Skip to content

feat(workforce-validation): establish governed validity-study registry boundary - #235

Draft
seonghobae wants to merge 599 commits into
developfrom
feat/workforce-validation-registry-boundary
Draft

seonghobae wants to merge 599 commits into
developfrom
feat/workforce-validation-registry-boundary

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

Current exact-head authority — 2026-09-21

Protected base remains develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f. Current head is 202d9d87d6a45529497279b881169aab127727f8; this PR is open · Draft · mechanically mergeable. All changes remain ordinary-forward. No force-push, destructive rebase, self-approval, administrator bypass, predecessor-verdict transfer or gate weakening is authorized.

Canonical boundary

Issue #234 owns the P0/FR-007 Workforce Validation owner-to-buyer gap. This lane remains the canonical workforce_validation in-process application/service owner. #248 is the durable persistence child; #426 owns governed/idempotent registration/lifecycle after durable persistence; #425 owns scientific design lineage after #426; #427 owns the buyer HTTP/OpenAPI boundary after #425.

Fresh live review corrected the former assumption that #428 was simply the next UI source lane. There is already an existing Validation presentation owner: #145 (feat/ui: add governed validation dashboard states) on the separate UI stack #53#130#145. #428 now owns only the later commercial convergence of protected/released #145 with protected/released #427.

Therefore the owner graph is:

Nothing in #145/#428 authorizes expanding this mutable parent into transport/UI. Later product lanes consume only protected/released contracts; they never import this branch, service internals or owner tables directly. Scientific #57 remains an independent leaf and is not a mutable source prerequisite for #248.

The application read model remains deliberately narrower than #426. ValidityStudyRecord.study_status_code currently validates only an exact lower-snake-case stored code; no executable versioned lifecycle vocabulary or transition policy exists here. recorded_from / recorded_to are system-recorded bitemporal knowledge time, not business lifecycle state.

Current ordinary-forward repairs

01c3da48b1d013b57ea749bfb4284d314e3ff3a6 resolved the lifecycle docs-to-code contradiction: study_status_code now documents only the executable truth and does not infer lifecycle governance. Actual governed vocabulary/transition authority remains #426 scope.

Hosted Foundation on predecessor 03bf5040e7eb307c4df55ebd01453dcbd1ae0cef then exposed a separate reality RED. All substantive Workforce Validation execution passed before the final repository-cleanliness gate: 1,441 tests, 5,186/5,186 owned statements, 1,116/1,116 branches and isolated PostgreSQL contracts. The job failed only at Prove validation is read-only: tracked diff was clean but wheel acceptance had generated untracked build output in the checkout. Those counts are predecessor evidence only.

202d9d87d6a45529497279b881169aab127727f8 repairs that test causally instead of weakening the gate or hiding build/: Keyverse and Workforce Validation package sources are copied to a pytest temporary build area and wheel construction runs only against those disposable copies. The checkout remains evidence input, not build workspace.

Retained owner/scientific invariants

#411#424 remain active owner/provenance/currentness/authorization/view-integrity/scientific-reproducibility dependencies. #423 rejects material final-weight adjustment families without governed released/versioned owner evidence. #424 requires every admitted governed adjustment to have an exact one-based contiguous component binding. Resolver-issued public views remain non-tuple and closure-private-issued; proof/runtime seals are not durable authorization; consequential downstream actions re-authorize and re-resolve owner truth.

Ten earlier github-code-quality findings alleging unused successor_* locals were re-read against actual supersession dataflow. Each value is consumed in returned successor fields or, for successor_correction, the contiguous-correction invariant; they were false positives and their threads were resolved without source churn.

Evidence boundary

No predecessor verdict transfers after the last material source write. Fresh exact-head workflows remain non-terminal at the latest read:

  • Foundation CI 35507388584 — queued;
  • Security Scan 35507388575 — queued;
  • SAST Semgrep 35507388588 — queued;
  • CodeQL PR 35507388573 — pending.

Review inventory has no qualifying independent APPROVED; visible inline threads are resolved. The older Node action-runtime warning remains owned by #339/#340 rather than being suppressed/copied here.

This PR stays Draft until this exact head has terminal functional GREEN, 100% owned statement/branch/docstring/edge evidence, pinned installed-wheel acceptance, deterministic repository/manifest validation, isolated PostgreSQL owner-schema evidence, terminal Foundation/Security/SAST/CodeQL/model-review evidence, resolved review threads and then-live non-bypass review governance. No merge, immutable release or release-ready claim is made.

@coderabbitai

coderabbitai Bot commented Sep 5, 2026

Copy link
Copy Markdown

Review Change StackReview Change Stack

📝 Walkthrough

Walkthrough

Changes

workforce_validation 서비스 기반과 소유 스키마

Layer / File(s) Summary
서비스 계약과 패키지 설정
services/workforce-validation-api/README.md, services/workforce-validation-api/pyproject.toml, services/workforce-validation-api/src/...
workforce_validation 경계, Python 패키지 설정, 공개 계약 재내보내기를 추가했습니다.
PostgreSQL 소유 스키마
services/workforce-validation-api/database/migrations/0001_owner_schema.sql, tests/test_workforce_validation_owner_schema_postgres.sh
NOLOGIN 역할과 workforce_validation 스키마를 생성하고 PUBLIC 권한과 초기 관계 생성을 검증합니다.
Foundation CI 연결
.github/workflows/foundation-ci.yml, scripts/foundation-contract-core.mjs, tests/validate_repository.py, manifest.json
서비스 pytest와 PostgreSQL 계약 테스트를 CI에 등록하고 새 테스트 스크립트를 필수 아티팩트로 지정했습니다.

검증 연구 레지스트리

Layer / File(s) Summary
레지스트리 읽기 경계
services/workforce-validation-api/src/.../registry.py, services/workforce-validation-api/tests/test_registry.py
ValidationPrincipal, ValidityStudyRecord, 읽기 포트와 필드 최소화 뷰를 추가했습니다. 목적 기반 접근 승인 후 저장소를 조회하고, 비정상 결과와 위조된 식별자를 거부합니다.
런타임 무결성 회귀 테스트
services/workforce-validation-api/tests/test_*integrity.py, services/workforce-validation-api/tests/test_uuid_*.py
정책 하위 타입, 정적 read capability, UUID 저장 분리, 직접 뷰 생성을 검증합니다.

Authority 해석기

Layer / File(s) Summary
Authority 레코드와 해석기
services/workforce-validation-api/src/.../*authority.py, services/workforce-validation-api/src/.../result_nonverifiability.py
보정·무응답·trimming/bounding·가중치·분산·검증 결과 권한의 불변 레코드, 읽기 포트, 예외, 해석기를 추가했습니다. 해석기는 목적 기반 접근을 먼저 수행하고, owner evidence의 좌표와 출시 시각을 재검증한 뒤 최소 필드 뷰를 반환합니다.
계약 테스트
services/workforce-validation-api/tests/test_*authority*.py, services/workforce-validation-api/tests/test_validation_result_*.py
정상 조회, 접근 거부 순서, 누락·비정규 증거, 좌표 불일치, 시간 순서, digest aliasing, 입력 형식, 불변성 및 UUID 분리를 검증합니다.

Priority: ➖ Normal

Estimated code review effort: 5 (Critical) | ~90 minutes

Sequence Diagram(s)

sequenceDiagram
  participant Caller
  participant AuthorityResolver
  participant PurposeBoundAccess
  participant OwnerReadPort
  Caller->>AuthorityResolver: authority 좌표와 used_at 전달
  AuthorityResolver->>PurposeBoundAccess: 목적·리소스·필드 접근 평가
  PurposeBoundAccess-->>AuthorityResolver: 승인 또는 거부
  AuthorityResolver->>OwnerReadPort: 요청 좌표로 출시 증거 조회
  OwnerReadPort-->>AuthorityResolver: authority record 또는 None
  AuthorityResolver-->>Caller: 검증된 최소화 view 또는 오류
Loading

Merge Risk: 🟡 Moderate · up to f23e1

These contract defects can authorize overlapping validation results or reject valid weight/variance evidence. They should be corrected before merge.

🚥 Pre-merge checks | ✅ 3 | ❌ 2

❌ Failed checks (1 warning, 1 inconclusive)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 55.60% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 687 functions across 54 files. (1 skipped… Write docstrings for the functions missing them to satisfy the coverage threshold.
Linked Issues check ❓ Inconclusive PR 설명은 #248을 후속 영속성 작업으로 언급합니다. 그러나 연결된 이슈의 존재, 상태, 요구사항 충족 여부를 확인할 수 있는 상세 정보는 제공되지 않았습니다. 연결된 이슈의 식별자와 상태를 제공하고, 이 PR의 범위 및 #248과의 경계를 확인하십시오.
✅ Passed checks (3 passed)
Check name Status Explanation
Out of Scope Changes check ✅ Passed 서비스 코드, 계약 테스트, Foundation CI, manifest, PostgreSQL 소유자 스키마 검사가 모두 PR 목표에 포함됩니다. 영속 상태 구현은 명시적으로 후속 작업으로 제외되어 범위가 일관됩니다.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed 제목은 workforce-validation 서비스의 governed validity-study registry boundary 구축이라는 PR의 핵심 목적을 정확히 설명합니다. 간결하고 구체적이며 변경 사항과 관련됩니다.
Full details: Docstring Coverage

Explanation

Docstring coverage is 55.60% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 687 functions across 54 files. (1 skipped: 1 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

Please review exact head b59f9cadfab1d4571efd62d805b9d319f9cb9741 against protected develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f. Focus on Issue #234: DDD ownership, purpose-before-persistence authorization, field minimization, exact tenant/study binding, executable-subtype/callback boundaries, timestamp detachment, and whether this application slice accidentally normalizes the legacy public schema as a service contract. Do not treat declared 100% coverage as evidence until the service is admitted to Foundation CI.

@coderabbitai

coderabbitai Bot commented Sep 5, 2026

Copy link
Copy Markdown
🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

base="eb9757f8649aaad026a9865508d9aad50c1a7a4f"
head="b59f9cadfab1d4571efd62d805b9d319f9cb9741"

echo "== Exact commits =="
git show -s --format='%H%n%P%n%s' "$base"
git show -s --format='%H%n%P%n%s' "$head"
echo "== Merge base =="
git merge-base "$base" "$head"

echo "== Changed files =="
git diff --name-status "$base" "$head"

echo "== Diff summary =="
git diff --stat "$base" "$head"

echo "== Candidate outlines =="
git diff --name-only "$base" "$head" | while IFS= read -r file; do
  case "$file" in
    *.py)
      echo "--- $file"
      ast-grep outline "$file" --items all 2>/dev/null || true
      ;;
  esac
done

echo "== Relevant documentation/CI references =="
rg -n -i -C 3 \
  'workforce_validation|validity.study|validity_study|foundation-ci|pytest|coverage|public\.' \
  .github ARCHITECTURE.md README.md 2>/dev/null || true

Length of output: 22416


🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo "== Changed package contents =="
for file in \
  services/workforce-validation-api/src/orgmetra_workforce_validation_api/registry.py \
  services/workforce-validation-api/src/orgmetra_workforce_validation_api/__init__.py \
  services/workforce-validation-api/tests/test_registry.py \
  services/workforce-validation-api/pyproject.toml \
  services/workforce-validation-api/README.md
do
  echo "--- $file"
  cat -n "$file"
done

echo "== Keyverse authorization API candidates =="
fd -t f . packages/keyverse-adapter | sort
ast-grep outline packages/keyverse-adapter/src --items all 2>/dev/null || true
rg -n -C 5 \
  'class PurposeBoundAccess|def require_purpose_bound_access|AuthorizationDeniedError|PurposeBoundAccessRequest|runtime_checkable' \
  packages/keyverse-adapter/src packages/keyverse-adapter/tests

echo "== Foundation CI unit-test and install steps =="
sed -n '35,75p' .github/workflows/foundation-ci.yml

echo "== Existing service port patterns =="
rg -n -C 4 \
  '`@runtime_checkable`|class .*ReadPort\(Protocol\)|isinstance\(.*Port|def read_.*\(' \
  services/job-analysis-api/src services/people-api/src 2>/dev/null || true

Length of output: 65327


🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo "== Validity-study schema and migration references =="
rg -n -i -C 8 \
  'create table.*validity|validity_study|criterion_blueprint|recorded_from|recorded_to|study_status_code' \
  -g '*.sql' -g '*.md' -g '*.py' . \
  | head -n 800

echo "== Keyverse authorization implementation =="
sed -n '1,330p' packages/keyverse-adapter/src/orgmetra_keyverse_adapter/authorization.py

echo "== Comparable port validation helpers and read functions =="
sed -n '70,160p' services/people-api/src/orgmetra_people_api/people.py
sed -n '330,510p' services/job-analysis-api/src/orgmetra_job_analysis_api/snapshot.py

echo "== Complete changed-diff scan for persistence/schema dependencies =="
git diff --unified=40 eb9757f8649aaad026a9865508d9aad50c1a7a4f b59f9cadfab1d4571efd62d805b9d319f9cb9741 \
  -- services/workforce-validation-api \
  | rg -n -i -C 3 'public|postgres|sql|schema|select|insert|validity_study|read_port|callable|timezone|zoneinfo'

Length of output: 143503


🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo "== Base validity_study table definition =="
rg -n -i -A 80 -B 5 'CREATE TABLE validity_study\s*\(' database/migrations -g '*.sql'

echo "== Repository inventory validation mechanism =="
sed -n '1,130p' tests/validate_repository.py
rg -n -C 3 \
  'manifest\.json|REQUIRED|EXPECTED|inventory|services/job-analysis-api|services/people-api|workforce-validation' \
  tests scripts package.json .github/workflows/foundation-ci.yml \
  -g '*.py' -g '*.mjs' -g '*.json' -g '*.yml'

echo "== New package references outside its own directory =="
rg -n -C 2 \
  'workforce-validation-api|orgmetra_workforce_validation_api' \
  . \
  -g '!services/workforce-validation-api/**'

echo "== Current CI workflow context around unit commands =="
nl -ba .github/workflows/foundation-ci.yml | sed -n '52,74p'

Length of output: 36146


@seonghobae I reviewed exact head b59f9cadfab1d4571efd62d805b9d319f9cb9741 against protected develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f.

I found two blocking issues:

  1. P1 — Foundation CI does not execute this service contract.
    .github/workflows/foundation-ci.yml Lines 59-70 compiles all services, but it has no pytest command for services/workforce-validation-api. The declared --cov-fail-under=100 setting is therefore not hosted test evidence. Add the documented command, with both source paths in PYTHONPATH, to the canonical unit and service contract step. Do not mark this PR Ready or merge it until the exact head is GREEN with that command.

  2. P1 — Reject a non-callable read port before authorization.
    services/workforce-validation-api/src/orgmetra_workforce_validation_api/registry.py Line 190 checks only structural ValidityStudyReadPort membership. A value with read_validity_study = None can satisfy that shallow runtime protocol check. The code then completes authorization and fails at Line 214 with a generic call error. Validate callable(read_port.read_validity_study) together with the protocol check. Add a regression test that proves this invalid dependency fails before authorization and before any repository access.

The remaining requested boundary checks are sound in the reviewed slice:

  • The package introduces no SQL adapter and no direct public schema contract.
  • ValidityStudyRecord matches the protected validity_study header scalar set.
  • Authorization precedes the repository call.
  • The request binds the active tenant, principal tenant, resource tenant, and exact study UUID.
  • The returned view contains only requested fields that the policy authorizes.
  • A returned record for another tenant or study fails closed.
  • Exact ValidityStudyRecord and datetime checks prevent untrusted subclasses from crossing the boundary.
  • Timestamps are detached to UTC and only accept standard-library timezone or ZoneInfo providers.
⚠️ Action not completed

Head commit changed.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

Current exact head moved to 3fe809250c86b328dedf3cb46c3d5953966cfc72. Please review that head against protected develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f; predecessor b59f9cad... review evidence is stale. In addition to the prior #234 focus, verify the b22383c...3fe80925... test-first repair rejects executable policy scalar subtypes before any comparison/hash or persistence and that detached exact policy evidence preserves the protected Keyverse authorization semantics.

@coderabbitai

coderabbitai Bot commented Sep 5, 2026

Copy link
Copy Markdown

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

base="eb9757f8649aaad026a9865508d9aad50c1a7a4f"
prior="b59f9cadfab1d4571efd62d805b9d319f9cb9741"
test_first="b22383c27ec3da6c8111e78fc862363e84399822"
head="3fe809250c86b328dedf3cb46c3d5953966cfc72"

echo "== Exact commit identity and ancestry =="
for commit in "$base" "$prior" "$test_first" "$head"; do
  git show -s --format='%H%n%P%n%s%n' "$commit"
done
echo "merge-base:"
git merge-base "$base" "$head"
echo "base ancestor of head:"
git merge-base --is-ancestor "$base" "$head" && echo yes
echo "test-first ancestor of head:"
git merge-base --is-ancestor "$test_first" "$head" && echo yes

echo "== Changed files from protected base to exact head =="
git diff --name-status "$base" "$head"
echo "== Repair diff =="
git diff --stat "$test_first" "$head"
git diff --unified=80 "$test_first" "$head" -- \
  services/workforce-validation-api \
  packages/keyverse-adapter

echo "== Changed Python outlines =="
git diff --name-only "$base" "$head" | while IFS= read -r file; do
  case "$file" in
    *.py)
      echo "--- $file"
      ast-grep outline "$file" --items all || true
      ;;
  esac
done

echo "== Registry, tests, package definition, and CI =="
for file in \
  services/workforce-validation-api/src/orgmetra_workforce_validation_api/registry.py \
  services/workforce-validation-api/tests/test_registry.py \
  services/workforce-validation-api/pyproject.toml \
  services/workforce-validation-api/README.md \
  .github/workflows/foundation-ci.yml
do
  if [ -f "$file" ]; then
    echo "--- $file"
    cat -n "$file"
  fi
done

echo "== Keyverse authorization contract =="
fd -t f . packages/keyverse-adapter/src | sort
rg -n -C 8 \
  'class PurposeBoundAccess|def require_purpose_bound_access|PurposeBoundAccessRequest|AuthorizationDeniedError' \
  packages/keyverse-adapter/src

Length of output: 71392


🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo "== Executable-policy regression test =="
cat -n services/workforce-validation-api/tests/test_policy_runtime_integrity.py

echo "== Complete Keyverse evaluator =="
sed -n '1,340p' packages/keyverse-adapter/src/orgmetra_keyverse_adapter/authorization.py

echo "== Owner package exports and all direct dependency imports =="
cat -n services/workforce-validation-api/src/orgmetra_workforce_validation_api/__init__.py
rg -n -C 3 \
  '^(from|import) |public\.|SELECT |INSERT |UPDATE |DELETE |psycopg|sqlalchemy|database|postgres|people|talent|performance|job_analysis|psychometric|fast_mlsirm|tepp' \
  services/workforce-validation-api

echo "== Architecture and protected table evidence =="
rg -n -i -C 6 \
  'workforce_validation|validity_study|CREATE TABLE validity_study|CREATE TABLE.*validity_study' \
  ARCHITECTURE.md database/migrations -g '*.md' -g '*.sql'

echo "== Read-port runtime protocol behavior test shape =="
python - <<'PY'
from typing import Protocol, runtime_checkable

`@runtime_checkable`
class Port(Protocol):
    def read_validity_study(self) -> object: ...

class NonCallable:
    read_validity_study = None

print(isinstance(NonCallable(), Port))
PY

Length of output: 61765


@seonghobae I reviewed exact head 3fe809250c86b328dedf3cb46c3d5953966cfc72 against protected develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f.

I found one blocking issue.

  1. P1 — Foundation CI does not execute the new service tests.
    .github/workflows/foundation-ci.yml Lines 59-70 omit the documented services/workforce-validation-api pytest command. The package declares 100% coverage, but the hosted workflow does not run its tests. Add the command with both required source paths in PYTHONPATH. Keep this PR Draft. Do not merge until Foundation CI executes the service tests and the exact head is GREEN.

The requested boundary checks are correct in this head:

  • The package has no SQL adapter and no public schema contract.
  • ValidityStudyRecord matches the protected validity_study header fields.
  • Authorization completes before the read port is called.
  • The request binds the active tenant, authenticated tenant, resource tenant, and exact study UUID.
  • The response returns only requested fields that the policy permits.
  • Foreign tenant and foreign study results fail closed.
  • Timestamp values accept only exact datetime values with timezone or ZoneInfo, then detach to UTC.
  • _detach_policy(...) snapshots all policy attributes, requires exact inert UUID, str, and frozenset values, and reconstructs PurposeBoundAccessPolicy before Keyverse evaluates it.
  • The regression test proves a custom policy str subtype cannot invoke __ne__ and cannot reach persistence.
  • The reconstructed policy preserves the same Keyverse tenant, version, resource, purpose, operation, scope, and field inputs. It does not change authorization semantics for valid exact values.

The prior read-port finding does not apply to this runtime. The @runtime_checkable protocol check rejects an object where read_validity_study = None. I withdraw that predecessor finding.

You are interacting with an AI system.

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

Please review exact current head b609b0a46b835e4ba4c7f46f51088c5673dcbdb7 against protected develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f. Focus on #236 structural immutability, the new Foundation inventory/test command, purpose-before-persistence authorization, exact runtime evidence, and whether any unrelated gate or manifest contract was weakened. Do not treat predecessor reviews as current-head evidence.

@coderabbitai

coderabbitai Bot commented Sep 5, 2026

Copy link
Copy Markdown

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

base="eb9757f8649aaad026a9865508d9aad50c1a7a4f"
head="b609b0a46b835e4ba4c7f46f51088c5673dcbdb7"

echo "== Commit identity and ancestry =="
git show -s --format='commit=%H%nparents=%P%nsubject=%s' "$base"
git show -s --format='commit=%H%nparents=%P%nsubject=%s' "$head"
echo "merge_base=$(git merge-base "$base" "$head")"
git merge-base --is-ancestor "$base" "$head" && echo "base_is_ancestor=yes"

echo "== Changed files =="
git diff --name-status "$base" "$head"
echo "== Diff summary =="
git diff --stat "$base" "$head"

echo "== Changed Python outlines =="
git diff --name-only "$base" "$head" | while IFS= read -r file; do
  case "$file" in
    *.py)
      echo "--- $file"
      ast-grep outline "$file" --items all 2>/dev/null || true
      ;;
  esac
done

echo "== Exact full diff for service, workflow, and inventory-related files =="
git diff --unified=80 "$base" "$head" -- \
  services/workforce-validation-api \
  .github/workflows/foundation-ci.yml \
  tests/validate_repository.py \
  package.json \
  manifest.json \
  | sed -n '1,5000p'

echo "== Locate repository inventory and Foundation test contracts =="
rg -n -i -C 6 \
  'workforce-validation|workforce_validation|foundation-ci|pytest|PYTHONPATH|manifest|inventory|required|expected' \
  .github tests scripts package.json \
  -g '*.py' -g '*.json' -g '*.yml' -g '*.yaml' -g '*.mjs' \
  | sed -n '1,5000p'

echo "== Current relevant files =="
for file in \
  services/workforce-validation-api/src/orgmetra_workforce_validation_api/registry.py \
  services/workforce-validation-api/tests/test_registry.py \
  services/workforce-validation-api/tests/test_policy_runtime_integrity.py \
  services/workforce-validation-api/pyproject.toml \
  .github/workflows/foundation-ci.yml \
  tests/validate_repository.py
do
  if [ -f "$file" ]; then
    echo "--- $file"
    cat -n "$file"
  fi
done

Length of output: 194155


🏁 Script executed:

#!/bin/bash
set -euo pipefail

base="eb9757f8649aaad026a9865508d9aad50c1a7a4f"
head="b609b0a46b835e4ba4c7f46f51088c5673dcbdb7"

echo "== Head commit and immediate `#236` patch =="
git show --format=fuller --stat "$head"
git show --format=fuller --unified=120 "$head" -- \
  services/workforce-validation-api/src/orgmetra_workforce_validation_api/registry.py \
  services/workforce-validation-api/tests/test_registry.py \
  tests/test_foundation_ci_dependency_hygiene.sh \
  .github/workflows/foundation-ci.yml

echo "== Complete Foundation CI dependency-hygiene contract =="
cat -n tests/test_foundation_ci_dependency_hygiene.sh

echo "== Base-to-head diff for the hygiene contract =="
git diff --unified=100 "$base" "$head" -- tests/test_foundation_ci_dependency_hygiene.sh

echo "== All Foundation CI test commands and hygiene assertions =="
rg -n -C 4 \
  'PYTHONPATH=|python -m pytest|workforce-validation|candidate-evidence|keyverse-adapter|foundation-test' \
  .github/workflows/foundation-ci.yml \
  tests/test_foundation_ci_dependency_hygiene.sh \
  .github/requirements/foundation-test.txt

echo "== Keyverse policy construction and evaluation =="
ast-grep outline packages/keyverse-adapter/src --items all 2>/dev/null || true
rg -n -C 12 \
  'class PurposeBoundAccessPolicy|class PurposeBoundAccessRequest|def require_purpose_bound_access|AuthorizationDeniedError|permitted_fields|policy_version_code' \
  packages/keyverse-adapter/src \
  -g '*.py'

echo "== Service persistence, schema, and dependency references =="
rg -n -i -C 3 \
  'public\.|postgres|psycopg|sqlalchemy|\bselect\b|\binsert\b|\bupdate\b|\bdelete\b|database|schema|read_validity_study' \
  services/workforce-validation-api \
  -g '*.py' -g '*.md' -g '*.toml'

echo "== Changed non-service files and gate removals =="
git diff --unified=20 "$base" "$head" -- .github/workflows/foundation-ci.yml tests/test_foundation_ci_dependency_hygiene.sh
git diff --name-only "$base" "$head" | while IFS= read -r file; do
  case "$file" in
    .github/*|tests/*|scripts/*|package.json|manifest.json)
      echo "--- $file"
      git diff --numstat "$base" "$head" -- "$file"
      ;;
  esac
done

Length of output: 77396


🏁 Script executed:

#!/bin/bash
set -euo pipefail

base="eb9757f8649aaad026a9865508d9aad50c1a7a4f"
head="b609b0a46b835e4ba4c7f46f51088c5673dcbdb7"
workflow=".github/workflows/foundation-ci.yml"

echo "== Manifest changed in exact range? =="
git diff --name-status "$base" "$head" -- manifest.json

echo "== Checked-in manifest entry =="
jq -c --arg path "$workflow" '.files[] | select(.path == $path)' manifest.json

echo "== Current workflow metadata =="
printf 'sha256='
sha256sum "$workflow" | awk '{print $1}'
printf 'bytes='
wc -c < "$workflow" | tr -d ' '
printf '\nlines='
awk 'END { print NR }' "$workflow"

echo "== Base workflow manifest metadata =="
git show "$base:$workflow" | sha256sum | awk '{print "base_sha256=" $1}'
git show "$base:$workflow" | wc -c | tr -d ' ' | sed 's/^/base_bytes=/'
git show "$base:$workflow" | awk 'END { print "base_lines=" NR }'

echo "== Required-list and manifest validation logic around the workflow =="
rg -n -C 3 --fixed-strings "$workflow" tests/validate_repository.py scripts/foundation-contract-core.mjs
sed -n '179,202p' tests/validate_repository.py

Length of output: 3837


@seonghobae I reviewed exact head b609b0a46b835e4ba4c7f46f51088c5673dcbdb7 against protected develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f.

I found one blocking issue.

  1. P1 — The Foundation manifest is stale, so CI fails before it runs the new service tests.
    .github/workflows/foundation-ci.yml Line 71 correctly adds the workforce-validation pytest command. However, this workflow is a required manifest artifact. manifest.json still records the base workflow metadata: 6651 bytes, 125 lines, and SHA-256 b6a436.... The current workflow is 6911 bytes, 126 lines, and SHA-256 80b9e4.... npm run validate calls tests/validate_repository.py, which rejects this mismatch at the Foundation validation step before Line 71 can run. Regenerate and commit the exact manifest data for the current workflow. Do not treat the new coverage declaration or command as GREEN evidence until the exact head passes hosted Foundation CI.

The requested current-head checks are otherwise sound:

  • ValidityStudyRecord is tuple-backed with __slots__ = (). The new test proves that object.__setattr__ cannot change a record field.
  • The boundary rejects a non-exact persisted ValidityStudyRecord before it reconstructs response evidence.
  • The service validates request inputs and detaches policy evidence before require_purpose_bound_access(...).
  • Authorization occurs before ValidityStudyReadPort.read_validity_study(...).
  • The request binds the active tenant, principal tenant, resource tenant, and exact study UUID.
  • The view returns only requested fields after authorization.
  • The package introduces no SQL adapter and no public-schema service contract.
  • The Foundation dependency-hygiene test adds the new service source path without removing prior source-path requirements or weakening the locked test-toolchain checks.

You are interacting with an AI system.

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

Please review exact current head cf498b96c0308e5037ebe11441e77c3677b0bdac against protected develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f. This supersedes the stale b609b0a... request only for review scope. Focus on #236 structural immutability, Foundation service-test admission plus matching manifest seal, code-current README, purpose-before-persistence authorization, exact runtime evidence, and any unrelated gate/manifest weakening. Do not promote predecessor review evidence.

@coderabbitai

coderabbitai Bot commented Sep 5, 2026

Copy link
Copy Markdown

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

base="eb9757f8649aaad026a9865508d9aad50c1a7a4f"
head="cf498b96c0308e5037ebe11441e77c3677b0bdac"

echo "== Commit identity and ancestry =="
git show -s --format='commit=%H%nparents=%P%nsubject=%s' "$base"
git show -s --format='commit=%H%nparents=%P%nsubject=%s' "$head"
printf 'merge_base='
git merge-base "$base" "$head"
git merge-base --is-ancestor "$base" "$head" && echo "base_is_ancestor=yes"

echo "== Changed files and diff summary =="
git diff --name-status "$base" "$head"
git diff --stat "$base" "$head"

echo "== Full exact-range diff for review scope =="
git diff --unified=100 "$base" "$head" -- \
  services/workforce-validation-api \
  .github/workflows/foundation-ci.yml \
  manifest.json \
  tests/validate_repository.py \
  tests/test_foundation_ci_dependency_hygiene.sh \
  .github/requirements/foundation-test.txt \
  package.json \
  | sed -n '1,9000p'

echo "== Changed Python outlines =="
git diff --name-only "$base" "$head" | while IFS= read -r file; do
  case "$file" in
    *.py)
      echo "--- $file"
      ast-grep outline "$file" --items all 2>/dev/null || true
      ;;
  esac
done

echo "== Current application, tests, documentation, CI, and manifest =="
for file in \
  services/workforce-validation-api/src/orgmetra_workforce_validation_api/registry.py \
  services/workforce-validation-api/src/orgmetra_workforce_validation_api/__init__.py \
  services/workforce-validation-api/tests/test_registry.py \
  services/workforce-validation-api/tests/test_policy_runtime_integrity.py \
  services/workforce-validation-api/README.md \
  services/workforce-validation-api/pyproject.toml \
  .github/workflows/foundation-ci.yml \
  manifest.json \
  tests/validate_repository.py \
  tests/test_foundation_ci_dependency_hygiene.sh
do
  if [ -f "$file" ]; then
    echo "--- $file"
    cat -n "$file"
  fi
done

echo "== Manifest seal for Foundation workflow =="
workflow=".github/workflows/foundation-ci.yml"
echo "manifest_entry:"
jq -c --arg path "$workflow" '.files[] | select(.path == $path)' manifest.json
echo "current_sha256=$(sha256sum "$workflow" | awk '{print $1}')"
echo "current_bytes=$(wc -c < "$workflow" | tr -d ' ')"
echo "current_lines=$(awk 'END {print NR}' "$workflow")"
echo "base_manifest_entry:"
git show "$base:manifest.json" | jq -c --arg path "$workflow" '.files[] | select(.path == $path)'

echo "== Authorization, persistence, and forbidden dependency scan =="
rg -n -i -C 5 \
  'require_purpose_bound_access|read_validity_study|_detach_policy|ValidityStudyRecord|object\.__setattr__|public\.|postgres|psycopg|sqlalchemy|\bselect\b|\binsert\b|\bupdate\b|\bdelete\b|people-api|job-analysis-api' \
  services/workforce-validation-api \
  packages/keyverse-adapter/src/orgmetra_keyverse_adapter \
  -g '*.py' -g '*.md' -g '*.toml'

echo "== Gate and contract removals in exact range =="
git diff --diff-filter=D --name-status "$base" "$head"
git diff --unified=40 "$base" "$head" -- \
  .github/workflows/foundation-ci.yml \
  tests/test_foundation_ci_dependency_hygiene.sh \
  .github/requirements/foundation-test.txt \
  manifest.json \
  package.json

Length of output: 200831


@seonghobae I reviewed exact head cf498b96c0308e5037ebe11441e77c3677b0bdac against protected develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f.

I found no blocking issue in the requested scope.

  • Foundation CI now runs the workforce-validation tests at .github/workflows/foundation-ci.yml Line 71.
  • The command uses the required direct source paths and a dedicated coverage file.
  • tests/test_foundation_ci_dependency_hygiene.sh Line 21 protects the new source-path contract. Existing path, lockfile, and installation controls remain in place.
  • manifest.json now seals the current workflow. Its SHA-256, byte count, and line count match the checked-in workflow.
  • ValidityStudyRecord is tuple-backed with __slots__ = (). The structural-immutability regression proves that object.__setattr__ cannot modify its evidence.
  • The application validates exact principal, request, policy, persistence-record, UUID, string, field-set, and timestamp evidence.
  • The code detaches policy values before Keyverse authorization.
  • Authorization completes before ValidityStudyReadPort.read_validity_study(...).
  • The code reconstructs repository output as exact immutable evidence. It rejects non-canonical, foreign-tenant, and foreign-study results.
  • The returned view contains only requested authorized fields.
  • The new README matches the current code and workflow. It correctly states that workflow admission is not current-head GREEN evidence.
  • The service contains no SQL adapter and does not establish a public-schema application contract.
  • The exact-range diff adds the service test admission and its integrity assertion. It does not weaken an existing gate or manifest contract.

Hosted CI must still provide terminal results for this exact head. The README states that condition correctly.

You are interacting with an AI system.

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

Please review exact head d264b89dad290887d265a1010ff2622b96f9909a against protected develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f. Focus on Issue #237 authenticated-principal structural immutability, the test-first service-local persistence-layout contract, workforce_validation_role / workforce_validation schema least-privilege semantics, active global migration-number collision avoidance, and whether this slice accidentally creates or normalizes a long-lived public.validity_study contract. Also verify that #236 persisted-record immutability and purpose-before-persistence authorization remain intact. Do not transfer predecessor review or check evidence to this head.

@coderabbitai

coderabbitai Bot commented Sep 5, 2026

Copy link
Copy Markdown

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

base="eb9757f8649aaad026a9865508d9aad50c1a7a4f"
head="d264b89dad290887d265a1010ff2622b96f9909a"

echo "== Commit identity and ancestry =="
git show -s --format='commit=%H%nparents=%P%nsubject=%s' "$base"
git show -s --format='commit=%H%nparents=%P%nsubject=%s' "$head"
printf 'merge_base='
git merge-base "$base" "$head"
git merge-base --is-ancestor "$base" "$head" && echo "base_is_ancestor=yes"

echo "== Exact-range changed files and summary =="
git diff --name-status "$base" "$head"
git diff --stat "$base" "$head"

echo "== Changed Python and SQL outlines =="
git diff --name-only "$base" "$head" | while IFS= read -r file; do
  case "$file" in
    *.py|*.sql)
      echo "--- $file"
      ast-grep outline "$file" --items all 2>/dev/null || true
      ;;
  esac
done

echo "== Exact-range diff for requested scope =="
git diff --unified=100 "$base" "$head" -- \
  services/workforce-validation-api \
  .github/workflows/foundation-ci.yml \
  manifest.json \
  tests/test_foundation_ci_dependency_hygiene.sh \
  tests/validate_repository.py \
  | sed -n '1,10000p'

echo "== Current application, tests, migration, documentation, and CI files =="
for file in \
  services/workforce-validation-api/src/orgmetra_workforce_validation_api/registry.py \
  services/workforce-validation-api/src/orgmetra_workforce_validation_api/__init__.py \
  services/workforce-validation-api/tests/test_registry.py \
  services/workforce-validation-api/tests/test_policy_runtime_integrity.py \
  services/workforce-validation-api/tests/test_principal_runtime_integrity.py \
  services/workforce-validation-api/tests/test_owner_schema_migration.py \
  services/workforce-validation-api/database/migrations/0001_owner_schema.sql \
  services/workforce-validation-api/README.md \
  services/workforce-validation-api/pyproject.toml \
  .github/workflows/foundation-ci.yml \
  manifest.json \
  tests/test_foundation_ci_dependency_hygiene.sh \
  tests/validate_repository.py
do
  if [ -f "$file" ]; then
    echo "--- $file"
    cat -n "$file"
  fi
done

echo "== Service persistence and cross-context dependency scan =="
rg -n -i -C 5 \
  'public\.|validity_study|postgres|psycopg|sqlalchemy|\bselect\b|\binsert\b|\bupdate\b|\bdelete\b|database|schema|read_validity_study|require_purpose_bound_access|object\.__setattr__|ValidationPrincipal|ValidityStudyRecord' \
  services/workforce-validation-api \
  -g '*.py' -g '*.sql' -g '*.md' -g '*.toml'

echo "== Global migration lanes and migration-number inventory =="
fd -t f -e sql . | sort | sed -n '1,3000p'
echo "--- numbered migration filenames ---"
fd -t f -e sql . | rg '/[0-9]{4,}.*\.sql$|/[0-9]+.*\.sql$' | sort | sed -n '1,3000p'

echo "== Architecture and repository migration rules =="
rg -n -i -C 8 \
  'workforce_validation|migration history|migration|public\.validity_study|validity_study|bounded context|schema' \
  ARCHITECTURE.md README.md services/workforce-validation-api/README.md \
  -g '*.md'

echo "== Foundation workflow manifest seal =="
workflow=".github/workflows/foundation-ci.yml"
jq -c --arg path "$workflow" '.files[] | select(.path == $path)' manifest.json
printf 'current_sha256='; sha256sum "$workflow" | awk '{print $1}'
printf 'current_bytes='; wc -c < "$workflow" | tr -d ' '; printf '\n'
printf 'current_lines='; awk 'END {print NR}' "$workflow"

echo "== Deletions and weakening candidates in gate files =="
git diff --diff-filter=D --name-status "$base" "$head"
git diff --unified=60 "$base" "$head" -- \
  .github/workflows/foundation-ci.yml \
  tests/test_foundation_ci_dependency_hygiene.sh \
  tests/validate_repository.py \
  manifest.json

Length of output: 167248


🏁 Script executed:

#!/bin/bash
set -euo pipefail

base="eb9757f8649aaad026a9865508d9aad50c1a7a4f"
prior="cf498b96c0308e5037ebe11441e77c3677b0bdac"
head="d264b89dad290887d265a1010ff2622b96f9909a"

echo "== Increment identity, ancestry, and changed files =="
git show -s --format='commit=%H%nparents=%P%nsubject=%s' "$prior"
git show -s --format='commit=%H%nparents=%P%nsubject=%s' "$head"
git merge-base --is-ancestor "$prior" "$head" && echo "prior_is_ancestor=yes"
git diff --name-status "$prior" "$head"
git diff --stat "$prior" "$head"

echo "== Complete incremental patch =="
git diff --unified=120 "$prior" "$head" -- \
  services/workforce-validation-api \
  .github/workflows/foundation-ci.yml \
  tests/test_foundation_ci_dependency_hygiene.sh \
  manifest.json \
  tests/validate_repository.py

echo "== Owner migration =="
cat -n services/workforce-validation-api/database/migrations/0001_owner_schema.sql

echo "== Persistence-layout contract =="
cat -n services/workforce-validation-api/tests/test_persistence_layout.py

echo "== Registry value objects and authorization order =="
sed -n '1,345p' services/workforce-validation-api/src/orgmetra_workforce_validation_api/registry.py

echo "== Principal and persisted-record regression tests =="
rg -n -A35 -B8 \
  'principal|ValidationPrincipal|structurally_immutable|object\.__setattr__|ValidityStudyRecord|authorization_denial|dependency_and_request' \
  services/workforce-validation-api/tests \
  -g '*.py'

echo "== All service migration and legacy-schema references =="
rg -n -i -C 3 \
  'public\.validity_study|validity_study|CREATE TABLE|ALTER TABLE|SELECT |INSERT |UPDATE |DELETE |GRANT |REVOKE |search_path|CREATE ROLE|CREATE SCHEMA' \
  services/workforce-validation-api \
  -g '*.sql' -g '*.py' -g '*.md'

echo "== Global migration lane modifications in exact range =="
git diff --name-status "$base" "$head" -- database/migrations
git diff --unified=30 "$base" "$head" -- database/migrations

echo "== Gate-file changes from the protected base, excluding additions =="
git diff --word-diff=plain "$base" "$head" -- \
  .github/workflows/foundation-ci.yml \
  tests/test_foundation_ci_dependency_hygiene.sh \
  tests/validate_repository.py \
  manifest.json \
  | sed -n '1,5000p'

Length of output: 120236


@seonghobae I reviewed exact head d264b89dad290887d265a1010ff2622b96f9909a against protected develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f.

I found no blocking issue in the requested scope.

  • ValidationPrincipal is tuple-backed and declares __slots__ = ().
  • Its constructor validates the tenant UUID, actor reference, and scope set before it creates the value.
  • services/workforce-validation-api/tests/test_registry.py verifies that object.__setattr__ cannot modify the retained tenant, actor, or scopes.
  • ValidityStudyRecord remains tuple-backed and structurally immutable.
  • The application still validates and detaches exact input evidence before authorization.
  • read_validity_study(...) calls require_purpose_bound_access(...) before ValidityStudyReadPort.read_validity_study(...).
  • The application still rejects non-canonical, foreign-tenant, and foreign-study persistence results before it returns fields.

The new migration preserves the ownership boundary.

  • services/workforce-validation-api/database/migrations/0001_owner_schema.sql is local to the workforce_validation service.
  • It creates workforce_validation_role with NOLOGIN, NOSUPERUSER, NOCREATEDB, NOCREATEROLE, NOINHERIT, NOREPLICATION, and NOBYPASSRLS.
  • It creates the workforce_validation schema with workforce_validation_role as owner.
  • It revokes all schema privileges from PUBLIC.
  • It sets the role default search path to workforce_validation, pg_catalog.
  • It creates no application table and contains no public.validity_study reference.
  • The service source contains no SQL adapter or legacy public-schema application contract.

The migration-number boundary is correct.

  • The global lane remains database/migrations/0001 through database/migrations/0013.
  • This increment changes no global migration file.
  • The new 0001_owner_schema.sql starts a separate migration history at services/workforce-validation-api/database/migrations/.

The Foundation admission and seal remain intact.

  • .github/workflows/foundation-ci.yml includes the workforce-validation pytest command.
  • tests/test_foundation_ci_dependency_hygiene.sh requires its direct source-tree dependency path.
  • manifest.json matches the current workflow SHA-256, byte count, and line count.
  • The exact-range gate changes add the service command and its hygiene assertion. They do not remove an existing gate.

The new persistence-layout test is a static contract. It does not prove PostgreSQL execution, role membership, or effective privileges in a running database. The README states this limitation correctly. Hosted Foundation results and a PostgreSQL-backed owner-schema acceptance contract remain required for exact-head acceptance.

You are interacting with an AI system.

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

Please review exact head 7ca30f3447169e678269124dbf1fd23180b997b9 against protected develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f. Revalidate #236/#237 structural immutability and purpose-before-persistence, then focus on the new test-first PostgreSQL owner-schema acceptance lane: tests/test_workforce_validation_owner_schema_postgres.sh, canonical Foundation admission, pinned isolated PostgreSQL execution, deny-default role flags, schema ownership/search_path, PUBLIC privilege probe, no premature application tables, and the manifest reseal. Also verify that ordinary successor 83e5c9418f912878f0b829df24c7bf19a11e2b83 fully restores the unrelated 0005_outbox_delivery_finalization.sql seal accidentally changed by a0ccaf0afc1fa26ed979a5181e05c08140f92aff. Do not transfer the predecessor d264b89... review.

@coderabbitai

coderabbitai Bot commented Sep 5, 2026

Copy link
Copy Markdown

Oops, something went wrong! Please try again later. 🐰 💔

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

Please review exact head a04c8b4cd58145f9e74a085d3fdb037d90966012 against protected develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f, with particular attention to #238: PostgreSQL ALTER ROLE ... SET is login-time only and must not be represented as isolation after SET ROLE; the NOLOGIN schema-owner role is now owner-only, the PostgreSQL contract exercises actual SET ROLE search-path behavior, and future runtime access must use a distinct least-privilege role plus schema-qualified relations. Please also verify that #236/#237 structural-immutability and the no-cross-context-SQL boundary remain intact.

@coderabbitai

coderabbitai Bot commented Sep 5, 2026

Copy link
Copy Markdown

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

base="eb9757f8649aaad026a9865508d9aad50c1a7a4f"
head="a04c8b4cd58145f9e74a085d3fdb037d90966012"

echo "== Exact commit identity and ancestry =="
git show -s --format='commit=%H%nparents=%P%nsubject=%s' "$base"
git show -s --format='commit=%H%nparents=%P%nsubject=%s' "$head"
printf 'merge_base='
git merge-base "$base" "$head"
git merge-base --is-ancestor "$base" "$head" && echo "base_is_ancestor=yes"

echo "== Exact-range changed files and summary =="
git diff --name-status "$base" "$head"
git diff --stat "$base" "$head"

echo "== Exact-range diff in requested scope =="
git diff --unified=100 "$base" "$head" -- \
  services/workforce-validation-api \
  tests/test_workforce_validation_owner_schema_postgres.sh \
  .github/workflows/foundation-ci.yml \
  manifest.json \
  tests/test_foundation_ci_dependency_hygiene.sh \
  tests/validate_repository.py \
  | sed -n '1,12000p'

echo "== Current relevant files =="
for file in \
  services/workforce-validation-api/database/migrations/0001_owner_schema.sql \
  services/workforce-validation-api/src/orgmetra_workforce_validation_api/registry.py \
  services/workforce-validation-api/src/orgmetra_workforce_validation_api/__init__.py \
  services/workforce-validation-api/tests/test_registry.py \
  services/workforce-validation-api/tests/test_policy_runtime_integrity.py \
  services/workforce-validation-api/tests/test_principal_runtime_integrity.py \
  services/workforce-validation-api/tests/test_persistence_layout.py \
  services/workforce-validation-api/README.md \
  services/workforce-validation-api/pyproject.toml \
  tests/test_workforce_validation_owner_schema_postgres.sh \
  .github/workflows/foundation-ci.yml \
  tests/test_foundation_ci_dependency_hygiene.sh \
  manifest.json
do
  if [ -f "$file" ]; then
    echo "--- $file"
    cat -n "$file"
  fi
done

echo "== Manifest verification for every changed manifest-tracked file =="
python - <<'PY'
import hashlib
import json
import subprocess

base = "eb9757f8649aaad026a9865508d9aad50c1a7a4f"
head = "a04c8b4cd58145f9e74a085d3fdb037d90966012"
manifest = json.load(open("manifest.json", encoding="utf-8"))
entries = {item["path"]: item for item in manifest.get("files", [])}
changed = subprocess.check_output(
    ["git", "diff", "--name-only", base, head], text=True
).splitlines()
for path in changed:
    if path in entries:
        data = open(path, "rb").read()
        entry = entries[path]
        print(f"path={path}")
        print(f" manifest={json.dumps(entry, sort_keys=True)}")
        print(f" sha256={hashlib.sha256(data).hexdigest()} bytes={len(data)} lines={data.count(b'\\n')}")
PY

echo "== PostgreSQL role/search_path semantics and contract assertions =="
rg -n -i -C 8 \
  'ALTER ROLE|SET ROLE|SET\s+search_path|SHOW\s+search_path|current_setting|NOLOGIN|NOINHERIT|NOBYPASSRLS|CREATE ROLE|CREATE SCHEMA|GRANT|REVOKE|PUBLIC|schema-qualified|pg_catalog|workforce_validation_role|workforce_validation' \
  services/workforce-validation-api tests/test_workforce_validation_owner_schema_postgres.sh \
  -g '*.sql' -g '*.sh' -g '*.md' -g '*.py' -g '*.yml'

echo "== Service persistence and cross-context SQL scan =="
rg -n -i -C 4 \
  'public\.|validity_study|postgres|psycopg|sqlalchemy|\bselect\b|\binsert\b|\bupdate\b|\bdelete\b|database|schema|read_validity_study|require_purpose_bound_access|ValidationPrincipal|ValidityStudyRecord|object\.__setattr__' \
  services/workforce-validation-api \
  -g '*.py' -g '*.sql' -g '*.md' -g '*.toml'

echo "== Foundation admission and changed-gate deletion check =="
rg -n -C 5 \
  'workforce.validation|workforce_validation|postgres|pytest|PYTHONPATH|postgres:|16\.14|manifest|validate' \
  .github/workflows/foundation-ci.yml tests/test_foundation_ci_dependency_hygiene.sh \
  -g '*.yml' -g '*.sh'
git diff --diff-filter=D --name-status "$base" "$head"
git diff --unified=50 "$base" "$head" -- \
  .github/workflows/foundation-ci.yml \
  tests/test_foundation_ci_dependency_hygiene.sh \
  tests/validate_repository.py \
  manifest.json

echo "== Global migration lanes unchanged and numbered migration inventory =="
git diff --name-status "$base" "$head" -- database/migrations
fd -t f -e sql . | rg '/[0-9]+[^/]*\.sql$' | sort

Length of output: 139294


🏁 Script executed:

#!/bin/bash
set -euo pipefail

base="eb9757f8649aaad026a9865508d9aad50c1a7a4f"
head="a04c8b4cd58145f9e74a085d3fdb037d90966012"
parent="$(git show -s --format=%P "$head")"

echo "== Immediate exact-head correction =="
git show -s --format='parent=%H%nsubject=%s' "$parent"
git diff --unified=120 "$parent" "$head" -- \
  services/workforce-validation-api/database/migrations/0001_owner_schema.sql \
  services/workforce-validation-api/README.md \
  services/workforce-validation-api/tests/test_persistence_layout.py \
  tests/test_workforce_validation_owner_schema_postgres.sh \
  .github/workflows/foundation-ci.yml \
  manifest.json

echo "== Manifest seals =="
python - <<'PY'
import hashlib
import json
from pathlib import Path

manifest = json.loads(Path("manifest.json").read_text(encoding="utf-8"))
entries = {entry["path"]: entry for entry in manifest["files"]}
for path in (
    ".github/workflows/foundation-ci.yml",
    "database/migrations/0005_outbox_delivery_finalization.sql",
):
    data = Path(path).read_bytes()
    actual = {
        "sha256": hashlib.sha256(data).hexdigest(),
        "bytes": len(data),
        "lines": data.count(b"\n"),
    }
    print(f"{path}: manifest={entries.get(path)} actual={actual}")
PY
echo "== Base and known predecessor 0005 manifest entries, if present =="
for commit in \
  "$base" \
  a0ccaf0afc1fa26ed979a5181e05c08140f92aff \
  83e5c9418f912878f0b829df24c7bf19a11e2b83 \
  7ca30f3447169e678269124dbf1fd23180b997b9 \
  "$head"
do
  if git cat-file -e "${commit}:manifest.json" 2>/dev/null; then
    printf '%s ' "$commit"
    git show "${commit}:manifest.json" | jq -c \
      '.files[] | select(.path == "database/migrations/0005_outbox_delivery_finalization.sql")'
  fi
done

echo "== Full requested PostgreSQL semantic evidence =="
rg -n -i -C 8 \
  'ALTER ROLE|SET ROLE|RESET ROLE|SET search_path|current_setting|rolconfig|NOLOGIN|NOINHERIT|NOBYPASSRLS|CREATE ROLE|CREATE SCHEMA|REVOKE ALL|PUBLIC|schema-qualified|SECURITY DEFINER|workforce_validation_role|workforce_validation' \
  services/workforce-validation-api \
  tests/test_workforce_validation_owner_schema_postgres.sh \
  -g '*.sql' -g '*.sh' -g '*.md' -g '*.py'

echo "== Cross-context SQL and application dependency scan =="
rg -n -i -C 4 \
  'public\.|psycopg|sqlalchemy|asyncpg|postgresql|CREATE TABLE|ALTER TABLE|DROP TABLE|\bSELECT\b|\bINSERT\b|\bUPDATE\b|\bDELETE\b|people-api|job-analysis-api|talent|performance|psychometric|fast-mlsirm|tepp' \
  services/workforce-validation-api \
  -g '*.py' -g '*.sql' -g '*.md' -g '*.toml' || true

echo "== Foundation CI and hygiene contract context =="
sed -n '55,130p' .github/workflows/foundation-ci.yml
sed -n '1,105p' tests/test_foundation_ci_dependency_hygiene.sh

echo "== No gate weakening or global migration modification =="
echo "-- deletions in the exact range --"
git diff --diff-filter=D --name-status "$base" "$head"
echo "-- global migration changes --"
git diff --name-status "$base" "$head" -- database/migrations
echo "-- gate-file changes --"
git diff --unified=70 "$base" "$head" -- \
  .github/workflows/foundation-ci.yml \
  tests/test_foundation_ci_dependency_hygiene.sh \
  tests/validate_repository.py \
  .github/requirements/foundation-test.txt \
  manifest.json

echo "== Structural immutability and authorization ordering evidence =="
rg -n -C 6 \
  'class ValidationPrincipal|class ValidityStudyRecord|__slots__|object\.__setattr__|def read_validity_study|require_purpose_bound_access|read_port\.read_validity_study|type\(persisted\)|_detach_policy' \
  services/workforce-validation-api/src \
  services/workforce-validation-api/tests \
  -g '*.py'

Length of output: 103838


@seonghobae I reviewed exact head a04c8b4cd58145f9e74a085d3fdb037d90966012 against protected develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f.

I found no blocking issue in the requested scope.

  • services/workforce-validation-api/database/migrations/0001_owner_schema.sql creates workforce_validation_role as a NOLOGIN schema-owner role. It retains the deny-default role flags.
  • The migration contains no ALTER ROLE ... SET search_path statement.
  • The migration documentation correctly states that role-level settings apply at login and do not re-apply after SET ROLE.
  • The migration requires a distinct least-privilege runtime role for the later adapter. It also requires schema-qualified relations and explicit function-level search_path for future SECURITY DEFINER code.
  • tests/test_workforce_validation_owner_schema_postgres.sh checks rolconfig is empty for the owner role.
  • The PostgreSQL contract sets search_path = public, runs SET ROLE workforce_validation_role, and requires workforce_validation_role|public. This proves that SET ROLE retains the active session search path.
  • The PostgreSQL contract verifies schema ownership, deny-default role flags, revoked PUBLIC USAGE and CREATE, and zero bootstrap-schema relations.
  • Foundation CI runs this contract in its own isolated container using the pinned PostgreSQL 16.14 image.

The prior boundaries remain intact.

  • ValidationPrincipal and ValidityStudyRecord remain tuple-backed with __slots__ = ().
  • The tests reject object.__setattr__ changes to retained principal and persisted-record evidence.
  • read_validity_study(...) validates and detaches policy evidence before require_purpose_bound_access(...).
  • Authorization completes before ValidityStudyReadPort.read_validity_study(...).
  • The service has no PostgreSQL adapter and no cross-context SQL dependency.
  • The migration does not create application relations or reference public.validity_study.

The Foundation workflow seal is correct. Its manifest SHA-256, byte count, and line count match the checked-in workflow. No existing Foundation gate was removed. No global migration file changed.

The database/migrations/0005_outbox_delivery_finalization.sql manifest seal is restored correctly. Its entry matches both the actual file and protected develop. It no longer contains the accidental a0ccaf0... hash mutation.

Hosted Foundation and applicable security workflows must still provide terminal results for this exact head.

You are interacting with an AI system.

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

Please review exact head 4ef7ad130e4d0aa314ea59de3dafaea79cc0630c against protected develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f. Focus on Issue #239 and its interaction with #236/#237/#238: a low-level tuple.__new__(ValidationPrincipal, ...) can bypass the validating constructor while retaining the exact outer type, so the owner boundary must reconstruct/revalidate principal storage before PurposeBoundAccessRequest or Keyverse evaluation. Verify that executable UUID subtype behavior cannot run before exact rejection, persistence remains authorization-after-only, canonical callers retain behavior, and the change does not broaden Keyverse compatibility, persistence ownership, schema/runtime-role scope, or requested-field exposure. Treat hosted coverage/security as separate evidence.

@coderabbitai

coderabbitai Bot commented Sep 5, 2026

Copy link
Copy Markdown

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

base="eb9757f8649aaad026a9865508d9aad50c1a7a4f"
head="4ef7ad130e4d0aa314ea59de3dafaea79cc0630c"

echo "== Exact commit identity and ancestry =="
git show -s --format='commit=%H%nparents=%P%nsubject=%s' "$base"
git show -s --format='commit=%H%nparents=%P%nsubject=%s' "$head"
printf 'merge_base='
git merge-base "$base" "$head"
git merge-base --is-ancestor "$base" "$head" && echo "base_is_ancestor=yes"

echo "== Exact-range changed files and summary =="
git diff --name-status "$base" "$head"
git diff --stat "$base" "$head"

echo "== Increment from parent =="
parent="$(git show -s --format=%P "$head")"
git show -s --format='parent=%H%nsubject=%s' "$parent"
git diff --name-status "$parent" "$head"
git diff --unified=120 "$parent" "$head" -- \
  services/workforce-validation-api \
  packages/keyverse-adapter \
  .github/workflows/foundation-ci.yml \
  tests/test_foundation_ci_dependency_hygiene.sh \
  manifest.json

echo "== Changed Python outlines =="
git diff --name-only "$base" "$head" | while IFS= read -r file; do
  case "$file" in
    *.py)
      echo "--- $file"
      ast-grep outline "$file" --items all 2>/dev/null || true
      ;;
  esac
done

echo "== Current owner boundary and related tests =="
for file in \
  services/workforce-validation-api/src/orgmetra_workforce_validation_api/registry.py \
  services/workforce-validation-api/tests/test_principal_runtime_integrity.py \
  services/workforce-validation-api/tests/test_registry.py \
  services/workforce-validation-api/tests/test_policy_runtime_integrity.py \
  services/workforce-validation-api/tests/test_persistence_layout.py \
  services/workforce-validation-api/database/migrations/0001_owner_schema.sql \
  services/workforce-validation-api/README.md \
  services/workforce-validation-api/pyproject.toml \
  packages/keyverse-adapter/src/orgmetra_keyverse_adapter/authorization.py \
  .github/workflows/foundation-ci.yml \
  tests/test_foundation_ci_dependency_hygiene.sh
do
  if [ -f "$file" ]; then
    echo "--- $file"
    cat -n "$file"
  fi
done

echo "== Principal construction and evaluation ordering =="
rg -n -C 8 \
  'class ValidationPrincipal|def __new__|tuple\.__new__|ValidationPrincipal\(|PurposeBoundAccessRequest|require_purpose_bound_access|read_port\.read_validity_study|type\(.*UUID|isinstance\(.*UUID|tenant_id|actor_reference|scope' \
  services/workforce-validation-api \
  packages/keyverse-adapter/src/orgmetra_keyverse_adapter \
  -g '*.py'

echo "== Cross-context SQL, schema/runtime-role, and field exposure scan =="
rg -n -i -C 5 \
  'public\.|validity_study|psycopg|sqlalchemy|asyncpg|postgres|SELECT |INSERT |UPDATE |DELETE |CREATE TABLE|ALTER TABLE|GRANT |REVOKE |ALTER ROLE|SET ROLE|search_path|requested_fields|permitted_fields|field' \
  services/workforce-validation-api \
  -g '*.py' -g '*.sql' -g '*.md' -g '*.toml'

echo "== Gate deletion and manifest validation =="
git diff --diff-filter=D --name-status "$base" "$head"
python - <<'PY'
import hashlib
import json
import subprocess
from pathlib import Path

base = "eb9757f8649aaad026a9865508d9aad50c1a7a4f"
head = "4ef7ad130e4d0aa314ea59de3dafaea79cc0630c"
manifest = json.loads(Path("manifest.json").read_text(encoding="utf-8"))
entries = {entry["path"]: entry for entry in manifest.get("files", [])}
changed = subprocess.check_output(
    ["git", "diff", "--name-only", base, head], text=True
).splitlines()
for path in changed:
    if path in entries and Path(path).is_file():
        data = Path(path).read_bytes()
        entry = entries[path]
        print(
            f"{path}: manifest={entry} "
            f"actual={{'sha256': '{hashlib.sha256(data).hexdigest()}', "
            f"'bytes': {len(data)}, 'lines': {data.count(b'\\n')}}}"
        )
PY

Length of output: 252143


🏁 Script executed:

#!/bin/bash
set -euo pipefail

base="eb9757f8649aaad026a9865508d9aad50c1a7a4f"
head="4ef7ad130e4d0aa314ea59de3dafaea79cc0630c"
parent="$(git show -s --format=%P "$head")"

echo "== Complete Issue `#239` regression =="
cat -n services/workforce-validation-api/tests/test_principal_storage_integrity.py

echo "== Complete exact increment diff =="
git diff --unified=160 "$parent" "$head"

echo "== Changed files after parent, outside registry =="
git diff --name-status "$parent" "$head" -- \
  ':!services/workforce-validation-api/src/orgmetra_workforce_validation_api/registry.py'

echo "== Corrected manifest verification =="
python - <<'PY'
import hashlib
import json
import subprocess
from pathlib import Path

base = "eb9757f8649aaad026a9865508d9aad50c1a7a4f"
head = "4ef7ad130e4d0aa314ea59de3dafaea79cc0630c"
entries = {
    entry["path"]: entry
    for entry in json.loads(Path("manifest.json").read_text(encoding="utf-8")).get("files", [])
}
changed = subprocess.check_output(
    ["git", "diff", "--name-only", base, head], text=True
).splitlines()
for path in changed:
    artifact = Path(path)
    if path in entries and artifact.is_file():
        data = artifact.read_bytes()
        actual = {
            "sha256": hashlib.sha256(data).hexdigest(),
            "bytes": len(data),
            "lines": data.count(b"\n"),
        }
        print(f"{path}")
        print(" manifest=" + json.dumps(entries[path], sort_keys=True))
        print(" actual=" + json.dumps(actual, sort_keys=True))
PY

echo "== Manifest validator and current status =="
git diff --unified=60 "$base" "$head" -- manifest.json .github/workflows/foundation-ci.yml tests/test_foundation_ci_dependency_hygiene.sh
git status --short
git diff --diff-filter=D --name-status "$base" "$head"

echo "== Service imports and forbidden runtime integration scan =="
rg -n -C 3 \
  '^(from|import) |public\.|psycopg|sqlalchemy|asyncpg|CREATE TABLE|ALTER TABLE|SELECT |INSERT |UPDATE |DELETE |workforce_validation_role|SET ROLE|search_path|openapi|FastAPI|flask' \
  services/workforce-validation-api \
  -g '*.py' -g '*.sql' -g '*.toml' -g '*.md'

echo "== Keyverse source changed in exact range =="
git diff --name-status "$base" "$head" -- packages/keyverse-adapter

Length of output: 43354


@seonghobae I reviewed exact head 4ef7ad130e4d0aa314ea59de3dafaea79cc0630c against protected develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f.

I found no blocking issue in the requested scope.

  • read_validity_study(...) reconstructs ValidationPrincipal at services/workforce-validation-api/src/orgmetra_workforce_validation_api/registry.py Lines 293-297.

  • The reconstruction occurs before PurposeBoundAccessRequest construction at Line 305.

  • The reconstruction occurs before require_purpose_bound_access(...) at Line 304.

  • The reconstruction revalidates the tenant UUID, actor reference, and granted scope set.

  • _require_operational_uuid(...) checks type(value) is UUID before it accesses value.int.

  • A forged UUID subtype therefore fails before its .int callback can execute.

  • services/workforce-validation-api/tests/test_principal_storage_integrity.py constructs a forged principal with tuple.__new__(ValidationPrincipal, ...).

  • Its _ExecutableUUID raises if code accesses .int.

  • The test requires ValueError and verifies that the read port receives no call.

  • This verifies rejection before Keyverse evaluation and persistence.

  • Canonical callers retain the existing values and authorization inputs.

  • The change only replaces use of the inbound principal storage with use of the reconstructed principal.

  • No Keyverse adapter source changes in the exact range.

  • The change does not broaden Keyverse compatibility.

The prior boundaries remain intact.

  • Authorization completes before ValidityStudyReadPort.read_validity_study(...).
  • ValidityStudyRecord remains tuple-backed and is reconstructed after repository access.
  • The response remains limited to the requested fields in _READ_FIELDS.
  • The service adds no SQL adapter and no public.validity_study service contract.
  • The owner migration remains local to workforce_validation.
  • workforce_validation_role remains a NOLOGIN migration/schema-owner role. The change does not modify its runtime-role boundary.
  • Foundation CI admission remains present.
  • The Foundation workflow manifest entry matches the current SHA-256, byte count, and line count.
  • The exact range removes no gate.

Hosted coverage, PostgreSQL acceptance, and security workflow results remain separate exact-head evidence.

You are interacting with an AI system.

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

Please review exact head ccb5c0c58dc74c1d7eee59431e6337c207fcac35 against protected develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f. Focus on Issue #240 and preserved #239: the earlier P1 non-callable ValidityStudyReadPort finding must now fail before principal/policy authorization without evaluating a caller-controlled descriptor. Verify that inspect.getattr_static plus callability rejects the descriptor regression before authorization, valid ordinary instance-method ports still pass and are called only after purpose-bound authorization, the #239 principal reconstruction remains before Keyverse evaluation, and there is no persistence/schema/Keyverse/requested-field broadening. Hosted coverage/security remain separate evidence.

@coderabbitai

coderabbitai Bot commented Sep 5, 2026

Copy link
Copy Markdown

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

base="eb9757f8649aaad026a9865508d9aad50c1a7a4f"
head="ccb5c0c58dc74c1d7eee59431e6337c207fcac35"
parent="$(git show -s --format=%P "$head")"

echo "== Commit identity and ancestry =="
git show -s --format='commit=%H%nparents=%P%nsubject=%s' "$base"
git show -s --format='commit=%H%nparents=%P%nsubject=%s' "$head"
printf 'merge_base='
git merge-base "$base" "$head"
git merge-base --is-ancestor "$base" "$head" && echo "base_is_ancestor=yes"

echo "== Exact-range changed files and summary =="
git diff --name-status "$base" "$head"
git diff --stat "$base" "$head"

echo "== Issue `#240` incremental diff =="
git show -s --format='parent=%H%nsubject=%s' "$parent"
git diff --name-status "$parent" "$head"
git diff --unified=160 "$parent" "$head" -- \
  services/workforce-validation-api \
  packages/keyverse-adapter \
  .github/workflows/foundation-ci.yml \
  tests/test_foundation_ci_dependency_hygiene.sh \
  manifest.json

echo "== Changed Python outlines =="
git diff --name-only "$base" "$head" | while IFS= read -r file; do
  case "$file" in
    *.py)
      echo "--- $file"
      ast-grep outline "$file" --items all 2>/dev/null || true
      ;;
  esac
done

echo "== Owner boundary and all relevant regression tests =="
for file in \
  services/workforce-validation-api/src/orgmetra_workforce_validation_api/registry.py \
  services/workforce-validation-api/tests/test_read_port_runtime_integrity.py \
  services/workforce-validation-api/tests/test_principal_storage_integrity.py \
  services/workforce-validation-api/tests/test_principal_runtime_integrity.py \
  services/workforce-validation-api/tests/test_policy_runtime_integrity.py \
  services/workforce-validation-api/tests/test_registry.py \
  services/workforce-validation-api/database/migrations/0001_owner_schema.sql \
  services/workforce-validation-api/README.md \
  packages/keyverse-adapter/src/orgmetra_keyverse_adapter/authorization.py \
  .github/workflows/foundation-ci.yml \
  tests/test_foundation_ci_dependency_hygiene.sh \
  manifest.json
do
  if [ -f "$file" ]; then
    echo "--- $file"
    cat -n "$file"
  fi
done

echo "== Static-access, authorization, and persistence order =="
rg -n -C 8 \
  'getattr_static|ValidityStudyReadPort|read_validity_study|ValidationPrincipal\(|PurposeBoundAccessRequest|require_purpose_bound_access|_detach_policy|tuple\.__new__|descriptor|__get__|callable\(' \
  services/workforce-validation-api \
  packages/keyverse-adapter/src/orgmetra_keyverse_adapter \
  -g '*.py'

echo "== Scope expansion and forbidden persistence integration scan =="
rg -n -i -C 4 \
  '^(from|import) |public\.|psycopg|sqlalchemy|asyncpg|\bselect\b|\binsert\b|\bupdate\b|\bdelete\b|CREATE TABLE|ALTER TABLE|GRANT |REVOKE |ALTER ROLE|SET ROLE|search_path|openapi|FastAPI|requested_fields|permitted_fields' \
  services/workforce-validation-api \
  -g '*.py' -g '*.sql' -g '*.toml' -g '*.md'

echo "== Keyverse changes and gate deletions in the exact range =="
git diff --name-status "$base" "$head" -- packages/keyverse-adapter
git diff --diff-filter=D --name-status "$base" "$head"
git diff --unified=80 "$base" "$head" -- \
  .github/workflows/foundation-ci.yml \
  tests/test_foundation_ci_dependency_hygiene.sh \
  tests/validate_repository.py \
  manifest.json

echo "== Manifest entries for changed tracked artifacts =="
python - <<'PY'
import hashlib
import json
import subprocess
from pathlib import Path

base = "eb9757f8649aaad026a9865508d9aad50c1a7a4f"
head = "ccb5c0c58dc74c1d7eee59431e6337c207fcac35"
entries = {
    entry["path"]: entry
    for entry in json.loads(Path("manifest.json").read_text(encoding="utf-8")).get("files", [])
}
for path in subprocess.check_output(
    ["git", "diff", "--name-only", base, head], text=True
).splitlines():
    artifact = Path(path)
    if path in entries and artifact.is_file():
        data = artifact.read_bytes()
        print(path)
        print(" manifest=" + json.dumps(entries[path], sort_keys=True))
        print(" actual=" + json.dumps({
            "sha256": hashlib.sha256(data).hexdigest(),
            "bytes": len(data),
            "lines": data.count(b"\n"),
        }, sort_keys=True))
PY

Length of output: 240722


@seonghobae I reviewed exact head ccb5c0c58dc74c1d7eee59431e6337c207fcac35 against protected develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f.

I found no blocking issue in the requested scope.

  • read_validity_study(...) uses inspect.getattr_static(...) at services/workforce-validation-api/src/orgmetra_workforce_validation_api/registry.py Line 291.

  • It checks callable(read_capability) at Line 292.

  • It raises before principal reconstruction, policy detachment, PurposeBoundAccessRequest construction, Keyverse evaluation, and repository access.

  • This static lookup does not invoke the read_validity_study property getter.

  • services/workforce-validation-api/tests/test_read_port_dependency_integrity.py contains the descriptor regression.

  • Its property raises AssertionError if evaluated.

  • Its policy would cause authorization denial if the code reached Keyverse.

  • The test expects the static-capability TypeError.

  • This proves that the non-callable descriptor fails before authorization without getter evaluation.

  • Ordinary instance-method ports remain accepted. getattr_static(...) returns the class function, which is callable.

  • The allowed-read test confirms that the port receives the exact tenant and study identifiers.

  • The denial test confirms that an ordinary port receives no call when Keyverse denies access.

  • The #239 repair remains intact.

  • ValidationPrincipal(...) reconstructs and revalidates stored principal evidence at Lines 295-299.

  • This occurs before PurposeBoundAccessRequest at Line 307 and before require_purpose_bound_access(...) at Line 306.

  • The executable UUID subtype regression remains protected by exact UUID validation before .int access.

  • The exact range does not change packages/keyverse-adapter.

  • It adds no persistence adapter, SQL query, public.validity_study contract, schema change, runtime-role change, or requested-field expansion.

  • The Foundation workflow admission and dependency-hygiene controls remain present.

  • The manifest.json entry matches the current Foundation workflow SHA-256, byte count, and line count.

  • The exact range removes no gate.

Hosted Foundation, PostgreSQL, coverage, and security results remain separate exact-head evidence.

You are interacting with an AI system.

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

Please review exact head 17092c94d180d082d1e389982e0beea9872f53f9 against protected develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f. Focus on Issue #241 and the ordinary successor pair 1a344f8057755ae8b652c31963d787ff8abf2beb17092c94d180d082d1e389982e0beea9872f53f9: confirm that a field-minimized authorized ValidityStudyView can no longer be rewritten through object.__setattr__, that the public tenant_record_id / validity_study_id / fields shape remains unchanged, and that no authorization, owner-port, SQL/schema, #236/#237/#239/#240, Foundation, or manifest semantics were weakened. Treat hosted gates on predecessor heads as non-transferable.

@coderabbitai

coderabbitai Bot commented Sep 5, 2026

Copy link
Copy Markdown

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

base="eb9757f8649aaad026a9865508d9aad50c1a7a4f"
prior="1a344f8057755ae8b652c31963d787ff8abf2beb"
head="17092c94d180d082d1e389982e0beea9872f53f9"

echo "== Commit identity and ancestry =="
for commit in "$base" "$prior" "$head"; do
  git show -s --format='commit=%H%nparents=%P%nsubject=%s%n' "$commit"
done
printf 'merge_base='
git merge-base "$base" "$head"
git merge-base --is-ancestor "$base" "$head" && echo "base_is_ancestor=yes"
git merge-base --is-ancestor "$prior" "$head" && echo "prior_is_ancestor=yes"

echo "== Exact-range changed files and summary =="
git diff --name-status "$base" "$head"
git diff --stat "$base" "$head"

echo "== Issue `#241` immediate increment =="
git diff --name-status "$prior" "$head"
git diff --unified=160 "$prior" "$head" -- \
  services/workforce-validation-api \
  .github/workflows/foundation-ci.yml \
  tests/test_foundation_ci_dependency_hygiene.sh \
  manifest.json \
  tests/validate_repository.py

echo "== Changed Python outlines =="
git diff --name-only "$base" "$head" | while IFS= read -r file; do
  case "$file" in
    *.py)
      echo "--- $file"
      ast-grep outline "$file" --items all 2>/dev/null || true
      ;;
  esac
done

echo "== Current owner boundary, Issue `#241` regression, and governance artifacts =="
for file in \
  services/workforce-validation-api/src/orgmetra_workforce_validation_api/registry.py \
  services/workforce-validation-api/src/orgmetra_workforce_validation_api/__init__.py \
  services/workforce-validation-api/tests/test_validity_study_view_integrity.py \
  services/workforce-validation-api/tests/test_registry.py \
  services/workforce-validation-api/tests/test_read_port_dependency_integrity.py \
  services/workforce-validation-api/tests/test_principal_storage_integrity.py \
  services/workforce-validation-api/tests/test_policy_runtime_integrity.py \
  services/workforce-validation-api/database/migrations/0001_owner_schema.sql \
  services/workforce-validation-api/README.md \
  services/workforce-validation-api/pyproject.toml \
  .github/workflows/foundation-ci.yml \
  tests/test_foundation_ci_dependency_hygiene.sh \
  manifest.json
do
  if [ -f "$file" ]; then
    echo "--- $file"
    cat -n "$file"
  fi
done

echo "== View shape, immutability, authorization order, and read-port validation =="
rg -n -C 8 \
  'class ValidityStudyView|ValidityStudyView\(|tenant_record_id|validity_study_id|fields|__slots__|object\.__setattr__|getattr_static|callable\(|ValidationPrincipal\(|_detach_policy|PurposeBoundAccessRequest|require_purpose_bound_access|read_port\.read_validity_study' \
  services/workforce-validation-api \
  -g '*.py'

echo "== Scope expansion and forbidden persistence integration scan =="
rg -n -i -C 4 \
  '^(from|import) |public\.|psycopg|sqlalchemy|asyncpg|\bselect\b|\binsert\b|\bupdate\b|\bdelete\b|CREATE TABLE|ALTER TABLE|DROP TABLE|GRANT |REVOKE |ALTER ROLE|SET ROLE|search_path|openapi|FastAPI|requested_fields|permitted_fields' \
  services/workforce-validation-api \
  -g '*.py' -g '*.sql' -g '*.toml' -g '*.md' || true

echo "== Keyverse, global migration, and gate changes =="
git diff --name-status "$base" "$head" -- packages/keyverse-adapter database/migrations
git diff --diff-filter=D --name-status "$base" "$head"
git diff --unified=80 "$base" "$head" -- \
  .github/workflows/foundation-ci.yml \
  tests/test_foundation_ci_dependency_hygiene.sh \
  tests/validate_repository.py \
  .github/requirements/foundation-test.txt \
  manifest.json

echo "== Manifest integrity for changed tracked artifacts =="
python - <<'PY'
import hashlib
import json
import subprocess
from pathlib import Path

base = "eb9757f8649aaad026a9865508d9aad50c1a7a4f"
head = "17092c94d180d082d1e389982e0beea9872f53f9"
entries = {
    entry["path"]: entry
    for entry in json.loads(Path("manifest.json").read_text(encoding="utf-8")).get("files", [])
}
for path in subprocess.check_output(
    ["git", "diff", "--name-only", base, head], text=True
).splitlines():
    artifact = Path(path)
    if path in entries and artifact.is_file():
        data = artifact.read_bytes()
        actual = {
            "sha256": hashlib.sha256(data).hexdigest(),
            "bytes": len(data),
            "lines": data.count(b"\n"),
        }
        print(path)
        print(" manifest=" + json.dumps(entries[path], sort_keys=True))
        print(" actual=" + json.dumps(actual, sort_keys=True))
PY

Length of output: 246991


@seonghobae I reviewed exact head 17092c94d180d082d1e389982e0beea9872f53f9 against protected develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f.

I found no blocking issue in the requested scope.

  • 17092c94d... is the direct successor of 1a344f8057755ae8b652c31963d787ff8abf2beb.
  • The immediate increment changes only services/workforce-validation-api/src/orgmetra_workforce_validation_api/registry.py.

Issue #241 is addressed in the reviewed code.

  • ValidityStudyView is now tuple-backed with __slots__ = ().
  • It exposes the existing public properties: tenant_record_id, validity_study_id, and fields.
  • read_validity_study(...) still creates the view with the same three named values.
  • services/workforce-validation-api/tests/test_registry.py Lines 277-299 attempts object.__setattr__ on each public property.
  • The regression requires AttributeError.
  • The regression then verifies that the authorized tenant ID, study ID, and minimized fields value remain unchanged.

The prior controls remain intact.

  • The static read_validity_study capability check occurs before principal reconstruction and Keyverse authorization.
  • Principal reconstruction occurs before PurposeBoundAccessRequest construction and Keyverse evaluation.
  • Policy evidence is detached before authorization.
  • Keyverse authorization completes before ValidityStudyReadPort.read_validity_study(...).
  • The persisted result must be an exact ValidityStudyRecord.
  • The persisted tenant ID and study ID must match the authorized target before fields are returned.
  • ValidityStudyRecord and ValidationPrincipal remain tuple-backed with __slots__ = ().
  • The requested-field allowlist remains limited to the existing four registry fields.

The increment does not broaden the boundary.

  • It changes no Keyverse adapter source.
  • It changes no global migration.
  • It adds no SQL adapter, application relation, runtime role, or public.validity_study contract.
  • The service-local bootstrap migration remains schema and owner-role only.
  • Foundation service-test admission and dependency-hygiene checks remain present.
  • The manifest.json entry for .github/workflows/foundation-ci.yml matches the current SHA-256, byte count, and line count.
  • The exact range removes no gate.

Hosted Foundation, PostgreSQL, coverage, and security results remain separate evidence for this exact head.

You are interacting with an AI system.

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

Please review exact head 57214b4968c5968a4009cad56ea9d23a186ee9d9. Focus on #423's governed final-weight adjustment admission (d7aa67c6...17b80f9e...9625f95d...) and the paired CHANGELOG/manifest provenance commits (e4945f0b...57214b4968c...). Do not treat predecessor test/coverage evidence as current-head evidence.

@coderabbitai

coderabbitai Bot commented Sep 19, 2026

Copy link
Copy Markdown

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

base="eb9757f8649aaad026a9865508d9aad50c1a7a4f"
head="57214b4968c5968a4009cad56ea9d23a186ee9d9"
service="services/workforce-validation-api"
src="$service/src/orgmetra_workforce_validation_api"
tests="$service/tests"

echo "== Resolve short SHAs =="
for short in d7aa67c6 17b80f9e 9625f95d e4945f0b; do
  echo "-- $short --"
  git rev-parse "${short}^{commit}" 2>/dev/null || echo "not found"
done

echo "== Exact commits and ancestry =="
for commit in "$base" "$head"; do
  git show -s --format='commit=%H%nparents=%P%nsubject=%s%n' "$commit" 2>/dev/null || true
done
printf 'merge_base='; git merge-base "$base" "$head"
git merge-base --is-ancestor "$base" "$head" && echo 'base_is_ancestor=yes'
parent="$(git show -s --format=%P "$head" | awk '{print $1}')"
echo "parent=$parent"

echo "== Exact scope =="
git diff --name-status "$base" "$head"
git diff --check "$base" "$head"

echo "== recent log of last ~30 commits touching service =="
git log --oneline -30 "$head" -- "$service" CHANGELOG.md manifest.json

Length of output: 22104


🏁 Script executed:

#!/bin/bash
set -euo pipefail

red="d7aa67c6d2550a0b3ff8d790e845667009d02438"
fix="17b80f9e360dc82bf93c6831c2c6d3504af50a90"
align="9625f95dc3b90ba119c462a7587accf2c4f068e1"
docs="e4945f0bcea20aff5cc5dee3f86a9964ddbb3107"
head="57214b4968c5968a4009cad56ea9d23a186ee9d9"

service="services/workforce-validation-api"
src="$service/src/orgmetra_workforce_validation_api"
tests="$service/tests"

echo "== Commit subjects and parents =="
for c in "$red" "$fix" "$align" "$docs" "$head"; do
  git show -s --format='commit=%H%nparents=%P%nsubject=%s%n' "$c"
done

echo "== Ancestry check =="
for pair in "$red $fix" "$fix $align" "$align $docs" "$docs $head"; do
  set -- $pair
  git merge-base --is-ancestor "$1" "$2" && echo "$1 -> $2 : ancestor OK" || echo "$1 -> $2 : NOT ANCESTOR"
done

echo "== RED commit diff (d7aa67c6) =="
git show --stat "$red"
git show "$red" -- "$tests" | head -300

echo "== GREEN fix diff (17b80f9e) =="
git show --stat "$fix"
git show "$fix" -- "$src" | head -400

echo "== Test alignment diff (9625f95d) =="
git show --stat "$align"
git show "$align" -- "$tests" | head -300

echo "== Docs commit diff (e4945f0b) =="
git show --stat "$docs"
git show "$docs" | head -200

echo "== Provenance reseal diff (57214b4968c) =="
git show --stat "$head"
git show "$head" | head -200

Length of output: 11799


🏁 Script executed:

#!/bin/bash
set -euo pipefail

head="57214b4968c5968a4009cad56ea9d23a186ee9d9"
module="services/workforce-validation-api/src/orgmetra_workforce_validation_api/final_weight_authority.py"

echo "== Governed adjustment-code map =="
git show "$head:$module" | rg -n -B2 -A20 '_SPECIALIZED_EVIDENCE_KIND_BY_ADJUSTMENT_CODE\s*='

echo "== Full FinalWeightAdjustmentCoordinate constructor =="
git show "$head:$module" | sed -n '1,200p' | rg -n -B5 -A60 'class FinalWeightAdjustmentCoordinate'

echo "== All usages of adjustment_code in tests referencing ungoverned codes =="
git grep -n -I "adjustment_code=" "$head" -- services/workforce-validation-api/tests | rg -v 'sequence_number' || true

echo "== Manifest CHANGELOG entry at head =="
git show "$head:manifest.json" | rg -n -A4 '"CHANGELOG.md"'

echo "== Compute actual CHANGELOG.md sha256/bytes/lines at head =="
git show "$head:CHANGELOG.md" > /tmp/CHANGELOG_head.md
sha256sum /tmp/CHANGELOG_head.md
wc -c /tmp/CHANGELOG_head.md
wc -l /tmp/CHANGELOG_head.md

echo "== Confirm repository validation script logic for hashing (bytes vs lines definition) =="
rg -n -A20 'def.*manifest|sha256|bytes.*lines' tests/validate_repository.py | head -100

echo "== Check test suite scope for final_weight_authority to ensure other adjustment codes still function =="
git show "$head:services/workforce-validation-api/tests/test_final_analysis_weight_authority.py" | sed -n '1,60p'

Length of output: 15066


🏁 Script executed:

#!/bin/bash
set -euo pipefail

head="57214b4968c5968a4009cad56ea9d23a186ee9d9"
file="services/workforce-validation-api/tests/test_final_weight_component_evidence_resolution_edges.py"

echo "== Context around replicate_weight_projection usage =="
git show "$head:$file" | sed -n '260,360p'

echo "== Check if FinalWeightAdjustmentCoordinate is imported/used in this test =="
git show "$head:$file" | rg -n 'import|FinalWeightAdjustmentCoordinate|adjustment_code'

echo "== Check final_weight_component_evidence_resolution.py for its own adjustment validation logic (separate from FinalWeightAdjustmentCoordinate) =="
module="services/workforce-validation-api/src/orgmetra_workforce_validation_api/final_weight_component_evidence_resolution.py"
git show "$head:$module" | rg -n 'adjustment_code|_SPECIALIZED_EVIDENCE_KIND|replicate_weight_projection'

Length of output: 5073


@seonghobae I reviewed exact head 57214b4968c5968a4009cad56ea9d23a186ee9d9 against develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f, with focus on the d7aa67c6...17b80f9e...9625f95d... chain and the e4945f0b...57214b4968c... provenance commits.

I found one blocking issue.

  1. P1 — The governed-adjustment fix breaks the existing non-specialized adjustment contract.

    services/workforce-validation-api/src/orgmetra_workforce_validation_api/final_weight_authority.py Line 140-144, added in 17b80f9e..., rejects every adjustment_code that is absent from _SPECIALIZED_EVIDENCE_KIND_BY_ADJUSTMENT_CODE:

    required_kind = _SPECIALIZED_EVIDENCE_KIND_BY_ADJUSTMENT_CODE.get(code)
    if required_kind is None:
        raise ValueError(
            "adjustment_code must identify a governed adjustment with released owner evidence."
        )
    if kind != required_kind:
        raise ValueError(f"{code} requires evidence_kind {required_kind}.")

    This closes the RED case in d7aa67c6... (custom_transform). The test alignment commit 9625f95d... correctly updates test_final_analysis_weight_authority.py for that same case.

    However, this change also rejects adjustment_code="replicate_weight_projection", which is not in _SPECIALIZED_EVIDENCE_KIND_BY_ADJUSTMENT_CODE. services/workforce-validation-api/tests/test_final_weight_component_evidence_resolution_edges.py Line 305-329, function test_non_specialized_adjustment_needs_no_cross_owner_locator, constructs exactly this coordinate:

    local_adjustment = FinalWeightAdjustmentCoordinate(
        sequence_number=1,
        adjustment_code="replicate_weight_projection",
        method_reference="weight_method:dddddddd-dddd-4ddd-8ddd-dddddddddddd",
        method_version=1,
        input_weight_artifact_digest=BASE_ARTIFACT_DIGEST,
        output_weight_artifact_digest="c" * 64,
        configuration_digest="d" * 64,
        evidence_receipt_digest="e" * 64,
        evidence_kind="replicate_weight_receipt",
    )

    This test file is not part of the d7aa67c6...9625f95d... chain and was not updated. With the new rejection rule, the constructor call fails with ValueError before the test reaches _corroborate(...). The test docstring states the purpose: "Resolve base evidence while leaving a non-specialized transform owner-local." The fix eliminates the entire non-specialized, owner-local adjustment path that this test exercises.

    Choose one of these two corrections:

    • Restore an explicit governed allowlist for non-specialized, owner-local codes (for example, replicate_weight_projection), separate from the specialized evidence-kind map, and reject only codes that match neither list.
    • If a non-specialized, owner-local adjustment is no longer a supported concept, update test_final_weight_component_evidence_resolution_edges.py to remove or change test_non_specialized_adjustment_needs_no_cross_owner_locator in the same commit chain.

    Do not merge until this contradiction is resolved and the exact head runs the full services/workforce-validation-api test suite GREEN.

Verified provenance reseal

manifest.json at 57214b4968c5968a4009cad56ea9d23a186ee9d9 correctly reflects the CHANGELOG.md content added in e4945f0b....

  • Manifest entry: sha256=026289e0ff0131a081786e4029999292c72e1e2e08c4675c7ec96c4617b93049, bytes=20244, lines=82.
  • Computed from the exact-head blob: identical sha256, bytes, and lines.

This part of the provenance chain is correct.

This is static exact-head evidence only. I did not execute the test suite, coverage, or hosted gates. The finding above is based on direct inspection of the constructor logic and the unmodified test that calls it.

You are interacting with an AI system.

seonghobae commented Sep 20, 2026

Copy link
Copy Markdown
Contributor Author

Exact-head RCA and verification — 731b5e9605f0d4d8f27e45920c68b73da2d44be0

Fresh full-suite execution on predecessor 36fd2627… exposed 3 failures / 1,439 passes:

  1. two new science(workforce-validation): require resolvable authority for every material final-weight adjustment #423 tests expected a governed adjustment_code diagnostic but production emitted the same rule with the words reversed;
  2. test_non_specialized_adjustment_needs_no_cross_owner_locator still asserted that an ungoverned replicate_weight_projection could bypass component binding;
  3. that stale assumption kept an unreachable continue branch in the corroborator and left its owned coverage below the repository gate.

Ordinary-forward repair 731b5e9605f0d4d8f27e45920c68b73da2d44be0 aligns the diagnostic, deletes the stale test and dead branch, and requires exact component binding for every adjustment that #423 permits. It adds no adjustment family, locator scan, cross-context SQL or mutable dependency.

Fresh exact-tree evidence:

  • focused affected suites: 96/96 passed;
  • full service + pinned built-wheel acceptance: 1,441/1,441 passed;
  • owned production: 5,186/5,186 statements, 1,116/1,116 branches, 100%;
  • Foundation: 23/23;
  • repository/manifest validation, Deprecation-Warning-fail-closed compileall and git diff --check: PASS;
  • remote commit tree 16b21d2cec980e349543d25659e7b65f8591e3d0 is the independently verified local tree.

Independent delta review found no actionable Critical or Important findings; its focused verification passed 177/177, Foundation 23/23, repository validation and diff checks. The PR is now Ready / Proposed for review admission. Ready is not merge authority.

Fresh hosted Foundation, Security, SAST, and CodeQL remain queued. PostgreSQL owner-schema evidence and qualifying current-head independent approval remain outstanding; no merge or release authority is claimed.

@seonghobae
seonghobae marked this pull request as ready for review September 20, 2026 00:29

Copy link
Copy Markdown
Contributor Author

Canonical repair clarification after the Draft transition: because #426 is downstream of normal #235 integration and #248 durable adoption, this PR cannot wait for #426 to make the current lifecycle wording true. The executable path is ordinary-forward neutralization of the ValidityStudyRecord.study_status_code property docstring on #235 so it describes the current syntactic code contract only. #426 may later replace that neutral wording when a versioned lifecycle vocabulary/transition policy is actually protected truth. No source evidence or predecessor GREEN is transferred by this metadata clarification.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant