docs: reconcile protected runtime and commercial gap authority - #547
Conversation
|
Important Review skippedToo many files! This PR contains 112 files, which is 12 over the limit of 100. To get a review, reduce the PR to 100 files or fewer by splitting it into smaller PRs or changing its base branch. Upgrade to a paid plan to raise the limit. This review couldn't start because sufficient usage credits or metered capacity aren't available. Add credits or update usage-based reviews in the billing tab, then retry. ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Team Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (112)
You can disable this status message by setting the Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
fix(toolchain): replace Wrangler/Miniflare GPL-family path
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
* test(docs): expose post-547 commercial authority drift * test(docs): require current active commercial lanes * docs: refresh commercial gap authority after #547 * test: advance patch-validator candidate authority * test: reject superseded patch-validator candidate * docs: refresh patch-validator exact authority * test: require current #535 commercial authority * docs: repair current commercial authority after hosted RED * test(docs): require live post-558 commercial authority Require the documentation lane to reflect protected #558 integration, the newly converged #535 exact head, and the newly observed #556 stacked head before production baseline text is repaired. * docs(gap): repair post-558 live commercial authority Bring #559's owned baseline in line with protected #558 integration, exact #535 convergence, and the newly observed #556 stack while preserving canonical owner boundaries and release-evidence discipline. * test(docs): require latest observed #556 authority Advance the documentation contract to the live #556 successor after its hosted release-test RED, while rejecting the superseded observation. Production baseline text follows in the causal repair commit. * docs(gap): record live #556 successor and hosted RED Update #559's sole documentation authority to the latest #556 exact head, preserve the observed hosted release-test failure as historical evidence, and keep the downstream stack non-authorizing until #535 reaches protected main. * test(docs): require current #535 endpoint-repair authority * docs: track current #535 gateway endpoint repair * test(docs): require #535 coverage-repair authority * docs: track #535 coverage-gate repair * test(docs): require current central control-plane snapshot * docs: refresh central control-plane snapshot * test(docs): retire stale commercial authority assertions * docs: refresh protected and claim-evidence authority * test(docs): track protected #535 integration * test(docs): track current claim-evidence head * test(docs): bind post-535 protected authority * test(docs): refresh current candidate contract * test(docs): align claim-binding authority wording * docs: refresh claim-evidence candidate authority * test(docs): match hosted run authority casing * docs: refresh live Noema commercial authority * test(docs): track current Noema feature authority * test(docs): bind commercial gap to live feature heads * test(docs): require settled external-extension authority * docs: converge commercial gap to current plugin admission * test(docs): track active policy-approval RED * docs: bind commercial gap to policy-approval RED * docs: restore durable commercial gap owners * docs: align external-extension authority after restack * test: bind documentation authority to restacked #560 * test(d(docs): require complete gap authority schema * docs: bind gap status to architecture authorities * test(docs): reject stale tool-capability candidate * docs: refresh current tool-capability evidence * docs: refresh active extension authority * docs: bind extension event chronology evidence * docs: refresh extension chronology authority * docs: bind gap baseline to hostile admission repair * test(docs): bind live candidate to admission repair * test(docs): preserve candidate ADR authority wording * docs: refresh external-extension runtime-time authority * test(docs): bind current runtime-time candidate authority * test(docs): refresh live external-extension candidate authority * docs: bind gap authority to invocation replay repair * docs: converge on public replay authority repair * docs: converge on activation revocation repair * docs: converge on admission-bound invocation authority * docs: bind commercial gap to exact admission provenance * test(docs): require exact-admission candidate authority * test(docs): bind candidate contract to exact admission * docs: track crypto-provider RED authority * test(docs): bind external-extension authority to Web Crypto repair * docs: converge external-extension Web Crypto authority * test(docs): follow current external-extension authority * test(docs): assert public receipt binding authority * test(docs): match activation revocation authority wording * docs: converge baseline after #560 protected integration * test: bind documentation authority to #560 integration * test: treat external-extension admission as protected history * test: extend protected integration history through #560 * test: move external-extension gap to lifecycle successor
Purpose
Sole cross-lane writer for
docs/product-technical-gap-baseline.mdand its executable documentation-authority contracts. Protected truth, active candidate, transient workflow evidence and foreign-owner authority remain separate. Feature lanes must not carry competing historical baseline blobs through semantic restack.Fresh docs-to-code repair — 2026-09-08 KST
Protected Noema construction parent is GitHub-verified
main@099d7d89a51bca4a2cf7c6b285b50ffadd08d001, the normal #540 integration. Re-reading #547 after non-force restack found coupled authority defects:main@d6394b2...current and treated already merged fix(toolchain): replace Wrangler/Miniflare GPL-family path #540 as active;d6394b2.../ active-fix(toolchain): replace Wrangler/Miniflare GPL-family path #540 semantics;documentation-live-open-pr-authority.test.tsthen still described fix(toolchain): replace Wrangler/Miniflare GPL-family path #540 as part of the live open-PR set through a permissive substring assertion even though the baseline had moved it into protected history.The durable rule is explicit: committed docs do not freeze a pre-merge protected parent or moving foreign-owner head as evergreen
currentauthority. Exact live heads are re-read before mutation/merge/release; committed exact SHAs are construction/integration snapshots or immutable reviewed pins.RED → causal repair lineage
fb1cdc77f97dc8930f4fd6dd2d09398184066c4c: predecessor CI/reviewer/Security success, but stale baseline; non-authorizing.21dfa9410d792f9ec1a703276087bf15e26afc95: made the unchanged stale baseline deterministic source RED by requiring fix(toolchain): replace Wrangler/Miniflare GPL-family path #540-protected construction truth and rejecting old current-main/fix(toolchain): replace Wrangler/Miniflare GPL-family path #540/image wording. Hosted CI existed but stayed queued before the next causal mutation, so no hosted RED is fabricated.cc940c05a359614d1a3d2a28d02b2aa9a04da024: rewrote the commercial baseline to construction-snapshot/live-read authority, protected fix(toolchain): replace Wrangler/Miniflare GPL-family path #540 source history, license: remove GPL-family build tooling path #531 release-rights remainder, protected feat(workflow): add atomic durable task claim and checkpoint CAS #542 vs deployed-runtime separation, and active fix: pin NOEMA_LLM_MODEL routing alias to orchestrator/free #535/feat(reviewer): bind evidence receipts to exact claims #556 stack. Hosted CI34165002943then produced the real contract RED: 3 failing documentation-authority tests / 4117 passing tests after exact checkout, lockfile controls, install and typecheck all succeeded.6525bf7e43dccbe4d77bbb1057acc299f560ac44: aligneddocumentation-current-trust-authority,documentation-post-trust-integration-authority, anddocumentation-workflow-concurrency-authoritywith that repaired production model.30b7e7e5cdab8de65715834a16f994b2047eafa6: tightensdocumentation-live-open-pr-authorityso fix: pin NOEMA_LLM_MODEL routing alias to orchestrator/free #535/feat(reviewer): bind evidence receipts to exact claims #556 are the active lanes while fix(toolchain): replace Wrangler/Miniflare GPL-family path #540 must be explicitlymerged PR #540; it also forbids the obsoletePR #540은 아직 merge authority가 아니다claim. No production behavior changes aftercc940c0....Fresh compare from protected construction parent is ahead-only,
behind_by=0, merge-base exactly099d7d8...; effective diff remains the 13 documentation/contract paths owned by this lane.Review finding disposition
The Scorecard inline
npmCommand not pinned by hashfinding on.github/workflows/ci.ymlis resolved as non-actionable for this PR. The line is inherited unchanged from protected main and runs the exact Node 24.19.0 / npm 11.17.0 toolchain only to regenerate a lockfile in a disposable workspace for byte comparison; dependency installation remainsnpm ci. Rewriting the command to evade a heuristic would weaken evidence rather than improve dependency integrity. The thread records the upstream Scorecard false-positive precedent and is resolved; no Security gate was weakened.Current exact-head evidence
Fresh unchanged-head workflow generation for
30b7e7e...:34165467830: terminal success; exact checkout/live-base/lockfile/typecheck/tests/security/KPI/license/acquisition-integrity path all passed;34165467802: terminal success;34165467813: terminal success;34165467851: in progress at the exact-image build/verification lane on the latest read.The remaining image run is non-passing until terminal success. All predecessor generations are historical after source movement.
Keep Draft. Normal merge requires unchanged exact
30b7e7e..., terminal-success patch-validator-image, livebehind_by=0against then-current protected main, stable ancestry, and a fresh clean review-thread read immediately before integration.No force push, destructive rebase, self-approval, gate weakening, predecessor-GREEN transfer, or release fabrication.