Repository navigation
Fail closed on unavailable Windows startup evidence - #10238
lawrencecchen wants to merge 23 commits into
Conversation
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Bugbot is paused — on-demand spend limit reachedBugbot uses usage-based billing for this team and has hit its on-demand spend limit. A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue. |
Bugbot is paused — on-demand spend limit reachedBugbot uses usage-based billing for this team and has hit its on-demand spend limit. A team admin can raise the spend limit in the Cursor dashboard, or wait for the next billing cycle to continue. |
Stacked on #10131.
The trusted preflight currently reports Windows job, process, privilege, and handle observations that it does not collect. The red test requires unavailable observations to stay null. The follow-up commit will relay only the optional child job observation and leave unsupported signals unavailable, so existing validation rejects an unproven Windows claim.
Regression proof uses two commits: test first, implementation second. Hosted CI only; no local Rust/Cargo/Zig/Xcode tests.
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.Summary by cubic
Fails closed when Windows startup preflight evidence is unavailable and publishes an explicit skipped Windows claim. Previously, missing Windows signals implied success; now Windows-only unavailability exits 78 with a Windows-specific reason, sets
claim_status=unverifiedandclaim_reason, attests the account-process AppContainer probe and staging failures, and gates packaging, paired runs, and profile capture.Review notes
startup_benchmark_contract.py;verify-startup-benchmark.pyvalidates schema v8, rejects malformed/foreign fields, and classifies Windowsverifiedvsunverified. Links claims to attested inputs by checking bootstrap SHA-256 and approved imports plus Windows API set DLLs, and requires linked AppContainer feasibility evidence and the attested account-process probe.windows_grandchild_in_job;trueis required for verification,Noneexits 78 with a Windows reason (unverified), andfalsehard-fails. AppContainer feasibility unavailability exits 78; access denied or core failures hard-fail. The account-process probe and staging capability failures are attested before any skip.startup_benchmark_claim.py, and gates downstream onclaim_status/claim_reason.Required actions
claim_status; treat Windows exit 78 as unverified, not error.startup_benchmark_claim.pyto write the skipped claim with expected SHA-256s; include and link Windows AppContainer feasibility evidence and the attested account-process probe.Written for commit e488456. Summary will update on new commits.