Skip to content

Authorize exact post-submit execution and receipt custody - #456

Merged
abiorh-claw merged 7 commits into
mainfrom
codex/arch04d2-post-submit-authority
Oct 1, 2026
Merged

abiorh-claw merged 7 commits into
mainfrom
codex/arch04d2-post-submit-authority

Conversation

@Abiorh001

@Abiorh001 Abiorh001 commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

Change

ARCH-04D2 — authorize exact post-submit materialization, execution and finalization.

Goal And Planning Context

Connect the existing hidden checker executor to real fixed-service AUTH/PREP. Each phase authorizes the exact run and lease; final results retain immutable authorization receipts. Bounded change record owns design, allowed files, acceptance criteria and remaining boundaries.

What Changed

  • Add the fixed workstream.checker.post_submit identity with only execute/finalize actions; activate input materialization under the existing ART identity.
  • Require the current execution lease before materialization, then revalidate live authority and the original read receipt after I/O.
  • Validate both stored receipts on terminal replay without another provider read or audit insert.
  • Add migration 0010 with deferred receipt foreign keys and exact phase digests. Preserve queued work; refuse unprovable retained receipts without rewriting or deleting data.
  • Preserve cancellation/deadline precedence while surfacing actual scratch-cleanup failures. Failed cleanup cannot become a retained infrastructure result.
  • Replace unavailable execution participants and permissive current-schema test authorities with real composition; update affected callers, tests, inventories and current documentation together.

Scope And Product Behavior

The hidden executor now requires real exact service authority. Principals must be explicitly provisioned through the existing administration path. No public execution route, automatic dispatch handler, TASK routing, acceptance, review or output-file publishing is activated. No compatibility alias or fallback path is added. All changed files are within the record's allowed scope.

ARCH-04E1A routing-source facts remain next. Shared final acceptance is still required for human_review_required=false; human review remains the default. The receipt correction does not change roadmap exposure or this sequence.

Receipt-Custody Review Correction

Head c6eebfed fixes the external finding: migration 0010 independently requires a non-null execute receipt before accepting a finalize receipt. The direct-SQL regression isolates the deferred receipt validator from the earlier immediate run-state guard, supplies an otherwise matching real-service audit event, and verifies the named custody rejection and full rollback. Its non-null control commits.

Security independently ran both cases on the exact clean head: 2 passed. Restoring the old SQL predicate makes only the missing-execute case fail at DID NOT RAISE IntegrityError; the valid control still passes. Earlier fixture-setup failures are excluded from this proof. The existing 13 receipt/migration cases also passed during repair. The generated schema fingerprint reflects the changed SQL function.

Evidence And Test Delta

Backend run 36881408854 passed all nine lanes and the aggregate: 8,005 collected = 8,005 completed, zero skipped or deselected. Tested merge 877a2805 has exactly the same tree as final head c6eebfed. All required checks, including API contracts and Agent Gates, pass. Diagnostic coverage: 94.99%. Backend wall time: 22m44s, above the advisory timing target.

Focused proof covers exact receipt substitution, real audit INSERT failure and rollback, live revocation, currentness, replay without extra effects, cancellation versus cleanup, migration writer exclusion, and Local/MinIO material custody. Deliberate removals fail at the intended assertions. Existing distinct lineage, privacy, concurrency and upgrade proofs remain. No tests are skipped or gates weakened. Ruff, module/ownership/structure checks, markdown links, stale-wording and Commitrail checks passed.

Impact-Routed Reviewer Results

  • Architecture/reuse and senior engineering: PASS on code candidate 4a4f6b31.
  • Documentation/product operations: PASS on 8b5b086b.
  • Security and QA/test delta: PASS on final clean c6eebfed, explicitly reviewing the four-file receipt correction against 8b5b086b and relevant unchanged guards.
  • CI integrity: PASS on final clean c6eebfed; independently validated the final hosted aggregate, exact tree/artifact custody and complete execution.

Earlier review targets are not relabeled as final-head receipts. The final delta is the bounded SQL/test/fingerprint/change-record correction described above; no new architecture or product workflow was introduced. Reviewer summaries mirror private sessions without copying receipt custody.

External Review

The reported missing-execute receipt finding is fixed with discriminating PostgreSQL proof. CodeRabbit is not fresh substantive review: it skipped because the PR exceeds its 100-file limit. Human approval remains required.

CI And Gate Integrity

No workflow, test selection, lint, docstring, coverage, package-script or required-check weakening. Coverage is diagnostic only. Exact ownership/lane registrations and schema fingerprint follow changed owners.

Remaining Risks And Human Review Focus

Migration 0010 refuses retained receipts without provable authorization. No service actor is automatically created. Inspect AUTH → fence/run lock ordering, phase digest parity, post-I/O revocation, original-receipt replay, non-null execute/finalize chaining and retained-data refusal. Automatic routing, remediation, shared acceptance and public intake remain separate work.

Human Merge Ownership

  • The user explicitly approved this specific PR for merge.

@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Too many files!

This PR contains 110 files, which is 10 over the limit of 100.

To get a review, reduce the PR to 100 files or fewer by splitting it into smaller PRs or changing its base branch.

Upgrade to a paid plan to raise the limit.

This review couldn't start because sufficient usage credits or metered capacity aren't available. Add credits or update usage-based reviews in the billing tab, then retry.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: d526c053-a7e9-4254-92eb-00b104d3ae99

📥 Commits

Reviewing files that changed from the base of the PR and between 39a6b82 and c6eebfe.

⛔ Files ignored due to path filters (6)
  • docs/architecture_brief/images/backend_v01_components.png is excluded by !**/*.png
  • docs/architecture_brief/images/task_lifecycle_sequence.png is excluded by !**/*.png
  • docs/architecture_brief/images/workstream_v01_container.png is excluded by !**/*.png
  • docs/architecture_brief/workstream_architecture_brief.pdf is excluded by !**/*.pdf
  • docs/diagrams/rendered/backend_v01_components.svg is excluded by !**/*.svg
  • docs/diagrams/rendered/workstream_v01_container.svg is excluded by !**/*.svg
📒 Files selected for processing (110)
  • .ci/auth-boundaries/TEST_STRUCTURE_DEBT.json
  • .ci/behavior-ownership/partition.v1.json
  • .commitrail/INDEX.md
  • .commitrail/initiatives/WS-ARCH-001/OVERVIEW.md
  • .commitrail/initiatives/WS-ARCH-001/WS-ARCH-001-04D2.md
  • .commitrail/initiatives/WS-ARCH-001/planning/CHUNK_MAP.md
  • .commitrail/initiatives/WS-ARCH-001/planning/PLAN.md
  • .commitrail/initiatives/WS-ARCH-001/planning/chunks/WS-ARCH-001-04D-auth-post-submit-activation.md
  • .commitrail/initiatives/WS-ART-001/OVERVIEW.md
  • .commitrail/initiatives/WS-AUTH-001/OVERVIEW.md
  • .commitrail/initiatives/WS-AUTH-001/planning/CHUNK_MAP.md
  • .commitrail/initiatives/WS-AUTH-001/planning/PLAN.md
  • .commitrail/initiatives/WS-AUTH-003/OVERVIEW.md
  • .commitrail/initiatives/WS-CON-001/OVERVIEW.md
  • .commitrail/initiatives/WS-POL-003/OVERVIEW.md
  • .commitrail/initiatives/WS-POL-003/planning/CHUNK_MAP.md
  • .commitrail/initiatives/WS-POL-003/planning/PLAN.md
  • .commitrail/initiatives/WS-POL-003/planning/chunks/WS-POL-003-07-single-checker-service-port.md
  • README.md
  • backend/alembic/env.py
  • backend/alembic/versions/0010_post_submit_authority.py
  • backend/app/adapters/artifacts/__init__.py
  • backend/app/adapters/auth/__init__.py
  • backend/app/adapters/checkers/__init__.py
  • backend/app/modules/actors/api/service_identities.py
  • backend/app/modules/artifacts/post_submit_materialization.py
  • backend/app/modules/artifacts/preparation.py
  • backend/app/modules/artifacts/sources.py
  • backend/app/modules/audit/schemas.py
  • backend/app/modules/authorization/admin_schemas.py
  • backend/app/modules/authorization/catalogue.py
  • backend/app/modules/authorization/domain/audit.py
  • backend/app/modules/authorization/domain/audit_targets.py
  • backend/app/modules/authorization/domain/post_submit.py
  • backend/app/modules/authorization/domain/prepared_service.py
  • backend/app/modules/authorization/domain/resource_digest.py
  • backend/app/modules/authorization/post_submit_authorization.py
  • backend/app/modules/authorization/prepared.py
  • backend/app/modules/authorization/prepared_post_submit_replay.py
  • backend/app/modules/authorization/runtime.py
  • backend/app/modules/checkers/api/execution.py
  • backend/app/modules/checkers/api/materialization.py
  • backend/app/modules/checkers/execution.py
  • backend/app/modules/checkers/execution_authority.py
  • backend/app/modules/checkers/execution_coordination.py
  • backend/app/modules/checkers/models.py
  • backend/scripts/behavior_ownership.py
  • backend/scripts/test_lane_catalogue.py
  • backend/tests/authorization/admin_access/test_admin_reads_postgresql.py
  • backend/tests/authorization/admin_access/test_grant_reads_postgresql.py
  • backend/tests/authorization/catalogue_fixtures.py
  • backend/tests/authorization/post_submit/__init__.py
  • backend/tests/authorization/post_submit/test_atomicity.py
  • backend/tests/authorization/post_submit/test_concurrency.py
  • backend/tests/authorization/post_submit/test_live_authority.py
  • backend/tests/authorization/post_submit/test_migration.py
  • backend/tests/authorization/post_submit/test_principals.py
  • backend/tests/authorization/post_submit/test_receipt_custody.py
  • backend/tests/authorization/post_submit/test_timeout.py
  • backend/tests/authorization/setup_finalization/test_catalogue.py
  • backend/tests/authorization/test_assignment_invalidation_contract.py
  • backend/tests/authorization/test_catalogue.py
  • backend/tests/checkers/execution/material_storage_helpers.py
  • backend/tests/checkers/execution/predecessor_material_helpers.py
  • backend/tests/checkers/execution/predecessor_support.py
  • backend/tests/checkers/execution/storage_fixture.py
  • backend/tests/checkers/execution/support.py
  • backend/tests/checkers/execution/test_concurrency.py
  • backend/tests/checkers/execution/test_coordination.py
  • backend/tests/checkers/execution/test_execution.py
  • backend/tests/checkers/execution/test_material_lineage.py
  • backend/tests/checkers/execution/test_material_migration.py
  • backend/tests/checkers/execution/test_migration.py
  • backend/tests/checkers/execution/test_storage.py
  • backend/tests/checkers/post_submit/test_request.py
  • backend/tests/checkers/test_phase_service.py
  • backend/tests/conftest.py
  • backend/tests/post_submit_materialization_helpers.py
  • backend/tests/retained_material_fixtures.py
  • backend/tests/test_alembic.py
  • backend/tests/test_approved_guide_intake.py
  • backend/tests/test_artifact_architecture.py
  • backend/tests/test_artifact_preparation.py
  • backend/tests/test_audit.py
  • backend/tests/test_authorization.py
  • backend/tests/test_behavior_ownership.py
  • backend/tests/test_ci_lane_catalogue.py
  • backend/tests/test_coverage_contract.py
  • backend/tests/test_post_submit_materialization.py
  • backend/tests/test_post_submit_selection.py
  • backend/tests/test_pre_submit_attempt_authority_integration.py
  • backend/tests/test_pre_submit_attempt_lock_order.py
  • backend/tests/test_submission_bundle_preparation_recovery.py
  • backend/tests/test_tasks.py
  • docs/architecture_brief/README.md
  • docs/architecture_brief/task_lifecycle_sequence.puml
  • docs/architecture_brief/workstream_architecture_brief.md
  • docs/architecture_checker_framework.md
  • docs/architecture_data_model.md
  • docs/architecture_system_architecture.md
  • docs/current_system_data_flow.html
  • docs/diagrams/backend_v01_components.md
  • docs/diagrams/backend_v01_components.puml
  • docs/diagrams/workstream_v01_container.puml
  • docs/engineering/authorization_activation_custody.md
  • docs/operations_project_operating_manual.md
  • docs/roadmap_status.md
  • docs/spec_artifact_storage_service.md
  • docs/spec_authorization_service.md
  • mcp_server/contracts/authorization_context_get.json

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@Abiorh001
Abiorh001 marked this pull request as ready for review October 1, 2026 12:56
@abiorh-claw
abiorh-claw self-requested a review October 1, 2026 16:07
@abiorh-claw
abiorh-claw merged commit d5bf346 into main Oct 1, 2026
16 checks passed
@abiorh-claw
abiorh-claw deleted the codex/arch04d2-post-submit-authority branch October 1, 2026 16:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants