fix(host): keep empty readiness checks responsive - #382
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (4)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughRuntime readiness reuse now checks storage for an unexpired successful native-readiness result before requesting the authenticated cache key. Tests cover candidate states and cache-key lookup calls. ChangesNative readiness lookup
Priority: ➖ Normal Estimated code review effort: 2 (Simple) | ~10 minutes Change: Bug fix Merge Risk: ⚪ Minimal · up to The readiness shortcut has no identified merge-blocking issue; complete the remaining normal CI and release checks before deployment. Security Architecture ReviewSecurity architecture risk: ⚪ Minimal · up to The change avoids unnecessary runtime authentication when no usable readiness evidence exists. It does not make a stored candidate sufficient to authorize work: current identity, runtime, permissions, and approvals must still match, and execution retains its separate checks. No material security risk was identified in the changed behavior. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 55.56% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 9 functions across 3 files. (1 skipped: 1 unsupported.)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
df240e4 to
ce67cef
Compare
|
Note 🤖 Codex responding on behalf of Microck @coderabbitai review |
|
ce67cef to
f28c976
Compare
|
Note 🤖 Codex responding on behalf of Microck @coderabbitai review |
✅ Action performedReview finished.
|
|
Note 🤖 Codex responding on behalf of Microck the new storage lookup documents the candidate check and why it cannot authorize execution. the runtime explains why an empty cache must skip native authentication. the remaining coverage warning includes test helpers and an existing private method; i am keeping those comments focused on the behavior rather than adding docstrings to meet a percentage. all three OS quality lanes pass, and the native build and lifecycle checks are still running. |
after setup clears native readiness, the mac host can listen normally while
/v1/capabilitiestimes out. an in-flight stack shows the status lookup authenticating the Codex app to build a cache key even though there is no saved evidence to reuse. this prevents the controller from reaching first-use preflight.the status path now checks authoritative SQLite for an unexpired successful candidate first. empty, failed, future, expired and invalidated evidence returns unavailable without native runtime discovery. a candidate still needs the full current authenticated key, so changed runtime evidence cannot authorize execution. prompt admission and live probes keep their existing checks.
validation: the owning runtime test uses real SQLite and the existing fake adapter to cover all seven states, including exact-match reuse and runtime mismatch. Crabbox passed all three owning runtime tests, including the seven candidate states, and workspace/all-target/all-feature Clippy with warnings denied. formatting passed. the build used one worker and disabled debug symbols because the shared host is short on disk and memory. cross-platform CI, build and lifecycle checks are running. device acceptance will follow the signed release; this PR does not claim the updated Mac has passed Luna yet.
Summary by CodeRabbit