Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
14 changes: 14 additions & 0 deletions .agent-loop/REVIEW_LOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -2646,3 +2646,17 @@ rejected the stale pre-final evidence record. This state-transition commit is
therefore the exact review target; its evidence-only descendant must bind the
reviewed SHA, record every reviewer run, pass the evidence gate, and then receive
final CI/docs confirmation before external checks resume.
## 2026-07-20 - WS-AUTH-001-REV-CUSTODY Internal Review

The inherited REV custody contract failed preimplementation review because it
did not independently freeze the exact 19-row transfer, non-dispatch denial,
documentation parity, migration boundary, or hosted coverage gates. The
repaired contract passed all nine plan-review tracks before production edits.

Implementation candidate `c95239b9` then received all nine required tracks.
Review found a retained ART documentation regression and a stale spec statement
that still described REV custody as pending. Candidate `baa86dfe` restores the
exact ART no-migration invariant, records REV no-migration separately, and
states the completed owner-only transfer. Sixty-three focused cases and all
deterministic scans pass; all nine exact-SHA reviewers report PASS with no open
finding. GitHub full-suite, Agent Gates, CodeRabbit, and human review remain.
Original file line number Diff line number Diff line change
Expand Up @@ -60,9 +60,13 @@ eleven-membership service matrix is unchanged.
| `WS-AUTH-001-REV-11` | `review.lease.force_release`, `review.queue.routing.override`, `review.queue.routing.correct`, `review.queue.close`, `review.reconcile.run` |
| `WS-AUTH-001-REV-12` | `review.artifact_reference.reconcile`, `review.projection.rebuild` |

`WS-AUTH-001-REV-CUSTODY` performs the atomic 19-row transfer and removes the
seven historical REV owner enum values. It changes no mapping or availability
and adds no migration.
`WS-AUTH-001-REV-CUSTODY` atomically transfers these 19 rows with exact owner
cardinalities `2/5/3/1/1/5/2` in the table order above and removes the seven
historical REV owner enum values. It changes no mapping or availability and
adds no migration. All 19 actions remain planned and unavailable; these AUTH
custodian labels grant no reviewer, Operator, or service authority. The four
proposed lifecycle actions remain unregistered, and PREP remains separately
human-gated.

## Additive registration gates

Expand Down
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
# Chunk Contract: WS-AUTH-001-PREP — Prepared Mutation Authorization Protocol
# Chunk Contract: WS-AUTH-001-PREP - Prepared Mutation Authorization Protocol

## Parent initiative

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -54,10 +54,54 @@ partial transfer or retained REV activation-owner enum
## Acceptance criteria

- Exactly the 19 canonical rows move to the seven AUTH owner values.
- The exact owner cardinalities are `2/5/3/1/1/5/2` for
`WS-AUTH-001-REV-05`, `WS-AUTH-001-REV-06`, `WS-AUTH-001-REV-07`,
`WS-AUTH-001-REV-08`, `WS-AUTH-001-REV-09A`, `WS-AUTH-001-REV-11`, and
`WS-AUTH-001-REV-12`, respectively.
- All seven REV owner enum values are removed atomically.
- Catalogue counts, mappings, active/planned state, PostgreSQL audit parity,
and denial behavior remain unchanged.
- Every REV action remains unavailable through the real kernel.
- Frozen expectations independent of the modified catalogue bind the entry
baseline to trusted `main` SHA
`be2a79a243ec50049c37f1f634322a9b3ab895ba`: all 65
`(ActionId, PermissionId, availability)` tuples, 74 PermissionIds,
65 ActionIds, 17 active and 48 planned actions, and the exact seven-identity,
eleven-membership fixed-service matrix remain unchanged. This chunk has a
zero-count, zero-mapping, zero-availability, and zero-service-matrix delta.
- The exact 19-row action, permission, owner, and `planned` map is frozen in one
hand-authored test-only fixture independent of `ACTION_DEFINITIONS`,
`ACTION_BY_ID`, owner enums, identifier prefixes, grouping logic, and
documentation. Tests assert all seven new AUTH REV owners are present, all
seven historical `WS-REV-*` owner values are absent, and catalogue
construction rejects a missing row, extra or duplicate row, wrong or swapped
custodian, retained historical or dual custody, changed mapping, and changed
availability.
- Every non-REV owner assignment remains exactly equal to the frozen trusted
baseline, including all 25 merged ART AUTH custody rows. The four proposed
REV lifecycle actions remain absent from the registered catalogue.
- `ActionOwner` changes only in the typed catalogue. PostgreSQL and historical
audit evidence have no owner field and receive no write or rewrite. Database
and audit proof preserves the existing ActionId-to-PermissionId and evidence
contracts; it does not invent persisted owner parity.
- Canonical documentation tables enumerate the same exact 19-row,
seven-custodian handoff and cardinalities. Documentation parity is parsed and
checked deterministically in addition to stale-wording and Markdown-link
scans. Custodian labels grant no reviewer, Operator, or service authority.
- Every one of the 19 REV actions remains unavailable through
`AuthorizationService.require()` using the real kernel. Each denial is
sensitive `action_unavailable`, records the exact action and permission, is
not revalidated, records one bounded denial event, and reaches no grant,
evaluator, revalidation, route, job, or REV behavior path.
- Alembic remains at the immutable entry head
`0029_shared_transactional_outbox`; `backend/alembic/**` has no diff and no
migration is added, edited, reserved, or allocated.
- Existing tests are not removed, skipped, xfailed, deselected, weakened, or
rewritten to derive expected truth from changed production metadata or docs.
Modified existing expectations retain all baseline assertions and change only
the exact 19 owner values.
- This chunk transfers REV custody only. `WS-AUTH-001-PREP` remains a separate
later human-started chunk; combined REV/PREP work is forbidden.
- Exactly one schema-v2 merge intent is added for this chunk, naming only the
declared same-initiative `WS-AUTH-001-PREP` successor with a separate explicit
human start.

## Verification commands

Expand All @@ -66,9 +110,37 @@ partial transfer or retained REV activation-owner enum
(cd backend && WORKSTREAM_DATABASE_URL=<test-db> .venv/bin/python -m pytest -q tests/test_authorization.py tests/test_auth.py --cov=app.modules.authorization --cov-report=term-missing --cov-fail-under=90)
python3 scripts/check_stale_authorization_docs.py
python3 scripts/check_markdown_links.py
test -z "$(git diff --name-only be2a79a243ec50049c37f1f634322a9b3ab895ba -- backend/alembic)"
(cd backend && test "$(.venv/bin/alembic heads | tr -d '[:space:]')" = "0029_shared_transactional_outbox(head)")
git diff --check
```

After push, the unchanged GitHub `Backend` workflow is the authoritative full
suite gate. It must pass its isolated backend suite, preserve repository-wide
coverage at or above 78 percent, preserve authorization-subsystem coverage at
or above 90 percent, and pass every existing workflow gate. The full suite runs
in GitHub Actions rather than on the user's slow local machine. This chunk does
not change workflows, scripts, exclusions, thresholds, coverage configuration,
or package commands.

## Implementation and test reuse constraints

- Extend the existing exact catalogue expectation and `_index_actions()`
fail-closed tests in `backend/tests/test_authorization.py`; do not add a
parallel catalogue validator or a second 65-row fixture.
- Add one hand-authored test-only 19-row REV custody fixture and reuse it for
owner/cardinality, mutation, real-kernel denial, and documentation-parity
proof.
- Reuse the existing ART custody table parser pattern, `_runtime_context()`,
`_runtime_service()`, and decision-evidence abstractions. Exploding
revalidation, admin/grant, evaluator, and downstream dependencies must prove
planned actions fail before dispatch.
- Add no production owner-family helper, prefix classifier, compatibility
alias, new registry abstraction, evaluator, service identity, or matrix path.
- Documentation parity may consume the independent test fixture, but neither
production metadata nor rendered documentation may derive the other's
expected values.

## Required reviewers

Senior engineering, QA/test, security/auth, product/ops, architecture,
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,82 @@
# WS-AUTH-001-REV-CUSTODY Internal Review Evidence

Reviewed code SHA: `438c2bcf6a91b97f46264a1b6e5d0110a28f16d5`

Reviewed implementation SHA: `baa86dfe94015f66570844ce81ed1310729cded1`

Reviewed pre-CI status SHA: `9150960ce1f4fdd1f7a02129401f97f43a5ec667`

Reviewed CI-repair SHA: `438c2bcf6a91b97f46264a1b6e5d0110a28f16d5`

Reviewed against trusted main: `be2a79a243ec50049c37f1f634322a9b3ab895ba`

Reviewed at: `2026-07-20T12:42:54Z`

Reviewer run IDs: `rev_plan_core`, `rev_plan_security_qa`,
`rev_plan_ops_ci_docs`

Reviewer tracks: senior engineering, QA/test, security/auth, product/ops,
architecture, CI integrity, docs, reuse/dedup, and test delta

## Deterministic Evidence

- Ruff passed for the complete backend application and test trees.
- Sixty-three focused catalogue, fail-closed construction, documentation
parity, and real-kernel custody cases passed after review repair. The 19 REV
actions each deny as sensitive `action_unavailable` evidence with exact
action and permission and cannot reach revalidation or administrative grant
dependencies.
- The literal test fixture independently freezes all 19 action, permission,
owner, and `planned` values. Exact documentation parsing checks both canonical
tables, mappings, seven owner cardinalities, counts, and operations invariants.
- Stale Workstream and authorization wording scans, Markdown links, loop-memory
state, merge-intent validation, Alembic `0029_shared_transactional_outbox`
head, migration-directory no-diff, and diff integrity pass.
- No workflow, dependency, ActionId, PermissionId, mapping, availability,
evaluator, grant, route, service identity, matrix membership, persistence,
audit schema, or migration changed. The four proposed REV lifecycle actions
remain unregistered.
- A broader local authorization/auth command passed 288 non-database cases and
then failed closed because `WORKSTREAM_TEST_DATABASE_URL` is absent; its
coverage output is not claimed. The unchanged GitHub Backend workflow remains
the mandatory database/full-suite proof for the 78 percent repository-wide
and 90 percent authorization-subsystem coverage floors.

## Reviewer Results

| Reviewer | Result | Blocking findings | Notes |
|---|---|---|---|
| senior engineering | PASS AFTER FIXES | none | Restored the retained ART no-migration invariant before exact-SHA re-review. |
| QA/test | PASS AFTER FIXES | none | Corrected one broken ART docs regression and one stale REV-pending statement. |
| security/auth | PASS | none | All 19 actions stay planned and unavailable; no grant, runtime, audit, or persistence path changes. |
| product/ops | PASS AFTER FIXES | none | Custody labels grant no reviewer, Operator, or service authority; PREP remains human-gated. |
| architecture | PASS | none | AUTH changes activation-custody metadata while REV retains facts, guards, and behavior. |
| CI integrity | PASS AFTER FIXES | none | No CI weakening; focused proof is green and hosted full coverage remains mandatory. |
| docs | PASS AFTER FIXES | none | Spec, operations, custody plan, and exact parsed tables now agree. |
| reuse/dedup | PASS | none | Existing catalogue validator, parser pattern, kernel helpers, and evidence abstraction are reused. |
| test delta | PASS AFTER FIXES | none | No removal, skip, xfail, deselection, assertion relaxation, or threshold change. |

## Findings Resolved

Valid findings addressed: yes

Open sub-agent sessions: none

Initial candidate `c95239b9` replaced the exact retained sentence `The ART
transfer adds no migration` and left a stale spec statement claiming REV
custody was still pending. Repair candidate `baa86dfe` restores the independent
ART invariant, separately records the REV no-migration truth, and states that
all 19 REV rows now have AUTH custody while remaining planned. All nine tracks
passed exact-SHA re-review with no remaining finding.
Status candidate `9150960c` adds only the canonical review-log chronology; all
nine tracks confirmed that exact SHA without a remaining finding.
GitHub Agent Gates then found that the existing PREP successor heading used an
em dash while the canonical schema-v2 parser requires ` - `. Repair
`438c2bcf` normalizes only that delimiter, starts no PREP work, and passes exact
merge-intent validation plus all nine exact-SHA repair tracks.

## Remaining Risk And Gate

GitHub Backend, Agent Gates, external review, and explicit human review remain.
All 19 REV actions remain planned and unavailable. PREP is the only declared
successor and requires signed merge memory plus a separate explicit human start.
Original file line number Diff line number Diff line change
@@ -0,0 +1,81 @@
# WS-AUTH-001-REV-CUSTODY PR Trust Bundle

## Chunk

`WS-AUTH-001-REV-CUSTODY` - REV Activation Custody Transfer (L1).

## Goal And Human-Approved Intent

Transfer exactly 19 planned REV action-owner labels to seven exact AUTH
activation custodians without changing permission mappings, availability, or
REV behavior. The user explicitly started this chunk after ART custody merged
and signed memory stopped at the REV gate.

## What Changed And Why

- Removes seven historical REV `ActionOwner` enum values and adds seven exact
AUTH activation-custodian values.
- Changes only the owner field of the 19 canonical REV definitions.
- Preserves 74 PermissionIds, 65 ActionIds, 17 active and 48 planned actions,
every ActionId-to-PermissionId pair, all non-REV owners, and the exact
seven-identity/eleven-membership service matrix.
- Adds one literal independent 19-row fixture, exact docs parity, mutation
rejection, and all-19 real-kernel denial proof.

The owner-only typed-catalogue transfer was chosen because AUTH owns activation
custody while REV continues to own resources, facts, guards, jobs, and hidden
behavior. Registration, runtime activation, a migration, or a combined PREP
change were rejected as boundary violations.

## Scope And Product Behavior

No migration, database or audit rewrite, availability change, evaluator,
resource composer, route, job, grant, service identity, matrix membership, or
REV lifecycle behavior is included. Custodian labels create no reviewer,
Operator, or service entitlement. All 19 actions remain planned and unavailable;
the four proposed lifecycle actions remain unregistered.

## Acceptance Proof And Test Delta

- Ruff passed for `app` and `tests`.
- 63 focused catalogue/kernel/documentation cases passed after review repair.
- Stale wording, stale authorization docs, Markdown links, loop-memory state,
merge intent, Alembic-head/no-migration, and diff checks passed.
- No test or assertion was removed or weakened; no skip, xfail, deselection,
exclusion, workflow, script, dependency, or threshold changed.
- The local environment has no test database; GitHub Backend remains the
authoritative full-suite gate for global coverage at or above 78 percent and
authorization coverage at or above 90 percent.

## Internal Review And CI Integrity

Final reviewed CI-repair SHA `438c2bcf6a91b97f46264a1b6e5d0110a28f16d5`, containing
reviewed implementation `baa86dfe94015f66570844ce81ed1310729cded1`, against
trusted main `be2a79a243ec50049c37f1f634322a9b3ab895ba` passes senior engineering,
QA/test, security/auth, product/ops, architecture, CI integrity, docs,
reuse/dedup, and test-delta review after two documentation findings were fixed.
No CI, coverage configuration, package command, workflow, or migration file
changed.
The repair only normalizes the PREP contract heading delimiter required by the
schema-v2 successor parser; it does not start or change PREP.

## External Review And Remaining Risks

GitHub Backend, Agent Gates, and CodeRabbit remain pending until publication.
The remaining risk is exact metadata/docs drift, bounded by literal independent
fixtures, exact table parsing, frozen whole-catalogue expectations, and hosted
full-suite proof.

## Follow-Up And Human Review Focus

The sole merge-intent successor is `WS-AUTH-001-PREP`, which must not start
until this PR merges, signed memory succeeds, and the user explicitly starts it.
Human review should verify the exact 19-row/seven-custodian owner-only delta,
`2/5/3/1/1/5/2` cardinalities, unchanged ART/non-REV rows, mappings, counts,
matrix and availability, absent lifecycle registration, and zero migration.

## Human Merge Ownership

The agent may publish and repair this branch but may not merge it. Only the
human may approve this PR for merge. Trusted-main automation owns signed
post-merge memory generation.
9 changes: 9 additions & 0 deletions .agent-loop/merge-intents/WS-AUTH-001-REV-CUSTODY.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
{
"chunk_id": "WS-AUTH-001-REV-CUSTODY",
"chunk_title": "REV Activation Custody Transfer",
"initiative_id": "WS-AUTH-001",
"next_chunk_id": "WS-AUTH-001-PREP",
"next_chunk_title": "Prepared Mutation Authorization Protocol",
"next_requires_explicit_start": true,
"schema_version": 2
}
Loading
Loading