Skip to content

[Governance] Remove routine administrator bypass from the central control-plane merge path #1340

Description

@seonghobae

Current governance defect — 2026-09-02

Fresh full-payload reads show two distinct live settings surfaces remain out of the current solo-maintainer contract.

Organization ruleset 18156473 (CWL Central required workflows)

The effective inherited ruleset on Orgmetra develop remains active and default-branch-only, preserves the seven central required workflows plus deletion/non-fast-forward protection, and allows only merge/squash. Its pull-request rule currently has:

  • required_approving_review_count = 1;
  • dismiss_stale_reviews_on_push = true;
  • require_code_owner_review = false;
  • require_last_push_approval = false;
  • required_review_thread_resolution = true;
  • required_reviewers = [];
  • require_extra_approval_for_unattributed_changes = true; and
  • OrganizationAdmin with bypass_mode = always.

The positive generic approval count is structurally unsatisfiable in the current one-human-maintainer fleet. Per #772/#1351, do not manufacture independence with bot/service-account approval, self-approval, broadened reviewer credentials, or administrator bypass.

.github repository ruleset 17921150 (Lock default branch)

The repository-local ruleset already has approval count 0, last-push approval disabled, CODEOWNER review disabled, required reviewers empty, review-thread resolution enabled, and deletion/non-fast-forward protection. It remains out of contract because:

  • it still permits rebase in addition to merge/squash; and
  • it still exposes OrganizationAdmin/always bypass.

Current target contract

For the present one-human-maintainer operating model:

  • required_approving_review_count = 0;
  • require_last_push_approval = false;
  • require_code_owner_review = false while the sole code owner is also the author;
  • no synthetic required_reviewers merely to recreate unavailable human independence;
  • stale-review dismissal and required review-thread resolution remain enabled;
  • exact central required workflows and default-branch-only scope remain enforced;
  • only merge and squash are accepted;
  • deletion and non-fast-forward protection remain enabled; and
  • no routine bypass actor exists. Any emergency repair path must be separately activated, time-bounded, attributable, and auditable.

This does not weaken OpenCode, Noema, Strix, Security/SAST, Dependency Review, coverage/provenance, or repository-specific deterministic gates and does not authorize direct protected-branch writes.

Causal owner and authorized mutation boundary

PR #1176 is the canonical source audit / regression / rollout-documentation writer for this contract. It must not be expanded into a fake settings repair when no authorized settings credential exists.

GitHub's current REST contract provides PUT /orgs/{org}/rulesets/{ruleset_id} for an organization ruleset and requires organization Administration: write. Repository rulesets have their corresponding repository administration endpoint. These are privileged owner-plane mutations, not ordinary pull-request source writes.

The currently connected ChatGPT GitHub surface exposes ruleset reads but no ruleset-settings mutation. Protected .github/main separately contains the repository-metadata reconciliation lane introduced by #1576/#1625, but its CWL_REPOSITORY_METADATA_TOKEN is deliberately scoped to repository description/topics/Pages authority and external provisioning remains open in #1579. Do not silently broaden or reuse that credential for organization rulesets. If automated ruleset reconciliation is adopted, provision a separate least-privilege protected-environment GitHub App/token with exactly the organization/repository Administration authority required for these rulesets, unavailable to pull-request code and model processes.

Primary GitHub reference: REST API endpoints for rules — organization rulesets, including the update endpoint and permission contract: https://docs.github.com/en/rest/orgs/rules

Acceptance

  1. fix(governance): enforce satisfiable solo-maintainer rulesets #1176's then-current exact head reaches terminal deterministic review/security/quality evidence and its final tree remains limited to intended governance source paths relative to protected main.
  2. An authorized owner-plane mutation changes organization ruleset 18156473 to the current target without weakening required workflows, scope, deletion/non-fast-forward protection, stale-review handling, or thread resolution.
  3. An authorized owner-plane mutation removes rebase and routine OrganizationAdmin/always bypass from repository ruleset 17921150 while preserving the remaining controls.
  4. Fresh full-payload reads prove both rulesets match the target. A settings source file, workflow definition, or successful API status alone is insufficient.
  5. An unchanged deterministic-GREEN sole-author canary such as Orgmetra 🛡️ Sentinel: [CRITICAL] CI 게이트 우회 방지를 위한 Python JSON 정규화 강제 적용 #88 can proceed through the ordinary protected merge path without a nonexistent independent human and without administrator bypass.
  6. A negative canary remains blocked by any genuine failed/absent required workflow or unresolved required review thread.
  7. If emergency bypass capability is retained elsewhere, evidence identifies activation authority, exact SHA, reason, bounded window, and post-event review; steady-state always bypass is absent.

Do not direct-push, self-approve, synthesize approval, reuse reviewer/model credentials, broaden CWL_REPOSITORY_METADATA_TOKEN, use current_user_can_bypass=always, or lower deterministic gate requirements to make the control plane pass.

Activity

  1. added
    area: ci-cdCI, GitHub Actions, checks, release, or supply chain
    area: securitySecurity boundary, hardening, or vulnerability prevention
    priority: criticalImmediate blocker, P0, urgent deadlock, or critical incident
    status: blockedBlocked by conflict, dependency, or required prerequisite
    type: maintenanceMaintenance, build, dependency, or operational upkeep
    on Aug 25, 2026
  2. seonghobae commented on Aug 25, 2026

    @seonghobae
    ContributorAuthor

    Fresh downstream control-plane evidence from ContextualWisdomLab/Orgmetra confirms the same routine-admin bypass class is not limited to the central repository's local ruleset.

    • Orgmetra default branch: develop@9e3e4847510e1e612b48474ba42b177b8ed824df.
    • Effective inherited organization ruleset: 18156473 — CWL Central required workflows, enforcement=active, condition ref_name.include=["~DEFAULT_BRANCH"].
    • Its PR rule requires 2 approving reviews, dismiss_stale_reviews_on_push=true, require_last_push_approval=true, required_review_thread_resolution=true, and extra approval for unattributed changes; it also requires the central workflow set and blocks deletion/non-fast-forward updates.
    • The same live ruleset payload nevertheless exposes bypass_actors=[{actor_type:"OrganizationAdmin", bypass_mode:"always"}] and current_user_can_bypass="always".
    • Oldest Orgmetra root PR ⚡ Bolt: JSON 파싱 성능 최적화 #40 is exact head 8d8896b14db10a5a4981f0b9e209ea00ee3be64c, all applicable exact-head product/Foundation/Recovery/SAST/Security workflows GREEN, all fetched threads resolved, but zero qualifying independent APPROVE. The Orgmetra loop deliberately refuses to use the administrator bypass as a substitute.

    This is downstream evidence for the existing governance owner boundary, not a request for an Orgmetra-local workaround. Acceptance should prove that the normal OrganizationAdmin path cannot bypass the inherited organization ruleset's review/workflow evidence on product repositories, or that any emergency capability is separately activated, time-bounded and auditable rather than always available. No central source/ref/workflow/settings mutation was attempted from the Orgmetra writer.

  3. seonghobae commented on Aug 28, 2026

    @seonghobae
    ContributorAuthor

    Fresh realized central-merge evidence — PR #1363 (2026-08-28)

    This is a realized instance of the policy weakness already owned here, not a duplicate issue and not evidence that the central merge scheduler ignored its own approval guard.

    • Immediately before merge, ContextualWisdomLab/.github#1363 was at exact head c5772d8efa237aec163ee89162bc4d74f944faad against protected main@17052a7ca3c16db90932a4d6036b43165ddee418.
    • GitHub's Reviews API contains no APPROVED review for that PR. The only formal non-comment verdict is OpenCode CHANGES_REQUESTED submitted at 2026-08-27T22:35:08Z for predecessor head b4919d36f63e835b2503d9d8c1e882bb755b4c6a; it is not exact-current-head approval evidence.
    • GitHub recorded a merged event at 2026-08-28T03:16:45Z with actor seonghobae, producing protected main@d8216dee3f3b67aee20a28c244ae5420bfdeacb2. The PR payload reports auto_merge: null.
    • The freshly refetched repository ruleset 17921150 still has required_approving_review_count: 0, require_last_push_approval: false, OrganizationAdmin/always, and current_user_can_bypass: always.
    • Direct classic branch-protection detail remains unreadable to this integration (HTTP 403), so this evidence does not claim which GitHub UI/API bypass option was selected. It proves the commercially material outcome: central control-plane source reached protected main without any exact-head formal approval, while the visible repository policy did not require one.

    The central scheduler source on the integrated tree still checks has_current_head_approval() before direct or auto merge, so the smallest causal owner boundary is effective repository/organization merge policy and administrator bypass governance, not a relaxation or rewrite of the scheduler gate.

    Acceptance should now include a negative central-repository canary proving an otherwise merge-ready exact head cannot merge with zero exact-head approvals, plus a supported settings read showing that OrganizationAdmin cannot use an always-on normal path around the required review/check evidence. Do not revert #1363 blindly, fabricate an approval, lower downstream review requirements, or treat this comment as retrospective approval evidence.

    Second realized merge — PR #1364

    A second central merge reproduced the same outcome less than 30 minutes later:

    • ContextualWisdomLab/.github#1364 exact head 9505a5b457380fc72a846ab0f8253e7533f57d69 was merged at 2026-08-28T03:46:01Z by seonghobae, producing protected main@f8823a544c3c4c046977f8511f683e85f83eb496; the PR again reports auto_merge: null.
    • The Reviews API again contains no APPROVED review. Its only formal non-comment verdict is OpenCode CHANGES_REQUESTED on predecessor head b7167a65e2d2b8eae8f41fc8f565573b096d8723.
    • Ruleset 17921150 remains unchanged with zero required approvals, no last-push approval, and the always-on OrganizationAdmin path.

    This repeated protected-main outcome strengthens the required owner action: enforce the intended exact-head independent-review policy at the effective repository/settings boundary before treating later central merges as defensible governance evidence.

    Third realized merge — PR #1370

    The catalog-envelope runtime repair reproduced the same governance outcome:

    • ContextualWisdomLab/.github#1370 exact head 0f40d415b112ca0055f5db5b2f434788b08f01f1 was merged at 2026-08-28T04:19:09Z by seonghobae, producing protected main@24ee38b097dbfc1a895e1199ade48cff36431d05.
    • The Reviews API contains no APPROVED or CHANGES_REQUESTED verdict for that exact head; every recorded review is COMMENTED.
    • A fresh post-merge refetch still showed exact-head workflow runs in queued or cancelled states. Those states are not passing release evidence and cannot substitute for an independent exact-head formal verdict.

    This is the third realized protected-main merge in the same session without exact-head formal approval. It does not change the previously identified causal owner boundary: effective repository/organization approval requirements and the routine OrganizationAdmin bypass path must be repaired and proven with a negative merge canary.

  4. seonghobae commented on Aug 28, 2026

    @seonghobae
    ContributorAuthor

    Fresh governance evidence on 2026-08-28 UTC:

    • PR fix(strix): qualify contextual gateway model for LiteLLM #1373 exact head 5d55d5369faebdc9c16f92f743a3bad41069a214 merged at 2026-08-28T05:07:21Z as protected main@8f84b661e468de451ba5c076dc938f342bf52d70.
    • Reviews API contains six submissions, all COMMENTED; there is no APPROVED or CHANGES_REQUESTED formal verdict on that exact head.
    • The active repository ruleset remains 17921150 (Lock default branch).
    • The merge integrated the valid LiteLLM child-model qualification, but also retained raw bearer transport through GITHUB_ENV; canonical PR fix(review): keep gateway bearer out of step environments #1369 now supersedes that credential boundary at exact head 986cfc2faa1ede59d5e6e21209bf87db3679ad47 through a normal two-parent merge with current main.

    This is another observed merge-without-formal-approval event, not retrospective approval evidence. #1369 remains unmerged pending fresh exact-head gates and independent review.

  5. seonghobae commented on Aug 29, 2026

    @seonghobae
    ContributorAuthor

    Fresh realized central-merge evidence — PR #897 (2026-08-29)

    This is another realized instance of the existing effective-policy/admin-bypass owner boundary, not a duplicate issue and not retrospective approval evidence.

    • ContextualWisdomLab/.github#897 advanced to exact final head 49f3237067d2eeb82cd5e8fb4761f92fc0f2b07e and GitHub records it merged at 2026-08-29T13:11:38Z, producing merge commit b18ee32057c991428973e99a6ce84702123771cb.
    • The retrievable PR Reviews API contains no APPROVED submission and no review bound to exact final head 49f3237.... The latest formal OpenCode verdicts before the final synchronization were CHANGES_REQUESTED on predecessor heads, including d240ba4657300bb7e127fa0b539516a9a48cee4a.
    • Exact-final-head Security Scan run 33254377258 was created/started at 2026-08-29T13:11:21Z and concluded cancelled at 13:11:43Z; the merge timestamp falls inside that non-passing interval. Later final-head workflow successes began after the merge and therefore are post-merge evidence, not admission evidence.
    • This comment does not infer which UI/API bypass option or credential path was used. The existing acceptance requirement remains: reconstruct the actual merge decision through audit log / Rule Insights, remove or constrain routine always-on administrator bypass, and prove a negative canary cannot merge with missing exact-head approval or a required current-head check still cancelled/queued/failed.

    Inkspan release issue ContextualWisdomLab/inkspan#118 treats an unexplained protected control-plane admission that lacks then-required review/gate evidence as a downstream release blocker. Do not fabricate a review for #897, weaken downstream gates, or treat the later successful runs as if they preceded the merge.

  6. seonghobae commented on Aug 30, 2026

    @seonghobae
    ContributorAuthor

    Fresh operational reproduction — 2026-08-30

    The routine administrator bypass is no longer only a settings-level risk; it was used twice on the central control plane while exact-head governance evidence was non-passing.

    • #1430 merged as protected-main commit 755fe8e15cce451b61d36332db93072fbe325d49. Its merge commit records an admin bypass past opencode-review; Reviews API has no APPROVED review on head ffeb56d592e680a6bae78ed165c42d1e635a269a, and two review threads were still unresolved at merge/close.
    • #1429 merged as protected-main commit dc2ed58f7976940f75ed57f73ecffbd7253b348b. Its merge commit explicitly records admin bypass past opencode-review, noema-review, and strix. Reviews API has only COMMENTED reviews and no approval on exact head c0350870a8fac09bf0fdad0639156753076b1a1a. The head's strix status is failure, linked to run 33303987644; job 99238309140 subsequently rejected the dispatch because the PR was already closed, and job 99238337353 also failed to publish the non-success status through the configured credential.

    This is non-passing provenance even where the merged source tree is useful. It demonstrates that ruleset 17921150's OrganizationAdmin/always path can bypass current-head review, required security-review status, and thread-resolution evidence on the repository that owns those controls. Do not count either merge as an acceptance canary for #1340.

  7. seonghobae commented on Aug 30, 2026

    @seonghobae
    ContributorAuthor

    Fresh realized bypass evidence — PRs #1436 and #1434 (2026-08-30)

    Two more central control-plane changes reached protected main through explicit bypass commits while the qualifying review contract was non-passing. This records admission provenance separately from whether the source changes are useful.

    • #1436 exact head 307086967519e29107c6a37dd1b821fbd417dc22 merged as main@1d7f441a56ae43cf0b9d10b8958242ea64679444. The commit message explicitly says Bypass-merge: opencode-review required check is structurally deadlocked. Reviews API contains only two COMMENTED Devin submissions and no APPROVED review. One current review thread remained unresolved at merge/close. The TDD change itself is narrow and causal (gateway preflight max_tokens synchronized from 16 to 4096 while reasoning-only output remains fail-closed), but that does not retroactively supply independent approval or thread-resolution evidence.
    • #1434 exact head 3f6c92fec9d9fb1988494ab2b0a26f8f31ef7915 merged as protected main@e36a1f716d2ba0334c0e40597d7f9a90eee9cb14. Its commit message explicitly records bypassing opencode-review/noema-review/strix. Reviews API contains seven submissions, all COMMENTED, and no APPROVED review. The PR expanded from a ZDR citation into 18 files, including required Strix workflow behavior, an unconditional orchestrator/auto → orchestrator/free switch, family-cap changes, smoke/quick-gate changes and ADR amendments. The PR body itself says the family-cap mitigation was not verified on a live hosted run.
    • The unconditional free-only switch is now contradicted by open Draft #1437 head 49227aadaad3f928fa48a8dcd3a4ad27cf1cd631, which implements the prior review acceptance contract: select orchestrator/free only when live free_family_diversity >= 2, otherwise retain orchestrator/auto, with negative fixtures. This is a source-policy contradiction to converge, not evidence that fix(zdr): cite NVIDIA's own Trial ToS for the nvidia_nim not-ZDR classification #1434's bypassed admission was acceptable.

    Protected main is now e36a1f716d2ba0334c0e40597d7f9a90eee9cb14. These events reinforce the existing acceptance criterion: a useful/deadlock-breaking patch still needs a separately activated, time-bounded and audited emergency path; routine OrganizationAdmin/always cannot stand in for exact-head checks, independent approval or resolved-thread evidence.

  8. seonghobae commented on Aug 30, 2026

    @seonghobae
    ContributorAuthor

    Additional realized bypass — PR #1440 (2026-08-30)

    #1440 exact head 28e9cb4f6f84cc050b6a39f2e7bb3a7d0913887e merged as protected main@2c725dd928c884db2ea0d5d1e3442d54e6f3d7d4.

    • The merge commit again explicitly records Bypass-merge.
    • Reviews API contains zero review submissions: no APPROVED, CHANGES_REQUESTED or even COMMENTED review on the exact head.
    • At fresh refetch, exact-head Python Security run 33307905631 and Hourly NVIDIA NIM Review Repair run 33307873473 were still in_progress; predecessor runs also include cancelled SAST/CodeQL/Python/Security/SBOM/OSV evidence. Pending/cancelled evidence is non-passing and cannot be retroactively satisfied by post-merge completion.
    • The source change is a narrow TDD response to exact operational evidence: it surfaces bounded per-route preflight diagnostics and raises the separate gateway curl bound from 30s to 120s after a healthy route was observed being cut off at 30.0s. That causal utility does not provide admission approval or terminal exact-head evidence.

    This is the third explicit bypass merge in the current sequence (#1436, #1434, #1440). Repeatedly labeling the same steady-state OrganizationAdmin/always path as a structural deadlock does not make it emergency-only, time-bounded or independently audited. The issue acceptance criteria remain unchanged.

  9. seonghobae commented on Aug 30, 2026

    @seonghobae
    ContributorAuthor

    Additional realized bypass evidence — PRs #1439, #1435, #1448 and #1451 (2026-08-30)

    Four further central changes reached protected main without a qualifying approval. Admission provenance remains separate from whether a source change is useful.

    • #1439 exact head a9ffa981f1638e46403e80b612fbd9db3b167c22 merged at 11:05:51 UTC as main@71abbd1a. Its commit explicitly records Bypass-merge. The only Reviews API submission is COMMENTED at 11:06:19 UTC, after the merge; there was no approval at admission.
    • #1435 exact head 8388cd7c352f82dbbb7716ff54729b0a69a03241 merged as main@8b3235d2. All seven formal submissions are COMMENTED; none is APPROVED. Current-head thread PRRT_kwDOS_C14s6dgZuS remained unresolved and identifies an executable pytest-module runtime-policy bypass. Canonical corrective #1450 now owns that defect with RED→GREEN coverage; the original merge is not acceptance evidence.
    • #1448 exact head 17e90ad8180dba80519df0b1c42d5b654805bd90 merged at 12:15:28 UTC as main@702392a2. Reviews API has one COMMENTED submission and no approval. The request-shape fix has focused security/quality success, but that does not satisfy the independent approval rule.
    • #1451 exact head 34c883565e4538dbf7f90760a9c93ec373678989 merged at 12:19:44 UTC as main@1d8e8724. Reviews API has one COMMENTED submission and no approval. Exact-head SAST run 33310974525 was cancelled; the later push-triggered security/SBOM/CodeQL/SAST jobs were still queued at admission. Its pagination invariant repair is preserved by fix(pingora): enforce runtime policy on executable test modules #1450, but neither source usefulness nor later completion is admission evidence.

    No retrospective approval, status-only evidence, or post-merge run is being promoted into admission evidence.

  10. seonghobae commented on Aug 30, 2026

    @seonghobae
    ContributorAuthor

    Additional realized bypass evidence — PR #1452 (2026-08-30)

    #1452 exact final head cabbe0c160a7acb4d534407e0e55e24fee5fbc1c merged at 2026-08-30T14:54:45Z as protected main@1ff8268255b061461d9d49b4cab4febf9a8e7bfa. The merge commit explicitly records a bypass merge.

    Admission evidence was non-passing:

    • Reviews API has no APPROVED or CHANGES_REQUESTED submission bound to exact final head cabbe0c1...; the only exact-head review is the author's COMMENTED submission at 14:49:32Z.
    • Three current review threads remained unresolved at merge/close.
    • Current-head dependency-review, Trivy, OSV, Python Security, CodeQL, Noema and OpenCode/coverage jobs were still non-terminal and were cancelled or skipped when the PR closed. For example, Security Scan run 33317919854 had its dependency-review, Trivy, OSV and Scorecard jobs cancelled at 14:54:48Z, three seconds after merge; CodeQL run 33317919865 was likewise cancelled at 14:54:48Z.
    • Predecessor OpenCode CHANGES_REQUESTED reviews do not transfer to this final head, and later post-close workflow activity is not admission evidence.

    The source change may be useful and has separate local/general-quality evidence, but that does not manufacture an independent exact-head approval, thread resolution, or terminal required evidence at admission. This is another realized instance of the existing OrganizationAdmin/always owner boundary. Acceptance remains removal or precise constraint of routine bypass plus a negative canary proving protected main cannot merge without exact-head approval, resolved threads, and terminal passing required gates.

  11. seonghobae commented on Aug 31, 2026

    @seonghobae
    ContributorAuthor

    Fresh protected-main admission evidence — PRs #1433, #1456 and #1459 (2026-08-31)

    Three additional central control-plane changes reached protected main without a qualifying formal approval. This records admission provenance separately from source usefulness.

    • #1433 exact final head 882932b6d523a9ac958187567dbc51aa85274ec6 merged at 2026-08-31T00:45:20Z as main@6d640af2. The merge commit explicitly says it was bypass-merged while OpenCode formal-verdict dispatch had not completed. Reviews API contains five submissions, all COMMENTED, with no APPROVED; two review threads remain unresolved.
    • #1456 exact final head 92a546bba5e35a78ab1bd8346d9178dfce13f128 merged at 2026-08-31T00:46:19Z as main@38e7dddf. All 33 review submissions are COMMENTED; none is APPROVED, and one review thread remains unresolved. The scheduler repair may be valuable, but its integration is not an approval canary.
    • #1459 exact final head b64c3a4e0570c12a16263d6faca1b3eff762f8f2 merged at 2026-08-31T00:59:49Z as main@883edda5. Its only review is COMMENTED; one thread remains unresolved. At admission, Strix changed-path quality was still in progress and Security Scan, CodeQL, Python Security and SAST runs included cancelled evidence. Later terminal success cannot be backdated into admission evidence.

    The live repository ruleset still requires 0 approvals, disables last-push approval, permits rebase, and grants OrganizationAdmin/always bypass. Do not fabricate retrospective approval or treat these merges as acceptance for #1340. The negative canary and settings convergence requirements remain unchanged.

  12. 2 remaining items

  13. seonghobae commented on Sep 1, 2026

    @seonghobae
    ContributorAuthor

    Fresh protected-main admission evidence — PRs #1532, #1533 and #1463 (2026-09-01)

    Three additional control-plane changes reached protected main without terminal-clean exact-head admission evidence. This records governance provenance separately from whether each source change is useful.

    • #1532 final head 6b24429264597ae8d0f4dc3bc432c1e6cd71f052 merged at 2026-09-01T00:36:32Z as main@5ed6ddfe. Reviews contain 0 approvals. The exact-head check collection still has 13 queued jobs and cancelled required OpenCode, Noema, coverage, CodeQL, SAST, dependency, SBOM and provenance/security jobs; several corresponding jobs are also skipped. The merge commit explicitly records an owner-authorized admin bypass.
    • #1533 final head bb8fe2347061fffec4bcd6c7ef12b14418b60b0e merged at 2026-09-01T00:40:14Z as main@a3f9f9b6. Reviews contain 0 approvals. Its exact-head evidence still includes queued jobs plus cancelled and skipped Security/CodeQL/Noema/scan evidence, so the queue-latency repair is not an admission canary.
    • #1463 final head 85b764cdf94ade462d2a3063b28f26df3bcc35b4 merged at 2026-09-01T00:55:35Z as protected main@1186a9f4. Reviews contain 0 approvals. Required OpenCode is failed, Noema and scan-pr-queue are cancelled, 13 jobs remain queued, and numerous security/SAST/CodeQL/SBOM/provenance jobs are skipped. Its merge commit also explicitly states that it was bypass-merged.

    Current protected main is 1186a9f4e5eda7683b23ae63d2c806831743432a. Live ruleset 17921150 still requires 0 approvals, disables latest-push approval, permits rebase, and grants OrganizationAdmin/always bypass. Do not backdate later success into admission evidence or treat source usefulness as retrospective approval.

  14. seonghobae commented on Sep 1, 2026

    @seonghobae
    ContributorAuthor

    2026-09-01 admission provenance — #1540

    Protected main advanced from 1186a9f4e5eda7683b23ae63d2c806831743432a to 7b1a028e704a98ae8a807bb827f44aeaee0399af by merging #1540 (final submitted head 439d945ee4667e7f1b32e785e3378a8732ac81d6).

    The revert removes #1533's verified cross-head security-authority regression, but its own admission was not terminal-clean:

    • formal reviews/approvals: 0
    • exact-head checks: 72 total
    • terminal success: 1
    • queued: 13
    • cancelled: 23
    • skipped: 35

    This records the live admission fact without treating queued/cancelled/skipped evidence as passing and without transferring predecessor evidence to the reverted head.

  15. seonghobae commented on Sep 1, 2026

    @seonghobae
    ContributorAuthor

    2026-09-01 admission provenance — #1507

    Protected main advanced from 7b1a028e704a98ae8a807bb827f44aeaee0399af to 9b57e4bb95b1a6efe9976a208fe7ca2c0d36dfec when #1507 was merged at 2026-09-01T03:07:11Z (final submitted head e698f2895543afb95eab9a32e20a27e7d0ff9d42).

    Admission was not terminal-clean:

    • formal approvals: 0 (the exact-head submission was COMMENTED, not APPROVED)
    • exact-head checks: 82 total — 6 success, 15 queued, 24 cancelled, 37 skipped
    • queued/cancelled/skipped Security, review, coverage, CodeQL, SBOM, provenance, and related evidence is non-passing
    • unresolved review threads were reported as 0 before integration

    Record source usefulness separately from admission integrity. This entry preserves the exact governance evidence and is not a rollback request.

  16. seonghobae commented on Sep 1, 2026

    @seonghobae
    ContributorAuthor

    Fresh live evidence — 2026-09-01: protected main advanced from 9b57e4bb95b1a6efe9976a208fe7ca2c0d36dfec to signed commit 2436454e3a969a282b5edc7303a485ccd37c3e9f for PR #1499. The merge commit message itself records: Bypass-merged per explicit owner authorization: opencode-review is blocked by a pre-existing, org-wide opencode-app credential 403 (fix pending in #1227) and an org-wide Actions queue backlog. A fresh branch read after that merge still reports classic required-status enforcement level non_admins and a non-empty required context set including scan-pr-queue, dependency-review, OSV, Trivy, Scorecard, noema-review, required-workflow-bootstrap, coverage-evidence, and opencode-review.

    This is direct operational proof that the always-available administrator path tracked by this issue is not merely theoretical: the central control-plane default branch has now been changed through a bypass while required review infrastructure was unavailable. This comment does not dispute the source quality or owner authorization for #1499; it records the governance consequence. A review/provider outage plus queue saturation can currently cause the normal protected evidence path to be replaced by routine administrator authority.

    Acceptance therefore remains unchanged and more urgent: remove the steady-state OrganizationAdmin/always bypass or convert it into a separately activated, time-bounded, audited break-glass mechanism; make normal administrator integration subject to exact-head required evidence; and preserve an emergency audit record including exact SHA, actor, reason, activation window, missing/failed contexts, and post-incident review. Do not retroactively manufacture passing checks for #1499.

  17. seonghobae commented on Sep 1, 2026

    @seonghobae
    ContributorAuthor

    2026-09-01 admission provenance — #1541

    Protected main advanced to 44a3c740f7c46c06e7500174d4127413f3f581eb when #1541 was merged at 2026-09-01T04:06:55Z (final submitted head 79f4dff32f6e2e73872c438699f0a65182fab501).

    Admission was not terminal-clean:

    • formal exact-head approvals: 0
    • exact-head checks: 69 total — 1 success, 13 queued, 22 cancelled, 33 skipped
    • unresolved review threads: 0
    • queued/cancelled/skipped review, Security, SAST, CodeQL, coverage, SBOM and provenance evidence remains non-passing

    The merge commit records a bounded owner-authorized control-plane bootstrap rationale. This ledger entry preserves the exact admission evidence separately from source usefulness and is not a rollback request.

  18. seonghobae commented on Sep 1, 2026

    @seonghobae
    ContributorAuthor

    2026-09-02 owner-plane checkpoint: #1176 is now at exact head 12076f9ab99e7da3198bc628be835267d0320a00 with protected main@7683f1da91f1fc9e046660169f1f7ac4aabcc3c6 integrated by an ordinary two-parent commit and no force-push. The latest main advance (#1348 queue-hygiene live-ref race repair) touched six paths that are disjoint from #1176's governance ownership; those six blobs were taken byte-for-byte from protected main. Fresh compare reports behind_by=0 and exactly the seven intended #1176 governance paths remain different.

    Fresh full-payload settings reads still reproduce the owner-plane defect: organization ruleset 18156473 has required_approving_review_count=1 and OrganizationAdmin/always bypass; repository ruleset 17921150 has approval count 0 but still allows rebase and retains OrganizationAdmin/always. No settings mutation was claimed or simulated. Orgmetra #88 remains unchanged at 0dc4f09cc3c87829ea1e3a0e3dc0188df07ad8cd, mergeable, with repository-owned exact-head workflows terminal successful, so it remains the positive ordinary-path canary after authorized settings reconciliation.

    The new #1176 exact-head ordinary checks have materialized and are currently queued; predecessor checks/reviews are not promoted to this head. Acceptance remains: reconcile both live settings surfaces with an independently authorized least-privilege owner-plane identity, re-read the full payloads, obtain terminal current-head deterministic/review/security evidence, then prove #88 can merge without synthetic approval or routine admin bypass.

  19. seonghobae commented on Sep 1, 2026

    @seonghobae
    ContributorAuthor

    Owner-plane source repair is now open as #1644 at exact head 4e3f6ae063e3c3bde74abbb6c121a111f19d77a9, based on protected main@7683f1da91f1fc9e046660169f1f7ac4aabcc3c6. The behavior contract was committed before implementation. The branch adds an exact two-ruleset manifest, a fail-closed reconciler with pre-PUT race detection and post-PUT full-payload convergence, read-only PR validation at 100% owned statement/branch/docstring gates, and a separate protected owner-plane apply job.

    This closes only the missing source/configuration-as-code path. It does not claim that either live ruleset has changed. Mutation is disabled unless trusted main has CWL_RULESET_RECONCILE_ENABLED=true and protected environment ruleset-governance-maintenance independently provides a dedicated CWL_RULESET_ADMIN_TOKEN; that credential is intentionally distinct from the repository-metadata token. Fresh live settings remain the same: organization 18156473 approval=1 + OrganizationAdmin/always; repository 17921150 approval=0 but rebase + OrganizationAdmin/always.

    After #1644 reaches terminal exact-head evidence and merges normally, remaining owner-plane acceptance is independent least-privilege credential/environment provisioning, explicit enablement, full-payload post-change proof, then #1176 audit proof and unchanged Orgmetra #88 ordinary-path canary. Do not use the current user's bypass capability to shortcut that sequence.

  20. seonghobae commented on Sep 2, 2026

    @seonghobae
    ContributorAuthor

    Fresh downstream acceptance evidence from ContextualWisdomLab/life-os turns the steady-state OrganizationAdmin/always concern into an observed control-plane incident. Protected life-os/main advanced through c689d22d2da77a928cf1eea0dd8752677cd6ff8a (noop, added one-byte tests-never) and then 232a53fce43291ce19414c56e0ab5e46e653eaf7 (chore: remove accidental placeholder) 16 seconds later. Both commits are authored/committed by the repository owner and current repository evidence does not identify them as normal PR merge commits. The final tree is clean; the finding is the bypass path itself.

    LifeOS-side RED/acceptance criterion for this owner-plane repair: after removing steady-state OrganizationAdmin/always and reconciling the generic approval rule under the current solo-maintainer contract, a fresh ruleset read must show no routine always-on bypass; a direct protected-main write attempt must be rejected; an unchanged deterministic-GREEN PR must still pass only through the ordinary PR + required-workflow + thread-resolution path; a negative canary with a failed/absent required workflow must remain blocked. LifeOS issue #212 now records the exact downstream incident and will revalidate after this central settings repair. No LifeOS leaf workaround is appropriate.

  21. seonghobae commented on Sep 2, 2026

    @seonghobae
    ContributorAuthor

    Fresh downstream canary for the live ruleset contract (2026-09-02): ContextualWisdomLab/scopeweave#523 is open/ready/mergeable at exact head e28b5caba7a6f16071ead232b33d0c5d64d78b7a, tree 5d4b4a6a55e627180e69f40c99190b7e99417a33, directly descended from current protected develop@2c328875e00e86537df3e965170be80532571cad (ahead_by=317, behind_by=0). All seven repository-owned exact-head workflows are terminal success on that head: CodeQL Required 33247472708, Server Tests 33247472679, Fuzz 33247472689, Dependency Review 33247472663, OSV Scanner 33247472656, SAST Semgrep 33247472709, Security Scan 33247472787; legacy statuses CodeRabbit and Devin Review are also success, and the current inline-review-thread sweep has no unresolved thread.

    The effective organization ruleset 18156473 was freshly read after its 2026-09-02 19:15 +09 update and still requires required_approving_review_count=1 (thread resolution on; last-push approval off) plus ten central workflow paths. ScopeWeave's repository-local Lock default branch ruleset 17214767 independently requires required_approving_review_count=1 and require_last_push_approval=true, with no bypass actor. Current #523 review submissions contain no APPROVED review. Per this issue's single-human-maintainer contract, do not self-approve or use the organization-admin bypass.

    There is a second rollout symptom on this unchanged head: the now-required central OpenCode/Strix workflows do not have current-head check runs (Required OpenCode Review count 0; Required Strix count 0). Current opencode-review.yml only admits opened/synchronize/reopened/ready_for_review/converted_to_draft/closed, so changing the organization ruleset after an already-open unchanged PR does not itself provide a pull-request event that materializes the newly-required check. Do not manufacture synchronize with a no-op commit or toggle draft state only to shake CI.

    Owner-path acceptance for this canary: (1) make the approval contract satisfiable under the declared solo-maintainer policy without weakening deterministic workflows/thread resolution; (2) provide a fail-closed, auditable way for newly-enrolled required workflows to materialize for already-open unchanged PR heads; (3) re-read both effective rulesets; (4) prove #523's unchanged e28b5cab... receives every required current-head workflow result and can proceed normally while a negative canary still blocks. This fleet lane will not mutate .github source/ruleset state while its dedicated writer lease is active.

  22. seonghobae commented on Sep 4, 2026

    @seonghobae
    ContributorAuthor

    OriginWeave에서 steady-state OrganizationAdmin/always가 실제 protected-main routine bypass로 사용된 최신 사례가 확인됐습니다.

    PR #284는 head 61bcf88c960c6c437ccd29b3fbb73cd4325f9e5a, base c789b802fc98a8d7fd8c09d9327f36828054d2a1에서 2026-09-04T14:20:16Z에 새 main 4ed08bfa7c063fc7f2ef9278ee8d281887b8296b로 squash merge됐습니다. GitHub rule-suite 3948421709는 actor seonghobae, result: bypass를 반환합니다.

    당시 active ruleset 18156473은 non-author approval 1개와 7개 central required workflow를 요구했습니다. PR reviews는 병합 뒤 COMMENTED만 제출됐고, 새 main의 CI/coverage/Code Quality도 병합 후 queued였습니다. 변경 내용의 품질이나 사후 checks 결과와 무관하게 이 rule-suite는 routine bypass 제거 acceptance의 직접 RED입니다.

    OriginWeave consumer RCA: ContextualWisdomLab/OriginWeave#215 (comment)

    복구 뒤 negative canary는 approval 또는 required workflow가 빠진 상태에서 차단돼야 하고, positive canary는 result: bypass 없이 모든 deterministic gate가 terminal success가 된 뒤에만 protected main으로 진행해야 합니다.

  23. seonghobae commented on Sep 4, 2026

    @seonghobae
    ContributorAuthor

    LifeOS owner-path evidence update (protected life-os/main@193a87ef54c3fe6dcda4755bce4d6bc81e3a0297): #247 now closes three chained local review-evidence fail-opens while the current inherited policy still expects one approval and exposes the routine-admin owner problem tracked here.

    Approval-presence RED cba8917778d15f1f1cbc4d4f4d049c5de5953300 → repair fd98e5a4d5ba8f614ef849b1e9f3d8c0c254ea2e prevents zero-review/COMMENTED-only evidence from reaching the merge path. Malformed-review RED 50b935263eadd01ed5b63075d0b316c9b965f273 → repair 2cc35bbbaaa7ccfb521e5884ccfdb0cbb24869ba rejects blank reviewer identity and invalid/missing submission timestamps before they can become decisive.

    Fresh exact-source review then found that GitHub REST provides immutable review commit_id, but LifeOS normalizeReview() discarded it. That left local approval freshness dependent on inherited stale-review dismissal and allowed a stale later approval to replace the same reviewer's earlier current-head CHANGES_REQUESTED inside the reducer. RED c3a496f77884bf2477c706c14bc5f4f47b9edf36 requires stale/missing/malformed approval commit_id to remain missing-approval and preserves current change-request authority. Causal evaluator repair 9c3b626c45d3679a30ff00f75b0eb2a4482c193c filters stale approvals before per-reviewer reduction; snapshot RED/fixture repair c99fef79b3089e61ef0dfa7cbf0a088f76a04d1e requires commit_id to survive collection; collector repair 35fc087e9a2af6e67d4bcc9805fcbdafb1a59acb retains bounded commit identity. CHANGELOG.md is code-current at exact #247 descendant 41345644c306252b29aa5906de8a5171a37519a6. A bounded reproduction is GREEN for stale-approval rejection, stale-approval/non-clearing of current change request, and current-head approval acceptance. Hosted exact-head evidence is still required before merge.

    This remains a current-live-policy safety repair, not a request to preserve approval-count=1 permanently. The canonical one-human-maintainer target here remains approval-count=0 with no routine OrganizationAdmin/always. If that settings contract lands, LifeOS must atomically reconcile/remove its local missing-approval condition rather than retain a stale stricter shadow policy. The immutable review-head consumer gap itself is now closed; target-policy reconciliation remains the owner handoff. No synthetic reviewer, self-approval, gate weakening, or routine bypass is introduced.

  24. seonghobae commented on Sep 5, 2026

    @seonghobae
    ContributorAuthor

    Fresh OriginWeave consumer evidence on 2026-09-05: PR #285 is Ready at unchanged exact head f455c2cd64b3dd3f027c91d396103792a205ddd0. Its ready_for_review transition materialized repository-native CI 33930234387 (queued), but no fresh central Security Scan, SAST Semgrep, CodeQL PR, Required OpenCode, Required Noema, Strix, or merge-scheduler runs. The only such exact-head runs are from the earlier Draft event and are terminal cancelled; dynamic Code Quality 33924014421 alone succeeded. Thus an unchanged Ready head cannot currently acquire a complete fresh required-workflow evidence set through its ordinary lifecycle event. This is consumer evidence for the existing owner-plane rollout/materialization acceptance, not permission to create a no-op commit, toggle Draft again, self-approve, bypass, or weaken required workflows. Positive acceptance should show the same unchanged head receives every required result after the owner repair; a negative head must remain blocked.

  25. added
    bugSomething isn't working
    type: bugDefect or incorrect behavior
    on Sep 7, 2026
  26. seonghobae commented on Sep 19, 2026

    @seonghobae
    ContributorAuthor

    Fresh consumer proof from ContextualWisdomLab/quarantine-sandbox-runtime (2026-09-19 KST), preserving the central owner boundary:

    • protected/default branch remains develop@60a85c7633e03b425b67159ec6822c8178cf87ea;
    • inherited organization ruleset 18156473 is active on ~DEFAULT_BRANCH and still requires the seven central workflows, one approving review, stale-review dismissal, review-thread resolution, deletion protection, non-fast-forward protection, and merge/squash only;
    • the same live payload still exposes OrganizationAdmin with bypass_mode=always, and the connected identity reports current_user_can_bypass=always;
    • quarantine's checked-in AGENTS.md/CLAUDE.md require exact-head CI/security/review evidence and forbid weakening gates; its integration root Add Palette journal for profile repo #1 remains Draft and immutable GitHub Release authority is absent;
    • repository Actions are separately queue-starved under .github#712, so queued evidence is incomplete and is not a reason to exercise bypass.

    This confirms #1340 is not only a .github-repository settings concern: the inherited routine-admin bypass is live on a security-runtime consumer whose release contract explicitly requires ordinary protected integration. I did not use the available bypass, direct-push, self-approve, lower review/security requirements, or mutate the leaf to work around it.

    Consumer-side acceptance remains: after the central owner-plane repair, refetch the full effective ruleset on this unchanged protected default branch and prove routine OrganizationAdmin/always bypass is absent while required workflows, thread resolution, stale-review handling, deletion/non-fast-forward protection, and allowed merge methods remain intact. Any future quarantine merge/release claim must then use the repaired ordinary path, not the historical bypass capability.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: ci-cdCI, GitHub Actions, checks, release, or supply chainarea: securitySecurity boundary, hardening, or vulnerability preventionbugSomething isn't workingpriority: criticalImmediate blocker, P0, urgent deadlock, or critical incidentstatus: blockedBlocked by conflict, dependency, or required prerequisitetype: bugDefect or incorrect behaviortype: maintenanceMaintenance, build, dependency, or operational upkeep

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions