Roadmap item 4: Add local Git materializer protocol - #228
Conversation
…cal-git-materializer-protocol-v1 # Conflicts: # README.md # RESTORE.md # ci/required-files.txt
…cal-git-materializer-protocol-v1
…cal-git-materializer-protocol-v1 # Conflicts: # README.md # RESTORE.md # ci/required-files.txt # scripts/test/portable-core-schema.test.sh
Deploying ystack with
|
| Latest commit: |
4b71b0b
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://c03d2692.fabrica-6yx.pages.dev |
| Branch Preview URL: | https://codex-local-git-materializer.fabrica-6yx.pages.dev |
Codex reviewer (cross-vendor, read-only)Reviewed-head: 9058c55 Posted verbatim by The protocol can project receipts and passing results from unvalidated or insufficiently bound inputs. It also fails to enforce payload identity and two explicit materialization limits, undermining the exact evidence relations it is intended to establish. Full review comments:
|
Codex reviewer (cross-vendor, read-only)Reviewed-head: 06dd4f5 Posted verbatim by The safety-focused contract tests pass for the wrong reason and therefore do not protect the contract validation logic from regression. Review comment:
|
Codex reviewer (cross-vendor, read-only)Reviewed-head: 7152a76 Posted verbatim by The result projection can create core-valid passing evidence for an arbitrary, unvalidated receipt digest, bypassing the receipt-side guards added by this patch. Review comment:
|
|
Round-cap escalation: the third independent review on exact head The branch and worktree are preserved and clean. No merge or further revision will occur without an operator ruling. Operator question: authorize one final revision strictly limited to adding a caller-verified receipt pair, binding its digest/request/attempt/outcome to |
|
Operator ruling received directly in the active construction task: authorize one final revision only. Exact scope: add a caller-verified receipt pair; bind its digest, request, attempt, and outcome before |
Codex reviewer (cross-vendor, read-only)Reviewed-head: e639cd8 Posted verbatim by The protocol can emit a passing stage result for internally inconsistent candidate Git identities. The otherwise inactive implementation remains bounded, but this evidence-validation gap should be fixed before the protocol is consumed by a runtime. Review comment:
|
|
Post-authorization final-review escalation: exact head The branch/worktree are preserved and clean; CI is green. No merge or further edit will occur without a new operator ruling. Operator question: authorize one last two-line semantic correction ( |
|
Operator explicitly authorized this exact final correction in the active construction task: on PR #228 change |
Codex reviewer (cross-vendor, read-only)Reviewed-head: 5ee7d61 Posted verbatim by The stage-result path can validate and attest a nested source tree even though receipt generation requires the repository root. This leaves inconsistent validation paths at the protocol's evidence boundary. Review comment:
|
|
Final-review fail-closed escalation: exact head The explicitly authorized OR-to-AND correction and its two tests are complete; this is a distinct omitted root-location invariant. The branch/worktree remain clean and CI is green. No merge or further edit will occur without operator disposition. Operator question: authorize one additional exact two-file revision to require |
|
Operator explicitly authorized the exact root-location correction in the active construction task. Scope is limited to requiring |
Codex reviewer (cross-vendor, read-only)Reviewed-head: 4b71b0b Posted verbatim by No actionable correctness issues were found in the diff. The protocol consistently validates its input graph, payload bindings, receipt relations, and stage-result projection, with focused negative coverage for the relevant boundaries. |
|
Operator authorized the exact downstream runtime conflict disposition in the active construction task: on |
Summary
core.forge.materialize-candidate.v2.Scope
Tracks Roadmap item 4 without closing an intake issue. This protocol is the missing dependency between the merged GitHub forge observation payload and a real inactive local candidate materializer. The runtime remains a separate unit; default-profile assembly waits for its durable merge identity.
Safety
This unit has no product executable. It cannot read or write a repository, run hooks or filters, use a credential or network, contact a provider, grant authority or qualification, activate a profile, or perform an external effect.
Targeted proof
The preserved one-concern branch was adopted by merging current main normally. It was not rebased or force-pushed.