Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
31 changes: 31 additions & 0 deletions .agent-loop/REVIEW_LOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,36 @@
# Review Log

## 2026-07-20 - WS-AUTH-001-ART-CUSTODY Internal Review Passed

- Exact code SHA `abb3fb1a035f544f5ee07b7d725451dfa2d90864` passes senior
engineering, QA/test, security/auth, product/ops, architecture, CI integrity,
docs, reuse/dedup, and test-delta review against trusted main `42a89b2d`.
- Initial candidate `e7c2602e` had self-referential owner expectations and
permissive documentation proof. The repair freezes literal owner truth,
parses exact custody tables and operations invariants, and proves no planned
ART action reaches revalidation or administrative grant dependencies.
- Forty-five focused cases, Ruff, stale scans, Markdown links, loop state,
merge intent, Alembic `0029`, migration no-diff, and diff integrity pass.
Hosted Backend remains the authoritative full-suite coverage gate.

## 2026-07-20 - WS-AUTH-001-ART-CUSTODY Preimplementation Review Passed

- PR #157 merged AUTH-09E to trusted `main` as `42a89b2d`; signed schema-v2
memory `a5b9bad3` stopped and named ART custody. The user explicitly started
this chunk on 2026-07-20.
- Initial QA/security/product/CI/test-delta review rejected self-derived
baselines, ambiguous database-owner parity, incomplete all-action denial
proof, unclear `OPERATOR` wording, missing non-ART freeze and hosted CI gate,
and insufficient reuse/test-preservation constraints before runtime edits.
- The repaired contract freezes all 65 action mappings and availability values,
exact counts and service matrix, the 25-row/eight-custodian ART map, every
non-ART owner, Alembic head `0029`, and zero migration delta. It requires all
25 actions to remain unavailable through the real kernel and keeps ART, REV,
and PREP as separate human-started chunks.
- Senior engineering, QA/test, security/auth, product/ops, architecture, CI
integrity, docs, reuse/dedup, and test-delta tracks pass. Implementation may
begin for ART custody only; no action availability or ART behavior may change.

## 2026-07-20 - WS-AUTH-001-09E External Review Repair

CodeRabbit raised two valid findings. The specification now says the service
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -37,10 +37,16 @@ mappings, and availability must remain identical.
| `WS-AUTH-001-ART-06A` | `artifact.post_submit.checker_input.materialize` |
| `WS-AUTH-001-ART-06B` | `artifact.checker_output.write`, `artifact.checker_output.binding.create` |

`WS-AUTH-001-ART-CUSTODY` performs the atomic 25-row transfer to eight exact AUTH
groups and removes the seven historical ART owner enum values. It adds no migration because owner and
availability are typed metadata, while PostgreSQL preserves the exact
ActionId-to-PermissionId set.
`WS-AUTH-001-ART-CUSTODY` atomically transfers these 25 rows with exact owner
cardinalities `3/8/3/6/1/1/1/2` in the table order above and removes the seven
historical ART owner enum values. The `OPERATOR` suffix denotes only future
activation custody; it grants no Operator entitlement. All 25 actions remain
planned, including independently gated `artifact.verification_job.retry`, which
cannot be activated by read/status proof. The transfer adds no migration because
owner and availability are typed metadata, while PostgreSQL preserves the exact
ActionId-to-PermissionId set. The catalogue remains at 74 PermissionIds,
65 ActionIds, 17 active actions, and 48 planned actions; the seven-identity,
eleven-membership service matrix is unchanged.

## REV custody transfer

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -53,13 +53,49 @@ partial transfer or retained ART activation-owner enum
## Acceptance criteria

- Exactly the 25 canonical rows move to the eight AUTH owner values.
- The exact owner cardinalities are `8/3/3/6/1/1/1/2` for
`WS-AUTH-001-ART-02D-OPERATOR`, `WS-AUTH-001-ART-02D-INTERNAL`,
`WS-AUTH-001-ART-03`, `WS-AUTH-001-ART-04A`,
`WS-AUTH-001-ART-04B`, `WS-AUTH-001-ART-05`,
`WS-AUTH-001-ART-06A`, and `WS-AUTH-001-ART-06B`, respectively.
- All seven ART owner enum values are removed atomically.
- Catalogue ActionId, PermissionId, active/planned counts, static matrix rows,
and every ActionId-to-PermissionId pair remain exactly equal to the trusted
entry head; this chunk has a zero-count and zero-availability delta.
- Typed, PostgreSQL, audit, definition-owner, and documentation parity reject
missing, extra, dual, or changed mappings.
- Every ART action remains unavailable through the real kernel.
- Frozen expectations independent of the modified catalogue bind the entry
baseline to trusted `main` SHA `42a89b2deac8fc7672556a567a6124f8a4e5d423`:
all 65 `(ActionId, PermissionId, availability)` tuples, 74 PermissionIds,
65 ActionIds, 17 active and 48 planned actions, and the exact seven-identity,
eleven-membership fixed-service matrix remain unchanged. This chunk has a
zero-count and zero-availability delta.
- The exact 25-row owner map is frozen independently of
`ACTION_DEFINITIONS`. Tests assert the eight new AUTH ART owners are present,
all seven historical ART owners are absent, and the catalogue rejects a
missing row, extra or duplicate row, wrong custodian, retained historical or
dual custody, changed mapping, and changed availability.
- Every non-ART owner assignment remains exactly equal to the frozen trusted
baseline, including all 19 REV rows and all seven historical REV owner enum
values.
- `WS-AUTH-001-ART-02D-OPERATOR` is only a future AUTH activation-custody
grouping. It grants no Operator authority and changes no permission, grant,
evaluator, route, service identity, or availability. In particular,
`artifact.verification_job.retry` remains planned and requires its own later
evaluator, guards, and independent activation proof; read/status proof cannot
activate retry.
- `ActionOwner` changes only in the typed catalogue. PostgreSQL and historical
audit evidence have no owner field and receive no write or rewrite. Database
and audit proof preserves the existing ActionId-to-PermissionId and evidence
contracts; it does not invent persisted owner parity.
- Canonical documentation tables enumerate the same 25-row/eight-owner handoff
and exact counts; documentation parity is checked deterministically in
addition to the stale-wording scan.
- Every one of the 25 ART actions remains unavailable through
`AuthorizationService.require()` using the real kernel. Each denial is
`action_unavailable`, is sensitive, records the exact action and permission,
and reaches no grant, evaluator, or ART behavior path.
- Alembic remains at the immutable entry head
`0029_shared_transactional_outbox`; `backend/alembic/**` has no diff and no
migration is added, edited, or allocated.
- This chunk transfers ART custody only. `WS-AUTH-001-REV-CUSTODY` remains a
separate later human-started chunk, followed by separately started
`WS-AUTH-001-PREP`; a combined ART/REV transfer is forbidden.

## Verification commands

Expand All @@ -68,18 +104,51 @@ partial transfer or retained ART activation-owner enum
(cd backend && WORKSTREAM_DATABASE_URL=<test-db> .venv/bin/python -m pytest -q tests/test_authorization.py tests/test_auth.py --cov=app.modules.authorization --cov-report=term-missing --cov-fail-under=90)
python3 scripts/check_stale_authorization_docs.py
python3 scripts/check_markdown_links.py
test -z "$(git diff --name-only 42a89b2deac8fc7672556a567a6124f8a4e5d423 -- backend/alembic)"
(cd backend && test "$(.venv/bin/alembic heads | tr -d '[:space:]')" = "0029_shared_transactional_outbox(head)")
git diff --check
```

After push, the existing GitHub `Backend` workflow is the authoritative full
suite gate. It must pass its isolated backend suite, preserve repository-wide
coverage at or above 78 percent, preserve authorization-subsystem coverage at
or above 90 percent, and pass every existing workflow gate. The full suite runs
in GitHub Actions rather than on the user's slow local machine. This chunk does
not change workflows, scripts, exclusions, thresholds, or package commands.

## Implementation and test reuse constraints

- Extend the existing exact catalogue expectation and `_index_actions()`
fail-closed tests in `backend/tests/test_authorization.py`; do not add a
parallel catalogue validator or a second 65-row fixture.
- Add one hand-authored test-only 25-row ART custody fixture, independent of
`ACTION_DEFINITIONS`, `ACTION_BY_ID`, enum-name prefixes, and production
grouping logic. Reuse that one fixture for owner cardinality, mutation,
real-kernel denial, and documentation-parity proof.
- Reuse the existing `_runtime_context()`, `_runtime_service()`, and decision
evidence test abstractions for all 25 real-kernel denial cases; do not add a
duplicate fake authorization stack.
- Add no production owner-family helper, prefix classifier, compatibility
alias, or new registry abstraction for this metadata-only transfer.
- Documentation parity may consume the independent test fixture, but neither
production metadata nor rendered documentation may derive the other's
expected values.
- Existing tests may not be removed, weakened, skipped, xfailed, deselected,
or have assertions relaxed. Every modified existing expectation retains all
trusted-baseline assertions and changes only the exact 25 ART owner values.
Tests removed, skipped, or xfailed by this chunk must remain zero.

## Required reviewers

Senior engineering, QA/test, security/auth, product/ops, architecture,
CI integrity, docs, reuse/dedup, and test delta.

## Human review focus

Verify exact 25-row/eight-owner custody transfer, unchanged mappings/counts, and zero
activation.
Verify the exact 25-row/eight-custodian ART transfer; all non-ART owners,
especially the 19 REV rows, remain unchanged; `OPERATOR` means a future custody
group rather than runtime entitlement; all 25 ART actions remain planned and
unavailable; and ART -> REV -> PREP remains separate and human-gated.

## Stop conditions

Expand Down
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
# Chunk Contract: WS-AUTH-001-REV-CUSTODY — REV Activation Custody Transfer
# Chunk Contract: WS-AUTH-001-REV-CUSTODY - REV Activation Custody Transfer

## Parent initiative

Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,77 @@
# WS-AUTH-001-ART-CUSTODY Internal Review Evidence

Reviewed code SHA: `a20ab6b2004e2f7a13e1e0d600595f0af7d67985`

Reviewed implementation SHA: `abb3fb1a035f544f5ee07b7d725451dfa2d90864`

Reviewed pre-CI status SHA: `125e018b8fa13b38a0cc66dfa9c724c040d84ae1`

Reviewed against trusted main: `42a89b2deac8fc7672556a567a6124f8a4e5d423`

Reviewed at: `2026-07-20T10:49:58Z`

Reviewer run IDs: `plan_product`, `plan_qa`, `plan_security`

Reviewer tracks: senior engineering, QA/test, security/auth, product/ops,
architecture, CI integrity, docs, reuse/dedup, and test delta

## Deterministic Evidence

- Ruff passed for the complete backend application and test trees.
- Forty-five focused catalogue, fixed-service matrix, fail-closed construction,
documentation-parity, and real-kernel custody cases passed. The 25 ART
actions each deny as sensitive `action_unavailable` evidence with exact
action and permission and cannot reach revalidation or administrative grant
dependencies.
- The literal test fixture independently freezes all 25 action, permission,
owner, and `planned` values. Exact documentation parsing rejects missing,
extra, duplicate, or wrong-custodian rows and checks owner cardinalities,
spec mappings, counts, and operations invariants.
- Stale Workstream and authorization wording scans, Markdown links, loop-memory
state, merge-intent validation, Alembic `0029_shared_transactional_outbox`
head, migration-directory no-diff, and diff integrity pass.
- No workflow, dependency, ActionId, PermissionId, mapping, availability,
evaluator, grant, route, service identity, matrix membership, persistence,
audit schema, or migration changed.
- The unchanged GitHub Backend workflow remains the mandatory hosted full-suite
proof for the 78 percent repository-wide and 90 percent authorization
subsystem coverage floors. No local full-suite result is claimed.

## Reviewer Results

| Reviewer | Result | Blocking findings | Notes |
|---|---|---|---|
| senior engineering | PASS AFTER FIXES | none | Exact bounded documentation parsing replaced permissive substring proof. |
| QA/test | PASS AFTER FIXES | none | Literal fixtures, exact docs parity, and exploding downstream dependencies close self-derived proof gaps. |
| security/auth | PASS | none | All 25 actions stay planned and unavailable; no database, audit, grant, or runtime path changes. |
| product/ops | PASS | none | `OPERATOR` is custody-only, retry stays independent, and ART -> REV sequencing remains human-gated. |
| architecture | PASS | none | AUTH changes activation custody metadata while ART retains feature facts, guards, and behavior. |
| CI integrity | PASS | none | No CI weakening; hosted full coverage remains mandatory. |
| docs | PASS | none | Spec, operations, custody, state, queue, map, and contract wording are consistent. |
| reuse/dedup | PASS | none | Existing catalogue/kernel helpers are reused; the sole literal fixture and parser remain test-only. |
| test delta | PASS | none | No test removal, skip, xfail, deselection, assertion relaxation, or threshold change. |

## Findings Resolved

Valid findings addressed: yes

Open sub-agent sessions: none

Initial candidate `e7c2602e` used production enum members as expected owner
truth and only checked documentation substring presence. Repaired exact code
SHA `abb3fb1a` uses literal action/permission/owner/availability truth, parses
the bounded canonical tables exactly, asserts operations invariants, and fails
if any planned ART action reaches a downstream authorization dependency. All
nine implementation tracks pass with no remaining finding. Final candidate
`125e018b` adds only deterministic status/review-log updates; all nine tracks
confirmed that exact SHA without a remaining finding. GitHub Agent Gates then
exposed a trusted-main fixture invariant for four authored status files. Repair
`a20ab6b2` restores those files byte-for-byte to `origin/main` without changing
the gate or implementation; all 88 agent-gate regression tests and all nine
exact-SHA repair tracks pass.

## Remaining Risk And Gate

GitHub Backend, Agent Gates, external review, and explicit human review remain.
All 25 ART actions remain planned and unavailable. REV custody remains a
separate successor requiring signed memory and an explicit human start.
Original file line number Diff line number Diff line change
@@ -0,0 +1,67 @@
# WS-AUTH-001-ART-CUSTODY PR Trust Bundle

## Goal

Transfer exactly 25 planned ART action-owner labels to eight exact AUTH
activation custodians without changing permission mappings, availability, or
ART behavior.

## Changes And Design

- Removes seven historical ART `ActionOwner` enum values and adds eight exact
AUTH activation-custodian values.
- Changes only the owner field of the 25 canonical ART definitions and the
matching closed fixed-service metadata expectations.
- Preserves 74 PermissionIds, 65 ActionIds, 17 active and 48 planned actions,
every ActionId-to-PermissionId pair, all non-ART owners, and the exact
seven-identity/eleven-membership service matrix.
- Adds literal independent catalogue truth, exact documentation parity, and
all-25 real-kernel denial proof.

## Scope Control

No migration, database or audit rewrite, availability change, evaluator,
resource composer, route, command, grant, service provisioning, identity,
matrix membership, or ART runtime behavior is included. `OPERATOR` denotes
future activation custody only and creates no entitlement. Verification retry
remains planned and independently gated.

## Proof And CI Integrity

- Ruff passed for `app` and `tests`.
- 45 focused catalogue/kernel/documentation tests passed.
- Stale wording, stale authorization docs, Markdown links, loop-memory state,
merge intent, Alembic-head/no-migration, and diff checks passed.
- No tests or assertions were removed or weakened; no skips, xfails,
deselection, exclusions, workflows, scripts, or thresholds changed.
- GitHub Backend remains the authoritative full-suite gate for global coverage
at or above 78 percent and authorization coverage at or above 90 percent.

## Internal Review

Final reviewed SHA `a20ab6b2004e2f7a13e1e0d600595f0af7d67985`, containing
reviewed implementation `abb3fb1a035f544f5ee07b7d725451dfa2d90864`, against
trusted main `42a89b2deac8fc7672556a567a6124f8a4e5d423` passes senior engineering,
QA/test, security/auth, product/ops, architecture, CI integrity, docs,
reuse/dedup, and test-delta review after all valid proof findings were repaired.
The final CI repair preserves four authored trusted-main status fixtures
byte-for-byte rather than weakening their gate; all 88 agent-gate regression
tests pass. Canonical live state remains automation-owned.

## Remaining Risk And Follow-up

Hosted Backend CI, Agent Gates, CodeRabbit, and human review remain. The merge
intent names only `WS-AUTH-001-REV-CUSTODY`, which remains inactive until this
PR merges, signed memory succeeds, and the user explicitly starts it.

## Human Review Focus

Verify the exact 25-row/eight-custodian owner-only delta, unchanged non-ART and
REV owners, unchanged mappings/counts/matrix/availability, custody-only
`OPERATOR` meaning, independent retry gating, and absence of a migration.

## Human Merge Ownership

The agent may publish and repair this branch but may not merge it. Only the
human may approve this PR for merge. Trusted-main automation owns post-merge
schema-v2 memory generation when the workflow succeeds.
9 changes: 9 additions & 0 deletions .agent-loop/merge-intents/WS-AUTH-001-ART-CUSTODY.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
{
"chunk_id": "WS-AUTH-001-ART-CUSTODY",
"chunk_title": "ART Activation Custody Transfer",
"initiative_id": "WS-AUTH-001",
"next_chunk_id": "WS-AUTH-001-REV-CUSTODY",
"next_chunk_title": "REV Activation Custody Transfer",
"next_requires_explicit_start": true,
"schema_version": 2
}
Loading
Loading