Skip to content

fix(opencode): restore coverage-blocked status after fallback review - #1056

Draft
cursor[bot] wants to merge 3 commits into
mainfrom
cursor/bc-eaa0f2a9-0a33-4ebd-82f7-2fe0c9374b5a-0a81
Draft

fix(opencode): restore coverage-blocked status after fallback review#1056
cursor[bot] wants to merge 3 commits into
mainfrom
cursor/bc-eaa0f2a9-0a33-4ebd-82f7-2fe0c9374b5a-0a81

Conversation

@cursor

@cursor cursor Bot commented Aug 16, 2026

Copy link
Copy Markdown
Contributor

Summary

This is the landing vehicle for the OriginWeave #47 review-surface split (#1052) plus two buyer-visible gaps found on that draft:

  1. Status comment honesty. publish_fallback_diff_review posts a COMMENT product-file review, and create_pull_review COMMENT rewrites the issue comment to Gate result: COMMENT. On the real ⚡ Bolt: opencode_review_normalize_output.py의 iter_json_objects 성능 최적화 #47 path — coverage miss plus unavailable model — that left the status surface looking finished. The fallback publisher now restores COVERAGE_BLOCKED after the review so the next action is still “fix coverage evidence, then rerun OpenCode.”
  2. Mermaid honesty. The class diagram listed public Rust items and then invented FirstType --> SecondType. It now lists the extracted API names only.

Coverage remains a fail-closed gate, not the review. Formal review still names the changed crate files. The central workflow file is still not cited unless it is in the diff. Isolated coverage still installs the declared rustup channel plus llvm-tools-preview. Read-only review-agent keys and NVIDIA_NIM_API_KEY routing are unchanged. No COPILOT_GITHUB_TOKEN.

Prefer this branch over draft #1052. Close or supersede #1052 after this head is reviewed.

Test plan

  • tests/test_opencode_review_surfaces.py — fallback publisher restores COVERAGE_BLOCKED; two public Rust items do not get a fabricated class edge
  • tests/test_pr_review_autofix_nvidia_nim_contract.py — independent-reviewer dispatch blob pin updated
  • Full coverage run -m pytest tests && coverage report --show-missing (1162 passed, 100%) and interrogate (100%)

Next action

Review this head. Do not merge #1052 while it still leaves Gate result: COMMENT on a coverage miss.

Open in Web View Automation 

cursoragent and others added 3 commits August 16, 2026 16:17
OriginWeave #47 posted the same coverage-gate body as both the formal
review and the issue comment, citing opencode-review.yml:1 while the
diff was a Rust crate. Split those surfaces, still review changed
product files when coverage-evidence fails, label crates/ as a Rust
surface, and install the declared rustup channel plus llvm-tools in
the isolated coverage image.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Update the independent-reviewer workflow hash after the publisher
split, and add the remaining OriginWeave-style rustup/mermaid branches
so scripts/ci stays at 100% coverage.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
create_pull_review COMMENT rewrites the issue comment to Gate result:
COMMENT. On the OriginWeave #47 path — coverage miss plus unavailable
model — that left the status surface looking finished. Restore
COVERAGE_BLOCKED after the product-file review, and list extracted
Rust API names without inventing a classDiagram edge.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>

Copy link
Copy Markdown
Contributor

Fresh downstream evidence for the central coverage/review boundary: ContextualWisdomLab/OriginWeave#45 is currently at exact head 6e615ecb9b946943f2e360a4ba4fe3ed8003ce6b. OriginWeave-native CI run 31683160261 is terminal success on that head, including Production coverage job 94393052343, which enforces the repository's exact owned production function/line/region/branch coverage contract. SAST 31683160234 and Security Scan 31683160241 are also successful. The central OpenCode review for the same exact head remains CHANGES_REQUESTED from .github run 31695895087 because the separately dispatched coverage-evidence path failed and reported branch coverage around 36.70355191256831 instead of consuming OriginWeave's repository verifier contract. Please use this exact unchanged consumer head as a regression/operational canary for the inherited #1052 behavior in this landing vehicle: coverage failure must remain fail-closed, but the central path should honor the repository's scripts/ci/verify_coverage.py contract rather than manufacture a generic below-100 conclusion when repository-native exact-head coverage is already proven. After protected integration, rerun OpenCode against the then-current OriginWeave #45 head; only a fresh same-head verdict should supersede the existing review.

Copy link
Copy Markdown
Contributor

Fresh consumer canary for this same review-surface/control-plane boundary: ContextualWisdomLab/OriginWeave#37 exact head 89b761031e24f5202958aa6785763ad0bbac751e, protected/base tip 0841d2ab3d8b5e60a03c0a8e818cf438e2716829.

Central OpenCode dispatch run 32003668784 at .github protected head c47afc2dc68488292c1db7c9d6f82dcd5360f181 reached the exact merge-tree coverage path. validate-pr-metadata and coverage-source-tree succeeded; coverage job 95308823452 then passed trusted-source materialization, merge-artifact extraction, stale-head replay guard, and changed-file syntax gate, but failed specifically at Measure test and docstring evidence when the isolated sandbox exited 1. The available job annotation is only the generic Coverage sandbox reported failing test, build, or coverage evidence; the connector does not expose the inner sandbox log, so the actual failing command/test boundary is not yet proven and must not be invented.

Separately, the unchanged OriginWeave exact head has its own native Production coverage check 95247924465 / run 31981170803 passing with functions/lines/regions/branches all 100%. That leaf result does not override the central merge-tree sandbox failure, but it is a useful differential signal for RCA.

The current formal OpenCode review 4949132961 is anchored to exact head 89b761... and requests changes because coverage evidence did not pass, but renders the control-plane failure as a HIGH source finding at .github/workflows/opencode-review.yml:1 with a source-fix instruction. That path is not an OriginWeave changed-file finding established by source evidence. This reproduces the review-surface non-conflation problem this PR is intended to prevent.

Please treat this as a second acceptance canary, not permission to make coverage fail open. Required repair/verification: (1) recover or expose the exact isolated-sandbox failure boundary from the central run so a genuine merge-tree product defect can still be handed back precisely when one exists; (2) when coverage is unavailable/failed without independently source-backed finding evidence, retain a typed non-passing COVERAGE_BLOCKED/infrastructure-evidence state and semantic ABSTAIN/COMMENT-equivalent rather than fabricating path:line, severity, root cause, or source-fix text; (3) keep genuine test/docstring/coverage failure merge-blocking; (4) after central integration, fresh-dispatch the then-current unchanged OriginWeave #37 head and require coherent central coverage evidence plus no synthetic workflow-file source finding. If the sandbox does prove an OriginWeave defect, hand back the exact command/test/failing boundary and keep REQUEST_CHANGES source-backed.

Copy link
Copy Markdown
Contributor

Fresh third consumer canary for the same central coverage/review boundary: ContextualWisdomLab/OriginWeave#40 exact head 7c5aa8b0669c276589e412add43414c4610fbcaa.

Central OpenCode workflow run 32007986049, job 95321409303, reaches the review pipeline but fails before semantic model execution. Checkout/shared config, trusted uv, Node setup, immutable OpenCode evidence validation, orchestration-contract validation, NVIDIA SDK setup, target resolution, source fetch, and base fetch all succeeded. The first failed step is Run source repository tests with coverage; all later coverage-feedback, model-secret materialization, OpenCode CLI, review parsing/claim validation, and review-summary steps were skipped.

OriginWeave-native exact-head CI and Manifest V3 evidence for the same caller head are green. That leaf evidence does not override a failing central merge/review boundary, but it is a useful differential signal. The current connector has not exposed the inner failed-step log body, so no deeper command/test/error string is asserted here.

Acceptance for the central owner path: repair or expose the exact coverage-bootstrap failure boundary so the central path either emits valid coverage evidence or a typed fail-closed infrastructure/coverage-blocked classification; do not convert a pre-model control-plane failure into a source-code CHANGES_REQUESTED finding without independent source-backed evidence. Semantic review should run only after its prerequisite coverage evidence succeeds. After integration, rerun the then-current unchanged OriginWeave #40 head and require exact-head coverage evidence plus a non-conflated review result. No OriginWeave leaf/source workaround is appropriate for this owner defect.

Copy link
Copy Markdown
Contributor

Fresh OriginWeave owner-boundary evidence for the same coverage-blocked review-surface class:

  • Repository/PR: ContextualWisdomLab/OriginWeave#40
  • Exact source head: 8a4b4c2358f2478c7ad58ebcab595fece977ba95
  • Protected main: 0841d2ab3d8b5e60a03c0a8e818cf438e2716829
  • Native exact-head evidence is green: CI 31985283570, Production coverage job 95259128203, MV3 31985283604, SAST 31985283617, Security Scan 31985283638; current inline review threads are resolved.
  • Current formal OpenCode review on that unchanged head is nevertheless CHANGES_REQUESTED, workflow run 32007986049, because central coverage-evidence reported failure / test-docstring evidence not proven and rendered a HIGH finding at .github/workflows/opencode-review.yml:1.
  • The available review evidence does not establish an OriginWeave product-source defect at that path. Do not require branch churn or a leaf workaround merely to provoke another review.

Please treat #40 as another real acceptance case for this existing central repair lane: preserve genuine coverage failure as fail-closed, expose/recover the first isolated-sandbox causal boundary, and keep infrastructure/control-plane coverage-blocked state separate from semantic source findings. After the central repair integrates, the OriginWeave owner should fresh-dispatch/revalidate this exact or then-current head. If recovered evidence proves an OriginWeave defect, return the exact failing command/test/source boundary.

cursor Bot pushed a commit that referenced this pull request Aug 17, 2026
Fold the two buyer-visible honesty fixes from draft #1056 without merging it.

publish_fallback_diff_review still posts a COMMENT product-file review, then
restores COVERAGE_BLOCKED on the status comment so a coverage miss cannot look
finished as Gate result: COMMENT. Mermaid class diagrams now list extracted
public Rust API names only and no longer invent a FirstType --> SecondType edge.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
cursor Bot pushed a commit that referenced this pull request Aug 18, 2026
Fold the two buyer-visible honesty fixes from draft #1056 without merging it.

publish_fallback_diff_review still posts a COMMENT product-file review, then
restores COVERAGE_BLOCKED on the status comment so a coverage miss cannot look
finished as Gate result: COMMENT. Mermaid class diagrams now list extracted
public Rust API names only and no longer invent a FirstType --> SecondType edge.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>

Copy link
Copy Markdown
Contributor

Fresh OriginWeave consumer canary for the same central coverage/review boundary: ContextualWisdomLab/OriginWeave#46 is now at exact head ad5ca9316b100a33b335d017625fcefcb2cbfea6, exact protected/base tip 0841d2ab3d8b5e60a03c0a8e818cf438e2716829, ahead 10 / behind 0 with only its four intended policy/test/changelog paths. OriginWeave-native exact-head CI 32039142170, SAST 32039142230, and Security Scan 32039142156 are all terminal success.

The current formal OpenCode review on that same exact head is CHANGES_REQUESTED from central run 32045075869. Fresh job inspection proves the first failing central boundary: coverage-source-tree succeeded, and coverage-evidence job 95431121965 passed trusted OpenCode source materialization, merge-tree download/preparation, stale-agent replay guard, and changed-file syntax, then failed specifically at step 9 Measure test and docstring evidence. The downstream opencode-review job 95431381398 correctly skipped model execution and approval, then emitted the non-passing review/status. The connector still exposes no inner sandbox error for step 9, so no OriginWeave source defect is proven and none should be invented.

Please use this exact unchanged consumer head as another #1056 acceptance canary: preserve fail-closed coverage behavior, but recover/expose the exact sandbox failure when possible and avoid synthesizing a source-file/root-cause repair claim from a coverage-control-plane failure alone. If the sandbox ultimately proves an OriginWeave defect, route the exact command/test/source boundary back to the leaf; otherwise retain a typed coverage-blocked/control-plane outcome. After the central owner fix lands, only a fresh dispatch on the then-current #46 head should supersede this evidence. No OriginWeave product workaround is appropriate for this owner defect.

Copy link
Copy Markdown
Contributor

Fresh OriginWeave evidence for the central coverage/review owner: two independently native-green branches still reproduce the central coverage-evidence failure without an OriginWeave source failure.

  • OriginWeave Ignore transient governance helper cancellations #46 exact head ad5ca9316b100a33b335d017625fcefcb2cbfea6: native CI 32039142170 is success, including Rust contracts 95415232720 and exact Production coverage 95415232692; SAST 32039142230 and Security 32039142156 are success. Central OpenCode run 32045075869 failed in coverage-evidence job 95431121965 at Measure test and docstring evidence after trusted-source materialization, merge-tree preparation, stale-agent replay guard, and changed-file syntax had passed.
  • OriginWeave ⚡ Bolt: iter_json_objects JSON 파싱 성능 병목 해결 (O(N^2) 제거) #53 exact current head 18f51014550ae621ceda6f41a1097c9afee969d5, now exactly based on Ignore transient governance helper cancellations #46 head ad5ca9316b100a33b335d017625fcefcb2cbfea6: native CI 32039200984 is success, while same-head OpenCode reviews repeatedly report coverage-evidence failure in runs 32086803773, 32091804825, 32095445367, 32100338995, and 32104350562.

This recurrence across a direct-main root and its aligned child is evidence of the central coverage-evidence/review boundary, not a reason to mutate OriginWeave product code or weaken the gate. Please use these exact heads/runs as regression inputs for #1056; preserve fail-closed behavior, but make the trusted test/docstring measurement reliably recognize the repository's already-green native Rust/exact-coverage evidence path.

Copy link
Copy Markdown
Contributor

Fresh exact-head acceptance canary for the same central review/coverage boundary: ContextualWisdomLab/OriginWeave#37 is now at b686685075bfd0573fd58198776cdfca7084be35 against protected main 0841d2ab3d8b5e60a03c0a8e818cf438e2716829.

OriginWeave-native evidence is terminal on that unchanged head: CI 32105543794 succeeded; Rust contracts job 95614098615 succeeded through repository contracts, formatting, workspace check, full tests, Clippy, and API docs; Production coverage job 95614098558 succeeded through exact production function/line/region/branch enforcement; Security Scan 32105543786 succeeded; SAST Semgrep 32105543843 succeeded.

The latest formal OpenCode review is also anchored to this exact head and remains CHANGES_REQUESTED from central run 32107539057 solely because its coverage-evidence result was failure; the review again renders that control-plane failure as a HIGH finding at .github/workflows/opencode-review.yml:1 without an independently proven OriginWeave source defect. This supersedes the earlier #37 canary comment at 89b761....

Please keep the central gate fail-closed, but use this exact unchanged consumer head to verify #1056's intended non-conflation contract: a failed/unavailable coverage-evidence boundary must remain non-passing and clearly typed, without fabricating a source path/severity/root cause/fix unless source-backed evidence actually proves one. After the central owner repair lands, rerun against the then-current unchanged #37 head and require coherent same-head coverage evidence before any approval. No OriginWeave-local workaround is appropriate for this owner defect.

Copy link
Copy Markdown
Contributor

Fresh OriginWeave consumer canary for this owner lane: ContextualWisdomLab/OriginWeave#37 is unchanged at exact head b686685075bfd0573fd58198776cdfca7084be35 on protected main 0841d2ab3d8b5e60a03c0a8e818cf438e2716829. Its native CI (32105543794), owned production coverage (95614098558), Security Scan (32105543786), and SAST (32105543843) are green, and the current OriginWeave review-thread sweep returns no unresolved inline source thread. Nevertheless the current-head formal OpenCode review from run 32107539057 is CHANGES_REQUESTED solely because central coverage-evidence reports that tests/docstring evidence were not proven. This is exact-current-head evidence, not predecessor/stale review evidence. Please use this unchanged consumer head as a RED/GREEN acceptance canary for the Rust coverage-evidence repair on #1056: the central lane should consume/prove the repository’s real Rust test/coverage evidence (or emit a typed fail-closed reason for a real unsupported condition) and then permit regeneration of a formal exact-head review without requiring OriginWeave source churn. Do not treat the existing native coverage pass itself as formal approval.

Copy link
Copy Markdown
Contributor

Fresh OriginWeave consumer evidence on the same fail-closed review/coverage owner boundary: ContextualWisdomLab/OriginWeave#37 is now at exact head 097e51ef1f0a945b7ec5668fa16254222535effc, independently based on protected main 0841d2ab3d8b5e60a03c0a8e818cf438e2716829.

OriginWeave-native exact-head evidence is terminal green: CI run 32162472018 has Production coverage job 95794313050 success (including Measure production functions, lines, regions, and branches and Enforce exact production coverage), plus Rust contracts job 95794313131 success; SAST run 32162472085 and Security Scan run 32162472028 are also success on the same SHA.

The central OpenCode dispatch for this exact head is run 32167661516. Its coverage job 95821477336 fails earlier at Select trusted coverage evidence; artifact upload is cancelled. The dependent OpenCode Review job 95821458695 consequently fails, and the formal review on the unchanged OriginWeave head is CHANGES_REQUESTED. The connector still does not expose a deeper trustworthy error body for that failed selector step, so no leaf/root cause beyond that boundary is asserted.

This current canary is useful because the failure has moved from the prior isolated sandbox/test phase to the trusted-evidence-selection phase while OriginWeave-native exact-head coverage remains proven. Please keep the central path fail-closed, but repair/diagnose the selector/provenance contract so an exact-head trusted repository coverage artifact can be selected or the run emits a typed evidence-blocked state without manufacturing an OriginWeave source finding. No OriginWeave product workaround is appropriate unless the central path returns a concrete source-owned failing command/test boundary. After the central fix lands, fresh-dispatch the then-current unchanged #37 head and require coherent exact-head coverage provenance plus semantic review.

Copy link
Copy Markdown
Contributor

Fresh recurrence on the same OriginWeave acceptance canary, without OriginWeave source churn: ContextualWisdomLab/OriginWeave#37 remains at exact head 097e51ef1f0a945b7ec5668fa16254222535effc against protected main 0841d2ab3d8b5e60a03c0a8e818cf438e2716829. Native exact-head CI remains green (32162472018; Production coverage 95794313050; Rust contracts 95794313131), with SAST 32162472085 and Security Scan 32162472028 also green.

A later central OpenCode dispatch, run 32175062738, still fails its coverage-evidence job 95851639287. The step boundary is now concrete: trusted OpenCode source resolution, trusted coverage-contract materialization, merge-tree download/preparation, stale-agent replay guard, and changed-file syntax gate all succeed; step 9, Measure test and docstring evidence, fails. This differs from prior run 32167661516, whose job 95821477336 failed earlier at Select trusted coverage evidence, so the current #1056 Rust/toolchain changes have moved the failure boundary but have not yet produced usable central coverage evidence for this unchanged Rust consumer head.

Please keep this as a fail-closed owner regression input: fix or expose the exact Measure test and docstring evidence subcommand/error, preserve provenance and merge-tree semantics, and rerun against the then-current unchanged #37 head. No OriginWeave product workaround is appropriate unless the central sandbox returns a concrete source-owned failing command/test boundary.

Copy link
Copy Markdown
Contributor

Fresh exact-current OriginWeave canary after the earlier #37 evidence: ContextualWisdomLab/OriginWeave#37 is now unchanged at head 13c9dde6ad607ccf478b2b6d32afc75225f0c357 on protected/base 0841d2ab3d8b5e60a03c0a8e818cf438e2716829.

OriginWeave-native same-head runs are terminal green: CI 32203237020, SAST Semgrep 32203237053, Security Scan 32203237110; the CI includes the repository’s exact production coverage enforcement. All current inline review threads are resolved and GitHub reports the PR mergeable.

The central review boundary still reproduces independently on this exact unchanged head. Formal OpenCode CHANGES_REQUESTED reviews from runs 32204700909 and 32210529022 both say required coverage-evidence failed and render the generic control-plane condition as a HIGH finding at .github/workflows/opencode-review.yml:1 with a source-fix instruction. No independently source-backed OriginWeave product finding is identified by those reviews.

Please treat 13c9dde6... as the current acceptance canary for this owner lane: keep coverage fail-closed; expose/retain the exact failing coverage command/test boundary when available; do not synthesize a product source path/severity/root cause from a generic coverage-control failure; after the central repair is integrated, fresh-dispatch the then-current unchanged OriginWeave #37 head and require coherent same-head coverage evidence plus a non-conflated review result. This is owner routing only; no OriginWeave leaf workaround or gate weakening is appropriate.

seonghobae added a commit that referenced this pull request Aug 19, 2026
Fold the two buyer-visible honesty fixes from draft #1056 without merging it.

publish_fallback_diff_review still posts a COMMENT product-file review, then
restores COVERAGE_BLOCKED on the status comment so a coverage miss cannot look
finished as Gate result: COMMENT. Mermaid class diagrams now list extracted
public Rust API names only and no longer invent a FirstType --> SecondType edge.

Co-authored-by: Seongho Bae <seonghobae@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants