Skip to content

test: canonicalize temp root for secure capability fixtures - #539

Draft
seonghobae wants to merge 10 commits into
mainfrom
fix/canonical-test-temp-root
Draft

test: canonicalize temp root for secure capability fixtures#539
seonghobae wants to merge 10 commits into
mainfrom
fix/canonical-test-temp-root

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

Scope

Security-sensitive tests canonicalize the physical temp root without weakening production no-symlink-parent validation.

Current exact authority — 2026-09-06 KST

Protected Noema is main@e26d771470a4ece873c367b40b3cd6cb03ac7de3. Ordinary two-parent/non-force restack f2a1f4d048b816d09a74bac911cca21cc9cb1613 preserves the four-file test-harness delta and adopts merged #527 OIDC trust.

Fresh exact-head patch-validator-image 34026811715, reviewer-ci 34026811790, ci 34026811879, and required Security Scan 34026811925 are queued. Historical GREEN does not transfer. Keep Draft until the unchanged head has terminal current gates and clear review state.

@coderabbitai

coderabbitai Bot commented Sep 2, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@seonghobae seonghobae added bug Something isn't working priority: medium Normal-priority or P2 work status: draft Draft pull request type: bug Defect or incorrect behavior labels Sep 2, 2026 — with ChatGPT Codex Connector

Copy link
Copy Markdown
Contributor Author

Freshness check on exact head 601bba3edfa1d7b635a9f115732bcd7b52b77686 (re-fetched, not relying on this PR's own body text):

All 8 check-runs are now terminal, contradicting this PR's current body ("queued and therefore non-passing"):

  • ci/verify — success
  • verify-patch-validator-image — success
  • reviewer-ci/reviewer — workflow conclusion success
  • required Security Scan (dependency-review, osv-scan, scorecard, trivy-fs) — success
  • CodeQL ×3 (python, javascript-typescript, actions) — success

However, pulling the actual job log for the reviewer check (job 100471292279, run 33698105806) shows the same defect already documented and being repaired in #546: the CodeGraph smoke indexes the 1-file fixture successfully, then

## codegraph explore
No relevant code found for "Review blast radius and focused tests for example.ts"

The workflow still reports success because the current gate only checks for the ## codegraph explore heading plus the copy banner, not actual retrieved content — this is the identical false-green class confirmed on #526, #533, #537, and #543, just not yet called out in this PR's own body. There is no separate noema-review/OpenCode verdict comment or an APPROVED GitHub review on this PR (get_reviews returns none) — only bot commentary (CodeRabbit draft-skip notice) — so there is no independent approval evidence either.

No code defect found in this PR's own change (test-harness temp-root canonicalization) — leaving it in Draft is correct. Once #546 reaches protected main, this exact head should get fresh reviewer evidence regenerated under the repaired gate before being considered for ready-for-review, consistent with the "Merge discipline" already stated for the sibling PRs above. No action taken beyond this evidence update.
Co-Authored-By: Claude Sonnet 5 noreply@anthropic.com
Claude-Session: https://claude.ai/code/session_01BV96rXhqoR3tYZ9AeAVur4


Generated by Claude Code

Copy link
Copy Markdown
Contributor Author

Fresh exact-head state supersedes the older queued block in this PR description. 601bba3edfa1d7b635a9f115732bcd7b52b77686 now has terminal ci 33698105808, Security Scan 33698105874, reviewer-ci 33698105806, and patch-validator-image 33698106022, all reported success, and there are currently zero inline review threads. I am still keeping this PR Draft rather than transferring those results into merge readiness because the reviewer evidence was produced under the pre-#546 CodeGraph semantic-admission contract. #546 remains the canonical fail-closed repair and is itself unverified/queued. Once that foundation reaches protected truth, this unchanged four-file test-harness delta should be revalidated under the repaired reviewer contract; no source churn or gate weakening is needed here.

Copy link
Copy Markdown
Contributor Author

Fresh exact-head reclassification for 601bba3edfa1d7b635a9f115732bcd7b52b77686: all four hosted workflow surfaces are now terminal success (ci 33698105808, required Security Scan 33698105874, reviewer-ci 33698105806, patch-validator-image 33698106022), and the fresh inline-thread read is empty. This supersedes the older PR-body statement that those runs were queued.

This does not make the PR merge-ready yet. The reviewer success was generated under the repository-wide pre-#546 CodeGraph semantic-admission contract; #546 (fb3510e8f5e5613c8b5a0bf9cebb3a6395688fe1) is still Draft with all four exact-head lanes queued. Keep #539 Draft and unchanged until #546 reaches protected truth and reviewer evidence is regenerated for this same exact head under the repaired semantic gate. No source churn or predecessor-evidence transfer.

Copy link
Copy Markdown
Contributor Author

Fresh protected-base repair supersedes the prior exact-head block. Protected main is e1ac9d50f6c646f04be8c137c8acdc7200182fcd. Ordinary two-parent non-force merge de64f66e94950e15dc213ec76093629d00fbe6e8 preserves the canonical temp-root security-test harness delta and inherits the protected stateless GitHub installation-token regression. Current exact-head workflows ci 33871953188, reviewer-ci 33871953162, required Security Scan 33871952998, and patch-validator-image 33871953203 are all queued/non-passing. The old four-workflow success set, including pre-#546 reviewer evidence, does not transfer. Keep Draft.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working priority: medium Normal-priority or P2 work status: draft Draft pull request type: bug Defect or incorrect behavior

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant