fix: adopt published integration-base validation - #135
Conversation
There was a problem hiding this comment.
Deterministic Validator approval for exact head fe469919a0d83d449b9f343cb05d9a1f46ca971c.
Ticket: ticket-094
Correlation ID: goal-pr-135-ticket-094
Model: zai/glm-5.3
Package advisory authority: ADVISORY (promotion FORBIDDEN)
Package digest: af01c25142beb252f0899d16a58425edecf20a68726bba7116c21442c42b10b3
Package evidence digest: b23dc1f8375546d7fe75b86dfcd6cbb1bda829251c59434af1034f4960c722cd
Package files: 9; high-risk samples: .governance/governance_check.py, .governance/worktree_overlap_check.py, .governance/worktree_path_check.py
Reviewed diff chunks: 1
Advisory LLM verdict: APPROVE
Advisory summary: Reviewed all 1 diff chunk(s). Ticket-094 adopts published standard wellmanifest/new-project 0.20.16 at immutable revision 6d2da01 via an atomic governance adoption. Visible changes are limited to governance manifests/checkers, ticket metadata, and the pyproject standard/revision pin bump (0.20.13 -> 0.20.16), consistent with the advisory binding. Sampled high-risk governance checkers show a conservative change: is_published_integration only recognizes a clean integration whose supplied base equals the exact first parent and never grants approval; worktree overlap/path validation tightening (repositoryName basename validation, shared-observation comparison) are defensive improvements. All four required checks pass.
Advisory findings: none
The LLM output above is advisory and was not used as the approval trust root.
Actual PR impact radar
Exact range: c684b082618c8b7ba0cd54ca03d04aeff1f771b3...fe469919a0d83d449b9f343cb05d9a1f46ca971c
Change digest: 0e94f159352b33238131968a5314f3de6f346c0cd9b29235fc6c38ccf186eb0a
Score: 76/100 (L), estimated 99 min, split recommended: true
Affected services/components: repository-wide/unclassified
Machine-readable radar JSONL and SVG
{"actual_change":{"additions":208,"base_sha":"c684b082618c8b7ba0cd54ca03d04aeff1f771b3","binary_files":0,"categories":{"code":3,"configuration":7,"docs":2},"change_digest":"0e94f159352b33238131968a5314f3de6f346c0cd9b29235fc6c38ccf186eb0a","comparison":"c684b082618c8b7ba0cd54ca03d04aeff1f771b3...fe469919a0d83d449b9f343cb05d9a1f46ca971c","deletions":35,"file_count":12,"files":["governance/error/GOV-WORKTREE-OVERLAP.md","governance/governance_check.py","governance/manifest.base.json","governance/manifest.json","governance/manifest.lock.json","governance/worktree_overlap_check.py","governance/worktree_path_check.py","governance/worktrees.lock.json","governance/worktrees.schema.json","project/ticket-094/README.md","project/ticket-094/intent.json","pyproject.toml"],"head_sha":"fe469919a0d83d449b9f343cb05d9a1f46ca971c","service_count":0,"services":[]},"assessment_mode":"observed-pr","axes":{"coupling":5,"delivery":4,"scope":5,"uncertainty":3,"validation":2},"complexity":"L","confidence":0.9,"diagnostics":["RADAR-ACCEPTANCE-MISSING","RADAR-BUDGET-EXCEEDED"],"estimate":{"budget_minutes":30,"minutes":99,"within_budget":false},"impact":{"components":["3.12","governance","project","repository-root","wellmanifest"],"files":["3.12/3.13","governance/error/GOV-WORKTREE-OVERLAP.md","governance/governance_check.py","governance/manifest.base.json","governance/manifest.json","governance/manifest.lock.json","governance/worktree_overlap_check.py","governance/worktree_path_check.py","governance/worktrees.lock.json","governance/worktrees.schema.json","project/ticket-094/README.md","project/ticket-094/intent.json","pyproject.toml","wellmanifest/new-project"],"public_interfaces":["governance/worktrees.schema.json"],"runtime_dependencies":1},"schema":"subactor.ticket-radar/v1","score":76,"split":{"parts":[{"estimated_minutes":20,"name":"Define contract and acceptance boundary","scope":["governance/worktrees.schema.json"]},{"estimated_minutes":14,"name":"Implement 3.12","scope":["3.12"]},{"estimated_minutes":14,"name":"Implement governance","scope":["governance"]},{"estimated_minutes":14,"name":"Implement project","scope":["project"]},{"estimated_minutes":14,"name":"Implement repository-root","scope":["repository-root"]},{"estimated_minutes":14,"name":"Implement wellmanifest","scope":["wellmanifest"]},{"estimated_minutes":15,"name":"Validate and project to trackers","scope":["tests","planfile","github/gitlab/jira projections"]}],"reason":"estimated_minutes_exceed_budget","recommended":true},"standards":[{"id":"wellmanifest/dsl","revision":"6c60fc4e0dd1f1bb74f46a7745e28019908d1203","version":"0.1.0-dev"},{"id":"wellmanifest/ticket-lifecycle","revision":"5bf581907a87b46a13a73e6c033d3abe4d9a306f","version":"0.1.0-dev"},{"id":"wellmanifest/git-lifecycle","revision":"7d77d4b7af57e69bc75c3a0290b3a4805c5c4438","version":"0.2.0-dev"},{"id":"wellmanifest/logs","revision":"48c284ef7a069055c0bcb6b900147ce5e65f8b43","version":"0.3.0"}],"ticket_ref":"ticket-094"}<svg xmlns="http://www.w3.org/2000/svg" width="128" height="128" viewBox="0 0 128 128" role="img"><title>ticket-094: fix: adopt published integration-base validation</title><rect width="128" height="128" rx="12" fill="#f8fafc"/><g stroke-width="1"><polygon points="64,55 72,61 69,71 59,71 56,61" fill="none" stroke="#d7dde5"/><polygon points="64,47 80,59 74,78 54,78 48,59" fill="none" stroke="#d7dde5"/><polygon points="64,38 89,56 79,85 49,85 39,56" fill="none" stroke="#d7dde5"/><polygon points="64,30 97,53 84,92 44,92 31,53" fill="none" stroke="#d7dde5"/><polygon points="64,21 105,51 89,99 39,99 23,51" fill="none" stroke="#d7dde5"/><line x1="64" y1="64" x2="64" y2="21" stroke="#aab4c0"/><line x1="64" y1="64" x2="105" y2="51" stroke="#aab4c0"/><line x1="64" y1="64" x2="89" y2="99" stroke="#aab4c0"/><line x1="64" y1="64" x2="39" y2="99" stroke="#aab4c0"/><line x1="64" y1="64" x2="23" y2="51" stroke="#aab4c0"/></g><polygon points="64,21 105,51 79,85 54,78 31,53" fill="#fb923c" fill-opacity="0.45" stroke="#c2410c" stroke-width="2"/><circle cx="64" cy="64" r="3" fill="#c2410c"/><g font-family="sans-serif" font-size="7" fill="#334155"><text x="64" y="11" text-anchor="middle">SCO</text><text x="114" y="48" text-anchor="middle">COU</text><text x="95" y="107" text-anchor="middle">UNC</text><text x="33" y="107" text-anchor="middle">VAL</text><text x="14" y="48" text-anchor="middle">DEL</text></g><text x="64" y="124" text-anchor="middle" font-family="sans-serif" font-size="8" fill="#0f172a">L · 99m</text></svg>DECISION D-094-4420
TICKET ticket-094
HEAD_SHA fe469919a0d83d449b9f343cb05d9a1f46ca971c
CORRELATION_ID goal-pr-135-ticket-094
ACTOR agent:ifuri-validator-agent[bot]
APPLIED_RULE P-CORE-015
INPUT advisory_package_receipt = {"binding":{"repository":"semcod/goal","pull_request":135,"base_branch":"main","base_sha":"c684b082618c8b7ba0cd54ca03d04aeff1f771b3","head_sha":"fe469919a0d83d449b9f343cb05d9a1f46ca971c","policy_digest":"90ec326181674596010fe7f363cc3a839340b36cf2bfb2edf9f2aeff93494ddf","registry_digest":"bb7f19005d6008c37ef2614fa13ca7bc4d53c2cde7531bc4b6fd86cbb297b9f2"},"package_digest":"af01c25142beb252f0899d16a58425edecf20a68726bba7116c21442c42b10b3","evidence_digest":"b23dc1f8375546d7fe75b86dfcd6cbb1bda829251c59434af1034f4960c722cd","package_file_count":9,"samples":[{"path":".governance/governance_check.py","risk":"executable,code","diff_digest":"c6d4298f3c387dd25008eba65c0151c0ddf55cca9a452af45f47fdcfc5128b12","sample_digest":"cabbd4271659ff75654caecd4ea94f8a0c09a545a054f4684c392a55468596fa"},{"path":".governance/worktree_overlap_check.py","risk":"executable,code","diff_digest":"47b63a6dd9f685ea50be6b9c5109b37e4640125bd7dff1edf5842a0715158ee3","sample_digest":"d2eaa8aaac561e5baed095368ce1342919b881aa48aadd2eae3f0ea0794e9d0d"},{"path":".governance/worktree_path_check.py","risk":"executable,code","diff_digest":"c871227a59ca57783415cf740e831d96fb52ad6f3a1461bda7a29b29b5fb22eb","sample_digest":"2f86a1f05bc02d0d4f2bc3c2bfc180a8bb9a961c2dc9253a967d91dc039d4a45"}],"authority":"ADVISORY","promotion":"FORBIDDEN"}
INPUT author_login = "tom-sapletta-com"
INPUT observed_checks = ["governance / enforce=PASS","governance / remote lifecycle=PASS","test (3.13)=PASS","test (3.12)=PASS"]
INPUT required_checks = ["test (3.12)","test (3.13)"]
INPUT required_checks_source = "protected registry (env/request)"
INPUT reviewer_login = "ifuri-validator-agent[bot]"
INPUT superseded_checks = []
INPUT ticket_radar_receipt = {"schema":"subactor.ticket-radar/v1","base_sha":"c684b082618c8b7ba0cd54ca03d04aeff1f771b3","head_sha":"fe469919a0d83d449b9f343cb05d9a1f46ca971c","change_digest":"0e94f159352b33238131968a5314f3de6f346c0cd9b29235fc6c38ccf186eb0a","score":76,"complexity":"L","estimated_minutes":99,"split_recommended":true,"services":[],"authority":"ADVISORY","promotion":"FORBIDDEN"}
VERDICT APPROVE AUTHORITY DETERMINISTIC
REJECTED REQUEST_CHANGES BECAUSE NO_UNSAFE_CHANGE_REASON_FOUND
ADVISORY llm_verdict = "APPROVE" MODEL "zai/glm-5.3"
ASSERT VERDICT_AUTHORITY != "ADVISORY"
A clean main-branch CI checkout previously reported its own integrated changes as conflicting target-branch drift (GOV-BASE-002), stopping pytest before collection. Adopt published wellmanifest/new-project 0.20.16 at immutable revision
6d2da011088b69ebe1636f3bf681e5ec21a062aband update the package governance declaration from that lock. The published checker recognizes only a clean integration whose supplied base is its exact first parent; real intervening overlap, dirty checkouts and ambiguous ranges remain rejected.Validation: 735 tests passed, 2 existing skips; all 10 published real-Git regression cases passed against digest-verified adopted code; governance passed with zero findings; adoption, hook activation, local pin and Compose validation passed. Both PR Python jobs and governance passed; the protected local Validator approved the exact head and merged it. Post-merge main CI passed on Python 3.12 and 3.13 (730 passed, 7 existing environment-dependent skips in each job): https://github.com/semcod/goal/actions/runs/34234868554. All 12 repository-boundary regression cases ran in both jobs. The actual local CLI installation also passed governance, all 12 boundary regressions, all 10 adopted-engine cases and immutable adoption verification.
Ticket: ticket-094. No product version or dependency changes.