Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
72 commits
Select commit Hold shift + click to select a range
cf12d3e
test(naming): expose generic runner evidence fields
seonghobae Sep 1, 2026
70fc253
fix(naming): project runner evidence into semantic fields
seonghobae Sep 1, 2026
31c9254
fix(naming): use semantic runner audit contract
seonghobae Sep 1, 2026
f2fb1a4
test(naming): align runner source expectations
seonghobae Sep 1, 2026
118ce96
test(naming): use semantic runner audit evidence
seonghobae Sep 1, 2026
7aa7f38
test(naming): update attempt report vocabulary
seonghobae Sep 1, 2026
2bb7477
test(naming): update timestamp audit vocabulary
seonghobae Sep 1, 2026
3cc86f1
test(naming): update evaluator attempt vocabulary
seonghobae Sep 1, 2026
273b035
test(ci): expose semantic runner report regression
seonghobae Sep 1, 2026
fed8694
fix(naming): version semantic runner audit report
seonghobae Sep 1, 2026
5a06070
fix(ci): preserve runner report contract with semantic decision
seonghobae Sep 1, 2026
bcee514
test(naming): verify semantic runner report schema
seonghobae Sep 1, 2026
823adae
test(naming): use semantic audit status fixture
seonghobae Sep 1, 2026
40846d3
test(naming): verify semantic capability report
seonghobae Sep 1, 2026
75ec842
test(naming): align retained audit report name
seonghobae Sep 1, 2026
9b0103f
test(runner-audit): preserve stable operator report contract
seonghobae Sep 1, 2026
e36d419
Merge 9b0103fffa11a7aed07b6659319a2f0814c954b9 into 6b2b3e90dc3d5bd24…
seonghobae Sep 1, 2026
95b3d15
test: align runner audit retained report contract
seonghobae Sep 1, 2026
478b3d3
test: restore runner audit report schema expectations
seonghobae Sep 1, 2026
e75b54e
test(acquisition): require distributed package metadata digest
seonghobae Sep 1, 2026
eeb0ea8
fix(acquisition): bind distributed package metadata digest
seonghobae Sep 1, 2026
4b77cd7
docs(acquisition): bind package metadata digest evidence
seonghobae Sep 1, 2026
b2ee3d0
docs(acquisition): refresh integrated licensing authority
seonghobae Sep 1, 2026
1365d46
docs(gap): refresh protected licensing baseline
seonghobae Sep 1, 2026
c3f55c2
docs(changelog): record semantic runner and package evidence repairs
seonghobae Sep 1, 2026
f4eed91
test(operations): preserve runner audit v1 nested report schema
seonghobae Sep 1, 2026
083f3e0
fix(operations): preserve runner audit v1 report schema
seonghobae Sep 1, 2026
37e6c90
docs(changelog): restore accurate undici gate history
seonghobae Sep 1, 2026
f608670
test(runner): follow semantic workflow-run evidence contract
seonghobae Sep 2, 2026
162c0ab
refactor(naming): qualify runner evidence internals
seonghobae Sep 2, 2026
cb6c236
Merge remote-tracking branch 'origin/main' into fix/runner-assignment…
claude Sep 2, 2026
5ed63ed
fix(ops): restack semantic runner evidence on protected main
seonghobae Sep 3, 2026
a2d6310
Merge protected main into semantic runner evidence lane
seonghobae Sep 4, 2026
f92fdb2
Merge #546 semantic reviewer prerequisite into runner-assignment lane
seonghobae Sep 4, 2026
4926f85
merge: restack runner-assignment lane on reviewer fixture repair
seonghobae Sep 4, 2026
7a016f3
merge: restack runner-assignment lane on symbol-seeded reviewer recovery
seonghobae Sep 4, 2026
0fbfd94
merge: restack runner-assignment lane on unambiguous CodeGraph recovery
seonghobae Sep 4, 2026
e4771c1
merge: inherit bounded CodeGraph recovery coverage
seonghobae Sep 4, 2026
f4003ca
merge: inherit lifecycle-safe CodeGraph recovery
seonghobae Sep 4, 2026
425ff4c
merge: inherit exact-whitespace CodeGraph recovery
seonghobae Sep 4, 2026
8a50151
merge: inherit code-current CodeGraph recovery docs
seonghobae Sep 4, 2026
3510a22
merge: inherit exact CodeGraph path identity repair
seonghobae Sep 4, 2026
9987257
merge: inherit CodeGraph scope coverage guard
seonghobae Sep 4, 2026
c292287
merge: inherit exact long-path CodeGraph recovery
seonghobae Sep 4, 2026
a41e42a
merge: inherit CodeGraph ambient-authority isolation
seonghobae Sep 5, 2026
3289867
merge: inherit reviewer cycle and isolated-home repairs
seonghobae Sep 5, 2026
b74e684
merge: inherit complete CodeGraph recovery boundary
seonghobae Sep 5, 2026
3311242
merge: inherit independent reviewer evidence boundary
seonghobae Sep 5, 2026
029e9e4
merge: inherit deterministic finding identity boundary
seonghobae Sep 5, 2026
3f96cef
test(reviewer): inherit CodeGraph probe-budget boundary
seonghobae Sep 5, 2026
67afcb0
merge: restack #533 on #546 reviewer prerequisite
seonghobae Sep 5, 2026
7bf318d
merge: restack #533 on complete CodeGraph recovery
seonghobae Sep 5, 2026
764b95d
merge: restack #533 on complete CodeGraph primary scope
seonghobae Sep 5, 2026
9b9dc0d
merge: restack #533 on symlink-safe CodeGraph seed boundary
seonghobae Sep 5, 2026
af501f7
merge: restack #533 on review-wait cycle repair
seonghobae Sep 5, 2026
c7365bf
merge: restack #533 on complete symbol-map recovery
seonghobae Sep 5, 2026
02393d1
merge: restack #533 on physical CodeGraph checkout provenance
seonghobae Sep 5, 2026
bf7f8e0
merge: restack #533 on exact CodeGraph path identity
seonghobae Sep 5, 2026
5e992dc
merge: restack #533 on Unicode CodeGraph scope parity
seonghobae Sep 5, 2026
4c6adc5
merge: restack #533 on executable CodeGraph retry semantics
seonghobae Sep 5, 2026
5e5772d
merge: restack #533 on physical Docker checkout provenance
seonghobae Sep 5, 2026
80bbcae
merge: restack #533 on CodeGraph temp isolation
seonghobae Sep 5, 2026
8cad975
merge: restack #533 on complete reviewer context
seonghobae Sep 5, 2026
818a120
merge: restack #533 on fail-before-execution reviewer scope
seonghobae Sep 5, 2026
efcebeb
merge: restack #533 on JSON-scope reviewer recovery
seonghobae Sep 5, 2026
d961bf1
merge: restack #533 on JSON-safe symbol recovery
seonghobae Sep 5, 2026
53ea72f
merge: restack #533 on reviewer recovery documentation
seonghobae Sep 5, 2026
52b9195
merge: restack #533 on exact Linux path identity prerequisite
seonghobae Sep 5, 2026
91c59bb
merge: restack #533 on reviewer hosted-RED repair
seonghobae Sep 5, 2026
a819159
merge: restack #533 on reviewer docstring repair
seonghobae Sep 5, 2026
83c9c9a
merge: restack #533 on protected reviewer truth
seonghobae Sep 6, 2026
8ced86c
merge(context-fabric): restack runner-assignment evidence on protecte…
seonghobae Sep 6, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
15 changes: 8 additions & 7 deletions docs/LICENSING_AND_IP_TRANSFER.md
Original file line number Diff line number Diff line change
@@ -1,12 +1,12 @@
# Noema Licensing and IP Transfer

- **Status:** Repository rights policy/evidence baseline; source-license decision is Apache-2.0 on PR #530 until protected integration. This is not acquisition or transfer legal clearance.
- **Status:** Repository rights policy/evidence baseline; Apache-2.0 source-license decision is integrated on protected `main@6b2b3e90dc3d5bd24cd27ed11db41b9eb7106010` through PR #530. This is not acquisition or transfer legal clearance.
- **Scope:** Noema source rights, package/container metadata, third-party obligations, contributor/IP provenance, release distribution, and acquisition transfer evidence.
- **Decision authority:** Repository automation may detect, authenticate, inventory, and compare evidence. The repository owner has explicitly selected Apache License 2.0 for Noema source; future outbound-license changes and transfer-rights decisions remain owner/legal governance actions.

## 1. Core invariant

**Public source availability is not a grant of rights by itself.** The grant comes from the controlling repository rights file. On PR #530, root `LICENSE` declares Apache-2.0 for Noema source. Until that exact head integrates, protected `main` remains the currently shipped source-rights authority.
**Public source availability is not a grant of rights by itself.** The grant comes from the controlling repository rights file. Protected `main@6b2b3e90dc3d5bd24cd27ed11db41b9eb7106010` includes root `LICENSE` declaring Apache-2.0 for Noema source through merged PR #530.

Noema keeps source licensing, package publication, third-party obligations, and transfer authority separate:

Expand Down Expand Up @@ -40,6 +40,7 @@ For a package that is actually distributed through npm:
- use a valid **SPDX** expression when approved terms have one;
- use `SEE LICENSE IN <filename>` for approved custom terms stored in a bounded repository file;
- use `UNLICENSED` only when package metadata intentionally grants no use rights;
- record the SHA-256 of the exact retained `package.json` bytes in transfer evidence so package-publication metadata cannot be substituted after review;
- regenerate `package-lock.json` whenever root package metadata changes so tracked lock metadata stays exact.

For current Noema, `"private": true` plus absence of an npm distribution channel means root `LICENSE` is the controlling source grant. `private` itself is still only a publication safeguard; it neither grants nor narrows Apache-2.0 source rights.
Expand Down Expand Up @@ -124,7 +125,7 @@ The machine-checkable transfer contract binds, at minimum:
- repository identity and exact source/release revision;
- approved owner/legal decision identifier;
- controlling `LICENSE`/custom-rights file path and SHA-256 when applicable;
- package-publication rights declaration plus metadata hash when a package is actually distributed;
- package-publication rights declaration plus SHA-256 of the exact retained `package.json` bytes when a package is actually distributed;
- exact-release `artifact_rights_metadata` path and SHA-256 when an artifact exposes rights metadata;
- exact-release SBOM identity;
- dependency-license and NOTICE/attribution artifact identities;
Expand Down Expand Up @@ -157,15 +158,15 @@ owner source-license decision

Each arrow requires independent identity/consistency evidence. A mismatch, missing required record, malformed/ambiguous JSON, or unresolved right is a fail-closed condition.

## 8. Current evidence and residual gap — 2026-09-01
## 8. Current evidence and residual gap — 2026-09-02

Protected `main@03ef2301bad020b9ab4dfde2ec3c4e7f460024ca` still has no root `LICENSE`. PR #530 now carries the explicit owner-selected Apache-2.0 source posture:
As observed after PR #530 merged, protected `main@6b2b3e90dc3d5bd24cd27ed11db41b9eb7106010` carries the explicit owner-selected Apache-2.0 source posture:

- root `LICENSE`: Apache License 2.0;
- root `README.md`: customer-facing Apache-2.0 source-license statement and separate third-party obligation boundary;
- `package.json`: remains private and lock-stable; no npm package distribution claim is introduced.

Those declarations are candidate truth until #530 integrates; they are not predecessor evidence for protected main.
These declarations are protected-main source truth. They do not by themselves establish acquisition-transfer authority, third-party compatibility, or release/publication evidence.

Current residual gaps remain deliberately separate:

Expand All @@ -175,7 +176,7 @@ Current residual gaps remain deliberately separate:
- release/publication/deployment evidence remains separate from repository-source rights;
- no source file, README sentence, scanner result, or successful CI run may upgrade those missing evidence classes into a commercial or legal PASS.

Issue #5 carries acquisition owner/legal and ownership/assignment evidence. Issue #66 carries remaining release/publication, NOTICE and provenance/activation boundaries. Issue #531 owns the GPL-family development/build-tool replacement. The source-license decision narrows the gap but does not close those issues.
Issue #5 carries acquisition owner/legal and ownership/assignment evidence. Issue #66 carries remaining release/publication, NOTICE and provenance/activation boundaries. Issue #531 owns the GPL-family development/build-tool replacement. The integrated source-license decision narrows the gap but does not close those issues.

## 9. Non-goals

Expand Down
5 changes: 3 additions & 2 deletions docs/evidence-templates/transfer-evidence.example.json
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,8 @@
"sha256": "replace-with-sha256-of-reviewed-root-rights-file"
},
"package_metadata": {
"license": "replace-with-exact-package-json-license-value"
"license": "replace-with-exact-package-json-license-value",
"sha256": "replace-with-sha256-of-exact-package-json-bytes-when-distributed"
},
"release_rights": {
"tag": "replace-with-v0.0.0",
Expand Down Expand Up @@ -60,4 +61,4 @@
]
}
}
}
}
11 changes: 5 additions & 6 deletions docs/product-technical-gap-baseline.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,13 +4,13 @@

이 문서는 제품 요구, 구현, 검증, 운영 증거 사이의 현재 차이를 한곳에서 추적한다. 저장소 파일과 테스트는 revision-local 또는 protected-source 구현만 증명한다. PR 상태는 exact head와 live base에서, 운영·배포·고객·매출·법적 증거는 해당 외부 권한에서 각각 다시 확인해야 한다. 문서나 성공 boolean만으로 이후 단계의 증거를 만들지 않는다.

이 baseline의 protected-source snapshot은 `main@5aad3e410703faaf52882e2f33fadd25d217bcdd`이며, README/license candidate truth는 PR #530 exact head에만 적용한다. issues #3, #5, #27, #29, #66, #227, #531의 live 상태를 GitHub 권위로 다시 읽어야 하며, protected/main·PR·외부 증거를 서로 대체하지 않는다.
이 baseline의 protected-source snapshot은 `main@6b2b3e90dc3d5bd24cd27ed11db41b9eb7106010`이다. PR #530은 이 protected revision에 이미 병합되어 product-first README와 Apache-2.0 root source grant가 protected truth가 되었다. issues #3, #5, #27, #29, #66, #227, #531의 live 상태를 GitHub 권위로 다시 읽어야 하며, protected/main·PR·외부 증거를 서로 대체하지 않는다.

## Live external observation — 2026-09-01 KST
## Live external observation — 2026-09-02 KST

| Authority | Observation | Consequence |
| --- | --- | --- |
| README/license lane | PR #530 is open and carries the product-first README plus Apache-2.0 root source grant; every push invalidates predecessor-head checks | protected main remains unlicensed until the unchanged exact head integrates |
| README/license lane | PR #530 merged into protected `main@6b2b3e90dc3d5bd24cd27ed11db41b9eb7106010`; root `LICENSE` and product-first README now carry the Apache-2.0 source grant | source-license posture is protected truth, but it is not acquisition-transfer or third-party compatibility evidence |
| npm package boundary | `package.json` remains `private` and the npm package is not a product distribution channel; no package-publication license field is introduced | root `LICENSE` controls source rights without forcing unrelated lockfile metadata churn |
| Dependency licensing | `package-lock.json` contains `LGPL-3.0-or-later` optional dev/build packages on `wrangler → miniflare → sharp → @img/sharp-libvips-*`; issue #531 owns removal/replacement | source Apache-2.0 does not make the current toolchain compliant with the organization no-GPL-family default |
| Release/publication | immutable release/deployment/customer/revenue/transfer evidence remains a separate authority class | source licensing cannot be promoted into acquisition readiness |
Expand All @@ -23,7 +23,7 @@
| Reviewer and maintenance control plane | 독립 App identity, bounded manifest, deterministic fail-closed gates | `reviewer/noema_reviewer/`, maintainer/reviewer workflows, capability-file ingress | reviewer tests, workflow contract tests, current-head review artifacts | Maintainer/Reviewer App 설치·권한·key custody·rotation 및 publication identity | Source contract implemented; external activation evidence is open |
| Hourly product-development loop | `contextual-orchestrator` inference와 별도 Maintainer App publication identity를 사용하는 work-conserving loop | `.github/workflows/hourly-product-development.yml`, orchestrator gateway contract, publication/readiness validators | workflow shape, gateway preflight, lease, publication prerequisite and stale-head refusal tests | zero-PR scheduled proposal publication과 rollback/recovery exercise | Implemented source; production activation incomplete |
| Patch-validator supply chain | exact source/image/receipt binding과 fail-closed vulnerability policy | `Dockerfile.patch-validator`, image workflow, validator/SBOM/receipt modules | build, runtime, smoke, SBOM, vulnerability and receipt tests | protected-main operational receipt와 registry publication/signing/attestation | Implemented source; operational/publication evidence incomplete |
| Source licensing | Noema-owned source uses one explicit commercial-friendly outbound grant; package publication and dependencies retain independent terms | PR #530 `LICENSE`, root `README.md`, `docs/LICENSING_AND_IP_TRANSFER.md`; private `package.json` remains non-distribution metadata | exact-head repository/doc/test consistency | protected integration plus third-party/tooling policy resolution | Apache-2.0 candidate truth on #530; not yet protected truth |
| Source licensing | Noema-owned source uses one explicit commercial-friendly outbound grant; package publication and dependencies retain independent terms | protected `LICENSE`, root `README.md`, `docs/LICENSING_AND_IP_TRANSFER.md`; private `package.json` remains non-distribution metadata | protected repository/doc/test consistency at `main@6b2b3e90dc3d5bd24cd27ed11db41b9eb7106010` | third-party/tooling policy resolution and acquisition-transfer evidence remain separate | Apache-2.0 source grant implemented on protected main |
| Third-party/tooling licensing | GPL-family packages are not accepted as the normal inbound dependency baseline | current lockfile + dependency-license inventory + issue #531 | exact lockfile scan/inventory must become free of GPL/LGPL/AGPL toolchain entries | commercially compatible Wrangler/Miniflare/build-tool replacement or exact approved exception | Open compliance gap; source license does not resolve it |
| Release and deployment | source → package/SBOM/provenance → immutable publication → deployment/rollback | release, publication, deployment and readiness scripts | exact-source/reproducibility/receipt/rollback contract tests | immutable release, protected deployment, recovery and production smoke evidence | Incomplete; repository evidence cannot establish deployment |
| KPI, customer and acquisition | authentic evidence must retain source, time and buyer/legal authority | KPI, acquisition manifest/integrity/readiness and license validators | bounded input, provenance, ordering, integrity and fail-closed tests | authentic 30-day production KPI, customer/revenue and transfer evidence | Incomplete; no commercial-readiness claim |
Expand All @@ -35,14 +35,13 @@
| P0 | GPL-family development/build dependency path | 조직의 상업용 inbound 정책과 현재 npm toolchain이 충돌한다 | issue #531 | exact-head `package-lock.json`과 dependency inventory에서 GPL/LGPL/AGPL 경로가 사라지고 Worker dev/deploy·typecheck·tests·security가 그대로 통과 | Wrangler/Miniflare/Sharp 경로를 상업적으로 호환되는 도구 경계로 교체하고 lockfile을 재검증한다 |
| P0 | Maintainer/Reviewer App 및 hourly publication identity 활성화 | 자동 유지보수와 독립 리뷰가 production capability로 동작한다는 증거가 없다 | issues #29 / #227 | 현재 App 설치·권한·key custody/rotation, 성공한 scheduled publication artifact와 rollback 결과 | 외부 App 구성을 완료한 뒤 readiness와 scheduled run을 실행하고 artifact를 보존한다 |
| P0 | protected `main` governance 목표와 live policy 정합성 | source 검증만으로 실제 merge/release 통제를 보장할 수 없다 | issue #27 | live ruleset/branch-protection API와 관찰된 required workflow/status 결과 | governance audit을 live policy에 실행하고 차이를 owning control에서 수정한다 |
| P1 | Apache-2.0 source grant integration | 공개 저장소가 protected main에서는 아직 명시적 사용권을 제공하지 않는다 | PR #530 | unchanged exact-head README/LICENSE + applicable reviews/checks + protected merge | #530 exact head를 정상 protected path로 통합한다 |
| P1 | patch-validator 운영·배포 증거 | 검증된 source image가 실제 배포·서명·활성화됐는지 구매자가 확인할 수 없다 | issue #66 | protected-main operational receipt, registry digest, signature/attestation과 activation proof | exact protected source에서 publication pipeline을 실행한다 |
| P1 | authentic 30-day KPI | 신뢰성·성능·운영가치를 fixture가 아닌 실운영 자료로 입증하지 못한다 | issue #3 | production-origin, time-bound, integrity-checked 30-day KPI evidence | 승인된 production source에서 collector와 verifier를 실행한다 |
| P1 | release/deployment/acquisition evidence | buyer/legal/commercial 권한이 없어 매각 readiness를 선언할 수 없다 | issue #5 | immutable release/deployment/customer/revenue/legal transfer evidence | 앞선 evidence family를 순서대로 충족하고 acquisition audit을 재실행한다 |

## Documentation contradictions

과거 PR 번호와 당시 상태는 historical provenance일 뿐 현재 owner나 구현 상태가 아니다. Canonical TRD와 ADR은 protected implementation surface와 durable live issue owner를 사용하며, historical PR을 current owner로 사용하지 않는다. PR #530의 Apache-2.0 grant도 merge 전에는 protected truth로 표현하지 않는다.
과거 PR 번호와 당시 상태는 historical provenance일 뿐 현재 owner나 구현 상태가 아니다. Canonical TRD와 ADR은 protected implementation surface와 durable live issue owner를 사용하며, historical PR을 current owner로 사용하지 않는다. PR #530의 Apache-2.0 grant는 `main@6b2b3e90dc3d5bd24cd27ed11db41b9eb7106010`에 병합된 이후 protected source truth로만 표현한다.

## Completion discipline

Expand Down
13 changes: 12 additions & 1 deletion scripts/acquisition-readiness-audit.mjs
Original file line number Diff line number Diff line change
Expand Up @@ -123,7 +123,7 @@ function readJson(path) {
if (hasDuplicateJsonObjectKeys(text)) {
return { ok: false, reason: "duplicate_json_key", path };
}
return { ok: true, path, value: JSON.parse(text) };
return { ok: true, path, value: JSON.parse(text), bytes };
} catch (error) {
return { ok: false, reason: "invalid_json", path, error: error.message };
}
Expand Down Expand Up @@ -459,6 +459,17 @@ function validateLicensingIpEvidence(value) {
failures.push("package_metadata.license must match package.json license exactly");
}
}
if (packageDistributionApplies) {
const expectedPackageDigest = String(licensing.package_metadata?.sha256 ?? "");
if (!/^[0-9a-f]{64}$/i.test(expectedPackageDigest)) {
failures.push("licensing_ip.package_metadata.sha256 required when package distribution applies");
} else if (packageJson.ok) {
const actualPackageDigest = createHash("sha256").update(packageJson.bytes).digest("hex");
if (actualPackageDigest !== expectedPackageDigest.toLowerCase()) {
failures.push("package_metadata.sha256 does not match retained package.json bytes");
}
}
}

if (
decision
Expand Down
35 changes: 27 additions & 8 deletions scripts/actions-runner-assignment-audit.mjs
Original file line number Diff line number Diff line change
Expand Up @@ -279,24 +279,43 @@ function parseQueueGrace(value) {
* single-link regular-file authority, descriptor/path identity checks, complete
* staged writes, identity-bounded cleanup, and atomic replacement.
*
* @param {unknown} report Bounded report value.
* @param {unknown} auditReport Bounded runner-assignment audit report value.
* @param {object} io File-system operations used by the private-output boundary.
* @returns {string} Absolute report path.
*/
export function writeReportAtomically(report, io = defaultWriteIo) {
export function writeReportAtomically(auditReport, io = defaultWriteIo) {
const reportPath = resolve(REPORT_PATH);
const reportDirectory = dirname(reportPath);
assertAcquisitionPrivatePathParents(reportPath, io);
io.mkdirSync(reportDirectory, { recursive: true, mode: 0o700 });
assertAcquisitionPrivatePathParents(reportPath, io);
writeAcquisitionPrivateFile(
reportPath,
`${JSON.stringify(report, null, 2)}\n`,
`${JSON.stringify(auditReport, null, 2)}\n`,
io,
);
return reportPath;
}

function schemaVersionOneCheck(semanticCheck) {
const {
check_code: code,
check_passed: pass,
check_detail: detail,
...context
} = semanticCheck;
return { code, pass, detail, ...context };
}

function schemaVersionOneFailure(semanticFailure) {
const {
failure_code: code,
failure_detail: detail,
...context
} = semanticFailure;
return { code, detail, ...context };
}

/**
* Execute the runner-assignment audit from explicit operator inputs.
*
Expand Down Expand Up @@ -353,7 +372,7 @@ export async function runActionsRunnerAssignmentAudit(input) {
fetch_run: adapters.fetch_run,
fetch_job_pages: adapters.fetch_job_pages,
});
const decision = evaluateRunnerAssignmentEvidence(evidence);
const auditDecision = evaluateRunnerAssignmentEvidence(evidence);
const report = {
schema_version: 1,
objective: "github_actions_runner_assignment",
Expand All @@ -362,9 +381,9 @@ export async function runActionsRunnerAssignmentAudit(input) {
selected_run_ids: runIds,
observed_at: observedAt,
queue_grace_milliseconds: queueGrace,
status: decision.status,
checks: decision.checks,
failures: decision.failures,
status: auditDecision.audit_status,
checks: auditDecision.assignment_checks.map(schemaVersionOneCheck),
failures: auditDecision.assignment_failures.map(schemaVersionOneFailure),
authority: {
runner_assignment_only: true,
required_check_success: false,
Expand All @@ -377,7 +396,7 @@ export async function runActionsRunnerAssignmentAudit(input) {
await input.write_report(report);

return {
exit_code: decision.status === "PASS" ? 0 : 1,
exit_code: auditDecision.audit_status === "PASS" ? 0 : 1,
report,
Comment thread
devin-ai-integration[bot] marked this conversation as resolved.
};
}
Expand Down
Loading
Loading