fix(release): close PR17 post-merge Codex P2 review debt#18
Conversation
Constrain OpenSSL to trusted absolute binaries, scrub GIT_COMMON_DIR, require raw commit objects for repo_commit (reject annotated tags), and reject duplicate JSON keys. Add G-18d1d/d4b/d5/d5b/d6 gates. Lock signed fixture bytes via gitattributes. Refresh G-19 pins mechanically. Token: CEO_GO_VTOOLS_PR17_POSTMERGE_CODEX_REVIEW_P2_REMEDIATION_01
Keep signed-fixture CRLF lock out of this PR; GitHub runners already preserve fixture bytes. Focus remains the 4 post-merge Codex P2 fixes.
CI runners without user.name/email could not create annotated tags, so repo_commit never received a 40-hex tag object SHA.
Force annotated-tag object SHA via ^{tag}, normalize hex ids without
collapsing symbolic HEAD, and accept fail-closed diagnostics for G-18d1d.
Token: CEO_GO_GROK_AUTHORITY_MEMORIALIZE_AND_VTOOLS_PR17_POSTMERGE_P2_REPAIR_01
Token: CEO_GO_GROK_AUTHORITY_MEMORIALIZE_AND_VTOOLS_PR17_POSTMERGE_P2_REPAIR_01
Reject planted paths that merely contain the substring program files/openssl; require real c:/program files[/ (x86)]/openssl* prefixes after resolve.
…n in G-18d1d Codex P2 on dbf67ff: do not strip/lowercase signed repo_commit fields; fail closed on non-canonical hex. Gate fixture disables tag.gpgSign so signed-tag configs cannot abort annotated-tag setup. Refresh G-19 pins. Token: CEO_GO_GROK_VTOOLS_PR18_CLOSEOUT_REVIEW_REPAIR_MERGE_POSTVERIFY_AND_PR17_THREAD_CLOSE_01
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: dbf67ffafd
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Reject openssl-malicious-style siblings under Program Files. Only exact layouts openssl|openssl-win64|openssl-win32 under bin/openssl.exe pass. Addresses Codex P2 on 3c4dd77. Refresh release-material pin.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 3c4dd77d4d
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
Codex Review: Didn't find any major issues. Keep it up! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
Authority
CEO_GO_GROK_AUTHORITY_MEMORIALIZE_AND_VTOOLS_PR17_POSTMERGE_P2_REPAIR_01
Post-facto Founder/CEO confirmation memorial (not a pre-merge artifact):
06_AGENT_EXCHANGE/CEO/2026-07-09T01-52-00Z_CEO_FOUNDER_AUTHORITY_MEMORIALIZATION_EEE90_VTOOLS17_POSTFACTO.mdClassification
PR #17 merge is not unauthorized. This draft repairs post-merge Codex P2 debt only.
Base / head
main@5a15e4f1443211d919af82e9f0165ae6099a5954(PR feat(release): add signed manifest readiness model #17 merge)dbf67ffafde5a66684d917b21fefa334aa636a58Scope (allowlist)
memoriaia/verify/verify-release-manifest.pytests/run-gates.sh.github/workflows/ci.yml— G-19 pin refresh onlyLive P2 families (PR #17 threads)
PRRT_kwDOR508U86PbHG4PRRT_kwDOR508U86PbHG7GIT_COMMON_DIR(G-18d4b)PRRT_kwDOR508U86PbHG-git cat-file -tmust be exactcommit(G-18d1d)PRRT_kwDOR508U86PbHHDAlso preserved:
GIT_NO_REPLACE_OBJECTS/git --no-replace-objects; G-18d0 release-candidate requires--release-mode.Remote CI
28989156811: Ubuntu SUCCESS + Windows SUCCESS on headdbf67ffafde5a66684d917b21fefa334aa636a580Boundaries
Maximum claim