Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions .github/workflows/hourly-nvidia-nim-review-repair.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,6 +16,7 @@ on:
- .github/workflows/nonnest2-hourly-review-repair.yml
- .github/workflows/orgmetra-hourly-review-repair.yml
- .github/workflows/originweave-hourly-review-repair.yml
- .github/workflows/lineageweave-hourly-review-repair.yml
- .github/workflows/quarantine-sandbox-hourly-review-repair.yml
- .github/workflows/afipc-hourly-review-repair.yml
- scripts/ci/pr_review_conflict_scope.py
Expand All @@ -29,6 +30,7 @@ on:
- tests/test_nonnest2_hourly_review_caller.py
- tests/test_orgmetra_hourly_review_caller.py
- tests/test_originweave_hourly_review_caller.py
- tests/test_lineageweave_hourly_review_caller.py
- tests/test_quarantine_sandbox_hourly_review_caller.py
- tests/test_afipc_hourly_review_caller.py
- tests/test_hourly_autofix_context_quality_gate.py
Expand All @@ -55,6 +57,7 @@ on:
- docs/doctoring/nonnest2-hourly-review-caller.md
- docs/doctoring/orgmetra-hourly-review-caller.md
- docs/doctoring/originweave-hourly-review-caller.md
- docs/doctoring/lineageweave-hourly-review-caller.md
- docs/doctoring/quarantine-sandbox-hourly-review-caller.md
- docs/doctoring/afipc-hourly-review-caller.md
push:
Expand All @@ -72,6 +75,7 @@ on:
- .github/workflows/nonnest2-hourly-review-repair.yml
- .github/workflows/orgmetra-hourly-review-repair.yml
- .github/workflows/originweave-hourly-review-repair.yml
- .github/workflows/lineageweave-hourly-review-repair.yml
- .github/workflows/quarantine-sandbox-hourly-review-repair.yml
- .github/workflows/afipc-hourly-review-repair.yml
- scripts/ci/pr_review_conflict_scope.py
Expand All @@ -85,6 +89,7 @@ on:
- tests/test_nonnest2_hourly_review_caller.py
- tests/test_orgmetra_hourly_review_caller.py
- tests/test_originweave_hourly_review_caller.py
- tests/test_lineageweave_hourly_review_caller.py
- tests/test_quarantine_sandbox_hourly_review_caller.py
- tests/test_afipc_hourly_review_caller.py
- tests/test_hourly_autofix_context_quality_gate.py
Expand All @@ -111,6 +116,7 @@ on:
- docs/doctoring/nonnest2-hourly-review-caller.md
- docs/doctoring/orgmetra-hourly-review-caller.md
- docs/doctoring/originweave-hourly-review-caller.md
- docs/doctoring/lineageweave-hourly-review-caller.md
- docs/doctoring/quarantine-sandbox-hourly-review-caller.md
- docs/doctoring/afipc-hourly-review-caller.md

Expand Down Expand Up @@ -169,6 +175,7 @@ jobs:
tests/test_nonnest2_hourly_review_caller.py \
tests/test_orgmetra_hourly_review_caller.py \
tests/test_originweave_hourly_review_caller.py \
tests/test_lineageweave_hourly_review_caller.py \
tests/test_quarantine_sandbox_hourly_review_caller.py \
tests/test_afipc_hourly_review_caller.py \
tests/test_pr_review_conflict_scope_control_files.py \
Expand Down
37 changes: 37 additions & 0 deletions .github/workflows/lineageweave-hourly-review-repair.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,37 @@
name: LineageWeave Hourly Review Repair

on:
schedule:
# Minute 4 avoids pg-llm-batch (1), aFIPC (2), kaefa (3), codec-carver (5),
# life-os (6), Wardnet (7), mightyETL (8), psychometrics-commons (9),
# OriginWeave (10), naruon (11), pg-erd-cloud (13), Quarantine Sandbox (14),
# nonnest2 (16), orchestrator (17), noema (19), central GitHub (21),
# Clearfolio (23), accounting-information-platform (27), Keyverse (29),
# Scopeweave (31), DiskSage (37), Appguardrail (41), GRC (43),
# newsdom-api (43), Inkspan (47), fast-mlsirm (49), BandScope (53), and
Comment on lines +10 to +11

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

📝 Info: Schedule comment lists two products at minute 43

The schedule comment lists both GRC (43) and newsdom-api (43) at the same minute (lineageweave-hourly-review-repair.yml). Cosmetic only; comments do not affect scheduling, and minute 4 remains free.

Open in Devin Review

Was this helpful? React with 👍 or 👎 to provide feedback.

# Orgmetra (58).
- cron: "4 * * * *"

concurrency:
group: lineageweave-hourly-review-repair
# A later heartbeat must not cancel an in-flight OpenCode RCA.
cancel-in-progress: false

permissions:
contents: read

jobs:
dispatch-review-repair:
permissions:
contents: read
id-token: write
uses: ./.github/workflows/pr-review-fix-scheduler.yml
with:
target_repository: ContextualWisdomLab/LineageWeave
base_branch: main
max_prs: "50"
max_dispatches: "1"
retry_hours: "2"
secrets:
PR_REVIEW_MERGE_TOKEN: ${{ secrets.PR_REVIEW_MERGE_TOKEN }}
OPENCODE_APPROVE_TOKEN: ${{ secrets.OPENCODE_APPROVE_TOKEN }}
1 change: 1 addition & 0 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ directive is not trust evidence. See
[`docs/doctoring/opencode-exact-vcs-dependency-evidence.md`](docs/doctoring/opencode-exact-vcs-dependency-evidence.md).
Conflict-scope roots fail closed when the immediate parent directory is a symbolic link.
OriginWeave hourly NVIDIA NIM repair is a thin caller at minute 10. See [`docs/doctoring/originweave-hourly-review-caller.md`](docs/doctoring/originweave-hourly-review-caller.md).
LineageWeave hourly NVIDIA NIM repair is a thin caller at minute 4. See [`docs/doctoring/lineageweave-hourly-review-caller.md`](docs/doctoring/lineageweave-hourly-review-caller.md).
nonnest2 hourly NVIDIA NIM repair is a thin caller at minute 16. See [`docs/doctoring/nonnest2-hourly-review-caller.md`](docs/doctoring/nonnest2-hourly-review-caller.md).

OpenCode may repair only trusted `path:line` bindings on LLM probes that already carry an independent proof and source-line digest. See [`docs/doctoring/opencode-llm-review-publication.md`](docs/doctoring/opencode-llm-review-publication.md).
Expand Down
9 changes: 8 additions & 1 deletion ARCHITECTURE.md
Original file line number Diff line number Diff line change
Expand Up @@ -34,6 +34,13 @@ flowchart LR
only established scheduler credentials, and grants job-scoped
`id-token: write`. The reusable engine stays product-neutral.

## LineageWeave hourly caller

`lineageweave-hourly-review-repair.yml` is a thin, read-only caller at minute
4. It names `ContextualWisdomLab/LineageWeave` and protected `main`, maps
only established scheduler credentials, and grants job-scoped
`id-token: write`. The reusable engine stays product-neutral.

## nonnest2 hourly caller

`nonnest2-hourly-review-repair.yml` is a thin, read-only caller at minute
Expand Down Expand Up @@ -75,7 +82,7 @@ The worker checks out helpers at `${{ github.sha }}` so a later default-branch
push cannot replace privileged scripts after dispatch (CWE-367). Repair binds
`NVIDIA_NIM_API_KEY`, never `COPILOT_GITHUB_TOKEN`.

Product callers stagger Clearfolio at minute 23, DiskSage at minute 37, and
Product callers stagger LineageWeave at minute 4, Clearfolio at minute 23, DiskSage at minute 37, and
fast-mlsirm at minute 49. Each caller is read-only, dispatches at most one
repair, and delegates all privileged logic to the same sealed scheduler.

Expand Down
2 changes: 1 addition & 1 deletion CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -19,11 +19,11 @@ Semantic Versioning where the repository publishes a release.

### Added

- Added a dedicated LineageWeave hourly caller at minute 4 that invokes the product-neutral central scheduler with the exact repository, protected `main` branch, one-dispatch budget, two-hour same-head retry floor, non-cancelling single-flight heartbeat, job-scoped OIDC, and only the established scheduler credentials.
- Refresh the live product and technical gap baseline against the current
open-PR queue, with SHA-bound snapshot rows, a same-session open/close
delta section, ADR Figma File ID N/A, and APA 7th doctoring. The inventory
is not merge authorization.

- Classify Strix `ModelBehaviorError` and provider exhaustion as typed
`STRIX_PROVIDER_UNAVAILABLE` evidence while preserving a nonzero required
check. Incomplete scans and reported vulnerabilities both fail closed.
Expand Down
2 changes: 2 additions & 0 deletions docs/automation/hourly-review-repair.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,8 @@ engine**.

- `clearfolio-hourly-review-repair.yml` owns Clearfolio's heartbeat at minute 23
of every hour.
- `lineageweave-hourly-review-repair.yml` owns LineageWeave's heartbeat at minute 4
of every hour against protected `main`.
- `orgmetra-hourly-review-repair.yml` owns Orgmetra's heartbeat at minute 58
of every hour against protected `develop`.
- `pr-review-fix-scheduler.yml` is the reusable, product-neutral scheduler
Expand Down
147 changes: 147 additions & 0 deletions docs/doctoring/lineageweave-hourly-review-caller.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,147 @@
# LineageWeave hourly review-repair caller

검토 기준일: **2026-08-23**

## Decision

ContextualWisdomLab operates one protected hourly caller for
`ContextualWisdomLab/LineageWeave` (git-branch-style lineage DAGs from
short records via multi-channel score fusion and LLM adjudication). The
caller runs at minute 4, delegates to the product-neutral central
review-fix scheduler, inspects at most 50 open pull requests targeting
protected `main`, and dispatches at most one bounded repair per heartbeat.

A reviewer of reconstructable event lineage would feel live LineageWeave
pull requests stalling while hourly NVIDIA NIM repair scanned OriginWeave,
DiskSage, and fast-mlsirm. Live heads such as
ContextualWisdomLab/LineageWeave#494 (login typecheck),
ContextualWisdomLab/LineageWeave#426 (frontend build and ontology Pages),
ContextualWisdomLab/LineageWeave#429 (`/healthz` liveness), and
ContextualWisdomLab/LineageWeave#355 (Naruon calendar projection) target
`main` and never enter those other callers.

The caller does not implement review or mutation logic itself.
LineageWeave remains standalone; naruon, RankWeave, ThreadWeave, TEPP,
fast-mlsirm, and contextual-orchestrator may be consumed as modules
without owning LineageWeave's merge gates. Privileged automation stays in
`ContextualWisdomLab/.github`.

This thin caller supersedes a product-specific stacked-queue driver. The
reusable scheduler already owns exact-head admission, writer leases, and
one-dispatch repair. A LineageWeave-only stack list would drift as soon as
new heads land.

## Root-cause analysis and remediation feasibility

The reusable worker performs exact-head root-cause analysis and tests
remediation feasibility before it edits. The reusable worker must:

1. Refetch the exact live head, base, reviews, checks, changed paths, and
writer state.
2. Establish the causal chain rather than repeat the terminal symptom.
3. Enumerate materially distinct minimal remedies.
4. Reject remedies that lack writer authority, cross sealed paths, require
unavailable credentials or protected-setting changes, violate stack
order, cannot be verified, or do not alter the diagnosed cause.
5. Dispatch at most one feasible repair. Otherwise leave the tree
unchanged.

A queued or pending check remains a merge blocker but is not itself a
code finding. The independent non-author approval remains an external
authorization gate and is never synthesized by the repair worker. The
worker cannot approve, merge, release, resolve review findings by
inference, change protection, or manufacture passing checks.

## Cadence and concurrency

The caller uses a single concurrency group and `cancel-in-progress: false`.
This preserves an in-flight bounded RCA instead of discarding evidence
when the next hourly heartbeat arrives. The reusable scheduler
cancels only its own superseded short queue scan.

The caller sets a **two-hour same-head retry floor**. Central OpenCode and
NVIDIA NIM work, plus frontend typecheck, Event Lineage, and Naruon
calendar analysis, can legitimately approach two hours. An hourly
redispatch of the same unchanged head would create duplicate writer
pressure rather than faster remediation.

GitHub scheduled workflows can be delayed under load and execute only
from the default branch. The cron expression is a heartbeat, not a
real-time SLA.

## Credential and model boundary

The caller keeps workflow `GITHUB_TOKEN` at `contents: read` and grants
the reusable job `id-token: write` so the central scheduler can mint the
OpenCode GitHub App token from GitHub OIDC when the mapped PAT is absent
(GitHub, n.d.-c). It maps only `PR_REVIEW_MERGE_TOKEN` and
`OPENCODE_APPROVE_TOKEN`. It never uses `secrets: inherit`, receives
`NVIDIA_NIM_API_KEY`, or introduces `COPILOT_GITHUB_TOKEN`. CWE-250
forbids executing the caller with write or model privileges it does not
need (MITRE, 2026).

Model execution remains inside the central worker. The model credential
is the GitHub Secret `NVIDIA_NIM_API_KEY`; the caller does not receive or
forward it.

Before protected-main activation, the repository variable
`OPENCODE_REPOSITORY_DISPATCH_TARGETS` must contain the exact
`ContextualWisdomLab/LineageWeave` target. Missing or mismatched
configuration fails before mutation credential materialization.

## Security, standalone operation, and modularity

The caller adds no LineageWeave runtime dependency, database object,
network endpoint, tenant authority, or product credential. LineageWeave
continues to run as a standalone lineage reconstruction service. Naruon,
RankWeave, ThreadWeave, TEPP, fast-mlsirm, keyverse, and
contextual-orchestrator may be imported as modules, but they cannot
weaken LineageWeave's exact-head, approval, or security gates.

## Verification and rollback

Machine-checkable contracts require the exact target/base, minute 4
cadence, non-cancelling single-flight group, one dispatch, two-hour
retry floor, explicit secret mapping, read-only contents plus job-scoped
`id-token: write`, focused path-filter coverage, and absence of model or
Copilot credentials. Independent `pull_request`, `push`, and `compileall`
path blocks must each name the caller, doctoring, or contract they own.

After source integration, closure requires a scheduled or manual
protected-main consumer run proving the exact LineageWeave repository and
`main` base. Source checks alone are not protected-main operational acceptance.
Merge still requires zero unresolved valid findings and a
qualifying independent non-author approval.

Rollback removes the LineageWeave caller, its focused test, doctoring, and
central path-filter/documentation entries. It must not remove scheduler
dispatch validation or affect independent product callers.

## APA 7th references

GitHub, Inc. (n.d.-a). *Events that trigger workflows*. GitHub Docs.
Retrieved August 23, 2026, from
https://docs.github.com/en/actions/reference/workflows-and-actions/events-that-trigger-workflows#schedule

GitHub, Inc. (n.d.-b). *Reuse workflows*. GitHub Docs. Retrieved August
23, 2026, from
https://docs.github.com/en/actions/how-tos/sharing-automations/reuse-workflows

GitHub, Inc. (n.d.-c). *Automatic token authentication*. GitHub Docs.
Retrieved August 23, 2026, from
https://docs.github.com/en/actions/security-for-github-actions/security-guides/automatic-token-authentication#permissions-for-the-github-token

MITRE. (2026). *CWE-250: Execution with unnecessary privileges*.
https://cwe.mitre.org/data/definitions/250.html

National Institute of Standards and Technology. (2022). *Secure software
development framework (SSDF) version 1.1: Recommendations for mitigating
the risk of software vulnerabilities* (NIST Special Publication 800-218).
https://doi.org/10.6028/NIST.SP.800-218

NVIDIA. (n.d.). *NVIDIA NIM for large language models documentation*.
Retrieved August 23, 2026, from
https://docs.nvidia.com/nim/large-language-models/latest/

OpenCode. (n.d.). *OpenCode documentation*. Retrieved August 23, 2026,
from https://opencode.ai/docs/
Loading
Loading