Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -16,14 +16,17 @@ typed symbol/manifest, and tests.
| `WS-REV-001-01` | Canonical Contract Adoption And Dependency Conformance | L1 | PLAN | Merged PR #145 |
| `WS-REV-001-02` | Locked Review Policy And Task Lifecycle Alignment | L1 | 01 | Merged PR #147; non-executable split record |
| `WS-REV-001-PLAN2` | REV-02A Runtime Readiness Plan Refresh | L1 | 02; planning-only human start | Merged PR #150 |
| `WS-REV-001-02A` | Guide Chronology And Task Locking Split | L1 | PLAN2; exact merged AUTH contributor foundation; separate human start | Active planning-only split record after preimplementation FAIL; no runtime |
| `WS-REV-001-02A1` | Project And Setup Publication Fence | L1 | 02A; current writer inventory; separate human start | Proposed executable child |
| `WS-REV-001-02A3` | Guide Activation Chronology | L1 | 02A1; current AUTH foundation/head; separate human start | Proposed executable child |
| `WS-REV-001-02A4` | Task Guide Triplet And Screening | L1 | 02A3; current migration head; separate human start | Proposed executable child |
| `WS-REV-001-02B` | Locked Review Policy And Dormant Task Lifecycle Compatibility | L1 | 02A4; approved duration defaults; separate start | Proposed |
| `WS-REV-001-02C` | Submission Attribution, Context, And Immutable Lineage | L1 | 02B; merged AUTH canonical contributor constraints; separate start | Proposed |
| `WS-REV-001-03` | Review Queue And Lease Persistence | L1 | 02C | Non-executable split record |
| `WS-REV-001-03A` | Queue And Lease Base Persistence | L1 | 02C; merged `WS-CON-001-03B`; contract review | Proposed; no contract yet |
| `WS-REV-001-02A` | Guide Chronology And Task Locking Split | L1 | Historical | Superseded boundary-crossing plan; never executable by REV |
| `WS-REV-001-02A1` | Project And Setup Publication Fence | L1 | Historical | Retired from REV; upstream owner concern |
| `WS-REV-001-02A3` | Guide Activation Chronology | L1 | Historical | Retired from REV; upstream owner concern |
| `WS-REV-001-02A4` | Task Guide Triplet And Screening | L1 | Historical | Retired from REV; upstream owner concern |
| `WS-REV-001-02A2` | Prepared Superseded Guide Reactivation | L1 | Historical | Retired from REV; upstream owner concern |
| `WS-REV-001-02B` | Locked Review Policy And Dormant Task Lifecycle Compatibility | L1 | Historical | Superseded; any upstream gap is reported to its owner |
| `WS-REV-001-02C` | Submission Attribution, Context, And Immutable Lineage | L1 | Historical | Superseded as an ownership chunk; REV consumes owner-supplied Submission lineage |
| `WS-REV-001-PLAN3` | Allow-Review Boundary Reset | L1 | Signed start required on exact current main | Proposed planning correction; not canonically active |
| `WS-REV-001-03P` | Review And Revision Policy Persistence | L1 | PLAN3; signed separate start | Recommended first REV runtime chunk; proposed contract, not started |
| `WS-REV-001-03` | Review Queue And Lease Persistence | L1 | PLAN3 | Non-executable split record |
| `WS-REV-001-03A` | Queue And Lease Base Persistence | L1 | 03P; exact merged `allow_review`, Submission/artifact, and actor handoffs; signed separate start | Proposed contract, not started |
| `WS-REV-001-03B` | Normalized Review Packet Manifest Persistence | L1 | 03A; exact ART packet-membership owner chunk merged | Proposed; owner chunk unscheduled |
| `WS-REV-001-04` | Review Chain Persistence | L1 | 03B | Non-executable split record |
| `WS-REV-001-04A` | Immutable Review Chain And Decision Request Persistence | L1 | 03B; current actor constraints | Proposed; no contract yet |
Expand All @@ -39,12 +42,11 @@ typed symbol/manifest, and tests.
| `WS-REV-001-07A` | Lease-Bounded Packet And Review Chain Context | L1 | 06C; exact ART packet-read owner chunk | Proposed; owner chunk unscheduled |
| `WS-REV-001-07B` | Reviewer Finding Evidence Candidate And Finalize | L1 | 07A; exact ART review-evidence owner chunk and AUTH binding contracts | Proposed; owner chunk unscheduled |
| `WS-REV-001-08` | Pure Decision, Final Acceptance, And Task-Effect Contract | L1 | 07B; typed participant contracts | Proposed; executable contract after repair, no canonical write |
| `WS-REV-001-02A2` | Prepared Superseded Guide Reactivation | L1 | 08 and 02A4; merged AUTH-PREP/custody; AUTH-12 contract amendment; `project.guide.activate` remains unavailable | Proposed hidden behavior; manifest gates AUTH-12 evaluator/cutover/activation |
| `WS-REV-001-09A` | Revision Context Preparation And Resubmission | L1 | 08 | Non-executable split record |
| `WS-REV-001-09A1` | Review-Rooted Revision Preparation Persistence | L1 | 02A2; approved human round/deadline semantics; migration/head refresh | Proposed; no contract yet |
| `WS-REV-001-09A1` | Review-Rooted Revision Preparation Persistence | L1 | 08; exact owner-supplied guide/task facts; approved human round/deadline semantics; migration/head refresh | Proposed; no contract yet |
| `WS-REV-001-09A2` | Revision Preparation Participant, Resolver, And Task Context | L1 | 09A1 | Proposed; task-owned flush-only participant, no transaction composition |
| `WS-REV-001-09A3` | Human Revision Response Evidence Finalize | L1 | 09A2; ART evidence port and exact AUTH action | Proposed; owner chunk unscheduled |
| `WS-REV-001-09A4` | Hidden Human Prepared N+1 And Checker Source Compatibility | L1 | 09A3; merged AUTH-14 contract amendment only; ART digest contract | Proposed; adds preparation binding/source XOR while retaining 02C checker source; AUTH-14 owns public request acknowledgement, authorization cutover, and activation |
| `WS-REV-001-09A4` | Hidden Human Prepared N+1 And Checker Source Compatibility | L1 | 09A3; merged AUTH-14 contract amendment only; ART digest contract | Proposed; adds preparation binding/source XOR while consuming owner-supplied checker source; AUTH-14 owns public request acknowledgement, authorization cutover, and activation |
| `WS-REV-001-09A5` | Hidden Replacement Assignment Preparation Transfer | L1 | 09A4; merged AUTH-13 contract amendment only | Proposed; AUTH-13 later owns public command/cutover/activation |
| `WS-REV-001-09B` | Finding Replay, Resolution, And Preferred Return Routing | L1 | 09A5 | Proposed |
| `WS-REV-001-10` | Canonical Review, Final Acceptance, And CON Atomic Integration | L1 | 09B; merged `WS-CON-001-03C` and `07`; stabilized digest owner chunk | Proposed; first canonical decision commit |
Expand All @@ -70,14 +72,14 @@ typed symbol/manifest, and tests.
## Same-initiative order

```text
PLAN -> 01 -> 02(parent) -> PLAN2 -> 02A(parent split)
-> 02A1 -> 02A3 -> 02A4 -> 02B -> 02C
PLAN -> 01 -> 02(parent) -> PLAN2 -> 02A(historical, superseded)
-> PLAN3(boundary reset) -> 03P
-> 03(parent) -> 03A -> 03B
-> 04(parent) -> 04A -> 04B
-> 05(parent) -> 05A -> 05B
-> 06(parent) -> 06A -> 06B -> 06C
-> 07(parent) -> 07A -> 07B
-> 08 -> 02A2
-> 08
-> 09A(parent) -> 09A1 -> 09A2 -> 09A3 -> 09A4 -> 09A5 -> 09B
-> 10
-> 11(parent) -> 11A -> 11B -> 11C -> 11D
Expand Down Expand Up @@ -108,9 +110,9 @@ REV neither invents those IDs nor edits owner plans.

## Parent split records

After this planning-only split merges, parent 02A joins the existing parent
contract files for 03, 04, 05, 06, 07, 09A, 11, 12, former 12A release control,
and 13 as a non-executable historical planning record.
Parent 02A and all of its children are retired historical planning records.
Existing parent contract files for 03, 04, 05, 06, 07, 09A, 11, 12, former 12A
release control, and 13 remain non-executable split records.
They must not be used as implementation authorization. New child contracts are
authored only from the then-current main when each child receives a human start.

Expand All @@ -123,6 +125,6 @@ configuration, or coverage changes add CI integrity.

## Stop condition

Complete and merge only the planning-only parent split `WS-REV-001-02A`, then
stop. Its schema-v2 merge intent names `WS-REV-001-02A1` and requires a separate
explicit start. Do not begin 02A1, 02A3, 02A4, 02A2, or 02B from this PR.
Complete only the proposed `WS-REV-001-PLAN3`, then stop. Never resume 02A, 02A1, 02A2,
02A3, 02A4, 02B, or 02C as REV implementation. The next eligible runtime chunk
is 03P, only after merge and a signed explicit start on exact current main.
Original file line number Diff line number Diff line change
Expand Up @@ -5,13 +5,13 @@ No row is complete from prose or an unmerged owner contract.

| Area | Owning chunks | Required executable proof | Release proof |
|---|---|---|---|
| Authority | 05B, 06A-C, 07A-B, 08, 02A2, 09A2-A5, 10, 11A-D, 12P2, 12A1-A4, 13C | Exact active/project reviewer grant; canonical human actors; AUTH-first prepared mutations; opaque one-use bindings; clean denial/restaging; service identity isolation; no direct grant reads; no adjudication authority | Exact merged feature manifests -> AUTH activation -> phase-enabled HTTP denial/allow matrix |
| Guide chronology | 02A1, 02A3, 02A4, 02A2 | Complete Project/setup writer fence; positive immutable per-project sequence; canonical-human approval; exact status/provenance; Project-first screening; immutable Task triplet; hidden prepared If-Match reactivation; both-order races | Forward/backward active guide changes without reviewer-side rebase or stale retry |
| Authority | 05B, 06A-C, 07A-B, 08, 09A2-A5, 10, 11A-D, 12P2, 12A1-A4, 13C | Exact active/project reviewer grant; canonical human actors; AUTH-first prepared mutations; opaque one-use bindings; clean denial/restaging; service identity isolation; no direct grant reads; no adjudication authority | Exact merged feature manifests -> AUTH activation -> phase-enabled HTTP denial/allow matrix |
| Upstream intake handoff | external Project/Task/Submission/Checker owners; consumed by 03A/05A/09A | Finalized immutable Submission; verified bindings; final current CheckerRun `allow_review`; immutable Submission predecessor and stamped context contracts. REV performs no upstream mutation. | Owner evidence plus REV admission/replay proof; gaps block and are reported, never implemented inside REV |
| Queue routing | 03A-B, 05A-B, 06A-C, 09B, 11A/C | Exact checker admission; one open/preferred entry; normalized packet membership; current returns lease/offer/none; duplicate/supersession races; authorized batched historical classification | New and historical eligible rows, preferred return, takeover, counts/age evidence |
| Leases | 03A-B, 06A-C, 11A/C | One active lease globally; canonical reviewer; packet manifest; reviewer ContributionPolicyVersion freeze; release/decline/expiry/revocation/lazy recovery and both-order races | Claim/release/expiry/reclaim/revocation through exact admitted service identities |
| Review history | 04A-B, 08, 10 | Every decision/finding/resolution immutable; exact predecessor/assignment lineage; reviewer CON operation before branch; accept-only FinalAcceptance and submitter operation; reject exact assignment; atomic rollback | Real accept/needs_revision/reject HTTP/database/audit/CON agreement and changed replay denial |
| Revision paths | 02C, 09A1-A5, 09B, 10, 11B-D | Human Review revision creates one immutable non-branching preparation before readable state; checker remediation persists unique immutable `remediation_source_checker_run_id`, keeps task context, creates no Review/preparation/CON record, and is never classified as legacy | Separate checker and human drills both reach corrected N+1 without policy or lineage drift |
| Revision context | 02A1, 02A3, 02A4, 02A2, 02B-C, 09A1-A5, 09B | Prepared `If-Match`-protected superseded-guide reactivation; Review-rooted task-owned preparation; kept/forward/backward/blocked; exact head acknowledgement; one winner per head; replacement successor; no contribution-policy rebase; checker path bypasses rebase | Human context display, checker rerun, prior-reviewer preference, resolution, final decision; checker correction returns open |
| Revision paths | 09A1-A5, 09B, 10, 11B-D | Human Review revision creates one immutable non-branching preparation before readable state; REV consumes owner-supplied checker remediation lineage, keeps task context, creates no Review/preparation/CON record for checker-only remediation, and never classifies it as legacy | Separate checker and human drills both reach corrected N+1 without policy or lineage drift |
| Revision context | 09A1-A5, 09B | Review-rooted preparation consumes owner-supplied immutable Submission/current-context facts; kept/rebased/blocked; exact head acknowledgement; one winner per head; replacement successor; no contribution-policy rebase; checker path bypasses human preparation | Human context display, checker rerun, prior-reviewer preference, resolution, final decision; checker correction returns open |
| Limits/deadlines | 09A1-A4, 11B | Human-approved round/deadline semantics only; DB time and frozen episode facts; checker retries excluded; repair cannot bypass exhaustion; D6 close only | Before/equal/after, exact replay/races, checker D6 denial, no synthetic Review/CON record |
| Reject/admin close | 10, 11B/D | Human reject only from Review; exact assignment blocked/task rejected. PM/Operator closes use canonical cancelled reasons and create no Review/CON | Authorized/denied/cross-project/rollback proof; no `closed` token |
| Artifact evidence | 03B, 07A-B, 09A3, 11D | Active-exact-lease bytes; metadata-only history; ART candidate/finalize; immutable slot plus append-only attachment; orphan-only failed finalization; no raw store/provider path | Local/MinIO/S3 owner conformance plus outage/integrity no-adverse-outcome drill |
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -589,3 +589,21 @@ the unique children in `CHUNK_MAP.md` may receive future implementation
contracts. Chunk 08 is pure contracts/validation only; chunk 10 is the first
canonical Review/FinalAcceptance/CON commit. Active release docs and router
registration occur together only in 13C.

### D28 - REV Starts At Allow Review And Never Repairs Upstream Owners

The human reconfirmed the canonical boundary after a complete source reread.
REV consumes the existing finalized Submission, its verified artifact bindings,
and one durable final current CheckerRun recommendation of `allow_review`.
Project Guide setup/publication/activation/chronology/reactivation and general
Task intake stamping are not REV-owned. D21 and D24 are superseded wherever
they assigned those implementations to 02A1/02A2/02A3/02A4.

REV owns queue admission, routing, leases, review packet semantics, immutable
Review/finding/resolution history, human revision replay, FinalAcceptance, and
the canonical decision composition. Every Review produces one reviewer
contribution through CON; accept alone produces FinalAcceptance and one
submitter accepted-submission contribution. Submission and Review predecessor
chains remain fully traversable for future adjudication without implementing
adjudication now. A missing owner capability is documented and escalated to the
human; REV never fills it opportunistically.
Original file line number Diff line number Diff line change
@@ -1,17 +1,69 @@
# Discovery: WS-REV-001 Review And Revision Lifecycle

## 2026-07-22 Boundary Correction

Complete rereading of the checksum-bound WS-REV Markdown, all 52 pages of its
PDF companion, the active `docs/spec_review_lifecycle.md`, and ADR 0010 confirms
that REV begins after a final current checker `allow_review` admission and must
preserve the proven Project Guide/Task/Submission/Checker intake spine. ADR 0010
requires REV revision preparation to consume a stable active-guide identity; it
does not transfer Project Guide setup or activation ownership to REV.

The derived PLAN2/02A sequence incorrectly converted that dependency into REV
implementation ownership. Proposed 02A1 Project/setup fencing, 02A3 activation
chronology, 02A4 general Task stamping, and 02A2 guide reactivation are therefore
retired as REV chunks. Any still-needed capability must be specified as an
external owner handoff. The unmerged 02A1 runtime candidate was reverted before
publication.

After merging current main at `14fa4316f7d984f2176657bfafd2a2dae56f944e`,
the sole migration head is `0033_authorization_read_rate_control`. AUTH PR #175
changes no REV product boundary. Signed loop memory remains stopped with retired
02A1 named next; PLAN3 must replace that successor through reviewed merge memory
before 03P can receive a signed start.

## Baseline

Discovery was refreshed read-only from trusted main
`44f2467cedc266d2efe261119cfff436ac6b7715` after ART admission foundation PR
#154 merged on top of REV PLAN2 PR #150, AUTH-09D-B PR #152, and the AUTH
contributor foundation PR #153. The active parent-split repair makes no
backend/runtime changes.

## Current backend
`14fa4316f7d984f2176657bfafd2a2dae56f944e`. PLAN3 makes no backend/runtime
changes.

## Current boundary facts

- The repository remains FastAPI/Python with async SQLAlchemy 2.x, Alembic,
Pydantic, and PostgreSQL; the sole head is
`0033_authorization_read_rate_control`.
- `Submission` remains the owner-supplied versioned submission entity. REV must
consume its exact finalized identity, immediate-predecessor lineage, Task and
contributor facts, and submitted artifact membership; any missing invariant
or typed read contract is work for that owner.
- Checker completion remains owner-supplied. REV admission may consume only one
durable final/current `allow_review` result; it may not produce or repair a
CheckerRun.
Comment thread
coderabbitai[bot] marked this conversation as resolved.
- ART recovery is present through migration `0032_artifact_recovery_attempts`,
but each future REV artifact read/evidence need still requires an exact merged
typed owner contract and proof at that chunk's signed start.
- AUTH PR #175 and migration `0033_authorization_read_rate_control` add
authorization-read rate control without transferring reviewer identity,
permission, or lifecycle ownership to REV.
- CON remains the owner of contribution records. REV later composes its typed
participant so every committed Review creates one reviewer contribution and
only accept creates the submitter accepted-submission contribution.
- REV owns ReviewPolicy/RevisionPolicy (03P), queue/lease persistence (03A/03B),
admission/routing (05A/05B), immutable Review/finding/resolution chains,
human revision replay, FinalAcceptance, and decision orchestration.

## Historical PLAN2 discovery snapshot — archival and void

> Every section and ownership/chunk statement below this heading records the
> superseded PLAN2/02A investigation only. It is not current dependency truth,
> an owner assignment, a human-decision request, or implementation authority.
> D28, PLAN3, `CHUNK_MAP.md`, and the proposed 03P/03A contracts control.

## Historical backend snapshot

- FastAPI/Python, async SQLAlchemy 2.x, Alembic, Pydantic, PostgreSQL.
- Single Alembic head: `0028_artifact_admission`.
- Historical single Alembic head: `0028_artifact_admission`.
- `Submission` is the existing versioned submission entity; no separate
SubmissionVersion is needed.
- TaskAssignment and Submission now expose only `contributor_id`; each has an
Expand Down Expand Up @@ -82,13 +134,14 @@ backend/runtime changes.
## Product findings

- All reviewer decisions/findings/resolutions are append-only.
- Checker-caused remediation is supported but accepted ADRs scope controlled
- The historical PLAN2 proposal observed that checker-caused remediation is
supported but accepted ADRs scope controlled
guide rebase/preparation to human Review revision. The plan must preserve a
distinct CheckerRun-rooted N+1 path rather than treating it as legacy or
silently applying human RevisionPolicy/D6 behavior. Current Submission storage
lacks immutable causal CheckerRun lineage, so 02C must add and backfill
`remediation_source_checker_run_id` before human prepared cutover adds the
source XOR.
lacked immutable causal CheckerRun lineage. It incorrectly assigned 02C to add
and backfill `remediation_source_checker_run_id`; under PLAN3, any still-needed
lineage is an external Checker/Submission owner requirement that REV consumes.
- Human revision context is task-owned. REV supplies exact human decision/
finding facts through a typed task participant. Checker remediation retains
its existing task/checker path and locked context.
Expand Down
Loading
Loading