fix(governance): automate ruleset owner-plane reconciliation - #1644
fix(governance): automate ruleset owner-plane reconciliation#1644seonghobae wants to merge 243 commits into
Conversation
…ked-pr-central-required-workflows
# Conflicts: # scripts/ci/test_strix_quick_gate.sh
Merge protected main non-destructively while retaining only the create-transition audit and its executable regressions. Focused ruleset audit: 20 passed. Full suite: 1,402 passed, 1 skipped, 16 subtests.
Preserve only the two governance owner files over protected main 0c6b9a6. Focused ruleset audit: 20 passed. Full suite: 1,402 passed, 1 skipped, 16 subtests.
|
Wardnet consumer/control-plane handoff — fresh 2026-09-05 KST live state:
RED remains live-settings drift plus stale/non-mergeable owner ancestry. Please adopt the intervening protected-main delta non-force, reacquire exact-head gates, then after protected source integration use the already-designed least-privilege reconciliation path to converge the live ruleset. GREEN for Wardnet remains: approval count 0 with no synthetic reviewer, routine bypass absent, deterministic workflow/security/thread/deletion/non-fast-forward controls preserved, followed by an unchanged exact Wardnet candidate completing all then-required gates and taking the ordinary protected merge path. No Wardnet source churn or self/model approval is needed for this owner-plane repair. |
|
Fresh owner-plane revalidation: keep this PR as the canonical solo-maintainer reconciler, but it is not integration-ready and it must not be superseded by #1861's two-human policy. Current head is Three current blockers remain source-backed on this head: (1) the unresolved identical-external-write/ambiguous-recovery race in #1861 currently asserts two approvals plus last-push approval. That conflicts with this reconciler's reviewed solo-maintainer contract (0 approvals, last-push false, no synthetic reviewer) and #772. Preserve any useful fail-fast audit ordering from #1861 only after expressing the expected values through this canonical policy; never apply the two-human expectation to live rules. Re-run full exact-head governance/security/coverage after reconciliation, resolve only verified findings, then use the protected owner-plane environment/token path to converge live rulesets. |
|
Fresh Context Fabric owner-plane handoff (revalidated 2026-09-05 KST): the live PR metadata, not this PR body’s historical SHA prose, is authoritative. The product-side RED is unchanged and was independently reread: both |
|
Owner-plane freshness update: protected |
|
@jules Fresh owner-plane drift requires another non-destructive reconciliation before this ruleset repair can become protected truth. Please re-read all intervening protected-main deltas, then adopt/adapt them with a non-force merge/restack while preserving only this PR's still-valid ruleset-governance owner delta. Re-run the repository's deterministic governance/security/coverage/docstring/SBOM/provenance/thread gates on the resulting exact head. The intended live policy remains the solo-maintainer contract already encoded here: generic approval count 0, no synthetic human/model approval, stale-review dismissal + unresolved-thread/deletion/non-fast-forward controls retained, required workflows retained, and routine bypass actors removed. Do not weaken the newer #1922 scheduler/CI isolation or any later protected control-plane repair. After source integration, the privileged settings apply still must verify exact protected source and live ruleset identity/history before mutation; source merge alone is not live-settings convergence. |
The single conflict is two adjacent assertions, and the two lines resolve in opposite directions — taking either side wholesale fails. Line 1 — take main's. The surrounding test body (common to both sides after the merge) duplicates `.github/workflows/security-scan.yml`, not `scorecard-pr.yml`, so the duplicate-count assertion must name security-scan. `scorecard-pr.yml` no longer exists in the merged tree at all. Line 2 — take this branch's. `scripts/ci/audit_central_required_workflows.py` emits "central solo-maintainer ruleset must not require approving reviews"; main's "exactly two approving reviews are not required" matches no string the production code produces. The next (unconflicted) assertion in the same test already reads "central solo-maintainer ruleset must not require last-push approval", so this branch's wording is the one consistent with the module. Both choices were determined from the merged tree's own fixture and production strings, not from either branch's prior state. Verified after resolution: 3044 passed, 1 skipped, coverage 100%, interrogate 100%; zero conflict markers; `ruff check --select F821` clean. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
|
Fresh owner-path canary from a writable leaf; no
Leaf exact-head repository requirements are genuinely terminal GREEN: Live organization ruleset Owner acceptance for #1644 should therefore include this unchanged leaf as a post-reconciliation canary in addition to Orgmetra:
This canary is useful because it separates leaf source correctness from both live ruleset drift and required-workflow generation/recovery. Please preserve that distinction in the owner RED/GREEN contract. |
|
Fresh fleet owner-path correction after re-reading the dedicated writer lane; no The PR body's
Exact-head workflow inventory for Please make the dedicated writer's next normal descendant/body reconciliation use the live The unchanged GREEN boundary: owner ruleset state matches canonical policy; #1644 exact current head has terminal owner security/CodeQL/review evidence; and the unchanged #219 canary obtains genuine current central workflow/verdict evidence (or a typed owner failure) under ordinary protected flow. No admin bypass, self-approval, source-neutral leaf churn, or predecessor-check substitution. |
|
Fresh Context Fabric dependency handoff (2026-09-06 KST), no
Owner GREEN remains: non-force adopt current protected main -> reacquire every exact-head central gate -> ordinary merge -> privileged live reconciliation from exact protected truth -> prove solo-compatible ruleset + routine bypass removal -> protect Context Fabric main refs -> then allow default switch and fresh product stack reconstruction. |
|
Context Fabric owner-path RCA for the current exact head |
|
Fresh Context Fabric owner-plane revalidation on live head Two unresolved findings are still source-backed on this exact head and should be repaired test-first in this owner lane before privileged reconciliation:
The third unresolved Fresh live Context Fabric control evidence remains nonconverged: inherited org ruleset After #1644 is repaired, non-force reconciled onto current protected main, exact-head gates/threads are clean, and normally integrated, use the existing protected owner-plane path to converge the impossible solo-maintainer rule without weakening deterministic checks. Then continue #1137's already-accepted protected-main -> default-main transition and re-read effective rulesets before reconstructing CGC/EA stacks. |
|
@jules Fresh owner-path restack finding from Wardnet dependency sweep; please repair this lane rather than treating solo-governance as a user blocker. Current protected Repair acceptance: read/adopt every intervening protected delta; non-force merge current protected main into the owner branch (or produce a verified successor carrying the complete unique ruleset-governance delta); preserve the canonical solo-maintainer policy of generic approval count 0/no synthetic reviewer/no routine bypass plus deterministic workflow/security/thread/non-fast-forward/deletion controls; rerun the focused governance/adversarial suites and every then-live exact-head gate; resolve any new current review findings. Only after ordinary protected integration should the privileged protected-main reconciler mutate live rules, followed by fresh ruleset reads proving convergence and an unchanged deterministic-clean product canary using ordinary protected admission without self/model approval or silent admin bypass. |
|
Fresh Context Fabric owner handoff, 2026-09-06 KST. This governance implementation is no longer based on current protected central truth and its current CodeQL evidence must not be reused after reconciliation.
The same post-runner dispatch/verdict failure now reproduces on CGC root Please adopt the 28 intervening protected-main commits by ordinary non-force merge/restack, audit their delta, and reacquire all exact-head checks on the resulting SHA. Do not force-rebase, transfer this head's GREENs, or treat the current CodeQL failure as leaf runner starvation. After reconciliation, the acceptance condition is an authenticated terminal current-head CodeQL dispatch/verdict plus the existing deterministic ruleset-governance gates. |
|
Stacked PR 검사 적용 범위의 신규 운영 증거를 이 canonical owner에 연결합니다. CO#1074 head239f894edb2b37f4c28430d1acecb5ab36eef712의 base codex/psychometric-kpi-successor에는 effective branch rules가 없습니다. 상속 조회된18156473은 active/~DEFAULT_BRANCH에7개workflow와승인·삭제·non-fast-forward규칙이혼합돼있습니다. 로컬검사trigger수리후제품quality run34039966047은생겼지만중앙required검사적용완료증거는아닙니다. 현재source audit_central_required_workflows.py의 stackowner21732164는 evaluate/ #1644현manifest/reconciler가승인규칙을전제하는기존2target만지원하므로workflow-onlytarget을단순추가하거나18156473전체조건을~ALL로확대하지않아야합니다. 기존관리자실행경로에서21732164현재payload를확인한뒤, 정상branch작성/후속수정을보존하는stack검사설계를별도로검증해야합니다. 단일OpenCodecanary는있더라도전체7개필수검사/조직전체완료를대체할수없습니다. 실제rulesetwrite·adminscope추가·권한확대는하지않았습니다. |
|
Taking the existing #1644 branch as the single writer for the bounded Context Fabric P0 repair from exact head |
Adopt protected main@6e014c9bae22f1e6d8302a4f1cc38f4f6a114ae2 without dropping the ruleset governance owner delta.
Observe ambiguous recovery writes through the full settlement horizon, preserve a later administrator version after an identical external write, and accept an existing native code-scanning gate without weakening the managed ruleset contract.
|
Context Fabric owner-plane P0 execution receipt — exact head
Source writer released. Any successor must fresh-fetch this exact head and protected main before writing. |
|
Single-writer reacquired only because protected |
Ordinary two-parent adoption of protected main #1975 while preserving the ruleset governance P0 delta.
|
Latest-main ordinary-restack receipt — exact head
Source writer released again. |
|
Read-only adoption-boundary audit at exact head 82ef13a. This PR is not by itself evidence that Naruon stacked PRs receive enforced central required checks:
For the Naruon consumer gap, retain the current PRs and require a separately reviewed workflow-only stacked enforcement contract and tests in this canonical owner after the scope/authority decision. Do not broaden the mixed default-branch ruleset, reduce approvals, or copy consumer workflows as a shortcut. No settings, permissions, allowlists or source files were changed during this audit; tests were inspected, not executed. No current-head check or approval is asserted by this comment. |
|
Single-writer reacquired because protected |
Ordinary non-force adoption of protected main@ad0779bee66624c3997947d7691f4b0dbb973be1. Preserve #1973 scheduler conflict-admission changes byte-for-byte while retaining all #1644 governance reconciliation semantics. Exact-tree verification: 582 focused tests; governance 185 tests; reconciler 396 statements / 154 branches at 100%; docstrings 100%; full suite 3124 passed, 1 skipped, 21 subtests. The first full invocation exposed only an unseeded local uv virtualenv missing pip; after matching hosted setup-python's pip presence, the exact failing test and full suite passed without source changes.
|
Latest protected-main adoption receipt — exact head
Source writer released. Do not merge or execute live settings reconciliation until this unchanged exact head has terminal required security/CodeQL/reconcile/SBOM/provenance/review evidence and the ordinary protected path is available. No settings, ruleset, default-branch, branch-protection, principal allowlist, consumer head, or run was mutated. |
|
SOURCE WRITER CLAIM — protected |
|
SOURCE WRITER RELEASE — exact head |
Current authoritative execution receipt — 2026-09-06
8d0c3e7de921c4e45ebc022b1e035c7f5c1e52fbmain@49eb9e7035a6994fffb5b24bf943156be27a02fb8d0c3e7de921c4e45ebc022b1e035c7f5c1e52fb, with parents predecessor4556483380bf7e7770bfc5e8c1094ce3350134edand protected main49eb9e7035a6994fffb5b24bf943156be27a02fb.14b9a3170fa61391b9a4d949184ea7ab0df2ff56; protected-main test(concurrency): anchor every cancel-in-progress contract, strix included #1979 cancel-in-progress contract tests are preserved byte-for-byte.813 passed; reconciler396 statements / 154 branches = 100%; docstrings100%; full3124 passed, 1 skipped, 21 subtests; diff clean.Historical receipts below are retained as provenance and are not current-head acceptance.
Buyer/control-plane outcome
This is the owner-plane writer for the live ruleset drift blocking Orgmetra's ordinary protected merge canary. Source integration alone does not mutate live settings: privileged apply remains disabled unless trusted protected
mainhasCWL_RULESET_RECONCILE_ENABLED=trueand the protectedruleset-governance-maintenanceenvironment supplies a separately provisioned least-privilegeCWL_RULESET_ADMIN_TOKENwith Administration write authority.Current exact stack — 2026-09-02
Current exact head:
528139ff3c2a3680d67b8489c38fdb65cd31d98c.Current protected
main:78271917b526469c559fa75cb5ee39426e5494d1(#1734). A concurrent writer reconciled this branch without force-push or destructive rebase after protected main advanced: fresh comparison reportsbehind_by=0, and the effective protected-main-relative diff remains exactly the same 19 ruleset-governance owner paths. The protected #1734 OpenCode superseded-poll retirement delta is preserved rather than overwritten.Exact-head evidence reset: no predecessor Check evidence transfers across protected-main integration. On current exact head
528139ff…,Ruleset Governance Reconcilerun33636088810is terminal SUCCESS. Security Scan33636089120and SBOM33636088874are pending; OSV33636090369, SAST33636088896, Python Security33636089086, Secret Scan33636088792, Scorecard33636088771, and CodeQL33636089031are queued. Therefore the focused governance result is valid evidence for its own contract only; the PR is not represented as fully merge-ready until the unchanged exact head has terminal required evidence. All materialized inline review threads must remain revalidated against this exact head. Ordinary squash auto-merge remains the intended merge path; administrator bypass and self-approval are not used.Predecessor #1176 was retired only after verified complete successor transfer of all seven valid changed paths. Four paths are tree-identical here; the audit script has identical content with executable-mode strengthening; and the two differing tests each add the explicit
require_code_owner_review = falsesolo-maintainer assertion. No predecessor Check evidence was transferred.Completed one-shot source-fix artifacts are absent from the current tree; this lane contains only permanent governance source/tests/docs.
Reviewed implementation boundary
config/ruleset-governance.jsonbinds exactly repository ruleset17921150and organization ruleset18156473.PUTprecondition for these ruleset updates. A second live read detects visible drift but is not represented as compare-and-swap.PUT, and rechecks version state after settlement before trusting the restore.PUTmay already have been accepted, history settlement and lossless compensation finish without a stale-main veto so an overwritten administrator predecessor is not stranded.Live drift and acceptance boundary
Live settings must be re-read independently of source integration. The last verified state showed inherited organization ruleset
18156473withrequired_approving_review_count=1and routineOrganizationAdmin/alwaysbypass, while.githubrepository ruleset17921150had approval 0/last-push false/CODEOWNER false but still permitted rebase and routineOrganizationAdmin/alwaysbypass. This PR therefore has not completed settings reconciliation merely by changing source.Require terminal successor-head security/review evidence before ordinary merge. After source reaches protected
main, provision the distinct least-privilege owner-plane identity, enable reconciliation only for a controlled maintenance interval, require exact live payload plus immutable-history convergence, re-run the canonical audit, and prove unchanged deterministic-GREENContextualWisdomLab/Orgmetra#88@0dc4f09cc3c87829ea1e3a0e3dc0188df07ad8cdcan take the ordinary protected merge path without synthetic approval or routine administrator bypass. Genuine failed/absent required workflows and unresolved required threads remain blocking.Refs #772, #1176, #1340, #1351, #1669, #1728, #1731, #1734, ContextualWisdomLab/Orgmetra#89.
Summary by CodeRabbit
새 기능
문서
품질 개선