Skip to content

fix: support Git LFS assets in canonical change evidence - #800

Draft
0xGaspar wants to merge 5 commits into
mainfrom
fix/lfs-canonical-evidence
Draft

0xGaspar wants to merge 5 commits into
mainfrom
fix/lfs-canonical-evidence

Conversation

@0xGaspar

@0xGaspar 0xGaspar commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Problem and change

Fixes #789. change check currently rejects a repository as soon as canonical workspace evidence encounters a Git LFS filter, even when those assets are unchanged and outside the delivery scope.

This change recognizes plain SHA-256 LFS v1 pointers and hashes downloaded asset bytes into the same canonical representation. Asset edits still change the evidence, including assets listed in ignored_paths; no assets are excluded to make verification pass. Large assets are streamed with bounded memory. Evidence queries disable LFS filters locally, without invoking git-lfs or fetching asset content. Unsupported filters, malformed pointers and pointer extensions remain rejected.

Validation

  • All six new LFS tests pass in the full project, including Git evidence and change-check lifecycle regressions.
  • Local type checks, lint and the mandatory pre-push gate pass.
  • Strict spec validation: 62 specs, zero warnings, 107/107 source files covered.
  • Scoped change check --commit passed and recorded verification on this branch.
  • Attest records the final commit’s automated validation; policy verification passed, with human approval explicitly false.
  • Full local verification passed: 2,510 unit tests, 437 integration tests, release build, 52 release-candidate validator tests and 29 CI-gate tests.
  • Augur verdict: review (risk 39.85; block threshold 65).

The approved change-package notes retain the earlier dependency-cache blocker as historical evidence. Bruno subsequently authorized a one-time fetch of locked Cargo dependencies, enabling the local validation above; current results are tracked in the living module specs.

Review

The two human-intent criteria were explicitly confirmed by Bruno. Human implementation review and same-PR SpecSync finalization are still pending; no review approval or merge readiness is claimed. Standard LFS pointers are supported; extension-based transformations remain out of scope. Hashing downloaded assets requires reading their contents, so I/O scales with asset size.

…ssets-in-canonical-change-evidence-without-hiding-content-changes
…-in-canonical-change-evidence-without-hiding-content-changes verification
github-actions[bot]
github-actions Bot previously approved these changes Sep 30, 2026

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Corvin says...

      _
    <(^\  .oO(Caw! ^v^)
     |/(\
      \(\\
      " "\\

"Looking sharp! Like a beak should be."

CI Summary

Check Status
Validate action.yml ✅ Passed
Packaged Action Consumer ✅ Passed
Dependency Audit ✅ Passed
Code Coverage ✅ Passed
Format Check ✅ Passed
Human intent check ✅ Passed
Docs Site ✅ Passed
Spec Validation ✅ Passed
Tests (build, test, clippy) ✅ Passed
VS Code Extension ✅ Passed
📋 Spec Validation Details

✅ SpecSync: Passed

Metric Value
Specs checked 62
Passed 62
Errors 0
Warnings 0
File coverage 100% (107/107)
LOC coverage 100% (149594/149594)

Generated by specsync · Run specsync check --format github to reproduce


Powered by corvid-pet

…ssets-in-canonical-change-evidence-without-hiding-content-changes
…-in-canonical-change-evidence-without-hiding-content-changes verification
@github-actions
github-actions Bot dismissed their stale review September 30, 2026 20:10

Superseded by updated review.

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Corvin says...

      _
    <(^\  .oO(Caw! ^v^)
     |/(\
      \(\\
      " "\\

"Caw! Your code sparkles like a dropped french fry."

CI Summary

Check Status
Validate action.yml ✅ Passed
Packaged Action Consumer ✅ Passed
Dependency Audit ✅ Passed
Code Coverage ✅ Passed
Format Check ✅ Passed
Human intent check ✅ Passed
Docs Site ✅ Passed
Spec Validation ✅ Passed
Tests (build, test, clippy) ✅ Passed
VS Code Extension ✅ Passed
📋 Spec Validation Details

✅ SpecSync: Passed

Metric Value
Specs checked 62
Passed 62
Errors 0
Warnings 0
File coverage 100% (107/107)
LOC coverage 100% (149594/149594)

Generated by specsync · Run specsync check --format github to reproduce


Powered by corvid-pet

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

change check rejects unchanged Git LFS assets through the whole-workspace evidence digest

1 participant