Skip to content

test(runtime): pin Source Cache Git bundle primitives - #2762

Merged
zfy0701 merged 2 commits into
agentconnect-md:mainfrom
Harbor404:feat/source-cache-p0
Oct 1, 2026
Merged

zfy0701 merged 2 commits into
agentconnect-md:mainfrom
Harbor404:feat/source-cache-p0

Conversation

@Harbor404

Copy link
Copy Markdown
Contributor

Summary

Records the Source Cache P0 prerequisites and pins the runtime image's Git capabilities so a base-image bump cannot silently regress them.

This PR covers the locally provable parts of #2731:

  • adds an in-image regression check for Git >= 2.38, --bundle-uri, git bundle create --filter=blob:none, and GIT_NO_LAZY_FETCH
  • records the verified runtime image Git 2.39.5 baseline
  • records the MinIO S3 compatibility matrix for conditional writes, signed presigned PUT headers, and tag-filtered lifecycle
  • records container-level bundle behavior evidence for HTTPS query URLs, foreign bundles, incomplete bundles, and blobless clones
  • records the remaining AWS S3, test-app pod, and timing blockers
  • records the P0 go/no-go

Verification

  • node --test scripts/*.test.mjs: 85 passed
  • the new probe executed in the pinned runtime base digest: passed
  • pnpm exec eslint docker/runtime-sandbox/verify-image.mjs: passed
  • pnpm exec prettier --check docker/runtime-sandbox/verify-image.mjs docs/designs/source-cache.md: passed

CP0.1 is complete. CP0.2 is complete for MinIO and blocked on AWS credentials. CP0.3 has container-level evidence but is not complete until the test-app pod run. CP0.4 remains blocked without test-app access. CP0.5 is updated.

Part of #2731

Created by Codex . deepseek-v4-flash

@agentconnect-md-test agentconnect-md-test Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Architecture review — APPROVE

I checked this against the approved Source Cache design (#2729). It fits the design and doesn't move it.

What fits

  • The Git capability pin sits in the existing runtime-image verifier. It runs for both runtime-sandbox and runtime-sandbox-full after the non-root check, so it tests the final runtime user, not a build-time root. That's the right layer: pool daemons spawn no Git, so the runtime image is the only place these primitives matter.
  • The probe uses file:// only. The image build stays hermetic, and the --bundle-uri https-only exec rule is unaffected.
  • The probe pins the exact shapes the design depends on: a filtered blob:none bundle create under GIT_NO_LAZY_FETCH=1 (the narrow write-back form), lazy-fetch suppression, and a bundle consumed by a blobless clone. The tree:0 → full-clone failure leaves refs/bundles/* behind, which backs up the retry contract (§7) and the shim's ref cleanup.
  • The go/no-go is scoped honestly. P1 goes ahead against the pinned base and MinIO. AWS S3 support, default-on, and the pod/timing baselines stay blocked, and the chart default stays off. The PR says "Part of #2731" and lists the CP0.x items that are still open, as CLAUDE.md requires.

Non-blocking — please settle before P1 write-back lands

  1. The store-capability fallbacks are new rules with no mechanism behind them. The §14 block now says: no If-Match → last-writer-wins; no enforced signed length/checksum/tag → write-back off; no tag-filtered lifecycle → write-back off. Only the first is already in §9. The other two are new invariants, and they only appear in a dated evidence section. Nothing in §9, §10 or the §12 Helm values says how the daemon knows a store's capabilities. A store that silently ignores signed headers looks like a successful PUT, so this can't be found out at runtime. Move the rule into §9/§12 as an explicit gate that defaults to closed. Write-back should be enabled only for a store the operator declares, or a startup conformance probe proves, to enforce all three. Otherwise the "no object reaches the bucket without a row or a pending tag" guarantee depends on deployment luck.
  2. CP0.3 is a dangling reference. Nothing in docs/ defines it; it's a checklist item in #2731. Link the issue or name the check ("test-app pod run").
  3. Lab notes in the design doc will go stale. The image digest, "this workstation had no AWS credentials", and the per-run evidence table are a status log, not design. Consider keeping only the requirement and the pinned gate in §3/§14 and moving the evidence to #2731. Then the next base bump doesn't leave a stale digest in the design.
  4. HTTPS query-string bundle URLs are so far only tested at the container level. Make sure the P1 test-app pod run covers the real presigned-GET path, since the image probe can't.

sent by architect (Claude Agent · default) · open in session

@agentconnect-md-test agentconnect-md-test Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved. The new image verifier exercises filtered bundle creation, bundle-backed clone, and the GIT_NO_LAZY_FETCH guard under the runtime user. I ran the probe with Git 2.39.5; it passed, and a negative control confirmed that removing GIT_NO_LAZY_FETCH invokes the configured failing upload-pack helper. The Source Cache note clearly records the remaining AWS S3 and test-app pod checks as unverified. No blocking findings for this revision.

sent by review-bot (Codex · gpt-6-sol) · open in session

@zfy0701
zfy0701 merged commit 7d08484 into agentconnect-md:main Oct 1, 2026
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants