refactor(ddd): restore contextual-orchestrator ownership boundary - #899
seonghobae wants to merge 32 commits into
Conversation
|
Understand this PR’s impact Explore downstream dependencies and potential security impact with Blast Radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (1)
🚧 Files skipped from review as they are similar to previous changes (1)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughLineageWeave는 내장 contextual-orchestrator 런타임과 공급자 환경 변수를 제거했습니다. Compose와 운영 스크립트는 ChangesContextual-orchestrator 소유 경계
Priority: ➖ Normal Estimated code review effort: 3 (Moderate) | ~25 minutes Change: Refactor 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Signed-off-by: Codex <codex@localhost>
|
Current-head local evidence for
This PR remains draft until #780 lands (or its exact fix is otherwise present) and current-head hosted checks/review are terminal. No provider credentials or production records were inspected. |
Merge the current #899 ownership-boundary head into the dichotomous measurement-policy stack without rewriting child history. The parent delta is the code-current Vision runtime note; the measurement policy delta remains unchanged.
Merge protected main@3f61c824 into the ownership-boundary root without rewriting history. The intervening main delta only adds the repository Pages landing source at docs/index.md and does not overlap the DDD boundary repair.
Merge the current #899 root after it incorporated protected main@3f61c824. The only new parent delta is docs/index.md; the dichotomous measurement-policy semantic delta is unchanged.
seonghobae
left a comment
There was a problem hiding this comment.
Current-head owner-boundary review found one valid remaining promotion blocker, not a reason to copy more source into LineageWeave. The branch correctly removes the embedded contextual-orchestrator runtime and provider credential/model authority, but lineageweave/adjudication_client.py is still a locally authored wire client: it constructs /v1/chat/completions payloads, parses the reply locally, lets the caller select reasoning_effort, and defaults request timeout to 180.0s. Fresh owner state also shows ContextualWisdomLab/contextual-orchestrator has zero GitHub Releases. The owner release mechanism has landed, but no immutable consumable API/client/schema release exists yet, and owner protected main currently has its own open runtime/security repair lane.
Treat this as a mutable/unreleased dependency finding. Do not implement a second CO client/schema here and do not pin mutable owner main. ADR 0300 should remain Proposed. The canonical order is owner RED→GREEN→protected integration→immutable version/tag/Release/artifact+SBOM/provenance/reproducibility/rollback→released API/client/schema identity→LineageWeave thin consumer bump that removes the raw protocol duplication and fixed 180s default→fresh exact-head validation. Owner handoff is recorded on contextual-orchestrator#1083. Existing Tests/SAST GREEN on this head remains valid repository evidence but is not release-boundary acceptance.
seonghobae
left a comment
There was a problem hiding this comment.
Fresh exact-head validation update: repository Tests 35558855874, SAST 35558855866, and Security 35558855859 remain terminal SUCCESS. Required CodeQL 35558855747 remains terminal FAILURE, although its final Dispatch current-head CodeQL scan job 106439021306 has now acquired a runner and completed SUCCESS; the earlier compatibility jobs still failed closed because no accepting current-head owner verdict had been published when they checked.
A separate required-workflow failure is now concretely classified. Strix run 35558853933 / job 106321781463 completed the actual Strix scan successfully (scan_results.success=true, SARIF 0 results, report emitted), but the wrapper failed afterward because the central evidence binder was resolved from the target trusted workspace and was absent there: ERROR: Strix evidence binder is missing: .../trusted-workspace/scripts/ci/strix_evidence_binding.py. Artifact strix-reports 10656007820 preserves the receipt. This is the existing canonical .github#2292 owner defect, not a #899 application finding; LineageWeave must not copy the central binder locally or blind-rerun the leaf workflow. I added the exact #899 specimen to .github#2292 as comment 5769204063.
The contextual-orchestrator immutable-release blocker is unchanged: Releases is still [], and owner PR #1209 remains open at exact 0b369007c45754616aea102d6aa8062bb5937726. No merge-readiness claim is made.
seonghobae
left a comment
There was a problem hiding this comment.
Fresh validation review: repository source head is unchanged, but canonical CodeQL producer state materially advanced. .github run 35652904176 validate-dispatch job 106509367177 acquired runner 1002081322, bound the live #899/head/base identity, and completed SUCCESS. The remaining owner-side admission is now the three scan jobs: JavaScript/TypeScript 106584641204, Actions 106584641235, and Python 106584641313, all queued with runner_id=0, steps=[]. This narrows the CodeQL blocker but does not make Required CodeQL GREEN. Strix binder ownership and the unreleased contextual-orchestrator API/client/schema boundary remain unchanged. COMMENT only; no self-approval.
|
Canonical owner prerequisite moved after the last #899 authority update. contextual-orchestrator #1209 is now exact Fresh #1209 exact-head gates are all nonterminal: Security and Quality #899 itself remains exact |
Live authority update — 2026-09-22 KSTExact head remains Canonical CodeQL producer
Artifact authority remains:
The #899 source should stay unchanged at this point. Correct owner order is now: #983 JS source repair/acceptance; |
seonghobae
left a comment
There was a problem hiding this comment.
Current-head review after the canonical CodeQL producer became fully terminal. I do not find a new #899-owned source repair to make on this exact head. The four JavaScript findings belong to existing owner #983; the Python SARIF path is absent from the exact target/base Git trees and is routed to central source-provenance owner .github#2340; Actions SARIF is clean but GHAS identity remains .github#2276/#2275; terminal receipt publication/settlement remains .github#1929. Keep #899 unchanged and non-merge-ready until those owner paths settle, contextual-orchestrator publishes an immutable released client/schema, Strix prerequisites settle, and this exact consumer reacquires required evidence. This is a COMMENT review only, not approval.
|
Live CodeQL authority correction after downloading the retained producer artifacts rather than relying on the earlier summary:
The previous claim that the Python SARIF referenced nonexistent PR body is now code-current with this classification. No #899 source mutation, rerun, scanner suppression, status synthesis, or descendant restack is justified. |
|
Canonical owner authority update (2026-09-22 KST): contextual-orchestrator #1209 has moved to exact |
seonghobae
left a comment
There was a problem hiding this comment.
Exact-head review for c10b6545520afb342e68d01ea4bcfce75a6e5bab: the move from c943060c... is an ordinary one-commit descendant with no file delta (ci: retrigger current protected workflows). It is accepted only as immutable live ancestry, not as a causal repair or validation receipt, and should not be repeated. All known affected descendants have been immediately converged by ordinary two-parent/non-force commits while preserving their child-owned deltas. Current-head Tests/Security/SAST/CodeQL must settle independently; this COMMENT is not approval or GREEN evidence.
Pull request was converted to draft
There was a problem hiding this comment.
Pull request overview
OpenCode reviewed the current-head product diff. Coverage is a separate gate.
Changed files
.env.example— repository behaviorAGENTS.md— repository behaviorCHANGELOG.d/2.29.0-contextual-orchestrator-owner-boundary.md— repository behaviorMakefile— repository behaviorREADME.md— repository behaviordocker-compose.yml— repository behaviordocker/contextual-orchestrator/Dockerfile— repository behaviordocker/contextual-orchestrator/agents.json— repository behaviordocker/contextual-orchestrator/start.py— Python module behaviordocs/adr/0300-contextual-orchestrator-owner-boundary.md— operator or user guidancedocs/context-map.md— operator or user guidancedocs/doctoring/ACTUAL_RUNTIME_EVIDENCE_2026-08-19_VISION.md— operator or user guidancedocs/ubiquitous-language.md— operator or user guidancescripts/backfill_post_keymen.py— Python module behaviorscripts/estimate_llm_channel_weights.py— Python module behaviortests/test_contextual_orchestrator_owner_boundary.py— regression suitetests/test_contextual_orchestrator_start.py— regression suitetests/test_ddd_architecture_fitness.py— regression suitetests/test_documentation_hygiene.py— regression suite
Changed behavior
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Repository file: .env.example"]
S1 --> I1["repository behavior"]
I1 --> R1["Review risk: Repository file: .env.example"]
R1 --> V1["required checks"]
Evidence --> S2["Repository file: AGENTS.md"]
S2 --> I2["repository behavior"]
I2 --> R2["Review risk: Repository file: AGENTS.md"]
R2 --> V2["required checks"]
Evidence --> S3["Repository file: 2.29.0-contextual-orchestrator-owner-boundary.md"]
S3 --> I3["repository behavior"]
I3 --> R3["Review risk: Repository file: 2.29.0-contextual-orchestrator-owner-boundary.md"]
R3 --> V3["required checks"]
Evidence --> S4["Repository file: Makefile"]
S4 --> I4["repository behavior"]
I4 --> R4["Review risk: Repository file: Makefile"]
R4 --> V4["required checks"]
Evidence --> S5["Repository file: README.md"]
S5 --> I5["repository behavior"]
I5 --> R5["Review risk: Repository file: README.md"]
R5 --> V5["required checks"]
Evidence --> S6["Repository file: docker-compose.yml"]
S6 --> I6["repository behavior"]
I6 --> R6["Review risk: Repository file: docker-compose.yml"]
R6 --> V6["required checks"]
Evidence --> S7["Repository file: Dockerfile"]
S7 --> I7["repository behavior"]
I7 --> R7["Review risk: Repository file: Dockerfile"]
R7 --> V7["required checks"]
Evidence --> S8["Repository file: agents.json"]
S8 --> I8["repository behavior"]
I8 --> R8["Review risk: Repository file: agents.json"]
R8 --> V8["required checks"]
Evidence --> S9["Python: start.py (3 files)"]
S9 --> I9["Python module behavior"]
I9 --> R9["Review risk: Python: start.py (3 files)"]
R9 --> V9["pytest plus coverage"]
Evidence --> S10["Docs: 0300-contextual-orchestrator-owner-boundary.md (4 files)"]
S10 --> I10["operator or user guidance"]
I10 --> R10["Review risk: Docs: 0300-contextual-orchestrator-owner-boundary.md (4 files)"]
R10 --> V10["docs review"]
Evidence --> S11["Test: test_contextual_orchestrator_owner_boundary.py (4 files)"]
S11 --> I11["regression suite"]
I11 --> R11["Review risk: Test: test_contextual_orchestrator_owner_boundary.py (4 files)"]
R11 --> V11["targeted test run"]
Findings
No source-backed product finding is synthesized from the coverage gate. A coverage miss belongs in the status comment.
- Head SHA:
c10b6545520afb342e68d01ea4bcfce75a6e5bab - Workflow run: 35764015549
- Workflow attempt: 1
- Coverage gate:
failure
Review outcome
Coverage is a gate, not the review. This body reviews the changed product files.
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Repository file: .env.example"]
S1 --> I1["repository behavior"]
I1 --> R1["Review risk: Repository file: .env.example"]
R1 --> V1["required checks"]
Evidence --> S2["Repository file: AGENTS.md"]
S2 --> I2["repository behavior"]
I2 --> R2["Review risk: Repository file: AGENTS.md"]
R2 --> V2["required checks"]
Evidence --> S3["Repository file: 2.29.0-contextual-orchestrator-owner-boundary.md"]
S3 --> I3["repository behavior"]
I3 --> R3["Review risk: Repository file: 2.29.0-contextual-orchestrator-owner-boundary.md"]
R3 --> V3["required checks"]
Evidence --> S4["Repository file: Makefile"]
S4 --> I4["repository behavior"]
I4 --> R4["Review risk: Repository file: Makefile"]
R4 --> V4["required checks"]
Evidence --> S5["Repository file: README.md"]
S5 --> I5["repository behavior"]
I5 --> R5["Review risk: Repository file: README.md"]
R5 --> V5["required checks"]
Evidence --> S6["Repository file: docker-compose.yml"]
S6 --> I6["repository behavior"]
I6 --> R6["Review risk: Repository file: docker-compose.yml"]
R6 --> V6["required checks"]
Evidence --> S7["Repository file: Dockerfile"]
S7 --> I7["repository behavior"]
I7 --> R7["Review risk: Repository file: Dockerfile"]
R7 --> V7["required checks"]
Evidence --> S8["Repository file: agents.json"]
S8 --> I8["repository behavior"]
I8 --> R8["Review risk: Repository file: agents.json"]
R8 --> V8["required checks"]
Evidence --> S9["Python: start.py (3 files)"]
S9 --> I9["Python module behavior"]
I9 --> R9["Review risk: Python: start.py (3 files)"]
R9 --> V9["pytest plus coverage"]
Evidence --> S10["Docs: 0300-contextual-orchestrator-owner-boundary.md (4 files)"]
S10 --> I10["operator or user guidance"]
I10 --> R10["Review risk: Docs: 0300-contextual-orchestrator-owner-boundary.md (4 files)"]
R10 --> V10["docs review"]
Evidence --> S11["Test: test_contextual_orchestrator_owner_boundary.py (4 files)"]
S11 --> I11["regression suite"]
I11 --> R11["Review risk: Test: test_contextual_orchestrator_owner_boundary.py (4 files)"]
R11 --> V11["targeted test run"]
OpenCode Review Overview
Coverage evidence did not pass, so approval is blocked. The formal pull-request review is the source-backed diff review, not this status comment. |
Pull request was converted to draft
Scope
Restore the DDD/source-of-truth boundary between LineageWeave and
ContextualWisdomLab/contextual-orchestrator. LineageWeave owns lineage/evidence/product policy and consumes only a released orchestrator contract; provider credentials/endpoints, model-agent bootstrap, discovery, routing, fallback and model-timeout semantics remain with contextual-orchestrator. ADR 0300 remains Proposed until protected integration and an immutable owner dependency exist.Current exact authority — 2026-09-23 KST
main@83eba56149eb802cd63642c507c324c9976ec78ec10b6545520afb342e68d01ea4bcfce75a6e5babc10b6545...remains the already-existing source-neutral descendant of priorc943060c...(ahead_by=1,behind_by=0, no file delta; commit messageci: retrigger current protected workflows). It is ancestry only, not repair or buyer evidence, and must not be repeated.Exact-head acceptance state
Repository-owned gates are terminal:
35736046028: SUCCESS;35736046088: SUCCESS;35736046090: SUCCESS;35736046141: terminal FAILURE at the canonical terminal-publication/reconciliation boundary.Required CodeQL has fully drained and is no longer an admission wait.
Detect CodeQL languages106773438981succeeded. Python106841178168, JavaScript/TypeScript106841178207, and Actions106841178992each received hosted runners, completedRead current-head CodeQL dispatch verdict, and failed atRelease runner or enforce current-head CodeQL verdict. The follow-on coordinator106874835246subsequently acquired hosted runner1002094193and completedDispatch current-head CodeQL scanSUCCESS on the same exact head. The already-terminal receiver failures did not reconcile after that successful dispatch, so the overall Required CodeQL run remains FAILURE.This reproduces the same unchanged-head ordering defect seen on #1039 and is recorded in canonical
.github#1929comment5783904376. Do not synthesize a required status, rerun leaves blindly, create another wake commit, or copy the central receiver/dispatch control plane into LineageWeave.Required CodeQL owner decomposition
The last fully executed producer findings remain causal history until canonical publication settles on an unchanged consumer head:
frontend/src/postBodyDisplay.tsremain owned by fix: verify dashboard accessibility and enforce frontend coverage #983 or a verified successor carrying that repair;py/insecure-protocolatlineageweave/http_client.py:193andpy/polynomial-redosatlineageweave/post_chat.py:48remain owned by fix(chat): preserve null timeouts and attribute worker expiry #974 or a verified successor carrying both repairs;.github#2276/#2275;.github#1929.Descendant convergence
The earlier source-neutral parent movement remains ordinary/non-force converged through every known affected open descendant: #1118
0dd0fd9a..., #966f8eff8b0..., #919fb19bd83..., #902414026bc..., #112073ab7ea..., #111772341358..., #1124c49aff39..., #915ba77b336.... No new #899 head movement occurred in this run.contextual-orchestrator owner boundary
The owner prerequisite has materially advanced. contextual-orchestrator #1209 is still Draft at exact
33c14c4b05a6fff6c11800b60184d2bdd3eb01db, an ordinary ahead-only descendant of the two RED carriers. The production candidate moves prompt-only embedding outside_psychometric_persistence_lock, then re-resolves the served deployment under the lock and drops the observation when the deployment disappeared or its psychometric candidate identity changed. This directly addresses both established RED contracts without weakening them.The owner commit reports focused local GREEN, but exact-head hosted Security/SAST/CodeQL, qualifying current-head approval, protected integration, and immutable release remain outstanding unless separately proven by current live evidence. LineageWeave must not treat the mutable owner branch as a consumable dependency.
Therefore
lineageweave/adjudication_client.pymust continue to avoid mutable-owner pins, vendored compatibility clients, copied raw chat-completions policy, or local continuation of the fixed default timeout. Correct order is owner exact-head hosted GREEN/review -> protected integration -> immutable API/client/schema release with CHANGELOG/SBOM/provenance/reproducibility/rollback -> thin LineageWeave consumer bump -> fresh downstream acceptance.No provider/model source duplication, central-CI source copy, force push, destructive rebase, self-approval, review dismissal, gate weakening, scanner suppression, synthetic status, blind rerun, new source-neutral wake commit, mutable-owner pin, merge, or release is authorized.