Repository navigation
feat: install continuous curllm verification timer - #14
Conversation
There was a problem hiding this comment.
Validator approval after policy checks for exact head f65fcfe8792d2c62ea7e5dec4af87d3f0f7388b0.
Ticket: ticket-008
Correlation ID: curllm008-deploy-autonomy-20261006
Model: openai/cursor-auto
Reviewed diff chunks: 2
Advisory LLM verdict: BLOCK
Advisory summary: Reviewed all 2 diff chunk(s). The PR chunk provides the configuration files and the installation script logic for extracting and verifying a merged release. The script uses secure methods to handle subprocesses (avoiding shell injections) and validates the contents of the tar archive before extraction, including rejecting symlinked paths or unsupported entries. | Required checks pass, and the visible tests cover release drift, operator-file preservation, symlink rejection, virtual-environment path retention, and quoted ExecStart arguments. However, systemd unit generation leaves WorkingDirectory vulnerable to directive injection through an unvalidated path.
Advisory findings: descriptors() interpolates release directly into WorkingDirectory after escaping only '%' characters. A release/data-root path containing a newline or carriage return can inject additional systemd directives into the generated service. Apply the same control-character rejection and systemd quoting used by systemd_quote(), and add an adverse test for newline-containing release paths.
The LLM output above is advisory and was not used as the approval trust root.
Semantic review prerequisite: not_required; policy 676cb4516bbfed2a000e40b9b1b6e4a430ecc761ec546aeb53d721a1905cfdd7.
Actual PR impact radar
Exact range: 13574ac8bfc62221d3192e2a0e29bb8988658732...f65fcfe8792d2c62ea7e5dec4af87d3f0f7388b0
Change digest: dd75b21e2bce8b292b491b904968563642e9d75ac6b9b62a2efd422b2dfb7e1b
Score: 68/100 (L), estimated 83 min, split recommended: true
Affected services/components: repository-wide/unclassified
Machine-readable radar JSONL and SVG
{"actual_change":{"additions":474,"base_sha":"13574ac8bfc62221d3192e2a0e29bb8988658732","binary_files":0,"categories":{"code":1,"configuration":1,"docs":2,"tests":1},"change_digest":"dd75b21e2bce8b292b491b904968563642e9d75ac6b9b62a2efd422b2dfb7e1b","comparison":"13574ac8bfc62221d3192e2a0e29bb8988658732...f65fcfe8792d2c62ea7e5dec4af87d3f0f7388b0","deletions":0,"file_count":5,"files":["README.md","project/ticket-008/README.md","project/ticket-008/intent.json","scripts/install-autonomy.py","scripts/test_install_autonomy.py"],"head_sha":"f65fcfe8792d2c62ea7e5dec4af87d3f0f7388b0","service_count":0,"services":[]},"assessment_mode":"observed-pr","axes":{"coupling":5,"delivery":3,"scope":4,"uncertainty":3,"validation":2},"complexity":"L","confidence":0.9,"diagnostics":["RADAR-ACCEPTANCE-MISSING","RADAR-BUDGET-EXCEEDED"],"estimate":{"budget_minutes":30,"minutes":83,"within_budget":false},"impact":{"components":["Chromium","MCP","origin","project","repository-root","scripts"],"files":["Chromium/DSL","MCP/v2","README.md","origin/main","project/ticket-008/README.md","project/ticket-008/intent.json","scripts/install-autonomy.py","scripts/test_install_autonomy.py"],"public_interfaces":[],"runtime_dependencies":0},"schema":"subactor.ticket-radar/v1","score":68,"split":{"parts":[{"estimated_minutes":13,"name":"Implement Chromium","scope":["Chromium"]},{"estimated_minutes":13,"name":"Implement MCP","scope":["MCP"]},{"estimated_minutes":13,"name":"Implement origin","scope":["origin"]},{"estimated_minutes":13,"name":"Implement project","scope":["project"]},{"estimated_minutes":13,"name":"Implement repository-root","scope":["repository-root"]},{"estimated_minutes":15,"name":"Validate and project to trackers","scope":["tests","planfile","github/gitlab/jira projections"]}],"reason":"estimated_minutes_exceed_budget","recommended":true},"standards":[{"id":"wellmanifest/dsl","revision":"6c60fc4e0dd1f1bb74f46a7745e28019908d1203","version":"0.1.0-dev"},{"id":"wellmanifest/ticket-lifecycle","revision":"5bf581907a87b46a13a73e6c033d3abe4d9a306f","version":"0.1.0-dev"},{"id":"wellmanifest/git-lifecycle","revision":"7d77d4b7af57e69bc75c3a0290b3a4805c5c4438","version":"0.2.0-dev"},{"id":"wellmanifest/logs","revision":"48c284ef7a069055c0bcb6b900147ce5e65f8b43","version":"0.3.0"}],"ticket_ref":"ticket-008"}<svg xmlns="http://www.w3.org/2000/svg" width="128" height="128" viewBox="0 0 128 128" role="img"><title>ticket-008: feat: install continuous curllm verification timer</title><rect width="128" height="128" rx="12" fill="#f8fafc"/><g stroke-width="1"><polygon points="64,55 72,61 69,71 59,71 56,61" fill="none" stroke="#d7dde5"/><polygon points="64,47 80,59 74,78 54,78 48,59" fill="none" stroke="#d7dde5"/><polygon points="64,38 89,56 79,85 49,85 39,56" fill="none" stroke="#d7dde5"/><polygon points="64,30 97,53 84,92 44,92 31,53" fill="none" stroke="#d7dde5"/><polygon points="64,21 105,51 89,99 39,99 23,51" fill="none" stroke="#d7dde5"/><line x1="64" y1="64" x2="64" y2="21" stroke="#aab4c0"/><line x1="64" y1="64" x2="105" y2="51" stroke="#aab4c0"/><line x1="64" y1="64" x2="89" y2="99" stroke="#aab4c0"/><line x1="64" y1="64" x2="39" y2="99" stroke="#aab4c0"/><line x1="64" y1="64" x2="23" y2="51" stroke="#aab4c0"/></g><polygon points="64,30 105,51 79,85 54,78 39,56" fill="#fb923c" fill-opacity="0.45" stroke="#c2410c" stroke-width="2"/><circle cx="64" cy="64" r="3" fill="#c2410c"/><g font-family="sans-serif" font-size="7" fill="#334155"><text x="64" y="11" text-anchor="middle">SCO</text><text x="114" y="48" text-anchor="middle">COU</text><text x="95" y="107" text-anchor="middle">UNC</text><text x="33" y="107" text-anchor="middle">VAL</text><text x="14" y="48" text-anchor="middle">DEL</text></g><text x="64" y="124" text-anchor="middle" font-family="sans-serif" font-size="8" fill="#0f172a">L · 83m</text></svg>DECISION D-008-4470
TICKET ticket-008
HEAD_SHA f65fcfe8792d2c62ea7e5dec4af87d3f0f7388b0
CORRELATION_ID curllm008-deploy-autonomy-20261006
ACTOR agent:ifuri-validator-agent[bot]
APPLIED_RULE P-CORE-015
INPUT author_login = "tom-sapletta-com"
INPUT observed_checks = ["metadata=PASS","governance / remote lifecycle=PASS","governance / enforce=PASS"]
INPUT required_checks = ["metadata","governance / enforce","governance / remote lifecycle"]
INPUT required_checks_source = "protected registry (env/request)"
INPUT reviewer_login = "ifuri-validator-agent[bot]"
INPUT semantic_review_assessment = {"schema":"subactor.validator/semantic-review-assessment/v1","subject":{"repository":"autogrammar/curllm","pull_request":14,"head_sha":"f65fcfe8792d2c62ea7e5dec4af87d3f0f7388b0","base_sha":"13574ac8bfc62221d3192e2a0e29bb8988658732","diff_sha256":"f962821cba76a36c215c0815976c9c04c8b869d441459be9a10e714e35225e55"},"policy":{"policy_schema":"subactor.validator/semantic-review-policy/v1","policy_version":1,"policy_sha256":"676cb4516bbfed2a000e40b9b1b6e4a430ecc761ec546aeb53d721a1905cfdd7","required":false,"critical_paths":[],"observed_paths":["README.md","project/ticket-008/README.md","project/ticket-008/intent.json","scripts/install-autonomy.py","scripts/test_install_autonomy.py"]},"grounding":"full-diff-not-per-finding-proof","execution_authority":false,"status":"not_required","reason":null,"review_sha256":null,"unresolved":[]}
INPUT superseded_checks = []
INPUT ticket_radar_receipt = {"schema":"subactor.ticket-radar/v1","base_sha":"13574ac8bfc62221d3192e2a0e29bb8988658732","head_sha":"f65fcfe8792d2c62ea7e5dec4af87d3f0f7388b0","change_digest":"dd75b21e2bce8b292b491b904968563642e9d75ac6b9b62a2efd422b2dfb7e1b","score":68,"complexity":"L","estimated_minutes":83,"split_recommended":true,"services":[],"authority":"ADVISORY","promotion":"FORBIDDEN"}
VERDICT APPROVE AUTHORITY DETERMINISTIC
REJECTED REQUEST_CHANGES BECAUSE NO_UNSAFE_CHANGE_REASON_FOUND
ADVISORY llm_verdict = "BLOCK" MODEL "openai/cursor-auto"
ASSERT VERDICT_AUTHORITY != "ADVISORY"
Install continuous curllm verification from a source revision already merged into origin/main, preserving uncommitted primary files and differing operator configuration. Export a versioned release, retain file digests, and stage a serialized user systemd timer with explicit activation. Preserve the supplied virtual-environment executable path instead of resolving it to global Python.
Default cycles run real Chromium/DSL, MCP/v2 and autonomy regressions, with durable deduplicated incident intake. Source digests are verified before each service start. Runtime repairs require explicit operator configuration; development findings await protected controller admission.
Validation: seven installer tests passed, both descriptors passed systemd-analyze verification, and an actual merged-source canary cycle passed all three probes (58 tests total, zero active incidents). Native governance passed. Runtime activation and first-cycle readback will follow protected merge under the user's recorded deployment authorization; AC-03 remains a post-merge action with external evidence.