Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
144 commits
Select commit Hold shift + click to select a range
4c62031
test(codeql): reproduce rerun dead-end after pre-runner cancellation
seonghobae Sep 5, 2026
fabc998
fix(codeql): recover reruns with no dispatch verdict
seonghobae Sep 5, 2026
e47de34
docs(codeql): trace pre-runner rerun recovery evidence
seonghobae Sep 5, 2026
db15e4c
chore(codeql): restack rerun recovery on protected main
seonghobae Sep 5, 2026
9691960
chore(codeql): adopt latest verification guidance without force restack
seonghobae Sep 5, 2026
67a6bc9
docs(codeql): align ADR with evidence-driven rerun recovery
seonghobae Sep 5, 2026
510e337
merge(main): adopt concurrent CI governance deltas
seonghobae Sep 5, 2026
0599331
chore(codeql): adopt latest protected main
seonghobae Sep 5, 2026
2d4624a
chore(codeql): adopt protected main into rerun recovery
seonghobae Sep 5, 2026
e72ae30
chore(codeql): adopt current protected main
seonghobae Sep 6, 2026
acfa17e
test(codeql): require complete status pagination before redispatch
seonghobae Sep 6, 2026
7628274
fix(codeql): inspect complete status history before redispatch
seonghobae Sep 6, 2026
622ea74
docs(codeql): record complete status-history recovery guard
seonghobae Sep 6, 2026
bf732f9
test(codeql): exercise paginated empty-verdict recovery
seonghobae Sep 6, 2026
eb9d4d2
chore(codeql): merge current main into PR 1902
seonghobae Sep 6, 2026
4bf80b9
test(codeql): align verdict fixtures with paginated status reads
seonghobae Sep 6, 2026
951d0ec
fix(scheduler): require explicit open live PR identity
seonghobae Sep 6, 2026
9bfe575
fix(scheduler): bind Strix reruns to verified job identity
seonghobae Sep 6, 2026
fe64f24
test(ci): cover remaining Strix rerun identity rejections
seonghobae Sep 6, 2026
3549de5
chore(codeql): isolate rerun recovery on current protected main
seonghobae Sep 6, 2026
b966f82
fix(codeql): require preserved SARIF before terminal publication
seonghobae Sep 7, 2026
8c11d86
fix(codeql): verify live base before consuming terminal verdicts
seonghobae Sep 7, 2026
3d8a8b6
test(codeql): bind rerun recovery fixture to live base
seonghobae Sep 7, 2026
82ca0b8
fix(codeql): require preserved SARIF before status
seonghobae Sep 7, 2026
8c4fd55
merge(codeql): integrate canonical SARIF publication guard
seonghobae Sep 7, 2026
1a5957b
fix(codeql): bind terminal verdict receipt to base
seonghobae Sep 7, 2026
4b025af
test(codeql): prove old-base receipt redispatch
seonghobae Sep 7, 2026
8cc62ce
test(scheduler): reproduce central Actions credential leakage
seonghobae Sep 7, 2026
7bf3451
fix(scheduler): scope Actions credentials by run host
seonghobae Sep 7, 2026
ebcc671
test(scheduler): reproduce workflow-token mutation fallback
seonghobae Sep 7, 2026
e2204ee
fix(scheduler): prove workflow-starting mutation token
seonghobae Sep 7, 2026
890bac2
test(ci): reproduce missing stacked Python and runtime checks
seonghobae Sep 7, 2026
14f7c85
fix(ci): cover stacked Python and runtime reviews
seonghobae Sep 7, 2026
51c9df5
fix(codeql): settle exact multi-language reruns
seonghobae Sep 8, 2026
a7ff488
Merge protected main into scheduler repair stack
seonghobae Sep 8, 2026
8842c44
Merge updated scheduler stack parent into #2003
seonghobae Sep 8, 2026
f6b6a4a
Merge updated scheduler stack parent into #2004
seonghobae Sep 8, 2026
b18b7ca
test(scheduler): align cancellation doubles with host-scoped runner
seonghobae Sep 8, 2026
7f32c68
test(scheduler): prove workflow-starting credentials in fixtures
seonghobae Sep 8, 2026
71e7678
Merge updated #2002 test contract into #2003
seonghobae Sep 8, 2026
9fb02c9
Merge updated #2003 scheduler fixture contract into #2004
seonghobae Sep 8, 2026
b9b98cf
fix(codeql): bind self-status to exact handler evidence
seonghobae Sep 8, 2026
3349848
fix(codeql): harden self-repository fallback provenance
seonghobae Sep 8, 2026
23cc2df
test(codeql): reject HTTP-successful untrusted status creator
seonghobae Sep 8, 2026
af8334e
fix(codeql): authenticate published status creator
seonghobae Sep 8, 2026
c1351dc
test(codeql): return authenticated status creators in fixtures
seonghobae Sep 8, 2026
61b88b8
merge(main): replace unauthenticated CodeQL fallback with provenance …
seonghobae Sep 8, 2026
1a3133f
fix(codeql): bind exact dispatch settlement evidence
seonghobae Sep 8, 2026
e25800f
test(codeql): reproduce mixed-verdict settlement gap
seonghobae Sep 8, 2026
ef5ef47
fix(codeql): retain complete mixed-verdict settlement identity
seonghobae Sep 8, 2026
86898d3
test(codeql): require complete direct-evidence pagination
seonghobae Sep 8, 2026
df35cfe
fix(codeql): paginate direct settlement evidence
seonghobae Sep 8, 2026
211b763
fix(test): repair CodeQL pagination shim syntax
seonghobae Sep 8, 2026
0764ac2
fix(test): repair CodeQL settlement shim syntax
seonghobae Sep 8, 2026
4da013b
fix(codeql): integrate complete producer evidence
seonghobae Sep 8, 2026
49fd5fe
fix(codeql): preserve producer source across handler advances
seonghobae Sep 8, 2026
ccd4dd3
fix(codeql): select the unique evidence-complete handler
seonghobae Sep 8, 2026
e9589ed
test(codeql): prove App receipts require producer evidence
seonghobae Sep 8, 2026
e9c69e1
fix(codeql): authenticate App receipts with dispatch evidence
seonghobae Sep 8, 2026
3ca05c3
test(codeql): bind App receipts to exact evidence
seonghobae Sep 8, 2026
e07e8fd
fix(codeql): recover live base and reject receipt ambiguity
seonghobae Sep 8, 2026
723d1c3
test(codeql): complete successor evidence fixtures
seonghobae Sep 8, 2026
48baf18
test(codeql): reproduce stale-base and receipt ambiguity cycles
seonghobae Sep 8, 2026
2b60f0e
fix(codeql): converge mixed handler settlement
seonghobae Sep 8, 2026
855f017
fix(codeql): integrate live-base and receipt ambiguity repair
seonghobae Sep 8, 2026
0a1ebb1
fix(codeql): wake required jobs with the exchanged target app token
seonghobae Sep 8, 2026
87228f9
fix(codeql): reconcile attempt-wide base settlement
seonghobae Sep 8, 2026
afc477c
test(codeql): cover denied wake credential fallback
seonghobae Sep 8, 2026
b75ab70
fix(codeql): retry wake with configured credentials
seonghobae Sep 8, 2026
459af0c
fix(codeql): try every wake credential before succeeding a clean scan
seonghobae Sep 8, 2026
7ca416e
fix(codeql): require predecessor language-gate evidence
seonghobae Sep 8, 2026
eacf5e1
test(codeql): cover wake read credential fallback
seonghobae Sep 8, 2026
ba1781a
fix(codeql): retry wake identity reads
seonghobae Sep 8, 2026
1a863ac
merge: integrate remote wake credential retry
seonghobae Sep 8, 2026
c035e48
merge: integrate remote wake identity-read retry history
seonghobae Sep 8, 2026
11f4bd9
fix(codeql): keep post_wake for rerun and retry identity reads
seonghobae Sep 8, 2026
ebf054e
fix(codeql): recover attempt after base advance
seonghobae Sep 8, 2026
acea6d9
test(codeql): require dispatch validation for App receipts
seonghobae Sep 8, 2026
27fdc97
fix(codeql): authenticate App dispatch validation
seonghobae Sep 8, 2026
fe8b73e
docs(codeql): bind validation RED to published commit
seonghobae Sep 8, 2026
b924580
test(codeql): reproduce late base-advance deadlock
seonghobae Sep 8, 2026
3c8da48
fix(codeql): recover forward base advance during handler scan
seonghobae Sep 8, 2026
4566b15
fix(codeql): bound terminal recovery
seonghobae Sep 8, 2026
e092426
fix(codeql): report ambiguous evidence
seonghobae Sep 8, 2026
310e9e6
test(codeql): expose dispatch payload limit
seonghobae Sep 8, 2026
e28d7c6
fix(codeql): accept bounded rerun request payload
seonghobae Sep 8, 2026
80c139c
fix(codeql): bound repository dispatch payload
seonghobae Sep 8, 2026
2117695
test(codeql): bind nested rerun request
seonghobae Sep 8, 2026
da98bdc
test(codeql): require nested rerun payload parsing
seonghobae Sep 8, 2026
f0562e8
docs(codeql): record dispatch payload RCA
seonghobae Sep 8, 2026
9307973
docs(codeql): bind payload limit evidence
seonghobae Sep 8, 2026
ff2f7ab
test(codeql): fail when clean scan cannot wake exact shard
seonghobae Sep 8, 2026
aed803d
test(codeql): close receipt review gaps
seonghobae Sep 8, 2026
e17d1e7
fix(codeql): fail closed when exact shard wake is not accepted
seonghobae Sep 8, 2026
e7f893a
test(codeql): require versioned dispatch head envelope
seonghobae Sep 8, 2026
e99cce8
fix(codeql): accept versioned dispatch head envelope
seonghobae Sep 8, 2026
57b944e
test(codeql): reject unversioned head envelope
seonghobae Sep 8, 2026
4955a8b
fix(codeql): require head envelope schema
seonghobae Sep 8, 2026
0caa75a
test: execute versioned codeql head envelope
seonghobae Sep 8, 2026
5e65ab5
test(codeql): execute versioned head envelope path
seonghobae Sep 8, 2026
77c3dcb
test: reject non-string CodeQL head schema
seonghobae Sep 8, 2026
7cab524
fix: validate CodeQL head envelope types
seonghobae Sep 8, 2026
1ed0ca8
test(codeql): expose cross-channel producer ambiguity
seonghobae Sep 8, 2026
9b84832
fix(codeql): unify authenticated verdict evidence
seonghobae Sep 8, 2026
da1cbe5
test(codeql): expose wake credential shadowing
seonghobae Sep 8, 2026
8cb0a28
fix(codeql): preserve wake credential fallback
seonghobae Sep 8, 2026
2f3ff51
docs(codeql): bind verdict and wake evidence
seonghobae Sep 8, 2026
5761a2b
test(codeql): require nested rerun envelope compatibility
seonghobae Sep 8, 2026
7fe4300
merge: preserve CodeQL envelope base repair
seonghobae Sep 8, 2026
060597a
test(codeql): restore exact tree and expose cross-channel ambiguity
seonghobae Sep 8, 2026
631ccfc
fix(codeql): unify authenticated verdict evidence
seonghobae Sep 8, 2026
be87023
test(codeql): expose wake credential shadowing
seonghobae Sep 8, 2026
5e95eb0
fix(codeql): accept nested rerun request envelope
seonghobae Sep 8, 2026
3762301
fix(codeql): preserve wake credential fallback
seonghobae Sep 8, 2026
d116229
fix: preserve missing-schema rejection contract
seonghobae Sep 8, 2026
9f06558
docs(codeql): bind verdict and wake evidence
seonghobae Sep 8, 2026
1eaf07d
test(codeql): require one attempt settlement owner
seonghobae Sep 8, 2026
057ef77
docs(gap): bind strict CodeQL envelope evidence
seonghobae Sep 8, 2026
4876772
fix(codeql): settle dispatch wake once per attempt
seonghobae Sep 8, 2026
dd2796d
test(codeql): reject conflicting rerun representations
seonghobae Sep 8, 2026
57c8143
fix(codeql): reject conflicting rerun identities
seonghobae Sep 8, 2026
e0800ad
test(codeql): require source-bound settlement evidence
seonghobae Sep 8, 2026
d93a78a
fix(codeql): bind run-wide settlement evidence
seonghobae Sep 8, 2026
5043c17
merge: stack CodeQL wake repair on head envelope
seonghobae Sep 8, 2026
79a7b35
test(codeql): reject malformed head envelopes
seonghobae Sep 8, 2026
0fb9151
fix(codeql): validate original head envelope
seonghobae Sep 8, 2026
7f0615b
test(codeql): reject conflicting head identities
seonghobae Sep 8, 2026
4434a5d
fix(codeql): reject conflicting head identities
seonghobae Sep 8, 2026
bfca56f
docs(gap): bind dual head identity evidence
seonghobae Sep 8, 2026
3720dd8
merge: reconcile strict CodeQL head identity
seonghobae Sep 8, 2026
2b5b9a9
merge: carry strict head envelope into wake repair
seonghobae Sep 8, 2026
e930551
test(codeql): bind producer merge provenance and dual head identity
seonghobae Sep 8, 2026
5c30993
fix(codeql): verify live producer merge provenance
seonghobae Sep 8, 2026
45ef97c
merge: stack head envelope on review trigger repair
seonghobae Sep 8, 2026
9054b5e
merge: preserve stacked check admission after provenance repair
seonghobae Sep 8, 2026
940242d
test(codeql): require full failed-job rerun matrix
seonghobae Sep 8, 2026
c8d7caa
fix(codeql): bind rerun matrix to failed job set
seonghobae Sep 8, 2026
a22dd5b
test(codeql): pin every identity and credential invariant
seonghobae Sep 8, 2026
72d71b0
test(codeql): reproduce stale status publication cycle
seonghobae Sep 8, 2026
d4a9563
fix(codeql): retire superseded status publication
seonghobae Sep 8, 2026
6901dd6
test(codeql): reject head-only status migration bridge
seonghobae Sep 8, 2026
d7bb95f
fix(codeql): require base-bound authenticated receipts
seonghobae Sep 8, 2026
91a94a2
fix(codeql): authenticate protected handler evidence
seonghobae Sep 8, 2026
6706c23
fix(codeql): bridge protected handler rollout
seonghobae Sep 8, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/agent-review-runtime-quality-ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@ name: Agent Review Runtime Quality CI

on:
pull_request:
branches: [main]
# Scan every PR base ref, including stacked feature branches.
paths:
- ".github/workflows/agent-review-runtime-quality-ci.yml"
- ".github/workflows/noema-review.yml"
Expand Down
596 changes: 508 additions & 88 deletions .github/workflows/codeql-pr.yml

Large diffs are not rendered by default.

433 changes: 377 additions & 56 deletions .github/workflows/codeql-scan-dispatch.yml

Large diffs are not rendered by default.

1 change: 1 addition & 0 deletions .github/workflows/pr-review-merge-scheduler.yml
Original file line number Diff line number Diff line change
Expand Up @@ -496,6 +496,7 @@ jobs:
SCHEDULER_DISPATCH_TOKEN: ${{ github.token }}
SCHEDULER_READ_TOKEN: ${{ github.event_name == 'repository_dispatch' && github.event.client_payload.target_repository != '' && github.event.client_payload.target_repository != github.repository && (secrets.PR_REVIEW_MERGE_TOKEN || secrets.OPENCODE_APPROVE_TOKEN || steps.scheduler_app_token.outputs.token) || github.token }}
SCHEDULER_MUTATION_TOKEN_SOURCE: ${{ secrets.PR_REVIEW_MERGE_TOKEN != '' && 'PR_REVIEW_MERGE_TOKEN' || secrets.OPENCODE_APPROVE_TOKEN != '' && 'OPENCODE_APPROVE_TOKEN' || steps.scheduler_app_token.outputs.available == 'true' && 'opencode-app' || 'github-token' }}
SCHEDULER_WORKFLOW_TOKEN: ${{ github.token }}
SCHEDULER_REQUIRED_WORKFLOW_REPOSITORY: ContextualWisdomLab/.github
SCHEDULER_ALLOW_CROSS_REPO_REPOSITORY_DISPATCH: ${{ (secrets.PR_REVIEW_MERGE_TOKEN != '' || secrets.OPENCODE_APPROVE_TOKEN != '') && 'true' || 'false' }}
run: |
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/python-security.yml
Original file line number Diff line number Diff line change
Expand Up @@ -24,8 +24,8 @@ name: Python Security

on:
pull_request:
# Scan every PR base ref, including stacked feature branches.
types: [opened, synchronize, reopened, ready_for_review, closed]
branches: [main, master, develop]
push:
branches: [main, master, develop]
# Periodic full-repo coverage so non-PR drift is caught (the removed local
Expand Down
40 changes: 40 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,16 @@
### Stale-review cleanup revalidates through the run host credential

- The destructive-boundary refresh for an active review run now uses the same repository-scoped Actions credential selector as its later cancellation. A denied target-repository read token therefore cannot preserve a stale central `.github` run and suppress current-head dispatch when the central dispatch credential can still authenticate that run.
- The stacked-PR security workflow contract now rejects both `branches` and `branches-ignore` filters, closing the remaining test false-negative that could let a feature-base filter suppress required PR coverage.

### CodeQL dispatch uses one run-wide settlement owner

- The producer now keeps `failed`-mode dispatches wire-compatible with the protected pre-cutover handler by sending the complete top-level `required_jobs` map; only the new `all` mode uses `rerun_request:{mode,required_jobs}`. Each payload still has exactly one rerun authority and stays within GitHub's ten-property limit. This repairs handler run `34249932036`, where the protected handler observed `SUPPLIED_REQUIRED_JOBS: null` from #2040's nested-only payload. Refs #2040, #1902.
- Direct-evidence consumers now authenticate a `repository_dispatch` handler source against protected `.github/main`, accepting the exact protected tip or a still-reachable ancestor. They no longer require the target PR's synthetic merge revision to be an ancestor of the handler: GitHub runs those events from different refs and, for product repositories, different histories. Exact target base/head/run/producer provenance remains bound independently in the handler title, payload validation, gate, and SARIF artifact. Refs #2040, #1902.
- A native scan that becomes superseded between initial validation and its privileged scan no longer publishes an `error` status to the unchanged current head: status publication now requires the second live-metadata check and SARIF preservation to succeed, verifies the returned status creator, and emits only `codeql-dispatch/<language>/<base_sha>`. The evidence-complete #1902 producer is integrated into the same successor, eliminating the unsafe head-only compatibility context and its circular rollout. Exact evidence: handler run `34235814716`. Refs #2040, #1902.
- Producer provenance is now bound to GitHub's live synthetic pull-request merge revision rather than to an unrelated ancestry relation with the protected handler workflow. The handler requires `producer_source_sha == pull_request.merge_commit_sha`, fetches that immutable commit, and verifies its two ordered parents are the live base and head SHAs. Raw `pr_head` JSON is also type-checked and must agree with independently extracted legacy scalars, so numeric schema coercion and nested-field shadowing fail closed. Refs #2040, #2044, #1902.
- The handler accepts either the legacy top-level rerun fields or #1902's bounded `rerun_request:{mode,required_jobs}` envelope, rejects conflicting or malformed dual authority, and normalizes both to one validated mode/job map. Matrix scans now hold only `actions: read`; after every language has a terminal gate and an exact unexpired SARIF artifact, one non-matrix job revalidates the live PR/base/head and every required job before one run-wide `/rerun-failed-jobs` (`failed`) or `/rerun` (`all`) request. A partial matrix cannot authorize waking an unscanned required language; #1902 must send the complete rerun map as its matrix after this handler lands. This removes the observed race where the first job-level rerun moved the shared workflow and the second received HTTP 403. The sole settlement owner preserves the target App → `PR_REVIEW_MERGE_TOKEN` → `OPENCODE_APPROVE_TOKEN` → same-repository `github.token` fallback chain and fails closed if no request is accepted. Refs #2040, #1902, #1999, #2028, naruon#1592.

### Failed-check finding names the Strix sandbox instead of the gateway

- `opencode-review-dispatch.yml`'s `emit_strix_provider_failure_finding` rendered one fixed finding for every `STRIX_PROVIDER_UNAVAILABLE` line, whose Root cause read "The contextual-orchestrator gateway or its discovered provider pool was unavailable for this run". `#1953` had just given the Strix sandbox bootstrap failure its own second verdict token (`STRIX_SANDBOX_UNAVAILABLE`) precisely because that attribution is wrong for it -- the sandbox container never reaches its Caido proxy, so the run dies before the gateway serves anything -- and this consumer re-applied the wrong attribution one step downstream, into the review findings and the failure census. The emitter now branches on the second token: a sandbox verdict gets a finding that names Strix's sandbox, says the verdict does not name the gateway, and tells the reader not to change gateway or provider configuration on its strength. A `STRIX_PROVIDER_UNAVAILABLE` line without the token keeps its existing text verbatim, so the gateway class has no regression surface. No test covered this finding text at all before (`gateway or its discovered provider pool` matched nothing under `tests/`); `tests/test_opencode_dispatch_strix_sandbox_finding.py` now runs the production emitter from the published run block and pins both directions plus the no-signal case. Refs #1953, #1935.
Expand Down Expand Up @@ -68,6 +81,13 @@
- Raised `hourly-review-repair.yml`'s discovery ceiling from 50 to 200 while rotating deterministic 50-PR deep-inspection windows by hourly run number. The scheduler hydrates only the selected window and stops immediately after its single dispatch, preserving access to newer PRs without quadrupling expensive review/check/comment work. See `docs/doctoring/hourly-review-repair-single-file-consolidation.md`'s 2026-09-03 follow-up.

## [Unreleased]
- Accept a versioned `pr_head` object (`schema`, `ref`, and `sha`) in the
central CodeQL scan-dispatch handler while retaining the legacy
`pr_head_ref`/`pr_head_sha` fallback for already-queued callers. This is the
backward-compatible handler prerequisite for moving the producer below
GitHub's ten-top-level-property `repository_dispatch.client_payload` limit;
missing or unknown envelope versions fail closed before pull-request metadata
is used.
- Include merge-scheduler entrypoint, core, and regression-test changes in
the existing runtime-quality workflow's trigger and suite selector. Scheduler
workflow edits retain queue checks and also select the full review-repair
Expand Down Expand Up @@ -160,6 +180,26 @@

# Changelog

## Proposed

- Run Python Security and Agent Review Runtime Quality CI for stacked pull
requests by removing their pull-request base-branch filters. Extend the
permanent stacked-workflow contract so all four owner review workflows
continue covering feature-branch bases.

- Prove that the scheduler's selected head-mutation credential is present and
distinct from the workflow `github.token`, even when its declared source is
allowlisted. Missing comparison evidence and same-token fallback now fail
closed, and later operator guidance renders from the immutable recorded
decision rather than re-reading mutable environment state.

- Route scheduler Actions inventory and force-cancellation through the credential
scoped to the repository hosting each run. Central required-workflow runs use
the receiving repository runner token; target runs retain the explicit
cross-repository Actions token. This prevents an exhausted mutation App quota
from blocking current-head review admission while preserving fail-closed
cross-repository authority.

- **Consolidate current-head queue coalescing into the merge scheduler.** The standalone `Current Head Run Coalescer` duplicated one runner admission for every central pull-request event. Its exact-head worker now runs inside the already-required merge-scheduler job after immutable trusted-source materialization, preserving fail-closed PR/head/base revalidation while deleting the redundant workflow job.

All notable changes to the organization automation repository are documented in
Expand Down
Loading
Loading