feat: add governed employment leave review packet - #47
Conversation
📝 WalkthroughWalkthrough고용 휴가 검토 패킷의 거버넌스 계약과 Python 구현을 추가했습니다. 입력 검증, 데이터 최소화, 발급 무결성, 우회 방어 테스트와 Changes고용 휴가 검토 패킷
Estimated code review effort: 4 (Complex) | ~45 minutes Merge Risk: 🔵 Low · up to The packet remains mergeable, but the changelog wording could mislead integrators into believing the packet performs authoritative tenant and worker resolution before approval. Correct that wording with owner awareness; no merge-blocking runtime risk is supported. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 52.46% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 61 functions across 7 files. (7 skipped: 7 unsupported.)
✨ Finishing Touches 💡 2📝 Generate docstrings 💡
🛠️ Fix failing CI checks 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
_validate_digest now enforces the exact built-in str contract matching the rest of the packet boundary; a regression rejects a hostile digest subclass whose forged equality would otherwise pass pattern matching. Suite stays at 100% statement+branch coverage (119 tests). Addresses Devin review observation on PR #47.
Buyer-visible gap
This lane provides a value-minimized, human-review-only employment-leave packet before any authoritative Employment/Assignment mutation. It keeps sensitive leave-case values out of the portable artifact while binding exact tenant/worker correlations, business dates, case/policy provenance, continuity/return-to-work evidence, privacy-policy evidence, and accountable reviewer scope that the authoritative host must re-resolve before approval.
Current exact state
Current exact head:
8562166d0d5bfca42f8a0ae323b80d78d015e22e.Fresh live base:
develop@9e3e4847510e1e612b48474ba42b177b8ed824df.GitHub currently reports the PR open, non-draft, and mergeable. Lifecycle state remains mutable repository state and is not treated as technical evidence.
The current branch includes structural-equality/issuance-registry cleanup plus later review repairs: exact built-in string validation for digests, corrected non-authoritative CHANGELOG wording, explicit non-UUIDv4 reference rejection coverage, direct weak-reference cleanup verification, and traceability that makes intentional single-day leave semantics explicit. Fresh review-thread state shows all current threads resolved; no current thread identifies an actionable authorization/privacy/data-integrity defect.
Exact-current-head Orgmetra evidence
The materialized Orgmetra-local workflows are terminal GREEN on this exact head:
32858198656— success32858198731— success32858200065— success32858198325— success32858200060— successFresh submitted reviews are COMMENTED only. There is no qualifying independent non-author
APPROVEorCHANGES_REQUESTED.Required central Strix evidence
The prior body incorrectly stated that Strix had not materialized. Exact-head required Strix did materialize and completed successfully:
32858195461978352973758562166d0d5bfca42f8a0ae323b80d78d015e22edevelop@9e3e4847510e1e612b48474ba42b177b8ed824df.github@d2c554dbbc04854db6215970fabb70cef1ceb690The primary NVIDIA Nemotron model hit repeated HTTP 429 rate limits, but the trusted bounded fallback
nvidia_nim/nvidia/llama-3.3-nemotron-super-49b-v1.5actually completed the penetration-test run and produced an authoritative structured no-finding report. The run reportedVulnerabilities 0 (No exploitable vulnerabilities detected), emitted executive summary/methodology/technical analysis/recommendations, finishedRun Strix (quick)successfully, collected reports, and uploaded thestrix-reportsartifact successfully.Artifact: ID
9569398682, SHA-2566fcfcc3c1e0e93cb8a011101742bc86c2f78ed0b086029c1dac265af84773248.This differs materially from the current provider-exhaustion failures on other Orgmetra heads: here an authorized fallback completed authoritative analysis, so this exact-head Strix evidence is passing rather than a log-only
Vulnerabilities 0fragment.Governance boundary
The packet remains human-review-only and carries minimum-necessary personal data while excluding medical/family values, direct identifiers, compensation/benefit values, credentials and free-form model output. Any actual HRIS mutation must re-resolve authoritative tenant/Person/Employment/Assignment/Job/Position and policy scope, record human approval, and use immutable audit/outbox evidence.
PR #113 is a separate independent root lane for reason-free authoritative Employment absence truth in the HRIS kernel. It does not replace this pre-mutation review evidence, and this PR does not inherit #113 evidence.
Merge governance
Effective organization ruleset
18156473is active on the default branch, but its live policy is weaker than Orgmetra's acquisition-grade acceptance. Re-fetch it at merge time; do not infer commercial readiness from this body.Orgmetra acceptance remains at least two qualifying independent non-author approvals, approval after the last push, all applicable exact-current-head local and central gates terminal GREEN, resolved conversations, and no routine administrator bypass. This PR currently has no qualifying independent non-author approval, so keep it unmerged. Do not self-approve, use routine administrator bypass, transfer predecessor evidence, or treat process-local issuance integrity as durable authorization.