Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view

Large diffs are not rendered by default.

Original file line number Diff line number Diff line change
Expand Up @@ -6,9 +6,9 @@ No row is complete from prose or an unmerged owner contract.
| Area | Owning chunks | Required executable proof | Release proof |
|---|---|---|---|
| Authority | 05B, 06A-C, 07A-B, 08, 09A2-A5, 10, 11A-D, 12P2, 12A1-A4, 13C | Exact active/project reviewer grant; canonical human actors; AUTH-first prepared mutations; opaque one-use bindings; clean denial/restaging; service identity isolation; no direct grant reads; no adjudication authority | Exact merged feature manifests -> AUTH activation -> phase-enabled HTTP denial/allow matrix |
| Upstream intake handoff | external Project/Task/Submission/Checker owners; consumed by 03A/05A/09A | Finalized immutable Submission; verified bindings; final current CheckerRun `allow_review`; immutable Submission predecessor and stamped context contracts. REV performs no upstream mutation. | Owner evidence plus REV admission/replay proof; gaps block and are reported, never implemented inside REV |
| Queue routing | 03A-B, 05A-B, 06A-C, 09B, 11A/C | Exact checker admission; one open/preferred entry; normalized packet membership; current returns lease/offer/none; duplicate/supersession races; authorized batched historical classification | New and historical eligible rows, preferred return, takeover, counts/age evidence |
| Leases | 03A-B, 06A-C, 11A/C | One active lease globally; canonical reviewer; packet manifest; reviewer ContributionPolicyVersion freeze; release/decline/expiry/revocation/lazy recovery and both-order races | Claim/release/expiry/reclaim/revocation through exact admitted service identities |
| Upstream intake handoff | external Project/Task/Submission/Checker owners; Submission identity referenced by 03A1, admission consumed by 05A, revision lineage consumed by 09A4 | Finalized immutable Submission; verified bindings; final current CheckerRun `allow_review`; immutable Submission predecessor and stamped context contracts. REV performs no upstream mutation. | Owner evidence plus REV admission/replay proof; gaps block and are reported, never implemented inside REV |
| Queue routing | 03A1, 03A2, 03B, 05A-B, 06A-C, 09B, 11A/C | Exact checker admission; one open/preferred entry; normalized packet membership; current returns lease/offer/none; duplicate/supersession races; authorized batched historical classification | New and historical eligible rows, preferred return, takeover, counts/age evidence |
| Leases | 03A2, 03B, 06A-C, 11A/C | One active lease globally; canonical reviewer; packet manifest; reviewer ContributionPolicyVersion freeze; release/decline/expiry/revocation/lazy recovery and both-order races | Claim/release/expiry/reclaim/revocation through exact admitted service identities |
| Review history | 04A-B, 08, 10 | Every decision/finding/resolution immutable; exact predecessor/assignment lineage; reviewer CON operation before branch; accept-only FinalAcceptance and submitter operation; reject exact assignment; atomic rollback | Real accept/needs_revision/reject HTTP/database/audit/CON agreement and changed replay denial |
| Revision paths | 09A1-A5, 09B, 10, 11B-D | Human Review revision creates one immutable non-branching preparation before readable state; REV consumes owner-supplied checker remediation lineage, keeps task context, creates no Review/preparation/CON record for checker-only remediation, and never classifies it as legacy | Separate checker and human drills both reach corrected N+1 without policy or lineage drift |
| Revision context | 09A1-A5, 09B | Review-rooted preparation consumes owner-supplied immutable Submission/current-context facts; kept/rebased/blocked; exact head acknowledgement; one winner per head; replacement successor; no contribution-policy rebase; checker path bypasses human preparation | Human context display, checker rerun, prior-reviewer preference, resolution, final decision; checker correction returns open |
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -206,8 +206,9 @@ adverse review outcome.

REV may land decision schemas, pure validation, and transaction input types
behind an unexposed boundary, but no service may commit a canonical Review until
the merged CON flush-only participant and ReviewLease/TaskAssignment
`ContributionPolicyVersion` freezes are mandatory. CON failure rolls back the
the merged CON flush-only participant and REV-owned ReviewLease plus task-owned
TaskAssignment `ContributionPolicyVersion` freezes are mandatory. CON lookup or
participant failure rolls back the
entire decision. No production or test-only no-op participant exists. AUTH may
activate `review.decision` only after the complete hidden REV+CON composition
merges.
Expand Down Expand Up @@ -606,3 +607,50 @@ submitter accepted-submission contribution. Submission and Review predecessor
chains remain fully traversable for future adjudication without implementing
adjudication now. A missing owner capability is documented and escalated to the
human; REV never fills it opportunistically.

### D29 - AUTH 02D Unblocks Hidden REV Core

Merged PR #257 publishes the closed typed authorization contracts for all
approved REV actions while keeping those actions unavailable. REV may now build
hidden persistence and lifecycle rules without waiting for activation. Later
XINT activation consumes exact merged REV behavior; it does not authorize or
implement that behavior.

### D30 - Core Persistence Proceeds Before External Integration

ART and CON do not block queue persistence or other REV-owned persistence that
contains no unresolved foreign invariant. They do gate the exact consumer
schema or behavior: REV owns ReviewLease completely, but its migration follows
CON-03B because the canonical reviewer ContributionPolicyVersion table must
already exist as a mandatory FK target. ART's membership identifier contract
precedes ReviewPacketManifest; later CON and ART operations precede claim,
packet read, and decision composition. REV never guesses the missing interface,
creates a placeholder foreign model, or imports the foreign repository.

### D31 - Queue And Lease Persistence Are Separate L1 Children

The former 03A combined child is non-executable. 03A1 owns queue and admission-
idempotency persistence; 03A2 owns lease and preference persistence. Automatic
checker admission remains 05A, and claim behavior remains 06A.

### D32 - v0.1 Review Evidence Is Records, Not Uploaded Artifacts

ReviewFinding and SubmissionFindingResponse store bounded text/metadata.
`review.finding_evidence.ingest`,
`review.finding_response_evidence.ingest`, and ART review-evidence binding stay
future-intent-required and unavailable. ART packet materialization remains in
scope because it supplies the exact submitted work being reviewed.

### D33 - Contribution Cardinality And Source Are Fixed

Every committed human Review invokes CON's reviewer operation exactly once.
Only accept creates REV-owned FinalAcceptance and invokes CON's submitter
operation. Needs revision and reject create no submitter contribution. CON owns
ContributionRecord and award persistence; REV owns orchestration and one commit.

### D34 - PLAN4 Is The Live Sequence

PLAN4, the live CHUNK_MAP, and the active review specification control future
work. PLAN2/PLAN3 and retired 02-family files remain historical evidence. Only
03A1 is proposed as the first runtime child after PLAN4 approval; later child
contracts must be refreshed from then-current main.
Loading
Loading