Skip to content

feat(rev): persist immutable review packets (REV-03B) - #460

Merged
abiorh-claw merged 9 commits into
mainfrom
codex/rev03b-packet-persistence
Oct 2, 2026
Merged

abiorh-claw merged 9 commits into
mainfrom
codex/rev03b-packet-persistence

Conversation

@Abiorh001

@Abiorh001 Abiorh001 commented Oct 2, 2026 •

Copy link
Copy Markdown
Collaborator

Change

REV-03B — immutable normalized reviewer packet persistence.

Goal

Freeze the exact Submission ZIP and complete guide document set for one review lease. This completes the packet-storage prerequisite before complete REV-04A Review storage and shared FinalAcceptance.

Intent And Planning Context

Change record defines scope, custody rules, named proof and the next boundary. The approved sequence still permits automated acceptance as the first complete runtime path; this PR activates no human-review workflow.

What Changed

  • Two normalized tables retain one packet per lease, its exact original ZIP binding, and all declared guide members.
  • PostgreSQL reconciles canonical owners, active unexpired lease/queue creation using PostgreSQL time, committed guide uploads, complete membership, and semantic digest. Packet and live-ingest facts reject mutation, deletion and truncation.
  • Caller-owned repository operations provide exact replay after expiry/closure, conflict rejection and project-qualified detached reads. The stored DTO uses AUTH’s packet_manifest_id name with no alias.
  • Replace the unusable guide_binding_id packet field with live ingest_id. The old target is retained extraction evidence whose writes are sealed. No alias or revived path; no retained data deletion.
  • Current specs, roadmap and navigation advance to complete REV-04A Review storage.

Design Chosen

One header plus normalized guide members; the required ZIP is represented by non-null header fields. Existing canonical hashing and immutable-fact guards are reused. ORM references preserve owner representations; detached contracts use native UUIDs. Metadata grants no authority or artifact access.

Scope Control

Allowed implementation, proof and documentation paths are listed in the change record. No public route, resolver, provider I/O, claim activation, Review, acceptance effects, worker or CI-policy change. Identifier and lane inventories add only the new owned entries. This cohesive L1 schema change exceeds the usual size preference because migration custody, direct-SQL proof and current navigation belong together.

Product Behavior

  • Product behavior changed and is explained here: internal storage only; no runtime exposure.

Evidence

Current clean candidate: 49be77efe361823b08fe380fd97639d3ae634e5a, base 7754703f.

The human-review corrections enforce the lease deadline independently in the repository and PostgreSQL INSERT guard, preserve exact replay after expiry/closure, compute substituted digests from final altered fields, require named rejection boundaries, and exercise child insertion while its parent is uncommitted and later rolls back.

Focused real-PostgreSQL deadline, replay, owner-substitution and concurrency cases pass. Removing only the deadline or result-owner predicate makes the expected rejection assertion fail. The parent-visibility test proves PostgreSQL’s immediate FK denial in the second session while the first still owns the uncommitted parent, followed by rollback and no retained rows.

The complete packet/contract batch passed on clean 49be77ef: 52 tests, zero skips/deselections, including the existing migration-head and truncate regressions. All required hosted checks passed: 8,099 tests completed, zero skips or deselections. The tested merge tree exactly matches this candidate, and the downloaded lane evidence passed the canonical validator. Ruff, module boundaries, ownership, Commitrail, Markdown links and stale wording checks pass. The schema fingerprint was measured from the new migration; no validation was weakened.

Acceptance Criteria Proof

The record's named test inventory covers canonical membership, direct-SQL rejection, database-owned time, lease generation, exact replay, rollback, concurrent writers/closure, migration preservation and historical lineage. Guard-removal probes must fail at the intended assertion, not fixture setup. Namespace substitution is rejected by ART's existing namespace FK before packet validation.

Test Delta

New PostgreSQL storage/repository/migration tests; existing ART contract tests replace the obsolete field and explicitly reject it. Identifier, schema-reset, lane and ownership inventories are extended. No tests removed or skipped; no coverage gate introduced or weakened.

Impact-Routed Reviewer Results

Security, QA/test-delta, architecture/reuse and documentation/product operations passed on exact 49be77ef. No findings remain. Security independently reran the deadline and altered-result owner cases: 2 passed. Final CI-integrity review passed with no active findings: exact-tree hosted completeness, evidence digests, all nine lane inventories, and PostgreSQL/MinIO cleanup were verified. The remaining low risk is timing headroom, described below.

CodeRabbit completed a substantive review of 49be77ef, with no actionable findings and no unresolved threads. Its docstring-percentage advisory is not a repository gate.

Risks And Human Review Focus

Verify canonical stored lineage and the absence of byte/claim authority. Live packet resolution, exact authorization, complete Review storage and both acceptance triggers remain later work. Local tests use real PostgreSQL and canonical owner fixtures; they do not claim live reviewer endpoints or new provider execution.

The final hosted run took 22m03s; its slowest lane used 1,144.9s of the unchanged 1,200s limit. Timing remains above the advisory target, with about 55 seconds of lane headroom. No timeout or gate was relaxed.

Roadmap impact is reflected in the same PR, including the diagram, remaining gates and current initiative navigation. No local spreadsheet exports are present.

  • Eligible human approval of the final reviewable head.
  • Human merge after final checks and review conversations are resolved.

@coderabbitai

coderabbitai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 41c0a4e1-e40b-4288-8615-f60acdabefe5

📥 Commits

Reviewing files that changed from the base of the PR and between 58001b7 and 49be77e.

📒 Files selected for processing (12)
  • .commitrail/initiatives/WS-REV-001/WS-REV-001-03B.md
  • backend/alembic/versions/0012_review_packet.py
  • backend/app/modules/reviews/packet/repository.py
  • backend/app/modules/reviews/packet/schemas.py
  • backend/tests/checkers/execution/test_migration.py
  • backend/tests/conftest.py
  • backend/tests/reviews/packet/support.py
  • backend/tests/reviews/packet/test_repository.py
  • backend/tests/reviews/packet/test_storage.py
  • backend/tests/test_checker_output_storage.py
  • docs/architecture_data_model.md
  • docs/spec_review_lifecycle.md

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The pull request adds immutable, normalized review packet storage tied to exact leases, queue entries, submissions, guide snapshots, and live guide ingests. It adds database validation and repository operations, updates tests and ownership records, and marks REV-03B delivered with REV-04A next.

Changes

Review packet storage

Layer / File(s) Summary
Packet contract and data model
backend/app/modules/artifacts/api/review_packet.py, backend/app/modules/reviews/packet/*, backend/app/db/models.py, backend/app/modules/projects/models.py, backend/tests/artifacts/test_review_packet_contract.py, backend/tests/test_identifier_schema.py, .commitrail/initiatives/WS-REV-001/WS-REV-001-03B.md
Guide members now use ingest_id. New schemas and ORM models represent packet manifests and ordered guide items, with constraints on identifiers, digest format, generation, role, and media type.
Database validation and immutability
backend/alembic/versions/0012_review_packet.py, backend/alembic/env.py, backend/tests/reviews/packet/test_storage.py, backend/tests/reviews/packet/test_migration.py, backend/tests/conftest.py, backend/tests/test_alembic.py
The migration adds packet tables, checks lease and queue state, validates complete guide membership and upload custody, and verifies digest parity. Triggers reject packet and ingest mutations. Tests cover constraints, migration preservation, and immutability.
Repository storage and replay
backend/app/modules/reviews/packet/repository.py, backend/tests/reviews/packet/support.py, backend/tests/reviews/packet/test_repository.py, backend/scripts/test_lane_catalogue.py, backend/tests/test_ci_lane_catalogue.py
The repository stores or reads project-qualified packet metadata. Matching membership replays the stored packet; changed membership conflicts. Tests cover transaction rollback, concurrent stores, lease closure, and guide lineage.
Ownership, evidence, and delivery status
.ci/behavior-ownership/partition.v1.json, backend/scripts/behavior_ownership.py, backend/tests/test_behavior_ownership.py, .commitrail/*, README.md, docs/*
Ownership and test-lane records include packet storage. Initiative records and documentation identify REV-03B storage as delivered and complete REV-04A Review storage as next.

Priority: ➖ Normal

Estimated code review effort: 4 (Complex) | ~60 minutes

Change: Feature

Sequence Diagram(s)

sequenceDiagram
  participant ApplicationCaller
  participant ReviewPacketRepository
  participant PostgreSQL
  ApplicationCaller->>ReviewPacketRepository: store lease and membership
  ReviewPacketRepository->>PostgreSQL: lock lease and queue entry
  PostgreSQL-->>ReviewPacketRepository: current lease and queue state
  ReviewPacketRepository->>PostgreSQL: insert packet manifest and guide items
  PostgreSQL-->>ReviewPacketRepository: validated packet records
  ReviewPacketRepository-->>ApplicationCaller: stored packet without commit
Loading

Merge Risk: ⚪ Minimal · up to 49be7

No actionable packet-storage issue remains identified; the change is mergeable after normal checks.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 49be7

The new review records have layered ownership, expiry and immutability checks, without activating a new user-facing access path. No concrete security regression was established, but deployment compatibility and correction-test results remain unverified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • observed — Packet operations are project-qualified, while the migration’s guide-ingest mutation prohibition applies table-wide, including ingests not referenced by packets. This is a broader custody-control change than the new packet rows alone.

Trust Boundaries and Controls

  • observed — Supplied project, lease and membership identifiers cross into authoritative database custody only after lease/queue checks and canonical lineage reconciliation. Upload receipts, content identity, storage namespace, complete guide membership and the reconstructed semantic digest are checked before commit.

Resilience and Maintainability Implications

  • observed — Head source uses clock_timestamp for creation-time deadline enforcement, avoiding a stale transaction-start clock. The expiry test deliberately begins before expiry and attempts creation afterward; the parent-rollback test checks that failed concurrent insertion leaves no retained packet rows and does not poison subsequent creation.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 16.67% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 60 functions across 24 files. (3 skipped:… Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title clearly and concisely identifies the primary change: immutable review-packet persistence for REV-03B.
Description check ✅ Passed The description is detailed and covers the change, goal, planning context, implementation, scope, behavior, evidence, acceptance proof, tests, risks, and review status. Some optional template headings…
Full details: Docstring Coverage

Explanation

Docstring coverage is 16.67% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 60 functions across 24 files. (3 skipped: 3 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@Abiorh001
Abiorh001 marked this pull request as ready for review October 2, 2026 02:58
@abiorh-claw
abiorh-claw self-requested a review October 2, 2026 08:46
@abiorh-claw
abiorh-claw merged commit fcff997 into main Oct 2, 2026
16 checks passed
@abiorh-claw
abiorh-claw deleted the codex/rev03b-packet-persistence branch October 2, 2026 08:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants