Own generation sessions and run artifacts in interfacectl - #31
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 8fdc82c946
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| const prohibitedRoles = uniqueStrings([...shellOwns, ...mustNotEmit]); | ||
|
|
||
| if (prohibitedRoles.length > 0) { | ||
| addRepair(repairs, "shell.primitive.disallowed", "high", "boundary", { |
There was a problem hiding this comment.
Align shell-boundary repair code with adapter findings
buildRepairMapPayload emits the shell-boundary repair as shell.primitive.disallowed, but adapter outputs use shell-owned-primitive-emitted (including the guard output and validate remapping), and runSummarizeGenerationSessionCommand matches recurring findings to repairs by exact code. In repeated shell-boundary failures, this mismatch prevents recurringRepairCodes from surfacing the corresponding boundary repair instruction, so session summaries lose actionable guidance for a high-priority violation.
Useful? React with 👍 / 👎.
| const loadedBundle = loadCompiledSurfaceBundle(options.bundleRoot, options.surfaceId, process.cwd()); | ||
| const sessionId = options.sessionId?.trim() || buildDefaultSessionId(); | ||
| const artifactsRoot = resolveWorkspaceRelative(workspaceRoot, options.artifactsRoot); | ||
| const sessionDir = path.join(artifactsRoot, options.surfaceId, sessionId); |
There was a problem hiding this comment.
Reject path separators in generation session IDs
The --session value is used verbatim in path.join(artifactsRoot, options.surfaceId, sessionId) without sanitization, so inputs like ../outside (or nested path segments) escape the intended artifacts/generation-sessions/... subtree. Because init-generation-session then creates directories, copies bundles, and writes JSON under that computed path, a crafted session ID can write artifacts outside the scoped session root and clobber unrelated files.
Useful? React with 👍 / 👎.
Summary
interfacectlVerification
pnpm --filter @surfaces/interfacectl-cli run testsuccessNotes
Surfaces-Platform/surfaces-webappsbranchcodex/surfaces-webapps-main-clean