fix(license): replace psycopg2 synchronous PostgreSQL boundary - #911
seonghobae wants to merge 72 commits into
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (6)
🚧 Files skipped from review as they are similar to previous changes (1)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthrough동기 PostgreSQL 연결을 Changes동기 PostgreSQL 드라이버 교체
Priority: ➖ Normal Estimated code review effort: 4 (Complex) | ~60 minutes Change: Refactor · Severity of issue fixed: Medium Sequence Diagram(s)sequenceDiagram
participant PostgreSQLTest
participant postgres_sync
participant pg8000
participant PostgreSQL
PostgreSQLTest->>postgres_sync: connect(DSN)
postgres_sync->>postgres_sync: DSN 및 SSL 옵션 검증
postgres_sync->>pg8000: 연결 생성
pg8000->>PostgreSQL: 동기 연결 시도
PostgreSQL-->>pg8000: 연결 또는 SQLSTATE 오류
postgres_sync-->>PostgreSQLTest: Connection 또는 OperationalError
Merge Risk: ⚪ Minimal · up to The synchronous PostgreSQL migration has no identified merge-blocking risk in the supplied current-head evidence. 🚥 Pre-merge checks | ✅ 2 | ❌ 3❌ Failed checks (3 warnings)
✅ Passed checks (2 passed)
Full details: Linked Issues checkExplanation 직접 연결된 이슈 Full details: Out of Scope Changes checkExplanation 대부분의 변경은 Full details: Docstring CoverageExplanation Docstring coverage is 67.27% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 110 functions across 19 files. (2 skipped: 2 unsupported.)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Scheduled review-feedback autofix for this PR head.
|
seonghobae
left a comment
There was a problem hiding this comment.
Fresh canonical-owner correction: this PR body's OPENCODE_REPOSITORY_DISPATCH_ACTOR blocker is stale. .github#1927 now records post-change execution where opencode-agent[bot] was authorized by the live github-actions[bot],opencode-agent[bot] same-principal allowlist. Do not rerun/churn this leaf merely because that earlier authorization defect is fixed: .github#1902 is still Draft with the exact-job wake/recovery race unresolved, .github#810 still owns the public Dependency Review HTTP-403 availability incident, and this exact head still lacks qualifying independent approval. Preserve 5d40eed3..., ADR0366 Proposed, and the existing exact source/test evidence; merge readiness remains fail-closed on those current gates.
|
Scheduled review-feedback autofix for this PR head.
|
Pull request was converted to draft
|
Scheduled review-feedback autofix for this PR head.
|
seonghobae
left a comment
There was a problem hiding this comment.
Fresh compatibility finding on the synchronous PostgreSQL boundary: the adapter had changed libpq connect_timeout semantics while the migration contract in #910 requires DSN behavior preservation. PostgreSQL 18 documents connect_timeout as a decimal integer and defines zero/negative/omitted as an indefinite wait. The prior adapter parsed URI values as arbitrary floats and rejected every non-positive value, so valid psycopg2/libpq DSNs such as ?connect_timeout=0 became configuration errors.
RED 326a97d89b3642fae392857218e4274bd456a8c0 adds focused DSN/keyword contracts for the no-deadline sentinel and rejects non-integer URI text. Causal repair b7838e40d6a200b8b9474cd03fcd52046c80bd6b preserves non-positive values by omitting pg8000's timeout argument and parses URI timeout text as an integer; 6030b295aadc3ee76dc4d27f5713273f35888325 makes the changelog code-current. PostgreSQL 18 source: https://www.postgresql.org/docs/18/libpq-connect.html (connect_timeout).
This does not widen the async runtime or another CWL owner's boundary. No predecessor GREEN is transferred: the PR remains Draft and fresh exact-head evidence must settle before promotion.
|
@coderabbitai review Please review exact head |
🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
echo '== Commit availability and repository state =='
git rev-parse --verify 6030b295aadc3ee76dc4d27f5713273f35888325^{commit}
git status --short
git show -s --format='%H%n%P%n%s' 6030b295aadc3ee76dc4d27f5713273f35888325
echo '== Requested repair commits =='
git log --all --oneline --decorate --ancestry-path 326a97d8..b7838e40 2>/dev/null || true
git show -s --format='%H%n%P%n%s' 326a97d8 b7838e40 2>/dev/null || true
echo '== Relevant module outlines =='
ast-grep outline lineageweave/postgres_sync.py --items all --view expanded
ast-grep outline tests/test_postgres_sync_driver_contract.py --items all --view expanded
ast-grep outline tests/test_postgres_sync_review_regressions.py --items all --view expanded
ast-grep outline tests/test_postgres_sync_sslmode_contract.py --items all --view expanded
echo '== Diff from RED to repair =='
git diff --find-renames 326a97d8 b7838e40 -- lineageweave/postgres_sync.py tests/test_postgres_sync_driver_contract.py tests/test_postgres_sync_review_regressions.py tests/test_postgres_sync_sslmode_contract.py
echo '== Requested-head changes since repair =='
git diff --find-renames b7838e40 6030b295aadc3ee76dc4d27f5713273f35888325 -- lineageweave/postgres_sync.py tests/test_postgres_sync_driver_contract.py tests/test_postgres_sync_review_regressions.py tests/test_postgres_sync_sslmode_contract.py
echo '== Targeted implementation references =='
rg -n -C 5 --glob '*.py' '(connect_timeout|sslmode|_translate|sqlstate|SQLSTATE|commit\s*\(|rollback\s*\(|def connect\s*\()' lineageweave/postgres_sync.py tests/test_postgres_sync_driver_contract.py tests/test_postgres_sync_review_regressions.py tests/test_postgres_sync_sslmode_contract.pyLength of output: 46126 🏁 Script executed: #!/bin/bash
set -euo pipefail
echo '== Adapter implementation: TLS, URI parsing, timeout, and error translation =='
nl -ba lineageweave/postgres_sync.py | sed -n '118,285p'
nl -ba lineageweave/postgres_sync.py | sed -n '285,430p'
echo '== Driver contract timeout tests =='
nl -ba tests/test_postgres_sync_driver_contract.py | sed -n '176,245p'
echo '== TLS contract tests =='
nl -ba tests/test_postgres_sync_sslmode_contract.py | sed -n '1,125p'
echo '== Transaction SQLSTATE tests =='
nl -ba tests/test_postgres_sync_review_regressions.py | sed -n '1,110p'
echo '== RED commit patch and its parent context =='
git show --find-renames --format=fuller --stat 326a97d89b3642fae392857218e4274bd456a8c0
git show --find-renames --format= --unified=80 326a97d89b3642fae392857218e4274bd456a8c0 -- lineageweave/postgres_sync.py tests/test_postgres_sync_driver_contract.py
echo '== Direct synchronous adapter call sites =='
rg -n -C 2 --glob '*.py' '(?:from\s+lineageweave(?:\.postgres_sync|\s+import\s+postgres_sync)|import\s+lineageweave\.postgres_sync|postgres_sync\.connect\s*\(|psycopg2\.connect\s*\()' scripts backend tests lineageweaveLength of output: 60903 🤖 web_search executed:
Length of output: 4980 🏁 Script executed: #!/bin/bash
set -euo pipefail
echo '== RED-to-repair timeout contract =='
nl -ba tests/test_postgres_sync_timeout_contract.py | sed -n '1,160p'
git diff --find-renames --unified=80 326a97d89b3642fae392857218e4274bd456a8c0 b7838e40d6a200b8b9474cd03fcd52046c80bd6b -- tests/test_postgres_sync_timeout_contract.py
echo '== pg8000 pin and installed distribution metadata =='
rg -n -C 2 'pg8000' pyproject.toml uv.lock
python - <<'PY'
from importlib.metadata import metadata, version
try:
print("pg8000 version:", version("pg8000"))
md = metadata("pg8000")
print("Home-page:", md.get("Home-page"))
print("Project-URL:", md.get_all("Project-URL"))
except Exception as exc:
print(type(exc).__name__ + ":", exc)
PY
echo '== Full repair commit =='
git show --format=fuller --find-renames --unified=20 b7838e40d6a200b8b9474cd03fcd52046c80bd6b
echo '== Timeout call sites and values =='
rg -n -C 3 --glob '*.py' '\bconnect\s*\([^)]*connect_timeout\s*=' backend scripts tests lineageweaveLength of output: 17386 🤖 web_search executed:
Length of output: 9627
I found no blocking regression in the
The repair does not modify the TLS or SQLSTATE boundaries.
I did not run repository tests because the inspection environment does not execute repository code. The static implementation and contract tests are consistent with the reviewed PostgreSQL 18 timeout, TLS, and SQLSTATE requirements.
|
|
Current exact-head gate correction for
#911 therefore stays Ready only for validation admission and is not merge-authorized. Do not rerun/churn the unchanged source merely to clear the hard gate, substitute independent scanners for Dependency Review, transfer predecessor receipts, or weaken the required Security contract. |
There was a problem hiding this comment.
Pull request overview
OpenCode reviewed the current-head product diff. Coverage is a separate gate.
Changed files
.github/workflows/tests.yml— GitHub Actions review jobCHANGELOG.d/2.28.0-postgres-sync-driver.md— repository behaviorbackend/app/main.py— API and service runtimebackend/tests/test_api.py— regression suitedocs/adr/0366-synchronous-postgresql-default-tls.md— operator or user guidancelineageweave/optional_extra_collection.py— Python module behaviorlineageweave/postgres_sync.py— Python module behaviorpyproject.toml— repository behaviorscripts/seed_demo_data.py— Python module behaviortests/test_analysis_run_authorization.py— regression suitetests/test_analysis_run_reconstruction_schema.py— regression suitetests/test_analysis_run_registry_schema.py— regression suitetests/test_optional_extra_collection.py— regression suitetests/test_person_mention_projection.py— regression suitetests/test_postgres_sync_adr_number_contract.py— regression suitetests/test_postgres_sync_driver_contract.py— regression suitetests/test_postgres_sync_review_regressions.py— regression suitetests/test_postgres_sync_sslmode_contract.py— regression suitetests/test_postgres_sync_timeout_contract.py— regression suitetests/test_prov_o_schema.py— regression suitetests/test_schema.py— regression suitetests/test_source_post_voice_history_live.py— regression suitetests/test_synthetic_seed_cleanup.py— regression suiteuv.lock— repository behavior
Changed behavior
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow: tests.yml"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow: tests.yml"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Repository file: 2.28.0-postgres-sync-driver.md"]
S2 --> I2["repository behavior"]
I2 --> R2["Review risk: Repository file: 2.28.0-postgres-sync-driver.md"]
R2 --> V2["required checks"]
Evidence --> S3["Backend: main.py"]
S3 --> I3["API and service runtime"]
I3 --> R3["Review risk: Backend: main.py"]
R3 --> V3["backend tests"]
Evidence --> S4["Test: test_api.py"]
S4 --> I4["regression suite"]
I4 --> R4["Review risk: Test: test_api.py"]
R4 --> V4["targeted test run"]
Evidence --> S5["Docs: 0366-synchronous-postgresql-default-tls.md"]
S5 --> I5["operator or user guidance"]
I5 --> R5["Review risk: Docs: 0366-synchronous-postgresql-default-tls.md"]
R5 --> V5["docs review"]
Evidence --> S6["Python: optional_extra_collection.py (3 files)"]
S6 --> I6["Python module behavior"]
I6 --> R6["Review risk: Python: optional_extra_collection.py (3 files)"]
R6 --> V6["pytest plus coverage"]
Evidence --> S7["Repository file: pyproject.toml"]
S7 --> I7["repository behavior"]
I7 --> R7["Review risk: Repository file: pyproject.toml"]
R7 --> V7["required checks"]
Evidence --> S8["Test: test_analysis_run_authorization.py (14 files)"]
S8 --> I8["regression suite"]
I8 --> R8["Review risk: Test: test_analysis_run_authorization.py (14 files)"]
R8 --> V8["targeted test run"]
Evidence --> S9["Repository file: uv.lock"]
S9 --> I9["repository behavior"]
I9 --> R9["Review risk: Repository file: uv.lock"]
R9 --> V9["required checks"]
Findings
No source-backed product finding is synthesized from the coverage gate. A coverage miss belongs in the status comment.
- Head SHA:
6030b295aadc3ee76dc4d27f5713273f35888325 - Workflow run: 35042841604
- Workflow attempt: 1
- Coverage gate:
failure
Review outcome
Coverage is a gate, not the review. This body reviews the changed product files.
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow: tests.yml"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow: tests.yml"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Repository file: 2.28.0-postgres-sync-driver.md"]
S2 --> I2["repository behavior"]
I2 --> R2["Review risk: Repository file: 2.28.0-postgres-sync-driver.md"]
R2 --> V2["required checks"]
Evidence --> S3["Backend: main.py"]
S3 --> I3["API and service runtime"]
I3 --> R3["Review risk: Backend: main.py"]
R3 --> V3["backend tests"]
Evidence --> S4["Test: test_api.py"]
S4 --> I4["regression suite"]
I4 --> R4["Review risk: Test: test_api.py"]
R4 --> V4["targeted test run"]
Evidence --> S5["Docs: 0366-synchronous-postgresql-default-tls.md"]
S5 --> I5["operator or user guidance"]
I5 --> R5["Review risk: Docs: 0366-synchronous-postgresql-default-tls.md"]
R5 --> V5["docs review"]
Evidence --> S6["Python: optional_extra_collection.py (3 files)"]
S6 --> I6["Python module behavior"]
I6 --> R6["Review risk: Python: optional_extra_collection.py (3 files)"]
R6 --> V6["pytest plus coverage"]
Evidence --> S7["Repository file: pyproject.toml"]
S7 --> I7["repository behavior"]
I7 --> R7["Review risk: Repository file: pyproject.toml"]
R7 --> V7["required checks"]
Evidence --> S8["Test: test_analysis_run_authorization.py (14 files)"]
S8 --> I8["regression suite"]
I8 --> R8["Review risk: Test: test_analysis_run_authorization.py (14 files)"]
R8 --> V8["targeted test run"]
Evidence --> S9["Repository file: uv.lock"]
S9 --> I9["repository behavior"]
I9 --> R9["Review risk: Repository file: uv.lock"]
R9 --> V9["required checks"]
OpenCode Review Overview
Coverage evidence did not pass, so approval is blocked. The formal pull-request review is the source-backed diff review, not this status comment. |
There was a problem hiding this comment.
Pull request overview
OpenCode reviewed the current-head product diff. Coverage is a separate gate.
Changed files
.github/workflows/tests.yml— GitHub Actions review jobCHANGELOG.d/2.28.0-postgres-sync-driver.md— repository behaviorbackend/tests/test_api.py— regression suitedocs/adr/0366-synchronous-postgresql-default-tls.md— operator or user guidancelineageweave/optional_extra_collection.py— Python module behaviorlineageweave/postgres_sync.py— Python module behaviorpyproject.toml— repository behaviorscripts/seed_demo_data.py— Python module behaviortests/test_analysis_run_authorization.py— regression suitetests/test_analysis_run_reconstruction_schema.py— regression suitetests/test_analysis_run_registry_schema.py— regression suitetests/test_optional_extra_collection.py— regression suitetests/test_person_mention_projection.py— regression suitetests/test_postgres_sync_adr_number_contract.py— regression suitetests/test_postgres_sync_driver_contract.py— regression suitetests/test_postgres_sync_review_regressions.py— regression suitetests/test_postgres_sync_sslmode_contract.py— regression suitetests/test_postgres_sync_timeout_contract.py— regression suitetests/test_prov_o_schema.py— regression suitetests/test_schema.py— regression suitetests/test_source_post_voice_history_live.py— regression suitetests/test_synthetic_seed_cleanup.py— regression suiteuv.lock— repository behavior
Changed behavior
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow: tests.yml"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow: tests.yml"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Repository file: 2.28.0-postgres-sync-driver.md"]
S2 --> I2["repository behavior"]
I2 --> R2["Review risk: Repository file: 2.28.0-postgres-sync-driver.md"]
R2 --> V2["required checks"]
Evidence --> S3["Test: test_api.py"]
S3 --> I3["regression suite"]
I3 --> R3["Review risk: Test: test_api.py"]
R3 --> V3["targeted test run"]
Evidence --> S4["Docs: 0366-synchronous-postgresql-default-tls.md"]
S4 --> I4["operator or user guidance"]
I4 --> R4["Review risk: Docs: 0366-synchronous-postgresql-default-tls.md"]
R4 --> V4["docs review"]
Evidence --> S5["Python: optional_extra_collection.py (3 files)"]
S5 --> I5["Python module behavior"]
I5 --> R5["Review risk: Python: optional_extra_collection.py (3 files)"]
R5 --> V5["pytest plus coverage"]
Evidence --> S6["Repository file: pyproject.toml"]
S6 --> I6["repository behavior"]
I6 --> R6["Review risk: Repository file: pyproject.toml"]
R6 --> V6["required checks"]
Evidence --> S7["Test: test_analysis_run_authorization.py (14 files)"]
S7 --> I7["regression suite"]
I7 --> R7["Review risk: Test: test_analysis_run_authorization.py (14 files)"]
R7 --> V7["targeted test run"]
Evidence --> S8["Repository file: uv.lock"]
S8 --> I8["repository behavior"]
I8 --> R8["Review risk: Repository file: uv.lock"]
R8 --> V8["required checks"]
Findings
No source-backed product finding is synthesized from the coverage gate. A coverage miss belongs in the status comment.
- Head SHA:
2d91db2e76849dead722b343fb5d816886114b81 - Workflow run: 35584806055
- Workflow attempt: 1
- Coverage gate:
failure
Review outcome
Coverage is a gate, not the review. This body reviews the changed product files.
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow: tests.yml"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow: tests.yml"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Repository file: 2.28.0-postgres-sync-driver.md"]
S2 --> I2["repository behavior"]
I2 --> R2["Review risk: Repository file: 2.28.0-postgres-sync-driver.md"]
R2 --> V2["required checks"]
Evidence --> S3["Test: test_api.py"]
S3 --> I3["regression suite"]
I3 --> R3["Review risk: Test: test_api.py"]
R3 --> V3["targeted test run"]
Evidence --> S4["Docs: 0366-synchronous-postgresql-default-tls.md"]
S4 --> I4["operator or user guidance"]
I4 --> R4["Review risk: Docs: 0366-synchronous-postgresql-default-tls.md"]
R4 --> V4["docs review"]
Evidence --> S5["Python: optional_extra_collection.py (3 files)"]
S5 --> I5["Python module behavior"]
I5 --> R5["Review risk: Python: optional_extra_collection.py (3 files)"]
R5 --> V5["pytest plus coverage"]
Evidence --> S6["Repository file: pyproject.toml"]
S6 --> I6["repository behavior"]
I6 --> R6["Review risk: Repository file: pyproject.toml"]
R6 --> V6["required checks"]
Evidence --> S7["Test: test_analysis_run_authorization.py (14 files)"]
S7 --> I7["regression suite"]
I7 --> R7["Review risk: Test: test_analysis_run_authorization.py (14 files)"]
R7 --> V7["targeted test run"]
Evidence --> S8["Repository file: uv.lock"]
S8 --> I8["repository behavior"]
I8 --> R8["Review risk: Repository file: uv.lock"]
R8 --> V8["required checks"]
Pull request was converted to draft
Closes #910 only after all protected promotion gates are satisfied.
Problem and boundary
Replace reachable
psycopg2-binaryuse in synchronous seed/admin/schema/test tooling with the LineageWeave-ownedpg8000==1.31.5compatibility boundary. Runtime persistence remainsasyncpg; this PR does not move domain/schema authority or duplicate another CWL owner's functionality.Generated-identifier quoting, SQLSTATE translation, transaction/context-manager behavior, resolver-candidate artifact identity/retention, committed
uv.lock, public docstrings, and explicit TLS compatibility modes retain their RED→causal-repair coverage. Omittedsslmodefails closed asverify-full; ADR 0366 remains Proposed.The libpq
connect_timeoutcompatibility repair remains in this lane: URI timeout text is a decimal integer and zero/negative/omitted means no finite deadline. RED326a97d89b3642fae392857218e4274bd456a8c0; causal repairb7838e40d6a200b8b9474cd03fcd52046c80bd6b; changelog predecessor6030b295aadc3ee76dc4d27f5713273f35888325.Current exact authority — 2026-09-23 KST
main@83eba56149eb802cd63642c507c324c9976ec78e2d91db2e76849dead722b343fb5d816886114b81APPROVED: noneThe current head is an ordinary ahead-only descendant of
6030b295...(ahead_by=1,behind_by=0). Commit2d91db2...only removes the now-unusedload_occupational_construct_evidence_statusimport frombackend/app/main.py; it does not alter the pg8000/TLS/timeout contract. No open PR currently targets this branch as its base, so there is no descendant restack action.Exact-head hosted evidence
Current-head repository evidence is terminal:
35530737544: SUCCESS;35530737530: SUCCESS;35530737566: SUCCESS;35530737715: SUCCESS;35530737487: terminal FAILURE only at the canonical fail-closed Dependency Review availability boundary. Scope detection, OSV, Trivy and Scorecard are SUCCESS. Dependency Review job106194100912verified exact head2d91db2..., thenGET /dependency-graph/compare/83eba561...2d91db2...returned HTTP403withcurl_exit=0; the pinned Dependency Review action was skipped because authoritative evidence was unavailable. Canonical owner remains.github#810; OSV/Trivy/Scorecard are not substitutes;35530737493: terminal FAILURE at the canonical terminal-verdict settlement boundary. Detect-languages106130754402is SUCCESS. Python106194204774, Actions106194204879, and JavaScript/TypeScript106194204917each received hosted runners, read the current-head dispatch verdict, then failed atRelease runner or enforce current-head CodeQL verdict. Follow-on coordinator106287482234later completedDispatch current-head CodeQL scanSUCCESS, but the already-terminal receivers did not reconcile. Canonical owner is.github#1929.The current-head OpenCode review is
CHANGES_REQUESTEDbecause its coverage gate is FAILURE; its review body explicitly synthesizes no source-backed product finding from that coverage gate. That distinction does not make the review accepting. Coverage and qualifying independent approval remain promotion gates.Owner convergence
Historical CodeQL producer findings in
lineageweave/http_client.py,lineageweave/post_chat.py, andfrontend/src/postBodyDisplay.tsremain outside this commercial-license delta and must converge through their owner lanes (#974 and #983 or verified successors), not by copying those repairs here. The current Dependency Review 403 is likewise owned centrally in.github#810.Promotion boundary
Keep this PR Draft and unmerged until authoritative Dependency Review evidence is available, Required CodeQL settlement is accepting against the then-current exact head/baseline, current-head coverage/review gates are accepting, all valid findings are resolved, and qualifying independent approval exists. Any source movement invalidates current receipts.
Do not self-approve, transfer predecessor evidence, reintroduce ADR 0363 collision, mark ADR 0366 Accepted prematurely, force-push, synthesize status, substitute scanners, copy another owner's repair, blind-rerun leaf jobs, add a source-neutral wake commit, or weaken the commercial-license/supply-chain gates.