fix(runtime): gate Draft admission and sandbox evidence - #2109
seonghobae wants to merge 40 commits into
Conversation
Preserve an existing command, timeout, or copy-rejection exit code when trusted evidence publication fails. A successful command whose evidence cannot be written still returns 125. Adds RED/GREEN coverage for child exit 2, explicit exit 124, and timeout 124 collisions.
📝 WalkthroughWalkthrough샌드박스 검증 도구가 바이너리 출력과 결과 envelope을 별도 파일로 기록합니다. 관련 CI 계약을 추가합니다. Draft PR의 주요 보안·품질 작업을 건너뛰고 Changes샌드박스 증거 및 Draft PR 입장 제어
Priority: ➖ Normal Estimated code review effort: 4 (Complex) | ~45 minutes Change: Bug fix Merge Risk: 🟡 Moderate · up to The new workflow contract test fails due to an incorrect job name, so this should be corrected before merge. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 77.27% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 66 functions across 4 files. (9 skipped: 9 unsupported.)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Ordinary two-parent integration of protected main@fb17ef556f94f673234aa557254ae52779e9a7b0. Preserve the four-path sandbox result handoff delta while carrying every concurrent protected-main change.
seonghobae
left a comment
There was a problem hiding this comment.
Exact-head review for 2df3dbbd4c2a59046da961f2c4d5f95f9331b063 (ce065f879d1d1b34b087bc9ae6f51dc9cae0cbbe): reviewed the nine-file delta and the Draft canary follow-up. The independent Security Scan gitleaks admission is now covered by RED de7c1ca99b399e50fa98af81467f2765902eb9c2 and guarded at GREEN head. Focused security/queue contracts: 9 passed; full suite: 3040 passed, 1 skipped, 36 subtests; compileall and diff check clean. All five exact-head Draft workflow runs completed skipped, including Security Scan 34689809757. No additional substantive finding in this pass. This COMMENT is not approval or merge authority.
|
@opencode-agent Review exact head |
|
P1 lifecycle repair integrated at exact head Root cause: RED |
Flush wrapper-owned text diagnostics before writing command bytes through the binary buffer. Clarify that all command bytes are preserved, document internal_error, and bound cleanup guarantees to the absence of --keep-sandbox. Adds a RED/GREEN ordering contract for redirected streams.
|
Successor carryover verified at exact head |
seonghobae
left a comment
There was a problem hiding this comment.
Exact-head review for 0c0e73d9ea8aaa80cfe5addee6dd6f2d397d3660 / tree 15c4d1d7a0bcfad86290af1dc1d5dc44b974ef2a: reviewed the complete nine-file delta and non-force concurrent integration. RED→GREEN now covers the independent Gitleaks Draft path and Runtime Quality ready_for_review re-entry. Exact-tree focused contracts: 10 passed; full suite: 3041 passed, 1 skipped, 36 subtests; compileall and diff check clean. Hosted lifecycle canary shows five Draft runs skipped and five Ready runs created at the unchanged head. No additional substantive finding in this pass. This COMMENT is not approval or merge authority.
|
@opencode-agent Review current exact head |
|
Exact-head hosted canary update for
The Draft-generation canary remains five completed |
|
Ready review admission is now open at unchanged exact head The lifecycle proof is exact-head and same-SHA:
Ready means review/check admission, not approval or merge readiness. All five runs are queued/pending and there is no qualifying independent current-head approval; no rerun, bypass, self-approval, Force Push, or merge was used. |
|
Exact-head admission audit — Ready 상태와 충돌하는 실질 blocker를 확인했습니다: latest opencode-agent state is CHANGES_REQUESTED. Commit, review, thread와 유효 delta를 보존하며 이 PR을 Draft/Proposed로 전환합니다. blocker가 exact current head에서 해소되고 hosted evidence가 terminal-valid해지면 Ready review admission을 재평가합니다. 이는 Close, review dismissal, synthetic status/approval, manual rerun, bypass, Force Push 또는 history rewrite가 아닙니다. |
New required-workflow concurrency finding from #2278This lane already owns the five heavy required workflows' PR lifecycle/admission and explicitly preserves PR-keyed concurrency. Fresh #2278 evidence shows that preservation is incomplete under runner backlog, so this belongs here rather than in the dependency PR or OriginWeave. Exact specimen:
Protected The REST evidence does not expose the actor/reason for each exact cancellation, so do not encode a test that assumes Please extend the #2109 RED/GREEN contract rather than preserving PR-keyed Acceptance for this owner delta should include all five required workflows: delayed predecessor cannot evict current-head evidence; same-head lifecycle cancellation (Ready→Draft) still works; closed/superseded heads are retired; the sole current-head run is never selected for cleanup; malformed/missing run-to-PR head identity fails closed; and no leaf repo needs a no-op wake commit, runner-label change, blind rerun, or protection bypass. Canonical queue-health issue #712 has the same exact specimen. #2278 is now frozen against further blind reruns pending this owner repair. |
Fresh stacked-base canary from the live CodeQL owner chainCurrent protected
This is not a new #2275 source defect and does not justify a leaf workflow copy, base retarget, no-op wake commit, or manual rerun. It is live confirmation that the protected Python Security base-name filter still suppresses required evidence on an ordinary stacked owner branch. #2109 already owns the causal removal of that PR base-name filter while preserving push policy, so keep the repair single-writer here. Acceptance implication: after the #2109 prerequisite chain is accepted into protected main, a fresh unchanged-or-validly-reconciled stacked canary must actually materialize Python Security on the non-main PR base before this admission slice is called GREEN. The separate current-head cancellations in SAST/Security remain #712 queue/lifecycle evidence, not proof that the missing Python generation is runner starvation. |
Correction — withdrawn RED after reading live protected authorityThe earlier version of this comment incorrectly treated I therefore withdrew the invalid oracle by ordinary forward commit The remaining valid finding is now a governance/source contradiction, not permission to patch #2109 against AGENTS. Protected Per |
Current exact authority correction — 2026-09-20 KSTThe top-of-body
Keep Draft. No source-neutral wake commit, blind rerun, self-approval, force update, destructive rebase, duplicate stale-head cleanup owner, or gate weakening is authorized. |
Current-head correction — 2026-09-20 KSTThe live PR head is Fresh exact-head workflow inventory is now terminal for this Draft generation: Runtime Quality The owned source contract remains stacked-base/Draft/Ready admission, including removal of the Python Security and Runtime Quality PR base-name filters. Do not add a third concurrency architecture here while protected |
2026-09-20 exact-head Ready admission evidenceCurrent exact head is The current-head Draft canary had already terminated runner-heavy work as expected. The Ready transition on the unchanged stacked head has now generated all five owned required workflows:
This closes the admission-generation question for the current stacked head: Python Security and Runtime Quality are no longer omitted when Ready. It does not constitute hosted acceptance while the runs remain nonterminal, and no predecessor success, self-approval, wake commit, or blind rerun is transferable. Keep the PR open/Ready until these exact-head runs settle and a qualifying independent current-head review exists. Ownership remains bounded: #2109 owns Draft/Ready lifecycle admission, stacked-base admission, |
seonghobae
left a comment
There was a problem hiding this comment.
Current-head reconciliation review for 42e3f7a8cbb03b117c898d3e125af87a5c6ce86b / tree 0dcd95f1838f68d677249284e240caf3fc63849d. This is evidence review, not approval.
The branch advanced two ordinary commits from the body-recorded f62172a...: ef0304be... added a structural stale-head cancellation RED, then 42e3f7a... withdrew that oracle because exact-head admission plus predecessor retirement belongs to the queue/scheduler owner rather than this Draft/Ready admission lane. The final tree is byte-identical to f62172a...; no #2109 production/workflow delta was changed by that detour.
The current Ready event has naturally admitted all five required workflows on the unchanged final tree: CodeQL 35494752040, Python Security 35494752070, Runtime Quality 35494752102, SAST 35494752067, and Security Scan 35494752139 are all queued/nonterminal. The preceding Draft generation on the same exact head completed skipped for all five lanes. That is the intended lifecycle shape, but queued work is not acceptance and the old 0c0e73d... Noema approval does not bind this head.
No additional source-backed finding survives this pass. The remaining order is canonical base #2291 acceptance, terminal exact-head hosted checks here, and qualifying independent current-head approval before ordinary integration. No source-neutral wake commit, blind rerun, self-approval, bypass, force push, or predecessor-check transfer is justified.
|
Fresh live-authority correction — 2026-09-20 KST PR metadata and the branch ref both identify the current head as The current Ready generation on exact Direct source prerequisite is now #2291 exact |
|
2026-09-20 lifecycle authority update — exact head The Ready canary admitted all five required heavy workflows on this stacked base: CodeQL All five Ready-generation runs above are now terminal This is not merge acceptance. #2109 remains Draft until #2291 is accepted and runner capacity is healthy enough to re-enter Ready and obtain terminal current-head GREEN plus independent review. Exact-head review scheduling / predecessor-cleanup ownership remains with #2283→#2289; do not expand #2109 into that lane. |
|
Fresh exact-head lifecycle correction (2026-09-20): PR metadata is Draft again at |
|
Parent-owner handoff correction: canonical #2291 exact Keep #2109 Draft at exact |
There was a problem hiding this comment.
Pull request overview
OpenCode reviewed the current-head product diff. Coverage is a separate gate.
Changed files
.github/workflows/agent-review-runtime-quality-ci.yml— GitHub Actions review job.github/workflows/codeql-pr.yml— GitHub Actions review job.github/workflows/python-security.yml— GitHub Actions review job.github/workflows/sast-semgrep.yml— GitHub Actions review job.github/workflows/security-scan.yml— GitHub Actions review jobCHANGELOG.d/20260920-draft-transition-cancels-ready-runs.md— repository behaviorCHANGELOG.md— repository behaviordocs/doctoring/draft-required-workflow-admission-20260912.md— operator or user guidancedocs/pr-review-and-merge-procedure.md— operator or user guidancedocs/product-technical-gap-baseline.md— operator or user guidancescripts/ci/sandboxed_verify.py— review and security gate shell pathtests/test_docs_only_pr_runner_admission.py— regression suitetests/test_required_workflow_queue_contract.py— regression suitetests/test_sandboxed_verify.py— regression suite
Changed behavior
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow: agent-review-runtime-quality-ci.yml"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow: agent-review-runtime-quality-ci.yml"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Workflow: codeql-pr.yml"]
S2 --> I2["GitHub Actions review job"]
I2 --> R2["Review risk: Workflow: codeql-pr.yml"]
R2 --> V2["actionlint plus required checks"]
Evidence --> S3["Workflow: python-security.yml"]
S3 --> I3["GitHub Actions review job"]
I3 --> R3["Review risk: Workflow: python-security.yml"]
R3 --> V3["actionlint plus required checks"]
Evidence --> S4["Workflow: sast-semgrep.yml"]
S4 --> I4["GitHub Actions review job"]
I4 --> R4["Review risk: Workflow: sast-semgrep.yml"]
R4 --> V4["actionlint plus required checks"]
Evidence --> S5["Workflow: security-scan.yml"]
S5 --> I5["GitHub Actions review job"]
I5 --> R5["Review risk: Workflow: security-scan.yml"]
R5 --> V5["actionlint plus required checks"]
Evidence --> S6["Repository file: 20260920-draft-transition-cancels-ready-runs.md"]
S6 --> I6["repository behavior"]
I6 --> R6["Review risk: Repository file: 20260920-draft-transition-cancels-ready-runs.md"]
R6 --> V6["required checks"]
Evidence --> S7["Repository file: CHANGELOG.md"]
S7 --> I7["repository behavior"]
I7 --> R7["Review risk: Repository file: CHANGELOG.md"]
R7 --> V7["required checks"]
Evidence --> S8["Docs: draft-required-workflow-admission-20260912.md (3 files)"]
S8 --> I8["operator or user guidance"]
I8 --> R8["Review risk: Docs: draft-required-workflow-admission-20260912.md (3 files)"]
R8 --> V8["docs review"]
Evidence --> S9["CI script: sandboxed_verify.py"]
S9 --> I9["review and security gate shell path"]
I9 --> R9["Review risk: CI script: sandboxed_verify.py"]
R9 --> V9["bash -n plus Strix self-test"]
Evidence --> S10["Test: test_docs_only_pr_runner_admission.py (3 files)"]
S10 --> I10["regression suite"]
I10 --> R10["Review risk: Test: test_docs_only_pr_runner_admission.py (3 files)"]
R10 --> V10["targeted test run"]
Findings
No source-backed product finding is synthesized from the coverage gate. A coverage miss belongs in the status comment.
- Head SHA:
42e3f7a8cbb03b117c898d3e125af87a5c6ce86b - Workflow run: 35743808312
- Workflow attempt: 1
- Coverage gate:
failure
Review outcome
Coverage is a gate, not the review. This body reviews the changed product files.
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow: agent-review-runtime-quality-ci.yml"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow: agent-review-runtime-quality-ci.yml"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Workflow: codeql-pr.yml"]
S2 --> I2["GitHub Actions review job"]
I2 --> R2["Review risk: Workflow: codeql-pr.yml"]
R2 --> V2["actionlint plus required checks"]
Evidence --> S3["Workflow: python-security.yml"]
S3 --> I3["GitHub Actions review job"]
I3 --> R3["Review risk: Workflow: python-security.yml"]
R3 --> V3["actionlint plus required checks"]
Evidence --> S4["Workflow: sast-semgrep.yml"]
S4 --> I4["GitHub Actions review job"]
I4 --> R4["Review risk: Workflow: sast-semgrep.yml"]
R4 --> V4["actionlint plus required checks"]
Evidence --> S5["Workflow: security-scan.yml"]
S5 --> I5["GitHub Actions review job"]
I5 --> R5["Review risk: Workflow: security-scan.yml"]
R5 --> V5["actionlint plus required checks"]
Evidence --> S6["Repository file: 20260920-draft-transition-cancels-ready-runs.md"]
S6 --> I6["repository behavior"]
I6 --> R6["Review risk: Repository file: 20260920-draft-transition-cancels-ready-runs.md"]
R6 --> V6["required checks"]
Evidence --> S7["Repository file: CHANGELOG.md"]
S7 --> I7["repository behavior"]
I7 --> R7["Review risk: Repository file: CHANGELOG.md"]
R7 --> V7["required checks"]
Evidence --> S8["Docs: draft-required-workflow-admission-20260912.md (3 files)"]
S8 --> I8["operator or user guidance"]
I8 --> R8["Review risk: Docs: draft-required-workflow-admission-20260912.md (3 files)"]
R8 --> V8["docs review"]
Evidence --> S9["CI script: sandboxed_verify.py"]
S9 --> I9["review and security gate shell path"]
I9 --> R9["Review risk: CI script: sandboxed_verify.py"]
R9 --> V9["bash -n plus Strix self-test"]
Evidence --> S10["Test: test_docs_only_pr_runner_admission.py (3 files)"]
S10 --> I10["regression suite"]
I10 --> R10["Review risk: Test: test_docs_only_pr_runner_admission.py (3 files)"]
R10 --> V10["targeted test run"]
There was a problem hiding this comment.
Pull request overview
OpenCode reviewed the current-head product diff. Coverage is a separate gate.
Changed files
.github/workflows/agent-review-runtime-quality-ci.yml— GitHub Actions review job.github/workflows/codeql-pr.yml— GitHub Actions review job.github/workflows/python-security.yml— GitHub Actions review job.github/workflows/sast-semgrep.yml— GitHub Actions review job.github/workflows/security-scan.yml— GitHub Actions review jobCHANGELOG.d/20260920-draft-transition-cancels-ready-runs.md— repository behaviorCHANGELOG.md— repository behaviordocs/doctoring/draft-required-workflow-admission-20260912.md— operator or user guidancedocs/pr-review-and-merge-procedure.md— operator or user guidancedocs/product-technical-gap-baseline.md— operator or user guidancescripts/ci/sandboxed_verify.py— review and security gate shell pathtests/test_docs_only_pr_runner_admission.py— regression suitetests/test_required_workflow_queue_contract.py— regression suitetests/test_sandboxed_verify.py— regression suite
Changed behavior
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow: agent-review-runtime-quality-ci.yml"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow: agent-review-runtime-quality-ci.yml"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Workflow: codeql-pr.yml"]
S2 --> I2["GitHub Actions review job"]
I2 --> R2["Review risk: Workflow: codeql-pr.yml"]
R2 --> V2["actionlint plus required checks"]
Evidence --> S3["Workflow: python-security.yml"]
S3 --> I3["GitHub Actions review job"]
I3 --> R3["Review risk: Workflow: python-security.yml"]
R3 --> V3["actionlint plus required checks"]
Evidence --> S4["Workflow: sast-semgrep.yml"]
S4 --> I4["GitHub Actions review job"]
I4 --> R4["Review risk: Workflow: sast-semgrep.yml"]
R4 --> V4["actionlint plus required checks"]
Evidence --> S5["Workflow: security-scan.yml"]
S5 --> I5["GitHub Actions review job"]
I5 --> R5["Review risk: Workflow: security-scan.yml"]
R5 --> V5["actionlint plus required checks"]
Evidence --> S6["Repository file: 20260920-draft-transition-cancels-ready-runs.md"]
S6 --> I6["repository behavior"]
I6 --> R6["Review risk: Repository file: 20260920-draft-transition-cancels-ready-runs.md"]
R6 --> V6["required checks"]
Evidence --> S7["Repository file: CHANGELOG.md"]
S7 --> I7["repository behavior"]
I7 --> R7["Review risk: Repository file: CHANGELOG.md"]
R7 --> V7["required checks"]
Evidence --> S8["Docs: draft-required-workflow-admission-20260912.md (3 files)"]
S8 --> I8["operator or user guidance"]
I8 --> R8["Review risk: Docs: draft-required-workflow-admission-20260912.md (3 files)"]
R8 --> V8["docs review"]
Evidence --> S9["CI script: sandboxed_verify.py"]
S9 --> I9["review and security gate shell path"]
I9 --> R9["Review risk: CI script: sandboxed_verify.py"]
R9 --> V9["bash -n plus Strix self-test"]
Evidence --> S10["Test: test_docs_only_pr_runner_admission.py (3 files)"]
S10 --> I10["regression suite"]
I10 --> R10["Review risk: Test: test_docs_only_pr_runner_admission.py (3 files)"]
R10 --> V10["targeted test run"]
Findings
No source-backed product finding is synthesized from the coverage gate. A coverage miss belongs in the status comment.
- Head SHA:
42e3f7a8cbb03b117c898d3e125af87a5c6ce86b - Workflow run: 35799035407
- Workflow attempt: 1
- Coverage gate:
failure
Review outcome
Coverage is a gate, not the review. This body reviews the changed product files.
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow: agent-review-runtime-quality-ci.yml"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow: agent-review-runtime-quality-ci.yml"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Workflow: codeql-pr.yml"]
S2 --> I2["GitHub Actions review job"]
I2 --> R2["Review risk: Workflow: codeql-pr.yml"]
R2 --> V2["actionlint plus required checks"]
Evidence --> S3["Workflow: python-security.yml"]
S3 --> I3["GitHub Actions review job"]
I3 --> R3["Review risk: Workflow: python-security.yml"]
R3 --> V3["actionlint plus required checks"]
Evidence --> S4["Workflow: sast-semgrep.yml"]
S4 --> I4["GitHub Actions review job"]
I4 --> R4["Review risk: Workflow: sast-semgrep.yml"]
R4 --> V4["actionlint plus required checks"]
Evidence --> S5["Workflow: security-scan.yml"]
S5 --> I5["GitHub Actions review job"]
I5 --> R5["Review risk: Workflow: security-scan.yml"]
R5 --> V5["actionlint plus required checks"]
Evidence --> S6["Repository file: 20260920-draft-transition-cancels-ready-runs.md"]
S6 --> I6["repository behavior"]
I6 --> R6["Review risk: Repository file: 20260920-draft-transition-cancels-ready-runs.md"]
R6 --> V6["required checks"]
Evidence --> S7["Repository file: CHANGELOG.md"]
S7 --> I7["repository behavior"]
I7 --> R7["Review risk: Repository file: CHANGELOG.md"]
R7 --> V7["required checks"]
Evidence --> S8["Docs: draft-required-workflow-admission-20260912.md (3 files)"]
S8 --> I8["operator or user guidance"]
I8 --> R8["Review risk: Docs: draft-required-workflow-admission-20260912.md (3 files)"]
R8 --> V8["docs review"]
Evidence --> S9["CI script: sandboxed_verify.py"]
S9 --> I9["review and security gate shell path"]
I9 --> R9["Review risk: CI script: sandboxed_verify.py"]
R9 --> V9["bash -n plus Strix self-test"]
Evidence --> S10["Test: test_docs_only_pr_runner_admission.py (3 files)"]
S10 --> I10["regression suite"]
I10 --> R10["Review risk: Test: test_docs_only_pr_runner_admission.py (3 files)"]
R10 --> V10["targeted test run"]
There was a problem hiding this comment.
Pull request overview
OpenCode reviewed the current-head product diff. Coverage is a separate gate.
Changed files
.github/workflows/agent-review-runtime-quality-ci.yml— GitHub Actions review job.github/workflows/codeql-pr.yml— GitHub Actions review job.github/workflows/python-security.yml— GitHub Actions review job.github/workflows/sast-semgrep.yml— GitHub Actions review job.github/workflows/security-scan.yml— GitHub Actions review jobCHANGELOG.d/20260920-draft-transition-cancels-ready-runs.md— repository behaviorCHANGELOG.md— repository behaviordocs/doctoring/draft-required-workflow-admission-20260912.md— operator or user guidancedocs/pr-review-and-merge-procedure.md— operator or user guidancedocs/product-technical-gap-baseline.md— operator or user guidancescripts/ci/sandboxed_verify.py— review and security gate shell pathtests/test_docs_only_pr_runner_admission.py— regression suitetests/test_required_workflow_queue_contract.py— regression suitetests/test_sandboxed_verify.py— regression suite
Changed behavior
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow: agent-review-runtime-quality-ci.yml"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow: agent-review-runtime-quality-ci.yml"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Workflow: codeql-pr.yml"]
S2 --> I2["GitHub Actions review job"]
I2 --> R2["Review risk: Workflow: codeql-pr.yml"]
R2 --> V2["actionlint plus required checks"]
Evidence --> S3["Workflow: python-security.yml"]
S3 --> I3["GitHub Actions review job"]
I3 --> R3["Review risk: Workflow: python-security.yml"]
R3 --> V3["actionlint plus required checks"]
Evidence --> S4["Workflow: sast-semgrep.yml"]
S4 --> I4["GitHub Actions review job"]
I4 --> R4["Review risk: Workflow: sast-semgrep.yml"]
R4 --> V4["actionlint plus required checks"]
Evidence --> S5["Workflow: security-scan.yml"]
S5 --> I5["GitHub Actions review job"]
I5 --> R5["Review risk: Workflow: security-scan.yml"]
R5 --> V5["actionlint plus required checks"]
Evidence --> S6["Repository file: 20260920-draft-transition-cancels-ready-runs.md"]
S6 --> I6["repository behavior"]
I6 --> R6["Review risk: Repository file: 20260920-draft-transition-cancels-ready-runs.md"]
R6 --> V6["required checks"]
Evidence --> S7["Repository file: CHANGELOG.md"]
S7 --> I7["repository behavior"]
I7 --> R7["Review risk: Repository file: CHANGELOG.md"]
R7 --> V7["required checks"]
Evidence --> S8["Docs: draft-required-workflow-admission-20260912.md (3 files)"]
S8 --> I8["operator or user guidance"]
I8 --> R8["Review risk: Docs: draft-required-workflow-admission-20260912.md (3 files)"]
R8 --> V8["docs review"]
Evidence --> S9["CI script: sandboxed_verify.py"]
S9 --> I9["review and security gate shell path"]
I9 --> R9["Review risk: CI script: sandboxed_verify.py"]
R9 --> V9["bash -n plus Strix self-test"]
Evidence --> S10["Test: test_docs_only_pr_runner_admission.py (3 files)"]
S10 --> I10["regression suite"]
I10 --> R10["Review risk: Test: test_docs_only_pr_runner_admission.py (3 files)"]
R10 --> V10["targeted test run"]
Findings
No source-backed product finding is synthesized from the coverage gate. A coverage miss belongs in the status comment.
- Head SHA:
42e3f7a8cbb03b117c898d3e125af87a5c6ce86b - Workflow run: 35848994274
- Workflow attempt: 1
- Coverage gate:
failure
Review outcome
Coverage is a gate, not the review. This body reviews the changed product files.
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow: agent-review-runtime-quality-ci.yml"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow: agent-review-runtime-quality-ci.yml"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Workflow: codeql-pr.yml"]
S2 --> I2["GitHub Actions review job"]
I2 --> R2["Review risk: Workflow: codeql-pr.yml"]
R2 --> V2["actionlint plus required checks"]
Evidence --> S3["Workflow: python-security.yml"]
S3 --> I3["GitHub Actions review job"]
I3 --> R3["Review risk: Workflow: python-security.yml"]
R3 --> V3["actionlint plus required checks"]
Evidence --> S4["Workflow: sast-semgrep.yml"]
S4 --> I4["GitHub Actions review job"]
I4 --> R4["Review risk: Workflow: sast-semgrep.yml"]
R4 --> V4["actionlint plus required checks"]
Evidence --> S5["Workflow: security-scan.yml"]
S5 --> I5["GitHub Actions review job"]
I5 --> R5["Review risk: Workflow: security-scan.yml"]
R5 --> V5["actionlint plus required checks"]
Evidence --> S6["Repository file: 20260920-draft-transition-cancels-ready-runs.md"]
S6 --> I6["repository behavior"]
I6 --> R6["Review risk: Repository file: 20260920-draft-transition-cancels-ready-runs.md"]
R6 --> V6["required checks"]
Evidence --> S7["Repository file: CHANGELOG.md"]
S7 --> I7["repository behavior"]
I7 --> R7["Review risk: Repository file: CHANGELOG.md"]
R7 --> V7["required checks"]
Evidence --> S8["Docs: draft-required-workflow-admission-20260912.md (3 files)"]
S8 --> I8["operator or user guidance"]
I8 --> R8["Review risk: Docs: draft-required-workflow-admission-20260912.md (3 files)"]
R8 --> V8["docs review"]
Evidence --> S9["CI script: sandboxed_verify.py"]
S9 --> I9["review and security gate shell path"]
I9 --> R9["Review risk: CI script: sandboxed_verify.py"]
R9 --> V9["bash -n plus Strix self-test"]
Evidence --> S10["Test: test_docs_only_pr_runner_admission.py (3 files)"]
S10 --> I10["regression suite"]
I10 --> R10["Review risk: Test: test_docs_only_pr_runner_admission.py (3 files)"]
R10 --> V10["targeted test run"]
Current authority — 2026-09-24 KST
Exact head
42e3f7a8cbb03b117c898d3e125af87a5c6ce86b; OPEN / Draft / mergeable. Base branch iscodex/strix-trusted-binder-root, whose live owner #2291 remains Draft at exact1794626af3473ef23b9c2e678c3f06fd6c11636f. This lane is intentionally not reconciled again until the foundation chain below reaches protected authority.This PR had drifted to Ready while its own authority still required parent integration and ordinary reconciliation first, so it was converted back to Draft. That lifecycle change is not source progress or merge acceptance.
#2291 has repaired the trusted Strix binder/source-fixture defect, but its current exact head inherits protected-main AnyIO 4.14.0 and therefore fails Python Security. Canonical dependency owner #2278 exact
8a5251bf409fe84b3dd0cba1e48992f5b8d9eda5supplies the 4.14.2 repair; however #2278 cannot obtain a valid Required OpenCode coverage receipt while protected main lacks canonical coverage build-context repair #2286.#2286 now breaks that cycle at Draft exact
42e4198fa012eb24596e7984d77e27f0905348d6by ordinary two-parent ancestry: it retains the five canonical coverage-owner paths and adopts #2278 exact head as an ancestor, so its protected-main diff also carries the exact one-file AnyIO repair. Fresh exact-head hosted runs exist on #2286 and are still nonterminal.Required parent order is therefore #2286 exact-head acceptance/protected integration → ordinary/non-force #2291 reconciliation and fresh acceptance → protected #2291 integration → ordinary/non-force #2109 parent reconciliation. #2109 must not copy the dependency, coverage, or Strix binder repairs.
This lane owns Draft/Ready and stacked-base admission for the five heavy required workflows, including runner-free Draft behavior,
ready_for_reviewadmission,converted_to_draftwithdrawal, stacked-base PR admission, and non-vacuous sandbox/queue contract selection. Exact-head predecessor cleanup and OpenCode scheduler serialization are owned elsewhere and are not duplicated here.Current Draft lifecycle evidence
The 2026-09-24 conversion back to Draft produced a fresh same-head generation without any source commit or synthetic wake activity. All five heavy workflows terminated SKIPPED as intended:
35933884621: SKIPPED35933884620: SKIPPED35933884668: SKIPPED35933884737: SKIPPED35933884739: SKIPPEDThis proves only the Draft withdrawal contract. It is not source GREEN, independent review acceptance, or merge authority. Retained local evidence remains focused queue/Gap 80 passed and full suite 3,413 passed / 5 skipped / 40 subtests, plus compileall and
git diff --checkPASS; those receipts do not transfer to a future reconciled head.Completion requires the canonical parent chain above to become protected, then ordinary/non-force reconciliation of this lane, policy-consistent Ready re-entry, terminal exact-head hosted acceptance, zero actionable review, qualifying independent current-head approval, and normal protected-main integration.
No self-approval, source-neutral wake/no-op commit, blind rerun, force push, destructive rebase, duplicate scheduler/runtime owner, review dismissal, gate weakening, or predecessor-evidence transfer is authorized.