Repository navigation
[PILOT-11] Enforce requires_second_review=false #498
Copy link
Copy link
Closed
Labels
area/backendBackend API, data model, migrations, services, repositoriesBackend API, data model, migrations, services, repositoriesarea/pilotReal pilot tasks, batch runs, metrics, reportsReal pilot tasks, batch runs, metrics, reportsarea/reviewHuman review, findings, review packets, reviewer qualityHuman review, findings, review packets, reviewer qualityenhancementNew feature or requestNew feature or requestfocus/v0.1Current Workstream v0.1 roadmap focus; open to contributors unless explicitly assignedCurrent Workstream v0.1 roadmap focus; open to contributors unless explicitly assignedstatus/needs-scopeNeeds maintainer scoping before implementationNeeds maintainer scoping before implementation
Description
Activity
- addedenhancementNew feature or requestNew feature or requestarea/backendBackend API, data model, migrations, services, repositoriesBackend API, data model, migrations, services, repositoriesarea/reviewHuman review, findings, review packets, reviewer qualityHuman review, findings, review packets, reviewer qualityarea/pilotReal pilot tasks, batch runs, metrics, reportsReal pilot tasks, batch runs, metrics, reportsstatus/needs-scopeNeeds maintainer scoping before implementationNeeds maintainer scoping before implementationfocus/v0.1Current Workstream v0.1 roadmap focus; open to contributors unless explicitly assignedCurrent Workstream v0.1 roadmap focus; open to contributors unless explicitly assigned
on Oct 7, 2026 - changed the title
[-]Pilot cleanup: enforce requires_second_review=false without changing retained policy facts[/-][+][PILOT-11] Enforce requires_second_review=false[/+]on Oct 7, 2026 Completed by merged PR #502: #502 (merge 9f774cb; reviewed head 08bb029). Review verified public TRUE rejection, direct PostgreSQL enforcement, retained-TRUE migration refusal with unchanged evidence, supported FALSE hashes/lineage, and shared consumers. Fresh CI completed 8,733 unique backend tests with zero skips/deselections plus 57 CLI tests; independent canonical evidence validation and scoped reviews passed. No second-review or adjudication workflow was introduced.
Metadata
Metadata
Assignees
Labels
area/backendBackend API, data model, migrations, services, repositoriesBackend API, data model, migrations, services, repositoriesarea/pilotReal pilot tasks, batch runs, metrics, reportsReal pilot tasks, batch runs, metrics, reportsarea/reviewHuman review, findings, review packets, reviewer qualityHuman review, findings, review packets, reviewer qualityenhancementNew feature or requestNew feature or requestfocus/v0.1Current Workstream v0.1 roadmap focus; open to contributors unless explicitly assignedCurrent Workstream v0.1 roadmap focus; open to contributors unless explicitly assignedstatus/needs-scopeNeeds maintainer scoping before implementationNeeds maintainer scoping before implementation
Completion and evidence
Closed as completed after the human merge of PR #502 (merge
9f774cbbaa84583e19042affc22c7f78b87b50d1, reviewed head08bb029d4167f74f418e0216dbbd23673ee579d9). The fresh Backend run passed all nine lanes and aggregate: 8,733 unique backend tests completed, zero skips/deselections, plus 57 CLI tests. Its tested merge59684d03b4ca528ecf27a3a1c4ae9c8bbd3be0f3has the reviewed source tree. Independent canonical evidence validation and scoped internal reviews passed.Real PostgreSQL tests proved public true-input rejection without selector advancement, direct-write enforcement, retained-true refusal without changed rows/hashes/selectors/revision, and unchanged supported false policy lineage after upgrade. All nine lane database/storage cleanup records passed. No second-review/adjudication lifecycle or payment fulfillment was added.
Outcome and existing work
Adjudication/second-review implementation is deferred. Reject
requires_second_review=trueat current policy input and persisted boundaries, while already-false policy hashes remain unchanged.The prerequisite "Remove obsolete TASK payment policy storage" is delivered by merged PR #487, recorded in
.commitrail/changes/remove-obsolete-task-payment-policy.md. Migration 0023 removed the obsolete guide-keyed PaymentPolicy and TASK/Submission fields while preserving current ContributionPolicy/award lineage. This issue owns only the second-review restriction, delivered by merged PR #502. Do not repeat the payment cleanup. Contributor display of existing locked compensation terms is separate open work in PILOT-14 / #506.Scope and owners
Inspect
backend/app/modules/projects/schemas.py,backend/app/modules/projects/api/policy_lineage.py, project policy models/activation, canonical policy hashes, migrations and direct/bulk write callers.Literal[False] = Falsein input and exact lineage contracts; enforce the same invariant at model/database boundary, including raw writes.Leave alone
No ContributionPolicy/award changes, second reviewer/adjudication workflow, deleting retained rows, new compatibility path or rerunning payment cleanup under a new owner. Historical specifications/migrations are not blanket deletion targets.
Acceptance and how to check
Working and verification rules
Read
AGENTS.md,CONTRIBUTING.md,docs/roadmap_status.mdand the affected owner contracts before coding. The baseline inspected for this plan is mainc0c4fe70f77e2e84347cec979e3de00e9d7f4295; recheck current main and open PRs before selecting a bounded implementation. Open/planned work is not delivered capability.This is a planning issue and may require several bounded PRs. Record each PR's allowed files, prohibited changes, acceptance criteria and review scope using the repository's existing Commitrail process. Extend existing owner operations/typed public ports; do not add parallel legacy/new implementations or bypass authority. Preserve retained data, locked lineage, immutable evidence and caller-owned atomicity. A planning issue does not authorize deployment or merging a PR.
Run focused positive/negative tests and applicable repository checks. Use real PostgreSQL for database/locking claims and MinIO/S3 for storage claims. Add regressions that fail on the reproduced defect; do not skip failing tests or weaken CI. Run required full CI and affected independent review tracks before requesting human approval. Update affected current specs/ADRs, README/CLI contracts and roadmap in the same PR. Report exact tested head, commands, failure/cleanup evidence and remaining limitations; passing counts alone are insufficient.