Skip to content

fix(audio): establish canonical local-audio resource policy - #866

Open
seonghobae wants to merge 672 commits into
developfrom
fix/audio-resource-policy-781
Open

seonghobae wants to merge 672 commits into
developfrom
fix/audio-resource-policy-781

Conversation

@seonghobae

@seonghobae seonghobae commented Aug 16, 2026

Copy link
Copy Markdown
Collaborator

Canonical #781 Resource Admission & Decode lane

BandScope local-audio Resource Admission & Decode의 단일 source owner입니다. Current source head는 0cb51e4d042a8f4cd5742086156a307bfe1ffac6, base는 protected develop@314ddeae7b775a4957594b599358c8255617eb2e이며 Open / Ready / mergeable입니다. Predecessor·cancelled-run·downstream evidence를 current source head로 이전하지 않습니다.

Ownership 경계는 유지합니다. #1116만 docs/product-technical-gap-baseline.md를 쓰고, #970은 durable Project Persistence와 derived cache/final rehearsal-result persistence/reuse, #1160은 protected/released Resource Admission + Project Persistence의 Active Player 소비를 소유합니다. Repository-generic Security Notes parser/checker는 #1204가 소유합니다. Dependency/frontend/control-plane 경고는 각각의 canonical owner에서 처리하며 #866에 섞지 않습니다.

Current semantic lineage

344b273c49758d46181511940c4ac16eaa04208b까지 owned-production Python statement/branch 100%와 unintended warning 0을 달성했습니다. Preservation #1197의 valid projectId whitespace/dot invariant도 이 canonical branch에서 RED→minimal fix로 직접 승계했습니다.

  • RED f920a4c2acce56b8eaa43cff09c2d74098c45c0b: " .. ", " . ", " project-1 " 거부와 project-1, my..id 보존.
  • GREEN 0cb51e4d042a8f4cd5742086156a307bfe1ffac6: leading/trailing whitespace와 stripped ./..를 canonical validator에서 fail closed 처리.

#1197 branch 자체를 merge/cherry-pick하지 않았고 unrelated formatter/dependency delta도 가져오지 않았습니다.

Fresh gate correction — 2026-09-17

Exact 0cb51e4d...의 repository-owned workflows remain terminal ci=success, build-baseline=success, Security Scan=success, sbom=success, SAST Semgrep=success; organization CodeQL PR remains terminal failure through the central verdict-publication path.

A newer exact-head OpenCode review run reports COVERAGE_BLOCKED / Coverage gate: failure for workflow run 35014435731. Its formal review explicitly says approval is blocked by coverage evidence. Therefore the older statement that current-head acceptance evidence is fully green is no longer sufficient merge authority, even though the product ci workflow itself is green. Do not merge, self-approve, synthesize coverage status, or create a no-op retrigger. The coverage failure must be traced to its actual evidence producer/owner before any source change is made; the formal source review did not synthesize a product defect from that coverage result.

Current formal review inventory still contains no qualifying non-author APPROVED on exact 0cb51e4d.... CodeRabbit also skipped whole-PR review because the selected file count exceeds its current review limit/capacity; do not split the canonical Resource Admission vertical into arbitrary micro-PRs merely to satisfy that vendor limit.

Current protected / central authority

Protected develop remains 314ddeae7b775a4957594b599358c8255617eb2e with 14 required contexts: ci / build-and-test, dependency-review, sbom, Windows/macOS build gates, trivy-fs, coverage-evidence, opencode-review, strix, scan-pr-queue, osv-scan, scorecard, Analyze (javascript-typescript), Analyze (python).

Protected central .github/main is now 346b46d0025672b727242cec702ec2246b4c844d. Canonical central CodeQL bootstrap owner .github#2106 is exact 1336eae994859203b08ec40c174b55a0f435ef92, Open / Draft / mergeable. Its focused owner-identity RED was reverted before leaving a test-only non-green branch, so the canonical baseline still contains two ownerless cross-repository evidence identities and repair progress for that source finding remains zero. Current #2106 workflows are a fresh queued generation; predecessor settlement does not transfer.

GitHub-managed dynamic Analyze (javascript-typescript) / Analyze (python) and central CodeQL PR compatibility are distinct evidence until the organization rollout deliberately converges them. BandScope does not copy central handler code, manufacture statuses, or weaken protected contexts.

Dependency boundaries

#970 remains Project Persistence/cache owner; #1204 remains generic Security Notes governance owner; #1160 remains Active Player consumer. Final-result publication durability, feature-cache integrity/resource admission, packaged restart/power-loss evidence and audible-source re-admission stay outside #866. Cache identity is not scientific reproducibility evidence until model/implementation generation plus checkpoint provenance/rights are bound.

Acceptance / next boundary

  1. Preserve source 0cb51e4d... unless a source-backed finding is proven.
  2. Trace the exact-head COVERAGE_BLOCKED result to its evidence producer before deciding whether any repository source change is causal.
  3. Track .github#2106 until owner-qualified source evidence and authenticated terminal CodeQL settlement reach protected central main.
  4. Require one unchanged final fix(audio): establish canonical local-audio resource policy #866 identity with every applicable protected/central gate terminal-success, zero valid unresolved findings, and qualifying independent non-author approval before normal protected merge.
  5. No bypass, self-approval, force-push, destructive rebase, synthetic status, no-op freshness commit, copied scanner, or predecessor evidence transfer.
  6. Only after protected fix(audio): establish canonical local-audio resource policy #866 integration should fix(project): stage saves before atomic publication #970 and then feat(player): admit and bind playable stem artifacts #1160 ordinary/non-force reconcile onto that ancestry.

UI Delivery Gate: FAIL — actual audio→audible playback, restart re-admission, stale-media races, pointer/touch/keyboard/browser focus, Narrator/VoiceOver, responsive evidence, KO/EN/JA/ZH/VI/ES/DE/FR acceptance가 남아 있습니다.

Commercial Release Gate: FAIL — current coverage evidence, independent review, central CodeQL settlement, #970 packaged fault injection, rights-cleared real-audio MIR reproducibility, Windows containment, model/audio licensing, signing/notarization, immutable release/SBOM/provenance와 updater rollback이 남아 있습니다.

@coderabbitai

coderabbitai Bot commented Aug 16, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Too many files!

This PR contains 120 files, which is 20 over the limit of 100.

To get a review, reduce the PR to 100 files or fewer by splitting it into smaller PRs or changing its base branch.

Upgrade to a paid plan to raise the limit.

This review couldn't start because sufficient usage credits or metered capacity aren't available. Add credits or update usage-based reviews in the billing tab, then retry.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: fb05b54b-9250-49fe-977f-fbe32ab9c548

📥 Commits

Reviewing files that changed from the base of the PR and between 314ddea and 0cb51e4.

⛔ Files ignored due to path filters (1)
  • apps/desktop/src-tauri/gen/schemas/capabilities.json is excluded by !**/gen/**
📒 Files selected for processing (120)
  • ARCHITECTURE.md
  • CHANGELOG.md
  • CLAUDE.md
  • apps/desktop/core/Cargo.toml
  • apps/desktop/core/src/audio_resource.rs
  • apps/desktop/core/src/content_sha256.rs
  • apps/desktop/core/src/lib.rs
  • apps/desktop/core/src/process_output.rs
  • apps/desktop/core/src/publication_identity.rs
  • apps/desktop/core/src/root.rs
  • apps/desktop/core/src/score_pdf.rs
  • apps/desktop/core/tests/analysis_job_cancellation_error.rs
  • apps/desktop/core/tests/audio_resource_next_action.rs
  • apps/desktop/core/tests/audio_resource_policy.rs
  • apps/desktop/core/tests/content_sha256_shared_kernel.rs
  • apps/desktop/core/tests/local_audio_content_identity.rs
  • apps/desktop/core/tests/local_audio_publication_identity.rs
  • apps/desktop/core/tests/local_audio_publication_identity_deserialization.rs
  • apps/desktop/core/tests/score_pdf_read.rs
  • apps/desktop/core/tests/youtube_process_containment.rs
  • apps/desktop/src-tauri/build.rs
  • apps/desktop/src-tauri/capabilities/main.json
  • apps/desktop/src-tauri/permissions/autogenerated/cancel_analysis_job.toml
  • apps/desktop/src-tauri/src/local_audio_publication.rs
  • apps/desktop/src-tauri/src/main.rs
  • apps/desktop/src-tauri/tests/analysis_job_cancellation_contract.rs
  • apps/desktop/src-tauri/tests/analysis_process_job_identity_contract.rs
  • apps/desktop/src-tauri/tests/analysis_process_output_admission_contract.rs
  • apps/desktop/src-tauri/tests/analysis_process_progress_state_contract.rs
  • apps/desktop/src-tauri/tests/analysis_process_requested_at_contract.rs
  • apps/desktop/src-tauri/tests/analysis_process_terminal_containment_contract.rs
  • apps/desktop/src-tauri/tests/analysis_process_terminal_status_contract.rs
  • apps/desktop/src-tauri/tests/local_audio_publication_contract.rs
  • apps/desktop/src-tauri/tests/youtube_process_containment_runtime.rs
  • apps/desktop/src/lib/analysis.audio-resource-next-action.test.ts
  • apps/desktop/src/lib/analysis.cancellation-bridge.test.ts
  • apps/desktop/src/lib/analysis.resource-policy.test.ts
  • apps/desktop/src/lib/analysis.test.ts
  • apps/desktop/src/lib/analysis.ts
  • docs/architecture/overview.md
  • docs/doctoring/analysis-single-orchestration-owner.md
  • docs/doctoring/audio-resource-policy.md
  • docs/doctoring/feature-cache-archive-path-admission.md
  • docs/doctoring/feature-cache-generation-manifest.md
  • docs/doctoring/feature-cache-json-numeric-admission.md
  • docs/doctoring/feature-cache-metadata-sidecar-admission.md
  • docs/doctoring/feature-cache-replay-admission.md
  • docs/doctoring/feature-cache-resource-admission.md
  • docs/doctoring/local-audio-analysis-source-identity-handoff.md
  • docs/doctoring/local-audio-source-materialization.md
  • docs/doctoring/local-audio-stem-work-identity.md
  • docs/doctoring/model-output-shape-admission.md
  • docs/doctoring/request-path-security-diagnostics.md
  • docs/doctoring/subprocess-containment.md
  • docs/doctoring/youtube-process-containment.md
  • docs/security/app-security.md
  • packages/shared-types/src/index.ts
  • packages/shared-types/test/analysis_job_cancellation.test.ts
  • services/analysis-engine/src/bandscope_analysis/__init__.py
  • services/analysis-engine/src/bandscope_analysis/api.py
  • services/analysis-engine/src/bandscope_analysis/audio_decode.py
  • services/analysis-engine/src/bandscope_analysis/audio_metadata.py
  • services/analysis-engine/src/bandscope_analysis/audio_resource_policy.py
  • services/analysis-engine/src/bandscope_analysis/chords/chord_recognizer.py
  • services/analysis-engine/src/bandscope_analysis/cli.py
  • services/analysis-engine/src/bandscope_analysis/feature_cache_admission.py
  • services/analysis-engine/src/bandscope_analysis/feature_cache_generation.py
  • services/analysis-engine/src/bandscope_analysis/separation/audio_separator.py
  • services/analysis-engine/src/bandscope_analysis/temporal/analyzer.py
  • services/analysis-engine/src/bandscope_analysis/transcription/api.py
  • services/analysis-engine/src/bandscope_analysis/youtube.py
  • services/analysis-engine/tests/test_api.py
  • services/analysis-engine/tests/test_audio_decode_backing_memory.py
  • services/analysis-engine/tests/test_audio_decode_dtype_boundary.py
  • services/analysis-engine/tests/test_audio_decode_port.py
  • services/analysis-engine/tests/test_audio_decode_preconversion_budget.py
  • services/analysis-engine/tests/test_audio_decode_reproducibility.py
  • services/analysis-engine/tests/test_audio_metadata.py
  • services/analysis-engine/tests/test_audio_model_output_policy.py
  • services/analysis-engine/tests/test_audio_resource_policy.py
  • services/analysis-engine/tests/test_audio_resource_policy_coverage_regressions.py
  • services/analysis-engine/tests/test_audio_resource_policy_dtype.py
  • services/analysis-engine/tests/test_audio_resource_policy_finiteness_memory.py
  • services/analysis-engine/tests/test_audio_resource_policy_integration.py
  • services/analysis-engine/tests/test_audio_separator_device_boundary.py
  • services/analysis-engine/tests/test_branch_coverage_contract.py
  • services/analysis-engine/tests/test_chord_recognizer.py
  • services/analysis-engine/tests/test_cli.py
  • services/analysis-engine/tests/test_cli_requested_at_authority.py
  • services/analysis-engine/tests/test_cli_source_identity_cache.py
  • services/analysis-engine/tests/test_cli_source_identity_temp_scope.py
  • services/analysis-engine/tests/test_current_coverage_boundaries.py
  • services/analysis-engine/tests/test_feature_cache_archive_path_admission.py
  • services/analysis-engine/tests/test_feature_cache_generation_manifest.py
  • services/analysis-engine/tests/test_feature_cache_json_number_admission.py
  • services/analysis-engine/tests/test_feature_cache_metadata_admission.py
  • services/analysis-engine/tests/test_feature_cache_metadata_generation.py
  • services/analysis-engine/tests/test_feature_cache_producer_admission.py
  • services/analysis-engine/tests/test_feature_cache_protocol_contract.py
  • services/analysis-engine/tests/test_feature_cache_resource_admission.py
  • services/analysis-engine/tests/test_feature_cache_role_binding.py
  • services/analysis-engine/tests/test_project_id_admission.py
  • services/analysis-engine/tests/test_request_security_diagnostics.py
  • services/analysis-engine/tests/test_resource_admission_coverage_edges.py
  • services/analysis-engine/tests/test_resource_admission_reachable_edges.py
  • services/analysis-engine/tests/test_segmenter.py
  • services/analysis-engine/tests/test_separation.py
  • services/analysis-engine/tests/test_stem_separation_logging_privacy.py
  • services/analysis-engine/tests/test_stem_separation_traceback_privacy.py
  • services/analysis-engine/tests/test_supply_chain_policy.py
  • services/analysis-engine/tests/test_temporal.py
  • services/analysis-engine/tests/test_temporal_error_privacy.py
  • services/analysis-engine/tests/test_transcription.py
  • services/analysis-engine/tests/test_youtube.py
  • services/analysis-engine/tests/test_youtube_downloaded_duration_revalidation.py
  • services/analysis-engine/tests/test_youtube_duration_contract.py
  • services/analysis-engine/tests/test_youtube_fragment_identity_cleanup.py
  • services/analysis-engine/tests/test_youtube_post_download_admission_reason.py
  • services/analysis-engine/tests/test_youtube_post_download_path_authority.py
  • services/analysis-engine/tests/test_youtube_transient_cleanup_authority.py

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@seonghobae
seonghobae changed the base branch from develop to fix/bounded-score-pdf-read-864 August 16, 2026 14:38
@seonghobae
seonghobae changed the base branch from fix/bounded-score-pdf-read-864 to develop August 16, 2026 14:42
cursor[bot]
cursor Bot previously requested changes Aug 16, 2026

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Reviewed exact head 3f976e55. Local-file Python, TypeScript, and Rust encoded-byte ceilings match (100 MiB, exclusive upper bound, exact ceiling accepted). Do not mark Ready or merge this draft until YouTube download uses that same ceiling and #865 is in protected develop.

Request changes: import_youtube_url now calls validate_local_audio_file_size only after youtube.py has already finished. That module still downloads with no yt-dlp max_filesize and then rejects > 50 * 1024 * 1024. A 60–100 MiB import that policy-v1 would accept is still rejected with a 50 MB message. A multi-gigabyte transfer can fill the cache root before the new native check ever runs, so the new YouTube-path size check is dead for oversized inputs.

Doctoring residual-risk text on this head still says the desktop/Rust intake path is not established, which is no longer true for local-file bootstrap.

The successor branch cursor/bc-977eae6a-247d-427f-a2eb-533a75284f2e-6591 drives YouTube admission from DEFAULT_MAX_ENCODED_FILE_BYTES, aborts in-flight, and updates the evidence note. Apply that here or reconstruct this branch onto it before Ready.

Checks on this synchronization were still queued at review time. Queued, skipped, predecessor, or draft-skipped CodeRabbit evidence is not success.

Open in Web View Automation 

Sent by Cursor Automation: fix all

Comment thread apps/desktop/src-tauri/src/main.rs
Comment thread docs/doctoring/audio-resource-policy.md Outdated
Comment thread CHANGELOG.md
cursor[bot]
cursor Bot previously requested changes Aug 16, 2026

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Stale comment

Reviewed exact head 1f3fdb8b. The prior 50 MB / missing max_filesize / stale doctoring findings are fully addressed: YouTube download now uses DEFAULT_MAX_ENCODED_FILE_BYTES, rejects announced oversize before download=True, aborts from the progress hook, and revalidates the written file. Do not mark Ready or merge this draft until #865 is in protected develop and the abort-path cache leak below is on this head.

Request changes: in-flight abort still returns size_exceeded without deleting bytes already written. yt-dlp HttpFD writes the current block, then calls the hook; on exception it only closes the stream. The post-download path deletes an oversize final artifact; the abort path does not. Each rejected import can leave *.part, *-Frag*, and *.ytdl in a fresh project cache.

Successor cursor/bc-75568fe4-aa90-4cf7-bb40-c9d68be95b82-b46f at 5e8fa77f deletes owned siblings that stay inside that import out_dir and ignores escaped paths. Apply that here or reconstruct this branch onto it before Ready.

Queued, skipped, predecessor, or draft-skipped CodeRabbit evidence is not success.

Open in Web View Automation 

Sent by Cursor Automation: Fix Issues

Comment thread services/analysis-engine/src/bandscope_analysis/youtube.py

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed exact head 5e8fa77f on fix/audio-resource-policy-781 (base develop@acdbea63). The prior in-flight abort finding is fully addressed on this head: _abort_over_budget_download deletes owned siblings before the fail-closed size_exceeded raise. _owned_file_path realpaths the candidate and the import out_dir, rejects the directory root, and requires resolved.startswith(root + os.sep), so a path or symlink that escapes that import directory is ignored. _remove_download_artifacts stems tmpfilename / filename (one .part strip) and removes matching stem, stem.*, and stem-* entries, which covers .part, .ytdl, and -Frag*. test_download_youtube_audio_progress_hook_deletes_partial_artifacts proves those three are gone after abort while keep-me.txt and an outsider .part remain.

The earlier 50 MB post-write, missing Rust intake doctoring, CHANGELOG 50 MB, and progress-hook int-only items stay fixed. YouTube admission uses DEFAULT_MAX_ENCODED_FILE_BYTES (100 MiB) in Python, desktop analysis.ts, and native audio_resource.rs. Announced oversize rejects before download=True. Exact 100 MiB is accepted; 60 MiB is accepted; 100 MiB + 1 is rejected. Closed #875 is the same tree as this head — do not reopen a competing abort-cleanup owner.

Next action: keep this Draft. Integrate #865 into protected develop first, then reconstruct and revalidate this stack on the unchanged resulting exact head. Do not mark Ready or merge on queued, skipped, predecessor, or CodeRabbit draft-skipped evidence. Remaining #781 channel/rate contracts and decoded-memory / CPU/GPU admission budgets are still out of this draft's claim — do not treat policy-v1 encoded-byte admission as full #781 closure.

Residual (not a change request): a process kill, a locked Windows .part, or a differently named format-id fragment can still leave cache bytes until that per-project import directory is removed. Generic DownloadError / timeout paths do not sweep unnamed artifacts. Admission still fails closed.

Open in Web View Automation 

Sent by Cursor Automation: Fix Issues

Comment thread services/analysis-engine/tests/test_youtube_duration_contract.py Fixed
Comment thread services/analysis-engine/tests/test_youtube_duration_contract.py Fixed

Copy link
Copy Markdown
Collaborator Author

@opencode-agent Take the canonical #781 owner lane on the existing fix/audio-resource-policy-781 branch only. Fresh exact head 223dd78126deeb3f12a68dc140f6a83fbe422225, protected base develop@acdbea6344fe1231c39535b575f4de35e4c607c9, logical predecessor #865 f86e266b2ab2dc5a95e6b4a484e777b29f0feeaf. Do not create a competing PR, rebase/force-push, touch foreign repos, or suppress #783 dependency findings.

First repair the exact current-head CI blocker with repository-pinned tooling, not guessed formatting: CI run 32336903836, job 96328111793, actual checkout 92c5d3db777cbea11bd73f5f3e7dccf5482cb4cf passed docs/security/supply-chain/desktop lint and then failed first at services/analysis-engine/src/bandscope_analysis/__init__.py:3:1 Ruff I001. Run the pinned Ruff fixer/checker for that file, preserve the privacy-filter import-before-API semantics, and commit the smallest formatter-equivalent repair.

Then, on the resulting exact head, preserve the unique non-duplicative #781 evidence currently stranded in competing PR #985 (feat/canonical-audio-resource-policy-781@d2cf2047af790cddf02b3957856d246638a754b5) by integrating it into this canonical lane with TDD rather than merging/cherry-picking #985 wholesale:

  • fix(audio): establish canonical local-audio resource policy #866 already owns cross-boundary native desktop-core + desktop bridge + service admission + temporal/separation + YouTube resource policy. Keep that authority and its one-sample-over decode probe, payload-safe errors, device boundary, and existing tests.
  • Add source-container metadata admission before any librosa.load(... sr=..., mono=True, duration=...) transform can hide the original source duration/sample-rate/channel count. Use one canonical policy-owned source-rate/channel contract, not helper-local constants; the feat(analysis): enforce one canonical audio resource policy (#781) #985 candidate evidence is 8 kHz–192 kHz and mono/stereo. Validate exact product compatibility before adopting those bounds. The preflight must inspect the already-open handle without PCM decode, rewind it for the decoder, fail closed/payload-free on malformed metadata, and keep the existing post-decode validation.
  • Add realistic REDs proving >15-minute source metadata, unsupported original source rate, and >2 original channels are rejected before librosa.load in every local decoder path that transforms these properties (at minimum TemporalAnalyzer and AudioStemSeparator; include bass transcription if its bytes decoder has the same bypass). Preserve encoded-byte checks before metadata parsing.
  • Preserve feat(analysis): enforce one canonical audio resource policy (#781) #985's shape-invariant chord empty-buffer regression: zero-element arrays such as (2, 0) must return no chords rather than bypass the intended empty-audio behavior merely because len(y) != 0; non-empty malformed layouts must still fail closed under the canonical policy.
  • Reconcile stale reason-code tests against this branch's published cross-boundary error contract; do not replace fix(audio): establish canonical local-audio resource policy #866's established policy/error architecture merely to match feat(analysis): enforce one canonical audio resource policy (#781) #985.

Run focused RED→GREEN tests, repository-pinned Ruff check/format, Bandit, mypy where applicable, then canonical quickcheck. If a finding belongs to #865 or #783 rather than this exact branch, prove the first causal boundary and leave it with its owner rather than adding a leaf workaround. Commit only to this branch and report resulting exact head and evidence.

Copy link
Copy Markdown
Collaborator Author

@OpenCode repair exact head 223dd78126deeb3f12a68dc140f6a83fbe422225 only if fix/audio-resource-policy-781 is still unchanged. CI run 32336903836, job 96328111793, actual merge checkout 92c5d3db777cbea11bd73f5f3e7dccf5482cb4cf fails first at services/analysis-engine/src/bandscope_analysis/__init__.py:3 with Ruff I001 (uv run ruff check src tests). Run the repository-pinned Ruff/isort fixer on that file rather than guessing import order, inspect the resulting diff, and commit only the formatter-equivalent import-block change; do not alter the diagnostic privacy behavior, dependency/security policy, gates, lockfiles, stack ancestry, or other files. Then run focused uv run ruff check src/bandscope_analysis/__init__.py and uv run ruff format --check src/bandscope_analysis/__init__.py, followed by the normal exact-head CI. If the head moved, inspect the intervening delta and do not race the writer.

@seonghobae

Copy link
Copy Markdown
Collaborator Author

@opencode-agent Please review the current exact PR head c2cc5bbeda6628fa9999401d6b0d228cb9b6bb9c. Publish only a current-head APPROVED or CHANGES_REQUESTED verdict; do not rely on predecessor evidence or a provider-unavailable fallback. The branch remains subject to required Checks, unresolved-thread, independent-approval, and protected-merge rules.

@seonghobae

Copy link
Copy Markdown
Collaborator Author

Exact-head maintenance update for 505a595:

  • Ordinary-merged current origin/develop as b4a3513; CHANGELOG.md was the only conflict.
  • Fixed y.size zero-element chord handling for empty layouts (0, 2) and (2, 0).
  • Full local verification: 783 passed, 24 numeric-parity tests skipped by platform policy, 100% statements/branches/functions/lines; Ruff, mypy, and Bandit passed.
  • Existing source metadata preflight remains wired before all three local decoder paths; no duplicate policy authority added.

Keep Draft; predecessor evidence does not transfer.

@seonghobae

Copy link
Copy Markdown
Collaborator Author

@opencode-agent review\n\nReview only current PR head 505a595 against protected develop base 749511c. Revalidate the canonical local-audio resource policy, source metadata preflight before decode, post-decode limits, empty-layout chord handling, payload-safe diagnostics, exact tests, and current security checks. Do not reuse predecessor-head evidence or provider-unavailable results.

Copy link
Copy Markdown
Collaborator Author

Intervening central-main update after the preceding authority note: .github/main advanced normally to 78393ea901efc0d57b35dd1e383e473425b7c1da by #2163 (contextual-orchestrator sidecar pin → 767e67fb, no implicit model timeout). The delta from d6cf5726... is bounded to CHANGELOG.md, ADR-0003, contextual_orchestrator_review_sidecar.sh, and its contract test; it does not repair or remove the current Strix changed-file attribution RED. #939 has already been updated to adopt this intervening delta during ordinary reconciliation. Use 78393ea... as the current central protected-main authority; the dependency order and #866 no-source-mutation decision in the preceding note are otherwise unchanged.

@opencode-agent

Copy link
Copy Markdown
Contributor

Queued @opencode-agent for PR #866 at head 0cb51e4d042a8f4cd5742086156a307bfe1ffac6. Central exact-name Actions artifacts are the durable dispatch ledger; existing review workflows remain authoritative for the final verdict and failure evidence.

@opencode-agent

Copy link
Copy Markdown
Contributor

Queued @opencode-agent for PR #866 at head 0cb51e4d042a8f4cd5742086156a307bfe1ffac6. Central exact-name Actions artifacts are the durable dispatch ledger; existing review workflows remain authoritative for the final verdict and failure evidence.

@opencode-agent

Copy link
Copy Markdown
Contributor

Queued @opencode-agent for PR #866 at head 0cb51e4d042a8f4cd5742086156a307bfe1ffac6. Central exact-name Actions artifacts are the durable dispatch ledger; existing review workflows remain authoritative for the final verdict and failure evidence.

@opencode-agent

Copy link
Copy Markdown
Contributor

Queued @opencode-agent for PR #866 at head 0cb51e4d042a8f4cd5742086156a307bfe1ffac6. Central exact-name Actions artifacts are the durable dispatch ledger; existing review workflows remain authoritative for the final verdict and failure evidence.

Copy link
Copy Markdown
Collaborator Author

2026-09-14 KST fresh central-prerequisite correction for unchanged exact 0cb51e4d042a8f4cd5742086156a307bfe1ffac6:

The central .github#2106 source is still exact 1ba96e4ddf6a800435651ec1c49acff533242fd9 on protected main@828eaaefb0cc97bba4da63eb9270447476d26710. Its required CodeQL run 34773233399 is terminal failure only because the first-pass compatibility shards recorded VERDICT_STATE=pending after the run-wide dispatch job succeeded. The matching protected-handler execution now exists as repository-dispatch run 34785332128, exact title CodeQL Scan Dispatch ContextualWisdomLab/.github#2106@1ba96e4ddf6a800435651ec1c49acff533242fd9/828eaaefb0cc97bba4da63eb9270447476d26710/34773233399, but it is still queued in the organization-wide Actions backlog. It has not executed settlement yet, so there is no new central source/SARIF finding to copy into BandScope and no basis for a consumer-side rerun.

Keep #866 unchanged and Ready but unmerged. Do not create a source-neutral wake commit, manually rerun the consumer CodeQL workflow, synthesize statuses, or copy the central handler. Once 34785332128 becomes terminal, re-read its exact scan/SARIF/settlement evidence before classifying the central prerequisite as GREEN or opening a new causal repair. The separate current-head non-author formal approval requirement on #866 remains unchanged.

Copy link
Copy Markdown
Collaborator Author

Central prerequisite refresh: .github/main has advanced ordinarily to protected ebc69a4016f7668beaef5e3b592d378f22ada684. Canonical .github#2106 was therefore non-force reconciled through ordinary PR #2185 and now has exact head 4288590362282074d55ef874291ffc2ba884e93d on that base. Its prior CodeQL handler tuple #2106@1ba96e.../828eaa.../34773233399 is historical and still queued with no assigned runner; the central repository currently has a broad Actions queue, so BandScope must not manufacture a rerun or copy the handler.

#866 source identity remains unchanged. Keep consumer-side acceptance bound to fresh live central metadata: only the new #2106 exact-head generation can become prerequisite evidence, after terminal checks and qualifying review. The old handler/check generation does not transfer across the ordinary ancestry change.

Copy link
Copy Markdown
Collaborator Author

Project Persistence dependent authority refresh (2026-09-14): #970 moved from 46478c4aadb4f4ad4a5c4ed9821a6456be0db09d to exact f408b5a4e322b16159fb87df6c5e3e07692fd36c with an intentional durability RED only. The new executable tests require one Project Persistence-owned durable no-replace publication port for an already-synced app-owned source stage and cover success, competing-destination preservation, and parent-directory durability failure. Production materialize_local_audio_source still uses the hard-link path at this exact head, so #970 is not GREEN and no durability claim transfers to #866. #866 remains unchanged at 0cb51e4d042a8f4cd5742086156a307bfe1ffac6; do not duplicate the filesystem publication owner here.

Copy link
Copy Markdown
Collaborator Author

#970 dependency authority refresh — source boundary unchanged

Project Persistence #970 has advanced ordinarily from the previously recorded 1fa9dd315cf13884dcd9973dafe960a2aeb75e4a to exact 316cf44961ee6a7a0a79d2d9efc80a169a02f2e8, still Open / Draft / mergeable on protected develop@314ddeae7b775a4957594b599358c8255617eb2e.

The new #970 slice closes the previously recorded derived-cache scientific-equivalence gap without moving Resource Admission authority into persistence:

  • RED efcffad68c5f0e1af4f14729bc7e063d9ce5bc82: cache identity must bind the current MIR implementation/model generation and fail closed when that generation cannot be established.
  • 33ebea0219e0341dd574af395b1b6b4c93d888d5: Signal/MIR-owned generation adapter consumes the existing AudioStemSeparator checkpoint mapping/parser plus installed Demucs/torch package metadata; it does not copy fix(audio): establish canonical local-audio resource policy #866 source-byte identity logic.
  • Fix 3b1c2378abfad1a08f0e20e22617bbc06447b283: Project Persistence cache identity now combines fix(audio): establish canonical local-audio resource policy #866 native byte-count/SHA-256 evidence with that MIR-generation discriminator and advances final-result analysis generation.
  • Coverage f17051f8e2fe9fc2b2857232573f617f12d4da44, existing round-trip update 8cee9523f4ad5026e3db59524d053e1f333faa38, style-only 316cf44961ee6a7a0a79d2d9efc80a169a02f2e8, and traceability a035d32c182d033820edfe085700ea23f1448bc6 complete the current source slice.

#866 remains the sole local-audio Resource Admission & Decode source owner. Do not add feature-manifest parsing, NPZ admission, MIR generation, checkpoint provenance, cache publication, or derived-cache hashing here. #970 consumes #866 evidence only after the existing typed/native handoff.

This is source-level repair, not protected/release truth. Exact 316cf449... hosted runs are fresh and non-terminal, and no predecessor checks/reviews transfer. Full checkpoint digest/signature/acquisition provenance/rights and packaged scientific acceptance remain Distribution/MIR release work, not #866 work.

Copy link
Copy Markdown
Collaborator Author

Authority refresh — no #866 source change.

Project Persistence #970 is no longer at the 1fa9dd... state described in the current body. Fresh live state is exact 316cf44961ee6a7a0a79d2d9efc80a169a02f2e8, Open / Draft / mergeable on protected develop@314ddeae7b775a4957594b599358c8255617eb2e. Its later ordinary descendants bind derived-cache reuse to current MIR implementation/model generation; #866 still owns only native source admission/byte-count/SHA-256 and must not copy that consumer logic.

Distribution/model-release authority also advanced separately in #1126 exact a6e48e0f63e0eaa87e6304abb629fac80a66cd89. It now keeps upstream htdemucs commercially blocked under #1181 and prevents version-tag artifact packaging unless a future exact model artifact is commercially admitted with immutable rights/provenance/loader-policy evidence. This is not a Resource Admission source delta and is not a reason to move #866.

Central .github#2106 remains exact 9defd52f4a3b42d6a63a9520d6da82224d8c864d on protected .github/main@91be6442906c7b6b4f600272c953699708394327, Draft with its own traceability/check settlement. #866 stays exact 0cb51e4d042a8f4cd5742086156a307bfe1ffac6; predecessor/downstream evidence does not transfer.

@opencode-agent

Copy link
Copy Markdown
Contributor

Queued @opencode-agent for PR #866 at head 0cb51e4d042a8f4cd5742086156a307bfe1ffac6. Central exact-name Actions artifacts are the durable dispatch ledger; existing review workflows remain authoritative for the final verdict and failure evidence.

@opencode-agent

Copy link
Copy Markdown
Contributor

Queued @opencode-agent for PR #866 at head 0cb51e4d042a8f4cd5742086156a307bfe1ffac6. Central exact-name Actions artifacts are the durable dispatch ledger; existing review workflows remain authoritative for the final verdict and failure evidence.

@opencode-agent

Copy link
Copy Markdown
Contributor

Already queued @opencode-agent on this exact request for PR #866 at head 0cb51e4d042a8f4cd5742086156a307bfe1ffac6. Central exact-name Actions artifacts are the durable dispatch ledger; existing review workflows remain authoritative for the final verdict and failure evidence.

@opencode-agent

Copy link
Copy Markdown
Contributor

Queued @opencode-agent for PR #866 at head 0cb51e4d042a8f4cd5742086156a307bfe1ffac6. Central exact-name Actions artifacts are the durable dispatch ledger; existing review workflows remain authoritative for the final verdict and failure evidence.

@opencode-agent

Copy link
Copy Markdown
Contributor

Queued @opencode-agent for PR #866 at head 0cb51e4d042a8f4cd5742086156a307bfe1ffac6. Central exact-name Actions artifacts are the durable dispatch ledger; existing review workflows remain authoritative for the final verdict and failure evidence.

@opencode-agent

Copy link
Copy Markdown
Contributor

Queued @opencode-agent for PR #866 at head 0cb51e4d042a8f4cd5742086156a307bfe1ffac6. Central exact-name Actions artifacts are the durable dispatch ledger; existing review workflows remain authoritative for the final verdict and failure evidence.

@opencode-agent

Copy link
Copy Markdown
Contributor

Queued @opencode-agent for PR #866 at head 0cb51e4d042a8f4cd5742086156a307bfe1ffac6. Central exact-name Actions artifacts are the durable dispatch ledger; existing review workflows remain authoritative for the final verdict and failure evidence.

@opencode-agent

Copy link
Copy Markdown
Contributor

Already queued @opencode-agent on this exact request for PR #866 at head 0cb51e4d042a8f4cd5742086156a307bfe1ffac6. Central exact-name Actions artifacts are the durable dispatch ledger; existing review workflows remain authoritative for the final verdict and failure evidence.

@opencode-agent

Copy link
Copy Markdown
Contributor

Queued @opencode-agent for PR #866 at head 0cb51e4d042a8f4cd5742086156a307bfe1ffac6. Central exact-name Actions artifacts are the durable dispatch ledger; existing review workflows remain authoritative for the final verdict and failure evidence.

@opencode-agent

Copy link
Copy Markdown
Contributor

Already queued @opencode-agent on this exact request for PR #866 at head 0cb51e4d042a8f4cd5742086156a307bfe1ffac6. Central exact-name Actions artifacts are the durable dispatch ledger; existing review workflows remain authoritative for the final verdict and failure evidence.

@opencode-agent

Copy link
Copy Markdown
Contributor

Queued @opencode-agent for PR #866 at head 0cb51e4d042a8f4cd5742086156a307bfe1ffac6. Central exact-name Actions artifacts are the durable dispatch ledger; existing review workflows remain authoritative for the final verdict and failure evidence.

seonghobae added a commit that referenced this pull request Sep 16, 2026
The CR/LF log-forging finding is valid, but this generated implementation remains weaker than the canonical temporal privacy contract: it still emits the selected local-audio path and raw decoder exception text. The same finding is already preserved in #1211 for canonical owner #1055, which requires path-free bounded context plus exception type after the active #866 source lane releases.

Restore this duplicate branch to the protected develop tree as an ordinary descendant so it cannot become a second temporal source writer. Preserve the finding through the existing canonical/preservation path rather than merging a weaker repr(path) implementation.

No force update, destructive rebase, self-approval, gate weakening, or security-completion claim.
seonghobae added a commit that referenced this pull request Sep 16, 2026
The CR/LF log-forging finding is valid, but this branch's repr(path) implementation still discloses the selected local-audio path and preserves raw decoder exception text. Its focused test only asserts repr(path) on the info call and does not establish the stronger path-free failure contract.

Restore the duplicate branch to protected develop as an ordinary descendant. Preserve the valid finding in #1211 for canonical temporal privacy owner #1055, which already specifies attacker-shaped path plus decoder-exception RED and path-free, exception-type-only GREEN after active source owner #866 releases.

Also remove the foreign #1176 formatter delta. No force update, destructive rebase, self-approval, gate weakening, or security-completion claim.

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode reviewed the current-head product diff. Coverage is a separate gate.

Changed files

  • ARCHITECTURE.md — repository behavior
  • CHANGELOG.md — repository behavior
  • CLAUDE.md — repository behavior
  • apps/desktop/core/Cargo.toml — Rust workspace or package manifest
  • apps/desktop/core/src/audio_resource.rs — Rust package behavior
  • apps/desktop/core/src/content_sha256.rs — Rust package behavior
  • apps/desktop/core/src/lib.rs — Rust package behavior
  • apps/desktop/core/src/process_output.rs — Rust package behavior
  • apps/desktop/core/src/publication_identity.rs — Rust package behavior
  • apps/desktop/core/src/root.rs — Rust package behavior
  • apps/desktop/core/src/score_pdf.rs — Rust package behavior
  • apps/desktop/core/tests/analysis_job_cancellation_error.rs — regression suite
  • apps/desktop/core/tests/audio_resource_next_action.rs — regression suite
  • apps/desktop/core/tests/audio_resource_policy.rs — regression suite
  • apps/desktop/core/tests/content_sha256_shared_kernel.rs — regression suite
  • apps/desktop/core/tests/local_audio_content_identity.rs — regression suite
  • apps/desktop/core/tests/local_audio_publication_identity.rs — regression suite
  • apps/desktop/core/tests/local_audio_publication_identity_deserialization.rs — regression suite
  • apps/desktop/core/tests/score_pdf_read.rs — regression suite
  • apps/desktop/core/tests/youtube_process_containment.rs — regression suite
  • apps/desktop/src-tauri/build.rs — Rust package behavior
  • apps/desktop/src-tauri/capabilities/main.json — repository behavior
  • apps/desktop/src-tauri/gen/schemas/capabilities.json — repository behavior
  • apps/desktop/src-tauri/permissions/autogenerated/cancel_analysis_job.toml — repository behavior
  • apps/desktop/src-tauri/src/local_audio_publication.rs — Rust package behavior
  • apps/desktop/src-tauri/src/main.rs — Rust package behavior
  • apps/desktop/src-tauri/tests/analysis_job_cancellation_contract.rs — regression suite
  • apps/desktop/src-tauri/tests/analysis_process_job_identity_contract.rs — regression suite
  • apps/desktop/src-tauri/tests/analysis_process_output_admission_contract.rs — regression suite
  • apps/desktop/src-tauri/tests/analysis_process_progress_state_contract.rs — regression suite
  • apps/desktop/src-tauri/tests/analysis_process_requested_at_contract.rs — regression suite
  • apps/desktop/src-tauri/tests/analysis_process_terminal_containment_contract.rs — regression suite
  • apps/desktop/src-tauri/tests/analysis_process_terminal_status_contract.rs — regression suite
  • apps/desktop/src-tauri/tests/local_audio_publication_contract.rs — regression suite
  • apps/desktop/src-tauri/tests/youtube_process_containment_runtime.rs — regression suite
  • apps/desktop/src/lib/analysis.audio-resource-next-action.test.ts — TypeScript or JavaScript runtime
  • apps/desktop/src/lib/analysis.cancellation-bridge.test.ts — TypeScript or JavaScript runtime
  • apps/desktop/src/lib/analysis.resource-policy.test.ts — TypeScript or JavaScript runtime
  • apps/desktop/src/lib/analysis.test.ts — TypeScript or JavaScript runtime
  • apps/desktop/src/lib/analysis.ts — TypeScript or JavaScript runtime
  • docs/architecture/overview.md — operator or user guidance
  • docs/doctoring/analysis-single-orchestration-owner.md — operator or user guidance
  • docs/doctoring/audio-resource-policy.md — operator or user guidance
  • docs/doctoring/feature-cache-archive-path-admission.md — operator or user guidance
  • docs/doctoring/feature-cache-generation-manifest.md — operator or user guidance
  • docs/doctoring/feature-cache-json-numeric-admission.md — operator or user guidance
  • docs/doctoring/feature-cache-metadata-sidecar-admission.md — operator or user guidance
  • docs/doctoring/feature-cache-replay-admission.md — operator or user guidance
  • docs/doctoring/feature-cache-resource-admission.md — operator or user guidance
  • docs/doctoring/local-audio-analysis-source-identity-handoff.md — operator or user guidance
  • docs/doctoring/local-audio-source-materialization.md — operator or user guidance
  • docs/doctoring/local-audio-stem-work-identity.md — operator or user guidance
  • docs/doctoring/model-output-shape-admission.md — operator or user guidance
  • docs/doctoring/request-path-security-diagnostics.md — operator or user guidance
  • docs/doctoring/subprocess-containment.md — operator or user guidance
  • docs/doctoring/youtube-process-containment.md — operator or user guidance
  • docs/security/app-security.md — operator or user guidance
  • packages/shared-types/src/index.ts — TypeScript or JavaScript runtime
  • packages/shared-types/test/analysis_job_cancellation.test.ts — regression suite
  • services/analysis-engine/src/bandscope_analysis/__init__.py — Python module behavior
  • services/analysis-engine/src/bandscope_analysis/api.py — Python module behavior
  • services/analysis-engine/src/bandscope_analysis/audio_decode.py — Python module behavior
  • services/analysis-engine/src/bandscope_analysis/audio_metadata.py — Python module behavior
  • services/analysis-engine/src/bandscope_analysis/audio_resource_policy.py — Python module behavior
  • services/analysis-engine/src/bandscope_analysis/chords/chord_recognizer.py — Python module behavior
  • services/analysis-engine/src/bandscope_analysis/cli.py — Python module behavior
  • services/analysis-engine/src/bandscope_analysis/feature_cache_admission.py — Python module behavior
  • services/analysis-engine/src/bandscope_analysis/feature_cache_generation.py — Python module behavior
  • services/analysis-engine/src/bandscope_analysis/separation/audio_separator.py — Python module behavior
  • services/analysis-engine/src/bandscope_analysis/temporal/analyzer.py — Python module behavior
  • services/analysis-engine/src/bandscope_analysis/transcription/api.py — Python module behavior
  • services/analysis-engine/src/bandscope_analysis/youtube.py — Python module behavior
  • services/analysis-engine/tests/test_api.py — regression suite
  • services/analysis-engine/tests/test_audio_decode_backing_memory.py — regression suite
  • services/analysis-engine/tests/test_audio_decode_dtype_boundary.py — regression suite
  • services/analysis-engine/tests/test_audio_decode_port.py — regression suite
  • services/analysis-engine/tests/test_audio_decode_preconversion_budget.py — regression suite
  • services/analysis-engine/tests/test_audio_decode_reproducibility.py — regression suite
  • services/analysis-engine/tests/test_audio_metadata.py — regression suite
  • services/analysis-engine/tests/test_audio_model_output_policy.py — regression suite
  • services/analysis-engine/tests/test_audio_resource_policy.py — regression suite
  • services/analysis-engine/tests/test_audio_resource_policy_coverage_regressions.py — regression suite
  • services/analysis-engine/tests/test_audio_resource_policy_dtype.py — regression suite
  • services/analysis-engine/tests/test_audio_resource_policy_finiteness_memory.py — regression suite
  • services/analysis-engine/tests/test_audio_resource_policy_integration.py — regression suite
  • services/analysis-engine/tests/test_audio_separator_device_boundary.py — regression suite
  • services/analysis-engine/tests/test_branch_coverage_contract.py — regression suite
  • services/analysis-engine/tests/test_chord_recognizer.py — regression suite
  • services/analysis-engine/tests/test_cli.py — regression suite
  • services/analysis-engine/tests/test_cli_requested_at_authority.py — regression suite
  • services/analysis-engine/tests/test_cli_source_identity_cache.py — regression suite
  • services/analysis-engine/tests/test_cli_source_identity_temp_scope.py — regression suite
  • services/analysis-engine/tests/test_current_coverage_boundaries.py — regression suite
  • services/analysis-engine/tests/test_feature_cache_archive_path_admission.py — regression suite
  • services/analysis-engine/tests/test_feature_cache_generation_manifest.py — regression suite
  • services/analysis-engine/tests/test_feature_cache_json_number_admission.py — regression suite
  • services/analysis-engine/tests/test_feature_cache_metadata_admission.py — regression suite
  • services/analysis-engine/tests/test_feature_cache_metadata_generation.py — regression suite
  • services/analysis-engine/tests/test_feature_cache_producer_admission.py — regression suite
  • services/analysis-engine/tests/test_feature_cache_protocol_contract.py — regression suite
  • services/analysis-engine/tests/test_feature_cache_resource_admission.py — regression suite
  • services/analysis-engine/tests/test_feature_cache_role_binding.py — regression suite
  • services/analysis-engine/tests/test_project_id_admission.py — regression suite
  • services/analysis-engine/tests/test_request_security_diagnostics.py — regression suite
  • services/analysis-engine/tests/test_resource_admission_coverage_edges.py — regression suite
  • services/analysis-engine/tests/test_resource_admission_reachable_edges.py — regression suite
  • services/analysis-engine/tests/test_segmenter.py — regression suite
  • services/analysis-engine/tests/test_separation.py — regression suite
  • services/analysis-engine/tests/test_stem_separation_logging_privacy.py — regression suite
  • services/analysis-engine/tests/test_stem_separation_traceback_privacy.py — regression suite
  • services/analysis-engine/tests/test_supply_chain_policy.py — regression suite
  • services/analysis-engine/tests/test_temporal.py — regression suite
  • services/analysis-engine/tests/test_temporal_error_privacy.py — regression suite
  • services/analysis-engine/tests/test_transcription.py — regression suite
  • services/analysis-engine/tests/test_youtube.py — regression suite
  • services/analysis-engine/tests/test_youtube_downloaded_duration_revalidation.py — regression suite
  • services/analysis-engine/tests/test_youtube_duration_contract.py — regression suite
  • services/analysis-engine/tests/test_youtube_fragment_identity_cleanup.py — regression suite
  • services/analysis-engine/tests/test_youtube_post_download_admission_reason.py — regression suite
  • services/analysis-engine/tests/test_youtube_post_download_path_authority.py — regression suite
  • services/analysis-engine/tests/test_youtube_transient_cleanup_authority.py — regression suite

Changed behavior

classDiagram
  class LocalAudioCopyReceipt
  class validate_local_audio_file_size
  class copy_bounded_local_audio_with_receipt
  class verify_local_audio_publication_receipt
  class copy_bounded_local_audio
  class StreamingSha256
  class update
  class finalize_hex
Loading

Changed API

  • LocalAudioCopyReceipt
  • validate_local_audio_file_size
  • copy_bounded_local_audio_with_receipt
  • verify_local_audio_publication_receipt
  • copy_bounded_local_audio
  • StreamingSha256
  • update
  • finalize_hex
  • sha256_hex_reader
  • AppState
  • AppStateInner
  • AnalysisJobRequest
  • AnalysisJobErrorCode
  • AnalysisJobError
  • AnalysisJobState
  • AnalysisJobStage
  • AnalysisCacheStatus
  • RehearsalSongPayload
  • ScoreAttachmentMetadataPayload
  • ConfidencePayload
  • CuePayload
  • RangePayload
  • HarmonyPayload
  • ManualOverridePayload
  • RehearsalRolePayload
  • SectionTimeRangePayload
  • PartGraphNodePayload
  • RehearsalSectionPayload
  • ExportSummaryPayload
  • AnalysisJobStatus
  • LocalAudioSourcePayload
  • ProjectBootstrapSummaryPayload
  • next_project_id
  • youtube_source_from_metadata
  • is_supported_youtube_url
  • youtube_missing_metadata_error
  • configure_owned_process
  • terminate_owned_process
  • is_youtube_video_id
  • project_payload_from_content
  • ScoreAttachmentPayload
  • is_valid_project_id
  • is_valid_score_id
  • validate_score_pdf_source
  • resolve_existing_score_pdf
  • read_bounded_process_output
  • read_bounded_process_lines
  • wait_for_process_output
  • LocalAudioPublicationIdentity
  • build_local_audio_publication_identity
  • read_validated_score_pdf
  • commit_local_audio_publication

Findings

No source-backed product finding is synthesized from the coverage gate. A coverage miss belongs in the status comment.

  • Head SHA: 0cb51e4d042a8f4cd5742086156a307bfe1ffac6
  • Workflow run: 35014435731
  • Workflow attempt: 1
  • Coverage gate: failure

Review outcome

Coverage is a gate, not the review. This body reviews the changed product files.

Changed-File Evidence Map

classDiagram
  class LocalAudioCopyReceipt
  class validate_local_audio_file_size
  class copy_bounded_local_audio_with_receipt
  class verify_local_audio_publication_receipt
  class copy_bounded_local_audio
  class StreamingSha256
  class update
  class finalize_hex
Loading

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working priority: medium Normal-priority or P2 work type: bug Defect or incorrect behavior

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant