Skip to content

[architect] refactor: move manifest validator - #45

Open
hanthor-hive-agent[bot] wants to merge 4 commits into
mainfrom
arch/refactor-scoop-validator
Open

hanthor-hive-agent[bot] wants to merge 4 commits into
mainfrom
arch/refactor-scoop-validator

Conversation

@hanthor-hive-agent

Copy link
Copy Markdown
Contributor

Refactor

Moves the Scoop manifest contract implementation from tests/ to scripts/, updates its unit-test import and contributor-facing commands, and leaves a thin compatibility entry point for the existing CI workflow. This separates production validation policy from test code without changing validation behavior.

The compatibility entry point remains because the GitHub App installation cannot update workflow files; replacing the CI command with python3 scripts/validate_manifests.py can complete the migration once workflows permission is available.

Validation:

  • python3 tests/validate_manifests.py
  • python3 scripts/validate_manifests.py
  • python3 -m unittest discover -s tests -v (15 tests)
  • git diff --check

Refs #37


Filed by architect agent (ACMM L6 — full mode)

— hive: agent=architect backend=codex model=gpt-5.6-sol codex=0.146.0

Signed-off-by: hanthor-hive-agent[bot] <hive@users.noreply.github.com>
@hanthor-hive-agent

Copy link
Copy Markdown
Contributor Author

Important

Held for human sign-off on the direction, not on the code.

This PR's only tracked rationale is #37, which the hive filed itself — issue #37 was filed by hanthor-hive-agent[bot] and no human has acknowledged it. An agent-filed issue does not, on its own, establish that anyone agreed to the direction (hivecommons/hive#5117).

The change may well be right; nothing here is a review of it. To release the hold, acknowledge the direction on that issue — comment on it, assign yourself, or add the approved-direction label — and remove the hold label here.

@github-actions
github-actions Bot removed the request for review from hanthor September 8, 2026 18:51
@hanthor

hanthor commented Sep 18, 2026

Copy link
Copy Markdown
Member

Reviewed in a sweep of PRs open more than two days. Please rebase before this lands — as it stands it would silently revert a security fix.

The restructuring itself is right: the manifest validator is production tooling, not a test, and scripts/ is where it belongs. Leaving tests/validate_manifests.py as a thin runpy shim so CI keeps working until its workflow is updated is a good touch — much better than leaving two real copies to drift.

The problem is the content, not the layout. This branch predates #34, which I reviewed and merged earlier today. #33 added hash-algorithm validation to tests/validate_manifests.py: HASH_DIGEST_LENGTHS, _hash_error, and per-entry digest validation for the URL-list case, rejecting md5: and sha1: digests. Scoop picks its verification algorithm from the digest prefix, so a manifest pinned with md5: installs under an algorithm with practical collision attacks — that is what #33 closed.

HASH_DIGEST_LENGTHS is on main now. The scripts/validate_manifests.py this PR creates does not contain it — I grepped, zero matches for _hash_error, HASH_DIGEST_LENGTHS or sha512. So merging this would move the validator to its new home minus the hardening, and the shim would forward to the weaker copy. Nothing in CI would notice, because the tests would move with it.

Rebase onto main and carry #33's changes into scripts/validate_manifests.py, and this is good to go. Worth double-checking tests/test_validate_manifests.py picks up #33's cases too.

Apologies for the ordering — I merged #33 first, which is what created the gap.

architect added 3 commits September 30, 2026 05:10
Signed-off-by: architect <architect@hive.kubestellar.io>
Signed-off-by: architect <architect@hive.kubestellar.io>
Signed-off-by: architect <architect@hive.kubestellar.io>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants