Conversation
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Repository UI Review profile: ASSERTIVE Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
PR Summary by QodoEnforce fail-closed supply-chain release admission
AI Description
Diagram
High-Level Assessment
Files changed (114)
|
Code Review by Qodo
1.
|
7735a7f to
e8e22a2
Compare
|
Published e8e22a2 after a clean rebase onto dev 256d64d; range-diff preserves all seven patches. The applications SBOM now derives only the three workspace identity records from checked-in manifests while preserving the canonical required-only Bun dependency inventory. Clean-fixture pinned generation and CycloneDX schema validation pass. Both real Watchlist journey tests pass with a CI-only localhost-suffix fixture allowance; production egress defaults and default port checks are unchanged. Six actual-policy regressions exercise allowed fixture access and rejected unrelated hosts and ports. Verification before rebase: 858 focused Python tests passed. After rebase: 857 passed and one existing coverage contract fails because the newly added upstream test_pdf_summary_service_prompt.py is absent from the media shard inventory. That new repair is awaiting scoped approval. Workflow syntax, touched lint, and offline pinned lock freshness pass. Bandit has no new findings; its existing test-file --cov false positive is unchanged. Character Chat now selects the deterministic custom mock model, but its real success journey remains blocked by a pre-transport ChatBadRequestError in complete-v2. No backend fix or assertion/timeout bypass is included. Known vulnerability admission failures remain blocking, with no exceptions or policy relaxations. Fresh exact-head CI and review are still required; this PR is not merge-ready. |
9a581e2 to
a2839ef
Compare
|
Published a2839ef after rebasing onto dev 3b82e4c; all 16 patches remained equivalent in range-diff. Fixed an actual read-only startup failure: optional prompt templates no longer create directories inside installed packages during import. Added exact-OCI runtime checks for locked dependencies, real per-user Chroma collection/query isolation, live-client TCP listeners, and cryptography-backed ES256 signing. The original OCI candidate is loaded and run by immutable subject, and runtime evidence is checksummed alongside scan evidence. No Chroma replacement, vulnerability exception, or gate relaxation was introduced. Verification: 539 tests passed with one expected skip after rebase; actionlint passed; Bandit found no issues in touched production code. Supporting app/worker/audio-worker image tests with only the startup fix mounted passed locked Chroma 1.5.9, python-jose 3.5.0, and cryptography 50.0.1. Independent review found no actionable correctness/security issues. Exact rebuilt-candidate CI and fresh review are running. Known vulnerability findings remain blocking; this is not a release certification or merge-ready claim. |
8ef7660 to
e2af1cf
Compare
Candidate qualification checkpoint — 2026-09-07TASK-13013.7.7 is complete as candidate qualification only. Native amd64 run 34091697435 passed at
Artifact This supersedes the earlier pending util-linux qualification checkpoint, not the release blockers. Production images, source patches, test requirements, vulnerability policy and admission gates are unchanged. Privileged exploit-path testing, official scanner recognition and production adoption remain unverified/unapproved. Source/container admission and separate Notes E2E onboarding-overlay click failures remain red. No merge, package promotion or release publication occurred; the human Change summary is unchanged. |
|
Remediation checkpoint: commit 4de994d fixes the returning-user Notes fixture without changing production tutorial behavior or workflow API assertions. Exact-head critical E2E run https://github.com/rmusser01/tldw_server/actions/runs/34139549060/job/101798198369 passed all four Notes cases and the Notes-to-Flashcards journey without retries (46 passed; one existing unrelated Character Chat provider-configuration case skipped). Focused local regression/control coverage passed 16/16; independent review found no issues. TASK-13013.7.8 is complete. Commit f9857e1 adds candidate-only Expat source preparation, not a production fix: all five source archive hashes and the Expat, CPython and Debian source signatures were verified, and 13 preparation tests pass. Both the system and Python-bundled parser copies remain in the qualification scope. Native rebuilds, parser/ABI/application tests, combined-image scans and final security review remain outstanding. No production images, vulnerability thresholds or exceptions were changed; the PR remains blocked from merge. |
3ecd1e5 to
b2559cd
Compare
|
Published b2559cd after rebasing onto dev 6cd2745. All 66 patches are unchanged in range-diff. The reviewed candidate-only source-manifest validator now rejects incomplete coverage, altered input bytes, unsafe paths, invalid prerequisites and duplicate patch bytes; its 65 synthetic contract tests pass. It does not authenticate sources by itself, supply a completed source ledger, or authorize a wheel build. Also fixed two concrete CI defects: Docker inspection failures now preserve their exit status in the combined candidate workflow, and the admin permission filter has its missing accessible name. Three workflow execution regressions and all seven admin user-page tests pass. Post-rebase Supply_Chain verification: 587 passed, four existing opt-in skips, four warnings. Shard coverage has no newly uncovered tests. Exact-head GitHub workflow lint passes: https://github.com/rmusser01/tldw_server/actions/runs/34195919210 . All five existing Qodo inline review threads are resolved; fresh checks and review are running. Production recipes, security thresholds and exceptions are unchanged. Source-ledger and native wheel qualification work remain incomplete, and vulnerability admission remains blocking. This is not merge-ready. The human Change summary is unchanged. |
|
Final CI-repair checkpoint for b2559cd: frontend-required now passes (https://github.com/rmusser01/tldw_server/actions/runs/34195919213/job/101967552449). The admin unit ratchet reports inherited=40 and regressions=0; the formerly failing permission-filter case is repaired. The admin real-backend suite reports 26 passed, and the required frontend job completes successfully. This is not a claim that the inherited unit failures were fixed. Backend-required, e2e-required, critical E2E, CodeQL and workflow lint also pass. All five image candidates and the source SBOM reach security admission and remain rejected by the existing vulnerability policy. Dependency review remains blocked by the four ChromaDB advisories. No unresolved inline review threads or new Qodo comments are present; CodeRabbit explicitly skipped review for this base branch, which is not an approval. No further CI-only repair is identified. Candidate wheel source repair and qualification remain incomplete, and the source-history review remains paused at the documented platform security restriction. The follow-up loop is paused at this external blocker; no security checks, thresholds, exception lists or production inputs were changed. PR remains unmerged. The human Change summary is unchanged. |
Approval record — five OS applicability exceptions (TASK-13013.7.24)Codex is posting this record at the explicit direction of the requester, rmusser01, following their approval in the working task. The requester approved activating precisely the five reviewed OS records below, with rmusser01 as accountable owner, and authorized posting this approval on PR #2869. This records that instruction transparently; it is not a claim of a separate, independently authored review comment. Approved scope: the exact vulnerability/component/PURL/installed-version/severity combinations, rationales and mitigations below. All five are Critical, created 2026-09-10 and valid through 2026-09-17 UTC inclusive. The canonical policy approval reference will be this PR URL. No dates or other reviewed fields will change. The three backend Perl records are supported by exact-image Primary advisory references: Perl CVE-2026-8376 and zlib CVE-2023-45853. Reviewed packet: The underlying scans and image evidence are from PR head This approval covers only these five OS records. It does not cover the 16 conditional Chroma records, NLTK, other OS findings, a new push, merge, deployment or release. Complete raw reports remain unchanged. Expected residual blockers: Python source 5; applications/admin source 0 each; app 233; worker 58; audio worker 233; webui 55; admin-ui 55. Admission remains blocked. The exact approved records follow; {
"exceptions": [
{
"approval": "https://github.com/rmusser01/tldw_server/pull/2869",
"component": "image-app",
"created_on": "2026-09-10",
"expires_on": "2026-09-17",
"id": "TASK-13013.7.23-OS-01",
"installed_version": "5.40.1-6",
"mitigation": "Limited to the named linux/amd64 image and exact distribution package identity. Reassess after any package/build/architecture change. Evidence and limits: Docs/Evidence/TASK-13013.7.23-applicability-dispositions.md.",
"owner": "rmusser01",
"purl": "pkg:deb/debian/perl-base@5.40.1-6?arch=amd64&distro=debian-13.6",
"rationale": "Advisory requires a 32-bit Perl build; exact-image /usr/bin/perl reports 8-byte integer and pointer sizes.",
"severity": "CRITICAL",
"supersedes": null,
"vulnerability_id": "CVE-2026-8376"
},
{
"approval": "https://github.com/rmusser01/tldw_server/pull/2869",
"component": "image-worker",
"created_on": "2026-09-10",
"expires_on": "2026-09-17",
"id": "TASK-13013.7.23-OS-02",
"installed_version": "5.40.1-6",
"mitigation": "Limited to the named linux/amd64 image and exact distribution package identity. Reassess after any package/build/architecture change. Evidence and limits: Docs/Evidence/TASK-13013.7.23-applicability-dispositions.md.",
"owner": "rmusser01",
"purl": "pkg:deb/debian/perl-base@5.40.1-6?arch=amd64&distro=debian-13.6",
"rationale": "Advisory requires a 32-bit Perl build; exact-image /usr/bin/perl reports 8-byte integer and pointer sizes.",
"severity": "CRITICAL",
"supersedes": null,
"vulnerability_id": "CVE-2026-8376"
},
{
"approval": "https://github.com/rmusser01/tldw_server/pull/2869",
"component": "image-audio-worker",
"created_on": "2026-09-10",
"expires_on": "2026-09-17",
"id": "TASK-13013.7.23-OS-03",
"installed_version": "5.40.1-6",
"mitigation": "Limited to the named linux/amd64 image and exact distribution package identity. Reassess after any package/build/architecture change. Evidence and limits: Docs/Evidence/TASK-13013.7.23-applicability-dispositions.md.",
"owner": "rmusser01",
"purl": "pkg:deb/debian/perl-base@5.40.1-6?arch=amd64&distro=debian-13.6",
"rationale": "Advisory requires a 32-bit Perl build; exact-image /usr/bin/perl reports 8-byte integer and pointer sizes.",
"severity": "CRITICAL",
"supersedes": null,
"vulnerability_id": "CVE-2026-8376"
},
{
"approval": "https://github.com/rmusser01/tldw_server/pull/2869",
"component": "image-webui",
"created_on": "2026-09-10",
"expires_on": "2026-09-17",
"id": "TASK-13013.7.23-OS-04",
"installed_version": "1:1.2.13.dfsg-1",
"mitigation": "Limited to the named linux/amd64 image and exact distribution package identity. Reassess after any package/build/architecture change. Evidence and limits: Docs/Evidence/TASK-13013.7.23-applicability-dispositions.md.",
"owner": "rmusser01",
"purl": "pkg:deb/debian/zlib1g@1.2.13.dfsg-1?arch=amd64&distro=debian-12.15&epoch=1",
"rationale": "Debian states vulnerable contrib/minizip is not built into this Bookworm zlib binary package.",
"severity": "CRITICAL",
"supersedes": null,
"vulnerability_id": "CVE-2023-45853"
},
{
"approval": "https://github.com/rmusser01/tldw_server/pull/2869",
"component": "image-admin-ui",
"created_on": "2026-09-10",
"expires_on": "2026-09-17",
"id": "TASK-13013.7.23-OS-05",
"installed_version": "1:1.2.13.dfsg-1",
"mitigation": "Limited to the named linux/amd64 image and exact distribution package identity. Reassess after any package/build/architecture change. Evidence and limits: Docs/Evidence/TASK-13013.7.23-applicability-dispositions.md.",
"owner": "rmusser01",
"purl": "pkg:deb/debian/zlib1g@1.2.13.dfsg-1?arch=amd64&distro=debian-12.15&epoch=1",
"rationale": "Debian states vulnerable contrib/minizip is not built into this Bookworm zlib binary package.",
"severity": "CRITICAL",
"supersedes": null,
"vulnerability_id": "CVE-2023-45853"
}
],
"schema_version": 1
} |
…idence (TASK-13013.7) Lock dependencies and image identities, validate complete SBOM and scan evidence, and admit exact candidates before promotion so releases fail closed. Retain signed provenance and documented retry safeguards; known vulnerability findings remain blocking.
Bind native attestation verification to exact release subjects, preserve the existing admission routing, and make frozen packaging and scanner mounts reliable. Restore the canonical WebUI build without weakening budgets or vulnerability gates. TASK-13013.7; plan: Docs/superpowers/plans/2026-08-30-software-supply-chain-release.md. Verification: 846 focused tests, workflow lint, lock freshness, Bandit and independent review.
TASK-13013.7: record pushed correction, resolved review threads and remaining admission gates.
Keep the canonical Docker build contract aligned and cover each platform with the real shard matcher. Rebased onto dev 3bc8c6a; 851 focused Python tests and four frontend contract tests pass. TASK-13013.7; plan: Docs/superpowers/plans/2026-08-30-software-supply-chain-release.md. Security and newly diagnosed integration blockers remain explicit.
TASK-13013.7: keep the canonical required-only Bun dependency scan while making clean-checkout package metadata independent of child locks and node_modules. Verify the actual workflow with pinned generation and schema validation. Plan: Docs/superpowers/plans/2026-08-30-software-supply-chain-release.md.
Apply the exact TASK-13013.7.23 records after explicit requester approval recorded on PR #2869. Keep version/component/severity matching and September 17 expiry unchanged; retain full scan evidence and all remaining blockers. Plan and verification: TASK-13013.7.24. Eight retained reports reconcile to five exceptions and zero unmatched records; 82 policy/workflow tests, 25 matching boundary checks, expiry validation, scoped Bandit and independent review pass.
Close the release-image evidence gap from TASK-13013.7.23 by reusing the existing isolated probe against each authenticated immutable backend child. Retain runtime and manifest checksums and require runtime plus vulnerability-policy success before admission. Plan and verification: TASK-13013.7.25. 106 focused tests, 19 final behavioral tests, Actionlint/ShellCheck, formatting, syntax, scoped Bandit and independent review pass. Chroma exceptions remain conditional; this local change does not dispatch or certify a release.
Explicitly select the Rust API so CHROMA_API_IMPL cannot redirect internal persistent stores. Align the declared Chroma minimum with tested, already-locked 1.5.9 without changing the resolved graph. Preserve injected clients and record applicability limits. TASK-13013.7.26; plan and verification: Docs/Evidence/TASK-13013.7.26-embedded-chroma-settings.md. Verified 76 focused tests, offline lock consistency, scoped lint/compile/Bandit and independent review.
Bind the existing embedded runtime probe to the authenticated platform child, retain checksummed evidence, and require runtime plus vulnerability-policy success before promoting main aliases. Preserve the existing source gate and promotion commands. TASK-13013.7.27; plan and evidence: Docs/Evidence/TASK-13013.7.27-main-runtime-admission.md. Verified 101 focused tests, Actionlint/ShellCheck, Black/Ruff, shell/Python checks, scoped Bandit and independent review.
Use the reviewed embedded deployment evidence to exclude the exact Chroma 1.5.9 findings in source and backend images. Derive dependency-review allowances from the same expiring policy and revalidate complete raw output, preserving all other findings and the credential boundary.
…dispositions Disable and verify SQLite schema trust before uploaded database metadata is prepared, retaining read authorization to block nested FTS configuration views. Keep normal OpenWebUI hydration and APKG imports covered by regressions. Add fourteen exact current-use exclusions and five source advisory aliases while preserving existing approvals and documenting remaining gate boundaries. Retain source, candidate-library, report, test and independent-review evidence. Task: TASK-13013.7.40 Design: Docs/Design/TASK-13013.7.40-sqlite-metadata-validation.md
…r (TASK-13013.7.42)
…ngs (TASK-13013.7.42)
Remove duplicate shard assignments introduced by integrating both branches and reject repeats before path-set coverage checks. Retain the completed integration plan, preservation evidence and focused verification results; historical image evidence remains tied to its recorded source revision.
…K-13013.7.44) Keep optional lockfile approvals out of the required-only source inventory so unused optional records do not falsely fail base admission. Preserve exact matching and all approval details, prove runtime and duplicate-scope rejection, and retain fresh scans showing all three source gates pass.
78c3f92 to
ee856c7
Compare
Change summary
This PR strengthens release safety with reproducible Python and Bun dependencies, digest-pinned production images, and validated SBOM and vulnerability evidence. It gates publication on scans of the exact release artifacts, adds provenance verification and operator documentation, and prevents release retries from overwriting existing version tags. Known vulnerabilities remain explicitly blocking—no security exceptions or bypasses were introduced.
The Change summary above was supplied by the human requester and is retained verbatim.
Current verified checkpoint — 2026-09-06
Candidate snapshot amendment
e2af1cf3b8is rebased on dev83af7e5dcf, with full-image verification recorded in98d47e8078. All 26 rebased patches were preserved unchanged. Post-rebase verification: 266 tests passed across Supply Chain and release workflow/documentation contracts, one opt-in skip, four existing warnings per run; scoped Black/Ruff/Bandit clean; no newly uncovered shard tests. Independent snapshot review approved spec compliance and quality with no blocking findings. The full fixed-snapshot candidate built successfully assha256:0f82ed8871ebdd3e6c5e8d5ba0a4278c253f65f7d4b6d42420dab7669117b6a4. It passes all synthetic media probes with no unapproved capability loss. All 785 build/179 runtime package versions and configure flags match the earlier candidate; builder/runtime signed repository evidence is identical. Fresh scans bind to config0d6ba63550adb7d396b647d782c9921dc3c3e1869dbc3c1f850be75ac185adc7and retain the same blockers: Trivy 73 High/Critical OS matches, Grype 92 High/Critical matches overall, and incomplete source-built coverage. Production images and security admission are unchanged. Historical validation entries below describe their stated earlier integrations, not a claim that all current GitHub checks pass.The candidate-only FFmpeg 9 recipe authenticates upstream source, builds pinned libplacebo and its pinned Vulkan headers, derives exact runtime package versions, and includes a standard-library compatibility evaluator. The requester accepted the upstream Sonic, explicit V4xx codec, old HLS input protocol, and SDL/OpenGL output retirements alongside pp. The amended evaluator passes all synthetic media probes on the existing immutable candidate and records these observed retirements separately; no unapproved capability losses remain. HLS demuxing and the HLS output protocol are not retired. Trivy reports 73 High/Critical OS package findings and does not identify source-built FFmpeg/libplacebo; supplemental source-built coverage work is still underway. Production Dockerfiles, release selection, and vulnerability policy are unchanged. This PR is not merge-ready.
On published head
21227dd09e, Characters Harness and macOS E2E both pass; the earlier failure hypotheses were not implemented. Source and container security admission still fail. No new inline review comments were present at this checkpoint.Supplemental digest-pinned Syft detects FFmpeg 9.0.1 from the exact candidate libraries. Grype with a fresh database reports zero FFmpeg matches, but 92 High/Critical candidate matches overall. A 7.1.5 positive control finds vulnerabilities but does not cover all earlier FFmpeg findings. Source review now maps all 17 original FFmpeg findings to fixes in the authenticated 9.0.1 source; CVE-2026-58049 remains an evidence-backed patch mapping without explicit CNA/vendor clearance. Libplacebo/static dependency identification and remaining OS/advisory reconciliation remain unresolved. Fixed dependency selection is not a claim of bit-identical binaries. No missing component or zero-match result is treated as a vulnerability waiver. The requester approved separate candidate-only qualification of the official util-linux backport (TASK-13013.7.7); source/patch authentication is recorded, with native package tests, ABI checks and independent review still pending. No package adoption or privileged mount test is authorized by that qualification.
Summary
Validation
d308a40871integration: 1,079 passed, including source/release/deployment contracts, the newly merged summary modules, Character HTTP regressions and pinned Docker SBOM coverage. Final local interpreter garbage collection was unusually slow but completed with exit zero; no intervention was needed. This is not a claim that all live CI gates pass.33d7f9f1dapreserves all 14 patches unchanged. Four newly merged summary-test modules are added to the existing API shard on all five platforms; exhaustive/disjoint coverage assertions remain intact. Full-matrix evidence above is from the preceding integration; final-head CI remains required.Earlier frontend and critical-journey verification, exact commands, intentional skips, and inherited failures are recorded in the Backlog tasks. The full repository suite and all frontend journeys have not been rerun after the final rebase; CI must validate the resulting integration.
Known blockers — not merge-ready
4415afe0d4in run34044783356; all three backend images pass the UUID isolation and no-listener checks, with bounded Perl/systemd facts recorded. These observations are not vulnerability waivers. Source/image admission still fails on remaining findings, and fresh current-head checks remain required. The last complete frontend scans reported 56 package/CVE findings each. Digest pinning records identity, not a clean scan or deployment approval.Do not merge or publish a release until the required checks, actionable reviews, and release-admission blockers are genuinely resolved. No auto-merge is enabled by this PR.
Operator references
Certification is limited to
linux/amd64. Third-party references have identity/SBOM/scan evidence, not project-authored provenance.UX / Watchlists review
The child-task changes repair deterministic critical-journey terminal states, mock fixtures, and persisted Watchlist briefing behavior. Recorded journey evidence lives with TASK-13013.7.1. This PR does not claim a fresh full UX, accessibility, scale, or cross-client parity audit; applicable CI and review remain required.
Risk & rollback
Summary by cubic
Adds fail-closed supply-chain release controls (TASK-13013.7): Python and Bun dependencies are pinned, production images are digest-pinned, and releases publish only after scanning and verifying signed provenance of the exact candidate digests. Known Critical/High findings still block admission.
uv.lockoffline before staging.node_modules.PyJWT, removingpython-joseandecdsawhile preserving legacy tokens, OIDC keys, and RSA verification.uv.lockentries; scanner qualification remains open.avandopencv-pythonagainst a repaired FFmpeg 8.x baseline; no rebuild is implemented.@xmldom/xmldom, overrides nested Prism and OpenTelemetry core so EPUB, highlighting, and tracing dependencies can't retain affected releases.passlibwithlibpass1.9.3 for MCP password handling, keeping PBKDF2-SHA256 hashes and interop.schematoschema_definitionvia Pydantic alias so wire keys are unchanged, raising the Pydantic floor to >=2.11.7.ConfigDict.Known blockers
Migration
@sha256digest.Written for commit 9a6440f. Summary will update on new commits.