Skip to content

docs: align buyer README with read-only handoff - #73

Draft
seonghobae wants to merge 14 commits into
security/remove-autonomous-write-publisherfrom
docs/readonly-handoff-readme
Draft

docs: align buyer README with read-only handoff#73
seonghobae wants to merge 14 commits into
security/remove-autonomous-write-publisherfrom
docs/readonly-handoff-readme

Conversation

@seonghobae

@seonghobae seonghobae commented Aug 6, 2026

Copy link
Copy Markdown
Contributor

Test-first buyer trust-boundary repair

Progresses #72 and #81 as a documentation/test stack behind replacement PR #84. Closed #66 and all predecessor-head checks/reviews remain historical context only; no review, approval, status, or check transfers across PR objects or changed heads.

Exact live stack state

Preserved test-first history

The branch retains the earlier README, architecture, and accepted-ADR RED→GREEN history that removes the stale repository-local publisher description and states that repository-local product development ends at the independently reverified credential-free patch handoff.

Latest bounded RED→GREEN pair:

  • RED 2afb7eb749b963ed5e0c58d8804cdeefe28385e2 strengthens the buyer README contract to require the sentence-starting Model web/network tools are denied, a conventional final LF, and the hourly-workflow printf literal-\n incident regression.
  • GREEN 1385280f74b05b38cb955276636c495563b0e605 changes only README.md: it capitalizes that sentence-starting Model and restores exactly one final LF. The commit diff contains no other path or wording change.

The incident regression itself depends on the later #84 workflow commits and must not be treated as exact-head green on this divergent branch. No current-head workflow run exists for 1385280f74b05b38cb955276636c495563b0e605; draft-skipped or predecessor-head evidence is not acceptance.

Bounded product/documentation contract

This slice:

  • removes stale repository-local third-publisher claims from the public README, architecture, and accepted modular-integration ADR;
  • distinguishes denied model web/network tools from restricted runner egress to reviewed package sources, GitHub, and NVIDIA NIM;
  • preserves the separately governed organization-owned PR-maintenance/review workflow and its credential contract;
  • states that the product workflow creates no branch, pull request, repository write, or auto-merge request;
  • requires any future promotion to remain external, independently reviewed, credential-separated, and exact-tree verified before repository write;
  • updates [Unreleased] without a version bump;
  • does not intentionally change product code, dependencies, credentials, permissions, release authority, network policy, model choice, or reviewer identity.

Remaining gates

Keep this PR Draft. First integrate #84 through its own exact-head central security/review/approval gates. Then reconstruct or otherwise audibly reconcile this documentation slice against the accepted protected head without force-push/rebase shortcuts, rerun exact integrated-tree CI and the repaired organization Security Scan, complete current-head automated review, obtain a qualifying independent non-author APPROVED review, resolve only valid addressed threads, and satisfy branch protection and repository rules before integration.

Do not merge, enable auto-merge, release, publish, force-update, or count queued, skipped, stale, predecessor-head, synthetic-merge, fail-open, or absent evidence as success.

@coderabbitai

coderabbitai Bot commented Aug 6, 2026

Copy link
Copy Markdown

Important

Review skipped

Draft detected.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: d1ddd8e1-296a-4c88-992c-b0c04be1032b

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

Copy link
Copy Markdown
Contributor Author

@opencode-agent Apply only the bounded changelog completion to exact current head 5d1599a401746e0ed88f920003995cb8f97ee354 on branch docs/readonly-handoff-readme. Stop without writing if that is no longer the exact head.

Modify only CHANGELOG.md.

Under [Unreleased]Fixed, add one concise buyer-facing entry stating that the public README now matches the credential-free product scheduler boundary: the repository-local third publisher claim is removed, the product workflow ends at the independently reverified exact-base/digest-bound handoff, and any future promotion is external, independently reviewed, credential-separated, and must reconstruct and verify the exact tree before repository write.

Do not change the version. Do not modify README, tests, .github, workflows, scripts, product code, dependencies, credentials, permissions, protected refs, release behavior, model configuration, or review-agent identities. Do not rebase, retarget, merge, mark ready, enable auto-merge, release, or publish. Preserve the existing changelog structure and wording outside this single entry.

Copy link
Copy Markdown
Contributor Author

@opencode-agent Supersede the immediately preceding changelog-only request. On exact current head 5d1599a401746e0ed88f920003995cb8f97ee354 of docs/readonly-handoff-readme, apply only these two completion edits; stop without writing if the head changed.

  1. CHANGELOG.md: under [Unreleased]Fixed, add one concise buyer-facing entry stating that the public README now matches the credential-free product scheduler boundary: the stale repository-local third-publisher claim is removed, the workflow ends at the independently reverified exact-base/digest-bound handoff, and any future promotion is external, independently reviewed, credential-separated, and must reconstruct and verify the exact tree before repository write.
  2. README.md: preserve all current bytes and wording except restore the conventional final newline at EOF. Do not otherwise rewrite the already-completed trust-boundary paragraph.

Do not change the version. Do not modify tests, .github, workflows, scripts, product code, dependencies, credentials, permissions, protected refs, release behavior, model configuration, or review-agent identities. Do not rebase, retarget, merge, mark ready, enable auto-merge, release, or publish.

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

Review only exact current head 17f226211be1a6b810f3715b2c3a4686b9a5b67d against exact stacked base c038a9509d1a8eae8561cc9081e67e12bd373d42. Treat the earlier draft-skip output and all requests on prior heads as stale. This is a documentation/test contract only: verify the README now accurately matches #66's credential-free product handoff, the new regression would fail on the immutable RED head and pass on this exact GREEN tree, [Unreleased] is accurate, no historical release claim is rewritten, no .github/workflow/credential/product/release surface changed, and no unsupported CI/approval claim is made. Do not approve, merge, mark ready, rebase, retarget, publish, or infer success from absent/queued checks.

Copy link
Copy Markdown
Contributor Author

@opencode-agent Perform a read-only exact-head review of PR #73 at 17f226211be1a6b810f3715b2c3a4686b9a5b67d against stacked base c038a9509d1a8eae8561cc9081e67e12bd373d42. Do not modify any file, branch, ref, PR metadata, or workflow.

Verify that the immutable RED commit 233db635419ee21ec80a3409629ff6d767ebd9eb adds a contract that fails on the stale README, and that the exact GREEN head changes only README.md, CHANGELOG.md, and the contract test; accurately describes the two-runner credential-free handoff implemented by #66; forbids repository-local branch/PR/write/auto-merge publication in buyer-facing wording; preserves historical release notes; updates [Unreleased]; and introduces no workflow, credential, permission, product-code, dependency, release, version, or review-agent change. Also inspect formatting and test readability. Anchor every finding to this exact head. Do not claim hosted CI, approve, merge, rebase, retarget, mark ready, release, or publish.

@coderabbitai

coderabbitai Bot commented Aug 6, 2026

Copy link
Copy Markdown
🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

base="c038a9509d1a8eae8561cc9081e67e12bd373d42"
red="233db635419ee21ec80a3409629ff6d767ebd9eb"
green="17f226211be1a6b810f3715b2c3a4686b9a5b67d"

printf '%s\n' '== Checked-out commit and requested objects =='
git rev-parse HEAD
git cat-file -t "$base"
git cat-file -t "$red"
git cat-file -t "$green"
git show -s --format='commit=%H%nparents=%P%nsubject=%s' "$base" "$red" "$green"

printf '%s\n' '== Ancestry checks =='
git merge-base --is-ancestor "$base" "$red" && echo "base is ancestor of RED"
git merge-base --is-ancestor "$red" "$green" && echo "RED is ancestor of GREEN"

printf '%s\n' '== Changed paths and stats: base..GREEN =='
git diff --stat "$base" "$green"
git diff --name-status "$base" "$green"

printf '%s\n' '== Changed paths and stats: base..RED =='
git diff --stat "$base" "$red"
git diff --name-status "$base" "$red"

printf '%s\n' '== Changed paths and stats: RED..GREEN =='
git diff --stat "$red" "$green"
git diff --name-status "$red" "$green"

printf '%s\n' '== Full text diff: base..GREEN =='
git diff --no-ext-diff --unified=80 "$base" "$green" -- README.md CHANGELOG.md

printf '%s\n' '== Full text diff: base..RED =='
git diff --no-ext-diff --unified=80 "$base" "$red" -- README.md CHANGELOG.md

printf '%s\n' '== Full text diff: RED..GREEN =='
git diff --no-ext-diff --unified=80 "$red" "$green" -- README.md CHANGELOG.md

printf '%s\n' '== Candidate regression test files in base..GREEN =='
git diff --name-only "$base" "$green" | while IFS= read -r f; do
  case "$f" in
    *test*|*spec*) printf '%s\n' "$f" ;;
  esac
done

printf '%s\n' '== README assertions at each revision =='
for rev in "$base" "$red" "$green"; do
  echo "-- $rev --"
  git show "$rev:README.md" | rg -n -i -C 2 \
    'third.publisher|credential.free|credential-free|handoff|promotion|reconstruct|repository write|auto-merge|pull request|branch' \
    || true
done

printf '%s\n' '== Changelog release headings at base and GREEN =='
for rev in "$base" "$green"; do
  echo "-- $rev --"
  git show "$rev:CHANGELOG.md" | rg -n -C 2 '^\[Unreleased\]|^## \[|^### Fixed' || true
done

printf '%s\n' '== PR metadata and check status =='
gh pr view 73 --repo ContextualWisdomLab/EgressWeave \
  --json number,state,isDraft,headRefName,headRefOid,baseRefName,baseRefOid,mergeStateStatus,statusCheckRollup \
  --jq '{number,state,isDraft,headRefName,headRefOid,baseRefName,baseRefOid,mergeStateStatus,statusCheckRollup}'

Length of output: 45697


🏁 Script executed:

#!/bin/bash
set -euo pipefail

base="c038a9509d1a8eae8561cc9081e67e12bd373d42"
red="233db635419ee21ec80a3409629ff6d767ebd9eb"
green="17f226211be1a6b810f3715b2c3a4686b9a5b67d"
test_path="tests/test_hourly_opencode_nvidia_contract.py"
doc_path="docs/hourly-autonomous-maintenance.md"

printf '%s\n' '== Regression test diff and full source =='
git diff --no-ext-diff --unified=100 "$base" "$green" -- "$test_path"
for rev in "$red" "$green"; do
  echo "-- $rev:$test_path --"
  git show "$rev:$test_path" | cat -n
done

printf '%s\n' '== Test function map =='
ast-grep outline "$test_path" --items all --type function --view expanded

printf '%s\n' '== Base handoff contract excerpts =='
git show "$base:$doc_path" | rg -n -i -C 4 \
  'credential.free|credential-free|handoff|exact.base|exact base|digest|repository write|auto.merge|auto-merge|publisher|promotion|reconstruct|verify' \
  || true

printf '%s\n' '== Exact test-string evidence in README revisions =='
for rev in "$red" "$green"; do
  echo "-- $rev --"
  git show "$rev:README.md" | rg -n -F \
    -e 'The product workflow uses two fresh runners.' \
    -e 'The product workflow ends at the independently reverified credential-free patch handoff' \
    -e 'does not create branches, pull requests, repository writes, or auto-merge requests.' \
    -e 'Any future external, independently reviewed, credential-separated promotion must reconstruct' \
    -e 'and verify the exact tree before any repository write.' \
    -e 'The product workflow uses three fresh runners.' \
    -e 'A third publisher rechecks the sealed patch' \
    || true
done

printf '%s\n' '== README final-byte state =='
for rev in "$base" "$red" "$green"; do
  printf '%s ' "$rev"
  if git show "$rev:README.md" | tail -c 1 | od -An -t x1 | rg -q '0a'; then
    echo 'ends with LF'
  else
    echo 'does not end with LF'
  fi
done

printf '%s\n' '== Changelog changes, excluding Unreleased section context =='
git diff --no-ext-diff --unified=3 "$base" "$green" -- CHANGELOG.md
printf '%s\n' '== Non-doc/test changed paths classified =='
git diff --name-only "$base" "$green" | awk '
  $0 == "README.md" || $0 == "CHANGELOG.md" || $0 == "tests/test_hourly_opencode_nvidia_contract.py" { next }
  { print }
'

Length of output: 38009


🏁 Script executed:

#!/bin/bash
set -euo pipefail

base="c038a9509d1a8eae8561cc9081e67e12bd373d42"
red="233db635419ee21ec80a3409629ff6d767ebd9eb"
green="17f226211be1a6b810f3715b2c3a4686b9a5b67d"

normalize_readme() {
  git show "$1:README.md" | tr -s '[:space:]' ' '
}

printf '%s\n' '== Regression conditions after the test whitespace normalization =='
for rev in "$red" "$green"; do
  normalized="$(normalize_readme "$rev")"
  echo "-- $rev --"
  for condition in \
    'A third publisher' \
    'ends at the independently reverified credential-free patch handoff' \
    'does not create branches, pull requests, repository writes, or auto-merge requests' \
    'external, independently reviewed, credential-separated promotion' \
    'reconstruct and verify the exact tree before any repository write'
  do
    if printf '%s' "$normalized" | grep -Fq -- "$condition"; then
      printf 'present: %s\n' "$condition"
    else
      printf 'absent: %s\n' "$condition"
    fi
  done
done

printf '%s\n' '== README final byte, Base64 encoded =='
for rev in "$base" "$red" "$green"; do
  printf '%s: ' "$rev"
  git show "$rev:README.md" | tail -c 1 | base64 | tr -d '\n'
  printf '\n'
done

printf '%s\n' '== Whitespace error check for exact review range =='
git diff --check "$base" "$green"

printf '%s\n' '== Commit-level changed paths =='
git diff-tree --no-commit-id --name-status -r "$red"
git diff-tree --no-commit-id --name-status -r "$green"

Length of output: 2737


@seonghobae No findings from this scoped review.

I reviewed exact head 17f226211be1a6b810f3715b2c3a4686b9a5b67d against exact base c038a9509d1a8eae8561cc9081e67e12bd373d42.

  • The PR head and base OIDs match the requested commits.
  • The changed paths are limited to README.md, CHANGELOG.md, and tests/test_hourly_opencode_nvidia_contract.py.
  • The README removes the repository-local third-publisher claim.
  • The README states that the product workflow ends at the independently reverified credential-free handoff.
  • The README states that the workflow does not create branches, pull requests, repository writes, or auto-merge requests.
  • The README requires external, independently reviewed, credential-separated promotion to reconstruct and verify the exact tree before a repository write.
  • The README statements match the exact-base SHA and patch SHA-256 handoff contract in docs/hourly-autonomous-maintenance.md.
  • The new regression conditions fail on immutable RED 233db635419ee21ec80a3409629ff6d767ebd9eb and hold on this GREEN tree.
  • The changelog adds one entry under [Unreleased]Fixed. Historical release sections are unchanged.
  • No .github, workflow, credential, product, model, or release surface changed.
  • git diff --check reported no whitespace errors. README.md ends with an LF.
  • PR #73 remains draft. I did not approve, merge, or change PR state.
  • GitHub reports only a CodeRabbit status. I do not treat that status as required CI-gate success.
⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

Review only exact current head b58d1fd234b9224881e97c340d9eb18a03ff5cd5 against exact stacked base c038a9509d1a8eae8561cc9081e67e12bd373d42. Treat every draft-skip, rate-limit result, and review request anchored to earlier heads as stale. Verify only the three-file stack (README.md, CHANGELOG.md, tests/test_hourly_opencode_nvidia_contract.py): both immutable RED contracts are meaningful; buyer wording matches #66's two-runner credential-free handoff and its restricted runner-egress/model-web-tool boundary; historical release notes remain unchanged; [Unreleased] is accurate; and there is no .github, workflow, credential, permission, product-code, dependency, version, release, or review-agent change. Do not infer CI success from absent checks, approve, merge, mark ready, rebase, retarget, release, or publish.

Copy link
Copy Markdown
Contributor Author

@opencode-agent Perform a read-only exact-head review of PR #73 at b58d1fd234b9224881e97c340d9eb18a03ff5cd5 against stacked base c038a9509d1a8eae8561cc9081e67e12bd373d42. Do not modify any file, branch, ref, PR metadata, or workflow.

Verify both immutable test-first boundaries: 233db635419ee21ec80a3409629ff6d767ebd9eb must fail on the stale third-publisher README claim, and e1a4557fd42c16cad5469ecd2a362cf10c438854 must fail on the inaccurate no direct network access claim. The exact GREEN tree must change only README, CHANGELOG, and the contract test; accurately describe two runners, denied model web/network tools, restricted runner egress to reviewed package sources/GitHub/NVIDIA NIM, credential-free handoff, and external independently reviewed credential-separated exact-tree promotion; preserve historical release notes; and introduce no workflow, credential, permission, product-code, dependency, version, release, or review-agent change. Anchor findings only to this exact head. Do not claim hosted CI, approve, merge, rebase, retarget, mark ready, release, or publish.

@coderabbitai

coderabbitai Bot commented Aug 6, 2026

Copy link
Copy Markdown

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

base="c038a9509d1a8eae8561cc9081e67e12bd373d42"
red_publication="233db635419ee21ec80a3409629ff6d767ebd9eb"
red_egress="e1a4557fd42c16cad5469ecd2a362cf10c438854"
green="b58d1fd234b9224881e97c340d9eb18a03ff5cd5"
test_path="tests/test_hourly_opencode_nvidia_contract.py"
operator_path="docs/hourly-autonomous-maintenance.md"

printf '%s\n' '== Exact objects and ancestry =='
printf 'checked_out_head='
git rev-parse HEAD
for rev in "$base" "$red_publication" "$red_egress" "$green"; do
  git cat-file -e "${rev}^{commit}"
  git show -s --format='commit=%H%nparents=%P%nsubject=%s' "$rev"
done
git merge-base --is-ancestor "$base" "$red_publication" && echo 'base -> publication RED: yes'
git merge-base --is-ancestor "$red_publication" "$red_egress" && echo 'publication RED -> egress RED: yes'
git merge-base --is-ancestor "$red_egress" "$green" && echo 'egress RED -> GREEN: yes'

printf '%s\n' '== Changed paths and whitespace: base..GREEN =='
git diff --name-status "$base" "$green"
git diff --stat "$base" "$green"
git diff --check "$base" "$green"

printf '%s\n' '== Commit-level changed paths =='
for rev in "$red_publication" "$red_egress" "$green"; do
  printf '\n-- %s --\n' "$rev"
  git diff-tree --no-commit-id --name-status -r "$rev"
done

printf '%s\n' '== Three-file diff: base..GREEN =='
git diff --no-ext-diff --unified=80 "$base" "$green" -- \
  README.md CHANGELOG.md "$test_path"

printf '%s\n' '== README and changelog diffs at each RED boundary =='
for range in "$base $red_publication" "$red_publication $red_egress" "$red_egress $green"; do
  set -- $range
  printf '\n-- %s..%s --\n' "$1" "$2"
  git diff --no-ext-diff --unified=40 "$1" "$2" -- README.md CHANGELOG.md
done

printf '%s\n' '== Contract test source at RED and GREEN revisions =='
for rev in "$red_publication" "$red_egress" "$green"; do
  printf '\n-- %s:%s --\n' "$rev" "$test_path"
  git show "$rev:$test_path" | cat -n
done

printf '%s\n' '== Buyer wording at publication RED, egress RED, and GREEN =='
for rev in "$red_publication" "$red_egress" "$green"; do
  printf '\n-- %s:README.md --\n' "$rev"
  git show "$rev:README.md" | rg -n -i -C 3 \
    'two fresh runners|three fresh runners|third publisher|credential-free|handoff|exact-base|digest-bound|network|web tools|model|NVIDIA NIM|GitHub|package sources|promotion|repository write|auto-merge|pull requests|branches' || true
done

printf '%s\n' '== Operator contract evidence at stacked base =='
git show "$base:$operator_path" | rg -n -i -C 4 \
  'two fresh runners|credential-free|exact.base|digest|handoff|network|web tools|package sources|GitHub|NVIDIA NIM|repository write|auto-merge|pull request|branch|promotion|reconstruct|verify' || true

printf '%s\n' '== Changelog headings and changed Unreleased section =='
for rev in "$base" "$green"; do
  printf '\n-- %s:CHANGELOG.md headings --\n' "$rev"
  git show "$rev:CHANGELOG.md" | rg -n -C 2 '^\[Unreleased\]|^## \[|^### Fixed' || true
done

printf '%s\n' '== README EOF byte =='
for rev in "$base" "$green"; do
  printf '%s: ' "$rev"
  git show "$rev:README.md" | tail -c 1 | od -An -t x1
done

printf '%s\n' '== PR metadata (informational only) =='
gh pr view 73 --repo ContextualWisdomLab/EgressWeave \
  --json number,state,isDraft,headRefName,headRefOid,baseRefName,baseRefOid,statusCheckRollup \
  --jq '{number,state,isDraft,headRefName,headRefOid,baseRefName,baseRefOid,statusCheckRollup}'

Length of output: 98641


🏁 Script executed:

#!/bin/bash
set -euo pipefail

base="c038a9509d1a8eae8561cc9081e67e12bd373d42"
red_publication="233db635419ee21ec80a3409629ff6d767ebd9eb"
red_egress="e1a4557fd42c16cad5469ecd2a362cf10c438854"
green="b58d1fd234b9224881e97c340d9eb18a03ff5cd5"

normalized_readme() {
  git show "$1:README.md" | tr '\n\t' '  ' | tr -s ' '
}

check_phrase() {
  rev="$1"
  phrase="$2"
  expected="$3"
  content="$(normalized_readme "$rev")"
  if printf '%s' "$content" | grep -Fq -- "$phrase"; then
    actual="present"
  else
    actual="absent"
  fi
  printf '%s | expected=%s | actual=%s | %s\n' "$phrase" "$expected" "$actual" "$rev"
  [ "$actual" = "$expected" ]
}

printf '%s\n' '== Publication-boundary RED-to-GREEN text conditions =='
check_phrase "$red_publication" "A third publisher" "present"
check_phrase "$red_publication" "ends at the independently reverified credential-free patch handoff" "absent"
check_phrase "$red_publication" "does not create branches, pull requests, repository writes, or auto-merge requests" "absent"
check_phrase "$red_publication" "external, independently reviewed, credential-separated promotion" "absent"
check_phrase "$red_publication" "reconstruct and verify the exact tree before any repository write" "absent"
check_phrase "$green" "A third publisher" "absent"
check_phrase "$green" "ends at the independently reverified credential-free patch handoff" "present"
check_phrase "$green" "does not create branches, pull requests, repository writes, or auto-merge requests" "present"
check_phrase "$green" "external, independently reviewed, credential-separated promotion" "present"
check_phrase "$green" "reconstruct and verify the exact tree before any repository write" "present"

printf '%s\n' '== Egress-boundary RED-to-GREEN text conditions =='
check_phrase "$red_egress" "no direct network access" "present"
check_phrase "$red_egress" "runner egress is restricted" "absent"
check_phrase "$red_egress" "model web/network tools are denied" "absent"
check_phrase "$red_egress" "NVIDIA NIM endpoint" "absent"
check_phrase "$green" "no direct network access" "absent"
check_phrase "$green" "runner egress is restricted" "present"
check_phrase "$green" "model web/network tools are denied" "present"
check_phrase "$green" "NVIDIA NIM endpoint" "present"

printf '%s\n' '== Historical changelog content: base vs GREEN =='
historical_base="$(git show "$base:CHANGELOG.md" | sed -n '/^## \[0\.3\.0\]/,$p' | sha256sum | awk '{print $1}')"
historical_green="$(git show "$green:CHANGELOG.md" | sed -n '/^## \[0\.3\.0\]/,$p' | sha256sum | awk '{print $1}')"
printf 'base_sha256=%s\ngreen_sha256=%s\n' "$historical_base" "$historical_green"
[ "$historical_base" = "$historical_green" ]
git diff --no-ext-diff --exit-code "$base" "$green" -- \
  ':(literal)CHANGELOG.md' \
  --word-diff=porcelain >/dev/null || true
git diff --no-ext-diff --unified=0 "$base" "$green" -- CHANGELOG.md | sed -n '1,40p'

printf '%s\n' '== README final newline =='
for rev in "$base" "$green"; do
  if git show "$rev:README.md" | tail -c 1 | grep -qx ''; then
    printf '%s ends with LF\n' "$rev"
  else
    printf '%s does not end with LF\n' "$rev"
  fi
done

printf '%s\n' '== PR metadata, informational only =='
gh pr view 73 --repo ContextualWisdomLab/EgressWeave \
  --json number,state,isDraft,headRefName,headRefOid,baseRefName,baseRefOid,statusCheckRollup \
  --jq '{number,state,isDraft,headRefName,headRefOid,baseRefName,baseRefOid,statusCheckRollup}'

Length of output: 5989


@seonghobae I found one issue on exact head b58d1fd234b9224881e97c340d9eb18a03ff5cd5.

  • tests/test_hourly_opencode_nvidia_contract.py Line 205 requires the case-sensitive text "model web/network tools are denied".
  • README.md Line 334 contains "Model web/network tools are denied".

Python substring checks are case-sensitive. Therefore, test_buyer_readme_describes_restricted_model_egress fails on this GREEN head. Use the same capitalization in the assertion and the README.

You are interacting with an AI system.

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

Review only exact current head 9db7143d68c78a804fd653f48525332935bb28fd against exact stacked base c038a9509d1a8eae8561cc9081e67e12bd373d42. The prior review request on 17f226211be1a6b810f3715b2c3a4686b9a5b67d is stale. Verify the complete buyer-facing documentation/test contract: README and ARCHITECTURE must match #66's repository-local credential-free exact-base/digest-bound handoff; no third publisher or local product-publication runner may remain implied; future promotion must be external, independently reviewed, credential-separated and reconstruct/verify the exact tree before repository write; model tools remain network-denied while runner egress is accurately described; the regression tests and [Unreleased] entries are truthful; and no .github, workflow, credential, product-code, dependency, release, ref, signing, or publication surface changed in this stacked PR. Treat missing exact-head hosted checks as missing. Keep Draft and do not approve, merge, mark Ready, rebase, retarget, release, publish, or modify the branch.

@coderabbitai

coderabbitai Bot commented Aug 6, 2026

Copy link
Copy Markdown
🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

base="c038a9509d1a8eae8561cc9081e67e12bd373d42"
red_publication="233db635419ee21ec80a3409629ff6d767ebd9eb"
red_egress="e1a4557fd42c16cad5469ecd2a362cf10c438854"
red_architecture="cb1e9d9f19b118769eee64cf1a4b52a0c39c4b4b"
green="9db7143d68c78a804fd653f48525332935bb28fd"
test_path="tests/test_hourly_opencode_nvidia_contract.py"
operator_path="docs/hourly-autonomous-maintenance.md"

echo '== Exact revisions =='
printf 'checked_out_head='
git rev-parse HEAD
for rev in "$base" "$red_publication" "$red_egress" "$red_architecture" "$green"; do
  git cat-file -e "${rev}^{commit}"
  git show -s --format='commit=%H%nparents=%P%nsubject=%s' "$rev"
done

echo '== Ancestry =='
git merge-base --is-ancestor "$base" "$red_publication" && echo 'base -> publication RED: yes'
git merge-base --is-ancestor "$red_publication" "$red_egress" && echo 'publication RED -> egress RED: yes'
git merge-base --is-ancestor "$red_egress" "$red_architecture" && echo 'egress RED -> architecture RED: yes'
git merge-base --is-ancestor "$red_architecture" "$green" && echo 'architecture RED -> GREEN: yes'

echo '== Changed paths and whitespace: base..GREEN =='
git diff --name-status "$base" "$green"
git diff --stat "$base" "$green"
git diff --check "$base" "$green"

echo '== Per-commit changed paths =='
for rev in "$red_publication" "$red_egress" "$red_architecture" "$green"; do
  echo "-- $rev --"
  git diff-tree --no-commit-id --name-status -r "$rev"
done

echo '== Full scoped diff: base..GREEN =='
git diff --no-ext-diff --unified=100 "$base" "$green" -- \
  README.md ARCHITECTURE.md CHANGELOG.md "$test_path"

echo '== RED-to-GREEN document diffs =='
for range in \
  "$base $red_publication" \
  "$red_publication $red_egress" \
  "$red_egress $red_architecture" \
  "$red_architecture $green"
do
  set -- $range
  echo "-- $1..$2 --"
  git diff --no-ext-diff --unified=70 "$1" "$2" -- README.md ARCHITECTURE.md CHANGELOG.md "$test_path"
done

echo '== Full regression contract at RED and GREEN revisions =='
for rev in "$red_publication" "$red_egress" "$red_architecture" "$green"; do
  echo "-- $rev:$test_path --"
  git show "$rev:$test_path" | cat -n
done

echo '== Regression-test function map =='
ast-grep outline "$test_path" --items all --type function --view expanded

echo '== Buyer-facing contract wording at each boundary =='
for rev in "$red_publication" "$red_egress" "$red_architecture" "$green"; do
  echo "-- $rev --"
  for path in README.md ARCHITECTURE.md; do
    echo "  :: $path"
    git show "$rev:$path" | rg -n -i -C 3 \
      'two fresh runners|three fresh runners|third publisher|product.*publication|publication.*runner|credential-free|exact-base|exact base|digest-bound|handoff|network|web tools|runner egress|package sources|GitHub|NVIDIA NIM|promotion|repository write|auto-merge|pull requests|branches|reconstruct|verify' \
      || true
  done
done

echo '== Operator contract at stacked base =='
git show "$base:$operator_path" | rg -n -i -C 4 \
  'two fresh runners|credential-free|exact.base|exact base|digest|handoff|network|web tools|package sources|GitHub|NVIDIA NIM|repository write|auto-merge|pull request|branch|promotion|reconstruct|verify' \
  || true

echo '== Unreleased and historical changelog comparison =='
for rev in "$base" "$green"; do
  echo "-- $rev headings --"
  git show "$rev:CHANGELOG.md" | rg -n -C 3 '^\[Unreleased\]|^## \[|^### Fixed' || true
done
base_historical="$(git show "$base:CHANGELOG.md" | sed -n '/^## \[0\.3\.0\]/,$p' | sha256sum | awk '{print $1}')"
green_historical="$(git show "$green:CHANGELOG.md" | sed -n '/^## \[0\.3\.0\]/,$p' | sha256sum | awk '{print $1}')"
printf 'historical_base_sha256=%s\nhistorical_green_sha256=%s\n' "$base_historical" "$green_historical"

echo '== Exact test phrase checks =='
normalize() {
  git show "$1:$2" | tr '\n\t' '  ' | tr -s ' '
}
assert_phrase() {
  rev="$1"; path="$2"; expected="$3"; phrase="$4"
  if normalize "$rev" "$path" | grep -Fq -- "$phrase"; then actual=present; else actual=absent; fi
  printf '%s | %s | expected=%s | actual=%s\n' "$rev" "$path" "$expected" "$actual"
}
assert_phrase "$red_publication" README.md present 'A third publisher'
assert_phrase "$green" README.md absent 'A third publisher'
assert_phrase "$red_egress" README.md present 'no direct network access'
assert_phrase "$green" README.md absent 'no direct network access'
assert_phrase "$green" README.md present 'Model web/network tools are denied'
assert_phrase "$green" README.md present 'runner egress is restricted'
assert_phrase "$green" README.md present 'NVIDIA NIM endpoint'
assert_phrase "$red_architecture" ARCHITECTURE.md present 'publication'
assert_phrase "$green" ARCHITECTURE.md present 'credential-free'
assert_phrase "$green" ARCHITECTURE.md present 'does not create branches, pull requests, repository writes, or auto-merge requests'
assert_phrase "$green" ARCHITECTURE.md present 'reconstruct and verify the exact tree before any repository write'

echo '== PR metadata and exact-head checks, informational only =='
gh pr view 73 --repo ContextualWisdomLab/EgressWeave \
  --json number,state,isDraft,headRefName,headRefOid,baseRefName,baseRefOid,mergeStateStatus,statusCheckRollup \
  --jq '{number,state,isDraft,headRefName,headRefOid,baseRefName,baseRefOid,mergeStateStatus,statusCheckRollup}'

Length of output: 178321


@seonghobae I found one issue on exact head 9db7143d68c78a804fd653f48525332935bb28fd.

  • tests/test_hourly_opencode_nvidia_contract.py Line 206 requires the lowercase string "model web/network tools are denied".
  • README.md uses "Model web/network tools are denied".

Python string membership checks are case-sensitive. Therefore, test_buyer_readme_describes_restricted_model_egress fails on this exact head. Use the same capitalization in the test and the README.

The remaining scoped review results are consistent with the requested contract:

  • The exact head and stacked base match the requested OIDs.
  • The changed paths are limited to README.md, ARCHITECTURE.md, CHANGELOG.md, and tests/test_hourly_opencode_nvidia_contract.py.
  • The immutable publication, egress, and architecture RED contracts are meaningful by static inspection.
  • The README and ARCHITECTURE.md remove the local third-publisher and local product-publication claims.
  • The documents state the two-runner handoff, denied model web/network tools, restricted runner egress, credential-free handoff, and external credential-separated exact-tree promotion boundary.
  • [Unreleased] contains the buyer-facing README correction. Historical release sections are unchanged.
  • No workflow, credential, permission, product-code, dependency, version, release, ref, signing, or publication surface changed.
  • git diff --check reported no whitespace errors.
  • PR #73 remains draft.

GitHub reports only a successful CodeRabbit status for this exact head. Required hosted CI and security evidence is missing. I do not treat that status as acceptance evidence. I did not approve, merge, or modify the PR.

⚠️ Action not completed

Review rate limited.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

Copy link
Copy Markdown
Contributor Author

@opencode-agent Progress #81 only if the live PR #73 head is still exactly 9db7143d68c78a804fd653f48525332935bb28fd; stop without writing if it differs. Keep this PR draft and preserve its stack on exact #66 head c038a9509d1a8eae8561cc9081e67e12bd373d42.

Adjacent buyer-facing inspection found one stale accepted-ADR claim that #73 does not yet cover: docs/adr/0001-security-boundaries-and-modular-integration.md still says the credential-free product-development lane re-verifies a patch before a publishing identity creates a normal pull request. That contradicts #66/#73's implemented boundary, where repository-local product development ends at the independently reverified credential-free handoff and has no branch/PR/repository-write/auto-merge publisher.

Use two auditable commits in order:

  1. Immutable RED, test-only. Modify only tests/test_hourly_opencode_nvidia_contract.py. Add a focused contract that reads ADR 0001 and fails on the current stale publisher sentence while requiring the same external, independently reviewed, credential-separated exact-tree promotion boundary already enforced for README/ARCHITECTURE. Do not weaken or rewrite existing docs: align buyer README with read-only handoff #73 tests.
  2. GREEN documentation repair. Modify only docs/adr/0001-security-boundaries-and-modular-integration.md and, if needed for truthful consolidated buyer documentation, extend the existing docs: align buyer README with read-only handoff #73 [Unreleased] CHANGELOG.md entry rather than adding a contradictory duplicate. State that repository-local product development ends at the independently reverified credential-free patch handoff; it creates no branch, PR, repository write, or auto-merge request; any future repository promotion is external, independently reviewed, credential-separated, and reconstructs/verifies the exact tree before repository write. Preserve the separate organization-owned PR-maintenance/review workflow and existing review-agent credential contract.

Do not modify .github, workflows, credentials, permissions, dependencies, product code, protected refs, release/tag/publication behavior, model/review identities, README, ARCHITECTURE, or any other path. Do not rebase, retarget, force-update, merge, mark Ready, auto-merge, publish, or release.

After GREEN, run the focused documentation contract plus the complete repository contract available on this stacked branch. Report RED SHA, GREEN/current SHA, exact changed paths, and validation evidence in this PR conversation. Missing or draft-skipped hosted checks are not success; the final stack still requires auditable credential-separated reconstruction after #66 integrates.

Copy link
Copy Markdown
Contributor Author

@opencode-agent Complete only the bounded README GREEN on exact current head 4504a5ded75ae85c618dc3409c9f8dc0271110a0 of docs/readonly-handoff-readme; stop without writing if the branch head differs.

Exact-head CI run 31144606855 is valid RED evidence: package acceptance and Ruff passed, while every Python lane failed the same remaining contract; Python 3.13 reported 1 failed, 744 passed. The sole failure is test_buyer_readme_describes_restricted_model_egress, because the buyer README does not contain the explicit audited boundary model web/network tools are denied. The preceding ADR publication-boundary failure is already fixed at this head.

Modify only README.md. Make the smallest accurate wording change in the existing product-development scheduler paragraph so it explicitly states that model web/network tools are denied, while preserving the current statement that runner egress is restricted to the reviewed package-source domains, GitHub, and the NVIDIA NIM endpoint. Preserve the credential-free handoff/external-promotion wording and all other bytes as far as practical. Do not change tests, CHANGELOG, ARCHITECTURE, ADRs, .github, workflows, scripts, product code, dependencies, credentials, permissions, model/review identities, protected refs, version, release, package, tag, or publication behavior.

After that README-only change, run the focused failing contract and the complete repository CI/100% production statement+branch coverage/public-docstring/Ruff/compile/package contract available on the branch. Report the resulting exact head and evidence here. Keep the PR Draft. Do not merge, mark Ready, auto-merge, rebase, retarget, publish, or release.

Copy link
Copy Markdown
Contributor Author

@opencode-agent Supersede my immediately preceding README-only request because the branch advanced before it could apply. Complete only the bounded README GREEN on exact current head ddc1475a23ea9563d9cf3a97815d0a61f6d53bce; stop without writing if the head differs.

Exact-head CI run 31144810336 is fresh RED evidence. The package-acceptance job and Ruff succeed; all Python lanes fail the same sole contract, and Python 3.13 reports 1 failed, 744 passed: test_buyer_readme_describes_restricted_model_egress requires the exact buyer-facing phrase model web/network tools are denied. The ADR and changelog tails are already complete at this head.

Modify only README.md. Make the smallest accurate edit in the existing product-development scheduler description so it explicitly states that model web/network tools are denied, while preserving the current truth that runner egress is restricted to reviewed package-source domains, GitHub, and the NVIDIA NIM endpoint. Preserve all credential-free handoff/external-promotion wording and every other path. Do not touch tests, CHANGELOG, ARCHITECTURE, ADRs, .github, workflows, scripts, product code, dependencies, credentials, permissions, model/review identities, protected refs, version, release, package, tag, or publication behavior.

Then run the focused failing contract and the complete repository test/100% production statement+branch coverage/public-docstring/Ruff/compile/package contract. Report the resulting exact head and evidence here. Keep Draft; do not merge, mark Ready, auto-merge, rebase, retarget, publish, or release.

Copy link
Copy Markdown
Contributor Author

@opencode-agent Supersede my README-only request on ddc1475a23ea9563d9cf3a97815d0a61f6d53bce. Do not change README. Exact-tree inspection shows the production documentation already contains the required sentence at the current head: Model web/network tools are denied, while runner egress is restricted to reviewed package sources, GitHub, and the NVIDIA NIM endpoint. The CI failure is therefore a case-sensitive test false negative, not a missing buyer boundary.

On exact current head ddc1475a23ea9563d9cf3a97815d0a61f6d53bce, modify only tests/test_hourly_opencode_nvidia_contract.py so test_buyer_readme_describes_restricted_model_egress verifies the phrase case-insensitively (for example, normalize the joined README text with .lower() for this assertion) while preserving the substantive requirements: no no direct network access, runner egress restricted, model web/network tools denied, NVIDIA NIM endpoint present. Do not weaken or remove any semantic assertion and do not touch README, CHANGELOG, ARCHITECTURE, ADRs, .github, workflows, scripts, product code, dependencies, credentials, permissions, model/review identities, protected refs, version, release, package, tag, or publication behavior.

Then run the focused contract and the complete repository test/100% production statement+branch coverage/public-docstring/Ruff/compile/package contract. Report the resulting exact head and evidence here. Keep Draft; do not merge, mark Ready, auto-merge, rebase, retarget, publish, or release.

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

Review only exact current head 3b484b2692be2c078a68a77d810798832d0beacd against exact stacked base c038a9509d1a8eae8561cc9081e67e12bd373d42. Treat every prior-head review/status and the earlier draft-skip outputs as stale unless independently reproducible on this exact tree. This head only fixes the already-existing case-sensitive buyer-README contract after hosted CI RED 31144810336; exact-head CI 31146404269 is green with 745 tests and 100% production statement/branch coverage. Verify the five-file docs/test/changelog scope, credential-free product handoff claims, NVIDIA NIM/OpenCode wording, no repository-local publisher/write path claims, accepted ADR consistency, and no unsupported release/provenance/security assertion. Do not approve, merge, mark Ready, rebase, retarget, publish, or infer acceptance from draft/missing/queued checks.

@coderabbitai

coderabbitai Bot commented Aug 7, 2026

Copy link
Copy Markdown

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

base="c038a9509d1a8eae8561cc9081e67e12bd373d42"
head="3b484b2692be2c078a68a77d810798832d0beacd"
red_publication="233db635419ee21ec80a3409629ff6d767ebd9eb"
red_egress="e1a4557fd42c16cad5469ecd2a362cf10c438854"
red_architecture="cb1e9d9f19b118769eee64cf1a4b52a0c39c4b4b"
red_adr="294e562b9dfce43fcccd7209588b88597b8a42c7"
test_path="tests/test_hourly_opencode_nvidia_contract.py"

echo '== Exact revision and ancestry =='
printf 'checked_out_head='
git rev-parse HEAD
for rev in "$base" "$red_publication" "$red_egress" "$red_architecture" "$red_adr" "$head"; do
  git cat-file -e "${rev}^{commit}"
  git show -s --format='commit=%H%nparents=%P%nsubject=%s' "$rev"
done
git merge-base --is-ancestor "$base" "$head" && echo 'base_is_ancestor=yes'
git merge-base --is-ancestor "$red_publication" "$head" && echo 'publication_red_is_ancestor=yes'
git merge-base --is-ancestor "$red_egress" "$head" && echo 'egress_red_is_ancestor=yes'
git merge-base --is-ancestor "$red_architecture" "$head" && echo 'architecture_red_is_ancestor=yes'
git merge-base --is-ancestor "$red_adr" "$head" && echo 'adr_red_is_ancestor=yes'

echo '== Changed paths and whitespace =='
git diff --name-status "$base" "$head"
git diff --stat "$base" "$head"
git diff --check "$base" "$head"

echo '== Scoped file structure =='
ast-grep outline "$test_path" --items all --type function --view expanded

echo '== Full five-file diff =='
git diff --no-ext-diff --unified=45 "$base" "$head" -- \
  README.md ARCHITECTURE.md docs/adr/0001-security-boundaries-and-modular-integration.md \
  CHANGELOG.md "$test_path"

echo '== Per-boundary diffs =='
for pair in \
  "$base $red_publication" \
  "$red_publication $red_egress" \
  "$red_egress $red_architecture" \
  "$red_architecture $red_adr" \
  "$red_adr $head"
do
  set -- $pair
  echo "-- $1..$2 --"
  git diff --no-ext-diff --unified=20 "$1" "$2" -- \
    README.md ARCHITECTURE.md docs/adr/0001-security-boundaries-and-modular-integration.md \
    CHANGELOG.md "$test_path"
done

echo '== Relevant test functions at HEAD =='
rg -n -A45 -B3 \
  'def test_(buyer_readme_describes|architecture_describes|accepted_adr_describes)' \
  "$test_path"

echo '== Exact wording across buyer-facing documents at HEAD =='
for path in README.md ARCHITECTURE.md docs/adr/0001-security-boundaries-and-modular-integration.md; do
  echo "-- $path --"
  git show "$head:$path" | rg -n -i -C 3 \
    'third publisher|three fresh runners|publication.*runner|publishing identity|credential-free|handoff|exact-base|digest-bound|model web/network tools|runner egress|package sources|github|nvidia nim|branches|pull requests|repository writes|auto-merge|external|independently reviewed|credential-separated|reconstruct|verify' \
    || true
done

echo '== RED-to-GREEN phrase conditions =='
normalize() { git show "$1:$2" | tr '\n\t' '  ' | tr -s ' '; }
for rev in "$red_publication" "$red_egress" "$red_architecture" "$red_adr" "$head"; do
  echo "-- $rev --"
  for spec in \
    'README.md|A third publisher' \
    'README.md|no direct network access' \
    'README.md|model web/network tools are denied' \
    'ARCHITECTURE.md|publishing identity creates a normal pull request' \
    'docs/adr/0001-security-boundaries-and-modular-integration.md|publishing identity creates a normal pull request' \
    'docs/adr/0001-security-boundaries-and-modular-integration.md|external, independently reviewed, credential-separated promotion'
  do
    path="${spec%%|*}"; phrase="${spec#*|}"
    if normalize "$rev" "$path" | grep -Fiq -- "$phrase"; then state=present; else state=absent; fi
    printf '%s: %s\n' "$state" "$spec"
  done
done

echo '== Changelog historical-content checksum =='
for rev in "$base" "$head"; do
  printf '%s ' "$rev"
  git show "$rev:CHANGELOG.md" | sed -n '/^## \[0\.3\.0\]/,$p' | sha256sum
done
git diff --no-ext-diff --unified=12 "$base" "$head" -- CHANGELOG.md

echo '== Exact PR metadata and check runs =='
gh pr view 73 --repo ContextualWisdomLab/EgressWeave \
  --json number,state,isDraft,headRefName,headRefOid,baseRefName,baseRefOid,statusCheckRollup \
  --jq '{number,state,isDraft,headRefName,headRefOid,baseRefName,baseRefOid,statusCheckRollup}'
gh api "repos/ContextualWisdomLab/EgressWeave/commits/$head/check-runs" \
  --jq '.check_runs[] | {name,status,conclusion,details_url}'

Length of output: 94648


🏁 Script executed:

#!/bin/bash
set -euo pipefail

base="c038a9509d1a8eae8561cc9081e67e12bd373d42"
head="3b484b2692be2c078a68a77d810798832d0beacd"
parent="$(git rev-parse "${head}^")"
operator_path="docs/hourly-autonomous-maintenance.md"
test_path="tests/test_hourly_opencode_nvidia_contract.py"

echo '== README EOF bytes =='
for rev in "$base" "$parent" "$head"; do
  printf '%s ' "$rev"
  git show "$rev:README.md" | tail -c 1 | od -An -t x1
done
echo '-- README EOF diff metadata by revision --'
git diff --no-ext-diff --summary "$base" "$head" -- README.md
git diff --no-ext-diff --summary "$parent" "$head" -- README.md

echo '== Operator handoff contract at base =='
git show "$base:$operator_path" | rg -n -i -C 5 \
  'exact.base|exact base|digest|sha-256|credential-free|handoff|two fresh runners|model web/network tools|runner egress|package sources|nvidia nim|repository write|pull request|auto-merge|external.*promotion|reconstruct|verify' \
  || true

echo '== Cross-document exact required phrases at head =='
for path in README.md ARCHITECTURE.md docs/adr/0001-security-boundaries-and-modular-integration.md; do
  echo "-- $path --"
  git show "$head:$path" | tr '\n\t' '  ' | tr -s ' ' | \
    grep -Eio '.{0,90}(credential-free patch handoff|model web/network tools are denied|runner egress is restricted|external, independently reviewed, credential-separated promotion|reconstruct and verify the exact tree before any repository write).{0,90}' \
    || true
done

echo '== Test syntax and asserted-phrase audit =='
git show "$head:$test_path" | python3 -c '
import ast
import sys
source = sys.stdin.read()
ast.parse(source)
print("python_syntax=valid")
for phrase in (
    "model web/network tools are denied",
    "runner egress is restricted",
    "NVIDIA NIM endpoint",
    "ends at the independently reverified credential-free patch handoff",
    "reconstruct and verify the exact tree before any repository write",
):
    print(f"{phrase}={source.count(phrase)}")
'

echo '== Exact GitHub Actions run metadata =='
gh run view 31146404269 --repo ContextualWisdomLab/EgressWeave \
  --json databaseId,headSha,status,conclusion,event,workflowName,createdAt,updatedAt,jobs \
  --jq '{databaseId,headSha,status,conclusion,event,workflowName,createdAt,updatedAt,jobs:[.jobs[]|{name,status,conclusion,startedAt,completedAt,steps:[.steps[]|{name,status,conclusion}]}]}'

Length of output: 2775


🏁 Script executed:

#!/bin/bash
set -euo pipefail

base="c038a9509d1a8eae8561cc9081e67e12bd373d42"
head="3b484b2692be2c078a68a77d810798832d0beacd"
parent="$(git rev-parse "${head}^")"
operator_path="docs/hourly-autonomous-maintenance.md"
test_path="tests/test_hourly_opencode_nvidia_contract.py"

echo '== README EOF bytes =='
for rev in "$base" "$parent" "$head"; do
  printf '%s ' "$rev"
  git show "$rev:README.md" | python3 -c '
import sys
data = sys.stdin.buffer.read()
print("empty" if not data else f"last_byte=0x{data[-1]:02x}")
'
done
echo '-- README EOF diff metadata by revision --'
git diff --no-ext-diff --summary "$base" "$head" -- README.md
git diff --no-ext-diff --summary "$parent" "$head" -- README.md

echo '== Operator handoff contract at base =='
git show "$base:$operator_path" | rg -n -i -C 5 \
  'exact.base|exact base|digest|sha-256|credential-free|handoff|two fresh runners|model web/network tools|runner egress|package sources|nvidia nim|repository write|pull request|auto-merge|external.*promotion|reconstruct|verify' \
  || true

echo '== Cross-document exact required phrases at head =='
for path in README.md ARCHITECTURE.md docs/adr/0001-security-boundaries-and-modular-integration.md; do
  echo "-- $path --"
  git show "$head:$path" | tr '\n\t' '  ' | tr -s ' ' | \
    grep -Eio '.{0,90}(credential-free patch handoff|model web/network tools are denied|runner egress is restricted|external, independently reviewed, credential-separated promotion|reconstruct and verify the exact tree before any repository write).{0,90}' \
    || true
done

echo '== Test syntax and asserted-phrase audit =='
git show "$head:$test_path" | python3 -c '
import ast
import sys
source = sys.stdin.read()
ast.parse(source)
print("python_syntax=valid")
for phrase in (
    "model web/network tools are denied",
    "runner egress is restricted",
    "NVIDIA NIM endpoint",
    "ends at the independently reverified credential-free patch handoff",
    "reconstruct and verify the exact tree before any repository write",
):
    print(f"{phrase}={source.count(phrase)}")
'

echo '== Exact GitHub Actions run metadata =='
gh run view 31146404269 --repo ContextualWisdomLab/EgressWeave \
  --json databaseId,headSha,status,conclusion,event,workflowName,createdAt,updatedAt,jobs \
  --jq '{databaseId,headSha,status,conclusion,event,workflowName,createdAt,updatedAt,jobs:[.jobs[]|{name,status,conclusion,startedAt,completedAt,steps:[.steps[]|{name,status,conclusion}]}]}'

Length of output: 20945


🏁 Script executed:

#!/bin/bash
set -euo pipefail

head="3b484b2692be2c078a68a77d810798832d0beacd"

git show "$head:README.md" | nl -ba | tail -n 8

Length of output: 473


🏁 Script executed:

#!/bin/bash
set -euo pipefail

head="3b484b2692be2c078a68a77d810798832d0beacd"

git show "$head:README.md" | python3 -c '
import sys
lines = sys.stdin.read().splitlines()
start = max(0, len(lines) - 8)
for number, line in enumerate(lines[start:], start + 1):
    print(f"{number}: {line}")
'

Length of output: 722


@seonghobae I found one issue on exact head 3b484b2692be2c078a68a77d810798832d0beacd.

  • README.md Line 376 has no final newline. The stacked base and the immediate parent both end with LF. Restore the conventional final newline without changing the README text.

The remaining scoped review is consistent with the requested contract.

  • The checked-out head and PR head match the requested SHA.
  • The diff changes only the five requested files.
  • The README, ARCHITECTURE.md, and ADR describe the two-runner credential-free handoff.
  • The documents deny model web/network tools and restrict runner egress to reviewed package sources, GitHub, and the NVIDIA NIM endpoint.
  • The documents remove repository-local product publication, branch, pull request, repository-write, and auto-merge claims.
  • The documents require any future promotion to be external, independently reviewed, credential-separated, and exact-tree verified before a repository write.
  • The tests cover the publication, egress, architecture, and ADR boundaries.
  • Historical changelog sections are unchanged. The [Unreleased] entry matches the documentation changes.
  • git diff --check reports no whitespace errors.
  • GitHub Actions run 31146404269 is bound to this exact head. Its Python 3.10–3.13 jobs and wheel/sdist job completed successfully. The successful job steps include Ruff, coverage execution and reporting, the guard self-test, and compile validation.

I did not approve, merge, or change the draft state.

You are interacting with an AI system.

Copy link
Copy Markdown
Contributor Author

@opencode-agent Apply the validated one-byte completion on draft PR #73 only if the branch head is still exactly 3b484b2692be2c078a68a77d810798832d0beacd; otherwise stop without writing.

Modify only README.md. Preserve every current byte and all wording, and append exactly one final LF so the file ends with one conventional newline. Do not add a blank line or alter any other file. Verify before committing that the complete blob differs only by the single terminal 0a byte and that the resulting README contract tests still pass.

Do not modify CHANGELOG.md because this correction does not change product behavior and its buyer-facing handoff entry is already present. Do not touch tests, docs other than README.md, .github, workflows, dependencies, credentials, permissions, refs, release/publication paths, review-agent identities, or temporary artifacts. Keep the PR draft. Do not rebase, retarget, merge, mark ready, enable auto-merge, release, or publish. Report the new exact head and leave exact-head checks/reviews pending until they complete.

Copy link
Copy Markdown
Contributor Author

@opencode-agent Apply only the bounded GREEN repair to exact current head 2afb7eb749b963ed5e0c58d8804cdeefe28385e2 on branch docs/readonly-handoff-readme; stop without writing if the live head differs.

The immutable test-first RED commit is 2afb7eb749b963ed5e0c58d8804cdeefe28385e2. Before editing, run the focused contract and record that the current buyer README fails because it contains lowercase model web/network tools are denied and does not end with a final LF. Then modify only README.md:

  1. change that sentence start to Model web/network tools are denied without changing the surrounding trust-boundary wording;
  2. restore exactly one conventional final newline at EOF.

Run python -m pytest tests/test_hourly_opencode_nvidia_contract.py -q, then the repository's normal exact-head CI contract if available. Preserve the focused hourly incident regression requiring the two workflow printf commands to remain single indented YAML lines with literal \n escapes. Do not modify tests, .github, workflows, model choice, credentials, permissions, endpoints, reviewer identities, dependencies, publication semantics, product code, version, release state, base branch, or any other path. Do not mark Ready, rebase, retarget, merge, enable auto-merge, release, or publish.

Copy link
Copy Markdown
Contributor Author

@opencode-agent Fix the existing test-only RED on PR #73 only from exact current head 2afb7eb749b963ed5e0c58d8804cdeefe28385e2; stop without writing if the live head differs. The RED commit 2afb7eb749b963ed5e0c58d8804cdeefe28385e2 intentionally strengthened test_buyer_readme_describes_restricted_model_egress: the current README still says lowercase model web/network tools are denied and lacks a final LF, while the test requires the buyer-facing sentence Model web/network tools are denied and README.md ending in \n. Make the minimal GREEN repair in README.md only: capitalize that sentence-starting Model and restore exactly one conventional final newline. Do not alter the test, workflow, model/version, credentials, permissions, endpoints, publication semantics, reviewer identities, dependencies, branch base, or any unrelated text. Preserve this PR as Draft and stacked on #84. Run the focused contract plus repository validation available on this branch; do not merge, auto-merge, rebase, retarget, publish, or release.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant