Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
52 commits
Select commit Hold shift + click to select a range
180a52a
Replace artifact store with byte-only v2
Abiorh001 Jul 16, 2026
cad09d0
Harden artifact conformance boundaries
Abiorh001 Jul 16, 2026
935b1a2
Fence artifact migration and cancellation state
Abiorh001 Jul 16, 2026
712bfbc
Merge remote-tracking branch 'origin/main' into codex/ws-art-001-02a3…
Abiorh001 Jul 17, 2026
0d41837
Reconcile artifact cutover with merged boundaries
Abiorh001 Jul 17, 2026
a1808a5
Align artifact review gate with merged main
Abiorh001 Jul 17, 2026
8d7662c
Close artifact reconciliation review gaps
Abiorh001 Jul 17, 2026
381f50c
Finalize artifact loop state and downgrade proof
Abiorh001 Jul 17, 2026
f5588d2
Harden artifact replica finalization
Abiorh001 Jul 17, 2026
441d392
Guarantee artifact lock cleanup
Abiorh001 Jul 17, 2026
9d3a59f
Record final artifact reconciliation review
Abiorh001 Jul 17, 2026
744db48
Repair artifact merge-memory gate
Abiorh001 Jul 17, 2026
8bf9aae
Merge main and reconcile artifact authorization custody
Abiorh001 Jul 17, 2026
ddc9dad
Harden artifact startup namespace fencing
Abiorh001 Jul 17, 2026
37fcb37
Close artifact namespace startup race
Abiorh001 Jul 17, 2026
6caf846
Close artifact namespace descriptor vocabulary
Abiorh001 Jul 17, 2026
d535f57
Align artifact receipt documentation
Abiorh001 Jul 17, 2026
25f16b8
Harden artifact namespace ownership checks
Abiorh001 Jul 17, 2026
dd5d39c
Close artifact namespace descriptor contract
Abiorh001 Jul 17, 2026
dd6f6d6
Reject foreign local artifact layout entries
Abiorh001 Jul 17, 2026
0bebed4
Enforce full artifact foundation coverage
Abiorh001 Jul 17, 2026
25f9e4d
Close artifact initialization cleanup paths
Abiorh001 Jul 17, 2026
f2a3f38
Validate complete local artifact layout
Abiorh001 Jul 17, 2026
5b99ebb
Merge remote-tracking branch 'origin/main' into codex/ws-art-001-02a3…
Abiorh001 Jul 17, 2026
ad53052
Fail closed on orphan artifact temporaries
Abiorh001 Jul 17, 2026
b6e632c
Centralize artifact namespace material
Abiorh001 Jul 17, 2026
5188cc3
Refresh merged AUTH loop state
Abiorh001 Jul 17, 2026
4bfb608
Align artifact clean-cut migration guidance
Abiorh001 Jul 17, 2026
4a31c73
Enforce merged AUTH status in agent gates
Abiorh001 Jul 17, 2026
85a2815
Close merged AUTH blocker state
Abiorh001 Jul 17, 2026
2f073cc
Reconcile ART and AUTH review state
Abiorh001 Jul 17, 2026
67c3ea4
Merge remote-tracking branch 'origin/main' into codex/ws-art-001-02a3…
Abiorh001 Jul 17, 2026
956dbcf
Advance ART-02A3 to external review gate
Abiorh001 Jul 17, 2026
4294225
Bind ART-02A3 review evidence to final state
Abiorh001 Jul 17, 2026
a75b041
Refresh ART-02A3 trust evidence
Abiorh001 Jul 17, 2026
e59db88
Close ART-02A3 internal review evidence
Abiorh001 Jul 17, 2026
f110a21
Cover project setup worker domain failures
Abiorh001 Jul 17, 2026
d5ec502
Record ART worker coverage repair review
Abiorh001 Jul 17, 2026
03ed93c
Close ART worker coverage repair review
Abiorh001 Jul 17, 2026
904f763
Harden artifact store v2 finalization
Abiorh001 Jul 17, 2026
8f623f2
Repair local marker crash recovery
Abiorh001 Jul 17, 2026
14e7293
Merge remote-tracking branch 'origin/main' into codex/ws-art-001-02a3…
Abiorh001 Jul 17, 2026
39bca6e
Keep ART gates within artifact boundary
Abiorh001 Jul 17, 2026
829e776
Reuse artifact source test preparation
Abiorh001 Jul 17, 2026
18fa203
Complete artifact test helper consolidation
Abiorh001 Jul 17, 2026
cdeef29
Bind ART review evidence to final candidate
Abiorh001 Jul 17, 2026
ab7e466
Merge AUTH-09B before ART storage cutover
Abiorh001 Jul 17, 2026
f853283
Align ART migration ownership after AUTH merge
Abiorh001 Jul 17, 2026
9730ee5
Merge remote-tracking branch 'origin/main' into codex/ws-art-001-02a3…
Abiorh001 Jul 17, 2026
1836849
Reconcile future AUTH migration custody with ART
Abiorh001 Jul 18, 2026
c8eccaa
Prove namespace claim precedes provider IO
Abiorh001 Jul 18, 2026
7606798
Bind ART review evidence to reconciled candidate
Abiorh001 Jul 18, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
62 changes: 35 additions & 27 deletions .agent-loop/LOOP_STATE.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,45 +5,53 @@
- This authored file is reviewed planning/history context, not canonical live
post-merge state. Canonical state is the signed schema-v2 output on
`automation/loop-memory`.
- Active initiatives include parallel `WS-AUTH-001` and `WS-ART-001`.
- PR #132 merged `WS-AUTH-001-09A` into `main` as `299363a` on
2026-07-17; signed schema-v2 memory recorded the stopped checkpoint.
- Active implementation chunk: `WS-AUTH-001-09B` on
`codex/ws-auth-001-09b-controlled-service-provisioning` after explicit user
start.
- AUTH-09B is bounded to one controlled service-actor provisioning route and
activates only `actor.service.provision`. AUTH-09C remains inactive.
- Start basis: trusted `main` at `299363a` after PR #132, integrated through
`a947b86` after PR #142 before publication.
- Active initiatives include independently owned `WS-AUTH-001`, `WS-ART-001`,
`WS-REV-001`, and `WS-CON-001`. The planning-only `WS-XINT-001` boundary
reconciliation merged through PR #139 as `5d353b6` and starts no runtime.
- AUTH's owner reconciliation merged through PR #140 as `d541521`; it defines
fixed-service admission, prepared mutation authority, and activation custody
without activating ART, REV, or CON feature behavior.
- AUTH-09A merged through PR #132 as `299363a`; its fixed service identity
foundation is preserved as migration `0023_service_actor_identity`.
- AUTH-09B merged through PR #143 as `053242b`; it adds controlled service
actor provisioning and leaves service runtime admission plus feature actions
inactive.
- Active ART implementation chunk: `WS-ART-001-02A3` on
`codex/ws-art-001-02a3-artifact-store-v2-local-clean-cut`.
- Parallel AUTH, REV, and CON worktrees remain independently owned. This ART
branch consumes their merged handoff contracts without editing or activating
their runtime behavior.
- Start basis: PR #129 merged ART-02A2 into `main` as `9a04434`, and PR #139
then merged the cross-initiative boundary reconciliation as `5d353b6`.
- PR #119 merged `WS-AUTH-001-05B` as `ad71c7e`.
- PR #120 merged `WS-ART-001-OBJECT-STORAGE-AMENDMENT` as `4408256`.
- PR #122 merged the first automated post-merge memory implementation as
`fc89fb6`; its schema-v1 cross-initiative next pointer is superseded by the
schema-v2 initiative-local clean cut.
- Current gate: PR #143's replacement Backend run passed all 1,242 tests but
exposed 89.75 percent authorization coverage at the new 90 percent gate. The
behavior-test repair passes every required reviewer track at exact SHA
`127615f` and projects 90.31 percent on the unchanged 1,600-statement
denominator. Replacement GitHub checks and evidence rebinding remain; no
service caller becomes executable before AUTH-09E.
- Current gate: publish PR #141 for GitHub Actions, CodeRabbit, and explicit
human review after reconciling merged AUTH-09B and rebinding exact-SHA ART
evidence. No later ART chunk starts automatically.
- Scope checkpoint: AWS S3 is the only v0.1 production provider; MinIO is
local/CI S3 protocol proof; LocalStorage is focused development/test; R2 and
Flow Node are deferred. Product modules receive narrow artifact capabilities,
and AWS cannot instantiate in production without release-bound live proof.
- Authorization checkpoint: merged main contains 74 PermissionIds and 65
ActionIds, with the two actor-self and seven AUTH-08 administrative actions
active. AUTH-09A defines seven fixed artifact service identities and eleven
exact planned static matrix memberships. The
plan now requires availability-neutral ART/REV custody transfer, fixed-service
admission, prepared mutation authority, feature-owned hidden behavior, and
exact AUTH-only activation chunks. This planning amendment activates nothing.
- Parallel artifact checkpoint: `WS-ART-001-02A1` was explicitly started and
merged through PR #127 as `f64a8e5`; it is at the post-merge memory/stop
checkpoint. ART-02A2 merged through PR #129, and ART-02A3 is reviewed in its
isolated parallel worktree but has no open PR at this checkpoint.
active, plus the AUTH-09B `actor.service.provision` action. Merged AUTH-09A
defines seven fixed artifact
service identities and eleven exact planned static matrix memberships. ART
feature chunks supply hidden canonical behavior/resource composition. Merged
AUTH planning requires availability-neutral ART custody transfer, fixed-service
admission, prepared mutation authority, and exact AUTH-only activation chunks;
neither reconciliation PR activates feature behavior.
- Parallel artifact checkpoint: ART-02A1 merged through PR #127 as `f64a8e5`
and ART-02A2 merged through PR #129 as `9a04434`. ART-02A3 completed
merged-main deterministic repair, deterministic proof, and exact-SHA internal
review. PR #141 is open; refreshed evidence, external checks, and explicit
human merge approval remain. ART-02B1 remains inactive.
- Authorization checkpoint: AUTH-07B, AUTH-08, and AUTH-09A merged through PRs
#130, #131, and #132. Signed memory stopped after 09A, and the user explicitly
started 09B.
#130, #131, and #132; AUTH-09B merged through PR #143 as `053242b`.
AUTH-09C remains inactive until a separate explicit user start.
- Parallel coverage work: `WS-QUAL-001-01B2` remains paused. Its last official
whole-app result is `6466/8159` statements (`79.249908%`); no replacement
evidence exists.
Expand Down
170 changes: 170 additions & 0 deletions .agent-loop/REVIEW_LOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -2136,3 +2136,173 @@ creation while preserving the stabilized submission artifact digest as lineage.
Current gate: commit the planning baseline, run required internal plan review,
repair valid findings, publish one planning PR, and stop. No runtime chunk starts
from this record.

## 2026-07-16 - WS-ART-001-02A3 Pre-Main Review Passed (Superseded)

Reviewed code SHA: `935b1a2bb4663828ecde173b3f91c682250a1aed`.

ArtifactStore v1 was replaced by the byte-only v2 contract, LocalStorage and
the empty pre-production schema were cleanly cut over, the deployment namespace
fence and scratch cleanup were activated, and no product ingest, verification,
recovery, S3, or AUTH action was activated.

All nine required tracks passed for that pre-main revision after repair.
Deterministic proof includes
real PostgreSQL cancellation state, concurrent-writer migration refusal, 90
percent changed-subsystem coverage, stale-contract/wording checks, and the
engineering evidence gate.

Evidence: `.agent-loop/initiatives/WS-ART-001-immutable-artifact-storage/reviews/WS-ART-001-02A3-internal-review-evidence.md`

Trust bundle: `.agent-loop/initiatives/WS-ART-001-immutable-artifact-storage/reviews/WS-ART-001-02A3-pr-trust-bundle.md`

This review was invalidated for publication when merged-main reconciliation
changed the candidate. The current gate is final exact-SHA review and fresh
evidence for the merged-main ART-02A3 revision. Do not publish, merge, or start
`WS-ART-001-02B1` from this historical record.

## 2026-07-17 - WS-ART-001-02A3 Merged-Main Review Passed Before Gate Repair

Reviewed code SHA: `441d39230a341f2c43dd548776a2437ae6b2395d`.

All nine required tracks passed with no remaining findings after atomic
provider-replica finalization and LocalStorage cleanup ownership were repaired.
Every reviewer session was closed. GitHub Agent Gates then found a process-only
successor-heading mismatch and a stale durable-state assertion. This record is
historical; the process-only repair must receive fresh exact-SHA review and
evidence before publication resumes.

## 2026-07-17 - WS-ART-001-02A3 AUTH-Reconciled Review Repair

The first internal review after merging AUTH PR #140 found four valid issues:
provider initialization preceded the startup namespace fence, the LocalStorage
fingerprint did not distinguish same-path root replacement, the Operator read
port used vague generic methods, and same-item `replay_required` recovery lacked
an end-to-end accounting/receipt regression.

The repair now claims and validates the namespace before adapter construction,
binds LocalStorage to a pre-provisioned private root's hashed filesystem
identity, exposes exact Operator read method names, and proves one same-item
replay produces one content, replica, receipt, and accounting transition.
Deterministic proof passed 81 ART/PostgreSQL/conformance tests plus 177
preparation/config/application tests with 93.35 percent combined changed-scope
coverage. The first review results are superseded; fresh exact-SHA review and
evidence remain mandatory before PR #141 is republished.

## 2026-07-17 - WS-ART-001-02A3 Startup Claim Repair

The first exact-SHA review of `ddc9dad` found a residual LocalStorage startup
race and a typed-factory sequencing mismatch. Namespace validation observed a
root before adapter construction, so a same-path replacement could still
receive layout mutation. Real `s3_compatible` startup also failed in local-only
namespace preflight instead of through the canonical typed unavailable-provider
error. Product/ops additionally found that the planned Operator port retained
free-form resource-type strings and one stale generic method summary.

The repair keeps `ArtifactStore` byte-only and introduces a separate
composition-only bootstrap. The typed factory first opens and holds the existing
private root without layout mutation, PostgreSQL admits that exact namespace
identity, and initialization rechecks the configured path before writing only
through the held descriptor. `s3_compatible` now fails at the single typed
factory boundary before namespace work. Operator binding and audit lookups use
closed resource vocabularies and exact method names. All prior reviewer sessions
were closed; this candidate requires fresh deterministic coverage and all nine
exact-SHA reviewer tracks before evidence can be refreshed.

The first review of the startup-claim candidate then found two Low issues. A
future provider descriptor could collide with canonical `backend`, `adapter`,
or `provider_profile` keys, and the glossary retained two v1 provider-reference
phrases. The interface now rejects every reserved descriptor key, regression
coverage pins that rule, and the glossary uses the exact opaque
`provider_object_ref` term. Those reviewer sessions were closed; no prior pass
or pass-with-risk result is reusable for the repaired revision.

The next review round found one remaining Low documentation mismatch shared by
five tracks: `ArtifactOperationReceipt` still claimed a response digest and
provider/database timestamps that do not exist in the v2 model. The canonical
glossary and artifact specification now enumerate the exact Workstream-owned
put-acknowledgement fields, resolve adapter/namespace identity through the
linked replica, and explicitly forbid a response digest or provider receipt.
All reviewer sessions were closed, and this documentation repair requires one
final exact-SHA review round.

That review found one High and one Medium implementation issue plus one Low
documentation mismatch. LocalStorage enforced private mode but not runtime-user
ownership, and `ArtifactStoreNamespaceIdentity` accepted a mutable list despite
being frozen. Local directory, marker, and object descriptor checks now require
the current effective UID; root revalidation also requires exact `0700` mode.
Namespace descriptor containers must be tuples, with regression tests for both
rules. ADR 0013 and the artifact specification now describe the actual
factory-bootstrap, PostgreSQL-claim, byte-store initialization sequence. All
reviewer sessions were closed; the repaired SHA requires fresh review.

The next exact-SHA review found that provider descriptor keys were only
canonicalized, not closed by provider profile; the local layout marker accepted
owner-executable mode; and three active summaries still named direct
`ExternalServiceAdapterFactory[ArtifactStore]` construction. The namespace
identity now rejects unsupported profiles and any missing or unknown
`local-v2` key, the marker requires exact `0600`, and all active summaries use
the bootstrap -> PostgreSQL namespace claim -> byte-store initialization
sequence. The stale-evidence finding raised during the review was a sequencing
false positive: exact-SHA evidence is written only after reviewer sessions
complete. All reviewer sessions were closed; this repair requires fresh review.

The next exact-SHA review found one Low LocalStorage layout issue: a root with a
valid v2 marker could retain unknown top-level entries. Initialization now
accepts only the marker, `objects`, `tmp`, and `locks` entries, with regression
proof that an added legacy directory fails closed. All reviewer sessions were
closed; the repaired SHA requires fresh review.

During the next exact-SHA review, `origin/main` advanced through AUTH-09A PR
#132. Review stopped immediately because the ART branch still carried a sibling
`0023` migration and its diff would have obscured merged AUTH history. The
latest `main` is now merged in full. AUTH's `0023_service_actor_identity`,
service-identity runtime, merge intent, tests, and evidence remain unchanged;
At that checkpoint ART was renumbered to `0024_artifact_store_v2` and descended
from AUTH-09A. The
authored queue records AUTH-09A complete and ART-02A3 at its independent gate.
All reviewer sessions were closed; the merged candidate requires fresh
deterministic proof and exact-SHA review.

The final CI-integrity review found that the cumulative artifact-foundation
coverage source set omitted the new closed product-capability interface module.
The 90 percent workflow gate and its deterministic command-shape assertion now
include `app/interfaces/artifact_operations.py`. All reviewer sessions were
closed; the repaired SHA requires fresh exact-SHA review.

The next review found two Low closure gaps. The active and next ART focused
commands did not explicitly measure the operations interface, and bootstrap
initialization closed descriptors for configuration and operating-system errors
but not every sanitized `ArtifactStoreError`. Both focused commands now include
the operations interface, and initialization closes on all store errors with a
regression test for an integrity failure. All reviewer sessions were closed;
the repaired SHA requires fresh review.

The next review found that claim validation still occurred before the cleanup
guard and that exact root names did not constrain nested LocalStorage contents.
All namespace-claim failures now close pinned descriptors. Existing marked
stores are validated before mutation against the real local grammar: one
`objects/sha256` tree with canonical digest names, bounded private put
temporaries, canonical digest locks, and matched crash-recovery hard links.
Foreign nested entries, owners, modes, link counts, and recovery links fail
closed. Regression proof covers mismatched/repeated claims, foreign entries at
every level, and reopening a valid populated store. All reviewer sessions were
closed; the repaired SHA requires fresh review.

## 2026-07-17 - WS-ART-001-02A3 Merged-Main Final Review

The branch merged trusted `main` at `0302bcf`, preserving the independently
owned REV planning and the canonical AUTH `0023_service_actor_identity` -> ART
then-current `0024_artifact_store_v2` migration order. Deterministic proof then
passed 268
ART-focused tests at 93.18 percent changed-scope coverage, 56 byte-store
contract tests at 91.08 percent, four real PostgreSQL migration-safety cases,
Ruff, 92.0 percent docstring coverage, 80 agent-gate tests, stale-contract and
wording scans, Markdown links, and diff hygiene.

The final internal review found no remaining implementation, architecture, QA,
security, product/ops, reuse, or test-delta defect. Docs and CI correctly
rejected the stale pre-final evidence record. This state-transition commit is
therefore the exact review target; its evidence-only descendant must bind the
reviewed SHA, record every reviewer run, pass the evidence gate, and then receive
final CI/docs confirmation before external checks resume.
17 changes: 9 additions & 8 deletions .agent-loop/WORK_QUEUE.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@

| Chunk | Title | Risk | Status |
|---|---|---:|---|
| `WS-AUTH-001-09B` | Controlled Service Actor Provisioning | L1 | PR #143 open; coverage-gate behavior repair internally reviewed; replacement checks pending |
| `WS-ART-001-02A3` | ArtifactStore v2 Local Clean Cut | L1 | Internal review and deterministic evidence passed; external checks pending |

Live post-merge state remains read from signed `automation/loop-memory`
output. This authored queue records the separately approved parallel chunks.
Expand All @@ -17,7 +17,6 @@ output. This authored queue records the separately approved parallel chunks.
| `WS-AUTH-001-09C` | Actor And Identity-Link Administration Reads | L1 | Inactive until 09B merge/memory and explicit user start |
| `WS-QUAL-001-02` | Project Service Coverage | L1 | Inactive until 01B2 merge/memory plus explicit user start |
| `WS-POL-002-04` | Locked Runtime Execution And Routing Hardening | L1 | Inactive pending relevant authorization proof and a separate explicit user start |
| `WS-ART-001-02A3` | ArtifactStore v2 Local Clean Cut | L1 | Reviewed in isolated parallel worktree; pending its own PR and merge |
| `WS-ART-001-02B1` | S3-Compatible MinIO And AWS | L1 | Inactive until 02A3 merge and explicit user start |
| `WS-ART-001-02C1` | Admission And Put-Attempt Foundation | L1 | Inactive until 02B1 merge and explicit user start |
| `WS-ART-001-02C2` | Verification Publication And Fencing | L1 | Inactive until 02C1 merge and explicit user start |
Expand Down Expand Up @@ -71,10 +70,11 @@ output. This authored queue records the separately approved parallel chunks.
| `WS-AUTH-001-07A` | Closed Permission And Action Catalogue | L1 | Merged through PR #126 as `e9d72a1` on 2026-07-15 |
| `WS-AUTH-001-07B` | Deny-By-Default Kernel And Self-Action Cutover | L1 | Merged through PR #130 as `90eca12` on 2026-07-15 |
| `WS-AUTH-001-08` | Bootstrap Access Administrator Grant | L1 | Merged through PR #131 as `aa0fdcd` on 2026-07-16 |
| `WS-ART-001-02A2` | Committed Source And Local Preparation | L1 | Merged through PR #129 as `9a04434` on 2026-07-16 |
| `WS-XINT-001-PLAN` | Lifecycle Boundary Reconciliation | L1 | Merged through PR #139 as `5d353b6` on 2026-07-17 |
| `WS-ART-001-OBJECT-STORAGE-AMENDMENT` | AWS-First Object Storage Planning Amendment | L1 | Merged through PR #120 as `4408256` on 2026-07-14 |
| `WS-ART-001-02A1` | External Service Adapter Foundation | L1 | Merged through PR #127 as `f64a8e5` on 2026-07-15 |
| `WS-ART-001-02A2` | Committed Source And Local Preparation | L1 | Merged through PR #129 as `9a04434` on 2026-07-16 |
| `WS-AUTH-001-XINT` | Lifecycle Boundary Plan Reconciliation | L1 | Merged through PR #140 as `d541521` on 2026-07-17 |
| `WS-ENG-001-02` | Automated Post-Merge Memory | L1 | Merged through PR #122 as `fc89fb6`; schema-v1 output superseded by WS-ENG-001-03 |

## Proposed Next
Expand All @@ -85,16 +85,17 @@ AUTH-06 merged through PR #124 as `f599551`. AUTH-07A, AUTH-07B, and AUTH-08
merged through PRs #126, #130, and #131. WS-XINT planning merged through PR #139,
and its AUTH owner reconciliation merged through PR #140 as `d541521`.
AUTH-09A merged through PR #132 as `299363a`, and signed schema-v2 memory
stopped. The user explicitly started AUTH-09B. Do not start AUTH-09C or
stopped. AUTH-09B merged through PR #143 as `053242b`. Do not start AUTH-09C or
POL-002-04 automatically.

Coverage R10 merged through PR #108. Do not start 01B2, chunk 02, or another
coverage implementation chunk from this worktree.

`WS-ART-001-01`, the AWS-first planning amendment, and `02A1` are merged. R2
and Flow Node are deferred. `02A2` merged through PR #129 as `9a04434`.
`02A3` is reviewed in its isolated worktree and awaits its own PR publication
and human review; later ART chunks remain inactive.
`WS-ART-001-01`, the AWS-first planning amendment, `02A1`, and `02A2` are
merged. R2 and Flow Node are deferred. The user explicitly started `02A3` on
2026-07-16. Its merged-main deterministic proof and exact-SHA internal review
are complete; external checks remain pending and `02B1` must not start
automatically.

Coverage work proceeds independently in its own worktree and is not owned by
this AUTH queue update.
Expand Down
Loading
Loading