Repository navigation
Close CMUX local-acceptance child environments - #1091
Conversation
|
@greptile-apps review Please review exact head |
|
@coderabbitai review Please review exact repaired head |
|
Tip For best results, initiate chat on the files or code changes. 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
printf '%s\n' '== HEAD =='
git rev-parse HEAD
git status --short
printf '%s\n' '== COMMIT =='
git show -s --format='%H%n%P%n%s' 5493fc95e656c09a20f58a8431fa90afb405d425
printf '%s\n' '== CHANGED FILES =='
git diff --name-status 5493fc95e656c09a20f58a8431fa90afb405d425^ 5493fc95e656c09a20f58a8431fa90afb405d425
printf '%s\n' '== DIFF =='
git diff --find-renames --find-copies --unified=80 5493fc95e656c09a20f58a8431fa90afb405d425^ 5493fc95e656c09a20f58a8431fa90afb405d425 -- scripts/cmux_fleet.py scripts/test-cmux-fleet.py docs/CMUX_FLEET_ENROLLMENT.md
printf '%s\n' '== OUTLINE: scripts/cmux_fleet.py =='
ast-grep outline scripts/cmux_fleet.py --items all --type function,class
printf '%s\n' '== OUTLINE: scripts/test-cmux-fleet.py =='
ast-grep outline scripts/test-cmux-fleet.py --items all --type function,class
printf '%s\n' '== CHILD-PROCESS AND ENVIRONMENT REFERENCES =='
rg -n -C 5 -e 'subprocess\.' -e '\benv\b' -e 'PYTHONPATH|PYTHONHOME|SSH_AUTH_SOCK|GIT_|TMPDIR|LC_ALL|LANG|sys\.executable|python' scripts/cmux_fleet.py scripts/test-cmux-fleet.pyLength of output: 27055 🏁 Script executed: #!/bin/bash
set -euo pipefail
head=5493fc95e656c09a20f58a8431fa90afb405d425
implementation=635f53691e1c42ac0e24c9ffbc7d3969d3b65689
printf '%s\n' '== IMPLEMENTATION COMMIT AND PATCH =='
git show -s --format='%H%n%P%n%s' "$implementation"
git diff --find-renames --unified=50 "$implementation"^ "$implementation" -- scripts/cmux_fleet.py scripts/test-cmux-fleet.py
printf '%s\n' '== EXACT HEAD: CHILD ENVIRONMENT AND ACCEPT-LOCAL =='
git show "$head:scripts/cmux_fleet.py" | nl -ba | sed -n '1080,1320p'
printf '%s\n' '== EXACT HEAD: TESTS FOR ENVIRONMENT AND BOTH CHILDREN =='
git show "$head:scripts/test-cmux-fleet.py" | nl -ba | sed -n '420,620p'
printf '%s\n' '== EXACT HEAD: ALL SUBPROCESS CALL SITES =='
git show "$head:scripts/cmux_fleet.py" | grep -n -E 'subprocess\.(run|Popen|call|check_call|check_output)|os\.system|exec' -C 9
printf '%s\n' '== EXACT HEAD: ENVIRONMENT AND TEMPORARY-DIRECTORY REFERENCES =='
git show "$head:scripts/cmux_fleet.py" | grep -n -E 'acceptance_child_environment|os\.environ|TemporaryDirectory|mkdtemp|TMPDIR|LC_ALL|LANG|chmod|umask' -C 5
printf '%s\n' '== EXACT HEAD: FILE MODES AND IMPORTS =='
git show "$head:scripts/cmux_fleet.py" | nl -ba | sed -n '1,80p'Length of output: 52631 🏁 Script executed: #!/bin/bash
set -euo pipefail
repo="teamleaderleo/glaeda"
head="5493fc95e656c09a20f58a8431fa90afb405d425"
printf '%s\n' '== PR METADATA =='
gh pr view 1091 --repo "$repo" --json number,baseRefOid,headRefOid,commits,files --jq '{
number,
baseRefOid,
headRefOid,
commits: [.commits[] | {oid: .oid, messageHeadline: .messageHeadline}],
files: [.files[] | .path]
}'
base="$(gh pr view 1091 --repo "$repo" --json baseRefOid --jq .baseRefOid)"
printf '%s\n' '== BASE-TO-REQUESTED-HEAD STAT =='
git diff --stat "$base" "$head"
printf '%s\n' '== BASE-TO-REQUESTED-HEAD FILES =='
git diff --name-status "$base" "$head"
printf '%s\n' '== BASE-TO-REQUESTED-HEAD DIFF =='
git diff --find-renames --check "$base" "$head"
git diff --find-renames --unified=35 "$base" "$head" -- scripts/cmux_fleet.py scripts/test-cmux-fleet.py docs/CMUX_FLEET_ENROLLMENT.mdLength of output: 29440
I found no issues in the requested child-environment boundary.
I did not execute repository tests. The review used static inspection only. Note: You are interacting with an AI system. |
9615cfd to
64f1bc8
Compare
|
@greptile-apps review Exact rebased repair head: |
|
@coderabbitai review Exact rebased repair head: |
|
Tip For best results, initiate chat on the files or code changes. 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
repo="teamleaderleo/glaeda"
head="17e381506b2eab418a7b15300ab1c293fd8686e6"
printf '%s\n' '== REQUESTED COMMIT =='
git show -s --format='%H%n%P%n%s' "$head"
printf '%s\n' '== PR METADATA =='
gh pr view 1091 --repo "$repo" --json number,baseRefOid,headRefOid,commits,files --jq '{
number,
baseRefOid,
headRefOid,
commits: [.commits[] | {oid: .oid, messageHeadline: .messageHeadline}],
files: [.files[] | .path]
}'
base="$(gh pr view 1091 --repo "$repo" --json baseRefOid --jq .baseRefOid)"
printf '%s\n' '== BASE-TO-REQUESTED-HEAD FILES =='
git diff --name-status "$base" "$head"
printf '%s\n' '== BASE-TO-REQUESTED-HEAD CHECK =='
git diff --check "$base" "$head"
printf '%s\n' '== BASE-TO-REQUESTED-HEAD DIFF =='
git diff --find-renames --unified=45 "$base" "$head" -- scripts/cmux_fleet.py scripts/test-cmux-fleet.py docs/CMUX_FLEET_ENROLLMENT.md
printf '%s\n' '== OUTLINE: scripts/cmux_fleet.py =='
ast-grep outline scripts/cmux_fleet.py --items all --type function,class
printf '%s\n' '== OUTLINE: scripts/test-cmux-fleet.py =='
ast-grep outline scripts/test-cmux-fleet.py --items all --type function,class
printf '%s\n' '== SUBPROCESS AND ENVIRONMENT REFERENCES AT REQUESTED COMMIT =='
git show "$head:scripts/cmux_fleet.py" | nl -ba | grep -E -C 8 'subprocess\.|os\.environ|acceptance_child_environment|TemporaryDirectory|mkdtemp|TMPDIR|LC_ALL|LANG|sys\.executable|python'
printf '%s\n' '== TEST REFERENCES AT REQUESTED COMMIT =='
git show "$head:scripts/test-cmux-fleet.py" | nl -ba | grep -E -C 8 'subprocess\.|PYTHONPATH|PYTHONHOME|SSH_AUTH_SOCK|GIT_|TMPDIR|LC_ALL|LANG|sentinel|environment|sys\.executable|python' || trueLength of output: 55340
I found no issues in the requested child-environment boundary.
I performed static inspection only. I did not execute repository code or tests. You are interacting with an AI system. |
Follow-up repair for the execution-safety finding recorded on merged #1088.
#1088 correctly made
accept-localthe only path that can mint candidate-eligible CMUX fleet receipts, but its two Python child front doors inherited the full operator environment. That violatesdocs/AGENT_EXECUTION_SAFETY.mdand leaves ambient Python/Git/credential state able to influence acceptance before CMUX's own workload runner closes its child environment.This repair keeps the same acceptance semantics and closes only that subprocess boundary:
python -I;LC_ALL/LANGare fixed toC;TMPDIRis a private mode-0700 directory inside the acceptance attempt;PATH,HOME,CARGO_HOME,RUSTUP_HOME,DEVELOPER_DIR;PYTHONPATH,PYTHONHOME, SSH-agent variables, Git redirect variables, credentials/tokens, unrelated locale, and caller TMPDIR are excluded.Regression coverage injects hostile/sentinel ambient values and proves neither child receives them, while preserving the existing cold-state runner contract and post-run bootstrap flow.
Owned fence:
scripts/cmux_fleet.py,scripts/test-cmux-fleet.py,docs/CMUX_FLEET_ENROLLMENT.md.Excluded: CMUX workload semantics, role/capacity policy, routing, physical lease acquisition, and #1084 execution-role logic.
Because this repairs execution/acceptance authority, final merge requires implementation-independent exact-head acceptance under
docs/AGENT_COORDINATION.md.Related: #1057, #1088, manaflow-ai/cmux#13411.