Skip to content

governance: bind ConceptWeave Product workflow to protected merges #2348

Description

@seonghobae

Gap

ConceptWeave#35 owns canonical Product validation, but live protected policy still does not bind that workflow to ordinary protected merges. The accepted control remains a dedicated organization branch/workflows ruleset scoped only to ConceptWeave repository id 1353201939 and protected/default main, bound to source repository id 1353201939, .github/workflows/product.yml, refs/heads/main; no bypass actors, no repository required_status_checks fallback, and no Product injection into global ruleset 18156473.

Current owner authority — 2026-09-24 KST

Implementation PR #2350 is OPEN / Draft / mergeable on #1644. Current exact head is a1af52d7bf2fcb5dfd27790961faf62651b16510. No live Product-specific ruleset has been created or mutated.

Immutable-source review 5287728521 is repaired through 7a627f3e9c564bcf7ce2f826b57c1b6ef8d1ebae; owner run 35845521134 is terminal GREEN.

Mutation-boundary review 5289945740 has a real hosted RED at fdbe09abb9079638098de92f5a40575d0696b675 / run 35863230526. Ordinary-forward production repair a1628e75dc056098f4ea2d03ec799f2026025e84 requires a non-null reviewed Product blob before mutation, verifies exact protected Product bytes before evaluate creation/canary admission, and revalidates the exact blob before active PUT.

Owner run 35891410528 on a1628e7... is terminal FAILURE, but its focused lifecycle suite is behaviorally clean: exact checkout/tooling/manifest validation succeeded and 60 tests passed. The only failure is the owned 100% coverage gate: reconcile_conceptweave_product_ruleset.py measured 99%, with the staged legacy-manifest/malformed-coordinate paths (81->90, 103) uncovered.

Causal test-only repair a1af52d7bf2fcb5dfd27790961faf62651b16510 adds two contracts only: legacy reviewed manifest shape without product_workflow_blob_sha, and malformed string blob-coordinate rejection. Relative to a1628e7... it is 1 commit ahead / 0 behind, one test file, +19/-0, with no production delta. Fresh owner run 35918073452 / validate job 107374677579 is queued before runner assignment. Preserve this head until terminal evidence; do not manual/blind-rerun or no-op wake it.

Remaining P1s

Final protected-ref revalidation — review 5294002721

Current production flow checks protected .github/main and ConceptWeave main, performs the Product Contents network read/blob validation, then mutates. A ref can advance while the Contents read is in flight. After a1af52d... reaches exact owner GREEN, first stage a reality RED in which initial ref checks and blob validation succeed but a final protected-ref read observes drift and POST/PUT remains uncalled. Then minimally re-read both protected refs after blob validation and immediately before evaluate POST / active PUT. Keep the immutable blob guard unchanged.

Supported evaluate canary — reviews 5288830215 + 5291871021

This is a later separate head. GitHub ruleset workflows use supported PR activities; Foundation #1 already targets main, so its substantive ordinary/non-force reconciliation after #35 lands must supply pull_request:synchronize. Mandatory base_ref_changed evidence must be removed. Foundation intentionally remains OPEN / Draft; canary verification must accept that state without Ready/Draft manipulation while still binding exact PR/head/current protected base, reviewed Product blob, first-attempt Product success, exact evaluate-mode workflows PASS and no later source movement. Retarget/reopen/no-op/manual-rerun/predecessor evidence remains invalid.

Producer prerequisite

ConceptWeave#35 exact d7b7e30b278ec2f27096b4d313c7d5eaf5387ddc remains the one-time producer prerequisite. SAST 35825043007 and Security 35825042856 are GREEN. Required CodeQL 35825042996 is terminal FAILURE from central ordering/publication, not a ConceptWeave source finding. Downstream .github run 35870670165 has terminal-success validate-dispatch job 107213600319; python/actions scan jobs 107322443235 / 107322443261 remain queued before runner assignment. That remains .github#1929/#712-owned; do not move #35 merely to wake it.

Bootstrap ordering

  1. Converge generic solo-maintainer governance in [Governance] Make protected-PR review policy solo-maintainer compatible without weakening deterministic gates #772/ops(governance): resolve declared-versus-live central review-policy drift #1351/fix(governance): automate ruleset owner-plane reconciliation #1644 and central CodeQL/runtime owners independently.
  2. Obtain exact owner GREEN on fix(governance): stage ConceptWeave Product ruleset enforcement #2350 a1af52d....
  3. On a new head, RED -> minimally repair -> GREEN review 5294002721 final-ref revalidation.
  4. On another head, RED -> minimally repair -> GREEN reviews 5288830215 + 5291871021; land fix(governance): stage ConceptWeave Product ruleset enforcement #2350 source normally with no live Product mutation.
  5. Obtain terminal current-head central evidence for ConceptWeave#35 and land the canonical Product producer normally.
  6. Re-read protected ConceptWeave main Product Contents and adopt only that immutable blob coordinate through ordinary reviewed .github source.
  7. Create/adopt exactly one dedicated Product ruleset in evaluate; commit the returned positive ruleset ID through ordinary review.
  8. Ordinary/non-force reconcile Foundation Add Palette journal for profile repo #1 against landed protected main; use its substantive pull_request:synchronize run as first-attempt evaluate-mode canary while remaining Draft.
  9. Immediately before active PUT revalidate protected .github/main, ConceptWeave target main/canary base, exact Product blob, ruleset state/history and concurrent drift.
  10. Promote evaluate -> active, then prove missing/pending/failed Product blocks ordinary merge and terminal success satisfies the gate without administrator bypass.

Acceptance

  • dedicated organization branch/workflows rule only; unrelated repositories unaffected;
  • immutable reviewed Product blob is mandatory at every mutation boundary;
  • protected-owner/target refs and Product blob are revalidated immediately before mutation;
  • evaluate-mode evidence comes from supported substantive synchronize, not synthetic lifecycle manipulation;
  • no self-approval, synthetic status, no-op wake, manual/blind rerun, force push, destructive rebase, admin bypass, mutable source dependency or global-ruleset pollution;
  • active promotion occurs only after authentic evaluate canary evidence and exact state/history readback.

Refs #772, #1351, #1644, #2350, ContextualWisdomLab/ConceptWeave#35, ContextualWisdomLab/ConceptWeave#1, ContextualWisdomLab/ConceptWeave#4.

Activity

  1. added
    area: ci-cdCI, GitHub Actions, checks, release, or supply chain
    bugSomething isn't working
    status: blockedBlocked by conflict, dependency, or required prerequisite
    type: bugDefect or incorrect behavior
    on Sep 22, 2026
  2. seonghobae commented on Sep 23, 2026

    @seonghobae
    ContributorAuthor

    Implementation path is Draft stacked PR #2350, now exact c875b35b6ca4312756062c6ac75154d3d865e0bc on canonical owner #1644. It implements repository-only discovery → evaluate bootstrap → reviewed ruleset-ID adoption → normal ConceptWeave #35 producer landing → exact current-base Product canary → observed GitHub Actions integration binding → active promotion. Review 5285801953 repaired GitHub Contents API CR/LF-wrapped base64 canary decoding with an executed regression and strict post-normalization decode. Hosted 66992527... run 35805657970 then exposed a second pre-existing CLI-entrypoint defect at manifest validation; review 5285850467 → contract 06ae30fd... → production/current c875b35... replaces direct-script/PYTHONPATH-prone invocation with python -m scripts.ci.reconcile_conceptweave_product_ruleset. Exact current owner workflow 35806029592 is now terminal GREEN: exact checkout, hash-locked tooling, manifest validation and lifecycle contract all passed; privileged live/mutation jobs correctly skipped on the PR event. Central CodeQL/Security/SAST lanes remain independent/nonterminal. No live ruleset mutation was performed.

  3. seonghobae commented on Sep 23, 2026

    @seonghobae
    ContributorAuthor

    Owner-path update: dependent implementation #2350 is now at exact f37264ef539e555381cf0fac9a2779847dadcdc6 on top of #1644.

    Two additional P1s were closed in this pass. Review 5285966215 found a bootstrap TOCTOU: the create path checked trusted protected .github/main before repository-ruleset discovery but not immediately before the live POST. The race contract was wired in, the existing history expectation was currentized for the new guard, and production now rechecks _assert_current_main(expected_main_sha) directly at the create boundary while retaining post-create verification.

    Review 5286048812 then found a privileged source/runtime boundary issue. Exact hosted logs showed Harden Runner on ubuntu-slim says it is unsupported and will not be monitored, while verify-live exposed CWL_RULESET_ADMIN_TOKEN and lacked an explicit protected-main ref condition. Contract head e37dd17... was hosted RED in run 35808543490 (65 passed / 1 failed on the new ref/runner contract). Production/current f37264ef... moves all three jobs to ubuntu-24.04 and requires workflow_dispatch + mode=verify + refs/heads/main before the secret-bearing live verification job can run.

    Current exact owner run 35808617203 plus CodeQL 35808617183, Security 35808617233, and SAST 35808617199 are queued. No predecessor GREEN is being transferred, and no live ruleset mutation has been performed.

  4. seonghobae commented on Sep 23, 2026

    @seonghobae
    ContributorAuthor

    Implementation update: #2350 moved to test-only RED head f2130292a22908d7bd3a4b5f839e9b92fd04f3e3 after exact-head review 5286111728 found a second target-main TOCTOU in activation. _canary_integration_id() proves the canary base equals live ConceptWeave main, but activate_product_ruleset() did not re-read ConceptWeave main immediately before active PUT. Regression 08b9e0d... simulates target-main equality during canary proof followed by drift before mutation; f2130292... enrolls it in owner run 35809531211. Production remains intentionally unchanged pending hosted RED; no live ruleset mutation or predecessor evidence transfer is claimed.

  5. seonghobae commented on Sep 23, 2026

    @seonghobae
    ContributorAuthor

    2026-09-23 owner-path update: implementation PR #2350 is exact f2130292a22908d7bd3a4b5f839e9b92fd04f3e3. Review 5286111728 isolates activation target-main TOCTOU and regression 08b9e0d... + workflow enrollment f2130292... intentionally leave production unchanged until the hosted RED executes. Current owner run 35809531211 is still queued on ubuntu-24.04 before runner allocation (runner id 0); CodeQL 35809531224, Security 35809531153, and SAST 35809531156 are also queued. Generic owner #1644 authority has been currentized to protected .github/main@e6334e229581a918e2f22de18733b76fa65d7e71, where it is 252 ahead / 277 behind and still requires ordinary/non-force reconciliation. No live Product ruleset mutation is justified while this RED and the parent governance stack remain unsettled.

  6. changed the title [-]governance: bind ConceptWeave Product acceptance to protected merges[/-] [+]governance: bind ConceptWeave Product workflow to protected merges[/+] on Sep 23, 2026
  7. seonghobae commented on Sep 23, 2026

    @seonghobae
    ContributorAuthor

    Authority correction from #2350 review 5286977381: the ConceptWeave-only Product policy must be a branch organization ruleset whose conditions explicitly bind both repository and ref. Current GitHub schema requires branch/tag org-ruleset conditions to carry repository_id + ref_name; therefore the desired payload/contract must require target="branch", conditions.repository_id.repository_ids=[1353201939], and a default/main-only conditions.ref_name selector. The workflows rule remains separately bound to source repository_id=1353201939, path .github/workflows/product.yml, ref refs/heads/main; bypass_actors stays empty and required_status_checks fallback remains prohibited. This matters because a repository-target policy is not equivalent to branch workflow enforcement, while an under-specified branch condition can broaden Product beyond protected integration branches. Primary schema: https://docs.github.com/en/rest/orgs/rules#create-an-organization-repository-ruleset . No live ruleset mutation is authorized from this comment.

  8. seonghobae commented on Sep 23, 2026

    @seonghobae
    ContributorAuthor

    P1 follow-up from #2350 review 5287728521: repository/path/ref workflow binding still leaves the source ref mutable. Current _assert_base_product_workflow() only checks four marker strings, so the bootstrap window after ConceptWeave#35 lands but before Product enforcement is active can admit a later protected-main Product edit that keeps those markers while weakening substantive gates. The owner plane must not copy Product YAML, but it does need an immutable reviewed content coordinate. Contract RED is now #2350 28246b1e77ac387273aad63a8bb6746c331d633b: the reviewed manifest must reserve a nullable product_workflow_blob_sha; mutation must remain impossible while that coordinate is unadopted, and after #35 lands a normal reviewed manifest update must pin the GitHub Contents blob SHA. Bootstrap, canary admission and active PUT then re-read protected main and require the exact blob plus existing semantic sanity checks. This keeps Product truth in ConceptWeave while closing workflow-source drift without relying on marker-compatible content.

  9. seonghobae commented on Sep 23, 2026

    @seonghobae
    ContributorAuthor

    #2350 immutable Product-source contract has now crossed RED→minimal repair without live policy mutation. Hosted RED run 35828264122 on exact 28246b1e77ac387273aad63a8bb6746c331d633b completed/failure at the focused lifecycle-contract step after exact checkout/tooling/manifest validation succeeded. Ordinary-forward repair is now current 7a627f3e9c564bcf7ce2f826b57c1b6ef8d1ebae: fe3f452... validates/compares an optional reviewed Contents blob coordinate, d42ba5a... reserves product_workflow_blob_sha: null rather than guessing the unlanded #35 candidate blob, and 7a627f3... adds focused manifest/blob coverage. Current owner/security runs are fresh and nonterminal (35845521134, 35845521152, 35845521063, 35845521110), so no GREEN or predecessor-evidence transfer is claimed yet. Review 5288830215 remains the next separate P1 after this exact-head repair settles: remove the mandatory base_ref_changed canary assumption in favor of Foundation #1's substantive pull_request:synchronize evidence. No Product-specific live ruleset was created or mutated.

  10. seonghobae commented on Sep 23, 2026

    @seonghobae
    ContributorAuthor

    Current-owner update for #2350 exact 7a627f3e9c564bcf7ce2f826b57c1b6ef8d1ebae: the hosted immutable-coordinate RED at 28246b1e... already executed terminally, and fe3f452... -> d42ba5a... -> 7a627f3... added nullable manifest/blob validation. However review 5289945740 found the repair is not yet wired into live mutation boundaries: bootstrap and canary still call _assert_base_product_workflow() without the reviewed blob, so null does not fail closed and marker-compatible drift can still reach evaluate creation/activation. Keep #2350 Draft and do not mutate a live Product ruleset. After the current exact-head owner run settles, add the causal RED for null/drift at bootstrap+activate, thread the reviewed coordinate through bootstrap/canary/final pre-PUT revalidation, then separately repair the superseded mandatory-base-retarget canary model from review 5288830215.

  11. seonghobae commented on Sep 23, 2026

    @seonghobae
    ContributorAuthor

    Current owner evidence (2026-09-23 KST): #2350's prior immutable-coordinate repair 7a627f3e9c564bcf7ce2f826b57c1b6ef8d1ebae now has exact owner GREEN in run 35845521134. Review 5289945740 has therefore advanced contract-first, ordinary-forward only: e1d525557cc7e5edfd66ea3f8e3d22cf0a425ab8 adds bootstrap RED for null/marker-compatible Product blob before evaluate POST; current fdbe09abb9079638098de92f5a40575d0696b675 adds activation/canary/pre-PUT blob contracts. 7a627f3... -> fdbe09a... is 2 ahead / 0 behind with only the two focused race-test files changed. Current owner run 35863230526 is queued before runner assignment; do not production-fix or mutate a live Product ruleset until the intended hosted RED is terminal. The later 5288830215 supported-pull_request:synchronize canary repair remains a separate subsequent head.

  12. seonghobae commented on Sep 23, 2026

    @seonghobae
    ContributorAuthor

    Current owner-path correction — .github#2350 is exact fdbe09abb9079638098de92f5a40575d0696b675. The earlier immutable-coordinate repair through 7a627f3... now has owner-contract GREEN (35845521134); review 5289945740 is staged as the current tests-only mutation-boundary RED and exact owner run 35863230526 is still queued, so production must not replace that RED head yet.

    New exact-current P1 review 5291871021 closes a separate deadlock in the subsequent supported-canary repair. Canonical ConceptWeave Foundation #1 is OPEN / Draft and already targets main. GitHub ruleset workflows use the default pull_request activities opened, synchronize, and reopened; a substantive ordinary/non-force Foundation reconciliation can therefore provide the supported synchronize canary without making the PR Ready. The existing _canary_evidence() requirement draft == false would force an artificial Ready transition that is neither needed to dispatch the required workflow nor valid governance evidence. After 5289945740 reaches RED → minimal fix → GREEN, fold 5291871021 into 5288830215: accept the open Draft Foundation canary while retaining exact PR/head/current-base, immutable Product blob, first-attempt Product success, evaluate-mode workflow-rule PASS, and no-later-source-movement constraints. Ready/Draft toggling, retarget/reopen, no-op commits, manual reruns, predecessor evidence and administrator bypass remain invalid canary evidence.

    Primary GitHub authority: https://docs.github.com/en/enterprise-cloud@latest/repositories/configuring-branches-and-merges-in-your-repository/managing-rulesets/troubleshooting-rules

  13. seonghobae commented on Sep 23, 2026

    @seonghobae
    ContributorAuthor

    5289945740 moved from queued contract to attributable hosted RED and minimal ordinary-forward repair. Exact fdbe09abb9079638098de92f5a40575d0696b675 run 35863230526 completed FAILURE at Prove Product ruleset lifecycle contract after exact checkout, pinned tooling and manifest validation succeeded; live verification/mutation jobs were skipped. Repair lineage is 8128ec228ee89b5b39dd66b43faf2fe5129c1f22 (fixture alignment only) -> a1628e75dc056098f4ea2d03ec799f2026025e84 (require reviewed Product blob before mutation, exact blob check before evaluate creation, canary binding, pre-active-PUT revalidation). Current owner run is 35891410528; do not start 5288830215 + 5291871021 until this exact head is GREEN. No live Product ruleset mutation occurred.

  14. seonghobae commented on Sep 23, 2026

    @seonghobae
    ContributorAuthor

    Current-head follow-up review 5294002721 on #2350@a1628e75dc056098f4ea2d03ec799f2026025e84: the new exact Product-blob read occurs after protected-ref checks, so the Contents network operation itself re-opens a narrow TOCTOU window. Preserve a1628e7... until owner run 35891410528 settles; then reality RED must show initial .github/main/ConceptWeave-main checks + blob validation succeed but a final protected-ref read sees drift and prevents POST/PUT. Repair must re-read both protected refs after blob validation and immediately before mutation. Keep the immutable blob guard; this precedes later 5288830215 + 5291871021 canary-model work.

  15. seonghobae commented on Sep 23, 2026

    @seonghobae
    ContributorAuthor

    Fresh owner-evidence correction: the Producer prerequisite section in this issue body still says downstream Python/Actions CodeQL scans are queued. That is no longer current. In .github run 35870670165, validate-dispatch 107213600319 is SUCCESS; Python 107322443235 and Actions 107322443261 are both terminal FAILURE only at Verify GHAS base/head CodeQL configuration identity after exact-head materialization, CodeQL analysis, and Medium+ SARIF gating succeeded, with evidence/status publication succeeding afterward. The remaining queued job is settlement 107396154783. Treat this as central .github#1929/#2275/#2276 GHAS identity/credential evidence plus settlement admission, not a ConceptWeave#35 source defect and not a reason to wake that PR. Product-governance sequencing is unchanged: #2350 stays exact a1af52d7bf2fcb5dfd27790961faf62651b16510; owner validate 107374677579 is still runnerless queued, so 5294002721 must remain unstaged until exact owner GREEN.

  16. seonghobae commented on Sep 24, 2026

    @seonghobae
    ContributorAuthor

    Current-state correction for the producer prerequisite; no owner-source or live-policy mutation.

    Fresh downstream CodeQL run 35870670165 no longer has queued language scans. validate-dispatch 107213600319 is SUCCESS; python 107322443235 and actions 107322443261 are both terminal FAILURE only at Verify GHAS base/head CodeQL configuration identity after exact-head materialization, CodeQL analysis and Medium+ SARIF gate succeeded, with evidence/status publication succeeding afterward. The remaining runnerless queue specimen is settlement 107396154783.

    Queue-health continuation now belongs to #2356 because #712 is comment-cap exhausted; ConceptWeave specimen is recorded there as comment 5805398442. GHAS identity/credential ownership remains #1929/#2275/#2276.

    Product owner source remains #2350 exact a1af52d7bf2fcb5dfd27790961faf62651b16510; run 35918073452 / validate 107374677579 remains runnerless queued. Therefore the existing sequence is unchanged: preserve exact owner evidence -> only after GREEN stage 5294002721 reality RED/minimal final-ref repair/GREEN -> later supported substantive synchronize / OPEN-Draft canary repair. No live Product ruleset mutation is authorized before those source gates.

  17. seonghobae commented on Sep 24, 2026

    @seonghobae
    ContributorAuthor

    Current Product-governance handoff: #2350 predecessor a1af52d7bf2fcb5dfd27790961faf62651b16510 now has exact owner GREEN (35918073452 SUCCESS). Review 5294002721 is therefore active. Test-only ordinary descendant 1a6ddce2d02df50dddeb81450ff05cb9778c94a9 proves the missing post-blob TOCTOU boundary for both protected .github/main and ConceptWeave main: drift during the final immutable Product Contents/blob read must prevent evaluate creation and active PUT. Production remains unchanged on this RED candidate. Owner run 35944402217 / validate 107459043420 is currently pre-runner queued; preserve the exact head until it settles. Only after attributable RED may the minimal final-ref revalidation repair be added, followed by exact-head GREEN and then the separate supported pull_request:synchronize / OPEN-Draft canary repair.

  18. seonghobae commented on Sep 24, 2026

    @seonghobae
    ContributorAuthor

    ConceptWeave Product owner update for review 5294002721:

    • Hosted reality RED is now terminal on exact 1a6ddce2d02df50dddeb81450ff05cb9778c94a9: run 35944402217, validate 107459043420 acquired runner 1002117594; exact checkout/tooling/manifest validation passed and Prove Product ruleset lifecycle contract failed. Mutation/live jobs were skipped.
    • The retained bootstrap/activation race tests require zero evaluate POST / active PUT if protected .github/main or ConceptWeave main advances during the final reviewed Product blob read.
    • Minimal causal production repair is ordinary-forward 97acdfeef0830d56c7b9b78226fec53de791ee8f. Diff is exactly four executable lines: re-read both protected refs immediately after the final blob validation in bootstrap and activation, before POST/PUT. No workflow, manifest, policy shape, canary, or live ruleset mutation changed.
    • Exact repair run 35961585829 / validate 107511123583 is currently queued before runner assignment. Preserve that exact head until terminal evidence; only GREEN closes 5294002721.

    Later 5288830215 + 5291871021 synchronize/OPEN-Draft canary repair remains a separate subsequent head.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: ci-cdCI, GitHub Actions, checks, release, or supply chainbugSomething isn't workingpriority: highHigh-priority or P1 workstatus: blockedBlocked by conflict, dependency, or required prerequisitetype: bugDefect or incorrect behavior

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions