Skip to content

test(integration): enforce complete production coverage - #261

Draft
seonghobae wants to merge 185 commits into
perf/plugin-delivery-status-k6-v1from
test/integration-service-quality-gates-v1
Draft

test(integration): enforce complete production coverage#261
seonghobae wants to merge 185 commits into
perf/plugin-delivery-status-k6-v1from
test/integration-service-quality-gates-v1

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

Buyer / quality gap

Direct #260 descendant for the remaining Integration-owned production-quality gap. #260 already has production-faithful PostgreSQL/k6 delivery-status p95 GREEN. This slice keeps provider execution plus DNS/IP/redirect/proxy/connect authorization outside LifeOS, preserves the unchanged 100% statements / branches / functions / lines V8 threshold, and enforces the permanent AST-backed production-docstring contract over the same Integration-owned TypeScript production surface.

Exact production quality authority

Exact source 2e0fcde61fcb53b09b5f888a85cf4b00db9b18b9, run 34394729533, job 102611491182, completed PostgreSQL setup, frozen install, canonical source verification, Plugin SDK build, Integration typecheck and the exact coverage gate GREEN. Artifact 10121100682, SHA-256 8f62304d641c6573da6e384a860d78372933380f7fd2d0ae90877e6e369a650e, reports 221/221 suites passed; 642 tests passed, 0 failed, 3 pending; 7,218/7,218 statements, 2,655/2,655 branches, 496/496 functions and 7,218/7,218 lines — 100% in every production dimension. Permanent Integration AST docstring proof 1d822dbd1b24e25eb06425f8af46e27196da8f89, run 34380229364, job 102563065069, recorded 31 production files / 611 required declarations / 611 documented / 0 missing.

Reality regression 8bc0a29f1d6b211a1eca59646d1d3cce1e6fcf59 proved a concurrent durable credential winner could regain stale installation/binding authority after asynchronous provider verification. Minimum repair 0ba989d34e60f3fa6c634210da331efa34cf2131 re-reads active installation identity and exact scoped durable binding after provider I/O. Revoked-Proxy/Promise-assimilation hostile evidence remains in the same lineage.

Current #261 exact 26b878fae3159bd690a6ef3131c0fc03a91f31c7 is a CHANGELOG-only descendant of 2e0fcde.... Exact run 34396155776, job 102616279223, completed SUCCESS with the unchanged 100% production gate. Artifact 10121634768, SHA-256 b9591c259ee4cf80f86d098f108d0601f0a33103395e2c0af86f9b9b29c7b51c, is bound to this exact head. Returned inline CodeRabbit threads are resolved, but no current independent APPROVED is claimed. #261 remains Draft/unshipped.

Documentation and prerequisite currentness — 2026-09-10

CHANGELOG.md is source-current for #261. Root ARCHITECTURE.md is source-published on Draft #145 exact cbb654a8f837033f84b7c4a90e6ab3cf2c686a46. #247 exact 6a2d8d2299f84431b29bbdc1a1413b4bfecd6ae1 owns the original bounded GitHub Compare repair.

#249 exact 09d1430ec0f3266740266519af36e78907482ca1 retains the shared package graph (qs 6.16.0, multer 2.3.0, Next.js >= 15.5.24 with lock 15.5.25, sharp 0.35.4), bounded Compare request, canonical AppGuardrail formatting and AppGuardrail regressions. Its #262 docstring writer 34439856410 / 102754008005 established 116/116 (100.00%) Commercial Readiness production-docstring coverage before self-retiring; the permanent anti-filler gate was canonicalized by writer 34448538730 / 102778651638 SUCCESS.

Normal contributor exact #249 has CI 34448871673, Commercial Readiness 34448871653, SAST 34448871714, and AppGuardrail 34448871643 SUCCESS. Security 34448871689 remains fail closed only at dependency-review job 102780888062 while Trivy FS/OSV/Scorecard are GREEN. CodeQL 34448871609 has successful language detection and dispatch job 102784476918, while compatibility jobs fail terminal-verdict enforcement. Those central evidence-path incidents remain .github#810 and .github#1929; no LifeOS-local bypass is introduced. Independent current-head approval on #249 remains absent.

Canonical documentation owner #211 source-published this package-quality state through self-retiring writer 34453674174 / 102794960823 SUCCESS and ordinary traceability descendant 7ce7fc627169f385772cac88f73082eb93fd79eb. Its normal CI 34453909480 produced a real formatting RED only in validate job 102796550407, after compose runtime, merge compatibility, browser acceptance and Today concurrency all passed. Bounded diagnostic writer 34454594073 / 102797931880 proved README and CHANGELOG unchanged and identified .github/workflows/appguardrail.yml as the sole checked noncanonical file. That prerequisite control-plane formatting is already canonically owned by #249; #211 did not duplicate mutable source. The failed temporary writer was retired, leaving current #211 exact f46f471320abd02e46929856b0d5fc7365fedd29 with no temporary workflow.

The baseline and Commercial Readiness test-strategy/traceability content are current active-PR evidence. #211 must wait for #249 normal protected integration, then adopt the protected AppGuardrail foundation through ordinary non-force restack and reacquire exact checks/review. This dependency does not weaken #261's existing exact Integration quality evidence or promote any Draft branch into shipped truth.

Provider execution remains fail closed because EgressWeave exposes no immutable released/versioned release. No cross-service SQL, mutable sibling-source dependency or duplicate DNS/IP/redirect/proxy/connect authority is introduced.

Organization ruleset 18156473 requires one approving review, stale-review dismissal on push, review-thread resolution and central required workflows; #261's exact-current 100% coverage/docstring proof is quality evidence, not merge/release authority. Keep Draft until independent review/security authority, prerequisite integration, live-base compatibility, exact-current canonical documentation and normal protected-branch promotion are all satisfied.

Refs #130, #145, #211, #212, #247, #249, #259, #260, #262; ContextualWisdomLab/.github#810; ContextualWisdomLab/.github#1929.

@coderabbitai

coderabbitai Bot commented Sep 9, 2026

Copy link
Copy Markdown

Review Change StackReview Change Stack

📝 Walkthrough

Walkthrough

Integration service의 전달 시도와 저장소 경계 검증이 확장되었습니다. Vault 및 PostgreSQL 통합 테스트가 보강되었습니다. Vitest 커버리지 설정과 PostgreSQL 기반 GitHub Actions 검증 워크플로우가 추가되었습니다.

Changes

Integration 서비스 검증

Layer / File(s) Summary
전달 시도 수명주기 검증
apps/integration-service/src/plugin-delivery-attempt-{claim,control,execution-fence,retry,status}*.ts
잘못된 컨텍스트, 시계, durable evidence, 식별자와 수명주기 상태를 고정 오류로 거부하는 테스트가 추가되었습니다.
저장소 경계 검증
apps/integration-service/src/plugin-delivery-attempt-repository*, apps/integration-service/src/plugin-delivery-attempt-{claim,control,execution-fence,retry,status}-repository*
입력, SQL 의존성, 결과 봉투, 저장 행, timestamp와 retry evidence 검증이 확장되었습니다.
Vault 및 통합 테스트 설정
apps/integration-service/src/plugin-vault-secret-store*, apps/integration-service/src/plugin-operator-replay-postgres.integration.test.ts, apps/integration-service/src/plugin-delivery-attempt-test-database*
Vault 응답과 전송 경계, 기본 PostgreSQL 포트, loopback 대상과 replay migration 초기화가 검증되었습니다.

Integration 커버리지 CI

Layer / File(s) Summary
커버리지 실행 구성
apps/integration-service/package.json, apps/integration-service/vitest.config.ts
V8 커버리지 provider, JSON·텍스트 리포터와 100% 임계값이 구성되었습니다.
통합 커버리지 워크플로우
.github/workflows/verify-integration-coverage.yml
PostgreSQL 16, Node 22와 pnpm 환경에서 포맷 검사, SDK 빌드, 타입체크, 커버리지 실행과 산출물 업로드를 수행합니다.

Priority: ⬇️ Low

Estimated code review effort: 4 (Complex) | ~60 minutes

Merge Risk: 🟡 Moderate · up to 3dea0

The coverage gate remains blocked, and revoked durable evidence can produce the wrong error type. These issues should be fixed before merge.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 41.03% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 117 functions across 28 files. (1 skipped… Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed 제목은 Integration 패키지의 전체 프로덕션 커버리지 검증 및 강제라는 주요 변경 사항을 정확히 설명합니다.
Full details: Docstring Coverage

Explanation

Docstring coverage is 41.03% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 117 functions across 28 files. (1 skipped: 1 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 2
📝 Generate docstrings 💡
  • Create stacked PR
  • Commit on current branch
🛠️ Fix failing CI checks 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch test/integration-service-quality-gates-v1

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

Please review exact current head 530c2e7e9c333c47d48b55200934fa7883826075 rather than predecessor evidence. This descendant adds the credential hostile-read fixed-error boundary repair plus the replay installation-identity-drift regression. Exact run 34385473489 / job 102580523326 is GREEN with 219/219 suites, 637 passed / 0 failed / 3 pending and 100% statements/branches/functions/lines. Please verify the new trust-boundary behavior and retained service/persistence/network ownership constraints.

@coderabbitai

coderabbitai Bot commented Sep 9, 2026

Copy link
Copy Markdown

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

head='530c2e7e9c333c47d48b55200934fa7883826075'
base="$(git merge-base "$head" origin/main 2>/dev/null || git merge-base "$head" main)"

echo '=== exact identity ==='
git show -s --format='commit=%H%nparents=%P%nsubject=%s%nbody=%b' "$head"
echo "base=${base}"

echo '=== direct changed paths ==='
git diff-tree --no-commit-id --name-status -r "$head"
echo '=== direct diff ==='
git diff --no-ext-diff --find-renames --find-copies --unified=110 "${head}^" "$head"

echo '=== relevant range commits ==='
git log --format='%H %s' "$base..$head" -- \
  apps/integration-service/src/plugin-credential.ts \
  apps/integration-service/src/plugin-credential-repository.ts \
  apps/integration-service/src/plugin-credential-hostile-boundary-coverage.test.ts \
  apps/integration-service/src/plugin-credential-repository-coverage.test.ts \
  apps/integration-service/src/plugin-credential-repository-evidence-coverage.test.ts \
  apps/integration-service/src/plugin-operator-application.ts \
  apps/integration-service/src/plugin-operator-context.ts \
  apps/integration-service/src/plugin-operator-replay-postgres.integration.test.ts \
  .github/workflows/verify-integration-coverage.yml

echo '=== focused PR-range diff ==='
git diff --no-ext-diff --find-renames --find-copies --unified=70 "$base" "$head" -- \
  apps/integration-service/src/plugin-credential.ts \
  apps/integration-service/src/plugin-credential-repository.ts \
  apps/integration-service/src/plugin-credential-hostile-boundary-coverage.test.ts \
  apps/integration-service/src/plugin-credential-repository-coverage.test.ts \
  apps/integration-service/src/plugin-credential-repository-evidence-coverage.test.ts \
  apps/integration-service/src/plugin-operator-application.ts \
  apps/integration-service/src/plugin-operator-context.ts \
  apps/integration-service/src/plugin-operator-replay-postgres.integration.test.ts \
  .github/workflows/verify-integration-coverage.yml \
  apps/integration-service/vitest.config.ts \
  apps/integration-service/package.json

for file in \
  apps/integration-service/src/plugin-credential.ts \
  apps/integration-service/src/plugin-credential-repository.ts \
  apps/integration-service/src/plugin-credential-hostile-boundary-coverage.test.ts \
  apps/integration-service/src/plugin-credential-repository-coverage.test.ts \
  apps/integration-service/src/plugin-credential-repository-evidence-coverage.test.ts \
  apps/integration-service/src/plugin-operator-application.ts \
  apps/integration-service/src/plugin-operator-context.ts \
  apps/integration-service/src/plugin-operator-replay-postgres.integration.test.ts \
  .github/workflows/verify-integration-coverage.yml \
  apps/integration-service/vitest.config.ts \
  apps/integration-service/package.json
do
  if git cat-file -e "${head}:${file}" 2>/dev/null; then
    echo "=== outline: ${file} ==="
    case "$file" in
      *.ts)
        git show "${head}:${file}" > "/tmp/$(basename "$file")"
        ast-grep outline "/tmp/$(basename "$file")" --items all --view expanded || true
        ;;
    esac
    echo "=== source: ${file} ==="
    git show "${head}:${file}" | cat -n
  fi
done

echo '=== credential boundary and SQL contexts ==='
git grep -n -I -C 7 -E \
  '(bounded(Input|Evidence|.*Dependency)|Array\.isArray|\\.query\\s*\\(|getInstallation|findById|revokeActive|PluginCredential(Persistence)?Error|Promise<\\{ value)' \
  "$head" -- \
  apps/integration-service/src/plugin-credential.ts \
  apps/integration-service/src/plugin-credential-repository.ts \
  apps/integration-service/src/plugin-credential*test.ts || true

echo '=== replay identity drift contexts ==='
git grep -n -I -C 10 -E \
  '(replay|installation.*identity|installationId|installation_id|identity.*drift|findById)' \
  "$head" -- apps/integration-service/src ':!apps/integration-service/src/*coverage.test.ts' || true

echo '=== persistence query structure ==='
for file in apps/integration-service/src/plugin-credential-repository.ts apps/integration-service/src/plugin-delivery-attempt-repository.ts; do
  git show "${head}:${file}" > "/tmp/$(basename "$file")"
  echo "--- ${file} ---"
  ast-grep run --pattern '$OBJ.query($$$ARGS)' --lang typescript "/tmp/$(basename "$file") || true
done

echo '=== workflow permissions, coverage scope, and diagnostics ==='
git show "${head}:.github/workflows/verify-integration-coverage.yml" |
  rg -n -C 8 '(permissions:|contents:|test:coverage|coverage-summary|coverage_status|upload-artifact|raw|rm |JSON\\.parse)' || true

echo '=== formatting and trailing newline checks ==='
git diff --check "$base" "$head"
python3 - <<'PY'
import subprocess
head='530c2e7e9c333c47d48b55200934fa7883826075'
paths=subprocess.check_output(['git','diff','--name-only',f'{head}^',head],text=True).splitlines()
for path in paths:
    data=subprocess.check_output(['git','show',f'{head}:{path}'])
    if data and not data.endswith(b'\n'):
        print(f'MISSING_FINAL_NEWLINE {path}')
PY

Length of output: 205686


🏁 Script executed:

#!/bin/bash
set -euo pipefail

head='530c2e7e9c333c47d48b55200934fa7883826075'
parent="$(git rev-parse "${head}^")"

echo '=== exact commit ==='
git show -s --format='commit=%H%nparent=%P%nsubject=%s' "$head"
echo '=== changed paths ==='
git diff-tree --no-commit-id --name-status -r "$head"
echo '=== direct diff ==='
git diff --no-ext-diff --unified=80 "$parent" "$head" -- \
  apps/integration-service/src/plugin-credential.ts \
  apps/integration-service/src/plugin-credential-repository.ts \
  apps/integration-service/src/plugin-credential-hostile-boundary-coverage.test.ts \
  apps/integration-service/src/plugin-credential-repository-coverage.test.ts \
  apps/integration-service/src/plugin-credential-repository-evidence-coverage.test.ts \
  apps/integration-service/src/plugin-operator-application.ts \
  apps/integration-service/src/plugin-operator-application.test.ts \
  apps/integration-service/src/plugin-operator-replay.ts \
  apps/integration-service/src/plugin-operator-replay.test.ts

echo '=== credential application helpers and public operations ==='
git show "${head}:apps/integration-service/src/plugin-credential.ts" | nl -ba | sed -n '120,620p'

echo '=== credential repository helpers and SQL methods ==='
git show "${head}:apps/integration-service/src/plugin-credential-repository.ts" | nl -ba | sed -n '130,420p'

echo '=== exact credential boundary regression matches ==='
git grep -n -I -C 5 -E \
  'Proxy\.revocable|revok|defineProperty|getter|must-not-escape|mockRejectedValue|PersistenceValidationError|PersistenceEvidenceError|PluginCredentialError' \
  "$head" -- apps/integration-service/src/plugin-credential*test.ts || true

echo '=== installation identity-drift regression matches ==='
git grep -n -I -C 10 -E \
  'identity.*drift|drift|installationId.*(different|mismatch|changed)|installation.*(different|mismatch|changed)|replay' \
  "$head" -- apps/integration-service/src/plugin-credential*test.ts apps/integration-service/src/plugin-operator*test.ts || true

echo '=== replay and credential call relationships ==='
rg -n -C 5 --type ts \
  '\b(bindCredential|revokeCredential|findById|getInstallation|createIfAbsent|revokeActive|consume)\s*\(' \
  apps/integration-service/src/plugin-credential.ts \
  apps/integration-service/src/plugin-operator-application.ts \
  apps/integration-service/src/plugin-operator-replay.ts

echo '=== verifier permissions and coverage contract ==='
git show "${head}:.github/workflows/verify-integration-coverage.yml" | nl -ba | sed -n '1,240p'
git show "${head}:apps/integration-service/vitest.config.ts" | nl -ba
git show "${head}:apps/integration-service/package.json" | nl -ba

echo '=== direct whitespace and newline checks ==='
git diff --check "$parent" "$head"
python3 - <<'PY'
import subprocess
head='530c2e7e9c333c47d48b55200934fa7883826075'
for path in subprocess.check_output(['git','diff','--name-only',f'{head}^',head], text=True).splitlines():
    blob=subprocess.check_output(['git','show',f'{head}:{path}'])
    if blob and not blob.endswith(b'\n'):
        print('MISSING_FINAL_NEWLINE ' + path)
PY

Length of output: 203626


🏁 Script executed:

#!/bin/bash
set -euo pipefail

head='530c2e7e9c333c47d48b55200934fa7883826075'

echo '=== direct commit metadata and changed paths ==='
git show -s --format='commit=%H%nparents=%P%nsubject=%s' "$head"
git diff-tree --no-commit-id --name-status -r "$head"

echo '=== direct diff: credential repair and identity drift ==='
git diff --no-ext-diff --unified=45 "${head}^" "$head" -- \
  apps/integration-service/src/plugin-credential.ts \
  apps/integration-service/src/plugin-credential-repository.ts \
  apps/integration-service/src/plugin-credential-hostile-boundary-coverage.test.ts \
  apps/integration-service/src/plugin-credential-replay-secret.test.ts

echo '=== application helpers ==='
git show "${head}:apps/integration-service/src/plugin-credential.ts" | nl -ba | sed -n '115,245p'
echo '=== application bind/revoke operations ==='
git show "${head}:apps/integration-service/src/plugin-credential.ts" | nl -ba | sed -n '390,675p'

echo '=== repository helpers ==='
git show "${head}:apps/integration-service/src/plugin-credential-repository.ts" | nl -ba | sed -n '140,280p'
echo '=== repository SQL operations ==='
git show "${head}:apps/integration-service/src/plugin-credential-repository.ts" | nl -ba | sed -n '280,410p'

echo '=== direct identity-drift test ==='
git show "${head}:apps/integration-service/src/plugin-credential-replay-secret.test.ts" | nl -ba | sed -n '1,280p'

echo '=== direct hostile-boundary regression ==='
git show "${head}:apps/integration-service/src/plugin-credential-hostile-boundary-coverage.test.ts" | nl -ba | sed -n '1,360p'

echo '=== remaining unbounded coverage parser ==='
git show "${head}:.github/workflows/verify-integration-coverage.yml" | nl -ba | sed -n '135,225p'

Length of output: 60396


@seonghobae I reviewed exact head 530c2e7e9c333c47d48b55200934fa7883826075.

I found one current defect.

P2 — Preserve the captured Vitest status when coverage-summary parsing fails.

In .github/workflows/verify-integration-coverage.yml, Line 185 parses coverage-summary.json outside a try/catch.

If Vitest leaves partial or malformed coverage JSON, the Node diagnostics process exits before Line 211 writes coverage_status to GITHUB_OUTPUT. The artifact step at Line 215 then skips the diagnostics artifact. The workflow reports the parser error instead of the captured Vitest exit status.

Catch the coverage-summary read and parse failure. Keep approved.totals as null. Then always write coverage_status and exit with the captured status.

The credential trust-boundary repair is correct in the reviewed paths.

  • boundedDependency() returns { value }. It does not return hostile evidence as raw T.
  • Initial installation and binding-store calls unwrap the envelope before bounded evidence reads.
  • oneOrUndefined(), command snapshots, durable-row snapshots, and SQL calls in plugin-credential-repository.ts use the fixed validation or evidence boundaries.
  • The new replay regression changes installedAt between authority reads. PluginCredentialApplication.bind() rejects this drift after provider verification and before it returns replay authority.
  • The credential metadata interface remains credential-free. Vault remains the only plaintext secret-store boundary.
  • The coverage configuration retains production-source inclusion and 100% thresholds for statements, branches, functions, and lines.
  • The verifier retains contents: read permission and removes raw Vitest output before artifact upload.

I used the retrieved revoked-Proxy and async Promise-assimilation guidance for the envelope review. I performed static inspection only.


🧠 Learnings used
Learnt from: seonghobae
Repo: ContextualWisdomLab/life-os PR: 261
File: apps/integration-service/src/plugin-delivery-attempt-claim.test.ts:222-233
Timestamp: 2026-09-09T09:51:03.121Z
Learning: In `apps/integration-service/src/plugin-delivery-attempt-claim.ts` and `apps/integration-service/src/plugin-delivery-attempt-execution-fence.ts`, an async bounded dependency helper must not return hostile durable evidence as raw generic `T`. Promise resolution can inspect a revoked Proxy's `then` property outside the helper's `try` boundary. Return a plain envelope such as `{ value }` instead, then pass `value` to a bounded synchronous evidence parser so all revoked-Proxy failures convert to the fixed authority error.

Learnt from: seonghobae
Repo: ContextualWisdomLab/life-os PR: 261
File: apps/integration-service/src/plugin-delivery-attempt-claim.test.ts:228-239
Timestamp: 2026-09-09T08:11:03.259Z
Learning: In `apps/integration-service/src/plugin-delivery-attempt-claim.ts` and `apps/integration-service/src/plugin-delivery-attempt-execution-fence.ts`, `Array.isArray(value)` can throw for a revoked `Proxy`; evaluate it through the relevant bounded-read helper so the code converts the failure to the fixed authority error. Regression tests for durable revoked proxies must pre-resolve the proxy before revocation, because returning a revoked proxy directly from an async store can fail during Promise assimilation before post-persistence `requireEvidence` executes.

You are interacting with an AI system.

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

현재 exact head 530c2e7e9c333c47d48b55200934fa7883826075 전체 diff를 다시 검토해 주세요. 이전 review 범위 이후 credential authority·hostile durable evidence·coverage workflow·production docstring contract가 추가/수정되었으므로 predecessor review를 현재 승인 근거로 재사용하지 않습니다. 특히 fail-closed 오류 경계, Promise assimilation/Proxy hostile evidence, secret cleanup/credential replay·revocation, destructive-test isolation, retained CI evidence의 민감정보 노출 여부, 100% production coverage를 위한 dead-branch 삭제가 실제 invariant를 약화시키지 않았는지 확인해 주세요.

@coderabbitai

coderabbitai Bot commented Sep 9, 2026

Copy link
Copy Markdown

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

head='530c2e7e9c333c47d48b55200934fa7883826075'
base="$(git merge-base "$head" origin/main 2>/dev/null || git merge-base "$head" main)"

echo '=== identity and range ==='
git show -s --format='head=%H%nparents=%P%nsubject=%s%nbody=%b' "$head"
git show -s --format='base=%H%nsubject=%s' "$base"
echo '=== changed paths in full range ==='
git diff --name-status "$base" "$head"
echo '=== commits in full range ==='
git log --format='%H %s' "$base..$head"

echo '=== direct head change ==='
git diff-tree --no-commit-id --name-status -r "$head"
git diff --no-ext-diff --find-renames --find-copies --unified=100 "${head}^" "$head"

echo '=== production changes in full range ==='
git diff --no-ext-diff --find-renames --find-copies --unified=55 "$base" "$head" -- \
  'apps/integration-service/src/**/*.ts' \
  '.github/workflows/*.yml' \
  'apps/integration-service/migrations/*.sql' \
  'apps/integration-service/vitest.config.ts' \
  'apps/integration-service/package.json'

echo '=== changed production outlines ==='
git diff --name-only "$base" "$head" -- 'apps/integration-service/src/**/*.ts' |
  rg -v '\.test\.ts$' |
  while IFS= read -r file; do
    [ -n "$file" ] || continue
    echo "--- $file ---"
    git show "${head}:${file}" > "/tmp/$(basename "$file")"
    ast-grep outline "/tmp/$(basename "$file")" --items all --view expanded || true
  done

echo '=== focused exact-head sources ==='
for file in \
  apps/integration-service/src/plugin-credential.ts \
  apps/integration-service/src/plugin-credential-repository.ts \
  apps/integration-service/src/plugin-delivery-attempt-retry.ts \
  apps/integration-service/src/plugin-delivery-attempt-retry-repository.ts \
  apps/integration-service/src/plugin-vault-secret-store.ts \
  apps/integration-service/src/plugin-vault-hosted-runtime.ts \
  apps/integration-service/src/plugin-vault-operator-composition.ts \
  apps/integration-service/src/production-docstring-contract.test.ts \
  .github/workflows/verify-integration-coverage.yml \
  apps/integration-service/vitest.config.ts \
  apps/integration-service/package.json
do
  echo "--- $file ---"
  git show "${head}:${file}" | cat -n
done

echo '=== hostile boundary, persistence, secret cleanup, and workflow contexts ==='
git grep -n -I -C 7 -E \
  '(bounded(Input|Evidence|.*Dependency)|Promise<\{ value|Array\.isArray|\.query\s*\(|getInstallation|findById|revokeActive|cancel|release|zero|fill\(|coverage-summary|coverage_status|upload-artifact|raw|tee|JSON\.parse)' \
  "$head" -- apps/integration-service/src .github/workflows/verify-integration-coverage.yml || true

echo '=== tests that cover exact focused boundaries ==='
fd -a -e ts . apps/integration-service/src |
  rg '(plugin-credential|retry|vault.*(secret|hosted|composition)|production-docstring|replay|test-database).*test\.ts$' |
  while IFS= read -r file; do
    echo "--- $file ---"
    git show "${head}:${file}" | cat -n
  done

echo '=== destructive integration setup and migration scope ==='
fd -a -e ts . apps/integration-service/src |
  rg '(integration|test-database).*test\.ts$' |
  while IFS= read -r file; do
    echo "--- $file ---"
    git show "${head}:${file}" |
      rg -n -C 10 '(DROP|CREATE SCHEMA|TRUNCATE|loopback|localhost|127\.0\.0\.1|migration|beforeAll|afterAll)' || true
  done
fd -a -e sql . apps/integration-service/migrations --exec sh -c 'echo "--- $1 ---"; sed -n "1,220p" "$1"' sh {}

echo '=== format and final newline checks ==='
git diff --check "$base" "$head"
python3 - <<'PY'
import subprocess
head='530c2e7e9c333c47d48b55200934fa7883826075'
base=subprocess.check_output(
 ['git','merge-base',head,'origin/main'], text=True, stderr=subprocess.DEVNULL
).strip() if subprocess.call(
 ['git','rev-parse','--verify','origin/main'], stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL
)==0 else subprocess.check_output(['git','merge-base',head,'main'],text=True).strip()
for path in subprocess.check_output(['git','diff','--name-only',base,head],text=True).splitlines():
    blob=subprocess.check_output(['git','show',f'{head}:{path}'])
    if blob and not blob.endswith(b'\n'):
        print('MISSING_FINAL_NEWLINE ' + path)
PY

Length of output: 149014


🏁 Script executed:

#!/bin/bash
set -u

head='530c2e7e9c333c47d48b55200934fa7883826075'

show_range() {
  local file="$1"
  local range="$2"
  echo "=== ${file}:${range} ==="
  git show "${head}:${file}" | nl -ba | sed -n "${range}p"
}

echo '=== exact focused helper and operation ranges ==='
show_range apps/integration-service/src/plugin-credential.ts '110,680'
show_range apps/integration-service/src/plugin-credential-repository.ts '130,430'
show_range apps/integration-service/src/plugin-delivery-attempt-retry.ts '40,320'
show_range apps/integration-service/src/plugin-delivery-attempt-retry-repository.ts '60,430'
show_range apps/integration-service/src/plugin-vault-secret-store.ts '360,680'
show_range apps/integration-service/src/plugin-vault-hosted-runtime.ts '40,260'
show_range apps/integration-service/src/plugin-vault-operator-composition.ts '25,260'
show_range apps/integration-service/src/production-docstring-contract.test.ts '1,360'
show_range .github/workflows/verify-integration-coverage.yml '100,240'

echo '=== source diffs for dead-branch removals and credential fixes ==='
for commit in \
  1450aa0c2a60090ea09e01ef8c0e9952955d40d5 \
  37ba0904432581e6f58f1a49a9f062be1018f5a2 \
  60aba185577efbbf2c5d5d5f4815eaa7b5f00522 \
  52e63de3a725357aa54aaaeb81ef6ddc49286a13 \
  86408958b1cac25bacaaaf7094e27f39e1dcfe03 \
  2bfcf641051243c393a617e804b26f793777cf39
do
  echo "--- commit $commit ---"
  git show --format='%h %s' --unified=60 "$commit" -- \
    apps/integration-service/src \
    apps/integration-service/migrations \
    .github/workflows/verify-integration-coverage.yml
done

echo '=== exact tests: hostile proxies, assimilation, replay, revocation, cleanup ==='
for file in \
  apps/integration-service/src/plugin-credential-hostile-boundary-coverage.test.ts \
  apps/integration-service/src/plugin-credential-replay-secret.test.ts \
  apps/integration-service/src/plugin-credential-revocation-winner-consistency.test.ts \
  apps/integration-service/src/plugin-credential-repository-evidence-coverage.test.ts \
  apps/integration-service/src/plugin-delivery-attempt-retry-coverage.test.ts \
  apps/integration-service/src/plugin-delivery-attempt-retry-repository.test.ts \
  apps/integration-service/src/plugin-vault-secret-store-body-cleanup.test.ts \
  apps/integration-service/src/plugin-vault-secret-store-coverage.test.ts \
  apps/integration-service/src/plugin-operator-replay-postgres.integration.test.ts \
  apps/integration-service/src/plugin-delivery-attempt-test-database.ts \
  apps/integration-service/src/plugin-delivery-attempt-test-database.test.ts
do
  echo "--- $file ---"
  git show "${head}:${file}" | nl -ba | sed -n '1,760p'
done

echo '=== direct code patterns not in bounded helpers ==='
for file in \
  apps/integration-service/src/plugin-credential.ts \
  apps/integration-service/src/plugin-credential-repository.ts \
  apps/integration-service/src/plugin-delivery-attempt-retry.ts \
  apps/integration-service/src/plugin-delivery-attempt-retry-repository.ts \
  apps/integration-service/src/plugin-vault-secret-store.ts \
  apps/integration-service/src/plugin-vault-hosted-runtime.ts \
  apps/integration-service/src/plugin-vault-operator-composition.ts
do
  echo "--- $file ---"
  git show "${head}:${file}" | rg -n -C 5 \
    '(Array\.isArray|async function bounded|Promise<\{ value|Promise<T>|\.query\s*\(|getInstallation|findById|revokeActive|putSecret|verifySecret|deleteSecret|cancel|release|fill\()' || true
done

echo '=== direct destructive-operation contexts ==='
git grep -n -I -C 10 -E \
  '(DROP SCHEMA|DROP TABLE|TRUNCATE|CREATE SCHEMA|loopback|127\.0\.0\.1|localhost|::1|beforeAll)' \
  "$head" -- apps/integration-service/src || true

echo '=== direct workflow artifact and sensitive-output contexts ==='
git show "${head}:.github/workflows/verify-integration-coverage.yml" | \
  rg -n -C 10 '(raw_output|test_report|safe_summary|writeFileSync|upload-artifact|path:|coverage-final|coverage-summary|JSON\.parse|console\.|throw new Error|GITHUB_OUTPUT)' || true

echo '=== changed test file outline at direct head ==='
git show "${head}:apps/integration-service/src/plugin-credential-hostile-boundary-coverage.test.ts" \
  > /tmp/plugin-credential-hostile-boundary-coverage.test.ts
ast-grep outline /tmp/plugin-credential-hostile-boundary-coverage.test.ts --items all --view expanded || true

Length of output: 204883


@seonghobae 현재 exact head 530c2e7e9c333c47d48b55200934fa7883826075를 검토했습니다.

네 개의 현재 결함을 찾았습니다.

  1. P1 — Retry async helper가 hostile evidence를 raw T로 반환합니다.
    apps/integration-service/src/plugin-delivery-attempt-retry.tsboundedDependency()는 Line 67에서 Promise<T>를 반환합니다.
    apps/integration-service/src/plugin-delivery-attempt-retry-repository.tsboundedEvidenceDependency()도 Line 99에서 Promise<T>를 반환합니다.

    dependency가 이미 resolve된 Proxy를 반환한 후 Proxy가 revoke되면, outer Promise resolution이 helper의 try 범위 밖에서 then을 읽을 수 있습니다. 이 경우 native TypeErrorPluginDeliveryAttemptRetryAuthorityError 또는 PluginDeliveryAttemptRetryPersistenceEvidenceError를 우회합니다.

    helper는 { value } 같은 plain envelope을 반환해야 합니다. 이후 bounded synchronous parser가 value를 읽어야 합니다. Proxy를 먼저 resolve한 후 revoke하는 회귀 테스트도 추가해야 합니다.

  2. P1 — Hosted runtime과 operator composition이 hostile input read를 고정 오류로 변환하지 않습니다.
    apps/integration-service/src/plugin-vault-hosted-runtime.tsrequireEnvironment()requirePool()은 각각 Line 62와 Line 88에서 Array.isArray()를 경계 없이 호출합니다.
    apps/integration-service/src/plugin-vault-operator-composition.tsrequireEnvironment()도 Line 49에서 같은 호출을 합니다.

    또한 composition validator는 environment, dependency, port-method property를 직접 읽습니다. revoked Proxy 또는 throwing getter는 PluginVaultHostedRuntimeError 또는 PluginVaultOperatorCompositionError 대신 native error를 만들 수 있습니다.

    모든 shape check와 property snapshot을 bounded read helper 안에서 수행해야 합니다. revoked Proxy와 throwing getter 회귀 테스트가 필요합니다.

  3. P1 — Vault secret-store validator가 hostile payload와 durable envelope를 fail closed 하지 못합니다.
    apps/integration-service/src/plugin-vault-secret-store.tsrequirePayload()는 Line 155에서 Array.isArray(value)를 직접 호출합니다.
    requireVaultReadPayload()도 Line 211, Line 218, Line 226에서 Array.isArray()와 nested property reads를 직접 수행합니다.

    revoked Proxy 또는 throwing data getter는 PluginVaultSecretStoreError 대신 native exception을 노출할 수 있습니다. 이 경로는 plaintext secret을 다루는 boundary에 있습니다.

    payload와 Vault read envelope의 shape check 및 snapshot을 bounded read helper로 감싸야 합니다. hostile payload, outer envelope, nested data getter, revoked Proxy를 대상으로 fixed-error 회귀 테스트를 추가해야 합니다.

  4. P2 — coverage summary parse failure가 captured Vitest status와 artifact retention을 우회합니다.
    .github/workflows/verify-integration-coverage.yml의 Line 185는 coverage-summary.jsontry/catch 밖에서 parse합니다.

    Vitest가 partial 또는 malformed summary를 남기면 Node diagnostics step은 Line 211의 coverage_status 기록 전에 실패합니다. 그러면 Line 215의 artifact upload도 실행되지 않습니다. 이 경우 workflow는 captured Vitest exit status 대신 parser failure를 보고합니다.

    coverage summary read와 parse를 try/catch로 감싸야 합니다. 실패 시 approved.totalsnull로 유지해야 합니다. 이후 workflow는 항상 coverage_status를 기록하고 해당 status로 종료해야 합니다.

검토한 credential repair는 의도한 경계를 유지합니다. plugin-credential.tsplugin-credential-repository.ts의 async helper는 { value } envelope을 사용합니다. 새 installation identity-drift regression도 두 authority read 사이의 installedAt 변경을 거부합니다.

Raw Vitest stdout/stderr와 JSON test report는 artifact upload 전에 삭제됩니다. Retained aggregate summary는 4,096-byte 제한과 0o600 mode를 사용합니다. 다만 malformed coverage summary 경로에서는 이 retention flow가 완료되지 않습니다.

Destructive PostgreSQL setup은 dedicated database name과 role을 확인합니다. sslmode=disable은 loopback host에서만 허용됩니다. Replay integration setup은 별도 loopback check도 수행합니다.

Dead-branch removal diff는 검토한 범위에서 이미 stronger equality 또는 canonical-input validation이 보장한 중복 validation만 제거합니다. 해당 제거가 durable invariant를 약화시키는 증거는 찾지 못했습니다.

이 검토에는 이 PR의 retrieved revoked-Proxy 및 Promise-assimilation guidance를 사용했습니다. Repository code는 실행하지 않았습니다.


🧠 Learnings used
Learnt from: seonghobae
Repo: ContextualWisdomLab/life-os PR: 261
File: apps/integration-service/src/plugin-delivery-attempt-claim.test.ts:222-233
Timestamp: 2026-09-09T09:51:03.121Z
Learning: In `apps/integration-service/src/plugin-delivery-attempt-claim.ts` and `apps/integration-service/src/plugin-delivery-attempt-execution-fence.ts`, an async bounded dependency helper must not return hostile durable evidence as raw generic `T`. Promise resolution can inspect a revoked Proxy's `then` property outside the helper's `try` boundary. Return a plain envelope such as `{ value }` instead, then pass `value` to a bounded synchronous evidence parser so all revoked-Proxy failures convert to the fixed authority error.

Learnt from: seonghobae
Repo: ContextualWisdomLab/life-os PR: 261
File: apps/integration-service/src/plugin-delivery-attempt-claim.test.ts:228-239
Timestamp: 2026-09-09T08:11:03.259Z
Learning: In `apps/integration-service/src/plugin-delivery-attempt-claim.ts` and `apps/integration-service/src/plugin-delivery-attempt-execution-fence.ts`, `Array.isArray(value)` can throw for a revoked `Proxy`; evaluate it through the relevant bounded-read helper so the code converts the failure to the fixed authority error. Regression tests for durable revoked proxies must pre-resolve the proxy before revocation, because returning a revoked proxy directly from an async store can fail during Promise assimilation before post-persistence `requireEvidence` executes.

You are interacting with an AI system.

Copy link
Copy Markdown
Contributor Author

Fresh review of exact 530c2e7e9c333c47d48b55200934fa7883826075 found a still-unproven durable-acceptance race in credential creation. Existing replay already calls verifySecret before accepting metadata, but the create path can observe findById = undefined, materialize a new secret, lose createIfAbsent to a concurrent winner with the same binding authority but a different opaque secretReference, delete only the newly written loser secret, and then return the concurrent durable winner without proving that winner contains the caller's exact secret bytes. That can acknowledge a bind whose requested secret was never accepted.

Regression-only exact a2ca1fa5d2d1bea6250f78997f655ad7ed9dde6b adds plugin-credential-concurrent-winner-secret.test.ts: the provider-backed winner proof deliberately rejects, so correct behavior is fixed PluginCredentialError after loser-secret cleanup. Verify Integration coverage run 34387340168 is queued. No RED/GREEN claim is transferred from predecessor 530c2e7...; the previous 100% run is now historical evidence only until this exact regression executes.

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

Fresh whole-diff review requested for exact head 2e0fcde61fcb53b09b5f888a85cf4b00db9b18b9. Please review the current descendant, including the concurrent credential-winner post-provider authority revalidation and its RED→GREEN regressions. Do not treat predecessor review state as current-head approval.

@coderabbitai

coderabbitai Bot commented Sep 9, 2026

Copy link
Copy Markdown

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

head='2e0fcde61fcb53b09b5f888a85cf4b00db9b18b9'
parent="${head}^"
base="$(git merge-base "$head" origin/main 2>/dev/null || git merge-base "$head" main)"

echo '=== exact commit identity ==='
git show -s --format='commit=%H%nparents=%P%nsubject=%s%nbody=%b' "$head"

echo '=== direct changed paths ==='
git diff-tree --no-commit-id --name-status -r "$head"

echo '=== direct diff ==='
git diff --no-ext-diff --find-renames --find-copies --unified=120 "$parent" "$head"

echo '=== PR-range paths related to concurrent credential winner ==='
git log --format='%H %s' "$base..$head" -- \
  apps/integration-service/src/plugin-credential.ts \
  apps/integration-service/src/plugin-credential-concurrent-winner-secret.test.ts \
  apps/integration-service/src/plugin-credential-repository.ts \
  .github/workflows/verify-integration-coverage.yml

echo '=== full range diff for credential application ==='
git diff --no-ext-diff --find-renames --find-copies --unified=80 "$base" "$head" -- \
  apps/integration-service/src/plugin-credential.ts \
  apps/integration-service/src/plugin-credential-concurrent-winner-secret.test.ts \
  apps/integration-service/src/plugin-credential-repository.ts

echo '=== candidate files ==='
fd -a -i 'plugin-credential' apps/integration-service/src

echo '=== exact-head credential application full source ==='
git show "${head}:apps/integration-service/src/plugin-credential.ts" | cat -n

echo '=== exact-head concurrent winner secret regression ==='
git show "${head}:apps/integration-service/src/plugin-credential-concurrent-winner-secret.test.ts" | cat -n

Length of output: 113644


🏁 Script executed:

#!/bin/bash
set -euo pipefail

head='2e0fcde61fcb53b09b5f888a85cf4b00db9b18b9'

echo '=== retry.ts boundedDependency signature ==='
git show "${head}:apps/integration-service/src/plugin-delivery-attempt-retry.ts" | rg -n -C 10 'async function bounded|Promise<T>|Promise<\{ value'

echo '=== retry-repository.ts boundedEvidenceDependency signature ==='
git show "${head}:apps/integration-service/src/plugin-delivery-attempt-retry-repository.ts" | rg -n -C 10 'async function bounded|Promise<T>|Promise<\{ value'

echo '=== hosted-runtime.ts Array.isArray boundary ==='
git show "${head}:apps/integration-service/src/plugin-vault-hosted-runtime.ts" | rg -n -C 8 'Array\.isArray|function require|try \{'

echo '=== operator-composition.ts Array.isArray boundary ==='
git show "${head}:apps/integration-service/src/plugin-vault-operator-composition.ts" | rg -n -C 8 'Array\.isArray|function require|try \{'

echo '=== vault-secret-store.ts Array.isArray boundary ==='
git show "${head}:apps/integration-service/src/plugin-vault-secret-store.ts" | rg -n -C 8 'Array\.isArray|function require|try \{'

echo '=== workflow coverage-summary parse boundary ==='
git show "${head}:.github/workflows/verify-integration-coverage.yml" | rg -n -C 10 'coverage-summary|JSON\.parse|coverage_status|GITHUB_OUTPUT'

echo '=== whitespace / final newline check for exact head diff ==='
git diff --check "${head}^" "$head"

Length of output: 26028


@seonghobae Reviewed exact head 2e0fcde61fcb53b09b5f888a85cf4b00db9b18b9.

Concurrent credential-winner revalidation is correct.

bind() in apps/integration-service/src/plugin-credential.ts now closes the race you described.

  • The method captures boundAt once, before any authority read.
  • It requires installedAt <= boundAt from the initial installation snapshot.
  • On both the existing-active-binding path and the conflicting-durable-winner path, it calls secretStore.verifySecret() before granting authority.
  • After verifySecret() returns, it re-reads installation and binding evidence, and calls requireCurrentActiveBinding(). This function checks sameImmutableBindingEvidence() against the pre-verification evidence, and checks activeBinding() and bindingVisibleAt() against the fresh evidence.

This closes the race. A caller cannot receive a durable winner unless that winner's secret bytes are proven exact, and unless installation and binding state remain unchanged through the verification window.

The new regression, rejects a concurrent durable winner when installation identity changes during provider verification, exercises this exact boundary. It changes installedAt inside the verifySecret() callback and confirms PluginCredentialApplication.bind() rejects the result. This is a valid RED→GREEN addition. It complements the existing revocation-during-verification regressions for both the installation authority and the binding authority.

boundedDependency() in plugin-credential.ts and boundedEvidenceDependency() in plugin-credential-repository.ts return { value } envelopes. They do not return hostile evidence as raw T. This matches the retrieved guidance for this PR.

Open findings from earlier reviews remain present at this exact head. These files are unchanged by this commit, but the whole-diff review you requested should restate them because they are still live in the current head state:

  1. apps/integration-service/src/plugin-delivery-attempt-retry.ts: boundedDependency() at Line 67 still returns raw Promise<T>.
  2. apps/integration-service/src/plugin-delivery-attempt-retry-repository.ts: boundedEvidenceDependency() at Line 99 still returns raw Promise<T>.
  3. apps/integration-service/src/plugin-vault-hosted-runtime.ts: requireEnvironment() (Line 62) and requirePool() (Line 88) call Array.isArray() outside a boundary.
  4. apps/integration-service/src/plugin-vault-operator-composition.ts: requireEnvironment() (Line 49) calls Array.isArray() outside a boundary. requireConfiguration() (Line 60) reads environment[name] outside a boundary.
  5. apps/integration-service/src/plugin-vault-secret-store.ts: requirePayload() (Line 155) and requireVaultReadPayload() (Lines 211, 218, 226) call Array.isArray() outside a boundary.
  6. .github/workflows/verify-integration-coverage.yml: Line 217 parses coverage-summary.json outside a try/catch. A malformed summary after a failing run still skips coverage_status and the diagnostics artifact.

Each of these can let a revoked Proxy or throwing getter escape as a native error instead of the applicable fixed error. Convert each unbounded read into the bounded helper pattern used elsewhere in plugin-credential.ts and plugin-credential-repository.ts.

I performed static inspection only.


🧠 Learnings used
Learnt from: seonghobae
Repo: ContextualWisdomLab/life-os PR: 261
File: apps/integration-service/src/plugin-delivery-attempt-claim.test.ts:222-233
Timestamp: 2026-09-09T09:51:03.121Z
Learning: In `apps/integration-service/src/plugin-delivery-attempt-claim.ts` and `apps/integration-service/src/plugin-delivery-attempt-execution-fence.ts`, an async bounded dependency helper must not return hostile durable evidence as raw generic `T`. Promise resolution can inspect a revoked Proxy's `then` property outside the helper's `try` boundary. Return a plain envelope such as `{ value }` instead, then pass `value` to a bounded synchronous evidence parser so all revoked-Proxy failures convert to the fixed authority error.
Learnt from: seonghobae
Repo: ContextualWisdomLab/life-os PR: 261
File: apps/integration-service/src/plugin-delivery-attempt-claim.test.ts:228-239
Timestamp: 2026-09-09T08:11:03.259Z
Learning: In `apps/integration-service/src/plugin-delivery-attempt-claim.ts` and `apps/integration-service/src/plugin-delivery-attempt-execution-fence.ts`, `Array.isArray(value)` can throw for a revoked `Proxy`; evaluate it through the relevant bounded-read helper so the code converts the failure to the fixed authority error. Regression tests for durable revoked proxies must pre-resolve the proxy before revocation, because returning a revoked proxy directly from an async store can fail during Promise assimilation before post-persistence `requireEvidence` executes.

🧠 Learnings used
Learnt from: seonghobae
Repo: ContextualWisdomLab/life-os PR: 261
File: apps/integration-service/src/plugin-delivery-attempt-claim.test.ts:222-233
Timestamp: 2026-09-09T09:51:03.121Z
Learning: In `apps/integration-service/src/plugin-delivery-attempt-claim.ts` and `apps/integration-service/src/plugin-delivery-attempt-execution-fence.ts`, an async bounded dependency helper must not return hostile durable evidence as raw generic `T`. Promise resolution can inspect a revoked Proxy's `then` property outside the helper's `try` boundary. Return a plain envelope such as `{ value }` instead, then pass `value` to a bounded synchronous evidence parser so all revoked-Proxy failures convert to the fixed authority error.

Learnt from: seonghobae
Repo: ContextualWisdomLab/life-os PR: 261
File: apps/integration-service/src/plugin-delivery-attempt-claim.test.ts:228-239
Timestamp: 2026-09-09T08:11:03.259Z
Learning: In `apps/integration-service/src/plugin-delivery-attempt-claim.ts` and `apps/integration-service/src/plugin-delivery-attempt-execution-fence.ts`, `Array.isArray(value)` can throw for a revoked `Proxy`; evaluate it through the relevant bounded-read helper so the code converts the failure to the fixed authority error. Regression tests for durable revoked proxies must pre-resolve the proxy before revocation, because returning a revoked proxy directly from an async store can fail during Promise assimilation before post-persistence `requireEvidence` executes.

You are interacting with an AI system.

Copy link
Copy Markdown
Contributor Author

Exact current head is 2e0fcde61fcb53b09b5f888a85cf4b00db9b18b9. Push-triggered coverage run 34394729533 completed SUCCESS on that exact SHA, and retained artifact 10121100682 is bound to the same head. Prior review submissions predate this head. @coderabbitai review

Please review the whole current diff against base a81c8f243eaedb5f7efddc8a6c208083c8c256e3, with particular attention to durable credential authority after asynchronous provider I/O, hostile Promise-assimilation boundaries, persisted evidence validation, test-database destructive guards, and bounded CI diagnostics. This request does not treat predecessor review as current-head approval.

@coderabbitai

coderabbitai Bot commented Sep 9, 2026

Copy link
Copy Markdown

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

head='2e0fcde61fcb53b09b5f888a85cf4b00db9b18b9'
base='a81c8f243eaedb5f7efddc8a6c208083c8c256e3'

echo '=== confirm base and head identity ==='
git show -s --format='head=%H%nsubject=%s' "$head"
git show -s --format='base=%H%nsubject=%s' "$base" || echo 'base not found locally'

echo '=== merge-base check ==='
git merge-base "$base" "$head" 2>/dev/null || echo 'no common ancestor found locally'

echo '=== full diff stat base..head ==='
git diff --stat "$base" "$head" 2>/dev/null | tail -40 || echo 'diff failed, base may be unreachable'

echo '=== test-database destructive guard source ==='
git show "${head}:apps/integration-service/src/plugin-delivery-attempt-test-database.ts" | cat -n

echo '=== test-database test file ==='
git show "${head}:apps/integration-service/src/plugin-delivery-attempt-test-database.test.ts" | cat -n

echo '=== integration test destructive setup usages ==='
git grep -n -I -C 6 -E '(DROP SCHEMA|CREATE SCHEMA|TRUNCATE|LOOPBACK|loopback|127\.0\.0\.1|localhost)' "$head" -- apps/integration-service/src || true

echo '=== coverage workflow diagnostics current state ==='
git show "${head}:.github/workflows/verify-integration-coverage.yml" | nl -ba | sed -n '150,230p'

Length of output: 98548


@seonghobae I reviewed the whole diff for exact head 2e0fcde61fcb53b09b5f888a85cf4b00db9b18b9 against base a81c8f243eaedb5f7efddc8a6c208083c8c256e3. The base is the correct merge-base. This confirms and extends the review I completed on this same head in my previous message.

Test-database destructive guards are sound.

parsePluginDeliveryAttemptTestDatabaseTarget() in apps/integration-service/src/plugin-delivery-attempt-test-database.ts enforces three checks before any test can run destructive SQL:

  • The URL must resolve to the exact role life_os and the exact database life_os_integration.
  • The URL must supply exactly one sslmode value from the fixed allowlist.
  • sslmode=disable is valid only when the hostname is a loopback host.

Every integration test that issues DROP SCHEMA, CREATE SCHEMA, or TRUNCATE uses this validated target or a hardcoded loopback pool. plugin-operator-replay-postgres.integration.test.ts adds an equivalent loopback check before its own schema drop. I found no destructive path that bypasses these guards.

Bounded CI diagnostics still has one gap.

In .github/workflows/verify-integration-coverage.yml, the test-report parse at Line 166 has a try/catch. The coverage-summary parse at Line 217 does not. If Vitest leaves a partial or malformed coverage-summary.json after a failing run, this parse throws before the script writes coverage_status to GITHUB_OUTPUT. The artifact upload step then does not run. The workflow reports a parser error instead of the captured Vitest exit status. Wrap the coverage-summary read and parse in a try/catch. Keep totals as null on failure. Always write coverage_status and exit with the captured status.

Durable credential authority after asynchronous provider I/O is correct. This restates my prior confirmation for this exact head: bind() in apps/integration-service/src/plugin-credential.ts captures boundAt once, requires installedAt <= boundAt, calls secretStore.verifySecret() before granting authority, and re-reads installation and binding evidence after verification. The new regression test proves rejection when installation identity changes during provider verification.

Persisted evidence validation and hostile Promise-assimilation boundaries have open items that remain unchanged at this head. These files did not change in this commit, but they are part of the current head state, so I restate them for completeness:

  1. apps/integration-service/src/plugin-delivery-attempt-retry.ts: boundedDependency() returns raw Promise<T>.
  2. apps/integration-service/src/plugin-delivery-attempt-retry-repository.ts: boundedEvidenceDependency() returns raw Promise<T>.
  3. apps/integration-service/src/plugin-vault-hosted-runtime.ts: requireEnvironment() and requirePool() call Array.isArray() outside a boundary.
  4. apps/integration-service/src/plugin-vault-operator-composition.ts: requireEnvironment() and requireConfiguration() read untrusted values outside a boundary.
  5. apps/integration-service/src/plugin-vault-secret-store.ts: requirePayload() and requireVaultReadPayload() call Array.isArray() outside a boundary.

Each of these can let a revoked Proxy or a throwing getter escape as a native error instead of the applicable fixed error. Convert each read into the bounded helper pattern already used in plugin-credential.ts and plugin-credential-repository.ts.

I used the retrieved revoked-Proxy and Promise-assimilation guidance for this PR to evaluate items 1 and 2. I performed static inspection only.


🧠 Learnings used
Learnt from: seonghobae
Repo: ContextualWisdomLab/life-os PR: 261
File: apps/integration-service/src/plugin-delivery-attempt-claim.test.ts:222-233
Timestamp: 2026-09-09T09:51:03.121Z
Learning: In `apps/integration-service/src/plugin-delivery-attempt-claim.ts` and `apps/integration-service/src/plugin-delivery-attempt-execution-fence.ts`, an async bounded dependency helper must not return hostile durable evidence as raw generic `T`. Promise resolution can inspect a revoked Proxy's `then` property outside the helper's `try` boundary. Return a plain envelope such as `{ value }` instead, then pass `value` to a bounded synchronous evidence parser so all revoked-Proxy failures convert to the fixed authority error.
Learnt from: seonghobae
Repo: ContextualWisdomLab/life-os PR: 261
File: apps/integration-service/src/plugin-delivery-attempt-claim.test.ts:228-239
Timestamp: 2026-09-09T08:11:03.259Z
Learning: In `apps/integration-service/src/plugin-delivery-attempt-claim.ts` and `apps/integration-service/src/plugin-delivery-attempt-execution-fence.ts`, `Array.isArray(value)` can throw for a revoked `Proxy`; evaluate it through the relevant bounded-read helper so the code converts the failure to the fixed authority error. Regression tests for durable revoked proxies must pre-resolve the proxy before revocation, because returning a revoked proxy directly from an async store can fail during Promise assimilation before post-persistence `requireEvidence` executes.

🧠 Learnings used
Learnt from: seonghobae
Repo: ContextualWisdomLab/life-os PR: 261
File: apps/integration-service/src/plugin-delivery-attempt-claim.test.ts:222-233
Timestamp: 2026-09-09T09:51:03.121Z
Learning: In `apps/integration-service/src/plugin-delivery-attempt-claim.ts` and `apps/integration-service/src/plugin-delivery-attempt-execution-fence.ts`, an async bounded dependency helper must not return hostile durable evidence as raw generic `T`. Promise resolution can inspect a revoked Proxy's `then` property outside the helper's `try` boundary. Return a plain envelope such as `{ value }` instead, then pass `value` to a bounded synchronous evidence parser so all revoked-Proxy failures convert to the fixed authority error.

Learnt from: seonghobae
Repo: ContextualWisdomLab/life-os PR: 261
File: apps/integration-service/src/plugin-delivery-attempt-claim.test.ts:228-239
Timestamp: 2026-09-09T08:11:03.259Z
Learning: In `apps/integration-service/src/plugin-delivery-attempt-claim.ts` and `apps/integration-service/src/plugin-delivery-attempt-execution-fence.ts`, `Array.isArray(value)` can throw for a revoked `Proxy`; evaluate it through the relevant bounded-read helper so the code converts the failure to the fixed authority error. Regression tests for durable revoked proxies must pre-resolve the proxy before revocation, because returning a revoked proxy directly from an async store can fail during Promise assimilation before post-persistence `requireEvidence` executes.

You are interacting with an AI system.

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

현재 exact head 26b878fae3159bd690a6ef3131c0fc03a91f31c7 기준으로 전체 diff를 다시 검토해 주세요. 이전 head의 review verdict는 승계하지 말고, current production/security/persistence/coverage/docstring 경계에서 아직 유효한 finding만 남겨 주세요. Exact coverage run 34396155776은 이 head에서 SUCCESS였으며 100% production coverage gate와 bounded diagnostic-retention contract는 유지됩니다.

@coderabbitai

coderabbitai Bot commented Sep 9, 2026

Copy link
Copy Markdown

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

head='26b878fae3159bd690a6ef3131c0fc03a91f31c7'
base="$(git merge-base "$head" origin/main 2>/dev/null || git merge-base "$head" main)"

echo '=== exact identity and merge base ==='
git show -s --format='head=%H%nparents=%P%nsubject=%s%nbody=%b' "$head"
git show -s --format='base=%H%nsubject=%s' "$base"
printf 'range=%s..%s\n' "$base" "$head"

echo '=== full range paths ==='
git diff --name-status "$base" "$head"

echo '=== exact-head paths and direct diff ==='
git diff-tree --no-commit-id --name-status -r "$head"
git diff --no-ext-diff --find-renames --find-copies --unified=100 "${head}^" "$head"

echo '=== relevant range commits ==='
git log --format='%H %s' "$base..$head" -- \
  apps/integration-service/src \
  apps/integration-service/migrations \
  apps/integration-service/package.json \
  apps/integration-service/vitest.config.ts \
  .github/workflows

echo '=== changed production source outlines ==='
git diff --name-only "$base" "$head" -- 'apps/integration-service/src/**/*.ts' \
  | rg -v '\.test\.ts$' \
  | while IFS= read -r file; do
      [ -n "$file" ] || continue
      echo "--- $file ---"
      git show "${head}:${file}" > "/tmp/$(basename "$file")"
      ast-grep outline "/tmp/$(basename "$file")" --items all --view expanded || true
    done

echo '=== focused exact-head boundary modules ==='
for file in \
  apps/integration-service/src/plugin-credential.ts \
  apps/integration-service/src/plugin-credential-repository.ts \
  apps/integration-service/src/plugin-delivery-attempt-retry.ts \
  apps/integration-service/src/plugin-delivery-attempt-retry-repository.ts \
  apps/integration-service/src/plugin-vault-hosted-runtime.ts \
  apps/integration-service/src/plugin-vault-operator-composition.ts \
  apps/integration-service/src/plugin-vault-secret-store.ts \
  apps/integration-service/src/plugin-delivery-attempt-test-database.ts \
  apps/integration-service/src/production-docstring-contract.test.ts \
  apps/integration-service/vitest.config.ts \
  apps/integration-service/package.json \
  .github/workflows/verify-integration-coverage.yml
do
  if git cat-file -e "${head}:${file}" 2>/dev/null; then
    echo "--- $file ---"
    git show "${head}:${file}" | cat -n
  fi
done

echo '=== current fixed-error and hostile-boundary contexts ==='
git grep -n -I -C 6 -E \
  '(bounded(Input|Evidence|.*Dependency)|Promise<\{ value|Promise<T>|Array\.isArray|\.query\s*\(|getInstallation|findById|revokeActive|verifySecret|cancel|fill\(|JSON\.parse|coverage_status|upload-artifact|raw)' \
  "$head" -- apps/integration-service/src .github/workflows/verify-integration-coverage.yml || true

echo '=== destructive test setup contexts ==='
git grep -n -I -C 8 -E \
  '(DROP SCHEMA|CREATE SCHEMA|TRUNCATE|loopback|127\.0\.0\.1|localhost|sslmode|life_os_integration)' \
  "$head" -- apps/integration-service/src || true

echo '=== hostile-boundary regression inventory ==='
git grep -n -I -C 4 -E \
  '(Proxy\.revocable|revok|defineProperty|getter|Promise\.resolve|Persistence(Evidence|Validation)Error|PluginCredentialError|HostedRuntimeError|CompositionError|SecretStoreError)' \
  "$head" -- apps/integration-service/src '*test.ts' || true

echo '=== formatter, whitespace, and final newline checks ==='
git diff --check "$base" "$head"
python3 - <<'PY'
import subprocess
head = '26b878fae3159bd690a6ef3131c0fc03a91f31c7'
base = subprocess.check_output(
    ['git', 'merge-base', head, 'origin/main'], text=True, stderr=subprocess.DEVNULL
).strip() if subprocess.call(
    ['git', 'rev-parse', '--verify', 'origin/main'],
    stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL
) == 0 else subprocess.check_output(['git', 'merge-base', head, 'main'], text=True).strip()
for path in subprocess.check_output(
    ['git', 'diff', '--name-only', base, head], text=True
).splitlines():
    blob = subprocess.check_output(['git', 'show', f'{head}:{path}'])
    if blob and not blob.endswith(b'\n'):
        print('MISSING_FINAL_NEWLINE ' + path)
PY

Length of output: 102516


🏁 Script executed:

#!/bin/bash
set -u

head='26b878fae3159bd690a6ef3131c0fc03a91f31c7'
parent='2e0fcde61fcb53b09b5f888a85cf4b00db9b18b9'

show_file() {
  local file="$1"
  echo "=== ${file} ==="
  if git cat-file -e "${head}:${file}" 2>/dev/null; then
    git show "${head}:${file}" | nl -ba
  else
    echo 'MISSING'
  fi
}

echo '=== direct head diff ==='
git diff --no-ext-diff --unified=80 "$parent" "$head" || true

echo '=== direct CHANGELOG newline and formatter scope ==='
git show "${head}:CHANGELOG.md" | tail -c 1 | od -An -t x1
git show "${head}:.github/workflows/verify-integration-coverage.yml" 2>/dev/null \
  | rg -n -C 8 '(prettier|CHANGELOG|coverage-summary|JSON\.parse|coverage_status|upload-artifact|rm )' || true

for file in \
  apps/integration-service/src/plugin-delivery-attempt-retry.ts \
  apps/integration-service/src/plugin-delivery-attempt-retry-repository.ts \
  apps/integration-service/src/plugin-vault-hosted-runtime.ts \
  apps/integration-service/src/plugin-vault-operator-composition.ts \
  apps/integration-service/src/plugin-vault-secret-store.ts \
  apps/integration-service/src/plugin-credential.ts \
  apps/integration-service/src/plugin-credential-repository.ts \
  apps/integration-service/src/plugin-delivery-attempt-test-database.ts \
  apps/integration-service/src/plugin-operator-replay-postgres.integration.test.ts \
  apps/integration-service/src/production-docstring-contract.test.ts \
  apps/integration-service/vitest.config.ts \
  apps/integration-service/package.json \
  .github/workflows/verify-integration-coverage.yml
do
  show_file "$file"
done

echo '=== current helper signatures and unbounded access contexts ==='
for file in \
  apps/integration-service/src/plugin-delivery-attempt-retry.ts \
  apps/integration-service/src/plugin-delivery-attempt-retry-repository.ts \
  apps/integration-service/src/plugin-vault-hosted-runtime.ts \
  apps/integration-service/src/plugin-vault-operator-composition.ts \
  apps/integration-service/src/plugin-vault-secret-store.ts
do
  echo "--- ${file} ---"
  git show "${head}:${file}" 2>/dev/null \
    | rg -n -C 8 '(async function bounded|Promise<T>|Promise<\{ value|Array\.isArray|try \{|catch|environment\[|dependencies\.|\.query\s*\()' \
    || true
done

echo '=== current regression coverage for the focused hostile-boundary cases ==='
for file in \
  apps/integration-service/src/plugin-delivery-attempt-retry-coverage.test.ts \
  apps/integration-service/src/plugin-delivery-attempt-retry-repository.test.ts \
  apps/integration-service/src/plugin-vault-hosted-runtime.test.ts \
  apps/integration-service/src/plugin-vault-operator-composition-coverage.test.ts \
  apps/integration-service/src/plugin-vault-secret-store-coverage.test.ts \
  apps/integration-service/src/plugin-vault-final-coverage.test.ts
do
  echo "--- ${file} ---"
  git show "${head}:${file}" 2>/dev/null \
    | rg -n -i -C 5 '(Proxy|revoc|defineProperty|getter|Promise\.resolve|toThrow|rejects)' \
    || true
done

echo '=== current direct docs-only classification ==='
git diff --name-only "$parent" "$head" | while IFS= read -r file; do
  echo "--- ${file} ---"
  git diff --numstat "$parent" "$head" -- "$file"
done

echo '=== whitespace checks ==='
git diff --check "$parent" "$head" || true

Length of output: 220729


@seonghobae 현재 exact head 26b878fae3159bd690a6ef3131c0fc03a91f31c7를 전체 범위에서 검토했습니다.

현재 유효한 결함은 네 가지입니다.

  1. P1 — Retry async helper가 hostile evidence를 raw T로 반환합니다.
    apps/integration-service/src/plugin-delivery-attempt-retry.tsboundedDependency()는 Line 67에서 Promise<T>를 반환합니다.
    apps/integration-service/src/plugin-delivery-attempt-retry-repository.tsboundedEvidenceDependency()도 Line 99에서 Promise<T>를 반환합니다.

    dependency가 이미 resolve된 Proxy를 반환한 뒤 Proxy가 revoke되면, helper의 outer Promise가 then을 확인하는 작업은 try 블록 밖에서 발생할 수 있습니다. 이 경우 native TypeErrorPluginDeliveryAttemptRetryAuthorityError 또는 PluginDeliveryAttemptRetryPersistenceEvidenceError를 우회합니다.

    helper는 { value } 같은 plain envelope을 반환해야 합니다. 이후 bounded synchronous parser가 value를 읽어야 합니다. Proxy를 먼저 resolve한 뒤 revoke하는 회귀 테스트도 필요합니다.

  2. P1 — Hosted runtime과 operator composition이 hostile input read를 고정 오류로 변환하지 않습니다.
    apps/integration-service/src/plugin-vault-hosted-runtime.ts은 Line 62와 Line 88에서 Array.isArray()를 직접 호출합니다.
    apps/integration-service/src/plugin-vault-operator-composition.ts은 Line 49에서 같은 호출을 합니다.

    또한 composition 모듈은 Line 60에서 environment[name]을 직접 읽고, Line 88-91, Line 103-106, Line 118, Line 135-136, Line 174-177에서 dependency 또는 port 속성을 직접 읽습니다.

    revoked Proxy 또는 throwing getter는 PluginVaultHostedRuntimeError 또는 PluginVaultOperatorCompositionError 대신 native error를 만들 수 있습니다. shape check와 property snapshot을 bounded read helper 안에서 수행해야 합니다. revoked Proxy와 throwing-getter 회귀 테스트도 필요합니다.

  3. P1 — Vault secret-store가 hostile payload와 durable envelope을 고정 오류로 변환하지 않습니다.
    apps/integration-service/src/plugin-vault-secret-store.tsrequirePayload()는 Line 155에서 Array.isArray()를 직접 호출합니다.
    requireVaultReadPayload()도 Line 211, Line 218, Line 226에서 Array.isArray()와 nested data property read를 경계 없이 수행합니다.

    revoked Proxy 또는 throwing data getter는 PluginVaultSecretStoreError 대신 native exception을 노출할 수 있습니다. 이 경로는 plaintext credential material을 검증하는 secret-store boundary에 있습니다.

    payload와 Vault read envelope의 shape check 및 property snapshot을 bounded read helper로 감싸야 합니다. hostile payload, outer envelope, nested data getter, revoked Proxy를 대상으로 fixed-error 회귀 테스트를 추가해야 합니다.

  4. P2 — Malformed coverage summary가 captured Vitest status와 artifact retention을 우회합니다.
    .github/workflows/verify-integration-coverage.yml의 Line 217은 coverage-summary.jsontry/catch 밖에서 parse합니다.

    Vitest가 partial 또는 malformed summary를 남기면 Node diagnostics 단계는 Line 250의 coverage_status 기록 전에 실패합니다. Line 254의 artifact upload 조건도 충족하지 못합니다. 이 경우 workflow는 captured Vitest exit status 대신 parser failure를 보고합니다.

    coverage summary read와 parse를 try/catch로 감싸야 합니다. 실패 시 approved.totalsnull로 유지해야 합니다. 이후 workflow는 항상 coverage_status를 기록하고 captured status로 종료해야 합니다.

직접 head 변경은 CHANGELOG.md뿐입니다. 이 변경은 문서만 수정합니다. 실행 경로, persistence ownership, network authority, production coverage scope, 또는 100% threshold를 변경하지 않습니다.

보고된 exact run 34396155776의 SUCCESS와 100% production coverage gate는 현재 실행 증거입니다. Coverage workflow는 raw Vitest output과 full JSON report를 upload 전에 삭제합니다. Retained summary는 4096-byte 제한과 0o600 mode를 유지합니다.

이 검토에는 이 PR의 retrieved revoked-Proxy 및 Promise-assimilation guidance를 사용했습니다. Repository code는 실행하지 않았습니다.


🧠 Learnings used
Learnt from: seonghobae
Repo: ContextualWisdomLab/life-os PR: 261
File: apps/integration-service/src/plugin-delivery-attempt-claim.test.ts:222-233
Timestamp: 2026-09-09T09:51:03.121Z
Learning: In `apps/integration-service/src/plugin-delivery-attempt-claim.ts` and `apps/integration-service/src/plugin-delivery-attempt-execution-fence.ts`, an async bounded dependency helper must not return hostile durable evidence as raw generic `T`. Promise resolution can inspect a revoked Proxy's `then` property outside the helper's `try` boundary. Return a plain envelope such as `{ value }` instead, then pass `value` to a bounded synchronous evidence parser so all revoked-Proxy failures convert to the fixed authority error.

Learnt from: seonghobae
Repo: ContextualWisdomLab/life-os PR: 261
File: apps/integration-service/src/plugin-delivery-attempt-claim.test.ts:228-239
Timestamp: 2026-09-09T08:11:03.259Z
Learning: In `apps/integration-service/src/plugin-delivery-attempt-claim.ts` and `apps/integration-service/src/plugin-delivery-attempt-execution-fence.ts`, `Array.isArray(value)` can throw for a revoked `Proxy`; evaluate it through the relevant bounded-read helper so the code converts the failure to the fixed authority error. Regression tests for durable revoked proxies must pre-resolve the proxy before revocation, because returning a revoked proxy directly from an async store can fail during Promise assimilation before post-persistence `requireEvidence` executes.

You are interacting with an AI system.

Copy link
Copy Markdown
Contributor Author

2026-09-10 prerequisite-currentness supplement: #261 exact 26b878fae3159bd690a6ef3131c0fc03a91f31c7 and its 100% Integration quality evidence are unchanged. The shared #249 prerequisite has advanced beyond the 9d7bf... state in this PR body: formatter owner run 34432057506 / job 102729431968 completed and self-retired to candidate 5a950dc880887ace98fbc2c579e513583dd08a68; its bot-triggered ordinary PR workflows were action_required/zero-job and are not GREEN. Current #249 exact is 3090de570c29c4835b3cb1daed62351e4166e97e, carrying issue #262's permanent AST-backed Commercial Readiness production-docstring test and a bounded RED writer. Run 34436246532 / job 102741797513 is still queued without a runner. This does not alter or supersede #261's exact Integration coverage/docstring evidence; it only updates the shared prerequisite state.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant