Skip to content

docs: reconcile canonical protected product truth - #51

Draft
seonghobae wants to merge 111 commits into
developfrom
docs/protected-truth-refresh
Draft

docs: reconcile canonical protected product truth#51
seonghobae wants to merge 111 commits into
developfrom
docs/protected-truth-refresh

Conversation

@seonghobae

@seonghobae seonghobae commented Aug 20, 2026

Copy link
Copy Markdown
Contributor

Problem

Canonical buyer-facing repository truth drifted behind protected develop. This PR remains the canonical single-writer lane for protected-truth documentation, ADR/index consistency, deterministic manifest provenance, and Issue #181 model-routing governance.

Live authority

Protected authority is develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f. This branch is an ordinary-forward direct descendant of that protected head and is mechanically mergeable. Current exact head is 59993759523b9164ca098af55f05f5bdb3866298; the PR remains Draft because two current-head required central gates are RED and no qualifying independent approval exists.

The branch preserves protected repository-quality consolidation (single Foundation lane, superseded leaf workflows deleted, protected traceability) together with this lane's protected-maturity/ADR-index/status and model-routing corrections. No force-push, destructive rebase, recreated leaf workflow, predecessor-evidence transfer, self-approval, or routine bypass was used.

Issue #181 governance repair

AGENTS.md, CLAUDE.md, docs/TRD.md, docs/SECURITY.md, and docs/traceability/contextual-orchestrator-routing.md agree that model-backed product and GitHub Actions behavior consumes a released Contextual Orchestrator contract. GitHub Actions use orchestrator/free through the approved gateway token; Orgmetra does not require direct provider credentials, hard-code provider/model/group selection, or select a paid fallback. Missing capability fails closed and is repaired at the Contextual Orchestrator owner. Provider discovery/routing, timeout defaults, user cancellation, provider-end, and administrator-timeout semantics remain CO-owned.

tests/model-routing-governance.test.mjs, dispatcher inventory, and the Foundation validator make this contract executable rather than prose-only.

Causal RED → repair chain

  1. Exact predecessor 2dd16cf7b6eafa1c09fc707477b310bd054f4323 failed Foundation run 34268916070 because the integrity manifest lacked the protected-target provenance contract. The failure job emitted deterministic --print-manifest output for the same checkout. b600ce7ac265043988260aaf23455a9aa93bf020 applied that exact reseal: removed stale generated_for_branch, set canonical_target_branch: develop, registered newly required ADR/routing/model-governance artifacts, and refreshed sha256/bytes/lines without weakening validation.

  2. Exact b600ce7... then reached the Node contracts and exposed a separate buyer-truth RED: CHANGELOG.md did not state the protected Job Analysis and People-mutation runtime maturity required by the already protected implementation and traceability. 50dcae641ff1504f9cb263601e495dcd4979c94d corrected only those buyer-facing maturity statements.

  3. That source correction intentionally invalidated the manifest fingerprint. The next Foundation run failed only on the changed CHANGELOG.md fingerprint and emitted its exact replacement metadata. 59993759523b9164ca098af55f05f5bdb3866298 applied that exact final reseal.

Exact-head evidence

For 59993759523b9164ca098af55f05f5bdb3866298:

  • Foundation CI 34270638801: SUCCESS.
  • SAST Semgrep 34270638885: SUCCESS.
  • Required OpenCode run 34270636017: SUCCESS; opencode-review job 102211166630 is SUCCESS.
  • Required merge scheduler run 34270636044: SUCCESS; queue job 102211043034 is SUCCESS.
  • Required Strix run 34270636005: SUCCESS.
  • Required Noema run 34270636062: SUCCESS.
  • Security Scan 34270638859: FAILURE only at dependency-review job 102211144271; exact checkout was correct, but the public non-fork dependency comparison endpoint returned HTTP 403. This matches central availability incident ContextualWisdomLab/.github#810; OSV/Trivy/Scorecard successes are not substituted for authoritative Dependency Review evidence.
  • CodeQL PR 34270639102: FAILURE. Both compatibility consumers read a pending verdict and failed before Dispatch current-head CodeQL scan completed successfully. Canonical combined central repair ContextualWisdomLab/.github#2040 remains open at exact 6706c231ab06a3c91c43fdb5b989cfcd79fff593; its own exact CodeQL run 34251822255 is still terminal FAILURE while its Security, SAST, Python Security and Agent Review Runtime Quality runs are terminal SUCCESS. No no-op rerun, sleep/poll workaround, synthetic status, or predecessor verdict transfer is used.
  • Fresh review enumeration has no APPROVED review. Every returned review thread is resolved; historical comments do not substitute for the required independent approval.

Predecessor GREEN/RED remains RCA history only and is never transferred to this exact head.

Merge boundary

Normal merge only after this unchanged exact head satisfies protected rules, central Dependency Review and CodeQL owner repairs have produced valid exact-head evidence, and a qualifying independent approval exists. Strix/Noema are already terminal GREEN on this exact head and are no longer blockers. Mechanical mergeability is not acceptance evidence. No administrator bypass, gate weakening, no-op retrigger, force-push, destructive rebase, mutable foreign-owner source copy, or simple Close is permitted.

@coderabbitai

coderabbitai Bot commented Aug 20, 2026

Copy link
Copy Markdown

Review Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

Foundation CI와 매니페스트 검증 기준을 보호된 develop으로 변경했습니다. README, CHANGELOG, 추적성 문서와 ADR 상태를 갱신했습니다. 문서 상태, People API 범위, 보호된 기준과 테스트 인벤토리를 검증하는 계약 테스트를 강화했습니다.

Changes

보호된 develop 통합 기준

Layer / File(s) Summary
브랜치 및 매니페스트 계약
.github/workflows/foundation-ci.yml, manifest.json, tests/validate_repository.py, scripts/foundation-contract-core.mjs
CI 트리거와 매니페스트의 canonical 보호 브랜치 기준을 develop으로 변경했습니다. 필수 테스트와 매니페스트 검증 규칙을 갱신했습니다.
제품 진실 및 문서 상태
README.md, CHANGELOG.md, docs/TRACEABILITY.md, docs/adr/*
보호된 develop에 통합된 기능과 People API 범위를 문서화했습니다. 추적성 성숙도와 ADR 상태 및 색인을 갱신했습니다.
저장소 진실 검증
tests/foundation-contract.test.mjs, tests/openapi-contract.test.mjs, tests/protected-truth-contract.test.mjs, tests/dispatcher-inventory.test.mjs, package.json
README, CHANGELOG, 추적성 문서, People mutation 범위와 테스트 인벤토리를 검증하도록 계약 테스트와 validate 스크립트를 확장했습니다.

Estimated code review effort: 3 (Moderate) | ~25 minutes

Merge Risk: 🟡 Moderate · up to 6f751

The PR changes buyer-facing and contract documentation, but the current tree is still described as marking People mutation and confirmed-hire materialization as protected/shipped rather than active-PR and non-shipped. If merged as-is, users and release records could be told these paths are available when they are not, so merge should wait for the documentation and checks to agree.

Suggested reviewers: cursoragent

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 50.00% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed 제목은 README, 추적성 문서, ADR, 변경 로그, CI 및 manifest를 보호된 develop 기준으로 정렬하는 PR의 주요 변경을 명확히 요약합니다.
  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch docs/protected-truth-refresh

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Copy link
Copy Markdown
Contributor Author

@opencode-agent Please independently review exact current head f07e77b1245d585f61f2bebce16234af243ec55e against live protected develop@ebad8c1c97337819754572c0b615ab78b4a9f3ca. Re-read the full current diff and current review-thread state; do not reuse predecessor-head evidence. Verify that canonical README/TRACEABILITY/ADR/CHANGELOG maturity now matches capabilities actually integrated on protected develop, that still-open People mutation/API behavior remains non-shipped, that the Naruon provider-execution owner boundary is not overclaimed, and that the added Foundation regression plus deterministic manifest preserve the existing fail-closed repository-integrity contract. Submit a formal independent APPROVE only if this unchanged exact head satisfies the live review standard; otherwise REQUEST_CHANGES with the narrowest source-backed actionable finding. Do not modify or merge the branch.

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Aug 20, 2026

Copy link
Copy Markdown
⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

Copy link
Copy Markdown
Contributor Author

@opencode-agent Please independently review exact current head 2d84c4496a05cc23ffd43c4613ddd3b6b6f22197 against live protected develop@ebad8c1c97337819754572c0b615ab78b4a9f3ca. Do not reuse predecessor-head evidence. Re-read the complete current diff and verify that protected-product maturity claims match capabilities actually integrated on develop, open People mutation/API behavior remains explicitly non-shipped, Naruon execution remains a read-only external owner boundary, deterministic manifest evidence remains exact, and the Foundation workflow now correctly follows protected develop rather than the historical feat/audit-outbox-envelope branch. Submit a formal independent APPROVE only if this unchanged head satisfies the live review contract; otherwise leave source-backed actionable findings tied to this exact SHA. Do not modify or merge the branch.

Copy link
Copy Markdown
Contributor Author

@opencode-agent Please independently review exact current head 78db91bd1785b6abfe7fadb7c1e0d37761a8a0d1 against protected develop@ebad8c1c97337819754572c0b615ab78b4a9f3ca. Re-read the current diff and repository truth rather than the stale head recorded in the PR body. Verify that README/TRACEABILITY/ADR/CHANGELOG maturity claims exactly match protected develop, that open-PR capabilities remain non-shipped, that Naruon/migration integration wording respects foreign-owner execution boundaries, and that the Foundation push-routing plus manifest hashes/bytes/lines are internally consistent. If this unchanged head satisfies the independent review standard, submit a formal APPROVE; otherwise leave only source-backed actionable findings tied to this exact head. Do not modify, merge, weaken gates, or rely on predecessor evidence.

Copy link
Copy Markdown
Contributor Author

@opencode-agent Please independently review exact current head e8599704420360137b0a6ce79098ce3f49e04915 against live protected develop@ebad8c1c97337819754572c0b615ab78b4a9f3ca. Do not reuse any predecessor-head review or status. Re-read the complete current diff and current thread state. In particular verify the newly repaired provenance boundary: tests/validate_repository.py must now fail closed unless the deterministic foundation manifest identifies protected develop, and manifest.json must bind that same branch plus the exact current validator artifact (sha256 a0fb4b967ec57625c2cfa9ef77b523e51879d6cebf611e6750311e4a4de731e1, 23501 bytes, 563 lines) without weakening existing path/digest/byte/line integrity checks. Also verify README/TRACEABILITY/ADR/CHANGELOG maturity remains truthful to protected develop, open People mutation/API behavior remains non-shipped, and Naruon/migration provider execution remains outside Orgmetra ownership. If this unchanged head satisfies the independent review standard after exact-head checks are considered, submit formal APPROVE; otherwise leave only source-backed actionable findings tied to this exact head. Do not modify, merge, or weaken gates.

Copy link
Copy Markdown
Contributor Author

@opencode-agent Please independently review exact current head e8599704420360137b0a6ce79098ce3f49e04915 against live develop@ebad8c1c97337819754572c0b615ab78b4a9f3ca; the prior request targeted predecessor f07e77b... and does not transfer. Re-read the full current diff and current review/thread state. Verify canonical README/TRACEABILITY/ADR/CHANGELOG maturity matches protected develop, open People mutation/API work remains non-shipped truth, Naruon/provider and migration owner boundaries are not overclaimed, Foundation push routing targets protected develop, and manifest/validator deterministic provenance identifies the same protected branch without weakening the existing integrity contract. Exact-head workflows currently exist but queued/pending evidence remains non-passing; do not approve until applicable exact-head gates are terminal GREEN. If the unchanged head then satisfies the live standard, submit formal independent APPROVE; otherwise leave the narrowest source-backed actionable finding.

Copy link
Copy Markdown
Contributor Author

Current owner-path doctoring for #181: fresh protected truth is develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f, while this canonical docs writer remains exact aa33f8f9f2a7c0a72c91947e3edac90334bcaabf with recorded predecessor base develop@9e3e4847510e1e612b48474ba42b177b8ed824df; GitHub now reports the PR non-mergeable. Protected AGENTS.md still directs model-backed/OpenCode paths to NVIDIA_NIM_API_KEY, and repository search still has no orchestrator/free consumer wording. #181 owns that verified drift. Preserve this PR's valid documentation/manifest delta; repair by conflict-aware non-force adoption of current protected truth, then apply the Contextual Orchestrator consumer contract and reseal affected deterministic metadata from exact bytes. Historical checks/reviews do not transfer. Do not open an overlapping AGENTS writer, force/rebase, self-approve, bypass, weaken gates, or synthesize a blind merge tree merely to make the PR mergeable.

Copy link
Copy Markdown
Contributor Author

Docs/release-truth handoff from People owner #64/#266: the direct confirmed-hire PostgreSQL adapter had a checked-command/used-command TOCTOU because it authorized a caller-owned frozen HireAcceptanceCommand and only afterward invoked connection_factory(), allowing a retained reference to rewrite tenant/identity fields before SQL parameters were derived. Test-first 338305f4...; causal source fix e01e825... snapshots via dataclasses.replace(command) before authorization/executable DB acquisition. When #51 reconciles CHANGELOG/TRACEABILITY/release truth from protected owner integrations, carry the durable invariant and release note semantically, not these volatile PR SHAs. Do not copy mutable #64 source.

Adopt protected develop without rewriting history. Preserve the protected repository-quality consolidation and deleted leaf workflows while retaining the non-overlapping canonical protected-truth delta from #51. Semantic overlap is intentionally resolved to protected truth in this merge commit and repaired forward in follow-up commits.

Signed-off-by: Seongho Bae <me@seonghobae.me>
Add the executable RED contract for Issue #181 before changing consumer guidance. The test requires AGENTS/CLAUDE/TRD/security/traceability to agree on released contextual-orchestrator, orchestrator/free, gateway authentication, and fail-closed provider-independent routing.

Signed-off-by: Seongho Bae <me@seonghobae.me>
Run the Issue #181 governance regression in the canonical Foundation validation command so direct-provider guidance is a real RED rather than documentation-only intent.

Signed-off-by: Seongho Bae <me@seonghobae.me>
Satisfy the first Issue #181 RED by making released contextual-orchestrator the only Orgmetra model-routing authority. GitHub Actions use orchestrator/free through gateway authentication; provider credentials, provider/model/group selection, and paid fallback remain outside the Orgmetra consumer boundary.

Signed-off-by: Seongho Bae <me@seonghobae.me>
Keep provider discovery, routing and termination semantics in released contextual-orchestrator and make orchestrator/free plus gateway authentication the only model-backed GitHub Actions consumer path.

Signed-off-by: Seongho Bae <me@seonghobae.me>
Make the released contextual-orchestrator contract the sole model-backed consumer path, require orchestrator/free plus gateway authentication, and keep provider routing and termination semantics in the owner service.

Signed-off-by: Seongho Bae <me@seonghobae.me>
Record contextual-orchestrator as the sole model-routing trust boundary and require orchestrator/free plus gateway authentication while failing closed on missing owner capabilities.

Signed-off-by: Seongho Bae <me@seonghobae.me>
Record Issue #181 as an explicit consumer/owner contract with executable evidence, orchestrator/free gateway routing, no provider credentials or paid fallback, and fail-closed owner repair.

Signed-off-by: Seongho Bae <me@seonghobae.me>
Exercise the root guidance and the Issue #181 traceability record directly while keeping the larger product traceability matrix focused on shipped capability maturity.

Signed-off-by: Seongho Bae <me@seonghobae.me>
Preserve the protected foundation-ci verification introduced after #51 branched while restoring ADR 0011's shipped protected-develop status.

Signed-off-by: Seongho Bae <me@seonghobae.me>
Keep the consolidated Foundation CI verification while restoring ADR 0012 as shipped protected-develop architecture truth.

Signed-off-by: Seongho Bae <me@seonghobae.me>
Keep the protected consolidated Foundation CI evidence while restoring the capability's integrated protected-develop maturity.

Signed-off-by: Seongho Bae <me@seonghobae.me>
Preserve the consolidated Foundation CI verification while restoring the intent adapter's protected-develop maturity and foreign-owner execution boundary.

Signed-off-by: Seongho Bae <me@seonghobae.me>
Keep the consolidated Foundation CI gate while restoring the governed requisition review packet's protected-develop maturity.

Signed-off-by: Seongho Bae <me@seonghobae.me>
Remove the stale protected SHA/active-PR note, preserve the workflow-consolidation release note, promote already integrated Job Analysis and selection-review capability, and record the Issue #181 contextual-orchestrator governance repair.

Signed-off-by: Seongho Bae <me@seonghobae.me>
…ventory

Adopt #51's branch-neutral protected-target manifest semantics without restoring the deleted job-analysis leaf workflow. Preserve ADR 0017/0025 inventory and add the Issue #181 traceability/regression artifacts to deterministic provenance.

Signed-off-by: Seongho Bae <me@seonghobae.me>
Preserve #51's ADR 0017/0025 inventory and explicit non-canonical ADR-status rejection while retaining the protected workflow consolidation and keeping deleted leaf workflows deleted. Add the Issue #181 regression and traceability artifacts to the same durable inventory.

Signed-off-by: Seongho Bae <me@seonghobae.me>

Copy link
Copy Markdown
Contributor Author

Protected-truth documentation handoff from #64/#315: current docs/TRACEABILITY.md still lacks an explicit governed Employment-separation row even though #64 now has the active implementation and canonical API/Data Model/ERD/UML/PRD/TRD reconciliation. Please reconcile only after protected adoption (or clearly mark active-PR maturity if this lane intentionally tracks it), without copying mutable People source.

Required traceability facts: POST /v1/employment-separations; employment_record_version + employment_separation_record + people_mutation_idempotency_record + immutable audit/outbox; ADR 0015 remains Proposed; tests include application/HTTP/PostgreSQL root, capability/RLS, distinct-key concurrency, failure cleanup/server quiescence, uncertain-commit replay, and Assignment/separation serialization; maturity must not be represented as protected/shipped until #64 normal integration and #311/security/review acceptance. Rehire #302 remains planned, not an implemented transition.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant