fix(coverage): materialize requirements-directory locks - #785
fix(coverage): materialize requirements-directory locks#785seonghobae wants to merge 27 commits into
Conversation
|
Warning Review limit reached
Next review available in: 12 seconds Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (6)
Comment |
|
@opencode-agent @cwl-noema-review Perform an independent formal exact-head review of The final diff contains only the permanent five-file product change; all transient repair workflows and transformers are absent. Recompute current-head coverage and public-docstring evidence; verify that only direct |
|
@coderabbitai review @opencode-agent @cwl-noema-review Independently review exact current head The exact head is workflow-free and all direct current-head security, supply-chain, and Trusted uv Materializer Quality checks are successful. Verify the narrow direct-child |
|
Tip For best results, initiate chat on the files or code changes. 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
base='f070c504c1cb06891b800d7ab0cf6ac7d3cf8eae'
head='ed33253e5d6f93f2e71d80b24e27b301f96efb88'
printf '\n== Exact commits ==\n'
git cat-file -e "${base}^{commit}"
git cat-file -e "${head}^{commit}"
git show -s --format='base=%H%nbase-subject=%s%nbase-date=%cI' "$base"
git show -s --format='head=%H%nhead-subject=%s%nhead-date=%cI' "$head"
printf '\n== Changed files and stat ==\n'
git diff --name-status "$base" "$head"
git diff --stat "$base" "$head"
printf '\n== Full product diff ==\n'
git diff --find-renames --find-copies --no-ext-diff "$base" "$head"
printf '\n== Candidate source maps for changed Python files ==\n'
git diff --name-only "$base" "$head" -- '*.py' |
while IFS= read -r file; do
[ -n "$file" ] || continue
echo "--- $file"
ast-grep outline "$file" --items all --view compact || true
done
printf '\n== Candidate discovery and provenance references at exact head ==\n'
rg -n -C 4 --glob '*.py' \
'(requirements|require-hashes|materiali[sz]|manifest|symlink|git\s+cat-file|ls-tree|blob|traversal)' .
printf '\n== Workflow inventory and write-capable workflow references ==\n'
fd -t f -e yml -e yaml .github 2>/dev/null || true
rg -n -i -C 3 --glob '*.yml' --glob '*.yaml' \
'(contents:\s*write|pull-requests:\s*write|actions/github-script|git\s+push|force-with-lease|workflow_dispatch)' \
.github 2>/dev/null || true
printf '\n== Relevant tests and documentation references ==\n'
rg -n -C 3 --glob '*test*.py' --glob '*.md' \
'(requirements/|requirements\*\.txt|require-hashes|materiali[sz]|manifest|symlink|nested|PR-only)' .
printf '\n== PR metadata, checks, and review state ==\n'
gh pr view 785 --repo ContextualWisdomLab/.github \
--json number,state,isDraft,headRefOid,baseRefOid,mergeStateStatus,reviewDecision,statusCheckRollup,reviews \
|| trueLength of output: 202327 🏁 Script executed: #!/bin/bash
set -euo pipefail
base='f070c504c1cb06891b800d7ab0cf6ac7d3cf8eae'
head='ed33253e5d6f93f2e71d80b24e27b301f96efb88'
printf '\n== Exact changed files ==\n'
git diff --name-status "$base" "$head"
printf '\n== Exact changed-file diff ==\n'
git diff --no-ext-diff --unified=80 "$base" "$head"
printf '\n== Materializer complete source map ==\n'
ast-grep outline scripts/ci/materialize_base_python_requirements.py --items all --view expanded
printf '\n== Materializer candidate and base-lock implementation ==\n'
rg -n -C 12 \
'def (_is_candidate_lock_name|_is_candidate_lock_path|_is_hash_pinned|base_hash_locks|materialize|_regular|_git|_lock_blob)|manifest' \
scripts/ci/materialize_base_python_requirements.py
printf '\n== Materializer full source, bounded ==\n'
cat -n scripts/ci/materialize_base_python_requirements.py
printf '\n== New requirements-directory regression test ==\n'
cat -n tests/test_requirements_directory_lock_materialization.py
printf '\n== Existing Python materializer boundary tests: relevant regions ==\n'
rg -n -C 10 \
'(regular|symlink|traversal|nested|PR-modified|hash.pinned|manifest|base_hash_locks|require-hashes)' \
tests/test_materialize_base_python_requirements.py
printf '\n== Install closure preflight implementation and tests ==\n'
fd -t f 'install_base_python_locks.py|test_install_base_python_locks.py' . -x sh -c '
echo "--- $1"
cat -n "$1"
' sh {} \;
printf '\n== Exact-head workflow files changed by this diff, if any ==\n'
git diff --name-only "$base" "$head" -- .github/workflows |
while IFS= read -r file; do
[ -n "$file" ] && { echo "--- $file"; cat -n "$file"; }
done
printf '\n== Workflow writers introduced by the exact diff ==\n'
git diff --no-ext-diff "$base" "$head" -- .github |
rg -n -i -C 3 '(contents:\s*write|git\s+push|force-with-lease|gh\s+(api|pr|workflow)|workflow_dispatch)' || true
printf '\n== Current PR check summary, grouped ==\n'
gh pr checks 785 --repo ContextualWisdomLab/.github || trueLength of output: 127039 🏁 Script executed: #!/bin/bash
set -euo pipefail
repo='ContextualWisdomLab/.github'
head='ed33253e5d6f93f2e71d80b24e27b301f96efb88'
printf '\n== Exact-head materializer and installer calls in coverage workflows ==\n'
rg -n -C 8 --glob '*.yml' --glob '*.yaml' \
'(materialize_base_python_requirements\.py|install_base_python_locks\.py|base-python-requirements|--base-sha|--requirements-root)' \
.github/workflows
printf '\n== Candidate-status hash-pin regression coverage ==\n'
rg -n -C 8 --glob 'test*.py' \
'(--require-hashes.*(unpinned|>=)|_is_hash_pinned|requirements/ci\.txt|requirements/nested|symlink|PR-modified)' \
tests
printf '\n== Exact quality workflow runs and their logs ==\n'
gh run list --repo "$repo" --commit "$head" --workflow 'Trusted uv Materializer Quality CI' \
--limit 10 --json databaseId,headSha,status,conclusion,createdAt,updatedAt,url \
|| true
for run_id in $(gh run list --repo "$repo" --commit "$head" --workflow 'Trusted uv Materializer Quality CI' \
--limit 10 --json databaseId --jq '.[].databaseId' 2>/dev/null); do
echo "--- quality run $run_id"
gh run view "$run_id" --repo "$repo" --log 2>&1 | rg -n -C 4 \
'(passed|failed|FAIL|TOTAL|100%|coverage|interrogate|docstring|Python 3\.10|Python 3\.14)' \
|| true
done
printf '\n== Current Strix and failed-status details ==\n'
gh pr checks 785 --repo "$repo" --json name,state,link,bucket \
| jq -r '.[] | select(.name == "strix" or .name == "publish-manual-pr-evidence-status")' \
|| true
printf '\n== Branch protection / rulesets for main ==\n'
gh api "repos/${repo}/branches/main/protection" 2>&1 | jq '{required_status_checks,required_pull_request_reviews,enforce_admins,required_linear_history,allow_force_pushes,allow_deletions}' \
|| true
gh api "repos/${repo}/rulesets" 2>&1 | jq '.[] | {name,enforcement,target,conditions,rules}' \
|| trueLength of output: 207047
I reviewed Finding — P1: Do not materialize an unpinned direct-child lockIn
The existing test at Therefore, a base-owned This violates the stated boundary that only complete hash-pinned locks gain candidate status. It also conflicts with the new doctoring document, which says that candidate content must be hash-pinned. Update candidate validation so an unpinned direct-child Verified controls
You are interacting with an AI system. |
|
@opencode-agent @cwl-noema-review @coderabbitai review Review-only request for exact current head |
|
Tip For best results, initiate chat on the files or code changes. 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
base='f070c504c1cb06891b800d7ab0cf6ac7d3cf8eae'
head='ed33253e5d6f93f2e71d80b24e27b301f96efb88'
repo='ContextualWisdomLab/.github'
printf '%s\n' '== Exact commits =='
git cat-file -e "${base}^{commit}"
git cat-file -e "${head}^{commit}"
git show -s --format='base %H%n%cs %s' "$base"
git show -s --format='head %H%n%cs %s' "$head"
printf '%s\n' '== Exact changed files =='
git diff --name-status --find-renames "$base" "$head"
git diff --stat "$base" "$head"
printf '%s\n' '== Exact diff =='
git diff --no-ext-diff --find-renames --unified=60 "$base" "$head"
printf '%s\n' '== Changed Python file outlines =='
git diff --name-only "$base" "$head" -- '*.py' |
while IFS= read -r file; do
test -n "$file" || continue
printf '\n--- %s ---\n' "$file"
ast-grep outline "$file" --items all --view expanded || true
done
printf '%s\n' '== Materializer candidate, content-validation, tree, and manifest regions =='
rg -n -C 12 --glob 'materialize_base_python_requirements.py' \
'def (_is_candidate_lock_name|_is_candidate_lock_path|_is_hash_pinned|_.*regular.*|_.*tree.*|materialize)|require-hashes|hash|manifest|ls-tree|cat-file|symlink|traversal' .
printf '%s\n' '== Installer preflight regions =='
rg -n -C 10 --glob 'install_base_python_locks.py' \
'require-hashes|preflight|manifest|pip|closure|defer|skip|install' .
printf '%s\n' '== Relevant regression-test regions =='
rg -n -C 10 --glob 'test*.py' \
'requirements/ci\.txt|requirements/nested|require-hashes|unpinned|hash-pinned|symlink|traversal|PR-only|manifest|base_hash_locks' tests
printf '%s\n' '== Workflow inventory and exact-diff write capability scan =='
fd -t f -e yml -e yaml .github 2>/dev/null || true
git diff --no-ext-diff "$base" "$head" -- .github |
rg -n -i -C 3 'contents:\s*write|pull-requests:\s*write|git\s+push|force-with-lease|workflow_dispatch|actions/github-script' || true
printf '%s\n' '== Current PR and check metadata =='
gh pr view 785 --repo "$repo" \
--json state,isDraft,headRefOid,baseRefOid,mergeStateStatus,reviewDecision,statusCheckRollup,reviews
gh pr checks 785 --repo "$repo" || trueLength of output: 202643
I reviewed P1 — Reject incomplete direct-child locks before materialization
This file has no hash for The new direct-child rule accepts The later independent Update the candidate validation to require a hash for every requirement before materialization. Add a regression test for Verified controls
The PR is still blocked and requires review according to current GitHub metadata. I cannot approve while the incomplete-lock candidate path remains. You are interacting with an AI system. |
|
@jules Replace the current self-removing repair workflow with ordinary reviewed source commits on this branch. The product diff must contain only the permanent requirements-directory lock discovery, coverage/workflow contract, tests, doctoring, and CHANGELOG changes; no temporary writer, force-with-lease publisher, self-delete mechanism, or expected-RED artifact may remain. Implement the narrow direct-child rule for regular base-owned |
|
@coderabbitai review Review exact current head |
|
Tip For best results, initiate chat on the files or code changes. 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
base='f070c504c1cb06891b800d7ab0cf6ac7d3cf8eae'
head='ed33253e5d6f93f2e71d80b24e27b301f96efb88'
repo='ContextualWisdomLab/.github'
printf '\n== Exact commits ==\n'
git cat-file -e "${base}^{commit}"
git cat-file -e "${head}^{commit}"
git show -s --format='base=%H%n%s%n%cs' "$base"
git show -s --format='head=%H%n%s%n%cs' "$head"
printf '\n== Changed files ==\n'
git diff --name-status --find-renames "$base" "$head"
git diff --stat "$base" "$head"
printf '\n== Exact diff ==\n'
git diff --no-ext-diff --find-renames --unified=50 "$base" "$head"
printf '\n== Materializer outline ==\n'
materializer="$(fd -t f '^materialize_base_python_requirements\.py$' . | head -n1)"
test -n "$materializer"
ast-grep outline "$materializer" --items all --view expanded
printf '\n== Materializer validation, tree, and manifest code ==\n'
rg -n -C 14 \
'def (_is_candidate_lock_name|_is_candidate_lock_path|_is_hash_pinned|_.*tree.*|_.*regular.*|materialize)|--require-hashes|--hash|manifest|ls-tree|cat-file|symlink|traversal|base_hash_locks' \
"$materializer"
printf '\n== Installer preflight code ==\n'
fd -t f '^install_base_python_locks\.py$' . -x sh -c '
ast-grep outline "$1" --items all --view expanded
rg -n -C 12 "require-hashes|preflight|manifest|pip|closure|skip|defer|install" "$1"
' sh {}
printf '\n== Relevant test code ==\n'
fd -t f -e py . tests -x sh -c '
if rg -q "requirements/ci\.txt|requirements/nested|_is_hash_pinned|--require-hashes|base_hash_locks|symlink|PR-only|manifest" "$1"; then
echo "--- $1"
rg -n -C 10 "requirements/ci\.txt|requirements/nested|_is_hash_pinned|--require-hashes|base_hash_locks|symlink|PR-only|manifest" "$1"
fi
' sh {}
printf '\n== Workflow files changed by exact diff ==\n'
git diff --name-only "$base" "$head" -- .github/workflows |
while IFS= read -r file; do
test -n "$file" || continue
echo "--- $file"
git show "${head}:${file}" | nl -ba
done
printf '\n== Write-capability scan in exact workflow diff ==\n'
git diff --no-ext-diff "$base" "$head" -- .github |
rg -n -i -C 3 'contents:\s*write|pull-requests:\s*write|git\s+push|force-with-lease|workflow_dispatch|actions/github-script' || true
printf '\n== Current PR metadata and checks ==\n'
gh pr view 785 --repo "$repo" \
--json state,isDraft,headRefOid,baseRefOid,mergeStateStatus,reviewDecision,statusCheckRollup,reviews
gh pr checks 785 --repo "$repo" || true
printf '\n== Current unresolved review threads ==\n'
gh api graphql -F owner='ContextualWisdomLab' -F name='.github' -F number=785 -f query='
query($owner: String!, $name: String!, $number: Int!) {
repository(owner: $owner, name: $name) {
pullRequest(number: $number) {
reviewThreads(first: 100) { nodes { isResolved } }
}
}
}' | jq '[.data.repository.pullRequest.reviewThreads.nodes[] | select(.isResolved == false)] | length'Length of output: 130146 🏁 Script executed: #!/bin/bash
set -euo pipefail
base='f070c504c1cb06891b800d7ab0cf6ac7d3cf8eae'
head='ed33253e5d6f93f2e71d80b24e27b301f96efb88'
repo='ContextualWisdomLab/.github'
printf '\n== Exact changed workflow at requested head ==\n'
git show "${head}:.github/workflows/trusted-uv-materializer-quality-ci.yml" | sed -n '1,240p'
printf '\n== Write-capability tokens in the exact workflow diff ==\n'
git diff --no-ext-diff "$base" "$head" -- .github/workflows |
rg -n -i -C 3 'contents:\s*write|pull-requests:\s*write|issues:\s*write|id-token:\s*write|git\s+push|force-with-lease|workflow_dispatch|actions/github-script' || true
printf '\n== PR exact-head metadata and check rollup ==\n'
gh pr view 785 --repo "$repo" \
--json state,isDraft,headRefOid,baseRefOid,mergeStateStatus,reviewDecision,statusCheckRollup,reviews
printf '\n== Current check summary ==\n'
gh pr checks 785 --repo "$repo" || true
printf '\n== Current unresolved review-thread count ==\n'
gh api graphql -F owner='ContextualWisdomLab' -F name='.github' -F number=785 -f query='
query($owner: String!, $name: String!, $number: Int!) {
repository(owner: $owner, name: $name) {
pullRequest(number: $number) {
reviewThreads(first: 100) { nodes { isResolved } }
}
}
}' | jq '[.data.repository.pullRequest.reviewThreads.nodes[] | select(.isResolved == false)] | length'
printf '\n== Requested head workflow runs ==\n'
gh run list --repo "$repo" --commit "$head" --limit 100 \
--json name,headSha,status,conclusion,url \
--jq '.[] | select(.headSha == "'"$head"'") | [.name,.status,.conclusion,.url] | `@tsv`' \
|| trueLength of output: 45429
I reviewed P1 — Reject incomplete direct-child locks before materializationIn The existing test in
The later This behavior conflicts with the stated boundary that a candidate must be completely hash-pinned before materialization. Update the candidate-content validation so every requirement has a valid hash before the materializer emits the manifest entry. Add a regression test for Verified controls
The PR remains You are interacting with an AI system. |
|
@opencode-agent review Review exact head |
|
/oc Refetch the live PR and stop without writing unless exact head is Reconcile the latest protected After reconciliation, run the focused requirements-directory suite, the complete trusted-uv materializer quality suite, full repository tests, 100% statement/branch coverage, 100% public docstrings, compileall, and |
|
/oc Refetch the live pull request and abort without writing unless its exact head is |
|
@opencode-agent address Reconcile exact head After reconciliation, verify the effective PR diff contains only the intended six permanent files, run the focused materializer suite and complete exact-head suite with 100% production statement/branch coverage and docstrings, rerun all security/supply-chain checks, and keep Draft until fresh review and approval. |
|
/oc Refetch the exact live PR head and abort unless it is |
|
@opencode-agent Reconcile exact Draft head The branch is one protected-main commit behind and GitHub currently reports it non-mergeable. Preserve the exact six-file feature boundary, resolve
After reconciliation run focused requirements-directory tests, complete central statement/branch coverage, production docstrings, Python 3.10/3.14 compilation/compatibility, security/supply-chain gates, and clean-tree checks. Keep Draft until fresh exact-head automated review, qualifying independent approval, zero unresolved findings, and branch protection all succeed. Do not approve, merge, release, or alter reviewer credentials/protection. |
|
/oc Refetch PR #785 and reconcile its live Draft branch with protected |
|
Reconcile exact current head |
|
/oc Reconcile this six-file feature branch with current protected After reconciliation, prove direct-child |
|
@coderabbitai full review Perform a fresh exact-current-head review of authenticated-base Python requirements discovery and complete hash-closure enforcement. Submit the verdict without mutating or merging. |
|
Tip For best results, initiate chat on the files or code changes. 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
repo='ContextualWisdomLab/.github'
pr='785'
printf '%s\n' '== Live PR identity =='
pr_json="$(gh pr view "$pr" --repo "$repo" \
--json number,state,isDraft,headRefName,headRefOid,baseRefName,baseRefOid,mergeStateStatus,reviewDecision,statusCheckRollup,reviews)"
printf '%s\n' "$pr_json" | jq .
head="$(printf '%s\n' "$pr_json" | jq -r '.headRefOid')"
base="$(printf '%s\n' "$pr_json" | jq -r '.baseRefOid')"
printf 'base=%s\nhead=%s\n' "$base" "$head"
git cat-file -e "${base}^{commit}"
git cat-file -e "${head}^{commit}"
git merge-base --is-ancestor "$base" "$head" && echo 'base_is_ancestor=true' || echo 'base_is_ancestor=false'
git show -s --format='base %H%nbase subject %s%nhead %H%nhead subject %s%nhead parents %P' "$base" "$head"
printf '%s\n' '== Exact changed-file scope =='
git diff --name-status --find-renames "$base" "$head"
git diff --stat "$base" "$head"
printf '%s\n' '== Changed Python structure =='
git diff --name-only "$base" "$head" -- '*.py' |
while IFS= read -r file; do
[ -z "$file" ] && continue
printf '\n--- %s ---\n' "$file"
ast-grep outline "$file" --items all --view expanded || true
done
printf '%s\n' '== Exact materializer and installer source =='
for file in \
scripts/ci/materialize_base_python_requirements.py \
scripts/ci/install_base_python_locks.py; do
if git cat-file -e "${head}:${file}" 2>/dev/null; then
printf '\n--- %s ---\n' "$file"
git show "${head}:${file}" | cat -n
fi
done
printf '%s\n' '== Discovery, validation, and manifest tests =='
for file in \
tests/test_materialize_base_python_requirements.py \
tests/test_requirements_directory_lock_materialization.py; do
if git cat-file -e "${head}:${file}" 2>/dev/null; then
printf '\n--- %s ---\n' "$file"
git show "${head}:${file}" | cat -n
fi
done
printf '%s\n' '== Changed workflow, documentation, and full exact diff =='
for file in \
.github/workflows/trusted-uv-materializer-quality-ci.yml \
docs/doctoring/trusted-requirements-directory-lock-discovery.md \
CHANGELOG.md; do
if git cat-file -e "${head}:${file}" 2>/dev/null; then
printf '\n--- %s ---\n' "$file"
git show "${head}:${file}" | cat -n
fi
done
git diff --no-ext-diff --find-renames --unified=45 "$base" "$head"
printf '%s\n' '== Introduced workflow write-capability scan =='
git diff --no-ext-diff "$base" "$head" -- .github |
rg -n -i -C 3 \
'contents:\s*write|pull-requests:\s*write|issues:\s*write|id-token:\s*write|git\s+push|force-with-lease|workflow_dispatch|actions/github-script' \
|| true
printf '%s\n' '== Current checks and active review threads =='
gh pr checks "$pr" --repo "$repo" || true
gh api graphql -F owner='ContextualWisdomLab' -F name='.github' -F number="$pr" -f query='
query($owner: String!, $name: String!, $number: Int!) {
repository(owner: $owner, name: $name) {
pullRequest(number: $number) {
reviewThreads(first: 100) {
nodes { isResolved isOutdated comments(first: 1) { nodes { author { login } body path line } } }
}
}
}
}' |
jq '[.data.repository.pullRequest.reviewThreads.nodes[] |
select(.isResolved == false and .isOutdated == false)]'Length of output: 161260
I reviewed live head P1 — Reject invalid hashes and unbounded includes before materializationIn Therefore, each of these direct-child files can enter The first input is an option line, not a requirement. The second input has an invalid hash token. The third input has an absolute, unbounded include path.
Update
Reject option lines, malformed requirements, invalid hash tokens, absolute paths, traversal paths, and malformed include operands. Add materialization tests for each input. Assert that each source is absent from Verified controls
GitHub reports You are interacting with an AI system. |
|
Submit a formal current-head GitHub review after the current checks settle. Approve only if all exact-head checks succeed and no actionable finding remains; otherwise post the concrete blocker. Do not mutate or merge. |
|
Please submit the formal current-head review conclusion after the latest exact-head checks complete. Do not mutate or merge. |
|
Tip For best results, initiate chat on the files or code changes. 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
repo='ContextualWisdomLab/.github'
pr='785'
echo '== Live PR metadata =='
pr_json="$(gh pr view "$pr" --repo "$repo" \
--json number,state,isDraft,headRefName,headRefOid,baseRefName,baseRefOid,mergeStateStatus,reviewDecision,statusCheckRollup,reviews)"
printf '%s\n' "$pr_json" | jq '{
number, state, isDraft, headRefName, headRefOid, baseRefName, baseRefOid,
mergeStateStatus, reviewDecision,
checks: [.statusCheckRollup[] | {name, status, conclusion}]
}'
head="$(printf '%s\n' "$pr_json" | jq -r '.headRefOid')"
base="$(printf '%s\n' "$pr_json" | jq -r '.baseRefOid')"
echo '== Commit identity and changed paths =='
printf 'base=%s\nhead=%s\n' "$base" "$head"
git cat-file -e "${base}^{commit}"
git cat-file -e "${head}^{commit}"
git merge-base --is-ancestor "$base" "$head" && echo 'base_is_ancestor=true' || echo 'base_is_ancestor=false'
git diff --name-status --find-renames "$base" "$head"
echo '== Current checks =='
gh pr checks "$pr" --repo "$repo" || true
echo '== Candidate validation implementation at live head =='
git show "${head}:scripts/ci/materialize_base_python_requirements.py" |
nl -ba |
sed -n '110,190p;430,520p'
echo '== Candidate validation regressions at live head =='
for file in \
tests/test_materialize_base_python_requirements.py \
tests/test_requirements_directory_lock_materialization.py; do
if git cat-file -e "${head}:${file}" 2>/dev/null; then
echo "--- ${file}"
git show "${head}:${file}" |
nl -ba |
rg -n -C 5 -- '--hash=|--requirement|-r |requirements/ci\.txt|manifest|invalid|unpinned|absolute|traversal'
fi
done
echo '== Active review threads =='
gh api graphql -F owner='ContextualWisdomLab' -F name='.github' -F number="$pr" -f query='
query($owner: String!, $name: String!, $number: Int!) {
repository(owner: $owner, name: $name) {
pullRequest(number: $number) {
reviewThreads(first: 100) {
nodes {
isResolved
isOutdated
comments(first: 1) { nodes { author { login } body path line } }
}
}
}
}
}' | jq '[.data.repository.pullRequest.reviewThreads.nodes[] |
select(.isResolved == false and .isOutdated == false)]'Length of output: 14479 🏁 Script executed: #!/bin/bash
set -euo pipefail
repo='ContextualWisdomLab/.github'
pr='785'
head="$(gh pr view "$pr" --repo "$repo" --json headRefOid --jq '.headRefOid')"
echo '== Materializer: candidate validation and materialization =='
git show "${head}:scripts/ci/materialize_base_python_requirements.py" |
cat -n |
sed -n '110,210p;420,530p'
echo '== Tests: candidate validation and manifest assertions =='
for file in \
tests/test_materialize_base_python_requirements.py \
tests/test_requirements_directory_lock_materialization.py; do
echo "--- ${file}"
git show "${head}:${file}" |
cat -n |
grep -n -E -C 5 -- \
'requirements/ci\.txt|requirements/nested|--hash=|--requirement|-r |manifest|invalid|unpinned|absolute|traversal|symlink|directive'
done
echo '== Active non-outdated review threads =='
gh api graphql -F owner='ContextualWisdomLab' -F name='.github' -F number="$pr" -f query='
query($owner: String!, $name: String!, $number: Int!) {
repository(owner: $owner, name: $name) {
pullRequest(number: $number) {
reviewThreads(first: 100) {
nodes {
isResolved
isOutdated
comments(first: 1) {
nodes { author { login } body path line }
}
}
}
}
}
}' | jq '[.data.repository.pullRequest.reviewThreads.nodes[] |
select(.isResolved == false and .isOutdated == false)]'Length of output: 28144
I reviewed current head All listed checks have completed successfully. There are zero active non-outdated review threads. The parent-relative diff contains the declared six permanent files. P1 — Reject invalid requirement lines before materializationIn
Therefore, a direct-child
Update
Reject option lines, malformed requirements, invalid hashes, absolute include paths, traversal include paths, and malformed include operands. Add regression tests that confirm each invalid direct-child input is absent from GitHub currently reports this Draft PR as You are interacting with an AI system. |
|
@opencode-agent review Use the newest exact head only. If every required check is green and there is no actionable finding, submit formal approval; otherwise state the blocker. Do not mutate or merge. |
|
@cwl-noema-review review Use exact-current-head evidence only. Approve formally only when required checks are green and no actionable finding remains; otherwise identify the blocker. Do not mutate or merge. |
|
@opencode-agent review Do not post another top-level acknowledgement. Submit the formal exact-head review verdict through the GitHub review API when current-head checks are complete; approve only if no blocker remains. Do not mutate or merge. |
|
@coderabbitai full review Use the exact current head only and submit the review verdict through the formal GitHub review surface; do not post another summary comment, mutate, or merge. |
Rate Limit Exceeded
|
|
@cwl-noema-review Please use the GitHub review API rather than another comment for the final exact-head verdict. Do not mutate or merge. |
|
Final action expected: use the GitHub review API for the exact current head. Approve only if current required checks are successful and no actionable finding remains; otherwise post one concrete blocking review. Do not mutate or merge. |
|
@cwl-noema-review @opencode-agent Please review the exact current head after the fail-closed hash-lock classification repair. Earlier reviews and checks are stale. |
|
@cwl-noema-review Submit one formal exact-current-head review through GitHub's review API. Do not add another discussion comment, mutate, or merge. |
|
Do not acknowledge. Submit exactly one formal review on the exact current head through GitHub's review API after checks complete. Do not mutate or merge. |
|
@cwl-noema-review Do not acknowledge. Submit exactly one formal review on the exact current head through GitHub's review API after checks complete. Do not mutate or merge. |
|
Do not acknowledge. Submit exactly one formal review on the exact current head through GitHub's review API after checks complete. Do not mutate or merge. |
There was a problem hiding this comment.
Exact-head review for b3f5f7e: changes requested.
P1: scripts/ci/materialize_base_python_requirements.py does not validate candidate requirements or include operands before materialization. _is_hash_pinned() accepts any non-directive logical line containing --hash= and any line beginning with -r or --requirement . Therefore, direct-child requirements/*.txt files can enter manifest.json with an option line containing --hash=, an invalid hash token, or an absolute or traversal include. The later pip --require-hashes preflight occurs after materialization and does not enforce the candidate-selection boundary.
Require exact package pins with valid inline SHA-256 hashes. Permit only bounded relative include operands. Reject option lines, malformed hash tokens, absolute paths, traversal paths, and malformed includes. Add manifest-exclusion regression tests for each input.
GitHub also reports this pull request as DIRTY, so it is not mergeable.
|
Tip For best results, initiate chat on the files or code changes. 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
repo='ContextualWisdomLab/.github'
pr='785'
pr_json="$(gh pr view "$pr" --repo "$repo" \
--json number,state,isDraft,headRefOid,baseRefOid,mergeStateStatus,reviewDecision,statusCheckRollup,reviews)"
printf '%s\n' '== Live PR identity and checks =='
printf '%s\n' "$pr_json" | jq '{
number, state, isDraft, headRefOid, baseRefOid, mergeStateStatus, reviewDecision,
checks: [.statusCheckRollup[] | {name, status, conclusion}]
}'
head="$(printf '%s\n' "$pr_json" | jq -r '.headRefOid')"
base="$(printf '%s\n' "$pr_json" | jq -r '.baseRefOid')"
printf '%s\n' '== Commit relation and changed scope =='
printf 'base=%s\nhead=%s\n' "$base" "$head"
git cat-file -e "${base}^{commit}"
git cat-file -e "${head}^{commit}"
git merge-base --is-ancestor "$base" "$head" && echo 'base_is_ancestor=true' || echo 'base_is_ancestor=false'
git diff --name-status --find-renames "$base" "$head"
git diff --check "$base" "$head"
printf '%s\n' '== Materializer validation and materialization =='
git show "${head}:scripts/ci/materialize_base_python_requirements.py" |
nl -ba | sed -n '100,230p;430,540p'
printf '%s\n' '== Relevant regression tests =='
for file in \
tests/test_materialize_base_python_requirements.py \
tests/test_requirements_directory_lock_materialization.py; do
echo "--- ${file}"
git show "${head}:${file}" | nl -ba |
rg -n -C 6 -- 'requirements/ci\.txt|requirements/nested|require-hashes|--hash=|--requirement|-r |manifest|unpinned|invalid|absolute|traversal|symlink|directive'
done
printf '%s\n' '== Active review threads =='
gh api graphql -F owner='ContextualWisdomLab' -F name='.github' -F number="$pr" -f query='
query($owner: String!, $name: String!, $number: Int!) {
repository(owner: $owner, name: $name) {
pullRequest(number: $number) {
reviewThreads(first: 100) {
nodes {
isResolved
isOutdated
comments(first: 1) {
nodes { author { login } body path line }
}
}
}
}
}
}' | jq '[.data.repository.pullRequest.reviewThreads.nodes[] |
select(.isResolved == false and .isOutdated == false)]'Length of output: 8826 🏁 Script executed: #!/bin/bash
set -euo pipefail
repo='ContextualWisdomLab/.github'
pr='785'
head="$(gh pr view "$pr" --repo "$repo" --json headRefOid --jq '.headRefOid')"
printf '%s\n' '== Exact current head =='
printf '%s\n' "$head"
printf '%s\n' '== Materializer candidate validation and materialization =='
git show "${head}:scripts/ci/materialize_base_python_requirements.py" |
cat -n | sed -n '100,240p;430,550p'
printf '%s\n' '== Relevant materializer regression tests =='
for file in \
tests/test_materialize_base_python_requirements.py \
tests/test_requirements_directory_lock_materialization.py; do
printf '%s\n' "--- ${file}"
git show "${head}:${file}" | cat -n |
rg -n -C 6 -- 'requirements/ci\.txt|requirements/nested|require-hashes|--hash=|--requirement|-r |manifest|unpinned|invalid|absolute|traversal|symlink|directive'
done
printf '%s\n' '== Active non-outdated review threads =='
gh api graphql -F owner='ContextualWisdomLab' -F name='.github' -F number="$pr" -f query='
query($owner: String!, $name: String!, $number: Int!) {
repository(owner: $owner, name: $name) {
pullRequest(number: $number) {
reviewThreads(first: 100) {
nodes {
isResolved
isOutdated
comments(first: 1) {
nodes { author { login } body path line }
}
}
}
}
}
}' | jq '[.data.repository.pullRequest.reviewThreads.nodes[] |
select(.isResolved == false and .isOutdated == false)]'Length of output: 31716 🏁 Script executed: #!/bin/bash
set -euo pipefail
repo='ContextualWisdomLab/.github'
pr='785'
expected_head='b3f5f7e87b57d9b5b76e3c628fe5d21be84d269f'
current_head="$(gh pr view "$pr" --repo "$repo" --json headRefOid --jq '.headRefOid')"
if [ "$current_head" != "$expected_head" ]; then
printf 'Head changed; no review submitted. expected=%s current=%s\n' \
"$expected_head" "$current_head" >&2
exit 1
fi
body=$'Exact-head review for b3f5f7e87b57d9b5b76e3c628fe5d21be84d269f: changes requested.\n\nP1: `scripts/ci/materialize_base_python_requirements.py` does not validate candidate requirements or include operands before materialization. `_is_hash_pinned()` accepts any non-directive logical line containing `--hash=` and any line beginning with `-r ` or `--requirement `. Therefore, direct-child `requirements/*.txt` files can enter `manifest.json` with an option line containing `--hash=`, an invalid hash token, or an absolute or traversal include. The later `pip --require-hashes` preflight occurs after materialization and does not enforce the candidate-selection boundary.\n\nRequire exact package pins with valid inline SHA-256 hashes. Permit only bounded relative include operands. Reject option lines, malformed hash tokens, absolute paths, traversal paths, and malformed includes. Add manifest-exclusion regression tests for each input.\n\nGitHub also reports this pull request as `DIRTY`, so it is not mergeable.'
gh api --method POST "repos/${repo}/pulls/${pr}/reviews" \
-f commit_id="$current_head" \
-f event='REQUEST_CHANGES' \
-f body="$body" \
--jq '{id, state, commit_id, html_url}'Length of output: 1941
Verdict: Changes requested. The review identifies the fail-open candidate validation and the current You are interacting with an AI system. |
|
@opencode-agent @cwl-noema-review @coderabbitai No further discussion comments are needed. Complete the formal exact-current-head review through the review API only; do not mutate or merge. |
There was a problem hiding this comment.
Exact-head review for b3f5f7e: changes requested.
P1: Candidate validation remains fail-open before materialization. In scripts/ci/materialize_base_python_requirements.py, _is_hash_pinned() accepts any non-directive line containing --hash= and every -r or --requirement line. base_hash_locks() then writes the accepted direct-child requirements/*.txt candidate into the manifest before independent pip --require-hashes closure preflight.
This permits option lines that contain --hash=, malformed hash tokens, and absolute, traversal, or malformed requirement includes to gain candidate status. The later preflight can reject installation, but it does not enforce the required materialization boundary.
Require an exact package == pin with one or more valid inline SHA-256 hashes. Permit only bounded relative requirement includes. Reject option lines, malformed hashes, absolute paths, traversal paths, and malformed include operands. Add manifest-exclusion tests for each invalid input.
GitHub also reports this pull request as DIRTY, so the exact head is not mergeable.
|
Tip For best results, initiate chat on the files or code changes. 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
repo='ContextualWisdomLab/.github'
pr='785'
pr_json="$(gh pr view "$pr" --repo "$repo" \
--json number,state,isDraft,headRefOid,baseRefOid,mergeStateStatus,reviewDecision,statusCheckRollup,reviews)"
printf '%s\n' '== Live PR identity and checks =='
printf '%s\n' "$pr_json" | jq '{
number, state, isDraft, headRefOid, baseRefOid, mergeStateStatus, reviewDecision,
checks: [.statusCheckRollup[] | {name, status, conclusion}]
}'
head="$(printf '%s\n' "$pr_json" | jq -r '.headRefOid')"
base="$(printf '%s\n' "$pr_json" | jq -r '.baseRefOid')"
printf '%s\n' '== Commit relation and changed scope =='
printf 'base=%s\nhead=%s\n' "$base" "$head"
git cat-file -e "${base}^{commit}"
git cat-file -e "${head}^{commit}"
git merge-base --is-ancestor "$base" "$head" && echo 'base_is_ancestor=true' || echo 'base_is_ancestor=false'
git diff --name-status --find-renames "$base" "$head"
git diff --check "$base" "$head"
printf '%s\n' '== Candidate validation and materialization at live head =='
git show "${head}:scripts/ci/materialize_base_python_requirements.py" |
nl -ba | sed -n '100,250p;430,560p'
printf '%s\n' '== Relevant regression coverage at live head =='
for file in \
tests/test_materialize_base_python_requirements.py \
tests/test_requirements_directory_lock_materialization.py; do
printf '%s\n' "--- ${file}"
git show "${head}:${file}" | nl -ba |
rg -n -C 6 -- \
'requirements/ci\.txt|requirements/nested|require-hashes|--hash=|--requirement|-r |manifest|unpinned|invalid|absolute|traversal|symlink|directive'
done
printf '%s\n' '== Active non-outdated review threads =='
gh api graphql -F owner='ContextualWisdomLab' -F name='.github' -F number="$pr" -f query='
query($owner: String!, $name: String!, $number: Int!) {
repository(owner: $owner, name: $name) {
pullRequest(number: $number) {
reviewThreads(first: 100) {
nodes {
isResolved
isOutdated
comments(first: 1) {
nodes { author { login } body path line }
}
}
}
}
}
}' | jq '[.data.repository.pullRequest.reviewThreads.nodes[] |
select(.isResolved == false and .isOutdated == false)]'Length of output: 8892 🏁 Script executed: #!/bin/bash
set -euo pipefail
repo='ContextualWisdomLab/.github'
pr='785'
head="$(gh pr view "$pr" --repo "$repo" --json headRefOid --jq '.headRefOid')"
printf '== Exact live head ==\n%s\n' "$head"
printf '%s\n' '== Candidate validation and materialization =='
git show "${head}:scripts/ci/materialize_base_python_requirements.py" |
cat -n | sed -n '100,250p;430,560p'
printf '%s\n' '== Relevant regression coverage =='
for file in \
tests/test_materialize_base_python_requirements.py \
tests/test_requirements_directory_lock_materialization.py; do
printf '%s\n' "--- ${file}"
git show "${head}:${file}" | cat -n |
rg -n -C 6 -- \
'requirements/ci\.txt|requirements/nested|require-hashes|--hash=|--requirement|-r |manifest|unpinned|invalid|absolute|traversal|symlink|directive' \
|| true
done
printf '%s\n' '== Active non-outdated review threads =='
gh api graphql -F owner='ContextualWisdomLab' -F name='.github' -F number="$pr" -f query='
query($owner: String!, $name: String!, $number: Int!) {
repository(owner: $owner, name: $name) {
pullRequest(number: $number) {
reviewThreads(first: 100) {
nodes {
isResolved
isOutdated
comments(first: 1) {
nodes { author { login } body path line }
}
}
}
}
}
}' | jq '[.data.repository.pullRequest.reviewThreads.nodes[] |
select(.isResolved == false and .isOutdated == false)]'Length of output: 32443 🏁 Script executed: #!/bin/bash
set -euo pipefail
repo='ContextualWisdomLab/.github'
pr='785'
expected_head='b3f5f7e87b57d9b5b76e3c628fe5d21be84d269f'
current_head="$(gh pr view "$pr" --repo "$repo" --json headRefOid --jq '.headRefOid')"
if [ "$current_head" != "$expected_head" ]; then
printf 'Head changed; review was not submitted. expected=%s current=%s\n' \
"$expected_head" "$current_head" >&2
exit 1
fi
body=$'Exact-head review for b3f5f7e87b57d9b5b76e3c628fe5d21be84d269f: changes requested.\n\nP1: Candidate validation remains fail-open before materialization. In `scripts/ci/materialize_base_python_requirements.py`, `_is_hash_pinned()` accepts any non-directive line containing `--hash=` and every `-r ` or `--requirement ` line. `base_hash_locks()` then writes the accepted direct-child `requirements/*.txt` candidate into the manifest before independent `pip --require-hashes` closure preflight.\n\nThis permits option lines that contain `--hash=`, malformed hash tokens, and absolute, traversal, or malformed requirement includes to gain candidate status. The later preflight can reject installation, but it does not enforce the required materialization boundary.\n\nRequire an exact package `==` pin with one or more valid inline SHA-256 hashes. Permit only bounded relative requirement includes. Reject option lines, malformed hashes, absolute paths, traversal paths, and malformed include operands. Add manifest-exclusion tests for each invalid input.\n\nGitHub also reports this pull request as `DIRTY`, so the exact head is not mergeable.'
gh api --method POST "repos/${repo}/pulls/${pr}/reviews" \
-f commit_id="$current_head" \
-f event='REQUEST_CHANGES' \
-f body="$body" \
--jq '{id, state, commit_id, html_url}'Length of output: 2073
You are interacting with an AI system. |
Buyer and review problem
Central OpenCode coverage discovers conventional
requirements*.txtnames but historically ignored complete hash-pinned locks stored as direct children such asrequirements/ci.txt. Infast-mlsirm#546, the authenticated base contained a generated NumPy-bearingrequirements/ci.txt, yet central coverage materialized no usable lock and measured a dependency-free image rather than the changed production code.Exact implementation head
Current exact head:
b3f5f7e87b57d9b5b76e3c628fe5d21be84d269f.The feature diff contains only six permanent files and no branch-writing, self-removing, encoded-patch, trigger, or temporary repair workflow:
.github/workflows/trusted-uv-materializer-quality-ci.ymlCHANGELOG.mddocs/doctoring/trusted-requirements-directory-lock-discovery.mdscripts/ci/materialize_base_python_requirements.pytests/test_materialize_base_python_requirements.pytests/test_requirements_directory_lock_materialization.pyThe current head also merges protected
main; that merge carries the accepted log-redaction optimization and does not expand this feature boundary.Accepted trust boundary
The materializer recognizes a
.txtfile only when it is a direct child of a directory namedrequirements, in addition to the pre-existing conventional lock names. Candidate status does not grant trust by itself.--require-hashesdirective is not trust evidence by itself and a directive-only file is rejected.pip --require-hashesclosure..txtfiles, pull-request-only files, and malformed Git trees remain excluded.Test-first verification
The permanent regression suite proves direct-child discovery, deeper/unrelated rejection, realistic base-commit materialization, exclusion of unpinned
.inand note files, and rejection of--require-hashescombined with an unpinned package.Verified branch evidence includes:
77 passed;256/256;74/74;905 passed; and100%.Exact head
b3f5f7e87b57d9b5b76e3c628fe5d21be84d269fhas successful Trusted uv Materializer Quality CI, Python Security, Security Scan, CodeQL PR, SAST Semgrep, Secret Scan, OSV-Scanner PR, Scorecard PR, and SBOM Generation.Downstream activation
After protected merge, affected product PRs such as
fast-mlsirm#546,#549,#550, and#556must rerun the central exact-head coverage/review path. Predecessor failures and local-only evidence do not transfer.Merge gate
Merge only after current-head CodeRabbit, OpenCode, Noema, any other repository-required review surface, a qualifying non-author approval, zero unresolved actionable threads, and branch protection are satisfied without bypass.