-
Notifications
You must be signed in to change notification settings - Fork 0
feat(automation): run html4tree hourly NVIDIA NIM review repair #1097
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
22c3e88
5f9a8b8
c3c4eaa
3366bb7
5b69ff2
627b7ad
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,37 @@ | ||
| name: html4tree Hourly Review Repair | ||
|
|
||
| on: | ||
| schedule: | ||
| # Minute 15 avoids pg-llm-batch (1), aFIPC (2), kaefa (3), LineageWeave (4), | ||
| # codec-carver (5), life-os (6), Wardnet (7), mightyETL (8), | ||
| # psychometrics-commons (9), OriginWeave (10), naruon (11), | ||
| # DiagramWeave (12), pg-erd-cloud (13), mhtml-etl-gateway (14), | ||
| # orchestrator (17), noema (19), Clearfolio (23), Keyverse (29), | ||
| # Scopeweave (31), DiskSage (37), Appguardrail (41), newsdom-api (43), | ||
| # Inkspan (47), fast-mlsirm (49), BandScope (53), and | ||
| # semantic-data-portal (59). | ||
| - cron: "15 * * * *" | ||
|
Comment on lines
+5
to
+13
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 📝 Info: Cron comment omits adjacent nonnest2 (minute 16) The scheduling comment in html4tree-hourly-review-repair.yml enumerates other product minutes to justify choosing minute 15, but skips from Was this helpful? React with 👍 or 👎 to provide feedback.
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 📝 Info: Cron minute 15 is collision-free among org callers The new caller uses Was this helpful? React with 👍 or 👎 to provide feedback. |
||
|
|
||
| concurrency: | ||
| group: html4tree-hourly-review-repair | ||
| # A later heartbeat must not cancel an in-flight directory-index RCA. | ||
| cancel-in-progress: false | ||
|
|
||
| permissions: | ||
| contents: read | ||
|
|
||
| jobs: | ||
| dispatch-review-repair: | ||
| permissions: | ||
| contents: read | ||
| id-token: write | ||
| uses: ./.github/workflows/pr-review-fix-scheduler.yml | ||
| with: | ||
| target_repository: ContextualWisdomLab/html4tree | ||
| base_branch: master | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔍 base_branch: master unverifiable against upstream fork The caller targets Was this helpful? React with 👍 or 👎 to provide feedback. |
||
| max_prs: "50" | ||
| max_dispatches: "1" | ||
| retry_hours: "2" | ||
| secrets: | ||
| PR_REVIEW_MERGE_TOKEN: ${{ secrets.PR_REVIEW_MERGE_TOKEN }} | ||
| OPENCODE_APPROVE_TOKEN: ${{ secrets.OPENCODE_APPROVE_TOKEN }} | ||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,142 @@ | ||
| # html4tree hourly review-repair caller | ||
|
|
||
| 검토 기준일: **2026-08-17** | ||
|
|
||
| ## Decision | ||
|
|
||
| ContextualWisdomLab operates one protected hourly caller for | ||
| `ContextualWisdomLab/html4tree` (standalone MIT directory-index generator | ||
| that writes `index.html` trees in the style of Apache `mod_autoindex`). | ||
| The caller runs at minute 15, delegates to the product-neutral central | ||
| review-fix scheduler, inspects at most 50 open pull requests targeting | ||
| protected `master`, and dispatches at most one bounded repair per | ||
| heartbeat. | ||
|
|
||
| A paying buyer of governed directory listings would feel live html4tree | ||
| pull requests stalling while hourly NVIDIA NIM repair scanned only | ||
| Clearfolio, DiskSage, and fast-mlsirm. Live heads such as | ||
| ContextualWisdomLab/html4tree#475 (localized navigation labels), | ||
| ContextualWisdomLab/html4tree#472 (TOCTOU on `.html4ignore`), and | ||
| ContextualWisdomLab/html4tree#454 (BiDi spoof / Trojan Source) target | ||
| `master` and never enter those other callers. | ||
|
|
||
| html4tree is a public fork of `yencarnacion/html4tree`. Fork status is | ||
| not a categorical exclusion: onboarding is an explicit repository | ||
| decision, and pull-request mutation remains capability-gated per head. | ||
| The caller does not implement review or mutation logic itself. | ||
| html4tree remains standalone; naruon and other CWL services may consume | ||
| generated indexes without owning the crawler. Privileged automation | ||
| stays in `ContextualWisdomLab/.github`. | ||
|
|
||
| ## Root-cause analysis and remediation feasibility | ||
|
|
||
| The reusable worker performs exact-head root-cause analysis and tests | ||
| remediation feasibility before it edits. The reusable worker must: | ||
|
|
||
| 1. Refetch the exact live head, base, reviews, checks, changed paths, and | ||
| writer state. | ||
| 2. Establish the causal chain rather than repeat the terminal symptom. | ||
| 3. Enumerate materially distinct minimal remedies. | ||
| 4. Reject remedies that lack writer authority, cross sealed paths, require | ||
| unavailable credentials or protected-setting changes, violate stack | ||
| order, cannot be verified, or do not alter the diagnosed cause. | ||
| 5. Dispatch at most one feasible repair. Otherwise leave the tree | ||
| unchanged. | ||
|
|
||
| A queued or pending check remains a merge blocker but is not itself a | ||
| code finding. The independent non-author approval remains an external | ||
| authorization gate and is never synthesized by the repair worker. The | ||
| worker cannot approve, merge, release, resolve review findings by | ||
| inference, change protection, or manufacture passing checks. | ||
|
|
||
| ## Cadence and concurrency | ||
|
|
||
| The caller uses a single concurrency group and `cancel-in-progress: false`. | ||
| This preserves an in-flight bounded RCA instead of discarding directory- | ||
| listing evidence when the next hourly heartbeat arrives. The reusable | ||
| scheduler cancels only its own superseded short queue scan. | ||
|
|
||
| The caller sets a **two-hour same-head retry floor**. Central OpenCode and | ||
| NVIDIA NIM work, plus BiDi or TOCTOU analysis, can legitimately approach | ||
| two hours. An hourly redispatch of the same unchanged head would create | ||
| duplicate writer pressure rather than faster remediation. | ||
|
|
||
| GitHub scheduled workflows can be delayed under load and execute only | ||
| from the default branch. The cron expression is a heartbeat, not a | ||
| real-time SLA. | ||
|
|
||
| ## Credential and model boundary | ||
|
|
||
| The caller keeps workflow `GITHUB_TOKEN` at `contents: read` and grants | ||
| the reusable job `id-token: write` so the central scheduler can mint the | ||
| OpenCode GitHub App token from GitHub OIDC when the mapped PAT is absent | ||
| (GitHub, n.d.-c). It maps only `PR_REVIEW_MERGE_TOKEN` and | ||
| `OPENCODE_APPROVE_TOKEN`. It never uses `secrets: inherit`, receives | ||
| `NVIDIA_NIM_API_KEY`, or introduces `COPILOT_GITHUB_TOKEN`. CWE-250 | ||
| forbids executing the caller with write or model privileges it does not | ||
| need (MITRE, 2026). | ||
|
|
||
| Model execution remains inside the central worker. The model credential | ||
| is the GitHub Secret `NVIDIA_NIM_API_KEY`; the caller does not receive or | ||
| forward it. | ||
|
|
||
| Before protected-master activation, the repository variable | ||
| `OPENCODE_REPOSITORY_DISPATCH_TARGETS` must contain the exact | ||
| `ContextualWisdomLab/html4tree` target. Missing or mismatched | ||
| configuration fails before mutation credential materialization. | ||
|
|
||
| ## Security, standalone operation, and modularity | ||
|
|
||
| The caller adds no html4tree runtime dependency, database object, | ||
| network endpoint, tenant authority, or product credential. html4tree | ||
| continues to run as a standalone directory-index generator. Naruon and | ||
| other CWL services may consume its `index.html` trees, but they cannot | ||
| weaken its exact-head, approval, or security gates. | ||
|
|
||
| ## Verification and rollback | ||
|
|
||
| Machine-checkable contracts require the exact target/base, minute 15 | ||
| cadence, non-cancelling single-flight group, one dispatch, two-hour | ||
| retry floor, explicit secret mapping, read-only contents plus job-scoped | ||
| `id-token: write`, focused path-filter coverage, and absence of model or | ||
| Copilot credentials. Independent `pull_request`, `push`, and `compileall` | ||
| path blocks must each name the caller, doctoring, or contract they own. | ||
|
|
||
| After source integration, closure requires a scheduled or manual | ||
| protected-master consumer run proving the exact html4tree repository | ||
| and `master` base. Source checks alone are not protected-master operational acceptance. | ||
| Merge still requires zero unresolved valid findings and a | ||
| qualifying independent non-author approval. | ||
|
|
||
| Rollback removes the html4tree caller, its focused test, doctoring, and | ||
| central path-filter/documentation entries. It must not remove scheduler | ||
| dispatch validation or affect independent product callers. | ||
|
|
||
| ## APA 7th references | ||
|
|
||
| GitHub, Inc. (n.d.-a). *Events that trigger workflows*. GitHub Docs. | ||
| Retrieved August 17, 2026, from | ||
| https://docs.github.com/en/actions/reference/workflows-and-actions/events-that-trigger-workflows#schedule | ||
|
|
||
| GitHub, Inc. (n.d.-b). *Reuse workflows*. GitHub Docs. Retrieved August | ||
| 17, 2026, from | ||
| https://docs.github.com/en/actions/how-tos/sharing-automations/reuse-workflows | ||
|
|
||
| GitHub, Inc. (n.d.-c). *Automatic token authentication*. GitHub Docs. | ||
| Retrieved August 17, 2026, from | ||
| https://docs.github.com/en/actions/security-for-github-actions/security-guides/automatic-token-authentication#permissions-for-the-github_token | ||
|
|
||
| MITRE. (2026). *CWE-250: Execution with unnecessary privileges*. | ||
| https://cwe.mitre.org/data/definitions/250.html | ||
|
|
||
| National Institute of Standards and Technology. (2022). *Secure software | ||
| development framework (SSDF) version 1.1: Recommendations for mitigating | ||
| the risk of software vulnerabilities* (NIST Special Publication 800-218). | ||
| https://doi.org/10.6028/NIST.SP.800-218 | ||
|
|
||
| NVIDIA. (n.d.). *NVIDIA NIM for large language models documentation*. | ||
| Retrieved August 17, 2026, from | ||
| https://docs.nvidia.com/nim/large-language-models/latest/ | ||
|
|
||
| OpenCode. (n.d.). *OpenCode documentation*. Retrieved August 17, 2026, | ||
| from https://opencode.ai/docs/ |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -213,9 +213,9 @@ packaging==26.2 \ | |
| # via | ||
| # pip-audit | ||
| # pip-requirements-parser | ||
| pip==26.1.2 \ | ||
| --hash=sha256:382ff9f685ee3bc25864f820aa50505825f10f5458ffff07e30a6d96e5715cab \ | ||
| --hash=sha256:f49cd134c61cf2fd75e0ce2676db03e4054504a5a4986d00f8299ae632dc4605 | ||
| pip==26.2.1 \ | ||
| --hash=sha256:71138adf1f4ca900cdb7d289c21b7494329f2332b6d85f0e1c42108c0384ed3e \ | ||
| --hash=sha256:f6ad667e89a1fe78046c8f13232b247200f5258d7828f3f7883d660878e0813f | ||
|
Comment on lines
+216
to
+218
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔍 Unrelated pip bump in hashes lockfile requirements-pip-audit-ci-hashes.txt bumps pip 26.1.2 to 26.2.1, unrelated to adding the html4tree caller. Confirm it came from regenerating the input via the recorded Was this helpful? React with 👍 or 👎 to provide feedback. |
||
| # via pip-api | ||
| pip-api==0.0.34 \ | ||
| --hash=sha256:8b2d7d7c37f2447373aa2cf8b1f60a2f2b27a84e1e9e0294a3f6ef10eb3ba6bb \ | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
📝 Info: Quality-gate path filter and compileall additions are consistent with the contract tests
The three new entries in
hourly-nvidia-nim-review-repair.yml(caller, doctoring under pull_request/push; test file under pull_request/push/compileall) satisfytest_focused_quality_workflow_tracks_html4tree_contractsin test_html4tree_hourly_review_caller.py, which requires caller+doctoring+contract in both trigger blocks and only the contract in compileall. Cross-checked line-by-line; all assertions hold.Was this helpful? React with 👍 or 👎 to provide feedback.