Skip to content

fix(api): reject ambiguous HTTP request framing - #254

Merged
seonghobae merged 29 commits into
mainfrom
fix/session-http-framing-20260818
Aug 25, 2026
Merged

seonghobae merged 29 commits into
mainfrom
fix/session-http-framing-20260818

Conversation

@seonghobae

@seonghobae seonghobae commented Aug 18, 2026 •

Copy link
Copy Markdown
Contributor

Why

Protected main accepts session HTTP requests with the first Content-Length it sees and does not reject Transfer-Encoding. That lets an intermediary and the runtime disagree about where a request ends, creating a request-smuggling/message-framing boundary defect in the newly shipped session transport.

The same boundary also previously ignored HTTP field names with whitespace before the colon, such as Content-Length : 2, because they no longer matched the framing-header name after splitting. A stricter intermediary can reject that syntax while another recipient normalizes it, so malformed field-name aliases must fail before application dispatch rather than being treated as unrelated headers.

What

  • Add a fail-closed public session HTTP framing boundary without changing supported session lifecycle behavior.
  • Accept at most one Content-Length header.
  • Reject every Transfer-Encoding because this listener does not implement transfer-coding/chunk decoding.
  • Reject duplicate Content-Length, including equal duplicates, as a deliberately narrower supported grammar.
  • Require every parsed HTTP field name to use the HTTP token grammar; whitespace-before-colon, obsolete folded framing aliases, empty names, and other invalid field-name bytes fail closed.
  • Preserve valid fragmented single-Content-Length requests and GET reload behavior.
  • Reconcile onto exact protected main while preserving the shipped authorization/session behavior.

TDD lineage

  • f65e58dc537a7c276065395dccb94a765e3aaa45 adds behavior-level loopback regressions for Transfer-Encoding, TE+CL, conflicting duplicate CL, and equal duplicate CL before the guard exists.
  • cf1380f520b1b6fc5426b9b87b9d466004510b28 adds the framing guard.
  • 9a715a3a8094fa459f8e27faaddad759f0e68a47 routes the public session HTTP module through that guard.
  • c76d7ff07e94b28a91f0f6d89a2de012bddcc1c2 reconciles protected main without force-push.
  • RED 344fcce5d021c89e5c1479cc0d05b899206ccd72 adds loopback regressions for whitespace-before-colon and leading-whitespace framing aliases.
  • GREEN 82121a89291fe0c98ca260ed4ba7c31e777df14b enforces the HTTP field-name token grammar before framing-header matching and adds focused helper coverage for valid, empty, whitespace-bearing, and invalid-token names.

The RED commits are historical test-first evidence; no claim is made that they were locally executed outside CI. Exact-head CI remains authoritative.

Standard basis

Fielding, R., Nottingham, M., & Reschke, J. (2022). HTTP/1.1 (RFC 9112). RFC Editor. https://doi.org/10.17487/RFC9112

RFC 9112 treats conflicting or invalid HTTP/1.1 framing as a request-smuggling risk and requires request field-name/colon syntax to be parsed fail-closed. This bounded listener intentionally supports only the simpler Content-Length framing subset rather than implementing Transfer-Encoding partially.

Scope

No HTTP/2 implementation, no chunked decoder, no session-authentication redesign, no Keyverse ownership change, and no psychometric/scoring behavior change. Anonymous-session credential-to-resource authority remains on its separate current lane.

Required evidence before merge

Exact-current-head Runtime CI; exact owned statement/branch coverage; rustfmt/clippy/rustdoc; security/SAST/SBOM/provenance; zero valid unresolved findings; and qualifying independent non-author review where required by live policy.

Summary by CodeRabbit

  • 새로운 기능

    • 단일 HTTP 세션 연결을 안전하게 처리합니다.
    • 전체 읽기 데드라인과 요청·응답 크기 제한을 적용합니다.
    • HTTP/1.1 응답에 콘텐츠 길이와 연결 종료 정보를 포함합니다.
    • 주요 오류 응답에 올바른 HTTP 상태 설명을 제공합니다.
  • 버그 수정

    • 잘못된 헤더 형식과 줄바꿈을 거부합니다.
    • 모호하거나 중복된 메시지 프레이밍을 차단합니다.
    • 잘못된 Content-Length, 추가 데이터, 지원하지 않는 전송 인코딩을 거부합니다.

Open in Devin Review

@cursor

cursor Bot commented Aug 18, 2026

Copy link
Copy Markdown
Contributor

Bugbot is not enabled for your account, so this pull request was not reviewed.

Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs.

@coderabbitai

coderabbitai Bot commented Aug 18, 2026 •

Copy link
Copy Markdown

Review Change Stack

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: ac9bc1e3-5626-4f09-bca4-74aad999d204

📝 Walkthrough

Walkthrough

세션 HTTP 구현을 별도 경계 모듈로 이동했습니다. 요청 헤더와 프레이밍을 엄격하게 검증합니다. 전체 요청 읽기에 단일 데드라인을 적용하고 관련 오류 및 응답 reason phrase를 테스트합니다.

Changes

세션 HTTP 경계

Layer / File(s) Summary
경계 진입점과 전체 읽기 데드라인
src/lib.rs, src/session_http.rs, src/session_http_boundary.rs
session_http_boundary.rs를 명시적 모듈 경로로 로드합니다. 기존 session_http.rs의 TCP 요청 처리 코드를 제거합니다. 연결 수락 후 전체 요청 읽기에 단일 데드라인을 적용합니다.
요청 프레이밍과 오류 정규화
src/session_http_boundary.rs
소켓 읽기마다 남은 데드라인을 적용합니다. Content-Length와 Transfer-Encoding을 검증합니다. 추가 바이트, 중복 프레이밍 헤더, 잘못된 길이 문법 및 오버플로를 InvalidData로 처리합니다. 타임아웃 오류를 정규화합니다.
프레이밍 및 응답 회귀 검증
tests/session_http_framing.rs, tests/session_http_framing_security_regression.rs, tests/session_http_malformed_header.rs, src/session_http_boundary.rs
모호한 프레이밍, 잘못된 헤더 문법, obsolete folded 헤더, 잘못된 줄바꿈, 파이프라인 요청 및 느린 분할 읽기를 검증합니다. HTTP 404, 405, 409, 500 응답의 reason phrase도 검증합니다.

Estimated code review effort: 4 (Complex) | ~45 minutes

Merge Risk: 🟠 High · up to c72cb

This PR strengthens session HTTP framing, but the current implementation can still process truncated or malformed requests, allow slow clients to retain processing capacity, and accept invalid Content-Length syntax. Those concrete security, correctness, and availability risks make the PR unsafe to merge until addressed.

Sequence Diagram(s)

sequenceDiagram
  participant Client
  participant TcpListener
  participant accept_one_session_http
  participant SessionHttpPort
  Client->>TcpListener: HTTP 요청 전송
  TcpListener->>accept_one_session_http: TCP 연결 수락
  accept_one_session_http->>accept_one_session_http: 헤더 및 프레이밍 검증
  accept_one_session_http->>SessionHttpPort: 검증된 세션 요청 전달
  SessionHttpPort-->>accept_one_session_http: 세션 응답 반환
  accept_one_session_http-->>Client: HTTP 응답 전송 및 연결 종료
Loading
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 48.84% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 43 functions across 6 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed 제목은 모호한 HTTP 요청 프레이밍을 거부하는 이번 변경의 핵심 목적을 정확하고 간결하게 설명합니다.
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/session-http-framing-20260818

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode cannot approve yet because required coverage evidence did not pass.

Review outcome

1. HIGH .github/workflows/opencode-review.yml:1 - Coverage evidence did not prove required test/docstring evidence

  • Problem: The required coverage-evidence job result was failure, so OpenCode cannot establish approval sufficiency for this head.

  • Root cause: Automated approval is only valid when the same-head coverage-evidence job proves supported repository test suites passed and configured docstring gates passed or were advisory, or reports not applicable because no supported source files or package manifests exist. Missing, failed, skipped, unavailable, or unsupported-tooling test evidence is a blocker.

  • Fix: Install or configure the repository test/docstring evidence tooling when source files or package manifests exist, rerun the current-head coverage-evidence job, and approve only after it reports success with required evidence or explicit no-source not-applicable evidence.

  • Regression test: Keep the approval branch checking needs.coverage-evidence.result == success before posting APPROVE, and publish REQUEST_CHANGES when coverage-evidence blocker states such as cancelled, skipped, failed, unsupported-tooling, or below-100 evidence are present.

  • Result: REQUEST_CHANGES

  • Reason: coverage-evidence result was failure, so required test/docstring evidence was not proven for current head 2ba65562be3a36cb8202737c74edab0c3a3d1b68.

  • Head SHA: 2ba65562be3a36cb8202737c74edab0c3a3d1b68

  • Workflow run: 32132929403

  • Workflow attempt: 1

Coverage evidence

Coverage Decision

  • Result: FAIL
  • Test evidence: not proven passing
  • Docstring evidence: not proven passing when configured
  • Failure count: 1

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Changed file (2 files)"]
  S1 --> I1["repository behavior"]
  I1 --> R1["Review risk: Changed file (2 files)"]
  R1 --> V1["required checks"]
  Evidence --> S2["Test: session_http_framing.rs"]
  S2 --> I2["regression suite"]
  I2 --> R2["Review risk: Test: session_http_framing.rs"]
  R2 --> V2["targeted test run"]
Loading

@opencode-agent

opencode-agent Bot commented Aug 18, 2026 •

Copy link
Copy Markdown
Contributor

OpenCode Review Overview

  • Head SHA: f74c47809adbeec03b052dcd1fbe5778459ab852
  • Workflow run: 32700229291
  • Workflow attempt: 1
  • Gate result: REQUEST_CHANGES (approval step)

Pull request overview

OpenCode cannot approve yet because required coverage evidence did not pass.

Review outcome

1. HIGH .github/workflows/opencode-review.yml:1 - Coverage evidence did not prove required test/docstring evidence

  • Problem: The required coverage-evidence job result was failure, so OpenCode cannot establish approval sufficiency for this head.

  • Root cause: Automated approval is only valid when the same-head coverage-evidence job proves supported repository test suites passed and configured docstring gates passed or were advisory, or reports not applicable because no supported source files or package manifests exist. Missing, failed, skipped, unavailable, or unsupported-tooling test evidence is a blocker.

  • Fix: Install or configure the repository test/docstring evidence tooling when source files or package manifests exist, rerun the current-head coverage-evidence job, and approve only after it reports success with required evidence or explicit no-source not-applicable evidence.

  • Regression test: Keep the approval branch checking needs.coverage-evidence.result == success before posting APPROVE, and publish REQUEST_CHANGES when coverage-evidence blocker states such as cancelled, skipped, failed, unsupported-tooling, or below-100 evidence are present.

  • Result: REQUEST_CHANGES

  • Reason: coverage-evidence result was failure, so required test/docstring evidence was not proven for current head f74c47809adbeec03b052dcd1fbe5778459ab852.

  • Head SHA: f74c47809adbeec03b052dcd1fbe5778459ab852

  • Workflow run: 32700229291

  • Workflow attempt: 1

Coverage evidence

Coverage Decision

  • Result: FAIL
  • Test evidence: not proven passing
  • Docstring evidence: not proven passing when configured
  • Failure count: 1

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Changed file (3 files)"]
  S1 --> I1["repository behavior"]
  I1 --> R1["Review risk: Changed file (3 files)"]
  R1 --> V1["required checks"]
  Evidence --> S2["Test (3 files)"]
  S2 --> I2["regression suite"]
  I2 --> R2["Review risk: Test (3 files)"]
  R2 --> V2["targeted test run"]
Loading

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode cannot approve yet because required coverage evidence did not pass.

Review outcome

1. HIGH .github/workflows/opencode-review.yml:1 - Coverage evidence did not prove required test/docstring evidence

  • Problem: The required coverage-evidence job result was failure, so OpenCode cannot establish approval sufficiency for this head.

  • Root cause: Automated approval is only valid when the same-head coverage-evidence job proves supported repository test suites passed and configured docstring gates passed or were advisory, or reports not applicable because no supported source files or package manifests exist. Missing, failed, skipped, unavailable, or unsupported-tooling test evidence is a blocker.

  • Fix: Install or configure the repository test/docstring evidence tooling when source files or package manifests exist, rerun the current-head coverage-evidence job, and approve only after it reports success with required evidence or explicit no-source not-applicable evidence.

  • Regression test: Keep the approval branch checking needs.coverage-evidence.result == success before posting APPROVE, and publish REQUEST_CHANGES when coverage-evidence blocker states such as cancelled, skipped, failed, unsupported-tooling, or below-100 evidence are present.

  • Result: REQUEST_CHANGES

  • Reason: coverage-evidence result was failure, so required test/docstring evidence was not proven for current head 2ba65562be3a36cb8202737c74edab0c3a3d1b68.

  • Head SHA: 2ba65562be3a36cb8202737c74edab0c3a3d1b68

  • Workflow run: 32139440881

  • Workflow attempt: 1

Coverage evidence

Coverage Decision

  • Result: FAIL
  • Test evidence: not proven passing
  • Docstring evidence: not proven passing when configured
  • Failure count: 1

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Changed file (2 files)"]
  S1 --> I1["repository behavior"]
  I1 --> R1["Review risk: Changed file (2 files)"]
  R1 --> V1["required checks"]
  Evidence --> S2["Test: session_http_framing.rs"]
  S2 --> I2["regression suite"]
  I2 --> R2["Review risk: Test: session_http_framing.rs"]
  R2 --> V2["targeted test run"]
Loading

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode cannot approve yet because required coverage evidence did not pass.

Review outcome

1. HIGH .github/workflows/opencode-review.yml:1 - Coverage evidence did not prove required test/docstring evidence

  • Problem: The required coverage-evidence job result was failure, so OpenCode cannot establish approval sufficiency for this head.

  • Root cause: Automated approval is only valid when the same-head coverage-evidence job proves supported repository test suites passed and configured docstring gates passed or were advisory, or reports not applicable because no supported source files or package manifests exist. Missing, failed, skipped, unavailable, or unsupported-tooling test evidence is a blocker.

  • Fix: Install or configure the repository test/docstring evidence tooling when source files or package manifests exist, rerun the current-head coverage-evidence job, and approve only after it reports success with required evidence or explicit no-source not-applicable evidence.

  • Regression test: Keep the approval branch checking needs.coverage-evidence.result == success before posting APPROVE, and publish REQUEST_CHANGES when coverage-evidence blocker states such as cancelled, skipped, failed, unsupported-tooling, or below-100 evidence are present.

  • Result: REQUEST_CHANGES

  • Reason: coverage-evidence result was failure, so required test/docstring evidence was not proven for current head 9bd9f3db47c8577523934d35bf5074a95cd3bfd1.

  • Head SHA: 9bd9f3db47c8577523934d35bf5074a95cd3bfd1

  • Workflow run: 32213784052

  • Workflow attempt: 1

Coverage evidence

Coverage Decision

  • Result: FAIL
  • Test evidence: not proven passing
  • Docstring evidence: not proven passing when configured
  • Failure count: 1

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Changed file (2 files)"]
  S1 --> I1["repository behavior"]
  I1 --> R1["Review risk: Changed file (2 files)"]
  R1 --> V1["required checks"]
  Evidence --> S2["Test (2 files)"]
  S2 --> I2["regression suite"]
  I2 --> R2["Review risk: Test (2 files)"]
  R2 --> V2["targeted test run"]
Loading

coderabbitai[bot]

This comment was marked as resolved.

@seonghobae

Copy link
Copy Markdown
Contributor Author

Fixed the current-head line-coverage failure at exact head 096038ca7f271555884e0ce2480e7eee89b98e77 with a minimal root-cause change.

  • CI uncovered the private legacy listener/reader in src/session_http.rs, which is shadowed by the public hardened boundary module, plus uncovered boundary response reason branches.
  • Removed the unreachable duplicate framing path and its duplicate-only tests; retained the single public boundary implementation.
  • Added real TCP response coverage for 404/405/409/500 and direct fallback reason coverage.
  • New exact head: 8ab49c7d.
  • Local evidence: 20 focused session HTTP tests passed, cargo fmt --all -- --check, cargo clippy --all-targets -- -D warnings, and cargo test -q --lib --no-run passed.

This is validation evidence, not an approval. Required remote Runtime CI/coverage/security checks must complete on the new exact head.

@seonghobae

Copy link
Copy Markdown
Contributor Author

@opencode-agent Please review only the current exact head 8ab49c7 against protected main 5544149. The dead legacy framing path was removed and current boundary coverage was added; please review only exact head 8ab49c7 against protected main 5544149, including whether the deletion is complete and the new reason-phrase integration coverage is sufficient. Do not transfer conclusions from superseded heads.

@seonghobae

Copy link
Copy Markdown
Contributor Author

Fresh exact-head validation for 4fa541df70aa174e16b825e0f740457702750fa against protected main 5544149c: cargo fmt --all -- --check, git diff --check, session HTTP framing (1), malformed-header (7), framing security regression (6), session HTTP contract (3), PostgreSQL session HTTP (4), and cargo clippy --all-targets -- -D warnings passed. This is validation evidence, not approval.

@seonghobae

Copy link
Copy Markdown
Contributor Author

@opencode-agent Please review only exact head 4fa541df70aa174e16b825e0f740457702750fa against protected main 5544149c. The current head contains the single hardened framing boundary, overall read deadline, trailing-byte rejection, ASCII Content-Length validation, and expected peer-close test handling. Use only same-head checks and code.

coderabbitai[bot]

This comment was marked as resolved.

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Devin Review: No Issues Found

Devin Review analyzed this PR and found no bugs or issues to report.

Open in Devin Review

@seonghobae

Copy link
Copy Markdown
Contributor Author

Exact-head validation for c72cbb7fd1e1e517eaf416d04d43d8c77d0be43f (base 5544149ca5dc55d2bfc3402cc59c03c44830de5f): added only the missing digits-only usize parse-overflow assertion for declared_request_end; focused HTTP targets, cargo fmt --all -- --check, TEST_DATABASE_URL=postgresql://seonghobae@localhost/postgres cargo test -q --all-targets, cargo clippy --all-targets -- -D warnings, and cargo doc --no-deps all passed; local line coverage 11123/11123 (100%) and nightly branch coverage 1362/1362 (100%). No merge performed: PR remains OPEN, formal review is CHANGES_REQUESTED, and required remote checks are queued.

@seonghobae

Copy link
Copy Markdown
Contributor Author

@opencode-agent Please review only exact head c72cbb7fd1e1e517eaf416d04d43d8c77d0be43f against protected base 5544149ca5dc55d2bfc3402cc59c03c44830de5f. The change is a coverage-only test for the digits-only usize parse-overflow path in declared_request_end. Report findings against this exact head.

@seonghobae

Copy link
Copy Markdown
Contributor Author

Exact-head validation for d0b3e81adefe68ff80213e46f16007b743baaaf8 against protected base 5544149ca5dc55d2bfc3402cc59c03c44830de5f: added a shared incomplete_request_body_error() helper so the fail-closed peer-close guard is preserved without the Rust/LLVM coverage-map duplication caused by inline io::Error::new(...). Focused framing tests (4 + 6), cargo test -q --all-targets (all targets), cargo fmt --all -- --check, cargo clippy --all-targets -- -D warnings, cargo doc --no-deps, and exact full line coverage 11129/11129 passed locally. This is validation evidence, not approval; required remote checks and independent review must complete on this exact head.

@seonghobae

Copy link
Copy Markdown
Contributor Author

@opencode-agent Please review only exact head d0b3e81adefe68ff80213e46f16007b743baaaf8 against protected base 5544149ca5dc55d2bfc3402cc59c03c44830de5f. Re-check the shared EOF error helper, truncated declared-body regression, and same-head coverage evidence. Do not transfer conclusions from superseded heads.

@seonghobae

Copy link
Copy Markdown
Contributor Author

@opencode-agent Correction to the review basis: protected is now exact head (it descends from the PR metadata base via merged PR #258). Please review only current PR head against current protected main ; do not rely on the stale base value in earlier comments.

@seonghobae

Copy link
Copy Markdown
Contributor Author

@opencode-agent Corrected review basis: protected main is now exact head 503a4e6 (a descendant of the PR metadata base 5544149 via merged PR #258). Please review only current PR head d0b3e81 against protected main 503a4e6. Ignore the malformed preceding comment.

Preserve the #254 fail-closed HTTP/1.1 framing boundary and security regressions on top of current protected main. The #258 Rust toolchain-refresh paths are disjoint, so this reconciliation retains both change sets without force-pushing or changing session behavior beyond the existing PR delta.
@seonghobae

Copy link
Copy Markdown
Contributor Author

Verified current head a8f756a6748b0d5db833cc23e1b8419f407eb33f against protected main locally. The reviewed framing findings are covered in the current tree: one overall read deadline with remaining timeout per read, invalid-data on early EOF before declared Content-Length, and invalid-data on buffered trailing/pipelined bytes without Content-Length. Evidence: cargo fmt --all -- --check; TEST_DATABASE_URL=postgresql://seonghobae@localhost/postgres cargo test -q --all-targets (all targets passed); focused framing/security/malformed-header tests passed; cargo clippy --all-targets -- -D warnings; cargo doc --no-deps. Please review this exact head; do not treat older SHA findings as current-head approval.

@seonghobae

Copy link
Copy Markdown
Contributor Author

Exact-head follow-up for d2aa585efcfb41a710eeb6ac887828222aabe703:

  • Clarified the public module documentation for request framing, fail-closed behavior, and intermediaries in beginner-readable language. No framing logic changed.
  • The existing framing implementation already enforces one connection-wide deadline, early-EOF rejection, no-body trailing-byte rejection, and duplicate/invalid framing-header rejection.
  • Exact-head local evidence: session framing 6/6, security regression 4/4, malformed-header 4/4, fmt, clippy -D warnings, doc, and diff checks passed.

Please review current head d2aa585e.

Copy link
Copy Markdown
Contributor Author

@opencode-agent
@cwl-noema-review

Please review the unchanged exact head bd51db5694f9873c0ff29bd6f779fa10b0f969dd. The five repository-local exact-head workflows are green and all currently visible inline findings are resolved. Historical OpenCode REQUEST_CHANGES reviews are attached to predecessor heads and are not acceptance evidence for this head. This request is review-only; do not update or merge the branch.

@seonghobae
seonghobae dismissed stale reviews from opencode-agent[bot], opencode-agent[bot], and opencode-agent[bot] August 21, 2026 23:52

Superseded by later exact-head evidence. This review blocked head 2ba6556 solely because coverage evidence failed. Current head bd51db5 has completed-success Runtime CI including owned coverage plus Security, SAST, SPDX SBOM, and provenance; all current review threads are resolved.

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode cannot approve yet because required coverage evidence did not pass.

Review outcome

1. HIGH .github/workflows/opencode-review.yml:1 - Coverage evidence did not prove required test/docstring evidence

  • Problem: The required coverage-evidence job result was failure, so OpenCode cannot establish approval sufficiency for this head.

  • Root cause: Automated approval is only valid when the same-head coverage-evidence job proves supported repository test suites passed and configured docstring gates passed or were advisory, or reports not applicable because no supported source files or package manifests exist. Missing, failed, skipped, unavailable, or unsupported-tooling test evidence is a blocker.

  • Fix: Install or configure the repository test/docstring evidence tooling when source files or package manifests exist, rerun the current-head coverage-evidence job, and approve only after it reports success with required evidence or explicit no-source not-applicable evidence.

  • Regression test: Keep the approval branch checking needs.coverage-evidence.result == success before posting APPROVE, and publish REQUEST_CHANGES when coverage-evidence blocker states such as cancelled, skipped, failed, unsupported-tooling, or below-100 evidence are present.

  • Result: REQUEST_CHANGES

  • Reason: coverage-evidence result was failure, so required test/docstring evidence was not proven for current head f74c47809adbeec03b052dcd1fbe5778459ab852.

  • Head SHA: f74c47809adbeec03b052dcd1fbe5778459ab852

  • Workflow run: 32700229291

  • Workflow attempt: 1

Coverage evidence

Coverage Decision

  • Result: FAIL
  • Test evidence: not proven passing
  • Docstring evidence: not proven passing when configured
  • Failure count: 1

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Changed file (3 files)"]
  S1 --> I1["repository behavior"]
  I1 --> R1["Review risk: Changed file (3 files)"]
  R1 --> V1["required checks"]
  Evidence --> S2["Test (3 files)"]
  S2 --> I2["regression suite"]
  I2 --> R2["Review risk: Test (3 files)"]
  R2 --> V2["targeted test run"]
Loading

@seonghobae
seonghobae merged commit 2962d38 into main Aug 25, 2026
34 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant