fix(chat): preserve null timeouts and attribute worker expiry - #974
seonghobae wants to merge 8 commits into
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (1)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughGlobal Ask는 자체 타이머가 만료된 경우에만 데드라인 실패로 처리합니다. post-chat은 Changes타임아웃 귀속 및 전달
전송 및 입력 정규화 계약
Priority: ⬇️ Low Estimated code review effort: 3 (Moderate) | ~25 minutes Change: Bug fix Sequence Diagram(s)sequenceDiagram
participant GlobalAskWorker
participant compute_global_ask_answer
participant Settlement
GlobalAskWorker->>compute_global_ask_answer: 작업 계산 실행
compute_global_ask_answer-->>GlobalAskWorker: 결과 또는 TimeoutError
GlobalAskWorker->>GlobalAskWorker: answer_timeout.expired() 확인
GlobalAskWorker->>Settlement: 데드라인 또는 일반 실패 정산
sequenceDiagram
participant _post_chat_client
participant ContextualOrchestratorPostChatClient
participant post_json
participant HTTPConnection
_post_chat_client->>ContextualOrchestratorPostChatClient: timeout 전달
ContextualOrchestratorPostChatClient->>post_json: 선택적 timeout 전달
post_json->>HTTPConnection: timeout 또는 None 전달
Merge Risk: ⚪ Minimal · up to The changes preserve timeout behavior, enforce TLS 1.2, and retain question normalization semantics. Current-head validation remains pending, but no actionable code risk is established. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Pull request overview
OpenCode reviewed the current-head product diff. Coverage is a separate gate.
Changed files
AGENTS.md— repository behaviorbackend/app/global_ask_queue.py— API and service runtimebackend/app/main.py— API and service runtimedocs/adr/0083-orchestrator-runtime-commit-pin.md— operator or user guidancedocs/product-technical-gap-baseline.md— operator or user guidancelineageweave/http_client.py— Python module behaviorlineageweave/post_chat.py— Python module behaviortests/test_global_ask_queue.py— regression suitetests/test_http_client.py— regression suitetests/test_post_chat.py— regression suite
Changed behavior
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Repository file: AGENTS.md"]
S1 --> I1["repository behavior"]
I1 --> R1["Review risk: Repository file: AGENTS.md"]
R1 --> V1["required checks"]
Evidence --> S2["Backend: global_ask_queue.py (2 files)"]
S2 --> I2["API and service runtime"]
I2 --> R2["Review risk: Backend: global_ask_queue.py (2 files)"]
R2 --> V2["backend tests"]
Evidence --> S3["Docs: 0083-orchestrator-runtime-commit-pin.md (2 files)"]
S3 --> I3["operator or user guidance"]
I3 --> R3["Review risk: Docs: 0083-orchestrator-runtime-commit-pin.md (2 files)"]
R3 --> V3["docs review"]
Evidence --> S4["Python: http_client.py (2 files)"]
S4 --> I4["Python module behavior"]
I4 --> R4["Review risk: Python: http_client.py (2 files)"]
R4 --> V4["pytest plus coverage"]
Evidence --> S5["Test: test_global_ask_queue.py (3 files)"]
S5 --> I5["regression suite"]
I5 --> R5["Review risk: Test: test_global_ask_queue.py (3 files)"]
R5 --> V5["targeted test run"]
Findings
No source-backed product finding is synthesized from the coverage gate. A coverage miss belongs in the status comment.
- Head SHA:
def15fc691d4442c0d82103c1642147b1528d7be - Workflow run: 34111705214
- Workflow attempt: 1
- Coverage gate:
failure
Review outcome
Coverage is a gate, not the review. This body reviews the changed product files.
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Repository file: AGENTS.md"]
S1 --> I1["repository behavior"]
I1 --> R1["Review risk: Repository file: AGENTS.md"]
R1 --> V1["required checks"]
Evidence --> S2["Backend: global_ask_queue.py (2 files)"]
S2 --> I2["API and service runtime"]
I2 --> R2["Review risk: Backend: global_ask_queue.py (2 files)"]
R2 --> V2["backend tests"]
Evidence --> S3["Docs: 0083-orchestrator-runtime-commit-pin.md (2 files)"]
S3 --> I3["operator or user guidance"]
I3 --> R3["Review risk: Docs: 0083-orchestrator-runtime-commit-pin.md (2 files)"]
R3 --> V3["docs review"]
Evidence --> S4["Python: http_client.py (2 files)"]
S4 --> I4["Python module behavior"]
I4 --> R4["Review risk: Python: http_client.py (2 files)"]
R4 --> V4["pytest plus coverage"]
Evidence --> S5["Test: test_global_ask_queue.py (3 files)"]
S5 --> I5["regression suite"]
I5 --> R5["Review risk: Test: test_global_ask_queue.py (3 files)"]
R5 --> V5["targeted test run"]
OpenCode Review Overview
Coverage evidence did not pass, so approval is blocked. The formal pull-request review is the source-backed diff review, not this status comment. |
Pull request was converted to draft
There was a problem hiding this comment.
Noema LLM review
The PR correctly preserves null transport timeouts through the post-chat factory and shared HTTP transport, and attributes the worker deadline only when the asyncio timeout context actually expired. The added answer_timeout.expired() guard prevents provider TimeoutErrors from being misreported as the worker's own deadline expiry. Tests cover direct and factory construction with omitted/null/numeric timeouts, provider versus worker versus shutdown timeout sources, and null as well as numeric HTTP transport timeouts. No blocking issues found.
Reviewed changed lines
backend/app/global_ask_queue.py:589 (RIGHT): The addedanswer_timeout is not None and answer_timeout.expired()check ensures only an actualasyncio.timeoutcontext expiry is attributed to the worker deadline. Provider-raisedasyncio.TimeoutErrorinstances without an expired local timer now fall through to the bounded unavailable message, preventing misdiagnosis of the durable job outcome.backend/app/main.py:520 (RIGHT): The factory now passestimeout=timeoutdirectly to the client, eliminating the conditional that dropped aNonevalue and restored the previous 180-second default. Omitted and explicit-null timeouts both propagate as null, while explicit numeric limits are preserved unchanged.lineageweave/http_client.py:152 (RIGHT): The_requestsignature acceptsfloat | Nonewith no new adapter, allowing a null timeout to flow through the shared HTTP transport. Explicit numeric timeouts remain supported, and the TLSv1.2 minimum version is set on the shared SSL context.
Adversarial validation
backend/app/global_ask_queue.py:589 (RIGHT)falsified: A TimeoutError raised by the upstream provider is misattributed as expiry of the worker's execution deadline. —test_timeout_detail_identifies_only_an_expired_worker_deadlineparametrizestimeout_sourceas 'provider', 'worker', and 'shutdown'. The provider case asserts the durable detail is 'Ask Agent is unavailable: contextual-orchestrator returned no complete evidence object'; the worker case asserts 'job exceeded the 0s deadline'.backend/app/main.py:520 (RIGHT)falsified: The factory silently drops an explicit null timeout or imposes a default 180-second limit, contradicting the requested default-null behavior. —test_post_chat_preserves_optional_transport_timeoutparametrizestimeout_optionsas{},{'timeout': None}, and{'timeout': 7.5}for both direct and factory creation. Each configuration asserts the observed transport timeout is exactlyNone(for omitted/null) or7.5.lineageweave/http_client.py:152 (RIGHT)falsified: The shared HTTP transport rejects or coerces a null timeout, breaking null propagation from the client. —test_post_json_posts_json_to_http_endpointintests/test_http_client.pyis parametrized withrequest_timeout=Noneand2.0; both paths successfully POST to a local HTTP server and assert the server receives the payload without timeout-related errors.- Residual risk: Null transport timeouts do not prove blocking-socket cancellation; the explicit 570-second Ask worker socket setting, 600-second execution deadline, and age-based orphan recovery remain unresolved. Optional-model timeout behavior for other clients and upstream model administration still require owner-aligned verification.
Findings
- No blocking findings.
- Result: APPROVE
- Head SHA:
6911954363888d1e2d523ebbcf68f68d7217752a - Reviewer credential:
noema-review-github-app-refresh - Actor:
cwl-noema-review[bot]
There was a problem hiding this comment.
Pull request overview
OpenCode reviewed the current-head product diff. Coverage is a separate gate.
Changed files
AGENTS.md— repository behaviorbackend/app/global_ask_queue.py— API and service runtimebackend/app/main.py— API and service runtimedocs/adr/0083-orchestrator-runtime-commit-pin.md— operator or user guidancedocs/product-technical-gap-baseline.md— operator or user guidancelineageweave/http_client.py— Python module behaviorlineageweave/post_chat.py— Python module behaviortests/test_global_ask_queue.py— regression suitetests/test_http_client.py— regression suitetests/test_http_client_tls_floor_contract.py— regression suitetests/test_post_chat.py— regression suite
Changed behavior
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Repository file: AGENTS.md"]
S1 --> I1["repository behavior"]
I1 --> R1["Review risk: Repository file: AGENTS.md"]
R1 --> V1["required checks"]
Evidence --> S2["Backend: global_ask_queue.py (2 files)"]
S2 --> I2["API and service runtime"]
I2 --> R2["Review risk: Backend: global_ask_queue.py (2 files)"]
R2 --> V2["backend tests"]
Evidence --> S3["Docs: 0083-orchestrator-runtime-commit-pin.md (2 files)"]
S3 --> I3["operator or user guidance"]
I3 --> R3["Review risk: Docs: 0083-orchestrator-runtime-commit-pin.md (2 files)"]
R3 --> V3["docs review"]
Evidence --> S4["Python: http_client.py (2 files)"]
S4 --> I4["Python module behavior"]
I4 --> R4["Review risk: Python: http_client.py (2 files)"]
R4 --> V4["pytest plus coverage"]
Evidence --> S5["Test: test_global_ask_queue.py (4 files)"]
S5 --> I5["regression suite"]
I5 --> R5["Review risk: Test: test_global_ask_queue.py (4 files)"]
R5 --> V5["targeted test run"]
Findings
No source-backed product finding is synthesized from the coverage gate. A coverage miss belongs in the status comment.
- Head SHA:
6911954363888d1e2d523ebbcf68f68d7217752a - Workflow run: 35089654032
- Workflow attempt: 1
- Coverage gate:
failure
Review outcome
Coverage is a gate, not the review. This body reviews the changed product files.
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Repository file: AGENTS.md"]
S1 --> I1["repository behavior"]
I1 --> R1["Review risk: Repository file: AGENTS.md"]
R1 --> V1["required checks"]
Evidence --> S2["Backend: global_ask_queue.py (2 files)"]
S2 --> I2["API and service runtime"]
I2 --> R2["Review risk: Backend: global_ask_queue.py (2 files)"]
R2 --> V2["backend tests"]
Evidence --> S3["Docs: 0083-orchestrator-runtime-commit-pin.md (2 files)"]
S3 --> I3["operator or user guidance"]
I3 --> R3["Review risk: Docs: 0083-orchestrator-runtime-commit-pin.md (2 files)"]
R3 --> V3["docs review"]
Evidence --> S4["Python: http_client.py (2 files)"]
S4 --> I4["Python module behavior"]
I4 --> R4["Review risk: Python: http_client.py (2 files)"]
R4 --> V4["pytest plus coverage"]
Evidence --> S5["Test: test_global_ask_queue.py (4 files)"]
S5 --> I5["regression suite"]
I5 --> R5["Review risk: Test: test_global_ask_queue.py (4 files)"]
R5 --> V5["targeted test run"]
|
Fresh independent CodeQL evidence from the exact #1115 producer changes the baseline classification but does not transfer GREEN here. Canonical Those paths are this owner lane, not #1115's image-ingestion delta. Current #974 head |
There was a problem hiding this comment.
Pull request overview
OpenCode reviewed the current-head product diff. Coverage is a separate gate.
Changed files
AGENTS.md— repository behaviorbackend/app/global_ask_queue.py— API and service runtimebackend/app/main.py— API and service runtimedocs/adr/0083-orchestrator-runtime-commit-pin.md— operator or user guidancedocs/product-technical-gap-baseline.md— operator or user guidancelineageweave/http_client.py— Python module behaviorlineageweave/post_chat.py— Python module behaviortests/test_global_ask_queue.py— regression suitetests/test_http_client.py— regression suitetests/test_http_client_tls_floor_contract.py— regression suitetests/test_post_chat.py— regression suite
Changed behavior
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Repository file: AGENTS.md"]
S1 --> I1["repository behavior"]
I1 --> R1["Review risk: Repository file: AGENTS.md"]
R1 --> V1["required checks"]
Evidence --> S2["Backend: global_ask_queue.py (2 files)"]
S2 --> I2["API and service runtime"]
I2 --> R2["Review risk: Backend: global_ask_queue.py (2 files)"]
R2 --> V2["backend tests"]
Evidence --> S3["Docs: 0083-orchestrator-runtime-commit-pin.md (2 files)"]
S3 --> I3["operator or user guidance"]
I3 --> R3["Review risk: Docs: 0083-orchestrator-runtime-commit-pin.md (2 files)"]
R3 --> V3["docs review"]
Evidence --> S4["Python: http_client.py (2 files)"]
S4 --> I4["Python module behavior"]
I4 --> R4["Review risk: Python: http_client.py (2 files)"]
R4 --> V4["pytest plus coverage"]
Evidence --> S5["Test: test_global_ask_queue.py (4 files)"]
S5 --> I5["regression suite"]
I5 --> R5["Review risk: Test: test_global_ask_queue.py (4 files)"]
R5 --> V5["targeted test run"]
Findings
No source-backed product finding is synthesized from the coverage gate. A coverage miss belongs in the status comment.
- Head SHA:
4341080f6027d869acb08896e41d761c3f3b8e77 - Workflow run: 35310296619
- Workflow attempt: 1
- Coverage gate:
failure
Review outcome
Coverage is a gate, not the review. This body reviews the changed product files.
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Repository file: AGENTS.md"]
S1 --> I1["repository behavior"]
I1 --> R1["Review risk: Repository file: AGENTS.md"]
R1 --> V1["required checks"]
Evidence --> S2["Backend: global_ask_queue.py (2 files)"]
S2 --> I2["API and service runtime"]
I2 --> R2["Review risk: Backend: global_ask_queue.py (2 files)"]
R2 --> V2["backend tests"]
Evidence --> S3["Docs: 0083-orchestrator-runtime-commit-pin.md (2 files)"]
S3 --> I3["operator or user guidance"]
I3 --> R3["Review risk: Docs: 0083-orchestrator-runtime-commit-pin.md (2 files)"]
R3 --> V3["docs review"]
Evidence --> S4["Python: http_client.py (2 files)"]
S4 --> I4["Python module behavior"]
I4 --> R4["Review risk: Python: http_client.py (2 files)"]
R4 --> V4["pytest plus coverage"]
Evidence --> S5["Test: test_global_ask_queue.py (4 files)"]
S5 --> I5["regression suite"]
I5 --> R5["Review risk: Test: test_global_ask_queue.py (4 files)"]
R5 --> V5["targeted test run"]
* docs(gaps): refresh exact-head product evidence Record protected-main authority, live aggregate inventory, the active Customer Master cycle repair, and remaining acceptance boundaries. Commit-Message-Assisted-by: Claude (via Claude Code) Signed-off-by: Seongho Bae <me@seonghobae.me> * docs(gaps): bind Customer Master evidence to current head Record the current implementation SHA and the desktop/mobile Storybook audit while leaving authenticated PostgreSQL acceptance unresolved. Commit-Message-Assisted-by: Claude (via Claude Code) Signed-off-by: Seongho Bae <me@seonghobae.me> * docs(gaps): refresh current repair ownership evidence * docs(gaps): refresh ready-state evidence * docs(gaps): retract stale Ready evidence * docs(gaps): refresh exact-head queue evidence * docs(gaps): record authenticated scope repair evidence * docs(gaps): refresh protected loop evidence * docs(gaps): track replay repair head * docs(gaps): correct replay exact head * chore(docs): stage exact-head gap baseline refresh * docs(gaps): refresh live exact-head authority * chore(docs): refresh live gap overlay * chore(docs): remove purpose-complete refresh workflow * chore: stage bounded gap baseline refresh * fix: make bounded gap refresh workflow parseable * docs(gaps): refresh terminal Strix security evidence * chore: stage current gap baseline refresh * docs(gaps): record fresh security repair lanes * chore: stage final current gap baseline refresh * docs(gaps): refresh current security evidence * ci(docs): stage bounded baseline refresh * docs(gaps): refresh live exact-head overlay * chore(gaps): stage current authority overlay * chore(gaps): apply current authority overlay * docs(gaps): refresh customer-master exact-head authority * chore(gaps): stage 10:14 exact-head overlay * chore(gaps): run 10:14 exact-head overlay * docs(gaps): refresh exact-head customer-master evidence * chore(docs): stage bounded gap baseline refresh * docs(gaps): refresh exact-head security evidence * chore(docs): stage bounded gap baseline refresh * docs(gaps): refresh exact-head product evidence * chore(docs): stage live-authority baseline refresh * fix(docs): repair bounded live baseline workflow * docs(gaps): refresh live product authority * chore(gaps): stage bounded authority refresh * chore(gaps): remove failed bounded refresh helper * chore(docs): stage bounded baseline refresh * docs(gaps): converge release owner authority * docs(gaps): refresh current product authority * chore(docs): stage bounded gap baseline refresh * fix(docs): repair bounded gap baseline refresh runner * fix(docs): keep refresh payload inside workflow block * docs(gaps): refresh current Customer Master evidence * chore(docs): stage 20:05 gap baseline refresh * chore(docs): remove queued baseline helper * chore(docs): refresh 20:27 live gap baseline * docs(gaps): refresh 20:27 live authority * docs(gaps): make current baseline projection explicit * docs(gaps): refresh exact-head acceptance evidence * docs(gaps): record review-sidecar prerequisite RED * docs(gaps): record prerequisite exact-head GREEN * docs(gaps): refresh current gate evidence * docs(gaps): record exact-head security green * docs(gaps): refresh live review execution evidence * docs(gaps): record exact-head full-diff review evidence * docs(gaps): refresh central prerequisite evidence * docs(gaps): record exact-head review prerequisite approval * docs(gaps): correct current required-gate inventory * docs(gaps): record terminal review runtime evidence * docs(gaps): record current-main ADR occupancy reconstruction * docs(gaps): refresh central review gate settlement * docs(gaps): record canonical CodeQL dispatch progress * docs(gaps): record reconstructed comparison post repair * docs(gaps): record criterion coordinate stack convergence * docs(gaps): record current leftover-map stack convergence * docs(gaps): record non-force leftover-map convergence * docs(gaps): record comparison-axis repair and stack convergence * docs(gaps): record graphic badge repair and descendant convergence * docs(product): refresh live gap authority after owner and stack repairs * docs(product): refresh owner ADR authority after review repair * docs(gaps): record owner-boundary descendant convergence * docs(gaps): include bounded-operator descendant convergence * docs(gaps): record PostgreSQL timeout compatibility repair * docs(gaps): record exact-head PostgreSQL validation admission * docs(gaps): keep PostgreSQL validation admission current * docs(gaps): record report-axis missingness repair and current stack * docs(gaps): record live report-axis RED and descendant convergence * docs(gaps): repair live leftover-map ancestry authority * docs(gaps): refresh exact-head validation evidence * docs(gaps): refresh leftover-map convergence and repair RCA * docs(gaps): record comparison tick i18n RED * docs(gaps): refresh measurement descendant authority * docs(gaps): record fail-closed dependency review and queue differential * docs(gaps): record CodeQL owner repairs and parser finding * docs(gaps): admit exact-head validation for CodeQL repairs * docs(gaps): record post-body CodeQL repair and convergence * docs(gaps): record attributed script-tag parser repair * docs(gaps): record unresolved embedded-image parser gap * docs(gaps): refresh parser and leftover-map evidence * docs(gaps): refresh current product and validation authority * docs(gaps): record backend embedded-image parser repair * docs(gaps): advance embedded-image repair authority * docs(gaps): record current #1115 provenance repair * docs(gap): align owner-boundary lifecycle and stack heads * docs(gap): record hosted leftover-map and warning owner evidence * docs(gaps): record #983 hosted coverage evidence * docs(gaps): record repaired tick foundation and converged stack * docs(gaps): record comparison tick repair and convergence * docs(gaps): refresh live report-stack authority * docs(gaps): record repaired tick-share stack * docs(gaps): record terminal CodeQL verdict failure * docs(gaps): record current #983 coverage evidence * docs(gaps): record hosted parser RED and repair * docs(gaps): record scanner edge coverage convergence * docs(gaps): record ontology extension coverage ancestry * docs(gaps): correct report-axis exact head * docs(gaps): record image-ingestion security green * docs(gaps): record catalog coverage convergence * docs(gaps): converge report stack and current receipts * docs(gaps): record current-head cancellation class * docs(gaps): record comparison post accessibility evidence * docs(gaps): record current CodeQL producer state * docs(gaps): record #873 test coverage and descendant convergence * docs(gaps): refresh #873 exact queue evidence * docs(gaps): refresh #1115 CodeQL producer progress * docs(gaps): track Customer Master eight-locale review draft * docs(gaps): follow translation draft test repair * docs(gaps): admit translation candidate validation * docs(gaps): record Customer Master seed ownership repair * docs(gaps): scope Customer Master seed ownership lifecycle * docs(gaps): record translation ownership search-path repair * docs(gaps): track ledger search-path integrity repair * docs(gaps): track seed ownership replay concurrency * docs(gaps): refresh canonical scheduler authority * docs(gaps): record concurrent Customer Master seed replay repair * docs(gaps): refresh canonical GitHub owner authority * docs(gaps): track reviewed translation replay preservation * docs(gaps): refresh canonical owner head * docs(gaps): record completed-seed retirement lifecycle * docs(gaps): record non-destructive ownership upgrade * docs(gaps): track versioned ownership constraint repair * docs(gaps): follow canonical CodeQL owner movement * docs(gaps): classify terminal CodeQL owner findings * docs(gaps): refresh canonical queue owner * docs(gaps): classify executed image CodeQL producer * docs(gaps): settle current-head frontend evidence and queue authority * docs(gaps): record hosted TLS contract RED and repair * docs(gaps): record current-parent leftover-pair a11y repair * docs(gaps): record current leftover-pair interaction evidence * docs: track dense mobile leftover-pair repair * docs(gaps): archive prior overlay and refresh live authority * docs(gaps): record hosted Storybook and release inventory gaps * docs(gaps): record registry README owner-boundary convergence * docs(gaps): record OIDC smoke dependency repair * docs(gaps): refresh OIDC smoke operator contract evidence * docs(gaps): serialize OIDC smoke before registry README * docs(gaps): compact current owner chain after OIDC stack convergence * docs(gaps): record #974 exact-head GREEN tests * docs(gaps): record #974 security GREEN * docs(gaps): record hosted leftover selector RED * docs(gaps): separate OIDC smoke from browser auth acceptance * docs(gaps): record ROPC topology removal owner * docs(gaps): record #977 selector repair admission * docs(gaps): correct live translation owner heads * docs(a11y): align leftover-pair ADR with visible labels * docs(gaps): record code-current leftover accessibility ADR * docs(gaps): record executable ROPC security RED * docs(gaps): require PKCE S256 in public-client auth gap * docs(gaps): track queued OIDC causal repair * docs(gaps): make ROPC actor migration precede client shutdown * docs(gaps): record partial OIDC machine-actor migration * docs(gaps): converge README onto auth migration * docs(gaps): refresh auth stack exact-head evidence * docs(gaps): record OIDC ADR convergence * docs(gaps): record shared JWKS verifier repair * docs(gaps): record deterministic machine identity repair * docs(gaps): record terminal translation validation reds * docs: record completed #977 selector repair * docs: record terminal #974 CodeQL settlement RED * docs(gaps): record report-axis contract repair and convergence * docs(gaps): correct exact Customer Master authority * docs(gaps): record duplicate-kid auth hardening * docs(gaps): record current auth verifier evidence * docs(gaps): record RFC 7518 JWKS key floor * docs(gaps): record canonical JWK Base64urlUInt repair * docs(gaps): refresh RSA exponent auth evidence * docs(gaps): record minimal JWK integer hardening * docs(gaps): refresh live auth and delivery authority * docs(gaps): record local PU-scope authorization repair * docs(gaps): add mixed-scope fail-closed repair * docs(gaps): record RSA exponent bound and auth heads * docs(gaps): record odd-modulus auth boundary * docs(gaps): record RFC 7517 key-operations repair * docs(gaps): record null-valued JWK metadata repair * docs(gaps): record canonical Base64url pad-bit repair * docs(gaps): record comparison tick root repair and converged stack * docs(gaps): record #861 App acceptance root and telemetry owner * docs(gaps): record #861 axis-label clipping acceptance * docs(gaps): record report contract RCA and current owner head * docs(gaps): record public-only JWKS boundary * docs(gaps): record JWK x5c consistency repair * docs(gaps): record full x5c chain validation * docs(gaps): record x5c key-usage repair and descendant convergence * docs(gaps): record JWK certificate thumbprint invariant * docs(gaps): attach thumbprint exact-head receipts * docs(gaps): record realm-owned service subject boundary * docs(gaps): record disjoint machine and user principals * docs(gaps): record service-client boundary repair * docs(gaps): record usable machine-auth prerequisite * docs(gaps): refresh auth audiences and report receipt * docs(gaps): record x5u verifier boundary and auth heads * docs(gaps): record implicit-flow auth boundary * docs(gaps): record exact OIDC redirect boundary * docs(gaps): record executable seed auth RED * docs(gaps): refresh auth repair runner authority * docs(gaps): remove stale auth repair lane authority * docs(gaps): record seed auth repair and remaining ROPC * docs(gaps): record backend ROPC executable RED * docs(gaps): record exact report-stack failures * docs(gaps): record auth helper endpoint repair * docs(gaps): record PyJWT floor and auth convergence * docs(gaps): add PyJWT advisory traceability authority * docs(gaps): refresh Voice runtime authority Record the live PR and issue inventory, keep exact-head workflow states non-accepting, and mark Voice-of-X runtime acceptance unverified. Signed-off-by: Seongho Bae <me@seonghobae.me> * docs(gaps): keep baseline head claim immutable Label the observed PR head as the parent of this update so a new commit cannot make its own evidence statement stale. Signed-off-by: Seongho Bae <me@seonghobae.me> * docs(gap): record exact report RED and Voice authority repair * fix(a11y): align leftover pair accessible names * fix(ui): wrap leftover evidence on narrow screens * docs(gaps): refresh exact-head ecosystem authority Signed-off-by: Seongho Bae <me@seonghobae.me> * docs(gaps): converge report stack after merged intermediate * docs(gaps): correct current OIDC smoke authority * test(ui): align leftover pair accessible names * docs(gaps): track auth helper repair and convergence * docs(gaps): refresh auth helper boundary * docs(gaps): record remote OAuth TLS repair * docs(gaps): repair acceptance wording and catalog auth owner * codex: refresh exact-head gap evidence (#1041) * docs(gaps): keep #1041 authority self-reference safe * docs(gaps): record comparison axis repair candidate Separate current local rendering and regression evidence from protected delivery, authenticated acceptance, and the remaining stacked-parent gate. Signed-off-by: Seongho Bae <me@seonghobae.me> * docs(gaps): record coordinate tick repair Record the exact #860 candidate, local verification, queued hosted checks, stack ordering, and remaining authenticated acceptance boundary. Signed-off-by: Seongho Bae <seonghobae@users.noreply.github.com> * docs(gaps): refresh auth exact-head evidence * docs(gaps): refresh exact-head authority Signed-off-by: Seongho Bae <me@seonghobae.me> * docs(gaps): adopt source-repaired report and auth heads * fix(reports): omit unavailable leftover distance Signed-off-by: Seongho Bae <me@seonghobae.me> * test(reports): reject non-finite residual accessibility evidence * fix(reports): omit non-finite residual from accessible evidence * test(a11y): reject duplicate leftover evidence announcements * fix(a11y): announce leftover evidence once * test(a11y): preserve leftover action guidance while deduplicating evidence * fix(a11y): deduplicate leftover evidence without dropping guidance * test(a11y): cover all leftover action evidence branches * test(a11y): type leftover evidence branch cases explicitly --------- Signed-off-by: Seongho Bae <me@seonghobae.me> Signed-off-by: Seongho Bae <seonghobae@users.noreply.github.com> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
|
Fresh independent Python CodeQL canary from #899 confirms this remains the canonical owner lane for the two repository-baseline findings. Producer
Both paths/locations exist on #899 exact head. This corrects an earlier artifact-attribution mistake that had suggested a non-tree Python path; canonical Current #974 exact |
Current authority — 2026-09-19
main@83eba56149eb802cd63642c507c324c9976ec78e4341080f6027d869acb08896e41d761c3f3b8e772dfd21110813f474d3068796d0733d96f28d6061This lane owns the repository-baseline Python CodeQL repairs outside unrelated product PRs. ReDoS RED
216e4e3c41161f49b65c48128e8c178790222e3dremains causally fixed by linear whitespace normalization plus.rstrip("?.!").The TLS finding required predecessor source repair
ff2bcba3c85853da67acf90680e7927a5c9c83e7:_build_ssl_context()constructs the certifi-backed context and appliesminimum_version = ssl.TLSVersion.TLSv1_2before the context escapes, preserving hostname and certificate verification while presenting CodeQL with the secure local dataflow shape. No query, SARIF severity, provider/model/routing behavior, certificate verification, or TLS floor was weakened.Hosted RED and causal test repair
Predecessor Tests
35243765633executed after queue admission. Frontend105278564382succeeded across lint, tests, build and Storybook. Full suite/PostgreSQL105278564710failed narrowly at 1778 passed / 147 skipped / 1 failed:tests/test_http_client_tls_floor_contract.py::test_http_client_declares_tls_1_2_floor_in_owned_transport_boundarystill required the obsolete source spelling_SSL_CONTEXT.minimum_version = ssl.TLSVersion.TLSv1_2even though the intentional CodeQL repair had moved the floor assignment inside_build_ssl_context().Current head
4341080f...is the minimal causal repair. The TLS contract test now patchesssl.create_default_contextwith a context starting atMINIMUM_SUPPORTED, invokes_build_ssl_context(), and requires that same object to be raised exactly toTLSv1_2. The live_SSL_CONTEXTfloor assertion remains. This proves explicit owner configuration without pinning the scanner-hostile predecessor alias shape.Fresh exact-head execution
The repaired exact head has executed the repository/security suites:
35267030859: SUCCESS.105356637935: SUCCESS; dependency install and the full PostgreSQL suite executed on hosted runner1002018321.105356638142: SUCCESS; lint, test, build and Storybook all executed on hosted runner1002018322.35267030789: SUCCESS.35267030604: SUCCESS.105356643326: SUCCESS;105432724807: SUCCESS, including exact-head checkout, scan, SARIF filtering and upload;105432724858: SUCCESS, including exact-head checkout, SARIF gate and upload;35267030868: FAILURE at the canonical dispatch-verdict settlement boundary.105428561110: SUCCESS.105486539836, python105486539838, javascript-typescript105486539845: all received hosted runners, successfully read the current-head dispatch state, then failed only atRelease runner or enforce current-head CodeQL verdict.105545993014: SUCCESS.The Python job log is exact: the verdict-read step emitted
verdict=pending, withDISPATCH_OUTCOME=success; the enforcement step then failed withCodeQL scan dispatched. The dispatch workflow will rerun this exact failed CodeQL job after publishing its terminal verdict.A fresh status read on exact4341080f...still exposes no authenticatedcodeql-dispatch/*status, only Devin Review and CodeRabbit. The expected producer verdict publication/rerun therefore did not converge.This consumer specimen has been handed to canonical
.github#1929in comment5733274869. It is the same producer/consumer settlement class observed on #929, not a new LineageWeave source finding. No consumer wake commit, blind rerun, local CodeQL fork, synthetic status, or gate weakening is admitted.The exact-head repository RED caused by the stale TLS test contract is closed and Tests/SAST/Security are GREEN. CodeQL is terminal RED, so the PR has been returned to Draft and those successful suites are not merge authority by themselves.
Independent protected-baseline CodeQL evidence remains canonical producer
.githubrun35152871013from unrelated #1115: its Python artifact containspy/insecure-protocolandpy/polynomial-redoson the older protected state. Evidence comment5718846884is baseline classification only, not acceptance of this repaired head.Protected canonical
.github/mainremains64aa08d7fa487deacd41c761c36277ca68cab6c9, protected and signature-valid. #2213 improves queue-health classification but does not manufacture product or scanner acceptance.#979 remains ordinarily/non-force converged to
2dfd21110813f474d3068796d0733d96f28d6061on this exact parent. The parent head/base did not move, so no descendant restack is required and no child receipt transfers backward.Promotion requires canonical current-head producer/consumer CodeQL settlement proving the Python findings absent, qualifying independent exact-head approval, and normal protected integration. No self-approval, gate weakening, force push, destructive rebase, synthetic status, blind rerun, deployment, or release is claimed.