Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
55 commits
Select commit Hold shift + click to select a range
4f76db7
Refactor `label_section` to use `str.rfind()` for backwards scanning
seonghobae Sep 30, 2026
5d0cdf2
⚡ Bolt: Replace `str.find()` with `str.rfind()` for last occurrence s…
seonghobae Sep 30, 2026
e715602
⚡ Bolt: Replace `str.find()` with `str.rfind()` for last occurrence s…
seonghobae Sep 30, 2026
165e7f8
⚡ Bolt: Replace `str.find()` with `str.rfind()` for last occurrence s…
seonghobae Sep 30, 2026
f5b372c
chore: restore .jules/bolt.md to base scope
seonghobae Sep 30, 2026
a70b4b2
chore: remove unrelated requirements-pip-audit-ci-hashes.txt drift
seonghobae Sep 30, 2026
d201c67
chore: remove unrelated requirements-strix-ci-hashes.txt drift
seonghobae Sep 30, 2026
cafebb1
chore: remove unrelated tests/fixtures/coverage-cargo/Cargo.lock drift
seonghobae Sep 30, 2026
0816285
chore: remove unrelated tests/fixtures/coverage-cargo/Cargo.toml drift
seonghobae Sep 30, 2026
d094b15
test: preserve last-label parser behavior
seonghobae Sep 30, 2026
56ebd86
merge: stack #2543 on canonical security owner #2531
seonghobae Sep 30, 2026
df2d184
⚡ Bolt: Replace `str.find()` with `str.rfind()` for last occurrence s…
seonghobae Sep 30, 2026
102021c
chore: restore generated bolt notes after overlap
seonghobae Sep 30, 2026
7068746
test: restore last-label regression coverage
seonghobae Sep 30, 2026
2b2ef62
merge: stack rfind parser repair on #2530
seonghobae Sep 30, 2026
ed19d91
merge: preserve live #2543 writer and canonical stack
seonghobae Sep 30, 2026
2a76a11
docs(normalizer): state last-label behavior precisely
seonghobae Sep 30, 2026
f79a617
⚡ Bolt: Replace `str.find()` with `str.rfind()` for last occurrence s…
seonghobae Sep 30, 2026
acd0fbb
fix(security): refresh Noema reader npm locks
seonghobae Sep 30, 2026
fe5f581
docs(review): bind Noema repair evidence to live lineage
seonghobae Sep 30, 2026
e67418e
merge(review): restack normalizer on canonical security owners
seonghobae Sep 30, 2026
81de2b0
merge(review): refresh normalizer on formatting-clean owner
seonghobae Sep 30, 2026
5df9bbe
merge(review): carry source-integrity repair into normalizer leaf
seonghobae Sep 30, 2026
af06cf9
test(review): reproduce suffix-label evidence override
seonghobae Oct 1, 2026
4d49b83
fix(review): require standalone evidence labels
seonghobae Oct 1, 2026
e3bbc31
docs(review): record evidence-label boundary repair
seonghobae Oct 1, 2026
6efac0f
docs(review): bind Gap to executable label evidence
seonghobae Oct 1, 2026
d05f67f
test(review): reject nested malformed control promotion
seonghobae Oct 1, 2026
86f52f3
fix(review): scan embedded JSON containers once
seonghobae Oct 1, 2026
1a00c73
test(review): cover malformed array nesting
seonghobae Oct 1, 2026
c778807
docs(review): record outermost JSON boundary
seonghobae Oct 1, 2026
2541589
docs(gap): bind outermost JSON evidence repair
seonghobae Oct 1, 2026
2ee8dda
fix(docs): restore complete gap baseline after transport truncation
seonghobae Oct 1, 2026
e3191f1
merge(ci): integrate current combined owner head
seonghobae Oct 1, 2026
42099a3
test(review): skip non-JSON prose delimiters
seonghobae Oct 1, 2026
07baba2
fix(review): skip non-JSON prose delimiters
seonghobae Oct 1, 2026
d09a8d7
docs(review): record mixed-output framing repair
seonghobae Oct 1, 2026
038283d
docs(gap): bind mixed-output framing repair
seonghobae Oct 1, 2026
19cd282
merge(opencode): integrate current security owner
seonghobae Oct 1, 2026
857f036
fix(opencode): retain non-finite array framing
seonghobae Oct 1, 2026
cd4dd01
fix(opencode): restore normalizer executable mode
seonghobae Oct 1, 2026
b5a0507
test(opencode): reject invalid-token wrapper promotion
seonghobae Oct 1, 2026
443c29a
fix(opencode): keep invalid wrappers fail-closed
seonghobae Oct 1, 2026
0a5319e
docs(changelog): record invalid-wrapper evidence boundary
seonghobae Oct 1, 2026
24954aa
docs(gap): bind invalid-wrapper promotion repair
seonghobae Oct 1, 2026
36b4b4c
⚡ Bolt: Replace `str.find()` with `str.rfind()` for last occurrence s…
seonghobae Oct 1, 2026
a5fddfa
fix(opencode): restore reviewed evidence delta
seonghobae Oct 1, 2026
8b1bd4a
test(review): reject separatorless invalid wrappers
seonghobae Oct 1, 2026
5261145
fix(review): retain balanced separatorless wrappers
seonghobae Oct 1, 2026
2542b69
docs(review): record separatorless wrapper repair
seonghobae Oct 1, 2026
93d9fb4
docs(gap): bind separatorless wrapper evidence
seonghobae Oct 1, 2026
3e006bb
fix(docs): restore complete product gap source
seonghobae Oct 1, 2026
8168ce0
fix(docs): normalize restored gap ending
seonghobae Oct 1, 2026
8b0e0b7
merge(review): synchronize current Maturin owner
seonghobae Oct 1, 2026
24efc99
chore: trigger opencode review retry
seonghobae Oct 1, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 1 addition & 4 deletions .github/workflows/trusted-uv-materializer-quality-ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,16 +2,15 @@ name: Trusted uv Materializer Quality CI

on:
pull_request:
branches: [main]
paths:
- ".github/workflows/trusted-uv-materializer-quality-ci.yml"
- "scripts/ci/materialize_base_python_requirements.py"
- "scripts/ci/verify_release_maturin_tool_assets.py"
- "tests/conftest.py"
- "tests/test_materialize*.py"
- "tests/test_trusted_uv*.py"
- "tests/test_uv*.py"
- "tests/test_repository_branch_coverage_*.py"
- "tests/test_verify_release_maturin_tool_assets.py"
- "requirements-opencode-review-ci.txt"
- "requirements-noema-document-ci.txt"
- "requirements-opencode-review-ci-hashes.txt"
Expand All @@ -22,13 +21,11 @@ on:
paths:
- ".github/workflows/trusted-uv-materializer-quality-ci.yml"
- "scripts/ci/materialize_base_python_requirements.py"
- "scripts/ci/verify_release_maturin_tool_assets.py"
- "tests/conftest.py"
- "tests/test_materialize*.py"
- "tests/test_trusted_uv*.py"
- "tests/test_uv*.py"
- "tests/test_repository_branch_coverage_*.py"
- "tests/test_verify_release_maturin_tool_assets.py"
- "requirements-opencode-review-ci.txt"
- "requirements-noema-document-ci.txt"
- "requirements-opencode-review-ci-hashes.txt"
Expand Down
62 changes: 49 additions & 13 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,16 +1,52 @@
### Maturin download failures close every transport response

- Refactor the bounded Maturin asset downloader so successful and rejected
responses share one unconditional close path while `HTTPError` keeps its own
explicit close path. A new regression exercises a non-200 response and an
opener-raised HTTP error. This removes an impossible optional-response branch
without changing hosts, redirects, byte limits, hashes, or fail-closed error
mapping; the focused suite is 17 passed with 100% statement and branch
coverage. The trusted full-suite workflow now also tracks the verifier source
and its focused test, so a future lifecycle change cannot omit the repository
coverage gate that detected this regression. The pull-request trigger admits
stacked canonical-owner bases as well as `main`; the protected-branch push
trigger remains restricted to `main`.
### OpenCode invalid-token wrappers remain fail-closed

- Treat a balanced object or array whose first token is invalid JSON as one
outer evidence container instead of skipping its opener and promoting a
nested exact-run control. RED commit
`b5a0507b8ee4ec70cc5fca751f34df98719f219b` binds `undefined`, arbitrary
unquoted array tokens, and unquoted object keys; GREEN commit
`443c29aa6f56735f7fcf0ee6a550b6bad5f7e2f8` preserves the proven prose
delimiter recovery while keeping balanced malformed wrappers fail-closed.
The production normalizer remains executable (`100755`).

### OpenCode mixed-output framing preserves later controls

- Ignore prose `{` or `[` delimiters whose next non-whitespace token cannot
start the corresponding JSON container. This preserves a later complete
exact-run control after diagnostics such as `Diagnostic: [pending` without
weakening the existing fail-closed rule for malformed outer objects or
arrays. RED commit `42099a359cdfb8126ea4e3d9118c60f6d98af1fa`
records the lost-control case; GREEN commit
`07baba20259c9061fbb647963f09745a9ca6931b` restores the framing boundary.
Fresh exact-head hosted Checks and a qualifying independent approval remain
required before ordinary merge.

### OpenCode embedded JSON evidence is outermost and linear-time

- Parse prose-wrapped JSON by scanning each outermost object or array once,
with string and escape awareness, instead of retrying `raw_decode` at every
nested `{`. A malformed outer container can no longer promote a nested
exact-run control object into top-level approval evidence, and adversarial
nested prefixes no longer cause quadratic decoding work. RED commit
`d05f67f6c5f164309d3cbf15f4858c5fa3d176cd` preserves the malformed-object
exploit; GREEN commit `86f52f320e8eb5ac56efdf9a3e2552b20bf409de`
replaces the retry loop, and `1a00c73a752b45d9d2a808d9bc96baae51ea8402`
extends the same invariant to malformed array nesting. Fresh exact-head
hosted Checks and a qualifying independent approval remain required before
ordinary merge.

### OpenCode evidence labels require standalone identity boundaries

- Reject a purported verification label when it is only the suffix of an
identifier-like token such as `uncoverage:`. The OpenCode normalizer now
applies the same boundary rule while selecting the last admissible label and
while finding the next label that terminates its section. RED commit
`af06cf9c87de4ac76db575d087a170746d6ab83d` proves that a forged suffix could
override an earlier fail-closed coverage statement; GREEN commit
`4d49b8307706ab8d4565cca8b0d9728bcdad2a35` preserves repeated labels,
Markdown decoration, and the distinct `docstring coverage:` label while
rejecting the identity-confused form. Fresh exact-head hosted Checks and a
qualifying independent approval remain required before ordinary merge.

### Shared Strix lock advances beyond the PyJWT recursion DoS

Expand Down
44 changes: 0 additions & 44 deletions docs/doctoring/maturin-download-response-lifecycle-20261001.md

This file was deleted.

128 changes: 122 additions & 6 deletions docs/product-technical-gap-baseline.md
Original file line number Diff line number Diff line change
@@ -1,11 +1,5 @@
# Product and Technical Gap Baseline

## 2026-10-01 Maturin response-lifecycle coverage closure

| Gap | Exact evidence | Action | Status |
|---|---|---|---|
| `.github#1653@5cd141ec2c33b631d164af936cd1c9de70e4c9a4` passed all 5,314 tests but failed the complete branch gate because the canonical Maturin downloader left five error-path statements and two branches unexecuted; the owner workflow omitted both verifier paths and stacked PR bases | Trusted uv Materializer run `36811202519`, job `110206427182`; `verify_release_maturin_tool_assets.py` 95%, missing lines 104 and 106-112 plus branch 114→116; no owner run at #2530 predecessor `8cf2ea5f73976d47b2267fb52ac28284323404b7` because its base was #2531 rather than `main` | Repair canonical successor `.github#2530`: exercise non-200 and opener-raised `HTTPError` closure, replace the impossible nullable-response finalizer with one unconditional response-owned close scope, add source/test and stacked-PR trigger contracts to the complete gate while retaining protected-main push scope, preserve all network and fail-closed boundaries, then ordinary-merge the accepted owner head into #1653 | **Proposed / hosted RED reproduced; focused verifier coverage GREEN locally; path and stacked-admission contracts RED→GREEN; exact-head hosted full-suite, security, CodeQL, and independent approval required** |

## 2026-10-01 bounded Maturin release downloader SAST closure

| Gap | Exact evidence | Action | Status |
Expand Down Expand Up @@ -3725,3 +3719,125 @@ verdict-shape acceptance, and qualifying independent approval.
**Gap / failure scene.** The v2 handler names a run with `head/base/required-run/producer-source`, but its required-workflow fallback looked up only `head/base/required-run`. When authenticated status publication is unavailable, a completed clean handler job could not be found and a rerun ended false RED. Omitting the producer source would also allow a regenerated live merge revision to reuse predecessor evidence.

**Action / evidence.** Correct the fallback lookup to include the live merge source and retain fail-closed base, head, required-run, workflow-path, job-name, GHAS-identity, and SARIF checks. The test-first repair reproduced two failures, then passed 96 focused workflow-contract tests; the new edge case rejects a stale merge-source title. Ruff E9/F/I on the changed dispatch-contract file and `git diff --check` pass. Fresh hosted Checks and a qualifying independent approval are still required on the unchanged executable delta before merge.

## 2026-10-01 OpenCode evidence-label identity boundary

**Status:** Proposed on `ContextualWisdomLab/.github#2543`; fresh exact-head
hosted Checks and a qualifying independent approval remain mandatory.

**Context Map / owner.** The central `.github` review-control bounded context
owns OpenCode response normalization and approval-evidence admission. OpenCode
is the untrusted evidence producer; repository review workflows consume only
the normalizer's fail-closed verdict contract.

**Gap / RCA.** The optimized last-label search used an unconstrained
`rfind("coverage:")`. A response could state that real coverage evidence was
not measured, then append `uncoverage: ... 100%`; the suffix beginning inside
`uncoverage:` was accepted as a newer `coverage:` label. The false label could
therefore replace the genuine fail-closed section and make
`mentions_full_coverage` return true. The same missing identity boundary also
affected forward searches for the next section label.

**RED → GREEN / action.** RED
`af06cf9c87de4ac76db575d087a170746d6ab83d` adds the durable suffix-forgery
case. GREEN `4d49b8307706ab8d4565cca8b0d9728bcdad2a35` rejects label occurrences whose
preceding character is alphanumeric, underscore, or hyphen in both backward
selection and forward section termination. It retains decorated Markdown
labels, repeated legitimate labels, and the separate `docstring coverage:`
rule. Local direct behavior cases, Python compilation, and `git diff --check`
are GREEN; the local environment has no pytest installation, so no full-suite
claim is made. Completion still requires hosted exact-head tests, terminal
required Checks, no unresolved actionable thread, qualifying independent
approval, and ordinary protected integration.

## 2026-10-01 OpenCode outermost JSON evidence boundary

**Status:** Proposed on `ContextualWisdomLab/.github#2543`; executable repair
and local focused verification are GREEN, while fresh exact-head hosted Checks
and a qualifying independent approval remain mandatory.

**Context Map / owner.** The central `.github` review-control bounded context
owns OpenCode response normalization and exact-run evidence admission. The
model response is untrusted input; downstream required-review workflows may
consume only top-level controls accepted by this owner contract.

**Gap / RCA.** Exact-head Strix run
[36794394865](https://github.com/ContextualWisdomLab/.github/actions/runs/36794394865)
reported repeated JSON decoding in `iter_json_objects`. Direct reproduction
confirmed two effects from the same retry-at-every-`{` loop: a malformed outer
object could promote its valid nested exact-run control into top-level evidence,
and doubling an unclosed nested prefix increased processing time by roughly
four times. The first effect is an identity-boundary false admission; the
second permits model-controlled quadratic work.

**RED → GREEN / action.** RED
`d05f67f6c5f164309d3cbf15f4858c5fa3d176cd` records the malformed-object
promotion. GREEN `86f52f320e8eb5ac56efdf9a3e2552b20bf409de`
tracks one outermost container at a time, handles quoted strings and escapes,
and decodes only a completed outermost span. Follow-up test commit
`1a00c73a752b45d9d2a808d9bc96baae51ea8402` binds the same rule to malformed
array nesting. The existing embedded-object cases and both new adversarial
cases pass; Python compilation and `git diff --check` are GREEN. A direct
3,200-level measurement completed in 0.001236 seconds, while the prior
1,600-level case required 0.065367 seconds. These are local diagnostic values,
not a hosted performance claim. Pytest is unavailable in the local runner, so
the complete suite remains an exact-head hosted acceptance requirement.


## 2026-10-01 OpenCode mixed-output JSON framing boundary

**Status:** Proposed on `ContextualWisdomLab/.github#2543`; executable
RED→GREEN complete, fresh exact-head hosted Checks and a qualifying independent
approval remain mandatory.

**Context Map / owner.** The central `.github` review-control bounded context
owns mixed-output framing and exact-run evidence admission. OpenCode output is
untrusted: prose delimiters must not block a later complete top-level control,
while actual malformed outer containers must continue to suppress nested
controls.

**Gap / RCA.** CodeRabbit review on prior exact head
`2ee8ddad072fe59bbe33c99994fa1e8c9cb5387c` showed that
`Diagnostic: [pending` was treated as an unclosed JSON array and hid a later
valid control. Direct reproduction showed the same regression for
`Diagnostic: {pending`. The outermost single-pass repair had dropped the
predecessor's candidate-start grammar gate.

**RED → GREEN / action.** RED
`42099a359cdfb8126ea4e3d9118c60f6d98af1fa` binds both prose delimiters.
GREEN `07baba20259c9061fbb647963f09745a9ca6931b` admits an object start only
before `"` or `}`, and an array start only before a JSON value starter.
Existing malformed object/array nested-control cases remain fail-closed.
Direct focused cases 8/8, Python compilation, and `git diff --check` are GREEN;
pytest is unavailable locally, so the full hosted suite remains required.


## 2026-10-01 balanced invalid-token wrapper evidence boundary

**Status:** Proposed on `ContextualWisdomLab/.github#2543`; executable
RED→GREEN is published, while fresh exact-head hosted Checks and a qualifying
independent approval remain mandatory.

**Context Map / owner.** The central `.github` review-control bounded context
owns OpenCode mixed-output normalization and exact-run evidence admission.
OpenCode model output is untrusted. A nested control inside any balanced outer
container—including a syntactically invalid one—must never acquire top-level
identity.

**Gap / RCA.** The candidate-start allowlist skipped balanced wrappers whose
first token was invalid JSON. Inputs such as `[undefined, {control}]`,
`[unquoted_token, {control}]`, and `{unquoted_key: {control}}` therefore
promoted the nested exact-run control. The earlier `NaN`/`Infinity` repair
covered Python JSON extensions but not the general invalid-token boundary.

**RED → GREEN / action.** RED
`b5a0507b8ee4ec70cc5fca751f34df98719f219b` reproduces all three promotions.
GREEN `443c29aa6f56735f7fcf0ee6a550b6bad5f7e2f8` treats an invalid starter as a
malformed outer container when its token reaches a structural separator before
another opener; the proven unclosed prose-delimiter recovery remains intact.
Focused parser verification is 118/118 GREEN. Full repository verification
reached 5,318 passed, 7 skipped, and 40 subtests; its sole failure was the
published-commit ancestry test because the isolated `git archive` intentionally
has no `.git` directory. Warnings-fatal compilation and diff whitespace checks
are GREEN. Exact Git tree `dccb57a152c21600305c0eabac06cb29de2e0cf7`
preserves source mode `100755`.
Loading
Loading