Skip to content

feat(rulesets): require World-owned regression gate - #474

Closed
devantler wants to merge 8 commits into
mainfrom
codex/world-local-regression-cutover-166
Closed

devantler wants to merge 8 commits into
mainfrom
codex/world-local-regression-cutover-166

Conversation

@devantler

@devantler devantler commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

🤖 Generated by the Agentic Engineer

Why

World at Ruin’s new product-owned regression gate exists but is not yet enforced, so ordinary pull requests still skip it. A coexistence window is needed before the established gate can be retired without weakening protection.

What

Create a second World-scoped organization ruleset for the product-owned workflow, with no bypass actors, while leaving the established ruleset unchanged. The rules are independent so the established rule can later be disabled without turning off the replacement.

Part of #166

@github-code-quality

github-code-quality Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Code Coverage Overview

Languages: Go, C#

Go / code-coverage/test

The overall line coverage in commit bbd306a in the codex/world-local-re... branch remains at 50%, unchanged from commit dfdb8ad in the main branch.

C# / code-coverage/dotnet

The overall line coverage in commit bbd306a in the codex/world-local-re... branch remains at 100%, unchanged from commit dfdb8ad in the main branch.


Updated October 05, 2026 17:46 UTC

@devantler devantler left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Generated by the Agentic Engineer

Self-review (fallback — CodeRabbit, Codex and Cursor Bugbot unavailable)

Reviewed commit: 3af51f0

  • CodeRabbit: organization plan review capacity was rate-limited at 2026-10-05T10:28:54Z; provider evidence says the next included review is available at 2026-10-05T11:05:54Z.
  • Codex: account code-review usage was exhausted at 2026-10-05T08:40:17Z; provider evidence says recovery requires credits or a usage reset.
  • Cursor Bugbot: user or team usage/spend was exhausted at 2026-10-05T09:37:50Z; provider evidence says recovery requires an account administrator to increase the limit.

I reviewed the exact current-head diff for correctness and security. The World-owned workflow is enforced by its own active, default-branch-scoped ruleset with no bypass actors, leaving the existing externally owned regression rule independent during the coexistence period. The manifest, kustomization, documentation and contract test stay in lockstep, and the source repository and workflow path are exact.

Verdict: no P0/P1 findings

@devantler

Copy link
Copy Markdown
Contributor Author

🤖 Generated by the Agentic Engineer

@coderabbitai full review

@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Review rate limited.


Your included review limit is currently reached under our Fair Usage Limits Policy. This review may still proceed through usage-based billing if eligible. Your next included review will be available in 23 minutes.

@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 10 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Repository YAML (base), Organization UI (inherited)
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 200b0485-7a1c-4c69-a893-bc67849d4dcf
📥 Commits

Reviewing files that changed from the base of the PR and between 018f267 and cf7c11a.

📒 Files selected for processing (4)
  • deploy/organization-rulesets/README.md
  • deploy/organization-rulesets/kustomization.yaml
  • deploy/organization-rulesets/require-world-at-ruin-product-regressions.yaml
  • tests/world-at-ruin-regression-ruleset.sh
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@devantler devantler left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Generated by the Agentic Engineer

Self-review (fallback — CodeRabbit, Codex and Cursor Bugbot unavailable)

Reviewed commit: 9b055c1

  • CodeRabbit: the requested exact-head review was rate-limited; provider evidence states the next included review window.
  • Codex: the portfolio review lane is unavailable because its usage limit is exhausted; provider evidence.
  • Cursor Bugbot: the portfolio review lane is unavailable because its usage limit is exhausted; provider evidence.

I reviewed the complete exact-head diff for correctness, enforcement scope, lifecycle safety, and accidental weakening. The new rule is additive and separately active, targets only World at Ruin's default branch, has no bypass actors, and selects the product-owned workflow from reviewed main rather than candidate bytes. The existing external regression rule remains active for the coexistence period. The manifest is wired into the rendered inventory, and the contract test binds its identity, management policy, repository selector, workflow path, source repository, source ref, counts, and no-bypass invariant. Exact-head local rendering, the focused regression contract, ShellCheck, and diff validation all pass.

Verdict: no P0/P1 findings

@devantler devantler left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Generated by the Agentic Engineer

Self-review (fallback — CodeRabbit, Codex and Cursor Bugbot unavailable)

Reviewed commit: bbd306a

  • CodeRabbit: the portfolio lane is currently rate-limited; provider evidence.
  • Codex: the portfolio review lane is unavailable because its usage limit is exhausted; provider evidence.
  • Cursor Bugbot: the portfolio review lane is unavailable because its usage limit is exhausted; provider evidence.

I reviewed the complete exact-head diff after rebinding it to current main, including the intervening workflow-pin and Platform merge-queue changes. The product ruleset remains additive and independently active, targets only World at Ruin's default branch, has no bypass actors, and selects the product-owned workflow from reviewed main rather than candidate bytes. The established external regression rule remains active for coexistence. The manifest, rendered inventory, documentation, and focused contract test stay in lockstep; the test binds identity, lifecycle policy, repository selector, workflow path, source repository, source ref, counts, and the no-bypass invariant. Exact-head local rendering, the focused regression contract, ShellCheck, and diff validation all pass.

Verdict: no P0/P1 findings

@devantler

Copy link
Copy Markdown
Contributor Author

🤖 Generated by the Agentic Engineer

@coderabbitai full review

@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
⚠️ Action not completed

Review rate limited.


Your included review limit is currently reached under our Fair Usage Limits Policy. This review may still proceed through usage-based billing if eligible. Your next included review will be available in 10 minutes.

@devantler devantler left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 Generated by the Agentic Engineer

Self-review (fallback — CodeRabbit, Codex and Cursor Bugbot unavailable)

Reviewed commit: cf7c11a

  • CodeRabbit: the requested exact-head review was rate-limited; provider evidence.
  • Codex: the portfolio review lane is unavailable because its usage limit is exhausted; provider evidence.
  • Cursor Bugbot: the portfolio review lane is unavailable because its usage limit is exhausted; provider evidence.

I reviewed the complete exact-head diff after rebinding it to current main, including the newly added Go-template ruleset and required-workflow hardening. The product ruleset remains additive and independently active, targets only World at Ruin's default branch, has no bypass actors, and selects the product-owned workflow from reviewed main rather than candidate bytes. The established external regression rule remains active for coexistence. The overlapping inventory assertion was correctly reconciled to six managed rulesets and demonstrated RED before the repair, then GREEN after it. The manifest, rendered inventory, documentation, and focused contract test remain in lockstep; exact-head rendering, regression contract, ShellCheck, and diff validation all pass.

Verdict: no P0/P1 findings

@devantler

Copy link
Copy Markdown
Contributor Author

🤖 Generated by the Agentic Engineer

Closing this draft because maintainer direction now places World at Ruin protection in repository-scoped rulesets and reserves organization rulesets/reusable workflows for genuinely organization-wide policy and mechanisms. The repository-scoped controller, independently authenticated status publisher, live readiness checks, caller migration, and ownership documentation are tracked in devantler-tech/world-at-ruin#1256 through #1265.

The established organization gate remains active until that replacement has independently authenticated enforcement plus positive and negative canary evidence. No protection is removed by closing this unmerged additive draft.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant