Skip to content

feat(audit): persist append-only checkpoint acceptance trail - #62

Closed
seonghobae wants to merge 50 commits into
agent/checkpoint-opentelemetry-observabilityfrom
agent/checkpoint-audit-trail
Closed

seonghobae wants to merge 50 commits into
agent/checkpoint-opentelemetry-observabilityfrom
agent/checkpoint-audit-trail

Conversation

@seonghobae

@seonghobae seonghobae commented Aug 7, 2026 •

Copy link
Copy Markdown
Contributor

Commercial and acquisition gap

Durable checkpoint persistence and best-effort OpenTelemetry observability do not by themselves provide durable application audit evidence. This bounded stacked slice adds package-owned, tenant-isolated accepted-save evidence without claiming cryptographic non-repudiation or administrator-proof tamper resistance.

Implemented bounded vertical slice

  • adds opt-in AuditedPostgresBatchResultCheckpointStore on top of the durable PostgreSQL checkpoint store;
  • appends one fixed checkpoint_save_accepted event after every successful save call, including exact idempotent repeats, in the same PostgreSQL transaction as checkpoint persistence;
  • creates no success event after validation or compare-and-swap rejection;
  • exposes an immutable, strictly revalidated CheckpointAuditEvent and newest-first bounded reads with a non-coercive 1..1,000 limit;
  • keeps audit lookups tenant-qualified by trusted tenant, consumer, endpoint, and remote batch identity;
  • stores only structured checkpoint identity/coordinates and prefix digest, excluding prompts, provider bodies, model output, credentials, DSNs, transport headers, exception text, and arbitrary free-form log content;
  • adds llm_result_checkpoint_audit_events with forced RLS, fixed-value/checkpoint constraints, descriptive snake_case indexes/policy/triggers, UPDATE/DELETE rejection, and a statement-level TRUNCATE rejection trigger;
  • timestamps accepted-save rows with PostgreSQL clock_timestamp() at row insertion rather than transaction-start NOW()/CURRENT_TIMESTAMP;
  • idempotently repairs the future-row timestamp default on migration reapplication without rewriting retained evidence;
  • adds a fail-closed rollback that refuses to erase non-empty audit evidence across tenants;
  • keeps package and Docker audit migrations byte-identical and installs audit schema after durable checkpoint schema on fresh bundled PostgreSQL data directories;
  • verifies the permanent live PostgreSQL boundary with two random restricted roles: a normal NOSUPERUSER ... NOBYPASSRLS application role and a separate mutation-probe role;
  • grants the application role only checkpoint SELECT/INSERT/UPDATE, audit SELECT/INSERT, and USAGE/SELECT on the exact audit identity sequence resolved through pg_get_serial_sequence() plus parse_ident();
  • grants the mutation-probe role only the audit-table rights needed to prove UPDATE/DELETE/TRUNCATE rejection with SQLSTATE 55000, without checkpoint-table or audit-sequence authority;
  • scopes workflow contract assertions to the exact audit job/service/environment/steps and scopes each setup-uv pin, version, and cache control to its own step, so unrelated jobs, comments, and sibling steps cannot satisfy the gate;
  • keeps the CI token at contents: read, checkout credential persistence disabled, and the live verification job non-writing with respect to the repository; and
  • updates public exports, AGENTS, CLAUDE, ARCHITECTURE, CHANGELOG, ADR 0009, operator guidance, and doctoring with APA 7 references to NIST SP 800-53 Rev. 5 AU-3, the OWASP Logging Cheat Sheet, and PostgreSQL 18 trigger/current-time semantics.

No temporary or write-capable repair workflow, generated coverage database, build product, cache, version bump, publication, or release authority is included.

Strict RED → GREEN → refactor evidence

  • Stacked predecessor at slice start: PR feat(observability): instrument durable checkpoint operations #61 exact head 8a2deeb14c23d9db97bbad1d4c68837b6c8591cc.
  • Initial production RED head 3dfab0d6132e523396d2b2e27125aff34d8565e4; CI 31138134741 failed collection because pg_llm_batch.checkpoint_audit intentionally did not exist.
  • Live-gate RED head 467f40e7282b6916c7e681636550c7c215db88e2; CI 31139284742 failed because the permanent live PostgreSQL audit job did not yet exist.
  • Live setup RED head 31a584c62bab27774c93a18adbbacec22699bc78; CI 31139440808 exposed invalid protocol parameterization of CREATE ROLE ... PASSWORD, leading to safe psycopg composable identifiers/literals and fail-safe partial-provision cleanup.
  • Event-time test-first heads 9e43420097faabd97deab079c34c5e4e0207eb86, 19b39a23dc7e29a467cc6c0d6817f06b5da1e880, and 78184f6202d06831800ef3e90db498e9e04e26b5 encoded insert-time wall-clock semantics and idempotent migration repair before implementation. Their superseded/cancelled workflow is not counted as success.
  • Least-privilege RED head 5dfdecfaf1fb7a4d88be338bd44eddb69814a174; CI 31148349909, job 92772560159, failed the permanent role-binding contract because the application role still held audit mutation rights and blanket public-schema sequence access.
  • Refactor head b8d28af14d4ecef3d4497c11c782d13ded25d7d7; CI 31148738607 proved the live PostgreSQL role split succeeded but exposed two brittle workflow-parser tests. That run is failure evidence only and is not reused as success.
  • Current exact GREEN head 2820aa36d8dedf7d89d1b745e5728acf3b913d2b contains the least-privilege role separation, exact identity-sequence grant, scoped workflow parsing, decoy regressions, authoritative documentation, and changelog repair.

Current exact-head evidence

  • Head: 2820aa36d8dedf7d89d1b745e5728acf3b913d2b.
  • PR base metadata: 8a2deeb14c23d9db97bbad1d4c68837b6c8591cc on agent/checkpoint-opentelemetry-observability; the current predecessor branch tip is PR feat(observability): instrument durable checkpoint operations #61 head f3059450f1f263ed59979ae94fb7bf5b621616be. Connector base metadata is not treated as current integrated-base evidence.
  • CI 31148932545: success on the exact current head. Python 3.10/3.12/3.14 unit tests, coverage/docstrings/lint/package, container builds, and the live PostgreSQL checkpoint-audit integration completed successfully.
  • Production statement and branch coverage: 100% on the exact current head.
  • Production docstring coverage: 100% on the exact current head.
  • Release Acceptance 31148932566: success on the exact current head, including reproducible wheel and source distribution verification. This is acceptance evidence only; no version bump or publication is authorized by this stacked draft.
  • CodeRabbit commit status: success on the exact current head. Automated status is not independent approval.
  • Unresolved inline review threads: zero; all three valid CodeRabbit findings were addressed before resolution.
  • Submitted formal reviews: no qualifying independent non-author GitHub APPROVED review exists on the current exact head.
  • No queued, pending, cancelled, skipped-required, absent, predecessor-head, stale-base, or synthetic-merge result is counted as success. Branch-protection and security-check surfaces not exposed by the connector remain unproven rather than assumed green.

Dependency and merge boundary

Required order remains:

.github#790 -> pg-llm-batch#53 -> #55 -> #56 -> #57 -> #58 -> #59 -> #60 -> #61 -> this PR.

This PR remains a stacked draft. It must not be marked ready or merged until every prerequisite integrates into main, the branch is reconciled onto the actual integrated base without losing predecessor fixes, and fresh integrated exact-head/exact-base quality, security, dependency, packaging, migration, rollback, live PostgreSQL, container, provenance, supply-chain, release-acceptance, branch-protection, and independent-review gates succeed. Zero unresolved valid findings and a qualifying independent non-author GitHub APPROVED review are mandatory. Staged-base or synthetic merge-result evidence is not reusable as final integrated release evidence.

Summary by CodeRabbit

  • 새로운 기능

    • 체크포인트 저장 성공 이벤트를 PostgreSQL에 감사 기록으로 남깁니다.
    • 테넌트별 최신 감사 이벤트 조회를 지원하며, 최대 1,000건으로 제한됩니다.
    • 감사 기록의 수정·삭제·초기화를 차단해 변경 불가 이력을 제공합니다.
  • 보안 및 테스트

    • 일반 애플리케이션 역할과 mutation-probe 역할을 분리하고 정확한 감사 identity sequence에만 최소 권한을 부여합니다.
    • PostgreSQL 기반 통합 테스트와 테넌트 격리·트랜잭션·롤백·권한 경계 검증을 추가합니다.

@coderabbitai

coderabbitai Bot commented Aug 7, 2026 •

Copy link
Copy Markdown

Review Change Stack

Important

Review skipped

Draft detected.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 86e3fecb-4fae-4b6b-b2c0-49ed742350ed

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

PostgreSQL 체크포인트 저장 성공 감사 기능을 추가했습니다. 감사 이벤트는 저장과 같은 트랜잭션에 기록됩니다. 테넌트 격리, append-only 제약, 롤백 제한, 감사 조회 및 PostgreSQL 통합 CI 검증을 구현했습니다.

Changes

체크포인트 감사 추적

Layer / File(s) Summary
감사 계약과 운영 문서
AGENTS.md, ARCHITECTURE.md, CLAUDE.md, CHANGELOG.md, docs/adr/..., docs/checkpoint-audit.md, docs/checkpoint-observability.md, docs/doctoring/...
성공한 저장의 트랜잭션 결합, clock_timestamp(), 테넌트 범위 조회, 최대 1,000건 제한, 민감정보 제외, 보존 및 변조 방지 범위를 문서화했습니다.
감사 스키마와 배포 순서
pg_llm_batch/migrations/..., docker/postgres/..., pg_llm_batch/__init__.py
감사 테이블과 제약조건, 강제 RLS, UPDATE·DELETE·TRUNCATE 차단 트리거, 비어 있지 않은 감사 데이터의 롤백 거부, Docker 초기화 순서 및 공개 API를 추가했습니다.
감사 저장소 구현
pg_llm_batch/checkpoint_audit.py
CheckpointAuditEvent와 AuditedPostgresBatchResultCheckpointStore를 추가했습니다. 성공 저장과 멱등 재저장을 같은 트랜잭션에 기록합니다. 테넌트 한정 최신 감사 조회를 제공합니다.
계약 및 저장소 검증
tests/test_checkpoint_audit_contract.py, tests/test_checkpoint_audit_store.py
입력 검증, 마이그레이션 동일성, 단일 커밋, 실패 시 이벤트 부재, 조회 제한 및 테넌트 범위를 검증합니다.
PostgreSQL 통합 검증과 CI
.github/workflows/ci.yml, tests/test_checkpoint_audit_ci_contract.py, tests/test_checkpoint_audit_integration.py, tests/test_checkpoint_telemetry_concurrency.py, tests/test_dependency_refresh_contract.py
고정 PostgreSQL 16 환경에서 감사 이벤트, 시간 범위, 테넌트 격리, 변경 차단 및 롤백을 검증합니다. CI 계약과 기존 테스트 계약도 갱신했습니다.

Estimated code review effort: 4 (Complex) | ~45 minutes

Sequence Diagram(s)

sequenceDiagram
  participant 호출자
  participant 감사저장소
  participant PostgreSQL
  호출자->>감사저장소: save()
  감사저장소->>PostgreSQL: 체크포인트 저장
  감사저장소->>PostgreSQL: checkpoint_save_accepted 삽입
  PostgreSQL-->>호출자: 결과 반환 또는 트랜잭션 오류
Loading
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed Docstring coverage is 93.48% which is sufficient. The required threshold is 80.00%.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed 제목은 성공한 체크포인트 저장의 append-only 감사 추적을 추가하는 주요 변경 사항을 정확하고 간결하게 설명합니다.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch agent/checkpoint-audit-trail

Comment @coderabbitai help to get the list of available commands.

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

@opencode-agent @cwl-noema-review

Perform a review-only inspection of exact stacked head f765afa7f68391cf0460a8a151667ec3eaff2543 against the actual current predecessor tip f3059450f1f263ed59979ae94fb7bf5b621616be. Do not mutate branches, mark ready, or merge. Focus on same-transaction checkpoint/audit atomicity, RLS and least-privilege behavior, append-only UPDATE/DELETE/TRUNCATE enforcement, rollback refusal across tenants, clock_timestamp() insert-time semantics under caller-owned transactions, migration reapplication, database object naming, confidential evidence fields, bounded reads, PostgreSQL 16 live-gate realism, and APA 7 authority accuracy. Treat existing staged CI/Release Acceptance as supporting evidence only. Submit findings as review comments; submit formal approval only after final integrated-main reconciliation and exact protected-gate success.

@coderabbitai

coderabbitai Bot commented Aug 7, 2026 •

Copy link
Copy Markdown
🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

base="f3059450f1f263ed59979ae94fb7bf5b621616be"
head="f765afa7f68391cf0460a8a151667ec3eaff2543"

git cat-file -e "${base}^{commit}"
git cat-file -e "${head}^{commit}"
printf '%s\n' '=== commit ancestry ==='
git merge-base --is-ancestor "$base" "$head" && echo "base_is_ancestor=yes" || echo "base_is_ancestor=no"
git show -s --format='base=%H%nbase_subject=%s' "$base"
git show -s --format='head=%H%nhead_subject=%s' "$head"

printf '%s\n' '=== changed paths ==='
git diff --name-status "$base" "$head"

printf '%s\n' '=== relevant source candidates ==='
fd -t f . | rg -i '(audit|checkpoint|migration|postgres|docker|workflow|ci|operator|architecture|adr|changelog|agents|claude|doctor)'

printf '%s\n' '=== Python structure ==='
fd -e py . | xargs -r ast-grep outline --items all --type class,function --match 'Audit|Checkpoint|audit|checkpoint' --view compact

printf '%s\n' '=== SQL and workflow excerpts ==='
git diff --unified=80 "$base" "$head" -- \
  '*.sql' \
  '*.yml' \
  '*.yaml' \
  '*audit*' \
  '*checkpoint*' \
  'README.md' \
  'CHANGELOG.md' \
  'AGENTS.md' \
  'CLAUDE.md' \
  'ARCHITECTURE.md' \
  'docs/**' \
  ':!*.pyc'

Length of output: 5853


🏁 Script executed:

#!/bin/bash
set -euo pipefail

base="f3059450f1f263ed59979ae94fb7bf5b621616be"
head="f765afa7f68391cf0460a8a151667ec3eaff2543"

printf '%s\n' '=== checked-out and requested tree identities ==='
git rev-parse HEAD
git rev-parse "$head^{tree}"
git merge-base "$base" "$head"
git diff --stat "$base" "$head"

printf '%s\n' '=== audit and checkpoint module outlines ==='
ast-grep outline pg_llm_batch/checkpoint_audit.py --items all --view signatures
ast-grep outline pg_llm_batch/checkpoint_store.py --items all --view signatures

printf '%s\n' '=== audit store implementation ==='
git show "$head:pg_llm_batch/checkpoint_audit.py"

printf '%s\n' '=== checkpoint store transaction implementation ==='
git show "$head:pg_llm_batch/checkpoint_store.py" | sed -n '1,460p'

printf '%s\n' '=== package migration ==='
git show "$head:pg_llm_batch/migrations/0008_result_checkpoint_audit_events.sql"

printf '%s\n' '=== rollback migration ==='
git show "$head:pg_llm_batch/migrations/rollback/0008_result_checkpoint_audit_events.sql"

printf '%s\n' '=== package/Docker migration identity ==='
git show "$head:pg_llm_batch/migrations/0008_result_checkpoint_audit_events.sql" > /tmp/package-audit-migration.sql
git show "$head:docker/postgres/init/04_result_checkpoint_audit_events.sql" > /tmp/docker-audit-migration.sql
sha256sum /tmp/package-audit-migration.sql /tmp/docker-audit-migration.sql
cmp -s /tmp/package-audit-migration.sql /tmp/docker-audit-migration.sql && echo 'migration_bytes_identical=yes' || echo 'migration_bytes_identical=no'

printf '%s\n' '=== public export and changed test outlines ==='
git show "$head:pg_llm_batch/__init__.py"
for f in tests/test_checkpoint_audit_contract.py tests/test_checkpoint_audit_store.py tests/test_checkpoint_audit_integration.py tests/test_checkpoint_audit_ci_contract.py tests/test_dependency_refresh_contract.py; do
  echo "--- $f"
  ast-grep outline "$f" --items all --view signatures
done

printf '%s\n' '=== CI audit-related sections ==='
git show "$head:.github/workflows/ci.yml" | rg -n -C 18 -i 'audit|postgres|setup-uv|checkpoint'

Length of output: 47909


🏁 Script executed:

#!/bin/bash
set -euo pipefail

head="f765afa7f68391cf0460a8a151667ec3eaff2543"

show() {
  printf '\n=== %s ===\n' "$1"
  git show "$head:$1"
}

show tests/test_checkpoint_audit_integration.py
show tests/test_checkpoint_audit_store.py
show tests/test_checkpoint_audit_contract.py
show tests/test_checkpoint_audit_ci_contract.py
show pg_llm_batch/db.py
show pg_llm_batch/migrations/0007_result_stream_checkpoints.sql
show docker/postgres/Dockerfile
show docs/adr/0009-append-only-checkpoint-audit-trail.md
show docs/checkpoint-audit.md
show docs/doctoring/checkpoint-audit-trail.md

printf '%s\n' '=== migration-related references and privileges ==='
rg -n -C 4 \
  'llm_result_checkpoint_audit_events|reject_checkpoint_audit_mutation|GRANT|REVOKE|tenant_scope|FORCE ROW|clock_timestamp|CURRENT_TIMESTAMP|NOW\(\)' \
  pg_llm_batch docker tests docs AGENTS.md ARCHITECTURE.md CLAUDE.md CHANGELOG.md

printf '%s\n' '=== APA-style reference locations ==='
rg -n -C 6 -i 'NIST|OWASP|SP 800-53|APA|References|PostgreSQL 18|trigger|current time' \
  AGENTS.md ARCHITECTURE.md CHANGELOG.md CLAUDE.md docs

Length of output: 201616


🏁 Script executed:

#!/bin/bash
set -euo pipefail

head="f765afa7f68391cf0460a8a151667ec3eaff2543"

for spec in \
  'tests/test_checkpoint_audit_integration.py:1,280' \
  'tests/test_checkpoint_audit_store.py:1,380' \
  'tests/test_checkpoint_audit_contract.py:1,140' \
  'pg_llm_batch/db.py:1,180' \
  'pg_llm_batch/migrations/0007_result_stream_checkpoints.sql:1,260' \
  'docker/postgres/Dockerfile:1,160' \
  '.github/workflows/ci.yml:1,155' \
  'docs/checkpoint-audit.md:1,150'; do
  file="${spec%%:*}"
  ranges="${spec#*:}"
  start="${ranges%,*}"
  end="${ranges#*,}"
  printf '\n=== %s lines %s-%s ===\n' "$file" "$start" "$end"
  git show "$head:$file" | nl -ba | sed -n "${start},${end}p"
done

printf '%s\n' '=== audit-specific SQL test assertions ==='
git show "$head:tests/test_checkpoint_audit_contract.py" | nl -ba

printf '%s\n' '=== audit-specific changed diff with line numbers ==='
git diff --unified=12 f3059450f1f263ed59979ae94fb7bf5b621616be "$head" -- \
  pg_llm_batch/checkpoint_audit.py \
  pg_llm_batch/migrations/0008_result_checkpoint_audit_events.sql \
  pg_llm_batch/migrations/rollback/0008_result_checkpoint_audit_events.sql \
  tests/test_checkpoint_audit_integration.py \
  .github/workflows/ci.yml

Length of output: 1622


🤖 web_search executed:

Official PostgreSQL 18 documentation: CREATE TRIGGER TRUNCATE triggers are statement-level, and clock_timestamp() returns the actual current time rather than transaction-start time. Provide the official URLs and publication or documentation metadata.

Length of output: 10208


🏁 Script executed:

#!/bin/bash
set -euo pipefail

head="f765afa7f68391cf0460a8a151667ec3eaff2543"

show_range() {
  file="$1"
  start="$2"
  end="$3"
  printf '\n=== %s lines %s-%s ===\n' "$file" "$start" "$end"
  git show "$head:$file" | sed -n "${start},${end}p"
}

show_range tests/test_checkpoint_audit_integration.py 1 280
show_range tests/test_checkpoint_audit_store.py 1 380
show_range tests/test_checkpoint_audit_contract.py 1 140
show_range pg_llm_batch/db.py 1 180
show_range pg_llm_batch/migrations/0007_result_stream_checkpoints.sql 1 260
show_range docker/postgres/Dockerfile 1 160
show_range .github/workflows/ci.yml 1 155
show_range docs/checkpoint-audit.md 1 150

printf '%s\n' '=== audit-specific changed diff ==='
git diff --unified=12 f3059450f1f263ed59979ae94fb7bf5b621616be "$head" -- \
  pg_llm_batch/checkpoint_audit.py \
  pg_llm_batch/migrations/0008_result_checkpoint_audit_events.sql \
  pg_llm_batch/migrations/rollback/0008_result_checkpoint_audit_events.sql \
  tests/test_checkpoint_audit_integration.py \
  .github/workflows/ci.yml

Length of output: 80201


@seonghobae I completed a read-only staged review of f765afa7f68391cf0460a8a151667ec3eaff2543.

I found one least-privilege issue.

  • P2 — Reduce the live application-role grants. In tests/test_checkpoint_audit_integration.py, the random application role receives UPDATE, DELETE, and TRUNCATE on llm_result_checkpoint_audit_events, plus USAGE, SELECT ON ALL SEQUENCES IN SCHEMA public. Normal audited-store operation needs only audit-table SELECT and INSERT, and access to the audit identity sequence. The broad grants make the stated least-privilege proof inaccurate and can mask unintended dependencies on mutation privileges. Use a separate temporary mutation-probe role, or apply temporary mutation grants only around the trigger checks. Grant sequence access only to the audit identity sequence.

I found no additional defect in the reviewed same-transaction write sequence, forced-RLS policy, append-only trigger behavior, non-empty rollback refusal, clock_timestamp() default repair, bounded tenant-qualified reads, confidential audit fields, Docker migration ordering, or PostgreSQL 16 test setup.

The PostgreSQL authority supports the documented semantics: clock_timestamp() returns actual current time, and TRUNCATE triggers are statement-level only.

The package and Docker audit migrations have identical SHA-256 values. The reviewed head is exact. The requested predecessor tip is not an ancestor of this head. Their common merge base is 8a2deeb14c23d9db97bbad1d4c68837b6c8591cc. Therefore, this review is staged-stack evidence only. I did not approve the PR. Final approval remains blocked pending prerequisite integration, reconciliation onto the actual integrated base, and fresh protected exact-head checks.

✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 3

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@docs/doctoring/checkpoint-audit-trail.md`:
- Around line 114-119: 분리된 역할별 권한 계약과 mutation-probe 검증을 반영하십시오. 통합 테스트의 애플리케이션
역할에는 체크포인트 테이블의 SELECT·INSERT·UPDATE와 감사 테이블의 SELECT·INSERT만 부여하고, 감사 identity
sequence 권한만 허용하십시오. 감사 테이블의 UPDATE·DELETE·TRUNCATE 및 `55000` 실패 검증은 별도의
mutation-probe 역할로 수행하며, 문서의 권한 설명과 테스트 설정을 동일하게 갱신하십시오.

In `@tests/test_checkpoint_audit_ci_contract.py`:
- Around line 9-21: Replace the raw text checks in
tests/test_checkpoint_audit_ci_contract.py:9-21 with parsed YAML assertions
scoped to the checkpoint-audit-integration job, verifying its PostgreSQL
service, matching DSN, persist-credentials: false, and integration test command
within the appropriate job or step. Also update
tests/test_dependency_refresh_contract.py:11-19 to inspect each
astral-sh/setup-uv step independently and require version "0.12.1" and
prune-cache: true in that same step scope.

In `@tests/test_checkpoint_audit_integration.py`:
- Around line 92-110: Update the role grants in the checkpoint audit setup
around database_admin and cursor.execute: grant the normal application role only
SELECT and INSERT on llm_result_checkpoint_audit_events, plus the minimum
USAGE/SELECT permissions on the specific audit sequence it requires; remove
UPDATE, DELETE, TRUNCATE, and the blanket grant on all public-schema sequences.
Use a separate temporary mutation-probe role for validating append-only trigger
rejection.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: c15dfcca-11b3-431c-a546-58f66f88280f

📥 Commits

Reviewing files that changed from the base of the PR and between 8a2deeb and f765afa.

📒 Files selected for processing (21)
  • .github/workflows/ci.yml
  • AGENTS.md
  • ARCHITECTURE.md
  • CHANGELOG.md
  • CLAUDE.md
  • docker/postgres/Dockerfile
  • docker/postgres/init/04_result_checkpoint_audit_events.sql
  • docs/adr/0009-append-only-checkpoint-audit-trail.md
  • docs/checkpoint-audit.md
  • docs/checkpoint-observability.md
  • docs/doctoring/checkpoint-audit-trail.md
  • pg_llm_batch/__init__.py
  • pg_llm_batch/checkpoint_audit.py
  • pg_llm_batch/migrations/0008_result_checkpoint_audit_events.sql
  • pg_llm_batch/migrations/rollback/0008_result_checkpoint_audit_events.sql
  • tests/test_checkpoint_audit_ci_contract.py
  • tests/test_checkpoint_audit_contract.py
  • tests/test_checkpoint_audit_integration.py
  • tests/test_checkpoint_audit_store.py
  • tests/test_checkpoint_telemetry_concurrency.py
  • tests/test_dependency_refresh_contract.py

Comment thread docs/doctoring/checkpoint-audit-trail.md Outdated
Comment thread tests/test_checkpoint_audit_ci_contract.py Outdated
Comment thread tests/test_checkpoint_audit_integration.py

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@opencode-agent @cwl-noema-review

Review-only request for exact head 2820aa36d8dedf7d89d1b745e5728acf3b913d2b against stacked base branch agent/checkpoint-opentelemetry-observability. Do not mutate the branch, create a repair workflow, mark ready, or merge. Independently verify the separated application/mutation-probe PostgreSQL roles, exact identity-sequence grant, tenant/RLS and append-only boundaries, scoped CI contracts, migration/rollback safety, 100% production statement/branch and docstring evidence, reproducible-package acceptance, and absence of generated artifacts. Treat the current draft stack and missing independent non-author approval as blocking merge boundaries.

Copy link
Copy Markdown
Contributor Author

Exact-current-base ancestry audit (no branch mutation): source head 2820aa36d8dedf7d89d1b745e5728acf3b913d2b; live stacked base agent/checkpoint-opentelemetry-observability tip f3059450f1f263ed59979ae94fb7bf5b621616be. Git comparison is 44 ahead / 2 behind, merge base 8a2deeb14c23d9db97bbad1d4c68837b6c8591cc.

The two base-only predecessor corrections are already byte-identical on this source head: docs/checkpoint-observability.md is blob c77cfe7e33e202bd1c41dbbd8b26bf19abee436a at both tips, and tests/test_checkpoint_telemetry_concurrency.py is blob ca276224e14eb2fb967b80bf1b8df66c21eb5915 at both tips. This is ancestry drift, not a known content deficit.

Do not reuse the current CI/Release Acceptance evidence after predecessor ancestry reconciliation. Reconcile through one reviewed writer path in dependency order, then regenerate exact-head/exact-base quality, security, review, and release evidence. No temporary workflow, duplicate repair path, force update, merge, or protection bypass was created in this audit.

seonghobae commented Aug 7, 2026 •

Copy link
Copy Markdown
Contributor Author

Current head/base audit after dependency-order reconciliation:

  • source head: ba2c102476f834c2c25750de8ede146e391d4c74
  • exact stacked base: d23fc6eade6959fa19e22b39337c14dc65b21ab5
  • ancestry: 50 ahead / 0 behind
  • tree identity check: prior exact feature tree aac408d0aabef4acc6ab29123dfd5b8d8278808d → current head is ahead-only with files=[]; the temporary CHANGELOG normalization used solely to admit the prerequisite ancestry was restored before this head
  • CI 31166530774: completed / success for this pull-request run, but this branch predates the permanent exact-source checkout assertion introduced later in the stack; its job steps do not prove git rev-parse HEAD equals this source SHA. Treat it as supporting PR-event evidence only, not exact-source merge evidence.
  • Release Acceptance 31166530467: completed / success and explicitly checked out the exact pull-request head before materializing two clean exact-head source trees
  • CodeRabbit commit status: success
  • all three prior actionable CodeRabbit threads remain resolved; no qualifying independent non-author APPROVED review exists

Older 2820..., aac408..., predecessor-base, and synthetic-merge runs are stale/supporting evidence only. The successful CI run above is not promoted to exact-source evidence without an in-job source-SHA assertion; fresh exact-source CI remains required after integration. Branch protection, organization rulesets, and security/required-check surfaces unavailable through the connector remain unproven, so this stacked draft is not merge-authorized.

Copy link
Copy Markdown
Contributor Author

Superseded by #79. Replacement head e99c99b081cd5d85f67faf1a0f46944110efbef3 is exactly one commit ahead/zero behind replacement observability predecessor #78 and reproduces exactly the same 19 audit feature files. All eight files modified by this slice that overlap the predecessor were verified byte-identical between old base d23fc6eade6959fa19e22b39337c14dc65b21ab5 and new predecessor 64eea7edb28e391634a5d13c83495d20c6388c81. Fresh replacement CI 31285817835 and Release Acceptance 31285817861 completed successfully. This old branch remains preserved as development/RED-review history; its checks and reviews do not transfer.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant