feat(maplibre): validate source metadata projections - #1974
Merged
bartytime4life merged 3 commits intoAug 4, 2026
Conversation
bartytime4life
marked this pull request as ready for review
August 4, 2026 23:00
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Goal
Implement a deterministic, synthetic, no-network MapLibre source-metadata projection validator for local
epoch,license, SHA-256digest, and optional proof/manifest reference syntax without creating source, evidence, rights, policy, review, release, deployment, or publication authority.Current state
f52f2898f40aa35a2e8bd3a9ae9a6399978e541ewas inspected exactly, including its 17-path source-metadata diff and hosted checks.ed2584df8f0930e14e673087981c4c7c087ef4ca(fix(ci): classify governed MapLibre metadata fixtures).ed2584df8f0930e14e673087981c4c7c087ef4ca.fd04e0aa578e1da5cf6b9b36f3b002ddc01dad63, the branch is 3 commits ahead / 0 behind with 18 changed paths, 1,279 additions, and 10 deletions.Exact diff and bounded correction
The original requested-head diff added 17 paths:
.github/workflows/maplibre-source-metadata.yml;tools/validators/maplibre/validate_source_metadata.py;tests/maplibre/test_source_metadata.py;tests/fixtures/maplibre/source-metadata/**;data/receipts/generated/genrec-maplibre-source-metadata-20260804.json.The only corrective path added after the requested-head inspection is:
.github/workflows/maplibre-perf-governance.yml— 72 additions / 10 deletions.No release workflow, rollback workflow, RollbackCard schema or validator, Roads/Rail/Trade workflow or validator, repository setting, deployment path, publication path, source registry, evidence root, or policy root was changed.
The generated receipt remains scoped to the original 16 source-metadata implementation artifacts. It is AI-authoring process provenance only and grants no approval or lifecycle authority.
Requested-head hosted results
Requested branch head:
f52f2898f40aa35a2e8bd3a9ae9a6399978e541eGitHub merge ref inspected:
d8f3bfab9753f0999185180ced68bbb2481e1568maplibre-source-metadata— run30930761637, run number 2MapLibre Perf Governance— run30930763992, run number 82tests/fixtures/maplibre/**as an executable performance fixture. The new source-metadata JSON fixtures triggered that blanket check. Its exact validator inventory also did not admit the separately governedvalidate_source_metadata.pylane.release-dry-run— run30930763951, run number 9589rollback-card-presencestopped onRollbackCard schema metadata changed; reconcile the readiness boundary.x-kfmboundary metadata, while the job still asserted an older inventory.rollback-drill— run30930761492, run number 8094simulate-rollbackstopped onrelease RollbackCard metadata changed; reconcile the accepted profile.domain-roads-rail-trade— run30930764078, run number 8094no_python_filesfor the remaining scaffold validator-root set and emitted a broader-domainWORKFLOW_HOLD.Reconciliation: focused source-metadata versus performance governance
The passing focused workflow and the original failing performance-governance workflow were testing different boundaries:
maplibre-source-metadatadeliberately executes the new no-network validator and exact positive/negative fixtures.MapLibre Perf Governanceis a readiness sentinel for the still-held browser/performance/render/trust lane. Before this correction, it interpreted any MapLibre fixture payload and any new MapLibre validator as evidence that the held performance lane had matured.The bounded correction therefore does not weaken the performance hold. It:
tests/fixtures/maplibre/source-metadata/subtree;validate_source_metadata.pyas the separately governed validator;tests/fixtures/maplibre/**;Corrected-head hosted results
Corrected branch head:
ed2584df8f0930e14e673087981c4c7c087ef4caGitHub merge ref inspected:
d91d1a3fa7648d96cf381c4301c801b6b4211397, generated with base commit86af15bfc3a816bbd411d714ea7377f2738ba6ce.maplibre-source-metadata— run30951302221, run number 3MapLibre Perf Governance— run30951302443, run number 83WORKFLOW_HOLD.release-dry-run— run30951305585, run number 9601rollback-card-presenceadvanced past the current schema metadata checks, then failed becausetools/validators/release/validate_rollback_card.pyimportsjsonschemabut that job does not install/provide it:ModuleNotFoundError: No module named 'jsonschema'.rollback-drill— run30951302364, run number 8106release RollbackCard metadata changed; reconcile the accepted profile.domain-roads-rail-trade— run30951302283, run number 8106CI_READINESS_REASON: no_python_filesfor the remaining scaffold validator roots; the domain publish-dry-run and proof-hold jobs themselves succeeded.All other corrected-head pull-request workflows completed successfully, including
validator-suite,schema-validation,contracts-validate,contract-drift,promotion-gate,e2e-smoke,codeql,dependency-scan, and the other domain workflows.Validator behavior
tools/validators/maplibre/validate_source_metadata.pyremains:ALLOW/0,ABSTAIN/2,DENY/3, andERROR/4.The focused tests preserve exact valid, abstain, deny, malformed-input, duplicate-key, determinism/redaction, no-network, and CLI-exit behavior.
Trust boundary
A green
maplibre-source-metadataresult proves only that selected local JSON satisfies this bounded projection grammar and, when a local digest manifest is supplied, that two declared digest strings agree. It does not prove:A green
MapLibre Perf Governanceresult proves only that the separately governed source-metadata lane is classified without weakening the existing performance/runtime hold. It does not execute a browser, server, external source, render comparison, performance measurement, screenshot, attestation, proof, release object, correction, rollback, deployment, publication, or artifact upload.ALLOWremains a validator result, not aPolicyDecision,PromotionDecision,ReleaseManifest, release authorization, or publication approval. The three unrelated failures are documented rather than waived, masked, or converted into success.Rollback
Before an authorized merge, close this draft and abandon
agent/maplibre-source-metadata-validation-20260804.After an authorized merge, prefer reverting the PR merge commit as one unit. For a path-bounded rollback, revert
ed2584df8f0930e14e673087981c4c7c087ef4cafirst to remove the performance-readiness integration change, then revert the two preceding source-metadata commits in reverse order. No source activation, canonical evidence, lifecycle data, release state, deployment, publication, or public artifact requires restoration.Reviewer disposition
DRAFT — PR-CAUSED CI DEFECT CORRECTED; KEEP ON HOLD FOR HUMAN REVIEW AND SEPARATE BASELINE DISPOSITION.
No PR-caused hosted failure remains at
ed2584df8f0930e14e673087981c4c7c087ef4ca. The remainingrelease-dry-run,rollback-drill, anddomain-roads-rail-tradefailures are unrelated repository/workflow baseline issues and should be repaired or dispositioned in their owning lanes, not weakened or bundled into this source-metadata slice.Do not mark ready, approve, merge, release, deploy, publish, activate a source, approve workflow authority, or change repository settings from this pull request.