Skip to content

Diagnostics rc9: process cleanup, reliable reports and Bash 3.2 audit - #14

Open
pioner22 wants to merge 2 commits into
mainfrom
codex/diagnostics-rc9-comprehensive-audit
Open

pioner22 wants to merge 2 commits into
mainfrom
codex/diagnostics-rc9-comprehensive-audit

Conversation

@pioner22

Copy link
Copy Markdown
Owner

Problem

The rc8 audit reproduced probe descendants surviving deadlines/cancellation, accepted probe output after a log-write error, final PASS after an incomplete report, a stale profile after option 15 followed by EOF, and a readonly.sh syntax failure in early GNU Bash 3.2.

Changes

  • Bound ordinary probe descendants in their own process group; preserve deadline/signal results and reject unfinished work or failed logging.
  • Check report input/output failures explicitly, retaining known FAIL evidence and withholding an incomplete final report.
  • Save accepted profile restrictions before reading the next menu choice.
  • Keep the disk-ID regex in a variable compatible with early Bash 3.2, retaining the existing restriction.
  • Add 21 regressions and run them in the existing macOS compatibility workflow without hardware stress.
  • Pin the rc9 descriptor and all 18 wrappers to immutable payload/bootstrap a5f95d4; manifest bd9a30dcf4213977366f2bb0c1468acdd97296519155a578b9b82a68c60b9037. Bootstrap 1.4 and registry 2026-09-20.1 are unchanged.

Evidence

  • New coherent local full run: 330 tests in 108.278s, OK, no skips (309 existing + 21 new).
  • 21 new tests on actual GNU Bash 3.2.0/Linux: OK; 29 shell syntax checks: OK.
  • 15 existing native tests with GCC UBSan: OK; small allocations/files only.
  • 22 immutable payload files downloaded again and verified; offline toolkit selftest exit 0.
  • st.sh ShellCheck warning gate passes. Runtime-wide findings remain 35 SC2034 and 5 SC2209.

See docs/diagnostics/RC9_QA.md for reproductions, exact scope and the menu coverage matrix. Counts from repeated or alternate-shell runs are not added together. Raw logs are retained privately, not included here.

Remaining limits

No real Mac/Recovery, Apple clang, Metal or 40–48 GiB workload validation is claimed. Verified native Recovery binaries are still absent. The diagnostic-fixtures-v1 release returns 404; the fallback remains limited/INCONCLUSIVE. Previous Actions runs did not reach a runner; this PR's CI state must be read independently.

This PR is an audited candidate. The stable main/st.sh command continues to select rc8 until this PR is merged. Mandatory mlock, RAM coverage, volume/consent checks, one-selection/report/exit behavior and RAW quarantine remain in place. VPN/macdiag_core/Yagodka are untouched.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-21T06:32:56.535318Z da6627a PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant