Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions .github/workflows/hourly-nvidia-nim-review-repair.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,6 +16,7 @@ on:
- .github/workflows/nonnest2-hourly-review-repair.yml
- .github/workflows/originweave-hourly-review-repair.yml
- .github/workflows/quarantine-sandbox-hourly-review-repair.yml
- .github/workflows/kaefa-hourly-review-repair.yml
- scripts/ci/pr_review_conflict_scope.py
- scripts/ci/pr_review_autofix_context.py
- tests/test_bandscope_hourly_review_caller.py
Expand All @@ -27,6 +28,7 @@ on:
- tests/test_nonnest2_hourly_review_caller.py
- tests/test_originweave_hourly_review_caller.py
- tests/test_quarantine_sandbox_hourly_review_caller.py
- tests/test_kaefa_hourly_review_caller.py
- tests/test_hourly_autofix_context_quality_gate.py
- tests/test_pr_review_conflict_scope.py
- tests/test_pr_review_conflict_scope_control_files.py
Expand All @@ -51,6 +53,7 @@ on:
- docs/doctoring/nonnest2-hourly-review-caller.md
- docs/doctoring/originweave-hourly-review-caller.md
- docs/doctoring/quarantine-sandbox-hourly-review-caller.md
- docs/doctoring/kaefa-hourly-review-caller.md
push:
paths:
- .github/workflows/pr-review-fix-scheduler.yml
Expand All @@ -66,6 +69,7 @@ on:
- .github/workflows/nonnest2-hourly-review-repair.yml
- .github/workflows/originweave-hourly-review-repair.yml
- .github/workflows/quarantine-sandbox-hourly-review-repair.yml
- .github/workflows/kaefa-hourly-review-repair.yml
- scripts/ci/pr_review_conflict_scope.py
- scripts/ci/pr_review_autofix_context.py
- tests/test_bandscope_hourly_review_caller.py
Expand All @@ -77,6 +81,7 @@ on:
- tests/test_nonnest2_hourly_review_caller.py
- tests/test_originweave_hourly_review_caller.py
- tests/test_quarantine_sandbox_hourly_review_caller.py
- tests/test_kaefa_hourly_review_caller.py
- tests/test_hourly_autofix_context_quality_gate.py
- tests/test_pr_review_conflict_scope.py
- tests/test_pr_review_conflict_scope_control_files.py
Expand All @@ -101,6 +106,7 @@ on:
- docs/doctoring/nonnest2-hourly-review-caller.md
- docs/doctoring/originweave-hourly-review-caller.md
- docs/doctoring/quarantine-sandbox-hourly-review-caller.md
- docs/doctoring/kaefa-hourly-review-caller.md

permissions:
contents: read
Expand Down Expand Up @@ -157,6 +163,7 @@ jobs:
tests/test_nonnest2_hourly_review_caller.py \
tests/test_originweave_hourly_review_caller.py \
tests/test_quarantine_sandbox_hourly_review_caller.py \
tests/test_kaefa_hourly_review_caller.py \
tests/test_pr_review_conflict_scope_control_files.py \
tests/test_hourly_autofix_context_quality_gate.py \
tests/test_pr_review_conflict_scope_git_executable.py \
Expand Down
34 changes: 34 additions & 0 deletions .github/workflows/kaefa-hourly-review-repair.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,34 @@
name: kaefa Hourly Review Repair

on:
schedule:
# Minute 3 avoids pg-llm-batch (1), aFIPC (2), codec-carver (5),
# Wardnet (7), naruon (11), pg-erd-cloud (13), orchestrator (17),
# noema (19), Clearfolio (23), Keyverse (29), Scopeweave (31),
# DiskSage (37), Appguardrail (41), newsdom-api (43), Inkspan (47),
# fast-mlsirm (49), BandScope (53), and semantic-data-portal (59).
- cron: "3 * * * *"

concurrency:
group: kaefa-hourly-review-repair
# A later heartbeat must not cancel an in-flight EFA or item-fit RCA.
cancel-in-progress: false

permissions:
contents: read

jobs:
dispatch-review-repair:
permissions:
contents: read
id-token: write
uses: ./.github/workflows/pr-review-fix-scheduler.yml
with:
target_repository: ContextualWisdomLab/kaefa
base_branch: develop
max_prs: "50"
max_dispatches: "1"
retry_hours: "2"
secrets:
PR_REVIEW_MERGE_TOKEN: ${{ secrets.PR_REVIEW_MERGE_TOKEN }}
OPENCODE_APPROVE_TOKEN: ${{ secrets.OPENCODE_APPROVE_TOKEN }}
2 changes: 1 addition & 1 deletion ARCHITECTURE.md
Original file line number Diff line number Diff line change
Expand Up @@ -125,4 +125,4 @@ trusted `uv` exporter is downloaded from the literal GitHub Releases URL for
- [`docs/doctoring/hourly-nvidia-nim-autofix.md`](docs/doctoring/hourly-nvidia-nim-autofix.md)
— current increment's repair-worker decision and APA 7th citations.
- [`docs/doctoring/fast-mlsirm-hourly-review-caller.md`](docs/doctoring/fast-mlsirm-hourly-review-caller.md)
— product-specific psychometric repair heartbeat and scientific gates.
— product-specific psychometric repair heartbeat and scientific gates.
3 changes: 3 additions & 0 deletions CLAUDE.md
Original file line number Diff line number Diff line change
Expand Up @@ -64,6 +64,7 @@ Details: `docs/pr-review-and-merge-procedure.md` and `PR_GOVERNANCE_AUDIT.md`.
dependency sets (see below). `requirements-strix-ci-overrides.txt` documents one deliberate
`uv pip compile --override` (strix-agent's declared `cryptography<49` vs. this repo's
`cryptography==50.0.0` security pin; see #952) — re-verify it whenever strix-agent bumps again.
dependency sets (see below).
- `fuzz/` + `.clusterfuzzlite/` — Atheris fuzz targets for the review-output normalizer and the
ClusterFuzzLite discovery marker.
- `docs/` — master context, Project protocol, `org-required-workflow-rollout.md`,
Expand Down Expand Up @@ -100,6 +101,7 @@ e.g.:
uv pip compile --generate-hashes --python-version 3.12 --python-platform x86_64-manylinux_2_28 requirements-bandit-ci.txt -o requirements-bandit-ci-hashes.txt
uv pip compile --generate-hashes --python-version 3.12 --python-platform x86_64-manylinux_2_28 requirements-pip-audit-ci.txt -o requirements-pip-audit-ci-hashes.txt
uv pip compile --generate-hashes --python-version 3.13 --python-platform x86_64-manylinux_2_28 --override requirements-strix-ci-overrides.txt --output-file requirements-strix-ci-hashes.txt requirements-strix-ci.txt
uv pip compile --generate-hashes --python-version 3.13 --python-platform x86_64-manylinux_2_28 --output-file requirements-strix-ci-hashes.txt requirements-strix-ci.txt
./scripts/ci/compile_opencode_review_lock.sh
```

Expand All @@ -118,6 +120,7 @@ repeatable compile command.
- **100% coverage and 100% docstrings on `scripts/ci/`** are hard gates, not aspirations. New helper
code needs matching tests and docstrings.
- **Product hourly callers** stay thin. Do not hard-code OriginWeave, naruon, or Keyverse
- **Product hourly callers** stay thin. Do not hard-code kaefa, naruon, or Keyverse
into `pr-review-fix-scheduler.yml`. The model credential remains `NVIDIA_NIM_API_KEY`
on the worker, never `COPILOT_GITHUB_TOKEN`.
- **`pull_request_target` trust boundary.** The required review workflows run the *base branch's*
Expand Down
146 changes: 146 additions & 0 deletions docs/doctoring/kaefa-hourly-review-caller.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,146 @@
# kaefa hourly review-repair caller

검토 기준일: **2026-08-17**

## Decision

ContextualWisdomLab operates one protected hourly caller for
`ContextualWisdomLab/kaefa` (Kwangwoon automated exploratory factor
analysis — multilevel / cross-classified item-fit model search consumed
by fast-mlsirm). The caller runs at minute 3, delegates to the
product-neutral central review-fix scheduler, inspects at most 50 open
pull requests targeting protected Git Flow `develop`, and dispatches at
most one bounded repair per heartbeat.

A paying buyer of automated exploratory factor analysis would feel live
kaefa pull requests stalling while hourly NVIDIA NIM repair scanned only
Clearfolio, DiskSage, and fast-mlsirm. Live heads such as
ContextualWisdomLab/kaefa#78 (r-lib actions pin) and
ContextualWisdomLab/kaefa#75 (renamed-product documentation) target
`develop` and never enter those other callers. Historical required-workflow
proof on ContextualWisdomLab/kaefa#60 also showed only repo-local
R-CMD-check, dependency-review, and CodeQL rollup.

The caller does not implement review or mutation logic itself. kaefa
remains a standalone R package. This control-plane repository does not
vendor, import, or relicense kaefa source; the product's SPDX identifier
is GPL-3.0, and the caller only names the GitHub repository so the
shared scheduler can inspect pull requests. Privileged automation stays
in `ContextualWisdomLab/.github`.

## Root-cause analysis and remediation feasibility

The reusable worker performs exact-head root-cause analysis and tests
remediation feasibility before it edits. The reusable worker must:

1. Refetch the exact live head, base, reviews, checks, changed paths, and
writer state.
2. Establish the causal chain rather than repeat the terminal symptom.
3. Enumerate materially distinct minimal remedies.
4. Reject remedies that lack writer authority, cross sealed paths, require
unavailable credentials or protected-setting changes, violate stack
order, cannot be verified, or do not alter the diagnosed cause.
5. Dispatch at most one feasible repair. Otherwise leave the tree
unchanged.

A queued or pending check remains a merge blocker but is not itself a
code finding. The independent non-author approval remains an external
authorization gate and is never synthesized by the repair worker. The
worker cannot approve, merge, release, resolve review findings by
inference, change protection, or manufacture passing checks.
Psychometric item-fit, multilevel model-search, and R CMD check
acceptance bounds are not loosened to make a check green.

## Cadence and concurrency

The caller uses a single concurrency group and `cancel-in-progress: false`.
This preserves an in-flight bounded RCA instead of discarding EFA or
item-fit evidence when the next hourly heartbeat arrives. The reusable
scheduler cancels only its own superseded short queue scan.

The caller sets a **two-hour same-head retry floor**. Central OpenCode and
NVIDIA NIM work, plus R CMD check and multilevel model-search analysis,
can legitimately approach two hours. An hourly redispatch of the same
unchanged head would create duplicate writer pressure rather than faster
remediation.

GitHub scheduled workflows can be delayed under load and execute only
from the default branch. The cron expression is a heartbeat, not a
real-time SLA.

## Credential and model boundary

The caller keeps workflow `GITHUB_TOKEN` at `contents: read` and grants
the reusable job `id-token: write` so the central scheduler can mint the
OpenCode GitHub App token from GitHub OIDC when the mapped PAT is absent
(GitHub, n.d.-c). It maps only `PR_REVIEW_MERGE_TOKEN` and
`OPENCODE_APPROVE_TOKEN`. It never uses `secrets: inherit`, receives
`NVIDIA_NIM_API_KEY`, or introduces `COPILOT_GITHUB_TOKEN`. CWE-250
forbids executing the caller with write or model privileges it does not
need (MITRE, 2026).

Model execution remains inside the central worker. The model credential
is the GitHub Secret `NVIDIA_NIM_API_KEY`; the caller does not receive or
forward it.

Before protected-develop activation, the repository variable
`OPENCODE_REPOSITORY_DISPATCH_TARGETS` must contain the exact
`ContextualWisdomLab/kaefa` target. Missing or mismatched
configuration fails before mutation credential materialization.

## Security, standalone operation, and modularity

The caller adds no kaefa runtime dependency, database object, network
endpoint, tenant authority, or product credential. kaefa continues to
run as a standalone R exploratory-factor-analysis package. fast-mlsirm
and other CWL services may consume its item-fit search, but they cannot
weaken its exact-head, approval, or security gates. Operational PII is
not masked; only scheduler and model credentials stay redacted.

## Verification and rollback

Machine-checkable contracts require the exact target/base, minute 3
cadence, non-cancelling single-flight group, one dispatch, two-hour
retry floor, explicit secret mapping, read-only contents plus job-scoped
`id-token: write`, focused path-filter coverage, and absence of model or
Copilot credentials. Independent `pull_request`, `push`, and `compileall`
path blocks must each name the caller, doctoring, or contract they own.

After source integration, closure requires a scheduled or manual
protected-develop consumer run proving the exact kaefa repository and
`develop` base. Source checks alone are not protected-develop operational acceptance.
Comment thread
coderabbitai[bot] marked this conversation as resolved.
Merge still requires zero unresolved valid findings and a
qualifying independent non-author approval.

Rollback removes the kaefa caller, its focused test, doctoring, and
central path-filter/documentation entries. It must not remove scheduler
dispatch validation or affect independent product callers.

## APA 7th references

GitHub, Inc. (n.d.-a). *Events that trigger workflows*. GitHub Docs.
Retrieved August 17, 2026, from
https://docs.github.com/en/actions/reference/workflows-and-actions/events-that-trigger-workflows#schedule

GitHub, Inc. (n.d.-b). *Reuse workflows*. GitHub Docs. Retrieved August
17, 2026, from
https://docs.github.com/en/actions/how-tos/sharing-automations/reuse-workflows

GitHub, Inc. (n.d.-c). *Automatic token authentication*. GitHub Docs.
Retrieved August 17, 2026, from
https://docs.github.com/en/actions/security-for-github-actions/security-guides/automatic-token-authentication#permissions-for-the-github_token

MITRE. (2026). *CWE-250: Execution with unnecessary privileges*.
https://cwe.mitre.org/data/definitions/250.html

National Institute of Standards and Technology. (2022). *Secure software
development framework (SSDF) version 1.1: Recommendations for mitigating
the risk of software vulnerabilities* (NIST Special Publication 800-218).
https://doi.org/10.6028/NIST.SP.800-218

NVIDIA. (n.d.). *NVIDIA NIM for large language models documentation*.
Retrieved August 17, 2026, from
https://docs.nvidia.com/nim/large-language-models/latest/

OpenCode. (n.d.). *OpenCode documentation*. Retrieved August 17, 2026,
from https://opencode.ai/docs/
Loading
Loading