fix: bind PR preflight to the authoritative target base - #136
Conversation
There was a problem hiding this comment.
Deterministic Validator approval for exact head 9422c81ca25796641c4371fa4108cd1110736728.
Ticket: ticket-096
Correlation ID: goal-pr-136-ticket-096-policy2
Model: zai/glm-5.3
Reviewed diff chunks: 1
Advisory LLM verdict: APPROVE
Advisory summary: Reviewed all 1 diff chunk(s). PR preflight now resolves the configured remote base via git ls-remote, validates it strictly (single authoritative head, 40-hex SHA, locally known commit), and passes it explicitly to the unchanged governance gate. Failure paths fail closed rather than falling back to stale refs. Regression tests cover the happy path, stale tracking refs, malformed/ambiguous/unavailable remote output, and locally missing commits. No security issues: no secrets, no workflow changes, fail-closed validation. Tests all pass.
Advisory findings: none
The LLM output above is advisory and was not used as the approval trust root.
Actual PR impact radar
Exact range: bd43a30a3ce5122ebe551246bc8174900eae6174...9422c81ca25796641c4371fa4108cd1110736728
Change digest: 736aaf515c780344b69bd1d58d6afbfcac884dd2a265300d9a03aa0413303c2d
Score: 44/100 (M), estimated 46 min, split recommended: true
Affected services/components: repository-wide/unclassified
Machine-readable radar JSONL and SVG
{"actual_change":{"additions":203,"base_sha":"bd43a30a3ce5122ebe551246bc8174900eae6174","binary_files":0,"categories":{"code":1,"configuration":1,"docs":1,"tests":1},"change_digest":"736aaf515c780344b69bd1d58d6afbfcac884dd2a265300d9a03aa0413303c2d","comparison":"bd43a30a3ce5122ebe551246bc8174900eae6174...9422c81ca25796641c4371fa4108cd1110736728","deletions":3,"file_count":4,"files":["goal/governance/delivery.py","project/ticket-096/README.md","project/ticket-096/intent.json","tests/test_governance_delivery.py"],"head_sha":"9422c81ca25796641c4371fa4108cd1110736728","service_count":0,"services":[]},"assessment_mode":"observed-pr","axes":{"coupling":3,"delivery":2,"scope":2,"uncertainty":3,"validation":1},"complexity":"M","confidence":0.9,"diagnostics":["RADAR-ACCEPTANCE-MISSING","RADAR-BUDGET-EXCEEDED"],"estimate":{"budget_minutes":30,"minutes":46,"within_budget":false},"impact":{"components":["goal","project","tests"],"files":["goal/governance/delivery.py","project/ticket-096/README.md","project/ticket-096/intent.json","tests/test_governance_delivery.py"],"public_interfaces":[],"runtime_dependencies":0},"schema":"subactor.ticket-radar/v1","score":44,"split":{"parts":[{"estimated_minutes":12,"name":"Implement goal","scope":["goal"]},{"estimated_minutes":12,"name":"Implement project","scope":["project"]},{"estimated_minutes":12,"name":"Implement tests","scope":["tests"]},{"estimated_minutes":15,"name":"Validate and project to trackers","scope":["tests","planfile","github/gitlab/jira projections"]}],"reason":"estimated_minutes_exceed_budget","recommended":true},"standards":[{"id":"wellmanifest/dsl","revision":"6c60fc4e0dd1f1bb74f46a7745e28019908d1203","version":"0.1.0-dev"},{"id":"wellmanifest/ticket-lifecycle","revision":"5bf581907a87b46a13a73e6c033d3abe4d9a306f","version":"0.1.0-dev"},{"id":"wellmanifest/git-lifecycle","revision":"7d77d4b7af57e69bc75c3a0290b3a4805c5c4438","version":"0.2.0-dev"},{"id":"wellmanifest/logs","revision":"48c284ef7a069055c0bcb6b900147ce5e65f8b43","version":"0.3.0"}],"ticket_ref":"ticket-096"}<svg xmlns="http://www.w3.org/2000/svg" width="128" height="128" viewBox="0 0 128 128" role="img"><title>ticket-096: fix: bind PR preflight to the authoritative target base</title><rect width="128" height="128" rx="12" fill="#f8fafc"/><g stroke-width="1"><polygon points="64,55 72,61 69,71 59,71 56,61" fill="none" stroke="#d7dde5"/><polygon points="64,47 80,59 74,78 54,78 48,59" fill="none" stroke="#d7dde5"/><polygon points="64,38 89,56 79,85 49,85 39,56" fill="none" stroke="#d7dde5"/><polygon points="64,30 97,53 84,92 44,92 31,53" fill="none" stroke="#d7dde5"/><polygon points="64,21 105,51 89,99 39,99 23,51" fill="none" stroke="#d7dde5"/><line x1="64" y1="64" x2="64" y2="21" stroke="#aab4c0"/><line x1="64" y1="64" x2="105" y2="51" stroke="#aab4c0"/><line x1="64" y1="64" x2="89" y2="99" stroke="#aab4c0"/><line x1="64" y1="64" x2="39" y2="99" stroke="#aab4c0"/><line x1="64" y1="64" x2="23" y2="51" stroke="#aab4c0"/></g><polygon points="64,47 89,56 79,85 59,71 48,59" fill="#fb923c" fill-opacity="0.45" stroke="#c2410c" stroke-width="2"/><circle cx="64" cy="64" r="3" fill="#c2410c"/><g font-family="sans-serif" font-size="7" fill="#334155"><text x="64" y="11" text-anchor="middle">SCO</text><text x="114" y="48" text-anchor="middle">COU</text><text x="95" y="107" text-anchor="middle">UNC</text><text x="33" y="107" text-anchor="middle">VAL</text><text x="14" y="48" text-anchor="middle">DEL</text></g><text x="64" y="124" text-anchor="middle" font-family="sans-serif" font-size="8" fill="#0f172a">M · 46m</text></svg>DECISION D-096-0231
TICKET ticket-096
HEAD_SHA 9422c81ca25796641c4371fa4108cd1110736728
CORRELATION_ID goal-pr-136-ticket-096-policy2
ACTOR agent:ifuri-validator-agent[bot]
APPLIED_RULE P-CORE-015
INPUT author_login = "tom-sapletta-com"
INPUT observed_checks = ["test (3.12)=PASS","governance / enforce=PASS","governance / remote lifecycle=PASS","test (3.13)=PASS"]
INPUT required_checks = ["test (3.12)","test (3.13)","governance / remote lifecycle","governance / enforce"]
INPUT required_checks_source = "protected registry + GitHub applied rules (env/request)"
INPUT reviewer_login = "ifuri-validator-agent[bot]"
INPUT superseded_checks = []
INPUT ticket_radar_receipt = {"schema":"subactor.ticket-radar/v1","base_sha":"bd43a30a3ce5122ebe551246bc8174900eae6174","head_sha":"9422c81ca25796641c4371fa4108cd1110736728","change_digest":"736aaf515c780344b69bd1d58d6afbfcac884dd2a265300d9a03aa0413303c2d","score":44,"complexity":"M","estimated_minutes":46,"split_recommended":true,"services":[],"authority":"ADVISORY","promotion":"FORBIDDEN"}
VERDICT APPROVE AUTHORITY DETERMINISTIC
REJECTED REQUEST_CHANGES BECAUSE NO_UNSAFE_CHANGE_REASON_FOUND
ADVISORY llm_verdict = "APPROVE" MODEL "zai/glm-5.3"
ASSERT VERDICT_AUTHORITY != "ADVISORY"
PR preflight invoked the managed governance gate without a base. After a merged standard adoption, the gate could reuse the old adoption ticket base and attribute already integrated files to an unrelated new PR. Resolve the configured remote target to an immutable commit and pass it explicitly to the unchanged gate. Reject unavailable, ambiguous, malformed and locally missing targets instead of falling back to stale refs or ticket prose.
Validation: 35 focused and 743 full tests passed (2 existing skips); governance and Compose passed. Eight regression cases cover real Git remotes, stale tracking refs and failure paths. The actual ticket-095 preflight now passes without changing its managed gate. Independent approval and all active server checks remain required. Ticket: ticket-096.