Document Goal contributor verification and protected publication - #138
Conversation
There was a problem hiding this comment.
Deterministic Validator approval for exact head 495cd73dedb59487c6819585d6f2f15f79af5067.
Ticket: ticket-097
Correlation ID: goal-pr-138-ticket-097
Model: zai/glm-5.3
Reviewed diff chunks: 2
Advisory LLM verdict: APPROVE
Advisory summary: Reviewed all 2 diff chunk(s). Documentation-only change adding a contributor verification runbook, docs index entry, and ticket-097 intent metadata. Content accurately reflects existing hosted gates, explicitly does not waive required checks or independent review, and declares limitations. All checks pass. | Documentation-only chunk: intent metadata for ticket-097 contributor verification docs with no runtime dependencies, no interface/data changes, and preserved publication gates. Validation criteria include governance, tests, live main-protection check, and Compose config. All visible checks pass.
Advisory findings: none
The LLM output above is advisory and was not used as the approval trust root.
Actual PR impact radar
Exact range: 64e433beccfb94d3bdd9cb28309f4e8dacd86b09...495cd73dedb59487c6819585d6f2f15f79af5067
Change digest: a1cc27a78afa8bd1e0c3a1acca630e85f584b5ec5117e106a86cdbb4e427f52a
Score: 56/100 (L), estimated 65 min, split recommended: true
Affected services/components: repository-wide/unclassified
Machine-readable radar JSONL and SVG
{"actual_change":{"additions":211,"base_sha":"64e433beccfb94d3bdd9cb28309f4e8dacd86b09","binary_files":0,"categories":{"configuration":1,"docs":3},"change_digest":"a1cc27a78afa8bd1e0c3a1acca630e85f584b5ec5117e106a86cdbb4e427f52a","comparison":"64e433beccfb94d3bdd9cb28309f4e8dacd86b09...495cd73dedb59487c6819585d6f2f15f79af5067","deletions":0,"file_count":4,"files":["docs/README.md","docs/information/contributor-verification.md","project/ticket-097/README.md","project/ticket-097/intent.json"],"head_sha":"495cd73dedb59487c6819585d6f2f15f79af5067","service_count":0,"services":[]},"assessment_mode":"observed-pr","axes":{"coupling":3,"delivery":4,"scope":2,"uncertainty":3,"validation":2},"complexity":"L","confidence":0.9,"diagnostics":["RADAR-ACCEPTANCE-MISSING","RADAR-BUDGET-EXCEEDED"],"estimate":{"budget_minutes":30,"minutes":65,"within_budget":false},"impact":{"components":["docs","head","project"],"files":["docs/README.md","docs/information/contributor-verification.md","head/base","project/ticket-097/README.md","project/ticket-097/intent.json"],"public_interfaces":[],"runtime_dependencies":1},"schema":"subactor.ticket-radar/v1","score":56,"split":{"parts":[{"estimated_minutes":19,"name":"Implement docs","scope":["docs"]},{"estimated_minutes":19,"name":"Implement head","scope":["head"]},{"estimated_minutes":19,"name":"Implement project","scope":["project"]},{"estimated_minutes":15,"name":"Validate and project to trackers","scope":["tests","planfile","github/gitlab/jira projections"]}],"reason":"estimated_minutes_exceed_budget","recommended":true},"standards":[{"id":"wellmanifest/dsl","revision":"6c60fc4e0dd1f1bb74f46a7745e28019908d1203","version":"0.1.0-dev"},{"id":"wellmanifest/ticket-lifecycle","revision":"5bf581907a87b46a13a73e6c033d3abe4d9a306f","version":"0.1.0-dev"},{"id":"wellmanifest/git-lifecycle","revision":"7d77d4b7af57e69bc75c3a0290b3a4805c5c4438","version":"0.2.0-dev"},{"id":"wellmanifest/logs","revision":"48c284ef7a069055c0bcb6b900147ce5e65f8b43","version":"0.3.0"}],"ticket_ref":"ticket-097"}<svg xmlns="http://www.w3.org/2000/svg" width="128" height="128" viewBox="0 0 128 128" role="img"><title>ticket-097: Document Goal contributor verification and protected publication</title><rect width="128" height="128" rx="12" fill="#f8fafc"/><g stroke-width="1"><polygon points="64,55 72,61 69,71 59,71 56,61" fill="none" stroke="#d7dde5"/><polygon points="64,47 80,59 74,78 54,78 48,59" fill="none" stroke="#d7dde5"/><polygon points="64,38 89,56 79,85 49,85 39,56" fill="none" stroke="#d7dde5"/><polygon points="64,30 97,53 84,92 44,92 31,53" fill="none" stroke="#d7dde5"/><polygon points="64,21 105,51 89,99 39,99 23,51" fill="none" stroke="#d7dde5"/><line x1="64" y1="64" x2="64" y2="21" stroke="#aab4c0"/><line x1="64" y1="64" x2="105" y2="51" stroke="#aab4c0"/><line x1="64" y1="64" x2="89" y2="99" stroke="#aab4c0"/><line x1="64" y1="64" x2="39" y2="99" stroke="#aab4c0"/><line x1="64" y1="64" x2="23" y2="51" stroke="#aab4c0"/></g><polygon points="64,47 89,56 79,85 54,78 31,53" fill="#fb923c" fill-opacity="0.45" stroke="#c2410c" stroke-width="2"/><circle cx="64" cy="64" r="3" fill="#c2410c"/><g font-family="sans-serif" font-size="7" fill="#334155"><text x="64" y="11" text-anchor="middle">SCO</text><text x="114" y="48" text-anchor="middle">COU</text><text x="95" y="107" text-anchor="middle">UNC</text><text x="33" y="107" text-anchor="middle">VAL</text><text x="14" y="48" text-anchor="middle">DEL</text></g><text x="64" y="124" text-anchor="middle" font-family="sans-serif" font-size="8" fill="#0f172a">L · 65m</text></svg>DECISION D-097-9678
TICKET ticket-097
HEAD_SHA 495cd73dedb59487c6819585d6f2f15f79af5067
CORRELATION_ID goal-pr-138-ticket-097
ACTOR agent:ifuri-validator-agent[bot]
APPLIED_RULE P-CORE-015
INPUT author_login = "tom-sapletta-com"
INPUT observed_checks = ["governance / enforce=PASS","test (3.13)=PASS","test (3.12)=PASS","governance / remote lifecycle=PASS","onedev/local-verify=PASS"]
INPUT required_checks = ["test (3.12)","test (3.13)","governance / remote lifecycle","governance / enforce"]
INPUT required_checks_source = "protected registry + GitHub applied rules (env/request)"
INPUT reviewer_login = "ifuri-validator-agent[bot]"
INPUT superseded_checks = []
INPUT ticket_radar_receipt = {"schema":"subactor.ticket-radar/v1","base_sha":"64e433beccfb94d3bdd9cb28309f4e8dacd86b09","head_sha":"495cd73dedb59487c6819585d6f2f15f79af5067","change_digest":"a1cc27a78afa8bd1e0c3a1acca630e85f584b5ec5117e106a86cdbb4e427f52a","score":56,"complexity":"L","estimated_minutes":65,"split_recommended":true,"services":[],"authority":"ADVISORY","promotion":"FORBIDDEN"}
VERDICT APPROVE AUTHORITY DETERMINISTIC
REJECTED REQUEST_CHANGES BECAUSE NO_UNSAFE_CHANGE_REASON_FOUND
ADVISORY llm_verdict = "APPROVE" MODEL "zai/glm-5.3"
ASSERT VERDICT_AUTHORITY != "ADVISORY"
Contributors lacked a repository-specific route for validating and publishing Goal changes under its active server protections. Add an indexed runbook with runnable checks, protected publication, stale-base and dependency recovery, and explicit migration requirements.
Validation and publication completed:
onedev/local-verifysucceeded at 2026-09-08T17:11:28.148912Z for head495cd73dedb59487c6819585d6f2f15f79af5067, main64e433beccfb94d3bdd9cb28309f4e8dacd86b09, profile digestc6bbac4bdce611fec0ad6472a0ae3dee775628b3bb8c19ce7036988d943aeb0f, on deployed executor imagesha256:f25d028218b9c1842c3da694e818b40cea480fe633ca42d7778b87a3f68f7f9a.1360d7ef6b02b233708933af83edaf9f53d8840d, and deleted the remote ticket branch.The canonical runbook is
docs/information/contributor-verification.md. Document metadata, sections and links are valid. Remaining gaps are explicitly separate: the missing documentation adoption pin/protected checker, seven standard-pack declarations reported by audit mode, and protected review of any future required-check migration. This run confirms a fresh local canary but retires no existing server gate.Operational follow-up: the local advisory change lease expired during the queue/validation wait; its post-merge transition was rejected, then the expired lease was released without backfilling approval history. Add heartbeat renewal during long waits. Trusted publication authority remains the independent Validator report and server-bound exact-head review.
Ticket: ticket-097