From 848470c7fe56fb8cfd669aa011bb42feb98eea2c Mon Sep 17 00:00:00 2001 From: Abiorh001 Date: Thu, 9 Jul 2026 09:14:59 +0100 Subject: [PATCH 1/4] Plan WS-POL-002 post-submit checker foundation --- .agent-loop/LOOP_STATE.md | 33 +-- .agent-loop/REVIEW_LOG.md | 32 +++ .agent-loop/WORK_QUEUE.md | 8 +- .../STATUS.md | 12 +- .../CHUNK_MAP.md | 32 +++ .../DECISIONS.md | 53 +++++ .../DISCOVERY.md | 130 ++++++++++ .../INTENT.md | 99 ++++++++ .../PLAN.md | 225 ++++++++++++++++++ .../RISKS.md | 14 ++ .../STATUS.md | 40 ++++ ...OL-002-01-post-submit-compiler-contract.md | 126 ++++++++++ ...POL-002-02-post-submit-derivation-agent.md | 125 ++++++++++ ...-post-submit-policy-approval-visibility.md | 110 +++++++++ ...OL-002-04-post-submit-runtime-hardening.md | 102 ++++++++ ...S-POL-002-05-post-submit-live-api-proof.md | 136 +++++++++++ ...L-002-PLAN-post-submit-checker-planning.md | 78 ++++++ ...S-POL-002-PLAN-internal-review-evidence.md | 115 +++++++++ docs/roadmap_status.md | 8 +- 19 files changed, 1451 insertions(+), 27 deletions(-) create mode 100644 .agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/CHUNK_MAP.md create mode 100644 .agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/DECISIONS.md create mode 100644 .agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/DISCOVERY.md create mode 100644 .agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/INTENT.md create mode 100644 .agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/PLAN.md create mode 100644 .agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/RISKS.md create mode 100644 .agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/STATUS.md create mode 100644 .agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/chunks/WS-POL-002-01-post-submit-compiler-contract.md create mode 100644 .agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/chunks/WS-POL-002-02-post-submit-derivation-agent.md create mode 100644 .agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/chunks/WS-POL-002-03-post-submit-policy-approval-visibility.md create mode 100644 .agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/chunks/WS-POL-002-04-post-submit-runtime-hardening.md create mode 100644 .agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/chunks/WS-POL-002-05-post-submit-live-api-proof.md create mode 100644 .agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/chunks/WS-POL-002-PLAN-post-submit-checker-planning.md create mode 100644 .agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/reviews/WS-POL-002-PLAN-internal-review-evidence.md diff --git a/.agent-loop/LOOP_STATE.md b/.agent-loop/LOOP_STATE.md index fe18d61cc..3bebcdcf5 100644 --- a/.agent-loop/LOOP_STATE.md +++ b/.agent-loop/LOOP_STATE.md @@ -2,22 +2,20 @@ ## Current State -- Active initiative: `WS-POL-001` - Submission Artifact Policy Foundation -- Active planning chunk: none -- Active implementation chunk: `WS-POL-001-16` - Terminal Benchmark Live API Drill -- Branch: `codex/ws-pol-001-16-terminal-benchmark-live-api-drill` -- Status: `WS-POL-001-16` completed the final clean Terminal Benchmark live API - drill through real HTTP-visible APIs. The accepted run used sanitized source - material, automatic project setup, live `submission-requirements`-derived - worker packets, blocked pre-submit no-side-effect proof, successful - submission finalization, durable checker-run visibility, and final - `review_pending` task state without database inspection as lifecycle proof. -- Last merged implementation SHA: `b72a5b9` -- Last merge commit: `b1a9851` -- Current gate: PR creation and human checkpoint for `WS-POL-001-16`; internal - reviewer fanout and evidence gate are complete. -- Next chunk: inactive until this chunk is reviewed, merged, and followed by a - post-merge memory update. +- Active initiative: `WS-POL-002` - Post-Submit Checker Foundation +- Active planning chunk: `WS-POL-002-PLAN` - Post-submit checker foundation planning +- Active implementation chunk: none +- Branch: `codex/ws-pol-002-post-submit-checker-planning` +- Status: `WS-POL-001-16` merged through PR #84. Planning has started for + `WS-POL-002`, which will make post-submit checker setup follow the same + project-guide-derived, compiler-validated, deterministic shape as the + pre-submit checker pipeline. +- Last merged implementation SHA: `be2d5ec` +- Last merge commit: `a3d2a3f` +- Current gate: planning/specification for `WS-POL-002`; no implementation + chunk is active. +- Next chunk: `WS-POL-002-01` is proposed only and inactive until the + planning PR is reviewed and the user gives an explicit start signal. ## Operating Rule @@ -128,3 +126,6 @@ blockchain, frontend, or agent-runtime behavior. - `WS-POL-001-13` PR trust bundle is tracked at `.agent-loop/initiatives/WS-POL-001-submission-artifact-policy-foundation/reviews/WS-POL-001-13-pr-trust-bundle.md`. - PR #79 merged into `main` as `53a57c3`; it implemented `WS-POL-001-14` submission finalization and HTTP-visible Terminal Benchmark proof semantics. +- PR #84 merged into `main` as `a3d2a3f`; it implemented `WS-POL-001-16` + Terminal Benchmark live API drill evidence, privacy scrub, and a professional + PDF report proving the current lifecycle through HTTP-visible APIs. diff --git a/.agent-loop/REVIEW_LOG.md b/.agent-loop/REVIEW_LOG.md index a00448435..a8f5588b9 100644 --- a/.agent-loop/REVIEW_LOG.md +++ b/.agent-loop/REVIEW_LOG.md @@ -444,3 +444,35 @@ description warning was fixed before merge. Next gate: no active implementation chunk. Wait for the user's next explicit chunk start signal. + +## 2026-07-09 - WS-POL-001-16 Merged + +PR #84 merged into `main` as `a3d2a3f1701391c8dafdca6cff2f0f80dbebda3b`. + +Reviewed revision: `49101d4ad3fc22ec6e6065b1e593ef04145db953`. + +Required reviewer tracks: + +- senior engineering +- QA/test +- security/auth +- product/ops +- architecture +- docs +- reuse/dedup +- test delta +- CI integrity + +Result: PASS after internal review and privacy-scrub fixes. Agent Gates, +Backend, Week 1 API Demo UI, and external review passed before merge. + +Scope: Terminal Benchmark live API drill evidence, privacy scrub, professional +PDF report, setup/policy/task/submission/checker-run lifecycle proof through +HTTP-visible APIs, and no database inspection as proof. + +Evidence: `.agent-loop/initiatives/WS-POL-001-submission-artifact-policy-foundation/reviews/WS-POL-001-16-internal-review-evidence.md` + +Trust bundle: `.agent-loop/initiatives/WS-POL-001-submission-artifact-policy-foundation/reviews/WS-POL-001-16-pr-trust-bundle.md` + +Next gate: `WS-POL-002` planning for post-submit checker foundation. No +implementation chunk is active until the user explicitly starts it. diff --git a/.agent-loop/WORK_QUEUE.md b/.agent-loop/WORK_QUEUE.md index 0c4602d96..05c969de5 100644 --- a/.agent-loop/WORK_QUEUE.md +++ b/.agent-loop/WORK_QUEUE.md @@ -4,7 +4,7 @@ | Chunk | Title | Risk | Status | |---|---|---:|---| -| `WS-POL-001-16` | Terminal Benchmark Live API Drill | L1 | Active on `codex/ws-pol-001-16-terminal-benchmark-live-api-drill` | +| `WS-POL-002-PLAN` | Post-Submit Checker Foundation Planning | L1 | Active on `codex/ws-pol-002-post-submit-checker-planning` | ## Completed @@ -28,11 +28,13 @@ | `WS-POL-001-13` | Task Context And Submission Requirement APIs | L1 | Merged through PR #77 as `b567bac` on 2026-07-08 | | `WS-POL-001-14` | Submission Finalize And No-DB Terminal Benchmark Proof | L1 | Merged through PR #79 as `53a57c3` on 2026-07-08 | | `WS-POL-001-15` | Agent Derivation Policy Conflict Hardening | L1 | Merged through PR #81 as `b1a9851` on 2026-07-08 | +| `WS-POL-001-16` | Terminal Benchmark Live API Drill | L1 | Merged through PR #84 as `a3d2a3f` on 2026-07-09 | ## Proposed Next -Stop after `WS-POL-001-16` is implemented, reviewed, and opened for human -review. Do not start another implementation chunk from this branch. +Stop after `WS-POL-002-PLAN` is reviewed. Do not start `WS-POL-002-01` until +the planning PR is merged and the user explicitly starts the implementation +chunk. ## Blocked diff --git a/.agent-loop/initiatives/WS-POL-001-submission-artifact-policy-foundation/STATUS.md b/.agent-loop/initiatives/WS-POL-001-submission-artifact-policy-foundation/STATUS.md index ff4763215..5f5a4cb01 100644 --- a/.agent-loop/initiatives/WS-POL-001-submission-artifact-policy-foundation/STATUS.md +++ b/.agent-loop/initiatives/WS-POL-001-submission-artifact-policy-foundation/STATUS.md @@ -2,12 +2,12 @@ ## Current Status -`WS-POL-001-01` through `WS-POL-001-15` are merged to `main`. +`WS-POL-001-01` through `WS-POL-001-16` are merged to `main`. `WS-POL-001-16` completed the final clean Terminal Benchmark live API drill through real HTTP calls, using sanitized source material and a worker packet -derived from the live `submission-requirements` response. Evidence is recorded -and internal reviewer fanout is complete. The branch is ready for PR/human -checkpoint. +derived from the live `submission-requirements` response. Evidence is recorded, +reviewed, privacy-scrubbed, rendered as a professional PDF report, and merged +through PR #84. `WS-POL-001-14` replaced public submission lock wording with finalization, defined system actor audit semantics, and merged PR #79's HTTP-visible Terminal Benchmark proof evidence. The accepted post-merge no-DB Terminal Benchmark @@ -17,7 +17,7 @@ reran that accepted drill successfully before merging through PR #81. ## Active Chunk -`WS-POL-001-16` - Terminal Benchmark Live API Drill. +None. `WS-POL-001` is complete through `WS-POL-001-16`. ## Chunk Status @@ -38,7 +38,7 @@ reran that accepted drill successfully before merging through PR #81. | `WS-POL-001-13` | Merged | `codex/ws-pol-001-13-task-context-apis` | 77 | Adds task work-context, worker submission-requirements, and operator-only locked-context APIs. | | `WS-POL-001-14` | Merged | `codex/ws-pol-001-14-submission-finalize` | 79 | Replaces public submission lock with finalize, defines system actor audit semantics, scopes operator visibility, and proves the Terminal Benchmark flow through HTTP-visible lifecycle responses. | | `WS-POL-001-15` | Merged | `codex/ws-pol-001-15-agent-derivation-hardening` | 81 | Hardens agent-derived submission artifact policy instructions after the no-DB Terminal Benchmark drill exposed a required-artifact/forbidden-pattern self-conflict. | -| `WS-POL-001-16` | Internal review complete | `codex/ws-pol-001-16-terminal-benchmark-live-api-drill` | - | Proved a human-visible Terminal Benchmark drill through real HTTP APIs without DB inspection as lifecycle proof; PR/human checkpoint is pending. | +| `WS-POL-001-16` | Merged | `codex/ws-pol-001-16-terminal-benchmark-live-api-drill` | 84 | Proved a human-visible Terminal Benchmark drill through real HTTP APIs without DB inspection as lifecycle proof; merged as `a3d2a3f`. | ## Blockers diff --git a/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/CHUNK_MAP.md b/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/CHUNK_MAP.md new file mode 100644 index 000000000..1f4e7c093 --- /dev/null +++ b/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/CHUNK_MAP.md @@ -0,0 +1,32 @@ +# Chunk Map: WS-POL-002 - Post-Submit Checker Foundation + +## Rule + +Only one chunk may be active at a time. Do not start the next chunk until the +current chunk is implemented, verified, internally reviewed, externally +reviewed, merged by explicit human approval, and followed by a memory update. + +## Chunks + +| Chunk | Title | Risk | Status | +|---|---|---:|---| +| `WS-POL-002-01` | Post-Submit Provenance And Compiler Contract | L1 | Proposed | +| `WS-POL-002-02` | Post-Submit Derivation Agent And Resumable Setup Integration | L1 | Proposed | +| `WS-POL-002-03` | Server-Owned Policy Approval And Visibility APIs | L1 | Proposed | +| `WS-POL-002-04` | Locked Runtime Execution And Routing Hardening | L1 | Proposed | +| `WS-POL-002-05` | Terminal Benchmark Post-Submit Live API Proof | L1 | Proposed | + +## Dependency Order + +```text +WS-POL-002-01 +-> WS-POL-002-02 +-> WS-POL-002-03 +-> WS-POL-002-04 +-> WS-POL-002-05 +``` + +## Stop Condition + +After this planning chunk is reviewed, stop. The first implementation chunk is +inactive until the user explicitly starts `WS-POL-002-01`. diff --git a/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/DECISIONS.md b/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/DECISIONS.md new file mode 100644 index 000000000..00fac71d2 --- /dev/null +++ b/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/DECISIONS.md @@ -0,0 +1,53 @@ +# Decisions: WS-POL-002 - Post-Submit Checker Foundation + +## D1. Post-Submit Policy Is Project-Scoped + +`PostSubmitCheckerPolicy` remains attached to the project guide/source snapshot +context. Tasks lock the applicable project policy. Tasks do not derive, +compile, or own unique post-submit checker policies. + +## D2. Agent Derivation Happens During Setup Only + +The post-submit policy derivation agent runs during project setup. It receives +locked guide/source material plus relevant project policy context and emits a +constrained checker specification. + +The agent does not evaluate worker submissions. + +## D3. Runtime Is Deterministic + +Runtime post-submit evaluation executes Workstream-registered deterministic +checkers only. v0.1 does not allow arbitrary generated checker code as the +default path. + +## D4. Defaults Cannot Be Weakened + +The default durable post-submit checkers always run. Project-specific policy may +add registered checkers or tighten routing/severity, but it cannot remove +default checks or downgrade their required coverage. + +## D5. Unsupported Required Checks Block Setup + +If the project guide implies a required post-submit check that cannot be +represented by registered deterministic checker primitives, setup must surface a +clear blocking gap. Workstream must not silently ignore it or pretend the +project is fully protected. + +## D6. Manual Guide Payload Is Obsolete + +The long-term contract removes client-authored `post_submit_checker_policy` +from guide create/update request bodies. Workstream owns generated post-submit +policy setup and approval. No backward compatibility alias should be added once +the server-owned path replaces the manual payload. + +## D7. Worker-Facing Outcomes Stay Simple + +Post-submit checker failure that the worker can fix routes to `needs_revision`. +Internal setup defects and trusted checker failures stay in internal repair +routes and are hidden from worker-facing checker results. + +## D8. Evidence Must Be API-Visible + +The final proof must use API-visible setup runs, generated policy outputs, +task locked context, submission finalization, checker runs, audit events, and +task status. Database inspection is not accepted as lifecycle proof. diff --git a/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/DISCOVERY.md b/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/DISCOVERY.md new file mode 100644 index 000000000..20700ed8f --- /dev/null +++ b/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/DISCOVERY.md @@ -0,0 +1,130 @@ +# Discovery: WS-POL-002 - Post-Submit Checker Foundation + +## Current Code Path + +The backend already has a durable post-submit checker gate. + +Current runtime chain: + +```text +Submission finalization +-> task status evaluation_pending +-> CheckerService.run_submission_checkers +-> locked PostSubmitCheckerPolicy id/version/hash/body validation +-> registered deterministic checker execution +-> durable CheckerRun and CheckerResult rows +-> review_pending | needs_revision | internal blocked/retry route +``` + +Key files discovered: + +- `backend/app/modules/projects/post_submit_policy.py` +- `backend/app/modules/projects/models.py` +- `backend/app/modules/projects/service.py` +- `backend/app/modules/tasks/service.py` +- `backend/app/modules/tasks/models.py` +- `backend/app/modules/checkers/runner.py` +- `backend/app/modules/checkers/service.py` +- `backend/app/modules/checkers/models.py` +- `backend/tests/test_checkers.py` + +## Current Default Post-Submit Checkers + +`DEFAULT_DURABLE_CHECKERS` currently contains: + +- `check_submission_packet` +- `check_policy_context_present` +- `check_evidence_present` +- `check_evidence_integrity` +- `check_required_files` +- `check_forbidden_files` +- `check_confidentiality_attestation` +- `check_low_quality_generated_artifacts` + +The checker registry also includes `check_acceptance_criteria_present`, which +is a setup/readiness checker and is not part of the default durable list unless +a policy requires it. + +## Current Policy Shape + +`PostSubmitCheckerPolicy` is stored in the physical `checker_policies` table +and is attached to a project guide version. + +Current canonical body fields: + +- `schema_version` +- `project_id` +- `guide_version` +- `default_checkers` +- `required_checkers` +- `warning_checkers` +- `execution_checkers` +- `blocking_severities` + +The policy hash is a canonical JSON hash of the policy body. + +Task screening locks: + +- post-submit checker policy id +- post-submit checker policy version +- post-submit checker policy hash +- post-submit checker policy body + +Submissions copy that locked policy context from the task. + +Checker runs copy the locked policy context from the submission. + +## What Is Already Correct + +- Post-submit checker runtime is separated from pre-submit intake. +- Pre-submit failures prevent submission creation. +- Post-submit failures happen after finalization and create durable checker + evidence. +- The persisted post-submit evaluation status is `evaluation_pending`. +- Successful gate results route to `review_pending`. +- Worker-fixable checker failures route to `needs_revision`. +- Internal setup defects and trusted checker infrastructure failures can stay + hidden from workers. +- Task/submission/checker-run provenance is locked to the post-submit policy + id/version/hash/body. +- Guide activation already validates that a post-submit checker policy exists, + hashes correctly, and references registered checkers. + +## Gaps + +The missing part is setup-time policy generation and approval. + +Current gaps: + +- `ProjectGuideCreate` and `ProjectGuideUpdate` still accept manual + `post_submit_checker_policy` input. +- There is no `PostSubmitCheckerPolicyDerivationAgent`. +- There is no post-submit policy compiler equivalent to the pre-submit compiler + contract. +- Project-specific post-submit checker choices are not derived from the guide + source material. +- Unsupported project-specific checker needs are not represented as explicit + setup blockers. +- Policy visibility exists through downstream locked-context/checker-run + responses, but setup visibility for generated post-submit policy derivation is + not yet first-class. +- The Terminal Benchmark live API drill proves current post-submit execution, + not derived post-submit policy setup. + +## Constraints From Existing Architecture + +- Post-submit policy must remain project-scoped. +- Task-specific checker generation is explicitly rejected. +- Default Workstream checkers cannot be weakened. +- Runtime must use deterministic checkers, not an agent. +- Celery is the correct setup/job boundary for long-running derivation work. +- The Flow authentication boundary remains external; Workstream only verifies + tokens and uses local actor/profile records for product authorization. +- No backward compatibility layer should preserve obsolete request fields once + the new path exists. + +## Implementation Implication + +WS-POL-002 should not redesign the runtime gate from scratch. It should extend +the project setup pipeline so post-submit policy is derived, compiled, approved, +locked, visible, and proven with APIs the same way pre-submit policy now is. diff --git a/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/INTENT.md b/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/INTENT.md new file mode 100644 index 000000000..d4b264ec6 --- /dev/null +++ b/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/INTENT.md @@ -0,0 +1,99 @@ +# Intent: WS-POL-002 - Post-Submit Checker Foundation + +## Human Intent + +Make post-submit checkers work with the same discipline as the pre-submit +checker pipeline, while preserving the correct lifecycle boundary: + +```text +Project guide/source material +-> setup-time agent derivation +-> trusted Workstream compiler +-> project-scoped PostSubmitCheckerPolicy +-> task locks the project policy +-> finalized submission runs deterministic checks +``` + +The agent may help derive a constrained policy specification during project +setup. The agent must not judge worker submissions at runtime. Runtime +submission evaluation is performed by deterministic Workstream checkers under a +locked project policy context. + +## Product Intent + +Post-submit checks answer whether a finalized submission is ready for human +review. They do not replace reviewer judgment and they do not create product +review decisions. + +The user-facing review decision values remain: + +- `accept` +- `needs_revision` +- `reject` + +Post-submit checker routing may internally produce: + +- `allow_review` +- `needs_revision` +- `task_setup_blocked` +- `checker_retry` + +Only worker-fixable checker failures surface as `needs_revision`. Setup defects +and trusted checker infrastructure failures remain internal repair routes. + +## Architecture Intent + +Workstream already has a durable post-submit checker gate: + +```text +finalize submission +-> evaluation_pending +-> CheckerRun +-> review_pending | needs_revision | internal repair route +``` + +This initiative strengthens the setup side of that gate. Today, +`PostSubmitCheckerPolicy` exists and is locked into tasks/submissions, but the +project-specific policy is still too manual compared with the pre-submit +pipeline. The new work must derive, validate, compile, approve, lock, expose, +and prove the post-submit policy with the same zero-trust shape as pre-submit. + +## Non-Negotiable Boundaries + +- Post-submit checker policy is project-scoped, not task-specific. +- Tasks lock references to the project policy; tasks do not derive or compile + their own checker bundles. +- Workstream default post-submit checkers always run and cannot be weakened by + project policy. +- A project-specific policy may add registered deterministic checkers or tighten + severity/routing. It must not remove defaults. +- v0.1 must not execute arbitrary agent-generated checker code. +- Any unsupported project-specific checker requirement blocks setup or becomes a + documented implementation gap; it must not silently pass. +- Project owner material remains human-facing guide/source input. Workstream + owns the derived checker policy and approval workflow. +- No backward compatibility aliases are added for obsolete request fields. +- No frontend, blockchain, settlement, marketplace, external source adapter, or + agent workspace expansion is included. + +## Success Definition + +The system is ready when a real project can show through APIs: + +1. Guide/source material is captured as an immutable bundle. +2. Setup runs sufficiency first. +3. A post-submit policy derivation agent receives the same locked guide/source + context and produces a constrained spec. +4. Workstream compiles that spec into a deterministic project + `PostSubmitCheckerPolicy`. +5. Setup-authorized admin or project_manager can inspect and approve the + generated post-submit policy through APIs under the current v0.1 bootstrap + authorization boundary. +6. Guide activation requires the setup-approved compiled post-submit policy. +7. Tasks lock the policy id/version/hash/body. +8. Finalized submissions execute that locked policy and produce durable + `CheckerRun` evidence. +9. Worker-fixable failures become `needs_revision`; setup/internal failures are + hidden from workers and held for trusted repair. +10. A Terminal Benchmark-style live API drill proves the flow without database + inspection. diff --git a/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/PLAN.md b/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/PLAN.md new file mode 100644 index 000000000..20f67ff10 --- /dev/null +++ b/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/PLAN.md @@ -0,0 +1,225 @@ +# Plan: WS-POL-002 - Post-Submit Checker Foundation + +## Goal + +Make post-submit checker setup match the quality of the pre-submit checker +pipeline without changing the product review decision contract. + +The final architecture should be: + +```text +ProjectGuide +-> GuideSourceSnapshot +-> GuideSufficiencyReport +-> SubmissionArtifactPolicy +-> EffectiveProjectSubmissionArtifactPolicy +-> project PreSubmitCheckerPolicy +-> PostSubmitCheckerPolicyDerivationAgent +-> constrained PostSubmitCheckerPolicySpec +-> trusted Workstream compiler +-> project PostSubmitCheckerPolicy +-> tasks lock references +-> finalized submissions execute deterministic post-submit checkers +``` + +## Current Baseline + +The runtime gate already exists: + +```text +finalize submission +-> evaluation_pending +-> CheckerRun +-> review_pending | needs_revision | internal repair route +``` + +This initiative strengthens the project setup side so the policy feeding that +gate is no longer manually assembled in guide create/update payloads. + +## Design + +### Setup Pipeline + +The project setup pipeline becomes a resumable setup flow. The current Celery +pipeline stops when it produces a draft `SubmissionArtifactPolicy`; it does not +already have an effective policy or compiled pre-submit bundle at that point. +WS-POL-002 must preserve that reality. + +Phase 1: + +```text +Guide/source capture +-> GuideSufficiencyAgent +-> SubmissionArtifactPolicyDerivationAgent +-> policy_draft_ready +-> v0.1 setup-authorized admin/project_manager approval of SubmissionArtifactPolicy +-> EffectiveProjectSubmissionArtifactPolicy +-> trusted pre-submit compiler +``` + +Phase 2: + +```text +pre-submit compile success +-> PostSubmitCheckerPolicyDerivationAgent +-> trusted post-submit compiler +-> compiled post-submit policy pending setup approval +-> v0.1 setup-authorized admin/project_manager approval of PostSubmitCheckerPolicy +-> guide activation +``` + +The post-submit derivation agent runs after the effective project submission +artifact policy and pre-submit checker bundle exist, because durable +post-submit checks often depend on the same artifact and evidence contract. +The trigger is the server-owned continuation after pre-submit approval/compile, +not the initial source-capture enqueue. + +### Agent Contract + +`PostSubmitCheckerPolicyDerivationAgent` receives: + +- project id and guide version +- guide source snapshot id and bundle hash +- guide content/source excerpts +- guide sufficiency report summary +- submission artifact policy summary +- effective project submission artifact policy hash and summary +- compiled pre-submit checker bundle summary +- current registered post-submit checker catalog + +The agent returns a constrained `PostSubmitCheckerPolicySpec`: + +- required registered checker names +- warning registered checker names +- severity/routing requirements +- reasons tied to guide/source evidence +- unsupported required-check gaps +- human-readable setup notes + +The agent must not return executable runtime code in v0.1. + +Project source material is untrusted LLM input. The derivation adapter must +treat guide/source excerpts as data, not instructions. Returned reasons must be +tied to bounded source-evidence references, and server-side validation must +reject or ignore any source text that attempts to override Workstream defaults, +roles, checker routing, authorization, or review-decision values. + +### Compiler Contract + +The trusted Workstream post-submit compiler: + +- canonicalizes the spec +- always includes default durable checkers +- rejects unknown checker names +- rejects attempts to remove or weaken default checkers +- rejects duplicate or contradictory checker classifications +- rejects blocking-severity downgrade attempts +- requires every required checker to map to a registered deterministic checker +- emits the canonical `PostSubmitCheckerPolicy.policy_body` +- emits `policy_hash = sha256(canonical_json(policy_body))` + +The platform default checker list is authoritative. `policy_body.default_checkers` +must exactly equal the server-owned `DEFAULT_DURABLE_CHECKERS` list. Default-only +projects are valid: the compiler represents defaults as required durable +coverage and permits an empty project-specific addition set only when all +platform defaults remain required. + +The compiler, not the agent, decides the executable policy body. + +### Runtime Contract + +Runtime does not run derivation. Runtime loads the locked +`PostSubmitCheckerPolicy` id/version/hash/body from the submission and executes +the registered deterministic checkers listed in that body. + +Routing remains: + +- all blocking checks pass: `review_pending` +- worker-fixable blocking failure: `needs_revision` +- setup/context defect: internal `task_setup_blocked` +- transient trusted checker issue: internal `checker_retry` + +Internal repair routes must be operator-visible with a bounded reason, owner, +next action, retry/audit provenance, and proof that reviewers only receive work +after the task reaches `review_pending`. + +### Default Checkers + +Default durable post-submit checkers are currently: + +- `check_submission_packet` +- `check_policy_context_present` +- `check_evidence_present` +- `check_evidence_integrity` +- `check_required_files` +- `check_forbidden_files` +- `check_confidentiality_attestation` +- `check_low_quality_generated_artifacts` + +These remain platform-owned and cannot be removed by project policy. + +### Project-Specific Checkers + +Project-specific post-submit policy may add registered deterministic checkers. +For example, a project can require `check_acceptance_criteria_present` when it +needs task setup reviewability enforced before human review. + +If the guide implies a check that does not exist in the registered catalog, the +setup output must say that clearly and block activation until Workstream adds a +checker or the project guide expectation is corrected. + +### API Visibility + +Setup-authorized admins and project_managers need API-visible state for: + +- post-submit derivation input summary +- derivation result +- unsupported checker gaps +- compiled policy body summary +- compiled policy hash +- approval status +- activation readiness + +Setup visibility and approval endpoints use the current v0.1 bootstrap +authorization boundary: verified `admin` or `project_manager` roles. Workers, +reviewers, finance actors, and auditors remain denied. Project-scoped +project-manager authorization requires the future Workstream role-assignment +source of truth and is out of scope for WS-POL-002. + +Persisted derivation output and API summaries must be bounded and redacted by +default. They must not echo raw guide/source text, local paths, secrets, +credential-shaped values, replayable signed refs, or exact source hashes unless +an explicit future secure evidence surface is designed for that purpose. + +Workers should only see post-submit results that are safe and relevant to their +fix path. Internal setup defects remain hidden. + +## Non-Scope + +- Human review packet assignment. +- Reviewer decision APIs. +- Revision replay APIs beyond existing checker-caused `needs_revision` routing. +- Payment, reputation, blockchain, x402, ERC standards, or settlement. +- Frontend product work. +- Arbitrary generated checker code execution. +- Per-task checker derivation. +- Backward compatibility aliases for removed guide request fields. + +## Proof Strategy + +Each implementation chunk must include deterministic tests. The final chunk must +run a Terminal Benchmark-style live API drill that shows: + +- source snapshot capture +- setup-run progression +- post-submit policy derivation input/output +- compiled post-submit policy visibility +- activation gate +- task locked context +- submission finalization +- durable checker run +- worker-fixable `needs_revision` +- fixed resubmission returning to `review_pending` + +The drill must be API-visible and privacy-safe. Database inspection is not +accepted as proof. diff --git a/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/RISKS.md b/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/RISKS.md new file mode 100644 index 000000000..350480935 --- /dev/null +++ b/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/RISKS.md @@ -0,0 +1,14 @@ +# Risks: WS-POL-002 - Post-Submit Checker Foundation + +| Risk | Impact | Mitigation | +|---|---|---| +| Reintroducing task-specific checker generation | High architecture drift and operational cost | Keep `PostSubmitCheckerPolicy` project-scoped; tasks lock references only. | +| Letting agent output become runtime authority | High security and correctness risk | Agent emits constrained setup spec only; Workstream compiler and registered checkers own runtime. | +| Weakening default durable checks | Bad submissions can bypass review gate | Compiler must always include defaults and reject attempts to remove or downgrade them. | +| Referencing unknown checker names | Activation can pass but runtime fails | Compiler and activation must require registered checkers. Unsupported required checks become setup blockers. | +| Confusing post-submit checker routing with product decisions | Workers/reviewers misunderstand lifecycle | Keep product decisions limited to `accept`, `needs_revision`, `reject`; keep internal routes hidden unless operator authorized. | +| Manual guide payload survives as a second policy path | Contract drift and inconsistent setup | Remove obsolete manual `post_submit_checker_policy` guide request fields once generated path exists. | +| Overloading post-submit checks with review/revision lifecycle | Scope creep | This initiative stops at automated pre-review gate readiness; human review and revision APIs remain separate. | +| Privacy leak in live drill evidence | External source/source-material exposure | Use sanitized refs, redacted identifiers, PDF/report privacy scan, and no local private paths. | +| CI or tests become too broad and slow | Reduced iteration quality | Use focused tests per chunk plus full API drill only in the final proof chunk. | +| Confusing v0.1 setup authorization with future project-scoped roles | Inaccurate access-control contract | WS-POL-002 uses current verified `admin`/`project_manager` setup authorization; project-scoped role assignment remains a separate future authorization chunk. | diff --git a/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/STATUS.md b/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/STATUS.md new file mode 100644 index 000000000..ac14c9cd5 --- /dev/null +++ b/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/STATUS.md @@ -0,0 +1,40 @@ +# Status: WS-POL-002 - Post-Submit Checker Foundation + +## Current Status + +Planning started after `WS-POL-001-16` merged through PR #84. + +No implementation chunk is active. This initiative is in planning/specification +state on branch `codex/ws-pol-002-post-submit-checker-planning`. + +## Active Planning Chunk + +`WS-POL-002-PLAN` - Post-submit checker foundation planning. + +## Active Implementation Chunk + +None. + +## Proposed First Implementation Chunk + +`WS-POL-002-01` - Post-submit compiler and default policy contract. + +This chunk is inactive until the planning PR is reviewed and the user gives an +explicit start signal. + +## Chunk Status + +| Chunk | Status | Branch | PR | Notes | +|---|---|---|---:|---| +| `WS-POL-002-PLAN` | Active planning | `codex/ws-pol-002-post-submit-checker-planning` | - | Defines intent, discovery, design, risks, decisions, and implementation chunks. | +| `WS-POL-002-01` | Proposed | - | - | Post-submit provenance model and compiler contract. | +| `WS-POL-002-02` | Proposed | - | - | Post-submit derivation agent and resumable setup integration after pre-submit approval/compile. | +| `WS-POL-002-03` | Proposed | - | - | Server-owned approval and setup visibility APIs; remove manual guide payload. | +| `WS-POL-002-04` | Proposed | - | - | Runtime hardening for locked post-submit policy execution and routing. | +| `WS-POL-002-05` | Proposed | - | - | Terminal Benchmark-style live API proof and report. | + +## Blockers + +| Blocker | Owner | Next action | +|---|---|---| +| none | none | none | diff --git a/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/chunks/WS-POL-002-01-post-submit-compiler-contract.md b/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/chunks/WS-POL-002-01-post-submit-compiler-contract.md new file mode 100644 index 000000000..0546dceac --- /dev/null +++ b/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/chunks/WS-POL-002-01-post-submit-compiler-contract.md @@ -0,0 +1,126 @@ +# Chunk Contract: WS-POL-002-01 - Post-Submit Provenance And Compiler Contract + +## Parent Initiative + +`WS-POL-002` - Post-Submit Checker Foundation + +## Problem Being Solved + +Post-submit policy currently has a canonical body and hash, but it lacks a +trusted compiler contract equivalent to pre-submit. Before adding an agent, +Workstream needs deterministic compiler rules that prevent project policy from +weakening platform defaults or referencing unsupported checkers. + +## Goal + +Introduce the durable post-submit policy provenance fields, setup-run output +fields, and trusted compiler contract that produce the canonical project-scoped +`PostSubmitCheckerPolicy` body from a constrained spec. + +## Target Behavior + +- Compiler always includes platform default durable post-submit checkers. +- Compiler rejects unknown checker names. +- Compiler rejects attempts to remove or weaken defaults. +- Compiler rejects duplicate/conflicting checker classifications. +- Compiler rejects unsupported blocking-severity downgrade attempts. +- Compiler emits the canonical policy body and hash. +- Compiler supports default-only projects by representing platform defaults as + required durable coverage while permitting an empty project-specific addition + set. +- `policy_body.default_checkers` must exactly equal the platform-owned + `DEFAULT_DURABLE_CHECKERS` list. +- Policy rows bind to guide source snapshot id/hash, compiler version, + derivation provenance, lifecycle status, and approval provenance. +- `ProjectSetupRun` can reference post-submit derivation/compile output and + represent post-submit setup statuses without JSON-only hiding. +- Activation/runtime validation uses the compiled canonical body, not ad hoc + request lists. + +## Allowed Files + +```text +backend/app/modules/projects/post_submit_policy.py +backend/app/modules/checkers/compiler.py +backend/app/modules/projects/models.py +backend/app/modules/projects/repository.py +backend/app/modules/projects/service.py +backend/app/modules/projects/schemas.py +backend/alembic/versions/** +backend/tests/test_alembic.py +backend/tests/test_checkers.py +backend/tests/test_projects.py +docs/architecture_checker_framework.md +docs/architecture_data_model.md +docs/template_checker_policy.md +.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/** +.agent-loop/LOOP_STATE.md +.agent-loop/WORK_QUEUE.md +.agent-loop/REVIEW_LOG.md +``` + +## Not Allowed + +```text +backend/app/adapters/project_agents/** +backend/app/modules/tasks/** +frontend or demo UI work +payment/reputation/blockchain settlement +per-task checker generation +arbitrary generated checker code execution +``` + +## Acceptance Criteria + +- A constrained post-submit checker spec can be compiled into a canonical + project `PostSubmitCheckerPolicy` body. +- Default durable post-submit checkers are always present in + `execution_checkers`. +- `policy_body.default_checkers` exactly matches `DEFAULT_DURABLE_CHECKERS`; no + missing, extra, renamed, or reordered defaults are accepted. This chunk must + not change the `DEFAULT_DURABLE_CHECKERS` list; any future default-list change + requires explicit human approval and security review in its own chunk. +- Default-only project policy compilation and activation are valid when all + platform defaults remain required. +- Unknown checker names fail closed. +- Duplicate or contradictory required/warning checker classifications fail + closed. +- Policy hash equals `sha256(canonical_json(policy_body))`. +- Compiler implementation reuses or consolidates through existing + `post_submit_policy.py` canonical body, hash, default-list, and locked-body + parsing helpers instead of reimplementing a second post-submit canonicalizer. +- Migration and ORM metadata persist source snapshot id/hash, compiler version, + lifecycle status, approval actor/role/time, derivation provenance, and + unsupported checker gaps without weakening existing policy locks. +- Migration and ORM metadata add explicit setup-run post-submit output/status + support. +- Existing runtime tests still pass. +- Docs describe the compiler boundary and default checker list. + +## Verification Commands + +```bash +python3 scripts/check_stale_workstream_wording.py +python3 scripts/check_markdown_links.py +(cd backend && .venv/bin/pytest tests/test_projects.py tests/test_checkers.py -q) +(cd backend && .venv/bin/pytest tests/test_alembic.py -q) +git diff --check +``` + +## Required Reviewers + +- senior engineering +- QA/test +- security/auth +- product/ops +- architecture +- docs +- reuse/dedup +- test delta +- CI integrity + +## Human Review Focus + +- Confirm the compiler, not the agent, owns canonical runtime policy. +- Confirm project policy cannot weaken defaults. +- Confirm no task-specific checker generation is introduced. diff --git a/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/chunks/WS-POL-002-02-post-submit-derivation-agent.md b/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/chunks/WS-POL-002-02-post-submit-derivation-agent.md new file mode 100644 index 000000000..d53257b3a --- /dev/null +++ b/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/chunks/WS-POL-002-02-post-submit-derivation-agent.md @@ -0,0 +1,125 @@ +# Chunk Contract: WS-POL-002-02 - Post-Submit Derivation Agent And Resumable Setup Integration + +## Parent Initiative + +`WS-POL-002` - Post-Submit Checker Foundation + +## Problem Being Solved + +Post-submit policy must be derived from project guide/source context instead of +being invented manually in guide request bodies. The derivation must run +asynchronously inside the project setup pipeline and stop cleanly when the +guide implies unsupported checker requirements. + +## Goal + +Add `PostSubmitCheckerPolicyDerivationAgent` and integrate it into the +resumable setup continuation that runs after v0.1 setup-authorized +admin/project_manager approval creates the effective submission artifact policy +and compiled project pre-submit checker bundle. + +## Target Behavior + +- Initial source-capture setup still stops at `policy_draft_ready`. +- Setup-authorized admin/project_manager approval of the submission artifact + policy creates the effective policy and compiled pre-submit bundle, then + enqueues or resumes post-submit derivation. +- Post-submit derivation runs only after effective submission artifact policy + and pre-submit checker bundle are available. +- Agent input includes guide source snapshot, sufficiency summary, effective + policy summary, pre-submit checker summary, and registered post-submit + checker catalog. +- Agent output is a constrained spec, not executable runtime code. +- Unsupported required checks are recorded as setup blockers. +- Successful derivation passes through the trusted compiler. +- Setup run status makes post-submit derivation/compile state visible. +- Hostile guide/source instructions that attempt to weaken Workstream defaults, + roles, routing, authorization, or review decisions are ignored or rejected. +- Persisted derivation summaries are bounded and redacted; raw source text, + local paths, secrets, signed refs, and exact source hashes are not returned in + setup APIs by default. + +## Allowed Files + +```text +backend/app/adapters/project_agents/** +backend/app/workers/project_setup.py +backend/app/modules/projects/setup_queue.py +backend/app/modules/projects/service.py +backend/app/modules/projects/schemas.py +backend/app/modules/projects/models.py +backend/app/modules/projects/repository.py +backend/app/modules/checkers/compiler.py +backend/tests/test_projects.py +backend/tests/test_agent_runtime.py +backend/tests/test_alembic.py +docs/architecture_checker_framework.md +docs/architecture_data_model.md +docs/operations_project_operating_manual.md +.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/** +.agent-loop/LOOP_STATE.md +.agent-loop/WORK_QUEUE.md +.agent-loop/REVIEW_LOG.md +``` + +## Not Allowed + +```text +backend/app/modules/tasks/** +backend/app/modules/checkers/service.py +frontend or demo UI work +payment/reputation/blockchain settlement +per-task checker generation +runtime agent-based submission judgment +``` + +## Acceptance Criteria + +- The setup continuation invokes post-submit derivation only after v0.1 + setup-authorized admin/project_manager approval creates the effective + submission artifact policy and compiled project pre-submit checker bundle. +- Blocked guide sufficiency prevents post-submit derivation. +- Unsupported required checker gaps block setup and are visible to operators. +- Successful derivation creates a compiled project `PostSubmitCheckerPolicy`. +- Agent prompt/instructions explicitly forbid arbitrary checker code and + per-task checker generation. +- Tests include malicious guide/source excerpts and prove source text is treated + as data, not authority. +- Returned spec reasons must be tied to bounded source evidence references. +- API-visible setup summaries redact secrets, local paths, replayable refs, and + exact source hashes. +- Tests cover success, unsupported checker gap, and setup ordering. +- Tests prove the setup trigger boundary: no post-submit derivation before + submission artifact policy approval/pre-submit compile, and exactly one + post-submit setup continuation after that point. +- Implementation extends the existing project setup queue/worker boundary in + `setup_queue.py` and `project_setup.py`; it must not create a disconnected + post-submit-only queue or parallel pipeline. + +## Verification Commands + +```bash +python3 scripts/check_stale_workstream_wording.py +python3 scripts/check_markdown_links.py +(cd backend && .venv/bin/pytest tests/test_projects.py tests/test_agent_runtime.py -q) +(cd backend && .venv/bin/pytest tests/test_alembic.py -q) +git diff --check +``` + +## Required Reviewers + +- senior engineering +- QA/test +- security/auth +- product/ops +- architecture +- docs +- reuse/dedup +- test delta +- CI integrity + +## Human Review Focus + +- Confirm the agent derives setup policy only. +- Confirm unsupported checker requirements fail closed. +- Confirm no runtime submission judgment is delegated to an agent. diff --git a/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/chunks/WS-POL-002-03-post-submit-policy-approval-visibility.md b/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/chunks/WS-POL-002-03-post-submit-policy-approval-visibility.md new file mode 100644 index 000000000..d4f0e48ad --- /dev/null +++ b/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/chunks/WS-POL-002-03-post-submit-policy-approval-visibility.md @@ -0,0 +1,110 @@ +# Chunk Contract: WS-POL-002-03 - Server-Owned Policy Approval And Visibility APIs + +## Parent Initiative + +`WS-POL-002` - Post-Submit Checker Foundation + +## Problem Being Solved + +Operators need API-visible post-submit setup state. The old guide create/update +payload path also needs to be removed once server-owned derivation exists, so +there is one authoritative policy path. + +## Goal + +Expose generated post-submit policy setup state through APIs and remove manual +guide request-body policy creation for post-submit checkers. + +## Target Behavior + +- Setup-authorized admin or project_manager can inspect derivation input + summary, derivation output, unsupported gaps, compiled policy summary, and + policy hash under the current v0.1 bootstrap authorization boundary. +- Setup-authorized admin or project_manager can approve or request setup + correction for the generated project post-submit policy. +- Guide create/update no longer accepts `post_submit_checker_policy` from + clients. +- Guide activation requires the approved compiled project + `PostSubmitCheckerPolicy`. +- Worker-facing APIs continue to hide internal policy body details. +- Workers, reviewers, finance actors, and auditors are denied on new setup + visibility and approval endpoints. Project-scoped project_manager grants are + future Workstream role-assignment work, not part of WS-POL-002. + +## Allowed Files + +```text +backend/app/modules/projects/router.py +backend/app/modules/projects/service.py +backend/app/modules/projects/schemas.py +backend/app/modules/projects/repository.py +backend/app/modules/projects/models.py +backend/alembic/versions/** +backend/tests/test_alembic.py +backend/tests/test_projects.py +backend/tests/test_auth.py +docs/product_first_user_flows.md +docs/operations_project_operating_manual.md +docs/architecture_data_model.md +.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/** +.agent-loop/LOOP_STATE.md +.agent-loop/WORK_QUEUE.md +.agent-loop/REVIEW_LOG.md +``` + +## Not Allowed + +```text +backend/app/modules/tasks/** +backend/app/modules/checkers/service.py +frontend or demo UI work +payment/reputation/blockchain settlement +compatibility aliases for removed guide payload fields +``` + +## Acceptance Criteria + +- Project setup APIs show generated post-submit policy status without database + inspection. +- Guide create/update rejects obsolete manual `post_submit_checker_policy` + payload fields. +- Activation blocks unless the compiled post-submit policy is approved and + matches the guide/source context. +- Approval provenance is immutable and records actor id, role, timestamp, + source snapshot id/hash, and compiled policy hash. +- API responses are role-scoped and do not leak internal policy body to workers. +- Negative authorization tests cover worker, reviewer, finance, and auditor + access. A future project-scoped role-assignment chunk must add unrelated + project_manager denial once project-level roles exist. +- Visibility responses redact raw source text, local paths, secrets, + credential-shaped values, replayable refs, and exact source hashes by default. +- Tests cover request-body rejection, approval, activation guard, and operator + visibility. + +## Verification Commands + +```bash +python3 scripts/check_stale_workstream_wording.py +python3 scripts/check_markdown_links.py +(cd backend && .venv/bin/pytest tests/test_projects.py tests/test_auth.py -q) +(cd backend && .venv/bin/pytest tests/test_alembic.py -q) +git diff --check +``` + +## Required Reviewers + +- senior engineering +- QA/test +- security/auth +- product/ops +- architecture +- docs +- reuse/dedup +- test delta +- CI integrity + +## Human Review Focus + +- Confirm there is one authoritative server-owned post-submit policy path. +- Confirm obsolete manual payload fields are removed, not aliased. +- Confirm visibility is useful for operators but safe for workers. diff --git a/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/chunks/WS-POL-002-04-post-submit-runtime-hardening.md b/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/chunks/WS-POL-002-04-post-submit-runtime-hardening.md new file mode 100644 index 000000000..b9eb6da7a --- /dev/null +++ b/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/chunks/WS-POL-002-04-post-submit-runtime-hardening.md @@ -0,0 +1,102 @@ +# Chunk Contract: WS-POL-002-04 - Locked Runtime Execution And Routing Hardening + +## Parent Initiative + +`WS-POL-002` - Post-Submit Checker Foundation + +## Problem Being Solved + +Runtime already locks and executes post-submit policy, but it must be hardened +against the new generated/approved policy source and prove routing behavior +against worker-fixable failures, internal setup defects, and trusted retries. + +## Goal + +Harden only the runtime deltas introduced by generated and approved project +`PostSubmitCheckerPolicy` records, while preserving already-proven finalization, +locked-policy validation, and checker routing behavior. + +## Target Behavior + +- Task locked context stamps the generated, approved post-submit policy + provenance added by WS-POL-002. +- Finalization rejects generated-policy source snapshot or approval provenance + mismatches before checker execution. +- Internal setup and retry routes expose bounded reason, owner, next action, and + retry/audit provenance to authorized operators only. +- Reviewers receive tasks only after the task reaches `review_pending`. +- Existing worker-fixable `needs_revision`, internal `task_setup_blocked`, and + trusted `checker_retry` semantics are regression-tested, not redesigned. + +## Allowed Files + +```text +backend/app/modules/tasks/** +backend/app/modules/checkers/** +backend/app/modules/projects/service.py +backend/tests/test_tasks.py +backend/tests/test_checkers.py +backend/scripts/api_contract_e2e.py +docs/architecture_lifecycle_state_machine.md +docs/architecture_checker_framework.md +docs/operations_queue_policy.md +.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/** +.agent-loop/LOOP_STATE.md +.agent-loop/WORK_QUEUE.md +.agent-loop/REVIEW_LOG.md +``` + +## Not Allowed + +```text +backend/app/adapters/auth/** +frontend or demo UI work +payment/reputation/blockchain settlement +per-task checker generation +new review decision values +``` + +## Acceptance Criteria + +- Generated approved post-submit policy provenance is locked onto tasks and + submissions. +- Finalization fails closed for missing/stale/mismatched generated-policy + source snapshot, approval, or hash provenance. +- Operator-visible internal route responses include bounded reason, owner, next + action, retry eligibility, and audit event id. +- Worker-facing responses hide internal setup blocked and checker retry routes. +- Reviewers cannot access tasks/runs before `review_pending`. +- Checker-caused `needs_revision` keeps `outcome_source = auto_checker` and + does not create or reference a human review decision id. +- Existing pre-submit behavior is unchanged. +- Tests cover new generated-policy provenance mismatches plus regression cases + for pass, worker-fixable failure, setup blocked, trusted retry, stale + submission, and stale policy body behavior. + +## Verification Commands + +```bash +python3 scripts/check_stale_workstream_wording.py +python3 scripts/check_markdown_links.py +(cd backend && .venv/bin/pytest tests/test_tasks.py tests/test_checkers.py -q) +(cd backend && WORKSTREAM_DATABASE_URL=postgresql+asyncpg://workstream:workstream@localhost:5433/workstream_test .venv/bin/python scripts/api_contract_e2e.py) +git diff --check +``` + +## Required Reviewers + +- senior engineering +- QA/test +- security/auth +- product/ops +- architecture +- docs +- reuse/dedup +- test delta +- CI integrity + +## Human Review Focus + +- Confirm post-submit routing remains distinct from review decisions. +- Confirm worker-facing responses stay understandable. +- Confirm no pre-submit regression is introduced. diff --git a/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/chunks/WS-POL-002-05-post-submit-live-api-proof.md b/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/chunks/WS-POL-002-05-post-submit-live-api-proof.md new file mode 100644 index 000000000..ac210a5b8 --- /dev/null +++ b/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/chunks/WS-POL-002-05-post-submit-live-api-proof.md @@ -0,0 +1,136 @@ +# Chunk Contract: WS-POL-002-05 - Terminal Benchmark Post-Submit Live API Proof + +## Parent Initiative + +`WS-POL-002` - Post-Submit Checker Foundation + +## Problem Being Solved + +The implementation must be proven as a real operator/worker flow, not only by +unit tests. The proof must show the generated post-submit policy setup and the +runtime checker gate through APIs. + +## Goal + +Run a privacy-safe Terminal Benchmark-style live API drill that proves +post-submit policy derivation, approval, task locking, finalization, checker +routing, `needs_revision`, fixed resubmission, and `review_pending`. + +## Target Behavior + +- Project setup captures sanitized source material. +- Sufficiency passes or blocks before post-submit derivation. +- Post-submit derivation input/output is visible through setup APIs. +- Compiled post-submit policy hash is visible before activation. +- Activation requires the approved compiled post-submit policy. +- Task locks that policy context. +- Submission finalization runs the locked policy. +- A clean path reaches `review_pending`. +- A worker-fixable post-submit failure reaches `needs_revision`. +- A fixed resubmission returns to `review_pending`. + +## Allowed Files + +```text +.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/reviews/** +.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/** +.agent-loop/LOOP_STATE.md +.agent-loop/WORK_QUEUE.md +.agent-loop/REVIEW_LOG.md +docs/roadmap_status.md +examples/terminal_benchmark/** +scripts/privacy_scan_evidence.py +``` + +The exact `scripts/privacy_scan_evidence.py` path is allowed so this chunk can +add the committed privacy scan used by the verification command. Broader +`scripts/**` edits remain out of scope. + +## Not Allowed + +```text +backend/app/** +backend/alembic/versions/** +backend/tests/** +backend/scripts/** +frontend or demo UI work +payment/reputation/blockchain settlement +private source identifiers in committed evidence +database inspection as lifecycle proof +``` + +## Acceptance Criteria + +- Evidence shows every lifecycle step through API-visible request/response + facts. +- Evidence includes post-submit derivation input and output summaries. +- Evidence includes compiled post-submit policy hash and approved status. +- Evidence reads back approval actor, role, timestamp, setup context, source + snapshot id, source snapshot hash field presence/shape, and compiled policy + hash field presence/shape through APIs. Committed evidence must redact exact + source and policy hash values as `sha256:`. +- Evidence proves clean finalization to `review_pending`. +- Evidence proves worker-fixable post-submit failure to `needs_revision`. +- Evidence proves checker-caused `needs_revision` has + `outcome_source = auto_checker` and no human review decision id. +- Evidence proves fixed resubmission back to `review_pending`. +- Evidence proves internal setup/retry routes remain hidden from workers. +- Evidence proves operator-visible internal repair routes include bounded + reason, owner, next action, retry eligibility, and audit event id. +- Evidence is privacy-safe and contains no raw local paths, source-specific task + identifiers, source hashes, credentials, or replayable private refs. +- Privacy scan rejects exact source hashes while allowing approved redacted + provenance placeholders such as `sha256:`. +- A professional PDF report is generated when evidence volume exceeds a concise + Markdown review packet. + +## Verification Commands + +```bash +python3 scripts/check_stale_workstream_wording.py +python3 scripts/check_markdown_links.py +(cd backend && WORKSTREAM_DATABASE_URL=postgresql+asyncpg://workstream:workstream@localhost:5433/workstream_test .venv/bin/python scripts/api_contract_e2e.py) +(cd backend && WORKSTREAM_DATABASE_URL=postgresql+asyncpg://workstream:workstream@localhost:5433/workstream_test .venv/bin/python scripts/week2_api_e2e.py) +(cd backend && WORKSTREAM_DATABASE_URL=postgresql+asyncpg://workstream:workstream@localhost:5433/workstream_test OPENAI_API_KEY=\"${OPENAI_API_KEY:?set OpenAI key}\" WORKSTREAM_PROJECT_AGENT_OPENAI_AGENT_SDK_MODEL=\"${WORKSTREAM_PROJECT_AGENT_OPENAI_AGENT_SDK_MODEL:?set model}\" WORKSTREAM_TERMINAL_BENCH_FIXTURE=\"${WORKSTREAM_TERMINAL_BENCH_FIXTURE:?set fixture}\" WORKSTREAM_TERMINAL_BENCH_GUIDE_ROOT=\"${WORKSTREAM_TERMINAL_BENCH_GUIDE_ROOT:-}\" .venv/bin/python ../examples/terminal_benchmark/terminal_benchmark_api_e2e.py) +python3 -m py_compile scripts/privacy_scan_evidence.py +(cd backend && .venv/bin/python -m ruff check ../scripts/privacy_scan_evidence.py) +python3 scripts/privacy_scan_evidence.py .agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/reviews +git diff --check +``` + +Prerequisites: + +- local Postgres test database `workstream_test` +- backend dependencies installed in `backend/.venv` +- `OPENAI_API_KEY` set in local shell only; never committed +- `WORKSTREAM_PROJECT_AGENT_OPENAI_AGENT_SDK_MODEL` set to the approved local + OpenAI Agents SDK model for the drill +- `WORKSTREAM_TERMINAL_BENCH_FIXTURE` set to the sanitized local fixture path +- `WORKSTREAM_TERMINAL_BENCH_GUIDE_ROOT` set when the fixture needs a separate + guide-material root +- local API/worker execution configured exactly as the drill command requires +- only redacted evidence committed under + `.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/reviews/` + +If `scripts/privacy_scan_evidence.py` does not exist when this chunk starts, +the chunk must add it or replace it with an equivalent committed privacy scan +script before evidence is accepted. + +## Required Reviewers + +- senior engineering +- QA/test +- security/auth +- product/ops +- architecture +- docs +- reuse/dedup +- test delta +- CI integrity + +## Human Review Focus + +- Confirm the report proves behavior through APIs without DB inspection. +- Confirm Terminal Benchmark material is used only as a sanitized example. +- Confirm post-submit checker policy is project-scoped and deterministic. +- Confirm worker-facing lifecycle remains clear. diff --git a/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/chunks/WS-POL-002-PLAN-post-submit-checker-planning.md b/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/chunks/WS-POL-002-PLAN-post-submit-checker-planning.md new file mode 100644 index 000000000..0c709a6a3 --- /dev/null +++ b/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/chunks/WS-POL-002-PLAN-post-submit-checker-planning.md @@ -0,0 +1,78 @@ +# Chunk Contract: WS-POL-002-PLAN - Post-Submit Checker Foundation Planning + +## Parent Initiative + +`WS-POL-002` - Post-Submit Checker Foundation + +## Problem Being Solved + +The current post-submit checker runtime is durable and policy-locked, but the +project setup side is not yet as disciplined as pre-submit. Planning must close +the previous WS-POL-001 loop, discover the existing post-submit code path, and +define the smallest implementation chunks before code changes start. + +## Goal + +Produce intent, discovery, plan, decisions, risks, chunk map, and chunk +contracts for project-guide-derived post-submit checker setup. + +## Allowed Files + +```text +.agent-loop/LOOP_STATE.md +.agent-loop/WORK_QUEUE.md +.agent-loop/REVIEW_LOG.md +.agent-loop/initiatives/WS-POL-001-submission-artifact-policy-foundation/STATUS.md +.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/** +docs/roadmap_status.md +``` + +## Not Allowed + +```text +backend/app/** +backend/alembic/versions/** +backend/tests/** +backend/scripts/** +frontend or demo UI work +payment/reputation/blockchain settlement +runtime product behavior changes +``` + +## Acceptance Criteria + +- `WS-POL-001-16` loop memory is closed as merged through PR #84. +- `WS-POL-002` intent and discovery accurately describe the current + post-submit runtime and the missing setup pipeline. +- Plan preserves project-scoped `PostSubmitCheckerPolicy`; no per-task checker + generation is introduced. +- Plan defines exact setup trigger boundary after pre-submit approval/compile. +- Chunk contracts include allowed files, not-allowed changes, acceptance + criteria, verification commands, required reviewers, and human review focus. +- Internal reviewer findings are addressed or explicitly documented. + +## Verification Commands + +```bash +python3 scripts/check_stale_workstream_wording.py +python3 scripts/check_markdown_links.py +git diff --check +``` + +## Required Reviewers + +- senior engineering +- QA/test +- security/auth +- product/ops +- architecture +- docs +- reuse/dedup +- test delta +- CI integrity + +## Human Review Focus + +- Confirm the intent matches the desired post-submit checker direction. +- Confirm the setup trigger boundary is realistic against current code. +- Confirm implementation chunks are small enough to review. diff --git a/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/reviews/WS-POL-002-PLAN-internal-review-evidence.md b/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/reviews/WS-POL-002-PLAN-internal-review-evidence.md new file mode 100644 index 000000000..125dacacd --- /dev/null +++ b/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/reviews/WS-POL-002-PLAN-internal-review-evidence.md @@ -0,0 +1,115 @@ +# Internal Review Evidence: WS-POL-002-PLAN + +## Chunk + +`WS-POL-002-PLAN` - Post-Submit Checker Foundation Planning + +open sub-agent sessions: none + +valid findings addressed: yes + +## Reviewed Revision + +Base SHA: `a3d2a3f1701391c8dafdca6cff2f0f80dbebda3b` + +Reviewed at: 2026-07-09T07:51:21Z + +Reviewer run IDs: + +- senior-engineering: `019f45cc-18c8-7773-96e5-69718376bc68` +- QA/test: `019f45d6-0b10-7711-b93a-36829979e9b4` +- security/auth: `019f45d3-1319-7171-873b-85670bfcf071` +- product/ops: `019f45cc-3125-72c1-9396-4346ae293529` +- architecture: `019f45d3-0d52-7423-82a5-524a61841f86` +- docs: `019f45cc-453d-73c0-acd9-58f906dd27f4` +- reuse/dedup: `019f45d3-5206-75b1-a245-0c5fc8f015b3` +- test delta: `019f45d3-6067-78c0-8f2b-cc5001da3e17` +- CI integrity: `019f45d9-2c32-7df2-bdae-98d90a46e6d1` + +## Reviewed Change + +Scope: + +- Closed stale `WS-POL-001-16` loop memory after PR #84 merged. +- Started `WS-POL-002` planning for post-submit checker foundation. +- Added intent, discovery, plan, risks, decisions, status, chunk map, and chunk + contracts. +- Preserved project-scoped `PostSubmitCheckerPolicy`; no task-specific checker + generation is introduced. +- Defined a resumable setup boundary: initial guide/source setup stops at + `policy_draft_ready`; post-submit derivation starts only after setup-approved + submission artifact policy approval creates the effective policy and compiled + project pre-submit checker bundle. +- Kept v0.1 setup authorization honest: verified `admin` / `project_manager` + roles remain the current bootstrap boundary; project-scoped role assignment is + out of scope for WS-POL-002. + +## Reviewer Results + +| Reviewer | Result | Blocking findings | Notes | +|---|---:|---|---| +| senior engineering | PASS WITH LOW RISKS | None | Confirmed real Celery files, persistence scope, planning contract, and narrowed runtime scope after fixes. | +| QA/test | PASS | None | Confirmed feasible commands and resolved source-hash evidence contradiction. | +| security/auth | PASS | None | Confirmed v0.1 setup authorization wording, prompt-injection controls, redaction, and default-checker protections. | +| product/ops | PASS WITH LOW RISKS | None | Confirmed lifecycle/product routing boundaries; low clarifications were folded into final proof and runtime contracts. | +| architecture | PASS | None | Confirmed current authorization boundary, setup trigger boundary, model/migration scope, planning contract, and privacy scan path. | +| docs | PASS WITH LOW RISKS | None | Confirmed persistence scope, canonical wording, command shape, and docs clarity; env prerequisites were added. | +| reuse/dedup | PASS WITH LOW RISKS | None | Confirmed reuse of existing post-submit helpers and setup boundary; low notes were folded into chunk contracts. | +| test delta | PASS WITH LOW RISKS | None | Confirmed no tests were weakened; low notes on privacy scan lint and redacted hash proof were addressed. | +| CI integrity | PASS | None | Confirmed no CI changes and CI integrity reviewer is required where tests/scripts can change. | + +## Valid Findings Addressed + +- Added model/migration scope for post-submit policy provenance, approval + provenance, setup-run post-submit outputs, and lifecycle status. +- Added real setup worker/queue files to the derivation chunk. +- Corrected setup trigger boundary so post-submit derivation starts after + setup-approved submission artifact policy approval and pre-submit compilation, + not during initial source capture. +- Added explicit planning chunk contract. +- Replaced non-canonical `ProjectSubmissionArtifactPolicy` wording with + `SubmissionArtifactPolicy`. +- Required default-only post-submit policy support while preserving exact + platform default checker identity. +- Required prompt-injection tests and bounded/redacted setup summaries. +- Corrected authorization wording from project-scoped manager claims to the + current v0.1 verified `admin` / `project_manager` setup boundary. +- Required worker/reviewer/finance/auditor denials for new setup visibility and + approval endpoints. +- Added operator-visible internal route evidence requirements. +- Preserved checker-caused `needs_revision` provenance as + `outcome_source = auto_checker` with no human review decision id. +- Added executable Terminal Benchmark drill prerequisites and privacy scan + script scope. +- Required privacy scan lint/compile checks and redacted source-hash proof. +- Added CI integrity to chunks that allow tests or scripts. + +## Commands Run + +```bash +python3 scripts/check_stale_workstream_wording.py +python3 scripts/check_markdown_links.py +git diff --check +find .agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation -type f -print0 | xargs -0 -n1 sh -c 'for f do if grep -n "[[:blank:]]$" "$f"; then echo "trailing whitespace in $f"; exit 1; fi; done' sh +``` + +Results: + +- Stale wording check: passed. +- Markdown link check: passed for 18 changed Markdown files. +- `git diff --check`: passed. +- Extra whitespace scan over new untracked WS-POL-002 files: passed. + +## Residual Risks + +- `WS-POL-002-04` still allows broad task/checker module globs, but its target + behavior and acceptance criteria are narrowed to generated-policy runtime + deltas. Senior engineering accepted this as low risk. +- Project-scoped role assignment remains future Workstream authorization work. + WS-POL-002 must not pretend it exists. + +## Stop Condition + +No implementation chunk is active. `WS-POL-002-01` remains proposed and must not +start until the planning PR is reviewed, merged, and the user explicitly starts +the implementation chunk. diff --git a/docs/roadmap_status.md b/docs/roadmap_status.md index 55a2571d8..15fe2a329 100644 --- a/docs/roadmap_status.md +++ b/docs/roadmap_status.md @@ -48,6 +48,9 @@ Current phase: Week 3 review and revision preparation. - Chunk 13 task work-context, worker submission-requirements, and operator-only locked-context APIs. - Chunk 14 submission finalization, system actor pre-review gate audit semantics, scoped operator visibility, and HTTP-visible Terminal Benchmark proof. - Chunk 15 agent-derivation hardening after the accepted no-DB Terminal Benchmark drill exposed a required/forbidden self-conflict. +- Chunk 16 Terminal Benchmark live API drill with privacy-scrubbed evidence and + professional PDF report proving the current lifecycle through HTTP-visible + APIs without database inspection. ## Review Tracks Closed @@ -71,8 +74,9 @@ Current phase: Week 3 review and revision preparation. contract after the accepted no-DB Terminal Benchmark drill exposed a required/forbidden self-conflict; the drill now passes after hardening. - `WS-POL-001-16` completed a human-visible Terminal Benchmark live API drill - without database inspection as lifecycle proof; the privacy-scrubbed evidence - is at PR/human checkpoint. + without database inspection as lifecycle proof and merged through PR #84. +- `WS-POL-002` planning is open to make post-submit checker setup match the + project-guide-derived, compiler-validated, deterministic pre-submit pipeline. ## Pending Before Pilot From 5cced6d397f4126e708f884e96c0a493944483db Mon Sep 17 00:00:00 2001 From: Abiorh001 Date: Thu, 9 Jul 2026 09:27:26 +0100 Subject: [PATCH 2/4] Address WS-POL-002 planning review comments --- .../STATUS.md | 4 ++-- .../WS-POL-002-05-post-submit-live-api-proof.md | 11 ++++++++--- 2 files changed, 10 insertions(+), 5 deletions(-) diff --git a/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/STATUS.md b/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/STATUS.md index ac14c9cd5..bf7147650 100644 --- a/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/STATUS.md +++ b/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/STATUS.md @@ -17,7 +17,7 @@ None. ## Proposed First Implementation Chunk -`WS-POL-002-01` - Post-submit compiler and default policy contract. +`WS-POL-002-01` - Post-Submit Provenance And Compiler Contract. This chunk is inactive until the planning PR is reviewed and the user gives an explicit start signal. @@ -27,7 +27,7 @@ explicit start signal. | Chunk | Status | Branch | PR | Notes | |---|---|---|---:|---| | `WS-POL-002-PLAN` | Active planning | `codex/ws-pol-002-post-submit-checker-planning` | - | Defines intent, discovery, design, risks, decisions, and implementation chunks. | -| `WS-POL-002-01` | Proposed | - | - | Post-submit provenance model and compiler contract. | +| `WS-POL-002-01` | Proposed | - | - | Post-Submit Provenance And Compiler Contract. | | `WS-POL-002-02` | Proposed | - | - | Post-submit derivation agent and resumable setup integration after pre-submit approval/compile. | | `WS-POL-002-03` | Proposed | - | - | Server-owned approval and setup visibility APIs; remove manual guide payload. | | `WS-POL-002-04` | Proposed | - | - | Runtime hardening for locked post-submit policy execution and routing. | diff --git a/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/chunks/WS-POL-002-05-post-submit-live-api-proof.md b/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/chunks/WS-POL-002-05-post-submit-live-api-proof.md index ac210a5b8..90f689d4c 100644 --- a/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/chunks/WS-POL-002-05-post-submit-live-api-proof.md +++ b/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/chunks/WS-POL-002-05-post-submit-live-api-proof.md @@ -4,6 +4,10 @@ `WS-POL-002` - Post-Submit Checker Foundation +## Risk Class + +L1 + ## Problem Being Solved The implementation must be proven as a real operator/worker flow, not only by @@ -78,9 +82,10 @@ database inspection as lifecycle proof - Evidence proves operator-visible internal repair routes include bounded reason, owner, next action, retry eligibility, and audit event id. - Evidence is privacy-safe and contains no raw local paths, source-specific task - identifiers, source hashes, credentials, or replayable private refs. -- Privacy scan rejects exact source hashes while allowing approved redacted - provenance placeholders such as `sha256:`. + identifiers, raw source hashes, raw policy hashes, credentials, or replayable + private refs. +- Privacy scan rejects exact source and policy hashes while allowing approved + redacted provenance placeholders such as `sha256:`. - A professional PDF report is generated when evidence volume exceeds a concise Markdown review packet. From f07160145fd5b92515cfbbd1c78c81a583a86508 Mon Sep 17 00:00:00 2001 From: Abiorh001 Date: Thu, 9 Jul 2026 09:37:31 +0100 Subject: [PATCH 3/4] Normalize WS-POL-002 chunk contracts --- ...OL-002-01-post-submit-compiler-contract.md | 25 +++++++++++++++ ...POL-002-02-post-submit-derivation-agent.md | 25 +++++++++++++++ ...-post-submit-policy-approval-visibility.md | 25 +++++++++++++++ ...OL-002-04-post-submit-runtime-hardening.md | 25 +++++++++++++++ ...S-POL-002-05-post-submit-live-api-proof.md | 32 ++++++++++++++++--- ...L-002-PLAN-post-submit-checker-planning.md | 25 +++++++++++++++ 6 files changed, 152 insertions(+), 5 deletions(-) diff --git a/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/chunks/WS-POL-002-01-post-submit-compiler-contract.md b/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/chunks/WS-POL-002-01-post-submit-compiler-contract.md index 0546dceac..c5b7e3f30 100644 --- a/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/chunks/WS-POL-002-01-post-submit-compiler-contract.md +++ b/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/chunks/WS-POL-002-01-post-submit-compiler-contract.md @@ -4,6 +4,20 @@ `WS-POL-002` - Post-Submit Checker Foundation +## Approved Plan Reference + +- INTENT: `.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/INTENT.md` +- PLAN: `.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/PLAN.md` +- CHUNK_MAP: `.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/CHUNK_MAP.md` + +## Risk class + +L1 + +## SLA + +P1 + ## Problem Being Solved Post-submit policy currently has a canonical body and hash, but it lacks a @@ -124,3 +138,14 @@ git diff --check - Confirm the compiler, not the agent, owns canonical runtime policy. - Confirm project policy cannot weaken defaults. - Confirm no task-specific checker generation is introduced. + +## Stop conditions + +Stop and escalate if: + +- scope must expand beyond allowed files +- architecture direction changes +- auth/payment/policy/data boundary changes beyond this contract +- CI/test weakening is required to pass +- the same blocker remains after 2 repair attempts +- secrets or production data are needed diff --git a/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/chunks/WS-POL-002-02-post-submit-derivation-agent.md b/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/chunks/WS-POL-002-02-post-submit-derivation-agent.md index d53257b3a..69c2faa41 100644 --- a/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/chunks/WS-POL-002-02-post-submit-derivation-agent.md +++ b/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/chunks/WS-POL-002-02-post-submit-derivation-agent.md @@ -4,6 +4,20 @@ `WS-POL-002` - Post-Submit Checker Foundation +## Approved Plan Reference + +- INTENT: `.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/INTENT.md` +- PLAN: `.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/PLAN.md` +- CHUNK_MAP: `.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/CHUNK_MAP.md` + +## Risk class + +L1 + +## SLA + +P1 + ## Problem Being Solved Post-submit policy must be derived from project guide/source context instead of @@ -123,3 +137,14 @@ git diff --check - Confirm the agent derives setup policy only. - Confirm unsupported checker requirements fail closed. - Confirm no runtime submission judgment is delegated to an agent. + +## Stop conditions + +Stop and escalate if: + +- scope must expand beyond allowed files +- architecture direction changes +- auth/payment/policy/data boundary changes beyond this contract +- CI/test weakening is required to pass +- the same blocker remains after 2 repair attempts +- secrets or production data are needed diff --git a/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/chunks/WS-POL-002-03-post-submit-policy-approval-visibility.md b/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/chunks/WS-POL-002-03-post-submit-policy-approval-visibility.md index d4f0e48ad..729f1cdc6 100644 --- a/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/chunks/WS-POL-002-03-post-submit-policy-approval-visibility.md +++ b/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/chunks/WS-POL-002-03-post-submit-policy-approval-visibility.md @@ -4,6 +4,20 @@ `WS-POL-002` - Post-Submit Checker Foundation +## Approved Plan Reference + +- INTENT: `.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/INTENT.md` +- PLAN: `.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/PLAN.md` +- CHUNK_MAP: `.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/CHUNK_MAP.md` + +## Risk class + +L1 + +## SLA + +P1 + ## Problem Being Solved Operators need API-visible post-submit setup state. The old guide create/update @@ -108,3 +122,14 @@ git diff --check - Confirm there is one authoritative server-owned post-submit policy path. - Confirm obsolete manual payload fields are removed, not aliased. - Confirm visibility is useful for operators but safe for workers. + +## Stop conditions + +Stop and escalate if: + +- scope must expand beyond allowed files +- architecture direction changes +- auth/payment/policy/data boundary changes beyond this contract +- CI/test weakening is required to pass +- the same blocker remains after 2 repair attempts +- secrets or production data are needed diff --git a/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/chunks/WS-POL-002-04-post-submit-runtime-hardening.md b/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/chunks/WS-POL-002-04-post-submit-runtime-hardening.md index b9eb6da7a..4a96eaac3 100644 --- a/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/chunks/WS-POL-002-04-post-submit-runtime-hardening.md +++ b/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/chunks/WS-POL-002-04-post-submit-runtime-hardening.md @@ -4,6 +4,20 @@ `WS-POL-002` - Post-Submit Checker Foundation +## Approved Plan Reference + +- INTENT: `.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/INTENT.md` +- PLAN: `.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/PLAN.md` +- CHUNK_MAP: `.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/CHUNK_MAP.md` + +## Risk class + +L1 + +## SLA + +P1 + ## Problem Being Solved Runtime already locks and executes post-submit policy, but it must be hardened @@ -100,3 +114,14 @@ git diff --check - Confirm post-submit routing remains distinct from review decisions. - Confirm worker-facing responses stay understandable. - Confirm no pre-submit regression is introduced. + +## Stop conditions + +Stop and escalate if: + +- scope must expand beyond allowed files +- architecture direction changes +- auth/payment/policy/data boundary changes beyond this contract +- CI/test weakening is required to pass +- the same blocker remains after 2 repair attempts +- secrets or production data are needed diff --git a/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/chunks/WS-POL-002-05-post-submit-live-api-proof.md b/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/chunks/WS-POL-002-05-post-submit-live-api-proof.md index 90f689d4c..427a72343 100644 --- a/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/chunks/WS-POL-002-05-post-submit-live-api-proof.md +++ b/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/chunks/WS-POL-002-05-post-submit-live-api-proof.md @@ -4,10 +4,20 @@ `WS-POL-002` - Post-Submit Checker Foundation -## Risk Class +## Approved Plan Reference + +- INTENT: `.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/INTENT.md` +- PLAN: `.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/PLAN.md` +- CHUNK_MAP: `.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/CHUNK_MAP.md` + +## Risk class L1 +## SLA + +P1 + ## Problem Being Solved The implementation must be proven as a real operator/worker flow, not only by @@ -69,10 +79,11 @@ database inspection as lifecycle proof facts. - Evidence includes post-submit derivation input and output summaries. - Evidence includes compiled post-submit policy hash and approved status. -- Evidence reads back approval actor, role, timestamp, setup context, source - snapshot id, source snapshot hash field presence/shape, and compiled policy - hash field presence/shape through APIs. Committed evidence must redact exact - source and policy hash values as `sha256:`. +- Evidence reads back approval provenance, setup context, source snapshot id, + source snapshot hash field presence/shape, and compiled policy hash field + presence/shape through APIs. Committed evidence must show field presence/shape + or approved redacted placeholders for actor/source/setup identifiers, and must + redact exact source and policy hash values as `sha256:`. - Evidence proves clean finalization to `review_pending`. - Evidence proves worker-fixable post-submit failure to `needs_revision`. - Evidence proves checker-caused `needs_revision` has @@ -139,3 +150,14 @@ script before evidence is accepted. - Confirm Terminal Benchmark material is used only as a sanitized example. - Confirm post-submit checker policy is project-scoped and deterministic. - Confirm worker-facing lifecycle remains clear. + +## Stop conditions + +Stop and escalate if: + +- scope must expand beyond allowed files +- architecture direction changes +- auth/payment/policy/data boundary changes beyond this contract +- CI/test weakening is required to pass +- the same blocker remains after 2 repair attempts +- secrets or production data are needed diff --git a/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/chunks/WS-POL-002-PLAN-post-submit-checker-planning.md b/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/chunks/WS-POL-002-PLAN-post-submit-checker-planning.md index 0c709a6a3..4870c156e 100644 --- a/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/chunks/WS-POL-002-PLAN-post-submit-checker-planning.md +++ b/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/chunks/WS-POL-002-PLAN-post-submit-checker-planning.md @@ -4,6 +4,20 @@ `WS-POL-002` - Post-Submit Checker Foundation +## Approved Plan Reference + +- INTENT: `.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/INTENT.md` +- PLAN: `.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/PLAN.md` +- CHUNK_MAP: `.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/CHUNK_MAP.md` + +## Risk class + +L1 + +## SLA + +P1 + ## Problem Being Solved The current post-submit checker runtime is durable and policy-locked, but the @@ -76,3 +90,14 @@ git diff --check - Confirm the intent matches the desired post-submit checker direction. - Confirm the setup trigger boundary is realistic against current code. - Confirm implementation chunks are small enough to review. + +## Stop conditions + +Stop and escalate if: + +- scope must expand beyond allowed files +- architecture direction changes +- auth/payment/policy/data boundary changes beyond this contract +- CI/test weakening is required to pass +- the same blocker remains after 2 repair attempts +- secrets or production data are needed From bfb60254c2001c0cbfeff6618960e08c57d8d1c3 Mon Sep 17 00:00:00 2001 From: Abiorh001 Date: Thu, 9 Jul 2026 09:52:58 +0100 Subject: [PATCH 4/4] Refresh WS-POL-002 review evidence --- ...S-POL-002-PLAN-external-review-response.md | 62 ++++++ ...S-POL-002-PLAN-internal-review-evidence.md | 84 ++++---- .../WS-POL-002-PLAN-pr-trust-bundle.md | 180 ++++++++++++++++++ 3 files changed, 276 insertions(+), 50 deletions(-) create mode 100644 .agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/reviews/WS-POL-002-PLAN-external-review-response.md create mode 100644 .agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/reviews/WS-POL-002-PLAN-pr-trust-bundle.md diff --git a/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/reviews/WS-POL-002-PLAN-external-review-response.md b/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/reviews/WS-POL-002-PLAN-external-review-response.md new file mode 100644 index 000000000..956cac350 --- /dev/null +++ b/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/reviews/WS-POL-002-PLAN-external-review-response.md @@ -0,0 +1,62 @@ +# External Review Response + +## PR + +`https://github.com/Flow-Research/workstream/pull/85` + +## Chunk + +`WS-POL-002-PLAN` + +## Source + +CodeRabbit / GitHub checks + +## Summary + +CodeRabbit flagged missing PR-description structure, one inconsistent chunk +title, a missing risk-class declaration, and incomplete committed-evidence hash +redaction wording. GitHub Actions failed because internal review evidence was +not bound to the reviewed code SHA and had reviewer run IDs on separate lines. + +## External Findings + +| Source | Finding | Severity | Status | Response | +|---|---|---:|---:|---| +| CodeRabbit | PR description omitted required trust-bundle sections. | Warning | Fixed | Added a committed PR trust bundle and updated the PR body with the same structure. | +| CodeRabbit | `WS-POL-002-01` title differed between `STATUS.md` and `CHUNK_MAP.md`. | Trivial | Fixed | Normalized `STATUS.md` to `Post-Submit Provenance And Compiler Contract`. | +| CodeRabbit | `WS-POL-002-05` omitted explicit risk class. | Minor | Fixed | Added `Risk class: L1`; internal review then required the same metadata across every WS-POL-002 chunk contract. | +| CodeRabbit | Privacy scan acceptance criteria rejected raw source hashes but not raw policy hashes. | Major | Fixed | Updated the live proof contract to reject exact source and policy hashes and require `sha256:` placeholders. | +| GitHub Actions | Agent Gates and Backend failed internal review evidence validation. | Major | Fixed locally | Replaced stale `Base SHA` evidence with `Reviewed code SHA` and same-line reviewer run IDs. | + +## Fix plan + +- Normalize the first implementation chunk title. +- Add approved-plan reference, risk class, SLA, and stop conditions to every + WS-POL-002 chunk contract. +- Tighten evidence privacy wording for source hashes, policy hashes, and + actor/source/setup identifiers. +- Add this external review response and a PR trust bundle. +- Update internal review evidence to bind reviewer output to + `f07160145fd5b92515cfbbd1c78c81a583a86508`. +- Rerun local gates, push the branch, and allow GitHub checks and CodeRabbit to + rerun on the updated PR head. + +## Out-of-scope items to defer + +None. + +## Evidence after fixes + +```bash +python3 scripts/check_stale_workstream_wording.py +python3 scripts/check_markdown_links.py +python3 scripts/check_internal_review_evidence.py +git diff --check +``` + +Expected PR follow-up: + +```text +GitHub Actions and CodeRabbit must rerun on the pushed branch head before merge. +``` diff --git a/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/reviews/WS-POL-002-PLAN-internal-review-evidence.md b/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/reviews/WS-POL-002-PLAN-internal-review-evidence.md index 125dacacd..9717861ad 100644 --- a/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/reviews/WS-POL-002-PLAN-internal-review-evidence.md +++ b/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/reviews/WS-POL-002-PLAN-internal-review-evidence.md @@ -10,21 +10,11 @@ valid findings addressed: yes ## Reviewed Revision -Base SHA: `a3d2a3f1701391c8dafdca6cff2f0f80dbebda3b` +Reviewed code SHA: f07160145fd5b92515cfbbd1c78c81a583a86508 -Reviewed at: 2026-07-09T07:51:21Z +Reviewed at: 2026-07-09T08:46:42Z -Reviewer run IDs: - -- senior-engineering: `019f45cc-18c8-7773-96e5-69718376bc68` -- QA/test: `019f45d6-0b10-7711-b93a-36829979e9b4` -- security/auth: `019f45d3-1319-7171-873b-85670bfcf071` -- product/ops: `019f45cc-3125-72c1-9396-4346ae293529` -- architecture: `019f45d3-0d52-7423-82a5-524a61841f86` -- docs: `019f45cc-453d-73c0-acd9-58f906dd27f4` -- reuse/dedup: `019f45d3-5206-75b1-a245-0c5fc8f015b3` -- test delta: `019f45d3-6067-78c0-8f2b-cc5001da3e17` -- CI integrity: `019f45d9-2c32-7df2-bdae-98d90a46e6d1` +Reviewer run IDs: senior-engineering=019f4607-7d3d-75f1-9f95-1c97e6a754ed; QA/test=019f4607-9e65-7dd3-a4a1-e5902738c7ae; security/auth=019f4607-c400-7d70-ba90-d3a864da5619; product/ops=019f4607-e130-7183-935e-399d7c0da675; architecture=019f4608-0acf-72a0-a876-f9e0b2d1f8c6; docs=019f4609-1043-76f0-9474-7a0ecb9d43eb; CI-integrity=019f4610-a68c-7742-bff9-6b89fa3931c9 ## Reviewed Change @@ -43,46 +33,40 @@ Scope: - Kept v0.1 setup authorization honest: verified `admin` / `project_manager` roles remain the current bootstrap boundary; project-scoped role assignment is out of scope for WS-POL-002. +- Addressed CodeRabbit and internal-review findings by normalizing chunk titles, + adding required chunk metadata, tightening committed-evidence redaction, and + adding external review and PR trust artifacts. ## Reviewer Results | Reviewer | Result | Blocking findings | Notes | |---|---:|---|---| -| senior engineering | PASS WITH LOW RISKS | None | Confirmed real Celery files, persistence scope, planning contract, and narrowed runtime scope after fixes. | -| QA/test | PASS | None | Confirmed feasible commands and resolved source-hash evidence contradiction. | -| security/auth | PASS | None | Confirmed v0.1 setup authorization wording, prompt-injection controls, redaction, and default-checker protections. | -| product/ops | PASS WITH LOW RISKS | None | Confirmed lifecycle/product routing boundaries; low clarifications were folded into final proof and runtime contracts. | -| architecture | PASS | None | Confirmed current authorization boundary, setup trigger boundary, model/migration scope, planning contract, and privacy scan path. | -| docs | PASS WITH LOW RISKS | None | Confirmed persistence scope, canonical wording, command shape, and docs clarity; env prerequisites were added. | -| reuse/dedup | PASS WITH LOW RISKS | None | Confirmed reuse of existing post-submit helpers and setup boundary; low notes were folded into chunk contracts. | -| test delta | PASS WITH LOW RISKS | None | Confirmed no tests were weakened; low notes on privacy scan lint and redacted hash proof were addressed. | -| CI integrity | PASS | None | Confirmed no CI changes and CI integrity reviewer is required where tests/scripts can change. | +| senior engineering | PASS AFTER FIXES | None | Content passed; evidence provenance and remote push findings are addressed by this evidence update and follow-up push. | +| QA/test | PASS WITH LOW RISKS | None | Confirmed contract metadata and CodeRabbit fixes; remote push was the only remaining low note. | +| security/auth | PASS | None | Confirmed raw source hashes, raw policy hashes, actor/source/setup identifiers, secrets, local paths, and private refs are handled safely. | +| product/ops | PASS AFTER FIXES | None | Product lifecycle passed; evidence provenance and PR trust bundle findings are addressed in this review artifact update. | +| architecture | PASS WITH LOW RISKS | None | Confirmed project-scoped policy, deterministic runtime, no per-task checker generation; broad future runtime globs remain accepted low risk. | +| docs | PASS AFTER FIXES | None | Canonical wording and chunk content passed; external response and trust-bundle findings are addressed in this review artifact update. | +| CI integrity | PASS | None | Confirmed no workflow, script, package, or CI configuration changes; local evidence gate passes and artifacts do not overclaim remote checks. | +| reuse/dedup | N/A - with approved reason | N/A | No skills, agents, backend app code, or scripts changed in this repair. | +| test delta | N/A - with approved reason | N/A | No tests or test-like files changed in this repair. | ## Valid Findings Addressed -- Added model/migration scope for post-submit policy provenance, approval - provenance, setup-run post-submit outputs, and lifecycle status. -- Added real setup worker/queue files to the derivation chunk. -- Corrected setup trigger boundary so post-submit derivation starts after - setup-approved submission artifact policy approval and pre-submit compilation, - not during initial source capture. -- Added explicit planning chunk contract. -- Replaced non-canonical `ProjectSubmissionArtifactPolicy` wording with - `SubmissionArtifactPolicy`. -- Required default-only post-submit policy support while preserving exact - platform default checker identity. -- Required prompt-injection tests and bounded/redacted setup summaries. -- Corrected authorization wording from project-scoped manager claims to the - current v0.1 verified `admin` / `project_manager` setup boundary. -- Required worker/reviewer/finance/auditor denials for new setup visibility and - approval endpoints. -- Added operator-visible internal route evidence requirements. -- Preserved checker-caused `needs_revision` provenance as - `outcome_source = auto_checker` with no human review decision id. -- Added executable Terminal Benchmark drill prerequisites and privacy scan - script scope. -- Required privacy scan lint/compile checks and redacted source-hash proof. -- Added CI integrity to chunks that allow tests or scripts. +- CodeRabbit: added explicit `Risk class` to `WS-POL-002-05`. +- CodeRabbit: updated privacy proof criteria to reject raw source and policy + hashes and require `sha256:` placeholders for committed evidence. +- CodeRabbit: normalized the `WS-POL-002-01` title in `STATUS.md` to match + `CHUNK_MAP.md`. +- Internal architecture/QA/docs: added approved-plan references, `Risk class`, + `SLA`, and stop conditions to every WS-POL-002 chunk contract. +- Internal security: tightened committed-evidence handling so actor/source/setup + identifiers are represented by field presence/shape or approved redacted + placeholders. +- Internal product/docs: added a separate external review response artifact and + PR trust bundle instead of mixing CodeRabbit findings into internal evidence. +- CI: replaced stale `Base SHA` provenance with `Reviewed code SHA` and made + reviewer run IDs parseable on one line for `check_internal_review_evidence.py`. ## Commands Run @@ -90,21 +74,21 @@ Scope: python3 scripts/check_stale_workstream_wording.py python3 scripts/check_markdown_links.py git diff --check -find .agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation -type f -print0 | xargs -0 -n1 sh -c 'for f do if grep -n "[[:blank:]]$" "$f"; then echo "trailing whitespace in $f"; exit 1; fi; done' sh +for f in .agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/chunks/*.md; do rg -n "^## (Approved Plan Reference|Risk class|SLA|Stop conditions)$" "$f"; done ``` Results: - Stale wording check: passed. -- Markdown link check: passed for 18 changed Markdown files. +- Markdown link check: passed for 19 changed Markdown files. - `git diff --check`: passed. -- Extra whitespace scan over new untracked WS-POL-002 files: passed. +- Chunk metadata heading scan: passed for every WS-POL-002 chunk contract. -## Residual Risks +## Remaining Risks - `WS-POL-002-04` still allows broad task/checker module globs, but its target behavior and acceptance criteria are narrowed to generated-policy runtime - deltas. Senior engineering accepted this as low risk. + deltas. Architecture accepted this as low risk. - Project-scoped role assignment remains future Workstream authorization work. WS-POL-002 must not pretend it exists. diff --git a/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/reviews/WS-POL-002-PLAN-pr-trust-bundle.md b/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/reviews/WS-POL-002-PLAN-pr-trust-bundle.md new file mode 100644 index 000000000..9ea344332 --- /dev/null +++ b/.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/reviews/WS-POL-002-PLAN-pr-trust-bundle.md @@ -0,0 +1,180 @@ +# PR Trust Bundle + +## Chunk + +`WS-POL-002-PLAN` - Post-Submit Checker Foundation Planning + +## Goal + +Close the previous WS-POL-001 loop state and create the reviewed planning +foundation for project-guide-derived post-submit checker setup. + +## Human-approved intent + +- Intent: `.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/INTENT.md` +- Plan: `.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/PLAN.md` +- Chunk contract: `.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/chunks/WS-POL-002-PLAN-post-submit-checker-planning.md` + +## What changed + +- Closed stale `WS-POL-001-16` loop state after PR #84 merged. +- Added WS-POL-002 intent, discovery, plan, decisions, risks, status, chunk map, + and six chunk contracts. +- Normalized every WS-POL-002 chunk contract with approved-plan reference, risk + class, SLA, allowed files, not-allowed changes, acceptance criteria, + verification commands, reviewer set, human review focus, and stop conditions. +- Added external review response and refreshed internal review evidence. + +## Why it changed + +Post-submit checker setup needs the same discipline as pre-submit: setup-time +derivation, trusted compilation, project-scoped policy, deterministic runtime, +and no manual guide request-body checker payloads. + +## Design chosen + +The plan keeps `PostSubmitCheckerPolicy` project-scoped. An agent may derive a +constrained setup specification from approved project guide/source context, but +Workstream compiles deterministic checker policy and runtime executes only the +locked compiled policy. + +## Alternatives rejected + +- Per-task checker generation: rejected because tasks should lock references to + the project policy/checker context, not compile their own checkers. +- Runtime agent judgment: rejected because submission checks must be + deterministic and auditable. +- Manual guide payloads for post-submit policy: rejected because policy setup is + server-owned. + +## Scope control + +### Allowed files changed + +- `.agent-loop/LOOP_STATE.md` +- `.agent-loop/WORK_QUEUE.md` +- `.agent-loop/REVIEW_LOG.md` +- `.agent-loop/initiatives/WS-POL-001-submission-artifact-policy-foundation/STATUS.md` +- `.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/**` +- `docs/roadmap_status.md` + +### Files outside scope + +- None. + +## Product Behavior + +- [x] No Workstream product runtime behavior changed. +- [ ] Product behavior changed and is explained here: + +## Acceptance criteria proof + +- [x] WS-POL-001 loop memory closed - `LOOP_STATE.md`, `WORK_QUEUE.md`, + `REVIEW_LOG.md`, and WS-POL-001 status updated. +- [x] WS-POL-002 planning artifacts created - intent, discovery, plan, decisions, + risks, status, chunk map, and chunk contracts added. +- [x] Project-scoped post-submit policy preserved - plan and chunks reject + per-task checker generation. +- [x] External review findings handled - see + `.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/reviews/WS-POL-002-PLAN-external-review-response.md`. +- [x] Internal review evidence refreshed - see + `.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/reviews/WS-POL-002-PLAN-internal-review-evidence.md`. + +## Tests/checks run + +```bash +python3 scripts/check_stale_workstream_wording.py +python3 scripts/check_markdown_links.py +python3 scripts/check_internal_review_evidence.py +git diff --check +for f in .agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/chunks/*.md; do rg -n "^## (Approved Plan Reference|Risk class|SLA|Stop conditions)$" "$f"; done +``` + +Result summary: + +```text +Local stale wording, Markdown links, internal review evidence, chunk metadata +scan, and diff whitespace checks passed after the review-artifact update. +``` + +## Test delta + +### Tests added + +- None. + +### Tests modified + +- None. + +### Tests removed/skipped + +- None. + +## CI integrity + +- [x] Coverage threshold unchanged +- [x] Lint unchanged +- [x] Typecheck unchanged +- [x] No workflow weakening +- [x] No package script weakening +- [x] No unpinned new GitHub Action +- [x] Checkout credential persistence unchanged + +## External review + +External review response file: + +- `.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/reviews/WS-POL-002-PLAN-external-review-response.md` + +| Source | Status | Notes | +|---|---:|---| +| CodeRabbit | Fixed locally | Title, risk class, privacy wording, and PR-description structure addressed. | +| GitHub checks | Fixed locally | Evidence provenance updated; checks must rerun on pushed head. | + +## Reviewer results + +Reviewed code SHA: f07160145fd5b92515cfbbd1c78c81a583a86508 + +Reviewed at: 2026-07-09T08:46:42Z + +Reviewer run IDs: senior-engineering=019f4607-7d3d-75f1-9f95-1c97e6a754ed; QA/test=019f4607-9e65-7dd3-a4a1-e5902738c7ae; security/auth=019f4607-c400-7d70-ba90-d3a864da5619; product/ops=019f4607-e130-7183-935e-399d7c0da675; architecture=019f4608-0acf-72a0-a876-f9e0b2d1f8c6; docs=019f4609-1043-76f0-9474-7a0ecb9d43eb; CI-integrity=019f4610-a68c-7742-bff9-6b89fa3931c9 + +| Reviewer | Result | Blocking findings | Notes | +|---|---:|---|---| +| senior engineering | PASS AFTER FIXES | None | Evidence provenance and push findings addressed by follow-up review artifact/push. | +| QA/test | PASS WITH LOW RISKS | None | Remote push was the only remaining low note. | +| security/auth | PASS | None | Privacy and redaction contract passed. | +| product/ops | PASS AFTER FIXES | None | Trust bundle and evidence findings addressed by this artifact. | +| architecture | PASS WITH LOW RISKS | None | Broad future runtime globs accepted as low risk. | +| docs | PASS AFTER FIXES | None | External response/trust-bundle findings addressed by this artifact. | +| CI integrity | PASS | None | Confirmed no workflow, script, package, or CI configuration changes; local evidence gate passes and artifacts do not overclaim remote checks. | + +## Remaining risks + +- `WS-POL-002-04` still allows broad future runtime globs. Architecture accepted + this as low risk because the acceptance criteria constrain the allowed work to + generated-policy runtime deltas. +- GitHub checks must rerun on the pushed PR head before merge. + +## Follow-up work + +Start `WS-POL-002-01` only after this planning PR is reviewed, merged by the +user, and the user explicitly starts the implementation chunk. + +## Human review focus + +Please inspect: + +- the project-scoped post-submit checker setup direction +- the setup-time derivation versus deterministic runtime boundary +- the v0.1 setup authorization boundary +- the WS-POL-002 chunk sequence and stop condition before implementation starts + +## Human ownership + +- [ ] I can explain what changed. +- [ ] I can explain why it changed. +- [ ] I know what could break. +- [ ] I accept the remaining risks. +- [ ] The user explicitly approved this specific PR for merge.