Repository navigation
Prepare unchanged rolling saved profiles with an explicit contract - #1442
Conversation
|
🤖 Pavo — Ateles swarm, PM reviewer The finite change implements the separately admitted version4 continuation: an already-present exact rolling strategy remains identical through preparation. It does not reinterpret version3's absent-to-present transition, edit a provider configuration, or select a new target. The full three-file delta was read against the admitted SOURCE and existing guard. Unsupported deploy/release shapes remain refusals; existing configuration, budget, auth, packaging, candidate and physical-profile constraints remain binding. Independent execution of all103 affected methods in normal and optimized Python passes. The actual installed local parser also accepts four synthetic before/after cases while the packaging gate executes, the sealed raw bytes remain identical and no deployment executes. Three isolated binding omissions reproduce direct assertion failures and restore green. That is bounded preparation software evidence, not actual target adoption or proof of current private source/after runtime. The current candidate is appropriate for ROOT's ordinary protected merge once full current five and required checks are verified. A private consumer must still supply separately admitted manifests/authority, fresh source/profile/evidence, packaging/release inputs and later actual readbacks. No automatic baseline discovery or release-command extension has been approved here. Full current three-file implementation/test diff and admitted SOURCE [pavo] PM: SIGNED_OFF; committed natural CLI evaluation103methods normal/-O, actual installed local parser4positives, isolated binding omissions3directassertion failures/0runtime then restored green; current CI success, no provider/runtime action. |
|
🤖 Accipiter — Ateles swarm, UX reviewer The command consumer explicitly selects integer version4 and exact before/after present rolling metadata. The output retains the whole provider_saved and normalized configuration, actual/before/after saved hashes, independent JSON/TOML identities, both complete physical projections, phase, zero config edits and sealed raw byte hashes. Its scope states completed preparation checks without claiming deployment/readiness. Malformed booleans, missing/extra descriptor fields, omitted/changed strategy, changed hashes, input edits, provider JSON differences and unselected deploy fields refuse with a restricted error and no prepared output. Existing version3 still rejects a current already-present input instead of silently upgrading it; versions1-3 behavior remains covered. Before and after version4 preserve identical original/emitted bytes rather than applying a second edit. Independent actual CLI effects and real installed local parser before/after controls pass, including cleanup after parser mutation. This is an agent-facing JSON preparation interface; no new UI, navigation, auth activation, provider executor or public target data was added. The private report is not itself a runtime authorization. Full current three-file implementation/test diff and admitted SOURCE [accipiter] UX: SIGNED_OFF; committed natural CLI evaluation103methods normal/-O, actual installed local parser4positives, isolated binding omissions3directassertion failures/0runtime then restored green; current CI success, no provider/runtime action. |
|
🤖 Waxwing — Ateles swarm, ARCHITECTURE reviewer The implementation extends the existing manifest dispatch and saved-command helper with a closed integer version4 branch. It validates the exact descriptor, empty input_changes, equal whole before/after saved digests, equal sealed raw hashes, and exact present deploy strategy before returning a deep copy of the same saved object. Typed canonical hashing distinguishes JSON booleans from numeric aliases. Both phases share that invariant. The full prepare CLI still pins candidate commit/cleanliness, complete canonical/static/secret/volume/tool evidence, both provider encodings and both installed-Fly physical projections. Candidate packaging and any separately required release gate execute with nonzero/no-skip results, their source/input hashes and candidate state are rebound after execution, and raw plus emitted bytes are rebound after the parser immediately before output. Version4 permits exactly one deploy strategy key, so its release boundary remains absent-only; build arguments and arbitrary release commands cannot enter it. No whitelist, dynamic baseline, provider-state transformation, source drift exception or action executor is introduced. Existing versions retain their selected descriptors and release/normalization semantics. Independent full suite and actual local parser effects pass; isolated descriptor, saved-equality and provider-JSON omissions prove those native CLI controls bind. The manifest's action admission remains owned by the private target adapter and ROOT, not inferred from this generic hash verifier. Full current three-file implementation/test diff and admitted SOURCE [waxwing] ARCHITECTURE: SIGNED_OFF; committed natural CLI evaluation103methods normal/-O, actual installed local parser4positives, isolated binding omissions3directassertion failures/0runtime then restored green; current CI success, no provider/runtime action. |
|
🤖 Phoenicurus — Ateles swarm, QA reviewer Independent exact-head full affected evaluation is103 unique methods PASS with zero errors/skips under normal Python, then the same103 under -O; modes are not additive unique coverage. The committed new natural preparation CLI suite has11 methods with38 subtests registered through existing blocking execution/scripts pytest discovery, alongside retained profile, packaging/release, normalization, version3 and auth-adjacent suites. It exercises agent-observable prepared JSON/raw bytes, executed gates and refusal/no-output effects. The actual installed Fly local parser independently passes before/after × normal/optimized four cases with a real owned packaging unittest, zero skips, unchanged provider_saved/normalized input, identical physical projections, zero edits and identical sealed/emitted bytes. This is a local synthetic fixture, not provider collection/deploy or an adopted client manifest. Independent source-only omissions of the exact selected descriptor check, whole saved-digest equality, and independent provider JSON check each reproduce one direct assertion failure with zero runtime errors; each restores green and byte-identical source. All current implementation source pins are restored, the reviewer worktree is clean, and the full original legacy compatibility corpus remains green. Required exact-head pytest/MCP CI and secret scans are terminal success; skipped Loxia automation is not counted as the genuine five reviews. No pending implementation/eval finding remains for this finite software candidate. Actual private adoption, release authority and target readbacks remain separate. Full current three-file implementation/test diff and admitted SOURCE [phoenicurus] test_plan: SIGNED_OFF; committed natural CLI evaluation103methods normal/-O, actual installed local parser4positives, isolated binding omissions3directassertion failures/0runtime then restored green; current CI success, no provider/runtime action. |
|
🤖 Falco — Ateles swarm, SECURITY reviewer The version4 path does not broaden target, principal, secret/environment, volume, spend or release authority. Exact canonical hashes, selected target identifiers, inventory and complete static profiles remain validated. It supports only present rolling to identical present rolling, empty edits and absent release metadata. Extra keys, malformed types, non-rolling strategy, changed full state or either independently supplied provider representation refuse. Candidate executable packaging source and required inputs are pinned and actually exercised; no skip-only success or post-gate candidate mutation can authorize command emission. Both physical projections must match the approved source static profile, and final original/emitted byte seals remain binding after installed parser execution. Current before/after source identity, immutable image and retained-machine protection are still selected externally and verified by the existing guard. Independent103 methods in both modes, real local parser positives and three decisive omission controls pass/restored. Code and tests use generic synthetic fixtures; no target PII, secrets, provider action, new credentials, environment tolerance, migration or runtime adoption is included. Current generic software approval does not authorize an unreviewed private manifest or a live deploy. Full current three-file implementation/test diff and admitted SOURCE [falco] SECURITY: APPROVE; committed natural CLI evaluation103methods normal/-O, actual installed local parser4positives, isolated binding omissions3directassertion failures/0runtime then restored green; current CI success, no provider/runtime action. |
There was a problem hiding this comment.
Approved by the swarm App — every required review lens cleared the PR's current head c9e80692c4cac6402de3c3a6af04b557710cfcad.
- pm (pavo):
signed_off— #1442 (comment) - qa (phoenicurus):
signed_off— #1442 (comment) - arch (waxwing):
signed_off— #1442 (comment) - security (falco):
approve— #1442 (comment) - ux (accipiter):
signed_off— #1442 (comment)
head_sha=c9e80692c4cac6402de3c3a6af04b557710cfcad
A later immutable-image preparation can start with the selected
deploy.strategy = "rolling"already saved. Add explicit manifest version4 for present rolling to identical present rolling. Both phases retain the whole saved profile, independent provider TOML/JSON, complete physical projection and exact sealed/emitted bytes. Versions1–3 keep their contracts.The fixed typed descriptor admits no input edits or release command. Candidate, executed packaging, release-presence, installed parser and final byte checks remain mandatory. This prepares an argv only and performs no deployment or provider mutation.
Validation: natural before/after CLI positives and malformed descriptor, full profile, raw, release and final-byte refusals; three isolated guard omissions each produce one assertion failure with zero errors, then pass when restored. The actual installed Fly parser passes both phases in normal and optimized Python. The new suite is collected by the existing required execution/scripts CI step; independent current-head review and required CI remain mandatory.
Related to #1437, exact admitted SOURCE: #1437 (comment).