Skip to content

fix: reject linked desired-state package documents - #537

Merged
devantler merged 2 commits into
mainfrom
codex/desired-state-boundaries-536
Oct 6, 2026
Merged

devantler merged 2 commits into
mainfrom
codex/desired-state-boundaries-536

Conversation

@devantler

Copy link
Copy Markdown
Contributor

🤖 Generated by the Agentic Engineer

Why

Package validation can skip linked onboarding documents while reporting success, allowing invalid or missing deployment guidance to reach consumers.

What

Require complete packaged onboarding documents and their directories, and refuse incomplete inventories before reporting a valid package.

Fixes #536

@devantler devantler left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Generated by the Agentic Engineer

Self-review (fallback — CodeRabbit, Codex and Cursor Bugbot unavailable)

Reviewed commit: 4ebc695
Base: e3000bc

  • CodeRabbit: the freshly read included-capacity summary, updated 2026-10-06T04:35:47Z, reports 0 included reviews remaining under the shared one-review-per-hour allowance. That review completed this hour; no paid overage is authorized. The recent successful service reported by the aggregate health classifier is separate from current included capacity. Availability must be verified again after provider recovery.
  • Codex: the freshly read account review refusal, updated 2026-10-06T00:30:33Z, reports exhausted code-review usage and requires credits/settings changes; no automatic reset is stated.
  • Cursor Bugbot: the freshly read user/team refusal, updated 2026-10-05T04:08:02Z, reports a usage/spend limit that a user/team administrator must change; no reset is stated.

Complete current-PR reviews, comments and threads were read directly and contain no provider verdict, code finding, maintainer instruction or unresolved thread. Native current-head CI diagnostics contain no Bugbot review run. The automatic-review-disabled status is not substantive review and was not used as availability evidence.

Reviewed all five changed files for complete parent/file inventories, producer status and NUL framing, refusal before linked/nonregular content reads, regular-file ancestor checks, canonical membership, optional resource compatibility, preserved fault-injection assertions and CI coverage. The independent review identified a zero-exit inventory omission of the canonical document; that defect was fixed with failing-then-passing regressions and the final independent current-head review is clean. Valid packaged documents and empty ordinary resources directories remain accepted; linked, dangling, directory and FIFO documents and linked/non-directory resources parents fail before reading their content.

The integrated current head passed the actual complete package gate, 22 complete-entrypoint boundary cases, all 433 existing manifest cases, package-boundary tests, shellcheck/actionlint and diff checks. The existing inventory-failure tests still assert failed/truncated producers; their argument matcher was adjusted to exercise the new inventory command shape. Validation completed before the host's later low-disk hold, and no new local builds or tests were started after that hold. Native CI is still settling and must pass completely before readiness.

Verdict: no P0/P1 findings
No remaining actionable findings at this head.

@devantler

Copy link
Copy Markdown
Contributor Author

🤖 Generated by the Agentic Engineer

Ready at 4ebc695 against freshly fetched main e3000bc.

Programmatic proof: production-gate regressions failed before the repair and passed afterwards, including the independently discovered zero-exit canonical inventory omission. The final integrated head passed 22 complete package boundary cases, all 433 existing manifest cases, package-boundary tests and shellcheck/actionlint/diff checks. Native current-head CI is settled: 44 successful checks, two expected automation skips, no failures or unfinished checks, complete pagination, and required CI - Required Checks succeeded in run 37416424768 (job 112118654135). The native script job log explicitly shows all 22 new cases passing; the returned broader log is truncated, so the complete 433-case local log and successful native job are retained separately.

Review proof: substantive current-head local review includes fresh individual provider unavailability facts and the independent five-file review. The canonical verdict helper returns GREEN self@4ebc69577dff0b1607f23d2c9af55940b2541ea8. Full current comments/reviews/thread reads contain zero unresolved findings or maintainer direction; pagination is complete. Native merge state is CLEAN and the source commit signature verifies.

User evaluation: I ran the actual complete package command on the integrated current marketplace and observed successful validation. Complete-command exercises verified healthy packaged onboarding documents and empty ordinary resource directories still pass, while canonical and ancillary links, dangling/nonregular files, linked/non-directory parents, failed/truncated inventories and missing canonical membership fail with a specific diagnostic before linked contents are read. The native current-head manifest job also passed on the real packaged tree. No external provider or credential is required for this offline package gate.

All three readiness conditions hold at this head. Normal promotion and head-pinned squash merge are authorized.

@devantler
devantler marked this pull request as ready for review October 6, 2026 05:13
@devantler
devantler merged commit 149b300 into main Oct 6, 2026
47 checks passed
@devantler
devantler deleted the codex/desired-state-boundaries-536 branch October 6, 2026 05:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: ✅ Done

Development

Successfully merging this pull request may close these issues.

Reject linked desired-state documents in complete package validation

1 participant