fix(workflows): allocate collision-free registry-audit ADR 0021 - #222
cursor[bot] wants to merge 57 commits into
Conversation
|
Bugbot is not enabled for your account, so this pull request was not reviewed. Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs. |
seonghobae
left a comment
There was a problem hiding this comment.
Reviewed exact head 84866b5cb5467a675f51140179840b11e238e8be against protected main@d2f1e32271910a6db98a0757d67194ddadca4566. The read-only workflow-registry auditor is bound to an independently supplied protected SHA/ref, validates protected ref stability before/after the audit, resolves the exact commit tree, rejects truncated trees, bounds registry cardinality and response bytes, validates exact decoder primitive types on authority/identity/registry surfaces, double-reads multi-page registries to detect drift, classifies GitHub dynamic/ identities separately, and never mutates Actions state. ADR 0021 avoids the active recovery ADR namespace and the duplicate-prefix regression makes future collisions fail CI. No current inline review threads exist and I found no source-level must-fix in the reviewed delta. This approval applies only to this unchanged head; queued/pending/cancelled or predecessor checks do not count, and every then-live required workflow/check plus current mergeability/ancestry must be freshly terminal-success before merge.
seonghobae
left a comment
There was a problem hiding this comment.
Current exact head a3ccb8ce65c136ead85edfbe6d91032dead3a6f5 is not mergeable against protected main@76e704415651bdef6ceb06efa8db279349bea22e. Fresh ancestry shows this branch is 54 commits ahead and 1 behind with merge base 5267146534a259f85c0985e153f3f6cb1281f58f; the missing protected commit is merged #212, and this PR also modifies overlapping public documentation surfaces (README.md, ARCHITECTURE.md, CHANGELOG.md). GitHub currently reports mergeable=false. The previous approval was for predecessor head 84866b5cb5467a675f51140179840b11e238e8be and does not satisfy last-push review for this head.
Do not force-push or destructively rebase. The existing branch owner should incorporate current protected main through an auditable non-destructive update, resolve any #212 documentation conflicts while preserving both bounded contracts, and update stale body/source references that still call #212 open. Then reacquire exact-head checks and fresh review. I am not re-approving this non-mergeable head, and this comment does not waive any workflow/thread/ruleset gate.
…228) * test(recovery): require isolated restore-target service names Add the RED contract for #204 isolated-target identity: a live pg_service name and a restore-drill name must be exact distinct libpq service identities. DSNs, tenant scope, subclasses, and same-name reuse must fail closed before pg_restore. Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com> * feat(recovery): isolate restore-target libpq service names Succeed the #204 isolated-target gap without racing #212. Operators must name a live pg_service and a distinct restore-drill service before pg_restore. DSNs, tenant scope, and same-name reuse fail closed. Allocate ADR 0021 so the record does not collide with #216/#219/#221. Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com> * fix(recovery): allocate collision-free restore-target ADR 0022 #222 already files ADR 0021 for the workflow-registry audit. Keep the isolation seam unchanged and retarget this decision, doctoring, and the documentation contract to 0022 after a fresh open-writer inventory. Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com> * fix(recovery): require cluster identity for restore-target isolation Distinct libpq service names are not cluster isolation. Require caller-owned pg_control_system() identifiers so two aliases for the same production cluster fail closed before pg_restore. Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com> --------- Co-authored-by: Cursor Agent <cursoragent@cursor.com> Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com> Co-authored-by: Seongho Bae <me@seonghobae.me>
Preserve the bounded read-only registry-audit implementation and focused regressions while taking the current protected tree as content authority. Drop stale root documentation copies, retain live observability metadata, keep ADR 0021 Proposed until protected integration, and leave canonical public-document convergence to its active owners.
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Treat canonical UTC receipt syntax as an explicit package contract instead of inheriting Python-version-specific datetime normalization. Also bind the doctoring test to the stable SLSA specification URL rather than brittle prose punctuation.
seonghobae
left a comment
There was a problem hiding this comment.
Current-head repair finding on 46a34ec3d0e5994417adbca61f5d177c9036e60b: CI 34693549815 fails only in Coverage, docstrings, lint, and package at Enforce line coverage; compile/lint/docstrings pass, Python 3.10/3.14 unit lanes shown by the exact run are GREEN, and Release Acceptance/Security/Semgrep are separately GREEN. This PR is nevertheless still based directly on protected main@5913c4bad..., while earliest serialized prerequisite #233 (01d231fde...) carries tests/test_postgres_recovery_evidence_registry.py, the test-only coverage delta that makes the unchanged protected production tree satisfy the 100% gate.
Repair this as ancestry, not by lowering --cov-fail-under=100, copying #233's test, synthetic rerun, or closing valid #222 work. Preserve the registry-auditor delta and ordinary/non-force reconcile through #233 (or a verified full successor), then reacquire exact-final-head CI/package/security/SAST/CodeQL/review evidence. I am not moving this ref because this branch also received a concurrent current-head update during this run.
Preserve the exact 23-file workflow-registry-audit delta while inheriting #233's recovery-registry coverage evidence as ancestry. This is an ordinary two-parent reconciliation: no copied test, coverage weakening, history rewrite, or force update.
Read-only workflow-registry auditor — serialized stack authority
Current exact head is
e3ea23746d004f189c433b78c799a78f821ca29c. This lane is now explicitly stacked on #233 exact01d231fde23b82e2ced258d7bfcb4721ed75706d(fix/recovery-evidence-weakref-coverage-b84f0c9) rather than directly on protectedmain@5913c4bad79d6bc29d7cc1c624abb7db2ea6a77c.The reconciliation is ordinary/non-force. Commit
e3ea2374...has predecessor #222 head46a34ec3d0e5994417adbca61f5d177c9036e60bas first parent and #233 as second parent. Fresh compare proves:tests/test_postgres_recovery_evidence_registry.pyinherited from test(recovery): cover stale evidence registry cleanup #233;No #233 test was copied into this lane, no coverage threshold was weakened, no history was rewritten, and no force update occurred. The prior direct-main CI failure at
Enforce line coverageis now executable wrong-base evidence rather than an auditor-source defect: the same repository 100% coverage gate is GREEN on the exact stacked head.Preserved capability
This lane owns the read-only workflow-registry auditor: exact protected SHA/ref binding, protected-ref stability checks before/after audit, commit→tree identity resolution, truncated-tree rejection, bounded registry/response reads, exact primitive-type validation, double-read pagination stability, separate
dynamic/classification, fixed-origin GET-only transport, and no Actions mutation. The installable entry point remainspg-llm-batch-workflow-audit.ADR 0021 remains Proposed until normal protected integration. Protected ADR 0022 already records 0021 as this #222 decision, so the numeric identity is retained rather than renumbered.
The effective 23-file delta contains only the auditor production module and checkout shim, ADR/doctoring evidence, one
pyproject.tomlconsole-script addition, ADR numeric-prefix regression, and focused auditor tests. Stale competing root AGENTS/CLAUDE/README/ARCHITECTURE/CHANGELOG copies remain absent. No database, provider, tenant/RLS, release-workflow, or Actions-state mutation is introduced by this lane.Current exact-head verification
Fresh hosted evidence on exact
e3ea2374...is now terminal:34695684133: SUCCESS. The priorEnforce line coverageRED disappears after the real test(recovery): cover stale evidence registry cleanup #233 ancestry repair, while the exact current auditor delta remains intact;34695684209: SUCCESS;34695684091: SUCCESS;34695684095: SUCCESS;34695684080: FAILURE, with current chronology again identifying receiver-before-dispatch control-plane ordering rather than an auditor-source finding. The Actions receiver completed failure at13:17:04Zand the Python receiver completed failure at13:19:17Z; only afterward didDispatch current-head CodeQL scanstart at13:21:08Zand complete successfully at13:21:14Z. Both receivers had already reached terminal failure before the producer dispatch for this same exact head.Fresh inline review-thread inventory is empty. Historical approval/review evidence on predecessor heads does not transfer, and no qualifying independent current-head
APPROVEDreview exists.The stack repair is therefore validated independently of the central CodeQL RED. Do not lower
--cov-fail-under=100, copy #233's test, add a source-neutral wake commit, synthesize status, or duplicate the central workflow. The remaining CodeQL failure belongs to #244 and the live.githubowner path.Keep this PR Draft while #233 remains unintegrated and while current central/model-backed governance plus independent review remain non-passing. After any ancestry movement, reacquire supported-Python behavior including 3.14, exact 100% owned production statement/branch coverage, public docstrings, security/SAST, package/SBOM/provenance/reproducibility evidence, CodeQL, formal review, and thread state on the exact final head.
Mutable central workflow/ruleset state belongs to #244 and central owners. No self-approval, synthetic status, protected-main direct write, force push, destructive rebase, copied prerequisite test, gate weakening, source-neutral wake commit, or routine administrator bypass is authorized.
Refs #158, #229, #233, #244, #316, #321, #324; supersedes the old #211 landing vehicle.