Repository navigation
ci(gyeot): add central self-hosted verification - #2611
seonghobae wants to merge 47 commits into
Conversation
Preserve the live security-owner and Gap-evidence lineage while merging the independently reviewed RED-to-GREEN repair that removes urlopen suppressions, accepts one credential-free HTTPS redirect only to the exact GitHub release-assets host, bounds reads, and closes every response/connection path. Local exact-tree evidence: 16 focused tests passed; git diff --check passed. The same repair on the immediately preceding owner tree passed 5,178 tests, 8 skipped, and 40 subtests, and independent review reported zero Critical, Important, or Minor findings. Fresh hosted exact-head evidence remains mandatory.
Replace only the corrupted 120,060-byte binary payload with the last complete 3,678-line UTF-8 baseline from the immediate valid predecessor. Preserve the SAST transport repair and all other a5ddcfc changes. Fresh exact-head hosted evidence remains required.
Complete the Semgrep transport repair by constructing the urllib opener with ProxyHandler({}). This prevents environment-derived HTTPS proxy authorities and proxy credentials from entering the fixed GitHub-to-release-assets request path while preserving the reviewed one-hop redirect handler.
RED-to-GREEN: the bounded-download contract first required an explicit empty proxy map and failed when build_opener received only the redirect handler. Final focused verification: 16 passed; compileall and git diff --check passed. Independent offline replay with a credential-bearing https_proxy confirmed exclusion, and re-review reported zero Critical, Important, or Minor findings. Fresh hosted exact-head evidence remains mandatory.
Preserve the live exact-head SAST RCA documentation and the independently reviewed ProxyHandler({}) repair as ordinary parents. The merged tree retains the restored complete Gap baseline, fixed one-hop redirect handler, ambient proxy/auth exclusion, focused GREEN evidence, and all release HOLD language.
Focused exact-tree verification: 16 passed; git diff --check passed. Fresh hosted exact-head evidence and qualifying approval remain mandatory.
Co-Authored-By: Claude Code <noreply@anthropic.com>
Co-Authored-By: Claude Code <noreply@anthropic.com>
Co-Authored-By: Claude Code <noreply@anthropic.com>
Co-Authored-By: Claude Code <noreply@anthropic.com>
Co-Authored-By: Claude Code <noreply@anthropic.com>
Co-Authored-By: Claude Code <noreply@anthropic.com>
Co-Authored-By: Claude Code <noreply@anthropic.com>
Co-Authored-By: Claude Code <noreply@anthropic.com>
Co-Authored-By: Claude Code <noreply@anthropic.com>
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: true
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Reviewed repair published — October 9, 2026 KSTExact head: 87a371a. Normal push; no merge or protection bypass. Three changed repair files only: sandboxed_web_e2e.py, its tests, and the CodeQL audit clock tests. The prior sandbox candidate was rejected by independent security review; two RED/GREEN repair cycles reject external executable symlinks, internal symlink plus dotdot traversal, and home/bind-root overlap while retaining legitimate workspace and relative PATH controls. The final independent re-review found no security/logic findings across 23 construction-only probes; its full targeted test run passed 117 with zero skips/deselections. Parent combined Gyeot/clock/sandbox run passed 219 with zero skips. This is local source review, NOT live bubblewrap isolation, model inference, GitHub App APPROVED review, or a green full gate. Final source hashes: sandbox runtime d6de19ccca907e3c98af0cd09be399a0d0dacaf97e9bbac0c06298c824115303; sandbox tests 2e1a44e7358a365753917c4c4fa430bcf9252d1b8d14145d6b8a66f4124e860e; clock tests c49cb17c53dd780995a22599c582d764dc1d61f3620e314903a42e50e359b081. Full post-repair exact-head local acceptance is now running with durable logs/JUnit and independent coverage/interrogate exits; no result yet. Earlier complete execution: 5260 passed, 7 failed, 4 skipped plus 40 passing subtests. Full gate remains unpassed; documented clock and sandbox failures are repaired but inherited coverage/docstrings still require #2572. Shared label/group admission is owned by #2565; existing clock fixture owner #2609 is preserved and not closed. GYEOT_HELPER_COMMIT sentinel remains intentional pending protected helper publication. Dedicated runner capacity and effective auto/LiteLLM review plus substantive independent App approval remain separate prerequisites. Draft/HOLD is unchanged. |
Post-repair full local acceptance result — October 9, 2026 KSTExact head: 87a371a. Completed source-stable full test run:
Evidence paths in the local runner:
Verdict: full central gate is still NOT GREEN. The repaired Gyeot/clock/sandbox source now clears the full pytest leg, but inherited coverage/docstring gates remain blockers under #2572 ownership, and Gyeot runner label/group admission remains under #2565 ownership. GitHub Code Quality is still a billing-lock start failure, not a source failure. Draft/HOLD remains unchanged; no approval, merge, runner provisioning, helper pin publication, or protection bypass is claimed. |
|
Shared-policy dependency is now a reviewed, published stacked Draft |
Exact-source inherited quality combination — verified October 9 KSTI independently checked the retained private no-commit merge of this PR head Receipt: |
…ot-central-self-hosted
Independent integration review PASS; distinct remote failuresFrozen current source dc59db2 / tree152d8668f72016293928c22fbbc177bf3da18fe8 independently passed integration review. All52incoming files match qualityowner and all17retained changed files match Gyeot parent; sets disjoint. Runtime/security/lock composition seams inspected, bounded42dependency/download+12releaseadmission cases passed0skip. This is source review only, not qualifying GitHub App approval or native/runtime proof. Fresh GraphQL exact-head annotations distinguish two failures:
Do not classify quota as source regression, inference failure or App approval. No unchanged rerun, artifact deletion, spending/billing/protection/credential mutation. REST quota hit too; authenticated GraphQL provided these annotations. Draft remains pending actual helperpin/runner integration and deployment gates. |
Scope
Fixed-caller Gyeot reusable workflow and four central helpers, with app export and PostgreSQL verification. Two jobs route only through the dedicated CWL Gyeot CI self-hosted group. The current branch also preserves the entire independently owned #2572 inherited-quality/security stack by ordinary merge, plus the reviewed sandbox and CodeQL-clock repairs; it is not only a seven-file change.
Current source and local acceptance
Exact head
dc59db224eb087d100d343ae125defc47b7a2a2c, parents Gyeot87a371a7and quality ownerb37356d5, tree152d8668f72016293928c22fbbc177bf3da18fe8. An exact-tree private no-commit merge ran Python 3.14.5 full tests: 5,405 passed, 4 skipped, 40 subtests passed. Statement 18,280/18,280 and branch 7,506/7,506 coverage = 100%; interrogate 1,473/1,473 = 100%. All three gate exits 0, source hashes stable and all Gyeot files preserved. Parent independently verified the 28-artifact receipt at/Users/seonghobae/.hermes/cache/scratch/gyeot-2572-private-accept-20261009/FINAL-MANIFEST.json(local host). One ResourceWarning remained; the 4 skips are explicit, not tested native functionality.Deliberate non-readiness
Still Draft.
GYEOT_HELPER_COMMIT=UNPUBLISHED_GYEOT_HELPER_COMMITdeliberately prevents calling or executing an unintegrated helper snapshot. The product caller template is not installed. Dedicated group 9 is selected for Gyeot only but currently has zero runners; no other group is borrowed. Shared exact label/group source-policy admission lives in stacked Draft #2613 on global migration #2565. Personal LiteLLMautosource wiring exists on current #2565 head but is not yet protected deployment, authenticated inference or qualifying independent App approval for this PR. GitHub-managed Code Quality is billing-locked before job start. No hosted fallback, protection bypass, fabricated status, pre-decided approval or merge is requested.Remaining gates
Integrate and independently review current cumulative tree under normal protection; publish the central helper snapshot before replacing the sentinel with its real immutable SHA and activating a product caller. Provision/attest the dedicated runner and run exact-head jobs. Preserve security and 100% quality gates; obtain real author-distinct Noema/OpenCode App verdict on the current head after Ready and deployed routing. CI outcomes, runner canary, formal review and protected merge remain separate.
References #2565, #2572, #2613 and Issue #2560; consumer ContextualWisdomLab/gyeot.