research: finalize Zenodo DOI metadata for pilot v1 - #160
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (3)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe PR records the published research-v1 Zenodo archive, documents its integrity evidence and citation rules, updates README citation guidance, and adds dataset-specific ChangesResearch citation and archival records
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~10 minutes Change: Other 🚥 Pre-merge checks | ✅ 7 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (7 passed)
Full details: Security RegressionExplanation The PR weakens the frozen dataset integrity gate. The base document required a Zenodo re-download, SHA-256 recomputation, and a blocked archival gate on any mismatch. The changed document removes that requirement and accepts DOI finalization from pre-upload SHA-256 plus exact sizes and MD5 values. The repository's archive workflow and release evidence use SHA-256 and an archive lock, so the post-publication check is the remaining control that verifies the bytes served by Zenodo. If a Zenodo asset is altered, same-size and MD5 evidence does not provide the same integrity protection because MD5 collision resistance is broken. The changed documentation then directs users to treat the DOI as the exact frozen evidence. Resolution Restore the post-publication integrity gate. In a trusted environment, download every Zenodo asset, recompute SHA-256, and compare each digest and size with the canonical release values and archive lock. Do not mark the DOI record as an exact archival copy, or instruct users to rely on it for exact reproducibility, until all comparisons pass. Keep MD5 values only as supplementary evidence, not as a substitute for SHA-256. If Zenodo downloads are unavailable, leave the gate pending and record the DOI as unverified rather than finalizing it.
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Summary
Finalize repository-side DOI metadata for the published BPFCompat Research
Dataset v1 without modifying the frozen
research-v1payload.Zenodo identifiers
10.5281/zenodo.2284815510.5281/zenodo.22848154research-v1Changes
README.mdresearch-v1reproducibility;docs/research-v1/CITATION.cffpayload;
version, date, licenses, and Zenodo record URL.
docs/research-v1-zenodo.mdevidence;
research/**remainsfrozen.
The root
CITATION.cffis deliberately unchanged because it is part of thefrozen v1 archive selection and remains the BPFCompat software citation
metadata.
Integrity evidence
Before upload, all four GitHub release assets were re-hashed locally with
SHA-256 and matched the frozen values.
After publication, the Zenodo record displayed the expected exact sizes and MD5
values for all four files; those MD5 values were independently reproduced from
the canonical GitHub archival artifact.
A strict post-publication Zenodo re-download followed by SHA-256 recomputation
was not completed in the assistant environment because direct Zenodo file
downloads were unavailable there. This limitation is recorded explicitly in
the documentation rather than being hidden.
Frozen-v1 boundary
This PR does not modify:
CITATION.cffat repository rootresearch/**research-v1tagCorrections to frozen evidence require a new research version instead of
rewriting v1.
Summary by CodeRabbit