Skip to content

fix(chat): preserve null timeouts and attribute worker expiry - #974

Draft
seonghobae wants to merge 8 commits into
mainfrom
codex/ask-timeout-attribution-20260907
Draft

seonghobae wants to merge 8 commits into
mainfrom
codex/ask-timeout-attribution-20260907

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 7, 2026 •

Copy link
Copy Markdown
Contributor

Current authority — 2026-09-19

  • Protected base: main@83eba56149eb802cd63642c507c324c9976ec78e
  • Exact head: 4341080f6027d869acb08896e41d761c3f3b8e77
  • State: open / Draft / mechanically mergeable
  • Direct descendant fix(ask): fence Ask settlement on the claim generation #979: 2dfd21110813f474d3068796d0733d96f28d6061
  • Qualifying independent current-head APPROVE: none

This lane owns the repository-baseline Python CodeQL repairs outside unrelated product PRs. ReDoS RED 216e4e3c41161f49b65c48128e8c178790222e3d remains causally fixed by linear whitespace normalization plus .rstrip("?.!").

The TLS finding required predecessor source repair ff2bcba3c85853da67acf90680e7927a5c9c83e7: _build_ssl_context() constructs the certifi-backed context and applies minimum_version = ssl.TLSVersion.TLSv1_2 before the context escapes, preserving hostname and certificate verification while presenting CodeQL with the secure local dataflow shape. No query, SARIF severity, provider/model/routing behavior, certificate verification, or TLS floor was weakened.

Hosted RED and causal test repair

Predecessor Tests 35243765633 executed after queue admission. Frontend 105278564382 succeeded across lint, tests, build and Storybook. Full suite/PostgreSQL 105278564710 failed narrowly at 1778 passed / 147 skipped / 1 failed: tests/test_http_client_tls_floor_contract.py::test_http_client_declares_tls_1_2_floor_in_owned_transport_boundary still required the obsolete source spelling _SSL_CONTEXT.minimum_version = ssl.TLSVersion.TLSv1_2 even though the intentional CodeQL repair had moved the floor assignment inside _build_ssl_context().

Current head 4341080f... is the minimal causal repair. The TLS contract test now patches ssl.create_default_context with a context starting at MINIMUM_SUPPORTED, invokes _build_ssl_context(), and requires that same object to be raised exactly to TLSv1_2. The live _SSL_CONTEXT floor assertion remains. This proves explicit owner configuration without pinning the scanner-hostile predecessor alias shape.

Fresh exact-head execution

The repaired exact head has executed the repository/security suites:

  • Tests 35267030859: SUCCESS.
    • Full test suite/PostgreSQL 105356637935: SUCCESS; dependency install and the full PostgreSQL suite executed on hosted runner 1002018321.
    • Frontend lint/test/build 105356638142: SUCCESS; lint, test, build and Storybook all executed on hosted runner 1002018322.
  • SAST 35267030789: SUCCESS.
  • Security 35267030604: SUCCESS.
    • scope detection 105356643326: SUCCESS;
    • Scorecard 105432724807: SUCCESS, including exact-head checkout, scan, SARIF filtering and upload;
    • Trivy filesystem 105432724858: SUCCESS, including exact-head checkout, SARIF gate and upload;
    • inapplicable gitleaks/OSV/dependency-review jobs are scope-skipped rather than substituted for another required check.
  • CodeQL PR 35267030868: FAILURE at the canonical dispatch-verdict settlement boundary.
    • Detect CodeQL languages 105428561110: SUCCESS.
    • compatibility actions 105486539836, python 105486539838, javascript-typescript 105486539845: all received hosted runners, successfully read the current-head dispatch state, then failed only at Release runner or enforce current-head CodeQL verdict.
    • dispatch job 105545993014: SUCCESS.

The Python job log is exact: the verdict-read step emitted verdict=pending, with DISPATCH_OUTCOME=success; the enforcement step then failed with CodeQL scan dispatched. The dispatch workflow will rerun this exact failed CodeQL job after publishing its terminal verdict. A fresh status read on exact 4341080f... still exposes no authenticated codeql-dispatch/* status, only Devin Review and CodeRabbit. The expected producer verdict publication/rerun therefore did not converge.

This consumer specimen has been handed to canonical .github#1929 in comment 5733274869. It is the same producer/consumer settlement class observed on #929, not a new LineageWeave source finding. No consumer wake commit, blind rerun, local CodeQL fork, synthetic status, or gate weakening is admitted.

The exact-head repository RED caused by the stale TLS test contract is closed and Tests/SAST/Security are GREEN. CodeQL is terminal RED, so the PR has been returned to Draft and those successful suites are not merge authority by themselves.

Independent protected-baseline CodeQL evidence remains canonical producer .github run 35152871013 from unrelated #1115: its Python artifact contains py/insecure-protocol and py/polynomial-redos on the older protected state. Evidence comment 5718846884 is baseline classification only, not acceptance of this repaired head.

Protected canonical .github/main remains 64aa08d7fa487deacd41c761c36277ca68cab6c9, protected and signature-valid. #2213 improves queue-health classification but does not manufacture product or scanner acceptance.

#979 remains ordinarily/non-force converged to 2dfd21110813f474d3068796d0733d96f28d6061 on this exact parent. The parent head/base did not move, so no descendant restack is required and no child receipt transfers backward.

Promotion requires canonical current-head producer/consumer CodeQL settlement proving the Python findings absent, qualifying independent exact-head approval, and normal protected integration. No self-approval, gate weakening, force push, destructive rebase, synthetic status, blind rerun, deployment, or release is claimed.

@coderabbitai

coderabbitai Bot commented Sep 7, 2026 •

Copy link
Copy Markdown

Review Change StackReview Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: f116457f-e0e9-4ea6-843c-d42e21aba150

📥 Commits

Reviewing files that changed from the base of the PR and between ff2bcba and 4341080.

📒 Files selected for processing (1)
  • tests/test_http_client_tls_floor_contract.py

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

Global Ask는 자체 타이머가 만료된 경우에만 데드라인 실패로 처리합니다. post-chat은 None 및 명시적 타임아웃을 HTTP 전송 계층까지 전달합니다. TLS 최소 버전과 질문 정규화 계약도 갱신합니다.

Changes

타임아웃 귀속 및 전달

Layer / File(s) Summary
Global Ask 데드라인 귀속
AGENTS.md, backend/app/global_ask_queue.py, tests/test_global_ask_queue.py, docs/product-technical-gap-baseline.md
asyncio.timeout의 만료 상태를 사용합니다. 상류 TimeoutError, 작업자 데드라인, 종료 취소를 서로 다른 결과로 검증합니다.
post-chat 선택적 타임아웃 전달
backend/app/main.py, lineageweave/post_chat.py, lineageweave/http_client.py, tests/test_post_chat.py, tests/test_http_client.py, docs/adr/0083-orchestrator-runtime-commit-pin.md, docs/product-technical-gap-baseline.md
post-chat 기본 타임아웃을 None으로 변경합니다. factory와 HTTP 전송 계층은 None 및 명시적 초 값을 그대로 전달합니다.

전송 및 입력 정규화 계약

Layer / File(s) Summary
TLS 및 질문 정규화 계약
lineageweave/http_client.py, lineageweave/post_chat.py, tests/test_http_client_tls_floor_contract.py
HTTPS 최소 TLS 버전을 TLS 1.2로 설정합니다. 질문 후행 처리를 rstrip("?.!")로 변경하고 관련 계약 테스트를 추가합니다.

Priority: ⬇️ Low

Estimated code review effort: 3 (Moderate) | ~25 minutes

Change: Bug fix

Sequence Diagram(s)

sequenceDiagram
  participant GlobalAskWorker
  participant compute_global_ask_answer
  participant Settlement
  GlobalAskWorker->>compute_global_ask_answer: 작업 계산 실행
  compute_global_ask_answer-->>GlobalAskWorker: 결과 또는 TimeoutError
  GlobalAskWorker->>GlobalAskWorker: answer_timeout.expired() 확인
  GlobalAskWorker->>Settlement: 데드라인 또는 일반 실패 정산
Loading
sequenceDiagram
  participant _post_chat_client
  participant ContextualOrchestratorPostChatClient
  participant post_json
  participant HTTPConnection
  _post_chat_client->>ContextualOrchestratorPostChatClient: timeout 전달
  ContextualOrchestratorPostChatClient->>post_json: 선택적 timeout 전달
  post_json->>HTTPConnection: timeout 또는 None 전달
Loading

Merge Risk: ⚪ Minimal · up to 43410

The changes preserve timeout behavior, enforce TLS 1.2, and retain question normalization semantics. Current-head validation remains pending, but no actionable code risk is established.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 60.87% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 23 functions across 8 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed 제목은 명시적 null 타임아웃 보존과 워커 만료 귀속 변경이라는 주요 변경 사항을 정확하고 간결하게 설명합니다.
  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@seonghobae seonghobae added the bug Something isn't working label Sep 7, 2026 — with ChatGPT Codex Connector
@seonghobae seonghobae changed the title fix(ask): distinguish provider timeouts from worker expiry fix(chat): preserve null timeouts and attribute worker expiry Sep 7, 2026

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode reviewed the current-head product diff. Coverage is a separate gate.

Changed files

  • AGENTS.md — repository behavior
  • backend/app/global_ask_queue.py — API and service runtime
  • backend/app/main.py — API and service runtime
  • docs/adr/0083-orchestrator-runtime-commit-pin.md — operator or user guidance
  • docs/product-technical-gap-baseline.md — operator or user guidance
  • lineageweave/http_client.py — Python module behavior
  • lineageweave/post_chat.py — Python module behavior
  • tests/test_global_ask_queue.py — regression suite
  • tests/test_http_client.py — regression suite
  • tests/test_post_chat.py — regression suite

Changed behavior

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Repository file: AGENTS.md"]
  S1 --> I1["repository behavior"]
  I1 --> R1["Review risk: Repository file: AGENTS.md"]
  R1 --> V1["required checks"]
  Evidence --> S2["Backend: global_ask_queue.py (2 files)"]
  S2 --> I2["API and service runtime"]
  I2 --> R2["Review risk: Backend: global_ask_queue.py (2 files)"]
  R2 --> V2["backend tests"]
  Evidence --> S3["Docs: 0083-orchestrator-runtime-commit-pin.md (2 files)"]
  S3 --> I3["operator or user guidance"]
  I3 --> R3["Review risk: Docs: 0083-orchestrator-runtime-commit-pin.md (2 files)"]
  R3 --> V3["docs review"]
  Evidence --> S4["Python: http_client.py (2 files)"]
  S4 --> I4["Python module behavior"]
  I4 --> R4["Review risk: Python: http_client.py (2 files)"]
  R4 --> V4["pytest plus coverage"]
  Evidence --> S5["Test: test_global_ask_queue.py (3 files)"]
  S5 --> I5["regression suite"]
  I5 --> R5["Review risk: Test: test_global_ask_queue.py (3 files)"]
  R5 --> V5["targeted test run"]
Loading

Findings

No source-backed product finding is synthesized from the coverage gate. A coverage miss belongs in the status comment.

  • Head SHA: def15fc691d4442c0d82103c1642147b1528d7be
  • Workflow run: 34111705214
  • Workflow attempt: 1
  • Coverage gate: failure

Review outcome

Coverage is a gate, not the review. This body reviews the changed product files.

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Repository file: AGENTS.md"]
  S1 --> I1["repository behavior"]
  I1 --> R1["Review risk: Repository file: AGENTS.md"]
  R1 --> V1["required checks"]
  Evidence --> S2["Backend: global_ask_queue.py (2 files)"]
  S2 --> I2["API and service runtime"]
  I2 --> R2["Review risk: Backend: global_ask_queue.py (2 files)"]
  R2 --> V2["backend tests"]
  Evidence --> S3["Docs: 0083-orchestrator-runtime-commit-pin.md (2 files)"]
  S3 --> I3["operator or user guidance"]
  I3 --> R3["Review risk: Docs: 0083-orchestrator-runtime-commit-pin.md (2 files)"]
  R3 --> V3["docs review"]
  Evidence --> S4["Python: http_client.py (2 files)"]
  S4 --> I4["Python module behavior"]
  I4 --> R4["Review risk: Python: http_client.py (2 files)"]
  R4 --> V4["pytest plus coverage"]
  Evidence --> S5["Test: test_global_ask_queue.py (3 files)"]
  S5 --> I5["regression suite"]
  I5 --> R5["Review risk: Test: test_global_ask_queue.py (3 files)"]
  R5 --> V5["targeted test run"]
Loading

@opencode-agent

opencode-agent Bot commented Sep 7, 2026 •

Copy link
Copy Markdown
Contributor

OpenCode Review Overview

Coverage evidence did not pass, so approval is blocked. The formal pull-request review is the source-backed diff review, not this status comment.

@seonghobae
seonghobae enabled auto-merge (squash) September 8, 2026 02:45
@seonghobae
seonghobae marked this pull request as draft September 11, 2026 20:20
auto-merge was automatically disabled September 11, 2026 20:20

Pull request was converted to draft

seonghobae added a commit that referenced this pull request Sep 15, 2026
cwl-noema-review[bot]
cwl-noema-review Bot previously approved these changes Sep 16, 2026

@cwl-noema-review cwl-noema-review Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Noema LLM review

The PR correctly preserves null transport timeouts through the post-chat factory and shared HTTP transport, and attributes the worker deadline only when the asyncio timeout context actually expired. The added answer_timeout.expired() guard prevents provider TimeoutErrors from being misreported as the worker's own deadline expiry. Tests cover direct and factory construction with omitted/null/numeric timeouts, provider versus worker versus shutdown timeout sources, and null as well as numeric HTTP transport timeouts. No blocking issues found.

Reviewed changed lines

  • backend/app/global_ask_queue.py:589 (RIGHT): The added answer_timeout is not None and answer_timeout.expired() check ensures only an actual asyncio.timeout context expiry is attributed to the worker deadline. Provider-raised asyncio.TimeoutError instances without an expired local timer now fall through to the bounded unavailable message, preventing misdiagnosis of the durable job outcome.
  • backend/app/main.py:520 (RIGHT): The factory now passes timeout=timeout directly to the client, eliminating the conditional that dropped a None value and restored the previous 180-second default. Omitted and explicit-null timeouts both propagate as null, while explicit numeric limits are preserved unchanged.
  • lineageweave/http_client.py:152 (RIGHT): The _request signature accepts float | None with no new adapter, allowing a null timeout to flow through the shared HTTP transport. Explicit numeric timeouts remain supported, and the TLSv1.2 minimum version is set on the shared SSL context.

Adversarial validation

  • backend/app/global_ask_queue.py:589 (RIGHT) falsified: A TimeoutError raised by the upstream provider is misattributed as expiry of the worker's execution deadline. — test_timeout_detail_identifies_only_an_expired_worker_deadline parametrizes timeout_source as 'provider', 'worker', and 'shutdown'. The provider case asserts the durable detail is 'Ask Agent is unavailable: contextual-orchestrator returned no complete evidence object'; the worker case asserts 'job exceeded the 0s deadline'.
  • backend/app/main.py:520 (RIGHT) falsified: The factory silently drops an explicit null timeout or imposes a default 180-second limit, contradicting the requested default-null behavior. — test_post_chat_preserves_optional_transport_timeout parametrizes timeout_options as {}, {'timeout': None}, and {'timeout': 7.5} for both direct and factory creation. Each configuration asserts the observed transport timeout is exactly None (for omitted/null) or 7.5.
  • lineageweave/http_client.py:152 (RIGHT) falsified: The shared HTTP transport rejects or coerces a null timeout, breaking null propagation from the client. — test_post_json_posts_json_to_http_endpoint in tests/test_http_client.py is parametrized with request_timeout=None and 2.0; both paths successfully POST to a local HTTP server and assert the server receives the payload without timeout-related errors.
  • Residual risk: Null transport timeouts do not prove blocking-socket cancellation; the explicit 570-second Ask worker socket setting, 600-second execution deadline, and age-based orphan recovery remain unresolved. Optional-model timeout behavior for other clients and upstream model administration still require owner-aligned verification.

Findings

  • No blocking findings.
  • Result: APPROVE
  • Head SHA: 6911954363888d1e2d523ebbcf68f68d7217752a
  • Reviewer credential: noema-review-github-app-refresh
  • Actor: cwl-noema-review[bot]

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode reviewed the current-head product diff. Coverage is a separate gate.

Changed files

  • AGENTS.md — repository behavior
  • backend/app/global_ask_queue.py — API and service runtime
  • backend/app/main.py — API and service runtime
  • docs/adr/0083-orchestrator-runtime-commit-pin.md — operator or user guidance
  • docs/product-technical-gap-baseline.md — operator or user guidance
  • lineageweave/http_client.py — Python module behavior
  • lineageweave/post_chat.py — Python module behavior
  • tests/test_global_ask_queue.py — regression suite
  • tests/test_http_client.py — regression suite
  • tests/test_http_client_tls_floor_contract.py — regression suite
  • tests/test_post_chat.py — regression suite

Changed behavior

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Repository file: AGENTS.md"]
  S1 --> I1["repository behavior"]
  I1 --> R1["Review risk: Repository file: AGENTS.md"]
  R1 --> V1["required checks"]
  Evidence --> S2["Backend: global_ask_queue.py (2 files)"]
  S2 --> I2["API and service runtime"]
  I2 --> R2["Review risk: Backend: global_ask_queue.py (2 files)"]
  R2 --> V2["backend tests"]
  Evidence --> S3["Docs: 0083-orchestrator-runtime-commit-pin.md (2 files)"]
  S3 --> I3["operator or user guidance"]
  I3 --> R3["Review risk: Docs: 0083-orchestrator-runtime-commit-pin.md (2 files)"]
  R3 --> V3["docs review"]
  Evidence --> S4["Python: http_client.py (2 files)"]
  S4 --> I4["Python module behavior"]
  I4 --> R4["Review risk: Python: http_client.py (2 files)"]
  R4 --> V4["pytest plus coverage"]
  Evidence --> S5["Test: test_global_ask_queue.py (4 files)"]
  S5 --> I5["regression suite"]
  I5 --> R5["Review risk: Test: test_global_ask_queue.py (4 files)"]
  R5 --> V5["targeted test run"]
Loading

Findings

No source-backed product finding is synthesized from the coverage gate. A coverage miss belongs in the status comment.

  • Head SHA: 6911954363888d1e2d523ebbcf68f68d7217752a
  • Workflow run: 35089654032
  • Workflow attempt: 1
  • Coverage gate: failure

Review outcome

Coverage is a gate, not the review. This body reviews the changed product files.

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Repository file: AGENTS.md"]
  S1 --> I1["repository behavior"]
  I1 --> R1["Review risk: Repository file: AGENTS.md"]
  R1 --> V1["required checks"]
  Evidence --> S2["Backend: global_ask_queue.py (2 files)"]
  S2 --> I2["API and service runtime"]
  I2 --> R2["Review risk: Backend: global_ask_queue.py (2 files)"]
  R2 --> V2["backend tests"]
  Evidence --> S3["Docs: 0083-orchestrator-runtime-commit-pin.md (2 files)"]
  S3 --> I3["operator or user guidance"]
  I3 --> R3["Review risk: Docs: 0083-orchestrator-runtime-commit-pin.md (2 files)"]
  R3 --> V3["docs review"]
  Evidence --> S4["Python: http_client.py (2 files)"]
  S4 --> I4["Python module behavior"]
  I4 --> R4["Review risk: Python: http_client.py (2 files)"]
  R4 --> V4["pytest plus coverage"]
  Evidence --> S5["Test: test_global_ask_queue.py (4 files)"]
  S5 --> I5["regression suite"]
  I5 --> R5["Review risk: Test: test_global_ask_queue.py (4 files)"]
  R5 --> V5["targeted test run"]
Loading

Copy link
Copy Markdown
Contributor Author

Fresh independent CodeQL evidence from the exact #1115 producer changes the baseline classification but does not transfer GREEN here. Canonical .github producer run 35152871013 scanned LineageWeave #1115@6545b5ff7ed88d98daad74ca3ba8f8606dad3fc4 against protected main@83eba56149eb802cd63642c507c324c9976ec78e. Its Python job 105039317130 reached CodeQL analysis and failed the Medium+ SARIF gate with exactly two repository-baseline findings: py/insecure-protocol at lineageweave/http_client.py:193 and py/polynomial-redos at lineageweave/post_chat.py:48. Preserved artifact: codeql-dispatch-python-35152871013-1, digest sha256:d5ed4802bffeed9a58bdc7aa599b6fe31f81d5e803d14e8952e66f830ba5114c.

Those paths are this owner lane, not #1115's image-ingestion delta. Current #974 head ff2bcba3c85853da67acf90680e7927a5c9c83e7 already carries the linear punctuation repair and the scanner-visible TLS construction repair, but its fresh Tests/SAST/CodeQL/Security runs are still queued. Treat the #1115 producer artifact as independent predecessor/baseline confirmation only; do not call #974 GREEN until this exact head receives current producer/consumer settlement. No query allowlist, gate weakening, or source copy to #1115.

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode reviewed the current-head product diff. Coverage is a separate gate.

Changed files

  • AGENTS.md — repository behavior
  • backend/app/global_ask_queue.py — API and service runtime
  • backend/app/main.py — API and service runtime
  • docs/adr/0083-orchestrator-runtime-commit-pin.md — operator or user guidance
  • docs/product-technical-gap-baseline.md — operator or user guidance
  • lineageweave/http_client.py — Python module behavior
  • lineageweave/post_chat.py — Python module behavior
  • tests/test_global_ask_queue.py — regression suite
  • tests/test_http_client.py — regression suite
  • tests/test_http_client_tls_floor_contract.py — regression suite
  • tests/test_post_chat.py — regression suite

Changed behavior

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Repository file: AGENTS.md"]
  S1 --> I1["repository behavior"]
  I1 --> R1["Review risk: Repository file: AGENTS.md"]
  R1 --> V1["required checks"]
  Evidence --> S2["Backend: global_ask_queue.py (2 files)"]
  S2 --> I2["API and service runtime"]
  I2 --> R2["Review risk: Backend: global_ask_queue.py (2 files)"]
  R2 --> V2["backend tests"]
  Evidence --> S3["Docs: 0083-orchestrator-runtime-commit-pin.md (2 files)"]
  S3 --> I3["operator or user guidance"]
  I3 --> R3["Review risk: Docs: 0083-orchestrator-runtime-commit-pin.md (2 files)"]
  R3 --> V3["docs review"]
  Evidence --> S4["Python: http_client.py (2 files)"]
  S4 --> I4["Python module behavior"]
  I4 --> R4["Review risk: Python: http_client.py (2 files)"]
  R4 --> V4["pytest plus coverage"]
  Evidence --> S5["Test: test_global_ask_queue.py (4 files)"]
  S5 --> I5["regression suite"]
  I5 --> R5["Review risk: Test: test_global_ask_queue.py (4 files)"]
  R5 --> V5["targeted test run"]
Loading

Findings

No source-backed product finding is synthesized from the coverage gate. A coverage miss belongs in the status comment.

  • Head SHA: 4341080f6027d869acb08896e41d761c3f3b8e77
  • Workflow run: 35310296619
  • Workflow attempt: 1
  • Coverage gate: failure

Review outcome

Coverage is a gate, not the review. This body reviews the changed product files.

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Repository file: AGENTS.md"]
  S1 --> I1["repository behavior"]
  I1 --> R1["Review risk: Repository file: AGENTS.md"]
  R1 --> V1["required checks"]
  Evidence --> S2["Backend: global_ask_queue.py (2 files)"]
  S2 --> I2["API and service runtime"]
  I2 --> R2["Review risk: Backend: global_ask_queue.py (2 files)"]
  R2 --> V2["backend tests"]
  Evidence --> S3["Docs: 0083-orchestrator-runtime-commit-pin.md (2 files)"]
  S3 --> I3["operator or user guidance"]
  I3 --> R3["Review risk: Docs: 0083-orchestrator-runtime-commit-pin.md (2 files)"]
  R3 --> V3["docs review"]
  Evidence --> S4["Python: http_client.py (2 files)"]
  S4 --> I4["Python module behavior"]
  I4 --> R4["Review risk: Python: http_client.py (2 files)"]
  R4 --> V4["pytest plus coverage"]
  Evidence --> S5["Test: test_global_ask_queue.py (4 files)"]
  S5 --> I5["regression suite"]
  I5 --> R5["Review risk: Test: test_global_ask_queue.py (4 files)"]
  R5 --> V5["targeted test run"]
Loading

seonghobae added a commit that referenced this pull request Sep 21, 2026
* docs(gaps): refresh exact-head product evidence

Record protected-main authority, live aggregate inventory, the active Customer Master cycle repair, and remaining acceptance boundaries.

Commit-Message-Assisted-by: Claude (via Claude Code)
Signed-off-by: Seongho Bae <me@seonghobae.me>

* docs(gaps): bind Customer Master evidence to current head

Record the current implementation SHA and the desktop/mobile Storybook audit while leaving authenticated PostgreSQL acceptance unresolved.

Commit-Message-Assisted-by: Claude (via Claude Code)
Signed-off-by: Seongho Bae <me@seonghobae.me>

* docs(gaps): refresh current repair ownership evidence

* docs(gaps): refresh ready-state evidence

* docs(gaps): retract stale Ready evidence

* docs(gaps): refresh exact-head queue evidence

* docs(gaps): record authenticated scope repair evidence

* docs(gaps): refresh protected loop evidence

* docs(gaps): track replay repair head

* docs(gaps): correct replay exact head

* chore(docs): stage exact-head gap baseline refresh

* docs(gaps): refresh live exact-head authority

* chore(docs): refresh live gap overlay

* chore(docs): remove purpose-complete refresh workflow

* chore: stage bounded gap baseline refresh

* fix: make bounded gap refresh workflow parseable

* docs(gaps): refresh terminal Strix security evidence

* chore: stage current gap baseline refresh

* docs(gaps): record fresh security repair lanes

* chore: stage final current gap baseline refresh

* docs(gaps): refresh current security evidence

* ci(docs): stage bounded baseline refresh

* docs(gaps): refresh live exact-head overlay

* chore(gaps): stage current authority overlay

* chore(gaps): apply current authority overlay

* docs(gaps): refresh customer-master exact-head authority

* chore(gaps): stage 10:14 exact-head overlay

* chore(gaps): run 10:14 exact-head overlay

* docs(gaps): refresh exact-head customer-master evidence

* chore(docs): stage bounded gap baseline refresh

* docs(gaps): refresh exact-head security evidence

* chore(docs): stage bounded gap baseline refresh

* docs(gaps): refresh exact-head product evidence

* chore(docs): stage live-authority baseline refresh

* fix(docs): repair bounded live baseline workflow

* docs(gaps): refresh live product authority

* chore(gaps): stage bounded authority refresh

* chore(gaps): remove failed bounded refresh helper

* chore(docs): stage bounded baseline refresh

* docs(gaps): converge release owner authority

* docs(gaps): refresh current product authority

* chore(docs): stage bounded gap baseline refresh

* fix(docs): repair bounded gap baseline refresh runner

* fix(docs): keep refresh payload inside workflow block

* docs(gaps): refresh current Customer Master evidence

* chore(docs): stage 20:05 gap baseline refresh

* chore(docs): remove queued baseline helper

* chore(docs): refresh 20:27 live gap baseline

* docs(gaps): refresh 20:27 live authority

* docs(gaps): make current baseline projection explicit

* docs(gaps): refresh exact-head acceptance evidence

* docs(gaps): record review-sidecar prerequisite RED

* docs(gaps): record prerequisite exact-head GREEN

* docs(gaps): refresh current gate evidence

* docs(gaps): record exact-head security green

* docs(gaps): refresh live review execution evidence

* docs(gaps): record exact-head full-diff review evidence

* docs(gaps): refresh central prerequisite evidence

* docs(gaps): record exact-head review prerequisite approval

* docs(gaps): correct current required-gate inventory

* docs(gaps): record terminal review runtime evidence

* docs(gaps): record current-main ADR occupancy reconstruction

* docs(gaps): refresh central review gate settlement

* docs(gaps): record canonical CodeQL dispatch progress

* docs(gaps): record reconstructed comparison post repair

* docs(gaps): record criterion coordinate stack convergence

* docs(gaps): record current leftover-map stack convergence

* docs(gaps): record non-force leftover-map convergence

* docs(gaps): record comparison-axis repair and stack convergence

* docs(gaps): record graphic badge repair and descendant convergence

* docs(product): refresh live gap authority after owner and stack repairs

* docs(product): refresh owner ADR authority after review repair

* docs(gaps): record owner-boundary descendant convergence

* docs(gaps): include bounded-operator descendant convergence

* docs(gaps): record PostgreSQL timeout compatibility repair

* docs(gaps): record exact-head PostgreSQL validation admission

* docs(gaps): keep PostgreSQL validation admission current

* docs(gaps): record report-axis missingness repair and current stack

* docs(gaps): record live report-axis RED and descendant convergence

* docs(gaps): repair live leftover-map ancestry authority

* docs(gaps): refresh exact-head validation evidence

* docs(gaps): refresh leftover-map convergence and repair RCA

* docs(gaps): record comparison tick i18n RED

* docs(gaps): refresh measurement descendant authority

* docs(gaps): record fail-closed dependency review and queue differential

* docs(gaps): record CodeQL owner repairs and parser finding

* docs(gaps): admit exact-head validation for CodeQL repairs

* docs(gaps): record post-body CodeQL repair and convergence

* docs(gaps): record attributed script-tag parser repair

* docs(gaps): record unresolved embedded-image parser gap

* docs(gaps): refresh parser and leftover-map evidence

* docs(gaps): refresh current product and validation authority

* docs(gaps): record backend embedded-image parser repair

* docs(gaps): advance embedded-image repair authority

* docs(gaps): record current #1115 provenance repair

* docs(gap): align owner-boundary lifecycle and stack heads

* docs(gap): record hosted leftover-map and warning owner evidence

* docs(gaps): record #983 hosted coverage evidence

* docs(gaps): record repaired tick foundation and converged stack

* docs(gaps): record comparison tick repair and convergence

* docs(gaps): refresh live report-stack authority

* docs(gaps): record repaired tick-share stack

* docs(gaps): record terminal CodeQL verdict failure

* docs(gaps): record current #983 coverage evidence

* docs(gaps): record hosted parser RED and repair

* docs(gaps): record scanner edge coverage convergence

* docs(gaps): record ontology extension coverage ancestry

* docs(gaps): correct report-axis exact head

* docs(gaps): record image-ingestion security green

* docs(gaps): record catalog coverage convergence

* docs(gaps): converge report stack and current receipts

* docs(gaps): record current-head cancellation class

* docs(gaps): record comparison post accessibility evidence

* docs(gaps): record current CodeQL producer state

* docs(gaps): record #873 test coverage and descendant convergence

* docs(gaps): refresh #873 exact queue evidence

* docs(gaps): refresh #1115 CodeQL producer progress

* docs(gaps): track Customer Master eight-locale review draft

* docs(gaps): follow translation draft test repair

* docs(gaps): admit translation candidate validation

* docs(gaps): record Customer Master seed ownership repair

* docs(gaps): scope Customer Master seed ownership lifecycle

* docs(gaps): record translation ownership search-path repair

* docs(gaps): track ledger search-path integrity repair

* docs(gaps): track seed ownership replay concurrency

* docs(gaps): refresh canonical scheduler authority

* docs(gaps): record concurrent Customer Master seed replay repair

* docs(gaps): refresh canonical GitHub owner authority

* docs(gaps): track reviewed translation replay preservation

* docs(gaps): refresh canonical owner head

* docs(gaps): record completed-seed retirement lifecycle

* docs(gaps): record non-destructive ownership upgrade

* docs(gaps): track versioned ownership constraint repair

* docs(gaps): follow canonical CodeQL owner movement

* docs(gaps): classify terminal CodeQL owner findings

* docs(gaps): refresh canonical queue owner

* docs(gaps): classify executed image CodeQL producer

* docs(gaps): settle current-head frontend evidence and queue authority

* docs(gaps): record hosted TLS contract RED and repair

* docs(gaps): record current-parent leftover-pair a11y repair

* docs(gaps): record current leftover-pair interaction evidence

* docs: track dense mobile leftover-pair repair

* docs(gaps): archive prior overlay and refresh live authority

* docs(gaps): record hosted Storybook and release inventory gaps

* docs(gaps): record registry README owner-boundary convergence

* docs(gaps): record OIDC smoke dependency repair

* docs(gaps): refresh OIDC smoke operator contract evidence

* docs(gaps): serialize OIDC smoke before registry README

* docs(gaps): compact current owner chain after OIDC stack convergence

* docs(gaps): record #974 exact-head GREEN tests

* docs(gaps): record #974 security GREEN

* docs(gaps): record hosted leftover selector RED

* docs(gaps): separate OIDC smoke from browser auth acceptance

* docs(gaps): record ROPC topology removal owner

* docs(gaps): record #977 selector repair admission

* docs(gaps): correct live translation owner heads

* docs(a11y): align leftover-pair ADR with visible labels

* docs(gaps): record code-current leftover accessibility ADR

* docs(gaps): record executable ROPC security RED

* docs(gaps): require PKCE S256 in public-client auth gap

* docs(gaps): track queued OIDC causal repair

* docs(gaps): make ROPC actor migration precede client shutdown

* docs(gaps): record partial OIDC machine-actor migration

* docs(gaps): converge README onto auth migration

* docs(gaps): refresh auth stack exact-head evidence

* docs(gaps): record OIDC ADR convergence

* docs(gaps): record shared JWKS verifier repair

* docs(gaps): record deterministic machine identity repair

* docs(gaps): record terminal translation validation reds

* docs: record completed #977 selector repair

* docs: record terminal #974 CodeQL settlement RED

* docs(gaps): record report-axis contract repair and convergence

* docs(gaps): correct exact Customer Master authority

* docs(gaps): record duplicate-kid auth hardening

* docs(gaps): record current auth verifier evidence

* docs(gaps): record RFC 7518 JWKS key floor

* docs(gaps): record canonical JWK Base64urlUInt repair

* docs(gaps): refresh RSA exponent auth evidence

* docs(gaps): record minimal JWK integer hardening

* docs(gaps): refresh live auth and delivery authority

* docs(gaps): record local PU-scope authorization repair

* docs(gaps): add mixed-scope fail-closed repair

* docs(gaps): record RSA exponent bound and auth heads

* docs(gaps): record odd-modulus auth boundary

* docs(gaps): record RFC 7517 key-operations repair

* docs(gaps): record null-valued JWK metadata repair

* docs(gaps): record canonical Base64url pad-bit repair

* docs(gaps): record comparison tick root repair and converged stack

* docs(gaps): record #861 App acceptance root and telemetry owner

* docs(gaps): record #861 axis-label clipping acceptance

* docs(gaps): record report contract RCA and current owner head

* docs(gaps): record public-only JWKS boundary

* docs(gaps): record JWK x5c consistency repair

* docs(gaps): record full x5c chain validation

* docs(gaps): record x5c key-usage repair and descendant convergence

* docs(gaps): record JWK certificate thumbprint invariant

* docs(gaps): attach thumbprint exact-head receipts

* docs(gaps): record realm-owned service subject boundary

* docs(gaps): record disjoint machine and user principals

* docs(gaps): record service-client boundary repair

* docs(gaps): record usable machine-auth prerequisite

* docs(gaps): refresh auth audiences and report receipt

* docs(gaps): record x5u verifier boundary and auth heads

* docs(gaps): record implicit-flow auth boundary

* docs(gaps): record exact OIDC redirect boundary

* docs(gaps): record executable seed auth RED

* docs(gaps): refresh auth repair runner authority

* docs(gaps): remove stale auth repair lane authority

* docs(gaps): record seed auth repair and remaining ROPC

* docs(gaps): record backend ROPC executable RED

* docs(gaps): record exact report-stack failures

* docs(gaps): record auth helper endpoint repair

* docs(gaps): record PyJWT floor and auth convergence

* docs(gaps): add PyJWT advisory traceability authority

* docs(gaps): refresh Voice runtime authority

Record the live PR and issue inventory, keep exact-head workflow states non-accepting, and mark Voice-of-X runtime acceptance unverified.

Signed-off-by: Seongho Bae <me@seonghobae.me>

* docs(gaps): keep baseline head claim immutable

Label the observed PR head as the parent of this update so a new commit cannot make its own evidence statement stale.

Signed-off-by: Seongho Bae <me@seonghobae.me>

* docs(gap): record exact report RED and Voice authority repair

* fix(a11y): align leftover pair accessible names

* fix(ui): wrap leftover evidence on narrow screens

* docs(gaps): refresh exact-head ecosystem authority

Signed-off-by: Seongho Bae <me@seonghobae.me>

* docs(gaps): converge report stack after merged intermediate

* docs(gaps): correct current OIDC smoke authority

* test(ui): align leftover pair accessible names

* docs(gaps): track auth helper repair and convergence

* docs(gaps): refresh auth helper boundary

* docs(gaps): record remote OAuth TLS repair

* docs(gaps): repair acceptance wording and catalog auth owner

* codex: refresh exact-head gap evidence (#1041)

* docs(gaps): keep #1041 authority self-reference safe

* docs(gaps): record comparison axis repair candidate

Separate current local rendering and regression evidence from protected delivery, authenticated acceptance, and the remaining stacked-parent gate.

Signed-off-by: Seongho Bae <me@seonghobae.me>

* docs(gaps): record coordinate tick repair

Record the exact #860 candidate, local verification, queued hosted checks, stack ordering, and remaining authenticated acceptance boundary.

Signed-off-by: Seongho Bae <seonghobae@users.noreply.github.com>

* docs(gaps): refresh auth exact-head evidence

* docs(gaps): refresh exact-head authority

Signed-off-by: Seongho Bae <me@seonghobae.me>

* docs(gaps): adopt source-repaired report and auth heads

* fix(reports): omit unavailable leftover distance

Signed-off-by: Seongho Bae <me@seonghobae.me>

* test(reports): reject non-finite residual accessibility evidence

* fix(reports): omit non-finite residual from accessible evidence

* test(a11y): reject duplicate leftover evidence announcements

* fix(a11y): announce leftover evidence once

* test(a11y): preserve leftover action guidance while deduplicating evidence

* fix(a11y): deduplicate leftover evidence without dropping guidance

* test(a11y): cover all leftover action evidence branches

* test(a11y): type leftover evidence branch cases explicitly

---------

Signed-off-by: Seongho Bae <me@seonghobae.me>
Signed-off-by: Seongho Bae <seonghobae@users.noreply.github.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>

Copy link
Copy Markdown
Contributor Author

Fresh independent Python CodeQL canary from #899 confirms this remains the canonical owner lane for the two repository-baseline findings.

Producer .github run 35652904176, Python job 106584641313, target LineageWeave#899@c943060c7c16f74faf48d1ee40eaa5301c830065 executed CodeQL analysis successfully and then failed the Medium+ SARIF gate. The retained live artifact is id 10677342334, codeql-dispatch-python-35652904176-1, digest sha256:f9312c6a435fabb4cf3504319f77c435535e6acf7fc1c65c192f0c1dc476c3c6. Its SARIF contains exactly:

  • py/insecure-protocol at lineageweave/http_client.py:193;
  • py/polynomial-redos at lineageweave/post_chat.py:48.

Both paths/locations exist on #899 exact head. This corrects an earlier artifact-attribution mistake that had suggested a non-tree Python path; canonical .github#2340 has been closed invalid after downloading and parsing the actual artifact.

Current #974 exact 4341080f6027d869acb08896e41d761c3f3b8e77 already carries the causal source shapes for both findings: _build_ssl_context() sets a certifi-backed context to TLSv1.2 before it escapes, and question normalization uses linear split/join + rstrip("?.!") rather than the flagged regex. This canary is owner/baseline evidence only; it is not #974 current-head CodeQL GREEN. Promotion still requires an authenticated producer/consumer settlement on this repaired exact head (or a verified successor carrying both fixes), plus qualifying review and normal protected integration.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working priority: high

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant