Skip to content

feat(core): apply reviewed Organization hierarchy changes - #119

Draft
seonghobae wants to merge 66 commits into
feat/organization-hierarchy-change-reviewfrom
feat/organization-hierarchy-change-application
Draft

feat(core): apply reviewed Organization hierarchy changes#119
seonghobae wants to merge 66 commits into
feat/organization-hierarchy-change-reviewfrom
feat/organization-hierarchy-change-application

Conversation

@seonghobae

@seonghobae seonghobae commented Aug 25, 2026

Copy link
Copy Markdown
Contributor

Stack position

Dependency-first descendant of #96 (feat/organization-hierarchy-change-review). Fresh parent #96 is exact f2c6e70edcf5c62ae0f848c29efd7bd3b8d45b97, open · Draft · mechanically mergeable on protected develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f. The parent owns post-issuance representation/export integrity (#279), one-snapshot checked-versus-used issuance (#280), per-live-object single-use issuance (#281), timestamp provenance separation (#282), closure-private process-local issuance state (#283), captured digest verification (#284), retained-slot/export verifier integrity (#285), captured issuance semantic validation (#286), direct issuance snapshot/canonical-byte/live-reference-guard helper binding (#287), public builder-to-governed-packet authority (#288), transitive validation/canonicalization authority binding (#289), nested recorded_at timezone-runtime integrity before post-issuance comparison (#290), and exact built-in datetime representation identity after issuance (#291).

#291 is the current parent repair lineage. Exact predecessor 70212e6e00e0e3c0104b2444aadd7ac01880847b retained #290's built-in nested-timezone guard but still used Python aware-datetime equality afterward. Because 16:00+09:00 == 07:00+00:00, a low-level replacement by a distinct exact built-in datetime representing the same instant could escape the parent's stated changed-live-state rejection. Test-first 4bf2c1411d19ce60099948ec9ce9d97c31af6ab8 records the counterexample; no hosted RED is claimed because no PR workflow materialized before that test-only head was superseded. Minimal source repair 1d5f423f3ff3c654dc6dfc6d896ab024c92b9045 keeps the #290 nested-timezone guard and, for exact built-in datetime only, requires the retained value to be the same immutable object captured at issuance before skipping instant-based equality. Package CHANGELOG 60d203d9..., README 5e35c3ab..., TRACEABILITY 70615f59..., and ADR 0096 f2c6e70e... document the same boundary. Current exact-parent Foundation 34441833963, Security 34441833987, SAST 34441834059, and CodeQL 34441833995 are queued/pending; Foundation job 102758308481 still has no runner (runner_id=0, no steps), so no current-head GREEN is claimed.

Historical predecessor 6573a629... had Foundation 34427958099/102717113694 and SAST 34427958070 SUCCESS, plus central coverage/OpenCode/Noema GREEN. Its Security 34427958063 failed closed at dependency-review support and its CodeQL 34427958061 reproduced the central producer/consumer ordering defect. Strix 34427956795/102719245996 subsequently completed SUCCESS after a substantive scan, but that evidence is historical only for the current parent. #290's intermediate 70212e6e... also has only superseded queued evidence and does not authorize the current head.

This child still records the older parent snapshot in its commit graph: current child head is eda9ef283996e65cf19ec250ae3aeec118001346, base ref feat/organization-hierarchy-change-review at stale b9f8e3d291c4bdcd2f0aa5f9d0378dea09e5e7cd, and GitHub reports open · Draft · conflicting/mergeable=false. The stale parent pointer is a repair finding, not a reason to close or destructively rebase this child. Parent #96 must integrate first; after normal protected integration, non-force adopt the resulting protected develop, reconcile this existing child while preserving its valid delta, renumber provisional migrations 0027–0029 if required by integrated truth, reseal exact changed artifacts, and rerun every applicable exact-current-head gate.

Governed application boundary

Migrations 0027–0029 implement a tenant-scoped bitemporal Organization hierarchy application boundary. The mutation re-resolves current/proposed parents, recomputes reviewed unit/hierarchy digests, serializes graph mutation per tenant, rejects stale evidence, self-parenting, current/future-effective cycles and parent continuity gaps, preserves pre-effective business-time truth by correction rather than rewrite, binds exact predecessor/successor/preserved segments, and writes immutable human-confirmed organization_core audit/outbox evidence in the same transaction. FORCE RLS, typed/null-safe review evidence, append-only application evidence, hardened function search paths, and no routine PUBLIC function execution remain part of the boundary.

The parent review packet is evidence only. This application boundary must consume the canonical evidence snapshot emitted by the integrated #96 contract and then independently re-resolve authoritative same-tenant HRIS truth at mutation time; it must not assume the parent packet's closure-private in-process tamper, single-use issuance, creation digest, captured verifier/validator/helper/builder/transitive bindings, nested timezone/identity guard, or live-reference state supplies durable uniqueness, authorization or concurrency control. #283#291 reduce ordinary same-interpreter mutation/execution capability over leaf defense-in-depth state and its construction/verification/sealing paths; they do not move any durable HRIS responsibility from this application/persistence boundary.

Issue #282 adds a clock-provenance acceptance requirement. After normal parent integration, this transaction must generate or attest its authoritative system-recorded audit/outbox timestamp from the system/database clock boundary and persist it separately from packet recorded_at. Packet time may remain immutable review evidence but must never become transaction-time authority. Preserve effective_on business time separately from review-evidence time and authoritative application/audit system time.

Test-first repairs already preserved on this child

  • Interrupted CREATE INDEX CONCURRENTLY retry: RED 41328310e77bdf13d62ce39b2c41cb3e566b715d; migration 0028 detects/removes invalid same-name residue concurrently, preserves completed valid work and resumes governed indexes.
  • Valid-but-wrong index / disabled-or-wrong trigger: RED ecb0b9cd08ae3a17d45e17b5ae0b718e5ddbab2a; repair c2879cd1754287adffadf7059e7a47055e8538ec validates owning table, btree method, uniqueness/readiness/validity, exact key order/predicate and exact enabled BEFORE INSERT ROW trigger function.
  • Cross-schema name collision: RED f75e6377bacb54785cf8757a687114035a97ab44, wiring 38d9534eb5c6e0c9ff1e185c7b5fe6241f1fb6ee, repair d0d8950dc818a7c6a2ff8aa1eaf8e36d600875f6 scopes governed postconditions to public.
  • Missing preserved business-time history: RED d84c5d88142a3726bbb65c6c775c8a154b26dea3, repair 996aaef68fbcfb5954d9bb953228c4e37fc3dae8 requires the exact preserved predecessor segment.
  • Unexpected preserved segment when no split is required: RED c39d7f667bd0ff985239dc74594a80346fad2a3c, wiring 13e98f047bc6f4cc18ab0de556981fac20e2e417, repair dabb5ba15497ddde9788bf98b230239e202df459 rejects the extra segment.
  • Exact-head inventory harness false negative: run 33392422398 / job 99488965687; repair 9d9ade3d2fa0d0d4fb9e5ad33ba2ef7813293cd5 requires both CONCURRENTLY and IF NOT EXISTS rather than weakening either property.
  • Current child eda9ef283996e65cf19ec250ae3aeec118001346 preserves unrelated sealed manifest evidence.

Broader tenant-context trust, exclusive write routing/future grant discipline, production runtime EXECUTE provisioning, provisional migration numbering, deployment-runner ownership and #282 authoritative clock provenance remain distinct controls.

Exact-current-head evidence

Exact current child head remains eda9ef283996e65cf19ec250ae3aeec118001346. This child is still based on a stale #96 snapshot and conflicting/non-mergeable. Earlier hosted evidence belongs to predecessor heads and does not transfer. Reacquire exact-head evidence only after normal #96 protected integration and non-force child adoption rather than churning this stale descendant now.

Do not merge while #96 is unintegrated, this child conflicts with its advanced parent, exact-current-head hosted evidence is absent/non-passing, or unresolved security/deployment/clock-provenance controls remain. Do not self-approve, use routine administrator bypass, weaken a gate, manufacture evidence, or directly modify a dedicated-writer dependency.

@coderabbitai

coderabbitai Bot commented Aug 25, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Team

Run ID: 05dd92f5-4776-401e-9a56-381ed00483cc

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@seonghobae
seonghobae marked this pull request as ready for review August 25, 2026 23:30
devin-ai-integration[bot]

This comment was marked as resolved.

devin-ai-integration[bot]

This comment was marked as resolved.

devin-ai-integration[bot]

This comment was marked as resolved.

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note

This report is out of date. Scroll down for Devin Review's latest report on this PR.

Devin Review found 7 new potential issues.

Devin Review

Comment thread database/migrations/0027_organization_hierarchy_change_application.sql Outdated
Comment thread database/migrations/0027_organization_hierarchy_change_application.sql Outdated
Comment on lines +805 to +808
CREATE POLICY organization_hierarchy_change_application_scope_policy
ON organization_hierarchy_change_application_record
USING (tenant_record_id = current_tenant_record_id())
WITH CHECK (tenant_record_id = current_tenant_record_id());

@devin-ai-integration devin-ai-integration Bot Aug 29, 2026

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟥 Caller-controlled tenant context bypasses isolation

Any table-capable role can set orgmetra.tenant_record_id to another tenant. The RLS policy then grants that tenant's row access.

Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note

This report is out of date. Scroll down for Devin Review's latest report on this PR.

Devin Review found 5 new potential issues.

Devin Review

Comment on lines +692 to +697
PERFORM pg_catalog.pg_advisory_xact_lock(
pg_catalog.hashtextextended(
'orgmetra_organization_hierarchy:' || p_tenant_record_id::text,
0
)
);

@devin-ai-integration devin-ai-integration Bot Aug 29, 2026

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔍 Serialization depends on exclusive write routing

The advisory lock coordinates only apply_organization_hierarchy_change callers. Deployment privileges must prevent direct hierarchy writes from bypassing its graph serialization.

Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

Comment on lines +1003 to +1008
ALTER TABLE organization_hierarchy_change_application_record ENABLE ROW LEVEL SECURITY;
ALTER TABLE organization_hierarchy_change_application_record FORCE ROW LEVEL SECURITY;
CREATE POLICY organization_hierarchy_change_application_scope_policy
ON organization_hierarchy_change_application_record
USING (tenant_record_id = current_tenant_record_id())
WITH CHECK (tenant_record_id = current_tenant_record_id());

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔍 Evidence table grants need discipline

The migration revokes public function execution, not table insertion. Future grants must keep direct evidence writes unavailable to routine roles.

Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

devin-ai-integration[bot]

This comment was marked as resolved.

Copy link
Copy Markdown
Contributor Author

Parent repair receipt: #96 has now ordinary-merged current protected develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f into its existing history and advanced to exact 54dd31bc240624a3fdb05f6df217eeaad1f92709 without force-push/destructive rebase. The obsolete hierarchy-review leaf workflow was retired under protected #161; its exact installed-wheel/CPython 3.14.7/100%-coverage contract now runs from canonical Foundation CI with a repository regression preventing leaf resurrection.

#119 remains intentionally unchanged and Draft. Its base snapshot b9f8e3d… is stale relative to the repaired parent and must not be low-level restacked while #96 is still mutable. After #96 reaches fresh exact-head gates and normal protected integration, non-force adopt that protected result, then reconcile the migration/evidence delta and rerun exact-current-head gates. No predecessor/parent check or review evidence transfers.

Copy link
Copy Markdown
Contributor Author

Fresh parent-authority correction for this descendant: #96 is no longer at the body-recorded 6a8454ff... / old protected parent. Live #96 is exact 54dd31bc240624a3fdb05f6df217eeaad1f92709, direct base develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f, open · Draft · mechanically mergeable, with Foundation and SAST terminal SUCCESS and central Security/CodeQL gates still non-passing.

This #119 head remains eda9ef283996e65cf19ec250ae3aeec118001346 on stale child base b9f8e3d291c4bdcd2f0aa5f9d0378dea09e5e7cd and GitHub still reports non-mergeable. Do not restack it onto mutable #96 now and do not copy #96 source. Preserve the child delta; after #96 normally reaches protected develop, non-force adopt that protected result, reconcile provisional migration numbering/intervening #161 truth, reseal changed artifacts, and reacquire exact-head evidence. #274/#275 Position extraction remains downstream of that protected integration order.

Copy link
Copy Markdown
Contributor Author

Live parent-authority correction: #96 is no longer 6a8454ff... on develop@9e3e.... Fresh 2026-09-08 state is #96 exact 54dd31bc240624a3fdb05f6df217eeaad1f92709, direct from protected develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f, open · Draft · mechanically mergeable. Its exact-head Foundation 34151005914 and SAST 34151005850 are SUCCESS; Security 34151005865 and CodeQL 34151005886 remain terminal central-owner failures, so #96 is not protected truth yet. This child stays exact eda9ef283996e65cf19ec250ae3aeec118001346, Draft and conflicting on stale parent b9f8e3d.... Do not restack it onto mutable #96. Preserve the existing delta; after #96 normally integrates, ordinary/non-force adopt the protected result, reconcile provisional migration numbers/manifests, and obtain fresh exact-head evidence. This comment supersedes the stale parent snapshot in the PR body; no source or ref was changed.

Copy link
Copy Markdown
Contributor Author

Fresh parent-authority correction for the stacked child; source/commit graph is intentionally unchanged.

Parent #96 remains exact 0262d70eaac37e2ab4096c67894a0bae71a4b1d2 on protected develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f, Draft and mechanically mergeable. The body sentence saying the parent Foundation/Security/model-backed workflows are all still nonterminal is now stale. Current exact-parent evidence is:

  • Foundation 34369393258 / repository-quality 102526382630: SUCCESS
  • SAST 34369393198: SUCCESS
  • OpenCode 102527871752: SUCCESS
  • Noema 102527471651: SUCCESS
  • Security 34369393189: FAILURE only at dependency-review support establishment (102526931585); canonical availability owner .github#810, fresh canary 5604514013
  • CodeQL 34369393184: FAILURE because Actions/Python consumers settle before authoritative dispatch starts; canonical settlement owner .github#2040, fresh canary 5604510396
  • Strix 34369390074 / 102527232339: still genuinely IN PROGRESS in Run Strix (quick) after successful CO-sidecar/install/input preparation
  • no qualifying independent APPROVED review; all visible feat(core): add governed Organization hierarchy-change review #96 inline threads are resolved

The child remains exact eda9ef283996e65cf19ec250ae3aeec118001346, based on stale parent b9f8e3d291c4bdcd2f0aa5f9d0378dea09e5e7cd, Draft and conflicting/non-mergeable. Preserve the existing valid application/migration delta. Do not copy mutable parent source or destructively rebase. Normal order remains #96 protected integration -> child non-force adoption of resulting develop -> reconcile/renumber/reseal as required -> reacquire exact-head PostgreSQL/security/review evidence. #282 authoritative transaction/audit clock provenance and #283 durable-vs-process-local integrity split remain child acceptance requirements.

Copy link
Copy Markdown
Contributor Author

Parent-authority update after #284.

Canonical #96 has advanced ordinarily to fc3c5111c2a6a4b9bef15954c483126dcd771def on protected develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f. New #284 is distinct from #283: #283 hides mutable issuance-registry handles; #284 binds the creation/export/public evidence SHA-256 verifier inside the private packet runtime so later mutation of the module-level sha256 name cannot forge changed live evidence. Test-only RED 0b9144dc... → Foundation 34381041056/102565671738 installed-artifact failure; causal source repair 5605e209...; ADR/TRACEABILITY/README/package CHANGELOG descendant fc3c511....

This does not move durable authority into the leaf. #119 still owns tenant-qualified persistence uniqueness, authoritative hierarchy re-resolution/mutation, transaction concurrency, authoritative system-recorded audit/outbox time, and immutable persistence. Keep the child graph unchanged while #96 is unintegrated: current #119 eda9ef283996e65cf19ec250ae3aeec118001346 remains Draft/conflicting on stale parent b9f8e3d.... Required order remains #96 normal protected integration → adopt resulting develop non-force → reconcile existing #119 delta/migration numbering/evidence → reacquire exact-head PostgreSQL/security/review gates. No mutable-parent source copying or destructive restack now.

Copy link
Copy Markdown
Contributor Author

Current parent-authority correction after fresh #96 evidence sweep:

  • canonical parent feat(core): add governed Organization hierarchy-change review #96 is now exact fc3c5111c2a6a4b9bef15954c483126dcd771def, still open · Draft · mechanically mergeable on protected develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f
  • exact parent Foundation/SAST/OpenCode/merge-scheduler/Noema are terminal SUCCESS
  • Security remains the central .github#810 public Dependency Review HTTP-403 availability RED
  • CodeQL remains the central .github#2040 producer/consumer settlement-ordering RED
  • Strix 34381793320/102568747529 is mechanically SUCCESS, but immutable artifact 10116773992 is non-authorizing under central .github#891: zero-result SARIF, generic/template 307-byte report, and no machine-readable repository/PR/head/base/scope receipt. Current #891 canary comment: 5606595426.
  • fresh formal review still has no qualifying independent APPROVED; visible inline threads are resolved.

The child graph itself is unchanged: eda9ef283996e65cf19ec250ae3aeec118001346 remains Draft/conflicting on stale parent b9f8e3d291c4bdcd2f0aa5f9d0378dea09e5e7cd. Do not copy or restack against mutable #96. Preserve the existing valid #119 delta and keep the order #96 normal protected integration -> resulting develop non-force adoption -> reconcile/renumber/reseal #119 -> reacquire exact-head PostgreSQL/security/review evidence, including #282 authoritative transaction/audit clock provenance.

Copy link
Copy Markdown
Contributor Author

Fresh parent handoff: #96 has advanced by ordinary forward commits through #285. Current parent exact head is caab072f0de0508e949788725986077efb1aa7f2 on protected develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f; the child graph remains intentionally unchanged at eda9ef283996e65cf19ec250ae3aeec118001346 on stale parent b9f8e3d291c4bdcd2f0aa5f9d0378dea09e5e7cd.

#285 closes a leaf process-local export capability gap: post-issuance canonical_json() no longer selects mutable module payload/serializer helpers as evidence authority. The private runtime retains exact issuance canonical bytes and exact issuance field state, captures direct retained-slot state once at export, compares exact type/value against issuance state, verifies stored bytes with the runtime-bound digest implementation, and only then returns those issuance bytes. This does not move durable mutation/persistence responsibilities: #119 still owns authoritative same-tenant re-resolution, transaction concurrency, durable uniqueness, system/database audit time, immutable audit/outbox persistence and restart/distributed authority.

Do not restack onto mutable #96 source. Preserve the existing order: #96 normal protected integration → non-force adopt resulting develop → reconcile the existing #119 delta/migration numbering/evidence → reacquire exact-head PostgreSQL/security/review gates.

Copy link
Copy Markdown
Contributor Author

Parent #96 advanced ordinary-forward to ff16a08dc035faf05dc1b921e947b1cf82cfb36e while remaining open/Draft and direct-based on protected develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f. New #286 is a leaf issuance-authority repair: hosted RED a0e616c68d5e194ecdb06089c6d83d8074fad833 proved module replacement of _validate_issuance_snapshot could bypass mandatory requester/reviewer separation (34395501352/102614084636, 1 failed/66 passed, 100% production coverage); causal repair b48df4d71121387240ab23b9d475b0cce2b1f15e binds that top-level validator at packet-runtime construction, and current ff16a08... carries ADR/TRACEABILITY/README/CHANGELOG doctoring. This does not move durable authority into the leaf: #119 still owns same-tenant authoritative re-resolution, hierarchy mutation/concurrency, durable uniqueness, system audit time and immutable audit/outbox. Do not restack onto mutable #96 now. Preserve the existing child delta and continue the established order: normal #96 protected integration → non-force adopt resulting develop → reconcile migrations/evidence → reacquire exact-head PostgreSQL/security/review gates.

seonghobae commented Sep 9, 2026

Copy link
Copy Markdown
Contributor Author

Fresh parent-authority handoff from #96/#287. The #96 branch advanced ordinary-forward through test-first bba6374d... / 497a75b..., initial direct-helper repair bf371184..., follow-up live-reference constructor regression 24cd7668..., minimal constructor-binding repair bb32b719..., and code-current ADR/TRACEABILITY/README/CHANGELOG descendant 6e5784b77e4dc00f15fd6e072dc61babd85d5910. The repaired leaf invariant binds the direct issuance _snapshot, _payload_from_snapshot, _canonical_payload_json, and _LiveReferenceBinding selections at packet-runtime construction so semantic validation/sealing and the still-live digest-conflict guard cannot be redirected by later ordinary module reassignment. This does not transfer durable hierarchy mutation, same-tenant re-resolution, concurrency, authoritative system time, distributed authorization, or immutable audit/outbox ownership from #119. Preserve the existing integration order: do not restack #119 onto mutable #96; after #96 integrates normally into protected develop, non-force adopt that resulting protected parent, reconcile the existing valid #119 delta/migration numbering/evidence, then reacquire exact-head PostgreSQL/security/review acceptance.

Copy link
Copy Markdown
Contributor Author

Parent authority advanced ordinary-forward for #288. Current #96 head is 24c48b14ed03a28e9af7982549ff5e7f996468fb on unchanged protected develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f.

#288 closes only the process-local public-builder constructor-binding gap: both package-root and implementation-module builder paths retain the governed packet constructor selected at package import even if the later implementation-module class name is reassigned. It does not move durable tenant-qualified uniqueness, authoritative hierarchy re-resolution/concurrency, system-clock provenance, or immutable audit/outbox responsibility out of #119.

Keep this child on its existing stale graph while #96 remains unintegrated. Required order is unchanged: normal #96 protected integration -> non-force adoption of resulting protected develop -> reconcile this child’s valid delta/migration numbering -> reacquire PostgreSQL/security/review evidence. Current #96 exact-head workflows are nonterminal, so no parent GREEN or merge authorization transfers.

Copy link
Copy Markdown
Contributor Author

Fresh parent handoff: #96 advanced by ordinary forward commit to exact 28b050bd131e5aacdbf50ed35da5e3ec7615ec9f on protected develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f. #288 now includes an executable exact-head Foundation RED/RCA from predecessor 24c48b14...: 73/73 hierarchy-review tests passed but the 100% owned-coverage gate failed at 99.70% because the obsolete plain implementation-module builder remained as dead/shadow production code. 28b050bd... removes only that duplicate; the governed closure in package __init__.py remains the single builder and is still published at both public paths. Exact 28b050... Foundation 34421894293 is nonterminal, so no GREEN transfers yet.

Do not restack this child while #96 remains mutable. Preserve the existing child eda9ef283996e65cf19ec250ae3aeec118001346 and its valid PostgreSQL/migration delta. Required order remains: normal #96 protected integration → non-force adoption of the resulting develop → reconcile existing child/migration numbering and #282 authoritative clock boundary → reacquire exact-head PostgreSQL/security/review evidence.

Copy link
Copy Markdown
Contributor Author

Fresh parent handoff: #96 has advanced ordinary-forward to exact 20e9ab4e2c843089e078e92c028720581b57ea9b on the same protected develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f base. New #289 proves that merely capturing _validate_issuance_snapshot was insufficient while its source-module dependencies remained late-bound: exact predecessor 28b050bd... accepted and sealed organization_unit:not-a-uuid after ordinary reassignment of review._validate_reference. The parent repair binds those validation/canonicalization authorities before later module reassignment. This remains leaf process-local defense only; durable same-tenant re-resolution, uniqueness/concurrency, authoritative application/audit time, and immutable mutation/audit/outbox persistence remain here in #119.

Do not restack this child onto mutable #96. Preserve current child eda9ef283996e65cf19ec250ae3aeec118001346 and its valid migrations/delta. After #96 normally integrates into protected develop, non-force adopt that protected result, reconcile migration numbering/evidence, then reacquire exact-head PostgreSQL/security/review gates. The previous body statement that parent 28b050bd... Foundation was nonterminal is now historical: run 34421894293, job 102698923237, completed SUCCESS on that predecessor, but it does not transfer to current #96 head.

seonghobae commented Sep 10, 2026

Copy link
Copy Markdown
Contributor Author

Parent-authority correction only; no child source restack performed. Parent #96 remains exact f2c6e70edcf5c62ae0f848c29efd7bd3b8d45b97 on protected develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f. Current-head Foundation 34441833963/102758308481 and SAST 34441834059 are SUCCESS. Security 34441833987 is FAILURE only at the central Dependency Review HTTP-403 availability boundary; CodeQL 34441833995 is non-passing because both compatibility consumers have failed while its dispatch job remains queued. Noema/Strix remain in progress. #96 therefore stays Draft and is not protected-integration-ready; no qualifying independent approval exists.

This does not change #119’s stack rule. Current child eda9ef283996e65cf19ec250ae3aeec118001346 still records stale parent b9f8e3d291c4bdcd2f0aa5f9d0378dea09e5e7cd and is Draft/conflicting. Preserve its valid migration/application delta unchanged until #96 integrates normally; then non-force adopt resulting protected develop, reconcile provisional migration numbering/evidence, and reacquire exact-head PostgreSQL/security/review gates. #291 remains leaf representation integrity only; authoritative system/audit time, durable hierarchy concurrency, audit/outbox and mutation authority remain here.

Copy link
Copy Markdown
Contributor Author

Parent-authority correction for the current stack. Parent #96 remains exact f2c6e70edcf5c62ae0f848c29efd7bd3b8d45b97 on protected develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f, open · Draft · mechanically mergeable. The older body sentence saying its Foundation/Security/SAST/CodeQL are queued/pending is now historical.

Current exact-parent evidence is: Foundation 34441833963/102758308481 SUCCESS; SAST 34441834059 SUCCESS; Noema 34441832326 SUCCESS; Security 34441833987 FAILURE only at the fail-closed Dependency Review public-comparison HTTP 403 owned by .github#810; CodeQL 34441833995 FAILURE in both consumers before the same-run dispatch job 102763941196 later started and completed SUCCESS, owned by .github#2040.

Required Strix 34441832410/102760977777 is terminal workflow/job SUCCESS, but its exact artifact 10139235414 (sha256:c56b080f7357b5e9187f2d5d55396f61bbaa223e0e1cd27ea5acfe0fccde8c3e) is not admissible no-finding evidence. The report regressed to a 437-byte generic No vulnerabilities were found template; empty SARIF/run.json lack the repository + PR + exact-head + live-base + materialized-scope/content + report/SARIF/finding-set terminal receipt required by .github#891. Current canary: .github#891 comment 5614504202; implementation handoff: .github#1563 comment 5614507024.

This does not change child ownership or justify mutable-parent restacking. #119 remains exact eda9ef283996e65cf19ec250ae3aeec118001346, Draft, conflicting against stale recorded parent b9f8e3d291c4bdcd2f0aa5f9d0378dea09e5e7cd. Preserve its valid migration/application delta. Required order remains #96 normal protected integration -> non-force adoption of resulting protected develop -> reconcile existing #119 delta/migration numbering/provenance -> reacquire PostgreSQL/security/review evidence.

Copy link
Copy Markdown
Contributor Author

Current-parent authority correction without source restack: parent #96 remains exact f2c6e70edcf5c62ae0f848c29efd7bd3b8d45b97 on protected develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f, but the PR body paragraph that still calls its Foundation/Security/SAST/CodeQL generation queued/pending is historical and no longer current.

Fresh exact-parent state is: Foundation 34441833963/102758308481 SUCCESS; SAST 34441834059 SUCCESS; Noema 34441832326/102761043453 SUCCESS; Security 34441833987 FAILURE on canonical .github#810 Dependency Review HTTP-403 availability; CodeQL 34441833995 FAILURE on canonical .github#2040 producer/consumer settlement ordering; Strix 34441832410/102760977777 workflow SUCCESS but its terminal template/no-finding artifact remains non-authorizing under .github#891 because authoritative exact-head/live-base/scope/finding-set receipt evidence is absent. Fresh #96 reviews remain COMMENTED-only with all visible inline threads resolved and no qualifying independent APPROVED review.

This does not change the child graph. #119 remains exact eda9ef283996e65cf19ec250ae3aeec118001346, Draft and conflicting on stale parent snapshot b9f8e3d291c4bdcd2f0aa5f9d0378dea09e5e7cd. Preserve all existing migration/application delta. Do not rebase onto mutable #96. Required order remains: normal #96 protected integration → non-force adoption of the resulting protected develop → reconcile existing #119 migrations/application evidence (including provisional numbering if protected truth requires it) → reacquire PostgreSQL/security/review evidence on the then-current child head.

Copy link
Copy Markdown
Contributor Author

Fresh authority correction: the opening parent snapshot in this PR body that still describes #96@f2c6e70... Foundation/Security/SAST/CodeQL as queued/pending is historical and must not be treated as current evidence. Fresh #96 remains exact f2c6e70edcf5c62ae0f848c29efd7bd3b8d45b97, Draft and mechanically mergeable on protected develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f. Its current exact-head Foundation, SAST and Noema are SUCCESS; Security is non-passing at the central Dependency Review 403 lane, CodeQL is non-passing at central producer/consumer ordering, and Strix workflow success is not admissible no-finding authority because the exact-head artifact is the hollow/template class already handed to .github#891/#1563. There is still no qualifying independent approval.

This does not authorize restacking this child. #119 remains exact eda9ef283996e65cf19ec250ae3aeec118001346, Draft/conflicting on stale parent b9f8e3d291c4bdcd2f0aa5f9d0378dea09e5e7cd. Preserve the existing child delta and wait for normal #96 protected integration; then non-force adopt the resulting protected develop, reconcile migrations/evidence, and reacquire all exact-current-head PostgreSQL/security/review gates. No destructive rebase, force push, predecessor evidence transfer, self-approval, or administrator bypass.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant