Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view

Large diffs are not rendered by default.

Original file line number Diff line number Diff line change
Expand Up @@ -17,3 +17,11 @@
8. The revision-0023 frozen Python contract, service-identity migration helper,
and its CLI are obsolete after the clean cut and are deleted. The current
runtime service-identity registry remains authoritative.
9. The two singleton seed sequences are advanced to their seeded maximum with
`is_called = true`. The old development chain left both at `(1, false)`,
which would make the first generated key collide with row `1`; preserving
that unsafe runtime state would contradict the approved collision guard.
10. The raw pre-reset source manifest is retained unchanged. A separate
installed-baseline manifest and machine-checked approved-delta record make
the two sequence repairs visible; parity proof must never mutate the source
evidence until it appears identical to the safer target.
13 changes: 8 additions & 5 deletions .agent-loop/initiatives/WS-DB-001-v01-schema-baseline/PLAN.md
Original file line number Diff line number Diff line change
Expand Up @@ -22,14 +22,16 @@
3. Build one root Alembic revision, `0001_v01_baseline`, from reviewed
deterministic schema and seed resources.
4. Commit deterministic resources under `backend/alembic/baseline/`:
`v01_schema.sql`, `v01_reference_data.sql`, and
`v01_source_manifest.json`. The SQL must contain no owner, database,
`v01_schema.sql`, `v01_reference_data.sql`, the raw
`v01_pre_reset_source_manifest.json`, the installed
`v01_baseline_manifest.json`, and `v01_approved_manifest_delta.json`. The SQL must contain no owner, database,
credential, session authorization, or environment-specific statement. It
emits grants against the allowlisted target-role mapping and applies
deterministic `setval`/identity restart state after seeded inserts.
5. Provision a second empty database from only the new baseline.
6. Compare normalized old-head and new-baseline manifests byte-for-byte, then
run ORM, runtime catalogue, fixed-service, mutation-guard, and API proof.
6. Machine-check that normalized old-head and new-baseline manifests differ
only by the approved two-sequence collision repair, then run ORM, runtime
catalogue, fixed-service, mutation-guard, and API proof.
7. Delete the 63 old revisions and replace historical-transition tests with
current-state baseline and enforcement tests.
8. Delete `backend/migration_contracts/**`, the revision-0023-only service
Expand Down Expand Up @@ -63,7 +65,8 @@ change.

- Alembic reports exactly one head/root revision.
- Empty database upgrade succeeds twice on independent databases.
- Normalized old-head and new-baseline object/reference manifests match.
- Normalized old-head and new-baseline object/reference manifests differ only
by the committed, approved sequence-state repair.
- Sequence runtime/identity restart state matches, and the first generated key
after baseline installation cannot collide with a seeded row.
- For every canonical ACL entry, effective privileges queried under each
Expand Down
Original file line number Diff line number Diff line change
@@ -1,9 +1,10 @@
# Status

- Initiative: `WS-DB-001-v01-schema-baseline`
- State: planning proposed
- Source head: `98eae13e`
- Current Alembic head: `0063_compilation_authority`
- Next action: approve `WS-DB-001-01` for implementation
- State: `WS-DB-001-01` local implementation and internal review complete;
hosted CI pending
- Source head: `1ad50f4f`
- Current Alembic head: `0001_v01_baseline`
- Next action: publish the single PR and complete hosted Backend and Agent Gates
- Product work remains paused until the baseline reset is merged and a clean
database passes the full hosted backend gate.
Original file line number Diff line number Diff line change
Expand Up @@ -35,7 +35,9 @@ schema baseline. No old database is upgradeable.
`0001_v01_baseline`, with `down_revision = None`.
2. A fresh database reaches the single head and exposes exact current tables,
columns, keys, checks, indexes, sequences, types, functions, and triggers.
3. Normalized source-head and baseline manifests match byte-for-byte.
3. The raw normalized source-head manifest and installed-baseline manifest
differ only by the committed, machine-checked correction that advances the
two singleton-row sequences past their seeded keys.
4. Canonical authorization catalogue and fixed-service reference rows match
runtime definitions exactly.
5. Database immutability, append-only, evidence-linkage, and lifecycle guards
Expand All @@ -57,7 +59,10 @@ schema baseline. No old database is upgradeable.
rows remain unchanged.
12. The committed manifest extractor covers a closed list of PostgreSQL object
classes and has sentinel tests for each class. Source and baseline manifests
are committed at `backend/alembic/baseline/v01_source_manifest.json` and
are committed at
`backend/alembic/baseline/v01_pre_reset_source_manifest.json` and
`backend/alembic/baseline/v01_baseline_manifest.json`, with the sole
approved difference recorded in `v01_approved_manifest_delta.json` and
compared by the hosted suite.
Sequence runtime state (`last_value`/`is_called` and equivalent identity
restart state) is included; seed SQL restores it deterministically and a
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,39 @@
# WS-DB-001-01 External Review Response

## Comments addressed

- Human review identified that pretty-printing the two generated schema
manifests inflated the PR by 53,844 presentation-only lines. The canonical
serializer and committed manifests now use compact, sorted JSON, with a
regression test requiring exact compact bytes. Manifest content and schema
parity proof are unchanged.
- GitHub Backend `shared_foundations_a` exposed one stale documentation assertion
that still required the removed revision-specific ART catalogue wording. The
test now proves that the catalogue reconciliation is part of the v0.1
baseline, matching the current operations runbook.
- The frozen test-structure ledger was regenerated after a one-line reduction
in the existing oversized authorization test file. Structural enforcement was
not bypassed or relaxed.

## Comments deferred

- None.

## Human decisions needed

- None. CodeRabbit produced no actionable review thread. Its review was skipped
because the clean-cut removal of the historical migration graph exceeds the
service's 100-file limit; splitting the atomic baseline reset would violate
the approved chunk contract.

## Commands rerun

- Focused authorization documentation contract test.
- Compact-manifest canonicalization and approved-delta tests.
- Frozen test-structure debt validation.
- Ruff on the corrected test file.
- Git diff whitespace validation.

## Remaining risks

- Hosted exact-head CI remains the final full-suite and coverage proof.
Original file line number Diff line number Diff line change
@@ -0,0 +1,46 @@
# WS-DB-001-01 PR Trust Bundle

## Intent and scope

Reset the unreleased v0.1 development migration graph to one authoritative
Alembic baseline while preserving the exact current schema, reference data,
security behavior, and application contracts. Historical revisions and their
migration-only tooling are removed; existing databases are not upgraded through
the deleted graph.

## Design

- One root/head revision installs deterministic schema and reference-data SQL.
- Canonical manifests prove the baseline against the pre-reset schema, with one
explicit sequence-state delta. They are compact sorted JSON machine evidence
so generated formatting does not obscure the human-reviewable SQL and delta.
- Fresh empty databases are supported; old stamps and nonempty schemas fail
closed; downgrade is unsupported.
- Product behavior, authorization, module-boundary, and coverage tests remain in
the parallel hosted lanes.

## Verification and review

- Alembic reports exactly one root/head.
- Focused baseline, reset, behavior-ownership, authorization documentation, and
test-structure tests pass locally. Compact-manifest tests also prove exact
deterministic serialization and unchanged approved-delta semantics.
- Ruff, boundary checks, stale-wording scan, markdown-link checks, and diff
whitespace checks pass locally.
- Required architecture, security, QA, test-delta, CI-integrity, reuse, senior,
and documentation reviews have no unresolved valid finding.
- CodeRabbit has no actionable thread; its automated review is service-limited
by the atomic clean-cut file count.

## Human review focus

- Confirm the clean-cut policy: recreate development databases and require a
separately reviewed forward remediation for any pre-v0.1 production data.
- Confirm the deterministic schema/reference manifests and approved sequence
delta represent the intended v0.1 database.
- Confirm no removed migration-only workflow remains presented as current.

## Remaining gate

All exact-head GitHub Actions lanes and the aggregate coverage job must pass
before merge.
12 changes: 6 additions & 6 deletions .ci/behavior-ownership/partition.v1.json
Original file line number Diff line number Diff line change
Expand Up @@ -156,10 +156,6 @@
"group": "shared",
"target": "backend/app/modules/actors/service_identities.py"
},
{
"group": "shared",
"target": "backend/app/modules/actors/service_identity_migration.py"
},
{
"group": "shared",
"target": "backend/app/modules/api_controls/models.py"
Expand Down Expand Up @@ -774,7 +770,11 @@
},
{
"group": "shared",
"target": "backend/scripts/service_actor_identity_mapping.py"
"target": "backend/scripts/schema_baseline_manifest.py"
},
{
"group": "shared",
"target": "backend/scripts/schema_baseline_sql.py"
},
{
"group": "shared",
Expand All @@ -789,7 +789,7 @@
"target": "backend/scripts/week2_api_e2e.py"
}
],
"authority_digest": "980703d737c30d6579d96d01bb348116af9bfbc772a1d74ad15131d9e2388597",
"authority_digest": "a26548020ee449fb68a72c86e17bd1f98a6d47804e55d09a5f1a9f3b4c5fb095",
"protected_base_commit": "7676ce4347db0c9694962a9b587a20765e16eac6",
"schema": "workstream.behavior-ownership-partition.v1"
}
4 changes: 4 additions & 0 deletions CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -50,6 +50,10 @@ progress. Calendar plans, early chunk specifications, imported files under
are useful history unless a current document explicitly adopts them; they are
not by themselves current sequencing or proof that behavior is live.

The active migration graph is the clean v0.1 baseline. A local database with a
removed pre-v0.1 revision must be recreated; do not add a compatibility stamp,
bridge migration, or second baseline.

Roadmaps and status documents must use capability milestones and evidence. Do
not introduce delivery promises such as day plans, numbered weeks, or rolling
time windows as repository authority.
Expand Down
5 changes: 5 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -357,6 +357,11 @@ uv sync --locked --extra dev --python python3
.venv/bin/python -m uvicorn app.main:app --reload
```

The v0.1 schema starts at the single `0001_v01_baseline` Alembic revision.
Development databases stamped with any earlier revision are intentionally not
upgradeable: delete and recreate the local database, then run `alembic upgrade
head`. Workstream never rewrites or compatibility-stamps an old database.

Verify the API from another terminal with:

```bash
Expand Down
Loading
Loading