feat: add optional Experiential Labs provider support - #1145
Conversation
|
Warning Review limit reachedNext included review available in 46 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (14)
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (12)
🚧 Files skipped from review as they are similar to previous changes (1)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughExperiential Labs를 모델 검색과 리뷰 풀에 연결했습니다. 선택적 API 자격 증명을 워크플로에 추가했습니다. 누출 검사는 허용된 자격 증명 목록과 미설정 환경 변수를 처리합니다. ZDR 증거는 명시적 부정 증거를 우선합니다. ChangesExperiential Labs 공급자 통합
Priority: ➖ Normal Estimated code review effort: 3 (Moderate) | ~25 minutes Change: Feature Sequence Diagram(s)sequenceDiagram
participant CatalogSync
participant collect_provider_credentials
participant discover_provider_models
participant ExperientialLabsAPI
participant build_review_orchestrator
CatalogSync->>collect_provider_credentials: 선택적 EXPeriental Labs 자격 증명 전달
collect_provider_credentials->>discover_provider_models: 자격 증명과 공급자 설정 전달
discover_provider_models->>ExperientialLabsAPI: /v1/models 요청
ExperientialLabsAPI-->>discover_provider_models: 모델 목록 반환
discover_provider_models-->>build_review_orchestrator: 모델과 증거 전달
build_review_orchestrator-->>CatalogSync: 리뷰 풀 입장 결과 반환
Merge Risk: ⚪ Minimal · up to Experiential models are consistently identified and excluded from free-only routing. No concrete merge-blocking defect remains in the reviewed changes. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
@coderabbitai review Please review current head 6e920bf. The previously reported included-review reset interval has elapsed; this is the first manual request for this head. |
|
✅ Action performedReview finished.
|
There was a problem hiding this comment.
Pull request overview
OpenCode reviewed the current-head product diff. Coverage is a separate gate.
Changed files
.github/workflows/provider-catalog-sync.yml— GitHub Actions review jobcontextual_orchestrator/model_discovery.py— Python module behaviorcontextual_orchestrator/review_gateway.py— Python module behaviordocs/doctoring/current-main-provider-bootstrap.md— operator or user guidancetests/test_experiential_provider.py— regression suitetests/test_experiential_review_admission.py— regression suitetests/test_provider_bootstrap_secret_normalization.py— regression suitetests/test_review_gateway_credential_array.py— regression suite
Changed behavior
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow: provider-catalog-sync.yml"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow: provider-catalog-sync.yml"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Python: model_discovery.py (2 files)"]
S2 --> I2["Python module behavior"]
I2 --> R2["Review risk: Python: model_discovery.py (2 files)"]
R2 --> V2["pytest plus coverage"]
Evidence --> S3["Docs: current-main-provider-bootstrap.md"]
S3 --> I3["operator or user guidance"]
I3 --> R3["Review risk: Docs: current-main-provider-bootstrap.md"]
R3 --> V3["docs review"]
Evidence --> S4["Test: test_experiential_provider.py (4 files)"]
S4 --> I4["regression suite"]
I4 --> R4["Review risk: Test: test_experiential_provider.py (4 files)"]
R4 --> V4["targeted test run"]
Findings
No source-backed product finding is synthesized from the coverage gate. A coverage miss belongs in the status comment.
- Head SHA:
6e920bf38ad4af4f26630b193de5e1eab7bf0896 - Workflow run: 34700567547
- Workflow attempt: 1
- Coverage gate:
failure
Review outcome
Coverage is a gate, not the review. This body reviews the changed product files.
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow: provider-catalog-sync.yml"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow: provider-catalog-sync.yml"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Python: model_discovery.py (2 files)"]
S2 --> I2["Python module behavior"]
I2 --> R2["Review risk: Python: model_discovery.py (2 files)"]
R2 --> V2["pytest plus coverage"]
Evidence --> S3["Docs: current-main-provider-bootstrap.md"]
S3 --> I3["operator or user guidance"]
I3 --> R3["Review risk: Docs: current-main-provider-bootstrap.md"]
R3 --> V3["docs review"]
Evidence --> S4["Test: test_experiential_provider.py (4 files)"]
S4 --> I4["regression suite"]
I4 --> R4["Review risk: Test: test_experiential_provider.py (4 files)"]
R4 --> V4["targeted test run"]
OpenCode Review Overview
Coverage evidence did not pass, so approval is blocked. The formal pull-request review is the source-backed diff review, not this status comment. |
|
Exact-head lifecycle/RCA receipt for Direct source review found no new paid/unknown-price admission in this delta: Experiential CodeQL PR run 34700018061 is terminal RED in all three compatibility shards. Exact logs show Moving this PR to Draft preserves the complete provider delta while the protected |
|
@coderabbitai review Please review current head The existing Draft lifecycle disposition remains in place. This request does not claim central coverage or CodeQL convergence, merge readiness, live ZDR admission, or consumer deployment. |
🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
echo '=== HEAD and delta ==='
git rev-parse HEAD
git diff --stat 6e920bf38ad4af4f26630b193de5e1eab7bf0896..HEAD
git diff --check 6e920bf38ad4af4f26630b193de5e1eab7bf0896..HEAD
git diff --unified=80 6e920bf38ad4af4f26630b193de5e1eab7bf0896..HEAD
echo '=== Issue 1153 ==='
gh issue view 1153 --repo ContextualWisdomLab/contextual-orchestrator --comments
echo '=== Touched Python function map ==='
changed_py=$(git diff --name-only 6e920bf38ad4af4f26630b193de5e1eab7bf0896..HEAD -- '*.py' || true)
if [ -n "$changed_py" ]; then
printf '%s\n' "$changed_py" | while IFS= read -r file; do
echo "--- $file ---"
ast-grep outline "$file" --items all --type function
done
fi
echo '=== Relevant docstring and test references ==='
rg -n -C 5 '"""|mocked transport|KV isolation|bootstrap|free-admission|experiential_labs|EXPERIENTIAL_LABS_API_KEY' tests/test_experiential_provider.py tests/test_experiential_review_admission.py 2>/dev/null || trueLength of output: 18171
The delta modifies only the two Experiential test files. It adds docstrings for every touched function and method. This includes fixtures, test functions, helper functions, the nested mock transport function, and
I found no actionable touched-function docstring issue in this exact-head delta. This focused result does not change the Draft lifecycle disposition or establish central coverage, CodeQL convergence, merge readiness, ZDR admission, or deployment status.
|
|
Security follow-up for exact head The separate RFC6598 validation gap was reproduced with the default empty host allowlist. Owner PR #1046 does not currently repair that branch; the exact reproduction and request for owner repair/delegation are linked at #1046 (comment) . No occupied owner code was changed. This preserves the Experiential provider delta and current Draft disposition. Neither a scanner's temporary-checkout fix nor the new repair PR establishes that this head is fixed, approved, released, or admitted for live free/ZDR routing. |
|
Offline integration acceptance: disposable merge Graphify 0.9.58 refreshed the affected local AST union (19 code files): 1632 nodes, 4129 clustered edges. Graph SHA-256 This supports compatibility between the pending repairs, not production admission. The reproduced cross-provider ZDR promotion (#971), default shared-address validation (#1046), organization require-ZDR confirmation, hosted review, immutable release and consumer verification remain unresolved. No live inference, secret access, protected merge or release occurred. PR branches were not changed by the disposable integration. |
There was a problem hiding this comment.
Pull request overview
OpenCode reviewed the current-head product diff. Coverage is a separate gate.
Changed files
.github/workflows/provider-catalog-sync.yml— GitHub Actions review jobcontextual_orchestrator/model_discovery.py— Python module behaviorcontextual_orchestrator/orchestrator.py— Python module behaviorcontextual_orchestrator/provider_catalog_store.py— Python module behaviorcontextual_orchestrator/review_gateway.py— Python module behaviordocs/doctoring/current-main-provider-bootstrap.md— operator or user guidancedocs/research/experiential-free-lane-admission.md— operator or user guidancetests/test_experiential_provider.py— regression suitetests/test_experiential_review_admission.py— regression suitetests/test_model_discovery.py— regression suitetests/test_provider_bootstrap_secret_normalization.py— regression suitetests/test_provider_catalog_store.py— regression suitetests/test_review_gateway_admission_contract_1106.py— regression suitetests/test_review_gateway_credential_array.py— regression suite
Changed behavior
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow: provider-catalog-sync.yml"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow: provider-catalog-sync.yml"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Python: model_discovery.py (4 files)"]
S2 --> I2["Python module behavior"]
I2 --> R2["Review risk: Python: model_discovery.py (4 files)"]
R2 --> V2["pytest plus coverage"]
Evidence --> S3["Docs: current-main-provider-bootstrap.md (2 files)"]
S3 --> I3["operator or user guidance"]
I3 --> R3["Review risk: Docs: current-main-provider-bootstrap.md (2 files)"]
R3 --> V3["docs review"]
Evidence --> S4["Test: test_experiential_provider.py (7 files)"]
S4 --> I4["regression suite"]
I4 --> R4["Review risk: Test: test_experiential_provider.py (7 files)"]
R4 --> V4["targeted test run"]
Findings
No source-backed product finding is synthesized from the coverage gate. A coverage miss belongs in the status comment.
- Head SHA:
a2f576be4e1cefd0293299dcc9d814b433836b4c - Workflow run: 34750116284
- Workflow attempt: 1
- Coverage gate:
failure
Review outcome
Coverage is a gate, not the review. This body reviews the changed product files.
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow: provider-catalog-sync.yml"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow: provider-catalog-sync.yml"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Python: model_discovery.py (4 files)"]
S2 --> I2["Python module behavior"]
I2 --> R2["Review risk: Python: model_discovery.py (4 files)"]
R2 --> V2["pytest plus coverage"]
Evidence --> S3["Docs: current-main-provider-bootstrap.md (2 files)"]
S3 --> I3["operator or user guidance"]
I3 --> R3["Review risk: Docs: current-main-provider-bootstrap.md (2 files)"]
R3 --> V3["docs review"]
Evidence --> S4["Test: test_experiential_provider.py (7 files)"]
S4 --> I4["regression suite"]
I4 --> R4["Review risk: Test: test_experiential_provider.py (7 files)"]
R4 --> V4["targeted test run"]
There was a problem hiding this comment.
Pull request overview
OpenCode reviewed the current-head product diff. Coverage is a separate gate.
Changed files
.github/workflows/provider-catalog-sync.yml— GitHub Actions review jobcontextual_orchestrator/model_discovery.py— Python module behaviorcontextual_orchestrator/orchestrator.py— Python module behaviorcontextual_orchestrator/provider_catalog_store.py— Python module behaviorcontextual_orchestrator/review_gateway.py— Python module behaviordocs/doctoring/current-main-provider-bootstrap.md— operator or user guidancedocs/research/experiential-free-lane-admission.md— operator or user guidancetests/test_experiential_provider.py— regression suitetests/test_experiential_review_admission.py— regression suitetests/test_model_discovery.py— regression suitetests/test_provider_bootstrap_secret_normalization.py— regression suitetests/test_provider_catalog_store.py— regression suitetests/test_review_gateway_admission_contract_1106.py— regression suitetests/test_review_gateway_credential_array.py— regression suite
Changed behavior
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow: provider-catalog-sync.yml"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow: provider-catalog-sync.yml"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Python: model_discovery.py (4 files)"]
S2 --> I2["Python module behavior"]
I2 --> R2["Review risk: Python: model_discovery.py (4 files)"]
R2 --> V2["pytest plus coverage"]
Evidence --> S3["Docs: current-main-provider-bootstrap.md (2 files)"]
S3 --> I3["operator or user guidance"]
I3 --> R3["Review risk: Docs: current-main-provider-bootstrap.md (2 files)"]
R3 --> V3["docs review"]
Evidence --> S4["Test: test_experiential_provider.py (7 files)"]
S4 --> I4["regression suite"]
I4 --> R4["Review risk: Test: test_experiential_provider.py (7 files)"]
R4 --> V4["targeted test run"]
Findings
No source-backed product finding is synthesized from the coverage gate. A coverage miss belongs in the status comment.
- Head SHA:
3f1ac5b89644888e4b0b5bcc99bd1bdfb939c0ed - Workflow run: 34750981485
- Workflow attempt: 1
- Coverage gate:
failure
Review outcome
Coverage is a gate, not the review. This body reviews the changed product files.
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow: provider-catalog-sync.yml"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow: provider-catalog-sync.yml"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Python: model_discovery.py (4 files)"]
S2 --> I2["Python module behavior"]
I2 --> R2["Review risk: Python: model_discovery.py (4 files)"]
R2 --> V2["pytest plus coverage"]
Evidence --> S3["Docs: current-main-provider-bootstrap.md (2 files)"]
S3 --> I3["operator or user guidance"]
I3 --> R3["Review risk: Docs: current-main-provider-bootstrap.md (2 files)"]
R3 --> V3["docs review"]
Evidence --> S4["Test: test_experiential_provider.py (7 files)"]
S4 --> I4["regression suite"]
I4 --> R4["Review risk: Test: test_experiential_provider.py (7 files)"]
R4 --> V4["targeted test run"]
There was a problem hiding this comment.
Noema LLM review
PR #1145 adds optional Experiential Labs provider support with fail-closed semantics across discovery, free-pool admission, ZDR evidence scoping, and workflow leak-guard handling. The change correctly keeps Promotional/zero-price Experiential rows out of free routes, treats conflicting ZDR tags as explicit no-ZDR, restricts OpenRouter ZDR attestation to its own rows, and preserves independently supplied privacy evidence. The updated catalog-sync leak guard tolerates optional secrets. New tests cover discovery, admission, persistence, conflict resolution, and the workflow guard. Verified probes found no regression, misuse, or security issue; the change is safe to merge.
Reviewed changed lines
contextual_orchestrator/model_discovery.py:1963 (RIGHT): The updated privacy_tags_for_discovered gates privacy:zdr on supports_zero_data_retention is not False, so explicit negative evidence vetoes a legacy positive zdr_capable marker. The conflict case (supports_zero_data_retention=False, zdr_capable=True) yields only ('privacy:no_zdr',), verified by test_conflicting_zdr_evidence_fails_closed.contextual_orchestrator/model_discovery.py:2187 (RIGHT): general_free_serving_candidates excludes all experiential_labs rows before the free-eligibility filter, preventing promotional zero prices from entering the general free pool even when discovery reports is_free=True. Test test_experiential_review_admission.py confirms free admission fails closed without lane evidence.contextual_orchestrator/provider_catalog_store.py:436 (RIGHT): _restore_model_semantics re-orders the ZDR tag evaluation so privacy:no_zdr takes precedence over privacy:zdr. Persisted contradictory tags now restore supports_zero_data_retention=False, matching the fail-closed intent. test_last_known_good_dual_zdr_tags_restore_fail_closed validates this..github/workflows/provider-catalog-sync.yml:153 (RIGHT): The leak guard now uses os.environ.get(name, '').rstrip(...), so an unset optional secret (e.g., EXPERIENTAL_LABS_API_KEY) evaluates to an empty string and is skipped without a KeyError. test_catalog_sync_leak_guard_rejects_optional_secret exercises the guard with missing environment variables and confirms correct pass/fail behavior.
Adversarial validation
contextual_orchestrator/model_discovery.py:1963 (RIGHT)falsified: The new privacy_tags_for_discovered condition could still emit privacy:zdr for a model carrying explicit negative evidence. — test_conflicting_zdr_evidence_fails_closed asserts privacy_tags_for_discovered(conflicted) == ('privacy:no_zdr',) for a model with supports_zero_data_retention=False and zdr_capable=True. The condition's short-circuit (is not False) prevents emission of privacy:zdr.contextual_orchestrator/model_discovery.py:2187 (RIGHT)falsified: Experiential promotional zero-price models might leak into the general free pool through general_free_serving_candidates. — The filter explicitly requires model.provider_name != 'experiential_labs' as the first conjunction. test_experiential_review_admission.py's test_experiential_labs_free_review_admission_fails_closed_without_lane_evidence shows build_review_orchestrator raises NotConfigured (no eligible zero-cost) when only experiential zero-price models are present.contextual_orchestrator/provider_catalog_store.py:436 (RIGHT)falsified: Persisted conflicting privacy:zdr/privacy:no_zdr tags could restore supports_zero_data_retention=True, defeating fail-closed behavior. — The re-ordered conditional checks 'privacy:no_zdr' first, restoring False when the negative tag is present. test_last_known_good_dual_zdr_tags_restore_fail_closed records such dual tags and asserts the restored supports_zero_data_retention is False..github/workflows/provider-catalog-sync.yml:153 (RIGHT)falsified: The leak guard referencing an optional secret name (EXPERIENTAL_LABS_API_KEY) would raise KeyError when that secret is unset in the environment. — The guard now uses os.environ.get(name, ''), and test_catalog_sync_leak_guard_rejects_optional_secret deletes every credential env var, runs the guard against '{}' without error, and only after setting the optional secret detects the leak and raises SystemExit deliberately.- Residual risk: The hosted Experiential Labs deployment revision is not independently verified against the pinned public source snapshot; pricing and free-only enforcement remain unverified for hosted routes. This is documented rather than asserted, and all admission paths fail closed when evidence is absent, so no blocking risk is identified.
Findings
- No blocking findings.
- Result: APPROVE
- Head SHA:
97857d8bdac4ef9b5297dba535b3bdc69a9786d8 - Reviewer credential:
noema-review-github-app-refresh - Actor:
cwl-noema-review[bot]
There was a problem hiding this comment.
Pull request overview
OpenCode reviewed the current-head product diff. Coverage is a separate gate.
Changed files
.github/workflows/provider-catalog-sync.yml— GitHub Actions review jobcontextual_orchestrator/model_discovery.py— Python module behaviorcontextual_orchestrator/orchestrator.py— Python module behaviorcontextual_orchestrator/provider_catalog_store.py— Python module behaviorcontextual_orchestrator/review_gateway.py— Python module behaviordocs/doctoring/current-main-provider-bootstrap.md— operator or user guidancedocs/research/experiential-free-lane-admission.md— operator or user guidancetests/test_experiential_provider.py— regression suitetests/test_experiential_review_admission.py— regression suitetests/test_model_discovery.py— regression suitetests/test_provider_bootstrap_secret_normalization.py— regression suitetests/test_provider_catalog_store.py— regression suitetests/test_review_gateway_admission_contract_1106.py— regression suitetests/test_review_gateway_credential_array.py— regression suite
Changed behavior
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow: provider-catalog-sync.yml"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow: provider-catalog-sync.yml"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Python: model_discovery.py (4 files)"]
S2 --> I2["Python module behavior"]
I2 --> R2["Review risk: Python: model_discovery.py (4 files)"]
R2 --> V2["pytest plus coverage"]
Evidence --> S3["Docs: current-main-provider-bootstrap.md (2 files)"]
S3 --> I3["operator or user guidance"]
I3 --> R3["Review risk: Docs: current-main-provider-bootstrap.md (2 files)"]
R3 --> V3["docs review"]
Evidence --> S4["Test: test_experiential_provider.py (7 files)"]
S4 --> I4["regression suite"]
I4 --> R4["Review risk: Test: test_experiential_provider.py (7 files)"]
R4 --> V4["targeted test run"]
Findings
No source-backed product finding is synthesized from the coverage gate. A coverage miss belongs in the status comment.
- Head SHA:
97857d8bdac4ef9b5297dba535b3bdc69a9786d8 - Workflow run: 34756709296
- Workflow attempt: 1
- Coverage gate:
failure
Review outcome
Coverage is a gate, not the review. This body reviews the changed product files.
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow: provider-catalog-sync.yml"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow: provider-catalog-sync.yml"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Python: model_discovery.py (4 files)"]
S2 --> I2["Python module behavior"]
I2 --> R2["Review risk: Python: model_discovery.py (4 files)"]
R2 --> V2["pytest plus coverage"]
Evidence --> S3["Docs: current-main-provider-bootstrap.md (2 files)"]
S3 --> I3["operator or user guidance"]
I3 --> R3["Review risk: Docs: current-main-provider-bootstrap.md (2 files)"]
R3 --> V3["docs review"]
Evidence --> S4["Test: test_experiential_provider.py (7 files)"]
S4 --> I4["regression suite"]
I4 --> R4["Review risk: Test: test_experiential_provider.py (7 files)"]
R4 --> V4["targeted test run"]
|
Local verification of exact head
🤖 Addressed by Claude Code |
|
Follow-up to the line above: the two interrogate misses at 🤖 Addressed by Claude Code |
Module docstrings were the last interrogate misses on the touched test files; every touched function and class was already documented. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
|
Ownership: the Codex session that drove this PR ended interrupted at 21:55 KST (no later activity), so this session is taking the branch over. Pushed 🤖 Addressed by Claude Code |
…s-provider-20260912
There was a problem hiding this comment.
Noema LLM review
The PR adds optional Experiential Labs provider support with discovery, bootstrap, workflow secret transport, and doc updates. The integration is generally well-tested and fail-closed, but the unconditional provider-name exclusion in _is_free_agent blocks paid Experiential agents from paid-fallback free routing, and the hard provider-name filter in general_free_serving_candidates permanently excludes all Experiential rows even with verifiable free-lane evidence, contradicting the documented evidence-based intent. A test gap exists around the accepted vs. required credential inventories.
Reviewed changed lines
contextual_orchestrator/orchestrator.py:8328 (RIGHT): Unconditionalagent.provider_name == "experiential_labs"guard excludes all Experiential agents from free-lane classification, including paid models with nonzero pricing, causing free-selector fallback to break.contextual_orchestrator/model_discovery.py:2191 (RIGHT): Provider-name filtermodel.provider_name != "experiential_labs"removes all Experiential rows from the free pool regardless of free-lane evidence, contradicting the documented evidence-based admission intent.tests/test_experiential_provider.py:74 (RIGHT): The test usesPROVIDER_CREDENTIAL_NAMESwithout asserting the subset relationship toPROVIDER_ACCEPTED_CREDENTIAL_NAMES, leaving the two inventories able to silently diverge.
Adversarial validation
contextual_orchestrator/orchestrator.py:8328 (RIGHT)confirmed: A paid Experiential Labs agent (price_per_million > 0) is excluded from free-lane classification, breaking paid fallback. — The unconditional provider-name guard returns False for every Experiential agent, and the testtest_experiential_labs_free_tags_cannot_reach_persisted_or_capability_routesasserts the resulting RuntimeError for the free lane.contextual_orchestrator/model_discovery.py:2191 (RIGHT)confirmed: An Experiential Labs model with explicit zero pricing and free-only evidence is still excluded from the free pool solely by provider name. — The added filtermodel.provider_name != "experiential_labs"drops the row regardless of pricing evidence, as verified by the changed line and the documented evidence-based admission intent.tests/test_experiential_provider.py:74 (RIGHT)confirmed: The optional key could silently appear in PROVIDER_CREDENTIAL_NAMES without any test catch it, causing a required-key bootstrap change. — The test imports only PROVIDER_CREDENTIAL_NAMES and does not validate the relationship to the new accepted inventory constant used by the workflow.- Residual risk: Even with the confirmed regression, the provider exclusion is intentional for promotional/free metadata; a fix could preserve the safety intent while restoring paid fallback behavior. The test gap is non-blocking but should be tightened.
Findings
- [high] contextual_orchestrator/orchestrator.py:8328 (RIGHT): The unconditional
agent.provider_name == "experiential_labs"guard in_is_free_agentexcludes all Experiential agents from free-lane classification, including paid models with nonzero pricing. This breaks paid fallback routing when only paid Experiential models are configured, causingno enabled zero-cost modelfailures. - [medium] contextual_orchestrator/model_discovery.py:2191 (RIGHT): The hard provider-name filter
model.provider_name != "experiential_labs"removes all Experiential rows from the free pool, even those with verifiable free-lane evidence, contradicting the documented evidence-based admission intent and preventing future verified free-only routes. - [medium] tests/test_experiential_provider.py:74 (RIGHT): The test asserts optional-key absence from
PROVIDER_CREDENTIAL_NAMESbut does not assert the relationship betweenPROVIDER_CREDENTIAL_NAMESand the newly introducedPROVIDER_ACCEPTED_CREDENTIAL_NAMES, allowing the required and accepted inventories to silently diverge.
- Result: REQUEST_CHANGES
- Head SHA:
fde504ce918b6a8437ef85cd086c4136073a5863 - Reviewer credential:
noema-review-github-app-refresh - Actor:
cwl-noema-review[bot]
There was a problem hiding this comment.
Pull request overview
OpenCode reviewed the current-head product diff. Coverage is a separate gate.
Changed files
.github/workflows/provider-catalog-sync.yml— GitHub Actions review jobcontextual_orchestrator/model_discovery.py— Python module behaviorcontextual_orchestrator/orchestrator.py— Python module behaviorcontextual_orchestrator/provider_catalog_store.py— Python module behaviorcontextual_orchestrator/review_gateway.py— Python module behaviordocs/doctoring/current-main-provider-bootstrap.md— operator or user guidancedocs/research/experiential-free-lane-admission.md— operator or user guidancetests/test_experiential_provider.py— regression suitetests/test_experiential_review_admission.py— regression suitetests/test_model_discovery.py— regression suitetests/test_provider_bootstrap_secret_normalization.py— regression suitetests/test_provider_catalog_store.py— regression suitetests/test_review_gateway_admission_contract_1106.py— regression suitetests/test_review_gateway_credential_array.py— regression suite
Changed behavior
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow: provider-catalog-sync.yml"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow: provider-catalog-sync.yml"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Python: model_discovery.py (4 files)"]
S2 --> I2["Python module behavior"]
I2 --> R2["Review risk: Python: model_discovery.py (4 files)"]
R2 --> V2["pytest plus coverage"]
Evidence --> S3["Docs: current-main-provider-bootstrap.md (2 files)"]
S3 --> I3["operator or user guidance"]
I3 --> R3["Review risk: Docs: current-main-provider-bootstrap.md (2 files)"]
R3 --> V3["docs review"]
Evidence --> S4["Test: test_experiential_provider.py (7 files)"]
S4 --> I4["regression suite"]
I4 --> R4["Review risk: Test: test_experiential_provider.py (7 files)"]
R4 --> V4["targeted test run"]
Findings
No source-backed product finding is synthesized from the coverage gate. A coverage miss belongs in the status comment.
- Head SHA:
fde504ce918b6a8437ef85cd086c4136073a5863 - Workflow run: 34768160673
- Workflow attempt: 1
- Coverage gate:
failure
Review outcome
Coverage is a gate, not the review. This body reviews the changed product files.
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow: provider-catalog-sync.yml"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow: provider-catalog-sync.yml"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Python: model_discovery.py (4 files)"]
S2 --> I2["Python module behavior"]
I2 --> R2["Review risk: Python: model_discovery.py (4 files)"]
R2 --> V2["pytest plus coverage"]
Evidence --> S3["Docs: current-main-provider-bootstrap.md (2 files)"]
S3 --> I3["operator or user guidance"]
I3 --> R3["Review risk: Docs: current-main-provider-bootstrap.md (2 files)"]
R3 --> V3["docs review"]
Evidence --> S4["Test: test_experiential_provider.py (7 files)"]
S4 --> I4["regression suite"]
I4 --> R4["Review risk: Test: test_experiential_provider.py (7 files)"]
R4 --> V4["targeted test run"]
There was a problem hiding this comment.
Pull request overview
OpenCode reviewed the current-head product diff. Coverage is a separate gate.
Changed files
.github/workflows/provider-catalog-sync.yml— GitHub Actions review jobcontextual_orchestrator/model_discovery.py— Python module behaviorcontextual_orchestrator/orchestrator.py— Python module behaviorcontextual_orchestrator/provider_catalog_store.py— Python module behaviorcontextual_orchestrator/review_gateway.py— Python module behaviordocs/doctoring/current-main-provider-bootstrap.md— operator or user guidancedocs/research/experiential-free-lane-admission.md— operator or user guidancetests/test_experiential_provider.py— regression suitetests/test_experiential_review_admission.py— regression suitetests/test_model_discovery.py— regression suitetests/test_provider_bootstrap_secret_normalization.py— regression suitetests/test_provider_catalog_store.py— regression suitetests/test_review_gateway_admission_contract_1106.py— regression suitetests/test_review_gateway_credential_array.py— regression suite
Changed behavior
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow: provider-catalog-sync.yml"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow: provider-catalog-sync.yml"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Python: model_discovery.py (4 files)"]
S2 --> I2["Python module behavior"]
I2 --> R2["Review risk: Python: model_discovery.py (4 files)"]
R2 --> V2["pytest plus coverage"]
Evidence --> S3["Docs: current-main-provider-bootstrap.md (2 files)"]
S3 --> I3["operator or user guidance"]
I3 --> R3["Review risk: Docs: current-main-provider-bootstrap.md (2 files)"]
R3 --> V3["docs review"]
Evidence --> S4["Test: test_experiential_provider.py (7 files)"]
S4 --> I4["regression suite"]
I4 --> R4["Review risk: Test: test_experiential_provider.py (7 files)"]
R4 --> V4["targeted test run"]
Findings
No source-backed product finding is synthesized from the coverage gate. A coverage miss belongs in the status comment.
- Head SHA:
fde504ce918b6a8437ef85cd086c4136073a5863 - Workflow run: 34832272879
- Workflow attempt: 1
- Coverage gate:
failure
Review outcome
Coverage is a gate, not the review. This body reviews the changed product files.
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow: provider-catalog-sync.yml"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow: provider-catalog-sync.yml"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Python: model_discovery.py (4 files)"]
S2 --> I2["Python module behavior"]
I2 --> R2["Review risk: Python: model_discovery.py (4 files)"]
R2 --> V2["pytest plus coverage"]
Evidence --> S3["Docs: current-main-provider-bootstrap.md (2 files)"]
S3 --> I3["operator or user guidance"]
I3 --> R3["Review risk: Docs: current-main-provider-bootstrap.md (2 files)"]
R3 --> V3["docs review"]
Evidence --> S4["Test: test_experiential_provider.py (7 files)"]
S4 --> I4["regression suite"]
I4 --> R4["Review risk: Test: test_experiential_provider.py (7 files)"]
R4 --> V4["targeted test run"]
Resolve the sole conflict in test_model_discovery by keeping main's discovery-deadline regressions and the PR's provider-scoped ZDR coverage. Co-authored-by: Cursor <cursoragent@cursor.com>
Main uses _DISCOVERY_RETRY_TIMEOUT_SECONDS in the bounded retry helper but dropped its definition; keep the PR's 5.0s cap so explicit caller budgets stay enforceable. Co-authored-by: Cursor <cursoragent@cursor.com>
Add Experiential Labs as an optional KV-backed provider using the exact registered Secret
EXPERIENTAL_LABS_API_KEY. Bootstrap transports the key to the registry; discovery uses Bearer authentication athttps://api.experientiallabs.ai/v1/models. Missing optional credentials are tolerated. Experiential remains available for ordinary routing, but promotional zero prices do not prove free-only execution: discovery-time free selection and persisted/capability free routing reject Experiential until enforceable free-only routing is available. The authenticated model UI showed account-wide paid overflow enabled; no paid inference was made.ZDR evidence stays scoped to each model and provider. OpenRouter evidence cannot grant Experiential or NIM ZDR through a matching model name. Explicit non-ZDR evidence now vetoes a legacy positive ZDR marker; persisted dual tags restore as non-ZDR, and require-ZDR requests reject contradictory tags. Policy-disabled requests retain normal eligibility. This fixes the demonstrated tag-generation, catalog-restoration and request-filter conflict without claiming remote organization enforcement. The public review-admission function also imports its missing
Anyannotation dependency.Follow-up
3f1ac5b8repairs the hosted credential-array expectation: registered Experiential credentials remain in KV while the free pool rejects unverified promotional routes. The original test failed (1 failed, 17 passed); the repaired credential-array suite passed all 18 tests and Ruff. At this exact head, hosted Tests and package quality passed 3613 tests with 2 optional skips, plus 134 benchmark tests. Local canonicaltests/finished with 3612 passed, 2 skipped and one intermittent commercial-proposal HTTP timeout; the isolated test passed, but this does not resolve the full-suite failure. Existing PR #1167 owns the relevant HTTP resource cleanup; its commercial-proposal module passed 2 tests in an isolated checkout. The optional mocked MCP test passed with MCP 2.2.0 (1 test); the official SDK wheel SHA-256 and all 128 hashed RECORD files match the isolated installation. A deployment-owned hash lock for MCP-specific transitive dependencies remains outstanding; this is not release packaging acceptance.Prior validation at
a2f576be4e1cefd0293299dcc9d814b433836b4c: 208 focused tests passed in 3.82s and Ruff passed. Regression covers persisted promotional free tags, capability-scoped free rejection and ordinary named capability success. Raw log:graphify-out/free-lane-regression-final.log. Earlier mixed-ZDR RED evidence was tool stdout only. Local integration with full PR #1162/#1163 ancestry at8d6e26e7c76d32d37366924022a378ca042a722dpassed 311 focused tests; this is not hosted or release validation.Graphify 0.9.58 local AST was incrementally updated on the local integration candidate. Final graph SHA-256
a319456dedf9d187c884087dd7496627376c5f8c970a5b32d844db00bf8d16bc; report278853497a266dd94f3cb509dd00f7df1f9732eb29841ec51da1dedafb27671f. An earlier hash was captured before asynchronous post-processing finished and is superseded. SQL extraction remains unavailable and Cargo.toml emitted no nodes; this is partial AST evidence, not runtime enforcement proof.Authenticated organization UI: prompt-content Private mode is enabled, while usage metadata is retained. The documented
/settings/data-controlspage returns 404. Neither observation establishes upstream require-ZDR routing. A credit-overflow button was inadvertently toggled during inspection and immediately restored to its original enabled state, confirmed by visible UI; no inference request occurred.Release remains incomplete: exact model/deployment/account ZDR evidence, organization require-ZDR enforcement, accessible free routes, central integration issue ContextualWisdomLab/.github#2119, security repairs #1046/#1163, current-head hosted checks/review, immutable release and consumer acceptance. No live inference, deployment, merge or repair of late-life-anxiety-reanalysis#10 is claimed. Previous-head hosted results do not satisfy current-head gates.
Official references: Authentication, API reference, Models, checked September 12–13, 2026. Catalog retention verdicts describe routed platform-funded lanes; they do not prove organization enforcement, BYOK or arbitrary waterfall overrides.
Current review result: Noema run 34750904362/job 103707389778 failed during model-output validation: request_changes lacked a confirmed probe on a published finding. This is neither a confirmed source finding nor a bootstrap outage. Strix remains pending; CodeQL compatibility and OpenCode failures remain unresolved.
Latest local integration head
aabe1d9cf1118fd6832e18d83590129399464df3passed the 18 credential-array tests. Its full graph incremental update refused shrinkage, leaving the previous full graph stale. A fresh focused Graphify graph covering provider discovery, review admission, orchestration and related tests has SHA-2569a2a02588018bfd2d7bf254dd1ae6be1da8bf1b2d5cdaba13162754a0393c6ef; reportd4d349d67104e812ac4f1f3b93b9246f39df096be4d2ecbb99be3c7dfe2469e9. The five reported cross-community candidates were reviewed as expected test/type coupling; this partial scope is not whole-repository structural approval.The consumer owner merged late-life-anxiety-reanalysis#10 at
3f7a77526211d9654263aba9036d3facc5809ab2. That separate merge does not establish Experiential ZDR enforcement or this provider release.Summary by CodeRabbit
새로운 기능
개선 사항
문서