Repository navigation
Conversation
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 92c33932ee
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: cc57a33bd6
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: d4aa1ce84f
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: c9ec495fda
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: f4003860f9
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
f400386 to
4f0e61b
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 4f0e61b667
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
4f0e61b to
7df9a46
Compare
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 7df9a469d5
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| measured-exceedance receipt against base `8591730ffe5708b785055488e902fad1a7e63c5a`: | ||
| family digest `97cdab30f667cb780957d599a98733e5a72bd708ccb7135f26912b6a12ad3011`, | ||
| 210 generated files, 21,788,470 changed generated bytes, and 39,347,035 tracked |
There was a problem hiding this comment.
Point the completion report at the committed KAG family
The committed family manifest identifies digest 6da91910... and its matching receipt records parent 48002943..., 214 generated files, and 22,046,743 changed bytes, but this report instead presents the intermediate 97cdab30... receipt against 8591730f... as the final refresh. Consumers following the completion artifact therefore verify a family other than the one actually committed; update these provenance values to match kag/indexes/index_family.manifest.json and its current receipt.
AGENTS.md reference: AGENTS.md:L197-L198
Useful? React with 👍 / 👎.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: b5e2c41022
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: c04e1d752e
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
c04e1d7 to
2410069
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: ca3beb3529
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: ccd6598622
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| "path": "mechanics/runtime-lifecycle/parts/live-code-intelligence/live_code_intelligence.py", | ||
| "lines": 3761, | ||
| "sha256": "2d96fb28428cbf7116ab0683ed3dcb5b5507f547e539eb535712dcd8ba96c9ab" |
There was a problem hiding this comment.
Regenerate source evidence after the final code additions
The committed provider blob is 3,990 lines with SHA-256 0e0db28c..., not the recorded 3,761 lines and 2d96fb28...; its test blob is likewise 985 lines rather than 926, and several other entries in changed_source_evidence also disagree with the target commit. Because this completion artifact claims to carry exact changed-path hashes, consumers cannot verify the final LSP-enabled source from it; regenerate these records from the final commit contents.
AGENTS.md reference: AGENTS.md:L193-L194
Useful? React with 👍 / 👎.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: d40f8b2009
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: b5d83410ff
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 2cd4c2ccd6
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 8fc718a092
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 659e0d2cd2
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 89422377b1
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: a5c11269e0
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 52673b4a2e
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 95f6c87bcc
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 73880f48b0
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 9c4869eb38
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 24902f4faf
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 5debee46ed
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 4ec2879750
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: df6500761e
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 791cb75f66
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 7ecb274dd9
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| if not set(invalidated or []).issubset(set(universe_paths)): | ||
| return False | ||
| if not set(added or []).issubset(set(changed or [])): | ||
| return False | ||
| if not set(reused or []).issubset(set(files)): |
There was a problem hiding this comment.
Authenticate persisted invalidation metadata
When a same-UID process rewrites current.json while the working-tree bytes remain unchanged, these subset checks accept fabricated transition metadata; for example, it can replace a first build's changed/added/invalidated paths with empty lists, mark the file reused, set full_rebuild false, update the mirrored envelope/provenance, and status() still reports current. Fresh evidence beyond the prior persisted-observation findings is that source rederivation now verifies files only, leaving the diagnostic invalidation history unauthenticated; bind the complete transition state to owner-backed evidence or verify it against an authenticated prior snapshot.
AGENTS.md reference: AGENTS.md:L290-L291
Useful? React with 👍 / 👎.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 7ecb274dd9
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| # state committed by this still-live runtime instance may be | ||
| # used until an owner-backed immutable epoch store exists. | ||
| return self._trusted_observation_digests.get(source_epoch) == ( | ||
| _digest_payload(files) |
There was a problem hiding this comment.
Persist historical-state trust across CLI invocations
When an operator runs refresh, edits the source, and runs refresh again through the documented CLI, the second invocation creates a new runtime whose _trusted_observation_digests is empty, so this branch rejects the prior current state as soon as its epoch differs from disk. Consequently compatible becomes false, the previous state is never copied to last-good.json, and a later standalone rollback also rejects any historical target created by a resident process. Fresh evidence beyond the earlier historical-state finding is that main() constructs a new runtime for every operation, making this process-local authentication incompatible with the advertised cross-command lifecycle; preserve historical authentication in an owner-backed cross-process store.
Useful? React with 👍 / 👎.
| "owner": {"const": "abyss-machine"}, | ||
| "key_id": {"type": "string", "minLength": 1}, | ||
| "algorithm": {"const": "ed25519"}, | ||
| "public_key": {"type": "string", "minLength": 1} |
There was a problem hiding this comment.
Constrain the trust-anchor key to an Ed25519 encoding
When abyss-machine validates a trust anchor against this public schema, any nonempty string is accepted as public_key, but _machine_gate_trust_anchor() subsequently requires valid base64 decoding to exactly 32 bytes. A schema-valid anchor such as "x" therefore cannot be consumed by the runtime; encode the fixed Ed25519 public-key base64 shape and length in the authored schema so provisioning fails at the contract boundary.
Useful? React with 👍 / 👎.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 06013ffc5c
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| marker = "/".join(parts[start:marker_end] + ["__init__.py"]) | ||
| if marker in known: |
There was a problem hiding this comment.
Preserve source prefixes when matching package markers
When a package is nested under nonconventional monorepo directories, such as workspace/vendor/pkg/provider.py with workspace/vendor/pkg/__init__.py, this constructs vendor/pkg/__init__.py rather than the source-relative marker, so _module_name_variants() never emits pkg.provider. A change to that provider consequently leaves a from pkg.provider import ... consumer in reused_paths instead of dependency-invalidating it; probe markers with their full source-relative prefix while deriving the corresponding import-root suffix.
Useful? React with 👍 / 👎.
|
|
||
| def _reader_loop(self) -> None: | ||
| try: | ||
| while self._process is not None and self._process.poll() is None: |
There was a problem hiding this comment.
Record child exit instead of silently stopping the reader
When an LSP child exits after returning a successful response but before the reader begins its next iteration, this condition terminates the loop without reading EOF or calling _fail_pending(). _last_error therefore remains empty, and snapshot() reports the stopped generation as starting rather than degraded; future requests also fail without correcting that lifecycle state. Detect a non-running child as EOF/failure unless the session is intentionally closing.
Useful? React with 👍 / 👎.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 7c1e9a4b76
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| descriptor = os.open(path, flags, 0o400) | ||
| encoded = ( | ||
| _canonical_json(record) + "\n" | ||
| ).encode("utf-8") | ||
| offset = 0 | ||
| while offset < len(encoded): | ||
| offset += os.write(descriptor, encoded[offset:]) | ||
| os.fchmod(descriptor, 0o400) |
There was a problem hiding this comment.
Store historical trust outside the mutable state root
When another process running as the provider UID can write state_root, O_EXCL and mode 0400 do not make this record immutable: the process can unlink the record or its epoch directory and recreate both the persisted snapshot and a matching digest record. _persisted_observations_match_source() and _persisted_invalidation_matches_source() then accept the fabricated historical state once its source bytes are no longer available. Fresh evidence beyond the earlier cross-process-trust finding is that the new durable implementation places its purported trust anchor under the same UID-writable state root; authenticate it through an owner-protected location or keyed evidence instead.
AGENTS.md reference: AGENTS.md:L290-L291
Useful? React with 👍 / 👎.
| "claim_limits_digest": {"type": "string", "pattern": "^sha256:[0-9a-f]{64}$"} | ||
| } | ||
| }, | ||
| "signature": {"type": "string", "minLength": 1}, |
There was a problem hiding this comment.
Constrain signatures to the Ed25519 encoding
When an abyss-machine producer validates a gate bundle against this public schema, any nonempty signature is accepted, but _validate_machine_evidence_gate_bundle() later calls _base64_bytes(..., length=64) and rejects values that are not valid base64 decoding to exactly 64 bytes. This lets schema-valid owner evidence fail only at runtime admission; encode the canonical 64-byte Ed25519 signature shape and length here.
Useful? React with 👍 / 👎.
| last_good_available = bool( | ||
| self._state_identity_matches_config(existing_last_good) | ||
|
|
There was a problem hiding this comment.
Reuse validated states when building status pointers
When status() has a valid current snapshot matching the working-tree epoch, this call validates it a second time after current_valid was already computed above. That validation reaches _persisted_observations_match_source(), which scans and reparses the complete source tree, so every ordinary status request performs two full scans/parses of an admitted tree (and can repeat work for other populated pointers), doubling latency and CPU for large repositories. Pass the already-computed validity result into pointer() instead of revalidating the same payload.
Useful? React with 👍 / 👎.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 7b63585c03
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| package_start = marker_end - (2 if is_package_init else 1) | ||
| candidate = module_parts[package_start:] |
There was a problem hiding this comment.
Derive package initializer names from the marker
When a package initializer is nested below nonconventional directories, such as workspace/vendor/pkg/__init__.py, this is_package_init offset emits vendor.pkg rather than pkg. Consequently, changing that initializer leaves a consumer containing from pkg import VALUE in reused_paths instead of dependency-invalidating it; derive the suffix from the directory containing the matched package marker.
Useful? React with 👍 / 👎.
| flags |= os.O_NOFOLLOW | ||
| descriptor: int | None = None | ||
| try: | ||
| descriptor = os.open(path, flags, 0o400) |
There was a problem hiding this comment.
Publish historical trust records atomically
When the process crashes or an I/O error occurs after this target file is created but before its JSON is completely written and synced, a partial read-only trust record remains at the final content-addressed path. The next refresh hits FileExistsError, reads the malformed record as a conflict, and can never promote that same source epoch without manual deletion; write and sync a temporary file before atomically publishing the final record.
Useful? React with 👍 / 👎.
left a comment
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: df5fb00fd6
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| label="LSP script interpreter", | ||
| ) | ||
| descriptors.append(interpreter_descriptor) | ||
| executable_ref = f"/proc/self/fd/{executable_descriptor}" |
There was a problem hiding this comment.
Preserve executable FDs across bubblewrap exec
When an admitted LSP session reaches launch, the sandboxed command names the executable—and sometimes its interpreter—as /proc/self/fd/<fd>, but _sandbox_command() never adds --keep-fd for those descriptors. The Bubblewrap command reference documents --keep-fd FD as the option that prevents an FD from being closed when executing the sandboxed process; subprocess.pass_fds only carries these FDs into bubblewrap. Bubblewrap therefore closes the memfd before the payload resolves /proc/self/fd/..., preventing the LSP child from starting; keep the executable/interpreter descriptors explicitly or execute their sealed read-only bindings instead.
Useful? React with 👍 / 👎.
| for system_root in ("/bin", "/etc", "/lib", "/lib64", "/sbin", "/usr"): | ||
| if Path(system_root).exists(): | ||
| sandbox.extend(("--ro-bind", system_root, system_root)) |
There was a problem hiding this comment.
Hide system-backed source roots before mounting the snapshot
When the admitted source root is beneath one of these host mounts—for example /usr/src/project—the whole host /usr tree remains visible under the individually overlaid sealed source files. The Bubblewrap command reference defines --ro-bind as a read-only bind of the host source, while the later --ro-bind-data options replace only named files, so a file added to /usr/src/project after admission remains visible to the LSP even though it is absent from the signed source manifest. Fresh evidence beyond the earlier missing-source-mount finding is that the admitted snapshot is now mounted but does not mask its host-backed parent; reject such roots or place an empty mount over the source directory before binding sealed files.
AGENTS.md reference: mechanics/AGENTS.md:L63-L65
Useful? React with 👍 / 👎.
left a comment
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 642d204916
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| f"{label}.source_root is required for observed LSP sessions" | ||
| ) | ||
| _non_empty_string(session.get("transport"), f"{label}.transport") | ||
| _non_empty_string(session.get("source_epoch"), f"{label}.source_epoch") |
There was a problem hiding this comment.
Bind LSP epochs to their source manifests
When authenticated machine evidence contains a stale or mistyped source_epoch alongside a correct current source_manifest, this validation accepts the epoch as any nonempty string, while ManagedLspSession verifies the manifest independently without confirming that it derives that epoch. The child can therefore read one exact source snapshot while its session evidence and responses claim another epoch, corrupting downstream cache and attribution; validate the epoch format and cryptographically bind or recompute it from the admitted manifest and configuration.
AGENTS.md reference: AGENTS.md:L290-L291
Useful? React with 👍 / 👎.
| self.notify("initialized", {}) | ||
| self._last_good_at = _now() |
There was a problem hiding this comment.
Validate InitializeResult before marking the LSP healthy
When the server answers initialize with a matching, valid JSON-RPC response whose result is null or lacks the required capabilities object, request() treats it as successful and these lines send initialized and mark the session observed. A broken or incompatible child is consequently exposed as healthy even though initialization never produced a usable LSP result; validate the InitializeResult structure before notifying the server or setting _last_good_at.
Useful? React with 👍 / 👎.
left a comment
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 2101d3b893
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| if self._source_epoch(scanned) != source_epoch: | ||
| # A historical snapshot has no live source bytes to rederive | ||
| # aga |
There was a problem hiding this comment.
Avoid reparsing every file during no-op refreshes
When refresh() runs again without source changes, validating previous_current reaches this call and reparses the entire admitted tree before delta invalidation determines that every path is reusable. I reproduced two _parse_file calls for two unchanged files on the second refresh, so a nominal no-op refresh at the 4,096-file/256 MiB envelope still incurs whole-tree parsing and can become prohibitively slow; consult the authenticated durable/in-memory observation digest before source rederivation or reuse the already validated scan.
Useful? React with 👍 / 👎.
| "artifact_ref" | ||
| ], | ||
| "properties": { | ||
| "provider": {"type": "object"}, |
There was a problem hiding this comment.
Constrain the subject provider in the public schema
When an abyss-machine producer validates evidence against this public schema, an empty or arbitrarily shaped subject.provider object is accepted, but _validate_machine_evidence_payload() later requires it to equal the complete configured provider identity. Consequently a schema-valid, signed bundle can fail only at runtime admission; encode the required provider fields, constants, and additionalProperties policy in this schema.
Useful? React with 👍 / 👎.
PLAN
mainat8591730ffe5708b785055488e902fad1a7e63c5a; only the canonical source, required reports, active-schema regression, and derived KAG family are in scope.DIFF
aoa-kag@578e4cea9a04b76a881bde240d5479efceea4926generator and final digest-bound measured-exceedance receipt against base8591730ffe5708b785055488e902fad1a7e63c5a: digest97cdab30f667cb780957d599a98733e5a72bd708ccb7135f26912b6a12ad3011, 210 generated files, 21,788,470 changed generated bytes, and 39,347,035 tracked bytes. No standing budget was raised; this is navigation data only.VERIFY
python3 scripts/validate_stack.py, andpython3 scripts/validate_nested_agents.pypassed.python3 scripts/ci_gate.py --mode source-fastpassed through stack validation but is blocked by the unavailable localaoa-statsvalidator.python3 scripts/ci_gate.py --mode testscollected 2,796 tests but is blocked by seven collection errors: six installed-MCP API errors plus the unavailableaoa_sdk.contracts.programmatic_executionmodule from the rebased base seam.REPORT
mechanics/runtime-lifecycle/parts/live-code-intelligence/; the exact G59 provider-neutral consumer ABI remains available without admitting the unsigned G59 artifact.reports/live-code-intelligence-direction-completion.jsonand.md.RESIDUAL RISK