Skip to content

Fix: harden guided checkpoint reuse - #142

Merged
0xLeif merged 1 commit into
mainfrom
leif/fix-guided-example-hardening
Jul 29, 2026
Merged

0xLeif merged 1 commit into
mainfrom
leif/fix-guided-example-hardening

Conversation

@0xLeif

@0xLeif 0xLeif commented Jul 29, 2026

Copy link
Copy Markdown
Owner

Summary

  • avoid unfiltered state dumps during agent-memory startup
  • consume the complete key inventory and validate compatible key metadata and storage paths before reuse
  • cover a 12,000-key inventory plus incompatible type and path collisions

Test Plan

  • fledge lanes run verify
  • serial tests: 266 passed, 0 failed
  • parallel tests: 266 passed, 0 failed
  • smoke, release, and guided example contracts pass
  • SpecSync CHG-0067 verified and accepted

@cursor

cursor Bot commented Jul 29, 2026

Copy link
Copy Markdown

Bugbot is not enabled for your account, so this pull request was not reviewed.

Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs.

@0xLeif
0xLeif merged commit 8fb9cb3 into main Jul 29, 2026
5 checks passed
@0xLeif
0xLeif deleted the leif/fix-guided-example-hardening branch July 29, 2026 17:23

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

馃挕 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: a9c026c563

鈩癸笍 About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 馃憤.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +31 to +34
index($0, "\"name\" : \"" key "\"") { in_entry = 1; found = 1 }
in_entry && index($0, "\"path\" : \"" expected_path "\"") { path_matches = 1 }
in_entry && /^ }/ { exit(path_matches ? 0 : 1) }
END { if (!found || !path_matches) exit 1 }

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Parse compatible schemas independently of JSON formatting

When a valid pre-existing schema.json was minified, reformatted, or serialized with path before name, these whitespace- and order-sensitive patterns do not find the entry even though the CLI's JSONDecoder accepts it. Both guided scripts then return 65 for a fully compatible checkpoint schema, so the path must be obtained through structural JSON parsing rather than matching the CLI writer's current pretty-print layout; the identical helper in examples/release-pipeline/run.sh has the same failure.

Useful? React with 馃憤聽/ 馃憥.

in_entry && index($0, "\"path\" : \"" expected_path "\"") { path_matches = 1 }
in_entry && /^ }/ { exit(path_matches ? 0 : 1) }
END { if (!found || !path_matches) exit 1 }
' "$APS_HOME/schema.json"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Resolve APS_HOME the same way as the CLI

When APS_HOME contains a supported tilde path such as APS_HOME='~/.agents/codex', aps expands it in APSPaths.resolve, but this direct file access tries to open a literal ~/.../schema.json relative to the working directory. The preceding CLI calls therefore operate on the intended root while validation fails, potentially after adding the first key; use the CLI-resolved root rather than concatenating the raw environment value. The release-pipeline helper has the same direct access.

Useful? React with 馃憤聽/ 馃憥.

Comment on lines +18 to +20
"$aps_bin" key add "$name" \
--type "$type" --storage FileState --path "$path" --doc "$doc" \
"$@" >/dev/null

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Validate every existing key before adding missing ones

When an incompatible collision occurs on a later checkpoint key while one or more earlier keys are absent, each earlier ensure_key call adds its key before the later collision is examined. For example, a root containing only an incompatible blocker leaves currentIssue, workingBranch, phase, and testsPassed added even though the script exits 65, contradicting the change's stated fail-before-mutation behavior. Both scripts need a complete validation preflight before performing any key add operations.

Useful? React with 馃憤聽/ 馃憥.

@0xLeif 0xLeif mentioned this pull request Jul 29, 2026
3 tasks done
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant