Skip to content

Reject symlinked governance metadata - #99

Merged
ifuri-validator-agent[bot] merged 4 commits into
mainfrom
ticket/076-scan-wellmanifest-standard-adoptions
Sep 20, 2026
Merged

ifuri-validator-agent[bot] merged 4 commits into
mainfrom
ticket/076-scan-wellmanifest-standard-adoptions

Conversation

@tom-sapletta-com

Copy link
Copy Markdown
Contributor

Summary

  • reject symlinked .governance/standard-adoption.json and manifest.lock.json metadata
  • add regression coverage for both metadata paths

Closes #91

Validation

  • PYTHONPATH=worktree/src /usr/bin/python3 -m pytest -p no:cacheprovider -q — 347 passed, 4 skipped
  • ./project/governance-check.sh — GOV-PASS
  • git diff --check — pass

Exact publication head: 9a432813d4e43595437dd5c8d66a0109238979dc

@ifuri-validator-agent ifuri-validator-agent Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Validator approval after policy checks for exact head ffde5fa323256fbeb63da7bd05c0a8449d475c99.

Ticket: ticket-076
Correlation ID: monag-ticket076-pr99-v3-20260920
Model: zai/glm-5.3
Reviewed diff chunks: 2
Advisory LLM verdict: APPROVE
Advisory summary: Reviewed all 2 diff chunk(s). Chunk 1 of 2 adds ticket-076 intent metadata and a new read-only governance scanner module. The scanner handles malformed JSON, non-UTF-8, symlinks, bounded traversal with depth validation (including bool rejection), and detects adoption/lock pin disagreement without claiming network freshness. All required checks (governance/enforce, governance/remote lifecycle, onedev/local-verify) pass per the protected assessment. | Chunk 2 adds a 'standards' report section wiring governance.scan into report.collect and rendering adoption/drift observations with proper escaping via presentation.cell. New tests cover malformed metadata, drift reporting, and XSS-escaping of untrusted values in the standards formatter. All required protected checks (onedev/local-verify, governance/remote lifecycle, governance/enforce) pass, consistent with test_results_data.
Advisory findings: none
The LLM output above is advisory and was not used as the approval trust root.
Semantic review prerequisite: not_required; policy 676cb4516bbfed2a000e40b9b1b6e4a430ecc761ec546aeb53d721a1905cfdd7.

Actual PR impact radar

Exact range: 03f6c5dd7da6bb66b8e76282d36013b81aec783c...ffde5fa323256fbeb63da7bd05c0a8449d475c99
Change digest: 6ee54dc907b6b73710d860d771bbaeb8838ec26fe803e9a7b188fecdddf32eea
Score: 64/100 (L), estimated 84 min, split recommended: true
Affected services/components: repository-wide/unclassified

Machine-readable radar JSONL and SVG
{"actual_change":{"additions":451,"base_sha":"03f6c5dd7da6bb66b8e76282d36013b81aec783c","binary_files":0,"categories":{"code":2,"configuration":1,"docs":2,"tests":2},"change_digest":"6ee54dc907b6b73710d860d771bbaeb8838ec26fe803e9a7b188fecdddf32eea","comparison":"03f6c5dd7da6bb66b8e76282d36013b81aec783c...ffde5fa323256fbeb63da7bd05c0a8449d475c99","deletions":2,"file_count":7,"files":["project/TICKETS.md","project/ticket-076/README.md","project/ticket-076/intent.json","src/monag/governance.py","src/monag/report.py","tests/test_governance.py","tests/test_report.py"],"head_sha":"ffde5fa323256fbeb63da7bd05c0a8449d475c99","service_count":0,"services":[]},"assessment_mode":"observed-pr","axes":{"coupling":5,"delivery":2,"scope":5,"uncertainty":3,"validation":1},"complexity":"L","confidence":0.9,"diagnostics":["RADAR-ACCEPTANCE-MISSING","RADAR-BUDGET-EXCEEDED"],"estimate":{"budget_minutes":30,"minutes":84,"within_budget":false},"impact":{"components":["governance","project","src/monag","tests","usr","worktree"],"files":["governance/standard-adoption.json","project/TICKETS.md","project/governance-check.sh","project/ticket-076/README.md","project/ticket-076/intent.json","src/monag/governance.py","src/monag/report.py","tests/test_governance.py","tests/test_report.py","usr/bin/python3","worktree/src"],"public_interfaces":[],"runtime_dependencies":0},"schema":"subactor.ticket-radar/v1","score":64,"split":{"parts":[{"estimated_minutes":13,"name":"Implement governance","scope":["governance"]},{"estimated_minutes":13,"name":"Implement project","scope":["project"]},{"estimated_minutes":13,"name":"Implement src/monag","scope":["src/monag"]},{"estimated_minutes":13,"name":"Implement tests","scope":["tests"]},{"estimated_minutes":13,"name":"Implement usr","scope":["usr"]},{"estimated_minutes":15,"name":"Validate and project to trackers","scope":["tests","planfile","github/gitlab/jira projections"]}],"reason":"estimated_minutes_exceed_budget","recommended":true},"standards":[{"id":"wellmanifest/dsl","revision":"6c60fc4e0dd1f1bb74f46a7745e28019908d1203","version":"0.1.0-dev"},{"id":"wellmanifest/ticket-lifecycle","revision":"5bf581907a87b46a13a73e6c033d3abe4d9a306f","version":"0.1.0-dev"},{"id":"wellmanifest/git-lifecycle","revision":"7d77d4b7af57e69bc75c3a0290b3a4805c5c4438","version":"0.2.0-dev"},{"id":"wellmanifest/logs","revision":"48c284ef7a069055c0bcb6b900147ce5e65f8b43","version":"0.3.0"}],"ticket_ref":"ticket-076"}
<svg xmlns="http://www.w3.org/2000/svg" width="128" height="128" viewBox="0 0 128 128" role="img"><title>ticket-076: Reject symlinked governance metadata</title><rect width="128" height="128" rx="12" fill="#f8fafc"/><g stroke-width="1"><polygon points="64,55 72,61 69,71 59,71 56,61" fill="none" stroke="#d7dde5"/><polygon points="64,47 80,59 74,78 54,78 48,59" fill="none" stroke="#d7dde5"/><polygon points="64,38 89,56 79,85 49,85 39,56" fill="none" stroke="#d7dde5"/><polygon points="64,30 97,53 84,92 44,92 31,53" fill="none" stroke="#d7dde5"/><polygon points="64,21 105,51 89,99 39,99 23,51" fill="none" stroke="#d7dde5"/><line x1="64" y1="64" x2="64" y2="21" stroke="#aab4c0"/><line x1="64" y1="64" x2="105" y2="51" stroke="#aab4c0"/><line x1="64" y1="64" x2="89" y2="99" stroke="#aab4c0"/><line x1="64" y1="64" x2="39" y2="99" stroke="#aab4c0"/><line x1="64" y1="64" x2="23" y2="51" stroke="#aab4c0"/></g><polygon points="64,21 105,51 79,85 59,71 48,59" fill="#fb923c" fill-opacity="0.45" stroke="#c2410c" stroke-width="2"/><circle cx="64" cy="64" r="3" fill="#c2410c"/><g font-family="sans-serif" font-size="7" fill="#334155"><text x="64" y="11" text-anchor="middle">SCO</text><text x="114" y="48" text-anchor="middle">COU</text><text x="95" y="107" text-anchor="middle">UNC</text><text x="33" y="107" text-anchor="middle">VAL</text><text x="14" y="48" text-anchor="middle">DEL</text></g><text x="64" y="124" text-anchor="middle" font-family="sans-serif" font-size="8" fill="#0f172a">L · 84m</text></svg>
Merge will be attempted after this approval when explicitly authorized. ## Decision record (recomputable)
DECISION D-076-2704
TICKET ticket-076
HEAD_SHA ffde5fa323256fbeb63da7bd05c0a8449d475c99
CORRELATION_ID monag-ticket076-pr99-v3-20260920
ACTOR agent:ifuri-validator-agent[bot]
APPLIED_RULE P-CORE-015
INPUT author_login = "tom-sapletta-com"
INPUT observed_checks = ["governance / remote lifecycle=PASS","governance / enforce=PASS","onedev/local-verify=PASS"]
INPUT required_checks = ["onedev/local-verify","governance / remote lifecycle","governance / enforce"]
INPUT required_checks_source = "protected registry (env/request)"
INPUT reviewer_login = "ifuri-validator-agent[bot]"
INPUT semantic_review_assessment = {"schema":"subactor.validator/semantic-review-assessment/v1","subject":{"repository":"semcod/monag","pull_request":99,"head_sha":"ffde5fa323256fbeb63da7bd05c0a8449d475c99","base_sha":"03f6c5dd7da6bb66b8e76282d36013b81aec783c","diff_sha256":"f2bb790ed781a729c2732ff9ac4fdaa573a07700aeff66ef480d88e57ba2434f"},"policy":{"policy_schema":"subactor.validator/semantic-review-policy/v1","policy_version":1,"policy_sha256":"676cb4516bbfed2a000e40b9b1b6e4a430ecc761ec546aeb53d721a1905cfdd7","required":false,"critical_paths":[],"observed_paths":["project/TICKETS.md","project/ticket-076/README.md","project/ticket-076/intent.json","src/monag/governance.py","src/monag/report.py","tests/test_governance.py","tests/test_report.py"]},"grounding":"full-diff-not-per-finding-proof","execution_authority":false,"status":"not_required","reason":null,"review_sha256":null,"unresolved":[]}
INPUT superseded_checks = []
INPUT ticket_radar_receipt = {"schema":"subactor.ticket-radar/v1","base_sha":"03f6c5dd7da6bb66b8e76282d36013b81aec783c","head_sha":"ffde5fa323256fbeb63da7bd05c0a8449d475c99","change_digest":"6ee54dc907b6b73710d860d771bbaeb8838ec26fe803e9a7b188fecdddf32eea","score":64,"complexity":"L","estimated_minutes":84,"split_recommended":true,"services":[],"authority":"ADVISORY","promotion":"FORBIDDEN"}
VERDICT APPROVE AUTHORITY DETERMINISTIC
REJECTED REQUEST_CHANGES BECAUSE NO_UNSAFE_CHANGE_REASON_FOUND
ADVISORY llm_verdict = "APPROVE" MODEL "zai/glm-5.3"
ASSERT VERDICT_AUTHORITY != "ADVISORY"

@ifuri-validator-agent
ifuri-validator-agent Bot merged commit e67a6cb into main Sep 20, 2026
3 checks passed
@ifuri-validator-agent
ifuri-validator-agent Bot deleted the ticket/076-scan-wellmanifest-standard-adoptions branch September 20, 2026 08:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

feat: Include Wellmanifest standard adoption and governance audit in workspace reports

1 participant