Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
20 commits
Select commit Hold shift + click to select a range
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
32 changes: 21 additions & 11 deletions .agent-loop/LOOP_STATE.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,29 +5,39 @@
- This authored file is reviewed planning/history context, not canonical live
post-merge state. Canonical state is the signed schema-v2 output on
`automation/loop-memory`.
- Active initiative: none recorded here
- Active initiative: `WS-AUTH-001` - Workstream Authorization Service
- Active planning chunk: none
- Active implementation chunk: none
- Active implementation chunk: `WS-AUTH-001-07A` - Closed Permission And Action
Catalogue
- Current branch: `codex/ws-auth-001-07-authorization-kernel`
- Start basis: the user explicitly started AUTH-07 after PR #124 merged AUTH-06
as `f599551`; signed merge state required a separate explicit start.
- PR #119 merged `WS-AUTH-001-05B` as `ad71c7e`.
- PR #120 merged `WS-ART-001-OBJECT-STORAGE-AMENDMENT` as `4408256`.
- PR #122 merged the first automated post-merge memory implementation as
`fc89fb6`; its schema-v1 cross-initiative next pointer is superseded by the
schema-v2 initiative-local clean cut.
- Current gate: no product chunk is selected by this authored file. A human
must explicitly start one candidate after reading current signed state.
- Current gate: AUTH-07A's canonical review/revision amendment passed every
required internal reviewer track at `160af8a`; deterministic evidence is
complete and PR #126 awaits external checks and explicit human approval.
- Scope checkpoint: AWS S3 is the only v0.1 production provider; MinIO is
local/CI S3 protocol proof; LocalStorage is focused development/test; R2 and
Flow Node are deferred. Product modules receive narrow artifact capabilities,
and AWS cannot instantiate in production without release-bound live proof.
- Authorization checkpoint: the approved catalogue contains 73 identifiers,
including 21 artifact permissions. AUTH-07 registers them, AUTH-08 defines
- Authorization checkpoint: the approved catalogue contains 74 PermissionIds
and 50 planned ActionIds, including 21 artifact permissions and one additive
`review.queue.override` permission. AUTH-07 registers them, AUTH-08 defines
applicable Operator grants, AUTH-09 provisions fixed service principals, and
each owning WS-ART feature chunk activates only its own canonical actions.
- Next artifact candidate: `WS-ART-001-02A1` remains inactive until the user
gives a separate explicit start signal.
- Parallel authorization work: `WS-AUTH-001-05B` merged through PR #119 as
`ad71c7e`. `WS-AUTH-001-06` remains inactive pending a separate explicit
user start.
- Parallel artifact checkpoint: `WS-ART-001-02A1` was explicitly started and
merged through PR #127 as `f64a8e5`; it is at the post-merge memory/stop
checkpoint. `WS-ART-001-02A2` remains inactive until signed memory completes
and the user gives a separate explicit start signal.
- Authorization checkpoint: `WS-AUTH-001-06` merged through PR #124 as
`f599551`. The user separately started parent `WS-AUTH-001-07`; required L1
review split it into 07A/07B before runtime implementation. AUTH-07B and
AUTH-08 remain inactive until their predecessor merges, automated memory
completes, and the user gives another explicit start.
- Parallel coverage work: `WS-QUAL-001-01B2` remains paused. Its last official
whole-app result is `6466/8159` statements (`79.249908%`); no replacement
evidence exists.
Expand Down
92 changes: 92 additions & 0 deletions .agent-loop/REVIEW_LOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,97 @@
# Review Log

## 2026-07-15 - WS-AUTH-001-07A Canonical Review Amendment Passed

Exact reviewed head `160af8afd030f042ee72ec963e6f47cd8b7d4c9a` reserves
the canonical `submission.create` dependency and 19 review actions. The closed
catalogue is now exactly 74 PermissionIds and 50 planned ActionIds; only
`review.queue.override` is additive. Initial and revision submissions share
`submission.create`. Required exact-head review passed after removing duplicate
session authority from the public contract: request-scoped
`AuthorizationService` binds the caller-owned `AsyncSession` and exposes only
`require(action_id, typed_resource_context)`. Full migration proof passed 16
tests; focused authorization/audit coverage remains above 90 percent. PR #126
is the current external and explicit-human gate; AUTH-07B remains inactive.

## 2026-07-15 - WS-AUTH-001-07A Internal Review Passed

Exact implementation SHA `478a819236b9cff1e1d7b61203015691ce0aaf45`
passed senior engineering, architecture/reuse, security/auth, product/ops,
docs, QA/test, test-delta, and CI-integrity review after all valid findings were
repaired. The final downgrade guard covers action evidence, new permissions,
permission-registry target references, and permission-registry invalidation
references under one exclusive table lock. Focused authorization/audit branch
coverage is 94/93 percent, all 37 focused behavior tests pass, and the full
isolated Alembic suite passes 16 tests at exact migration head. PR publication
is pending; AUTH-07B remains inactive.

## 2026-07-15 - WS-AUTH-001-07A Repaired Plan Passed

Exact-SHA `beb85ac` passed senior engineering, architecture/reuse,
security/auth, product/ops, docs, QA/test, test-delta, and CI-integrity review.
The final contract keeps planned/active availability in typed validation while
PostgreSQL enforces registered identifiers, decision-event use, exact
action-to-permission mapping, post-`0018` permission pairing, and guarded
downgrade custody. Seventy-one agent-gate tests and all static documentation
checks passed. Bounded AUTH-07A implementation may begin; AUTH-07B remains
inactive.

## 2026-07-15 - WS-AUTH-001-07A Third Repaired Plan Failed

Exact-SHA architecture/reuse and CI review of `8690ef5` passed all prior
mapping, downgrade, scope, and verification findings but rejected one
temporal-schema ambiguity. If migration `0021` froze all planned actions to
denial-only PostgreSQL evidence, AUTH-07B could not activate its two self
actions without an unowned migration. The repair keeps availability enforcement
in typed catalogue validation while PostgreSQL permanently enforces registered
identifiers, decision-event-only use, and exact action-to-permission mapping.
Runtime code remains unmodified pending fresh exact-SHA review.

## 2026-07-15 - WS-AUTH-001-07A Second Repaired Plan Failed

Exact-SHA senior engineering, architecture/reuse, QA/test, and CI-integrity
review passed `b1b47b0`, while security/auth, product/ops, and docs review found
one remaining audit-integrity blocker. The contract independently bounded
ActionIds and PermissionIds but did not enforce each action's exact permission
mapping, allowed newly admitted permissions without action evidence, did not
bar planned actions from allowed-decision evidence, and checked only non-null
actions before downgrade. The repair closes all four cases in typed and
PostgreSQL acceptance criteria and keeps runtime code unmodified pending fresh
exact-SHA review.

## 2026-07-15 - WS-AUTH-001-07 Started

PR #124 merged `WS-AUTH-001-06` as `f599551`; Backend, Agent Gates,
CodeRabbit, and signed automated merge memory passed. The user explicitly
started `WS-AUTH-001-07` on branch
`codex/ws-auth-001-07-authorization-kernel`. This L1 authorization chunk is in
read-only discovery and required plan review; runtime implementation has not
started.

## 2026-07-15 - WS-AUTH-001-07 Combined Plan Rejected

Architecture/reuse and security/auth/product/docs reviewers failed the combined
contract; QA/test and CI integrity passed only with blocking conditions. The
contract required grant-backed admin reads before AUTH-08, project capabilities
before AUTH-10, omitted the audit ORM and actor-route ownership files, and did
not define exact active actions, denial precedence, transaction ownership, or
coverage-compatible verification. No runtime code was written.

The bounded repair splits parent AUTH-07 into 07A closed catalogue/action-aware
audit parity and 07B minimal kernel/actor self-action cutover. The repaired 07A
contract must pass fresh L1 plan review before implementation.

## 2026-07-15 - WS-AUTH-001-07A First Repaired Plan Failed

Exact-SHA review of `581ecd7` confirmed the split and deferrals but found four
remaining blockers: migration `0021` omitted the two AUTH-07B self ActionIds,
the planned catalogue lacked one exact mapping/owner table, AUTH-13/14 still
claimed later permission-registry migrations, and combined coverage could hide
a sub-90 materially changed subsystem. QA additionally corrected the isolated
database runner invocation, while security required an exclusive audit-table
lock before downgrade evidence checks. No runtime code was written. The second
repair closes those exact findings and requires another fresh exact-SHA review.

## 2026-07-15 - WS-ENG-001-02 Internal Review Passed

Reviewed implementation SHA `8670005` passed senior engineering,
Expand Down
10 changes: 7 additions & 3 deletions .agent-loop/WORK_QUEUE.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,17 +4,18 @@

| Chunk | Title | Risk | Status |
|---|---|---:|---|
| `WS-AUTH-001-07A` | Closed Permission And Action Catalogue | L1 | Review/revision amendment internally approved at `160af8a`; PR #126 external/human review pending |
| `WS-ART-001-02A1` | External Service Adapter Foundation | L1 | Active after explicit user start on 2026-07-15 |

Live post-merge state remains read from signed `automation/loop-memory`
output. This authored queue records the separately approved active chunk.
output. This authored queue records the separately approved parallel chunks.

## Planned Next

| Chunk | Title | Risk | Status |
|---|---|---:|---|
| `WS-AUTH-001-06` | Canonical Actor Profile And Identity Link | L1 | Inactive until a separate explicit user start |
| `WS-QUAL-001-01B2` | Baseline Evidence And CI Ratchet | L1 | Paused for AUTH priority; no valid replacement baseline yet |
| `WS-AUTH-001-07B` | Deny-By-Default Kernel And Self-Action Cutover | L1 | Inactive until 07A merge/memory and explicit user start |
| `WS-QUAL-001-02` | Project Service Coverage | L1 | Inactive until 01B2 merge/memory plus explicit user start |
| `WS-POL-002-04` | Locked Runtime Execution And Routing Hardening | L1 | Inactive pending relevant authorization proof and a separate explicit user start |
| `WS-ART-001-02A2` | Committed Source And Local Preparation | L1 | Inactive until 02A1 merge and explicit user start |
Expand Down Expand Up @@ -68,14 +69,17 @@ output. This authored queue records the separately approved active chunk.
| `WS-AUTH-001-CAT` | Action And Resource Catalogue Reconciliation | L1 | Merged through PR #117 as `4c5d4fc` on 2026-07-14 |
| `WS-AUTH-001-CAT-MEMORY` | Catalogue Post-Merge Memory | L1 | Merged through PR #118 as `eba7e2b` on 2026-07-14 |
| `WS-AUTH-001-05B` | Authority Idempotency And Invalidation Foundation | L1 | Merged through PR #119 as `ad71c7e` on 2026-07-14 |
| `WS-AUTH-001-06` | Canonical Actor Profile And Identity Link | L1 | Merged through PR #124 as `f599551` on 2026-07-15 |
| `WS-ART-001-OBJECT-STORAGE-AMENDMENT` | AWS-First Object Storage Planning Amendment | L1 | Merged through PR #120 as `4408256` on 2026-07-14 |
| `WS-ENG-001-02` | Automated Post-Merge Memory | L1 | Merged through PR #122 as `fc89fb6`; schema-v1 output superseded by WS-ENG-001-03 |

## Proposed Next

AUTH-05A merged through PR #115 as `8e1cde6`, and CAT plus its post-merge memory
merged through PRs #117 and #118. AUTH-05B merged through PR #119 as `ad71c7e`.
Do not start AUTH-06 or POL-002-04 automatically.
AUTH-06 merged through PR #124 as `f599551`, and the user explicitly started
AUTH-07. Required L1 review split it into 07A/07B before runtime implementation.
Do not start 07B, AUTH-08, or POL-002-04 automatically.

Coverage R10 merged through PR #108. Do not start 01B2, chunk 02, or another
coverage implementation chunk from this worktree.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -22,8 +22,10 @@ stopped.
| `WS-AUTH-001-05A` | Shared Audit Ownership And Append-Only Authority Evidence | L1 | Merged through PR #115 as `8e1cde6` |
| `WS-AUTH-001-CAT` | Action And Resource Catalogue Reconciliation | L1 | Merged through PR #117 as `4c5d4fc` |
| `WS-AUTH-001-05B` | Authority Idempotency And Invalidation Foundation | L1 | Merged through PR #119 as `ad71c7e` |
| `WS-AUTH-001-06` | Canonical Actor Profile And Identity Link | L1 | Proposed |
| `WS-AUTH-001-07` | Authorization Kernel And Permission Registry | L1 | Proposed |
| `WS-AUTH-001-06` | Canonical Actor Profile And Identity Link | L1 | Merged through PR #124 as `f599551` |
| `WS-AUTH-001-07` | Authorization Kernel And Permission Registry | L1 | Split before implementation after required L1 plan review |
| `WS-AUTH-001-07A` | Closed Permission And Action Catalogue | L1 | Implementation and repair internally approved at `478a819`; PR pending |
| `WS-AUTH-001-07B` | Deny-By-Default Kernel And Self-Action Cutover | L1 | Inactive until 07A merge/memory and explicit user start |
| `WS-AUTH-001-08` | Bootstrap And Administrative Role Grants | L1 | Proposed |
| `WS-AUTH-001-09` | Actor State, Identity Revocation, And Service Actors | L1 | Proposed |
| `WS-AUTH-001-10` | Project Qualification And Contributor Role Grants | L1 | Proposed |
Expand All @@ -47,7 +49,8 @@ WS-AUTH-001-PLAN
-> WS-AUTH-001-CAT
-> WS-AUTH-001-05B
-> WS-AUTH-001-06
-> WS-AUTH-001-07
-> WS-AUTH-001-07A
-> WS-AUTH-001-07B
-> WS-AUTH-001-08
-> WS-AUTH-001-09
-> WS-AUTH-001-10
Expand Down Expand Up @@ -75,13 +78,16 @@ WS-AUTH-001-PLAN
- Chunk 06 establishes canonical actor resolution while preserving only the
enumerated non-authoritative legacy workflow-eligibility consumers required
for intermediate-release operability.
- Chunk 07 provides the single authorization engine before grant APIs.
- Parent chunk 07 was split before runtime implementation. Chunk 07A owns the
closed permission/action catalogue and action-aware audit parity; chunk 07B
owns the minimal deny-by-default kernel and actor self-action cutover.
- Chunks 08-10 establish local grant truth before product cutover.
- Chunks 11-15 migrate bounded complete product/system surfaces.
- Artifact upload, read, retention, release/delete, replication, integrity, and
reconciliation remain mechanically owned by the artifact subsystem but must
receive centralized AUTH decisions. Chunk 07 owns the permission registry,
chunk 08 owns Operator grant definitions, chunk 09 owns fixed artifact service
receive centralized AUTH decisions. Chunk 07A owns the permission/action
registry, chunk 07B owns the central kernel, chunk 08 owns Operator grant
definitions, chunk 09 owns fixed artifact service
principals, and each WS-ART feature chunk owns the canonical resource facts,
guards, surface declarations, and behavior tests for the exact artifact
actions it activates. AUTH-12, AUTH-14, and AUTH-15 do not pre-activate or
Expand Down Expand Up @@ -116,5 +122,8 @@ human approval merged PR #115 as `8e1cde6` on 2026-07-14, followed by merged
post-merge memory. `WS-AUTH-001-CAT` then merged through PR #117 as `4c5d4fc`
after Backend, Agent Gates, CodeRabbit, and explicit human approval passed. The
CAT post-merge memory merged through PR #118 as `eba7e2b`; AUTH-05B then merged
through PR #119 as `ad71c7e`. Do not start AUTH-06 or POL-002-04 without a
separate explicit user start.
through PR #119 as `ad71c7e`. AUTH-06 merged through PR #124 as `f599551`, its
signed automated memory completed, and the user explicitly started AUTH-07.
Required L1 review rejected the combined contract before runtime edits and
required 07A/07B. Do not start 07B, AUTH-08, or POL-002-04 without a separate
explicit user start after their prerequisites complete.
Loading
Loading