Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
18 commits
Select commit Hold shift + click to select a range
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
50 changes: 29 additions & 21 deletions .agent-loop/LOOP_STATE.md
Original file line number Diff line number Diff line change
Expand Up @@ -18,42 +18,50 @@
inactive.
- AUTH-09C merged through PR #146 as `0ffdabf`; signed schema-v2 memory at
`eeb3dc2` recorded its two administrative reads and stopped.
- PR #141 merged `WS-ART-001-02A3` into `main` as `a10d901` on
2026-07-18; the user then explicitly started ART-02B1.
- Active ART implementation chunk: `WS-ART-001-02B1` on
`codex/ws-art-001-02b1-s3-compatible-minio-aws`.
- The ART worktree consumes merged AUTH, REV, and CON contracts without
editing or activating their independently owned runtime behavior.
- AUTH-09D-A merged through PR #148 as `99ae4c9`; AUTH-09D-B remains inactive
until signed memory and an explicit human start.
- ART integration basis: trusted `main` at `99ae4c9` after PR #148.
- PR #141 merged `WS-ART-001-02A3` into `main` as `a10d901` on 2026-07-18.
PR #151 then merged `WS-ART-001-02B1` as `1b5422f` on 2026-07-19;
ART-02C1 remains inactive pending signed memory and a separate explicit start.
- AUTH-09D-A merged through PR #148 as `99ae4c9`; signed schema-v2 memory at
`cf8a3e8` recorded the stopped gate and exact 09D-B successor.
- PR-ready implementation chunk: `WS-AUTH-001-09D-B` in PR #152 on
`codex/ws-auth-001-09d-b-identity-link-lifecycle`, started from trusted
`main` at `99ae4c9` after the user's explicit start signal. Contract repair
passed required L1 preimplementation review at exact contract `9ec6390b`.
Implementation, deterministic proof, and required internal review pass; the
branch now integrates trusted `main` at `1b5422f`.
- PR #119 merged `WS-AUTH-001-05B` as `ad71c7e`.
- PR #120 merged `WS-ART-001-OBJECT-STORAGE-AMENDMENT` as `4408256`.
- PR #122 merged the first automated post-merge memory implementation as
`fc89fb6`; its schema-v1 cross-initiative next pointer is superseded by the
schema-v2 initiative-local clean cut.
- Current ART gate: integrate trusted `main`, complete deterministic 02B1
proof, and pass all nine exact-SHA internal reviewer tracks before opening
the ART PR. No later ART chunk starts automatically.
- Current gate: refreshed external checks and explicit human review for PR
#152. The inactive
`WS-AUTH-001-CONTRIBUTOR-FOUNDATION` is the next same-initiative gate; it
changes no action availability. No service caller becomes executable before
AUTH-09E.
- Scope checkpoint: AWS S3 is the only v0.1 production provider; MinIO is
local/CI S3 protocol proof; LocalStorage is focused development/test; R2 and
Flow Node are deferred. Product modules receive narrow artifact capabilities,
and AWS cannot instantiate in production without release-bound live proof.
- Authorization checkpoint: merged main contains 74 PermissionIds and 65
ActionIds, with 12 active actions: the two actor-self actions, seven AUTH-08
administrative actions, AUTH-09B `actor.service.provision`, and AUTH-09C
`actor.profile.read` plus `actor.identity_link.read`. Merged AUTH-09A defines
seven fixed artifact
- Authorization checkpoint: trusted main contains 74 PermissionIds and 65
ActionIds, with 15 active actions: the two actor-self actions, seven AUTH-08
administrative actions, AUTH-09B `actor.service.provision`, AUTH-09C
`actor.profile.read` plus `actor.identity_link.read`, and the three merged
AUTH-09D-A profile lifecycle actions. PR #152 activates only the two 09D-B
identity-link lifecycle actions, producing a candidate total of 17.
Merged AUTH-09A defines seven fixed artifact
service identities and eleven exact planned static matrix memberships. ART
feature chunks supply hidden canonical behavior/resource composition. Merged
AUTH planning requires availability-neutral ART custody transfer, fixed-service
admission, prepared mutation authority, and exact AUTH-only activation chunks;
neither reconciliation PR activates feature behavior.
- Parallel artifact checkpoint: ART-02A1, ART-02A2, and ART-02A3 merged through
PRs #127, #129, and #141. ART-02B1 is active and adds real MinIO protocol
proof plus a fail-closed, runtime-ineligible native AWS profile.
- Parallel artifact checkpoint: ART-02A1, ART-02A2, ART-02A3, and ART-02B1
merged through PRs #127, #129, #141, and #151. ART-02B1 adds real MinIO
protocol proof plus a fail-closed, runtime-ineligible native AWS profile;
ART-02C1 remains inactive.
- Authorization checkpoint: AUTH-07B through AUTH-09D-A merged through PRs
#130, #131, #132, #143, #146, and #148. AUTH-09D-B remains inactive.
#130, #131, #132, #143, #146, and #148. AUTH-09D-B is the reviewed PR #152
candidate; its contributor foundation and AUTH-09E remain inactive.
- Parallel coverage work: `WS-QUAL-001-01B2` remains paused. Its last official
whole-app result is `6466/8159` statements (`79.249908%`); no replacement
evidence exists.
Expand Down
50 changes: 50 additions & 0 deletions .agent-loop/REVIEW_LOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,55 @@
# Review Log

## 2026-07-18 - WS-AUTH-001-09D-B Internal Review Passed

- Identity-link revoke/reactivate implementation, real PostgreSQL concurrency,
exact rollback/evidence proof, and the contributor-foundation sequencing
repair passed all required reviewer tracks at exact head `bd0b063b`.
- QA's four proof blockers, architecture/docs' three closeout blockers, and the
contributor-contract's two scope/allowlist blockers were repaired without a
production compatibility path, threshold reduction, skip, or lifecycle
expansion.
- Exact evidence is 112 authorization tests at 90.11 percent branch coverage,
two mandatory PostgreSQL nodes in 241.09 seconds, the live HTTP drill, Ruff,
both stale scans, Markdown links, 87 Agent Gates, merge-intent validation,
and diff integrity.
- Ready PR publication is the remaining local gate. The contributor foundation
remains inactive behind merge, signed memory, and a separate explicit start.

## 2026-07-18 - AUTH Contributor Foundation Sequence Reconciled

- Current REV planning correctly identified that deferring assignment and
Submission ownership renames to AUTH-13/14 creates a dependency cycle.
- Durable AUTH planning now names inactive same-initiative successor
`WS-AUTH-001-CONTRIBUTOR-FOUNDATION` immediately after 09D-B. Its bounded
contract owns only the two `contributor_id` clean cuts, database-backed
canonical-human lineage, and transaction-local active-human revalidation.
- AUTH-13/14 now consume those canonical fields and retain their later
authorization/lifecycle responsibilities. Fixed future migration
reservations are retired; each unmerged chunk allocates from trusted `main`.
- This planning repair changes no 09D-B runtime behavior and starts no successor.

## 2026-07-18 - WS-AUTH-001-09D-B Preimplementation Review Passed

- Required L1 review initially rejected broad race, rollback, lock-order,
allowed-file, evidence, and process-state contracts before runtime edits.
- Exact candidate `9ec6390b` repairs every valid finding: canonical
profile/link/grant target locking, exact link evidence, closed missing-target
denial flow, four actor-self lock/timestamp cases, nine-stage rollback on both
operations, blocker-observed PostgreSQL races, 90 percent authorization
coverage, and explicit 09E inactivity.
- Senior engineering, QA/test, security/auth, product/ops, architecture, CI
integrity, docs, reuse/dedup, and test delta pass. Bounded runtime
implementation may begin for 09D-B only.

## 2026-07-18 - WS-AUTH-001-09D-B Explicitly Started

- PR #148 merged AUTH-09D-A as `99ae4c9`; signed schema-v2 memory `cf8a3e8`
stopped and named 09D-B as the same-initiative successor.
- The user explicitly started 09D-B. Its broad inherited contract is being
repaired to exact files, exclusions, behavior, proof, reviewers, and human
review focus before any runtime edit.

## 2026-07-18 - WS-AUTH-001-09D-A External Repair Review Passed

- PR #148 CodeRabbit correctly found an API/database normalization mismatch:
Expand Down
27 changes: 17 additions & 10 deletions .agent-loop/WORK_QUEUE.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@

| Chunk | Title | Risk | Status |
|---|---|---:|---|
| `WS-ART-001-02B1` | S3-Compatible MinIO And AWS | L1 | Active after explicit user start; implementation repair and exact-head internal review in progress |
| `WS-AUTH-001-09D-B` | Identity-Link Lifecycle And Race Closure | L1 | PR #152 open; trusted main `1b5422f` integrated; refreshed checks and explicit human review pending |

Live post-merge state remains read from signed `automation/loop-memory`
output. This authored queue records the separately approved parallel chunks.
Expand All @@ -14,10 +14,11 @@ output. This authored queue records the separately approved parallel chunks.
| Chunk | Title | Risk | Status |
|---|---|---:|---|
| `WS-QUAL-001-01B2` | Baseline Evidence And CI Ratchet | L1 | Paused for AUTH priority; no valid replacement baseline yet |
| `WS-AUTH-001-09D-B` | Identity-Link Lifecycle And Race Closure | L1 | Inactive until 09D-A merge/memory and explicit user start |
| `WS-AUTH-001-CONTRIBUTOR-FOUNDATION` | Contributor Fields And Canonical-Human Lineage | L1 | Inactive until 09D-B merge/memory and explicit user start |
| `WS-AUTH-001-09E` | Fixed Service Runtime Admission | L1 | Inactive until contributor-foundation merge/memory and explicit user start |
| `WS-QUAL-001-02` | Project Service Coverage | L1 | Inactive until 01B2 merge/memory plus explicit user start |
| `WS-POL-002-04` | Locked Runtime Execution And Routing Hardening | L1 | Inactive pending relevant authorization proof and a separate explicit user start |
| `WS-ART-001-02C1` | Admission And Put-Attempt Foundation | L1 | Inactive until 02B1 merge and explicit user start |
| `WS-ART-001-02C1` | Admission And Put-Attempt Foundation | L1 | Inactive until signed 02B1 merge memory and explicit user start |
| `WS-ART-001-02C2` | Verification Publication And Fencing | L1 | Inactive until 02C1 merge and explicit user start |
| `WS-ART-001-02C3` | Recovery Attempt And Idempotency Chain | L1 | Inactive until 02C2 merge and explicit user start |
| `WS-ART-001-02D` | Operator Artifact Operations And AWS Readiness | L1 | Inactive until 02C3 and exact AUTH prerequisites |
Expand All @@ -26,6 +27,7 @@ output. This authored queue records the separately approved parallel chunks.

| Chunk | Title | Risk | Status |
|---|---|---:|---|
| `WS-ART-001-02B1` | S3-Compatible MinIO And AWS | L1 | Merged through PR #151 as `1b5422f` on 2026-07-19 |
| `WS-AUTH-001-09D-A` | Profile Lifecycle And Evidence Repair | L1 | Merged through PR #148 as `99ae4c9` on 2026-07-18 |
| `WS-AUTH-001-09C` | Actor And Identity-Link Administration Reads | L1 | Merged through PR #146 as `0ffdabf` on 2026-07-18 |
| `WS-ENG-001-01` | Codex-native zero-trust loop bootstrap | L1 | Merged through PR #23 on 2026-06-20 |
Expand Down Expand Up @@ -91,17 +93,22 @@ and its AUTH owner reconciliation merged through PR #140 as `d541521`.
AUTH-09A merged through PR #132 as `299363a`, and signed schema-v2 memory
stopped. AUTH-09B merged through PR #143 as `053242b`; the user then explicitly
started AUTH-09C. PR #146 merged it as `0ffdabf`; signed memory at `eeb3dc2`
stopped. Required review split AUTH-09D before runtime edits, and AUTH-09D-A
merged through PR #148 as `99ae4c9`. Do not start 09D-B, 09E, or POL-002-04
automatically.
stopped. The user explicitly started AUTH-09D, and required review split it
before runtime edits. PR #148 merged 09D-A as `99ae4c9`; signed memory
`cf8a3e8` stopped and named 09D-B. The user explicitly started 09D-B; exact
contract `9ec6390b` passed required L1 review. Implementation, deterministic
proof, and required internal review pass. PR #152 is open and integrates trusted
main at `1b5422f`; refreshed external checks and explicit human review are the
current gate. The contributor foundation is the next AUTH gate; 09E and
POL-002-04 remain inactive pending their own gates and explicit starts.

Coverage R10 merged through PR #108. Do not start 01B2, chunk 02, or another
coverage implementation chunk from this worktree.

`WS-ART-001-01`, the AWS-first planning amendment, `02A1`, `02A2`, and `02A3`
are merged; PR #141 merged `02A3` as `a10d901`. R2 and Flow Node are deferred.
The user explicitly started `02B1` on 2026-07-18. `02C1` remains inactive
until `02B1` merges and receives a separate explicit start.
`WS-ART-001-01`, the AWS-first planning amendment, `02A1`, `02A2`, `02A3`, and
`02B1` are merged; PR #151 merged `02B1` as `1b5422f`. R2 and Flow Node are
deferred. `02C1` remains inactive until signed merge memory and a separate
explicit start.

Coverage work proceeds independently in its own worktree and is not owned by
this AUTH queue update.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -33,9 +33,10 @@ stopped.
| `WS-AUTH-001-09B` | Controlled Service Actor Provisioning | L1 | Merged through PR #143 as `053242b` |
| `WS-AUTH-001-09C` | Actor And Identity-Link Administration Reads | L1 | Merged through PR #146 as `0ffdabf` |
| `WS-AUTH-001-09D` | Actor And Identity-Link Lifecycle Mutations | L1 | Split before runtime implementation into 09D-A and 09D-B |
| `WS-AUTH-001-09D-A` | Profile Lifecycle And Evidence Repair | L1 | Implementation and deterministic proof passed; exact-head internal review pending |
| `WS-AUTH-001-09D-B` | Identity-Link Lifecycle And Race Closure | L1 | Inactive until 09D-A merge/memory and explicit start |
| `WS-AUTH-001-09E` | Fixed Service Runtime Admission | L1 | Inactive until 09D-B merge/memory and explicit start |
| `WS-AUTH-001-09D-A` | Profile Lifecycle And Evidence Repair | L1 | Merged through PR #148 as `99ae4c9`; signed memory `cf8a3e8` passed |
| `WS-AUTH-001-09D-B` | Identity-Link Lifecycle And Race Closure | L1 | Implemented; deterministic proof and required internal review pass; ready PR publication |
| `WS-AUTH-001-CONTRIBUTOR-FOUNDATION` | Contributor Fields And Canonical-Human Lineage | L1 | Inactive until 09D-B merge/memory and explicit start |
| `WS-AUTH-001-09E` | Fixed Service Runtime Admission | L1 | Inactive until contributor-foundation merge/memory and explicit start |
| `WS-AUTH-001-ART-CUSTODY` | ART Activation Custody Transfer | L1 | Inactive until 09E merge/memory and explicit start |
| `WS-AUTH-001-REV-CUSTODY` | REV Activation Custody Transfer | L1 | Inactive until 09E merge/memory and explicit start |
| `WS-AUTH-001-PREP` | Prepared Mutation Authorization Protocol | L1 | Inactive until 09E merge/memory and explicit start |
Expand Down Expand Up @@ -97,6 +98,7 @@ WS-AUTH-001-PLAN
-> WS-AUTH-001-09C
-> WS-AUTH-001-09D-A
-> WS-AUTH-001-09D-B
-> WS-AUTH-001-CONTRIBUTOR-FOUNDATION
-> WS-AUTH-001-09E
-> WS-AUTH-001-ART-CUSTODY and WS-AUTH-001-REV-CUSTODY
-> WS-AUTH-001-PREP
Expand Down Expand Up @@ -132,8 +134,11 @@ WS-AUTH-001-PLAN
- PR #139 merged the WS-XINT boundary contract. `WS-AUTH-001-XINT` is the
planning-only AUTH owner response; it changes no runtime.
- Chunks 08-10 establish local grant truth before product cutover. Parent chunk
09 is split into 09A through 09E with no inserted dependency; 09E separately
admits fixed services without entering human grant evaluation. ART/REV custody
09 is split into 09A through 09E. The separately reviewed contributor
foundation follows 09D-B so REV can consume canonical human attribution
without waiting for the full AUTH-13/14 cutovers. It changes no authority or
lifecycle behavior. 09E separately admits fixed services without entering
human grant evaluation. ART/REV custody
transfer follows 09E and changes only owner metadata and availability-neutral
parity. PREP then establishes AUTH-first
locking and caller-owned commit before sensitive product/review mutations.
Expand Down Expand Up @@ -195,6 +200,10 @@ explicitly started AUTH-09B. PR #143 merged it as `053242b`; signed memory
stopped, and the user explicitly started AUTH-09C. PR #146 merged it as
`0ffdabf`; signed memory at `eeb3dc2` stopped. The user explicitly started
AUTH-09D. Required preimplementation review rejected the combined lifecycle
contract before runtime edits, so it is split into 09D-A and 09D-B. Only 09D-A
may proceed after its repaired contract passes exact review. Do not start
09D-B, 09E, or POL-002-04 automatically.
contract before runtime edits, so it was split into 09D-A and 09D-B. PR #148
merged 09D-A as `99ae4c9`; signed memory `cf8a3e8` stopped and named 09D-B. The
user explicitly started 09D-B; exact contract `9ec6390b` passed required L1
review. Implementation, deterministic proof, and required internal review pass;
ready PR publication is the current gate. The contributor foundation is the next
same-initiative gate; 09E and POL-002-04 remain inactive pending their own gates
and explicit starts.
Original file line number Diff line number Diff line change
Expand Up @@ -122,14 +122,19 @@ product vocabulary or authority concepts.

The field cutover is explicitly owned as follows:

- `WS-AUTH-001-13` renames assignment ownership from legacy `worker_id` to
`contributor_id` across storage, models, services, schemas, audits, and tests.
- `WS-AUTH-001-14` renames submission ownership/attestation and checker-result
visibility fields from legacy `worker_*` names to their `contributor_*`
equivalents across storage, models, services, schemas, audits, and tests. It
also renames the submission-policy JSON field `worker_facing_fix` to
- `WS-AUTH-001-CONTRIBUTOR-FOUNDATION` clean-cuts both retired assignment and
Submission human-owner identifiers to `contributor_id` across
storage, models, services, schemas, audits, and tests. It also supplies
database-backed canonical-human ActorProfile lineage and a transaction-local
active-human revalidation capability.
- `WS-AUTH-001-13` consumes the canonical assignment field during task
authorization cutover; it does not rename it again.
- `WS-AUTH-001-14` consumes the canonical Submission owner field and renames
the remaining submission attestation and checker-result visibility fields
from legacy `worker_*` names to their `contributor_*` equivalents. It also
renames the submission-policy JSON field `worker_facing_fix` to
`contributor_facing_fix` across derivation schemas, prompts, persistence, and
compatibility tests.
tests.
- Revision replay is not implemented yet and must begin with
`contributor_claim_status`; it must not introduce the legacy name.
- `ContributionRecord`, `CompensationAward`,
Expand Down Expand Up @@ -658,3 +663,24 @@ grant path that can remove the final effective Access Administrator, so no
target-first alternate lock path is introduced. Profile and link reactivation
invalidate from ineffective to effective; loss transitions invalidate from
effective to ineffective.

## D31: Prioritize the contributor/canonical-human foundation after AUTH-09D-B

Status: accepted sequencing reconciliation on 2026-07-18.

The prior plan left assignment ownership renaming in AUTH-13 and Submission
ownership renaming in AUTH-14. That creates an unnecessary dependency cycle:
REV needs canonical human attribution before its first runtime child, while the
full AUTH-13/14 product cutovers depend on later REV preparation behavior.

`WS-AUTH-001-CONTRIBUTOR-FOUNDATION` is therefore the next same-initiative gate
after AUTH-09D-B and before AUTH-09E. It clean-cuts only the two ownership fields,
adds reusable database-backed human ActorProfile lineage, and exposes bounded
transaction-local active-human revalidation. It changes no permission, action,
grant, lifecycle, or feature availability. AUTH-13/14 retain their later
authorization and lifecycle cutovers and consume the canonical fields.

The foundation allocates only the then-current next migration from trusted
`main`. This decision supersedes only the future fixed-number reservation
clauses in D29, D30, and earlier decisions; their other boundaries remain in
force. Merged migration ownership through AUTH-09D-A `0026` is unchanged.
Loading
Loading