Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
91 commits
Select commit Hold shift + click to select a range
67d6b53
test(coverage): define bounded trusted uv download retries
seonghobae Aug 5, 2026
8e28523
docs(coverage): define trusted uv transient retry boundary
seonghobae Aug 5, 2026
b3fb370
ci: verify trusted uv retry repair once
seonghobae Aug 5, 2026
6cc1c40
ci: repair trusted uv retry workflow syntax
seonghobae Aug 5, 2026
a893955
ci: add one-shot trusted uv retry patch helper
seonghobae Aug 5, 2026
03499b1
ci: run trusted uv retry repair with a standalone helper
seonghobae Aug 5, 2026
581cf5c
ci: exclude one-shot helper from final coverage gate
seonghobae Aug 5, 2026
e053a9a
fix(coverage): retry transient trusted uv downloads
github-actions[bot] Aug 5, 2026
5b7f42c
ci(pr790): repair transient transport classification
seonghobae Aug 5, 2026
390c52b
test(coverage): narrow trusted uv retries to transient failures
seonghobae Aug 5, 2026
d4db09b
ci(pr790): trigger bounded transport repair
seonghobae Aug 5, 2026
5b0766a
ci(pr790): align repair with reviewed RED contracts
seonghobae Aug 5, 2026
b4196bd
ci: export exact PR 790 repair source for verified publication
seonghobae Aug 5, 2026
26a7873
ci: expose exact PR 790 source artifact to pull-request verification
seonghobae Aug 5, 2026
492dd41
chore: remove temporary PR 790 export workflow
seonghobae Aug 5, 2026
f191b1e
chore: remove temporary PR 790 repair workflow
seonghobae Aug 5, 2026
0c1002f
ci(pr790): add deterministic transport finalizer
seonghobae Aug 5, 2026
d62c5a1
ci: apply test-first PR 790 classifier repair
seonghobae Aug 5, 2026
5582e9b
ci(pr790): finalize reviewed transport repair
seonghobae Aug 5, 2026
182d8a6
fix(pr790): cover explicit timeout classification
seonghobae Aug 5, 2026
d78c922
ci(pr790): remove temporary sources before coverage
seonghobae Aug 5, 2026
379b3ec
fix(coverage): classify transient uv transport failures
github-actions[bot] Aug 5, 2026
84d8aa9
test(coverage): lock retry documentation to closed policy
seonghobae Aug 5, 2026
8a51b4f
docs(coverage): reconcile closed trusted uv retry policy
seonghobae Aug 5, 2026
c95a122
docs(changelog): remove overbroad retry claim
seonghobae Aug 5, 2026
24b7f1f
test(coverage): normalize retry policy Markdown
seonghobae Aug 5, 2026
b30303b
test(coverage): align retry policy wording
seonghobae Aug 5, 2026
8516ecb
test(security): prove Git PATH injection fails closed
seonghobae Aug 5, 2026
95816a5
ci(repair): add bounded trusted Git exact-trigger repair
seonghobae Aug 5, 2026
e8d6b2a
ci(repair): bind trusted Git repair to PR exact head
seonghobae Aug 5, 2026
7f426f3
ci(repair): correct exact-head trusted Git commit path
seonghobae Aug 5, 2026
945a6c5
ci(repair): reconcile workflow-permission boundary
seonghobae Aug 5, 2026
075299d
fix(security): resolve Git outside ambient PATH
github-actions[bot] Aug 5, 2026
09744fc
ci(coverage): gate trusted Git executable regression
seonghobae Aug 5, 2026
409fd96
ci(repair): remove bounded trusted Git repair workflow
seonghobae Aug 5, 2026
a306e7c
test(ci): require trusted Git contract trigger coverage
seonghobae Aug 5, 2026
5570d5a
fix(ci): trigger trusted Git contract quality gate
seonghobae Aug 5, 2026
c2fffa1
test(coverage): reject malformed URL reasons without retry
seonghobae Aug 6, 2026
c09313e
ci(pr790): add malformed URL error regression
seonghobae Aug 6, 2026
614002d
test(coverage): pin malformed URL error failure
github-actions[bot] Aug 6, 2026
d11085b
test(coverage): reject malformed URL error reasons
seonghobae Aug 6, 2026
e9fb719
test(coverage): consolidate malformed URL error regression
seonghobae Aug 6, 2026
6f6354b
test(coverage): remove duplicate malformed URL regression
seonghobae Aug 6, 2026
f190f28
test(security): reproduce materializer output path races
seonghobae Aug 6, 2026
e84990c
fix(security): pin materializer output descriptors
seonghobae Aug 6, 2026
b20de65
ci(security): gate descriptor-pinned output regressions
seonghobae Aug 6, 2026
ee90706
docs(security): record descriptor-pinned output contract
seonghobae Aug 6, 2026
b27a1c0
chore(changelog): record output race remediation
seonghobae Aug 6, 2026
1bad6f8
test(coverage): exercise output descriptor failure edges
seonghobae Aug 6, 2026
9211a66
test(coverage): lock malformed URLError reason fail-closed
seonghobae Aug 6, 2026
b90461f
test(coverage): remove duplicate malformed reason contract
seonghobae Aug 6, 2026
5b3a692
test(strix): define semantic non-finding classification
seonghobae Aug 6, 2026
85a122e
fix(strix): classify contradictory semantic non-findings
seonghobae Aug 6, 2026
1d17661
test(strix): require classifier before severity handling
seonghobae Aug 6, 2026
f976605
ci(repair): apply exact-head Strix classifier integration
seonghobae Aug 6, 2026
9502bd4
chore(ci): stop unsafe Strix gate rewrite
seonghobae Aug 6, 2026
9a22722
revert(security): keep contradictory Strix findings blocking
seonghobae Aug 6, 2026
1cae779
revert(test): remove Strix gate-bypass contract
seonghobae Aug 6, 2026
dc78b91
test(coverage): reject hard links added during pinned writes
seonghobae Aug 7, 2026
9e6b720
fix(coverage): revalidate output link count after writes
seonghobae Aug 7, 2026
1bee5b0
docs(coverage): record post-write hard-link validation
seonghobae Aug 7, 2026
c70b954
docs(coverage): define post-write link-count boundary
seonghobae Aug 7, 2026
80b54da
docs(uv): pin Python 3.14 urllib reference
seonghobae Aug 7, 2026
b4c82b2
test(uv): isolate trusted Git executable cache
seonghobae Aug 7, 2026
62f9cde
ci(uv): register retry doctoring regression consistently
seonghobae Aug 7, 2026
d69c073
test(uv): require retry doctoring in focused quality lists
seonghobae Aug 7, 2026
969c1c6
chore(stack): reconcile trusted uv hardening with main
seonghobae Aug 7, 2026
4d26938
chore(stack): resolve current-main changelog overlap
seonghobae Aug 7, 2026
ff86304
chore(stack): keep main changelog hunk identical
seonghobae Aug 7, 2026
04a3783
Merge branch 'main' into fix/trusted-uv-transient-download-retry
opencode-agent[bot] Aug 7, 2026
83f5a05
test(coverage): reject blocking FIFO outputs
seonghobae Aug 7, 2026
cf5c29e
fix(coverage): reject blocking special-file outputs
seonghobae Aug 7, 2026
07d9a4f
ci(coverage): gate FIFO output regression
seonghobae Aug 7, 2026
3336efb
docs(coverage): record non-blocking FIFO boundary
seonghobae Aug 7, 2026
8a7c04b
docs(changelog): record FIFO fail-closed hardening
seonghobae Aug 7, 2026
c9f11e8
test(coverage): pin FIFO regression in quality contract
seonghobae Aug 7, 2026
1912d39
test(strix): require complete quality-gate runtime budget
seonghobae Aug 7, 2026
e0ea9ce
fix(strix): budget complete changed-path quality gate
seonghobae Aug 7, 2026
ab52a13
docs(strix): record bounded quality-gate runtime budget
seonghobae Aug 7, 2026
25a27d5
docs(changelog): record bounded Strix quality budget
seonghobae Aug 7, 2026
463572a
chore(coverage): defer Strix fixture timing to prerequisite
seonghobae Aug 7, 2026
a72c82c
chore(coverage): drop competing Strix budget contract
seonghobae Aug 7, 2026
98deea1
docs(coverage): defer Strix runtime repair to prerequisite
seonghobae Aug 7, 2026
48715e4
chore(coverage): restore canonical Strix doctoring
seonghobae Aug 7, 2026
76e4a6e
docs(changelog): defer Strix fixture repair to prerequisite
seonghobae Aug 7, 2026
6eb06cd
fix(strix): bound quality timeout fixtures (#823)
seonghobae Aug 8, 2026
17e1b56
chore(ci): reconcile Strix quality fixtures from protected main
seonghobae Aug 8, 2026
e519ede
chore(ci): carry Strix timeout doctoring from protected main
seonghobae Aug 8, 2026
16243c5
test(ci): carry Strix timeout fixture regressions from protected main
seonghobae Aug 8, 2026
5879add
chore(changelog): reconcile protected-main Strix fix
seonghobae Aug 8, 2026
28a878f
Merge 5879add039a3892fa0fffa85bca0db1b8e0e93d3 into 6eb06cdd08c79a06f…
seonghobae Aug 8, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 6 additions & 1 deletion .github/workflows/strix-changed-path-quality-ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -7,10 +7,12 @@ on:
- ".github/workflows/strix-changed-path-quality-ci.yml"
- "CHANGELOG.md"
- "docs/doctoring/strix-legal-git-paths.md"
- "docs/doctoring/strix-quality-timeout-fixtures.md"
- "scripts/ci/strix_quick_gate.sh"
- "scripts/ci/test_strix_quick_gate.sh"
- "tests/test_strix_changed_path_policy.py"
- "tests/test_strix_workflow_dependency_hashes.py"
- "tests/test_strix_quality_timeout_fixture_budget.py"

permissions:
contents: read
Expand Down Expand Up @@ -56,11 +58,14 @@ jobs:
-r "${RUNNER_TEMP}/strix-quality-requirements.txt"

- name: Verify exact-head path policy and syntax
env:
STRIX_TEST_PROCESS_TIMEOUT_SECONDS: "3"
STRIX_TEST_FAKE_SLEEP_SECONDS: "5"
shell: bash --noprofile --norc -e -o pipefail {0}
run: |
test "$(git rev-parse HEAD)" = "${{ github.event.pull_request.head.sha || github.sha }}"
python -m coverage run -m pytest tests -q
bash scripts/ci/test_strix_quick_gate.sh
python -m compileall -q tests/test_strix_changed_path_policy.py tests/test_strix_workflow_dependency_hashes.py
python -m compileall -q tests/test_strix_changed_path_policy.py tests/test_strix_workflow_dependency_hashes.py tests/test_strix_quality_timeout_fixture_budget.py
bash -n scripts/ci/strix_quick_gate.sh
git diff --exit-code
10 changes: 10 additions & 0 deletions .github/workflows/trusted-uv-materializer-quality-ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,7 @@ on:
- "scripts/ci/materialize_base_python_requirements.py"
- "tests/conftest.py"
- "tests/test_materialize*.py"
- "tests/test_trusted_git_executable.py"
- "tests/test_trusted_uv*.py"
- "tests/test_uv*.py"
- "tests/test_repository_branch_coverage_*.py"
Expand All @@ -20,6 +21,7 @@ on:
- "scripts/ci/materialize_base_python_requirements.py"
- "tests/conftest.py"
- "tests/test_materialize*.py"
- "tests/test_trusted_git_executable.py"
- "tests/test_trusted_uv*.py"
- "tests/test_uv*.py"
- "tests/test_repository_branch_coverage_*.py"
Expand Down Expand Up @@ -125,9 +127,13 @@ jobs:
python -m coverage erase
python -m coverage run -m pytest \
tests/test_materialize_base_python_requirements.py \
tests/test_materialize_fifo_output_security.py \
tests/test_materialize_output_directory_security.py \
tests/test_materialize_uv_export_hash_contract.py \
tests/test_trusted_git_executable.py \
tests/test_trusted_uv_download_contract.py \
tests/test_trusted_uv_portability_and_streaming.py \
tests/test_trusted_uv_retry_documentation.py \
tests/test_uv_export_isolation_contract.py \
tests/test_uv_redirect_and_coverage_contract.py \
tests/test_uv_redirect_boundary.py \
Expand All @@ -151,9 +157,13 @@ jobs:
python -m compileall -q \
scripts/ci/materialize_base_python_requirements.py \
tests/test_materialize_base_python_requirements.py \
tests/test_materialize_fifo_output_security.py \
tests/test_materialize_output_directory_security.py \
tests/test_materialize_uv_export_hash_contract.py \
tests/test_trusted_git_executable.py \
tests/test_trusted_uv_download_contract.py \
tests/test_trusted_uv_portability_and_streaming.py \
tests/test_trusted_uv_retry_documentation.py \
tests/test_uv_export_isolation_contract.py \
tests/test_uv_redirect_and_coverage_contract.py \
tests/test_uv_redirect_boundary.py \
Expand Down
5 changes: 5 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,12 @@ Semantic Versioning where the repository publishes a release.

### Fixed

- Bounded the Strix quality self-test's deterministic timeout fixtures to 3-second process and 5-second fake-sleep budgets so exact-head policy evidence completes inside the existing job limit without changing production Strix scanner timeouts, providers, credentials, or review semantics.
- Allowed commas and ASCII parentheses in the bounded Strix changed-file path policy so legal tracked Packrat fixtures can receive exact-head security analysis, while rejecting raw `..` components before normalization and keeping controls, backslashes, whitespace ambiguity, and shell punctuation fail-closed.
- Bound each review-agent invocation key to the wrapper's complete canonical payload, including the base branch and requesting actor; altered fields with a valid-format key now fail before durable-leader election or forwarding, and wrapper write permission is job-scoped.
- Bound both trusted-uv quality jobs to `github.event.pull_request.head.sha` and added a permanent two-checkout regression contract so exact-head compatibility, coverage, docstring, and compilation claims cannot silently measure GitHub's generated pull-request merge revision.
- Made Strix treat only a single LiteLLM provider-error line containing NVIDIA NIM context and model-catalog 404 evidence as cross-model fallback evidence, rejecting cross-line signal assembly and provider-like target source literals; moved the public default to Nemotron 3 Super 120B and added a second NVIDIA hosted candidate before GitHub Models without neutralizing reported vulnerabilities.
- Pinned generated Python lock output to no-follow directory and file descriptors, rejected symbolic and multiply linked destinations before mutation, revalidated inode and single-link bindings after synchronized writes, and added deterministic regressions for output-path races, hard links introduced during writes, file swaps, and stalled writes.
- Opened existing generated-lock outputs non-blocking before regular-file validation so attacker-controlled FIFOs and other special entries cannot stall trusted materialization; `ENXIO` now fails closed and a permanent regression is included in the exact-head 100% coverage gate.
- Resolved Git only through the operating system default executable path and rejected missing or relative results before trusted base-lock materialization, preventing pull-request-controlled `PATH` selection.
- Restricted trusted uv retries to HTTP 408/425/429/500/502/503/504 and explicitly classified temporary DNS, timeout, connection, host, or network failures; every retry reuses the immutable request contract and discards failed-attempt bytes, while TLS, permanent DNS, malformed, and unclassified local errors fail after one attempt.
51 changes: 51 additions & 0 deletions docs/doctoring/strix-quality-timeout-fixtures.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,51 @@
# Strix quality timeout-fixture budget

검토 기준일: **2026-08-07**

## Incident

`Strix Changed Path Quality CI`는 실제 Strix 모델 스캔이 아니라 중앙 정책과 `scripts/ci/test_strix_quick_gate.sh`의 결정적 회귀를 검증하는 품질 게이트입니다. 그러나 테스트 하네스의 timeout fixture가 기본적으로 실제 프로세스 제한 30초와 가짜 sleep 60초를 사용하면서 여러 timeout/fallback 경로를 순차 실행했습니다.

PR #821 exact head `f92784f389317d512376a0725cbd78606b2e832c`의 품질 실행은 저장소 테스트 978개와 subtest 16개를 55.11초에 완료한 뒤 timeout fixture 구간을 수행하다가 job의 10분 제한에서 취소되었습니다. 동일 exact head의 rerun도 같은 단계에서 취소되었습니다. 이 결과는 소스 정책 실패가 아니라 결정적 테스트 fixture의 시간 스케일이 품질 job 예산과 맞지 않는다는 증거입니다.

## Decision

품질 workflow의 `Verify exact-head path policy and syntax` 단계에 테스트 전용 환경값만 전달합니다.

- `STRIX_TEST_PROCESS_TIMEOUT_SECONDS=3`
- `STRIX_TEST_FAKE_SLEEP_SECONDS=5`

`test_strix_quick_gate.sh`는 이미 두 값을 명시적 테스트 seam으로 제공하며, fake sleep이 process timeout보다 커야 한다고 fail closed 검증합니다. 따라서 timeout, cleanup, fallback의 순서와 결론은 그대로 유지하면서 wall-clock 대기만 축소합니다.

다음 production scanner 설정은 이 변경에서 건드리지 않습니다.

- `STRIX_PROCESS_TIMEOUT_SECONDS`
- `STRIX_TOTAL_TIMEOUT_SECONDS`
- `LLM_TIMEOUT`
- 실제 Strix workflow의 90분 process budget과 95분 total budget
- 모델, provider, credential, 권한, changed-path 정책 및 branch-protection 의미

테스트 전용 환경값은 해당 품질 step에만 존재해야 하며 production Strix 실행으로 전파되어서는 안 됩니다.

## Verification contract

`tests/test_strix_quality_timeout_fixture_budget.py`는 정확한 named step을 분리하여 다음을 고정합니다.

1. 짧은 process/fake-sleep fixture 값이 모두 존재합니다.
2. 하네스 실행이 같은 step에서 유지됩니다.
3. production timeout 변수는 해당 step에서 override되지 않습니다.
4. workflow trigger가 이 회귀 파일 자체를 포함하여 이후 변경이 정확한 품질 gate를 다시 실행합니다.

전체 `tests` suite, shell harness, Python compilation, Bash syntax 및 clean-worktree 검증은 계속 같은 exact-head quality step에서 수행합니다. 품질 gate의 성공은 실제 Strix 모델 security review, 독립 승인 또는 branch protection을 대체하지 않습니다.

## Rollback

3초/5초 fixture가 GitHub-hosted runner에서 재현 가능한 race margin을 제공하지 못한다는 결정적 실패가 관찰되면 테스트 전용 값만 가장 작은 재현 가능한 상한으로 올립니다. production scanner timeout을 낮추거나 품질 테스트를 삭제하여 문제를 숨기지 않습니다. 10분 job timeout 자체를 늘리는 것은 fixture 가속으로도 완료할 수 없다는 실행 증거가 있을 때 별도 검토합니다.

## References (APA 7th)

GitHub. (n.d.). *Workflow syntax for GitHub Actions*. GitHub Docs. Retrieved August 7, 2026, from https://docs.github.com/en/actions/reference/workflows-and-actions/workflow-syntax

GitHub. (n.d.). *Contexts reference*. GitHub Docs. Retrieved August 7, 2026, from https://docs.github.com/en/actions/reference/workflows-and-actions/contexts

GitHub. (n.d.). *Viewing job execution time*. GitHub Docs. Retrieved August 7, 2026, from https://docs.github.com/en/actions/how-tos/monitor-workflows/view-job-execution-time
Loading
Loading