Skip to content

docs: reconcile protected runtime and commercial gap authority - #547

Merged
seonghobae merged 581 commits into
mainfrom
chatgpt/runtime-doc-authority-repair
Sep 8, 2026
Merged

docs: reconcile protected runtime and commercial gap authority#547
seonghobae merged 581 commits into
mainfrom
chatgpt/runtime-doc-authority-repair

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 3, 2026

Copy link
Copy Markdown
Contributor

Purpose

Sole cross-lane writer for docs/product-technical-gap-baseline.md and its executable documentation-authority contracts. Protected truth, active candidate, transient workflow evidence and foreign-owner authority remain separate. Feature lanes must not carry competing historical baseline blobs through semantic restack.

Fresh docs-to-code repair — 2026-09-08 KST

Protected Noema construction parent is GitHub-verified main@099d7d89a51bca4a2cf7c6b285b50ffadd08d001, the normal #540 integration. Re-reading #547 after non-force restack found coupled authority defects:

  1. the baseline still called old main@d6394b2... current and treated already merged fix(toolchain): replace Wrangler/Miniflare GPL-family path #540 as active;
  2. after correcting production prose, three regression tests still demanded superseded d6394b2... / active-fix(toolchain): replace Wrangler/Miniflare GPL-family path #540 semantics;
  3. documentation-live-open-pr-authority.test.ts then still described fix(toolchain): replace Wrangler/Miniflare GPL-family path #540 as part of the live open-PR set through a permissive substring assertion even though the baseline had moved it into protected history.

The durable rule is explicit: committed docs do not freeze a pre-merge protected parent or moving foreign-owner head as evergreen current authority. Exact live heads are re-read before mutation/merge/release; committed exact SHAs are construction/integration snapshots or immutable reviewed pins.

RED → causal repair lineage

Fresh compare from protected construction parent is ahead-only, behind_by=0, merge-base exactly 099d7d8...; effective diff remains the 13 documentation/contract paths owned by this lane.

Review finding disposition

The Scorecard inline npmCommand not pinned by hash finding on .github/workflows/ci.yml is resolved as non-actionable for this PR. The line is inherited unchanged from protected main and runs the exact Node 24.19.0 / npm 11.17.0 toolchain only to regenerate a lockfile in a disposable workspace for byte comparison; dependency installation remains npm ci. Rewriting the command to evade a heuristic would weaken evidence rather than improve dependency integrity. The thread records the upstream Scorecard false-positive precedent and is resolved; no Security gate was weakened.

Current exact-head evidence

Fresh unchanged-head workflow generation for 30b7e7e...:

  • application CI 34165467830: terminal success; exact checkout/live-base/lockfile/typecheck/tests/security/KPI/license/acquisition-integrity path all passed;
  • reviewer-ci 34165467802: terminal success;
  • required Security Scan 34165467813: terminal success;
  • patch-validator-image 34165467851: in progress at the exact-image build/verification lane on the latest read.

The remaining image run is non-passing until terminal success. All predecessor generations are historical after source movement.

Keep Draft. Normal merge requires unchanged exact 30b7e7e..., terminal-success patch-validator-image, live behind_by=0 against then-current protected main, stable ancestry, and a fresh clean review-thread read immediately before integration.

No force push, destructive rebase, self-approval, gate weakening, predecessor-GREEN transfer, or release fabrication.

@coderabbitai

coderabbitai Bot commented Sep 3, 2026

Copy link
Copy Markdown

Important

Review skipped

Too many files!

This PR contains 112 files, which is 12 over the limit of 100.

To get a review, reduce the PR to 100 files or fewer by splitting it into smaller PRs or changing its base branch.

Upgrade to a paid plan to raise the limit.

This review couldn't start because sufficient usage credits or metered capacity aren't available. Add credits or update usage-based reviews in the billing tab, then retry.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Team

Run ID: af711191-75ea-4bf4-b5c2-6a0522c14928

📥 Commits

Reviewing files that changed from the base of the PR and between d9b2a95 and 30b7e7e.

⛔ Files ignored due to path filters (1)
  • package-lock.json is excluded by !**/package-lock.json
📒 Files selected for processing (112)
  • .github/lockfile-change-policy.json
  • .github/workflows/central-review.yml
  • .github/workflows/ci.yml
  • .github/workflows/hourly-product-development.yml
  • .github/workflows/patch-validator-image.yml
  • .github/workflows/reviewer-ci.yml
  • .gitignore
  • CHANGELOG.md
  • docs/CONTEXT_MAP.md
  • docs/LICENSING_AND_IP_TRANSFER.md
  • docs/PRD.md
  • docs/adr/0012-runtime-orchestration-bounded-contexts.md
  • docs/adr/0013-durable-workflow-execution-authority.md
  • docs/adr/0014-shared-noema-core-package.md
  • docs/adr/README.md
  • docs/automation-threat-model.md
  • docs/doctoring/hourly-product-development-prerequisites.md
  • docs/noema-agent-sandbox-plan.md
  • docs/operations/hourly-product-development.md
  • docs/product-technical-gap-baseline.md
  • package.json
  • packages/noema-core/.gitignore
  • packages/noema-core/README.md
  • packages/noema-core/pyproject.toml
  • packages/noema-core/src/noema_core/__init__.py
  • packages/noema-core/src/noema_core/agent.py
  • packages/noema-core/tests/__init__.py
  • packages/noema-core/tests/test_agent.py
  • packages/noema-core/tests/test_owner_boundary.py
  • reviewer/MANIFEST.in
  • reviewer/README.md
  • reviewer/build_backend.py
  • reviewer/noema_reviewer/__init__.py
  • reviewer/noema_reviewer/agent.py
  • reviewer/noema_reviewer/config.py
  • reviewer/noema_reviewer/gating.py
  • reviewer/noema_reviewer/github_io.py
  • reviewer/noema_reviewer/models.py
  • reviewer/pyproject.toml
  • reviewer/requirements-ci.in
  • reviewer/tests/test_agent.py
  • reviewer/tests/test_build_backend_editable.py
  • reviewer/tests/test_build_backend_staging.py
  • reviewer/tests/test_check_run_pagination.py
  • reviewer/tests/test_deterministic_finding_identity.py
  • reviewer/tests/test_failed_check_causal_binding.py
  • reviewer/tests/test_failed_check_coverage_edges.py
  • reviewer/tests/test_finding_line_contract.py
  • reviewer/tests/test_gating.py
  • reviewer/tests/test_github_io.py
  • reviewer/tests/test_models.py
  • reviewer/tests/test_non_success_check_gate.py
  • reviewer/tests/test_shared_core_import_boundary.py
  • reviewer/tests/test_verdict_invariants.py
  • scripts/cloudflare-worker-deploy.mjs
  • scripts/cloudflare-worker-dev.mjs
  • scripts/hourly-commercial-readiness.mjs
  • scripts/lib/cloudflare-worker-config.mjs
  • scripts/lockfile-change-policy-candidate.mjs
  • src/runtime-entrypoint.ts
  • src/runtime-shared/execution-identity.ts
  • src/workflow-task-execution/workflow-recovery-claim.ts
  • src/workflow-task-execution/workflow-state-durable-object.ts
  • src/workflow-task-execution/workflow-state-store.ts
  • src/workflow-task-execution/workflow-task-runner.ts
  • test/ci-exact-head-contract.test.ts
  • test/cloudflare-toolchain-license-boundary.test.ts
  • test/cloudflare-worker-config.test.mjs
  • test/documentation-architecture-contract.test.ts
  • test/documentation-current-trust-authority.test.ts
  • test/documentation-durable-workflow-protected-authority.test.ts
  • test/documentation-live-open-pr-authority.test.ts
  • test/documentation-post-trust-integration-authority.test.ts
  • test/documentation-runtime-protected-authority.test.ts
  • test/documentation-workflow-concurrency-authority.test.ts
  • test/helpers/hourly-workflow.ts
  • test/hourly-commercial-readiness-script.test.ts
  • test/hourly-commercial-readiness-work-conserving-dispatch.test.ts
  • test/hourly-product-development-final-candidate-cleanup.test.ts
  • test/hourly-product-development-no-model-timeout.test.ts
  • test/hourly-product-development-runner-isolation.test.ts
  • test/hourly-product-development-workflow.test.ts
  • test/lockfile-reproducibility-workflow.test.ts
  • test/noema-core-packaging-contract.test.ts
  • test/patch-validator-image-build-cache.test.ts
  • test/patch-validator-image-contract.test.ts
  • test/product-technical-gap-current-candidate-contract.test.ts
  • test/reviewer-ci-action-runtime-integrity.test.ts
  • test/runtime-bounded-context-fitness.test.ts
  • test/upload-artifact-node24-integrity.test.ts
  • test/workflow-concurrency-policy.test.ts
  • test/workflow-recovery-claim.test.ts
  • test/workflow-state-durable-object-command-shape.test.ts
  • test/workflow-state-durable-object-payload-minimization.test.ts
  • test/workflow-state-durable-object-plan-authority.test.ts
  • test/workflow-state-durable-object-routing.test.ts
  • test/workflow-state-store-atomicity.test.ts
  • test/workflow-state-store-cancellation-policy.test.ts
  • test/workflow-state-store-failure-contracts.test.ts
  • test/workflow-state-store-integrity-regressions.test.ts
  • test/workflow-state-store-malformed-record-shape.test.ts
  • test/workflow-state-store-missing-state-coverage.test.ts
  • test/workflow-state-store-plan-authority.test.ts
  • test/workflow-state-store-provenance.test.ts
  • test/workflow-state-store-recovery.test.ts
  • test/workflow-state-store-retained-provenance-integrity.test.ts
  • test/workflow-state-store-transition-result-contract.test.ts
  • test/workflow-task-execution-coverage-contract.test.ts
  • test/workflow-task-runner-claim-authority.test.ts
  • test/workflow-task-runner-terminal-authority.test.ts
  • test/workflow-task-runner.test.ts
  • wrangler.toml

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Comment thread .github/workflows/ci.yml
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@seonghobae
seonghobae merged commit 699489c into main Sep 8, 2026
18 of 19 checks passed
@seonghobae
seonghobae deleted the chatgpt/runtime-doc-authority-repair branch September 8, 2026 00:12
seonghobae added a commit that referenced this pull request Sep 9, 2026
* test(docs): expose post-547 commercial authority drift

* test(docs): require current active commercial lanes

* docs: refresh commercial gap authority after #547

* test: advance patch-validator candidate authority

* test: reject superseded patch-validator candidate

* docs: refresh patch-validator exact authority

* test: require current #535 commercial authority

* docs: repair current commercial authority after hosted RED

* test(docs): require live post-558 commercial authority

Require the documentation lane to reflect protected #558 integration, the newly converged #535 exact head, and the newly observed #556 stacked head before production baseline text is repaired.

* docs(gap): repair post-558 live commercial authority

Bring #559's owned baseline in line with protected #558 integration, exact #535 convergence, and the newly observed #556 stack while preserving canonical owner boundaries and release-evidence discipline.

* test(docs): require latest observed #556 authority

Advance the documentation contract to the live #556 successor after its hosted release-test RED, while rejecting the superseded observation. Production baseline text follows in the causal repair commit.

* docs(gap): record live #556 successor and hosted RED

Update #559's sole documentation authority to the latest #556 exact head, preserve the observed hosted release-test failure as historical evidence, and keep the downstream stack non-authorizing until #535 reaches protected main.

* test(docs): require current #535 endpoint-repair authority

* docs: track current #535 gateway endpoint repair

* test(docs): require #535 coverage-repair authority

* docs: track #535 coverage-gate repair

* test(docs): require current central control-plane snapshot

* docs: refresh central control-plane snapshot

* test(docs): retire stale commercial authority assertions

* docs: refresh protected and claim-evidence authority

* test(docs): track protected #535 integration

* test(docs): track current claim-evidence head

* test(docs): bind post-535 protected authority

* test(docs): refresh current candidate contract

* test(docs): align claim-binding authority wording

* docs: refresh claim-evidence candidate authority

* test(docs): match hosted run authority casing

* docs: refresh live Noema commercial authority

* test(docs): track current Noema feature authority

* test(docs): bind commercial gap to live feature heads

* test(docs): require settled external-extension authority

* docs: converge commercial gap to current plugin admission

* test(docs): track active policy-approval RED

* docs: bind commercial gap to policy-approval RED

* docs: restore durable commercial gap owners

* docs: align external-extension authority after restack

* test: bind documentation authority to restacked #560

* test(d(docs): require complete gap authority schema

* docs: bind gap status to architecture authorities

* test(docs): reject stale tool-capability candidate

* docs: refresh current tool-capability evidence

* docs: refresh active extension authority

* docs: bind extension event chronology evidence

* docs: refresh extension chronology authority

* docs: bind gap baseline to hostile admission repair

* test(docs): bind live candidate to admission repair

* test(docs): preserve candidate ADR authority wording

* docs: refresh external-extension runtime-time authority

* test(docs): bind current runtime-time candidate authority

* test(docs): refresh live external-extension candidate authority

* docs: bind gap authority to invocation replay repair

* docs: converge on public replay authority repair

* docs: converge on activation revocation repair

* docs: converge on admission-bound invocation authority

* docs: bind commercial gap to exact admission provenance

* test(docs): require exact-admission candidate authority

* test(docs): bind candidate contract to exact admission

* docs: track crypto-provider RED authority

* test(docs): bind external-extension authority to Web Crypto repair

* docs: converge external-extension Web Crypto authority

* test(docs): follow current external-extension authority

* test(docs): assert public receipt binding authority

* test(docs): match activation revocation authority wording

* docs: converge baseline after #560 protected integration

* test: bind documentation authority to #560 integration

* test: treat external-extension admission as protected history

* test: extend protected integration history through #560

* test: move external-extension gap to lifecycle successor
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation priority: medium Normal-priority or P2 work status: draft Draft pull request type: docs Documentation, ADR, PRD, or technical writing

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants