Skip to content

fix(review): include mutable prompt inputs in linked-issue satisfaction cache fingerprint - #4114

Merged
JSONbored merged 1 commit into
mainfrom
codex/fix-stale-linked-issue-cache-vulnerability
Jul 8, 2026
Merged

fix(review): include mutable prompt inputs in linked-issue satisfaction cache fingerprint#4114
JSONbored merged 1 commit into
mainfrom
codex/fix-stale-linked-issue-cache-vulnerability

Conversation

@JSONbored

Copy link
Copy Markdown
Owner

Motivation

  • The linked-issue satisfaction cache omitted mutable prompt inputs (issue title/body and PR title/body/diff), allowing an edited issue or PR to replay a stale "addressed" verdict and bypass a configured blocking gate.
  • The change ties the cache fingerprint to the exact model prompt so edits to issue/PR metadata force a fresh assessment and prevent stale verdict reuse.

Description

  • Bumped the cache input version to linked-issue-satisfaction-input:v2 and extended LinkedIssueSatisfactionCacheInput to include issueText, prTitle, prBody, and diff, and included those fields in the fingerprint computation (src/review/linked-issue-satisfaction-cache-input.ts).
  • Compute the unified review diff once in the processor and include the mutable prompt fields and diff when building the cache fingerprint, and pass the same diff into fresh model calls (src/queue/processors.ts).
  • Added regression tests verifying the fingerprint changes when prompt text edits occur and that same-head edits miss the cache and trigger a fresh assessment which restores the blocking linked_issue_scope_mismatch finding (test/unit/linked-issue-satisfaction-cache.test.ts, test/unit/linked-issue-satisfaction-run.test.ts).
  • Regenerated Cloudflare worker runtime types so the cf-typegen drift check is satisfied (worker-configuration.d.ts).

Testing

  • Ran targeted unit tests with npx vitest run test/unit/linked-issue-satisfaction-cache.test.ts test/unit/linked-issue-satisfaction-run.test.ts and the targeted suites passed.
  • Ran npm run typecheck and it completed without type errors.
  • Ran npm run cf-typegen to refresh runtime types and npm run cf-typegen:check passed after the refresh.
  • git diff --check passed; an attempted full npm run test:ci encountered an external npm audit lookup failure (HTTP 403) in this environment and the end-to-end coverage job was not completed here, but the focused regression tests for this fix passed locally.

Codex Task

@codecov

codecov Bot commented Jul 8, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 93.65%. Comparing base (1ec9f94) to head (4cf730b).
⚠️ Report is 1 commits behind head on main.
✅ All tests successful. No failed tests found.

Additional details and impacted files
@@           Coverage Diff           @@
##             main    #4114   +/-   ##
=======================================
  Coverage   93.65%   93.65%           
=======================================
  Files         384      384           
  Lines       35865    35871    +6     
  Branches    13160    13165    +5     
=======================================
+ Hits        33589    33595    +6     
  Misses       1618     1618           
  Partials      658      658           
Files with missing lines Coverage Δ
src/queue/processors.ts 95.15% <100.00%> (+<0.01%) ⬆️
...rc/review/linked-issue-satisfaction-cache-input.ts 100.00% <100.00%> (ø)
🚀 New features to boost your workflow:
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@superagent-security

Copy link
Copy Markdown
Contributor

Superagent didn't find any vulnerabilities or security issues in this PR.

@loopover-orb loopover-orb Bot added the gittensor:bug Gittensor-scored bug fix — scores a 0.05x multiplier. label Jul 8, 2026
@loopover-orb

loopover-orb Bot commented Jul 8, 2026

Copy link
Copy Markdown
Contributor

Warning

🟨🟨🟨🟨🟨🟨🟨🟨🟨🟨🟨🟨

⏸️ Gittensory review result - manual review recommended

Review updated: 2026-07-08 03:32:43 UTC

4 files · 2 blockers · readiness 93/100 · CI green · clean

⏸️ Suggested Action - Manual Review

  • No linked issue detected — If this PR is intended to solve an issue, link it explicitly in the PR body.
  • Maintainer requires a linked issue — Link the relevant issue (for example Closes #123) before opening the PR.

Concerns raised — review before merging

  • No linked issue detected — If this PR is intended to solve an issue, link it explicitly in the PR body.
  • Maintainer requires a linked issue — Link the relevant issue (for example Closes #123) before opening the PR.
Signal Result Evidence
Code review ❌ 2 blockers No AI review summary
Linked issue ⚠️ Missing No linked issue or no-issue rationale found.
Related work ✅ No active overlap found No same-issue or scoped active PR overlap found.
Change scope ✅ 20/20 Low review scope from cached public metadata (no linked issue context).
Validation posture ✅ 25/25 PR body includes validation/test evidence.
Contributor workload ✅ 10/10 Author activity: 51 registered-repo PR(s), 43 merged, 505 issue(s).
Contributor context ✅ Confirmed Gittensor contributor JSONbored; Gittensor profile; 51 PR(s), 505 issue(s).
Gate result ❌ Blocking Repo-configured hard blocker found.
Review context
  • Author: JSONbored
  • Role context: owner (maintainer lane)
  • Public audience mode: oss maintainer
  • Lane context: Repository is configured for direct PR review.
  • Public profile languages: Python, TypeScript, JavaScript, Ruby, Go, Kotlin, MDX, Shell
  • Official Gittensor activity: 51 PR(s), 505 issue(s).
  • PR-specific overlap: none found.
Contributor next steps
  • Treat this as maintainer-lane context rather than normal contributor-lane activity.
  • Explain no-issue PR.
  • Link the issue being solved, or explicitly explain why this is a no-issue PR.
Signal definitions
  • Related work = same linked issue, overlapping active PRs, or title/path similarity.
  • Change scope = cached public metadata such as size labels, draft state, and review-burden hints.
  • Validation posture = whether the PR provides enough public validation/test evidence for maintainer review.
  • Contributor workload = public contributor activity and cleanup pressure, not a repo-wide quality failure.
  • Contributor context = public GitHub/Gittensor identity context; non-Gittensor status is not a blocker.

🟩 Safe / merged · 🟦 Advisory · 🟨 Held for review · 🟥 Blocked / closed


💰 Earn for open-source contributions like this. Gittensor lets GitHub contributors earn for the work they already do — register to start earning →.

Checked by Gittensory, a quiet PR intelligence layer for OSS maintainers.

  • Re-run Gittensory review

@loopover-orb loopover-orb Bot added the manual-review Gittensor contributor context label Jul 8, 2026
@JSONbored
JSONbored force-pushed the codex/fix-stale-linked-issue-cache-vulnerability branch from 93eab13 to 4cf730b Compare July 8, 2026 02:52
@JSONbored
JSONbored merged commit 189f824 into main Jul 8, 2026
10 checks passed
@JSONbored
JSONbored deleted the codex/fix-stale-linked-issue-cache-vulnerability branch July 8, 2026 03:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

gittensor:bug Gittensor-scored bug fix — scores a 0.05x multiplier. manual-review Gittensor contributor context

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant