Skip to content

ci(gyeot): add central self-hosted verification - #2611

Draft
seonghobae wants to merge 47 commits into
mainfrom
feat/gyeot-central-self-hosted
Draft

seonghobae wants to merge 47 commits into
mainfrom
feat/gyeot-central-self-hosted

Conversation

@seonghobae

@seonghobae seonghobae commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Scope

Fixed-caller Gyeot reusable workflow and four central helpers, with app export and PostgreSQL verification. Two jobs route only through the dedicated CWL Gyeot CI self-hosted group. The current branch also preserves the entire independently owned #2572 inherited-quality/security stack by ordinary merge, plus the reviewed sandbox and CodeQL-clock repairs; it is not only a seven-file change.

Current source and local acceptance

Exact head dc59db224eb087d100d343ae125defc47b7a2a2c, parents Gyeot 87a371a7 and quality owner b37356d5, tree 152d8668f72016293928c22fbbc177bf3da18fe8. An exact-tree private no-commit merge ran Python 3.14.5 full tests: 5,405 passed, 4 skipped, 40 subtests passed. Statement 18,280/18,280 and branch 7,506/7,506 coverage = 100%; interrogate 1,473/1,473 = 100%. All three gate exits 0, source hashes stable and all Gyeot files preserved. Parent independently verified the 28-artifact receipt at /Users/seonghobae/.hermes/cache/scratch/gyeot-2572-private-accept-20261009/FINAL-MANIFEST.json (local host). One ResourceWarning remained; the 4 skips are explicit, not tested native functionality.

Deliberate non-readiness

Still Draft. GYEOT_HELPER_COMMIT=UNPUBLISHED_GYEOT_HELPER_COMMIT deliberately prevents calling or executing an unintegrated helper snapshot. The product caller template is not installed. Dedicated group 9 is selected for Gyeot only but currently has zero runners; no other group is borrowed. Shared exact label/group source-policy admission lives in stacked Draft #2613 on global migration #2565. Personal LiteLLM auto source wiring exists on current #2565 head but is not yet protected deployment, authenticated inference or qualifying independent App approval for this PR. GitHub-managed Code Quality is billing-locked before job start. No hosted fallback, protection bypass, fabricated status, pre-decided approval or merge is requested.

Remaining gates

Integrate and independently review current cumulative tree under normal protection; publish the central helper snapshot before replacing the sentinel with its real immutable SHA and activating a product caller. Provision/attest the dedicated runner and run exact-head jobs. Preserve security and 100% quality gates; obtain real author-distinct Noema/OpenCode App verdict on the current head after Ready and deployed routing. CI outcomes, runner canary, formal review and protected merge remain separate.

References #2565, #2572, #2613 and Issue #2560; consumer ContextualWisdomLab/gyeot.

Preserve the live security-owner and Gap-evidence lineage while merging the independently reviewed RED-to-GREEN repair that removes urlopen suppressions, accepts one credential-free HTTPS redirect only to the exact GitHub release-assets host, bounds reads, and closes every response/connection path.

Local exact-tree evidence: 16 focused tests passed; git diff --check passed. The same repair on the immediately preceding owner tree passed 5,178 tests, 8 skipped, and 40 subtests, and independent review reported zero Critical, Important, or Minor findings. Fresh hosted exact-head evidence remains mandatory.
Replace only the corrupted 120,060-byte binary payload with the last complete 3,678-line UTF-8 baseline from the immediate valid predecessor. Preserve the SAST transport repair and all other a5ddcfc changes. Fresh exact-head hosted evidence remains required.
Complete the Semgrep transport repair by constructing the urllib opener with ProxyHandler({}). This prevents environment-derived HTTPS proxy authorities and proxy credentials from entering the fixed GitHub-to-release-assets request path while preserving the reviewed one-hop redirect handler.

RED-to-GREEN: the bounded-download contract first required an explicit empty proxy map and failed when build_opener received only the redirect handler. Final focused verification: 16 passed; compileall and git diff --check passed. Independent offline replay with a credential-bearing https_proxy confirmed exclusion, and re-review reported zero Critical, Important, or Minor findings. Fresh hosted exact-head evidence remains mandatory.
seonghobae and others added 15 commits October 1, 2026 10:58
Preserve the live exact-head SAST RCA documentation and the independently reviewed ProxyHandler({}) repair as ordinary parents. The merged tree retains the restored complete Gap baseline, fixed one-hop redirect handler, ambient proxy/auth exclusion, focused GREEN evidence, and all release HOLD language.

Focused exact-tree verification: 16 passed; git diff --check passed. Fresh hosted exact-head evidence and qualifying approval remain mandatory.
Co-Authored-By: Claude Code <noreply@anthropic.com>
Co-Authored-By: Claude Code <noreply@anthropic.com>
Co-Authored-By: Claude Code <noreply@anthropic.com>
Co-Authored-By: Claude Code <noreply@anthropic.com>
Co-Authored-By: Claude Code <noreply@anthropic.com>
Co-Authored-By: Claude Code <noreply@anthropic.com>
Co-Authored-By: Claude Code <noreply@anthropic.com>
Co-Authored-By: Claude Code <noreply@anthropic.com>
Co-Authored-By: Claude Code <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true
  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@seonghobae

Copy link
Copy Markdown
Contributor Author

Reviewed repair published — October 9, 2026 KST

Exact head: 87a371a. Normal push; no merge or protection bypass. Three changed repair files only: sandboxed_web_e2e.py, its tests, and the CodeQL audit clock tests. The prior sandbox candidate was rejected by independent security review; two RED/GREEN repair cycles reject external executable symlinks, internal symlink plus dotdot traversal, and home/bind-root overlap while retaining legitimate workspace and relative PATH controls. The final independent re-review found no security/logic findings across 23 construction-only probes; its full targeted test run passed 117 with zero skips/deselections. Parent combined Gyeot/clock/sandbox run passed 219 with zero skips. This is local source review, NOT live bubblewrap isolation, model inference, GitHub App APPROVED review, or a green full gate.

Final source hashes: sandbox runtime d6de19ccca907e3c98af0cd09be399a0d0dacaf97e9bbac0c06298c824115303; sandbox tests 2e1a44e7358a365753917c4c4fa430bcf9252d1b8d14145d6b8a66f4124e860e; clock tests c49cb17c53dd780995a22599c582d764dc1d61f3620e314903a42e50e359b081.

Full post-repair exact-head local acceptance is now running with durable logs/JUnit and independent coverage/interrogate exits; no result yet. Earlier complete execution: 5260 passed, 7 failed, 4 skipped plus 40 passing subtests. Full gate remains unpassed; documented clock and sandbox failures are repaired but inherited coverage/docstrings still require #2572. Shared label/group admission is owned by #2565; existing clock fixture owner #2609 is preserved and not closed. GYEOT_HELPER_COMMIT sentinel remains intentional pending protected helper publication. Dedicated runner capacity and effective auto/LiteLLM review plus substantive independent App approval remain separate prerequisites. Draft/HOLD is unchanged.

@seonghobae

Copy link
Copy Markdown
Contributor Author

Post-repair full local acceptance result — October 9, 2026 KST

Exact head: 87a371a.

Completed source-stable full test run:

  • tests: 5,330 tests collected/executed, 0 failures, 0 errors, 4 skips; exit 0; JUnit/log retained.
  • coverage report: exit 2, total 99%, below the fixed 100% threshold. Missing lines remain inherited shared-gate scope, including opencode_queue_priority, place_maturin_extension, resolve_base_rust_toolchain, strix_report_scope, strix_unverified_dependency and others.
  • interrogate: exit 1, actual 97.1%, below the fixed 100% threshold.
  • source stability: true; working tree clean before/after; reviewed source hashes unchanged.

Evidence paths in the local runner:

  • /Users/seonghobae/.hermes/cache/scratch/gyeot-post-repair-20261009/receipt.json
  • /Users/seonghobae/.hermes/cache/scratch/gyeot-post-repair-20261009/tests.log
  • /Users/seonghobae/.hermes/cache/scratch/gyeot-post-repair-20261009/full.xml
  • /Users/seonghobae/.hermes/cache/scratch/gyeot-post-repair-20261009/coverage.log
  • /Users/seonghobae/.hermes/cache/scratch/gyeot-post-repair-20261009/interrogate.log

Verdict: full central gate is still NOT GREEN. The repaired Gyeot/clock/sandbox source now clears the full pytest leg, but inherited coverage/docstring gates remain blockers under #2572 ownership, and Gyeot runner label/group admission remains under #2565 ownership. GitHub Code Quality is still a billing-lock start failure, not a source failure. Draft/HOLD remains unchanged; no approval, merge, runner provisioning, helper pin publication, or protection bypass is claimed.

@seonghobae

Copy link
Copy Markdown
Contributor Author

Shared-policy dependency is now a reviewed, published stacked Draft ContextualWisdomLab/.github#2613 at exact head 67726a07d292beed8f6138619dff1066228b2b11, based on global owner #2565 exact ef65b2fdc2036ccaca8d19c1db88dc8075ae9164. It adds only Gyeot runner group/label admission and keeps the dedicated CWL Gyeot CI selector. Normal protected publication, isolated runner provisioning/canary and helper-pin adoption are separate gates. Current #2611 head remains 87a371a7783fa16f6988c9c98da8e5eb5820eae7 Draft; no actual Gyeot runner jobs or substantive App review yet.

@seonghobae

Copy link
Copy Markdown
Contributor Author

Exact-source inherited quality combination — verified October 9 KST

I independently checked the retained private no-commit merge of this PR head 87a371a7783fa16f6988c9c98da8e5eb5820eae7 with existing inherited quality owner #2572 head b37356d5c5180d29638302308a4ff2ea0df613c1. Merge exit0, conflict0, index tree 152d8668f72016293928c22fbbc177bf3da18fe8. All ten Gyeot PR files and reviewed sandbox/UTC bytes remain identical. I verified all 28 artifact hashes, source before/after hashes, actual tool exits, JUnit, coverage JSON and interrogate log. Python3.14.5 full suite: 5,405 passed, 4 skipped, 40 subtests passed; statements18,280/18,280 and branches7,506/7,506 (100%, coverage exit0), docstrings1,473/1,473 (100%, interrogate exit0). Four skips (two unconfigured HWP/HWPX fixtures, LLVM19 unavailable, GNU find -printf unavailable) and one ResourceWarning remain explicit.

Receipt: /Users/seonghobae/.hermes/cache/scratch/gyeot-2572-private-accept-20261009/REPORT.ko.md and FINAL-MANIFEST.json on local host. This is private macOS integration evidence only: current #2611 head itself still has 99% coverage/97.1% docstrings; owner #2572 must reach protected integration, and current-head self-hosted/required checks, key-backed auto inference, App approval and runner canary still need real execution. I did not cherry-pick owner security changes or lower 100% gates. No private merge commit or GitHub branch update.

@seonghobae

Copy link
Copy Markdown
Contributor Author

Independent integration review PASS; distinct remote failures

Frozen current source dc59db2 / tree152d8668f72016293928c22fbbc177bf3da18fe8 independently passed integration review. All52incoming files match qualityowner and all17retained changed files match Gyeot parent; sets disjoint. Runtime/security/lock composition seams inspected, bounded42dependency/download+12releaseadmission cases passed0skip. This is source review only, not qualifying GitHub App approval or native/runtime proof.

Fresh GraphQL exact-head annotations distinguish two failures:

  • Analyze javascript-typescript job113856227419: NOT_STARTED because account billing lock.
  • noema-review job113858314104: CreateArtifact failed because artifact storage quota exhausted; model review was skipped BEFORE sidecar because PR is Draft. Annotation also records intended repository-scoped cwl-noema-review App token selection, not actual substantive review/approval.

Do not classify quota as source regression, inference failure or App approval. No unchanged rerun, artifact deletion, spending/billing/protection/credential mutation. REST quota hit too; authenticated GraphQL provided these annotations. Draft remains pending actual helperpin/runner integration and deployment gates.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant