Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
37 changes: 37 additions & 0 deletions .github/workflows/embedrelay-hourly-review-repair.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,37 @@
name: EmbedRelay Hourly Review Repair

on:
schedule:
# Minute 20 avoids pg-llm-batch (1), aFIPC (2), kaefa (3), LineageWeave (4),
# codec-carver (5), life-os (6), Wardnet (7), mightyETL (8),
# psychometrics-commons (9), OriginWeave (10), naruon (11),
# DiagramWeave (12), pg-erd-cloud (13), mhtml-etl-gateway (14),
# html4tree (15), nonnest2 (16), orchestrator (17), RankWeave (18),
# noema (19), Clearfolio (23), Keyverse (29), Scopeweave (31),
# DiskSage (37), Appguardrail (41), newsdom-api (43), Inkspan (47),
# fast-mlsirm (49), BandScope (53), and semantic-data-portal (59).
Comment on lines +5 to +12

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📝 Info: Cron reservation comment diverges from in-repo minute assignments

The heartbeat comment attributes minute 14 to mhtml-etl-gateway and minute 18 to RankWeave, but in this repo minute 14 is actually held by quarantine-sandbox-hourly-review-repair.yml and there is no RankWeave caller. This mirrors the same informational style as the nonnest2 caller comment (which also lists org-wide product minute reservations rather than only in-repo callers), so it is documentation drift rather than a functional bug. Worth confirming these org-wide minute reservations are still accurate.

Open in Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

- cron: "20 * * * *"

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📝 Info: Minute 20 cron slot is unique and collision-free

The new caller uses cron: "20 * * * *". Checking all existing hourly review-repair callers, the minute slots in use are 10, 14, 16, 21, 23, 27, 37, 43, 49, 53 — minute 20 is unused, so this does not collide with any sibling caller. The comment enumerating avoided minutes is informational only and does not affect scheduling.

Open in Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.


concurrency:
group: embedrelay-hourly-review-repair
# A later heartbeat must not cancel an in-flight embedding-swap RCA.
cancel-in-progress: false

permissions:
contents: read

jobs:
dispatch-review-repair:
permissions:
contents: read
id-token: write
uses: ./.github/workflows/pr-review-fix-scheduler.yml
with:
target_repository: ContextualWisdomLab/EmbedRelay
base_branch: main
max_prs: "50"
max_dispatches: "1"
retry_hours: "2"
secrets:
PR_REVIEW_MERGE_TOKEN: ${{ secrets.PR_REVIEW_MERGE_TOKEN }}
OPENCODE_APPROVE_TOKEN: ${{ secrets.OPENCODE_APPROVE_TOKEN }}
Comment on lines +28 to +37

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📝 Info: Caller inputs match reusable scheduler contract

The new caller forwards target_repository, base_branch, max_prs, max_dispatches, retry_hours and two secrets. All of these are declared string/secret inputs on .github/workflows/pr-review-fix-scheduler.yml:11-62, and the shape exactly matches the sibling callers (originweave/nonnest2). Permissions (contents: read at workflow scope, id-token: write at job scope) and cancel-in-progress: false also match the established pattern, so the caller is contract-consistent.

Open in Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

7 changes: 7 additions & 0 deletions .github/workflows/hourly-nvidia-nim-review-repair.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,7 @@ on:
- .github/workflows/orgmetra-hourly-review-repair.yml
- .github/workflows/originweave-hourly-review-repair.yml
- .github/workflows/quarantine-sandbox-hourly-review-repair.yml
- .github/workflows/embedrelay-hourly-review-repair.yml
- scripts/ci/pr_review_conflict_scope.py
- scripts/ci/pr_review_autofix_context.py
- tests/test_bandscope_hourly_review_caller.py
Expand All @@ -29,6 +30,7 @@ on:
- tests/test_orgmetra_hourly_review_caller.py
- tests/test_originweave_hourly_review_caller.py
- tests/test_quarantine_sandbox_hourly_review_caller.py
- tests/test_embedrelay_hourly_review_caller.py
- tests/test_hourly_autofix_context_quality_gate.py
- tests/test_pr_review_conflict_scope.py
- tests/test_pr_review_conflict_scope_control_files.py
Expand All @@ -54,6 +56,7 @@ on:
- docs/doctoring/orgmetra-hourly-review-caller.md
- docs/doctoring/originweave-hourly-review-caller.md
- docs/doctoring/quarantine-sandbox-hourly-review-caller.md
- docs/doctoring/embedrelay-hourly-review-caller.md
push:
paths:
- .github/workflows/pr-review-fix-scheduler.yml
Expand All @@ -70,6 +73,7 @@ on:
- .github/workflows/orgmetra-hourly-review-repair.yml
- .github/workflows/originweave-hourly-review-repair.yml
- .github/workflows/quarantine-sandbox-hourly-review-repair.yml
- .github/workflows/embedrelay-hourly-review-repair.yml
- scripts/ci/pr_review_conflict_scope.py
- scripts/ci/pr_review_autofix_context.py
- tests/test_bandscope_hourly_review_caller.py
Expand All @@ -82,6 +86,7 @@ on:
- tests/test_orgmetra_hourly_review_caller.py
- tests/test_originweave_hourly_review_caller.py
- tests/test_quarantine_sandbox_hourly_review_caller.py
- tests/test_embedrelay_hourly_review_caller.py
- tests/test_hourly_autofix_context_quality_gate.py
- tests/test_pr_review_conflict_scope.py
- tests/test_pr_review_conflict_scope_control_files.py
Expand All @@ -107,6 +112,7 @@ on:
- docs/doctoring/orgmetra-hourly-review-caller.md
- docs/doctoring/originweave-hourly-review-caller.md
- docs/doctoring/quarantine-sandbox-hourly-review-caller.md
- docs/doctoring/embedrelay-hourly-review-caller.md

permissions:
contents: read
Expand Down Expand Up @@ -164,6 +170,7 @@ jobs:
tests/test_orgmetra_hourly_review_caller.py \
tests/test_originweave_hourly_review_caller.py \
tests/test_quarantine_sandbox_hourly_review_caller.py \
tests/test_embedrelay_hourly_review_caller.py \

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📝 Info: Path-filter and compileall additions are consistent across all three blocks

The caller, its doctoring, and its contract test were added to both the pull_request and push path filters, and only the test was added to the compileall list — matching the invariants asserted by test_embedrelay_hourly_review_caller.py (caller not in compileall_paths, doctoring not in compileall_paths, contract in compileall_paths). Inputs (target_repository, base_branch, max_prs, max_dispatches, retry_hours) all match the reusable scheduler's declared workflow_call inputs.

Open in Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

tests/test_pr_review_conflict_scope_control_files.py \
tests/test_hourly_autofix_context_quality_gate.py \
tests/test_pr_review_conflict_scope_git_executable.py \
Expand Down
1 change: 1 addition & 0 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,4 +7,5 @@ Materialize accepts only exact SHA-256 pins or a bounded relative `-r` include (
Conflict-scope roots fail closed when the immediate parent directory is a symbolic link.
OriginWeave hourly NVIDIA NIM repair is a thin caller at minute 10. See [`docs/doctoring/originweave-hourly-review-caller.md`](docs/doctoring/originweave-hourly-review-caller.md).
nonnest2 hourly NVIDIA NIM repair is a thin caller at minute 16. See [`docs/doctoring/nonnest2-hourly-review-caller.md`](docs/doctoring/nonnest2-hourly-review-caller.md).
EmbedRelay hourly NVIDIA NIM repair is a thin caller at minute 20. See [`docs/doctoring/embedrelay-hourly-review-caller.md`](docs/doctoring/embedrelay-hourly-review-caller.md).
The materialization contract is also covered by [`docs/doctoring/exact-artifact-sbom-attestation.md`](docs/doctoring/exact-artifact-sbom-attestation.md).
7 changes: 7 additions & 0 deletions ARCHITECTURE.md
Original file line number Diff line number Diff line change
Expand Up @@ -39,6 +39,13 @@ only established scheduler credentials, and grants job-scoped
only established scheduler credentials, and grants job-scoped
`id-token: write`. The reusable engine stays product-neutral.

## EmbedRelay hourly caller

`embedrelay-hourly-review-repair.yml` is a thin, read-only caller at minute
20. It names `ContextualWisdomLab/EmbedRelay` and protected `main`, maps
Comment thread
seonghobae marked this conversation as resolved.
only established scheduler credentials, and grants job-scoped
`id-token: write`. The reusable engine stays product-neutral.

## Hourly NVIDIA NIM repair gate

```mermaid
Expand Down
2 changes: 1 addition & 1 deletion CLAUDE.md
Original file line number Diff line number Diff line change
Expand Up @@ -118,7 +118,7 @@ repeatable compile command.
without running the test suite will break CI.
- **100% coverage and 100% docstrings on `scripts/ci/`** are hard gates, not aspirations. New helper
code needs matching tests and docstrings.
- **Product hourly callers** stay thin. Do not hard-code OriginWeave, naruon, or Keyverse
- **Product hourly callers** stay thin. Do not hard-code EmbedRelay, naruon, or Keyverse

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📝 Info: CLAUDE.md rule example change is only asserted by the new test

The Product hourly callers stay thin rule swapped the example product from OriginWeave to EmbedRelay. A grep confirms no other test references this CLAUDE.md line — only test_embedrelay_hourly_review_caller.py asserts it — so the change does not break existing contract tests. The rule remains semantically equivalent (an illustrative do-not-hard-code list).

Open in Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

into `pr-review-fix-scheduler.yml`. The model credential remains `NVIDIA_NIM_API_KEY`
on the worker, never `COPILOT_GITHUB_TOKEN`.
- **`pull_request_target` trust boundary.** The required review workflows run the *base branch's*
Expand Down
136 changes: 136 additions & 0 deletions docs/doctoring/embedrelay-hourly-review-caller.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,136 @@
# EmbedRelay hourly review-repair caller

검토 기준일: **2026-08-17**

## Decision

ContextualWisdomLab operates one protected hourly caller for
`ContextualWisdomLab/EmbedRelay` (swap embedding models without stopping
retrieval). The caller runs at minute 20, delegates to the
product-neutral central review-fix scheduler, inspects at most 50 open
pull requests targeting protected `main`, and dispatches at most one
bounded repair per heartbeat.

A paying buyer of live retrieval continuity would feel EmbedRelay pull
requests stalling while hourly NVIDIA NIM repair scanned only Clearfolio,
DiskSage, and fast-mlsirm. The live head
ContextualWisdomLab/EmbedRelay#3 (retire protected-main M1 materializer)
targets `main` and never enters those other callers.

The caller does not implement review or mutation logic itself.
EmbedRelay remains standalone; naruon and RankWeave consume embeddings
without owning the swap runtime. Privileged automation stays in
`ContextualWisdomLab/.github`.

## Root-cause analysis and remediation feasibility

The reusable worker performs exact-head root-cause analysis and tests
remediation feasibility before it edits. The reusable worker must:

1. Refetch the exact live head, base, reviews, checks, changed paths, and
writer state.
2. Establish the causal chain rather than repeat the terminal symptom.
3. Enumerate materially distinct minimal remedies.
4. Reject remedies that lack writer authority, cross sealed paths, require
unavailable credentials or protected-setting changes, violate stack
order, cannot be verified, or do not alter the diagnosed cause.
5. Dispatch at most one feasible repair. Otherwise leave the tree
unchanged.

A queued or pending check remains a merge blocker but is not itself a
code finding. The independent non-author approval remains an external
authorization gate and is never synthesized by the repair worker. The
worker cannot approve, merge, release, resolve review findings by
inference, change protection, or manufacture passing checks.

## Cadence and concurrency

The caller uses a single concurrency group and `cancel-in-progress: false`.
This preserves an in-flight bounded RCA instead of discarding embedding
evidence when the next hourly heartbeat arrives. The reusable scheduler
cancels only its own superseded short queue scan.

The caller sets a **two-hour same-head retry floor**. Central OpenCode and
NVIDIA NIM work, plus materializer retirement analysis, can legitimately
approach two hours. An hourly redispatch of the same unchanged head
would create duplicate writer pressure rather than faster remediation.

GitHub scheduled workflows can be delayed under load and execute only
from the default branch. The cron expression is a heartbeat, not a
real-time SLA.

## Credential and model boundary

The caller keeps workflow `GITHUB_TOKEN` at `contents: read` and grants
the reusable job `id-token: write` so the central scheduler can mint the
OpenCode GitHub App token from GitHub OIDC when the mapped PAT is absent
(GitHub, n.d.-c). It maps only `PR_REVIEW_MERGE_TOKEN` and
`OPENCODE_APPROVE_TOKEN`. It never uses `secrets: inherit`, receives
`NVIDIA_NIM_API_KEY`, or introduces `COPILOT_GITHUB_TOKEN`. CWE-250
forbids executing the caller with write or model privileges it does not
need (MITRE, 2026).

Model execution remains inside the central worker. The model credential
is the GitHub Secret `NVIDIA_NIM_API_KEY`; the caller does not receive or
forward it.

Before protected-main activation, the repository variable
`OPENCODE_REPOSITORY_DISPATCH_TARGETS` must contain the exact
`ContextualWisdomLab/EmbedRelay` target. Missing or mismatched
configuration fails before mutation credential materialization.

## Security, standalone operation, and modularity

The caller adds no EmbedRelay runtime dependency, database object,
network endpoint, tenant authority, or product credential. EmbedRelay
continues to run as a standalone embedding-swap service. Naruon,
RankWeave, and other CWL services may consume its vectors, but they
cannot weaken its exact-head, approval, or security gates.

## Verification and rollback

Machine-checkable contracts require the exact target/base, minute 20
cadence, non-cancelling single-flight group, one dispatch, two-hour
retry floor, explicit secret mapping, read-only contents plus job-scoped
`id-token: write`, focused path-filter coverage, and absence of model or
Copilot credentials. Independent `pull_request`, `push`, and `compileall`
path blocks must each name the caller, doctoring, or contract they own.

After source integration, closure requires a scheduled or manual
protected-main consumer run proving the exact EmbedRelay repository and
`main` base. Source checks alone are not protected-main operational acceptance.
Merge still requires zero unresolved valid findings and a
qualifying independent non-author approval.

Rollback removes the EmbedRelay caller, its focused test, doctoring, and
central path-filter/documentation entries. It must not remove scheduler
dispatch validation or affect independent product callers.

## APA 7th references

GitHub, Inc. (n.d.-a). *Events that trigger workflows*. GitHub Docs.
Retrieved August 17, 2026, from
https://docs.github.com/en/actions/reference/workflows-and-actions/events-that-trigger-workflows#schedule

GitHub, Inc. (n.d.-b). *Reuse workflows*. GitHub Docs. Retrieved August
17, 2026, from
https://docs.github.com/en/actions/how-tos/sharing-automations/reuse-workflows

GitHub, Inc. (n.d.-c). *Automatic token authentication*. GitHub Docs.
Retrieved August 17, 2026, from
https://docs.github.com/en/actions/security-for-github-actions/security-guides/automatic-token-authentication#permissions-for-the-github_token

MITRE. (2026). *CWE-250: Execution with unnecessary privileges*.
https://cwe.mitre.org/data/definitions/250.html

National Institute of Standards and Technology. (2022). *Secure software
development framework (SSDF) version 1.1: Recommendations for mitigating
the risk of software vulnerabilities* (NIST Special Publication 800-218).
https://doi.org/10.6028/NIST.SP.800-218

NVIDIA. (n.d.). *NVIDIA NIM for large language models documentation*.
Retrieved August 17, 2026, from
https://docs.nvidia.com/nim/large-language-models/latest/

OpenCode. (n.d.). *OpenCode documentation*. Retrieved August 17, 2026,
from https://opencode.ai/docs/
Comment on lines +109 to +136

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📝 Info: Uncited APA references in doctoring

The doctoring lists APA references (GitHub n.d.-a, n.d.-b, NIST 800-218, NVIDIA, OpenCode) that the prose body never cites; only n.d.-c and MITRE 2026 are referenced. Documentation hygiene only.

Open in Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

6 changes: 3 additions & 3 deletions requirements-pip-audit-ci-hashes.txt
Original file line number Diff line number Diff line change
Expand Up @@ -213,9 +213,9 @@ packaging==26.2 \
# via
# pip-audit
# pip-requirements-parser
pip==26.1.2 \
--hash=sha256:382ff9f685ee3bc25864f820aa50505825f10f5458ffff07e30a6d96e5715cab \
--hash=sha256:f49cd134c61cf2fd75e0ce2676db03e4054504a5a4986d00f8299ae632dc4605
pip==26.2.1 \
--hash=sha256:71138adf1f4ca900cdb7d289c21b7494329f2332b6d85f0e1c42108c0384ed3e \
--hash=sha256:f6ad667e89a1fe78046c8f13232b247200f5258d7828f3f7883d660878e0813f
# via pip-api
pip-api==0.0.34 \
--hash=sha256:8b2d7d7c37f2447373aa2cf8b1f60a2f2b27a84e1e9e0294a3f6ef10eb3ba6bb \
Expand Down
Loading
Loading