Skip to content

fix(license): replace psycopg2 synchronous PostgreSQL boundary - #911

Draft
seonghobae wants to merge 72 commits into
mainfrom
fix/remove-psycopg2-commercial-license
Draft

seonghobae wants to merge 72 commits into
mainfrom
fix/remove-psycopg2-commercial-license

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 1, 2026 •

Copy link
Copy Markdown
Contributor

Closes #910 only after all protected promotion gates are satisfied.

Problem and boundary

Replace reachable psycopg2-binary use in synchronous seed/admin/schema/test tooling with the LineageWeave-owned pg8000==1.31.5 compatibility boundary. Runtime persistence remains asyncpg; this PR does not move domain/schema authority or duplicate another CWL owner's functionality.

Generated-identifier quoting, SQLSTATE translation, transaction/context-manager behavior, resolver-candidate artifact identity/retention, committed uv.lock, public docstrings, and explicit TLS compatibility modes retain their RED→causal-repair coverage. Omitted sslmode fails closed as verify-full; ADR 0366 remains Proposed.

The libpq connect_timeout compatibility repair remains in this lane: URI timeout text is a decimal integer and zero/negative/omitted means no finite deadline. RED 326a97d89b3642fae392857218e4274bd456a8c0; causal repair b7838e40d6a200b8b9474cd03fcd52046c80bd6b; changelog predecessor 6030b295aadc3ee76dc4d27f5713273f35888325.

Current exact authority — 2026-09-23 KST

  • protected base: main@83eba56149eb802cd63642c507c324c9976ec78e
  • exact head: 2d91db2e76849dead722b343fb5d816886114b81
  • state: open / Draft / mechanically mergeable
  • ADR 0366: Proposed
  • qualifying independent current-head APPROVED: none

The current head is an ordinary ahead-only descendant of 6030b295... (ahead_by=1, behind_by=0). Commit 2d91db2... only removes the now-unused load_occupational_construct_evidence_status import from backend/app/main.py; it does not alter the pg8000/TLS/timeout contract. No open PR currently targets this branch as its base, so there is no descendant restack action.

Exact-head hosted evidence

Current-head repository evidence is terminal:

  • Tests 35530737544: SUCCESS;
  • PROV-O 35530737530: SUCCESS;
  • Ontology Pages 35530737566: SUCCESS;
  • SAST 35530737715: SUCCESS;
  • Security 35530737487: terminal FAILURE only at the canonical fail-closed Dependency Review availability boundary. Scope detection, OSV, Trivy and Scorecard are SUCCESS. Dependency Review job 106194100912 verified exact head 2d91db2..., then GET /dependency-graph/compare/83eba561...2d91db2... returned HTTP 403 with curl_exit=0; the pinned Dependency Review action was skipped because authoritative evidence was unavailable. Canonical owner remains .github#810; OSV/Trivy/Scorecard are not substitutes;
  • Required CodeQL 35530737493: terminal FAILURE at the canonical terminal-verdict settlement boundary. Detect-languages 106130754402 is SUCCESS. Python 106194204774, Actions 106194204879, and JavaScript/TypeScript 106194204917 each received hosted runners, read the current-head dispatch verdict, then failed at Release runner or enforce current-head CodeQL verdict. Follow-on coordinator 106287482234 later completed Dispatch current-head CodeQL scan SUCCESS, but the already-terminal receivers did not reconcile. Canonical owner is .github#1929.

The current-head OpenCode review is CHANGES_REQUESTED because its coverage gate is FAILURE; its review body explicitly synthesizes no source-backed product finding from that coverage gate. That distinction does not make the review accepting. Coverage and qualifying independent approval remain promotion gates.

Owner convergence

Historical CodeQL producer findings in lineageweave/http_client.py, lineageweave/post_chat.py, and frontend/src/postBodyDisplay.ts remain outside this commercial-license delta and must converge through their owner lanes (#974 and #983 or verified successors), not by copying those repairs here. The current Dependency Review 403 is likewise owned centrally in .github#810.

Promotion boundary

Keep this PR Draft and unmerged until authoritative Dependency Review evidence is available, Required CodeQL settlement is accepting against the then-current exact head/baseline, current-head coverage/review gates are accepting, all valid findings are resolved, and qualifying independent approval exists. Any source movement invalidates current receipts.

Do not self-approve, transfer predecessor evidence, reintroduce ADR 0363 collision, mark ADR 0366 Accepted prematurely, force-push, synthesize status, substitute scanners, copy another owner's repair, blind-rerun leaf jobs, add a source-neutral wake commit, or weaken the commercial-license/supply-chain gates.

@coderabbitai

coderabbitai Bot commented Sep 1, 2026 •

Copy link
Copy Markdown

Review Change StackReview Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: dac363a1-767e-437a-97db-54e5fede3f67

📥 Commits

Reviewing files that changed from the base of the PR and between 7651ca9 and 6030b29.

📒 Files selected for processing (6)
  • CHANGELOG.d/2.28.0-postgres-sync-driver.md
  • docs/adr/0366-synchronous-postgresql-default-tls.md
  • lineageweave/postgres_sync.py
  • tests/test_postgres_sync_adr_number_contract.py
  • tests/test_postgres_sync_sslmode_contract.py
  • tests/test_postgres_sync_timeout_contract.py
🚧 Files skipped from review as they are similar to previous changes (1)
  • CHANGELOG.d/2.28.0-postgres-sync-driver.md

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

동기 PostgreSQL 연결을 psycopg2에서 pg8000 기반 postgres_sync 어댑터로 교체했습니다. DSN, SQL 식별자, SSL, 오류 변환, 트랜잭션 동작을 구현했습니다. 호출부, 테스트, 선택적 모듈 검색, CI 잠금 검증과 변경 기록을 갱신했습니다.

Changes

동기 PostgreSQL 드라이버 교체

Layer / File(s) Summary
pg8000 어댑터와 호환성 계약
lineageweave/postgres_sync.py, tests/test_postgres_sync_driver_contract.py, tests/test_postgres_sync_sslmode_contract.py, tests/test_postgres_sync_timeout_contract.py
pg8000 기반 연결·커서 프록시를 추가했습니다. DSN, SSL 옵션, 타임아웃, SQL 식별자, SQLSTATE 오류를 처리합니다. 연결, 트랜잭션, 조회, 정리 동작을 검증합니다.
드라이버 의존성과 선택적 모듈 검색 갱신
pyproject.toml, lineageweave/optional_extra_collection.py, tests/test_optional_extra_collection.py
개발 의존성을 pg8000==1.31.5로 교체했습니다. 선택적 모듈 검색이 pg8000과 패키지 하위 모듈을 추적합니다.
호출부와 PostgreSQL 테스트 픽스처 전환
scripts/seed_demo_data.py, backend/app/main.py, backend/tests/test_api.py, tests/test_analysis_run_*.py, tests/test_schema.py, tests/test_source_post_voice_history_live.py, tests/test_synthetic_seed_cleanup.py, tests/test_person_mention_projection.py, tests/test_prov_o_schema.py
동기 PostgreSQL 연결과 오류 참조를 lineageweave.postgres_sync로 전환했습니다. 데이터베이스 생성·삭제 SQL에 sql.Identifier를 적용했습니다. 테스트 픽스처에 새 마이그레이션을 추가했습니다.
잠금 검증과 변경 기록
.github/workflows/tests.yml, tests/test_postgres_sync_review_regressions.py, CHANGELOG.d/2.28.0-postgres-sync-driver.md, docs/adr/0366-synchronous-postgresql-default-tls.md
CI에서 uv lock --check를 실행합니다. 잠금이 오래되면 생성된 uv.lock 후보를 artifact로 업로드하고 작업을 실패시킵니다. 잠금 후보, 트랜잭션 오류 변환, 기본 TLS 정책과 변경 내용을 검증하고 기록했습니다.

Priority: ➖ Normal

Estimated code review effort: 4 (Complex) | ~60 minutes

Change: Refactor · Severity of issue fixed: Medium

Sequence Diagram(s)

sequenceDiagram
  participant PostgreSQLTest
  participant postgres_sync
  participant pg8000
  participant PostgreSQL
  PostgreSQLTest->>postgres_sync: connect(DSN)
  postgres_sync->>postgres_sync: DSN 및 SSL 옵션 검증
  postgres_sync->>pg8000: 연결 생성
  pg8000->>PostgreSQL: 동기 연결 시도
  PostgreSQL-->>pg8000: 연결 또는 SQLSTATE 오류
  postgres_sync-->>PostgreSQLTest: Connection 또는 OperationalError
Loading

Merge Risk: ⚪ Minimal · up to 2d91d

The synchronous PostgreSQL migration has no identified merge-blocking risk in the supplied current-head evidence.

🚥 Pre-merge checks | ✅ 2 | ❌ 3

❌ Failed checks (3 warnings)

Check name Status Explanation Resolution
Linked Issues check ⚠️ Warning 직접 연결된 이슈 #910의 핵심 구현은 확인됩니다. pyproject.toml은 psycopg2-binary 대신 pg8000==1.31.5를 선언합니다. lineageweave/postgres_sync.py는 DSN 옵션, 식별자 인용, 타임아웃, TLS, SQLSTATE 변환, 커밋·롤백·정리 경계를 제공합니다. 관련 seed, admi… 커밋 6030b295aadc3ee76dc4d27f5713273f35888325에서 Tests, PROV-O, Security, SAST 게이트를 완료하십시오. 각 게이트의 exact-head 성공 결과와 resolver가 생성한 최종 uv.lock 바이트를 보존한 뒤 통합하십시오.
Out of Scope Changes check ⚠️ Warning 대부분의 변경은 #910의 동기 PostgreSQL 드라이버 교체와 직접 연결됩니다. 그러나 backend/app/main.py의 load_occupational_construct_evidence_status import 추가는 PostgreSQL 드라이버 경계, 라이선스 제거, DSN 호환성 또는 관련 테스트와 연결되지 않습니다. 변경 요약도 이 … backend/app/main.py의 occupational construct import 변경을 제거하십시오. 이 변경이 필요하면 #910과 직접 연결된 별도 이슈로 분리하십시오.
Docstring Coverage ⚠️ Warning Docstring coverage is 67.27% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 110 functions across 19 files. (2 skipped… Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (2 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed 제목은 동기식 PostgreSQL 경계에서 psycopg2를 교체하는 PR의 주요 변경 사항을 명확하고 간결하게 설명합니다.
Full details: Linked Issues check

Explanation

직접 연결된 이슈 #910의 핵심 구현은 확인됩니다. pyproject.toml은 psycopg2-binary 대신 pg8000==1.31.5를 선언합니다. lineageweave/postgres_sync.py는 DSN 옵션, 식별자 인용, 타임아웃, TLS, SQLSTATE 변환, 커밋·롤백·정리 경계를 제공합니다. 관련 seed, admin, schema, PROV-O 및 테스트 호출부도 해당 경계로 전환되었습니다. optional_extra_collection.py, 변경 로그, 잠금 검증 워크플로와 회귀 테스트도 추가되었습니다. 그러나 #910은 통합 전에 exact-head Tests, PROV-O, Security, SAST 게이트를 실행할 것을 요구합니다. 현재 exact head의 해당 워크플로는 queued 또는 pending이며, 독립적인 exact-head 승인도 없습니다. 따라서 이 코딩·검증 요구사항의 완료를 확인할 수 없습니다.

Full details: Out of Scope Changes check

Explanation

대부분의 변경은 #910의 동기 PostgreSQL 드라이버 교체와 직접 연결됩니다. 그러나 backend/app/main.py의 load_occupational_construct_evidence_status import 추가는 PostgreSQL 드라이버 경계, 라이선스 제거, DSN 호환성 또는 관련 테스트와 연결되지 않습니다. 변경 요약도 이 import를 별도 occupational construct 동작을 위한 준비 변경으로 설명합니다. 이 변경은 #910의 범위를 벗어납니다.

Full details: Docstring Coverage

Explanation

Docstring coverage is 67.27% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 110 functions across 19 files. (2 skipped: 2 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/remove-psycopg2-commercial-license

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@opencode-agent

opencode-agent Bot commented Sep 7, 2026

Copy link
Copy Markdown
Contributor

Scheduled review-feedback autofix for this PR head.

  • Head SHA: 5d40eed35a0b6e0d182397f8d02b29c38e9bdd17

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fresh canonical-owner correction: this PR body's OPENCODE_REPOSITORY_DISPATCH_ACTOR blocker is stale. .github#1927 now records post-change execution where opencode-agent[bot] was authorized by the live github-actions[bot],opencode-agent[bot] same-principal allowlist. Do not rerun/churn this leaf merely because that earlier authorization defect is fixed: .github#1902 is still Draft with the exact-job wake/recovery race unresolved, .github#810 still owns the public Dependency Review HTTP-403 availability incident, and this exact head still lacks qualifying independent approval. Preserve 5d40eed3..., ADR0366 Proposed, and the existing exact source/test evidence; merge readiness remains fail-closed on those current gates.

@opencode-agent

Copy link
Copy Markdown
Contributor

Scheduled review-feedback autofix for this PR head.

  • Head SHA: 5d40eed35a0b6e0d182397f8d02b29c38e9bdd17

@seonghobae
seonghobae marked this pull request as draft September 11, 2026 18:27
auto-merge was automatically disabled September 11, 2026 18:27

Pull request was converted to draft

@opencode-agent

Copy link
Copy Markdown
Contributor

Scheduled review-feedback autofix for this PR head.

  • Head SHA: 5d40eed35a0b6e0d182397f8d02b29c38e9bdd17

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fresh compatibility finding on the synchronous PostgreSQL boundary: the adapter had changed libpq connect_timeout semantics while the migration contract in #910 requires DSN behavior preservation. PostgreSQL 18 documents connect_timeout as a decimal integer and defines zero/negative/omitted as an indefinite wait. The prior adapter parsed URI values as arbitrary floats and rejected every non-positive value, so valid psycopg2/libpq DSNs such as ?connect_timeout=0 became configuration errors.

RED 326a97d89b3642fae392857218e4274bd456a8c0 adds focused DSN/keyword contracts for the no-deadline sentinel and rejects non-integer URI text. Causal repair b7838e40d6a200b8b9474cd03fcd52046c80bd6b preserves non-positive values by omitting pg8000's timeout argument and parses URI timeout text as an integer; 6030b295aadc3ee76dc4d27f5713273f35888325 makes the changelog code-current. PostgreSQL 18 source: https://www.postgresql.org/docs/18/libpq-connect.html (connect_timeout).

This does not widen the async runtime or another CWL owner's boundary. No predecessor GREEN is transferred: the PR remains Draft and fresh exact-head evidence must settle before promotion.

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

Please review exact head 6030b295aadc3ee76dc4d27f5713273f35888325, especially the new libpq connect_timeout compatibility RED→repair path (326a97d8… → b7838e40…) and whether the synchronous adapter still preserves the stated PostgreSQL 18 semantics without weakening the existing TLS/SQLSTATE boundaries.

@coderabbitai

coderabbitai Bot commented Sep 15, 2026 •

Copy link
Copy Markdown
🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo '== Commit availability and repository state =='
git rev-parse --verify 6030b295aadc3ee76dc4d27f5713273f35888325^{commit}
git status --short
git show -s --format='%H%n%P%n%s' 6030b295aadc3ee76dc4d27f5713273f35888325
echo '== Requested repair commits =='
git log --all --oneline --decorate --ancestry-path 326a97d8..b7838e40 2>/dev/null || true
git show -s --format='%H%n%P%n%s' 326a97d8 b7838e40 2>/dev/null || true

echo '== Relevant module outlines =='
ast-grep outline lineageweave/postgres_sync.py --items all --view expanded
ast-grep outline tests/test_postgres_sync_driver_contract.py --items all --view expanded
ast-grep outline tests/test_postgres_sync_review_regressions.py --items all --view expanded
ast-grep outline tests/test_postgres_sync_sslmode_contract.py --items all --view expanded

echo '== Diff from RED to repair =='
git diff --find-renames 326a97d8 b7838e40 -- lineageweave/postgres_sync.py tests/test_postgres_sync_driver_contract.py tests/test_postgres_sync_review_regressions.py tests/test_postgres_sync_sslmode_contract.py

echo '== Requested-head changes since repair =='
git diff --find-renames b7838e40 6030b295aadc3ee76dc4d27f5713273f35888325 -- lineageweave/postgres_sync.py tests/test_postgres_sync_driver_contract.py tests/test_postgres_sync_review_regressions.py tests/test_postgres_sync_sslmode_contract.py

echo '== Targeted implementation references =='
rg -n -C 5 --glob '*.py' '(connect_timeout|sslmode|_translate|sqlstate|SQLSTATE|commit\s*\(|rollback\s*\(|def connect\s*\()' lineageweave/postgres_sync.py tests/test_postgres_sync_driver_contract.py tests/test_postgres_sync_review_regressions.py tests/test_postgres_sync_sslmode_contract.py

Length of output: 46126


🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo '== Adapter implementation: TLS, URI parsing, timeout, and error translation =='
nl -ba lineageweave/postgres_sync.py | sed -n '118,285p'
nl -ba lineageweave/postgres_sync.py | sed -n '285,430p'

echo '== Driver contract timeout tests =='
nl -ba tests/test_postgres_sync_driver_contract.py | sed -n '176,245p'

echo '== TLS contract tests =='
nl -ba tests/test_postgres_sync_sslmode_contract.py | sed -n '1,125p'

echo '== Transaction SQLSTATE tests =='
nl -ba tests/test_postgres_sync_review_regressions.py | sed -n '1,110p'

echo '== RED commit patch and its parent context =='
git show --find-renames --format=fuller --stat 326a97d89b3642fae392857218e4274bd456a8c0
git show --find-renames --format= --unified=80 326a97d89b3642fae392857218e4274bd456a8c0 -- lineageweave/postgres_sync.py tests/test_postgres_sync_driver_contract.py

echo '== Direct synchronous adapter call sites =='
rg -n -C 2 --glob '*.py' '(?:from\s+lineageweave(?:\.postgres_sync|\s+import\s+postgres_sync)|import\s+lineageweave\.postgres_sync|postgres_sync\.connect\s*\(|psycopg2\.connect\s*\()' scripts backend tests lineageweave

Length of output: 60903


🤖 web_search executed:

PostgreSQL 18 documentation libpq connect_timeout connection parameter zero negative values integer seconds

Length of output: 4980


🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo '== RED-to-repair timeout contract =='
nl -ba tests/test_postgres_sync_timeout_contract.py | sed -n '1,160p'
git diff --find-renames --unified=80 326a97d89b3642fae392857218e4274bd456a8c0 b7838e40d6a200b8b9474cd03fcd52046c80bd6b -- tests/test_postgres_sync_timeout_contract.py

echo '== pg8000 pin and installed distribution metadata =='
rg -n -C 2 'pg8000' pyproject.toml uv.lock
python - <<'PY'
from importlib.metadata import metadata, version
try:
    print("pg8000 version:", version("pg8000"))
    md = metadata("pg8000")
    print("Home-page:", md.get("Home-page"))
    print("Project-URL:", md.get_all("Project-URL"))
except Exception as exc:
    print(type(exc).__name__ + ":", exc)
PY

echo '== Full repair commit =='
git show --format=fuller --find-renames --unified=20 b7838e40d6a200b8b9474cd03fcd52046c80bd6b

echo '== Timeout call sites and values =='
rg -n -C 3 --glob '*.py' '\bconnect\s*\([^)]*connect_timeout\s*=' backend scripts tests lineageweave

Length of output: 17386


🤖 web_search executed:

pg8000 1.31.5 dbapi connect timeout parameter documentation seconds accepted values

Length of output: 9627


@seonghobae I reviewed exact commit 6030b295aadc3ee76dc4d27f5713273f35888325.

I found no blocking regression in the 326a97d8… to b7838e40… repair path.

  • The repair matches the PostgreSQL 18 connect_timeout contract. URI values must be decimal integers. Zero, negative, and omitted values mean no deadline.
  • connection_kwargs_from_dsn() now omits pg8000’s timeout argument for zero and negative values. pg8000 treats an omitted timeout as no timeout.
  • The caller argument still overrides the URI value. The dedicated contract tests cover both DSN and keyword non-positive values.
  • The repair rejects fractional URI values. This preserves the PostgreSQL 18 integer-only URI grammar.
  • The existing reachability probes use connect_timeout=2. Their bounded behavior remains unchanged.

The repair does not modify the TLS or SQLSTATE boundaries.

  • The default remains fail-closed sslmode=verify-full.
  • sslmode=prefer still attempts TLS first. It retries plaintext only for the exact pg8000 Server refuses SSL condition.
  • Arbitrary TLS or network failures do not downgrade to plaintext.
  • sslmode=require still uses encrypted transport without implicit certificate or hostname verification.
  • SQLSTATE translation remains active for execute, executemany, commit, rollback, and transaction completion through Connection.__exit__.

I did not run repository tests because the inspection environment does not execute repository code. The static implementation and contract tests are consistent with the reviewed PostgreSQL 18 timeout, TLS, and SQLSTATE requirements.

⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@seonghobae
seonghobae marked this pull request as ready for review September 15, 2026 13:58
@seonghobae
seonghobae marked this pull request as draft September 15, 2026 13:58
@seonghobae
seonghobae marked this pull request as ready for review September 15, 2026 14:01

Copy link
Copy Markdown
Contributor Author

Current exact-head gate correction for 6030b295aadc3ee76dc4d27f5713273f35888325; this supersedes the body’s earlier “Security queued” snapshot without changing source.

  • Security Scan 34977841173 is now terminal failure, not queued.
  • The causal failing job is dependency-review 104497459473: exact checkout/verification succeeded, Check dependency review support failed, and the pinned Dependency review step was skipped.
  • changed-scope, OSV, Trivy and Scorecard on the same required Security run completed successfully, so this is not evidence of a pg8000/libpq product regression.
  • Canonical owner remains ContextualWisdomLab/.github#810; fresh downstream evidence was recorded there as comment 5689139333.
  • CodeQL PR 34977841115 remains queued and has no terminal exact-head receipt.

#911 therefore stays Ready only for validation admission and is not merge-authorized. Do not rerun/churn the unchanged source merely to clear the hard gate, substitute independent scanners for Dependency Review, transfer predecessor receipts, or weaken the required Security contract.

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode reviewed the current-head product diff. Coverage is a separate gate.

Changed files

  • .github/workflows/tests.yml — GitHub Actions review job
  • CHANGELOG.d/2.28.0-postgres-sync-driver.md — repository behavior
  • backend/app/main.py — API and service runtime
  • backend/tests/test_api.py — regression suite
  • docs/adr/0366-synchronous-postgresql-default-tls.md — operator or user guidance
  • lineageweave/optional_extra_collection.py — Python module behavior
  • lineageweave/postgres_sync.py — Python module behavior
  • pyproject.toml — repository behavior
  • scripts/seed_demo_data.py — Python module behavior
  • tests/test_analysis_run_authorization.py — regression suite
  • tests/test_analysis_run_reconstruction_schema.py — regression suite
  • tests/test_analysis_run_registry_schema.py — regression suite
  • tests/test_optional_extra_collection.py — regression suite
  • tests/test_person_mention_projection.py — regression suite
  • tests/test_postgres_sync_adr_number_contract.py — regression suite
  • tests/test_postgres_sync_driver_contract.py — regression suite
  • tests/test_postgres_sync_review_regressions.py — regression suite
  • tests/test_postgres_sync_sslmode_contract.py — regression suite
  • tests/test_postgres_sync_timeout_contract.py — regression suite
  • tests/test_prov_o_schema.py — regression suite
  • tests/test_schema.py — regression suite
  • tests/test_source_post_voice_history_live.py — regression suite
  • tests/test_synthetic_seed_cleanup.py — regression suite
  • uv.lock — repository behavior

Changed behavior

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Workflow: tests.yml"]
  S1 --> I1["GitHub Actions review job"]
  I1 --> R1["Review risk: Workflow: tests.yml"]
  R1 --> V1["actionlint plus required checks"]
  Evidence --> S2["Repository file: 2.28.0-postgres-sync-driver.md"]
  S2 --> I2["repository behavior"]
  I2 --> R2["Review risk: Repository file: 2.28.0-postgres-sync-driver.md"]
  R2 --> V2["required checks"]
  Evidence --> S3["Backend: main.py"]
  S3 --> I3["API and service runtime"]
  I3 --> R3["Review risk: Backend: main.py"]
  R3 --> V3["backend tests"]
  Evidence --> S4["Test: test_api.py"]
  S4 --> I4["regression suite"]
  I4 --> R4["Review risk: Test: test_api.py"]
  R4 --> V4["targeted test run"]
  Evidence --> S5["Docs: 0366-synchronous-postgresql-default-tls.md"]
  S5 --> I5["operator or user guidance"]
  I5 --> R5["Review risk: Docs: 0366-synchronous-postgresql-default-tls.md"]
  R5 --> V5["docs review"]
  Evidence --> S6["Python: optional_extra_collection.py (3 files)"]
  S6 --> I6["Python module behavior"]
  I6 --> R6["Review risk: Python: optional_extra_collection.py (3 files)"]
  R6 --> V6["pytest plus coverage"]
  Evidence --> S7["Repository file: pyproject.toml"]
  S7 --> I7["repository behavior"]
  I7 --> R7["Review risk: Repository file: pyproject.toml"]
  R7 --> V7["required checks"]
  Evidence --> S8["Test: test_analysis_run_authorization.py (14 files)"]
  S8 --> I8["regression suite"]
  I8 --> R8["Review risk: Test: test_analysis_run_authorization.py (14 files)"]
  R8 --> V8["targeted test run"]
  Evidence --> S9["Repository file: uv.lock"]
  S9 --> I9["repository behavior"]
  I9 --> R9["Review risk: Repository file: uv.lock"]
  R9 --> V9["required checks"]
Loading

Findings

No source-backed product finding is synthesized from the coverage gate. A coverage miss belongs in the status comment.

  • Head SHA: 6030b295aadc3ee76dc4d27f5713273f35888325
  • Workflow run: 35042841604
  • Workflow attempt: 1
  • Coverage gate: failure

Review outcome

Coverage is a gate, not the review. This body reviews the changed product files.

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Workflow: tests.yml"]
  S1 --> I1["GitHub Actions review job"]
  I1 --> R1["Review risk: Workflow: tests.yml"]
  R1 --> V1["actionlint plus required checks"]
  Evidence --> S2["Repository file: 2.28.0-postgres-sync-driver.md"]
  S2 --> I2["repository behavior"]
  I2 --> R2["Review risk: Repository file: 2.28.0-postgres-sync-driver.md"]
  R2 --> V2["required checks"]
  Evidence --> S3["Backend: main.py"]
  S3 --> I3["API and service runtime"]
  I3 --> R3["Review risk: Backend: main.py"]
  R3 --> V3["backend tests"]
  Evidence --> S4["Test: test_api.py"]
  S4 --> I4["regression suite"]
  I4 --> R4["Review risk: Test: test_api.py"]
  R4 --> V4["targeted test run"]
  Evidence --> S5["Docs: 0366-synchronous-postgresql-default-tls.md"]
  S5 --> I5["operator or user guidance"]
  I5 --> R5["Review risk: Docs: 0366-synchronous-postgresql-default-tls.md"]
  R5 --> V5["docs review"]
  Evidence --> S6["Python: optional_extra_collection.py (3 files)"]
  S6 --> I6["Python module behavior"]
  I6 --> R6["Review risk: Python: optional_extra_collection.py (3 files)"]
  R6 --> V6["pytest plus coverage"]
  Evidence --> S7["Repository file: pyproject.toml"]
  S7 --> I7["repository behavior"]
  I7 --> R7["Review risk: Repository file: pyproject.toml"]
  R7 --> V7["required checks"]
  Evidence --> S8["Test: test_analysis_run_authorization.py (14 files)"]
  S8 --> I8["regression suite"]
  I8 --> R8["Review risk: Test: test_analysis_run_authorization.py (14 files)"]
  R8 --> V8["targeted test run"]
  Evidence --> S9["Repository file: uv.lock"]
  S9 --> I9["repository behavior"]
  I9 --> R9["Review risk: Repository file: uv.lock"]
  R9 --> V9["required checks"]
Loading

@opencode-agent

opencode-agent Bot commented Sep 16, 2026 •

Copy link
Copy Markdown
Contributor

OpenCode Review Overview

Coverage evidence did not pass, so approval is blocked. The formal pull-request review is the source-backed diff review, not this status comment.

@seonghobae
seonghobae enabled auto-merge (squash) September 20, 2026 18:59
@opencode-agent
opencode-agent Bot disabled auto-merge September 21, 2026 02:19
@seonghobae
seonghobae enabled auto-merge (squash) September 21, 2026 17:27

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode reviewed the current-head product diff. Coverage is a separate gate.

Changed files

  • .github/workflows/tests.yml — GitHub Actions review job
  • CHANGELOG.d/2.28.0-postgres-sync-driver.md — repository behavior
  • backend/tests/test_api.py — regression suite
  • docs/adr/0366-synchronous-postgresql-default-tls.md — operator or user guidance
  • lineageweave/optional_extra_collection.py — Python module behavior
  • lineageweave/postgres_sync.py — Python module behavior
  • pyproject.toml — repository behavior
  • scripts/seed_demo_data.py — Python module behavior
  • tests/test_analysis_run_authorization.py — regression suite
  • tests/test_analysis_run_reconstruction_schema.py — regression suite
  • tests/test_analysis_run_registry_schema.py — regression suite
  • tests/test_optional_extra_collection.py — regression suite
  • tests/test_person_mention_projection.py — regression suite
  • tests/test_postgres_sync_adr_number_contract.py — regression suite
  • tests/test_postgres_sync_driver_contract.py — regression suite
  • tests/test_postgres_sync_review_regressions.py — regression suite
  • tests/test_postgres_sync_sslmode_contract.py — regression suite
  • tests/test_postgres_sync_timeout_contract.py — regression suite
  • tests/test_prov_o_schema.py — regression suite
  • tests/test_schema.py — regression suite
  • tests/test_source_post_voice_history_live.py — regression suite
  • tests/test_synthetic_seed_cleanup.py — regression suite
  • uv.lock — repository behavior

Changed behavior

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Workflow: tests.yml"]
  S1 --> I1["GitHub Actions review job"]
  I1 --> R1["Review risk: Workflow: tests.yml"]
  R1 --> V1["actionlint plus required checks"]
  Evidence --> S2["Repository file: 2.28.0-postgres-sync-driver.md"]
  S2 --> I2["repository behavior"]
  I2 --> R2["Review risk: Repository file: 2.28.0-postgres-sync-driver.md"]
  R2 --> V2["required checks"]
  Evidence --> S3["Test: test_api.py"]
  S3 --> I3["regression suite"]
  I3 --> R3["Review risk: Test: test_api.py"]
  R3 --> V3["targeted test run"]
  Evidence --> S4["Docs: 0366-synchronous-postgresql-default-tls.md"]
  S4 --> I4["operator or user guidance"]
  I4 --> R4["Review risk: Docs: 0366-synchronous-postgresql-default-tls.md"]
  R4 --> V4["docs review"]
  Evidence --> S5["Python: optional_extra_collection.py (3 files)"]
  S5 --> I5["Python module behavior"]
  I5 --> R5["Review risk: Python: optional_extra_collection.py (3 files)"]
  R5 --> V5["pytest plus coverage"]
  Evidence --> S6["Repository file: pyproject.toml"]
  S6 --> I6["repository behavior"]
  I6 --> R6["Review risk: Repository file: pyproject.toml"]
  R6 --> V6["required checks"]
  Evidence --> S7["Test: test_analysis_run_authorization.py (14 files)"]
  S7 --> I7["regression suite"]
  I7 --> R7["Review risk: Test: test_analysis_run_authorization.py (14 files)"]
  R7 --> V7["targeted test run"]
  Evidence --> S8["Repository file: uv.lock"]
  S8 --> I8["repository behavior"]
  I8 --> R8["Review risk: Repository file: uv.lock"]
  R8 --> V8["required checks"]
Loading

Findings

No source-backed product finding is synthesized from the coverage gate. A coverage miss belongs in the status comment.

  • Head SHA: 2d91db2e76849dead722b343fb5d816886114b81
  • Workflow run: 35584806055
  • Workflow attempt: 1
  • Coverage gate: failure

Review outcome

Coverage is a gate, not the review. This body reviews the changed product files.

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Workflow: tests.yml"]
  S1 --> I1["GitHub Actions review job"]
  I1 --> R1["Review risk: Workflow: tests.yml"]
  R1 --> V1["actionlint plus required checks"]
  Evidence --> S2["Repository file: 2.28.0-postgres-sync-driver.md"]
  S2 --> I2["repository behavior"]
  I2 --> R2["Review risk: Repository file: 2.28.0-postgres-sync-driver.md"]
  R2 --> V2["required checks"]
  Evidence --> S3["Test: test_api.py"]
  S3 --> I3["regression suite"]
  I3 --> R3["Review risk: Test: test_api.py"]
  R3 --> V3["targeted test run"]
  Evidence --> S4["Docs: 0366-synchronous-postgresql-default-tls.md"]
  S4 --> I4["operator or user guidance"]
  I4 --> R4["Review risk: Docs: 0366-synchronous-postgresql-default-tls.md"]
  R4 --> V4["docs review"]
  Evidence --> S5["Python: optional_extra_collection.py (3 files)"]
  S5 --> I5["Python module behavior"]
  I5 --> R5["Review risk: Python: optional_extra_collection.py (3 files)"]
  R5 --> V5["pytest plus coverage"]
  Evidence --> S6["Repository file: pyproject.toml"]
  S6 --> I6["repository behavior"]
  I6 --> R6["Review risk: Repository file: pyproject.toml"]
  R6 --> V6["required checks"]
  Evidence --> S7["Test: test_analysis_run_authorization.py (14 files)"]
  S7 --> I7["regression suite"]
  I7 --> R7["Review risk: Test: test_analysis_run_authorization.py (14 files)"]
  R7 --> V7["targeted test run"]
  Evidence --> S8["Repository file: uv.lock"]
  S8 --> I8["repository behavior"]
  I8 --> R8["Review risk: Repository file: uv.lock"]
  R8 --> V8["required checks"]
Loading

@seonghobae
seonghobae marked this pull request as draft September 22, 2026 20:54
auto-merge was automatically disabled September 22, 2026 20:54

Pull request was converted to draft

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

license: remove LGPL psycopg2 dependency path

1 participant