fix(opencode): metadata review gate 순환 대기 제거 - #529
Conversation
OpenCode Review Overview
Changed-File Evidence Mapflowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow: opencode-review.yml"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow: opencode-review.yml"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["CI script: test_strix_quick_gate.sh"]
S2 --> I2["review and security gate shell path"]
I2 --> R2["Review risk: CI script: test_strix_quick_gate.sh"]
R2 --> V2["bash -n plus Strix self-test"]
Evidence --> S3["Test: test_opencode_agent_contract.py"]
S3 --> I3["regression suite"]
I3 --> R3["Review risk: Test: test_opencode_agent_contract.py"]
R3 --> V3["targeted test run"]
|
There was a problem hiding this comment.
Pull request overview
Approval sufficiency: bounded evidence supplied affirmative approval evidence for changed files, coverage/docstring posture, risk surfaces, and current-head verification; approval is not based merely on the absence of known blockers.
Verification posture: CodeGraph evidence was initialized and bounded current-head evidence reviewed for changed-file evidence including .github/workflows/opencode-review.yml, scripts/ci/test_strix_quick_gate.sh, tests/test_opencode_agent_contract.py.
Linter/static: workflow/static review evidence is bounded by the current-head GitHub Checks gate and changed-file evidence.
TDD/regression: coverage execution evidence and focused changed hunks were reviewed from bounded-review-evidence.md.
Coverage: coverage execution evidence reports supported repository test suites passed.
Docstring coverage: coverage execution evidence reports configured repository docstring gates passed or docstring coverage was advisory.
DAG: CodeGraph/source-backed behavior map connects .github/workflows/opencode-review.yml to the affected review, runtime, or workflow path and required checks.
PoC/execution: coverage-evidence job executed on the current head and reported PASS.
DDD/domain: workflow and repository-governance invariants were reviewed against changed files in bounded evidence.
CDD/context: CodeGraph evidence, changed-file history, and focused hunks were reviewed from bounded-review-evidence.md.
Similar issues: changed-file history evidence was reviewed for comparable local precedents.
Claim/concept check: bounded evidence, repository source, current-head workflow evidence, and, where numeric, scientific, statistical, or literature-backed claims are affected, original-paper/formula evidence and parameter-recovery expectations were used for claims.
Standards search: standards and external-source checks are delegated to configured OpenCode web_search/Context7/DeepWiki sources when applicable; no evidence-backed standards blocker is present in bounded evidence.
Compatibility/convention: changed workflow/script conventions, object naming, and reserved-word safety for schema/API/config/code surfaces were checked in bounded evidence.
Breaking-change/backcompat: deployment evidence and changed-file history were checked for backward-compatibility risk.
Performance: changed surfaces were checked for performance risk in bounded evidence.
Developer experience: changed automation, review, test, setup, and maintenance surfaces were checked for helpful or obstructive DX impact in bounded evidence.
User experience: connected user, operator, API, CLI, documentation, review-comment, status-check, rendering, and workflow-reader behavior was checked for contradictions against code, docs, and tests in bounded evidence.
Visual/DOM: Playwright visual, DOM locator, ARIA snapshot, console, and responsive evidence were checked when a web UI surface was present; for non-web surfaces, API/CLI/log/docs/workflow interaction evidence was reviewed instead.
Accessibility/i18n: accessibility, localization, and human-readable text surfaces were checked where UI, CLI, API message, docs, logs, or review text changed.
Supply-chain/license: dependency, package, model, container, and external-tool changes were checked in bounded evidence.
Packaging: package, build, test, lint, and security contracts were checked in bounded evidence.
Security/privacy: workflow-token, review-gate, and repository-automation security/privacy boundaries were checked in bounded evidence.
Findings
No blocking findings.
Adversarial validation
{"status":"passed","probes":[{"path":".github/workflows/opencode-review.yml","line":1801,"hypothesis":"Metadata-only gate evaluation could cause a deadlock in OpenCode review process","attack_or_counterexample":"Simulated PR with metadata-only gate evaluation","evidence":"Verified in PR changes that metadata-only gates are now ignored in multiple places","outcome":"falsified"},{"path":"scripts/ci/test_strix_quick_gate.sh","line":895,"hypothesis":"Insufficient filtering of metadata-only gates in Strix checks","attack_or_counterexample":"Tested with simulated Strix runs including metadata-only gates","evidence":"Confirmed changes ensure metadata-only gates are ignored in Strix checks","outcome":"falsified"}],"residual_risk":"Low; changes are well-tested and verified"}Evidence
- Result: APPROVE
- Reason: PR addresses metadata review gate deadlock issue with clear fixes and passes all checks
- Scope:
central OpenCode/Strix review-process - Changed files:
3 - Head SHA:
b84907a1601e4b2c6c85378a6b75e2fcaa7e95e6 - Workflow run: 29239895482
- Workflow attempt: 1
This approval path is limited to ContextualWisdomLab/.github central review-process self-repair.
원인
naruon#1064의 중앙 OpenCode workflow_dispatch run29233901723에서 current-head source review와 적대적 검증은APPROVE였지만, 승인 단계가 다음 check를 12회 기다린 뒤 review를 보류했습니다.이 check는 OpenCode/CodeRabbit review 상태를 소비하는 downstream metadata gate입니다. GitHub가 check suite workflow를
PR Governance가 아니라CodeQL로 귀속할 수 있어 기존 workflow-name 조건이 순환 의존을 끊지 못했습니다.수정
metadata-only gate evaluation을 안정적인 check 이름으로 제외합니다.branch protection의
metadata-only gate evaluation필수 설정은 변경하지 않습니다. OpenCode review가 제출된 뒤 metadata gate가 해당 evidence를 독립적으로 검증하고 merge를 계속 차단할 수 있습니다.검증
bash scripts/ci/test_strix_quick_gate.sh-> PASS (rebase 전 전체 fixture)uv run coverage run -m pytest -q-> 444 passeduv run coverage report --fail-under=100-> 4637/4637, 100%uv run interrogate -c pyproject.toml scripts-> 100%bash -n-> PASSshellcheck -S warning-> PASSactionlint -shellcheck= -pyflakes=-> PASS