Skip to content

fix(workflows): allocate collision-free registry-audit ADR 0021 - #222

Draft
cursor[bot] wants to merge 54 commits into
mainfrom
cursor/bc-df73ecc5-7f76-47cd-9c06-483e539fc6fd-f514
Draft

fix(workflows): allocate collision-free registry-audit ADR 0021#222
cursor[bot] wants to merge 54 commits into
mainfrom
cursor/bc-df73ecc5-7f76-47cd-9c06-483e539fc6fd-f514

Conversation

@cursor

@cursor cursor Bot commented Aug 16, 2026

Copy link
Copy Markdown
Contributor

Read-only workflow-registry auditor — existing Cursor lane

Current contributor head remains exact a3ccb8ce65c136ead85edfbe6d91032dead3a6f5; protected main is exact b84f0c94154043a3473939c01bb6471de5a129ae. A fresh comparison remains diverged from protected ancestry: the recorded branch base is 5267146534a259f85c0985e153f3f6cb1281f58f, and GitHub currently reports mergeable=false. This PR remains Draft so Ready state does not overstate merge eligibility.

Candidate capability

This branch packages a read-only workflow-registry auditor that accepts an independently supplied protected SHA/ref, checks protected-ref stability before/after audit, resolves the exact commit tree, rejects truncated trees, bounds registry cardinality/response bytes, validates exact primitive types on decoded authority/identity/registry surfaces, double-reads paginated registries to detect drift, classifies GitHub-managed dynamic/ identities separately, and does not mutate Actions state. It also allocates ADR 0021 and adds a duplicate-numeric-prefix regression.

Those properties remain ACTIVE-PR truth only until integrated through the current protected tree and current governance. Historical verification lines in predecessor source/body are not current-head/current-base acceptance.

Stale lineage corrected

Merged #212 is protected-main behavior and no longer an open ADR claimant. Protected main already contains recovery ADRs including 0016 logical restore, 0017 recovery evidence binding, 0018 restore catalog acceptance, 0019 physical/PITR profile semantics, 0020 receipt verification, and 0022 restore target isolation. This branch's ADR 0021 remains numerically distinct, but its public-documentation surfaces (README.md, ARCHITECTURE.md, CHANGELOG.md, AGENTS.md, CLAUDE.md) predate multiple later protected integrations and require a writer-safe non-destructive current-main reconciliation on this existing branch before they can be canonical.

Do not force-push/destructively rebase, create a competing registry-audit branch, or overwrite the active canonical documentation lane #229. Preserve the unique auditor/test/ADR work while incorporating the then-live protected base and resolving public-documentation conflicts explicitly.

Review / governance boundary — refreshed 2026-08-26

Fresh formal review inventory is unchanged: the sole APPROVED review applies only to predecessor head 84866b5cb5467a675f51140179840b11e238e8be, not to current head a3ccb8ce.... The current-head review is COMMENTED and explicitly records non-mergeable stale ancestry; fresh inline review-thread inventory is empty. There is no qualifying approval of the exact current head.

Fresh organization ruleset 18156473 currently requires 1 approving review, dismisses stale approvals after push, does not require approval of the most recent reviewable push, requires review-thread resolution, and requires an extra approval for unattributed changes. require_code_owner_review=false remains explicit. Merge/squash are allowed; deletion and non-fast-forward updates are protected. Required central workflows include close-empty PR, OpenCode review, PR review/merge scheduler, Security Scan, Strix, SAST Semgrep, and Noema review. Administrative bypass is not control-plane/acquisition evidence and must not be used to manufacture readiness. The previous 2-approval/latest-push snapshot is stale mutable control-plane prose.

Before any branch mutation or integration, refetch the exact contributor head, protected-main tip/base/ancestry/mergeability, every overlapping source/documentation PR/no-PR writer and affected blob, live policy/protection, exact-head/current-base workflows/checks and material checkout identity, formal reviews/threads/reviewer authority, and releases. Mark Ready only after writer-safe current-main reconciliation removes the stale ancestry/documentation conflict; merge only an unchanged current-base Ready head with terminal-success live gates, zero valid product/security/privacy/reliability findings, and all then-live qualifying review conditions satisfied.

Queued, pending, cancelled, skipped-required, absent, neutral, stale, predecessor, status-only, synthetic, author-only, rate-limited, infrastructure-failed, dismissed, or conclusion-null evidence does not transfer.

Refs #158; supersedes the old #211 landing vehicle.

seonghobae and others added 11 commits August 16, 2026 19:31
Move the read-only workflow-registry auditor into pg_llm_batch so
install, coverage, docstring, and compile gates see the production
module. Type-check ref and SHA identity members before equality so a
hostile str subclass cannot certify the caller commit while resolving
another tree. Add the pg-llm-batch-workflow-audit console script,
operator/ADR/doctoring/CHANGELOG contract, and realistic fail-closed
regressions.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Lock the packaged detector to ADR 0021, reject a leftover 0016 slug, and
fail CI when two ADR files share one numeric prefix after merge.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Open recovery PRs already claim 0016-0020. Move the read-only registry
audit decision to 0021, cite RFC 3339 for receipt timestamps, and drop
the unreachable re-serialize branch that broke 100% coverage.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
@cursor

cursor Bot commented Aug 16, 2026

Copy link
Copy Markdown
Contributor Author

Bugbot is not enabled for your account, so this pull request was not reviewed.

Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed exact head 84866b5cb5467a675f51140179840b11e238e8be against protected main@d2f1e32271910a6db98a0757d67194ddadca4566. The read-only workflow-registry auditor is bound to an independently supplied protected SHA/ref, validates protected ref stability before/after the audit, resolves the exact commit tree, rejects truncated trees, bounds registry cardinality and response bytes, validates exact decoder primitive types on authority/identity/registry surfaces, double-reads multi-page registries to detect drift, classifies GitHub dynamic/ identities separately, and never mutates Actions state. ADR 0021 avoids the active recovery ADR namespace and the duplicate-prefix regression makes future collisions fail CI. No current inline review threads exist and I found no source-level must-fix in the reviewed delta. This approval applies only to this unchanged head; queued/pending/cancelled or predecessor checks do not count, and every then-live required workflow/check plus current mergeability/ancestry must be freshly terminal-success before merge.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Current exact head a3ccb8ce65c136ead85edfbe6d91032dead3a6f5 is not mergeable against protected main@76e704415651bdef6ceb06efa8db279349bea22e. Fresh ancestry shows this branch is 54 commits ahead and 1 behind with merge base 5267146534a259f85c0985e153f3f6cb1281f58f; the missing protected commit is merged #212, and this PR also modifies overlapping public documentation surfaces (README.md, ARCHITECTURE.md, CHANGELOG.md). GitHub currently reports mergeable=false. The previous approval was for predecessor head 84866b5cb5467a675f51140179840b11e238e8be and does not satisfy last-push review for this head.

Do not force-push or destructively rebase. The existing branch owner should incorporate current protected main through an auditable non-destructive update, resolve any #212 documentation conflicts while preserving both bounded contracts, and update stale body/source references that still call #212 open. Then reacquire exact-head checks and fresh review. I am not re-approving this non-mergeable head, and this comment does not waive any workflow/thread/ruleset gate.

seonghobae added a commit that referenced this pull request Aug 16, 2026
…228)

* test(recovery): require isolated restore-target service names

Add the RED contract for #204 isolated-target identity: a live
pg_service name and a restore-drill name must be exact distinct
libpq service identities. DSNs, tenant scope, subclasses, and
same-name reuse must fail closed before pg_restore.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>

* feat(recovery): isolate restore-target libpq service names

Succeed the #204 isolated-target gap without racing #212. Operators
must name a live pg_service and a distinct restore-drill service
before pg_restore. DSNs, tenant scope, and same-name reuse fail
closed. Allocate ADR 0021 so the record does not collide with
#216/#219/#221.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>

* fix(recovery): allocate collision-free restore-target ADR 0022

#222 already files ADR 0021 for the workflow-registry audit. Keep the
isolation seam unchanged and retarget this decision, doctoring, and the
documentation contract to 0022 after a fresh open-writer inventory.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>

* fix(recovery): require cluster identity for restore-target isolation

Distinct libpq service names are not cluster isolation. Require
caller-owned pg_control_system() identifiers so two aliases for the
same production cluster fail closed before pg_restore.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Co-authored-by: Seongho Bae <me@seonghobae.me>
@seonghobae
seonghobae marked this pull request as draft August 18, 2026 20:14
@opencode-agent opencode-agent Bot added area: ci-cd CI, GitHub Actions, checks, release, or supply chain priority: medium Normal-priority or P2 work status: draft Draft pull request type: docs Documentation, ADR, PRD, or technical writing labels Aug 22, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: ci-cd CI, GitHub Actions, checks, release, or supply chain priority: medium Normal-priority or P2 work status: draft Draft pull request type: docs Documentation, ADR, PRD, or technical writing

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants