Skip to content

openDox root: bump code to 05bbde80 (S3 fail-closed follow-up, S4 route-tail split, S6 /source core-arm) - #7

Merged
brettheap merged 1 commit into
mainfrom
chore/pin-code-to-s4-s6-landings
Sep 13, 2026
Merged

brettheap merged 1 commit into
mainfrom
chore/pin-code-to-s4-s6-landings

Conversation

@brettheap

@brettheap brettheap commented Sep 12, 2026 •

Copy link
Copy Markdown
Contributor

Lane: openxfactory-4-opendox-extraction

Refs opensoft/openxFactory#656 (stays OPEN). CLAIM: 5647338637.

First leg of the pin lockstep that advances openxFactory's openDox and
openXdox pins to the § 3.4 S4/S6 landings (precedent: this root's own #6,
openXdox's #8, then openxFactory#984 — the same order, followed here).

code (opensoft/openDox-code) advances a99eba03 → 05bbde80:

spec is unchanged. scripts/validate-pins.py recomputes the tree digest
(98634678b193dd9e24a6ab86211546e6b415864dabffd44999f18ff646c01a81) and
confirms gitlink/pin-file lockstep; validate-manifest.py and
validate-repository-naming.py also pass. No .github/workflows/*.yml
names this leg by sha.

🤖 Generated with Claude Code

Summary by Sourcery

Advance the openDox code pin to incorporate route validation hardening, route-tail classification, and the fixed /source core arm.

New Features:

  • Advance the openDox code dependency to the S4/S6 landing revision, including fail-closed route validation and a fixed core /source arm.

Bug Fixes:

  • Reject contributed route entries with missing or invalid route-shape fields during manifest and ownership checks.

Enhancements:

  • Separate gate-route constants into class-B bindings while retaining /actions/refresh as class A.

Chores:

  • Update the code pin and verified tree digest to maintain repository lockstep.

…te-tail split, S6 /source core-arm)

Lane: openxfactory-4-opendox-extraction

Refs opensoft/openxFactory#656 (stays OPEN). CLAIM: 5647338637.

`code` (opensoft/openDox-code) advances a99eba03 -> 05bbde80, carrying three
landed slices since the last bump: S4 (opensoft/openDox-code#17, the thirteen
gate-route constants split from lens-model.js/repo-selector.js/staging-
workbench-model.js to the class-B bindings that call them), its S3 fail-
closed follow-up (opensoft/openDox-code#18, landed via #22 after a base-
branch retarget correction: a shared requireRouteShape() now refuses a
malformed contributed-routes entry instead of coercing it), and S6
(opensoft/openDox-code#16, /source becomes openDox's own fixed core arm per
RULED Q4). `scripts/validate-pins.py` recomputes the tree digest
(98634678b193dd9e24a6ab86211546e6b415864dabffd44999f18ff646c01a81) and
confirms the gitlink/pin-file lockstep; no workflow file names this leg by
sha. `spec` is unchanged.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Copilot AI lite review requested due to automatic review settings September 12, 2026 23:57

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @brettheap, you've used your own review budget of 250,000 diff characters for the last 7 days.

You can request another review in 1 day and 17 hours by commenting @sourcery-ai review. Upgrade to get a review now.

@sourcery-ai

sourcery-ai Bot commented Sep 12, 2026

Copy link
Copy Markdown
Reviewer's guide (collapsed on small PRs)

Reviewer's Guide

Updates the openDox code pin to 05bbde80 and its verified tree digest, incorporating the S4 route-tail binding split, S3 fail-closed route-shape validation, and S6 fixed core handling for /source; specification files remain unchanged.

Sequence diagram for fail-closed contributed-route validation

sequenceDiagram
    participant Manifest as manifestRoutes()
    participant Shape as requireRouteShape(claimed)
    participant Breach as ownershipBreach()

    Manifest->>Shape: validate contributed route
    Shape-->>Manifest: valid route shape
    Breach->>Shape: validate contributed route
    Shape-->>Breach: valid route shape
    alt missing string pattern or non-boolean is_prefix
        Shape-->>Manifest: reject route
        Shape-->>Breach: reject route
    end
Loading

Flow diagram for fixed core /source routing

flowchart TD
    Request[HTTP request]
    Source{path is /source}
    Core[openDox fixed core arm]
    Contributed[Contributed route consult]
    Response[Route response]

    Request --> Source
    Source -->|yes| Core
    Source -->|no| Contributed
    Core --> Response
    Contributed --> Response
Loading

File-Level Changes

Change Details Files
Advance the openDox code submodule pin and synchronize its verified tree digest.
  • Update the code gitlink from a99eba03 to 05bbde80.
  • Replace the recorded tree SHA-256 digest with the digest for the new revision.
  • Preserve commit-based pin verification and lockstep metadata.
code
contracts/code-pin.yaml
Bring in S4 route-tail binding splits while retaining the class-A refresh route.
  • Move thirteen gate-route constants from model modules into four class-B binding files.
  • Keep /actions/refresh measured as class A.
code
Harden contributed-route validation to fail closed on malformed route shapes.
  • Require contributed routes to have a string pattern and boolean is_prefix.
  • Share the validation between manifest route generation and ownership-breach checks.
code
Make /source an openDox-owned fixed core arm before contributed-route consultation.
  • Add the fixed /source handling in serve.py ahead of the § 2.4 contributed consult.
  • Apply the S6 core-arm routing behavior.
code

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@sonarqubecloud

Copy link
Copy Markdown

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

Advance the code gitlink to match the recorded pin and restore lockstep validation.

Pull request overview

Advances the openDox code pin to include route validation hardening, route-tail classification, and the fixed /source core arm.

Changes:

  • Updates the pinned commit and verified tree digest.
  • Preserves the documented spec and workflow references.
  • The corresponding code gitlink remains unadvanced, breaking pin lockstep.
File summaries
File Summary
contracts/code-pin.yaml Records the new code commit and tree digest; the matching code gitlink must also be updated.
Review details

Suppressed comments (1)

contracts/code-pin.yaml:24

  • This change updates only the recorded pin; the corresponding code submodule gitlink is not moved in the diff. That leaves the lockstep invariant broken and scripts/validate-pins.py will report pin-gitlink-mismatch until the gitlink is advanced to 05bbde80f91a870f23aaa762fc03e40635ccbffd in the same commit. Please use scripts/bump-leg.py (or otherwise update the gitlink and rerun make validate).
commit: "05bbde80f91a870f23aaa762fc03e40635ccbffd"
  • Files reviewed: 2/2 changed files
  • Comments generated: 0
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@brettheap
brettheap merged commit 7cf6c14 into main Sep 13, 2026
4 checks passed
brettheap added a commit to opensoft/openXdox that referenced this pull request Sep 13, 2026
…n column) and openDox pin to 7cf6c143 (S3/S4/S6 landings) (#9)

Lane: openxfactory-4-opendox-extraction

Refs opensoft/openxFactory#656 (stays OPEN). CLAIM: 5647338637.

Second leg of the pin lockstep: `code` advances `af15f712` → `d6e7bbe3` (S6),
`contracts/opendox-pin.yaml` advances `8ec3036c` → `7cf6c143` (matching
opensoft/openDox#7). `spec` unchanged.

Gate evidence: destination gate; `validate` SUCCESS (base confirmed `main`);
`scripts/validate-pins.py --pin-source openDox=<sibling clone>` recomputes
every digest (`pins ok`); `validate-manifest.py` and
`validate-repository-naming.py` also pass. 1 review thread, 0 unresolved —
Copilot's pin-ordering finding (`openXdox-code`'s own `pyproject.toml` still
depends on `openDox-code@a99eba03`), the same shape as two already-
registered findings on opensoft/openDox-code#16 and opensoft/openXdox-code#17
— replied (out of scope for an assembly-root pin bump; the remediation is
`openXdox-code`'s own separate pin-bump ceremony per
`docs/opendox-cutover-runbook.md` § 5.1, design D12, "two pin moves per
hop") and registered on #656, resolved. CLEAN/MERGEABLE, not draft.
brettheap added a commit to opensoft/openxFactory that referenced this pull request Sep 13, 2026
Lane: openxfactory-4-opendox-extraction

Refs #656 (stays OPEN). CLAIM: 5647338637.

Third and final leg of the pin lockstep (after opensoft/openDox#7 and
opensoft/openXdox#9), precedent #984: two gitlinks, two pin YAMLs, one test
literal.

| | from | to |
| --- | --- | --- |
| `openDox` gitlink + `contracts/opendox-pin.yaml` `commit:` | `8ec3036c…` | `7cf6c143e65e0bde799a5135dfde2dd66df5d495` |
| `contracts/opendox-pin.yaml` `digests.tree_sha256` | `71b97c8b…` | `46f49679e721e1d6c0d43c1aad370feec34c56bc5bbb2fffc88fa680734ecbc8` |
| `openXdox` gitlink + `contracts/openxdox-pin.yaml` `commit:` | `eca0b597…` | `76df74c8fd32db9aa71448c0ddac185c019b97fb` |
| `contracts/openxdox-pin.yaml` `digests.tree_sha256` | `c6d1078d…` | `a0a4a22f2d1729f655a8be499a375b61808f9ad1659d1b3c606143693b6f414d` |
| `tests/openxdox_pin/…::test_ruling_q7_two_direct_upstreams_in_lockstep` | `8ec3036c…` | `7cf6c143…` |

`openDox` assembly `7cf6c143` moves `code` (opensoft/openDox-code)
`a99eba03` → `05bbde80`: § 3.4 S4 (#17, thirteen gate-route constants split
to the class-B bindings that call them), its S3 fail-closed follow-up
(#18, landed via #22 after a base-branch retarget correction), and S6
(#16, `/source` becomes openDox's own fixed core arm). `openXdox` assembly
`76df74c8` moves `code` d6e7bbe3: S6's paired leg (the `/source` pair
leaves `serve_projection.py`) and its own `opendox-pin.yaml` copy advances
to match. `spec` unchanged on both.

Nine files, not five: the pin mechanics (five, per #984) plus four
`tests/ideation-dashboard/` consumer fixes the bump's own CI run forced
across two follow-up rounds (real breakage in this repo's own
characterization of code S4/S6 legitimately moved — `test_route_
extension.py`, `test_serve_column_split.py`, `test_extension_point_
parity.py`, `test_lens.py`), disclosed and itemized in the PR body.

Verified: `verify-opendox-pin.py` / `verify-openxdox-pin.py` OK;
`pytest tests/opendox_pin tests/openxdox_pin` 105 passed;
`validate-carve-manifest.py` OK; the four consumer files together 114
passed/1 skipped; the whole `tests/ideation-dashboard/` directory 1124
passed/13 skipped.

Plain gate: pytest-suite run 34730017839 SUCCESS at 0b14193; all required
checks green; 3 threads / 0 unresolved.
brettheap added a commit that referenced this pull request Sep 15, 2026
…arameterized) (#8)

Lane: openxfactory-4 (openXfactory-4-openDox_extraction)

Refs opensoft/openxFactory#656 (stays OPEN). CLAIM: 5656720756.

First leg of pin lockstep #2, on pin lockstep #1's precedent
(#7 -> 7cf6c14): `code` (opensoft/openDox-code) advances
`05bbde80` -> `1e469713`, carrying S 3.4 S5 leg B (opensoft/openDox-code#20
-> 8efb3cf5, the shell contributes the gate loop; RULED Q1-Q12) and S 3.4 S7
(opensoft/openDox-code#21 -> 1e469713, class C parameterized plus the four
arrived Act-1 suites). `spec` unchanged at `a8f5eb73`. Two files, the two #7
predicts; the digest is sorted-ls-tree-r-v1 recomputed from the submodule's own
object store, not retyped.

Gate evidence: `validate` SUCCESS at `f4e89880b237291790eb8e40ec9499df47893b01` (base confirmed `main`);
`scripts/validate-pins.py` recomputes the tree digest and confirms gitlink/pin-file
lockstep (`pins ok`); `validate-manifest.py` and `validate-repository-naming.py`
also pass; 0 review thread(s), 0 unresolved.

Lane: openxfactory-4
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants