Skip to content

feat(ci): require external review for soundness paths - #2444

Merged
joeharris76 merged 9 commits into
developfrom
fix/dev-loop-v2-soundness-hold
Sep 29, 2026
Merged

joeharris76 merged 9 commits into
developfrom
fix/dev-loop-v2-soundness-hold

Conversation

@joeharris76

@joeharris76 joeharris76 commented Sep 28, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • Require external soundness review evidence for manifest paths.
  • Execute the soundness checker from the immutable base revision, with a trusted legacy bootstrap path for the first rollout.
  • Re-run validation when PR body evidence changes.
  • Add tooling to the documented required merge-queue status contract.

Soundness review:

External reviewer: codex
Review output: #2444 (comment)
All Critical/High findings resolved.

Validation

  • 440 focused tests passed.
  • Ruff check and format checks passed.
  • Workflow YAML parsing passed.
  • Full local preflight reached 32,181 tests, with 59 unrelated baseline failures on macOS.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-28T21:23:16.981251Z d3f3e5c PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: d3f3e5ce83

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread .github/workflows/ci.yml
Comment thread .github/workflows/ci.yml Outdated
Comment thread .github/workflows/ci.yml
@joeharris76
joeharris76 added this pull request to the merge queue Sep 29, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to no response for status checks Sep 29, 2026
GitHub documents the function as toJson; the allowlist only had toJSON, so the new ci.yml merge-group usage failed the guard. Accept both casings.
The soundness-flag step crashed with 'Cannot iterate over null' when the
merge_group event carried no pull_requests payload, failing the tooling
check for every queue group and bouncing grouped PRs. Fall back to
validating the merged tree directly when the payload is absent.
When the merge_group payload carries no pull_requests list, derive the
anchor PR from the gh-readonly-queue branch name, verify its head is an
ancestor of the group HEAD via the API, validate the anchor member, then
validate the full base-to-head group diff so soundness paths elsewhere
in the group cannot slip through.
@joeharris76
joeharris76 force-pushed the fix/dev-loop-v2-soundness-hold branch from 4936484 to 6f14c93 Compare September 29, 2026 11:44
@joeharris76
joeharris76 added this pull request to the merge queue Sep 29, 2026
The queue squashes the anchor PR onto the group base, so the anchor head
is never an ancestor of the group HEAD. The ancestry check failed every
queued soundness-path PR. Compare each anchor-changed file byte-for-byte
between the anchor head and the group HEAD instead.
@joeharris76
joeharris76 removed this pull request from the merge queue due to a manual request Sep 29, 2026
@joeharris76
joeharris76 added this pull request to the merge queue Sep 29, 2026
Merged via the queue into develop with commit 6ab697f Sep 29, 2026
45 checks passed
@joeharris76
joeharris76 deleted the fix/dev-loop-v2-soundness-hold branch September 29, 2026 14:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant