Skip to content

Harden CI planning against hostile Git state - #525

Merged
omkhar merged 5 commits into
mainfrom
risk/canonical-ci-plan-git-state
Jul 28, 2026
Merged

Harden CI planning against hostile Git state#525
omkhar merged 5 commits into
mainfrom
risk/canonical-ci-plan-git-state

Conversation

@omkhar

@omkhar omkhar commented Jul 23, 2026

Copy link
Copy Markdown
Owner

Summary

  • derive changed paths only from resident, immutable Git object IDs under a canonical scrubbed Git environment
  • reject every effective conversion-filter association before diff planning, including populated nested submodules
  • collect NUL-delimited paths without process-substitution status loss and preserve Bash 3.2 compatibility

Security properties

  • no network fetch, lazy object fetch, replacement objects, grafts, hooks, fsmonitor, global attributes, or credential helpers participate in planning
  • remote-ref absence is distinguished from malformed/unreadable state before the local fallback is accepted
  • populated submodule roots and Git directories are physically bound and cannot reuse an enclosing authority
  • classified attributes are pinned to the resident base object and all returned filter associations fail closed, including drivers named unset or unspecified

Validation

  • independent exact adversarial review and clean rebind onto current main
  • Bash 3.2.57 and source-built Git 2.50.0 planner probes
  • focused and race TestCIPlan suites, including filter/submodule/symlink/lazy-fetch/fsmonitor mutants
  • full Go, shellcheck, shfmt, diff, operator-contract, requirements, docs, and repository hygiene checks
  • canonical pr-parity on the exact staged tree, including live Workcell invariants

No provider, runtime, public CLI, or support-tier behavior changes in this unit.

… review pass; supporting validation security)
@omkhar omkhar added the approved-heavy-ci Maintainer-approved heavy GitHub Actions runs label Jul 23, 2026
@omkhar

omkhar commented Jul 23, 2026

Copy link
Copy Markdown
Owner Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: b3cb9f2e45

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread scripts/ci-plan.sh
Comment thread scripts/ci-plan.sh Outdated
…al review pass; supporting validation security)
@omkhar

omkhar commented Jul 28, 2026

Copy link
Copy Markdown
Owner Author

Fixed both review findings in signed commit 4c9ac5d. The planner now fails closed on index flags that can hide tracked modifications and on repository-local info excludes that can hide untracked files. Focused Git-state, workflow-metadata, and exact planner checks pass; all hosted checks are green.

@omkhar

omkhar commented Jul 28, 2026

Copy link
Copy Markdown
Owner Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: b3cb9f2e45

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/validation-scenarios.md Outdated
@omkhar

omkhar commented Jul 28, 2026

Copy link
Copy Markdown
Owner Author

@codex review for current head commit 4c9ac5d

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: b3cb9f2e45

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/validation-scenarios.md Outdated
@omkhar

omkhar commented Jul 28, 2026

Copy link
Copy Markdown
Owner Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 4c9ac5d908

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread scripts/ci-plan.sh
@omkhar

omkhar commented Jul 28, 2026

Copy link
Copy Markdown
Owner Author

@codex review. Re-review exact PR head 4c9ac5d. Verify commit signatures against the PR commit object and GitHub verification metadata, not an unrelated synthetic object.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Can't wait for the next one!

Reviewed commit: 4c9ac5d908

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@omkhar
omkhar marked this pull request as ready for review July 28, 2026 06:15
@omkhar

omkhar commented Jul 28, 2026

Copy link
Copy Markdown
Owner Author

@codex review. Ready-state final review of exact head 4c9ac5d.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 4c9ac5d908

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread scripts/ci-plan.sh
@omkhar

omkhar commented Jul 28, 2026

Copy link
Copy Markdown
Owner Author

@codex review

Please review exact signed head abd7ac3. Bind all findings to that object. The enclosing-repository finding is fixed by the script-root .git anchor and its regression test.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. 🚀

Reviewed commit: abd7ac3086

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

…on and peer review pass; user-visible planner security bug)
@omkhar

omkhar commented Jul 28, 2026

Copy link
Copy Markdown
Owner Author

@codex review

Please review exact signed head f18029b. The planner now rejects every root .git file and symlink before Git runs, so a gitdir file cannot redirect planning to an enclosing repository. The regression models that exact gitdir-file case. Full clean-tree PR parity passed on this object.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: f18029b188

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread scripts/ci-plan.sh
@omkhar

omkhar commented Jul 28, 2026

Copy link
Copy Markdown
Owner Author

@codex review

Please review exact signed head c2ae7b1. The planner rejects any root .git/commondir file or symlink before Git runs, and the regression covers the reported ../../.git redirection. Fresh canonical pr-parity passed on this exact 1,198-line tree.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. 🎉

Reviewed commit: c2ae7b1f9c

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@omkhar

omkhar commented Jul 28, 2026

Copy link
Copy Markdown
Owner Author

Final single-maintainer pre-merge sweep for signed head c2ae7b1: required checks are green, all review threads are resolved, all five commits have valid GitHub signature verification, and the final Codex review found no major issue. GitHub still requires an independent approval that a sole maintainer cannot supply, so this merge uses the explicit administrator bypass.

@omkhar
omkhar merged commit 1a0b661 into main Jul 28, 2026
19 checks passed
@omkhar
omkhar deleted the risk/canonical-ci-plan-git-state branch July 28, 2026 16:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved-heavy-ci Maintainer-approved heavy GitHub Actions runs

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant