fix(audio): establish canonical local-audio resource policy - #866
seonghobae wants to merge 672 commits into
Conversation
|
Important Review skippedToo many files! This PR contains 120 files, which is 20 over the limit of 100. To get a review, reduce the PR to 100 files or fewer by splitting it into smaller PRs or changing its base branch. Upgrade to a paid plan to raise the limit. This review couldn't start because sufficient usage credits or metered capacity aren't available. Add credits or update usage-based reviews in the billing tab, then retry. ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (120)
You can disable this status message by setting the Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Stale comment
Reviewed exact head
3f976e55. Local-file Python, TypeScript, and Rust encoded-byte ceilings match (100 MiB, exclusive upper bound, exact ceiling accepted). Do not mark Ready or merge this draft until YouTube download uses that same ceiling and #865 is in protecteddevelop.Request changes:
import_youtube_urlnow callsvalidate_local_audio_file_sizeonly afteryoutube.pyhas already finished. That module still downloads with no yt-dlpmax_filesizeand then rejects> 50 * 1024 * 1024. A 60–100 MiB import that policy-v1 would accept is still rejected with a 50 MB message. A multi-gigabyte transfer can fill the cache root before the new native check ever runs, so the new YouTube-path size check is dead for oversized inputs.Doctoring residual-risk text on this head still says the desktop/Rust intake path is not established, which is no longer true for local-file bootstrap.
The successor branch
cursor/bc-977eae6a-247d-427f-a2eb-533a75284f2e-6591drives YouTube admission fromDEFAULT_MAX_ENCODED_FILE_BYTES, aborts in-flight, and updates the evidence note. Apply that here or reconstruct this branch onto it before Ready.Checks on this synchronization were still queued at review time. Queued, skipped, predecessor, or draft-skipped CodeRabbit evidence is not success.
Sent by Cursor Automation: fix all
There was a problem hiding this comment.
Stale comment
Reviewed exact head
1f3fdb8b. The prior 50 MB / missingmax_filesize/ stale doctoring findings are fully addressed: YouTube download now usesDEFAULT_MAX_ENCODED_FILE_BYTES, rejects announced oversize beforedownload=True, aborts from the progress hook, and revalidates the written file. Do not mark Ready or merge this draft until #865 is in protecteddevelopand the abort-path cache leak below is on this head.Request changes: in-flight abort still returns
size_exceededwithout deleting bytes already written. yt-dlp HttpFD writes the current block, then calls the hook; on exception it only closes the stream. The post-download path deletes an oversize final artifact; the abort path does not. Each rejected import can leave*.part,*-Frag*, and*.ytdlin a fresh project cache.Successor
cursor/bc-75568fe4-aa90-4cf7-bb40-c9d68be95b82-b46fat5e8fa77fdeletes owned siblings that stay inside that importout_dirand ignores escaped paths. Apply that here or reconstruct this branch onto it before Ready.Queued, skipped, predecessor, or draft-skipped CodeRabbit evidence is not success.
Sent by Cursor Automation: Fix Issues
There was a problem hiding this comment.
Reviewed exact head 5e8fa77f on fix/audio-resource-policy-781 (base develop@acdbea63). The prior in-flight abort finding is fully addressed on this head: _abort_over_budget_download deletes owned siblings before the fail-closed size_exceeded raise. _owned_file_path realpaths the candidate and the import out_dir, rejects the directory root, and requires resolved.startswith(root + os.sep), so a path or symlink that escapes that import directory is ignored. _remove_download_artifacts stems tmpfilename / filename (one .part strip) and removes matching stem, stem.*, and stem-* entries, which covers .part, .ytdl, and -Frag*. test_download_youtube_audio_progress_hook_deletes_partial_artifacts proves those three are gone after abort while keep-me.txt and an outsider .part remain.
The earlier 50 MB post-write, missing Rust intake doctoring, CHANGELOG 50 MB, and progress-hook int-only items stay fixed. YouTube admission uses DEFAULT_MAX_ENCODED_FILE_BYTES (100 MiB) in Python, desktop analysis.ts, and native audio_resource.rs. Announced oversize rejects before download=True. Exact 100 MiB is accepted; 60 MiB is accepted; 100 MiB + 1 is rejected. Closed #875 is the same tree as this head — do not reopen a competing abort-cleanup owner.
Next action: keep this Draft. Integrate #865 into protected develop first, then reconstruct and revalidate this stack on the unchanged resulting exact head. Do not mark Ready or merge on queued, skipped, predecessor, or CodeRabbit draft-skipped evidence. Remaining #781 channel/rate contracts and decoded-memory / CPU/GPU admission budgets are still out of this draft's claim — do not treat policy-v1 encoded-byte admission as full #781 closure.
Residual (not a change request): a process kill, a locked Windows .part, or a differently named format-id fragment can still leave cache bytes until that per-project import directory is removed. Generic DownloadError / timeout paths do not sweep unnamed artifacts. Admission still fails closed.
Sent by Cursor Automation: Fix Issues
|
@opencode-agent Take the canonical #781 owner lane on the existing First repair the exact current-head CI blocker with repository-pinned tooling, not guessed formatting: CI run Then, on the resulting exact head, preserve the unique non-duplicative #781 evidence currently stranded in competing PR #985 (
Run focused RED→GREEN tests, repository-pinned Ruff check/format, Bandit, mypy where applicable, then canonical quickcheck. If a finding belongs to #865 or #783 rather than this exact branch, prove the first causal boundary and leave it with its owner rather than adding a leaf workaround. Commit only to this branch and report resulting exact head and evidence. |
|
@OpenCode repair exact head |
|
@opencode-agent Please review the current exact PR head |
|
Exact-head maintenance update for 505a595:
Keep Draft; predecessor evidence does not transfer. |
|
@opencode-agent review\n\nReview only current PR head 505a595 against protected develop base 749511c. Revalidate the canonical local-audio resource policy, source metadata preflight before decode, post-decode limits, empty-layout chord handling, payload-safe diagnostics, exact tests, and current security checks. Do not reuse predecessor-head evidence or provider-unavailable results. |
|
Intervening central-main update after the preceding authority note: |
|
Queued @opencode-agent for PR #866 at head |
|
Queued @opencode-agent for PR #866 at head |
|
Queued @opencode-agent for PR #866 at head |
|
Queued @opencode-agent for PR #866 at head |
|
2026-09-14 KST fresh central-prerequisite correction for unchanged exact The central Keep #866 unchanged and Ready but unmerged. Do not create a source-neutral wake commit, manually rerun the consumer CodeQL workflow, synthesize statuses, or copy the central handler. Once |
|
Central prerequisite refresh: #866 source identity remains unchanged. Keep consumer-side acceptance bound to fresh live central metadata: only the new #2106 exact-head generation can become prerequisite evidence, after terminal checks and qualifying review. The old handler/check generation does not transfer across the ordinary ancestry change. |
|
Project Persistence dependent authority refresh (2026-09-14): #970 moved from |
|
#970 dependency authority refresh — source boundary unchanged Project Persistence #970 has advanced ordinarily from the previously recorded The new #970 slice closes the previously recorded derived-cache scientific-equivalence gap without moving Resource Admission authority into persistence:
#866 remains the sole local-audio Resource Admission & Decode source owner. Do not add feature-manifest parsing, NPZ admission, MIR generation, checkpoint provenance, cache publication, or derived-cache hashing here. #970 consumes #866 evidence only after the existing typed/native handoff. This is source-level repair, not protected/release truth. Exact |
|
Authority refresh — no #866 source change. Project Persistence #970 is no longer at the Distribution/model-release authority also advanced separately in #1126 exact Central |
|
Queued @opencode-agent for PR #866 at head |
|
Queued @opencode-agent for PR #866 at head |
|
Already queued @opencode-agent on this exact request for PR #866 at head |
|
Queued @opencode-agent for PR #866 at head |
|
Queued @opencode-agent for PR #866 at head |
|
Queued @opencode-agent for PR #866 at head |
|
Queued @opencode-agent for PR #866 at head |
|
Already queued @opencode-agent on this exact request for PR #866 at head |
|
Queued @opencode-agent for PR #866 at head |
|
Already queued @opencode-agent on this exact request for PR #866 at head |
|
Queued @opencode-agent for PR #866 at head |
The CR/LF log-forging finding is valid, but this generated implementation remains weaker than the canonical temporal privacy contract: it still emits the selected local-audio path and raw decoder exception text. The same finding is already preserved in #1211 for canonical owner #1055, which requires path-free bounded context plus exception type after the active #866 source lane releases. Restore this duplicate branch to the protected develop tree as an ordinary descendant so it cannot become a second temporal source writer. Preserve the finding through the existing canonical/preservation path rather than merging a weaker repr(path) implementation. No force update, destructive rebase, self-approval, gate weakening, or security-completion claim.
The CR/LF log-forging finding is valid, but this branch's repr(path) implementation still discloses the selected local-audio path and preserves raw decoder exception text. Its focused test only asserts repr(path) on the info call and does not establish the stronger path-free failure contract. Restore the duplicate branch to protected develop as an ordinary descendant. Preserve the valid finding in #1211 for canonical temporal privacy owner #1055, which already specifies attacker-shaped path plus decoder-exception RED and path-free, exception-type-only GREEN after active source owner #866 releases. Also remove the foreign #1176 formatter delta. No force update, destructive rebase, self-approval, gate weakening, or security-completion claim.
There was a problem hiding this comment.
Pull request overview
OpenCode reviewed the current-head product diff. Coverage is a separate gate.
Changed files
ARCHITECTURE.md— repository behaviorCHANGELOG.md— repository behaviorCLAUDE.md— repository behaviorapps/desktop/core/Cargo.toml— Rust workspace or package manifestapps/desktop/core/src/audio_resource.rs— Rust package behaviorapps/desktop/core/src/content_sha256.rs— Rust package behaviorapps/desktop/core/src/lib.rs— Rust package behaviorapps/desktop/core/src/process_output.rs— Rust package behaviorapps/desktop/core/src/publication_identity.rs— Rust package behaviorapps/desktop/core/src/root.rs— Rust package behaviorapps/desktop/core/src/score_pdf.rs— Rust package behaviorapps/desktop/core/tests/analysis_job_cancellation_error.rs— regression suiteapps/desktop/core/tests/audio_resource_next_action.rs— regression suiteapps/desktop/core/tests/audio_resource_policy.rs— regression suiteapps/desktop/core/tests/content_sha256_shared_kernel.rs— regression suiteapps/desktop/core/tests/local_audio_content_identity.rs— regression suiteapps/desktop/core/tests/local_audio_publication_identity.rs— regression suiteapps/desktop/core/tests/local_audio_publication_identity_deserialization.rs— regression suiteapps/desktop/core/tests/score_pdf_read.rs— regression suiteapps/desktop/core/tests/youtube_process_containment.rs— regression suiteapps/desktop/src-tauri/build.rs— Rust package behaviorapps/desktop/src-tauri/capabilities/main.json— repository behaviorapps/desktop/src-tauri/gen/schemas/capabilities.json— repository behaviorapps/desktop/src-tauri/permissions/autogenerated/cancel_analysis_job.toml— repository behaviorapps/desktop/src-tauri/src/local_audio_publication.rs— Rust package behaviorapps/desktop/src-tauri/src/main.rs— Rust package behaviorapps/desktop/src-tauri/tests/analysis_job_cancellation_contract.rs— regression suiteapps/desktop/src-tauri/tests/analysis_process_job_identity_contract.rs— regression suiteapps/desktop/src-tauri/tests/analysis_process_output_admission_contract.rs— regression suiteapps/desktop/src-tauri/tests/analysis_process_progress_state_contract.rs— regression suiteapps/desktop/src-tauri/tests/analysis_process_requested_at_contract.rs— regression suiteapps/desktop/src-tauri/tests/analysis_process_terminal_containment_contract.rs— regression suiteapps/desktop/src-tauri/tests/analysis_process_terminal_status_contract.rs— regression suiteapps/desktop/src-tauri/tests/local_audio_publication_contract.rs— regression suiteapps/desktop/src-tauri/tests/youtube_process_containment_runtime.rs— regression suiteapps/desktop/src/lib/analysis.audio-resource-next-action.test.ts— TypeScript or JavaScript runtimeapps/desktop/src/lib/analysis.cancellation-bridge.test.ts— TypeScript or JavaScript runtimeapps/desktop/src/lib/analysis.resource-policy.test.ts— TypeScript or JavaScript runtimeapps/desktop/src/lib/analysis.test.ts— TypeScript or JavaScript runtimeapps/desktop/src/lib/analysis.ts— TypeScript or JavaScript runtimedocs/architecture/overview.md— operator or user guidancedocs/doctoring/analysis-single-orchestration-owner.md— operator or user guidancedocs/doctoring/audio-resource-policy.md— operator or user guidancedocs/doctoring/feature-cache-archive-path-admission.md— operator or user guidancedocs/doctoring/feature-cache-generation-manifest.md— operator or user guidancedocs/doctoring/feature-cache-json-numeric-admission.md— operator or user guidancedocs/doctoring/feature-cache-metadata-sidecar-admission.md— operator or user guidancedocs/doctoring/feature-cache-replay-admission.md— operator or user guidancedocs/doctoring/feature-cache-resource-admission.md— operator or user guidancedocs/doctoring/local-audio-analysis-source-identity-handoff.md— operator or user guidancedocs/doctoring/local-audio-source-materialization.md— operator or user guidancedocs/doctoring/local-audio-stem-work-identity.md— operator or user guidancedocs/doctoring/model-output-shape-admission.md— operator or user guidancedocs/doctoring/request-path-security-diagnostics.md— operator or user guidancedocs/doctoring/subprocess-containment.md— operator or user guidancedocs/doctoring/youtube-process-containment.md— operator or user guidancedocs/security/app-security.md— operator or user guidancepackages/shared-types/src/index.ts— TypeScript or JavaScript runtimepackages/shared-types/test/analysis_job_cancellation.test.ts— regression suiteservices/analysis-engine/src/bandscope_analysis/__init__.py— Python module behaviorservices/analysis-engine/src/bandscope_analysis/api.py— Python module behaviorservices/analysis-engine/src/bandscope_analysis/audio_decode.py— Python module behaviorservices/analysis-engine/src/bandscope_analysis/audio_metadata.py— Python module behaviorservices/analysis-engine/src/bandscope_analysis/audio_resource_policy.py— Python module behaviorservices/analysis-engine/src/bandscope_analysis/chords/chord_recognizer.py— Python module behaviorservices/analysis-engine/src/bandscope_analysis/cli.py— Python module behaviorservices/analysis-engine/src/bandscope_analysis/feature_cache_admission.py— Python module behaviorservices/analysis-engine/src/bandscope_analysis/feature_cache_generation.py— Python module behaviorservices/analysis-engine/src/bandscope_analysis/separation/audio_separator.py— Python module behaviorservices/analysis-engine/src/bandscope_analysis/temporal/analyzer.py— Python module behaviorservices/analysis-engine/src/bandscope_analysis/transcription/api.py— Python module behaviorservices/analysis-engine/src/bandscope_analysis/youtube.py— Python module behaviorservices/analysis-engine/tests/test_api.py— regression suiteservices/analysis-engine/tests/test_audio_decode_backing_memory.py— regression suiteservices/analysis-engine/tests/test_audio_decode_dtype_boundary.py— regression suiteservices/analysis-engine/tests/test_audio_decode_port.py— regression suiteservices/analysis-engine/tests/test_audio_decode_preconversion_budget.py— regression suiteservices/analysis-engine/tests/test_audio_decode_reproducibility.py— regression suiteservices/analysis-engine/tests/test_audio_metadata.py— regression suiteservices/analysis-engine/tests/test_audio_model_output_policy.py— regression suiteservices/analysis-engine/tests/test_audio_resource_policy.py— regression suiteservices/analysis-engine/tests/test_audio_resource_policy_coverage_regressions.py— regression suiteservices/analysis-engine/tests/test_audio_resource_policy_dtype.py— regression suiteservices/analysis-engine/tests/test_audio_resource_policy_finiteness_memory.py— regression suiteservices/analysis-engine/tests/test_audio_resource_policy_integration.py— regression suiteservices/analysis-engine/tests/test_audio_separator_device_boundary.py— regression suiteservices/analysis-engine/tests/test_branch_coverage_contract.py— regression suiteservices/analysis-engine/tests/test_chord_recognizer.py— regression suiteservices/analysis-engine/tests/test_cli.py— regression suiteservices/analysis-engine/tests/test_cli_requested_at_authority.py— regression suiteservices/analysis-engine/tests/test_cli_source_identity_cache.py— regression suiteservices/analysis-engine/tests/test_cli_source_identity_temp_scope.py— regression suiteservices/analysis-engine/tests/test_current_coverage_boundaries.py— regression suiteservices/analysis-engine/tests/test_feature_cache_archive_path_admission.py— regression suiteservices/analysis-engine/tests/test_feature_cache_generation_manifest.py— regression suiteservices/analysis-engine/tests/test_feature_cache_json_number_admission.py— regression suiteservices/analysis-engine/tests/test_feature_cache_metadata_admission.py— regression suiteservices/analysis-engine/tests/test_feature_cache_metadata_generation.py— regression suiteservices/analysis-engine/tests/test_feature_cache_producer_admission.py— regression suiteservices/analysis-engine/tests/test_feature_cache_protocol_contract.py— regression suiteservices/analysis-engine/tests/test_feature_cache_resource_admission.py— regression suiteservices/analysis-engine/tests/test_feature_cache_role_binding.py— regression suiteservices/analysis-engine/tests/test_project_id_admission.py— regression suiteservices/analysis-engine/tests/test_request_security_diagnostics.py— regression suiteservices/analysis-engine/tests/test_resource_admission_coverage_edges.py— regression suiteservices/analysis-engine/tests/test_resource_admission_reachable_edges.py— regression suiteservices/analysis-engine/tests/test_segmenter.py— regression suiteservices/analysis-engine/tests/test_separation.py— regression suiteservices/analysis-engine/tests/test_stem_separation_logging_privacy.py— regression suiteservices/analysis-engine/tests/test_stem_separation_traceback_privacy.py— regression suiteservices/analysis-engine/tests/test_supply_chain_policy.py— regression suiteservices/analysis-engine/tests/test_temporal.py— regression suiteservices/analysis-engine/tests/test_temporal_error_privacy.py— regression suiteservices/analysis-engine/tests/test_transcription.py— regression suiteservices/analysis-engine/tests/test_youtube.py— regression suiteservices/analysis-engine/tests/test_youtube_downloaded_duration_revalidation.py— regression suiteservices/analysis-engine/tests/test_youtube_duration_contract.py— regression suiteservices/analysis-engine/tests/test_youtube_fragment_identity_cleanup.py— regression suiteservices/analysis-engine/tests/test_youtube_post_download_admission_reason.py— regression suiteservices/analysis-engine/tests/test_youtube_post_download_path_authority.py— regression suiteservices/analysis-engine/tests/test_youtube_transient_cleanup_authority.py— regression suite
Changed behavior
classDiagram
class LocalAudioCopyReceipt
class validate_local_audio_file_size
class copy_bounded_local_audio_with_receipt
class verify_local_audio_publication_receipt
class copy_bounded_local_audio
class StreamingSha256
class update
class finalize_hex
Changed API
LocalAudioCopyReceiptvalidate_local_audio_file_sizecopy_bounded_local_audio_with_receiptverify_local_audio_publication_receiptcopy_bounded_local_audioStreamingSha256updatefinalize_hexsha256_hex_readerAppStateAppStateInnerAnalysisJobRequestAnalysisJobErrorCodeAnalysisJobErrorAnalysisJobStateAnalysisJobStageAnalysisCacheStatusRehearsalSongPayloadScoreAttachmentMetadataPayloadConfidencePayloadCuePayloadRangePayloadHarmonyPayloadManualOverridePayloadRehearsalRolePayloadSectionTimeRangePayloadPartGraphNodePayloadRehearsalSectionPayloadExportSummaryPayloadAnalysisJobStatusLocalAudioSourcePayloadProjectBootstrapSummaryPayloadnext_project_idyoutube_source_from_metadatais_supported_youtube_urlyoutube_missing_metadata_errorconfigure_owned_processterminate_owned_processis_youtube_video_idproject_payload_from_contentScoreAttachmentPayloadis_valid_project_idis_valid_score_idvalidate_score_pdf_sourceresolve_existing_score_pdfread_bounded_process_outputread_bounded_process_lineswait_for_process_outputLocalAudioPublicationIdentitybuild_local_audio_publication_identityread_validated_score_pdfcommit_local_audio_publication
Findings
No source-backed product finding is synthesized from the coverage gate. A coverage miss belongs in the status comment.
- Head SHA:
0cb51e4d042a8f4cd5742086156a307bfe1ffac6 - Workflow run: 35014435731
- Workflow attempt: 1
- Coverage gate:
failure
Review outcome
Coverage is a gate, not the review. This body reviews the changed product files.
Changed-File Evidence Map
classDiagram
class LocalAudioCopyReceipt
class validate_local_audio_file_size
class copy_bounded_local_audio_with_receipt
class verify_local_audio_publication_receipt
class copy_bounded_local_audio
class StreamingSha256
class update
class finalize_hex


Canonical #781 Resource Admission & Decode lane
BandScope local-audio Resource Admission & Decode의 단일 source owner입니다. Current source head는
0cb51e4d042a8f4cd5742086156a307bfe1ffac6, base는 protecteddevelop@314ddeae7b775a4957594b599358c8255617eb2e이며 Open / Ready / mergeable입니다. Predecessor·cancelled-run·downstream evidence를 current source head로 이전하지 않습니다.Ownership 경계는 유지합니다. #1116만
docs/product-technical-gap-baseline.md를 쓰고, #970은 durable Project Persistence와 derived cache/final rehearsal-result persistence/reuse, #1160은 protected/released Resource Admission + Project Persistence의 Active Player 소비를 소유합니다. Repository-generic Security Notes parser/checker는 #1204가 소유합니다. Dependency/frontend/control-plane 경고는 각각의 canonical owner에서 처리하며 #866에 섞지 않습니다.Current semantic lineage
344b273c49758d46181511940c4ac16eaa04208b까지 owned-production Python statement/branch 100%와 unintended warning 0을 달성했습니다. Preservation #1197의 validprojectIdwhitespace/dot invariant도 이 canonical branch에서 RED→minimal fix로 직접 승계했습니다.f920a4c2acce56b8eaa43cff09c2d74098c45c0b:" .. "," . "," project-1 "거부와project-1,my..id보존.0cb51e4d042a8f4cd5742086156a307bfe1ffac6: leading/trailing whitespace와 stripped./..를 canonical validator에서 fail closed 처리.#1197 branch 자체를 merge/cherry-pick하지 않았고 unrelated formatter/dependency delta도 가져오지 않았습니다.
Fresh gate correction — 2026-09-17
Exact
0cb51e4d...의 repository-owned workflows remain terminalci=success,build-baseline=success,Security Scan=success,sbom=success,SAST Semgrep=success; organizationCodeQL PRremains terminal failure through the central verdict-publication path.A newer exact-head OpenCode review run reports
COVERAGE_BLOCKED/Coverage gate: failurefor workflow run35014435731. Its formal review explicitly says approval is blocked by coverage evidence. Therefore the older statement that current-head acceptance evidence is fully green is no longer sufficient merge authority, even though the productciworkflow itself is green. Do not merge, self-approve, synthesize coverage status, or create a no-op retrigger. The coverage failure must be traced to its actual evidence producer/owner before any source change is made; the formal source review did not synthesize a product defect from that coverage result.Current formal review inventory still contains no qualifying non-author
APPROVEDon exact0cb51e4d.... CodeRabbit also skipped whole-PR review because the selected file count exceeds its current review limit/capacity; do not split the canonical Resource Admission vertical into arbitrary micro-PRs merely to satisfy that vendor limit.Current protected / central authority
Protected
developremains314ddeae7b775a4957594b599358c8255617eb2ewith 14 required contexts:ci / build-and-test,dependency-review,sbom, Windows/macOS build gates,trivy-fs,coverage-evidence,opencode-review,strix,scan-pr-queue,osv-scan,scorecard,Analyze (javascript-typescript),Analyze (python).Protected central
.github/mainis now346b46d0025672b727242cec702ec2246b4c844d. Canonical central CodeQL bootstrap owner.github#2106is exact1336eae994859203b08ec40c174b55a0f435ef92, Open / Draft / mergeable. Its focused owner-identity RED was reverted before leaving a test-only non-green branch, so the canonical baseline still contains two ownerless cross-repository evidence identities and repair progress for that source finding remains zero. Current #2106 workflows are a fresh queued generation; predecessor settlement does not transfer.GitHub-managed dynamic
Analyze (javascript-typescript)/Analyze (python)and centralCodeQL PRcompatibility are distinct evidence until the organization rollout deliberately converges them. BandScope does not copy central handler code, manufacture statuses, or weaken protected contexts.Dependency boundaries
#970 remains Project Persistence/cache owner; #1204 remains generic Security Notes governance owner; #1160 remains Active Player consumer. Final-result publication durability, feature-cache integrity/resource admission, packaged restart/power-loss evidence and audible-source re-admission stay outside #866. Cache identity is not scientific reproducibility evidence until model/implementation generation plus checkpoint provenance/rights are bound.
Acceptance / next boundary
0cb51e4d...unless a source-backed finding is proven.COVERAGE_BLOCKEDresult to its evidence producer before deciding whether any repository source change is causal..github#2106until owner-qualified source evidence and authenticated terminal CodeQL settlement reach protected central main.UI Delivery Gate: FAIL — actual audio→audible playback, restart re-admission, stale-media races, pointer/touch/keyboard/browser focus, Narrator/VoiceOver, responsive evidence, KO/EN/JA/ZH/VI/ES/DE/FR acceptance가 남아 있습니다.
Commercial Release Gate: FAIL — current coverage evidence, independent review, central CodeQL settlement, #970 packaged fault injection, rights-cleared real-audio MIR reproducibility, Windows containment, model/audio licensing, signing/notarization, immutable release/SBOM/provenance와 updater rollback이 남아 있습니다.