Skip to content

chore(deploy,dev): helm values.schema.json + dev-MCP Containerfile ADR-0700 path drift - #354

Merged
lusoris merged 1 commit into
masterfrom
chore/helm-values-schema-and-container-audit
May 31, 2026
Merged

lusoris merged 1 commit into
masterfrom
chore/helm-values-schema-and-container-audit

Conversation

@lusoris

@lusoris lusoris commented May 30, 2026

Copy link
Copy Markdown
Contributor

Summary

Adds deploy/helm/vmafx/values.schema.json (JSON Schema Draft 2020-12)
and fixes dev/Containerfile drift from ADR-0700's libvmaf/ → core/
rename. Single audit cycle per CLAUDE.md §15 vmaf-dev-mcp rebuild policy.

  • Schema enforces enums on the three load-bearing fields (workload,
    gpu.vendor, storage.mode) plus six more (image.pullPolicy,
    service.type, persistence.accessMode, operator.logLevel,
    statefulSet.podManagementPolicy,
    monitoring.serviceMonitor.scheme). additionalProperties: false
    on every typed sub-object catches sibling-key typos
    (replicaCounts, repostiory, maxSurg) at install time.
  • Containerfile: COPY libvmaf/ → COPY core/ + new COPY compat/;
    two cd libvmaf → cd core; comment-block path fixes;
    .dockerignore gains core/build*/ siblings (legacy
    libvmaf/build*/ retained for pre-rename worktrees);
    dev/AGENTS.md gains a "Source-tree paths after ADR-0700 /
    ADR-0870" invariant so future rebases rewrite incoming
    libvmaf/ patches to core/.

Type

  • chore — operational hygiene (helm schema + container path drift)
  • fix — Containerfile is broken against current master without this
  • docs — ADR, research digest, AGENTS.md, rebase-notes, state.md

Checklist

  • Conventional Commits (chore(deploy,dev):).
  • helm lint deploy/helm/vmafx --strict passes.
  • pre-commit run --files <touched> passes.
  • No SIMD/GPU code touched.
  • No new .c / .cpp / .cu / .h / .hpp files.
  • Not a breaking change.
  • ADR row added via docs/adr/_index_fragments/0870-*.md
    (concat-adr-index.sh-driven, ADR-0221).

Bug-status hygiene (ADR-0165)

  • docs/state.md updated — new T-HELM-VALUES-SCHEMA-AND-CONTAINER-AUDIT-2026-05-30
    row under ## Recently closed.

Netflix golden-data gate (ADR-0024)

  • Did not modify any assertAlmostEqual(...) score.
  • No golden value change.

Cross-backend numerical results

no SIMD/GPU code touched: pure ops/devx hygiene.

ADR-0108 six deliverables (strict)

  • D1 research digest:
    docs/research/0870-helm-values-schema-and-container-rebuild-audit.md
  • D2 alternatives matrix: ADR-0870 ## Alternatives considered
    (5 rows: schema-only-defer-container, container-only-defer-schema,
    helm schema-gen plugin, comment-driven generation, COPY . .)
  • D3 AGENTS.md invariant: new ### Source-tree paths after ADR-0700 / ADR-0870 section in dev/AGENTS.md so future rebases
    rewrite incoming libvmaf/ patches
  • D4 reproducer:
    helm template deploy/helm/vmafx --set gpu.vendor=qualcomm
    # Error: at '/gpu/vendor': value must be one of 'nvidia', 'amd', 'intel', 'cpu'
    
    docker compose --project-directory $(git rev-parse --show-toplevel) \
        -f dev/docker-compose.yml build dev-mcp
    # Successful COPY core/ and COPY compat/, proceeds through CUDA/SYCL/HIP stages
  • D5 changelog fragments (per ADR-0221):
    changelog.d/added/0870-helm-values-schema.md +
    changelog.d/fixed/0870-dev-mcp-containerfile-adr-0700-paths.md
  • D6 rebase notes: new section in docs/rebase-notes.md
    ("ADR-0870 — Helm values.schema.json + dev-MCP path drift —
    2026-05-30")

Verification

Check Result
helm lint deploy/helm/vmafx --strict passes
helm template deploy/helm/vmafx renders 174 lines of manifests
helm template ... --set workload=Job --set gpu.vendor=amd --set storage.mode=rclone renders 151 lines
helm template ... --set gpu.vendor=qualcomm rejected: at '/gpu/vendor': value must be one of 'nvidia', 'amd', 'intel', 'cpu'
helm template ... --set workload=Daemonset rejected: at '/workload': value must be one of 'Deployment', 'Job', 'StatefulSet'
helm template ... --set storage.mode=ftp rejected: at '/storage/mode': value must be one of 'http-serve', 'rclone'
hadolint dev/Containerfile 8 pre-existing DL3003/DL4006/DL3002/DL3009 advisories; zero HIGH-severity
grep -rn 'libvmaf/' dev/ only the ADR-0700 annotation comment in the fixed Containerfile
pre-commit run --files <touched> all hooks pass

Files

  • deploy/helm/vmafx/values.schema.json (new, ~250 lines)
  • dev/Containerfile (5 hunks: COPY libvmaf/ → core/, COPY compat/, two cd libvmaf → cd core, two comment blocks)
  • dev/docker-compose.yml (unchanged in this PR — pure annotation comment skip)
  • .dockerignore (3 new core/build*/ lines + ADR-0700 comment)
  • dev/AGENTS.md (new ### Source-tree paths after ADR-0700 / ADR-0870 section)
  • docs/adr/0870-*.md (new ADR)
  • docs/adr/_index_fragments/0870-*.md (new fragment for concat-adr-index)
  • docs/adr/README.md (regenerated row by hand; matches what concat-adr-index produces)
  • docs/adr/_index_fragments/_order.txt (slug appended)
  • docs/research/0870-*.md (new research digest)
  • docs/development/k8s-deployment.md (schema reference paragraph)
  • docs/rebase-notes.md (new ADR-0870 section)
  • docs/state.md (new T-HELM-… row under Recently closed)
  • changelog.d/added/0870-helm-values-schema.md (new)
  • changelog.d/fixed/0870-dev-mcp-containerfile-adr-0700-paths.md (new)

@lusoris
lusoris marked this pull request as ready for review May 31, 2026 13:05
@lusoris
lusoris force-pushed the chore/helm-values-schema-and-container-audit branch from 8653c85 to baf2288 Compare May 31, 2026 13:05
@lusoris
lusoris merged commit 03a41e5 into master May 31, 2026
30 of 31 checks passed
@lusoris
lusoris deleted the chore/helm-values-schema-and-container-audit branch May 31, 2026 13:06
lusoris added a commit that referenced this pull request Jun 12, 2026
…CI) (#868)

* fix(codeql): resolve HIGH-severity security-cpp-high alerts (23 sites)

- cpp/integer-multiplication-cast-to-long (11): pre-cast one operand to
  size_t / double / ptrdiff_t before int*int multiplications in
  cambi.c, float_vif.c (log message), iqa/convolve.c (img_offset),
  moment.c, psnr.c, and vif_tools.c (four memcpy size expressions).
  Add stddef.h to convolve.c for ptrdiff_t.

- cpp/incomplete-parity-check (3): change `% 2 == 1` to `% 2 != 0`
  in vif_tools.c (assert), svm.cpp (powi loop), pdjson.c (JSON
  object key/value alternation). The == 1 form is wrong for negative
  operands; != 0 is always correct.

- cpp/wrong-type-format-argument (2): fix float_vif.c error log that
  printed size_t fields scaled_w/scaled_h with %d; change to %zu.

- cpp/world-writable-file-creation (1): in vmaf.cpp replace bare
  fopen("wb") with open(O_WRONLY|O_CREAT|O_TRUNC, 0644)+fdopen() on
  POSIX so the created file is never world-writable independent of the
  caller's umask. Add <fcntl.h>.

- cpp/path-injection (4): in test_output.c resolve the mkstemp-created
  path through realpath() immediately after creation, breaking the taint
  chain from getenv("TMPDIR") to the vmaf_write_output call site.

- cpp/toctou-race-condition (2): skipped — both sites are in test
  cleanup (RMDIR after stat assertion). The stat result drives a test
  assertion, not a security-sensitive access decision; no atomic
  replacement of open() is applicable to rmdir. Reported as skipped.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(codeql): resolve security-python-and-ci CodeQL alerts

Fixes 18 open CodeQL alerts across the Python and CI categories:

- yaml.github-actions.security.run-shell-injection (#661): move
  github.event_name, github.base_ref, and github.event.before from
  inline ${{...}} interpolation to env: vars in the SYCL clang-tidy
  detect step of lint-and-format.yml.

- python.lang.security.use-defused-xml-parse (#216, #217): replace
  xml.etree.ElementTree with defusedxml.ElementTree in
  feature_extractor.py and quality_runner.py; add defusedxml>=0.7.1
  to python/pyproject.toml and python/requirements.txt.

- py/undefined-export (#352, #353, #354, #616): restructure
  aiutils/__init__.py to do a conditional eager import of the parquet
  helpers so the names are defined when pyarrow is present, and only
  include them in __all__ when the import succeeded.

- py/stack-trace-exposure (#178, #179, #585): log exception detail
  server-side and return a generic message to the HTTP client in
  http_transport.py _handle_score (invalid JSON, bad params, scorer
  error branches).

- python.lang.security.audit.dangerous-subprocess-use-tainted-env-args
  (#227, #372): add shlex.quote() around user-supplied path arguments
  passed into shell strings in extract_ugc_features.py and
  test_bbb_e2e_v5_bug_cluster.py.

- py/file-not-closed (#677, #678): replace bare open() calls with
  context managers in test_coverage_round3.py.

- py/redundant-comparison (#427, #431): remove redundant
  assert not (x != y) lines that duplicate the preceding assert x == y.

- py/equals-hash-mismatch (#182): convert RdPoint to frozen=True
  dataclass so __eq__ and __hash__ are generated consistently.

- py/inheritance/signature-mismatch (#197): add result_dict=None
  default to EnsembleVmafQualityRunner._populate_result_dict so the
  signature is compatible with the base class.

- py/multiple-definition (#201): drop redundant assignment to
  feature_found in feature_extractor.py wildcard discovery path.

- py/str-format/surplus-named-argument (#204): remove unused
  dataset= kwarg from the format() call in routine.py.

Skipped: python.lang.security.audit.insecure-file-permissions (#373) —
  the Unix socket at 0o660 is intentional (Go sidecar node must write
  to it and runs as the same UNIX group); tightening to 0o644 would
  break the IPC channel.

Skipped: py/path-injection (#180, #181) — _validate_path() already
  resolves the path and checks it against an allowlist before any file
  operation; the data flow is secure and the CodeQL dataflow trace is a
  false positive on this allowlisted pattern.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Lusoris <lusoris@pm.me>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
@lusoris lusoris added this to the 1.0.0 — First release milestone Sep 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant