Skip to content

fix(dispatch): skip stale dispatches for closed PRs or superseded heads - #2382

Draft
seonghobae wants to merge 27 commits into
mainfrom
fix/dispatch-skip-stale-head
Draft

seonghobae wants to merge 27 commits into
mainfrom
fix/dispatch-skip-stale-head

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

Status

Ready / Proposed. Ordinary-forward convergence at exact head d9e31329e2e0361e904aef3072984ec1b4e076cd is review-admissible; fresh exact-head Checks and independent approval remain merge gates, not Ready prerequisites.

Stack

Summary

  • A dispatch for a closed PR, or for a head proven older than the PR's current head (compare API reports ahead with behind_by 0), now exits with a notice instead of failing.
  • Draft PRs are not skipped.
  • The EVENT_NAME asymmetry between the CodeQL and OpenCode dispatch workflows is intentional.
  • The race between reading the PR head and dispatching is closed via the compare API.

Validation

  • Original symptom RED: the fix(dispatch): skip stale dispatches for closed PRs or superseded heads #2382 coverage build context lacked the trusted Noema document lock.
  • Integrated invariant and owner/consumer contracts: 541 passed, 2 skipped.
  • Full Python regression suite on the exact convergence tree: 3402 passed, 28 skipped, 40 subtests passed.
  • Local 100% coverage was not claimed: this runner lacks cargo, so 25 Rust materializer tests skip and the report is 99%; hosted exact-head evidence must settle that environment.
  • python -m interrogate is unavailable in this runner; hosted Runtime Quality remains authoritative.
  • compileall, staged/unstaged git diff --check, merge-parent identity, and six-path successor delta checks passed.
  • Fresh hosted runs for the current head are queued.

Note

Open PR #2363 also edits opencode-review-dispatch.yml and its pinned hash, so whichever of the two merges second needs a rebase.

Summary by CodeRabbit

  • 변경 사항
    • 대상 PR이 닫혔거나 현재 변경사항이 디스패치 당시 변경사항에서 이어졌음이 확인되면, CodeQL 및 OpenCode 디스패치를 성공적으로 종료합니다.
    • 오래된 디스패치에서는 CodeQL 검사와 OpenCode의 커버리지 및 리뷰 단계를 건너뜁니다.
    • CodeQL 분석에 접근할 수 있는 인증 정보를 확인한 뒤 검사 결과를 검증합니다.
    • 그 외 검증 실패나 변경사항의 연관성을 확인할 수 없는 경우에는 기존처럼 처리합니다.

seonghobae and others added 23 commits September 18, 2026 18:39
Semgrep OSS and Bandit B310 Medium alerts on main flagged dynamic urllib
use in CodeQL identity and Strix evidence helpers. Fail closed unless the
URL is https://api.github.com so file:// and arbitrary hosts cannot reach
urlopen.

Co-authored-by: Cursor <cursoragent@cursor.com>
Bumps [anyio](https://github.com/agronholm/anyio) from 4.14.0 to 4.14.2.
- [Release notes](https://github.com/agronholm/anyio/releases)
- [Commits](agronholm/anyio@4.14.0...4.14.2)

---
updated-dependencies:
- dependency-name: anyio
  dependency-version: 4.14.2
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Replace retired urllib urlopen monkeypatches with direct CodeQL and Strix dedicated-opener patches. Remove the PR-specific global conftest bridge so both security helpers exercise the same explicit transport boundary without live network access.
Clears Bandit/Semgrep B310 on shared scripts/ci urlopen so the anyio bump is not blocked by unrelated SAST.
Restore the unrelated #2269 URL-opener paths to protected main while retaining the AnyIO 4.14.2 pin and hashes. The URL/redirect responsibility remains in canonical #2279; this PR owns only the dependency security update.

Validated with 56 focused tests, 3,335 full tests plus 28 skipped/40 subtests, warnings-as-errors, diff check, and pip-audit reporting no known vulnerabilities.
Remove the unused queue-health collector and CLI, validate run IDs at the shared parsing boundary, and exercise document-reader and scheduler edge cases. The main baseline failed the 100% gate before PR #2358.
…tead of failures

A dispatch whose target PR is closed, or whose live head has moved strictly
past the dispatched head, ends validate with a ::notice:: and stale=true;
later jobs are gated on that output so the run concludes success.

A head mismatch alone is not treated as stale: GitHub can briefly serve the
previous head right after a push. Retirement requires the compare API
(repos/{target}/compare/{dispatched}...{live}) to answer status "ahead" with
behind_by 0 and ahead_by >= 1. Behind (API lag), diverged (force-push), or a
failed/malformed compare keeps the original fail-closed head_sha mismatch.

The OpenCode side keeps its EVENT_NAME == repository_dispatch guard because
its authorization and supplied-head binding are nested under that check;
CodeQL triggers only on repository_dispatch and authorizes unconditionally,
so it needs no guard. Tests pin both premises. Draft PRs are not stale.
@coderabbitai

coderabbitai Bot commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 5369d489-95d1-4ab3-853e-7cd6baddbc96

📥 Commits

Reviewing files that changed from the base of the PR and between 3d03521 and d9e3132.

📒 Files selected for processing (20)
  • .github/workflows/codeql-scan-dispatch.yml
  • .github/workflows/opencode-review-dispatch.yml
  • CHANGELOG.md
  • docs/product-technical-gap-baseline.md
  • requirements-strix-ci-hashes.txt
  • requirements-strix-ci.txt
  • scripts/ci/actions_queue_health.py
  • scripts/ci/actions_queue_health_core.py
  • tests/test_actions_queue_health_cancelled_before_runner.py
  • tests/test_actions_queue_health_post_evidence_retry.py
  • tests/test_actions_queue_health_snapshot_consistency.py
  • tests/test_actions_queue_health_terminal_preexecution.py
  • tests/test_codeql_scan_dispatch_ghas_credential_contract.py
  • tests/test_noema_document_review_context.py
  • tests/test_noema_review_document_boundaries.py
  • tests/test_opencode_agent_contract.py
  • tests/test_organization_commercial_readiness_loop_receipt_contract.py
  • tests/test_pr_review_autofix_nvidia_nim_contract.py
  • tests/test_pr_review_merge_scheduler.py
  • tests/test_strix_runtime_dependencies.py

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

CodeQL과 OpenCode dispatch 검증이 닫힌 PR 또는 compare API로 확인된 후속 head를 stale로 표시합니다. stale dispatch에서는 관련 scan, coverage 및 review 작업을 건너뜁니다. CodeQL은 분석 읽기 권한이 있는 인증 정보를 선택합니다. Queue-health 코드, coverage 이미지 입력, Strix 의존성 및 계약 테스트도 갱신합니다.

Changes

Stale dispatch 처리 및 CodeQL 인증

Layer / File(s) Summary
CodeQL stale 검증 및 분석 인증
.github/workflows/codeql-scan-dispatch.yml, tests/test_codeql_scan_dispatch_workflow_contract.py, tests/test_codeql_scan_dispatch_ghas_credential_contract.py, CHANGELOG.d/20260926-dispatch-stale-head-skip.md
닫힌 PR 또는 dispatched SHA가 live head의 strict ancestor인 경우 stale dispatch를 성공적으로 종료합니다. stale이면 scan을 건너뜁니다. SARIF gate 통과 후 분석 읽기 권한을 확인한 인증 정보를 GHAS 구성 신원 확인에 사용합니다. 테스트가 stale 판별, 인증 선택 순서 및 후속 제어를 확인합니다.
OpenCode stale 검증 및 후속 작업 제어
.github/workflows/opencode-review-dispatch.yml, tests/test_opencode_review_dispatch_stale_skip.py, CHANGELOG.d/20260926-dispatch-stale-head-skip.md
repository_dispatch에서 닫힌 PR 또는 확인된 후속 head를 stale로 처리합니다. stale이면 coverage 및 review 관련 작업을 건너뜁니다. 테스트가 정상 경로, stale 경로 및 기존 fail-closed 검증을 확인합니다.

OpenCode coverage 이미지 입력

Layer / File(s) Summary
Coverage 잠금 파일 검증 및 설치
.github/workflows/opencode-review-dispatch.yml, tests/test_opencode_agent_contract.py, CHANGELOG.md, docs/product-technical-gap-baseline.md
Coverage 이미지 빌드에 Noema 문서 요구사항 파일을 추가합니다. workflow는 파일이 일반 파일이고 심볼릭 링크가 아닌지 확인한 뒤 build directory에 설치합니다. 계약 테스트와 문서가 해당 입력을 기록합니다.

Actions queue-health 수집 코드

Layer / File(s) Summary
Workflow run ID 검증 및 수집기 변경
scripts/ci/actions_queue_health.py, scripts/ci/actions_queue_health_core.py, tests/test_actions_queue_health_post_evidence_retry.py, tests/test_actions_queue_health_cancelled_before_runner.py, tests/test_actions_queue_health_terminal_preexecution.py
Core가 workflow run의 boolean, 비정수 또는 양수가 아닌 ID를 거부합니다. Wrapper의 ID 사전 검사는 제거되고, core의 collect_snapshot과 CLI 진입점도 삭제됩니다. 테스트가 수집 오류, 재시도 및 보고서의 external_actions 보존을 확인합니다.
Queue-health 계약 테스트 조정
tests/test_actions_queue_health_snapshot_consistency.py, tests/test_pr_review_merge_scheduler.py
권한 선언 테스트가 top-level 및 들여쓰기된 선언을 각각 검사합니다. Scheduler 테스트 fixture에서 다른 workflow의 성공 실행 순서를 변경합니다.

Strix CI 의존성 갱신

Layer / File(s) Summary
anyio 버전 및 잠금 해시 갱신
requirements-strix-ci.txt, requirements-strix-ci-hashes.txt, tests/test_strix_runtime_dependencies.py
Strix CI 요구사항과 해시 잠금 파일의 anyio 버전을 4.14.2로 갱신하고, 두 파일의 고정 버전을 확인하는 테스트를 추가합니다.

기타 계약 및 문서 테스트 갱신

Layer / File(s) Summary
문서 입력 경계 테스트
tests/test_noema_document_review_context.py, tests/test_noema_review_document_boundaries.py
잘못된 Base64 입력이 문서 판독기에 전달되기 전에 실패하는지 확인합니다. 추가 테스트가 문서 형식·크기, DOCX·HWP 처리 및 CLI 결과를 검증합니다.
독립 workflow 및 endpoint 계약 조정
tests/test_pr_review_autofix_nvidia_nim_contract.py, tests/test_organization_commercial_readiness_loop_receipt_contract.py
독립 review-agent workflow의 기대 blob SHA를 변경합니다. Endpoint 계약 테스트는 허용 목록에 대한 집합 부분집합 검사를 사용합니다.

Priority: ⬇️ Low

Estimated code review effort: 4 (Complex) | ~45 minutes

Change: Bug fix

Sequence Diagram(s)

sequenceDiagram
  participant Dispatch
  participant ValidateDispatch
  participant GitHubCompareAPI
  participant Scan
  participant CredentialProbe
  participant GHASIdentityCheck
  Dispatch->>ValidateDispatch: PR 메타데이터 전달
  ValidateDispatch->>GitHubCompareAPI: head 불일치 시 SHA 비교
  GitHubCompareAPI-->>ValidateDispatch: compare 결과 반환
  ValidateDispatch-->>Scan: stale가 아니면 scan 실행
  Scan->>CredentialProbe: SARIF gate 통과 후 분석 읽기 권한 확인
  CredentialProbe-->>GHASIdentityCheck: 확인된 인증 정보 전달
Loading

Merge Risk: ⚪ Minimal · up to d9e31

No actionable issue remains from this review. Merge after the required exact-head hosted checks pass.

Security Architecture Review

Security architecture risk: 🔵 Low · up to d9e31

The dispatch paths now skip only closed PRs or heads proven superseded, while other mismatches continue through validation. No introduced security finding was established. Some upstream authorization and deployment details remain unverified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The security-relevant reach is the authorized target-repository dispatch path, its CI credentials, coverage execution, and downstream review publication. The changed stale gates reduce work on proven obsolete heads; they do not establish a broader target scope.

Trust Boundaries and Controls

  • observed — Dispatch actor and sender checks and live PR metadata binding precede downstream work. A differing head is retired only on a strict-ancestor comparison; other disagreements continue to validation rather than becoming successful stale results.
  • observed — Coverage lock validation and installation precede its image build. The privileged OpenCode review job requires non-stale validation and non-cancelled coverage, with a later live-head check before publication.

Resilience and Maintainability Implications

  • inferred — The fail-closed comparison path, credential-read probe, and downstream stale conditions limit the effect of malformed or superseded dispatch data. Protection of allowlist variables and behavior of external dispatch producers remain outside the established evidence.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 77.27% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 66 functions across 16 files. (6 skipped:… Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed 제목은 닫힌 PR과 이전 head를 가진 오래된 dispatch를 건너뛰는 변경을 정확하고 간결하게 설명합니다.
Full details: Docstring Coverage

Explanation

Docstring coverage is 77.27% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 66 functions across 16 files. (6 skipped: 6 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

- Select a target-scoped credential that can actually read code-scanning
  analyses before the GHAS base/head configuration identity check, instead
  of the first non-empty token (the OpenCode app token returns 403).
  Ported from #2275.
- Replace the set-membership URL assertion flagged by CodeQL
  py/incomplete-url-substring-sanitization with an issubset check.
  Ported from #2351.
Preserve #2385, #2359, and #2286 as explicit parents while composing their byte-identical overlapping locks and endpoint contract. This creates one exact-head bootstrap stack for the coverage-image, 100% coverage, AnyIO audit, and CodeQL dispatch failures without force-push, rebase, or delta disposal.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 dependency / single-writer repair — current exact head 3d0352198303ad055e751f1f5580313a687a2638 cannot be accepted on protected main@e6334e22….

Exact-log RCA for Python Security run 36220837176, job 108362326873, shows the hard gate audited requirements-strix-ci-hashes.txt and found AnyIO 4.14.0 vulnerable to CVE-2026-63374, CVE-2026-64847, and CVE-2026-63349; all require 4.14.2. This is a real dependency finding, not queue saturation or transport failure.

Canonical lock/source repair already exists in #2385@8e1aba9c: it adds anyio==4.14.2 to the source requirements, updates the hashed lock, and pins source↔lock parity. Do not copy a second lock repair here. The heads are diverged at main@e6334e22…: this PR is ahead 1 / behind 25 relative to #2385, and both modify .github/workflows/opencode-review-dispatch.yml.

Required order: settle #2385 first, then ordinary/non-force restack this branch on its accepted head while preserving only the unique stale-dispatch retirement delta and reconciling the shared OpenCode workflow. Re-run every exact-head gate after reconciliation; predecessor receipts do not transfer. Runtime Quality 36220837157, SAST 36220837165, and Security 36220837182 passed, but Python Security failed and CodeQL 36220837170 remains queued. Ready is review admission only; no merge, auto-merge, bypass, synthetic status, or blind rerun is authorized.

Copy link
Copy Markdown
Contributor Author

Exact-head admission correction for 3d0352198303ad055e751f1f5580313a687a2638.

Exact-head Python Security run 36220837176, job 108362326873, found AnyIO 4.14.0 vulnerable to CVE-2026-63374, CVE-2026-64847, and CVE-2026-63349 (fixed in 4.14.2). The canonical source/lock convergence is .github#2385; this leaf is not allowed to copy or bypass it.

The PR stays open with its complete delta and review evidence preserved. Draft is Proposed/not merge-admissible, not completion. No rerun, bypass, synthetic status, force update, review dismissal, or Close is performed.

@seonghobae
seonghobae marked this pull request as draft September 26, 2026 10:00
@seonghobae
seonghobae changed the base branch from main to fix/codeql-dispatch-unblock September 26, 2026 18:55
@seonghobae
seonghobae changed the base branch from fix/codeql-dispatch-unblock to main September 26, 2026 18:55

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Exact-head/base dependency finding for 3d0352198303ad055e751f1f5580313a687a2638.

Canonical foundation parent #2385 is still open at 8e1aba9ce1d52acb36f095da32511da06958733f. A direct base retarget was tested and GitHub reported the child unmergeable. The cause is concrete three-path ownership overlap:

  • .github/workflows/codeql-scan-dispatch.yml
  • .github/workflows/opencode-review-dispatch.yml
  • tests/test_pr_review_autofix_nvidia_nim_contract.py

The child’s six-path stale-dispatch delta remains preserved: the base was restored to protected main@e6334e229581a918e2f22de18733b76fa65d7e71, the head was never moved or rewritten, and GitHub recomputed the PR as mergeable on that original base. Pre-parent Checks cannot be used as post-convergence evidence.

Required order: settle #2385 normally; then create an ordinary non-force successor/restack that resolves the three overlapping paths while preserving both the foundation and stale-dispatch contracts; finally acquire fresh exact-head/base Checks and independent review. Do not force-push, drop the child delta, or treat #2385 evidence as inherited passing proof.

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode reviewed the current-head product diff. Coverage is a separate gate.

Changed files

  • .github/workflows/codeql-scan-dispatch.yml — GitHub Actions review job
  • .github/workflows/opencode-review-dispatch.yml — GitHub Actions review job
  • CHANGELOG.d/20260926-dispatch-stale-head-skip.md — repository behavior
  • tests/test_codeql_scan_dispatch_workflow_contract.py — regression suite
  • tests/test_opencode_review_dispatch_stale_skip.py — regression suite
  • tests/test_pr_review_autofix_nvidia_nim_contract.py — regression suite

Changed behavior

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Workflow: codeql-scan-dispatch.yml"]
  S1 --> I1["GitHub Actions review job"]
  I1 --> R1["Review risk: Workflow: codeql-scan-dispatch.yml"]
  R1 --> V1["actionlint plus required checks"]
  Evidence --> S2["Workflow: opencode-review-dispatch.yml"]
  S2 --> I2["GitHub Actions review job"]
  I2 --> R2["Review risk: Workflow: opencode-review-dispatch.yml"]
  R2 --> V2["actionlint plus required checks"]
  Evidence --> S3["Repository file: 20260926-dispatch-stale-head-skip.md"]
  S3 --> I3["repository behavior"]
  I3 --> R3["Review risk: Repository file: 20260926-dispatch-stale-head-skip.md"]
  R3 --> V3["required checks"]
  Evidence --> S4["Test: test_codeql_scan_dispatch_workflow_contract.py (3 files)"]
  S4 --> I4["regression suite"]
  I4 --> R4["Review risk: Test: test_codeql_scan_dispatch_workflow_contract.py (3 files)"]
  R4 --> V4["targeted test run"]
Loading

Findings

No source-backed product finding is synthesized from the coverage gate. A coverage miss belongs in the status comment.

  • Head SHA: 3d0352198303ad055e751f1f5580313a687a2638
  • Workflow run: 36234093075
  • Workflow attempt: 1
  • Coverage gate: failure

Review outcome

Coverage is a gate, not the review. This body reviews the changed product files.

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Workflow: codeql-scan-dispatch.yml"]
  S1 --> I1["GitHub Actions review job"]
  I1 --> R1["Review risk: Workflow: codeql-scan-dispatch.yml"]
  R1 --> V1["actionlint plus required checks"]
  Evidence --> S2["Workflow: opencode-review-dispatch.yml"]
  S2 --> I2["GitHub Actions review job"]
  I2 --> R2["Review risk: Workflow: opencode-review-dispatch.yml"]
  R2 --> V2["actionlint plus required checks"]
  Evidence --> S3["Repository file: 20260926-dispatch-stale-head-skip.md"]
  S3 --> I3["repository behavior"]
  I3 --> R3["Review risk: Repository file: 20260926-dispatch-stale-head-skip.md"]
  R3 --> V3["required checks"]
  Evidence --> S4["Test: test_codeql_scan_dispatch_workflow_contract.py (3 files)"]
  S4 --> I4["regression suite"]
  I4 --> R4["Review risk: Test: test_codeql_scan_dispatch_workflow_contract.py (3 files)"]
  R4 --> V4["targeted test run"]
Loading

@opencode-agent

opencode-agent Bot commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

OpenCode Review Overview

Coverage evidence did not pass, so approval is blocked. The formal pull-request review is the source-backed diff review, not this status comment.

Ordinary-forward integrates PR #2385 into draft PR #2382 so the canonical Noema coverage build-context repair and the stale-dispatch retirement remain one reviewable lineage. The only textual conflict was the workflow blob identity contract; it is pinned to the computed merged workflow blob b22750e.

Copy link
Copy Markdown
Contributor Author

Ordinary-forward convergence evidence for exact head d9e31329e2e0361e904aef3072984ec1b4e076cd (tree 1e07dc0fd4b4b676931834d25059a6c0a889b8e6):

  • Parents are preserved in order: child 3d0352198303ad055e751f1f5580313a687a2638, canonical foundation repair(foundation): unblock coverage and CodeQL control plane #2385 8e1aba9ce1d52acb36f095da32511da06958733f.
  • RED reproduced before integration: the OpenCode coverage build context copied requirements-noema-document-ci-hashes.txt without materializing that trusted lock.
  • GREEN after integration: the trusted file is validated, installed into the isolated build context, and its contract test is present.
  • The only merge conflict was the immutable OpenCode workflow blob constant; it now equals the computed merged blob b22750e16ca5bb4765436d7bd4479e6591d59052.
  • Successor comparison against repair(foundation): unblock coverage and CodeQL control plane #2385 contains exactly the original six stale-dispatch paths.
  • Focused integrated contracts: 541 passed, 2 skipped.
  • Full Python suite: 3402 passed, 28 skipped, 40 subtests passed.
  • compileall, git diff --check, no-conflict, tree identity, and two-parent identity checks passed.
  • Local coverage is explicitly not promoted as complete: this runner has no cargo, so 25 Rust materializer tests skip and coverage reports 99%; interrogate is also unavailable. Fresh hosted exact-head evidence is required.
  • New current-head runs are queued: Runtime Quality 36279546322, Security 36279546333, Python Security 36279546248, SAST 36279546335, CodeQL 36279546340.
  • Review threads: 0. The earlier CHANGES_REQUESTED review is bound to predecessor head 3d035219… and is not treated as current-head evidence.

The PR remains Draft / Proposed. No Force Push, destructive rebase, rerun, self-approval, bypass, or merge was used.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Exact-head review for d9e31329e2e0361e904aef3072984ec1b4e076cd (COMMENT, not approval).

The ordinary-forward successor preserves canonical #2385 exact 8e1aba9c… and leaves only the six stale-dispatch paths as the effective delta: ahead 2 / behind 0. The two dispatch validators retire only a closed PR or a head mismatch proven by GitHub compare as ahead with behind_by: 0 and ahead_by >= 1; API lag (behind), force-push divergence, contradictory/malformed compare evidence, lookup failure, unauthorized sender, and other identity mismatches remain fail closed. Current exact remote verification: Python AST 3/3, workflow YAML 2/2, and bash -n for both changed validation shell blocks 2/2.

The prior OpenCode CHANGES_REQUESTED review is anchored to predecessor 3d035219… / run 36234093075 and explicitly reports no source-backed product finding; it is stale after the non-force #2385 convergence. Dismissing it does not satisfy coverage, hosted Checks, or independent approval. Current exact Runtime Quality, Security, Python Security, SAST, and CodeQL runs remain queued, so this PR stays Draft/Proposed and is not merge-authorized.

@seonghobae
seonghobae dismissed opencode-agent[bot]’s stale review September 26, 2026 23:52

Dismissed as stale exact-head evidence after ordinary-forward convergence. This review is anchored to predecessor 3d03521 / run 36234093075 and explicitly states that no source-backed product finding was synthesized. Current exact d9e3132 has a fresh COMMENT review; queued hosted Checks, coverage, and independent approval remain mandatory.

@seonghobae
seonghobae marked this pull request as ready for review September 27, 2026 00:16

Copy link
Copy Markdown
Contributor Author

Ready / Proposed admission correction for unchanged exact head d9e31329e2e0361e904aef3072984ec1b4e076cd (2026-09-27): the ordinary-forward successor already preserves #2385 and the six-path stale-dispatch delta, is mergeable, has 0 unresolved threads, and the fresh exact-head COMMENT review reports no additional source-backed finding. Keeping Draft while waiting for hosted Checks and independent approval would make those review gates circular. Ready admits review only; #2385 settlement, current-head terminal Checks, and qualifying independent approval remain merge gates. No rerun, merge, auto-merge, self-approval, dismissal, or protection bypass was used.

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode reviewed the current-head product diff. Coverage is a separate gate.

Changed files

  • .github/workflows/codeql-scan-dispatch.yml — GitHub Actions review job
  • .github/workflows/opencode-review-dispatch.yml — GitHub Actions review job
  • CHANGELOG.d/20260926-dispatch-stale-head-skip.md — repository behavior
  • CHANGELOG.md — repository behavior
  • docs/product-technical-gap-baseline.md — operator or user guidance
  • requirements-strix-ci-hashes.txt — repository behavior
  • requirements-strix-ci.txt — repository behavior
  • scripts/ci/actions_queue_health.py — review and security gate shell path
  • scripts/ci/actions_queue_health_core.py — review and security gate shell path
  • tests/test_actions_queue_health_cancelled_before_runner.py — regression suite
  • tests/test_actions_queue_health_post_evidence_retry.py — regression suite
  • tests/test_actions_queue_health_snapshot_consistency.py — regression suite
  • tests/test_actions_queue_health_terminal_preexecution.py — regression suite
  • tests/test_codeql_scan_dispatch_ghas_credential_contract.py — regression suite
  • tests/test_codeql_scan_dispatch_workflow_contract.py — regression suite
  • tests/test_noema_document_review_context.py — regression suite
  • tests/test_noema_review_document_boundaries.py — regression suite
  • tests/test_opencode_agent_contract.py — regression suite
  • tests/test_opencode_review_dispatch_stale_skip.py — regression suite
  • tests/test_organization_commercial_readiness_loop_receipt_contract.py — regression suite
  • tests/test_pr_review_autofix_nvidia_nim_contract.py — regression suite
  • tests/test_pr_review_merge_scheduler.py — regression suite
  • tests/test_strix_runtime_dependencies.py — regression suite

Changed behavior

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Workflow: codeql-scan-dispatch.yml"]
  S1 --> I1["GitHub Actions review job"]
  I1 --> R1["Review risk: Workflow: codeql-scan-dispatch.yml"]
  R1 --> V1["actionlint plus required checks"]
  Evidence --> S2["Workflow: opencode-review-dispatch.yml"]
  S2 --> I2["GitHub Actions review job"]
  I2 --> R2["Review risk: Workflow: opencode-review-dispatch.yml"]
  R2 --> V2["actionlint plus required checks"]
  Evidence --> S3["Repository file: 20260926-dispatch-stale-head-skip.md"]
  S3 --> I3["repository behavior"]
  I3 --> R3["Review risk: Repository file: 20260926-dispatch-stale-head-skip.md"]
  R3 --> V3["required checks"]
  Evidence --> S4["Repository file: CHANGELOG.md"]
  S4 --> I4["repository behavior"]
  I4 --> R4["Review risk: Repository file: CHANGELOG.md"]
  R4 --> V4["required checks"]
  Evidence --> S5["Docs: product-technical-gap-baseline.md"]
  S5 --> I5["operator or user guidance"]
  I5 --> R5["Review risk: Docs: product-technical-gap-baseline.md"]
  R5 --> V5["docs review"]
  Evidence --> S6["Repository file: requirements-strix-ci-hashes.txt"]
  S6 --> I6["repository behavior"]
  I6 --> R6["Review risk: Repository file: requirements-strix-ci-hashes.txt"]
  R6 --> V6["required checks"]
  Evidence --> S7["Repository file: requirements-strix-ci.txt"]
  S7 --> I7["repository behavior"]
  I7 --> R7["Review risk: Repository file: requirements-strix-ci.txt"]
  R7 --> V7["required checks"]
  Evidence --> S8["CI script: actions_queue_health.py"]
  S8 --> I8["review and security gate shell path"]
  I8 --> R8["Review risk: CI script: actions_queue_health.py"]
  R8 --> V8["bash -n plus Strix self-test"]
  Evidence --> S9["CI script: actions_queue_health_core.py"]
  S9 --> I9["review and security gate shell path"]
  I9 --> R9["Review risk: CI script: actions_queue_health_core.py"]
  R9 --> V9["bash -n plus Strix self-test"]
  Evidence --> S10["Test: test_actions_queue_health_cancelled_before_runner.py (14 files)"]
  S10 --> I10["regression suite"]
  I10 --> R10["Review risk: Test: test_actions_queue_health_cancelled_before_runner.py (14 files)"]
  R10 --> V10["targeted test run"]
Loading

Findings

No source-backed product finding is synthesized from the coverage gate. A coverage miss belongs in the status comment.

  • Head SHA: d9e31329e2e0361e904aef3072984ec1b4e076cd
  • Workflow run: 36308944761
  • Workflow attempt: 1
  • Coverage gate: failure

Review outcome

Coverage is a gate, not the review. This body reviews the changed product files.

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Workflow: codeql-scan-dispatch.yml"]
  S1 --> I1["GitHub Actions review job"]
  I1 --> R1["Review risk: Workflow: codeql-scan-dispatch.yml"]
  R1 --> V1["actionlint plus required checks"]
  Evidence --> S2["Workflow: opencode-review-dispatch.yml"]
  S2 --> I2["GitHub Actions review job"]
  I2 --> R2["Review risk: Workflow: opencode-review-dispatch.yml"]
  R2 --> V2["actionlint plus required checks"]
  Evidence --> S3["Repository file: 20260926-dispatch-stale-head-skip.md"]
  S3 --> I3["repository behavior"]
  I3 --> R3["Review risk: Repository file: 20260926-dispatch-stale-head-skip.md"]
  R3 --> V3["required checks"]
  Evidence --> S4["Repository file: CHANGELOG.md"]
  S4 --> I4["repository behavior"]
  I4 --> R4["Review risk: Repository file: CHANGELOG.md"]
  R4 --> V4["required checks"]
  Evidence --> S5["Docs: product-technical-gap-baseline.md"]
  S5 --> I5["operator or user guidance"]
  I5 --> R5["Review risk: Docs: product-technical-gap-baseline.md"]
  R5 --> V5["docs review"]
  Evidence --> S6["Repository file: requirements-strix-ci-hashes.txt"]
  S6 --> I6["repository behavior"]
  I6 --> R6["Review risk: Repository file: requirements-strix-ci-hashes.txt"]
  R6 --> V6["required checks"]
  Evidence --> S7["Repository file: requirements-strix-ci.txt"]
  S7 --> I7["repository behavior"]
  I7 --> R7["Review risk: Repository file: requirements-strix-ci.txt"]
  R7 --> V7["required checks"]
  Evidence --> S8["CI script: actions_queue_health.py"]
  S8 --> I8["review and security gate shell path"]
  I8 --> R8["Review risk: CI script: actions_queue_health.py"]
  R8 --> V8["bash -n plus Strix self-test"]
  Evidence --> S9["CI script: actions_queue_health_core.py"]
  S9 --> I9["review and security gate shell path"]
  I9 --> R9["Review risk: CI script: actions_queue_health_core.py"]
  R9 --> V9["bash -n plus Strix self-test"]
  Evidence --> S10["Test: test_actions_queue_health_cancelled_before_runner.py (14 files)"]
  S10 --> I10["regression suite"]
  I10 --> R10["Review risk: Test: test_actions_queue_health_cancelled_before_runner.py (14 files)"]
  R10 --> V10["targeted test run"]
Loading

Copy link
Copy Markdown
Contributor Author

Exact-head admission correction — d9e31329e2e0361e904aef3072984ec1b4e076cd

Ready is review admission only. Fresh audit against base e6334e229581a918e2f22de18733b76fa65d7e71 found:

  • mergeability=false on current base
  • latest terminal workflow blockers: CodeQL PR 36282016222=failure
  • CHANGES_REQUESTED: opencode-agent

This PR is moved to Draft/Proposed until the causal owner repair is present on a successor exact head and re-audited. Queued/pending work is neither an additional blocker nor passing evidence. No Close, force push, destructive rebase, manual rerun, synthetic status/approval, merge, auto-merge, or bypass was performed.

@seonghobae
seonghobae marked this pull request as draft September 30, 2026 05:14

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant