fix(governance): enforce satisfiable solo-maintainer rulesets - #1176
fix(governance): enforce satisfiable solo-maintainer rulesets#1176seonghobae wants to merge 127 commits into
Conversation
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: 📝 WalkthroughWalkthroughChanges에이전트 멘션 동시성
중앙 required-workflow 적용 범위
Estimated code review effort: 2 (Simple) | ~10 minutes Merge Risk: 🟡 Moderate · up to This PR expands central governance reviews to stacked branches, but its validation currently permits malformed branch-scope configurations that could allow required review coverage to be missed without detection. The audit contract and regression tests should be tightened before merging. 🚥 Pre-merge checks | ✅ 3 | ❌ 2❌ Failed checks (2 warnings)
✅ Passed checks (3 passed)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Current-head validation at
The full central suite had prior 100% evidence on the unchanged main source; this PR adds only the scoped audit/docs/ADR/test contract. Hosted current-head Checks and two qualifying independent approvals remain required; no bypass or self-approval. |
|
Successor current-head validation at
The documentation-only successor preserves the implementation proof; stale predecessor-head review evidence does not count. A fresh exact-head independent review and current hosted Checks remain required before merge. |
|
Exact current head is now |
|
Current-head validation for bc2c93a: verified the live organization ruleset 18156473 is active with ref_name.include=[~ALL], and the PR aligns the audit code, regression fixture, ADR, and operator rollout ledger with stacked pull-request coverage. Passed: 16 central ruleset audit tests, Ruff, compileall, and git diff --check. Please review this exact head; merge remains gated on an independent non-author approval and terminal protected checks. |
|
@opencode-agent Please review the current PR head bc2c93a. Verify the live ruleset alignment, stacked-PR scope audit, changed-file evidence, current mergeability, and required checks. Do not approve a stale head. |
|
@opencode-agent review exact current HEAD bc2c93a. Inspect the complete diff, validate security and regression behavior, and publish only evidence bound to this SHA. Do not transfer predecessor approval, modify the branch, or merge. |
|
@opencode-agent please review exact current HEAD |
|
@cwl-noema-review please independently review exact current HEAD |
|
Reproduced and fixed the central router Check failure at exact HEAD |
|
@cwl-noema-review independently re-review exact current HEAD |
|
Exact-head causal repair evidence for
Hosted exact-head workflows and independent formal review remain separate non-passing gates until terminal evidence exists. |
|
Current-head validation for |
|
@opencode-agent review\nHead SHA: aa63517\nReview current HEAD only; check ruleset scope, stacked-PR required workflows, workflow permissions, and all changed tests/docs. Re-run after any push. |
|
Current-head validation for |
|
@opencode-agent review\nHead SHA: aa63517\nReview this exact head only, including least-privilege permissions, repository-dispatch authorization, and all changed queue/idempotency contracts. Re-run after any push. |
|
Exact-head verification for the stacked central workflow governance change. Current pushed head: Root cause fixed: GitHub Actions rejects the unsupported Verified at this exact head:
@opencode-agent please perform the independent formal review for current head |
|
Correction to the previous evidence comment: the exact pushed/current PR head is |
…ked-pr-central-required-workflows
|
Queued @opencode-agent for PR #1176 at head |
|
Queued @cwl-noema-review for PR #1176 at head |
Preserve protected main #1625 byte-for-byte in its four owned paths while retaining the solo-maintainer governance writer. No force-push or history rewrite.
Preserve protected main #1466 binary documentation evidence while retaining the seven intended solo-maintainer governance paths. Comparison before merge showed the writer one commit behind and differing from current main only in those seven intended paths. No force-push or history rewrite.
Restore the six protected-main #1466 paths byte-for-byte after ancestry integration exposed that the writer tree still carried predecessor content. This keeps the governance delta limited to its intended seven paths without force-push or history rewrite.
Preserve protected main #1640 documentation cleanup while retaining only the seven intended solo-maintainer governance paths. Fresh pre-merge comparison showed the writer one commit behind and no content delta outside those seven paths. No force-push or history rewrite.
Restore protected main #1640 documentation retirement byte-for-byte after ancestry integration exposed two predecessor documentation paths still present in the writer tree. Keep the final delta limited to the seven intended governance paths.
Integrate ContextualWisdomLab/.github main@7683f1da91f1fc9e046660169f1f7ac4aabcc3c6 without force-push. Preserve the seven governance-owned paths while taking the six queue-hygiene files byte-for-byte from protected main.
|
Ownership split after fresh causal analysis: keep this PR scoped to executable audit/regression/rollout contract. The previously missing settings-application mechanism is now isolated in #1644 ( Do not merge or restack this PR merely because #1644 exists. Its current exact head still needs its own terminal evidence, and #1176 still needs fresh exact-head deterministic/review evidence plus post-reconciliation live payload proof. |
…leset repair Preserve the seven solo-maintainer governance paths from the existing writer while taking all other files byte-for-byte from protected main@cfcde258dc2836838d00982ed812dd3b9d6072ca. This non-rebase two-parent merge retains concurrent queue-coalescing, OpenCode, Noema, Strix and runner-capacity repairs without force-push or history rewrite.
Preserve the owner-plane reconciler's seven unique paths, including RED-first review regressions and their fixes, while taking the complete current #1176 tree as the canonical governance base. This keeps protected main and the solo-maintainer audit repair byte-for-byte current without force-push or rebase.
…leset repair Preserve the seven solo-maintainer governance files from the existing writer while taking every other path from protected main@fb021296afbe7c27e30363627971fc9d36d12979. This non-rebase two-parent merge retains the OpenCode evidence-driven review repair without force-push or predecessor-evidence transfer.
|
Fresh downstream/control-plane revalidation after protected-main movement — 2026-09-02 KST The live protected RED acceptance: before this governance writer can become merge-ready, re-integrate the new protected-main ancestry non-destructively in the existing owner lane, then regenerate all exact-successor-head review/check evidence. Do not transfer the 44b4ea predecessor check set, do not cancel/re-run currently queued jobs merely for latency, and do not use admin bypass. Required GREEN: fresh live-main/head comparison shows no missing protected-main ancestry; diff remains limited to the intended governance paths; review threads and exact-head required checks are re-read; then the settings-authority step still separately proves live organization/repository rulesets match the solo-maintainer contract before the unchanged Orgmetra #88 consumer canary is revalidated. |
|
Fresh protected-main movement invalidated the predecessor alignment evidence again. Current owner truth at re-read:
RED: the current #1176 head is no longer current-main-aligned and its previous exact-head checks/reviews cannot authorize integration after a parent merge. Owner-lane remedy remains non-destructive integration of the exact live protected-main ancestry into this existing branch, with any real conflict resolved at the causal seven-path boundary and no force-push/destructive rebase. Then regenerate all checks/reviews on the successor head. Do not carry predecessor GREEN, do not use admin bypass, and do not mutate the Orgmetra consumer canary merely to create activity. GREEN: fresh live-main/successor-head comparison |
|
LifeOS consumer evidence (fresh 2026-09-01): inherited organization ruleset |
Current purpose — 2026-09-02
This existing writer lane owns the executable ruleset-audit repair for the solo-maintainer governance decision in #772/#1351. Superseded
2 approvals + last-push approvalguidance must not be restored from predecessor comments or evidence.Current exact writer head:
44b4ea473bdd8753e992465c76ce347e02994e5a.Protected
main@fb021296afbe7c27e30363627971fc9d36d12979is integrated without force-push or history rewrite. Fresh comparison isbehind_by=0; the final tree differs from protected main in exactly seven intended governance paths:.github/workflows/audit-central-ruleset.ymldocs/org-required-workflow-rollout.mdscripts/ci/audit_central_required_workflows.pytests/test_central_required_workflow_ruleset_audit.pytests/test_ruleset_audit_completeness_regression.pytests/test_ruleset_merge_method_shape_regression.pytests/test_solo_maintainer_ruleset_policy.pyThe integrated protected-main ancestry includes the merged current-head run coalescer (#1645), Strix required-smoke availability repair (#1650), and evidence-driven OpenCode review-policy repair (#1654). Every check and review must still regenerate on this exact successor head; predecessor evidence does not transfer. Queued or pending current-head runs remain non-passing until terminal success.
Current governance contract
For the one-human-maintainer operating model:
.githubrepository rulesets userequired_approving_review_count = 0while no genuinely independent human reviewer exists;require_last_push_approval = false;require_code_owner_review = falsewhile the sole code owner is also the author;required_reviewersis required; a bot/service/user cannot manufacture human independence;do_not_enforce_on_create=trueremain enforced;OrganizationAdmin/always.This changes only structurally impossible generic human-approval gates. It does not self-approve, invent bot approvals, transfer old evidence, disable semantic/security gates, or authorize protected-branch bypass.
Durable TDD and proof lineage
The regression suite was written before production changes and now fail-closes on synthetic reviewers, code-owner/last-push approval deadlocks, malformed or extra workflows, creation restrictions, malformed merge-method payloads, rebase drift, undeclared rule types and missing/malformed/non-empty bypass evidence. The passing fixtures explicitly state the code-owner policy. Auditor failures are aggregated after successful reads so simultaneous drift is visible. The temporary focused source-fix workflow executed the permanent governance regression set successfully and was removed before this final diff; permanent coverage requires it to remain absent. All current inline review threads are resolved.
Live drift and authorized settings boundary
Fresh full-payload reads on 2026-09-02 still show inherited organization ruleset
18156473active withrequired_approving_review_count = 1,require_code_owner_review = false,require_last_push_approval = false,required_reviewers = [], default-branch-only scope, merge/squash methods, deletion/non-fast-forward protection, andOrganizationAdmin/alwaysbypass. The declared solo-maintainer contract is therefore not live yet.The
.githubrepository ruleset17921150has approval 0/code-owner false/last-push false but still permits rebase and retainsOrganizationAdmin/alwaysbypass.GitHub's REST contract exposes ruleset update endpoints to appropriately privileged identities, but the connected GitHub action surface in this environment exposes ruleset reads and not settings mutation. The repository-metadata reconciler credential is deliberately scoped to metadata/Pages and must not be silently broadened into organization governance authority. #1340 records the privileged owner-plane mutation boundary.
Acceptance requires exact-current-head central checks/reviews, authorized live ruleset reconciliation with no routine bypass/synthetic reviewer/rebase/code-owner drift, a fresh full-payload read, and an unchanged deterministic-GREEN consumer canary.
ContextualWisdomLab/Orgmetra#88@0dc4f09cc3c87829ea1e3a0e3dc0188df07ad8cdremains the canary for proving the ordinary protected path after settings reconciliation. Do not use routine administrator bypass as a substitute.Refs #712, #772, #1200, #1340, #1351.