Skip to content

fix(governance): automate ruleset owner-plane reconciliation - #1644

Open
seonghobae wants to merge 243 commits into
mainfrom
fix/ruleset-owner-plane-reconciler
Open

fix(governance): automate ruleset owner-plane reconciliation#1644
seonghobae wants to merge 243 commits into
mainfrom
fix/ruleset-owner-plane-reconciler

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

Current authoritative execution receipt — 2026-09-06

  • Exact PR head: 8d0c3e7de921c4e45ebc022b1e035c7f5c1e52fb
  • Current protected base: main@49eb9e7035a6994fffb5b24bf943156be27a02fb
  • Ordinary adoption commit: 8d0c3e7de921c4e45ebc022b1e035c7f5c1e52fb, with parents predecessor 4556483380bf7e7770bfc5e8c1094ce3350134ed and protected main 49eb9e7035a6994fffb5b24bf943156be27a02fb.
  • Exact tree: 14b9a3170fa61391b9a4d949184ea7ab0df2ff56; protected-main test(concurrency): anchor every cancel-in-progress contract, strix included #1979 cancel-in-progress contract tests are preserved byte-for-byte.
  • Current-tree GREEN: combined governance/scheduler/main-delta focused 813 passed; reconciler 396 statements / 154 branches = 100%; docstrings 100%; full 3124 passed, 1 skipped, 21 subtests; diff clean.
  • No predecessor hosted check or approval transfers. Fresh exact-head workflows must reach terminal evidence before ordinary merge.
  • Live ruleset, Actions variable, repository default branch, branch protection, and dependency-graph settings were not mutated. Owner-plane apply remains disabled until this source reaches protected truth and the separately provisioned least-privilege Administration-write environment is actually exposed.

Historical receipts below are retained as provenance and are not current-head acceptance.

Buyer/control-plane outcome

This is the owner-plane writer for the live ruleset drift blocking Orgmetra's ordinary protected merge canary. Source integration alone does not mutate live settings: privileged apply remains disabled unless trusted protected main has CWL_RULESET_RECONCILE_ENABLED=true and the protected ruleset-governance-maintenance environment supplies a separately provisioned least-privilege CWL_RULESET_ADMIN_TOKEN with Administration write authority.

Current exact stack — 2026-09-02

Current exact head: 528139ff3c2a3680d67b8489c38fdb65cd31d98c.

Current protected main: 78271917b526469c559fa75cb5ee39426e5494d1 (#1734). A concurrent writer reconciled this branch without force-push or destructive rebase after protected main advanced: fresh comparison reports behind_by=0, and the effective protected-main-relative diff remains exactly the same 19 ruleset-governance owner paths. The protected #1734 OpenCode superseded-poll retirement delta is preserved rather than overwritten.

Exact-head evidence reset: no predecessor Check evidence transfers across protected-main integration. On current exact head 528139ff…, Ruleset Governance Reconcile run 33636088810 is terminal SUCCESS. Security Scan 33636089120 and SBOM 33636088874 are pending; OSV 33636090369, SAST 33636088896, Python Security 33636089086, Secret Scan 33636088792, Scorecard 33636088771, and CodeQL 33636089031 are queued. Therefore the focused governance result is valid evidence for its own contract only; the PR is not represented as fully merge-ready until the unchanged exact head has terminal required evidence. All materialized inline review threads must remain revalidated against this exact head. Ordinary squash auto-merge remains the intended merge path; administrator bypass and self-approval are not used.

Predecessor #1176 was retired only after verified complete successor transfer of all seven valid changed paths. Four paths are tree-identical here; the audit script has identical content with executable-mode strengthening; and the two differing tests each add the explicit require_code_owner_review = false solo-maintainer assertion. No predecessor Check evidence was transferred.

Completed one-shot source-fix artifacts are absent from the current tree; this lane contains only permanent governance source/tests/docs.

Reviewed implementation boundary

  • config/ruleset-governance.json binds exactly repository ruleset 17921150 and organization ruleset 18156473.
  • The canonical policy is the solo-maintainer contract: approval count 0, last-push and same-author CODEOWNER approval disabled, no synthetic required reviewers, stale-review dismissal and thread resolution retained, merge/squash only, deletion/non-fast-forward retained, and routine bypass actors forbidden.
  • The reconciler validates exact live target identity and invokes the canonical ruleset auditors against projected and post-write live-shaped payloads so unmanaged scope/workflow/protection drift cannot be mislabeled as convergence.
  • GitHub exposes no conditional unsafe PUT precondition for these ruleset updates. A second live read detects visible drift but is not represented as compare-and-swap.
  • Privileged mutation samples immutable ruleset history before its final live read and binds both CLI and callable mutation paths to an exact protected-main SHA. Ambiguous mutation results are settled from live state plus immutable history rather than blindly retried.
  • Collision recovery follows immutable predecessor evidence, preserves newer administrator state, settles ambiguous recovery writes across the bounded observation horizon before any subsequent PUT, and rechecks version state after settlement before trusting the restore.
  • Visible current-state changes are checked before a recovery write; protected-main freshness is then checked immediately before that privileged write. Once an earlier PUT may already have been accepted, history settlement and lossless compensation finish without a stale-main veto so an overwritten administrator predecessor is not stranded.
  • Privileged non-PR owner-plane runs share one serialized non-cancellable concurrency group; read-only PR validation may supersede itself.
  • Pull-request validation uses pinned actions and hash-locked tooling, verifies exact checkout, executes the permanent governance/adversarial suites, and enforces 100% owned statement/branch/docstring gates without persisted checkout credentials.
  • The source-derived two-target critical-section bound is 7,680 seconds / 128 minutes; the apply job uses GitHub's documented 360-minute hosted-job ceiling rather than inventing a smaller setup allowance.
  • Doctoring records the REST/history authority boundary, timeout/collision semantics, current GitHub Actions execution limits, NIST SP 800-53 Rev. 5 AC-6/CM-3, and Sinan, Shahin, and Gondal (2025) in APA 7th form.

Live drift and acceptance boundary

Live settings must be re-read independently of source integration. The last verified state showed inherited organization ruleset 18156473 with required_approving_review_count=1 and routine OrganizationAdmin/always bypass, while .github repository ruleset 17921150 had approval 0/last-push false/CODEOWNER false but still permitted rebase and routine OrganizationAdmin/always bypass. This PR therefore has not completed settings reconciliation merely by changing source.

Require terminal successor-head security/review evidence before ordinary merge. After source reaches protected main, provision the distinct least-privilege owner-plane identity, enable reconciliation only for a controlled maintenance interval, require exact live payload plus immutable-history convergence, re-run the canonical audit, and prove unchanged deterministic-GREEN ContextualWisdomLab/Orgmetra#88@0dc4f09cc3c87829ea1e3a0e3dc0188df07ad8cd can take the ordinary protected merge path without synthetic approval or routine administrator bypass. Genuine failed/absent required workflows and unresolved required threads remain blocking.

Refs #772, #1176, #1340, #1351, #1669, #1728, #1731, #1734, ContextualWisdomLab/Orgmetra#89.

Summary by CodeRabbit

  • 새 기능

    • 저장소 및 조직 규칙 세트를 선언적으로 관리하고 자동 검증·조정하는 거버넌스 기능이 추가되었습니다.
    • PR, 기본 브랜치 변경, 예약 실행 시 규칙 세트 검증이 자동 수행됩니다.
    • 기본 브랜치 보호와 필수 워크플로 정책이 강화되었습니다.
    • 규칙 세트 변경 충돌과 일시적 API 오류를 안전하게 확인하고 복구합니다.
  • 문서

    • 필수 워크플로, 적용 범위, 검증 절차 및 운영 정책 문서가 최신화되었습니다.
  • 품질 개선

    • 누락·비정상 규칙, 잘못된 병합 방식과 설정을 더 정확히 감지합니다.
    • 검증 결과를 누적해 모든 검사를 완료한 뒤 오류를 보고합니다.

seonghobae and others added 30 commits August 21, 2026 03:21
# Conflicts:
#	scripts/ci/test_strix_quick_gate.sh
Merge protected main non-destructively while retaining only the create-transition audit and its executable regressions. Focused ruleset audit: 20 passed. Full suite: 1,402 passed, 1 skipped, 16 subtests.
Preserve only the two governance owner files over protected main 0c6b9a6. Focused ruleset audit: 20 passed. Full suite: 1,402 passed, 1 skipped, 16 subtests.

Copy link
Copy Markdown
Contributor Author

Wardnet consumer/control-plane handoff — fresh 2026-09-05 KST live state:

  • protected ContextualWisdomLab/wardnet main@5829a0f08d78de464dd24393ce5d0f25fba9d126 is currently governed by organization ruleset 18156473;
  • the live repo-view of that ruleset was updated 2026-09-04T21:34:39.804+09:00 but still reports required_approving_review_count=1, required_reviewers=[], require_code_owner_review=false, require_last_push_approval=false, and OrganizationAdmin/always routine bypass;
  • Wardnet auto-merge 대기 PR의 update-branch 처리 보강 #140 exact d28a0119d4708b535dc04763dd51a11c835dba45 remains a deterministic product canary but its CI/security lanes are separately non-passing at pre-checkout runner acquisition under .github#712, so it cannot yet prove the post-reconcile ordinary-merge GREEN;
  • this owner PR is now exact c94faa446774d012d684304fb0ac505d03e2f765 with GitHub-recorded base main@09ac6366ddd018fd0085368f4b669ba797fd0158, while current protected .github/main has advanced to f43dcb884be5a0efc61611b5c8cb83c4c7735995; GitHub currently reports fix(governance): automate ruleset owner-plane reconciliation #1644 non-mergeable.

RED remains live-settings drift plus stale/non-mergeable owner ancestry. Please adopt the intervening protected-main delta non-force, reacquire exact-head gates, then after protected source integration use the already-designed least-privilege reconciliation path to converge the live ruleset. GREEN for Wardnet remains: approval count 0 with no synthetic reviewer, routine bypass absent, deterministic workflow/security/thread/deletion/non-fast-forward controls preserved, followed by an unchanged exact Wardnet candidate completing all then-required gates and taking the ordinary protected merge path. No Wardnet source churn or self/model approval is needed for this owner-plane repair.

Copy link
Copy Markdown
Contributor Author

Fresh owner-plane revalidation: keep this PR as the canonical solo-maintainer reconciler, but it is not integration-ready and it must not be superseded by #1861's two-human policy.

Current head is c94faa446774d012d684304fb0ac505d03e2f765; protected .github/main is now f43dcb884be5a0efc61611b5c8cb83c4c7735995. Fresh compare is diverged, 132 behind / 237 ahead from merge base 09ac6366..., so first adopt protected-main deltas by non-force reconciliation and regenerate all exact-head evidence.

Three current blockers remain source-backed on this head: (1) the unresolved identical-external-write/ambiguous-recovery race in reconcile_ruleset_governance.py; (2) the unresolved canonical-auditor rejection of live code_scanning rule type, which can leave repository repair applied while organization repair is refused; and (3) current exact-head CodeQL is failing. The review summary also reports touched-function docstring coverage below the repository threshold, so do not claim release readiness until the live policy's docstring gate is met on the reconciled head.

#1861 currently asserts two approvals plus last-push approval. That conflicts with this reconciler's reviewed solo-maintainer contract (0 approvals, last-push false, no synthetic reviewer) and #772. Preserve any useful fail-fast audit ordering from #1861 only after expressing the expected values through this canonical policy; never apply the two-human expectation to live rules. Re-run full exact-head governance/security/coverage after reconciliation, resolve only verified findings, then use the protected owner-plane environment/token path to converge live rulesets.

Copy link
Copy Markdown
Contributor Author

Fresh Context Fabric owner-plane handoff (revalidated 2026-09-05 KST): the live PR metadata, not this PR body’s historical SHA prose, is authoritative. .github#1644 is still open/non-mergeable at exact head c94faa446774d012d684304fb0ac505d03e2f765. Protected .github/main has advanced to exact a01ffc1edee2e5fc9c56e4351f90a0ce4a75e77b (2026-09-05T09:06:47Z). Fresh compare main...#1644 is diverged, behind_by=161, ahead_by=237, merge base 09ac6366ddd018fd0085368f4b669ba797fd0158; the effective PR delta remains the governance reconciler/auditor/test/docs paths. Therefore all predecessor-head check/review claims are historical until the central owner non-force adopts current protected main and reacquires exact-head gates. Do not force-push, drop intervening protected-main work, or apply privileged ruleset mutation from the stale head.

The product-side RED is unchanged and was independently reread: both context-graph-contracts and enterprise-architecture-core still report default_branch=develop; CGC main@99cb5468ba3c15c5e79688f53dee74724fae2d13 remains unprotected, and organization ruleset 18156473 still targets ~DEFAULT_BRANCH with bare required_approving_review_count=1, required_reviewers=[], no code-owner/last-push approval requirement, plus routine OrganizationAdmin/always bypass. The central sequence remains: converge this owner PR on current protected .github/main -> obtain exact-head deterministic gates -> integrate normally -> run the separately authorized ruleset reconciliation -> prove approval count 0/no routine bypass while retaining machine/thread/branch-integrity controls -> pre-protect each Context Fabric main -> switch defaults -> reread effective ~DEFAULT_BRANCH -> hand fresh refs back for non-force CGC/EA stack reconstruction. No CGC/EA leaf workaround is justified.

Copy link
Copy Markdown
Contributor Author

Owner-plane freshness update: protected .github/main advanced again after the prior handoff and is now exact 7fcada597d5b79bdb14445f24322b2c9f6ed4b19 (merge of #1914, 2026-09-05T09:18:25Z). Live #1644 remains exact c94faa446774d012d684304fb0ac505d03e2f765, open/non-mergeable. Fresh main...#1644 compare is still diverged, now behind_by=168, ahead_by=237, same merge base 09ac6366ddd018fd0085368f4b669ba797fd0158; the effective delta remains the ruleset-governance reconciler/auditor/tests/docs paths. The central owner must therefore adopt the additional protected-main delta non-force before claiming any exact-head evidence or privileged reconciliation readiness. Do not force-update or reuse predecessor checks. Product evidence is unchanged: CGC/EA defaults remain develop, Context Fabric main is not yet the protected/default authority, and org ruleset 18156473 still carries bare approval count 1 plus routine OrganizationAdmin/always bypass. The previously recorded protect-main -> default-switch -> effective-ruleset-reread -> stack-rebuild sequence remains the correct causal order.

Copy link
Copy Markdown
Contributor Author

@jules Fresh owner-plane drift requires another non-destructive reconciliation before this ruleset repair can become protected truth. .github protected main is now exact f250638827f8252b0d9e5cb2601f4d333f96162f after #1922, while this PR remains Ready but non-mergeable at exact head c94faa446774d012d684304fb0ac505d03e2f765 and GitHub still records base SHA 09ac6366ddd018fd0085368f4b669ba797fd0158.

Please re-read all intervening protected-main deltas, then adopt/adapt them with a non-force merge/restack while preserving only this PR's still-valid ruleset-governance owner delta. Re-run the repository's deterministic governance/security/coverage/docstring/SBOM/provenance/thread gates on the resulting exact head. The intended live policy remains the solo-maintainer contract already encoded here: generic approval count 0, no synthetic human/model approval, stale-review dismissal + unresolved-thread/deletion/non-fast-forward controls retained, required workflows retained, and routine bypass actors removed. Do not weaken the newer #1922 scheduler/CI isolation or any later protected control-plane repair.

After source integration, the privileged settings apply still must verify exact protected source and live ruleset identity/history before mutation; source merge alone is not live-settings convergence.

The single conflict is two adjacent assertions, and the two lines resolve in
opposite directions — taking either side wholesale fails.

Line 1 — take main's. The surrounding test body (common to both sides after
the merge) duplicates `.github/workflows/security-scan.yml`, not
`scorecard-pr.yml`, so the duplicate-count assertion must name security-scan.
`scorecard-pr.yml` no longer exists in the merged tree at all.

Line 2 — take this branch's. `scripts/ci/audit_central_required_workflows.py`
emits "central solo-maintainer ruleset must not require approving reviews";
main's "exactly two approving reviews are not required" matches no string the
production code produces. The next (unconflicted) assertion in the same test
already reads "central solo-maintainer ruleset must not require last-push
approval", so this branch's wording is the one consistent with the module.

Both choices were determined from the merged tree's own fixture and production
strings, not from either branch's prior state.

Verified after resolution: 3044 passed, 1 skipped, coverage 100%,
interrogate 100%; zero conflict markers; `ruff check --select F821` clean.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Copy link
Copy Markdown
Contributor Author

Fresh owner-path canary from a writable leaf; no .github source/PR-state mutation requested from the fleet.

ContextualWisdomLab/xtrmLLMBatchPython#219 is open on protected develop@80096c8b8e21f288992b00d2db873d81208eba10, exact head b0c2e09b8ee90a8ce027a996d7c66d8550ebac4a. Its substantive dependency tree is unchanged from parent c6bc085de2d09fbfc25617c94189272c7bf4eac8; the one intervening commit is an old source-neutral chore(ci): refresh exact-head governance evidence from 2026-08-30 and GitHub compare reports zero changed files. Do not solve this by asking the leaf to push another no-op commit.

Leaf exact-head repository requirements are genuinely terminal GREEN: test, Bandit (Python SAST), pip-audit (Dependency Vulnerabilities), and PostgreSQL smoke all ran on b0c2e09... and succeeded. The only inline review thread is resolved. There is no qualifying APPROVED review.

Live organization ruleset 18156473 was re-read now and is still active with required_approving_review_count=1, dismiss_stale_reviews_on_push=true, thread resolution, and current required workflows OpenCode / merge scheduler / Security / Strix / SAST / Noema / CodeQL. Its updated_at is 2026-09-04, while this unchanged leaf head's workflow generation is from 2026-08-30 and predates the current Strix/Noema requirement set. This reproduces the owner-plane mismatch already described in #1644: the declared solo-maintainer target is approval count 0, but live inherited policy still requires 1.

Owner acceptance for #1644 should therefore include this unchanged leaf as a post-reconciliation canary in addition to Orgmetra:

  1. reconcile the live ruleset only through the protected owner-plane path and immutable-history safeguards already specified here; no Admin bypass or synthetic approval;
  2. prove the then-live policy matches the canonical solo-maintainer review count while retaining required thread/workflow protection;
  3. make the central scheduler/review path evaluate an unchanged, already-open pre-ruleset-update head under the current required-workflow set without a leaf source-neutral commit;
  4. require actual exact-head OpenCode/Strix/Noema/Security/SAST/CodeQL/scheduler evidence (or a typed owner failure), not predecessor/local-success substitution;
  5. once those gates are terminal, allow the leaf to progress through ordinary protected merge if no source/review finding remains.

This canary is useful because it separates leaf source correctness from both live ruleset drift and required-workflow generation/recovery. Please preserve that distinction in the owner RED/GREEN contract.

Copy link
Copy Markdown
Contributor Author

Fresh fleet owner-path correction after re-reading the dedicated writer lane; no .github source/ref/lifecycle mutation requested.

The PR body's Current exact stack block is stale relative to live GitHub authority. Fresh PR read reports:

Exact-head workflow inventory for f0c97210... is mixed rather than merge-ready: Ruleset Governance Reconcile 33966029070, SAST Semgrep 33966029025, Python Security 33966029075, and Security Scan 33966029047 are terminal success, but CodeQL PR 33966029195 is terminal failure. Its Detect job succeeded on a GitHub-hosted runner; both Python job 101320716759 and Actions job 101320716773 successfully completed Request current-head CodeQL scan dispatch and then failed at Release runner or enforce current-head CodeQL verdict. This is an owner/control-plane verdict-recovery failure shape, not evidence that #1644 itself is otherwise GREEN.

Please make the dedicated writer's next normal descendant/body reconciliation use the live f0c97210... generation and preserve the existing CodeQL owner path (#1902) rather than leaf/local workaround, dummy retrigger, or stale predecessor evidence transfer.

The unchanged xtrmLLMBatchPython#219@b0c2e09b8ee90a8ce027a996d7c66d8550ebac4a canary from the prior handoff remains useful after ruleset reconciliation: its source tree is unchanged from its substantive predecessor, its repository-local required checks are terminal GREEN, but its Aug-30 workflow generation predates the Sep-4 central workflow/ruleset update and it has no qualifying approval. Acceptance should still prove that an already-open unchanged old head can be evaluated under the then-current central required-workflow set without forcing another leaf no-op commit.

GREEN boundary: owner ruleset state matches canonical policy; #1644 exact current head has terminal owner security/CodeQL/review evidence; and the unchanged #219 canary obtains genuine current central workflow/verdict evidence (or a typed owner failure) under ordinary protected flow. No admin bypass, self-approval, source-neutral leaf churn, or predecessor-check substitution.

Copy link
Copy Markdown
Contributor Author

Fresh Context Fabric dependency handoff (2026-09-06 KST), no .github source mutation from this writer. Revalidated current owner state before any CGC/EA restack:

  • fix(governance): automate ruleset owner-plane reconciliation #1644 exact head remains f0c97210b127139cfef0b8dac08cb02966bd814e, Ready/mergeable.
  • Protected .github/main is now exact f2f91b806122ed233e3a0e2a325246077c2e15e4; fresh compare is diverged, behind_by=4, ahead_by=238, merge base f250638827f8252b0d9e5cb2601f4d333f96162f. Adopt those protected-main commits non-force and preserve only the governance delta; do not transfer current-head checks.
  • On current fix(governance): automate ruleset owner-plane reconciliation #1644 head, Ruleset Governance Reconcile 33966029070, SAST 33966029025, Python Security 33966029075, and Security Scan 33966029047 are terminal SUCCESS; CodeQL PR 33966029195 is terminal FAILURE. Repair that central dispatch/verdict failure before ordinary protected integration; no gate weakening or bypass.
  • Live org ruleset 18156473 remains required_approving_review_count=1, required_reviewers=[], no CODEOWNER/last-push approval, with required workflows/thread/deletion/non-FF retained and OrganizationAdmin/always bypass still present.
  • Direct product branch APIs still show CGC main@99cb5468... unprotected and EA product main@ca688949...; both repository defaults remain develop. Do not trigger Context Fabric default switching/restack until [Context Fabric governance] Protect and adopt main as the integration/default branch #1137 can prove actual main protection from live branch/ruleset state.

Owner GREEN remains: non-force adopt current protected main -> reacquire every exact-head central gate -> ordinary merge -> privileged live reconciliation from exact protected truth -> prove solo-compatible ruleset + routine bypass removal -> protect Context Fabric main refs -> then allow default switch and fresh product stack reconstruction.

Copy link
Copy Markdown
Contributor Author

Context Fabric owner-path RCA for the current exact head f0c97210b127139cfef0b8dac08cb02966bd814e: required CodeQL PR run 33966029195 is not a source/SARIF failure yet. Both compatibility shards dispatched successfully, then failed closed with VERDICT_STATE=pending. The corresponding repository-dispatch wake for .github#1644 (33975726260, validate job 101331959599) later acquired a hosted runner and failed before scan at Bind workflow inputs to live organization pull request metadata: DISPATCH_ACTOR=opencode-agent[bot], DISPATCH_SENDER=opencode-agent[bot], while ALLOWED_DISPATCH_ACTOR resolved to github-actions[bot]; the workflow rejected the event and skipped the scan. This is a central dispatch-authorization/control-plane defect, not runner acquisition and not a qualifying CodeQL verdict. Repair the trusted scheduler identity contract without broadening organization/repository scope or relaxing actor==sender binding, add/retain a regression that reproduces the real app-token dispatch identity, then rerun/revalidate the unchanged exact head. Do not treat run 33966029195 or either failed dispatch as passing evidence. This owner-path repair is prerequisite to #772/#1137 protected convergence for CGC/EA.

Copy link
Copy Markdown
Contributor Author

Fresh Context Fabric owner-plane revalidation on live head f0c97210b127139cfef0b8dac08cb02966bd814e; protected .github/main is now fe827e133e7d867015d088777553e22736344c55, so predecessor exact-head evidence must not transfer and the branch must first non-force adopt current protected-main deltas.

Two unresolved findings are still source-backed on this exact head and should be repaired test-first in this owner lane before privileged reconciliation:

  1. scripts/ci/reconcile_ruleset_governance.py::_settle_ambiguous_recovery_history() still terminates as soon as the newest history state's editable payload equals expected_payload. That cannot distinguish this timed-out recovery PUT from an identical external write that arrived first; the original delayed PUT can later land after a distinct administrator edit and overwrite it outside recovery. Preserve the full settlement horizon / immutable predecessor proof so payload equality alone cannot identify the original request, with the existing identical-write -> distinct-admin-write -> delayed-original regression.
  2. .github/workflows/ruleset-governance-reconcile.yml still has pull_request, push(main), and schedule but no workflow_dispatch, despite its own comments referring to manual runs. Restore a controlled manual trigger so the protected-environment owner path can run immediately after protected adoption instead of requiring a synthetic push or waiting for cron; retain the same main/ref/enable/environment/token guards.

The third unresolved code_scanning review should not be fixed mechanically: fresh live org ruleset 18156473 currently contains workflows/pull_request/deletion/non_fast_forward, not code_scanning. The current auditor still excludes code_scanning, so reconcile that thread against the intended canonical policy first; permit it only if central policy deliberately treats the deterministic scanning rule as valid.

Fresh live Context Fabric control evidence remains nonconverged: inherited org ruleset 18156473 still targets ~DEFAULT_BRANCH, has bare required_approving_review_count=1, required_reviewers=[], code-owner=false, last-push=false, and OrganizationAdmin/always bypass; CGC #21 exact 6a0d559a0e58037e84feb9daa666b6fd42363f0d and EA #40 exact 9cea817b15a92710e0677d30e5103965b58f0699 each still materialize zero Actions workflow runs. Keep those source heads Draft/non-passing; do not no-op retrigger or transfer predecessor GREEN.

After #1644 is repaired, non-force reconciled onto current protected main, exact-head gates/threads are clean, and normally integrated, use the existing protected owner-plane path to converge the impossible solo-maintainer rule without weakening deterministic checks. Then continue #1137's already-accepted protected-main -> default-main transition and re-read effective rulesets before reconstructing CGC/EA stacks.

Copy link
Copy Markdown
Contributor Author

@jules Fresh owner-path restack finding from Wardnet dependency sweep; please repair this lane rather than treating solo-governance as a user blocker.

Current protected .github/main is 43024633eba9d96b0456970391360da5a171fbda. #1644 remains exact f0c97210b127139cfef0b8dac08cb02966bd814e, and a fresh compare is status=diverged, ahead_by=238, behind_by=26. The PR body's protected-baseline/evidence narrative is therefore stale relative to 26 protected commits, including newer central control-plane work. Do not apply live rules from this stale branch and do not force-push/destructively rebase it.

Repair acceptance: read/adopt every intervening protected delta; non-force merge current protected main into the owner branch (or produce a verified successor carrying the complete unique ruleset-governance delta); preserve the canonical solo-maintainer policy of generic approval count 0/no synthetic reviewer/no routine bypass plus deterministic workflow/security/thread/non-fast-forward/deletion controls; rerun the focused governance/adversarial suites and every then-live exact-head gate; resolve any new current review findings. Only after ordinary protected integration should the privileged protected-main reconciler mutate live rules, followed by fresh ruleset reads proving convergence and an unchanged deterministic-clean product canary using ordinary protected admission without self/model approval or silent admin bypass.

Copy link
Copy Markdown
Contributor Author

Fresh Context Fabric owner handoff, 2026-09-06 KST. This governance implementation is no longer based on current protected central truth and its current CodeQL evidence must not be reused after reconciliation.

  • protected .github/main is now 0b0f10476469d52adc40f98495d50855486cd32f;
  • this PR remains exact f0c97210b127139cfef0b8dac08cb02966bd814e with merge base f250638827f8252b0d9e5cb2601f4d333f96162f;
  • fresh compare is diverged, behind_by=28, ahead_by=238;
  • current CodeQL PR 33966029195 is non-passing: detector acquired a hosted runner and completed exact checkout, while both compatibility jobs acquired runners, completed their current-head dispatch request, then failed at Release runner or enforce current-head CodeQL verdict.

The same post-runner dispatch/verdict failure now reproduces on CGC root context-graph-contracts#4@5117383ac15cdfe3813340455cd99b92937ef47c (CodeQL PR 34009096429, compatibility jobs 101428051612 and 101428051650).

Please adopt the 28 intervening protected-main commits by ordinary non-force merge/restack, audit their delta, and reacquire all exact-head checks on the resulting SHA. Do not force-rebase, transfer this head's GREENs, or treat the current CodeQL failure as leaf runner starvation. After reconciliation, the acceptance condition is an authenticated terminal current-head CodeQL dispatch/verdict plus the existing deterministic ruleset-governance gates.

@seonghobae

Copy link
Copy Markdown
Contributor Author

Stacked PR 검사 적용 범위의 신규 운영 증거를 이 canonical owner에 연결합니다. CO#1074 head239f894edb2b37f4c28430d1acecb5ab36eef712의 base codex/psychometric-kpi-successor에는 effective branch rules가 없습니다. 상속 조회된18156473은 active/~DEFAULT_BRANCH에7개workflow와승인·삭제·non-fast-forward규칙이혼합돼있습니다. 로컬검사trigger수리후제품quality run34039966047은생겼지만중앙required검사적용완료증거는아닙니다.

현재source audit_central_required_workflows.py의 stackowner21732164는 evaluate/ALL에서DEFAULT_BRANCH제외/OpenCode1개계약입니다. docs/org-required-workflow-rollout.md는 이를모든비기본branch에active로적용했을때생성·후속push가거부되어되돌린이력을기록합니다. 이번상속조회에서21732164가없고상세404였지만조직관리자조회권한이없어ruleset삭제로단정하지않습니다.

#1644현manifest/reconciler가승인규칙을전제하는기존2target만지원하므로workflow-onlytarget을단순추가하거나18156473전체조건을~ALL로확대하지않아야합니다. 기존관리자실행경로에서21732164현재payload를확인한뒤, 정상branch작성/후속수정을보존하는stack검사설계를별도로검증해야합니다. 단일OpenCodecanary는있더라도전체7개필수검사/조직전체완료를대체할수없습니다. 실제rulesetwrite·adminscope추가·권한확대는하지않았습니다.

Copy link
Copy Markdown
Contributor Author

Taking the existing #1644 branch as the single writer for the bounded Context Fabric P0 repair from exact head f0c97210b127139cfef0b8dac08cb02966bd814e onto protected main@6e014c9bae22f1e6d8302a4f1cc38f4f6a114ae2. Scope: ordinary non-force main adoption; preserve all 20 governance paths and intervening protected-main deltas; reproduce and minimally repair only the three current unresolved findings (ambiguous identical-write settlement, manual controlled-entry contract, and code_scanning audit acceptance); then exact-head focused/full validation and normal guarded push. No live ruleset/default-branch mutation, bypass, self-approval, force-push, consumer retrigger, or secret/principal change is included in this source-writing phase.

Adopt protected main@6e014c9bae22f1e6d8302a4f1cc38f4f6a114ae2 without dropping the ruleset governance owner delta.
Observe ambiguous recovery writes through the full settlement horizon, preserve a later administrator version after an identical external write, and accept an existing native code-scanning gate without weakening the managed ruleset contract.

Copy link
Copy Markdown
Contributor Author

Context Fabric owner-plane P0 execution receipt — exact head 825a7d56441c323a66254f5aadf2b26b625885c4.

  • Ordinary non-force ancestry adoption is explicit: merge commit 3605a088161b57371c642a1f0e6de741adc43582 has predecessor f0c97210b127139cfef0b8dac08cb02966bd814e and protected main@6e014c9bae22f1e6d8302a4f1cc38f4f6a114ae2 as parents.
  • Valid REDs were delayed identical-settlement overwrite and dropped native code_scanning preservation. The requested workflow_dispatch change was rejected after adopting current main because the protected security contract prohibits a branch-selected central manual entrypoint.
  • Minimal GREEN: observe the full ambiguous-write settlement horizon and follow the final immutable predecessor; admit code_scanning as a preserved native gate; keep trusted push/schedule + protected environment credential boundary unchanged.
  • Exact-tree validation: focused 185 passed; reconciler 396 statements / 154 branches = 100%; docstrings 100%; full 3117 passed, 1 skipped, 21 subtests; compile/diff clean.
  • All three addressed threads are resolved on the current conversation state. Fresh exact-head hosted evidence is still incomplete: Ruleset Governance Reconcile is successful; security/SAST/CodeQL lanes are queued. No predecessor evidence transfers.
  • No live ruleset/default-branch/protection mutation, bypass, self-approval, force update, consumer rerun, or secret invention was performed.

Source writer released. Any successor must fresh-fetch this exact head and protected main before writing.

Copy link
Copy Markdown
Contributor Author

Single-writer reacquired only because protected main advanced after the prior release. Scope: ordinary merge main@9aad23c09da468716a788cfed65cd44f7d84a284 into current #1644 head 825a7d56441c323a66254f5aadf2b26b625885c4, preserve the merged #1975 concurrency-parser test delta, and rerun focused/full exact-head verification before a guarded non-force update. No live settings, product refs, approvals, reruns, bypasses or force updates.

Ordinary two-parent adoption of protected main #1975 while preserving the ruleset governance P0 delta.

Copy link
Copy Markdown
Contributor Author

Latest-main ordinary-restack receipt — exact head 82ef13ac35e4046e2eafba68bd1650ffc32b3470.

  • Parents: predecessor 825a7d56441c323a66254f5aadf2b26b625885c4 and protected main@9aad23c09da468716a788cfed65cd44f7d84a284; exact tree 84e04fbc605e5a60b42ed21322e9bd8fd86d2fde.
  • Main's merged test(concurrency): assert the real group key and the real cancel flag #1975 changes only strengthen concurrency-contract parsing/tests and are preserved byte-for-byte.
  • Exact-head validation: combined focused 279 passed; owner focused 185 passed; reconciler statement/branch 100%; docstrings 100%; full 3120 passed, 1 skipped; diff clean.
  • The separate HOME=/tmp false fixture setup is recorded in the PR body; its exact five failures passed under the repository's normal isolated HOME=/root contract, followed by the full GREEN run.
  • Unresolved review threads at this fresh read: 0.
  • New exact-head hosted security/SAST/CodeQL/reconcile evidence is queued; predecessor evidence is not transferred. No merge, live apply, consumer rerun, bypass, self-approval or force update.

Source writer released again.

@seonghobae

Copy link
Copy Markdown
Contributor Author

Read-only adoption-boundary audit at exact head 82ef13a.

This PR is not by itself evidence that Naruon stacked PRs receive enforced central required checks:

  • scripts/ci/audit_central_required_workflows.py:272-327 explicitly accepts stacked ruleset 21732164 in evaluate mode, covering non-default branches and only the central OpenCode workflow. tests/test_central_required_workflow_ruleset_audit.py:85-94 and 400-462 exercise that evaluate-only contract; these are not enforcement acceptance tests.
  • config/ruleset-governance.json targets only 17921150 and 18156473, not 21732164. The central auditor at lines 157-163 requires default-branch-only scope. The reconciler preserves live conditions rather than adding stacked coverage.
  • scripts/ci/reconcile_ruleset_governance.py:498-501 sets required_approving_review_count=0, require_code_owner_review=False, require_last_push_approval=False and required_reviewers=[]. Applying this existing policy is materially different from repairing missing stacked workflow coverage. Pending operator policy/authority decisions must not be bypassed by invoking apply.
  • .github/workflows/ruleset-governance-reconcile.yml:135-181 contains the protected-main, enable-variable, protected-environment, dedicated administration credential, exact-revision and post-write verification path. Source presence does not prove credential provisioning or live convergence.

For the Naruon consumer gap, retain the current PRs and require a separately reviewed workflow-only stacked enforcement contract and tests in this canonical owner after the scope/authority decision. Do not broaden the mixed default-branch ruleset, reduce approvals, or copy consumer workflows as a shortcut. No settings, permissions, allowlists or source files were changed during this audit; tests were inspected, not executed. No current-head check or approval is asserted by this comment.

Copy link
Copy Markdown
Contributor Author

Single-writer reacquired because protected main advanced after the last release. Bounded scope: ordinary non-force merge of main@ad0779bee66624c3997947d7691f4b0dbb973be1 into current #1644 head 82ef13ac35e4046e2eafba68bd1650ffc32b3470; preserve #1973 scheduler conflict-admission delta byte-for-byte; rerun current-tree governance, scheduler, coverage/docstring, and full suites; refetch remote head/main before a guarded fast-forward branch update. No ruleset/default-branch/settings mutation, approval, bypass, force-push, or consumer rerun is in this source-writer claim.

Ordinary non-force adoption of protected main@ad0779bee66624c3997947d7691f4b0dbb973be1. Preserve #1973 scheduler conflict-admission changes byte-for-byte while retaining all #1644 governance reconciliation semantics.

Exact-tree verification: 582 focused tests; governance 185 tests; reconciler 396 statements / 154 branches at 100%; docstrings 100%; full suite 3124 passed, 1 skipped, 21 subtests. The first full invocation exposed only an unseeded local uv virtualenv missing pip; after matching hosted setup-python's pip presence, the exact failing test and full suite passed without source changes.

Copy link
Copy Markdown
Contributor Author

Latest protected-main adoption receipt — exact head 4556483380bf7e7770bfc5e8c1094ce3350134ed.

  • Ordinary two-parent commit preserves predecessor 82ef13ac35e4046e2eafba68bd1650ffc32b3470 and protected main@ad0779bee66624c3997947d7691f4b0dbb973be1; exact tree 4195f8a8a6d77a252650a90fa6ca804c411afceb.
  • Main's fix(scheduler): skip review dispatch when the merge tree cannot materialize #1973 scheduler delta is retained byte-for-byte: scripts/ci/pr_review_merge_scheduler_core.py blob cffb52cb…, tests/test_pr_review_merge_scheduler.py blob 8b924291….
  • Exact-tree GREEN: governance+merge-scheduler focused 582 passed; governance focused 185 passed; reconciler 396 statements / 154 branches = 100%; interrogate 100%; full 3124 passed, 1 skipped, 21 subtests; diff check clean.
  • The first full invocation exposed a local execution-fixture mismatch only: the newly created uv venv had no pip, whereas hosted setup-python does. After seeding pip, the exact failing materializer test and unchanged full tree passed. No source change, suppression, or gate weakening was used.
  • Fresh remote readback: head/base/main match the SHAs above, mergeable source tree, unresolved threads 0, approvals 0; new hosted evidence is 12 queued, 1 in_progress, 2 skipped and does not inherit predecessor evidence.

Source writer released. Do not merge or execute live settings reconciliation until this unchanged exact head has terminal required security/CodeQL/reconcile/SBOM/provenance/review evidence and the ordinary protected path is available. No settings, ruleset, default-branch, branch-protection, principal allowlist, consumer head, or run was mutated.

Copy link
Copy Markdown
Contributor Author

SOURCE WRITER CLAIM — protected main advanced to 49eb9e7035a6994fffb5b24bf943156be27a02fb after the prior writer release. I am resuming this existing owner branch only, will ordinary-merge that protected tip without force or delta loss, re-run exact-tree focused/full validation, then advance the existing ref only after a fresh head/base compare. No settings/apply/merge action is included in this claim.

Copy link
Copy Markdown
Contributor Author

SOURCE WRITER RELEASE — exact head 8d0c3e7de921c4e45ebc022b1e035c7f5c1e52fb now ordinarily adopts protected main@49eb9e7035a6994fffb5b24bf943156be27a02fb with parents 4556483380bf7e7770bfc5e8c1094ce3350134ed and 49eb9e7035a6994fffb5b24bf943156be27a02fb; exact tree 14b9a3170fa61391b9a4d949184ea7ab0df2ff56. Exact-tree evidence: focused governance/scheduler/main-delta 813 passed; reconciler 396 statements / 154 branches = 100%; docstrings 100%; full 3124 passed, 1 skipped, 21 subtests; diff check clean. #1979's 13 test-only cancel-in-progress contract deltas are preserved. No predecessor hosted evidence transfers; no live ruleset/default-branch/protection/Actions-variable/security setting was changed. Fresh exact-head hosted gates and current-head review remain required before ordinary merge.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: ci-cd CI, GitHub Actions, checks, release, or supply chain bug Something isn't working priority: high High-priority or P1 work status: needs-review Open pull request requiring current-head review or checks type: bug Defect or incorrect behavior

Projects

Status: In Progress

Development

Successfully merging this pull request may close these issues.

2 participants