Skip to content

fix: resolve remaining PR #50 post-rename conflict markers - #181

Closed
lusoris wants to merge 4 commits into
masterfrom
fix/pr50-residual-conflict-markers
Closed

lusoris wants to merge 4 commits into
masterfrom
fix/pr50-residual-conflict-markers

Conversation

@lusoris

@lusoris lusoris commented May 29, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Removes all committed git conflict markers left over from commit 24bb5daf89 (post-merge-train sweep) across 38 files
  • HEAD (core/ path) side taken in every conflict; the libvmaf/ side from 24bb5daf89 discarded
  • Files covered: .github/codeql-config.yml, .semgrepignore, ai/src/aiutils/jsonl_utils.py, ai/src/vmaf_train/registry.py, core/AGENTS.md, core/test/test_hip_smoke.c, and 32 docs/ files

Reproducer

git grep -nE '^(<{7}|={7}|>{7})( |$)' -- ':(exclude)docs/research/' ':(exclude)docs/adr/_index_fragments/' ':(exclude)*.lock' ':(exclude)CHANGELOG.md' || echo 'clean'

Expected after merge: clean

Checklist

  • Research digest — no digest needed: trivial marker cleanup, no design decision
  • Decision matrix — no alternatives: only-one-way fix (take HEAD / core/ side)
  • AGENTS.md invariant note — no rebase-sensitive invariants
  • Reproducer / smoke-test command — see command above
  • Changelog fragment — changelog.d/fixed/pr50-residual-conflicts.md
  • docs/rebase-notes.md — no rebase impact: conflict marker cleanup
  • docs/state.md — no bug opened/closed (cosmetic cleanup)
  • ffmpeg-patches/ — no C-API or public-header changes

🤖 Generated with Claude Code

@lusoris
lusoris enabled auto-merge (squash) May 29, 2026 10:26
@lusoris
lusoris disabled auto-merge May 29, 2026 11:43
@lusoris
lusoris marked this pull request as draft May 29, 2026 11:43
@lusoris
lusoris force-pushed the fix/pr50-residual-conflict-markers branch from f2109f7 to 46f5e26 Compare May 29, 2026 12:12
Expands PR #181 to cover the docs/research/ and docs/adr/_index_fragments/
files left behind by the 40-file initial sweep. All conflicts originate
from 24bb5da trying to revert the ADR-0700 path rename
(libvmaf/ -> core/, python/vmaf/ -> compat/python-vmaf/) and the VMAFx
rebrand; HEAD side kept verbatim per the resolution policy because the
canonical tree already carries the renamed paths and VMAFx branding.

Net change is purely the removal of <<<<<<< / ======= / >>>>>>> envelopes
plus the discarded incoming-side lines (258 deletions, 0 insertions); no
file content was edited beyond marker resolution.
@lusoris
lusoris marked this pull request as ready for review May 29, 2026 13:11
lusoris added 2 commits May 29, 2026 15:49
… fix

Two follow-up fixes after the PR #181 CI run:

1. docs/state.md (CLAUDE.md §12 r13 / ADR-0165): Add a "Recently closed"
   row for T-CASCADING-CONFLICT-MARKERS-PR50-RESIDUAL-2026-05-29.
   Commit 24bb5da left committed git conflict markers across 38 files
   (PR #174 covered the CI YAML subset; PR #181 sweeps the remainder).
   The state.md touch gate flagged the omission.

2. .gitleaks.toml: gitleaks 8.24.3 evaluates allowlist `paths` regex
   against the scanned file's *absolute* path (e.g. `/repo/ai/...`)
   when --source is an absolute directory. Patterns anchored with `^`
   only matched files directly at the source root (so `^go\.sum$`
   worked, but `^ai/src/.../README\.md$` and `^subprojects/` never
   matched anything). The README's `- key: src01_hrc00_576x324`
   example tripped the generic-api-key entropy rule despite being
   explicitly allowlisted. Rewrote subdirectory patterns to drop the
   leading `^` (and prefix with `/` where root-anchoring is desired);
   `^go\.sum$`-style root-anchored single-file patterns kept as-is
   via `/go\.sum$`. Local verification with the pinned CI gitleaks
   v8.24.3 image: 0 leaks (was 2: one allowlisted-but-not-skipped
   README finding plus a separate `vmaf-fixtures` regex-allowlisted
   pair). Bytes scanned drops 162 MB -> 39 MB because subprojects/,
   build/, builddir*/, .git/, gen/go/ are now actually skipped.

Also fixes the PR body item name to match the deliverables-check
parser exactly ("Reproducer / smoke-test command" not
"Reproducer / smoke-test"); body edited via gh pr edit, not in
this commit.
Follow-up to c70dfd7. The previous commit unblocked the in-tree
README + workflow YAML allowlist failures, but gitleaks scans the
full git history when `fetch-depth: 0` is set, and 2 historical
findings remained from commit `c35b50e4de` (Netflix upstream,
2016-01-30): random YUV pixel bytes in `resource/yuv/src01_hrc00_
576x324.yuv:1` and `resource/yuv/src01_hrc01_576x324.yuv:1` trip
the `generic-api-key` and `sourcegraph-access-token` entropy
gates respectively.

Today those fixtures live at `python/test/resource/yuv/...` —
already allowlisted — but the pre-2016-rename path `resource/yuv/`
was not. Added the historical path so the full-history scan stops
flagging upstream Netflix commits.

Local reproduce on a fresh full-history clone with the pinned CI
gitleaks v8.24.3 image: 3619 commits scanned, 0 leaks found
(was 2 leaks).
@lusoris

lusoris commented May 29, 2026

Copy link
Copy Markdown
Contributor Author

Superseded — my admin merges of #236 (codeql) + #221 (hip_smoke) have rendered this not-mergeable. Replacing with a fresh branch that takes HEAD side of remaining 70 marker files.

@lusoris lusoris closed this May 29, 2026
lusoris added a commit that referenced this pull request Jun 3, 2026
Two Open rows in docs/state.md cited PRs that were CLOSED-not-merged
and flagged as follow-up by the PR #291 closing agent. Verified
against master tip bbcaa8d and master state of the underlying
issues:

1. T-CUDA-FILTER1D-RES-DISPATCH-CONFLICT-2026-05-29 — migrated from
   Open to Recently closed (superseded). The conflict markers only
   existed on the unmerged scaffold branch tip 35a1fb6. PR #91
   (merged 2026-05-29T09:37:48Z) landed ADR-0753 resolution-aware
   dispatch via the adm_cm_device() consumer without extending
   dispatch into filter1d_8(), so master never carried the
   build-failing scaffold variant. PR #214 (the planned
   conflict-marker cleanup) was CLOSED-not-merged 2026-05-30 when
   its base scaffold branch was abandoned. core/src/feature/cuda/
   integer_vif_cuda.c::filter1d_8() on master uses the clean
   unconditional cuLaunchKernel paths.

2. T-CPP23-READ-JSON-MODEL-PENDING-2026-05-29 — kept Open but the
   dead PR #215 citation removed. The C++23 Wave 8 conversion of
   core/src/read_json_model.c is still pending on master (still a
   .c source per core/src/meson.build:1578); PR #215 was
   CLOSED-not-merged 2026-05-30. Owner field rewritten to
   "Owner-driven; pending fresh PR per ADR-0846 Wave 8".

Scope-coordinated with DRAFT PR #291 (docs/state-md-drift-sync —
already migrates the 3 Vulkan rows + T-LEGACY-RUNNER-ANSNR-BROKEN
+ T-LEGACY-RUNNER-STUB-MISSING). Row 203
(T-LEGACY-RUNNER-STUB-MISSING-2026-05-29) cites closed PRs #213
and #181 as OPEN but is left untouched here since PR #291 already
rewrites it.

Net Open count -1; total T-row count unchanged (153).
No code changes — documentation cleanup only.

Deliverables (ADR-0108):
- no digest needed: state.md hygiene
- no alternatives: only-one-way reconciliation
- no rebase-sensitive invariants
- Reproducer: `gh pr view 214 -R VMAFx/vmafx --json state,mergedAt`
  returns `{"state":"CLOSED","mergedAt":null}`;
  `grep -nE '^(<{7}|={7}|>{7})( |$)' core/src/feature/cuda/integer_vif_cuda.c`
  on master returns empty; `ls core/src/read_json_model.*` returns
  only `.c` and `.h`.
- Changelog: changelog.d/changed/state-md-closed-pr-row-sweep.md
- no rebase impact: docs only

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
lusoris added a commit that referenced this pull request Jun 3, 2026
Two Open rows in docs/state.md cited PRs that were CLOSED-not-merged
and flagged as follow-up by the PR #291 closing agent. Verified
against master tip bbcaa8d and master state of the underlying
issues:

1. T-CUDA-FILTER1D-RES-DISPATCH-CONFLICT-2026-05-29 — migrated from
   Open to Recently closed (superseded). The conflict markers only
   existed on the unmerged scaffold branch tip 35a1fb6. PR #91
   (merged 2026-05-29T09:37:48Z) landed ADR-0753 resolution-aware
   dispatch via the adm_cm_device() consumer without extending
   dispatch into filter1d_8(), so master never carried the
   build-failing scaffold variant. PR #214 (the planned
   conflict-marker cleanup) was CLOSED-not-merged 2026-05-30 when
   its base scaffold branch was abandoned. core/src/feature/cuda/
   integer_vif_cuda.c::filter1d_8() on master uses the clean
   unconditional cuLaunchKernel paths.

2. T-CPP23-READ-JSON-MODEL-PENDING-2026-05-29 — kept Open but the
   dead PR #215 citation removed. The C++23 Wave 8 conversion of
   core/src/read_json_model.c is still pending on master (still a
   .c source per core/src/meson.build:1578); PR #215 was
   CLOSED-not-merged 2026-05-30. Owner field rewritten to
   "Owner-driven; pending fresh PR per ADR-0846 Wave 8".

Scope-coordinated with DRAFT PR #291 (docs/state-md-drift-sync —
already migrates the 3 Vulkan rows + T-LEGACY-RUNNER-ANSNR-BROKEN
+ T-LEGACY-RUNNER-STUB-MISSING). Row 203
(T-LEGACY-RUNNER-STUB-MISSING-2026-05-29) cites closed PRs #213
and #181 as OPEN but is left untouched here since PR #291 already
rewrites it.

Net Open count -1; total T-row count unchanged (153).
No code changes — documentation cleanup only.

Deliverables (ADR-0108):
- no digest needed: state.md hygiene
- no alternatives: only-one-way reconciliation
- no rebase-sensitive invariants
- Reproducer: `gh pr view 214 -R VMAFx/vmafx --json state,mergedAt`
  returns `{"state":"CLOSED","mergedAt":null}`;
  `grep -nE '^(<{7}|={7}|>{7})( |$)' core/src/feature/cuda/integer_vif_cuda.c`
  on master returns empty; `ls core/src/read_json_model.*` returns
  only `.c` and `.h`.
- Changelog: changelog.d/changed/state-md-closed-pr-row-sweep.md
- no rebase impact: docs only

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
lusoris added a commit that referenced this pull request Jun 3, 2026
Two Open rows in docs/state.md cited PRs that were CLOSED-not-merged
and flagged as follow-up by the PR #291 closing agent. Verified
against master tip bbcaa8d and master state of the underlying
issues:

1. T-CUDA-FILTER1D-RES-DISPATCH-CONFLICT-2026-05-29 — migrated from
   Open to Recently closed (superseded). The conflict markers only
   existed on the unmerged scaffold branch tip 35a1fb6. PR #91
   (merged 2026-05-29T09:37:48Z) landed ADR-0753 resolution-aware
   dispatch via the adm_cm_device() consumer without extending
   dispatch into filter1d_8(), so master never carried the
   build-failing scaffold variant. PR #214 (the planned
   conflict-marker cleanup) was CLOSED-not-merged 2026-05-30 when
   its base scaffold branch was abandoned. core/src/feature/cuda/
   integer_vif_cuda.c::filter1d_8() on master uses the clean
   unconditional cuLaunchKernel paths.

2. T-CPP23-READ-JSON-MODEL-PENDING-2026-05-29 — kept Open but the
   dead PR #215 citation removed. The C++23 Wave 8 conversion of
   core/src/read_json_model.c is still pending on master (still a
   .c source per core/src/meson.build:1578); PR #215 was
   CLOSED-not-merged 2026-05-30. Owner field rewritten to
   "Owner-driven; pending fresh PR per ADR-0846 Wave 8".

Scope-coordinated with DRAFT PR #291 (docs/state-md-drift-sync —
already migrates the 3 Vulkan rows + T-LEGACY-RUNNER-ANSNR-BROKEN
+ T-LEGACY-RUNNER-STUB-MISSING). Row 203
(T-LEGACY-RUNNER-STUB-MISSING-2026-05-29) cites closed PRs #213
and #181 as OPEN but is left untouched here since PR #291 already
rewrites it.

Net Open count -1; total T-row count unchanged (153).
No code changes — documentation cleanup only.

Deliverables (ADR-0108):
- no digest needed: state.md hygiene
- no alternatives: only-one-way reconciliation
- no rebase-sensitive invariants
- Reproducer: `gh pr view 214 -R VMAFx/vmafx --json state,mergedAt`
  returns `{"state":"CLOSED","mergedAt":null}`;
  `grep -nE '^(<{7}|={7}|>{7})( |$)' core/src/feature/cuda/integer_vif_cuda.c`
  on master returns empty; `ls core/src/read_json_model.*` returns
  only `.c` and `.h`.
- Changelog: changelog.d/changed/state-md-closed-pr-row-sweep.md
- no rebase impact: docs only

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
lusoris added a commit that referenced this pull request Jun 3, 2026
…overage + #336 state.md row sweep + #383 README badges + #337 ADR-0865 ANSNR) (#529)

* docs(libvmaf): doxygen comments on 15 undocumented public C-API entry points

Round-2 follow-on to PR #302 (which closed five targeted gap-findings in
libvmaf.h / picture.h / dnn.h). This pass covers the public surfaces that
PR #302 left untouched, focusing on the headers the ffmpeg patch stack,
the upcoming Go/Rust bindings, and the embedded MCP server consume.

Entry points documented:

- feature.h (file was 100 % undocumented):
  - VmafFeatureDictionary (struct doc + ownership-transfer rules)
  - vmaf_feature_dictionary_set
  - vmaf_feature_dictionary_free

- model.h:
  - VmafModelFlags (enum + per-flag semantics)
  - VmafModelConfig (struct + per-field doc)
  - vmaf_model_load
  - vmaf_model_load_from_path
  - vmaf_model_feature_overload (incl. opts_dict ownership transfer)
  - vmaf_model_destroy (incl. do-not-destroy-after-collection-handoff)
  - VmafModelCollection (struct doc)
  - VmafModelCollectionScoreType (enum doc)
  - VmafModelCollectionScore (struct + per-field doc)
  - vmaf_model_collection_load
  - vmaf_model_collection_load_from_path
  - vmaf_model_collection_feature_overload
  - vmaf_model_collection_destroy

- dnn.h:
  - vmaf_dnn_session_close (pair-with-open contract)

Each block documents the negative-errno return convention, NULL-safety,
ownership-transfer semantics, and the destroy-pairing required to avoid
double-free of collection-owned sub-models. No semantic / no ABI change.

Cleanup pass (CLAUDE.md §12 r12 — touched-file lint-clean rule):
the three Netflix-copyright include guards (__VMAF_FEATURE_H__ /
__VMAF_MODEL_H__ / __VMAF_DNN_H__) trip clang-tidy's
bugprone-reserved-identifier check. Renaming them would diverge from
Netflix/vmaf master and break port-only upstream sync (CLAUDE.md §10),
so each #ifndef / #define gets an inline NOLINT citing the upstream-mirror
invariant — the exact pattern ADR-0278 endorses for load-bearing
upstream-parity identifiers.

Build + lint:
- meson setup build-cpu-doc core -Denable_cuda=false -Denable_sycl=false
- ninja -C build-cpu-doc (35 targets touched by header change; clean)
- clang-tidy -p build-cpu-doc on all 3 touched headers: 0 fork-local
  warnings (the 3 reserved-identifier warnings present on master are now
  NOLINT-cited; remaining warnings are in system headers and suppressed).
- pre-commit run --files <all 5 touched files>: green.

ADR-0108 deliverables:
- Research digest: no digest needed — trivial doc-only addition over
  Netflix-stable signatures already covered by the existing reference
  manual.
- Decision matrix: no alternatives needed — only-one-way fix; the
  ownership-transfer text matches the implementation in core/src/model.c
  and core/src/dict.c verbatim.
- AGENTS.md invariant note: no rebase-sensitive invariants — the doc
  text sits above unchanged upstream signatures; future merges from
  Netflix produce tractable 3-way merges. The NOLINT cites name the
  invariant they preserve (upstream-mirror include guards).
- Reproducer / smoke test: see PR body.
- Changelog fragment:
  changelog.d/added/libvmaf-public-header-doc-comments-round2.md.
- Rebase notes: docs/rebase-notes.md updated with a dedicated section.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* test(go): expand cmd/vmafx-{controller,server,mcp} coverage

Add unit tests for the lowest-coverage Go cmd/ subpackages identified by
the master-tip workflow audit (Section F). No behavior change.

Coverage deltas (against origin/master tip bbcaa8d):

  cmd/vmafx-controller        18.6% -> 32.4%  (+13.8 pp)
  cmd/vmafx-controller/nodes  80.7% -> 82.5%  (+1.8 pp)
  cmd/vmafx-server            27.5% -> 47.9%  (+20.4 pp)
  cmd/vmafx-mcp                3.5% -> 24.6%  (+21.1 pp)

New test files:

- cmd/vmafx-controller/main_extra_test.go
    405 method-not-allowed on /healthz, /readyz, /v1/score;
    400 invalid-JSON body; 500 scorer-error mapping via a stub vmaf
    binary; runHTTP graceful shutdown bounded by GracefulShutdownTimeout;
    envOr default+override; version().
- cmd/vmafx-controller/nodes/registry_edge_test.go
    Get(unknown), distinct-IDs-for-same-name contract pin,
    Heartbeat updates JobsRunning + advances LastHeartbeat
    (reaper eviction predicate), concurrent Register/Heartbeat under
    -race, defensive-copy assertion on All().
- cmd/vmafx-server/main_extra_test.go
    Same shape as the controller HTTP server tests; pins the PR #300
    bounded-timeout shutdown invariant.
- cmd/vmafx-mcp/impl_test.go
    All arg helpers (strArg, intArg, floatArg, boolArg, hasArg);
    every pure helper (classifySourceResolution, modelResolutionClass,
    resolutionMismatchWarning, inferBackendFromPayload,
    inferBackendFromSym, stripModelExt, toFFmpegPixfmt, pickWorstFrames,
    floatFromAny, roundF, truncate); representative handler error paths
    (handleProbeBackend missing/unknown backend, handleDescribeModel
    missing name, handleVmafScore invalid path / zero dimensions,
    handleCompareModels empty list). Pins the errorResult().IsError ==
    true invariant from project memory (MCP isError must be True so
    clients branch correctly).

Drive-by fix: .gitignore anchored the Go binary-ignore rules with a
leading slash so they only match the repo-root binaries, not any path
component sharing the name. Without this, untracked files like
cmd/vmafx-server/main_extra_test.go were silently ignored by `git add`.

Verification:

  go test -race -cover ./cmd/vmafx-controller/... \
                      ./cmd/vmafx-server/...     \
                      ./cmd/vmafx-mcp/...
  go vet  ./...

All green; no behavior change. The pre-existing
cmd/vmafx-operator/internal/controller failure (kubebuilder envtest
needs etcd binaries on PATH) is unrelated to this change and reproduces
on a clean origin/master checkout.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* docs(state): reconcile 2 Open rows that cited CLOSED PRs (#214, #215)

Two Open rows in docs/state.md cited PRs that were CLOSED-not-merged
and flagged as follow-up by the PR #291 closing agent. Verified
against master tip bbcaa8d and master state of the underlying
issues:

1. T-CUDA-FILTER1D-RES-DISPATCH-CONFLICT-2026-05-29 — migrated from
   Open to Recently closed (superseded). The conflict markers only
   existed on the unmerged scaffold branch tip 35a1fb6. PR #91
   (merged 2026-05-29T09:37:48Z) landed ADR-0753 resolution-aware
   dispatch via the adm_cm_device() consumer without extending
   dispatch into filter1d_8(), so master never carried the
   build-failing scaffold variant. PR #214 (the planned
   conflict-marker cleanup) was CLOSED-not-merged 2026-05-30 when
   its base scaffold branch was abandoned. core/src/feature/cuda/
   integer_vif_cuda.c::filter1d_8() on master uses the clean
   unconditional cuLaunchKernel paths.

2. T-CPP23-READ-JSON-MODEL-PENDING-2026-05-29 — kept Open but the
   dead PR #215 citation removed. The C++23 Wave 8 conversion of
   core/src/read_json_model.c is still pending on master (still a
   .c source per core/src/meson.build:1578); PR #215 was
   CLOSED-not-merged 2026-05-30. Owner field rewritten to
   "Owner-driven; pending fresh PR per ADR-0846 Wave 8".

Scope-coordinated with DRAFT PR #291 (docs/state-md-drift-sync —
already migrates the 3 Vulkan rows + T-LEGACY-RUNNER-ANSNR-BROKEN
+ T-LEGACY-RUNNER-STUB-MISSING). Row 203
(T-LEGACY-RUNNER-STUB-MISSING-2026-05-29) cites closed PRs #213
and #181 as OPEN but is left untouched here since PR #291 already
rewrites it.

Net Open count -1; total T-row count unchanged (153).
No code changes — documentation cleanup only.

Deliverables (ADR-0108):
- no digest needed: state.md hygiene
- no alternatives: only-one-way reconciliation
- no rebase-sensitive invariants
- Reproducer: `gh pr view 214 -R VMAFx/vmafx --json state,mergedAt`
  returns `{"state":"CLOSED","mergedAt":null}`;
  `grep -nE '^(<{7}|={7}|>{7})( |$)' core/src/feature/cuda/integer_vif_cuda.c`
  on master returns empty; `ls core/src/read_json_model.*` returns
  only `.c` and `.h`.
- Changelog: changelog.d/changed/state-md-closed-pr-row-sweep.md
- no rebase impact: docs only

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* chore(meta): README badge audit + Cargo / pyproject repo-metadata sweep

Audit + backfill the fork's repo-metadata surface so cargo / pip /
GitHub all advertise the canonical VMAFx/vmafx URLs:

- README.md: add Rust CI + Go CI workflow badges (both workflows ship
  on master but were not surfaced). All five pre-existing workflow
  badges already point at VMAFx/vmafx and reference real, active,
  master-green workflows; verified via the Actions API. License,
  Conventional Commits, OpenSSF Scorecard, ko-fi badges already
  present.
- Cargo.toml: add [workspace.package] with repository / homepage /
  documentation / license / authors. Both workspace members
  (bindings/rust/vmafx-sys, core/src/feature/rust/tad) switched to
  workspace-inherited metadata so URL drift is impossible across the
  Rust workspace. cargo metadata confirms both crates now expose the
  VMAFx/vmafx URLs.
- pyproject.toml (root, ai/, tools/vmaf-tune, tools/vmaf-roi-score,
  tools/ensemble-training-kit, dev-llm/, mcp-server/vmaf-mcp/): add
  [project.urls] with Homepage / Repository / Documentation / Issues /
  Changelog. All seven fork-authored projects now ship the same URL
  block; the package indexes (PyPI / internal) get a consistent
  repository link.
- deploy/helm/vmafx/Chart.yaml: already correct (home + sources
  already point at VMAFx/vmafx). No change needed.
- changelog.d/fixed/ + docs/rebase-notes.md: deliverables.

Coordination with PR #331 (rebrand sweep): #331 only touches the
line-1 copyright header of two of the seven pyproject files; this
PR adds a new [project.urls] block below — no merge conflict.

Deep-dive deliverables (ADR-0108):
- Research digest: no digest needed: trivial repo-metadata sweep.
- Decision matrix: no alternatives: only-one-way fix (URLs must
  match the rebrand target).
- AGENTS.md invariant: no rebase-sensitive invariants — fork-only
  metadata files, none mirror upstream Netflix.
- Reproducer: `cargo metadata --no-deps --format-version 1 | jq` +
  `python3 -c "import tomllib; tomllib.loads(open('pyproject.toml','rb').read().decode())"`.
- CHANGELOG fragment: changelog.d/fixed/readme-badges-metadata-audit.md.
- Rebase note: added to docs/rebase-notes.md (impact: none, fork-only).

* docs(adr): author ADR-0865 for ANSNR sunset (closes PR #38 ADR-0108 gap)

PR #38 (merged 2026-05-28) removed `float_ansnr` from the C backend
but cited `Parent ADR-0709` in its body — ADR-0709 is the Phase 4b
distributed-platform umbrella and contains zero ANSNR content.
PR #295 + PR #324 inherited the bad cite. No dedicated ANSNR-sunset
ADR existed in tree.

This change:
- Authors `docs/adr/0865-ansnr-sunset-pre-vmaf-metric-drop.md` as the
  missing parent ADR, back-dated to 2026-05-28 (PR #38 merge date) so
  the dependency chain (ADR-0865 -> PR #38 -> ADR-0749 Python sunset)
  is consistent.
- Documents the historical mis-cite in the new ADR's `## Notes`
  section so future readers landing on PR #38 can recover the trail.
  PR bodies on the remote are immutable merge-history and cannot be
  rewritten.
- Adds the index fragment + `_order.txt` row; regenerates
  `docs/adr/README.md` via `scripts/docs/concat-adr-index.sh`.
- Adds `docs/state.md` row (Updated note + Recently-closed entry).
- Adds `docs/rebase-notes.md` entry documenting the rebase invariant
  (upstream still ships `ansnr` extractors; fork must keep deleting).
- Adds `changelog.d/changed/ansnr-sunset-adr-authoring.md` fragment.

In-tree audit confirmed zero `ADR-0709` references mis-cite ANSNR —
all remaining tree-side `ADR-0709` cites correctly point at Phase 4b
distributed-platform content. No tree-side citation fix-up required.

Docs-only PR. No code changes.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

* chore(bundle): add changelog fragment for doc-sweep bundle batch-1

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
Co-authored-by: Lusoris <lusoris@pm.me>
@lusoris
lusoris deleted the fix/pr50-residual-conflict-markers branch June 4, 2026 08:12
lusoris added a commit that referenced this pull request Jun 12, 2026
…CI) (#868)

* fix(codeql): resolve HIGH-severity security-cpp-high alerts (23 sites)

- cpp/integer-multiplication-cast-to-long (11): pre-cast one operand to
  size_t / double / ptrdiff_t before int*int multiplications in
  cambi.c, float_vif.c (log message), iqa/convolve.c (img_offset),
  moment.c, psnr.c, and vif_tools.c (four memcpy size expressions).
  Add stddef.h to convolve.c for ptrdiff_t.

- cpp/incomplete-parity-check (3): change `% 2 == 1` to `% 2 != 0`
  in vif_tools.c (assert), svm.cpp (powi loop), pdjson.c (JSON
  object key/value alternation). The == 1 form is wrong for negative
  operands; != 0 is always correct.

- cpp/wrong-type-format-argument (2): fix float_vif.c error log that
  printed size_t fields scaled_w/scaled_h with %d; change to %zu.

- cpp/world-writable-file-creation (1): in vmaf.cpp replace bare
  fopen("wb") with open(O_WRONLY|O_CREAT|O_TRUNC, 0644)+fdopen() on
  POSIX so the created file is never world-writable independent of the
  caller's umask. Add <fcntl.h>.

- cpp/path-injection (4): in test_output.c resolve the mkstemp-created
  path through realpath() immediately after creation, breaking the taint
  chain from getenv("TMPDIR") to the vmaf_write_output call site.

- cpp/toctou-race-condition (2): skipped — both sites are in test
  cleanup (RMDIR after stat assertion). The stat result drives a test
  assertion, not a security-sensitive access decision; no atomic
  replacement of open() is applicable to rmdir. Reported as skipped.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(codeql): resolve security-python-and-ci CodeQL alerts

Fixes 18 open CodeQL alerts across the Python and CI categories:

- yaml.github-actions.security.run-shell-injection (#661): move
  github.event_name, github.base_ref, and github.event.before from
  inline ${{...}} interpolation to env: vars in the SYCL clang-tidy
  detect step of lint-and-format.yml.

- python.lang.security.use-defused-xml-parse (#216, #217): replace
  xml.etree.ElementTree with defusedxml.ElementTree in
  feature_extractor.py and quality_runner.py; add defusedxml>=0.7.1
  to python/pyproject.toml and python/requirements.txt.

- py/undefined-export (#352, #353, #354, #616): restructure
  aiutils/__init__.py to do a conditional eager import of the parquet
  helpers so the names are defined when pyarrow is present, and only
  include them in __all__ when the import succeeded.

- py/stack-trace-exposure (#178, #179, #585): log exception detail
  server-side and return a generic message to the HTTP client in
  http_transport.py _handle_score (invalid JSON, bad params, scorer
  error branches).

- python.lang.security.audit.dangerous-subprocess-use-tainted-env-args
  (#227, #372): add shlex.quote() around user-supplied path arguments
  passed into shell strings in extract_ugc_features.py and
  test_bbb_e2e_v5_bug_cluster.py.

- py/file-not-closed (#677, #678): replace bare open() calls with
  context managers in test_coverage_round3.py.

- py/redundant-comparison (#427, #431): remove redundant
  assert not (x != y) lines that duplicate the preceding assert x == y.

- py/equals-hash-mismatch (#182): convert RdPoint to frozen=True
  dataclass so __eq__ and __hash__ are generated consistently.

- py/inheritance/signature-mismatch (#197): add result_dict=None
  default to EnsembleVmafQualityRunner._populate_result_dict so the
  signature is compatible with the base class.

- py/multiple-definition (#201): drop redundant assignment to
  feature_found in feature_extractor.py wildcard discovery path.

- py/str-format/surplus-named-argument (#204): remove unused
  dataset= kwarg from the format() call in routine.py.

Skipped: python.lang.security.audit.insecure-file-permissions (#373) —
  the Unix socket at 0o660 is intentional (Go sidecar node must write
  to it and runs as the same UNIX group); tightening to 0o644 would
  break the IPC channel.

Skipped: py/path-injection (#180, #181) — _validate_path() already
  resolves the path and checks it against an allowlist before any file
  operation; the data flow is secure and the CodeQL dataflow trace is a
  false positive on this allowlisted pattern.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Lusoris <lusoris@pm.me>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant