Skip to content

feat(reviews): authorize scoped first-contribution lifecycle control - #516

Open
Abiorh001 wants to merge 11 commits into
mainfrom
codex/arch04e-completion-delivery
Open

Abiorh001 wants to merge 11 commits into
mainfrom
codex/arch04e-completion-delivery

Conversation

@Abiorh001

@Abiorh001 Abiorh001 commented Oct 8, 2026 •

Copy link
Copy Markdown
Collaborator

Outcome

The first contribution path needs an authorized lifecycle generation without requiring payment-delivery machinery. This extends the existing REV controller and Operator action with exact phase transitions, immutable history and AUTH custody. New REV/TASK/CON participant effects require LIVE at the current generation; unchanged terminal replay remains read-only after shutdown. Conditional awards remain atomic with contributions.

Payment delivery and obligation/root/cutoff machinery stay deferred until fulfillment is enabled. This PR does not activate production routing, acceptance source authority, human review or a public controller endpoint. The initial manifest refuses retained pre-authority FinalAcceptance facts before LIVE; exact source receipts and complete authorized outcomes remain the next integration boundary.

Scope and safety

  • One existing singleton, fence and AUTH action; no compatibility path or separate lifecycle controller.
  • Controller/history/exact AUTH evidence commit together; PostgreSQL rejects missing, substituted or rewritten custody.
  • Lifecycle-only actor NO KEY UPDATE avoids a foreign-key deadlock with a prior acceptance writer while preserving revocation serialization.
  • Existing participant tests now obtain LIVE through real Operator authority. Caller transactions, paid/unpaid outcomes and immutable retained data remain required.
  • Current roadmap, initiative navigation and canonical lifecycle/compensation specifications reflect the selected fulfillment deferral. Main's pilot and CLI guide-upload updates are preserved.

Record: .commitrail/initiatives/WS-REV-001/WS-REV-001-12A4A.md.

Verification

Candidate: cf28cfc7ece4faaad1f189d7bd38939419de2a27, based on 3b9fbf64e01ec8d7311687785760836c3c0aa3cc. Hosted merge e96fd6275217a5bac0654f41696eab6335069d65 has the identical tree a91e820e39f089324fe17283b190714a64d1ac30.

  • Fresh full Backend run: all nine lanes and aggregate pass. Downloaded evidence independently confirms 8,836 unique completed tests, exact collected/completed equality, zero skips/deselections, and matching evidence hashes. Database/MinIO cleanup is confirmed.
  • Exact-head focused PostgreSQL batch: 33 passed. Ten deliberate guard regressions fail at their intended assertions, including a real actor/fence deadlock. All isolated runs confirm cleanup.
  • Repository gates, module boundaries, structural checks, documentation checks, CLI and MCP API contracts pass.
  • Internal architecture, reuse, security, documentation, product-operations, QA and test-delta reviews pass. CI-integrity review passes with the nonblocking timing risk below. All required internal review sessions are complete.
  • Earlier full-run failures were repaired: the audit allow-action inventory now names the exact active action, and the lifecycle-participant module runs beside related acceptance proofs in the project partitions. Repeated stopped-phase setup was consolidated while retaining fresh transactions and unchanged-effect assertions for all three phases. No caps, partition hashing, inventory equality, skips or failure propagation were relaxed.
  • Timing limitation: Task A finished in 1,191.85 seconds against the unchanged 1,200-second limit, leaving only 8.15 seconds of headroom. The diagnostic timing target remains unmet.
  • CodeRabbit is rate-limited, not a substantive review. No unresolved GitHub review threads. No new live-provider result is claimed for this controller work.

Human review focus: exact Operator authority and immutable receipt closure, both writer/transition lock orders, stopped replay without new effects, and preservation of conditional award facts while fulfillment remains disabled. Merge remains a human decision after updated checks and reviews.

@coderabbitai

coderabbitai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 24 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 14e9146d-b19d-4f2f-8dc5-afd7b851f32e
📥 Commits

Reviewing files that changed from the base of the PR and between 3b9fbf6 and cf28cfc.

📒 Files selected for processing (85)
  • .ci/auth-boundaries/TEST_STRUCTURE_DEBT.json
  • .ci/behavior-ownership/partition.v1.json
  • .commitrail/INDEX.md
  • .commitrail/initiatives/WS-ARCH-001/OVERVIEW.md
  • .commitrail/initiatives/WS-ARCH-001/planning/CHUNK_MAP.md
  • .commitrail/initiatives/WS-ARCH-001/planning/PLAN.md
  • .commitrail/initiatives/WS-AUTH-001/OVERVIEW.md
  • .commitrail/initiatives/WS-AUTH-001/planning/CHUNK_MAP.md
  • .commitrail/initiatives/WS-AUTH-001/planning/PLAN.md
  • .commitrail/initiatives/WS-CON-001/OVERVIEW.md
  • .commitrail/initiatives/WS-POL-003/OVERVIEW.md
  • .commitrail/initiatives/WS-POL-003/planning/CHUNK_MAP.md
  • .commitrail/initiatives/WS-POL-003/planning/PLAN.md
  • .commitrail/initiatives/WS-REV-001/OVERVIEW.md
  • .commitrail/initiatives/WS-REV-001/WS-REV-001-12A4A.md
  • README.md
  • backend/alembic/env.py
  • backend/alembic/versions/0027_lifecycle_transitions.py
  • backend/app/adapters/auth/__init__.py
  • backend/app/modules/audit/schemas.py
  • backend/app/modules/authorization/catalogue.py
  • backend/app/modules/authorization/domain/audit.py
  • backend/app/modules/authorization/domain/audit_targets.py
  • backend/app/modules/authorization/domain/guide_mutations.py
  • backend/app/modules/authorization/domain/lifecycle.py
  • backend/app/modules/authorization/domain/prepared_guide_mutations.py
  • backend/app/modules/authorization/kernel.py
  • backend/app/modules/authorization/lifecycle_authorization.py
  • backend/app/modules/authorization/prepared.py
  • backend/app/modules/authorization/prepared_admin_authority.py
  • backend/app/modules/authorization/prepared_lifecycle_replay.py
  • backend/app/modules/authorization/repository.py
  • backend/app/modules/authorization/review_contracts.py
  • backend/app/modules/authorization/runtime.py
  • backend/app/modules/contributions/api/participation.py
  • backend/app/modules/contributions/records/participant.py
  • backend/app/modules/reviews/acceptance/participant.py
  • backend/app/modules/reviews/api/lifecycle.py
  • backend/app/modules/reviews/lifecycle/fence.py
  • backend/app/modules/reviews/lifecycle/models.py
  • backend/app/modules/reviews/lifecycle/service.py
  • backend/app/modules/tasks/accepted_effects.py
  • backend/app/modules/tasks/api/accepted_effects.py
  • backend/scripts/behavior_ownership.py
  • backend/scripts/test_lane_catalogue.py
  • backend/tests/authorization/catalogue_fixtures.py
  • backend/tests/authorization/setup_finalization/test_catalogue.py
  • backend/tests/authorization/test_catalogue.py
  • backend/tests/conftest.py
  • backend/tests/contributions/participation/conftest.py
  • backend/tests/contributions/participation/support.py
  • backend/tests/contributions/participation/test_postgresql.py
  • backend/tests/contributions/participation/test_transactions.py
  • backend/tests/reviews/acceptance/conftest.py
  • backend/tests/reviews/acceptance/participation_support.py
  • backend/tests/reviews/acceptance/test_participation.py
  • backend/tests/reviews/acceptance/test_participation_transactions.py
  • backend/tests/reviews/lifecycle/conftest.py
  • backend/tests/reviews/lifecycle/fixtures.py
  • backend/tests/reviews/lifecycle/test_authority_binding.py
  • backend/tests/reviews/lifecycle/test_contracts.py
  • backend/tests/reviews/lifecycle/test_fence.py
  • backend/tests/reviews/lifecycle/test_migration.py
  • backend/tests/reviews/lifecycle/test_participant_control.py
  • backend/tests/reviews/lifecycle/test_storage.py
  • backend/tests/reviews/lifecycle/test_transition_storage.py
  • backend/tests/reviews/lifecycle/test_transitions.py
  • backend/tests/reviews/lifecycle/transition_support.py
  • backend/tests/tasks/accepted_effects/conftest.py
  • backend/tests/tasks/accepted_effects/test_postgresql.py
  • backend/tests/tasks/post_submit_routing/conftest.py
  • backend/tests/tasks/post_submit_routing/test_evaluation_currentness.py
  • backend/tests/test_alembic.py
  • backend/tests/test_behavior_ownership.py
  • backend/tests/test_ci_lane_catalogue.py
  • backend/tests/test_database_reset.py
  • backend/tests/test_review_authorization_contracts.py
  • docs/architecture_data_model.md
  • docs/engineering/authorization_activation_custody.md
  • docs/engineering/review_authorization_action_custody.md
  • docs/roadmap_status.md
  • docs/roles_permissions.md
  • docs/spec_authorization_service.md
  • docs/spec_contribution_compensation.md
  • docs/spec_review_lifecycle.md
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@Abiorh001
Abiorh001 marked this pull request as ready for review October 8, 2026 18:05

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant