Add opt-in source-bound ruleset profiles - #100
Merged
Merged
Conversation
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
11 tasks
mochan-tk
marked this pull request as ready for review
August 17, 2026 05:46
Owner
Author
|
Human approval: PR #100 is approved after strict-restart authorization, durable tests-only expected-red run, fail-closed mixed issuer coverage, exact two-path ownership, 380-line bound, and current-head CI 5/5. The repository owner explicitly accepts the disclosed app-local Rubber Duck provenance limitation for Task #99 and authorizes administrator merge. |
This was referenced Aug 17, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #99
Plan: #99 (comment)
Summary
Adds opt-in
--profile solo|teamhandling to the explicit ruleset actuator while leaving the no-profile path unchanged. Explicit intent is persisted before fresh ruleset creation; team payloads bind every required context to one common App ID derived from paginated latest check runs on the target repository's default branch. All invalid, incomplete, mixed, unauthorized, unavailable, or failed evidence/persistence paths stop before a ruleset write.Tests-first record
a494b9ead97b94a34948944a738450ff3832ade2completed / failureon the exact tests-only head)ok; all 24 new profile-contract assertions werenot ok; the cumulative no-DELETE/no-probe wall wasok; summary39 case(s), 24 failed.0951ae6(test-only), followed by production-only commite6e7ad6.Evidence
a494b9e; preserved run31997677917on exact head; production appears only in latere6e7ad6--profile solo|team; invalid usage; unchanged no-profile pathbash .github/scripts/tests/run-tests.sh setup-ruleset->39 case(s), 0 failed; production diff is additive and all legacy assertions passtrunk, latest/pagination, missing/multiple/cross-context/numeric+null/numeric+malformed evidence15368Fresh custom reviewer audit
Disposition: GAPS. The fresh risk:high reviewer independently verified Task linkage, authorization chronology, tests-first expected-red history, the surgical correction, production separation, every acceptance criterion, live GET-only behavior, no test/check weakening, exact ownership, the 380-line budget, governance safety, deviation honesty, and final CI run https://github.com/mochan-tk/agentic-dev-kit-for-copilot/actions/runs/31998430977 at exact head
e6e7ad68abcaa40b5b68993426fca74148b61735with all five jobs successful.The sole gap is review-gate provenance: this app surface exposes the completed Rubber Duck child agents (
tests-first-duck,tests-first-duck-final, andimplementation-duck, owned by worker sessionfe292f8a-6ed5-4b6b-8fce-1ae21d500ee5) but supplied no independently inspectable GitHub run/session URL or immutable timestamp artifact. The reviewer therefore treats both PASS statements above as attestation-only and requires durable historical references proving the first gate preceded the fixture-only commit and the second followed deterministic verification. A new run cannot substitute for missing historical chronology.The requester explicitly accepted this disclosed provenance limitation as a Task #99 exception: #99 (comment). This human decision accepts the app-local PASS attestations without rewriting the fresh reviewer
GAPSdisposition, inventing chronology, or treating a later review as historical proof. All other gates remain unchanged.Deviations
During the initial local production implementation, the focused wall exposed an impossible blanket test condition: the Plan phrase
persistence failure ... before writescould be read to forbid the intentionally attempted variable write itself, while the issue acceptance criterion and the Plan's variable-before-ruleset sequence require that POST/PATCH attempt to fail and then prohibit any ruleset write. The supervisor and Epic parent clarified the existing contract without changing the Plan. Commit0951ae6surgically requires exactly one failed variable create/update attempt and zero later ruleset/probe mutation; discovery/read failures retain the original zero-write helper. This correction was committed separately before the production commit, but it did not predate the initial local production edit. The original tests-only commit and expected-red run remain preserved.No implementation deviation from the clarified Task contract remains.
Follow-ups
No implementation follow-up. Readiness awaits supervisor independent final-ledger verification and Epic-parent report. Serialized followers #96 and #97 remain blocked and untouched.
Checklist