Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
23 commits
Select commit Hold shift + click to select a range
d3b445f
docs(doctoring): plan-ceiling owner brief for headroom decisions
seonghobae Sep 17, 2026
21fc02e
docs(doctoring): surface A–E headroom options at top of plan-ceiling …
seonghobae Sep 17, 2026
513302a
test(strix): bind evidence helper to trusted source root
seonghobae Sep 19, 2026
c08b13d
fix(strix): resolve evidence binder from trusted source
seonghobae Sep 19, 2026
ca7e1e7
test(strix): materialize trusted binder fixtures
seonghobae Sep 19, 2026
db1fd61
fix(strix): restore complete verified fixture tree
seonghobae Sep 19, 2026
fb9c0e2
test(strix): require consumer-free trusted binder fixture
seonghobae Sep 19, 2026
78b33a8
repair(strix): restore executable harness after binary blob corruption
seonghobae Sep 19, 2026
191bd63
test(strix): require binder-free consumer fixture
seonghobae Sep 19, 2026
ef1a866
test(strix): separate trusted gate from consumer root
seonghobae Sep 19, 2026
abc9a7d
docs(strix): bind consumer isolation evidence to exact commits
seonghobae Sep 19, 2026
00082e8
docs(strix): describe separated trusted runtime fixture
seonghobae Sep 19, 2026
782d67b
test(strix): retain canonical gate source under scan
seonghobae Sep 20, 2026
a8d6261
test(strix): red specialized fixture owner boundary
seonghobae Sep 20, 2026
bbe225d
test(strix): materialize specialized fixtures' trusted runtime outsid…
Sep 21, 2026
9b6a805
Merge branch 'main' into plan-ceiling-owner-brief
seonghobae Sep 21, 2026
1794626
test(strix): pin trusted evidence-binder path
seonghobae Sep 21, 2026
361a9eb
merge: adopt current CI owner and repair CodeQL URL oracle
seonghobae Sep 26, 2026
1fd22f4
test(strix): require Job Analysis authority context
seonghobae Sep 26, 2026
808a8a7
fix(strix): include Job Analysis authority context
seonghobae Sep 26, 2026
b90d873
docs(strix): record Job Analysis authority context
seonghobae Sep 26, 2026
a45f718
merge(owner): restack doctoring evidence on current security stack
seonghobae Sep 26, 2026
60bafcd
merge(main): restack plan-ceiling owner brief onto current main
seonghobae Sep 28, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
17 changes: 17 additions & 0 deletions CHANGELOG.d/20260920-strix-trusted-binder-runtime-fixture.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
### Strix keeps trusted evidence binding outside consumer workspaces

- The Strix gate resolves its evidence binder beside the trusted gate source.
The executable core harness now materializes that trusted runtime under a
separate source directory, passes a binder-free consumer workspace through
`STRIX_REPO_ROOT`, and invokes the trusted gate by its absolute path.
- OpenCode coverage assertions follow the consolidated
`validate-pr-metadata` owner instead of the removed
`coverage-source-tree` job and failure-report step.
- The commercial-readiness receipt contract now compares the complete parsed
harden-runner endpoint set instead of treating an expected hostname as a URL
substring. This closes the exact CodeQL
`py/incomplete-url-substring-sanitization` finding without suppressing it or
widening egress.
- The branch adopts the current central dependency owner, including the
explicit AnyIO 4.14.2 source-to-hash pin required by the Python security
gate.
4 changes: 4 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,7 @@
### Strix supplies bounded Job Analysis authority context from the trusted base

- Orgmetra #63 changes `packages/hris-kernel/src/orgmetra_hris_kernel/job_analysis.py`, but the Strix scan workspace previously omitted the unchanged authorization, HTTP, snapshot, and persistence collaborators that establish its resource-ownership boundary. That incomplete context produced a false HIGH IDOR finding even though the product reconstructs owner scope and authorizes resource fields before port access. A source-first executable fixture now requires the changed PR-head module, exactly five unchanged Job Analysis authority files from the authenticated trusted base, and exclusion of an unrelated administration file. RED `1fd22f4e` failed because `auth.py` was absent; the gate now recognizes only the normalized Job Analysis trigger and adds the five fixed context paths through the existing trusted-base materialization boundary. No consumer source, provider/model policy, severity gate, timeout, or write authority changes.

### Intel macOS native archives are bound to x86_64 bytes

- The release prescreener now requires every native member in an Intel macOS
Expand Down
135 changes: 135 additions & 0 deletions docs/doctoring/plan-ceiling-owner-brief-20260918.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,135 @@
# Owner brief: plan-ceiling residual after job folding (2026-09-18)

- **Date:** 2026-09-18
- **Audience:** org owner (billing / Actions concurrency decision)
- **Purpose:** one-page decision brief. Residual queue pain after folding and
coalesce repairs is still the **plan concurrent-job ceiling**, not a missing
workflow kill-switch.
- **Sources:** ContextualWisdomLab/.github#2252 (remeasure), #2249 (fail-open /
re-enable gate grounding), #2233 (fail-open coalesce when tick is stale), plus
the in-tree doctoring records those PRs cite.
- **Non-goals of this brief:** flipping `OPENCODE_REVIEW_COALESCE_ENABLED`,
turning workflows off, adding symptom caps that weaken required gates, or
claiming a new admission bug beyond what `#2242` already fixed.

### Owner options at a glance (headroom, not kill-switches)

Concrete concurrent-job headroom choices for the owner; full table below.

| ID | Owner action | Role |
|---|---|---|
| **A** | Raise plan concurrent-job quota (~60 today; verify Billing UI) | Direct ceiling lift |
| **B** | Add a separate runner pool for a defined heavy job class | Offload shared hosted slots |
| **C** | Keep ceiling; cut arrival via stale-PR supersede + proven superseded-head cancel only | Arrival hygiene (complements A/B) |
| **D** | Keep `OPENCODE_REVIEW_COALESCE_ENABLED=false` until A/B/C yield headroom (or explicit fail-open accept) | **Recommended default** |
| **E** | Cap/disable required review or security workflows | **Reject** — symptom kill-switch, weakens gates |

Do **not** treat workflow kill-switches or a coalesce flip under ~10³ queued as
the residual fix. Coalesce stays **false** from this brief.

## Snapshot (measured)

Full 66-repo REST census and job-level admission samples from the post-folding
remeasure carried by #2252
(`docs/doctoring/actions-queue-wait-24h-remeasure-post-2244-20260917.md`,
window closed ~`2026-09-17T20:15Z`, ~4h after `#2242`):

| Metric | Value |
|---|---|
| Org `in_progress` (sum of runs) | **34** |
| Org `queued` (sum of runs) | **~2,090** |
| Mid-day same day (`#2237` / earlier remasure) | 48 in_progress / 1,911 queued |
| Open PRs org-wide | **~4,256** (was ~4,288 mid-day) |
| Plan concurrent-job ceiling (billing UI, 2026-09-03 primary) | **~60** |
| `opencode-review-dispatch` first-job admission | **p50 ~3.2h / p95 ~3.3h** |
| Coalesce ticks with flag `false` after `#2242` | **skipped in ~1s** (not queued) |
| `OPENCODE_REVIEW_COALESCE_ENABLED` | **`false`** (unchanged) |

Shape is unchanged from
`docs/doctoring/actions-plan-concurrency-ceiling-20260903.md`: low-double-digit
concurrent work against ~10³ queued. That is the signature of a hard org-wide
concurrent-job quota, not of a single defective workflow.

## What engineering already did (cause-adjacent, not ceiling-lifting)

| Change | Effect | What it did **not** do |
|---|---|---|
| `#2228` / `#2230` job folding | Removed same-trust-level `needs:` hops on OpenCode Review Dispatch / required bootstrap; under saturation that hop previously cost **hours** of pure queue wait per edge (`actions-capacity-root-cause-20260917.md`: ~97.5% of a ~14h wall clock was inter-job wait). | Did not raise how many jobs can run at once. First-job admission remains ~**3.2h**. |
| `#2233` fail-open coalesce | When coalescing is on, synchronize dispatch does **not** wait forever on a missing recent successful tick (`DEFAULT_COALESCE_TICK_MAX_AGE_SECONDS=600`). Grounded further in #2249. | Does not drain the org backlog; irrelevant while the flag stays `false`. |
| `#2242` job-level coalesce gate | Disabled ticks skip **before** runner admission (1s `skipped`), so inert five-minute crons no longer sit multi-hour `queued` competing for the ~60 slots. | Does not add headroom for real review/dispatch work. |
| Hygiene / evidence merges same day | Strix/Noema correctness; schedule observability experiments | Not capacity. |

Net: engineering removed **repeatable multi-hour hops** and stopped **wasting slots on inert ticks**. The residual is **admission under the plan ceiling**.

## Why coalesce stays `false`

Re-enable criteria live in
`docs/doctoring/coalesce-tick-post-2242-live-verify-20260917.md` (and #2249's
contract/docs grounding of N=600). Must-haves for gate health are largely met
(job-level skip-before-admission proven live; fail-open present on `main` via
#2233). **Should-have capacity is not met:**

- Prefer enable when org `in_progress` is clearly below ceiling **and** queued
depth is not order-of-10³, **or**
- Explicitly accept that enabled ticks may still queue for hours and that
#2233 fail-open will temporarily bypass coalesce deferral until a `success`
tick completes.

Today: **~34 in_progress / ~2,090 queued** against ~60. Enabling under that
depth without accepting fail-open-as-normal recreates "reviews never dispatch"
rather than "inert ticks clog the queue." This brief therefore **leaves the
variable false** and does not authorize a flip.

## Owner options (fix the cause, not the symptom)

Do **not** treat "turn off required workflows," "cap model jobs to hide wait,"
or "flip coalesce under saturation" as the decision. Those attack symptoms or
reintroduce known failure modes. Options that address **concurrent-job budget /
plan headroom**:

| Option | What the owner does | Expected effect on residual | Cost / risk | Notes |
|---|---|---|---|---|
| **A. Raise plan concurrent-job quota** | Confirm exact ceiling on org Settings → Actions / Billing; purchase higher included concurrency or a tier that lifts the ~60 job cap. | Directly increases concurrent throughput; only lever that lifts the hard ceiling documented since 2026-09-03. | Billing. | REST cannot read the quota; owner must verify the UI number before purchase. |
| **B. Add a separate runner pool** | Provision self-hosted / larger runners with their **own** capacity pool for a defined job class (e.g. long AI review dispatch), leaving hosted quota for everything else. | Moves a heavy class off the shared ~60 hosted slots. | Ops + trust boundary (who may run on those runners). | Hosted org runners API was `total_count=0` at remasure — no separate pool today. |
| **C. Accept ceiling; buy time with PR load** | Keep ~60; aggressively close/supersede stale open PRs (~4.2k feeding required workflows) and cancel only **proven** superseded-head queued runs (event-specific evidence — no org-wide sweep). | Reduces **arrival rate** into the same ceiling; does not raise concurrency. | Process discipline; wrong cancellation discards live work. | Complements A/B; does not replace them if admission p50 stays multi-hour. |
| **D. Defer coalesce enable until headroom** | Leave `OPENCODE_REVIEW_COALESCE_ENABLED=false` until A/B/C produce clearer headroom **or** owner explicitly accepts #2233 fail-open under deep queue. | Avoids recreating "dispatch waits on ticks that never admit." | Delayed coalesce benefit on push bursts. | **Recommended default** until A or B lands. |
| **E. Symptom caps / disable workflows** | Cap or turn off required review/security workflows to shrink queue depth. | Appears to drain queue; **weakens gates** and hides ceiling pressure. | Governance / security regression. | **Out of scope / reject** for this residual. |

### Recommended owner sequence

1. Re-attest the concurrent-job number on the billing UI (still ~60 from 2026-09-03
primary evidence unless changed).
2. Choose **A** and/or **B** if multi-hour first-job admission (~3.2h) is
unacceptable for product review SLA.
3. Use **C** in parallel for arrival-rate hygiene.
4. Keep **D** until census shows material headroom; then follow the flip
procedure in the post-`#2242` verify record (watch for `conclusion=success`
ticks; rely on #2233 fail-open if a tick queues).

## Explicit non-actions for agents

- Do **not** set `OPENCODE_REVIEW_COALESCE_ENABLED=true` from this brief.
- Do **not** disable or path-filter required workflows to "fix" queue depth.
- Do **not** add model-path timeouts or concurrency caps as a substitute for
plan headroom (`docs/product-goal-directive.md` §8; ADR-0030 scope).
- Do **not** treat job folding as unfinished: the remaining cost is first-job
admission under the ceiling, which folding cannot remove.

## Citations

| Ref | Role |
|---|---|
| ContextualWisdomLab/.github#2252 | Post-`#2228`–`#2244` remasure: **34 / ~2090**, ~**3.2h** first-job admission, coalesce 1s skip |
| ContextualWisdomLab/.github#2249 | Grounds coalesce fail-open N=600 + re-enable gate; flag left **false** |
| ContextualWisdomLab/.github#2233 | Fail-open coalesce when no recent successful tick |
| `docs/doctoring/actions-plan-concurrency-ceiling-20260903.md` | Original ~60 plan-ceiling diagnosis |
| `docs/doctoring/actions-capacity-root-cause-20260917.md` | Inter-job queue wait vs model time |
| `docs/doctoring/coalesce-tick-post-2242-live-verify-20260917.md` | Why enable is still blocked on capacity |
| `docs/adr/0030-ci-centralization-scope-given-plan-ceiling.md` | Centralization cannot lift the ceiling |

## Audit trail

- Numbers in the Snapshot table are copied from the #2252 doctoring remasure
(measurement ~`2026-09-17T20:07Z`–`20:15Z`), not re-sampled in this docs-only
brief.
- This file is documentation only; no workflow, variable, or gate change.
67 changes: 67 additions & 0 deletions docs/product-technical-gap-baseline.md
Original file line number Diff line number Diff line change
Expand Up @@ -3438,6 +3438,73 @@ alone -- it is a documented multi-PR hot-file collision zone. Contract:

**Evidence / remaining condition.** The standalone fixture mechanism was executed locally against Python stdlib and produced one canonical request followed by terminal HTTP 302 for every hostile target. This is mechanism evidence, not repository acceptance. Final authority requires focused/full exact-tree GREEN, fresh exact-head Security/SAST/Python Security/CodeQL/runtime-quality checks, no unresolved actionable review, ordinary protected-main integration, and downstream consumer validation. No scanner suppression, redirect allowlist widening, provider fallback, workflow gate weakening, or credential-boundary change is included.

## 2026-09-20 Strix trusted-binder consumer-isolation gap

**Status:** Proposed on `ContextualWisdomLab/.github#2291`; exact-head hosted
checks, independent review, and protected-main integration remain required.

**Context Map / owner.** The central `.github` CI bounded context owns
`strix_quick_gate.sh`, its evidence binder, and the executable gate harness.
Consumer repositories supply only the scan workspace through
`STRIX_REPO_ROOT`; they do not copy or own the binder.

**Gap / root cause.** The production gate incorrectly resolved the trusted
binder from the consumer root. The first repair correctly moved that lookup to
`SCRIPT_DIR`, but its test harness copied only the gate and model helper into
the isolated fixture. The current PR head therefore still reproduced the same
missing-binder exit in the `success` scenario. Three assertions in that harness
also described the removed standalone `coverage-source-tree` job after its
responsibility moved into `validate-pr-metadata`.

**Action / evidence.** The production gate resolves
`strix_evidence_binding.py` beside its trusted source. RED `191bd630`
requires the generic executable consumer fixture to contain no binder. GREEN
`ef1a8667` materializes the gate, model helper, and binder under a separate
`trusted-source/scripts/ci` directory, passes only the binder-free consumer
workspace through `STRIX_REPO_ROOT`, and invokes the trusted gate by its
absolute path. This makes the core executable fixture reproduce the production
owner boundary instead of proving a co-located copy. The full exact-tree Strix
harness and hosted checks remain the release authority; no provider, model,
timeout, severity, or consumer ownership boundary changes.

**2026-09-26 exact-head RCA / owner integration.** Exact Python-security job
`107750961662` on head `1794626af3473ef23b9c2e678c3f06fd6c11636f`
found AnyIO 4.14.0's CVE-2026-63374, CVE-2026-64847, and CVE-2026-63349 in
`requirements-strix-ci-hashes.txt`; this branch had not adopted the central
source-to-hash AnyIO 4.14.2 repair from `ContextualWisdomLab/.github#2385`.
Exact CodeQL dispatch run `36204821293`, Python job `108319933572`, separately
produced one Medium+ SARIF result:
`py/incomplete-url-substring-sanitization` at
`tests/test_organization_commercial_readiness_loop_receipt_contract.py:60`.
The receipt test parsed the complete YAML endpoint block but then expressed the
expected receiver hostname through a subset/membership-style assertion that
CodeQL correctly rejects on URL-security surfaces. The ordinary two-parent
owner integration adopts #2385's AnyIO contract; the test now compares the
complete seven-entry endpoint set exactly. This strengthens the egress oracle:
an unexpected endpoint fails rather than being tolerated. No CodeQL query,
severity, SARIF gate, dependency audit, or endpoint allowlist is suppressed or
widened. Fresh exact-head hosted Python Security and CodeQL remain mandatory.

**2026-09-27 Job Analysis bounded-context repair.** Orgmetra #63 exact head
`d88800a5ca3ca15df332e8def5e25064c46e4005` changes the HRIS-kernel Job
Analysis aggregate module, while the trusted scan workspace previously omitted
the unchanged product-owned authority context that explains its ownership
checks. Strix consequently reported a HIGH IDOR finding against an incomplete
workspace even though the Job Analysis API reconstructs the canonical owner and
authorizes resource fields before snapshot or PostgreSQL port access. Source-
first RED `1fd22f4e1e86d0ebfe5dab932697e95593c9ad10` adds an executable
pull-request-target fixture whose fake scanner refuses to run unless the changed
PR-head `job_analysis.py` is accompanied by exactly the five fixed trusted-base
collaborators (`auth.py`, `authorization.py`, `http.py`, `postgres.py`, and
`snapshot.py`); it also proves an unrelated administration module is excluded.
The minimal GREEN recognizes only that normalized trigger and emits those five
paths through the existing trusted-base context materializer. This is a bounded
CI-context repair, not a transfer of product domain truth: no Orgmetra source,
authorization order, persistence boundary, model/provider policy, severity,
timeout, or write capability changes. Exact-head hosted Strix acceptance,
independent review, ordinary protected-main integration, and a fresh Orgmetra
#63 consumer run remain mandatory before the false-positive gap is complete.

## 2026-09-27 exact release distribution/scope evidence coverage

**Status:** Proposed on `ContextualWisdomLab/.github#2400`; the current
Expand Down
14 changes: 14 additions & 0 deletions scripts/ci/strix_quick_gate.sh
Original file line number Diff line number Diff line change
Expand Up @@ -1384,6 +1384,7 @@ pull_request_scope_context_files() {
local needs_backend_app_python=0
local needs_contextual_orchestrator_python=0
local needs_frontend_email_api_context=0
local needs_orgmetra_job_analysis_authority_context=0
local needs_deployment_context=0
local changed_file normalized_changed_file
for changed_file in "$@"; do
Expand All @@ -1400,6 +1401,9 @@ pull_request_scope_context_files() {
contextual_orchestrator/*.py)
needs_contextual_orchestrator_python=1
;;
packages/hris-kernel/src/orgmetra_hris_kernel/job_analysis.py)
needs_orgmetra_job_analysis_authority_context=1
;;
# The app shell, email components, threading URL builder, and API client can
# shape frontend email retrieval flows; include backend auth context with them.
frontend/src/components/EmailDetail.tsx | frontend/src/components/EmailList.tsx | frontend/src/app/page.tsx | frontend/src/lib/api-client.ts | frontend/src/lib/email-threading.ts)
Expand Down Expand Up @@ -1549,6 +1553,16 @@ backend/services/threading_service.py
EOF
fi

if [ "$needs_orgmetra_job_analysis_authority_context" -eq 1 ]; then
cat <<'EOF'
services/job-analysis-api/src/orgmetra_job_analysis_api/auth.py
services/job-analysis-api/src/orgmetra_job_analysis_api/authorization.py
services/job-analysis-api/src/orgmetra_job_analysis_api/http.py
services/job-analysis-api/src/orgmetra_job_analysis_api/postgres.py
services/job-analysis-api/src/orgmetra_job_analysis_api/snapshot.py
EOF
fi

if [ "$needs_deployment_context" -eq 1 ]; then
cat <<'EOF'
Dockerfile
Expand Down
Loading
Loading