docs: reconcile canonical protected product truth - #51
Conversation
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
📝 WalkthroughWalkthroughFoundation CI와 매니페스트 검증 기준을 보호된 Changes보호된 develop 통합 기준
Estimated code review effort: 3 (Moderate) | ~25 minutes Merge Risk: 🟡 Moderate · up to The PR changes buyer-facing and contract documentation, but the current tree is still described as marking People mutation and confirmed-hire materialization as protected/shipped rather than active-PR and non-shipped. If merged as-is, users and release records could be told these paths are available when they are not, so merge should wait for the documentation and checks to agree. Suggested reviewers: 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
@opencode-agent Please independently review exact current head |
|
@coderabbitai review |
|
|
@opencode-agent Please independently review exact current head |
|
@opencode-agent Please independently review exact current head |
|
@opencode-agent Please independently review exact current head |
|
@opencode-agent Please independently review exact current head |
|
Current owner-path doctoring for #181: fresh protected truth is |
|
Docs/release-truth handoff from People owner #64/#266: the direct confirmed-hire PostgreSQL adapter had a checked-command/used-command TOCTOU because it authorized a caller-owned frozen |
Adopt protected develop without rewriting history. Preserve the protected repository-quality consolidation and deleted leaf workflows while retaining the non-overlapping canonical protected-truth delta from #51. Semantic overlap is intentionally resolved to protected truth in this merge commit and repaired forward in follow-up commits. Signed-off-by: Seongho Bae <me@seonghobae.me>
Add the executable RED contract for Issue #181 before changing consumer guidance. The test requires AGENTS/CLAUDE/TRD/security/traceability to agree on released contextual-orchestrator, orchestrator/free, gateway authentication, and fail-closed provider-independent routing. Signed-off-by: Seongho Bae <me@seonghobae.me>
Run the Issue #181 governance regression in the canonical Foundation validation command so direct-provider guidance is a real RED rather than documentation-only intent. Signed-off-by: Seongho Bae <me@seonghobae.me>
Satisfy the first Issue #181 RED by making released contextual-orchestrator the only Orgmetra model-routing authority. GitHub Actions use orchestrator/free through gateway authentication; provider credentials, provider/model/group selection, and paid fallback remain outside the Orgmetra consumer boundary. Signed-off-by: Seongho Bae <me@seonghobae.me>
Keep provider discovery, routing and termination semantics in released contextual-orchestrator and make orchestrator/free plus gateway authentication the only model-backed GitHub Actions consumer path. Signed-off-by: Seongho Bae <me@seonghobae.me>
Make the released contextual-orchestrator contract the sole model-backed consumer path, require orchestrator/free plus gateway authentication, and keep provider routing and termination semantics in the owner service. Signed-off-by: Seongho Bae <me@seonghobae.me>
Record contextual-orchestrator as the sole model-routing trust boundary and require orchestrator/free plus gateway authentication while failing closed on missing owner capabilities. Signed-off-by: Seongho Bae <me@seonghobae.me>
Record Issue #181 as an explicit consumer/owner contract with executable evidence, orchestrator/free gateway routing, no provider credentials or paid fallback, and fail-closed owner repair. Signed-off-by: Seongho Bae <me@seonghobae.me>
Exercise the root guidance and the Issue #181 traceability record directly while keeping the larger product traceability matrix focused on shipped capability maturity. Signed-off-by: Seongho Bae <me@seonghobae.me>
Preserve the protected foundation-ci verification introduced after #51 branched while restoring ADR 0011's shipped protected-develop status. Signed-off-by: Seongho Bae <me@seonghobae.me>
Keep the consolidated Foundation CI verification while restoring ADR 0012 as shipped protected-develop architecture truth. Signed-off-by: Seongho Bae <me@seonghobae.me>
Keep the protected consolidated Foundation CI evidence while restoring the capability's integrated protected-develop maturity. Signed-off-by: Seongho Bae <me@seonghobae.me>
Preserve the consolidated Foundation CI verification while restoring the intent adapter's protected-develop maturity and foreign-owner execution boundary. Signed-off-by: Seongho Bae <me@seonghobae.me>
Keep the consolidated Foundation CI gate while restoring the governed requisition review packet's protected-develop maturity. Signed-off-by: Seongho Bae <me@seonghobae.me>
Remove the stale protected SHA/active-PR note, preserve the workflow-consolidation release note, promote already integrated Job Analysis and selection-review capability, and record the Issue #181 contextual-orchestrator governance repair. Signed-off-by: Seongho Bae <me@seonghobae.me>
Preserve #51's ADR 0017/0025 inventory and explicit non-canonical ADR-status rejection while retaining the protected workflow consolidation and keeping deleted leaf workflows deleted. Add the Issue #181 regression and traceability artifacts to the same durable inventory. Signed-off-by: Seongho Bae <me@seonghobae.me>
|
Protected-truth documentation handoff from #64/#315: current Required traceability facts: |
Problem
Canonical buyer-facing repository truth drifted behind protected
develop. This PR remains the canonical single-writer lane for protected-truth documentation, ADR/index consistency, deterministic manifest provenance, and Issue #181 model-routing governance.Live authority
Protected authority is
develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f. This branch is an ordinary-forward direct descendant of that protected head and is mechanically mergeable. Current exact head is59993759523b9164ca098af55f05f5bdb3866298; the PR remains Draft because two current-head required central gates are RED and no qualifying independent approval exists.The branch preserves protected repository-quality consolidation (single Foundation lane, superseded leaf workflows deleted, protected traceability) together with this lane's protected-maturity/ADR-index/status and model-routing corrections. No force-push, destructive rebase, recreated leaf workflow, predecessor-evidence transfer, self-approval, or routine bypass was used.
Issue #181 governance repair
AGENTS.md,CLAUDE.md,docs/TRD.md,docs/SECURITY.md, anddocs/traceability/contextual-orchestrator-routing.mdagree that model-backed product and GitHub Actions behavior consumes a released Contextual Orchestrator contract. GitHub Actions useorchestrator/freethrough the approved gateway token; Orgmetra does not require direct provider credentials, hard-code provider/model/group selection, or select a paid fallback. Missing capability fails closed and is repaired at the Contextual Orchestrator owner. Provider discovery/routing, timeout defaults, user cancellation, provider-end, and administrator-timeout semantics remain CO-owned.tests/model-routing-governance.test.mjs, dispatcher inventory, and the Foundation validator make this contract executable rather than prose-only.Causal RED → repair chain
Exact predecessor
2dd16cf7b6eafa1c09fc707477b310bd054f4323failed Foundation run34268916070because the integrity manifest lacked the protected-target provenance contract. The failure job emitted deterministic--print-manifestoutput for the same checkout.b600ce7ac265043988260aaf23455a9aa93bf020applied that exact reseal: removed stalegenerated_for_branch, setcanonical_target_branch: develop, registered newly required ADR/routing/model-governance artifacts, and refreshed sha256/bytes/lines without weakening validation.Exact
b600ce7...then reached the Node contracts and exposed a separate buyer-truth RED:CHANGELOG.mddid not state the protected Job Analysis and People-mutation runtime maturity required by the already protected implementation and traceability.50dcae641ff1504f9cb263601e495dcd4979c94dcorrected only those buyer-facing maturity statements.That source correction intentionally invalidated the manifest fingerprint. The next Foundation run failed only on the changed
CHANGELOG.mdfingerprint and emitted its exact replacement metadata.59993759523b9164ca098af55f05f5bdb3866298applied that exact final reseal.Exact-head evidence
For
59993759523b9164ca098af55f05f5bdb3866298:34270638801: SUCCESS.34270638885: SUCCESS.34270636017: SUCCESS;opencode-reviewjob102211166630is SUCCESS.34270636044: SUCCESS; queue job102211043034is SUCCESS.34270636005: SUCCESS.34270636062: SUCCESS.34270638859: FAILURE only at dependency-review job102211144271; exact checkout was correct, but the public non-fork dependency comparison endpoint returned HTTP 403. This matches central availability incidentContextualWisdomLab/.github#810; OSV/Trivy/Scorecard successes are not substituted for authoritative Dependency Review evidence.34270639102: FAILURE. Both compatibility consumers read a pending verdict and failed beforeDispatch current-head CodeQL scancompleted successfully. Canonical combined central repairContextualWisdomLab/.github#2040remains open at exact6706c231ab06a3c91c43fdb5b989cfcd79fff593; its own exact CodeQL run34251822255is still terminal FAILURE while its Security, SAST, Python Security and Agent Review Runtime Quality runs are terminal SUCCESS. No no-op rerun, sleep/poll workaround, synthetic status, or predecessor verdict transfer is used.APPROVEDreview. Every returned review thread is resolved; historical comments do not substitute for the required independent approval.Predecessor GREEN/RED remains RCA history only and is never transferred to this exact head.
Merge boundary
Normal merge only after this unchanged exact head satisfies protected rules, central Dependency Review and CodeQL owner repairs have produced valid exact-head evidence, and a qualifying independent approval exists. Strix/Noema are already terminal GREEN on this exact head and are no longer blockers. Mechanical mergeability is not acceptance evidence. No administrator bypass, gate weakening, no-op retrigger, force-push, destructive rebase, mutable foreign-owner source copy, or simple Close is permitted.