fix(kpi): restack provenance JSON byte integrity on d8bdcf main - #335
fix(kpi): restack provenance JSON byte integrity on d8bdcf main#335seonghobae wants to merge 1 commit into
Conversation
|
Important Review skippedDraft detected. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Superseded by consolidated current lineage PR #348, which carries this strict KPI provenance integrity and entrypoint coverage work on the current protected-main line. Closing the predecessor; its checks and reviews are historical only. |
Purpose
Rebuild only PR #327's strict production-KPI provenance byte-integrity hardening onto the current protected-main lineage after #331 advanced
main. No predecessor CI, review, scanner, coverage, model/status, production-KPI, release, deployment, legal-rights, or acquisition authority transfers.Exact construction
mainat the final pre-write refetch:d8bdcf79149635e5c34c992e91ce22b9a78c9b49;46485f3024885746e58beff0ff559b426f06186a;57f1f229c16ef845f6ad8ff943eafde3d829c06a;scripts/kpi-gate.mjsandtest/kpi-provenance-json-integrity.test.ts;2ce57ef368f36a196645c94948dad3f2476ca5a0andc8a072efd12f86c826c0b6d98b506ecee9817c76.A fresh comparison from #327's construction base
2d9d4e26a81d043a1985fc2244efb2a311fcf1d0to current protected main showed only the two production-environment-governance paths merged through #331, with no overlap on this KPI provenance slice. The protectedscripts/kpi-gate.mjsblob was still the original12363af16b4168efef2fd0e45bae6086d968bdf2, and the focused test path remained absent, immediately before construction.KPI provenance integrity contract
Strict provenance remains raw bytes until fatal UTF-8 decoding and rejects escape-equivalent duplicate decoded JSON object names before
JSON.parseor production-source identity, collection timestamp, record count, SHA-256/byte-size, verified snapshot, final identity, and least-authority KPI child-process decisions. Existing production-source/provenance binding remains unchanged.This hardens evidence parsing only. It does not synthesize or claim a real 30-day production KPI window.
Evidence boundary
Keep Draft until this unchanged exact head receives fresh terminal-success application
ci,reviewer-ci, protected-base-eligible centralSecurity Scan, configured exact 100% owned production statement/branch/function/line coverage with realistic tests, and zero valid unresolved findings. Pending, queued, skipped, absent, neutral, failed, cancelled, stale, predecessor, status-only, model-only, or rate-limited evidence is non-passing.Immediately before Ready or merge, independently re-resolve protected main, exact head/base/ancestry, workflow checkout SHAs, formal reviews/threads, live rulesets, exact central Security Scan revision/triggers/base filters/thresholds, releases, and active-writer state.
No force update, gate weakening, synthetic KPI/release/deployment/legal evidence, reviewer/secret invention, outbound-license choice, repair/self-modifying workflow, or acquisition-ready claim is introduced.
Supersedes #327 only after fresh exact-head verification and protected integration. Related: #3, #84.