test: gate routed pg-erd loopback latency - #22
seonghobae wants to merge 406 commits into
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (1)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughRust 기반 bounded origin과 pg-erd 라우팅 부하 검증을 추가했습니다. CI는 두 라우트의 k6 테스트와 요약 산출물을 실행합니다. 계약 테스트와 기술 문서는 성능, 릴리스, 공급망 증거 기준을 갱신합니다. Changes라우팅 부하 검증
Estimated code review effort: 4 (Complex) | ~45 minutes Sequence Diagram(s)sequenceDiagram
participant CI
participant RustOrigin
participant PgErdMigration
participant K6
CI->>RustOrigin: 두 bounded origin 실행
CI->>PgErdMigration: pg-erd 설정으로 migration gateway 실행
K6->>PgErdMigration: backend/frontend 라우트 요청
PgErdMigration->>RustOrigin: 라우팅된 요청 전달
K6->>CI: 상태, 본문, 지연시간 및 요약 파일 기록
Merge Risk: ⚪ Minimal · up to This change updates CI load-validation evidence to use the Rust origin and verifies readiness before routed traffic. No current merge-blocking risk remains. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
@coderabbitai review Fresh exact-head review requested for Please verify the complete current 18-path range, including the existing Rust-only measured-path, independent backend/frontend p95 thresholds, and route-sample-floor contracts. The latest causal change is formatter-only Also verify the current route-sample-floor TDD: RED |
|
|
|
Tip For best results, initiate chat on the files or code changes. 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
base="db17db4d6e41f9dd1afa9e1fbc2402ad0dc969e8"
head="f707c56412243608031509d18570f999f193ad16"
merge="885d44e1265be408b3fbf459fcb71c6c1c2db4be"
echo "== Exact range and ancestry =="
git diff --name-status "$base...$head"
printf '\nmerge parents: '
git show -s --format='%P' "$merge"
printf 'merge tree: '
git show -s --format='%T' "$merge"
printf 'base tree: '
git show -s --format='%T' "$base"
printf 'head tree: '
git show -s --format='%T' "$head"
printf '\nbase is ancestor of head: '
git merge-base --is-ancestor "$base" "$head" && echo yes || echo no
printf 'merge first parent: '
git rev-parse "$merge^1"
printf 'merge second parent: '
git rev-parse "$merge^2"
printf 'merge second parent tree: '
git show -s --format='%T' "$merge^2"
printf '\nRange commits:\n'
git log --format='%H %P %s' --reverse "$base..$head"
echo
echo "== Targeted workflow references =="
rg -n -C 4 --glob '.github/workflows/ci.yml' \
'load_origin|upstream_fixture|fixture-ready|/livez|k6-pg-erd-summary|if: always|upload-artifact|pg_erd_gateway_smoke|cargo (test|build)|--release|oci' .
echo
echo "== Targeted load-test and contract references =="
rg -n -C 4 --glob 'tests/load/pg_erd_gateway_smoke.js' --glob 'tests/rust_load_origin_workflow_contract.rs' \
'400|vus|/api/load-contract|/load-contract|http_req_failed|http_req_duration|p\(95\)|fixture-ready|python3|load_origin|release|cargo' tests
echo
echo "== Rust fixture structure =="
ast-grep outline tests/load/load_origin.rs --items all
echo
rg -n -C 3 'fn (main|handle|parse|write)|fixture-ready|TCP_NODELAY|Content-Length|MAX_|worker|queue|delay|port|header|partial' tests/load/load_origin.rs
echo
echo "== Documentation terms =="
rg -n -C 2 --glob 'CHANGELOG.md' --glob 'TEST_STRATEGY.md' --glob 'TRD.md' --glob 'docs/product-technical-gap-baseline.md' \
'load_origin|upstream_fixture|Python|Rust|400|four VUs|4 VUs|p95|20 ms|fixture-ready|/livez|pg-erd|k6' \
CHANGELOG.md TEST_STRATEGY.md TRD.md docs/product-technical-gap-baseline.md
echo
echo "== Python fixture status and OCI diff =="
test ! -e tests/load/upstream_fixture.py && echo "tests/load/upstream_fixture.py: absent"
git diff --unified=30 "$base...$head" -- .github/workflows/ci.yml tests/load/pg_erd_gateway_smoke.js tests/rust_load_origin_workflow_contract.rsLength of output: 6446
You are interacting with an AI system. |
|
@coderabbitai review Fresh exact-range review requested after deterministic hosted formatter RED repair. Predecessor Hosted CI Please review the complete current #21→#22 effective range plus this one-file repair. The predecessor routed artifact remains useful lane-local evidence: 400 requests, 800/800 checks, zero HTTP failures, aggregate p95 0.5510101 ms, backend p95 0.61089945 ms over 200 requests, frontend p95 0.5004503 ms over 200 requests; all |
|
Oops, something went wrong! Please try again later. 🐰 💔 |
|
@coderabbitai review Please bind the fresh technical review to current exact head Since the prior request, source commit |
🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
base="51f1242663ccbf164efc50ca2ac74c4d0a1c7126"
head="6a747837133380563e3f7fa32a86148ab6a37da7"
echo "== Exact range =="
git merge-base "$base" "$head"
git merge-base --is-ancestor "$base" "$head" && echo "base_is_ancestor=yes"
git diff --name-status "$base...$head"
echo "== Commits =="
git log --reverse --format='%H%n%P%n%s%n' "$base..$head"
echo "== Relevant file outlines =="
ast-grep outline tests/load/load_origin.rs --items all
ast-grep outline tests/rust_load_origin_workflow_contract.rs --items all
echo "== Routed k6 contract =="
cat -n tests/load/pg_erd_gateway_smoke.js
echo "== Rust load origin =="
cat -n tests/load/load_origin.rs
echo "== Workflow measured-path sections =="
rg -n -C 12 --glob '.github/workflows/ci.yml' \
'load-contract|load_origin|upstream_fixture|pg_erd_gateway_smoke|k6|cargo (build|test)|python|fixture-ready|upload-artifact' \
.github/workflows/ci.yml
echo "== Rust workflow-contract assertions =="
cat -n tests/rust_load_origin_workflow_contract.rs
echo "== Baseline documentation diff =="
git diff --unified=80 "$base...$head" -- docs/product-technical-gap-baseline.md
echo "== All source changes in range =="
git diff --stat "$base...$head"
git diff --check "$base...$head"Length of output: 79699 🏁 Script executed: #!/bin/bash
set -euo pipefail
base="51f1242663ccbf164efc50ca2ac74c4d0a1c7126"
head="6a747837133380563e3f7fa32a86148ab6a37da7"
echo "== Routed load workflow, complete segment =="
sed -n '193,308p' .github/workflows/ci.yml | cat -n
echo "== Route latency regression contract =="
cat -n tests/pg_erd_routed_latency_contract.rs
echo "== Relevant pg-erd configuration model and routing-plan references =="
rg -n -C 5 --type rust \
'struct PgErdMigrationConfig|deny_unknown_fields|pg_erd_migration_plan|load-contract|/api/load-contract|backend-ok|frontend-ok' \
.
echo "== Exact formatter repair =="
git show --format=fuller --stat 648db6b25c8227baf1f4cad7170790637b70a515
git diff 648db6b25c8227baf1f4cad7170790637b70a515^ 648db6b25c8227baf1f4cad7170790637b70a515 -- tests/rust_load_origin_workflow_contract.rs
echo "== Exact documentation follow-up =="
git show --format=fuller --stat 6a747837133380563e3f7fa32a86148ab6a37da7
git diff 6a747837133380563e3f7fa32a86148ab6a37da7^ 6a747837133380563e3f7fa32a86148ab6a37da7 -- docs/product-technical-gap-baseline.md
echo "== Current-head whitespace/errors =="
git diff --check "$base...$head"Length of output: 35337
I found no actionable source or workflow finding. The effective range has nine paths. The routed k6 contract remains intact:
The measured path remains Rust-only. The workflow builds and tests The workflow starts the compiled Commit I did not execute repository code in this inspection environment. Current-head CI and Supply Chain closure must still be established on ✅ Action performedReview finished.
|
|
@coderabbitai review Please review the current exact head |
🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
base="6a747837133380563e3f7fa32a86148ab6a37da7"
head="3db4fe08e3c2145559ea01b01598a028d0be798b"
echo "== Exact range =="
echo -n "merge-base: "
git merge-base "$base" "$head"
git merge-base --is-ancestor "$base" "$head" && echo "base_is_ancestor=yes"
echo "-- changed paths --"
git diff --name-status "$base...$head"
echo "-- commits --"
git log --reverse --format='%H%n%P%n%s%n' "$base..$head"
echo "-- whitespace --"
git diff --check "$base...$head"
echo
echo "== Changed contract test outline and content =="
ast-grep outline tests/load_origin_readiness_workflow_contract.rs --items all
cat -n tests/load_origin_readiness_workflow_contract.rs
echo
echo "== Exact delta =="
git diff --unified=100 "$base...$head" -- tests/load_origin_readiness_workflow_contract.rs
echo
echo "== Current workflow load-contract section =="
rg -n -C 20 --glob '.github/workflows/ci.yml' \
'load-contract|/tmp/load_origin|fixture-ready|/livez|cwl-pingora|pg_erd_gateway_smoke|k6 run|gateway_pid|backend_pid|frontend_pid' \
.github/workflows/ci.yml
echo
echo "== Related contract-test patterns and registration =="
rg -n -C 4 --type rust \
'load_origin_readiness_workflow_contract|readiness|fixture-ready|/tmp/load_origin|pg_erd_gateway_smoke' \
Cargo.toml testsLength of output: 37504
I found no actionable issue. The exact range contains one commit and one changed file: The updated contract now requires the actual generic measured-path startup command: This string matches the current
The workflow still uses the bounded Rust origin. The change does not restore a Python fixture dependency. I performed static inspection only. I did not run repository code or verify current-head CI or Supply Chain results. Earlier review and CI receipts remain non-transferable to
|
|
@coderabbitai review Please review the exact current range |
🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
base="6a747837133380563e3f7fa32a86148ab6a37da7"
head="3db4fe08e3c2145559ea01b01598a028d0be798b"
echo "== Exact range topology =="
printf 'merge-base: '
git merge-base "$base" "$head"
git merge-base --is-ancestor "$base" "$head" && echo "base_is_ancestor=yes"
echo "-- commits --"
git log --reverse --format='%H%n%P%n%s%n' "$base..$head"
echo "-- changed paths --"
git diff --name-status "$base...$head"
echo "-- whitespace --"
git diff --check "$base...$head"
echo
echo "== Changed contract test outline =="
ast-grep outline tests/load_origin_readiness_workflow_contract.rs --items all
echo "== Changed contract test =="
cat -n tests/load_origin_readiness_workflow_contract.rs
echo "== Exact contract-test delta =="
git diff --unified=100 "$base...$head" -- tests/load_origin_readiness_workflow_contract.rs
echo
echo "== Workflow load-contract section =="
rg -n -C 24 --glob '.github/workflows/ci.yml' \
'load-contract|/tmp/load_origin|fixture-ready|/livez|cwl-pingora-pg-erd-migration|pg_erd_gateway_smoke|k6 run|upstream_pid|gateway_pid|python' \
.github/workflows/ci.yml
echo
echo "== Related test registration and readiness contracts =="
rg -n -C 4 --type rust \
'load_origin_readiness_workflow_contract|fixture-ready|/tmp/load_origin|upstream_pid|pg_erd_gateway_smoke' \
Cargo.toml tests
echo
echo "== Exact-head GitHub check runs =="
gh api "repos/ContextualWisdomLab/pingora-gateway/commits/$head/check-runs?per_page=100" \
--jq '.check_runs[] | [.name, .status, .conclusion, .details_url] | `@tsv`'Length of output: 28870
I found no actionable issue. The range contains one commit and one changed file: The updated contract now requires the actual Rust-origin startup command: The command matches the The contract preserves the required source order:
The workflow still starts the bounded Rust origin before gateway startup. The workflow does not use Python in the measured load job. The routed pg-erd job still uses separate Rust origins.
I also verified exact-head GitHub check runs. ✅ Action performedReview finished.
|
seonghobae
left a comment
There was a problem hiding this comment.
Exact-current technical review for dbc728485aee8ecc461fe5144dd73b60ffe55626: base is current #21 4e7907b63345ea62362c6b8e826c35839679ed24, and the effective PR scope is back to the intended nine routed-load paths. The ordinary restack repair preserved current-parent read-stall/graceful-drain/partial-response contracts and restored the parent CI admission/protected-main/concurrency gates that the historical child workflow had regressed. The Rust measured-origin replacement and routed pg-erd k6 contract remain controlled-loopback evidence only: 4 VUs / 400 iterations, exact body/status, aggregate/backend/frontend p95 <20 ms, and per-route sample floors. No predecessor GREEN, production SLO, release, merge, canary or cutover credit is transferred. I found no unresolved inline review thread on this exact state; fresh exact-head CI/Supply Chain execution is still required before dependent restack.
seonghobae
left a comment
There was a problem hiding this comment.
Current-head review after ancestry reconciliation: the effective delta is still exactly the nine routed-load paths, with #21 parent changes preserved on the two overlapping documentation files. The load contract remains deliberately bounded: Rust-only measured origins, 4 VUs / 400 iterations, exact body/status, zero HTTP failures, independent aggregate/backend/frontend p95 <20 ms, and >=198 samples per route. The workflow keeps route selection compiled into the migration binary and does not promote loopback timing into a production/TLS/multi-hop SLO. No product-domain auth/business authority, Keyverse identity, Wardnet/EgressWeave policy, certificate authority, or service-discovery behavior is introduced. Historical GREEN does not transfer; this exact head still requires fresh CI/Supply evidence, and dependency order forbids integrating ahead of #20/#21.
seonghobae
left a comment
There was a problem hiding this comment.
Current-head review at 4281562e4788e65c5016f5b7332d50cd5560ef46: predecessor 8d624f9b... produced a genuine coverage RED in tests/pg_erd_production_path.rs after normal test/Clippy/rustdoc and routed load/OCI succeeded. The failing oracle showed traffic and metrics authorities both recycled to 127.0.0.1:36021; the fixture had sequentially bound and dropped each ephemeral reservation before process bind. This exact repairs only that evidence race by retaining both TcpListener reservations simultaneously through config construction and dropping them immediately before the compiled gateway binds. The sibling saturation fixture receives the same reservation discipline. Production Rust, route/forwarding behavior, k6 4-VU/400-iteration sample contract, independent route p95 <20 ms gates and product-domain authority are unchanged. Fresh compare to exact #21 remains merge-base 157e2605..., ahead 65 / behind 0; effective scope is the prior routed-load nine paths plus this explicit inherited fixture repair. Fresh exact CI/Supply must independently settle; no predecessor receipt transfers.
seonghobae
left a comment
There was a problem hiding this comment.
Current-head technical review at 6250df134eb5597abd243784bd949048aa62f849: fresh review of tests/load/load_origin.rs found that the supposedly bounded UPSTREAM_RESPONSE_DELAY_MS accepted any parsed u64, so u64::MAX could reach Duration::from_millis() / thread::sleep() and create effectively unbounded worker occupancy in the measured-origin fixture. Test-first 97ace58a... encoded the fail-closed boundary; causal repair 6250df13... admits at most 60,000 ms and rejects 60,001 ms and u64::MAX before listener/worker activation. This changes test tooling only: the measured path still uses zero delay, and gateway production Rust, routing semantics, 4-VU/400-iteration traffic, per-route sample floors, and p95 <20 ms gates are unchanged. Fresh compare to exact #21 is ahead 67 / behind 0 with the same ten effective paths. New same-SHA CI/Supply are required; predecessor receipts do not transfer. This COMMENT is technical evidence only, not approval.
seonghobae
left a comment
There was a problem hiding this comment.
Current-head technical review at 4d2c2b220363d943e435d5002023468dc2a2673c: after the worker-count/queue and synthetic-delay bounds, tests/load/load_origin.rs still left accepted sockets with no finite read/write I/O budget. An incomplete header could therefore retain a measured-origin worker indefinitely; a peer that stopped reading could similarly retain a worker in write_all(). Test-first be00c264... adds a real connected-socket oracle requiring finite accepted-socket timeouts; causal repair 4d2c2b22... sets five-second read/write timeouts before request I/O. This is test tooling only: healthy routed load remains 4 VUs / 400 iterations with unchanged exact status/body, per-route sample floors and p95 <20 ms gates, and production gateway Rust/timeouts are untouched. Fresh compare to exact #21 is ahead 69 / behind 0 with the same ten effective paths. Same-SHA CI/Supply must settle independently; this COMMENT is technical evidence only, not approval.
seonghobae
left a comment
There was a problem hiding this comment.
Current-head technical review for 04337c0b9c44335fa30a5c8d6aca45a0d6b96945: Repair 140 closes inherited GIT_CONFIG_PARAMETERS command-scope configuration authority before Git is used as the routed provenance oracle. Test-first 924429ad3ab222ad63180c8463ca92341bac1a1d makes the previous workflow deterministically RED; causal 04337c0b... changes only .github/workflows/ci.yml from unset GIT_CONFIG_NOSYSTEM GIT_CONFIG_COUNT to unset GIT_CONFIG_NOSYSTEM GIT_CONFIG_COUNT GIT_CONFIG_PARAMETERS (+1/-1). Git upstream defines GIT_CONFIG_PARAMETERS as config transport and explicitly preserves it when sanitizing repo-local Git environment. No production Rust, traffic workload, threshold, sample-floor, authority boundary, or gate weakening is introduced. Current hosted exact-head jobs are still pre-runner/zero-step, so no GREEN is claimed.
seonghobae
left a comment
There was a problem hiding this comment.
Repair 141 current-head review: routed provenance now neutralizes inherited Git pathspec interpretation authority (GIT_LITERAL_PATHSPECS, GIT_GLOB_PATHSPECS, GIT_NOGLOB_PATHSPECS, GIT_ICASE_PATHSPECS) before Git is used as the exact-source oracle. Git documents these variables as process-wide equivalents of the corresponding pathspec modes, including case-insensitive path selection. Test-first f4df833c5eb524f15e734367b6d530bf0b315b87 adds a fail-closed contract; causal/current 8cc87a3f620b22570de34441148675fe40a2d144 changes only .github/workflows/ci.yml +1/-0. No production Rust, routing/business authority, workload, threshold, sample floor, release, or gate semantics were weakened. Hosted exact-head GREEN remains required before integration.
seonghobae
left a comment
There was a problem hiding this comment.
Repair 142 technical review @ exact 0e2722d0962feb66267d13b5d2625bc625276657: valid finding confirmed. Grafana k6 option precedence puts K6_* environment options above script options, so runner-inherited values could override the reviewed 4-VU/400-iteration shape or disable threshold evaluation without changing the checked-in script. Test-first 3af6b5e375de9b957a92a8421a2e9182610850c7 adds a fail-closed dynamic K6_* sanitization contract; causal current adds only the sanitizer immediately before the checksum-proven k6 binary is executed. Test-first hosted jobs were cancelled pre-runner (steps=[], runner_id=0), so only deterministic source RED is credited. Current exact jobs are still queued pre-runner; no hosted GREEN, merge, release, or cutover credit. COMMENT only; no self-approval.
seonghobae
left a comment
There was a problem hiding this comment.
Current-head technical review for 251dd78935bc559f4e12da49a13e0c20335aa9d2: Repair 143 closes mutable runner k6 disk-config authority by creating a known-empty config and passing it explicitly; Repair 144 removes k6's default external usage-report side effect with the highest-precedence --no-usage-report CLI flag. Both changes preserve the reviewed 4 VU / 400 iteration workload, route/body/failure assertions, sample floors, and p95 gates. Test-first heads were deterministic source RED and were superseded before runner admission, so no hosted RED/GREEN is credited. Current exact still requires fresh hosted CI/Supply execution before integration. No self-approval.
seonghobae
left a comment
There was a problem hiding this comment.
Current-head technical review for b213f7824e85d9721aac5892f4395d8da8d6792d: Repair 145 closes the same k6 mutable-authority class on the required generic loopback preflight, which still preceded routed evidence in the load-contract job. The generic step now dynamically clears inherited K6_*, creates a known-empty explicit config, invokes the checksum-installed /usr/local/bin/k6, and disables default usage reporting. This preserves its checked-in 4 VU / 400 iteration / checks=1 / http_req_failed=0 / p95<20ms contract while removing runner-local config/environment and external telemetry influence. Test-first was deterministic source RED and superseded pre-runner; no hosted RED/GREEN is credited. No self-approval.
seonghobae
left a comment
There was a problem hiding this comment.
Repair 145의 intervening delta를 adopt한 뒤 Repair 146을 exact-head 기준으로 검토했습니다. TAR_OPTIONS는 GNU tar에서 explicit CLI options 앞에 삽입되는 default option authority이므로 checksum-pinned k6 archive라도 extraction semantics를 runner environment가 바꿀 수 있었습니다. Test-first 0bee7f41f718ce5fa37b6a6aca20d088134ad9f7는 install + routed point-of-use extraction 모두에서 pre-tar unset TAR_OPTIONS를 요구하고, causal 9487ba2c823f2308a5b2f0c8526c3d39e8eb22d5가 두 지점만 수정했습니다. Contents API의 incidental final-newline normalization은 successor 7526feb536b5a7e556aa26d7e274bb2231ac9ec2에서 non-force로 복구되어 test-first→current effective workflow delta는 +2/-0입니다. Test-first CI/Supply는 runner_id=0, steps=[] 상태에서 cancelled되어 hosted RED/GREEN으로 세지 않습니다. Current exact CI/Supply는 아직 queued/no-runner이므로 GREEN, merge, release, cutover credit을 부여하지 않습니다.
seonghobae
left a comment
There was a problem hiding this comment.
Repair 147 review: routed exact-source provenance now proves Git's own rev-parse --show-toplevel equals GITHUB_WORKSPACE before HEAD/path-content checks. This closes repository-local core.worktree / linked-worktree redirection while preserving production Rust, route authority, workload, thresholds and sample floors. Test-first hosted jobs were superseded pre-runner, so only deterministic source RED is credited; current exact still requires hosted GREEN.
seonghobae
left a comment
There was a problem hiding this comment.
Current-range audit on exact 30237084b1f39dbd78fd98f4a48b0bb9a8e86c70 found no new valid source repair. The candidate Cargo ancestor-configuration finding was rechecked against the live routed workflow and is already closed: the step scans $PWD through / for .cargo/config and .cargo/config.toml, rejects CARGO_HOME/config{,.toml}, and performs those guards before the measured release rebuild. The test-first candidate 7479517641d43206ea3db2688440003b0a71a26b was therefore a duplicate/non-RED and was removed by forward commit 30237084...; compare from prior valid exact 17ff8106585d6ac878d21d5521e09f07920c3b6d has zero effective files. Repair count remains 147; Repair 147 Git worktree identity remains intact. CI/Supply on current exact are still runner-unassigned/nonterminal, so no exact-head GREEN, merge, release, or cutover credit is assigned. This is a COMMENT review only; no self-approval.
seonghobae
left a comment
There was a problem hiding this comment.
Current-range review on exact 740fe704c5f78ccad18812d9c066bb3fa10611e8: Repair 148 is a valid evidence-authority fix. curl reads a default config (CURL_HOME/.curlrc, XDG_CONFIG_HOME/curlrc, HOME/.curlrc, fallbacks) unless -q/--disable is the first command-line parameter; the pre-repair workflow used ordinary curl --fail... for k6 download, loopback/routed readiness, and OCI live/metrics probes. Test-first ffb75b5209ee71081cdc9f495d3b1cb698b2fd2a adds a fail-closed contract; causal exact changes only ten existing invocations to curl -q ... and preserves workload/threshold/route semantics. Test-first hosted jobs were cancelled before runner admission (steps=[], runner_id=0), so only deterministic source RED is credited. Current exact CI/Supply are still runner-unassigned/nonterminal; no hosted GREEN, merge, release, or cutover credit. COMMENT only; no self-approval.
|
Exact-head admission audit: 현재 blocker: terminal workflow: CI:failure. 유효 commit·diff·review evidence를 보존한 채 Draft/Proposed로 교정합니다. Base 이동이나 queue 대기만을 이유로 Close하지 않으며, Force Push·synthetic status/approval·manual rerun·bypass는 사용하지 않습니다. Blocker 수리 후 새 exact head에서 Checks와 review admission을 다시 받아야 합니다. |
Buyer-visible migration gap
The bounded pg-erd multi-route composition root needs routed concurrency/latency evidence of its own. Generic one-upstream timing does not transfer to the migration binary with compiled route selection, forwarding reconstruction, response policy, and two concrete upstream authorities. This lane remains gateway test/CI evidence only; it does not absorb product authentication/business routing, Wardnet/EgressWeave policy, Keyverse identity, certificate authority, or service-discovery authority.
Routed k6 remains 4 VUs / 400 iterations, exact HTTP 200/body identity, zero HTTP failures, aggregate/backend/frontend p95
<20 ms, wall-clock end-to-end p95<20 ms, and at least 198 samples per route. This is controlled loopback regression evidence, not a production/TLS/WAN/NUMA SLO.Current exact — 2026-09-25
Exact #21
157e26050f2014642f03016c1b69a9ea1ef3dc49remains the merge-base. Current exact is740fe704c5f78ccad18812d9c066bb3fa10611e8, open, Ready and mergeable; fresh compare is ahead 406 / behind 0, 90 effective paths / 148 valid repairs.Cargo ancestor audit retraction — no repair credit
Fresh Cargo authority review considered
.cargo/config/.cargo/config.tomldiscovery from the current directory and ancestor directories. Candidate7479517641d43206ea3db2688440003b0a71a26bwas created, but fresh exact-source review proved the workflow already scans$PWDthrough/, rejects both Cargo config names at every level, separately rejectsCARGO_HOME/config{,.toml}, and does so before the measured release rebuild. The duplicate candidate was removed by forward commit30237084b1f39dbd78fd98f4a48b0bb9a8e86c70; compare from prior valid exact17ff8106585d6ac878d21d5521e09f07920c3b6dhas zero effective files. No force update, destructive rebase, gate weakening, or repair credit was assigned.Repair 148 — curl default-config authority
Fresh evidence review found that every CI/OCI
curlinvocation could read runner-owned default configuration before command-line evidence options. curl's primary documentation states that, unless disabled, the tool searchesCURL_HOME/.curlrc,XDG_CONFIG_HOME/curlrc,HOME/.curlrcand platform fallbacks, and that-q/--disableprevents reading the default config only when supplied as the first command-line parameter. Ambient config could therefore redirect or mutate k6 artifact download, loopback readiness, routed readiness, or OCI health/metrics probes without a repository delta.Test-first
ffb75b5209ee71081cdc9f495d3b1cb698b2fd2aaddstests/load_curl_default_config_authority_contract.rs. It enumerates workflow shellrunblocks, rejects evidence-producing curl calls that do not usecurl -qas the first option, rejects late-q, and covers command-substitution probes. The test-first CI36020650927jobs107704386511load-contract,107704386911oci-runtime,107704386925test and Supply36020650911 / 107704387503were superseded before runner admission and completed cancelled withsteps=[],runner_id=0; deterministic source RED only is credited.Causal/current
740fe704c5f78ccad18812d9c066bb3fa10611e8changes only the ten existing evidencecurlinvocations to place-qfirst: checksum-pinned k6 download, generic fixture/gateway readiness, routed origin/gateway readiness, generic OCI readiness, and pg-erd OCI live/metrics probes. Test-first→causal compare is exactly 1 commit,.github/workflows/ci.yml+10/-10. Production Rust, route/business authority, k6 workload, thresholds and sample floors are unchanged.Exact-head evidence
Current workflows are CI
36020875243and Supply Chain36020875218. CI jobs107705141706test,107705142079load-contract,107705142159oci-runtime and Supply107705138146candidate-evidence are queued withsteps=[], no runner assigned and no terminal conclusion. Current exact therefore does not yet have hosted GREEN.#23 remains historical Draft
ce022f2e4c540acf55e49d8629cbb3bf162c75d8, diverged ahead 33 / behind 336 versus current #22 with merge-base27cffbb38900512255880a890d516f2d3103e4cf, preserving onlyCHANGELOG.md,TEST_STRATEGY.md, andtests/pg_erd_payload_free_observability.rs. #24 remains historical Draft824b10411ba3b58c7b8a8dceb12eb69eef6ca43b, directly ahead 79 / behind 0 over historical #23 with its established five child paths. Their source/ref/state are not rewritten from this lane.Parent-first order remains
foundation current-exact settlement -> release-qualified supplier/security root -> #22 exact GREEN/integration -> #23 current-parent reconciliation + exact GREEN/integration -> #24 current-parent reconciliation + exact GREEN/integration.Foundation #1 remains Draft/open at
0cf3b4377745d8a59f40f16e60a164e443595becwith Security Scan and CodeQL FAILURE, SAST SUCCESS, and CI/Supply Draft-lifecycle SKIPPED.cloudflare/pingora#889remains open, unassigned, with three comments forderivative 2.2.0 / RUSTSEC-2024-0388; latest public supplier release remains Pingora 0.9.0, published2026-09-09T23:34:48Z,immutable=false, assets 0. No release-qualified repaired supplier is claimed.Protected
main@f8b4c99b8e5d3de79af1ff0c00c0c8fd63b52991remains protected. Repository-local required status contexts are empty while organization rulesetCWL Central required workflowsremains active. Repository Release inventory remains empty. Repository-wide baseline/TRACEABILITY remains dedicated #61 authority; Repair 148/current ancestry and curl primary evidence are handed off without modifying that lane's source/ref/state.No self-approval, blind rerun, force-push, destructive rebase, protected-main merge, immutable release, SBOM/provenance/reproducibility, cutover, rollback, or legacy-removal credit is claimed.