Skip to content

fix(workflows): allocate collision-free registry-audit ADR 0021 - #222

Draft
cursor[bot] wants to merge 57 commits into
fix/recovery-evidence-weakref-coverage-b84f0c9from
cursor/bc-df73ecc5-7f76-47cd-9c06-483e539fc6fd-f514
Draft

cursor[bot] wants to merge 57 commits into
fix/recovery-evidence-weakref-coverage-b84f0c9from
cursor/bc-df73ecc5-7f76-47cd-9c06-483e539fc6fd-f514

Conversation

@cursor

@cursor cursor Bot commented Aug 16, 2026 •

Copy link
Copy Markdown
Contributor

Read-only workflow-registry auditor — serialized stack authority

Current exact head is e3ea23746d004f189c433b78c799a78f821ca29c. This lane is now explicitly stacked on #233 exact 01d231fde23b82e2ced258d7bfcb4721ed75706d (fix/recovery-evidence-weakref-coverage-b84f0c9) rather than directly on protected main@5913c4bad79d6bc29d7cc1c624abb7db2ea6a77c.

The reconciliation is ordinary/non-force. Commit e3ea2374... has predecessor #222 head 46a34ec3d0e5994417adbca61f5d177c9036e60b as first parent and #233 as second parent. Fresh compare proves:

No #233 test was copied into this lane, no coverage threshold was weakened, no history was rewritten, and no force update occurred. The prior direct-main CI failure at Enforce line coverage is now executable wrong-base evidence rather than an auditor-source defect: the same repository 100% coverage gate is GREEN on the exact stacked head.

Preserved capability

This lane owns the read-only workflow-registry auditor: exact protected SHA/ref binding, protected-ref stability checks before/after audit, commit→tree identity resolution, truncated-tree rejection, bounded registry/response reads, exact primitive-type validation, double-read pagination stability, separate dynamic/ classification, fixed-origin GET-only transport, and no Actions mutation. The installable entry point remains pg-llm-batch-workflow-audit.

ADR 0021 remains Proposed until normal protected integration. Protected ADR 0022 already records 0021 as this #222 decision, so the numeric identity is retained rather than renumbered.

The effective 23-file delta contains only the auditor production module and checkout shim, ADR/doctoring evidence, one pyproject.toml console-script addition, ADR numeric-prefix regression, and focused auditor tests. Stale competing root AGENTS/CLAUDE/README/ARCHITECTURE/CHANGELOG copies remain absent. No database, provider, tenant/RLS, release-workflow, or Actions-state mutation is introduced by this lane.

Current exact-head verification

Fresh hosted evidence on exact e3ea2374... is now terminal:

  • CI 34695684133: SUCCESS. The prior Enforce line coverage RED disappears after the real test(recovery): cover stale evidence registry cleanup #233 ancestry repair, while the exact current auditor delta remains intact;
  • Release Acceptance 34695684209: SUCCESS;
  • Security Scan 34695684091: SUCCESS;
  • SAST Semgrep 34695684095: SUCCESS;
  • CodeQL PR 34695684080: FAILURE, with current chronology again identifying receiver-before-dispatch control-plane ordering rather than an auditor-source finding. The Actions receiver completed failure at 13:17:04Z and the Python receiver completed failure at 13:19:17Z; only afterward did Dispatch current-head CodeQL scan start at 13:21:08Z and complete successfully at 13:21:14Z. Both receivers had already reached terminal failure before the producer dispatch for this same exact head.

Fresh inline review-thread inventory is empty. Historical approval/review evidence on predecessor heads does not transfer, and no qualifying independent current-head APPROVED review exists.

The stack repair is therefore validated independently of the central CodeQL RED. Do not lower --cov-fail-under=100, copy #233's test, add a source-neutral wake commit, synthesize status, or duplicate the central workflow. The remaining CodeQL failure belongs to #244 and the live .github owner path.

Keep this PR Draft while #233 remains unintegrated and while current central/model-backed governance plus independent review remain non-passing. After any ancestry movement, reacquire supported-Python behavior including 3.14, exact 100% owned production statement/branch coverage, public docstrings, security/SAST, package/SBOM/provenance/reproducibility evidence, CodeQL, formal review, and thread state on the exact final head.

Mutable central workflow/ruleset state belongs to #244 and central owners. No self-approval, synthetic status, protected-main direct write, force push, destructive rebase, copied prerequisite test, gate weakening, source-neutral wake commit, or routine administrator bypass is authorized.

Refs #158, #229, #233, #244, #316, #321, #324; supersedes the old #211 landing vehicle.

@cursor

cursor Bot commented Aug 16, 2026

Copy link
Copy Markdown
Contributor Author

Bugbot is not enabled for your account, so this pull request was not reviewed.

Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs.

seonghobae
seonghobae previously approved these changes Aug 16, 2026

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed exact head 84866b5cb5467a675f51140179840b11e238e8be against protected main@d2f1e32271910a6db98a0757d67194ddadca4566. The read-only workflow-registry auditor is bound to an independently supplied protected SHA/ref, validates protected ref stability before/after the audit, resolves the exact commit tree, rejects truncated trees, bounds registry cardinality and response bytes, validates exact decoder primitive types on authority/identity/registry surfaces, double-reads multi-page registries to detect drift, classifies GitHub dynamic/ identities separately, and never mutates Actions state. ADR 0021 avoids the active recovery ADR namespace and the duplicate-prefix regression makes future collisions fail CI. No current inline review threads exist and I found no source-level must-fix in the reviewed delta. This approval applies only to this unchanged head; queued/pending/cancelled or predecessor checks do not count, and every then-live required workflow/check plus current mergeability/ancestry must be freshly terminal-success before merge.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Current exact head a3ccb8ce65c136ead85edfbe6d91032dead3a6f5 is not mergeable against protected main@76e704415651bdef6ceb06efa8db279349bea22e. Fresh ancestry shows this branch is 54 commits ahead and 1 behind with merge base 5267146534a259f85c0985e153f3f6cb1281f58f; the missing protected commit is merged #212, and this PR also modifies overlapping public documentation surfaces (README.md, ARCHITECTURE.md, CHANGELOG.md). GitHub currently reports mergeable=false. The previous approval was for predecessor head 84866b5cb5467a675f51140179840b11e238e8be and does not satisfy last-push review for this head.

Do not force-push or destructively rebase. The existing branch owner should incorporate current protected main through an auditable non-destructive update, resolve any #212 documentation conflicts while preserving both bounded contracts, and update stale body/source references that still call #212 open. Then reacquire exact-head checks and fresh review. I am not re-approving this non-mergeable head, and this comment does not waive any workflow/thread/ruleset gate.

seonghobae added a commit that referenced this pull request Aug 16, 2026
…228)

* test(recovery): require isolated restore-target service names

Add the RED contract for #204 isolated-target identity: a live
pg_service name and a restore-drill name must be exact distinct
libpq service identities. DSNs, tenant scope, subclasses, and
same-name reuse must fail closed before pg_restore.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>

* feat(recovery): isolate restore-target libpq service names

Succeed the #204 isolated-target gap without racing #212. Operators
must name a live pg_service and a distinct restore-drill service
before pg_restore. DSNs, tenant scope, and same-name reuse fail
closed. Allocate ADR 0021 so the record does not collide with
#216/#219/#221.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>

* fix(recovery): allocate collision-free restore-target ADR 0022

#222 already files ADR 0021 for the workflow-registry audit. Keep the
isolation seam unchanged and retarget this decision, doctoring, and the
documentation contract to 0022 after a fresh open-writer inventory.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>

* fix(recovery): require cluster identity for restore-target isolation

Distinct libpq service names are not cluster isolation. Require
caller-owned pg_control_system() identifiers so two aliases for the
same production cluster fail closed before pg_restore.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Co-authored-by: Seongho Bae <me@seonghobae.me>
@seonghobae
seonghobae marked this pull request as draft August 18, 2026 20:14
@opencode-agent opencode-agent Bot added area: ci-cd CI, GitHub Actions, checks, release, or supply chain priority: medium Normal-priority or P2 work status: draft Draft pull request type: docs Documentation, ADR, PRD, or technical writing labels Aug 22, 2026
@seonghobae seonghobae added the documentation Improvements or additions to documentation label Sep 6, 2026 — with ChatGPT Codex Connector
Preserve the bounded read-only registry-audit implementation and focused regressions while taking the current protected tree as content authority. Drop stale root documentation copies, retain live observability metadata, keep ADR 0021 Proposed until protected integration, and leave canonical public-document convergence to its active owners.
@coderabbitai

coderabbitai Bot commented Sep 12, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 86d68d95-b23a-4c18-a949-6f1eac7398ed

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Treat canonical UTC receipt syntax as an explicit package contract instead of inheriting Python-version-specific datetime normalization. Also bind the doctoring test to the stable SLSA specification URL rather than brittle prose punctuation.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Current-head repair finding on 46a34ec3d0e5994417adbca61f5d177c9036e60b: CI 34693549815 fails only in Coverage, docstrings, lint, and package at Enforce line coverage; compile/lint/docstrings pass, Python 3.10/3.14 unit lanes shown by the exact run are GREEN, and Release Acceptance/Security/Semgrep are separately GREEN. This PR is nevertheless still based directly on protected main@5913c4bad..., while earliest serialized prerequisite #233 (01d231fde...) carries tests/test_postgres_recovery_evidence_registry.py, the test-only coverage delta that makes the unchanged protected production tree satisfy the 100% gate.

Repair this as ancestry, not by lowering --cov-fail-under=100, copying #233's test, synthetic rerun, or closing valid #222 work. Preserve the registry-auditor delta and ordinary/non-force reconcile through #233 (or a verified full successor), then reacquire exact-final-head CI/package/security/SAST/CodeQL/review evidence. I am not moving this ref because this branch also received a concurrent current-head update during this run.

Preserve the exact 23-file workflow-registry-audit delta while inheriting #233's recovery-registry coverage evidence as ancestry. This is an ordinary two-parent reconciliation: no copied test, coverage weakening, history rewrite, or force update.
@seonghobae
seonghobae changed the base branch from main to fix/recovery-evidence-weakref-coverage-b84f0c9 September 12, 2026 13:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: ci-cd CI, GitHub Actions, checks, release, or supply chain documentation Improvements or additions to documentation priority: medium Normal-priority or P2 work status: draft Draft pull request type: docs Documentation, ADR, PRD, or technical writing

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants