Skip to content

fix(opencode): vendor both base Cargo lock roots - #2360

Merged
seonghobae merged 6 commits into
mainfrom
fix/opencode-rust-multi-root-vendor-20260924
Sep 27, 2026
Merged

seonghobae merged 6 commits into
mainfrom
fix/opencode-rust-multi-root-vendor-20260924

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Change

Materialize the full union of validated base Cargo lock roots, including distinct repository-root and fuzz/ workspaces, into one vendor tree and generated manifest. Reject missing or changed lock inputs before publishing dependency evidence.

The exact-head repair also confines synthesized Cargo target placeholders to each manifest root. Absolute target paths and .. traversal now fail closed before any out-of-root write.

This remains the canonical owner repair for the fast-mlsirm multi-workspace coverage failure. The effective stacked delta changes only:

  • scripts/ci/materialize_base_rust_dependencies.py
  • tests/test_materialize_base_rust_dependencies.py
  • tests/test_materialize_base_rust_path_safety.py

Current authority

  • Status: Draft / Proposed / do not merge
  • Exact head: fc9c8d2c8537e9a0582299d5b26eef31d6309710
  • Exact tree: bc9e81e98770a614f7d23987436a394671f27cc6
  • Stacked base: fix/codeql-dispatch-unblock@8e1aba9ce1d52acb36f095da32511da06958733f (#2385)
  • Topology: 6 ahead / 0 behind; mergeable; 3 effective paths
  • Ordinary merge commit: 4e29c11f13c527c3d402939da46370b2b6d3115b
  • Cleanup child: 9fb90974afc4c396db9415f7313074e696b81bd9 removes one dead if False test probe.
  • Path-safety RED: 93a8e08d50bf51e8d190796357a4787e6542125d
  • Path-safety GREEN: 00b9e2530cd027b8ba9d893d727cbb1ba89b6d7a

The stack adopts #2385's AnyIO 4.14.2, exact endpoint-set CodeQL repair, GHAS credential selection, Noema dependency/coverage inputs, and coverage baseline. Those responsibilities are not duplicated in this PR.

Exact-tree verification

  • Path-safety RED: 2 failed (relative traversal and absolute target path both escaped before the guard)
  • Path-safety GREEN: 2 passed
  • New guard accept/reject branches: exercised
  • Full warnings-as-errors + branch-coverage suite: 3411 passed, 8 skipped, 40 subtests passed; 100% (14,895 statements / 6,026 branches)
  • Python compile, Ruff, and git diff --check: PASS
  • Current GitHub tree is bc9e81e98770a614f7d23987436a394671f27cc6; its only child delta from 00b9e253… is the materializer test path (+33/-12).
  • A no-Cargo runner now executes every mock/unit materializer contract and skips only the 3 real-Cargo integration cases. Focused result: 26 passed, 3 skipped; materializer 155 statements / 60 branches = 100%.
  • Unresolved review threads: 0

Fresh exact-head hosted runs are Security 36263712408, CodeQL 36263712472, and SAST 36263712518. They are queued and are not acceptance evidence. Additional lifecycle runs may still be admitted for this head.

Keep Draft until this unchanged exact head receives terminal applicable checks and qualifying independent review. No predecessor check/review transfers; no self-approval, Force Push, destructive rebase, blind rerun, synthetic status, or bypass.

Toolchain-independent coverage repair

  • RED on predecessor 00b9e253…: repository coverage failed at 99% because the file-level Cargo skip suppressed all 29 tests and left materialize_base_rust_dependencies.py at 27% on a no-Cargo runner.
  • GREEN fc9c8d2c…: only the 3 real dependency-graph integration tests require Cargo; deterministic Git/mock/error/CLI/path-safety contracts run everywhere.
  • This is test-only. Production code and the real-Cargo integration assertions are unchanged.

@coderabbitai

coderabbitai Bot commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@seonghobae
seonghobae changed the base branch from main to fix/codeql-dispatch-unblock September 26, 2026 16:52

Copy link
Copy Markdown
Contributor Author

Exact-head repair receipt for 9fb90974afc4c396db9415f7313074e696b81bd9:

  • Prior head 2e791553… was source-complete for multi-root Cargo vendoring but terminal RED for three foundation causes outside its two-path ownership: AnyIO 4.14.0 vulnerabilities, missing Noema/defusedxml quality inputs, and the exact endpoint-set CodeQL finding.
  • Ordinary two-parent 4e29c11f… stacks the PR on canonical foundation #2385 without copying those responsibilities. The PR base is now repair(foundation): unblock coverage and CodeQL control plane #2385's branch.
  • Child 9fb90974… removes an introduced dead if False/unused assignment from the Cargo test.
  • Exact remote tree 8f694bd2… equals the locally verified tree.
  • Effective diff against repair(foundation): unblock coverage and CodeQL control plane #2385 is exactly the Cargo materializer and its test: +206/-75 across 2 paths; 3 ahead/0 behind; mergeable; unresolved threads 0.
  • Exact-tree local evidence: full warnings-as-errors 3385 passed, 31 skipped, 40 subtests passed; two Cargo-independent multi-root/command contracts 2 passed; compile/Ruff/diff-check PASS.
  • Cargo is absent from this local runner, so the 26 Cargo-gated cases are explicitly not claimed on the new head. Fresh hosted Materializer Quality and five repository/security gates are queued/pending.

@coderabbitai review

Please review this exact head only. Draft/Proposed remains appropriate until current-head hosted evidence and an independent qualifying approval are terminal.

@coderabbitai

coderabbitai Bot commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor
⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Exact-head review for 00b9e2530cd027b8ba9d893d727cbb1ba89b6d7a.

Found and repaired a materialization-root escape in the touched owner: an authenticated base Cargo.toml could declare an absolute target path or .. traversal, and placeholder synthesis wrote outside its temporary manifest root.

  • RED 93a8e08d50bf51e8d190796357a4787e6542125d: 2 failed
  • GREEN 00b9e2530cd027b8ba9d893d727cbb1ba89b6d7a: relative traversal and absolute target paths fail closed before an out-of-root write
  • focused: 2 passed
  • full warnings-as-errors: 3387 passed / 31 skipped / 40 subtests
  • Ruff, compileall, and diff check: PASS
  • exact tree: a3924fd48790073045d579e18eda3259ed3e54a4, identical to the independently verified local tree
  • unresolved review threads: 0

Cargo is absent from the local runner, so the 26 Cargo-gated tests remain skipped and are not represented as current-head GREEN evidence. Fresh hosted exact-head checks are queued. This is a COMMENT review, not approval; keep Draft/Proposed until terminal applicable checks and qualifying independent approval.

Copy link
Copy Markdown
Contributor Author

Exact-head repair receipt: 00b9e2530cd027b8ba9d893d727cbb1ba89b6d7a / tree a3924fd48790073045d579e18eda3259ed3e54a4.

The path-safety regression was reproduced as 2 failures at RED 93a8e08d50bf51e8d190796357a4787e6542125d, then repaired with one fail-closed target-path guard. GREEN evidence: 2 focused passed and 3387 full passed / 31 skipped / 40 subtests, plus Ruff, compileall, and diff check PASS.

Exact-head COMMENT review: #2360 (review)

Fresh hosted runs:

These runs are queued, and qualifying independent approval is absent. Draft/Proposed remains correct; no merge, auto-merge, bypass, synthetic status, force push, destructive rebase, or PR close was used.

Copy link
Copy Markdown
Contributor Author

Exact-head RCA and repair evidence for fc9c8d2c8537e9a0582299d5b26eef31d6309710 (tree bc9e81e98770a614f7d23987436a394671f27cc6).

  • RED on predecessor 00b9e253…: full branch coverage was 99%; all 29 tests in test_materialize_base_rust_dependencies.py were skipped when Cargo was absent, leaving the production materializer at 27%. The skip boundary, not production behavior, was the cause.
  • GREEN: the file-level skip is narrowed to the 3 genuine Cargo integration cases. Mock/unit/error/CLI/Git/path-safety contracts use a committed minimal lock fixture and run without Cargo.
  • Focused no-Cargo proof: 26 passed, 3 skipped; materializer 155 statements / 60 branches = 100%.
  • Full exact-tree warnings-as-errors proof: 3,411 passed, 8 skipped, 40 subtests; aggregate 14,895 statements / 6,026 branches = 100%.
  • Compile, Ruff, and git diff --check: PASS.
  • Delta from prior head: exactly one test path, +33/-12; 1 ahead / 0 behind. Production code is unchanged.
  • Unresolved review threads: 0. Fresh Security 36263712408, CodeQL 36263712472, and SAST 36263712518 are queued; no predecessor check/review is promoted.

Draft/Proposed remains correct until terminal exact-head Checks and qualifying independent review. No Force Push, bypass, synthetic status, blind rerun, self-approval, or PR close was used.

seonghobae added a commit that referenced this pull request Sep 27, 2026
Cover DOCX/HWP/UTF-8/CLI trust boundaries through public behavior. Keep the independently owned Rust materializer gap on #2360 and the PR Draft.

Copy link
Copy Markdown
Contributor Author

Downstream integration receipt: canonical owner head fc9c8d2c8537e9a0582299d5b26eef31d6309710 is now the second parent of .github#2400@0c557f7e0ab8295ee153705c34f42e25a6be24e3.

  • Integration is an ordinary two-parent merge; owner source/tests and foundation ancestry were not copied or rewritten.
  • GitHub/local integration tree: 3ebd4ff013c8c069a67ee82ccb8702615ce35fa9.
  • Focused materializer: 26 passed / 3 real-Cargo skips; 155/155 statements and 60/60 branches.
  • Full integrated tree: 4,030 passed / 8 skipped / 40 subtests; repository coverage 100% (17,144 statements / 6,982 branches).
  • The added nested-helper docstrings and import-only Ruff normalization close exact merged-tree quality gates without changing materializer behavior.

#2360 remains Draft/Proposed and open because its valid owner delta has not yet landed on its protected-base lineage; downstream integration is not a substitute for terminal hosted Checks or independent approval.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Independent scoped review at fc9c8d2 against protected main e6334e2.

The materializer now represents root Cargo.lock and fuzz/Cargo.lock as independent committed roots and passes the additional manifest using cargo vendor --sync with --locked. It reports both locks and continues to fail closed for missing sibling manifests/locks and unsafe target paths. This matches the multi-workspace failure originally observed in fast-mlsirm #2114/#2120.

Independent detached-head verification: tests/test_materialize_base_rust_dependencies.py and tests/test_materialize_base_rust_path_safety.py: 26 passed, 3 skipped in 1.96s. Cargo discovery was intentionally disabled and a subprocess guard rejected any live cargo/rustc/maturin execution; the 3 real Cargo integration checks were not performed. Mock command construction and path-safety validation passed. Real union vendoring/build, hosted checks, and protected merge readiness are not asserted.

Base automatically changed from fix/codeql-dispatch-unblock to main September 27, 2026 10:38
@seonghobae
seonghobae merged commit cae61aa into main Sep 27, 2026
25 of 30 checks passed
@seonghobae
seonghobae deleted the fix/opencode-rust-multi-root-vendor-20260924 branch September 27, 2026 10:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant