fix(procurement): require reconstructable source provenance - #1145
seonghobae wants to merge 4 commits into
Conversation
|
Important Review skippedDraft detected. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
@coderabbitai review Please review the exact current Draft head |
|
|
|
Closing: same situation as #1147 — this branch is a strict ancestor of its base |
Closes #1144.
Stack and exact scope
This is a direct child of active procurement/governance writer #1015. The parent advanced from
5a855b731f9857d4a177263f94c9987952be224cto7f7109078314727ce47f762f08c636cc3155a52f. The intervening parent delta touched only.jules/sentinel.md,scripts/_bounded_subprocess.py,tests/test_bounded_subprocess_pipe_cleanup.py, andtests/test_subprocess_output_bounds.py; it did not overlap this child’s procurement source/test/changelog files.The child therefore absorbed that exact parent tip with a normal non-force merge commit
cce90aa5dd3ba8b3abcaae4a7acfe0f21b951bb4. Fresh ancestry is now 4 commits ahead / 0 behind the live parent, with merge-base exactly7f7109078314727ce47f762f08c636cc3155a52f. The effective parent-relative diff remains only the three procurement files listed below. If #1015 moves again, re-evaluate the intervening delta and exact-head evidence; do not transfer checks or reviews.Defect
build_procurement_due_diligence.py::_source_commit()preserved the literal"unknown"on non-timeout Git failures and accepted arbitrary non-emptygit rev-parse HEADoutput such as abbreviated or malformed identities. Procurement evidence could therefore be emitted without a reconstructable source revision.RED → GREEN
594512d25c7eec50b6af1d3ca985adff28598e2d: replace the historicalunknownfallback expectation with fail-closed command/executable regressions; reject empty, abbreviated, uppercase, non-hexadecimal, undersized, and oversized identities; preserve bounded lookup and canonical full SHA-1/SHA-256 compatibility.e8b896aab0d9e9fc2072a99b6235cf3eae565d6e: non-timeout OS/subprocess failures now raise stable package-ownedRuntimeError, and successful Git stdout must be a lowercase 40-hex SHA-1 or 64-hex SHA-256 identity.64bfa8d932ad533182ec5d9a17e749821e41b8fb: governed changelog fragment records the procurement provenance contract.cce90aa5dd3ba8b3abcaae4a7acfe0f21b951bb4: absorb current fix(ops): replay bounded subprocess integrity on current review workflow #1015 without changing the child’s effective three-file product diff.Effective parent-relative scope:
scripts/build_procurement_due_diligence.pytests/test_procurement_git_metadata_timeout.pydocs/changelog.d/1144-procurement-source-provenance.md#1015's bounded GitHub subprocess/capture behavior is preserved.
Ownership boundary
Procurement/release provenance control-plane only. No likelihood, estimator, scoring, fit statistic, uncertainty, recovery, or other production psychometric/statistical arithmetic changed; Rust-first numerical ownership and downstream
psychometrics-commonsownership remain unchanged.Review boundary
Keep Draft until the exact current head has terminal required CI/security/package/provenance evidence and any effective formal review requirements are satisfied. Parent/predecessor-head checks and reviews are historical only and do not transfer.