Authorize exact post-submit execution and receipt custody - #456
Conversation
|
Important Review skippedToo many files! This PR contains 110 files, which is 10 over the limit of 100. To get a review, reduce the PR to 100 files or fewer by splitting it into smaller PRs or changing its base branch. Upgrade to a paid plan to raise the limit. This review couldn't start because sufficient usage credits or metered capacity aren't available. Add credits or update usage-based reviews in the billing tab, then retry. ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: ⛔ Files ignored due to path filters (6)
📒 Files selected for processing (110)
You can disable this status message by setting the
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Change
ARCH-04D2 — authorize exact post-submit materialization, execution and finalization.
Goal And Planning Context
Connect the existing hidden checker executor to real fixed-service AUTH/PREP. Each phase authorizes the exact run and lease; final results retain immutable authorization receipts. Bounded change record owns design, allowed files, acceptance criteria and remaining boundaries.
What Changed
workstream.checker.post_submitidentity with only execute/finalize actions; activate input materialization under the existing ART identity.Scope And Product Behavior
The hidden executor now requires real exact service authority. Principals must be explicitly provisioned through the existing administration path. No public execution route, automatic dispatch handler, TASK routing, acceptance, review or output-file publishing is activated. No compatibility alias or fallback path is added. All changed files are within the record's allowed scope.
ARCH-04E1A routing-source facts remain next. Shared final acceptance is still required for
human_review_required=false; human review remains the default. The receipt correction does not change roadmap exposure or this sequence.Receipt-Custody Review Correction
Head
c6eebfedfixes the external finding: migration 0010 independently requires a non-null execute receipt before accepting a finalize receipt. The direct-SQL regression isolates the deferred receipt validator from the earlier immediate run-state guard, supplies an otherwise matching real-service audit event, and verifies the named custody rejection and full rollback. Its non-null control commits.Security independently ran both cases on the exact clean head: 2 passed. Restoring the old SQL predicate makes only the missing-execute case fail at
DID NOT RAISE IntegrityError; the valid control still passes. Earlier fixture-setup failures are excluded from this proof. The existing 13 receipt/migration cases also passed during repair. The generated schema fingerprint reflects the changed SQL function.Evidence And Test Delta
Backend run 36881408854 passed all nine lanes and the aggregate: 8,005 collected = 8,005 completed, zero skipped or deselected. Tested merge
877a2805has exactly the same tree as final headc6eebfed. All required checks, including API contracts and Agent Gates, pass. Diagnostic coverage: 94.99%. Backend wall time: 22m44s, above the advisory timing target.Focused proof covers exact receipt substitution, real audit INSERT failure and rollback, live revocation, currentness, replay without extra effects, cancellation versus cleanup, migration writer exclusion, and Local/MinIO material custody. Deliberate removals fail at the intended assertions. Existing distinct lineage, privacy, concurrency and upgrade proofs remain. No tests are skipped or gates weakened. Ruff, module/ownership/structure checks, markdown links, stale-wording and Commitrail checks passed.
Impact-Routed Reviewer Results
4a4f6b31.8b5b086b.c6eebfed, explicitly reviewing the four-file receipt correction against8b5b086band relevant unchanged guards.c6eebfed; independently validated the final hosted aggregate, exact tree/artifact custody and complete execution.Earlier review targets are not relabeled as final-head receipts. The final delta is the bounded SQL/test/fingerprint/change-record correction described above; no new architecture or product workflow was introduced. Reviewer summaries mirror private sessions without copying receipt custody.
External Review
The reported missing-execute receipt finding is fixed with discriminating PostgreSQL proof. CodeRabbit is not fresh substantive review: it skipped because the PR exceeds its 100-file limit. Human approval remains required.
CI And Gate Integrity
No workflow, test selection, lint, docstring, coverage, package-script or required-check weakening. Coverage is diagnostic only. Exact ownership/lane registrations and schema fingerprint follow changed owners.
Remaining Risks And Human Review Focus
Migration 0010 refuses retained receipts without provable authorization. No service actor is automatically created. Inspect AUTH → fence/run lock ordering, phase digest parity, post-I/O revocation, original-receipt replay, non-null execute/finalize chaining and retained-data refusal. Automatic routing, remediation, shared acceptance and public intake remain separate work.
Human Merge Ownership