feat(data): add bounded tenant provenance portability - #1497
Conversation
📝 WalkthroughWalkthroughThis change adds deterministic BagIt/RO-Crate provenance bundle export and import for scoped tenant project evidence. It adds OIDC-authoritative API routes, bounded archive validation, transactional restoration, identity mapping, conditional schema backfill handling, tests, ADR-0005, and planning updates. ChangesTenant provenance portability
Schema bootstrap compatibility
Estimated code review effort: 5 (Critical) | ~120 minutes Merge Risk: ⚪ Minimal · up to The change is merge-ready after normal checks and review; no actionable merge-blocking risk remains. A localized test helper should narrow its error handling so genuine database failures are not reported as skipped tests. Sequence Diagram(s)sequenceDiagram
participant Client
participant DataAPI
participant AuthContext
participant ProvenanceBundleService
participant PostgreSQL
Client->>DataAPI: Request export or import
DataAPI->>AuthContext: Resolve OIDC-authoritative scope
AuthContext-->>DataAPI: Return user, organization, and workspace
DataAPI->>ProvenanceBundleService: Process bounded provenance archive
ProvenanceBundleService->>PostgreSQL: Query or restore scoped records
PostgreSQL-->>ProvenanceBundleService: Return archive data or import receipt
ProvenanceBundleService-->>DataAPI: Return ZIP archive or receipt
DataAPI-->>Client: Return response
🚥 Pre-merge checks | ✅ 4✅ Passed checks (4 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
PR governance metadata gate is not ready for
|
|
Current-head remediation evidence for
Verification: full backend with warnings as errors: |
|
@coderabbitai review Please re-review exact current head |
|
Please review exact current head |
|
|
|
@coderabbitai review Please re-review exact current head |
|
Please review exact current head |
|
|
Dismissed as obsolete predecessor-head CHANGES_REQUESTED after the cited findings were addressed and their current review threads are resolved. This does not constitute approval and does not transfer any predecessor review evidence to current head 152d199.
|
Fresh exact-head gate correction (2026-09-03): the PR body still describes Run Repository-local Application CI, Security Scan, Dependency Review, SAST Semgrep, Bandit, and Docker checks on this exact head remain terminal-success. Do not mutate product code or transfer predecessor review evidence to satisfy the failed Noema control. Merge remains blocked until a fresh exact-head Noema result is terminal-valid, all then-live required checks are passing, and the required independent post-last-push approval exists. |
Exact-head review evidenceReviewed unchanged head
|
Connect PR #1497's bounded archive contract and real PostgreSQL validation to the product-technical baseline.\n\nAssisted-by: OpenAI Codex <codex@openai.com>
…ualWisdomLab/naruon into codex/pr1497-current # Conflicts: # CHANGELOG.md # backend/api/data.py # backend/scripts/bootstrap_db.py # backend/tests/test_bootstrap_db.py # docs/adr/README.md
|
현재 exact head 충돌은 기존 64 MiB PDF 경계, PostgreSQL 조건부 legacy-index bootstrap, provenance portability를 함께 유지하도록 통합했습니다. 중복 ADR-0005는 ADR-0007로 바꾸고 foundation 병합 전 상태를 Proposed로 낮췄습니다. 유효 child delta는 17개 파일이며 ADR-0007만 포함합니다. 검증: 비-PostgreSQL focused suite 157 passed / 117 skipped, Ruff 통과. 격리된 실제 |
…ties Preserve both parent deltas and reconcile bootstrap against the canonical owner implementation. Real migration and rollback tests pass; forced import overlap preserves the winner and rejects incompatible changes. Local integration checkpoint: 288 tests pass, but the unchanged large-content case still fails at the GiST index limit. Do not publish as passing integration until search-schema owner #1572 is inherited and the original case passes. Co-authored-by: Codex <noreply@openai.com> Signed-off-by: Seongho Bae <me@seonghobae.me>
…ities Normally merge the repaired PDF owner chain; retain both histories, all original archive bounds, and the unchanged large-content case. The unpublished merge revision becomes 0021 to join provenance identity and search storage 0020. Published IDs remain unchanged. Real migrated PostgreSQL: 345 tests pass with warnings as errors, zero failures or skips, including rollback and incompatible writers. Renumber the conflicting ADR proposal to 0022, preserve its lineage, and record source, artifact, and performance evidence limits. Co-authored-by: Codex <noreply@openai.com> Signed-off-by: Seongho Bae <me@seonghobae.me>
Current migrated integration receipt (2026-09-05)
Head
69f50ae684f50c501ff2f49be2969f1d211d7f3c, tree839d62316b5ff5f1e84e346e48982f0d4494c8c7, normally merges checkpoint7ee6e68c31b2e716210fc8b62e287a78b765062bwith #1427cb08b1c3ea2aba8844fc29ef703c34368cc55e47. The preserved stack is #1565 → #1503 → #1572 → #1468 → #1427 → #1497. No force push, PR close, or valid-delta deletion was used.345 tests pass, zero failed/skipped, with
-W error, after exactuv sync --lockedand fresh/repeated actual migration to the single0021_merge_provenance_workspacehead. The terminal run took 176.52 seconds and exit zero; its exact isolated Compose resources were cleaned up. Ruff, diff checks and 13 touched-document file links pass. The unchanged 8 MiB-classtest_export_counts_cited_segment_bytes_oncenow passes: the preceding 288-pass/1-failure checkpoint had exposed GiST overflow, repaired at #1572 instead of shrinking the fixture or dropping the indexes.Real migration regressions preserve existing portable-identity mappings through rollback/re-upgrade. Forced simultaneous identical and incompatible imports preserve the winning records; incompatible input yields one rejected writer with no losing rows/mappings. ADR-0022 corrects the prior lock description: the first lock keys the complete sorted portable-identity sets, followed by sorted per-email locks scoped to target user and organization. It does not claim to serialize every arbitrary partial overlap.
The local not-yet-pushed merge revision was renamed from 0020 to 0021 before publication, joining
0018_provenance_identityand0020_search_trigram_storage; inherited migration IDs remain intact. ADR-0007 collided with #1361, so its proposal/content/discussion lineage is preserved as ADR-0022. The PDF parent similarly carries ADR-0021, formerly 0005. The detailed source/history/artifact receipt isdocs/doctoring/tenant_provenance_integration.md; no competing canonical Gap ledger is introduced here.Keep Draft. The GIN storage candidate does not accelerate distance-only top-k ordering; representative p95 and migration costs, NewsDOM's immutable 64MiB release/exact pin, current-head hosted Checks and qualifying review, and signed HTTP/browser restore remain open acceptance gates. Local API success tests use service overrides, so no signed end-to-end restore or full customer-exit portability is claimed. Prior numerical/ADR receipts below retain their historical scope only.
Current evidence — 2026-09-05
Exact head:
705d8ece2c97edc8575ea59766fd8f68bf4cdb82; direct base #1427codex/pdf-dom-upload-64m@3a5f2b3751987fa8baaf85f96641e1659679aa80. Remains Draft/Proposed.uv run --frozen python -m pytest -q -W error -ra --tb=short tests/test_tenant_provenance_bundle.py tests/test_data_api.pyreturned 224 passed, 0 failed, 0 skipped in 12.53 seconds. This supersedes the earlier environment-skipped observation. The existing worktree environment retained packages outside the lock, so this is not clean-lock proof.uv run --frozen python scripts/migrate_db.pyon the same source head failed, exit 1, at0011_email_read_state:relation "emails" does not exist. The suite creates tables through ORM metadata, not that migration chain. A schema-fixture pass cannot be promoted to installability.19d5860bc27e860acba940390f5792721cd99e5e, non-force stacked on fix(test): install Starlette TestClient dependency #1565. Exact synchronization, fresh/repeated migration to0019_email_read_state_repair, 75 strict PostgreSQL/dependency tests, Ruff, and diff checks pass there. This PR has not yet inherited that repair.Historical PR description and receipts — superseded where inconsistent above
The following is retained for lineage. Its older heads, counts, and readiness statements are historical, not current gate evidence.
Summary
Adds a deterministic bounded BagIt + RO-Crate 1.3 + PROV archive for the exact project-evidence closure, with transactional tenant-scoped import, portable identity remapping, conflict detection, fail-closed metadata/security validation, and authoritative signed Data API export/import endpoints.
Exact current identity
develop@042b0c70531b229af3acbd0421a2f23098d848b3feat/tenant-provenance-roundtrip152d1998c4e8024be9dc7026c8789d343c884fd0The latest product-source change ensures PostgreSQL pool disposal still runs if connection cleanup itself fails. All current inline Devin/CodeRabbit review threads are resolved. Historical CHANGES_REQUESTED/dismissed submissions are predecessor governance evidence only and are not treated as approval.
Security and scope
tests/real_datasetswas not accessed or included.Exact-head repository evidence
For unchanged head
152d1998c4e8024be9dc7026c8789d343c884fd0at the latest fresh refetch:coverage-evidence: completed / success;APPROVEDreview: absent;opencode-reviewcheck-run99830468507: completed / failure because the authenticated dispatch never produced anopencode-agentAPPROVED or CHANGES_REQUESTED verdict on this exact head before the fail-closed poll ended;noema-reviewcheck-run99928013216: completed / failure after exact-head validation, sidecar startup andorchestrator/freepreflight; terminal model output was malformed JSON (Expecting ',' delimiter, response length 3540, SHA-2562ad0e386c189243f). Raw model output was correctly not logged.The two review-control failures are not Naruon product-source findings. Open central owner issues already cover the reproduced classes:
ContextualWisdomLab/.github#1531tracks OpenCode review queue/dispatch starvation and missing current-head verdicts;ContextualWisdomLab/.github#1637tracks malformed/truncated Noema verdict envelopes and typed fail-closed review-unavailable handling. Protected.github/mainhas advanced beyond the immutable workflow sources used by these historical runs, so rerunning the old Actions jobs would re-materialize predecessor workflow code and would not validate current owner repairs.Earlier local/backend pass counts, predecessor reviews, cancelled/skipped checks and predecessor central failures remain useful development history only and are not transferred as current merge gates.
Owner-path recovery boundary
Do not mutate Naruon product code to compensate for a canonical review-control defect. The central owner must reach protected GREEN for the failing class, after which this unchanged Naruon exact head needs a fresh trigger that materializes the then-current central workflow source. A normal merge requires fresh schema-valid OpenCode and Noema evidence on the exact current head, plus all other then-live required checks and a qualifying post-last-push independent approval.
Do not force-push, destructively rebase, self-approve, bypass branch protection, fabricate review evidence, transfer predecessor checks, broaden reviewer credentials or weaken a required gate.
Remaining product scope
Full mailbox-only mail portability, binary lifecycle, credentials, provider/connector state, embeddings, audit-history portability, and operator-safe remediation diagnostics remain explicitly outside this bounded slice unless a later accepted contract adds them.
Merge boundary
Do not merge until the unchanged exact head satisfies every then-live protected-branch/ruleset required check, fresh Noema/OpenCode current-head evidence is terminal passing, all valid review threads remain resolved, and the qualifying independent non-author approval required by live governance exists after the latest push. Failed, queued, pending, in-progress, skipped-required, absent, stale, predecessor, dismissed, model-only, status-only and author-only evidence is non-passing.