Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions .github/workflows/hourly-nvidia-nim-review-repair.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,7 @@ on:
- .github/workflows/github-hourly-review-repair.yml
- .github/workflows/governance-risk-compliance-hourly-review-repair.yml
- .github/workflows/hourly-nvidia-nim-review-repair.yml
- .github/workflows/naruon-hourly-review-repair.yml
- .github/workflows/nonnest2-hourly-review-repair.yml
- .github/workflows/originweave-hourly-review-repair.yml
- scripts/ci/pr_review_conflict_scope.py
Expand All @@ -25,6 +26,7 @@ on:
- tests/test_hourly_scheduler_runtime_budget.py
- tests/test_nonnest2_hourly_review_caller.py
- tests/test_originweave_hourly_review_caller.py
- tests/test_naruon_hourly_review_caller.py
- tests/test_hourly_autofix_context_quality_gate.py
- tests/test_pr_review_conflict_scope.py
- tests/test_pr_review_conflict_scope_control_files.py
Expand All @@ -48,6 +50,7 @@ on:
- docs/doctoring/hourly-nvidia-nim-autofix.md
- docs/doctoring/nonnest2-hourly-review-caller.md
- docs/doctoring/originweave-hourly-review-caller.md
- docs/doctoring/naruon-hourly-review-caller.md
push:
paths:
- .github/workflows/pr-review-fix-scheduler.yml
Expand All @@ -60,6 +63,7 @@ on:
- .github/workflows/github-hourly-review-repair.yml
- .github/workflows/governance-risk-compliance-hourly-review-repair.yml
- .github/workflows/hourly-nvidia-nim-review-repair.yml
- .github/workflows/naruon-hourly-review-repair.yml
- .github/workflows/nonnest2-hourly-review-repair.yml
- .github/workflows/originweave-hourly-review-repair.yml
- scripts/ci/pr_review_conflict_scope.py
Expand All @@ -72,6 +76,7 @@ on:
- tests/test_hourly_scheduler_runtime_budget.py
- tests/test_nonnest2_hourly_review_caller.py
- tests/test_originweave_hourly_review_caller.py
- tests/test_naruon_hourly_review_caller.py
- tests/test_hourly_autofix_context_quality_gate.py
- tests/test_pr_review_conflict_scope.py
- tests/test_pr_review_conflict_scope_control_files.py
Expand All @@ -95,6 +100,7 @@ on:
- docs/doctoring/hourly-nvidia-nim-autofix.md
- docs/doctoring/nonnest2-hourly-review-caller.md
- docs/doctoring/originweave-hourly-review-caller.md
- docs/doctoring/naruon-hourly-review-caller.md

permissions:
contents: read
Expand Down Expand Up @@ -150,6 +156,7 @@ jobs:
tests/test_hourly_scheduler_runtime_budget.py \
tests/test_nonnest2_hourly_review_caller.py \
tests/test_originweave_hourly_review_caller.py \
tests/test_naruon_hourly_review_caller.py \
tests/test_pr_review_conflict_scope_control_files.py \
tests/test_hourly_autofix_context_quality_gate.py \
tests/test_pr_review_conflict_scope_git_executable.py \
Expand Down
30 changes: 30 additions & 0 deletions .github/workflows/naruon-hourly-review-repair.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,30 @@
name: naruon Hourly Review Repair

on:
schedule:
# Minute 11 avoids Clearfolio (23), DiskSage (37), and fast-mlsirm (49).
- cron: "11 * * * *"

concurrency:
group: naruon-hourly-review-repair
# A later heartbeat must not cancel an in-flight platform RCA or repair.
cancel-in-progress: false

permissions:
contents: read

jobs:
dispatch-review-repair:
permissions:
contents: read
id-token: write
uses: ./.github/workflows/pr-review-fix-scheduler.yml
with:
target_repository: ContextualWisdomLab/naruon
base_branch: develop
max_prs: "50"
max_dispatches: "1"
retry_hours: "2"
secrets:
PR_REVIEW_MERGE_TOKEN: ${{ secrets.PR_REVIEW_MERGE_TOKEN }}
OPENCODE_APPROVE_TOKEN: ${{ secrets.OPENCODE_APPROVE_TOKEN }}
1 change: 1 addition & 0 deletions AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,7 @@
> **Agents: read the master context FIRST.** Before any work, read [`docs/CWL-MASTER-CONTEXT.md`](docs/CWL-MASTER-CONTEXT.md) (mission · naruon-as-platform + inter-component UML · cross-cutting disciplines · conventions · roadmap · current state), the live **GitHub Project #1** <https://github.com/orgs/ContextualWisdomLab/projects/1> (work/roadmap source of truth), the full spec **ContextualWisdomLab/naruon#974**, and operate the Project per [`docs/agent-github-project-protocol.md`](docs/agent-github-project-protocol.md). The repo/Project — not any private agent memory — is the source of truth.

Materialize accepts only exact SHA-256 pins or a bounded relative `-r` include (no `.`/`..`); a lone `--require-hashes` directive is not trust evidence. See [`docs/doctoring/hourly-nvidia-nim-autofix.md`](docs/doctoring/hourly-nvidia-nim-autofix.md).
naruon's platform hourly caller scans `ContextualWisdomLab/naruon` `develop` via the product-neutral NVIDIA NIM scheduler (`NVIDIA_NIM_API_KEY` stays on the worker; never `COPILOT_GITHUB_TOKEN`). See [`docs/doctoring/naruon-hourly-review-caller.md`](docs/doctoring/naruon-hourly-review-caller.md).
Conflict-scope roots fail closed when the immediate parent directory is a symbolic link.
OriginWeave hourly NVIDIA NIM repair is a thin caller at minute 10. See [`docs/doctoring/originweave-hourly-review-caller.md`](docs/doctoring/originweave-hourly-review-caller.md).
nonnest2 hourly NVIDIA NIM repair is a thin caller at minute 16. See [`docs/doctoring/nonnest2-hourly-review-caller.md`](docs/doctoring/nonnest2-hourly-review-caller.md).
11 changes: 7 additions & 4 deletions ARCHITECTURE.md
Original file line number Diff line number Diff line change
Expand Up @@ -66,9 +66,10 @@ The worker checks out helpers at `${{ github.sha }}` so a later default-branch
push cannot replace privileged scripts after dispatch (CWE-367). Repair binds
`NVIDIA_NIM_API_KEY`, never `COPILOT_GITHUB_TOKEN`.

Product callers stagger Clearfolio at minute 23, DiskSage at minute 37, and
fast-mlsirm at minute 49. Each caller is read-only, dispatches at most one
repair, and delegates all privileged logic to the same sealed scheduler.
Product callers stagger naruon at minute 11, Clearfolio at minute 23, DiskSage
at minute 37, and fast-mlsirm at minute 49. Each caller is read-only,
dispatches at most one repair, and delegates all privileged logic to the same
sealed scheduler.

## Control-plane data flow

Expand Down Expand Up @@ -123,4 +124,6 @@ trusted `uv` exporter is downloaded from the literal GitHub Releases URL for
- [`docs/doctoring/hourly-nvidia-nim-autofix.md`](docs/doctoring/hourly-nvidia-nim-autofix.md)
— current increment's repair-worker decision and APA 7th citations.
- [`docs/doctoring/fast-mlsirm-hourly-review-caller.md`](docs/doctoring/fast-mlsirm-hourly-review-caller.md)
— product-specific psychometric repair heartbeat and scientific gates.
— product-specific psychometric repair heartbeat and scientific gates.
- [`docs/doctoring/naruon-hourly-review-caller.md`](docs/doctoring/naruon-hourly-review-caller.md)
— naruon platform hourly NVIDIA NIM repair heartbeat on protected `develop`.
2 changes: 2 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -16,13 +16,15 @@ Semantic Versioning where the repository publishes a release.
- Added a dedicated Clearfolio hourly caller that invokes the product-neutral central scheduler with the exact repository, protected base branch, one-dispatch budget, one-hour retry floor, single-flight concurrency, and only the established scheduler credentials.
- Added a dedicated DiskSage hourly caller that invokes the same product-neutral RCA and remediation-feasibility scheduler with an exact repository target, one-dispatch budget, two-hour same-head retry floor, non-cancelling single-flight heartbeat, and explicit established scheduler credentials.
- Added a dedicated fast-mlsirm hourly caller that preserves Rust-owned psychometric arithmetic while dispatching at most one exact-head, root-cause-driven repair with a two-hour same-head retry floor.
- Added a dedicated naruon hourly caller that scans `ContextualWisdomLab/naruon` protected `develop` at minute 11 with one dispatch, a two-hour same-head retry floor, job-scoped `id-token: write` for the OpenCode OIDC fallback, and only the established scheduler credentials so platform pull requests receive NVIDIA NIM repair.

### Changed

- Require the hourly repair worker to establish an exact-head root cause, enumerate the smallest remediation candidates, and prove writer authority, sealed-path scope, credentials, dependency order, verifiability, and causal effect before editing; infeasible or external blockers leave the tree unchanged while the broader loop continues with another eligible PR or buyer-visible product gap.
- Run the bounded Clearfolio PR review-feedback repair caller at minute 23 of every hour while keeping the shared scheduler free of product-specific timers and repository names for modular reuse by naruon, contextual-orchestrator, Inkspan, and other CWL services.
- Run the bounded DiskSage repair heartbeat at minute 37 of every hour, dispatch no more than one exact-head repair, and wait two hours before redispatching an unchanged head so legitimate OpenCode or NVIDIA NIM latency does not create duplicate writers.
- Run the bounded fast-mlsirm repair heartbeat at minute 49 of every hour with one-dispatch scope and a two-hour same-head floor, without weakening true-parameter recovery, CPU/GPU parity, skipped-test, or Rust-ownership gates.
- Run the bounded naruon platform repair heartbeat at minute 11 of every hour against protected `develop`, dispatching at most one exact-head repair and waiting two hours before redispatching an unchanged head.
- Use NVIDIA NIM `mistralai/mistral-small-4-119b-2603` with explicit high reasoning for scheduled repair and `nvidia/nemotron-3-nano-30b-a3b` for bounded helper work instead of GitHub Models in the write-capable autofix worker.
- Apply one NUL-delimited exact-path and complete pre/post-worktree verification contract to both ordinary review repair and merge-conflict repair rather than relying on a visible post-model diff for the ordinary path.

Expand Down
1 change: 1 addition & 0 deletions CLAUDE.md
Original file line number Diff line number Diff line change
Expand Up @@ -69,6 +69,7 @@ Details: `README.md` and `PR_GOVERNANCE_AUDIT.md`.
`scorecard-governance.md`, SBOM inventory. Doctoring records live under
`docs/doctoring/`. [`ARCHITECTURE.md`](ARCHITECTURE.md) is the control-plane
diagram for review, hourly NVIDIA NIM repair, and merge trust boundaries.
naruon's platform caller is `naruon-hourly-review-repair.yml` (minute 11, `develop`).
- `.jules/` — recorded performance (`bolt.md`) and security (`sentinel.md`) learnings from past work
on `scripts/ci/`; worth scanning before optimizing or hardening those scripts.

Expand Down
24 changes: 24 additions & 0 deletions docs/automation/hourly-review-repair.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,8 @@ engine**.

- `clearfolio-hourly-review-repair.yml` owns Clearfolio's heartbeat at minute 23
of every hour.
- `naruon-hourly-review-repair.yml` owns naruon's platform heartbeat at minute 11
of every hour against protected `develop`.
- `pr-review-fix-scheduler.yml` is the reusable, product-neutral scheduler
module. It has no product-specific timer and can be called by naruon,
contextual-orchestrator, Inkspan, or another CWL service with an explicit
Expand Down Expand Up @@ -39,6 +41,28 @@ The caller passes only the established `PR_REVIEW_MERGE_TOKEN` and
`NVIDIA_NIM_API_KEY`; the model credential is scoped exclusively to the two
OpenCode execution steps in the separately reviewed autofix worker.

## naruon execution contract

The naruon caller provides the following immutable operating parameters:

```yaml
target_repository: ContextualWisdomLab/naruon
base_branch: develop
max_prs: "50"
max_dispatches: "1"
retry_hours: "2"
```

The scheduled heartbeat is `11 * * * *`. The caller job grants `id-token: write`
so the reusable NVIDIA NIM scheduler can mint its OpenCode App fallback from
GitHub OIDC. It does not receive or forward `NVIDIA_NIM_API_KEY` and never
introduces `COPILOT_GITHUB_TOKEN`.

The caller passes only the established `PR_REVIEW_MERGE_TOKEN` and
`OPENCODE_APPROVE_TOKEN` scheduler credentials. It does not receive or forward
`NVIDIA_NIM_API_KEY`; the model credential is scoped exclusively to the two
OpenCode execution steps in the separately reviewed autofix worker.

## Reusable target-selection contract

The shared scheduler resolves its target in this order:
Expand Down
132 changes: 132 additions & 0 deletions docs/doctoring/naruon-hourly-review-caller.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,132 @@
# naruon hourly review-repair caller

검토 기준일: **2026-08-17**

## Decision

ContextualWisdomLab operates one protected hourly caller for
`ContextualWisdomLab/naruon` (naruon.net / naruon.io — the email-workspace
platform). The caller runs at minute 11, delegates to the product-neutral
central review-fix scheduler, inspects at most 50 open pull requests targeting
protected `develop`, and dispatches at most one bounded repair per heartbeat.

A paying buyer of the email workspace would feel live naruon pull requests
stalling while hourly NVIDIA NIM repair scanned only Clearfolio, DiskSage, and
fast-mlsirm, all against `main`. Live heads such as
ContextualWisdomLab/naruon#1388 (NetworkGraph lookup), #1387 (calendar
sidebar), #1386 (graph rendering), #1383 (NVIDIA NIM review config), #1382
(first-wins graph ids), and #1380 (DAV capability honesty) target `develop`
and never enter those other callers.

The caller does not implement review or mutation logic itself. Naruon remains
standalone; wardnet, keyverse, and inkspan plug into it without owning its
runtime. Privileged automation stays in `ContextualWisdomLab/.github`.

## Root-cause analysis and remediation feasibility

The reusable worker performs exact-head root-cause analysis and tests
remediation feasibility before it edits. The reusable worker must:

1. Refetch the exact live head, base, reviews, checks, changed paths, and
writer state.
2. Establish the causal chain rather than repeat the terminal symptom.
3. Enumerate materially distinct minimal remedies.
4. Reject remedies that lack writer authority, cross sealed paths, require
unavailable credentials or protected-setting changes, violate stack order,
cannot be verified, or do not alter the diagnosed cause.
5. Dispatch at most one feasible repair. Otherwise leave the tree unchanged.

A queued or pending check remains a merge blocker but is not itself a code
finding. The independent non-author approval remains an external authorization
gate and is never synthesized by the repair worker. The worker cannot approve,
merge, release, resolve review findings by inference, change protection, or
manufacture passing checks.

## Cadence and concurrency

The caller uses a single concurrency group and `cancel-in-progress: false`.
This preserves an in-flight bounded RCA instead of discarding platform
evidence when the next hourly heartbeat arrives. The reusable scheduler
cancels only its own superseded short queue scan.

The caller sets a **two-hour same-head retry floor**. Central OpenCode and
NVIDIA NIM work, plus naruon's dense-KG and connector analysis, can
legitimately approach two hours. An hourly redispatch of the same unchanged
head would create duplicate writer pressure rather than faster remediation.

GitHub scheduled workflows can be delayed under load and execute only from the
default branch. The cron expression is a heartbeat, not a real-time SLA.

## Credential and model boundary

The caller keeps workflow `GITHUB_TOKEN` at `contents: read` and grants the
reusable job `id-token: write` so the central scheduler can mint the OpenCode
GitHub App token from GitHub OIDC when the mapped PAT is absent (GitHub,
n.d.-c). It maps only `PR_REVIEW_MERGE_TOKEN` and `OPENCODE_APPROVE_TOKEN`.
It never uses `secrets: inherit`, receives `NVIDIA_NIM_API_KEY`, or introduces
`COPILOT_GITHUB_TOKEN`. CWE-250 forbids executing the caller with write or
model privileges it does not need (MITRE, 2026).

Model execution remains inside the central worker. The model credential is the
GitHub Secret `NVIDIA_NIM_API_KEY`; the caller does not receive or forward it.

Before protected-develop activation, the repository variable
`OPENCODE_REPOSITORY_DISPATCH_TARGETS` must contain the exact
`ContextualWisdomLab/naruon` target. Missing or mismatched configuration
fails before mutation credential materialization.

## Security, standalone operation, and modularity

The caller adds no naruon runtime dependency, database object, network
endpoint, tenant authority, or product credential. Naruon continues to run as
a standalone email workspace. Sibling services may plug into naruon, but they
cannot weaken its local validation, protected-branch, exact-head, approval,
or security gates.

## Verification and rollback

Machine-checkable contracts require the exact target/base, minute 11 cadence,
non-cancelling single-flight group, one dispatch, two-hour retry floor,
explicit secret mapping, read-only contents plus job-scoped `id-token: write`,
focused path-filter coverage, and absence of model or Copilot credentials.
Independent `pull_request`, `push`, and `compileall` path blocks must each
name the caller, doctoring, or contract they own.

After source integration, closure requires a scheduled or manual
protected-develop consumer run proving the exact naruon repository and
`develop` base. Source checks alone are not protected-develop operational acceptance.
Merge still requires zero unresolved valid findings and a
qualifying independent non-author approval.

Rollback removes the naruon caller, its focused test, doctoring, and central
path-filter/documentation entries. It must not remove scheduler dispatch
validation or affect independent product callers.

## APA 7th references

GitHub, Inc. (n.d.-a). *Events that trigger workflows*. GitHub Docs. Retrieved
August 17, 2026, from
https://docs.github.com/en/actions/reference/workflows-and-actions/events-that-trigger-workflows#schedule

GitHub, Inc. (n.d.-b). *Reuse workflows*. GitHub Docs. Retrieved August 17,
2026, from
https://docs.github.com/en/actions/how-tos/sharing-automations/reuse-workflows

GitHub, Inc. (n.d.-c). *Automatic token authentication*. GitHub Docs.
Retrieved August 17, 2026, from
https://docs.github.com/en/actions/security-for-github-actions/security-guides/automatic-token-authentication#permissions-for-the-github_token

MITRE. (2026). *CWE-250: Execution with unnecessary privileges*.
https://cwe.mitre.org/data/definitions/250.html

National Institute of Standards and Technology. (2022). *Secure software
development framework (SSDF) version 1.1: Recommendations for mitigating the
risk of software vulnerabilities* (NIST Special Publication 800-218).
https://doi.org/10.6028/NIST.SP.800-218

NVIDIA. (n.d.). *NVIDIA NIM for large language models documentation*.
Retrieved August 17, 2026, from
https://docs.nvidia.com/nim/large-language-models/latest/

OpenCode. (n.d.). *OpenCode documentation*. Retrieved August 17, 2026, from
https://opencode.ai/docs/
5 changes: 3 additions & 2 deletions tests/test_hourly_scheduler_runtime_budget.py
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,7 @@
REUSABLE = Path(".github/workflows/pr-review-fix-scheduler.yml")
CLEARFOLIO = Path(".github/workflows/clearfolio-hourly-review-repair.yml")
DISKSAGE = Path(".github/workflows/disksage-hourly-review-repair.yml")
NARUON = Path(".github/workflows/naruon-hourly-review-repair.yml")
QUALITY = Path(".github/workflows/hourly-nvidia-nim-review-repair.yml")


Expand All @@ -25,8 +26,8 @@ def test_queue_scanner_has_a_bounded_superseding_runtime() -> None:


def test_product_callers_do_not_cancel_an_in_flight_rca() -> None:
"""Clearfolio and DiskSage preserve the non-cancelling product lease."""
for caller_path in (CLEARFOLIO, DISKSAGE):
"""Clearfolio, DiskSage, and naruon preserve the non-cancelling product lease."""
for caller_path in (CLEARFOLIO, DISKSAGE, NARUON):
caller = _read(caller_path)
assert "cancel-in-progress: false" in caller
assert "cancel-in-progress: true" not in caller
Expand Down
Loading
Loading