Skip to content

feat: install continuous curllm verification timer - #14

Merged
ifuri-validator-agent[bot] merged 1 commit into
mainfrom
ticket/008-install-autonomy
Oct 6, 2026
Merged

ifuri-validator-agent[bot] merged 1 commit into
mainfrom
ticket/008-install-autonomy

Conversation

@tom-sapletta-com

Copy link
Copy Markdown
Contributor

Install continuous curllm verification from a source revision already merged into origin/main, preserving uncommitted primary files and differing operator configuration. Export a versioned release, retain file digests, and stage a serialized user systemd timer with explicit activation. Preserve the supplied virtual-environment executable path instead of resolving it to global Python.

Default cycles run real Chromium/DSL, MCP/v2 and autonomy regressions, with durable deduplicated incident intake. Source digests are verified before each service start. Runtime repairs require explicit operator configuration; development findings await protected controller admission.

Validation: seven installer tests passed, both descriptors passed systemd-analyze verification, and an actual merged-source canary cycle passed all three probes (58 tests total, zero active incidents). Native governance passed. Runtime activation and first-cycle readback will follow protected merge under the user's recorded deployment authorization; AC-03 remains a post-merge action with external evidence.

@ifuri-validator-agent ifuri-validator-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Validator approval after policy checks for exact head f65fcfe8792d2c62ea7e5dec4af87d3f0f7388b0.

Ticket: ticket-008
Correlation ID: curllm008-deploy-autonomy-20261006
Model: openai/cursor-auto
Reviewed diff chunks: 2
Advisory LLM verdict: BLOCK
Advisory summary: Reviewed all 2 diff chunk(s). The PR chunk provides the configuration files and the installation script logic for extracting and verifying a merged release. The script uses secure methods to handle subprocesses (avoiding shell injections) and validates the contents of the tar archive before extraction, including rejecting symlinked paths or unsupported entries. | Required checks pass, and the visible tests cover release drift, operator-file preservation, symlink rejection, virtual-environment path retention, and quoted ExecStart arguments. However, systemd unit generation leaves WorkingDirectory vulnerable to directive injection through an unvalidated path.
Advisory findings: descriptors() interpolates release directly into WorkingDirectory after escaping only '%' characters. A release/data-root path containing a newline or carriage return can inject additional systemd directives into the generated service. Apply the same control-character rejection and systemd quoting used by systemd_quote(), and add an adverse test for newline-containing release paths.
The LLM output above is advisory and was not used as the approval trust root.
Semantic review prerequisite: not_required; policy 676cb4516bbfed2a000e40b9b1b6e4a430ecc761ec546aeb53d721a1905cfdd7.

Actual PR impact radar

Exact range: 13574ac8bfc62221d3192e2a0e29bb8988658732...f65fcfe8792d2c62ea7e5dec4af87d3f0f7388b0
Change digest: dd75b21e2bce8b292b491b904968563642e9d75ac6b9b62a2efd422b2dfb7e1b
Score: 68/100 (L), estimated 83 min, split recommended: true
Affected services/components: repository-wide/unclassified

Machine-readable radar JSONL and SVG
{"actual_change":{"additions":474,"base_sha":"13574ac8bfc62221d3192e2a0e29bb8988658732","binary_files":0,"categories":{"code":1,"configuration":1,"docs":2,"tests":1},"change_digest":"dd75b21e2bce8b292b491b904968563642e9d75ac6b9b62a2efd422b2dfb7e1b","comparison":"13574ac8bfc62221d3192e2a0e29bb8988658732...f65fcfe8792d2c62ea7e5dec4af87d3f0f7388b0","deletions":0,"file_count":5,"files":["README.md","project/ticket-008/README.md","project/ticket-008/intent.json","scripts/install-autonomy.py","scripts/test_install_autonomy.py"],"head_sha":"f65fcfe8792d2c62ea7e5dec4af87d3f0f7388b0","service_count":0,"services":[]},"assessment_mode":"observed-pr","axes":{"coupling":5,"delivery":3,"scope":4,"uncertainty":3,"validation":2},"complexity":"L","confidence":0.9,"diagnostics":["RADAR-ACCEPTANCE-MISSING","RADAR-BUDGET-EXCEEDED"],"estimate":{"budget_minutes":30,"minutes":83,"within_budget":false},"impact":{"components":["Chromium","MCP","origin","project","repository-root","scripts"],"files":["Chromium/DSL","MCP/v2","README.md","origin/main","project/ticket-008/README.md","project/ticket-008/intent.json","scripts/install-autonomy.py","scripts/test_install_autonomy.py"],"public_interfaces":[],"runtime_dependencies":0},"schema":"subactor.ticket-radar/v1","score":68,"split":{"parts":[{"estimated_minutes":13,"name":"Implement Chromium","scope":["Chromium"]},{"estimated_minutes":13,"name":"Implement MCP","scope":["MCP"]},{"estimated_minutes":13,"name":"Implement origin","scope":["origin"]},{"estimated_minutes":13,"name":"Implement project","scope":["project"]},{"estimated_minutes":13,"name":"Implement repository-root","scope":["repository-root"]},{"estimated_minutes":15,"name":"Validate and project to trackers","scope":["tests","planfile","github/gitlab/jira projections"]}],"reason":"estimated_minutes_exceed_budget","recommended":true},"standards":[{"id":"wellmanifest/dsl","revision":"6c60fc4e0dd1f1bb74f46a7745e28019908d1203","version":"0.1.0-dev"},{"id":"wellmanifest/ticket-lifecycle","revision":"5bf581907a87b46a13a73e6c033d3abe4d9a306f","version":"0.1.0-dev"},{"id":"wellmanifest/git-lifecycle","revision":"7d77d4b7af57e69bc75c3a0290b3a4805c5c4438","version":"0.2.0-dev"},{"id":"wellmanifest/logs","revision":"48c284ef7a069055c0bcb6b900147ce5e65f8b43","version":"0.3.0"}],"ticket_ref":"ticket-008"}
<svg xmlns="http://www.w3.org/2000/svg" width="128" height="128" viewBox="0 0 128 128" role="img"><title>ticket-008: feat: install continuous curllm verification timer</title><rect width="128" height="128" rx="12" fill="#f8fafc"/><g stroke-width="1"><polygon points="64,55 72,61 69,71 59,71 56,61" fill="none" stroke="#d7dde5"/><polygon points="64,47 80,59 74,78 54,78 48,59" fill="none" stroke="#d7dde5"/><polygon points="64,38 89,56 79,85 49,85 39,56" fill="none" stroke="#d7dde5"/><polygon points="64,30 97,53 84,92 44,92 31,53" fill="none" stroke="#d7dde5"/><polygon points="64,21 105,51 89,99 39,99 23,51" fill="none" stroke="#d7dde5"/><line x1="64" y1="64" x2="64" y2="21" stroke="#aab4c0"/><line x1="64" y1="64" x2="105" y2="51" stroke="#aab4c0"/><line x1="64" y1="64" x2="89" y2="99" stroke="#aab4c0"/><line x1="64" y1="64" x2="39" y2="99" stroke="#aab4c0"/><line x1="64" y1="64" x2="23" y2="51" stroke="#aab4c0"/></g><polygon points="64,30 105,51 79,85 54,78 39,56" fill="#fb923c" fill-opacity="0.45" stroke="#c2410c" stroke-width="2"/><circle cx="64" cy="64" r="3" fill="#c2410c"/><g font-family="sans-serif" font-size="7" fill="#334155"><text x="64" y="11" text-anchor="middle">SCO</text><text x="114" y="48" text-anchor="middle">COU</text><text x="95" y="107" text-anchor="middle">UNC</text><text x="33" y="107" text-anchor="middle">VAL</text><text x="14" y="48" text-anchor="middle">DEL</text></g><text x="64" y="124" text-anchor="middle" font-family="sans-serif" font-size="8" fill="#0f172a">L · 83m</text></svg>
Merge will be attempted after this approval when explicitly authorized. ## Decision record (recomputable)
DECISION D-008-4470
TICKET ticket-008
HEAD_SHA f65fcfe8792d2c62ea7e5dec4af87d3f0f7388b0
CORRELATION_ID curllm008-deploy-autonomy-20261006
ACTOR agent:ifuri-validator-agent[bot]
APPLIED_RULE P-CORE-015
INPUT author_login = "tom-sapletta-com"
INPUT observed_checks = ["metadata=PASS","governance / remote lifecycle=PASS","governance / enforce=PASS"]
INPUT required_checks = ["metadata","governance / enforce","governance / remote lifecycle"]
INPUT required_checks_source = "protected registry (env/request)"
INPUT reviewer_login = "ifuri-validator-agent[bot]"
INPUT semantic_review_assessment = {"schema":"subactor.validator/semantic-review-assessment/v1","subject":{"repository":"autogrammar/curllm","pull_request":14,"head_sha":"f65fcfe8792d2c62ea7e5dec4af87d3f0f7388b0","base_sha":"13574ac8bfc62221d3192e2a0e29bb8988658732","diff_sha256":"f962821cba76a36c215c0815976c9c04c8b869d441459be9a10e714e35225e55"},"policy":{"policy_schema":"subactor.validator/semantic-review-policy/v1","policy_version":1,"policy_sha256":"676cb4516bbfed2a000e40b9b1b6e4a430ecc761ec546aeb53d721a1905cfdd7","required":false,"critical_paths":[],"observed_paths":["README.md","project/ticket-008/README.md","project/ticket-008/intent.json","scripts/install-autonomy.py","scripts/test_install_autonomy.py"]},"grounding":"full-diff-not-per-finding-proof","execution_authority":false,"status":"not_required","reason":null,"review_sha256":null,"unresolved":[]}
INPUT superseded_checks = []
INPUT ticket_radar_receipt = {"schema":"subactor.ticket-radar/v1","base_sha":"13574ac8bfc62221d3192e2a0e29bb8988658732","head_sha":"f65fcfe8792d2c62ea7e5dec4af87d3f0f7388b0","change_digest":"dd75b21e2bce8b292b491b904968563642e9d75ac6b9b62a2efd422b2dfb7e1b","score":68,"complexity":"L","estimated_minutes":83,"split_recommended":true,"services":[],"authority":"ADVISORY","promotion":"FORBIDDEN"}
VERDICT APPROVE AUTHORITY DETERMINISTIC
REJECTED REQUEST_CHANGES BECAUSE NO_UNSAFE_CHANGE_REASON_FOUND
ADVISORY llm_verdict = "BLOCK" MODEL "openai/cursor-auto"
ASSERT VERDICT_AUTHORITY != "ADVISORY"

@ifuri-validator-agent
ifuri-validator-agent Bot merged commit 802d9f7 into main Oct 6, 2026
3 checks passed
@ifuri-validator-agent
ifuri-validator-agent Bot deleted the ticket/008-install-autonomy branch October 6, 2026 18:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant