Conversation
|
Coordinator decision record for exact head aa9ccce Decision: split the trust migration into this prerequisite and the later pull request #65 refresh. Facts:
Rejected alternatives:
This prerequisite adds trusted expectations and schema 2 validation only. The live registry still binds six schema 1 receipts and zero schema 2 receipts. The old comparator at 84fdf96 fails the new self-authorization guard with DID NOT RAISE. This head passes the same guard. The complete local evidence is in the pull request body. GitHub Codex and one cold built-in reviewer provide the two independent reviews. Pull request #65 will consume the new trusted expectations only after this prerequisite reaches master. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: aa9ccce744
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review Review target: This correction addresses all current findings at the prior head. Decisions and mechanisms:
Rejected alternatives:
Verification on this exact candidate:
One independent built-in cold breadth re-review is running on this exact commit. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: c03f1f9003
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| launcher_path.write_text(_PYTEST_LAUNCHER, encoding="utf-8", newline="\n") | ||
| report_path = plugin_dir / "pytest-report.json" | ||
| environment = _test_environment(worktree, python) | ||
| environment["CRYODAQ_RED_REPRODUCTION_REPORT"] = str(report_path) |
There was a problem hiding this comment.
Protect the capture report from candidate hooks
When the defective commit contains a conftest.py session-finish hook, that candidate code can read CRYODAQ_RED_REPRODUCTION_REPORT and overwrite the JSON after the trusted plugin writes it (for example, with a tryfirst hookwrapper whose teardown runs last). I reproduced this against the exact producer: an unrelated failure originating in helper.py was accepted after the hook forged the expected guard path and message. The report therefore needs an authenticated/protected channel that code under test cannot write, rather than a candidate-visible filesystem path.
AGENTS.md reference: AGENTS.md:L380-L386
Useful? React with 👍 / 👎.
| import sys | ||
| from pathlib import Path | ||
|
|
||
| import pytest |
There was a problem hiding this comment.
Load pytest outside the defective checkout namespace
When the defective tree contains src/pytest.py (or an equivalent package), this launcher imports that checkout-controlled module because _test_environment places <worktree>/src on PYTHONPATH before the interpreter starts. Its fake main() can invoke or bypass the trusted plugin, emit the accepted failure summary/report, and return 1 without running real pytest. Fresh evidence after the file-bound plugin fix is that the launcher still resolves pytest through the defective checkout, so load and verify the real pytest package before exposing candidate import paths.
AGENTS.md reference: AGENTS.md:L380-L386
Useful? React with 👍 / 👎.
| _mode, kind, object_id = _tree_entry(root, candidate, path) | ||
| if kind != "blob": | ||
| raise RedReproductionComparisonError(f"candidate-added red-reproduction evidence is not a blob: {identity}") |
There was a problem hiding this comment.
Require a safe mode for newly added receipts
When a candidate adds a schema-v2 receipt with mode 100755, this branch discards _mode and accepts the executable JSON blob; the full registry validator also reads only its bytes, so both Linux and Windows checks can remain green. Once that candidate becomes the trusted base, the inherited-binding logic preserves this unsafe mode permanently and refuses later correction. Require candidate-added receipts to start as regular non-executable 100644 files, just as the manifest does.
Useful? React with 👍 / 👎.
Purpose
Protected CI loads the red-reproduction judge from the trusted base. The current judge accepts only exact schema 1 receipts.
Pull request #65 creates schema 2 receipts. It cannot safely change the judge and use that changed judge in one candidate.
This prerequisite changes the trusted judge first. It does not add a schema 2 receipt binding.
Decision
Rejected alternatives
Evidence
The candidate is aa9ccce.
The red-before control used the same new guard on commit 84fdf96. The guard failed because the old comparator did not raise. The candidate passes that guard.
Hosted CI is pending. This pull request stays in draft until Codex returns a clean exact-head verdict and no live findings remain.
Follow-up
After this prerequisite merges, refresh pull request #65 onto the new master. Regenerate its schema 2 receipts against that trusted base. Then repeat its reviews and merge gates.