test(recovery): cover stale evidence registry cleanup - #233
Conversation
|
Bugbot is not enabled for your account, so this pull request was not reviewed. Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs. |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (1)
Included review availability: Your plan includes up to 1 review per rolling hour; 0 remain after this review. 📝 WalkthroughWalkthrough백업 및 스키마 복구 증거 레지스트리에 stale weak-reference callback 회귀 테스트를 추가했다. 각 테스트는 replacement entry 보존을 검증하고 테스트 후 레지스트리를 정리한다. ChangesPostgreSQL 복구 증거 레지스트리
Estimated code review effort: 2 (Simple) | ~10 minutes Merge Risk: ⚪ Minimal · up to This is a localized test-only change that adds regression coverage without changing production behavior; no actionable merge-blocking risk remains after normal checks and review. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Pull request overview
OpenCode cannot approve yet because required coverage evidence did not pass.
Review outcome
1. HIGH .github/workflows/opencode-review.yml:1 - Coverage evidence did not prove required test/docstring evidence
-
Problem: The required coverage-evidence job result was
failure, so OpenCode cannot establish approval sufficiency for this head. -
Root cause: Automated approval is only valid when the same-head coverage-evidence job proves supported repository test suites passed and configured docstring gates passed or were advisory, or reports not applicable because no supported source files or package manifests exist. Missing, failed, skipped, unavailable, or unsupported-tooling test evidence is a blocker.
-
Fix: Install or configure the repository test/docstring evidence tooling when source files or package manifests exist, rerun the current-head coverage-evidence job, and approve only after it reports
successwith required evidence or explicit no-source not-applicable evidence. -
Regression test: Keep the approval branch checking
needs.coverage-evidence.result == successbefore posting APPROVE, and publish REQUEST_CHANGES when coverage-evidence blocker states such as cancelled, skipped, failed, unsupported-tooling, or below-100 evidence are present. -
Result: REQUEST_CHANGES
-
Reason: coverage-evidence result was
failure, so required test/docstring evidence was not proven for current head1ddfc3260cc8e7e981c5c3bdd4ba2206348f4143. -
Head SHA:
1ddfc3260cc8e7e981c5c3bdd4ba2206348f4143 -
Workflow run: 32003415023
-
Workflow attempt: 1
Coverage evidence
Coverage evidence job did not run or did not publish coverage evidence.
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Test: test_postgres_recovery_evidence_registry.py"]
S1 --> I1["regression suite"]
I1 --> R1["Review risk: Test: test_postgres_recovery_evidence_registry.py"]
R1 --> V1["targeted test run"]
OpenCode Review Overview
Pull request overviewOpenCode cannot approve yet because required coverage evidence did not pass. Review outcome1. HIGH .github/workflows/opencode-review.yml:1 - Coverage evidence did not prove required test/docstring evidence
Coverage evidenceCoverage evidence job did not run or did not publish coverage evidence. Changed-File Evidence Mapflowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Test: test_postgres_recovery_evidence_registry.py"]
S1 --> I1["regression suite"]
I1 --> R1["Review risk: Test: test_postgres_recovery_evidence_registry.py"]
R1 --> V1["targeted test run"]
|
|
@opencode-agent Please re-review the unchanged exact head |
Create a tree-identical branch commit after the authenticated OpenCode review failed before PR test execution while downloading the trusted central uv archive. This does not alter source/docs or count as passing evidence; all required workflows and the independent review must revalidate this new exact head.
|
@opencode-agent Please re-evaluate the current exact head |
There was a problem hiding this comment.
Pull request overview
OpenCode cannot approve yet because required coverage evidence did not pass.
Review outcome
1. HIGH .github/workflows/opencode-review.yml:1 - Coverage evidence did not prove required test/docstring evidence
-
Problem: The required coverage-evidence job result was
failure, so OpenCode cannot establish approval sufficiency for this head. -
Root cause: Automated approval is only valid when the same-head coverage-evidence job proves supported repository test suites passed and configured docstring gates passed or were advisory, or reports not applicable because no supported source files or package manifests exist. Missing, failed, skipped, unavailable, or unsupported-tooling test evidence is a blocker.
-
Fix: Install or configure the repository test/docstring evidence tooling when source files or package manifests exist, rerun the current-head coverage-evidence job, and approve only after it reports
successwith required evidence or explicit no-source not-applicable evidence. -
Regression test: Keep the approval branch checking
needs.coverage-evidence.result == successbefore posting APPROVE, and publish REQUEST_CHANGES when coverage-evidence blocker states such as cancelled, skipped, failed, unsupported-tooling, or below-100 evidence are present. -
Result: REQUEST_CHANGES
-
Reason: coverage-evidence result was
failure, so required test/docstring evidence was not proven for current head5951b7a4d779903b8924abaef2a387cae50b7f54. -
Head SHA:
5951b7a4d779903b8924abaef2a387cae50b7f54 -
Workflow run: 32069198553
-
Workflow attempt: 1
Coverage evidence
Coverage evidence job did not run or did not publish coverage evidence.
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Test: test_postgres_recovery_evidence_registry.py"]
S1 --> I1["regression suite"]
I1 --> R1["Review risk: Test: test_postgres_recovery_evidence_registry.py"]
R1 --> V1["targeted test run"]
|
@cwl-noema-review |
|
@opencode-agent review Please re-evaluate exact current head |
|
@cwl-noema-review Please perform a fresh independent review of exact current head |
|
@opencode-agent review Please re-review the unchanged exact head |
|
@opencode-agent review Please re-evaluate the unchanged exact current head |
|
@opencode-agent review Please re-evaluate the unchanged exact current head |
|
@opencode-agent Please re-review the unchanged exact contributor head |
|
@opencode-agent Please re-review the unchanged exact contributor head This is one bounded retry after material protected control-plane change. Run fresh same-head coverage/test/docstring evidence and publish a new semantic verdict only for |
|
@opencode-agent Please perform a fresh review-only pass on the unchanged exact contributor head |
|
@opencode-agent review Please re-evaluate the unchanged exact contributor head |
|
@opencode-agent Please re-review the unchanged exact contributor head Since the prior bounded same-head request on 2026-08-23, protected This is one bounded activation after a material protected-central change. Generate fresh same-head coverage/test/docstring evidence and a new semantic verdict only for |
|
@opencode-agent review Please re-evaluate the unchanged exact contributor head Since the prior same-head activation, protected central #1333 materially changed this review path: it removed nonexistent This is one bounded review-only activation after that material protected control-plane change. Generate fresh same-head coverage/test/docstring evidence and publish a new semantic verdict only from current trusted evidence. Do not update or rebase the pg branch, transfer predecessor or infrastructure-failed evidence, treat existing synthetic Security/SAST merge-preview execution as exact-head proof, self-approve, weaken gates, or enable auto-merge. |
|
@opencode-agent review Please re-evaluate the unchanged exact contributor head Since the prior same-head activation against central This is one bounded review-only activation after that material protected control-plane change. Generate fresh same-head coverage/test/docstring evidence and publish a new semantic verdict only from current trusted evidence. Do not update/rebase the pg branch, transfer predecessor or infrastructure-failed evidence, treat existing synthetic Security/SAST merge-preview execution as exact-head proof, self-approve, weaken gates, or enable auto-merge. |
|
@opencode-agent review Please perform one bounded review-only re-evaluation of the unchanged exact contributor head Since the last same-head activation, protected central #1360 materially changed this exact review execution path: central Keep the pg head unchanged. Do not update/rebase the branch, transfer predecessor/infrastructure-failed evidence, reinterpret the existing synthetic Security/SAST merge-preview execution as exact-head proof, self-approve, weaken gates, or enable auto-merge. |
Summary
postgres_backup_evidence.py:65->exitandpostgres_schema_evidence.py:49->exitwithout changing production behavior.Exact protected base and current head
Protected
mainremains exactb84f0c94154043a3473939c01bb6471de5a129ae.Current PR head remains exact
5951b7a4d779903b8924abaef2a387cae50b7f54, exactly two commits ahead / zero behind, and changes onlytests/test_postgres_recovery_evidence_registry.py. Production source and canonical documentation are unchanged. Fresh targeted branch inventory finds this as the onlyrecovery-evidence-weakrefbranch.Root cause and regression contract
Protected main inherited two unexercised weakref-callback guard branches from merged recovery-evidence work. The regression tests model a registry slot being replaced while the original weak reference is still live, collect the original object, and prove its stale callback cannot delete the replacement. Production behavior is unchanged.
Exact-head validation — actual checkout authority
Do not infer source identity from workflow-run
head_shametadata or a green conclusion alone. Fresh job-log inspection distinguishes actual contributor-head execution from synthetic pull-request merge execution.True exact-head evidence on unchanged
5951b7a4d779903b8924abaef2a387cae50b7f54:32066570209: the quality job explicitly checks outref: 5951b7a4d779903b8924abaef2a387cae50b7f54, verifiesgit rev-parse HEAD, runs Python 3.14.7, reaches exact 100% owned production statement/branch coverage (3633statements /1006branches, zero misses/partials), 100% public docstrings,1334 passed, 5 deselected, lock freshness and distribution build;32098143650: the reproducible wheel/sdist job explicitly checks out and verifies exact5951b7a4d779903b8924abaef2a387cae50b7f54, uses Python 3.14.7, builds two clean exact-head source trees, verifies reproducible wheel/sdist identity, and uploads bounded evidence named for the exact source commit.Non-passing under the repository's exact-head acceptance contract despite green workflow conclusions:
32066570256: this is organization-required central workflowContextualWisdomLab/.githubrequired-workflow id309078942. Its Trivy job default checkout fetchedrefs/pull/233/mergeand actually ran at synthetic merge commit20581a0a9c51be71baa229cfa1d9e6b050c14c5b, not contributor head5951b7a...;32066570191: this is organization-required central workflow id309078929. Its Semgrep job likewise default-checks outrefs/pull/233/mergeand actually ran at synthetic merge commit20581a0a9c51be71baa229cfa1d9e6b050c14c5b.Those Security/SAST results are useful merge-preview evidence but not exact-head Security/SAST success. Synthetic evidence does not transfer into the exact-head gate. The owning workflow source is the read-only central
.githubcontrol plane; do not copy its workflow locally merely to manufacture a passing pg gate.Fresh inline review-thread inventory is empty.
Current independent-review state
The pg source/test head is unchanged and has no known source finding, but it is not review-clean and must not merge yet.
Fresh formal review inventory remains:
1ddfc3260cc8e7e981c5c3bdd4ba2206348f4143:CHANGES_REQUESTED— predecessor evidence;5951b7a4d779903b8924abaef2a387cae50b7f54, OpenCode run32069198553:DISMISSED— not approval; and5951b7a4d779903b8924abaef2a387cae50b7f54, OpenCode run32100082025: activeCHANGES_REQUESTEDbecause centralcoverage-evidencefailed before proving required test/docstring evidence.Those current-head review failures remain non-passing until superseded by a qualifying fresh same-head review. They are not reinterpreted or dismissed as approval.
Read-only central control-plane boundary
The review/evidence and organization-required Security/SAST control planes are owned by
ContextualWisdomLab/.github, which has its own enabled writer and remains read-only from this repository loop. Mutable central branch, PR, workflow-run, and review state is intentionally not duplicated in this PR body because it can change independently of this unchanged pg head.Issue #244 is the sole pg-owned mutable control-plane ledger for the current central prerequisites and must be freshly read before any action that depends on them. It tracks both the independent-review/coverage prerequisite and the newly proven exact-source defect in the central required Security/SAST workflows.
Accordingly, there is presently no pg-owned source defect that justifies churn on this unchanged head. Keep the head stable while the dedicated central writer resolves its own lanes. After repaired review/evidence and exact-source Security/SAST controls are actually integrated on protected central ancestry, reacquire fresh same-head evidence if protected scheduling does not materialize it automatically.
Governance boundary
Protected
mainremains protected. Merge only the unchanged expected head after fresh verification of protected pg main, exact head/base/ancestry, every available live protection/ruleset surface, actual checkout SHA for required workflows, formal reviews and review threads. Every required exact-head/current-base gate must be terminal-success, zero valid findings/threads may remain, and any qualifying non-author current-last-push approval required by then-live governance must exist.Queued, pending, cancelled, skipped-required, absent, neutral, stale, predecessor, status-only, synthetic, author-only, rate-limited, infrastructure-failed, dismissed, or conclusion-null evidence is non-passing.
Do not copy central materializer/reviewer/scheduler/security workarounds into pg-llm-batch, manufacture a pg head event, self-approve, dismiss substantive review state, weaken gates, or transfer frozen review runs.
Refs #244, #157, #204.