Skip to content

fix: bind Context Assertion message to CloudEvent envelope - #21

Draft
seonghobae wants to merge 139 commits into
chatgpt/ddd-context-fitness-v1from
chatgpt/context-assertion-event-envelope-v1
Draft

seonghobae wants to merge 139 commits into
chatgpt/ddd-context-fitness-v1from
chatgpt/context-assertion-event-envelope-v1

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 1, 2026 •

Copy link
Copy Markdown
Contributor

Current exact state

Exact head is 238773711aec5c22482fa073ccf3e73a0878d812, Draft. GitHub still records obsolete base chatgpt/ddd-context-fitness-v1@0044d7193a8e9f477e42e961d49b71dc1a956c47; live parent #20 has moved, and this child must be rebuilt from fresh protected integration truth before it becomes an integration candidate. Fresh exact-head Actions lookup remains zero workflow runs. No exact-head checkout/test/package/security/conformance/SBOM/provenance GREEN exists and no predecessor evidence transfers. Fresh review-thread lookup has no unresolved thread.

Context Assertion / CloudEvent contract

This lane binds Context Assertion data to one structured CloudEvent envelope. It preserves canonical id, source, specversion, type, time, subject, dataschema, outer application/cloudevents+json media type, producer authority, all six truth dispositions, separate valid/business and recorded/system time, mandatory typed provenance, and explicit schema/event-profile/message-profile/admission receipt identity. Event/data subject mismatch, wrong type/dataschema/media type, missing required envelope identity or provenance, incompatible admission, and direct receipt minting outside the transport admission boundary fail closed.

The separately versioned structured-message profile urn:cwl:context-contracts:context-assertion-message-admission:v1 binds outer transport admission to event-semantics profile urn:cwl:context-contracts:context-assertion-event-semantics:v1 at exact version 1. Canonical and UTF-8 structured media types are accepted; generic JSON, unsupported charset, duplicate parameters, header injection and oversized transport metadata fail closed.

Current TDD repair: revalidate packaged profile identity for every receipt

Fresh admission-boundary review found that _validate_packaged_profile_identity() was process-lifetime memoized. After one successful admission, a later drift in the installed event/message profile resources could be hidden by that cache while subsequent receipts continued to claim fixed schema/profile/admission identities.

  • RED 3dd8c7ad8269d693f3bece17be7c22470e611031 first admits the canonical structured event, then exposes a drifted packaged event-profile version and requires the next receipt to fail closed. On the predecessor implementation this second call is skipped by the populated cache.
  • Minimum production repair e3a128c9fe59f3c630e3d037c0bd9d0bdc1b669c removes the process-lifetime lru_cache; every receipt now reloads and validates both packaged profile identities/link/media type immediately before minting receipt evidence.
  • Documentation head 238773711aec5c22482fa073ccf3e73a0878d812 records the defect and acceptance boundary in docs/product-technical-gap-baseline.md. No schema, event payload, truth, bitemporal semantics, authority boundary, media type, product ownership, or provider-specific runtime mechanic changed.
  • Exact e3a128c9... immediately after the production repair had zero Actions runs, and the documentation movement invalidates even hypothetical predecessor evidence. Current exact head therefore has no remote GREEN claim. .github#712 has been refreshed with the exact materialization evidence.

The immediately preceding repair remains inherited: RED aaa9d5c6417cf99d2c4b27e3b86faaadb7ad29e3 -> production fdaf5a94bc0504a221c3a06166da733621fd4980 binds the exact runner-visible event profile to its v1 ID/version before vectors execute. Earlier repairs bind the message profile's own v1 identity/media type, its referenced event-profile ID/version, immutable admission receipt construction, event/data identity, strict structured media admission, all-six-status provenance semantics and package inventory.

Truth / authority

Foreign observed, inferred, and proposed evidence retains its producer source. authoritative, superseded, and rejected remain owner-controlled. Adapters retain the supplied disposition exactly; no producer or consumer may promote analysis/risk/model output into another bounded context's authoritative fact. Canonical references, bitemporal intervals and typed provenance remain Shared Kernel contract semantics rather than application/store/workflow ownership.

EA / quarantine handoff

Quarantine Sandbox Runtime remains an independently deployable reusable hostile-workload isolation and artifact-analysis evidence authority. contextual-orchestrator owns caller/application/task/tool authorization and user-visible actions; Wardnet owns maliciousness/SOC verdicts and incidents. EA may project only architecture-relevant runtime/service/API/backend/technology/lifecycle/ownership/remediation/transformation/attestation context after a protected immutable CGC release carries compatible schema/event-profile/message-profile/admission/conformance/package/SBOM/provenance/source identity. malware_verdict, artifact_risk_score, direct database coupling and source copy remain prohibited as EA authoritative coupling.

Governance / integration discipline

Fresh repository metadata still reports default_branch=develop; protected develop@99cb5468ba3c15c5e79688f53dee74724fae2d13 and byte-identical unprotected main@99cb5468ba3c15c5e79688f53dee74724fae2d13 remain the live branch topology. Neither integration ref currently contains .github/workflows, while this PR head contains ci.yml, receipt-package-smoke.yml, reproducibility.yml, and supply-chain.yml. Effective organization ruleset 18156473 still follows ~DEFAULT_BRANCH with bare required_approving_review_count=1, no named required reviewer/code-owner/last-push approval, required thread resolution/central workflows/deletion/non-fast-forward protection, and routine OrganizationAdmin/always bypass.

.github#1137 owns protect-main-first -> safe default switch -> effective ~DEFAULT_BRANCH reread. .github#772 owns replacement of only the structurally impossible solo-maintainer approval count/routine bypass while deterministic gates remain fail closed. .github#712 owns workflow/materialization/dispatch defects. Central owner PR .github#1644@e35cdc5d6527dfa8634654719a6c3681f16ed82a remains Draft; its current receipt states that live rules/default/protection settings were not mutated and privileged owner-plane apply remains disabled until protected source plus the least-privilege Administration-write environment are available.

After central convergence, rebuild dependency-root first from fresh protected main, non-force restack descendants while preserving only each valid delta, and reacquire every exact-source CI/security/conformance/package/SBOM/provenance/review artifact. No self-approval, synthetic reviewer, routine bypass, force-push/destructive rebase, stale evidence, mutable-PR release authority, source copy or cross-service SQL is authorized.

@coderabbitai

coderabbitai Bot commented Sep 1, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@seonghobae seonghobae added the bug Something isn't working label Sep 1, 2026 — with ChatGPT Codex Connector

Copy link
Copy Markdown
Contributor Author

Context Fabric owner handoff — fresh terminal failure evidence for PR #21, exact advertised head a3a3125619ed6e777818811b1c0b97f3a4574b73.

The PR body is now stale: hosted lanes are no longer queued. reproducibility 33485592238 and supply-chain 33485592251 completed success, while ci 33485592465 and receipt-package-smoke 33485592219 completed failure. Treat the latter two as current blockers; predecessor GREEN does not transfer.

There are three concrete causal gaps to repair in the dedicated Context Fabric writer lane:

  1. CI is not exact-head evidence. CI job 99784804556 fetched and checked out PR merge ref fa2ce1ecc047f567000a8d8910ca8b71b943486c (Merge a3a312... into b5397e0...), not source head a3a312.... Receipt smoke job 99784802088 did the same. A future GREEN must explicitly checkout/assert github.event.pull_request.head.sha == a3a312... (or the then-current head) so merge-ref results are not represented as exact-head evidence.

  2. Current source has real Ruff failures. CI job 99784804556 reports: src/cwl_context_contracts/assertion.py:259:89 E501 (91 > 88), tests/test_asyncapi_contract.py:3:1 I001 (imports unsorted), and tests/test_asyncapi_contract.py:34:89 E501 (92 > 88). Repair these minimally and rerun the full matrix; do not suppress/skip Ruff.

  3. The newly packaged assertion-event conformance profile is not wired through release conformance. Current conformance._PROFILE_NAMES includes context-assertion-event-semantics.v1.json, but conformance_runner._PROFILE_RUNNERS has no runner for it. run_packaged_conformance() therefore fails closed with profile_dispatch: no executable runner is registered for this packaged profile. The package-smoke script is also stale: its exact available_conformance_profile_names() assertion omits this new profile, which explains the bare AssertionError in CI package job 99784804313. Receipt smoke 99784802088 exits in Exercise release evidence from installed wheel, consistent with the same fail-closed conformance gap.

RED/GREEN acceptance: first preserve an executable RED proving the packaged context-assertion-event-semantics.v1.json fails dispatch; then add a dedicated runner that exercises every valid vector through ContextAssertion.from_event(...) and every invalid vector against its published error_pattern. Update package resource/profile expectations to include the new profile. GREEN only when exact-current-head source checkout is asserted and lint, tests/100%-policy coverage, installed-wheel package smoke, receipt/release-evidence admission, reproducibility, supply-chain, and required security/review gates are terminal passing. Keep #21 Draft and stacked behind exact #20; do not bypass the existing branch/default/review governance blockers.

Copy link
Copy Markdown
Contributor Author

Noema consumer acceptance has advanced and tightens the release boundary. Fresh Noema #528 head 5a9872158d8beb26f1d480109c9660f2bfa0298f now validates the required Context Graph release metadata/capability surface but deliberately refuses production admission from a self-asserted manifest alone. Its required capability set is: canonical object reference, canonical authority reference, truth status/origin, bitemporal valid/system time, provenance, Context Assertion, CloudEvent envelope, Context Assertion event semantics, schema conformance, and admission receipt. Producer-side GREEN therefore needs more than this Draft becoming schema-correct: protected integration plus an immutable version/tag/package release whose source commit is externally bindable, package/SBOM/provenance digests and conformance/admission receipts are published, compatibility/migration and licensing/NOTICE evidence are present, and a consumer can authenticate that release authority through the repository's canonical publication mechanism rather than trusting fields supplied by a caller. Noema will keep candidate SHA testing non-authoritative; once that immutable release exists, its own ACL will add trusted release-registry/provenance verification before production pinning. Please preserve this as downstream release acceptance when finishing the stack; an open PR head or a manifest that merely says released is not sufficient.

Copy link
Copy Markdown
Contributor Author

Noema consumer acceptance has moved to an exact current protected-base candidate and should be treated as downstream release input, not as authority promotion. Current Noema PR #528 is restacked on protected main@03ef2301bad020b9ab4dfde2ec3c4e7f460024ca, exact head 15a5768ac130658bc570c0473344fee385b80f09, and is now mergeable. Its ContextContractReleaseAuthority boundary deliberately rejects self-asserted release metadata: production admission requires an independently authenticated immutable producer identity with exact repository/ref/source/package/SBOM/provenance/conformance/admission/capability equality.

For this CGC owner path, Noema's falsifiable acceptance is therefore:

RED: an open PR head, mutable branch, structurally valid released=true payload, package digest supplied only by the candidate, missing public conformance resource, mismatched source/package/provenance identity, or unknown immutable release must remain inadmissible to Noema.

GREEN: after this stack reaches the intended protected integration, publish through CGC's canonical immutable mechanism with one exact version/tag/package bound to source commit; include the structured Context Assertion CloudEvent envelope and all declared schema/profile/admission/conformance resources in the distributable artifact; prove installed-package positive/hostile conformance; provide compatibility/migration evidence plus applicable SBOM/provenance/license/NOTICE receipts. Noema must be able to authenticate that identity independently at its release-authority port.

Noema will not vendor this Draft or treat beff93585dfb510841f66cae0cc52cb5caeb6a33 as production truth. Once an immutable CGC release exists, Noema's next production step is RED against the released artifact, pin its exact released identity through the authority/ACL boundary, then GREEN before asking EA Core to promote any dependent projection.

seonghobae commented Sep 1, 2026 •

Copy link
Copy Markdown
Contributor Author

Noema consumer acceptance — fresh exact authority, 2026-09-02.

Current Noema protected base is main@b505cb807536e9cf2bdbfcb05ad3fefe99999a14; current Noema consumer PR #528 is 0c016b4f972d4fef3985cf759ced4ee0d12005f4. Current CGC Context Assertion owner PR #21 is de376b0608a60ad195e06f5522887be2e63d7b60. On that exact CGC head, ci 33524763601, receipt-package-smoke 33524763503, reproducibility 33524763497, and supply-chain 33524763509 are terminal success. This remains candidate evidence: GitHub releases are still empty and the live default remains protected develop@99cb5468ba3c15c5e79688f53dee74724fae2d13 while the accepted integration target is protected main after the central governance transition.

Noema's production admission requires these exact event/profile identities in addition to release authority:

  • https://schemas.contextualwisdomlab.org/context/context-assertion.v1.schema.json
  • https://schemas.contextualwisdomlab.org/context/cloudevent-envelope.v1.schema.json
  • org.contextualwisdomlab.context_graph.assertion.v1
  • urn:cwl:context-contracts:context-assertion-event-semantics:v1
  • application/cloudevents+json

RED: an open PR/Draft, mutable ref, package version string without protected publication, self-asserted released metadata, unknown release, mismatched repository/tag/source/package/SBOM/provenance/schema/profile/conformance/admission identity, or missing promotion disposition remains inadmissible.

GREEN: after dependency-first protected integration, publish through CGC's canonical immutable mechanism with one exact version/tag/distribution bound to the protected source; retain installed positive/hostile conformance and admission evidence; bind package/SBOM/provenance/reproducibility identities; and expose independently verifiable compatibility=passed, migration in {passed, not-required}, licensing=passed, and notice in {passed, not-required} evidence. The current candidate tree contains package metadata and release-evidence verifiers but its workflow inventory is CI/package-smoke/reproducibility/supply-chain only, so the owner path must also make the actual immutable publication step and its authority explicit rather than treating internal evidence coherence as publication.

Do not prescribe GitHub Release if the repository adopts another reviewed immutable publication mechanism. Noema will not vendor #21 or promote it as production truth. Once the first immutable CGC release exists, Noema's next step is a released-artifact RED, exact authenticated release-authority/ACL pin, then GREEN on a fresh Noema exact head before EA projection can be promoted.

Copy link
Copy Markdown
Contributor Author

pg-llm-batch consumer acceptance update (read-only owner handoff; no CGC source/ref mutation): current CGC candidate is still #21beff935 on #200044d71, and GitHub Releases remains empty. The pg consumer lane now has a TDD release-readiness contract that requires exact distribution/version/source commit plus distribution/profile/resource/conformance/admission/provenance SHA-256 identities and fails closed on identity drift instead of trusting mutable aliases or an unreleased PR head. This does not copy CGC schema/profile bytes and remains candidate-only until an immutable CGC publication exists.

Consumer GREEN required from this owner path before pg can promote the integration: integrate the dependency stack onto the then-protected release branch; publish one immutable cwl-context-contracts version from an exact protected source commit; bind wheel/sdist (or repository-canonical distribution), context-assertion-event-semantics.v1.json, required Context Assertion resource(s), conformance result, admission evidence and provenance to exact SHA-256 identities; expose the source commit and version in release evidence; verify installed-package positive/hostile conformance; and make those identities reconstructable from the immutable release without consulting a mutable branch. pg will then re-read the release and require exact equality with its approved deployment pin before enabling the optional ACL/publisher. Mutable PR-head artifacts remain non-authoritative.

Copy link
Copy Markdown
Contributor Author

Fresh exact-head Context Assertion conformance repair — 2026-09-08 KST.

Current head advanced linearly/non-force from 49318782cfe3dffdc78fbcd2bb8e3ee0860d9329 through RED a21da225d17135a72ede45b935707954bc940e3a to GREEN candidate 6615b5adedc6790112f23414656f51b4358ff511; compare is ahead 2 / behind 0. The delta is limited to one new hostile conformance test and the packaged conformance runner (27 added test lines; runner +6/-2).

Fresh audit found a second half of the event-profile-version binding defect: structured-message admission itself already rejected packaged event_profile_version drift, but the buyer-facing run_packaged_conformance() path only compared the message profile's event_profile_id. Because its execution path receives the loaded message profile separately from transport admission's packaged-profile reload, executable release evidence could fail to report an event-profile version mismatch in the profile it was asked to execute.

RED a21da225... mutates only the conformance runner's loaded context-assertion-message-admission.v1.json view to event_profile_version=2 and requires an event_profile_link failure identifying version drift. The preceding runner checks only the ID and therefore has no such failure. GREEN candidate 6615b5ad... requires both event_profile_id and event_profile_version to match the referenced event-semantics profile before executing message vectors. No event/data schema, truth, authority, bitemporal, provenance, application/runtime ownership or provider-specific mechanics changed.

Fresh Actions lookup for exact 6615b5ad... is empty, so this is source-level RED -> minimum causal GREEN candidate only; hosted conformance/package/SBOM/provenance/reproducibility GREEN is not claimed. Keep Draft and transfer no predecessor evidence.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant