Skip to content

ARCH-04E1A: bind post-submit routing source evidence - #457

Merged
abiorh-claw merged 10 commits into
mainfrom
codex/arch04e1a-routing-source
Oct 1, 2026
Merged

abiorh-claw merged 10 commits into
mainfrom
codex/arch04e1a-routing-source

Conversation

@Abiorh001

@Abiorh001 Abiorh001 commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

Change

ARCH-04E1A — Bind future post-submit routing to immutable source evidence.

Goal and planning context

A successful checker result needs an exact retained Submission source before shared acceptance can reference it. The change record defines field ownership, scope, proofs and next dependencies.

What changed and why

  • Add one immutable TASK source table binding Submission, assignment, contributor and locked policy identity to the exact completed checker result, phase receipts and canonical ART material.
  • Add detached source facts and a source-neutral, type-only accepted-effects interface.
  • Enforce exact source custody, database-owned creation time, restrictive ownership references and immutable retained history in PostgreSQL. Preserve existing owners' string/Python UUID representations while storing native PostgreSQL UUIDs.
  • Reconcile affected roadmap, current initiative navigation and canonical specifications.

This introduces no runtime writer, reader, handler, current pointer, routing authority or acceptance implementation. human_review_required=false remains unavailable for guide activation; its contract test proves scalar transport only. Later publication must harden this same table with mandatory exact routing/owner receipts and refuse retained pre-authority rows.

Design and scope

Reuse TASK policy lineage and canonical ART material/CHECKERS receipt validation. CHECKERS receipts do not authorize routing. No compatibility path, new dependency, metadata-boundary exception or parallel acceptance operation.

All changed files are within the record. Existing migration tests retain their original target where appropriate; current-head assertions advance to 0011. No test was removed or skipped.

Repeated shared-lane timeouts exposed costly static repository and CI collection/evidence contracts. Their measured reassignment to the existing schema-contract lane preserves all nine lanes and all 8,047 tests. The latest run also exposed a primary-key inventory mismatch; the equivalent column-level declaration repairs it without changing generated PostgreSQL DDL. No workflow, runner, service, hashing, timeout, coverage policy or complete-execution validator changed. This scheduling repair changes no product capability or roadmap dependency.

Evidence

Candidate: e63d89430b1bbe9178f9813355ac633eb51e8dd7; base: d5bf346081f813614522cb08ad63bbdd178ab511.

  • Real PostgreSQL/MinIO proof covers admitted ZIP custody, activated and superseded guide lineage, coherent same-project/cross-project substitutions, exact phase receipts, complete historical policy DTOs, rollback and immutability.
  • Five guard-removal probes passed real-source controls and failed the intended timestamp, request-digest, execute-receipt, activation and immutability regressions. SQL guards are unchanged since that clean-head proof.
  • Schema comparison retains all 5,517 predecessor catalogue objects and adds 58 source objects.
  • Focused identifier/affected PostgreSQL repair tests passed 8/8. The existing identifier parity regression is unchanged.
  • Static architecture and CI profiles informed the bounded lane placement. The final focused repair suite passed 212 tests; identifier/schema checks passed 11 tests. Real PostgreSQL schema/upgrade checks passed 2 tests and retained the same fingerprint; the complete generated PostgreSQL DDL is byte-identical before/after the primary-key declaration repair. These development checks do not replace final hosted execution.
  • Canonical before/after collection retains the same 8,047 unique nodes and execution modes; only the intended 207 additional nodes change lanes (376 total in the schema lane). No other assignment changes.
  • Final Ruff, structural/boundary checks, stale wording, 24 changed Markdown links, Commitrail validation and diff checks pass.
  • Hosted verification passed: Backend run 36915160013, all nine lanes and aggregate; 8,047/8,047 tests completed, zero skipped/deselected, 95.01% diagnostic global coverage. Downloaded manifest, evidence, isolation and coverage hashes reconcile. Tested merge ecc01c76524dddceaad158cd8a6f815d57966f12 has the identical tree to this candidate. Agent gates and real API contract also pass.

Findings repaired: caller-controlled creation time, incomplete sibling/historical proof, oversized fixture, ORM reference representation mismatch, static identifier-inventory mismatch, and shared-lane scheduling pressure. No guard or test assertion was relaxed.

Impact-routed review

Current review target: e63d89430b1bbe9178f9813355ac633eb51e8dd7. All required internal review tracks are complete on this head. The following summarize separate specialty verdicts; paired tracks share one reviewer session.

Track Result Proof boundary
Architecture / reuse PASS / PASS Owner APIs, acyclic source boundary, model/FK parity, no runtime consumer, exact lane ownership
Security PASS Composite source custody, exact receipts/material, database clock, no premature authority
QA / test delta PASS / PASS Real source controls, discriminating guard mutations, full historical facts, unchanged test-node set
Documentation / product operations PASS / PASS Accurate source-only capability, both policy branches, shared acceptance sequence, honest timing limits
CI integrity PASS WITH LOW RISKS Complete exact-tree nine-lane aggregate; unchanged gates; narrow remaining runtime margin

Reviews used clean matching start/end targets, inspected relevant unchanged owners and distinguished executed proof from source inspection. Mutation probes target unchanged production/test bytes from earlier clean candidates; no old execution was relabeled as final-head execution.

External review

CodeRabbit completed substantive review of the prior 9ea4fd68 head (run ca9660e6-c0ee-4314-a61a-e4029b5686a3), covering the changes since its prior review. No actionable findings or unresolved threads. The latest e63d8943 status is rate-limited, not a fresh substantive review. The earlier docstring-percentage advisory is non-blocking; repository behavior, documentation and lint checks remain the applicable requirements, and no percentage gate is introduced.

Remaining scope and human review focus

Next: shared REV-04B source/FinalAcceptance persistence, CON-03C/07 and existing REV-12A/CON fence foundations, then shared acceptance composition, ARCH-04E1B/04E2/04E3 and remediation. Human and automated acceptance must share one operation; no fabricated Review or reviewer contribution.

Inspect exact retained source custody, historical validity without a currentness claim, and the absence of premature routing/acceptance authority. The final Backend wall time was 22m14s, above the advisory timing target. Shared A completed in 1,150.546s with 49.454s margin under its unchanged 1,200s cap; hosted contention remains a timing risk.

Human approval and merge remain required. No merge is authorized by these checks.

@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: ca9660e6-c0ee-4314-a61a-e4029b5686a3

📥 Commits

Reviewing files that changed from the base of the PR and between 42f586d and 9ea4fd6.

📒 Files selected for processing (6)
  • .commitrail/initiatives/WS-ARCH-001/WS-ARCH-001-04E1A.md
  • backend/app/modules/tasks/post_submit_routing/models.py
  • backend/scripts/test_lane_catalogue.py
  • backend/tests/tasks/post_submit_routing/support.py
  • backend/tests/tasks/post_submit_routing/test_storage.py
  • backend/tests/test_ci_lane_catalogue.py

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The change adds an immutable, route-neutral TASK source table, detached source facts, and type-only accepted-effects contracts. It adds database lineage and immutability checks, tests, and documentation updates. It does not add runtime routing or acceptance behavior.

Changes

TASK source contracts and persistence

Layer / File(s) Summary
Source model and API contracts
backend/app/modules/tasks/api/*, backend/app/modules/tasks/post_submit_routing/*, backend/app/db/models.py
Adds strict detached source facts and accepted-effects request, result, and port contracts. The manifest model records source and evidence lineage with database constraints.
Migration and database enforcement
backend/alembic/..., backend/alembic/env.py, backend/tests/conftest.py, backend/tests/test_alembic.py, backend/tests/test_coverage_contract.py, backend/tests/checkers/execution/test_migration.py, backend/tests/authorization/post_submit/test_migration.py
Adds revision 0011_task_routing_source with insert-time lineage checks and immutable-row guards. Updates migration configuration, schema reset support, and revision expectations.
Contract, storage, and migration tests
backend/tests/tasks/post_submit_routing/*
Adds tests for contract validation, source-row lineage, database-owned timestamps, immutability, historical retention, uniqueness, rollback, and migration preservation.
Ownership and delivery records
.ci/behavior-ownership/*, backend/scripts/*, backend/tests/test_behavior_ownership.py, backend/tests/test_ci_lane_catalogue.py, .commitrail/*, docs/*, README.md
Registers the TASK source modules and tests. Updates architecture, initiative, roadmap, and specification text to describe the delivered source-only boundary and the remaining routing and acceptance work.

Priority: ⬇️ Low

Estimated code review effort: 4 (Complex) | ~60 minutes

Change: Feature

Merge Risk: ⚪ Minimal · up to 9ea4f

The change adds source storage and detached contracts without enabling routing or acceptance. No actionable merge-blocking defect is established; normal checks and required approval remain necessary.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 9ea4f

The change establishes tightly validated, immutable evidence without enabling new routing or acceptance behavior. No introduced security concern was identified, but the new retention lifecycle and incomplete concurrency and deployment coverage warrant a low rather than minimal assessment.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The effective new exposure is evidence integrity and retention within the existing backend database. Source-level caller analysis found no new production routing or acceptance caller; the public-entrypoint signals in test support and lane registration do not establish network reachability. This conclusion does not cover unavailable deployment or dynamic-registration behavior.

Trust Boundaries and Controls

  • observed — Caller-supplied source identities and digests must match canonical owner records before storage. Composite foreign keys and trigger comparisons constrain cross-project and cross-submission substitution. These are custody and identity-integrity controls; they do not replace request authorization or grant future acceptance authority.

Resilience and Maintainability Implications

  • observed — Creation time is database-owned, referenced evidence is retained through restricted deletion, and stored manifests cannot be edited into different custody facts. Historical activated or superseded guides remain eligible as source history rather than being treated as current routing authority.
🚥 Pre-merge checks | ✅ 3 | ❌ 1 | ❓ 1

❌ Failed checks (1 warning, 1 inconclusive)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 28.33% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 60 functions across 22 files. (1 skipped:… Write docstrings for the functions missing them to satisfy the coverage threshold.
Linked Issues check ❓ Inconclusive The description links PR #457 and the applicable Commitrail change record, but no issue-linking policy or required issue identifier is provided. Provide the repository policy for linked issues or confirm that the PR and Commitrail record satisfy the required linkage.
✅ Passed checks (3 passed)
Check name Status Explanation
Description check ✅ Passed The description is mostly complete and explains the change, intent, design, scope, evidence, review results, remaining risks, and human merge requirements. Some template headings and checkboxes are co…
Out of Scope Changes check ✅ Passed The changes match the stated objective: immutable TASK source evidence, detached facts, accepted-effects types, migrations, tests, and related documentation. The description also states that all chang…
Title check ✅ Passed The title clearly identifies the main change: binding post-submit routing source evidence for ARCH-04E1A.
Full details: Docstring Coverage

Explanation

Docstring coverage is 28.33% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 60 functions across 22 files. (1 skipped: 1 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@Abiorh001
Abiorh001 marked this pull request as ready for review October 1, 2026 17:45
@abiorh-claw
abiorh-claw self-requested a review October 1, 2026 20:17
@abiorh-claw
abiorh-claw merged commit 7f8acfa into main Oct 1, 2026
16 checks passed
@abiorh-claw
abiorh-claw deleted the codex/arch04e1a-routing-source branch October 1, 2026 20:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants