Repository navigation
test(analysis): govern real YouTube known-stem benchmark - #828
seonghobae wants to merge 47 commits into
Conversation
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueNote Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (33)
💤 Files with no reviewable changes (1)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughBandScope는 로컬 ChangesBandScope 검증 및 런타임
문서·공급망·개발 도구
저장소 정책과 리뷰 거버넌스
Priority: ⬆️ High Estimated code review effort: 5 (Critical) | ~120 minutes Change: Feature · Severity of issue fixed: High Sequence Diagram(s)sequenceDiagram
participant YouTube
participant download_youtube_audio
participant AudioStemSeparator
participant htdemucs
participant known_stem_benchmark
YouTube->>download_youtube_audio: HTTPS audio download
download_youtube_audio->>download_youtube_audio: validate URL, path, TLS, and media tools
download_youtube_audio->>known_stem_benchmark: provide validated temporary audio
known_stem_benchmark->>AudioStemSeparator: aligned 12-second window
AudioStemSeparator->>htdemucs: load verified local artifact and infer with shifts=0
htdemucs-->>AudioStemSeparator: vocals, bass, drums, other
AudioStemSeparator-->>known_stem_benchmark: separated stems
known_stem_benchmark->>known_stem_benchmark: calculate SI-SDR and assignment margin
Merge Risk: ⚪ Minimal · up to The changelog entries record inherited features and should remain. No actionable issue identified here prevents merging this benchmark slice, but it does not qualify a model or establish a passing live quality result. Security Architecture ReviewSecurity architecture risk: 🟡 Moderate · up to Previously saved results may be reused after the processing method changes, and a verification failure can still lead to a successful analysis with fallback cues. The available evidence does not establish broader deployment exposure. Retained concerns
Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 2 | ❌ 3❌ Failed checks (3 warnings)
✅ Passed checks (2 passed)
Full details: Linked Issues checkExplanation 직접 연결된 Resolution
Full details: Out of Scope Changes checkExplanation 모델 무결성 검사, 로컬 로더, YouTube 입력 경계, 관련 테스트와 문서는 Full details: Docstring CoverageExplanation Docstring coverage is 78.25% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 354 functions across 30 files. (13 skipped: 13 unsupported.) ✨ Finishing Touches 💡 2📝 Generate docstrings 💡
⚔️ Resolve merge conflicts 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 14
🧹 Nitpick comments (3)
supply-chain/supplemental-component-inventory.json (1)
7-7: 📐 Maintainability & Code Quality | 🔵 Trivial | 💤 Low value
yt-dlp버전을 범위가 아닌 정확한 값으로 기록하는 방안을 검토하십시오.
">=2026.7.4"는 상한이 없는 범위입니다. 43행 notes는 모든 아티팩트에 대해 version 추적을 요구합니다. 재현 가능한 빌드와 SBOM 대조에는 정확한 해석 버전이 더 유용합니다.uv.lock에서 해석된 정확한 버전을 기록하고, 하한 요구사항은 별도 필드로 두는 방안을 검토하십시오.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@supply-chain/supplemental-component-inventory.json` at line 7, Update the yt-dlp component entry in supplemental-component-inventory.json to record the exact resolved version from uv.lock instead of the open-ended “>=2026.7.4” range. Preserve the minimum-version requirement in a separate field if the inventory schema supports it, while keeping the artifact’s version field exact for reproducible SBOM comparison.services/analysis-engine/tests/test_youtube_stem_e2e.py (1)
319-324: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win러너 검사가 정확한 공백과 줄바꿈에 의존합니다.
324행은
scripts/checks/run_root_tests.mjs의 원본 텍스트에서'"-m",\n "not youtube_stem_e2e"'를 찾습니다. 이 검사는 2칸 들여쓰기와 특정 줄바꿈 위치를 전제합니다. 포매터가 배열 요소를 한 줄로 합치거나 들여쓰기를 바꾸면, 정책이 그대로여도 테스트가 실패합니다.공백에 둔감한 검사로 바꾸십시오.
♻️ 공백에 둔감한 검사로 변경하는 예시
- assert '"-m",\n "not youtube_stem_e2e"' in runner + normalized = " ".join(runner.split()) + assert '"-m", "not youtube_stem_e2e"' in normalized🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@services/analysis-engine/tests/test_youtube_stem_e2e.py` around lines 319 - 324, Update test_required_root_suite_explicitly_excludes_live_youtube_marker to validate the runner’s exclusion policy without relying on exact whitespace or line breaks; normalize the runner text or use a whitespace-tolerant pattern while still requiring the "-m" option and "not youtube_stem_e2e" marker.services/analysis-engine/tests/known_stem_benchmark.py (1)
250-261: 🎯 Functional Correctness | 🔵 Trivial | 💤 Low value거친 정렬과 정밀 정렬의 상관 부호 처리가 다릅니다.
250-260행의 거친 단계는
coarse_correlation[valid_coarse]의 최대값을 부호 그대로 선택합니다. 287행의 정밀 단계는np.abs(...)의 최대값을 선택합니다. 290행_normalized_correlation도 절댓값을 반환합니다.이 차이 때문에 정밀 단계는 위상이 반전된 정렬 위치를 최적으로 선택할 수 있습니다. 그 결과
identity_correlation이 높게 나와도 신호가 반전 상태일 수 있습니다. 정체성 검증 용도에서는 부호를 무시하는 것이 의도인지 확인하십시오.의도가 "동일 녹음 확인"이라면 정밀 단계도 부호 있는 최대값을 사용하는 편이 일관됩니다.
♻️ 부호 처리를 일치시키는 변경 예시
- best_refined_index = int(valid_refined[np.argmax(np.abs(refined_correlation[valid_refined]))]) + best_refined_index = int(valid_refined[np.argmax(refined_correlation[valid_refined])])Also applies to: 287-290
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@services/analysis-engine/tests/known_stem_benchmark.py` around lines 250 - 261, Align the correlation sign handling in the coarse and fine alignment stages: update the fine-stage selection around _normalized_correlation and the logic at lines 287-290 to choose the maximum signed correlation rather than the maximum absolute value. Preserve the existing lag search and ensure identity validation cannot prefer phase-inverted matches.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@ARCHITECTURE.md`:
- Around line 96-102: AudioStemSeparator._load_model에서
demucs.pretrained.get_model() 호출 전에 지정된 모델 캐시/아티팩트의 바이트 크기와 전체 SHA-256을 검증하고, 누락
또는 불일치 시 torch 역직렬화 전에 closed 상태로 실패하게 하십시오. 검증용 다운로드 경로를 제공하거나 htdemucs 캐시가 없으면
로드를 거부하고, supply-chain/supplemental-component-inventory.json의 메타데이터와 실제 검증값을
일치시키십시오. ARCHITECTURE.md 96-102, CLAUDE.md 61-64, docs/TRD.md 78-84,
docs/engineering/youtube-known-stem-validation.md 73-82,
docs/operations/deploy-runbook.md 35-36의 설명을 이 실제 로드 경계 동작 및 release blocker 정책에
맞게 갱신하십시오.
In `@docs/architecture/diagrams.md`:
- Around line 144-148: Update the Mermaid relationship between REFERENCE_ARCHIVE
and REFERENCE_STEM to use one-to-many cardinality, changing the current ||--||
association to ||--|{ so an archive can contain multiple extracted members while
preserving the existing diagram entities.
- Around line 130-134: Update the deployment diagram around the YouTube,
archive, master, model, App, and Evidence nodes by adding a KnownStemBenchmark
opt-in validation boundary. Route YouTube, Pinned creator archive, Pinned
creator master, and bounded numeric evidence through KnownStemBenchmark instead
of connecting them directly to App; keep App as the local runtime, and show
model provisioning separately without adding network dependencies to the
React/Tauri, Rust, or Python runtime layers.
In `@docs/architecture/overview.md`:
- Around line 48-50: Update the known-stem validation description in the
architecture overview to replace “proves” with wording such as “defines and
exercises,” and explicitly state that no live passing run currently validates
the complete YouTube intake through SI-SDR scoring path. Preserve the
distinction between offline deterministic-component coverage and unverified
production behavior.
In `@docs/documentation-coverage-matrix.md`:
- Around line 56-57: Clarify the “13 passed” entry in the documentation-coverage
matrix by identifying it as a historical partial suite and specifying which
deterministic known-stem contract cases were missing or expected failures
relative to the documented 16-test baseline. Add a reference to the execution
command or case manifest used so the result is traceable, while preserving the
separate 16-test standard.
In `@docs/engineering/acceptance-criteria.md`:
- Around line 60-61: Update the release-blocker criteria in the acceptance
criteria entry to explicitly require closure of the model-rights/legal decision
before a release can be blocked or passed. Add this requirement alongside the
existing ADR-0001/0002 blockers without removing the authorization,
verification, candidate, calibration, or platform-evidence conditions.
In `@docs/PRD.md`:
- Around line 13-15: Update the BandScope proof-obligation text in PRD.md to
state the requirement directly, without referring to the current conversation or
other external context. Describe that production YouTube intake and the
production separator must demonstrate improvement on a real, known source rather
than merely returning plausible arrays or synthetic output, and reference the
relevant repository Issue or ADR.
In `@docs/repository/bootstrap-plan.md`:
- Around line 20-21: Align the protected-check lists in
docs/repository/bootstrap-plan.md lines 20-21 and
docs/workflow/github-bootstrap-execution-policy.md lines 90-92 with the
canonical list in docs/security/github-required-checks.md by adding
trivy-fs-scan or directly referencing the canonical document at both sites; do
not weaken the required CI and security gates.
In `@docs/TRD.md`:
- Around line 86-88: Define an allowlisted executable policy in docs/TRD.md:
release evidence must use a verified absolute ffmpeg path rather than an
operator-provided PATH resolution, record its file hash or trusted package
source, and reject evidence when identity verification fails. Update
docs/engineering/youtube-known-stem-validation.md lines 73-75 so the benchmark
invokes that verified absolute path. Update docs/operations/deploy-runbook.md
lines 31-32 to record the executable path and file identity alongside ffmpeg
-version; yt-dlp remains a locked Python package and neither dependency should
be described as bundled.
In `@scripts/checks/verify_docs.py`:
- Around line 99-110: Update documentation_violations to recursively inspect
every Markdown file under docs/plans, independently of REQUIRED_REFERENCES, and
append a violation for each file lacking a “Security Notes” section while
preserving existing checks. Add a regression test covering a newly discovered
plan document without that section and asserting the violation is reported.
In `@scripts/checks/verify_supply_chain.py`:
- Around line 81-123: Strengthen the inventory validation around the function
handling supplemental inventory: first require the top-level inventory to be a
dictionary before calling get, then strictly validate required model-artifact
fields for presence, non-empty values, and expected types. Reject booleans as
sizeBytes by checking for an actual integer, while preserving positive-size
validation; also add regression tests covering an empty modelArtifacts list,
array-valued inventories, sizeBytes=true, and invalid or empty required-field
values.
In `@services/analysis-engine/src/bandscope_analysis/youtube.py`:
- Around line 146-148: Ensure the YouTube download configuration using
compat_opts explicitly supports environments with unavailable or unconfigured
system CA stores. Preserve the valid no-certifi option for OS-managed trust,
while documenting or enforcing CA availability for target CI/container
environments and validating a certifi fallback path where needed.
In `@services/analysis-engine/tests/known_stem_benchmark.py`:
- Around line 237-246: 추가된 align_active_reference_window 검증 분기를 직접 호출하는 테스트를
작성하십시오. sample_rate, alignment durations, alignment resolution, 참조 신호보다 긴
scoring window, 허용 lag 없음, 전체 scoring window 생성 불가 조합마다 ValueError를 검증하고, 각 오류
메시지와 해당 입력 조건을 명시적으로 확인하여 100% 분기 커버리지를 확보하십시오.
In `@services/analysis-engine/tests/test_youtube_stem_e2e.py`:
- Around line 327-422: known_stem_benchmark.py의 align_active_reference_window()
입력 검증 및 lag 탐색 분기가 커버되지 않았습니다.
services/analysis-engine/tests/known_stem_benchmark.py:237-286에 sample_rate <=
0, 잘못된 duration/refinement, scoring window보다 짧은 reference, 허용된 coarse lag 부재,
refinement 전체 조회에서 유효한 refined lag 부재를 각각 검증하는 테스트를 추가하거나 해당 테스트 모듈을 coverage
source에 포함하십시오. services/analysis-engine/tests/test_youtube_stem_e2e.py:327-422는
이 변경으로 직접 수정할 필요가 없습니다.
---
Nitpick comments:
In `@services/analysis-engine/tests/known_stem_benchmark.py`:
- Around line 250-261: Align the correlation sign handling in the coarse and
fine alignment stages: update the fine-stage selection around
_normalized_correlation and the logic at lines 287-290 to choose the maximum
signed correlation rather than the maximum absolute value. Preserve the existing
lag search and ensure identity validation cannot prefer phase-inverted matches.
In `@services/analysis-engine/tests/test_youtube_stem_e2e.py`:
- Around line 319-324: Update
test_required_root_suite_explicitly_excludes_live_youtube_marker to validate the
runner’s exclusion policy without relying on exact whitespace or line breaks;
normalize the runner text or use a whitespace-tolerant pattern while still
requiring the "-m" option and "not youtube_stem_e2e" marker.
In `@supply-chain/supplemental-component-inventory.json`:
- Line 7: Update the yt-dlp component entry in
supplemental-component-inventory.json to record the exact resolved version from
uv.lock instead of the open-ended “>=2026.7.4” range. Preserve the
minimum-version requirement in a separate field if the inventory schema supports
it, while keeping the artifact’s version field exact for reproducible SBOM
comparison.
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro Plus
Run ID: 0f8ca180-cf33-4f83-90f4-acbf593cccb3
📒 Files selected for processing (43)
AGENTS.mdARCHITECTURE.mdCHANGELOG.mdCLAUDE.mdCONTRIBUTING.mdREADME.mddocs/PRD.mddocs/README.mddocs/TRD.mddocs/adr/0001-source-separation-runtime-and-model-delivery.mddocs/adr/0002-known-stem-youtube-quality-gate.mddocs/adr/0003-ephemeral-benchmark-evidence-model.mddocs/adr/README.mddocs/architecture/diagrams.mddocs/architecture/overview.mddocs/doctoring/real-audio-accuracy-acceptance.mddocs/documentation-coverage-matrix.mddocs/engineering/acceptance-criteria.mddocs/engineering/harness-engineering.mddocs/engineering/youtube-known-stem-validation.mddocs/operations/deploy-runbook.mddocs/plans/2026-03-28-ml-engine-integration.mddocs/release/release-policy.mddocs/repository/bootstrap-plan.mddocs/repository/gitflow.mddocs/repository/governance.mddocs/security/dependency-policy.mddocs/security/github-required-checks.mddocs/workflow/github-bootstrap-execution-policy.mdscripts/checks/run_root_tests.mjsscripts/checks/verify_docs.pyscripts/checks/verify_supply_chain.pyservices/analysis-engine/pyproject.tomlservices/analysis-engine/src/bandscope_analysis/separation/audio_separator.pyservices/analysis-engine/src/bandscope_analysis/separation/model_weights/bandsplit-v1.jsonservices/analysis-engine/src/bandscope_analysis/youtube.pyservices/analysis-engine/tests/known_stem_benchmark.pyservices/analysis-engine/tests/test_documentation_policy.pyservices/analysis-engine/tests/test_separation.pyservices/analysis-engine/tests/test_supply_chain_policy.pyservices/analysis-engine/tests/test_youtube.pyservices/analysis-engine/tests/test_youtube_stem_e2e.pysupply-chain/supplemental-component-inventory.json
💤 Files with no reviewable changes (1)
- services/analysis-engine/src/bandscope_analysis/separation/model_weights/bandsplit-v1.json
|
@coderabbitai review Please review the current exact head |
|
✅ Action performedReview finished.
|
There was a problem hiding this comment.
Actionable comments posted: 5
♻️ Duplicate comments (1)
scripts/checks/verify_supply_chain.py (1)
80-140: 🔒 Security & Privacy | 🟠 Major | ⚡ Quick win인벤토리와 런타임 모델 식별자를 비교하십시오.
Line 80-83은 런타임 모델 이름만 읽습니다. Line 120-139은
checksum과sizeBytes의 형식만 확인합니다. 따라서 다른 유효 SHA-256과 양수 크기를 가진htdemucs인벤토리도 통과합니다.인벤토리의 SHA-256 및 바이트 수를
audio_separator.py의_HTDEMUCS_MODEL_SHA256및_HTDEMUCS_MODEL_BYTES와 비교하십시오. 스키마에 파일명이 있으면_HTDEMUCS_MODEL_FILENAME도 비교하십시오. 유효한 형식이지만 값이 다른 인벤토리를 거부하는 테스트를 추가하십시오.이 문제는 이전 모델 인벤토리와 런타임 검증 계약 지적과 같은 근본 원인입니다.
As per coding guidelines, "Treat files, URLs, metadata, model artifacts, and project files as untrusted input" 및 "strict schema validation" 요구를 적용했습니다.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@scripts/checks/verify_supply_chain.py` around lines 80 - 140, Update the supplemental inventory validation around the runtime artifact checks to compare checksum and sizeBytes against audio_separator.py’s _HTDEMUCS_MODEL_SHA256 and _HTDEMUCS_MODEL_BYTES, rejecting values that are valid in format but do not match. If the artifact schema includes a filename field, also require it to match _HTDEMUCS_MODEL_FILENAME. Add tests covering mismatched checksum and size values for an otherwise valid htdemucs artifact.Source: Coding guidelines
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@apps/desktop/package.json`:
- Line 23: Update the pull request description for the pdfjs-dist 6.2.108 change
by adding a Security Notes section covering the desktop PDF attack surface,
trust boundary, mitigations, verification or test points, dependency and
supply-chain impact, and any i18n impact.
In `@CHANGELOG.md`:
- Around line 21-28: CHANGELOG.md must document the required security evidence
for these changes. Add a Security Notes section covering attack surfaces, trust
boundaries, mitigations, test points, dependency and supply-chain impact, and
i18n impact; also include the result of running ./scripts/harness/quickcheck.sh
before claiming completion.
- Around line 25-28: Update AudioStemSeparator failure handling and the
_stem_separation_failure() mapping so missing or invalid local htdemucs
artifacts that raise ValueError are classified as FAILED, not BLOCKED. Preserve
BLOCKED for operator authorization, authentication, or network-related failures,
and return the appropriate failed classification/API response for both
missing-file and invalid-artifact cases.
In
`@services/analysis-engine/src/bandscope_analysis/separation/audio_separator.py`:
- Around line 180-203: Update the model artifact validation flow around
configured and artifact_path so expanduser() runs before the symlink check,
ensuring paths such as ~/model-link are rejected with ValueError before
resolve(). Add a regression test covering a tilde-based path that points
directly to a symlink, while preserving the existing artifact filename, size,
and SHA-256 validation.
In `@services/analysis-engine/tests/test_separation.py`:
- Around line 373-396: Update AudioStemSeparator._verified_model_artifact_path()
to call expanduser() before checking is_symlink(), ensuring user-relative paths
cannot bypass symlink rejection before resolve(). Extend
test_audio_stem_separator_rejects_untrusted_model_path_shapes with a regression
case using a ~/... configured path that resolves to a symlink, and verify it
raises the existing “model artifact” ValueError.
---
Duplicate comments:
In `@scripts/checks/verify_supply_chain.py`:
- Around line 80-140: Update the supplemental inventory validation around the
runtime artifact checks to compare checksum and sizeBytes against
audio_separator.py’s _HTDEMUCS_MODEL_SHA256 and _HTDEMUCS_MODEL_BYTES, rejecting
values that are valid in format but do not match. If the artifact schema
includes a filename field, also require it to match _HTDEMUCS_MODEL_FILENAME.
Add tests covering mismatched checksum and size values for an otherwise valid
htdemucs artifact.
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro Plus
Run ID: dc829a52-8d24-4146-923e-44d6c970c772
⛔ Files ignored due to path filters (1)
package-lock.jsonis excluded by!**/package-lock.json
📒 Files selected for processing (30)
ARCHITECTURE.mdCHANGELOG.mdCLAUDE.mdapps/desktop/package.jsondocs/PRD.mddocs/TRD.mddocs/adr/0001-source-separation-runtime-and-model-delivery.mddocs/adr/README.mddocs/architecture/diagrams.mddocs/architecture/overview.mddocs/documentation-coverage-matrix.mddocs/engineering/acceptance-criteria.mddocs/engineering/youtube-known-stem-validation.mddocs/operations/deploy-runbook.mddocs/plans/2026-03-28-ml-engine-integration.mddocs/repository/bootstrap-plan.mddocs/workflow/github-bootstrap-execution-policy.mdscripts/checks/verify_docs.pyscripts/checks/verify_supply_chain.pyservices/analysis-engine/src/bandscope_analysis/api.pyservices/analysis-engine/src/bandscope_analysis/separation/audio_separator.pyservices/analysis-engine/src/bandscope_analysis/youtube.pyservices/analysis-engine/tests/known_stem_benchmark.pyservices/analysis-engine/tests/test_api.pyservices/analysis-engine/tests/test_documentation_policy.pyservices/analysis-engine/tests/test_separation.pyservices/analysis-engine/tests/test_supply_chain_policy.pyservices/analysis-engine/tests/test_youtube.pyservices/analysis-engine/tests/test_youtube_stem_e2e.pysupply-chain/supplemental-component-inventory.json
🚧 Files skipped from review as they are similar to previous changes (17)
- services/analysis-engine/tests/test_documentation_policy.py
- docs/workflow/github-bootstrap-execution-policy.md
- docs/adr/README.md
- docs/repository/bootstrap-plan.md
- scripts/checks/verify_docs.py
- docs/operations/deploy-runbook.md
- docs/PRD.md
- docs/documentation-coverage-matrix.md
- docs/architecture/overview.md
- docs/plans/2026-03-28-ml-engine-integration.md
- docs/engineering/acceptance-criteria.md
- supply-chain/supplemental-component-inventory.json
- docs/adr/0001-source-separation-runtime-and-model-delivery.md
- CLAUDE.md
- docs/TRD.md
- services/analysis-engine/tests/test_youtube_stem_e2e.py
- services/analysis-engine/tests/known_stem_benchmark.py
Exact-head handoff — 2026-08-10PR #828 is published at:
The remote tree is byte-identical to the frozen locally audited tree. OutcomeThe bounded known-vocal YouTube sentinel is now design-sufficient, not release-ready. The canonical graph includes 11 PRD requirements, 13 TRD requirements, three ADRs, root/discoverable Architecture, sequence/state/deployment/class UML, a schema-v1 logical run/evidence aggregate, explicit physical-ERD non-applicability, and 13 complete machine-checked requirement-to-evidence rows. The evidence contract now resolves the prior contradictions:
Local exact-tree verification
Honest live boundaryHistorical production YouTube intake failed closed with HTTP 502 after 65.49 s, before separation. It produced no identity correlation or SI-SDR score. Creator-master-only calibration (+1.752 dB SI-SDRi, +7.631 dB margin) is not a YouTube pass. Still blocking release/mergeProduct release remains blocked by formal authorization, model rights/delivery, exact-checkpoint approved-pickle risk acceptance or non-pickle replacement, authorized YouTube calibration/pass, accepted retention controls plus schema-v1 emitter/artifact, per-advertised-platform evidence, planned failure UX, and broader #770 coverage. Merge additionally waits for unchanged-head hosted workflows and qualifying exact-head independent review. The PR intentionally remains open and unmerged. |
|
@coderabbitai review Please review the current exact head |
|
I will focus on the restricted ✅ Action performedReview finished.
|
There was a problem hiding this comment.
Actionable comments posted: 3
🧹 Nitpick comments (5)
CHANGELOG.md (1)
24-25: 🔒 Security & Privacy | 🔵 Trivial | ⚡ Quick win패치된 버전의 변경 내역을 고정된 출처로 기록하세요.
changeset의 현재 변경 내용에는pdfjs-dist,nanoid,undici의 advisory ID, 이전·이후 버전, lockfile/SBOM 근거가 없습니다.CHANGELOG.md항목에GHSA-/CVE-ID와 해당 패키지의 고정된 패치 버전 또는 lockfile/SBOM 감사 출력을 추가하세요.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@CHANGELOG.md` around lines 24 - 25, Update the changelog entry describing the patched pdfjs-dist, nanoid, and undici versions to include each applicable GHSA or CVE advisory ID, the previous and fixed package versions, and immutable lockfile or SBOM audit evidence. Keep the existing security-update summary while recording these concrete provenance details in CHANGELOG.md.Source: Coding guidelines
services/analysis-engine/tests/test_youtube.py (1)
339-342: 📐 Maintainability & Code Quality | 🔵 Trivial | 💤 Low value전역
os.access대신 대상 모듈 속성을 패치하십시오.현재 패치는 stdlib
os모듈 전역을 교체합니다. 같은 테스트 실행 중 pytest 내부나 다른 헬퍼가os.access를 호출하면 예기치 않은 결과를 받습니다. 검증 경계인bandscope_analysis.youtube.os.access로 범위를 좁히십시오.♻️ 제안 수정
ffmpeg = tmp_path / "ffmpeg" ffmpeg.write_bytes(b"not executable") - monkeypatch.setattr(os, "access", lambda *_args: False) + monkeypatch.setattr( + "bandscope_analysis.youtube.os.access", + lambda *_args, **_kwargs: False, + )🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@services/analysis-engine/tests/test_youtube.py` around lines 339 - 342, Update the monkeypatch in the test’s non-executable ffmpeg branch to target bandscope_analysis.youtube.os.access instead of the global os.access attribute. Keep the lambda behavior returning False unchanged, while limiting the patch to the module under test.services/analysis-engine/tests/test_supply_chain_policy.py (1)
285-293: 🚀 Performance & Scalability | 🔵 Trivial | 💤 Low value저장소 전체 순회 테스트의 실행 비용을 확인하세요.
security_pattern_violations(repo_root)는repo_root.rglob("*")로 모든 항목을 순회합니다.EXCLUDED_PARTS는 스캔 대상만 걸러내고 디렉터리 순회 자체는 막지 않습니다.node_modules,target,.venv가 존재하는 개발 환경에서는 이 테스트 하나가 수만 개 경로를 방문합니다.
security_pattern_violations에서 제외 디렉터리를 순회 단계에서 잘라내면 이 테스트와 실제 게이트 실행 모두 빨라집니다.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@services/analysis-engine/tests/test_supply_chain_policy.py` around lines 285 - 293, Update security_pattern_violations to prune directories listed in EXCLUDED_PARTS during traversal, rather than filtering them only after repo_root.rglob("*") yields paths. Preserve scanning of all non-excluded files and directories while preventing descent into excluded trees such as node_modules, target, and .venv.scripts/checks/verify_supply_chain.py (1)
115-118: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick win
analysis_lock_path기본값이inventory_path위치에 암묵적으로 결속됩니다.기본값은
inventory_path.resolve().parent.parent를 저장소 루트로 가정합니다. 이 가정은 인벤토리가supply-chain/바로 아래에 있을 때만 성립합니다. 호출자가 다른 위치의 인벤토리를 전달하면 잘못된 경로를 읽고analysis lock is unreadable위반이 발생합니다.services/analysis-engine/tests/test_supply_chain_policy.py의tmp_path기반 테스트가 이미 이 상태에 해당하며, 해당 테스트는 특정 문자열만 확인하므로 잉여 위반이 조용히 섞입니다.저장소 루트를 파일 위치에서 직접 유도하세요.
♻️ 제안 수정
if analysis_lock_path is None: - analysis_lock_path = ( - inventory_path.resolve().parent.parent / ANALYSIS_LOCK_PATH - ) + analysis_lock_path = REPO_ROOT / ANALYSIS_LOCK_PATH
REPO_ROOT = Path(__file__).resolve().parents[2]를 모듈 상수로 추가하세요.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@scripts/checks/verify_supply_chain.py` around lines 115 - 118, Update the default analysis_lock_path resolution in the surrounding verification flow to derive the repository root from the script location, not inventory_path; add the REPO_ROOT module constant using Path(__file__).resolve().parents[2] and use it when analysis_lock_path is None.scripts/checks/security_gates.py (1)
42-77: 📐 Maintainability & Code Quality | 🔵 Trivial | 💤 Low value예외 규칙이 로더 소스의 정확한 문자열 스냅샷에 결속되어 있습니다.
VERIFIED_MODEL_SAFE_GLOBALS_DEFINITION은audio_separator.py의 함수 본문을 공백과 줄바꿈까지 포함해 복제합니다.VERIFIED_TORCH_LOAD_CALL도 주석 문구와 줄 배치를 고정합니다. 포매터 설정, 줄 길이, 주석 문구가 바뀌면 예외가 사라지고 게이트는 무해한 변경에도 실패합니다.이 결속은 의도된 fail-closed 동작이므로 지금은 안전합니다. 다만 실패 메시지가 원인을 설명하지 않습니다. 스냅샷 불일치 시 별도 진단 메시지를 추가하면 유지보수 비용이 줄어듭니다.
♻️ 진단 메시지 추가 예시
def _content_for_pattern_scan(relative_path: Path, content: str) -> str: """Remove only the one fully constrained checkpoint-deserialization call.""" if relative_path != VERIFIED_MODEL_LOADER_PATH: return content
security_pattern_violations()에서 이 파일이 위반으로 보고될 때, 스냅샷 상수 중 어떤 항목이 불일치했는지 함께 출력하도록 확장하세요.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@scripts/checks/security_gates.py` around lines 42 - 77, Update security_pattern_violations() to include a diagnostic identifying which snapshot validation failed when this file is reported as a violation. Distinguish mismatches for VERIFIED_MODEL_SAFE_GLOBALS_DEFINITION, VERIFIED_TORCH_LOAD_CALL, and VERIFIED_MODEL_LOADER_PREREQUISITES while preserving the existing fail-closed validation behavior.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@CHANGELOG.md`:
- Around line 20-33: Under [Unreleased] in CHANGELOG.md, add a Security Notes
section documenting the security evidence for the changes listed in the Fixed
section: untrusted YouTube inputs and model artifacts, TLS and ffmpeg/ffprobe
trust boundaries and allowlists, fail-closed validation behavior, logging and
privacy impact, security verification tests, and dependency/supply-chain
verification scope.
In `@scripts/checks/verify_security_notes.py`:
- Around line 18-31: Update security_notes_section to locate the heading with
the same SECURITY_NOTES_PATTERN contract used by documentation_violations,
allowing trailing whitespace, and return an empty string when absent. Track
fenced code blocks with FENCE_PATTERN while scanning, and only apply
HEADING_PATTERN as the section terminator outside fences; preserve the existing
section extraction and lowercasing behavior.
In
`@services/analysis-engine/src/bandscope_analysis/separation/audio_separator.py`:
- Around line 38-40: Update the _numpy_scalar import in audio_separator.py to
use the NumPy 2.x-compatible numpy._core.multiarray path instead of
numpy.core.multiarray, while preserving the existing scalar alias and behavior.
---
Nitpick comments:
In `@CHANGELOG.md`:
- Around line 24-25: Update the changelog entry describing the patched
pdfjs-dist, nanoid, and undici versions to include each applicable GHSA or CVE
advisory ID, the previous and fixed package versions, and immutable lockfile or
SBOM audit evidence. Keep the existing security-update summary while recording
these concrete provenance details in CHANGELOG.md.
In `@scripts/checks/security_gates.py`:
- Around line 42-77: Update security_pattern_violations() to include a
diagnostic identifying which snapshot validation failed when this file is
reported as a violation. Distinguish mismatches for
VERIFIED_MODEL_SAFE_GLOBALS_DEFINITION, VERIFIED_TORCH_LOAD_CALL, and
VERIFIED_MODEL_LOADER_PREREQUISITES while preserving the existing fail-closed
validation behavior.
In `@scripts/checks/verify_supply_chain.py`:
- Around line 115-118: Update the default analysis_lock_path resolution in the
surrounding verification flow to derive the repository root from the script
location, not inventory_path; add the REPO_ROOT module constant using
Path(__file__).resolve().parents[2] and use it when analysis_lock_path is None.
In `@services/analysis-engine/tests/test_supply_chain_policy.py`:
- Around line 285-293: Update security_pattern_violations to prune directories
listed in EXCLUDED_PARTS during traversal, rather than filtering them only after
repo_root.rglob("*") yields paths. Preserve scanning of all non-excluded files
and directories while preventing descent into excluded trees such as
node_modules, target, and .venv.
In `@services/analysis-engine/tests/test_youtube.py`:
- Around line 339-342: Update the monkeypatch in the test’s non-executable
ffmpeg branch to target bandscope_analysis.youtube.os.access instead of the
global os.access attribute. Keep the lambda behavior returning False unchanged,
while limiting the patch to the module under test.
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro Plus
Run ID: cbed67a7-5530-4015-b6c8-7569e46dce82
📒 Files selected for processing (43)
ARCHITECTURE.mdCHANGELOG.mdCLAUDE.mddocs/PRD.mddocs/TRD.mddocs/adr/0001-source-separation-runtime-and-model-delivery.mddocs/adr/0002-known-stem-youtube-quality-gate.mddocs/adr/README.mddocs/architecture/diagrams.mddocs/architecture/overview.mddocs/doctoring/real-audio-accuracy-acceptance.mddocs/documentation-coverage-matrix.mddocs/engineering/acceptance-criteria.mddocs/engineering/youtube-known-stem-validation.mddocs/operations/deploy-runbook.mddocs/plans/2026-03-10-bandscope-cross-platform-build.mddocs/plans/2026-03-10-bandscope-harness.mddocs/plans/2026-03-10-bandscope-supply-chain-design.mddocs/plans/2026-03-10-bandscope-supply-chain.mddocs/plans/2026-03-28-ml-engine-integration.mddocs/release/release-policy.mddocs/repository/bootstrap-plan.mddocs/security/dependency-policy.mddocs/security/sbom-policy.mddocs/workflow/github-bootstrap-execution-policy.mdscripts/checks/run_analysis_command.pyscripts/checks/security_gates.pyscripts/checks/verify_docs.pyscripts/checks/verify_security_notes.pyscripts/checks/verify_supply_chain.pyservices/analysis-engine/src/bandscope_analysis/api.pyservices/analysis-engine/src/bandscope_analysis/separation/__init__.pyservices/analysis-engine/src/bandscope_analysis/separation/audio_separator.pyservices/analysis-engine/src/bandscope_analysis/youtube.pyservices/analysis-engine/tests/known_stem_benchmark.pyservices/analysis-engine/tests/test_analysis_command.pyservices/analysis-engine/tests/test_api.pyservices/analysis-engine/tests/test_documentation_policy.pyservices/analysis-engine/tests/test_separation.pyservices/analysis-engine/tests/test_supply_chain_policy.pyservices/analysis-engine/tests/test_youtube.pyservices/analysis-engine/tests/test_youtube_stem_e2e.pysupply-chain/supplemental-component-inventory.json
🚧 Files skipped from review as they are similar to previous changes (18)
- docs/adr/README.md
- services/analysis-engine/tests/test_api.py
- services/analysis-engine/src/bandscope_analysis/api.py
- docs/adr/0002-known-stem-youtube-quality-gate.md
- docs/repository/bootstrap-plan.md
- docs/PRD.md
- scripts/checks/verify_docs.py
- ARCHITECTURE.md
- docs/doctoring/real-audio-accuracy-acceptance.md
- docs/architecture/overview.md
- docs/operations/deploy-runbook.md
- docs/engineering/youtube-known-stem-validation.md
- services/analysis-engine/tests/known_stem_benchmark.py
- docs/plans/2026-03-28-ml-engine-integration.md
- docs/engineering/acceptance-criteria.md
- docs/documentation-coverage-matrix.md
- docs/adr/0001-source-separation-runtime-and-model-delivery.md
- services/analysis-engine/tests/test_separation.py
|
@coderabbitai review Please review the current exact head |
🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
head_sha='e37b456f55ab3fb117bbaab306ac5846207ad89d'
git rev-parse --verify "${head_sha}^{commit}"
git status --short
git diff --name-status "${head_sha}^" "${head_sha}"
printf '\n--- focused symbols ---\n'
rg -n -C 3 \
-e 'Security Notes' \
-e 'numpy\._core|numpy\.core|_core' \
-e 'safe_globals|torch\.load|weights_only|pickle' \
-e 'security_pattern_violations|default.*lock|lock.*default' \
-e 'exclude|excluded|rglob|os\.walk|glob' \
scripts services --glob '*.py' || trueLength of output: 100318 🏁 Script executed: #!/bin/bash
set -euo pipefail
head_sha='e37b456f55ab3fb117bbaab306ac5846207ad89d'
printf '%s\n' '--- commit diff: focused files ---'
git diff --unified=80 "${head_sha}^" "${head_sha}" -- \
scripts/checks/verify_security_notes.py \
scripts/checks/security_gates.py \
scripts/checks/verify_supply_chain.py \
services/analysis-engine/src/bandscope_analysis/separation/audio_separator.py \
services/analysis-engine/tests/test_documentation_policy.py \
services/analysis-engine/tests/test_supply_chain_policy.py
printf '%s\n' '--- security notes checker ---'
cat -n scripts/checks/verify_security_notes.py
printf '%s\n' '--- security gate ---'
sed -n '1,170p' scripts/checks/security_gates.py | cat -n
printf '%s\n' '--- supplemental inventory function and constants ---'
rg -n -C 8 'def supplemental_inventory_violations|ANALYSIS_LOCK_PATH|analysis_lock_path|default.*lock|lock_path' scripts/checks/verify_supply_chain.py
printf '%s\n' '--- focused test ranges ---'
sed -n '1,130p' services/analysis-engine/tests/test_documentation_policy.py | cat -n
sed -n '70,125p' services/analysis-engine/tests/test_supply_chain_policy.py | cat -n
sed -n '300,590p' services/analysis-engine/tests/test_supply_chain_policy.py | cat -nLength of output: 88114 🤖 web_search executed:
Length of output: 11497 🏁 Script executed: #!/bin/bash
set -euo pipefail
head_sha='e37b456f55ab3fb117bbaab306ac5846207ad89d'
printf '%s\n' '--- NumPy lock entries ---'
rg -n -C 4 'name = "numpy"|name = "torch"|name = "demucs"' services/analysis-engine/uv.lock
printf '%s\n' '--- release-risk traceability changes ---'
git diff --unified=20 "${head_sha}^" "${head_sha}" -- \
CHANGELOG.md \
docs/TRD.md \
docs/adr/0001-source-separation-runtime-and-model-delivery.md
printf '%s\n' '--- fence parser call sites and parser tests ---'
rg -n -C 3 '\bsecurity_notes_section\s*\(' . --glob '*.py'
rg -n -C 4 'FENCE_PATTERN|fenced|fence|```|~~~' services/analysis-engine/tests --glob '*.py'
printf '%s\n' '--- static diff hygiene ---'
git diff --check "${head_sha}^" "${head_sha}"Length of output: 26306
Security Notes fence parsing —
A plan can therefore put Restrict the fence prefix to zero through three literal spaces. Add a regression case that confirms a four-space-indented ````` line does not suppress the next peer heading. The requested NumPy compatibility alias, checkpoint security-gate binding, excluded-tree pruning, and repository-root default lock behavior otherwise appear correctly constrained by the inspected source and tests.
|
|
@coderabbitai The exact-head Security Notes parser finding is fixed in |
|
Tip For best results, initiate chat on the files or code changes.
I will treat If you found this review helpful, would you consider giving us a shout-out on X? Thank you for using CodeRabbit! You are interacting with an AI system. |
|
@coderabbitai review Please review exact head |
|
Tip For best results, initiate chat on the files or code changes. 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
head_sha='189d722c6a1fc6ec8e23363d38eb97da5680f3eb'
git rev-parse --verify "${head_sha}^{commit}"
git show -s --format='commit=%H%nparent=%P%ntree=%T%nsubject=%s' "$head_sha"
printf '%s\n' '--- changed paths ---'
git diff --name-status "${head_sha}^" "$head_sha"
printf '%s\n' '--- changed Python and Markdown outlines ---'
changed_files=$(git diff --name-only "${head_sha}^" "$head_sha")
while IFS= read -r path; do
case "$path" in
*.py)
printf '\n--- outline: %s ---\n' "$path"
ast-grep outline "$path" --items all || true
;;
esac
done <<< "$changed_files"
printf '%s\n' '--- focused symbols and schema/policy references ---'
rg -n -C 4 \
-e 'schema-v1|schema_v1|schemaVersion|evidence' \
-e 'rendered|Markdown|markdown|fence|heading' \
-e 'authority|authoritative|PRD|TRD|ADR' \
scripts services docs \
--glob '*.py' --glob '*.md' --glob '*.json' || true
printf '%s\n' '--- focused commit diff ---'
git diff --unified=70 "${head_sha}^" "$head_sha" -- \
scripts/checks \
services/analysis-engine/tests \
docs \
AGENTS.md ARCHITECTURE.md README.md CLAUDE.md CONTRIBUTING.md CHANGELOG.md \
supply-chain || true
printf '%s\n' '--- diff whitespace check ---'
git diff --check "${head_sha}^" "$head_sha"Length of output: 91305 🏁 Script executed: #!/bin/bash
set -euo pipefail
head_sha='189d722c6a1fc6ec8e23363d38eb97da5680f3eb'
printf '%s\n' '--- commit metadata and changed paths ---'
git show -s --format='commit=%H%nparent=%P%ntree=%T%nsubject=%s' "$head_sha"
git diff --name-status "${head_sha}^" "$head_sha"
printf '%s\n' '--- parser and checkers ---'
cat -n scripts/checks/markdown_sections.py
sed -n '1,470p' scripts/checks/verify_docs.py | cat -n
cat -n scripts/checks/verify_security_notes.py
printf '%s\n' '--- Markdown parser dependency and check invocations ---'
rg -n -C 4 'markdown-it|markdown_it' services/analysis-engine/pyproject.toml services/analysis-engine/uv.lock package.json scripts services --glob '!**/test/**' || true
rg -n -C 3 'verify_docs\.py|verify_security_notes\.py|run_analysis_command' package.json scripts .github --glob '*.json' --glob '*.yml' --glob '*.yaml' --glob '*.mjs' --glob '*.py' || true
printf '%s\n' '--- authority and evidence-contract content ---'
for path in \
docs/README.md docs/PRD.md docs/TRD.md docs/documentation-coverage-matrix.md \
docs/adr/0003-ephemeral-benchmark-evidence-model.md \
docs/release/release-policy.md \
docs/engineering/youtube-known-stem-validation.md; do
if [ -f "$path" ]; then
printf '\n--- %s ---\n' "$path"
rg -n -C 5 'authority|authoritative|schema-v1|schema v1|evidence|retention|upload|path|environment' "$path" || true
fi
done
printf '%s\n' '--- targeted test inventory ---'
rg -n -C 2 \
-e 'table|traceability|canonical_outer_pipe|source_headers|source_rows' \
-e 'html|comment|heading|Setext|fence|link|image|escape' \
services/analysis-engine/tests/test_documentation_policy.py \
services/analysis-engine/tests/test_*security* \
|| trueLength of output: 142761
I found no actionable issue. The rendered-Markdown checks use the directly pinned The schema-v1 contract consistently keeps artifact upload and retention disabled until governance accepts the required store, access, TTL, deletion-verification, and incident-owner controls. The documents correctly separate historical failures and creator-master calibration from current-head production-path evidence. This review was static. The sandbox cannot run the repository test suite. You are interacting with an AI system. |
There was a problem hiding this comment.
Actionable comments posted: 3
🧹 Nitpick comments (4)
scripts/checks/verify_docs.py (1)
361-372: 📐 Maintainability & Code Quality | 🔵 Trivial | ⚡ Quick wincanonical
## Security Notesheading 판별 로직이 두 스크립트에 중복됩니다.이 블록은
scripts/checks/verify_security_notes.py의_security_notes_contract(27-33행)과 동일한 판정을 수행합니다. 두 구현은 같은 정책 계약을 표현합니다. 한쪽만 수정하면 두 검사기의 판정이 갈라집니다.공유 헬퍼를
scripts/checks/markdown_sections.py에 두고 두 스크립트가 호출하도록 정리하십시오.♻️ 제안 방향
+# scripts/checks/markdown_sections.py +def canonical_h2_headings( + document: MarkdownDocument, + heading_text: str, +) -> list[MarkdownHeading]: + """Return exact column-zero canonical H2 headings from a scanned document.""" + return [ + heading + for heading in document.headings + if heading.level == 2 + and heading.text == heading_text + and document.lines[heading.start].rstrip(" \t") == f"## {heading_text}" + ]
verify_docs.py의_canonical_h2_headings와verify_security_notes.py의 heading 필터를 이 헬퍼로 대체하십시오.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@scripts/checks/verify_docs.py` around lines 361 - 372, Extract the shared canonical “Security Notes” heading detection into a helper in markdown_sections.py, preserving the existing heading-level, exact-text, regex, and unsafe-HTML checks. Update verify_docs.py’s _canonical_h2_headings and verify_security_notes.py’s _security_notes_contract to call this helper so both checks use one policy implementation.services/analysis-engine/tests/test_documentation_policy.py (2)
680-690: 📐 Maintainability & Code Quality | 🔵 Trivial | 💤 Low value기대값을 파라미터와 함께 선언하십시오.
680-689행은 공통 기대값을 만든 다음
hidden_kind로 다시 덮어씁니다. 1265-1271행도 같은 패턴입니다. 파라미터마다 기대 결과가 다르므로,pytest.mark.parametrize에 입력과 기대값을 쌍으로 넣으면 각 케이스의 계약이 한 곳에서 읽힙니다. 이 방식은 케이스 추가 시 분기 조건을 갱신하는 실수를 막습니다.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@services/analysis-engine/tests/test_documentation_policy.py` around lines 680 - 690, Update the parameterized tests around security_notes_violations and the analogous case near the other duplicated expectation to pass each hidden_kind together with its expected result through pytest.mark.parametrize. Remove the in-test expected-value reassignment branches, and assert directly against the case-specific expected value so each parameter’s contract is declared in one place.
786-788: 📐 Maintainability & Code Quality | 🔵 Trivial | 💤 Low value후행 공백에 의존하는 픽스처를 명시적으로 표현하십시오.
787행은 ``` 뒤의 후행 공백 한 칸에 테스트 의도가 걸려 있습니다. 편집기 설정이나
trailing-whitespace계열 포매터가 이 공백을 제거하면 픽스처가 유효한 GFM 펜스 종료로 바뀝니다. 그러면 테스트 의도가 사라집니다.공백을 문자열 연결로 명시하십시오.
♻️ 제안 수정
plan_path.write_text( - """# Unsafe plan + """# Unsafe plan ## Security Notes ```text -``` +```""" + + " " + + """ ### Attack surface또는 픽스처 본문을
"\n".join([...])로 구성하고 해당 줄만"``` "로 두십시오.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@services/analysis-engine/tests/test_documentation_policy.py` around lines 786 - 788, Make the Markdown fixture around the closing ``` before “### Attack surface” explicitly include its trailing space through string concatenation or a joined-line representation. Ensure the resulting fixture still contains exactly “``` ” rather than relying on source-line trailing whitespace.scripts/checks/verify_security_notes.py (1)
25-26: 📐 Maintainability & Code Quality | 🔵 Trivial | 💤 Low valueraw HTML 실패와 heading 누락 실패를 구분해 보고하십시오.
25-26행은
has_unsafe_html이 참일 때 빈 계약을 반환합니다.security_notes_violations는 이 상태를missing section: ## Security Notes로 보고합니다. 문서에 canonical heading이 실제로 존재해도 같은 메시지가 나옵니다. 작성자는 원인을 찾기 어렵습니다.별도 상태를 반환해
contains unsupported raw HTML위반을 보고하십시오.verify_docs.py의requirement_traceability_violations는 이미 같은 방식으로 구분합니다. 이 변경은 관련 테스트 기대값 갱신을 동반합니다.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In `@scripts/checks/verify_security_notes.py` around lines 25 - 26, Update the unsafe-HTML branch in security_notes_violations so it returns a distinct violation state instead of the empty contract currently produced when document.has_unsafe_html is true. Make the reporting path emit “contains unsupported raw HTML” while preserving “missing section: ## Security Notes” for genuinely absent headings, following the distinction used by requirement_traceability_violations. Update related test expectations.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@docs/engineering/youtube-known-stem-validation.md`:
- Around line 106-110: Update the youtube-known-stem-v1 documentation to define
authorization_ref as a required non-null evidence input, describe its validation
before live execution proceeds, and document the preflight authorization_missing
termination path when it is absent. Keep the existing execution-input and
retained-evidence rules unchanged.
In `@package.json`:
- Around line 16-17: Update the check:docs and check:security-notes npm scripts,
along with the Python launcher contract used by scripts/harness/quickcheck.sh,
to invoke the cross-platform Python executable guaranteed on Windows instead of
python3. Preserve the existing run_analysis_command.py arguments so its
uv/local-venv fallback remains reachable.
In `@services/analysis-engine/tests/test_youtube.py`:
- Around line 342-345: Update the symlink test around _has_execute_permission to
create an actual symbolic link pointing to an executable regular file,
preserving the target’s execute permission, then assert
runtime_dependency_invalid for that artifact. Keep the existing non-executable
regular-file validation as a separate test case rather than using it for the
symlink scenario.
---
Nitpick comments:
In `@scripts/checks/verify_docs.py`:
- Around line 361-372: Extract the shared canonical “Security Notes” heading
detection into a helper in markdown_sections.py, preserving the existing
heading-level, exact-text, regex, and unsafe-HTML checks. Update
verify_docs.py’s _canonical_h2_headings and verify_security_notes.py’s
_security_notes_contract to call this helper so both checks use one policy
implementation.
In `@scripts/checks/verify_security_notes.py`:
- Around line 25-26: Update the unsafe-HTML branch in security_notes_violations
so it returns a distinct violation state instead of the empty contract currently
produced when document.has_unsafe_html is true. Make the reporting path emit
“contains unsupported raw HTML” while preserving “missing section: ## Security
Notes” for genuinely absent headings, following the distinction used by
requirement_traceability_violations. Update related test expectations.
In `@services/analysis-engine/tests/test_documentation_policy.py`:
- Around line 680-690: Update the parameterized tests around
security_notes_violations and the analogous case near the other duplicated
expectation to pass each hidden_kind together with its expected result through
pytest.mark.parametrize. Remove the in-test expected-value reassignment
branches, and assert directly against the case-specific expected value so each
parameter’s contract is declared in one place.
- Around line 786-788: Make the Markdown fixture around the closing ``` before
“### Attack surface” explicitly include its trailing space through string
concatenation or a joined-line representation. Ensure the resulting fixture
still contains exactly “``` ” rather than relying on source-line trailing
whitespace.
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro Plus
Run ID: fd7a46a2-643c-4af1-9812-32081f880358
⛔ Files ignored due to path filters (1)
services/analysis-engine/uv.lockis excluded by!**/*.lock
📒 Files selected for processing (34)
ARCHITECTURE.mdCHANGELOG.mddocs/PRD.mddocs/TRD.mddocs/adr/0001-source-separation-runtime-and-model-delivery.mddocs/adr/0002-known-stem-youtube-quality-gate.mddocs/adr/0003-ephemeral-benchmark-evidence-model.mddocs/adr/README.mddocs/architecture/diagrams.mddocs/architecture/overview.mddocs/doctoring/real-audio-accuracy-acceptance.mddocs/documentation-coverage-matrix.mddocs/engineering/acceptance-criteria.mddocs/engineering/youtube-known-stem-validation.mddocs/operations/deploy-runbook.mddocs/plans/2026-03-10-bandscope-harness.mddocs/plans/2026-03-12-issue-32-analysis-orchestration-design.mddocs/release/release-policy.mdpackage.jsonscripts/checks/markdown_sections.pyscripts/checks/run_analysis_command.pyscripts/checks/security_gates.pyscripts/checks/verify_docs.pyscripts/checks/verify_security_notes.pyscripts/checks/verify_supply_chain.pyscripts/harness/quickcheck.shservices/analysis-engine/pyproject.tomlservices/analysis-engine/src/bandscope_analysis/separation/audio_separator.pyservices/analysis-engine/src/bandscope_analysis/youtube.pyservices/analysis-engine/tests/conftest.pyservices/analysis-engine/tests/test_analysis_command.pyservices/analysis-engine/tests/test_documentation_policy.pyservices/analysis-engine/tests/test_supply_chain_policy.pyservices/analysis-engine/tests/test_youtube.py
🚧 Files skipped from review as they are similar to previous changes (17)
- services/analysis-engine/pyproject.toml
- docs/adr/README.md
- docs/plans/2026-03-10-bandscope-harness.md
- docs/architecture/overview.md
- docs/doctoring/real-audio-accuracy-acceptance.md
- docs/adr/0003-ephemeral-benchmark-evidence-model.md
- ARCHITECTURE.md
- docs/PRD.md
- docs/engineering/acceptance-criteria.md
- scripts/checks/security_gates.py
- docs/adr/0001-source-separation-runtime-and-model-delivery.md
- docs/operations/deploy-runbook.md
- docs/architecture/diagrams.md
- docs/release/release-policy.md
- services/analysis-engine/src/bandscope_analysis/separation/audio_separator.py
- docs/documentation-coverage-matrix.md
- services/analysis-engine/src/bandscope_analysis/youtube.py
Source owner checkpoint — no-OEM model qualification (2026-09-29)Continuing the user's approved no-OEM replacement work on this existing Signal/MIR owner, not opening a competing MIR PR. Observed head This run's bounded source scope: an explicit evaluation-only UMX-HQ local tensor loader/adapter, deterministic no-network/strict-state negative tests, and an exact-candidate rights/qualification record. No production model-default change, weights download inside normal analysis, runtime dependency/lock change, Distribution policy mutation, or release claim. UMX-HQ ( The current container has PyTorch/torchaudio/Open-Unmix available, but |
Build four targets directly without pretrained factories or downloads, require exact byte receipts and weights_only tensor state, reject unsafe/unset backend autoload, and preserve stereo output identity. Record original UMX-HQ weight MIT evidence and no-OEM alternatives separately from acquisition, real-audio quality and native release gates. Local scoped verification: 58 tests; candidate statements 100/100, branches 34/34; actual-library architecture UNIT smoke passed with random unit weights, not pretrained quality. No production dependency, default model, Distribution policy, or original weight bytes changed. Canonical owner #828; advances #1181/#1180 without closing either.
|
@coderabbitai review Please perform read-only review of the new no-OEM reference-evaluator slice at exact head Focus: complete immutable four-target receipts before deserialization; no pretrained factory/download or UMXL fallback; direct Open-Unmix 1.3.0 construction; explicit weights_only/strict tensor keys+shape+dtype+layout; pre-import backend disable including unset default; empty process safe globals; stereo and source-order preservation; caller-hash consistency versus source authentication; separation of public model permission, unit evidence, pretrained quality and native release authority. Local source evidence: 58 tests, candidate module 100/100 statements and 34/34 branches; actual-library architecture UNIT smoke on torch/torchaudio 2.10.0+cpu. Original weight bytes were not acquired. Synthetic/random unit fixtures are explicitly not real-audio quality. No default/dependency/lock/production/Distribution policy changes. Review receipt must bind to this unchanged head; no request for self/automatic approval, source mutation or release. |
✅ Action performedReview finished.
|
Add a build-only bootstrap/reacquisition command, fixed original sources and notices, bounded streaming checks, full SHA256 receipts, cancellation and non-overwrite publication. Inference and release admission remain separate. Run offline contracts in the existing native Distribution matrix. Local exact-blob tests: 73 passed. Original live acquisition remains blocked by container network/DNS; no model bytes or native success are claimed. Refs #1180 #1181 #828
| Tensor=FakeTensor, | ||
| strided="strided", | ||
| serialization=SimpleNamespace(get_safe_globals=lambda: []), | ||
| from_numpy=lambda array: FakeTensor(array), |
| monkeypatch.delenv("TORCH_FORCE_NO_WEIGHTS_ONLY_LOAD", raising=False) | ||
|
|
||
|
|
||
| def candidate_module(): |
실제 API 실패 상태 회귀 — 2026-10-05 11:13 KST현재 exact head b02ac12f890069d8e7aefe1a8bf801122b87d54d에서 Coordinator가 실제 API→separator→worker→parent→JSON result cache 경로를 직접 재실행했습니다. 16 tests:12 FAILED/4 PASSED, errors0/skips0, pytest exit1. 디코더·native 실행·추론 경계는 synthetic이며 실제 음원/GPU acceptance는 아닙니다. 모델 검증 오류·runtime·timeout·native no-result를 audio_features=None으로 계속 진행해 실제 demo-song 생성→result cache 저장→succeeded로 표시합니다. retry는 cache hit로 separator를 재실행하지 않고 같은 가짜 성공을 반환합니다. Native start OSError는 structured failed 밖으로 escape합니다. 최소 수리는 local separation terminal truth와 legacy result-cache 무효화/성공 provenance, 실패 cleanup입니다. #770/#828 정본을 유지합니다. #866도 api.py/test_api.py를 변경하므로 생산 동시 writer를 시작하지 않습니다. 현재 #866 source writer/release 확인 요청5986920079, Orca peer 협의 msg2974688285a3를 보냈습니다. 지금은 별도 scratch에서만 TDD 수리 중이며 검증/독립 검토/ownership admission/ordinary reconciliation 뒤 기존 PR에 반영합니다. 이 댓글이나 assignee는 source release/approval가 아닙니다. 증거는 Git administrative evidence store의 hermes-evidence/analysis-failure-truth-20261005에 원본 보고·54-input snapshot·hash manifest·parent receipt로 보존했습니다. 개인 journal/model/audio/credential은 포함하지 않았습니다. 현 격리 수리가 생산 적용·hosted gate PASS·merge를 뜻하지 않습니다. Security Notes: 실패 결과 무결성 및 로컬 cache 경계. fixture-only 입력, app-owned paths, fixed error messages와 argument arrays를 유지하며 네트워크/권한/ignore를 추가하지 않습니다. 기존 잘못된 cache replay와 native envelope를 함께 테스트합니다. |
실패 상태 수리 후보 재검토 — 2026-10-05 12:21 KST격리 후보의 새 독립 정적 재검토 deleg_e1ee99d9는 세 파일의 exact hash에서 PASS입니다. 이전 큰 JSON 정수의 NumPy TypeError escape와 강제 fork 테스트 지적을 해소했습니다. Local separation 실패→demo 성공/캐시 저장을 금지하고 legacy fake result cache를 무효화합니다. 합성 정상 pipeline/cache hit와 명시적 demo helper는 유지합니다. 공유 observations 파일 쓰기는 제거했고 실제 I/O failure branch 호출도 확인합니다. Coordinator가 새 해시에서 직접 실행:108 passed,1 real uninjected media/model CLI test deliberately deselected, exit0. 실제 Mac spawn timeout/no-result 자식은 둘 다 종료하고 queue를 닫았습니다. Windows 실행·모델 진위/권리·실음원 품질·GPU·전체 coverage/native/security/SBOM acceptance를 주장하지 않습니다. 리뷰는 정적이며 hosted non-author approval 또는 merge 승인이 아닙니다. 생산 source/PR head는 b02ac12 그대로입니다. Patch·원본 RED·새 review·유일 이름의 parent command/XML/stdout/해시/PID binding은 Git administrative hermes-evidence/analysis-failure-truth-20261005/review-fix-pending-review에 보존했습니다. Producer의 덮어쓴 green-selected 시간/PID 불일치는 역사 증거로 보존하고 parent 실행에 혼합하지 않았습니다. 다음 독립 wave는 현재 protected develop314ddeae와 #828의 ordinary merge conflict, #866 shared API hunk, #970 cache identity/generation 소유권을 읽기 전용으로 비교합니다. 무단 mutable stacking/소유권 release/최신 source 재실행 승인 추론 없이 canonical #828 통합 경로를 확정합니다. 새 경쟁 PR, commit/push/merge, gate waiver나 source-neutral dispatch는 아직 없습니다. |
Signal/MIR 실패 정책과 캐시 admission 인계 — 2026-10-05 12:35 KST#828 exactb02ac12f에서 모델/runtime/timeout/native 실패가 demo-song+succeeded로 final cache에 저장되고 retry가 재사용되는 실제 RED12FAIL/4PASS를 재현했습니다. Scratch repair는108PASS/1realmodelCLI제외, 새 독립3파일hash reviewPASS입니다. 생산 반영은 아직 없습니다. 현재 #970 exact3dfd77e11187211e9b7ed2317b8f559e5e1fb018도 api1411–1436→1468→1485–1500의 fallback 성공/게시 경로를 유지합니다. Generation identity만으로 terminal truth가 보장되지 않습니다. #970의 native source+MIR identity, shared result validator와 durable staged/fsync/metadata-last 게시 계약을 #828의 legacy cache writer로 덮어쓰지 않겠습니다. 인계 범위: #828은 separation/model/start/no-result/timeout/invalidfeatures/pipeline-empty의 failed/no-result/no-new-cache 정책. #970은 그 정책에 따른 역사적 가짜 성공 cache migration/차단을 현 persisted final-result admission에서 결정하며 source/MIR identity·내구성·동시성·sync실패 계약을 보존. #866은 source/process/stem/archive admission을 유지. #1180 Distribution의 상업 immutableartifact 계약과 MIR reuse generation은 별개입니다. 현재 active writer/session/lease와 api/cache hunk 소유 범위, 이 실패 정책을 수용할 bounded writer admission을 확인해 주세요. 최근 @jules 요청의 네 formatter 파일은 별도 범위로 보존합니다. Assignee 배정·이 요청·reply 부재는 admission/release/독립 승인으로 간주하지 않습니다. Parent는 격리본에서만 portable failure-policy와 owner-preserving cache migration 후보를 독립 검증합니다. Mutable prerequisite 복사/무단 stack/새경쟁PR/forcepush/보호gate완화 없음. Security Notes: untrusted cache·native result의 integrity 경계. 고정 오류 문구·app-owned 경로·기존schema/identity/durablepublication을 유지하며 원음/모델/credentials를 수집하지 않습니다. Scratch 수리와 보호 통합/모델권리/실음원품질은 별개입니다. Git administrative evidence store hermes-evidence/analysis-failure-truth-20261005/domain-ownership에 줄번호/hash-bound보고를 보존했습니다. |
Unsigned consumer 회귀 재검토 결과 — 2026-10-05 13:33 KST독립 정적 재검토 deleg_875578f1는 현재 #828 terminal-only 후보의 세 파일 해시에서 PASS입니다. Consumer의 fi→fiu 한 줄 변경으로 uint8/16/32/64의 기존 지원을 복원했으며 새 blocking finding은 없습니다. Cache owner 16개 정의·schema/key/readers/writers는 원본대로 유지합니다. Coordinator의 직접 실행은163 passed,1 real uninjected media/model CLI test deliberately deselected, exit0입니다. 실제 native/media/model 추론은 synthetic 경계이고 macOS spawn 시험을 Windows 실행으로 전용하지 않습니다. 상속된 NPY context-manager TypeError escape는 미해결입니다. 이를 관찰한 테스트가 안전한 실패 증거는 아닙니다. 최종 해시: api6368612350bbf65ff1f5441fb62a42da766428e1b852d3de93fbc9b81eb37b57 / test_api35e03c07cce2b0a1fee547139be0fe09d7f2da63c459c0952aa08067953604c0 / failure_truth9c82e05d9419c8e3cc1a995f94268746ad849891a954b05913c514603ba80d7c. Source/parent command/XML/stdout와 review를 Git administrative hermes-evidence/analysis-failure-truth-20261005/828-unsigned-pending-review/accepted-source-binding.json에 결속했습니다. 이전 FAIL/RED는 보존합니다. 현재 PR head b02ac12 및 생산 파일은 변경하지 않았습니다. 별도 #970 owner-preserving combined 후보는 Parent 선정165개 통과이나 아직 독립 판정 대기입니다. 그 판정은 #828 승인과 별개이며, 정상 조상 통합·공유 API coordination·필수 checks·비작성자 승인 후에만 정상 merge합니다. 재검토 PASS는 hosted approval/merge/release 승인이 아닙니다. |
Actual failure-truth and reference-boundary follow-up — 2026-10-05 14:52 KSTOrdinary non-force push verified:7c1acf80a49c32910ebb132f24b0834a8181cd9b. Parents:b02ac12f + protected develop314ddeae. Four protected-policy conflicts reconciled, no unmerged entries, palette unstaged/unchanged. PR is now MERGEABLE, not merged. Local separation/start/timeout/no-result/invalid stem/empty pipeline now ends failed without demo success or new result/feature cache publication. Consumer guards preserve unsigned numeric compatibility and existing cache-owner schema/key/readers/writers. Canonical #970 durable/MIR cache compatibility candidate remains separate, not copied into ancestry. UMX source-only pattern findings resolved via independently reviewed exact paths+complete AST fixed hashes; semantic changes revoke recognition. Existing htdemucs boundary and unrelated rules remain. Actual smoke clear_safe_globals removed; nonempty globals fail before model factory/save/load. Historic clearing observations are not current runtime acceptance. Direct production selected tests:506 passed,1 uninjected real-model CLI explicitly NOT_RUN, exit0, no warnings with junit_family legacy. Actual security gate, documentation/security-notes/supply-chain/bootstrap, changed6Python Ruff/format, scanner/api targeted mypy pass. Static reviews of terminal bytes, protected conflict resolution and final4securityfiles passed their scoped introduced-finding checks. Stored model/audio payloads not acquired/executed. Whole-repo unchanged helper/fake lint7findings/format2files, fullcoverage/audits/SBOM/Windows/native/GPU/modelrights/scientificquality remain independent gates; local-green is not release readiness. Current-head hosted checks include skipped CI/SBOM/platform jobs and failed CodeQL. Skips are not PASS. Actual annotations are retained in administrative hermes-evidence/analysis-failure-truth-20261005/828-final-production with delivery/parent tests/index/review bindings. Do not bypass billing/platform/review controls, synthesize verdicts or wake-commit. Existing Draft is preserved for remaining whole-lane qualification. Security Notes: untrusted cache/native/model-reference/source fixtures are checked at existing app-owned boundaries; fixed errors omit paths. No new dependency/lock/runtime network/exec/pickle permission. Reference source recognition is not model provenance/rights/signature or a native sandbox. Inherited NPY rawloader TypeError and internal MIR heuristics remain explicit unresolved scope. |
UMX formatting and fixed source-pin follow-up — 2026-10-05 15:24 KSTOrdinary non-force push verified:69a6d585dcd4514741c657a2e319999ad019202a, parent7c1acf80. Exactly3files changed:helper imports/format,fake testformat and helper completeAST fixedpin. Independent source-trust re-review deleg_6a86936a passed exact bytes. Helper ordered bindings/standard-library object identity unchanged; import-hook call count is not claimed identical. Fake AST and smoke bytes unchanged; no runtime-generated trust/ignore/permission expansion. Direct production checks:506passed/1uninjected real-model CLI NOT_RUN, exit0; defaultanalysis src/tests lintPASS; format102filesPASS; mypy49sourcefilesPASS; scannerlint/defaultformat/strictmypyPASS; actualsecuritypattern gatePASS. This is not fullrepo/frontend/Rust/model/GPU/Windows/audio quality/fullcoverage/audit/SBOM/release or qualifyingremoteapproval. Actualartifactmodelsmoke notrun. OriginalRED and final parent/review/sourcebindings retained inadministrative hermes-evidence/analysis-failure-truth-20261005/umx-lint-production. FreshPRread confirmsOPEN/Draft/MERGEABLE. NewheadCodeQL37272067023,OSbuild37272068712,CI37272068643,SBOM37272068386 carry billing accountlocked NOTSTARTED annotations. DownstreamSKIPPED isnotPASS. Existing payer recovery #2356/#712 remains; no unchangedrerun/statussynthesis/wakecommit/purchases/permissionchanges. PR hasnotmerged. Security Notes:reference/fake exactAST/sourcebounds and restrictions preserved. Sourcepinnotmodelauthenticity/rights. No globalsmutation or newdependency/modeldownload. Inherited malformed-cache TypeError boundaries remain scoped follow-up, not advertised as repaired here. |
Malformed feature cache acquisition — 2026-10-05 15:51 KSTOrdinary non-force push verified:f8de90fe931e4522c18a1020fcae0a1c779d674b, parent69a6d585. Independent static review deleg_67d3a250 passed api0f074da2/truth955e24dc exact bytes. Production selected509tests passed,1uninjected real-model CLI NOT_RUN, exit0. Defaultanalysislint/102format/49source mypy and actualsecuritygate pass. Real standalone NPY at feature NPZ path returns ndarray and raises context-manager TypeError. Cache acquisition only now returns fixed failed/engine_unavailable/Cached stems unavailable and cache miss for updates/terminal on first/retry. Private bytes preserved, no native/pipeline/demo/new-cache publication; consumer programming TypeError is not hidden. Raw ownerreader16definitions/schema/key/read/write remain unchanged and directrawreaderTypeError remains scoped limitation. No #970 identity/durability copying, dependencies/model/network/exec permissions or broad catchall. Original2RED/new3GREEN, final509directexecution/review/sourcebindings retained in administrative hermes-evidence/analysis-failure-truth-20261005/npy-consumer-production. Sourcefix is not complete archive authenticity/rights/modelquality/GPU/Windows/fullcoverage/audit/SBOM/hosted qualifying approval. Current PR OPEN/Draft/MERGEABLE, notmerged; currenthead hosted execution billing NOT_STARTED, downstream SKIPPED notPASS. Do not rerun unchanged source, synthesize status, waive gates or use wakecommit. |
Portable fixtures and real cue-consumption acceptance — 2026-10-05 16:52 KSTOrdinary non-force push verified2115ce812b30ba7a9036a181096e6efa35af06d1, parentf8de90fe. Exactly2testfiles changed, production/API/YouTube path/TLS guard/cache schema/locks/coverageconfiguration bytes unchanged. Frozenexactbase independentstaticreviewdeleg_26683458 PASS; parentverifiedactualcanonicalHEAD beforeapplication(the review's314ddeae livecwd notewasotherroot,notthisbranch). Actualproductionselectedoffline suite:1137passed/23Rustparityskipped/3realmodel-networkNOT_RUN, directexit0. All49productionfiles coverage100:3349/3349statements and1138/1138branches; existing20excludedlinesunchanged. Defaultanalysislint/102format/49source mypy/securitygatePASS. Librosa2syntheticDSPwarningsretained. Thisisnotfullconfiguredgate/model/nativeWindows/GPU/realquality/rights orCLIchildcoverageproof. Original32YouTubefixtureFAIL duehardcoded/tmpoutsideownedroot/directsymlink nowrepairedusingrealpytestownedroot+actualpathguards; all38originalcasesretainand5pathcontrolsadded. Additional32APIcases userealJSON/NPZownerreaders+strictpipeline/nonfirstchecks+validupperbound/rebuildcontrols. CorrectguardsalreadyPASS, syntheticweakguard28failuresaretest-sensitivitycontrolsnotproductdefects. No guard deletion/threshold lowering/ignore/newruntime/dependency/permission. Hash-bound fullselection/parentcoverage/actualchildexit/review/originalRED are retained in administrative hermes-evidence/analysis-failure-truth-20261005/test-only-production. Newexactheadrequired hostedCI/SBOM/OS/CodeQL jobs remain billingNOT_STARTED;aggregateSKIPPEDnotPASS. PR OPEN/Draft/MERGEABLE notmerged. No bypass/selfapproval/unchangedretry/wakecommit/paidchange. |
CLI validation and temporal privacy — October 5, 2026 17:57 KSTNormal non-force push verified4f93f95f655e400a1cabf1ad4cb9b3a2b42d80d8, parent2115ce812. Eight exacthash files independently revieweddeleg_f88482a1 PASS and appliedaftercanonicalbranchHEAD/remote verification. Reviewerothercwd314ddeae observation wasnotthiscanonicalworktree andnotusedasapproval. CLI nowvalidates/normalizesbeforetemporalsideeffects, preservesrealAPItypedfailureandJSON/JSONL/transportexit; sourceKind/extension unhashableJSONtypes safelyrejectvia2narrowstringguards. DeterministicordinaryCLI syntheticnative/media success/failure transportreplaceswrongunconditionalmodelsuccessassumption. ExistingactualDemucs/liveYouTube opt-in remainunchanged. TemporalINFO/ERROR/publicexception omitpath/rawdetail; size/decoderbounds,algorithm, localaudio_pathmetadata andthirdpartywarningpassthrough preserved. DirectproductionwithrealtemporaryRustoverlay:1227passed,0failed/error/skip,2model/networkNOT_RUN, exit0. All49sourcecoverage100:3354/3354statements,1136/1136branches. Defaultlint/105format/mypy49/securitypattern/supplychainpolicyPASS. Existinglibrosa2syntheticwarnings retained. Unchanged23Rustparity alsoseparately directlyPASSwithnaturalHAVE_RUSTTrue andbuilt/loadedSHA121b276f... . Nativecdylibbuiltfromexactlockafterofficialndarray0.16.1 checksumverifiedfetch; invocation-onlymacOSdynamic_lookuplinkerfix. No wheel/parentvenv/globalcache/locksourceinstall,Windows,GPU,actualmodelquality/rights/realreleaseacceptance. CLIchildcoverageandfullconfiguredMLgate remainseparate. CurrentheadchecksCodeQL37286588771/platform37286590189/CI37286590209/SBOM37286590579 arebillingNOT_STARTED;aggregateSKIPPEDnotPASS. PRstillOPEN/Draft/MERGEABLE,notmerged.Noqualifyingnon-authorapproval/gatewaiver/statussynthesis/unchangedrerun/wakecommit. Existingpayer2356/712routepreserved. Security Notes:untrustedstdin/cache/media/nativeerrorscheckedbeforefilework; fixedprivacy-safe logs,envelopes andargumentarrays. Unknownkeyreflection/sourceLabelresponse/thirdpartywarningtext/localaudio_path/Pythoninternalcontextremainlimitations,notfullJSONprivacycertification. Hash-boundparenttest/source/coverage/native/review/delivery preserved inadministrative hermes-evidence/analysis-failure-truth-20261005/cli-temporal-native-production andpending-review. Userpaletteunstagedandpreserved. |
Focused retained-candidate continuation — 2026-10-06 09:11 KSTCanonical head remains New actual execution on unchanged private 13-file candidate:
Review continuation: deleg_775af7ed has completed; its retained transcript visibly reports PASS/no security or logic concerns, but final JSON is truncated. Complete hash-bound approval was not recovered or invented. No new competing review/source worker started. Canonical adoption needs complete review evidence and fresh source custody. Orca runtime is unavailable, while existing BandScope Python sessions are present. No restart/quit/peer interruption. Canonical source custody cannot be freshly confirmed, so the source lane remains untouched. User palette and #1134 dirty dependency work preserved without reading/staging/restoring palette. #1206 stays read-only in its dependency/lock scope, not a universal #828 Git prerequisite. Fresh exact-head annotations: 8 billing pre-start failures, 6 downstream skipped jobs. CodeRabbit Draft skip is not approval. Existing payer .github#2356/#712 remains the route; no unchanged rerun, source-neutral wake commit, status synthesis, paid fallback or permission/budget changes. Auth summary is not enough: /user returned HTTP403 rate-limit while authenticated GraphQL succeeded; no credential change. Durable evidence: Git administrative Next transition: restored fresh custody + complete final-hash review, then actual canonical integration checks and normal non-force follow-up push. Current required hosted gates and qualifying non-author approval remain mandatory before merge. No new Goal/cron. Security NotesOnly bounded synthetic request keys and owned scratch fixtures. Explicit nonsecret subprocess environments, argument arrays, private TMP/HOME, bounded concurrency/timeouts. No private audio, original models, credentials, user palette contents, permission expansion, audit suppression, gate weakening or evidence deletion. CLI transport seams are synthetic; hash consistency is not model rights/provenance, whole privacy certification or native/release quality. |
…al tests - Analysis job request and local audio source validation (Python and shared-types) now report a fixed diagnostic for unknown fields instead of echoing caller-supplied key names into public errors/JSONL. Known-field diagnostics, error codes and strict rejection are unchanged. - apps/desktop/tsconfig.test.json reset the inherited production exclude, so 17 test files and setup are actually type-checked (was 0 files). - Repair the test typing defects this exposed (ready-state narrowing, Partial invalid fixtures, typed Blob guards) without changing production unions; drop two unneeded @ts-expect-error markers. Verification (local, Node 22.23.3/npm 10.9.9, Python 3.12): desktop 216 PASS, shared 35 PASS, lint/typecheck/test-typecheck/build exit 0; analysis API/CLI/truth/unknown-field 239 PASS, ruff, format, mypy 49 files, security gate exit 0. Independent static review PASS on the 13 file hashes. Security Notes: removes reflection of untrusted request keys from error output; no new inputs, IPC, subprocess, dependency or lock changes.
a00da6a — unknown request key reflection fix + real test type-checkChanged (13 files): Python Local verification on this exact head (Node 22.23.3 / npm 10.9.9, Python 3.12):
Hosted checks on the previous head 4f93f95: they are not code failures. Each job annotation says: "The job was not started because your account is locked due to a billing issue." The required checks are therefore NOT RUN, and NOT RUN is not PASS. This PR stays Draft until billing is restored, the required checks run, and a non-author approval is given. Security Notes: this change stops reflecting untrusted request keys in error output. There are no new inputs, IPC, subprocess, dependency or lock changes. |
Product outcome
This Draft is the canonical #770 Signal/MIR known-stem lane. It retains the explicit opt-in, fail-closed production-path sentinel for authorized public YouTube intake → independently pinned creator-master identity → composed global alignment → deterministic htdemucs → zero-mean SI-SDR improvement and named-stem assignment. It now also contains an independent evaluation-only, local UMX-HQ reference adapter for the user-approved no-OEM replacement route.
The original benchmark remains one known-vocal slice, not the full multi-fixture/four-stem commercial MIR acceptance program. There is still no passing authorized live exact-candidate quality score. Do not open a parallel MIR PR or treat the new architecture-unit fixtures as scientific acceptance.
Exact current identity
b02ac12f890069d8e7aefe1a8bf801122b87d54d.0ba16b192b66773f52df2af544896e3c2a432142.3c23b12dfc5ef9397bcc6c822843040079f9eadf.b02ac12f890069d8e7aefe1a8bf801122b87d54d.feature/youtube-known-stem-e2e; updated withforce=false.develop, but the pre-existing branch ancestry still usesdevelop@749511c3ad4000090048718f685c6bee6b3d2c25; protecteddevelopis314ddeae7b775a4957594b599358c8255617eb2e. Existing conflicts are not claimed repaired by this change.No-OEM qualification implementation
Five new files:
tests/open_unmix_candidate.py: reference-only four-target byte loader and stereo inference adapter, outside the installed package.tests/test_open_unmix_candidate.py: 58 scoped contract cases; optional framework doubles are not quality evidence.tests/run_open_unmix_candidate_smoke.py: explicit actual-library architecture UNIT smoke; fails rather than silently skipping missing reference dependencies.tests/model_candidates/umxhq_qualification.json: original candidate coordinates and public weight-license evidence; unacquired sizes/full hashes remain null. This is not a release manifest or shipped SBOM.docs/adr/2026-09-29-no-oem-model-qualification.md: Proposed release decision, scope, controls, primary sources and owner-return conditions.UMX-HQ Zenodo record
10.5281/zenodo.3370489, version 1.0.1, explicitly describes weights and declaresmetadata.license.id=mit-license. A separate OEM contract is not required by that public grant; preserve the actual notice. This is separate from third-party training/input-music rights and indemnity. UMXL is not an admissible default. X-UMX-HQ (CC BY 4.0) and official Spleeter four-stem remain separate unmeasured alternatives, not runtime fallbacks.All four immutable blobs must match fixed UMX-HQ filenames, exact declared size, and full SHA-256 before any deserialization. Caller-provided bytes plus caller-provided hashes establish consistency, not origin or legal admission. The reference uses direct
OpenUnmix/Separatorconstruction, CPUweights_only=True, exact tensor keys/shapes/dtypes/layout/finite checks and strict state loading; no pretrained factory, torch.hub, missing-key random initialization, unrestricted retry, download, paid API or model fallback. Stereo 44.1-kHz input and four finite float32 outputs preserve sample count and canonical order without hidden downmix/resample/padding/clipping.The runtime requires explicit
TORCH_DEVICE_BACKEND_AUTOLOAD=0before import. Verified upstream PyTorch v2.10.0 treats unset as enabled; rejecting only explicit1is insufficient for that version. The loader rejects nonempty process safe globals. Only the dedicated architecture-unit interpreter clears its own imported helpers; no host global-state mutation or sandbox claim is made.Local verification boundary
The exact three code blobs were tested locally in an isolated sparse reconstruction, not in a complete repository checkout:
(2, 4410)and callable-bearing checkpoint rejection withweights_only=True;Final warnings-as-errors verification initially stopped before tests because this container's pytest-asyncio plugin had no explicit fixture-loop scope. Re-running with
-o asyncio_default_fixture_loop_scope=functionsupplied that missing runner configuration without suppressing warnings, and all 58 tests passed with-W error. This is local test-runner configuration, not a BandScope production repair.The actual original Zenodo checkpoint acquisition failed; git transport failed DNS resolution. No original model bytes or full model SHA-256 were acquired. Repository-pinned Ruff 0.15.5 is unavailable in the offline tool cache; Ruff, full repository suites, dependency audits, exact-head hosted checks, independent approval and native packaged acceptance remain unverified. No production dependency/lock/default-model/Distribution policy or original audio was changed.
Retained hosted runtime finding
A full analysis-engine run previously exposed
tests/test_cli.py::test_cli_main_temporal_analyzer_mock_successentering real stem separation after its fake TemporalAnalyzer completed, then fatally aborting on hosted macOS while traversing system proxy discovery in Demucs/torch.hub resolution.b2da2b4d7c52af396c472b6210a1128647518624injectscli.run_analysis_jobonly in that temporal-probe test and separately asserts the request and TemporalAnalyzer boundaries.5b4dd436fdb55d8fcfe9bd5436b106a217fc8e36restores the final newline. Dedicated known-stem/production-path scientific acceptance remains required; these mocks do not replace it.0ba16b192b66773f52df2af544896e3c2a432142records the macOS process-start finding. The existing “fork whenever available” policy remains open; the observed abort does not prove fork was its sole cause. Repair only behind a process-start RED preserving timeout/terminate/join/kill cleanup, native Windows/macOS behavior and real-audio reproducibility.Metric authority
Ownership and release boundary
#1180/#1126 retain acquisition, immutable model distribution, full provenance/signing, production serialization/native adapter, packaging, update and rollback. #1181 records weight rights. #970 owns Project Persistence; #866 owns Resource Admission & Decode; #1160 owns Active Player; #1116 owns the product-gap baseline. This change does not copy those owners. Python is only a reference ML oracle outside shipped code; production Rust/native integration needs exact-artifact parity and quality evidence.
Next: obtain original UMX-HQ bytes and notices through explicit approved acquisition; verify provenance/full size/digests; run the reference on those exact tensors and authorized held-out four-stem real audio; compare no-OEM alternatives without lowering acceptance; integrate a measured production adapter through Distribution; reconcile existing conflicts and acquire full unchanged-head CI/review/native evidence.
Security Notes
Untrusted boundaries: candidate bytes/receipts, checkpoint deserialization, inherited runtime environment, optional dependency code and decoded audio. Controls: fixed complete target set, immutable byte snapshots, size/hash consistency, restricted tensor-only exact state, explicit backend disable, empty safe globals, bounded audio/output, no network factories or fallback, generic diagnostics. The receipt is not authentication; weights-only is not an OS sandbox or immunity to runtime bugs. Python audit hooks cover Python socket operations only. No original user audio or credentials were used or published.
Merge gate
Keep Draft and unmerged until ordinary/non-force current-develop reconciliation, terminal-success applicable repository/central CI/build/SBOM/SAST/security/supply-chain/coverage gates, exact owned coverage/docstrings, zero valid findings, qualifying independent non-author last-push approval, original-model provenance, authorized real-audio quality and native release acceptance are established on one unchanged final head. No predecessor/partial/model-only/unit-fixture evidence transfers into commercial acceptance. No self-approval, force-push, destructive rebase, gate weakening, synthetic status, no-op retry commit or hidden paid fallback. This PR does not close #1180/#1181 merely by adding the candidate evaluator.
Summary by CodeRabbit
새 기능
문서
개선 사항