Conversation
How I verified this13 commands recorded - as recorded (shortened, folded onto one line), grouped by kind. No entry asserts a pass or a fail: read the output. Not necessarily everything the session ran. Not everything recorded is shown: the 12 most recent of those listed are shown with their captured output, and the other 1 command is shown as a command line only. test
excerpt - 4,442 characters of output in total
excerpt - 2,486 characters of output in total
excerpt - 3,548 characters of output in total
excerpt - 2,185 characters of output in total
lint
Not verified: everything below is a limit of this section, listed whether or not it bit this attempt.
See the PR body's Evidence table for the orchestrator's own test run. |
Independent review — PASSED (1 round) on
|
| Severity | Finding | Where | Note |
|---|---|---|---|
| ✅ | All five acceptance criteria met with mutation-killing tests | src/no_human/ci_action/run.py:1287 |
Traced the fork path end to end and it holds up: the artifact is fetched strictly by run id, the pull is fetched by the artifact-claimed number and then cross-c |
| ✅ | security angle did not run (reached no verdict) | — | advisory — the extra angle pass was skipped; the main review still gates |
| ✅ | tests angle did not run (reached no verdict) | — | advisory — the extra angle pass was skipped; the main review still gates |
| ✅ | silent-failure angle did not run (reached no verdict) | — | advisory — the extra angle pass was skipped; the main review still gates |
1 advisory finding (low/nit — never blocking)
| Severity | Finding | Where | Note |
|---|---|---|---|
| ❌ low | maintainability: duplicated client-construct + error-funnel across the two branches | src/no_human/ci_action/run.py:1225 |
These two branches each open their own GitHubClient and wrap it in the same except (GitHubAPIError, WriteSurfaceViolation) -> identical `_fail("a GitHub API |
Evidence
Verifiers (1)
Merge-ready policy (6 rules, source: default)
Acceptance criteria
Changes
Final Report
Resuming context: The prior blocker (reviewer discarding a verdict without opening
src/no_human/ci_action/github.py) was fixed on main by d2bf0c1, confirmed by the operator. My prior implementation was intact in the worktree at commit85d44c8a1on top of a merge ofno-human/7f1660bb-2, but the branch was stale relative to currentorigin/main. I rebased: sinceno-human/7f1660bb-2's ci_action content was byte-identical to what landed on main as4ea03f774, I resolved the three redundant intermediate-commit conflicts by taking the upstream content (verified identical beforehand), then git auto-dropped the fully-redundant final dependency commit as "patch contents already upstream." My feature commit now sits cleanly on top of currentorigin/mainas a single commit522304b6b, with a diff (vs4ea03f774) touching exactly the 4 intended files:RELEASE_MANIFEST.txt,src/no_human/ci_action/github.py,src/no_human/ci_action/run.py,tests/test_ci_action.py(1118 insertions, 61 deletions) — no scope creep.Rest of the coder's report (7 more paragraphs)
Implementation summary:
github.py: added GET-only allowlist anchors_RUN_ARTIFACTS_PATH(/actions/runs/{id}/artifacts) and_ARTIFACT_ZIP_PATH(/actions/artifacts/{id}/zip), deliberately excluding the name-scoped?name=listing;find_run_artifact()fetches run-id-scoped, re-filters client-side on exact name, refuses on 0/>1 matches/expired/oversize;download_artifact_zip()follows exactly one redirect hop on a credential-free client, size-capped.run.py: fork path (pull_requestsempty) reads trustedworkflow_runfields, resolves PR number via_resolve_pr_context(artifact bound to run id + head-sha check), fetches the pull by that number, then_assert_pull_matches_runcross-checks number/head-sha/head-repo/head-branch/base-repo/base-ref — all before the credential is read. Same-repo path untouched.Mutation evidence (each applied, confirmed RED, then reverted — working tree verified clean afterward):
find_run_artifact→ name-only lookup: 3 tests failed, includingtest_fork_workflow_run_artifact_fetch_is_scoped_to_triggering_run_id—WriteSurfaceViolation: refused GET /repos/acme/widgets/actions/artifacts?per_page=100&name=pr-context ... (never the name-scoped .../actions/artifacts?name=... listing, which is not run-bound).numbercomparison from_assert_pull_matches_run:test_pull_whose_number_disagrees_with_the_artifact_is_refusedfailed —assert 0 == 2(ran toEXIT_OKinstead of refusing). Full suite:1 failed, 131 passed.test_pull_base_repository_mismatch_is_refusedandtest_pull_base_ref_empty_is_refusedboth failed —assert 0 == 2.Test run (final gate):
uv run python scripts/check_release_manifest.py --strict→OK: 1712 file(s) match RELEASE_MANIFEST.txt.(a paragraph matched a filtered-phrase list and was removed)
ASSUMPTIONS:
Resolved the stale-rebase conflicts by taking
origin/main's content for the 3 intermediate dependency commits (verified byte-identical to my branch's pre-rebaseno-human/7f1660bb-2tip before doing so), then replaying only my own feature commit — a reversible, content-preserving resolution.origin/mainadvanced by one more unrelated commit (81f3c2a5b, touchingblockers/challenge.py/core/orchestrator.py) while I worked; I did not chase this further churn since it's outside scope and unrelated toci_action.MET — The artifact is fetched by the triggering run id, not by name alone — evidence:
src/no_human/ci_action/github.py:413-427(find_run_artifactbuilds/repos/{repo}/actions/runs/{run_id}/artifacts),github.py:90(_RUN_ARTIFACTS_PATHallowlist excludes name-only shape). Mutation test: `test_fork(summary truncated at 4000 characters — full report:
nh task show <task-id>)Superseded PRs
Earlier attempts on this task opened these drafts and did not finish them:
How I verified this
Tests (11 runs, last shown) —
git status echo "---" uv run pytest tests/test_ci_action.py -q -n 4 2>&1 | tail -10· full logLint (2 runs, last shown) —
uv run python -m ruff check src/<redacted>/ci_action tests/test_ci_action.py 2>&1 | tail -40· full log13 commands recorded while working. Full verification log: ~/.no_human/artifacts/b4a1761d514340b0b539b6ee92dc4535/verification-attempt-2.md —
nh logs b4a1761d; the same log, every command with its captured output, is posted as this PR's How I verified this comment when posting succeeds. Whether it passed is in the Evidence table above: no entry here asserts a pass or a fail.Opened by no_human (attempt 2 of 3,
no-human/b4a1761d-2→main). It never merges: review and merge this yourself, or runnh approve b4a1761d.