Skip to content

chore(temp): merge current main into OpenCode bootstrap reconciliation branch - #1620

Closed
seonghobae wants to merge 31 commits into
reconcile/opencode-bootstrap-with-main-20260902from
main
Closed

chore(temp): merge current main into OpenCode bootstrap reconciliation branch#1620
seonghobae wants to merge 31 commits into
reconcile/opencode-bootstrap-with-main-20260902from
main

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

Temporary non-destructive reconciliation only. Merge protected current main into the historical #1489 branch so Git can preserve main's later same-repository status-credential fixes while retaining #1489's independent orphan-bootstrap deletion. This PR is not a product integration lane; after the merge, only the reconciled three-file blobs will be used on #1619 and this temporary branch will not be merged to protected main.


Devin Review

seonghobae and others added 30 commits August 22, 2026 17:24
…s credential

Resolve CHANGELOG and the opencode-review-dispatch blob pin after a
normal merge of origin/main. The job-scoped github.token same-repo
status path remains the PR change; the dispatch workflow pin now
matches the merged blob SHA.
…o-status-token

# Conflicts:
#	CHANGELOG.md
#	tests/test_pr_review_autofix_nvidia_nim_contract.py
…o-status-token

# Conflicts:
#	CHANGELOG.md
#	tests/test_pr_review_autofix_nvidia_nim_contract.py
The merge conflict resolution left a placeholder in REVIEW_DISPATCH_BLOB_SHA
pending a fresh git hash-object of the merged opencode-review-dispatch.yml
(neither side's pinned value was still correct once both changes combined).
Filled in with the actual post-merge blob hash.
…o-status-token

# Conflicts:
#	tests/test_pr_review_autofix_nvidia_nim_contract.py
Protected main regressed to 99% scripts/ci coverage after #1546 added
live_head_matches, a no-active/no-stale fall-through in
prepare_autofix_slot, and an "already queued or running" wait branch
to pr_review_fix_scheduler.py without covering them, while the
pre-existing inspect_pr conflicted-draft/conflicted-unauthorized
returns and pr_review_merge_scheduler.py's
fetch_workflow_names_by_check_suite_rest pagination/filtering/
permission-denied paths stayed untested. Every PR rebasing onto main
inherits this via the coverage-evidence required check regardless of
its own diff. Test-only change; no production code touched.

(cherry picked from commit db106d5)
Raise scoped docstring coverage for the newly added scheduler REST regression helpers to 100% without changing test behavior or production code.

(cherry picked from commit 6f40a06)
RCA: the #1567 exact-head Hourly NVIDIA NIM Review Repair run failed in test_scheduler_wake_reuses_trusted_receipt_predicate with exit 141. The production block pipes jq JSON into gh api --input -, while the test fake exited without reading stdin. Under pipefail that can SIGPIPE jq. Reuse the already RED/GREEN-verified #1569 fixture blob and drain stdin before recording the fake dispatch. This makes #1567 self-contained so the central 100% coverage repair no longer depends on a separate PR that itself inherits the coverage failure.
(cherry picked from commit 6948175)
QUEUE_SATURATION_CHICKEN_EGG: protected main is deterministically red on 15 inherited Noema fixture tests after #1564 changed the changed-file/deleted-file/CodeGraph contracts. This exact head is a two-test-file-only repair reconciled onto current main, source verification reports 2318 passed, 1 skipped, 21 subtests with 100% line/branch/docstring coverage, GitHub reports mergeable with zero review threads, and exact-head Devin/CodeRabbit both completed successfully. Required Actions evidence remains queued in the saturated central fleet; no substantive test, security, provenance, or review defect is bypassed.
Root cause: Strix 1.5.3 passes LLM_TIMEOUT to asyncio.wait_for, so LLM_TIMEOUT=0 immediately cancels contextual-orchestrator model preflight. The focused regression and one-line LLM_TIMEOUT=300 repair were verified before publication. Merge uses the ordinary expected-head path; no review/security/finding gate is weakened.
#1583)

QUEUE_SATURATION_CHICKEN_EGG: exact head 09f2b19 is mechanically mergeable, current-head Devin/CodeRabbit verdicts are success, all review threads are resolved, and the in-place workflow identity quality CI is terminal success. The remaining current-head security/CodeQL/SAST/SBOM evidence is queued in a 745-run saturated Actions fleet. The workflow path/ID remains stable, write authority is not expanded, and no substantive test, security, review, or provenance defect is bypassed.
QUEUE_SATURATION_CHICKEN_EGG: exact-head Devin/CodeRabbit review is clean, substantive review findings are resolved, and the remaining current-head security/supply-chain workflows are queued behind the saturated central Actions fleet. The Strix 1.5.3 compatibility layer is version-gated and preserves non-model operational timeouts while removing the fixed inference deadline.
QUEUE_SATURATION_CHICKEN_EGG: exact head 674e0d5 is mechanically mergeable, current-head Devin/CodeRabbit statuses are success, all review threads are resolved, and the source/test contract has already corrected the discovered publication credential, private-repository visibility, and executable-wiring defects. Remaining required workflows are queued in an 828-run saturated Actions fleet. This merge preserves non-force publication history and excludes forks before inventory work; no substantive failure is bypassed.
)

QUEUE_SATURATION_CHICKEN_EGG: this exact one-line test repair matches protected production's three-argument GITHUB_ENV publication contract. The stale protected-main assertion is independently proven as the sole failure after 2,344 passing tests in #1606's exact-head Strix quality run. Current-head Devin/CodeRabbit statuses are success, there are zero review threads, and all required workflows are queued in a 894-run saturated Actions fleet. No substantive product, security, provenance, or review defect is bypassed.
QUEUE_SATURATION_CHICKEN_EGG: exact-head TDD proved the queue-drain scheduler itself was starved on ubuntu-latest while explicit ubuntu-24.04 acquired runners. The unchanged PR head is mergeable, has zero review threads, no source-backed failing checks, a successful exact-head scan-pr-queue run, and repository review-count 0. Remaining required jobs are queued on the saturated floating-image surface. Merge this minimal causal repair so the protected scheduler can retire stale queue work; revalidate protected-main scheduler execution immediately after integration.
QUEUE_SATURATION_CHICKEN_EGG: exact head 1e121e0 is a one-file test-only coverage repair with RED/GREEN/full-suite evidence, zero review threads, Devin no-issues and CodeRabbit/Devin success; remaining required workflows are queued under central Actions saturation. This repair is prerequisite evidence infrastructure for #1612.
QUEUE_SATURATION_CHICKEN_EGG: exact head 1af7cee is mechanically mergeable, has zero unresolved review threads, latest Devin reports 0 new issues, CodeRabbit/Devin and exact-head Strix quality are success, and the remaining broad required workflows are queued under central Actions saturation. The change has full-suite/coverage/docstring evidence and repairs a central Noema handoff defect that can otherwise discard valid current-head verdicts.
QUEUE_SATURATION_CHICKEN_EGG: exact head 8abc1c1 is mechanically mergeable, all current review threads are resolved after correcting residual attribution/citation defects, Devin/CodeRabbit exact-head statuses are success, and the remaining broad workflows are queued under central Actions saturation. This documentation/provenance repair removes unsupported claims of human authorization from authoritative governance material.
…epo-status-token

fix(opencode): use same-repo status credential
QUEUE_SATURATION_CHICKEN_EGG: current-head review statuses are successful, no substantive review thread remains, deterministic randomized equivalence produced zero mismatches, and the remaining protected Actions evidence is queued behind the saturated central fleet.
* test(actions): require explicit runner for security gates

* fix(actions): pin required security runners

* fix(actions): pin required SAST runners

* fix(actions): pin secret scan runner image

* fix(actions): pin scorecard runner image
QUEUE_SATURATION_CHICKEN_EGG: exact head was mechanically mergeable, all substantive review threads were resolved, independent review status was successful, the two-phase credential-lifetime repair had deterministic verification, and all current-head hosted workflows were queued with no current-head failed run. Merge is bound to the expected head SHA; predecessor evidence is not transferred.
* test(metadata): require fleet reconciliation contract

* feat(metadata): declare initial fleet desired state

* feat(metadata): add repository settings reconciler

* feat(metadata): add trusted hourly reconciliation workflow

* feat(metadata): add context graph contract desired state

* test(metadata): cover context graph desired state

* feat(metadata): add ThreadWeave desired state

* test(metadata): cover ThreadWeave desired state

* feat(metadata): add RankWeave desired state

* test(metadata): cover RankWeave desired state

* test(metadata): require executable DeepWiki gate

* fix(metadata): enforce DeepWiki and Pages preconditions

* test(metadata): require non-blocking fleet apply

* fix(metadata): continue independent repositories on failure

* test(metadata): require apply diagnostics import

* fix(metadata): import diagnostics stream

* feat(metadata): add fast-mlsirm desired state

* test(metadata): cover fast-mlsirm desired state

* fix(metadata): close reconciliation review gaps

* test(metadata): cover mutation and failure behavior

* fix(metadata): serialize apply runs by ref

* fix(metadata): enforce exact DeepWiki URL casing

* test(metadata): reject mis-cased DeepWiki targets

* fix(metadata): make reconciliation workflow executable

* fix(metadata): keep DeepWiki image inside target anchor

* test(metadata): format contracts and cover split anchors

* feat(metadata): centralize evidence-backed label mappings

* test(metadata): pin repository label taxonomy contract

* fix(metadata): make desired-state reconciliation convergent

* test(metadata): cover convergent Pages and strict manifest state

* fix(metadata): make reconciliation checks complete and non-cancelling

* feat(metadata): declare evidence-backed label assignments

* feat(metadata): reconcile label taxonomy assignments

* test(metadata): pin reviewed label assignments

* test(metadata): cover idempotent label reconciliation

* test(metadata): close label reconciler coverage gaps

* feat(metadata): operationalize label taxonomy reconciliation

* docs(metadata): record repository reconciliation architecture decision

* docs(metadata): add repository reconciliation operational baseline

* docs(metadata): add public-surface control-plane architecture

* fix(metadata): place label reconciler under CI quality scope

* fix(metadata): isolate focused coverage configuration

* fix(metadata): remove duplicate label reconciler path

* fix(metadata): follow canonical label reconciler path

* fix(metadata): bind label tests to CI-owned reconciler

* fix(metadata): keep reconciliation on trusted schedule

* fix(metadata): preserve concurrent unmanaged labels

* test(metadata): prove label updates are concurrency-safe

* fix(metadata): converge topics and deduplicate narrow filters

* test(metadata): prove set-convergent topics and filter idempotence

* docs(metadata): align baseline with trusted scheduled reconciliation

* fix(metadata): keep metadata and label lanes independent

* docs(metadata): align ADR with concurrency-safe scheduled apply

* docs(metadata): align control-plane architecture with trusted schedule

* test(metadata): cover mixed managed label convergence

* test(metadata): close label branch coverage gap

* fix(metadata): reject case-colliding repository identities

* fix(metadata): canonicalize label repository identities

* test(metadata): reject case-aliased repository state

* test(metadata): normalize label repository identities

* fix(metadata): bound fleet identity and apply capacity

* feat(metadata): verify live repository state after apply

* feat(metadata): verify live label state after apply

* test(metadata): prove live post-apply repository verification

* test(metadata): prove live post-apply label verification

* feat(metadata): re-read live public state after reconciliation

* fix(metadata): preserve reconciliation failure contract

* fix(metadata): preserve label reconciliation failure contract

* fix(metadata): compare managed labels case-insensitively

* test(metadata): prove label identities ignore casing

* fix(metadata): verify Pages is built and reachable

* test(metadata): require built reachable Pages publication

* fix(metadata): confine Pages verification to GitHub Pages

* test(metadata): cover Pages origin and redirect confinement

* feat(metadata): add EgressWeave desired state

* chore(metadata): classify EgressWeave public-surface PR

* feat(metadata): add Psychometrics Commons desired state

* chore(metadata): classify Psychometrics Commons public-surface PR

* docs(metadata): refresh eight-repository fleet baseline

* test(metadata): cover eight-repository desired state

* test(metadata): cover expanded label assignments

* fix(metadata): retry transient Pages publication verification

* chore(metadata): extend reviewed documentation label assignments

* chore(metadata): classify Orgmetra and Noema public-surface work

* test(metadata): cover expanded label assignments

* chore(metadata): add product workspace public surfaces

* test(metadata): cover expanded product fleet

* revert(metadata): preserve reviewed fleet scope

* test(metadata): document exact taxonomy drift guard

* docs(metadata): refresh managed label inventory

* chore(metadata): track learning contracts classification

* test(metadata): cover learning contracts classification

* feat(metadata): add EmbedRelay public surface

* revert(metadata): keep reviewed fleet contract stable

* docs(metadata): reconcile label assignment inventory

---------

Co-authored-by: opencode-agent[bot] <219766164+opencode-agent[bot]@users.noreply.github.com>
@seonghobae seonghobae closed this Sep 1, 2026

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 3 potential issues.

Devin Review

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔍 Focused regression execution unavailable

This environment lacks pytest, so the new Noema, reconciliation, and Strix suites were not executed locally. Their hosted results require review.

Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

if: env.PR_NUMBER != '' && steps.noema_prepare.outputs.prepared == 'true'
env:
GH_TOKEN: ${{ steps.noema_credential.outputs.source == 'pat' && secrets.NOEMA_REVIEW_TOKEN || steps.noema_credential.outputs.source == 'github-app' && steps.noema_github_app_publication_token.outputs.token || steps.noema_credential.outputs.source == 'oidc' && steps.noema_oidc_token.outputs.token || '' }}
NOEMA_REVIEW_TOKEN_SOURCE: ${{ steps.noema_credential.outputs.source == 'pat' && 'noema-review-pat' || steps.noema_credential.outputs.source == 'github-app' && 'noema-review-github-app-refresh' || steps.noema_credential.outputs.source == 'oidc' && 'noema-review-app-oidc' || '' }}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔴 Refreshed App reviews never publish

GitHub App publication labels NOEMA_REVIEW_TOKEN_SOURCE as an unsupported value. current_actor() rejects every refreshed credential before submitting its verdict.

Suggested change
NOEMA_REVIEW_TOKEN_SOURCE: ${{ steps.noema_credential.outputs.source == 'pat' && 'noema-review-pat' || steps.noema_credential.outputs.source == 'github-app' && 'noema-review-github-app-refresh' || steps.noema_credential.outputs.source == 'oidc' && 'noema-review-app-oidc' || '' }}
NOEMA_REVIEW_TOKEN_SOURCE: ${{ steps.noema_credential.outputs.source == 'pat' && 'noema-review-pat' || steps.noema_credential.outputs.source == 'github-app' && 'noema-review-github-app' || steps.noema_credential.outputs.source == 'oidc' && 'noema-review-app-oidc' || '' }}
Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

@@ -0,0 +1,45 @@
# Hourly commercial-license SBOM remediation

Status: implementation evidence for the central ContextualWisdomLab supply-chain control plane.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔍 New documentation fails whitespace gate

The status line ends with trailing whitespace. Repository quality workflows run git diff --check, so this revision cannot pass them unchanged.

Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants