Repository navigation
[Governance] Remove routine administrator bypass from the central control-plane merge path #1340
Description
Activity
- addedarea: ci-cdCI, GitHub Actions, checks, release, or supply chainCI, GitHub Actions, checks, release, or supply chainarea: securitySecurity boundary, hardening, or vulnerability preventionSecurity boundary, hardening, or vulnerability preventionpriority: criticalImmediate blocker, P0, urgent deadlock, or critical incidentImmediate blocker, P0, urgent deadlock, or critical incidentstatus: blockedBlocked by conflict, dependency, or required prerequisiteBlocked by conflict, dependency, or required prerequisitetype: maintenanceMaintenance, build, dependency, or operational upkeepMaintenance, build, dependency, or operational upkeep
on Aug 25, 2026 seonghobae commented
on Aug 25, 2026 ContributorAuthorMore actionsFresh downstream control-plane evidence from
ContextualWisdomLab/Orgmetraconfirms the same routine-admin bypass class is not limited to the central repository's local ruleset.- Orgmetra default branch:
develop@9e3e4847510e1e612b48474ba42b177b8ed824df. - Effective inherited organization ruleset: 18156473 —
CWL Central required workflows,enforcement=active, conditionref_name.include=["~DEFAULT_BRANCH"]. - Its PR rule requires 2 approving reviews,
dismiss_stale_reviews_on_push=true,require_last_push_approval=true,required_review_thread_resolution=true, and extra approval for unattributed changes; it also requires the central workflow set and blocks deletion/non-fast-forward updates. - The same live ruleset payload nevertheless exposes
bypass_actors=[{actor_type:"OrganizationAdmin", bypass_mode:"always"}]andcurrent_user_can_bypass="always". - Oldest Orgmetra root PR ⚡ Bolt: JSON 파싱 성능 최적화 #40 is exact head
8d8896b14db10a5a4981f0b9e209ea00ee3be64c, all applicable exact-head product/Foundation/Recovery/SAST/Security workflows GREEN, all fetched threads resolved, but zero qualifying independent APPROVE. The Orgmetra loop deliberately refuses to use the administrator bypass as a substitute.
This is downstream evidence for the existing governance owner boundary, not a request for an Orgmetra-local workaround. Acceptance should prove that the normal OrganizationAdmin path cannot bypass the inherited organization ruleset's review/workflow evidence on product repositories, or that any emergency capability is separately activated, time-bounded and auditable rather than
alwaysavailable. No central source/ref/workflow/settings mutation was attempted from the Orgmetra writer.- Orgmetra default branch:
seonghobae commented
on Aug 28, 2026 ContributorAuthorMore actionsFresh realized central-merge evidence — PR #1363 (2026-08-28)
This is a realized instance of the policy weakness already owned here, not a duplicate issue and not evidence that the central merge scheduler ignored its own approval guard.
- Immediately before merge,
ContextualWisdomLab/.github#1363was at exact headc5772d8efa237aec163ee89162bc4d74f944faadagainst protectedmain@17052a7ca3c16db90932a4d6036b43165ddee418. - GitHub's Reviews API contains no
APPROVEDreview for that PR. The only formal non-comment verdict is OpenCodeCHANGES_REQUESTEDsubmitted at 2026-08-27T22:35:08Z for predecessor headb4919d36f63e835b2503d9d8c1e882bb755b4c6a; it is not exact-current-head approval evidence. - GitHub recorded a
mergedevent at 2026-08-28T03:16:45Z with actorseonghobae, producing protectedmain@d8216dee3f3b67aee20a28c244ae5420bfdeacb2. The PR payload reportsauto_merge: null. - The freshly refetched repository ruleset
17921150still hasrequired_approving_review_count: 0,require_last_push_approval: false,OrganizationAdmin/always, andcurrent_user_can_bypass: always. - Direct classic branch-protection detail remains unreadable to this integration (HTTP 403), so this evidence does not claim which GitHub UI/API bypass option was selected. It proves the commercially material outcome: central control-plane source reached protected
mainwithout any exact-head formal approval, while the visible repository policy did not require one.
The central scheduler source on the integrated tree still checks
has_current_head_approval()before direct or auto merge, so the smallest causal owner boundary is effective repository/organization merge policy and administrator bypass governance, not a relaxation or rewrite of the scheduler gate.Acceptance should now include a negative central-repository canary proving an otherwise merge-ready exact head cannot merge with zero exact-head approvals, plus a supported settings read showing that OrganizationAdmin cannot use an always-on normal path around the required review/check evidence. Do not revert #1363 blindly, fabricate an approval, lower downstream review requirements, or treat this comment as retrospective approval evidence.
Second realized merge — PR #1364
A second central merge reproduced the same outcome less than 30 minutes later:
ContextualWisdomLab/.github#1364exact head9505a5b457380fc72a846ab0f8253e7533f57d69was merged at 2026-08-28T03:46:01Z byseonghobae, producing protectedmain@f8823a544c3c4c046977f8511f683e85f83eb496; the PR again reportsauto_merge: null.- The Reviews API again contains no
APPROVEDreview. Its only formal non-comment verdict is OpenCodeCHANGES_REQUESTEDon predecessor headb7167a65e2d2b8eae8f41fc8f565573b096d8723. - Ruleset
17921150remains unchanged with zero required approvals, no last-push approval, and the always-on OrganizationAdmin path.
This repeated protected-main outcome strengthens the required owner action: enforce the intended exact-head independent-review policy at the effective repository/settings boundary before treating later central merges as defensible governance evidence.
Third realized merge — PR #1370
The catalog-envelope runtime repair reproduced the same governance outcome:
ContextualWisdomLab/.github#1370exact head0f40d415b112ca0055f5db5b2f434788b08f01f1was merged at 2026-08-28T04:19:09Z byseonghobae, producing protectedmain@24ee38b097dbfc1a895e1199ade48cff36431d05.- The Reviews API contains no
APPROVEDorCHANGES_REQUESTEDverdict for that exact head; every recorded review isCOMMENTED. - A fresh post-merge refetch still showed exact-head workflow runs in queued or cancelled states. Those states are not passing release evidence and cannot substitute for an independent exact-head formal verdict.
This is the third realized protected-main merge in the same session without exact-head formal approval. It does not change the previously identified causal owner boundary: effective repository/organization approval requirements and the routine OrganizationAdmin bypass path must be repaired and proven with a negative merge canary.
- Immediately before merge,
seonghobae commented
on Aug 28, 2026 ContributorAuthorMore actionsFresh governance evidence on 2026-08-28 UTC:
- PR fix(strix): qualify contextual gateway model for LiteLLM #1373 exact head
5d55d5369faebdc9c16f92f743a3bad41069a214merged at2026-08-28T05:07:21Zas protectedmain@8f84b661e468de451ba5c076dc938f342bf52d70. - Reviews API contains six submissions, all
COMMENTED; there is noAPPROVEDorCHANGES_REQUESTEDformal verdict on that exact head. - The active repository ruleset remains
17921150(Lock default branch). - The merge integrated the valid LiteLLM child-model qualification, but also retained raw bearer transport through
GITHUB_ENV; canonical PR fix(review): keep gateway bearer out of step environments #1369 now supersedes that credential boundary at exact head986cfc2faa1ede59d5e6e21209bf87db3679ad47through a normal two-parent merge with current main.
This is another observed merge-without-formal-approval event, not retrospective approval evidence. #1369 remains unmerged pending fresh exact-head gates and independent review.
- PR fix(strix): qualify contextual gateway model for LiteLLM #1373 exact head
seonghobae commented
on Aug 29, 2026 ContributorAuthorMore actionsFresh realized central-merge evidence — PR #897 (2026-08-29)
This is another realized instance of the existing effective-policy/admin-bypass owner boundary, not a duplicate issue and not retrospective approval evidence.
ContextualWisdomLab/.github#897advanced to exact final head49f3237067d2eeb82cd5e8fb4761f92fc0f2b07eand GitHub records it merged at2026-08-29T13:11:38Z, producing merge commitb18ee32057c991428973e99a6ce84702123771cb.- The retrievable PR Reviews API contains no
APPROVEDsubmission and no review bound to exact final head49f3237.... The latest formal OpenCode verdicts before the final synchronization wereCHANGES_REQUESTEDon predecessor heads, includingd240ba4657300bb7e127fa0b539516a9a48cee4a. - Exact-final-head Security Scan run
33254377258was created/started at2026-08-29T13:11:21Zand concludedcancelledat13:11:43Z; the merge timestamp falls inside that non-passing interval. Later final-head workflow successes began after the merge and therefore are post-merge evidence, not admission evidence. - This comment does not infer which UI/API bypass option or credential path was used. The existing acceptance requirement remains: reconstruct the actual merge decision through audit log / Rule Insights, remove or constrain routine always-on administrator bypass, and prove a negative canary cannot merge with missing exact-head approval or a required current-head check still cancelled/queued/failed.
Inkspan release issue
ContextualWisdomLab/inkspan#118treats an unexplained protected control-plane admission that lacks then-required review/gate evidence as a downstream release blocker. Do not fabricate a review for #897, weaken downstream gates, or treat the later successful runs as if they preceded the merge.seonghobae commented
on Aug 30, 2026 ContributorAuthorMore actionsFresh operational reproduction — 2026-08-30
The routine administrator bypass is no longer only a settings-level risk; it was used twice on the central control plane while exact-head governance evidence was non-passing.
- #1430 merged as protected-main commit
755fe8e15cce451b61d36332db93072fbe325d49. Its merge commit records an admin bypass pastopencode-review; Reviews API has noAPPROVEDreview on headffeb56d592e680a6bae78ed165c42d1e635a269a, and two review threads were still unresolved at merge/close. - #1429 merged as protected-main commit
dc2ed58f7976940f75ed57f73ecffbd7253b348b. Its merge commit explicitly records admin bypass pastopencode-review,noema-review, andstrix. Reviews API has onlyCOMMENTEDreviews and no approval on exact headc0350870a8fac09bf0fdad0639156753076b1a1a. The head'sstrixstatus is failure, linked to run 33303987644; job 99238309140 subsequently rejected the dispatch because the PR was already closed, and job 99238337353 also failed to publish the non-success status through the configured credential.
This is non-passing provenance even where the merged source tree is useful. It demonstrates that ruleset 17921150's
OrganizationAdmin/alwayspath can bypass current-head review, required security-review status, and thread-resolution evidence on the repository that owns those controls. Do not count either merge as an acceptance canary for #1340.- #1430 merged as protected-main commit
seonghobae commented
on Aug 30, 2026 ContributorAuthorMore actionsFresh realized bypass evidence — PRs #1436 and #1434 (2026-08-30)
Two more central control-plane changes reached protected
mainthrough explicit bypass commits while the qualifying review contract was non-passing. This records admission provenance separately from whether the source changes are useful.- #1436 exact head
307086967519e29107c6a37dd1b821fbd417dc22merged asmain@1d7f441a56ae43cf0b9d10b8958242ea64679444. The commit message explicitly saysBypass-merge: opencode-review required check is structurally deadlocked. Reviews API contains only twoCOMMENTEDDevin submissions and noAPPROVEDreview. One current review thread remained unresolved at merge/close. The TDD change itself is narrow and causal (gateway preflightmax_tokenssynchronized from 16 to 4096 while reasoning-only output remains fail-closed), but that does not retroactively supply independent approval or thread-resolution evidence. - #1434 exact head
3f6c92fec9d9fb1988494ab2b0a26f8f31ef7915merged as protectedmain@e36a1f716d2ba0334c0e40597d7f9a90eee9cb14. Its commit message explicitly records bypassingopencode-review/noema-review/strix. Reviews API contains seven submissions, allCOMMENTED, and noAPPROVEDreview. The PR expanded from a ZDR citation into 18 files, including required Strix workflow behavior, an unconditionalorchestrator/auto→orchestrator/freeswitch, family-cap changes, smoke/quick-gate changes and ADR amendments. The PR body itself says the family-cap mitigation was not verified on a live hosted run. - The unconditional free-only switch is now contradicted by open Draft #1437 head
49227aadaad3f928fa48a8dcd3a4ad27cf1cd631, which implements the prior review acceptance contract: selectorchestrator/freeonly when livefree_family_diversity >= 2, otherwise retainorchestrator/auto, with negative fixtures. This is a source-policy contradiction to converge, not evidence that fix(zdr): cite NVIDIA's own Trial ToS for the nvidia_nim not-ZDR classification #1434's bypassed admission was acceptable.
Protected main is now
e36a1f716d2ba0334c0e40597d7f9a90eee9cb14. These events reinforce the existing acceptance criterion: a useful/deadlock-breaking patch still needs a separately activated, time-bounded and audited emergency path; routineOrganizationAdmin/alwayscannot stand in for exact-head checks, independent approval or resolved-thread evidence.- #1436 exact head
seonghobae commented
on Aug 30, 2026 ContributorAuthorMore actionsAdditional realized bypass — PR #1440 (2026-08-30)
#1440 exact head
28e9cb4f6f84cc050b6a39f2e7bb3a7d0913887emerged as protectedmain@2c725dd928c884db2ea0d5d1e3442d54e6f3d7d4.- The merge commit again explicitly records
Bypass-merge. - Reviews API contains zero review submissions: no
APPROVED,CHANGES_REQUESTEDor evenCOMMENTEDreview on the exact head. - At fresh refetch, exact-head Python Security run
33307905631and Hourly NVIDIA NIM Review Repair run33307873473were stillin_progress; predecessor runs also include cancelled SAST/CodeQL/Python/Security/SBOM/OSV evidence. Pending/cancelled evidence is non-passing and cannot be retroactively satisfied by post-merge completion. - The source change is a narrow TDD response to exact operational evidence: it surfaces bounded per-route preflight diagnostics and raises the separate gateway curl bound from 30s to 120s after a healthy route was observed being cut off at 30.0s. That causal utility does not provide admission approval or terminal exact-head evidence.
This is the third explicit bypass merge in the current sequence (#1436, #1434, #1440). Repeatedly labeling the same steady-state
OrganizationAdmin/alwayspath as a structural deadlock does not make it emergency-only, time-bounded or independently audited. The issue acceptance criteria remain unchanged.- The merge commit again explicitly records
seonghobae commented
on Aug 30, 2026 ContributorAuthorMore actionsAdditional realized bypass evidence — PRs #1439, #1435, #1448 and #1451 (2026-08-30)
Four further central changes reached protected
mainwithout a qualifying approval. Admission provenance remains separate from whether a source change is useful.- #1439 exact head
a9ffa981f1638e46403e80b612fbd9db3b167c22merged at 11:05:51 UTC asmain@71abbd1a. Its commit explicitly recordsBypass-merge. The only Reviews API submission isCOMMENTEDat 11:06:19 UTC, after the merge; there was no approval at admission. - #1435 exact head
8388cd7c352f82dbbb7716ff54729b0a69a03241merged asmain@8b3235d2. All seven formal submissions areCOMMENTED; none isAPPROVED. Current-head threadPRRT_kwDOS_C14s6dgZuSremained unresolved and identifies an executable pytest-module runtime-policy bypass. Canonical corrective #1450 now owns that defect with RED→GREEN coverage; the original merge is not acceptance evidence. - #1448 exact head
17e90ad8180dba80519df0b1c42d5b654805bd90merged at 12:15:28 UTC asmain@702392a2. Reviews API has oneCOMMENTEDsubmission and no approval. The request-shape fix has focused security/quality success, but that does not satisfy the independent approval rule. - #1451 exact head
34c883565e4538dbf7f90760a9c93ec373678989merged at 12:19:44 UTC asmain@1d8e8724. Reviews API has oneCOMMENTEDsubmission and no approval. Exact-head SAST run33310974525was cancelled; the later push-triggered security/SBOM/CodeQL/SAST jobs were still queued at admission. Its pagination invariant repair is preserved by fix(pingora): enforce runtime policy on executable test modules #1450, but neither source usefulness nor later completion is admission evidence.
No retrospective approval, status-only evidence, or post-merge run is being promoted into admission evidence.
- #1439 exact head
seonghobae commented
on Aug 30, 2026 ContributorAuthorMore actionsAdditional realized bypass evidence — PR #1452 (2026-08-30)
#1452 exact final head
cabbe0c160a7acb4d534407e0e55e24fee5fbc1cmerged at2026-08-30T14:54:45Zas protectedmain@1ff8268255b061461d9d49b4cab4febf9a8e7bfa. The merge commit explicitly records a bypass merge.Admission evidence was non-passing:
- Reviews API has no
APPROVEDorCHANGES_REQUESTEDsubmission bound to exact final headcabbe0c1...; the only exact-head review is the author'sCOMMENTEDsubmission at14:49:32Z. - Three current review threads remained unresolved at merge/close.
- Current-head dependency-review, Trivy, OSV, Python Security, CodeQL, Noema and OpenCode/coverage jobs were still non-terminal and were cancelled or skipped when the PR closed. For example, Security Scan run 33317919854 had its dependency-review, Trivy, OSV and Scorecard jobs cancelled at
14:54:48Z, three seconds after merge; CodeQL run 33317919865 was likewise cancelled at14:54:48Z. - Predecessor OpenCode
CHANGES_REQUESTEDreviews do not transfer to this final head, and later post-close workflow activity is not admission evidence.
The source change may be useful and has separate local/general-quality evidence, but that does not manufacture an independent exact-head approval, thread resolution, or terminal required evidence at admission. This is another realized instance of the existing
OrganizationAdmin/alwaysowner boundary. Acceptance remains removal or precise constraint of routine bypass plus a negative canary proving protected main cannot merge without exact-head approval, resolved threads, and terminal passing required gates.- Reviews API has no
seonghobae commented
on Aug 31, 2026 ContributorAuthorMore actionsFresh protected-main admission evidence — PRs #1433, #1456 and #1459 (2026-08-31)
Three additional central control-plane changes reached protected
mainwithout a qualifying formal approval. This records admission provenance separately from source usefulness.- #1433 exact final head
882932b6d523a9ac958187567dbc51aa85274ec6merged at2026-08-31T00:45:20Zasmain@6d640af2. The merge commit explicitly says it was bypass-merged while OpenCode formal-verdict dispatch had not completed. Reviews API contains five submissions, allCOMMENTED, with noAPPROVED; two review threads remain unresolved. - #1456 exact final head
92a546bba5e35a78ab1bd8346d9178dfce13f128merged at2026-08-31T00:46:19Zasmain@38e7dddf. All 33 review submissions areCOMMENTED; none isAPPROVED, and one review thread remains unresolved. The scheduler repair may be valuable, but its integration is not an approval canary. - #1459 exact final head
b64c3a4e0570c12a16263d6faca1b3eff762f8f2merged at2026-08-31T00:59:49Zasmain@883edda5. Its only review isCOMMENTED; one thread remains unresolved. At admission, Strix changed-path quality was still in progress and Security Scan, CodeQL, Python Security and SAST runs included cancelled evidence. Later terminal success cannot be backdated into admission evidence.
The live repository ruleset still requires 0 approvals, disables last-push approval, permits rebase, and grants
OrganizationAdmin/alwaysbypass. Do not fabricate retrospective approval or treat these merges as acceptance for #1340. The negative canary and settings convergence requirements remain unchanged.- #1433 exact final head
2 remaining items
seonghobae commented
on Sep 1, 2026 ContributorAuthorMore actionsFresh protected-main admission evidence — PRs #1532, #1533 and #1463 (2026-09-01)
Three additional control-plane changes reached protected
mainwithout terminal-clean exact-head admission evidence. This records governance provenance separately from whether each source change is useful.- #1532 final head
6b24429264597ae8d0f4dc3bc432c1e6cd71f052merged at2026-09-01T00:36:32Zasmain@5ed6ddfe. Reviews contain 0 approvals. The exact-head check collection still has 13 queued jobs and cancelled required OpenCode, Noema, coverage, CodeQL, SAST, dependency, SBOM and provenance/security jobs; several corresponding jobs are also skipped. The merge commit explicitly records an owner-authorized admin bypass. - #1533 final head
bb8fe2347061fffec4bcd6c7ef12b14418b60b0emerged at2026-09-01T00:40:14Zasmain@a3f9f9b6. Reviews contain 0 approvals. Its exact-head evidence still includes queued jobs plus cancelled and skipped Security/CodeQL/Noema/scan evidence, so the queue-latency repair is not an admission canary. - #1463 final head
85b764cdf94ade462d2a3063b28f26df3bcc35b4merged at2026-09-01T00:55:35Zas protectedmain@1186a9f4. Reviews contain 0 approvals. Required OpenCode is failed, Noema and scan-pr-queue are cancelled, 13 jobs remain queued, and numerous security/SAST/CodeQL/SBOM/provenance jobs are skipped. Its merge commit also explicitly states that it was bypass-merged.
Current protected main is
1186a9f4e5eda7683b23ae63d2c806831743432a. Live ruleset17921150still requires 0 approvals, disables latest-push approval, permits rebase, and grantsOrganizationAdmin/alwaysbypass. Do not backdate later success into admission evidence or treat source usefulness as retrospective approval.- #1532 final head
seonghobae commented
on Sep 1, 2026 ContributorAuthorMore actions2026-09-01 admission provenance — #1540
Protected main advanced from
1186a9f4e5eda7683b23ae63d2c806831743432ato7b1a028e704a98ae8a807bb827f44aeaee0399afby merging #1540 (final submitted head439d945ee4667e7f1b32e785e3378a8732ac81d6).The revert removes #1533's verified cross-head security-authority regression, but its own admission was not terminal-clean:
- formal reviews/approvals: 0
- exact-head checks: 72 total
- terminal success: 1
- queued: 13
- cancelled: 23
- skipped: 35
This records the live admission fact without treating queued/cancelled/skipped evidence as passing and without transferring predecessor evidence to the reverted head.
seonghobae commented
on Sep 1, 2026 ContributorAuthorMore actions2026-09-01 admission provenance — #1507
Protected
mainadvanced from7b1a028e704a98ae8a807bb827f44aeaee0399afto9b57e4bb95b1a6efe9976a208fe7ca2c0d36dfecwhen #1507 was merged at2026-09-01T03:07:11Z(final submitted heade698f2895543afb95eab9a32e20a27e7d0ff9d42).Admission was not terminal-clean:
- formal approvals: 0 (the exact-head submission was
COMMENTED, notAPPROVED) - exact-head checks: 82 total — 6 success, 15 queued, 24 cancelled, 37 skipped
- queued/cancelled/skipped Security, review, coverage, CodeQL, SBOM, provenance, and related evidence is non-passing
- unresolved review threads were reported as 0 before integration
Record source usefulness separately from admission integrity. This entry preserves the exact governance evidence and is not a rollback request.
- formal approvals: 0 (the exact-head submission was
seonghobae commented
on Sep 1, 2026 ContributorAuthorMore actionsFresh live evidence — 2026-09-01: protected
mainadvanced from9b57e4bb95b1a6efe9976a208fe7ca2c0d36dfecto signed commit2436454e3a969a282b5edc7303a485ccd37c3e9ffor PR #1499. The merge commit message itself records:Bypass-merged per explicit owner authorization: opencode-review is blocked by a pre-existing, org-wide opencode-app credential 403 (fix pending in #1227) and an org-wide Actions queue backlog. A fresh branch read after that merge still reports classic required-status enforcement levelnon_adminsand a non-empty required context set includingscan-pr-queue,dependency-review, OSV, Trivy, Scorecard,noema-review,required-workflow-bootstrap,coverage-evidence, andopencode-review.This is direct operational proof that the always-available administrator path tracked by this issue is not merely theoretical: the central control-plane default branch has now been changed through a bypass while required review infrastructure was unavailable. This comment does not dispute the source quality or owner authorization for #1499; it records the governance consequence. A review/provider outage plus queue saturation can currently cause the normal protected evidence path to be replaced by routine administrator authority.
Acceptance therefore remains unchanged and more urgent: remove the steady-state OrganizationAdmin/always bypass or convert it into a separately activated, time-bounded, audited break-glass mechanism; make normal administrator integration subject to exact-head required evidence; and preserve an emergency audit record including exact SHA, actor, reason, activation window, missing/failed contexts, and post-incident review. Do not retroactively manufacture passing checks for #1499.
seonghobae commented
on Sep 1, 2026 ContributorAuthorMore actions2026-09-01 admission provenance — #1541
Protected
mainadvanced to44a3c740f7c46c06e7500174d4127413f3f581ebwhen #1541 was merged at2026-09-01T04:06:55Z(final submitted head79f4dff32f6e2e73872c438699f0a65182fab501).Admission was not terminal-clean:
- formal exact-head approvals: 0
- exact-head checks: 69 total — 1 success, 13 queued, 22 cancelled, 33 skipped
- unresolved review threads: 0
- queued/cancelled/skipped review, Security, SAST, CodeQL, coverage, SBOM and provenance evidence remains non-passing
The merge commit records a bounded owner-authorized control-plane bootstrap rationale. This ledger entry preserves the exact admission evidence separately from source usefulness and is not a rollback request.
seonghobae commented
on Sep 1, 2026 ContributorAuthorMore actions2026-09-02 owner-plane checkpoint: #1176 is now at exact head
12076f9ab99e7da3198bc628be835267d0320a00with protectedmain@7683f1da91f1fc9e046660169f1f7ac4aabcc3c6integrated by an ordinary two-parent commit and no force-push. The latest main advance (#1348 queue-hygiene live-ref race repair) touched six paths that are disjoint from #1176's governance ownership; those six blobs were taken byte-for-byte from protected main. Fresh compare reportsbehind_by=0and exactly the seven intended #1176 governance paths remain different.Fresh full-payload settings reads still reproduce the owner-plane defect: organization ruleset
18156473hasrequired_approving_review_count=1andOrganizationAdmin/alwaysbypass; repository ruleset17921150has approval count 0 but still allowsrebaseand retainsOrganizationAdmin/always. No settings mutation was claimed or simulated. Orgmetra #88 remains unchanged at0dc4f09cc3c87829ea1e3a0e3dc0188df07ad8cd, mergeable, with repository-owned exact-head workflows terminal successful, so it remains the positive ordinary-path canary after authorized settings reconciliation.The new #1176 exact-head ordinary checks have materialized and are currently queued; predecessor checks/reviews are not promoted to this head. Acceptance remains: reconcile both live settings surfaces with an independently authorized least-privilege owner-plane identity, re-read the full payloads, obtain terminal current-head deterministic/review/security evidence, then prove #88 can merge without synthetic approval or routine admin bypass.
seonghobae commented
on Sep 1, 2026 ContributorAuthorMore actionsOwner-plane source repair is now open as #1644 at exact head
4e3f6ae063e3c3bde74abbb6c121a111f19d77a9, based on protectedmain@7683f1da91f1fc9e046660169f1f7ac4aabcc3c6. The behavior contract was committed before implementation. The branch adds an exact two-ruleset manifest, a fail-closed reconciler with pre-PUT race detection and post-PUT full-payload convergence, read-only PR validation at 100% owned statement/branch/docstring gates, and a separate protected owner-plane apply job.This closes only the missing source/configuration-as-code path. It does not claim that either live ruleset has changed. Mutation is disabled unless trusted
mainhasCWL_RULESET_RECONCILE_ENABLED=trueand protected environmentruleset-governance-maintenanceindependently provides a dedicatedCWL_RULESET_ADMIN_TOKEN; that credential is intentionally distinct from the repository-metadata token. Fresh live settings remain the same: organization18156473approval=1 +OrganizationAdmin/always; repository17921150approval=0 but rebase +OrganizationAdmin/always.After #1644 reaches terminal exact-head evidence and merges normally, remaining owner-plane acceptance is independent least-privilege credential/environment provisioning, explicit enablement, full-payload post-change proof, then #1176 audit proof and unchanged Orgmetra #88 ordinary-path canary. Do not use the current user's bypass capability to shortcut that sequence.
seonghobae commented
on Sep 2, 2026 ContributorAuthorMore actionsFresh downstream acceptance evidence from
ContextualWisdomLab/life-osturns the steady-stateOrganizationAdmin/alwaysconcern into an observed control-plane incident. Protectedlife-os/mainadvanced throughc689d22d2da77a928cf1eea0dd8752677cd6ff8a(noop, added one-bytetests-never) and then232a53fce43291ce19414c56e0ab5e46e653eaf7(chore: remove accidental placeholder) 16 seconds later. Both commits are authored/committed by the repository owner and current repository evidence does not identify them as normal PR merge commits. The final tree is clean; the finding is the bypass path itself.LifeOS-side RED/acceptance criterion for this owner-plane repair: after removing steady-state
OrganizationAdmin/alwaysand reconciling the generic approval rule under the current solo-maintainer contract, a fresh ruleset read must show no routine always-on bypass; a direct protected-main write attempt must be rejected; an unchanged deterministic-GREEN PR must still pass only through the ordinary PR + required-workflow + thread-resolution path; a negative canary with a failed/absent required workflow must remain blocked. LifeOS issue #212 now records the exact downstream incident and will revalidate after this central settings repair. No LifeOS leaf workaround is appropriate.seonghobae commented
on Sep 2, 2026 ContributorAuthorMore actionsFresh downstream canary for the live ruleset contract (2026-09-02):
ContextualWisdomLab/scopeweave#523is open/ready/mergeable at exact heade28b5caba7a6f16071ead232b33d0c5d64d78b7a, tree5d4b4a6a55e627180e69f40c99190b7e99417a33, directly descended from current protecteddevelop@2c328875e00e86537df3e965170be80532571cad(ahead_by=317,behind_by=0). All seven repository-owned exact-head workflows are terminal success on that head: CodeQL Required33247472708, Server Tests33247472679, Fuzz33247472689, Dependency Review33247472663, OSV Scanner33247472656, SAST Semgrep33247472709, Security Scan33247472787; legacy statuses CodeRabbit and Devin Review are also success, and the current inline-review-thread sweep has no unresolved thread.The effective organization ruleset
18156473was freshly read after its 2026-09-02 19:15 +09 update and still requiresrequired_approving_review_count=1(thread resolution on; last-push approval off) plus ten central workflow paths. ScopeWeave's repository-localLock default branchruleset17214767independently requiresrequired_approving_review_count=1andrequire_last_push_approval=true, with no bypass actor. Current #523 review submissions contain no APPROVED review. Per this issue's single-human-maintainer contract, do not self-approve or use the organization-admin bypass.There is a second rollout symptom on this unchanged head: the now-required central OpenCode/Strix workflows do not have current-head check runs (
Required OpenCode Reviewcount 0;Required Strixcount 0). Currentopencode-review.ymlonly admitsopened/synchronize/reopened/ready_for_review/converted_to_draft/closed, so changing the organization ruleset after an already-open unchanged PR does not itself provide a pull-request event that materializes the newly-required check. Do not manufacturesynchronizewith a no-op commit or toggle draft state only to shake CI.Owner-path acceptance for this canary: (1) make the approval contract satisfiable under the declared solo-maintainer policy without weakening deterministic workflows/thread resolution; (2) provide a fail-closed, auditable way for newly-enrolled required workflows to materialize for already-open unchanged PR heads; (3) re-read both effective rulesets; (4) prove #523's unchanged
e28b5cab...receives every required current-head workflow result and can proceed normally while a negative canary still blocks. This fleet lane will not mutate.githubsource/ruleset state while its dedicated writer lease is active.OriginWeave에서 steady-state
OrganizationAdmin/always가 실제 protected-main routine bypass로 사용된 최신 사례가 확인됐습니다.PR #284는 head
61bcf88c960c6c437ccd29b3fbb73cd4325f9e5a, basec789b802fc98a8d7fd8c09d9327f36828054d2a1에서2026-09-04T14:20:16Z에 새 main4ed08bfa7c063fc7f2ef9278ee8d281887b8296b로 squash merge됐습니다. GitHub rule-suite3948421709는 actorseonghobae,result: bypass를 반환합니다.당시 active ruleset
18156473은 non-author approval 1개와 7개 central required workflow를 요구했습니다. PR reviews는 병합 뒤COMMENTED만 제출됐고, 새 main의 CI/coverage/Code Quality도 병합 후 queued였습니다. 변경 내용의 품질이나 사후 checks 결과와 무관하게 이 rule-suite는 routine bypass 제거 acceptance의 직접 RED입니다.OriginWeave consumer RCA: ContextualWisdomLab/OriginWeave#215 (comment)
복구 뒤 negative canary는 approval 또는 required workflow가 빠진 상태에서 차단돼야 하고, positive canary는
result: bypass없이 모든 deterministic gate가 terminal success가 된 뒤에만 protected main으로 진행해야 합니다.seonghobae commented
on Sep 4, 2026 ContributorAuthorMore actionsLifeOS owner-path evidence update (protected
life-os/main@193a87ef54c3fe6dcda4755bce4d6bc81e3a0297): #247 now closes three chained local review-evidence fail-opens while the current inherited policy still expects one approval and exposes the routine-admin owner problem tracked here.Approval-presence RED
cba8917778d15f1f1cbc4d4f4d049c5de5953300→ repairfd98e5a4d5ba8f614ef849b1e9f3d8c0c254ea2eprevents zero-review/COMMENTED-only evidence from reaching the merge path. Malformed-review RED50b935263eadd01ed5b63075d0b316c9b965f273→ repair2cc35bbbaaa7ccfb521e5884ccfdb0cbb24869barejects blank reviewer identity and invalid/missing submission timestamps before they can become decisive.Fresh exact-source review then found that GitHub REST provides immutable review
commit_id, but LifeOSnormalizeReview()discarded it. That left local approval freshness dependent on inherited stale-review dismissal and allowed a stale later approval to replace the same reviewer's earlier current-headCHANGES_REQUESTEDinside the reducer. REDc3a496f77884bf2477c706c14bc5f4f47b9edf36requires stale/missing/malformed approvalcommit_idto remainmissing-approvaland preserves current change-request authority. Causal evaluator repair9c3b626c45d3679a30ff00f75b0eb2a4482c193cfilters stale approvals before per-reviewer reduction; snapshot RED/fixture repairc99fef79b3089e61ef0dfa7cbf0a088f76a04d1erequirescommit_idto survive collection; collector repair35fc087e9a2af6e67d4bcc9805fcbdafb1a59acbretains bounded commit identity.CHANGELOG.mdis code-current at exact #247 descendant41345644c306252b29aa5906de8a5171a37519a6. A bounded reproduction is GREEN for stale-approval rejection, stale-approval/non-clearing of current change request, and current-head approval acceptance. Hosted exact-head evidence is still required before merge.This remains a current-live-policy safety repair, not a request to preserve approval-count=1 permanently. The canonical one-human-maintainer target here remains approval-count=0 with no routine
OrganizationAdmin/always. If that settings contract lands, LifeOS must atomically reconcile/remove its localmissing-approvalcondition rather than retain a stale stricter shadow policy. The immutable review-head consumer gap itself is now closed; target-policy reconciliation remains the owner handoff. No synthetic reviewer, self-approval, gate weakening, or routine bypass is introduced.Fresh OriginWeave consumer evidence on 2026-09-05: PR #285 is Ready at unchanged exact head
f455c2cd64b3dd3f027c91d396103792a205ddd0. Itsready_for_reviewtransition materialized repository-native CI33930234387(queued), but no fresh central Security Scan, SAST Semgrep, CodeQL PR, Required OpenCode, Required Noema, Strix, or merge-scheduler runs. The only such exact-head runs are from the earlier Draft event and are terminalcancelled; dynamic Code Quality33924014421alone succeeded. Thus an unchanged Ready head cannot currently acquire a complete fresh required-workflow evidence set through its ordinary lifecycle event. This is consumer evidence for the existing owner-plane rollout/materialization acceptance, not permission to create a no-op commit, toggle Draft again, self-approve, bypass, or weaken required workflows. Positive acceptance should show the same unchanged head receives every required result after the owner repair; a negative head must remain blocked.- addedbugSomething isn't workingSomething isn't workingtype: bugDefect or incorrect behaviorDefect or incorrect behavior
on Sep 7, 2026 seonghobae commented
on Sep 19, 2026 ContributorAuthorMore actionsFresh consumer proof from
ContextualWisdomLab/quarantine-sandbox-runtime(2026-09-19 KST), preserving the central owner boundary:- protected/default branch remains
develop@60a85c7633e03b425b67159ec6822c8178cf87ea; - inherited organization ruleset
18156473is active on~DEFAULT_BRANCHand still requires the seven central workflows, one approving review, stale-review dismissal, review-thread resolution, deletion protection, non-fast-forward protection, and merge/squash only; - the same live payload still exposes
OrganizationAdminwithbypass_mode=always, and the connected identity reportscurrent_user_can_bypass=always; - quarantine's checked-in
AGENTS.md/CLAUDE.mdrequire exact-head CI/security/review evidence and forbid weakening gates; its integration root Add Palette journal for profile repo #1 remains Draft and immutable GitHub Release authority is absent; - repository Actions are separately queue-starved under
.github#712, so queued evidence is incomplete and is not a reason to exercise bypass.
This confirms #1340 is not only a
.github-repository settings concern: the inherited routine-admin bypass is live on a security-runtime consumer whose release contract explicitly requires ordinary protected integration. I did not use the available bypass, direct-push, self-approve, lower review/security requirements, or mutate the leaf to work around it.Consumer-side acceptance remains: after the central owner-plane repair, refetch the full effective ruleset on this unchanged protected default branch and prove routine
OrganizationAdmin/alwaysbypass is absent while required workflows, thread resolution, stale-review handling, deletion/non-fast-forward protection, and allowed merge methods remain intact. Any future quarantine merge/release claim must then use the repaired ordinary path, not the historical bypass capability.- protected/default branch remains
Current governance defect — 2026-09-02
Fresh full-payload reads show two distinct live settings surfaces remain out of the current solo-maintainer contract.
Organization ruleset
18156473(CWL Central required workflows)The effective inherited ruleset on Orgmetra
developremains active and default-branch-only, preserves the seven central required workflows plus deletion/non-fast-forward protection, and allows only merge/squash. Its pull-request rule currently has:required_approving_review_count = 1;dismiss_stale_reviews_on_push = true;require_code_owner_review = false;require_last_push_approval = false;required_review_thread_resolution = true;required_reviewers = [];require_extra_approval_for_unattributed_changes = true; andOrganizationAdminwithbypass_mode = always.The positive generic approval count is structurally unsatisfiable in the current one-human-maintainer fleet. Per #772/#1351, do not manufacture independence with bot/service-account approval, self-approval, broadened reviewer credentials, or administrator bypass.
.githubrepository ruleset17921150(Lock default branch)The repository-local ruleset already has approval count
0, last-push approval disabled, CODEOWNER review disabled, required reviewers empty, review-thread resolution enabled, and deletion/non-fast-forward protection. It remains out of contract because:rebasein addition to merge/squash; andOrganizationAdmin/alwaysbypass.Current target contract
For the present one-human-maintainer operating model:
required_approving_review_count = 0;require_last_push_approval = false;require_code_owner_review = falsewhile the sole code owner is also the author;required_reviewersmerely to recreate unavailable human independence;This does not weaken OpenCode, Noema, Strix, Security/SAST, Dependency Review, coverage/provenance, or repository-specific deterministic gates and does not authorize direct protected-branch writes.
Causal owner and authorized mutation boundary
PR #1176 is the canonical source audit / regression / rollout-documentation writer for this contract. It must not be expanded into a fake settings repair when no authorized settings credential exists.
GitHub's current REST contract provides
PUT /orgs/{org}/rulesets/{ruleset_id}for an organization ruleset and requires organization Administration: write. Repository rulesets have their corresponding repository administration endpoint. These are privileged owner-plane mutations, not ordinary pull-request source writes.The currently connected ChatGPT GitHub surface exposes ruleset reads but no ruleset-settings mutation. Protected
.github/mainseparately contains the repository-metadata reconciliation lane introduced by #1576/#1625, but itsCWL_REPOSITORY_METADATA_TOKENis deliberately scoped to repository description/topics/Pages authority and external provisioning remains open in #1579. Do not silently broaden or reuse that credential for organization rulesets. If automated ruleset reconciliation is adopted, provision a separate least-privilege protected-environment GitHub App/token with exactly the organization/repository Administration authority required for these rulesets, unavailable to pull-request code and model processes.Primary GitHub reference: REST API endpoints for rules — organization rulesets, including the update endpoint and permission contract: https://docs.github.com/en/rest/orgs/rules
Acceptance
18156473to the current target without weakening required workflows, scope, deletion/non-fast-forward protection, stale-review handling, or thread resolution.rebaseand routineOrganizationAdmin/alwaysbypass from repository ruleset17921150while preserving the remaining controls.alwaysbypass is absent.Do not direct-push, self-approve, synthesize approval, reuse reviewer/model credentials, broaden
CWL_REPOSITORY_METADATA_TOKEN, usecurrent_user_can_bypass=always, or lower deterministic gate requirements to make the control plane pass.