Skip to content

fix(release): preserve marketplace assessment identities - #529

Merged
devantler merged 2 commits into
mainfrom
codex/marketplace-observation-525
Oct 5, 2026
Merged

devantler merged 2 commits into
mainfrom
codex/marketplace-observation-525

Conversation

@devantler

@devantler devantler commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

🤖 Generated by the Agentic Engineer

Why

Valid marketplace releases could be refused after a queued dispatch or in unusual checkout paths, and verification could execute a local observation hook.

What

Release assessment now follows the checkout it actually examines, accepts matching native CI identities, and preserves safe offline inspection across supported checkout paths.

This also implements the related requirements in #526, #527 and #528.

Fixes #525

@devantler

Copy link
Copy Markdown
Contributor Author

🤖 Generated by the Agentic Engineer

Validation at fa8e469 covers #525, #526, #527 and #528.

The four reproduced root causes now have shipped regressions: repository-configured filesystem hooks stay inert; native CI workflow paths qualified with the main ref are accepted while other workflows/refs refuse; publication assessment binds to the checkout selected by the workflow; and historical inspection preserves exact checkout names ending in newlines without sharing a line-based object-alternates path.

The verifier passes 44 cases, release proposals 98, historical inspection 46, and the new actual workflow checkout-identity test four. Existing publication/proposal workflow guards, complete script lint, manifest/provenance checks, changed-workflow lint and diff checks pass. Independent whole-diff review exercised real Git checkouts, configured benign hooks and additional newline/linked-worktree controls; selected observations retained index/configuration/refs and object inventories, and no hook executed.

These are exercised command and workflow assessment paths, not a production marketplace publication. Automatic publication remains disabled. CI is pending at this head, so promotion is not yet claimed. #526–#528 will be closed only after this PR merges and its shipped bytes are verified.

@devantler

Copy link
Copy Markdown
Contributor Author

🤖 Generated by the Agentic Engineer

Validation at 18600ab supersedes the earlier validation comment and covers #525, #526, #527 and #528.

Native CI at the previous head reproduced an observation-completeness regression: the existing fault injector did not recognize the new explicit inert Git configuration. The test still requires the same truncated observation to be refused for the same reason; recognizing that exact command prefix restores the intended injection. All 15 observation-completeness controls now pass. The production changes remain identical to the independently reviewed earlier head.

The verifier passes 44 cases, historical inspection 46, release proposal 98, workflow checkout identity four, release preparation 62, version gates 36, remote assessment 62, publication 73 and merged-release preparation 52. Existing publication/proposal workflow guards, full script lint, changed-workflow lint and diff checks pass. Independent whole-diff review of all eleven changed files at this exact head is clean, including the repaired negative control.

Repository-configured filesystem hooks stay inert; native main-qualified CI workflow paths retain exact-head/event/workflow binding; assessment uses the actual selected checkout; and historical inspection preserves exact physical checkout names, including terminal newlines. Actual Git controls verified index, configuration, refs and object inventories, with no hook execution.

Automatic publication remains disabled. These tests exercise release commands and workflow assessment, without claiming a production marketplace publication. Current-head CI is still pending. Companion issues #526–#528 will close only after merge and shipped-byte readback.

@devantler

Copy link
Copy Markdown
Contributor Author

🤖 Generated by the Agentic Engineer

@coderabbitai full review

@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
✅ Action performed

Full review finished.

@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 5d5b7df0-c84c-41c4-afb2-d0b571f243e6
📥 Commits

Reviewing files that changed from the base of the PR and between 796afb2 and 18600ab.

📒 Files selected for processing (11)
  • .github/workflows/ci.yaml
  • .github/workflows/publish-marketplace-release.yaml
  • docs/marketplace-releases.md
  • scripts/inspect-marketplace-release.sh
  • scripts/inspect-marketplace-release.test.sh
  • scripts/marketplace-observation-completeness.test.sh
  • scripts/marketplace-publication-identity.test.sh
  • scripts/propose-marketplace-release.sh
  • scripts/propose-marketplace-release.test.sh
  • scripts/verify-marketplace-release.sh
  • scripts/verify-marketplace-release.test.sh

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.

📜 Recent review details
🧰 Additional context used
📓 Path-based instructions (2)
Source excerpt: Preparation is opt-in and offline.

📄 CodeRabbit inference engine (docs/marketplace-releases.md)

Files:

  • docs/marketplace-releases.md
Source excerpt: **Least-privilege permissions.**

📄 CodeRabbit inference engine (AGENTS.md)

Files:

  • .github/workflows/ci.yaml
  • .github/workflows/publish-marketplace-release.yaml
🪛 LanguageTool
docs/marketplace-releases.md

[uncategorized] ~309-~309: The official name of this software platform is spelled with a capital “H”.
Context: ... path or the exact main-qualified forms .github/workflows/ci.yaml@main and `.github/wo...

(GITHUB)


[uncategorized] ~310-~310: The official name of this software platform is spelled with a capital “H”.
Context: ...ms .github/workflows/ci.yaml@main and .github/workflows/ci.yaml@refs/heads/main. Two...

(GITHUB)

🔇 Additional comments (5)
scripts/propose-marketplace-release.sh (1)

79-79: LGTM!

scripts/propose-marketplace-release.test.sh (1)

80-91: LGTM!

Also applies to: 289-292

.github/workflows/publish-marketplace-release.yaml (1)

58-58: LGTM!

scripts/marketplace-publication-identity.test.sh (1)

7-74: LGTM!

.github/workflows/ci.yaml (1)

141-142: LGTM!


📝 Walkthrough

Walkthrough

The publication assessment now resolves the release commit from checked-out HEAD. Inspection preserves trailing newlines in repository paths and creates clones without hardlinks. Verification disables the configured filesystem-monitor hook for its diff-tree call. The proposal validator accepts the bare CI workflow path and its exact @main and @refs/heads/main forms. Tests and documentation cover these changes.

Priority: ➖ Normal

Severity of issue fixed: Medium

Merge Risk: ⚪ Minimal · up to 18600

The release assessment, inspection, and CI identity changes appear ready to merge after normal checks. No specific unresolved failure was identified.

Security Architecture Review

Security architecture risk: ⚪ Minimal · up to 18600

The changes align release checks with the checkout actually examined and prevent a configured observation hook from running during verification. Repository, commit, successful-CI, and explicit publication controls remain intact. No material security risk was found to be introduced or worsened.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • observed — The privileged workflow targets github.repository and grants contents-write only to the explicitly armed publish job. Local verification operates under the caller's process authority, making checkout-configured hook execution a separate local boundary. The PR does not change workflow token permissions or add a cross-repository publication target.

Trust Boundaries and Controls

  • observed — Caller-selected CI IDs and candidate content do not independently authorize writes. Native API responses must match the selected repository, main commit, workflow identity, and successful push result. Proposal writes additionally retain native Actions bot and writer-capability checks, expected-parent commit creation, fixed manifest paths, and independent draft readback.
  • observed — Inspection neutralizes inherited Git layout and command-scoped configuration overrides, disables lazy fetching and replacement objects, checks complete local history, and removes a candidate tag only inside its disposable repository. Its captured verification verdict is converted into a historical inspection result rather than exposed as publication clearance.

Resilience and Maintainability Implications

  • inferred — The newly accepted CI path forms do not bypass existing proposal transition guards. Repeated snapshots bind repository state and owned branch commits; uncertain writes stop with manual-recovery guidance. Publication likewise stops before a subsequent write when identity readback fails. These preserve failure containment but do not provide distributed reservation or automatic recovery after partial success.

Important

Pre-merge checks failed

Please resolve all errors before merging. Addressing warnings is optional.

❌ Failed checks (1 error)

Check name Status Explanation Resolution
Out of Scope Changes check ❌ Error The changes to publish-marketplace-release.yaml and propose-marketplace-release.sh change checkout-commit selection and accepted CI workflow identities. The changes to `inspect-marketplace-release… Remove these unrelated workflow-identity and historical-path changes from this PR, or move them to changes tied to their respective active issue requirements.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed #525 requires inert Git observation hooks during valid verification, continued refusal of negative controls, and unchanged caller state. The verifier disables core.fsmonitor for diff-tree. The add…
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 3 functions across 8 files. (3 skipped: 3 …
Title check ✅ Passed The title clearly summarizes the main change: preserving marketplace release assessment identities.
Description check ✅ Passed The description explains the release assessment, CI identity, and offline inspection changes addressed by the pull request.
Full details: Out of Scope Changes check

Explanation

The changes to publish-marketplace-release.yaml and propose-marketplace-release.sh change checkout-commit selection and accepted CI workflow identities. The changes to inspect-marketplace-release.sh add historical-inspection path handling. These address release identity and checkout-path behavior, not #525’s observation-hook defect or its related hook-input variants.

  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@devantler

Copy link
Copy Markdown
Contributor Author

🤖 Generated by the Agentic Engineer

The selected review's scope finding is resolved at unchanged head 18600ab. The description now explicitly links all active companion requirements: #525 covers inert repository observation; #526 covers the supported successful-check identities; #527 covers the actual checkout selected for publication assessment; and #528 covers exact historical checkout paths. These issues were filed before implementation and their shipped regressions and actual command evaluations are recorded in the validation comment above.

The primary closing reference remains #525 under the repository's single-closing-issue body convention. #526–#528 will be closed after actual merge and immutable shipped-byte readback. All four requirements concern the integrity of marketplace release assessment and inspection; the body change introduces no additional code or release authority. Automatic publication remains disabled.

This resolution restarts review at the same commit without an empty commit. No code findings, review threads or maintainer requirements were discarded.

@devantler devantler left a comment •

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Generated by the Agentic Engineer

Self-review (fallback — CodeRabbit, Codex and Cursor Bugbot unavailable)

Reviewed commit: 18600ab

  • CodeRabbit: the authenticated current-PR summary updated at 2026-10-05T16:33:34Z reports that the completed review consumed the included allowance, with zero remaining under the one-review-per-hour plan. Freshly read after the scope resolution; applicable to this PR's restarted round. Recovery is renewed included allowance; paid recovery is not authorized. Source: #529 (comment).
  • Codex: the authenticated account usage-limit response remains unchanged at 2026-10-05T04:07:07Z on a fresh read. It identifies this account's exhausted code-review allowance and requires account credits/settings recovery; no paid recovery is authorized. Source: devantler-tech/agent-skills#246 (comment).
  • Cursor Bugbot: the authenticated user/team usage-or-spend-limit response remains unchanged at 2026-10-05T04:08:02Z on a fresh read. Recovery requires a user/team administrator to change the limit; no paid recovery is authorized. Source: devantler-tech/agent-skills#246 (comment).

I reviewed the complete eleven-file diff against 796afb2 for correctness, security, complete observations, retained caller state, and the repository's review guidelines. The command-local filesystem-monitor override covers the tree diff that can consult the index; its native marker control detects execution and verifies unchanged caller index/configuration. Historical inspection preserves complete logical and physical checkout paths and copies immutable objects into its disposable repository without line-based alternates. Supported CI identities remain narrowly bound to repository, main branch, full commit, push event and completed success. Publication assessment resolves the actual selected checkout before invoking assessment, and a failed native identity read stops the step. Publication remains explicitly opt-in.

The selected review's scope finding was resolved before this round by linking the already active #526, #527 and #528 requirements alongside primary #525. These four requirements and their acceptance controls are covered by this diff; no extra code was added during resolution. LanguageTool's case suggestions concern literal, case-sensitive repository paths, which correctly retain their actual lowercase directory names. There are no unresolved code, scope, inline or non-thread findings and no maintainer requirements being overridden.

The verifier's 44, historical inspector's 46, proposal's 98 and actual workflow identity's four controls pass, with fifteen observation-completeness controls retaining the same negative producer fault and refusal reason. Independent whole-diff review is clean. All 46 native current-head CI checks are settled green, including CI - Required Checks. Actual native Git checkouts, unusual physical paths and the workflow's real assessment shell were exercised; production marketplace publication is not claimed.

Verdict: no P0/P1 findings

@devantler

Copy link
Copy Markdown
Contributor Author

🤖 Generated by the Agentic Engineer

Ready at 18600ab: all 46 native CI checks are settled green, including CI - Required Checks; the base and owned worktree are freshly rebound; there are zero unresolved threads or remaining review/maintainer requirements. The current-head CodeRabbit code review is clean. Its scope finding has been resolved against the four active issue requirements, and the prescribed subsequent local review is posted and programmatically GREEN at this exact head.

Native release commands and the workflow's actual assessment shell were exercised with normal, queued, malformed and unusual-path controls. Caller state remains unchanged and callbacks stay inert. Publication remains explicitly opt-in; no production marketplace publication is claimed. #526–#528 will close only after merge and immutable shipped-byte readback.

@devantler
devantler marked this pull request as ready for review October 5, 2026 16:57
@devantler
devantler merged commit 52e20bf into main Oct 5, 2026
47 checks passed
@devantler
devantler deleted the codex/marketplace-observation-525 branch October 5, 2026 16:57
@devantler

Copy link
Copy Markdown
Contributor Author

🤖 Generated by the Agentic Engineer

Post-merge user-path proof is complete at signed main commit 52e20bf. From that exact archived source, the native release verifier passed 44 cases, historical inspector 46, proposal command 98, actual publication assessment shell four and observation completeness fifteen: 207 controls passed. These exercised the merged command implementations, retained caller state and negative producer controls. All eleven changed blobs also match the independently reviewed implementation. Publication remains explicitly opt-in; no production marketplace publication is claimed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: ✅ Done

Development

Successfully merging this pull request may close these issues.

Keep marketplace verification Git observations inert

1 participant