Skip to content
Closed
Show file tree
Hide file tree
Changes from 7 commits
Commits
Show all changes
130 commits
Select commit Hold shift + click to select a range
c11fb65
fix(governance): require central reviews for stacked prs
seonghobae Aug 20, 2026
ab65fcc
docs(governance): record restored approval contract
seonghobae Aug 20, 2026
bc2c93a
docs(governance): refresh stacked review rollout ledger
seonghobae Aug 20, 2026
501fe54
fix(router): permit exact-head dispatch enqueue
seonghobae Aug 20, 2026
aa63517
fix(router): preserve every trusted mention with least privilege
seonghobae Aug 20, 2026
a7aeb56
fix(workflows): remove unsupported concurrency queue
seonghobae Aug 20, 2026
c18d8c0
Merge remote-tracking branch 'refs/remotes/origin/main' into fix/stac…
seonghobae Aug 20, 2026
158f090
fix(governance): enforce exact central ref scope
seonghobae Aug 20, 2026
b873e71
fix(router): use reviewer token for sibling acknowledgements
seonghobae Aug 20, 2026
a56bf7f
fix(strix): classify caido sandbox startup failure
seonghobae Aug 20, 2026
33b85a8
fix(strix): require trusted caido traceback marker
seonghobae Aug 20, 2026
08f0f04
Merge main into stacked PR governance fix
seonghobae Aug 21, 2026
b628e88
fix(governance): preserve proposal branch create transition
seonghobae Aug 21, 2026
cf94d18
chore(governance): synchronize protected main
seonghobae Aug 21, 2026
f0bef61
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] Aug 21, 2026
8923bad
fix(ci): refresh audit lock and scheduler assertion
seonghobae Aug 21, 2026
d6be648
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] Aug 21, 2026
c6e1ba3
chore(governance): restore canonical pip lock ownership
seonghobae Aug 21, 2026
6bf0447
fix(governance): avoid misleading multi-rule drift
seonghobae Aug 21, 2026
5d64102
ci: refresh dependency and scheduler contracts
seonghobae Aug 21, 2026
4eedfa4
Merge remote-tracking branch 'origin/main' into codex/pr1176-restack
seonghobae Aug 21, 2026
5b2a216
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] Aug 21, 2026
49f6988
merge(main): retain only proposal-branch governance repair
seonghobae Aug 23, 2026
2f16ea9
merge(main): refresh proposal-branch governance repair
seonghobae Aug 24, 2026
cc941b2
merge(main): refresh create-transition audit after Strix hotfix
seonghobae Aug 24, 2026
55a6a79
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] Aug 24, 2026
27a686b
Merge protected main into fix/stacked-pr-central-required-workflows
seonghobae Aug 25, 2026
366fe2f
merge: converge governance create-transition owner with protected main
seonghobae Aug 25, 2026
437ea84
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] Aug 26, 2026
d6bb951
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] Aug 26, 2026
5486790
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] Aug 26, 2026
2701cf9
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] Aug 26, 2026
8664a7c
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] Aug 26, 2026
36d4fec
Merge branch 'main' into fix/stacked-pr-central-required-workflows
seonghobae Aug 26, 2026
6b09d65
Merge branch 'main' into fix/stacked-pr-central-required-workflows
seonghobae Aug 27, 2026
31e00c1
Merge branch 'main' into fix/stacked-pr-central-required-workflows
seonghobae Aug 28, 2026
940511d
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] Aug 28, 2026
f94292a
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] Aug 28, 2026
482d4c0
Merge protected main into proposal-branch governance repair
seonghobae Aug 28, 2026
2a9d115
fix(governance): audit owner repository review ruleset
seonghobae Aug 30, 2026
4ae3c61
fix(governance): reject hidden ruleset drift
seonghobae Aug 30, 2026
d222401
fix(governance): audit organization bypass actors
seonghobae Aug 30, 2026
0b0a45b
fix(governance): fail closed on missing bypass evidence
seonghobae Aug 30, 2026
63ca5e7
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] Aug 30, 2026
8ea2ec5
Retrigger required checks against refreshed main (no new main commits…
claude Aug 30, 2026
8dea465
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] Aug 30, 2026
ce108e7
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] Aug 30, 2026
8a7c5b1
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] Aug 30, 2026
faf1dd6
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] Aug 30, 2026
36ade87
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] Aug 30, 2026
53f99d7
Merge branch 'main' into fix/stacked-pr-central-required-workflows
seonghobae Aug 30, 2026
dc8d7d9
Merge branch 'main' into fix/stacked-pr-central-required-workflows
seonghobae Aug 30, 2026
718ae19
Merge protected main into fix/stacked-pr-central-required-workflows
seonghobae Aug 30, 2026
c1b31b2
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] Aug 31, 2026
2bc22cc
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] Aug 31, 2026
73b5b28
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] Aug 31, 2026
135f16f
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] Aug 31, 2026
5acc547
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] Aug 31, 2026
a14822c
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] Aug 31, 2026
3407ca6
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] Aug 31, 2026
df92a2e
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] Aug 31, 2026
d33dd13
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] Aug 31, 2026
d435f88
Merge protected main into fix/stacked-pr-central-required-workflows
seonghobae Aug 31, 2026
4d88d45
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] Sep 1, 2026
1141b31
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] Sep 1, 2026
ed314f6
test(governance): define solo-maintainer ruleset RED
seonghobae Sep 1, 2026
a815b54
ci(governance): run focused solo-maintainer contract
seonghobae Sep 1, 2026
3830a7d
fix(governance): align ruleset audit to solo maintainer
seonghobae Sep 1, 2026
f01d2cb
test(governance): rebaseline solo-maintainer ruleset policy
seonghobae Sep 1, 2026
260705b
test(governance): reject synthetic required reviewers
seonghobae Sep 1, 2026
1f0d0e8
ci(governance): exercise synthetic-reviewer RED
seonghobae Sep 1, 2026
033d6ec
fix(governance): reject synthetic required reviewers
seonghobae Sep 1, 2026
1c9c831
test(governance): require executable ruleset regressions
seonghobae Sep 1, 2026
06e1ba2
fix(governance): execute full focused ruleset suite
seonghobae Sep 1, 2026
c3a0571
test(governance): detach temporary proof from permanent suite
seonghobae Sep 1, 2026
2b381e1
fix(governance): pin focused contract Python
seonghobae Sep 1, 2026
3ec4abf
ci(governance): move focused ruleset contract off saturated latest queue
seonghobae Sep 1, 2026
81a7afb
ci(governance): retire proven focused ruleset contract lane
seonghobae Sep 1, 2026
29f004d
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] Sep 1, 2026
66757ec
ci(governance): restore unproven focused contract lane
seonghobae Sep 1, 2026
c52470b
test(governance): cover complete ruleset drift evidence
seonghobae Sep 1, 2026
a9505c3
fix(governance): reject undeclared ruleset controls
seonghobae Sep 1, 2026
c3ec79a
fix(governance): report all fetched ruleset drift
seonghobae Sep 1, 2026
d1c0b7c
ci(governance): execute completeness regressions
seonghobae Sep 1, 2026
c2ab699
docs(governance): align rollout with solo-maintainer policy
seonghobae Sep 1, 2026
49ebfae
test(governance): pin focused proof interpreter
seonghobae Sep 1, 2026
1bd407d
fix(governance): restore Python 3.14 proof runtime
seonghobae Sep 1, 2026
76516f4
fix(governance): run focused contract on explicit runner
seonghobae Sep 1, 2026
af04bac
docs(governance): preserve regression fixture history
seonghobae Sep 1, 2026
63609f2
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] Sep 1, 2026
3156622
ci(governance): allow exact-head focused redispatch
seonghobae Sep 1, 2026
74c0148
test(governance): reproduce malformed merge-method audit crash
seonghobae Sep 1, 2026
9b5d822
test(governance): reject malformed merge methods
seonghobae Sep 1, 2026
b3c2f6d
ci(governance): repair malformed merge-method finding on exact head
seonghobae Sep 1, 2026
ce752a4
fix(governance): reject malformed merge-method payloads
seonghobae Sep 1, 2026
7e82462
chore(governance): retire source-fix helper
seonghobae Sep 1, 2026
2fb3a48
chore(governance): retire focused proof workflow
seonghobae Sep 1, 2026
a4b817b
chore(governance): integrate current main into ruleset writer
seonghobae Sep 1, 2026
5d1e416
fix(governance): retire stale temporary-workflow regression
seonghobae Sep 1, 2026
ed3b562
chore(governance): integrate current main after queue repair
seonghobae Sep 1, 2026
5c46858
chore(governance): integrate hourly queue-pressure repair
seonghobae Sep 1, 2026
15ce91c
chore(governance): integrate required-review runner pin
seonghobae Sep 1, 2026
214b0bd
fix(governance): preserve protected-main review runner repair
seonghobae Sep 1, 2026
a53b008
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] Sep 1, 2026
8977092
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] Sep 1, 2026
2bbdcaa
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] Sep 1, 2026
6455ecd
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] Sep 1, 2026
f77890e
Merge branch 'main' into fix/stacked-pr-central-required-workflows
opencode-agent[bot] Sep 1, 2026
0852bc5
Merge current main into solo-maintainer governance writer
seonghobae Sep 1, 2026
a6d169d
Merge current main into solo-maintainer governance writer
seonghobae Sep 1, 2026
9a33ecc
chore: preserve current label taxonomy
seonghobae Sep 1, 2026
37f7f77
chore: preserve current repository metadata
seonghobae Sep 1, 2026
8f66c9a
docs: preserve current public-surface reconciliation
seonghobae Sep 1, 2026
c69b254
test: preserve current label taxonomy contract
seonghobae Sep 1, 2026
a001ec2
test: preserve current repository metadata contract
seonghobae Sep 1, 2026
48d9772
chore: restore exact protected-main metadata blobs
seonghobae Sep 1, 2026
8339b9b
test: reject code-owner review in solo-maintainer rulesets
seonghobae Sep 1, 2026
2887bb6
fix: reject code-owner approval deadlocks
seonghobae Sep 1, 2026
fbc90b3
Merge dedicated metadata credential into governance writer
seonghobae Sep 1, 2026
0097f93
Merge current protected main into governance writer
seonghobae Sep 1, 2026
9457e66
fix(governance): preserve current-main Pingora evidence
seonghobae Sep 1, 2026
5c684d8
Merge current protected main into governance writer
seonghobae Sep 1, 2026
65be10b
fix(governance): preserve current-main NIM retirement
seonghobae Sep 1, 2026
12076f9
Merge protected main into solo-maintainer ruleset writer
seonghobae Sep 1, 2026
41b0c97
test(governance): make code-owner policy explicit in passing fixture
seonghobae Sep 1, 2026
437a782
merge(governance): integrate current protected main without losing ru…
seonghobae Sep 1, 2026
44b4ea4
merge(governance): integrate current protected main without losing ru…
seonghobae Sep 2, 2026
51c469c
merge(governance): integrate current protected main
seonghobae Sep 2, 2026
a3f1b0f
merge(main): preserve current OpenCode dispatch repair
seonghobae Sep 2, 2026
dcb8580
merge(main): preserve current scheduler cadence on ruleset audit writer
seonghobae Sep 2, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 0 additions & 1 deletion .github/workflows/agent-mention-noema-dispatch.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,6 @@ on:
concurrency:
group: agent-mention-noema-${{ github.event.client_payload.agent_invocation_key || github.run_id }}
cancel-in-progress: false
queue: max

permissions:
contents: read
Expand Down
1 change: 0 additions & 1 deletion .github/workflows/agent-mention-opencode-dispatch.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,6 @@ on:
concurrency:
group: agent-mention-opencode-${{ github.event.client_payload.agent_invocation_key || github.run_id }}
cancel-in-progress: false
queue: max

permissions:
contents: read
Expand Down
3 changes: 0 additions & 3 deletions .github/workflows/agent-mention-router.yml
Original file line number Diff line number Diff line change
Expand Up @@ -24,9 +24,6 @@ jobs:
contains(github.event.comment.body, '@cwl-noema-review')
|| contains(github.event.comment.body, '@opencode-agent')
)
concurrency:
group: review-agent-mention-router-local-${{ github.repository }}
queue: max
runs-on: ubuntu-24.04
timeout-minutes: 5
permissions:
Expand Down
1 change: 1 addition & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -35,6 +35,7 @@ Semantic Versioning where the repository publishes a release.

### Fixed

- Keep local agent-mention Actions access read-only and remove its replacing concurrency group together with the unsupported `concurrency.queue` key, so every eligible exact-head mention can enqueue while scheduled sweeps remain independently single-flight.
- Parsed `opencode.jsonc` as JSONC (stripping `//` and `/* */` comments outside string literals) in the reasoning-effort guard and its contract tests, instead of raw `json.loads`, which rejected the file the moment it carried its first explanatory comment (added for the `contextual-orchestrator` provider block) with `Expecting property name enclosed in double quotes`. Comment markers inside string values, such as the `$schema` URL, are left untouched.
- Download the pinned `uv` 0.12.1 exporter from the official GitHub Releases URL instead of `releases.astral.sh`, which now returns HTTP 403 and blocks org-wide OpenCode `coverage-evidence`. The SHA-256 pin is unchanged. The opener may follow one hop onto `release-assets.githubusercontent.com` or `objects.githubusercontent.com` and still rejects every other host, userinfo, non-HTTPS scheme, and nondefault port (ContextualWisdomLab/.github#1109).
- Compared the trusted `uv` executable's post-install `--version` output against the real GitHub Releases build's full string, `uv 0.12.1 (x86_64-unknown-linux-gnu)`, instead of the bare `uv 0.12.1` the prior check required; the genuine release binary always prints the target triple, so every installation was failing the pin check immediately after the archive download itself was fixed (ContextualWisdomLab/.github#1109).
Expand Down
12 changes: 7 additions & 5 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -48,7 +48,7 @@ that means:
| Mode | What happens |
| --- | --- |
| **따로 (this repo alone)** | Clone, test, and operate `.github` as the org profile and workflow source. Local quality gates, Cloudflare dry-run, and this repository's own PRs do not depend on naruon or any sibling product checkout. |
| **또 같이 (siblings call it)** | A sibling enables the org required-workflow ruleset (already `repository_name.include=["~ALL"]` on default branches). GitHub runs the trusted workflows from `ContextualWisdomLab/.github@main` in that sibling's repository context. Optional reusable callers (`deploy-pages.yml`, `pr-review-fix-scheduler.yml`) are `workflow_call` entry points, not files to copy. |
| **또 같이 (siblings call it)** | A sibling enables the org required-workflow ruleset (already `repository_name.include=["~ALL"]`, `ref_name.include=["~ALL"]`). GitHub runs the trusted workflows from `ContextualWisdomLab/.github@main` in that sibling's repository context, including stacked PR base branches. Optional reusable callers (`deploy-pages.yml`, `pr-review-fix-scheduler.yml`) are `workflow_call` entry points, not files to copy. |

Do not copy Strix, OpenCode, Noema, or scheduler workflow files into a
sibling to "satisfy CI." Thick downstream sync PRs are an anti-pattern
Expand All @@ -61,12 +61,13 @@ Live work and roadmap live on
The narrative brief is [docs/CWL-MASTER-CONTEXT.md](docs/CWL-MASTER-CONTEXT.md).
The last checked-in ruleset ledger is
[docs/org-required-workflow-rollout.md](docs/org-required-workflow-rollout.md)
(updated 2026-07-23 KST).
(updated 2026-08-21 KST).

Checked-in operator facts:

- Ruleset `18156473` is **active**. It targets every repository default
branch (`~ALL` / `~DEFAULT_BRANCH`) and sources workflows from this
- Ruleset `18156473` is **active**. It targets every repository branch
(`repository_name.include=["~ALL"]`, `ref_name.include=["~ALL"]`), including
stacked pull-request base branches, and sources workflows from this
repository at `refs/heads/main`.
- Active required workflow paths: `close-empty-pr.yml`, `noema-review.yml`,
`opencode-review.yml`, `pr-review-merge-scheduler.yml`,
Expand All @@ -89,7 +90,8 @@ workflows into siblings.
public repositories inherit ruleset `18156473` without a name-list update.
2. Keep product, build, release, and repo-specific security workflows local.
Do not add local copies of OpenCode, Strix, Noema, or the merge scheduler.
3. On each default-branch pull request, GitHub creates the required checks in
3. On each pull request, including stacked pull requests targeting a feature
branch, GitHub creates the required checks in
the sibling context. Review judgment stays with OpenCode (and the
independent Noema reviewer). Mechanical branch update and merge stay with
GitHub Actions in that sibling context, using the configured central
Expand Down
36 changes: 36 additions & 0 deletions docs/adr/0001-central-review-stacked-pull-requests.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,36 @@
# ADR-0001: Central review for stacked pull requests

- Status: Accepted
- Date: 2026-08-20
- Owners: ContextualWisdomLab platform maintainers
- Figma File ID: N/A — this is a workflow and governance contract with no UI

## Decision

The organization ruleset `CWL Central required workflows` (`18156473`) applies
to every branch reference (`ref_name.include=["~ALL"]`) in inherited
repositories. Central OpenCode, Noema, security, and scheduler workflows stay
owned by `ContextualWisdomLab/.github` at `refs/heads/main`.

## Context

Stacked PRs target another feature branch, so a default-branch-only ruleset did
not materialize the central required workflow entrypoints. This left buyer-
visible changes with local checks but without the same independent review and
security evidence used for main-targeting PRs.

## Consequences

- Every stacked PR receives the same current-head governance entrypoints.
- The scheduler may dispatch review-only work for non-default base branches;
merge automation remains guarded by the PR's actual policy and checks.
- Branch-scope drift is detected by
`scripts/ci/audit_central_required_workflows.py` and its regression tests.
- No workflow is copied into a product repository, preserving the MSA control
boundary.

## Verification

The exact live ruleset was read before and after the change. TEPP PRs #158 and
#159 were re-read at their current heads before review-only dispatch. Hosted
Comment thread
coderabbitai[bot] marked this conversation as resolved.
Outdated
Checks remain authoritative for merge decisions.
24 changes: 15 additions & 9 deletions docs/doctoring/agent-mention-concurrency-isolation.md
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ Neither defect is evidence that the requesting maintainer, model, repository all
The permanent regression contracts were committed before their corresponding production changes.

- `tests/test_agent_mention_dispatch_payload_limit.py` requires both dispatch hops to stay at or below ten top-level payload properties and requires the router to reject an oversized payload before GitHub does.
- `tests/test_agent_mention_queue_isolation.py` requires the interactive route and scheduled sweep to use different job-level concurrency groups, with `queue: max` on the interactive route and no cancellation of in-progress interactive work.
- `tests/test_agent_mention_queue_isolation.py` requires the interactive route to have no replacing concurrency group while the scheduled sweep remains independently single-flight.

## Decision

Expand All @@ -34,31 +34,37 @@ merge_mode=disabled

The wrapper-to-scheduler payload carries exactly ten fields, including the three values that override unsafe scheduler defaults. The wrapper therefore remains review-only and cannot merge or update a branch.

### Isolated concurrency queues
### Non-replacing interactive routing

Concurrency is scoped to each job rather than the whole workflow:
The event-driven local route has no concurrency group, so each eligible
`issue_comment` event receives its own run. The scheduled sweep remains
single-flight and cannot cancel an interactive run:

```yaml
route-local-agent-mention:
concurrency:
group: review-agent-mention-router-local-${{ github.repository }}
queue: max
runs-on: ubuntu-24.04

sweep-organization-agent-mentions:
concurrency:
group: review-agent-mention-router-sweep-${{ github.repository }}
cancel-in-progress: false
```

GitHub documents that `queue: max` permits up to 100 pending jobs or workflow runs in one concurrency group and cannot be combined with `cancel-in-progress: true`. The interactive queue therefore retains bounded pending requests instead of replacing the previous pending request. Scheduled sweeps retain coalescing behavior in a separate group and cannot displace interactive work.
GitHub's supported concurrency contract permits at most one running and one
pending member per group, and a newly queued member replaces an older pending
member. The unsupported `queue: max` key cannot provide durability. Omitting a
local concurrency group is therefore the smallest supported boundary that does
not discard a trusted mention before its durable invocation claim exists.
Scheduled sweeps still coalesce in their separate group and cannot displace
interactive work.

Concurrency is not the idempotency authority. Duplicate forwarding remains governed by the complete canonical invocation key, exact-key downstream concurrency, and the immutable exact-name Actions artifact ledger.

## Preserved boundaries

- No model provider, reviewer identity, repository allowlist, token name, credential scope, or branch-protection rule changes.
- `COPILOT_GITHUB_TOKEN` remains unused.
- Workflow-default permissions remain read-only; existing bounded jobs keep only their required writes.
- Workflow-default permissions remain read-only; the local router has read-only Actions access and keeps only the content/comment writes required for dispatch and acknowledgement.
- Only trusted non-bot `OWNER`, `MEMBER`, or `COLLABORATOR` comments on open pull requests are eligible.
- Pull request number, exact head and base SHAs, base branch, source comment, requested agent, and requesting actor remain bound to the invocation key.
- Mention routing remains unable to approve, merge, update branches, publish, or release.
Expand All @@ -81,7 +87,7 @@ Do not restore either defective boundary:

- do not increase the first- or second-hop payload beyond GitHub's limit;
- do not move local and scheduled work back into one workflow-level concurrency group;
- do not replace `queue: max` with the default single-pending interactive queue unless another independently reviewed durable queue preserves every eligible request.
- do not add a local concurrency group whose default single-pending contract can replace an eligible interactive request before the durable claim exists.

A safe emergency degradation may suspend the scheduled sweep while retaining the isolated interactive route.

Expand Down
17 changes: 15 additions & 2 deletions docs/org-required-workflow-rollout.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# ContextualWisdomLab central required workflow rollout

Updated: 2026-07-23 06:35 KST
Updated: 2026-08-21 03:30 KST

## Decision

Expand All @@ -9,7 +9,7 @@ Use an organization repository ruleset instead of copying workflow files into ea
- Ruleset: `CWL Central required workflows`
- Ruleset ID: `18156473`
- Enforcement: `active`
- Target: branch rules on every repository's default branch (`repository_name.include=["~ALL"]`, `ref_name.include=["~DEFAULT_BRANCH"]`)
- Target: branch rules on every repository branch (`repository_name.include=["~ALL"]`, `ref_name.include=["~ALL"]`), including stacked pull-request base branches
Comment thread
coderabbitai[bot] marked this conversation as resolved.
Outdated
- Required workflow source repository: `ContextualWisdomLab/.github`
- Required workflow source repository ID: `1274066402`
- Active required workflow paths:
Expand All @@ -31,6 +31,19 @@ reports another ref, treat that as operations drift and restore ruleset

This keeps Strix security evidence, OpenCode and independent Noema review evidence, and merge/update automation sourced from the central `.github` repository. Target repositories do not need local copies of these workflows for the organization required workflow rule, and new repositories inherit the rule without a repository-name list update.

### Stacked pull-request coverage

On 2026-08-20, live PRs #158 and #159 in `ContextualWisdomLab/TEPP` targeted
`feat/lineageweave-live-consumer-contract` rather than `main`. They had product
checks but no centrally materialized OpenCode or Noema workflow runs because
the ruleset was scoped to `~DEFAULT_BRANCH`. Ruleset `18156473` now uses
`ref_name.include=["~ALL"]`; the existing scheduler already enumerates open
PRs across base branches and dispatches exact-head review-only work for
stacked PRs. The audit script and regression test enforce this scope so a
future ruleset rollback fails closed. The live repair also restored the
checked-in two-approval contract; workflow source, repository exclusions, and
stale-review/thread-resolution/last-push protections were preserved.

## OpenCode required workflow posture

The central `.github/workflows/opencode-review.yml` is now part of the active organization required workflow ruleset.
Expand Down
4 changes: 2 additions & 2 deletions scripts/ci/audit_central_required_workflows.py
Original file line number Diff line number Diff line change
Expand Up @@ -112,8 +112,8 @@ def audit_ruleset(payload: dict[str, Any]) -> list[str]:

ref_names = conditions.get("ref_name")
ref_names = ref_names if isinstance(ref_names, dict) else {}
if "~DEFAULT_BRANCH" not in (ref_names.get("include") or []):
errors.append("central ruleset does not target every default branch")
if "~ALL" not in (ref_names.get("include") or []):
errors.append("central ruleset does not target stacked and default-branch PRs")
Comment thread
coderabbitai[bot] marked this conversation as resolved.
Outdated

workflow_rules = _typed_rules(payload, "workflows")
if len(workflow_rules) != 1:
Expand Down
6 changes: 3 additions & 3 deletions tests/test_agent_mention_downstream_idempotency.py
Original file line number Diff line number Diff line change
Expand Up @@ -11,8 +11,8 @@
UPLOAD_ARTIFACT_SHA = "043fb46d1a93c77aae656e7c1c64a875d1fc6a0a"


def test_router_can_read_durable_central_artifacts() -> None:
"""Both local routing and sibling sweeping receive actions read access."""
def test_router_uses_read_only_actions_access_for_durable_artifacts() -> None:
"""Both local routing and sibling sweeping only read Actions artifacts."""

text = ROUTER_WORKFLOW.read_text(encoding="utf-8")
local, sweep = text.split("\n sweep-organization-agent-mentions:\n", 1)
Expand All @@ -33,7 +33,7 @@ def test_downstream_workflows_claim_artifacts_and_bind_exact_key() -> None:
assert "source_comment_id" in text
assert "requested_agent" in text
assert "cancel-in-progress: false" in text
assert "queue: max" in text
assert "queue: max" not in text
assert "cancel-in-progress: true" not in text
assert "^[0-9a-f]{64}$" in text
assert "^[1-9][0-9]*$" in text
Expand Down
23 changes: 10 additions & 13 deletions tests/test_agent_mention_queue_isolation.py
Original file line number Diff line number Diff line change
Expand Up @@ -22,13 +22,15 @@ def _job_block(workflow: str, job_name: str, next_job_name: str | None) -> str:
def _concurrency_block(job: str) -> str:
"""Return the job-scoped concurrency mapping before ``runs-on``."""

if " concurrency:\n" not in job:
return ""
start = job.index(" concurrency:\n")
end = job.index("\n runs-on:", start)
return job[start:end]


def test_interactive_mentions_and_sweeps_use_independent_queues() -> None:
"""A scheduled sweep cannot replace a pending trusted mention request."""
def test_interactive_mentions_run_without_a_replacing_concurrency_queue() -> None:
"""Every trusted mention receives a run while sweeps stay single-flight."""

workflow = WORKFLOW.read_text(encoding="utf-8")
header = workflow.split("\njobs:\n", 1)[0]
Expand All @@ -44,28 +46,23 @@ def test_interactive_mentions_and_sweeps_use_independent_queues() -> None:
)

assert not any(line.startswith("concurrency:") for line in header.splitlines())
assert _concurrency_block(local_job) == (
" concurrency:\n"
" group: review-agent-mention-router-local-${{ github.repository }}\n"
" queue: max"
)
assert _concurrency_block(local_job) == ""
assert _concurrency_block(sweep_job) == (
" concurrency:\n"
" group: review-agent-mention-router-sweep-${{ github.repository }}\n"
" cancel-in-progress: false"
)


def test_interactive_queue_retains_pending_requests_without_cancellation() -> None:
"""The bounded interactive queue retains work and never cancels in progress."""
def test_interactive_route_has_no_unsupported_or_replacing_queue_controls() -> None:
"""Interactive work is neither invalid YAML nor a replaceable pending run."""

workflow = WORKFLOW.read_text(encoding="utf-8")
local_job = _job_block(
workflow,
"route-local-agent-mention",
"sweep-organization-agent-mentions",
)
concurrency = _concurrency_block(local_job)

assert "queue: max" in concurrency
assert "cancel-in-progress: true" not in concurrency
assert _concurrency_block(local_job) == ""
assert "queue: max" not in local_job
assert "cancel-in-progress" not in local_job
13 changes: 11 additions & 2 deletions tests/test_central_required_workflow_ruleset_audit.py
Original file line number Diff line number Diff line change
Expand Up @@ -28,7 +28,7 @@ def ruleset_payload() -> dict:
"include": ["~ALL"],
"exclude": ["noema", "IRT-bibliography-set", ".github"],
},
"ref_name": {"include": ["~DEFAULT_BRANCH"], "exclude": []},
"ref_name": {"include": ["~ALL"], "exclude": []},
},
"rules": [
{
Expand Down Expand Up @@ -94,6 +94,15 @@ def test_inherited_ruleset_and_organization_scope_probes_pass() -> None:
assert audit.audit_ruleset(inherited_ruleset_payload()) == []


def test_default_branch_only_scope_rejects_stacked_pull_requests() -> None:
payload = ruleset_payload()
payload["conditions"]["ref_name"]["include"] = ["~DEFAULT_BRANCH"]

assert audit.audit_ruleset(payload) == [
"central ruleset does not target stacked and default-branch PRs"
]


def test_inherited_scope_allows_private_exclusion_outside_token_visibility() -> None:
payload = inherited_ruleset_payload()
payload[audit.INHERITED_SCOPE_FIELD].pop("IRT-bibliography-set")
Expand Down Expand Up @@ -204,7 +213,7 @@ def test_audit_reports_all_structural_and_protection_drift() -> None:
"central ruleset enforcement is not active",
"central ruleset does not include all repositories",
"central ruleset repository exclusions drifted: expected ['.github', 'IRT-bibliography-set', 'noema'], got []",
"central ruleset does not target every default branch",
"central ruleset does not target stacked and default-branch PRs",
"expected one workflows rule, found 0",
"missing central required workflow .github/workflows/close-empty-pr.yml",
"missing central required workflow .github/workflows/noema-review.yml",
Expand Down
Loading