Conversation
Preserve the exact tree of PR #474 CI-signed source e46716d (6af17c7) on signed ancestry from current dev. PR #474 retains implementation history, real RED evidence and review dispositions. This successor must pass fresh required CI and external capsule acceptance; earlier receipts do not confer authority on this commit.
External Python repositories could reach capsule analyzers without their dependencies or pytest plugins. This change discovers and prepares a separate project runtime through pip/pip-tools, Hatch, uv or Poetry. It adds read-only inspection, explicit project configuration and local v2 runtime descriptors while preserving existing review invocations and the v1 reader. Project imports, plugins and tests execute in isolated workers with recorded dependencies. Preparation failures preserve independent static findings and mark affected members incomplete. All review scopes attach runtime context; local preparation cannot grant protected `pr_range` authority. Implements OpenSpec `code-review-16-portable-project-runtime`, story #473 under Feature #163 / Epic #162. Addresses #472, which remains open pending the inaccessible original customer reproduction. Context: #466, #459, #175. This is the signed delivery successor to closed #474, which preserves the original development history, actual RED evidence and earlier review discussions. Core documentation follow-up is [PR #730](nold-ai/specfact-cli#730). Runtime discovery handles configuration-only setup.cfg repositories and pytest file/glob testpaths. Nested Python retains caller environment, cwd, private files and its verified member graph, including explicitly empty environments. Initial worker isolation remains mandatory. Six real subprocess cases exercise this in the reconstructed Hatch corpus. Build diagnostics remain in a private controller log. Builder stdout/stderr reaches it only through a pipe with bounded, nonblocking reads, a shared deadline and deterministic child/descriptor cleanup. The builder never inherits the regular log descriptor. Artifact preflight rejects symlinks, special files and multiply linked files before inventory/native enrichment; sealing and reuse also reject linked payloads/descriptors. Installed distributions are copied to independent artifact files. Actual RED/GREEN evidence covers log exposure, artifact aliases, select/read races, failure/timeout retention and copied-package compatibility. The exact reported Linux cross-bind hardlink exploit was not reproduced; tests distinguish that claim from the validated descriptor and topology boundaries. Current head is `ce96307188f80fb1e694e462957c4daa43159a71`. Full and smart suites each passed **2,697 tests**, with **one Linux-only /proc skip** and two existing lark warnings (124.65 and 125.63 seconds). All **28 contracts** passed. Formatting, typing, lint, YAML, import boundaries, strict OpenSpec, planned Requirements and normal signed Git hooks passed. The latest review fixes preserve sanitized controller validation codes and exact numeric builder exits alongside the private log path, without exposing arbitrary exception details. Nested Python now retains caller PYTHONPATH semantics, including relative/empty entries and child/grandchild inheritance. Trusted startup precedes caller path attachment. The final insertion uses a trusted list primitive captured before project hooks, avoiding a newly reproduced post-validation callback. Actual failing-before evidence records ten diagnostic failures, twenty native-versus-attached import-path failures and one callback regression. Focused checks passed 42 diagnostic tests (one Linux-only skip) and 115 launch/bootstrap tests. The reconstructed Hatch corpus now includes a caller-only relative import through a child and grandchild. Fresh explicit-file SpecFact bug-hunt review at **2026-09-15T02:43:37.908786Z** returned **PASS_WITH_ADVISORY**, exit 0: one testing error from the Linux-only local skip, six documented startup-contract/private-access warnings and three explicit-structure informational findings. The newly introduced line-length warning was corrected. The platform skip remains incomplete evidence; exact local-only dispositions in `REVIEW_EXCEPTIONS.md` cannot waive failed or missing Linux acceptance. An earlier report was correctly discarded as UNKNOWN because an evidence document changed during analysis; the final report used an unchanged tree. Canonical [CI signing run 34922474811](https://github.com/nold-ai/specfact-cli-modules/actions/runs/34922474811) produced the publisher signature. Its exact manifest bytes were retained in a normally hooked signed Git commit. Delivery tree `73512dff07b46106daed3f1239c4d9e8f9932abf` is identical to CI source `cf05d4a222810465fcb29ed47fa87e4bedf72e5e`; no unsigned bot ancestry was merged. Strict public-key verification passed all seven manifests. GitHub CI owns signatures and registry publication. All tracked review findings are resolved after pushed fixes and current Linux validation. Resolution replies 4011682282, 4011682362 and 4011682440 record the evidence for the final three threads. Current-head Codex code review completed without new findings; this does not claim a new dedicated security review. Current signed candidate `ce96307188f80fb1e694e462957c4daa43159a71` passed every native and quality job in [run 34922619042](https://github.com/nold-ai/specfact-cli-modules/actions/runs/34922619042). Independent checks verified all three provider ZIP digests/sizes, tested merge `edfd14cd32f8281675fe0492b2618d3fafb50893`, its expected parents and identical delivery tree. All **15 combinations** completed: **189 host, 189 cold and 189 warm passed calls**, plus **15 controlled failing calls with source-defect detection**. All ten analyzers completed in 45 reports without unknown required evidence. The new explicit-PYTHONPATH child/grandchild case passed all nine host/cold/warm executions across the three ABIs. Linux quality logs confirm the descriptor, numeric-exit, diagnostic, PYTHONPATH and container-hook regressions passed. Each ABI full suite passed 2,696 tests, with two case-collision tests skipped because the Linux filesystem preserves case-distinct identities and two existing warnings. Provider ZIPs: 3.11 artifact10379405086 SHA-256 `f4d251639c48441ce335ebea73d2a6d84e140cc9cd208aa45a9908e94b5ea12e`; 3.12 artifact10379063595 SHA-256 `c8f0b002ee76bc488c9f3877c27377585384b3e4256274d0dc6139744164727c`; 3.13 artifact10379181482 SHA-256 `766bcd2924fc742eb66c7728c96aa5f44e0924c279283736acb8a9b9b13c427e`. These are candidate overlays over the public signed baseline, not public signed 0.50.0 installation acceptance. Source immutability is recorded by the harness; offline verification uses the retained namespace probe rather than host-wide byte counters. Real static findings remain visible in untouched Requests and reconstructed Hatch. The corpus pins Requests, Hatch, Flask and Poetry plus a labelled reconstructed detached-Hatch fixture across Python 3.11–3.13. It records host, cold/warm capsule, controlled-defect, source-immutability, timing and transfer evidence separately. Acceptance requires completed applicable analysis and real execution, not zero findings. The reconstruction does not validate the inaccessible customer PR. Core PR #730 passes its normal checks and protected retained-RED reconciliation: 38 actual original failures become 38 passes with unchanged tests/mapping and verified ancestry. Its remaining review thread tracks refreshing the documentation fixture to the final accepted module source. Preserve its separate Requirements execution fixture and obtain new exact-head authority after that update. Execution support remains **Linux x86-64, Python 3.11–3.13**. Automatic Windows/macOS handoff is not implemented. Mixed analyzer/project namespace portions are not composed. Unsupported Poetry caret, tilde, union and table constraints receive explicit diagnostics. Version **0.50.0** is still unpublished; the registry baseline is 0.49.85. Remaining delivery gates are protected integration, CI registry publication and the corpus through public signed installation. Protected integration is blocked by a verified Code Quality trigger/ruleset mismatch: the provider scans PRs to main, while ruleset 19505704 also requires its result on dev. No Code Quality run exists for this PR, and manual dispatch is unsupported (HTTP 422). Normal protected auto-merge remains enabled. See the latest blocker evidence comment; no protections were changed. Keep #472 open until its original customer reproduction is validated. Rollback requires reviewed changes and a new signed version, preserving immutable prior artifacts. CodeRabbit skipped the original 193-file successor because its per-review limit is 150; its green status does not establish review coverage. Earlier review history remains in #474, supplemented by independent reviews and Codex code/security reviews. Strix did not run because its trial ended; no billing changes were made.
Automated registry publish update from workflow run 35007410944. Bundle selection reasons: - `specfact-code-review`: changed, registry-outdated
|
Strix is installed on this repository, but we couldn't run this PR security review because this workspace's trial has ended. Add a card to resume code reviews here. So far, Strix has reviewed 48 pull requests across this workspace. |
|
Warning Review limit reached
On-demand reviews are free for the next 4 days. After that, they cost $0.25 per reviewed file. View limit detailsReview configuration: ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Essentials Run ID: ⛔ Files ignored due to path filters (4)
📒 Files selected for processing (284)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Comment |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 23410c2d1f
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
#478) Portable review now prepares and attaches the selected repository runtime while preserving native imports, pytest options, test outcomes and coverage policy. Previously, installed source copies could appear uncovered; runtime activation was lost in materialized snapshots; and review instrumentation could activate a customer aggregate coverage gate that ordinary pytest had not requested. The controller now attributes installed coverage only through verified distribution ownership and exact source bytes. It preserves raw evidence and rejects ambiguous, modified or transformed sources. Uniquely RECORD-owned top-level `py_modules` also retain byte-verified attribution without measuring all of site-packages; ambiguous default module/directory selectors produce explicit incomplete evidence. Snapshot runtime selection retains verified Hatch activation and explicit configuration precedence. Declared native tools and public CA certificates are sealed into the runtime, with cache identities and no ambient host dependency fallback. Pytest keeps every non-pass result and native coverage control, including configured sources, exclusions, report destinations, disabled coverage, thresholds and precision. Reviewer-owned measurement uses a separate collector with the native plugin lifecycle; it does not alter an active customer collector or suppress native failures. Missing worker receipts, excluded reviewed sources and unsupported collection remain explicit incomplete evidence. Each reviewed production file still requires at least 80% coverage or the higher effective configured threshold. Native aggregate threshold failures receive a specific blocking diagnostic. Related story #473, defect #472, release PR #477, and OpenSpec `code-review-16-portable-project-runtime`. This also fixes release comments4019944740/4019944751 and PR478 startup-root comment4020397305. The controlled-defect corpus now imports and calls the deliberately wrong-return function from an explicitly pinned package path. This preserves native coverage scope and the required type-failure, test-failure and complete-evidence checks. The previous injector never called its function and placed it outside several native coverage scopes. ## Validation - Final original full and smart suites: **3,014 passed, one Linux-only /proc skip, two existing lark warnings** each (149.94s and 149.57s). - Real pytest-cov7.0.0/7.1.0, xdist and subprocess tests cover native/reviewer lifecycle, report fidelity, thresholds, exclusions and missing evidence. New collector coverage97.04%; introduced bootstrap loader27/28 statements covered. Whole legacy bootstrap coverage remains separately qualified; no coverage threshold was reduced. - Strict OpenSpec, planned Requirements evidence, formatting, typing, lint, YAML/import checks and all original commit hooks passed. Fresh full bug-hunt passed with documented legacy/boundary advisories; the final affected review had zero warnings/errors and two informational fixture-length suggestions. Independent reviews reported no remaining findings. - Follow-up source commit `2cd93755` and exact CI-signature import `8ef33d6a` are GPG-signed and GitHub verified. Canonical [CI signing 35131005219](https://github.com/nold-ai/specfact-cli-modules/actions/runs/35131005219) passed. Exact CI manifest bytes were imported without unsigned bot ancestry; strict filesystem payload, version and cryptographic verification passed all seven manifests. - Single-module regressions: 55 bridge, 128 wiring and 32 helper tests passed, including real imports, unrelated-module exclusion and native/configured source preservation. Controlled-package fixture regressions: 47 passed, including actual traced function execution under unchanged source_pkgs and omit-only coverage configurations. Committed RED evidence and independent reviews support both corrections. - [Current-head candidate CI 35150340281](https://github.com/nold-ai/specfact-cli-modules/actions/runs/35150340281) passed all three candidate jobs for signed head `8ef33d6a` across Python 3.11–3.13. All 45 retained external reports were independently checked: 30 cold/warm executions passed; all 15 controlled defects produced actual test and type failures with the bad function executed and zero UNKNOWN evidence. All three corpus summaries are PASS. Signatures, Requirements evidence, Docs Review, CodeQL, CodeRabbit and minimum-core compatibility checks have passed; all three Linux quality suites passed with 3,015 tests, two existing warnings and no skips each; both case-sensitive file/directory tests explicitly passed on every ABI. All current-head integration checks are green. - Previous candidate 35124077143 failed: all 30 cold/warm pinned-corpus executions passed without UNKNOWN evidence, but nine controlled-defect runs exposed the injector defect corrected here. That failure and the earlier signed 0.50.0 failures remain regression evidence, not acceptance of the current candidate. ## Release and limits Candidate version **0.50.1** preserves immutable0.50.0 assets. GitHub CI owns registry publication and signatures. Linux x86-64 is the supported execution platform; macOS/Windows controllers receive capability diagnostics rather than claimed native execution. Current-head candidate gates and the pinned upstream corpus must pass before integration; public signed-installation acceptance follows protected publication. The original customer repository remains inaccessible. Defect #472 and story #473 stay open until acceptance passes. The paired core fixture update must bind the final accepted module identity. Rollback is a reviewed revert and a new signed version, preserving existing immutable assets.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 046d366c19
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Automated registry publish update from workflow run 35154689597. Bundle selection reasons: - `specfact-code-review`: changed, registry-outdated
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 3d6e984f8d
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Deferred follow-up tracked in #480 (P2: preserve explicitly selected pytest files). The ticket includes the original annotation, proposed reproduction, acceptance criteria, and a triage ledger distinguishing the P1 findings already addressed by #478/#479. Per the maintainer decision, Code Review 0.50.1 remains frozen. This follow-up is for a subsequent version and does not request further changes to the 0.50.1 source or release artifacts. The resolved P2 thread denotes deferral, not a completed fix. |
Promote portable Code Review runtime documentation and authenticated command generation from `dev` to `main`, accompanying [Code Review module 0.50.1 / modules PR #477](nold-ai/specfact-cli-modules#477). This includes #730 and the validated fixture follow-up #737, linked to #728 and OpenSpec `docs-16-code-review-runtime-parity` / `docs-17-code-review-pytest-fixture-parity`. The generated reference includes runtime inspect/prepare and project configuration/runtime options. Documentation workflows authenticate their separate immutable module source before loading it. The approved Requirements execution fixture and frozen test mappings remain unchanged. ## Validation and promotion - #737 merged as `1bd17dbfed1ae5b3b806e5d7d5882ab032cf2cef`; its tree `4c9ba46b2ace65cd8df0fcd5a77c2b14a42f599c` exactly matches validated head `947df30724953419d61ad0d9924c8e6c13024cba`. - The documentation fixture now selects accepted, CI-signed modules source `046d366c190af7a188d6f48953a96edb65e766db` (Code Review 0.50.1), delivered by [modules #478](nold-ai/specfact-cli-modules#478). Automated registry publication was integrated by [modules #479](nold-ai/specfact-cli-modules#479). - Protected #737 Requirements CI run [35156480395](https://github.com/nold-ai/specfact-cli/actions/runs/35156480395) reconciled the six frozen pytest regressions against genuine prior failing evidence: `implementation-verified`, `passing-after-red-proven`, no findings. Existing 38-case proof remains intact. - Local follow-up validation: six regression cases passed; existing 38 cases and 60 documentation tests passed; smart suite 3,206 passed, 10 skipped, two existing warnings. All #737 protected checks passed before merge. - CHANGE_ORDER now includes the omitted CI change and reconciles the inventory to 35 active-tree, 21 parking-lot and 120 archived entries. The corresponding release review thread is addressed by #737. - Fresh main-target Requirements promotion [35157226973, attempt 2](https://github.com/nold-ai/specfact-cli/actions/runs/35157226973) and Trusted Requirements Authority [35157229290, attempt 2](https://github.com/nold-ai/specfact-cli/actions/runs/35157229290) passed on the merged head. All reported checks pass. GitHub still expects `Assert signing reproducibility`, whose workflow is restricted to a post-merge push to main; this protection/workflow mismatch remains a merge blocker. No protection was changed or bypassed. ## Release boundaries Code Review **0.50.1 is frozen**. The explicit pytest-file selection P2 is deferred to [modules #480](nold-ai/specfact-cli-modules#480) for a subsequent version; do not alter 0.50.1 source or immutable publication assets for that follow-up. Modules #477 merged to main as `b3ca3014c8d0e064b860856d4b560a2591999532`; canonical signing/publication workflows passed. Public signed-installation corpus run [35158056310](https://github.com/nold-ai/specfact-cli-modules/actions/runs/35158056310) is still running, so its acceptance remains outstanding. Capsule execution support remains Linux x86-64 on Python 3.11–3.13; automatic Windows/macOS handoff is not implemented. No core version bump or Python package publication is implied by this documentation promotion. Rollback is a reviewed revert of the documentation/tooling changes; immutable prior artifacts remain available.
Promote Code Review 0.50.1 from
devtomainso public signed installation can prepare and attach external Python project runtimes. This includes the portable runtime implementation from #475, the validated runtime/pytest corrections merged in #478, and the CI-produced 0.50.1 registry assets merged in #479.Refs: User Story #473, defect #472, OpenSpec
code-review-16-portable-project-runtime.Scope and behavior
nold-ai/specfact-code-review0.49.85 → 0.50.1 in the public main registry. Other bundles are unchanged; core compatibility remains>=0.55.1,<1.0.0.Validated candidate
PR #478 acceptance run 35150340281 passed on Linux x86-64 with Python 3.11, 3.12 and 3.13 at signed head
8ef33d6a7b9f9881acac81009da47a1c64ce93a8.046d366c190af7a188d6f48953a96edb65e766db.Canonical publication run 35154689597 produced the 0.50.1 registry update merged through #479. The archive is 410,572 bytes, SHA-256
61489b8b3e9596082f738d093987fe0427815b2a6148cfae678a996878d117e7. Its embedded signed manifest exactly matches the validated candidate. This release PR must still satisfy its own current-head protected checks and merge requirements.Remaining release gates and limits
devdo not establish public-main installation acceptance.Rollback requires a reviewed revert and a new signed version, preserving immutable artifacts. Reverting restores the earlier customer limitation.