Conversation
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. 🧰 Additional context used📚 Code guidelines (2)No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: lidge-jun/opencodex/.coderabbit.yaml Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (6)
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 6 remain after this review. 📝 WalkthroughWalkthroughLaunch and restore now use bundle trust validation. The checks cover executable signatures, ownership, permissions, and ancestor directories. Restore can run without the experimental flag or a bundled app-server binary. ChangesChatGPT bundle trust
Priority: ➖ Normal Estimated code review effort: 3 (Moderate) | ~20 minutes Change: Bug fix Sequence Diagram(s)sequenceDiagram
participant handleChatgptCommand
participant untrustedChatgptBundleReason
participant ChatGPTProcess
participant ShimLauncher
handleChatgptCommand->>untrustedChatgptBundleReason: validate bundle and app executable
untrustedChatgptBundleReason-->>handleChatgptCommand: return trust result
handleChatgptCommand->>ChatGPTProcess: quit and open when trusted
ChatGPTProcess-->>handleChatgptCommand: return open result
handleChatgptCommand->>ShimLauncher: retain on failure or remove after successful open
Merge Risk: ⚪ Minimal · up to No actionable defect is established for this change. Native security validation remains incomplete, and the stated maintainer security-review hold still applies. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The change strengthens validation before quitting or relaunching ChatGPT while preserving recovery behavior. No introduced security regression was established, but native filesystem permissions and replacement behavior remain incompletely verified. Retained concerns Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 33.33% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 6 functions across 4 files. (2 skipped: 2 unsupported.)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
✅ Deterministic PR hygiene checks passed. |
) Apply signature and path ownership checks before either relaunch path can quit or execute a discovered app. Restore validates the app shell without requiring experimental opt-in or the app-server binary. Carries lidge-jun#6453 by @luvs01. Co-authored-by: luvs01 <27862058+luvs01@users.noreply.github.com>
Brings the branch level with dev (100 commits) and resolves four conflicts: - `src/cli/chatgpt-command.ts`: dev's carry of lidge-jun#6453 checks the discovered bundle's trust before either relaunch path. It now runs after the intercept listener probe and the shim's binary resolution, and before the restore watcher guard, so the intercept relaunch is validated too. An intercept-only launch reports "launch ChatGPT" rather than "launch the shim". - `src/chatgpt/app-server-shim/gate-rewrite.ts`: dev's carry of lidge-jun#6463 makes the same `used_percent` change; only the comment differed, and dev's wording is kept. - `structure/config.md` and the ChatGPT desktop guide: our `chatgptDesktop` fields alongside dev's `claudeCode.subagentModelForce` text and restore trust paragraphs. The command-child fixture from lidge-jun#6453 now stubs the intercept status and watcher modules, so its status and restore scenarios never probe this machine's listener, launchd agent, keychain or running proxy. A new scenario covers restore refusing while the watcher is loaded. The desktop-unblock layout entries share lines, which keeps `tests/fixtures/test-layout-expected.json` under the 2000-line ratchet as dev's packed entries already do.
Brings the branch level with dev (100 commits) and resolves four conflicts: - `src/cli/chatgpt-command.ts`: dev's bundle trust check before either relaunch path (0358e72, from lidge-jun#6453) now runs after the intercept listener probe and the shim's binary resolution, and before the restore watcher guard, so the intercept relaunch is validated too. An intercept-only launch reports "launch ChatGPT" rather than "launch the shim". - `src/chatgpt/app-server-shim/gate-rewrite.ts`: dev already has the same `used_percent` change (f5572a0, from lidge-jun#6463); only the comment differed, and dev's wording is kept. - `structure/config.md` and the ChatGPT desktop guide: our `chatgptDesktop` fields alongside dev's `claudeCode.subagentModelForce` text and restore trust paragraphs. The bundle-trust command-child fixture now stubs the intercept status and watcher modules, so its status and restore scenarios never probe this machine's listener, launchd agent, keychain or running proxy. A new scenario covers restore refusing while the watcher is loaded. The desktop-unblock layout entries share lines, which keeps `tests/fixtures/test-layout-expected.json` under the 2000-line ratchet as dev's packed entries already do.
|
Superseded by the integration in #6487, with reviewed follow-up fixes in #6490 and Windows validation repairs in #6494/#6495, all merged into Bundle trust validation before restore was carried. The recovery also makes the ancestor-boundary test fixture portable; it does not claim real installed-app trust/relaunch acceptance. Original carry commit: Closing this PR as superseded, not claiming that its original head was merged. Thank you for the contribution. |
Summary
Verification
bun test tests/clients/desktop-app-server-shim-launcher.test.ts— 18 pass, 6 fail. Five unsafe-bundle restore cases reached success; the legitimate control exposed missing signature checks.bun test tests/clients/desktop-app-server-shim-launcher.test.ts tests/clients/desktop-app-server-shim.test.ts— 51 pass, 0 fail. Covers unsafe restore rejection before quit/open, valid restore with the flag disabled and no app-server, failed-open preservation, no-install cleanup, status, and existing launch requirements.bun run typecheck,bun run structure:check,bun run privacy:scan,bun scripts/file-size-ratchet.ts, andgit diff HEAD --check— passed.bun test tests/test-layout.test.ts tests/test-layout-tooling.test.ts— 18 pass, 0 fail.ASTRO_TELEMETRY_DISABLED=1 XDG_CONFIG_HOME=../.tmp/security-macrestore/docs-config bun run buildfrom docs-site — passed: 561 pages and 77,818 internal links. The initial ordinary build failed because its telemetry config path was outside the writable workspace; the successful retry used an isolated local config directory and existing shared dependencies.Checklist
Exact-head review evidence
Cross-platform CI completed successfully for
50d9acd38133f8612a468397607c2469f81a940d. The documented focused local validation satisfies the repository's scoped-validation exception, and the branch is one commit behind currentdev, within its readiness tolerance. No open Codex/CodeRabbit review threads were present at attestation. The previous CodeRabbit Draft status was a review skip; substantive review is now requested. Review readiness does not establish actual signing, LaunchServices, ACL or volume-policy verification, and does not grant merge or security-closure approval.Summary by CodeRabbit