Skip to content

CI: anchor R9 immutable boundary on main - #13

Merged
EmergentMonk merged 1 commit into
mainfrom
ci/r9-trust-anchor
Sep 27, 2026
Merged

EmergentMonk merged 1 commit into
mainfrom
ci/r9-trust-anchor

Conversation

@EmergentMonk

@EmergentMonk EmergentMonk commented Sep 27, 2026 •

Copy link
Copy Markdown
Member

Adds a base-branch-only pull_request_target guard for R9 authority blobs and PR #12's frozen-surface allowlist. The workflow checks out candidate code as data and never executes it, so PR #12 cannot rewrite its own authority pins or allowlist.

Summary by Sourcery

Anchor R9 immutability checks to the trusted main branch and enforce the frozen-surface boundary for PR #12.

New Features:

Enhancements:

  • Ensure candidate changes cannot modify the trust-anchor workflow or immutable R9 authority files.

CI:

  • Run the trust-boundary validation for pull requests targeting main using trusted base-branch workflow code.

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @EmergentMonk, you've used your own review budget of 250,000 diff characters for the last 7 days.

You can request another review in 23 hours and 55 minutes by commenting @sourcery-ai review. Upgrade to get a review now.

@sourcery-ai

sourcery-ai Bot commented Sep 27, 2026

Copy link
Copy Markdown

Reviewer's Guide

Introduces a base-branch-controlled R9 trust-anchor workflow that compares candidate authority blobs and workflow integrity against trusted base content, while enforcing PR #12’s frozen-surface allowlist without executing candidate code.

Sequence diagram for the R9 immutable trust-anchor check

sequenceDiagram
    participant GitHub
    participant Base
    participant Candidate
    participant Guard as TrustAnchorWorkflow

    GitHub->>Guard: pull_request_target on main
    Guard->>Base: Checkout base SHA
    Guard->>Candidate: Checkout head SHA as data
    Guard->>Candidate: hash-object authority blobs
    Guard->>Base: hash-object trust workflow
    Guard->>Candidate: hash-object trust workflow
    alt PR_NUMBER == 12
        Guard->>Candidate: git diff baseline..HEAD --name-only
        Guard->>Guard: Check changed paths against allowlist
    end
    Guard-->>GitHub: Exit success or failure
Loading

File-Level Changes

Change Details Files
Add a trusted-base pull_request_target workflow that validates candidate changes against immutable R9 authority content.
  • Trigger only for pull requests targeting main, with read-only repository permissions.
  • Check out the base revision and candidate head into separate directories, treating candidate files as data.
  • Verify SHA-1 blob hashes for the three R9 authority files and require the trust workflow to match the base version.
  • Fail PR R9: complete historical target harnesses #12 when its changed paths fall outside the enumerated frozen-surface allowlist.
.github/workflows/r9-trust-anchor.yml

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-27T14:56:49.621048Z d4c8250 PR opened
🔒 Security Review ✅ Completed 2026-09-27T14:59:48.753635Z d4c8250 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@EmergentMonk
EmergentMonk merged commit 75f46a7 into main Sep 27, 2026
89 checks passed

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: d4c825089a

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

failed=1
fi

if [[ "$PR_NUMBER" == "12" ]]; then

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Enforce the frozen-surface check beyond PR 12

For every PR after #12, this condition skips the only base-controlled comparison against the pre-R9 baseline. A candidate can therefore alter a frozen R1-R8 path and weaken .github/workflows/r9-retro.yml in the same PR; that workflow executes candidate code, while this trusted job will still pass as long as the three pinned blobs and this file remain unchanged. Apply the frozen-surface restriction to every applicable R9 candidate rather than keying it to one PR number.

AGENTS.md reference: AGENTS.md:L137-L139

Useful? React with 👍 / 👎.

Comment on lines +79 to +80
done < <(
git -C candidate diff --name-only --no-renames "$baseline" HEAD

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Fail closed when the baseline is unavailable

When PR #12 comes from a fork or branch that does not contain 7d260e0—for example, one created before PR #11 merged—the candidate checkout has a separate object database and git diff exits with bad object. Because that command runs inside a process substitution, set -euo pipefail does not propagate its failure; the loop receives no paths and the job exits successfully, allowing changes to frozen R1-R8 files. Fetch the baseline into the candidate repository and explicitly check the diff command's status before accepting the allowlist result.

AGENTS.md reference: AGENTS.md:L137-L139

Useful? React with 👍 / 👎.

check_blob() {
path="$1"
expected="$2"
actual="$(git -C candidate hash-object -- "$path")" || {

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Hash committed blobs instead of following symlinks

On PR #12, each pinned path is allowlisted, so a candidate can commit it as a symlink to another allowlisted file containing the expected bytes. git hash-object reads the checked-out path and follows that symlink, causing this check to pass even though the committed object at the authority path is only a symlink blob; the same issue affects the workflow comparison below. Such a repository no longer preserves the pinned authority across checkouts that do not materialize symlinks, and replacing the guard itself can undermine future workflow discovery. Compare the committed HEAD:<path> blob and require a regular-file tree mode instead.

AGENTS.md reference: AGENTS.md:L127-L131

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant