Skip to content

docs(gap): record isolated application service boundary - #992

Draft
seonghobae wants to merge 15 commits into
mainfrom
docs/qsr-application-service-gap-20260901
Draft

docs(gap): record isolated application service boundary#992
seonghobae wants to merge 15 commits into
mainfrom
docs/qsr-application-service-gap-20260901

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

Summary

Validation

  • uv run --locked --group dev pytest tests/test_product_planning_contract.py tests/test_commercial_gap_register.py tests/test_paper_contracts.py -q (11 passed)
  • uv run --locked --group dev python -m compileall -q contextual_orchestrator
  • git diff --check

No runtime adapter is added before the upstream published-contract gate exists.


Devin Review

Summary by CodeRabbit

  • 문서
    • Chat, Agent, 정책, 테넌트 인가 등 저장소와 외부 샌드박스 런타임의 책임 범위를 문서화했습니다.
    • 업스트림 계약 대기 상태와 향후 ACL·테스트·API 계획을 기록했습니다.
    • 관련 보안 기준과 실행 검증 결과를 기준선 문서에 추가했습니다.

@coderabbitai

coderabbitai Bot commented Sep 1, 2026

Copy link
Copy Markdown

Review Change Stack

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Team

Run ID: 60966285-9e93-419e-af5f-cf77d4ee9a81

📝 Walkthrough

Walkthrough

애플리케이션 서비스와 외부 quarantine-sandbox-runtime의 책임 경계를 문서화했습니다. 업스트림 계약 검토 결과, 근거 자료, WAIT_FOR_UPSTREAM_CONTRACT 상태 및 후속 계획을 추가했습니다.

Changes

외부 런타임 경계

Layer / File(s) Summary
경계 및 계약 상태
docs/product-technical-gap-baseline.md
Chat, Agent, 정책, 테넌트 인가, 시크릿, 사용자 가시 라이프사이클을 저장소 범위로 정의했습니다. 컨테이너 라이프사이클, 격리, 리소스 제한, readiness, lease attestation, 정리를 외부 런타임 범위로 정의했습니다. 업스트림 Draft PR 검토 결과와 WAIT_FOR_UPSTREAM_CONTRACT 상태를 기록했습니다.

Estimated code review effort: 1 (간단) | ~5분

Merge Risk: 🟡 Moderate · up to dda21

This change records a future cross-service lease boundary without enabling runtime integration. Merge readiness is moderate because the release criteria do not yet explicitly require authenticated, integrity-protected communication or durable retry and restart cleanup guarantees, which could enable an unsafe future integration or leave orphaned leases unless corrected or explicitly accepted; the citation issue is minor.

Suggested reviewers: claude

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed 제목은 격리된 애플리케이션 서비스 경계를 문서화하는 주요 변경 사항을 정확하고 간결하게 설명합니다.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Docstring Coverage

Explanation

No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0 files. (1 skipped: 1 unsupported.)

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch docs/qsr-application-service-gap-20260901

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 1, 2026

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review Completed 2026-09-01T05:44:45.500417Z 853f6a7 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note

This report is out of date. Scroll down for Devin Review's latest report on this PR.

✅ Devin Review: No Issues Found

Devin Review analyzed this PR and found no bugs or issues to report.

Devin Review

chatgpt-codex-connector[bot]

This comment was marked as resolved.

devin-ai-integration[bot]

This comment was marked as resolved.

devin-ai-integration[bot]

This comment was marked as resolved.

coderabbitai[bot]

This comment was marked as resolved.

devin-ai-integration[bot]

This comment was marked as resolved.

devin-ai-integration[bot]

This comment was marked as resolved.

devin-ai-integration[bot]

This comment was marked as resolved.

Devin flagged "It do not prove" as a grammar error obscuring the
release-gate qualification. Fixed to "It does not prove".

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01BV96rXhqoR3tYZ9AeAVur4
@seonghobae seonghobae added documentation Improvements or additions to documentation priority: medium Normal-priority or P2 work status: needs-review Open pull request requiring current-head review or checks labels Sep 2, 2026 — with ChatGPT Codex Connector
@seonghobae seonghobae added the type: docs Documentation, ADR, PRD, or technical writing label Sep 2, 2026 — with ChatGPT Codex Connector

Copy link
Copy Markdown
Contributor Author

noema-review failure isn't this PR's

Job log (noema-review, run 33581851116): Noema model-output repair remained invalid; initial failure: Noema LLM response was not valid JSON (Expecting property name enclosed in double quotes: line 1 column 1725 (char 1724)) ... repair failure: Noema LLM response findings must be a list of objects.

This is the review LLM (orchestrator/free) returning malformed/truncated JSON for its verdict, not a defect in this PR's diff (a docs-only change). The same job's own status payload shows heavy provider instability on this call — several nvidia_nim/nvidia_nim_sub candidates rejected with 429, 404, and TimeoutError before one finally served, plausibly explaining a truncated/malformed response from whichever model actually answered.

Re-ran the failed job once (rerun_failed_jobs on run 33581851116) to confirm this is transient rather than a reproducible defect in the review pipeline's JSON-repair path. Will not re-run again beyond this per this session's flake-verification policy — if it fails identically a second time, that's a real review-pipeline robustness gap worth its own investigation (likely in the JSON-repair fallback in .github/actions/noema-review/two_phase.py), not something to keep retrying blind.


Generated by Claude Code

…service-gap-20260901

Bring PR #992 (isolated application service boundary gap-baseline
entry + NIST SP 800-190/800-207a papers) up to date with main, which
had advanced past the PR's stale base sha. Purely additive docs merge;
no conflicts.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01BV96rXhqoR3tYZ9AeAVur4

Copy link
Copy Markdown
Contributor Author

Rebased this PR onto current main (it was stuck mergeable_state: behind against a stale base sha 8839081...).

CI status before merge: all checks green (noema-review was queued, not failed, at last check).

Merge: git merge origin/main was completely clean — this PR only touches docs/papers/README.md, two new PDFs, and a purely-additive 66-line new dated section in docs/product-technical-gap-baseline.md. No conflicts, no conflict markers.

Verification (Python 3.12 venv, pip install --require-hashes -r requirements.lock + pip install --no-deps -e .), reproducing the PR's own stated validation:

  • pytest tests/test_product_planning_contract.py tests/test_commercial_gap_register.py tests/test_paper_contracts.py -q — 11 passed (matches the PR description's stated 11 passed)
  • python -m compileall -q contextual_orchestrator — clean
  • git diff --check — clean

Pushed directly to docs/qsr-application-service-gap-20260901 (no force-push).


Generated by Claude Code

Copy link
Copy Markdown
Contributor Author

Autonomous loop note: "Full unit and contract suite" run 33723688939 failed with exactly one test — tests/test_provider_embedding_batch_backend.py::test_unknown_tokenizer_byte_bound_never_becomes_recorded_usage[한글🙂é] - KeyError: 'total_tokens'. This is confirmed unrelated to this PR's own diff (docs-only, no code touched): it is the known async embedding-batch race condition already root-caused and fixed (test-only) in #1044 — see that PR's description for the deterministic repro and fix. Re-ran the failed job (rerun_failed_jobs on run 33723688939); it should pass once the race doesn't lose. No source change needed here; #1044 landing on main removes the flake for good.


Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation priority: medium Normal-priority or P2 work status: needs-review Open pull request requiring current-head review or checks type: docs Documentation, ADR, PRD, or technical writing

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants