Skip to content

[PILOT-11] Enforce requires_second_review=false #498

Description

@Abiorh001

Completion and evidence

Closed as completed after the human merge of PR #502 (merge 9f774cbbaa84583e19042affc22c7f78b87b50d1, reviewed head 08bb029d4167f74f418e0216dbbd23673ee579d9). The fresh Backend run passed all nine lanes and aggregate: 8,733 unique backend tests completed, zero skips/deselections, plus 57 CLI tests. Its tested merge 59684d03b4ca528ecf27a3a1c4ae9c8bbd3be0f3 has the reviewed source tree. Independent canonical evidence validation and scoped internal reviews passed.

Real PostgreSQL tests proved public true-input rejection without selector advancement, direct-write enforcement, retained-true refusal without changed rows/hashes/selectors/revision, and unchanged supported false policy lineage after upgrade. All nine lane database/storage cleanup records passed. No second-review/adjudication lifecycle or payment fulfillment was added.

Outcome and existing work

Adjudication/second-review implementation is deferred. Reject requires_second_review=true at current policy input and persisted boundaries, while already-false policy hashes remain unchanged.

The prerequisite "Remove obsolete TASK payment policy storage" is delivered by merged PR #487, recorded in .commitrail/changes/remove-obsolete-task-payment-policy.md. Migration 0023 removed the obsolete guide-keyed PaymentPolicy and TASK/Submission fields while preserving current ContributionPolicy/award lineage. This issue owns only the second-review restriction, delivered by merged PR #502. Do not repeat the payment cleanup. Contributor display of existing locked compensation terms is separate open work in PILOT-14 / #506.

Scope and owners

Inspect backend/app/modules/projects/schemas.py, backend/app/modules/projects/api/policy_lineage.py, project policy models/activation, canonical policy hashes, migrations and direct/bulk write callers.

  • Use Literal[False] = False in input and exact lineage contracts; enforce the same invariant at model/database boundary, including raw writes.
  • Preflight retained true values before adding a constraint. Refuse unsafe upgrade without a separately documented preservation/disposition design; never silently rewrite/rehash locked policy facts.
  • Update affected compiler, public schemas/CLI/MCP contracts, fixtures and current docs. Retain tests for required lineage and hash custody; remove only obsolete behavior tests.

Leave alone

No ContributionPolicy/award changes, second reviewer/adjudication workflow, deleting retained rows, new compatibility path or rerunning payment cleanup under a new owner. Historical specifications/migrations are not blanket deletion targets.

Acceptance and how to check

  • Input true returns 422; supported false/omitted values preserve existing canonical policy hash.
  • Real PostgreSQL/direct-write checks enforce false rather than relying only on API validation.
  • Migration on a disposable DB with retained true facts refuses with evidence intact; ordinary already-false upgrade succeeds without changed hashes/lineage.
  • Shared policy consumers, activation, replay and public contracts pass affected regressions/full required checks, without bypass or skipped tests.

Working and verification rules

Read AGENTS.md, CONTRIBUTING.md, docs/roadmap_status.md and the affected owner contracts before coding. The baseline inspected for this plan is main c0c4fe70f77e2e84347cec979e3de00e9d7f4295; recheck current main and open PRs before selecting a bounded implementation. Open/planned work is not delivered capability.

This is a planning issue and may require several bounded PRs. Record each PR's allowed files, prohibited changes, acceptance criteria and review scope using the repository's existing Commitrail process. Extend existing owner operations/typed public ports; do not add parallel legacy/new implementations or bypass authority. Preserve retained data, locked lineage, immutable evidence and caller-owned atomicity. A planning issue does not authorize deployment or merging a PR.

Run focused positive/negative tests and applicable repository checks. Use real PostgreSQL for database/locking claims and MinIO/S3 for storage claims. Add regressions that fail on the reproduced defect; do not skip failing tests or weaken CI. Run required full CI and affected independent review tracks before requesting human approval. Update affected current specs/ADRs, README/CLI contracts and roadmap in the same PR. Report exact tested head, commands, failure/cleanup evidence and remaining limitations; passing counts alone are insufficient.

Activity

  1. added
    enhancementNew feature or request
    area/backendBackend API, data model, migrations, services, repositories
    area/reviewHuman review, findings, review packets, reviewer quality
    area/pilotReal pilot tasks, batch runs, metrics, reports
    status/needs-scopeNeeds maintainer scoping before implementation
    focus/v0.1Current Workstream v0.1 roadmap focus; open to contributors unless explicitly assigned
    on Oct 7, 2026
  2. changed the title [-]Pilot cleanup: enforce requires_second_review=false without changing retained policy facts[/-] [+][PILOT-11] Enforce requires_second_review=false[/+] on Oct 7, 2026
  3. Abiorh001 commented on Oct 8, 2026

    @Abiorh001
    CollaboratorAuthor

    Completed by merged PR #502: #502 (merge 9f774cb; reviewed head 08bb029). Review verified public TRUE rejection, direct PostgreSQL enforcement, retained-TRUE migration refusal with unchanged evidence, supported FALSE hashes/lineage, and shared consumers. Fresh CI completed 8,733 unique backend tests with zero skips/deselections plus 57 CLI tests; independent canonical evidence validation and scoped reviews passed. No second-review or adjudication workflow was introduced.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area/backendBackend API, data model, migrations, services, repositoriesarea/pilotReal pilot tasks, batch runs, metrics, reportsarea/reviewHuman review, findings, review packets, reviewer qualityenhancementNew feature or requestfocus/v0.1Current Workstream v0.1 roadmap focus; open to contributors unless explicitly assignedstatus/needs-scopeNeeds maintainer scoping before implementation

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions