Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
20 commits
Select commit Hold shift + click to select a range
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
25 changes: 17 additions & 8 deletions .agent-loop/LOOP_STATE.md
Original file line number Diff line number Diff line change
Expand Up @@ -20,12 +20,18 @@
`eeb3dc2` recorded its two administrative reads and stopped.
- PR #141 merged `WS-ART-001-02A3` into `main` as `a10d901` on 2026-07-18.
PR #151 then merged `WS-ART-001-02B1` as `1b5422f` on 2026-07-19;
ART-02C1 remains inactive pending signed memory and a separate explicit start.
the user then explicitly started ART-02C1.
- Active ART implementation chunk: `WS-ART-001-02C1` on
`codex/ws-art-001-02c1-admission-put-attempt`.
- The ART worktree consumes merged AUTH, REV, and CON contracts without
editing or activating their independently owned runtime behavior.
- AUTH-09D-A merged through PR #148 as `99ae4c9`; signed schema-v2 memory at
`cf8a3e8` recorded the stopped gate and exact 09D-B successor.
- AUTH-09D-B merged through PR #152 as `93dd392`; signed schema-v2 memory at
`912a6254` stopped and named the contributor foundation as its exact
successor.
- PR #153 merged `WS-AUTH-001-CONTRIBUTOR-FOUNDATION` as `8d5eb15`; ART-02C1
now integrates that trusted `main` state without activating AUTH-09E.
- PR #119 merged `WS-AUTH-001-05B` as `ad71c7e`.
- PR #120 merged `WS-ART-001-OBJECT-STORAGE-AMENDMENT` as `4408256`.
- PR #122 merged the first automated post-merge memory implementation as
Expand All @@ -38,6 +44,11 @@
required internal tracks. PR publication and external checks are the current
gate; Backend must still prove 78/90 percent aggregate coverage. It changes no action
availability, and no service caller becomes executable before AUTH-09E.
- Current ART gate: integrate trusted `main`, complete deterministic 02C1
proof, and pass all nine exact-SHA internal reviewer tracks. Those steps are
complete; publish the final candidate to existing PR #154, then pass fresh
external checks and explicit human review. No later ART chunk starts
automatically.
- Scope checkpoint: AWS S3 is the only v0.1 production provider; MinIO is
local/CI S3 protocol proof; LocalStorage is focused development/test; R2 and
Flow Node are deferred. Product modules receive narrow artifact capabilities,
Expand All @@ -55,13 +66,11 @@
admission, prepared mutation authority, and exact AUTH-only activation chunks;
neither reconciliation PR activates feature behavior.
- Parallel artifact checkpoint: ART-02A1, ART-02A2, ART-02A3, and ART-02B1
merged through PRs #127, #129, #141, and #151. ART-02B1 adds real MinIO
protocol proof plus a fail-closed, runtime-ineligible native AWS profile;
ART-02C1 remains inactive.
- Authorization checkpoint: AUTH-07B through AUTH-09D-B merged through PRs
#130, #131, #132, #143, #146, #148, and #152. The contributor foundation is
internally approved at code SHA `4d1fc507`; AUTH-09E remains
inactive.
merged through PRs #127, #129, #141, and #151. ART-02C1 is active and adds
only durable admission plus prepared put-attempt state before provider I/O.
- Authorization checkpoint: AUTH-07B through AUTH-09D-B and the contributor
foundation merged through PRs #130, #131, #132, #143, #146, #148, #152,
and #153. AUTH-09E remains inactive.
- Parallel coverage work: `WS-QUAL-001-01B2` remains paused. Its last official
whole-app result is `6466/8159` statements (`79.249908%`); no replacement
evidence exists.
Expand Down
10 changes: 5 additions & 5 deletions .agent-loop/WORK_QUEUE.md
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,7 @@
| Chunk | Title | Risk | Status |
|---|---|---:|---|
| `WS-AUTH-001-CONTRIBUTOR-FOUNDATION` | Contributor Fields And Canonical-Human Lineage | L1 | Internal review passed at `4d1fc507`; PR/external checks pending; aggregate coverage mandatory in Backend |
| `WS-ART-001-02C1` | Admission And Put-Attempt Foundation | L1 | Active after PR #151 and explicit user start; implementation and deterministic proof in progress |

Live post-merge state remains read from signed `automation/loop-memory`
output. This authored queue records the separately approved parallel chunks.
Expand All @@ -17,7 +18,6 @@ output. This authored queue records the separately approved parallel chunks.
| `WS-AUTH-001-09E` | Fixed Service Runtime Admission | L1 | Inactive until contributor-foundation merge/memory and explicit user start |
| `WS-QUAL-001-02` | Project Service Coverage | L1 | Inactive until 01B2 merge/memory plus explicit user start |
| `WS-POL-002-04` | Locked Runtime Execution And Routing Hardening | L1 | Inactive pending relevant authorization proof and a separate explicit user start |
| `WS-ART-001-02C1` | Admission And Put-Attempt Foundation | L1 | Inactive until signed 02B1 merge memory and explicit user start |
| `WS-ART-001-02C2` | Verification Publication And Fencing | L1 | Inactive until 02C1 merge and explicit user start |
| `WS-ART-001-02C3` | Recovery Attempt And Idempotency Chain | L1 | Inactive until 02C2 merge and explicit user start |
| `WS-ART-001-02D` | Operator Artifact Operations And AWS Readiness | L1 | Inactive until 02C3 and exact AUTH prerequisites |
Expand All @@ -26,7 +26,7 @@ output. This authored queue records the separately approved parallel chunks.

| Chunk | Title | Risk | Status |
|---|---|---:|---|
| `WS-ART-001-02B1` | S3-Compatible MinIO And AWS | L1 | Merged through PR #151 as `1b5422f` on 2026-07-19 |
| `WS-ART-001-02B1` | S3-Compatible MinIO And AWS | L1 | Merged through PR #151 as `1b5422fc` on 2026-07-19 |
| `WS-AUTH-001-09D-A` | Profile Lifecycle And Evidence Repair | L1 | Merged through PR #148 as `99ae4c9` on 2026-07-18 |
| `WS-AUTH-001-09C` | Actor And Identity-Link Administration Reads | L1 | Merged through PR #146 as `0ffdabf` on 2026-07-18 |
| `WS-ENG-001-01` | Codex-native zero-trust loop bootstrap | L1 | Merged through PR #23 on 2026-06-20 |
Expand Down Expand Up @@ -105,9 +105,9 @@ Coverage R10 merged through PR #108. Do not start 01B2, chunk 02, or another
coverage implementation chunk from this worktree.

`WS-ART-001-01`, the AWS-first planning amendment, `02A1`, `02A2`, `02A3`, and
`02B1` are merged; PR #151 merged `02B1` as `1b5422f`. R2 and Flow Node are
deferred. `02C1` remains inactive until signed merge memory and a separate
explicit start.
`02B1` are merged; PR #151 merged `02B1` as `1b5422fc`. R2 and Flow Node are
deferred. The user explicitly started `02C1` on 2026-07-19. `02C2` remains
inactive until `02C1` merges and receives a separate explicit start.

Coverage work proceeds independently in its own worktree and is not owned by
this AUTH queue update.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -10,8 +10,8 @@ Each chunk is one PR. No later chunk starts automatically.
| `WS-ART-001-02A1` | Install only ADR 0014's small typed external-service adapter/factory foundation without migrating a capability. | L1 | Merged through PR #127 as `f64a8e5` |
| `WS-ART-001-02A2` | Add bounded committed-source preparation and inactive scratch-cleanup mechanics without changing the active v1 port. | L1 | Merged through PR #129 as `9a04434` on 2026-07-16 |
| `WS-ART-001-02A3` | Replace ArtifactStore v1 with byte-only v2, activate API-startup and Celery Beat scratch cleanup, migrate schema/callers/factory, and remove `flow_node` in one atomic clean cut. | L1 | Merged through PR #141 as `a10d901` on 2026-07-18 |
| `WS-ART-001-02B1` | Implement the S3-compatible adapter, MinIO integration, and AWS S3 production profile. | L1 | Active after 02A3 merged through PR #141 and explicit user start |
| `WS-ART-001-02C1` | Add the generic durable-byte admission ledger and durable put-attempt state foundation without provider execution. | L1 | Proposed after 02B1 |
| `WS-ART-001-02B1` | Implement the S3-compatible adapter, MinIO integration, and AWS S3 production profile. | L1 | Merged through PR #151 as `1b5422fc` on 2026-07-19 |
| `WS-ART-001-02C1` | Add the generic durable-byte admission ledger and durable put-attempt state foundation without provider execution. | L1 | Active after PR #151 and explicit user start on 2026-07-19 |
| `WS-ART-001-02C2` | Add put resolution, verification publication, complete-object observation, immutable receipts, and PostgreSQL execution fencing without recovery attempts or routes. | L1 | Proposed after 02C1 |
| `WS-ART-001-02C3` | Add the recovery-attempt model and exact idempotent source-job to retry-job chain without public or Operator routes. | L1 | Proposed after 02C2 |
| `WS-ART-001-02D` | Add hidden Operator content/job/retry/recovery/audit APIs, canonical resource composition, and production-readiness checks while actions and provider profiles remain inactive. | L1 | Proposed after 02C3, AUTH-09E, and `WS-AUTH-001-ART-CUSTODY` |
Expand Down
Original file line number Diff line number Diff line change
@@ -1,21 +1,24 @@
# Status: WS-ART-001 S3-Compatible Object Storage Amendment
# Status: WS-ART-001 Immutable Artifact Storage

## Current State

Original planning merged through PR #97, artifact/LocalStorage foundation
merged through PR #101, the AWS-first object-storage amendment merged through
PR #120 as `4408256`, the external-service adapter foundation merged through
PR #127 as `f64a8e5`, committed-source preparation merged through PR #129 as
`9a04434`, and the ArtifactStore v2 Local clean cut merged through PR #141 as
`a10d901` on 2026-07-18. The user explicitly started `WS-ART-001-02B1` on
2026-07-18.
`9a04434`, the ArtifactStore v2 Local clean cut merged through PR #141 as
`a10d901`, and S3-compatible MinIO/AWS preparation merged through PR #151 as
`1b5422fc` on 2026-07-19. The user explicitly started `WS-ART-001-02C1` on
2026-07-19.

The planning-only cross-initiative boundary reconciliation merged through
PR #139 as `5d353b6`, and AUTH's owner reconciliation merged through PR #140 as
`d541521`. ART now consumes AUTH's canonical activation-custody and prepared
mutation contracts without editing or activating AUTH runtime behavior.
AUTH-09D-A merged through PR #148 as `99ae4c9` and is integrated into the ART
candidate; AUTH-09D-B remains inactive.
AUTH-09D-A merged through PR #148 as `99ae4c9`, AUTH-09D-B merged through PR
#152 as `93dd392`, and the contributor foundation merged through PR #153 as
`8d5eb15b`; all are integrated into the ART candidate. AUTH-09E remains
inactive.

The Flow Node-focused amendment candidate `6cc422d` passed deterministic checks
but failed internal review on recovery/API completeness. Before repair, the user
Expand All @@ -34,29 +37,32 @@ approval or reusable evidence. Its source remains on branch

## Current Work

`WS-ART-001-02B1` is active. It adds one `S3CompatibleArtifactStore`, runs the
shared ArtifactStore v2 vectors against real digest-pinned MinIO, and validates
an isolated native-AWS workload-identity profile. MinIO is runtime-eligible
only in local/development/test after the PostgreSQL namespace claim. Native AWS
remains runtime-ineligible and fails with
`artifact_provider_live_proof_required` before factory construction,
credential resolution, namespace claim, or provider I/O. No product ingest,
durable admission, put-attempt resolution, verification job, recovery route,
or optional-provider runtime is activated. R2 and Flow Node remain deferred.
`WS-ART-001-02C1` is active. It adds the PostgreSQL durable-byte admission
ledger, closed internal guide/contributor/checker-output requests, and one
`prepared` `ArtifactPutAttempt` created atomically before provider I/O. Scope
limits are explicit configuration; callers cannot supply scope collections;
exact content is charged once per task, producer, project, and deployment
scope. Provider execution, verification, publication, recovery, routes, and
product cutover remain inactive. Native AWS remains runtime-ineligible. R2 and
Flow Node remain deferred.

Final implementation SHA `535069cfb1a7312d731bb14a6023ceb0894402e9`
passed 371 focused tests with 94.02 percent scoped coverage and all nine
required internal reviewer tracks. The current gate is publication of that
reviewed candidate to existing PR #154 followed by fresh GitHub and CodeRabbit
evidence.

## Next Proposed Chunk

`02C1` owns generic durable-byte admission and put-attempt state only after
`02B1` merges and receives a separate explicit start. Neither R2 nor Flow Node
`02C2` may add fenced put resolution and verification publication only after
`02C1` merges and receives a separate explicit start. Neither R2 nor Flow Node
has a v0.1 chunk.

## Gate

The reviewed implementation recorded: "The current gate is deterministic 02B1
proof followed by all nine exact-SHA internal reviewer tracks." After integrating
latest `main`, including merged REV planning, that gate passed again at
`9cd5620e` after addressing all four valid CodeRabbit findings, with no ART
runtime or ownership drift. The remaining gate is the post-fix GitHub Actions
and CodeRabbit rerun plus explicit human review. Durable admission, put attempts,
verification publication, and recovery remain in later owning chunks. No later
artifact chunk starts automatically, and only the user may approve merge.
The current gate is deterministic 02C1 proof followed by all nine exact-SHA
internal reviewer tracks; that gate is complete. GitHub Actions, CodeRabbit,
and explicit human review remain pending on the published final candidate.
Provider execution, verification publication, and recovery remain in later
owning chunks. No later artifact chunk starts automatically, and only the user
may approve merge.
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# Chunk Contract: WS-ART-001-02C1 - Admission And Put-Attempt Foundation

Initiative: `WS-ART-001` | Risk: L1 | Status: Proposed after 02B1
Initiative: `WS-ART-001` | Risk: L1 | Status: Active after explicit user start

Artifact contract phase: `artifact_store_cutover`

Expand All @@ -15,9 +15,13 @@ publication, recovery, Operator routes, and product cutovers inactive.
- one artifact-foundation migration;
- artifact admission and put-attempt models, schemas, repository, service, and
contracts;
- the actors-owned frozen admission-proof contract, repository lock, and
service method required to revalidate an exact profile/link pair in the
caller-owned admission transaction;
- `backend/app/core/config.py` for durable byte limits;
- generic audit repository only when existing audit support is insufficient;
- focused PostgreSQL admission, concurrency, migration, and state tests;
- focused actor/artifact ownership-boundary and transactional proof tests;
- `.github/workflows/backend.yml` only to expand the exact 90 percent scoped gate;
- `scripts/test_agent_gates.py` only to assert that backend CI retains this
chunk's exact scoped coverage sources and fail-closed 90 percent threshold;
Expand All @@ -31,6 +35,8 @@ publication, recovery, Operator routes, and product cutovers inactive.
- provider mutation replay, overwrite, delete, retain, or release;
- task-claim or reviewer-lease changes;
- production dispatch or activation.
- AUTH permission decisions or action activation, actor provisioning or
lifecycle mutation, and actor-facing routes or product cutover.

## Acceptance Criteria

Expand Down Expand Up @@ -80,7 +86,7 @@ coverage report --include='app/modules/audit/*' --precision=2 --fail-under=90

```bash
docker compose up -d --wait postgres redis minio
(cd backend && WORKSTREAM_TEST_DATABASE_URL=postgresql+asyncpg://workstream:workstream@localhost:5433/workstream_test .venv/bin/pytest tests/test_alembic.py tests/test_artifact_admission.py tests/test_config.py -q --cov=app.interfaces.artifact_operations --cov=app.modules.artifacts --cov=app.modules.audit --cov=app.core.config --cov-report=term-missing --cov-fail-under=90)
(cd backend && WORKSTREAM_DATABASE_URL=postgresql+asyncpg://workstream:workstream@localhost:5433/workstream_test WORKSTREAM_TEST_DATABASE_URL=postgresql+asyncpg://workstream:workstream@localhost:5433/workstream_test .venv/bin/pytest tests/test_artifact_admission.py tests/test_artifact_architecture.py tests/test_artifact_cleanup_wiring.py tests/test_artifact_preparation.py tests/test_artifact_store_conformance.py tests/test_artifacts.py tests/test_local_artifact_store.py tests/test_s3_artifact_store.py tests/test_audit.py tests/test_config.py -q --cov=app.interfaces.artifact_operations --cov=app.modules.artifacts --cov=app.modules.audit --cov=app.core.config --cov-report=term-missing --cov-fail-under=90)
(metadata_dir="$(mktemp -d)" && trap 'rm -rf "$metadata_dir"' EXIT && (cd backend && WORKSTREAM_TEST_ADMIN_DATABASE_URL=postgresql+asyncpg://workstream:workstream@localhost:5433/postgres .venv/bin/python scripts/run_isolated_tests.py --metadata-json "$metadata_dir/result.json" --timeout-seconds 12600 -- .venv/bin/python -m pytest -q --ignore=tests/test_isolated_database_runner.py --cov=app --cov-report=term-missing --cov-fail-under=78))
(cd backend && .venv/bin/ruff check app tests)
python3 scripts/check_stale_artifact_contracts.py
Expand Down
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
# Chunk Contract: WS-ART-001-02C2 Verification Publication And Fencing
# Chunk Contract: WS-ART-001-02C2 - Verification Publication And Fencing

Initiative: `WS-ART-001` | Risk: L1 | Status: Proposed after 02C1

Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,67 @@
# External Review Response: WS-ART-001-02C1

## Boundary

This file records GitHub Actions and CodeRabbit separately from internal
review. It does not replace internal exact-SHA evidence.

Reviewed implementation SHA: `535069cfb1a7312d731bb14a6023ceb0894402e9`

Trusted base: `8d5eb15b384fd75787ce98a099400a1d335d2560`

PR: #154, `https://github.com/Flow-Research/workstream/pull/154`

## Historical Evidence

Earlier GitHub and CodeRabbit results ran on pre-rebase heads and are not
evidence for the reviewed implementation SHA. The old remote Backend failure
was caused by stale migration-head expectations before the contributor
foundation rebase; local current-SHA migration and focused proof pass. No old
external PASS is carried forward.

## Current Status

| Source | Status | Notes |
|---|---:|---|
| GitHub Agent Gates | Pending | Await publication of the rebased final candidate. |
| GitHub Backend | Pending | Must run the full isolated suite, all scoped gates, and 78-percent floor on the final head. |
| CodeRabbit | Pending | Request a fresh review on the published final head. |
| Human review | Pending | Only the user may approve merge. |

## Current-Head Triage

Comments addressed:

- The first Agent Gates and Backend runs on evidence head `a93be2ec` failed at
the shared internal-review evidence parser before tests. The regenerated
evidence used non-canonical provenance labels and verdict text.
- Evidence now uses the required `Reviewed code SHA`, UTC `Reviewed at`, and
`Reviewer run IDs` labels. QA and docs use canonical `PASS after fixes` with
no remaining blocking findings.

Comments deferred: none.

Human decisions needed: explicit merge approval only after external checks pass.

Commands rerun:

```text
PR_HEAD_SHA=a93be2ec25689e1f8e036321d8a45b1fe35455ed python3 scripts/check_internal_review_evidence.py: PASS
python3 scripts/test_agent_gates.py: PASS, 88 tests
python3 scripts/check_markdown_links.py: PASS
git diff --check: PASS
```

Remaining risks: GitHub and CodeRabbit must complete against the corrected
published evidence head.

## Response Rule

Assess only external findings verified against the published final head. Any
implementation, test, workflow, policy, specification, or chunk-contract repair
requires affected internal reviewers to rerun and evidence to be rebound.

## Stop Condition

Wait for fresh external checks and explicit user approval of PR #154. Do not
merge and do not start `WS-ART-001-02C2` automatically.
Loading
Loading