Rodin rodin
  • Joined on 2026-04-23
rodin commented on pull request rodin/review-bot#152 2026-05-15 23:22:09 +00:00
fix(#150): add EvalSymlinks to validateDocmapPath — close dir-symlink bypass

Fix Plan against d6bab7a9cf6ce3d084d8f40a91a51c1a8fc084e7:

Addressing bot-review findings from the current HEAD round (sonnet/4810, security/4812, gpt/4813):

rodin commented on pull request rodin/review-bot#152 2026-05-15 23:18:01 +00:00
fix(#150): add EvalSymlinks to validateDocmapPath — close dir-symlink bypass

Self-Review: PR #152

Self-review against d6bab7a9cf6ce3d084d8f40a91a51c1a8fc084e7

Phase 1: Independent Findings

rodin commented on pull request rodin/review-bot#152 2026-05-15 23:11:36 +00:00
fix(#150): add EvalSymlinks to validateDocmapPath — close dir-symlink bypass

Fix Plan against d6bab7a9cf6ce3d084d8f40a91a51c1a8fc084e7

Addressing self-review findings from 345f9a5 (all 3 findings resolved):

rodin pushed to issue-150 at rodin/review-bot 2026-05-15 23:11:21 +00:00
d6bab7a9cf fix(#150): close residual TOCTOU with LimitedReader at docmap open
4359518e50 nit(#150): report original --docmap flag value in parse error, not resolved path
6e11107c77 nit(#150): fix misleading 'this is unreachable' in Lstat comment
Compare 3 commits »
rodin commented on pull request rodin/review-bot#158 2026-05-15 22:50:08 +00:00
fix(#157): add never-close constraint to spec, S9 invariant, and regression test

Self-review against ec6fdbff4290a7fbf9fc7277aebabc4e7d5dc02d

Assessment: Clean

Verification at ec6fdbff

Finding #1 (Sonnet NIT) — §9 prose run-on: Fixed. Commit splits the final §9…

rodin commented on pull request rodin/review-bot#158 2026-05-15 22:43:42 +00:00
fix(#157): add never-close constraint to spec, S9 invariant, and regression test

Fix Plan against ec6fdbff4290a7fbf9fc7277aebabc4e7d5dc02d:

  • Sonnet #1 (NIT): paragraph break in §9
  • GPT #1 (MINOR): clarify §8 S8/S10 wording
rodin commented on pull request rodin/review-bot#158 2026-05-15 22:43:41 +00:00
fix(#157): add never-close constraint to spec, S9 invariant, and regression test

Fix Plan against ec6fdbff4290a7fbf9fc7277aebabc4e7d5dc02d:

Acknowledging Finding #1 (sonnet, NIT) and Finding #1 (gpt, MINOR). Will adjust §8 wording (S8/S10 clarity) and add a paragraph break…

rodin pushed to issue-157 at rodin/review-bot 2026-05-15 22:40:58 +00:00
ec6fdbff42 fix(#158): address bot feedback — correct S8/S10 description, fix §9 prose break
rodin commented on pull request rodin/review-bot#158 2026-05-15 22:39:44 +00:00
fix(#157): add never-close constraint to spec, S9 invariant, and regression test

Fix Plan against f883f39dbf8b90ac8a4f5c7470d9cc4bd32eaf7e:

Findings Review at Current HEAD

All three bots APPROVED at f883f39d. No REQUEST_CHANGES. Findings at this HEAD:

rodin commented on pull request rodin/review-bot#152 2026-05-15 22:37:33 +00:00
fix(#150): add EvalSymlinks to validateDocmapPath — close dir-symlink bypass

Self-Review: PR #152

Self-review against 345f9a5aac059e05378d3f0a48c6e2a9258ce249

Phase 1: Independent Findings

rodin commented on pull request rodin/review-bot#158 2026-05-15 20:37:37 +00:00
fix(#157): add never-close constraint to spec, S9 invariant, and regression test

Self-review against f883f39dbf8b90ac8a4f5c7470d9cc4bd32eaf7e

Self-Review: PR #158

Phase 1: Independent Findings

rodin pushed to issue-157 at rodin/review-bot 2026-05-15 18:06:54 +00:00
f883f39dbf fix(#158): address NIT feedback — clarify enforcement split, clean §9 prose
rodin pushed to issue-150 at rodin/review-bot 2026-05-15 18:06:17 +00:00
345f9a5aac test(#150): add positive test for in-repo symlink allowed by EvalSymlinks fix
0fedefad3f fix(#150): return resolved path from validateDocmapPath to close TOCTOU gap
20e9899835 docs(#150): fix stale comments in validateDocmapPath — reflect new in-repo-symlink semantic
d3b9027da3 Merge pull request 'feat(#141): validate-docmap subcommand' (#156) from issue-141 into main
bacb25e029 nit(#141): fix stale-docs error message phrasing
Compare 44 commits »
rodin commented on pull request rodin/review-bot#158 2026-05-15 18:06:12 +00:00
fix(#157): add never-close constraint to spec, S9 invariant, and regression test

Fix Plan against fb7d8d5e3bb47385cae9b17e9d5ba0313fbd1eb4:

Findings Review at Current HEAD

All three bots APPROVED at fb7d8d5e. No REQUEST_CHANGES. Only NITs remain.

rodin commented on pull request rodin/review-bot#158 2026-05-15 18:04:18 +00:00
fix(#157): add never-close constraint to spec, S9 invariant, and regression test

Self-Review: PR #158

Self-review against fb7d8d5e3bb47385cae9b17e9d5ba0313fbd1eb4

Phase 1: Independent Findings

rodin pushed to issue-157 at rodin/review-bot 2026-05-15 17:26:19 +00:00
fb7d8d5e3b fix(#158): add S10 invariant to spec, fix enforcement wording in §8
rodin commented on pull request rodin/review-bot#158 2026-05-15 17:22:41 +00:00
fix(#157): add never-close constraint to spec, S9 invariant, and regression test

Fix Plan against 6cefbb070e3a730d61ceb37858605d27e75e8a81:

Findings Review

All three bots approved this PR. No REQUEST_CHANGES. Findings are MINOR and NIT from Sonnet and GPT.

rodin commented on pull request rodin/review-bot#156 2026-05-15 17:20:17 +00:00
feat(#141): validate-docmap subcommand

Self-Review: PR #156

Self-review against bacb25e029cd8e3601e21fe108ed868d29fef5f6

Phase 1: Independent Findings

Reviewed three changes to cmd/review-bot/validatedocmap.go and two new…

rodin commented on pull request rodin/review-bot#156 2026-05-15 17:20:16 +00:00
feat(#141): validate-docmap subcommand

Self-Review: PR #156

Self-review against bacb25e029cd8e3601e21fe108ed868d29fef5f6

Phase 1: Independent Findings

Reviewed the diff fresh, as a stranger.

Changes in scope: 1.…