Skip to content

fix(coverage): materialize requirements-directory locks - #785

Draft
seonghobae wants to merge 34 commits into
mainfrom
fix/coverage-materialize-requirements-directory-locks
Draft

fix(coverage): materialize requirements-directory locks#785
seonghobae wants to merge 34 commits into
mainfrom
fix/coverage-materialize-requirements-directory-locks

Conversation

@seonghobae

@seonghobae seonghobae commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Buyer and review problem

Central OpenCode coverage historically discovered conventional requirements*.txt names but ignored complete base-owned locks stored as direct children such as requirements/ci.txt. In fast-mlsirm#546, that meant the isolated coverage image could measure a dependency-free environment rather than the changed production code.

The first implementation then exposed a second, more important trust-boundary defect: candidate qualification treated any line containing --hash= or beginning with -r / --requirement as trusted enough to materialize. That allowed range requirements, malformed digests, option lines, absolute/traversal includes, and malformed include operands to enter the trusted build context before the independent pip closure preflight.

Exact current head

Current exact head: dcc539176271658f024de7419044f513c6fb7317.

The feature diff remains six permanent files:

  • .github/workflows/trusted-uv-materializer-quality-ci.yml
  • CHANGELOG.md
  • docs/doctoring/trusted-requirements-directory-lock-discovery.md
  • scripts/ci/materialize_base_python_requirements.py
  • tests/test_materialize_base_python_requirements.py
  • tests/test_requirements_directory_lock_materialization.py

No branch-writing, self-removing, encoded-patch, trigger, or temporary repair workflow is part of the final feature scope.

Accepted trust boundary

A .txt file may become a candidate when it is a direct child of a directory named requirements, in addition to the existing conventional lock names. Candidate path eligibility does not grant dependency trust.

  • Source must be a regular blob in the authenticated base commit.
  • Candidate paths remain relative, traversal-free, and non-symlink Git blobs.
  • Every substantive package line must be an exact == pin with one or more complete 64-hex SHA-256 --hash= values.
  • A global --require-hashes directive is not trust evidence by itself.
  • Requirement includes are limited to the two-token -r / --requirement form with a bounded relative operand.
  • Absolute paths, .., URL/scheme syntax, home expansion, backslashes, query/fragment syntax, option-like operands, extra inline options/hashes, range pins, malformed hashes, and pip option lines are rejected before materialization.
  • The exact trusted source path is recorded in the manifest.
  • The existing downstream installer still preflights every candidate as an independently complete pip --require-hashes closure. Parser eligibility does not replace dependency-closure proof.
  • Unpinned inputs, notes, deeper descendants, unrelated .txt files, PR-only files, malformed Git trees, and unsafe includes remain excluded.

Test-first evidence

The security hardening was driven by an exact RED head before production repair. At 4914e124c339f93bac5da42aeaf649ed893315d4, Trusted uv Materializer Quality CI reported 12 failed, 77 passed: the failures reproduced range-pin, malformed-hash, option-line, absolute/traversal include, extra-option include, and manifest-admission defects.

At the exact current head dcc539176271658f024de7419044f513c6fb7317, the Python 3.14 quality job checked out that exact SHA and succeeded with:

  • focused materializer suite: 97 passed;
  • materializer statement coverage: 265/265;
  • materializer branch coverage: 78/78;
  • complete central suite: 925 passed;
  • complete owned production statement coverage: 6588/6588;
  • complete owned production branch coverage: 2626/2626;
  • public docstring coverage for the changed production module: 100.0%; and
  • production/test compilation successful.

The separate Python 3.10 compatibility contract also succeeded on the same exact head.

Exact-head gates

All 10 pull-request workflows completed successfully on dcc539176271658f024de7419044f513c6fb7317:

  • Trusted uv Materializer Quality CI
  • Strix Changed Path Quality CI
  • CodeQL PR
  • Python Security
  • Security Scan
  • SAST Semgrep
  • Secret Scan
  • OSV-Scanner PR
  • Scorecard PR
  • SBOM Generation

The older OpenCode and CodeRabbit CHANGES_REQUESTED reviews were submitted against predecessor head b3f5f7e87b57d9b5b76e3c628fe5d21be84d269f. Their two concrete objections—merge conflict and fail-open candidate validation—are historical: GitHub now reports the current PR mergeable, and the source/test repair above directly closes the candidate-validation finding. They are not current-head approvals.

Downstream activation

After protected integration, affected product PRs such as fast-mlsirm#546, #549, #550, and #556 must rerun the central exact-head coverage/review path. Predecessor failures and local-only evidence do not transfer.

Merge gate

This PR remains Draft until current-head automated review, any repository-required review surface, a qualifying independent non-author formal approval, zero valid unresolved actionable threads, live branch protection, independently resolved live-base compatibility, and protected expected-head merge authority are all satisfied. Do not bypass or infer those authorities from the green machine workflows above.

@coderabbitai

coderabbitai Bot commented Aug 5, 2026

Copy link
Copy Markdown

Important

Review skipped

Draft detected.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: cd87250e-b55c-4b68-ada3-4562188812d7

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@seonghobae seonghobae closed this Aug 5, 2026
@seonghobae seonghobae reopened this Aug 5, 2026
@seonghobae seonghobae closed this Aug 5, 2026
@seonghobae seonghobae reopened this Aug 5, 2026
@seonghobae seonghobae closed this Aug 5, 2026
@seonghobae seonghobae reopened this Aug 5, 2026
Comment thread .github/workflows/reopen-requirements-directory-locks.yml Fixed
Comment thread .github/workflows/repair-requirements-directory-locks.yml Fixed
@seonghobae
seonghobae marked this pull request as ready for review August 6, 2026 04:54
@seonghobae
seonghobae enabled auto-merge (squash) August 6, 2026 04:55

Copy link
Copy Markdown
Contributor Author

@opencode-agent @cwl-noema-review

Perform an independent formal exact-head review of ed33253e5d6f93f2e71d80b24e27b301f96efb88 against protected main f070c504c1cb06891b800d7ab0cf6ac7d3cf8eae. Do not reuse predecessor-head verdicts.

The final diff contains only the permanent five-file product change; all transient repair workflows and transformers are absent. Recompute current-head coverage and public-docstring evidence; verify that only direct .txt children of a directory named requirements gain candidate status, while regular authenticated-base blobs, traversal/path safety, complete hash pinning, independently installable closure preflight, exact source receipts, and rejection of symlinks, PR-only files, nested descendants, .in files, and unpinned notes remain fail-closed. The verified materialization run passed 70 focused tests, 898 complete tests, production statement/branch coverage 100%, and docstrings 100%. Submit a formal exact-head verdict only; a qualifying independent non-author approval and branch protection remain mandatory.

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

@opencode-agent @cwl-noema-review Independently review exact current head ed33253e5d6f93f2e71d80b24e27b301f96efb88 against protected main at f070c504c1cb06891b800d7ab0cf6ac7d3cf8eae.

The exact head is workflow-free and all direct current-head security, supply-chain, and Trusted uv Materializer Quality checks are successful. Verify the narrow direct-child requirements/*.txt candidate rule, authenticated-base regular-blob requirement, traversal/deeper-path/symlink/PR-only rejection, complete hash-locked closure preflight, exact manifest provenance, Python 3.10/3.14 compatibility, 100% production statement/branch/docstring evidence, and removal of every temporary branch writer. Submit actionable findings or an exact-head formal review; independent approval and branch protection remain mandatory.

@coderabbitai

coderabbitai Bot commented Aug 6, 2026

Copy link
Copy Markdown

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

base='f070c504c1cb06891b800d7ab0cf6ac7d3cf8eae'
head='ed33253e5d6f93f2e71d80b24e27b301f96efb88'

printf '\n== Exact commits ==\n'
git cat-file -e "${base}^{commit}"
git cat-file -e "${head}^{commit}"
git show -s --format='base=%H%nbase-subject=%s%nbase-date=%cI' "$base"
git show -s --format='head=%H%nhead-subject=%s%nhead-date=%cI' "$head"

printf '\n== Changed files and stat ==\n'
git diff --name-status "$base" "$head"
git diff --stat "$base" "$head"

printf '\n== Full product diff ==\n'
git diff --find-renames --find-copies --no-ext-diff "$base" "$head"

printf '\n== Candidate source maps for changed Python files ==\n'
git diff --name-only "$base" "$head" -- '*.py' |
while IFS= read -r file; do
  [ -n "$file" ] || continue
  echo "--- $file"
  ast-grep outline "$file" --items all --view compact || true
done

printf '\n== Candidate discovery and provenance references at exact head ==\n'
rg -n -C 4 --glob '*.py' \
  '(requirements|require-hashes|materiali[sz]|manifest|symlink|git\s+cat-file|ls-tree|blob|traversal)' .

printf '\n== Workflow inventory and write-capable workflow references ==\n'
fd -t f -e yml -e yaml .github 2>/dev/null || true
rg -n -i -C 3 --glob '*.yml' --glob '*.yaml' \
  '(contents:\s*write|pull-requests:\s*write|actions/github-script|git\s+push|force-with-lease|workflow_dispatch)' \
  .github 2>/dev/null || true

printf '\n== Relevant tests and documentation references ==\n'
rg -n -C 3 --glob '*test*.py' --glob '*.md' \
  '(requirements/|requirements\*\.txt|require-hashes|materiali[sz]|manifest|symlink|nested|PR-only)' .

printf '\n== PR metadata, checks, and review state ==\n'
gh pr view 785 --repo ContextualWisdomLab/.github \
  --json number,state,isDraft,headRefOid,baseRefOid,mergeStateStatus,reviewDecision,statusCheckRollup,reviews \
  || true

Length of output: 202327


🏁 Script executed:

#!/bin/bash
set -euo pipefail

base='f070c504c1cb06891b800d7ab0cf6ac7d3cf8eae'
head='ed33253e5d6f93f2e71d80b24e27b301f96efb88'

printf '\n== Exact changed files ==\n'
git diff --name-status "$base" "$head"
printf '\n== Exact changed-file diff ==\n'
git diff --no-ext-diff --unified=80 "$base" "$head"

printf '\n== Materializer complete source map ==\n'
ast-grep outline scripts/ci/materialize_base_python_requirements.py --items all --view expanded

printf '\n== Materializer candidate and base-lock implementation ==\n'
rg -n -C 12 \
  'def (_is_candidate_lock_name|_is_candidate_lock_path|_is_hash_pinned|base_hash_locks|materialize|_regular|_git|_lock_blob)|manifest' \
  scripts/ci/materialize_base_python_requirements.py

printf '\n== Materializer full source, bounded ==\n'
cat -n scripts/ci/materialize_base_python_requirements.py

printf '\n== New requirements-directory regression test ==\n'
cat -n tests/test_requirements_directory_lock_materialization.py

printf '\n== Existing Python materializer boundary tests: relevant regions ==\n'
rg -n -C 10 \
  '(regular|symlink|traversal|nested|PR-modified|hash.pinned|manifest|base_hash_locks|require-hashes)' \
  tests/test_materialize_base_python_requirements.py

printf '\n== Install closure preflight implementation and tests ==\n'
fd -t f 'install_base_python_locks.py|test_install_base_python_locks.py' . -x sh -c '
  echo "--- $1"
  cat -n "$1"
' sh {} \;

printf '\n== Exact-head workflow files changed by this diff, if any ==\n'
git diff --name-only "$base" "$head" -- .github/workflows |
while IFS= read -r file; do
  [ -n "$file" ] && { echo "--- $file"; cat -n "$file"; }
done

printf '\n== Workflow writers introduced by the exact diff ==\n'
git diff --no-ext-diff "$base" "$head" -- .github |
rg -n -i -C 3 '(contents:\s*write|git\s+push|force-with-lease|gh\s+(api|pr|workflow)|workflow_dispatch)' || true

printf '\n== Current PR check summary, grouped ==\n'
gh pr checks 785 --repo ContextualWisdomLab/.github || true

Length of output: 127039


🏁 Script executed:

#!/bin/bash
set -euo pipefail

repo='ContextualWisdomLab/.github'
head='ed33253e5d6f93f2e71d80b24e27b301f96efb88'

printf '\n== Exact-head materializer and installer calls in coverage workflows ==\n'
rg -n -C 8 --glob '*.yml' --glob '*.yaml' \
  '(materialize_base_python_requirements\.py|install_base_python_locks\.py|base-python-requirements|--base-sha|--requirements-root)' \
  .github/workflows

printf '\n== Candidate-status hash-pin regression coverage ==\n'
rg -n -C 8 --glob 'test*.py' \
  '(--require-hashes.*(unpinned|>=)|_is_hash_pinned|requirements/ci\.txt|requirements/nested|symlink|PR-modified)' \
  tests

printf '\n== Exact quality workflow runs and their logs ==\n'
gh run list --repo "$repo" --commit "$head" --workflow 'Trusted uv Materializer Quality CI' \
  --limit 10 --json databaseId,headSha,status,conclusion,createdAt,updatedAt,url \
  || true
for run_id in $(gh run list --repo "$repo" --commit "$head" --workflow 'Trusted uv Materializer Quality CI' \
  --limit 10 --json databaseId --jq '.[].databaseId' 2>/dev/null); do
  echo "--- quality run $run_id"
  gh run view "$run_id" --repo "$repo" --log 2>&1 | rg -n -C 4 \
    '(passed|failed|FAIL|TOTAL|100%|coverage|interrogate|docstring|Python 3\.10|Python 3\.14)' \
    || true
done

printf '\n== Current Strix and failed-status details ==\n'
gh pr checks 785 --repo "$repo" --json name,state,link,bucket \
  | jq -r '.[] | select(.name == "strix" or .name == "publish-manual-pr-evidence-status")' \
  || true

printf '\n== Branch protection / rulesets for main ==\n'
gh api "repos/${repo}/branches/main/protection" 2>&1 | jq '{required_status_checks,required_pull_request_reviews,enforce_admins,required_linear_history,allow_force_pushes,allow_deletions}' \
  || true
gh api "repos/${repo}/rulesets" 2>&1 | jq '.[] | {name,enforcement,target,conditions,rules}' \
  || true

Length of output: 207047


@seonghobae Exact-head review verdict: changes requested.

I reviewed ed33253e5d6f93f2e71d80b24e27b301f96efb88 against f070c504c1cb06891b800d7ab0cf6ac7d3cf8eae.

Finding — P1: Do not materialize an unpinned direct-child lock

In scripts/ci/materialize_base_python_requirements.py at Line 100, the new direct-child rule delegates content validation to _is_hash_pinned().

_is_hash_pinned() returns True for this content:

--require-hashes
demo==1

The existing test at tests/test_materialize_base_python_requirements.py Line 153 confirms this behavior. The file has no hashes for demo==1.

Therefore, a base-owned requirements/ci.txt with this content gains candidate status and is written into manifest.json. The later pip --require-hashes preflight detects the incomplete closure, but the installer classifies this failure as deferable and skips the candidate.

This violates the stated boundary that only complete hash-pinned locks gain candidate status. It also conflicts with the new doctoring document, which says that candidate content must be hash-pinned.

Update candidate validation so an unpinned direct-child .txt file is rejected before materialization. Add a regression case for requirements/ci.txt with a global --require-hashes directive and an unpinned requirement. Assert that it is absent from the materialization manifest.

Verified controls

  • The diff contains exactly five permanent product files.
  • The changed quality workflow has contents: read.
  • The exact diff introduces no write-capable repair workflow or branch writer.
  • The direct-child predicate accepts only .txt files whose immediate parent is named requirements.
  • Nested descendants such as requirements/nested/ci.txt remain rejected.
  • Exact-base Git tree parsing admits regular 100* blobs only.
  • The materializer rejects symlinks, non-blob entries, absolute paths, and traversal paths.
  • The materializer reads selected content from the authenticated base SHA.
  • PR-only content cannot enter the base materialization result.
  • The manifest records the exact source path.
  • The coverage image runs the trusted installer with independent pip --require-hashes preflight.
  • The quality workflow checked out the requested exact head.
  • The quality run passed 70 focused tests and 898 complete tests.
  • Focused and complete statement/branch coverage were 100%.
  • The docstring gate reported 100%.
  • Python 3.10 and Python 3.14 checks passed.

strix was still in progress during verification. The branch-protection API response was inconclusive. These merge-gate items remain unverified.

You are interacting with an AI system.

Copy link
Copy Markdown
Contributor Author

@opencode-agent @cwl-noema-review @coderabbitai review

Review-only request for exact current head ed33253e5d6f93f2e71d80b24e27b301f96efb88 against protected main f070c504c1cb06891b800d7ab0cf6ac7d3cf8eae. Trusted uv Materializer Quality CI and every exact-head security/supply-chain workflow are successful; the final diff is workflow-free, all prior token-permission threads are resolved/outdated, and unresolved threads are zero. Validate direct-child requirements/*.txt discovery, authenticated-base regular-file and hash-pin boundaries, independent pip --require-hashes closure preflight, manifest provenance, 100% statement/branch/docstring evidence, and absence of transient writer machinery. Do not mutate the branch or merge; submit actionable findings or a formal exact-head review.

@coderabbitai

coderabbitai Bot commented Aug 6, 2026

Copy link
Copy Markdown

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

base='f070c504c1cb06891b800d7ab0cf6ac7d3cf8eae'
head='ed33253e5d6f93f2e71d80b24e27b301f96efb88'
repo='ContextualWisdomLab/.github'

printf '%s\n' '== Exact commits =='
git cat-file -e "${base}^{commit}"
git cat-file -e "${head}^{commit}"
git show -s --format='base %H%n%cs %s' "$base"
git show -s --format='head %H%n%cs %s' "$head"

printf '%s\n' '== Exact changed files =='
git diff --name-status --find-renames "$base" "$head"
git diff --stat "$base" "$head"

printf '%s\n' '== Exact diff =='
git diff --no-ext-diff --find-renames --unified=60 "$base" "$head"

printf '%s\n' '== Changed Python file outlines =='
git diff --name-only "$base" "$head" -- '*.py' |
while IFS= read -r file; do
  test -n "$file" || continue
  printf '\n--- %s ---\n' "$file"
  ast-grep outline "$file" --items all --view expanded || true
done

printf '%s\n' '== Materializer candidate, content-validation, tree, and manifest regions =='
rg -n -C 12 --glob 'materialize_base_python_requirements.py' \
  'def (_is_candidate_lock_name|_is_candidate_lock_path|_is_hash_pinned|_.*regular.*|_.*tree.*|materialize)|require-hashes|hash|manifest|ls-tree|cat-file|symlink|traversal' .

printf '%s\n' '== Installer preflight regions =='
rg -n -C 10 --glob 'install_base_python_locks.py' \
  'require-hashes|preflight|manifest|pip|closure|defer|skip|install' .

printf '%s\n' '== Relevant regression-test regions =='
rg -n -C 10 --glob 'test*.py' \
  'requirements/ci\.txt|requirements/nested|require-hashes|unpinned|hash-pinned|symlink|traversal|PR-only|manifest|base_hash_locks' tests

printf '%s\n' '== Workflow inventory and exact-diff write capability scan =='
fd -t f -e yml -e yaml .github 2>/dev/null || true
git diff --no-ext-diff "$base" "$head" -- .github |
  rg -n -i -C 3 'contents:\s*write|pull-requests:\s*write|git\s+push|force-with-lease|workflow_dispatch|actions/github-script' || true

printf '%s\n' '== Current PR and check metadata =='
gh pr view 785 --repo "$repo" \
  --json state,isDraft,headRefOid,baseRefOid,mergeStateStatus,reviewDecision,statusCheckRollup,reviews
gh pr checks 785 --repo "$repo" || true

Length of output: 202643


@seonghobae Exact-head review verdict: changes requested.

I reviewed ed33253e5d6f93f2e71d80b24e27b301f96efb88 against f070c504c1cb06891b800d7ab0cf6ac7d3cf8eae.

P1 — Reject incomplete direct-child locks before materialization

tests/test_materialize_base_python_requirements.py Line 153 proves that _is_hash_pinned() accepts this content:

--require-hashes
demo==1

This file has no hash for demo==1.

The new direct-child rule accepts requirements/ci.txt. The materializer uses _is_hash_pinned() to grant candidate status. Therefore, a base-owned requirements/ci.txt with the content above can enter manifest.json.

The later independent pip --require-hashes preflight detects the missing hash. That preflight is necessary, but it occurs after candidate selection. It does not satisfy the required boundary that candidate status requires a complete hash-pinned lock.

Update the candidate validation to require a hash for every requirement before materialization. Add a regression test for requirements/ci.txt containing a global --require-hashes directive and an unhashed requirement. Assert that the file is absent from the materialization manifest.

Verified controls

  • The direct-child rule accepts requirements/ci.txt.
  • The direct-child rule rejects requirements/nested/ci.txt.
  • The materializer uses authenticated-base Git content.
  • The materializer has regular-file, path-safety, and symlink rejection controls.
  • The installer has an independent pip --require-hashes preflight.
  • The exact-head quality checks report successful Python 3.10 compatibility and Python 3.14 quality gates.
  • The current security and supply-chain check runs report success.
  • The current OpenCode coverage evidence reports success.

The PR is still blocked and requires review according to current GitHub metadata. I cannot approve while the incomplete-lock candidate path remains.

You are interacting with an AI system.

Copy link
Copy Markdown
Contributor Author

@jules Replace the current self-removing repair workflow with ordinary reviewed source commits on this branch. The product diff must contain only the permanent requirements-directory lock discovery, coverage/workflow contract, tests, doctoring, and CHANGELOG changes; no temporary writer, force-with-lease publisher, self-delete mechanism, or expected-RED artifact may remain.

Implement the narrow direct-child rule for regular base-owned requirements/*.txt locks while preserving traversal, symlink, malformed tree, unpinned input, and full pip --require-hashes closure failures. Add exact tests proving requirements/ci.txt is discovered for fast-mlsirm, deeper/unrelated files are excluded, and the workflow installs the authenticated base-owned lock in the isolated sandbox. Keep Draft until the branch is workflow-free and exact-head quality, coverage, docstrings, security, OpenCode/Noema/CodeRabbit, and independent approval gates pass.

Copy link
Copy Markdown
Contributor Author

@coderabbitai review
@opencode-agent review
@cwl-noema-review review
@strix review

Review exact current head ed33253e5d6f93f2e71d80b24e27b301f96efb88. The branch is workflow-free and contains only the permanent direct-child requirements/*.txt materializer rule, focused tests, trusted quality-workflow coverage, doctoring, and CHANGELOG. Trusted uv Quality, Python Security, Security Scan, CodeQL, Semgrep, Secret Scan, OSV, Scorecard, and SBOM are successful on this head; unresolved current-head threads are zero. Review only—do not update, self-approve, bypass protections, or merge.

@coderabbitai

coderabbitai Bot commented Aug 6, 2026

Copy link
Copy Markdown

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

base='f070c504c1cb06891b800d7ab0cf6ac7d3cf8eae'
head='ed33253e5d6f93f2e71d80b24e27b301f96efb88'
repo='ContextualWisdomLab/.github'

printf '\n== Exact commits ==\n'
git cat-file -e "${base}^{commit}"
git cat-file -e "${head}^{commit}"
git show -s --format='base=%H%n%s%n%cs' "$base"
git show -s --format='head=%H%n%s%n%cs' "$head"

printf '\n== Changed files ==\n'
git diff --name-status --find-renames "$base" "$head"
git diff --stat "$base" "$head"

printf '\n== Exact diff ==\n'
git diff --no-ext-diff --find-renames --unified=50 "$base" "$head"

printf '\n== Materializer outline ==\n'
materializer="$(fd -t f '^materialize_base_python_requirements\.py$' . | head -n1)"
test -n "$materializer"
ast-grep outline "$materializer" --items all --view expanded

printf '\n== Materializer validation, tree, and manifest code ==\n'
rg -n -C 14 \
  'def (_is_candidate_lock_name|_is_candidate_lock_path|_is_hash_pinned|_.*tree.*|_.*regular.*|materialize)|--require-hashes|--hash|manifest|ls-tree|cat-file|symlink|traversal|base_hash_locks' \
  "$materializer"

printf '\n== Installer preflight code ==\n'
fd -t f '^install_base_python_locks\.py$' . -x sh -c '
  ast-grep outline "$1" --items all --view expanded
  rg -n -C 12 "require-hashes|preflight|manifest|pip|closure|skip|defer|install" "$1"
' sh {}

printf '\n== Relevant test code ==\n'
fd -t f -e py . tests -x sh -c '
  if rg -q "requirements/ci\.txt|requirements/nested|_is_hash_pinned|--require-hashes|base_hash_locks|symlink|PR-only|manifest" "$1"; then
    echo "--- $1"
    rg -n -C 10 "requirements/ci\.txt|requirements/nested|_is_hash_pinned|--require-hashes|base_hash_locks|symlink|PR-only|manifest" "$1"
  fi
' sh {}

printf '\n== Workflow files changed by exact diff ==\n'
git diff --name-only "$base" "$head" -- .github/workflows |
while IFS= read -r file; do
  test -n "$file" || continue
  echo "--- $file"
  git show "${head}:${file}" | nl -ba
done

printf '\n== Write-capability scan in exact workflow diff ==\n'
git diff --no-ext-diff "$base" "$head" -- .github |
  rg -n -i -C 3 'contents:\s*write|pull-requests:\s*write|git\s+push|force-with-lease|workflow_dispatch|actions/github-script' || true

printf '\n== Current PR metadata and checks ==\n'
gh pr view 785 --repo "$repo" \
  --json state,isDraft,headRefOid,baseRefOid,mergeStateStatus,reviewDecision,statusCheckRollup,reviews
gh pr checks 785 --repo "$repo" || true

printf '\n== Current unresolved review threads ==\n'
gh api graphql -F owner='ContextualWisdomLab' -F name='.github' -F number=785 -f query='
query($owner: String!, $name: String!, $number: Int!) {
  repository(owner: $owner, name: $name) {
    pullRequest(number: $number) {
      reviewThreads(first: 100) { nodes { isResolved } }
    }
  }
}' | jq '[.data.repository.pullRequest.reviewThreads.nodes[] | select(.isResolved == false)] | length'

Length of output: 130146


🏁 Script executed:

#!/bin/bash
set -euo pipefail

base='f070c504c1cb06891b800d7ab0cf6ac7d3cf8eae'
head='ed33253e5d6f93f2e71d80b24e27b301f96efb88'
repo='ContextualWisdomLab/.github'

printf '\n== Exact changed workflow at requested head ==\n'
git show "${head}:.github/workflows/trusted-uv-materializer-quality-ci.yml" | sed -n '1,240p'

printf '\n== Write-capability tokens in the exact workflow diff ==\n'
git diff --no-ext-diff "$base" "$head" -- .github/workflows |
  rg -n -i -C 3 'contents:\s*write|pull-requests:\s*write|issues:\s*write|id-token:\s*write|git\s+push|force-with-lease|workflow_dispatch|actions/github-script' || true

printf '\n== PR exact-head metadata and check rollup ==\n'
gh pr view 785 --repo "$repo" \
  --json state,isDraft,headRefOid,baseRefOid,mergeStateStatus,reviewDecision,statusCheckRollup,reviews

printf '\n== Current check summary ==\n'
gh pr checks 785 --repo "$repo" || true

printf '\n== Current unresolved review-thread count ==\n'
gh api graphql -F owner='ContextualWisdomLab' -F name='.github' -F number=785 -f query='
query($owner: String!, $name: String!, $number: Int!) {
  repository(owner: $owner, name: $name) {
    pullRequest(number: $number) {
      reviewThreads(first: 100) { nodes { isResolved } }
    }
  }
}' | jq '[.data.repository.pullRequest.reviewThreads.nodes[] | select(.isResolved == false)] | length'

printf '\n== Requested head workflow runs ==\n'
gh run list --repo "$repo" --commit "$head" --limit 100 \
  --json name,headSha,status,conclusion,url \
  --jq '.[] | select(.headSha == "'"$head"'") | [.name,.status,.conclusion,.url] | `@tsv`' \
  || true

Length of output: 45429


@seonghobae Exact-head review verdict: changes requested.

I reviewed ed33253e5d6f93f2e71d80b24e27b301f96efb88 against f070c504c1cb06891b800d7ab0cf6ac7d3cf8eae.

P1 — Reject incomplete direct-child locks before materialization

In scripts/ci/materialize_base_python_requirements.py at Line 139, _is_hash_pinned() returns True when any line is exactly --require-hashes.

The existing test in tests/test_materialize_base_python_requirements.py at Line 153 confirms that this content is accepted:

--require-hashes
demo==1

demo==1 has no hash. A direct-child path such as requirements/ci.txt passes the new path rule. The materializer then writes this file into manifest.json.

The later pip --require-hashes preflight detects the missing hash. However, scripts/ci/install_base_python_locks.py classifies this failure as deferable and skips an unrecovered candidate. The coverage image can therefore continue without the intended dependency closure.

This behavior conflicts with the stated boundary that a candidate must be completely hash-pinned before materialization.

Update the candidate-content validation so every requirement has a valid hash before the materializer emits the manifest entry. Add a regression test for requirements/ci.txt containing --require-hashes and an unhashed requirement. Assert that the file is absent from the materialization result and manifest.json.

Verified controls

  • The diff contains five permanent product files.
  • The direct-child rule accepts requirements/ci.txt and services/.../requirements/package.txt.
  • The direct-child rule rejects requirements/nested/ci.txt and docs/ci.txt.
  • The materializer reads regular blobs from the authenticated base commit.
  • The tree parser rejects non-blob entries, non-regular modes, absolute paths, and traversal paths.
  • The materializer records exact source paths in the manifest.
  • The changed quality workflow has contents: read.
  • The exact workflow diff introduces no write-capability token or branch-writing command.
  • The requested-head quality, OpenCode, Noema, security, and supply-chain checks are successful.
  • The current unresolved-thread count is zero.

The PR remains BLOCKED with REVIEW_REQUIRED. I cannot approve until the incomplete-lock materialization path is fixed.

You are interacting with an AI system.

Copy link
Copy Markdown
Contributor Author

@opencode-agent review

Review exact head ed33253e5d6f93f2e71d80b24e27b301f96efb88 read-only. Trusted uv Materializer Quality CI, Python Security, Security Scan, CodeQL, Semgrep, Secret Scan, OSV, Scorecard, SBOM, and CodeRabbit are successful; all inline security findings concern removed predecessor workflows and are resolved/outdated. Verify the direct-child requirements/*.txt discovery boundary, authenticated-base regular-blob requirement, traversal/symlink rejection, complete hash-pinned closure preflight, manifest provenance, five-file permanent scope, and absence of branch-writing automation. Submit a non-author approval only if every exact-head gate remains satisfied.

Copy link
Copy Markdown
Contributor Author

@opencode-agent

Submit a formal current-head GitHub review after the current checks settle. Approve only if all exact-head checks succeed and no actionable finding remains; otherwise post the concrete blocker. Do not mutate or merge.

Copy link
Copy Markdown
Contributor Author

@coderabbitai

Please submit the formal current-head review conclusion after the latest exact-head checks complete. Do not mutate or merge.

@coderabbitai

coderabbitai Bot commented Aug 7, 2026

Copy link
Copy Markdown

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

repo='ContextualWisdomLab/.github'
pr='785'

echo '== Live PR metadata =='
pr_json="$(gh pr view "$pr" --repo "$repo" \
  --json number,state,isDraft,headRefName,headRefOid,baseRefName,baseRefOid,mergeStateStatus,reviewDecision,statusCheckRollup,reviews)"
printf '%s\n' "$pr_json" | jq '{
  number, state, isDraft, headRefName, headRefOid, baseRefName, baseRefOid,
  mergeStateStatus, reviewDecision,
  checks: [.statusCheckRollup[] | {name, status, conclusion}]
}'

head="$(printf '%s\n' "$pr_json" | jq -r '.headRefOid')"
base="$(printf '%s\n' "$pr_json" | jq -r '.baseRefOid')"

echo '== Commit identity and changed paths =='
printf 'base=%s\nhead=%s\n' "$base" "$head"
git cat-file -e "${base}^{commit}"
git cat-file -e "${head}^{commit}"
git merge-base --is-ancestor "$base" "$head" && echo 'base_is_ancestor=true' || echo 'base_is_ancestor=false'
git diff --name-status --find-renames "$base" "$head"

echo '== Current checks =='
gh pr checks "$pr" --repo "$repo" || true

echo '== Candidate validation implementation at live head =='
git show "${head}:scripts/ci/materialize_base_python_requirements.py" |
  nl -ba |
  sed -n '110,190p;430,520p'

echo '== Candidate validation regressions at live head =='
for file in \
  tests/test_materialize_base_python_requirements.py \
  tests/test_requirements_directory_lock_materialization.py; do
  if git cat-file -e "${head}:${file}" 2>/dev/null; then
    echo "--- ${file}"
    git show "${head}:${file}" |
      nl -ba |
      rg -n -C 5 -- '--hash=|--requirement|-r |requirements/ci\.txt|manifest|invalid|unpinned|absolute|traversal'
  fi
done

echo '== Active review threads =='
gh api graphql -F owner='ContextualWisdomLab' -F name='.github' -F number="$pr" -f query='
query($owner: String!, $name: String!, $number: Int!) {
  repository(owner: $owner, name: $name) {
    pullRequest(number: $number) {
      reviewThreads(first: 100) {
        nodes {
          isResolved
          isOutdated
          comments(first: 1) { nodes { author { login } body path line } }
        }
      }
    }
  }
}' | jq '[.data.repository.pullRequest.reviewThreads.nodes[] |
  select(.isResolved == false and .isOutdated == false)]'

Length of output: 14479


🏁 Script executed:

#!/bin/bash
set -euo pipefail

repo='ContextualWisdomLab/.github'
pr='785'
head="$(gh pr view "$pr" --repo "$repo" --json headRefOid --jq '.headRefOid')"

echo '== Materializer: candidate validation and materialization =='
git show "${head}:scripts/ci/materialize_base_python_requirements.py" |
  cat -n |
  sed -n '110,210p;420,530p'

echo '== Tests: candidate validation and manifest assertions =='
for file in \
  tests/test_materialize_base_python_requirements.py \
  tests/test_requirements_directory_lock_materialization.py; do
  echo "--- ${file}"
  git show "${head}:${file}" |
    cat -n |
    grep -n -E -C 5 -- \
      'requirements/ci\.txt|requirements/nested|--hash=|--requirement|-r |manifest|invalid|unpinned|absolute|traversal|symlink|directive'
done

echo '== Active non-outdated review threads =='
gh api graphql -F owner='ContextualWisdomLab' -F name='.github' -F number="$pr" -f query='
query($owner: String!, $name: String!, $number: Int!) {
  repository(owner: $owner, name: $name) {
    pullRequest(number: $number) {
      reviewThreads(first: 100) {
        nodes {
          isResolved
          isOutdated
          comments(first: 1) {
            nodes { author { login } body path line }
          }
        }
      }
    }
  }
}' | jq '[.data.repository.pullRequest.reviewThreads.nodes[] |
  select(.isResolved == false and .isOutdated == false)]'

Length of output: 28144


@seonghobae Formal current-head review conclusion: changes requested.

I reviewed current head b3f5f7e87b57d9b5b76e3c628fe5d21be84d269f against e6fc91416c4fb13febd07b985c6e9c74fe888306.

All listed checks have completed successfully. There are zero active non-outdated review threads. The parent-relative diff contains the declared six permanent files.

P1 — Reject invalid requirement lines before materialization

In scripts/ci/materialize_base_python_requirements.py, Lines 143-146, _is_hash_pinned() accepts each non-directive line that:

  • Contains --hash=, or
  • Starts with -r or --requirement .

Therefore, a direct-child requirements/ci.txt can enter manifest.json with invalid content, including:

--index-url https://packages.example.invalid/simple --hash=sha256:aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
demo==1 --hash=not-a-valid-hash
-r /unbounded/external-requirements.txt

base_hash_locks() materializes these candidates before the installer runs its independent pip --require-hashes preflight. The preflight can prevent installation, but it does not enforce the required candidate-selection boundary.

Update _is_hash_pinned() to accept only:

  • An exact valid requirement with one or more valid inline SHA-256 hashes; or
  • A supported bounded relative -r or --requirement include.

Reject option lines, malformed requirements, invalid hashes, absolute include paths, traversal include paths, and malformed include operands. Add regression tests that confirm each invalid direct-child input is absent from manifest.json.

GitHub currently reports this Draft PR as DIRTY with CHANGES_REQUESTED. I cannot approve until the validation defect is fixed and the branch is mergeable.

You are interacting with an AI system.

Copy link
Copy Markdown
Contributor Author

@opencode-agent review

Use the newest exact head only. If every required check is green and there is no actionable finding, submit formal approval; otherwise state the blocker. Do not mutate or merge.

Copy link
Copy Markdown
Contributor Author

@cwl-noema-review review

Use exact-current-head evidence only. Approve formally only when required checks are green and no actionable finding remains; otherwise identify the blocker. Do not mutate or merge.

Copy link
Copy Markdown
Contributor Author

@opencode-agent review
@cwl-noema-review review

Do not post another top-level acknowledgement. Submit the formal exact-head review verdict through the GitHub review API when current-head checks are complete; approve only if no blocker remains. Do not mutate or merge.

Copy link
Copy Markdown
Contributor Author

@coderabbitai full review

Use the exact current head only and submit the review verdict through the formal GitHub review surface; do not post another summary comment, mutate, or merge.

@coderabbitai

coderabbitai Bot commented Aug 7, 2026

Copy link
Copy Markdown

Rate Limit Exceeded

@seonghobae have exceeded the limit for the number of chat messages per hour. Please wait 7 minutes and 8 seconds before sending another message.

Copy link
Copy Markdown
Contributor Author

@cwl-noema-review

Please use the GitHub review API rather than another comment for the final exact-head verdict. Do not mutate or merge.

Copy link
Copy Markdown
Contributor Author

@opencode-agent

Final action expected: use the GitHub review API for the exact current head. Approve only if current required checks are successful and no actionable finding remains; otherwise post one concrete blocking review. Do not mutate or merge.

Copy link
Copy Markdown
Contributor Author

@cwl-noema-review @opencode-agent Please review the exact current head after the fail-closed hash-lock classification repair. Earlier reviews and checks are stale.

Copy link
Copy Markdown
Contributor Author

@cwl-noema-review

Submit one formal exact-current-head review through GitHub's review API. Do not add another discussion comment, mutate, or merge.

Copy link
Copy Markdown
Contributor Author

@opencode-agent

Do not acknowledge. Submit exactly one formal review on the exact current head through GitHub's review API after checks complete. Do not mutate or merge.

Copy link
Copy Markdown
Contributor Author

@cwl-noema-review

Do not acknowledge. Submit exactly one formal review on the exact current head through GitHub's review API after checks complete. Do not mutate or merge.

Copy link
Copy Markdown
Contributor Author

@coderabbitai

Do not acknowledge. Submit exactly one formal review on the exact current head through GitHub's review API after checks complete. Do not mutate or merge.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Exact-head review for b3f5f7e: changes requested.

P1: scripts/ci/materialize_base_python_requirements.py does not validate candidate requirements or include operands before materialization. _is_hash_pinned() accepts any non-directive logical line containing --hash= and any line beginning with -r or --requirement . Therefore, direct-child requirements/*.txt files can enter manifest.json with an option line containing --hash=, an invalid hash token, or an absolute or traversal include. The later pip --require-hashes preflight occurs after materialization and does not enforce the candidate-selection boundary.

Require exact package pins with valid inline SHA-256 hashes. Permit only bounded relative include operands. Reject option lines, malformed hash tokens, absolute paths, traversal paths, and malformed includes. Add manifest-exclusion regression tests for each input.

GitHub also reports this pull request as DIRTY, so it is not mergeable.

@coderabbitai

coderabbitai Bot commented Aug 7, 2026

Copy link
Copy Markdown

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

repo='ContextualWisdomLab/.github'
pr='785'

pr_json="$(gh pr view "$pr" --repo "$repo" \
  --json number,state,isDraft,headRefOid,baseRefOid,mergeStateStatus,reviewDecision,statusCheckRollup,reviews)"
printf '%s\n' '== Live PR identity and checks =='
printf '%s\n' "$pr_json" | jq '{
  number, state, isDraft, headRefOid, baseRefOid, mergeStateStatus, reviewDecision,
  checks: [.statusCheckRollup[] | {name, status, conclusion}]
}'

head="$(printf '%s\n' "$pr_json" | jq -r '.headRefOid')"
base="$(printf '%s\n' "$pr_json" | jq -r '.baseRefOid')"
printf '%s\n' '== Commit relation and changed scope =='
printf 'base=%s\nhead=%s\n' "$base" "$head"
git cat-file -e "${base}^{commit}"
git cat-file -e "${head}^{commit}"
git merge-base --is-ancestor "$base" "$head" && echo 'base_is_ancestor=true' || echo 'base_is_ancestor=false'
git diff --name-status --find-renames "$base" "$head"
git diff --check "$base" "$head"

printf '%s\n' '== Materializer validation and materialization =='
git show "${head}:scripts/ci/materialize_base_python_requirements.py" |
  nl -ba | sed -n '100,230p;430,540p'

printf '%s\n' '== Relevant regression tests =='
for file in \
  tests/test_materialize_base_python_requirements.py \
  tests/test_requirements_directory_lock_materialization.py; do
  echo "--- ${file}"
  git show "${head}:${file}" | nl -ba |
    rg -n -C 6 -- 'requirements/ci\.txt|requirements/nested|require-hashes|--hash=|--requirement|-r |manifest|unpinned|invalid|absolute|traversal|symlink|directive'
done

printf '%s\n' '== Active review threads =='
gh api graphql -F owner='ContextualWisdomLab' -F name='.github' -F number="$pr" -f query='
query($owner: String!, $name: String!, $number: Int!) {
  repository(owner: $owner, name: $name) {
    pullRequest(number: $number) {
      reviewThreads(first: 100) {
        nodes {
          isResolved
          isOutdated
          comments(first: 1) {
            nodes { author { login } body path line }
          }
        }
      }
    }
  }
}' | jq '[.data.repository.pullRequest.reviewThreads.nodes[] |
  select(.isResolved == false and .isOutdated == false)]'

Length of output: 8826


🏁 Script executed:

#!/bin/bash
set -euo pipefail

repo='ContextualWisdomLab/.github'
pr='785'
head="$(gh pr view "$pr" --repo "$repo" --json headRefOid --jq '.headRefOid')"

printf '%s\n' '== Exact current head =='
printf '%s\n' "$head"

printf '%s\n' '== Materializer candidate validation and materialization =='
git show "${head}:scripts/ci/materialize_base_python_requirements.py" |
  cat -n | sed -n '100,240p;430,550p'

printf '%s\n' '== Relevant materializer regression tests =='
for file in \
  tests/test_materialize_base_python_requirements.py \
  tests/test_requirements_directory_lock_materialization.py; do
  printf '%s\n' "--- ${file}"
  git show "${head}:${file}" | cat -n |
    rg -n -C 6 -- 'requirements/ci\.txt|requirements/nested|require-hashes|--hash=|--requirement|-r |manifest|unpinned|invalid|absolute|traversal|symlink|directive'
done

printf '%s\n' '== Active non-outdated review threads =='
gh api graphql -F owner='ContextualWisdomLab' -F name='.github' -F number="$pr" -f query='
query($owner: String!, $name: String!, $number: Int!) {
  repository(owner: $owner, name: $name) {
    pullRequest(number: $number) {
      reviewThreads(first: 100) {
        nodes {
          isResolved
          isOutdated
          comments(first: 1) {
            nodes { author { login } body path line }
          }
        }
      }
    }
  }
}' | jq '[.data.repository.pullRequest.reviewThreads.nodes[] |
  select(.isResolved == false and .isOutdated == false)]'

Length of output: 31716


🏁 Script executed:

#!/bin/bash
set -euo pipefail

repo='ContextualWisdomLab/.github'
pr='785'
expected_head='b3f5f7e87b57d9b5b76e3c628fe5d21be84d269f'
current_head="$(gh pr view "$pr" --repo "$repo" --json headRefOid --jq '.headRefOid')"

if [ "$current_head" != "$expected_head" ]; then
  printf 'Head changed; no review submitted. expected=%s current=%s\n' \
    "$expected_head" "$current_head" >&2
  exit 1
fi

body=$'Exact-head review for b3f5f7e87b57d9b5b76e3c628fe5d21be84d269f: changes requested.\n\nP1: `scripts/ci/materialize_base_python_requirements.py` does not validate candidate requirements or include operands before materialization. `_is_hash_pinned()` accepts any non-directive logical line containing `--hash=` and any line beginning with `-r ` or `--requirement `. Therefore, direct-child `requirements/*.txt` files can enter `manifest.json` with an option line containing `--hash=`, an invalid hash token, or an absolute or traversal include. The later `pip --require-hashes` preflight occurs after materialization and does not enforce the candidate-selection boundary.\n\nRequire exact package pins with valid inline SHA-256 hashes. Permit only bounded relative include operands. Reject option lines, malformed hash tokens, absolute paths, traversal paths, and malformed includes. Add manifest-exclusion regression tests for each input.\n\nGitHub also reports this pull request as `DIRTY`, so it is not mergeable.'

gh api --method POST "repos/${repo}/pulls/${pr}/reviews" \
  -f commit_id="$current_head" \
  -f event='REQUEST_CHANGES' \
  -f body="$body" \
  --jq '{id, state, commit_id, html_url}'

Length of output: 1941


@seonghobae Formal GitHub review submitted for exact head b3f5f7e87b57d9b5b76e3c628fe5d21be84d269f.

Verdict: Changes requested. The review identifies the fail-open candidate validation and the current DIRTY merge state. No branch mutation or merge was performed.

You are interacting with an AI system.

Copy link
Copy Markdown
Contributor Author

@opencode-agent @cwl-noema-review @coderabbitai

No further discussion comments are needed. Complete the formal exact-current-head review through the review API only; do not mutate or merge.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Exact-head review for b3f5f7e: changes requested.

P1: Candidate validation remains fail-open before materialization. In scripts/ci/materialize_base_python_requirements.py, _is_hash_pinned() accepts any non-directive line containing --hash= and every -r or --requirement line. base_hash_locks() then writes the accepted direct-child requirements/*.txt candidate into the manifest before independent pip --require-hashes closure preflight.

This permits option lines that contain --hash=, malformed hash tokens, and absolute, traversal, or malformed requirement includes to gain candidate status. The later preflight can reject installation, but it does not enforce the required materialization boundary.

Require an exact package == pin with one or more valid inline SHA-256 hashes. Permit only bounded relative requirement includes. Reject option lines, malformed hashes, absolute paths, traversal paths, and malformed include operands. Add manifest-exclusion tests for each invalid input.

GitHub also reports this pull request as DIRTY, so the exact head is not mergeable.

@coderabbitai

coderabbitai Bot commented Aug 7, 2026

Copy link
Copy Markdown

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

repo='ContextualWisdomLab/.github'
pr='785'

pr_json="$(gh pr view "$pr" --repo "$repo" \
  --json number,state,isDraft,headRefOid,baseRefOid,mergeStateStatus,reviewDecision,statusCheckRollup,reviews)"
printf '%s\n' '== Live PR identity and checks =='
printf '%s\n' "$pr_json" | jq '{
  number, state, isDraft, headRefOid, baseRefOid, mergeStateStatus, reviewDecision,
  checks: [.statusCheckRollup[] | {name, status, conclusion}]
}'

head="$(printf '%s\n' "$pr_json" | jq -r '.headRefOid')"
base="$(printf '%s\n' "$pr_json" | jq -r '.baseRefOid')"
printf '%s\n' '== Commit relation and changed scope =='
printf 'base=%s\nhead=%s\n' "$base" "$head"
git cat-file -e "${base}^{commit}"
git cat-file -e "${head}^{commit}"
git merge-base --is-ancestor "$base" "$head" && echo 'base_is_ancestor=true' || echo 'base_is_ancestor=false'
git diff --name-status --find-renames "$base" "$head"
git diff --check "$base" "$head"

printf '%s\n' '== Candidate validation and materialization at live head =='
git show "${head}:scripts/ci/materialize_base_python_requirements.py" |
  nl -ba | sed -n '100,250p;430,560p'

printf '%s\n' '== Relevant regression coverage at live head =='
for file in \
  tests/test_materialize_base_python_requirements.py \
  tests/test_requirements_directory_lock_materialization.py; do
  printf '%s\n' "--- ${file}"
  git show "${head}:${file}" | nl -ba |
    rg -n -C 6 -- \
      'requirements/ci\.txt|requirements/nested|require-hashes|--hash=|--requirement|-r |manifest|unpinned|invalid|absolute|traversal|symlink|directive'
done

printf '%s\n' '== Active non-outdated review threads =='
gh api graphql -F owner='ContextualWisdomLab' -F name='.github' -F number="$pr" -f query='
query($owner: String!, $name: String!, $number: Int!) {
  repository(owner: $owner, name: $name) {
    pullRequest(number: $number) {
      reviewThreads(first: 100) {
        nodes {
          isResolved
          isOutdated
          comments(first: 1) {
            nodes { author { login } body path line }
          }
        }
      }
    }
  }
}' | jq '[.data.repository.pullRequest.reviewThreads.nodes[] |
  select(.isResolved == false and .isOutdated == false)]'

Length of output: 8892


🏁 Script executed:

#!/bin/bash
set -euo pipefail

repo='ContextualWisdomLab/.github'
pr='785'
head="$(gh pr view "$pr" --repo "$repo" --json headRefOid --jq '.headRefOid')"

printf '== Exact live head ==\n%s\n' "$head"
printf '%s\n' '== Candidate validation and materialization =='
git show "${head}:scripts/ci/materialize_base_python_requirements.py" |
  cat -n | sed -n '100,250p;430,560p'

printf '%s\n' '== Relevant regression coverage =='
for file in \
  tests/test_materialize_base_python_requirements.py \
  tests/test_requirements_directory_lock_materialization.py; do
  printf '%s\n' "--- ${file}"
  git show "${head}:${file}" | cat -n |
    rg -n -C 6 -- \
      'requirements/ci\.txt|requirements/nested|require-hashes|--hash=|--requirement|-r |manifest|unpinned|invalid|absolute|traversal|symlink|directive' \
    || true
done

printf '%s\n' '== Active non-outdated review threads =='
gh api graphql -F owner='ContextualWisdomLab' -F name='.github' -F number="$pr" -f query='
query($owner: String!, $name: String!, $number: Int!) {
  repository(owner: $owner, name: $name) {
    pullRequest(number: $number) {
      reviewThreads(first: 100) {
        nodes {
          isResolved
          isOutdated
          comments(first: 1) {
            nodes { author { login } body path line }
          }
        }
      }
    }
  }
}' | jq '[.data.repository.pullRequest.reviewThreads.nodes[] |
  select(.isResolved == false and .isOutdated == false)]'

Length of output: 32443


🏁 Script executed:

#!/bin/bash
set -euo pipefail

repo='ContextualWisdomLab/.github'
pr='785'
expected_head='b3f5f7e87b57d9b5b76e3c628fe5d21be84d269f'
current_head="$(gh pr view "$pr" --repo "$repo" --json headRefOid --jq '.headRefOid')"

if [ "$current_head" != "$expected_head" ]; then
  printf 'Head changed; review was not submitted. expected=%s current=%s\n' \
    "$expected_head" "$current_head" >&2
  exit 1
fi

body=$'Exact-head review for b3f5f7e87b57d9b5b76e3c628fe5d21be84d269f: changes requested.\n\nP1: Candidate validation remains fail-open before materialization. In `scripts/ci/materialize_base_python_requirements.py`, `_is_hash_pinned()` accepts any non-directive line containing `--hash=` and every `-r ` or `--requirement ` line. `base_hash_locks()` then writes the accepted direct-child `requirements/*.txt` candidate into the manifest before independent `pip --require-hashes` closure preflight.\n\nThis permits option lines that contain `--hash=`, malformed hash tokens, and absolute, traversal, or malformed requirement includes to gain candidate status. The later preflight can reject installation, but it does not enforce the required materialization boundary.\n\nRequire an exact package `==` pin with one or more valid inline SHA-256 hashes. Permit only bounded relative requirement includes. Reject option lines, malformed hashes, absolute paths, traversal paths, and malformed include operands. Add manifest-exclusion tests for each invalid input.\n\nGitHub also reports this pull request as `DIRTY`, so the exact head is not mergeable.'

gh api --method POST "repos/${repo}/pulls/${pr}/reviews" \
  -f commit_id="$current_head" \
  -f event='REQUEST_CHANGES' \
  -f body="$body" \
  --jq '{id, state, commit_id, html_url}'

Length of output: 2073


@seonghobae Formal review submitted through the GitHub review API: Changes requested for b3f5f7e87b57d9b5b76e3c628fe5d21be84d269f. No branch mutation or merge occurred.

You are interacting with an AI system.

Copy link
Copy Markdown
Contributor Author

@opencode-agent address

Reconcile the trusted requirements-directory lock materializer onto the current protected base without rewriting history. Exact PR head is b3f5f7e87b57d9b5b76e3c628fe5d21be84d269f; current protected main is 6eb06cdd08c79a06f7b390069d4ffa49e2eb7dba. The exact scripts/ci/materialize_base_python_requirements.py blob is 807c33aa484074792fb3eed7ffa4ce1bf0374520 on the PR head and 98cdad4594a72f68ac00b536161984509ae0be03 on current main. Do not write if any relevant head/base/blob identity moves.

Use a trusted checkout and normally merge exact protected main into this existing branch. Resolve conflicts by preserving every newer protected-main behavior plus only this bounded lock-discovery contract:

  • direct children of a directory named requirements may be candidate .txt locks in addition to the established conventional names;
  • candidate status never grants trust: source must be a regular blob in the authenticated base, relative/traversal-free/non-symlink, and content must remain a complete independently preflighted pip --require-hashes closure;
  • a global --require-hashes directive alone or with an unpinned requirement is not evidence; directive-only/empty/unpinned inputs remain rejected;
  • deeper descendants such as requirements/nested/ci.txt, unrelated notes, PR-only files, malformed Git trees, and unsafe paths remain excluded;
  • exact trusted source provenance remains in the materialization manifest and no lock is fetched, repaired, inferred, or rewritten.

The old exact head had Trusted uv Materializer Quality CI plus all security/supply-chain checks green, and its GA-S temporary workflow findings are already resolved/outdated; none of that evidence transfers after reconciliation. Do not resurrect any reopen-*, repair-*, branch-writing, one-shot, self-modifying, or encoded-patch workflow.

After the normal merge commit, run the focused requirements/uv materializer suite with exact 100% production statement/branch/docstring coverage, complete central suite and Strix quick gate, Python 3.10/3.14 compilation, and all exact-head Security Scan, SAST, CodeQL, Python Security, Secret Scan, OSV, Scorecard, and SBOM gates. Remove only genuine merge-conflict artifacts if created by the merge and keep Draft until current-head automated and qualifying independent review are clean. Do not merge or synthesize approval.

Copy link
Copy Markdown
Contributor Author

/oc Refetch the live PR and abort without writing unless exact head is still 4914e124c339f93bac5da42aeaf649ed893315d4. Keep Draft. This exact head is the deliberate RED state: Strix run 31316856693, job 93253405450, proves the new permanent candidate-lock security tests fail on the current _is_hash_pinned implementation while the rest of the suite remains intact. Do not weaken those tests.

Implement the minimum GREEN repair in scripts/ci/materialize_base_python_requirements.py on this existing branch only:

  1. Reuse _is_fully_hash_pinned_requirement(line) as the sole package-requirement predicate. A substantive package line qualifies only when it is an exact == requirement accepted by UV_EXACT_REQUIREMENT_RE and every hash token is a complete SHA-256 accepted by UV_SHA256_HASH_RE. This must reject range pins such as demo>=1, truncated/malformed hashes, option/directive lines that merely contain --hash=, direct/local/VCS references, and unsupported algorithms.
  2. Add one small helper for bounded relative requirement includes. Accept only a line that is exactly -r <relative-path> or --requirement <relative-path>, with no additional hash/options/tokens. The path must be POSIX-relative, non-absolute, contain no empty/./.. segments, no backslashes, no URL scheme/colon, no NUL/control/whitespace tricks, and remain a repository-relative requirements-file reference. Preserve the existing legitimate -r other-hashes.txt contract; a safe nested relative path may be accepted if every segment is safe.
  3. Keep a standalone --require-hashes directive neutral: remove it from substantive-line evaluation, but it cannot qualify an empty/directive-only file. Every remaining logical line must satisfy either the exact package-pin predicate or the safe-include predicate.
  4. Do not broaden network, build, environment, Git-tree, output-path, uv, or trusted-base behavior. This is admission hardening only.
  5. Update the _is_hash_pinned docstring to state the exact predicates and fail-closed include boundary. Add positive tests for a safe nested relative include if needed for branch coverage, but do not remove any current adversarial RED case.

Run first the two focused suites tests/test_requirements_directory_lock_materialization.py and tests/test_materialize_base_python_requirements.py, then the complete Trusted uv Materializer Quality CI suite, full central tests, 100% owned production statement/branch coverage, 100% public docstrings, compileall, Strix quick gate, and git diff --check. Preserve the RED run in history and publish a new exact-head GREEN result. Do not force-push, create a repair workflow/branch, mark Ready, approve, merge, retarget, or alter reviewer/model/credential policy.

Copy link
Copy Markdown
Contributor Author

/oc Refetch the live PR and stop without writing unless exact head is 4914e124c339f93bac5da42aeaf649ed893315d4. The permanent exact-head RED is authoritative: Trusted uv Materializer Quality CI run 31316856691, job 93253405580, reports 12 intended failures and 77 passes. Apply the minimum production GREEN repair in scripts/ci/materialize_base_python_requirements.py; do not weaken or remove the RED tests.

_is_hash_pinned() must stop treating the mere substring --hash= or an arbitrary -r/--requirement prefix as trust evidence. For each non---require-hashes logical line: (1) ordinary package lines must satisfy the existing exact == package requirement plus one-or-more complete sha256:<64 hex> hash contract already encoded by _is_fully_hash_pinned_requirement; (2) requirement includes may remain supported only as exactly one -r <relative-path> or --requirement <relative-path> token pair, with no hash/options appended, no absolute path, backslash, URL/scheme, option-like target, ./.. path segment, or traversal after normalization. Preserve the existing accepted -r other-hashes.txt contract and multiline pip-compile/uv-export format. Keep the later independent pip --require-hashes closure preflight authoritative for transitive completeness.

Run the 12 failing cases first, then the complete trusted-uv focused suite, 100% statement/branch coverage, full central tests, 100% public docstrings, Python 3.10/3.14 compatibility, compileall and git diff --check. Update the existing doctoring/CHANGELOG only if the trust contract wording becomes stale. Keep Draft until exact-head security/review/approval gates are complete. Do not create another branch/PR, temporary writer workflow, encoded patch, force-push, or weaken the immutable-base/offline/hash/uv supply-chain boundaries.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants