fix(delivery): republish a stale record when a verified delivery lands on a current generation - #2636
Conversation
…s on a current generation Live-QA finding (v5.260723.6): genie install converged the codex plugin itself (normal non-deferred path), leaving installed N current with T — but publication was deferral-only, so the prior generation's delivery record survived the verified install and setup's Decision-9 gate refused with 'mismatch' while its recovery pointed back at the very commands that skip publishing in that state. - codex-delivery seam: CodexDeliveryFacts gains an optional existingRecord read-state; a 'current' classification now publishes ONLY when the caller supplies that state and it fails the core binding (absent/invalid/stale) — a matching record is never republished, and callers that omit the state keep the conservative no-publish contract - install: publication is no longer deferral-only; the converged path derives N from the snapshot registration and routes through the same shared gate - update: the delivery-flow publisher passes the record state for the same converged-host truth Both call sites sit immediately after a signature/attestation-verified tarball delivery and bind the physically scanned tree, so this is delivery-fact recording under Decision 10, not self-attestation; the same-version REPAIR path (no fresh artifact) is untouched.
|
Caution The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased. |
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 773b9a2af6
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| if (lease !== null) { | ||
| try { | ||
| publishDeferredInstallDeliveryFacts(codexDeferral.installedVersion, lease); | ||
| publishInstallDeliveryFacts(codexDeferral?.installedVersion ?? null, lease); |
There was a problem hiding this comment.
Require verified handoff before republishing installs
This widens delivery-record publication from deferred installs to every successful in-scope genie install. When an operator runs the exposed manual path (genie install --integrations codex) rather than the install.sh handoff, this process has not downloaded or attestation-verified a release; if the local $GENIE_HOME/plugins/genie tree is stale or tampered and the existing record is absent/mismatched, the new call writes a fresh delivery record and makes setup/doctor treat those local bytes as a verified delivery. Please gate this publication to a verified installer context, or route standalone current/absent repairs through the existing re-fetch/verify flow.
Useful? React with 👍 / 👎.
…s, IN_PROGRESS The H3 SessionStart line surfaced ledger drift: waves 1+2 shipped 2026-07-22 (PRs automagik-dev#2625/automagik-dev#2626/automagik-dev#2628/automagik-dev#2629, per-group SHIP reviews, validations reproduced) but their evidence and criteria were never recorded; status still read APPROVED with execution long underway. - status APPROVED -> IN_PROGRESS - 41 evidence-backed criteria ticked (5 -> 46/67): Groups A-D ACs + global criteria owned by merged groups; deliberately NOT ticked: the two live 'codex mcp get genie --json' operator proofs, Group F/G criteria, and all post-merge QA rows - appended the waves-1+2 evidence block, the seven live-QA fixes (automagik-dev#2631-automagik-dev#2634, automagik-dev#2636), Group E's actual merge commit (4be6917), and the open automagik-dev#2633-deferred follow-up (pre-A route-arm retirement) Adversarially verified pre-commit by the pm-ledger-verify workflow: 0 must-fix; its 4 advisory findings (defect count, untracked follow-up, unrecorded E merge) are incorporated above.
Live-QA finding from the v5.260723.6 dogfood
genie installrefreshed the codex plugin itself ("+ codex: plugin refreshed; 7 role agents installed"), thengenie setup --codexrefused:Root cause: install's delivery publication was deferral-only (pending N≠T). On the normal converged path install advances the plugin itself, so N ends current with T — and the shared seam publishes nothing for
current— leaving the prior generation's record on disk. Setup's Decision-9 gate then truthfully refusesmismatch, but its recovery names the very commands that skip publishing in exactly that state.Fix
codex-delivery.ts):CodexDeliveryFactsgains optionalexistingRecord;currentpublishes only when the caller supplies the on-disk record state and it fails the core binding (absent/invalid/stale). Matching records are never republished; callers omitting the state keep the conservative pre-E contract (back-compat pinned by tests).Decision-10 compliance: both call sites sit immediately after a signature/attestation-verified tarball delivery and bind the physically scanned tree — this is delivery-fact recording by update/install, not installed bytes attesting to themselves. The same-version repair path (no fresh artifact, full re-fetch+verify) is untouched.
Validation (self-run): genie-commands suites 568/0 (three new seam tests: current+matching never republishes, current+stale/absent publishes, current-without-state stays null); codex-stripped CI condition 285/0; typecheck + lint clean.