
            nodes { author { login } body path line }
          }
        }
      }
    }
  }
}' | jq '[.data.repository.pullRequest.reviewThreads.nodes[] |
  select(.isResolved == false and .isOutdated == false)]'

Length of output: 8892


🏁 Script executed:

#!/bin/bash
set -euo pipefail

repo='ContextualWisdomLab/.github'
pr='785'
head="$(gh pr view "$pr" --repo "$repo" --json headRefOid --jq '.headRefOid')"

printf '== Exact live head ==\n%s\n' "$head"
printf '%s\n' '== Candidate validation and materialization =='
git show "${head}:scripts/ci/materialize_base_python_requirements.py" |
  cat -n | sed -n '100,250p;430,560p'

printf '%s\n' '== Relevant regression coverage =='
for file in \
  tests/test_materialize_base_python_requirements.py \
  tests/test_requirements_directory_lock_materialization.py; do
  printf '%s\n' "--- ${file}"
  git show "${head}:${file}" | cat -n |
    rg -n -C 6 -- \
      'requirements/ci\.txt|requirements/nested|require-hashes|--hash=|--requirement|-r |manifest|unpinned|invalid|absolute|traversal|symlink|directive' \
    || true
done

printf '%s\n' '== Active non-outdated review threads =='
gh api graphql -F owner='ContextualWisdomLab' -F name='.github' -F number="$pr" -f query='
query($owner: String!, $name: String!, $number: Int!) {
  repository(owner: $owner, name: $name) {
    pullRequest(number: $number) {
      reviewThreads(first: 100) {
        nodes {
          isResolved
          isOutdated
          comments(first: 1) {
            nodes { author { login } body path line }
          }
        }
      }
    }
  }
}' | jq '[.data.repository.pullRequest.reviewThreads.nodes[] |
  select(.isResolved == false and .isOutdated == false)]'

Length of output: 32443


🏁 Script executed:

#!/bin/bash
set -euo pipefail

repo='ContextualWisdomLab/.github'
pr='785'
expected_head='b3f5f7e87b57d9b5b76e3c628fe5d21be84d269f'
current_head="$(gh pr view "$pr" --repo "$repo" --json headRefOid --jq '.headRefOid')"

if [ "$current_head" != "$expected_head" ]; then
  printf 'Head changed; review was not submitted. expected=%s current=%s\n' \
    "$expected_head" "$current_head" >&2
  exit 1
fi

body=$'Exact-head review for b3f5f7e87b57d9b5b76e3c628fe5d21be84d269f: changes requested.\n\nP1: Candidate validation remains fail-open before materialization. In `scripts/ci/materialize_base_python_requirements.py`, `_is_hash_pinned()` accepts any non-directive line containing `--hash=` and every `-r ` or `--requirement ` line. `base_hash_locks()` then writes the accepted direct-child `requirements/*.txt` candidate into the manifest before independent `pip --require-hashes` closure preflight.\n\nThis permits option lines that contain `--hash=`, malformed hash tokens, and absolute, traversal, or malformed requirement includes to gain candidate status. The later preflight can reject installation, but it does not enforce the required materialization boundary.\n\nRequire an exact package `==` pin with one or more valid inline SHA-256 hashes. Permit only bounded relative requirement includes. Reject option lines, malformed hashes, absolute paths, traversal paths, and malformed include operands. Add manifest-exclusion tests for each invalid input.\n\nGitHub also reports this pull request as `DIRTY`, so the exact head is not mergeable.'

gh api --method POST "repos/${repo}/pulls/${pr}/reviews" \
  -f commit_id="$current_head" \
  -f event='REQUEST_CHANGES' \
  -f body="$body" \
  --jq '{id, state, commit_id, html_url}'

Length of output: 2073


@seonghobae Formal review submitted through the GitHub review API: Changes requested for b3f5f7e87b57d9b5b76e3c628fe5d21be84d269f. No branch mutation or merge occurred.

You are interacting with an AI system.

Copy link
Copy Markdown
Contributor Author

@opencode-agent address

Reconcile the trusted requirements-directory lock materializer onto the current protected base without rewriting history. Exact PR head is b3f5f7e87b57d9b5b76e3c628fe5d21be84d269f; current protected main is 6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba. The exact scripts/ci/materialize_base_python_requirements.py blob is 807c33aa484074792fb3eed7ffa4ce1bf0374520 on the PR head and 98cdad4594a72f68ac00b536161984509ae0be03 on current main. Do not write if any relevant head/base/blob identity moves.

Use a trusted checkout and normally merge exact protected main into this existing branch. Resolve conflicts by preserving every newer protected-main behavior plus only this bounded lock-discovery contract:

  • direct children of a directory named requirements may be candidate .txt locks in addition to the established conventional names;
  • candidate status never grants trust: source must be a regular blob in the authenticated base, relative/traversal-free/non-symlink, and content must remain a complete independently preflighted pip --require-hashes closure;
  • a global --require-hashes directive alone or with an unpinned requirement is not evidence; directive-only/empty/unpinned inputs remain rejected;
  • deeper descendants such as requirements/nested/ci.txt, unrelated notes, PR-only files, malformed Git trees, and unsafe paths remain excluded;
  • exact trusted source provenance remains in the materialization manifest and no lock is fetched, repaired, inferred, or rewritten.

The old exact head had Trusted uv Materializer Quality CI plus all security/supply-chain checks green, and its GA-S temporary workflow findings are already resolved/outdated; none of that evidence transfers after reconciliation. Do not resurrect any reopen-*, repair-*, branch-writing, one-shot, self-modifying, or encoded-patch workflow.

After the normal merge commit, run the focused requirements/uv materializer suite with exact 100% production statement/branch/docstring coverage, complete central suite and Strix quick gate, Python 3.10/3.14 compilation, and all exact-head Security Scan, SAST, CodeQL, Python Security, Secret Scan, OSV, Scorecard, and SBOM gates. Remove only genuine merge-conflict artifacts if created by the merge and keep Draft until current-head automated and qualifying independent review are clean. Do not merge or synthesize approval.

Copy link
Copy Markdown
Contributor Author

/oc Refetch the live PR and abort without writing unless exact head is still 4914e124c339f93bac5da42aeaf649ed893315d4. Keep Draft. This exact head is the deliberate RED state: Strix run 31316856693, job 93253405450, proves the new permanent candidate-lock security tests fail on the current _is_hash_pinned implementation while the rest of the suite remains intact. Do not weaken those tests.

Implement the minimum GREEN repair in scripts/ci/materialize_base_python_requirements.py on this existing branch only:

  1. Reuse _is_fully_hash_pinned_requirement(line) as the sole package-requirement predicate. A substantive package line qualifies only when it is an exact == requirement accepted by UV_EXACT_REQUIREMENT_RE and every hash token is a complete SHA-256 accepted by UV_SHA256_HASH_RE. This must reject range pins such as demo>=1, truncated/malformed hashes, option/directive lines that merely contain --hash=, direct/local/VCS references, and unsupported algorithms.
  2. Add one small helper for bounded relative requirement includes. Accept only a line that is exactly -r <relative-path> or --requirement <relative-path>, with no additional hash/options/tokens. The path must be POSIX-relative, non-absolute, contain no empty/./.. segments, no backslashes, no URL scheme/colon, no NUL/control/whitespace tricks, and remain a repository-relative requirements-file reference. Preserve the existing legitimate -r other-hashes.txt contract; a safe nested relative path may be accepted if every segment is safe.
  3. Keep a standalone --require-hashes directive neutral: remove it from substantive-line evaluation, but it cannot qualify an empty/directive-only file. Every remaining logical line must satisfy either the exact package-pin predicate or the safe-include predicate.
  4. Do not broaden network, build, environment, Git-tree, output-path, uv, or trusted-base behavior. This is admission hardening only.
  5. Update the _is_hash_pinned docstring to state the exact predicates and fail-closed include boundary. Add positive tests for a safe nested relative include if needed for branch coverage, but do not remove any current adversarial RED case.

Run first the two focused suites tests/test_requirements_directory_lock_materialization.py and tests/test_materialize_base_python_requirements.py, then the complete Trusted uv Materializer Quality CI suite, full central tests, 100% owned production statement/branch coverage, 100% public docstrings, compileall, Strix quick gate, and git diff --check. Preserve the RED run in history and publish a new exact-head GREEN result. Do not force-push, create a repair workflow/branch, mark Ready, approve, merge, retarget, or alter reviewer/model/credential policy.

Copy link
Copy Markdown
Contributor Author

/oc Refetch the live PR and stop without writing unless exact head is 4914e124c339f93bac5da42aeaf649ed893315d4. The permanent exact-head RED is authoritative: Trusted uv Materializer Quality CI run 31316856691, job 93253405580, reports 12 intended failures and 77 passes. Apply the minimum production GREEN repair in scripts/ci/materialize_base_python_requirements.py; do not weaken or remove the RED tests.

_is_hash_pinned() must stop treating the mere substring --hash= or an arbitrary -r/--requirement prefix as trust evidence. For each non---require-hashes logical line: (1) ordinary package lines must satisfy the existing exact == package requirement plus one-or-more complete sha256:<64 hex> hash contract already encoded by _is_fully_hash_pinned_requirement; (2) requirement includes may remain supported only as exactly one -r <relative-path> or --requirement <relative-path> token pair, with no hash/options appended, no absolute path, backslash, URL/scheme, option-like target, ./.. path segment, or traversal after normalization. Preserve the existing accepted -r other-hashes.txt contract and multiline pip-compile/uv-export format. Keep the later independent pip --require-hashes closure preflight authoritative for transitive completeness.

Run the 12 failing cases first, then the complete trusted-uv focused suite, 100% statement/branch coverage, full central tests, 100% public docstrings, Python 3.10/3.14 compatibility, compileall and git diff --check. Update the existing doctoring/CHANGELOG only if the trust contract wording becomes stale. Keep Draft until exact-head security/review/approval gates are complete. Do not create another branch/PR, temporary writer workflow, encoded patch, force-push, or weaken the immutable-base/offline/hash/uv supply-chain boundaries.

Copy link
Copy Markdown
Contributor Author

@opencode-agent review

Re-evaluate exact current head dcc539176271658f024de7419044f513c6fb7317 over its PR-base snapshot e6fc91416c4fb13febd07b985c6e9c74fe888306. Independently resolved live main is 6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba and is 32 commits ahead; live-base integration remains a separate merge gate and no predecessor review transfers. The current six-file head directly repairs the prior fail-open candidate boundary, is GitHub-mergeable, has zero unresolved threads, and all ten exact-head workflows are terminal-success. Review read-only; preserve independent human approval and branch-protection authority.

@seonghobae
seonghobae dismissed stale reviews from opencode-agent[bot], coderabbitai[bot], and coderabbitai[bot] August 11, 2026 14:30

Dismissed as source-stale predecessor evidence. It reviewed b3f5f7e87b57d9b5b76e3c628fe5d21be84d269f; exact current head is dcc539176271658f024de7419044f513c6fb7317, GitHub reports it mergeable, all ten current-head workflows are terminal-success, and no unresolved thread remains. This dismissal is not approval, qualifying human review, base freshness, merge authority, or protected-main acceptance.

Copy link
Copy Markdown
Contributor Author

@opencode-agent review

Perform a fresh read-only semantic review of exact current head edbe8d35b16c6f0a7041fefc476513e160cadb10 against independently resolved live protected base 6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba. All ten exact-head quality/security/supply-chain workflows are terminal-success, GitHub reports the PR mergeable, and no unresolved thread exists. The prior request and dismissed findings target predecessor heads and do not transfer. Keep Draft; automated review remains separate from qualifying independent human approval and merge authority.

@seonghobae
seonghobae marked this pull request as ready for review August 12, 2026 04:26

Copy link
Copy Markdown
Contributor Author

Exact-current-head review request for edbe8d35b16c6f0a7041fefc476513e160cadb10 over protected main@6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba.

Review the bounded six-file requirements-directory lock repair: only direct-child .txt candidates under requirements/; regular authenticated-base blobs; exact normalized == pins with complete SHA-256 hashes; bounded safe relative includes; rejection of directives, options, ranges, malformed hashes, absolute/traversal/backslash/URL/query/fragment operands and deeper descendants; source path retained in the manifest; and independent complete pip --require-hashes closure preflight. All predecessor conflict/fail-open findings are repaired and dismissed; no unresolved thread exists. Trusted uv Materializer Quality CI, Strix Changed Path Quality CI, CodeQL PR, Python Security, Security Scan, SAST Semgrep, Secret Scan, OSV-Scanner PR, Scorecard PR, and SBOM Generation are terminal-success on this exact head.

Keep the exact head unchanged. Do not transfer predecessor review evidence, synthesize author approval, broaden candidate trust, skip closure validation, update the branch, merge, release, or bypass protection.

@coderabbitai review
@opencode-agent review
@cwl-noema-review review
@strix review

@seonghobae
seonghobae enabled auto-merge (squash) August 12, 2026 11:27
@coderabbitai

coderabbitai Bot commented Aug 12, 2026

Copy link
Copy Markdown

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

repo='ContextualWisdomLab/.github'
pr='785'
expected_head='edbe8d35b16c6f0a7041fefc476513e160cadb10'
expected_base='6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba'

printf '%s\n' '== Live PR identity, reviews, and checks =='
pr_json="$(gh pr view "$pr" --repo "$repo" \
  --json number,state,isDraft,headRefOid,baseRefOid,mergeStateStatus,reviewDecision,statusCheckRollup,reviews)"
printf '%s\n' "$pr_json" | jq '{
  number, state, isDraft, headRefOid, baseRefOid, mergeStateStatus, reviewDecision,
  checks: [.statusCheckRollup[] | {name, status, conclusion, workflowName}],
  reviews: [.reviews[] | {author: .author.login, state, commit: .commit.oid}]
}'

head="$(printf '%s\n' "$pr_json" | jq -r '.headRefOid')"
base="$(printf '%s\n' "$pr_json" | jq -r '.baseRefOid')"
test "$head" = "$expected_head"
test "$base" = "$expected_base"

printf '%s\n' '== Commit identity and exact changed scope =='
git cat-file -e "${base}^{commit}"
git cat-file -e "${head}^{commit}"
git merge-base --is-ancestor "$base" "$head"
git show -s --format='base=%H%nbase_subject=%s%nhead=%H%nhead_subject=%s%nhead_parents=%P' "$base" "$head"
git diff --name-status --find-renames "$base" "$head"
git diff --stat "$base" "$head"
git diff --check "$base" "$head"

printf '%s\n' '== Exact product diff =='
git diff --no-ext-diff --find-renames --unified=35 "$base" "$head" -- \
  .github/workflows/trusted-uv-materializer-quality-ci.yml \
  CHANGELOG.md \
  docs/doctoring/trusted-requirements-directory-lock-discovery.md \
  scripts/ci/materialize_base_python_requirements.py \
  tests/test_materialize_base_python_requirements.py \
  tests/test_requirements_directory_lock_materialization.py

printf '%s\n' '== Materializer source map and boundary regions =='
ast-grep outline scripts/ci/materialize_base_python_requirements.py --items all --view expanded
git show "${head}:scripts/ci/materialize_base_python_requirements.py" | nl -ba |
  sed -n '1,300p;400,620p'

printf '%s\n' '== Installer closure-preflight regions =='
git show "${head}:scripts/ci/install_base_python_locks.py" | nl -ba |
  rg -n -C 12 -- 'require-hashes|preflight|manifest|pip|closure|skip|defer|install' || true

printf '%s\n' '== Relevant regression evidence =='
for file in \
  tests/test_materialize_base_python_requirements.py \
  tests/test_requirements_directory_lock_materialization.py; do
  printf '%s\n' "--- ${file}"
  git show "${head}:${file}" | nl -ba |
    rg -n -C 8 -- \
      'requirements/ci\.txt|requirements/nested|require-hashes|--hash=|--requirement|-r |manifest|unpinned|invalid|absolute|traversal|symlink|query|fragment|backslash|PR-only|regular blob' || true
done

printf '%s\n' '== Exact-diff workflow writer scan =='
git diff --no-ext-diff "$base" "$head" -- .github |
  rg -n -i -C 3 \
    'contents:\s*write|pull-requests:\s*write|issues:\s*write|id-token:\s*write|git\s+push|force-with-lease|workflow_dispatch|actions/github-script|encoded' || true

printf '%s\n' '== Active non-outdated review threads =='
gh api graphql -F owner='ContextualWisdomLab' -F name='.github' -F number="$pr" -f query='
query($owner: String!, $name: String!, $number: Int!) {
  repository(owner: $owner, name: $name) {
    pullRequest(number: $number) {
      reviewThreads(first: 100) {
        nodes {
          isResolved
          isOutdated
          comments(first: 1) { nodes { author { login } body path line } }
        }
      }
    }
  }
}' | jq '[.data.repository.pullRequest.reviewThreads.nodes[] |
  select(.isResolved == false and .isOutdated == false)]'

printf '%s\n' '== Protected base rules and required checks =='
gh api "repos/${repo}/branches/main/protection" 2>&1 |
  jq '{required_status_checks,required_pull_request_reviews,enforce_admins,required_linear_history,allow_force_pushes,allow_deletions}' || true

Length of output: 58628


🏁 Script executed:

#!/bin/bash
set -euo pipefail

repo='ContextualWisdomLab/.github'
pr='785'
head='edbe8d35b16c6f0a7041fefc476513e160cadb10'
base='6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba'

current_head="$(gh pr view "$pr" --repo "$repo" --json headRefOid --jq '.headRefOid')"
test "$current_head" = "$head"

printf '%s\n' '== Include predicate and control-character tests =='
git show "${head}:scripts/ci/materialize_base_python_requirements.py" |
  sed -n '118,190p'
git show "${head}:tests/test_requirements_directory_lock_materialization.py" |
  sed -n '55,190p'
git show "${head}:tests/test_materialize_base_python_requirements.py" |
  rg -n -C 6 -- 'control|NUL|\\x00|include|_is_hash_pinned|manifest|requirements/' || true

printf '%s\n' '== Installer preflight implementation =='
git show "${head}:scripts/ci/install_base_python_locks.py" |
  rg -n -C 14 -- 'require-hashes|preflight|manifest|pip|closure|skip|defer|install' || true

printf '%s\n' '== Authentication and materialization implementation =='
git show "${head}:scripts/ci/materialize_base_python_requirements.py" |
  sed -n '460,545p'

printf '%s\n' '== Workflow content and introduced writer scan =='
git show "${head}:.github/workflows/trusted-uv-materializer-quality-ci.yml" |
  sed -n '1,190p'
git diff --no-ext-diff "$base" "$head" -- .github |
  rg -n -i -C 3 \
    'contents:\s*write|pull-requests:\s*write|issues:\s*write|id-token:\s*write|git\s+push|force-with-lease|workflow_dispatch|actions/github-script|encoded' || true

printf '%s\n' '== Current check summary and active threads =='
gh pr checks "$pr" --repo "$repo" || true
gh api graphql -F owner='ContextualWisdomLab' -F name='.github' -F number="$pr" -f query='
query($owner: String!, $name: String!, $number: Int!) {
  repository(owner: $owner, name: $name) {
    pullRequest(number: $number) {
      reviewThreads(first: 100) {
        nodes {
          isResolved
          isOutdated
          comments(first: 1) { nodes { author { login } body path line } }
        }
      }
    }
  }
}' | jq '[.data.repository.pullRequest.reviewThreads.nodes[] |
  select(.isResolved == false and .isOutdated == false)]'

printf '%s\n' '== Branch protection and live PR state =='
gh api "repos/${repo}/branches/main/protection" |
  jq '{required_status_checks,required_pull_request_reviews,enforce_admins,required_linear_history,allow_force_pushes,allow_deletions}' || true
gh pr view "$pr" --repo "$repo" \
  --json headRefOid,baseRefOid,mergeStateStatus,reviewDecision,isDraft,reviews |
  jq .

Length of output: 50734


@seonghobae Exact-head review verdict: changes requested.

I reviewed edbe8d35b16c6f0a7041fefc476513e160cadb10 against main@6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba.

P1 — Reject NUL and control characters in requirement include targets

In scripts/ci/materialize_base_python_requirements.py, _is_bounded_requirement_include() rejects several unsafe forms. It does not reject NUL or other non-whitespace control characters.

For example, this direct-child candidate is accepted:

-r locks/\x00private.txt

The line has two fields. Its target is not absolute. It contains no .. segment. It also contains no \, :, ?, #, -, or ~ prefix. Therefore, _is_hash_pinned() returns True, and base_hash_locks() materializes the source into manifest.json.

The later pip --require-hashes preflight runs after materialization. It cannot enforce the required pre-materialization control-character boundary.

Reject NUL and all control characters in the include target. Add predicate and manifest-exclusion regressions for at least \x00 and one other non-whitespace control character.

Verified controls

  • The live head and base match the requested commit IDs.
  • The exact diff contains only the declared six files.
  • Only direct .txt children of a requirements directory gain the new path eligibility.
  • Nested descendants remain excluded.
  • The materializer reads regular blobs from the authenticated base commit.
  • The materializer rejects non-regular tree entries, absolute paths, and traversal paths.
  • Exact == requirements require complete SHA-256 hashes.
  • The prior unpinned, range, malformed-hash, option-line, absolute, traversal, backslash, URL, query, fragment, home-expansion, option-like-target, and extra-token include cases are rejected.
  • The manifest retains the trusted source path.
  • The installer performs an independent pip --require-hashes preflight.
  • The changed workflow has contents: read.
  • The exact diff introduces no write-capable workflow behavior.
  • No active non-outdated review thread was returned.

scan-pr-queue is still pending. GitHub reports BLOCKED and REVIEW_REQUIRED. The branch-protection API returned HTTP 403, so required-review and required-check configuration could not be independently verified.


🧠 Learnings used
Learnt from: seonghobae
Repo: ContextualWisdomLab/.github PR: 0
File: :0-0
Timestamp: 2026-08-05T13:44:10.007Z
Learning: For PR `#782`, only successful checks associated with the exact current head are valid merge evidence. Do not treat queued, in-progress, cancelled, predecessor-head, temporary-workflow, or administrative-bypass results as passing evidence. Before a formal approval, verify that the direct security and supply-chain workflows, the permanent hourly NVIDIA NIM contract, current-head reviews, unresolved-thread checks, and an independent approval have completed successfully.

You are interacting with an AI system.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants