Skip to content

feat(policy): gate semantic-node actions on deterministic policy - #95

Draft
seonghobae wants to merge 34 commits into
feat/semantic-node-action-bindingfrom
feat/semantic-node-policy-authorization
Draft

feat(policy): gate semantic-node actions on deterministic policy#95
seonghobae wants to merge 34 commits into
feat/semantic-node-action-bindingfrom
feat/semantic-node-policy-authorization

Conversation

@seonghobae

@seonghobae seonghobae commented Aug 11, 2026

Copy link
Copy Markdown
Contributor

Current verified parent adoption

Exact head 6b29d890245ed2f612c2998198f4e8c8a06da312 includes current #93 82056d13aa94c106060b84ee76be56fcb7787fc8 through ordinary merge 8416de55. Test-first commit 55f38590 reproduced a replacement connection completing the original observation; the inherited fix rejects replacement success/error/exception replies, preserves the pending request, and permits only the original connection to complete it.

The original policy crate and five policy tests are byte-identical to prior #95; core, network and workflows are byte-identical to current #93. Explicit Allow-only authorization and current registry-owned node checks remain independent of reply provenance and execution success.

At this exact head: 8 focused Rust tests, 150 Python contracts, complete workspace Rust tests, format, all-target check, strict Clippy and warnings-denied rustdoc passed. Production coverage is 100%: 1,408 functions, 14,897 lines, 19,022 regions and 1,552 branches. Coverage artifact SHA-256: 666797dec8486f0f196616525303bd24dc52ef5d035f1c548e1bddde3fb48a22. Independent read-only review found no actionable issues; it is not a formal GitHub approval.

Actual Microsoft Edge visual inspection at 1440×1300 verified readable API documentation without clipping or overlap. The initial --no-deps documentation build omitted cross-crate links; RUSTDOCFLAGS='-D warnings' cargo doc --workspace rendered both links, and their destination pages were opened successfully. No source workaround was added.

Keep Draft while prerequisites remain active. New exact-head GitHub runs must finish independently; previous-head success, local verification and visual inspection do not establish protected-main acceptance, merge or release.

Historical evidence (superseded head)

Partial implementation of #28, stacked on the live feat/semantic-node-action-binding branch.

Current dependency / repair state

Fresh ancestry is exact current #93 0664f0452cb329cd692cce7f61f9001652abfda2#95 97aa0f2e340ee6fd920d0418f97af276b190554f. The restack removed stale parent deltas that had reverted the current browser-authority registry and coverage contracts.

Only Decision::Allow creates a policy-authorized semantic-node action. Deny and ApprovalRequired remain non-authorizing, and current registry-owned browser authority is revalidated before use. After a document advance removes the admitted node, current validation fails closed as NotAdmitted. This slice performs no browser I/O and makes no postcondition claim.

Exact-current evidence

At exact head 97aa0f2e340ee6fd920d0418f97af276b190554f, local verification passed: 142 Python contract tests; locked Rust format, check, all-target tests, strict Clippy, and rustdoc; exact 100% production function, line, region, and branch coverage. GitHub checks are still non-passing until their exact-head runs finish.

Keep Draft while its prerequisite stack remains active. No self-approval, force-push, destructive rebase, workflow/ruleset/secret mutation, gate weakening, release, or predecessor-evidence transfer is authorized.

@coderabbitai

coderabbitai Bot commented Aug 11, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Signed-off-by: Seongho Bae <me@seonghobae.me>
…g' into codex/restack-pr95

Signed-off-by: Seongho Bae <me@seonghobae.me>

# Conflicts:
#	CHANGELOG.md
#	crates/originweave-core/src/browser_authority_registry.rs
@seonghobae

Copy link
Copy Markdown
Contributor Author

Restacked non-destructively on PR #93 exact head 21224af5674e428425dedf58e6c48d0e2d3b753e; new exact head is 5ae19913b2a1281a2fef83f22f2bdcdfa7c6d5f9. Preserved the policy-authorization slice, including its public retired-context diagnostic and stale-document rebind coverage. Local verification: 139 Python contracts; full locked workspace tests; fmt; strict Clippy; rustdoc; exact workspace LLVM function/line/region/branch coverage all pass at 100%.

Bring PR #95 onto PR #93 exact head 82b0ebb without rewriting either branch.

Commit-Message-Assisted-by: Claude (via Claude Code)
Signed-off-by: Seongho Bae <me@seonghobae.me>
Drop stale parent-file deltas, align document retirement with NotAdmitted, and record that deterministic policy allow remains separate from browser execution and post-condition proof.

Commit-Message-Assisted-by: Claude (via Claude Code)
Signed-off-by: Seongho Bae <me@seonghobae.me>
Bring PR #95 onto PR #93 exact head 0664f04 without rewriting either branch.

Commit-Message-Assisted-by: Claude (via Claude Code)
Signed-off-by: Seongho Bae <me@seonghobae.me>
@seonghobae

Copy link
Copy Markdown
Contributor Author

Exact-head repair evidence for 97aa0f2e340ee6fd920d0418f97af276b190554f: merged current prerequisite #93 0664f0452cb329cd692cce7f61f9001652abfda2, removed stale parent reversions, and retained only the policy-authorization slice. Focused behavior now proves only Allow authorizes, non-allow decisions fail closed, and registry-owned current authority reports NotAdmitted after document advance. Local exact-head verification passed 142 Python contracts, full locked Rust gates, and exact 100% production function/line/region/branch coverage. GitHub checks remain pending and are not claimed as passing.

seonghobae commented Sep 7, 2026

Copy link
Copy Markdown
Contributor Author

Writer lease RELEASED — root task 01a06c0f-b427-7830-b654-9addcdfe7aff. Published #95 6b29d89, base #93 82056d1; head/base/body read back exactly. 8 focused Rust tests, 150 Python contracts, complete stable Rust pipeline and 100% production coverage passed (1408 functions,14897 lines,19022 regions,1552 branches; SHA256 666797dec8486f0f196616525303bd24dc52ef5d035f1c548e1bddde3fb48a22). Child policy and parent core/network/workflows byte-identical. Independent read-only review no findings, not formal approval. Actual Edge visual inspection /tmp/pr95-linked-rustdoc-6b29d890.png readable, both cross-crate links opened successfully after dependency-inclusive workspace doc build; no source workaround. All local processes terminal. CI 34080772063, Rust job101615473690 and coverage job101615473415 QUEUED at readback; no hosted pass/merge/release claim. Local worktree /private/tmp/originweave-pr95-sync.uJPXMN preserved, ignored results.tsv and untracked coverage artifact retained. Next safe item #96 current-parent adoption, then bounded baseline checkpoint.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request priority: medium

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant