feat(opencode): separate semantic and merge decisions - #836
Conversation
|
Important Review skippedDraft detected. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
|
@opencode-agent @cwl-noema-review Review-only request for exact stacked head Inspect the complete 10-file diff, the corrected RED→GREEN lineage, semantic-versus-merge decision matrix, coverage-failure non-conflation invariant, hard-blocked versus unknown evidence classification, exact-head binding, strict JSON and scalar boundaries, duplicate rejection, path-free infrastructure blockers, deterministic receipts, atomic output, exact-head CI, APA 7th doctoring, rollback, and the explicit production-dispatch writer boundary. Do not modify the branch; update or retarget the base; synthesize source findings from infrastructure state; approve on behalf of an author; merge; release; weaken tests; alter reviewer credentials, model policy, provider secrets, or branch protection; edit |
Purpose
Implement the test-first, production-independent part of Task 5 in the OpenCode review-quality plan: a versioned decision envelope that keeps semantic source review separate from merge readiness.
Exact stacked identity
feat/opencode-review-gold-corpus(PR feat(opencode): add head-matched gold corpus tooling #831);2d3100b27d1d979e6e2f3ead2fc278b08a840b44;feat/opencode-review-decision-envelope;48a609d177b2fcd5d8a261570bc845ad5abb1af3;c3133887df775605bfca2aaaa8b94094aec609fc;No check, review, approval, or comment from PR #829 or #831 authorizes this stacked head. If either predecessor moves or integrates, this branch must be reconciled once onto the resulting exact protected base and every exact-head evidence surface regenerated.
Test-first lineage
The first branch run exposed a test-support import-path defect rather than the intended product gap, so it is not counted as the authoritative RED. The test harness was corrected without adding production behavior.
Run
31259792839then checked out exact test-only head48a609d177b2fcd5d8a261570bc845ad5abb1af3and failed during collection becausescripts/ci/opencode_review_decision.pydid not exist. That is the valid RED evidence for the permanent contract.Production implementation, strict validation, additional branch-coverage regressions, doctoring, and changelog traceability were added without deleting, skipping, weakening, or converting any permanent test into an expected failure.
Implemented decision contract
Semantic channel
complete,unavailable, andfailedsemantic states;APPROVE,COMMENT,REQUEST_CHANGES, andABSTAIN;Merge-readiness channel
READY,BLOCKED, andUNKNOWN;Non-conflation invariant
A coverage or check failure may block merge readiness but cannot create a source finding, severity, path, line, trigger, root cause, or code-fix instruction. A valid semantic finding remains present even when infrastructure evidence independently fails.
The Markdown renderer physically separates
Semantic findingsfromInfrastructure and policy blockers; only semantic findings may renderpath:line.Evidence integrity
Exact-current-head verification
OpenCode Review Decision Quality CI run
31260754829checked out exact headc3133887df775605bfca2aaaa8b94094aec609fcwith persisted credentials disabled and completed successfully:29 passed;232/232;76/76;100%;opencode_review_decision.py: 81 statements, 30 branches, 100%;The exact regression for the observed failure mode proves that a complete defect-free semantic review plus failed coverage yields
review_verdict=APPROVE,merge_readiness=BLOCKED, no source finding, and one path-free coverage blocker.docs/doctoring/opencode-review-decision-envelope.mdrecords the decision matrix, exact-head contract, strict evidence boundary, security/privacy constraints, later dispatch integration sequence, monitoring, rollback, limitations, and APA 7th references to GitHub protection/check semantics, NIST SSDF 1.1 and 800-218A, SLSA 1.2, and empirical code-review research.CHANGELOG.mdrecords the bounded capability.Production writer boundary
This PR deliberately does not edit
.github/workflows/opencode-review-dispatch.yml. Active central branches #789, #812, #816, and #827 modify that workflow. Editing it here would violate the repository-writer lease and risk discarding unrelated exact-head repairs.Dispatch integration remains a later protected slice after writer clearance. It must begin with a fresh failing production contract requiring the dispatch to continue bounded semantic review when safe source evidence exists, publish source comments only from validated semantic findings, and route coverage/check/approval/protection failures exclusively through the merge-readiness channel.
Safety and acceptance
COPILOT_GITHUB_TOKENuse;Keep Draft and do not merge until PR #829 and #831 integrate, this branch is reconciled onto the exact protected base, the complete organization quality/security/review suite reruns on the resulting exact head, no valid unresolved finding remains, and a qualifying independent non-author formal approval exists. Pending, queued, skipped-required, status-only, author-only, stale-head, predecessor-head, synthetic-merge, rate-limited, or absent evidence is not acceptance.