Repository navigation
Prepare and verify private checkpoint proof handoffs locally - #60
Conversation
Entire-Checkpoint: 3d456e13c593
Entire-Checkpoint: 8f654bbc72b2
Entire-Checkpoint: d87799de037e
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: f78ae58bcb
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
| const { repository, git, github, remote } = dependencies; | ||
| assertScopeOptions(options, repository); | ||
| const canonical = github(`repos/${repository.fullName}`); | ||
| if (`github.com/${canonical.full_name}` !== repositoryId) throw new Error('Canonical repository mismatch.'); |
There was a problem hiding this comment.
Canonicalize repository ID casing before creating a proof
When the origin URL or --repo-id differs from GitHub's canonical full_name only by case, preparation is blocked even though the preceding repository check accepts that same repository case-insensitively. For example, a valid lowercase clone of a repository whose GitHub canonical name contains capitals reaches this comparison and fails with Canonical repository mismatch; normalize the ID used for the scope/envelope to the API's canonical name (or compare normalized identities) so valid clones can produce hosted-loader-compatible proofs.
Useful? React with 👍 / 👎.
Manual private-proof assembly makes it easy to mix candidates, bases, metadata and transport chunks. This adds local
tabellio-checkpoint-proof prepare/checkcommands that reuse the genuine native exporter, resolve PR/squash ranges, audit the serialized pack, create bounded private chunks, and verify a separately retained scope digest before an approved handoff.The command performs only local writes and GitHub/Git read operations. It rejects stale targets, source/Git output destinations (including subdirectories and symlinks), expired or altered scope, extra packed blobs, context-bearing fields and text hidden in native counters. It supports schema-checked Entire0.7.7 numeric attribution and transcript-offset metadata without exporting prompt/transcript blobs.
Hosted sharing, protected review, actual validators, merge and cleanup remain separate. No private proof was uploaded for this PR. The proposed two-phase capsule is documented only and requires separate security/sharing approval; it is not implemented.
Validation on exact head
f78ae58bcbd84d5f338bcbfb459fce8202cf7112: