From 00681e9d5ed60b019e1e02497668ed337833701f Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 28 Aug 2026 14:24:41 +0900 Subject: [PATCH 1/4] fix(ci): allow bounded review request envelopes The contextual-orchestrator server keeps a conservative generic body limit, but Strix and Noema send tool schemas and repository context in one request. Configure an explicit bounded limit for the review sidecar while preserving the library default. Signed-off-by: Seongho Bae --- .../contextual-orchestrator-vendored-sidecar.md | 11 +++++++++++ docs/product-technical-gap-baseline.md | 16 ++++++++++++++++ .../contextual_orchestrator_review_launcher.py | 11 ++++++++++- ...xtual_orchestrator_review_sidecar_contract.py | 7 +++++++ 4 files changed, 44 insertions(+), 1 deletion(-) diff --git a/docs/doctoring/contextual-orchestrator-vendored-sidecar.md b/docs/doctoring/contextual-orchestrator-vendored-sidecar.md index 33d2a73317..52854c5c72 100644 --- a/docs/doctoring/contextual-orchestrator-vendored-sidecar.md +++ b/docs/doctoring/contextual-orchestrator-vendored-sidecar.md @@ -7,6 +7,17 @@ prioritized. - **Decision record:** [`docs/adr/0003-contextual-orchestrator-vendored-free-zdr.md`](adr/0003-contextual-orchestrator-vendored-free-zdr.md) +## 2026-08-28 Strix request envelope + +The first post-#1373 main Strix execution reached the gateway and selected +`openai/orchestrator/free`, but the pinned server rejected the initial agent +request with HTTP 413 (`request_too_large`). The vendored server's generic +`SecurityConfig.max_body_bytes` default is 64 KiB; Strix and Noema requests +include tool schemas and repository context and therefore need a larger, +still-bounded integration envelope. The review launcher now sets an explicit +8 MiB limit for this sidecar only; the library default remains unchanged for +other deployments. A 413 remains fail-closed if a request exceeds that bound. + ## What changed `pr-review-autofix.yml` now provisions the sidecar diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 3565e839ca..33aea2e56e 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -287,6 +287,22 @@ flowchart LR Strix completion and an independently authorized Noema verdict remain separate evidence items. +## 2026-08-28 post-#1373 request-envelope recheck + +- #1373 was merged by `seonghobae` at `8f84b661e468de451ba5c076dc938f342bf52d70` + to exercise the post-merge runtime path. Main Strix run `33143805461` + reached the contextual-orchestrator sidecar and sent the qualified + `openai/orchestrator/free` request, then failed closed with HTTP 413 + `request_too_large` from the pinned gateway. This proves the earlier model + qualification defect was repaired, but the review request envelope was + still smaller than the Strix/Noema tool-and-source context. +- The fix is scoped to the review launcher: use an explicit bounded 8 MiB + `SecurityConfig.max_body_bytes` for the sidecar while preserving the + contextual-orchestrator library's generic 64 KiB default. Noema run + `33143860315` was a successful `workflow_run` event handler but skipped + because the push event had no associated pull request; it is not an LLM + verdict. + ## 5. 실행 루프와 고객의 다음 행동 각 hourly pass는 아래 순서를 유지한다. diff --git a/scripts/ci/contextual_orchestrator_review_launcher.py b/scripts/ci/contextual_orchestrator_review_launcher.py index e8f238ad24..83d8109e9e 100644 --- a/scripts/ci/contextual_orchestrator_review_launcher.py +++ b/scripts/ci/contextual_orchestrator_review_launcher.py @@ -27,6 +27,12 @@ from pathlib import Path +# The vendored server's generic 64 KiB default is intentionally conservative, +# but Strix and Noema send tool schemas plus repository context in one request. +# Keep the review-specific envelope bounded without weakening the library default. +REVIEW_MAX_BODY_BYTES = 8 * 1024 * 1024 + + def _free_report_rows(discovered: list[object]) -> list[dict[str, object]]: """Convert in-process discovered models into free-only report rows. @@ -157,7 +163,10 @@ def main(argv: list[str] | None = None) -> int: orchestrator, host=args.host, port=args.port, - security=SecurityConfig(auth_token=auth_token), + security=SecurityConfig( + auth_token=auth_token, + max_body_bytes=REVIEW_MAX_BODY_BYTES, + ), ) return 0 diff --git a/tests/test_contextual_orchestrator_review_sidecar_contract.py b/tests/test_contextual_orchestrator_review_sidecar_contract.py index d80525d348..de940c88db 100644 --- a/tests/test_contextual_orchestrator_review_sidecar_contract.py +++ b/tests/test_contextual_orchestrator_review_sidecar_contract.py @@ -129,6 +129,13 @@ def test_launcher_requires_gateway_token_and_a_provider_credential() -> None: assert "requires at least one provider credential in the KV" in text +def test_launcher_sets_a_bounded_review_request_body_limit() -> None: + """Large review envelopes fit without changing the library's generic default.""" + text = _read(LAUNCHER) + assert "REVIEW_MAX_BODY_BYTES = 8 * 1024 * 1024" in text + assert "max_body_bytes=REVIEW_MAX_BODY_BYTES" in text + + def test_autofix_workflow_provisions_sidecar_with_all_five_secrets() -> None: """The write-capable autofix path bootstraps the gateway with the five keys.""" workflow = _read(AUTOFIX_WORKFLOW) From bc5afabf24de1e0fca8f6384ddb71362f51c85d5 Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 28 Aug 2026 14:29:39 +0900 Subject: [PATCH 2/4] test(ci): validate pinned review server envelope Signed-off-by: Seongho Bae --- scripts/ci/contextual_orchestrator_review_sidecar.sh | 2 ++ .../test_contextual_orchestrator_review_sidecar_contract.py | 6 ++++++ 2 files changed, 8 insertions(+) diff --git a/scripts/ci/contextual_orchestrator_review_sidecar.sh b/scripts/ci/contextual_orchestrator_review_sidecar.sh index d13e5b2f5a..ff1ffa4773 100644 --- a/scripts/ci/contextual_orchestrator_review_sidecar.sh +++ b/scripts/ci/contextual_orchestrator_review_sidecar.sh @@ -74,6 +74,8 @@ python3 -m pip install --quiet --disable-pip-version-check --no-cache-dir \ -r "$requirements_lock" PYTHONPATH="$ORCHESTRATOR_SOURCE:$ORG_REPO_ROOT" "$(command -v python3)" -c \ 'from contextual_orchestrator.credentials import get_credential; from contextual_orchestrator.model_discovery import discover_all_models, free_discovered_models; from contextual_orchestrator.orchestrator import ModelClient, TaskOrchestrator, load_agents; from contextual_orchestrator.review_gateway import register_review_credentials; from contextual_orchestrator.server import SecurityConfig, serve' +PYTHONPATH="$ORCHESTRATOR_SOURCE:$ORG_REPO_ROOT" "$(command -v python3)" -c \ + 'from contextual_orchestrator.server import SecurityConfig; SecurityConfig(auth_token="contract", max_body_bytes=8 * 1024 * 1024)' discovery_report="$ORCHESTRATOR_WORK/discovery-free.json" zdr_feed="$ORCHESTRATOR_WORK/openrouter-zdr-endpoints.json" diff --git a/tests/test_contextual_orchestrator_review_sidecar_contract.py b/tests/test_contextual_orchestrator_review_sidecar_contract.py index de940c88db..22b74f58a1 100644 --- a/tests/test_contextual_orchestrator_review_sidecar_contract.py +++ b/tests/test_contextual_orchestrator_review_sidecar_contract.py @@ -136,6 +136,12 @@ def test_launcher_sets_a_bounded_review_request_body_limit() -> None: assert "max_body_bytes=REVIEW_MAX_BODY_BYTES" in text +def test_sidecar_validates_the_pinned_server_body_limit_constructor() -> None: + """The exact vendored SHA must accept the review envelope keyword at boot.""" + text = _read(SIDECAR) + assert 'from contextual_orchestrator.server import SecurityConfig; SecurityConfig(auth_token="contract", max_body_bytes=8 * 1024 * 1024)' in text + + def test_autofix_workflow_provisions_sidecar_with_all_five_secrets() -> None: """The write-capable autofix path bootstraps the gateway with the five keys.""" workflow = _read(AUTOFIX_WORKFLOW) From d3e7cee4b01219cb0a93f1a4249049de3bf05b4b Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 28 Aug 2026 14:32:21 +0900 Subject: [PATCH 3/4] refactor(ci): share review envelope limit Signed-off-by: Seongho Bae --- scripts/ci/contextual_orchestrator_review_sidecar.sh | 2 +- tests/test_contextual_orchestrator_review_sidecar_contract.py | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/scripts/ci/contextual_orchestrator_review_sidecar.sh b/scripts/ci/contextual_orchestrator_review_sidecar.sh index ff1ffa4773..fdb300ed29 100644 --- a/scripts/ci/contextual_orchestrator_review_sidecar.sh +++ b/scripts/ci/contextual_orchestrator_review_sidecar.sh @@ -75,7 +75,7 @@ python3 -m pip install --quiet --disable-pip-version-check --no-cache-dir \ PYTHONPATH="$ORCHESTRATOR_SOURCE:$ORG_REPO_ROOT" "$(command -v python3)" -c \ 'from contextual_orchestrator.credentials import get_credential; from contextual_orchestrator.model_discovery import discover_all_models, free_discovered_models; from contextual_orchestrator.orchestrator import ModelClient, TaskOrchestrator, load_agents; from contextual_orchestrator.review_gateway import register_review_credentials; from contextual_orchestrator.server import SecurityConfig, serve' PYTHONPATH="$ORCHESTRATOR_SOURCE:$ORG_REPO_ROOT" "$(command -v python3)" -c \ - 'from contextual_orchestrator.server import SecurityConfig; SecurityConfig(auth_token="contract", max_body_bytes=8 * 1024 * 1024)' + 'from contextual_orchestrator.server import SecurityConfig; from scripts.ci.contextual_orchestrator_review_launcher import REVIEW_MAX_BODY_BYTES; SecurityConfig(auth_token="contract", max_body_bytes=REVIEW_MAX_BODY_BYTES)' discovery_report="$ORCHESTRATOR_WORK/discovery-free.json" zdr_feed="$ORCHESTRATOR_WORK/openrouter-zdr-endpoints.json" diff --git a/tests/test_contextual_orchestrator_review_sidecar_contract.py b/tests/test_contextual_orchestrator_review_sidecar_contract.py index 22b74f58a1..4cc0fb1d45 100644 --- a/tests/test_contextual_orchestrator_review_sidecar_contract.py +++ b/tests/test_contextual_orchestrator_review_sidecar_contract.py @@ -139,7 +139,7 @@ def test_launcher_sets_a_bounded_review_request_body_limit() -> None: def test_sidecar_validates_the_pinned_server_body_limit_constructor() -> None: """The exact vendored SHA must accept the review envelope keyword at boot.""" text = _read(SIDECAR) - assert 'from contextual_orchestrator.server import SecurityConfig; SecurityConfig(auth_token="contract", max_body_bytes=8 * 1024 * 1024)' in text + assert 'from contextual_orchestrator.server import SecurityConfig; from scripts.ci.contextual_orchestrator_review_launcher import REVIEW_MAX_BODY_BYTES; SecurityConfig(auth_token="contract", max_body_bytes=REVIEW_MAX_BODY_BYTES)' in text def test_autofix_workflow_provisions_sidecar_with_all_five_secrets() -> None: From 3d7cf123ea7459b7f0082bb354280288866256db Mon Sep 17 00:00:00 2001 From: Seongho Bae Date: Fri, 28 Aug 2026 14:43:51 +0900 Subject: [PATCH 4/4] docs(ci): record trusted-base review boundary Signed-off-by: Seongho Bae --- docs/product-technical-gap-baseline.md | 24 ++++++++++++++++++++++-- 1 file changed, 22 insertions(+), 2 deletions(-) diff --git a/docs/product-technical-gap-baseline.md b/docs/product-technical-gap-baseline.md index 33aea2e56e..25b5a8061f 100644 --- a/docs/product-technical-gap-baseline.md +++ b/docs/product-technical-gap-baseline.md @@ -240,8 +240,9 @@ flowchart LR ## 2026-08-28 current-main routing and runtime recheck -- Current protected main is `24ee38b097dbfc1a895e1199ade48cff36431d05`, - the merge commit for #1370. #1364 is merged at +- Current protected main is `8f84b661e468de451ba5c076dc938f342bf52d70`, + the merge commit for #1373 (following #1370 at + `24ee38b097dbfc1a895e1199ade48cff36431d05`). #1364 is merged at `f8823a544c3c4c046977f8511f683e85f83eb496`; #1360 is merged at `17052a7ca3c16db90932a4d6036b43165ddee418`. - The current Required OpenCode dispatch, `noema-review.yml`, `strix.yml`, @@ -303,6 +304,25 @@ flowchart LR because the push event had no associated pull request; it is not an LLM verdict. +## 2026-08-28 #1374 trusted-base runtime boundary + +- Follow-up PR #1374 is open at head + `d3e7cee4b01219cb0a93f1a4249049de3bf05b4b`, based on current main + `8f84b661e468de451ba5c076dc938f342bf52d70`. Its launcher sets the bounded + 8 MiB review envelope, and its sidecar boot check validates that keyword + against the exact pinned orchestrator SHA before discovery. +- PR-target Strix run `33145070402` used trusted workflow source SHA + `8f84b661e468de451ba5c076dc938f342bf52d70`, not the PR launcher. It reached + the pinned sidecar and then failed three bounded attempts with HTTP 413 + `request_too_large`; this is evidence of the pre-merge trusted-base path, + not evidence that #1374's launcher setting failed. +- PR-target Noema run `33145070347` also reached the pinned sidecar and set + `orchestrator/free`, then skipped before the LLM call because the current + head had no primary OpenCode approval. Required OpenCode run `33145070315` + failed closed for the same missing current-head verdict. Therefore the + envelope fix still needs a normal governed merge followed by a post-merge + Strix runtime result; no protected completion is claimed here. + ## 5. 실행 루프와 고객의 다음 행동 각 hourly pass는 아래 순서를 유지한다.