Skip to content

fix(strix): map findings in added PR-head files - #2482

Draft
seonghobae wants to merge 4 commits into
mainfrom
fix/strix-added-file-finding-map
Draft

seonghobae wants to merge 4 commits into
mainfrom
fix/strix-added-file-finding-map

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Problem

ContextualWisdomLab/contextual-orchestrator#1257 Strix job 108739269659 reported a finding in a newly added schema file, then failed closed with Unable to map Strix findings to changed files. Its artifact 10946346186 cites /workspace/strix-pr-scope.cQ5gwy/contextual_orchestrator/schemas/release_semver/v1/receipt_envelope.schema.json. The PR-head scope contains that file, but the trusted base checkout does not. The location mapper discarded it because it required the file to exist in the base checkout.

Change

For PR-head scans only, map a location found inside the bounded scan tree when the corresponding path is a regular file in the authenticated PR-head commit. Existing path containment, symlink, and head-blob checks remain. A new regression checks that a critical finding in an added file is classified as evidence_scope=pr_delta instead of block_unmapped.

This changes attribution, not the vulnerability verdict. The finding in #1257 still needs source-level adjudication.

Verification

  • bash -n scripts/ci/strix_quick_gate.sh scripts/ci/test_strix_quick_gate.sh
  • STRIX_TEST_CASE_FILTER=pull-request-target-added-file-finding-maps-to-head bash scripts/ci/test_strix_quick_gate.sh (exit 0)
  • STRIX_TEST_CASE_FILTER=pull-request-target-scanner-created-finding-stays-unmapped bash scripts/ci/test_strix_quick_gate.sh (exit 0)
  • git diff --check

The full shell gate suite was started but stopped after several minutes of unrelated scenarios; the focused new regression completed. Hosted exact-head checks and independent review remain required.

@coderabbitai

coderabbitai Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

Next included review available in 10 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: a867e80b-f4e0-4ebb-964c-f8e26cdb84fe

📥 Commits

Reviewing files that changed from the base of the PR and between 3295c25 and 03bbce2.

📒 Files selected for processing (2)
  • scripts/ci/strix_quick_gate.sh
  • scripts/ci/test_strix_quick_gate.sh

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@seonghobae
seonghobae enabled auto-merge (squash) September 28, 2026 05:49
@seonghobae

Copy link
Copy Markdown
Contributor Author

Consolidation note: older overlapping #2484 is closed in favor of this current-main branch. The decisive trust-boundary difference is the authenticated PR-HEAD regular-blob check here, plus the negative regression for scanner-created files. The #1257 finding remains subject to its own source/security review; this PR only maps its path to the PR delta. Current-head hosted checks and independent review are still required.

@opencode-agent
opencode-agent Bot disabled auto-merge September 28, 2026 08:51

Copy link
Copy Markdown
Contributor Author

Exact-head admission correction — 03bbce2b19a8f1a6f5227d548c5529128bde0307

Ready is review admission only. Fresh audit against base 3295c259bcb688673170a1902f46d1d6c775bad4 found:

  • mergeability=false on current base
  • latest terminal workflow blockers: SAST Semgrep 36384103776=failure, Python Security 36384103806=failure, Security Scan 36384103791=failure, CodeQL PR 36384103787=failure

This PR is moved to Draft/Proposed until the causal owner repair is present on a successor exact head and re-audited. Queued/pending work is neither an additional blocker nor passing evidence. No Close, force push, destructive rebase, manual rerun, synthetic status/approval, merge, auto-merge, or bypass was performed.

@seonghobae
seonghobae marked this pull request as draft September 30, 2026 05:19

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: In Progress

Development

Successfully merging this pull request may close these issues.

1 participant