test(recovery): cover stale evidence registry cleanup - #233
Conversation
|
Bugbot is not enabled for your account, so this pull request was not reviewed. Enable Bugbot in the Cursor dashboard to get automatic reviews on future PRs. |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (1)
Included review availability: Your plan includes up to 1 review per rolling hour; 0 remain after this review. 📝 WalkthroughWalkthrough백업 및 스키마 복구 증거 레지스트리에 stale weak-reference callback 회귀 테스트를 추가했다. 각 테스트는 replacement entry 보존을 검증하고 테스트 후 레지스트리를 정리한다. ChangesPostgreSQL 복구 증거 레지스트리
Estimated code review effort: 2 (Simple) | ~10 minutes Merge Risk: ⚪ Minimal · up to This is a localized test-only change that adds regression coverage without changing production behavior; no actionable merge-blocking risk remains after normal checks and review. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Pull request overview
OpenCode cannot approve yet because required coverage evidence did not pass.
Review outcome
1. HIGH .github/workflows/opencode-review.yml:1 - Coverage evidence did not prove required test/docstring evidence
-
Problem: The required coverage-evidence job result was
failure, so OpenCode cannot establish approval sufficiency for this head. -
Root cause: Automated approval is only valid when the same-head coverage-evidence job proves supported repository test suites passed and configured docstring gates passed or were advisory, or reports not applicable because no supported source files or package manifests exist. Missing, failed, skipped, unavailable, or unsupported-tooling test evidence is a blocker.
-
Fix: Install or configure the repository test/docstring evidence tooling when source files or package manifests exist, rerun the current-head coverage-evidence job, and approve only after it reports
successwith required evidence or explicit no-source not-applicable evidence. -
Regression test: Keep the approval branch checking
needs.coverage-evidence.result == successbefore posting APPROVE, and publish REQUEST_CHANGES when coverage-evidence blocker states such as cancelled, skipped, failed, unsupported-tooling, or below-100 evidence are present. -
Result: REQUEST_CHANGES
-
Reason: coverage-evidence result was
failure, so required test/docstring evidence was not proven for current head1ddfc3260cc8e7e981c5c3bdd4ba2206348f4143. -
Head SHA:
1ddfc3260cc8e7e981c5c3bdd4ba2206348f4143 -
Workflow run: 32003415023
-
Workflow attempt: 1
Coverage evidence
Coverage evidence job did not run or did not publish coverage evidence.
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Test: test_postgres_recovery_evidence_registry.py"]
S1 --> I1["regression suite"]
I1 --> R1["Review risk: Test: test_postgres_recovery_evidence_registry.py"]
R1 --> V1["targeted test run"]
OpenCode Review Overview
Pull request overviewOpenCode cannot approve yet because required coverage evidence did not pass. Review outcome1. HIGH .github/workflows/opencode-review.yml:1 - Coverage evidence did not prove required test/docstring evidence
Coverage evidenceCoverage evidence job did not run or did not publish coverage evidence. Changed-File Evidence Mapflowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Test: test_postgres_recovery_evidence_registry.py"]
S1 --> I1["regression suite"]
I1 --> R1["Review risk: Test: test_postgres_recovery_evidence_registry.py"]
R1 --> V1["targeted test run"]
|
|
@opencode-agent Please re-review the unchanged exact head |
Create a tree-identical branch commit after the authenticated OpenCode review failed before PR test execution while downloading the trusted central uv archive. This does not alter source/docs or count as passing evidence; all required workflows and the independent review must revalidate this new exact head.
|
@opencode-agent Please re-evaluate the current exact head |
There was a problem hiding this comment.
Pull request overview
OpenCode cannot approve yet because required coverage evidence did not pass.
Review outcome
1. HIGH .github/workflows/opencode-review.yml:1 - Coverage evidence did not prove required test/docstring evidence
-
Problem: The required coverage-evidence job result was
failure, so OpenCode cannot establish approval sufficiency for this head. -
Root cause: Automated approval is only valid when the same-head coverage-evidence job proves supported repository test suites passed and configured docstring gates passed or were advisory, or reports not applicable because no supported source files or package manifests exist. Missing, failed, skipped, unavailable, or unsupported-tooling test evidence is a blocker.
-
Fix: Install or configure the repository test/docstring evidence tooling when source files or package manifests exist, rerun the current-head coverage-evidence job, and approve only after it reports
successwith required evidence or explicit no-source not-applicable evidence. -
Regression test: Keep the approval branch checking
needs.coverage-evidence.result == successbefore posting APPROVE, and publish REQUEST_CHANGES when coverage-evidence blocker states such as cancelled, skipped, failed, unsupported-tooling, or below-100 evidence are present. -
Result: REQUEST_CHANGES
-
Reason: coverage-evidence result was
failure, so required test/docstring evidence was not proven for current head5951b7a4d779903b8924abaef2a387cae50b7f54. -
Head SHA:
5951b7a4d779903b8924abaef2a387cae50b7f54 -
Workflow run: 32069198553
-
Workflow attempt: 1
Coverage evidence
Coverage evidence job did not run or did not publish coverage evidence.
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Test: test_postgres_recovery_evidence_registry.py"]
S1 --> I1["regression suite"]
I1 --> R1["Review risk: Test: test_postgres_recovery_evidence_registry.py"]
R1 --> V1["targeted test run"]
|
@cwl-noema-review |
|
@opencode-agent review Please re-evaluate exact current head |
|
@cwl-noema-review Please perform a fresh independent review of exact current head |
|
@opencode-agent review Please re-evaluate the unchanged exact current head |
|
@opencode-agent review Please re-evaluate the unchanged exact current head |
|
@opencode-agent Please re-review the unchanged exact contributor head |
|
@opencode-agent Please re-review the unchanged exact contributor head This is one bounded retry after material protected control-plane change. Run fresh same-head coverage/test/docstring evidence and publish a new semantic verdict only for |
|
@opencode-agent Please perform a fresh review-only pass on the unchanged exact contributor head |
|
@opencode-agent review Please re-evaluate the unchanged exact contributor head |
|
@opencode-agent Please re-review the unchanged exact contributor head Since the prior bounded same-head request on 2026-08-23, protected This is one bounded activation after a material protected-central change. Generate fresh same-head coverage/test/docstring evidence and a new semantic verdict only for |
|
@opencode-agent review Please re-evaluate the unchanged exact contributor head Since the prior same-head activation, protected central #1333 materially changed this review path: it removed nonexistent This is one bounded review-only activation after that material protected control-plane change. Generate fresh same-head coverage/test/docstring evidence and publish a new semantic verdict only from current trusted evidence. Do not update or rebase the pg branch, transfer predecessor or infrastructure-failed evidence, treat existing synthetic Security/SAST merge-preview execution as exact-head proof, self-approve, weaken gates, or enable auto-merge. |
|
@opencode-agent review Please re-evaluate the unchanged exact contributor head Since the prior same-head activation against central This is one bounded review-only activation after that material protected control-plane change. Generate fresh same-head coverage/test/docstring evidence and publish a new semantic verdict only from current trusted evidence. Do not update/rebase the pg branch, transfer predecessor or infrastructure-failed evidence, treat existing synthetic Security/SAST merge-preview execution as exact-head proof, self-approve, weaken gates, or enable auto-merge. |
|
@opencode-agent review Please perform one bounded review-only re-evaluation of the unchanged exact contributor head Since the last same-head activation, protected central #1360 materially changed this exact review execution path: central Keep the pg head unchanged. Do not update/rebase the branch, transfer predecessor/infrastructure-failed evidence, reinterpret the existing synthetic Security/SAST merge-preview execution as exact-head proof, self-approve, weaken gates, or enable auto-merge. |
|
@opencode-agent review Please re-evaluate the unchanged exact contributor head Since the prior bounded activation on 2026-08-25, protected central has materially advanced; the current tip includes the protected #1379 request-size enforcement probe in the shared review/control-plane lineage. The pg contributor head and protected pg base are unchanged, and the active same-head OpenCode This is one bounded review-only activation after material protected-control-plane change. Generate fresh same-head coverage/test/docstring evidence and publish a new semantic verdict only from current trusted evidence. Do not mutate or rebase the pg branch, transfer predecessor/infrastructure-failed/synthetic evidence, treat historical Security/SAST merge-preview scans as exact-head proof, self-approve, weaken gates, or enable auto-merge. The independent exact-source Security prerequisite tracked by read-only central |
|
@opencode-agent review Please perform one bounded review-only re-evaluation of the unchanged exact contributor head Since the previous same-head activation, protected central #1400 merged as Run fresh same-head coverage/test/docstring evidence and publish a new semantic verdict only for this unchanged exact head. Do not update or rebase the pg branch, transfer predecessor or infrastructure-failed evidence, self-approve, weaken gates, or enable auto-merge. Keep Security/SAST/Dependency Review evidence independently exact-source and current. |
|
@opencode-agent review Please perform one bounded review-only re-evaluation of unchanged exact contributor head This is not a duplicate no-op activation: since the last same-head request (2026-08-29T13:34:11Z, then-central Generate a genuinely fresh authenticated semantic formal verdict for this exact unchanged head under the current trusted review runtime. Do not update/rebase the pg branch, transfer predecessor or stale infrastructure evidence, reinterpret the old change request as approval, self-approve, weaken gates, or enable auto-merge. |
|
@opencode-agent review Please perform one bounded review-only re-evaluation of unchanged exact contributor head This activation follows a material protected-control-plane change after the prior request: the previous same-head activation was posted at 2026-08-30T12:15:20Z against then-central The pg head/base are unchanged, current inline review threads remain empty, and the active same-head formal verdict is still the legacy coverage-evidence-bound |
|
@opencode-agent review Please perform one bounded review-only re-evaluation of unchanged exact contributor head This is materially distinct from the previous same-head activation: after that request, protected Generate genuinely fresh authenticated same-head coverage/test/docstring evidence and a new semantic formal verdict under the now-protected central review runtime. Do not update/rebase this pg branch, transfer predecessor/stale/infrastructure/synthetic evidence, reinterpret the old change request as approval, self-approve, weaken gates, or enable auto-merge. |
|
@opencode-agent review Please perform one bounded review-only re-evaluation of unchanged exact contributor head This is materially distinct from the previous same-head activation at central Generate genuinely fresh authenticated same-head coverage/test/docstring evidence and a new semantic formal verdict only for this unchanged head. Do not update/rebase the pg branch, transfer predecessor/stale/infrastructure/synthetic evidence, reinterpret the old change request as approval, self-approve, weaken gates, or enable auto-merge. |
Summary
postgres_backup_evidence.py:65->exitandpostgres_schema_evidence.py:49->exitwithout changing production behavior.Exact protected base and current head
Protected
mainis exactb84f0c94154043a3473939c01bb6471de5a129ae.Current PR head is exact
5951b7a4d779903b8924abaef2a387cae50b7f54, exactly two commits ahead / zero behind, and changes onlytests/test_postgres_recovery_evidence_registry.py. Production source and canonical documentation are unchanged.Root cause and regression contract
Protected main inherited two unexercised weakref-callback guard branches from merged recovery-evidence work. The regression tests model a registry slot being replaced while the original weak reference is still live, collect the original object, and prove its stale callback cannot delete the replacement. Production behavior is unchanged.
Exact-head validation — evidence authority
Do not infer source identity from workflow-run
head_shametadata or a green conclusion alone. Immutable exact-source job/log evidence previously captured for this unchanged head established contributor-head execution for the required validation runs below. In the 2026-08-31 fresh inventory, CI run32066570209is still bound to exacthead_sha=5951b7a4d779903b8924abaef2a387cae50b7f54, and its quality, Python 3.14, unit-test, and container jobs still report successfulCheckoutandVerify exact source headsteps. The current connector does not expose raw job-log downloads, so historical log text is not relabeled as freshly inspected evidence.Previously captured immutable exact-source evidence on unchanged
5951b7a4d779903b8924abaef2a387cae50b7f54includes:32066570209: the quality job explicitly checked out and verified exact5951b7a4d779903b8924abaef2a387cae50b7f54, ran Python 3.14.7, reached exact 100% owned-production statement/branch coverage (3633statements /1006branches, zero misses/partials), 100% public docstrings,1334 passed, 5 deselected, lock freshness, and distribution build;32098143650: the reproducible wheel/sdist job explicitly checked out and verified exact5951b7a4d779903b8924abaef2a387cae50b7f54, built two clean exact-head source trees, verified reproducible wheel/sdist identity, and uploaded bounded evidence named for the exact source commit;32066570256, attempt 4: the repaired required workflow's Trivy job explicitly checked out exact5951b7a4d779903b8924abaef2a387cae50b7f54, emittedSECURITY_CHECKOUT ... expected_sha=5951... actual_sha=5951..., reported zero CRITICAL/HIGH/MEDIUM findings, and uploaded SARIF bound torefs/pull/233/head/ exact head. A later SARIF server-side merge-base fallback warning does not alter the scanner workspace identity;32066570191, attempt 2: the exact-head job99106222843succeeded throughCheckout exact submitted revision,Verify exact submitted revision, pinned-manifest validation, Semgrep execution, SARIF, and reporting for head5951b7a4d779903b8924abaef2a387cae50b7f54;32066566426, attempt 2: job99109445105independently boundPR_HEAD_SHA=5951b7a4d779903b8924abaef2a387cae50b7f54andPR_BASE_SHA=b84f0c94154043a3473939c01bb6471de5a129ae, fetched both immutable commits into the trusted workspace, passed the required-workflow smoke test, provisioned the contextual-orchestrator sidecar, and concluded that this test-only PR has no scannable changed files. That bounded not-applicable result is accepted by the required Strix job; it is not represented as a vulnerability scan of unrelated source.Historical Security/SAST runs that inspected synthetic merge commit
20581a0a9c51be71baa229cfa1d9e6b050c14c5bremain historical evidence only and are not transferred. The exact-source reruns above supersede only that source-identity defect for this unchanged head.The 2026-08-31 fresh exact-head inventory contains 35 check runs. It has no current
failure,neutral, or conclusion-null result, but it does containskippedauxiliary/conditional runs, includingpublish-manual-pr-evidence-status,org-queue-sweep, and severalcancel-closed-pr-runsinstances.Skippedevidence is never promoted to exact-head success. Those auxiliary skipped runs are not among the workflows currently required by organization ruleset18156473, so their presence alone is not a merge blocker. Acceptance is restricted to then-live required contexts that are terminal-success plus the separately evaluated formal-review state.Fresh inline review-thread inventory is empty.
Current independent-review state
The pg source/test head is unchanged and has no known current product finding, but it is not review-clean and must not merge yet.
Fresh formal review inventory remains:
1ddfc3260cc8e7e981c5c3bdd4ba2206348f4143:CHANGES_REQUESTED— predecessor evidence;5951b7a4d779903b8924abaef2a387cae50b7f54, OpenCode run32069198553:DISMISSED— not approval; and5951b7a4d779903b8924abaef2a387cae50b7f54, OpenCode run32100082025: activeCHANGES_REQUESTEDbecause its then-current centralcoverage-evidencefailed before proving required test/docstring evidence.That active same-head review remains formally blocking until a genuinely fresh current-head semantic review supersedes it. It is not reinterpreted or dismissed as approval. A current trusted OpenCode review-only activation already exists for this unchanged head under the present protected central control plane, so duplicate activation comments are intentionally avoided.
Live organization governance independently requires one qualifying approval. Model, COMMENTED, status, author, dismissed, predecessor, synthetic, skipped, or other non-passing evidence does not satisfy that approval requirement.
Read-only central control-plane boundary
The organization-required reviewer/scheduler/security control plane is owned by
ContextualWisdomLab/.github, has its own enabled writer, and remains read-only from this repository loop. Mutable central SHA/run state is intentionally not duplicated here.Issue #244 is the sole pg-owned mutable control-plane ledger for current central prerequisites and must be freshly read before any action that depends on them.
There is no pg-owned source defect that justifies churn on this unchanged head. Keep the contributor head stable while fresh same-head semantic review materializes.
Governance boundary
Protected
mainremains protected. Merge only this unchanged expected head after fresh verification of protected pg main, exact head/base/ancestry, every live protection/ruleset surface, actual checkout/source identity for required workflows, formal reviews, and review threads. Every required gate must be terminal-success on acceptable exact-current evidence, zero valid findings/threads may remain, and the qualifying non-author approval required by then-live governance must exist.Queued, pending, cancelled, skipped, absent, neutral, stale, predecessor, status-only, synthetic, author-only, rate-limited, infrastructure-failed, dismissed, or conclusion-null evidence is non-passing.
Do not copy central materializer/reviewer/scheduler/security workarounds into pg-llm-batch, manufacture a pg head event, self-approve, dismiss substantive review state, weaken gates, or transfer frozen review runs.
Refs #244, #157, #204.