fix(data): align PDF DOM upload budget with sidecar - #1427
Conversation
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
@opencode-agent @cwl-noema-review Please independently review exact current head |
Review finding withdrawnWithdrawn after exact-base recheck. The earlier P1 relied on stale local evidence that treated protected |
Follow-up withdrawnThe previous dependency disposition is withdrawn for the same reason: exact protected |
|
The new |
|
@opencode-agent @cwl-noema-review Current-head review request after the ADR traceability stack merged. Exact head: 29be15e Read the complete current PDF DOM upload diff including ADR-0005 with its Figma File ID field. Verify 64 MiB alignment with the NewsDOM sidecar, signed-session/auth-before-data handling, PDF signature, first over-limit byte accounting, base64 persistence, pending decode, quota/cleanup, tests, and rollback implications. Produce a substantive current-head verdict with path:line evidence; do not reuse predecessor evidence. |
|
Current-head review finding: the live consumer dependency is not aligned as described. Exact Naruon head 29be15e sets _MAX_PDF_DOM_UPLOAD_BYTES to 64 MiB, but ContextualWisdomLab/newsdom-api develop currently defines MAX_PARSE_UPLOAD_BYTES = 20 * 1024 * 1024 in src/newsdom_api/main.py:44 and tests still assert the 20 MiB boundary. This is a substantive cross-repository contract gap, not a review or runner deadlock. I am opening the owning sidecar PR first; keep this PR blocked until the exact sidecar contract is merged and revalidated. |
|
Owning sidecar contract PR opened: ContextualWisdomLab/newsdom-api#682. Its exact head 71671c6 raises MAX_PARSE_UPLOAD_BYTES from the live 20 MiB to 64 MiB with a regression test, ADR/doctoring record, and 100% local coverage. Naruon#1427 remains stacked logically on that merge; after #682 normal merge, revalidate #1427 against the new sidecar contract and current Naruon head. |
|
PR governance metadata gate is not ready for
|
|
Exact-head disposition for |
|
@coderabbitai review\n\nPlease review only exact current head 29be15e; do not reuse predecessor-head evidence. The current metadata gate is stale until this exact head receives a fresh review. |
|
Current-head Checks RCA: the historical failure for this exact head was not a source finding. The run log shows Strix Caido bootstrap failing after 10 attempts because was unavailable; no scan report was produced and the gate failed closed. A normal was attempted, but GitHub returned 404 because the owning workflow is no longer available. The metadata-only gate therefore remains stale/infrastructure-blocked; no test or security check was weakened. |
🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
echo "Local checkout:"
git rev-parse HEAD
echo "GitHub PR `#1427` head:"
gh pr view 1427 --repo ContextualWisdomLab/naruon --json headRefOid --jq '.headRefOid'Length of output: 448
|
|
Correction to the preceding audit comment: the historical strix failure for this exact head was not a source finding. The run log shows the Strix Caido bootstrap loginAsGuest failed after ten attempts because localhost port 48080 was unavailable; no scan report was produced and the gate failed closed. A normal Actions rerun was attempted, but GitHub returned 404 because the owning workflow is no longer available. The metadata-only gate therefore remains stale/infrastructure-blocked; no test or security check was weakened. |
|
@opencode-agent @cwl-noema-review review only exact current head |
|
Current-head restack ( |
|
Current-head review disposition for 37ab7bd: both Devin threads are informational, not change requests. The legacy-index removal is required for the current schema, and the 64 MiB parser/base64 storage capacity concern is already recorded as the bounded-contract object-storage gap in ADR-0005 and the product baseline. No source change is required for either thread; hosted Checks and independent review remain the merge gates. |
Co-Authored-By: Codex <codex@openai.com> Signed-off-by: Seongho Bae <me@seonghobae.me>
|
Exact-head repair evidence for |
…ntextualWisdomLab/naruon into codex/pr1427-restack
|
현재 head |
Non-force merge of updated #1468, retaining the PDF upload contract and Proposed ADR. Merged tree e0717d3 passes fresh Alembic upgrade, 76 clean-lock strict PostgreSQL/dependency tests, Ruff, and diff checks. Owner service release and hosted review/Checks remain separate prerequisites; no 64 MiB sidecar runtime or protected merge is claimed. Co-Authored-By: Codex <noreply@openai.com> Signed-off-by: Seongho Bae <me@seonghobae.me>
Normally merge #1468 while preserving the PDF admission, signed-session, and deferred-worker delta. Exact synchronization, fresh and repeat migration 0020, and 132 strict PostgreSQL/search tests pass. Renumber the colliding unpublished ADR proposal to 0021 and retain its former identity and owner-release gate. Correct provider maturity claims; 64MiB NewsDOM runtime and search performance remain unverified. Co-authored-by: Codex <noreply@openai.com> Signed-off-by: Seongho Bae <me@seonghobae.me>
Preserve the #1469 attachment parser, NewsDOM client/worker and focused tests while adopting #1427 as the prerequisite owner stack. Inherit ADR-0021 and the current direct PDF-DOM upload boundary from #1427 instead of the stale child data.py. Renumber the attachment parse-source proposal to ADR-0023 and keep the external NewsDOM transport contract fail-closed until an immutable owner release is pinned. The existing CHANGELOG child delta is preserved verbatim for lineage; its former ADR-0005/0006 references remain a known follow-up documentation RED before merge. Signed-off-by: Seongho Bae <me@seonghobae.me>
Restore #1427's exact CHANGELOG blob so the attachment child cannot delete valid prerequisite release notes while its former ADR references are being repaired. The #1469 attachment CHANGELOG delta remains a known Draft obligation to reintroduce with ADR-0021/0023 references before merge. Signed-off-by: Seongho Bae <me@seonghobae.me>
Preserve the complete #1469 source-retention and HTTP 413 delta on #1427. No branch, workflow, source, or decision is deleted or superseded; ADR-0023 remains Proposed. Real PostgreSQL commit/rollback contention reproduced two stranded leases. Add one-connection lifecycle coverage, strict unlock confirmation, disconnect cursor recovery, and invalidate-before-close cancellation regression. Focused review regressions reached five RED then five GREEN; full exact-head revalidation follows this commit.
Current owner-stack receipt (2026-09-05)
Head
cb08b1c3ea2aba8844fc29ef703c34368cc55e47, tree526ba4181a710f96f61a1347720d606bdf92aa0f, normally merges prior head02366791b2a449b8b23b527dcc550996361c0f96with #146853ce38ed6683d01a9d113069f5ac5a8f17e133a2. The preserved stack is #1565 → #1503 → #1572 → #1468 → #1427. No force push or valid-delta deletion is used.Exact dependency sync, fresh/repeated migration to
0020_search_trigram_storage, and 132 strict PostgreSQL/search/dependency tests pass, zero failed/skipped, in 25.07 seconds. Ruff and diff checks pass. Local receipts are/private/tmp/naruon-search-index-rca.VRmUrq/prop1427_tests.xmlandprop1427_migration.log; the exact isolated Compose project was removed. Tests using mocked PDF processing or reduced over-limit fixtures do not prove a real 64MiB PDF processed by an immutable NewsDOM release.The live all-open-PR ADR inventory showed unrelated 0005 proposals, so this proposal is now ADR-0021 with its former ID and #1427 lineage retained. #1469 must inherit that rename through the existing owner stack. The README and doctoring no longer imply a verified 64MiB NewsDOM runtime. All existing signed-session, signature, bounded-read, pending-payload and deferred-worker behavior is preserved.
Keep Draft until the NewsDOM immutable release/exact pin, #1572 representative search and migration-cost gates, and current-head hosted Checks/independent review are verified. Earlier receipts below are historical, not the state of this new head.
Customer outcome
This Draft raises Naruon's local Data-workspace PDF DOM upload bound to 64 MiB;
requests above it are rejected with
413before storage or recognition work.This is a local consumer contract, not proof that the NewsDOM owner has published
and deployed a matching immutable release.
Root cause
The direct Data upload and pending-payload decoder retained an independent 20 MiB guard after the cross-service transport contract moved to 64 MiB.
Historical focused evidence (before the current owner restack)
python -m pytest -q backend/tests/test_data_api.py -k 'pdf_dom_upload or pending_pdf_document_decoder'— 4 passed.ruff check backend/api/data.py backend/tests/test_data_api.py— passed.git diff --check— passed.Safety
Signed-session authorization, PDF signature validation, bounded read, base64 persistence, worker deferral, and fail-closed malformed-payload handling remain unchanged. The matching NewsDOM owner proposal is tracked separately in ContextualWisdomLab/newsdom-api#665.
Its open PR is Proposed evidence only; released contract and runtime compatibility
must be verified before production consumption.
No customer or private reference data was read or committed. This is a backend contract change; no Figma design file is required.
Current owner-restack receipt — 2026-09-05
02366791b2a449b8b23b527dcc550996361c0f96; direct base:fix/postgres-smoke-read-state@037b58adeda53e6c847f8949494b9b518a94dac9.3a5f2b3751987fa8baaf85f96641e1659679aa80and the full direct-parent delta; no force push or predecessor closure.uv sync --locked, a fresh isolated PostgreSQL 16.15 database migrated through0019_email_read_state_repairusinguv run --frozen python scripts/migrate_db.py.backend/:uv run --frozen python -m pytest -q -W error -ra --tb=short tests/test_alembic_migrations.py tests/test_bootstrap_db.py tests/test_data_api.py tests/test_email_read_state_migration_postgres.py tests/test_legacy_document_scope_postgres.py tests/test_workspace_document_migration.py tests/test_container_dependency_pin_contract.py— 76 passed, 0 failed, 0 skipped. These are local migrated-PostgreSQL/source tests, not protected-merge, deployed, or external-owner release evidence.git diff --checkpassed in that integration run.