Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
34 commits
Select commit Hold shift + click to select a range
f3facda
fix(ci): group review catalog admission/diversity by outage domain, n…
claude Aug 31, 2026
0c13cb8
fix(ci): normalize base_url before using it as the outage-domain key
claude Aug 31, 2026
ad3d2ce
fix(ci): stop the shared outage-domain cap from starving one credential
claude Aug 31, 2026
0c90beb
fix(ci): keep tier priority strict during fair admission, fix IPv6 co…
claude Aug 31, 2026
ec6a1e5
fix(ci): stop blanket-stripping OpenRouter rows on evidence_only alone
claude Aug 31, 2026
4adb60e
fix(ci): make the OpenRouter evidence_only exemption self-correcting
claude Aug 31, 2026
e27f7c2
fix(ci): preserve cross-domain priority positions, ignore URL fragmen…
claude Aug 31, 2026
a5f2b29
fix(ci): reconcile #950->#949, gate spend_admitted, close ZDR-bypass …
claude Aug 31, 2026
45b8604
merge: bring main into fix/openrouter-premature-evidence-only-filter
claude Aug 31, 2026
95406d2
test(ci): pin the OpenRouter evidence_only exemption's real boolean o…
claude Aug 31, 2026
9b74577
fix(ci): bound required-workflow-bootstrap awk extraction to its own job
claude Aug 31, 2026
7d693b8
fix(ci): remove grep -q from test_strix_quick_gate.sh pipeline checks
claude Aug 31, 2026
26f374a
Merge branch 'main' into fix/openrouter-premature-evidence-only-filter
seonghobae Aug 31, 2026
40ffd1f
Merge remote-tracking branch 'origin/main' into fix/outage-domain-cat…
claude Sep 1, 2026
fb084b6
fix(ci): bound required-workflow-bootstrap awk extraction to its own job
claude Sep 1, 2026
262a41c
fix(ci): keep the priced-fallback catalog stage domain-diverse
claude Sep 1, 2026
790de01
Merge remote-tracking branch 'origin/main' into fix/outage-domain-cat…
claude Sep 1, 2026
9106f68
test(ci): refresh review-dispatch blob pin and head-advance assertion…
claude Sep 1, 2026
59dc096
docs(changelog): record the priced-fallback domain-diversity fix
claude Sep 1, 2026
2154afa
fix(ci): stop the fallback domain-coverage fix from wasting probe slots
claude Sep 1, 2026
f03ecfa
docs(changelog): correct the fallback fix's mechanism after the revision
claude Sep 1, 2026
1715db0
fix(ci): extend domain-coverage guarantee to the primary auto-pool stage
claude Sep 1, 2026
e52923d
test(ci): revert the head-advance test changes now that main reverted…
claude Sep 1, 2026
93d1a4b
Merge remote-tracking branch 'origin/main' into fix/outage-domain-cat…
claude Sep 1, 2026
54fd95d
Merge remote-tracking branch 'origin/main' into fix/openrouter-premat…
claude Sep 1, 2026
db106d5
test(ci): close main's post-#1546 scheduler coverage regression
claude Sep 1, 2026
85c2469
docs(gap-baseline): record post-#1546 scheduler coverage regression
claude Sep 1, 2026
6f40a06
test(ci): document nested REST fixture helpers
seonghobae Sep 1, 2026
8d93f92
Merge remote-tracking branch 'origin/main' into fix/openrouter-premat…
claude Sep 1, 2026
a5394ef
Merge fix/main-coverage-gap-scheduler-rest-and-live-head (.github#156…
claude Sep 1, 2026
7287643
Merge remote-tracking branch 'origin/fix/openrouter-premature-evidenc…
claude Sep 1, 2026
9e6aa16
fix(ci): scope guarantee_domain_coverage's admission passes to one tier
claude Sep 1, 2026
19dddbb
merge: sync with origin/main (5768f2bd)
claude Sep 1, 2026
1eaa3b3
fix(ci): merge #1474's tier-scoped domain-cap fix with #1587/#1592/#1564
claude Sep 1, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
92 changes: 92 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,30 @@ this file. The format follows Keep a Changelog, and versioned releases follow
Semantic Versioning where the repository publishes a release.

## [Unreleased]
- `scripts/ci/contextual_orchestrator_review_launcher.py`'s `_routable_discovered_models()`
no longer blanket-strips every OpenRouter row on `evidence_only` alone.
`contextual-orchestrator`'s OpenRouter `ProviderModelSource` currently
hardcodes `evidence_only=True` for every discovered model unconditionally
(a confirmed bug, being fixed upstream separately), which was excluding
100% of OpenRouter discovery rows here before
`zdr_policy.is_zdr_model()`'s purpose-built, per-route OpenRouter ZDR-feed
check ever got a chance to evaluate them -- making that already-correct
mechanism dead code for OpenRouter specifically. OpenRouter rows are now
exempt from this exclusion; a genuinely non-servable OpenRouter row is
still excluded by the existing, provider-agnostic chat-capability check
every other provider's rows already go through. `_routable_discovered_models()`
also now excludes a `spend_admitted=False` row the same way it excludes
`evidence_only=True`, so a credit-exhausted priced OpenRouter row cannot
reach `orchestrator/auto`'s served catalog.
- Close a 99% `scripts/ci` coverage regression on protected main: merged #1546 added an
uncovered `live_head_matches` helper, an uncovered no-active/no-stale-runs fall-through in
`prepare_autofix_slot`, and an uncovered "current-head autofix run is already queued or
running" wait path in `pr_review_fix_scheduler.py::inspect_pr`, while the pre-existing
conflicted-draft and conflicted-unauthorized `inspect_pr` returns and the REST
`fetch_workflow_names_by_check_suite_rest` pagination/name-filtering/permission-denied paths
in `pr_review_merge_scheduler.py` remained untested. Every PR rebasing onto main inherited
this failure via the `coverage-evidence` required check regardless of its own diff; this adds
test-only coverage for all of the above with no production code change.
- **Fix `opencode-review.yml` admission gaps around stale/out-of-order events (`#1568`).**
Building on the draft-poll exemption's live PR/head validation, Devin Review found two
further defects. (1) The concurrency group was keyed only by repository and PR number, so
Expand Down Expand Up @@ -237,6 +261,74 @@ Semantic Versioning where the repository publishes a release.
still named the removed `free_family_diversity` evidence field instead of
its `free_account_diversity` replacement, which could send future
monitoring work looking for a field that no longer exists.
- `scripts/ci/contextual_orchestrator_review_policy.py`'s catalog admission
cap and diversity evidence no longer conflate "independent credential
account" with "independent outage domain": `nvidia_nim`/`nvidia_nim_sub`
are independent accounts (may expose different models) but share one
physical upstream endpoint (`https://integrate.api.nvidia.com/v1`), so
they now share one admission-cap budget and count as one outage domain. A
new `free_outage_domain_diversity` report field (additive, alongside the
existing `free_account_diversity`) reflects this for callers deciding
whether a single provider outage could empty the free catalog. Outage-
domain grouping normalizes each row's `base_url` first (lowercasing
scheme/host, dropping an explicit default port, stripping a trailing
slash, and never raising even on a malformed IPv6-bracket URL), so a
formatting difference alone cannot split one physical endpoint into two
domains. Within a shared domain, the admission cap's bounded slots are
now split round-robin across the domain's contending accounts instead of
being consumed entirely by whichever account's rows happen to sort first
-- fixing a narrower starvation bug the outage-domain grouping itself
introduced (one credential could otherwise get zero admissions from a
shared domain even with rows available and cap budget nominally unused
by it). That fairness reordering is now strictly scoped to one admission-
priority tier (cost tier + ZDR status) at a time, never across tiers --
an earlier revision grouped a whole outage domain's rows into one block
regardless of tier, which could drag a lower-priority route (paid,
non-ZDR) ahead of a higher-priority route (free, ZDR) belonging to a
different domain, sometimes dropping a free route for a paid one under a
tight catalog limit. IPv6 host normalization now re-brackets a
colon-bearing host before appending a port, so an explicit-port address
(`[::1]:8443`) and an unrelated literal that merely contains the same
digits (`[::1:8443]`) no longer collapse to one outage domain. The
priced-fallback catalog stage (`orchestrator/auto`'s post-primary-stage
fallback) gets its own domain-diversity fix: with both defaults at 4,
the fallback route budget coincidentally equaled the per-domain cap, so
a single dominant outage domain could exhaust the entire fallback stage
before a genuinely independent domain's row was ever considered (Devin
Review finding). `build_zdr_prioritized_catalog` gains an opt-in
`guarantee_domain_coverage` flag (only the priced-fallback call site
sets it) that admits in two passes instead of one: the first pass
admits at most one row per outage domain, guaranteeing representation;
the second fills any remaining budget from whichever domain's
next-highest-priority row comes first, still bounded by `account_cap`.
A first revision shrank the cap to `fallback_limit // domain_count`
instead, which fixed representation but wasted capacity whenever the
split was uneven (a second Devin Review finding, "fallback quota wastes
probe slots" -- `limit=4` across 3 domains admitted only 3 routes under
a floor of 1); the two-pass approach guarantees both properties at
once. The common single-domain case is unchanged. A third Devin Review
finding caught the identical gap reachable through the *primary*
`auto`-pool stage too, not just the fallback: the review sidecar's real
deployed default is `ORCHESTRATOR_CATALOG_ACCOUNT_CAP=8` (not the
launcher's `DEFAULT_ACCOUNT_CAP=4` fallback, which the sidecar never
leaves the env var unset for), and the primary stage's own route limit
for the `auto` pool is also capped at 8
(`REVIEW_PREFLIGHT_PRIMARY_ROUTE_LIMIT`) -- the same cap-equals-limit
coincidence, just at 8 instead of 4. `guarantee_domain_coverage=True`
now applies to both `build_zdr_prioritized_catalog` call sites in
`main()`.
- `guarantee_domain_coverage`'s two admission passes now run strictly
within one admission-priority tier at a time, in tier order, instead of
across `ordered_rows` as a whole (Devin Review: "domain coverage defeats
ZDR priority") -- without this, a worse-tier row could win a first-pass
"guaranteed representation" seat for its domain ahead of a better-tier
row from an already-represented domain (e.g. two free/ZDR routes in one
domain plus one free/non-ZDR route in an independent domain, `limit=2`,
wrongly admitted one row from each instead of both free/ZDR routes).
This is the same tier-boundary discipline `_fair_admission_order`
already enforces for its own reordering, now applied one level up; the
cumulative-representation and `account_cap` accounting across tiers is
unchanged.
- Noema, Strix, and OpenCode review sidecars now vendor contextual-orchestrator
at `c107e3e52371993aa9c326fcc245e01c41fc3850` and treat every KV credential
as an independent discovery account. Same-vendor credentials no longer
Expand Down
23 changes: 23 additions & 0 deletions docs/adr/0003-contextual-orchestrator-vendored-free-zdr.md
Original file line number Diff line number Diff line change
Expand Up @@ -190,6 +190,29 @@ all five, and auto-optimize routing by cost.
amendment" (above) are closed, without requiring a manual re-audit.
`docs/doctoring/contextual-orchestrator-strix-free-diversity-evidence.md`
records that PR's own reasoning trail.
- **2026-08-31 correction: account diversity is not outage-domain diversity.**
Review during this session found that #1468 (above), in correctly stopping
`nvidia_nim`/`nvidia_nim_sub` from being treated as one *model-catalog*
family, also let `free_account_diversity` and the catalog's admission cap
treat them as two fully independent *outage domains* — they are not: both
resolve to the identical `https://integrate.api.nvidia.com/v1` upstream
(see `PROVIDER_BASE_URLS` in `scripts/ci/zdr_policy.py`, and that table's
own `nvidia_nim_sub` ZDR-scope note). Conflating the two meant a discovery
report whose only free routes were these two credentials reported
`free_account_diversity == 2` — falsely reassuring for exactly the decision
this evidence exists to support (would a single physical outage empty the
free catalog) — and the admission cap let the pair jointly consume up to
twice its intended per-domain budget, crowding out a genuinely independent
provider even when one had free routes available.
`contextual_orchestrator_review_policy.py` now reports a second, distinct
field, `free_outage_domain_diversity`, grouped by each row's own `base_url`
evidence rather than a second hand-maintained provider-name table, and the
admission cap (`account_cap`; the name predates this fix and is kept for
CLI/environment stability) groups by outage domain, not by credential. A
caller deciding whether Strix can safely rely on a strict `orchestrator/free`
pool without the `orchestrator/auto` paid fallback (open PR #1437) should
read `free_outage_domain_diversity`, not `free_account_diversity`, for that
specific decision.
- **2026-08-31 amendment: Noema reviews independently of OpenCode.** Noema no
longer waits for an OpenCode approval, review-thread state, or other check
conclusions before calling the gateway and submitting its current-head
Expand Down
2 changes: 1 addition & 1 deletion docs/product-goal-directive.md
Original file line number Diff line number Diff line change
Expand Up @@ -66,7 +66,7 @@ Per this file's own conflict policy above: this note is the resolution, and `doc

**Note (flagged by CodeRabbit on this PR, 2026-08-30):** section 8's quoted text describes `contextual-orchestrator`'s general product capability — broad model/modality support and all-five-secret auto model discovery as a *design principle for the orchestrator itself*. It does not specify, and must not be read as overriding, which pool each CI consumer routes through: that is governed exclusively by `docs/adr/0003-contextual-orchestrator-vendored-free-zdr.md` and its doctoring records — `OpenCode` and `Noema` use the fail-closed, ZDR-prioritized `orchestrator/free` pool; only `Strix` security analysis uses the provider-diverse `orchestrator/auto` pool; private/internal review targets require an attested ZDR-only catalog and never fall back to a non-ZDR provider. Do not loosen any CI consumer's pool or credential scope on the strength of this section's general wording alone.

**Note (2026-08-30, superseded by the merged pin flip — see the correction below):** an earlier draft of this note said Strix stayed on `orchestrator/auto` pending `free_family_diversity` reaching `>= 2`. That is no longer true and must not be read as current: `.github/workflows/strix.yml` now hardcodes `STRIX_MODEL`/`CONTEXTUAL_ORCHESTRATOR_POOL` to `orchestrator/free` and fails closed on any other value, and ADR-0003's 2026-08-30 amendment records the owner's decision to accept the residual single-outage-domain risk immediately rather than wait for the evidence-gated threshold this note originally described. `free_account_diversity` (`scripts/ci/contextual_orchestrator_review_policy.py`; renamed from `free_family_diversity` once every KV credential became an independent discovery account rather than being grouped into a vendor "family", see #1468) remains useful as ongoing monitoring evidence for that accepted risk, not as a gate blocking the pin.
**Note (2026-08-30, superseded by the merged pin flip — see the correction below):** an earlier draft of this note said Strix stayed on `orchestrator/auto` pending `free_family_diversity` reaching `>= 2`. That is no longer true and must not be read as current: `.github/workflows/strix.yml` now hardcodes `STRIX_MODEL`/`CONTEXTUAL_ORCHESTRATOR_POOL` to `orchestrator/free` and fails closed on any other value, and ADR-0003's 2026-08-30 amendment records the owner's decision to accept the residual single-outage-domain risk immediately rather than wait for the evidence-gated threshold this note originally described. `free_account_diversity` (`scripts/ci/contextual_orchestrator_review_policy.py`; renamed from `free_family_diversity` once every KV credential became an independent discovery account rather than being grouped into a vendor "family", see #1468) remains useful as ongoing monitoring evidence for that accepted risk, not as a gate blocking the pin. **Correction (2026-08-31):** for *this specific* single-outage-domain risk, read `free_outage_domain_diversity`, not `free_account_diversity` — #1468's rename correctly made every KV credential an independent *account*, but `nvidia_nim`/`nvidia_nim_sub` remain one *outage domain* (both resolve to the identical `https://integrate.api.nvidia.com/v1` upstream), so `free_account_diversity` alone can read `2` for a catalog that is, in fact, still exposed to a single provider outage. `free_outage_domain_diversity` is the field that actually answers this note's question.

## 9. Reference libraries, tool invocations, and ecosystem repositories

Expand Down
Loading
Loading