Skip to content
Merged
Original file line number Diff line number Diff line change
@@ -0,0 +1,32 @@
# Review Log: WS-ART-001 Immutable Artifact Storage

## WS-ART-001-02C3

- Signed explicit start verified on 2026-07-21 against trusted main `f2aa57a4`.
- L1 preimplementation plan review: PASS WITH CONDITIONS.
- Required conditions cover verification-job lineage, database recovery
invariants, concurrency-safe replay, AUTH separation, atomic audits, terminal
fencing, and cumulative coverage gates.
- First internal review batch returned blocking findings: taskless guide
recovery was not representable, the Operator mutation seam was not yet
fail-closed, and required fencing/terminal/migration proofs were incomplete.
- Repair in progress: recovery task context is nullable, the exact Operator
authority seam defaults to deny until AUTH-owned activation, authorization
evidence is retained in the initiation audit, and focused guide/authority
drift tests were added. No publication claim is recorded yet.
- Re-review cleared taskless-guide and architecture blockers, then identified
an authorization-ordering bypass on exact replay. Every normal and
concurrent-winner replay now revalidates the persisted human identity and
exact recovery authority before returning identifiers; denied replay is
covered with zero-write assertions.
- Final internal review results on `841f2a38`: senior engineering PASS WITH
LOW RISKS; architecture PASS WITH LOW RISKS; QA PASS; security PASS WITH LOW
RISKS; product/ops PASS WITH LOW RISKS; reuse/dedup PASS WITH LOW RISKS; CI
integrity PASS; test delta PASS; docs PASS.
- Accepted low risks are limited to legacy terminal-audit top-level metadata,
private audit-builder ownership coupling, and duplicated human-proof shape;
none changes authorization, recovery custody, or product lifecycle state.
- GitHub Actions run `29851665477` found two valid integration issues: an
over-broad lineage trigger and an incomplete integrity-mismatch upload-item
transition. Both received bounded repairs and their three failing tests pass
locally; final internal re-review and hosted rerun remain.
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
# Chunk Contract: WS-ART-001-02D Operator Artifact Operations
# Chunk Contract: WS-ART-001-02D - Operator Artifact Operations

Initiative: `WS-ART-001` | Risk: L1 | Status: Proposed after 02C3, AUTH-09E, and `WS-AUTH-001-ART-CUSTODY`

Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,36 @@
# WS-ART-001-02C3 External Review Response

## GitHub Actions run 29851665477

Comments addressed:

- shard 1 exposed that the new verification-lineage trigger blocked two
existing pre-recovery drift/fence tests. The trigger now freezes lineage only
after a job is a recovery source or retry; unrecovered initial jobs retain
the drift behavior needed for fail-closed verification revalidation.
- shard 2 exposed that integrity mismatch moved a contributor upload item to
`failed` without clearing stored-result references. The terminal transition
now clears `content_id` and `provider_object_ref`, preserving the existing
database state-shape invariant.
- the fan-in `test` failure was downstream of those two shard failures and
requires no independent repair.

Comments deferred:

- CodeRabbit supplied no code findings because its review was rate limited.

Human decisions needed:

- none for these bounded CI repairs; explicit human approval remains required
before merge.

Commands rerun:

- Ruff on the changed artifact service, migration, and focused tests: PASS.
- Both failed shard-1 tests and the failed shard-2 integrity-mismatch test:
3 PASS.

Remaining risks:

- the complete hosted shards and cumulative coverage gates must rerun on the
repaired commit.
Original file line number Diff line number Diff line change
@@ -0,0 +1,93 @@
# WS-ART-001-02C3 Internal Review Evidence

Reviewed code SHA: `dd1aa0d91ed0b0a3f67638f719e8332865c128eb`

Reviewed at: `2026-07-21T17:43:00Z`

Reviewer run IDs: `ci_repair_senior_arch`, `ci_repair_qa_security`,
`ci_repair_ops_ci_docs`

## CI repair review addendum

| Reviewer | Result | Blocking findings | Notes |
|---|---|---|---|
| senior engineering | PASS WITH LOW RISKS | none | Recovery-only lineage custody and failed-item state shape are maintainable. |
| QA/test | PASS WITH LOW RISKS | none | The three exact hosted failures pass after bounded repairs. |
| security/auth | PASS | none | Recovery participants remain immutable and stale content ownership references are cleared. |
| product/ops | PASS | none | No route, review decision, or product lifecycle behavior changed. |
| architecture | PASS WITH LOW RISKS | none | Trigger coupling is intentionally limited to recovery participation. |
| CI integrity | PASS | none | No workflow, test, threshold, or bypass change was made. |
| docs | PASS | none | External response and trust status accurately describe PR #174 and the hosted rerun gate. |
| reuse/dedup | PASS | none | The bounded state transition and custody predicate need no new helper. |
| test delta | PASS | none | Existing tests exposed both failures; no test was changed or weakened. |

Valid findings addressed: yes

Open sub-agent sessions: none

---

Reviewed code SHA: `f302838146f39e78a15080df7231ef3904a052ed`

Reviewed against trusted main: `1473f7a0cab6d879c7b7c049a9b94f557ad712c2`

Reviewed at: `2026-07-21T17:03:00Z`

Reviewer run IDs: `review_senior_arch`, `review_qa_test`,
`review_security_product`, `review_reuse_ci_docs`

Reviewer tracks: senior engineering, QA/test, security/auth, product/ops,
architecture, CI integrity, docs, reuse/dedup, and test delta

## Scope

WS-ART-001-02C3 adds one durable recovery-attempt envelope, immutable
source-to-retry verification lineage, exact replay ownership, atomic terminal
finalization, and a deny-only Operator authority seam. It adds no route,
provider mutation, product lifecycle transition, dependency, or CI weakening.

## Deterministic evidence

- Focused artifact recovery suite: PASS before reviewer repair; repaired guide,
authority-drift, denied-replay, and sampled terminal-outcome tests: PASS.
- Alembic upgrade/downgrade and recovery-schema proof: PASS.
- Ruff for backend app, tests, and migration: PASS.
- Stale artifact contracts: PASS.
- Agent gate unit suite: 89 PASS.
- Merge-intent validation against `origin/main`: PASS.
- `git diff --check`: PASS.
- Heavy sharded backend suite and cumulative coverage remain hosted CI gates.

## Reviewer results

| Reviewer | Result | Blocking findings | Notes |
|---|---|---|---|
| senior engineering | PASS WITH LOW RISKS | none | Taskless guide recovery is represented end to end. |
| QA/test | PASS | none | Creation, replay authorization, terminal outcomes, fencing, and chaining are covered. |
| security/auth | PASS WITH LOW RISKS | none | Every creation and replay requires fresh exact authority; deny remains production default. |
| product/ops | PASS WITH LOW RISKS | none | Recovery remains infrastructure-only and provider-read-only. |
| architecture | PASS WITH LOW RISKS | none | One recovery chain spans guide and task-backed producers without route activation. |
| CI integrity | PASS | none | No workflow, threshold, package, runner, or bypass change. |
| docs | PASS | none | Existing ART plan/glossary cover the internal contract; memory and trust evidence are current. |
| reuse/dedup | PASS WITH LOW RISKS | none | Existing repositories, hashing, actor proof, audit, and verification fences are reused. |
| test delta | PASS | none | Tests were added and strengthened; none were removed, skipped, or weakened. |

## Findings resolved

Initial review blocked task-bound guide recovery, missing fresh Operator
authority, incomplete terminal/fence tests, and replay-before-authorization.
The repair made task context nullable, added the deny-only exact authority seam,
retained bounded decision evidence, covered all terminal mappings and authority
drift, and reauthorized normal and concurrent-winner replay before returning
identifiers. The post-review `WS-ART-001-02D` heading change is canonical
metadata formatting only; docs and CI reviewers confirmed their PASS results
remain valid.

Valid findings addressed: yes

Open sub-agent sessions: none

## Remaining gate

GitHub backend shards, cumulative 90 percent artifact coverage, repository-wide
78 percent coverage, external review, and explicit human merge approval remain.
Original file line number Diff line number Diff line change
@@ -0,0 +1,107 @@
# PR Trust Bundle: WS-ART-001-02C3

## Chunk

`WS-ART-001-02C3` — Recovery Attempt And Idempotency Chain (L1)

## Goal And Human-Approved Intent

Add the durable, read-only provider-observation recovery envelope and exact
source-job to retry-job chain. The signed loop-memory start authorized this ART
chunk to run concurrently with AUTH; it does not activate Operator routes.

## What Changed And Why

- added migration `0032` for recovery envelopes and immutable verification
lineage;
- added nullable task context so the same chain supports guide and task-backed
artifacts;
- added exact replay, lifetime source ownership, concurrent winner recovery,
linear retry ancestry, and atomic terminal finalization;
- added a typed Operator authority seam whose production-safe implementation
denies until the later AUTH-owned activation;
- required fresh actor and exact authority revalidation on creation and every
replay, with bounded authorization evidence in the initiation audit;
- added focused migration, concurrency, guide, authorization, fencing, and
terminal-outcome tests.

## Design And Alternatives

The verification job remains the sole executable lease owner. Recovery is an
envelope, not a second worker lease. PostgreSQL uniqueness and custody triggers
enforce one lifetime source owner and immediate-parent chaining. Provider
mutation replay and a task-only recovery abstraction were rejected because
both violate the initiative contract.

## Scope And Product Behavior

No routes, provider mutation, guide/task/submission lifecycle transitions,
review decisions, payment, reputation, dependencies, CI workflow changes, or
coverage reductions are included. Recovery remains infrastructure state and
does not introduce product decisions beyond `accept`, `needs_revision`, and
`reject`.

## Acceptance Evidence

- exact and concurrent replay preserve one envelope, retry job, and initiation
audit;
- changed/lifetime reuse conflicts without new recovery ownership;
- only exhausted terminal `provider_unavailable` work is recoverable;
- taskless guide recovery is representable and replayable;
- denied creation and denied replay return no identifiers and add no rows;
- success and every failed terminal outcome finalize envelope and audit under
the verification transaction;
- terminal authority drift writes no terminal recovery facts;
- exhausted retries form only the next linear chain link.

## Tests And CI Integrity

Local focused evidence:

- `ruff check app tests alembic/versions/0032_artifact_recovery_attempts.py`;
- focused recovery tests, including all original five, guide/deny replay,
authority drift, and sampled failed outcome;
- migration upgrade/downgrade and recovery-schema tests;
- `python3 scripts/check_stale_artifact_contracts.py`;
- `python3 scripts/test_agent_gates.py` — 89 passed;
- `git diff --check`.

The expensive full backend suite, remaining parameter combinations, global
78% coverage, and cumulative artifact 90% coverage are intentionally delegated
to the existing sharded GitHub Actions. No CI or package-script file changed.
No tests were removed, skipped, or weakened.

## Reviewer Results

- senior engineering: PASS WITH LOW RISKS;
- architecture: PASS WITH LOW RISKS;
- QA/test: PASS;
- security/auth: PASS WITH LOW RISKS;
- product/ops: PASS WITH LOW RISKS;
- reuse/dedup: PASS WITH LOW RISKS;
- CI integrity: PASS;
- test delta: PASS;
- docs: PASS.

PR #174 is published. External review and final hosted CI remain open gates.

The first hosted shard attempt passed agent gates, preflight, API E2E, and
shards 3-4. Shards 1-2 found an over-broad lineage trigger and an incomplete
integrity-mismatch item transition; both were repaired and their three exact
failing tests pass locally. A full hosted rerun remains required.

## Remaining Risks And Follow-Up

Low risks: legacy terminal audit metadata describes the verifier imperfectly,
the audit builder has private cross-class ownership, and human-proof validation
has small domain-specific duplication. The later typed Operator audit surface
may clean these up. Successor `WS-ART-001-02D` owns Operator routes and real AUTH
activation; it must not start automatically before this chunk merges and the
signed successor event is approved.

## Human Review Focus And Merge Ownership

Verify that no source can own two recoveries, no replay can bypass fresh
authority, and recovery stays separate from provider mutation and product
lifecycle state. A human owns the merge decision; Codex must not merge without
explicit approval for this PR.
9 changes: 9 additions & 0 deletions .agent-loop/merge-intents/WS-ART-001-02C3.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
{
"chunk_id": "WS-ART-001-02C3",
"chunk_title": "Recovery Attempt And Idempotency Chain",
"initiative_id": "WS-ART-001",
"next_chunk_id": "WS-ART-001-02D",
"next_chunk_title": "Operator Artifact Operations",
"next_requires_explicit_start": true,
"schema_version": 2
}
Loading
Loading