feat(policy): gate semantic-node actions on deterministic policy - #95
feat(policy): gate semantic-node actions on deterministic policy#95seonghobae wants to merge 34 commits into
Conversation
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
…g' into codex/restack-pr95
Signed-off-by: Seongho Bae <me@seonghobae.me>
…g' into codex/restack-pr95 Signed-off-by: Seongho Bae <me@seonghobae.me> # Conflicts: # CHANGELOG.md # crates/originweave-core/src/browser_authority_registry.rs
|
Restacked non-destructively on PR #93 exact head |
Drop stale parent-file deltas, align document retirement with NotAdmitted, and record that deterministic policy allow remains separate from browser execution and post-condition proof. Commit-Message-Assisted-by: Claude (via Claude Code) Signed-off-by: Seongho Bae <me@seonghobae.me>
|
Exact-head repair evidence for |
|
Writer lease RELEASED — root task 01a06c0f-b427-7830-b654-9addcdfe7aff. Published #95 6b29d89, base #93 82056d1; head/base/body read back exactly. 8 focused Rust tests, 150 Python contracts, complete stable Rust pipeline and 100% production coverage passed (1408 functions,14897 lines,19022 regions,1552 branches; SHA256 666797dec8486f0f196616525303bd24dc52ef5d035f1c548e1bddde3fb48a22). Child policy and parent core/network/workflows byte-identical. Independent read-only review no findings, not formal approval. Actual Edge visual inspection /tmp/pr95-linked-rustdoc-6b29d890.png readable, both cross-crate links opened successfully after dependency-inclusive workspace doc build; no source workaround. All local processes terminal. CI 34080772063, Rust job101615473690 and coverage job101615473415 QUEUED at readback; no hosted pass/merge/release claim. Local worktree /private/tmp/originweave-pr95-sync.uJPXMN preserved, ignored results.tsv and untracked coverage artifact retained. Next safe item #96 current-parent adoption, then bounded baseline checkpoint. |
Current verified parent adoption
Exact head
6b29d890245ed2f612c2998198f4e8c8a06da312includes current #9382056d13aa94c106060b84ee76be56fcb7787fc8through ordinary merge8416de55. Test-first commit55f38590reproduced a replacement connection completing the original observation; the inherited fix rejects replacement success/error/exception replies, preserves the pending request, and permits only the original connection to complete it.The original policy crate and five policy tests are byte-identical to prior #95; core, network and workflows are byte-identical to current #93. Explicit Allow-only authorization and current registry-owned node checks remain independent of reply provenance and execution success.
At this exact head: 8 focused Rust tests, 150 Python contracts, complete workspace Rust tests, format, all-target check, strict Clippy and warnings-denied rustdoc passed. Production coverage is 100%: 1,408 functions, 14,897 lines, 19,022 regions and 1,552 branches. Coverage artifact SHA-256:
666797dec8486f0f196616525303bd24dc52ef5d035f1c548e1bddde3fb48a22. Independent read-only review found no actionable issues; it is not a formal GitHub approval.Actual Microsoft Edge visual inspection at 1440×1300 verified readable API documentation without clipping or overlap. The initial
--no-depsdocumentation build omitted cross-crate links;RUSTDOCFLAGS='-D warnings' cargo doc --workspacerendered both links, and their destination pages were opened successfully. No source workaround was added.Keep Draft while prerequisites remain active. New exact-head GitHub runs must finish independently; previous-head success, local verification and visual inspection do not establish protected-main acceptance, merge or release.
Historical evidence (superseded head)
Partial implementation of #28, stacked on the live
feat/semantic-node-action-bindingbranch.Current dependency / repair state
Fresh ancestry is exact current #93
0664f0452cb329cd692cce7f61f9001652abfda2→ #9597aa0f2e340ee6fd920d0418f97af276b190554f. The restack removed stale parent deltas that had reverted the current browser-authority registry and coverage contracts.Only
Decision::Allowcreates a policy-authorized semantic-node action.DenyandApprovalRequiredremain non-authorizing, and current registry-owned browser authority is revalidated before use. After a document advance removes the admitted node, current validation fails closed asNotAdmitted. This slice performs no browser I/O and makes no postcondition claim.Exact-current evidence
At exact head
97aa0f2e340ee6fd920d0418f97af276b190554f, local verification passed: 142 Python contract tests; locked Rust format, check, all-target tests, strict Clippy, and rustdoc; exact 100% production function, line, region, and branch coverage. GitHub checks are still non-passing until their exact-head runs finish.Keep Draft while its prerequisite stack remains active. No self-approval, force-push, destructive rebase, workflow/ruleset/secret mutation, gate weakening, release, or predecessor-evidence transfer is authorized.