-
Notifications
You must be signed in to change notification settings - Fork 0
Keep native fuzz-engine locks out of generic coverage dependency images #762
Copy link
Copy link
Open
Labels
area: ci-cdCI, GitHub Actions, checks, release, or supply chainCI, GitHub Actions, checks, release, or supply chainarea: dependenciesDependency or lockfile maintenanceDependency or lockfile maintenancearea: securitySecurity boundary, hardening, or vulnerability preventionSecurity boundary, hardening, or vulnerability preventionautomationmaintenancepriority: mediumNormal-priority or P2 workNormal-priority or P2 workstatus: blockedBlocked by conflict, dependency, or required prerequisiteBlocked by conflict, dependency, or required prerequisitetestingtype: maintenanceMaintenance, build, dependency, or operational upkeepMaintenance, build, dependency, or operational upkeep
Description
Activity
Metadata
Metadata
Assignees
Labels
area: ci-cdCI, GitHub Actions, checks, release, or supply chainCI, GitHub Actions, checks, release, or supply chainarea: dependenciesDependency or lockfile maintenanceDependency or lockfile maintenancearea: securitySecurity boundary, hardening, or vulnerability preventionSecurity boundary, hardening, or vulnerability preventionautomationmaintenancepriority: mediumNormal-priority or P2 workNormal-priority or P2 workstatus: blockedBlocked by conflict, dependency, or required prerequisiteBlocked by conflict, dependency, or required prerequisitetestingtype: maintenanceMaintenance, build, dependency, or operational upkeepMaintenance, build, dependency, or operational upkeep
Outcome
Central OpenCode coverage evidence installs only dependencies needed to import and measure selected production/test code. Native coverage-guided fuzz-engine locks remain in repository fuzz workflows and are not materialized into the generic Python coverage image.
Problem
The trusted-base Python lock materializer currently selects every hash-pinned
requirements*.txtcandidate. Incontextual-orchestrator, this includesfuzz/requirements-atheris.txt. The generic coverage image runs a newer CPython and attempts to install a platform/interpreter-specific libFuzzer binding even though no fuzz target is executed, converting an irrelevant toolchain mismatch into aCHANGES_REQUESTEDreview and blocking the dependency repair that would make later fuzz installations portable.Scope
requirements-atheris.txtfrom generic coverage dependency materialization regardless of directory depth;requirements-property.txtwhen they are hash-pinned;CHANGELOG.md;Acceptance
ContextualWisdomLab/contextual-orchestrator#96can obtain coverage evidence from its existing protected base without installing Atheris;Refs ContextualWisdomLab/contextual-orchestrator#76 and #96.