Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions .github/workflows/hourly-nvidia-nim-review-repair.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,7 @@ on:
- .github/workflows/github-hourly-review-repair.yml
- .github/workflows/governance-risk-compliance-hourly-review-repair.yml
- .github/workflows/hourly-nvidia-nim-review-repair.yml
- .github/workflows/semantic-data-portal-hourly-review-repair.yml
- .github/workflows/nonnest2-hourly-review-repair.yml
- .github/workflows/orgmetra-hourly-review-repair.yml
- .github/workflows/originweave-hourly-review-repair.yml
Expand All @@ -29,6 +30,7 @@ on:
- tests/test_orgmetra_hourly_review_caller.py
- tests/test_originweave_hourly_review_caller.py
- tests/test_quarantine_sandbox_hourly_review_caller.py
- tests/test_semantic_data_portal_hourly_review_caller.py
- tests/test_hourly_autofix_context_quality_gate.py
- tests/test_pr_review_conflict_scope.py
- tests/test_pr_review_conflict_scope_control_files.py
Expand All @@ -54,6 +56,7 @@ on:
- docs/doctoring/orgmetra-hourly-review-caller.md
- docs/doctoring/originweave-hourly-review-caller.md
- docs/doctoring/quarantine-sandbox-hourly-review-caller.md
- docs/doctoring/semantic-data-portal-hourly-review-caller.md
push:
paths:
- .github/workflows/pr-review-fix-scheduler.yml
Expand All @@ -66,6 +69,7 @@ on:
- .github/workflows/github-hourly-review-repair.yml
- .github/workflows/governance-risk-compliance-hourly-review-repair.yml
- .github/workflows/hourly-nvidia-nim-review-repair.yml
- .github/workflows/semantic-data-portal-hourly-review-repair.yml
- .github/workflows/nonnest2-hourly-review-repair.yml
- .github/workflows/orgmetra-hourly-review-repair.yml
- .github/workflows/originweave-hourly-review-repair.yml
Expand All @@ -82,6 +86,7 @@ on:
- tests/test_orgmetra_hourly_review_caller.py
- tests/test_originweave_hourly_review_caller.py
- tests/test_quarantine_sandbox_hourly_review_caller.py
- tests/test_semantic_data_portal_hourly_review_caller.py
- tests/test_hourly_autofix_context_quality_gate.py
- tests/test_pr_review_conflict_scope.py
- tests/test_pr_review_conflict_scope_control_files.py
Expand All @@ -107,6 +112,7 @@ on:
- docs/doctoring/orgmetra-hourly-review-caller.md
- docs/doctoring/originweave-hourly-review-caller.md
- docs/doctoring/quarantine-sandbox-hourly-review-caller.md
- docs/doctoring/semantic-data-portal-hourly-review-caller.md

permissions:
contents: read
Expand Down Expand Up @@ -164,6 +170,7 @@ jobs:
tests/test_orgmetra_hourly_review_caller.py \
tests/test_originweave_hourly_review_caller.py \
tests/test_quarantine_sandbox_hourly_review_caller.py \
tests/test_semantic_data_portal_hourly_review_caller.py \
tests/test_pr_review_conflict_scope_control_files.py \
tests/test_hourly_autofix_context_quality_gate.py \
tests/test_pr_review_conflict_scope_git_executable.py \
Expand Down
33 changes: 33 additions & 0 deletions .github/workflows/semantic-data-portal-hourly-review-repair.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,33 @@
name: semantic-data-portal Hourly Review Repair

on:
schedule:
# Minute 59 avoids Clearfolio (23), DiskSage (37), fast-mlsirm (49),
# BandScope (53), naruon (11), Inkspan (47), orchestrator (17),
# Wardnet (7), codec-carver (5), pg-erd-cloud (13), Keyverse (29),
# noema (19), Scopeweave (31), Appguardrail (41), and newsdom-api (43).
- cron: "59 * * * *"
Comment on lines +5 to +9

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📝 Info: Cron collision comment is internally inconsistent

The cron: "59 * * * *" comment at semantic-data-portal-hourly-review-repair.yml lists a set of minutes to avoid that omits several real callers in this repo (OriginWeave 10, nonnest2 16, quarantine-sandbox 14, github 21, accounting 27) and instead attributes minute 43 to newsdom-api when it is actually owned by governance-risk-compliance. This is only an explanatory comment and does not affect scheduling — minute 59 is genuinely free (confirmed against all existing caller crons and the reserved-slot comment in originweave-hourly-review-repair.yml). Worth tidying for accuracy but not a functional issue.

Open in Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📝 Info: Cron minute 59 is unique among callers

Across all *hourly-review-repair.yml callers, minute 59 is unused; the nearest is orgmetra at 58. No scheduling collision is introduced.

Open in Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.


concurrency:
group: semantic-data-portal-hourly-review-repair
# A later heartbeat must not cancel in-flight catalog or governance RCA.
cancel-in-progress: false

permissions:
contents: read

jobs:
dispatch-review-repair:
permissions:
contents: read
id-token: write
uses: ./.github/workflows/pr-review-fix-scheduler.yml
with:
target_repository: ContextualWisdomLab/semantic-data-portal
base_branch: main
max_prs: "50"
max_dispatches: "1"
retry_hours: "2"
secrets:
PR_REVIEW_MERGE_TOKEN: ${{ secrets.PR_REVIEW_MERGE_TOKEN }}
OPENCODE_APPROVE_TOKEN: ${{ secrets.OPENCODE_APPROVE_TOKEN }}
13 changes: 10 additions & 3 deletions ARCHITECTURE.md
Original file line number Diff line number Diff line change
Expand Up @@ -38,6 +38,12 @@ only established scheduler credentials, and grants job-scoped
16. It names `ContextualWisdomLab/nonnest2` and protected `master`, maps
only established scheduler credentials, and grants job-scoped
`id-token: write`. The reusable engine stays product-neutral.
## semantic-data-portal hourly caller
Comment on lines 40 to +41

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📝 Info: Missing blank line before new ARCHITECTURE.md heading

The new ## semantic-data-portal hourly caller heading at ARCHITECTURE.md is inserted directly after the end of the preceding nonnest2 paragraph (ARCHITECTURE.md) with no blank line, unlike every other section in the file (e.g. the nonnest2 heading at line 35 has surrounding blank lines). GitHub-flavored Markdown still renders an ATX heading that interrupts a paragraph, so this renders correctly, but it breaks the established formatting convention in this document. Cosmetic only.

Open in Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.


`semantic-data-portal-hourly-review-repair.yml` is a thin, read-only caller
at minute 59. It names `ContextualWisdomLab/semantic-data-portal` and
protected `main`, maps only established scheduler credentials, and grants
job-scoped `id-token: write`. The reusable engine stays product-neutral.

## Hourly NVIDIA NIM repair gate

Expand Down Expand Up @@ -66,9 +72,10 @@ The worker checks out helpers at `${{ github.sha }}` so a later default-branch
push cannot replace privileged scripts after dispatch (CWE-367). Repair binds
`NVIDIA_NIM_API_KEY`, never `COPILOT_GITHUB_TOKEN`.

Product callers stagger Clearfolio at minute 23, DiskSage at minute 37, and
fast-mlsirm at minute 49. Each caller is read-only, dispatches at most one
repair, and delegates all privileged logic to the same sealed scheduler.
Product callers stagger Clearfolio at minute 23, DiskSage at minute 37,
fast-mlsirm at minute 49, and semantic-data-portal at minute 59. Each
caller is read-only, dispatches at most one repair, and delegates all
privileged logic to the same sealed scheduler.

## Exact-artifact SBOM attestation

Expand Down
1 change: 1 addition & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,7 @@ Semantic Versioning where the repository publishes a release.
- Added an hourly organization commercial-readiness coordinator that discovers writable repositories, honors enabled dedicated writer leases and fully paginated live writer runs, refetches exact repository/workflow/run/PR state before dispatch, rotates bounded review-repair and opt-in NVIDIA OpenCode product-development targets, fails nonzero on fleet-wide inspection or dispatch outages, retains three-day JSON receipts, and keeps the existing 15-minute merge scheduler authoritative.
- Added a dedicated Quarantine Sandbox Runtime hourly caller at minute 14 that targets protected `develop`, dispatches at most one exact-head repair, applies a two-hour same-head retry floor, preserves non-cancelling single-flight execution, and maps only the established scheduler credentials with job-scoped OIDC.
- Added a dedicated OriginWeave hourly caller that invokes the product-neutral central scheduler with the exact repository, protected `main` branch, one-dispatch budget, two-hour same-head retry floor, non-cancelling single-flight heartbeat, job-scoped OIDC, and only the established scheduler credentials.
- Added a dedicated semantic-data-portal hourly caller that invokes the product-neutral central scheduler with the exact repository, protected `main` branch, one-dispatch budget, two-hour same-head retry floor, non-cancelling single-flight heartbeat, job-scoped OIDC, and only the established scheduler credentials.
- Added a trusted pull-request comment router for `@cwl-noema-review` and review-only `@opencode-agent` dispatches, with an organization sweep, exact-head receipts, repository allowlisting, fixed runners, immutable checkout pins, and a permanent 100% statement/branch/docstring quality gate.
- Added an organization-owned reusable exact-artifact SBOM attestation boundary that validates inert six-file wheel/sdist evidence, binds CycloneDX 1.7 predicates to exact SHA-256 subjects, signs through least-privilege GitHub artifact attestations, and exports online and offline verification bundles.
- Added exact-base `uv.lock` materialization that reconstructs standalone nested projects with a checksum-pinned official `uv` exporter, isolated frozen/offline execution, strict exact-pin and SHA-256 output validation, and complete Python 3.10/3.14 quality evidence.
Expand Down
2 changes: 2 additions & 0 deletions docs/automation/hourly-review-repair.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,8 @@ engine**.

- `clearfolio-hourly-review-repair.yml` owns Clearfolio's heartbeat at minute 23
of every hour.
- `semantic-data-portal-hourly-review-repair.yml` owns SDP's catalog-plane
heartbeat at minute 59 of every hour.
- `orgmetra-hourly-review-repair.yml` owns Orgmetra's heartbeat at minute 58
of every hour against protected `develop`.
- `pr-review-fix-scheduler.yml` is the reusable, product-neutral scheduler
Expand Down
143 changes: 143 additions & 0 deletions docs/doctoring/semantic-data-portal-hourly-review-caller.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,143 @@
# semantic-data-portal hourly review-repair caller

검토 기준일: **2026-08-17**

## Decision

ContextualWisdomLab operates one protected hourly caller for
`ContextualWisdomLab/semantic-data-portal` (SDP — the higher ontology /
catalog / governance plane above naruon's document KG). The caller runs
at minute 59, delegates to the product-neutral central review-fix
scheduler, inspects at most 50 open pull requests targeting protected
`main`, and dispatches at most one bounded repair per heartbeat.

A paying buyer of the catalog plane would feel live semantic-data-portal
pull requests stalling while hourly NVIDIA NIM repair scanned only
Clearfolio, DiskSage, and fast-mlsirm. Live heads such as
ContextualWisdomLab/semantic-data-portal#61 (DiskSage catalog preview),
ContextualWisdomLab/semantic-data-portal#59 (DiskSage catalog ingestion),
ContextualWisdomLab/semantic-data-portal#58 (Keyverse claim aliases),
and ContextualWisdomLab/semantic-data-portal#35 (SQL source-table
allowlist) target `main` and never enter those other callers.

The caller does not implement review or mutation logic itself.
semantic-data-portal remains standalone; naruon owns the document KG and
imports SDP as a module without owning its catalog validators.
Privileged automation stays in `ContextualWisdomLab/.github`.

## Root-cause analysis and remediation feasibility

The reusable worker performs exact-head root-cause analysis and tests
remediation feasibility before it edits. The reusable worker must:

1. Refetch the exact live head, base, reviews, checks, changed paths, and
writer state.
2. Establish the causal chain rather than repeat the terminal symptom.
3. Enumerate materially distinct minimal remedies.
4. Reject remedies that lack writer authority, cross sealed paths, require
unavailable credentials or protected-setting changes, violate stack
order, cannot be verified, or do not alter the diagnosed cause.
5. Dispatch at most one feasible repair. Otherwise leave the tree
unchanged.

A queued or pending check remains a merge blocker but is not itself a
code finding. The independent non-author approval remains an external
authorization gate and is never synthesized by the repair worker. The
worker cannot approve, merge, release, resolve review findings by
inference, change protection, or manufacture passing checks.

## Cadence and concurrency

The caller uses a single concurrency group and `cancel-in-progress: false`.
This preserves an in-flight bounded RCA instead of discarding catalog or
governance evidence when the next hourly heartbeat arrives. The reusable
scheduler cancels only its own superseded short queue scan.

The caller sets a **two-hour same-head retry floor**. Central OpenCode and
NVIDIA NIM work, plus catalog-ontology or SQL-gate analysis, can
legitimately approach two hours. An hourly redispatch of the same
unchanged head would create duplicate writer pressure rather than faster
remediation.

GitHub scheduled workflows can be delayed under load and execute only
from the default branch. The cron expression is a heartbeat, not a
real-time SLA.

## Credential and model boundary

The caller keeps workflow `GITHUB_TOKEN` at `contents: read` and grants
the reusable job `id-token: write` so the central scheduler can mint the
OpenCode GitHub App token from GitHub OIDC when the mapped PAT is absent
(GitHub, n.d.-c). It maps only `PR_REVIEW_MERGE_TOKEN` and
`OPENCODE_APPROVE_TOKEN`. It never uses `secrets: inherit`, receives
`NVIDIA_NIM_API_KEY`, or introduces `COPILOT_GITHUB_TOKEN`. CWE-250
forbids executing the caller with write or model privileges it does not
need (MITRE, 2026).

Model execution remains inside the central worker. The model credential
is the GitHub Secret `NVIDIA_NIM_API_KEY`; the caller does not receive or
forward it.

Before protected-main activation, the repository variable
`OPENCODE_REPOSITORY_DISPATCH_TARGETS` must contain the exact
`ContextualWisdomLab/semantic-data-portal` target. Missing or mismatched
configuration fails before mutation credential materialization.

## Security, standalone operation, and modularity

The caller adds no semantic-data-portal runtime dependency, database
object, network endpoint, tenant authority, or product credential.
semantic-data-portal continues to run as a standalone catalog and
governance plane. Naruon and other CWL services may consume its ontology
output, but they cannot weaken its exact-head, approval, or security
gates.

## Verification and rollback

Machine-checkable contracts require the exact target/base, minute 59
cadence, non-cancelling single-flight group, one dispatch, two-hour
retry floor, explicit secret mapping, read-only contents plus job-scoped
`id-token: write`, focused path-filter coverage, and absence of model or
Copilot credentials. Independent `pull_request`, `push`, and `compileall`
path blocks must each name the caller, doctoring, or contract they own.

After source integration, closure requires a scheduled or manual
protected-main consumer run proving the exact semantic-data-portal
repository and `main` base. Source checks alone are not
protected-main operational acceptance. Merge still requires zero
unresolved valid findings and a qualifying independent non-author
approval.

Rollback removes the semantic-data-portal caller, its focused test,
doctoring, and central path-filter/documentation entries. It must not
remove scheduler dispatch validation or affect independent product
callers.

## APA 7th references

GitHub, Inc. (n.d.-a). *Events that trigger workflows*. GitHub Docs.
Retrieved August 17, 2026, from
https://docs.github.com/en/actions/reference/workflows-and-actions/events-that-trigger-workflows#schedule

GitHub, Inc. (n.d.-b). *Reuse workflows*. GitHub Docs. Retrieved August
17, 2026, from
https://docs.github.com/en/actions/how-tos/sharing-automations/reuse-workflows

GitHub, Inc. (n.d.-c). *Automatic token authentication*. GitHub Docs.
Retrieved August 17, 2026, from
https://docs.github.com/en/actions/security-for-github-actions/security-guides/automatic-token-authentication#permissions-for-the-github_token

MITRE. (2026). *CWE-250: Execution with unnecessary privileges*.
https://cwe.mitre.org/data/definitions/250.html

National Institute of Standards and Technology. (2022). *Secure software
development framework (SSDF) version 1.1: Recommendations for mitigating
the risk of software vulnerabilities* (NIST Special Publication 800-218).
https://doi.org/10.6028/NIST.SP.800-218

NVIDIA. (n.d.). *NVIDIA NIM for large language models documentation*.
Retrieved August 17, 2026, from
https://docs.nvidia.com/nim/large-language-models/latest/

OpenCode. (n.d.). *OpenCode documentation*. Retrieved August 17, 2026,
from https://opencode.ai/docs/
4 changes: 2 additions & 2 deletions scripts/ci/test_strix_quick_gate.sh
Original file line number Diff line number Diff line change
Expand Up @@ -1506,8 +1506,8 @@ assert_pr_review_merge_scheduler_uses_github_actions_bot_token() {
assert_file_contains "$workflow_file" "github.event_name == 'pull_request_target' && format('pr-{0}', github.event.pull_request.number)" "scheduler scopes pull_request_target concurrency to the active PR"
assert_file_contains "$workflow_file" "github.event_name == 'workflow_run' && github.event.workflow_run.pull_requests[0].number && format('pr-{0}', github.event.workflow_run.pull_requests[0].number)" "scheduler scopes workflow_run concurrency to the completed review PR"
assert_file_contains "$workflow_file" "github.event_name == 'schedule' && format('schedule-{0}', github.event.schedule)" "scheduler isolates the 15-minute organization sweep from the separate 30-minute scheduled scan"
assert_file_contains "$workflow_file" "github.event_name == 'repository_dispatch' && github.run_id" "scheduler keeps manual queue scans isolated per run"
assert_file_contains "$workflow_file" "cancel-in-progress: \${{ github.event_name == 'pull_request_target' || github.event_name == 'pull_request_review' || github.event_name == 'repository_dispatch' }}" "scheduler cancels stale PR/review/manual queue scans instead of accumulating merge/update attempts"
assert_file_contains "$workflow_file" "github.event_name == 'repository_dispatch' && format('repo-dispatch-{0}', github.repository)" "scheduler isolates default-branch manual queue scans by repository"
assert_file_contains "$workflow_file" "cancel-in-progress: \${{ github.event_name == 'pull_request_target' || github.event_name == 'pull_request_review' || github.event_name == 'repository_dispatch' || (github.event_name == 'workflow_run' && !github.event.workflow_run.pull_requests[0].number) }}" "scheduler cancels stale PR/review/manual scans without cancelling PR-linked workflow runs"
assert_file_contains "$workflow_file" "timeout-minutes: 60" "organization sweep has enough headroom to finish the complete repository walk"
assert_file_contains "$workflow_file" "ORG_SWEEP_TRIGGER_REVIEWS: \${{ github.event_name == 'schedule' ||" "scheduled organization sweeps retry missing current-head OpenCode reviews"
assert_file_contains "$workflow_file" "ORG_SWEEP_ENABLE_AUTO_MERGE: \${{ github.event_name == 'schedule' ||" "scheduled organization sweeps merge approved current heads"
Expand Down
Loading
Loading