Add complete fake adapter 2×2 contract matrix - #205
Conversation
Deploying ystack with
|
| Latest commit: |
7536643
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://2dbc9c01.fabrica-6yx.pages.dev |
| Branch Preview URL: | https://codex-portable-adapter-contr.fabrica-6yx.pages.dev |
Codex reviewer (cross-vendor, read-only)Reviewed-head: 188587b Posted verbatim by The contract runner does not independently bind complete Git references, accepts protocol data beyond the validated response, and its negative matrix bypasses the real validation path. These issues undermine the central guarantees the new matrix is intended to prove. Full review comments:
|
Codex reviewer (cross-vendor, read-only)Reviewed-head: 3de11d9 Posted verbatim by The matrix can emit passing Git-provenance observations for unresolved source references and can miss target repository mutations. These gaps undermine two core assertions of the new contract runner. Full review comments:
|
Codex reviewer (cross-vendor, read-only)Reviewed-head: d0b370a Posted verbatim by The adapter runner does not reliably contain timed-out subprocesses or stop after termination signals, and its fixture setup can fail under valid Git hash-format configuration. These are functional reliability issues in the new contract suite. Full review comments:
|
Codex reviewer (cross-vendor, read-only)Reviewed-head: 3eae067 Posted verbatim by The runner can execute bytes other than the verified Git package and can leave adapter descendants running after accepting a response. Both undermine the claimed digest and disposable-process boundaries. Full review comments:
|
Codex reviewer (cross-vendor, read-only)Reviewed-head: a4b3ac8 Posted verbatim by The request protocol accepts payload digests without validating them against the payload bytes. Combined with mutable target rereads, this can produce a successful observation bound to the wrong target content. Review comment:
|
Codex reviewer (cross-vendor, read-only)Reviewed-head: e9dea66 Posted verbatim by The runner snapshots several trust-boundary inputs but continues using their mutable original paths. Concurrent changes can invalidate inventory authorization, repository mapping, and reported profile provenance. Full review comments:
|
Codex reviewer (cross-vendor, read-only)Reviewed-head: 2dd595e Posted verbatim by The adapter runner has a signal-handling race that can leave a launched process group running after the runner exits. This undermines the cleanup and containment behavior introduced by the patch. Review comment:
|
Codex reviewer (cross-vendor, read-only)Reviewed-head: 7536643 Posted verbatim by The adapter matrix, protocol validation, provenance checks, process cleanup, and regression coverage appear internally consistent. No actionable correctness issue was identified in the diff. |
Summary
Review size
This is one end-to-end adapter-contract concern. Its complete implementation keeps runner, four distinct packages, canonical inventory checks, unrelated fixture, and adversarial matrix together. Splitting them would leave an unprovable partial runner or duplicate the same protocol boundary.
Safety
This is inactive, fake-only, and repo-only. It is not a generic adapter launcher and provides no real-adapter qualification, credential, network or host isolation, authority, approval, remote branch write, release, install, profile activation, or deployment. Core generations, resolver, and stable wrapper are unchanged.
The test alone bootstraps the same official jq 1.6 asset used by existing core/resolver tests, with TLS 1.2+ and a fixed platform SHA-256 before use. The product runner and fake adapters remain network-free.
Targeted proof
Exact head:
7536643bbec4d98bd658ccb4040af8383082f0bfExact base:
04d5c166318f118012bc222de50e0130f2dbe91dTracks #153