fix: bind Context Assertion message to CloudEvent envelope - #21
seonghobae wants to merge 139 commits into
Conversation
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Context Fabric owner handoff — fresh terminal failure evidence for PR #21, exact advertised head The PR body is now stale: hosted lanes are no longer queued. There are three concrete causal gaps to repair in the dedicated Context Fabric writer lane:
RED/GREEN acceptance: first preserve an executable RED proving the packaged |
|
Noema consumer acceptance has advanced and tightens the release boundary. Fresh Noema #528 head |
|
Noema consumer acceptance has moved to an exact current protected-base candidate and should be treated as downstream release input, not as authority promotion. Current Noema PR #528 is restacked on protected For this CGC owner path, Noema's falsifiable acceptance is therefore: RED: an open PR head, mutable branch, structurally valid GREEN: after this stack reaches the intended protected integration, publish through CGC's canonical immutable mechanism with one exact version/tag/package bound to source commit; include the structured Context Assertion CloudEvent envelope and all declared schema/profile/admission/conformance resources in the distributable artifact; prove installed-package positive/hostile conformance; provide compatibility/migration evidence plus applicable SBOM/provenance/license/NOTICE receipts. Noema must be able to authenticate that identity independently at its release-authority port. Noema will not vendor this Draft or treat |
|
Noema consumer acceptance — fresh exact authority, 2026-09-02. Current Noema protected base is Noema's production admission requires these exact event/profile identities in addition to release authority:
RED: an open PR/Draft, mutable ref, package version string without protected publication, self-asserted GREEN: after dependency-first protected integration, publish through CGC's canonical immutable mechanism with one exact version/tag/distribution bound to the protected source; retain installed positive/hostile conformance and admission evidence; bind package/SBOM/provenance/reproducibility identities; and expose independently verifiable Do not prescribe GitHub Release if the repository adopts another reviewed immutable publication mechanism. Noema will not vendor #21 or promote it as production truth. Once the first immutable CGC release exists, Noema's next step is a released-artifact RED, exact authenticated release-authority/ACL pin, then GREEN on a fresh Noema exact head before EA projection can be promoted. |
|
pg-llm-batch consumer acceptance update (read-only owner handoff; no CGC source/ref mutation): current CGC candidate is still #21beff935 on #200044d71, and GitHub Releases remains empty. The pg consumer lane now has a TDD release-readiness contract that requires exact distribution/version/source commit plus distribution/profile/resource/conformance/admission/provenance SHA-256 identities and fails closed on identity drift instead of trusting mutable aliases or an unreleased PR head. This does not copy CGC schema/profile bytes and remains candidate-only until an immutable CGC publication exists. Consumer GREEN required from this owner path before pg can promote the integration: integrate the dependency stack onto the then-protected release branch; publish one immutable |
|
Fresh exact-head Context Assertion conformance repair — 2026-09-08 KST. Current head advanced linearly/non-force from Fresh audit found a second half of the event-profile-version binding defect: structured-message admission itself already rejected packaged RED Fresh Actions lookup for exact |
Current exact state
Exact head is
238773711aec5c22482fa073ccf3e73a0878d812, Draft. GitHub still records obsolete basechatgpt/ddd-context-fitness-v1@0044d7193a8e9f477e42e961d49b71dc1a956c47; live parent #20 has moved, and this child must be rebuilt from fresh protected integration truth before it becomes an integration candidate. Fresh exact-head Actions lookup remains zero workflow runs. No exact-head checkout/test/package/security/conformance/SBOM/provenance GREEN exists and no predecessor evidence transfers. Fresh review-thread lookup has no unresolved thread.Context Assertion / CloudEvent contract
This lane binds Context Assertion data to one structured CloudEvent envelope. It preserves canonical
id,source,specversion,type,time,subject,dataschema, outerapplication/cloudevents+jsonmedia type, producer authority, all six truth dispositions, separate valid/business and recorded/system time, mandatory typed provenance, and explicit schema/event-profile/message-profile/admission receipt identity. Event/data subject mismatch, wrong type/dataschema/media type, missing required envelope identity or provenance, incompatible admission, and direct receipt minting outside the transport admission boundary fail closed.The separately versioned structured-message profile
urn:cwl:context-contracts:context-assertion-message-admission:v1binds outer transport admission to event-semantics profileurn:cwl:context-contracts:context-assertion-event-semantics:v1at exact version1. Canonical and UTF-8 structured media types are accepted; generic JSON, unsupported charset, duplicate parameters, header injection and oversized transport metadata fail closed.Current TDD repair: revalidate packaged profile identity for every receipt
Fresh admission-boundary review found that
_validate_packaged_profile_identity()was process-lifetime memoized. After one successful admission, a later drift in the installed event/message profile resources could be hidden by that cache while subsequent receipts continued to claim fixed schema/profile/admission identities.3dd8c7ad8269d693f3bece17be7c22470e611031first admits the canonical structured event, then exposes a drifted packaged event-profile version and requires the next receipt to fail closed. On the predecessor implementation this second call is skipped by the populated cache.e3a128c9fe59f3c630e3d037c0bd9d0bdc1b669cremoves the process-lifetimelru_cache; every receipt now reloads and validates both packaged profile identities/link/media type immediately before minting receipt evidence.238773711aec5c22482fa073ccf3e73a0878d812records the defect and acceptance boundary indocs/product-technical-gap-baseline.md. No schema, event payload, truth, bitemporal semantics, authority boundary, media type, product ownership, or provider-specific runtime mechanic changed.e3a128c9...immediately after the production repair had zero Actions runs, and the documentation movement invalidates even hypothetical predecessor evidence. Current exact head therefore has no remote GREEN claim..github#712has been refreshed with the exact materialization evidence.The immediately preceding repair remains inherited: RED
aaa9d5c6417cf99d2c4b27e3b86faaadb7ad29e3-> productionfdaf5a94bc0504a221c3a06166da733621fd4980binds the exact runner-visible event profile to its v1 ID/version before vectors execute. Earlier repairs bind the message profile's own v1 identity/media type, its referenced event-profile ID/version, immutable admission receipt construction, event/data identity, strict structured media admission, all-six-status provenance semantics and package inventory.Truth / authority
Foreign
observed,inferred, andproposedevidence retains its producer source.authoritative,superseded, andrejectedremain owner-controlled. Adapters retain the supplied disposition exactly; no producer or consumer may promote analysis/risk/model output into another bounded context's authoritative fact. Canonical references, bitemporal intervals and typed provenance remain Shared Kernel contract semantics rather than application/store/workflow ownership.EA / quarantine handoff
Quarantine Sandbox Runtime remains an independently deployable reusable hostile-workload isolation and artifact-analysis evidence authority. contextual-orchestrator owns caller/application/task/tool authorization and user-visible actions; Wardnet owns maliciousness/SOC verdicts and incidents. EA may project only architecture-relevant runtime/service/API/backend/technology/lifecycle/ownership/remediation/transformation/attestation context after a protected immutable CGC release carries compatible schema/event-profile/message-profile/admission/conformance/package/SBOM/provenance/source identity.
malware_verdict,artifact_risk_score, direct database coupling and source copy remain prohibited as EA authoritative coupling.Governance / integration discipline
Fresh repository metadata still reports
default_branch=develop; protecteddevelop@99cb5468ba3c15c5e79688f53dee74724fae2d13and byte-identical unprotectedmain@99cb5468ba3c15c5e79688f53dee74724fae2d13remain the live branch topology. Neither integration ref currently contains.github/workflows, while this PR head containsci.yml,receipt-package-smoke.yml,reproducibility.yml, andsupply-chain.yml. Effective organization ruleset18156473still follows~DEFAULT_BRANCHwith barerequired_approving_review_count=1, no named required reviewer/code-owner/last-push approval, required thread resolution/central workflows/deletion/non-fast-forward protection, and routineOrganizationAdmin/alwaysbypass..github#1137owns protect-main-first -> safe default switch -> effective~DEFAULT_BRANCHreread..github#772owns replacement of only the structurally impossible solo-maintainer approval count/routine bypass while deterministic gates remain fail closed..github#712owns workflow/materialization/dispatch defects. Central owner PR.github#1644@e35cdc5d6527dfa8634654719a6c3681f16ed82aremains Draft; its current receipt states that live rules/default/protection settings were not mutated and privileged owner-plane apply remains disabled until protected source plus the least-privilege Administration-write environment are available.After central convergence, rebuild dependency-root first from fresh protected
main, non-force restack descendants while preserving only each valid delta, and reacquire every exact-source CI/security/conformance/package/SBOM/provenance/review artifact. No self-approval, synthetic reviewer, routine bypass, force-push/destructive rebase, stale evidence, mutable-PR release authority, source copy or cross-service SQL is authorized.