Skip to content

docs(doctoring): OpenCode exact-head dispatch audit (2026-09-17) - #2255

Open
seonghobae wants to merge 21 commits into
mainfrom
docs/opencode-exact-head-dispatch-audit-20260917
Open

seonghobae wants to merge 21 commits into
mainfrom
docs/opencode-exact-head-dispatch-audit-20260917

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 17, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Strix now includes the five unchanged Job Analysis authority files from the trusted base when a pull request changes packages/hris-kernel/src/orgmetra_hris_kernel/job_analysis.py, and the executable fixture requires that bounded context.
  • The commercial-readiness receipt contract compares the complete harden-runner endpoint set.
  • The OpenCode exact-head dispatch audit from 2026-09-17 stays as a doctoring record.
  • This branch is merged with current main. The trusted fixture still copies strix_report_scope.py and runs the gate from the trusted runtime.

Test plan

  • tests/test_strix_trusted_fixture_boundary.py, the evidence-binder path test, the commercial-readiness receipt contract, and the product gap baseline contracts passed locally.
  • STRIX_TEST_CASE_FILTER=pull-request-target-job-analysis-authority-context bash scripts/ci/test_strix_quick_gate.sh passed.
  • Fresh exact-head required checks and an independent current-head approval are still required before merge.

Record the /tmp/docs-review-dispatch.json snapshot: 2 redispatched
(#2215, #2226), 11 skipped, 0 errors.

Co-authored-by: Cursor <cursoragent@cursor.com>
@coderabbitai

coderabbitai Bot commented Sep 17, 2026 •

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

Next included review available in 1 minute.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 459c5b02-6fca-4d75-af67-7591ce01cfd5

📥 Commits

Reviewing files that changed from the base of the PR and between 3295c25 and 68544b4.

📒 Files selected for processing (7)
  • CHANGELOG.d/20260920-strix-trusted-binder-runtime-fixture.md
  • CHANGELOG.md
  • docs/doctoring/opencode-exact-head-dispatch-audit-20260917.md
  • docs/product-technical-gap-baseline.md
  • scripts/ci/strix_quick_gate.sh
  • scripts/ci/test_strix_quick_gate.sh
  • tests/test_organization_commercial_readiness_loop_receipt_contract.py

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@seonghobae seonghobae added documentation Improvements or additions to documentation priority: high High-priority or P1 work labels Sep 19, 2026 — with ChatGPT Codex Connector
seonghobae and others added 18 commits September 20, 2026 06:27
…e the consumer root

Green step for a8d6261. The 24 specialized cases in
test_strix_quick_gate.sh installed the trusted gate/model/binder into
$repo_root_dir/scripts/ci and ran ./scripts/ci/strix_quick_gate.sh, so a
consumer-root binder lookup could never fail there and masked the #2292
defect. Each case now materializes into
$tmp_dir/trusted-source/scripts/ci and runs the gate from that directory
with STRIX_REPO_ROOT=$repo_root_dir, which keeps the old repo-root
semantics (the gate defaults REPO_ROOT to SCRIPT_DIR/../..).

Evidence:
- tests/test_strix_trusted_fixture_boundary.py: fails on a8d6261 (CI
  job 106083294309), passes here.
- bash scripts/ci/test_strix_quick_gate.sh on Linux, umask 022:
  a8d6261 PASS (rc=0, 727s) and this commit PASS (rc=0, 726s).
- strix-related pytest (8 files): 242 passed.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01P5o6j4zfxGPdRaH4Lug8UY

Copy link
Copy Markdown
Contributor Author

Admission correction — exact current head 8057a8a3c272bd99f56b1fea46c0d3eef145de8c was re-fetched immediately before this transition. The PR remains Open and its branch, commits, reviews, and valid delta are preserved, but it is not merge-admissible: terminal workflow failure: Python Security:failure. Moving it to Draft/Proposed records the live blocker without retiring or closing the work. Return it to Ready only after the same exact head (or a non-destructive reconciled successor) is mergeable, has no substantive unresolved review state, and has terminal required Checks.

@seonghobae
seonghobae marked this pull request as draft September 26, 2026 17:01

Copy link
Copy Markdown
Contributor Author

Run 35276488677 / job 105464236317 reported the two stale B310 findings.

Root-cause repair (exact-head preserving, non-force).

The failed Python Security evidence was inherited from the stale central base, not introduced by this PR's documentation delta. I ordinary-restacked this branch on current canonical security/CodeQL owner #2291 (b90d873e67860944308d5cef919a1f95243ef98f) using a two-parent commit; the PR remains Open and Draft.

Post-restack evidence:

  • effective delta versus fix(strix): resolve evidence binder from trusted source #2291: exactly one existing docs/doctoring/ file;
  • no force push or history rewrite;
  • git diff --check: clean;
  • current owner security validation on the reconstructed tree: Bandit MEDIUM+/MEDIUM+ scan 0 findings; test_strix_runtime_dependencies.py + test_codeql_scan_dispatch_ghas_credential_contract.py: 5 passed.

New exact head: 0ce27f058e435a7fee7699823e02f41b8b5a1cb3. Fresh hosted Checks are required before any Ready/merge decision; queued, pending, skipped, or absent Checks are not GREEN.

Copy link
Copy Markdown
Contributor Author

Concurrent-head re-audit: 0ce27f058e435a7fee7699823e02f41b8b5a1cb3 (base main@e6334e229581a918e2f22de18733b76fa65d7e71, 45 ahead / 0 behind).

새 head는 0-behind·mergeable·미해결 thread 0·활성 CHANGES_REQUESTED 0·terminal workflow failure 0입니다. Checks는 queued/pending이나 review admission blocker가 아니므로 Ready로 복구합니다.

이전 head의 approval/Checks는 병합 근거로 승계하지 않습니다. Current head의 terminal Checks와 qualifying independent approval 전에는 merge하지 않습니다.

@seonghobae
seonghobae marked this pull request as ready for review September 26, 2026 17:13
Resolve the trusted-fixture, changelog, and gap-baseline conflicts so the
gate still copies strix_report_scope.py, executes from the trusted runtime,
and adds the five trusted-base Job Analysis collaborators.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation priority: high High-priority or P1 work

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant