Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
26 commits
Select commit Hold shift + click to select a range
70a0945
docs(artifacts): reconcile submission bundle plan
Abiorh001 Jul 24, 2026
8fd0320
docs(artifacts): address external plan review
Abiorh001 Jul 24, 2026
525182b
docs(artifacts): close review state boundaries
Abiorh001 Jul 24, 2026
4111218
docs(artifacts): align submission manifest templates
Abiorh001 Jul 24, 2026
080a427
docs(artifacts): clarify preflight bundle evidence
Abiorh001 Jul 24, 2026
58b766e
docs(agent-loop): finalize PLAN2 review evidence
Abiorh001 Jul 24, 2026
1eec271
fix(agent-gates): recognize technical worker modules
Abiorh001 Jul 24, 2026
5934be5
fix(agent-gates): reject authority in worker paths
Abiorh001 Jul 24, 2026
12638db
test(agent-gates): reject worker path task claims
Abiorh001 Jul 24, 2026
2c210b8
fix(agent-gates): restrict worker paths to references
Abiorh001 Jul 24, 2026
7204261
docs(agent-loop): authorize scanner gate repair
Abiorh001 Jul 24, 2026
ad1ffdf
docs(agent-loop): clarify scanner repair scope
Abiorh001 Jul 24, 2026
f36d237
docs(agent-loop): refresh PLAN2 repair evidence
Abiorh001 Jul 24, 2026
57a7d1e
docs(artifacts): close PLAN2 admission lifecycle gaps
Abiorh001 Jul 25, 2026
07cea22
docs(artifacts): complete executable manifest template
Abiorh001 Jul 25, 2026
cbeaffb
docs(artifacts): enforce canonical admission gates
Abiorh001 Jul 25, 2026
dea6955
test(agent-gates): guard canonical materializer action
Abiorh001 Jul 25, 2026
822b43d
docs(agent-loop): record PLAN2 amendment review
Abiorh001 Jul 25, 2026
cd1dd12
docs(agent-loop): bind PLAN2 amendment evidence
Abiorh001 Jul 25, 2026
cd19af5
test(agent-gates): prove typed AUTH boundary
Abiorh001 Jul 25, 2026
b839d25
docs(agent-loop): record hosted PLAN2 gate repair
Abiorh001 Jul 25, 2026
7c88bbf
docs(agent-loop): bind hosted PLAN2 repair evidence
Abiorh001 Jul 25, 2026
1169992
docs(agent-loop): record latest-main PLAN2 integration
Abiorh001 Jul 25, 2026
3185af5
fix(agent-gates): remove obsolete ART contract read
Abiorh001 Jul 25, 2026
1dbc0d4
docs(agent-loop): record Ruff integration repair
Abiorh001 Jul 25, 2026
be62b74
docs(agent-loop): bind latest-main PLAN2 evidence
Abiorh001 Jul 25, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
58 changes: 57 additions & 1 deletion .agent-loop/REVIEW_LOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -2844,7 +2844,6 @@ inline finding. Its unexplained 37.61 percent docstring warning is
non-actionable because the unchanged repository gate independently passes the
same head at 87.6 percent against the 80 percent floor. Human review and
explicit approval of PR #178 remain.

## 2026-07-23 - WS-AUTH-001-10C Internal Implementation Review

AUTH-10C exact implementation SHA
Expand Down Expand Up @@ -2883,3 +2882,60 @@ retryability. Full GitHub shards then exposed and closed a stale linked-event
matrix classification plus legacy-fixture trigger/constraint cleanup residue;
the exact isolated audit case and sequential upgrade/downgrade matrices pass.
fresh GitHub Backend, Agent Gates, CodeRabbit, and human review remain.

# WS-ART-001-PLAN2 Submission Bundle Reconciliation

- Signed automation run `30100940860` cancelled the rejected combined
`WS-ART-001-03` implementation before runtime edits.
- Human intent locks one outer ZIP, bounded process-local scratch through every
pre-submit gate, no candidate retention/provider namespace, conservative
existing limits, existing recovery reuse, and full integrity recomputation on
downstream byte streams.
- Initial planning review failed on stale ART history, incomplete guide chunks,
duplicate upload-session/artifact-set contracts, partial scratch surfaces,
pre-submit evidence privacy, nested-archive ambiguity, AUTH sequencing, and
failing governance/coverage/e2e gates.
- The repaired candidate splits 03A-C and 04A-C/05, reconciles canonical specs
and templates, defines the exact AUTH handoff, preserves existing
scratch/admission/recovery abstractions, and passes all deterministic gates.
- Final senior, architecture, QA/test, security/auth, product/ops, reuse/dedup,
CI integrity, test-delta, and docs reviews pass with no open finding.

## 2026-07-24 - WS-ART-001-PLAN2 External Review Reconciliation

CodeRabbit found seven valid inconsistencies in phase ownership, hidden route
composition, canonical ZIP paths, AUTH retirement custody, successor wording,
put-attempt state vocabulary, and server-owned manifest input. Hosted CI also
found noncanonical chunk headings and a successor-title mismatch. The repair
resolves all findings without runtime behavior or AUTH activation; refreshed
internal review, hosted checks, and human approval remain required.

## 2026-07-25 - WS-ART-001-PLAN2 Admission And Authorization Amendment

The final planning candidate now closes verified-but-unbound admission
lifecycle, canonical executable intent, and fresh authorization at durable put
intent and Submission consumption. Review repair replaced shared PermissionIds
misnamed as service actions with the canonical phase-specific AUTH ActionIds
and strengthened the governance test to require exact no-expiry, no-release,
no-deletion, no-cleanup, and no-retention-process clauses. Exact material SHA
`3185af57055f8e7b2411a2090671a9707a26dc58` is rebased on trusted main
`bba4ba5f171a4438b072740707a5cf8bde49d9af`; all nine internal reviewer tracks
pass with no open finding. Hosted external checks and human merge approval
remain required.

GitHub Agent Gates then exercised the full pytest collection that the direct
script entry point does not run and exposed two line-wrap-sensitive assertions.
The repair makes the 05 typed-capability/no-AUTH-repository boundary explicit
and normalizes handoff whitespace before semantic ActionId/PermissionId checks.
The exact hosted-equivalent command passes 300 tests with 90.46 percent branch
coverage for the loop-memory updater.

The later trusted-main reconciliation incorporates PR #198's exact CI custody
and Ruff/orchestration repairs without changing the 22-commit PLAN2 patch
series; range-diff equivalence and fresh exact-base integration review are the
required evidence before republishing PR #197.

The exact Ruff 0.15.22 integration review found one branch-owned `F841`: a
historical ART contract read remained after its assertion was retired. The
repair removes only that dead read; focused Ruff passes, all 104 collected
agent-gate pytest cases pass, and the 100 direct regression cases pass.
Original file line number Diff line number Diff line change
@@ -0,0 +1,91 @@
# WS-ART-001 Authorization Handoff

ART owns hidden artifact behavior, canonical product resource facts, lifecycle
guards, surface manifests, and feature tests. AUTH owns ActionId/PermissionId
catalogues, service identities, fixed matrices, evaluator integration, grants,
activation custody, and availability.

## Guide Source Sequence

1. Existing guide-source actions remain planned and unavailable.
2. ART-03A implements hidden `artifact.guide_source.ingest` behavior and its
exact resource/guard/surface manifest.
3. AUTH activates only that exact action through a separately reviewed AUTH
contract after consuming ART evidence.
4. ART-03B implements hidden `artifact.guide_source.read` and
`artifact.guide_source.binding.create` behavior; binding maps to fixed
permission `artifact.binding.create`.
5. AUTH activates only those exact actions after consuming 03B evidence.
6. ART-03C performs the legacy clean cut. No ART chunk writes availability.

## Submission Bundle Sequence

Before ART-04A starts, AUTH must merge a separately reviewed registration
contract, provisionally named
`WS-AUTH-001-ART-SUBMISSION-BUNDLE-REGISTRATION`, that:

- registers planned ActionId `artifact.submission_bundle.prepare`;
- maps it only to existing human PermissionId `submission.create`;
- limits candidates to the assigned contributor for the exact task/project;
- names ART-owned canonical facts for actor, identity link, project, task,
active assignment, locked policy context, and operation generation;
- keeps the action unavailable and adds no grant or evaluator activation;
- records parity evidence in AUTH's closed catalogue/constraint/owner manifests;
- explicitly retires the unused planned multi-step upload-session ActionIds or
proves they are unavailable and have no route/command manifest entry.

Until that AUTH contract merges, current agent-gate catalogue assertions retain
those strings only as an exact planned/unavailable discovery baseline. Their
presence in the closed catalogue is not an active design, grant, route, or
permission to implement a second intake path, and PLAN2 does not edit AUTH-owned
catalogue or parity assertions.

ART-04A through 04C then implement one hidden continuous surface and publish
its exact route/resource/guard manifest. After 04C, a separate reviewed AUTH
activation contract may integrate the evaluator and change only
`artifact.submission_bundle.prepare` to active. ART-05 cannot start until that
activation merges.

The preparation surface authorizes before scratch intake, but the initial
decision cannot authorize the later durable mutation. Immediately before
capacity reservation and `ArtifactPutAttempt` creation, 04C must consume an
AUTH-owned transaction-local prepared capability whose canonical facts cover
the current actor, exact identity link, project authority, assignment, task,
predecessor, locked task/guide/policy context, action availability, and
operation generation. AUTH and the owning product services reload/lock their
own facts; ART receives only the typed capability and never imports AUTH-owned
repositories. Authorization evidence, capacity reservation, and durable put
intent commit atomically before provider I/O.

ART-05 requires a new human authorization decision for `submission.create` and
a separately prepared fixed-service capability for
ActionId `artifact.submission.binding.create`, mapped to PermissionId
`artifact.binding.create`. Both are consumed in the one transaction that locks
the ready admission and TASK-owned context, creates Submission and binding,
and marks the admission consumed. Human authority implies no service authority.
Revocation after durable put intent does not cancel verification/recovery, but
the resulting admission remains unbound until a fresh 05 decision succeeds.
Authorization denial precedes admission-detail errors so unrelated actors
cannot distinguish missing, ready, stale, or consumed admissions.

The continuous contributor action never implies the fixed service actions:

- `artifact.pre_submit.checker_input.materialize` and
`artifact.post_submit.checker_input.materialize`, both mapped to PermissionId
`artifact.checker_input.materialize`;
- `artifact.verification.execute`;
- `artifact.pending_work.scan`;
- `artifact.put_attempt.resolve`;
- `artifact.submission.binding.create`, mapped to PermissionId
`artifact.binding.create`.

Each fixed service action retains its canonical provisioned service identity,
matrix row, resource facts, terminal reauthorization, and separate activation
evidence. No human grant supplies fixed service authority.

## Fail-Closed Rule

An ART implementation contract stops if its required AUTH registration or
activation contract is absent, unmerged, inactive, differently mapped, or
targets a different resource fact shape. Planned catalogue presence, a local
action string, or hidden feature code is never executable authority.
Original file line number Diff line number Diff line change
Expand Up @@ -12,14 +12,19 @@ Each chunk is one PR. No later chunk starts automatically.
| `WS-ART-001-02A3` | Replace ArtifactStore v1 with byte-only v2, activate API-startup and Celery Beat scratch cleanup, migrate schema/callers/factory, and remove `flow_node` in one atomic clean cut. | L1 | Merged through PR #141 as `a10d901` on 2026-07-18 |
| `WS-ART-001-02B1` | Implement the S3-compatible adapter, MinIO integration, and AWS S3 production profile. | L1 | Merged through PR #151 as `1b5422fc` on 2026-07-19 |
| `WS-ART-001-02C1` | Add the generic durable-byte admission ledger and durable put-attempt state foundation without provider execution. | L1 | Merged through PR #154 as `44f2467c` on 2026-07-19 |
| `WS-ART-001-02C2` | Add put resolution, verification publication, complete-object observation, immutable receipts, and PostgreSQL execution fencing without recovery attempts or routes. | L1 | Active after PR #154 and explicit user start on 2026-07-19 |
| `WS-ART-001-02C3` | Add the recovery-attempt model and exact idempotent source-job to retry-job chain without public or Operator routes. | L1 | Proposed after 02C2 |
| `WS-ART-001-02D` | Add hidden Operator content/job/retry/recovery/audit APIs, canonical resource composition, and production-readiness checks while actions and provider profiles remain inactive. | L1 | Proposed after 02C3, AUTH-09E, and `WS-AUTH-001-ART-CUSTODY` |
| `WS-ART-001-03` | Store and bind guide-source bytes; add same-snapshot setup recovery through the authorized artifact reader. | L1 | Proposed after 02D |
| `WS-ART-001-04A` | Add task-scoped upload sessions/items, trusted archive inspection, independent verification, immutable sealing, and artifact-set manifests. | L1 | Proposed after 03 |
| `WS-ART-001-04B` | Execute authoritative pre-submit against sealed artifact sets and persist exact admissions with bounded infrastructure continuation. | L1 | Proposed after 04A |
| `WS-ART-001-05` | Atomically bind admitted artifact sets to submissions and remove legacy URI/hash/finalization contracts. | L1 | Proposed after 04B |
| `WS-ART-001-06A` | Persist checker input snapshots and materialize authorized immutable bytes into bounded checker workspaces. | L1 | Proposed after 05 |
| `WS-ART-001-02C2` | Add put resolution, verification publication, complete-object observation, immutable receipts, and PostgreSQL execution fencing without recovery attempts or routes. | L1 | Merged through PR #159 as `bc5e6a42` |
| `WS-ART-001-02C3` | Add the recovery-attempt model and exact idempotent source-job to retry-job chain without public or Operator routes. | L1 | Merged through PR #174 as `92b8a7aa` |
| `WS-ART-001-02D` | Add hidden Operator content/job/retry/recovery/audit APIs, canonical resource composition, and production-readiness checks while actions and provider profiles remain inactive. | L1 | Merged through PR #177 as `93c14181` |
| `WS-ART-001-03` | Original combined guide-source cutover. | L1 | Cancelled before implementation; no runtime changes |
| `WS-ART-001-PLAN2` | Reconcile guide and one-ZIP submission planning with bounded scratch, existing immutable admission/recovery, exact AUTH sequencing, and downstream ownership. | L1 | Planning-only successor proposed after cancellation |
| `WS-ART-001-03A` | Add hidden guide-source byte ingest through existing preparation, admission, verification, and publication. | L1 | Proposed after PLAN2 |
| `WS-ART-001-03B` | Bind verified guide-source content and provide authorized integrity-checking setup materialization. | L1 | Proposed after 03A and exact AUTH activation |
| `WS-ART-001-03C` | Remove legacy guide-source identity and add exact same-generation setup continuation. | L1 | Proposed after 03B and exact AUTH activation |
| `WS-ART-001-04A` | Accept one outer ZIP in bounded scratch, safely inspect its tree, normalize executable intent, produce canonical identities, and reject unchanged work before provider I/O. | L1 | Proposed after 03C and AUTH planned action registration |
| `WS-ART-001-04B` | Run mandatory platform and locked Project Guide pre-submit checks against the same scratch-bound tree and executable semantics without durable storage. | L1 | Proposed after 04A |
| `WS-ART-001-04C` | Reauthorize at durable intent, admit/verify the passing ZIP once, and publish one capacity-charged `ready` admission that may remain unbound. | L1 | Proposed after 04B; AUTH activation follows hidden completion |
| `WS-ART-001-05` | Freshly authorize and atomically consume one ready admission into one immutable Submission/binding, or terminally stale it on proven context drift. | L1 | Proposed after 04C and exact AUTH activation |
| `WS-ART-001-06A` | Persist checker input snapshots and materialize authorized immutable bytes with identical normalized executable semantics. | L1 | Proposed after 05 |
| `WS-ART-001-06B` | Ingest checker logs/outputs as artifacts, persist checker completion facts, and preserve existing checker-owned routing without creating review aggregates. | L1 | Proposed after 06A |
| `WS-ART-001-07` | Prove Local/MinIO plus AWS S3 readiness, Operator recovery, and exact-byte guide/pre/post-submit behavior through real APIs. | L1 | Proposed after 06B |

Expand All @@ -35,9 +40,17 @@ OBJECT-STORAGE-AMENDMENT
-> 02C2 put resolution, verification publication, and fencing
-> 02C3 recovery attempt and idempotency chain
-> 02D Operator and production readiness
-> 03 guide source cutover
-> 04A upload/inspection/sealing
-> 04B pre-submit admission and outage continuation
-> PLAN2 planning reconciliation
-> 03A guide-source byte ingest
-> AUTH activation for exact 03A actions
-> 03B guide-source binding/materialization
-> AUTH activation for exact 03B actions
-> 03C guide-source clean cut/continuation
-> AUTH planned registration of `artifact.submission_bundle.prepare`
-> 04A one-ZIP scratch intake/inspection/manifest/change gate
-> 04B scratch-bound platform/project pre-submit checks
-> 04C one-time immutable admission/verification
-> AUTH activation of exact complete contributor surface
-> 05 submission cutover
-> 06A checker input/materialization
-> 06B checker output/post-submit routing
Expand All @@ -48,10 +61,14 @@ OBJECT-STORAGE-AMENDMENT
deferred. It has no active chunk, runtime profile, credential service, or
configuration value in v0.1.
`ReviewPacketManifest` and `ReviewEvidenceArtifact` remain owned by WS-REV.
Physical deletion and semantic search require separate approved initiatives.
Physical deletion, temporary provider retention, candidate object storage, and
semantic search require separate approved initiatives.

## Cross-Initiative Handoffs

The exact authorization sequence and stop conditions are recorded in
`AUTH_HANDOFF.md`.

- Artifact actions follow AUTH planned registration -> hidden ART behavior and
canonical resource composition -> AUTH evaluator integration and activation.
`WS-AUTH-001-ART-CUSTODY` first transfers the 25 current ART actions to eight
Expand All @@ -64,7 +81,10 @@ Physical deletion and semantic search require separate approved initiatives.
- WS-REV owns `ReviewPacketManifest` and `ReviewEvidenceArtifact`. Review code
receives verified Workstream `ArtifactBinding` IDs through a narrow
review-facing capability; it must not receive provider references, scratch
paths, or concrete adapters.
paths, or concrete adapters. REV also owns reviewer decisions and
note/findings for
the exact `Submission`; `needs_revision` authorizes a later contributor ZIP
but contains no reviewer-uploaded artifact.
- A future optional contribution-evidence projection requires separately
approved ART-owned read/write capabilities and AUTH action activation. Core
ContributionRecord creation makes no ART capability/provider call and is not
Expand All @@ -73,8 +93,17 @@ Physical deletion and semantic search require separate approved initiatives.
- Cross-initiative terminology must use ART's canonical `resource_type`,
`resource_id`, and `logical_role`, or define an explicit integration mapping;
product initiatives must not create a second binding vocabulary implicitly.
- The existing immutable `Submission` row is the version aggregate. TASK/REV
jointly own the exact `needs_revision` response relation and indexed
latest/current/accepted access; no initiative creates a competing
`SubmissionVersion` table.
- Reviewer and delivery streams consume an ART-owned integrity-checking read
capability that recomputes full SHA-256 and byte count. ART does not own the
review decision, ContributionRecord, compensation, reputation, or delivery
lifecycle that consumes that capability.

## Checkpoint Before Checker Expansion

Do not resume checker feature expansion until `WS-ART-001-06B` proves pre-submit
and post-submit consume the same immutable artifact-set commitment.
evidence and post-submit execution name the same archive identity,
semantic-manifest hash, verified admission, and exact binding.
Loading
Loading