Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
206 changes: 100 additions & 106 deletions .agent-loop/initiatives/WS-REV-001-review-revision-lifecycle/CHUNK_MAP.md

Large diffs are not rendered by default.

Original file line number Diff line number Diff line change
@@ -1,25 +1,37 @@
# Conformance Matrix: WS-REV-001

This matrix binds revised archival specification sections 25.1-25.9 to the
active reconciled contract, implementation chunks, executable proof, and final
live evidence. Chunk start must replace proposed test names with exact
collected node IDs; a section is not complete based only on prose.
Chunk starts replace proposed test descriptions with exact collected node IDs.
No row is complete from prose or an unmerged owner contract.

| Spec section | Owning chunks | Required executable proof | Live/evidence proof |
| Area | Owning chunks | Required executable proof | Release proof |
|---|---|---|---|
| 25.1 Authority | 05-08, 09A, 10-13 | One exact registered ActionId and canonical typed scope for every endpoint/command; reads use request-scoped require while mutations use AUTH-first prepare with an opaque single-use handle bound to exact session/action/actor/idempotency/request identity; REV locks feature rows and recomposes final facts, then AUTH validates bindings/current authority, consumes once, evaluates once, and stages evidence before first feature mutation; wrong-binding/forged/serialized/caller-constructed misuse preserves the legitimate unconsumed handle without staging state, while stale/already-consumed or concurrent duplicate use remains consumed and stages no new state; evaluated authority/policy denial uses clean AUTH evidence after dirty rollback; human-only actor-kind DB enforcement; independent submitter/reviewer/adjudicator/admin/external matrices with exact reviewer grant, no combined role, no-self-review, and collateral-revocation denial; distinct fixed service ActorProfiles/static rows for preference expiry, lease expiry, authority-invalidation reconciliation, general review reconciliation, artifact-reference reconciliation, and projection through AUTH-09E plus exact identity extensions; chain read limited to exact submitter, active reviewer, currently reviewer-granted prior participant, or privileged inspector; two-phase evidence reauthorization leaves no canonical binding/relation/lifecycle mutation; human/service path isolation | Feature/release manifest plus separate AUTH custody/registration/availability manifest proves registration -> hidden behavior -> AUTH activation -> joint release for every action; separate misuse tests prove later exact first use only after rejected pre-consumption substitution and permanent rejection after consumption/duplicate use; denial/evidence-failure matrix distinguishes clean AUTH denial evidence from rolled-back feature effects and proves denial-restaging failure commits nothing; adjudication remains unavailable |
| 25.2 Queue routing | 03, 05-06, 09B, 11-12 | First-open, revision-preferred, immutable exact successful admitting-CheckerRun anchor, admission-versus-supersession both race orders, duplicate delivery, active preference conflict, expiry/decline/invalidation age preservation, admin time-limited assignment, preferred-before-open, current returns one/lease/none, arbitrary or stale ID denied | Existing `review_pending` activation scan, legacy remediation report, preferred return/takeover, admin assignment, operational counts/ages |
| 25.3 Leases | 03, 06, 11 | One lease per queue and canonical human `ActorProfile.id`; immutable ReviewPacketManifest; frozen reviewer ContributionPolicyVersion independent of guide context; release/expiry distinction, database time, exact reviewer-revocation effects with submitter/adjudicator grants unchanged, service/human isolation, races in both permutations, rollback injection | Claim/release/expiry/reclaim/revocation with AUTH-09E-admitted service jobs and lazy recovery enabled |
| 25.4 Reviews | 04, 08, 10 | Every decision appends one immutable Review; every submitted finding and later resolution is immutable; later rounds append rather than rewrite; canonical human reviewer identity; lease/queue/packet-manifest linkage; ReviewEvidenceArtifact slots; finding rules; reject reason; idempotency; CON reviewer operation runs before the decision branch; an `accept` Review additionally creates one immutable FinalAcceptance with unique task/Review/Submission and exact ReviewPolicy/actor lineage, then invokes the CON submitter operation; exact locked Review/Submission/lease/assignment/actor/ContributionPolicyVersion/stabilized artifact_hash lineage; reviewer contribution direct from Review, submitter contribution only from FinalAcceptance; REV-staged audit/outbox; no ART call or no-op participant; rollback | needs_revision without FinalAcceptance, accept with exactly one FinalAcceptance, reject without FinalAcceptance, exact contribution source shapes and task/assignment effects for all three decisions, explicit unpaid/payable awards, changed replay, revoked replay, crossed-lineage rejection, and atomic rollback across Review, the accept-path FinalAcceptance, contributions, and outbox |
| 25.5 Revisions | 02A-02C, 04, 09A-09B, 13 | Immutable same-task N-1 Submission chain; strict prepared cutover; immutable guide activation sequence; equal identity/sequence keeps and any different current active guide rebases; every preparation episode is bound to its Review/prior Submission/task/assignments/project and forms one non-branching chain; AUTH-13 replacement appends a target-assignment successor; preparation freezes guide/source/task-execution policy but no ContributionPolicyVersion; Submission N+1 and CheckerRun use the frozen context; TaskAssignment and ReviewLease contribution-policy freezes do not drift; Task Context uses the head; no reviewer rebase; all blocking findings answered/resolved | v1 guide context -> needs_revision -> same/forward/backward/unsafe classification -> optional authority-loss replacement -> prepared v2 context without contribution-policy drift -> contributor context -> checker readmission -> reviewer consumes v2 -> resolution -> accept |
| 25.6 Reject | 08, 10 | Queue close, lease consume, same-task assignment block, task `rejected` with bounded reason, grants unchanged, other tasks unaffected, later version denied, reviewer contribution only | Authorized reject plus API/database/audit/CON agreement; no `closed` status token or synthetic Review |
| 25.7 Recovery | 06, 09A, 11, 12A | Idempotent preference/lease sweeps and lazy repair; every actor/grant/self-review/policy invalidation; reason-bound covered Project Manager preparation-successor repair with stale-head/race proof; separate covered Project Manager D6 closure only after server-proven limit/deadline, with Operator/cross-project/not-reached denial; leased-without-active and consumed-without-Review detection; canonical reconciliation identity/generation with one unresolved partial uniqueness, duplicate/concurrent scan reload, one resolution, and post-resolution recurrence; Operator-only evidence-linked closure for legacy needs_revision without Review/root; no synthetic Review or silent immutable rewrite; persisted joint lifecycle phases, shared/exclusive advisory-lock mutation fencing, bounded drains, callbacks-through-drain, crash resume, and forward-only timeout recovery | Service-job loss/restart, revocation, preparation repair, D6 closure/replay/races, duplicate reconciliation, legacy unrecoverable closure, controlled recurrence, reconciliation alert, durable fence/drain/crash-resume/forward-reactivation procedure |
| 25.8 Artifact evidence | 05-09B, 11 | ART v2 only; active-lease read limited to immutable ReviewPacketManifest; chain history metadata-only; expired/consumed/prior/later/sibling/cross-task/project access denied; exact ReviewEvidenceArtifact finding/response slots; ART candidate intake outside locks then AUTH -> REV -> ART database finalization with one final AUTH evaluation; exact `artifact.review_evidence.binding.create` service action and binding identity; no raw store, v1 retention, generic retrieval/binding-read, provider locator, or human-token forwarding | Current packet bounded stream, prior history without bytes, finding/response finalize, orphan-only failed races, outage/integrity block with no adverse decision, ART-owned recovery, LocalStorage/MinIO/S3 conformance |
| 25.9 Projection | 04, 08, 10, 12 | REV stages canonical shared-outbox records after the reviewer contribution operation and, for `accept`, the submitter contribution operation; the request route or service command then commits once; accept projection includes FinalAcceptance lineage; no remote call in transaction; deterministic bytes; idempotent receipt; changed bytes conflict; retry/dead-letter/reconciliation; reauthorized disclosure | Forced pre-commit staging rollback and post-commit projection failure/retry, one ART receipt, unchanged Review and FinalAcceptance truth, bounded outbox/dead-letter evidence |
| Authority | 05B, 06A-C, 07A-B, 08, 02A2, 09A2-A5, 10, 11A-D, 12P2, 12A1-A4, 13C | Exact active/project reviewer grant; canonical human actors; AUTH-first prepared mutations; opaque one-use bindings; clean denial/restaging; service identity isolation; no direct grant reads; no adjudication authority | Exact merged feature manifests -> AUTH activation -> phase-enabled HTTP denial/allow matrix |
| Guide chronology | 02A, 02A2 | Positive immutable per-project sequence; exact status/provenance; Project-first publication/screening; immutable Task triplet; hidden prepared If-Match reactivation; both-order races | Forward/backward active guide changes without reviewer-side rebase or stale retry |
| Queue routing | 03A-B, 05A-B, 06A-C, 09B, 11A/C | Exact checker admission; one open/preferred entry; normalized packet membership; current returns lease/offer/none; duplicate/supersession races; authorized batched historical classification | New and historical eligible rows, preferred return, takeover, counts/age evidence |
| Leases | 03A-B, 06A-C, 11A/C | One active lease globally; canonical reviewer; packet manifest; reviewer ContributionPolicyVersion freeze; release/decline/expiry/revocation/lazy recovery and both-order races | Claim/release/expiry/reclaim/revocation through exact admitted service identities |
| Review history | 04A-B, 08, 10 | Every decision/finding/resolution immutable; exact predecessor/assignment lineage; reviewer CON operation before branch; accept-only FinalAcceptance and submitter operation; reject exact assignment; atomic rollback | Real accept/needs_revision/reject HTTP/database/audit/CON agreement and changed replay denial |
| Revision paths | 02C, 09A1-A5, 09B, 10, 11B-D | Human Review revision creates one immutable non-branching preparation before readable state; checker remediation persists unique immutable `remediation_source_checker_run_id`, keeps task context, creates no Review/preparation/CON record, and is never classified as legacy | Separate checker and human drills both reach corrected N+1 without policy or lineage drift |
| Revision context | 02A-C, 09A1-A5, 09B | Review-rooted task-owned preparation; kept/forward/backward/blocked; exact head acknowledgement; one winner per head; replacement successor; no contribution-policy rebase; checker path bypasses rebase | Human context display, checker rerun, prior-reviewer preference, resolution, final decision; checker correction returns open |
| Limits/deadlines | 09A1-A4, 11B | Human-approved round/deadline semantics only; DB time and frozen episode facts; checker retries excluded; repair cannot bypass exhaustion; D6 close only | Before/equal/after, exact replay/races, checker D6 denial, no synthetic Review/CON record |
| Reject/admin close | 10, 11B/D | Human reject only from Review; exact assignment blocked/task rejected. PM/Operator closes use canonical cancelled reasons and create no Review/CON | Authorized/denied/cross-project/rollback proof; no `closed` token |
| Artifact evidence | 03B, 07A-B, 09A3, 11D | Active-exact-lease bytes; metadata-only history; ART candidate/finalize; immutable slot plus append-only attachment; orphan-only failed finalization; no raw store/provider path | Local/MinIO/S3 owner conformance plus outage/integrity no-adverse-outcome drill |
| Projection | 04B, 10, 12P1-P3 | Shared outbox only; deterministic handler/receipt; reauthorized reads; independent projection/reconciliation services; no canonical truth change on failure | Forced post-commit failure/retry and one immutable receipt |
| Release control | 12P3, 12A1-A4, 13A-C | Persisted phase history; read/mutation classes; checker revision routing allowed with checker completion through revision-cutover fence; human preparation inside leased decision; REV/task/checker/CON fences; bounded drain/cutoff/crash resume | Static routes/AUTH mappings, phase-denied execution, scheduler runbook, forward reactivation, final real-HTTP drill |

## Concurrency invariants

- Concurrent initial creates produce one v1; loser exact replay or stable
conflict. They never produce v2.
- Concurrent creates against one human preparation head produce one N+1; loser
exact replay/conflict. Concurrent checker remediation likewise produces one
N+1 from its exact final CheckerRun state. N+2 requires a later human
Review/preparation or final needs-revision CheckerRun.
- Every mutation race uses independent PostgreSQL sessions and both lock/commit
orders.

## Closure rule

Chunk 13 validates every row against fresh real-PostgreSQL coverage evidence and
the privacy-safe HTTP drill. Missing node IDs, skipped mandatory cases, direct
database state fabrication, or an unavailable AUTH/ART/CON/outbox participant
blocks product release.
13C validates all rows against fresh real-PostgreSQL evidence, exact merged owner
SHAs, AUTH-active actions, mandatory phase fences, privacy-safe HTTP proof, and
active docs generated from the released behavior. Missing/skipped proof, direct
database fabrication, or an unavailable owner participant blocks release.
Loading
Loading