fix(governance): stage ConceptWeave Product ruleset enforcement - #2350
seonghobae wants to merge 47 commits into
Conversation
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
seonghobae
left a comment
There was a problem hiding this comment.
P1 runtime finding: the privileged verify-live and mutate-owner-plane jobs execute the new Python 3.10+ reconciler but do not install/pin Python at all. The validation job does, and canonical #1644 apply also does. On a GitHub-hosted runner this makes the live control path depend on the runner image's incidental Python, so the source can validate while the privileged path later fails before governance verification/mutation. Add the same pinned actions/setup-python@5fda3b95... / Python 3.12 boundary to both live jobs and contract-test that requirement. Do not weaken the Python requirement or fall back to whatever python happens to be on the image.
seonghobae
left a comment
There was a problem hiding this comment.
P1 activation-path correctness: _decode_workflow() uses base64.b64decode(content, validate=True) directly on the repository-contents API content field. GitHub's current REST documentation shows that field as line-wrapped base64 containing \n separators. Python strict base64 validation rejects those separators, so a legitimate protected-base .github/workflows/product.yml can fail before canary validation and make evaluate→active promotion impossible. Please preserve strict alphabet validation but normalize only GitHub's documented CR/LF wrapping before decoding, and add a regression that uses a line-wrapped contents payload. RED is a valid GitHub contents response that fails current _decode_workflow; GREEN is the same payload decoding exactly while malformed non-base64 remains fail-closed. Source: https://docs.github.com/en/rest/repos/contents#get-repository-content (current response example contains \n in content).
seonghobae
left a comment
There was a problem hiding this comment.
P1 hosted entrypoint failure confirmed by current run 35805657970: validate fails at Validate reviewed Product target manifest before any lifecycle tests. The workflow executes python scripts/ci/reconcile_conceptweave_product_ruleset.py, but that file imports scripts.ci.reconcile_ruleset_governance; direct script execution sets the import root to scripts/ci, so the package-qualified scripts.ci import is not a reliable CLI entrypoint. The same failure already existed at predecessor run 35805011918, so it is not caused by the wrapped-base64 repair. Repair the workflow to use the package entrypoint python -m scripts.ci.reconcile_conceptweave_product_ruleset for validate/verify/bootstrap/activate, and contract-test that direct-script invocation is absent. Do not paper over it with PYTHONPATH.
seonghobae
left a comment
There was a problem hiding this comment.
P1 — bootstrap create has a protected-main TOCTOU window. bootstrap_product_ruleset() checks expected_main_sha only at entry, then performs repository ruleset discovery before _create_evaluate_ruleset() issues the POST. If protected .github/main advances during that discovery/read window, the live repository ruleset can be created from a stale trusted source revision and only be rejected after the mutation already exists. Activation already rechecks immediately before its PUT. Bootstrap should do the same immediately before POST, with a regression that proves a second current-main check aborts before _create_evaluate_ruleset() is called. Do not paper over this in the workflow or with PYTHONPATH; keep the guard in the owner mutation boundary.
seonghobae
left a comment
There was a problem hiding this comment.
P1 — the immutable Product blob coordinate is parsed and _assert_base_product_workflow() can compare it, but neither live mutation path actually consumes it yet.
Current bootstrap_product_ruleset() calls _assert_base_product_workflow(target_main_sha) without manifest["product_workflow_blob_sha"]; therefore product_workflow_blob_sha: null does not fail closed and an evaluate ruleset can still be created from marker-compatible Product content. _canary_evidence() does the same unpinned call, and activate_product_ruleset() never requires a non-null reviewed blob coordinate before evaluate evidence or active PUT. That violates #2348's staged bootstrap contract and leaves the exact mutable-main gap this repair is intended to close.
Required repair after the currently queued exact-head owner run settles: add a contract RED proving bootstrap and activation reject null coordinates and marker-compatible blob drift before any POST/PUT, then thread the reviewed coordinate through bootstrap, canary admission and the final pre-PUT revalidation. Keep Product semantics ConceptWeave-owned; .github should compare only the immutable Contents blob coordinate plus existing marker/TOCTOU/ruleset-history guards. Do not pre-adopt #35's unlanded candidate blob.
seonghobae
left a comment
There was a problem hiding this comment.
P1 — the supported Foundation canary is still impossible without a governance-state manipulation because _canary_evidence() rejects draft=true. Canonical Foundation #1 is intentionally OPEN / Draft on main, and its ordinary/non-force parent reconciliation is supposed to produce the substantive pull_request:synchronize canary after #35 lands. GitHub's current ruleset-workflow contract does not require a PR to be Ready for synchronize: required workflows run on the default pull_request activities opened, synchronize, and reopened, and GitHub explicitly lists pushing/updating the branch as the way to trigger a newly required workflow on an already-open PR. A Ready transition is a different ready_for_review activity and is not a supported ruleset-workflow trigger.
Therefore, after the current 5289945740 mutation-boundary RED → repair → GREEN is complete, fold this into the separate supported-canary repair 5288830215: accept an open Draft Foundation PR as canary evidence while still requiring the exact PR number, substantive current head, current protected main base, reviewed Product blob, first-attempt terminal Product success from the supported pull_request:synchronize run, exact evaluate-mode workflows rule PASS, and no later source movement. Keep Ready/Draft toggling, reopen, no-op commits, manual reruns, predecessor evidence and administrator bypass explicitly invalid as canary evidence. Do not weaken the PR's own Draft/acceptance lifecycle merely to satisfy owner-plane activation.
Primary GitHub authority: https://docs.github.com/en/enterprise-cloud@latest/repositories/configuring-branches-and-merges-in-your-repository/managing-rulesets/troubleshooting-rules and https://docs.github.com/en/actions/reference/workflows-and-actions/events-that-trigger-workflows.
seonghobae
left a comment
There was a problem hiding this comment.
P1 follow-up on the mutation-boundary repair: the immutable Product blob is now revalidated before POST/PUT, but the network read itself re-opens the protected-ref TOCTOU window. Bootstrap currently checks .github/main and ConceptWeave main, then performs _assert_base_product_workflow(... expected_blob_sha=...), then POSTs without re-reading either protected ref. Activation does the same before active PUT. If either protected ref advances while the Contents request is in flight, the mutation can still be authorized from stale owner source/base evidence even though the immutable blob check itself passed. Preserve the current exact head until its owner run settles; then add a reality RED where the first ref checks and blob check succeed but a final ref read observes drift, and require both _assert_current_main(expected_main_sha) and _assert_target_main(base_sha/target_main_sha) after the blob revalidation and immediately before POST/PUT. Do not weaken or remove the blob coordinate guard; this is the final ordering guard around it.
|
2026-09-24 KST fresh coordination: #2350 source remains exact |
|
Fresh ConceptWeave owner-path correction: the Producer prerequisite paragraph in this PR body is now stale only for downstream CodeQL execution state. |
|
Authority correction — producer prerequisite only; no source/head change. The
The two scan failures remain #2350 itself remains exact |
|
Authority update — Ordinary-forward test-only head is now Fresh owner run Separate central CodeQL state remains owner-external: #35 downstream Python/Actions shards completed scan + Medium+ SARIF and fail only at GHAS configuration-identity verification; only settlement remains queued. Keep that under #1929/#2275/#2276 rather than moving ConceptWeave source. |
|
Exact-current correction (2026-09-24 KST): PR head is
Owner run Separately, ConceptWeave #35 downstream settlement |
seonghobae
left a comment
There was a problem hiding this comment.
Review 5294002721 has now produced attributable hosted RED on 1a6ddce2.../35944402217. Current 97acdfeef0830d56c7b9b78226fec53de791ee8f is the minimal causal repair: exactly two protected-ref reads after the final Product blob validation in bootstrap and two in activation, immediately before POST/PUT. No policy/workflow/manifest/test/live-state delta is included. Keep the finding open until owner run 35961585829 is terminal GREEN; do not transfer predecessor GREEN.
|
Current-head RCA / repair update (2026-09-24 KST)
The failure is attributable to a retained success-path unit expectation, not the four-line production repair. Ordinary-forward test-only repair: New exact owner run |
|
A concurrent ordinary-forward commit, |
|
Ordinary-forward repair published at exact head Attributable predecessor RED remains run Local evidence on the identical published tree:
The live-mutation jobs were not invoked. Keep this PR Draft / merge HOLD: fresh hosted exact-head evidence is still required, and the branch must then be non-force reconciled from recorded #1644 base |
|
Non-force stack reconciliation completed at exact head The commit has ordinary parents Exact merged-tree local verification:
Fresh hosted runs are terminal but not GREEN: Product validate Keep Draft / Proposed / HOLD. No blind rerun, wake commit, Ready toggle, bypass, or merge. |
|
Ready admission completed on the unchanged exact head Preconditions re-read immediately before transition:
Ready is review admission only, not merge authorization. Fresh same-head Security, Semgrep, and CodeQL runs were created, but every entry job failed before executable steps ( @opencode-agent please revalidate the unchanged exact head/tree after the ordinary #1644 restack. Treat predecessor reviews as stale unless their reviewed delta/tree is mechanically proven equivalent. Keep merge HOLD until executable current-head Checks and a qualifying independent approval exist. |
Purpose
Repair ConceptWeave Product ruleset activation without weakening the owner-plane boundary. This remains a dependent Ready PR on #1644. Ready admits review only; source publication does not authorize merge or perform a live ruleset mutation.
Current authority — 2026-10-03
fix/ruleset-owner-plane-reconciler@cf6627439ecf99413f49a3c4ca7f9a81ffda972d1f0e2edfb1883ffb7073440d2b15acf87d77b686b1f759aa3f09d132310b9f4d2538d258b2cfba35cf662743...The non-force stack repair preserved both #1644 G-17–G-19 evidence and this PR's G-20 Product-canary delta. No Force Push or destructive rebase was used.
Attributable RED
Test-only head
1e8da05d5b0851da212b3e340e7085fb1de550ceproduced hosted run36010121000, validate job107668353987. Exact checkout and setup completed;Prove Product ruleset lifecycle contractfailed because production rejected the canonical OPEN / Draft Foundation canary and required_latest_base_retarget()instead of substantivepull_request:synchronizeevidence.Result: 2 failed, 66 passed. Mutation and live-verification jobs were skipped.
The same source generation also exposed the repository-wide contract failure that central workflows must not offer branch-selected
workflow_dispatch.Ordinary-forward repair
.github/main, protected ConceptWeavemain, reviewed Product workflow blob, and exact canary PR head/base immediately before active PUT.workflow_dispatchwith namedrepository_dispatch, loaded from protected default-branch code and bound toexpected_main_sha == github.sha.Verified merge-result evidence
On the exact merged tree
b1f759aa...:373statements,142branches)compileall: PASSgit diff --check: PASSExact-head hosted evidence
Run
37126448652(ConceptWeave Product Ruleset Reconcile) ended FAILURE before executable steps: validate job111212568762hassteps=[].verify-liveandmutate-owner-planewere skipped.The same exact head has:
37126448625/ job111212568480: FAILURE,steps=[], log artifactBlobNotFound37126448631: gitleaks111212568588and scope111212568722failed withsteps=[]; dependent jobs skipped37126448681: skipped under Draft admissionThe Ready admission event then created fresh same-head runs without changing source:
37127911156/111216918347: FAILURE,steps=[]37127911112: gitleaks111216918192and scope111216918215failed withsteps=[]37127911160: language detection111216918356failed withsteps=[]; downstream dispatch/compatibility jobs skippedThese are pre-execution runner/admission failures, not acceptable GREEN. They are recorded for canonical runner RCA; no blind rerun or wake commit is authorized. This PR remains Ready / Proposed / HOLD until executable exact-head Checks, independent review/approval, and protected ordinary integration exist.
Required order
main.synchronizerun as evaluate evidence.The Ready event is review admission only and is not canary, Check, approval, or merge evidence. No self-approval, synthetic status/reviewer, direct protected-branch write, routine administrator bypass, manual/blind rerun, or no-op wake is authorized.
Refs #2348, #1644, #772, #1351, #2356, ContextualWisdomLab/ConceptWeave#35, ContextualWisdomLab/ConceptWeave#1.