Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 5 additions & 1 deletion .ci/behavior-ownership/partition.v1.json
Original file line number Diff line number Diff line change
Expand Up @@ -1496,6 +1496,10 @@
"group": "lifecycle",
"target": "backend/app/modules/tasks/post_submit_routing/requests.py"
},
{
"group": "lifecycle",
"target": "backend/app/modules/tasks/post_submit_routing/source.py"
},
{
"group": "lifecycle",
"target": "backend/app/modules/tasks/queue_router.py"
Expand Down Expand Up @@ -1665,7 +1669,7 @@
"target": "backend/scripts/validate_test_lane_evidence.py"
}
],
"authority_digest": "97f3bee29efd7d0d2214bf11cf1406172feb9375ab157287dc487163a1dfacd2",
"authority_digest": "95fa9e2fa5e30557c54a51940b41141a4ebc67f083345ff66fc359d854525070",
"protected_base_commit": "7676ce4347db0c9694962a9b587a20765e16eac6",
"schema": "workstream.behavior-ownership-partition.v1"
}
2 changes: 1 addition & 1 deletion .commitrail/INDEX.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@ for current product capability.
| [WS-DB-002](initiatives/WS-DB-002/OVERVIEW.md) | Complete | Shared UUIDv7 record generation, native-UUID relationships and fresh v0.1 baseline; natural-owner retry custody and aligned CI/local setup |
| [WS-MCP-002](initiatives/WS-MCP-002/OVERVIEW.md) | Planned | Nine tools through WS-MCP-002-03: self-service and administrative reads; 18 tools remain and WS-MCP-002-04 administrative grant mutations are next |
| [WS-CLI-001](initiatives/WS-CLI-001/OVERVIEW.md) | Planned | Public Go CLI self-service, project inspection, manager browsing and contributor discovery delivered through WS-CLI-001-05; further public journeys and binary distribution remain |
| [WS-ARCH-001](initiatives/WS-ARCH-001/OVERVIEW.md) | Planned | Source storage, inert AUTH contracts, TASK request reservation, hidden exact AUTH preparation and the REV-04C hidden FinalAcceptance/TASK/CON participant are delivered; TASK-before-CHECKERS reservation/current-read custody and ordered admission INSERTs are delivered by 04E1B-B1; hidden routing handlers are next. True admission remains independent of shared acceptance; false activation still requires exact AUTH receipt custody, database complete-set enforcement, currentness race proof and atomic routing activation. |
| [WS-ARCH-001](initiatives/WS-ARCH-001/OVERVIEW.md) | Planned | Source storage, inert AUTH contracts, TASK request reservation, hidden exact AUTH preparation and the REV-04C hidden FinalAcceptance/TASK/CON participant are delivered; TASK-before-CHECKERS reservation/current-read custody and ordered admission INSERTs are delivered by 04E1B-B1; 04E1B-B2 adds exact source preparation without publication; remaining hidden routing handlers are next. True admission remains independent of shared acceptance; false activation still requires exact AUTH receipt custody, database complete-set enforcement, currentness race proof and atomic routing activation. |
| [WS-ART-001](initiatives/WS-ART-001/OVERVIEW.md) | Planned | Exact checker input/output custody and packet foundations are delivered; routing integration, remediation and public intake remain. |
| [WS-AUTH-001](initiatives/WS-AUTH-001/OVERVIEW.md) | Planned | AUTH-19A commitments, TASK request reservation, ARCH-04E2-A hidden strict PREP matching and the REV-04C hidden FinalAcceptance/TASK/CON participant are delivered; the action remains unavailable, with mandatory exact AUTH receipt input, database closure, audit/outbox and scoped activation still required for the automated path. |
| [WS-CON-001](initiatives/WS-CON-001/OVERVIEW.md) | Planned | Contribution/award storage, CON-07 participation and REV-04C hidden FinalAcceptance/TASK/CON composition are delivered; production consumption still requires genuine authority, database complete-set enforcement, currentness race proof, shared audit/outbox, fulfillment-root ordinals and lifecycle activation. |
Expand Down
8 changes: 8 additions & 0 deletions .commitrail/initiatives/WS-ARCH-001/OVERVIEW.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,13 @@
# WS-ARCH-001 — Modular monolith boundaries

[ARCH-04E1B-B2](WS-ARCH-001-04E1BB2.md) supplies exact source preparation through
TASK, CHECKERS and historical PROJECTS policy facts. It stages only the existing
routing request; proposed source facts have no fabricated creation timestamp.
Remaining handlers, source publication, current pointers and authority/effect
activation are still required. False composition must acquire its REV lifecycle
fence before TASK and revalidate policy under TASK custody; true admission
remains independent of that fence.

[AUTH-19A](../WS-AUTH-001/WS-AUTH-001-19A.md) delivers inert exact source/receipt contracts and the
planned router identity. ARCH-04E1B-A delivers caller-owned routing-request and
future source-identity reservation. ARCH-04E2-A now delivers strict hidden
Expand Down
125 changes: 125 additions & 0 deletions .commitrail/initiatives/WS-ARCH-001/WS-ARCH-001-04E1BB2.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,125 @@
# ARCH-04E1B-B2 — Exact routing source preparation

- Initiative: `WS-ARCH-001`
- Durable disposition: `Complete`
- Intended merge outcome: hidden TASK source preparation joins the existing reserved routing identity to exact current CHECKERS material and historical PROJECTS policy, without publishing a source or applying effects.

## Intent

Prepare exact, owner-verified facts for the governed post-submit route.

## Current behavior

After 04E1B-B1, reservation and current reads retain TASK-before-CHECKERS custody.
`TaskRoutingRequests.stage` reserves a future manifest identity but receives only
an integer from `require_current_completion`. TASK cannot assemble its source
without reaching into CHECKERS/PROJECTS private tables. The existing PROJECTS
locked-policy port already resolves historical policy bodies and activation
custody. Reuse it; extend the existing CHECKERS completion projection.

This is the next bounded part of 04E1B-B, not completion of its handlers.

## Bounded change

### Allowed

Allowed files: CHECKERS `api/execution.py`, `execution_coordination.py`;
TASK `api/post_submit_routing.py`, `api/__init__.py`,
`post_submit_routing/requests.py`, `post_submit_routing/source.py`;
`adapters/tasks/__init__.py`; directly affected TASK/CHECKERS contract and
PostgreSQL tests, their existing fixture helpers, lane/ownership registrations;
this record, current ARCH overview/plan/chunk map/parent 04E contract, INDEX,
README, roadmap and canonical checker/TASK specifications where claims change.

### Not allowed

Prohibited: migrations, AUTH action activation or synthetic allows, new source
storage or INSERT, routing pointers/status changes, REV/CON effects, outbox
registration/publication, live workers/routes, guide activation changes,
compatibility aliases, retained-data deletion or weakened tests/checks.

## Design and decisions

1. Replace the version-only completion return with closed detached verified
completion facts; update all affected callers. CHECKERS retains the same
currentness/phase-receipt/material checks and root transaction requirement.
2. TASK prepares semantic source facts without a fabricated creation timestamp.
The existing persisted manifest facts retain their mandatory database time
and share the same semantic fields. This distinguishes a proposal from a
stored record, not parallel implementations.
3. In the caller root transaction, lock exact TASK/Assignment/Submission scope,
resolve the historical PROJECTS context before acquiring CHECKERS custody,
reserve/recover the existing route identity and construct the exact proposal.
Compare complete activation and Submission lineage, including review boolean,
contribution-policy identity and material facts. No current project policy
can replace locked policy. Return detached facts, never ORM rows.
4. Exact replay reuses the existing reservation. Caller rollback removes newly
staged requests; preparation never commits or creates another owner effect.

The future false handler must acquire the joint REV lifecycle fence before
TASK, then revalidate the policy under TASK custody. It must not call shared
acceptance for the first time after holding TASK/CHECKERS. True admission stays
independent of the shared acceptance fence. Full handler/receipt/publication
composition remains separately required by 04E1B-B/04E2-B/04E3.

## Acceptance criteria

- Real PostgreSQL completed-source fixture returns the exact reserved identity,
Submission/predecessor/contributor, locked policies, checker references/phase
receipts and canonical ART material, with no private storage coordinates.
- Same request replays identically; root rollback removes new reservations.
- Foreign valid source substitutions, stale generation and changed lineage deny;
no source, status, REV/CON, audit or outbox effects are introduced.
- Independent sessions prove preparation retains TASK custody and a successor
that wins first makes the old completion unavailable.
- Managed/raw savepoints remain rejected through the existing root guard.
- False policy remains pure value-contract proof only: guide activation and
genuine false runtime authority remain unavailable. No fake allow or guide
activation is evidence for this chunk. The current hidden intake leaves TASK
in_progress; focused tests explicitly seed the future dispatch-owned
evaluation_pending precondition and separately prove earlier-state denial.
The ART fixture also seeds assignments directly; these tests explicitly set
its missing accepted_at claim precondition after proving that absence denies.
They do not claim authorized claim or initial dispatch proof.

## Risk and review routing

Risk: L1. Required focused architecture/reuse, security, QA/test-delta,
CI integrity and documentation review. Human focus: historical policy versus
current policy; currentness lock lifetime; proposal versus persisted source;
no premature runtime/authority claim. The plan review identified absent REV
admission and initial dispatch composition plus the false-handler fence order;
this bounded preparation does not fabricate those dependencies.

## Evidence

Run affected pure contracts, real PostgreSQL source preparation/currentness,
module boundaries, Ruff, lane inventory, stale wording, links and Commitrail;
then full hosted CI and exact-head internal review. The four new PostgreSQL preparation cases passed, including exact full-value
comparison, replay/rollback, historical guide preservation, mixed valid source
rejection and retained locks followed by stale-generation rejection. Expanded
root-transaction and cross-project probes and full hosted evidence are tracked
in the PR.
## Reconciliation

Main reconciled at `31ac857b`; #476 supplies lock repair.
No local spreadsheet export has yet been assumed present.

Next usable boundary: remaining hidden request/completion handlers, mandatory
AUTH receipt/database/audit/outbox closure, then live composition and remediation.


## Review findings

The final ownership inventory admits only the new source module and rejects
an adjacent activation module. No migration or database schema changed. Local
spreadsheet exports are absent. Plan review retained evaluation_pending and
accepted-assignment guards; older ART-only fixture setup is explicitly arranged
in these new mechanical tests rather than relaxing the production requirements.

Review corrections: isolate the task-state denial from the missing claim timestamp,
prepare a fully eligible sibling before selector substitution, and prove version-2
predecessor lookup through a genuinely admitted and evaluated successor ZIP.
The independent-session lock probes establish retained custody; shared B1 race
cases cover the overlapping admission/currentness sequence. Reconcile B2 in the
roadmap trace links and current ARCH dependency tables, not only their summaries.
10 changes: 9 additions & 1 deletion .commitrail/initiatives/WS-ARCH-001/planning/CHUNK_MAP.md
Original file line number Diff line number Diff line change
@@ -1,4 +1,12 @@
# WS-ARCH-001 — Current remaining change map
[ARCH-04E1B-B2](../WS-ARCH-001-04E1BB2.md) supplies exact source preparation through
TASK, CHECKERS and historical PROJECTS policy facts. It stages only the existing
routing request; proposed source facts have no fabricated creation timestamp.
Remaining handlers, source publication, current pointers and authority/effect
activation are still required. False composition must acquire its REV lifecycle
fence before TASK and revalidate policy under TASK custody; true admission
remains independent of that fence.


[AUTH-19A](../../WS-AUTH-001/WS-AUTH-001-19A.md) delivers inert exact source/receipt contracts and the
planned router identity. ARCH-04E1B-A delivers caller-owned routing-request and
Expand Down Expand Up @@ -60,7 +68,7 @@ currentness proof stay within 04E1B-B, before activation and live composition.
| [WS-ARCH-001-04D1](../WS-ARCH-001-04D1.md) | Canonical terminal ART material custody | L1 | Complete; valid retained history preserved; invalid upgrades refused |
| [WS-ARCH-001-04D2](../WS-ARCH-001-04D2.md) | AUTH exact fixed-service post-submit activation (replaces XINT-06B) | L1 | Complete: exact input, execute and finalize authority; output write/bind remains unavailable |
| [WS-ARCH-001-04E1A](../WS-ARCH-001-04E1A.md) | Route-neutral immutable source schema and shared accepted-effects types | L1 | Complete; REV-04C uses a bounded exact-source verifier, with no general routing publication writer/reader, routing authority or current pointer; its hidden effects participant does not make false routing available |
| [WS-ARCH-001-04E](chunks/WS-ARCH-001-04E-canonical-allow-review.md) | TASK current routing: true to canonical `allow_review`, false/pass to shared acceptance | L1 | Both branches: delivered 04E1A/04D2/OUTBOX-02, request reservation 04E1B-A and AUTH preparation 04E2-A -> hidden handlers/currentness proof 04E1B-B -> authority/evidence closure and activation 04E2-B -> live 04E3. False uses delivered REV-04C participation and additionally needs mandatory exact receipt/database/audit closure, fulfillment-root ordinal custody and scoped lifecycle activation; true does not depend on CON. False guide activation also requires 04F remediation |
| [WS-ARCH-001-04E](chunks/WS-ARCH-001-04E-canonical-allow-review.md) | TASK current routing: true to canonical `allow_review`, false/pass to shared acceptance | L1 | Both branches: delivered 04E1A/04D2/OUTBOX-02, request reservation 04E1B-A and AUTH preparation 04E2-A; exact source preparation [04E1B-B2](../WS-ARCH-001-04E1BB2.md) -> remaining handlers/currentness proof 04E1B-B -> authority/evidence closure and activation 04E2-B -> live 04E3. False uses delivered REV-04C participation and additionally needs mandatory exact receipt/database/audit closure, fulfillment-root ordinal custody and scoped lifecycle activation; true does not depend on CON. False guide activation also requires 04F remediation |
| [WS-ARCH-001-03D](../WS-ARCH-001-03D.md) | Exact activated historical guide through hidden durable intake; obsolete lookup removed | L1 | Complete; hidden exact post-submit materialization, ARCH-04B2 output custody, ARCH-04C execution, ARCH-04D1/04D2 custody/authority and ARCH-04E1A source-only facts/types delivered; public cutover remains deferred |
| [WS-ARCH-001-04F](chunks/WS-ARCH-001-04F-checker-remediation.md) | Contributor-correctable checker failures and same-lineage admission-backed replacement Submission | L1 | Planned after 04E; replaces XINT-05C, required before public 02I, not before REV begins from `allow_review` |

Expand Down
9 changes: 9 additions & 0 deletions .commitrail/initiatives/WS-ARCH-001/planning/PLAN.md
Original file line number Diff line number Diff line change
@@ -1,4 +1,12 @@
# WS-ARCH-001 — Current delivery plan through allow_review
[ARCH-04E1B-B2](../WS-ARCH-001-04E1BB2.md) supplies exact source preparation through
TASK, CHECKERS and historical PROJECTS policy facts. It stages only the existing
routing request; proposed source facts have no fabricated creation timestamp.
Remaining handlers, source publication, current pointers and authority/effect
activation are still required. False composition must acquire its REV lifecycle
fence before TASK and revalidate policy under TASK custody; true admission
remains independent of that fence.


[AUTH-19A](../../WS-AUTH-001/WS-AUTH-001-19A.md) delivers inert exact source/receipt contracts and the
planned router identity. ARCH-04E1B-A delivers caller-owned routing-request and
Expand Down Expand Up @@ -82,6 +90,7 @@ checker-remediation boundary before public Submission cutover.
| ARCH-04E1B-A | ARCH-04E1A, AUTH-19A | Complete: TASK caller-session request/source-identity reservation; no source publication, handler or commit |
| [ARCH-04E2-A](../WS-ARCH-001-04E2A.md) | ARCH-04E1B-A | Complete: strict AUTH-private resource/request/consequence matcher and nominal fixed-router adapter through canonical PREP; action stays planned/unavailable, with no handle, allow, receipt, source write or effect |
| [ARCH-04E1B-B1](../WS-ARCH-001-04E1BB1.md) | REV-04C and existing CHECKERS coordinator | Complete: required TASK reservation/current-read guard, ordered admission INSERTs, exact terminal replay and mechanical race proof; no handler or activation |
| [ARCH-04E1B-B2](../WS-ARCH-001-04E1BB2.md) | 04E1B-B1, existing historical PROJECTS context | Complete: exact detached source preparation and reserved identity; no publication, authority or handler effect |
| ARCH-04E1B-B | ARCH-04E2-A and CON-02B; false additionally uses delivered REV-04C shared acceptance participation | Hidden TASK handlers plus TASK-before-CHECKERS currentness and both successor-generation race orders; durable receipt proof follows at exact activation |
| Scoped XINT-003-08B controller activation | Existing REV-12A foundation, delivered REV-04C hidden participant and remaining real-writer observation proof | Existing Operator lifecycle-control action for the bounded shared manifest, not human runtime |
| ARCH-04E2-B | ARCH-04E1B-B; scoped XINT-003-08B controller activation for false | Require the exact AUTH receipt on the same strict input; add database complete-set and audit/outbox closure; genuine allow commits with all governed effects |
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -106,7 +106,12 @@ creating human admission, acceptance or contribution effects.
[04E1B-B1](../../WS-ARCH-001-04E1BB1.md) installs mandatory TASK-before-CHECKERS
reservation custody and exact terminal replay. Mechanical race proof covers
acceptance-first reservation rejection and successor-first stale completion
rejection; the full authorized handler races remain required. After 04E1B-A/04E2-A and
rejection. [04E1B-B2](../../WS-ARCH-001-04E1BB2.md) supplies exact
semantic source preparation from current CHECKERS and historical PROJECTS
custody, without source publication or authority. The full authorized
handler races remain required. False composition must take the REV lifecycle
fence before TASK and revalidate the policy after locking; source preparation
does not acquire that fence or authorize later lock-order inversion. After 04E1B-A/04E2-A and
CON-02B's handler/claim contract (plus delivered REV-04C acceptance foundations
for false), TASK implements unavailable request/event
production for its own evaluation-request event and the TASK consumer of
Expand Down
4 changes: 3 additions & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -186,7 +186,9 @@ no exact AUTH decision-event receipt, and database complete-set enforcement,
currentness race proof, shared audit/outbox and lifecycle activation remain.
ARCH-04E1B-B1 requires TASK locking before checker reservation, current-result
reads and review admission INSERTs, preserving exact read-only reservation replay
after acceptance. Hidden handlers still need complete
after acceptance. ARCH-04E1B-B2 prepares exact source proposals from current
CHECKERS custody and historical PROJECTS policy, without inserting a manifest
or granting authority. Hidden handlers still need complete
authorized currentness proof. These prerequisites do not require live
human review before the first automated acceptance path.

Expand Down
12 changes: 12 additions & 0 deletions backend/app/adapters/tasks/__init__.py
Original file line number Diff line number Diff line change
Expand Up @@ -188,3 +188,15 @@ def submitted_bundle_port(session: AsyncSession) -> SubmittedBundlePort:
"""Compose the exact immutable Submission read without private owner imports in ART."""
from app.modules.tasks.submitted_bundle import SubmittedBundleReader
return SubmittedBundleReader(session)


def routing_source_preparer(session):
"""Compose exact hidden source preparation through existing owner ports."""
from app.adapters.checkers import evaluation_coordinator
from app.adapters.projects import project_locked_policy_context_port
from app.modules.tasks.post_submit_routing.source import TaskRoutingSourcePreparer

return TaskRoutingSourcePreparer(
session, evaluations=evaluation_coordinator(session),
projects=project_locked_policy_context_port(session),
)
Loading
Loading