Skip to content

adoption: qualify pinned Git hook scanner on 2604 - #767

Closed
seathatflowsinourveins wants to merge 6 commits into
mainfrom
codex/ns2604-p1-git-20261006
Closed

seathatflowsinourveins wants to merge 6 commits into
mainfrom
codex/ns2604-p1-git-20261006

Conversation

@seathatflowsinourveins

@seathatflowsinourveins seathatflowsinourveins commented Oct 6, 2026 •

Copy link
Copy Markdown
Owner

Scope

Prepare the approved Phase 1 Git hook recipe and qualify Gitleaks 8.30.1 through mise's aqua backend in an isolated installation and a real scratch clone. Preserve the tracked hook, rules and production guard. Read named systemd properties in the guard test instead of assuming output order.

The review repair corrects the scanner's two currency deadlines and copies the verified native binary into the guard's target, so pruning the mise installation cannot break commits. It also verifies scanner prerequisites before enabling hooks in all linked worktrees.

  • Base commit: ecfa112764c664d35377dd66b8cfcb67e5a94d60
  • Lane: lane:foundation
  • Owned paths: adoption/git-hook-acceptance.md, the dated decision, evidence/artifacts/p1-git-hook-20261006/, its receipt, tests/test_adoption_guarded_runners.py, and the evidence registry last.
  • A21 assigns the central installer bundle to P1-CLI. This PR supplies its bounded prerequisite and leaves that bundle to its owner.

SOTA sources

  • Gitleaks v8.30.1, gitleaks/gitleaks@83d9cd684c87d95d656c1458ef04895a7f1cbd8e:config/config.go:19-20,config/gitleaks.toml,cmd/root.go:76.
  • Betterleaks v1.9.0, betterleaks/betterleaks@81aff7a638638aae3a659845d089043e1d8fe9ac:config/config.go:22-23,config/betterleaks.toml,cmd/root.go:82. Findings default to exit 1 in both, but 222 versus 463 embedded rules and different configuration bytes fail the required equivalence condition.
  • mise aqua, pinned backend, isolated directories, and pruning semantics, mise 2026.10.1.
  • Gitleaks master commit, dated 2026-07-22. The separate 90-day commit deadline is 2026-10-20. The release API dates v8.30.1 to 2026-03-21; its 180-day release line lapsed on 2026-09-17. These native GETs correct this PR's original mistaken comparison; no current-release claim is made.
  • systemd v259.5 property iteration/filter and named output.
  • Git hooks and git-config, read 2026-10-06. Git aborts commits for any nonzero pre-commit result; a positive native findings line distinguishes detection.
  • native-agent-stack@ecfa112764c664d35377dd66b8cfcb67e5a94d60:scripts/git-hooks/pre-commit:7-12,adoption/tools/gitleaks-guarded:5,adoption/tools/ecosystem-bounded-run:133,docs/secret-storage.md:353,tests/test_pre_commit_gate.py:58,docs/decisions/2026-10-04-repository-quality-rule.md:19.

Evidence-class table

Claim Evidence class Command / receipt
Scanner defaults differ; native backend and pruning behavior are supported source_review Pinned native GETs in evidence/receipts/p1-git-hook-acceptance-20261006.json
Isolated installation and guarded scratch-clone clean/finding commits executed local_integration Original install 0, clean 0, finding 1, unchanged HEAD and redacted output
One generated inert AWS-shaped value was rejected synthetic Existing fixture; actual value omitted
Native named-property containment test local_integration Original 33 cases passed with one Shellcheck-unavailable skip
Copied layout survives absence of its mise source local_integration Review repair check retained separately in the receipt
Unchanged upstream tests and host application not_run Co-op owns host application; local checks are not upstream acceptance
Hosted checks observed separately Prior review identified unrelated time-of-day validate flake and OSV advisories covered by #765

Local commands run

These are actual native integration checks; prior results remain distinct from review-repair checks.

# Original isolated acceptance, six task-private mise directories.
nice -n 19 mise install --jobs=1 aqua:gitleaks/gitleaks@8.30.1 # exit 0
mise where aqua:gitleaks/gitleaks@8.30.1 # exit 0
mise exec aqua:gitleaks/gitleaks@8.30.1 -- gitleaks version # exit 0; 8.30.1
# Guarded scratch-clone commits: clean 0; generated finding 1;
# positive native findings line, unchanged HEAD, generated value absent.
nice -n 19 python3 -m unittest tests.test_pre_commit_gate tests.test_gitleaks_config # exit 0; 40 tests
nice -n 19 python3 -m unittest tests.test_adoption_guarded_runners # exit 0; 33 tests, one skip
nice -n 19 python3 -m unittest tests.test_pre_push_gate # exit 0; 16 tests
nice -n 19 python3 scripts/validate.py # original exit 0; 10277 hashed files
nice -n 19 python3 scripts/component_matrix.py --check # exit 0
nice -n 19 python3 scripts/new_host_grand_list.py --check # exit 0
git diff --check # exit 0

Review repair: the supported task-private mise install passed; the copied binary's SHA matched and the guarded scanner stayed usable after moving away its original task-private mise source. A real scratch-clone clean commit passed and the generated-value commit failed with a positive findings count, unchanged HEAD and redacted output. The three focused modules ran 73 tests in 101.446s, exit 0 with one existing Shellcheck-unavailable skip. Final python3 scripts/validate.py passed with 69 components, four profiles, 212 receipts and 10277 hashed files; git diff --check passed. No destructive prune operation, host application or additional full-suite claim is made.

Host apply, read-back and rollback

The co-op applies the exact recipe in adoption/git-hook-acceptance.md. First create a fresh checkpoint under the native stack's XDG state directory, save only the safe hooksPath key and three public tool paths, and export its external TMPDIR.

repo="$HOME/code/native-agent-stack"
eco="${ECO_INSTALL_ROOT:-$HOME/.local/share/codex-ecosystem}"
nice -n 19 mise install --jobs=1 aqua:gitleaks/gitleaks@8.30.1
native_dir="$(mise where aqua:gitleaks/gitleaks@8.30.1)"
install -D -m 0755 "$repo/adoption/tools/gitleaks-guarded" "$eco/bin/gitleaks"
install -D -m 0755 "$repo/adoption/tools/ecosystem-bounded-run" "$eco/bin/ecosystem-bounded-run"
mkdir -p "$eco/tools/gitleaks-8.30.1"
install -m 0755 "$native_dir/gitleaks" "$eco/tools/gitleaks-8.30.1/gitleaks"
test "$(sha256sum "$eco/tools/gitleaks-8.30.1/gitleaks" | cut -d ' ' -f 1)" = 88f91962aa2f93ac6ab281d553b9e125f5197bbbce38f9f2437f7299c32e5509
test "$(command -v gitleaks)" = "$eco/bin/gitleaks"
test "$(gitleaks version)" = 8.30.1
command -v zizmor
git -C "$repo" config --local core.hooksPath scripts/git-hooks
test "$(git -C "$repo" config --local --get core.hooksPath)" = scripts/git-hooks

The setting covers all linked worktrees. Each client must inherit the guarded PATH; the existing pre-push gate also needs Zizmor and external TMPDIR. The recipe's real scratch clone must pass a clean commit and reject the generated value with a positive leaks found: N line, unchanged HEAD and redaction. Git returns 1 for any hook failure: refusal 78 and contention 75 remain unfinished acceptance. Retry contention after the holder finishes.

Applied change Rollback from fresh checkpoint
hooksPath Restore the saved safe value; if absent originally, unset and tolerate only native missing-key exit 5
Guard, runner and copied native binary Restore each saved public file/link; remove only a newly introduced path
mise installation Uninstall this exact version only if absent before apply

The existing vendor-archive layout is cross-referenced in the recipe. A reciprocal edit to the separate secret-storage guide is deferred to that document's consolidation owner.

Failed attempts

The original 73-case run failed because positional systemctl parsing read running as TasksCurrent. The named-property correction and subsequent passes remain distinct. Other retained preparation failures: source classifier KeyError, registry CLI help exit 2, and initial clone without nice 19. This review repair also corrected nonexistent guessed README/test/mise paths before execution. No failed condition is promoted into upstream acceptance.

Decision record

docs/decisions/2026-10-06-git-hook-scanner-pin.md records the source comparison, corrected currency dates, pruning remedy and Betterleaks qualification trigger before 2026-10-20.

Host evidence

No host-receipt or platform-status change. The co-op owns native host application and read-back. Request command-center micro-check of the new exact head; keep this PR a draft.

Checklist

  • Hook, rules and production guard are unchanged; native source references supplied.
  • No workflow changes; pin/permissions items are not applicable.
  • No credentials printed, read or committed; generated value is private scratch only.
  • No paid hosting or billing surface.
  • Peer-owned paths and central bundle preserved.
  • Evidence registry committed last.

@seathatflowsinourveins seathatflowsinourveins added the lane:foundation Foundation lane: Claude/Codex setup, hosts, memory, RAG, research, workers label Oct 6, 2026
seathatflowsinourveins added a commit that referenced this pull request Oct 6, 2026
)

### Scope

Fix the newly reviewed advisories that blocked every required OSV check: target only fsspec 2026.6.0/multidict 6.9.1 in the OpenHands runtime lock, Mako 1.4.2 in the application Python lock, and source-map-js 1.2.2 in its pnpm lock. Preserve all other package pins and the original captured artifact bytes.

The command center selected a dated source-backed exception for the frozen macOS input in its isolated config, and exclusion of both retired Lumibot lockchecks after the owner's confirmation. Each lock has native before/after evidence and its supported installation/qualification checks. No workflow or branch-protection setting changes.

- Base: `ecfa112764c664d35377dd66b8cfcb67e5a94d60` (fetch confirmed current main).
- Lane: `lane:foundation`.
- Owned scope: three production locks, SDK pins/research/evidence, qualification and ruling receipts, bounded OSV configuration/inventory, existing binding/no-use guards and closure record. Evidence registry committed last.

## SOTA sources

- [fsspec advisory GHSA-27vj-qcqg-25rc](GHSA-27vj-qcqg-25rc), [official 2026.6.0 release metadata](https://pypi.org/pypi/fsspec/2026.6.0/json), [maintainer tag](https://github.com/fsspec/filesystem_spec/tree/2026.6.0).
- [multidict advisory GHSA-54p9-h82j-f925](GHSA-54p9-h82j-f925), [official 6.9.1 release](https://github.com/aio-libs/multidict/releases/tag/v6.9.1), [PyPI metadata](https://pypi.org/pypi/multidict/6.9.1/json).
- [Mako advisory GHSA-5639-2j2p-m4mx](GHSA-5639-2j2p-m4mx), [maintainer release](https://github.com/sqlalchemy/mako/releases/tag/rel_1_4_2), [official metadata](https://pypi.org/pypi/Mako/1.4.2/json).
- [source-map-js advisory GHSA-68fv-2mgg-jv7q](GHSA-68fv-2mgg-jv7q), [published 1.2.2 metadata](https://registry.npmjs.org/source-map-js/1.2.2), [maintainer fix PR79](7rulnik/source-map-js#79).
- Dependent ranges: [Hugging Face Hub0.35.3](https://pypi.org/pypi/huggingface-hub/0.35.3/json), [aiohttp3.14.3](https://pypi.org/pypi/aiohttp/3.14.3/json), [yarl1.22.0](https://pypi.org/pypi/yarl/1.22.0/json), [Alembic1.20.0](https://pypi.org/pypi/alembic/1.20.0/json), [PostCSS8.5.23](https://registry.npmjs.org/postcss/8.5.23). Complete declared-parent checks include optional/null metadata handling; limitations remain explicit in receipts.
- [#562 at74cc5468](#562): original builder/relock/hash/install/scan/guard pattern. Installed [uv0.12.22](https://github.com/astral-sh/uv/releases/tag/0.12.22) reproduces the accepted baseline byte for byte; #562's0.12.17 remains historical.
- [#587 at798ac445](#587), [#252 atc96c2555](#252): bounded frontend qualification. [pnpm12.4.2 update parser](https://github.com/pnpm/pnpm/blob/9502f3c457717dae3a4ddbf4315a8c4aee16fdb4/pnpm/crates/cli/src/cli_args/update.rs) and [supported update docs](https://pnpm.io/cli/update): selective bare-name transitive update, no-save/lockfile-only; obsolete explicit-version/Infinity forms avoided.
- Frozen config precedent [8fc8611](8fc8611) and the maintained closure at `docs/decisions/2026-09-22-github-automation-closure.md`. Indexed source offsets/reconstruction inspected at [source-map-js1.2.1](https://github.com/7rulnik/source-map-js/blob/428d49f6b1e1614f082b7706fa879a3d9c64f728/lib/source-map-consumer.js#L944). Dedicated input/digest/expiry guards retained.
- Trial [#336 at20b52a5b](#336), existing captured XNYS exclusion precedent, and command-center ruling `task-ns2604-coop-20261006T003954Z`. The verified owner confirmation is a **report** row: `report-native-agent-stack-5f-20261006T0045Z-osv`, from `native-agent-stack-5f`, at `2026-10-06T00:41:23Z`, replying to `task-native-agent-stack-5f-20261006T004011Z`. Sanitized evidence: `evidence/receipts/osv-captured-lumibot-lockchecks-20261005.json`. No trial replay or new host-process census is claimed.

### Evidence-class table

| Claim | Class | Actual result |
| --- | --- | --- |
| Published dependent ranges permit the fixes | source_review | Complete pinned metadata review; no caps/errors; exact parents linked above |
| Targeted locks preserve other pins | local_integration | SDK byte-identical control; only two package blocks move. Mako only package block, native lock revision3→5 recorded. pnpm manager/importers unchanged; only source-map-js move |
| Release identity and supported artifact hashes match | local_integration | Native hash checks0: fsspec2, multidict14, Mako2; universal wheels/sdist included |
| Supported isolated/native qualification succeeds | local_integration | SDK178-package check/imports0; backend28-package check/import/render0; frontend frozen install/peers/typecheck/build0 |
| Both required scan partitions pass locally | local_integration | Before:60ordinary/1frozen,5+1 unignored findings. After:58ordinary/1frozen, actual native exits0/0, zero unignored findings |
| Binding/coverage/no-use guards remain effective | local_integration / synthetic |70 touched tests0; clean control0; all deliberate negative controls1 as expected |
| Registry integrity | local_integration | validate.py0;69components/4profiles/212receipts/10309hashes; integrity only |
| Hosted, image, provider and full API/browser acceptance | unknown | No claim; command-center exact-head cross-family read remains pending |

### Local commands run

All heavy phases used nice19; scratch/cache and installs were isolated. Exact supported commands and sanitized actual returned output/hashes are retained in the three relock prefixes and linked receipts.

```
#562-pattern paired native uv control/targeted lock/check/export:0
native release hash checks:0
hashed SDK install / uv pip check / exact imports:0
targeted Mako lock/check; frozen/no-build sync; pip check; imports/render:0
pnpm12.4.2 update source-map-js --no-save --lockfile-only --ignore-scripts:0
pnpm install --frozen-lockfile --ignore-scripts; peers check; typecheck; build:0
python -m unittest tests.test_openhands_lock_binding tests.test_osv_lockfile_coverage tests.test_frozen_macos_variant_no_use
70 tests; latest final data-pin run6.936s; exit0
OSV2.6.0 ordinary scan:0; frozen scan:0
python3 scripts/validate.py:0,10309hashes
component_matrix --write:0,32rows/zero flips
new_host_grand_list --write:0,32layers/66winners
git diff --check and git diff --cached --check:0
```

### Failed conditions

The initial root-added UV_NO_CONFIG1 discarded the resolver's Linux workspace settings; the next copied formatter inserted two plus signs. Native lock/check/export succeeded in both, while the relock byte-comparison script failed. Neither candidate was adopted; both are disclosed separately. Test preflight rejected inside-checkout TMPDIR before execution; existing external lane cache was used. Intermediate stale receipt/unreviewed metadata-line guards failed before being corrected. Publication caught one private interpreter path in a negative-control trace; it was sanitized. Terminal progress whitespace was normalized and its capture hash rebound. No failure is promoted to a passing upstream test.

### Decision record

`docs/decisions/2026-09-22-github-automation-closure.md`, "Four production relocks and preserved receipt inputs (2026-10-06)"; SDK research section and qualification/ruling receipts record alternatives, source/replay limits and overturn conditions. The macOS exception expires2026-12-24; its `.frozen` rename is a separate follow-up. Future use of captured trial dependencies requires a separately maintained/scanned qualification environment.

### Host evidence

No evidence/hosts or platform-status flip. The native runtime imports/builds are local integration; source reviews, synthetic controls and hosted acceptance remain separate. Exact-head command-center review is requested.

### Checklist

- [x] No workflow/action permission or branch-protection change.
- [x] No credential value or authentication store read/printed/copied; no new required secret.
- [x] No paid hosting, provider/model runtime call, deployment or restart.
- [x] Peer-owned worktrees preserved; three captured locks remain byte-identical.
- [x] Registry committed last; one lane:foundation label.
- [x] Ordinary AND frozen native scans and touched tests passed before ready.
- [ ] Command-center exact-head cross-family read and 5f landing; lane never merges.

## Dated input-binding repair (2026-10-06)

The command-center exact-head read of67c6594d2 found two omitted downstream gates: both convergence records still resolved their original UV digest through the newly relocked live file, and the recipe ledger's PNPM current digest was stale. This amendment preserves trial evidence instead of attributing new dependencies to the original runs.

- Retain ecfa112 UV/PNPM bytes and the two pre-amendment experiment snapshots byte-for-byte.
- Change only each canonical record's UV input path; keep frozen digests, commands, observations, outputs and usage. Both records remain declared.
- Append dated recipe supersession/current mappings and ordered path relocations; protect original/prior/superseded bytes and all non-path record bytes with the portability assertions.
- Source: [#252 path-only relocation](https://github.com/seathatflowsinourveins/native-agent-stack/blob/c96c2555c2d84683d9e519623354c814aeb6a584/blueprints/convergence-practice/application-delivery/history/recipe-revisions.json#L121) and [#587 supersession](https://github.com/seathatflowsinourveins/native-agent-stack/blob/798ac445307e2cd8eba6e74d7722ac0e16da02c7/blueprints/convergence-practice/application-delivery/history/recipe-revisions.json#L99).
- Dated decision/source receipt: `docs/decisions/2026-10-06-application-input-binding-amendment.md`, `evidence/receipts/pr765-bindings-amendment-20261006.json`.

Before repair, all-recorded convergence exited1 (2invalid/32) and native-maintenance exited1 (29cases/one PNPM mismatch). Repaired focused checks: native-maintenance29passed; convergence/OSVcoverage/frozenMAC102passed. After main-registry refresh and full own-file re-registration, local validate0/10315hashes and all-recorded convergence0/32valid. Full local suite ran under A22's specific copied-fixture `install.sh --list` exception and exited1:10,343tests/2217.568s,18failures/18errors/905skips. Installer apply paths remain banned. Raw output is retained privately; known systemd parser (#767), missing calendar/mutation imports, PATH fixtures, token-canary fixtures and installed Windows Terminal type drift are recorded separately, never presented as a pass.

Old reviewed head's hosted baseline was6/7 required contexts: validate failed, six others passed. Required acceptance is measured at the new pushed head; no workflow rerun loop or old local check is promoted into that acceptance. No production pin, recorded trial output, raw receipt, frozen macOS lock, captured trading lock or scanner exclusion changed in this repair.
@seathatflowsinourveins

Copy link
Copy Markdown
Owner Author

Closed with a record by the PR triage of 2026-10-07 (the command center's ruling). Not merged; the branch codex/ns2604-p1-git-20261006 stays on origin at 206cb8c.

Folded into #733 at beee52d. Of this PR's 7 changed files, 6 are byte-identical there and 1 is merged; none is lost. Registry: 6 entries added or changed by this PR are all present there, 0 of them re-registered to the merged file's hash.

Reopen trigger: none while #733 carries the content. Reopen with gh pr reopen 767.

@seathatflowsinourveins
seathatflowsinourveins deleted the codex/ns2604-p1-git-20261006 branch October 8, 2026 17:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

lane:foundation Foundation lane: Claude/Codex setup, hosts, memory, RAG, research, workers

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant