Skip to content

test: gate routed pg-erd loopback latency - #22

Draft
seonghobae wants to merge 406 commits into
test/pg-erd-partial-response-v1from
test/pg-erd-routed-load-v1
Draft

seonghobae wants to merge 406 commits into
test/pg-erd-partial-response-v1from
test/pg-erd-routed-load-v1

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 2, 2026 •

Copy link
Copy Markdown
Contributor

Buyer-visible migration gap

The bounded pg-erd multi-route composition root needs routed concurrency/latency evidence of its own. Generic one-upstream timing does not transfer to the migration binary with compiled route selection, forwarding reconstruction, response policy, and two concrete upstream authorities. This lane remains gateway test/CI evidence only; it does not absorb product authentication/business routing, Wardnet/EgressWeave policy, Keyverse identity, certificate authority, or service-discovery authority.

Routed k6 remains 4 VUs / 400 iterations, exact HTTP 200/body identity, zero HTTP failures, aggregate/backend/frontend p95 <20 ms, wall-clock end-to-end p95 <20 ms, and at least 198 samples per route. This is controlled loopback regression evidence, not a production/TLS/WAN/NUMA SLO.

Current exact — 2026-09-25

Exact #21 157e26050f2014642f03016c1b69a9ea1ef3dc49 remains the merge-base. Current exact is 740fe704c5f78ccad18812d9c066bb3fa10611e8, open, Ready and mergeable; fresh compare is ahead 406 / behind 0, 90 effective paths / 148 valid repairs.

Cargo ancestor audit retraction — no repair credit

Fresh Cargo authority review considered .cargo/config / .cargo/config.toml discovery from the current directory and ancestor directories. Candidate 7479517641d43206ea3db2688440003b0a71a26b was created, but fresh exact-source review proved the workflow already scans $PWD through /, rejects both Cargo config names at every level, separately rejects CARGO_HOME/config{,.toml}, and does so before the measured release rebuild. The duplicate candidate was removed by forward commit 30237084b1f39dbd78fd98f4a48b0bb9a8e86c70; compare from prior valid exact 17ff8106585d6ac878d21d5521e09f07920c3b6d has zero effective files. No force update, destructive rebase, gate weakening, or repair credit was assigned.

Repair 148 — curl default-config authority

Fresh evidence review found that every CI/OCI curl invocation could read runner-owned default configuration before command-line evidence options. curl's primary documentation states that, unless disabled, the tool searches CURL_HOME/.curlrc, XDG_CONFIG_HOME/curlrc, HOME/.curlrc and platform fallbacks, and that -q / --disable prevents reading the default config only when supplied as the first command-line parameter. Ambient config could therefore redirect or mutate k6 artifact download, loopback readiness, routed readiness, or OCI health/metrics probes without a repository delta.

Test-first ffb75b5209ee71081cdc9f495d3b1cb698b2fd2a adds tests/load_curl_default_config_authority_contract.rs. It enumerates workflow shell run blocks, rejects evidence-producing curl calls that do not use curl -q as the first option, rejects late -q, and covers command-substitution probes. The test-first CI 36020650927 jobs 107704386511 load-contract, 107704386911 oci-runtime, 107704386925 test and Supply 36020650911 / 107704387503 were superseded before runner admission and completed cancelled with steps=[], runner_id=0; deterministic source RED only is credited.

Causal/current 740fe704c5f78ccad18812d9c066bb3fa10611e8 changes only the ten existing evidence curl invocations to place -q first: checksum-pinned k6 download, generic fixture/gateway readiness, routed origin/gateway readiness, generic OCI readiness, and pg-erd OCI live/metrics probes. Test-first→causal compare is exactly 1 commit, .github/workflows/ci.yml +10/-10. Production Rust, route/business authority, k6 workload, thresholds and sample floors are unchanged.

Exact-head evidence

Current workflows are CI 36020875243 and Supply Chain 36020875218. CI jobs 107705141706 test, 107705142079 load-contract, 107705142159 oci-runtime and Supply 107705138146 candidate-evidence are queued with steps=[], no runner assigned and no terminal conclusion. Current exact therefore does not yet have hosted GREEN.

#23 remains historical Draft ce022f2e4c540acf55e49d8629cbb3bf162c75d8, diverged ahead 33 / behind 336 versus current #22 with merge-base 27cffbb38900512255880a890d516f2d3103e4cf, preserving only CHANGELOG.md, TEST_STRATEGY.md, and tests/pg_erd_payload_free_observability.rs. #24 remains historical Draft 824b10411ba3b58c7b8a8dceb12eb69eef6ca43b, directly ahead 79 / behind 0 over historical #23 with its established five child paths. Their source/ref/state are not rewritten from this lane.

Parent-first order remains foundation current-exact settlement -> release-qualified supplier/security root -> #22 exact GREEN/integration -> #23 current-parent reconciliation + exact GREEN/integration -> #24 current-parent reconciliation + exact GREEN/integration.

Foundation #1 remains Draft/open at 0cf3b4377745d8a59f40f16e60a164e443595bec with Security Scan and CodeQL FAILURE, SAST SUCCESS, and CI/Supply Draft-lifecycle SKIPPED. cloudflare/pingora#889 remains open, unassigned, with three comments for derivative 2.2.0 / RUSTSEC-2024-0388; latest public supplier release remains Pingora 0.9.0, published 2026-09-09T23:34:48Z, immutable=false, assets 0. No release-qualified repaired supplier is claimed.

Protected main@f8b4c99b8e5d3de79af1ff0c00c0c8fd63b52991 remains protected. Repository-local required status contexts are empty while organization ruleset CWL Central required workflows remains active. Repository Release inventory remains empty. Repository-wide baseline/TRACEABILITY remains dedicated #61 authority; Repair 148/current ancestry and curl primary evidence are handed off without modifying that lane's source/ref/state.

No self-approval, blind rerun, force-push, destructive rebase, protected-main merge, immutable release, SBOM/provenance/reproducibility, cutover, rollback, or legacy-removal credit is claimed.

@coderabbitai

coderabbitai Bot commented Sep 2, 2026 •

Copy link
Copy Markdown

Review Change StackReview Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 397f273e-6ab7-4491-a27d-e4c8880b0f8b

📥 Commits

Reviewing files that changed from the base of the PR and between 6a74783 and 3db4fe0.

📒 Files selected for processing (1)
  • tests/load_origin_readiness_workflow_contract.rs

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

Rust 기반 bounded origin과 pg-erd 라우팅 부하 검증을 추가했습니다. CI는 두 라우트의 k6 테스트와 요약 산출물을 실행합니다. 계약 테스트와 기술 문서는 성능, 릴리스, 공급망 증거 기준을 갱신합니다.

Changes

라우팅 부하 검증

Layer / File(s) Summary
Rust origin 구현
tests/load/load_origin.rs
환경 변수 검증, bounded worker pool, keep-alive/close 응답, HTTP 헤더 처리 및 단위 테스트를 추가합니다.
CI routed-load 실행
.github/workflows/ci.yml
Rust origin과 두 gateway 바이너리를 빌드합니다. 일반 loopback 경로와 backend/frontend pg-erd 경로를 실행하고 k6 요약 파일을 업로드합니다.
라우팅 부하 계약 및 검증
tests/load/pg_erd_gateway_smoke.js, tests/pg_erd_routed_latency_contract.rs, tests/rust_load_origin_workflow_contract.rs, tests/load_origin_readiness_workflow_contract.rs
k6가 backend/frontend 라우트를 교대 호출하고 상태, 본문, p(95) 지연 및 요청 수를 검증합니다. 계약 테스트는 Rust origin 사용, readiness 순서 및 CI 명령 구조를 확인합니다.
수용 기준 및 기준선 문서
CHANGELOG.md, TEST_STRATEGY.md, docs/product-technical-gap-baseline.md
라우팅 부하 기준, 릴리스 증거, 공급망 검증, OCI 조건 및 잔여 수용 조건을 갱신합니다.

Estimated code review effort: 4 (Complex) | ~45 minutes

Sequence Diagram(s)

sequenceDiagram
  participant CI
  participant RustOrigin
  participant PgErdMigration
  participant K6
  CI->>RustOrigin: 두 bounded origin 실행
  CI->>PgErdMigration: pg-erd 설정으로 migration gateway 실행
  K6->>PgErdMigration: backend/frontend 라우트 요청
  PgErdMigration->>RustOrigin: 라우팅된 요청 전달
  K6->>CI: 상태, 본문, 지연시간 및 요약 파일 기록
Loading

Merge Risk: ⚪ Minimal · up to 3db4f

This change updates CI load-validation evidence to use the Rust origin and verifies readiness before routed traffic. No current merge-blocking risk remains.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed Docstring coverage is 96.15% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 26 functions across 5 files.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed 제목은 routed pg-erd loopback 지연 시간 게이트를 추가하는 주요 변경 사항을 정확하고 간결하게 설명합니다.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch test/pg-erd-routed-load-v1

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

seonghobae commented Sep 7, 2026 •

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

Fresh exact-head review requested for db17db4d6e41f9dd1afa9e1fbc2402ad0dc969e8...c71bd51fec222508cbf98931e76a98f0830c312b. Treat all predecessor checks/reviews as non-transferable.

Please verify the complete current 18-path range, including the existing Rust-only measured-path, independent backend/frontend p95 thresholds, and route-sample-floor contracts. The latest causal change is formatter-only 97e1f517f8b2ce998ba5e9184bc03b5659d34f74...c71bd51fec222508cbf98931e76a98f0830c312b: hosted predecessor CI 34120301871 had GREEN OCI/load but test 101736592666 failed at Rust 1.98.0 cargo fmt --all -- --check; the repair applies exactly that deterministic rustfmt output to seven test files without changing routing semantics, fixture behavior, workflows, sample count, thresholds, OCI/security policy, or product authority.

Also verify the current route-sample-floor TDD: RED ef2f466c600391f2a991aabae3ea7fca66c822ba requires route-local request counts; GREEN 43470af91001454f02fc4e62855b80aa0f596c25 requires at least 198 samples for each characterized route while preserving 400 requests / 4 VUs, per-VU alternation, both exact bodies, zero failures, and aggregate/backend/frontend p95 <20 ms. Candidate ADR 0008 remains non-production evidence.

@coderabbitai

coderabbitai Bot commented Sep 7, 2026 •

Copy link
Copy Markdown

@seonghobae I will perform a fresh review of the exact current range. I will treat predecessor checks and reviews as non-transferable.

⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@coderabbitai

coderabbitai Bot commented Sep 7, 2026

Copy link
Copy Markdown

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

base="db17db4d6e41f9dd1afa9e1fbc2402ad0dc969e8"
head="f707c56412243608031509d18570f999f193ad16"
merge="885d44e1265be408b3fbf459fcb71c6c1c2db4be"

echo "== Exact range and ancestry =="
git diff --name-status "$base...$head"
printf '\nmerge parents: '
git show -s --format='%P' "$merge"
printf 'merge tree: '
git show -s --format='%T' "$merge"
printf 'base tree: '
git show -s --format='%T' "$base"
printf 'head tree: '
git show -s --format='%T' "$head"
printf '\nbase is ancestor of head: '
git merge-base --is-ancestor "$base" "$head" && echo yes || echo no
printf 'merge first parent: '
git rev-parse "$merge^1"
printf 'merge second parent: '
git rev-parse "$merge^2"
printf 'merge second parent tree: '
git show -s --format='%T' "$merge^2"
printf '\nRange commits:\n'
git log --format='%H %P %s' --reverse "$base..$head"

echo
echo "== Targeted workflow references =="
rg -n -C 4 --glob '.github/workflows/ci.yml' \
  'load_origin|upstream_fixture|fixture-ready|/livez|k6-pg-erd-summary|if: always|upload-artifact|pg_erd_gateway_smoke|cargo (test|build)|--release|oci' .

echo
echo "== Targeted load-test and contract references =="
rg -n -C 4 --glob 'tests/load/pg_erd_gateway_smoke.js' --glob 'tests/rust_load_origin_workflow_contract.rs' \
  '400|vus|/api/load-contract|/load-contract|http_req_failed|http_req_duration|p\(95\)|fixture-ready|python3|load_origin|release|cargo' tests

echo
echo "== Rust fixture structure =="
ast-grep outline tests/load/load_origin.rs --items all
echo
rg -n -C 3 'fn (main|handle|parse|write)|fixture-ready|TCP_NODELAY|Content-Length|MAX_|worker|queue|delay|port|header|partial' tests/load/load_origin.rs

echo
echo "== Documentation terms =="
rg -n -C 2 --glob 'CHANGELOG.md' --glob 'TEST_STRATEGY.md' --glob 'TRD.md' --glob 'docs/product-technical-gap-baseline.md' \
  'load_origin|upstream_fixture|Python|Rust|400|four VUs|4 VUs|p95|20 ms|fixture-ready|/livez|pg-erd|k6' \
  CHANGELOG.md TEST_STRATEGY.md TRD.md docs/product-technical-gap-baseline.md

echo
echo "== Python fixture status and OCI diff =="
test ! -e tests/load/upstream_fixture.py && echo "tests/load/upstream_fixture.py: absent"
git diff --unified=30 "$base...$head" -- .github/workflows/ci.yml tests/load/pg_erd_gateway_smoke.js tests/rust_load_origin_workflow_contract.rs

Length of output: 6446


@seonghobae The Git topology check confirms the stated ordinary two-parent adoption. I will now inspect the changed source and workflow content.

You are interacting with an AI system.

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

Fresh exact-range review requested after deterministic hosted formatter RED repair. Predecessor ef1833d7234433454252d9bc49beb60bf8d6d856 is evidence only and must not transfer to the changed head.

Hosted CI 34191744954 proved the routed load and dual-profile OCI lanes GREEN, but test 101951051107 failed at Rust 1.98.0 cargo fmt --all -- --check only because tests/rust_load_origin_workflow_contract.rs had two overlong normalized_scripts.contains(...) assertions. Exact repair 648db6b25c8227baf1f4cad7170790637b70a515 applies the formatter-prescribed wrapping only; it does not change workflow semantics, traffic volume, thresholds, routing, fixture behavior, production Rust, OCI/security policy, or authority boundaries.

Please review the complete current #21→#22 effective range plus this one-file repair. The predecessor routed artifact remains useful lane-local evidence: 400 requests, 800/800 checks, zero HTTP failures, aggregate p95 0.5510101 ms, backend p95 0.61089945 ms over 200 requests, frontend p95 0.5004503 ms over 200 requests; all <20 ms thresholds passed. Do not treat those predecessor measurements as current-head hosted GREEN.

@coderabbitai

coderabbitai Bot commented Sep 8, 2026

Copy link
Copy Markdown

Oops, something went wrong! Please try again later. 🐰 💔

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

Please bind the fresh technical review to current exact head 6a747837133380563e3f7fa32a86148ab6a37da7 over final parent 51f1242663ccbf164efc50ca2ac74c4d0a1c7126. Treat all earlier review/check receipts as non-transferable.

Since the prior request, source commit 648db6b25c8227baf1f4cad7170790637b70a515 only applied the Rust 1.98.0 formatter-prescribed wrapping that fixed hosted test 101951051107. Documentation commit 6a747837... removes self-staling current-head/run IDs from docs/product-technical-gap-baseline.md while preserving exact evidence in live PR/owner issue authority; it changes no runtime behavior. Please verify that the nine-path #22 routed-load contract remains intact: Rust-only measured origins, 4 VUs / 400 iterations, exact bodies/status, zero HTTP failures, aggregate/backend/frontend p95 <20 ms, and at least 198 requests per route.

@coderabbitai

coderabbitai Bot commented Sep 8, 2026 •

Copy link
Copy Markdown
🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

base="51f1242663ccbf164efc50ca2ac74c4d0a1c7126"
head="6a747837133380563e3f7fa32a86148ab6a37da7"

echo "== Exact range =="
git merge-base "$base" "$head"
git merge-base --is-ancestor "$base" "$head" && echo "base_is_ancestor=yes"
git diff --name-status "$base...$head"
echo "== Commits =="
git log --reverse --format='%H%n%P%n%s%n' "$base..$head"

echo "== Relevant file outlines =="
ast-grep outline tests/load/load_origin.rs --items all
ast-grep outline tests/rust_load_origin_workflow_contract.rs --items all

echo "== Routed k6 contract =="
cat -n tests/load/pg_erd_gateway_smoke.js

echo "== Rust load origin =="
cat -n tests/load/load_origin.rs

echo "== Workflow measured-path sections =="
rg -n -C 12 --glob '.github/workflows/ci.yml' \
  'load-contract|load_origin|upstream_fixture|pg_erd_gateway_smoke|k6|cargo (build|test)|python|fixture-ready|upload-artifact' \
  .github/workflows/ci.yml

echo "== Rust workflow-contract assertions =="
cat -n tests/rust_load_origin_workflow_contract.rs

echo "== Baseline documentation diff =="
git diff --unified=80 "$base...$head" -- docs/product-technical-gap-baseline.md

echo "== All source changes in range =="
git diff --stat "$base...$head"
git diff --check "$base...$head"

Length of output: 79699


🏁 Script executed:

#!/bin/bash
set -euo pipefail

base="51f1242663ccbf164efc50ca2ac74c4d0a1c7126"
head="6a747837133380563e3f7fa32a86148ab6a37da7"

echo "== Routed load workflow, complete segment =="
sed -n '193,308p' .github/workflows/ci.yml | cat -n

echo "== Route latency regression contract =="
cat -n tests/pg_erd_routed_latency_contract.rs

echo "== Relevant pg-erd configuration model and routing-plan references =="
rg -n -C 5 --type rust \
  'struct PgErdMigrationConfig|deny_unknown_fields|pg_erd_migration_plan|load-contract|/api/load-contract|backend-ok|frontend-ok' \
  .

echo "== Exact formatter repair =="
git show --format=fuller --stat 648db6b25c8227baf1f4cad7170790637b70a515
git diff 648db6b25c8227baf1f4cad7170790637b70a515^ 648db6b25c8227baf1f4cad7170790637b70a515 -- tests/rust_load_origin_workflow_contract.rs

echo "== Exact documentation follow-up =="
git show --format=fuller --stat 6a747837133380563e3f7fa32a86148ab6a37da7
git diff 6a747837133380563e3f7fa32a86148ab6a37da7^ 6a747837133380563e3f7fa32a86148ab6a37da7 -- docs/product-technical-gap-baseline.md

echo "== Current-head whitespace/errors =="
git diff --check "$base...$head"

Length of output: 35337


@seonghobae Fresh technical review completed for 51f1242663ccbf164efc50ca2ac74c4d0a1c7126...6a747837133380563e3f7fa32a86148ab6a37da7.

I found no actionable source or workflow finding.

The effective range has nine paths. The routed k6 contract remains intact:

  • It uses 4 VUs and 400 iterations.
  • It alternates /api/load-contract and /load-contract.
  • It tags every request as backend or frontend.
  • It checks HTTP 200 and the route-specific exact response body.
  • It requires zero HTTP failures.
  • It gates aggregate, backend, and frontend p95 latency at <20 ms.
  • It requires at least 198 requests for each route.

The measured path remains Rust-only. The workflow builds and tests tests/load/load_origin.rs, then builds an optimized Rust fixture. It starts separate bounded Rust origins for backend-ok and frontend-ok. The measured load-contract job contains no Python invocation.

The workflow starts the compiled cwl-pingora-pg-erd-migration binary. Its configuration contains transport and runtime values only. It does not add routes:. PgErdMigrationConfig remains fail-closed with deny_unknown_fields, and route selection remains in pg_erd_migration_plan().

Commit 648db6b25c8227baf1f4cad7170790637b70a515 contains only the stated rustfmt line wrapping. Commit 6a747837133380563e3f7fa32a86148ab6a37da7 changes only the migration baseline documentation. git diff --check reported no whitespace errors.

I did not execute repository code in this inspection environment. Current-head CI and Supply Chain closure must still be established on 6a747837133380563e3f7fa32a86148ab6a37da7. Earlier receipts remain non-transferable.

✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

Please review the current exact head 3db4fe08e3c2145559ea01b01598a028d0be798b. The new delta after the previously reviewed 6a747837133380563e3f7fa32a86148ab6a37da7 is intentionally limited to tests/load_origin_readiness_workflow_contract.rs: it replaces the stale removed-Python fixture startup oracle with the actual bounded Rust /tmp/load_origin startup command while preserving readiness/liveness/gateway/k6 ordering. Treat prior review evidence as non-transferable to this head.

@coderabbitai

coderabbitai Bot commented Sep 8, 2026 •

Copy link
Copy Markdown
🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

base="6a747837133380563e3f7fa32a86148ab6a37da7"
head="3db4fe08e3c2145559ea01b01598a028d0be798b"

echo "== Exact range =="
echo -n "merge-base: "
git merge-base "$base" "$head"
git merge-base --is-ancestor "$base" "$head" && echo "base_is_ancestor=yes"
echo "-- changed paths --"
git diff --name-status "$base...$head"
echo "-- commits --"
git log --reverse --format='%H%n%P%n%s%n' "$base..$head"
echo "-- whitespace --"
git diff --check "$base...$head"

echo
echo "== Changed contract test outline and content =="
ast-grep outline tests/load_origin_readiness_workflow_contract.rs --items all
cat -n tests/load_origin_readiness_workflow_contract.rs

echo
echo "== Exact delta =="
git diff --unified=100 "$base...$head" -- tests/load_origin_readiness_workflow_contract.rs

echo
echo "== Current workflow load-contract section =="
rg -n -C 20 --glob '.github/workflows/ci.yml' \
  'load-contract|/tmp/load_origin|fixture-ready|/livez|cwl-pingora|pg_erd_gateway_smoke|k6 run|gateway_pid|backend_pid|frontend_pid' \
  .github/workflows/ci.yml

echo
echo "== Related contract-test patterns and registration =="
rg -n -C 4 --type rust \
  'load_origin_readiness_workflow_contract|readiness|fixture-ready|/tmp/load_origin|pg_erd_gateway_smoke' \
  Cargo.toml tests

Length of output: 37504


@seonghobae Fresh review completed for 6a747837133380563e3f7fa32a86148ab6a37da7...3db4fe08e3c2145559ea01b01598a028d0be798b.

I found no actionable issue.

The exact range contains one commit and one changed file: tests/load_origin_readiness_workflow_contract.rs.

The updated contract now requires the actual generic measured-path startup command:

/tmp/load_origin >/tmp/upstream-fixture.log 2>&1 &

This string matches the current load-contract workflow. The contract also preserves the required source order:

  1. Rust origin startup.
  2. Direct /fixture-ready probe.
  3. Origin liveness failure check with kill -0 "$upstream_pid".
  4. Gateway startup.
  5. Measured k6 execution.

The workflow still uses the bounded Rust origin. The change does not restore a Python fixture dependency. git diff --check found no whitespace errors.

I performed static inspection only. I did not run repository code or verify current-head CI or Supply Chain results. Earlier review and CI receipts remain non-transferable to 3db4fe08e3c2145559ea01b01598a028d0be798b.

⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

Please review the exact current range 6a747837133380563e3f7fa32a86148ab6a37da7..3db4fe08e3c2145559ea01b01598a028d0be798b, especially tests/load_origin_readiness_workflow_contract.rs. Current exact head has terminal hosted CI and Supply Chain GREEN; do not transfer older review credit.

@coderabbitai

coderabbitai Bot commented Sep 8, 2026 •

Copy link
Copy Markdown
🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

base="6a747837133380563e3f7fa32a86148ab6a37da7"
head="3db4fe08e3c2145559ea01b01598a028d0be798b"

echo "== Exact range topology =="
printf 'merge-base: '
git merge-base "$base" "$head"
git merge-base --is-ancestor "$base" "$head" && echo "base_is_ancestor=yes"
echo "-- commits --"
git log --reverse --format='%H%n%P%n%s%n' "$base..$head"
echo "-- changed paths --"
git diff --name-status "$base...$head"
echo "-- whitespace --"
git diff --check "$base...$head"

echo
echo "== Changed contract test outline =="
ast-grep outline tests/load_origin_readiness_workflow_contract.rs --items all
echo "== Changed contract test =="
cat -n tests/load_origin_readiness_workflow_contract.rs
echo "== Exact contract-test delta =="
git diff --unified=100 "$base...$head" -- tests/load_origin_readiness_workflow_contract.rs

echo
echo "== Workflow load-contract section =="
rg -n -C 24 --glob '.github/workflows/ci.yml' \
  'load-contract|/tmp/load_origin|fixture-ready|/livez|cwl-pingora-pg-erd-migration|pg_erd_gateway_smoke|k6 run|upstream_pid|gateway_pid|python' \
  .github/workflows/ci.yml

echo
echo "== Related test registration and readiness contracts =="
rg -n -C 4 --type rust \
  'load_origin_readiness_workflow_contract|fixture-ready|/tmp/load_origin|upstream_pid|pg_erd_gateway_smoke' \
  Cargo.toml tests

echo
echo "== Exact-head GitHub check runs =="
gh api "repos/ContextualWisdomLab/pingora-gateway/commits/$head/check-runs?per_page=100" \
  --jq '.check_runs[] | [.name, .status, .conclusion, .details_url] | `@tsv`'

Length of output: 28870


@seonghobae Fresh review completed for 6a747837133380563e3f7fa32a86148ab6a37da7..3db4fe08e3c2145559ea01b01598a028d0be798b.

I found no actionable issue.

The range contains one commit and one changed file: tests/load_origin_readiness_workflow_contract.rs.

The updated contract now requires the actual Rust-origin startup command:

/tmp/load_origin >/tmp/upstream-fixture.log 2>&1 &

The command matches the load-contract workflow.

The contract preserves the required source order:

  1. Start the Rust origin.
  2. Probe /fixture-ready directly.
  3. Check upstream_pid liveness.
  4. Start cwl-pingora-gateway.
  5. Run the measured k6 traffic.

The workflow still starts the bounded Rust origin before gateway startup. The workflow does not use Python in the measured load job. The routed pg-erd job still uses separate Rust origins.

git diff --check reported no whitespace errors.

I also verified exact-head GitHub check runs. load-contract, test, oci-runtime, and candidate-evidence completed successfully. This review uses the current-head results only. It does not transfer earlier review or CI credit.

✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Exact-current technical review for dbc728485aee8ecc461fe5144dd73b60ffe55626: base is current #21 4e7907b63345ea62362c6b8e826c35839679ed24, and the effective PR scope is back to the intended nine routed-load paths. The ordinary restack repair preserved current-parent read-stall/graceful-drain/partial-response contracts and restored the parent CI admission/protected-main/concurrency gates that the historical child workflow had regressed. The Rust measured-origin replacement and routed pg-erd k6 contract remain controlled-loopback evidence only: 4 VUs / 400 iterations, exact body/status, aggregate/backend/frontend p95 <20 ms, and per-route sample floors. No predecessor GREEN, production SLO, release, merge, canary or cutover credit is transferred. I found no unresolved inline review thread on this exact state; fresh exact-head CI/Supply Chain execution is still required before dependent restack.

@seonghobae
seonghobae marked this pull request as ready for review September 13, 2026 05:30
@seonghobae
seonghobae marked this pull request as draft September 13, 2026 19:34
@seonghobae
seonghobae marked this pull request as ready for review September 20, 2026 08:22

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Current-head review after ancestry reconciliation: the effective delta is still exactly the nine routed-load paths, with #21 parent changes preserved on the two overlapping documentation files. The load contract remains deliberately bounded: Rust-only measured origins, 4 VUs / 400 iterations, exact body/status, zero HTTP failures, independent aggregate/backend/frontend p95 <20 ms, and >=198 samples per route. The workflow keeps route selection compiled into the migration binary and does not promote loopback timing into a production/TLS/multi-hop SLO. No product-domain auth/business authority, Keyverse identity, Wardnet/EgressWeave policy, certificate authority, or service-discovery behavior is introduced. Historical GREEN does not transfer; this exact head still requires fresh CI/Supply evidence, and dependency order forbids integrating ahead of #20/#21.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Current-head review at 4281562e4788e65c5016f5b7332d50cd5560ef46: predecessor 8d624f9b... produced a genuine coverage RED in tests/pg_erd_production_path.rs after normal test/Clippy/rustdoc and routed load/OCI succeeded. The failing oracle showed traffic and metrics authorities both recycled to 127.0.0.1:36021; the fixture had sequentially bound and dropped each ephemeral reservation before process bind. This exact repairs only that evidence race by retaining both TcpListener reservations simultaneously through config construction and dropping them immediately before the compiled gateway binds. The sibling saturation fixture receives the same reservation discipline. Production Rust, route/forwarding behavior, k6 4-VU/400-iteration sample contract, independent route p95 <20 ms gates and product-domain authority are unchanged. Fresh compare to exact #21 remains merge-base 157e2605..., ahead 65 / behind 0; effective scope is the prior routed-load nine paths plus this explicit inherited fixture repair. Fresh exact CI/Supply must independently settle; no predecessor receipt transfers.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Current-head technical review at 6250df134eb5597abd243784bd949048aa62f849: fresh review of tests/load/load_origin.rs found that the supposedly bounded UPSTREAM_RESPONSE_DELAY_MS accepted any parsed u64, so u64::MAX could reach Duration::from_millis() / thread::sleep() and create effectively unbounded worker occupancy in the measured-origin fixture. Test-first 97ace58a... encoded the fail-closed boundary; causal repair 6250df13... admits at most 60,000 ms and rejects 60,001 ms and u64::MAX before listener/worker activation. This changes test tooling only: the measured path still uses zero delay, and gateway production Rust, routing semantics, 4-VU/400-iteration traffic, per-route sample floors, and p95 <20 ms gates are unchanged. Fresh compare to exact #21 is ahead 67 / behind 0 with the same ten effective paths. New same-SHA CI/Supply are required; predecessor receipts do not transfer. This COMMENT is technical evidence only, not approval.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Current-head technical review at 4d2c2b220363d943e435d5002023468dc2a2673c: after the worker-count/queue and synthetic-delay bounds, tests/load/load_origin.rs still left accepted sockets with no finite read/write I/O budget. An incomplete header could therefore retain a measured-origin worker indefinitely; a peer that stopped reading could similarly retain a worker in write_all(). Test-first be00c264... adds a real connected-socket oracle requiring finite accepted-socket timeouts; causal repair 4d2c2b22... sets five-second read/write timeouts before request I/O. This is test tooling only: healthy routed load remains 4 VUs / 400 iterations with unchanged exact status/body, per-route sample floors and p95 <20 ms gates, and production gateway Rust/timeouts are untouched. Fresh compare to exact #21 is ahead 69 / behind 0 with the same ten effective paths. Same-SHA CI/Supply must settle independently; this COMMENT is technical evidence only, not approval.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Current-head technical review for 04337c0b9c44335fa30a5c8d6aca45a0d6b96945: Repair 140 closes inherited GIT_CONFIG_PARAMETERS command-scope configuration authority before Git is used as the routed provenance oracle. Test-first 924429ad3ab222ad63180c8463ca92341bac1a1d makes the previous workflow deterministically RED; causal 04337c0b... changes only .github/workflows/ci.yml from unset GIT_CONFIG_NOSYSTEM GIT_CONFIG_COUNT to unset GIT_CONFIG_NOSYSTEM GIT_CONFIG_COUNT GIT_CONFIG_PARAMETERS (+1/-1). Git upstream defines GIT_CONFIG_PARAMETERS as config transport and explicitly preserves it when sanitizing repo-local Git environment. No production Rust, traffic workload, threshold, sample-floor, authority boundary, or gate weakening is introduced. Current hosted exact-head jobs are still pre-runner/zero-step, so no GREEN is claimed.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Repair 141 current-head review: routed provenance now neutralizes inherited Git pathspec interpretation authority (GIT_LITERAL_PATHSPECS, GIT_GLOB_PATHSPECS, GIT_NOGLOB_PATHSPECS, GIT_ICASE_PATHSPECS) before Git is used as the exact-source oracle. Git documents these variables as process-wide equivalents of the corresponding pathspec modes, including case-insensitive path selection. Test-first f4df833c5eb524f15e734367b6d530bf0b315b87 adds a fail-closed contract; causal/current 8cc87a3f620b22570de34441148675fe40a2d144 changes only .github/workflows/ci.yml +1/-0. No production Rust, routing/business authority, workload, threshold, sample floor, release, or gate semantics were weakened. Hosted exact-head GREEN remains required before integration.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Repair 142 technical review @ exact 0e2722d0962feb66267d13b5d2625bc625276657: valid finding confirmed. Grafana k6 option precedence puts K6_* environment options above script options, so runner-inherited values could override the reviewed 4-VU/400-iteration shape or disable threshold evaluation without changing the checked-in script. Test-first 3af6b5e375de9b957a92a8421a2e9182610850c7 adds a fail-closed dynamic K6_* sanitization contract; causal current adds only the sanitizer immediately before the checksum-proven k6 binary is executed. Test-first hosted jobs were cancelled pre-runner (steps=[], runner_id=0), so only deterministic source RED is credited. Current exact jobs are still queued pre-runner; no hosted GREEN, merge, release, or cutover credit. COMMENT only; no self-approval.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Current-head technical review for 251dd78935bc559f4e12da49a13e0c20335aa9d2: Repair 143 closes mutable runner k6 disk-config authority by creating a known-empty config and passing it explicitly; Repair 144 removes k6's default external usage-report side effect with the highest-precedence --no-usage-report CLI flag. Both changes preserve the reviewed 4 VU / 400 iteration workload, route/body/failure assertions, sample floors, and p95 gates. Test-first heads were deterministic source RED and were superseded before runner admission, so no hosted RED/GREEN is credited. Current exact still requires fresh hosted CI/Supply execution before integration. No self-approval.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Current-head technical review for b213f7824e85d9721aac5892f4395d8da8d6792d: Repair 145 closes the same k6 mutable-authority class on the required generic loopback preflight, which still preceded routed evidence in the load-contract job. The generic step now dynamically clears inherited K6_*, creates a known-empty explicit config, invokes the checksum-installed /usr/local/bin/k6, and disables default usage reporting. This preserves its checked-in 4 VU / 400 iteration / checks=1 / http_req_failed=0 / p95<20ms contract while removing runner-local config/environment and external telemetry influence. Test-first was deterministic source RED and superseded pre-runner; no hosted RED/GREEN is credited. No self-approval.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Repair 145의 intervening delta를 adopt한 뒤 Repair 146을 exact-head 기준으로 검토했습니다. TAR_OPTIONS는 GNU tar에서 explicit CLI options 앞에 삽입되는 default option authority이므로 checksum-pinned k6 archive라도 extraction semantics를 runner environment가 바꿀 수 있었습니다. Test-first 0bee7f41f718ce5fa37b6a6aca20d088134ad9f7는 install + routed point-of-use extraction 모두에서 pre-tar unset TAR_OPTIONS를 요구하고, causal 9487ba2c823f2308a5b2f0c8526c3d39e8eb22d5가 두 지점만 수정했습니다. Contents API의 incidental final-newline normalization은 successor 7526feb536b5a7e556aa26d7e274bb2231ac9ec2에서 non-force로 복구되어 test-first→current effective workflow delta는 +2/-0입니다. Test-first CI/Supply는 runner_id=0, steps=[] 상태에서 cancelled되어 hosted RED/GREEN으로 세지 않습니다. Current exact CI/Supply는 아직 queued/no-runner이므로 GREEN, merge, release, cutover credit을 부여하지 않습니다.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Repair 147 review: routed exact-source provenance now proves Git's own rev-parse --show-toplevel equals GITHUB_WORKSPACE before HEAD/path-content checks. This closes repository-local core.worktree / linked-worktree redirection while preserving production Rust, route authority, workload, thresholds and sample floors. Test-first hosted jobs were superseded pre-runner, so only deterministic source RED is credited; current exact still requires hosted GREEN.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Current-range audit on exact 30237084b1f39dbd78fd98f4a48b0bb9a8e86c70 found no new valid source repair. The candidate Cargo ancestor-configuration finding was rechecked against the live routed workflow and is already closed: the step scans $PWD through / for .cargo/config and .cargo/config.toml, rejects CARGO_HOME/config{,.toml}, and performs those guards before the measured release rebuild. The test-first candidate 7479517641d43206ea3db2688440003b0a71a26b was therefore a duplicate/non-RED and was removed by forward commit 30237084...; compare from prior valid exact 17ff8106585d6ac878d21d5521e09f07920c3b6d has zero effective files. Repair count remains 147; Repair 147 Git worktree identity remains intact. CI/Supply on current exact are still runner-unassigned/nonterminal, so no exact-head GREEN, merge, release, or cutover credit is assigned. This is a COMMENT review only; no self-approval.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Current-range review on exact 740fe704c5f78ccad18812d9c066bb3fa10611e8: Repair 148 is a valid evidence-authority fix. curl reads a default config (CURL_HOME/.curlrc, XDG_CONFIG_HOME/curlrc, HOME/.curlrc, fallbacks) unless -q/--disable is the first command-line parameter; the pre-repair workflow used ordinary curl --fail... for k6 download, loopback/routed readiness, and OCI live/metrics probes. Test-first ffb75b5209ee71081cdc9f495d3b1cb698b2fd2a adds a fail-closed contract; causal exact changes only ten existing invocations to curl -q ... and preserves workload/threshold/route semantics. Test-first hosted jobs were cancelled before runner admission (steps=[], runner_id=0), so only deterministic source RED is credited. Current exact CI/Supply are still runner-unassigned/nonterminal; no hosted GREEN, merge, release, or cutover credit. COMMENT only; no self-approval.

Copy link
Copy Markdown
Contributor Author

Exact-head admission audit: 740fe704c5f78ccad18812d9c066bb3fa10611e8 (base test/pg-erd-partial-response-v1@157e26050f2014642f03016c1b69a9ea1ef3dc49, 406 ahead / 0 behind).

현재 blocker: terminal workflow: CI:failure.

유효 commit·diff·review evidence를 보존한 채 Draft/Proposed로 교정합니다. Base 이동이나 queue 대기만을 이유로 Close하지 않으며, Force Push·synthetic status/approval·manual rerun·bypass는 사용하지 않습니다. Blocker 수리 후 새 exact head에서 Checks와 review admission을 다시 받아야 합니다.

@seonghobae
seonghobae marked this pull request as draft September 26, 2026 19:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant