fix(workflows): allocate collision-free registry-audit ADR 0021 - #222
fix(workflows): allocate collision-free registry-audit ADR 0021#222cursor[bot] wants to merge 54 commits into
Conversation
Move the read-only workflow-registry auditor into pg_llm_batch so install, coverage, docstring, and compile gates see the production module. Type-check ref and SHA identity members before equality so a hostile str subclass cannot certify the caller commit while resolving another tree. Add the pg-llm-batch-workflow-audit console script, operator/ADR/doctoring/CHANGELOG contract, and realistic fail-closed regressions. Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Lock the packaged detector to ADR 0021, reject a leftover 0016 slug, and fail CI when two ADR files share one numeric prefix after merge. Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Open recovery PRs already claim 0016-0020. Move the read-only registry audit decision to 0021, cite RFC 3339 for receipt timestamps, and drop the unreachable re-serialize branch that broke 100% coverage. Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
|
Bugbot is not enabled for your account, so this pull request was not reviewed. Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs. |
seonghobae
left a comment
There was a problem hiding this comment.
Reviewed exact head 84866b5cb5467a675f51140179840b11e238e8be against protected main@d2f1e32271910a6db98a0757d67194ddadca4566. The read-only workflow-registry auditor is bound to an independently supplied protected SHA/ref, validates protected ref stability before/after the audit, resolves the exact commit tree, rejects truncated trees, bounds registry cardinality and response bytes, validates exact decoder primitive types on authority/identity/registry surfaces, double-reads multi-page registries to detect drift, classifies GitHub dynamic/ identities separately, and never mutates Actions state. ADR 0021 avoids the active recovery ADR namespace and the duplicate-prefix regression makes future collisions fail CI. No current inline review threads exist and I found no source-level must-fix in the reviewed delta. This approval applies only to this unchanged head; queued/pending/cancelled or predecessor checks do not count, and every then-live required workflow/check plus current mergeability/ancestry must be freshly terminal-success before merge.
seonghobae
left a comment
There was a problem hiding this comment.
Current exact head a3ccb8ce65c136ead85edfbe6d91032dead3a6f5 is not mergeable against protected main@76e704415651bdef6ceb06efa8db279349bea22e. Fresh ancestry shows this branch is 54 commits ahead and 1 behind with merge base 5267146534a259f85c0985e153f3f6cb1281f58f; the missing protected commit is merged #212, and this PR also modifies overlapping public documentation surfaces (README.md, ARCHITECTURE.md, CHANGELOG.md). GitHub currently reports mergeable=false. The previous approval was for predecessor head 84866b5cb5467a675f51140179840b11e238e8be and does not satisfy last-push review for this head.
Do not force-push or destructively rebase. The existing branch owner should incorporate current protected main through an auditable non-destructive update, resolve any #212 documentation conflicts while preserving both bounded contracts, and update stale body/source references that still call #212 open. Then reacquire exact-head checks and fresh review. I am not re-approving this non-mergeable head, and this comment does not waive any workflow/thread/ruleset gate.
…228) * test(recovery): require isolated restore-target service names Add the RED contract for #204 isolated-target identity: a live pg_service name and a restore-drill name must be exact distinct libpq service identities. DSNs, tenant scope, subclasses, and same-name reuse must fail closed before pg_restore. Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com> * feat(recovery): isolate restore-target libpq service names Succeed the #204 isolated-target gap without racing #212. Operators must name a live pg_service and a distinct restore-drill service before pg_restore. DSNs, tenant scope, and same-name reuse fail closed. Allocate ADR 0021 so the record does not collide with #216/#219/#221. Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com> * fix(recovery): allocate collision-free restore-target ADR 0022 #222 already files ADR 0021 for the workflow-registry audit. Keep the isolation seam unchanged and retarget this decision, doctoring, and the documentation contract to 0022 after a fresh open-writer inventory. Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com> * fix(recovery): require cluster identity for restore-target isolation Distinct libpq service names are not cluster isolation. Require caller-owned pg_control_system() identifiers so two aliases for the same production cluster fail closed before pg_restore. Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com> --------- Co-authored-by: Cursor Agent <cursoragent@cursor.com> Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com> Co-authored-by: Seongho Bae <me@seonghobae.me>
Read-only workflow-registry auditor — existing Cursor lane
Current contributor head remains exact
a3ccb8ce65c136ead85edfbe6d91032dead3a6f5; protectedmainis exactb84f0c94154043a3473939c01bb6471de5a129ae. A fresh comparison remains diverged from protected ancestry: the recorded branch base is5267146534a259f85c0985e153f3f6cb1281f58f, and GitHub currently reportsmergeable=false. This PR remains Draft so Ready state does not overstate merge eligibility.Candidate capability
This branch packages a read-only workflow-registry auditor that accepts an independently supplied protected SHA/ref, checks protected-ref stability before/after audit, resolves the exact commit tree, rejects truncated trees, bounds registry cardinality/response bytes, validates exact primitive types on decoded authority/identity/registry surfaces, double-reads paginated registries to detect drift, classifies GitHub-managed
dynamic/identities separately, and does not mutate Actions state. It also allocates ADR 0021 and adds a duplicate-numeric-prefix regression.Those properties remain ACTIVE-PR truth only until integrated through the current protected tree and current governance. Historical verification lines in predecessor source/body are not current-head/current-base acceptance.
Stale lineage corrected
Merged #212 is protected-main behavior and no longer an open ADR claimant. Protected main already contains recovery ADRs including 0016 logical restore, 0017 recovery evidence binding, 0018 restore catalog acceptance, 0019 physical/PITR profile semantics, 0020 receipt verification, and 0022 restore target isolation. This branch's ADR 0021 remains numerically distinct, but its public-documentation surfaces (
README.md,ARCHITECTURE.md,CHANGELOG.md,AGENTS.md,CLAUDE.md) predate multiple later protected integrations and require a writer-safe non-destructive current-main reconciliation on this existing branch before they can be canonical.Do not force-push/destructively rebase, create a competing registry-audit branch, or overwrite the active canonical documentation lane #229. Preserve the unique auditor/test/ADR work while incorporating the then-live protected base and resolving public-documentation conflicts explicitly.
Review / governance boundary — refreshed 2026-08-26
Fresh formal review inventory is unchanged: the sole
APPROVEDreview applies only to predecessor head84866b5cb5467a675f51140179840b11e238e8be, not to current heada3ccb8ce.... The current-head review is COMMENTED and explicitly records non-mergeable stale ancestry; fresh inline review-thread inventory is empty. There is no qualifying approval of the exact current head.Fresh organization ruleset
18156473currently requires 1 approving review, dismisses stale approvals after push, does not require approval of the most recent reviewable push, requires review-thread resolution, and requires an extra approval for unattributed changes.require_code_owner_review=falseremains explicit. Merge/squash are allowed; deletion and non-fast-forward updates are protected. Required central workflows include close-empty PR, OpenCode review, PR review/merge scheduler, Security Scan, Strix, SAST Semgrep, and Noema review. Administrative bypass is not control-plane/acquisition evidence and must not be used to manufacture readiness. The previous 2-approval/latest-push snapshot is stale mutable control-plane prose.Before any branch mutation or integration, refetch the exact contributor head, protected-main tip/base/ancestry/mergeability, every overlapping source/documentation PR/no-PR writer and affected blob, live policy/protection, exact-head/current-base workflows/checks and material checkout identity, formal reviews/threads/reviewer authority, and releases. Mark Ready only after writer-safe current-main reconciliation removes the stale ancestry/documentation conflict; merge only an unchanged current-base Ready head with terminal-success live gates, zero valid product/security/privacy/reliability findings, and all then-live qualifying review conditions satisfied.
Queued, pending, cancelled, skipped-required, absent, neutral, stale, predecessor, status-only, synthetic, author-only, rate-limited, infrastructure-failed, dismissed, or conclusion-null evidence does not transfer.
Refs #158; supersedes the old #211 landing vehicle.