feat: add governed selection outcome monitoring plan - #42
Conversation
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueNo actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (8)
🚧 Files skipped from review as they are similar to previous changes (1)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthrough
Changes선택 결과 모니터링
Estimated code review effort: 4 (복잡) | ~45분 Merge Risk: 🟡 Moderate · up to This PR adds aggregate-only monitoring evidence with deterministic integrity checks and human-controlled employment decisions, but it should not merge until all required current-head reviews, validations, and independent approval pass; integrating hosts must also enforce tenant ownership, actor separation, purpose authorization, and durable audit to prevent evidence from being attributed to the wrong tenant or unauthorized purpose. Sequence Diagram(s)sequenceDiagram
participant Caller
participant build_selection_outcome_monitoring_plan
participant SelectionOutcomeMonitoringPlan
Caller->>build_selection_outcome_monitoring_plan: 계획 입력 전달
build_selection_outcome_monitoring_plan->>SelectionOutcomeMonitoringPlan: 입력 검증 및 계획 생성
SelectionOutcomeMonitoringPlan-->>Caller: HMAC 봉인된 계획 반환
Caller->>SelectionOutcomeMonitoringPlan: canonical_json() 호출
SelectionOutcomeMonitoringPlan-->>Caller: 검증된 canonical JSON 반환
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches 💡 1🛠️ Fix failing CI checks 💡
📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
@opencode-agent Please independently review exact current head |
|
Current-head control-evidence correction for The PR body’s statement that no authenticated exact-head OpenCode review exists is stale. A post- The first current OpenCode boundary is central coverage double-instrumentation, not missing dispatch and not uncovered Orgmetra code. In The exact RED/GREEN acceptance canary has been routed through the existing central owner path |
|
Scheduled review-feedback autofix for this PR head.
|
|
Scheduled review-feedback autofix for this PR head.
|
|
Scheduled review-feedback autofix for this PR head.
|
|
Scheduled review-feedback autofix for this PR head.
|
Adopt protected develop without resurrecting the retired package-local workflow. Preserve selection-monitoring 100% statement/branch coverage through a hash-locked Foundation-owned contract and add executable non-resurrection/ownership regression. Signed-off-by: Seongho Bae <me@seonghobae.me>
Replace the selection-monitoring-specific dispatcher edit with a stable Foundation-owned discovery convention so later package artifact contracts can be added without competing edits to the shared dependency-hygiene script. Keep the retired leaf workflow deleted, preserve hash-locked 100% coverage, compile before tests, and clean the isolated venv on exit. Signed-off-by: Seongho Bae <me@seonghobae.me>
|
Canonical prerequisite #258 now has an active protected-parent implementation in Draft PR #259 at exact head |
|
New current-head repair, refs #273. Fresh review found a gap not covered by the existing issuance HMAC: a post-issuance exact built-in field could be replaced via Test-first Net delta from |
|
Fresh exact-head gate authority for
Keep Draft. The #273 runtime-type repair has current-head Foundation/SAST execution evidence, but required Security/CodeQL/review admission is still non-passing. Do not no-op retrigger, self-approve, transfer predecessor checks, or use administrator bypass. |
|
Fresh exact-head acceptance correction for unchanged
#273's representation-integrity source repair is therefore current-head Foundation/SAST GREEN and should not be churned for central control-plane failures. Keep #42 Draft until its shared Foundation prerequisite is protected truth and then-current central/security/review governance is satisfied; no predecessor transfer, no leaf workflow resurrection, no no-op retrigger. |
Buyer-visible outcome
Adds a governed, aggregate-only selection-outcome monitoring plan for post-hire criterion evidence while keeping high-impact employment decisions human-controlled. The packet binds tenant and Job scope, exact population/outcome snapshot evidence, monitoring window, protected-attribute/small-sample/statistical-plan provenance, accountable actor/reviewer/purpose/reason, evidence version, and opaque governed references into deterministic canonical evidence. LLM/model output is not an employment decision authority.
Current authority — 2026-09-09
Protected base is
develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f. Current exact head is155c9cdc9586ac29bdc4ace8a718fba3ab6304a5; the PR remains open · Draft · mechanically mergeable. Predecessor checks and reviews are causal evidence only and do not authorize this head.The retired
.github/workflows/selection-monitoring-quality.ymlstays deleted. Canonical.github/workflows/foundation-ci.ymlremains the repository owner path; this feature must not resurrect a leaf workflow or copy mutable Foundation source into siblings.Governed evidence contract retained
SelectionOutcomeMonitoringPlanremains aggregate-only, Job-scoped, human-review-only evidence. It carries no candidate identity, protected-attribute value, individual assessment score, individual employment decision, or free-form model output. Tenant and packet references remain opaque and purpose-bound; every reference must be re-resolved within the exact tenant before accountable review. The package does not calculate selection rates, apply a four-fifths pass/fail rule, infer discrimination, or authorize an employment-process change.Construction continues to require exact built-in trust-bearing text/date/time/numeric/boolean evidence and freezes
generated_atinto a detached built-in UTC instant. A process-local HMAC seal binds each live issued plan to its construction-time canonical bytes, with single-use seal registration and fail-closed export when issuance evidence is missing or semantically changed.#273 post-issuance runtime-type repair
Issue #273's representation-integrity gap is already repaired on this exact head. HMAC proves canonical-byte identity, but bytes alone do not prove that the live Python field still has the exact inert runtime type validated at construction. After issuance, low-level
object.__setattr__could otherwise substitute a behavior-bearingstrsubtype carrying the same underlying text, preserving canonical JSON and therefore the HMAC while retaining caller-owned executable runtime state. Adatesubtype could similarly reach overridden rendering behavior if canonical export did not re-establish the exact type boundary first.Test-first
06d8d2fbf8822f26758b810004dadbcf218c83e0added regressions for a same-valuestrsubtype and an executabledatesubtype. That short-lived test-only head produced no materialized hosted run, so no hosted RED is claimed. Ordinary successorc2a157d37f3a0bf6ac04f3ca2101a6607087e8f7added_assert_canonical_runtime_evidence(...): every serialized trust-bearing text field and each date/datetime/int/bool field must still be its exact built-in type before date/timestamp rendering, JSON serialization, or HMAC comparison. HMAC remains the semantic-byte tamper check; the exact-type gate closes only the representation-preserving runtime-type blind spot.Forward documentation successors keep
README.md,CHANGELOG.md, ADR 0016, and selection-monitoring TRACEABILITY aligned with that behavior. The final current head is155c9cdc9586ac29bdc4ace8a718fba3ab6304a5. Net product behavior for valid plans and the public canonical JSON schema are unchanged. Fresh review enumeration has no qualifyingAPPROVEDreview, and all currently returned inline review threads are resolved; historical COMMENTED findings remain review provenance, not merge approval.Shared Foundation dependency
The package-quality contract remains reached through canonical Foundation ownership. Issue #258 / Draft PR #259 remains the canonical repository-level Foundation compatibility solution: package-neutral compatibility, exact runner/interpreter evidence, reviewed hash-locked tooling, complete dependency-file provenance binding, retired-leaf non-resurrection, and deterministic manifest sealing.
Required owner order remains #258/#259 normal protected integration first, then #42 non-force adoption of that protected Foundation truth while preserving the complete Selection Monitoring product/runtime delta. Do not copy this mutable shared-dispatcher source into sibling product branches.
Current exact-head acceptance
Fresh re-read of the workflows bound to exact
155c9cdc9586ac29bdc4ace8a718fba3ab6304a5supersedes the stale queued snapshot previously recorded here:34140109476— terminal SUCCESS.34140109425— terminal SUCCESS.34140109689— terminal FAILURE solely becausedependency-reviewfails closed atCheck dependency review supportafter exact-head checkout. Trivy and OSV jobs succeeded. Central owner.github#810still owns the public non-fork dependency-comparison availability/configuration incident; sibling scanner GREEN is not promoted as Dependency Review evidence.34140109611— terminal FAILURE. The actions compatibility consumer failed enforcement at2026-09-07T16:33:50Zand the Python consumer at16:34:36Z; the same run'sDispatch current-head CodeQL scanjob did not start until16:51:21Zand then dispatched successfully at16:51:25Z. This is the same central producer/consumer ordering class now reproduced on the combined central successor.github#2040@d7bb95f6d6ca705725596df5170d6e1345080535; it is not repaired by changing Selection Monitoring source or by repeating this immutable head.The combined central #2040 successor is still open · Draft and its own exact CodeQL run
34244658739reproduces the ordering RED: compatibility enforcement failed before the later dispatch job began and successfully published. Do not start a no-op #42 rerun until that canonical owner reaches exact-head GREEN, integrates normally to protected.github/main, and the protected workflow source is re-read.No predecessor result transfers to this head. There is no qualifying independent
APPROVEDreview. Keep Draft until #259 is protected truth and all then-current exact-head technical/governance gates materially authorize integration.Merge discipline
Do not restore package-local CI, transfer predecessor checks, copy mutable sibling Foundation source, self-approve, fabricate reviewer/verdict evidence, use routine administrator bypass, force-push/destructively rebase, weaken a gate, or Close the valid monitoring delta. If a current-head RED materializes in owned product code, repair its causal owner and reacquire exact-head evidence; central dependency-review/CodeQL failures remain central owner-path work.