Repository navigation
governance: bind ConceptWeave Product workflow to protected merges #2348
Description
Activity
- addedarea: ci-cdCI, GitHub Actions, checks, release, or supply chainCI, GitHub Actions, checks, release, or supply chainbugSomething isn't workingSomething isn't workingpriority: highHigh-priority or P1 workHigh-priority or P1 workstatus: blockedBlocked by conflict, dependency, or required prerequisiteBlocked by conflict, dependency, or required prerequisitetype: bugDefect or incorrect behaviorDefect or incorrect behavior
on Sep 22, 2026 seonghobae commented
on Sep 23, 2026 ContributorAuthorMore actionsImplementation path is Draft stacked PR #2350, now exact
c875b35b6ca4312756062c6ac75154d3d865e0bcon canonical owner #1644. It implements repository-only discovery →evaluatebootstrap → reviewed ruleset-ID adoption → normal ConceptWeave #35 producer landing → exact current-base Product canary → observed GitHub Actions integration binding →activepromotion. Review5285801953repaired GitHub Contents API CR/LF-wrapped base64 canary decoding with an executed regression and strict post-normalization decode. Hosted66992527...run35805657970then exposed a second pre-existing CLI-entrypoint defect at manifest validation; review5285850467→ contract06ae30fd...→ production/currentc875b35...replaces direct-script/PYTHONPATH-prone invocation withpython -m scripts.ci.reconcile_conceptweave_product_ruleset. Exact current owner workflow35806029592is now terminal GREEN: exact checkout, hash-locked tooling, manifest validation and lifecycle contract all passed; privileged live/mutation jobs correctly skipped on the PR event. Central CodeQL/Security/SAST lanes remain independent/nonterminal. No live ruleset mutation was performed.seonghobae commented
on Sep 23, 2026 ContributorAuthorMore actionsOwner-path update: dependent implementation #2350 is now at exact
f37264ef539e555381cf0fac9a2779847dadcdc6on top of #1644.Two additional P1s were closed in this pass. Review
5285966215found a bootstrap TOCTOU: the create path checked trusted protected.github/mainbefore repository-ruleset discovery but not immediately before the live POST. The race contract was wired in, the existing history expectation was currentized for the new guard, and production now rechecks_assert_current_main(expected_main_sha)directly at the create boundary while retaining post-create verification.Review
5286048812then found a privileged source/runtime boundary issue. Exact hosted logs showed Harden Runner onubuntu-slimsays it is unsupported and will not be monitored, whileverify-liveexposedCWL_RULESET_ADMIN_TOKENand lacked an explicit protected-main ref condition. Contract heade37dd17...was hosted RED in run35808543490(65 passed / 1 failed on the new ref/runner contract). Production/currentf37264ef...moves all three jobs toubuntu-24.04and requiresworkflow_dispatch + mode=verify + refs/heads/mainbefore the secret-bearing live verification job can run.Current exact owner run
35808617203plus CodeQL35808617183, Security35808617233, and SAST35808617199are queued. No predecessor GREEN is being transferred, and no live ruleset mutation has been performed.seonghobae commented
on Sep 23, 2026 ContributorAuthorMore actionsImplementation update: #2350 moved to test-only RED head
f2130292a22908d7bd3a4b5f839e9b92fd04f3e3after exact-head review5286111728found a second target-main TOCTOU in activation._canary_integration_id()proves the canary base equals live ConceptWeavemain, butactivate_product_ruleset()did not re-read ConceptWeavemainimmediately before active PUT. Regression08b9e0d...simulates target-main equality during canary proof followed by drift before mutation;f2130292...enrolls it in owner run35809531211. Production remains intentionally unchanged pending hosted RED; no live ruleset mutation or predecessor evidence transfer is claimed.seonghobae commented
on Sep 23, 2026 ContributorAuthorMore actions2026-09-23 owner-path update: implementation PR #2350 is exact
f2130292a22908d7bd3a4b5f839e9b92fd04f3e3. Review5286111728isolates activation target-main TOCTOU and regression08b9e0d...+ workflow enrollmentf2130292...intentionally leave production unchanged until the hosted RED executes. Current owner run35809531211is still queued onubuntu-24.04before runner allocation (runner id 0); CodeQL35809531224, Security35809531153, and SAST35809531156are also queued. Generic owner #1644 authority has been currentized to protected.github/main@e6334e229581a918e2f22de18733b76fa65d7e71, where it is 252 ahead / 277 behind and still requires ordinary/non-force reconciliation. No live Product ruleset mutation is justified while this RED and the parent governance stack remain unsettled.- changed the title
[-]governance: bind ConceptWeave Product acceptance to protected merges[/-][+]governance: bind ConceptWeave Product workflow to protected merges[/+]on Sep 23, 2026 seonghobae commented
on Sep 23, 2026 ContributorAuthorMore actionsAuthority correction from #2350 review
5286977381: the ConceptWeave-only Product policy must be a branch organization ruleset whose conditions explicitly bind both repository and ref. Current GitHub schema requires branch/tag org-ruleset conditions to carryrepository_id+ref_name; therefore the desired payload/contract must requiretarget="branch",conditions.repository_id.repository_ids=[1353201939], and a default/main-onlyconditions.ref_nameselector. Theworkflowsrule remains separately bound to sourcerepository_id=1353201939, path.github/workflows/product.yml, refrefs/heads/main;bypass_actorsstays empty andrequired_status_checksfallback remains prohibited. This matters because a repository-target policy is not equivalent to branch workflow enforcement, while an under-specified branch condition can broaden Product beyond protected integration branches. Primary schema: https://docs.github.com/en/rest/orgs/rules#create-an-organization-repository-ruleset . No live ruleset mutation is authorized from this comment.seonghobae commented
on Sep 23, 2026 ContributorAuthorMore actionsP1 follow-up from #2350 review
5287728521: repository/path/ref workflow binding still leaves the source ref mutable. Current_assert_base_product_workflow()only checks four marker strings, so the bootstrap window after ConceptWeave#35 lands but before Product enforcement is active can admit a later protected-main Product edit that keeps those markers while weakening substantive gates. The owner plane must not copy Product YAML, but it does need an immutable reviewed content coordinate. Contract RED is now #235028246b1e77ac387273aad63a8bb6746c331d633b: the reviewed manifest must reserve a nullableproduct_workflow_blob_sha; mutation must remain impossible while that coordinate is unadopted, and after #35 lands a normal reviewed manifest update must pin the GitHub Contents blob SHA. Bootstrap, canary admission and active PUT then re-read protectedmainand require the exact blob plus existing semantic sanity checks. This keeps Product truth in ConceptWeave while closing workflow-source drift without relying on marker-compatible content.seonghobae commented
on Sep 23, 2026 ContributorAuthorMore actions#2350 immutable Product-source contract has now crossed RED→minimal repair without live policy mutation. Hosted RED run
35828264122on exact28246b1e77ac387273aad63a8bb6746c331d633bcompleted/failure at the focused lifecycle-contract step after exact checkout/tooling/manifest validation succeeded. Ordinary-forward repair is now current7a627f3e9c564bcf7ce2f826b57c1b6ef8d1ebae:fe3f452...validates/compares an optional reviewed Contents blob coordinate,d42ba5a...reservesproduct_workflow_blob_sha: nullrather than guessing the unlanded #35 candidate blob, and7a627f3...adds focused manifest/blob coverage. Current owner/security runs are fresh and nonterminal (35845521134,35845521152,35845521063,35845521110), so no GREEN or predecessor-evidence transfer is claimed yet. Review5288830215remains the next separate P1 after this exact-head repair settles: remove the mandatorybase_ref_changedcanary assumption in favor of Foundation #1's substantivepull_request:synchronizeevidence. No Product-specific live ruleset was created or mutated.seonghobae commented
on Sep 23, 2026 ContributorAuthorMore actionsCurrent-owner update for #2350 exact
7a627f3e9c564bcf7ce2f826b57c1b6ef8d1ebae: the hosted immutable-coordinate RED at28246b1e...already executed terminally, andfe3f452... -> d42ba5a... -> 7a627f3...added nullable manifest/blob validation. However review5289945740found the repair is not yet wired into live mutation boundaries: bootstrap and canary still call_assert_base_product_workflow()without the reviewed blob, so null does not fail closed and marker-compatible drift can still reach evaluate creation/activation. Keep #2350 Draft and do not mutate a live Product ruleset. After the current exact-head owner run settles, add the causal RED for null/drift at bootstrap+activate, thread the reviewed coordinate through bootstrap/canary/final pre-PUT revalidation, then separately repair the superseded mandatory-base-retarget canary model from review5288830215.seonghobae commented
on Sep 23, 2026 ContributorAuthorMore actionsCurrent owner evidence (2026-09-23 KST): #2350's prior immutable-coordinate repair
7a627f3e9c564bcf7ce2f826b57c1b6ef8d1ebaenow has exact owner GREEN in run35845521134. Review5289945740has therefore advanced contract-first, ordinary-forward only:e1d525557cc7e5edfd66ea3f8e3d22cf0a425ab8adds bootstrap RED for null/marker-compatible Product blob before evaluate POST; currentfdbe09abb9079638098de92f5a40575d0696b675adds activation/canary/pre-PUT blob contracts.7a627f3... -> fdbe09a...is 2 ahead / 0 behind with only the two focused race-test files changed. Current owner run35863230526is queued before runner assignment; do not production-fix or mutate a live Product ruleset until the intended hosted RED is terminal. The later5288830215supported-pull_request:synchronizecanary repair remains a separate subsequent head.seonghobae commented
on Sep 23, 2026 ContributorAuthorMore actionsCurrent owner-path correction —
.github#2350is exactfdbe09abb9079638098de92f5a40575d0696b675. The earlier immutable-coordinate repair through7a627f3...now has owner-contract GREEN (35845521134); review5289945740is staged as the current tests-only mutation-boundary RED and exact owner run35863230526is still queued, so production must not replace that RED head yet.New exact-current P1 review
5291871021closes a separate deadlock in the subsequent supported-canary repair. Canonical ConceptWeave Foundation #1 is OPEN / Draft and already targetsmain. GitHub ruleset workflows use the defaultpull_requestactivitiesopened,synchronize, andreopened; a substantive ordinary/non-force Foundation reconciliation can therefore provide the supportedsynchronizecanary without making the PR Ready. The existing_canary_evidence()requirementdraft == falsewould force an artificial Ready transition that is neither needed to dispatch the required workflow nor valid governance evidence. After5289945740reaches RED → minimal fix → GREEN, fold5291871021into5288830215: accept the open Draft Foundation canary while retaining exact PR/head/current-base, immutable Product blob, first-attempt Product success, evaluate-mode workflow-rule PASS, and no-later-source-movement constraints. Ready/Draft toggling, retarget/reopen, no-op commits, manual reruns, predecessor evidence and administrator bypass remain invalid canary evidence.Primary GitHub authority: https://docs.github.com/en/enterprise-cloud@latest/repositories/configuring-branches-and-merges-in-your-repository/managing-rulesets/troubleshooting-rules
seonghobae commented
on Sep 23, 2026 ContributorAuthorMore actions5289945740moved from queued contract to attributable hosted RED and minimal ordinary-forward repair. Exactfdbe09abb9079638098de92f5a40575d0696b675run35863230526completed FAILURE atProve Product ruleset lifecycle contractafter exact checkout, pinned tooling and manifest validation succeeded; live verification/mutation jobs were skipped. Repair lineage is8128ec228ee89b5b39dd66b43faf2fe5129c1f22(fixture alignment only) ->a1628e75dc056098f4ea2d03ec799f2026025e84(require reviewed Product blob before mutation, exact blob check before evaluate creation, canary binding, pre-active-PUT revalidation). Current owner run is35891410528; do not start5288830215 + 5291871021until this exact head is GREEN. No live Product ruleset mutation occurred.seonghobae commented
on Sep 23, 2026 ContributorAuthorMore actionsCurrent-head follow-up review
5294002721on #2350@a1628e75dc056098f4ea2d03ec799f2026025e84: the new exact Product-blob read occurs after protected-ref checks, so the Contents network operation itself re-opens a narrow TOCTOU window. Preservea1628e7...until owner run35891410528settles; then reality RED must show initial.github/main/ConceptWeave-main checks + blob validation succeed but a final protected-ref read sees drift and prevents POST/PUT. Repair must re-read both protected refs after blob validation and immediately before mutation. Keep the immutable blob guard; this precedes later5288830215 + 5291871021canary-model work.seonghobae commented
on Sep 23, 2026 ContributorAuthorMore actionsFresh owner-evidence correction: the
Producer prerequisitesection in this issue body still says downstream Python/Actions CodeQL scans are queued. That is no longer current. In.githubrun35870670165,validate-dispatch107213600319is SUCCESS; Python107322443235and Actions107322443261are both terminal FAILURE only atVerify GHAS base/head CodeQL configuration identityafter exact-head materialization, CodeQL analysis, and Medium+ SARIF gating succeeded, with evidence/status publication succeeding afterward. The remaining queued job is settlement107396154783. Treat this as central.github#1929/#2275/#2276GHAS identity/credential evidence plus settlement admission, not a ConceptWeave#35 source defect and not a reason to wake that PR. Product-governance sequencing is unchanged: #2350 stays exacta1af52d7bf2fcb5dfd27790961faf62651b16510; owner validate107374677579is still runnerless queued, so5294002721must remain unstaged until exact owner GREEN.seonghobae commented
on Sep 24, 2026 ContributorAuthorMore actionsCurrent-state correction for the producer prerequisite; no owner-source or live-policy mutation.
Fresh downstream CodeQL run
35870670165no longer has queued language scans.validate-dispatch107213600319is SUCCESS; python107322443235and actions107322443261are both terminal FAILURE only atVerify GHAS base/head CodeQL configuration identityafter exact-head materialization, CodeQL analysis and Medium+ SARIF gate succeeded, with evidence/status publication succeeding afterward. The remaining runnerless queue specimen is settlement107396154783.Queue-health continuation now belongs to #2356 because #712 is comment-cap exhausted; ConceptWeave specimen is recorded there as comment
5805398442. GHAS identity/credential ownership remains #1929/#2275/#2276.Product owner source remains #2350 exact
a1af52d7bf2fcb5dfd27790961faf62651b16510; run35918073452/ validate107374677579remains runnerless queued. Therefore the existing sequence is unchanged: preserve exact owner evidence -> only after GREEN stage5294002721reality RED/minimal final-ref repair/GREEN -> later supported substantivesynchronize/ OPEN-Draft canary repair. No live Product ruleset mutation is authorized before those source gates.seonghobae commented
on Sep 24, 2026 ContributorAuthorMore actionsCurrent Product-governance handoff: #2350 predecessor
a1af52d7bf2fcb5dfd27790961faf62651b16510now has exact owner GREEN (35918073452SUCCESS). Review5294002721is therefore active. Test-only ordinary descendant1a6ddce2d02df50dddeb81450ff05cb9778c94a9proves the missing post-blob TOCTOU boundary for both protected.github/mainand ConceptWeavemain: drift during the final immutable Product Contents/blob read must prevent evaluate creation and active PUT. Production remains unchanged on this RED candidate. Owner run35944402217/ validate107459043420is currently pre-runner queued; preserve the exact head until it settles. Only after attributable RED may the minimal final-ref revalidation repair be added, followed by exact-head GREEN and then the separate supportedpull_request:synchronize/ OPEN-Draft canary repair.seonghobae commented
on Sep 24, 2026 ContributorAuthorMore actionsConceptWeave Product owner update for review
5294002721:- Hosted reality RED is now terminal on exact
1a6ddce2d02df50dddeb81450ff05cb9778c94a9: run35944402217, validate107459043420acquired runner1002117594; exact checkout/tooling/manifest validation passed andProve Product ruleset lifecycle contractfailed. Mutation/live jobs were skipped. - The retained bootstrap/activation race tests require zero evaluate POST / active PUT if protected
.github/mainor ConceptWeavemainadvances during the final reviewed Product blob read. - Minimal causal production repair is ordinary-forward
97acdfeef0830d56c7b9b78226fec53de791ee8f. Diff is exactly four executable lines: re-read both protected refs immediately after the final blob validation in bootstrap and activation, before POST/PUT. No workflow, manifest, policy shape, canary, or live ruleset mutation changed. - Exact repair run
35961585829/ validate107511123583is currently queued before runner assignment. Preserve that exact head until terminal evidence; only GREEN closes5294002721.
Later
5288830215 + 5291871021synchronize/OPEN-Draft canary repair remains a separate subsequent head.- Hosted reality RED is now terminal on exact
Gap
ConceptWeave#35 owns canonical Product validation, but live protected policy still does not bind that workflow to ordinary protected merges. The accepted control remains a dedicated organization branch/workflows ruleset scoped only to ConceptWeave repository id
1353201939and protected/defaultmain, bound to source repository id1353201939,.github/workflows/product.yml,refs/heads/main; no bypass actors, no repositoryrequired_status_checksfallback, and no Product injection into global ruleset18156473.Current owner authority — 2026-09-24 KST
Implementation PR #2350 is OPEN / Draft / mergeable on #1644. Current exact head is
a1af52d7bf2fcb5dfd27790961faf62651b16510. No live Product-specific ruleset has been created or mutated.Immutable-source review
5287728521is repaired through7a627f3e9c564bcf7ce2f826b57c1b6ef8d1ebae; owner run35845521134is terminal GREEN.Mutation-boundary review
5289945740has a real hosted RED atfdbe09abb9079638098de92f5a40575d0696b675/ run35863230526. Ordinary-forward production repaira1628e75dc056098f4ea2d03ec799f2026025e84requires a non-null reviewed Product blob before mutation, verifies exact protected Product bytes before evaluate creation/canary admission, and revalidates the exact blob before active PUT.Owner run
35891410528ona1628e7...is terminal FAILURE, but its focused lifecycle suite is behaviorally clean: exact checkout/tooling/manifest validation succeeded and 60 tests passed. The only failure is the owned 100% coverage gate:reconcile_conceptweave_product_ruleset.pymeasured 99%, with the staged legacy-manifest/malformed-coordinate paths (81->90,103) uncovered.Causal test-only repair
a1af52d7bf2fcb5dfd27790961faf62651b16510adds two contracts only: legacy reviewed manifest shape withoutproduct_workflow_blob_sha, and malformed string blob-coordinate rejection. Relative toa1628e7...it is 1 commit ahead / 0 behind, one test file, +19/-0, with no production delta. Fresh owner run35918073452/ validate job107374677579is queued before runner assignment. Preserve this head until terminal evidence; do not manual/blind-rerun or no-op wake it.Remaining P1s
Final protected-ref revalidation — review
5294002721Current production flow checks protected
.github/mainand ConceptWeavemain, performs the Product Contents network read/blob validation, then mutates. A ref can advance while the Contents read is in flight. Aftera1af52d...reaches exact owner GREEN, first stage a reality RED in which initial ref checks and blob validation succeed but a final protected-ref read observes drift and POST/PUT remains uncalled. Then minimally re-read both protected refs after blob validation and immediately before evaluate POST / active PUT. Keep the immutable blob guard unchanged.Supported evaluate canary — reviews
5288830215+5291871021This is a later separate head. GitHub ruleset workflows use supported PR activities; Foundation #1 already targets
main, so its substantive ordinary/non-force reconciliation after #35 lands must supplypull_request:synchronize. Mandatorybase_ref_changedevidence must be removed. Foundation intentionally remains OPEN / Draft; canary verification must accept that state without Ready/Draft manipulation while still binding exact PR/head/current protected base, reviewed Product blob, first-attempt Product success, exact evaluate-modeworkflowsPASS and no later source movement. Retarget/reopen/no-op/manual-rerun/predecessor evidence remains invalid.Producer prerequisite
ConceptWeave#35 exact
d7b7e30b278ec2f27096b4d313c7d5eaf5387ddcremains the one-time producer prerequisite. SAST35825043007and Security35825042856are GREEN. Required CodeQL35825042996is terminal FAILURE from central ordering/publication, not a ConceptWeave source finding. Downstream.githubrun35870670165has terminal-successvalidate-dispatchjob107213600319; python/actions scan jobs107322443235/107322443261remain queued before runner assignment. That remains.github#1929/#712-owned; do not move #35 merely to wake it.Bootstrap ordering
a1af52d....5294002721final-ref revalidation.5288830215 + 5291871021; land fix(governance): stage ConceptWeave Product ruleset enforcement #2350 source normally with no live Product mutation.mainProduct Contents and adopt only that immutable blob coordinate through ordinary reviewed.githubsource.evaluate; commit the returned positive ruleset ID through ordinary review.main; use its substantivepull_request:synchronizerun as first-attempt evaluate-mode canary while remaining Draft..github/main, ConceptWeave target main/canary base, exact Product blob, ruleset state/history and concurrent drift.evaluate -> active, then prove missing/pending/failed Product blocks ordinary merge and terminal success satisfies the gate without administrator bypass.Acceptance
branch/workflowsrule only; unrelated repositories unaffected;synchronize, not synthetic lifecycle manipulation;Refs #772, #1351, #1644, #2350, ContextualWisdomLab/ConceptWeave#35, ContextualWisdomLab/ConceptWeave#1, ContextualWisdomLab/ConceptWeave#4.