Skip to content

fix(scheduler): casefold repository identity - #2007

Draft
seonghobae wants to merge 7 commits into
fix/scheduler-draft-merge-mutation-guardfrom
fix/scheduler-casefold-repository-identity
Draft

fix(scheduler): casefold repository identity#2007
seonghobae wants to merge 7 commits into
fix/scheduler-draft-merge-mutation-guardfrom
fix/scheduler-casefold-repository-identity

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 7, 2026

Copy link
Copy Markdown
Contributor

Root cause

GitHub repository identity is case-insensitive, but scheduler owned-head and compare-ref routing used exact string equality. Canonical casing drift could therefore misclassify an organization-owned branch as an external fork and block normal restack/update processing.

This bounded successor carries the corresponding valid delta from historical Draft #1231 and remains stacked after repaired #2006.

RED → GREEN

Verification

Fresh detached verification at exact remote head de5e6220726b0b91a2482c36953bf379671eb340:

  • python -m py_compile scripts/ci/pr_review_merge_scheduler_core.py
  • python -m pytest tests/test_pr_review_merge_scheduler.py -q344 passed
  • GITHUB_ACTIONS=true python -W error -m pytest tests/test_pr_review_merge_scheduler.py -q344 passed
  • git diff --check 5e6fd0ca2fc052057b75473a528d533e346c131e..de5e6220726b0b91a2482c36953bf379671eb340

Prior Checks on 5e6fd0ca… are not transferred. Hosted Runtime Quality and security evidence is GREEN on this exact head; lifecycle-triggered replacement Checks, CodeQL settlement, and qualifying independent approval remain required before merge.

Stack and authority

  • Base: fix/scheduler-draft-merge-mutation-guard@d739e0d8d6285261da0a2f530181a929f19a202d
  • Fast-forward ref update only; no force push or rebase
  • No ownership, review, status, credential, or mutation permission is broadened
  • Status remains Proposed / Ready-for-review; this is review admission only, not merge authority
  • Pre-admission exact-head runs: Runtime Quality 34197136278 succeeded; CodeQL 34197136206 failed settlement; Python Security, SAST, and Security succeeded. Ready admission created replacement CodeQL 34202091140, Python Security 34202091202, SAST 34202090959, and Security 34202091133; these are not predecessor evidence and must terminate independently.

@coderabbitai

coderabbitai Bot commented Sep 7, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@seonghobae seonghobae added bug Something isn't working type: bug Defect or incorrect behavior priority: medium Normal-priority or P2 work labels Sep 7, 2026 — with ChatGPT Codex Connector
Preserve this PR's bounded RED→GREEN delta while integrating protected-main CodeQL fixes through its exact parent branch. No force update; both parent SHAs are recorded.
Preserve case-insensitive repository identity while inheriting the complete current-main scheduler stack and exact fixture repairs. No rebase or force update.

Copy link
Copy Markdown
Contributor Author

Current scheduler stack receipt — tip 5e6fd0ca2fc052057b75473a528d533e346c131e

Exact lineage:
main@78a4937#2002@b18b7ca#2003@71e7678#2004@9fb02c9#2005@3f09f31#2006@fb552da#2007@5e6fd0c.

Every edge is 0 behind its exact base and was reconciled with a normal merge commit. The tip inherits #2008/#2009 CodeQL coordinator fixes plus the permanent Runtime Quality fixture repairs for host-scoped cancellation calls and workflow-starting token proof. All six PRs remain Draft/Proposed; no predecessor check, review, or status was transferred. Five fresh hosted workflows exist on this exact tip and are still non-terminal.

Copy link
Copy Markdown
Contributor Author

Fresh stack verification: Runtime Quality succeeded on #2002@b18b7ca (run 34178933394), #2004@9fb02c9 (34179040923), #2005@3f09f31 (34179079329), #2006@fb552da (34179118151), and #2007@5e6fd0c (34179154325). #2003 intentionally lacks that trigger until #2004's restoration delta. CodeQL/SAST and other required evidence remain non-terminal on the respective exact heads, so every stack node remains Draft/Proposed; no child inherits a parent's status.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Exact-head bounded-delta review: no new substantive finding in this child’s case-insensitive repository-identity change. Both routing boundaries case-fold only already-equal GitHub repository identities, missing metadata retains the conservative behavior, and the focused regression covers owned-head/compare-ref semantics. This is not approval or merge authority: #2007 inherits the unresolved #2006 live Draft-race finding (review 5136886031), has no qualifying independent approval, and must remain Draft until the prerequisite is repaired and combined exact-head hosted evidence is regenerated.

Copy link
Copy Markdown
Contributor Author

Restack 착수: exact child 5e6fd0ca2fc052057b75473a528d533e346c131e는 repaired parent #2006 d739e0d8d6285261da0a2f530181a929f19a202d 이전 base fb552daf…에 남아 mergeable=false입니다. Child 고유 casefold delta를 보존하면서 parent exact head를 normal two-parent merge로 non-force 흡수하고, combined scheduler suite와 child 경계 회귀를 exact head에서 재검증하겠습니다. 현재 remote owner receipt나 active exact-head run은 보이지 않습니다. Force/rebase/bypass/close/lifecycle toggle은 사용하지 않습니다.

Copy link
Copy Markdown
Contributor Author

Restack complete at exact head de5e6220. This normal two-parent commit preserves prior child 5e6fd0ca… and repaired parent #2006 d739e0d8…; the remote ref moved fast-forward with force=false. Conflict reconciliation retained both the child casefold boundaries and parent live open/Draft/head mutation guard. Fresh detached exact-head evidence: py_compile PASS; normal scheduler suite 344 passed; GITHUB_ACTIONS=true -W error 344 passed; git diff --check PASS. Prior 5e6fd0ca… Checks are not transferred. Five new hosted workflows are queued, so #2007 remains Draft/Proposed pending exact-head evidence and independent review.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Exact-head re-review at de5e6220726b0b91a2482c36953bf379671eb340: the normal two-parent restack preserves the child casefold routing delta and repaired parent live open/Draft/head mutation guard. There are no unresolved inline threads. Current-head Runtime Quality, SAST, Python Security, and Security Scan are GREEN. CodeQL run 34197136206 is not GREEN: both language shards dispatched but terminated pending because no authenticated terminal verdict returned to rerun/settle them. That central handshake failure remains a merge blocker. No new substantive source finding in this bounded child; this COMMENT is not approval or merge authority.

@seonghobae
seonghobae marked this pull request as ready for review September 8, 2026 07:59
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 8, 2026

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review Completed 2026-09-08T08:03:06.183518Z de5e622 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

Copy link
Copy Markdown
Contributor Author

Ready-for-review admission receipt for exact head de5e6220726b0b91a2482c36953bf379671eb340. Before transition the PR was open/Draft/mergeable, exact base #2006 remained d739e0d8d6285261da0a2f530181a929f19a202d, there were zero active runs and zero unresolved threads, and exact-head review 5138926199 found no new bounded child defect. Runtime Quality, SAST, Python Security, and Security Scan were terminal GREEN; CodeQL 34197136206 remained a central settlement failure and was not treated as GREEN. Ready created same-head replacement runs: SAST 34202090959, Security 34202091133, CodeQL 34202091140, Python Security 34202091202. They must terminate independently. Qualifying current-head approval, parent order, and required Checks still block merge; no auto-merge or bypass was configured.

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode reviewed the current-head product diff. Coverage is a separate gate.

Changed files

  • CHANGELOG.md — repository behavior
  • docs/doctoring/case-insensitive-owned-head-identity.md — operator or user guidance
  • docs/product-technical-gap-baseline.md — operator or user guidance
  • scripts/ci/pr_review_merge_scheduler_core.py — review and security gate shell path
  • tests/test_pr_review_merge_scheduler.py — regression suite

Changed behavior

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Repository file: CHANGELOG.md"]
  S1 --> I1["repository behavior"]
  I1 --> R1["Review risk: Repository file: CHANGELOG.md"]
  R1 --> V1["required checks"]
  Evidence --> S2["Docs: case-insensitive-owned-head-identity.md (2 files)"]
  S2 --> I2["operator or user guidance"]
  I2 --> R2["Review risk: Docs: case-insensitive-owned-head-identity.md (2 files)"]
  R2 --> V2["docs review"]
  Evidence --> S3["CI script: pr_review_merge_scheduler_core.py"]
  S3 --> I3["review and security gate shell path"]
  I3 --> R3["Review risk: CI script: pr_review_merge_scheduler_core.py"]
  R3 --> V3["bash -n plus Strix self-test"]
  Evidence --> S4["Test: test_pr_review_merge_scheduler.py"]
  S4 --> I4["regression suite"]
  I4 --> R4["Review risk: Test: test_pr_review_merge_scheduler.py"]
  R4 --> V4["targeted test run"]
Loading

Findings

No source-backed product finding is synthesized from the coverage gate. A coverage miss belongs in the status comment.

  • Head SHA: de5e6220726b0b91a2482c36953bf379671eb340
  • Workflow run: 34203237461
  • Workflow attempt: 1
  • Coverage gate: failure

Review outcome

Coverage is a gate, not the review. This body reviews the changed product files.

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Repository file: CHANGELOG.md"]
  S1 --> I1["repository behavior"]
  I1 --> R1["Review risk: Repository file: CHANGELOG.md"]
  R1 --> V1["required checks"]
  Evidence --> S2["Docs: case-insensitive-owned-head-identity.md (2 files)"]
  S2 --> I2["operator or user guidance"]
  I2 --> R2["Review risk: Docs: case-insensitive-owned-head-identity.md (2 files)"]
  R2 --> V2["docs review"]
  Evidence --> S3["CI script: pr_review_merge_scheduler_core.py"]
  S3 --> I3["review and security gate shell path"]
  I3 --> R3["Review risk: CI script: pr_review_merge_scheduler_core.py"]
  R3 --> V3["bash -n plus Strix self-test"]
  Evidence --> S4["Test: test_pr_review_merge_scheduler.py"]
  S4 --> I4["regression suite"]
  I4 --> R4["Review risk: Test: test_pr_review_merge_scheduler.py"]
  R4 --> V4["targeted test run"]
Loading

@opencode-agent

opencode-agent Bot commented Sep 8, 2026

Copy link
Copy Markdown
Contributor

OpenCode Review Overview

Coverage evidence did not pass, so approval is blocked. The formal pull-request review is the source-backed diff review, not this status comment.

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode reviewed the current-head product diff. Coverage is a separate gate.

Changed files

  • CHANGELOG.md — repository behavior
  • docs/doctoring/case-insensitive-owned-head-identity.md — operator or user guidance
  • docs/product-technical-gap-baseline.md — operator or user guidance
  • scripts/ci/pr_review_merge_scheduler_core.py — review and security gate shell path
  • tests/test_pr_review_merge_scheduler.py — regression suite

Changed behavior

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Repository file: CHANGELOG.md"]
  S1 --> I1["repository behavior"]
  I1 --> R1["Review risk: Repository file: CHANGELOG.md"]
  R1 --> V1["required checks"]
  Evidence --> S2["Docs: case-insensitive-owned-head-identity.md (2 files)"]
  S2 --> I2["operator or user guidance"]
  I2 --> R2["Review risk: Docs: case-insensitive-owned-head-identity.md (2 files)"]
  R2 --> V2["docs review"]
  Evidence --> S3["CI script: pr_review_merge_scheduler_core.py"]
  S3 --> I3["review and security gate shell path"]
  I3 --> R3["Review risk: CI script: pr_review_merge_scheduler_core.py"]
  R3 --> V3["bash -n plus Strix self-test"]
  Evidence --> S4["Test: test_pr_review_merge_scheduler.py"]
  S4 --> I4["regression suite"]
  I4 --> R4["Review risk: Test: test_pr_review_merge_scheduler.py"]
  R4 --> V4["targeted test run"]
Loading

Findings

No source-backed product finding is synthesized from the coverage gate. A coverage miss belongs in the status comment.

  • Head SHA: de5e6220726b0b91a2482c36953bf379671eb340
  • Workflow run: 34206225146
  • Workflow attempt: 1
  • Coverage gate: failure

Review outcome

Coverage is a gate, not the review. This body reviews the changed product files.

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Repository file: CHANGELOG.md"]
  S1 --> I1["repository behavior"]
  I1 --> R1["Review risk: Repository file: CHANGELOG.md"]
  R1 --> V1["required checks"]
  Evidence --> S2["Docs: case-insensitive-owned-head-identity.md (2 files)"]
  S2 --> I2["operator or user guidance"]
  I2 --> R2["Review risk: Docs: case-insensitive-owned-head-identity.md (2 files)"]
  R2 --> V2["docs review"]
  Evidence --> S3["CI script: pr_review_merge_scheduler_core.py"]
  S3 --> I3["review and security gate shell path"]
  I3 --> R3["Review risk: CI script: pr_review_merge_scheduler_core.py"]
  R3 --> V3["bash -n plus Strix self-test"]
  Evidence --> S4["Test: test_pr_review_merge_scheduler.py"]
  S4 --> I4["regression suite"]
  I4 --> R4["Review risk: Test: test_pr_review_merge_scheduler.py"]
  R4 --> V4["targeted test run"]
Loading

@seonghobae
seonghobae marked this pull request as draft September 8, 2026 16:22

Copy link
Copy Markdown
Contributor Author

Non-force parent reconciliation completed after #2006 advanced.

The case-folded repository routing delta, live Ready/Draft/head mutation boundary, and complete current parent prerequisites are preserved. Publication used an exact Git tree and force:false; no force push or rebase was used.

Detached combined verification:

  • scheduler + central inventory + CodeQL contracts: 394 passed under GITHUB_ACTIONS=true and -W error
  • python -m py_compile scripts/ci/pr_review_merge_scheduler_core.py → PASS
  • git diff --check → PASS

#2007 remains Draft/Proposed. Predecessor Checks and reviews do not transfer; fresh exact-head hosted Checks and a qualifying independent approval remain mandatory.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working priority: medium Normal-priority or P2 work type: bug Defect or incorrect behavior

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant