test(runtime): pin Source Cache Git bundle primitives - #2762
Conversation
There was a problem hiding this comment.
Architecture review — APPROVE
I checked this against the approved Source Cache design (#2729). It fits the design and doesn't move it.
What fits
- The Git capability pin sits in the existing runtime-image verifier. It runs for both
runtime-sandboxandruntime-sandbox-fullafter the non-root check, so it tests the final runtime user, not a build-time root. That's the right layer: pool daemons spawn no Git, so the runtime image is the only place these primitives matter. - The probe uses
file://only. The image build stays hermetic, and the--bundle-urihttps-only exec rule is unaffected. - The probe pins the exact shapes the design depends on: a filtered
blob:nonebundle create underGIT_NO_LAZY_FETCH=1(the narrow write-back form), lazy-fetch suppression, and a bundle consumed by a blobless clone. Thetree:0→ full-clone failure leavesrefs/bundles/*behind, which backs up the retry contract (§7) and the shim's ref cleanup. - The go/no-go is scoped honestly. P1 goes ahead against the pinned base and MinIO. AWS S3 support, default-on, and the pod/timing baselines stay blocked, and the chart default stays off. The PR says "Part of #2731" and lists the CP0.x items that are still open, as CLAUDE.md requires.
Non-blocking — please settle before P1 write-back lands
- The store-capability fallbacks are new rules with no mechanism behind them. The §14 block now says: no
If-Match→ last-writer-wins; no enforced signed length/checksum/tag → write-back off; no tag-filtered lifecycle → write-back off. Only the first is already in §9. The other two are new invariants, and they only appear in a dated evidence section. Nothing in §9, §10 or the §12 Helm values says how the daemon knows a store's capabilities. A store that silently ignores signed headers looks like a successful PUT, so this can't be found out at runtime. Move the rule into §9/§12 as an explicit gate that defaults to closed. Write-back should be enabled only for a store the operator declares, or a startup conformance probe proves, to enforce all three. Otherwise the "no object reaches the bucket without a row or apendingtag" guarantee depends on deployment luck. CP0.3is a dangling reference. Nothing indocs/defines it; it's a checklist item in #2731. Link the issue or name the check ("test-app pod run").- Lab notes in the design doc will go stale. The image digest, "this workstation had no AWS credentials", and the per-run evidence table are a status log, not design. Consider keeping only the requirement and the pinned gate in §3/§14 and moving the evidence to #2731. Then the next base bump doesn't leave a stale digest in the design.
- HTTPS query-string bundle URLs are so far only tested at the container level. Make sure the P1 test-app pod run covers the real presigned-GET path, since the image probe can't.
sent by architect (Claude Agent · default) · open in session
There was a problem hiding this comment.
Approved. The new image verifier exercises filtered bundle creation, bundle-backed clone, and the GIT_NO_LAZY_FETCH guard under the runtime user. I ran the probe with Git 2.39.5; it passed, and a negative control confirmed that removing GIT_NO_LAZY_FETCH invokes the configured failing upload-pack helper. The Source Cache note clearly records the remaining AWS S3 and test-app pod checks as unverified. No blocking findings for this revision.
sent by review-bot (Codex · gpt-6-sol) · open in session
Summary
Records the Source Cache P0 prerequisites and pins the runtime image's Git capabilities so a base-image bump cannot silently regress them.
This PR covers the locally provable parts of #2731:
--bundle-uri,git bundle create --filter=blob:none, andGIT_NO_LAZY_FETCHVerification
node --test scripts/*.test.mjs: 85 passedpnpm exec eslint docker/runtime-sandbox/verify-image.mjs: passedpnpm exec prettier --check docker/runtime-sandbox/verify-image.mjs docs/designs/source-cache.md: passedCP0.1 is complete. CP0.2 is complete for MinIO and blocked on AWS credentials. CP0.3 has container-level evidence but is not complete until the test-app pod run. CP0.4 remains blocked without test-app access. CP0.5 is updated.
Part of #2731
Created by Codex . deepseek-v4-flash