Repository navigation
fix(governance): automate ruleset owner-plane reconciliation - #1644
seonghobae wants to merge 255 commits into
Conversation
…ked-pr-central-required-workflows
# Conflicts: # scripts/ci/test_strix_quick_gate.sh
Merge protected main non-destructively while retaining only the create-transition audit and its executable regressions. Focused ruleset audit: 20 passed. Full suite: 1,402 passed, 1 skipped, 16 subtests.
Preserve only the two governance owner files over protected main 0c6b9a6. Focused ruleset audit: 20 passed. Full suite: 1,402 passed, 1 skipped, 16 subtests.
|
Exact-head repair receipt for Noema's source finding was valid. RED pinned the missing failure ledger, subject-specific central/owner/stacked attribution, absence of early exits before the next audit, and the terminal named receipt. The workflow now records a failed API read as a named failure, skips auditing the unavailable payload, continues collecting any remaining subject evidence, and exits nonzero once with every proven failure subject. A later owner/stacked fetch error can no longer hide an already-observed central governance drift. Verification on the exact tree:
The PR is Draft/Proposed while the new hosted runs and qualifying independent review are reacquired. This does not claim live ruleset convergence or authorize bypass/merge. |
|
Exact-head CodeQL RCA for
Draft/Proposed remains correct. Do not manually rerun, synthesize status, transfer successor evidence, or merge until exact-head CodeQL converges and a qualifying independent approval exists. |
|
Ready transition preserved exact head Noema's source finding is bound to predecessor |
|
@opencode-agent Revalidate unchanged exact head |
|
Fresh consumer canary for the governance owner: |
|
Fresh owner-path audit against protected
The causal repair remains an ordinary, non-force, current-main reconciliation that preserves both current protected contents and those two additive deltas, then reacquires exact-head/current-base evidence from zero. Historical GREEN/reviews must not transfer. I did not move the branch ref in this sweep. The available Git-data primitives can safely reuse the 20 non-overlap blobs, but the two overlapping documents are ~151 KiB and ~323 KiB. Without a verified lossless hunk application or complete reconstructed blobs, constructing a candidate would risk deleting intervening protected documentation—the same class of repair error this lineage is meant to prevent. No force update, destructive rebase, approval bypass, or policy weakening was used. Live organization ruleset |
|
ConceptWeave consumer canary update (read-only coordination, no owner-source mutation): fresh effective org ruleset A second consumer requirement is now recorded on #35 review Fresh owner-head correction — 2026-09-23 KST: direct protected-branch read now shows |
seonghobae
left a comment
There was a problem hiding this comment.
P1 owner-capability finding for the ConceptWeave consumer canary. Live ConceptWeave policy now needs a repository-specific binding for canonical Product acceptance, but this exact reconciler cannot currently represent that target: config/ruleset-governance.json contains only .github ruleset 17921150 and organization ruleset 18156473; load_manifest() requires len(raw_targets) == 2 and exact equality with those two identities. Therefore #1644 can repair the generic solo-maintainer approval/bypass drift, but it cannot by itself make ContextualWisdomLab/ConceptWeave Product acceptance merge-blocking. Adding the Product status to org-wide ruleset 18156473 would deadlock unrelated repositories that do not emit it. Central issue #2348 now owns the repository-specific create/adopt/bind lifecycle. Preserve #1644's current scope and ordinary/non-force reconciliation unless the governance owner explicitly absorbs #2348 through a verified successor; do not fake GREEN by claiming #1644 already covers Product binding. Current protected .github/main is e6334e229581a918e2f22de18733b76fa65d7e71, so this head is 252 ahead / 277 behind and requires current-main reconciliation before any successor acceptance.
|
ConceptWeave consumer follow-up: #2348 is now implemented as dependent Draft #2350 on this exact #1644 head. A new bootstrap-order P1 was corrected: |
|
Dependent Product-owner update only: #2350 remains exact |
Current-main reconciliation rationale — 2026-10-03Fresh protected-state evidence binds this repair to The live repository ruleset I will reconcile by an ordinary two-parent merge of the exact current protected main into this branch—no force push, destructive rebase, closure, or delta disposal—then repair the canonical auditor/reconciler test-first. The target contract is: repository ruleset one qualifying independent approval plus last-push approval; organization ruleset retains protected-main's two-approval policy; stale-review dismissal and thread resolution remain required; only merge/squash are allowed; deletion/non-fast-forward remain; bypass actors are empty. Privileged apply remains disabled and no live ruleset mutation is authorized by this source repair. The PR remains Draft. After the repair, all evidence must be regenerated on the exact successor head and no merge/Ready transition is permitted without terminal hosted checks and qualifying independent approval. |
Exact-head hosted RCA / retry —
|
Exact-head hosted evidence addendum
PR remains Draft / HOLD. No readiness promotion, merge, auto-merge, ruleset mutation, or bypass is justified until exact-head hosted evidence and an independent current-head approval exist. |
Ready admission rationaleFresh revalidation at exact head Draft is now the circular blocker: CodeQL was skipped and Noema did not execute substantive review because the PR was Draft. Ready is therefore restored solely to admit required review and Checks. Approval count remains 0 and the prior hosted security/governance runs failed before repository steps, so Proposed / merge HOLD remains binding. No merge, auto-merge, retry commit, ruleset mutation, or bypass is authorized. |
Ready-generation exact-head evidenceThe Ready transition preserved
No job received a runner or executed repository code. This generation removes the prior Draft-skip ambiguity while preserving a terminal runner-admission failure. Approval remains 0 and unresolved threads remain 0; merge HOLD continues. No rerun, wake commit, source mutation, auto-merge, or bypass was used. |
|
@opencode-agent Revalidate unchanged exact head |
Current authority / repair state — 2026-10-03
Canonical source head is
cf6627439ecf99413f49a3c4ca7f9a81ffda972d, exact treee3973f0f7dc2dfd08d117142e2ff5a0718ffef34. It is an ordinary fast-forward successor of the prior PR head through merge commit68c60ba9f4c970901120f7c0e76b1a1c5ab27295, whose parents are prior head722fec9de67aece7500993ee2999b21df0fab83band protectedmain@37b10243cec3d160ecc9c1be75c71428b160a703. No force push, destructive rebase, closure, bypass, or delta disposal occurred.GitHub reports the branch ahead 255 / behind 0, merge base exactly
37b10243cec3d160ecc9c1be75c71428b160a703, 23 changed paths, and a clean mergeable result. The repaired source is Open / Ready / Proposed / merge HOLD: Ready admits CodeQL and model review; it does not authorize merge.Root cause and repair
Fresh live evidence for repository ruleset
17921150showed approval count 0, last-push approval false,rebaseallowed, andOrganizationAdmin/alwaysbypass. The stale PR policy encoded the same zero-review posture for both managed scopes, overriding protected-main's organization review contract.The canonical auditor/reconciler now preserves distinct scopes:
18156473: exactly 2 approving reviews;17921150: exactly 1 approving review;Unrelated live editable rules/conditions remain deep-copied and preserved. Privileged apply remains disabled unless trusted protected
mainenablesCWL_RULESET_RECONCILE_ENABLEDand the protectedruleset-governance-maintenanceenvironment supplies the dedicated least-privilege token. This source repair did not mutate a live ruleset.Exact-tree evidence
14ccf013e6995ce9be48c80c02e95209bfbdf85c, tree1fddf34aec1f8821161e564d1b89bcfccfbd94a3: 3 focused failures proved both auditors and the writer flattened policy to zero approvals/no last-push.e3973f0f7dc2dfd08d117142e2ff5a0718ffef34: 189 permanent owner-plane tests passed with 100% statement/branch coverage ofreconcile_ruleset_governance.pyand 100% public-doc coverage.The first hosted attempt failed before any repository step: failed jobs had empty step lists,
runner_id=0, and 2–4 second lifetimes. The ordinary failed-job rerun produced the identical pre-execution signature in all five direct workflows; it did not expose a repository log or execute PR code. The Code Quality child run failed with the same zero-step signature, and GitHub rejected its one bounded ordinary retry with403 This workflow run cannot be retried. No exact-head substantive approval exists; the Draft-gated Noema run did not execute model review. These external execution-admission blockers are preserved without repeated blind retries and no historical check/review transfers.The Ready event preserved the exact head and admitted a fresh generation: Security
37123186852, Python Security37123186943, CodeQL37123186847, and Semgrep37123187068. Each failed before an executable step; every failed admission job again hassteps=[]and no runner assignment, while dependent jobs were skipped. Ready therefore removed the Draft/CodeQL circularity but did not satisfy any merge gate.Ownership boundary
This PR owns only generic organization/repository ruleset reconciliation. ConceptWeave Product-specific lifecycle remains with #2348 and dependent Draft #2350. Do not fold Product enforcement into this owner.
Acceptance boundary
Ready is review admission, not merge authorization. Keep merge HOLD until GitHub produces terminal exact-head security, governance, coverage, provenance, and substantive model-review evidence; no unresolved actionable thread remains; and a qualifying independent current-head approval exists. Then use only the ordinary protected merge path with exact-head binding. Do not self-approve, fabricate reviewers, auto-merge from local evidence, or use administrator bypass.
Refs #772, #1176, #1351, #2348, #2350.