Skip to content

fix(governance): stage ConceptWeave Product ruleset enforcement - #2350

Open
seonghobae wants to merge 47 commits into
fix/ruleset-owner-plane-reconcilerfrom
fix/conceptweave-product-ruleset-bootstrap
Open

seonghobae wants to merge 47 commits into
fix/ruleset-owner-plane-reconcilerfrom
fix/conceptweave-product-ruleset-bootstrap

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Purpose

Repair ConceptWeave Product ruleset activation without weakening the owner-plane boundary. This remains a dependent Ready PR on #1644. Ready admits review only; source publication does not authorize merge or perform a live ruleset mutation.

Current authority — 2026-10-03

  • base branch / exact base: fix/ruleset-owner-plane-reconciler@cf6627439ecf99413f49a3c4ca7f9a81ffda972d
  • current exact head: 1f0e2edfb1883ffb7073440d2b15acf87d77b686
  • current exact tree: b1f759aa3f09d132310b9f4d2538d258b2cfba35
  • topology: ordinary two-parent merge; 47 ahead / 0 behind fix(governance): automate ruleset owner-plane reconciliation #1644, merge base cf662743...
  • OPEN / Ready / mechanically mergeable
  • approvals: 0
  • merge authorization: HOLD
  • no Product-specific ruleset was created, updated, activated, or verified live

The non-force stack repair preserved both #1644 G-17–G-19 evidence and this PR's G-20 Product-canary delta. No Force Push or destructive rebase was used.

Attributable RED

Test-only head 1e8da05d5b0851da212b3e340e7085fb1de550ce produced hosted run 36010121000, validate job 107668353987. Exact checkout and setup completed; Prove Product ruleset lifecycle contract failed because production rejected the canonical OPEN / Draft Foundation canary and required _latest_base_retarget() instead of substantive pull_request:synchronize evidence.

Result: 2 failed, 66 passed. Mutation and live-verification jobs were skipped.

The same source generation also exposed the repository-wide contract failure that central workflows must not offer branch-selected workflow_dispatch.

Ordinary-forward repair

  • Admit OPEN / Draft only when the final timeline commit equals the exact live PR head.
  • Reject malformed identity, no-op/non-substantive commits, stale bases, later commits, Ready/Draft toggles, reopen events, manual reruns, predecessor runs, and later PR movement.
  • Bind first-attempt repository-owned Product success and evaluate-mode workflow-rule PASS to exact PR/head/base and synchronize time.
  • Revalidate protected .github/main, protected ConceptWeave main, reviewed Product workflow blob, and exact canary PR head/base immediately before active PUT.
  • Remove the now-uncalled base-retarget helper and obsolete fixtures.
  • Replace branch-selected workflow_dispatch with named repository_dispatch, loaded from protected default-branch code and bound to expected_main_sha == github.sha.
  • Retain protected environment, dedicated administration token, explicit enable variable, serialized non-cancellable mutation, immutable-history settlement, and fail-closed recovery.

Verified merge-result evidence

On the exact merged tree b1f759aa...:

  • warning-fatal full suite: 5392 passed, 11 skipped, 40 subtests passed
  • Product/queue contracts: 147 passed
  • Product lifecycle coverage suite: 75 passed
  • reconciler statement/branch coverage: 100% (373 statements, 142 branches)
  • public-doc coverage: 100%
  • compileall: PASS
  • worktree git diff --check: PASS
  • GitHub-created tree exactly equals the locally verified merge tree

Exact-head hosted evidence

Run 37126448652 (ConceptWeave Product Ruleset Reconcile) ended FAILURE before executable steps: validate job 111212568762 has steps=[]. verify-live and mutate-owner-plane were skipped.

The same exact head has:

  • SAST Semgrep 37126448625 / job 111212568480: FAILURE, steps=[], log artifact BlobNotFound
  • Security Scan 37126448631: gitleaks 111212568588 and scope 111212568722 failed with steps=[]; dependent jobs skipped
  • CodeQL PR 37126448681: skipped under Draft admission

The Ready admission event then created fresh same-head runs without changing source:

  • SAST Semgrep 37127911156 / 111216918347: FAILURE, steps=[]
  • Security 37127911112: gitleaks 111216918192 and scope 111216918215 failed with steps=[]
  • CodeQL 37127911160: language detection 111216918356 failed with steps=[]; downstream dispatch/compatibility jobs skipped

These are pre-execution runner/admission failures, not acceptable GREEN. They are recorded for canonical runner RCA; no blind rerun or wake commit is authorized. This PR remains Ready / Proposed / HOLD until executable exact-head Checks, independent review/approval, and protected ordinary integration exist.

Required order

  1. fix(governance): automate ruleset owner-plane reconciliation #1644 lands through ordinary protection and remains the canonical generic ruleset owner plane.
  2. fix(governance): stage ConceptWeave Product ruleset enforcement #2350 reacquires executable exact-head Checks and independent review on the unchanged merged tree, then lands with no live Product mutation.
  3. chore(ci): bootstrap Product pull-request workflow ConceptWeave#35 lands normally and publishes Product on protected ConceptWeave main.
  4. Adopt the immutable protected Product workflow blob and positive evaluate-ruleset identity through reviewed source.
  5. Ordinary/non-force reconcile the Foundation canary; use its substantive Draft synchronize run as evaluate evidence.
  6. Activate only after exact canary/evaluate PASS and immediate live revalidation.

The Ready event is review admission only and is not canary, Check, approval, or merge evidence. No self-approval, synthetic status/reviewer, direct protected-branch write, routine administrator bypass, manual/blind rerun, or no-op wake is authorized.

Refs #2348, #1644, #772, #1351, #2356, ContextualWisdomLab/ConceptWeave#35, ContextualWisdomLab/ConceptWeave#1.

@coderabbitai

coderabbitai Bot commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 35c81a22-9d8f-4c5e-895e-be46df15133f

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@seonghobae seonghobae added area: ci-cd CI, GitHub Actions, checks, release, or supply chain bug Something isn't working priority: high High-priority or P1 work status: blocked Blocked by conflict, dependency, or required prerequisite type: bug Defect or incorrect behavior labels Sep 23, 2026 — with ChatGPT Codex Connector

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 runtime finding: the privileged verify-live and mutate-owner-plane jobs execute the new Python 3.10+ reconciler but do not install/pin Python at all. The validation job does, and canonical #1644 apply also does. On a GitHub-hosted runner this makes the live control path depend on the runner image's incidental Python, so the source can validate while the privileged path later fails before governance verification/mutation. Add the same pinned actions/setup-python@5fda3b95... / Python 3.12 boundary to both live jobs and contract-test that requirement. Do not weaken the Python requirement or fall back to whatever python happens to be on the image.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 activation-path correctness: _decode_workflow() uses base64.b64decode(content, validate=True) directly on the repository-contents API content field. GitHub's current REST documentation shows that field as line-wrapped base64 containing \n separators. Python strict base64 validation rejects those separators, so a legitimate protected-base .github/workflows/product.yml can fail before canary validation and make evaluate→active promotion impossible. Please preserve strict alphabet validation but normalize only GitHub's documented CR/LF wrapping before decoding, and add a regression that uses a line-wrapped contents payload. RED is a valid GitHub contents response that fails current _decode_workflow; GREEN is the same payload decoding exactly while malformed non-base64 remains fail-closed. Source: https://docs.github.com/en/rest/repos/contents#get-repository-content (current response example contains \n in content).

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 hosted entrypoint failure confirmed by current run 35805657970: validate fails at Validate reviewed Product target manifest before any lifecycle tests. The workflow executes python scripts/ci/reconcile_conceptweave_product_ruleset.py, but that file imports scripts.ci.reconcile_ruleset_governance; direct script execution sets the import root to scripts/ci, so the package-qualified scripts.ci import is not a reliable CLI entrypoint. The same failure already existed at predecessor run 35805011918, so it is not caused by the wrapped-base64 repair. Repair the workflow to use the package entrypoint python -m scripts.ci.reconcile_conceptweave_product_ruleset for validate/verify/bootstrap/activate, and contract-test that direct-script invocation is absent. Do not paper over it with PYTHONPATH.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 — bootstrap create has a protected-main TOCTOU window. bootstrap_product_ruleset() checks expected_main_sha only at entry, then performs repository ruleset discovery before _create_evaluate_ruleset() issues the POST. If protected .github/main advances during that discovery/read window, the live repository ruleset can be created from a stale trusted source revision and only be rejected after the mutation already exists. Activation already rechecks immediately before its PUT. Bootstrap should do the same immediately before POST, with a regression that proves a second current-main check aborts before _create_evaluate_ruleset() is called. Do not paper over this in the workflow or with PYTHONPATH; keep the guard in the owner mutation boundary.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 — the immutable Product blob coordinate is parsed and _assert_base_product_workflow() can compare it, but neither live mutation path actually consumes it yet.

Current bootstrap_product_ruleset() calls _assert_base_product_workflow(target_main_sha) without manifest["product_workflow_blob_sha"]; therefore product_workflow_blob_sha: null does not fail closed and an evaluate ruleset can still be created from marker-compatible Product content. _canary_evidence() does the same unpinned call, and activate_product_ruleset() never requires a non-null reviewed blob coordinate before evaluate evidence or active PUT. That violates #2348's staged bootstrap contract and leaves the exact mutable-main gap this repair is intended to close.

Required repair after the currently queued exact-head owner run settles: add a contract RED proving bootstrap and activation reject null coordinates and marker-compatible blob drift before any POST/PUT, then thread the reviewed coordinate through bootstrap, canary admission and the final pre-PUT revalidation. Keep Product semantics ConceptWeave-owned; .github should compare only the immutable Contents blob coordinate plus existing marker/TOCTOU/ruleset-history guards. Do not pre-adopt #35's unlanded candidate blob.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 — the supported Foundation canary is still impossible without a governance-state manipulation because _canary_evidence() rejects draft=true. Canonical Foundation #1 is intentionally OPEN / Draft on main, and its ordinary/non-force parent reconciliation is supposed to produce the substantive pull_request:synchronize canary after #35 lands. GitHub's current ruleset-workflow contract does not require a PR to be Ready for synchronize: required workflows run on the default pull_request activities opened, synchronize, and reopened, and GitHub explicitly lists pushing/updating the branch as the way to trigger a newly required workflow on an already-open PR. A Ready transition is a different ready_for_review activity and is not a supported ruleset-workflow trigger.

Therefore, after the current 5289945740 mutation-boundary RED → repair → GREEN is complete, fold this into the separate supported-canary repair 5288830215: accept an open Draft Foundation PR as canary evidence while still requiring the exact PR number, substantive current head, current protected main base, reviewed Product blob, first-attempt terminal Product success from the supported pull_request:synchronize run, exact evaluate-mode workflows rule PASS, and no later source movement. Keep Ready/Draft toggling, reopen, no-op commits, manual reruns, predecessor evidence and administrator bypass explicitly invalid as canary evidence. Do not weaken the PR's own Draft/acceptance lifecycle merely to satisfy owner-plane activation.

Primary GitHub authority: https://docs.github.com/en/enterprise-cloud@latest/repositories/configuring-branches-and-merges-in-your-repository/managing-rulesets/troubleshooting-rules and https://docs.github.com/en/actions/reference/workflows-and-actions/events-that-trigger-workflows.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 follow-up on the mutation-boundary repair: the immutable Product blob is now revalidated before POST/PUT, but the network read itself re-opens the protected-ref TOCTOU window. Bootstrap currently checks .github/main and ConceptWeave main, then performs _assert_base_product_workflow(... expected_blob_sha=...), then POSTs without re-reading either protected ref. Activation does the same before active PUT. If either protected ref advances while the Contents request is in flight, the mutation can still be authorized from stale owner source/base evidence even though the immutable blob check itself passed. Preserve the current exact head until its owner run settles; then add a reality RED where the first ref checks and blob check succeed but a final ref read observes drift, and require both _assert_current_main(expected_main_sha) and _assert_target_main(base_sha/target_main_sha) after the blob revalidation and immediately before POST/PUT. Do not weaken or remove the blob coordinate guard; this is the final ordering guard around it.

Copy link
Copy Markdown
Contributor Author

2026-09-24 KST fresh coordination: #2350 source remains exact a1628e75dc056098f4ea2d03ec799f2026025e84; owner run 35891410528 / validate 107284521412 is still queued before runner assignment, so preserve this exact repair head and do not stage review 5294002721 yet. ConceptWeave#35 central CodeQL downstream run 35870670165 has progressed independently: validate-dispatch 107213600319 is terminal SUCCESS on the bound PR/head/base tuple, while scan jobs 107322443235 (python) and 107322443261 (actions) remain queued. This narrows #35's central blocker but does not change the Product-ruleset sequence: exact owner evidence here → 5294002721 RED/final protected-ref revalidation/GREEN → separate 5288830215 + 5291871021 canary repair → normal source landing with no live Product mutation.

Copy link
Copy Markdown
Contributor Author

Fresh ConceptWeave owner-path correction: the Producer prerequisite paragraph in this PR body is now stale only for downstream CodeQL execution state. .github run 35870670165 still binds the exact ConceptWeave#35@d7b7e30b278ec2f27096b4d313c7d5eaf5387ddc / base f4f440dd58c77d7cd90dff8a1eb2eeb9a9940425 / required 35825042996 tuple. validate-dispatch 107213600319 is SUCCESS. Both language jobs have now run: Python 107322443235 and Actions 107322443261 each completed exact-head materialization, CodeQL init/analysis, and the Medium+ SARIF gate, then failed only at Verify GHAS base/head CodeQL configuration identity; SARIF preservation and dispatch-status publication completed afterward. The new settle exact required run job 107396154783 is the remaining runnerless queued job. This narrows the central path to .github#1929/#2275/#2276 for GHAS identity/credential plus settlement admission, and does not justify moving ConceptWeave#35 or this #2350 source. Current #2350 exact head remains a1af52d7bf2fcb5dfd27790961faf62651b16510; owner validate 107374677579 is still queued with runner_id=0 and no steps, so preserve this head and do not start 5294002721 yet.

Copy link
Copy Markdown
Contributor Author

Authority correction — producer prerequisite only; no source/head change.

The Producer prerequisite paragraph in the current PR body is stale where it says downstream CodeQL python/actions scans remain queued. Fresh 35870670165 state is:

  • validate-dispatch 107213600319: terminal SUCCESS;
  • python 107322443235: terminal FAILURE only at Verify GHAS base/head CodeQL configuration identity, after exact-head materialization, CodeQL analysis, and Medium+ SARIF gate succeeded; evidence preservation/status publication succeeded;
  • actions 107322443261: same terminal failure boundary and same preceding successes;
  • settle exact required run 107396154783: current runnerless queue specimen ([ubuntu-24.04], runner_id=0, steps=[]).

The two scan failures remain .github#1929/#2275/#2276-owned GHAS identity/credential evidence, not ConceptWeave source defects. The queue specimen is now recorded on bounded continuation issue #2356 (comment 5805398442) rather than unwritable #712.

#2350 itself remains exact a1af52d7bf2fcb5dfd27790961faf62651b16510; owner run 35918073452 / validate 107374677579 is still queued pre-runner. Preserve this exact head. Review 5294002721 remains sequenced only after exact owner GREEN.

Copy link
Copy Markdown
Contributor Author

Authority update — a1af52d7bf2fcb5dfd27790961faf62651b16510 is now exact owner GREEN: Product Ruleset Reconcile 35918073452 completed SUCCESS. This settles the prior 100% coverage repair and unlocks review 5294002721.

Ordinary-forward test-only head is now 1a6ddce2d02df50dddeb81450ff05cb9778c94a9 (test(governance): prove post-blob protected ref drift). It changes only the bootstrap/activation race tests. The new contract covers both protected refs (.github/main and ConceptWeave main) and requires that a ref advancing during the final exact Product blob read causes fail-closed behavior with zero evaluate create / zero active PUT. Production reconciler code is intentionally unchanged so this head remains the reality-RED candidate.

Fresh owner run 35944402217 / validate 107459043420 is queued before runner assignment with no steps. Preserve this exact head until the owner run settles; do not no-op wake, blind-rerun, or apply the production fix early. If it reaches the intended RED, the minimum causal repair is to re-read both protected refs immediately after final blob validation and immediately before _create_evaluate_ruleset() / active PUT, then reacquire exact-head GREEN.

Separate central CodeQL state remains owner-external: #35 downstream Python/Actions shards completed scan + Medium+ SARIF and fail only at GHAS configuration-identity verification; only settlement remains queued. Keep that under #1929/#2275/#2276 rather than moving ConceptWeave source.

Copy link
Copy Markdown
Contributor Author

Exact-current correction (2026-09-24 KST): PR head is 1a6ddce2d02df50dddeb81450ff05cb9778c94a9, not the stale body coordinate a1af52d....

a1af52d7bf2fcb5dfd27790961faf62651b16510 completed the prior coverage-repair gate successfully. 1a6ddce... is the subsequent test-only reality contract for review 5294002721: bootstrap and activation tests stage protected .github/main / ConceptWeave-main drift during successful Product Contents/blob validation and require evaluate POST / active PUT to remain uncalled. Production reconciler behavior is intentionally unchanged on this head.

Owner run 35944402217 remains queued before execution. Preserve this exact head until terminal evidence. If it produces the intended RED, apply only the causal production repair: re-read both protected refs after successful blob validation and immediately before mutation, retain the immutable blob check, then reacquire exact-head GREEN. Do not fold the later supported-synchronize / OPEN-Draft canary repair (5288830215 + 5291871021) into this head.

Separately, ConceptWeave #35 downstream settlement 107396154783 has now left the queue and completed FAILURE at its settlement step; that is central lifecycle evidence, not a reason to move this Product-governance head.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review 5294002721 has now produced attributable hosted RED on 1a6ddce2.../35944402217. Current 97acdfeef0830d56c7b9b78226fec53de791ee8f is the minimal causal repair: exactly two protected-ref reads after the final Product blob validation in bootstrap and two in activation, immediately before POST/PUT. No policy/workflow/manifest/test/live-state delta is included. Keep the finding open until owner run 35961585829 is terminal GREEN; do not transfer predecessor GREEN.

Copy link
Copy Markdown
Contributor Author

Current-head RCA / repair update (2026-09-24 KST)

97acdfeef0830d56c7b9b78226fec53de791ee8f is no longer queued evidence. Owner run 35961585829 reached hosted runner 1002120081 and failed in Prove Product ruleset lifecycle contract after exact checkout/revision/tooling/manifest validation; mutate-owner-plane and verify-live remained skipped, so no live Product-specific ruleset mutation occurred.

The failure is attributable to a retained success-path unit expectation, not the four-line production repair. bootstrap_product_ruleset() now intentionally revalidates both protected refs once more immediately after the final reviewed Product blob read and before evaluate POST, while retaining the existing post-create settlement checks. test_bootstrap_create still expected only 3 .github/main checks and 2 ConceptWeave-main checks; the repaired control flow correctly performs 4 and 3 respectively.

Ordinary-forward test-only repair: 04414c5e30ba6aed2bf3d82268b356c6d6b1ad84 (test(governance): align bootstrap ref revalidation expectations). The commit changes only those two call-count assertions. Production code, workflow, manifest, policy shape, canary semantics, and live ruleset state are unchanged.

New exact owner run 35983462019 / validate 107580552666 is currently queued on [ubuntu-24.04] with no runner and steps=[]. Preserve 04414c5... until terminal exact evidence; no blind rerun/no-op wake. Review 5294002721 remains open until this exact head is GREEN.

Copy link
Copy Markdown
Contributor Author

5294002721 is now evidence-complete. Exact test-only successor 04414c5e30ba6aed2bf3d82268b356c6d6b1ad84 reached terminal owner GREEN in run 35983462019; validate 107580552666 completed SUCCESS on hosted runner 1002122732, including exact checkout/revision, hash-locked tooling, reviewed Product manifest validation, and the lifecycle contract. mutate-owner-plane and verify-live were skipped, so no live Product-specific ruleset state changed. This closes the post-blob protected-ref ordering finding without transferring predecessor GREEN.

A concurrent ordinary-forward commit, 1e8da05d5b0851da212b3e340e7085fb1de550ce, is one test-only commit ahead of 04414c5... and is adopted as the separate 5288830215 + 5291871021 supported-canary RED candidate. It adds OPEN-Draft and no-base-retarget expectations only; current production still rejects Draft and calls _latest_base_retarget(). Preserve 1e8da05... until exact owner run 36010121000 reaches terminal hosted evidence; do not pre-apply the repair or manufacture a wake.

Copy link
Copy Markdown
Contributor Author

Ordinary-forward repair published at exact head 2abbe740c84f97345d9f96ee87900a7836daf628, tree 423785817ef2f6da686f6e4d3c7d9bfbf88622e9.

Attributable predecessor RED remains run 36010121000 / validate 107668353987: 2 failed, 66 passed at the supported OPEN-Draft / synchronize contract. The repair also closes the independently reproduced central-workflow violation by replacing branch-selected workflow_dispatch with protected-default-branch repository_dispatch bound to the exact main SHA.

Local evidence on the identical published tree:

  • full warning-fatal suite: 3270 passed, 1 skipped, 36 subtests passed
  • Product lifecycle suite: 75 passed
  • reconciler statement + branch coverage: 100% (373 statements / 142 branches)
  • public-doc coverage: 100%
  • compileall and diff check: PASS

The live-mutation jobs were not invoked. Keep this PR Draft / merge HOLD: fresh hosted exact-head evidence is still required, and the branch must then be non-force reconciled from recorded #1644 base 722fec9... to current #1644 head cf662743... without discarding any delta.

Copy link
Copy Markdown
Contributor Author

Non-force stack reconciliation completed at exact head 1f0e2edfb1883ffb7073440d2b15acf87d77b686, tree b1f759aa3f09d132310b9f4d2538d258b2cfba35.

The commit has ordinary parents 2abbe740... (supported Product synchronize repair) and current #1644 cf662743.... Fresh comparison is 47 ahead / 0 behind, merge base cf662743...; the only semantic conflict was the gap ledger, resolved by preserving #1644 G-17–G-19 and #2350 G-20.

Exact merged-tree local verification:

  • full warning-fatal suite: 5392 passed, 11 skipped, 40 subtests passed
  • Product/queue contracts: 147 passed
  • Product lifecycle: 75 passed, 100% statement/branch coverage
  • public-doc coverage 100%, compileall PASS, worktree diff check PASS

Fresh hosted runs are terminal but not GREEN: Product validate 111212568762, Semgrep 111212568480, Security gitleaks 111212568588, and Security scope 111212568722 all ended before executable steps with steps=[]; CodeQL was Draft-skipped. Mutation and live-verification jobs were skipped. Canonical runner evidence is recorded in #2356 comment 5969658709.

Keep Draft / Proposed / HOLD. No blind rerun, wake commit, Ready toggle, bypass, or merge.

@seonghobae
seonghobae marked this pull request as ready for review October 3, 2026 13:56

Copy link
Copy Markdown
Contributor Author

Ready admission completed on the unchanged exact head 1f0e2edfb1883ffb7073440d2b15acf87d77b686.

Preconditions re-read immediately before transition:

  • OPEN / Draft / mechanically mergeable
  • exact base cf662743..., 47 ahead / 0 behind
  • unresolved review threads: 0
  • CHANGES_REQUESTED: 0
  • approvals: 0
  • no status: draft label
  • locally verified exact merge-result tree b1f759aa...

Ready is review admission only, not merge authorization. Fresh same-head Security, Semgrep, and CodeQL runs were created, but every entry job failed before executable steps (steps=[]); downstream jobs skipped. No Product mutation job ran and the Product workflow was not manufactured from the Ready event.

@opencode-agent please revalidate the unchanged exact head/tree after the ordinary #1644 restack. Treat predecessor reviews as stale unless their reviewed delta/tree is mechanically proven equivalent. Keep merge HOLD until executable current-head Checks and a qualifying independent approval exist.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: ci-cd CI, GitHub Actions, checks, release, or supply chain bug Something isn't working priority: high High-priority or P1 work status: blocked Blocked by conflict, dependency, or required prerequisite type: bug Defect or incorrect behavior

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant