Skip to content

U2: Next.js 16.3.6 -> 16.3.8 (seven advisories, one high) with its qualification receipt and dated record - #587

Merged
seathatflowsinourveins merged 3 commits into
mainfrom
foundation/u2-nextjs-16.3.8-20261001
Oct 1, 2026
Merged

seathatflowsinourveins merged 3 commits into
mainfrom
foundation/u2-nextjs-16.3.8-20261001

Conversation

@seathatflowsinourveins

@seathatflowsinourveins seathatflowsinourveins commented Oct 1, 2026 •

Copy link
Copy Markdown
Owner

Scope

  • What this PR changes: program unit U2 for Next.js. The application-delivery recipe's lock and the stack pin move from 16.3.6 to 16.3.8, the version whose release notes list seven security advisories (one high: GHSA-cjq9-62q9-8jv4, server-side request forgery in Image Optimization). The derived records follow the pin, and a sanitized qualification receipt and a dated U2 record are added.
  • Base commit: 752714a82c92bcb254f7eab2ba8894d6d8c15b66
  • Lane: lane:shared (foundation content; manifests/stack.json and manifests/evidence.json are shared hot files, so the trading lane owner acknowledges)
  • Owned paths touched: blueprints/convergence-practice/application-delivery/ (package.json, pnpm-lock.yaml, README.md, history/recipe-revisions.json, two retained 16.3.6 files), evidence/receipts/nextjs-1638-qualification-20261001.json, docs/decisions/2026-10-01-u2-nextjs-16-3-8.md, catalogs/landscape/upstream-snapshot.json (the Next.js entry), blueprints/token-native-focus/saturation-audit.json (the Next.js row's version and pin), and, in the last commit, manifests/stack.json and manifests/evidence.json.

How it was qualified: the Codex catalog lane's builder, delegated by the foundation coordinator, ran the recipe's bounded checks in an owned worktree. The first frozen install, at 12:13Z, exited 1 with ERR_PNPM_MINIMUM_RELEASE_AGE_VIOLATION for the ten packages published on 2026-09-30. No exclusion or policy change was made; after the window the unchanged two-file patch passed the frozen install, peer check, typecheck and production build, each exit 0. The receipt keeps the failed attempt and the hashes of every output.

SOTA sources

Evidence-class table

Claim Evidence class Command / receipt
The recipe installs frozen, passes peers and typecheck and builds at 16.3.8 local_integration evidence/receipts/nextjs-1638-qualification-20261001.json (exit 0 for each; outputs hashed)
The first install inside pnpm's release-age window failed local_integration (failed, kept) the same receipt, failed_attempts
16.3.8 fixes the seven advisories source_review the v16.3.8 release notes, read 2026-10-01
The upstream snapshot entry is current native public API metadata four gh api calls on 2026-10-01, recorded in the entry's checks
make verify (PostgreSQL, API, browser) at 16.3.8 none: not run listed as a limit in the receipt and the record

Local commands run

$ python3 -m unittest discover -s blueprints/convergence-practice/application-delivery -p 'test_portability.py'   # Ran 6 tests, OK
$ python3 scripts/validate.py                                       # passed: 69 components, 8909 hashed files, 183 receipts
$ python3 scripts/build_ecosystem.py --check                        # passed; architecture_pin_drift lists nextjs (dated edition 16.3.6, stack 16.3.8), by design
$ python3 scripts/landscape.py --root .                             # rc 0
$ python3 -m unittest -q tests.test_stack_lifecycle tests.test_catalog_freshness_propose tests.test_ecosystem_manifest tests.test_osv_lockfile_coverage tests.test_component_matrix
Ran 266 tests, OK
$ git diff --check origin/main HEAD                                 # clean

A wider run of the 35 test modules that name the stack or the recipe, before the snapshot refresh, failed in three places: two were the snapshot and audit rows this pull request then moved, and tests.test_secret_path_guard.SecretPathGuardTests.test_host_profile_copy_is_verbatim fails on main as well on this host (it compares the host's own profile copy).

Manifest: files rows 8,906 to 8,909 (the two retained 16.3.6 files and the receipt), none lost; receipts 183 to 184 (the new receipt is indexed in receipts[] as native_cli_e2e and cited in the nextjs component's evidence_ids and the lifecycle audit's public receipts, as the #446 qualification receipts are; the Gate A owner's review found it hash-listed only at the first head, 680ab77); convergence records 26 unchanged.

Decision record

docs/decisions/2026-10-01-u2-nextjs-16-3-8.md: the move, its qualification, what did not run, the alternatives (a release-age exclusion, a hold, another framework) and the overturn conditions.

Host evidence

Not relevant: no file under evidence/hosts/ changes.

Checklist

  • No workflow or action changes.
  • No secrets are printed, logged or committed.
  • No new paid hosting, subscription or billing surface was introduced.
  • Peer-owned untracked files and worktrees were preserved.

🤖 Generated with Claude Code

@seathatflowsinourveins seathatflowsinourveins added the lane:shared Touches files owned by both lanes; needs both lanes' acknowledgement label Oct 1, 2026
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@seathatflowsinourveins

Copy link
Copy Markdown
Owner Author

Trading lane: manifest part acknowledged at 680ab775 (base 752714a8). I read it in code. manifests/evidence.json goes from 8,906 to 8,909 files: 3 added (the two retained 16.3.6 recipe files and evidence/receipts/nextjs-1638-qualification-20261001.json), 7 re-pinned, 0 dropped. No re-pinned or added row is a trading path. receipts (183) and convergence_records (26) are unchanged. In manifests/stack.json only the nextjs component changes, and none is removed. None of the 12 changed files is under blueprints/us-equities, catalogs/us-equities or catalogs/landscape/us-equities.

@socket-security

socket-security Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednpm/​next@​16.3.6 ⏵ 16.3.86110090 +19970

View full report

Scout and others added 3 commits October 1, 2026 12:39
… its qualification receipt and the dated U2 record

The v16.3.8 release notes list seven security advisories, the most severe GHSA-cjq9-62q9-8jv4 (high, SSRF in
Image Optimization). The qualified two-file patch changes next, @next/env and the eight @next/swc-* lock entries.
pnpm's release-age rule refused the first frozen install at 12:13Z; no exclusion was added, and after the window the
unchanged candidate passed the frozen install, peer check, typecheck and production build (exit 0 each). The 16.3.6
files are retained under history/, the receipt keeps the failed attempt, and make verify is not claimed.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…16.3.8 pin

The snapshot's Next.js entry is refreshed with its own method (gh api on the repository, the latest release and the
pin and tag commits; one call each, no retry), as #446 did for ccusage; the latest stable is v16.3.8, so the
selected version matches it. The lifecycle audit row carries the stack version, which its test compares.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…anifest rows (hot-file protocol, last commit)

manifests/stack.json: nextjs 16.3.6 -> 16.3.8 at tag commit b0fad0d4, upstream sources, the freshness note, and the
new receipt id in evidence_ids beside the two 2026-09-20 receipts, which qualify 16.3.5 only.
manifests/evidence.json: the receipt nextjs-1638-qualification-20261001 in receipts[] (kind native_cli_e2e, as the
#446 qualification receipts are); three new file rows (the two retained 16.3.6 files and the receipt) and the
re-registered recipe, history, snapshot, audit and stack files. Files 8,906 -> 8,909; receipts 183 -> 184;
convergence records unchanged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@seathatflowsinourveins
seathatflowsinourveins force-pushed the foundation/u2-nextjs-16.3.8-20261001 branch from 680ab77 to b47d7f2 Compare October 1, 2026 16:41
@seathatflowsinourveins

Copy link
Copy Markdown
Owner Author

Trading lane: re-acknowledged at b47d7f2f (base 752714a8), read in code. manifests/evidence.json still has 8,909 files (3 added, none dropped). receipts goes from 183 to 184 with one entry added (nextjs-1638-qualification-20261001) and none removed; convergence_records is unchanged. In manifests/stack.json only nextjs changes, and no trading path changes.

@seathatflowsinourveins
seathatflowsinourveins merged commit 798ac44 into main Oct 1, 2026
30 of 31 checks passed
@seathatflowsinourveins
seathatflowsinourveins deleted the foundation/u2-nextjs-16.3.8-20261001 branch October 1, 2026 17:24
seathatflowsinourveins pushed a commit that referenced this pull request Oct 3, 2026
…-16 cause, authority and review date

Round 3 of PR #635, answering the reviews of round 2:
- tests/test_frozen_macos_variant_no_use.py is now a tripwire for direct references. It matches the
  artifact directory's name (the parent of variant/) in every file git ls-files lists except the
  record classes (*.md, evidence/**, manifests/evidence.json, catalogs/**, blueprints/**/*.json), and
  scans configuration and scripts inside those classes too (package.json and other workspace
  manifests, .devcontainer/**, *.toml, *.yml, *.yaml, script suffixes, build files, shebangs,
  executable modes, symbolic links). Whole-file allowances are replaced by 31 pinned lines in 15
  files (sha256 of each stripped line, the module's own constant included); a new referencing line
  fails anywhere, and a pinned line that is no longer found fails too, so a broken scope rule cannot
  drop a pinned file. git ls-files failing is a failure, not a skip. OS metadata files are ignored
  in the variant directory, and an absent variant passes. Its docstring states the limit: a route
  that never spells the name (inventory loop, glob, fragments, Markdown recipe) is not caught.
- Mutation checks in a scratch clone: the reconstructed round-2 mutants, the five round-3 mutants and
  eight added checks fail; the four stated limits and the two allowed cases pass; the unmutated tree
  passes. The results are retained in the receipt's guard_mutation_checks.
- evidence/receipts/dependabot-alert-16-dismissal-20261003.json and the closure record's alert-16
  note: Dependabot alerts come from the dependency graph (manifests, lock files and submissions;
  GitHub Docs read 2026-10-03), so the alert is independent of the OSV exception's scope; the
  dismissal was made at the user's request of 2026-10-03 under section 8's not_used practice
  (alerts 7-15); it has no expiry and is rechecked when the frozen OSV exception (ignoreUntil
  2026-12-24) is renewed, changed or removed, or when the tripwire fails; the live recipe lock pins
  next 16.3.8 (the frozen config's 16.3.6 clause predates #587 and is left unedited). The branch is
  rebased onto main 652c15a (#620, after #639), and the receipt's checked_commit moves to it; the
  files the receipt cites are identical at e88d59e and 652c15a.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
seathatflowsinourveins added a commit that referenced this pull request Oct 6, 2026
)

### Scope

Fix the newly reviewed advisories that blocked every required OSV check: target only fsspec 2026.6.0/multidict 6.9.1 in the OpenHands runtime lock, Mako 1.4.2 in the application Python lock, and source-map-js 1.2.2 in its pnpm lock. Preserve all other package pins and the original captured artifact bytes.

The command center selected a dated source-backed exception for the frozen macOS input in its isolated config, and exclusion of both retired Lumibot lockchecks after the owner's confirmation. Each lock has native before/after evidence and its supported installation/qualification checks. No workflow or branch-protection setting changes.

- Base: `ecfa112764c664d35377dd66b8cfcb67e5a94d60` (fetch confirmed current main).
- Lane: `lane:foundation`.
- Owned scope: three production locks, SDK pins/research/evidence, qualification and ruling receipts, bounded OSV configuration/inventory, existing binding/no-use guards and closure record. Evidence registry committed last.

## SOTA sources

- [fsspec advisory GHSA-27vj-qcqg-25rc](GHSA-27vj-qcqg-25rc), [official 2026.6.0 release metadata](https://pypi.org/pypi/fsspec/2026.6.0/json), [maintainer tag](https://github.com/fsspec/filesystem_spec/tree/2026.6.0).
- [multidict advisory GHSA-54p9-h82j-f925](GHSA-54p9-h82j-f925), [official 6.9.1 release](https://github.com/aio-libs/multidict/releases/tag/v6.9.1), [PyPI metadata](https://pypi.org/pypi/multidict/6.9.1/json).
- [Mako advisory GHSA-5639-2j2p-m4mx](GHSA-5639-2j2p-m4mx), [maintainer release](https://github.com/sqlalchemy/mako/releases/tag/rel_1_4_2), [official metadata](https://pypi.org/pypi/Mako/1.4.2/json).
- [source-map-js advisory GHSA-68fv-2mgg-jv7q](GHSA-68fv-2mgg-jv7q), [published 1.2.2 metadata](https://registry.npmjs.org/source-map-js/1.2.2), [maintainer fix PR79](7rulnik/source-map-js#79).
- Dependent ranges: [Hugging Face Hub0.35.3](https://pypi.org/pypi/huggingface-hub/0.35.3/json), [aiohttp3.14.3](https://pypi.org/pypi/aiohttp/3.14.3/json), [yarl1.22.0](https://pypi.org/pypi/yarl/1.22.0/json), [Alembic1.20.0](https://pypi.org/pypi/alembic/1.20.0/json), [PostCSS8.5.23](https://registry.npmjs.org/postcss/8.5.23). Complete declared-parent checks include optional/null metadata handling; limitations remain explicit in receipts.
- [#562 at74cc5468](#562): original builder/relock/hash/install/scan/guard pattern. Installed [uv0.12.22](https://github.com/astral-sh/uv/releases/tag/0.12.22) reproduces the accepted baseline byte for byte; #562's0.12.17 remains historical.
- [#587 at798ac445](#587), [#252 atc96c2555](#252): bounded frontend qualification. [pnpm12.4.2 update parser](https://github.com/pnpm/pnpm/blob/9502f3c457717dae3a4ddbf4315a8c4aee16fdb4/pnpm/crates/cli/src/cli_args/update.rs) and [supported update docs](https://pnpm.io/cli/update): selective bare-name transitive update, no-save/lockfile-only; obsolete explicit-version/Infinity forms avoided.
- Frozen config precedent [8fc8611](8fc8611) and the maintained closure at `docs/decisions/2026-09-22-github-automation-closure.md`. Indexed source offsets/reconstruction inspected at [source-map-js1.2.1](https://github.com/7rulnik/source-map-js/blob/428d49f6b1e1614f082b7706fa879a3d9c64f728/lib/source-map-consumer.js#L944). Dedicated input/digest/expiry guards retained.
- Trial [#336 at20b52a5b](#336), existing captured XNYS exclusion precedent, and command-center ruling `task-ns2604-coop-20261006T003954Z`. The verified owner confirmation is a **report** row: `report-native-agent-stack-5f-20261006T0045Z-osv`, from `native-agent-stack-5f`, at `2026-10-06T00:41:23Z`, replying to `task-native-agent-stack-5f-20261006T004011Z`. Sanitized evidence: `evidence/receipts/osv-captured-lumibot-lockchecks-20261005.json`. No trial replay or new host-process census is claimed.

### Evidence-class table

| Claim | Class | Actual result |
| --- | --- | --- |
| Published dependent ranges permit the fixes | source_review | Complete pinned metadata review; no caps/errors; exact parents linked above |
| Targeted locks preserve other pins | local_integration | SDK byte-identical control; only two package blocks move. Mako only package block, native lock revision3→5 recorded. pnpm manager/importers unchanged; only source-map-js move |
| Release identity and supported artifact hashes match | local_integration | Native hash checks0: fsspec2, multidict14, Mako2; universal wheels/sdist included |
| Supported isolated/native qualification succeeds | local_integration | SDK178-package check/imports0; backend28-package check/import/render0; frontend frozen install/peers/typecheck/build0 |
| Both required scan partitions pass locally | local_integration | Before:60ordinary/1frozen,5+1 unignored findings. After:58ordinary/1frozen, actual native exits0/0, zero unignored findings |
| Binding/coverage/no-use guards remain effective | local_integration / synthetic |70 touched tests0; clean control0; all deliberate negative controls1 as expected |
| Registry integrity | local_integration | validate.py0;69components/4profiles/212receipts/10309hashes; integrity only |
| Hosted, image, provider and full API/browser acceptance | unknown | No claim; command-center exact-head cross-family read remains pending |

### Local commands run

All heavy phases used nice19; scratch/cache and installs were isolated. Exact supported commands and sanitized actual returned output/hashes are retained in the three relock prefixes and linked receipts.

```
#562-pattern paired native uv control/targeted lock/check/export:0
native release hash checks:0
hashed SDK install / uv pip check / exact imports:0
targeted Mako lock/check; frozen/no-build sync; pip check; imports/render:0
pnpm12.4.2 update source-map-js --no-save --lockfile-only --ignore-scripts:0
pnpm install --frozen-lockfile --ignore-scripts; peers check; typecheck; build:0
python -m unittest tests.test_openhands_lock_binding tests.test_osv_lockfile_coverage tests.test_frozen_macos_variant_no_use
70 tests; latest final data-pin run6.936s; exit0
OSV2.6.0 ordinary scan:0; frozen scan:0
python3 scripts/validate.py:0,10309hashes
component_matrix --write:0,32rows/zero flips
new_host_grand_list --write:0,32layers/66winners
git diff --check and git diff --cached --check:0
```

### Failed conditions

The initial root-added UV_NO_CONFIG1 discarded the resolver's Linux workspace settings; the next copied formatter inserted two plus signs. Native lock/check/export succeeded in both, while the relock byte-comparison script failed. Neither candidate was adopted; both are disclosed separately. Test preflight rejected inside-checkout TMPDIR before execution; existing external lane cache was used. Intermediate stale receipt/unreviewed metadata-line guards failed before being corrected. Publication caught one private interpreter path in a negative-control trace; it was sanitized. Terminal progress whitespace was normalized and its capture hash rebound. No failure is promoted to a passing upstream test.

### Decision record

`docs/decisions/2026-09-22-github-automation-closure.md`, "Four production relocks and preserved receipt inputs (2026-10-06)"; SDK research section and qualification/ruling receipts record alternatives, source/replay limits and overturn conditions. The macOS exception expires2026-12-24; its `.frozen` rename is a separate follow-up. Future use of captured trial dependencies requires a separately maintained/scanned qualification environment.

### Host evidence

No evidence/hosts or platform-status flip. The native runtime imports/builds are local integration; source reviews, synthetic controls and hosted acceptance remain separate. Exact-head command-center review is requested.

### Checklist

- [x] No workflow/action permission or branch-protection change.
- [x] No credential value or authentication store read/printed/copied; no new required secret.
- [x] No paid hosting, provider/model runtime call, deployment or restart.
- [x] Peer-owned worktrees preserved; three captured locks remain byte-identical.
- [x] Registry committed last; one lane:foundation label.
- [x] Ordinary AND frozen native scans and touched tests passed before ready.
- [ ] Command-center exact-head cross-family read and 5f landing; lane never merges.

## Dated input-binding repair (2026-10-06)

The command-center exact-head read of67c6594d2 found two omitted downstream gates: both convergence records still resolved their original UV digest through the newly relocked live file, and the recipe ledger's PNPM current digest was stale. This amendment preserves trial evidence instead of attributing new dependencies to the original runs.

- Retain ecfa112 UV/PNPM bytes and the two pre-amendment experiment snapshots byte-for-byte.
- Change only each canonical record's UV input path; keep frozen digests, commands, observations, outputs and usage. Both records remain declared.
- Append dated recipe supersession/current mappings and ordered path relocations; protect original/prior/superseded bytes and all non-path record bytes with the portability assertions.
- Source: [#252 path-only relocation](https://github.com/seathatflowsinourveins/native-agent-stack/blob/c96c2555c2d84683d9e519623354c814aeb6a584/blueprints/convergence-practice/application-delivery/history/recipe-revisions.json#L121) and [#587 supersession](https://github.com/seathatflowsinourveins/native-agent-stack/blob/798ac445307e2cd8eba6e74d7722ac0e16da02c7/blueprints/convergence-practice/application-delivery/history/recipe-revisions.json#L99).
- Dated decision/source receipt: `docs/decisions/2026-10-06-application-input-binding-amendment.md`, `evidence/receipts/pr765-bindings-amendment-20261006.json`.

Before repair, all-recorded convergence exited1 (2invalid/32) and native-maintenance exited1 (29cases/one PNPM mismatch). Repaired focused checks: native-maintenance29passed; convergence/OSVcoverage/frozenMAC102passed. After main-registry refresh and full own-file re-registration, local validate0/10315hashes and all-recorded convergence0/32valid. Full local suite ran under A22's specific copied-fixture `install.sh --list` exception and exited1:10,343tests/2217.568s,18failures/18errors/905skips. Installer apply paths remain banned. Raw output is retained privately; known systemd parser (#767), missing calendar/mutation imports, PATH fixtures, token-canary fixtures and installed Windows Terminal type drift are recorded separately, never presented as a pass.

Old reviewed head's hosted baseline was6/7 required contexts: validate failed, six others passed. Required acceptance is measured at the new pushed head; no workflow rerun loop or old local check is promoted into that acceptance. No production pin, recorded trial output, raw receipt, frozen macOS lock, captured trading lock or scanner exclusion changed in this repair.
seathatflowsinourveins added a commit that referenced this pull request Oct 6, 2026
### Scope

Patch the live application recipe's sharp 0.35.4 dependency to the first fixed release 0.35.5 for GHSA-wq5f-xc86-pv6w. Its required Sharp/@img family moves with it; the captured macOS lock stays byte-identical under one file-scoped exception expiring 2026-12-24.

- Base commit: `0d5e6506434fab598dee861c749a22e628beb75a`.
- Lane: `lane:foundation`.
- Owned paths: live application pnpm lock, retained prior lock and recipe history, bounded qualification outputs, dedicated frozen-macOS exception, its coverage test, dated decision, qualification receipt and evidence registry.
- `.github/osv-scanner.toml` and `.github/osv-scanner-lockfiles.json` are byte-identical to the base. The frozen variant retains SHA-256 `f1c707b8295e85bd396e49b990de92dc82bc0d58eca1e4e4bef31262d9898cd2`.

## SOTA sources

- [Sharp maintainer advisory GHSA-wq5f-xc86-pv6w](GHSA-wq5f-xc86-pv6w), published 2026-10-06T13:43:57Z: affected `<0.35.5`, first patched `0.35.5`, librsvg CVE-2026-96889.
- [Sharp v0.35.5 release](https://github.com/lovell/sharp/releases/tag/v0.35.5), published 2026-09-27T13:44:22Z, `lovell/sharp@51a990faa26ade5586a4934ac9673c98d8893326`; [sharp-libvips v1.3.4](https://github.com/lovell/sharp-libvips/releases/tag/v1.3.4) supplies librsvg 2.63.2.
- [pnpm supported targeted update](https://pnpm.io/cli/update) and [frozen-lockfile installation](https://pnpm.io/cli/install), read 2026-10-06; installed pinned pnpm 12.4.2 help/error rejects a versioned selector on an indirect dependency. Published latest and the resulting resolved version were independently checked as exactly 0.35.5; no override or package.json edit was needed.
- [Next 16.3.8 published metadata](https://registry.npmjs.org/next/16.3.8): its `optionalDependencies.sharp` range `^0.35.4` permits 0.35.5. This is the lock's only direct dependent on sharp. All 27 replacement resolution integrity values match published npm metadata; 67 unrelated package entries, importers and the pnpm manager document remain unchanged.
- [Sharp source at the prior pin](https://github.com/lovell/sharp/blob/7f1a0a22cc285fe180766f4935d50b55af6e8432/src/common.cc#L323), `src/common.cc:323,506,596`, and `src/pipeline.cc:48`: SVG file/buffer input can reach librsvg. Exception justification rests on the retained variant having no supported installer/build/server/replay consumer found in scoped source review, with removal before any manual replay or new consuming route; the macOS label is not itself a reachability exemption.
- Repository conventions: `native-agent-stack@0d5e650:blueprints/convergence-practice/application-delivery/Makefile:3-5,27-32`, `README.md:170-180`; [#765](#765), [#587](#587) and [#252](#252) retain prior bytes/qualifications and append supersessions. Original full-stack receipts and canonical experiment records remain untouched.

### Evidence-class table

| Claim | Evidence class | Command / receipt |
| --- | --- | --- |
| First patched release, dependent range and SVG reachability | source_review | Maintainer advisory/release, pinned source and published npm metadata above |
| Exact frozen install, peers, typecheck, production build, loaded sharp/librsvg versions | local_integration | `relock-2026-10-06-sharp.*.txt`; `evidence/receipts/sharp-0355-qualification-20261006.json` |
| Frozen byte identity, retained old live lock and bounded family-only changes | local_integration | Hash/source comparisons and recipe revision ledger; 27 replacements / 67 unrelated unchanged |
| Repository integrity and declared-record consistency | local_integration | Validator, 32 convergence records and 96 touched tests pass; these do not establish upstream or live application acceptance |
| Advisory present for sharp 0.35.4 and absent for 0.35.5 | source_review | Supported OSV version-query API; this is not a native scanner or full-inventory scan |
| Complete application/API/browser qualification | local_integration, failed | `make verify` exits 2 on 12 dedicated-PostgreSQL setup errors; browser attempt exits 1 on occupied configured port 18080, with no browser case executed |
| Required hosted OSV and other CI checks | pending | Must be observed at this PR's head; no local scanner executable was found in the inspected locations |

### Local commands run

Frontend commands below ran in the live application directory, using the recipe's pinned pnpm 12.4.2 through Corepack, task-private cache/store/state/temp paths and a public-registry-only npmrc; heavy commands ran one at a time at nice 19. `relock-2026-10-06-sharp.sh.txt` records the supported replay pattern. Worktree/state path prefixes are sanitized in public outputs.

```text
corepack pnpm update sharp --no-save --lockfile-only --ignore-scripts
exit 0; exact resolved sharp 0.35.5 checked
corepack pnpm install --frozen-lockfile --ignore-scripts
exit 0
corepack pnpm peers check
exit 0
corepack pnpm typecheck
exit 0
corepack pnpm build
exit 0
node -e 'const r=require("module").createRequire(require.resolve("next/package.json"));const s=r("sharp");console.log(JSON.stringify({sharp:s.versions.sharp,vips:s.versions.vips,rsvg:s.versions.rsvg}));if(s.versions.sharp!=="0.35.5"||s.versions.rsvg!=="2.63.2")process.exit(1)'
exit 0; sharp 0.35.5, vips 8.18.7, rsvg 2.63.2
nice -n 19 python3 scripts/validate.py
exit 0; 69 components, 4 profiles, 214 receipts, 10,345 hashed files
nice -n 19 python3 scripts/validate_convergence.py --all-recorded --json
exit 0; all 32 records valid
nice -n 19 python3 -m unittest tests.test_osv_lockfile_coverage tests.test_frozen_macos_variant_no_use tests.test_native_maintenance
exit 0; 96 tests, repeated after the new files were staged
git diff --check
exit 0
git diff --cached --check
exit 0 after explicit output whitespace sanitization
```

### Failed attempts and acceptance limits

- `pnpm update sharp@0.35.5 --no-save --lockfile-only --ignore-scripts` exits 1 with `ERR_PNPM_UPDATE_VERSION_ON_INDIRECT_DEP`, before mutation. The supported unversioned indirect update resolves exactly the independently verified first patch; no override is added.
- A single-document PyYAML read exits 1 because pnpm 12 stores two YAML documents; upstream `safe_load_all` corrects the comparison.
- First `make verify` exits 2 because pnpm is not on PATH. Supported Corepack enable creates only task-private shims. The second unchanged run passes schema/type/build checks on supported Python 3.13.16, then exits 2 on 12 PostgreSQL connection-timeout setup errors. The full actual failed log is retained privately and its decisive counts/cause in the public receipt. No PostgreSQL build, container/image pull or global installer was introduced.
- Separate unchanged `pnpm test:e2e` exits 1 because port 18080 is occupied and Playwright's recipe refuses reuse. No other owner's service was stopped and no test was relaxed. Full-stack acceptance remains unfinished.
- Initial staged diff checking found three trailing build-progress spaces. They were trimmed with that sanitization explicitly recorded, their hashes re-registered and the check repeated. Actual private output remains retained.
- Native full-inventory OSV execution and unchanged upstream tests are unclaimed. The database's zero finding for the fixed version does not replace the required hosted scanner verdict.

### Decision record

`docs/decisions/2026-10-06-sharp-live-relock-frozen-variant.md` records the targeted patch, rejected broad-ignore/historical-rewrite alternatives and evidence boundaries. Remove or re-review the frozen exception before replay, a new consumer, changed bytes or 2026-12-24. Registry is committed last. Independent bounded source/scope critic accepted this separation; co-op GPT micro-check and command-center exact-head ACK are requested. PR stays draft for that read; 5f owns landing.

### Host evidence

No `evidence/hosts/` change or platform-status claim.

- [ ] Host-receipt validation: not applicable.
- [ ] Command-center exact-head review requested; no platform status flip.

### Checklist

- [x] No workflow/action change; existing pinned actions and permissions stay untouched.
- [x] No secrets are printed, logged or committed; no new required secret.
- [x] No paid hosting or billing surface.
- [x] Peer-owned paths, services and worktrees preserved.
- [x] Frozen evidence remains byte-identical; registry last; no merge or settings change.

### Review follow-up — 2026-10-06

The co-op relays CC item `task-ns2604-coop-20261006T170124Z`, ruling 2: accept the disclosed browser gap for this urgent security landing conditional on a fresh frozen install/frontend build and restoration of the unrelated Mako JSON escape spelling. Both fresh frontend commands passed. `make postgres-init` exits 2 (inner 127) because the recipe's `.runtime/postgresql/18.6/bin/initdb` is missing. The recipe's `postgres-install` source-build target was not run under the upstream-never-rebuild and park rules. Playwright fixes both service and base URLs to port 18080, held by the local alert service; the service is untouched. No new browser cases ran.

Source: `native-agent-stack@4f32d59:blueprints/convergence-practice/application-delivery/Makefile:3-5,27-32,34-58` and `playwright.config.ts:8-16`; original Mako row at base `0d5e6506`. Full sanitized argv, return codes, actual outputs and classes are in `evidence/receipts/sharp-review-followup-20261006.json` and `relock-2026-10-06-sharp.review-*.txt`. Actual returned output remains privately durable; public progress whitespace/EOF normalization is explicit. The original qualification receipt and production/frozen locks stay byte-identical to the reviewed head.

```text
pnpm 12.4.2 install --frozen-lockfile (task-private cache/store/state/public-registry config)
exit 0; lock current, resolution skipped, 26ms
NEXT_TELEMETRY_DISABLED=1 pnpm build
exit 0; Next 16.3.8 production build
make postgres-init
exit 2; missing .runtime/postgresql/18.6/bin/initdb, inner 127
nice -n 19 python3 -m unittest tests.test_osv_lockfile_coverage tests.test_frozen_macos_variant_no_use tests.test_native_maintenance
exit 0; 96 tests, 8.999s
nice -n 19 python3 scripts/validate.py
exit 0; 69 components, 4 profiles, 214 receipts, 10,349 hashed files
```

Both original literal Mako `\u2192` spellings now exactly match the base row; parsed values are unchanged. Dated unfinished follow-up after the tools window: qualify the dedicated test DB through an upstream-supported release path and run the unchanged browser recipe in an isolated network namespace if no supported port override exists. Frontend build is not a browser/image-response or exploit test. Independent bounded source critic accepts the repair and separation. New-head co-op micro-check/CC ACK and hosted checks still required; registry is committed last. No broad ignore, alert-service takeover, source build, host configuration or merge.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

lane:shared Touches files owned by both lanes; needs both lanes' acknowledgement

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant