test(review): lock split target and central mention authority - #1623
seonghobae wants to merge 13 commits into
Conversation
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Team Run ID: Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Preserve the current writer history while joining protected main. The effective delta is limited to permanent assertions that sibling target access and central repository_dispatch use distinct credentials.
Preserve the exact split-authority regression while carrying protected-main OpenCode queue-capacity changes. The two branch test files do not overlap main's intervening workflow/contract edits.
|
2026-09-20 protected-base admission correction for GitHub reports this Ready PR mechanically non-mergeable. Exact comparison with protected Moving the PR to Draft / Proposed preserves every commit, review, thread, and valid delta. This is not closure or abandonment. Reconcile protected main through an ordinary non-force merge, repair valid findings, run terminal exact-head protection, and obtain qualifying independent current-head approval before returning to Ready. No review dismissal, synthetic status, manual rerun, bypass, Force Push, merge, or Close is authorized. |
Verified review-evaluation case
A current-head Devin review correctly identified that this branch had crossed two distinct authority domains: the organization sweep needs a cross-repository credential to read and acknowledge sibling PRs, but
agent_mention_router.dispatch_request()always publishes wrapper events toContextualWisdomLab/.github. Replacing the central job token with the target/App credential can therefore make the installation-fallback path unable to dispatch the central workflow.The original branch hypothesis was falsified. Protected current
main@4ae90e18b03a3a455e13e501628010cabc5c37a8already has the correct split: target reads use the selected organization/App credential while central artifact lookup andrepository_dispatchuse the.githubjob-scopedgithub.tokenwith job-scopedcontents: write.Finding-to-fix closure
AGENT_DISPATCH_TOKEN: ${{ github.token }}in the sweep and rejectexport AGENT_DISPATCH_TOKEN="$TARGET_REPOSITORY_TOKEN".repos/ContextualWisdomLab/.github/dispatcheswhile acknowledgements mutate only the target repository.This converts a demonstrated external-review finding into a durable Noema/OpenCode false-negative/false-positive evaluation case for internal-vs-external authority-boundary overreach, instead of shipping the initially proposed fix.
Scope and acceptance
This PR no longer claims that the target/dispatch credential split caused
semantic-data-portal#81to miss an OpenCode verdict. That incident remains a separate causal investigation and must not be 'fixed' by broadening or conflating credential authority.Current exact head:
e30ccae6f0fc8c16f7b67650d0523d1639f10281.Require fresh exact-head checks/review evidence and ordinary protected-branch admission. No gate, approval, merge authority, or external-write scope is expanded.