Skip to content

fix(delivery): republish a stale record when a verified delivery lands on a current generation - #2636

Merged
namastex888 merged 1 commit into
devfrom
wish/dogfood-E-install-record
Jul 23, 2026
Merged

namastex888 merged 1 commit into
devfrom
wish/dogfood-E-install-record

Conversation

@namastex888

Copy link
Copy Markdown
Contributor

Live-QA finding from the v5.260723.6 dogfood

genie install refreshed the codex plugin itself ("+ codex: plugin refreshed; 7 role agents installed"), then genie setup --codex refused:

✖ delivery record is mismatch; update or install must publish a matching authenticated delivery record before activation

Root cause: install's delivery publication was deferral-only (pending N≠T). On the normal converged path install advances the plugin itself, so N ends current with T — and the shared seam publishes nothing for current — leaving the prior generation's record on disk. Setup's Decision-9 gate then truthfully refuses mismatch, but its recovery names the very commands that skip publishing in exactly that state.

Fix

  • Seam (codex-delivery.ts): CodexDeliveryFacts gains optional existingRecord; current publishes only when the caller supplies the on-disk record state and it fails the core binding (absent/invalid/stale). Matching records are never republished; callers omitting the state keep the conservative pre-E contract (back-compat pinned by tests).
  • Install: publication runs on both paths (deferred N from the deferral, converged N from the snapshot registration), always through the one shared gate.
  • Update: the delivery-flow publisher passes the record state for the same converged-host truth.

Decision-10 compliance: both call sites sit immediately after a signature/attestation-verified tarball delivery and bind the physically scanned tree — this is delivery-fact recording by update/install, not installed bytes attesting to themselves. The same-version repair path (no fresh artifact, full re-fetch+verify) is untouched.

Validation (self-run): genie-commands suites 568/0 (three new seam tests: current+matching never republishes, current+stale/absent publishes, current-without-state stays null); codex-stripped CI condition 285/0; typecheck + lint clean.

…s on a current generation

Live-QA finding (v5.260723.6): genie install converged the codex plugin
itself (normal non-deferred path), leaving installed N current with T — but
publication was deferral-only, so the prior generation's delivery record
survived the verified install and setup's Decision-9 gate refused with
'mismatch' while its recovery pointed back at the very commands that skip
publishing in that state.

- codex-delivery seam: CodexDeliveryFacts gains an optional existingRecord
  read-state; a 'current' classification now publishes ONLY when the caller
  supplies that state and it fails the core binding (absent/invalid/stale) —
  a matching record is never republished, and callers that omit the state
  keep the conservative no-publish contract
- install: publication is no longer deferral-only; the converged path derives
  N from the snapshot registration and routes through the same shared gate
- update: the delivery-flow publisher passes the record state for the same
  converged-host truth

Both call sites sit immediately after a signature/attestation-verified
tarball delivery and bind the physically scanned tree, so this is
delivery-fact recording under Decision 10, not self-attestation; the
same-version REPAIR path (no fresh artifact) is untouched.
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Caution

The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased.

@coderabbitai

coderabbitai Bot commented Jul 23, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: cfd06219-a9a5-40d9-bd50-b260f82955e5

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch wish/dogfood-E-install-record

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 773b9a2af6

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +200 to +202
if (lease !== null) {
try {
publishDeferredInstallDeliveryFacts(codexDeferral.installedVersion, lease);
publishInstallDeliveryFacts(codexDeferral?.installedVersion ?? null, lease);

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Require verified handoff before republishing installs

This widens delivery-record publication from deferred installs to every successful in-scope genie install. When an operator runs the exposed manual path (genie install --integrations codex) rather than the install.sh handoff, this process has not downloaded or attestation-verified a release; if the local $GENIE_HOME/plugins/genie tree is stale or tampered and the existing record is absent/mismatched, the new call writes a fresh delivery record and makes setup/doctor treat those local bytes as a verified delivery. Please gate this publication to a verified installer context, or route standalone current/absent repairs through the existing re-fetch/verify flow.

Useful? React with 👍 / 👎.

@namastex888
namastex888 merged commit 121fb46 into dev Jul 23, 2026
16 checks passed
lirazsiri pushed a commit to lirazsiri/genie that referenced this pull request Jul 28, 2026
…s, IN_PROGRESS

The H3 SessionStart line surfaced ledger drift: waves 1+2 shipped 2026-07-22
(PRs automagik-dev#2625/automagik-dev#2626/automagik-dev#2628/automagik-dev#2629, per-group SHIP reviews, validations reproduced)
but their evidence and criteria were never recorded; status still read
APPROVED with execution long underway.

- status APPROVED -> IN_PROGRESS
- 41 evidence-backed criteria ticked (5 -> 46/67): Groups A-D ACs + global
  criteria owned by merged groups; deliberately NOT ticked: the two live
  'codex mcp get genie --json' operator proofs, Group F/G criteria, and all
  post-merge QA rows
- appended the waves-1+2 evidence block, the seven live-QA fixes
  (automagik-dev#2631-automagik-dev#2634, automagik-dev#2636), Group E's actual merge commit (4be6917), and the
  open automagik-dev#2633-deferred follow-up (pre-A route-arm retirement)

Adversarially verified pre-commit by the pm-ledger-verify workflow: 0
must-fix; its 4 advisory findings (defect count, untracked follow-up,
unrecorded E merge) are incorporated above.
@automagik-genie
automagik-genie deleted the wish/dogfood-E-install-record branch September 25, 2026 04:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant