Conversation
Contributor
Author
|
Status refresh, verified live on 2026-08-12 at 17:07 UTC.
Bounded purpose of this PR: anchor Codex hook executables to the trusted parent or secondmate root while preserving each worker's canonical worktree for scope classification, so a worker-controlled worktree cannot retarget a trusted hook payload. Regression coverage accompanies payload substitution, linked-worktree exemptions, and Codex spawn bindings. Posting this only so the current state is on the record; no action is requested here. |
Contributor
Author
|
Closing this — main now launches Codex crewmates and scouts with the hook layer disabled (#4689), so worker worktrees can no longer supply hook payloads. Thanks! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Intent
Publish the actual PR 1537B Route B branch, not the stale recorded branch. Preserve the trusted Codex hook executable-root boundary while rebasing it onto current upstream main, carrying the documentation and regression coverage needed to keep worker-controlled worktrees from retargeting trusted hook payloads. Gate the exact rebased commit locally, push only through the configured fork path, open exactly one pull request against kunchenguid/firstmate main, and do not merge, self-approve, force-push, or bypass any ask-user decision.
What Changed
Risk Assessment
✅ Low: The rebased change consistently separates trusted hook payload resolution from worker worktree scope, with matching regression coverage and no source-verifiable defect found.
Testing
Targeted CLI-only validation exercised substituted worktree payloads, untrusted hook CWD, CD policy ownership, and generated Codex launch bindings; all completed successfully with transcripts captured. No visual evidence applies because this change exposes no rendered UI. Live Codex trust-dialog re-prompt behavior is NOT_VERIFIABLE in the offline fixture.
Evidence: Trusted-hook end-to-end transcript
Legacy worker payload executed; anchored hook refused worker and untrusted-cwd payloads while executing trusted payload. Live Codex trust-dialog behavior remains NOT_VERIFIABLE.Evidence: CD-hook boundary transcript
Codex CD hook exercised trusted executable code versus worker-controlled runtime scope.Evidence: Codex launch-root transcript
Captured fake-tmux launch construction, including trusted parent root for crewmates and secondmate root binding.Pipeline
Updates from git push no-mistakes
✅ **intent** - passed
✅ No issues found.
docs/turnend-guard.md- merge conflict rebasing onto refs/remotes/no-mistakes-push/fm/c0806n-fm-1537b-route-b✅ **Review** - passed
✅ No issues found.
✅ **Test** - passed
✅ No issues found.
env PATH='/Users/admin/.hermes/node/bin:/opt/homebrew/bin:/usr/bin:/bin:/usr/sbin:/sbin' bash tests/fm-codex-hook-integrity.test.shenv PATH='/Users/admin/.hermes/node/bin:/opt/homebrew/bin:/usr/bin:/bin:/usr/sbin:/sbin' bash tests/fm-cd-pretool-check.test.sh(ShellCheck intentionally unavailable, so its optional lint check skipped)bash tests/fm-spawn-dispatch-profile.test.shgit diff --check b5d430d6fdcd961ce9b681bf196f365c1825c284 7d2c34a1040b729c5a7b22be491f2d2c4e3da27c✅ **Document** - passed
✅ No issues found.
✅ **Lint** - passed
✅ No issues found.
✅ **Push** - passed
✅ No issues found.