Skip to content

fix(governance): automate ruleset owner-plane reconciliation - #1644

Open
seonghobae wants to merge 255 commits into
mainfrom
fix/ruleset-owner-plane-reconciler
Open

seonghobae wants to merge 255 commits into
mainfrom
fix/ruleset-owner-plane-reconciler

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 1, 2026 •

Copy link
Copy Markdown
Contributor

Current authority / repair state — 2026-10-03

Canonical source head is cf6627439ecf99413f49a3c4ca7f9a81ffda972d, exact tree e3973f0f7dc2dfd08d117142e2ff5a0718ffef34. It is an ordinary fast-forward successor of the prior PR head through merge commit 68c60ba9f4c970901120f7c0e76b1a1c5ab27295, whose parents are prior head 722fec9de67aece7500993ee2999b21df0fab83b and protected main@37b10243cec3d160ecc9c1be75c71428b160a703. No force push, destructive rebase, closure, bypass, or delta disposal occurred.

GitHub reports the branch ahead 255 / behind 0, merge base exactly 37b10243cec3d160ecc9c1be75c71428b160a703, 23 changed paths, and a clean mergeable result. The repaired source is Open / Ready / Proposed / merge HOLD: Ready admits CodeQL and model review; it does not authorize merge.

Root cause and repair

Fresh live evidence for repository ruleset 17921150 showed approval count 0, last-push approval false, rebase allowed, and OrganizationAdmin/always bypass. The stale PR policy encoded the same zero-review posture for both managed scopes, overriding protected-main's organization review contract.

The canonical auditor/reconciler now preserves distinct scopes:

  • organization ruleset 18156473: exactly 2 approving reviews;
  • owner-repository ruleset 17921150: exactly 1 approving review;
  • both scopes: last-push approval, stale-review dismissal, review-thread resolution, merge/squash only, deletion/non-fast-forward protection, empty bypass actors, empty synthetic required-reviewer list, and no same-author CODEOWNER requirement.

Unrelated live editable rules/conditions remain deep-copied and preserved. Privileged apply remains disabled unless trusted protected main enables CWL_RULESET_RECONCILE_ENABLED and the protected ruleset-governance-maintenance environment supplies the dedicated least-privilege token. This source repair did not mutate a live ruleset.

Exact-tree evidence

  • RED remote commit 14ccf013e6995ce9be48c80c02e95209bfbdf85c, tree 1fddf34aec1f8821161e564d1b89bcfccfbd94a3: 3 focused failures proved both auditors and the writer flattened policy to zero approvals/no last-push.
  • GREEN tree e3973f0f7dc2dfd08d117142e2ff5a0718ffef34: 189 permanent owner-plane tests passed with 100% statement/branch coverage of reconcile_ruleset_governance.py and 100% public-doc coverage.
  • Repository warning-fatal suite: 5,317 passed, 11 skipped, 40 subtests passed.
  • Actions-mode ruleset suite: 192 passed.
  • Independent post-repair review: no Critical, Important, or Minor finding; merge topology and exact delta preservation were rechecked.
  • All 65 historical inline threads remain resolved. Current-head qualifying approval count is 0.

The first hosted attempt failed before any repository step: failed jobs had empty step lists, runner_id=0, and 2–4 second lifetimes. The ordinary failed-job rerun produced the identical pre-execution signature in all five direct workflows; it did not expose a repository log or execute PR code. The Code Quality child run failed with the same zero-step signature, and GitHub rejected its one bounded ordinary retry with 403 This workflow run cannot be retried. No exact-head substantive approval exists; the Draft-gated Noema run did not execute model review. These external execution-admission blockers are preserved without repeated blind retries and no historical check/review transfers.

The Ready event preserved the exact head and admitted a fresh generation: Security 37123186852, Python Security 37123186943, CodeQL 37123186847, and Semgrep 37123187068. Each failed before an executable step; every failed admission job again has steps=[] and no runner assignment, while dependent jobs were skipped. Ready therefore removed the Draft/CodeQL circularity but did not satisfy any merge gate.

Ownership boundary

This PR owns only generic organization/repository ruleset reconciliation. ConceptWeave Product-specific lifecycle remains with #2348 and dependent Draft #2350. Do not fold Product enforcement into this owner.

Acceptance boundary

Ready is review admission, not merge authorization. Keep merge HOLD until GitHub produces terminal exact-head security, governance, coverage, provenance, and substantive model-review evidence; no unresolved actionable thread remains; and a qualifying independent current-head approval exists. Then use only the ordinary protected merge path with exact-head binding. Do not self-approve, fabricate reviewers, auto-merge from local evidence, or use administrator bypass.

Refs #772, #1176, #1351, #2348, #2350.

seonghobae and others added 30 commits August 21, 2026 06:02
# Conflicts:
#	scripts/ci/test_strix_quick_gate.sh
Merge protected main non-destructively while retaining only the create-transition audit and its executable regressions. Focused ruleset audit: 20 passed. Full suite: 1,402 passed, 1 skipped, 16 subtests.
Preserve only the two governance owner files over protected main 0c6b9a6. Focused ruleset audit: 20 passed. Full suite: 1,402 passed, 1 skipped, 16 subtests.
@seonghobae
seonghobae marked this pull request as draft September 12, 2026 11:20

Copy link
Copy Markdown
Contributor Author

Exact-head repair receipt for 722fec9de67aece7500993ee2999b21df0fab83b / tree 629fc3684bcfca48b66146ccda0f1b70956cdf4a.

Noema's source finding was valid. RED pinned the missing failure ledger, subject-specific central/owner/stacked attribution, absence of early exits before the next audit, and the terminal named receipt. The workflow now records a failed API read as a named failure, skips auditing the unavailable payload, continues collecting any remaining subject evidence, and exits nonzero once with every proven failure subject. A later owner/stacked fetch error can no longer hide an already-observed central governance drift.

Verification on the exact tree:

  • focused ruleset contracts: 55 passed
  • full repository: 3195 passed, 1 skipped, 36 subtests passed
  • GITHUB_ACTIONS=true, Deprecation Warnings as errors, workflow syntax, and git diff --check: PASS
  • protected-base compare: 252 ahead / 0 behind, mergeable

The PR is Draft/Proposed while the new hosted runs and qualifying independent review are reacquired. This does not claim live ruleset convergence or authorize bypass/merge.

Copy link
Copy Markdown
Contributor Author

Exact-head CodeQL RCA for 722fec9de67aece7500993ee2999b21df0fab83b:

  • Required run 34690754218 is now terminal FAILURE. Python attempt 1 dispatched successfully and ended VERDICT_STATE=pending; Actions later entered attempt 2 and failed closed because no authenticated terminal verdict existed (Exact CodeQL job was rerun without an authenticated terminal verdict). The coordinator dispatch job succeeded.
  • Ruleset Governance Reconcile, Runtime Quality, Security, SAST, and Python Security are terminal GREEN. This CodeQL state is the shared protected-handler settlement defect, not a ruleset-reconciler source finding.
  • Canonical bootstrap remains fix(codeql): bootstrap versioned dispatch handler #2106 at 24bb6591ab7df23558cb793b4af60c567ff9da97; protected-handler run 34692405217 is still pre-runner queued.

Draft/Proposed remains correct. Do not manually rerun, synthesize status, transfer successor evidence, or merge until exact-head CodeQL converges and a qualifying independent approval exists.

@seonghobae
seonghobae marked this pull request as ready for review September 12, 2026 12:51

Copy link
Copy Markdown
Contributor Author

Ready transition preserved exact head 722fec9de67aece7500993ee2999b21df0fab83b and produced a fresh review-admission generation. Current-head Security 34694804912, SAST 34694804913, Python Security 34694804932, and CodeQL 34694804935 are now terminal SUCCESS. Ruleset Governance 34690754225 and Runtime Quality 34690754262 remain same-head SUCCESS; review threads are 0.

Noema's source finding is bound to predecessor 02d76fa7… and is repaired by current 722fec9d…, but its formal CHANGES_REQUESTED has not yet been replaced by a qualifying current-head approval. OpenCode's earlier check-only request is likewise not dismissed here. Therefore Ready remains review admission only; no merge/auto-merge authorization is inferred.

Copy link
Copy Markdown
Contributor Author

@opencode-agent Revalidate unchanged exact head 722fec9de67aece7500993ee2999b21df0fab83b against its fresh Ready-generation evidence. Ruleset Governance 34690754225, Runtime Quality 34690754262, Security 34694804912, SAST 34694804913, Python Security 34694804932, and CodeQL 34694804935 are terminal SUCCESS; the branch is mergeable, unresolved review threads are zero, and the predecessor-head Noema finding is repaired by this head but does not transfer as approval. Use only the contextual-orchestrator gateway with fixed orchestrator/free; no provider/model/group override or paid fallback.

@seonghobae
seonghobae marked this pull request as draft September 14, 2026 21:05

Copy link
Copy Markdown
Contributor Author

Fresh consumer canary for the governance owner: ContextualWisdomLab/TEPP#523@b733492c5ff9f108bc8f52e78da53ba7927a575d is Ready/mergeable, 0-behind protected main, all three inline review threads are resolved, and combined statuses currently include Devin Review=success and CodeRabbit=success. Formal review submissions still contain no APPROVED review, so organization ruleset 18156473's required_approving_review_count=1 remains an independent landing blocker under the no-self-approval/no-bot-as-human policy documented here. I requested an exact-head CodeRabbit evaluation only; I am not counting it as human approval or weakening the gate. This TEPP canary therefore supports #1644's existing conclusion that source-level ruleset reconciliation, not leaf bypass/self-approval, is the correct owner path.

Copy link
Copy Markdown
Contributor Author

Fresh owner-path audit against protected .github/main@64aa08d7fa487deacd41c761c36277ca68cab6c9:

  • fix(governance): automate ruleset owner-plane reconciliation #1644 remains exact 722fec9de67aece7500993ee2999b21df0fab83b, Draft/open/non-mergeable, with historical merge base fb17ef556f94f673234aa557254ae52779e9a7b0.
  • Current compare is diverged 252 ahead / 244 behind. The retained effective surface is 22 paths.
  • Intervening protected-main changes overlap only two of those 22 paths: CHANGELOG.md and docs/product-technical-gap-baseline.md. The other 20 governance/workflow/config/test paths are non-overlapping with protected changes since the historical merge base.
  • The two overlapping fix(governance): automate ruleset owner-plane reconciliation #1644 deltas are additive, not replacement semantics: the changelog adds the owner-plane reconciliation entry, and the product baseline adds G-17 for fail-closed accumulation of central/owner/stacked ruleset audit failures.

The causal repair remains an ordinary, non-force, current-main reconciliation that preserves both current protected contents and those two additive deltas, then reacquires exact-head/current-base evidence from zero. Historical GREEN/reviews must not transfer.

I did not move the branch ref in this sweep. The available Git-data primitives can safely reuse the 20 non-overlap blobs, but the two overlapping documents are ~151 KiB and ~323 KiB. Without a verified lossless hunk application or complete reconstructed blobs, constructing a candidate would risk deleting intervening protected documentation—the same class of repair error this lineage is meant to prevent. No force update, destructive rebase, approval bypass, or policy weakening was used.

Live organization ruleset 18156473 still requires one generic approval with no required reviewers while retaining the seven central workflows, thread resolution, merge/squash-only, deletion and non-fast-forward protections. Thus #772 remains live owner-plane drift until #1644 is reconciled, integrated, and the separately gated privileged reconciler actually proves live convergence.

seonghobae commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor Author

ConceptWeave consumer canary update (read-only coordination, no owner-source mutation): fresh effective org ruleset 18156473 on ContextualWisdomLab/ConceptWeave still reports required_approving_review_count=1, required_reviewers=[], CODEOWNER/last-push approval disabled, seven central required workflows, required thread resolution, deletion/non-fast-forward protection, and OrganizationAdmin/always bypass. ConceptWeave Product bootstrap #35 exact c4b304fd5b0d8934f7c9f05ef6d54e1a4ef21e0d is Draft/mergeable, but its landing gate is now explicitly bound to this live owner-plane defect rather than asking the leaf to fabricate an independent reviewer or use bypass.

A second consumer requirement is now recorded on #35 review 5284225958: the same effective ruleset does not make repository-owned Product a required workflow/status, and protected pr-review-merge-scheduler.yml does not name Product. Once #35 lands, Product execution alone therefore must not be represented as mechanically merge-blocking until governance provides an owner-approved repository/status or equivalent central binding. Please preserve this as a consumer acceptance case when #1644 is reconciled: solo-maintainer approval count becomes satisfiable without self/bot approval, routine admin bypass is absent, existing central gates stay fail-closed, and ConceptWeave Product acceptance has an explicit protected-merge binding before that repository claims enforced Product quality.

Fresh owner-head correction — 2026-09-23 KST: direct protected-branch read now shows .github/main@e6334e229581a918e2f22de18733b76fa65d7e71. Comparing that protected head to #1644 exact 722fec9de67aece7500993ee2999b21df0fab83b is still diverged, but now 252 ahead / 277 behind with merge base fb17ef556f94f673234aa557254ae52779e9a7b0. The #1644 body still says protected main 64aa08d7... and 244 behind, so that checkpoint is stale. This does not change the repair strategy: ordinary/non-force current-main reconciliation is still required, and historical exact-tree GREEN/reviews must not transfer to the reconciled descendant. Do not move the stale branch merely to refresh metadata; preserve all current protected documentation plus the retained owner deltas before publishing a new exact head.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 owner-capability finding for the ConceptWeave consumer canary. Live ConceptWeave policy now needs a repository-specific binding for canonical Product acceptance, but this exact reconciler cannot currently represent that target: config/ruleset-governance.json contains only .github ruleset 17921150 and organization ruleset 18156473; load_manifest() requires len(raw_targets) == 2 and exact equality with those two identities. Therefore #1644 can repair the generic solo-maintainer approval/bypass drift, but it cannot by itself make ContextualWisdomLab/ConceptWeave Product acceptance merge-blocking. Adding the Product status to org-wide ruleset 18156473 would deadlock unrelated repositories that do not emit it. Central issue #2348 now owns the repository-specific create/adopt/bind lifecycle. Preserve #1644's current scope and ordinary/non-force reconciliation unless the governance owner explicitly absorbs #2348 through a verified successor; do not fake GREEN by claiming #1644 already covers Product binding. Current protected .github/main is e6334e229581a918e2f22de18733b76fa65d7e71, so this head is 252 ahead / 277 behind and requires current-main reconciliation before any successor acceptance.

Copy link
Copy Markdown
Contributor Author

ConceptWeave consumer follow-up: #2348 is now implemented as dependent Draft #2350 on this exact #1644 head. A new bootstrap-order P1 was corrected: Product acceptance cannot be made active before ConceptWeave#35 lands because protected ConceptWeave main does not contain the Product producer and #35 currently emits no Product run. #2350 therefore reuses this PR's history/collision primitives but keeps the repository-specific rule in evaluate through #35 producer landing; only a subsequent real current-base Product canary can supply the GitHub Actions integration ID for active promotion. #1644 remains the prerequisite canonical owner for generic solo-maintainer approval/bypass policy and must still ordinary/non-force reconcile from its stale base before #2350 can be restacked/current-base validated.

Copy link
Copy Markdown
Contributor Author

Dependent Product-owner update only: #2350 remains exact 7a627f3e9c564bcf7ce2f826b57c1b6ef8d1ebae, but exact-current review 5289945740 found its immutable Product blob coordinate is not yet consumed by bootstrap/canary/activation. Null therefore does not yet fail closed even though the parser/comparer repair exists. Keep #1644 focused on generic solo-maintainer governance and its required ordinary/non-force current-main reconciliation; do not absorb ConceptWeave-specific blob/canary lifecycle here. #2350 owner run 35845521134 remains queued, so no dependent source movement or evidence transfer is justified.

Copy link
Copy Markdown
Contributor Author

Current-main reconciliation rationale — 2026-10-03

Fresh protected-state evidence binds this repair to main@37b10243cec3d160ecc9c1be75c71428b160a703 and PR head 722fec9de67aece7500993ee2999b21df0fab83b.

The live repository ruleset 17921150 is active but materially drifts from protected-main governance: it requires zero approvals, disables last-push approval, permits rebase, and grants OrganizationAdmin an always bypass. The PR currently codifies most of that stale solo-maintainer posture, so historical GREEN cannot be reused.

I will reconcile by an ordinary two-parent merge of the exact current protected main into this branch—no force push, destructive rebase, closure, or delta disposal—then repair the canonical auditor/reconciler test-first. The target contract is: repository ruleset one qualifying independent approval plus last-push approval; organization ruleset retains protected-main's two-approval policy; stale-review dismissal and thread resolution remain required; only merge/squash are allowed; deletion/non-fast-forward remain; bypass actors are empty. Privileged apply remains disabled and no live ruleset mutation is authorized by this source repair.

The PR remains Draft. After the repair, all evidence must be regenerated on the exact successor head and no merge/Ready transition is permitted without terminal hosted checks and qualifying independent approval.

Copy link
Copy Markdown
Contributor Author

Exact-head hosted RCA / retry — cf6627439ecf99413f49a3c4ca7f9a81ffda972d

The first hosted attempts for runs 37122658939, 37122659024, 37122658972, 37122659004, and 37122659081 failed before repository code executed. Every failed job exposed steps=[], runner_id=0, an empty runner name, and a 2–4 second lifetime; dependent security jobs were skipped. This is terminal pre-execution runner provisioning evidence, not a semantic security/test/governance verdict.

All five failed-job sets were rerun through the ordinary Actions API. The PR stays Draft/HOLD while reruns and the already in-progress exact-head checks settle. No bypass, merge, Ready transition, or historical-evidence transfer is authorized.

Copy link
Copy Markdown
Contributor Author

Exact-head hosted evidence addendum

  • Exact head: cf6627439ecf99413f49a3c4ca7f9a81ffda972d
  • Protected-main merge base: 37b10243cec3d160ecc9c1be75c71428b160a703; compare is 255 ahead / 0 behind.
  • Local/remote tree receipt: e3973f0f7dc2dfd08d117142e2ff5a0718ffef34.
  • Current-head approvals: 0; review threads: 65 total / 0 unresolved.
  • Code Quality child run 37122656631, job 111201677019, failed before any repository step (steps=[], no runner assignment). An ordinary failed-job retry was attempted once and GitHub returned 403 This workflow run cannot be retried; no blind retry or bypass was used.
  • The other five direct exact-head failures were each retried once and reproduced the same pre-step/no-runner signature. This is hosted execution admission/provisioning evidence, not a repository test failure.

PR remains Draft / HOLD. No readiness promotion, merge, auto-merge, ruleset mutation, or bypass is justified until exact-head hosted evidence and an independent current-head approval exist.

Copy link
Copy Markdown
Contributor Author

Ready admission rationale

Fresh revalidation at exact head cf6627439ecf99413f49a3c4ca7f9a81ffda972d confirms: protected-main merge base 37b10243cec3d160ecc9c1be75c71428b160a703, 255 ahead / 0 behind, 23 intended paths, all 65 review threads resolved, independent post-repair review clean, and no outstanding source finding.

Draft is now the circular blocker: CodeQL was skipped and Noema did not execute substantive review because the PR was Draft. Ready is therefore restored solely to admit required review and Checks. Approval count remains 0 and the prior hosted security/governance runs failed before repository steps, so Proposed / merge HOLD remains binding. No merge, auto-merge, retry commit, ruleset mutation, or bypass is authorized.

@seonghobae seonghobae removed the status: draft Draft pull request label Oct 3, 2026
@seonghobae
seonghobae marked this pull request as ready for review October 3, 2026 12:32

Copy link
Copy Markdown
Contributor Author

Ready-generation exact-head evidence

The Ready transition preserved cf6627439ecf99413f49a3c4ca7f9a81ffda972d and created fresh runs:

  • Security 37123186852: Detect changed scope and gitleaks failed with steps=[]; downstream jobs skipped.
  • Python Security 37123186943: Detect Python failed with steps=[]; downstream jobs skipped.
  • CodeQL 37123186847: Detect CodeQL languages failed with steps=[]; compatibility/dispatch skipped.
  • Semgrep 37123187068: scan job failed with steps=[].

No job received a runner or executed repository code. This generation removes the prior Draft-skip ambiguity while preserving a terminal runner-admission failure. Approval remains 0 and unresolved threads remain 0; merge HOLD continues. No rerun, wake commit, source mutation, auto-merge, or bypass was used.

Copy link
Copy Markdown
Contributor Author

@opencode-agent Revalidate unchanged exact head cf6627439ecf99413f49a3c4ca7f9a81ffda972d after its current-main RED→GREEN repair and Ready admission. The branch is 0 behind protected main@37b10243cec3d160ecc9c1be75c71428b160a703, mergeable, and all 65 review threads are resolved. Fresh Ready-generation Security 37123186852, Python Security 37123186943, CodeQL 37123186847, and Semgrep 37123187068 failed before executable steps (steps=[], no runner assignment), so treat them as fail-closed hosted-admission evidence rather than passing or source verdicts. Review only this exact head; do not transfer historical approval or request bypass/merge.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: ci-cd CI, GitHub Actions, checks, release, or supply chain bug Something isn't working priority: high High-priority or P1 work type: bug Defect or incorrect behavior

Projects

Status: In Progress

Development

Successfully merging this pull request may close these issues.

2 participants