Skip to content

feat: add optional Experiential Labs provider support - #1145

Merged
seonghobae merged 20 commits into
mainfrom
feat/experiential-labs-provider-20260912
Sep 17, 2026
Merged

seonghobae merged 20 commits into
mainfrom
feat/experiential-labs-provider-20260912

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 12, 2026 •

Copy link
Copy Markdown
Contributor

Add Experiential Labs as an optional KV-backed provider using the exact registered Secret EXPERIENTAL_LABS_API_KEY. Bootstrap transports the key to the registry; discovery uses Bearer authentication at https://api.experientiallabs.ai/v1/models. Missing optional credentials are tolerated. Experiential remains available for ordinary routing, but promotional zero prices do not prove free-only execution: discovery-time free selection and persisted/capability free routing reject Experiential until enforceable free-only routing is available. The authenticated model UI showed account-wide paid overflow enabled; no paid inference was made.

ZDR evidence stays scoped to each model and provider. OpenRouter evidence cannot grant Experiential or NIM ZDR through a matching model name. Explicit non-ZDR evidence now vetoes a legacy positive ZDR marker; persisted dual tags restore as non-ZDR, and require-ZDR requests reject contradictory tags. Policy-disabled requests retain normal eligibility. This fixes the demonstrated tag-generation, catalog-restoration and request-filter conflict without claiming remote organization enforcement. The public review-admission function also imports its missing Any annotation dependency.

Follow-up 3f1ac5b8 repairs the hosted credential-array expectation: registered Experiential credentials remain in KV while the free pool rejects unverified promotional routes. The original test failed (1 failed, 17 passed); the repaired credential-array suite passed all 18 tests and Ruff. At this exact head, hosted Tests and package quality passed 3613 tests with 2 optional skips, plus 134 benchmark tests. Local canonical tests/ finished with 3612 passed, 2 skipped and one intermittent commercial-proposal HTTP timeout; the isolated test passed, but this does not resolve the full-suite failure. Existing PR #1167 owns the relevant HTTP resource cleanup; its commercial-proposal module passed 2 tests in an isolated checkout. The optional mocked MCP test passed with MCP 2.2.0 (1 test); the official SDK wheel SHA-256 and all 128 hashed RECORD files match the isolated installation. A deployment-owned hash lock for MCP-specific transitive dependencies remains outstanding; this is not release packaging acceptance.

Prior validation at a2f576be4e1cefd0293299dcc9d814b433836b4c: 208 focused tests passed in 3.82s and Ruff passed. Regression covers persisted promotional free tags, capability-scoped free rejection and ordinary named capability success. Raw log: graphify-out/free-lane-regression-final.log. Earlier mixed-ZDR RED evidence was tool stdout only. Local integration with full PR #1162/#1163 ancestry at 8d6e26e7c76d32d37366924022a378ca042a722d passed 311 focused tests; this is not hosted or release validation.

Graphify 0.9.58 local AST was incrementally updated on the local integration candidate. Final graph SHA-256 a319456dedf9d187c884087dd7496627376c5f8c970a5b32d844db00bf8d16bc; report 278853497a266dd94f3cb509dd00f7df1f9732eb29841ec51da1dedafb27671f. An earlier hash was captured before asynchronous post-processing finished and is superseded. SQL extraction remains unavailable and Cargo.toml emitted no nodes; this is partial AST evidence, not runtime enforcement proof.

Authenticated organization UI: prompt-content Private mode is enabled, while usage metadata is retained. The documented /settings/data-controls page returns 404. Neither observation establishes upstream require-ZDR routing. A credit-overflow button was inadvertently toggled during inspection and immediately restored to its original enabled state, confirmed by visible UI; no inference request occurred.

Release remains incomplete: exact model/deployment/account ZDR evidence, organization require-ZDR enforcement, accessible free routes, central integration issue ContextualWisdomLab/.github#2119, security repairs #1046/#1163, current-head hosted checks/review, immutable release and consumer acceptance. No live inference, deployment, merge or repair of late-life-anxiety-reanalysis#10 is claimed. Previous-head hosted results do not satisfy current-head gates.

Official references: Authentication, API reference, Models, checked September 12–13, 2026. Catalog retention verdicts describe routed platform-funded lanes; they do not prove organization enforcement, BYOK or arbitrary waterfall overrides.

Current review result: Noema run 34750904362/job 103707389778 failed during model-output validation: request_changes lacked a confirmed probe on a published finding. This is neither a confirmed source finding nor a bootstrap outage. Strix remains pending; CodeQL compatibility and OpenCode failures remain unresolved.

Latest local integration head aabe1d9cf1118fd6832e18d83590129399464df3 passed the 18 credential-array tests. Its full graph incremental update refused shrinkage, leaving the previous full graph stale. A fresh focused Graphify graph covering provider discovery, review admission, orchestration and related tests has SHA-256 9a2a02588018bfd2d7bf254dd1ae6be1da8bf1b2d5cdaba13162754a0393c6ef; report d4d349d67104e812ac4f1f3b93b9246f39df096be4d2ecbb99be3c7dfe2469e9. The five reported cross-community candidates were reviewed as expected test/type coupling; this partial scope is not whole-repository structural approval.

The consumer owner merged late-life-anxiety-reanalysis#10 at 3f7a77526211d9654263aba9036d3facc5809ab2. That separate merge does not establish Experiential ZDR enforcement or this provider release.

Summary by CodeRabbit

  • 새로운 기능

    • Experiential Labs 모델 제공자를 선택적으로 연동할 수 있습니다.
    • 모델 검색 및 리뷰 풀 후보 등록을 지원합니다.
  • 개선 사항

    • 무료 모델 여부를 명확한 무료 제공 계약에 따라 판단하도록 강화했습니다.
    • ZDR(제로 데이터 보존) 요청에서 명시적으로 검증된 모델만 허용합니다.
    • 가격·개인정보 보호 정보가 확인되지 않은 모델은 보수적으로 처리합니다.
  • 문서

    • Experiential Labs 설정, 인증 및 무료·개인정보 보호 정책을 안내하는 문서를 추가했습니다.

@coderabbitai

coderabbitai Bot commented Sep 12, 2026 •

Copy link
Copy Markdown

Review Change StackReview Change Stack

Warning

Review limit reached

Next included review available in 46 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 977f4269-2d19-4c7c-b07e-63c209efeeb9

📥 Commits

Reviewing files that changed from the base of the PR and between 2c99f7e and 29e2c4a.

📒 Files selected for processing (14)
  • .github/workflows/provider-catalog-sync.yml
  • contextual_orchestrator/model_discovery.py
  • contextual_orchestrator/orchestrator.py
  • contextual_orchestrator/provider_catalog_store.py
  • contextual_orchestrator/review_gateway.py
  • docs/doctoring/current-main-provider-bootstrap.md
  • docs/research/experiential-free-lane-admission.md
  • tests/test_experiential_provider.py
  • tests/test_experiential_review_admission.py
  • tests/test_model_discovery.py
  • tests/test_provider_bootstrap_secret_normalization.py
  • tests/test_provider_catalog_store.py
  • tests/test_review_gateway_admission_contract_1106.py
  • tests/test_review_gateway_credential_array.py

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 66bca199-3989-4c40-afef-77cd768a9787

📥 Commits

Reviewing files that changed from the base of the PR and between 4703596 and 2c99f7e.

📒 Files selected for processing (12)
  • contextual_orchestrator/model_discovery.py
  • contextual_orchestrator/orchestrator.py
  • contextual_orchestrator/provider_catalog_store.py
  • contextual_orchestrator/review_gateway.py
  • docs/doctoring/current-main-provider-bootstrap.md
  • docs/research/experiential-free-lane-admission.md
  • tests/test_experiential_provider.py
  • tests/test_experiential_review_admission.py
  • tests/test_model_discovery.py
  • tests/test_provider_catalog_store.py
  • tests/test_review_gateway_admission_contract_1106.py
  • tests/test_review_gateway_credential_array.py
🚧 Files skipped from review as they are similar to previous changes (1)
  • docs/doctoring/current-main-provider-bootstrap.md

Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

Experiential Labs를 모델 검색과 리뷰 풀에 연결했습니다. 선택적 API 자격 증명을 워크플로에 추가했습니다. 누출 검사는 허용된 자격 증명 목록과 미설정 환경 변수를 처리합니다. ZDR 증거는 명시적 부정 증거를 우선합니다.

Changes

Experiential Labs 공급자 통합

Layer / File(s) Summary
공급자 검색 등록 및 증거 범위
contextual_orchestrator/model_discovery.py, contextual_orchestrator/orchestrator.py, contextual_orchestrator/provider_catalog_store.py, tests/test_experiential_provider.py, tests/test_model_discovery.py, tests/test_provider_catalog_store.py, docs/doctoring/current-main-provider-bootstrap.md, docs/research/experiential-free-lane-admission.md
experiential_labs 검색 설정과 EXPERIENTAL_LABS_API_KEY를 추가했습니다. 가격과 개인정보 보호 증거가 없으면 알 수 없는 상태로 유지합니다. Experiential Labs 모델은 일반 무료 후보에서 제외합니다. privacy:no_zdr가 privacy:zdr보다 우선합니다.
무료 리뷰 풀 승인
contextual_orchestrator/review_gateway.py, tests/test_experiential_review_admission.py, tests/test_review_gateway_credential_array.py, tests/test_review_gateway_admission_contract_1106.py
Experiential Labs 자격 증명을 등록했습니다. 명시적 무료 계약과 모델별 ZDR 증거가 없는 모델의 입장을 거부하는 동작을 검증했습니다. 공개 리뷰 풀 입장 함수의 타입 힌트 해석도 검증했습니다.
선택적 자격 증명과 누출 검사
.github/workflows/provider-catalog-sync.yml, tests/test_provider_bootstrap_secret_normalization.py
워크플로에 선택적 API 자격 증명 매핑을 추가했습니다. 누출 검사 대상을 PROVIDER_ACCEPTED_CREDENTIAL_NAMES로 변경하고 미설정 환경 변수를 안전하게 처리했습니다. 선택적 시크릿의 보고서 누출 회귀 테스트를 추가했습니다.

Priority: ➖ Normal

Estimated code review effort: 3 (Moderate) | ~25 minutes

Change: Feature

Sequence Diagram(s)

sequenceDiagram
  participant CatalogSync
  participant collect_provider_credentials
  participant discover_provider_models
  participant ExperientialLabsAPI
  participant build_review_orchestrator
  CatalogSync->>collect_provider_credentials: 선택적 EXPeriental Labs 자격 증명 전달
  collect_provider_credentials->>discover_provider_models: 자격 증명과 공급자 설정 전달
  discover_provider_models->>ExperientialLabsAPI: /v1/models 요청
  ExperientialLabsAPI-->>discover_provider_models: 모델 목록 반환
  discover_provider_models-->>build_review_orchestrator: 모델과 증거 전달
  build_review_orchestrator-->>CatalogSync: 리뷰 풀 입장 결과 반환
Loading

Merge Risk: ⚪ Minimal · up to 2c99f

Experiential models are consistently identified and excluded from free-only routing. No concrete merge-blocking defect remains in the reviewed changes.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed 제목은 선택적 Experiential Labs 프로바이더 지원 추가라는 PR의 주요 변경 사항을 정확하고 간결하게 설명합니다.
Docstring Coverage ✅ Passed Docstring coverage is 96.77% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 31 functions across 10 files. (3 skipped: 2…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@seonghobae

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

Please review current head 6e920bf. The previously reported included-review reset interval has elapsed; this is the first manual request for this head.

@coderabbitai

coderabbitai Bot commented Sep 12, 2026 •

Copy link
Copy Markdown

@seonghobae I will review pull request #1145 at commit 6e920bf38ad4af4f26630b193de5e1eab7bf0896.

✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode reviewed the current-head product diff. Coverage is a separate gate.

Changed files

  • .github/workflows/provider-catalog-sync.yml — GitHub Actions review job
  • contextual_orchestrator/model_discovery.py — Python module behavior
  • contextual_orchestrator/review_gateway.py — Python module behavior
  • docs/doctoring/current-main-provider-bootstrap.md — operator or user guidance
  • tests/test_experiential_provider.py — regression suite
  • tests/test_experiential_review_admission.py — regression suite
  • tests/test_provider_bootstrap_secret_normalization.py — regression suite
  • tests/test_review_gateway_credential_array.py — regression suite

Changed behavior

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Workflow: provider-catalog-sync.yml"]
  S1 --> I1["GitHub Actions review job"]
  I1 --> R1["Review risk: Workflow: provider-catalog-sync.yml"]
  R1 --> V1["actionlint plus required checks"]
  Evidence --> S2["Python: model_discovery.py (2 files)"]
  S2 --> I2["Python module behavior"]
  I2 --> R2["Review risk: Python: model_discovery.py (2 files)"]
  R2 --> V2["pytest plus coverage"]
  Evidence --> S3["Docs: current-main-provider-bootstrap.md"]
  S3 --> I3["operator or user guidance"]
  I3 --> R3["Review risk: Docs: current-main-provider-bootstrap.md"]
  R3 --> V3["docs review"]
  Evidence --> S4["Test: test_experiential_provider.py (4 files)"]
  S4 --> I4["regression suite"]
  I4 --> R4["Review risk: Test: test_experiential_provider.py (4 files)"]
  R4 --> V4["targeted test run"]
Loading

Findings

No source-backed product finding is synthesized from the coverage gate. A coverage miss belongs in the status comment.

  • Head SHA: 6e920bf38ad4af4f26630b193de5e1eab7bf0896
  • Workflow run: 34700567547
  • Workflow attempt: 1
  • Coverage gate: failure

Review outcome

Coverage is a gate, not the review. This body reviews the changed product files.

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Workflow: provider-catalog-sync.yml"]
  S1 --> I1["GitHub Actions review job"]
  I1 --> R1["Review risk: Workflow: provider-catalog-sync.yml"]
  R1 --> V1["actionlint plus required checks"]
  Evidence --> S2["Python: model_discovery.py (2 files)"]
  S2 --> I2["Python module behavior"]
  I2 --> R2["Review risk: Python: model_discovery.py (2 files)"]
  R2 --> V2["pytest plus coverage"]
  Evidence --> S3["Docs: current-main-provider-bootstrap.md"]
  S3 --> I3["operator or user guidance"]
  I3 --> R3["Review risk: Docs: current-main-provider-bootstrap.md"]
  R3 --> V3["docs review"]
  Evidence --> S4["Test: test_experiential_provider.py (4 files)"]
  S4 --> I4["regression suite"]
  I4 --> R4["Review risk: Test: test_experiential_provider.py (4 files)"]
  R4 --> V4["targeted test run"]
Loading

@opencode-agent

opencode-agent Bot commented Sep 12, 2026 •

Copy link
Copy Markdown
Contributor

OpenCode Review Overview

Coverage evidence did not pass, so approval is blocked. The formal pull-request review is the source-backed diff review, not this status comment.

Copy link
Copy Markdown
Contributor Author

Exact-head lifecycle/RCA receipt for 6e920bf38ad4af4f26630b193de5e1eab7bf0896 (2026-09-13).

Direct source review found no new paid/unknown-price admission in this delta: Experiential /v1/models rows have no price evidence and therefore remain is_free=False; the review pool retains the existing CO-owned general_free_serving_candidates fail-closed selector plus registered-credential boundary. This is not an approval.

CodeQL PR run 34700018061 is terminal RED in all three compatibility shards. Exact logs show DISPATCH_OUTCOME=success and VERDICT_STATE=pending, followed by CodeQL scan dispatched... and exit 1. Semgrep, Security and Quality, and Security Scan are GREEN, but a dispatched/nonterminal central verdict is not exact-head terminal GREEN. OpenCode submitted COMMENTED/COVERAGE_BLOCKED, and independent APPROVED reviews remain zero.

Moving this PR to Draft preserves the complete provider delta while the protected .github CodeQL lifecycle publishes and replays authenticated terminal verdicts. Do not reuse predecessor/source-only GREEN or infer product-source failure from this central lifecycle state.

@seonghobae

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

Please review current head 31fc591db51d4a05b631d636a911b3876faa8dec, specifically the touched-function docstring warning tracked in #1153. This is the first manual request for this head; the previous request and completed response were for 6e920bf3. The two added test files now document their mocked transport, KV isolation, bootstrap and free-admission contracts. Relevant tests pass (4); this does not substitute for your touched-function check.

The existing Draft lifecycle disposition remains in place. This request does not claim central coverage or CodeQL convergence, merge readiness, live ZDR admission, or consumer deployment.

@coderabbitai

coderabbitai Bot commented Sep 12, 2026 •

Copy link
Copy Markdown
🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo '=== HEAD and delta ==='
git rev-parse HEAD
git diff --stat 6e920bf38ad4af4f26630b193de5e1eab7bf0896..HEAD
git diff --check 6e920bf38ad4af4f26630b193de5e1eab7bf0896..HEAD
git diff --unified=80 6e920bf38ad4af4f26630b193de5e1eab7bf0896..HEAD

echo '=== Issue 1153 ==='
gh issue view 1153 --repo ContextualWisdomLab/contextual-orchestrator --comments

echo '=== Touched Python function map ==='
changed_py=$(git diff --name-only 6e920bf38ad4af4f26630b193de5e1eab7bf0896..HEAD -- '*.py' || true)
if [ -n "$changed_py" ]; then
  printf '%s\n' "$changed_py" | while IFS= read -r file; do
    echo "--- $file ---"
    ast-grep outline "$file" --items all --type function
  done
fi

echo '=== Relevant docstring and test references ==='
rg -n -C 5 '"""|mocked transport|KV isolation|bootstrap|free-admission|experiential_labs|EXPERIENTIAL_LABS_API_KEY' tests/test_experiential_provider.py tests/test_experiential_review_admission.py 2>/dev/null || true

Length of output: 18171


@seonghobae I reviewed commit 31fc591db51d4a05b631d636a911b3876faa8dec for #1153.

The delta modifies only the two Experiential test files. It adds docstrings for every touched function and method. This includes fixtures, test functions, helper functions, the nested mock transport function, and _Response methods.

git diff --check also completed with no output.

I found no actionable touched-function docstring issue in this exact-head delta. This focused result does not change the Draft lifecycle disposition or establish central coverage, CodeQL convergence, merge readiness, ZDR admission, or deployment status.

⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@seonghobae

Copy link
Copy Markdown
Contributor Author

Security follow-up for exact head 31fc591db51d4a05b631d636a911b3876faa8dec: the Strix run is not merely a workflow outage. Its active provider-content finding was reproduced through the authenticated production HTTP boundary. The canonical shared-writer repair is now PR #1163 at 21499a98122e7400bce320d6fcea13a9bb430bfd with 54 local HTTP/file tests passing; it still requires review, CI and integration. Issue #1161 tracks the finding.

The separate RFC6598 validation gap was reproduced with the default empty host allowlist. Owner PR #1046 does not currently repair that branch; the exact reproduction and request for owner repair/delegation are linked at #1046 (comment) . No occupied owner code was changed.

This preserves the Experiential provider delta and current Draft disposition. Neither a scanner's temporary-checkout fix nor the new repair PR establishes that this head is fixed, approved, released, or admitted for live free/ZDR routing.

@seonghobae

Copy link
Copy Markdown
Contributor Author

Offline integration acceptance: disposable merge 8b9cf9140b450fd60638835c067545a781c33030 combines this PR at 2aa520590c2ad4ce3a5e0cb83a5b12e63385585f with input-count PR #1162 (db94d48d) and binary-content PR #1163 (21499a98). The merge was conflict-free. Seven existing focused suites passed 115 tests in 10.03s on the identical pre-commit tree: Experiential discovery/admission, bootstrap secret normalization, review-gateway credential arrays, multimodal HTTP, files, and API contracts.

Graphify 0.9.58 refreshed the affected local AST union (19 code files): 1632 nodes, 4129 clustered edges. Graph SHA-256 5f1be510c094c6a0bf2f49eafb5e559921a34378b6c40309e4554b1868427a1f; report 5bf70ae0fed477af4b4b5e1104c1252567062b02a14520d412cc0aa38e572f14. The five displayed surprising relationships concern existing credential-isolation fixtures and provider error/request-size tests; original sources were checked. This is partial structural evidence; workflow/document semantics and a full relation audit are not verified.

This supports compatibility between the pending repairs, not production admission. The reproduced cross-provider ZDR promotion (#971), default shared-address validation (#1046), organization require-ZDR confirmation, hosted review, immutable release and consumer verification remain unresolved. No live inference, secret access, protected merge or release occurred. PR branches were not changed by the disposable integration.

@seonghobae
seonghobae marked this pull request as ready for review September 13, 2026 08:49

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode reviewed the current-head product diff. Coverage is a separate gate.

Changed files

  • .github/workflows/provider-catalog-sync.yml — GitHub Actions review job
  • contextual_orchestrator/model_discovery.py — Python module behavior
  • contextual_orchestrator/orchestrator.py — Python module behavior
  • contextual_orchestrator/provider_catalog_store.py — Python module behavior
  • contextual_orchestrator/review_gateway.py — Python module behavior
  • docs/doctoring/current-main-provider-bootstrap.md — operator or user guidance
  • docs/research/experiential-free-lane-admission.md — operator or user guidance
  • tests/test_experiential_provider.py — regression suite
  • tests/test_experiential_review_admission.py — regression suite
  • tests/test_model_discovery.py — regression suite
  • tests/test_provider_bootstrap_secret_normalization.py — regression suite
  • tests/test_provider_catalog_store.py — regression suite
  • tests/test_review_gateway_admission_contract_1106.py — regression suite
  • tests/test_review_gateway_credential_array.py — regression suite

Changed behavior

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Workflow: provider-catalog-sync.yml"]
  S1 --> I1["GitHub Actions review job"]
  I1 --> R1["Review risk: Workflow: provider-catalog-sync.yml"]
  R1 --> V1["actionlint plus required checks"]
  Evidence --> S2["Python: model_discovery.py (4 files)"]
  S2 --> I2["Python module behavior"]
  I2 --> R2["Review risk: Python: model_discovery.py (4 files)"]
  R2 --> V2["pytest plus coverage"]
  Evidence --> S3["Docs: current-main-provider-bootstrap.md (2 files)"]
  S3 --> I3["operator or user guidance"]
  I3 --> R3["Review risk: Docs: current-main-provider-bootstrap.md (2 files)"]
  R3 --> V3["docs review"]
  Evidence --> S4["Test: test_experiential_provider.py (7 files)"]
  S4 --> I4["regression suite"]
  I4 --> R4["Review risk: Test: test_experiential_provider.py (7 files)"]
  R4 --> V4["targeted test run"]
Loading

Findings

No source-backed product finding is synthesized from the coverage gate. A coverage miss belongs in the status comment.

  • Head SHA: a2f576be4e1cefd0293299dcc9d814b433836b4c
  • Workflow run: 34750116284
  • Workflow attempt: 1
  • Coverage gate: failure

Review outcome

Coverage is a gate, not the review. This body reviews the changed product files.

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Workflow: provider-catalog-sync.yml"]
  S1 --> I1["GitHub Actions review job"]
  I1 --> R1["Review risk: Workflow: provider-catalog-sync.yml"]
  R1 --> V1["actionlint plus required checks"]
  Evidence --> S2["Python: model_discovery.py (4 files)"]
  S2 --> I2["Python module behavior"]
  I2 --> R2["Review risk: Python: model_discovery.py (4 files)"]
  R2 --> V2["pytest plus coverage"]
  Evidence --> S3["Docs: current-main-provider-bootstrap.md (2 files)"]
  S3 --> I3["operator or user guidance"]
  I3 --> R3["Review risk: Docs: current-main-provider-bootstrap.md (2 files)"]
  R3 --> V3["docs review"]
  Evidence --> S4["Test: test_experiential_provider.py (7 files)"]
  S4 --> I4["regression suite"]
  I4 --> R4["Review risk: Test: test_experiential_provider.py (7 files)"]
  R4 --> V4["targeted test run"]
Loading

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode reviewed the current-head product diff. Coverage is a separate gate.

Changed files

  • .github/workflows/provider-catalog-sync.yml — GitHub Actions review job
  • contextual_orchestrator/model_discovery.py — Python module behavior
  • contextual_orchestrator/orchestrator.py — Python module behavior
  • contextual_orchestrator/provider_catalog_store.py — Python module behavior
  • contextual_orchestrator/review_gateway.py — Python module behavior
  • docs/doctoring/current-main-provider-bootstrap.md — operator or user guidance
  • docs/research/experiential-free-lane-admission.md — operator or user guidance
  • tests/test_experiential_provider.py — regression suite
  • tests/test_experiential_review_admission.py — regression suite
  • tests/test_model_discovery.py — regression suite
  • tests/test_provider_bootstrap_secret_normalization.py — regression suite
  • tests/test_provider_catalog_store.py — regression suite
  • tests/test_review_gateway_admission_contract_1106.py — regression suite
  • tests/test_review_gateway_credential_array.py — regression suite

Changed behavior

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Workflow: provider-catalog-sync.yml"]
  S1 --> I1["GitHub Actions review job"]
  I1 --> R1["Review risk: Workflow: provider-catalog-sync.yml"]
  R1 --> V1["actionlint plus required checks"]
  Evidence --> S2["Python: model_discovery.py (4 files)"]
  S2 --> I2["Python module behavior"]
  I2 --> R2["Review risk: Python: model_discovery.py (4 files)"]
  R2 --> V2["pytest plus coverage"]
  Evidence --> S3["Docs: current-main-provider-bootstrap.md (2 files)"]
  S3 --> I3["operator or user guidance"]
  I3 --> R3["Review risk: Docs: current-main-provider-bootstrap.md (2 files)"]
  R3 --> V3["docs review"]
  Evidence --> S4["Test: test_experiential_provider.py (7 files)"]
  S4 --> I4["regression suite"]
  I4 --> R4["Review risk: Test: test_experiential_provider.py (7 files)"]
  R4 --> V4["targeted test run"]
Loading

Findings

No source-backed product finding is synthesized from the coverage gate. A coverage miss belongs in the status comment.

  • Head SHA: 3f1ac5b89644888e4b0b5bcc99bd1bdfb939c0ed
  • Workflow run: 34750981485
  • Workflow attempt: 1
  • Coverage gate: failure

Review outcome

Coverage is a gate, not the review. This body reviews the changed product files.

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Workflow: provider-catalog-sync.yml"]
  S1 --> I1["GitHub Actions review job"]
  I1 --> R1["Review risk: Workflow: provider-catalog-sync.yml"]
  R1 --> V1["actionlint plus required checks"]
  Evidence --> S2["Python: model_discovery.py (4 files)"]
  S2 --> I2["Python module behavior"]
  I2 --> R2["Review risk: Python: model_discovery.py (4 files)"]
  R2 --> V2["pytest plus coverage"]
  Evidence --> S3["Docs: current-main-provider-bootstrap.md (2 files)"]
  S3 --> I3["operator or user guidance"]
  I3 --> R3["Review risk: Docs: current-main-provider-bootstrap.md (2 files)"]
  R3 --> V3["docs review"]
  Evidence --> S4["Test: test_experiential_provider.py (7 files)"]
  S4 --> I4["regression suite"]
  I4 --> R4["Review risk: Test: test_experiential_provider.py (7 files)"]
  R4 --> V4["targeted test run"]
Loading

@cwl-noema-review cwl-noema-review Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Noema LLM review

PR #1145 adds optional Experiential Labs provider support with fail-closed semantics across discovery, free-pool admission, ZDR evidence scoping, and workflow leak-guard handling. The change correctly keeps Promotional/zero-price Experiential rows out of free routes, treats conflicting ZDR tags as explicit no-ZDR, restricts OpenRouter ZDR attestation to its own rows, and preserves independently supplied privacy evidence. The updated catalog-sync leak guard tolerates optional secrets. New tests cover discovery, admission, persistence, conflict resolution, and the workflow guard. Verified probes found no regression, misuse, or security issue; the change is safe to merge.

Reviewed changed lines

  • contextual_orchestrator/model_discovery.py:1963 (RIGHT): The updated privacy_tags_for_discovered gates privacy:zdr on supports_zero_data_retention is not False, so explicit negative evidence vetoes a legacy positive zdr_capable marker. The conflict case (supports_zero_data_retention=False, zdr_capable=True) yields only ('privacy:no_zdr',), verified by test_conflicting_zdr_evidence_fails_closed.
  • contextual_orchestrator/model_discovery.py:2187 (RIGHT): general_free_serving_candidates excludes all experiential_labs rows before the free-eligibility filter, preventing promotional zero prices from entering the general free pool even when discovery reports is_free=True. Test test_experiential_review_admission.py confirms free admission fails closed without lane evidence.
  • contextual_orchestrator/provider_catalog_store.py:436 (RIGHT): _restore_model_semantics re-orders the ZDR tag evaluation so privacy:no_zdr takes precedence over privacy:zdr. Persisted contradictory tags now restore supports_zero_data_retention=False, matching the fail-closed intent. test_last_known_good_dual_zdr_tags_restore_fail_closed validates this.
  • .github/workflows/provider-catalog-sync.yml:153 (RIGHT): The leak guard now uses os.environ.get(name, '').rstrip(...), so an unset optional secret (e.g., EXPERIENTAL_LABS_API_KEY) evaluates to an empty string and is skipped without a KeyError. test_catalog_sync_leak_guard_rejects_optional_secret exercises the guard with missing environment variables and confirms correct pass/fail behavior.

Adversarial validation

  • contextual_orchestrator/model_discovery.py:1963 (RIGHT) falsified: The new privacy_tags_for_discovered condition could still emit privacy:zdr for a model carrying explicit negative evidence. — test_conflicting_zdr_evidence_fails_closed asserts privacy_tags_for_discovered(conflicted) == ('privacy:no_zdr',) for a model with supports_zero_data_retention=False and zdr_capable=True. The condition's short-circuit (is not False) prevents emission of privacy:zdr.
  • contextual_orchestrator/model_discovery.py:2187 (RIGHT) falsified: Experiential promotional zero-price models might leak into the general free pool through general_free_serving_candidates. — The filter explicitly requires model.provider_name != 'experiential_labs' as the first conjunction. test_experiential_review_admission.py's test_experiential_labs_free_review_admission_fails_closed_without_lane_evidence shows build_review_orchestrator raises NotConfigured (no eligible zero-cost) when only experiential zero-price models are present.
  • contextual_orchestrator/provider_catalog_store.py:436 (RIGHT) falsified: Persisted conflicting privacy:zdr/privacy:no_zdr tags could restore supports_zero_data_retention=True, defeating fail-closed behavior. — The re-ordered conditional checks 'privacy:no_zdr' first, restoring False when the negative tag is present. test_last_known_good_dual_zdr_tags_restore_fail_closed records such dual tags and asserts the restored supports_zero_data_retention is False.
  • .github/workflows/provider-catalog-sync.yml:153 (RIGHT) falsified: The leak guard referencing an optional secret name (EXPERIENTAL_LABS_API_KEY) would raise KeyError when that secret is unset in the environment. — The guard now uses os.environ.get(name, ''), and test_catalog_sync_leak_guard_rejects_optional_secret deletes every credential env var, runs the guard against '{}' without error, and only after setting the optional secret detects the leak and raises SystemExit deliberately.
  • Residual risk: The hosted Experiential Labs deployment revision is not independently verified against the pinned public source snapshot; pricing and free-only enforcement remain unverified for hosted routes. This is documented rather than asserted, and all admission paths fail closed when evidence is absent, so no blocking risk is identified.

Findings

  • No blocking findings.
  • Result: APPROVE
  • Head SHA: 97857d8bdac4ef9b5297dba535b3bdc69a9786d8
  • Reviewer credential: noema-review-github-app-refresh
  • Actor: cwl-noema-review[bot]

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode reviewed the current-head product diff. Coverage is a separate gate.

Changed files

  • .github/workflows/provider-catalog-sync.yml — GitHub Actions review job
  • contextual_orchestrator/model_discovery.py — Python module behavior
  • contextual_orchestrator/orchestrator.py — Python module behavior
  • contextual_orchestrator/provider_catalog_store.py — Python module behavior
  • contextual_orchestrator/review_gateway.py — Python module behavior
  • docs/doctoring/current-main-provider-bootstrap.md — operator or user guidance
  • docs/research/experiential-free-lane-admission.md — operator or user guidance
  • tests/test_experiential_provider.py — regression suite
  • tests/test_experiential_review_admission.py — regression suite
  • tests/test_model_discovery.py — regression suite
  • tests/test_provider_bootstrap_secret_normalization.py — regression suite
  • tests/test_provider_catalog_store.py — regression suite
  • tests/test_review_gateway_admission_contract_1106.py — regression suite
  • tests/test_review_gateway_credential_array.py — regression suite

Changed behavior

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Workflow: provider-catalog-sync.yml"]
  S1 --> I1["GitHub Actions review job"]
  I1 --> R1["Review risk: Workflow: provider-catalog-sync.yml"]
  R1 --> V1["actionlint plus required checks"]
  Evidence --> S2["Python: model_discovery.py (4 files)"]
  S2 --> I2["Python module behavior"]
  I2 --> R2["Review risk: Python: model_discovery.py (4 files)"]
  R2 --> V2["pytest plus coverage"]
  Evidence --> S3["Docs: current-main-provider-bootstrap.md (2 files)"]
  S3 --> I3["operator or user guidance"]
  I3 --> R3["Review risk: Docs: current-main-provider-bootstrap.md (2 files)"]
  R3 --> V3["docs review"]
  Evidence --> S4["Test: test_experiential_provider.py (7 files)"]
  S4 --> I4["regression suite"]
  I4 --> R4["Review risk: Test: test_experiential_provider.py (7 files)"]
  R4 --> V4["targeted test run"]
Loading

Findings

No source-backed product finding is synthesized from the coverage gate. A coverage miss belongs in the status comment.

  • Head SHA: 97857d8bdac4ef9b5297dba535b3bdc69a9786d8
  • Workflow run: 34756709296
  • Workflow attempt: 1
  • Coverage gate: failure

Review outcome

Coverage is a gate, not the review. This body reviews the changed product files.

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Workflow: provider-catalog-sync.yml"]
  S1 --> I1["GitHub Actions review job"]
  I1 --> R1["Review risk: Workflow: provider-catalog-sync.yml"]
  R1 --> V1["actionlint plus required checks"]
  Evidence --> S2["Python: model_discovery.py (4 files)"]
  S2 --> I2["Python module behavior"]
  I2 --> R2["Review risk: Python: model_discovery.py (4 files)"]
  R2 --> V2["pytest plus coverage"]
  Evidence --> S3["Docs: current-main-provider-bootstrap.md (2 files)"]
  S3 --> I3["operator or user guidance"]
  I3 --> R3["Review risk: Docs: current-main-provider-bootstrap.md (2 files)"]
  R3 --> V3["docs review"]
  Evidence --> S4["Test: test_experiential_provider.py (7 files)"]
  S4 --> I4["regression suite"]
  I4 --> R4["Review risk: Test: test_experiential_provider.py (7 files)"]
  R4 --> V4["targeted test run"]
Loading

@seonghobae

Copy link
Copy Markdown
Contributor Author

Local verification of exact head 97857d8b (2026-09-13, detached checkout, no changes pushed — this branch is checked out and being edited in another session):

🤖 Addressed by Claude Code

@seonghobae

Copy link
Copy Markdown
Contributor Author

Follow-up to the line above: the two interrogate misses at 97857d8b are the module docstrings of tests/test_experiential_provider.py and tests/test_experiential_review_admission.py; every function/class touched by the diff is documented, so the function-scoped warning in #1153 no longer reproduces at this head.

🤖 Addressed by Claude Code

Module docstrings were the last interrogate misses on the touched test
files; every touched function and class was already documented.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@seonghobae

Copy link
Copy Markdown
Contributor Author

Ownership: the Codex session that drove this PR ended interrupted at 21:55 KST (no later activity), so this session is taking the branch over. Pushed 87cf5d67: module docstrings for the two touched test files — touched test files now 29/29 documented (interrogate 100%), 235 related tests still pass. Remaining blockers unchanged: opencode COVERAGE_BLOCKED (org coverage image, ContextualWisdomLab/.github#2157) and the CodeQL compatibility placeholders that clear with it.

🤖 Addressed by Claude Code

@cwl-noema-review cwl-noema-review Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Noema LLM review

The PR adds optional Experiential Labs provider support with discovery, bootstrap, workflow secret transport, and doc updates. The integration is generally well-tested and fail-closed, but the unconditional provider-name exclusion in _is_free_agent blocks paid Experiential agents from paid-fallback free routing, and the hard provider-name filter in general_free_serving_candidates permanently excludes all Experiential rows even with verifiable free-lane evidence, contradicting the documented evidence-based intent. A test gap exists around the accepted vs. required credential inventories.

Reviewed changed lines

  • contextual_orchestrator/orchestrator.py:8328 (RIGHT): Unconditional agent.provider_name == "experiential_labs" guard excludes all Experiential agents from free-lane classification, including paid models with nonzero pricing, causing free-selector fallback to break.
  • contextual_orchestrator/model_discovery.py:2191 (RIGHT): Provider-name filter model.provider_name != "experiential_labs" removes all Experiential rows from the free pool regardless of free-lane evidence, contradicting the documented evidence-based admission intent.
  • tests/test_experiential_provider.py:74 (RIGHT): The test uses PROVIDER_CREDENTIAL_NAMES without asserting the subset relationship to PROVIDER_ACCEPTED_CREDENTIAL_NAMES, leaving the two inventories able to silently diverge.

Adversarial validation

  • contextual_orchestrator/orchestrator.py:8328 (RIGHT) confirmed: A paid Experiential Labs agent (price_per_million > 0) is excluded from free-lane classification, breaking paid fallback. — The unconditional provider-name guard returns False for every Experiential agent, and the test test_experiential_labs_free_tags_cannot_reach_persisted_or_capability_routes asserts the resulting RuntimeError for the free lane.
  • contextual_orchestrator/model_discovery.py:2191 (RIGHT) confirmed: An Experiential Labs model with explicit zero pricing and free-only evidence is still excluded from the free pool solely by provider name. — The added filter model.provider_name != "experiential_labs" drops the row regardless of pricing evidence, as verified by the changed line and the documented evidence-based admission intent.
  • tests/test_experiential_provider.py:74 (RIGHT) confirmed: The optional key could silently appear in PROVIDER_CREDENTIAL_NAMES without any test catch it, causing a required-key bootstrap change. — The test imports only PROVIDER_CREDENTIAL_NAMES and does not validate the relationship to the new accepted inventory constant used by the workflow.
  • Residual risk: Even with the confirmed regression, the provider exclusion is intentional for promotional/free metadata; a fix could preserve the safety intent while restoring paid fallback behavior. The test gap is non-blocking but should be tightened.

Findings

  • [high] contextual_orchestrator/orchestrator.py:8328 (RIGHT): The unconditional agent.provider_name == "experiential_labs" guard in _is_free_agent excludes all Experiential agents from free-lane classification, including paid models with nonzero pricing. This breaks paid fallback routing when only paid Experiential models are configured, causing no enabled zero-cost model failures.
  • [medium] contextual_orchestrator/model_discovery.py:2191 (RIGHT): The hard provider-name filter model.provider_name != "experiential_labs" removes all Experiential rows from the free pool, even those with verifiable free-lane evidence, contradicting the documented evidence-based admission intent and preventing future verified free-only routes.
  • [medium] tests/test_experiential_provider.py:74 (RIGHT): The test asserts optional-key absence from PROVIDER_CREDENTIAL_NAMES but does not assert the relationship between PROVIDER_CREDENTIAL_NAMES and the newly introduced PROVIDER_ACCEPTED_CREDENTIAL_NAMES, allowing the required and accepted inventories to silently diverge.
  • Result: REQUEST_CHANGES
  • Head SHA: fde504ce918b6a8437ef85cd086c4136073a5863
  • Reviewer credential: noema-review-github-app-refresh
  • Actor: cwl-noema-review[bot]

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode reviewed the current-head product diff. Coverage is a separate gate.

Changed files

  • .github/workflows/provider-catalog-sync.yml — GitHub Actions review job
  • contextual_orchestrator/model_discovery.py — Python module behavior
  • contextual_orchestrator/orchestrator.py — Python module behavior
  • contextual_orchestrator/provider_catalog_store.py — Python module behavior
  • contextual_orchestrator/review_gateway.py — Python module behavior
  • docs/doctoring/current-main-provider-bootstrap.md — operator or user guidance
  • docs/research/experiential-free-lane-admission.md — operator or user guidance
  • tests/test_experiential_provider.py — regression suite
  • tests/test_experiential_review_admission.py — regression suite
  • tests/test_model_discovery.py — regression suite
  • tests/test_provider_bootstrap_secret_normalization.py — regression suite
  • tests/test_provider_catalog_store.py — regression suite
  • tests/test_review_gateway_admission_contract_1106.py — regression suite
  • tests/test_review_gateway_credential_array.py — regression suite

Changed behavior

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Workflow: provider-catalog-sync.yml"]
  S1 --> I1["GitHub Actions review job"]
  I1 --> R1["Review risk: Workflow: provider-catalog-sync.yml"]
  R1 --> V1["actionlint plus required checks"]
  Evidence --> S2["Python: model_discovery.py (4 files)"]
  S2 --> I2["Python module behavior"]
  I2 --> R2["Review risk: Python: model_discovery.py (4 files)"]
  R2 --> V2["pytest plus coverage"]
  Evidence --> S3["Docs: current-main-provider-bootstrap.md (2 files)"]
  S3 --> I3["operator or user guidance"]
  I3 --> R3["Review risk: Docs: current-main-provider-bootstrap.md (2 files)"]
  R3 --> V3["docs review"]
  Evidence --> S4["Test: test_experiential_provider.py (7 files)"]
  S4 --> I4["regression suite"]
  I4 --> R4["Review risk: Test: test_experiential_provider.py (7 files)"]
  R4 --> V4["targeted test run"]
Loading

Findings

No source-backed product finding is synthesized from the coverage gate. A coverage miss belongs in the status comment.

  • Head SHA: fde504ce918b6a8437ef85cd086c4136073a5863
  • Workflow run: 34768160673
  • Workflow attempt: 1
  • Coverage gate: failure

Review outcome

Coverage is a gate, not the review. This body reviews the changed product files.

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Workflow: provider-catalog-sync.yml"]
  S1 --> I1["GitHub Actions review job"]
  I1 --> R1["Review risk: Workflow: provider-catalog-sync.yml"]
  R1 --> V1["actionlint plus required checks"]
  Evidence --> S2["Python: model_discovery.py (4 files)"]
  S2 --> I2["Python module behavior"]
  I2 --> R2["Review risk: Python: model_discovery.py (4 files)"]
  R2 --> V2["pytest plus coverage"]
  Evidence --> S3["Docs: current-main-provider-bootstrap.md (2 files)"]
  S3 --> I3["operator or user guidance"]
  I3 --> R3["Review risk: Docs: current-main-provider-bootstrap.md (2 files)"]
  R3 --> V3["docs review"]
  Evidence --> S4["Test: test_experiential_provider.py (7 files)"]
  S4 --> I4["regression suite"]
  I4 --> R4["Review risk: Test: test_experiential_provider.py (7 files)"]
  R4 --> V4["targeted test run"]
Loading

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode reviewed the current-head product diff. Coverage is a separate gate.

Changed files

  • .github/workflows/provider-catalog-sync.yml — GitHub Actions review job
  • contextual_orchestrator/model_discovery.py — Python module behavior
  • contextual_orchestrator/orchestrator.py — Python module behavior
  • contextual_orchestrator/provider_catalog_store.py — Python module behavior
  • contextual_orchestrator/review_gateway.py — Python module behavior
  • docs/doctoring/current-main-provider-bootstrap.md — operator or user guidance
  • docs/research/experiential-free-lane-admission.md — operator or user guidance
  • tests/test_experiential_provider.py — regression suite
  • tests/test_experiential_review_admission.py — regression suite
  • tests/test_model_discovery.py — regression suite
  • tests/test_provider_bootstrap_secret_normalization.py — regression suite
  • tests/test_provider_catalog_store.py — regression suite
  • tests/test_review_gateway_admission_contract_1106.py — regression suite
  • tests/test_review_gateway_credential_array.py — regression suite

Changed behavior

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Workflow: provider-catalog-sync.yml"]
  S1 --> I1["GitHub Actions review job"]
  I1 --> R1["Review risk: Workflow: provider-catalog-sync.yml"]
  R1 --> V1["actionlint plus required checks"]
  Evidence --> S2["Python: model_discovery.py (4 files)"]
  S2 --> I2["Python module behavior"]
  I2 --> R2["Review risk: Python: model_discovery.py (4 files)"]
  R2 --> V2["pytest plus coverage"]
  Evidence --> S3["Docs: current-main-provider-bootstrap.md (2 files)"]
  S3 --> I3["operator or user guidance"]
  I3 --> R3["Review risk: Docs: current-main-provider-bootstrap.md (2 files)"]
  R3 --> V3["docs review"]
  Evidence --> S4["Test: test_experiential_provider.py (7 files)"]
  S4 --> I4["regression suite"]
  I4 --> R4["Review risk: Test: test_experiential_provider.py (7 files)"]
  R4 --> V4["targeted test run"]
Loading

Findings

No source-backed product finding is synthesized from the coverage gate. A coverage miss belongs in the status comment.

  • Head SHA: fde504ce918b6a8437ef85cd086c4136073a5863
  • Workflow run: 34832272879
  • Workflow attempt: 1
  • Coverage gate: failure

Review outcome

Coverage is a gate, not the review. This body reviews the changed product files.

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Workflow: provider-catalog-sync.yml"]
  S1 --> I1["GitHub Actions review job"]
  I1 --> R1["Review risk: Workflow: provider-catalog-sync.yml"]
  R1 --> V1["actionlint plus required checks"]
  Evidence --> S2["Python: model_discovery.py (4 files)"]
  S2 --> I2["Python module behavior"]
  I2 --> R2["Review risk: Python: model_discovery.py (4 files)"]
  R2 --> V2["pytest plus coverage"]
  Evidence --> S3["Docs: current-main-provider-bootstrap.md (2 files)"]
  S3 --> I3["operator or user guidance"]
  I3 --> R3["Review risk: Docs: current-main-provider-bootstrap.md (2 files)"]
  R3 --> V3["docs review"]
  Evidence --> S4["Test: test_experiential_provider.py (7 files)"]
  S4 --> I4["regression suite"]
  I4 --> R4["Review risk: Test: test_experiential_provider.py (7 files)"]
  R4 --> V4["targeted test run"]
Loading

seonghobae and others added 3 commits September 18, 2026 04:00
Resolve the sole conflict in test_model_discovery by keeping main's
discovery-deadline regressions and the PR's provider-scoped ZDR coverage.

Co-authored-by: Cursor <cursoragent@cursor.com>
Main uses _DISCOVERY_RETRY_TIMEOUT_SECONDS in the bounded retry helper
but dropped its definition; keep the PR's 5.0s cap so explicit caller
budgets stay enforceable.

Co-authored-by: Cursor <cursoragent@cursor.com>
@seonghobae
seonghobae merged commit 098ea16 into main Sep 17, 2026
17 of 21 checks passed
@seonghobae
seonghobae deleted the feat/experiential-labs-provider-20260912 branch September 17, 2026 19:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant