fix(opencode): materialize every coverage lock input - #2286
seonghobae wants to merge 18 commits into
Conversation
Semgrep OSS and Bandit B310 Medium alerts on main flagged dynamic urllib use in CodeQL identity and Strix evidence helpers. Fail closed unless the URL is https://api.github.com so file:// and arbitrary hosts cannot reach urlopen. Co-authored-by: Cursor <cursoragent@cursor.com>
Bumps [anyio](https://github.com/agronholm/anyio) from 4.14.0 to 4.14.2. - [Release notes](https://github.com/agronholm/anyio/releases) - [Commits](agronholm/anyio@4.14.0...4.14.2) --- updated-dependencies: - dependency-name: anyio dependency-version: 4.14.2 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
Replace retired urllib urlopen monkeypatches with direct CodeQL and Strix dedicated-opener patches. Remove the PR-specific global conftest bridge so both security helpers exercise the same explicit transport boundary without live network access.
Clears Bandit/Semgrep B310 on shared scripts/ci urlopen so the anyio bump is not blocked by unrelated SAST.
Restore the unrelated #2269 URL-opener paths to protected main while retaining the AnyIO 4.14.2 pin and hashes. The URL/redirect responsibility remains in canonical #2279; this PR owns only the dependency security update. Validated with 56 focused tests, 3,335 full tests plus 28 skipped/40 subtests, warnings-as-errors, diff check, and pip-audit reporting no known vulnerabilities.
|
Understand this PR’s impact Explore downstream dependencies and potential security impact with Blast Radius. Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueNo actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (5)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughOpenCode coverage 이미지 빌드가 ChangesOpenCode coverage lock context
Priority: ➖ Normal Estimated code review effort: 2 (Simple) | ~10 minutes Change: Bug fix · Severity of issue fixed: Medium Suggested reviewers: Merge Risk: ⚪ Minimal · up to No concrete implementation or documentation defect remains. Hosted exact-head acceptance is pending but does not establish a current failure. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches 💡 1🛠️ Fix failing CI checks 💡
📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
seonghobae
left a comment
There was a problem hiding this comment.
Exact-head COMMENT review for canonical OpenCode prerequisite e43a75b31177b2348b4f7afbf8298eea29a0c334 (tree 804448e51a518375c2856cbcd5907cac69021bf5).
The isolated coverage-image Dockerfile copied two lockfiles while staging only one. This head validates and stages both trusted regular non-symlink lockfiles before build. Focused GITHUB_ACTIONS=true: 77 passed. Full warnings-as-errors: 3,369 passed / 28 skipped / 40 subtests. compileall and diff check PASS. Five effective canonical-owner paths; no new source finding.
COMMENT only, not approval. Keep Draft until exact-head hosted evidence and real coverage-image acceptance complete.
Exact-head prerequisite receipt
Replacement Checks are queued: Runtime, Security, Python Security, SAST, CodeQL. Draft / Proposed; no merge or auto-merge. |
seonghobae
left a comment
There was a problem hiding this comment.
Exact-head traceability repair review for c4a73a174e6bf54cde1ac996bc7df1a94de949fa (tree 654b0b80d7e276057a314a4b124934c9352ffe28).
RCA: the Gap row named downstream failure carrier .github#2266 as the PR where the canonical RED/GREEN repair was prepared. The actual central owner repair is this PR, .github#2286; #2266 remains consumer evidence and prerequisite beneficiary.
Ordinary-forward commit c4a73a17… changes only docs/product-technical-gap-baseline.md (+1/-1), preserves the five-path workflow/test repair tree, and updates the PR body to the live head/tree. Direct exact-blob verification confirms the Gap row now names #2286. No force update or predecessor evidence transfer was used.
This is COMMENT evidence, not approval. The five fresh exact-head workflows are queued/nonterminal, real coverage-evidence image-build acceptance is still absent, and independent approval remains required. Keep Draft/Proposed; do not merge, auto-merge, bypass, or rerun unchanged evidence.
|
Current exact-head evidence update: |
|
Current exact-head authority update for
So the current acceptance boundary is: Semgrep, Runtime Quality, Python Security, and Security Scan remain exact-head SUCCESS; CodeQL remains non-accepted pending canonical producer + settlement, not a proven source RED and not GREEN. Keep Draft. Do not blind-rerun, synthesize status, no-op wake, or move downstream #2291/#2109/#2275/#2276. Real post-repair coverage-image acceptance and qualifying independent current-head approval remain separate requirements. Canonical lifecycle/publication tracking is |
|
Coverage-owner handoff: Draft #2363 carries this PR’s exact |
Preserve #2385, #2359, and #2286 as explicit parents while composing their byte-identical overlapping locks and endpoint contract. This creates one exact-head bootstrap stack for the coverage-image, 100% coverage, AnyIO audit, and CodeQL dispatch failures without force-push, rebase, or delta disposal.
|
Foundation convergence receipt: #2385 exact head |
Current authority
Status: OPEN / Draft / Proposed / do not merge.
main@e6334e229581a918e2f22de18733b76fa65d7e7142e4198fa012eb24596e7984d77e27f0905348d69c0d104eed561ad5e6cbfac4e0b8ed31e81350b98a5251bf409fe84b3dd0cba1e48992f5b8d9eda5as parents/ancestorsCanonical repair
Required OpenCode coverage failed before target-PR execution because the isolated Docker build context referenced
requirements-noema-document-ci-hashes.txtwithout materializing it. This lane remains the canonical owner for that control-plane defect:The source repair does not weaken coverage, read consumer source, synthesize status, or turn an infrastructure failure into a product finding.
Dependency-cycle repair
The predecessor exact head
c4a73a174e6bf54cde1ac996bc7df1a94de949fareached real hosted execution. SAST Semgrep35663211484and Security Scan35663211642succeeded. Python Security35663211397failed only because protected-mainrequirements-strix-ci-hashes.txtstill pinned AnyIO 4.14.0; pip-audit reported CVE-2026-63374, CVE-2026-64847, and CVE-2026-63349, all fixed in 4.14.2. That exact dependency delta is owned by #2278.At the same time, #2278 exact
8a5251bf...cannot obtain a valid OpenCode coverage/review receipt while protected main still has this #2286 build-context defect: run35683820627, job106642970542failed at Dockerfile line 89 because/requirements-noema-document-ci-hashes.txtwas absent, before any target-PR test execution; OpenCode explicitly reported no source-backed #2278 product finding.To break that circular foundation dependency without copying source or weakening either gate, ordinary two-parent commit
42e4198f...adopts #2278 as ancestry and uses its exactrequirements-strix-ci-hashes.txtblob while retaining the #2286 tree. Against protected main the effective delta is therefore the five #2286 owner paths plus the single #2278 dependency-owner path. #2278 remains open until this successor is verified/protected; it is not closed merely because its delta is now ancestral here.Evidence boundary
Predecessor local/source evidence remains: focused
GITHUB_ACTIONS=true77 passed; full warnings-as-errors 3,369 passed / 28 skipped / 40 subtests; compileall andgit diff --checkpassed. These receipts do not transfer as exact-head hosted acceptance.Fresh exact-head hosted runs on unchanged
42e4198f...have now materially advanced:35937114873: SUCCESS35937114942: SUCCESS35937115044: SUCCESS35937115071: SUCCESS35937114953: queuedThe four completed successes are genuine current-head evidence. The previous AnyIO 4.14.0 Python Security failure is therefore closed on this composite exact head, and Security Scan is likewise terminal-success. CodeQL remains nonterminal, so this is still not exact-head GREEN. There is still no qualifying independent
APPROVEDreview on exact42e4198f.... A real post-repair coverage-image canary is also still required; protected-main consumers must not be woken with no-op commits while the owner is unintegrated.Landing boundary
Keep Draft until CodeQL and any other applicable exact-head gates are terminal, source-relevant failures are repaired, current-head independent review requirements are met, and the coverage-image repair has real acceptance. Then integrate normally into protected main and let #2278 and downstream consumers reconcile by ordinary/non-force ancestry.
No force push, destructive rebase, self-approval, review dismissal, synthetic status, no-op freshness commit, blind rerun, source copying, or gate weakening is authorized.