Skip to content

fix(review): preserve discovered input modalities in gateway catalogs - #2538

Draft
seonghobae wants to merge 8 commits into
fix/full-suite-parser-locks-20260930from
fix/review-catalog-input-modalities-20260930
Draft

seonghobae wants to merge 8 commits into
fix/full-suite-parser-locks-20260930from
fix/review-catalog-input-modalities-20260930

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Problem and boundary

The central review sidecar dropped discovered input_modalities at both report and policy conversion boundaries. Persisted agents therefore lacked the gateway input tags needed to distinguish blind text from figure-bearing review requests.

This independently reproduced metadata defect is related to #1529, but its blanket text-only discovery filter is not copied. Existing image routes remain in the catalog. The unrelated #1529 deltas are not claimed superseded.

Minimal repair

  • Forward input evidence through the existing report.
  • Validate scalar string/list/tuple shape.
  • Normalize nonempty values and duplicates.
  • Persist input:<modality> tags through the released gateway contract.
  • Preserve legacy behavior for missing evidence and fail closed on malformed evidence.

Price, ZDR, credential source, priority, model identity, provider fallback, and timeout policy remain unchanged.

Canonical stack and exact identity

#2530 is the canonical tree authority for shared PyO3, PyJWT, urllib3, parser, HTTPError-lifecycle, runtime, coverage, and source-integrity repairs. No security lock is copied into this leaf.

Verification

  • RED/GREEN history: 11 failures before the modality repair; 211 related tests after repair.
  • Exact merged-tree focused runtime/policy/launcher/live-discovery verification: 316 passed with warnings fatal.
  • GitHub Actions-environment runtime preflight verification: 148 passed with warnings fatal.
  • Complete exact merged-tree warning-fatal verification: 5,323 passed, 7 skipped, 40 subtests passed.
  • Gap-baseline contract verification after the documentation child: 7 passed, 4 subtests passed.
  • Policy coverage on the original repair: 198 statements and 74 branches at 100%.
  • Local and GitHub-created tree SHAs independently matched for both published commits.
  • git diff --check against current fix(ci): integrate parser, security, response, and coverage gates #2530: PASS.
  • The fast-mlsirm#2052 HTTP 400 cause is not claimed resolved without same-target exact-head execution.

Merge gates

This PR remains Draft / Proposed. Fresh exact-head SAST 36805570134 and Security 36805570184 are terminal GREEN. CodeQL 36805570113 is skipped because the PR is Draft; skipped is not acceptance evidence. There are zero review threads, one predecessor-head COMMENTED review, and no qualifying APPROVED review. Ordinary merge remains HOLD until #2530 integrates through protected flow, this base is reconciled to protected main, fresh exact-head terminal checks and authenticated verdict evidence exist, and independent approval exists. No bypass, Force Push, destructive rebase, auto-merge, manual unchanged rerun, or predecessor closure.

2026-10-01 current Maturin-owner restack

  • Exact head: 5ebcb06a6b8b97773a4b8317669da9a7232dfced; exact tree: 873aa5b4c7ab467f38d92b13f9dd06b0e91eed2f.
  • Ordinary two-parent merge preserves prior leaf 6714c9a95722a13d04e114e3a7d14879e52f851f and canonical owner fix(ci): integrate parser, security, response, and coverage gates #2530 dc54310c8c5ee6637274e7e82f5ea53d64ad91e6; the branch ref advanced with force=false.
  • The overlapping complete Gap baseline preserves both input-modality evidence and Maturin response-lifecycle evidence. Fresh merged-tree verification passed git diff --check, conflict-marker scan, Python compilation, and 173 focused input-modality/Maturin contracts.
  • Exact-head Security Scan 36815062707 and SAST Semgrep 36815062796 are terminal success. CodeQL 36815062786 is skipped because the PR remains Draft, and no qualifying independent APPROVED review exists. No bypass, auto-merge, closure, or release is authorized.

seonghobae and others added 2 commits September 30, 2026 13:43
Keep existing price, credential and ZDR decisions intact while forwarding validated input evidence through the report boundary to input tags. Image-aware gateway admission remains request-shaped; malformed metadata fails closed. Related tests: 211 passed; policy branch coverage and both production docstrings: 100%.

Co-Authored-By: Claude Code <noreply@anthropic.com>
Co-Authored-By: Claude Code <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Exact-head COMMENT review for 3b928e9dacf07521be720863d291f76a5f86fc4b against main@37b10243cec3d160ecc9c1be75c71428b160a703. I traced the full source→report→policy→catalog path and cross-checked the pinned contextual-orchestrator contract: DiscoveredModel.input_modalities is a tuple of strings and the released gateway consumes normalized input:<value> tags. This diff preserves missing evidence as legacy unknown, rejects malformed scalar/container members, casefolds/deduplicates values, and does not remove image-capable candidates or change provider/model/cost/ZDR identity. I found no source-backed blocker in this exact diff. Remaining limits are correctly explicit: the inherited full-suite run was not GREEN and no provider-HTTP-400 recovery is proven. Five hosted workflows are queued and no qualifying independent approval exists, so this is COMMENT only.

@seonghobae seonghobae added area: ci-cd CI, GitHub Actions, checks, release, or supply chain bug Something isn't working priority: high High-priority or P1 work status: needs-review Open pull request requiring current-head review or checks labels Sep 30, 2026 — with ChatGPT Codex Connector
@seonghobae
seonghobae marked this pull request as draft September 30, 2026 11:19

Copy link
Copy Markdown
Contributor Author

Exact-head security RCA for 3b928e9dacf07521be720863d291f76a5f86fc4b:

  • Security Scan run 36678676768, job 109816145428, fails on the shared test fixture tests/fixtures/coverage-cargo/Cargo.lock: PyO3 advisories GHSA-36hh-v3qg-5jq4 and GHSA-chgr-c6px-7xpp.
  • Python Security run 36678676958, job 109816239450, fails because requirements-strix-ci-hashes.txt contains PyJWT 2.13.0 with 10 known vulnerabilities; the reported fixed release is 2.14.0.
  • Both vulnerable inputs are shared-owner artifacts. Canonical owner PR fix(security): refresh shared PyJWT and PyO3 locks #2531 at d1aa3659fca527a6c7330151f3ab4df3d7578391 upgrades PyO3 to 0.29.2 and PyJWT to 2.14.0; its exact-head Security Scan and Python Security checks are successful.

This PR is returned to Draft / Proposed. Preserve its valid gateway-catalog delta, but do not duplicate the security-lock repair here. After #2531 has qualifying approval, terminal required Checks, and an ordinary protected merge, integrate the immutable owner delta normally and reacquire exact-head Checks/review. No merge, auto-merge, close, bypass, force push, destructive rebase, source-neutral wake commit, or predecessor evidence transfer is authorized.

@seonghobae
seonghobae changed the base branch from main to codex/security-baseline-final-20260930 September 30, 2026 11:36

Copy link
Copy Markdown
Contributor Author

Canonical successor integration rationale

Current leaf head f9ae0aea3e7ca6f3e07e0692f71a096f2a228a93 is mergeable and preserves the reviewed input-modality delta, but its tree still lacks the canonical security/quality successor. Exact Security run 36710175449 fails in shared PyO3 fixture evidence; the earlier empty stack-refresh commit did not copy prerequisite bytes.

I will preserve the leaf lineage and integrate current #2530 head 5b3a76ea71d7ae2fa9b1719f4f82df8d52e98082 through an ordinary two-parent commit. #2530 already carries #2531's PyO3/PyJWT/urllib3 owner repairs, #2539's CLI route reliability prerequisite, and the complete coverage/runtime successor. The resolution will take #2530 as the tree authority and overlay only #2538's reviewed semantic leaf files; it will not copy security locks into the leaf.

Publication is conditional on live heads remaining exact and uses force=false. The PR remains Draft / Proposed pending exact-tree verification, fresh hosted Checks, prerequisite protected integration, and a qualifying independent approval. No bypass, Force Push, rebase, empty wake commit, merge authorization, or predecessor closure is implied.

Preserve the reviewed #2538 input-modality delta while integrating #2530's current security, parser, runtime, and coverage tree. No leaf-owned security lock copy.
@seonghobae
seonghobae changed the base branch from codex/security-baseline-final-20260930 to fix/full-suite-parser-locks-20260930 September 30, 2026 18:59

Copy link
Copy Markdown
Contributor Author

Exact-head canonical-successor integration receipt

  • head: 9b90cdc0b47548ecfa0467b27990694e2fcc1651
  • tree: d17f2b4802b65d6394bf65479f8ded6002bde15d
  • ordinary parents: prior leaf f9ae0aea3e7ca6f3e07e0692f71a096f2a228a93 + current fix(ci): integrate parser, security, response, and coverage gates #2530 5b3a76ea71d7ae2fa9b1719f4f82df8d52e98082
  • effective diff against fix(ci): integrate parser, security, response, and coverage gates #2530: exactly the existing four modality source/test/doctoring files
  • branch publication: fast-forward with force=false
  • base: retargeted to fix/full-suite-parser-locks-20260930
  • exact merged-tree focused verification: 226 passed with warnings fatal
  • local merge-tree SHA and GitHub tree SHA: identical
  • live result after retarget recalculation: mergeable

Fresh exact-head Security 36762485288, metadata 36762485255, and SAST 36762485214 are running; CodeQL 36762485165 is Draft-skipped and is not passing evidence. Draft / Proposed and merge HOLD remain correct until #2530 protected integration, fresh terminal checks, base reconciliation, and qualifying independent approval. No bypass, Force Push, rebase, empty wake commit, auto-merge, or predecessor retirement was used.

Copy link
Copy Markdown
Contributor Author

Exact-head review admission

Current head 9b90cdc0b47548ecfa0467b27990694e2fcc1651 is mergeable, preserves #2530 through ordinary two-parent ancestry, has exact-head Security 36762485288 and SAST 36762485214 SUCCESS, passes 226 focused warnings-fatal tests, and has zero unresolved review threads. No remaining source finding justifies Draft.

Ready is restored solely to admit CodeQL and independent review. CodeQL 36762485165 was Draft-skipped and is not passing evidence; metadata 36762485255 is still running. Ordinary merge remains HOLD for terminal exact-head checks, qualifying APPROVED review, stable live head/base, #2530 protected integration, and base reconciliation to protected main. No unchanged-head rerun, empty commit, bypass, Force Push, rebase, auto-merge, or predecessor closure.

@seonghobae
seonghobae marked this pull request as ready for review September 30, 2026 19:01

Copy link
Copy Markdown
Contributor Author

Ready-trigger CodeQL handoff RCA

Current head 9b90cdc0b47548ecfa0467b27990694e2fcc1651 is unchanged. CodeQL run 36762732734 completed detection and dispatch coordination successfully; python job 110049214548 and actions job 110049214598 failed closed only at VERDICT_STATE=pending.

The bound CodeQL Scan Dispatch run 36762803297 is queued for base 5b3a76ea71d7ae2fa9b1719f4f82df8d52e98082, required run 36762732734, and merge ref db25a857d7369906915ead4969e6dc59c45cc27b. Exact-head Security is SUCCESS; SAST and repository metadata remain in progress; unresolved threads are zero and there is no qualifying APPROVED review.

This is asynchronous evidence admission, not a source finding. Merge remains HOLD. No manual rerun, empty commit, Draft toggle, bypass, Force Push, rebase, auto-merge, or synthetic status was used.

Preserve the reviewed input-modality delta while integrating .github#2530 at 5a91ce9. The resulting tree keeps exactly the four leaf-owned files relative to the owner and restores the complete product gap baseline. Verified with 5,313 warning-fatal tests, 7 skips, and 40 passing subtests.

Copy link
Copy Markdown
Contributor Author

Exact-head readiness correction for e06e5138f31bb301226b0ac70c80494231a4d799: CodeQL PR run 36784686486 is terminal failure, there is no qualifying APPROVED review, and skipped/pending/predecessor evidence is not acceptance. Its stacked base is also not protected-main evidence.

Moving this PR to Draft / Proposed preserves every commit and valid delta while the central review/queue prerequisite is repaired. No close, force update, bypass, merge, or stale approval is performed.

@seonghobae
seonghobae marked this pull request as draft September 30, 2026 22:33
Preserve the reviewed four-file input-modality delta while carrying the current #2530 security, source-integrity, and product-gap baseline through an ordinary two-parent merge. Exact merged tree verified locally with focused and complete warning-fatal tests.
Bind the verified metadata-loss defect, exact restack evidence, bounded action, and remaining acceptance gates into the product/technical Gap baseline.
Ordinary two-parent reconciliation of #2538 with current #2530. Preserve the input-modality catalog delta and integrate the exact Maturin response-lifecycle, coverage-trigger, and stacked-PR quality-gate repairs. The Gap baseline conflict retains both independently owned sections.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: ci-cd CI, GitHub Actions, checks, release, or supply chain bug Something isn't working priority: high High-priority or P1 work status: needs-review Open pull request requiring current-head review or checks

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant