Repository navigation
openDox root: bump code to 05bbde80 (S3 fail-closed follow-up, S4 route-tail split, S6 /source core-arm) - #7
Conversation
…te-tail split, S6 /source core-arm) Lane: openxfactory-4-opendox-extraction Refs opensoft/openxFactory#656 (stays OPEN). CLAIM: 5647338637. `code` (opensoft/openDox-code) advances a99eba03 -> 05bbde80, carrying three landed slices since the last bump: S4 (opensoft/openDox-code#17, the thirteen gate-route constants split from lens-model.js/repo-selector.js/staging- workbench-model.js to the class-B bindings that call them), its S3 fail- closed follow-up (opensoft/openDox-code#18, landed via #22 after a base- branch retarget correction: a shared requireRouteShape() now refuses a malformed contributed-routes entry instead of coercing it), and S6 (opensoft/openDox-code#16, /source becomes openDox's own fixed core arm per RULED Q4). `scripts/validate-pins.py` recomputes the tree digest (98634678b193dd9e24a6ab86211546e6b415864dabffd44999f18ff646c01a81) and confirms the gitlink/pin-file lockstep; no workflow file names this leg by sha. `spec` is unchanged. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
There was a problem hiding this comment.
Sorry @brettheap, you've used your own review budget of 250,000 diff characters for the last 7 days.
You can request another review in 1 day and 17 hours by commenting @sourcery-ai review. Upgrade to get a review now.
Reviewer's guide (collapsed on small PRs)Reviewer's GuideUpdates the openDox code pin to 05bbde80 and its verified tree digest, incorporating the S4 route-tail binding split, S3 fail-closed route-shape validation, and S6 fixed core handling for /source; specification files remain unchanged. Sequence diagram for fail-closed contributed-route validationsequenceDiagram
participant Manifest as manifestRoutes()
participant Shape as requireRouteShape(claimed)
participant Breach as ownershipBreach()
Manifest->>Shape: validate contributed route
Shape-->>Manifest: valid route shape
Breach->>Shape: validate contributed route
Shape-->>Breach: valid route shape
alt missing string pattern or non-boolean is_prefix
Shape-->>Manifest: reject route
Shape-->>Breach: reject route
end
Flow diagram for fixed core /source routingflowchart TD
Request[HTTP request]
Source{path is /source}
Core[openDox fixed core arm]
Contributed[Contributed route consult]
Response[Route response]
Request --> Source
Source -->|yes| Core
Source -->|no| Contributed
Core --> Response
Contributed --> Response
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
|
There was a problem hiding this comment.
🔵 Needs a closer look
Advance the code gitlink to match the recorded pin and restore lockstep validation.
Pull request overview
Advances the openDox code pin to include route validation hardening, route-tail classification, and the fixed /source core arm.
Changes:
- Updates the pinned commit and verified tree digest.
- Preserves the documented
specand workflow references. - The corresponding
codegitlink remains unadvanced, breaking pin lockstep.
File summaries
| File | Summary |
|---|---|
contracts/code-pin.yaml |
Records the new code commit and tree digest; the matching code gitlink must also be updated. |
Review details
Suppressed comments (1)
contracts/code-pin.yaml:24
- This change updates only the recorded pin; the corresponding
codesubmodule gitlink is not moved in the diff. That leaves the lockstep invariant broken andscripts/validate-pins.pywill reportpin-gitlink-mismatchuntil the gitlink is advanced to05bbde80f91a870f23aaa762fc03e40635ccbffdin the same commit. Please usescripts/bump-leg.py(or otherwise update the gitlink and rerunmake validate).
commit: "05bbde80f91a870f23aaa762fc03e40635ccbffd"
- Files reviewed: 2/2 changed files
- Comments generated: 0
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
…n column) and openDox pin to 7cf6c143 (S3/S4/S6 landings) (#9) Lane: openxfactory-4-opendox-extraction Refs opensoft/openxFactory#656 (stays OPEN). CLAIM: 5647338637. Second leg of the pin lockstep: `code` advances `af15f712` → `d6e7bbe3` (S6), `contracts/opendox-pin.yaml` advances `8ec3036c` → `7cf6c143` (matching opensoft/openDox#7). `spec` unchanged. Gate evidence: destination gate; `validate` SUCCESS (base confirmed `main`); `scripts/validate-pins.py --pin-source openDox=<sibling clone>` recomputes every digest (`pins ok`); `validate-manifest.py` and `validate-repository-naming.py` also pass. 1 review thread, 0 unresolved — Copilot's pin-ordering finding (`openXdox-code`'s own `pyproject.toml` still depends on `openDox-code@a99eba03`), the same shape as two already- registered findings on opensoft/openDox-code#16 and opensoft/openXdox-code#17 — replied (out of scope for an assembly-root pin bump; the remediation is `openXdox-code`'s own separate pin-bump ceremony per `docs/opendox-cutover-runbook.md` § 5.1, design D12, "two pin moves per hop") and registered on #656, resolved. CLEAN/MERGEABLE, not draft.
Lane: openxfactory-4-opendox-extraction Refs #656 (stays OPEN). CLAIM: 5647338637. Third and final leg of the pin lockstep (after opensoft/openDox#7 and opensoft/openXdox#9), precedent #984: two gitlinks, two pin YAMLs, one test literal. | | from | to | | --- | --- | --- | | `openDox` gitlink + `contracts/opendox-pin.yaml` `commit:` | `8ec3036c…` | `7cf6c143e65e0bde799a5135dfde2dd66df5d495` | | `contracts/opendox-pin.yaml` `digests.tree_sha256` | `71b97c8b…` | `46f49679e721e1d6c0d43c1aad370feec34c56bc5bbb2fffc88fa680734ecbc8` | | `openXdox` gitlink + `contracts/openxdox-pin.yaml` `commit:` | `eca0b597…` | `76df74c8fd32db9aa71448c0ddac185c019b97fb` | | `contracts/openxdox-pin.yaml` `digests.tree_sha256` | `c6d1078d…` | `a0a4a22f2d1729f655a8be499a375b61808f9ad1659d1b3c606143693b6f414d` | | `tests/openxdox_pin/…::test_ruling_q7_two_direct_upstreams_in_lockstep` | `8ec3036c…` | `7cf6c143…` | `openDox` assembly `7cf6c143` moves `code` (opensoft/openDox-code) `a99eba03` → `05bbde80`: § 3.4 S4 (#17, thirteen gate-route constants split to the class-B bindings that call them), its S3 fail-closed follow-up (#18, landed via #22 after a base-branch retarget correction), and S6 (#16, `/source` becomes openDox's own fixed core arm). `openXdox` assembly `76df74c8` moves `code` d6e7bbe3: S6's paired leg (the `/source` pair leaves `serve_projection.py`) and its own `opendox-pin.yaml` copy advances to match. `spec` unchanged on both. Nine files, not five: the pin mechanics (five, per #984) plus four `tests/ideation-dashboard/` consumer fixes the bump's own CI run forced across two follow-up rounds (real breakage in this repo's own characterization of code S4/S6 legitimately moved — `test_route_ extension.py`, `test_serve_column_split.py`, `test_extension_point_ parity.py`, `test_lens.py`), disclosed and itemized in the PR body. Verified: `verify-opendox-pin.py` / `verify-openxdox-pin.py` OK; `pytest tests/opendox_pin tests/openxdox_pin` 105 passed; `validate-carve-manifest.py` OK; the four consumer files together 114 passed/1 skipped; the whole `tests/ideation-dashboard/` directory 1124 passed/13 skipped. Plain gate: pytest-suite run 34730017839 SUCCESS at 0b14193; all required checks green; 3 threads / 0 unresolved.
…arameterized) (#8) Lane: openxfactory-4 (openXfactory-4-openDox_extraction) Refs opensoft/openxFactory#656 (stays OPEN). CLAIM: 5656720756. First leg of pin lockstep #2, on pin lockstep #1's precedent (#7 -> 7cf6c14): `code` (opensoft/openDox-code) advances `05bbde80` -> `1e469713`, carrying S 3.4 S5 leg B (opensoft/openDox-code#20 -> 8efb3cf5, the shell contributes the gate loop; RULED Q1-Q12) and S 3.4 S7 (opensoft/openDox-code#21 -> 1e469713, class C parameterized plus the four arrived Act-1 suites). `spec` unchanged at `a8f5eb73`. Two files, the two #7 predicts; the digest is sorted-ls-tree-r-v1 recomputed from the submodule's own object store, not retyped. Gate evidence: `validate` SUCCESS at `f4e89880b237291790eb8e40ec9499df47893b01` (base confirmed `main`); `scripts/validate-pins.py` recomputes the tree digest and confirms gitlink/pin-file lockstep (`pins ok`); `validate-manifest.py` and `validate-repository-naming.py` also pass; 0 review thread(s), 0 unresolved. Lane: openxfactory-4 Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>



Lane: openxfactory-4-opendox-extraction
Refs opensoft/openxFactory#656 (stays OPEN). CLAIM: 5647338637.
First leg of the pin lockstep that advances openxFactory's
openDoxandopenXdoxpins to the § 3.4 S4/S6 landings (precedent: this root's own #6,openXdox's #8, then openxFactory#984 — the same order, followed here).
code(opensoft/openDox-code) advancesa99eba03→05bbde80:declared in
lens-model.js,repo-selector.js,staging-workbench- model.jssplit to the class-B bindings that call them (four new files);/actions/refreshmeasured and stays class A.after a base-branch retarget correction — see openDox + openXdox: two open-source layers, an installable app with users, projects and a database; domain descendants pin openXdox (Brett's ruling 2026-09-04) openxFactory#656's
S4 landing note for the detail):
requireRouteShape(claimed)now refusesa contributed-routes entry with a missing string
patternor anon-boolean
is_prefix, shared betweenmanifestRoutes()andownershipBreach()./sourcebecomes openDox'sown fixed core arm in
serve.py, above the § 2.4 contributed consult.specis unchanged.scripts/validate-pins.pyrecomputes the tree digest(
98634678b193dd9e24a6ab86211546e6b415864dabffd44999f18ff646c01a81) andconfirms gitlink/pin-file lockstep;
validate-manifest.pyandvalidate-repository-naming.pyalso pass. No.github/workflows/*.ymlnames this leg by sha.
🤖 Generated with Claude Code
Summary by Sourcery
Advance the openDox code pin to incorporate route validation hardening, route-tail classification, and the fixed
/sourcecore arm.New Features:
/sourcearm.Bug Fixes:
Enhancements:
/actions/refreshas class A.Chores: