feat(context-fabric): require immutable contract release pins - #319
feat(context-fabric): require immutable contract release pins#319seonghobae wants to merge 805 commits into
Conversation
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
@coderabbitai review |
|
|
Current-head repair finding on RED: add a lifecycle-continuity regression with the same scope identities and a distinct event id, but a regressed |
|
Exact-current development evidence (2026-09-05 KST) Current exact head is A new tenant-isolation finding was reproduced and repaired in migration 0008. The prior lifecycle-outbox RLS predicate used unqualified
PostgreSQL primary references: PostgreSQL 18 Exact-head hosted evidence is not GREEN yet. CI Parent #233 remains Ready/open/mergeable but still lacks a qualifying APPROVED review and retains the central authenticated CodeQL-dispatch verdict blocker. Immutable GitHub Release inventories remain empty for pg-llm-batch, context-graph-contracts, enterprise-architecture-core, and contextual-orchestrator; CO #1021 remains mutable open/Ready/mergeable evidence rather than release authority. Therefore this PR stays Draft and no merge/release authority is claimed. |
Current owner slice
This Draft is the pg-owned consumer-readiness/security stack for immutable Context Fabric release identity, provider-neutral
BatchInferencePort, tenant-scoped lifecycle/outbox evidence, and fail-closed PostgreSQL runtime admission. It remains stacked on dependency-root #233 and is not production/release authority before normal protected integration.Fresh exact boundary — 2026-09-07 KST
main:5913c4bad79d6bc29d7cc1c624abb7db2ea6a77c;01d231fde23b82e2ced258d7bfcb4721ed75706d;8597201242a3e4d43a9688aac12c94595abbbe7b;ahead 793 / behind 0;Latest RED -> causal repair lineage
Fresh review found that migration-time table-program admission was not sufficient runtime authority. Migrations 0008/0009 reject user triggers and rewrite rules at schema admission, but a privileged operator could attach one later, revoke the installer privilege, and leave the persistent program able to intercept or suppress lifecycle-outbox writes.
_require_rls_application_role()re-proved live RLS/role/definer/view/materialized/inheritance/foreign authority but did not re-read the canonical relation's ownpg_trigger/pg_rewriterows.b560c71c7b2cd348074aec511839fd1d401e142candf95e1a8d13366022bafc16fdb021cc9d8e62a1f4added structural and real PostgreSQL post-migration trigger/rule specimens;4823cae6f3d5198c6094c8e55f8e235551d9dae6wired the runtime smoke into hosted CI.34109490188on exact4823cae6...produced1 failed, 1628 passed, 7 deselectedin the structural suite and failed PostgreSQL/container job101702171341. The smoke first demonstrated a post-migrationBEFORE INSERTtrigger intercepting a canonical write, then failed because runtime admission still accepted the credential:runtime admitted post-migration user-trigger drift. The specimen also covers anON INSERT DO INSTEAD NOTHINGrewrite rule.ed74f30d699772e4b48d9b404f77fa336616acfcadds only two live catalog existence checks before tenant binding/data SQL: reject non-internalpg_catalog.pg_triggerrows whosetgrelidis the admitted outbox and rejectpg_catalog.pg_rewriterows whoseev_classis the admitted outbox. Existing RLS, role traversal, definer/view/materialized/foreign authority, migrations, tenant/data SQL, and workflow gates are unchanged.pg_trigger,pg_rewrite, and trigger-behavior primary documentation and remainsProposeduntil protected integration.Earlier RED/repair evidence in this PR remains part of the security lineage: selectable/administerable role authority, recursive mixed
SET/ADMINdelegation, callable and nested user-schemaSECURITY DEFINER, exact routinesearch_path = pg_catalog, pg_temp, effective-principal ordinary-view closure, materialized-copy provenance, direct/view/definer foreign-data authority, and inheritance/partition parents with foreign descendants through cycle-safepg_catalog.pg_inheritsancestry.Exact-current hosted GREEN
Exact current head
8597201242a3e4d43a9688aac12c94595abbbe7bis terminal GREEN; predecessor evidence is not being transferred.34110307432: success. Coverage/docstrings/lint/package, Python 3.10, Python 3.12, Python 3.14, and PostgreSQL/container all passed.101704769974:1629 passed, 7 deselected; owned production4236/4236statements and1126/1126branches covered, public docstrings 100%, Ruff/lock/build successful.101704770146: success after exact-head verification. The new live table-program authority smoke passed together with replay/default/column/relation/CHECK/RLS/effective-session-role/DML grant/MAINTAIN/role-admin delegation/live-policy/replication-definer/admin-definer/nested-definer/search-path/foreign-data/delegated-foreign-data/materialized-view/direct-foreign/partitioned-foreign authority smokes.34110307504, job101704743385: success. Two clean exact-head source trees independently produced matching wheel/sdist artifacts and bounded reproducibility evidence.Upstream prerequisite is not merge-ready
#233 remains the dependency root. Its leaf CI/Release Acceptance/security lanes do not substitute for the required central review/check state or a qualifying approval. Fresh review inventory still contains only dismissed historical OpenCode
REQUEST_CHANGESrecords and a DevinCOMMENTEDreview; there is no qualifying currentAPPROVEDreview.Normal merge therefore remains gated by the live #233 required-check state, including the central CodeQL/OpenCode/Noema owner paths. No leaf workaround, synthetic status, self-approval, routine administrator bypass, force update, or gate weakening is permitted.
Documentation, performance, and release boundaries
ARCHITECTURE.md,CHANGELOG.md, anddocs/product-technical-gap-baseline.mdoverlap documentation-only Draft #324. A fresh handoff records the table-program RED→repair→GREEN lineage while preserving #324's unique Result Application semantic-identifier decision/traceability delta. Do not replace either ledger wholesale from a stale parent.Issue #307 owns the acquisition/performance evidence gap. Its complete-path p95 <= 20 ms measurement must now include the live
pg_trigger/pg_rewriteprobes inside connection acquisition -> authority admission -> tenant binding -> data I/O -> cleanup. Security work may not be removed from the timing path to manufacture the target.No compatible immutable GitHub Release is assumed from a mutable sibling branch/head. After #233 normally integrates or is genuinely superseded with complete inherited delta/evidence, reconcile #319 non-destructively onto then-current protected main and reacquire exact-final-head CI/security/SAST/review/package/SBOM/provenance/reproducibility/release evidence before promotion.
No force push, destructive rebase, protected-main direct write, self-approval, routine bypass, gate weakening, cross-service SQL, sibling-source copy, mutable production dependency, or predecessor-evidence transfer is accepted.