Skip to content

fix(rotation): replay semantic control hardening on current review workflow - #1013

Merged
seonghobae merged 11 commits into
mainfrom
fix/rotation-current-review-984
Aug 24, 2026
Merged

fix(rotation): replay semantic control hardening on current review workflow#1013
seonghobae merged 11 commits into
mainfrom
fix/rotation-current-review-984

Conversation

@seonghobae

Copy link
Copy Markdown
Contributor

Supersedes #984 without changing its corrected product tree.

Exact source head: dcf2ee03f01de100c3571c48ce9b87e769fb7f9c. Repository CI, Security Scan, CodeQL, and Semgrep are terminal-success on this SHA, with no unresolved review threads. The implementation admits rotation/criterion/policy semantic controls before native discovery without caller-controlled text/numeric callback dispatch, while preserving concrete NumPy scalar compatibility through genuine Rust execution.

Rotation objectives, gradients, GPA optimization, multi-start convergence, bootstrap diagnostics, policy scoring, and selection arithmetic remain Rust-owned; Python performs validation/marshalling only.

#984's remaining formal OpenCode CHANGES_REQUESTED is solely central coverage-evidence run 32124695117, created before the current organization .github review/tooling fixes. This successor creates a fresh pull-request event without source churn, force-push, review dismissal, or gate weakening.

@coderabbitai

coderabbitai Bot commented Aug 19, 2026

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

@seonghobae, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 55 minutes

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits within each organization.

For paid Pro and Pro+ reviews, CodeRabbit uses a developer's included PR review attempts over the past 7 days to set the current hourly allowance. At typical activity levels, the full plan allowance applies. Higher sustained activity can lower the allowance until earlier attempts leave the 7-day window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 8b03cf48-0c28-460e-b12d-6c0827b384bb

📥 Commits

Reviewing files that changed from the base of the PR and between 04d0bc2 and dcf2ee0.

📒 Files selected for processing (6)
  • docs/changelog.d/983-rotation-control-boundary.md
  • python/fast_mlsirm/rotation.py
  • python/fast_mlsirm/rotation_selection.py
  • tests/test_rotation_control_callback_safety.py
  • tests/test_rotation_control_numpy_compatibility.py
  • tests/test_rotation_selection_control_callback_safety.py

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@seonghobae
seonghobae enabled auto-merge (squash) August 19, 2026 02:35

Copy link
Copy Markdown
Contributor Author

@opencode-agent @cwl-noema-review Please independently review exact current head dcf2ee03f01de100c3571c48ce9b87e769fb7f9c against live main. Security Scan 32208859790, CodeQL 32208859752, Semgrep 32208859756, and every required Python/Rust/package/fuzz job in CI 32208859785 are terminal-success; the workflow-level CI conclusion is cancelled only because gpu-smoke was cancelled while provisioning Vulkan, the same repository-owned first causal boundary now isolated in #1021. Inline review threads are empty. Verify semantic-control admission is callback-free before native discovery, exact trusted NumPy compatibility remains genuine Rust execution, and rotation/GPA/bootstrap/policy-selection arithmetic stays Rust-owned. Do not transfer #984 predecessor evidence.

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode cannot approve yet because required coverage evidence did not pass.

Review outcome

1. HIGH .github/workflows/opencode-review.yml:1 - Coverage evidence did not prove required test/docstring evidence

  • Problem: The required coverage-evidence job result was failure, so OpenCode cannot establish approval sufficiency for this head.

  • Root cause: Automated approval is only valid when the same-head coverage-evidence job proves supported repository test suites passed and configured docstring gates passed or were advisory, or reports not applicable because no supported source files or package manifests exist. Missing, failed, skipped, unavailable, or unsupported-tooling test evidence is a blocker.

  • Fix: Install or configure the repository test/docstring evidence tooling when source files or package manifests exist, rerun the current-head coverage-evidence job, and approve only after it reports success with required evidence or explicit no-source not-applicable evidence.

  • Regression test: Keep the approval branch checking needs.coverage-evidence.result == success before posting APPROVE, and publish REQUEST_CHANGES when coverage-evidence blocker states such as cancelled, skipped, failed, unsupported-tooling, or below-100 evidence are present.

  • Result: REQUEST_CHANGES

  • Reason: coverage-evidence result was failure, so required test/docstring evidence was not proven for current head dcf2ee03f01de100c3571c48ce9b87e769fb7f9c.

  • Head SHA: dcf2ee03f01de100c3571c48ce9b87e769fb7f9c

  • Workflow run: 32213341852

  • Workflow attempt: 1

Coverage evidence

Coverage evidence job did not run or did not publish coverage evidence.

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Docs: 983-rotation-control-boundary.md"]
  S1 --> I1["operator or user guidance"]
  I1 --> R1["Review risk: Docs: 983-rotation-control-boundary.md"]
  R1 --> V1["docs review"]
  Evidence --> S2["Changed file (2 files)"]
  S2 --> I2["repository behavior"]
  I2 --> R2["Review risk: Changed file (2 files)"]
  R2 --> V2["required checks"]
  Evidence --> S3["Test (3 files)"]
  S3 --> I3["regression suite"]
  I3 --> R3["Review risk: Test (3 files)"]
  R3 --> V3["targeted test run"]
Loading

@opencode-agent

opencode-agent Bot commented Aug 19, 2026

Copy link
Copy Markdown
Contributor

OpenCode Review Overview

  • Head SHA: dcf2ee03f01de100c3571c48ce9b87e769fb7f9c
  • Workflow run: 32217717573
  • Workflow attempt: 1
  • Gate result: REQUEST_CHANGES (approval step)

Pull request overview

OpenCode cannot approve yet because required coverage evidence did not pass.

Review outcome

1. HIGH .github/workflows/opencode-review.yml:1 - Coverage evidence did not prove required test/docstring evidence

  • Problem: The required coverage-evidence job result was failure, so OpenCode cannot establish approval sufficiency for this head.

  • Root cause: Automated approval is only valid when the same-head coverage-evidence job proves supported repository test suites passed and configured docstring gates passed or were advisory, or reports not applicable because no supported source files or package manifests exist. Missing, failed, skipped, unavailable, or unsupported-tooling test evidence is a blocker.

  • Fix: Install or configure the repository test/docstring evidence tooling when source files or package manifests exist, rerun the current-head coverage-evidence job, and approve only after it reports success with required evidence or explicit no-source not-applicable evidence.

  • Regression test: Keep the approval branch checking needs.coverage-evidence.result == success before posting APPROVE, and publish REQUEST_CHANGES when coverage-evidence blocker states such as cancelled, skipped, failed, unsupported-tooling, or below-100 evidence are present.

  • Result: REQUEST_CHANGES

  • Reason: coverage-evidence result was failure, so required test/docstring evidence was not proven for current head dcf2ee03f01de100c3571c48ce9b87e769fb7f9c.

  • Head SHA: dcf2ee03f01de100c3571c48ce9b87e769fb7f9c

  • Workflow run: 32217717573

  • Workflow attempt: 1

Coverage evidence

Coverage evidence job did not run or did not publish coverage evidence.

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Docs: 983-rotation-control-boundary.md"]
  S1 --> I1["operator or user guidance"]
  I1 --> R1["Review risk: Docs: 983-rotation-control-boundary.md"]
  R1 --> V1["docs review"]
  Evidence --> S2["Changed file (2 files)"]
  S2 --> I2["repository behavior"]
  I2 --> R2["Review risk: Changed file (2 files)"]
  R2 --> V2["required checks"]
  Evidence --> S3["Test (3 files)"]
  S3 --> I3["regression suite"]
  I3 --> R3["Review risk: Test (3 files)"]
  R3 --> V3["targeted test run"]
Loading

@opencode-agent
opencode-agent Bot disabled auto-merge August 19, 2026 05:52

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode cannot approve yet because required coverage evidence did not pass.

Review outcome

1. HIGH .github/workflows/opencode-review.yml:1 - Coverage evidence did not prove required test/docstring evidence

  • Problem: The required coverage-evidence job result was failure, so OpenCode cannot establish approval sufficiency for this head.

  • Root cause: Automated approval is only valid when the same-head coverage-evidence job proves supported repository test suites passed and configured docstring gates passed or were advisory, or reports not applicable because no supported source files or package manifests exist. Missing, failed, skipped, unavailable, or unsupported-tooling test evidence is a blocker.

  • Fix: Install or configure the repository test/docstring evidence tooling when source files or package manifests exist, rerun the current-head coverage-evidence job, and approve only after it reports success with required evidence or explicit no-source not-applicable evidence.

  • Regression test: Keep the approval branch checking needs.coverage-evidence.result == success before posting APPROVE, and publish REQUEST_CHANGES when coverage-evidence blocker states such as cancelled, skipped, failed, unsupported-tooling, or below-100 evidence are present.

  • Result: REQUEST_CHANGES

  • Reason: coverage-evidence result was failure, so required test/docstring evidence was not proven for current head dcf2ee03f01de100c3571c48ce9b87e769fb7f9c.

  • Head SHA: dcf2ee03f01de100c3571c48ce9b87e769fb7f9c

  • Workflow run: 32217717573

  • Workflow attempt: 1

Coverage evidence

Coverage evidence job did not run or did not publish coverage evidence.

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Docs: 983-rotation-control-boundary.md"]
  S1 --> I1["operator or user guidance"]
  I1 --> R1["Review risk: Docs: 983-rotation-control-boundary.md"]
  R1 --> V1["docs review"]
  Evidence --> S2["Changed file (2 files)"]
  S2 --> I2["repository behavior"]
  I2 --> R2["Review risk: Changed file (2 files)"]
  R2 --> V2["required checks"]
  Evidence --> S3["Test (3 files)"]
  S3 --> I3["regression suite"]
  I3 --> R3["Review risk: Test (3 files)"]
  R3 --> V3["targeted test run"]
Loading

Copy link
Copy Markdown
Contributor Author

@opencode-agent review
@cwl-noema-review review

Fresh re-review request: ContextualWisdomLab/.github#1136 has merged, fixing the central coverage-evidence bug (_install_trusted_uv() target-triple validation) that caused the prior REQUEST_CHANGES verdict on this PR. Please re-review exact current head dcf2ee03f01de100c3571c48ce9b87e769fb7f9c — the underlying infrastructure blocker is now resolved on .github main. Do not transfer evidence from any prior head.


Generated by Claude Code

@seonghobae
seonghobae enabled auto-merge (squash) August 19, 2026 13:18
@opencode-agent
opencode-agent Bot disabled auto-merge August 19, 2026 13:59

Copy link
Copy Markdown
Contributor Author

@opencode-agent review
@cwl-noema-review review

Re-dispatch unchanged exact head dcf2ee03f01de100c3571c48ce9b87e769fb7f9c under central .github@bbedc1a51ec1a2421f129955c629b3cd0507a4ec. Python 3.12/3.14, Rust, package, fuzz, Security Scan, CodeQL, and Semgrep all succeeded on the current PR run; only GPU provisioning was cancelled at the known pre-#1021 APT boundary. Inline threads are empty. Both formal CHANGES_REQUESTED reviews came from pre-#1136 central coverage runs 32213341852 and 32217717573; central main now also includes #1140's scheduler-caller OIDC repair. Reacquire same-head coverage/formal review evidence without transferring either infrastructure verdict.

@seonghobae seonghobae closed this Aug 19, 2026
@seonghobae seonghobae reopened this Aug 19, 2026

Copy link
Copy Markdown
Contributor Author

@opencode-agent review
@cwl-noema-review review

Fresh exact-head re-dispatch after central review authority advanced to .github@c47bee591c3d95bd305f2130833ed3a4780d2d1d. Current PR remains Ready at exact head dcf2ee03f01de100c3571c48ce9b87e769fb7f9c on live base main@04d0bc21a2a20693bcf16108cd76d394fe844d23. The prior current-head coverage failure 32217717573 actually materialized trusted workflow source eb0ee5c68c9e807644a920c1a5fb4caa1cf2fe97 and failed before PR tests at base-Python lock materialization (trusted uv executable reported an unexpected version or exit status), so it is infrastructure evidence from a superseded central workflow source, not product-code evidence. Recompute coverage/formal review from the current central contract; do not transfer the prior verdict.

@seonghobae
seonghobae enabled auto-merge (squash) August 20, 2026 03:02
@opencode-agent
opencode-agent Bot disabled auto-merge August 20, 2026 03:42
@seonghobae

Copy link
Copy Markdown
Contributor Author

@opencode-agent review
@cwl-noema-review review

Please re-review exact current head dcf2ee03f01de100c3571c48ce9b87e769fb7f9c against protected main@04d0bc21a2a20693bcf16108cd76d394fe844d23. Focused rotation and selection callback-safety tests pass locally (66 passed). Current repository CI/security evidence is terminal except the known GPU provisioning cancellation at the pre-#1021 APT boundary; do not treat that infrastructure condition as a psychometric defect or transfer predecessor coverage verdicts. Verify exact scalar/string admission before native discovery and unchanged Rust-owned rotation/selection arithmetic.

@seonghobae
seonghobae enabled auto-merge (squash) August 20, 2026 04:18
@opencode-agent
opencode-agent Bot disabled auto-merge August 20, 2026 04:47
@seonghobae

Copy link
Copy Markdown
Contributor Author

@opencode-agent review\n@cwl-noema-review review\n\nPlease review exact current head dcf2ee0. Bind every review and approval decision to this SHA and current main. Existing review state is not sufficient evidence for this head; use current Checks and changed-file evidence only.

@opencode-agent
opencode-agent Bot disabled auto-merge August 20, 2026 07:53
@seonghobae

Copy link
Copy Markdown
Contributor Author

Current-head re-review request for dcf2ee03f01de100c3571c48ce9b87e769fb7f9c against protected main. The prior REQUEST_CHANGES verdict cited predecessor or superseded coverage evidence; re-fetch the exact current-head coverage-evidence result and review the complete current diff. Do not transfer predecessor-head findings or approvals. @opencode-agent review @cwl-noema-review review

@seonghobae
seonghobae enabled auto-merge (squash) August 20, 2026 17:55
@opencode-agent
opencode-agent Bot disabled auto-merge August 20, 2026 19:53
@seonghobae
seonghobae enabled auto-merge (squash) August 20, 2026 20:04

Copy link
Copy Markdown
Contributor Author

@opencode-agent @cwl-noema-review Re-review the exact current head dcf2ee03f01de100c3571c48ce9b87e769fb7f9c.

The prior current-head REQUEST_CHANGES only reported unavailable/failed coverage evidence from an earlier run. Current CI, Security Scan, SAST Semgrep, and CodeQL runs for this exact head are terminal-success. Re-evaluate this head and publish independent approvals only from fresh evidence; do not reuse prior-head reviews. Protected merge policy remains unchanged.

@opencode-agent
opencode-agent Bot disabled auto-merge August 20, 2026 22:12
@seonghobae
seonghobae enabled auto-merge (squash) August 20, 2026 22:43

Copy link
Copy Markdown
Contributor Author

@opencode-agent Please perform a review-only formal review of exact current PR head dcf2ee03f01de100c3571c48ce9b87e769fb7f9c. Re-check changed-file scope, current-head findings, unresolved threads, mergeability, and every required Check. Do not reuse a stale review, mutate the branch, self-approve, or merge.

@seonghobae

Copy link
Copy Markdown
Contributor Author

Current-head manual review completed for dcf2ee0. Rotation and selector trust boundaries are correctly centralized: exact built-in and concrete NumPy booleans, integers, and finite reals are normalized before native discovery; caller-defined text/scalar subclasses are rejected; target/weight validation and Rust-owned rotation, gradients, multistart, bootstrap, and policy arithmetic remain intact. Focused safety/compatibility validation passed 66 tests; 3 native-execution compatibility tests could not run in this detached checkout because fast_mlsirm._core is not compiled, while hosted CI Rust/CI checks are green. Ruff, interrogate 100 percent, compileall, and diff check are clean. No actionable source defect found; normal merge remains subject to independent formal approval.

@opencode-agent
opencode-agent Bot disabled auto-merge August 21, 2026 00:48
@seonghobae
seonghobae enabled auto-merge (squash) August 21, 2026 04:46
@seonghobae

Copy link
Copy Markdown
Contributor Author

Fresh exact-head re-review requested for dcf2ee0. The two existing OpenCode CHANGES_REQUESTED reviews are coverage-evidence failures from 2026-08-19; current-head CI, security, Noema, Strix, and coverage evidence are terminal-success. Re-evaluate this unchanged head under the repaired central coverage contract and publish a fresh formal decision. No bypass or self-approval.

@opencode-agent
opencode-agent Bot disabled auto-merge August 21, 2026 08:28
@seonghobae
seonghobae enabled auto-merge (squash) August 21, 2026 10:18
@opencode-agent
opencode-agent Bot disabled auto-merge August 21, 2026 11:57
@opencode-agent

Copy link
Copy Markdown
Contributor

Scheduled review-feedback autofix for this PR head.

  • Head SHA: dcf2ee03f01de100c3571c48ce9b87e769fb7f9c

@opencode-agent opencode-agent Bot added area: ci-cd CI, GitHub Actions, checks, release, or supply chain area: security Security boundary, hardening, or vulnerability prevention priority: medium Normal-priority or P2 work status: needs-review Open pull request requiring current-head review or checks type: bug Defect or incorrect behavior labels Aug 22, 2026
@coderabbitai

coderabbitai Bot commented Aug 22, 2026

Copy link
Copy Markdown
Contributor

Caution

Review failed

An error occurred during the review process. Please try again later.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@seonghobae
seonghobae enabled auto-merge (squash) August 24, 2026 01:07
@opencode-agent
opencode-agent Bot disabled auto-merge August 24, 2026 02:19
@seonghobae
seonghobae merged commit 236a76e into main Aug 24, 2026
97 of 98 checks passed
@seonghobae
seonghobae deleted the fix/rotation-current-review-984 branch August 24, 2026 07:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: ci-cd CI, GitHub Actions, checks, release, or supply chain area: security Security boundary, hardening, or vulnerability prevention priority: medium Normal-priority or P2 work status: needs-review Open pull request requiring current-head review or checks type: bug Defect or incorrect behavior

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant