From 609be24d3b5a4825e9dd8f70f3f3f219d041b430 Mon Sep 17 00:00:00 2001 From: Abiorh001 Date: Sat, 25 Jul 2026 19:11:58 +0100 Subject: [PATCH 1/8] fix(agent-loop): recover unsigned ART planning merge --- .agent-loop/REVIEW_LOG.md | 13 +++ .../CHUNK_MAP.md | 11 ++- .../STATUS.md | 22 ++--- .../WS-ENG-007-00R6-art-plan2-recovery.md | 95 +++++++++++++++++++ .../merge-intents/WS-ENG-007-00R6.json | 9 ++ .../policies/loop-memory-recovery.json | 12 +-- docs/operations_post_merge_memory.md | 19 ++++ scripts/test_agent_gates.py | 12 +-- 8 files changed, 165 insertions(+), 28 deletions(-) create mode 100644 .agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/chunks/WS-ENG-007-00R6-art-plan2-recovery.md create mode 100644 .agent-loop/merge-intents/WS-ENG-007-00R6.json diff --git a/.agent-loop/REVIEW_LOG.md b/.agent-loop/REVIEW_LOG.md index 69ebbb06..62274d3f 100644 --- a/.agent-loop/REVIEW_LOG.md +++ b/.agent-loop/REVIEW_LOG.md @@ -2939,3 +2939,16 @@ The exact Ruff 0.15.22 integration review found one branch-owned `F841`: a historical ART contract read remained after its assertion was retired. The repair removes only that dead read; focused Ruff passes, all 104 collected agent-gate pytest cases pass, and the 100 direct regression cases pass. + +## 2026-07-25 - WS-ENG-007-00R6 ART PLAN2 Recovery Review + +PR #197 merged planning chunk `WS-ART-001-PLAN2` without its required signed +planning start, so canonical reconciliation fails closed at merge +`03a05eeb8f129e0d5f226cc5c058965f43590a81`. R6 reuses the closed schema-v5 +recovery engine with signed basis `bba4ba5f171a4438b072740707a5cf8bde49d9af`, +that one exact recovered merge, and only the direct-next R6 activation. Both +temporary exemptions must be merge-evidence-bound, first-parent adjacent, +consumed before signing, and absent from replay. ART remains stopped at 03A; +`WS-CI-001-03`, `WS-ENG-007-01`, and every other successor still require +ordinary explicit starts. All nine internal tracks reviewed the bounded recovery; exact final-SHA +evidence and protected GitHub checks remain required. diff --git a/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/CHUNK_MAP.md b/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/CHUNK_MAP.md index 57087784..4154abae 100644 --- a/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/CHUNK_MAP.md +++ b/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/CHUNK_MAP.md @@ -6,13 +6,14 @@ | 0 | `WS-ENG-007-00R2` | Canonicalize repeated trusted check evidence and reconcile PRs #187 and #188 exactly once | L1/P0 | Merged; superseded by mutable-history failure | | 0 | `WS-ENG-007-00R3` | Freeze accepted checks at merge time and give explicit starts deterministic recovery parity | L1/P0 | Merged; exposed cross-initiative projection mixing | | 0 | `WS-ENG-007-00R4` | Separate global merge evidence from initiative-local authority projections | L1/P0 | Merged as PR #191; awaiting exact R5 reconciliation | -| 0 | `WS-ENG-007-00R5` | Reconcile exact merged R4 and activate its closed authority-projection repair | L1/P0 | Active fail-closed recovery after R4 merged without signed-start evidence | -| 1 | `WS-ENG-007-01` | Add deterministic reviewed-patch identity and conservative base-delta review preservation | L1 | Blocked on 00R5 merge, successful reconciliation, and explicit start | +| 0 | `WS-ENG-007-00R5` | Reconcile exact merged R4 and activate its closed authority-projection repair | L1/P0 | Completed and merged as PR #192 | +| 0 | `WS-ENG-007-00R6` | Reconcile exact unsigned ART PLAN2 merge and restore ordinary signed starts | L1/P0 | Active fail-closed recovery after PR #197 merged without signed-start evidence | +| 1 | `WS-ENG-007-01` | Add deterministic reviewed-patch identity and conservative base-delta review preservation | L1 | Blocked on 00R6 merge, successful reconciliation, and explicit start | | 2 | `WS-ENG-007-02` | Add structured reviewer-track and upstream-finding reconciliation | L1 | Blocked on 01 merge and explicit start | | 3 | `WS-ENG-007-03` | Add merge-group CI parity and queue-readiness proof | L1 | Blocked on 02 merge and explicit start | -Recovery chunks are exceptional ordered prerequisites; `00R5` consumes the -exact unsigned R4 recovery merge while preserving R4's authority-projection -repair. Implementation chunks +Recovery chunks are exceptional ordered prerequisites. `00R6` consumes only +the exact unsigned ART PLAN2 merge and its own activation; it grants no ART or +CI implementation authority. Implementation chunks remain one PR each and stop after merge. Every successor requires a separate explicit signed start. diff --git a/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/STATUS.md b/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/STATUS.md index 44e9a971..5816a681 100644 --- a/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/STATUS.md +++ b/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/STATUS.md @@ -1,20 +1,20 @@ # STATUS: WS-ENG-007 - Concurrent PR Review Reconciliation -- Phase: R4 activation recovery +- Phase: ART PLAN2 signed-memory recovery - Gate: fail-closed automation repair - Active planning chunk: none - Active implementation chunk: none - Reconciled recovery history: `WS-ENG-007-00R1`, `WS-ENG-007-00R2`, `WS-ENG-007-00R3` -- Completed recovery chunk: `WS-ENG-007-00R3` -- Merged recovery chunk: `WS-ENG-007-00R4` -- Active recovery chunk: `WS-ENG-007-00R5` +- Completed recovery chunks: `WS-ENG-007-00R1` through `WS-ENG-007-00R5` +- Unsigned merge requiring recovery: `WS-ART-001-PLAN2` / PR #197 +- Active recovery chunk: `WS-ENG-007-00R6` - Proposed implementation successor after recovery: `WS-ENG-007-01` - Separate explicit start required: true -- Current gate: PR #191 merged as - `9bf16d478f669d48172810c83cdf6a7d2b8992ed`, but post-merge memory rejected it - because recovery chunk R4 had no signed start. Signed state remains at PR #190; - no successor is active. -- Review gate: all nine internal tracks passed exact implementation head - `10159497b3f3ca3464cbbbfd10f16945ade1879a`; awaiting external checks and the - user-owned merge decision. +- Current gate: PR #197 merged as + `03a05eeb8f129e0d5f226cc5c058965f43590a81` without a signed planning start. + Reconciliation fails closed at that merge, so later explicit starts cannot + reach current main. Signed state remains at merge + `bba4ba5f171a4438b072740707a5cf8bde49d9af` with AUTH-11 active. +- Review gate: R6 exact-head internal review and protected checks required + before the user-owned merge decision. diff --git a/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/chunks/WS-ENG-007-00R6-art-plan2-recovery.md b/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/chunks/WS-ENG-007-00R6-art-plan2-recovery.md new file mode 100644 index 00000000..84cded92 --- /dev/null +++ b/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/chunks/WS-ENG-007-00R6-art-plan2-recovery.md @@ -0,0 +1,95 @@ +# Chunk Contract: WS-ENG-007-00R6 — ART PLAN2 Signed-Memory Recovery + +## Parent initiative + +`WS-ENG-007` — Concurrent PR Review Reconciliation + +## Goal + +Reconcile exact merged planning chunk `WS-ART-001-PLAN2` and this activation +chunk into signed loop memory so ordinary writer-directed starts can resume. + +## Why this chunk exists + +PR #197 merged without the required signed planning start. Loop-memory replay +correctly fails closed at that merge and therefore cannot reach later protected +main or apply any new explicit start. + +## Risk class + +L1 / P0 signed-memory recovery. + +## Start phase + +Recovery implementation. Signed state cannot start this chunk until the exact +unrecorded predecessor is reconciled. + +## Allowed files + +```text +.agent-loop/policies/loop-memory-recovery.json +.agent-loop/REVIEW_LOG.md +scripts/test_agent_gates.py +docs/operations_post_merge_memory.md +.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/** +.agent-loop/merge-intents/WS-ENG-007-00R6.json +``` + +## Not allowed + +```text +workflow, updater, checker, permission, CI, test, or coverage behavior changes +application, API, database, auth, artifact, payment, or product changes +wildcard, persistent, reordered, reusable, or post-signing exemptions +automatic ART, CI, AUTH, ENG, or other successor starts +reinterpretation of PR #197 as implementation authority +``` + +## Acceptance criteria + +- [ ] Schema-v5 recovery binds signed basis `bba4ba5f…` and names only PR #197 / + `WS-ART-001-PLAN2` / `03a05eeb…` as the recovered predecessor. +- [ ] Activation names only `WS-ENG-007-00R6`; the target identity comes from + trusted GitHub merge evidence and must be direct-next on first-parent main. +- [ ] Both merges carry successful merge-bound `agent-gates` and `test` + provenance; mutable reruns and CodeRabbit are not recovery authority. +- [ ] Both temporary exemptions are consumed before signing and cannot persist, + replay, reorder, broaden, or authorize a third merge. +- [ ] ART PLAN2 reconciles to stopped state with `WS-ART-001-03A` requiring an + explicit start; recovery starts no implementation or planning chunk. +- [ ] Exactly one merge intent stops ENG-007 at its existing `01` gate. + +## Verification commands + +```bash +PYTEST_DISABLE_PLUGIN_AUTOLOAD=1 python3 -m pytest -q scripts/test_update_post_merge_memory.py scripts/test_check_loop_memory_state.py scripts/test_agent_gates.py +python3 scripts/check_internal_review_evidence.py +python3 scripts/check_markdown_links.py docs/operations_post_merge_memory.md .agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation +python3 scripts/check_stale_workstream_wording.py +python3 scripts/update_post_merge_memory.py validate-merge-intent --repository-root . --base-ref origin/main +git diff --check +``` + +## Required reviewers + +- senior engineering +- QA/test +- security/auth +- product/ops +- architecture +- CI integrity +- docs +- reuse/dedup +- test delta + +## Human review focus + +Confirm the certificate is exact, first-parent adjacent, merge-evidence-bound, +fully consumed, and incapable of starting ART PLAN2 successors or unrelated +work. + +## Stop conditions + +Stop if recovery requires an intervening merge, wildcard authority, missing +protected checks, persisted exemption, automatic successor start, or changes +outside the allowed files. diff --git a/.agent-loop/merge-intents/WS-ENG-007-00R6.json b/.agent-loop/merge-intents/WS-ENG-007-00R6.json new file mode 100644 index 00000000..0dddc285 --- /dev/null +++ b/.agent-loop/merge-intents/WS-ENG-007-00R6.json @@ -0,0 +1,9 @@ +{ + "chunk_id": "WS-ENG-007-00R6", + "chunk_title": "ART PLAN2 Signed-Memory Recovery", + "initiative_id": "WS-ENG-007", + "next_chunk_id": "WS-ENG-007-01", + "next_chunk_title": "Reviewed Patch and Base-Delta Reconciliation", + "next_requires_explicit_start": true, + "schema_version": 2 +} diff --git a/.agent-loop/policies/loop-memory-recovery.json b/.agent-loop/policies/loop-memory-recovery.json index 7e93e310..ffe5c6c4 100644 --- a/.agent-loop/policies/loop-memory-recovery.json +++ b/.agent-loop/policies/loop-memory-recovery.json @@ -1,15 +1,15 @@ { "activation": { - "chunk_id": "WS-ENG-007-00R5", + "chunk_id": "WS-ENG-007-00R6", "initiative_id": "WS-ENG-007" }, - "signed_basis": "a3eecadcf847ac70fc28c58dad642f2d761015e0", + "signed_basis": "bba4ba5f171a4438b072740707a5cf8bde49d9af", "recovered_merges": [ { - "chunk_id": "WS-ENG-007-00R4", - "initiative_id": "WS-ENG-007", - "merge_sha": "9bf16d478f669d48172810c83cdf6a7d2b8992ed", - "pr_number": 191 + "chunk_id": "WS-ART-001-PLAN2", + "initiative_id": "WS-ART-001", + "merge_sha": "03a05eeb8f129e0d5f226cc5c058965f43590a81", + "pr_number": 197 } ], "schema_version": 5 diff --git a/docs/operations_post_merge_memory.md b/docs/operations_post_merge_memory.md index 4ff8008d..656e25cd 100644 --- a/docs/operations_post_merge_memory.md +++ b/docs/operations_post_merge_memory.md @@ -314,6 +314,25 @@ The ephemeral recovery-file transport preserves schema v1 at its original two-entry maximum; schema v2 is emitted only for this exact three-entry result and requires exactly three unique entries on every reload. +## WS-ENG-007 ART PLAN2 Recovery + +`WS-ENG-007-00R6` uses the closed schema-v5 certificate after PR #197 merged +planning chunk `WS-ART-001-PLAN2` without its required signed planning start. +The certificate begins at signed basis +`bba4ba5f171a4438b072740707a5cf8bde49d9af` and permits exactly this adjacent +order: + +1. PR #197 / `WS-ART-001-PLAN2` / + `03a05eeb8f129e0d5f226cc5c058965f43590a81`; +2. the direct-next `WS-ENG-007-00R6` activation merge. + +Both records require merge-bound successful `agent-gates` and `test` evidence. +The two temporary exemptions are consumed before signing and cannot persist or +replay. Recovery records ART PLAN2 as completed and stopped at its explicit +`WS-ART-001-03A` gate; it does not start ART, CI, ENG, or any other successor. +Any intervening main merge invalidates adjacency and requires a newly reviewed +certificate. + ## Historical WS-ENG-006 Exact Root Repair `WS-ENG-006-00` uses the closed two-merge recovery certificate to reconcile diff --git a/scripts/test_agent_gates.py b/scripts/test_agent_gates.py index e9a657df..1df48129 100644 --- a/scripts/test_agent_gates.py +++ b/scripts/test_agent_gates.py @@ -2305,16 +2305,16 @@ def test_ws_eng_007_recovery_policy_is_exactly_pinned() -> None: policy = json.loads(Path(".agent-loop/policies/loop-memory-recovery.json").read_text()) assert policy == { "activation": { - "chunk_id": "WS-ENG-007-00R5", + "chunk_id": "WS-ENG-007-00R6", "initiative_id": "WS-ENG-007", }, - "signed_basis": "a3eecadcf847ac70fc28c58dad642f2d761015e0", + "signed_basis": "bba4ba5f171a4438b072740707a5cf8bde49d9af", "recovered_merges": [ { - "chunk_id": "WS-ENG-007-00R4", - "initiative_id": "WS-ENG-007", - "merge_sha": "9bf16d478f669d48172810c83cdf6a7d2b8992ed", - "pr_number": 191, + "chunk_id": "WS-ART-001-PLAN2", + "initiative_id": "WS-ART-001", + "merge_sha": "03a05eeb8f129e0d5f226cc5c058965f43590a81", + "pr_number": 197, }, ], "schema_version": 5, From fc603b4f9fdd2a15aba82b2ab0ebaed7f214c693 Mon Sep 17 00:00:00 2001 From: Abiorh001 Date: Sat, 25 Jul 2026 19:30:26 +0100 Subject: [PATCH 2/8] docs(agent-loop): bind ART PLAN2 recovery review --- ...S-ENG-007-00R6-internal-review-evidence.md | 70 +++++++++++++++++++ .../WS-ENG-007-00R6-pr-trust-bundle.md | 48 +++++++++++++ 2 files changed, 118 insertions(+) create mode 100644 .agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/reviews/WS-ENG-007-00R6-internal-review-evidence.md create mode 100644 .agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/reviews/WS-ENG-007-00R6-pr-trust-bundle.md diff --git a/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/reviews/WS-ENG-007-00R6-internal-review-evidence.md b/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/reviews/WS-ENG-007-00R6-internal-review-evidence.md new file mode 100644 index 00000000..c992e975 --- /dev/null +++ b/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/reviews/WS-ENG-007-00R6-internal-review-evidence.md @@ -0,0 +1,70 @@ +# Internal Review Evidence: WS-ENG-007-00R6 + +## Chunk + +`WS-ENG-007-00R6` — ART PLAN2 Signed-Memory Recovery + +open sub-agent sessions: none + +valid findings addressed: yes + +## Reviewed Revision + +Reviewed code SHA: 609be24d3b5a4825e9dd8f70f3f3f219d041b430 + +Reviewed at: 2026-07-25T18:29:10Z + +After the reviewed SHA, only this evidence and trust reconciliation changed. + +Reviewer run IDs: senior-engineering=`ci02b_lane_runner`; +QA/test=`ci02b_cr_arch`; security/auth=`ci02b_cr_ci`; +product/ops=`ci02b_cr_docs`; architecture=`ci02b_cr_arch`; +CI-integrity=`ci02b_cr_ci`; docs=`ci02b_cr_docs`; +reuse/dedup=`ci02b_cr_reuse`; test-delta=`ci02b_cr_test_delta`. + +## Reviewer Results + +| Reviewer | Result | Blocking findings | Notes | +|---|---:|---|---| +| senior engineering | PASS | None | Direct-next merge and protected evidence remain operational prerequisites. | +| QA/test | PASS | None | Exact basis, adjacency, consumption, replay, and stopped projections are covered. | +| security/auth | PASS | None | Certificate is exact and non-reusable; final evidence was pending during review. | +| product/ops | PASS | None | No product authority or lifecycle behavior changes. | +| architecture | PASS | None | Existing closed schema-v5 recovery path is reused without a parallel mechanism. | +| CI integrity | PASS | None | No workflow or gate weakening; merge-bound checks remain authority. | +| docs | PASS | None | Runbook, map, status, contract, review log, and trust evidence agree. | +| reuse/dedup | PASS | None | No new reducer, policy path, or exemption store. | +| test delta | PASS | None | Exact policy assertion changed; no test was removed, skipped, or weakened. | + +The architecture/QA and docs/CI reviewers initially reported the expected +absence of this final evidence file as blocking publication. This evidence and +the paired trust bundle resolve that publication gate; they do not change the +reviewed recovery behavior. + +## Commands Run + +```bash +PYTEST_DISABLE_PLUGIN_AUTOLOAD=1 python3 -m pytest -q scripts/test_update_post_merge_memory.py scripts/test_check_loop_memory_state.py scripts/test_agent_gates.py +python3 scripts/check_internal_review_evidence.py +python3 scripts/check_markdown_links.py docs/operations_post_merge_memory.md .agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation +python3 scripts/check_stale_workstream_wording.py +python3 scripts/update_post_merge_memory.py validate-merge-intent --repository-root . --base-ref origin/main +git diff --check +``` + +## Results + +- 300 recovery, checker, and Agent Gate tests passed. +- Merge-intent validation, Markdown links, stale wording, and diff integrity + passed. +- Exact policy equality pins the signed basis, PR #197 identity, recovered + merge SHA, R6 activation, and schema version. + +## Remaining Risks + +- R6 must be the direct-next protected-main merge. Any intervening merge + invalidates the certificate and requires a new reviewed recovery plan. +- Both target heads must retain merge-bound successful `agent-gates` and `test` + evidence. +- Successful post-merge automation, not this PR, proves exemption consumption + and restored signed-state continuity. diff --git a/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/reviews/WS-ENG-007-00R6-pr-trust-bundle.md b/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/reviews/WS-ENG-007-00R6-pr-trust-bundle.md new file mode 100644 index 00000000..1e25c86c --- /dev/null +++ b/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/reviews/WS-ENG-007-00R6-pr-trust-bundle.md @@ -0,0 +1,48 @@ +# PR Trust Bundle: WS-ENG-007-00R6 + +## Intent + +Restore signed-memory continuity after unsigned planning merge PR #197 without +granting ART, CI, AUTH, ENG, or product implementation authority. + +## Exact Scope + +- Signed basis: `bba4ba5f171a4438b072740707a5cf8bde49d9af`. +- Recovered predecessor: PR #197 / `WS-ART-001-PLAN2` / + `03a05eeb8f129e0d5f226cc5c058965f43590a81`. +- Activation: only `WS-ENG-007-00R6` as the direct-next main merge. +- Successors remain stopped: ART at `WS-ART-001-03A`, ENG at + `WS-ENG-007-01`; CI-03 still requires its own signed planning start. + +## Reviewed Revision + +`609be24d3b5a4825e9dd8f70f3f3f219d041b430` + +## Evidence + +- 300 recovery, checker, and Agent Gate tests passed. +- Policy regression asserts the complete schema-v5 object exactly. +- Existing behavior tests prove signed-basis matching, ordered adjacency, + merge-bound check selection, exemption consumption, wrong-basis rejection, + and inert replay. +- Merge intent, Markdown links, stale wording, and diff checks passed. + +## Reviewer Results + +All nine required internal tracks completed. No implementation blocker remains. +CI/security and senior engineering retain only the operational risk that any +intervening main merge or missing protected evidence invalidates recovery. + +## Human Review Focus + +- Confirm PR #197 is the only recovered merge. +- Confirm R6 is direct-next on main before merging. +- Confirm both recovered and activation heads have successful merge-bound + `agent-gates` and `test` evidence. +- Confirm the policy and generated result contain no persistent exemption or + automatic successor start. + +## Stop Conditions + +Do not merge if main advances, required checks fail, the reviewed SHA changes +outside evidence-only files, or recovery would need broader authority. From e4f146825013314337708aa71d26b575a8fe0491 Mon Sep 17 00:00:00 2001 From: Abiorh001 Date: Sun, 26 Jul 2026 01:08:58 +0100 Subject: [PATCH 3/8] fix(agent-loop): extend exact recovery sequence --- .agent-loop/REVIEW_LOG.md | 9 +- .../STATUS.md | 6 +- .../WS-ENG-007-00R6-art-plan2-recovery.md | 9 +- .../policies/loop-memory-recovery.json | 8 +- docs/operations_post_merge_memory.md | 10 ++- scripts/test_agent_gates.py | 8 +- scripts/test_update_post_merge_memory.py | 83 +++++++++++++++++++ scripts/update_post_merge_memory.py | 15 ++-- 8 files changed, 127 insertions(+), 21 deletions(-) diff --git a/.agent-loop/REVIEW_LOG.md b/.agent-loop/REVIEW_LOG.md index 62274d3f..0e38aec4 100644 --- a/.agent-loop/REVIEW_LOG.md +++ b/.agent-loop/REVIEW_LOG.md @@ -2944,10 +2944,11 @@ agent-gate pytest cases pass, and the 100 direct regression cases pass. PR #197 merged planning chunk `WS-ART-001-PLAN2` without its required signed planning start, so canonical reconciliation fails closed at merge -`03a05eeb8f129e0d5f226cc5c058965f43590a81`. R6 reuses the closed schema-v5 -recovery engine with signed basis `bba4ba5f171a4438b072740707a5cf8bde49d9af`, -that one exact recovered merge, and only the direct-next R6 activation. Both -temporary exemptions must be merge-evidence-bound, first-parent adjacent, +`03a05eeb8f129e0d5f226cc5c058965f43590a81`. After signed AUTH-11 PR #201 +merged, R6 extends the closed recovery engine with schema v6: signed basis +`bba4ba5f171a4438b072740707a5cf8bde49d9af`, exact PR #197 then exact signed +PR #201, and only the direct-next R6 activation. All three temporary exemptions +must be merge-evidence-bound, first-parent adjacent, consumed before signing, and absent from replay. ART remains stopped at 03A; `WS-CI-001-03`, `WS-ENG-007-01`, and every other successor still require ordinary explicit starts. All nine internal tracks reviewed the bounded recovery; exact final-SHA diff --git a/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/STATUS.md b/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/STATUS.md index 5816a681..17649b58 100644 --- a/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/STATUS.md +++ b/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/STATUS.md @@ -8,13 +8,15 @@ `WS-ENG-007-00R3` - Completed recovery chunks: `WS-ENG-007-00R1` through `WS-ENG-007-00R5` - Unsigned merge requiring recovery: `WS-ART-001-PLAN2` / PR #197 +- Later signed merge in the exact recovery sequence: `WS-AUTH-001-11` / PR #201 - Active recovery chunk: `WS-ENG-007-00R6` - Proposed implementation successor after recovery: `WS-ENG-007-01` - Separate explicit start required: true - Current gate: PR #197 merged as `03a05eeb8f129e0d5f226cc5c058965f43590a81` without a signed planning start. Reconciliation fails closed at that merge, so later explicit starts cannot - reach current main. Signed state remains at merge - `bba4ba5f171a4438b072740707a5cf8bde49d9af` with AUTH-11 active. + reach current main. Signed state remains based at merge + `bba4ba5f171a4438b072740707a5cf8bde49d9af`; AUTH-11 was correctly active + there and its later merge is preserved as the second exact predecessor. - Review gate: R6 exact-head internal review and protected checks required before the user-owned merge decision. diff --git a/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/chunks/WS-ENG-007-00R6-art-plan2-recovery.md b/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/chunks/WS-ENG-007-00R6-art-plan2-recovery.md index 84cded92..4aa6b9d4 100644 --- a/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/chunks/WS-ENG-007-00R6-art-plan2-recovery.md +++ b/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/chunks/WS-ENG-007-00R6-art-plan2-recovery.md @@ -30,6 +30,8 @@ unrecorded predecessor is reconciled. .agent-loop/policies/loop-memory-recovery.json .agent-loop/REVIEW_LOG.md scripts/test_agent_gates.py +scripts/test_update_post_merge_memory.py +scripts/update_post_merge_memory.py docs/operations_post_merge_memory.md .agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/** .agent-loop/merge-intents/WS-ENG-007-00R6.json @@ -38,7 +40,7 @@ docs/operations_post_merge_memory.md ## Not allowed ```text -workflow, updater, checker, permission, CI, test, or coverage behavior changes +workflow, checker, permission, CI, backend test, or coverage behavior changes application, API, database, auth, artifact, payment, or product changes wildcard, persistent, reordered, reusable, or post-signing exemptions automatic ART, CI, AUTH, ENG, or other successor starts @@ -47,8 +49,9 @@ reinterpretation of PR #197 as implementation authority ## Acceptance criteria -- [ ] Schema-v5 recovery binds signed basis `bba4ba5f…` and names only PR #197 / - `WS-ART-001-PLAN2` / `03a05eeb…` as the recovered predecessor. +- [ ] Schema-v6 recovery binds signed basis `bba4ba5f…` and names exactly PR + #197 / `WS-ART-001-PLAN2` / `03a05eeb…` followed by signed PR #201 / + `WS-AUTH-001-11` / `f670b705…` as its two predecessors. - [ ] Activation names only `WS-ENG-007-00R6`; the target identity comes from trusted GitHub merge evidence and must be direct-next on first-parent main. - [ ] Both merges carry successful merge-bound `agent-gates` and `test` diff --git a/.agent-loop/policies/loop-memory-recovery.json b/.agent-loop/policies/loop-memory-recovery.json index ffe5c6c4..f48ba739 100644 --- a/.agent-loop/policies/loop-memory-recovery.json +++ b/.agent-loop/policies/loop-memory-recovery.json @@ -10,7 +10,13 @@ "initiative_id": "WS-ART-001", "merge_sha": "03a05eeb8f129e0d5f226cc5c058965f43590a81", "pr_number": 197 + }, + { + "chunk_id": "WS-AUTH-001-11", + "initiative_id": "WS-AUTH-001", + "merge_sha": "f670b7058c71ad4d11a68c6e242e9fe501ae3aaf", + "pr_number": 201 } ], - "schema_version": 5 + "schema_version": 6 } diff --git a/docs/operations_post_merge_memory.md b/docs/operations_post_merge_memory.md index 656e25cd..9239461f 100644 --- a/docs/operations_post_merge_memory.md +++ b/docs/operations_post_merge_memory.md @@ -316,7 +316,7 @@ and requires exactly three unique entries on every reload. ## WS-ENG-007 ART PLAN2 Recovery -`WS-ENG-007-00R6` uses the closed schema-v5 certificate after PR #197 merged +`WS-ENG-007-00R6` uses the closed schema-v6 certificate after PR #197 merged planning chunk `WS-ART-001-PLAN2` without its required signed planning start. The certificate begins at signed basis `bba4ba5f171a4438b072740707a5cf8bde49d9af` and permits exactly this adjacent @@ -324,10 +324,12 @@ order: 1. PR #197 / `WS-ART-001-PLAN2` / `03a05eeb8f129e0d5f226cc5c058965f43590a81`; -2. the direct-next `WS-ENG-007-00R6` activation merge. +2. signed PR #201 / `WS-AUTH-001-11` / + `f670b7058c71ad4d11a68c6e242e9fe501ae3aaf`; +3. the direct-next `WS-ENG-007-00R6` activation merge. -Both records require merge-bound successful `agent-gates` and `test` evidence. -The two temporary exemptions are consumed before signing and cannot persist or +All three records require merge-bound successful `agent-gates` and `test` +evidence. The three temporary exemptions are consumed before signing and cannot persist or replay. Recovery records ART PLAN2 as completed and stopped at its explicit `WS-ART-001-03A` gate; it does not start ART, CI, ENG, or any other successor. Any intervening main merge invalidates adjacency and requires a newly reviewed diff --git a/scripts/test_agent_gates.py b/scripts/test_agent_gates.py index 1df48129..efa7a37d 100644 --- a/scripts/test_agent_gates.py +++ b/scripts/test_agent_gates.py @@ -2316,8 +2316,14 @@ def test_ws_eng_007_recovery_policy_is_exactly_pinned() -> None: "merge_sha": "03a05eeb8f129e0d5f226cc5c058965f43590a81", "pr_number": 197, }, + { + "chunk_id": "WS-AUTH-001-11", + "initiative_id": "WS-AUTH-001", + "merge_sha": "f670b7058c71ad4d11a68c6e242e9fe501ae3aaf", + "pr_number": 201, + }, ], - "schema_version": 5, + "schema_version": 6, } diff --git a/scripts/test_update_post_merge_memory.py b/scripts/test_update_post_merge_memory.py index fa6e6ed1..87d23c1a 100644 --- a/scripts/test_update_post_merge_memory.py +++ b/scripts/test_update_post_merge_memory.py @@ -2141,6 +2141,89 @@ def test_prepare_recovery_v5_uses_merge_bound_evidence_and_consumes_exact_r4( ) +def test_prepare_recovery_v6_consumes_exact_two_predecessor_sequence( + tmp_path: Path, monkeypatch: pytest.MonkeyPatch, +) -> None: + state_root = tmp_path / "state" + base = _record() + base["source"]["main_sha"] = "a" * 40 + loop.apply_merge_record(state_root, base) + first = _merge_bound_record() + second = _merge_bound_record() + target = _merge_bound_record() + _set_merge_identity( + first, chunk_id="WS-ENG-007-00R4", pr_number=191, + main_sha="c" * 40, first_parent_sha="a" * 40, head_sha="4" * 40, + ) + _set_merge_identity( + second, chunk_id="WS-ENG-007-00R5", pr_number=192, + main_sha="d" * 40, first_parent_sha="c" * 40, head_sha="5" * 40, + ) + _set_merge_identity( + target, chunk_id="WS-ENG-007-00R6", pr_number=202, + main_sha="f" * 40, first_parent_sha="d" * 40, head_sha="6" * 40, + ) + policy = { + "schema_version": 6, + "signed_basis": "a" * 40, + "activation": { + "initiative_id": "WS-ENG-007", "chunk_id": "WS-ENG-007-00R6", + }, + "recovered_merges": [ + { + "initiative_id": "WS-ENG-007", "chunk_id": "WS-ENG-007-00R4", + "pr_number": 191, "merge_sha": "c" * 40, + }, + { + "initiative_id": "WS-ENG-007", "chunk_id": "WS-ENG-007-00R5", + "pr_number": 192, "merge_sha": "d" * 40, + }, + ], + } + records = {"c" * 40: first, "d" * 40: second, "f" * 40: target} + monkeypatch.setattr(loop, "_load_json_at_commit", lambda *_args: policy) + monkeypatch.setattr( + loop, "collect_merge_record", + lambda _client, _repository, sha: json.loads(json.dumps(records[sha])), + ) + monkeypatch.setattr( + loop, "_validate_protected_actions_checks", + lambda *_args: pytest.fail("schema-v6 must not query mutable check authority"), + ) + + planned = ["c" * 40, "d" * 40, "f" * 40] + exemptions = loop.prepare_recovery_exemptions( + object(), "Flow-Research/workstream", repository_root=tmp_path, + state_root=state_root, target_sha="f" * 40, planned_shas=planned, + ) + assert [item["chunk_id"] for item in exemptions] == [ + "WS-ENG-007-00R4", "WS-ENG-007-00R5", "WS-ENG-007-00R6", + ] + assert loop.apply_merge_record(state_root, first, exemptions) + assert loop.apply_merge_record(state_root, second, exemptions) + assert loop.apply_merge_record(state_root, target, exemptions) + loop.assert_recovery_consumed(state_root, "f" * 40, exemptions) + assert loop.prepare_recovery_exemptions( + object(), "Flow-Research/workstream", repository_root=tmp_path, + state_root=state_root, target_sha="f" * 40, planned_shas=[], + ) == [] + + fresh = tmp_path / "wrong-order" + loop.apply_merge_record(fresh, base) + with pytest.raises(loop.LoopMemoryError, match="exact ordered sequence"): + loop.prepare_recovery_exemptions( + object(), "Flow-Research/workstream", repository_root=tmp_path, + state_root=fresh, target_sha="f" * 40, + planned_shas=["d" * 40, "c" * 40, "f" * 40], + ) + with pytest.raises(loop.LoopMemoryError, match="exact ordered sequence"): + loop.prepare_recovery_exemptions( + object(), "Flow-Research/workstream", repository_root=tmp_path, + state_root=fresh, target_sha="f" * 40, + planned_shas=[*planned, "1" * 40], + ) + + def _cross_initiative_merge_bound_state(tmp_path: Path) -> tuple[Path, Path]: state_root, repository_root = tmp_path / "state", tmp_path / "repo" _contract(repository_root) diff --git a/scripts/update_post_merge_memory.py b/scripts/update_post_merge_memory.py index 3a58cb1c..379c3412 100644 --- a/scripts/update_post_merge_memory.py +++ b/scripts/update_post_merge_memory.py @@ -2292,11 +2292,12 @@ def _validate_recovery_policy(payload: Any) -> dict[str, Any]: 3: {"schema_version", "activation", "recovered_merges"}, 4: {"schema_version", "signed_basis", "activation", "recovered_merges"}, 5: {"schema_version", "signed_basis", "activation", "recovered_merges"}, + 6: {"schema_version", "signed_basis", "activation", "recovered_merges"}, }.get(version, set()) if set(payload) != expected: raise LoopMemoryError("recovery policy has an invalid schema") activation = payload.get("activation") - if version not in {1, 2, 3, 4, 5} or not isinstance(activation, dict): + if version not in {1, 2, 3, 4, 5, 6} or not isinstance(activation, dict): raise LoopMemoryError("recovery policy is unsupported") if set(activation) != {"initiative_id", "chunk_id"} or not _is_valid_exemption_id( activation.get("initiative_id"), activation.get("chunk_id") @@ -2306,17 +2307,19 @@ def _validate_recovery_policy(payload: Any) -> dict[str, Any]: if payload.get("mode") != "exact_single_target": raise LoopMemoryError("recovery policy mode is unsupported") return json.loads(_canonical_json(payload)) - if version in {3, 4, 5}: + if version in {3, 4, 5, 6}: recovered_merges = payload.get("recovered_merges") valid_length = ( 1 <= len(recovered_merges) <= 2 if isinstance(recovered_merges, list) and version == 3 else isinstance(recovered_merges, list) - and len(recovered_merges) == (3 if version == 4 else 1) + and len(recovered_merges) == ( + 3 if version == 4 else 1 if version == 5 else 2 + ) ) if not valid_length: raise LoopMemoryError("recovered merge inventory is invalid") - if version in {4, 5}: + if version in {4, 5, 6}: _validate_sha(payload.get("signed_basis")) chunk_identities: set[tuple[str, str]] = set() pr_numbers: set[int] = set() @@ -2430,7 +2433,7 @@ def prepare_recovery_exemptions( if not isinstance(existing, list) or exemption in existing: raise LoopMemoryError("recovery exemption collides with signed state") return [exemption] - if policy["schema_version"] in {3, 4, 5}: + if policy["schema_version"] in {3, 4, 5, 6}: recovered_policies = policy["recovered_merges"] expected_shas = [item["merge_sha"] for item in recovered_policies] + [target_sha] if planned_shas != expected_shas: @@ -2457,7 +2460,7 @@ def prepare_recovery_exemptions( if _event_type(state) in {"start", "cancel"} else state.get("source", {}).get("main_sha") ) - if policy["schema_version"] in {4, 5} and signed_main != policy["signed_basis"]: + if policy["schema_version"] in {4, 5, 6} and signed_main != policy["signed_basis"]: raise LoopMemoryError("recovery signed basis does not match canonical state") records = [*recovered_records, target_record] expected_parent = signed_main From e5e11b29d09d455da281238e1318a8a0629fba2c Mon Sep 17 00:00:00 2001 From: Abiorh001 Date: Sun, 26 Jul 2026 01:15:11 +0100 Subject: [PATCH 4/8] test(agent-loop): prove cross-initiative recovery --- .../CHUNK_MAP.md | 4 +- .../WS-ENG-007-00R6-art-plan2-recovery.md | 4 +- scripts/test_update_post_merge_memory.py | 75 +++++++++++++++++-- 3 files changed, 71 insertions(+), 12 deletions(-) diff --git a/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/CHUNK_MAP.md b/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/CHUNK_MAP.md index 4154abae..7b4cbd04 100644 --- a/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/CHUNK_MAP.md +++ b/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/CHUNK_MAP.md @@ -13,7 +13,7 @@ | 3 | `WS-ENG-007-03` | Add merge-group CI parity and queue-readiness proof | L1 | Blocked on 02 merge and explicit start | Recovery chunks are exceptional ordered prerequisites. `00R6` consumes only -the exact unsigned ART PLAN2 merge and its own activation; it grants no ART or -CI implementation authority. Implementation chunks +the exact unsigned ART PLAN2 merge, the later signed AUTH-11 merge, and its own +activation; it grants no ART, AUTH, or CI implementation authority. Implementation chunks remain one PR each and stop after merge. Every successor requires a separate explicit signed start. diff --git a/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/chunks/WS-ENG-007-00R6-art-plan2-recovery.md b/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/chunks/WS-ENG-007-00R6-art-plan2-recovery.md index 4aa6b9d4..818ba861 100644 --- a/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/chunks/WS-ENG-007-00R6-art-plan2-recovery.md +++ b/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/chunks/WS-ENG-007-00R6-art-plan2-recovery.md @@ -54,9 +54,9 @@ reinterpretation of PR #197 as implementation authority `WS-AUTH-001-11` / `f670b705…` as its two predecessors. - [ ] Activation names only `WS-ENG-007-00R6`; the target identity comes from trusted GitHub merge evidence and must be direct-next on first-parent main. -- [ ] Both merges carry successful merge-bound `agent-gates` and `test` +- [ ] All three records carry successful merge-bound `agent-gates` and `test` provenance; mutable reruns and CodeRabbit are not recovery authority. -- [ ] Both temporary exemptions are consumed before signing and cannot persist, +- [ ] All three temporary exemptions are consumed before signing and cannot persist, replay, reorder, broaden, or authorize a third merge. - [ ] ART PLAN2 reconciles to stopped state with `WS-ART-001-03A` requiring an explicit start; recovery starts no implementation or planning chunk. diff --git a/scripts/test_update_post_merge_memory.py b/scripts/test_update_post_merge_memory.py index 87d23c1a..19240bd6 100644 --- a/scripts/test_update_post_merge_memory.py +++ b/scripts/test_update_post_merge_memory.py @@ -2145,20 +2145,63 @@ def test_prepare_recovery_v6_consumes_exact_two_predecessor_sequence( tmp_path: Path, monkeypatch: pytest.MonkeyPatch, ) -> None: state_root = tmp_path / "state" + repository_root = tmp_path / "repo" + _contract(repository_root) base = _record() - base["source"]["main_sha"] = "a" * 40 + base["source"].update( + main_sha="a" * 40, + intent_path=".agent-loop/merge-intents/WS-AUTH-001-10C.json", + ) + base["completed_chunk"].update( + initiative_id="WS-AUTH-001", chunk_id="WS-AUTH-001-10C", + chunk_title="Project Role Grant Mutations", + next_chunk_id="WS-AUTH-001-11", next_chunk_title="Project Read Cutover", + ) + base["gate"].update( + next_chunk_id="WS-AUTH-001-11", next_chunk_title="Project Read Cutover", + ) loop.apply_merge_record(state_root, base) + auth_start = _event("start", 40) + auth_start.update( + main_sha="a" * 40, + initiative_id="WS-AUTH-001", chunk_id="WS-AUTH-001-11", + ) + assert loop.apply_authority_event( + state_root, auth_start, repository_root=repository_root + ) first = _merge_bound_record() second = _merge_bound_record() target = _merge_bound_record() _set_merge_identity( - first, chunk_id="WS-ENG-007-00R4", pr_number=191, + first, chunk_id="WS-ART-001-PLAN2", pr_number=197, main_sha="c" * 40, first_parent_sha="a" * 40, head_sha="4" * 40, ) + first["source"]["intent_path"] = ( + ".agent-loop/merge-intents/WS-ART-001-PLAN2.json" + ) + first["completed_chunk"].update( + initiative_id="WS-ART-001", chunk_id="WS-ART-001-PLAN2", + chunk_title="Submission Bundle Reconciliation", + next_chunk_id="WS-ART-001-03A", next_chunk_title="Guide Source Byte Ingest", + ) + first["gate"].update( + next_chunk_id="WS-ART-001-03A", next_chunk_title="Guide Source Byte Ingest", + ) _set_merge_identity( - second, chunk_id="WS-ENG-007-00R5", pr_number=192, + second, chunk_id="WS-AUTH-001-11", pr_number=201, main_sha="d" * 40, first_parent_sha="c" * 40, head_sha="5" * 40, ) + second["source"]["intent_path"] = ".agent-loop/merge-intents/WS-AUTH-001-11.json" + second["completed_chunk"].update( + initiative_id="WS-AUTH-001", chunk_id="WS-AUTH-001-11", + chunk_title="Project Read Cutover Planning Parent", + next_chunk_id="WS-AUTH-001-11A", + next_chunk_title="Project Read Catalogue And Projection Foundation", + ) + second["gate"].update( + next_chunk_id="WS-AUTH-001-11A", + next_chunk_title="Project Read Catalogue And Projection Foundation", + ) _set_merge_identity( target, chunk_id="WS-ENG-007-00R6", pr_number=202, main_sha="f" * 40, first_parent_sha="d" * 40, head_sha="6" * 40, @@ -2171,12 +2214,12 @@ def test_prepare_recovery_v6_consumes_exact_two_predecessor_sequence( }, "recovered_merges": [ { - "initiative_id": "WS-ENG-007", "chunk_id": "WS-ENG-007-00R4", - "pr_number": 191, "merge_sha": "c" * 40, + "initiative_id": "WS-ART-001", "chunk_id": "WS-ART-001-PLAN2", + "pr_number": 197, "merge_sha": "c" * 40, }, { - "initiative_id": "WS-ENG-007", "chunk_id": "WS-ENG-007-00R5", - "pr_number": 192, "merge_sha": "d" * 40, + "initiative_id": "WS-AUTH-001", "chunk_id": "WS-AUTH-001-11", + "pr_number": 201, "merge_sha": "d" * 40, }, ], } @@ -2197,7 +2240,7 @@ def test_prepare_recovery_v6_consumes_exact_two_predecessor_sequence( state_root=state_root, target_sha="f" * 40, planned_shas=planned, ) assert [item["chunk_id"] for item in exemptions] == [ - "WS-ENG-007-00R4", "WS-ENG-007-00R5", "WS-ENG-007-00R6", + "WS-ART-001-PLAN2", "WS-AUTH-001-11", "WS-ENG-007-00R6", ] assert loop.apply_merge_record(state_root, first, exemptions) assert loop.apply_merge_record(state_root, second, exemptions) @@ -2207,6 +2250,22 @@ def test_prepare_recovery_v6_consumes_exact_two_predecessor_sequence( object(), "Flow-Research/workstream", repository_root=tmp_path, state_root=state_root, target_sha="f" * 40, planned_shas=[], ) == [] + latest = loop._latest_by_initiative( + loop._validate_ledger_entries(loop._load_ledger(state_root / loop.LEDGER_PATH)) + ) + assert latest["WS-ART-001"]["active"] == { + "planning_chunk": None, "implementation_chunk": None, + } + assert latest["WS-ART-001"]["gate"]["next_chunk_id"] == "WS-ART-001-03A" + assert latest["WS-AUTH-001"]["active"] == { + "planning_chunk": None, "implementation_chunk": None, + } + assert latest["WS-AUTH-001"]["gate"]["next_chunk_id"] == "WS-AUTH-001-11A" + assert latest["WS-ENG-007"]["active"] == { + "planning_chunk": None, "implementation_chunk": None, + } + assert latest["WS-ENG-007"]["gate"]["next_chunk_id"] == "WS-ENG-007-01" + loop.validate_generated_state(state_root) fresh = tmp_path / "wrong-order" loop.apply_merge_record(fresh, base) From f3eab24ecac32f959933369c1b5342bc901c7153 Mon Sep 17 00:00:00 2001 From: Abiorh001 Date: Sun, 26 Jul 2026 01:17:29 +0100 Subject: [PATCH 5/8] docs(agent-loop): clarify recovery cardinality --- .../chunks/WS-ENG-007-00R6-art-plan2-recovery.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/chunks/WS-ENG-007-00R6-art-plan2-recovery.md b/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/chunks/WS-ENG-007-00R6-art-plan2-recovery.md index 818ba861..5385b99f 100644 --- a/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/chunks/WS-ENG-007-00R6-art-plan2-recovery.md +++ b/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/chunks/WS-ENG-007-00R6-art-plan2-recovery.md @@ -57,7 +57,7 @@ reinterpretation of PR #197 as implementation authority - [ ] All three records carry successful merge-bound `agent-gates` and `test` provenance; mutable reruns and CodeRabbit are not recovery authority. - [ ] All three temporary exemptions are consumed before signing and cannot persist, - replay, reorder, broaden, or authorize a third merge. + replay, reorder, broaden, or authorize a fourth or additional merge. - [ ] ART PLAN2 reconciles to stopped state with `WS-ART-001-03A` requiring an explicit start; recovery starts no implementation or planning chunk. - [ ] Exactly one merge intent stops ENG-007 at its existing `01` gate. From 1917b6f825e1f96376e939f7bbba4c6f275fa58d Mon Sep 17 00:00:00 2001 From: Abiorh001 Date: Sun, 26 Jul 2026 01:20:04 +0100 Subject: [PATCH 6/8] docs(agent-loop): bind schema-v6 recovery review --- ...S-ENG-007-00R6-internal-review-evidence.md | 33 ++++++++++--------- .../WS-ENG-007-00R6-pr-trust-bundle.md | 22 ++++++++----- 2 files changed, 32 insertions(+), 23 deletions(-) diff --git a/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/reviews/WS-ENG-007-00R6-internal-review-evidence.md b/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/reviews/WS-ENG-007-00R6-internal-review-evidence.md index c992e975..a3433e1b 100644 --- a/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/reviews/WS-ENG-007-00R6-internal-review-evidence.md +++ b/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/reviews/WS-ENG-007-00R6-internal-review-evidence.md @@ -10,9 +10,9 @@ valid findings addressed: yes ## Reviewed Revision -Reviewed code SHA: 609be24d3b5a4825e9dd8f70f3f3f219d041b430 +Reviewed code SHA: f3eab24ecac32f959933369c1b5342bc901c7153 -Reviewed at: 2026-07-25T18:29:10Z +Reviewed at: 2026-07-26T00:19:17Z After the reviewed SHA, only this evidence and trust reconciliation changed. @@ -26,20 +26,21 @@ reuse/dedup=`ci02b_cr_reuse`; test-delta=`ci02b_cr_test_delta`. | Reviewer | Result | Blocking findings | Notes | |---|---:|---|---| -| senior engineering | PASS | None | Direct-next merge and protected evidence remain operational prerequisites. | -| QA/test | PASS | None | Exact basis, adjacency, consumption, replay, and stopped projections are covered. | -| security/auth | PASS | None | Certificate is exact and non-reusable; final evidence was pending during review. | +| senior engineering | PASS | None | Three-record cardinality and direct-next merge wording are exact. | +| QA/test | PASS | None | Cross-initiative ART, AUTH, and ENG recovery and stopped projections are covered. | +| security/auth | PASS | None | Certificate is exact, ordered, merge-bound, consumed, and non-reusable. | | product/ops | PASS | None | No product authority or lifecycle behavior changes. | -| architecture | PASS | None | Existing closed schema-v5 recovery path is reused without a parallel mechanism. | +| architecture | PASS | None | Existing closed recovery path is extended to schema v6 without a parallel mechanism. | | CI integrity | PASS | None | No workflow or gate weakening; merge-bound checks remain authority. | | docs | PASS | None | Runbook, map, status, contract, review log, and trust evidence agree. | | reuse/dedup | PASS | None | No new reducer, policy path, or exemption store. | | test delta | PASS | None | Exact policy assertion changed; no test was removed, skipped, or weakened. | -The architecture/QA and docs/CI reviewers initially reported the expected -absence of this final evidence file as blocking publication. This evidence and -the paired trust bundle resolve that publication gate; they do not change the -reviewed recovery behavior. +The first review pass found stale evidence wording and a missing exact +cross-initiative recovery proof. The repair models signed-active AUTH-11, +ART PLAN2 recovery, AUTH-11 completion, and ENG R6 while proving all successors +remain stopped. The final pass resolved a cardinality wording ambiguity. All +reviewers passed exact SHA `f3eab24ecac32f959933369c1b5342bc901c7153`. ## Commands Run @@ -54,17 +55,19 @@ git diff --check ## Results -- 300 recovery, checker, and Agent Gate tests passed. +- 301 recovery, checker, and Agent Gate tests passed. - Merge-intent validation, Markdown links, stale wording, and diff integrity passed. -- Exact policy equality pins the signed basis, PR #197 identity, recovered - merge SHA, R6 activation, and schema version. +- Exact policy equality pins schema v6, the signed basis, PR #197, signed PR + #201, and R6 activation. The cross-initiative regression proves exact order, + full consumption, inert replay, stopped projections, and rejection of a + reordered or additional merge. ## Remaining Risks - R6 must be the direct-next protected-main merge. Any intervening merge invalidates the certificate and requires a new reviewed recovery plan. -- Both target heads must retain merge-bound successful `agent-gates` and `test` - evidence. +- All three target heads must retain merge-bound successful `agent-gates` and + `test` evidence. - Successful post-merge automation, not this PR, proves exemption consumption and restored signed-state continuity. diff --git a/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/reviews/WS-ENG-007-00R6-pr-trust-bundle.md b/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/reviews/WS-ENG-007-00R6-pr-trust-bundle.md index 1e25c86c..cbd54502 100644 --- a/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/reviews/WS-ENG-007-00R6-pr-trust-bundle.md +++ b/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/reviews/WS-ENG-007-00R6-pr-trust-bundle.md @@ -8,23 +8,29 @@ granting ART, CI, AUTH, ENG, or product implementation authority. ## Exact Scope - Signed basis: `bba4ba5f171a4438b072740707a5cf8bde49d9af`. -- Recovered predecessor: PR #197 / `WS-ART-001-PLAN2` / +- First recovered predecessor: PR #197 / `WS-ART-001-PLAN2` / `03a05eeb8f129e0d5f226cc5c058965f43590a81`. +- Second recovered predecessor: signed PR #201 / `WS-AUTH-001-11` / + `f670b7058c71ad4d11a68c6e242e9fe501ae3aaf`. - Activation: only `WS-ENG-007-00R6` as the direct-next main merge. -- Successors remain stopped: ART at `WS-ART-001-03A`, ENG at - `WS-ENG-007-01`; CI-03 still requires its own signed planning start. +- Successors remain stopped: ART at `WS-ART-001-03A`, AUTH at + `WS-AUTH-001-11A`, and ENG at `WS-ENG-007-01`; CI-03 still requires its own + signed planning start. ## Reviewed Revision -`609be24d3b5a4825e9dd8f70f3f3f219d041b430` +`f3eab24ecac32f959933369c1b5342bc901c7153` ## Evidence -- 300 recovery, checker, and Agent Gate tests passed. -- Policy regression asserts the complete schema-v5 object exactly. +- 301 recovery, checker, and Agent Gate tests passed. +- Policy regression asserts the complete schema-v6 object exactly. - Existing behavior tests prove signed-basis matching, ordered adjacency, merge-bound check selection, exemption consumption, wrong-basis rejection, and inert replay. +- The exact cross-initiative regression proves ART PLAN2 recovery while AUTH-11 + is signed-active, AUTH-11 completion, ENG R6 activation, and stopped successor + projections for all three initiatives. - Merge intent, Markdown links, stale wording, and diff checks passed. ## Reviewer Results @@ -35,9 +41,9 @@ intervening main merge or missing protected evidence invalidates recovery. ## Human Review Focus -- Confirm PR #197 is the only recovered merge. +- Confirm PR #197 then signed PR #201 are the only recovered predecessors. - Confirm R6 is direct-next on main before merging. -- Confirm both recovered and activation heads have successful merge-bound +- Confirm both recovered predecessors and the activation head have successful merge-bound `agent-gates` and `test` evidence. - Confirm the policy and generated result contain no persistent exemption or automatic successor start. From 7a22070fe66770fc229671421ab0a899c9b2c97d Mon Sep 17 00:00:00 2001 From: Abiorh001 Date: Sun, 26 Jul 2026 01:31:05 +0100 Subject: [PATCH 7/8] docs(agent-loop): disposition R6 external review --- .agent-loop/REVIEW_LOG.md | 6 +++ ...S-ENG-007-00R6-external-review-response.md | 42 +++++++++++++++++++ .../WS-ENG-007-00R6-pr-trust-bundle.md | 5 +++ 3 files changed, 53 insertions(+) create mode 100644 .agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/reviews/WS-ENG-007-00R6-external-review-response.md diff --git a/.agent-loop/REVIEW_LOG.md b/.agent-loop/REVIEW_LOG.md index 0e38aec4..253b4ea2 100644 --- a/.agent-loop/REVIEW_LOG.md +++ b/.agent-loop/REVIEW_LOG.md @@ -2953,3 +2953,9 @@ consumed before signing, and absent from replay. ART remains stopped at 03A; `WS-CI-001-03`, `WS-ENG-007-01`, and every other successor still require ordinary explicit starts. All nine internal tracks reviewed the bounded recovery; exact final-SHA evidence and protected GitHub checks remain required. + +CodeRabbit's final-head review raised two stale-context findings: it treated the +superseded `609be24d` revision as current and proposed omitting signed PR #201 +from the first-parent recovery chain. The external-review response records why +final code review is bound to `f3eab24e` and why exact PR #201 reconciliation is +mandatory rather than expanded authority. diff --git a/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/reviews/WS-ENG-007-00R6-external-review-response.md b/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/reviews/WS-ENG-007-00R6-external-review-response.md new file mode 100644 index 00000000..1346df31 --- /dev/null +++ b/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/reviews/WS-ENG-007-00R6-external-review-response.md @@ -0,0 +1,42 @@ +# External Review Response: WS-ENG-007-00R6 + +## Comments addressed + +- CodeRabbit reported that review evidence should bind `609be24d`. That SHA was + the obsolete pre-PR-201 recovery revision named by the stale PR description. + All nine internal tracks reran against final recovery code SHA + `f3eab24ecac32f959933369c1b5342bc901c7153`; the evidence-only publication + commit is `1917b6f825e1f96376e939f7bbba4c6f275fa58d`. The PR description is updated + from the current trust bundle. +- CodeRabbit proposed limiting schema v6 to PR #197 alone. That would be + incorrect because protected main contains signed AUTH-11 PR #201 immediately + after PR #197. Recovery cannot skip that first-parent commit. Schema v6 + accepts exactly two recovered records, and the production certificate pins + them to PR #197 then PR #201. Runtime plan equality, first-parent adjacency, + merge-bound checks, uniqueness, consumption, replay, reorder, and extra-merge + tests prevent broader authority. + +## Comments deferred + +None. + +## Human decisions needed + +None. Both findings were based on stale PR context rather than a valid code or +policy defect. + +## Commands rerun + +```bash +PYTEST_DISABLE_PLUGIN_AUTOLOAD=1 python3 -m pytest -q scripts/test_update_post_merge_memory.py scripts/test_check_loop_memory_state.py scripts/test_agent_gates.py +python3 scripts/check_internal_review_evidence.py +python3 scripts/check_markdown_links.py docs/operations_post_merge_memory.md .agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation +python3 scripts/check_stale_workstream_wording.py +python3 scripts/update_post_merge_memory.py validate-merge-intent --repository-root . --base-ref origin/main +git diff --check +``` + +## Remaining risks + +PR #202 must remain the direct-next main merge. Any intervening main merge +invalidates the exact certificate and requires another reviewed reconciliation. diff --git a/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/reviews/WS-ENG-007-00R6-pr-trust-bundle.md b/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/reviews/WS-ENG-007-00R6-pr-trust-bundle.md index cbd54502..9f894afd 100644 --- a/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/reviews/WS-ENG-007-00R6-pr-trust-bundle.md +++ b/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/reviews/WS-ENG-007-00R6-pr-trust-bundle.md @@ -39,6 +39,11 @@ All nine required internal tracks completed. No implementation blocker remains. CI/security and senior engineering retain only the operational risk that any intervening main merge or missing protected evidence invalidates recovery. +CodeRabbit's two comments were dispositioned as stale-context findings. The +external-review response records why the reviewed SHA is `f3eab24e` and why +signed PR #201 is a mandatory exact predecessor rather than broadened recovery +authority. + ## Human Review Focus - Confirm PR #197 then signed PR #201 are the only recovered predecessors. From 79557119810b2764cfd57beda6926b4c9239d41a Mon Sep 17 00:00:00 2001 From: Abiorh001 Date: Sun, 26 Jul 2026 01:35:09 +0100 Subject: [PATCH 8/8] docs(agent-loop): bind R6 external review --- .../reviews/WS-ENG-007-00R6-internal-review-evidence.md | 9 ++++++--- .../reviews/WS-ENG-007-00R6-pr-trust-bundle.md | 8 +++++--- 2 files changed, 11 insertions(+), 6 deletions(-) diff --git a/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/reviews/WS-ENG-007-00R6-internal-review-evidence.md b/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/reviews/WS-ENG-007-00R6-internal-review-evidence.md index a3433e1b..82de55bf 100644 --- a/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/reviews/WS-ENG-007-00R6-internal-review-evidence.md +++ b/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/reviews/WS-ENG-007-00R6-internal-review-evidence.md @@ -10,9 +10,9 @@ valid findings addressed: yes ## Reviewed Revision -Reviewed code SHA: f3eab24ecac32f959933369c1b5342bc901c7153 +Reviewed code SHA: 7a22070fe66770fc229671421ab0a899c9b2c97d -Reviewed at: 2026-07-26T00:19:17Z +Reviewed at: 2026-07-26T00:27:00Z After the reviewed SHA, only this evidence and trust reconciliation changed. @@ -40,7 +40,10 @@ The first review pass found stale evidence wording and a missing exact cross-initiative recovery proof. The repair models signed-active AUTH-11, ART PLAN2 recovery, AUTH-11 completion, and ENG R6 while proving all successors remain stopped. The final pass resolved a cardinality wording ambiguity. All -reviewers passed exact SHA `f3eab24ecac32f959933369c1b5342bc901c7153`. +reviewers passed recovery code SHA `f3eab24ecac32f959933369c1b5342bc901c7153`. +All tracks then reviewed the CodeRabbit disposition and durable review-log +delta at exact SHA `7a22070fe66770fc229671421ab0a899c9b2c97d`; +no authority, code, test, CI, or product behavior changed in that delta. ## Commands Run diff --git a/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/reviews/WS-ENG-007-00R6-pr-trust-bundle.md b/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/reviews/WS-ENG-007-00R6-pr-trust-bundle.md index 9f894afd..505dd16e 100644 --- a/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/reviews/WS-ENG-007-00R6-pr-trust-bundle.md +++ b/.agent-loop/initiatives/WS-ENG-007-concurrent-pr-review-reconciliation/reviews/WS-ENG-007-00R6-pr-trust-bundle.md @@ -14,12 +14,14 @@ granting ART, CI, AUTH, ENG, or product implementation authority. `f670b7058c71ad4d11a68c6e242e9fe501ae3aaf`. - Activation: only `WS-ENG-007-00R6` as the direct-next main merge. - Successors remain stopped: ART at `WS-ART-001-03A`, AUTH at - `WS-AUTH-001-11A`, and ENG at `WS-ENG-007-01`; CI-03 still requires its own - signed planning start. + `WS-AUTH-001-11A`, and ENG at `WS-ENG-007-01`; `WS-CI-001-03` still requires + its own signed planning start. ## Reviewed Revision -`f3eab24ecac32f959933369c1b5342bc901c7153` +`7a22070fe66770fc229671421ab0a899c9b2c97d` + +Recovery code revision: `f3eab24ecac32f959933369c1b5342bc901c7153`. ## Evidence