Skip to content

fix: repair authored skill safety and integration contracts - #54

Merged
scrimshawlife-ctrl merged 5 commits into
mainfrom
fix/continuity-review-cycle1
Sep 15, 2026
Merged

scrimshawlife-ctrl merged 5 commits into
mainfrom
fix/continuity-review-cycle1

Conversation

@scrimshawlife-ctrl

Copy link
Copy Markdown
Owner

Summary

Make embedded/package Kubrick evolution plan-first, idempotent, evidence-bound and recovery-aware; preserve index entries; repair profile installation and MCP/writing recipes.

Verification

  • Independent initial review and bounded fix re-review passed for the recorded commit.
  • Parent reran python -m pytest -q -ra --tb=short -o addopts= tests -m 'not integration' in an isolated Python 3.12 environment.
  • Result: 255 passed, 2 deselected, 2 warnings in 5.39s
  • Changed-file syntax, Hermes frontmatter, whitespace and added-line security checks passed.

Scope and limits

Original working checkouts and installed profiles remain untouched; tests use disposable fixtures. No production deployment, live approval/enrollment, paid provider use, merge or release was performed. This is not a full production-service or crash-atomicity certification. Existing license grants are unchanged.

Live Postgres/MinIO integrations were deselected. Installed-wheel dry-run/apply/replay smoke also passed.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 5, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-05T01:41:33.602612Z 2d0350d PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 2d0350d8b4

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +84 to +86
These calls may write candidate artifacts but do not acquire a canon lease.
Do not add unsupported expected_state_hash / command_schema_version arguments;
the server constructs a versioned MutationEnvelope from the supported fields.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Bind candidate writes to the current project hash

When generation or repair targets an existing project's shot, this recipe explicitly forbids expected_state_hash, while queue_generation and run_shot_repair_loop construct envelopes without one and may persist a candidate. A concurrent re-ingest can therefore change the contract after before is read; the final assertion detects the change only after generation and persistence have occurred. Accept or internally construct and validate the freshly read project state_hash before performing either write.

AGENTS.md reference: AGENTS.md:L64-L72

Useful? React with 👍 / 👎.

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Addressed in 3771e2c8a060fb7331f0d2419b19d4f01b6bbb98.

Candidate generation and repair now accept/bind expected_state_hash, validate before provider execution, and retain one process-local store lock through persistence, including a re-entrant state recheck. This is not a distributed-lock guarantee. Race/repair regressions passed.

Independent scoped review passed; parent full M0 gate passed with declared CI dependencies (269 tests passed, 2 skipped). Current hosted M0, Postgres/MinIO, and wheel/sdist checks are successful. No merge performed.

Comment on lines +327 to +329
for path, value in changes.items():
with tempfile.NamedTemporaryFile(dir=path.parent, delete=False) as stream:
staged[path] = Path(stream.name)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Preserve file modes during atomic evolution updates

On Unix, NamedTemporaryFile creates these staged files with mode 0600, and os.replace transfers that mode to every evolved sidecar and index. Applying evolution to a group-readable or service-owned corpus therefore makes the files inaccessible to other readers; the rollback path creates the same mode change while claiming to restore prior state. Copy each original file's mode onto its staged and rollback replacement before installing it.

Useful? React with 👍 / 👎.

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Addressed in 3771e2c8a060fb7331f0d2419b19d4f01b6bbb98.

Both evolution engines now preserve original POSIX permission bits on staged and rollback replacements. Regressions inspect replacement sources and final modes, including failure after both corpus files are replaced.

Independent scoped review passed; parent full M0 gate passed with declared CI dependencies (269 tests passed, 2 skipped). Current hosted M0, Postgres/MinIO, and wheel/sdist checks are successful. No merge performed.

@scrimshawlife-ctrl
scrimshawlife-ctrl merged commit 49bc811 into main Sep 15, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant