fix: pin NOEMA_LLM_MODEL routing alias to orchestrator/free - #535
Conversation
|
Important Review skippedToo many files! This PR contains 171 files, which is 71 over the limit of 100. To get a review, reduce the PR to 100 files or fewer by splitting it into smaller PRs or changing its base branch. Upgrade to a paid plan to raise the limit. This review couldn't start because sufficient usage credits or metered capacity aren't available. Add credits or update usage-based reviews in the billing tab, then retry. ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (171)
You can disable this status message by setting the Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Cross-repo consistency check from a session that's spent this pass deep in Two things this PR does that line up cleanly with what the directive requires elsewhere in the org, worth having on record as independent cross-repo confirmation:
No blocking concerns from this reading — flagging for the record, not asking for changes. Generated by Claude Code |
Merge conflict resolution:
|
Reviewer-ci + verify failures on
|
|
Fresh protected-base repair supersedes the stale authority block. Protected |
|
2026-09-06 KST post-#546 repair finding: protected semantic reviewer truth is now |
…context admission
…ted context admission
Preserve PR-scoped verification while seeding the patch-validator BuildKit cache from path-bounded protected-main changes. Exact head 2f91bf8 had terminal success for CI, reviewer-ci, required Security Scan, and patch-validator-image with clean fresh review authority and current-main ancestry.
* test(docs): expose post-547 commercial authority drift * test(docs): require current active commercial lanes * docs: refresh commercial gap authority after #547 * test: advance patch-validator candidate authority * test: reject superseded patch-validator candidate * docs: refresh patch-validator exact authority * test: require current #535 commercial authority * docs: repair current commercial authority after hosted RED * test(docs): require live post-558 commercial authority Require the documentation lane to reflect protected #558 integration, the newly converged #535 exact head, and the newly observed #556 stacked head before production baseline text is repaired. * docs(gap): repair post-558 live commercial authority Bring #559's owned baseline in line with protected #558 integration, exact #535 convergence, and the newly observed #556 stack while preserving canonical owner boundaries and release-evidence discipline. * test(docs): require latest observed #556 authority Advance the documentation contract to the live #556 successor after its hosted release-test RED, while rejecting the superseded observation. Production baseline text follows in the causal repair commit. * docs(gap): record live #556 successor and hosted RED Update #559's sole documentation authority to the latest #556 exact head, preserve the observed hosted release-test failure as historical evidence, and keep the downstream stack non-authorizing until #535 reaches protected main. * test(docs): require current #535 endpoint-repair authority * docs: track current #535 gateway endpoint repair * test(docs): require #535 coverage-repair authority * docs: track #535 coverage-gate repair * test(docs): require current central control-plane snapshot * docs: refresh central control-plane snapshot * test(docs): retire stale commercial authority assertions * docs: refresh protected and claim-evidence authority * test(docs): track protected #535 integration * test(docs): track current claim-evidence head * test(docs): bind post-535 protected authority * test(docs): refresh current candidate contract * test(docs): align claim-binding authority wording * docs: refresh claim-evidence candidate authority * test(docs): match hosted run authority casing * docs: refresh live Noema commercial authority * test(docs): track current Noema feature authority * test(docs): bind commercial gap to live feature heads * test(docs): require settled external-extension authority * docs: converge commercial gap to current plugin admission * test(docs): track active policy-approval RED * docs: bind commercial gap to policy-approval RED * docs: restore durable commercial gap owners * docs: align external-extension authority after restack * test: bind documentation authority to restacked #560 * test(d(docs): require complete gap authority schema * docs: bind gap status to architecture authorities * test(docs): reject stale tool-capability candidate * docs: refresh current tool-capability evidence * docs: refresh active extension authority * docs: bind extension event chronology evidence * docs: refresh extension chronology authority * docs: bind gap baseline to hostile admission repair * test(docs): bind live candidate to admission repair * test(docs): preserve candidate ADR authority wording * docs: refresh external-extension runtime-time authority * test(docs): bind current runtime-time candidate authority * test(docs): refresh live external-extension candidate authority * docs: bind gap authority to invocation replay repair * docs: converge on public replay authority repair * docs: converge on activation revocation repair * docs: converge on admission-bound invocation authority * docs: bind commercial gap to exact admission provenance * test(docs): require exact-admission candidate authority * test(docs): bind candidate contract to exact admission * docs: track crypto-provider RED authority * test(docs): bind external-extension authority to Web Crypto repair * docs: converge external-extension Web Crypto authority * test(docs): follow current external-extension authority * test(docs): assert public receipt binding authority * test(docs): match activation revocation authority wording * docs: converge baseline after #560 protected integration * test: bind documentation authority to #560 integration * test: treat external-extension admission as protected history * test: extend protected integration history through #560 * test: move external-extension gap to lifecycle successor
Scope and ownership
Noema consumes the governed
orchestrator/freecontract only.ContextualWisdomLab/contextual-orchestratorowns provider/model discovery, routing, credentials, retry and failover. This lane owns Noema reviewer/config/privacy/tool/gateway-preflight boundaries;docs/product-technical-gap-baseline.mdremains #559's documentation lane.Verified RED → causal repair lineage
The earlier stale candidate was ordinary/non-force converged, then hosted CI
34169700288exposed a real release-test RED: the model-bearing proposer still used repository-selected${{ vars.NOEMA_LLM_MODEL }}and a 55-minute wall clock while the executable contract required literalorchestrator/freeand no repository-authored model timeout. Production97718814382112079d1348db5f2b6ee44d94687bsource-pinnedorchestrator/freeand removed onlypropose_product_increment.timeout-minuteswhile preserving work-conserving admission, immutable proposal validation and provider-owner boundaries.After #547 became protected source, test-only
f1bca1b44bc9b1cf5f67c200380aaeed8c67bb2fproduced hosted CI RED34177131397(1 failed / 4140 passed) because two procedure documents still restored a superseded global-empty-PR admission rule.06ed62fcc5611e9b25ef38b06e87e7521dbf1be1repaired only that documentation authority.Protected #558 convergence
#558 subsequently integrated as protected
main@59ae66de96b64c8ce51f0030a624815a08dbefdd. The branch was advanced without force by ordinary two-parent convergence while preserving the #558 patch-validator workflow/cache truth. Fresh compare remains ahead-only,behind_by=0, with merge-base exactly protected main.Python endpoint authority RED → repair
Fresh review found a cross-language contract defect. JavaScript gateway preflight and
contracts/orchestrator-gateway.jsonreject direct-provider hosts, URL userinfo/query/fragment and non-/v1endpoints, while the Python reviewer boundary only required HTTPS (or loopback HTTP). A direct provider or malformed OpenAI-compatible HTTPS endpoint could therefore receive the gateway credential even while the model alias remainedorchestrator/free.Test-only
9d67a3cff2700ec2672f78ea05a5e464e7857360added executable cases for the six forbidden direct-provider hosts, URL authority metadata,/v1shape and a valid contextual-orchestrator-compatible endpoint. Productione0a329916ab71b1009aa62cbab667a737d511223minimally applied the same endpoint invariant inreviewer/noema_reviewer/config.py, preserving exactorchestrator/free,AsyncOpenAI(timeout=None, max_retries=0), loopback-only HTTP development support and contextual-orchestrator provider/model ownership.Reviewer-ci
34182299455, job101923650070, then supplied a concrete coverage RED: all 631 reviewer tests passed, but mandatory line+branch coverage was 99.93%, leaving the hostless-URL rejection branch uncovered. Exact82b20b293f0a5f0ac0e69857c1b61dddfe478491adds only the missinghttps:///v1regression so the implemented fail-closed branch is exercised; production behavior did not change in this follow-up.Current exact-head authority — 2026-09-08 KST
Exact head remains
82b20b293f0a5f0ac0e69857c1b61dddfe478491; fresh compare against protectedmain@59ae66de96b64c8ce51f0030a624815a08dbefddremainsbehind_by=0with exact protected merge-base. Fresh current-head checks are:34182693606: SUCCESS;34182693512: SUCCESS;34182693575: SUCCESS;34182693666: IN_PROGRESS.Three GREEN gates do not authorize merge. Keep Draft until the unchanged image gate is terminal-success, then re-read current head/base, all review threads and all four gates immediately before ordinary merge. Predecessor evidence, self-approval, force update, destructive rebase, provider-authority copy, timeout/gate weakening and release fabrication remain prohibited.
#556 is downstream. Its current stacked exact head
363d62bc888e7b9555ff56bbce4dadc0a61d4efbis not final-integration authority while #535 is unmerged, and its required Security Scan is currently absent due central stacked-ruleset undercoverage tracked atContextualWisdomLab/.github#2037. After #535 normal integration, #556 must be re-read and ordinary/non-force restacked from resulting protected source with fresh Security-inclusive evidence.