Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
99 changes: 98 additions & 1 deletion PLANS.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,4 +4,101 @@ Use this file for active or blocked repository work. Update it before implementa

## Active Work

No active or blocked repository work.
### Deliver protected-target policy and bounded MR intent in v0.6.1

- **Status:** active
- **Release classification:** `release-required`
- **Target stable version:** `0.6.1`
- **Tracking:** #87, #88, #89, #90
- **Objective:** keep the forge-defined review range unchanged while sourcing policy from the current protected target, retain changed template evidence under existing limits, expose bounded untrusted merge-request intent, add top-level version reporting, qualify OCR 1.9.4 with its telemetry/backlog impact, add public scanner badges, then publish and independently verify stable v0.6.1.

#### Boundaries and decisions

- GitLab provider acquisition owns one bounded point-in-time MR snapshot. Protected target branch/SHA selection and author-controlled intent are separate trust projections; only the former may select policy.
- Evidence schema v4 adds a distinct immutable policy snapshot/ref while preserving v1-v3 readback. Policy applicability continues to use paths changed by the original diff-base-to-head range.
- Repository-owned OCR `--rule` content is never generated, parsed, or merged. The exact blob at the captured policy SHA is materialized privately and replaces only an in-repository rule argument; explicit external operator-owned rule paths remain untouched.
- Template plugins receive one immutable bounded changed-path set and prioritize changed template objects without increasing the per-ref or shared per-kind budgets.
- MR title, description, labels, and optional source-branch hint are invocation-trust data, never policy. Raw provider text stays out of bootstrap, argv, environment, logs, and receipts; admitted intent blocks automatic approval but not comment publication.
- The external-reference attack path is documented without implementing reference extraction, content prefetch, generic URL access, provider-specific MCP adapters, or external writes. Existing configured read-only allowlisted MCP tools remain the only retrieval route.
- Runtime remains standard-library-only; fixtures and public examples remain synthetic and private-safe.
- After OCR 1.9.4 qualification, map every #87-#90 acceptance criterion and every touched boundary to production-path evidence. A test double may replace an external collaborator only beyond the claimed boundary; it cannot replace the production owner being verified. Wiring-only tests remain unit evidence and must be paired with real Git, local HTTP, private artifact, hostile store reload, stdio MCP, installed wheel/sdist, subprocess, and actual OCR-consumer paths where those contracts are claimed.

#### Delivery checklist

1. [x] Verify synchronized clean `main`, open issues #87-#89, stable v0.6.0 receipts, current OCR 1.9.3, and no newer stable OCR release.
2. [x] Activate the v0.6.1 plan and mark M4 Established from independently verified v0.6.0 delivery.
3. [x] Open and maintain early Draft PR #91 after the first signed planning commit; avoid further pushes until the local feature is ready.
4. [x] Prioritize changed template evidence and add installed-artifact coverage.
5. [x] Add centralized `ocr-ci --version` source/wheel/sdist coverage.
6. [x] Add policy ref/schema v4, protected GitLab target acquisition, bounded object fetch, exact policy rules transport, and compatibility/failure tests.
7. [x] Add bounded MR intent, hostile readback, toolkit-authored trust guidance, receipt-v2 approval blocker, and external-MCP attack-path coverage.
8. [x] Add verified README security badges, public contracts, Towncrier fragments, and integration tests.
9. [x] Run focused gates for each commit, complete Python 3.12-3.14 quality/security/package validation, deterministic double builds, installed wheel/sdist tests, and Gitleaks.
10. [x] After completing #87-#89 and before the README/documentation pass, qualify OCR 1.9.4 through #90, analyze telemetry and backlog impact, update the local binary and compatibility contract, and use 1.9.4 thereafter; include any newer intervening stable release if one appears.
11. [x] Audit every #87-#90 acceptance criterion and touched boundary first, then audit the complete test suite: record each claimed production owner and test entry point, permit doubles only beyond that owner, and replace mock-selected success/rejection with real Git, local HTTP, persistence, MCP, installed-artifact, subprocess, and OCR-consumer paths before relying on integration coverage. The matrix covers all 38 test modules; no fake LLM is accepted as model-dependent #89 evidence.
12. [x] Run the single completed local OCR review over the exact feature range, audit its saved MCP transcript, remediate all four findings and the bootstrap-size warning, then repeat deterministic validation, requirement-to-evidence review, self-review, and architecture review without a second OCR run. The actual OCR/model path did not qualify #89 intent calibration: all 70 attempted evidence calls used `action=summary`, materialized incompatible union-schema arguments, and failed before reading MR context. Production transport/queryability is corrected and proven through real installed stdio paths; matching/contradictory/unknown model semantics remain an explicit non-claim rather than mock-selected evidence.
13. [ ] Push the complete feature history, pass required checks, merge the protected feature PR, and independently verify the resulting TestPyPI development artifacts.
14. [ ] Prepare and merge exact `Release v0.6.1`, then independently verify TestPyPI/PyPI bytes, provenance/attestations, supported-Python installs, annotated tag, immutable GitHub Release, and receipt.
15. [ ] Confirm only Actions-owned release receipts close #87-#90 and synchronize a clean local `main`.

#### Pre-OCR validation receipt

- The complete quality gate and independent Homebrew Python 3.12.14, 3.13.15,
and 3.14.7 matrices each pass 806 tests plus 102 subtests with at least 81%
coverage. Ruff formatting/lint, mypy, Bandit, dependency audit, compatibility
manifest validation, Towncrier rendering, `git diff --check`, and pinned
full-feature-history Gitleaks pass.
- Checksum-verified local OCR 1.9.4 passes version, help, JSON preview/result,
additive comment, manifest, and real protected-target rule-selection probes;
bounded discovery reports no unseen stable OCR release before the final review.
- Two source-epoch-controlled `0.6.1.dev0` builds are byte-identical and pass
Twine plus closed archive-content checks. The wheel SHA-256 is
`a14c4e6807dbbf9b1be67bf1a4fb82a94d37f2bb4528b738ebc3bcae646791c0` and
the sdist SHA-256 is
`aa6b99427c353d2a10614048ee617bf64fde03495b22b22d3b2adb32a76031d3`.
Real installed wheel and sdist-to-wheel policy/MR-context/stdin-MCP E2E passes,
as do clean restricted-path wheel installs on Python 3.12/3.13 and the sdist
on Python 3.14 with exact centralized `ocr-ci --version` output.

#### Final OCR and remediation receipt

- The one permitted OCR 1.9.4 review completed 26/26 items over immutable
`0b40c2e5400421d4d8be8697e81cf810d9cf826c..fcf90b116757e1af9d596488bb13ed2ad4e9d2db`,
reported four findings, and retained automatic-approval ineligibility. Its
result SHA-256 is
`3a00c19e833acbddb67f6a0cab0c6a67e45e9b70bbbf1c0451e84c77575cbe`.
- Remediation closes impossible persisted label status, legacy schema-v2
reserialization, malformed MCP-use approval receipts, and inactive-MR
provider acquisition. Sibling review also bounds composed retained plus
declared MCP servers and accepts the exact 16-external-plus-built-in receipt.
- The 2,372-character background warning came from duplicated coverage, MR
trust, and MCP guidance, not provider text. The default bootstrap budget is
now 2,000 characters; mandatory refs/MR/MCP guidance precedes variable
inventory sections. The final-review store renders 1,643 characters and the
dense installed-artifact fixture renders 1,974, both without truncation.
- Saved-session inspection found zero successful evidence calls: OCR 1.9.4
materialized every optional union-schema property and selected `summary` for
all 70 calls. The dispatcher now ignores declared inactive fields while still
rejecting unknown names, and direct wheel plus sdist-derived wheel stdio E2E
proves summary/list/get and raw synthetic MR-context retrieval. Because no
second OCR is allowed, this does not qualify model-dependent intent judgment.
- Post-remediation Python 3.12.14, 3.13.15, and 3.14.7 quality matrices each
pass 810 tests plus 105 subtests at 81.21% coverage. Ruff, mypy, Bandit,
pip-audit, Gitleaks, Towncrier, compatibility validation, and bounded stable
OCR discovery pass. Deterministic `0.6.1.dev0` rebuilds are byte-identical;
the remediated wheel SHA-256 is
`e20cc79b3c9aa41e16d425d80a1b2264ae89ba60b1b55bf713160d985379bc43`
and the sdist SHA-256 is
`574668fbfb4f0a422a6ad1610c4a817b27c118995eb197e041d1384afdd50614`.
Twine, closed archive-content checks, and direct wheel plus sdist-derived
installed MCP E2E pass.
- The first exact-head hosted run exposed two test-fixture defects rather than
runtime failures: a shallow clone relied on the bare remote's host-dependent
default branch, and the local TLS peer did not set an explicit protocol floor.
The real-Git fixture now selects `main` explicitly and the real HTTPS peer
requires TLS 1.2 or newer; item 13 remains open pending exact corrected-head
hosted readback.

#### Commit discipline

Before every logical commit: update status-bearing text to post-commit truth, run focused validation, inspect the complete staged diff, run `git diff --check`, and perform self-review plus architecture review for ownership, dependency direction, bounds, trust transitions, hostile readback, and unnecessary abstraction. Fix findings before signing the commit.
2 changes: 2 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,8 @@
# Open Code Review Toolkit

[![OpenSSF Best Practices](https://www.bestpractices.dev/projects/13906/badge)](https://www.bestpractices.dev/projects/13906)
[![OpenSSF Scorecard](https://api.securityscorecards.dev/projects/github.com/xeonvs/open-code-review-toolkit/badge)](https://securityscorecards.dev/viewer/?uri=github.com/xeonvs/open-code-review-toolkit)
[![CodeQL](https://github.com/xeonvs/open-code-review-toolkit/actions/workflows/codeql.yml/badge.svg?branch=main)](https://github.com/xeonvs/open-code-review-toolkit/actions/workflows/codeql.yml)

Open Code Review Toolkit is an unofficial GitLab CI integration layer for [Alibaba Open Code Review](https://github.com/alibaba/open-code-review). It provides bounded repository evidence, a compact review bootstrap, a built-in read-only MCP server, environment-driven OCR configuration, preflight validation, and safe GitLab merge-request posting. It does **not** bundle or download the `ocr` binary.

Expand Down
10 changes: 5 additions & 5 deletions ROADMAP.md
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ flowchart LR
M0["M0 Foundation<br/>established"] --> M1["M1 Evidence architecture<br/>established"]
M0 --> M3["M3 External MCP hardening<br/>next / planned"]
M1 --> M2["M2 Ecosystem and framework coverage<br/>established"]
M1 --> M4["M4 Policy and project guidance<br/>in progress"]
M1 --> M4["M4 Policy and project guidance<br/>established"]
M1 --> M5["M5 Measurement audit and profiles<br/>planned"]
M1 --> M6["M6 Later and conditional work<br/>conditional"]

Expand All @@ -19,8 +19,8 @@ flowchart LR
classDef planned fill:#57606a,stroke:#424a53,color:#ffffff
classDef conditional fill:#9a6700,stroke:#7d4e00,color:#ffffff

class M0,M1,M2 established
class M3,M4 next
class M0,M1,M2,M4 established
class M3 next
class M5 planned
class M6 conditional
```
Expand All @@ -31,7 +31,7 @@ flowchart LR
| M1 Evidence architecture | Established | One bounded evidence model supplies a compact bootstrap and built-in read-only MCP. | Machine-readable OCR capabilities and current context contracts. | Stable v0.4.0 publishes the model, immutable snapshots, typed deltas, bounded private storage, compact bootstrap, built-in MCP, semantic parity/removal, verified real-OCR use, reporting outcomes, and security hardening; TestPyPI/PyPI artifacts, provenance, hashes, annotated tag, immutable GitHub Release, and supported-Python smoke installs are independently verified. |
| M2 Ecosystem and framework coverage | Established | Supply framework and template evidence selected from demonstrated use without creating framework-specific review engines. | Established evidence, snapshot/delta, scoped-completeness, and built-in MCP contracts. | Selected static plugins and template review rules have deterministic fixtures, bounds, provenance, component ownership, completeness, first-class source/target delta queries, installed-artifact validation, verified use through the existing built-in MCP, and independently read-back stable delivery. |
| M3 External MCP hardening | Next / planned | Threat-model external references and validate provider-specific read-only examples on the established built-in/external MCP composition boundary. | Existing external MCP and built-in composition for current generic operation; BL-011 before reference detection or provider examples. | Threat model precedes reference detection and provider examples; synthetic YouTrack, Confluence, or documentation examples preserve narrow read-only tools, reserved namespaces, and trust separation. Managed OAuth remains conditional on a named provider requirement. |
| M4 Policy and project guidance | In progress | Supply relevant target-branch decisions and guidance without allowing self-whitelisting. | Evidence scoping and target/source snapshots. | Stable delivery independently proves backward-compatible structured decisions, bounded target-derived guidance, one read-only MCP lifecycle, and closure of the tracked release work. |
| M4 Policy and project guidance | Established | Supply relevant target-branch decisions and guidance without allowing self-whitelisting. | Evidence scoping and target/source snapshots. | Stable delivery independently proves backward-compatible structured decisions, bounded target-derived guidance, one read-only MCP lifecycle, and closure of the tracked release work. |
| M5 Profiles and quality measurement | Planned | Audit current OCR telemetry and result-derived review signals before adding profiles or any toolkit metrics. | Established result, discussion, coverage, posting, and MCP-use receipts; the owner-approved matrix is required only for profile implementation. | The audit either proves current bounded reporting sufficient or isolates a separately scoped provider-neutral gap; any later profiles are deterministic and documented without sensitive, high-cardinality, or duplicate data. |
| M6 Later and conditional work | Conditional | Activate routing, more ecosystems, fuzzing, configuration, forge adapters, or governance work only from demonstrated need. | Milestone-specific activation signals and stable preceding contracts. | Each item meets its own trigger and ships as a coherent validated slice without weakening core invariants. |

Expand All @@ -40,7 +40,7 @@ flowchart LR
- OCR compatibility and the established common evidence model now converge at compact-bootstrap/evidence-MCP integration.
- M3 threat modeling can proceed from the established generic composition boundary; provider examples wait for BL-011, while managed OAuth does not block static-header or stdio operation.
- M2 is established through independently verified stable delivery of its framework plugins, template rules, scoped evidence, deltas, and built-in MCP projection. Conditional future ecosystem packs remain in M6 and do not reopen M2; M4 can proceed independently from the stable evidence contracts it consumes.
- M4 implementation, protected feature merge, development publication, security review, and local OCR remediation are complete in the 0.6.0 lifecycle; it remains in progress until stable artifacts and tracking closure are independently read back.
- M4 is established through independently verified v0.6.0 artifacts, provenance, hashes, annotated tag, immutable GitHub Release, supported-Python installs, and release-receipt closure. Later target-policy identity improvements extend the established boundary without reopening the milestone.
- The M5 measurement-gap audit can begin from current lifecycle and result receipts; BL-016 is required only for later named-profile comparisons.
- Versioned documentation remains a separate MCP integration: the toolkit supplies package/version evidence but does not store documentation.
- Additional code-hosting adapters are not ecosystem collectors. They remain conditional because the near-term product is GitLab-first.
Expand Down
1 change: 1 addition & 0 deletions changelog.d/87.bugfix.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
Use the current protected GitLab target commit for repository-owned OCR rules, accepted decisions, and project guidance without changing the forge-defined review range.
1 change: 1 addition & 0 deletions changelog.d/88.bugfix.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
Prioritize changed templates on both immutable review refs before unchanged inventory, preserving typed template evidence under the existing bounded fact limits.
1 change: 1 addition & 0 deletions changelog.d/88.feature.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
Add top-level `ocr-ci --version` reporting from the installed package version metadata.
1 change: 1 addition & 0 deletions changelog.d/89.feature.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
Expose bounded redacted merge-request title, description, labels, and source-branch context as untrusted invocation evidence while blocking automatic approval for runs that admit mutable author-controlled intent.
1 change: 1 addition & 0 deletions changelog.d/90.feature.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
Target checksum-verified Open Code Review 1.9.4 after human qualification of its unchanged JSON result contract and terminal-only session correlation output.
1 change: 1 addition & 0 deletions changelog.d/91.doc.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
Add repository-specific OpenSSF Scorecard and CodeQL status badges to the README.
Loading