Skip to content

lane: connect Termux hub over Tailscale + repeatable collaborator bootstrap - #764

Draft
timerloggedout-spec wants to merge 19 commits into
masterfrom
feat/termux-hub-direct-tailscale-connection
Draft

timerloggedout-spec wants to merge 19 commits into
masterfrom
feat/termux-hub-direct-tailscale-connection

Conversation

@timerloggedout-spec

Copy link
Copy Markdown
Owner

Closes #763.

What this adds

  • project-owned Termux hub connection lane independent of Desktop Commander
  • Tailscale/MagicDNS-first SSH transport contract
  • repeatable collaborator onboarding without committing device secrets
  • explicit Shizuku-as-optional capability boundary
  • read-only scripts/termux-hub/health.sh
  • evidence gate separating Tailscale, SSH, MCP, Shizuku, and policy readiness

Current state

The operator-provided evidence shows termux-hub connected in Tailscale and identifies its MagicDNS name. This PR intentionally treats the observed IP as diagnostic only.

The PR does not claim that ChatGPT has completed a live SSH/MCP round-trip yet. That requires an SSH-capable client path outside the broken Desktop Commander lane.

Security

  • no private keys/tokens/OTP seeds
  • no public SSH
  • key-only collaborator flow
  • Shizuku is not required for base shell connectivity
  • transport remains separate from hub_mcp capability authorization

Follow-up

After the device-side bootstrap is applied, capture the health output and a harmless SSH/MCP identity probe as evidence. Then wire the first approved MCP client route to the pinned device-side server.

@blocksorg

blocksorg Bot commented Sep 23, 2026

Copy link
Copy Markdown

Mention Blocks like a regular teammate with your question or request:

@blocks review this pull request
@blocks make the following changes ...
@blocks create an issue from what was mentioned in the following comment ...
@blocks explain the following code ...
@blocks are there any security or performance concerns?

Run @blocks /help for more information.

Workspace settings | Disable this message

@ecc-tools

ecc-tools Bot commented Sep 23, 2026

Copy link
Copy Markdown

ECC Tools / Security Evidence

Commit: 3613dee91a76a6876bafc0219135a7a12e86f540

Security evidence gate passed (success)

No security-sensitive scanner-evidence gap detected.

Mode: enforce

Scanned 2 changed file(s). No missing scanner-evidence signal was detected.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Sep 23, 2026

Copy link
Copy Markdown

ECC Tools / PR Risk Taxonomy

Commit: 3613dee91a76a6876bafc0219135a7a12e86f540

PR taxonomy clear (success)

Scanned 2 changed file(s). No taxonomy bucket signals were detected.

Scanned 2 changed file(s).

No PR taxonomy bucket signals were detected.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Sep 23, 2026

Copy link
Copy Markdown

ECC Tools / Reference Set Readiness

Commit: 3613dee91a76a6876bafc0219135a7a12e86f540

Reference set readiness gaps detected (neutral)

Reference evidence present for 0/7 areas (0%) across 2 changed file(s).

This check is based on files changed in this PR. Repository-level readiness is still reported by /ecc-tools analyze comments and generated manifests.

Area Status Evidence / Next Step
Deep analyzer corpus Missing Add analyzer fixture, golden, benchmark, or reference-set files that can catch analyzer regressions.
RAG/evaluator comparison Missing Add retrieval or evaluator reference-set comparison fixtures with expected ranking behavior.
PR salvage/review corpus Missing Add stale-PR, review-thread, reopen-flow, or salvage reference cases for queue cleanup automation.
Discussion triage corpus Missing Add public discussion triage fixtures, golden cases, or reference sets for informational, answered, and no-response classifications.
Harness compatibility Missing Add cross-harness, adapter-compliance, or harness-audit evidence for Claude, Codex, OpenCode, Zed, dmux, and agent surfaces.
Security evidence Missing Attach security evidence such as SBOMs, SARIF, audit reports, or AgentShield evidence packs.
CI failure-mode evidence Missing Add captured CI failure logs, dry-run fixtures, or troubleshooting docs for common workflow failure modes.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@vercel

vercel Bot commented Sep 23, 2026

Copy link
Copy Markdown

Deployment failed for project termux-monorepo with the following error:

Resource is limited - try again in 24 hours (more than 100, code: "api-deployments-free-per-day").

Learn More: https://vercel.com/timerloggedout-5184s-projects?upgradeToPro=build-rate-limit

@ecc-tools

ecc-tools Bot commented Sep 23, 2026

Copy link
Copy Markdown

ECC Tools / Hosted Promotion Readiness

Commit: 3613dee91a76a6876bafc0219135a7a12e86f540

Hosted promotion readiness passed (success)

No hosted promotion evidence gaps detected across 2 changed file(s); 0 corpus scenarios had matching evidence.

This check compares PR file changes against the evaluator/RAG promotion corpus in src/analyzers/fixtures/evaluator-rag-corpus.ts.
Hosted output scoring inspected 0 completed cached hosted job results.

No evaluator corpus scenarios matched this PR.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@coderabbitai

coderabbitai Bot commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

Next included review available in 1 minute.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Repository: timerloggedout-spec/termux-monorepo/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 15c0d5ab-ddd4-42a0-8f02-e4be1c5f7391

📥 Commits

Reviewing files that changed from the base of the PR and between 6c4e0c7 and 623da83.

📒 Files selected for processing (12)
  • .github/workflows/termux-hub-static.yml
  • .github/workflows/termux-hub-tailnet-probe.yml
  • docs/ops/TERMUX_HUB_TAILSCALE_BOOTSTRAP.md
  • scripts/termux-hub/bootstrap.sh
  • scripts/termux-hub/health.sh
  • scripts/termux-hub/install-mcp.sh
  • scripts/termux-hub/preflight.sh
  • scripts/termux-hub/start-mcp.sh
  • termux_hub/__init__.py
  • termux_hub/mcp_server.py
  • termux_hub/requirements.txt
  • tests/termux_hub/test_mcp_server.py

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@timerloggedout-spec

Copy link
Copy Markdown
Owner Author

ECC App activity — dual-gate merges; review skills/hooks before merge.

@github-actions

github-actions Bot commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

PR Change Effectiveness Ledger

Measured head: 623da833f4da130eb37de5e53078d460a614ede0
Measured base: 6c4e0c780e72306557e730dcf7213f16416f478d
Merge base: 6c4e0c780e72306557e730dcf7213f16416f478d

Signal Value
commits in PR range 19
commits with no file delta 0
commits with file delta 19
no-op commit rate 0%
gross additions across commits 853
gross deletions across commits 1
final additions vs base 852
final deletions vs base 0
final changed files 12
churn → retained final diff 99%
ahead / behind base 19 / 0

Interpretation: commit count is context, not quality. Empty commits are explicitly measured, not silently treated as productive work. Gross churn describes work performed across history; the final base→head diff describes what remains. Review/comment/check evidence must be evaluated separately and tied to this measured head SHA.

State: 🟢 EFFECTIVE_DIFF_PRESENT; No empty commits observed.

Generated: 2026-09-23T04:00:15Z

@gitar-bot

gitar-bot Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

Gitar is working

Gitar

@vercel

vercel Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
help-wanted-oversight Ready Ready Preview Sep 23, 2026 3:58am UTC
mcp-hub Ready Ready Preview Sep 23, 2026 3:58am UTC

@ecc-tools

ecc-tools Bot commented Sep 23, 2026

Copy link
Copy Markdown

ECC Tools / Security Evidence

Commit: 13dc429ef8fc7ffec8fdc7649bf2898f48b7b09a

Security evidence gate passed (success)

No security-sensitive scanner-evidence gap detected.

Mode: enforce

Scanned 2 changed file(s). No missing scanner-evidence signal was detected.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@vercel

vercel Bot commented Sep 23, 2026

Copy link
Copy Markdown

Deployment failed for project help-wanted-dash with the following error:

Resource is limited - try again in 24 hours (more than 100, code: "api-deployments-free-per-day").

Learn More: https://vercel.com/timerloggedout-5184s-projects?upgradeToPro=build-rate-limit

@ecc-tools

ecc-tools Bot commented Sep 23, 2026

Copy link
Copy Markdown

ECC Tools / PR Risk Taxonomy

Commit: 13dc429ef8fc7ffec8fdc7649bf2898f48b7b09a

PR taxonomy clear (success)

Scanned 2 changed file(s). No taxonomy bucket signals were detected.

Scanned 2 changed file(s).

No PR taxonomy bucket signals were detected.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@vercel

vercel Bot commented Sep 23, 2026

Copy link
Copy Markdown

Deployment failed for project help-wanted-oversight with the following error:

Resource is limited - try again in 24 hours (more than 100, code: "api-deployments-free-per-day").

Learn More: https://vercel.com/timerloggedout-5184s-projects?upgradeToPro=build-rate-limit

@ecc-tools

ecc-tools Bot commented Sep 23, 2026

Copy link
Copy Markdown

ECC Tools / Reference Set Readiness

Commit: 13dc429ef8fc7ffec8fdc7649bf2898f48b7b09a

Reference set readiness gaps detected (neutral)

Reference evidence present for 0/7 areas (0%) across 2 changed file(s).

This check is based on files changed in this PR. Repository-level readiness is still reported by /ecc-tools analyze comments and generated manifests.

Area Status Evidence / Next Step
Deep analyzer corpus Missing Add analyzer fixture, golden, benchmark, or reference-set files that can catch analyzer regressions.
RAG/evaluator comparison Missing Add retrieval or evaluator reference-set comparison fixtures with expected ranking behavior.
PR salvage/review corpus Missing Add stale-PR, review-thread, reopen-flow, or salvage reference cases for queue cleanup automation.
Discussion triage corpus Missing Add public discussion triage fixtures, golden cases, or reference sets for informational, answered, and no-response classifications.
Harness compatibility Missing Add cross-harness, adapter-compliance, or harness-audit evidence for Claude, Codex, OpenCode, Zed, dmux, and agent surfaces.
Security evidence Missing Attach security evidence such as SBOMs, SARIF, audit reports, or AgentShield evidence packs.
CI failure-mode evidence Missing Add captured CI failure logs, dry-run fixtures, or troubleshooting docs for common workflow failure modes.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@vercel

vercel Bot commented Sep 23, 2026

Copy link
Copy Markdown

Deployment failed for project mcp-hub with the following error:

Resource is limited - try again in 24 hours (more than 100, code: "api-deployments-free-per-day").

Learn More: https://vercel.com/timerloggedout-5184s-projects?upgradeToPro=build-rate-limit

@ecc-tools

ecc-tools Bot commented Sep 23, 2026

Copy link
Copy Markdown

ECC Tools / Hosted Promotion Readiness

Commit: 13dc429ef8fc7ffec8fdc7649bf2898f48b7b09a

Hosted promotion readiness passed (success)

No hosted promotion evidence gaps detected across 2 changed file(s); 0 corpus scenarios had matching evidence.

This check compares PR file changes against the evaluator/RAG promotion corpus in src/analyzers/fixtures/evaluator-rag-corpus.ts.
Hosted output scoring inspected 0 completed cached hosted job results.

No evaluator corpus scenarios matched this PR.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Sep 23, 2026

Copy link
Copy Markdown

ECC Tools / Security Evidence

Commit: 9a1efae15623fe83c1106716a08f2a3723775314

Security evidence gate passed (success)

No security-sensitive scanner-evidence gap detected.

Mode: enforce

Scanned 3 changed file(s). No missing scanner-evidence signal was detected.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Sep 23, 2026

Copy link
Copy Markdown

ECC Tools / PR Risk Taxonomy

Commit: 9a1efae15623fe83c1106716a08f2a3723775314

PR taxonomy review recommended (neutral)

Detected 1 PR taxonomy bucket(s): CI/CD Recommendation.

Scanned 3 changed file(s).

Roadmap taxonomy buckets:

CI/CD Recommendation

CI, dependency, coverage, and contract signals should be routed into follow-up checks or verification work.

Signals:

  • Regression coverage may lag behind the diff
  • 0 CI or workflow path(s) changed

Paths:

  • scripts/termux-hub/bootstrap.sh
  • scripts/termux-hub/health.sh

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Sep 23, 2026

Copy link
Copy Markdown

ECC Tools / Reference Set Readiness

Commit: 9a1efae15623fe83c1106716a08f2a3723775314

Reference set readiness gaps detected (neutral)

Reference evidence present for 0/7 areas (0%) across 3 changed file(s).

This check is based on files changed in this PR. Repository-level readiness is still reported by /ecc-tools analyze comments and generated manifests.

Area Status Evidence / Next Step
Deep analyzer corpus Missing Add analyzer fixture, golden, benchmark, or reference-set files that can catch analyzer regressions.
RAG/evaluator comparison Missing Add retrieval or evaluator reference-set comparison fixtures with expected ranking behavior.
PR salvage/review corpus Missing Add stale-PR, review-thread, reopen-flow, or salvage reference cases for queue cleanup automation.
Discussion triage corpus Missing Add public discussion triage fixtures, golden cases, or reference sets for informational, answered, and no-response classifications.
Harness compatibility Missing Add cross-harness, adapter-compliance, or harness-audit evidence for Claude, Codex, OpenCode, Zed, dmux, and agent surfaces.
Security evidence Missing Attach security evidence such as SBOMs, SARIF, audit reports, or AgentShield evidence packs.
CI failure-mode evidence Missing Add captured CI failure logs, dry-run fixtures, or troubleshooting docs for common workflow failure modes.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Sep 23, 2026

Copy link
Copy Markdown

ECC Tools / Hosted Promotion Readiness

Commit: 9a1efae15623fe83c1106716a08f2a3723775314

Hosted promotion readiness passed (success)

No hosted promotion evidence gaps detected across 3 changed file(s); 0 corpus scenarios had matching evidence.

This check compares PR file changes against the evaluator/RAG promotion corpus in src/analyzers/fixtures/evaluator-rag-corpus.ts.
Hosted output scoring inspected 0 completed cached hosted job results.

No evaluator corpus scenarios matched this PR.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Sep 23, 2026

Copy link
Copy Markdown

ECC Tools / Security Evidence

Commit: 9ded66cd3c6fe48daf74e9bc4a7f46d3755400ba

Security evidence gate passed (success)

No security-sensitive scanner-evidence gap detected.

Mode: enforce

Scanned 11 changed file(s). No missing scanner-evidence signal was detected.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Sep 23, 2026

Copy link
Copy Markdown

ECC Tools / PR Risk Taxonomy

Commit: 9ded66cd3c6fe48daf74e9bc4a7f46d3755400ba

PR taxonomy review recommended (neutral)

Detected 2 PR taxonomy bucket(s): Security Evidence, CI/CD Recommendation.

Scanned 11 changed file(s).

Roadmap taxonomy buckets:

Security Evidence

Security-sensitive changes should carry explicit scanner, code-scanning, or focused regression evidence.

Signals:

  • 1 security-sensitive path(s) changed

Paths:

  • .github/workflows/termux-hub-tailnet-probe.yml

CI/CD Recommendation

CI, dependency, coverage, and contract signals should be routed into follow-up checks or verification work.

Signals:

  • CI workflow changes may ship without failure-mode evidence
  • Dependency or CI drift could surface after merge
  • 1 CI or workflow path(s) changed

Paths:

  • .github/workflows/termux-hub-tailnet-probe.yml
  • scripts/termux-hub/bootstrap.sh
  • scripts/termux-hub/health.sh
  • scripts/termux-hub/install-mcp.sh
  • scripts/termux-hub/preflight.sh
  • scripts/termux-hub/start-mcp.sh
  • termux_hub/__init__.py
  • termux_hub/mcp_server.py

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Sep 23, 2026

Copy link
Copy Markdown

ECC Tools / Reference Set Readiness

Commit: 9ded66cd3c6fe48daf74e9bc4a7f46d3755400ba

Reference set readiness gaps detected (neutral)

Reference evidence present for 1/7 areas (14%) across 11 changed file(s).

This check is based on files changed in this PR. Repository-level readiness is still reported by /ecc-tools analyze comments and generated manifests.

Area Status Evidence / Next Step
Deep analyzer corpus Missing Add analyzer fixture, golden, benchmark, or reference-set files that can catch analyzer regressions.
RAG/evaluator comparison Missing Add retrieval or evaluator reference-set comparison fixtures with expected ranking behavior.
PR salvage/review corpus Missing Add stale-PR, review-thread, reopen-flow, or salvage reference cases for queue cleanup automation.
Discussion triage corpus Missing Add public discussion triage fixtures, golden cases, or reference sets for informational, answered, and no-response classifications.
Harness compatibility Present tests/termux_hub/test_mcp_server.py
Security evidence Missing Attach security evidence such as SBOMs, SARIF, audit reports, or AgentShield evidence packs.
CI failure-mode evidence Missing Add captured CI failure logs, dry-run fixtures, or troubleshooting docs for common workflow failure modes.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Sep 23, 2026

Copy link
Copy Markdown

ECC Tools / Hosted Promotion Readiness

Commit: 9ded66cd3c6fe48daf74e9bc4a7f46d3755400ba

Hosted promotion readiness passed (success)

No hosted promotion evidence gaps detected across 11 changed file(s); 0 corpus scenarios had matching evidence.

This check compares PR file changes against the evaluator/RAG promotion corpus in src/analyzers/fixtures/evaluator-rag-corpus.ts.
Hosted output scoring inspected 0 completed cached hosted job results.

No evaluator corpus scenarios matched this PR.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Sep 23, 2026

Copy link
Copy Markdown

ECC Tools / PR Config Audit

Commit: 9ded66cd3c6fe48daf74e9bc4a7f46d3755400ba

No changed-config issues detected (success)

Scanned 1 config file(s) present at this commit across 1 changed config path(s) and found no issues in the supported security rules.

Changed config files:

  • .github/workflows/termux-hub-tailnet-probe.yml

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Sep 23, 2026

Copy link
Copy Markdown

ECC Tools / PR Harness Audit

Commit: 9ded66cd3c6fe48daf74e9bc4a7f46d3755400ba

No harness issues detected (success)

Scanned 1 changed config file(s) and found no harness issues.

Changed config files:

  • .github/workflows/termux-hub-tailnet-probe.yml

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Sep 23, 2026

Copy link
Copy Markdown

ECC Tools / Security Evidence

Commit: 0aef3ff618b3de1a7844845a3546220706bf6316

Security evidence gate passed (success)

No security-sensitive scanner-evidence gap detected.

Mode: enforce

Scanned 11 changed file(s). No missing scanner-evidence signal was detected.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Sep 23, 2026

Copy link
Copy Markdown

ECC Tools / PR Risk Taxonomy

Commit: 0aef3ff618b3de1a7844845a3546220706bf6316

PR taxonomy review recommended (neutral)

Detected 2 PR taxonomy bucket(s): Security Evidence, CI/CD Recommendation.

Scanned 11 changed file(s).

Roadmap taxonomy buckets:

Security Evidence

Security-sensitive changes should carry explicit scanner, code-scanning, or focused regression evidence.

Signals:

  • 1 security-sensitive path(s) changed

Paths:

  • .github/workflows/termux-hub-tailnet-probe.yml

CI/CD Recommendation

CI, dependency, coverage, and contract signals should be routed into follow-up checks or verification work.

Signals:

  • CI workflow changes may ship without failure-mode evidence
  • Dependency or CI drift could surface after merge
  • 1 CI or workflow path(s) changed

Paths:

  • .github/workflows/termux-hub-tailnet-probe.yml
  • scripts/termux-hub/bootstrap.sh
  • scripts/termux-hub/health.sh
  • scripts/termux-hub/install-mcp.sh
  • scripts/termux-hub/preflight.sh
  • scripts/termux-hub/start-mcp.sh
  • termux_hub/__init__.py
  • termux_hub/mcp_server.py

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Sep 23, 2026

Copy link
Copy Markdown

ECC Tools / Reference Set Readiness

Commit: 0aef3ff618b3de1a7844845a3546220706bf6316

Reference set readiness gaps detected (neutral)

Reference evidence present for 1/7 areas (14%) across 11 changed file(s).

This check is based on files changed in this PR. Repository-level readiness is still reported by /ecc-tools analyze comments and generated manifests.

Area Status Evidence / Next Step
Deep analyzer corpus Missing Add analyzer fixture, golden, benchmark, or reference-set files that can catch analyzer regressions.
RAG/evaluator comparison Missing Add retrieval or evaluator reference-set comparison fixtures with expected ranking behavior.
PR salvage/review corpus Missing Add stale-PR, review-thread, reopen-flow, or salvage reference cases for queue cleanup automation.
Discussion triage corpus Missing Add public discussion triage fixtures, golden cases, or reference sets for informational, answered, and no-response classifications.
Harness compatibility Present tests/termux_hub/test_mcp_server.py
Security evidence Missing Attach security evidence such as SBOMs, SARIF, audit reports, or AgentShield evidence packs.
CI failure-mode evidence Missing Add captured CI failure logs, dry-run fixtures, or troubleshooting docs for common workflow failure modes.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Sep 23, 2026

Copy link
Copy Markdown

ECC Tools / Hosted Promotion Readiness

Commit: 0aef3ff618b3de1a7844845a3546220706bf6316

Hosted promotion readiness passed (success)

No hosted promotion evidence gaps detected across 11 changed file(s); 0 corpus scenarios had matching evidence.

This check compares PR file changes against the evaluator/RAG promotion corpus in src/analyzers/fixtures/evaluator-rag-corpus.ts.
Hosted output scoring inspected 0 completed cached hosted job results.

No evaluator corpus scenarios matched this PR.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Sep 23, 2026

Copy link
Copy Markdown

ECC Tools / PR Config Audit

Commit: 0aef3ff618b3de1a7844845a3546220706bf6316

No changed-config issues detected (success)

Scanned 1 config file(s) present at this commit across 1 changed config path(s) and found no issues in the supported security rules.

Changed config files:

  • .github/workflows/termux-hub-tailnet-probe.yml

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Sep 23, 2026

Copy link
Copy Markdown

ECC Tools / PR Harness Audit

Commit: 0aef3ff618b3de1a7844845a3546220706bf6316

No harness issues detected (success)

Scanned 1 changed config file(s) and found no harness issues.

Changed config files:

  • .github/workflows/termux-hub-tailnet-probe.yml

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Sep 23, 2026

Copy link
Copy Markdown

ECC Tools / Security Evidence

Commit: a66af0faf6f8cbadd3eafc3774725457a5d712d1

Security evidence gate passed (success)

No security-sensitive scanner-evidence gap detected.

Mode: enforce

Scanned 11 changed file(s). No missing scanner-evidence signal was detected.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Sep 23, 2026

Copy link
Copy Markdown

ECC Tools / PR Risk Taxonomy

Commit: a66af0faf6f8cbadd3eafc3774725457a5d712d1

PR taxonomy review recommended (neutral)

Detected 2 PR taxonomy bucket(s): Security Evidence, CI/CD Recommendation.

Scanned 11 changed file(s).

Roadmap taxonomy buckets:

Security Evidence

Security-sensitive changes should carry explicit scanner, code-scanning, or focused regression evidence.

Signals:

  • 1 security-sensitive path(s) changed

Paths:

  • .github/workflows/termux-hub-tailnet-probe.yml

CI/CD Recommendation

CI, dependency, coverage, and contract signals should be routed into follow-up checks or verification work.

Signals:

  • CI workflow changes may ship without failure-mode evidence
  • Dependency or CI drift could surface after merge
  • 1 CI or workflow path(s) changed

Paths:

  • .github/workflows/termux-hub-tailnet-probe.yml
  • scripts/termux-hub/bootstrap.sh
  • scripts/termux-hub/health.sh
  • scripts/termux-hub/install-mcp.sh
  • scripts/termux-hub/preflight.sh
  • scripts/termux-hub/start-mcp.sh
  • termux_hub/__init__.py
  • termux_hub/mcp_server.py

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Sep 23, 2026

Copy link
Copy Markdown

ECC Tools / Reference Set Readiness

Commit: a66af0faf6f8cbadd3eafc3774725457a5d712d1

Reference set readiness gaps detected (neutral)

Reference evidence present for 1/7 areas (14%) across 11 changed file(s).

This check is based on files changed in this PR. Repository-level readiness is still reported by /ecc-tools analyze comments and generated manifests.

Area Status Evidence / Next Step
Deep analyzer corpus Missing Add analyzer fixture, golden, benchmark, or reference-set files that can catch analyzer regressions.
RAG/evaluator comparison Missing Add retrieval or evaluator reference-set comparison fixtures with expected ranking behavior.
PR salvage/review corpus Missing Add stale-PR, review-thread, reopen-flow, or salvage reference cases for queue cleanup automation.
Discussion triage corpus Missing Add public discussion triage fixtures, golden cases, or reference sets for informational, answered, and no-response classifications.
Harness compatibility Present tests/termux_hub/test_mcp_server.py
Security evidence Missing Attach security evidence such as SBOMs, SARIF, audit reports, or AgentShield evidence packs.
CI failure-mode evidence Missing Add captured CI failure logs, dry-run fixtures, or troubleshooting docs for common workflow failure modes.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Sep 23, 2026

Copy link
Copy Markdown

ECC Tools / Hosted Promotion Readiness

Commit: a66af0faf6f8cbadd3eafc3774725457a5d712d1

Hosted promotion readiness passed (success)

No hosted promotion evidence gaps detected across 11 changed file(s); 0 corpus scenarios had matching evidence.

This check compares PR file changes against the evaluator/RAG promotion corpus in src/analyzers/fixtures/evaluator-rag-corpus.ts.
Hosted output scoring inspected 0 completed cached hosted job results.

No evaluator corpus scenarios matched this PR.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Sep 23, 2026

Copy link
Copy Markdown

ECC Tools / PR Config Audit

Commit: a66af0faf6f8cbadd3eafc3774725457a5d712d1

No changed-config issues detected (success)

Scanned 1 config file(s) present at this commit across 1 changed config path(s) and found no issues in the supported security rules.

Changed config files:

  • .github/workflows/termux-hub-tailnet-probe.yml

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Sep 23, 2026

Copy link
Copy Markdown

ECC Tools / PR Harness Audit

Commit: a66af0faf6f8cbadd3eafc3774725457a5d712d1

No harness issues detected (success)

Scanned 1 changed config file(s) and found no harness issues.

Changed config files:

  • .github/workflows/termux-hub-tailnet-probe.yml

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Sep 23, 2026

Copy link
Copy Markdown

ECC Tools / Security Evidence

Commit: 623da833f4da130eb37de5e53078d460a614ede0

Security evidence gate passed (success)

No security-sensitive scanner-evidence gap detected.

Mode: enforce

Scanned 12 changed file(s). No missing scanner-evidence signal was detected.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Sep 23, 2026

Copy link
Copy Markdown

ECC Tools / PR Risk Taxonomy

Commit: 623da833f4da130eb37de5e53078d460a614ede0

PR taxonomy review recommended (neutral)

Detected 2 PR taxonomy bucket(s): Security Evidence, CI/CD Recommendation.

Scanned 12 changed file(s).

Roadmap taxonomy buckets:

Security Evidence

Security-sensitive changes should carry explicit scanner, code-scanning, or focused regression evidence.

Signals:

  • 2 security-sensitive path(s) changed

Paths:

  • .github/workflows/termux-hub-static.yml
  • .github/workflows/termux-hub-tailnet-probe.yml

CI/CD Recommendation

CI, dependency, coverage, and contract signals should be routed into follow-up checks or verification work.

Signals:

  • CI workflow changes may ship without failure-mode evidence
  • Dependency or CI drift could surface after merge
  • 2 CI or workflow path(s) changed

Paths:

  • .github/workflows/termux-hub-static.yml
  • .github/workflows/termux-hub-tailnet-probe.yml
  • scripts/termux-hub/bootstrap.sh
  • scripts/termux-hub/health.sh
  • scripts/termux-hub/install-mcp.sh
  • scripts/termux-hub/preflight.sh
  • scripts/termux-hub/start-mcp.sh
  • termux_hub/__init__.py

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Sep 23, 2026

Copy link
Copy Markdown

ECC Tools / Reference Set Readiness

Commit: 623da833f4da130eb37de5e53078d460a614ede0

Reference set readiness gaps detected (neutral)

Reference evidence present for 1/7 areas (14%) across 12 changed file(s).

This check is based on files changed in this PR. Repository-level readiness is still reported by /ecc-tools analyze comments and generated manifests.

Area Status Evidence / Next Step
Deep analyzer corpus Missing Add analyzer fixture, golden, benchmark, or reference-set files that can catch analyzer regressions.
RAG/evaluator comparison Missing Add retrieval or evaluator reference-set comparison fixtures with expected ranking behavior.
PR salvage/review corpus Missing Add stale-PR, review-thread, reopen-flow, or salvage reference cases for queue cleanup automation.
Discussion triage corpus Missing Add public discussion triage fixtures, golden cases, or reference sets for informational, answered, and no-response classifications.
Harness compatibility Present tests/termux_hub/test_mcp_server.py
Security evidence Missing Attach security evidence such as SBOMs, SARIF, audit reports, or AgentShield evidence packs.
CI failure-mode evidence Missing Add captured CI failure logs, dry-run fixtures, or troubleshooting docs for common workflow failure modes.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Sep 23, 2026

Copy link
Copy Markdown

ECC Tools / Hosted Promotion Readiness

Commit: 623da833f4da130eb37de5e53078d460a614ede0

Hosted promotion readiness passed (success)

No hosted promotion evidence gaps detected across 12 changed file(s); 0 corpus scenarios had matching evidence.

This check compares PR file changes against the evaluator/RAG promotion corpus in src/analyzers/fixtures/evaluator-rag-corpus.ts.
Hosted output scoring inspected 0 completed cached hosted job results.

No evaluator corpus scenarios matched this PR.

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Sep 23, 2026

Copy link
Copy Markdown

ECC Tools / PR Config Audit

Commit: 623da833f4da130eb37de5e53078d460a614ede0

No changed-config issues detected (success)

Scanned 2 config file(s) present at this commit across 2 changed config path(s) and found no issues in the supported security rules.

Changed config files:

  • .github/workflows/termux-hub-static.yml
  • .github/workflows/termux-hub-tailnet-probe.yml

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

@ecc-tools

ecc-tools Bot commented Sep 23, 2026

Copy link
Copy Markdown

ECC Tools / PR Harness Audit

Commit: 623da833f4da130eb37de5e53078d460a614ede0

No harness issues detected (success)

Scanned 2 changed config file(s) and found no harness issues.

Changed config files:

  • .github/workflows/termux-hub-static.yml
  • .github/workflows/termux-hub-tailnet-probe.yml

Check publication was denied or unavailable. An app owner must enable Checks: read and write, and the installation owner must approve the updated permission.

This branch was successfully deployed

1 active (outdated) deployment
Preview – help-wanted-oversight — 877caa76 Deployed Sep 23, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

lane: direct Termux hub connection over Tailscale + collaborator bootstrap

2 participants