Skip to content

Define strict portable tool records - #83

Closed
omry wants to merge 1 commit into
pr82from
pr83
Closed

Define strict portable tool records#83
omry wants to merge 1 commit into
pr82from
pr83

Conversation

@omry

@omry omry commented Aug 16, 2026

Copy link
Copy Markdown
Owner

Add versioned records for tool releases, contracts, targets, binding artifacts, payloads, native package sets, artifact sources, and validation evidence.

Enforce bounded strict JSON decoding, canonical identifiers and digests, request policy validation, credential-free HTTPS sources, and offline probes. Keep the records inert until later catalog migration activates them.

@omry
omry marked this pull request as ready for review August 16, 2026 00:25
Copilot AI lite review requested due to automatic review settings August 16, 2026 00:25

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@omry

omry commented Aug 16, 2026

Copy link
Copy Markdown
Owner Author

@codex review abdb90d

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: abdb90da27

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread internal/toolcatalog/records.go Outdated
@omry

omry commented Aug 16, 2026

Copy link
Copy Markdown
Owner Author

@codex review 3ce7f4b

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 3ce7f4b508

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread internal/toolcatalog/records.go
Comment thread internal/toolcatalog/records.go
@omry

omry commented Aug 16, 2026

Copy link
Copy Markdown
Owner Author

@codex review 9673dbc

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 9673dbc10d

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread internal/toolcatalog/records.go Outdated
@omry

omry commented Aug 16, 2026

Copy link
Copy Markdown
Owner Author

@codex review 563cf38

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 563cf38650

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread internal/toolcatalog/records.go
Comment thread internal/toolcatalog/records.go Outdated
@omry

omry commented Aug 16, 2026

Copy link
Copy Markdown
Owner Author

@codex review e5ee84b

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Already looking forward to the next diff.

Reviewed commit: e5ee84bb5c

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@omry omry added the approved PR reviewed and approved label Aug 16, 2026
@omry omry removed the approved PR reviewed and approved label Aug 16, 2026
@omry
omry force-pushed the pr83 branch 2 times, most recently from 92bc560 to 272fcf1 Compare August 16, 2026 06:17
@omry
omry force-pushed the pr82 branch 2 times, most recently from 0d691b6 to 359b1db Compare August 16, 2026 06:24
@omry
omry force-pushed the pr83 branch 2 times, most recently from db16d2d to 6cf3dd1 Compare August 16, 2026 06:31

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: d86dd0c8d0

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread internal/providers/python/package_request.go
@omry

omry commented Aug 16, 2026

Copy link
Copy Markdown
Owner Author

@codex review current head 3cccd26

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 3cccd266a4

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread internal/toolcatalog/record_validation.go Outdated
Comment thread internal/toolcatalog/record_validation.go
@omry

omry commented Aug 16, 2026

Copy link
Copy Markdown
Owner Author

@codex review current head ec57c2d

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: ec57c2d8d1

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread internal/toolcatalog/record_validation.go
Comment thread internal/toolcatalog/record_validation.go
Comment thread internal/toolcatalog/records.go Outdated
Comment thread internal/providers/python/version.go
@omry

omry commented Aug 16, 2026

Copy link
Copy Markdown
Owner Author

@codex review current head 6e35734

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 6e35734c93

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread internal/toolcatalog/records.go
@omry

omry commented Aug 16, 2026

Copy link
Copy Markdown
Owner Author

@codex review current head 3af6043

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 3af6043c9e

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread internal/toolcatalog/record_validation.go
Comment thread internal/toolcatalog/record_validation.go
Comment thread internal/toolcatalog/record_validation.go Outdated
@omry

omry commented Aug 16, 2026

Copy link
Copy Markdown
Owner Author

@codex review current head 1799a63

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 1799a634c4

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread internal/toolcatalog/record_validation.go
Comment thread internal/toolcatalog/record_validation.go
Comment thread internal/toolcatalog/record_validation.go
@omry

omry commented Aug 16, 2026

Copy link
Copy Markdown
Owner Author

@codex review current head 40d3a04

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 40d3a04620

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread internal/toolcatalog/record_validation.go
Comment thread internal/toolcatalog/record_validation.go
Comment thread internal/toolcatalog/record_validation.go
Comment thread internal/toolcatalog/record_validation.go
Comment thread internal/toolcatalog/record_validation.go
Comment thread internal/toolcatalog/record_validation.go
@omry

omry commented Aug 16, 2026

Copy link
Copy Markdown
Owner Author

@codex review current head 959fb04

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 959fb045b3

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread internal/toolcatalog/record_validation.go
Comment thread internal/toolcatalog/record_validation.go
Comment thread internal/toolcatalog/record_validation.go
Comment thread internal/toolcatalog/record_validation.go
Add versioned records for tool releases, contracts, targets, binding artifacts, payloads, native package sets, artifact sources, and validation evidence.

Enforce bounded strict JSON decoding, canonical identifiers and digests, request policy validation, credential-free HTTPS sources, and offline probes. Keep the records inert until later catalog migration activates them.
@omry

omry commented Aug 16, 2026

Copy link
Copy Markdown
Owner Author

@codex review current head 2db9a2f

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 2db9a2faca

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +778 to +781
for _, version := range contract.SupportedPython {
parsed, err := pep440.Parse(version)
if err == nil && pythonSpecifiers.Check(parsed) {
return nil

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Cover every supported interpreter with wheel tags

When the contract advertises Python 3.11 and 3.12 but the target provides only a cp311-cp311 wheel with requires_python: ">=3.11", this returns success after finding one version allowed by requires_python, even though Python 3.12 cannot install that artifact. Fresh evidence beyond the earlier artifact-contract finding is that the current acceptance path still never evaluates the wheel's Python/ABI tags or verifies that the complete artifact set covers every advertised interpreter; require tag-compatible artifact coverage for each SupportedPython value.

Useful? React with 👍 / 👎.

return string(payload), nil
}

func validateTupleContributionsV1(records map[string]loadedRecordV1, contract *ReleaseContractV1, target *TargetRecordV1, tuple supportTupleV1) error {

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Reject payload destination collisions per support tuple

When an unconditional payload and a selected payload, or two co-selectable payloads, use the same logical path or overlapping install destinations with different records, graph validation succeeds because tuple validation considers only package requirements and exports. The accepted tuple can therefore overwrite one payload with another during materialization; resolve the active payloads here and reject conflicting semantic paths while allowing only byte-identical contributions to deduplicate.

Useful? React with 👍 / 👎.

Comment on lines +695 to +700
group, reachable := reachableArtifacts[mapping.ArtifactSHA256]
if !reachable {
return fmt.Errorf("artifact source mapping %d is not reachable from an advertised target", index)
}
if _, belongs := group[artifact.ID]; !belongs {
return fmt.Errorf("artifact source mapping %d names an artifact outside its reachable content group", index)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Check sizes for every artifact sharing a mapped digest

When two reachable artifact records share one SHA-256 but declare different sizes, a source mapping that names the correctly sized record passes because the size comparison covers only mapping.Artifact, while this content-group check merely confirms that the named ID belongs to the digest group. The other reachable record then resolves through the same digest mapping with contradictory acquisition metadata and can fail size verification; require every record in the reachable content group to agree with the source size.

Useful? React with 👍 / 👎.

@omry

omry commented Aug 17, 2026

Copy link
Copy Markdown
Owner Author

Superseded by the portable-tool reconstruction. This PR's content is being split into individually reviewable slices PTD-01 through PTD-06 per docs/PORTABLE_TOOL_DEFINITION_IMPLEMENTATION_PLAN.md, each landing as its own commit and PR.

No content is lost. Local extraction source: b39985d247e5 (rewritten from 9e9cb456db0d, originally e5ee84b).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants