Skip to content

fix(opencode-review): surface exact coverage setup failures - #759

Open
seonghobae wants to merge 105 commits into
mainfrom
fix/opencode-coverage-failure-diagnostics
Open

fix(opencode-review): surface exact coverage setup failures#759
seonghobae wants to merge 105 commits into
mainfrom
fix/opencode-coverage-failure-diagnostics

Conversation

@seonghobae

@seonghobae seonghobae commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

Purpose

Make central OpenCode coverage failures actionable without weakening fail-closed review, credential, dependency, exact-head, scanner-filesystem, protected-main, or branch-writer boundaries.

Exact integration identity

  • Current exact head: e151a1044e9a88b708c5628190da598a4203cfd6
  • Current exact base: f070c504c1cb06891b800d7ab0cf6ac7d3cf8eae
  • Current GitHub merge-test SHA: 6747e0f3eaf5663f8eca470ea6aec3c4a2c7602e

Every check, review, approval, or commit status from an earlier head is historical only. Pending, queued, cancelled, absent, predecessor-head, or synthetic-merge evidence is not success.

Safe coverage diagnostics

  • JavaScript and Python trusted-lock materializers publish exact failed-stage, bounded exception, and remediation evidence through one shared helper.
  • The helper normalizes whitespace; redacts URL userinfo, every Authorization value regardless of authentication scheme, API keys, tokens, passwords, database URLs, connection strings, and encryption-key patterns; then bounds and HTML-escapes evidence before publication.
  • Bearer, Basic, Token, Digest, AWS signing schemes, custom schemes, and scheme-less values are all replaced in full after the original Authorization field separator.
  • Multiline delimiters are protected; missing GITHUB_OUTPUT preserves local nonzero failure rather than false success.
  • The sanitizer, shared publisher, both materializers, mixed-secret regressions, and scheme-neutral Authorization regressions execute in permanent Python 3.10/3.14 quality gates with 100% statement/branch coverage and production docstrings.
  • Exact contributor heads are checked out with persisted credentials disabled.

Authorization repair TDD history

  • RED scheme-neutral regression: 7624bae9f1b5db81a0773c245d630c36940434e4
  • GREEN production sanitizer: a6303cb70f3d6b42f26f7ec69c2a470e8681ac6a
  • Doctoring: 25c178c2c8a1568ad9c0cd56c32ee5e203b52350
  • Changelog: 37f3ac8d2fc619272dc371e6fe7ecc5a17b3fc91
  • Separator-preserving test correction: bf75c329ac6cd9e39975ca0881063353c7706e23
  • Materializer publication expectation correction/current head: e151a1044e9a88b708c5628190da598a4203cfd6

The first exact-head workflow attempt after the production repair correctly failed because two predecessor-contract assertions expected scheme preservation and one test normalized = to :. The current head preserves the actual separator, requires complete Authorization-value redaction, and no longer expects trailing key-value evidence after the intentionally line-consuming Authorization boundary.

Other preserved boundaries

  • Python 3.10 installs only hash-locked tomli==2.4.1 and exercises the same diagnostic publisher.
  • The final tree contains no branch-local one-shot or repair-pr* write workflow, self-modifying repair automation, apply_pr* helper, or encoded patch directory; a permanent regression prevents recurrence.
  • Protected-main OpenCode Git isolation and NVIDIA NIM fallback behavior remain unchanged and outside this bounded diff.
  • STRIX_SOURCE_DIRS accepts only . or bounded lexical direct directory names and rejects traversal, absolute/nested paths, symlink-expanding entries, globs, option-like values, control characters, oversized values, and excessive cardinality.
  • Native Atheris fuzz-engine locks remain in dedicated repository fuzz workflows, not generic central coverage.
  • Immutable hash-pinned property/regression locks remain eligible for exact-base materialization.
  • aiohttp==3.14.3, cryptography==50.0.0, compatible PyOpenSSL, and generated locks remain fixed.
  • CodeQL pull-request phases use the same immutable v4.37.5 action commit.

Exact-head verification

Every direct workflow completed successfully on e151a1044e9a88b708c5628190da598a4203cfd6:

  • OpenCode Coverage Diagnostics CI 31076981856, including Python 3.10, Python 3.14, 100% statement/branch coverage, docstrings, and compilation;
  • Trusted uv Materializer Quality CI 31076981840;
  • Python Security 31076981825;
  • Security Scan 31076981844;
  • CodeQL PR 31076981860;
  • SAST Semgrep 31076982036;
  • Secret Scan 31076981882;
  • OSV-Scanner PR 31076982213;
  • Scorecard PR 31076981848; and
  • SBOM Generation 31076981826.

The exact-head CodeRabbit commit status is successful and all inline review threads are resolved. A fresh exact-head OpenCode/Noema/CodeRabbit review request has been posted. The author's current-head comment is not an independent approval.

Merge gate

Do not merge until:

  1. no new valid current-head human, CodeRabbit, GitHub Advanced Security, OpenCode, Noema, Strix, Dependabot, or other automated finding remains;
  2. a qualifying non-author independent approval is anchored to e151a1044e9a88b708c5628190da598a4203cfd6; and
  3. branch protection and repository policy permit merge without administrative bypass or synthesized approval.

Auto-merge is enabled, but no predecessor-head evidence may satisfy the current gate.

Standards traceability

  • docs/doctoring/coverage-failure-diagnostics.md records scheme-neutral Authorization-value redaction and cites RFC 3986, GitHub workflow-command guidance, and the OWASP Logging Cheat Sheet in APA 7 format.
  • docs/doctoring/coverage-native-fuzz-lock-boundary.md records generic coverage versus native fuzz-engine dependency separation.
  • docs/doctoring/strix-source-directory-boundary.md cites MITRE CWE-22 and OWASP Path Traversal guidance in APA 7 format.

Pattern redaction remains defense in depth and does not make hostile output safe for shell or workflow-command evaluation.

@coderabbitai

coderabbitai Bot commented Aug 4, 2026

Copy link
Copy Markdown

Review Change Stack

Warning

Review limit reached

@seonghobae, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 9 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 734b6003-bd60-4ac2-8147-092aa6d8b585

📥 Commits

Reviewing files that changed from the base of the PR and between f070c50 and fcd1695.

📒 Files selected for processing (22)
  • .github/workflows/codeql-pr.yml
  • .github/workflows/opencode-coverage-diagnostics-ci.yml
  • CHANGELOG.md
  • docs/doctoring/coverage-failure-diagnostics.md
  • docs/doctoring/coverage-native-fuzz-lock-boundary.md
  • docs/doctoring/strix-source-directory-boundary.md
  • docs/superpowers/plans/2026-08-05-coverage-native-fuzz-lock-boundary.md
  • docs/superpowers/specs/2026-08-05-coverage-native-fuzz-lock-boundary-design.md
  • requirements-opencode-python310-ci-hashes.txt
  • scripts/ci/coverage_failure_summary.py
  • scripts/ci/materialize_base_javascript_packages.py
  • scripts/ci/materialize_base_python_requirements.py
  • scripts/ci/sanitize_github_output_summary.py
  • scripts/ci/strix_model_utils.sh
  • tests/conftest.py
  • tests/test_control_plane_branch_writer_absence.py
  • tests/test_coverage_materializer_failure_diagnostics.py
  • tests/test_coverage_native_fuzz_lock_boundary.py
  • tests/test_javascript_coverage_gate_type_only.py
  • tests/test_sanitize_github_output_summary.py
  • tests/test_strix_dependency_security_floor.py
  • tests/test_strix_model_utils_source_dirs.py
📝 Walkthrough

Walkthrough

Materializer 진단 출력에 redaction과 제한된 GitHub Actions summary를 추가했다. 커버리지와 LLVM 19 검증을 강화하고, Strix 의존성·PR 스코프 규칙·CodeQL 액션을 갱신했다.

Changes

CI 진단 및 보안 강화

Layer / File(s) Summary
조기 redaction 복구 흐름
.github/workflows/one-shot-redact-materializer-diagnostics.yml, .github/workflows/repair-pr759-early-redaction.yml, docs/doctoring/...
두 materializer의 secret, URL 자격 증명, Authorization 값 redaction과 관련 회귀 검증을 일회성 복구 워크플로에 연결했다.
실패 진단 출력과 검증
scripts/ci/materialize_base_*.py, tests/test_coverage_materializer_failure_diagnostics.py, .github/workflows/opencode-coverage-diagnostics-ci.yml
GitHub Actions에 HTML 이스케이프 및 길이 제한이 적용된 coverage_summary 출력을 게시하고, 실패·로컬 실행·입력 탐색 동작을 검증한다.
커버리지 CI와 LLVM 도구체인
.github/workflows/opencode-coverage-diagnostics-ci.yml, .github/workflows/opencode-review-dispatch.yml, docs/doctoring/opencode-llvm-coverage-toolchain.md, tests/test_opencode_agent_contract.py
Python 호환성, 100% branch coverage, docstring, 컴파일을 검사하고 LLVM 19 실행 파일을 구성한다.
Strix 의존성 및 스코프 보안 기준
requirements-strix-ci*, scripts/ci/strix_quick_gate.sh, scripts/ci/test_strix_quick_gate.sh, tests/test_strix_dependency_security_floor.py
aiohttp, cryptography, pyopenssl 핀과 해시를 갱신하고 Rust 및 백엔드 지원 파일의 PR-head 스코프 테스트를 추가한다.
CodeQL 액션 갱신
.github/workflows/scheduled-security-scan.yml
CodeQL 초기화 및 분석 액션을 v4.37.4로 갱신한다.

Estimated code review effort: 5 (Critical) | ~120 minutes

Sequence Diagram(s)

sequenceDiagram
  participant Materializer
  participant Sanitizer
  participant GitHubActions
  participant CoverageTests
  Materializer->>Sanitizer: 실패 진단 전달
  Sanitizer->>Sanitizer: secret 및 인증 정보 redaction
  Sanitizer->>GitHubActions: coverage_summary 기록
  CoverageTests->>GitHubActions: 출력 내용 검증
Loading

Possibly related PRs

Suggested labels: dependencies, python

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 69.23% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed 제목은 커버리지 설정 실패 진단을 노출하는 핵심 변경을 명확하고 간결하게 설명합니다.
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/opencode-coverage-failure-diagnostics

Comment @coderabbitai help to get the list of available commands.

Comment thread .github/workflows/one-shot-fix-opencode-coverage-diagnostics.yml Fixed
@seonghobae
seonghobae marked this pull request as ready for review August 4, 2026 23:11
@seonghobae
seonghobae enabled auto-merge (squash) August 4, 2026 23:12

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Aug 4, 2026

Copy link
Copy Markdown
⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

Comment thread .github/workflows/one-shot-refresh-strix-security-lock.yml Fixed
@opencode-agent
opencode-agent Bot disabled auto-merge August 4, 2026 23:19

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Aug 4, 2026

Copy link
Copy Markdown
⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@seonghobae
seonghobae enabled auto-merge (squash) August 4, 2026 23:25
@seonghobae
seonghobae marked this pull request as draft August 4, 2026 23:29
auto-merge was automatically disabled August 4, 2026 23:29

Pull request was converted to draft

@seonghobae
seonghobae marked this pull request as ready for review August 4, 2026 23:30
@seonghobae
seonghobae enabled auto-merge (squash) August 4, 2026 23:30

Copy link
Copy Markdown
Contributor Author

@opencode-agent @cwl-noema-review exact-current-head review requested for 988e10f2be7099fdc14759ead74a635ea39e555b. All published current-head security and quality workflows are green; verify the failure-diagnostic trust boundary, regenerated Strix lock, 100% statement/branch coverage, and merge policy without weakening existing reviewer credentials.

Copy link
Copy Markdown
Contributor Author

@opencode-agent @cwl-noema-review Please perform an independent exact-current-head review of 988e10f2be7099fdc14759ead74a635ea39e555b. All current-head security, coverage-diagnostics, and supply-chain checks are successful; approve only if the review finds no actionable issue.

@seonghobae
seonghobae marked this pull request as draft August 5, 2026 00:02
auto-merge was automatically disabled August 5, 2026 00:02

Pull request was converted to draft

@seonghobae
seonghobae marked this pull request as ready for review August 5, 2026 00:03
@seonghobae
seonghobae enabled auto-merge (squash) August 5, 2026 00:03

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

Please review exact current head 0165ed71d645c947827fa0680b5888643df2b9a9. All exact-head security, Python quality, coverage-diagnostics, and Strix scope checks are successful; approve only if no actionable issue remains.

@coderabbitai

coderabbitai Bot commented Aug 5, 2026

Copy link
Copy Markdown

@seonghobae I will review exact head 0165ed71d645c947827fa0680b5888643df2b9a9. I will approve only if the review finds no actionable issue.

⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

Copy link
Copy Markdown
Contributor Author

@opencode-agent @cwl-noema-review Please independently review exact current head dc81bb88220b3d6f6826f3a8d029dacfca96a6bf after all exact-head checks complete. Verify the central coverage-evidence diagnostic path remains fail-closed while exposing the exact setup failure, HTML-escapes and bounds untrusted diagnostic text, preserves immutable trusted-base dependency materialization, includes Rust/Tauri files in bounded Strix scope, retains hash-locked Python supply-chain checks, and introduces no self-modifying or write-enabled one-shot workflow. Submit APPROVE only for this exact head when no blocker remains.

Copy link
Copy Markdown
Contributor Author

@opencode-agent @cwl-noema-review Please independently review exact current head dc81bb88220b3d6f6826f3a8d029dacfca96a6bf. OpenCode Coverage Diagnostics CI, Python Security, Security Scan, CodeQL PR, SAST Semgrep, Secret Scan, OSV-Scanner PR, Scorecard PR, and SBOM Generation all completed successfully on this exact head, and there are zero actionable unresolved review threads. Verify the complete twelve-file diff, including fail-closed coverage setup diagnostics, bounded and escaped error evidence, Strix review scope for Rust/Tauri boundaries, immutable action pins, hash-locked security dependencies, 100% production statement/branch coverage, 100% production docstrings, and unchanged approval/security gates. Submit APPROVE only if no blocker remains; do not reuse earlier-head evidence.

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

Review exact current head dc81bb88220b3d6f6826f3a8d029dacfca96a6bf. All exact-head CI and security workflows are successful and no unresolved thread remains. Report only still-actionable findings against this head.

@coderabbitai

coderabbitai Bot commented Aug 5, 2026

Copy link
Copy Markdown

@seonghobae I will review exact head dc81bb88220b3d6f6826f3a8d029dacfca96a6bf. I will report only findings that remain actionable on this head.

⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@coderabbitai

coderabbitai Bot commented Aug 6, 2026

Copy link
Copy Markdown

Your plan includes PR reviews subject to rate limits. More reviews will be available in 9 minutes.

Copy link
Copy Markdown
Contributor Author

@opencode-agent @cwl-noema-review @coderabbitai review

Please perform a fresh exact-head review of 95f8f8b751f7b90f13527e6568c7d1488fb9c8a3. Every direct exact-head diagnostics, trusted-uv, security, and supply-chain workflow is successful and all inline threads are resolved. Ignore predecessor-head request-changes and rate-limit notices; branch protection and qualifying independent approval remain mandatory.

@coderabbitai

coderabbitai Bot commented Aug 6, 2026

Copy link
Copy Markdown

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

repo='ContextualWisdomLab/.github'
pr='759'
base='f070c504c1cb06891b800d7ab0cf6ac7d3cf8eae'
head='95f8f8b751f7b90f13527e6568c7d1488fb9c8a3'

echo '== PR identity and live state =='
gh pr view "$pr" --repo "$repo" \
  --json headRefOid,baseRefOid,state,isDraft,mergeable,reviewDecision,statusCheckRollup \
  --jq '{
    headRefOid, baseRefOid, state, isDraft, mergeable, reviewDecision,
    nonSuccess: [
      .statusCheckRollup[]
      | select(.name != null and (.status != "COMPLETED" or
        (.conclusion != "SUCCESS" and .conclusion != "SKIPPED" and .conclusion != "NEUTRAL")))
      | {name,status,conclusion,detailsUrl}
    ]
  }'

echo '== Revision relation and changed paths =='
printf 'checked_out='; git rev-parse HEAD
printf 'head='; git rev-parse "$head"
printf 'base='; git rev-parse "$base"
printf 'merge_base='; git merge-base "$base" "$head"
git merge-base --is-ancestor "$base" "$head" && echo 'base_is_ancestor=yes'
git diff --check "$base" "$head" && echo 'diff_check=OK'
git diff --name-status "$base" "$head"

echo '== Current unresolved threads =='
gh api graphql -F owner='ContextualWisdomLab' -F name='.github' -F number="$pr" -f query='
query($owner:String!, $name:String!, $number:Int!) {
  repository(owner:$owner,name:$name) {
    pullRequest(number:$number) {
      reviewThreads(first:100) { nodes { isResolved isOutdated path line } }
    }
  }
}' --jq '[.data.repository.pullRequest.reviewThreads.nodes[]
  | select(.isResolved == false and .isOutdated == false)]'

echo '== Changed-source structure =='
git diff --diff-filter=ACMR --name-only "$base" "$head" |
while IFS= read -r path; do
  case "$path" in
    *.py|*.sh)
      echo "--- $path"
      ast-grep outline "$path" --items all 2>/dev/null || true
      ;;
  esac
done

echo '== Diagnostics source and tests =='
for path in \
  scripts/ci/sanitize_github_output_summary.py \
  scripts/ci/coverage_failure_summary.py \
  scripts/ci/materialize_base_javascript_packages.py \
  scripts/ci/materialize_base_python_requirements.py \
  tests/test_sanitize_github_output_summary.py \
  tests/test_coverage_materializer_failure_diagnostics.py
do
  if git cat-file -e "$head:$path" 2>/dev/null; then
    echo "--- $path"
    git show "$head:$path" | nl -ba | sed -n '1,560p'
  fi
done

echo '== Full current diff =='
git diff --no-ext-diff --find-renames --unified=10 "$base" "$head" -- \
  scripts/ci .github/workflows tests requirements-opencode-python310-ci-hashes.txt \
  requirements-strix-ci.txt requirements-strix-ci-hashes.txt docs/doctoring \
  | sed -n '1,9000p'

echo '== Workflow writer and transient-artifact inventory =='
python3 - "$base" "$head" <<'PY'
from __future__ import annotations
import re
import subprocess
import sys

base, head = sys.argv[1:]
workflows = subprocess.check_output(
    ["git", "diff", "--name-only", base, head, "--", ".github/workflows"],
    text=True,
).splitlines()
signals = (
    "contents: write", "pull-requests: write", "issues: write", "id-token: write",
    "git push", "gh pr merge", "gh pr review", "workflow_dispatch:", "repository_dispatch:",
)
for path in workflows:
    text = subprocess.check_output(["git", "show", f"{head}:{path}"], text=True)
    matches = [
        f"{n}:{line}" for n, line in enumerate(text.splitlines(), 1)
        if "permissions:" in line or any(signal in line for signal in signals)
    ]
    print(f"--- {path}")
    print("\n".join(matches) if matches else "no matched write or dispatch signal")

paths = subprocess.check_output(
    ["git", "ls-tree", "-r", "--name-only", head], text=True,
).splitlines()
artifact = re.compile(
    r"(^|/)(one-shot[^/]*|repair[^/]*|[^/]*redact-materializer[^/]*|"
    r"apply[-_][^/]*|[^/]*encoded[^/]*patch[^/]*)($|/)", re.I,
)
matches = [path for path in paths if artifact.search(path)]
print("artifact_matches=" + (",".join(matches) if matches else "none"))
PY

echo '== Current workflow, lock, and policy contracts =='
for path in \
  .github/workflows/opencode-coverage-diagnostics-ci.yml \
  .github/workflows/trusted-uv-materializer-quality-ci.yml \
  scripts/ci/strix_model_utils.sh \
  scripts/ci/strix_quick_gate.sh \
  tests/test_strix_model_utils_source_dirs.py \
  tests/test_control_plane_branch_writer_absence.py \
  tests/test_coverage_native_fuzz_lock_boundary.py \
  requirements-opencode-python310-ci-hashes.txt
do
  if git cat-file -e "$head:$path" 2>/dev/null; then
    echo "--- $path"
    git show "$head:$path" | nl -ba | sed -n '1,520p'
  fi
done

echo '== Main branch protection and rulesets, if authorized =='
set +e
gh api "repos/$repo/branches/main/protection" \
  --jq '{required_pull_request_reviews,required_status_checks,required_linear_history,required_conversation_resolution,enforce_admins}'
echo "branch_protection_exit=$?"
gh api "repos/$repo/rulesets" \
  --jq '[.[] | {id,name,enforcement,target,conditions,rules,bypass_actors}]'
echo "rulesets_exit=$?"

Length of output: 15324


🏁 Script executed:

#!/bin/bash
set -euo pipefail

repo='ContextualWisdomLab/.github'
pr='759'
base='f070c504c1cb06891b800d7ab0cf6ac7d3cf8eae'
head='95f8f8b751f7b90f13527e6568c7d1488fb9c8a3'

print_object() {
  local path="$1"
  echo "--- $path"
  git show "$head:$path" | python3 -c '
import sys
for number, line in enumerate(sys.stdin, 1):
    print(f"{number:4}: {line}", end="")
'
}

echo '== Sanitizer, publisher, materializer handlers, and regression tests =='
for path in \
  scripts/ci/sanitize_github_output_summary.py \
  scripts/ci/coverage_failure_summary.py \
  scripts/ci/materialize_base_javascript_packages.py \
  scripts/ci/materialize_base_python_requirements.py \
  tests/test_sanitize_github_output_summary.py \
  tests/test_coverage_materializer_failure_diagnostics.py
do
  print_object "$path"
done

echo '== Exact-head workflow and Strix contracts =='
for path in \
  .github/workflows/opencode-coverage-diagnostics-ci.yml \
  .github/workflows/codeql-pr.yml \
  scripts/ci/strix_model_utils.sh \
  scripts/ci/strix_quick_gate.sh \
  tests/test_strix_model_utils_source_dirs.py \
  tests/test_control_plane_branch_writer_absence.py \
  tests/test_coverage_native_fuzz_lock_boundary.py \
  requirements-opencode-python310-ci-hashes.txt
do
  if git cat-file -e "$head:$path" 2>/dev/null; then
    print_object "$path"
  fi
done

echo '== Changed workflow permissions and mutation signals =='
python3 - "$base" "$head" <<'PY'
from __future__ import annotations
import subprocess
import sys

base, head = sys.argv[1:]
paths = subprocess.check_output(
    ["git", "diff", "--name-only", base, head, "--", ".github/workflows"],
    text=True,
).splitlines()
signals = (
    "contents: write", "pull-requests: write", "issues: write", "id-token: write",
    "git push", "gh pr merge", "gh pr review", "workflow_dispatch:", "repository_dispatch:",
)
for path in paths:
    body = subprocess.check_output(["git", "show", f"{head}:{path}"], text=True)
    print(f"--- {path}")
    found = False
    for number, line in enumerate(body.splitlines(), 1):
        if "permissions:" in line or any(item in line for item in signals):
            print(f"{number}: {line}")
            found = True
    if not found:
        print("no matched write or dispatch signal")
PY

echo '== Current-tree transient artifact inventory =='
python3 - "$head" <<'PY'
from __future__ import annotations
import re
import subprocess
import sys

paths = subprocess.check_output(
    ["git", "ls-tree", "-r", "--name-only", sys.argv[1]], text=True,
).splitlines()
pattern = re.compile(
    r"(^|/)(one-shot[^/]*|repair[^/]*|[^/]*redact-materializer[^/]*|"
    r"apply[-_][^/]*|[^/]*encoded[^/]*patch[^/]*)($|/)", re.I,
)
matches = [path for path in paths if pattern.search(path)]
print("\n".join(matches) if matches else "none")
PY

echo '== Focused source and test diff =='
git diff --no-ext-diff --unified=12 "$base" "$head" -- \
  scripts/ci/sanitize_github_output_summary.py \
  scripts/ci/coverage_failure_summary.py \
  scripts/ci/materialize_base_javascript_packages.py \
  scripts/ci/materialize_base_python_requirements.py \
  tests/test_sanitize_github_output_summary.py \
  tests/test_coverage_materializer_failure_diagnostics.py

echo '== Branch policy, if authorized =='
set +e
gh api "repos/$repo/branches/main/protection" \
  --jq '{required_pull_request_reviews,required_status_checks,required_linear_history,required_conversation_resolution,enforce_admins}'
echo "branch_protection_exit=$?"
gh api "repos/$repo/rulesets" \
  --jq '[.[] | {id,name,enforcement,target,conditions,rules,bypass_actors}]'
echo "rulesets_exit=$?"

Length of output: 98683


🏁 Script executed:

#!/bin/bash
set -euo pipefail

head='95f8f8b751f7b90f13527e6568c7d1488fb9c8a3'

for path in \
  scripts/ci/sanitize_github_output_summary.py \
  scripts/ci/coverage_failure_summary.py \
  tests/test_sanitize_github_output_summary.py \
  tests/test_coverage_materializer_failure_diagnostics.py
do
  echo "--- $path"
  git show "$head:$path" | head -n 180
done

Length of output: 13052


@seonghobae I reviewed exact head 95f8f8b751f7b90f13527e6568c7d1488fb9c8a3 against base f070c504c1cb06891b800d7ab0cf6ac7d3cf8eae.

I found one current-head blocker. I cannot approve this head.

P1 — Redact every Authorization header value

In scripts/ci/sanitize_github_output_summary.py, Line 19, AUTH_HEADER_RE only accepts Bearer and Basic schemes:

AUTH_HEADER_RE = re.compile(r"(?i)\b(Authorization\s*[:=]\s*)(Bearer|Basic)\s+[^\s,;]+")

publish_coverage_failure_summary() calls sanitize_text() before it writes caught materializer exceptions to GITHUB_OUTPUT.

These valid header values do not match the expression:

Authorization: Token secret-value
Authorization: Digest secret-value

SECRET_KEY_RE does not redact either value. The scheme is followed by whitespace, not : or =. The credential can therefore reach coverage_summary.

Redact the complete value after every Authorization: or Authorization= prefix. Do not depend on an allowlist of schemes. Add regression coverage for Token and Digest in:

  • tests/test_sanitize_github_output_summary.py
  • The parameterized JavaScript and Python materializer test in tests/test_coverage_materializer_failure_diagnostics.py

Keep the existing bounds, HTML escaping, delimiter protection, and nonzero materializer failure status.

I independently verified the requested head and base relationship, clean diff check, successful live check rollup, and zero unresolved current review threads.

You are interacting with an AI system.

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

@opencode-agent @cwl-noema-review Independently review exact current head 95f8f8b751f7b90f13527e6568c7d1488fb9c8a3 against protected main at f070c504c1cb06891b800d7ab0cf6ac7d3cf8eae. Every direct exact-head workflow is successful, including OpenCode Coverage Diagnostics CI, Trusted uv Materializer Quality CI, Python Security, Security Scan, CodeQL, Semgrep, Secret Scan, OSV, Scorecard, and SBOM. All inline threads are resolved and the final tree contains no branch-local repair workflow or patch payload.

Review the bounded diagnostic redaction and GITHUB_OUTPUT failure semantics, Python 3.10 tomli compatibility, exact-head checkout, native-fuzz-lock exclusion, trusted source and credential boundaries, Strix direct-child source-directory validation, permanent branch-writer absence contract, and preservation of protected-main Git isolation and NVIDIA NIM fallback behavior. Submit actionable current-head findings or a formal exact-head verdict; do not reuse predecessor-head request-changes reviews or rate-limit notices.

@coderabbitai

coderabbitai Bot commented Aug 6, 2026

Copy link
Copy Markdown

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

repo='ContextualWisdomLab/.github'
pr='759'
base='f070c504c1cb06891b800d7ab0cf6ac7d3cf8eae'
head='95f8f8b751f7b90f13527e6568c7d1488fb9c8a3'

echo '== Exact PR state =='
gh pr view "$pr" --repo "$repo" \
  --json headRefOid,baseRefOid,state,isDraft,mergeable,reviewDecision,statusCheckRollup \
  --jq '{
    headRefOid, baseRefOid, state, isDraft, mergeable, reviewDecision,
    nonSuccess: [
      .statusCheckRollup[]
      | select(.name != null and (.status != "COMPLETED" or
        (.conclusion != "SUCCESS" and .conclusion != "SKIPPED" and .conclusion != "NEUTRAL")))
      | {name,status,conclusion,detailsUrl}
    ]
  }'

echo '== Revision relation and changed paths =='
printf 'head='; git rev-parse "$head"
printf 'base='; git rev-parse "$base"
printf 'merge_base='; git merge-base "$base" "$head"
git merge-base --is-ancestor "$base" "$head" && echo 'base_is_ancestor=yes'
git diff --check "$base" "$head"
echo 'diff_check=OK'
git diff --name-status "$base" "$head"

echo '== Unresolved current review threads =='
gh api graphql -F owner='ContextualWisdomLab' -F name='.github' -F number="$pr" -f query='
query($owner:String!, $name:String!, $number:Int!) {
  repository(owner:$owner,name:$name) {
    pullRequest(number:$number) {
      reviewThreads(first:100) { nodes { isResolved isOutdated path line } }
    }
  }
}' --jq '[.data.repository.pullRequest.reviewThreads.nodes[]
  | select(.isResolved == false and .isOutdated == false)]'

echo '== Changed Python and shell structure =='
git diff --diff-filter=ACMR --name-only "$base" "$head" |
while IFS= read -r path; do
  case "$path" in
    *.py|*.sh)
      echo "--- $path"
      ast-grep outline "$path" --items all 2>/dev/null | head -120 || true
      ;;
  esac
done

echo '== Sanitizer, publisher, materializers, and tests =='
for path in \
  scripts/ci/sanitize_github_output_summary.py \
  scripts/ci/coverage_failure_summary.py \
  scripts/ci/materialize_base_javascript_packages.py \
  scripts/ci/materialize_base_python_requirements.py \
  tests/test_sanitize_github_output_summary.py \
  tests/test_coverage_materializer_failure_diagnostics.py
do
  if git cat-file -e "$head:$path" 2>/dev/null; then
    echo "--- $path"
    git show "$head:$path" | sed -n '1,560p'
  fi
done

echo '== Workflows and boundary contracts =='
for path in \
  .github/workflows/opencode-coverage-diagnostics-ci.yml \
  .github/workflows/trusted-uv-materializer-quality-ci.yml \
  .github/workflows/codeql-pr.yml \
  scripts/ci/strix_model_utils.sh \
  scripts/ci/strix_quick_gate.sh \
  tests/test_strix_model_utils_source_dirs.py \
  tests/test_control_plane_branch_writer_absence.py \
  tests/test_coverage_native_fuzz_lock_boundary.py \
  requirements-opencode-python310-ci-hashes.txt
do
  if git cat-file -e "$head:$path" 2>/dev/null; then
    echo "--- $path"
    git show "$head:$path" | sed -n '1,560p'
  fi
done

echo '== Complete exact diff =='
git diff --no-ext-diff --find-renames --unified=10 "$base" "$head" -- \
  scripts/ci .github/workflows tests \
  requirements-opencode-python310-ci-hashes.txt \
  requirements-strix-ci.txt requirements-strix-ci-hashes.txt \
  docs/doctoring | sed -n '1,9000p'

echo '== Changed-workflow write and transient-artifact inventory =='
python3 - "$base" "$head" <<'PY'
from __future__ import annotations
import re
import subprocess
import sys

base, head = sys.argv[1:]
workflow_paths = subprocess.check_output(
    ["git", "diff", "--name-only", base, head, "--", ".github/workflows"],
    text=True,
).splitlines()
signals = (
    "contents: write", "pull-requests: write", "issues: write", "id-token: write",
    "git push", "gh pr merge", "gh pr review", "workflow_dispatch:", "repository_dispatch:",
)
for path in workflow_paths:
    body = subprocess.check_output(["git", "show", f"{head}:{path}"], text=True)
    found = [
        f"{index}:{line}" for index, line in enumerate(body.splitlines(), 1)
        if "permissions:" in line or any(signal in line for signal in signals)
    ]
    print(f"--- {path}")
    print("\n".join(found) if found else "no matched write or dispatch signal")

tree_paths = subprocess.check_output(
    ["git", "ls-tree", "-r", "--name-only", head], text=True
).splitlines()
artifact_re = re.compile(
    r"(^|/)(one-shot[^/]*|repair[^/]*|[^/]*redact-materializer[^/]*|"
    r"apply[-_][^/]*|[^/]*encoded[^/]*patch[^/]*)($|/)",
    re.IGNORECASE,
)
matches = [path for path in tree_paths if artifact_re.search(path)]
print("artifact_matches=" + (",".join(matches) if matches else "none"))
PY

echo '== Static syntax for changed CI sources =='
git diff --diff-filter=ACMR --name-only "$base" "$head" -- scripts/ci |
while IFS= read -r path; do
  case "$path" in
    *.py)
      git show "$head:$path" | python3 -c \
        'import ast,sys; ast.parse(sys.stdin.read(), filename=sys.argv[1])' "$path"
      echo "python_ast=OK $path"
      ;;
    *.sh)
      temp_file="$(mktemp)"
      git show "$head:$path" > "$temp_file"
      bash -n "$temp_file"
      rm -f "$temp_file"
      echo "bash_syntax=OK $path"
      ;;
  esac
done

Length of output: 196048


@seonghobae I reviewed exact head 95f8f8b751f7b90f13527e6568c7d1488fb9c8a3 against base f070c504c1cb06891b800d7ab0cf6ac7d3cf8eae.

I found one current-head blocker. I cannot approve this pull request.

P1 — Redact every Authorization header value

scripts/ci/sanitize_github_output_summary.py, Line 19, limits AUTH_HEADER_RE to Bearer and Basic:

AUTH_HEADER_RE = re.compile(r"(?i)\b(Authorization\s*[:=]\s*)(Bearer|Basic)\s+[^\s,;]+")

Both materializers send caught exception text to publish_coverage_failure_summary(). The publisher sanitizes the text and writes it to GITHUB_OUTPUT.

The following valid header values do not match this expression:

Authorization: Token secret-value
Authorization: Digest secret-value

SECRET_KEY_RE does not redact these values. The authorization value can reach coverage_summary.

Redact the complete value after every Authorization: or Authorization= prefix. Do not restrict redaction to an allowlist of schemes. Add regression cases for Token and Digest in:

  • tests/test_sanitize_github_output_summary.py
  • The parameterized materializer publication test in tests/test_coverage_materializer_failure_diagnostics.py

Keep the existing bounded output, HTML escaping, delimiter protection, and nonzero materializer failure status.

I also verified the requested head and base relationship, git diff --check, the successful live check rollup, and zero unresolved current review threads.

You are interacting with an AI system.

Copy link
Copy Markdown
Contributor Author

@coderabbitai review
@cwl-noema-review
@opencode-agent

Re-review exact current head 95f8f8b751f7b90f13527e6568c7d1488fb9c8a3 against protected main. Verify the bounded diagnostics sanitizer, Python 3.10/3.14 execution, direct-child Strix source-directory validation, permanent trigger coverage, branch-writer absence contract, restored protected-main Git/NVIDIA boundaries, and zero transient repair artifacts. Review only; do not approve, merge, update branches, release, or mutate protection.

@coderabbitai

coderabbitai Bot commented Aug 6, 2026

Copy link
Copy Markdown

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

repo='ContextualWisdomLab/.github'
pr='759'
base='f070c504c1cb06891b800d7ab0cf6ac7d3cf8eae'
head='95f8f8b751f7b90f13527e6568c7d1488fb9c8a3'

echo '== Exact PR identity, status, and current threads =='
gh pr view "$pr" --repo "$repo" \
  --json headRefOid,baseRefOid,state,isDraft,mergeable,reviewDecision,statusCheckRollup \
  --jq '{
    headRefOid, baseRefOid, state, isDraft, mergeable, reviewDecision,
    nonSuccess: [.statusCheckRollup[]
      | select(.name != null and (.status != "COMPLETED" or
        (.conclusion != "SUCCESS" and .conclusion != "SKIPPED" and .conclusion != "NEUTRAL")))
      | {name,status,conclusion,detailsUrl}]
  }'
gh api graphql -F owner='ContextualWisdomLab' -F name='.github' -F number="$pr" -f query='
query($owner:String!, $name:String!, $number:Int!) {
  repository(owner:$owner,name:$name) {
    pullRequest(number:$number) {
      reviewThreads(first:100) { nodes { isResolved isOutdated path line } }
    }
  }
}' --jq '[.data.repository.pullRequest.reviewThreads.nodes[]
  | select(.isResolved == false and .isOutdated == false)]'

echo '== Revision relation and changed inventory =='
printf 'head='; git rev-parse "$head"
printf 'base='; git rev-parse "$base"
printf 'merge_base='; git merge-base "$base" "$head"
git merge-base --is-ancestor "$base" "$head" && echo 'base_is_ancestor=yes'
git diff --check "$base" "$head" && echo 'diff_check=OK'
git diff --name-status "$base" "$head"

echo '== Diagnostic sanitizer, publisher, materializer handlers, and tests =='
for path in \
  scripts/ci/sanitize_github_output_summary.py \
  scripts/ci/coverage_failure_summary.py \
  scripts/ci/materialize_base_javascript_packages.py \
  scripts/ci/materialize_base_python_requirements.py \
  tests/test_sanitize_github_output_summary.py \
  tests/test_coverage_materializer_failure_diagnostics.py
do
  echo "--- $path"
  git show "$head:$path" | nl -ba | sed -n '1,420p'
done

echo '== Workflow, Strix, and boundary contracts =='
for path in \
  .github/workflows/opencode-coverage-diagnostics-ci.yml \
  .github/workflows/trusted-uv-materializer-quality-ci.yml \
  scripts/ci/strix_model_utils.sh \
  scripts/ci/strix_quick_gate.sh \
  tests/test_strix_model_utils_source_dirs.py \
  tests/test_control_plane_branch_writer_absence.py \
  tests/test_coverage_native_fuzz_lock_boundary.py \
  requirements-opencode-python310-ci-hashes.txt
do
  if git cat-file -e "$head:$path" 2>/dev/null; then
    echo "--- $path"
    git show "$head:$path" | nl -ba | sed -n '1,520p'
  fi
done

echo '== Changed workflow permissions and mutation signals =='
python3 - "$base" "$head" <<'PY'
from __future__ import annotations
import subprocess
import sys

base, head = sys.argv[1:]
paths = subprocess.check_output(
    ["git", "diff", "--name-only", base, head, "--", ".github/workflows"],
    text=True,
).splitlines()
signals = (
    "contents: write", "pull-requests: write", "issues: write", "id-token: write",
    "git push", "gh pr merge", "gh pr review", "workflow_dispatch:", "repository_dispatch:",
)
for path in paths:
    text = subprocess.check_output(["git", "show", f"{head}:{path}"], text=True)
    matches = [
        f"{number}:{line}" for number, line in enumerate(text.splitlines(), 1)
        if "permissions:" in line or any(signal in line for signal in signals)
    ]
    print(f"--- {path}")
    print("\n".join(matches) if matches else "no matched write or dispatch signal")
PY

echo '== Transient artifact inventory =='
git ls-tree -r --name-only "$head" |
  grep -Ei '(^|/)(one-shot[^/]*|repair[^/]*|[^/]*redact-materializer[^/]*|apply[-_][^/]*|[^/]*encoded[^/]*patch[^/]*)($|/)' ||
  echo 'none'

echo '== Static syntax only =='
git diff --diff-filter=ACMR --name-only "$base" "$head" -- scripts/ci |
while IFS= read -r path; do
  case "$path" in
    *.py)
      git show "$head:$path" | python3 -c \
        'import ast,sys; ast.parse(sys.stdin.read(), filename=sys.argv[1])' "$path"
      echo "python_ast=OK $path"
      ;;
    *.sh)
      tmp="$(mktemp)"
      git show "$head:$path" > "$tmp"
      bash -n "$tmp"
      rm -f "$tmp"
      echo "bash_syntax=OK $path"
      ;;
  esac
done

echo '== Protected-main policy, when authorized =='
set +e
gh api "repos/$repo/branches/main/protection" \
  --jq '{required_pull_request_reviews,required_status_checks,required_linear_history,required_conversation_resolution,enforce_admins}'
echo "branch_protection_exit=$?"
gh api "repos/$repo/rulesets" \
  --jq '[.[] | {id,name,enforcement,target,rules,bypass_actors}]'
echo "rulesets_exit=$?"

Length of output: 6553


🏁 Script executed:

#!/bin/bash
set -euo pipefail

repo='ContextualWisdomLab/.github'
pr='759'
base='f070c504c1cb06891b800d7ab0cf6ac7d3cf8eae'
head='95f8f8b751f7b90f13527e6568c7d1488fb9c8a3'

show_numbered() {
  local path="$1"
  echo "--- $path"
  git show "$head:$path" | awk '{printf "%4d: %s\n", NR, $0}'
}

echo '== Diagnostics source and tests =='
for path in \
  scripts/ci/sanitize_github_output_summary.py \
  scripts/ci/coverage_failure_summary.py \
  scripts/ci/materialize_base_javascript_packages.py \
  scripts/ci/materialize_base_python_requirements.py \
  tests/test_sanitize_github_output_summary.py \
  tests/test_coverage_materializer_failure_diagnostics.py
do
  show_numbered "$path"
done

echo '== Workflow, Strix, and boundary contracts =='
for path in \
  .github/workflows/opencode-coverage-diagnostics-ci.yml \
  .github/workflows/trusted-uv-materializer-quality-ci.yml \
  scripts/ci/strix_model_utils.sh \
  scripts/ci/strix_quick_gate.sh \
  tests/test_strix_model_utils_source_dirs.py \
  tests/test_control_plane_branch_writer_absence.py \
  tests/test_coverage_native_fuzz_lock_boundary.py \
  requirements-opencode-python310-ci-hashes.txt
do
  if git cat-file -e "$head:$path" 2>/dev/null; then
    show_numbered "$path"
  fi
done

echo '== Changed workflow permissions, trigger paths, and mutation signals =='
while IFS= read -r path; do
  [ -n "$path" ] || continue
  echo "--- $path"
  git show "$head:$path" | awk '
    /permissions:|contents:|pull-requests:|issues:|id-token:|git push|gh pr (merge|review)|workflow_dispatch:|repository_dispatch:|pull_request:|paths:|paths-ignore:/ {
      printf "%4d: %s\n", NR, $0
    }'
done < <(git diff --name-only "$base" "$head" -- .github/workflows)

echo '== Current-tree transient artifact inventory =='
git ls-tree -r --name-only "$head" |
  grep -Ei '(^|/)(one-shot[^/]*|repair[^/]*|[^/]*redact-materializer[^/]*|apply[-_][^/]*|[^/]*encoded[^/]*patch[^/]*)($|/)' ||
  echo 'none'

echo '== Static parse checks =='
for path in scripts/ci/coverage_failure_summary.py \
            scripts/ci/materialize_base_javascript_packages.py \
            scripts/ci/materialize_base_python_requirements.py \
            scripts/ci/sanitize_github_output_summary.py; do
  git show "$head:$path" | python3 -c \
    'import ast,sys; ast.parse(sys.stdin.read(), filename=sys.argv[1])' "$path"
  echo "python_ast=OK $path"
done
tmp="$(mktemp)"
git show "$head:scripts/ci/strix_model_utils.sh" > "$tmp"
bash -n "$tmp"
rm -f "$tmp"
echo 'bash_syntax=OK scripts/ci/strix_model_utils.sh'

echo '== Protected-main policy =='
set +e
gh api "repos/$repo/branches/main/protection" \
  --jq '{required_pull_request_reviews,required_status_checks,required_linear_history,required_conversation_resolution,enforce_admins}'
echo "branch_protection_exit=$?"
gh api "repos/$repo/rulesets" \
  --jq '[.[] | {id,name,enforcement,target,rules,bypass_actors}]'
echo "rulesets_exit=$?"

Length of output: 97851


🏁 Script executed:

#!/bin/bash
set -euo pipefail

base='f070c504c1cb06891b800d7ab0cf6ac7d3cf8eae'
head='95f8f8b751f7b90f13527e6568c7d1488fb9c8a3'

echo '== Sanitizer and publisher =='
for path in scripts/ci/sanitize_github_output_summary.py scripts/ci/coverage_failure_summary.py; do
  echo "--- $path"
  git show "$head:$path" | sed -n '1,260p'
done

echo '== Materializer exception publication paths =='
for path in scripts/ci/materialize_base_javascript_packages.py scripts/ci/materialize_base_python_requirements.py; do
  echo "--- $path"
  git show "$head:$path" |
    grep -n -E -C 18 'publish_coverage_failure_summary|except Exception|GITHUB_OUTPUT|return 1|def main' || true
done

echo '== Sanitizer and materializer diagnostics test cases =='
for path in tests/test_sanitize_github_output_summary.py tests/test_coverage_materializer_failure_diagnostics.py; do
  echo "--- $path"
  git show "$head:$path" |
    grep -n -E -C 12 'Authorization|Bearer|Basic|Token|Digest|coverage_summary|redact|sanitize|parametrize' || true
done

echo '== Coverage workflow triggers, checkout, compatibility, and quality gates =='
git show "$head:.github/workflows/opencode-coverage-diagnostics-ci.yml" |
  grep -n -E -C 4 '^(on:|  pull_request:|  push:|[[:space:]]+paths:|[[:space:]]+- ")|permissions:|contents:|actions/checkout|persist-credentials|ref:|python-version|requirements-opencode-python310|--require-hashes|--cov-branch|fail-under=100|interrogate' || true

echo '== Changed workflow permissions and mutation terms =='
git diff --name-only "$base" "$head" -- .github/workflows > /tmp/pr759-workflows
while IFS= read -r path; do
  [ -n "$path" ] || continue
  echo "--- $path"
  git show "$head:$path" |
    grep -n -E 'permissions:|contents: write|pull-requests: write|issues: write|id-token: write|git push|gh pr (merge|review)|workflow_dispatch:|repository_dispatch:' || true
done < /tmp/pr759-workflows
rm -f /tmp/pr759-workflows

echo '== Artifact inventory =='
git ls-tree -r --name-only "$head" |
  grep -Ei '(^|/)(one-shot[^/]*|repair[^/]*|[^/]*redact-materializer[^/]*|apply[-_][^/]*|[^/]*encoded[^/]*patch[^/]*)($|/)' ||
  echo 'none'

echo '== Strix direct-child validator =='
git show "$head:scripts/ci/strix_model_utils.sh" |
  grep -n -E -C 30 'sanitize_strix_source_dirs|STRIX_SOURCE_DIRS' || true

echo '== Static syntax =='
for path in scripts/ci/coverage_failure_summary.py \
            scripts/ci/materialize_base_javascript_packages.py \
            scripts/ci/materialize_base_python_requirements.py \
            scripts/ci/sanitize_github_output_summary.py; do
  git show "$head:$path" | python3 -c \
    'import ast,sys; ast.parse(sys.stdin.read(), filename=sys.argv[1])' "$path"
  echo "python_ast=OK $path"
done
tmp="$(mktemp)"
git show "$head:scripts/ci/strix_model_utils.sh" > "$tmp"
bash -n "$tmp"
rm -f "$tmp"
echo 'bash_syntax=OK scripts/ci/strix_model_utils.sh'

Length of output: 33294


@seonghobae I reviewed exact head 95f8f8b751f7b90f13527e6568c7d1488fb9c8a3 against protected base f070c504c1cb06891b800d7ab0cf6ac7d3cf8eae.

I found one current-head blocker. I did not approve or modify the pull request.

P1 — Redact all Authorization header values

scripts/ci/sanitize_github_output_summary.py, Line 19, limits AUTH_HEADER_RE to Bearer and Basic:

AUTH_HEADER_RE = re.compile(r"(?i)\b(Authorization\s*[:=]\s*)(Bearer|Basic)\s+[^\s,;]+")

Both materializers pass caught exceptions to publish_coverage_failure_summary(). The publisher calls sanitize_text() before it writes coverage_summary to GITHUB_OUTPUT.

The current pattern does not redact these valid header forms:

Authorization: Token secret-value
Authorization: Digest secret-value

SECRET_KEY_RE does not redact these values. The scheme is followed by whitespace, not : or =. A credential can therefore reach the published workflow output.

Redact the complete value after every Authorization: or Authorization= prefix. Do not restrict the rule to selected schemes. Add regression cases for Token and Digest in:

  • tests/test_sanitize_github_output_summary.py
  • The parameterized materializer diagnostic test in tests/test_coverage_materializer_failure_diagnostics.py

Keep the existing output bounds, HTML escaping, delimiter protection, and nonzero materializer status.

I also verified these current-head conditions:

  • The active PR head matches the requested SHA.
  • The requested base is the merge base and an ancestor.
  • git diff --check passed.
  • The live check rollup has no failed or pending check.
  • No unresolved current review thread exists.
  • The workflow uses exact-head checkout and persist-credentials: false.
  • The workflow includes hash-locked Python 3.10 tomli and Python 3.14 coverage and docstring gates.
  • The Strix validator restricts STRIX_SOURCE_DIRS to safe direct-child names and makes it readonly.
  • No inspected transient repair artifact exists.
  • The inspected changed Python files parse successfully. The Strix shell helper passes bash -n.

You are interacting with an AI system.

@seonghobae seonghobae assigned seonghobae and unassigned seonghobae Aug 6, 2026

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Current exact head e151a1044e9a88b708c5628190da598a4203cfd6 has successful diagnostics, trusted-uv, Python Security, Security Scan, Semgrep, Secret Scan, OSV, Scorecard, SBOM, and CodeRabbit status; CodeQL is still running. All inline threads are resolved and prior OpenCode change requests are predecessor-head evidence only. Requesting fresh current-head independent review; no branch update or merge bypass.

Copy link
Copy Markdown
Contributor Author

@opencode-agent @cwl-noema-review @coderabbitai review

Please review exact head e151a1044e9a88b708c5628190da598a4203cfd6 against base f070c504c1cb06891b800d7ab0cf6ac7d3cf8eae. The scheme-specific Authorization redaction blocker was repaired test-first: all Authorization values are now redacted regardless of scheme while preserving the original field separator. Every direct exact-head workflow has completed successfully, including Python 3.10/3.14 quality and 100% statement/branch/docstring evidence, trusted uv materializer quality, Python Security, Security Scan, CodeQL, Semgrep, Secret Scan, OSV, Scorecard, and SBOM. Do not reuse predecessor-head review or approval evidence. Submit a current-head verdict and identify any remaining actionable finding; an independent non-author approval remains required for merge.

@opencode-agent
opencode-agent Bot disabled auto-merge August 6, 2026 06:26

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@opencode-agent

Review-only exact-head request for e151a1044e9a88b708c5628190da598a4203cfd6. Do not update branches, approve from author identity, or merge. Re-evaluate bounded failure diagnostics, credential redaction, exact-head evidence, Strix source-directory confinement, tests, 100% branch coverage, and production docstrings after CodeQL completes.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@cwl-noema-review

Independently review exact head e151a1044e9a88b708c5628190da598a4203cfd6. Validate the security and evidence boundary only; do not mutate the branch or merge.

@seonghobae
seonghobae enabled auto-merge (squash) August 6, 2026 06:27
@coderabbitai

coderabbitai Bot commented Aug 6, 2026

Copy link
Copy Markdown

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

repo='ContextualWisdomLab/.github'
pr='759'
base='f070c504c1cb06891b800d7ab0cf6ac7d3cf8eae'
head='e151a1044e9a88b708c5628190da598a4203cfd6'

echo '== Pull request identity, check state, and unresolved threads =='
gh pr view "$pr" --repo "$repo" \
  --json headRefOid,baseRefOid,state,isDraft,mergeable,reviewDecision,statusCheckRollup \
  --jq '{
    headRefOid, baseRefOid, state, isDraft, mergeable, reviewDecision,
    nonSuccess: [
      .statusCheckRollup[]
      | select(.name != null and (.status != "COMPLETED" or
          (.conclusion != "SUCCESS" and .conclusion != "SKIPPED" and .conclusion != "NEUTRAL")))
      | {name,status,conclusion,detailsUrl}
    ]
  }'
gh api graphql -F owner='ContextualWisdomLab' -F name='.github' -F number="$pr" -f query='
query($owner:String!, $name:String!, $number:Int!) {
  repository(owner:$owner,name:$name) {
    pullRequest(number:$number) {
      reviewThreads(first:100) { nodes { isResolved isOutdated path line } }
    }
  }
}' --jq '[.data.repository.pullRequest.reviewThreads.nodes[]
  | select(.isResolved == false and .isOutdated == false)]'

echo '== Exact revision relation and changed files =='
printf 'checked_out='; git rev-parse HEAD
printf 'head='; git rev-parse "$head"
printf 'base='; git rev-parse "$base"
printf 'merge_base='; git merge-base "$base" "$head"
git merge-base --is-ancestor "$base" "$head" && echo 'base_is_ancestor=yes'
git diff --check "$base" "$head"
echo 'diff_check=OK'
git diff --name-status "$base" "$head"

echo '== Changed source outlines =='
git diff --diff-filter=ACMR --name-only "$base" "$head" |
while IFS= read -r path; do
  case "$path" in
    *.py|*.sh)
      echo "--- $path"
      ast-grep outline "$path" --items all 2>/dev/null | head -120 || true
      ;;
  esac
done

echo '== Diagnostic sanitizer, publisher, materializers, and regression tests =='
for path in \
  scripts/ci/sanitize_github_output_summary.py \
  scripts/ci/coverage_failure_summary.py \
  scripts/ci/materialize_base_javascript_packages.py \
  scripts/ci/materialize_base_python_requirements.py \
  tests/test_sanitize_github_output_summary.py \
  tests/test_coverage_materializer_failure_diagnostics.py
do
  if git cat-file -e "$head:$path" 2>/dev/null; then
    echo "--- $path"
    git show "$head:$path" | nl -ba | sed -n '1,560p'
  fi
done

echo '== Full current diff =='
git diff --no-ext-diff --find-renames --unified=10 "$base" "$head" -- \
  scripts/ci .github/workflows tests \
  requirements-opencode-python310-ci-hashes.txt \
  requirements-strix-ci.txt requirements-strix-ci-hashes.txt \
  docs/doctoring | sed -n '1,9000p'

echo '== Workflow permissions, mutation signals, and transient artifacts =='
python3 - "$base" "$head" <<'PY'
from __future__ import annotations
import re
import subprocess
import sys

base, head = sys.argv[1:]
workflows = subprocess.check_output(
    ["git", "diff", "--name-only", base, head, "--", ".github/workflows"],
    text=True,
).splitlines()
signals = (
    "contents: write", "pull-requests: write", "issues: write", "id-token: write",
    "git push", "gh pr merge", "gh pr review", "workflow_dispatch:", "repository_dispatch:",
)
for path in workflows:
    body = subprocess.check_output(["git", "show", f"{head}:{path}"], text=True)
    found = [
        f"{number}:{line}" for number, line in enumerate(body.splitlines(), 1)
        if "permissions:" in line or any(signal in line for signal in signals)
    ]
    print(f"--- {path}")
    print("\n".join(found) if found else "no matched write or dispatch signal")

paths = subprocess.check_output(
    ["git", "ls-tree", "-r", "--name-only", head], text=True,
).splitlines()
artifact_re = re.compile(
    r"(^|/)(one-shot[^/]*|repair[^/]*|[^/]*redact-materializer[^/]*|"
    r"apply[-_][^/]*|[^/]*encoded[^/]*patch[^/]*)($|/)", re.IGNORECASE,
)
matches = [path for path in paths if artifact_re.search(path)]
print("artifact_matches=" + (",".join(matches) if matches else "none"))
PY

echo '== Coverage workflow and Strix boundary contracts =='
for path in \
  .github/workflows/opencode-coverage-diagnostics-ci.yml \
  .github/workflows/trusted-uv-materializer-quality-ci.yml \
  scripts/ci/strix_model_utils.sh \
  scripts/ci/strix_quick_gate.sh \
  tests/test_strix_model_utils_source_dirs.py \
  tests/test_control_plane_branch_writer_absence.py \
  tests/test_coverage_native_fuzz_lock_boundary.py \
  requirements-opencode-python310-ci-hashes.txt
do
  if git cat-file -e "$head:$path" 2>/dev/null; then
    echo "--- $path"
    git show "$head:$path" | nl -ba | sed -n '1,520p'
  fi
done

echo '== Static parse checks =='
git diff --diff-filter=ACMR --name-only "$base" "$head" -- scripts/ci |
while IFS= read -r path; do
  case "$path" in
    *.py)
      git show "$head:$path" | python3 -c \
        'import ast,sys; ast.parse(sys.stdin.read(), filename=sys.argv[1])' "$path"
      echo "python_ast=OK $path"
      ;;
    *.sh)
      temp_file="$(mktemp)"
      git show "$head:$path" > "$temp_file"
      bash -n "$temp_file"
      rm -f "$temp_file"
      echo "bash_syntax=OK $path"
      ;;
  esac
done

Length of output: 15932


🏁 Script executed:

#!/bin/bash
set -euo pipefail

repo='ContextualWisdomLab/.github'
pr='759'
base='f070c504c1cb06891b800d7ab0cf6ac7d3cf8eae'
head='e151a1044e9a88b708c5628190da598a4203cfd6'

show_numbered() {
  local path="$1"
  echo "--- $path"
  git show "$head:$path" | awk '{printf "%4d: %s\n", NR, $0}'
}

echo '== Repaired sanitizer and its test coverage =='
for path in \
  scripts/ci/sanitize_github_output_summary.py \
  scripts/ci/coverage_failure_summary.py \
  tests/test_sanitize_github_output_summary.py \
  tests/test_coverage_materializer_failure_diagnostics.py
do
  show_numbered "$path"
done

echo '== Materializer exception paths =='
for path in \
  scripts/ci/materialize_base_javascript_packages.py \
  scripts/ci/materialize_base_python_requirements.py
do
  echo "--- $path"
  git show "$head:$path" |
    grep -n -E -C 18 'publish_coverage_failure_summary|except Exception|GITHUB_OUTPUT|return 1|def main' || true
done

echo '== Exact source and test diff =='
git diff --no-ext-diff --unified=12 "$base" "$head" -- \
  scripts/ci/sanitize_github_output_summary.py \
  scripts/ci/coverage_failure_summary.py \
  scripts/ci/materialize_base_javascript_packages.py \
  scripts/ci/materialize_base_python_requirements.py \
  tests/test_sanitize_github_output_summary.py \
  tests/test_coverage_materializer_failure_diagnostics.py

echo '== Workflow and boundary contracts =='
for path in \
  .github/workflows/opencode-coverage-diagnostics-ci.yml \
  .github/workflows/trusted-uv-materializer-quality-ci.yml \
  scripts/ci/strix_model_utils.sh \
  scripts/ci/strix_quick_gate.sh \
  tests/test_strix_model_utils_source_dirs.py \
  tests/test_control_plane_branch_writer_absence.py \
  tests/test_coverage_native_fuzz_lock_boundary.py \
  requirements-opencode-python310-ci-hashes.txt
do
  if git cat-file -e "$head:$path" 2>/dev/null; then
    show_numbered "$path"
  fi
done

echo '== Changed workflow mutation signals and transient artifacts =='
python3 - "$base" "$head" <<'PY'
from __future__ import annotations
import re
import subprocess
import sys

base, head = sys.argv[1:]
workflow_paths = subprocess.check_output(
    ["git", "diff", "--name-only", base, head, "--", ".github/workflows"],
    text=True,
).splitlines()
signals = (
    "contents: write", "pull-requests: write", "issues: write", "id-token: write",
    "git push", "gh pr merge", "gh pr review", "workflow_dispatch:", "repository_dispatch:",
)
for path in workflow_paths:
    body = subprocess.check_output(["git", "show", f"{head}:{path}"], text=True)
    found = [
        f"{number}:{line}" for number, line in enumerate(body.splitlines(), 1)
        if "permissions:" in line or any(signal in line for signal in signals)
    ]
    print(f"--- {path}")
    print("\n".join(found) if found else "no matched write or dispatch signal")

paths = subprocess.check_output(
    ["git", "ls-tree", "-r", "--name-only", head], text=True,
).splitlines()
pattern = re.compile(
    r"(^|/)(one-shot[^/]*|repair[^/]*|[^/]*redact-materializer[^/]*|"
    r"apply[-_][^/]*|[^/]*encoded[^/]*patch[^/]*)($|/)", re.I,
)
matches = [path for path in paths if pattern.search(path)]
print("artifact_matches=" + (",".join(matches) if matches else "none"))
PY

echo '== Static syntax of changed CI source =='
git diff --diff-filter=ACMR --name-only "$base" "$head" -- scripts/ci |
while IFS= read -r path; do
  case "$path" in
    *.py)
      git show "$head:$path" | python3 -c \
        'import ast,sys; ast.parse(sys.stdin.read(), filename=sys.argv[1])' "$path"
      echo "python_ast=OK $path"
      ;;
    *.sh)
      temp_file="$(mktemp)"
      git show "$head:$path" > "$temp_file"
      bash -n "$temp_file"
      rm -f "$temp_file"
      echo "bash_syntax=OK $path"
      ;;
  esac
done

echo '== Current pull request check state =='
gh pr view "$pr" --repo "$repo" --json headRefOid,reviewDecision,statusCheckRollup \
  --jq '{
    headRefOid, reviewDecision,
    nonSuccess: [
      .statusCheckRollup[]
      | select(.name != null and (.status != "COMPLETED" or
          (.conclusion != "SUCCESS" and .conclusion != "SKIPPED" and .conclusion != "NEUTRAL")))
      | {name,status,conclusion,detailsUrl}
    ]
  }'

Length of output: 245108


🏁 Script executed:

#!/bin/bash
set -euo pipefail

repo='ContextualWisdomLab/.github'
pr='759'
head='e151a1044e9a88b708c5628190da598a4203cfd6'

echo '== Live exact-head status =='
gh pr view "$pr" --repo "$repo" \
  --json headRefOid,baseRefOid,state,isDraft,mergeable,reviewDecision,statusCheckRollup \
  --jq '{
    headRefOid, baseRefOid, state, isDraft, mergeable, reviewDecision,
    nonSuccess: [
      .statusCheckRollup[]
      | select(.name != null and (.status != "COMPLETED" or
          (.conclusion != "SUCCESS" and .conclusion != "SKIPPED" and .conclusion != "NEUTRAL")))
      | {name,status,conclusion,detailsUrl}
    ]
  }'

echo '== Unresolved current threads =='
gh api graphql -F owner='ContextualWisdomLab' -F name='.github' -F number="$pr" -f query='
query($owner:String!, $name:String!, $number:Int!) {
  repository(owner:$owner,name:$name) {
    pullRequest(number:$number) {
      reviewThreads(first:100) { nodes { isResolved isOutdated path line } }
    }
  }
}' --jq '[.data.repository.pullRequest.reviewThreads.nodes[]
  | select(.isResolved == false and .isOutdated == false)]'

echo '== Protected-main review requirement =='
gh api "repos/$repo/branches/main/protection" \
  --jq '{
    required_pull_request_reviews,
    required_status_checks,
    required_conversation_resolution,
    enforce_admins
  }'

echo '== Changed source syntax =='
for path in \
  scripts/ci/coverage_failure_summary.py \
  scripts/ci/materialize_base_javascript_packages.py \
  scripts/ci/materialize_base_python_requirements.py \
  scripts/ci/sanitize_github_output_summary.py
do
  git show "$head:$path" | python3 -c \
    'import ast,sys; ast.parse(sys.stdin.read(), filename=sys.argv[1])' "$path"
  echo "python_ast=OK $path"
done
temp_file="$(mktemp)"
git show "$head:scripts/ci/strix_model_utils.sh" > "$temp_file"
bash -n "$temp_file"
rm -f "$temp_file"
echo 'bash_syntax=OK scripts/ci/strix_model_utils.sh'

Length of output: 3085


@seonghobae I reviewed exact head e151a1044e9a88b708c5628190da598a4203cfd6 against base f070c504c1cb06891b800d7ab0cf6ac7d3cf8eae.

I found no new actionable source finding in the inspected changes.

The Authorization repair resolves the prior blocker:

  • AUTH_HEADER_RE now redacts every value after Authorization: or Authorization=.
  • The replacement preserves the original field separator.
  • The shared sanitizer test covers Token, Digest, AWS4, and scheme-less values.
  • Both materializers use the shared publisher before GITHUB_OUTPUT publication.
  • Both materializers preserve nonzero failure status.

I also verified that the active PR head matches the requested SHA, the base is the merge base and an ancestor, git diff --check passes, and no unresolved current review thread exists.

I cannot submit a completed current-head verdict yet. scan-pr-queue and strix are still in progress. The available GitHub token also cannot read protected-main branch protection because the API returned HTTP 403. The final static syntax check did not run because that API error stopped the verification script.

The remaining external gates are:

  1. Wait for scan-pr-queue and strix to complete successfully.
  2. Verify protected-main policy with credentials that can read branch protection.
  3. Obtain the required independent non-author approval.

You are interacting with an AI system.

Copy link
Copy Markdown
Contributor Author

@strix review

Perform a complete read-only security review of exact current head e151a1044e9a88b708c5628190da598a4203cfd6 against current main. Do not write to the branch, create a repair workflow or pull request, reuse predecessor-head evidence, or treat queued/infrastructure-only outcomes as success. Re-evaluate the credential-redaction, exact-head checkout, scanner filesystem, source-directory confinement, no-transient-workflow, coverage, docstring, and supply-chain boundaries; report actionable current-head findings only.

Copy link
Copy Markdown
Contributor Author

@opencode-agent @cwl-noema-review @coderabbitai review

Review the exact current head only. Revalidate fail-closed, redacted coverage diagnostics, Rust LLVM coverage toolchain compatibility, exact-head checkout, 100% changed production coverage/docstrings, and immutable security/action pins.

@coderabbitai

coderabbitai Bot commented Aug 6, 2026

Copy link
Copy Markdown
🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

repo='ContextualWisdomLab/.github'
pr='759'

echo '== Current PR identity, checks, and review threads =='
pr_json="$(gh pr view "$pr" --repo "$repo" \
  --json headRefOid,baseRefOid,state,isDraft,mergeable,reviewDecision,statusCheckRollup)"
printf '%s\n' "$pr_json" | jq '{
  headRefOid, baseRefOid, state, isDraft, mergeable, reviewDecision,
  nonSuccess: [
    .statusCheckRollup[]
    | select(.name != null and (.status != "COMPLETED" or
      (.conclusion != "SUCCESS" and .conclusion != "SKIPPED" and .conclusion != "NEUTRAL")))
    | {name,status,conclusion,detailsUrl}
  ]
}'
head="$(printf '%s\n' "$pr_json" | jq -r '.headRefOid')"
base="$(printf '%s\n' "$pr_json" | jq -r '.baseRefOid')"
echo "head=$head"
echo "base=$base"

gh api graphql -F owner='ContextualWisdomLab' -F name='.github' -F number="$pr" -f query='
query($owner:String!, $name:String!, $number:Int!) {
  repository(owner:$owner,name:$name) {
    pullRequest(number:$number) {
      reviewThreads(first:100) { nodes { isResolved isOutdated path line } }
    }
  }
}' --jq '[.data.repository.pullRequest.reviewThreads.nodes[]
  | select(.isResolved == false and .isOutdated == false)]'

echo '== Revision relation and changed paths =='
printf 'checked_out='; git rev-parse HEAD
printf 'head='; git rev-parse "$head"
printf 'base='; git rev-parse "$base"
printf 'merge_base='; git merge-base "$base" "$head"
git merge-base --is-ancestor "$base" "$head" && echo 'base_is_ancestor=yes'
git diff --check "$base" "$head" && echo 'diff_check=OK'
git diff --name-status "$base" "$head"

echo '== Requested source and workflow contracts at the active head =='
for path in \
  scripts/ci/sanitize_github_output_summary.py \
  scripts/ci/coverage_failure_summary.py \
  scripts/ci/materialize_base_javascript_packages.py \
  scripts/ci/materialize_base_python_requirements.py \
  scripts/ci/strix_model_utils.sh \
  .github/workflows/opencode-coverage-diagnostics-ci.yml \
  .github/workflows/opencode-review-dispatch.yml \
  .github/workflows/trusted-uv-materializer-quality-ci.yml \
  tests/test_sanitize_github_output_summary.py \
  tests/test_coverage_materializer_failure_diagnostics.py \
  tests/test_opencode_agent_contract.py \
  docs/doctoring/opencode-llvm-coverage-toolchain.md
do
  if git cat-file -e "$head:$path" 2>/dev/null; then
    echo "--- $path"
    git show "$head:$path" | nl -ba | sed -n '1,560p'
  fi
done

echo '== Exact changed diff for relevant paths =='
git diff --no-ext-diff --find-renames --unified=12 "$base" "$head" -- \
  scripts/ci .github/workflows tests docs/doctoring \
  requirements-opencode-python310-ci-hashes.txt \
  requirements-strix-ci.txt requirements-strix-ci-hashes.txt | sed -n '1,9000p'

echo '== Action pins and changed-workflow write signals =='
git grep -nE 'uses:[[:space:]]+[^[:space:]#]+@' "$head" -- .github/workflows || true
python3 - "$base" "$head" <<'PY'
from __future__ import annotations
import subprocess
import sys

base, head = sys.argv[1:]
paths = subprocess.check_output(
    ["git", "diff", "--name-only", base, head, "--", ".github/workflows"], text=True
).splitlines()
signals = (
    "contents: write", "pull-requests: write", "issues: write", "id-token: write",
    "git push", "gh pr merge", "gh pr review", "workflow_dispatch:", "repository_dispatch:",
)
for path in paths:
    body = subprocess.check_output(["git", "show", f"{head}:{path}"], text=True)
    found = [
        f"{number}:{line}" for number, line in enumerate(body.splitlines(), 1)
        if "permissions:" in line or any(signal in line for signal in signals)
    ]
    print(f"--- {path}")
    print("\n".join(found) if found else "no matched write or dispatch signal")
PY

echo '== Static syntax for changed CI source =='
git diff --diff-filter=ACMR --name-only "$base" "$head" -- scripts/ci |
while IFS= read -r path; do
  case "$path" in
    *.py)
      git show "$head:$path" | python3 -c \
        'import ast,sys; ast.parse(sys.stdin.read(), filename=sys.argv[1])' "$path"
      echo "python_ast=OK $path"
      ;;
    *.sh)
      temp_file="$(mktemp)"
      git show "$head:$path" > "$temp_file"
      bash -n "$temp_file"
      rm -f "$temp_file"
      echo "bash_syntax=OK $path"
      ;;
  esac
done

Length of output: 6615


🏁 Script executed:

#!/bin/bash
set -euo pipefail

repo='ContextualWisdomLab/.github'
pr='759'
base='f070c504c1cb06891b800d7ab0cf6ac7d3cf8eae'
head='e151a1044e9a88b708c5628190da598a4203cfd6'

show_numbered() {
  path="$1"
  echo "--- $path"
  git show "$head:$path" | awk '{printf "%4d: %s\n", NR, $0}'
}

echo '== Sanitizer, publisher, materializers, and diagnostic regression tests =='
for path in \
  scripts/ci/sanitize_github_output_summary.py \
  scripts/ci/coverage_failure_summary.py \
  scripts/ci/materialize_base_javascript_packages.py \
  scripts/ci/materialize_base_python_requirements.py \
  tests/test_sanitize_github_output_summary.py \
  tests/test_coverage_materializer_failure_diagnostics.py
do
  show_numbered "$path" | sed -n '1,580p'
done

echo '== LLVM toolchain workflow, contract test, and documentation =='
for path in \
  .github/workflows/opencode-review-dispatch.yml \
  tests/test_opencode_agent_contract.py \
  docs/doctoring/opencode-llvm-coverage-toolchain.md
do
  if git cat-file -e "$head:$path" 2>/dev/null; then
    show_numbered "$path" | sed -n '1,560p'
  fi
done

echo '== Exact-head checkout, Python quality gates, and immutable action references =='
for path in \
  .github/workflows/opencode-coverage-diagnostics-ci.yml \
  .github/workflows/trusted-uv-materializer-quality-ci.yml \
  .github/workflows/codeql-pr.yml \
  requirements-opencode-python310-ci-hashes.txt
do
  if git cat-file -e "$head:$path" 2>/dev/null; then
    show_numbered "$path" | sed -n '1,620p'
  fi
done

echo '== Relevant diff =='
git diff --no-ext-diff --unified=10 "$base" "$head" -- \
  scripts/ci/sanitize_github_output_summary.py \
  scripts/ci/coverage_failure_summary.py \
  scripts/ci/materialize_base_javascript_packages.py \
  scripts/ci/materialize_base_python_requirements.py \
  .github/workflows/opencode-coverage-diagnostics-ci.yml \
  .github/workflows/opencode-review-dispatch.yml \
  .github/workflows/codeql-pr.yml \
  tests/test_sanitize_github_output_summary.py \
  tests/test_coverage_materializer_failure_diagnostics.py \
  tests/test_opencode_agent_contract.py \
  docs/doctoring/opencode-llvm-coverage-toolchain.md | sed -n '1,7000p'

echo '== Action references with mutable-reference detection =='
git grep -nE 'uses:[[:space:]]+[^[:space:]#]+@' "$head" -- .github/workflows || true
python3 - "$head" <<'PY'
from __future__ import annotations
import re
import subprocess
import sys

head = sys.argv[1]
workflow_paths = subprocess.check_output(
    ["git", "ls-tree", "-r", "--name-only", head, "--", ".github/workflows"],
    text=True,
).splitlines()
pattern = re.compile(r"^\s*uses:\s*[^@#\s]+@([^#\s]+)")
for path in workflow_paths:
    body = subprocess.check_output(["git", "show", f"{head}:{path}"], text=True)
    for number, line in enumerate(body.splitlines(), 1):
        match = pattern.match(line)
        if match and not re.fullmatch(r"[0-9a-fA-F]{40}", match.group(1)):
            print(f"mutable_action_ref {path}:{number}: {line.strip()}")
PY

echo '== Static parsing for changed CI source =='
git diff --diff-filter=ACMR --name-only "$base" "$head" -- scripts/ci |
while IFS= read -r path; do
  case "$path" in
    *.py)
      git show "$head:$path" | python3 -c \
        'import ast,sys; ast.parse(sys.stdin.read(), filename=sys.argv[1])' "$path"
      echo "python_ast=OK $path"
      ;;
    *.sh)
      temp_file="$(mktemp)"
      git show "$head:$path" > "$temp_file"
      bash -n "$temp_file"
      rm -f "$temp_file"
      echo "bash_syntax=OK $path"
      ;;
  esac
done

echo '== Current check state =='
gh pr view "$pr" --repo "$repo" --json headRefOid,reviewDecision,statusCheckRollup \
  --jq '{
    headRefOid,reviewDecision,
    nonSuccess:[
      .statusCheckRollup[]
      | select(.name != null and (.status != "COMPLETED" or
        (.conclusion != "SUCCESS" and .conclusion != "SKIPPED" and .conclusion != "NEUTRAL")))
      | {name,status,conclusion,detailsUrl}
    ]
  }'

Length of output: 217274


🏁 Script executed:

#!/bin/bash
set -euo pipefail

repo='ContextualWisdomLab/.github'
pr='759'
head='e151a1044e9a88b708c5628190da598a4203cfd6'

echo '== LLVM 19 workflow contract =='
git show "$head:.github/workflows/opencode-review-dispatch.yml" |
  awk '
    /llvm-19|LLVM_COV|LLVM_PROFDATA|llvm-cov-19|llvm-profdata-19|cargo llvm-cov|Cargo\.(toml|lock)/ {
      start = NR - 12
      if (start < 1) start = 1
      for (i = start; i <= NR + 16; i++) wanted[i] = 1
    }
    { line[NR] = $0 }
    END {
      for (i = 1; i <= NR; i++) {
        if (wanted[i]) printf "%4d: %s\n", i, line[i]
      }
    }' | sed -n '1,1600p'

echo '== LLVM contract test assertions =='
git show "$head:tests/test_opencode_agent_contract.py" |
  awk '
    /test_opencode_coverage_image_provisions_compatible_llvm_tools/ { printing = 1 }
    printing { printf "%4d: %s\n", NR, $0 }
    printing && /^def / && NR > start { exit }
  ' | sed -n '1,260p'

echo '== LLVM doctoring document =='
git show "$head:docs/doctoring/opencode-llvm-coverage-toolchain.md" |
  awk '{printf "%4d: %s\n", NR, $0}' | sed -n '1,260p'

echo '== Same-head scan-pr-queue check runs =='
gh api "repos/$repo/commits/$head/check-runs?per_page=100" \
  --jq '[.check_runs[]
    | select(.name == "scan-pr-queue")
    | {name,status,conclusion,started_at,completed_at,details_url,external_id}]'

echo '== Current status contexts for the active head =='
gh api "repos/$repo/commits/$head/status" \
  --jq '{state,statuses:[.statuses[] | {context,state,updated_at,target_url}]}'

echo '== Current PR state =='
gh pr view "$pr" --repo "$repo" --json headRefOid,reviewDecision,statusCheckRollup \
  --jq '{
    headRefOid,reviewDecision,
    nonSuccess:[
      .statusCheckRollup[]
      | select(.name != null and (.status != "COMPLETED" or
        (.conclusion != "SUCCESS" and .conclusion != "SKIPPED" and .conclusion != "NEUTRAL")))
      | {name,status,conclusion,detailsUrl}
    ]
  }'

Length of output: 11583


🏁 Script executed:

#!/bin/bash
set -euo pipefail

base='f070c504c1cb06891b800d7ab0cf6ac7d3cf8eae'
head='e151a1044e9a88b708c5628190da598a4203cfd6'

echo '== Current-tree LLVM and Rust coverage references =='
git grep -nEi \
  'llvm-19|llvm-cov-19|llvm-profdata-19|LLVM_COV|LLVM_PROFDATA|cargo llvm-cov|cargo-llvm-cov' \
  "$head" -- \
  .github/workflows scripts tests docs Dockerfile '*Dockerfile*' 2>/dev/null || true

echo '== Current-tree package installation and executable checks near LLVM references =='
git grep -nEi -C 8 \
  'apt-get.*install|apt.*install|command -v.*llvm|test -x.*llvm|llvm-cov|llvm-profdata' \
  "$head" -- .github/workflows scripts tests 2>/dev/null || true

echo '== Files that currently contain LLVM-related references =='
git grep -lEi \
  'llvm-19|llvm-cov-19|llvm-profdata-19|LLVM_COV|LLVM_PROFDATA|cargo llvm-cov|cargo-llvm-cov' \
  "$head" -- . 2>/dev/null || true

echo '== Base-to-head changes that affect LLVM or Rust coverage references =='
git diff --no-ext-diff --unified=12 "$base" "$head" -- \
  .github/workflows scripts tests docs Dockerfile '*Dockerfile*' |
  grep -nEi -C 12 \
    'llvm-19|llvm-cov-19|llvm-profdata-19|LLVM_COV|LLVM_PROFDATA|cargo llvm-cov|cargo-llvm-cov|Cargo\.(toml|lock)|\.rs' || true

echo '== Exact diff membership of candidate LLVM contract files =='
for path in \
  .github/workflows/opencode-review-dispatch.yml \
  tests/test_opencode_agent_contract.py \
  docs/doctoring/opencode-llvm-coverage-toolchain.md
do
  if git cat-file -e "$head:$path" 2>/dev/null; then
    if git diff --quiet "$base" "$head" -- "$path"; then
      echo "unchanged $path"
    else
      echo "changed $path"
    fi
  else
    echo "missing_at_head $path"
  fi
done

echo '== Current relevant check state =='
gh pr view 759 --repo ContextualWisdomLab/.github --json headRefOid,reviewDecision,statusCheckRollup \
  --jq '{
    headRefOid,reviewDecision,
    nonSuccess:[
      .statusCheckRollup[]
      | select(.name != null and (.status != "COMPLETED" or
        (.conclusion != "SUCCESS" and .conclusion != "SKIPPED" and .conclusion != "NEUTRAL")))
      | {name,status,conclusion,detailsUrl}
    ]
  }'

Length of output: 55339


@seonghobae I reviewed exact head e151a1044e9a88b708c5628190da598a4203cfd6 against base f070c504c1cb06891b800d7ab0cf6ac7d3cf8eae.

I found one current-head blocker.

P1 — Provision and verify a compatible LLVM coverage toolchain

The Rust coverage image in .github/workflows/opencode-review-dispatch.yml installs Debian cargo and the pinned cargo-llvm-cov binary. It does not install llvm-19. It does not define LLVM_COV or LLVM_PROFDATA. It does not verify an llvm-cov or llvm-profdata executable.

The current Rust guard checks only cargo and cargo-llvm-cov before it runs cargo llvm-cov.

if ! command -v cargo-llvm-cov >/dev/null 2>&1; then

cargo llvm-cov requires compatible LLVM coverage tools. The current image can therefore pass the guard and fail only when Rust coverage starts. This weakens the required fail-closed coverage evidence path.

Install the intended LLVM version in the coverage image. Bind LLVM_COV and LLVM_PROFDATA to the versioned executables. Verify both executables during the image build. Add a contract test for those requirements.

The active tree has no llvm-19, llvm-cov-19, llvm-profdata-19, LLVM_COV, or LLVM_PROFDATA reference. The expected LLVM doctoring document is also absent. The workflow and existing Rust contract test are unchanged by this PR, so the final head does not contain the LLVM compatibility work described in the PR objective.

I also verified the following current-head contracts:

  • AUTH_HEADER_RE redacts every Authorization: and Authorization= value.
  • The publisher redacts, bounds, HTML-escapes, and delimiter-proofs fields before writing GITHUB_OUTPUT.
  • Both materializers retain nonzero failure status.
  • The diagnostics workflow checks out the exact head with persist-credentials: false.
  • The Python 3.10 job installs hash-locked tomli.
  • The Python 3.14 job requires 100% branch coverage and 100% production docstrings for the listed modules.
  • The inspected GitHub Actions references use immutable 40-character SHA pins.
  • git diff --check passed. There are no unresolved current review threads.
  • Changed Python sources passed AST parsing. scripts/ci/strix_model_utils.sh passed bash -n.

GitHub currently reports scan-pr-queue as CANCELLED. The PR remains REVIEW_REQUIRED. I cannot issue a clear current-head verdict until the LLVM coverage blocker is fixed and the required check state is successful.

⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

Review exact head e151a1044e9a88b708c5628190da598a4203cfd6 only. Re-evaluate the bounded diagnostics, scheme-neutral Authorization redaction, exact-head checkout/evidence, Strix source-directory confinement, 100% statement/branch coverage, production docstrings, and absence of branch-local write-capable repair workflows. Do not reuse predecessor-head findings or approvals.

@coderabbitai

coderabbitai Bot commented Aug 6, 2026

Copy link
Copy Markdown

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

repo='ContextualWisdomLab/.github'
pr='759'
head='e151a1044e9a88b708c5628190da598a4203cfd6'

echo '== PR identity and checks =='
pr_json="$(gh pr view "$pr" --repo "$repo" \
  --json headRefOid,baseRefOid,state,isDraft,mergeable,reviewDecision,statusCheckRollup)"
printf '%s\n' "$pr_json" | jq '{
  headRefOid, baseRefOid, state, isDraft, mergeable, reviewDecision,
  nonSuccess: [
    .statusCheckRollup[]
    | select(.name != null and (.status != "COMPLETED" or
      (.conclusion != "SUCCESS" and .conclusion != "SKIPPED" and .conclusion != "NEUTRAL")))
    | {name,status,conclusion,detailsUrl}
  ]
}'
base="$(printf '%s\n' "$pr_json" | jq -r '.baseRefOid')"

echo '== Exact revision relation =='
printf 'requested_head='; git rev-parse "$head"
printf 'pr_base='; git rev-parse "$base"
printf 'merge_base='; git merge-base "$base" "$head"
git merge-base --is-ancestor "$base" "$head" && echo 'base_is_ancestor=yes'
git diff --check "$base" "$head"
echo 'diff_check=OK'
git diff --name-status "$base" "$head"

echo '== Current unresolved threads =='
gh api graphql -F owner='ContextualWisdomLab' -F name='.github' -F number="$pr" -f query='
query($owner:String!, $name:String!, $number:Int!) {
  repository(owner:$owner,name:$name) {
    pullRequest(number:$number) {
      reviewThreads(first:100) { nodes { isResolved isOutdated path line } }
    }
  }
}' --jq '[.data.repository.pullRequest.reviewThreads.nodes[]
  | select(.isResolved == false and .isOutdated == false)]'

echo '== Relevant source outlines =='
for path in \
  scripts/ci/sanitize_github_output_summary.py \
  scripts/ci/coverage_failure_summary.py \
  scripts/ci/materialize_base_javascript_packages.py \
  scripts/ci/materialize_base_python_requirements.py \
  scripts/ci/strix_model_utils.sh \
  scripts/ci/strix_quick_gate.sh \
  tests/test_sanitize_github_output_summary.py \
  tests/test_coverage_materializer_failure_diagnostics.py \
  tests/test_opencode_agent_contract.py
do
  if git cat-file -e "$head:$path" 2>/dev/null; then
    echo "--- $path"
    ast-grep outline "$path" --items all 2>/dev/null || true
  fi
done

echo '== Diagnostic, Strix, and LLVM contracts =='
for path in \
  scripts/ci/sanitize_github_output_summary.py \
  scripts/ci/coverage_failure_summary.py \
  scripts/ci/materialize_base_javascript_packages.py \
  scripts/ci/materialize_base_python_requirements.py \
  scripts/ci/strix_model_utils.sh \
  scripts/ci/strix_quick_gate.sh \
  .github/workflows/opencode-coverage-diagnostics-ci.yml \
  .github/workflows/opencode-review-dispatch.yml \
  .github/workflows/trusted-uv-materializer-quality-ci.yml \
  tests/test_sanitize_github_output_summary.py \
  tests/test_coverage_materializer_failure_diagnostics.py \
  tests/test_opencode_agent_contract.py
do
  if git cat-file -e "$head:$path" 2>/dev/null; then
    echo "--- $path"
    git show "$head:$path" | nl -ba | sed -n '1,620p'
  fi
done

echo '== Focused exact diff =='
git diff --no-ext-diff --find-renames --unified=12 "$base" "$head" -- \
  scripts/ci .github/workflows tests docs/doctoring \
  requirements-opencode-python310-ci-hashes.txt \
  requirements-strix-ci.txt requirements-strix-ci-hashes.txt | sed -n '1,9000p'

echo '== Workflow mutation and transient-artifact inventory =='
python3 - "$base" "$head" <<'PY'
from __future__ import annotations
import re
import subprocess
import sys

base, head = sys.argv[1:]
workflows = subprocess.check_output(
    ["git", "diff", "--name-only", base, head, "--", ".github/workflows"],
    text=True,
).splitlines()
signals = (
    "contents: write", "pull-requests: write", "issues: write", "id-token: write",
    "git push", "gh pr merge", "gh pr review", "workflow_dispatch:", "repository_dispatch:",
)
for path in workflows:
    body = subprocess.check_output(["git", "show", f"{head}:{path}"], text=True)
    hits = [
        f"{number}:{line}" for number, line in enumerate(body.splitlines(), 1)
        if "permissions:" in line or any(signal in line for signal in signals)
    ]
    print(f"--- {path}")
    print("\n".join(hits) if hits else "no matched write or dispatch signal")

paths = subprocess.check_output(
    ["git", "ls-tree", "-r", "--name-only", head], text=True
).splitlines()
artifact_re = re.compile(
    r"(^|/)(one-shot[^/]*|repair[^/]*|[^/]*redact-materializer[^/]*|"
    r"apply[-_][^/]*|[^/]*encoded[^/]*patch[^/]*)($|/)", re.I,
)
matches = [path for path in paths if artifact_re.search(path)]
print("artifact_matches=" + (",".join(matches) if matches else "none"))
PY

echo '== Static parse checks =='
git diff --diff-filter=ACMR --name-only "$base" "$head" -- scripts/ci |
while IFS= read -r path; do
  case "$path" in
    *.py)
      git show "$head:$path" | python3 -c \
        'import ast,sys; ast.parse(sys.stdin.read(), filename=sys.argv[1])' "$path"
      echo "python_ast=OK $path"
      ;;
    *.sh)
      temp_file="$(mktemp)"
      git show "$head:$path" > "$temp_file"
      bash -n "$temp_file"
      rm -f "$temp_file"
      echo "bash_syntax=OK $path"
      ;;
  esac
done

Length of output: 16870


🏁 Script executed:

#!/bin/bash
set -euo pipefail

repo='ContextualWisdomLab/.github'
pr='759'
base='f070c504c1cb06891b800d7ab0cf6ac7d3cf8eae'
head='e151a1044e9a88b708c5628190da598a4203cfd6'

show_numbered() {
  local path="$1"
  echo "--- $path"
  git show "$head:$path" | awk '{printf "%4d: %s\n", NR, $0}'
}

echo '== Sanitizer, publisher, materializer failure paths, and tests =='
for path in \
  scripts/ci/sanitize_github_output_summary.py \
  scripts/ci/coverage_failure_summary.py \
  scripts/ci/materialize_base_javascript_packages.py \
  scripts/ci/materialize_base_python_requirements.py \
  tests/test_sanitize_github_output_summary.py \
  tests/test_coverage_materializer_failure_diagnostics.py
do
  show_numbered "$path" | sed -n '1,620p'
done

echo '== Strix confinement source and tests =='
for path in \
  scripts/ci/strix_model_utils.sh \
  scripts/ci/strix_quick_gate.sh \
  tests/test_strix_model_utils_source_dirs.py
do
  if git cat-file -e "$head:$path" 2>/dev/null; then
    show_numbered "$path" | sed -n '1,620p'
  fi
done

echo '== Coverage workflow and quality-gate source =='
for path in \
  .github/workflows/opencode-coverage-diagnostics-ci.yml \
  .github/workflows/trusted-uv-materializer-quality-ci.yml \
  requirements-opencode-python310-ci-hashes.txt \
  tests/test_control_plane_branch_writer_absence.py
do
  if git cat-file -e "$head:$path" 2>/dev/null; then
    show_numbered "$path" | sed -n '1,720p'
  fi
done

echo '== Changed workflow permissions and mutation signals =='
while IFS= read -r path; do
  [ -n "$path" ] || continue
  echo "--- $path"
  git show "$head:$path" |
    awk '/permissions:|contents: write|pull-requests: write|issues: write|id-token: write|git push|gh pr (merge|review)|workflow_dispatch:|repository_dispatch:/ {printf "%4d: %s\n", NR, $0}'
done < <(git diff --name-only "$base" "$head" -- .github/workflows)

echo '== Transient artifact inventory =='
git ls-tree -r --name-only "$head" |
  grep -Ei '(^|/)(one-shot[^/]*|repair[^/]*|[^/]*redact-materializer[^/]*|apply[-_][^/]*|[^/]*encoded[^/]*patch[^/]*)($|/)' ||
  echo 'none'

echo '== Static parse checks =='
for path in \
  scripts/ci/coverage_failure_summary.py \
  scripts/ci/materialize_base_javascript_packages.py \
  scripts/ci/materialize_base_python_requirements.py \
  scripts/ci/sanitize_github_output_summary.py
do
  git show "$head:$path" | python3 -c \
    'import ast,sys; ast.parse(sys.stdin.read(), filename=sys.argv[1])' "$path"
  echo "python_ast=OK $path"
done
tmp="$(mktemp)"
git show "$head:scripts/ci/strix_model_utils.sh" > "$tmp"
bash -n "$tmp"
rm -f "$tmp"
echo 'bash_syntax=OK scripts/ci/strix_model_utils.sh'

echo '== Current checks and required check names =='
gh pr view "$pr" --repo "$repo" --json headRefOid,reviewDecision,statusCheckRollup \
  --jq '{
    headRefOid,reviewDecision,
    checks:[.statusCheckRollup[] | {name,status,conclusion,detailsUrl}]
  }'
gh api "repos/$repo/branches/main/protection/required_status_checks" \
  --jq '{strict,contexts,checks}' 2>&1 || true

Length of output: 124572


🏁 Script executed:

#!/bin/bash
set -euo pipefail

repo='ContextualWisdomLab/.github'
pr='759'
base='f070c504c1cb06891b800d7ab0cf6ac7d3cf8eae'
head='e151a1044e9a88b708c5628190da598a4203cfd6'

workflow_list="$(mktemp)"
git diff --name-only "$base" "$head" -- .github/workflows >"$workflow_list"

echo '== Changed workflow mutation signals =='
while IFS= read -r path; do
  [ -n "$path" ] || continue
  echo "--- $path"
  git show "$head:$path" |
    awk '/permissions:|contents: write|pull-requests: write|issues: write|id-token: write|git push|gh pr (merge|review)|workflow_dispatch:|repository_dispatch:/ {printf "%4d: %s\n", NR, $0}'
done <"$workflow_list"
rm -f "$workflow_list"

echo '== Tree-level transient writer artifact inventory =='
git ls-tree -r --name-only "$head" |
  grep -Ei '(^|/)(one-shot[^/]*|repair[^/]*|[^/]*redact-materializer[^/]*|apply[-_][^/]*|[^/]*encoded[^/]*patch[^/]*)($|/)' ||
  echo 'none'

echo '== Static parse checks =='
for path in \
  scripts/ci/coverage_failure_summary.py \
  scripts/ci/materialize_base_javascript_packages.py \
  scripts/ci/materialize_base_python_requirements.py \
  scripts/ci/sanitize_github_output_summary.py
do
  git show "$head:$path" | python3 -c \
    'import ast,sys; ast.parse(sys.stdin.read(), filename=sys.argv[1])' "$path"
  echo "python_ast=OK $path"
done
tmp="$(mktemp)"
git show "$head:scripts/ci/strix_model_utils.sh" >"$tmp"
bash -n "$tmp"
rm -f "$tmp"
echo 'bash_syntax=OK scripts/ci/strix_model_utils.sh'

echo '== Current check state =='
gh pr view "$pr" --repo "$repo" --json headRefOid,reviewDecision,statusCheckRollup \
  --jq '{
    headRefOid,reviewDecision,
    nonSuccess:[
      .statusCheckRollup[]
      | select(.name != null and (.status != "COMPLETED" or
        (.conclusion != "SUCCESS" and .conclusion != "SKIPPED" and .conclusion != "NEUTRAL")))
      | {name,status,conclusion,detailsUrl}
    ]
  }'

echo '== Required status-check policy, when authorized =='
gh api "repos/$repo/branches/main/protection/required_status_checks" \
  --jq '{strict,contexts,checks}' 2>&1 || true

Length of output: 3371


@seonghobae I reviewed only exact head e151a1044e9a88b708c5628190da598a4203cfd6.

I found no actionable source-level finding in the requested areas.

Verified items:

  • The PR head matches the requested SHA.
  • Base f070c504c1cb06891b800d7ab0cf6ac7d3cf8eae is the merge base. git diff --check passes.
  • The diagnostics sanitizer redacts every same-line value after Authorization: or Authorization=.
  • Shared sanitizer tests cover Token, Digest, AWS4, and scheme-less authorization values.
  • The shared failure publisher redacts, bounds, HTML-escapes, and delimiter-proofs fields before it writes GITHUB_OUTPUT.
  • Both materializers use the shared publisher and retain nonzero failure status.
  • The diagnostics workflow checks out the exact PR head with persist-credentials: false.
  • The workflow defines Python 3.10 hash-locked tomli, Python 3.14 branch coverage with --cov-fail-under=100, and 100% production docstring enforcement.
  • The Strix source-directory validator rejects traversal, nested paths, glob patterns, and option-like values. It makes the sanitized value readonly.
  • No matching transient repair workflow, patch payload, or branch-writer artifact exists in the exact-head tree.
  • The changed Python sources pass AST parsing. scripts/ci/strix_model_utils.sh passes bash -n.
  • There are no unresolved current review threads.

I cannot give a clear merge-ready verdict.

scan-pr-queue is currently CANCELLED. The PR remains REVIEW_REQUIRED. The available token cannot read protected-main required-check policy because GitHub returned HTTP 403.

The remaining external gates are:

  1. Complete or replace scan-pr-queue according to repository policy.
  2. Verify protected-main requirements with authorized credentials.
  3. Obtain the required independent approval.

You are interacting with an AI system.

Copy link
Copy Markdown
Contributor Author

@opencode-agent

Implement the newly validated exact-head blocker on fix/opencode-coverage-failure-diagnostics only if the live head still equals e151a1044e9a88b708c5628190da598a4203cfd6. Do not create a one-shot, self-modifying, repair-pr*, or other branch-local write-capable workflow, and do not merge or weaken any gate.

Blocker: the trusted Rust coverage image generated in .github/workflows/opencode-review-dispatch.yml installs Debian cargo/rustc and a pinned cargo-llvm-cov, but does not provision or verify the compatible LLVM coverage executables that cargo-llvm-cov invokes. It currently has no llvm-19 package, no explicit LLVM_COV/LLVM_PROFDATA, and no pre-execution validation of llvm-cov/llvm-profdata.

Apply this test-first as one bounded repair:

  1. Add a permanent failing contract test against the generated Dockerfile requiring the compatible LLVM 19 toolchain, explicit executable paths, and ordering before the cargo-llvm-cov installation/use.
  2. Install the required LLVM 19 package(s) in the trusted image and set LLVM_COV and LLVM_PROFDATA to the exact LLVM 19 executables (prefer the package-owned /usr/lib/llvm-19/bin/llvm-cov and /usr/lib/llvm-19/bin/llvm-profdata paths unless live package evidence proves a different canonical path).
  3. Run test -x "$LLVM_COV" && test -x "$LLVM_PROFDATA" after package installation and before installing or invoking cargo-llvm-cov.
  4. Preserve the digest-pinned base image, immutable cargo-llvm-cov archive/hash, network isolation, exact-head materialization, 100% statement/branch/docstring evidence, and all existing credential and scanner boundaries.
  5. Update the authoritative doctoring and CHANGELOG.md with primary cargo-llvm-cov and LLVM coverage-tool evidence in APA 7 form.
  6. Rerun every direct workflow on the resulting exact head, request fresh CodeRabbit/OpenCode/Noema/Strix review, and do not reuse any e151a104... check or approval.

The public cargo-llvm-cov contract documents that it invokes llvm-profdata, supports explicit LLVM_COV and LLVM_PROFDATA, and requires compatible LLVM tools; LLVM's source-based coverage workflow likewise uses llvm-profdata to merge profiles and llvm-cov to report them. Treat the prior successful workflow execution as insufficient evidence for this unexercised Rust-toolchain branch.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants