fix(governance): preserve proposal branch create transition - #1176
fix(governance): preserve proposal branch create transition#1176seonghobae wants to merge 63 commits into
Conversation
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: 📝 WalkthroughWalkthroughChanges에이전트 멘션 동시성
중앙 required-workflow 적용 범위
Estimated code review effort: 2 (Simple) | ~10 minutes Merge Risk: 🟡 Moderate · up to This PR expands central governance reviews to stacked branches, but its validation currently permits malformed branch-scope configurations that could allow required review coverage to be missed without detection. The audit contract and regression tests should be tightened before merging. 🚥 Pre-merge checks | ✅ 3 | ❌ 2❌ Failed checks (2 warnings)
✅ Passed checks (3 passed)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Current-head validation at
The full central suite had prior 100% evidence on the unchanged main source; this PR adds only the scoped audit/docs/ADR/test contract. Hosted current-head Checks and two qualifying independent approvals remain required; no bypass or self-approval. |
|
Successor current-head validation at
The documentation-only successor preserves the implementation proof; stale predecessor-head review evidence does not count. A fresh exact-head independent review and current hosted Checks remain required before merge. |
|
Exact current head is now |
|
Current-head validation for bc2c93a: verified the live organization ruleset 18156473 is active with ref_name.include=[~ALL], and the PR aligns the audit code, regression fixture, ADR, and operator rollout ledger with stacked pull-request coverage. Passed: 16 central ruleset audit tests, Ruff, compileall, and git diff --check. Please review this exact head; merge remains gated on an independent non-author approval and terminal protected checks. |
|
@opencode-agent Please review the current PR head bc2c93a. Verify the live ruleset alignment, stacked-PR scope audit, changed-file evidence, current mergeability, and required checks. Do not approve a stale head. |
|
@opencode-agent review exact current HEAD bc2c93a. Inspect the complete diff, validate security and regression behavior, and publish only evidence bound to this SHA. Do not transfer predecessor approval, modify the branch, or merge. |
|
@opencode-agent please review exact current HEAD |
|
@cwl-noema-review please independently review exact current HEAD |
|
Reproduced and fixed the central router Check failure at exact HEAD |
|
@cwl-noema-review independently re-review exact current HEAD |
|
Exact-head causal repair evidence for
Hosted exact-head workflows and independent formal review remain separate non-passing gates until terminal evidence exists. |
|
Current-head validation for |
|
@opencode-agent review\nHead SHA: aa63517\nReview current HEAD only; check ruleset scope, stacked-PR required workflows, workflow permissions, and all changed tests/docs. Re-run after any push. |
|
Current-head validation for |
|
@opencode-agent review\nHead SHA: aa63517\nReview this exact head only, including least-privilege permissions, repository-dispatch authorization, and all changed queue/idempotency contracts. Re-run after any push. |
|
Exact-head verification for the stacked central workflow governance change. Current pushed head: Root cause fixed: GitHub Actions rejects the unsupported Verified at this exact head:
@opencode-agent please perform the independent formal review for current head |
|
Correction to the previous evidence comment: the exact pushed/current PR head is |
…ked-pr-central-required-workflows
|
Queued @opencode-agent for PR #1176 at head |
|
Queued @cwl-noema-review for PR #1176 at head |
… to merge; branch already current)
|
@opencode-agent review Please perform an independent review of exact head |
There was a problem hiding this comment.
Pull request overview
OpenCode could not approve from deterministic current-head evidence because GitHub Checks have failed.
Findings
1. HIGH Current-head GitHub Checks - Fix failed required checks before approval
- Problem: Failed same-head checks remain for
d435f88ca56603f6e6320766e36867933eba2248. - Root cause: The model-unavailable evidence fallback is allowed only when peer GitHub Checks are complete and clean.
- Fix: Read and fix the failed check logs below, then rerun the current-head checks.
- Regression test: Keep the model-unavailable fallback gated on an empty failed-check rollup.
Failed checks:
- Strix Security Scan/strix workflow run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/33390204495)
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow: audit-central-ruleset.yml"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow: audit-central-ruleset.yml"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["CI script: audit_central_required_workflows.py"]
S2 --> I2["review and security gate shell path"]
I2 --> R2["Review risk: CI script: audit_central_required_workflows.py"]
R2 --> V2["bash -n plus Strix self-test"]
Evidence --> S3["Test: test_central_required_workflow_ruleset_audit.py"]
S3 --> I3["regression suite"]
I3 --> R3["Review risk: Test: test_central_required_workflow_ruleset_audit.py"]
R3 --> V3["targeted test run"]
There was a problem hiding this comment.
Pull request overview
OpenCode could not approve from deterministic current-head evidence because GitHub Checks have failed.
Findings
1. HIGH Current-head GitHub Checks - Fix failed required checks before approval
- Problem: Failed same-head checks remain for
d435f88ca56603f6e6320766e36867933eba2248. - Root cause: The model-unavailable evidence fallback is allowed only when peer GitHub Checks are complete and clean.
- Fix: Read and fix the failed check logs below, then rerun the current-head checks.
- Regression test: Keep the model-unavailable fallback gated on an empty failed-check rollup.
Failed checks:
- Strix Security Scan/strix workflow run: cancelled (https://github.com/ContextualWisdomLab/.github/actions/runs/33390204495)
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow: audit-central-ruleset.yml"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow: audit-central-ruleset.yml"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["CI script: audit_central_required_workflows.py"]
S2 --> I2["review and security gate shell path"]
I2 --> R2["Review risk: CI script: audit_central_required_workflows.py"]
R2 --> V2["bash -n plus Strix self-test"]
Evidence --> S3["Test: test_central_required_workflow_ruleset_audit.py"]
S3 --> I3["regression suite"]
I3 --> R3["Review risk: Test: test_central_required_workflow_ruleset_audit.py"]
R3 --> V3["targeted test run"]
Current exact-head state (2026-08-31)
d435f88ca56603f6e6320766e36867933eba2248.main@1cbb6aaf0a24c3628d24c3dd6d9dcaa8a7eec0c5.d33dd13a65df3ae53acd85c4915e4f22603ecf26plus protected main; exact treef21763233acaf8bd02f96266c2556af6d27c62ed.0 behind / 63 ahead; the effective main-relative delta remains exactly the three governance-owner files:.github/workflows/audit-central-ruleset.ymlscripts/ci/audit_central_required_workflows.pytests/test_central_required_workflow_ruleset_audit.py38 passed2,143 passed · 1 skipped · 21 subtests10,611/10,6114,272/4,272100%33390204514is terminal-failure without a timely current-head verdict; Required Noema33390204632and full Strix33390204495are cancelled. These required semantic gates remain non-passing.CHANGES_REQUESTEDbecause the same-head full Strix run is cancelled; qualifying approval is absent and unresolved review threads are 0. Predecessor reviews/checks do not transfer.17921150still requires 0 approvals, does not require latest-push approval, permits rebase, and givesOrganizationAdminan always bypass. Do not merge while these admission contradictions and exact-head review requirements remain unresolved.Decision:
WAIT_FOR_EXACT_HEAD_HOSTED_AND_FORMAL_REVIEW_EVIDENCE.Buyer-visible gap and causal boundary
The create-transition repair is operationally effective: inherited organization ruleset
18156473is default-branch-only with create enforcement disabled, and a ScopeWeave proposal branch was created and updated normally. The remaining governance contradiction is layered protection:17921150: approvals0, last-push approvalfalse, rebase allowed, andOrganizationAdmin/alwaysbypass;18156473: approvals1, last-push approvalfalse, andOrganizationAdmin/alwaysbypass;The protected-main audit previously inspected the organization/stacked rulesets but did not read repository ruleset
17921150, and neither organization nor repository audit rejected configured bypass actors. This PR now fails closed on both live owner boundaries.Refs #1200.
Change
do_not_enforce_on_create=truefor normal proposal-branch creation;.githubrepository ruleset17921150in the protected-main governance workflow;No consumer source, protected branch, live ruleset setting, bypass, or gate reduction was used.
Test-first evidence
Initial repository-boundary repair:
17921150.Current review/live-payload regressions:
compileallandgit diff --check: pass.Protected-main merge-tree deterministic coverage is complete: 10,034/10,034 statements and 3,970/3,970 branches, with no missing or partial branches.
Acceptance state
The source repair is current-base aligned and locally complete, but hosted governance evidence is still non-passing:
CHANGES_REQUESTEDand noAPPROVEDverdict.Do not merge from local source tests or mechanical mergeability alone.
Keep #1200 open until:
Summary by CodeRabbit