Skip to content

test(public-safety): distinguish file URL rejection messages - #5930

Open
mikamikasuki wants to merge 2 commits into
loopx-project:mainfrom
mikamikasuki:codex/loopx-material-file-url-test-message
Open

mikamikasuki wants to merge 2 commits into
loopx-project:mainfrom
mikamikasuki:codex/loopx-material-file-url-test-message

Conversation

@mikamikasuki

@mikamikasuki mikamikasuki commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Goal And Delivered Outcome

  • Outcome basis / optional anchor: Related to [Architecture]: two modules both claim to own "private-looking text" #5136, which documents the public-safe location contract.
  • Goal/source and gap: Keep the location-shape regression test aligned with each entry point's established rejection behavior. On current main, file:// URLs are rejected as local paths by the material lifecycle validator, while remote object URLs such as s3:// exercise the remote-location URL check. The test previously expected the remote-URL message for both inputs.
  • Observable before → after, with the validation row that proves it: the material-lifecycle case failed on main for its file URL expectation; it now asserts the existing local-path rejection message for file:// and retains the remote-URL assertion for s3://. Runtime behavior is unchanged.
  • Issue/task and intended base: Related to [Architecture]: two modules both claim to own "private-looking text" #5136; base main at 44931b6. This PR does not close the broader issue.

Author Declaration

  • Written by: model_agent — OpenAI GPT-6 Luna

Implemented against

Criterion Disposition Symbol / path Test or command
Reject local filesystem locations through each supported entry point using that entry point's established validation implemented tests/control_plane/test_remote_location_shape_owner.py python -m pytest -q tests/control_plane/test_remote_location_shape_owner.py
Preserve remote object URL coverage independently from local file URL coverage implemented same test module focused regression suite; exact-base reproduction
  • Self-check before submission: Reproduced the material-lifecycle expectation failure three times on a clean checkout of the exact main SHA; inspected the validator and issue contract; searched for duplicate open PRs and found none; reviewed the two-test-file diff and confirmed both changes only align test expectations with established validation behavior.

Scope And Continuation

  • Completed scope and remaining work: Align the affected test expectations with each entry point's established local-path or remote-URL rejection message; no production behavior changes.
  • Slice boundary / successor: Complete within this scope.

Validation

  • Tested revision: b4812b0 (base 44931b6)
  • Run state: finished
  • Input classes: synthetic
Check kind Result Public-safe evidence / limitation
regression_parity passed The affected material-lifecycle case failed on exact-base main in 3/3 runs because it expected the remote-URL message for a local file URL; it passes with the corrected per-entry-point expectation.
unit passed tests/control_plane/test_remote_location_shape_owner.py: 17 passed.
static passed Ruff, Python compile, and git diff --check passed.
integration passed loopx canary premerge --from-git-diff completed: 1 changed Python test file, 0 selected catalog checks, 0 failures or manual holds.
  • Coverage and gaps: The focused suites cover entry-point location rejection messages and child-receipt local-path rejection. Runtime behavior is unchanged.

Follow-up on the same public-safety contract

  • Exact-main reproduction: On 44931b6d22a50b949d43354e6ea498fb6b68d231, the test_enabled_host_result_rejects_path_shaped_opaque_refs case for a file-prefixed local reference failed because the test expected the opaque-shape diagnostic while the validator correctly reported its local-path rejection. The drive-qualified path parameter passed. The [Architecture]: two modules both claim to own "private-looking text" #5136 direction 3 contract and docs/public-private-boundary.md classify colon-prefixed local references as local paths.
  • Change: Align tests/test_loopx_turn_executor.py with that established diagnostic. The test still verifies rejection, receipt exclusion from the returned result, and that the rejected value is not exposed.
  • Tested revision: 1951c441d3cbe5356a539c55a7887f77013a1caf (base 44931b6d22a50b949d43354e6ea498fb6b68d231).
  • Validation: the focused public-safety and turn-executor modules passed (100 tests); Ruff, Python compilation, diff checks, and the pre-merge canary passed. The exact-main parameterized test reproduced one failure and one pass before the expectation update.

Frontend / Visual Evidence

  • UI impact: none
  • Before: N/A
  • After: N/A
  • States and viewports shown: N/A
  • Source data: none
  • Attention review: N/A

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Refactoring (no functional changes)
  • Documentation update
  • Test update

LoopX Area

  • Control plane (goals, todos, quota, scheduler, registry, runtime)
  • Benchmark boundary (adapters, runners, verifiers, scoring, evidence)
  • Capability or extension (providers, adapters, skills)
  • Public docs or presentation surface (README, protocols, dashboard)
  • Build, packaging, installer, or CI
  • Host or runtime integration

Technical Direction

  • Direction / acceptance reference, when applicable: N/A

Shared-authority RFC fixture impact

  • Production-scale fixture schema: N/A
  • Semantic dimensions changed, or reviewed no-impact rationale: N/A; no authority schema or production behavior changes.
  • Provider conformance arms run: N/A
  • Read-only legacy/file/PostgreSQL three-arm rehearsal: N/A

Boundary Checklist

  • Neither the diff nor this PR body/comments/attachments disclose private state, credentials, raw traces or verifier output, internal links, or local machine paths.
  • I did not duplicate maintainer-owned benchmark work.
  • I kept the change scoped to the related public-safe location contract.
  • I completed the visual evidence section for UI changes, or marked UI impact none.
  • Every commit includes a DCO Signed-off-by trailer.

Signed-off-by: mika <211269698+mikamikasuki@users.noreply.github.com>
Signed-off-by: mika <211269698+mikamikasuki@users.noreply.github.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant