fix(api): validate vuongtest and icci option arguments - #126
Conversation
|
👋 Jules, reporting for duty! I'm here to lend a hand with this pull request. When you start a review, I'll add a 👀 emoji to each comment to let you know I've read it. I'll focus on feedback directed at me and will do my best to stay out of conversations between you and other bots or reviewers to keep the noise down. I'll push a commit with your requested changes shortly after. Please note there might be a delay between these steps, but rest assured I'm on the job! For more direct control, you can switch me to Reactive Mode. When this mode is on, I will only act on comments where you specifically mention me with New to Jules? Learn more at jules.google/docs. For security, I will only act on instructions from the user who triggered this task. |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Team Run ID: 📒 Files selected for processing (3)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthrough
Changes입력 검증
Estimated code review effort: 2 (Simple) | ~10 minutes Merge Risk: ⚪ Minimal · up to vuongtest() and icci() now fail early for invalid inputs while preserving covered valid-input behavior. No merge-blocking risk remains. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Current authority
master@b62bf9ac928988a4b988fc3efb0adfb88549fef25a4be4cc5e231dc14155b611b4396ec631d5083aR/icci.R,R/vuongtest.R,tests/testthat/test_exported_input_validation.RValid delta
The exported
vuongtest()boundary rejects invalidnestedandadjvalues before model inspection.icci()requires a scalar numericconf.levelstrictly inside(0, 1). The persistent regression covers zero-length, non-scalar, NA/NaN/infinite, wrong-type, boundary and out-of-domain values through the exported functions themselves, and every package-owned validation error must have the selected stable message plusconditionCall(err) == NULL.The source/test contract is input-contract hardening and deterministic error behavior. It is not promoted to a MEDIUM information-disclosure or denial-of-service vulnerability without a demonstrated deployment/threat model.
Duplicate-lane convergence
Generated PRs #99, #100, #103, #106 and #108 each changed only the same exported option-validation surface plus branch-local
.jules/sentinel.md; none carried a stronger executable regression than this lane. Their valid product semantics are fully present here, while the generated Sentinel doctrine is intentionally excluded because it is not protected repository authority.For #108, normal two-parent descendant
5a4be4cc5e231dc14155b611b4396ec631d5083arecords exact predecessor9b671ba6452b44e65c141ff574626cc0f957b78eas an ancestor while preserving the exact current semantic tree from6e68c37df52d3b7407bcb3c028d64ac7b5f2e122. Fresh#108 -> currentcomparison is ahead 19 / behind 0. #99/#100/#103/#106 were closed only after their diffs were re-read and the same valid source behavior was verified here; their generated doctrine is not treated as valid delta and none of their checks/reviews transfer.Fresh close-time review also verified #127 live exact
8274b193e7e48622e3c8140e6d0d1cd9191efc39carried no product semantic beyond thisconf.levelcontract. Its current regression was weaker because it exercised five cases through fitted MASS models, while this lane tests the exported admission boundary directly across zero-length, non-scalar, missing/non-finite, type and range cases. #127 was therefore closed unmerged only under verified complete succession; its branch-local.jules/sentinel.mddeletion was not treated as protected product authority.This convergence is provenance/single-writer repair, not a CI re-kick. Current exact-head evidence executes independently.
Callback-contract child
Former separate lane #122 still owns useful
ll1/ll2,score1/score2,vc1/vc2callback contracts plusNEWS, but it is stale/diverged from current protected authority. Draft child #129 is now stacked directly on this exact #126 head and carries those remaining semantics through a new exported-boundary RED and minimal callback guards. Current #129 exact is39d3cad1f4774f5a61bdc31427a90ca6da691bc2; #122 remains open until #129 obtains executable exact-head acceptance.#129 currently has zero check runs because the repository
R-CMD-check.yamladmits pull requests only when the PR base ismainormaster, while #129 correctly targets this prerequisite feature branch. That stack-evidence materialization RCA has been delivered read-only to canonical.github#712; no no-op child commit or #126 evidence transfer is used.Exact-head gate
R-CMD-check
34139084780is terminal SUCCESS on exact5a4be4cc.... CodeQL PR34139083971, SAST Semgrep34139083990, and Security Scan34139084031remain queued at the latest fresh read. There are no submitted reviews or inline review threads. Queued is not GREEN and predecessor evidence does not transfer. The split repository-GREEN/central-queued canary remains on the canonical.github#712owner path.Keep Draft until unchanged exact
5a4be4cc5e231dc14155b611b4396ec631d5083ahas terminal applicable Security/SAST/CodeQL evidence, zero valid unresolved findings, and the then-live qualifying independent review. No predecessor GREEN, source-neutral retry commit, self-approval, gate weakening, force push, or destructive rebase.