chore(temp): merge current main into OpenCode bootstrap reconciliation branch - #1620
Closed
seonghobae wants to merge 31 commits into
Closed
chore(temp): merge current main into OpenCode bootstrap reconciliation branch#1620seonghobae wants to merge 31 commits into
seonghobae wants to merge 31 commits into
Conversation
…s credential Resolve CHANGELOG and the opencode-review-dispatch blob pin after a normal merge of origin/main. The job-scoped github.token same-repo status path remains the PR change; the dispatch workflow pin now matches the merged blob SHA.
…o-status-token # Conflicts: # CHANGELOG.md # tests/test_pr_review_autofix_nvidia_nim_contract.py
…o-status-token # Conflicts: # CHANGELOG.md # tests/test_pr_review_autofix_nvidia_nim_contract.py
The merge conflict resolution left a placeholder in REVIEW_DISPATCH_BLOB_SHA pending a fresh git hash-object of the merged opencode-review-dispatch.yml (neither side's pinned value was still correct once both changes combined). Filled in with the actual post-merge blob hash.
…o-status-token # Conflicts: # tests/test_pr_review_autofix_nvidia_nim_contract.py
Protected main regressed to 99% scripts/ci coverage after #1546 added live_head_matches, a no-active/no-stale fall-through in prepare_autofix_slot, and an "already queued or running" wait branch to pr_review_fix_scheduler.py without covering them, while the pre-existing inspect_pr conflicted-draft/conflicted-unauthorized returns and pr_review_merge_scheduler.py's fetch_workflow_names_by_check_suite_rest pagination/filtering/ permission-denied paths stayed untested. Every PR rebasing onto main inherits this via the coverage-evidence required check regardless of its own diff. Test-only change; no production code touched. (cherry picked from commit db106d5)
Raise scoped docstring coverage for the newly added scheduler REST regression helpers to 100% without changing test behavior or production code. (cherry picked from commit 6f40a06)
RCA: the #1567 exact-head Hourly NVIDIA NIM Review Repair run failed in test_scheduler_wake_reuses_trusted_receipt_predicate with exit 141. The production block pipes jq JSON into gh api --input -, while the test fake exited without reading stdin. Under pipefail that can SIGPIPE jq. Reuse the already RED/GREEN-verified #1569 fixture blob and drain stdin before recording the fake dispatch. This makes #1567 self-contained so the central 100% coverage repair no longer depends on a separate PR that itself inherits the coverage failure. (cherry picked from commit 6948175)
…o-status-token # Conflicts: # CHANGELOG.md
QUEUE_SATURATION_CHICKEN_EGG: protected main is deterministically red on 15 inherited Noema fixture tests after #1564 changed the changed-file/deleted-file/CodeGraph contracts. This exact head is a two-test-file-only repair reconciled onto current main, source verification reports 2318 passed, 1 skipped, 21 subtests with 100% line/branch/docstring coverage, GitHub reports mergeable with zero review threads, and exact-head Devin/CodeRabbit both completed successfully. Required Actions evidence remains queued in the saturated central fleet; no substantive test, security, provenance, or review defect is bypassed.
Root cause: Strix 1.5.3 passes LLM_TIMEOUT to asyncio.wait_for, so LLM_TIMEOUT=0 immediately cancels contextual-orchestrator model preflight. The focused regression and one-line LLM_TIMEOUT=300 repair were verified before publication. Merge uses the ordinary expected-head path; no review/security/finding gate is weakened.
#1583) QUEUE_SATURATION_CHICKEN_EGG: exact head 09f2b19 is mechanically mergeable, current-head Devin/CodeRabbit verdicts are success, all review threads are resolved, and the in-place workflow identity quality CI is terminal success. The remaining current-head security/CodeQL/SAST/SBOM evidence is queued in a 745-run saturated Actions fleet. The workflow path/ID remains stable, write authority is not expanded, and no substantive test, security, review, or provenance defect is bypassed.
QUEUE_SATURATION_CHICKEN_EGG: exact-head Devin/CodeRabbit review is clean, substantive review findings are resolved, and the remaining current-head security/supply-chain workflows are queued behind the saturated central Actions fleet. The Strix 1.5.3 compatibility layer is version-gated and preserves non-model operational timeouts while removing the fixed inference deadline.
QUEUE_SATURATION_CHICKEN_EGG: exact head 674e0d5 is mechanically mergeable, current-head Devin/CodeRabbit statuses are success, all review threads are resolved, and the source/test contract has already corrected the discovered publication credential, private-repository visibility, and executable-wiring defects. Remaining required workflows are queued in an 828-run saturated Actions fleet. This merge preserves non-force publication history and excludes forks before inventory work; no substantive failure is bypassed.
) QUEUE_SATURATION_CHICKEN_EGG: this exact one-line test repair matches protected production's three-argument GITHUB_ENV publication contract. The stale protected-main assertion is independently proven as the sole failure after 2,344 passing tests in #1606's exact-head Strix quality run. Current-head Devin/CodeRabbit statuses are success, there are zero review threads, and all required workflows are queued in a 894-run saturated Actions fleet. No substantive product, security, provenance, or review defect is bypassed.
QUEUE_SATURATION_CHICKEN_EGG: exact-head TDD proved the queue-drain scheduler itself was starved on ubuntu-latest while explicit ubuntu-24.04 acquired runners. The unchanged PR head is mergeable, has zero review threads, no source-backed failing checks, a successful exact-head scan-pr-queue run, and repository review-count 0. Remaining required jobs are queued on the saturated floating-image surface. Merge this minimal causal repair so the protected scheduler can retire stale queue work; revalidate protected-main scheduler execution immediately after integration.
QUEUE_SATURATION_CHICKEN_EGG: exact head 1e121e0 is a one-file test-only coverage repair with RED/GREEN/full-suite evidence, zero review threads, Devin no-issues and CodeRabbit/Devin success; remaining required workflows are queued under central Actions saturation. This repair is prerequisite evidence infrastructure for #1612.
QUEUE_SATURATION_CHICKEN_EGG: exact head 1af7cee is mechanically mergeable, has zero unresolved review threads, latest Devin reports 0 new issues, CodeRabbit/Devin and exact-head Strix quality are success, and the remaining broad required workflows are queued under central Actions saturation. The change has full-suite/coverage/docstring evidence and repairs a central Noema handoff defect that can otherwise discard valid current-head verdicts.
QUEUE_SATURATION_CHICKEN_EGG: exact head 8abc1c1 is mechanically mergeable, all current review threads are resolved after correcting residual attribution/citation defects, Devin/CodeRabbit exact-head statuses are success, and the remaining broad workflows are queued under central Actions saturation. This documentation/provenance repair removes unsupported claims of human authorization from authoritative governance material.
…o-status-token # Conflicts: # CHANGELOG.md
…epo-status-token fix(opencode): use same-repo status credential
QUEUE_SATURATION_CHICKEN_EGG: current-head review statuses are successful, no substantive review thread remains, deterministic randomized equivalence produced zero mismatches, and the remaining protected Actions evidence is queued behind the saturated central fleet.
* test(actions): require explicit runner for security gates * fix(actions): pin required security runners * fix(actions): pin required SAST runners * fix(actions): pin secret scan runner image * fix(actions): pin scorecard runner image
QUEUE_SATURATION_CHICKEN_EGG: exact head was mechanically mergeable, all substantive review threads were resolved, independent review status was successful, the two-phase credential-lifetime repair had deterministic verification, and all current-head hosted workflows were queued with no current-head failed run. Merge is bound to the expected head SHA; predecessor evidence is not transferred.
* test(metadata): require fleet reconciliation contract * feat(metadata): declare initial fleet desired state * feat(metadata): add repository settings reconciler * feat(metadata): add trusted hourly reconciliation workflow * feat(metadata): add context graph contract desired state * test(metadata): cover context graph desired state * feat(metadata): add ThreadWeave desired state * test(metadata): cover ThreadWeave desired state * feat(metadata): add RankWeave desired state * test(metadata): cover RankWeave desired state * test(metadata): require executable DeepWiki gate * fix(metadata): enforce DeepWiki and Pages preconditions * test(metadata): require non-blocking fleet apply * fix(metadata): continue independent repositories on failure * test(metadata): require apply diagnostics import * fix(metadata): import diagnostics stream * feat(metadata): add fast-mlsirm desired state * test(metadata): cover fast-mlsirm desired state * fix(metadata): close reconciliation review gaps * test(metadata): cover mutation and failure behavior * fix(metadata): serialize apply runs by ref * fix(metadata): enforce exact DeepWiki URL casing * test(metadata): reject mis-cased DeepWiki targets * fix(metadata): make reconciliation workflow executable * fix(metadata): keep DeepWiki image inside target anchor * test(metadata): format contracts and cover split anchors * feat(metadata): centralize evidence-backed label mappings * test(metadata): pin repository label taxonomy contract * fix(metadata): make desired-state reconciliation convergent * test(metadata): cover convergent Pages and strict manifest state * fix(metadata): make reconciliation checks complete and non-cancelling * feat(metadata): declare evidence-backed label assignments * feat(metadata): reconcile label taxonomy assignments * test(metadata): pin reviewed label assignments * test(metadata): cover idempotent label reconciliation * test(metadata): close label reconciler coverage gaps * feat(metadata): operationalize label taxonomy reconciliation * docs(metadata): record repository reconciliation architecture decision * docs(metadata): add repository reconciliation operational baseline * docs(metadata): add public-surface control-plane architecture * fix(metadata): place label reconciler under CI quality scope * fix(metadata): isolate focused coverage configuration * fix(metadata): remove duplicate label reconciler path * fix(metadata): follow canonical label reconciler path * fix(metadata): bind label tests to CI-owned reconciler * fix(metadata): keep reconciliation on trusted schedule * fix(metadata): preserve concurrent unmanaged labels * test(metadata): prove label updates are concurrency-safe * fix(metadata): converge topics and deduplicate narrow filters * test(metadata): prove set-convergent topics and filter idempotence * docs(metadata): align baseline with trusted scheduled reconciliation * fix(metadata): keep metadata and label lanes independent * docs(metadata): align ADR with concurrency-safe scheduled apply * docs(metadata): align control-plane architecture with trusted schedule * test(metadata): cover mixed managed label convergence * test(metadata): close label branch coverage gap * fix(metadata): reject case-colliding repository identities * fix(metadata): canonicalize label repository identities * test(metadata): reject case-aliased repository state * test(metadata): normalize label repository identities * fix(metadata): bound fleet identity and apply capacity * feat(metadata): verify live repository state after apply * feat(metadata): verify live label state after apply * test(metadata): prove live post-apply repository verification * test(metadata): prove live post-apply label verification * feat(metadata): re-read live public state after reconciliation * fix(metadata): preserve reconciliation failure contract * fix(metadata): preserve label reconciliation failure contract * fix(metadata): compare managed labels case-insensitively * test(metadata): prove label identities ignore casing * fix(metadata): verify Pages is built and reachable * test(metadata): require built reachable Pages publication * fix(metadata): confine Pages verification to GitHub Pages * test(metadata): cover Pages origin and redirect confinement * feat(metadata): add EgressWeave desired state * chore(metadata): classify EgressWeave public-surface PR * feat(metadata): add Psychometrics Commons desired state * chore(metadata): classify Psychometrics Commons public-surface PR * docs(metadata): refresh eight-repository fleet baseline * test(metadata): cover eight-repository desired state * test(metadata): cover expanded label assignments * fix(metadata): retry transient Pages publication verification * chore(metadata): extend reviewed documentation label assignments * chore(metadata): classify Orgmetra and Noema public-surface work * test(metadata): cover expanded label assignments * chore(metadata): add product workspace public surfaces * test(metadata): cover expanded product fleet * revert(metadata): preserve reviewed fleet scope * test(metadata): document exact taxonomy drift guard * docs(metadata): refresh managed label inventory * chore(metadata): track learning contracts classification * test(metadata): cover learning contracts classification * feat(metadata): add EmbedRelay public surface * revert(metadata): keep reviewed fleet contract stable * docs(metadata): reconcile label assignment inventory --------- Co-authored-by: opencode-agent[bot] <219766164+opencode-agent[bot]@users.noreply.github.com>
Contributor
| if: env.PR_NUMBER != '' && steps.noema_prepare.outputs.prepared == 'true' | ||
| env: | ||
| GH_TOKEN: ${{ steps.noema_credential.outputs.source == 'pat' && secrets.NOEMA_REVIEW_TOKEN || steps.noema_credential.outputs.source == 'github-app' && steps.noema_github_app_publication_token.outputs.token || steps.noema_credential.outputs.source == 'oidc' && steps.noema_oidc_token.outputs.token || '' }} | ||
| NOEMA_REVIEW_TOKEN_SOURCE: ${{ steps.noema_credential.outputs.source == 'pat' && 'noema-review-pat' || steps.noema_credential.outputs.source == 'github-app' && 'noema-review-github-app-refresh' || steps.noema_credential.outputs.source == 'oidc' && 'noema-review-app-oidc' || '' }} |
Contributor
There was a problem hiding this comment.
🔴 Refreshed App reviews never publish
GitHub App publication labels NOEMA_REVIEW_TOKEN_SOURCE as an unsupported value. current_actor() rejects every refreshed credential before submitting its verdict.
Suggested change
| NOEMA_REVIEW_TOKEN_SOURCE: ${{ steps.noema_credential.outputs.source == 'pat' && 'noema-review-pat' || steps.noema_credential.outputs.source == 'github-app' && 'noema-review-github-app-refresh' || steps.noema_credential.outputs.source == 'oidc' && 'noema-review-app-oidc' || '' }} | |
| NOEMA_REVIEW_TOKEN_SOURCE: ${{ steps.noema_credential.outputs.source == 'pat' && 'noema-review-pat' || steps.noema_credential.outputs.source == 'github-app' && 'noema-review-github-app' || steps.noema_credential.outputs.source == 'oidc' && 'noema-review-app-oidc' || '' }} |
Was this helpful? React with 👍 or 👎 to provide feedback.
| @@ -0,0 +1,45 @@ | |||
| # Hourly commercial-license SBOM remediation | |||
|
|
|||
| Status: implementation evidence for the central ContextualWisdomLab supply-chain control plane. | |||
Contributor
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Temporary non-destructive reconciliation only. Merge protected current main into the historical #1489 branch so Git can preserve main's later same-repository status-credential fixes while retaining #1489's independent orphan-bootstrap deletion. This PR is not a product integration lane; after the merge, only the reconciled three-file blobs will be used on #1619 and this temporary branch will not be merged to protected main.