^B Verify validator workspace binds before certification - #535
Conversation
Fail local validator lanes before they certify the wrong checkout when the selected Docker daemon cannot see the requested workspace. Probe the exact canonical read-only bind with a per-run challenge before validation, docs, fuzz, mutation, and install-artifact workloads. Cover correct, stale, and missing daemon views by executing the production probe payload through a Docker stub. Preserve context-specific remediation and clean up every challenge artifact. Validated with three clean peer-review lenses, focused and full testkit runs, the quick gate, live positive and negative Docker-context controls, and the full dirty-tree pr-parity profile.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: f26971b17f
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review Please re-review signed head |
|
Codex Review: Didn't find any major issues. 🚀 Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
Summary
--mountrecords for the readonly probe and all five read-write validator workloadsValidation
./scripts/validate-repo.sh./scripts/pre-merge.sh --profile pr-parity --base main --parity-snapshot worktreeSigned commits:
f26971b17ffd2862fcce7262e7dd48e820866bb7,dfd1eda6761e71e7707adda24c551f4df6e40eb6