Skip to content

O4: Add authenticated hosted OAFF candidate intake - #212

Merged
chenmingtang830 merged 6 commits into
mainfrom
codex/aff-hosted-intake
Sep 30, 2026
Merged

chenmingtang830 merged 6 commits into
mainfrom
codex/aff-hosted-intake

Conversation

@chenmingtang830

@chenmingtang830 chenmingtang830 commented Sep 30, 2026 •

Copy link
Copy Markdown
Owner

Summary

  • Accept exact AFF/OAFF v0.1 package bytes through authenticated hosted candidate intake; derive the destination workspace from the live principal.
  • Reuse the independent AFF CandidateInbox for verification, idempotency, immutable-revision conflict quarantine, monotonic receipt snapshots, lineage-safe freshness checks, and workspace-local paged inspection.
  • Store accepted and quarantined packages in the primary hosted SQLite database, so normal backup/restore includes them. Audit every accepted, idempotent, and quarantined intake under the authenticated principal and credential.
  • Bridge a selected candidate to a receiver-local claim.propose only after every foreign evidence descriptor maps to a valid existing retrieval receipt in that workspace with the same source digest.
  • Preserve origin ID, revision, and package digest as attribution. Origin approval carries no local authority; ordinary evaluation and local review decide governed reuse.
  • Refuse stale receipt snapshots, withdrawn/rejected origins, and links needing lifecycle/dependency reconciliation. A file lock serializes hosted imports and proposals across threads/processes sharing the same database, closing the freshness race.
  • Install the public AFF source at pinned commit 4d6e7ef9544bd0d2271816baa293820de9f8d587 in CI and the checked-in Render build.

Verification

  • Full Proofpress suite: 423 tests passed locally after the final changes. Ruff and git diff --check passed; the Render blueprint parses and contains the pinned dependency.
  • Synthetic tests cover two-workspace isolation, duplicate and tampered import, cross-workspace cursor denial, principal/credential audit, backup/restore retention, out-of-order withdrawal, concurrent import/proposal serialization, receiver-local evidence binding, and admission only after normal local review.
  • Final CI passed on Python 3.11, 3.13, and 3.14, plus static, UI, package, RelayBench, security, and preview checks.

Remaining product and release gates

  • Owner decision UI, a real independent producer/receiver trial, hosted deployment validation, and O5 reconciliation of later foreign events against previously admitted local claims remain open.
  • The foreign package is not authenticated by its digest alone. A later source withdrawal is not automatically a receiver-local withdrawal.
  • Normal ruleset review and required checks apply; green CI alone is not approval.

@vercel

vercel Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
proofpress Ready Ready Preview Sep 30, 2026 6:09am UTC

Request Review

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-30T06:17:06.138720Z 178f369 New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 3948e3e391

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/proofpress/hosted/control_plane.py Outdated
Comment thread src/proofpress/hosted/control_plane.py Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 3de902581a

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/proofpress/hosted/service.py Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 842b4979ce

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread pyproject.toml
Comment thread src/proofpress/hosted/control_plane.py

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: a72c0962c8

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +653 to +654
"next_cursor": candidates[-1]["digest"]
if len(candidates) == limit else None,

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Return a null cursor for a full final page

When the number of remaining candidates is exactly equal to the requested limit, this condition sets next_cursor even though no subsequent page exists. Clients following the documented contract and paging until the cursor is null will therefore issue an unnecessary request and receive an empty page; fetch limit + 1 records or otherwise determine whether another row exists before emitting the cursor.

Useful? React with 👍 / 👎.

@chenmingtang830
chenmingtang830 merged commit 9213e93 into main Sep 30, 2026
11 checks passed
@chenmingtang830
chenmingtang830 deleted the codex/aff-hosted-intake branch September 30, 2026 06:13

This branch was successfully deployed

1 active deployment
Preview — 178f3690 Deployed Sep 30, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant