Skip to content

fix(tests): parse DOI links in doctoring contracts - #2171

Draft
seonghobae wants to merge 1 commit into
mainfrom
seonghobae/fmls-codeql-doi-url-parse
Draft

seonghobae wants to merge 1 commit into
mainfrom
seonghobae/fmls-codeql-doi-url-parse

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Parse URLs in the architecture and governance doctoring notes before checking for a DOI citation.
  • Require HTTPS, the exact doi.org authority, and a non-empty DOI path. The contract tests cover missing links, look-alike hosts, HTTP, an embedded DOI substring in another host's URL, and the real links in both notes.

Verification

  • Failing first: with the old substring check, the focused tests reported 2 failures and 4 passes. Both failures accepted https://evil.example/https://doi.org/10.1000/example.
  • After the fix: .venv/bin/python -m pytest -q tests/test_architecture_baseline_contract.py tests/test_governance_index_contract.py tests/test_changelog_fragment_contract.py → 16 passed.

This addresses the two pre-existing CodeQL Python findings without suppressing alerts. The CodeQL result on this PR is pending hosted verification.

Local CodeQL verification

CodeQL CLI 2.27.1 with bundled Python queries 1.8.11, run in an isolated Linux ARM64 container with Python 3.12 and networking disabled:

  • Before the fix: the targeted rule reported exactly two py/incomplete-url-substring-sanitization findings, at tests/test_architecture_baseline_contract.py:34 and tests/test_governance_index_contract.py:32.
  • Exact head cffb90fb742d0ebcb9c5aa49c8323ce349138eab: the full default Python suite produced zero SARIF findings. The central codeql_sarif_gate.py returned CODEQL_SARIF files=1 results=0 medium_plus=0 (exit 0).
  • Focused tests were rerun: 16 passed.

The required hosted Python compatibility job is still awaiting central scan run 36283765134. Local results do not establish that the hosted job succeeded.

@coderabbitai

coderabbitai Bot commented Sep 26, 2026

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

Next included review available in 11 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Repository: ContextualWisdomLab/fast-mlsirm/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: dc4101fb-4bca-4d39-b3a5-c0c3b15bd00d

📥 Commits

Reviewing files that changed from the base of the PR and between 00f5cb9 and cffb90f.

📒 Files selected for processing (2)
  • tests/test_architecture_baseline_contract.py
  • tests/test_governance_index_contract.py

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Copy link
Copy Markdown
Contributor Author

Exact-head blocker re-audit: cffb90fb742d0ebcb9c5aa49c8323ce349138eab (base main@00f5cb91b417e40102036eb31ab8a4b843c76076, 1 ahead / 0 behind).

현재 다음 실질 blocker가 있어 Draft/Proposed로 교정합니다:

  • terminal workflow failure: CodeQL PR=failure#36237188269

Queued/pending review·Checks 또는 승인 대기만으로 Draft 전환하지 않았습니다. Current head에서 blocker가 해소되면 Ready review admission을 복구합니다.

@seonghobae

seonghobae commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor Author

Continuation report for the #2114/#2120 review-gate investigation, now bound to #2171 head cffb90f.

Completed independent verification and submitted scoped COMMENT reviews on the existing repair owners:

  • central #2360 fc9c8d2c: multi-root Rust union materialization, 26 passed / 3 real Cargo integrations excluded;
  • central #2385 372f5b8b: GHAS analysis-read credential fallback and related contracts, 59 passed;
  • central #2387 33b90283: Noema retry credential separation, 85 passed. This covers fix(tests): parse DOI links in doctoring contracts #2171's eligible HTTP 504 followed by repository_dispatch integration 403.

New RCA from Strix run 36237188327, job 108408520367, retained artifact 10919666896: discovery completed, sequential provider probes advanced through several completed candidates, then nvidia_nim meta/llama-3.2-90b-vision-instruct started at 2026-09-26T19:06:49.173Z with no later outcome before cancellation at 2026-09-27T01:00:56.653Z. It blocked route readiness for approximately 5h54m, before the gateway probe and scan. The current no-inference-deadline runtime is intentional under ADR-0003; ADR-0029's old 90-second per-probe wall-time claim no longer applies. The serial preflight's eight-ready target lets one pending route prevent reaching remaining candidates. The next shared repair belongs in readiness scheduling rather than scan code, credential broadening, or a fixed inference deadline.

Organization inventory found 51 assigned running jobs (30 Strix / 19 Noema / 2 compatibility), while #2171 OpenCode coverage and CodeQL dispatch were unassigned. This proves occupancy but not the exact concurrency ceiling. Five oldest jobs still bind open current-head PRs; no stale cancellation was justified. The Actions budget does not halt spending (prevent_further_usage=false).

The DOI contract tests also passed 6/6 on this head and 6/6 after an isolated conflict-free merge with current main. Hosted exact-head gate success and qualifying approval remain separate requirements; no merge, bypass, or synthetic status was performed.

Shared readiness repair implemented

The serial-preflight RCA now has a concrete shared repair: ContextualWisdomLab/.github#2411 at c3934de96acf2a296c08257da2437dedf4efed64, tracking ContextualWisdomLab/.github#2408.

The existing route validator is reused with concurrent scheduling bounded by the unchanged sixteen-base-probe budget per stage and one locked four-escalation budget across primary/fallback. One or eight held probes no longer prevent eight later ready routes from starting the sidecar; pending calls are not cancelled, rejected or admitted. Catalog serving priority, free/ZDR selection, all-unavailable failure and fallback ordering are preserved.

The exact baseline reproduced the serial obstruction. Final-source focused tests pass 143/143 with warnings as errors in both ordinary local and GITHUB_ACTIONS=true modes; Ruff and diff whitespace checks pass. Implementation and proposed ADR amendment are reviewable at ContextualWisdomLab/.github#2411.

The fresh PR checks are queued at the exact current head. Deployment and live-provider completion remain unproven, so neither this repair nor the overall goal is marked complete. Project #1 records the issue and PR as In Progress.

Security prerequisite verified and integrated

The separate Noema #2387 pip-audit failure is confirmed: the shared Strix lock retains AnyIO 4.14.0 with three known findings. The canonical fix is ContextualWisdomLab/.github#2278 at 8a5251bf409fe84b3dd0cba1e48992f5b8d9eda5. Both official wheel/sdist bytes match the committed hashes. A strict audit of all 106 listed distributions reproduces the original three findings and returns zero findings for the repaired lock, with zero skipped packages.

The exact owner commit is integrated into ContextualWisdomLab/.github#2411 by an ordinary two-parent merge. Current head is 4ebadfc4d69552e18f9043335335e2a994cff2cd, superseding the earlier c3934de96 checkpoint. Related integrated-tree tests pass 144/144; the owner's branch and requested-changes review were preserved. Fresh hosted checks are queued at this new head; old-head checks/reviews are not transferred, and no main merge or deployment is claimed.

Governance RCA correction (2026-09-27)

Central repair PR #2411 now targets e7c2d0a6db4826646c477be7b88865c63f3ad5ad. September 4's documented correction intentionally restored the dispatch-safe CodeQL required workflow; the original inventory discrepancy is therefore superseded. The stale July explanation has been corrected without removing the gate.

The current ruleset instead has two review-policy mismatches against the protected-main auditor: one approval instead of two, and last-push approval disabled. A two-field candidate passes the auditor and preserves disabled code-owner review, but remains unapplied pending maintainer policy intent. Latest repair-head jobs are queued; hosted acceptance is not established. Default-branch alerts 11–13 all concern AnyIO, and the independently audited 4.14.2 lock fix is already included in #2411.

Protected integration deployed (2026-09-27 10:38 UTC)

Maintainer-authorized bypass integration #2414 is MERGED at main 23c6beaff3d8a1f376f1ba1e194118bd143a0788. Canonical OpenCode gateway owner #2333 and Noema continuation owner #2387 are also confirmed MERGED. Source includes #2385 prerequisites, #2360 Cargo roots, #2411 readiness, duplicate full-suite repair, and already-deployed #2416 self-hosted CodeQL/OpenCode/control allocation.

Merged-tree contracts: 133 passed with warnings as errors. The security lock remains byte-identical to the zero-finding audit. This is deployed source, not a claim of current downstream model verdicts or completed hosted security checks. Live old inferences were preserved. Five self-hosted runners were observed online; central assignment samples include actual self-hosted Noema and OpenCode execution. Organization approval settings were left unchanged as instructed.

REST Actions observation reached the API rate limit after merge; subsequent acceptance must use fresh authoritative run/check evidence when available.

Self-hosted 재검증 후속 확인 (2026-09-27 11:05 UTC)

중앙 대기 실행은 500건이며 org runner 5대가 online, 4대 busy입니다. fast-mlsirm CodeQL producer run 36237188269의 취소된 coordinator job 108604864815만 재실행하여 HTTP 201을 확인했습니다. attempt 3의 새 coordinator 108606768450는 self-hosted runner 배정 대기 상태입니다. 최신 중앙 소스의 coordinator 배정은 trusted-main workflow일 때 CWL central control이며, 해당 그룹은 visibility=all / selected-workflows 제한을 유지합니다. 새 native scan 생성 및 권한 수정 통과는 아직 확인하지 못했습니다. 기존 OpenCode run 36264497244는 실제 in_progress이므로 유지했습니다. 원래 CodeQL native 실패 로그는 GHAS analyses GET 403과 두 credential의 status 게시 403을 각각 확인했습니다; runner 부족으로 분류하지 않습니다.

CodeQL 설치 권한 RCA 및 후속 검증 (2026-09-27 12:28 UTC)

새 native scan 36315486750(중앙 source 12a844a76cb91a94e4d39895f3cfc54ddc114182)의 actions 108610143925와 Python 108610143996 분석이 모두 SUCCESS입니다. 실패한 settlement 108611199530는 live PR/run/job 및 SARIF 검증 이후 Actions 재실행 POST에서 403을 받았습니다. org installation API로 opencode-agent 설치 141441800의 실권한 actions=read / statuses=read를 확인했습니다. 해당 실행의 두 fallback secret 및 cross-repo github-token은 비어 있었습니다. 앱 설치 actions:write / statuses:write는 앱 운영자가 처리해야 하며 YAML permissions만으로 실권한을 높일 수 없습니다. 기존 검증된 terminal-job/SARIF fallback은 유지합니다. live head cffb90f… / base 5630256… 확인 후 maintainer credential로 producer 36237188269의 rerun-failed-jobs를 요청하여 HTTP 201을 받았습니다. 후속 필수 gate 108618976359(actions), 108618976410(Python)은 현재 QUEUED입니다. 분석 성공과 필수 gate/전체 리뷰 통과를 구분합니다.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant