Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
18 commits
Select commit Hold shift + click to select a range
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -186,7 +186,7 @@ Open pull requests, not this file, are the transient review view.
| `WS-AUTH-001-12F1` | Merged | `codex/ws-auth-001-12f1-submission-policy-foundation` | #286 | Submission-policy PREP, replay, provenance, and audit custody foundation merged as `5a4186cc`; zero activation. |
| `WS-AUTH-001-12F2` | Merged | `codex/ws-auth-001-12f2-manual-submission-policy` | #292 | Governed Project Manager append-only manual-draft create/update cutover merged as `81f281bd`. |
| `WS-AUTH-001-12F3` | Merged; transitional | `codex/ws-auth-001-12f3-service-derivation` | #295 | Merged as `99c0aaf0`; authority/provenance is reused, while its separate inference entry point is removed at POL-04B. |
| `WS-AUTH-001-12I` | Proposed | - | - | Activates hidden unified compilation request/execute only. |
| `WS-AUTH-001-12I` | Implemented; review pending | `codex/ws-auth-001-12i-unified-compilation-activation` | - | Exact Project Manager request/recovery and fixed project-setup execution activation; POL remains hidden until 03B. |
| `WS-AUTH-001-12F4` | Proposed | - | - | Activates approval of the stored unified pre-submit component; no inference. |
| `WS-AUTH-001-12G` | Proposed | - | - | Activates deterministic stored post-submit projection; zero model calls. |
| `WS-AUTH-001-12H` | Proposed | - | - | Activates only a complete approved unified guide lineage. |
Expand Down

Large diffs are not rendered by default.

Original file line number Diff line number Diff line change
@@ -0,0 +1,156 @@
# Workstream PR Trust Bundle

## Chunk

`WS-AUTH-001-12I` - Unified Compilation Authorization Activation

## Goal

Activate only `project.guide_compilation.request` for an exact-project Project
Manager and `project.guide_compilation.execute` for the fixed
`workstream.project.setup` service, while leaving POL's hidden compilation
workflow inactive until WS-POL-003-03B composes it.

## Human-approved intent

Continue AUTH-12 after the ART/AUTH prerequisites, preserve strict module
boundaries, avoid local full-suite execution, and use hosted GitHub Backend
lanes for repository-wide coverage.

## What changed

- Added exact request/execute catalogue, policy, kernel, PREP, audit, and SQL
parity plus migration `0063_guide_compilation_authority.py` (revision
`0063_compilation_authority`).
- Added the production AUTH implementation of the public compilation port.
- Added non-evidencing pre-provider authorization and fresh transaction-bound
final PREP with AUTH-verified result digest.
- Enforced exact-project PM grant selection and fixed-service isolation.
- Extracted bounded AUTH-internal helpers while shrinking recorded structural
debt and preserving the cross-module import ledger.
- Added focused runtime, actor-matrix, replay, strict-facts, migration, and
downgrade-refusal proof.
- Corrected the hosted schema fingerprint and strengthened migration `0063` so
both compilation permissions require exact action evidence, historical
permission-only execute evidence blocks upgrade, and every removed request
registry/resource reference blocks downgrade.

## Why it changed

POL-03B must not call a provider or persist an accepted compilation until AUTH
can prove the exact current human request and fixed-service execution authority.

## Design chosen

The existing opaque PREP protocol remains the sole durable authorization path.
Preflight validates the complete typed attempt context but issues no handle and
stages no evidence. Final persistence uses a new transaction and a single-use
handle whose result digest AUTH recomputes. POL-03B retains atomic product
idempotency custody; AUTH does not add a competing durable replay protocol.

## Alternatives rejected

- A normal PREP consume for preflight: it could commit allowed evidence before
provider I/O.
- Trusting the caller's final digest: it would not prove exact result facts.
- System-scoped PM fallback: compilation requests require the exact project.
- A second authorization protocol or POL-local evaluator.

## Scope control

No route, worker, provider call, prompt, product row, checker, ART, REV, task,
submission, or guide-activation behavior is added. Only the two 12I actions are
activated. The allowed-file contract was kept explicit.

## Product behavior

A covered PM may authorize dispatch/recovery for one immutable compilation
context. Only `workstream.project.setup` may pass exact preflight and authorize
accepted-result persistence. The workflow remains hidden until POL-03B wires
the port and product transaction.

## Acceptance criteria proof

- Exact PM project grant succeeds; system grant and actor/service substitutions
deny.
- Preflight binds lineage, catalogues, agent, attempt, and provider key without
a handle or evidence.
- Final result/component digest mismatch denies before PREP.
- Handles are opaque, transaction-bound, single-use, and replay-denying.
- Revoked services deny without allowed evidence.
- Migration roundtrip succeeds and retained request or execute evidence blocks
downgrade.

## Tests/checks run

```text
Focused adapter/domain tests: 16 passed
AUTH boundary plus focused non-DB tests: 65 passed (before final test additions)
PostgreSQL 0063 roundtrip and retained-evidence downgrade tests: passed
PostgreSQL compilation migration adoption/custody suite: 10 passed
Changed adapter coverage: 98.36%; hosted per-file AUTH enforcement coverage
and the complete AUTH-module coverage gate retain the 90% requirement
Ruff: passed
Authorization boundary: passed
Test-structure boundary: passed
Behavior ownership: passed
Stale authorization/Workstream wording: passed
Markdown links: passed
git diff --check: passed
```

Repository-wide tests and the 78% global floor run only in hosted GitHub
Backend lanes on the exact pushed head.

## Test delta

No tests were removed, skipped, weakened, or marked xfail. New focused tests
cover real-kernel positive and negative behavior rather than only mocks.

## CI integrity

No workflow, threshold, lint, typecheck, or failure-masking behavior was
weakened. Focused tests were added to the existing semantic lane and behavior
ownership manifests.

## Reviewer results

Architecture, security, QA, product/operations, senior engineering, CI
integrity, reuse/dedup, test-delta, and documentation reviews pass after their
findings were fixed.

## External review

The first hosted Backend run exposed a stale canonical schema fingerprint. The
second exact-head run proved that correction and then exposed missing
action-required SQL custody plus stale historical migration assertions. Those
failures were fixed without weakening CI. After current main was merged, the
next hosted run exposed two further historical assumptions: 0022 admitted later
12I evidence, and 0049 parity omitted later permission-registry additions. Both
were corrected, and the exact two PostgreSQL tests pass in a runner-owned
disposable database. Fresh GitHub Actions and a substantive CodeRabbit review
remain required on the next pushed exact head.

## Remaining risks

- POL-03B must consume these boundaries in the same transaction as its unique
operation/attempt transition; AUTH activation alone does not make the product
flow live.
- The AUTH-internal `domain`/`runtime` partition has a non-blocking layering
smell recorded by architecture review for later boundary recovery.

## Follow-up work

WS-POL-003-03B installs the live composition and provider/product ordering.
AUTH then resumes its approved post-12I sequence.

## Human review focus

- No preflight evidence or handle survives provider I/O.
- Exact-project PM selection when system and project grants coexist.
- Complete preflight and final digest binding.
- Only the two intended actions become active.

## Human merge ownership

- [ ] The user explicitly approves this specific PR for merge.
Loading
Loading