Skip to content

fix(voice): reject exports outside admitted Post endpoints - #971

Draft
seonghobae wants to merge 4 commits into
fix/voice-export-authority-20260828from
codex/voice-loop-20260907-evidence
Draft

fix(voice): reject exports outside admitted Post endpoints#971
seonghobae wants to merge 4 commits into
fix/voice-export-authority-20260828from
codex/voice-loop-20260907-evidence

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 7, 2026

Copy link
Copy Markdown
Contributor

Voice exports admitted endpoints outside the authorized Post neighborhood and emitted additional assignments after their derivation evidence was absent. Validate admitted endpoint types and omit unsupported additional assignments completely in exact-value/CSV and JSON-LD projections, preserving imported primary Voices and genuine derivation evidence.

Validation on exact b6046c9c23f647abfd7b2436419c5b5b0db91bc5: the missing-evidence regression failed before repair; all 78 ontology neighborhood, ingestion, Voice authority, and SHACL tests passed afterward. Exact-head hosted Tests 34084370524 later completed GREEN. A prior same-head Draft-admission Tests run was skipped. Neither result changes stack governance or supplies independent approval.

Fresh review found no further defect in the three-file export repair, but also recorded that this child should remain Draft. The PR had nevertheless been left Ready while stacked on unmerged #780. It is now Draft again without changing the product head. Parent #780 must merge normally under protected governance before this child is retargeted/converged to main; then collect fresh exact-head/base checks, central security verdicts, and qualifying independent approval. Do not allocate Ready-state product lanes merely to wait behind an unmerged parent, and do not transfer the current hosted GREEN across that future base movement.

Authenticated candidate PostgreSQL/API acceptance, desktop/mobile rendered acceptance where applicable, and synthetic k6 saturation remain incomplete. No UI layout/copy, API shape, schema, release number, inference policy, or owner-boundary changes. #934/#968 retain page-accumulation ownership; #936/#937 retain history and read-authorization ownership. No self-approval, bypass, force-push, destructive rebase, or gate weakening.

@coderabbitai

coderabbitai Bot commented Sep 7, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Team

Run ID: 485e4d18-c261-4f81-8946-6280bcc8357b

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@seonghobae seonghobae added the bug Something isn't working label Sep 7, 2026 — with ChatGPT Codex Connector

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Exact-head review: the repair is causal and keeps Voice export authority inside the admitted ontology neighborhood. exact_value_rows() already rejects a carrying identifier that is not an admitted Post via the Post-label lookup; this head adds the missing evidence-Post validation. jsonld_document() now validates both carrying and evidence Post endpoints before emitting Voice assignment nodes. The new parametrized regression covers both projections and both endpoint roles, including the wrong-type-but-present Person case. I found no additional source defect in this three-file delta. Keep Draft: the current head only has Draft-skipped repository admission so far; authenticated PostgreSQL/API/rendered acceptance, current-head central gates, and qualifying independent approval remain non-transferable.

@seonghobae
seonghobae marked this pull request as ready for review September 7, 2026 04:46
@seonghobae
seonghobae marked this pull request as draft September 7, 2026 06:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working priority: medium

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant