Skip to content

fix(voice): preserve truth and derivation at historical cutoffs - #1139

Merged
seonghobae merged 6 commits into
mainfrom
codex/voice-cutoff-reassertion-20261001
Oct 2, 2026
Merged

seonghobae merged 6 commits into
mainfrom
codex/voice-cutoff-reassertion-20261001

Conversation

@seonghobae

@seonghobae seonghobae commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Current exact-head authority — 2026-10-01

  • Exact head: 421324c1b29d315d1987f69c3c16ce18a4330924; exact tree: cd6d790239a1e34d905b446a329d1b00e069e055.
  • Ordinary parents: Voice cutoff repair e627d90e6daed0836a6602573d9d50a57d957601 and canonical dependency owner security(deps): enforce patched JWT and HTTP dependency floors #1137 db96ff11c977a92180b5480884bc361a4be5cf75.
  • PyJWT source floors and lock are 2.15.1; urllib3 source floor and lock are 2.8.0.
  • Tests 36828592050, SAST 36828591819, PROV-O 36828591808, and Ontology Pages 36828591758 are GREEN.
  • Security 36828591967: Trivy, OSV, and Scorecard GREEN; Dependency Review remains fail-closed because GitHub's exact base/head dependency-graph request returned HTTP 403.
  • CodeQL 36828591835 dispatched all three exact-head shards successfully; each has VERDICT_STATE=pending and remains fail-closed until authenticated SARIF completion. No independent approval exists. Ready is review admission only; merge is HOLD.

Superseded predecessor context

Updating an existing additional Voice overwrote its truth state, derivation assertion, and recording time. A historical cutoff could consequently lose its earlier evidence or acquire a later claim.

Serialize assignment writes with imported-primary changes on the carrying Post, retain closed intervals, and insert replacements at one database-clock boundary after the lock. An unchanged retry preserves its original interval. Post-detail and ontology reads omit additional rows recorded after the cutoff, including legacy rows whose earlier evidence was overwritten. ADR 0256 records the decision before implementation; the twelve atomic Voices and open composition contract remain unchanged.

Validation: 89 related tests passed with DeprecationWarning treated as an error, including full-migration synthetic PostgreSQL proof of truth-only and evidence-only revisions, retry idempotency, rollback, waiting writers, historical production read projections, and unchanged imported primary. Ruff and git diff --check passed. Temporary databases are dropped by fixture teardown.

Ownership and delivery: #1129 owns searched exports and paged JSON-LD; #1138 owns PROV derivation admission and remains stacked on dependency owner #1137. This change adds no schema migration, release number, estimation, provider selection, or UI design. Authenticated PostgreSQL HTTP/UI acceptance and authenticated synthetic k6 capacity evidence remain unverified. Hosted checks and independent approval are required on the current head before protected integration.

The Gap baseline records the exact-head queue, live rulesets, owner boundaries, API/ADR/migration/release identity collisions across the 177-PR observation, and the later 178-PR count. #1129's separate synthetic UI candidate passed 537 frontend tests and desktop/mobile screenshot/export checks; those results are not authenticated runtime or this PR's protected-delivery proof. The documentation follow-up advances this PR to e627d90 and requires fresh hosted checks and approval; the tested code remains abf66f8.

@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 45 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: fbefd3e1-784b-40ad-a9ad-6e49824b62e0
📥 Commits

Reviewing files that changed from the base of the PR and between 28f0c51 and bda1f9f.

📒 Files selected for processing (12)
  • CHANGELOG.d/voice-cutoff-reassertion.md
  • CHANGELOG.md
  • backend/app/main.py
  • backend/app/ontology_neighborhood_ingestion.py
  • backend/app/source_post_voice_ingestion.py
  • docs/adr/0256-evidence-bearing-voice-combinations.md
  • docs/doctoring/lineageweave-dependency-security-20261001.md
  • docs/product-requirements.md
  • pyproject.toml
  • tests/test_pyjwt_advisory_floor.py
  • tests/test_source_post_voice_history_live.py
  • tests/test_source_post_voice_ingestion.py
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@seonghobae
seonghobae enabled auto-merge (squash) October 1, 2026 06:25
@opencode-agent
opencode-agent Bot disabled auto-merge October 1, 2026 06:45
@seonghobae
seonghobae enabled auto-merge (squash) October 1, 2026 06:48
Preserve the Voice cutoff repair while integrating the complete PyJWT and urllib3 security owner delta, RED contract, doctoring, CHANGELOG, generated lock, and product-gap evidence through ordinary two-parent ancestry.
@opencode-agent
opencode-agent Bot disabled auto-merge October 1, 2026 07:08

seonghobae commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor Author

Exact-head Security RCA and canonical-owner integration — current evidence

Predecessor e627d90e6daed0836a6602573d9d50a57d957601 failed Security on 12 PyJWT findings and three urllib3 findings. Current exact head 421324c1b29d315d1987f69c3c16ce18a4330924 ordinarily integrates canonical dependency owner #1137 at db96ff11c977a92180b5480884bc361a4be5cf75; the complete PyJWT 2.15.1 and urllib3 2.8.0 owner delta is preserved.

Fresh exact-head evidence:

No manual rerun, force update, destructive rebase, gate weakening, self-approval, or merge was performed. Independent approval is absent; Ready is review admission only.

…urrent-main-20261003

# Conflicts:
#	docs/product-technical-gap-baseline.md
@seonghobae
seonghobae merged commit d57d861 into main Oct 2, 2026
2 of 8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant