Skip to content

PTD-23.1.4: Project binding records into Python provider inputs - #148

Merged
omry merged 1 commit into
pr149from
pr148
Sep 15, 2026
Merged

omry merged 1 commit into
pr149from
pr148

Conversation

@omry

@omry omry commented Sep 13, 2026

Copy link
Copy Markdown
Owner

Project validated portable Python binding contracts and artifacts into canonical application Python requests and deterministic exact-wheel constraints.

Preserve explicit interpreter requests, enforce application ownership and bounded wheel-tag policy, and cover deterministic projection and conflicts.


@omry
omry changed the base branch from main to pr147 September 13, 2026 11:29
@omry
omry added this pull request to stack #144 September 13, 2026 11:29
@omry

omry commented Sep 13, 2026

Copy link
Copy Markdown
Owner Author

PR-cycle state — maintained automatically. Do not edit by hand.

Mechanical PR-cycle state (JSON)
{
  "approval": {
    "candidate_revision_fingerprint": "sha256:42ad12d732cce18c9aad7d0519667e229152c7b0a169ee617922d55d1a5463a8",
    "evidence": {
      "attestations": [],
      "candidate_revision_fingerprint": "sha256:42ad12d732cce18c9aad7d0519667e229152c7b0a169ee617922d55d1a5463a8",
      "check_conclusions": [
        {
          "conclusion": "SUCCESS",
          "name": "Linux CI checks"
        },
        {
          "conclusion": "SUCCESS",
          "name": "Target smoke (darwin-amd64)"
        },
        {
          "conclusion": "SUCCESS",
          "name": "Target smoke (darwin-arm64)"
        },
        {
          "conclusion": "SUCCESS",
          "name": "Target smoke (linux-amd64)"
        },
        {
          "conclusion": "SUCCESS",
          "name": "Target smoke (linux-arm64)"
        },
        {
          "conclusion": "SUCCESS",
          "name": "Windows host smoke (windows-amd64)"
        },
        {
          "conclusion": "SUCCESS",
          "name": "Windows host smoke (windows-arm64)"
        }
      ],
      "delivery_deferral_ledger_digest": "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
      "finding_dispositions_digest": "sha256:84b9d3ad8bb9307e3d54879e5bcb266489bfbeba7072312f330ef0fb4103a151",
      "operation_identity": "sha256:e422f879631a854b5e7f547b61dc886eea0bc3ba5e57c9fac2a947edc4b32577",
      "review_request": {
        "body_digest": "sha256:9f5e0a50f27982c59bf819f3b0d7bf5f762220f6ab28f351a460a9e50ff2875c",
        "id": 5673797788
      },
      "review_result": {
        "body_digest": "sha256:2a9020e4863283d6dee81e7cc18b86d293bd77de68972143736d5a25364b0b42",
        "id": 5673839453
      }
    },
    "evidence_fingerprint": "sha256:68ed9656f67b75adf354867808617c6042e2e646fe05e6611ac11d698070201e",
    "head_sha": "7d8766a82271fc340ce1585a390f2b5444d26256",
    "operation_identity": "sha256:e422f879631a854b5e7f547b61dc886eea0bc3ba5e57c9fac2a947edc4b32577",
    "review_request_id": 5673797788,
    "review_result_id": 5673839453,
    "status": "approved-evidence-recorded"
  },
  "candidate_revision_fingerprint": "sha256:42ad12d732cce18c9aad7d0519667e229152c7b0a169ee617922d55d1a5463a8",
  "check_conclusions": [
    {
      "conclusion": "SUCCESS",
      "name": "Linux CI checks"
    },
    {
      "conclusion": "SUCCESS",
      "name": "Target smoke (darwin-amd64)"
    },
    {
      "conclusion": "SUCCESS",
      "name": "Target smoke (darwin-arm64)"
    },
    {
      "conclusion": "SUCCESS",
      "name": "Target smoke (linux-amd64)"
    },
    {
      "conclusion": "SUCCESS",
      "name": "Target smoke (linux-arm64)"
    },
    {
      "conclusion": "SUCCESS",
      "name": "Windows host smoke (windows-amd64)"
    },
    {
      "conclusion": "SUCCESS",
      "name": "Windows host smoke (windows-arm64)"
    }
  ],
  "check_observations": [
    {
      "checks": [],
      "head_sha": "82310e6df933d5e2abf928211da9061078555715",
      "id": "sha256:05910af5c2350ae2a283a0ca1b1c0beea658e82133a73477121b16c0868519b5",
      "required_checks": [],
      "status": "success"
    },
    {
      "checks": [
        {
          "conclusion": "SUCCESS",
          "name": "Linux CI checks",
          "run_id": 104183321064,
          "run_status": "completed",
          "status": "success",
          "url": "https://github.com/omry/reploy/actions/runs/34906202226/job/104183321064"
        },
        {
          "conclusion": "SUCCESS",
          "name": "Target smoke (darwin-amd64)",
          "run_id": 104183321373,
          "run_status": "completed",
          "status": "success",
          "url": "https://github.com/omry/reploy/actions/runs/34906202226/job/104183321373"
        },
        {
          "conclusion": "SUCCESS",
          "name": "Target smoke (darwin-arm64)",
          "run_id": 104183321309,
          "run_status": "completed",
          "status": "success",
          "url": "https://github.com/omry/reploy/actions/runs/34906202226/job/104183321309"
        },
        {
          "conclusion": "SUCCESS",
          "name": "Target smoke (linux-amd64)",
          "run_id": 104183321371,
          "run_status": "completed",
          "status": "success",
          "url": "https://github.com/omry/reploy/actions/runs/34906202226/job/104183321371"
        },
        {
          "conclusion": "SUCCESS",
          "name": "Target smoke (linux-arm64)",
          "run_id": 104183321424,
          "run_status": "completed",
          "status": "success",
          "url": "https://github.com/omry/reploy/actions/runs/34906202226/job/104183321424"
        },
        {
          "conclusion": "SUCCESS",
          "name": "Windows host smoke (windows-amd64)",
          "run_id": 104183321260,
          "run_status": "completed",
          "status": "success",
          "url": "https://github.com/omry/reploy/actions/runs/34906202226/job/104183321260"
        },
        {
          "conclusion": "SUCCESS",
          "name": "Windows host smoke (windows-arm64)",
          "run_id": 104183321241,
          "run_status": "completed",
          "status": "success",
          "url": "https://github.com/omry/reploy/actions/runs/34906202226/job/104183321241"
        }
      ],
      "head_sha": "cd3f5084e6fb3f32ada25098c7fcc61aec8c3eef",
      "id": "sha256:05fd68b2d614c2c3a2c39dbabcbd713929dc17e7b9ee2a485be642aac7deb4f5",
      "required_checks": [
        "Linux CI checks",
        "Target smoke (darwin-amd64)",
        "Target smoke (darwin-arm64)",
        "Target smoke (linux-amd64)",
        "Target smoke (linux-arm64)",
        "Windows host smoke (windows-amd64)",
        "Windows host smoke (windows-arm64)"
      ],
      "status": "success"
    },
    {
      "checks": [],
      "head_sha": "39b6568f0515b25e63e93fccc352ef1bd04a9011",
      "id": "sha256:0710384cbf997a2e5f32d4feba219cc2b312104550a1e67491de0597fb81fb75",
      "required_checks": [],
      "status": "success"
    },
    {
      "checks": [],
      "head_sha": "079f7f5ab3aad2a57f8d282acde2d747bf6ab555",
      "id": "sha256:10e145ff7078d9b8c1cab934acba1eff1ede0993bd9716949916a16e6efe2090",
      "required_checks": [],
      "status": "success"
    },
    {
      "checks": [
        {
          "conclusion": "SUCCESS",
          "name": "Linux CI checks",
          "run_id": 104223169480,
          "run_status": "completed",
          "status": "success",
          "url": "https://github.com/omry/reploy/actions/runs/34919159733/job/104223169480"
        },
        {
          "conclusion": "SUCCESS",
          "name": "Target smoke (darwin-amd64)",
          "run_id": 104223169475,
          "run_status": "completed",
          "status": "success",
          "url": "https://github.com/omry/reploy/actions/runs/34919159733/job/104223169475"
        },
        {
          "conclusion": "SUCCESS",
          "name": "Target smoke (darwin-arm64)",
          "run_id": 104223169467,
          "run_status": "completed",
          "status": "success",
          "url": "https://github.com/omry/reploy/actions/runs/34919159733/job/104223169467"
        },
        {
          "conclusion": "SUCCESS",
          "name": "Target smoke (linux-amd64)",
          "run_id": 104223169534,
          "run_status": "completed",
          "status": "success",
          "url": "https://github.com/omry/reploy/actions/runs/34919159733/job/104223169534"
        },
        {
          "conclusion": "SUCCESS",
          "name": "Target smoke (linux-arm64)",
          "run_id": 104223169532,
          "run_status": "completed",
          "status": "success",
          "url": "https://github.com/omry/reploy/actions/runs/34919159733/job/104223169532"
        },
        {
          "conclusion": "SUCCESS",
          "name": "Windows host smoke (windows-amd64)",
          "run_id": 104223169311,
          "run_status": "completed",
          "status": "success",
          "url": "https://github.com/omry/reploy/actions/runs/34919159733/job/104223169311"
        },
        {
          "conclusion": "SUCCESS",
          "name": "Windows host smoke (windows-arm64)",
          "run_id": 104223169528,
          "run_status": "completed",
          "status": "success",
          "url": "https://github.com/omry/reploy/actions/runs/34919159733/job/104223169528"
        }
      ],
      "head_sha": "b3ddcb13748e11880419ee196e94a89e6560abe0",
      "id": "sha256:11a8edf42ce9f9703698639941f84150f64861421f0b988485ab3bd2c73eaa5a",
      "required_checks": [
        "Linux CI checks",
        "Target smoke (darwin-amd64)",
        "Target smoke (darwin-arm64)",
        "Target smoke (linux-amd64)",
        "Target smoke (linux-arm64)",
        "Windows host smoke (windows-amd64)",
        "Windows host smoke (windows-arm64)"
      ],
      "status": "success"
    },
    {
      "checks": [
        {
          "conclusion": "SUCCESS",
          "name": "Linux CI checks",
          "run_id": 104205624230,
          "run_status": "completed",
          "status": "success",
          "url": "https://github.com/omry/reploy/actions/runs/34913385796/job/104205624230"
        },
        {
          "conclusion": "SUCCESS",
          "name": "Target smoke (darwin-amd64)",
          "run_id": 104205624404,
          "run_status": "completed",
          "status": "success",
          "url": "https://github.com/omry/reploy/actions/runs/34913385796/job/104205624404"
        },
        {
          "conclusion": "SUCCESS",
          "name": "Target smoke (darwin-arm64)",
          "run_id": 104205624397,
          "run_status": "completed",
          "status": "success",
          "url": "https://github.com/omry/reploy/actions/runs/34913385796/job/104205624397"
        },
        {
          "conclusion": "SUCCESS",
          "name": "Target smoke (linux-amd64)",
          "run_id": 104205624314,
          "run_status": "completed",
          "status": "success",
          "url": "https://github.com/omry/reploy/actions/runs/34913385796/job/104205624314"
        },
        {
          "conclusion": "SUCCESS",
          "name": "Target smoke (linux-arm64)",
          "run_id": 104205624477,
          "run_status": "completed",
          "status": "success",
          "url": "https://github.com/omry/reploy/actions/runs/34913385796/job/104205624477"
        },
        {
          "conclusion": "SUCCESS",
          "name": "Windows host smoke (windows-amd64)",
          "run_id": 104205624382,
          "run_status": "completed",
          "status": "success",
          "url": "https://github.com/omry/reploy/actions/runs/34913385796/job/104205624382"
        },
        {
          "conclusion": "SUCCESS",
          "name": "Windows host smoke (windows-arm64)",
          "run_id": 104205624486,
          "run_status": "completed",
          "status": "success",
          "url": "https://github.com/omry/reploy/actions/runs/34913385796/job/104205624486"
        }
      ],
      "head_sha": "c1fdf8afaffde2caccfdbf9a7417cc884ce815ef",
      "id": "sha256:342a21431ea012b5f0b70917dbed343e95434a2ea42d4f4f9d62994eff311705",
      "required_checks": [
        "Linux CI checks",
        "Target smoke (darwin-amd64)",
        "Target smoke (darwin-arm64)",
        "Target smoke (linux-amd64)",
        "Target smoke (linux-arm64)",
        "Windows host smoke (windows-amd64)",
        "Windows host smoke (windows-arm64)"
      ],
      "status": "success"
    },
    {
      "checks": [],
      "head_sha": "b63f33039f14c74d4a58a7c496ed1f68801aba99",
      "id": "sha256:63556596c5551ac7444ab903fb5d0a4d6172e157b5dea0898e9119cdd4672d66",
      "required_checks": [],
      "status": "success"
    },
    {
      "checks": [
        {
          "conclusion": "SUCCESS",
          "name": "Linux CI checks",
          "run_id": 104229358559,
          "run_status": "completed",
          "status": "success",
          "url": "https://github.com/omry/reploy/actions/runs/34921150773/job/104229358559"
        },
        {
          "conclusion": "SUCCESS",
          "name": "Target smoke (darwin-amd64)",
          "run_id": 104229358483,
          "run_status": "completed",
          "status": "success",
          "url": "https://github.com/omry/reploy/actions/runs/34921150773/job/104229358483"
        },
        {
          "conclusion": "SUCCESS",
          "name": "Target smoke (darwin-arm64)",
          "run_id": 104229358385,
          "run_status": "completed",
          "status": "success",
          "url": "https://github.com/omry/reploy/actions/runs/34921150773/job/104229358385"
        },
        {
          "conclusion": "SUCCESS",
          "name": "Target smoke (linux-amd64)",
          "run_id": 104229358637,
          "run_status": "completed",
          "status": "success",
          "url": "https://github.com/omry/reploy/actions/runs/34921150773/job/104229358637"
        },
        {
          "conclusion": "SUCCESS",
          "name": "Target smoke (linux-arm64)",
          "run_id": 104229358531,
          "run_status": "completed",
          "status": "success",
          "url": "https://github.com/omry/reploy/actions/runs/34921150773/job/104229358531"
        },
        {
          "conclusion": "SUCCESS",
          "name": "Windows host smoke (windows-amd64)",
          "run_id": 104229358595,
          "run_status": "completed",
          "status": "success",
          "url": "https://github.com/omry/reploy/actions/runs/34921150773/job/104229358595"
        },
        {
          "conclusion": "SUCCESS",
          "name": "Windows host smoke (windows-arm64)",
          "run_id": 104229358529,
          "run_status": "completed",
          "status": "success",
          "url": "https://github.com/omry/reploy/actions/runs/34921150773/job/104229358529"
        }
      ],
      "head_sha": "7d8766a82271fc340ce1585a390f2b5444d26256",
      "id": "sha256:637fa4a4f6872b9d909b9e7a8710f31f9408588ef9659ca904a140960cdf49ba",
      "required_checks": [
        "Linux CI checks",
        "Target smoke (darwin-amd64)",
        "Target smoke (darwin-arm64)",
        "Target smoke (linux-amd64)",
        "Target smoke (linux-arm64)",
        "Windows host smoke (windows-amd64)",
        "Windows host smoke (windows-arm64)"
      ],
      "status": "success"
    },
    {
      "checks": [],
      "head_sha": "91ca04dbea042dfd7d49d19be6d72484225c7394",
      "id": "sha256:6891420294b6c0456763fc8a7fb91dcdb9ab9f36ac41d41e315ff546bda37e91",
      "required_checks": [],
      "status": "success"
    },
    {
      "checks": [
        {
          "conclusion": "SUCCESS",
          "name": "Linux CI checks",
          "run_id": 104197573763,
          "run_status": "completed",
          "status": "success",
          "url": "https://github.com/omry/reploy/actions/runs/34910784726/job/104197573763"
        },
        {
          "conclusion": "SUCCESS",
          "name": "Target smoke (darwin-amd64)",
          "run_id": 104197573439,
          "run_status": "completed",
          "status": "success",
          "url": "https://github.com/omry/reploy/actions/runs/34910784726/job/104197573439"
        },
        {
          "conclusion": "SUCCESS",
          "name": "Target smoke (darwin-arm64)",
          "run_id": 104197573791,
          "run_status": "completed",
          "status": "success",
          "url": "https://github.com/omry/reploy/actions/runs/34910784726/job/104197573791"
        },
        {
          "conclusion": "SUCCESS",
          "name": "Target smoke (linux-amd64)",
          "run_id": 104197573680,
          "run_status": "completed",
          "status": "success",
          "url": "https://github.com/omry/reploy/actions/runs/34910784726/job/104197573680"
        },
        {
          "conclusion": "SUCCESS",
          "name": "Target smoke (linux-arm64)",
          "run_id": 104197573678,
          "run_status": "completed",
          "status": "success",
          "url": "https://github.com/omry/reploy/actions/runs/34910784726/job/104197573678"
        },
        {
          "conclusion": "SUCCESS",
          "name": "Windows host smoke (windows-amd64)",
          "run_id": 104197573656,
          "run_status": "completed",
          "status": "success",
          "url": "https://github.com/omry/reploy/actions/runs/34910784726/job/104197573656"
        },
        {
          "conclusion": "SUCCESS",
          "name": "Windows host smoke (windows-arm64)",
          "run_id": 104197573709,
          "run_status": "completed",
          "status": "success",
          "url": "https://github.com/omry/reploy/actions/runs/34910784726/job/104197573709"
        }
      ],
      "head_sha": "8b9b313edadbc105b4d32903fc09e69bce8745e1",
      "id": "sha256:6ab842557ded61a1e7f3867da7fa2ed93cc6cd647216a5766fc934e15b3267a8",
      "required_checks": [
        "Linux CI checks",
        "Target smoke (darwin-amd64)",
        "Target smoke (darwin-arm64)",
        "Target smoke (linux-amd64)",
        "Target smoke (linux-arm64)",
        "Windows host smoke (windows-amd64)",
        "Windows host smoke (windows-arm64)"
      ],
      "status": "success"
    },
    {
      "checks": [
        {
          "conclusion": "SUCCESS",
          "name": "Linux CI checks",
          "run_id": 104218698297,
          "run_status": "completed",
          "status": "success",
          "url": "https://github.com/omry/reploy/actions/runs/34917661264/job/104218698297"
        },
        {
          "conclusion": "SUCCESS",
          "name": "Target smoke (darwin-amd64)",
          "run_id": 104218698571,
          "run_status": "completed",
          "status": "success",
          "url": "https://github.com/omry/reploy/actions/runs/34917661264/job/104218698571"
        },
        {
          "conclusion": "SUCCESS",
          "name": "Target smoke (darwin-arm64)",
          "run_id": 104218698632,
          "run_status": "completed",
          "status": "success",
          "url": "https://github.com/omry/reploy/actions/runs/34917661264/job/104218698632"
        },
        {
          "conclusion": "SUCCESS",
          "name": "Target smoke (linux-amd64)",
          "run_id": 104218698638,
          "run_status": "completed",
          "status": "success",
          "url": "https://github.com/omry/reploy/actions/runs/34917661264/job/104218698638"
        },
        {
          "conclusion": "SUCCESS",
          "name": "Target smoke (linux-arm64)",
          "run_id": 104218698584,
          "run_status": "completed",
          "status": "success",
          "url": "https://github.com/omry/reploy/actions/runs/34917661264/job/104218698584"
        },
        {
          "conclusion": "SUCCESS",
          "name": "Windows host smoke (windows-amd64)",
          "run_id": 104218698628,
          "run_status": "completed",
          "status": "success",
          "url": "https://github.com/omry/reploy/actions/runs/34917661264/job/104218698628"
        },
        {
          "conclusion": "SUCCESS",
          "name": "Windows host smoke (windows-arm64)",
          "run_id": 104218698530,
          "run_status": "completed",
          "status": "success",
          "url": "https://github.com/omry/reploy/actions/runs/34917661264/job/104218698530"
        }
      ],
      "head_sha": "539143ce4c123bdb1167763488951d14ea585820",
      "id": "sha256:6c79f3d04a9e82e3d060c2610406ed53778eec66ecd336bc52fd3bc3f12e9d61",
      "required_checks": [
        "Linux CI checks",
        "Target smoke (darwin-amd64)",
        "Target smoke (darwin-arm64)",
        "Target smoke (linux-amd64)",
        "Target smoke (linux-arm64)",
        "Windows host smoke (windows-amd64)",
        "Windows host smoke (windows-arm64)"
      ],
      "status": "success"
    },
    {
      "checks": [
        {
          "conclusion": "SUCCESS",
          "name": "Linux CI checks",
          "run_id": 104212631961,
          "run_status": "completed",
          "status": "success",
          "url": "https://github.com/omry/reploy/actions/runs/34915671729/job/104212631961"
        },
        {
          "conclusion": "SUCCESS",
          "name": "Target smoke (darwin-amd64)",
          "run_id": 104212632220,
          "run_status": "completed",
          "status": "success",
          "url": "https://github.com/omry/reploy/actions/runs/34915671729/job/104212632220"
        },
        {
          "conclusion": "SUCCESS",
          "name": "Target smoke (darwin-arm64)",
          "run_id": 104212632156,
          "run_status": "completed",
          "status": "success",
          "url": "https://github.com/omry/reploy/actions/runs/34915671729/job/104212632156"
        },
        {
          "conclusion": "SUCCESS",
          "name": "Target smoke (linux-amd64)",
          "run_id": 104212632257,
          "run_status": "completed",
          "status": "success",
          "url": "https://github.com/omry/reploy/actions/runs/34915671729/job/104212632257"
        },
        {
          "conclusion": "SUCCESS",
          "name": "Target smoke (linux-arm64)",
          "run_id": 104212632204,
          "run_status": "completed",
          "status": "success",
          "url": "https://github.com/omry/reploy/actions/runs/34915671729/job/104212632204"
        },
        {
          "conclusion": "SUCCESS",
          "name": "Windows host smoke (windows-amd64)",
          "run_id": 104212632184,
          "run_status": "completed",
          "status": "success",
          "url": "https://github.com/omry/reploy/actions/runs/34915671729/job/104212632184"
        },
        {
          "conclusion": "SUCCESS",
          "name": "Windows host smoke (windows-arm64)",
          "run_id": 104212632280,
          "run_status": "completed",
          "status": "success",
          "url": "https://github.com/omry/reploy/actions/runs/34915671729/job/104212632280"
        }
      ],
      "head_sha": "2c7a30d0a4997d4367e52b7530d98dc8337c123e",
      "id": "sha256:86a559853664cbc8d8275057ab38881059810800f586e349240b4d7e0efec317",
      "required_checks": [
        "Linux CI checks",
        "Target smoke (darwin-amd64)",
        "Target smoke (darwin-arm64)",
        "Target smoke (linux-amd64)",
        "Target smoke (linux-arm64)",
        "Windows host smoke (windows-amd64)",
        "Windows host smoke (windows-arm64)"
      ],
      "status": "success"
    },
    {
      "checks": [],
      "head_sha": "f45ce095da4b5e2ef876a69f303c037829cc9c0e",
      "id": "sha256:93bc2ed28336de5cff339b09063810a5d13868bb08d71530845a1966c386e070",
      "required_checks": [],
      "status": "success"
    },
    {
      "checks": [],
      "head_sha": "990d5a42f420f67ec898d1fa573c0d2d5a75ee58",
      "id": "sha256:e5376abc81dd71999deb1ca49f5389200bcbe3361e2f9faaacef82244511e226",
      "required_checks": [],
      "status": "success"
    }
  ],
  "delivery_deferral_ledger_digest": "sha256:4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945",
  "delivery_deferrals": [],
  "findings": [
    {
      "discussion_url": "https://github.com/omry/reploy/pull/148#discussion_r4000820085",
      "disposition": "accepted",
      "id": "ptd2314-artifact-reference-platform-agreement",
      "invariant": "A projected exact artifact reference's canonical platform leaf must equal the canonical leaf derived from the exact wheel platform it identifies.",
      "line": 365,
      "path": "internal/providers/python/portable_tool_projection.go",
      "proposed_fix_paths": [
        "internal/portabletool/record_validate.go",
        "internal/portabletool/record_validate_test.go",
        "internal/providers/python/portable_tool_projection.go",
        "internal/providers/python/portable_tool_projection_test.go"
      ],
      "rationale": "Standalone projection validation currently validates the artifact reference namespace and wheel platform independently, allowing their target identities to disagree after decoding or mutation.",
      "severity": "P2",
      "status": "current-slice",
      "thread_id": "PRRT_kwDOTFQCkM6h71cR",
      "title": "Tie the artifact-reference leaf to the wheel platform"
    },
    {
      "discussion_url": "https://github.com/omry/reploy/pull/148#discussion_r4000381190",
      "disposition": "accepted",
      "id": "ptd2314-bundled-component-agreement",
      "invariant": "PTD-23.1.4 must reject a joined binding artifact that omits or contradicts bundled-component metadata declared by its exact contract before projection discards that metadata.",
      "line": 150,
      "path": "internal/providers/python/portable_tool_projection.go",
      "proposed_fix_paths": [
        "internal/portabletool/record_validate.go",
        "internal/portabletool/record_validate_test.go",
        "internal/providers/python/portable_tool_projection.go",
        "internal/providers/python/portable_tool_projection_test.go"
      ],
      "rationale": "Both selected records are individually strict, but the provider projection currently checks their binding, distribution, version, tag, and interpreter relationships without rechecking the existing cross-record bundled-component agreement. A directly constructed validated plan can therefore lose a detectable contradiction when the projection omits bundled metadata.",
      "severity": "P2",
      "status": "current-slice",
      "thread_id": "PRRT_kwDOTFQCkM6h6tot",
      "title": "Enforce bundled-component agreement before projection"
    },
    {
      "discussion_url": "https://github.com/omry/reploy/pull/148#discussion_r4000671785",
      "disposition": "accepted",
      "id": "ptd2314-canonical-cli-export-grammar",
      "invariant": "A canonical PTD-23.1.4 projection must preserve a binding contract CLI export that satisfies the shared canonical record identifier and normalized absolute non-root slash-path grammar.",
      "line": 367,
      "path": "internal/providers/python/portable_tool_projection.go",
      "proposed_fix_paths": [
        "internal/portabletool/record_validate.go",
        "internal/portabletool/record_validate_test.go",
        "internal/providers/python/portable_tool_projection.go",
        "internal/providers/python/portable_tool_projection_test.go"
      ],
      "rationale": "The strict binding contract validates CLI name and path completely, but the standalone canonical sidecar boundary currently checks only a nonempty name and path.IsAbs/path.Clean, allowing malformed names, root, backslashes, and control characters after direct construction or mutation.",
      "severity": "P2",
      "status": "current-slice",
      "thread_id": "PRRT_kwDOTFQCkM6h7dIh",
      "title": "Enforce the canonical CLI export grammar"
    },
    {
      "discussion_url": "https://github.com/omry/reploy/pull/148#discussion_r4000279987",
      "disposition": "accepted",
      "id": "ptd2314-canonical-exact-wheel-filename-consistency",
      "invariant": "PTD-23.1.4 carries filename, distribution, ecosystem version, and expanded tags as one exact-wheel constraint, so standalone canonical validation must prove those fields describe the same wheel through the shared filename projection.",
      "line": 364,
      "path": "internal/providers/python/portable_tool_projection.go",
      "proposed_fix_paths": [
        "internal/portabletool/record_validate.go",
        "internal/portabletool/record_validate_test.go",
        "internal/providers/python/portable_tool_projection.go",
        "internal/providers/python/portable_tool_projection_test.go"
      ],
      "rationale": "Selected artifact records already pass the shared strict filename validator, but the exported standalone canonical sidecar boundary only checks that Filename is a basename. It can therefore serialize contradictory exact-wheel identity fields after direct construction or mutation.",
      "severity": "P2",
      "status": "current-slice",
      "thread_id": "PRRT_kwDOTFQCkM6h6dFw",
      "title": "Validate exact wheel filename consistency at the canonical projection boundary"
    },
    {
      "discussion_url": "https://github.com/omry/reploy/pull/148#discussion_r4000381191",
      "disposition": "accepted",
      "id": "ptd2314-canonical-record-reference-categories",
      "invariant": "A canonical PTD-23.1.4 projection must carry valid tool-qualified record references whose IDs name the binding-contract and binding-artifact namespaces respectively.",
      "line": 333,
      "path": "internal/providers/python/portable_tool_projection.go",
      "proposed_fix_paths": [
        "internal/portabletool/record_validate.go",
        "internal/portabletool/record_validate_test.go",
        "internal/providers/python/portable_tool_projection.go",
        "internal/providers/python/portable_tool_projection_test.go"
      ],
      "rationale": "The standalone canonical sidecar boundary validates only nonempty IDs and digests, so directly constructed or decoded projections can serialize malformed IDs or swap the contract and artifact record categories even though the shared strict record grammar already defines both namespaces.",
      "severity": "P2",
      "status": "current-slice",
      "thread_id": "PRRT_kwDOTFQCkM6h6tou",
      "title": "Validate exact record-reference IDs and categories"
    },
    {
      "discussion_url": "https://github.com/omry/reploy/pull/148#discussion_r4000166338",
      "disposition": "accepted",
      "id": "ptd2314-canonical-requires-python-claim-coverage",
      "invariant": "A canonical PTD-23.1.4 Python binding projection must prove its exact target artifact Requires-Python covers every normalized SupportedPython claim using the PTD-23.1.2 provider-owned coverage helper.",
      "line": 359,
      "path": "internal/providers/python/portable_tool_projection.go",
      "proposed_fix_paths": [
        "internal/providers/python/portable_tool_projection.go",
        "internal/providers/python/portable_tool_projection_test.go"
      ],
      "rationale": "Catalog composition performs this cross-record proof, but the exported canonical projection boundary accepts caller-supplied data and rechecks the other joined invariants. Without repeating the established pure coverage check, it can canonically encode contradictory artifact and interpreter claims.",
      "severity": "P2",
      "status": "current-slice",
      "thread_id": "PRRT_kwDOTFQCkM6h6Kc9",
      "title": "Enforce Requires-Python claim coverage at the canonical projection boundary"
    },
    {
      "discussion_url": "https://github.com/omry/reploy/pull/148#discussion_r4000671787",
      "disposition": "accepted",
      "id": "ptd2314-canonical-requires-python-spelling",
      "invariant": "A canonical PTD-23.1.4 exact-wheel constraint must retain the strict artifact record's canonical PEP 440 Requires-Python spelling, not merely an equivalent parseable value.",
      "line": 367,
      "path": "internal/providers/python/portable_tool_projection.go",
      "proposed_fix_paths": [
        "internal/portabletool/record_validate.go",
        "internal/portabletool/record_validate_test.go",
        "internal/providers/python/portable_tool_projection.go",
        "internal/providers/python/portable_tool_projection_test.go"
      ],
      "rationale": "Coverage validation trims and parses the value, so standalone canonical projection serialization can currently preserve whitespace or another noncanonical spelling that the shared strict artifact envelope rejects.",
      "severity": "P2",
      "status": "current-slice",
      "thread_id": "PRRT_kwDOTFQCkM6h7dIj",
      "title": "Require canonical Requires-Python spelling"
    },
    {
      "discussion_url": "https://github.com/omry/reploy/pull/148#discussion_r3999529158",
      "disposition": "accepted",
      "id": "ptd2314-contract-artifact-version-consistency",
      "invariant": "An exact portable Python artifact's ecosystem version must satisfy the package-root requirement from its joined binding contract before projection emits provider inputs.",
      "line": 166,
      "path": "internal/providers/python/portable_tool_projection.go",
      "proposed_fix_paths": [
        "internal/providers/python/portable_tool_projection.go",
        "internal/providers/python/portable_tool_projection_test.go"
      ],
      "rationale": "The exported projection boundary accepts any validated portable-tool plan and already rechecks cross-record joins. Without this compatibility check it can emit a requirement pinned to one version and an exact-wheel constraint naming another. Reusing the repository's existing PEP 440 requirement machinery closes the contradiction without changing product direction.",
      "severity": "P2",
      "status": "current-slice",
      "thread_id": "PRRT_kwDOTFQCkM6h4gcn",
      "title": "Validate the wheel version against the contract root"
    },
    {
      "discussion_url": "https://github.com/omry/reploy/pull/148#discussion_r3999607089",
      "disposition": "accepted",
      "id": "ptd2314-eligible-wheel-tag-envelope",
      "invariant": "PTD-23.1.4 applies the static wheel-tag support envelope only to the contract-eligible SupportedTags and their TestedTags union while preserving every exact filename-derived Wheel.Tags entry as artifact metadata.",
      "line": 372,
      "path": "internal/providers/python/portable_tool_projection.go",
      "proposed_fix_paths": [
        "internal/providers/python/portable_tool_projection.go",
        "internal/providers/python/portable_tool_projection_test.go"
      ],
      "rationale": "The projection path already validates only the contract/artifact tag intersection, but canonical sidecar validation re-applies the support envelope to every exact artifact tag. That rejects valid compressed wheels containing an eligible tag plus additional metadata tags outside the initial runtime-testing envelope, contrary to the design's separation of exact artifact tags from bounded tested tags.",
      "severity": "P2",
      "status": "current-slice",
      "thread_id": "PRRT_kwDOTFQCkM6h4tl0",
      "title": "Validate only the eligible wheel-tag subset"
    },
    {
      "discussion_url": "https://github.com/omry/reploy/pull/148#discussion_r4000820082",
      "disposition": "accepted",
      "id": "ptd2314-portable-distribution-override-conflict",
      "invariant": "An existing Python provider override for a portable binding distribution must not cause resolution to reject or bypass the binding's selected exact wheel.",
      "line": 271,
      "path": "internal/providers/python/portable_tool_projection.go",
      "proposed_fix_paths": [
        "internal/providers/python/portable_tool_projection.go",
        "internal/providers/python/portable_tool_projection_test.go"
      ],
      "rationale": "The merge validates existing requirements but preserves matching version overrides unchecked, while the resolver later emits the override as an exact constraint that can contradict the selected wheel ecosystem version.",
      "severity": "P2",
      "status": "current-slice",
      "thread_id": "PRRT_kwDOTFQCkM6h71cP",
      "title": "Reject conflicting overrides for portable distributions"
    },
    {
      "discussion_url": "https://github.com/omry/reploy/pull/148#discussion_r4011035707",
      "disposition": "accepted",
      "id": "ptd2314-preserve-bare-vcs-url-semicolons",
      "invariant": "Bare VCS Python requirements with a valid egg identity must preserve semicolons belonging to the source URL rather than treating them as environment-marker delimiters.",
      "line": 817,
      "path": "internal/providers/python/portable_tool_projection.go",
      "proposed_fix_paths": [
        "internal/providers/python/portable_tool_projection.go",
        "internal/providers/python/portable_tool_projection_test.go"
      ],
      "rationale": "The URL-aware marker rule was applied only after detecting a named direct reference, leaving the bare VCS fallback to truncate at its first semicolon and discard the egg fragment used for distribution identity.",
      "severity": "P2",
      "status": "current-slice",
      "thread_id": "PRRT_kwDOTFQCkM6iVlT6",
      "title": "Preserve semicolons in bare VCS source URLs"
    },
    {
      "discussion_url": "https://github.com/omry/reploy/pull/148#discussion_r4010882046",
      "disposition": "accepted",
      "id": "ptd2314-preserve-direct-url-semicolons",
      "invariant": "PEP 508 environment-marker stripping must preserve semicolons that belong to a direct-reference URL so derivable wheel identity and version remain available for compatibility checks.",
      "line": 796,
      "path": "internal/providers/python/portable_tool_projection.go",
      "proposed_fix_paths": [
        "internal/providers/python/portable_tool_projection.go",
        "internal/providers/python/portable_tool_projection_test.go"
      ],
      "rationale": "The shared requirement-body helper truncates at the first semicolon regardless of context, so valid URL path parameters are mistaken for environment-marker delimiters and a compatible direct wheel becomes unverifiable.",
      "severity": "P2",
      "status": "current-slice",
      "thread_id": "PRRT_kwDOTFQCkM6iVNXT",
      "title": "Preserve semicolons inside direct-reference URLs"
    },
    {
      "discussion_url": "https://github.com/omry/reploy/pull/148#discussion_r4000166336",
      "disposition": "accepted",
      "id": "ptd2314-preserve-general-existing-requirements",
      "invariant": "PTD-23.1.4 preserves an existing Python contribution and its canonical package requests while merging portable binding roots; the portable binding root grammar must not narrow unrelated existing provider requirements.",
      "line": 505,
      "path": "internal/providers/python/portable_tool_projection.go",
      "proposed_fix_paths": [
        "internal/providers/python/portable_tool_projection.go",
        "internal/providers/python/portable_tool_projection_test.go"
      ],
      "rationale": "The merge groups every existing canonical provider requirement through the deliberately narrower portable binding root parser. Existing provider requests support extras, markers, and named direct URLs, so adding a portable binding can reject valid pre-existing input instead of preserving it.",
      "severity": "P1",
      "status": "current-slice",
      "thread_id": "PRRT_kwDOTFQCkM6h6Kc7",
      "title": "Preserve general existing requirements during portable binding merge"
    },
    {
      "discussion_url": "https://github.com/omry/reploy/pull/148#discussion_r4010537310",
      "disposition": "accepted",
      "id": "ptd2314-preserve-named-non-wheel-direct-references",
      "invariant": "An explicitly named non-wheel direct Python requirement must retain its declared distribution identity so an unrelated portable binding does not reject or discard it; source-version proof is required only when compatibility with a binding root must be established.",
      "line": 757,
      "path": "internal/providers/python/portable_tool_projection.go",
      "proposed_fix_paths": [
        "internal/providers/python/portable_tool_projection.go",
        "internal/providers/python/portable_tool_projection_test.go"
      ],
      "rationale": "The current named-direct-reference branch returns the filename-derived empty distribution for sdists and VCS URLs instead of the normalized explicitly declared package name, causing unrelated existing requirements to fail the unverifiable-source guard.",
      "severity": "P1",
      "status": "current-slice",
      "thread_id": "PRRT_kwDOTFQCkM6iUXsS",
      "title": "Preserve named non-wheel direct references"
    },
    {
      "discussion_url": "https://github.com/omry/reploy/pull/148#discussion_r4010736966",
      "disposition": "accepted",
      "id": "ptd2314-recognize-egg-named-vcs-requirements",
      "invariant": "A bare VCS Python requirement with a valid pip egg fragment must retain that declared distribution identity so an unrelated portable binding does not reject it as unverifiable.",
      "line": 638,
      "path": "internal/providers/python/portable_tool_projection.go",
      "proposed_fix_paths": [
        "internal/providers/python/portable_tool_projection.go",
        "internal/providers/python/portable_tool_projection_test.go"
      ],
      "rationale": "The source-location classifier returns no distribution for every non-wheel URL and ignores the pip egg fragment that names a bare VCS source, causing the existing unverifiable-source guard to reject an identifiable unrelated dependency.",
      "severity": "P2",
      "status": "current-slice",
      "thread_id": "PRRT_kwDOTFQCkM6iU2r1",
      "title": "Recognize egg-named VCS requirements before rejecting them"
    },
    {
      "discussion_url": "https://github.com/omry/reploy/pull/148#discussion_r4011162088",
      "disposition": "accepted",
      "id": "ptd2314-reject-disjoint-component-python-claims",
      "invariant": "All selected Python bindings projected into one application component must share at least one supported interpreter claim.",
      "line": 428,
      "path": "internal/providers/python/portable_tool_projection.go",
      "proposed_fix_paths": [
        "internal/providers/python/portable_tool_projection.go",
        "internal/providers/python/portable_tool_projection_test.go"
      ],
      "rationale": "The exported projection boundary validates each binding's supported-Python claims independently but does not prove their component-wide intersection, so a structurally valid direct caller can create a component no interpreter can satisfy.",
      "severity": "P2",
      "status": "current-slice",
      "thread_id": "PRRT_kwDOTFQCkM6iV4-z",
      "title": "Reject disjoint interpreter claims across component bindings"
    },
    {
      "discussion_url": "https://github.com/omry/reploy/pull/148#discussion_r4011272057",
      "disposition": "accepted",
      "id": "ptd2314-reject-mixed-component-platforms",
      "invariant": "All selected exact Python bindings projected into one application component must target the same platform.",
      "line": 395,
      "path": "internal/providers/python/portable_tool_projection.go",
      "proposed_fix_paths": [
        "internal/providers/python/portable_tool_projection.go",
        "internal/providers/python/portable_tool_projection_test.go"
      ],
      "rationale": "Canonical projection validation checks each exact wheel platform independently but does not establish a component-wide target, allowing a structurally valid direct caller to combine artifacts that no single deployment target can satisfy.",
      "severity": "P2",
      "status": "current-slice",
      "thread_id": "PRRT_kwDOTFQCkM6iWKiQ",
      "title": "Reject mixed target platforms within a component"
    }
  ],
  "pr": {
    "base_ref": "pr149",
    "base_sha": "dd10177e7a1b5f46ddd54e7b93b24cbaddef6d05",
    "body_digest": "sha256:2d5bbd6c5ca053c6e198af9dbeb66ffb225cc58fddce0e77cbf1f7e154bf22a7",
    "diff_digest": "sha256:16ad0ad1fc8a64b9feed9a4eb28c47ddf33578594b334e877f5d15482b31c271",
    "head_ref": "pr148",
    "head_sha": "7d8766a82271fc340ce1585a390f2b5444d26256",
    "pr": 148,
    "repository": "omry/reploy",
    "scope_authority": [
      {
        "digest": "sha256:bd02f5450b2940b3a960f6419994aa9c4e5e65ccb4dc5365b4d17ac233b49d9d",
        "path": "docs/PORTABLE_TOOL_DEFINITION_DESIGN.md"
      },
      {
        "digest": "sha256:570286ac642fd82e3177fb8ddb36dd15ee97395470726d69df086508be174a2e",
        "path": "docs/PORTABLE_TOOL_DEFINITION_IMPLEMENTATION_PLAN.md"
      }
    ],
    "title_digest": "sha256:7574a683df5b118de05c0b4af0b87841a7c6fa3b11583c7df2100234b9d2faea"
  },
  "record_version": 35,
  "review_observations": [],
  "review_requests": [
    {
      "base_established_at": "2026-09-13T11:29:27Z",
      "base_ref": "pr147",
      "base_sha": "ed41a7e6786e3089c76cd7c94ad921cdb7100d36",
      "body_digest": "sha256:5c1c0e323a239f519ccab47cc061260871f99758496af729f9cdd10d277f6fe2",
      "created_at": "2026-09-13T11:42:28Z",
      "head_sha": "91ca04dbea042dfd7d49d19be6d72484225c7394",
      "id": 5653041622,
      "kind": "regular-review"
    },
    {
      "base_established_at": "2026-09-13T11:29:27Z",
      "base_ref": "pr147",
      "base_sha": "ed41a7e6786e3089c76cd7c94ad921cdb7100d36",
      "body_digest": "sha256:b619e452a0dd6a60c3d91452609acb1e32b4d178e1cc1aa6a7be5107bd2950b0",
      "created_at": "2026-09-13T12:22:59Z",
      "head_sha": "82310e6df933d5e2abf928211da9061078555715",
      "id": 5653236986,
      "kind": "regular-review"
    },
    {
      "base_established_at": "2026-09-13T11:29:27Z",
      "base_ref": "pr147",
      "base_sha": "ed41a7e6786e3089c76cd7c94ad921cdb7100d36",
      "body_digest": "sha256:76a1140c006cc1efc86985b01ae5d44d42267c3008ab86de1896a71399bdc500",
      "created_at": "2026-09-13T16:32:33Z",
      "head_sha": "39b6568f0515b25e63e93fccc352ef1bd04a9011",
      "id": 5654554139,
      "kind": "regular-review"
    },
    {
      "base_established_at": "2026-09-13T11:29:27Z",
      "base_ref": "pr147",
      "base_sha": "ed41a7e6786e3089c76cd7c94ad921cdb7100d36",
      "body_digest": "sha256:55075c4bb0f98da8b85ec9eafa1d57abac00b195b7f70abdbf8b79b9ffa2a934",
      "created_at": "2026-09-13T17:11:23Z",
      "head_sha": "990d5a42f420f67ec898d1fa573c0d2d5a75ee58",
      "id": 5654768827,
      "kind": "regular-review"
    },
    {
      "base_established_at": "2026-09-13T11:29:27Z",
      "base_ref": "pr147",
      "base_sha": "ed41a7e6786e3089c76cd7c94ad921cdb7100d36",
      "body_digest": "sha256:ca4241d876ca8dc758cae3b924eeba519a7b8a462fb462496866c21baf7bd90a",
      "created_at": "2026-09-13T17:52:40Z",
      "head_sha": "b63f33039f14c74d4a58a7c496ed1f68801aba99",
      "id": 5655007423,
      "kind": "regular-review"
    },
    {
      "base_established_at": "2026-09-13T11:29:27Z",
      "base_ref": "pr147",
      "base_sha": "ed41a7e6786e3089c76cd7c94ad921cdb7100d36",
      "body_digest": "sha256:c7be577ea64d7b7a580b347851dd271e2bfb0ecd87c3a953ee2715e03d463c25",
      "created_at": "2026-09-13T19:42:15Z",
      "head_sha": "f45ce095da4b5e2ef876a69f303c037829cc9c0e",
      "id": 5655640539,
      "kind": "regular-review"
    },
    {
      "base_established_at": "2026-09-13T11:29:27Z",
      "base_ref": "pr147",
      "base_sha": "ed41a7e6786e3089c76cd7c94ad921cdb7100d36",
      "body_digest": "sha256:4e40785c70b99c86c9c6fd6afd82d6942c4525a78c579ee9274df78003e2331c",
      "created_at": "2026-09-13T20:36:33Z",
      "head_sha": "079f7f5ab3aad2a57f8d282acde2d747bf6ab555",
      "id": 5655962054,
      "kind": "regular-review"
    },
    {
      "base_established_at": "2026-09-14T19:57:10Z",
      "base_ref": "pr149",
      "base_sha": "dd10177e7a1b5f46ddd54e7b93b24cbaddef6d05",
      "body_digest": "sha256:9f97957cda9672f11617f68df1e71601799a28ec4d4258e96a90b95e515dc379",
      "created_at": "2026-09-14T23:31:20Z",
      "head_sha": "cd3f5084e6fb3f32ada25098c7fcc61aec8c3eef",
      "id": 5672265806,
      "kind": "regular-review"
    },
    {
      "base_established_at": "2026-09-14T19:57:10Z",
      "base_ref": "pr149",
      "base_sha": "dd10177e7a1b5f46ddd54e7b93b24cbaddef6d05",
      "body_digest": "sha256:911b0d1a9ee1247f51bbff0fd73442ac587938d96295b96b70803b42b3898573",
      "created_at": "2026-09-15T00:05:29Z",
      "head_sha": "8b9b313edadbc105b4d32903fc09e69bce8745e1",
      "id": 5672593145,
      "kind": "regular-review"
    },
    {
      "base_established_at": "2026-09-14T19:57:10Z",
      "base_ref": "pr149",
      "base_sha": "dd10177e7a1b5f46ddd54e7b93b24cbaddef6d05",
      "body_digest": "sha256:3b6c21254fc262e77c00dabe376baf69c542e3d53a669d30ef0011da0e87e142",
      "created_at": "2026-09-15T00:36:28Z",
      "head_sha": "c1fdf8afaffde2caccfdbf9a7417cc884ce815ef",
      "id": 5672872321,
      "kind": "regular-review"
    },
    {
      "base_established_at": "2026-09-14T19:57:10Z",
      "base_ref": "pr149",
      "base_sha": "dd10177e7a1b5f46ddd54e7b93b24cbaddef6d05",
      "body_digest": "sha256:acf62bc069ab342fbc7b2dd8714239d195c5cac31c3dc211bc970a7a3e382cfb",
      "created_at": "2026-09-15T01:10:36Z",
      "head_sha": "2c7a30d0a4997d4367e52b7530d98dc8337c123e",
      "id": 5673138499,
      "kind": "regular-review"
    },
    {
      "base_established_at": "2026-09-14T19:57:10Z",
      "base_ref": "pr149",
      "base_sha": "dd10177e7a1b5f46ddd54e7b93b24cbaddef6d05",
      "body_digest": "sha256:b518f429570d6a036eecf566adbf46d020892db56ab0aa2a3f2fd087b8ec5b6d",
      "created_at": "2026-09-15T01:38:33Z",
      "head_sha": "539143ce4c123bdb1167763488951d14ea585820",
      "id": 5673359052,
      "kind": "regular-review"
    },
    {
      "base_established_at": "2026-09-14T19:57:10Z",
      "base_ref": "pr149",
      "base_sha": "dd10177e7a1b5f46ddd54e7b93b24cbaddef6d05",
      "body_digest": "sha256:0917ab4ffa61db043c817aef60b4f0010979021b26a4844aabe8c4f9964d91a9",
      "created_at": "2026-09-15T02:01:12Z",
      "head_sha": "b3ddcb13748e11880419ee196e94a89e6560abe0",
      "id": 5673533355,
      "kind": "regular-review"
    },
    {
      "base_established_at": "2026-09-14T19:57:10Z",
      "base_ref": "pr149",
      "base_sha": "dd10177e7a1b5f46ddd54e7b93b24cbaddef6d05",
      "body_digest": "sha256:9f5e0a50f27982c59bf819f3b0d7bf5f762220f6ab28f351a460a9e50ff2875c",
      "created_at": "2026-09-15T02:33:17Z",
      "head_sha": "7d8766a82271fc340ce1585a390f2b5444d26256",
      "id": 5673797788,
      "kind": "regular-review"
    }
  ],
  "review_results": [
    {
      "base_ref": "pr147",
      "base_sha": "ed41a7e6786e3089c76cd7c94ad921cdb7100d36",
      "body_digest": "sha256:d23fafbda98698b033e2c4d06bab1c2a5457a5f03b01381599948d031e049c28",
      "commit_id": "91ca04dbea042dfd7d49d19be6d72484225c7394",
      "id": 5190589630,
      "inline_message_ids": [
        3999529158
      ],
      "request_comment_id": 5653041622,
      "result_kind": "findings",
      "status": "result",
      "submitted_at": "2026-09-13T11:47:40Z",
      "unresolved_thread_ids": [
        "PRRT_kwDOTFQCkM6h4gcn"
      ]
    },
    {
      "base_ref": "pr147",
      "base_sha": "ed41a7e6786e3089c76cd7c94ad921cdb7100d36",
      "body_digest": "sha256:c03f972f646559e50b0c21a68725af3f0f55e7550be8ec0400335b35396d8eae",
      "commit_id": "82310e6df933d5e2abf928211da9061078555715",
      "id": 5190664022,
      "inline_message_ids": [
        3999607089
      ],
      "request_comment_id": 5653236986,
      "result_kind": "findings",
      "status": "result",
      "submitted_at": "2026-09-13T12:26:43Z",
      "unresolved_thread_ids": [
        "PRRT_kwDOTFQCkM6h4qL_",
        "PRRT_kwDOTFQCkM6h4tl0"
      ]
    },
    {
      "base_ref": "pr147",
      "base_sha": "ed41a7e6786e3089c76cd7c94ad921cdb7100d36",
      "body_digest": "sha256:1e274cf22651af2e36754cd8f4e790df7d512ac658be329066b872d3481fc29d",
      "commit_id": "39b6568f0515b25e63e93fccc352ef1bd04a9011",
      "id": 5191366109,
      "inline_message_ids": [
        4000166336,
        4000166338
      ],
      "request_comment_id": 5654554139,
      "result_kind": "findings",
      "status": "result",
      "submitted_at": "2026-09-13T16:35:58Z",
      "unresolved_thread_ids": [
        "PRRT_kwDOTFQCkM6h6Kc7",
        "PRRT_kwDOTFQCkM6h6Kc9"
      ]
    },
    {
      "base_ref": "pr147",
      "base_sha": "ed41a7e6786e3089c76cd7c94ad921cdb7100d36",
      "body_digest": "sha256:a2e191d43fc57f856444a7092d1aaa88099415d26ccdb359885ec0f24700ec70",
      "commit_id": "990d5a42f420f67ec898d1fa573c0d2d5a75ee58",
      "id": 5191482022,
      "inline_message_ids": [
        4000279987
      ],
      "request_comment_id": 5654768827,
      "result_kind": "findings",
      "status": "result",
      "submitted_at": "2026-09-13T17:15:42Z",
      "unresolved_thread_ids": [
        "PRRT_kwDOTFQCkM6h6dFw"
      ]
    },
    {
      "base_ref": "pr147",
      "base_sha": "ed41a7e6786e3089c76cd7c94ad921cdb7100d36",
      "body_digest": "sha256:d30eeb7f1df63366ac080f8e31bd5ad06d24426e12be4917cef2cd4bbe6d6a89",
      "commit_id": "b63f33039f14c74d4a58a7c496ed1f68801aba99",
      "id": 5191655523,
      "inline_message_ids": [
        4000381190,
        4000381191
      ],
      "request_comment_id": 5655007423,
      "result_kind": "findings",
      "status": "result",
      "submitted_at": "2026-09-13T17:56:13Z",
      "unresolved_thread_ids": [
        "PRRT_kwDOTFQCkM6h6tot",
        "PRRT_kwDOTFQCkM6h6tou"
      ]
    },
    {
      "base_ref": "pr147",
      "base_sha": "ed41a7e6786e3089c76cd7c94ad921cdb7100d36",
      "body_digest": "sha256:fe4bbd922f6edd5d36c4ada1dac760e7418ac7a764f6b6d1af4cc6147671a5c2",
      "commit_id": "f45ce095da4b5e2ef876a69f303c037829cc9c0e",
      "id": 5192005176,
      "inline_message_ids": [
        4000671785,
        4000671787
      ],
      "request_comment_id": 5655640539,
      "result_kind": "findings",
      "status": "result",
      "submitted_at": "2026-09-13T19:44:55Z",
      "unresolved_thread_ids": [
        "PRRT_kwDOTFQCkM6h7dIh",
        "PRRT_kwDOTFQCkM6h7dIj"
      ]
    },
    {
      "base_ref": "pr147",
      "base_sha": "ed41a7e6786e3089c76cd7c94ad921cdb7100d36",
      "body_digest": "sha256:11a860fe400aed2e2a19e4dbb60f4eee750ce5ab938d0e97741e76d703fc138a",
      "commit_id": "079f7f5ab3aad2a57f8d282acde2d747bf6ab555",
      "id": 5192160468,
      "inline_message_ids": [
        4000820082,
        4000820085
      ],
      "request_comment_id": 5655962054,
      "result_kind": "findings",
      "status": "result",
      "submitted_at": "2026-09-13T20:40:29Z",
      "unresolved_thread_ids": [
        "PRRT_kwDOTFQCkM6h71cP",
        "PRRT_kwDOTFQCkM6h71cR"
      ]
    },
    {
      "base_ref": "pr149",
      "base_sha": "dd10177e7a1b5f46ddd54e7b93b24cbaddef6d05",
      "body_digest": "sha256:017e0137009cc2f69692bc6cc76be68638a8bf3229654c368371004821818493",
      "commit_id": "cd3f5084e6fb3f32ada25098c7fcc61aec8c3eef",
      "id": 5203945499,
      "inline_message_ids": [
        4010537310
      ],
      "request_comment_id": 5672265806,
      "result_kind": "findings",
      "status": "result",
      "submitted_at": "2026-09-14T23:34:57Z",
      "unresolved_thread_ids": [
        "PRRT_kwDOTFQCkM6h71cP",
        "PRRT_kwDOTFQCkM6h71cR",
        "PRRT_kwDOTFQCkM6iHdXX",
        "PRRT_kwDOTFQCkM6iUXsS"
      ]
    },
    {
      "base_ref": "pr149",
      "base_sha": "dd10177e7a1b5f46ddd54e7b93b24cbaddef6d05",
      "body_digest": "sha256:2c5adf76aafb29f47bd5de5d6f4c7195828752ab7ec479ae8bbcdf3ea18385e9",
      "commit_id": "8b9b313edadbc105b4d32903fc09e69bce8745e1",
      "id": 5204177385,
      "inline_message_ids": [
        4010736966
      ],
      "request_comment_id": 5672593145,
      "result_kind": "findings",
      "status": "result",
      "submitted_at": "2026-09-15T00:11:29Z",
      "unresolved_thread_ids": [
        "PRRT_kwDOTFQCkM6iU2r1"
      ]
    },
    {
      "base_ref": "pr149",
      "base_sha": "dd10177e7a1b5f46ddd54e7b93b24cbaddef6d05",
      "body_digest": "sha256:e699ec1f2a1a8c2870ed0e450da77819645d80c63bf23e3b9361aa9b27b006f3",
      "commit_id": "c1fdf8afaffde2caccfdbf9a7417cc884ce815ef",
      "id": 5204345116,
      "inline_message_ids": [
        4010882046
      ],
      "request_comment_id": 5672872321,
      "result_kind": "findings",
      "status": "result",
      "submitted_at": "2026-09-15T00:40:38Z",
      "unresolved_thread_ids": [
        "PRRT_kwDOTFQCkM6iVNXT"
      ]
    },
    {
      "base_ref": "pr149",
      "base_sha": "dd10177e7a1b5f46ddd54e7b93b24cbaddef6d05",
      "body_digest": "sha256:6c683af038d0fcbd713110fd59392fa7c2f78b9bb768e2b03e6e0446ffc7f23f",
      "commit_id": "2c7a30d0a4997d4367e52b7530d98dc8337c123e",
      "id": 5204514323,
      "inline_message_ids": [
        4011035707
      ],
      "request_comment_id": 5673138499,
      "result_kind": "findings",
      "status": "result",
      "submitted_at": "2026-09-15T01:14:42Z",
      "unresolved_thread_ids": [
        "PRRT_kwDOTFQCkM6iVlT6"
      ]
    },
    {
      "base_ref": "pr149",
      "base_sha": "dd10177e7a1b5f46ddd54e7b93b24cbaddef6d05",
      "body_digest": "sha256:8bf00d6015579b304dfcef50c4b12741a10c16b7e72c3a9bd42f1eee8584cbc8",
      "commit_id": "539143ce4c123bdb1167763488951d14ea585820",
      "id": 5204647536,
      "inline_message_ids": [
        4011162088
      ],
      "request_comment_id": 5673359052,
      "result_kind": "findings",
      "status": "result",
      "submitted_at": "2026-09-15T01:44:21Z",
      "unresolved_thread_ids": [
        "PRRT_kwDOTFQCkM6iV4-z"
      ]
    },
    {
      "base_ref": "pr149",
      "base_sha": "dd10177e7a1b5f46ddd54e7b93b24cbaddef6d05",
      "body_digest": "sha256:aadee6d46879902e1ce4545e302c5adf3dd70a720c3856c1adc41a9fd5c48782",
      "commit_id": "b3ddcb13748e11880419ee196e94a89e6560abe0",
      "id": 5204761130,
      "inline_message_ids": [
        4011272057
      ],
      "request_comment_id": 5673533355,
      "result_kind": "findings",
      "status": "result",
      "submitted_at": "2026-09-15T02:08:51Z",
      "unresolved_thread_ids": [
        "PRRT_kwDOTFQCkM6iWKiQ"
      ]
    },
    {
      "base_ref": "pr149",
      "base_sha": "dd10177e7a1b5f46ddd54e7b93b24cbaddef6d05",
      "body_digest": "sha256:2a9020e4863283d6dee81e7cc18b86d293bd77de68972143736d5a25364b0b42",
      "commit_id": "7d8766a82271fc340ce1585a390f2b5444d26256",
      "id": 5673839453,
      "inline_message_ids": [],
      "request_comment_id": 5673797788,
      "result_kind": "clean",
      "status": "result",
      "submitted_at": "2026-09-15T02:38:50Z",
      "unresolved_thread_ids": []
    }
  ],
  "revision_fingerprint": "sha256:42ad12d732cce18c9aad7d0519667e229152c7b0a169ee617922d55d1a5463a8",
  "rounds": [
    {
      "applied_fix_paths": [
        "internal/providers/python/portable_tool_projection.go",
        "internal/providers/python/portable_tool_projection_test.go"
      ],
      "disposition_changes": [
        "ptd2314-contract-artifact-version-consistency"
      ],
      "effective_diff_digest": "sha256:97f3962e474e701261be168b106948d89ebea3ef9fec42cee9ddcbe401b95206",
      "finding_ids": [
        "ptd2314-contract-artifact-version-consistency"
      ],
      "invariants": [
        "An exact portable Python artifact's ecosystem version must satisfy every matching package-root requirement from its joined binding contract before projection emits provider inputs."
      ],
      "outcome": "corrected",
      "proposed_fix_paths": [
        "internal/providers/python/portable_tool_projection.go",
        "internal/providers/python/portable_tool_projection_test.go"
      ],
      "resulting_head": "82310e6df933d5e2abf928211da9061078555715",
      "review_observation_id": null,
      "review_request_id": 5653041622,
      "review_result_id": 5190589630,
      "reviewed_head": "91ca04dbea042dfd7d49d19be6d72484225c7394",
      "root_cause": "The projection revalidated artifact identity and contract joins but did not revalidate the cross-record PEP 440 relationship between the artifact ecosystem version and the joined contract package-root requirements.",
      "round": 1,
      "unresolved_current_slice_findings": 0,
      "unresolved_design_blockers": 0
    },
    {
      "applied_fix_paths": [
        "internal/providers/python/portable_tool_projection.go",
        "internal/providers/python/portable_tool_projection_test.go"
      ],
      "disposition_changes": [
        "ptd2314-eligible-wheel-tag-envelope"
      ],
      "effective_diff_digest": "sha256:0f09a8bd15a7a69a8ad8dd1da67a309fb2214ca02ffefa54c66b8dc04cb1487d",
      "finding_ids": [
        "ptd2314-eligible-wheel-tag-envelope"
      ],
      "invariants": [
        "PTD-23.1.4 applies the static wheel-tag support envelope only to the contract-eligible SupportedTags and their TestedTags union while preserving every exact filename-derived Wheel.Tags entry as artifact metadata."
      ],
      "outcome": "corrected",
      "proposed_fix_paths": [
        "internal/providers/python/portable_tool_projection.go",
        "internal/providers/python/portable_tool_projection_test.go"
      ],
      "resulting_head": "39b6568f0515b25e63e93fccc352ef1bd04a9011",
      "review_observation_id": null,
      "review_request_id": 5653236986,
      "review_result_id": 5190664022,
      "reviewed_head": "82310e6df933d5e2abf928211da9061078555715",
      "root_cause": "Canonical sidecar validation repeated the static support-envelope check over the complete exact artifact tag list instead of limiting that policy check to the already-derived eligible SupportedTags subset.",
      "round": 2,
      "unresolved_current_slice_findings": 0,
      "unresolved_design_blockers": 0
    },
    {
      "applied_fix_paths": [
        "internal/providers/python/portable_tool_projection.go",
        "internal/providers/python/portable_tool_projection_test.go"
      ],
      "disposition_changes": [
        "ptd2314-canonical-requires-python-claim-coverage",
        "ptd2314-preserve-general-existing-requirements"
      ],
      "effective_diff_digest": "sha256:db7d44985f57c74edf80d475297244b883683b25e36d9f6100e44e52b7352bd2",
      "finding_ids": [
        "ptd2314-canonical-requires-python-claim-coverage",
        "ptd2314-preserve-general-existing-requirements"
      ],
      "invariants": [
        "A canonical PTD-23.1.4 Python binding projection must prove its exact target artifact Requires-Python covers every normalized SupportedPython claim using the PTD-23.1.2 provider-owned coverage helper.",
        "PTD-23.1.4 preserves an existing Python contribution and its canonical package requests while merging portable binding roots; the portable binding root grammar must not narrow unrelated existing provider requirements."
      ],
      "outcome": "corrected",
      "proposed_fix_paths": [
        "internal/providers/python/portable_tool_projection.go",
        "internal/providers/python/portable_tool_projection_test.go"
      ],
      "resulting_head": "990d5a42f420f67ec898d1fa573c0d2d5a75ee58",
      "review_observation_id": null,
      "review_request_id": 5654554139,
      "review_result_id": 5191366109,
      "reviewed_head": "39b6568f0515b25e63e93fccc352ef1bd04a9011",
      "root_cause": "The projection merge reused the narrower portable binding root parser for existing generic provider requirements, and canonical sidecar validation omitted the already-established Requires-Python coverage proof over its advertised interpreter claims.",
      "round": 3,
      "unresolved_current_slice_findings": 0,
      "unresolved_design_blockers": 0
    },
    {
      "applied_fix_paths": [
        "internal/portabletool/record_validate.go",
        "internal/portabletool/record_validate_test.go",
        "internal/providers/python/portable_tool_projection.go",
        "internal/providers/python/portable_tool_projection_test.go"
      ],
      "disposition_changes": [
        "ptd2314-canonical-exact-wheel-filename-consistency"
      ],
      "effective_diff_digest": "sha256:45e97cdd7747974587902abb4df171258d124667967c51616042c154e60b24d0",
      "finding_ids": [
        "ptd2314-canonical-exact-wheel-filename-consistency"
      ],
      "invariants": [
        "PTD-23.1.4 carries filename, distribution, ecosystem version, and expanded tags as one exact-wheel constraint, so standalone canonical validation must prove those fields describe the same wheel through the shared filename projection."
      ],
      "outcome": "corrected",
      "proposed_fix_paths": [
        "internal/portabletool/record_validate.go",
        "internal/portabletool/record_validate_test.go",
        "internal/providers/python/portable_tool_projection.go",
        "internal/providers/python/portable_tool_projection_test.go"
      ],
      "resulting_head": "b63f33039f14c74d4a58a7c496ed1f68801aba99",
      "review_observation_id": null,
      "review_request_id": 5654768827,
      "review_result_id": 5191482022,
      "reviewed_head": "990d5a42f420f67ec898d1fa573c0d2d5a75ee58",
      "root_cause": "Strict selected-record validation used the shared wheel-filename parser, but the exported standalone canonical sidecar boundary checked only basename shape and did not compare filename-derived identity and tags with the copied exact-wheel fields.",
      "round": 4,
      "unresolved_current_slice_findings": 0,
      "unresolved_design_blockers": 0
    },
    {
      "applied_fix_paths": [
        "internal/portabletool/record_validate.go",
        "internal/portabletool/record_validate_test.go",
        "internal/providers/python/portable_tool_projection.go",
        "internal/providers/python/portable_tool_projection_test.go",
        "internal/toolcatalog/records_compose.go"
      ],
      "disposition_changes": [
        "ptd2314-bundled-component-agreement",
        "ptd2314-canonical-record-reference-categories"
      ],
      "effective_diff_digest": "sha256:0168cc0e3bca13a55fd676043bb842d5fb724abdcfb925a97f6b262996d87c33",
      "finding_ids": [
        "ptd2314-bundled-component-agreement",
        "ptd2314-canonical-record-reference-categories"
      ],
      "invariants": [
        "PTD-23.1.4 must reject a joined binding artifact that omits or contradicts bundled-component metadata declared by its exact contract before projection discards that metadata.",
        "A canonical PTD-23.1.4 projection must carry valid tool-qualified record references whose IDs name the binding-contract and binding-artifact namespaces respectively."
      ],
      "outcome": "corrected",
      "proposed_fix_paths": [
        "internal/portabletool/record_validate.go",
        "internal/portabletool/record_validate_test.go",
        "internal/providers/python/portable_tool_projection.go",
        "internal/providers/python/portable_tool_projection_test.go",
        "internal/toolcatalog/records_compose.go"
      ],
      "resulting_head": "f45ce095da4b5e2ef876a69f303c037829cc9c0e",
      "review_observation_id": null,
      "review_request_id": 5655007423,
      "review_result_id": 5191655523,
      "reviewed_head": "b63f33039f14c74d4a58a7c496ed1f68801aba99",
      "root_cause": "The projection revalidated several exact contract/artifact relationships but omitted the existing bundled-component agreement check before dropping that metadata, while standalone canonical sidecar validation checked record-reference digests without applying the shared canonical ID and category grammar.",
      "round": 5,
      "unresolved_current_slice_findings": 0,
      "unresolved_design_blockers": 0
    },
    {
      "applied_fix_paths": [
        "internal/portabletool/record_validate.go",
        "internal/portabletool/record_validate_test.go",
        "internal/providers/python/portable_tool_projection.go",
        "internal/providers/python/portable_tool_projection_test.go"
      ],
      "disposition_changes": [
        "ptd2314-canonical-cli-export-grammar",
        "ptd2314-canonical-requires-python-spelling"
      ],
      "effective_diff_digest": "sha256:8a7dd5b0dfc958259b9bf1bf2262fc2150fd1880a43ef90ea39374f36066e76d",
      "finding_ids": [
        "ptd2314-canonical-cli-export-grammar",
        "ptd2314-canonical-requires-python-spelling"
      ],
      "invariants": [
        "A canonical PTD-23.1.4 projection must preserve a binding contract CLI export that satisfies the shared canonical record identifier and normalized absolute non-root slash-path grammar.",
        "A canonical PTD-23.1.4 exact-wheel constraint must retain the strict artifact record's canonical PEP 440 Requires-Python spelling, not merely an equivalent parseable value."
      ],
      "outcome": "corrected",
      "proposed_fix_paths": [
        "internal/portabletool/record_validate.go",
        "internal/portabletool/record_validate_test.go",
        "internal/providers/python/portable_tool_projection.go",
        "internal/providers/python/portable_tool_projection_test.go"
      ],
      "resulting_head": "079f7f5ab3aad2a57f8d282acde2d747bf6ab555",
      "review_observation_id": null,
      "review_request_id": 5655640539,
      "review_result_id": 5192005176,
      "reviewed_head": "f45ce095da4b5e2ef876a69f303c037829cc9c0e",
      "root_cause": "The standalone canonical projection boundary used partial structural checks instead of the shared strict record validators for CLI exports and Requires-Python spelling.",
      "round": 6,
      "unresolved_current_slice_findings": 0,
      "unresolved_design_blockers": 0
    },
    {
      "applied_fix_paths": [
        "internal/providers/python/portable_tool_projection.go",
        "internal/providers/python/portable_tool_projection_test.go"
      ],
      "disposition_changes": [
        "ptd2314-preserve-named-non-wheel-direct-references"
      ],
      "effective_diff_digest": "sha256:58827c8a00fc9417c08304de923cfdb37d1d0cdfaf36e35f4dc30e97164bdf9e",
      "finding_ids": [
        "ptd2314-preserve-named-non-wheel-direct-references"
      ],
      "invariants": [
        "An explicitly named non-wheel direct Python requirement must retain its declared distribution identity so an unrelated portable binding does not reject or discard it; source-version proof is required only when compatibility with a binding root must be established."
      ],
      "outcome": "corrected",
      "proposed_fix_paths": [
        "internal/providers/python/portable_tool_projection.go",
        "internal/providers/python/portable_tool_projection_test.go"
      ],
      "resulting_head": "8b9b313edadbc105b4d32903fc09e69bce8745e1",
      "review_observation_id": null,
      "review_request_id": 5672265806,
      "review_result_id": 5203945499,
      "reviewed_head": "cd3f5084e6fb3f32ada25098c7fcc61aec8c3eef",
      "root_cause": "The named-direct-reference branch relied exclusively on wheel-filename parsing for distribution identity and discarded the explicit PEP 508 package name when the source was an sdist or VCS URL.",
      "round": 7,
      "unresolved_current_slice_findings": 0,
      "unresolved_design_blockers": 0
    },
    {
      "applied_fix_paths": [
        "internal/providers/python/portable_tool_projection.go",
        "internal/providers/python/portable_tool_projection_test.go"
      ],
      "disposition_changes": [
        "ptd2314-recognize-egg-named-vcs-requirements"
      ],
      "effective_diff_digest": "sha256:277eae410e91c2297721a4094473d3cac975584e7657912838ac0abb52b24cb1",
      "finding_ids": [
        "ptd2314-recognize-egg-named-vcs-requirements"
      ],
      "invariants": [
        "A bare VCS Python requirement with a valid pip egg fragment must retain that declared distribution identity so an unrelated portable binding does not reject it as unverifiable."
      ],
      "outcome": "corrected",
      "proposed_fix_paths": [
        "internal/providers/python/portable_tool_projection.go",
        "internal/providers/python/portable_tool_projection_test.go"
      ],
      "resulting_head": "c1fdf8afaffde2caccfdbf9a7417cc884ce815ef",
      "review_observation_id": null,
      "review_request_id": 5672593145,
      "review_result_id": 5204177385,
      "reviewed_head": "8b9b313edadbc105b4d32903fc09e69bce8745e1",
      "root_cause": "The source-location classifier handled wheel filename identity but ignored the pip egg fragment used to name bare VCS requirements; the initial correction also needed strict whole-name validation to keep malformed fragments from becoming authority.",
      "round": 8,
      "unresolved_current_slice_findings": 0,
      "unresolved_design_blockers": 0
    },
    {
      "applied_fix_paths": [
        "internal/providers/python/portable_tool_projection.go",
        "internal/providers/python/portable_tool_projection_test.go"
      ],
      "disposition_changes": [
        "ptd2314-preserve-direct-url-semicolons"
      ],
      "effective_diff_digest": "sha256:96fe78c5ad8188ab9ed66c3eaf83f8a8346c1947ac3377196d411ab7ad25426d",
      "finding_ids": [
        "ptd2314-preserve-direct-url-semicolons"
      ],
      "invariants": [
        "Named PEP 508 direct references must preserve semicolons belonging to their source URL while removing only the whitespace-separated environment marker boundary."
      ],
      "outcome": "corrected",
      "proposed_fix_paths": [
        "internal/providers/python/portable_tool_projection.go",
        "internal/providers/python/portable_tool_projection_test.go"
      ],
      "resulting_head": "2c7a30d0a4997d4367e52b7530d98dc8337c123e",
      "review_observation_id": null,
      "review_request_id": 5672872321,
      "review_result_id": 5204345116,
      "reviewed_head": "c1fdf8afaffde2caccfdbf9a7417cc884ce815ef",
      "root_cause": "The shared requirement-body helper treated every semicolon as an environment-marker delimiter, including legal semicolons inside direct-reference URLs; once preserved, the existing query parser also incorrectly rejected legal fragment semicolons.",
      "round": 9,
      "unresolved_current_slice_findings": 0,
      "unresolved_design_blockers": 0
    },
    {
      "applied_fix_paths": [
        "internal/providers/python/portable_tool_projection.go",
        "internal/providers/python/portable_tool_projection_test.go"
      ],
      "disposition_changes": [
        "ptd2314-preserve-bare-vcs-url-semicolons"
      ],
      "effective_diff_digest": "sha256:0d58553b836b5cb32e47842aaaa741bb6abd587a76ab486273c9dae0569f50d8",
      "finding_ids": [
        "ptd2314-preserve-bare-vcs-url-semicolons"
      ],
      "invariants": [
        "Bare VCS Python requirements with a valid egg identity must preserve semicolons belonging to the source URL rather than treating them as environment-marker delimiters."
      ],
      "outcome": "corrected",
      "proposed_fix_paths": [
        "internal/providers/python/portable_tool_projection.go",
        "internal/providers/python/portable_tool_projection_test.go"
      ],
      "resulting_head": "539143ce4c123bdb1167763488951d14ea585820",
      "review_observation_id": null,
      "review_request_id": 5673138499,
      "review_result_id": 5204514323,
      "reviewed_head": "2c7a30d0a4997d4367e52b7530d98dc8337c123e",
      "root_cause": "The URL-aware marker rule was limited to named direct references, while the bare direct-URL fallback still truncated at the first semicolon; the initial correction also needed to constrain scheme detection to the pre-marker prefix to avoid misclassifying ordinary marker text.",
      "round": 10,
      "unresolved_current_slice_findings": 0,
      "unresolved_design_blockers": 0
    },
    {
      "applied_fix_paths": [
        "internal/providers/python/portable_tool_projection.go",
        "internal/providers/python/portable_tool_projection_test.go"
      ],
      "disposition_changes": [
        "ptd2314-reject-disjoint-component-python-claims"
      ],
      "effective_diff_digest": "sha256:0e496530c4be61ac468ea98f4bafd8e0e6ed0d670b4d5a58ed2e35b3d75c4520",
      "finding_ids": [
        "ptd2314-reject-disjoint-component-python-claims"
      ],
      "invariants": [
        "All selected Python bindings projected into one application component must share at least one supported interpreter claim."
      ],
      "outcome": "corrected",
      "proposed_fix_paths": [
        "internal/providers/python/portable_tool_projection.go",
        "internal/providers/python/portable_tool_projection_test.go"
      ],
      "resulting_head": "b3ddcb13748e11880419ee196e94a89e6560abe0",
      "review_observation_id": null,
      "review_request_id": 5673359052,
      "review_result_id": 5204647536,
      "reviewed_head": "539143ce4c123bdb1167763488951d14ea585820",
      "root_cause": "Projection canonicalization normalized and validated each binding's SupportedPython claims independently but did not intersect them across the application component, allowing a direct caller to serialize a component no interpreter could satisfy.",
      "round": 11,
      "unresolved_current_slice_findings": 0,
      "unresolved_design_blockers": 0
    },
    {
      "applied_fix_paths": [
        "internal/providers/python/portable_tool_projection.go",
        "internal/providers/python/portable_tool_projection_test.go"
      ],
      "disposition_changes": [
        "ptd2314-reject-mixed-component-platforms"
      ],
      "effective_diff_digest": "sha256:16ad0ad1fc8a64b9feed9a4eb28c47ddf33578594b334e877f5d15482b31c271",
      "finding_ids": [
        "ptd2314-reject-mixed-component-platforms"
      ],
      "invariants": [
        "All selected exact Python bindings projected into one application component must target the same platform."
      ],
      "outcome": "corrected",
      "proposed_fix_paths": [
        "internal/providers/python/portable_tool_projection.go",
        "internal/providers/python/portable_tool_projection_test.go"
      ],
      "resulting_head": "7d8766a82271fc340ce1585a390f2b5444d26256",
      "review_observation_id": null,
      "review_request_id": 5673533355,
      "review_result_id": 5204761130,
      "reviewed_head": "b3ddcb13748e11880419ee196e94a89e6560abe0",
      "root_cause": "Projection canonicalization validated each exact wheel platform and artifact-reference leaf independently but did not establish one component-wide target platform, allowing a direct caller to serialize bindings that no single deployment target could satisfy.",
      "round": 12,
      "unresolved_current_slice_findings": 0,
      "unresolved_design_blockers": 0
    },
    {
      "applied_fix_paths": [],
      "disposition_changes": [],
      "effective_diff_digest": "sha256:16ad0ad1fc8a64b9feed9a4eb28c47ddf33578594b334e877f5d15482b31c271",
      "finding_ids": [],
      "invariants": [
        "Portable Python binding records project into deterministic canonical component requests and an exact-artifact sidecar.",
        "All bindings in one application component share at least one supported interpreter claim and exactly one target platform.",
        "Existing Python requirements and overrides remain compatible with every projected exact wheel constraint."
      ],
      "outcome": "clean",
      "proposed_fix_paths": [],
      "resulting_head": "7d8766a82271fc340ce1585a390f2b5444d26256",
      "review_observation_id": null,
      "review_request_id": 5673797788,
      "review_result_id": 5673839453,
      "reviewed_head": "7d8766a82271fc340ce1585a390f2b5444d26256",
      "root_cause": null,
      "round": 13,
      "unresolved_current_slice_findings": 0,
      "unresolved_design_blockers": 0
    }
  ],
  "schema": "awd:swe:pr-cycle-state",
  "version": 2
}

@omry
omry marked this pull request as ready for review September 13, 2026 11:39
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 13, 2026

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review Completed 2026-09-15T02:38:51.966658Z 7d8766a Manual request
🔒 Security Review Completed 2026-09-13T11:42:24.776274Z 91ca04d Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@omry

omry commented Sep 13, 2026

Copy link
Copy Markdown
Owner Author

@codex, regular review 91ca04d

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 91ca04dbea

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread internal/providers/python/portable_tool_projection.go
Comment thread internal/providers/python/portable_tool_projection.go
@omry

omry commented Sep 13, 2026

Copy link
Copy Markdown
Owner Author

@codex, regular review 82310e6

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 82310e6df9

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread internal/providers/python/portable_tool_projection.go Outdated
@omry

omry commented Sep 13, 2026

Copy link
Copy Markdown
Owner Author

@codex, regular review 39b6568

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 39b6568f05

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread internal/providers/python/portable_tool_projection.go Outdated
Comment thread internal/providers/python/portable_tool_projection.go
@omry

omry commented Sep 13, 2026

Copy link
Copy Markdown
Owner Author

@codex, regular review 990d5a4

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 990d5a42f4

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread internal/providers/python/portable_tool_projection.go Outdated
@omry

omry commented Sep 13, 2026

Copy link
Copy Markdown
Owner Author

@codex, regular review b63f330

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: b63f33039f

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread internal/providers/python/portable_tool_projection.go
Comment thread internal/providers/python/portable_tool_projection.go Outdated
@omry

omry commented Sep 13, 2026

Copy link
Copy Markdown
Owner Author

@codex, regular review f45ce09

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: f45ce095da

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread internal/providers/python/portable_tool_projection.go Outdated
Comment thread internal/providers/python/portable_tool_projection.go Outdated
@omry

omry commented Sep 13, 2026

Copy link
Copy Markdown
Owner Author

@codex, regular review 079f7f5

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 079f7f5ab3

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread internal/providers/python/portable_tool_projection.go
Comment thread internal/providers/python/portable_tool_projection.go
@omry

omry commented Sep 14, 2026

Copy link
Copy Markdown
Owner Author

@codex, regular review cd3f508

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: cd3f5084e6

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread internal/providers/python/portable_tool_projection.go Outdated
@omry

omry commented Sep 15, 2026

Copy link
Copy Markdown
Owner Author

@codex, regular review 8b9b313

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 8b9b313eda

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread internal/providers/python/portable_tool_projection.go
@omry

omry commented Sep 15, 2026

Copy link
Copy Markdown
Owner Author

@codex, regular review c1fdf8a

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: c1fdf8afaf

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread internal/providers/python/portable_tool_projection.go Outdated
@omry

omry commented Sep 15, 2026

Copy link
Copy Markdown
Owner Author

@codex, regular review 2c7a30d

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 2c7a30d0a4

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread internal/providers/python/portable_tool_projection.go
@omry

omry commented Sep 15, 2026

Copy link
Copy Markdown
Owner Author

@codex, regular review 539143c

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 539143ce4c

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread internal/providers/python/portable_tool_projection.go
@omry

omry commented Sep 15, 2026

Copy link
Copy Markdown
Owner Author

@codex, regular review b3ddcb1

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: b3ddcb1374

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread internal/providers/python/portable_tool_projection.go
Project validated portable Python binding contracts and artifacts into canonical application Python requests and deterministic exact-wheel constraints.

Preserve explicit interpreter requests, enforce application ownership and bounded wheel-tag policy, and cover deterministic projection and conflicts.
@gitar-bot

gitar-bot Bot commented Sep 15, 2026

Copy link
Copy Markdown
Code Review ✅ Approved 2 resolved / 2 findings

Projects validated portable Python binding contracts into canonical application Python requests with deterministic exact-wheel constraints, preserving explicit interpreter requests and enforcing application ownership. The new version check aligns with existing requirementAllowsVersion semantics, and self-contradictory requirement handling is now consistent. No issues found.

✅ 2 resolved
Quality: New version check diverges from existing requirementAllowsVersion semantics

📄 internal/providers/python/portable_tool_projection.go:552-566
validatePortableToolArtifactVersionAgainstRequirementsV1 reimplements requirement-vs-version satisfaction with pep440.NewSpecifiers(...).Check(version), while the same package already has requirementAllowsVersion (version.go) which deliberately defers complex PEP 440 forms to the resolver and, per its comment, treats them as "the Python resolver's authority." The new path instead makes a hard local rejection and, because pep440.Specifiers.Check excludes pre-releases by default, could reject an exact selected wheel (e.g. a 2.0.0rc1 artifact against a >=1 pin) that the established helper would not. Consider reusing requirementAllowsVersion (or its release-constraint helpers) so version acceptance stays consistent across the provider.

Edge Case: Single self-contradictory requirement now passes compatibility check

📄 internal/portabletool/python.go:104 📄 internal/providers/python/portable_tool_projection.go:437 📄 internal/providers/python/portable_tool_projection.go:665
PythonPackageRootRequirementsCompatibleV1 was changed to short-circuit with return true, nil whenever there is at most one unique requirement (python.go:104), before the interval/satisfiability model runs. A single but internally unsatisfiable specifier such as "demo>=2,<1" passes PythonPackageRootDistributionNameV1 (valid PEP 440 syntax) and is now reported as compatible=true, whereas the previous interval model would have detected the empty intersection and returned false. Callers that can supply a single requirement (portable_tool_projection.go:437 and :665) will therefore admit a contradictory constraint that would otherwise be rejected. Consider only short-circuiting when the single requirement has no version constraint, or run the single requirement through the satisfiability/pep440 check before returning true.

Review coverage

Rules No rules evaluated

Functional validation Not enabled · Set up

Options

Auto-apply is off → Gitar will not commit updates to this branch.
Display: compact → Counting what did not apply, without listing it.

Comment with these commands to change the behavior for this request:

Auto-apply Compact
gitar auto-apply:on         
gitar display:verbose         

Was this helpful? React with 👍 / 👎 | Powered by Gitar — free for open source

@omry

omry commented Sep 15, 2026

Copy link
Copy Markdown
Owner Author

@codex, regular review 7d8766a

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Breezy!

Reviewed commit: 7d8766a822

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@omry omry added the approved PR reviewed and approved label Sep 15, 2026
@omry
omry merged commit a5a9dde into main Sep 15, 2026
8 checks passed
@omry
omry deleted the pr148 branch September 15, 2026 16:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved PR reviewed and approved

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant