feat(http): rebuild bounded HTTP/1.1 authority on current main - #37
feat(http): rebuild bounded HTTP/1.1 authority on current main#37seonghobae wants to merge 128 commits into
Conversation
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
📝 WalkthroughWalkthroughChangesBounded HTTP/1.1 교환
Estimated code review effort: 5 (Critical) | ~120 minutes Possibly related PRs
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Pull request overview
OpenCode cannot approve yet because required coverage evidence did not pass.
Review outcome
1. HIGH .github/workflows/opencode-review.yml:1 - Coverage evidence did not prove required test/docstring evidence
-
Problem: The required coverage-evidence job result was
failure, so OpenCode cannot establish approval sufficiency for this head. -
Root cause: Automated approval is only valid when the same-head coverage-evidence job proves supported repository test suites passed and configured docstring gates passed or were advisory, or reports not applicable because no supported source files or package manifests exist. Missing, failed, skipped, unavailable, or unsupported-tooling test evidence is a blocker.
-
Fix: Install or configure the repository test/docstring evidence tooling when source files or package manifests exist, rerun the current-head coverage-evidence job, and approve only after it reports
successwith required evidence or explicit no-source not-applicable evidence. -
Regression test: Keep the approval branch checking
needs.coverage-evidence.result == successbefore posting APPROVE, and publish REQUEST_CHANGES when coverage-evidence blocker states such as cancelled, skipped, failed, unsupported-tooling, or below-100 evidence are present. -
Result: REQUEST_CHANGES
-
Reason: coverage-evidence result was
failure, so required test/docstring evidence was not proven for current head89b761031e24f5202958aa6785763ad0bbac751e. -
Head SHA:
89b761031e24f5202958aa6785763ad0bbac751e -
Workflow run: 32003668784
-
Workflow attempt: 1
Coverage evidence
Coverage Decision
- Result: FAIL
- Test evidence: not proven passing
- Docstring evidence: not proven passing when configured
- Failure count: 1
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow: ci.yml"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow: ci.yml"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Changed file (42 files)"]
S2 --> I2["repository behavior"]
I2 --> R2["Review risk: Changed file (42 files)"]
R2 --> V2["required checks"]
Evidence --> S3["Docs (10 files)"]
S3 --> I3["operator or user guidance"]
I3 --> R3["Review risk: Docs (10 files)"]
R3 --> V3["docs review"]
Evidence --> S4["Test (3 files)"]
S4 --> I4["regression suite"]
I4 --> R4["Review risk: Test (3 files)"]
R4 --> V4["targeted test run"]
There was a problem hiding this comment.
Pull request overview
OpenCode cannot approve yet because required coverage evidence did not pass.
Review outcome
1. HIGH .github/workflows/opencode-review.yml:1 - Coverage evidence did not prove required test/docstring evidence
-
Problem: The required coverage-evidence job result was
failure, so OpenCode cannot establish approval sufficiency for this head. -
Root cause: Automated approval is only valid when the same-head coverage-evidence job proves supported repository test suites passed and configured docstring gates passed or were advisory, or reports not applicable because no supported source files or package manifests exist. Missing, failed, skipped, unavailable, or unsupported-tooling test evidence is a blocker.
-
Fix: Install or configure the repository test/docstring evidence tooling when source files or package manifests exist, rerun the current-head coverage-evidence job, and approve only after it reports
successwith required evidence or explicit no-source not-applicable evidence. -
Regression test: Keep the approval branch checking
needs.coverage-evidence.result == successbefore posting APPROVE, and publish REQUEST_CHANGES when coverage-evidence blocker states such as cancelled, skipped, failed, unsupported-tooling, or below-100 evidence are present. -
Result: REQUEST_CHANGES
-
Reason: coverage-evidence result was
failure, so required test/docstring evidence was not proven for current headb686685075bfd0573fd58198776cdfca7084be35. -
Head SHA:
b686685075bfd0573fd58198776cdfca7084be35 -
Workflow run: 32107539057
-
Workflow attempt: 1
Coverage evidence
Coverage Decision
- Result: FAIL
- Test evidence: not proven passing
- Docstring evidence: not proven passing when configured
- Failure count: 1
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow: ci.yml"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow: ci.yml"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Changed file (42 files)"]
S2 --> I2["repository behavior"]
I2 --> R2["Review risk: Changed file (42 files)"]
R2 --> V2["required checks"]
Evidence --> S3["Docs (10 files)"]
S3 --> I3["operator or user guidance"]
I3 --> R3["Review risk: Docs (10 files)"]
R3 --> V3["docs review"]
Evidence --> S4["Test (3 files)"]
S4 --> I4["regression suite"]
I4 --> R4["Review risk: Test (3 files)"]
R4 --> V4["targeted test run"]
|
Fresh exact-head review requested for |
There was a problem hiding this comment.
Pull request overview
OpenCode cannot approve yet because required coverage evidence did not pass.
Review outcome
1. HIGH .github/workflows/opencode-review.yml:1 - Coverage evidence did not prove required test/docstring evidence
-
Problem: The required coverage-evidence job result was
failure, so OpenCode cannot establish approval sufficiency for this head. -
Root cause: Automated approval is only valid when the same-head coverage-evidence job proves supported repository test suites passed and configured docstring gates passed or were advisory, or reports not applicable because no supported source files or package manifests exist. Missing, failed, skipped, unavailable, or unsupported-tooling test evidence is a blocker.
-
Fix: Install or configure the repository test/docstring evidence tooling when source files or package manifests exist, rerun the current-head coverage-evidence job, and approve only after it reports
successwith required evidence or explicit no-source not-applicable evidence. -
Regression test: Keep the approval branch checking
needs.coverage-evidence.result == successbefore posting APPROVE, and publish REQUEST_CHANGES when coverage-evidence blocker states such as cancelled, skipped, failed, unsupported-tooling, or below-100 evidence are present. -
Result: REQUEST_CHANGES
-
Reason: coverage-evidence result was
failure, so required test/docstring evidence was not proven for current headc95542a3d6799c55850fcbdd70ed56bd668ed783. -
Head SHA:
c95542a3d6799c55850fcbdd70ed56bd668ed783 -
Workflow run: 32132748096
-
Workflow attempt: 1
Coverage evidence
Coverage Decision
- Result: FAIL
- Test evidence: not proven passing
- Docstring evidence: not proven passing when configured
- Failure count: 1
Changed-File Evidence Map
flowchart LR
PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
Evidence --> S1["Workflow: ci.yml"]
S1 --> I1["GitHub Actions review job"]
I1 --> R1["Review risk: Workflow: ci.yml"]
R1 --> V1["actionlint plus required checks"]
Evidence --> S2["Changed file (44 files)"]
S2 --> I2["repository behavior"]
I2 --> R2["Review risk: Changed file (44 files)"]
R2 --> V2["required checks"]
Evidence --> S3["Docs (10 files)"]
S3 --> I3["operator or user guidance"]
I3 --> R3["Review risk: Docs (10 files)"]
R3 --> V3["docs review"]
Evidence --> S4["Test (3 files)"]
S4 --> I4["regression suite"]
I4 --> R4["Review risk: Test (3 files)"]
R4 --> V4["targeted test run"]
Purpose
Canonical non-destructive reconstruction of issue #9 / historical PR #11: one bounded reusable
originweave-httpHTTP/1.1 authority over an existing authenticated TLS stream, with strict framing, resource budgets, integrity/MIME/disposition evidence, realistic loopback tests, ADRs, and current repository quality contracts.Implemented boundary
The branch supports one bounded HTTP/1.1
GETorHEADexchange overAuthenticatedTlsConnection; it performs no DNS, reconnect, proxy/PAC, browser control, cookie persistence, file persistence, or model call. It enforces RFC 9110/9112 framing, bounded headers/body/chunks/trailers/interim responses/decoding/deadline, gzip/zlib decoding, RFC 9530 digest validation, conservative MIME/no-sniff/disposition handling, redirect evidence without automatic follow, and credential-safe immutable evidence.Historical custom coverage-verifier machinery was intentionally not replayed because protected main owns the current exact-coverage pipeline. Historical HTTP ADRs were reconstructed as 0011/0012 on this lineage.
Current exact state
Protected main is
0841d2ab3d8b5e60a03c0a8e818cf438e2716829. Current exact contributor head is097e51ef1f0a945b7ec5668fa16254222535effc. GitHub reports the PR open, Ready, and mergeable.The latest repair removed a duplicated MIME-classification facade and restored one canonical classifier boundary. The canonical HTML signature test now follows the current WHATWG MIME Sniffing table: every listed HTML signature is recognized only when its next byte is ASCII space (
0x20) or>(0x3e). Prefixes such as<htmlx>,<scriptx>,<article>via the short<asignature, and signatures followed by HT/LF/FF/CR therefore remain plain text rather than being promoted totext/html. The repair also removed the stalemime_checked.rssource that violated the repository's expected HTTP source inventory.Test-first lineage for the latest repair
e20de068e47e0c04bfd357c830255624c2850d86had two verified defects: repository governance rejected the unregisteredmime_checked.rssource, and the MIME facade/raw classifier duplicated incompatible HTML-signature termination rules.2a47bdee4326db85ef7fccf5d44609bbb4b60816addedmime_tag_termination_contract.rs, covering all 17 classifier signatures, valid SP/>termination, invalid no-next/x/HT/LF/FF/CR next bytes, and a BOM+whitespace<htmlx>false-positive regression. CI run32161410185reached the intended classifier boundary with two RED failures while repository governance still rejectedmime_checked.rs.94849f6d7ac181e2f306f044dfe0909a5a36d9f9restored directmod mime, deletedmime_checked.rs, and enforced the terminator rule in the canonicallooks_like_htmlimplementation.2ac59cb4222be01137452b95c903a38217aecdf3made the new test canonical-rustfmt clean. Its exact CI then exposed only one strict-Clippy style defect (byte-char-slices) in the new regression test.097e51ef1f0a945b7ec5668fa16254222535effcapplies the narrow Clippy repair using*b" >"without changing the classifier contract.No predecessor-head check, review, or status transfers to this head.
Exact-current native evidence
On unchanged exact head
097e51ef1f0a945b7ec5668fa16254222535effc:32162472018: success;95794313131: repository contracts, canonical formatting, workspace/all-target checks, full tests, strict Clippy, and API documentation success;95794313050: exact owned-production function/line/region/branch measurement and enforcement success;Security Scanrun32162472028andSAST Semgreprun32162472085are currently queued on this exact head. Queued evidence is non-passing and is not represented as success. The branch must remain unchanged while those transient lanes execute unless an exact-current failure identifies an OriginWeave-owned defect.Current formal-review state
The latest returned formal OpenCode
CHANGES_REQUESTEDreviews are anchored to predecessor heads, includingc95542a3d6799c55850fcbdd70ed56bd668ed783, not current head097e51ef1f0a945b7ec5668fa16254222535effc. They are therefore stale evidence for this head. Their reported cause was the read-only central.githubcoverage-evidence path, already tracked in the existing owner laneContextualWisdomLab/.github#1056, not a proven current OriginWeave source failure.A current-head qualifying independent approval/latest-push approval must still come through live organization governance. Passing CI, coverage, scanners, model reviews, comments, or author activity are not approval.
Governance / integration boundary
Protected-main
AGENTS.mdprohibits this scheduled writer from merging, self-approving, tagging, publishing, altering workflows, adding secrets, or weakening checks. Issue #9 remains open until the canonical replacement is integrated through an authorized path and protected-main acceptance is freshly re-established. Historical PR #11 remains lineage-only until its unique valuable delta is proven preserved, integrated, or explicitly rejected.