Repository navigation
CI: anchor R9 immutable boundary on main - #13
Conversation
There was a problem hiding this comment.
Sorry @EmergentMonk, you've used your own review budget of 250,000 diff characters for the last 7 days.
You can request another review in 23 hours and 55 minutes by commenting @sourcery-ai review. Upgrade to get a review now.
Reviewer's GuideIntroduces a base-branch-controlled R9 trust-anchor workflow that compares candidate authority blobs and workflow integrity against trusted base content, while enforcing PR #12’s frozen-surface allowlist without executing candidate code. Sequence diagram for the R9 immutable trust-anchor checksequenceDiagram
participant GitHub
participant Base
participant Candidate
participant Guard as TrustAnchorWorkflow
GitHub->>Guard: pull_request_target on main
Guard->>Base: Checkout base SHA
Guard->>Candidate: Checkout head SHA as data
Guard->>Candidate: hash-object authority blobs
Guard->>Base: hash-object trust workflow
Guard->>Candidate: hash-object trust workflow
alt PR_NUMBER == 12
Guard->>Candidate: git diff baseline..HEAD --name-only
Guard->>Guard: Check changed paths against allowlist
end
Guard-->>GitHub: Exit success or failure
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: d4c825089a
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| failed=1 | ||
| fi | ||
|
|
||
| if [[ "$PR_NUMBER" == "12" ]]; then |
There was a problem hiding this comment.
Enforce the frozen-surface check beyond PR 12
For every PR after #12, this condition skips the only base-controlled comparison against the pre-R9 baseline. A candidate can therefore alter a frozen R1-R8 path and weaken .github/workflows/r9-retro.yml in the same PR; that workflow executes candidate code, while this trusted job will still pass as long as the three pinned blobs and this file remain unchanged. Apply the frozen-surface restriction to every applicable R9 candidate rather than keying it to one PR number.
AGENTS.md reference: AGENTS.md:L137-L139
Useful? React with 👍 / 👎.
| done < <( | ||
| git -C candidate diff --name-only --no-renames "$baseline" HEAD |
There was a problem hiding this comment.
Fail closed when the baseline is unavailable
When PR #12 comes from a fork or branch that does not contain 7d260e0—for example, one created before PR #11 merged—the candidate checkout has a separate object database and git diff exits with bad object. Because that command runs inside a process substitution, set -euo pipefail does not propagate its failure; the loop receives no paths and the job exits successfully, allowing changes to frozen R1-R8 files. Fetch the baseline into the candidate repository and explicitly check the diff command's status before accepting the allowlist result.
AGENTS.md reference: AGENTS.md:L137-L139
Useful? React with 👍 / 👎.
| check_blob() { | ||
| path="$1" | ||
| expected="$2" | ||
| actual="$(git -C candidate hash-object -- "$path")" || { |
There was a problem hiding this comment.
Hash committed blobs instead of following symlinks
On PR #12, each pinned path is allowlisted, so a candidate can commit it as a symlink to another allowlisted file containing the expected bytes. git hash-object reads the checked-out path and follows that symlink, causing this check to pass even though the committed object at the authority path is only a symlink blob; the same issue affects the workflow comparison below. Such a repository no longer preserves the pinned authority across checkouts that do not materialize symlinks, and replacing the guard itself can undermine future workflow discovery. Compare the committed HEAD:<path> blob and require a regular-file tree mode instead.
AGENTS.md reference: AGENTS.md:L127-L131
Useful? React with 👍 / 👎.
Adds a base-branch-only pull_request_target guard for R9 authority blobs and PR #12's frozen-surface allowlist. The workflow checks out candidate code as data and never executes it, so PR #12 cannot rewrite its own authority pins or allowlist.
Summary by Sourcery
Anchor R9 immutability checks to the trusted main branch and enforce the frozen-surface boundary for PR #12.
New Features:
Enhancements:
CI: