Skip to content
Merged
4 changes: 2 additions & 2 deletions .commitrail/INDEX.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,13 +9,13 @@ for current product capability.
| [WS-DB-002](initiatives/WS-DB-002/OVERVIEW.md) | Complete | Shared UUIDv7 record generation, native-UUID relationships and fresh v0.1 baseline; natural-owner retry custody and aligned CI/local setup |
| [WS-MCP-002](initiatives/WS-MCP-002/OVERVIEW.md) | Planned | Nine tools through WS-MCP-002-03: self-service and administrative reads; 18 tools remain and WS-MCP-002-04 administrative grant mutations are next |
| [WS-CLI-001](initiatives/WS-CLI-001/OVERVIEW.md) | Planned | Public Go CLI self-service, project inspection, manager browsing, contributor discovery, claim/start and governing context/intake requirements delivered through WS-CLI-001-07; hidden submission is not exposed, further public journeys and binary distribution remain |
| [WS-ARCH-001](initiatives/WS-ARCH-001/OVERVIEW.md) | Planned | Source storage, inert AUTH contracts, TASK request reservation, hidden exact AUTH preparation and the REV-04C hidden FinalAcceptance/TASK/CON participant are delivered; TASK-before-CHECKERS reservation/current-read custody and ordered admission INSERTs are delivered by 04E1B-B1; 04E1B-B2 adds exact source preparation without publication; 04E1B-B3 retains inspected ZIP metadata for consumption; initial Submission/dispatch composition is next, followed by remaining hidden routing handlers. True admission remains independent of shared acceptance; false activation still requires exact AUTH receipt custody, database complete-set enforcement, currentness race proof and atomic routing activation. |
| [WS-ARCH-001](initiatives/WS-ARCH-001/OVERVIEW.md) | Planned | Source storage, inert AUTH contracts, TASK request reservation, hidden exact AUTH preparation and the REV-04C hidden FinalAcceptance/TASK/CON participant are delivered; TASK-before-CHECKERS reservation/current-read custody and ordered admission INSERTs are delivered by 04E1B-B1; 04E1B-B2 adds exact source preparation without publication; 04E1B-B3 retains inspected ZIP metadata and B4 binds Submission text to checked packet custody; initial Submission/dispatch composition is next under the [first-layer sequence](initiatives/WS-ARCH-001/planning/PLAN.md#first-complete-contributor-milestone), ending in a public contributor drill before live human review/revision. True admission remains independent of shared acceptance; false activation still requires exact AUTH receipt custody, database complete-set enforcement, currentness race proof and atomic routing activation. |
| [WS-ART-001](initiatives/WS-ART-001/OVERVIEW.md) | Planned | Exact checker input/output custody and packet foundations are delivered; routing integration, remediation and public intake remain. |
| [WS-AUTH-001](initiatives/WS-AUTH-001/OVERVIEW.md) | Planned | AUTH-19A commitments, TASK request reservation, ARCH-04E2-A hidden strict PREP matching and the REV-04C hidden FinalAcceptance/TASK/CON participant are delivered; the action remains unavailable, with mandatory exact AUTH receipt input, database closure, audit/outbox and scoped activation still required for the automated path. |
| [WS-CON-001](initiatives/WS-CON-001/OVERVIEW.md) | Planned | Contribution/award storage, CON-07 participation and REV-04C hidden FinalAcceptance/TASK/CON composition are delivered; production consumption still requires genuine authority, database complete-set enforcement, currentness race proof, shared audit/outbox, fulfillment-root ordinals and lifecycle activation. |
| [WS-AUTH-003](initiatives/WS-AUTH-003/OVERVIEW.md) | Planned | Canonical source facts and disabled lifecycle fencing are delivered; exact lifecycle activation remains tied to the governed consequence. |
| [WS-POL-003](initiatives/WS-POL-003/OVERVIEW.md) | Planned | Locked policy configuration, inert source commitments and the REV-04C hidden false/pass acceptance participant are delivered; false-policy activation remains gated by exact AUTH receipt custody, database closure, currentness proof, remediation and scoped lifecycle authority. |
| [WS-REV-001](initiatives/WS-REV-001/OVERVIEW.md) | Planned | Packet and Review storage plus REV-04C hidden source-neutral FinalAcceptance/TASK/CON composition are delivered; hidden routing handlers are next, while authority/evidence closure and human review/revision remain separately gated. |
| [WS-REV-001](initiatives/WS-REV-001/OVERVIEW.md) | Planned | Packet and Review storage plus REV-04C hidden source-neutral FinalAcceptance/TASK/CON composition are delivered; capacity alignment and atomic initial Submission/dispatch precede hidden routing handlers, while authority/evidence closure and human review/revision remain separately gated. |
| [WS-QUAL-002](initiatives/WS-QUAL-002/OVERVIEW.md) | Planned | Populate subsystem ownership before changed-line mutation work |
| [WS-QUAL-003](initiatives/WS-QUAL-003/OVERVIEW.md) | Planned | Audit and prune test proof, add missing safety cases, decompose oversized test modules |
| [WS-XINT-002](initiatives/WS-XINT-002/OVERVIEW.md) | Planned | Remaining ART/AUTH activation edges only |
Expand Down
20 changes: 14 additions & 6 deletions .commitrail/initiatives/WS-ARCH-001/OVERVIEW.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,9 @@
# WS-ARCH-001 — Modular monolith boundaries

Delivery priority: [first complete contributor milestone](planning/PLAN.md#first-complete-contributor-milestone). Use its nine-step order and end-to-end exit proof when selecting the next bounded change; live human review/revision and external integration are later work.

[ARCH-04E1B-B4](WS-ARCH-001-04E1BB4.md) binds Submission summary and attestation to the packet retained by intake, including database custody. Initial dispatch remains next and must reconcile capacity, exact receipts and fresh-authorized replay before connecting workers.

[ARCH-04E1B-B3](WS-ARCH-001-04E1BB3.md) retains the inspected ZIP manifest in immutable ART evidence and returns verified file metadata on admission consumption. Initial Submission/dispatch composition is next; it must reconcile existing ART/CHECKERS size limits and retain exact creation/binding receipts. No dispatch or routing authority is activated.

[ARCH-04E1B-B2](WS-ARCH-001-04E1BB2.md) supplies exact source preparation through
Expand Down Expand Up @@ -66,11 +70,14 @@ Exact pre-cutover work record: [`STATUS.md`](pre-cutover/STATUS.md),
[REV-04A](../WS-REV-001/WS-REV-001-04A.md) adds complete immutable Review, findings, resolutions and completed request storage; no decision runtime.
[REV-04B](../WS-REV-001/WS-REV-001-04B.md) adds shared FinalAcceptance source
storage, without AUTH receipt custody or a production writer.
- Next usable boundary: ARCH-04E1B-B hidden handlers using the delivered
REV-04C participant, then mandatory exact AUTH receipt input, database closure,
audit/outbox, TASK-before-CHECKERS currentness race proof and activation at
ARCH-04E2-B before 04E3 and ARCH-04F. Output-file
authority remains unavailable for the zero-output catalogue.
- Next usable boundary: capacity alignment and atomic initial Submission/dispatch,
then the remaining hidden 04E1B-B handlers. ARCH-04E2-B proves genuine authority
with exact receipt/database/effect closure under a valid scoped controller
generation for false. Prove ARCH-04F remediation before production false-policy
enablement and ARCH-04E3 live composition. True handoff remains independent of
CON/shared acceptance. Public intake and the first-layer drill follow the
[governing sequence](planning/PLAN.md#first-complete-contributor-milestone).
Output-file authority remains unavailable for the zero-output catalogue.
[AUTH-18](../WS-AUTH-001/WS-AUTH-001-18.md) delivers public manager activation
context and exact guide activation using the existing CP07 operation.
[CP05A](WS-ARCH-001-CP05A.md) supplies public Finance policy administration and recoverable draft selectors.
Expand Down Expand Up @@ -110,7 +117,8 @@ acceptance later uses the same authorized shared acceptance/CON operation.
ARCH-04E1B-B1 delivers TASK-before-CHECKERS reservation/current-read custody
and ordered review admission INSERTs, including intermediate admission waits,
terminal read-only replay and both mechanical race controls. The
remaining 04E1B-B handler work and full authorized currentness proof stay next;
next steps are capacity alignment and atomic initial Submission/dispatch, then
remaining 04E1B-B handlers and full authorized currentness proof;
no handler or action is activated by this prerequisite.

## Delivered and remaining
Expand Down
104 changes: 104 additions & 0 deletions .commitrail/initiatives/WS-ARCH-001/WS-ARCH-001-04E1BB4.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,104 @@
# ARCH-04E1B-B4 — Bind Submission text to its checked packet

- Initiative: `WS-ARCH-001`
- Durable disposition: `Complete`
- Intended merge outcome: admission consumption and persisted Submission text must match the exact packet retained by pre-submission checking.

## Intent

Initial dispatch must use exactly the input that passed preparation. Plan review
found that TASK forwards no packet commitment to ART consumption: prepared summary
and attestation A can be replaced with B when creating a Submission. The existing
pre-submit evidence already stores their canonical packet hash. Enforce that
existing commitment before building dispatch on this boundary.

## Bounded change

- Forward the canonical hash of the actual creation request's summary and
contributor attestation through existing TASK and ART consumption requests.
Share the existing packet hash construction; no second packet format.
- ART compares it with locked immutable pre-submit evidence before consumed
replay or new binding/consumption. Mismatch gives the existing concealed
unavailable error and no mutation or final binding authorization.
- A deferred PostgreSQL guard reads the final Submission row and compares its
summary/worker_attestation with its admission's retained evidence packet hash.
Support existing insert-unbound then bind in the same transaction. Once bound,
retain the existing guard against clearing or replacing the admission/binding/content triple. Reuse the
existing canonical SQL JSON function and qualify every protected reference with
a pinned safe search_path. Existing upstream hash/link immutability remains.
- Preserve retained data unchanged at upgrade. Unbound stored rows gain no
admission or dispatch eligibility. Newly bound/changed rows must satisfy the
guard; no optional current path, fabricated hash, compatibility API or backfill.

## Allowed files

TASK submission command contract/composition and adapters/tasks; ART consumption
contract/service, packet hashing caller and directly affected exports; CHECKERS public packet value helper; one migration after 0021, test_alembic and schema
fingerprint; focused binding/composition and real PostgreSQL submission tests plus
their affected canonical fixtures; exact lane/ownership registration; this record,
parent 04E contract and affected ARCH/AUTH/POL/CON/REV current navigation, README,
TASK/ART specifications and roadmap. The user's explicit delivery-priority
instruction also reconciles the existing first-layer sequence, roadmap/navigation,
04F dependencies and the existing AGENTS.md v0.1 rule in this same PR: focus
on the first complete public backend contributor path and defer unrelated work.

## Prohibited changes

No dispatch reservation/event/handler, capacity-limit changes, new receipt store,
AUTH replay activation, routing/acceptance/review effects, public route, claim
expiry, provider read, retained data rewrite/delete, compatibility path, weakened
CI or skipped tests. Preserve unrelated CLI work.

## Acceptance criteria

1. Exact prepared packet creates a Submission through real hidden TASK/ART/AUTH.
Changing only summary or only attestation rejects and rolls back Submission,
admission consumption, binding and staged AUTH evidence. No provider reread.
2. Exact ART consumption replay remains valid; a changed packet digest on a
consumed admission rejects before binding authorization or mutation.
3. PostgreSQL permits valid insert-unbound/update-bind in one transaction; rejects
changed packet fields, wrong packet on first binding and clearing/substituting
bound lineage. Verify persisted state after rollback. Existing upstream
evidence-hash/admission-link immutability tests remain valid.
4. Upgrade preserves existing rows unchanged. Canonical hash parity includes
quotes, backslashes and supported packet text. Tests target each independent
field; remove the service/SQL predicate and prove the intended assertions fail.
5. Run focused pure/PostgreSQL tests, Ruff, boundaries, lane/ownership inventory,
stale wording/link/Commitrail checks and full hosted completeness. Coverage is
diagnostic. Tests protect outcomes; no mirrored implementation-only cases.

## Risk and review routing

L1. Architecture/security/reuse and QA/test-delta plan review before code.
Implementation reviews additionally include CI-integrity and docs/product ops.
Human focus: exact pre-check-to-Submission input custody, rejection before effects,
immutable bound lineage, caller rollback, retained-data preservation.

## Next dependency

Initial Submission/dispatch remains next after capacity and replay reconciliation.
Discovery established three explicit obligations for that transaction: retain
exact creation/binding AUTH receipts; validate the same bounded checker request
before ready admission and at dispatch; resolve same-admission replay under fresh
AUTH after TASK reaches evaluation_pending without replacing original identities.
The current creation-context validator intentionally permits only in_progress or
needs_revision, so broadening it is not a replay design. Both true review admission
and false shared acceptance remain in the parent plan. Worker activation,
remediation and public intake follow; contributor claim expiry remains deferred.

## Plan review outcome

Architecture/security and QA found the original atomic dispatch proposal too early:
packet substitution is currently possible, creation replay rejects post-creation
TASK state, and ready ZIP capacities exceed CHECKERS inputs. This chunk repairs
only the first concrete boundary. Both plan reviews found it feasible. Reuse
`protect_submission_contribution_stamp` for once-bound identity and existing ART
immutable evidence/admission guards; do not duplicate them. The real test keeps
preparation artifacts/evidence intact while proving creation-side rollback.

## Evidence

Use the focused binding/composition suite and isolated PostgreSQL lineage and
upgrade tests, plus the shared checks listed above. Verify the service and
database predicates independently with guard-removal probes. Exact heads and
transient run results belong in the PR, not this record.
Loading
Loading