Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
42 commits
Select commit Hold shift + click to select a range
7bd411a
docs(review): adopt canonical lifecycle contract
Abiorh001 Jul 17, 2026
06548c5
build(docs): make architecture render reproducible
Abiorh001 Jul 17, 2026
0a0be1a
docs(review): repair canonical lifecycle adoption
Abiorh001 Jul 17, 2026
9b2fc11
docs(review): close canonical adoption findings
Abiorh001 Jul 17, 2026
2ef15bd
docs(review): bind chunk 01 internal evidence
Abiorh001 Jul 17, 2026
78ca0a0
Merge main and reconcile CON lifecycle contracts
Abiorh001 Jul 17, 2026
1c7c3e7
docs(review): reconcile merged CON provenance
Abiorh001 Jul 17, 2026
e2797fb
docs(review): align operational decision ordering
Abiorh001 Jul 17, 2026
76ed3c1
test(review): enforce canonical workflow ordering
Abiorh001 Jul 17, 2026
317431f
docs(review): separate checker and human revision flows
Abiorh001 Jul 17, 2026
7dae903
test(review): bind checker remediation exclusions
Abiorh001 Jul 17, 2026
df098f2
test(review): require standalone Review exclusion
Abiorh001 Jul 17, 2026
04c7078
docs(review): bind final internal review evidence
Abiorh001 Jul 17, 2026
a481d73
Merge branch 'main' of https://github.com/Flow-Research/workstream in…
Abiorh001 Jul 17, 2026
695e7a6
docs(review): reconcile merged AUTH-09B state
Abiorh001 Jul 17, 2026
6da45b2
docs(review): distinguish provisioning capability gates
Abiorh001 Jul 17, 2026
9ad0420
docs(review): bind AUTH-09B reconciliation evidence
Abiorh001 Jul 17, 2026
5b41969
fix(review): align successor merge intent heading
Abiorh001 Jul 17, 2026
b20b766
docs(review): state replacement CI accurately
Abiorh001 Jul 17, 2026
e7fc2f7
docs(review): bind PR gate repair evidence
Abiorh001 Jul 17, 2026
861bcee
Merge main and reconcile CON-01 authority
Abiorh001 Jul 18, 2026
694c02a
docs(review): make CON-01 canonical authority
Abiorh001 Jul 18, 2026
188887f
docs(review): bind CON-01 reconciliation evidence
Abiorh001 Jul 18, 2026
482e27d
docs(rev): address lifecycle review findings
Abiorh001 Jul 18, 2026
2b433ed
docs(art): align storage capability wording
Abiorh001 Jul 18, 2026
60e28ac
test(rev): harden revision policy scanner
Abiorh001 Jul 18, 2026
f2493df
style(rev): format scanner assertion
Abiorh001 Jul 18, 2026
59d3004
docs(rev): record external repair evidence
Abiorh001 Jul 18, 2026
2f0ee3b
Merge remote-tracking branch 'origin/main' into codex/ws-rev-001-01
Abiorh001 Jul 18, 2026
3572835
docs(rev): reconcile ART v2 clean cut
Abiorh001 Jul 18, 2026
ca6b46b
style(ci): format reconciled artifact gates
Abiorh001 Jul 18, 2026
627cc03
docs(rev): bind ART reconciliation evidence
Abiorh001 Jul 18, 2026
7742730
docs(rev): fail closed on reviewed scope
Abiorh001 Jul 18, 2026
7785b83
docs(rev): bind reviewed scope to diff status
Abiorh001 Jul 18, 2026
5af0adc
docs(rev): record scope verification review
Abiorh001 Jul 18, 2026
4eb8836
docs(rev): bind final scope review evidence
Abiorh001 Jul 18, 2026
1a1d4aa
Merge remote-tracking branch 'origin/main' into codex/ws-rev-001-01
Abiorh001 Jul 18, 2026
f100415
docs(rev): reconcile merged AUTH-09C
Abiorh001 Jul 18, 2026
a184e41
docs(rev): mark AUTH catalogue snapshots historical
Abiorh001 Jul 18, 2026
1d0e468
docs(rev): bind AUTH-09C reconciliation evidence
Abiorh001 Jul 18, 2026
e239282
docs(rev): require clean reviewed worktree
Abiorh001 Jul 18, 2026
79c22e3
docs(rev): bind clean scope evidence
Abiorh001 Jul 18, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -10,20 +10,20 @@ explicit start signal.

| Chunk | Title | Risk | Gate | Status |
|---|---|---:|---|---|
| `WS-REV-001-PLAN` | Review And Revision Lifecycle Planning | L1 | None | Active; post-AUTH-09A current-main reconciliation in review |
| `WS-REV-001-01` | Canonical Contract Adoption And Dependency Conformance | L1 | Plan approval; current-main refresh; merged WS-XINT-001 handoffs, AUTH PR #140 planning contracts, and AUTH-09A fixed-service foundation | Proposed |
| `WS-REV-001-PLAN` | Review And Revision Lifecycle Planning | L1 | None | Merged through PR #128 at trusted main `0302bcf854a565d429e232ad6b076a1931ea74e4` |
| `WS-REV-001-01` | Canonical Contract Adoption And Dependency Conformance | L1 | Plan approval; current-main refresh; merged WS-XINT-001 handoffs, AUTH PR #140 planning contracts, AUTH-09A/09B foundations, and CON-01 canonical contract adoption | Active on `codex/ws-rev-001-01` |
| `WS-REV-001-02` | Locked Review Policy And Task Lifecycle Alignment | L1 | AUTH canonical actor foundation; separately reviewed and merged AUTH-owned schema-only contributor-field foundation that breaks the current AUTH-13/14 <-> REV-09A cycle; ART submission commitment contract stable; canonical rejected/cancelled lifecycle amendment; D6 behavior approved | Proposed |
| `WS-REV-001-03` | Review Queue And Lease Persistence | L1 | 02 merged; WS-CON ContributionPolicyVersion persistence merged | Proposed |
| `WS-REV-001-04` | Immutable Review, Final Acceptance, Findings, And Replay Persistence | L1 | 03 merged; shared transactional-outbox persistence and caller-transaction lifecycle-audit participant merged at exact refreshed SHAs | Proposed |
| `WS-REV-001-05` | Checker Admission, Preferred Routing, And Queue Views | L1 | 04; ART v2 submission/checker cutover; AUTH-10 reviewer grants and AUTH-11 project visibility; registered actions remain planned; hidden manifest later gates `WS-AUTH-001-REV-05` | Proposed |
| `WS-REV-001-06` | Atomic Claims, Release, Preference, And Timers | L1 | 05; merged `WS-AUTH-001-REV-CUSTODY` and `WS-AUTH-001-PREP`; merged AUTH-09A foundation plus AUTH-09B/09E and exact expiry identity extensions from the merged REV-01 manifest; WS-CON ReviewLease ContributionPolicyVersion freeze participant; hidden manifest later gates `WS-AUTH-001-REV-06` | Proposed |
| `WS-REV-001-06` | Atomic Claims, Release, Preference, And Timers | L1 | 05; merged `WS-AUTH-001-REV-CUSTODY` and `WS-AUTH-001-PREP`; merged AUTH-09A foundation and AUTH-09B provisioning capability plus exact expiry identity extensions/provisioning and AUTH-09E admission from the merged REV-01 manifest; WS-CON ReviewLease ContributionPolicyVersion freeze participant; hidden manifest later gates `WS-AUTH-001-REV-06` | Proposed |
| `WS-REV-001-07` | Artifact-Backed Review Context And Finding Evidence | L1 | 06; merged PREP consumer contract; approved and merged ART-owner amendment for v2 packet-read; separately approved `WS-ART-001-REV-EVIDENCE` candidate/finalize capability; `WS-AUTH-001-ART-REV-EVIDENCE-REG` plus exact binding service row; hidden manifests later gate `WS-AUTH-001-REV-07` and `WS-AUTH-001-ART-REV-EVIDENCE` | Proposed |
| `WS-REV-001-08` | Decision, Final Acceptance, And Task-Effect Contract | L1 | 07; merged PREP consumer contract; Review persistence and the accept-only FinalAcceptance write remain disabled until 10; complete hidden REV+CON composition later gates `WS-AUTH-001-REV-08` | Proposed |
| `WS-REV-001-09A` | Revision Context Preparation And Resubmission | L1 | 08; ADR 0010 adopted; retired compensation-context field removal merged; schema-only contributor-field foundation; PREP; registered planned `submission.create`; hidden manifest later gates `WS-AUTH-001-REV-09A` and amended AUTH-13/14 product cutovers | Proposed |
| `WS-REV-001-09B` | Finding Replay, Resolution, And Return Routing | L1 | 09A | Proposed |
| `WS-REV-001-10` | Final Acceptance, WS-CON Atomic Integration, And Hidden Composition | L1 | 09B; PREP; approved and merged ART/task-owner `Submission.artifact_hash` amendment; merged CON FinalAcceptance-sourced lineage schema and two-operation flush-only contribution/award participant; no mandatory contribution-evidence projection; completion later gates `WS-AUTH-001-REV-08` | Proposed |
| `WS-REV-001-11` | Admin Overrides, Reviewer-Revocation Recovery, And Reconciliation | L1 | 10; AUTH invalidation; `WS-AUTH-001-REV-REG` registered/planned from the merged REV-01 manifest; PREP; merged AUTH-09A foundation plus AUTH-09B/09E and exact invalidation/reconciliation identity extensions from that manifest; ART Operator recovery port; hidden manifest later gates `WS-AUTH-001-REV-11` | Proposed |
| `WS-REV-001-12` | Snapshot Projection, Notifications, And Observability | L1 | 11; ART projection port; outbox foundation; PREP; merged AUTH-09A foundation plus AUTH-09B/09E and exact artifact-reference/projection identity extensions from the merged REV-01 manifest; hidden manifest later gates `WS-AUTH-001-REV-12` | Proposed |
| `WS-REV-001-11` | Admin Overrides, Reviewer-Revocation Recovery, And Reconciliation | L1 | 10; AUTH invalidation; `WS-AUTH-001-REV-REG` registered/planned from the merged REV-01 manifest; PREP; merged AUTH-09A foundation and AUTH-09B capability plus exact invalidation/reconciliation identity extensions/provisioning and AUTH-09E admission from that manifest; ART Operator recovery port; hidden manifest later gates `WS-AUTH-001-REV-11` | Proposed |
| `WS-REV-001-12` | Snapshot Projection, Notifications, And Observability | L1 | 11; ART projection port; outbox foundation; PREP; merged AUTH-09A foundation and AUTH-09B capability plus exact artifact-reference/projection identity extensions/provisioning and AUTH-09E admission from the merged REV-01 manifest; hidden manifest later gates `WS-AUTH-001-REV-12` | Proposed |
| `WS-REV-001-12A` | Joint Lifecycle Release-Control Foundation | L1 | 12 review drain-observation port; exact core WS-CON hidden-readiness manifest; `WS-AUTH-001-REV-REG`; PREP; CON obligation-writer, dispatch, and callback fence hooks plus fulfillment/outbox drain-cutoff and observation port; complete additive manifests later gate `WS-AUTH-001-REV-LIFECYCLE` | Proposed |
| `WS-REV-001-13` | Coherent Public Release, Live API Drill, And Release Proof | L1 | 12A; amended full AUTH-13/14 product cutovers; AUTH-14 `submission.create` active with prepared-revision proof; `WS-AUTH-001-REV-CUSTODY`; exact `WS-AUTH-001-REV-05/06/07/08/09A/11/12`, `WS-AUTH-001-REV-LIFECYCLE`, and ART evidence actions active after hidden behavior; ART/CON/outbox live readiness | Proposed |

Expand Down Expand Up @@ -117,6 +117,7 @@ workflow, script, dependency, or coverage gate changes.

## Stop condition

Planning is approved and merged AUTH PR #140/AUTH-08/AUTH-09A/ART-02A2 contracts are reconciled.
Publication still requires final exact-snapshot review and evidence binding. Do
not start 01 automatically; its merge-intent gate remains separate.
Planning is approved and merged AUTH PR #140/AUTH-08/AUTH-09A plus
ART-02A2/ART-02A3 contracts are reconciled. Finish, review, and merge Chunk 01
with explicit human approval, then stop. Do not start Chunk 02 automatically;
its merge-intent gate remains separate.
Original file line number Diff line number Diff line change
Expand Up @@ -75,12 +75,13 @@ before producing the reconciled active contract.
`ActorProfile.id`, not external subject, email, legacy typed-profile ID, or
role labels. Review authority requires the independent exact-project
`reviewer` grant; `submitter` and `adjudicator` grants do not substitute.
- AUTH-09A now supplies the fixed-service enum/schema/migration and the closed
seven-identity ART matrix, but it provisions no service actor and admits no
service token. Protected review jobs still require AUTH-09B provisioning,
AUTH-09E admission, and separately reviewed enum/constraint/matrix extensions
for each of REV's six exact identities. A generic system-principal or
fabricated human is not allowed.
- AUTH-09A supplies the fixed-service enum/schema/migration and the closed
seven-identity ART matrix. Merged AUTH-09B supplies controlled provisioning
only for that closed registry and admits no service token. Protected review
jobs still require separately reviewed enum/constraint/matrix extensions for
each of REV's six exact identities, provisioning through the merged AUTH-09B
capability, and AUTH-09E admission. A generic system-principal or fabricated
human is not allowed.
- `review.queue.override` is present in the merged 74-PermissionId catalogue;
the review actions mapped to it remain planned/inactive. Artifact recovery already uses
the registered `artifact.verification_job.retry` action and ART-owned
Expand All @@ -105,9 +106,10 @@ contracts assign the final `TaskAssignment.contributor_id` and
counts from current trusted main and account for its delta independently.
REV feature chunks build hidden behavior and typed facts; exact AUTH activation
custodians alone integrate evaluators and change availability. Current trusted
main contains 65 ActionIds: 9 active and 56 planned. The eight AUTH-09A
additions do not change the 24 REV dependencies, all of which remain
unavailable.
main after AUTH-09C contains 65 ActionIds: 12 active and 53 planned.
AUTH-09B activated `actor.service.provision`; AUTH-09C activates only the two
bounded actor-registry reads. No REV identity or action was added, and all 24
REV dependencies remain unavailable.

The merged AUTH plan contains an execution cycle: full AUTH-13/14 require
prepared revision/replacement behavior owned by REV-09A, while REV-02 needs
Expand Down Expand Up @@ -137,29 +139,31 @@ route-owned transaction. Its internal evidence records 275 focused behavior
tests, 90.17 percent branch-aware focused coverage, and 17 isolated Alembic
tests. Final PR checks passed Backend, Agent Gates, and CodeRabbit. REV runtime
chunks must preserve these merged invariants and still wait for the later AUTH
definition-of-done gate owned by each consumer, AUTH-09B/09E plus the exact
REV identity extensions for protected service callers, and the matching AUTH
activation checkpoint. Reads consume
definition-of-done gate owned by each consumer, exact REV identity extensions
and provisioning through merged AUTH-09B, AUTH-09E admission for protected
service callers, and the matching AUTH activation checkpoint. Reads consume
request-scoped `AuthorizationService.require`; mutations consume the future
authority-first prepared protocol and exactly one final evaluation without
importing grant persistence into the review module.

## Artifact boundary

- `ArtifactContent`, immutable `ArtifactBinding`, `ArtifactReplica`, operation
receipts, upload staging, a provider-neutral `ArtifactStore`, and a
LocalStorage adapter exist.
- Current ArtifactStore v1 operations cover store, recover committed store,
open, stat, verify, retain, release, and receipt lookup. They are discovery
state only: WS-XINT-001 requires ART v2 as the sole future provider boundary,
and REV must not consume the v1 provider contract.
receipts, upload staging, the byte-only provider-neutral ART v2
`ArtifactStore`, and `LocalStorageAdapter` exist.
- Merged ART-02A2 PR #129 at trusted main
`9a04434e2f23c5dec8939dadb943bba4d85110c0`, final head
`32aab89262a3944f305e9e5dc4c65a2d31e2e144`, adds an inactive
`PreparedArtifact`/`CommittedArtifactSource` boundary, bounded private
`ArtifactScratchManager`, deterministic cleanup mechanics, and shared bounded
file locking. Active ArtifactStore v1, provider selection, schema, routes, and
lifecycle behavior remain unchanged.
file locking. Those preparation types remain internal ART mechanics.
- Merged ART-02A3 PR #141 at trusted main
`a10d9018007d2e847b4870e9b26cbd24e24c7bb4`, final branch head
`7606798e751abf40218d23886779c3659b76e974`, removes ArtifactStore v1 and
activates the byte-only v2 LocalStorage clean cut, namespace fencing, typed
product capabilities, migration, and scratch-cleanup wiring. It does not
implement S3/MinIO, submission/checker artifact cutovers, review packet read,
or review-evidence candidate/finalize behavior.
- ART scratch is bounded private ephemeral processing state, not artifact
storage or a product reference. REV never imports ART preparation/scratch
types, persists their paths or ledger identities, or creates a second scratch
Expand Down Expand Up @@ -302,9 +306,10 @@ chunks must preserve these merged invariants and still wait for the later AUTH

- Exact merged AUTH service, resource-context, invalidation, and system-actor
interfaces.
- Exact later merged ART v2, S3, admission, verification/publication, read,
- Exact later merged ART S3, admission, verification/publication, read,
binding, intake, retention, recovery, service-scope, checker, and projection
interfaces. ART-02A2 does not provide those product capabilities.
interfaces. ART-02A3 provides the byte foundation and typed composition
boundary, not those review-facing capabilities.
- Exact WS-CON policy-freeze and transaction-participant interfaces.
- Whether a shared outbox foundation lands before the first review consumer.
- Production timer schedule and operational alert thresholds.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -79,7 +79,8 @@ After the exact owning AUTH gates merge, WS-REV consumes:
- one exact active project `reviewer` grant for human review. Separate
`submitter`, `adjudicator`, and administrative grants never substitute, and
revoking reviewer authority never mutates another grant;
- AUTH-09B provisioning and AUTH-09E fixed-service admission for protected jobs.
- exact REV identity extensions, controlled provisioning through merged
AUTH-09B, and AUTH-09E fixed-service admission for protected jobs.
Preference expiry, lease
expiry, reviewer-authority invalidation reconciliation, general review
reconciliation, artifact-reference reconciliation, and projection rebuild
Expand Down Expand Up @@ -154,9 +155,11 @@ The four additive ActionIds and their closed mappings are registered together by
and 12A; `WS-AUTH-001-REV-LIFECYCLE` later integrates their evaluators and
activates them together. They add no PermissionId. The AUTH-08 runtime snapshot
contained 57 actions: 9 active and 48 planned. That is historical provenance,
not a fixed future total. Current trusted main after AUTH-09A contains 65
actions: 9 active and 56 planned; its eight additions are unrelated to the 24
unavailable REV dependencies.
not a fixed future total. Current trusted main after AUTH-09C contains 65
actions: 12 active and 53 planned. AUTH-09B activates
`actor.service.provision`; AUTH-09C activates only `actor.profile.read` and
`actor.identity_link.read`. Neither adds a REV identity or action, and all 24
REV dependencies remain unavailable.
WS-XINT-001 separately proposes
`artifact.review_evidence.binding.create -> artifact.binding.create` for the
ART binding service. Every later AUTH registration or activation chunk derives
Expand All @@ -178,19 +181,19 @@ merged and proven. WS-REV consumes:
- stable verification/availability facts and deterministic projection storage;
- LocalStorage and MinIO conformance with AWS S3 as production provider.

Merged ART-02A2 PR #129 at trusted main
`9a04434e2f23c5dec8939dadb943bba4d85110c0`, final branch head
`32aab89262a3944f305e9e5dc4c65a2d31e2e144`, establishes only the inactive
committed-source and private scratch-preparation foundation. Its active
ArtifactStore v1 state is not a REV interface: ART v2 must be the sole provider
boundary before any REV artifact consumer starts. `ArtifactScratchManager`, `PreparedArtifact`, and
`CommittedArtifactSource` are ART-internal preparation mechanics, not REV
capabilities or durable product references; review code never imports or stores
them. Later ART-owned v2, S3, submission/checker binding cutovers, admission,
Merged ART-02A2 PR #129 established the committed-source/private-scratch
foundation. Merged ART-02A3 PR #141 at trusted main
`a10d9018007d2e847b4870e9b26cbd24e24c7bb4`, final branch head
`7606798e751abf40218d23886779c3659b76e974`, removes v1 and activates the
byte-only ART v2 LocalStorage clean cut and typed product capability boundary.
`ArtifactScratchManager`, `PreparedArtifact`, `CommittedArtifactSource`, and the
raw byte store are ART-internal mechanics, not REV capabilities or durable
product references; review code never imports or stores them. Later ART-owned
S3/MinIO, submission/checker binding cutovers, admission,
verification/publication, packet read, evidence candidate/finalize, projection,
and live-proof chunks remain hard gates. ART owns candidate retention and
Operator recovery; REV does not consume v1 verify/retain/release, raw
ArtifactStore, `artifact.binding.read`, or a generic artifact-retrieval action.
Operator recovery; REV does not consume the raw store,
`artifact.binding.read`, or a generic artifact-retrieval action.

The current merged ART plan does not yet assign two other exact XINT
requirements to an approved owner chunk: a narrow active-lease packet-read port
Expand Down Expand Up @@ -218,11 +221,15 @@ PermissionId substitutes.

### Contribution gate

The merged WS-XINT `REV_CON_HANDOFF.md` remains the trusted-main boundary, with
the human-approved 2026-07-17 amendment that `FinalAcceptance` is the sole
submitter-acceptance source and REV, rather than CON, stages shared audit/outbox
records. Any sibling WS-CON worktree remains discovery evidence until its owning
contracts merge to trusted main.
Merged CON-01 at `e118e33afcd89b8ee78ecfc8f0e0d585ae0ee4b9` publishes
`docs/spec_contribution_compensation.md` and ADR 0016 as the canonical CON
boundary. They require FinalAcceptance as the sole submitter-acceptance source,
REV-owned decision orchestration and sole commit, ordered flush-only CON
operations, and REV staging of shared audit/outbox inputs returned by CON. The
older WS-XINT `REV_CON_HANDOFF.md` remains historical supporting handoff
material; it no longer outranks the merged CON contract. CON-01 implements no
runtime, so its later persistence, freeze, lineage, and participant chunks still
gate canonical Review composition.

The cross-initiative sequence is explicit:

Expand Down
Loading
Loading