Skip to content

fix(scheduler): casefold repository identity - #2007

Draft
seonghobae wants to merge 7 commits into
fix/scheduler-draft-merge-mutation-guardfrom
fix/scheduler-casefold-repository-identity
Draft

seonghobae wants to merge 7 commits into
fix/scheduler-draft-merge-mutation-guardfrom
fix/scheduler-casefold-repository-identity

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 7, 2026 •

Copy link
Copy Markdown
Contributor

Root cause

GitHub repository identity is case-insensitive, but scheduler owned-head and compare-ref routing used exact string equality. Canonical casing drift could therefore misclassify an organization-owned branch as an external fork and block normal restack/update processing.

This bounded successor carries the corresponding valid delta from historical Draft #1231 and remains stacked after repaired #2006.

RED → GREEN

Verification

Fresh detached verification at exact remote head de5e6220726b0b91a2482c36953bf379671eb340:

  • python -m py_compile scripts/ci/pr_review_merge_scheduler_core.py
  • python -m pytest tests/test_pr_review_merge_scheduler.py -q → 344 passed
  • GITHUB_ACTIONS=true python -W error -m pytest tests/test_pr_review_merge_scheduler.py -q → 344 passed
  • git diff --check 5e6fd0ca2fc052057b75473a528d533e346c131e..de5e6220726b0b91a2482c36953bf379671eb340

Prior Checks on 5e6fd0ca… are not transferred. Hosted Runtime Quality and security evidence is GREEN on this exact head; lifecycle-triggered replacement Checks, CodeQL settlement, and qualifying independent approval remain required before merge.

Stack and authority

  • Base: fix/scheduler-draft-merge-mutation-guard@d739e0d8d6285261da0a2f530181a929f19a202d
  • Fast-forward ref update only; no force push or rebase
  • No ownership, review, status, credential, or mutation permission is broadened
  • Status remains Proposed / Ready-for-review; this is review admission only, not merge authority
  • Pre-admission exact-head runs: Runtime Quality 34197136278 succeeded; CodeQL 34197136206 failed settlement; Python Security, SAST, and Security succeeded. Ready admission created replacement CodeQL 34202091140, Python Security 34202091202, SAST 34202090959, and Security 34202091133; these are not predecessor evidence and must terminate independently.

@coderabbitai

coderabbitai Bot commented Sep 7, 2026 •

Copy link
Copy Markdown
Contributor

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@seonghobae seonghobae added bug Something isn't working type: bug Defect or incorrect behavior priority: medium Normal-priority or P2 work labels Sep 7, 2026 — with ChatGPT Codex Connector
Preserve this PR's bounded RED→GREEN delta while integrating protected-main CodeQL fixes through its exact parent branch. No force update; both parent SHAs are recorded.
Preserve case-insensitive repository identity while inheriting the complete current-main scheduler stack and exact fixture repairs. No rebase or force update.

Copy link
Copy Markdown
Contributor Author

Current scheduler stack receipt — tip 5e6fd0ca2fc052057b75473a528d533e346c131e

Exact lineage:
main@78a4937 → #2002@b18b7ca → #2003@71e7678 → #2004@9fb02c9 → #2005@3f09f31 → #2006@fb552da → #2007@5e6fd0c.

Every edge is 0 behind its exact base and was reconciled with a normal merge commit. The tip inherits #2008/#2009 CodeQL coordinator fixes plus the permanent Runtime Quality fixture repairs for host-scoped cancellation calls and workflow-starting token proof. All six PRs remain Draft/Proposed; no predecessor check, review, or status was transferred. Five fresh hosted workflows exist on this exact tip and are still non-terminal.

Copy link
Copy Markdown
Contributor Author

Fresh stack verification: Runtime Quality succeeded on #2002@b18b7ca (run 34178933394), #2004@9fb02c9 (34179040923), #2005@3f09f31 (34179079329), #2006@fb552da (34179118151), and #2007@5e6fd0c (34179154325). #2003 intentionally lacks that trigger until #2004's restoration delta. CodeQL/SAST and other required evidence remain non-terminal on the respective exact heads, so every stack node remains Draft/Proposed; no child inherits a parent's status.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Exact-head bounded-delta review: no new substantive finding in this child’s case-insensitive repository-identity change. Both routing boundaries case-fold only already-equal GitHub repository identities, missing metadata retains the conservative behavior, and the focused regression covers owned-head/compare-ref semantics. This is not approval or merge authority: #2007 inherits the unresolved #2006 live Draft-race finding (review 5136886031), has no qualifying independent approval, and must remain Draft until the prerequisite is repaired and combined exact-head hosted evidence is regenerated.

Copy link
Copy Markdown
Contributor Author

Restack 착수: exact child 5e6fd0ca2fc052057b75473a528d533e346c131e는 repaired parent #2006 d739e0d8d6285261da0a2f530181a929f19a202d 이전 base fb552daf…에 남아 mergeable=false입니다. Child 고유 casefold delta를 보존하면서 parent exact head를 normal two-parent merge로 non-force 흡수하고, combined scheduler suite와 child 경계 회귀를 exact head에서 재검증하겠습니다. 현재 remote owner receipt나 active exact-head run은 보이지 않습니다. Force/rebase/bypass/close/lifecycle toggle은 사용하지 않습니다.

Copy link
Copy Markdown
Contributor Author

Restack complete at exact head de5e6220. This normal two-parent commit preserves prior child 5e6fd0ca… and repaired parent #2006 d739e0d8…; the remote ref moved fast-forward with force=false. Conflict reconciliation retained both the child casefold boundaries and parent live open/Draft/head mutation guard. Fresh detached exact-head evidence: py_compile PASS; normal scheduler suite 344 passed; GITHUB_ACTIONS=true -W error 344 passed; git diff --check PASS. Prior 5e6fd0ca… Checks are not transferred. Five new hosted workflows are queued, so #2007 remains Draft/Proposed pending exact-head evidence and independent review.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Exact-head re-review at de5e6220726b0b91a2482c36953bf379671eb340: the normal two-parent restack preserves the child casefold routing delta and repaired parent live open/Draft/head mutation guard. There are no unresolved inline threads. Current-head Runtime Quality, SAST, Python Security, and Security Scan are GREEN. CodeQL run 34197136206 is not GREEN: both language shards dispatched but terminated pending because no authenticated terminal verdict returned to rerun/settle them. That central handshake failure remains a merge blocker. No new substantive source finding in this bounded child; this COMMENT is not approval or merge authority.

@seonghobae
seonghobae marked this pull request as ready for review September 8, 2026 07:59
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 8, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-08T08:03:06.183518Z de5e622 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

Copy link
Copy Markdown
Contributor Author

Ready-for-review admission receipt for exact head de5e6220726b0b91a2482c36953bf379671eb340. Before transition the PR was open/Draft/mergeable, exact base #2006 remained d739e0d8d6285261da0a2f530181a929f19a202d, there were zero active runs and zero unresolved threads, and exact-head review 5138926199 found no new bounded child defect. Runtime Quality, SAST, Python Security, and Security Scan were terminal GREEN; CodeQL 34197136206 remained a central settlement failure and was not treated as GREEN. Ready created same-head replacement runs: SAST 34202090959, Security 34202091133, CodeQL 34202091140, Python Security 34202091202. They must terminate independently. Qualifying current-head approval, parent order, and required Checks still block merge; no auto-merge or bypass was configured.

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode reviewed the current-head product diff. Coverage is a separate gate.

Changed files

  • CHANGELOG.md — repository behavior
  • docs/doctoring/case-insensitive-owned-head-identity.md — operator or user guidance
  • docs/product-technical-gap-baseline.md — operator or user guidance
  • scripts/ci/pr_review_merge_scheduler_core.py — review and security gate shell path
  • tests/test_pr_review_merge_scheduler.py — regression suite

Changed behavior

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Repository file: CHANGELOG.md"]
  S1 --> I1["repository behavior"]
  I1 --> R1["Review risk: Repository file: CHANGELOG.md"]
  R1 --> V1["required checks"]
  Evidence --> S2["Docs: case-insensitive-owned-head-identity.md (2 files)"]
  S2 --> I2["operator or user guidance"]
  I2 --> R2["Review risk: Docs: case-insensitive-owned-head-identity.md (2 files)"]
  R2 --> V2["docs review"]
  Evidence --> S3["CI script: pr_review_merge_scheduler_core.py"]
  S3 --> I3["review and security gate shell path"]
  I3 --> R3["Review risk: CI script: pr_review_merge_scheduler_core.py"]
  R3 --> V3["bash -n plus Strix self-test"]
  Evidence --> S4["Test: test_pr_review_merge_scheduler.py"]
  S4 --> I4["regression suite"]
  I4 --> R4["Review risk: Test: test_pr_review_merge_scheduler.py"]
  R4 --> V4["targeted test run"]
Loading

Findings

No source-backed product finding is synthesized from the coverage gate. A coverage miss belongs in the status comment.

  • Head SHA: de5e6220726b0b91a2482c36953bf379671eb340
  • Workflow run: 34203237461
  • Workflow attempt: 1
  • Coverage gate: failure

Review outcome

Coverage is a gate, not the review. This body reviews the changed product files.

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Repository file: CHANGELOG.md"]
  S1 --> I1["repository behavior"]
  I1 --> R1["Review risk: Repository file: CHANGELOG.md"]
  R1 --> V1["required checks"]
  Evidence --> S2["Docs: case-insensitive-owned-head-identity.md (2 files)"]
  S2 --> I2["operator or user guidance"]
  I2 --> R2["Review risk: Docs: case-insensitive-owned-head-identity.md (2 files)"]
  R2 --> V2["docs review"]
  Evidence --> S3["CI script: pr_review_merge_scheduler_core.py"]
  S3 --> I3["review and security gate shell path"]
  I3 --> R3["Review risk: CI script: pr_review_merge_scheduler_core.py"]
  R3 --> V3["bash -n plus Strix self-test"]
  Evidence --> S4["Test: test_pr_review_merge_scheduler.py"]
  S4 --> I4["regression suite"]
  I4 --> R4["Review risk: Test: test_pr_review_merge_scheduler.py"]
  R4 --> V4["targeted test run"]
Loading

@opencode-agent

opencode-agent Bot commented Sep 8, 2026 •

Copy link
Copy Markdown
Contributor

OpenCode Review Overview

Coverage evidence did not pass, so approval is blocked. The formal pull-request review is the source-backed diff review, not this status comment.

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode reviewed the current-head product diff. Coverage is a separate gate.

Changed files

  • CHANGELOG.md — repository behavior
  • docs/doctoring/case-insensitive-owned-head-identity.md — operator or user guidance
  • docs/product-technical-gap-baseline.md — operator or user guidance
  • scripts/ci/pr_review_merge_scheduler_core.py — review and security gate shell path
  • tests/test_pr_review_merge_scheduler.py — regression suite

Changed behavior

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Repository file: CHANGELOG.md"]
  S1 --> I1["repository behavior"]
  I1 --> R1["Review risk: Repository file: CHANGELOG.md"]
  R1 --> V1["required checks"]
  Evidence --> S2["Docs: case-insensitive-owned-head-identity.md (2 files)"]
  S2 --> I2["operator or user guidance"]
  I2 --> R2["Review risk: Docs: case-insensitive-owned-head-identity.md (2 files)"]
  R2 --> V2["docs review"]
  Evidence --> S3["CI script: pr_review_merge_scheduler_core.py"]
  S3 --> I3["review and security gate shell path"]
  I3 --> R3["Review risk: CI script: pr_review_merge_scheduler_core.py"]
  R3 --> V3["bash -n plus Strix self-test"]
  Evidence --> S4["Test: test_pr_review_merge_scheduler.py"]
  S4 --> I4["regression suite"]
  I4 --> R4["Review risk: Test: test_pr_review_merge_scheduler.py"]
  R4 --> V4["targeted test run"]
Loading

Findings

No source-backed product finding is synthesized from the coverage gate. A coverage miss belongs in the status comment.

  • Head SHA: de5e6220726b0b91a2482c36953bf379671eb340
  • Workflow run: 34206225146
  • Workflow attempt: 1
  • Coverage gate: failure

Review outcome

Coverage is a gate, not the review. This body reviews the changed product files.

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Repository file: CHANGELOG.md"]
  S1 --> I1["repository behavior"]
  I1 --> R1["Review risk: Repository file: CHANGELOG.md"]
  R1 --> V1["required checks"]
  Evidence --> S2["Docs: case-insensitive-owned-head-identity.md (2 files)"]
  S2 --> I2["operator or user guidance"]
  I2 --> R2["Review risk: Docs: case-insensitive-owned-head-identity.md (2 files)"]
  R2 --> V2["docs review"]
  Evidence --> S3["CI script: pr_review_merge_scheduler_core.py"]
  S3 --> I3["review and security gate shell path"]
  I3 --> R3["Review risk: CI script: pr_review_merge_scheduler_core.py"]
  R3 --> V3["bash -n plus Strix self-test"]
  Evidence --> S4["Test: test_pr_review_merge_scheduler.py"]
  S4 --> I4["regression suite"]
  I4 --> R4["Review risk: Test: test_pr_review_merge_scheduler.py"]
  R4 --> V4["targeted test run"]
Loading

@seonghobae
seonghobae marked this pull request as draft September 8, 2026 16:22

Copy link
Copy Markdown
Contributor Author

Non-force parent reconciliation completed after #2006 advanced.

The case-folded repository routing delta, live Ready/Draft/head mutation boundary, and complete current parent prerequisites are preserved. Publication used an exact Git tree and force:false; no force push or rebase was used.

Detached combined verification:

  • scheduler + central inventory + CodeQL contracts: 394 passed under GITHUB_ACTIONS=true and -W error
  • python -m py_compile scripts/ci/pr_review_merge_scheduler_core.py → PASS
  • git diff --check → PASS

#2007 remains Draft/Proposed. Predecessor Checks and reviews do not transfer; fresh exact-head hosted Checks and a qualifying independent approval remain mandatory.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working priority: medium Normal-priority or P2 work type: bug Defect or incorrect behavior

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant