Skip to content

feat(automation): add hourly protected PR and OpenCode product loops - #271

Draft
seonghobae wants to merge 37 commits into
mainfrom
feat/hourly-opencode-commercial-loop
Draft

feat(automation): add hourly protected PR and OpenCode product loops#271
seonghobae wants to merge 37 commits into
mainfrom
feat/hourly-opencode-commercial-loop

Conversation

@seonghobae

@seonghobae seonghobae commented Aug 5, 2026

Copy link
Copy Markdown
Collaborator

Objective

Add two non-duplicative hourly loops:

  1. PR maintenance at minute 7 invokes immutable central review/fix and guarded merge workflows while preserving the existing reviewer credential model.
  2. Product development at minute 23 runs only when the paginated open-PR count is zero. It uses checksum-pinned OpenCode 1.18.13 with NVIDIA_NIM_API_KEY, packages one bounded patch without executing repository code in the credentialed step, reverifies it separately, and uses a dedicated repository-scoped GitHub App only to open a draft PR.

The product loop never uses COPILOT_GITHUB_TOKEN, never approves or merges its own output, and never releases, publishes, or deploys.

Trust and backpressure controls

  • immutable central reusable-workflow pin 74e54255ec903e3ba5f920859b656fe2defcb057;
  • immutable action SHAs and checksum-pinned OpenCode archive 8d500b20fed2d26e537e221895b1a575476571b4f0089bb29fb13eeb8eb9e937;
  • NVIDIA egress allowlist and disabled OpenCode auto-update/model fetch/default plugins/LSP download/project config;
  • explicit OpenCode permission allowlist without --auto, so unmatched permission requests fail closed;
  • no Maven, pytest, project-code execution, commits, pushes, publication, nested tasks, web search, or web fetch in the credential-bearing model step;
  • exact credential-disclosure scan across model output and writable paths;
  • NUL-safe capture of allowed new text files and a fail-closed 20-file/200,000-byte proposal boundary;
  • deletion, rename, symlink, mode, binary, workflow, script, dependency, build-metadata, version, release, and deployment changes denied;
  • PR inventory, protected-base SHA, and patch SHA-256 rechecked before verification and publication;
  • short-lived repository-scoped App token requests only contents: write and pull-requests: write for branch and draft-PR publication;
  • fail-closed verifier and publisher egress allowlists;
  • non-cancelling concurrency and three-day evidence retention.

Test-first verifier-egress repair

The RED head a02bcde7bf60542f85297074fd21d2e697fbc72c added scripts/test_hourly_scheduler_egress_contract.py before production modification. CI run 31026008612 failed as intended because the credential-free verifier executed model-generated Java and Python tests under observation-only network policy.

The verifier now uses fail-closed egress-policy: block. Its allowlist is limited to GitHub API, checkout and Actions artifact transport, Maven Central, and the PyPI hosts required for hash-locked test dependencies.

Test-first publisher-egress repair

The RED head 7a34049d5a4c7a5a41f21c71f96af403ffde0dc3 added a regression contract before production modification. CI run 31028342182 failed as intended because the GitHub App credential-bearing publisher still used observation-only egress-policy: audit.

Exact current head cc533d982b38bd755cfa9c67e670ecc4bdcc64c6 repairs that valid supply-chain finding without weakening the test:

  • the publisher now uses fail-closed egress-policy: block;
  • only GitHub API, checkout, release-asset, and Actions artifact-transport endpoints are allowed;
  • NVIDIA, Maven Central, PyPI, and arbitrary external endpoints are absent from the publisher allowlist;
  • the App private key and short-lived write token remain confined to the publication-only job;
  • the operator guide and CHANGELOG.md record the boundary and recovery contract.

Relative to reviewed predecessor d565474dd516d7e612689374a51c990c8a3470c3, the repair changes only the workflow egress stanza, its deterministic regression test, the authoritative operator guide, and the changelog.

Exact-head evidence

For exact head cc533d982b38bd755cfa9c67e670ecc4bdcc64c6:

  • CI 31028760873: success.
    • Maven test job 92383820648: success.
    • Buyer-readiness script job 92383820672: success; 29 tests passed, including verifier and publisher egress contracts.
  • Security Scan 31028760722: success.
  • SAST Semgrep 31028760655: success.
  • Fuzz is not triggered by this workflow/documentation/script-only change under the repository's authoritative path filter; no absent fuzz result is represented as passing.
  • Exact-head CodeRabbit commit status: success, but no formal PR-level review is inferred from that status.
  • Formal GitHub reviews: none at the latest inspection.
  • Unresolved inline review threads: zero at the latest inspection.

Stack order

Keep this PR draft. Parent #270 must integrate first. This branch must then be reconciled onto protected main so the autonomous verifier also inherits #270's fail-closed Maven Surefire/Failsafe report-evidence gate, followed by fresh exact-head validation.

Merge gate

Do not merge until #270 is integrated and this branch reconciled, every exact-head required check succeeds, formal CodeRabbit and OpenCode/Noema/Strix evidence exists, zero unresolved threads remains true, a repository-write-authorized independent reviewer submits a counted approval, and every branch-protection and repository-policy rule is satisfied. Do not bypass protections, infer formal approval from commit status, or publish a release.

After integration, administrators must configure NVIDIA_NIM_API_KEY, CLEARFOLIO_MAINTAINER_APP_CLIENT_ID, and CLEARFOLIO_MAINTAINER_APP_PRIVATE_KEY; missing prerequisites fail closed without fallback identity or model.

@coderabbitai

coderabbitai Bot commented Aug 5, 2026

Copy link
Copy Markdown

Warning

Review limit reached

@seonghobae, you've reached your PR review limit, so we couldn't start this review.

Next review available in: 13 seconds

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 3d1f8965-9b94-4425-89c5-dc819b8d7a12

📥 Commits

Reviewing files that changed from the base of the PR and between f3cc09a and cc533d9.

📒 Files selected for processing (6)
  • .github/workflows/hourly-pr-maintenance.yml
  • .github/workflows/hourly-product-development.yml
  • CHANGELOG.md
  • docs/operations/hourly-development.md
  • scripts/test_hourly_opencode_scheduler_contract.py
  • scripts/test_hourly_scheduler_egress_contract.py

Comment @coderabbitai help to get the list of available commands.

@seonghobae seonghobae changed the title test(automation): define hourly OpenCode commercial loop feat(automation): add hourly protected PR and OpenCode product loops Aug 5, 2026

Copy link
Copy Markdown
Collaborator Author

@coderabbitai review

@opencode-agent @cwl-noema-review Please independently review exact current head 84980829a41f77ddb6ae471a3e7d80ef308d971a only.

Treat both workflows as privileged supply-chain code. Verify immutable source/action pins, central review-agent secret inheritance without credential remapping, zero-open-PR backpressure across every paginated gate, non-cancelling single-flight behavior, OpenCode 1.18.13 archive checksum, NVIDIA-only model routing, blocked egress, disabled auto-update/plugins/model-fetch/LSP/project config, prompt-injection boundaries, exact key-disclosure scanning, file/diff/deletion/rename/symlink/mode protections, immutable patch/base/hash evidence, no repository-code execution in the credentialed model step, complete credential-free Maven and buyer-readiness verification, Maintainer App least-privilege publication only after revalidation, draft-only PR creation, and absence of self-approval, auto-merge, release, publish, or deploy behavior.

Test-first evidence is RED 6812fac15158f36e059b82941f27ad00fad92e37 / CI 31016029745; exact-head evidence is CI 31016832999 (Maven 92342951361, 24 script tests in 92342951262), Security Scan 31016834248, and SAST Semgrep 31016833138, all successful. Queued, pending, cancelled, skipped-required, stale-head, predecessor, and dry-run evidence is not passing. Submit formal APPROVE only for this exact head if no blocker remains; otherwise report actionable path-specific findings.

@coderabbitai

coderabbitai Bot commented Aug 5, 2026

Copy link
Copy Markdown
🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo '== HEAD =='
git rev-parse HEAD
echo '== Changed files against first parent =='
git diff-tree --no-commit-id --name-status -r HEAD
echo '== Candidate files =='
fd -HI -t f -E .git '\.(ya?ml|md|py|sh)$' . | sort
echo '== Workflow structure =='
if [ -d .github/workflows ]; then
  for f in .github/workflows/*; do
    [ -f "$f" ] || continue
    echo "--- $f"
    sed -n '1,360p' "$f"
  done
fi
echo '== Documentation and test references =='
rg -n -C 3 --glob '*.{md,py,yml,yaml,sh}' \
  'OpenCode|NVIDIA_NIM_API_KEY|CLEARFOLIO_MAINTAINER|open PR|pull.?request|concurrency|mvn|pytest|publish|draft|auto-merge|workflow_call|secrets: inherit|74e54255|8d500b20|1\.18\.13' \
  . || true

Length of output: 116049


🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo '== PR merge-base and complete PR changed paths =='
base="$(git merge-base HEAD origin/main 2>/dev/null || git merge-base HEAD main)"
printf 'merge_base=%s\n' "$base"
git diff --name-status "$base..HEAD"

echo '== Product workflow: verification and publication jobs =='
grep -n -E '^  (verify|publish):|^      - name:|^      (run|uses|if|permissions|env):|^[[:space:]]{8}(GH_TOKEN|EXPECTED_|NIM_|APP_|base_sha|patch_sha256|open_prs|current_sha|git |gh )' \
  .github/workflows/hourly-product-development.yml
sed -n '300,620p' .github/workflows/hourly-product-development.yml

echo '== Product workflow: package boundary with line numbers =='
nl -ba .github/workflows/hourly-product-development.yml | sed -n '185,285p'

echo '== Complete scheduler contract tests =='
nl -ba scripts/test_hourly_opencode_scheduler_contract.py | sed -n '1,240p'

echo '== Static indicators for binary and pom semantic enforcement =='
rg -n -C 2 --glob '.github/workflows/hourly-product-development.yml' \
  'numstat|binary|diff-filter|pom\.xml|dependency|version|xmllint|maven.*help|git diff.*pom' .

Length of output: 10528


@seonghobae: I reviewed exact head 84980829a41f77ddb6ae471a3e7d80ef308d971a.

I found two blocking policy-enforcement gaps. I cannot approve this head.

  1. Dependency and version changes are not blocked.
    In .github/workflows/hourly-product-development.yml, Line 225 allows pom.xml. The packaging step then checks only the changed path, deletion, file count, rename, symlink, mode, whitespace, and patch size. A model can therefore change a Maven dependency or version in pom.xml. The prompt prohibition is not an enforcement control. Remove pom.xml from the allowed paths, or add a deterministic semantic diff check that rejects every dependency and version change. Add a contract test for the rejected case.

  2. Binary changes are not blocked.
    The packaging step produces the proposal with git diff --binary, but it does not detect binary diff entries. A binary file under an allowed path, such as docs/** or src/test/**, can pass the current path and size checks, then reach the verifier and publisher. Reject binary changes before packaging, for example by failing when git diff --numstat reports - for either byte-count column. Add a contract test for this condition.

The remaining reviewed controls match the stated design: immutable action and central workflow pins, secrets: inherit for both central scheduler calls, paginated zero-open-PR gates, non-cancelling concurrency, checksum-pinned OpenCode, NVIDIA-only model configuration, credential-free verification, dedicated App publication, and draft-only PR creation.

⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@seonghobae
seonghobae marked this pull request as ready for review August 5, 2026 14:51

Copy link
Copy Markdown
Collaborator Author

@coderabbitai review

@opencode-agent @cwl-noema-review Please independently review exact current head 2d63878b1490557725761984a8f62bc95fcb1d63 only.

A manual supply-chain review found that opencode run --auto would automatically grant any permission request that fell back to ask, weakening the intended fail-closed boundary when a tool is added or a resource rule fails to match. Test-first RED head 31c91a13a6214c549427d69bd1cc3244ba87def9 added an executable contract rejecting --auto. The production workflow now invokes non-interactive OpenCode without --auto, so explicitly allowed operations remain available and unmatched permission requests are rejected. The operator guide records the exact behavior with primary OpenCode source references, and CHANGELOG.md records the security change.

Verify the exact workflow permission map and last-match behavior, absence of automatic permission approval, NVIDIA-only routing, no repository-code execution in the credentialed step, immutable patch/base/hash evidence, credential-free acceptance, publication-only App identity, draft-only PR creation, and all existing branch-protection and independent-review gates. Current-head CI, Security Scan, and SAST are still running or queued and must not be treated as passing. Submit formal APPROVE only for this exact head after every required exact-head check succeeds; otherwise report actionable path-specific findings.

@coderabbitai

coderabbitai Bot commented Aug 5, 2026

Copy link
Copy Markdown

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

expected='2d63878b1490557725761984a8f62bc95fcb1d63'
actual="$(git rev-parse HEAD)"
printf 'HEAD=%s\nEXPECTED=%s\n' "$actual" "$expected"

echo '== Commit and changed paths from merge base =='
base="$(git merge-base HEAD origin/main 2>/dev/null || git merge-base HEAD main)"
printf 'MERGE_BASE=%s\n' "$base"
git diff --name-status "$base..HEAD"

echo '== Workflow files and structural outlines =='
fd -HI -t f -E .git 'hourly.*\.(yml|yaml)$|.*opencode.*\.(yml|yaml)$' .github/workflows 2>/dev/null | sort | while IFS= read -r f; do
  echo "--- $f"
  ast-grep outline "$f" --items all 2>/dev/null || sed -n '1,80p' "$f"
done

echo '== Relevant production workflow content =='
fd -HI -t f -E .git 'hourly-product-development\.(yml|yaml)$' .github/workflows 2>/dev/null | while IFS= read -r f; do
  echo "--- $f"
  nl -ba "$f" | sed -n '1,760p'
done

echo '== Changed documentation and contract-test references =='
rg -n -C 4 --glob '*.{yml,yaml,md,py}' \
  '(opencode run|--auto|permission|NVIDIA_NIM_API_KEY|NVIDIA|model|provider|patch_sha256|base_sha|numstat|pom\.xml|binary|open PR|pull.?request|mvn -B|pytest|draft|auto-merge|secrets: inherit|concurrency)' \
  .github docs scripts CHANGELOG.md 2>/dev/null || true

echo '== Exact-head pull request and check status =='
gh pr view 271 --repo ContextualWisdomLab/clearfolio \
  --json number,headRefOid,mergeStateStatus,isDraft,reviewDecision,statusCheckRollup \
  --jq '{number, headRefOid, mergeStateStatus, isDraft, reviewDecision, checks: [.statusCheckRollup[] | {name, status, conclusion}]}'

Length of output: 2687


🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo '== Product workflow, numbered =='
f='.github/workflows/hourly-product-development.yml'
awk '{printf "%6d\t%s\n", NR, $0}' "$f"

echo '== PR maintenance workflow, numbered =='
f='.github/workflows/hourly-pr-maintenance.yml'
awk '{printf "%6d\t%s\n", NR, $0}' "$f"

echo '== Operator guide and changelog excerpts =='
rg -n -C 5 --glob '*.{md,yml,yaml}' \
  '(opencode run|--auto|permission|last.match|NVIDIA_NIM_API_KEY|NVIDIA|model|provider|patch_sha256|base_sha|numstat|pom\.xml|binary|open PR|pull.?request|mvn -B|pytest|draft|auto-merge|secrets: inherit|concurrency)' \
  docs/operations/hourly-development.md CHANGELOG.md .github/workflows/hourly-product-development.yml .github/workflows/hourly-pr-maintenance.yml || true

echo '== Complete scheduler contract test =='
awk '{printf "%6d\t%s\n", NR, $0}' scripts/test_hourly_opencode_scheduler_contract.py

echo '== Exact-head PR and check status =='
gh pr view 271 --repo ContextualWisdomLab/clearfolio \
  --json number,headRefOid,mergeStateStatus,isDraft,reviewDecision,statusCheckRollup \
  --jq '{number, headRefOid, mergeStateStatus, isDraft, reviewDecision, checks: [.statusCheckRollup[] | {name, status, conclusion}]}'

Length of output: 88258


@seonghobae: I reviewed exact head 2d63878b1490557725761984a8f62bc95fcb1d63. I cannot approve this head.

  1. Dependency and version changes remain permitted.
    .github/workflows/hourly-product-development.yml Line 142 grants OpenCode edit permission for pom.xml. Line 225 also permits pom.xml in the packaged patch. The workflow does not apply a semantic Maven diff check. A proposed patch can therefore change dependencies, plugins, properties, or versions. The prompt prohibition is not an enforcement control.

    Remove pom.xml from both allowlists, or reject all dependency and version changes with a deterministic semantic check. Add a contract test for a rejected pom.xml dependency/version modification.

  2. Binary changes remain permitted.
    .github/workflows/hourly-product-development.yml Line 242 writes a binary-capable patch with git diff --binary. The package step does not inspect git diff --numstat or another binary indicator. A binary file within an allowed path can pass the path, count, and byte checks.

    Reject the proposal when either byte-count field from git diff --numstat is -. Add a contract test for this rejection.

The --auto change is present. The workflow now uses opencode run --model ... without --auto at Line 183. The permission map has an explicit default deny rule and narrow allow rules. This corrects the stated automatic-approval concern.

The remaining reviewed controls match the requested design. They include immutable action pins, NVIDIA-only model routing, disabled OpenCode expansion features, no repository-code execution in the credentialed step, paginated zero-open-PR gates, immutable base and patch checks, credential-free verification, a publication-only App token, and draft-only PR creation.

Exact-head checks are not complete. Analyze (java-kotlin), Semgrep (multi-language SAST), and strix remain in progress. The PR is also BLOCKED with REVIEW_REQUIRED. These states are not passing evidence.

You are interacting with an AI system.

Copy link
Copy Markdown
Collaborator Author

@coderabbitai review

@opencode-agent @cwl-noema-review Independently review exact current head ad68fd8b4528a4357896025fab02211901f6e911 only. The test-first repair now captures allowed newly created files in the immutable patch with git ls-files --others --exclude-standard -z plus git add --intent-to-add, counts them in the 20-file boundary, and rejects tracked or new binary payloads through git diff --numstat before artifact creation. Verify NUL-safe filename handling, path allowlisting before publication, deletion/rename/symlink/mode/binary rejection, exact patch/base/hash evidence, credential separation, zero-open-PR backpressure, and all prior supply-chain controls. Treat queued, pending, cancelled, skipped-required, absent, stale-head, and predecessor evidence as not passing. Submit a formal review only for this exact head.

@coderabbitai

coderabbitai Bot commented Aug 5, 2026

Copy link
Copy Markdown
🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

expected='ad68fd8b4528a4357896025fab02211901f6e911'
actual="$(git rev-parse HEAD)"
printf 'HEAD=%s\nEXPECTED=%s\n' "$actual" "$expected"

echo '== Changed paths from merge base =='
base="$(git merge-base HEAD origin/main 2>/dev/null || git merge-base HEAD main)"
printf 'MERGE_BASE=%s\n' "$base"
git diff --name-status "$base..HEAD"

echo '== Candidate workflow and contract files =='
fd -HI -t f -E .git \
  'hourly-(product-development|pr-maintenance)\.(yml|yaml)$|test_hourly_opencode_scheduler_contract\.py$|hourly-development\.md$|CHANGELOG\.md$' \
  . .github docs scripts 2>/dev/null | sort

echo '== Workflow structure =='
for f in .github/workflows/hourly-product-development.yml .github/workflows/hourly-pr-maintenance.yml; do
  if [ -f "$f" ]; then
    echo "--- $f"
    ast-grep outline "$f" --items all 2>/dev/null || true
  fi
done

echo '== Product workflow, numbered =='
if [ -f .github/workflows/hourly-product-development.yml ]; then
  nl -ba .github/workflows/hourly-product-development.yml | sed -n '1,760p'
fi

echo '== PR maintenance workflow, numbered =='
if [ -f .github/workflows/hourly-pr-maintenance.yml ]; then
  nl -ba .github/workflows/hourly-pr-maintenance.yml | sed -n '1,360p'
fi

echo '== Contract test and operator guide, numbered =='
if [ -f scripts/test_hourly_opencode_scheduler_contract.py ]; then
  nl -ba scripts/test_hourly_opencode_scheduler_contract.py | sed -n '1,420p'
fi
if [ -f docs/operations/hourly-development.md ]; then
  nl -ba docs/operations/hourly-development.md | sed -n '1,480p'
fi

echo '== Targeted workflow safeguards =='
rg -n -C 4 --glob '*.{yml,yaml,py,md}' \
  '(ls-files --others|intent-to-add|numstat|diff --check|diff-filter|--diff-filter|core\.quotepath|NUL|\\-z|pom\.xml|symlink|chmod|100[0-7]{3}|git diff --binary|patch_sha256|base_sha|open PR|pull.?request|concurrency|cancel-in-progress|secrets: inherit|74e54255|8d500b20|opencode run|--auto|NVIDIA_NIM_API_KEY|NVIDIA|auto-update|plugin|LSP|project.config|mvn -B|pytest|draft|auto-merge|actions/create-github-app-token)' \
  .github/workflows scripts docs CHANGELOG.md 2>/dev/null || true

echo '== Exact-head PR and check state =='
gh pr view 271 --repo ContextualWisdomLab/clearfolio \
  --json number,headRefOid,mergeStateStatus,isDraft,reviewDecision,reviews,statusCheckRollup \
  --jq '{number,headRefOid,mergeStateStatus,isDraft,reviewDecision,reviews:[.reviews[]|{author:.author.login,state,commit:.commit.oid}],checks:[.statusCheckRollup[]|{name,status,conclusion,workflowName}]}'

Length of output: 3989


🏁 Script executed:

#!/bin/bash
set -euo pipefail

numbered() {
  file="$1"
  echo "--- $file"
  sed = "$file" | sed 'N;s/\n/\t/'
}

echo '== Product workflow =='
numbered .github/workflows/hourly-product-development.yml

echo '== PR maintenance workflow =='
numbered .github/workflows/hourly-pr-maintenance.yml

echo '== Contract test =='
numbered scripts/test_hourly_opencode_scheduler_contract.py

echo '== Operator guide =='
numbered docs/operations/hourly-development.md

echo '== Changelog =='
numbered CHANGELOG.md

echo '== Focused safeguard matches =='
rg -n -C 5 --glob '*.{yml,yaml,py,md}' \
  '(ls-files --others|intent-to-add|numstat|diff --check|diff-filter|core\.quotepath|read -r -d|while IFS=|\\-z|pom\.xml|symlink|chmod|100[0-7]{3}|git diff --binary|patch_sha256|base_sha|open_prs|per_page=100|page=|concurrency|cancel-in-progress|secrets: inherit|74e54255|8d500b20|opencode run|--auto|NVIDIA_NIM_API_KEY|NVIDIA|auto-update|plugin|LSP|project.config|mvn -B|python -m pytest|draft|auto-merge|create-github-app-token)' \
  .github/workflows scripts docs CHANGELOG.md 2>/dev/null || true

echo '== Exact-head PR and check state =='
gh pr view 271 --repo ContextualWisdomLab/clearfolio \
  --json number,headRefOid,mergeStateStatus,isDraft,reviewDecision,reviews,statusCheckRollup \
  --jq '{number,headRefOid,mergeStateStatus,isDraft,reviewDecision,reviews:[.reviews[]|{author:.author.login,state,commit:.commit.oid}],checks:[.statusCheckRollup[]|{name,status,conclusion,workflowName}]}'

Length of output: 160818


@seonghobae I reviewed exact head ad68fd8b4528a4357896025fab02211901f6e911. I cannot approve this head.

  1. pom.xml dependency and version changes remain permitted.
    .github/workflows/hourly-product-development.yml Line 142 allows OpenCode to edit pom.xml. Line 229 also allows pom.xml in the packaged patch. The package step has no deterministic semantic check for Maven dependencies, plugins, properties, or versions.

    This conflicts with the documented boundary that prohibits dependency and version changes. Prompt text is not an enforcement control.

    Remove pom.xml from both allowlists, or add a deterministic semantic diff validation that rejects dependency and version changes. Add contract coverage for rejected Maven dependency and version modifications.

The requested repair works for the new-file and binary cases:

  • Line 208 reads untracked names with -z into mapfile -d ''.
  • Line 210 uses git add --intent-to-add -- "$path".
  • Line 212 includes the new paths in the changed-file count.
  • Lines 244-248 reject tracked and newly created binary payloads before artifact creation.
  • The path allowlist, deletion, rename, symlink, mode, patch hash, base SHA, paginated zero-open-PR gates, credential separation, and draft-only publication controls are present.

Exact-head approval evidence is also incomplete. CodeQL Analyze (java-kotlin) and strix are still in progress. PR #271 is BLOCKED with REVIEW_REQUIRED and no formal reviews. These states are not passing evidence.

⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

Copy link
Copy Markdown
Collaborator Author

@opencode-agent @cwl-noema-review Independently review exact current head 6dbd819ae0957794e13883c4544637e6f800dc51 only. Exact-head CI 31025180567, Security Scan 31025180471, and SAST Semgrep 31025181632 are successful; fuzz is path-filtered out because this PR changes no src/**, pom.xml, or .github/workflows/fuzz.yml path. Verify the complete privileged-workflow diff, especially NUL-safe capture of untracked files into immutable evidence, binary/deletion/rename/symlink/mode rejection, protected pom.xml and build inputs, zero-open-PR exact-base/hash gates, credential separation, explicit App-token permission categories, and draft-only publication behavior. Treat absent formal review and independent approval as blockers. Submit formal review evidence only for this exact head.

@seonghobae
seonghobae marked this pull request as draft August 5, 2026 16:38

Copy link
Copy Markdown
Collaborator Author

Security review on exact head a02bcde7bf60542f85297074fd21d2e697fbc72c: the credential-free verifier executes model-generated Java and Python tests while step-security/harden-runner is only in egress-policy: audit mode. That permits proposed code to contact arbitrary external hosts during acceptance, creating a post-model data-exfiltration path despite the credentialed OpenCode step being blocked. The test-first regression in scripts/test_hourly_scheduler_egress_contract.py correctly makes CI run 31026008612 fail. Change only the verifier hardening step to egress-policy: block with an explicit allowlist for GitHub Actions/artifacts plus Maven Central and hash-locked PyPI downloads; update the operator guide and CHANGELOG.md; then rerun all exact-head gates. Keep this PR draft and reconcile it after parent #270 integrates so the verifier also inherits #270's fail-closed Maven report gate. Do not weaken or remove the regression test.

Copy link
Copy Markdown
Collaborator Author

@coderabbitai review

@opencode-agent @cwl-noema-review Independently review exact current head d565474dd516d7e612689374a51c990c8a3470c3 only. Exact-head CI 31026559117, Security Scan 31026560248, and SAST Semgrep 31026559435 are successful; fuzz is not triggered by the authoritative path filter for this workflow/documentation/script-only diff. Verify the test-first verifier-egress repair: model-generated Java and Python code executes only under fail-closed egress-policy: block; the allowlist is limited to GitHub checkout/API/artifact transport, Maven Central, and hash-locked PyPI dependency delivery; no model, App, or review credential enters the verifier; arbitrary egress remains denied; and the publisher still executes no proposed code. Reverify NUL-safe new-file capture, binary and build-metadata rejection, exact base/patch identity, explicit App-token permission categories, draft-only publication, and absence of approval, merge, release, publish, or deploy commands. Treat the required post-#270 reconciliation, formal exact-head reviews, and counted independent write-authorized approval as blockers. Submit formal review evidence only for this exact head.

@coderabbitai

coderabbitai Bot commented Aug 5, 2026

Copy link
Copy Markdown

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

expected='d565474dd516d7e612689374a51c990c8a3470c3'
actual="$(git rev-parse HEAD)"
printf 'HEAD=%s\nEXPECTED=%s\n' "$actual" "$expected"
if [ "$actual" != "$expected" ]; then
  echo 'ERROR: checked-out repository is not the requested exact head.' >&2
  exit 0
fi

echo '== Changed paths against PR merge base =='
base="$(git merge-base HEAD origin/main 2>/dev/null || git merge-base HEAD main)"
printf 'MERGE_BASE=%s\n' "$base"
git diff --name-status "$base..HEAD"

echo '== Candidate files =='
fd -HI -t f -E .git \
  'hourly-(product-development|pr-maintenance)\.(yml|yaml)$|test_hourly_(opencode_scheduler|scheduler_egress)_contract\.py$|hourly-development\.md$|CHANGELOG\.md$' \
  .github scripts docs . 2>/dev/null | sort -u

for f in \
  .github/workflows/hourly-product-development.yml \
  .github/workflows/hourly-pr-maintenance.yml \
  scripts/test_hourly_scheduler_egress_contract.py \
  scripts/test_hourly_opencode_scheduler_contract.py \
  docs/operations/hourly-development.md \
  CHANGELOG.md
do
  if [ -f "$f" ]; then
    echo "== NUMBERED: $f =="
    nl -ba "$f"
  fi
done

echo '== Focused control references =='
rg -n -C 4 --glob '*.{yml,yaml,py,md}' \
  '(harden-runner|egress-policy|allowed-endpoints|NVIDIA_NIM_API_KEY|COPILOT_GITHUB_TOKEN|CLEARFOLIO_MAINTAINER|github-token|permissions:|contents: write|pull-requests: write|mvn|pytest|opencode run|--auto|git ls-files|intent-to-add|numstat|diff-filter|symlink|chmod|patch_sha256|base_sha|draft:|auto-merge|merge|publish|release|deploy|per_page=100|page=|cancel-in-progress)' \
  .github scripts docs CHANGELOG.md 2>/dev/null || true

echo '== Current PR state and exact-head check state =='
gh pr view 271 --repo ContextualWisdomLab/clearfolio \
  --json number,headRefOid,isDraft,mergeStateStatus,reviewDecision,reviews,statusCheckRollup \
  --jq '{number,headRefOid,isDraft,mergeStateStatus,reviewDecision,reviews:[.reviews[]|{author:.author.login,state,commit:.commit.oid}],checks:[.statusCheckRollup[]|{name,status,conclusion,workflowName}]}'

echo '== Parent PR `#270` state =='
gh pr view 270 --repo ContextualWisdomLab/clearfolio \
  --json number,state,mergedAt,mergeCommit,headRefOid,baseRefName \
  --jq '{number,state,mergedAt,mergeCommit:(.mergeCommit.oid // null),headRefOid,baseRefName}'

Length of output: 3670


🏁 Script executed:

#!/bin/bash
set -euo pipefail

numbered_slice() {
  file="$1"
  start="$2"
  end="$3"
  if [ -f "$file" ]; then
    echo "== $file, Lines $start-$end =="
    awk -v start="$start" -v end="$end" 'NR >= start && NR <= end { printf "%5d  %s\n", NR, $0 }' "$file"
  fi
}

numbered_slice .github/workflows/hourly-product-development.yml 1 760
numbered_slice .github/workflows/hourly-pr-maintenance.yml 1 360
numbered_slice scripts/test_hourly_scheduler_egress_contract.py 1 360
numbered_slice scripts/test_hourly_opencode_scheduler_contract.py 1 420
numbered_slice docs/operations/hourly-development.md 1 460
numbered_slice CHANGELOG.md 1 260

echo '== Focused control references =='
rg -n -C 5 --glob '*.{yml,yaml,py,md}' \
  '(harden-runner|egress-policy|allowed-endpoints|NVIDIA_NIM_API_KEY|COPILOT_GITHUB_TOKEN|CLEARFOLIO_MAINTAINER|github-token|permissions:|contents: write|pull-requests: write|mvn|pytest|opencode run|--auto|git ls-files|intent-to-add|numstat|diff-filter|symlink|chmod|patch_sha256|base_sha|draft:|auto-merge|merge|publish|release|deploy|per_page=100|page=|cancel-in-progress)' \
  .github scripts docs CHANGELOG.md 2>/dev/null || true

echo '== Current PR state and exact-head check state =='
gh pr view 271 --repo ContextualWisdomLab/clearfolio \
  --json number,headRefOid,isDraft,mergeStateStatus,reviewDecision,reviews,statusCheckRollup \
  --jq '{number,headRefOid,isDraft,mergeStateStatus,reviewDecision,reviews:[.reviews[]|{author:.author.login,state,commit:.commit.oid}],checks:[.statusCheckRollup[]|{name,status,conclusion,workflowName}]}'

echo '== Parent PR `#270` state =='
gh pr view 270 --repo ContextualWisdomLab/clearfolio \
  --json number,state,mergedAt,mergeCommit,headRefOid,baseRefName \
  --jq '{number,state,mergedAt,mergeCommit:(.mergeCommit.oid // null),headRefOid,baseRefName}'

Length of output: 202093


🏁 Script executed:

#!/bin/bash
set -euo pipefail

workflow='.github/workflows/hourly-product-development.yml'
test_file='scripts/test_hourly_scheduler_egress_contract.py'

echo '== Product workflow: all job boundaries and hardening context =='
grep -n -E '^  (propose|verify|publish):|^      - name:|harden-runner|egress-policy|allowed-endpoints|NVIDIA_|CLEARFOLIO_|permissions:|permission-|github-token|opencode run|git (apply|diff|ls-files|add|push)|mvn |pip install|pytest|gh pr create|--draft|merge|release|publish|deploy' "$workflow" || true

echo '== Product workflow: verifier job =='
awk '
  /^  verify:$/ { emit=1 }
  /^  publish:$/ { emit=0 }
  emit { printf "%5d  %s\n", NR, $0 }
' "$workflow"

echo '== Product workflow: publisher job =='
awk '
  /^  publish:$/ { emit=1 }
  emit { printf "%5d  %s\n", NR, $0 }
' "$workflow"

echo '== Egress regression test =='
awk '{ printf "%5d  %s\n", NR, $0 }' "$test_file"

echo '== Product scheduler contract: verifier and publisher assertions =='
awk '
  /^def test_uncredentialed_verifier_runs_complete_repository_acceptance/ { emit=1 }
  /^def test_pr_scheduler_preserves_central_review_agent_credentials/ { emit=0 }
  emit { printf "%5d  %s\n", NR, $0 }
' scripts/test_hourly_opencode_scheduler_contract.py

echo '== Exact workflow diff for the egress repair =='
git diff a02bcde7bf60542f85297074fd21d2e697fbc72c..d565474dd516d7e612689374a51c990c8a3470c3 -- \
  .github/workflows/hourly-product-development.yml \
  scripts/test_hourly_scheduler_egress_contract.py \
  docs/operations/hourly-development.md \
  CHANGELOG.md

Length of output: 30043


@seonghobae I reviewed exact head d565474dd516d7e612689374a51c990c8a3470c3.

I found no new code-level blocker in the verifier-egress repair.

  • .github/workflows/hourly-product-development.yml Lines 293-307 use egress-policy: block. The allowlist contains GitHub API, Actions transport, Maven Central, and the required PyPI hosts.
  • The verifier has read-only permissions. It does not receive NVIDIA_NIM_API_KEY or the Maintainer App private key.
  • The verifier rechecks paginated open PR count, protected-base SHA, and patch SHA-256 before it applies the patch. It then runs Maven verification and the hash-locked Python script tests.
  • scripts/test_hourly_scheduler_egress_contract.py rejects verifier audit mode and requires the explicit endpoint list.
  • The proposal workflow retains NUL-safe new-file handling, binary rejection, and protected build metadata.
  • The publication job revalidates state before it mints the repository-scoped App token. It requests only contents: write and pull-requests: write. It creates a draft PR only. I found no approval, merge, auto-merge, release, publish, or deploy command.

I cannot approve this head.

  • Parent #270 is still open. This branch has not been reconciled after #270.
  • strix is still in progress.
  • PR #271 is a draft with mergeStateStatus: BLOCKED and reviewDecision: REVIEW_REQUIRED.
  • The PR has no formal reviews or counted independent write-authorized approval.

Complete the post-#270 reconciliation and run fresh exact-head checks. Then obtain the required formal reviews and independent approval before requesting approval.

You are interacting with an AI system.

Copy link
Copy Markdown
Collaborator Author

@coderabbitai review

@opencode-agent @cwl-noema-review Independently review exact current head cc533d982b38bd755cfa9c67e670ecc4bdcc64c6 only.

Verify the test-first publisher-egress repair and the complete scheduler contract. RED evidence is 7a34049d5a4c7a5a41f21c71f96af403ffde0dc3 / CI 31028342182, which failed because the App credential-bearing publisher still used observation-only egress. Exact-head CI 31028760873 (Maven 92383820648; 29 buyer-readiness script tests in 92383820672), Security Scan 31028760722, and SAST Semgrep 31028760655 are successful.

Confirm that both code-executing verification and App credential-bearing publication use fail-closed egress-policy: block; publisher destinations are GitHub-only and exclude NVIDIA, Maven Central, PyPI, and arbitrary hosts; action/source pins remain immutable; the App token remains repository-scoped and limited to contents: write plus pull-requests: write; the publisher executes no proposed code and performs only branch push plus draft-PR creation; and no approval, merge, auto-merge, release, package publication, deployment, or protection bypass exists. Reverify zero-open-PR pagination, exact base and patch identity, binary/build-metadata rejection, credential separation, and operator documentation.

Fuzz is not triggered by the authoritative path filter for this workflow/documentation/script-only diff. Parent #270 integration, post-parent reconciliation, formal exact-head reviews, and counted independent write-authorized approval remain mandatory blockers. Submit formal review evidence only for this exact head; otherwise report actionable path-specific findings.

@coderabbitai

coderabbitai Bot commented Aug 5, 2026

Copy link
Copy Markdown

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

expected='cc533d982b38bd755cfa9c67e670ecc4bdcc64c6'
actual="$(git rev-parse HEAD)"
printf 'HEAD=%s\nEXPECTED=%s\n' "$actual" "$expected"
if [ "$actual" != "$expected" ]; then
  echo 'ERROR: The checkout does not match the requested exact head.' >&2
  exit 0
fi

echo '== Changed paths from PR merge base =='
base="$(git merge-base HEAD origin/main 2>/dev/null || git merge-base HEAD main)"
printf 'MERGE_BASE=%s\n' "$base"
git diff --name-status "$base..HEAD"

echo '== Relevant file map =='
fd -HI -t f -E .git \
  'hourly-(product-development|pr-maintenance)\.(yml|yaml)$|test_hourly_(opencode_scheduler|scheduler_egress)_contract\.py$|hourly-development\.md$|CHANGELOG\.md$' \
  .github scripts docs . 2>/dev/null | sort -u

for f in \
  .github/workflows/hourly-product-development.yml \
  .github/workflows/hourly-pr-maintenance.yml \
  scripts/test_hourly_scheduler_egress_contract.py \
  scripts/test_hourly_opencode_scheduler_contract.py \
  docs/operations/hourly-development.md \
  CHANGELOG.md
do
  if [ -f "$f" ]; then
    echo "== NUMBERED: $f =="
    nl -ba "$f"
  fi
done

echo '== Focused workflow and contract controls =='
rg -n -C 4 --glob '*.{yml,yaml,py,md}' \
  '(harden-runner|egress-policy|allowed-endpoints|NVIDIA_NIM_API_KEY|COPILOT_GITHUB_TOKEN|CLEARFOLIO_MAINTAINER|actions/create-github-app-token|permissions:|contents: write|pull-requests: write|github-token|git ls-files|intent-to-add|numstat|diff-filter|symlink|chmod|patch_sha256|base_sha|per_page=100|page=|cancel-in-progress|secrets: inherit|74e54255|8d500b20|opencode run|--auto|git apply|git push|gh pr create|draft:|auto-merge|merge|release|publish|deploy)' \
  .github scripts docs CHANGELOG.md 2>/dev/null || true

echo '== Exact repair diff =='
git diff 7a34049d5a4c7a5a41f21c71f96af403ffde0dc3..HEAD -- \
  .github/workflows/hourly-product-development.yml \
  scripts/test_hourly_scheduler_egress_contract.py \
  docs/operations/hourly-development.md \
  CHANGELOG.md

echo '== PR `#271` and parent `#270` state =='
gh pr view 271 --repo ContextualWisdomLab/clearfolio \
  --json number,headRefOid,isDraft,mergeStateStatus,reviewDecision,reviews,statusCheckRollup \
  --jq '{number,headRefOid,isDraft,mergeStateStatus,reviewDecision,reviews:[.reviews[]|{author:.author.login,state,commit:.commit.oid}],checks:[.statusCheckRollup[]|{name,status,conclusion,workflowName}]}'
gh pr view 270 --repo ContextualWisdomLab/clearfolio \
  --json number,state,mergedAt,mergeCommit,headRefOid,baseRefName \
  --jq '{number,state,mergedAt,mergeCommit:(.mergeCommit.oid // null),headRefOid,baseRefName}'

Length of output: 3973


🏁 Script executed:

#!/bin/bash
set -euo pipefail

expected='cc533d982b38bd755cfa9c67e670ecc4bdcc64c6'
test "$(git rev-parse HEAD)" = "$expected"

numbered() {
  file="$1"
  echo "== NUMBERED: $file =="
  awk '{printf "%5d  %s\n", NR, $0}' "$file"
}

numbered .github/workflows/hourly-product-development.yml
numbered .github/workflows/hourly-pr-maintenance.yml
numbered scripts/test_hourly_scheduler_egress_contract.py
numbered scripts/test_hourly_opencode_scheduler_contract.py
numbered docs/operations/hourly-development.md
numbered CHANGELOG.md

echo '== Exact publisher-egress repair diff =='
git diff 7a34049d5a4c7a5a41f21c71f96af403ffde0dc3..HEAD -- \
  .github/workflows/hourly-product-development.yml \
  scripts/test_hourly_scheduler_egress_contract.py \
  docs/operations/hourly-development.md \
  CHANGELOG.md

echo '== Focused control references =='
rg -n -C 4 --glob '*.{yml,yaml,py,md}' \
  '(harden-runner|egress-policy|allowed-endpoints|NVIDIA_NIM_API_KEY|COPILOT_GITHUB_TOKEN|CLEARFOLIO_MAINTAINER|actions/create-github-app-token|contents: write|pull-requests: write|github-token|git ls-files|intent-to-add|numstat|diff-filter|symlink|chmod|patch_sha256|base_sha|per_page=100|page=|cancel-in-progress|secrets: inherit|74e54255|8d500b20|opencode run|--auto|git apply|git push|gh pr create|draft:|auto-merge|merge|release|publish|deploy)' \
  .github scripts docs CHANGELOG.md 2>/dev/null || true

echo '== PR `#271` state =='
gh pr view 271 --repo ContextualWisdomLab/clearfolio \
  --json number,headRefOid,isDraft,mergeStateStatus,reviewDecision,reviews,statusCheckRollup \
  --jq '{number,headRefOid,isDraft,mergeStateStatus,reviewDecision,reviews:[.reviews[]|{author:.author.login,state,commit:.commit.oid}],checks:[.statusCheckRollup[]|{name,status,conclusion,workflowName}]}'

echo '== Parent PR `#270` state =='
gh pr view 270 --repo ContextualWisdomLab/clearfolio \
  --json number,state,mergedAt,mergeCommit,headRefOid,baseRefName \
  --jq '{number,state,mergedAt,mergeCommit:(.mergeCommit.oid // null),headRefOid,baseRefName}'

Length of output: 202168


@seonghobae I reviewed exact head cc533d982b38bd755cfa9c67e670ecc4bdcc64c6.

I found no new code-level blocker in the publisher-egress repair.

  • .github/workflows/hourly-product-development.yml uses egress-policy: block in the verifier and publisher jobs.
  • The publisher allowlist contains GitHub API, GitHub, GitHub Actions transport, artifact storage, and release-asset endpoints only. It excludes NVIDIA, Maven Central, PyPI, and arbitrary external endpoints.
  • The publisher receives the Maintainer App private key only in the publication job. The minted token is limited to ContextualWisdomLab/clearfolio, contents: write, and pull-requests: write.
  • The publisher rechecks the paginated open-PR count, protected base SHA, and patch SHA-256 before token minting. It applies the verified patch, pushes one branch, and creates a draft PR.
  • The publisher does not run Maven, pytest, or other proposed repository code. I found no approval, merge, auto-merge, release, package publication, deployment, or protection-bypass command.
  • The proposal boundary includes immutable action and OpenCode pins, NVIDIA-only routing, no --auto, NUL-safe new-file capture, file-count and patch-size limits, and deletion, rename, symlink, mode, binary, workflow, script, dependency, and build-input protections.
  • The verifier remains credential-free and uses blocked egress with the required GitHub, Maven Central, and hash-locked PyPI endpoints.
  • The operator guide records the verifier and publisher egress boundaries and recovery requirements.

I cannot approve this head.

  • strix is still IN_PROGRESS. This is not passing exact-head evidence.
  • PR #271 is a draft with mergeStateStatus: BLOCKED and reviewDecision: REVIEW_REQUIRED.
  • PR #271 has no formal reviews or counted independent write-authorized approval.
  • Parent #270 is still open. This branch still requires post-parent reconciliation and fresh exact-head validation.

Complete these gates before requesting approval.

You are interacting with an AI system.

Copy link
Copy Markdown
Collaborator Author

@coderabbitai review

@opencode-agent @cwl-noema-review Please review exact current head cc533d982b38bd755cfa9c67e670ecc4bdcc64c6 only. Verify the hourly maintenance and product-development workflows for immutable pins, zero-open-PR pagination, non-cancelling concurrency, bounded text-only changes, protected build and workflow paths, exact base and patch checks, separated model/verifier/publisher identities, blocked egress, complete credential-free acceptance tests, and draft-only PR creation with no self-approval, merge, release, or deployment behavior.

Current-head CI 31028760873, Security Scan 31028760722, and SAST Semgrep 31028760655 succeeded. This draft remains stacked behind #270. Submit a formal current-head review only; do not infer independent human approval or merge readiness.

@coderabbitai

coderabbitai Bot commented Aug 5, 2026

Copy link
Copy Markdown
🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

expected='cc533d982b38bd755cfa9c67e670ecc4bdcc64c6'
actual="$(git rev-parse HEAD)"
printf 'HEAD=%s\nEXPECTED=%s\n' "$actual" "$expected"
if [ "$actual" != "$expected" ]; then
  echo 'ERROR: checkout does not match the requested exact head.'
  exit 0
fi

for f in \
  .github/workflows/hourly-pr-maintenance.yml \
  .github/workflows/hourly-product-development.yml \
  scripts/test_hourly_opencode_scheduler_contract.py \
  scripts/test_hourly_scheduler_egress_contract.py \
  docs/operations/hourly-development.md \
  CHANGELOG.md
do
  if [ -f "$f" ]; then
    echo "== $f =="
    nl -ba "$f"
  fi
done

echo '== Focused control references =='
rg -n -C 3 --glob '*.{yml,yaml,py,md}' \
  '(74e54255ec903e3ba5f920859b656fe2defcb057|8d500b20fed2d26e537e221895b1a575476571b4f0089bb29fb13eeb8eb9e937|secrets: inherit|cancel-in-progress|per_page=100|page=|open_prs|opencode run|--auto|NVIDIA_NIM_API_KEY|egress-policy|allowed-endpoints|intent-to-add|numstat|diff-filter|pom\.xml|patch_sha256|base_sha|create-github-app-token|contents: write|pull-requests: write|gh pr create|--draft|auto-merge|git merge|release|deploy)' \
  .github scripts docs CHANGELOG.md || true

echo '== PR and parent state =='
gh pr view 271 --repo ContextualWisdomLab/clearfolio \
  --json headRefOid,isDraft,mergeStateStatus,reviewDecision,reviews,statusCheckRollup \
  --jq '{headRefOid,isDraft,mergeStateStatus,reviewDecision,reviews:[.reviews[]|{author:.author.login,state,commit:.commit.oid}],checks:[.statusCheckRollup[]|{name,status,conclusion}]}'
gh pr view 270 --repo ContextualWisdomLab/clearfolio \
  --json state,mergedAt,mergeCommit \
  --jq '{state,mergedAt,mergeCommit:(.mergeCommit.oid // null)}'

Length of output: 2205


🏁 Script executed:

#!/bin/bash
set -euo pipefail

expected='cc533d982b38bd755cfa9c67e670ecc4bdcc64c6'
test "$(git rev-parse HEAD)" = "$expected"

for f in \
  .github/workflows/hourly-pr-maintenance.yml \
  .github/workflows/hourly-product-development.yml \
  scripts/test_hourly_opencode_scheduler_contract.py \
  scripts/test_hourly_scheduler_egress_contract.py \
  docs/operations/hourly-development.md \
  CHANGELOG.md
do
  if [ -f "$f" ]; then
    printf '== %s ==\n' "$f"
    awk '{printf "%5d  %s\n", NR, $0}' "$f"
  fi
done

echo '== Focused control references =='
rg -n -C 3 --glob '*.{yml,yaml,py,md}' \
  '(74e54255ec903e3ba5f920859b656fe2defcb057|8d500b20fed2d26e537e221895b1a575476571b4f0089bb29fb13eeb8eb9e937|secrets: inherit|cancel-in-progress|per_page=100|page=|open_prs|opencode run|--auto|NVIDIA_NIM_API_KEY|egress-policy|allowed-endpoints|intent-to-add|numstat|diff-filter|pom\.xml|patch_sha256|base_sha|create-github-app-token|contents: write|pull-requests: write|gh pr create|--draft|auto-merge|git merge|release|deploy)' \
  .github scripts docs CHANGELOG.md || true

echo '== PR and parent state =='
gh pr view 271 --repo ContextualWisdomLab/clearfolio \
  --json headRefOid,isDraft,mergeStateStatus,reviewDecision,reviews,statusCheckRollup \
  --jq '{headRefOid,isDraft,mergeStateStatus,reviewDecision,reviews:[.reviews[]|{author:.author.login,state,commit:.commit.oid}],checks:[.statusCheckRollup[]|{name,status,conclusion}]}'
gh pr view 270 --repo ContextualWisdomLab/clearfolio \
  --json state,mergedAt,mergeCommit \
  --jq '{state,mergedAt,mergeCommit:(.mergeCommit.oid // null)}'

Length of output: 228913


@seonghobae I reviewed exact head cc533d982b38bd755cfa9c67e670ecc4bdcc64c6.

I found no new code-level blocker in the reviewed workflows.

  • .github/workflows/hourly-pr-maintenance.yml pins both central reusable workflows to 74e54255ec903e3ba5f920859b656fe2defcb057. Both calls use secrets: inherit. The local workflow does not remap reviewer credentials.
  • Both hourly workflows use non-cancelling concurrency.
  • .github/workflows/hourly-product-development.yml checks the paginated open-PR inventory before proposal, verification, and publication.
  • The product workflow pins OpenCode 1.18.13 to SHA-256 8d500b20fed2d26e537e221895b1a575476571b4f0089bb29fb13eeb8eb9e937. It routes the model through NVIDIA NIM. It does not use --auto.
  • The proposal job has blocked egress. The permission map denies workflows, scripts, pom.xml, web access, nested tasks, and unapproved shell commands.
  • The package stage includes new files with NUL-safe git ls-files ... -z handling and git add --intent-to-add. It enforces the file and byte limits. It rejects deletion, rename, symlink, mode, binary, workflow, script, and build-input changes.
  • The verifier rechecks the open-PR inventory, protected base SHA, and patch SHA-256. It has no model or App credential. It uses blocked egress and runs Maven verification plus hash-locked buyer-readiness tests.
  • The publisher also uses blocked GitHub-only egress. It mints a repository-scoped App token only after revalidation. The token requests only contents: write and pull-requests: write.
  • The publisher applies the verified patch, pushes one unique branch, and calls gh pr create --draft. I found no self-approval, merge, auto-merge, release, package publication, deployment, or protection-bypass command.

The reported exact-head CI, security, and SAST checks are complete and successful. The current GitHub state also shows successful Maven, buyer-readiness, CodeQL, Semgrep, OpenCode, Noema, and Strix checks.

I cannot approve this PR.

  • PR #271 remains a draft.
  • Its current state is BLOCKED with REVIEW_REQUIRED.
  • It has no formal reviews or counted independent write-authorized approval.
  • Parent #270 remains open.
  • This branch still requires reconciliation after #270 integrates and then fresh exact-head validation.
⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant