Skip to content

fix(security): gate summary shared-catalog enrichment - #1079

Draft
seonghobae wants to merge 34 commits into
mainfrom
fix/summary-catalog-authorization-1078
Draft

seonghobae wants to merge 34 commits into
mainfrom
fix/summary-catalog-authorization-1078

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 13, 2026 •

Copy link
Copy Markdown
Contributor

Problem and owner boundary

GET /api/posts/{post_id}/summary is readable under post_read, but missing-summary materialization previously admitted shared Customer Master catalog mutation capabilities. This lane owns the LineageWeave authorization/application boundary only: shared-catalog enrichment is derived from post_admin; readers get lookup/reuse without create/upsert; Null hierarchy/relation clients and allow_catalog_enrichment=False remain the fail-closed reader default. The canonical corporate catalog remains in corporate_entity_ingestion. ADR 0375 remains Proposed.

Current exact authority — 2026-09-23 KST

  • protected base: main@83eba56149eb802cd63642c507c324c9976ec78e
  • exact head: c2923950e73c88a9f9fd932332ddd47682da124b
  • state: open / Draft / mechanically mergeable
  • qualifying independent current-head APPROVED: none

Repository-owned acceptance is terminal and the repaired product boundary remains GREEN:

  • Tests 34815479029: SUCCESS, including frontend, full PostgreSQL suite, and PostgreSQL + Keycloak + Valkey summary-authorization integration;
  • SAST 34815434313: SUCCESS;
  • Security 34815434486: SUCCESS;
  • Required CodeQL 34815434324: terminal FAILURE at canonical verdict settlement.

The latest Required CodeQL attempt is no longer a simple producer-queue snapshot. Detect-languages 106390839868 is SUCCESS. Actions receiver 106390838575 settled SUCCESS, while JavaScript/TypeScript 106390838277 and Python 106390838659 each acquired hosted runners, read the current-head dispatch verdict, then failed at terminal enforcement. Follow-on coordinator 106488973605 later completed Dispatch current-head CodeQL scan SUCCESS on the same exact head. The overall run therefore remains non-accepting and belongs to canonical .github#1929; do not copy the central dispatch/receiver control plane or synthesize a status here.

The two CodeRabbit source findings in this lane were repaired in the current history; there is still no qualifying submitted APPROVED review. Historical Strix/Noema/OpenCode control-plane evidence remains external-owner evidence and is not grounds to weaken this authorization lane or copy provider/routing/sidecar policy into LineageWeave.

Promotion boundary

Keep Draft and unmerged until Required CodeQL reaches terminal acceptance on an unchanged current head, model-backed review/coverage evidence is current and accepting, all valid findings remain resolved, and qualifying independent approval exists. ADR 0375 stays Proposed until normal protected integration.

Do not use no-op commits, private-environment fabrication, provider/model fallback, manual status synthesis, self-approval, force push, destructive rebase, blind rerun, source-neutral wake commit, owner-source copy, total elapsed model timeout, or gate weakening to manufacture evidence.

Fixes #1078.

@coderabbitai

coderabbitai Bot commented Sep 13, 2026 •

Copy link
Copy Markdown

Review Change StackReview Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 832c6ba7-6e85-471b-a22a-f9564e0f257d

📥 Commits

Reviewing files that changed from the base of the PR and between 83eba56 and c292395.

📒 Files selected for processing (13)
  • .github/workflows/tests.yml
  • ARCHITECTURE.md
  • CHANGELOG.d/2.28.1-summary-catalog-authorization.md
  • backend/app/main.py
  • backend/app/post_summary_ingestion.py
  • backend/tests/test_api.py
  • backend/tests/test_summary_catalog_authorization_api.py
  • backend/tests/test_summary_catalog_fallback_authorization_api.py
  • docs/adr/0375-summary-read-catalog-authorization.md
  • scripts/backfill_post_summaries.py
  • tests/test_ingestion_transaction_contracts.py
  • tests/test_summary_catalog_authorization.py
  • tests/test_tests_workflow_contract.py

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

요약 저장 경로가 계정의 post_admin 권한을 확인합니다. 권한이 없으면 공유 카탈로그 보강을 차단하고 기존 팀만 조회합니다. 권한이 있으면 기존 조직·팀 보강을 유지합니다. 테스트, CI 작업, ADR과 변경 기록을 추가했습니다.

Changes

요약 카탈로그 인가

Layer / File(s) Summary
계정 권한 기반 보강 경계
backend/app/main.py, backend/app/post_summary_ingestion.py, tests/test_summary_catalog_authorization.py, tests/test_ingestion_transaction_contracts.py, backend/tests/test_api.py
요약 엔드포인트가 post_admin 권한에 따라 보강 클라이언트와 allow_catalog_enrichment를 선택합니다. 비보강 실행은 Null 클라이언트와 기존 cataloged_team의 읽기 전용 조회를 사용합니다.
인가 동작과 통합 검증
backend/tests/test_summary_catalog_authorization_api.py, backend/tests/test_summary_catalog_fallback_authorization_api.py
post_read 요청과 제공자 실패 시 fallback 경로에서 공유 카탈로그가 변경되지 않음을 검증합니다. post_admin 요청에서는 조직과 팀 보강이 수행됨을 검증합니다.
인가 결정과 운영 경로 기록
docs/adr/0375-summary-read-catalog-authorization.md, ARCHITECTURE.md, CHANGELOG.d/2.28.1-summary-catalog-authorization.md, scripts/backfill_post_summaries.py
요약 읽기와 공유 카탈로그 보강의 인가 경계를 기록합니다. 백필은 카탈로그 보강을 명시적으로 비활성화합니다.
통합 테스트 실행 격리
.github/workflows/tests.yml, tests/test_tests_workflow_contract.py
요약 인가 통합 테스트가 고유 Compose 프로젝트를 사용합니다. Valkey 확인, 로그 수집, 리소스 정리는 프로젝트 라벨을 사용합니다.

Priority: ⬆️ High

Estimated code review effort: 3 (Moderate) | ~25 minutes

Change: Bug fix · Severity of issue fixed: Medium

Sequence Diagram(s)

sequenceDiagram
  participant API
  participant AccountPolicy
  participant SummaryIngestion
  participant SharedCatalog
  API->>AccountPolicy: 현재 계정의 post_admin 권한 확인
  AccountPolicy->>SummaryIngestion: 보강 허용 여부와 클라이언트 전달
  SummaryIngestion->>SharedCatalog: 허용 시 조직·팀 생성 또는 갱신
  SummaryIngestion->>SharedCatalog: 차단 시 기존 팀과 조직만 조회
Loading

Merge Risk: ⚪ Minimal · up to c2923

The authorization boundary preserves reader summary access while preventing shared-catalog mutation; no remaining merge-blocking risk was identified.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Linked Issues check ⚠️ Warning #1078의 주요 코드 요구사항은 구현되었습니다. post_read 경로는 allow_catalog_enrichment=False로 고정되고 Null hierarchy/relation client를 사용합니다. 기존 cataloged_team 조회는 읽기 전용입니다. 요약 투영 저장과 post_admin 보강은 유지됩니다. 권한, 카탈로그 불… exact head c2923950e73c88a9f9fd932332ddd47682da124b에서 Strix를 재실행하십시오. 해당 실행에서 #1078의 CWE-862 finding이 absent 또는 closed임을 기록하십시오. 동일 exact head의 인증된 PostgreSQL·Keycloak·Valkey 회귀 결과도 기록하십시오.
✅ Passed checks (4 passed)
Check name Status Explanation
Out of Scope Changes check ✅ Passed 변경은 #1078의 권한 경계와 직접 연결됩니다. capability 제어, fail-closed Null client, 기존 카탈로그의 읽기 전용 조회, backfill 계약, 인증 회귀 테스트, workflow 격리, ADR 및 changelog 문서화는 해당 보안 수정의 구현 또는 검증을 지원합니다. #1077의 connection-lease 구현이나…
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 43 functions across 9 files. (4 skipped: 4…
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed PR 제목은 요약 경로의 공유 카탈로그 보강을 보안 권한으로 제한하는 주요 변경 사항을 정확하고 간결하게 설명합니다.
Full details: Linked Issues check

Explanation

#1078의 주요 코드 요구사항은 구현되었습니다. post_read 경로는 allow_catalog_enrichment=False로 고정되고 Null hierarchy/relation client를 사용합니다. 기존 cataloged_team 조회는 읽기 전용입니다. 요약 투영 저장과 post_admin 보강은 유지됩니다. 권한, 카탈로그 불변성, stale/provider-failure fallback을 검증하는 도메인 및 인증 테스트도 추가되었습니다. 그러나 exact head c2923950e73c88a9f9fd932332ddd47682da124b에 대한 필수 Strix 재실행이 아직 pending입니다. 따라서 CWE-862 finding이 종료되었거나 수정된 경로에서 재현되지 않는다는 증거가 없습니다.

  • Fix all pre-merge checks with AI
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/summary-catalog-authorization-1078

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Copy link
Copy Markdown
Contributor Author

Fresh review found one stale test contract before validation: test_same_team_named_in_two_posts_resolves_to_one_cataloged_team still uses the reader-only demo.analyst token while asserting that summary GET creates/deduplicates cataloged_team. That expectation is the authorization defect this PR removes. The test must explicitly grant post_admin, and the reader path needs its own authenticated invariance proof.

A bounded temporary patch workflow is staged at current head ffa9c39d3166bdb795fe9defd2e656d053fdac84 to make only those test changes: (1) grant post_admin in the existing team-dedup test; (2) add a real PostgreSQL + Keycloak + Valkey API regression that snapshots corporate_entity/cataloged_team, calls summary GET with the real demo.analyst bearer, proves neither shared catalog nor mutation-capable client admission changes, then grants post_admin and proves explicit enrichment still works. Schema review confirms post_summary_role.cataloged_team_id and cataloged_corporate_entity_id are the canonical stored FKs (ADR 0019/migrations).

The patch job 34772840775 currently has runner_id=0 and no steps: this is runner queue, not a code failure. This PR remains Draft. The temporary workflow must be removed again before candidate validation, and no GREEN claim is made until the real API regression actually executes.

Copy link
Copy Markdown
Contributor Author

Additional review finding before full-suite admission: tests/test_ingestion_transaction_contracts.py::test_post_summary_replacement_mentions_and_edges_share_one_transaction still calls persist_post_summary(...) without an enrichment capability while explicitly asserting upsert_team executes inside the summary transaction. With the new fail-closed default this test will take the read-only team lookup path instead and its _SummaryConnection.fetchrow does not even accept that lookup. This is another stale contract, not a production reason to re-open the default.

The repair is to make this enrichment-specific transaction test pass allow_catalog_enrichment=True explicitly. The separate reader tests retain the default/False path. I am keeping #1079 Draft; this stale test must be repaired on the same branch before exact-head repository validation.

Copy link
Copy Markdown
Contributor Author

Live authority update for the current Draft lane:

  • Product repair remains the fail-closed post_admin capability boundary already in this PR.
  • The earlier authenticated API patcher failure was not a product RED: run 34772840775 applied its edit, then failed source verification because its raw Python string wrote literal \\n tokens into backend/tests/test_api.py.
  • Two follow-up zero-job attempts exposed a separate YAML block-scalar indentation defect in the temporary patch machinery. That machinery is now replaced with a YAML-safe encoded bounded patch on exact staging head b87c4742543998c808345dc0bb9752e1e97d3cf8; run 34776138163 is valid and queued with job 103774480604 (runner_id=0). Repository-wide Actions currently show no in-progress run and 23 queued runs, so this is presently infrastructure queue evidence, not a new product failure.
  • The bounded patch adds the real PostgreSQL + Keycloak + Valkey reader/admin catalog-invariance regression, makes the two legacy transaction tests declare allow_catalog_enrichment=True where they intentionally test shared-catalog mutation, and deletes the temporary patch workflow in the same product-test commit.

This PR stays Draft. Do not treat b87c474... as the promotion head: promotion starts only from the successor product-only head after the queued patch commits and the temporary workflow is absent.

Copy link
Copy Markdown
Contributor Author

Fresh review found one workflow-governance defect in the temporary #1078 patch lane: .github/workflows/patch-summary-auth-integration-1078.yml currently grants contents: write but checks out with mutable actions/checkout@v4, contrary to the exact-SHA CI contract. I am not moving the branch while run 34776138163 is still the sole queued writer because that workflow itself checks out the branch ref at execution time; changing the head now would create an avoidable writer/evidence race. Treat any commit produced by this queued run as candidate source only, not transferable promotion evidence. After it terminalizes, the temporary workflow must be absent as already planned; any successor temporary/reusable workflow must pin external actions by immutable SHA. Product authorization semantics remain unchanged by this governance finding.

@seonghobae
seonghobae marked this pull request as ready for review September 14, 2026 03:57

Copy link
Copy Markdown
Contributor Author

@coderabbitai resume

현재 validation authority는 d7bc66c6cc21ac9046078b78369b9c388e7c8b7b입니다. 이전 detailed review는 7c0df2db5d9b64008e6b7addba27fb3fb0a071cf까지만 cover하므로, predecessor receipt를 승계하지 말고 이 exact head의 전체 diff를 기준으로 fresh review를 재개해 주세요. 특히 #1078 CWE-862 authorization boundary, reader/admin fallback matrix, whole-catalog invariance, dedicated PostgreSQL+Keycloak+Valkey job, docstring/typing cleanup이 현재 head에서 일관된지 확인해 주세요.

@coderabbitai

coderabbitai Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

@seonghobae 재개하겠습니다. 이전 review 결과는 승계하지 않습니다.

d7bc66c6cc21ac9046078b78369b9c388e7c8b7b의 전체 diff를 기준으로 fresh review를 실행합니다. 검토 범위에는 #1078 CWE-862 authorization boundary, reader/admin fallback matrix, shared catalog 전체 불변성, PostgreSQL·Keycloak·Valkey 전용 integration job, docstring 및 typing 정합성이 포함됩니다.

✅ Action performed

Reviews resumed.


Full review finished.

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Sep 14, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Already reviewed the last commit. Use @coderabbitai full review to rerun a review of the entire changeset.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@seonghobae
seonghobae marked this pull request as draft September 14, 2026 06:53
@seonghobae
seonghobae marked this pull request as ready for review September 14, 2026 06:55

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

Current review authority moved to exact head c2923950e73c88a9f9fd932332ddd47682da124b after hosted integration RED 34804318535/103853037604 exposed an unrelated Compose env_file dependency. Please review the exact protected-base→current-head diff; predecessor d7bc66c6... review evidence is non-transferable.

@coderabbitai

coderabbitai Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

@seonghobae c2923950e73c88a9f9fd932332ddd47682da124b를 기준으로 protected base부터 현재 head까지 전체 diff를 다시 검토합니다. d7bc66c6...의 이전 검토 결과는 사용하지 않습니다.

검토 범위에는 #1078 권한 경계, reader/admin fallback, 공유 카탈로그 전체 불변성, PostgreSQL·Keycloak·Valkey integration job, Compose env_file 격리, 문서 및 typing 정합성이 포함됩니다.

⚠️ Action not completed

Review rate limited.


Your included review limit is currently reached under our Fair Usage Limits Policy. This review may still proceed through usage-based billing if eligible. Your next included review will be available in 52 minutes.

Copy link
Copy Markdown
Contributor Author

Fresh owner-path integration finding: canonical read-only queue-health PR ContextualWisdomLab/.github#1150@42bb922f03bf75aed1bc1931d9fbaf04a5433e20 has an explicit bounded repository allowlist, and ContextualWisdomLab/LineageWeave was not in it. That meant #712 could carry this PR as an incident canary in comments, but the canonical collector itself could not produce a first-class LineageWeave repository/PR/head/workflow/job snapshot.

I repaired this at the canonical owner boundary rather than changing this leaf. New Draft child .github#2200@c4054eef3fc3cd84c87ea830b2e94d4145aa34e8 is based directly on #1150 and changes exactly two owner paths: the allowlist plus its exact-equality contract test. Test-first 1a61773a... intentionally required LineageWeave before config enrollment (deterministic RED); c4054eef... adds the matching entry. Fresh parent compare is ahead 2 / behind 0 with only those two files, and focused exact-content contract validation is 2 passed. Hosted Security 34835105055, SAST 34835105058, and CodeQL 34835105047 on that child are still queued, so the owner contribution remains Draft/non-GREEN.

#1079 itself stays unchanged at c2923950...; its existing queued evidence is preserved. No leaf rerun, no-op commit, selector change, provider/model fallback, cancellation or gate weakening was issued. Promotion still requires the original exact-head product/security/review gates plus normal integration of the central owner path where applicable.

Copy link
Copy Markdown
Contributor Author

2026-09-15 02:47 KST current-head authority update

Exact product head remains unchanged at c2923950e73c88a9f9fd932332ddd47682da124b on protected main@83eba56149eb802cd63642c507c324c9976ec78e; this comment supersedes only the stale runtime-status sentence in the PR body and does not transfer predecessor evidence.

Fresh exact-head state:

  • Tests 34815479029, SAST 34815434313, and Required Security Scan 34815434486 remain terminal SUCCESS.
  • Required CodeQL 34815434324: language detection 103965453105 is SUCCESS; compatibility analyses remain queued without runner assignment: actions 104064547137, javascript-typescript 104064547154, python 104064547176.
  • OpenCode current-head admission 103974955239 has now received a hosted runner and completed SUCCESS. Its actual review/evidence jobs remain queued with runner_id=0: opencode-review 104070870170, coverage-evidence 104070870162, coverage-source-tree 104070870386.
  • Strix 103970045852 is no longer queued. It has a hosted runner and is in progress on exact c2923950...; admission/cancellation/self-contract steps passed, contextual-orchestrator sidecar provisioning and Strix installation passed, and Run Strix (quick) is currently executing.
  • Noema 103965387845 is likewise in progress on a hosted runner. Exact-head admission/current-head validation passed; it is currently in Provision contextual-orchestrator review sidecar before preparing/publishing a verdict.
  • Both existing CodeRabbit inline threads are still resolved. Submitted reviews remain COMMENTED only; no qualifying independent current-head APPROVED review exists.

No source change, no no-op wake commit, no rerun, no selector/provider/model/timeout change, and no lifecycle flip was made. The correct merge boundary therefore remains fail-closed: wait for Required CodeQL compatibility + terminal Strix/Noema/OpenCode evidence + qualifying independent approval, then normal protected merge. Dynamic gap projection was refreshed in Draft docs lane #1041 at exact 0b9ded38af1180aef856fd4fbc8d0efb80e00438.

Copy link
Copy Markdown
Contributor Author

@coderabbitai full review

현재 validation authority는 변경 없는 exact head c2923950e73c88a9f9fd932332ddd47682da124b입니다. 이 head에서 Tests 34815479029, SAST 34815434313, Security 34815434486은 terminal GREEN이고, 두 inline finding도 resolved 상태입니다. 이전 incremental successor-delta review가 아니라 protected main@83eba56149eb802cd63642c507c324c9976ec78e → current head 전체 변경을 다시 검토해 주세요. 특히 #1078 CWE-862 reader/admin catalog-enrichment 경계, stale/provider-failure matrix, shared-catalog invariance, dedicated PostgreSQL+Keycloak+Valkey acceptance와 CI isolation의 일관성을 확인해 주세요. Required CodeQL/Strix/Noema/OpenCode는 별도 exact-head gate로 계속 fail closed하며, 이 요청은 그 gate를 대체하거나 우회하지 않습니다.

@coderabbitai

coderabbitai Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

@seonghobae main@83eba56149eb802cd63642c507c324c9976ec78e부터 c2923950e73c88a9f9fd932332ddd47682da124b까지의 전체 diff를 다시 검토합니다.

검토는 #1078 권한 경계, reader/admin fallback matrix, shared-catalog 전체 불변성, PostgreSQL·Keycloak·Valkey acceptance, 그리고 CI isolation을 포함합니다. Required CodeQL, Strix, Noema, OpenCode gate는 별도 exact-head gate로 유지합니다.

✅ Action performed

Full review finished.

Copy link
Copy Markdown
Contributor Author

Live exact-head review authority update (2026-09-15 KST): CodeRabbit has now completed a full base→head review of protected main@83eba56149eb802cd63642c507c324c9976ec78e through exact c2923950e73c88a9f9fd932332ddd47682da124b across all 13 changed files. It reported no actionable comments and Merge Risk: Minimal; both existing inline threads remain resolved. This is meaningful independent full-diff review evidence, but it is not a submitted APPROVED review, so it does not satisfy the qualifying approval gate by itself. Its only remaining pre-merge warning is the already-known exact-head Strix evidence requirement; Strix job 103970045852 is currently running Run Strix (quick) on the same unchanged head, while Noema 103965387845 is still provisioning its contextual-orchestrator sidecar. Required CodeQL compatibility (104064547137, 104064547154, 104064547176) and OpenCode downstream review/coverage (104070870170, 104070870162, 104070870386) remain pre-runner queued. No no-op commit, rerun, timeout insertion, provider/model override, or lifecycle churn is justified by this state.

Copy link
Copy Markdown
Contributor Author

Live exact-head authority — 2026-09-15 08:xx KST

This supersedes the earlier nonterminal review/check status notes for unchanged exact head c2923950e73c88a9f9fd932332ddd47682da124b on protected main@83eba56149eb802cd63642c507c324c9976ec78e. No product-source change, no-op wake commit, manual rerun, provider/model override, or gate weakening is justified by the terminal evidence below.

  • Repository acceptance remains GREEN: Tests 34815479029 (Frontend 103885140448, Full suite 103885140559, PostgreSQL + Keycloak + Valkey Summary authorization 103885140632), SAST 34815434313, and Required Security 34815434486 are successful on this exact head.
  • Required CodeQL compatibility receivers are now terminal FAIL-CLOSED, not product-analysis failures: Python 104064547176, JavaScript/TypeScript 104064547154, and Actions 104064547137 each obtained a runner, read the current-head dispatch state, and failed at the compatibility-verdict enforcement step. Their coordinator Dispatch current-head CodeQL scan 104180256379 is now queued with no runner. The canonical bootstrap/cutover remains .github#2106 -> #2040; do not patch or wake this leaf branch.
  • Required OpenCode coverage is no longer wholly queued: coverage-source-tree 104070870386 and coverage-evidence 104070870162 are exact-head SUCCESS. opencode-review 104070870170 dispatched a current-head review successfully, then correctly failed because no authenticated opencode-agent APPROVED/CHANGES_REQUESTED verdict had materialized for c2923950e...; the central dispatch path owns the eventual verdict/rerun.
  • Required Strix 103970045852 is terminal FAILURE, but its uploaded strix-reports artifact 10371857268 shows the scan reached a normal final report/SARIF with zero findings while concurrent sub-agent requests received CO 503 concurrency_limit_exceeded / too many concurrent orchestration runs. The gate correctly refused to promote that incomplete provider execution to GREEN. This is central review-runtime/caller-admission evidence, not a new LineageWeave vulnerability. Fresh exact consumer evidence was attached to .github#2139; CO's explicit overload contract must not be weakened locally.
  • Required Noema 103965387845 is terminal CANCELLED. Exact-head admission/credentials/live-head validation succeeded, but Provision contextual-orchestrator review sidecar started at 2026-09-14T16:50:39Z, logged sidecar startup at 16:52:41Z, never produced readiness, and GitHub cancelled the operation at 22:51:33Z after roughly six hours; no model-verdict step ran. That separates startup/provisioning occupancy from model inference duration and is also recorded under .github#2139/#2140, with #1629 retaining sidecar admission/preflight ownership.
  • CodeRabbit's full protected-base -> exact-head review remains clean (Merge Risk: Minimal, no actionable comments, both inline threads resolved), but it is not a submitted qualifying APPROVED review.

Merge remains fail-closed until the fresh current-head CodeQL producer/compatibility path is terminal GREEN, OpenCode publishes its authenticated current-head verdict, Strix and Noema acquire complete terminal evidence through their canonical owner repairs, and a qualifying current-head approval exists. The product authorization/catalog boundary itself remains unchanged and retains the prior exact-head GREEN repository/security evidence.

Copy link
Copy Markdown
Contributor Author

Current CodeQL authority correction for exact #1079 head c2923950e73c88a9f9fd932332ddd47682da124b: canonical producer run 34922377994 is no longer queued. It completed failure after all three actual language scans acquired hosted runners and CodeQL analysis itself completed.

  • JavaScript/TypeScript job 104312978305: analysis success; Medium+ SARIF gate failure.
  • Python job 104312978336: analysis success; Medium+ SARIF gate failure.
  • Actions job 104312978423: scan completed; no Actions SARIF finding was preserved as a product delta.
  • immutable producer artifacts: JS 10398331800 (sha256:3c2a76b8...), Python 10398012754 (sha256:481ce142...), Actions 10399095234 (sha256:1df7137a...).

The findings are repository-baseline files outside #1079's 13-file authorization diff, so they are not new summary-catalog authorization regressions and must not be patched into this PR:

  1. Python py/insecure-protocol in lineageweave/http_client.py and py/polynomial-redos in lineageweave/post_chat.py. Canonical active owner fix(chat): preserve null timeouts and attribute worker expiry #974 has now carried both through executable REDs and minimum causal fixes: explicit TLS 1.2 floor and linear chat trailing-punctuation normalization. Current fix(chat): preserve null timeouts and attribute worker expiry #974 is 6911954363888d1e2d523ebbcf68f68d7217752a; direct child fix(ask): fence Ask settlement on the claim generation #979 was immediately non-force converged to 2431fa8cde5927ca9e6afeb2652ff8b01f3f0a85. Those moved heads still need fresh exact-head CodeQL/repository acceptance.
  2. Four JavaScript js/incomplete-multi-character-sanitization findings in frontend/src/postBodyDisplay.ts. fix: verify dashboard accessibility and enforce frontend coverage #983 already owns that parser/rendering boundary; owner finding/evidence is recorded in fix: verify dashboard accessibility and enforce frontend coverage #983 comment 5689242771. The current React sink renders text nodes rather than dangerouslySetInnerHTML, so the scan does not by itself prove exploitable XSS, but regex-as-sanitizer remains a valid hard-gate robustness defect and must be causally repaired rather than suppressed.

The local #1079 compatibility jobs remain the earlier terminal fail-closed readers from before producer completion; because the producer published failure, there is no GREEN receipt to wake/reconcile. Required CodeQL therefore remains legitimately RED. Keep #1079 Ready only as its existing validation state; do not churn this head, copy baseline fixes into it, synthesize a status, or weaken the Medium+ gate. Promotion now requires the owner repairs to land/reconverge, then a fresh exact-head canonical scan/compatibility settlement plus the existing OpenCode/Strix/Noema/independent-approval gates.

Copy link
Copy Markdown
Contributor Author

Owner repair update: the four JavaScript js/incomplete-multi-character-sanitization findings from canonical dispatch 34922377994 are now under #983 exact head a91e3724978e95f0902b3e77df91f50f7baf3599. RED ec126f7b... reproduces tag recomposition and quoted-> truncation; causal fix replaces the four sanitizer-style regex rewrite sites with a deterministic scanner. #1079 itself remains unchanged because summary-catalog authorization is not the owner of postBodyDisplay.ts. Fresh #983 CodeQL/SAST/Security are still queued and Tests is Draft-skipped, so this is not yet acceptance evidence.

Copy link
Copy Markdown
Contributor Author

Current CodeQL authority correction: canonical producer run .github@34922377994 has now completed all three actual scans. Actions passed its Medium+ SARIF gate; JavaScript/TypeScript and Python analyses themselves completed successfully but their Medium+ SARIF gates failed, so this is no longer a producer-admission/runner wait. The findings are repository-baseline owner work outside #1079's 13-file authorization delta. Python owner #974 is source-repaired at exact 6911954363888d1e2d523ebbcf68f68d7217752a (TLS floor + linear trailing-punctuation normalization) but its fresh Tests/CodeQL/SAST/Security runs remain queued. Frontend parser owner #983 is now source-repaired through exact 611e56a6d42b38542265fb0fc080c10ae9f454a7, including the follow-up quoted-attribute embedded-image evidence-loss case; its exact-head Tests is Draft-skipped and CodeQL/Security/SAST remain queued. Therefore #1079 stays unmergeable by policy: do not reinterpret producer failure as an authorization regression, do not suppress central CodeQL, and do not transfer owner-repair receipts until fresh canonical scans settle.

@seonghobae seonghobae added bug Something isn't working priority: high labels Sep 19, 2026 — with ChatGPT Codex Connector
@seonghobae
seonghobae enabled auto-merge (squash) September 20, 2026 15:08
@seonghobae
seonghobae marked this pull request as draft September 22, 2026 20:55
auto-merge was automatically disabled September 22, 2026 20:55

Pull request was converted to draft

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working priority: high

Projects

None yet

Development

Successfully merging this pull request may close these issues.

security(summary): prevent post_read GET from mutating global corporate catalog

1 participant