-
Notifications
You must be signed in to change notification settings - Fork 0
feat(automation): run EmbedRelay hourly NVIDIA NIM review repair #1101
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
51f3fdc
2429d1f
76629bc
0f988db
33a4035
bebc881
77557a9
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,37 @@ | ||
| name: EmbedRelay Hourly Review Repair | ||
|
|
||
| on: | ||
| schedule: | ||
| # Minute 20 avoids pg-llm-batch (1), aFIPC (2), kaefa (3), LineageWeave (4), | ||
| # codec-carver (5), life-os (6), Wardnet (7), mightyETL (8), | ||
| # psychometrics-commons (9), OriginWeave (10), naruon (11), | ||
| # DiagramWeave (12), pg-erd-cloud (13), mhtml-etl-gateway (14), | ||
| # html4tree (15), nonnest2 (16), orchestrator (17), RankWeave (18), | ||
| # noema (19), Clearfolio (23), Keyverse (29), Scopeweave (31), | ||
| # DiskSage (37), Appguardrail (41), newsdom-api (43), Inkspan (47), | ||
| # fast-mlsirm (49), BandScope (53), and semantic-data-portal (59). | ||
| - cron: "20 * * * *" | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 📝 Info: Minute 20 cron slot is unique and collision-free The new caller uses Was this helpful? React with 👍 or 👎 to provide feedback. |
||
|
|
||
| concurrency: | ||
| group: embedrelay-hourly-review-repair | ||
| # A later heartbeat must not cancel an in-flight embedding-swap RCA. | ||
| cancel-in-progress: false | ||
|
|
||
| permissions: | ||
| contents: read | ||
|
|
||
| jobs: | ||
| dispatch-review-repair: | ||
| permissions: | ||
| contents: read | ||
| id-token: write | ||
| uses: ./.github/workflows/pr-review-fix-scheduler.yml | ||
| with: | ||
| target_repository: ContextualWisdomLab/EmbedRelay | ||
| base_branch: main | ||
| max_prs: "50" | ||
| max_dispatches: "1" | ||
| retry_hours: "2" | ||
| secrets: | ||
| PR_REVIEW_MERGE_TOKEN: ${{ secrets.PR_REVIEW_MERGE_TOKEN }} | ||
| OPENCODE_APPROVE_TOKEN: ${{ secrets.OPENCODE_APPROVE_TOKEN }} | ||
|
Comment on lines
+28
to
+37
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 📝 Info: Caller inputs match reusable scheduler contract The new caller forwards Was this helpful? React with 👍 or 👎 to provide feedback. |
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -17,6 +17,7 @@ on: | |
| - .github/workflows/orgmetra-hourly-review-repair.yml | ||
| - .github/workflows/originweave-hourly-review-repair.yml | ||
| - .github/workflows/quarantine-sandbox-hourly-review-repair.yml | ||
| - .github/workflows/embedrelay-hourly-review-repair.yml | ||
| - scripts/ci/pr_review_conflict_scope.py | ||
| - scripts/ci/pr_review_autofix_context.py | ||
| - tests/test_bandscope_hourly_review_caller.py | ||
|
|
@@ -29,6 +30,7 @@ on: | |
| - tests/test_orgmetra_hourly_review_caller.py | ||
| - tests/test_originweave_hourly_review_caller.py | ||
| - tests/test_quarantine_sandbox_hourly_review_caller.py | ||
| - tests/test_embedrelay_hourly_review_caller.py | ||
| - tests/test_hourly_autofix_context_quality_gate.py | ||
| - tests/test_pr_review_conflict_scope.py | ||
| - tests/test_pr_review_conflict_scope_control_files.py | ||
|
|
@@ -54,6 +56,7 @@ on: | |
| - docs/doctoring/orgmetra-hourly-review-caller.md | ||
| - docs/doctoring/originweave-hourly-review-caller.md | ||
| - docs/doctoring/quarantine-sandbox-hourly-review-caller.md | ||
| - docs/doctoring/embedrelay-hourly-review-caller.md | ||
| push: | ||
| paths: | ||
| - .github/workflows/pr-review-fix-scheduler.yml | ||
|
|
@@ -70,6 +73,7 @@ on: | |
| - .github/workflows/orgmetra-hourly-review-repair.yml | ||
| - .github/workflows/originweave-hourly-review-repair.yml | ||
| - .github/workflows/quarantine-sandbox-hourly-review-repair.yml | ||
| - .github/workflows/embedrelay-hourly-review-repair.yml | ||
| - scripts/ci/pr_review_conflict_scope.py | ||
| - scripts/ci/pr_review_autofix_context.py | ||
| - tests/test_bandscope_hourly_review_caller.py | ||
|
|
@@ -82,6 +86,7 @@ on: | |
| - tests/test_orgmetra_hourly_review_caller.py | ||
| - tests/test_originweave_hourly_review_caller.py | ||
| - tests/test_quarantine_sandbox_hourly_review_caller.py | ||
| - tests/test_embedrelay_hourly_review_caller.py | ||
| - tests/test_hourly_autofix_context_quality_gate.py | ||
| - tests/test_pr_review_conflict_scope.py | ||
| - tests/test_pr_review_conflict_scope_control_files.py | ||
|
|
@@ -107,6 +112,7 @@ on: | |
| - docs/doctoring/orgmetra-hourly-review-caller.md | ||
| - docs/doctoring/originweave-hourly-review-caller.md | ||
| - docs/doctoring/quarantine-sandbox-hourly-review-caller.md | ||
| - docs/doctoring/embedrelay-hourly-review-caller.md | ||
|
|
||
| permissions: | ||
| contents: read | ||
|
|
@@ -164,6 +170,7 @@ jobs: | |
| tests/test_orgmetra_hourly_review_caller.py \ | ||
| tests/test_originweave_hourly_review_caller.py \ | ||
| tests/test_quarantine_sandbox_hourly_review_caller.py \ | ||
| tests/test_embedrelay_hourly_review_caller.py \ | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 📝 Info: Path-filter and compileall additions are consistent across all three blocks The caller, its doctoring, and its contract test were added to both the Was this helpful? React with 👍 or 👎 to provide feedback. |
||
| tests/test_pr_review_conflict_scope_control_files.py \ | ||
| tests/test_hourly_autofix_context_quality_gate.py \ | ||
| tests/test_pr_review_conflict_scope_git_executable.py \ | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -118,7 +118,7 @@ repeatable compile command. | |
| without running the test suite will break CI. | ||
| - **100% coverage and 100% docstrings on `scripts/ci/`** are hard gates, not aspirations. New helper | ||
| code needs matching tests and docstrings. | ||
| - **Product hourly callers** stay thin. Do not hard-code OriginWeave, naruon, or Keyverse | ||
| - **Product hourly callers** stay thin. Do not hard-code EmbedRelay, naruon, or Keyverse | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 📝 Info: CLAUDE.md rule example change is only asserted by the new test The Was this helpful? React with 👍 or 👎 to provide feedback. |
||
| into `pr-review-fix-scheduler.yml`. The model credential remains `NVIDIA_NIM_API_KEY` | ||
| on the worker, never `COPILOT_GITHUB_TOKEN`. | ||
| - **`pull_request_target` trust boundary.** The required review workflows run the *base branch's* | ||
|
|
||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,136 @@ | ||
| # EmbedRelay hourly review-repair caller | ||
|
|
||
| 검토 기준일: **2026-08-17** | ||
|
|
||
| ## Decision | ||
|
|
||
| ContextualWisdomLab operates one protected hourly caller for | ||
| `ContextualWisdomLab/EmbedRelay` (swap embedding models without stopping | ||
| retrieval). The caller runs at minute 20, delegates to the | ||
| product-neutral central review-fix scheduler, inspects at most 50 open | ||
| pull requests targeting protected `main`, and dispatches at most one | ||
| bounded repair per heartbeat. | ||
|
|
||
| A paying buyer of live retrieval continuity would feel EmbedRelay pull | ||
| requests stalling while hourly NVIDIA NIM repair scanned only Clearfolio, | ||
| DiskSage, and fast-mlsirm. The live head | ||
| ContextualWisdomLab/EmbedRelay#3 (retire protected-main M1 materializer) | ||
| targets `main` and never enters those other callers. | ||
|
|
||
| The caller does not implement review or mutation logic itself. | ||
| EmbedRelay remains standalone; naruon and RankWeave consume embeddings | ||
| without owning the swap runtime. Privileged automation stays in | ||
| `ContextualWisdomLab/.github`. | ||
|
|
||
| ## Root-cause analysis and remediation feasibility | ||
|
|
||
| The reusable worker performs exact-head root-cause analysis and tests | ||
| remediation feasibility before it edits. The reusable worker must: | ||
|
|
||
| 1. Refetch the exact live head, base, reviews, checks, changed paths, and | ||
| writer state. | ||
| 2. Establish the causal chain rather than repeat the terminal symptom. | ||
| 3. Enumerate materially distinct minimal remedies. | ||
| 4. Reject remedies that lack writer authority, cross sealed paths, require | ||
| unavailable credentials or protected-setting changes, violate stack | ||
| order, cannot be verified, or do not alter the diagnosed cause. | ||
| 5. Dispatch at most one feasible repair. Otherwise leave the tree | ||
| unchanged. | ||
|
|
||
| A queued or pending check remains a merge blocker but is not itself a | ||
| code finding. The independent non-author approval remains an external | ||
| authorization gate and is never synthesized by the repair worker. The | ||
| worker cannot approve, merge, release, resolve review findings by | ||
| inference, change protection, or manufacture passing checks. | ||
|
|
||
| ## Cadence and concurrency | ||
|
|
||
| The caller uses a single concurrency group and `cancel-in-progress: false`. | ||
| This preserves an in-flight bounded RCA instead of discarding embedding | ||
| evidence when the next hourly heartbeat arrives. The reusable scheduler | ||
| cancels only its own superseded short queue scan. | ||
|
|
||
| The caller sets a **two-hour same-head retry floor**. Central OpenCode and | ||
| NVIDIA NIM work, plus materializer retirement analysis, can legitimately | ||
| approach two hours. An hourly redispatch of the same unchanged head | ||
| would create duplicate writer pressure rather than faster remediation. | ||
|
|
||
| GitHub scheduled workflows can be delayed under load and execute only | ||
| from the default branch. The cron expression is a heartbeat, not a | ||
| real-time SLA. | ||
|
|
||
| ## Credential and model boundary | ||
|
|
||
| The caller keeps workflow `GITHUB_TOKEN` at `contents: read` and grants | ||
| the reusable job `id-token: write` so the central scheduler can mint the | ||
| OpenCode GitHub App token from GitHub OIDC when the mapped PAT is absent | ||
| (GitHub, n.d.-c). It maps only `PR_REVIEW_MERGE_TOKEN` and | ||
| `OPENCODE_APPROVE_TOKEN`. It never uses `secrets: inherit`, receives | ||
| `NVIDIA_NIM_API_KEY`, or introduces `COPILOT_GITHUB_TOKEN`. CWE-250 | ||
| forbids executing the caller with write or model privileges it does not | ||
| need (MITRE, 2026). | ||
|
|
||
| Model execution remains inside the central worker. The model credential | ||
| is the GitHub Secret `NVIDIA_NIM_API_KEY`; the caller does not receive or | ||
| forward it. | ||
|
|
||
| Before protected-main activation, the repository variable | ||
| `OPENCODE_REPOSITORY_DISPATCH_TARGETS` must contain the exact | ||
| `ContextualWisdomLab/EmbedRelay` target. Missing or mismatched | ||
| configuration fails before mutation credential materialization. | ||
|
|
||
| ## Security, standalone operation, and modularity | ||
|
|
||
| The caller adds no EmbedRelay runtime dependency, database object, | ||
| network endpoint, tenant authority, or product credential. EmbedRelay | ||
| continues to run as a standalone embedding-swap service. Naruon, | ||
| RankWeave, and other CWL services may consume its vectors, but they | ||
| cannot weaken its exact-head, approval, or security gates. | ||
|
|
||
| ## Verification and rollback | ||
|
|
||
| Machine-checkable contracts require the exact target/base, minute 20 | ||
| cadence, non-cancelling single-flight group, one dispatch, two-hour | ||
| retry floor, explicit secret mapping, read-only contents plus job-scoped | ||
| `id-token: write`, focused path-filter coverage, and absence of model or | ||
| Copilot credentials. Independent `pull_request`, `push`, and `compileall` | ||
| path blocks must each name the caller, doctoring, or contract they own. | ||
|
|
||
| After source integration, closure requires a scheduled or manual | ||
| protected-main consumer run proving the exact EmbedRelay repository and | ||
| `main` base. Source checks alone are not protected-main operational acceptance. | ||
| Merge still requires zero unresolved valid findings and a | ||
| qualifying independent non-author approval. | ||
|
|
||
| Rollback removes the EmbedRelay caller, its focused test, doctoring, and | ||
| central path-filter/documentation entries. It must not remove scheduler | ||
| dispatch validation or affect independent product callers. | ||
|
|
||
| ## APA 7th references | ||
|
|
||
| GitHub, Inc. (n.d.-a). *Events that trigger workflows*. GitHub Docs. | ||
| Retrieved August 17, 2026, from | ||
| https://docs.github.com/en/actions/reference/workflows-and-actions/events-that-trigger-workflows#schedule | ||
|
|
||
| GitHub, Inc. (n.d.-b). *Reuse workflows*. GitHub Docs. Retrieved August | ||
| 17, 2026, from | ||
| https://docs.github.com/en/actions/how-tos/sharing-automations/reuse-workflows | ||
|
|
||
| GitHub, Inc. (n.d.-c). *Automatic token authentication*. GitHub Docs. | ||
| Retrieved August 17, 2026, from | ||
| https://docs.github.com/en/actions/security-for-github-actions/security-guides/automatic-token-authentication#permissions-for-the-github_token | ||
|
|
||
| MITRE. (2026). *CWE-250: Execution with unnecessary privileges*. | ||
| https://cwe.mitre.org/data/definitions/250.html | ||
|
|
||
| National Institute of Standards and Technology. (2022). *Secure software | ||
| development framework (SSDF) version 1.1: Recommendations for mitigating | ||
| the risk of software vulnerabilities* (NIST Special Publication 800-218). | ||
| https://doi.org/10.6028/NIST.SP.800-218 | ||
|
|
||
| NVIDIA. (n.d.). *NVIDIA NIM for large language models documentation*. | ||
| Retrieved August 17, 2026, from | ||
| https://docs.nvidia.com/nim/large-language-models/latest/ | ||
|
|
||
| OpenCode. (n.d.). *OpenCode documentation*. Retrieved August 17, 2026, | ||
| from https://opencode.ai/docs/ | ||
|
Comment on lines
+109
to
+136
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. |
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
📝 Info: Cron reservation comment diverges from in-repo minute assignments
The heartbeat comment attributes minute 14 to
mhtml-etl-gatewayand minute 18 toRankWeave, but in this repo minute 14 is actually held byquarantine-sandbox-hourly-review-repair.ymland there is no RankWeave caller. This mirrors the same informational style as the nonnest2 caller comment (which also lists org-wide product minute reservations rather than only in-repo callers), so it is documentation drift rather than a functional bug. Worth confirming these org-wide minute reservations are still accurate.Was this helpful? React with 👍 or 👎 to provide feedback.