feat(rdp): atomically verify native option selections - #291
Conversation
|
Release-candidate coordination: please keep reviewing and fixing this PR, but do not merge it until v1.25.1 is published and independently verified. The exact patch candidate is main@2be33278f41a5dc232133da515ae3bebbe8656bb; merging this feat before publication would change the authorized semantic release from patch to minor. |
|
Release sequencing update: v1.25.1 has been published and independently verified (tag/release commit lineage, GitHub/PyPI byte-identical artifacts, archive boundary checks, and both attestations). The temporary publication hold is lifted; resume normal review and merge sequencing from current main. |
6188d6e to
2e7d9a5
Compare
|
Coordination update: exact head 9b1217c must not merge. Required Citrix and Docker-RDP qualifications returned accepted=false. Independent review confirmed the preserved visual-anchor-vs-field-region correction (dirty-diff SHA-256 04566ac3bc74be077b5c5ec79f2359b59b8c6613b428390251638ca4d3491dad) is necessary; add the compact visual anchor -> unanchored TYPE regression and rerun both remote gates. PR #288 has now merged as current main f133bbd, so rebase the corrected candidate there before the single authoritative rerun. The superseded main CI was canceled to stop paid long jobs. |
|
Ownership update: Codex is resuming #291 in a fresh isolated clone from exact Git objects. Do not push, clean, reset, or reuse the dirty shared worktree. I will preserve the reviewed 04566ac3 correction, add the required compact-anchor/unanchored-TYPE regression, rebase onto current main f133bbd, then run one authoritative matrix. |
9b1217c to
f146842
Compare
f146842 to
67469d8
Compare
What changed
This PR closes the fail-closed OpenEMR/xrdp diagnosis without weakening input verification. It contains four focused commits:
SELECT_OPTIONcontract and verify the exact committed value.SELECT_OPTIONis deliberately a new fail-loud IR action rather than optional metadata onTYPE, so an older runtime cannot silently omit the commit. The compiler only emits it for externally controlled RDP/Citrix recordings when the retained frames prove an uninterrupted click/type/commit gesture and exact normalized committed value. It preserves the focusing anchor and identity audit, remaps absorbed risk overrides, excludes parameter pixels fromREGION_STABLE, and binds the target surface into compiler provenance.At runtime, the action:
West Virginiafor intendedVirginia.The shared
openadapt-typesschema and effect re-navigation schema cannot represent this composite contract yet, so both boundaries refuse lossy conversion explicitly.Why
The retained OpenEMR v25 campaign completed three healthy trials through the remote client and then safely halted at the native State selector in all 3/3 trials. The recorder demonstrated
Massachusettstypeahead followed by Enter, but the prior transport emitted one focus-sensitive process per character and ordinaryTYPEtried to verify the provisional pre-commit state.Those are diagnosis runs, not successful qualification evidence. Independent REST plus SQL checks proved no patient write in every trial; observed model calls and silent incorrect success were both zero. The campaign must be rerun after this candidate is merged and released before any success claim.
Validation
2be33278f41a5dc232133da515ae3bebbe8656bb6188d6e4b4d8152be57f7bfecfbc52674057df44SELECT_OPTIONactions, including Statestep_024No live campaign was restarted, no provider resource was enabled, and no provider spend occurred.
Merge boundary
Keep this PR unmerged until the v1.25.1 publication guard has cleared. After merge and exact-main CI, publish the patch candidate, then rerun the countable OpenEMR 3+3+3 qualification campaign from the retained recording.