fix(coverage): restore validated npm workspace lock owners - #748
fix(coverage): restore validated npm workspace lock owners#748seonghobae wants to merge 15 commits into
Conversation
|
Important Review skippedDraft detected. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
|
Stack correction: #731 was closed without merge on August 4, 2026, so it is not a valid remaining dependency and none of its checks or reviews are transferable. Keep this PR draft at exact head |
4d3bd2c to
785f2c2
Compare
785f2c2 to
b715577
Compare
|
Exact-head downstream evidence from At BandScope head Please preserve the supply-chain boundary rather than broadly skipping incomplete entries. A reviewable acceptance rule is: permit a metadata-only nested entry only when the lock contains a canonical package entry for the same package identity/version whose |
7d01600 to
dcbd777
Compare
b715577 to
f070c50
Compare
|
Closing this stale stacked draft. Its current head is the protected |
|
Correction after re-reading the live branch: the stale stack was already reset and retargeted to protected |
| cancel-in-progress: false | ||
|
|
||
| permissions: | ||
| contents: write |
| REVIEWED_BASE = "4d076f636b6de5043e8501e93c06ed0a8c896eb3" | ||
| REVIEWED_CHILD = "b715577b9e946ecad4bd00c9f8afc7b2a219e048" | ||
| EXPECTED_MAIN_PARENT = "f070c504c1cb06891b800d7ab0cf6ac7d3cf8eae" | ||
| PATCH_PATH = Path("/tmp/pr748-current-main.patch") |
Purpose
Restore the fail-closed npm workspace lock-owner resolver and its central OpenCode coverage integration as a focused current-
mainchange.A selected nested package such as BandScope
apps/desktopmust install from its nearest validated npm workspace owner instead of requiring an invalid duplicate lockfile beside every workspace package.Rebuild state
The branch was reset to protected
mainatf070c504c1cb06891b800d7ab0cf6ac7d3cf8eaebecause the previous stacked base had diverged and accidentally removed the verified LLVM 19 coverage toolchain while applying the workspace resolver. A bounded exact-parent repair now reapplies only the reviewed seven-file npm workspace ownership contract and its tests while preserving the current central control-plane baseline.The temporary branch-repair helper and workflow must delete themselves before the verified product-policy commit is published. The final diff must contain exactly:
.github/workflows/opencode-review-dispatch.ymldocs/doctoring/npm-workspace-lock-ownership.mdscripts/ci/npm_workspace_install_root.pytests/npm_workspace_test_support.pytests/test_npm_workspace_install_root.pytests/test_npm_workspace_install_root_hardening.pytests/test_opencode_agent_contract.pyMerge gate
This PR remains Draft until the rebuilt seven-file diff is published and exact-head focused/full tests, resolver statement/branch coverage 100%, production docstrings 100%, Python compilation, Ruff, workflow contracts, security workflows, OpenCode, Noema, CodeRabbit, qualifying independent approval, unresolved-thread policy, and branch protection all succeed.
No predecessor-head check or review result is reused.