Repository navigation
chore: update pull request - #10
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Intent
Fix the three independently reproduced CP-06 contract defects while preserving all prior CP-06 and PR9 commits: constrain schema-valid empty context.required selections to mandatory global authority instead of unrestricted CTX retrieval; require fresh-worker replay evidence to correlate successful read start/end events, exact canonical original bytes and digest, decisive full-range text, and reject failed, partial, wrong-range, incomplete, or extra-project reads; exercise recovery of a concrete omitted creation-ownership rule; and remove the critical in-memory auth fixture cross-tenant identifier existence oracle while preserving normal API and auth negative behavior. Preserve existing architecture and do not alter CTX, Firstmate, no-mistakes, deployed security systems, live accounts, routing, or shipping configuration. Use disposable isolated evidence with no credentials or raw transcripts retained, enforce Linux-only read-only credential mount isolation with safe failure when unsupported, and document the limitation. Validate full npm checks, deterministic regressions, real CTX ten-pack and bad/blocked paths, fresh Pi worker evidence, P-07 fail-before/fix-after/retest, exact-head/source-digest integrity, and diff checks. Do not merge.
What Changed
Final changed paths and statuses:
Risk Assessment
✅ Low: The changes are well-scoped to CP-06 context scoping, replay evidence, and credential-isolation proofing, with no substantiated merge-blocking defects found in the reviewed diff.
Testing
Exercised the targeted CP-06 regressions and end-to-end proofs: schema/CTX scoping, worker read-audit rejection cases, auth fixture behavior, Linux credential mount isolation, real ten-pack CTX proof, P-07 fail-before/fix-after/retest, fresh Pi worker recovery of the omitted ownership rule, and exact-head diff check; all commands passed and transient build/dependency outputs were removed from the worktree.
Evidence: CP-06 ten-pack proof manifest
Evidence: P-07 replay proof manifest
Evidence: Fresh Pi worker proof manifest
Evidence: Exact-head diff check
Pipeline
Updates from git push no-mistakes
✅ **intent** - passed
✅ No issues found.
✅ **Rebase** - passed
✅ No issues found.
🔧 **Review** - 2 issues found → auto-fixed ✅
scripts/replay-cp06-worker.mjs:98- The isolated auth path is only a symlink inside a writable evaluation agent directory, so a normal atomic credential refresh can write a temp file and rename it over auth.json without following the read-only symlink. That leaves the fresh Pi worker able to create credential state in the disposable home despite the required "read-only credential mount isolation" / "no credential copy/export" constraint; bind-mount the credential read-only onto the actual isolated auth path or otherwise OS-deny replacement/unlink at that path before running Pi.scripts/replay-cp06-worker.mjs:99- The denied-write probe iterates over credentialSource and attempts writeFile against the caller's real Pi auth file. The accepted requirement was to use dummy credentials for denied write probes and perform "no original-file writes"; even though the mount should reject it, this is still an intentional write attempt to the original credential path. Probe destructive writes against a dummy/read-only fixture and only expose the live credential through the proven read-only mechanism.🔧 Fix: Harden CP-06 credential isolation
✅ Re-checked - no issues remain.
✅ **Test** - passed
✅ No issues found.
npm cinpm run build && node --test test/cp06-credential-isolation.test.mjs test/cp06-worker-audit.test.mjs dist/test/context.test.js dist/test/workflow.test.jsCP06_OUTPUT=/home/ansh/.treehouse/Factory-86709f/8/Factory/.factory/state/cp06-final-correction/no-mistakes/home/evidence/01M3Q8K3A6FJJNJPXAE19VQH4R/cp06-proof npm run proof:cp06:ten-packCP06_OUTPUT=/home/ansh/.treehouse/Factory-86709f/8/Factory/.factory/state/cp06-final-correction/no-mistakes/home/evidence/01M3Q8K3A6FJJNJPXAE19VQH4R/cp06-proof npm run proof:cp06:p07CP06_OUTPUT=/home/ansh/.treehouse/Factory-86709f/8/Factory/.factory/state/cp06-final-correction/no-mistakes/home/evidence/01M3Q8K3A6FJJNJPXAE19VQH4R/cp06-proof npm run proof:cp06:workergit diff --check 8337ab7fcc5b511d3cb359ea214b6ae18003aeaa..HEAD✅ **Document** - passed
✅ No issues found.
✅ **Lint** - passed
✅ No issues found.
✅ **Push** - passed
✅ No issues found.