fix(coverage): validate nested npm metadata through canonical pins - #807
fix(coverage): validate nested npm metadata through canonical pins#807seonghobae wants to merge 52 commits into
Conversation
|
Important Review skippedDraft detected. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
📝 WalkthroughWalkthroughnpm lockfile v2/v3의 중첩 metadata-only 위치에 대한 canonical pin 검증을 추가했습니다. 관련 회귀 테스트, 정책 문서, 변경 이력과 품질 CI도 추가했습니다. Changesnpm 중첩 메타데이터 검증
Estimated code review effort: 4 (Complex) | ~45 minutes Sequence Diagram(s)sequenceDiagram
participant GitHubActions as GitHub Actions
participant Tests as npm lock validation tests
participant Materializer as materialize_base_javascript_packages.py
participant Lockfile as npm lockfile
GitHubActions->>Tests: 대상 테스트와 커버리지 실행
Tests->>Materializer: lockfile materialization 호출
Materializer->>Lockfile: package metadata 읽기
Materializer-->>Tests: pin 검증 결과 반환
Tests-->>GitHubActions: 테스트 및 커버리지 결과 보고
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Comment |
|
Implement the bounded GREEN slice on exact current head Apply the permanent tests and minimal production changes already specified by the branch contract:
Keep Draft and do not approve, merge, release, or change reviewer credentials. |
|
Release blocker: current branch contains only a trigger and branch-materialization workflows ( @opencode-agent address Remove every trigger, self-removing materializer, encoded patch, and branch-writing helper from the final tree. Preserve the test-first intent, but publish the four permanent implementation/test/doctoring/changelog files through ordinary reviewed commits. The final production rule may accept a metadata-only nested npm v2/v3 location only when one canonical root package with the same normalized identity and exact version has a valid public npm-registry tarball and SHA-512 SRI. Continue to reject missing canonical metadata, version mismatch, partial pins, malformed scoped identities, non-registry origins, userinfo/query/fragment/port abuse, invalid SRI, conflicting complete pins, unsafe paths, and links. Consume the lock unchanged; do not repair or synthesize metadata. Require exact-head Python 3.10/3.14 tests, 100% production statement/branch/docstring evidence, compilation, all security/supply-chain checks, current-head review, and independent approval before Ready. |
|
@jules Replace the trigger/materializer-only scope on exact live head Delete Implement the narrow npm v2/v3 rule directly: a metadata-only nested Add the BandScope-shaped positive case and every stated negative case. Run Python 3.10/3.14, focused and complete central tests, 100% production statement/branch/public-docstring coverage, Ruff, compileall, workflow contract, security and supply-chain checks, and |
|
/oc Fix the current exact-head failure directly in permanent source; do not rely on, add, or retain a one-shot/branch-writer workflow. The Python 3.14 quality run proves 12 focused failures because
Add the APA 7 doctoring and CHANGELOG entry, remove |
|
@opencode-agent address The branch has been restored to a reviewable TDD state at exact head Implement the permanent change directly in
Keep |
|
@opencode-agent address Implement the permanent production change on exact current Draft head Apply the minimal two-pass validator:
Add Run: python -m coverage erase
python -m coverage run --branch -m pytest -q \
tests/test_materialize_base_javascript_packages.py \
tests/test_npm_nested_metadata_lock_validation.py
python -m coverage report \
--include=scripts/ci/materialize_base_javascript_packages.py \
--show-missing --fail-under=100
python -m interrogate scripts/ci
python -m compileall -q scripts/ci tests
pytest -qThen rerun exact-head CodeQL, Python Security, SAST, Security Scan, Secret Scan, OSV, Scorecard, SBOM, CodeRabbit/OpenCode/Noema, and keep Draft until all evidence is current and a qualifying independent approval exists. |
|
@opencode-agent address Exact head Implement the minimum permanent production correction directly in
Add the permanent production tests to the authoritative existing module, complete public docstrings, APA 7 doctoring and |
|
@opencode-agent address Implement the permanent GREEN production change for exact head Update
Then add authoritative npm v11 package-lock doctoring with APA 7 primary-source references and |
|
@opencode-agent address Continue from exact current head A second RED contract set now closes the remaining descriptor ancestry boundary in Implement the smallest coherent root fix, not test exceptions:
Update doctoring and CHANGELOG to state the full descriptor-anchored ancestry, durability, capability, and cleanup boundary with APA 7 POSIX.1-2024 and CWE-59/CWE-367 references. Run the expanded focused suite RED→GREEN, then 100% statement/branch coverage, interrogate 100%, Python 3.10 compile, full central tests, and |
|
Continue on exact current head Root-cause repair requirements:
Update this branch only. Do not create another branch/PR, temporary workflow, patch artifact, writer automation, force push, approval bypass, merge, or release. |
|
@opencode-agent address Fix exact current head Quality run Apply the minimal root fix: capture the required CPython filesystem callables once at module import (before test monkeypatching) and have the capability preflight compare those immutable original callables against Rerun the exact expanded focused suite. Do not weaken regex/assertions merely to bypass the preflight. After these four tests reach the intended branches, address any remaining ancestor, inode, durability, or ownership-cleanup failures at their source, then restore 100% statement/branch coverage, interrogate 100%, Python 3.10 compilation, full central tests, and |
|
@opencode-agent address Continue from exact current head Do not retain the new A new RED suite,
The current pathname-based Add both |
|
/oc Refetch the exact live head of this PR before editing and abort if it moved. Diagnose and fix the four same-head failures from npm Nested Metadata Validation Quality CI run |
|
/oc Fix only the fresh exact-head quality regression on Apply the smallest production fix test-first: bind the original descriptor-capable OS callables at module import (for example an immutable Verify RED→GREEN with the exact four failing regressions plus |
|
/oc Continue only from exact live head
Use these observed same-head failures as RED. Preserve exact authenticated base/head lock identity, npm canonical-pin validation, |
|
@opencode-agent Implement the minimal permanent GREEN repair directly on exact current head Exact-head quality run
Repair test-first without weakening the canonical npm-pin validation or portability boundary:
Do not add a temporary/self-removing/encoded-patch/branch-writer workflow, change reviewer credentials, weaken a security result, merge, mark Ready, rebase, retarget, release, or publish. Run the three failing tests first, then every focused materializer test, the complete central suite, coverage/docstrings/compileall/ |
|
@opencode-agent Repair exact current head Implement the smallest authoritative-source fix in
Preserve all current npm canonical-pin validation, exact base/HEAD blob binding, no-follow/exclusive file creation, single-link checks, post-write inode checks, 100% coverage/docstrings, and Python 3.10 compatibility. Run the three failing security tests first, then the focused 101-test suite, then the complete central regression/coverage/docstring/compile/security suite. Keep Draft until the new exact head is fully GREEN. |
|
@opencode-agent address Repair exact head
Use the existing failing tests as RED evidence, add only regressions needed for uncovered cleanup/race branches, preserve the npm canonical-pin contract and authenticated lock consumption, then run the complete exact-head suite. Do not add a one-shot or branch-writing repair workflow. |
|
/oc Refetch the live PR head and stop without writing unless it is exactly
Run the three exact failing tests first, add a nested rollback adversarial case if the implementation introduces nested transaction entries, then run the focused 101-test contract, the complete central suite, production statement/branch coverage 100%, public docstrings 100%, Python 3.10 compilation, |
|
/oc Refetch the exact live PR head and abort unless it is |
|
@opencode-agent Repair the exact current Draft head Exact-head run
Keep the canonical nested npm metadata behavior unchanged. Add/adjust test-first contracts only as needed, retain Python 3.10 compatibility, exact-head checkout, 100% production statement/branch/docstring coverage, compileall, security boundaries, authenticated-base inputs, and clean-tree verification. Update doctoring/CHANGELOG only for materially changed behavior. Keep Draft and do not approve, merge, release, or alter reviewer credentials/protection. |
|
@opencode-agent address Repair exact current head
Use TDD and the minimum durable source repair. Add the existing creation/cleanup security regressions to the focused exact-head quality workflow so the affected branches are measured at 100%; keep descriptor-relative/no-follow operations, immutable source identity, current npm canonical-pin validation, credentials, reviewer identities, and branch protections unchanged. Rerun the complete central suite, 100% production statement/branch coverage, 100% docstrings, Python 3.10/3.14 compilation, all security/supply-chain checks, and fresh current-head reviews. No one-shot or branch-writing repair workflow. |
|
@coderabbitai autofix Commit directly to exact head |
|
Autofix skipped. No unresolved CodeRabbit review comments with fix instructions found. |
Problem
Central changed-head npm-lock validation historically required every non-link
node_moduleslocation to repeat its own registry tarball and SHA-512 integrity. npm v2/v3 can serialize workspace or peer locations with version/classification metadata while one canonical location carries the artifact pin, so valid BandScope-style entries were blocked despite an exact canonical root pin.Exact current stack
7b1a08f947e960e40be46f91227676066188e4d1;e71fdab2ab088001f218765ecb5e3b7fabfee11a;Permanent implementation
node_modules.node_modules/<same exact identity>in the same authenticated lock is a non-link canonical entry with identical exact version, a publicregistry.npmjs.orgHTTPS tarball, and one canonical SHA-512 SRI value.:443, query/fragment data, hostile origins, non-tarball URLs, and invalid SRI.Exact-head acceptance evidence
For
7b1a08f947e960e40be46f91227676066188e4d1, all exact-head workflows completed successfully:31152353756;31152353761;31152353801;31152353800;31152353834;31152353762;31152354083;31152353799;31152353804;Focused and complete central suites prove 100% production statement and branch coverage, complete production docstrings, compilation, authenticated-base workspace handling, malformed URL/port behavior, and no temporary writer scope. All inline findings are resolved or outdated; zero actionable unresolved thread remains.
Formal exact-current-head CodeRabbit/OpenCode/Noema review and a qualifying independent non-author approval remain required. Queued, cancelled, predecessor-head, status-only, author-only, local-only, or temporary-workflow evidence is not accepted.
Standards and merge gate
docs/doctoring/npm-nested-metadata-canonical-pins.mdrecords the trust boundary, explicit-port policy, failure and rollback behavior, and APA 7 references to npm package-lock format and Subresource Integrity. Merge only after exact-current-head automated review, qualifying independent non-author approval, zero unresolved actionable findings, and branch protection succeed without bypass.Refs ContextualWisdomLab/bandscope#751 and #748.