Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
34 changes: 19 additions & 15 deletions .agent-loop/LOOP_STATE.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,23 +2,27 @@

## Current State

- Active initiative: `WS-AUTH-001` - Workstream Authorization Service
- Active initiative: `WS-POL-002` - Post-Submit Checker Foundation
- Active planning chunk: none
- Active implementation chunk: none
- Branch: none for implementation; post-merge memory is on
`codex/ws-auth-001-post-merge-memory`
- Status: WS-AUTH-001 planning merged through PR #91. The initiative is stopped
at the L0 human checkpoint: D1-D3 are approved; D4-D10 require explicit
approval.
- Active implementation chunk: `WS-POL-002-03` - Server-Owned Policy Approval
And Visibility APIs
- Branch: `codex/ws-pol-002-03-post-submit-approval-visibility`
- Status: `WS-POL-002-03` implemented and internally reviewed; pull request
created at `https://github.com/Flow-Research/workstream/pull/90`.
- Last merged implementation SHA: `67fb3ca`
- Last merge commit: `ad6d6444e497b76d7cb925f3b0999ed4b74a3dac`
- Current gate: explicit durable human approval of D4-D10 followed by a
separate start signal for a fresh `WS-AUTH-001-01` worktree/branch. Planning
evidence is recorded at the WS-AUTH-001 internal review evidence path.
- Next chunk: `WS-AUTH-001-01` remains proposed until D4-D10 approval and a
separate implementation start signal.
- Paused initiative: `WS-POL-002`; chunk `WS-POL-002-03` must not start before
the relevant authorization foundation and an explicit resume signal.
- Last merge commit: `14fb216`
- Current gate: external review, GitHub checks, and user review.
- Next chunk: `WS-POL-002-04` remains inactive until `WS-POL-002-03` is merged
by explicit human approval and memory is updated.
Comment thread
coderabbitai[bot] marked this conversation as resolved.
- Checkpointed initiative: `WS-AUTH-001` - Workstream Authorization Service
- Checkpointed planning artifact: `WS-AUTH-001-PLAN`
- Status: WS-AUTH-001 planning merged through PR #91, post-merge memory merged
through PR #92, and the initiative is stopped at the L0 human checkpoint. It
is not the active implementation stream while PR #90 is current.
- Current gate: explicit durable human approval of D4-D10 before any
authorization implementation chunk starts.
- Next authorization chunk: `WS-AUTH-001-01` remains proposed until D4-D10
approval and a separate implementation start signal.

## Operating Rule

Expand Down
33 changes: 33 additions & 0 deletions .agent-loop/REVIEW_LOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,38 @@
# Review Log

## WS-POL-002-03

Status: implemented and internally reviewed on branch
`codex/ws-pol-002-03-post-submit-approval-visibility`; pull request #90 is
current with local CodeRabbit-response fixes complete and external checks
pending for the next pushed head.

Required reviewer tracks:

- senior engineering
- QA/test
- security/auth
- product/ops
- architecture
- CI integrity
- docs
- reuse/dedup
- test delta

Result: PASS after fixes locally; external review and GitHub checks must rerun
after the next push.

Scope: server-owned post-submit checker policy setup visibility, approval, and
correction APIs; safe operator summaries; immutable approval provenance; and
negative authorization coverage for non-setup roles.

Evidence: `.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/reviews/WS-POL-002-03-internal-review-evidence.md`

Trust bundle: `.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/reviews/WS-POL-002-03-pr-trust-bundle.md`

Next chunk: `WS-POL-002-04` remains inactive until this PR is externally
reviewed, merged by explicit human approval, and followed by memory update.

## WS-POL-002-02

Status: merged through PR #88 on 2026-07-11.
Expand Down
18 changes: 14 additions & 4 deletions .agent-loop/WORK_QUEUE.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,14 +2,22 @@

## In Progress

None. WS-AUTH-001 planning is merged and no implementation chunk is active.
| Chunk | Title | Risk | Status |
|---|---|---:|---|
| `WS-POL-002-03` | Server-Owned Policy Approval And Visibility APIs | L1 | Pull request #90 current; current `main` merged locally; evidence rebind and external checks pending |

## Planned Next

| Chunk | Title | Risk | Status |
|---|---|---:|---|
| `WS-POL-002-04` | Locked Runtime Execution And Routing Hardening | L1 | Inactive until explicit user start after `WS-POL-002-03` merge |
| `WS-AUTH-001-01` | Adopt Authorization Baseline And Repository Contracts | L1 | Proposed after D4-D10 approval and explicit start |
| `WS-POL-002-03` | Server-Owned Policy Approval And Visibility APIs | L1 | Paused behind WS-AUTH-001 and explicit resume |

## Human Checkpoints

| Gate | Initiative | Risk | Status |
|---|---|---:|---|
| D4-D10 approval | `WS-AUTH-001` | L0 | Stopped at human checkpoint; explicit D4-D10 approval required before implementation |

## Completed

Expand Down Expand Up @@ -41,9 +49,11 @@ None. WS-AUTH-001 planning is merged and no implementation chunk is active.

## Proposed Next

Do not start `WS-POL-002-04` until `WS-POL-002-03` is externally reviewed,
merged by explicit human approval, and followed by memory update.
Stop at the WS-AUTH-001 planning human checkpoint. Do not activate
`WS-AUTH-001-01` before explicit D4-D10 approval and a separate start signal;
do not resume `WS-POL-002-03` while auth has priority.
`WS-AUTH-001-01` before explicit D4-D10 approval and a separate start signal.
Future WS-POL work after PR #90 also requires a separate start signal.

## Blocked

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@ reviewed, merged by explicit human approval, and followed by a memory update.
|---|---|---:|---|
| `WS-POL-002-01` | Post-Submit Compiler Contract | L1 | Merged |
| `WS-POL-002-02` | Post-Submit Derivation Agent And Resumable Setup Integration | L1 | Merged |
| `WS-POL-002-03` | Server-Owned Policy Approval And Visibility APIs | L1 | Paused behind WS-AUTH-001 and explicit resume |
| `WS-POL-002-03` | Server-Owned Policy Approval And Visibility APIs | L1 | In review |
| `WS-POL-002-04` | Locked Runtime Execution And Routing Hardening | L1 | Proposed |
| `WS-POL-002-05` | Terminal Benchmark Post-Submit Live API Proof | L1 | Proposed |

Expand All @@ -32,5 +32,6 @@ After each implementation chunk is reviewed, externally checked, and merged by
explicit human approval, perform the memory update before starting the next
chunk.

The initiative is currently paused after chunk 02 by explicit human priority
for `WS-AUTH-001`. Do not start chunk 03 automatically.
`WS-POL-002-03` is current in PR #90 after an explicit user start. Do not start
`WS-POL-002-04` automatically after PR #90; it requires merge, memory update,
and a separate explicit start signal.
Original file line number Diff line number Diff line change
Expand Up @@ -5,11 +5,6 @@
Planning completed and merged through PR #85 as
`3fc1a688743f13476d6092078d40792592823d27`.

The initiative is paused after chunk 02 by the user's 2026-07-11 decision to
prioritize `WS-AUTH-001`. No later chunk may start until the relevant
authorization foundation exists and the user explicitly resumes this
initiative.

`WS-POL-002-01` merged through PR #87 as `ed52c21` on 2026-07-09. It
implemented the version-stamped trusted post-submit compiler contract,
default-checker snapshot validation, canonical policy hashing, and tests around
Expand All @@ -21,17 +16,22 @@ continuation, generated project `PostSubmitCheckerPolicy` persistence, automatic
contributor submission handoff to the pre-review gate, and repair-only
`/finalize` semantics.

`WS-POL-002-03` is implemented and internally reviewed on branch
`codex/ws-pol-002-03-post-submit-approval-visibility`; pull request #90 is
current with local CodeRabbit-response fixes complete; push and external checks
are pending.

## Active Planning Chunk

None.

## Active Implementation Chunk

None.
`WS-POL-002-03` - Server-Owned Policy Approval And Visibility APIs

## Current Implementation Branch

`main`
`codex/ws-pol-002-03-post-submit-approval-visibility`

## Chunk Status

Expand All @@ -40,12 +40,12 @@ None.
| `WS-POL-002-PLAN` | Merged | `codex/ws-pol-002-post-submit-checker-planning` | #85 | Defines intent, discovery, design, risks, decisions, and implementation chunks. |
| `WS-POL-002-01` | Merged | `codex/ws-pol-002-01-post-submit-compiler` | #87 | Post-Submit Compiler Contract; merged as `ed52c21`. |
| `WS-POL-002-02` | Merged | `codex/ws-pol-002-02-post-submit-derivation` | #88 | Post-submit derivation agent and resumable setup integration; merged as `32af6a7`. |
| `WS-POL-002-03` | Paused | - | - | Server-owned approval and setup visibility APIs; paused behind WS-AUTH-001 and explicit resume. |
| `WS-POL-002-03` | In review | `codex/ws-pol-002-03-post-submit-approval-visibility` | #90 | Server-owned approval and setup visibility APIs for compiled post-submit policies. |
| `WS-POL-002-04` | Proposed | - | - | Runtime hardening for locked post-submit policy execution and routing. |
| `WS-POL-002-05` | Proposed | - | - | Terminal Benchmark-style live API proof and report. |

## Blockers

| Blocker | Owner | Next action |
|---|---|---|
| `WS-AUTH-001` priority | Authorization foundation must precede new setup approval APIs | Complete relevant auth cutover, then require explicit user resume |
| none | none | none |
Original file line number Diff line number Diff line change
Expand Up @@ -36,6 +36,9 @@ server-owned approval/correction path for compiled post-submit checker policies.
policy hash under the current v0.1 bootstrap authorization boundary.
- Setup-authorized admin or project_manager can approve or request setup
correction for the generated project post-submit policy.
- Correction supersedes rather than deletes the rejected compiled policy,
preserves actor/reason/hash/body provenance, supplies bounded feedback to
rederivation, and rejects an unchanged replacement.
- Guide create/update continues to reject `post_submit_checker_policy` from
clients.
- Guide activation requires the approved compiled project
Expand All @@ -53,13 +56,19 @@ backend/app/modules/projects/service.py
backend/app/modules/projects/schemas.py
backend/app/modules/projects/repository.py
backend/app/modules/projects/models.py
backend/app/interfaces/project_agents.py
backend/app/adapters/project_agents/openai_agent_sdk.py
backend/alembic/versions/**
backend/tests/test_alembic.py
backend/tests/test_projects.py
backend/tests/test_auth.py
docs/product_first_user_flows.md
docs/operations_project_operating_manual.md
docs/operations_queue_policy.md
docs/architecture_data_model.md
docs/architecture_checker_framework.md
docs/architecture_lifecycle_state_machine.md
docs/current_system_data_flow.html
.agent-loop/initiatives/WS-POL-002-post-submit-checker-foundation/**
.agent-loop/LOOP_STATE.md
.agent-loop/WORK_QUEUE.md
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,59 @@
# External Review Response: WS-POL-002-03

## Comments Addressed

- GitHub Actions Agent Gates and Backend both failed at the internal review
evidence gate on PR head `8414dbdffcbcec108f0e736a06e7bbc750eca18b`.
The failure was valid: `main` had been merged into the PR branch after the
original evidence was bound, so the reviewed SHA was stale.
- Rebound `WS-POL-002-03` internal review evidence and PR trust bundle to the
merged PR head before this evidence-only repair commit.
- CodeRabbit found stale/conflicting lifecycle state across `LOOP_STATE.md`,
`WORK_QUEUE.md`, `REVIEW_LOG.md`, WS-POL-002 status/chunk-map artifacts, and
product/operator docs.
- Fixed the valid lifecycle-state comments by representing PR #90 as the current
`WS-POL-002-03` review chunk, removing duplicate or stale paused rows, and
marking future WS-POL work as separately gated.
- Fixed the valid correction-flow comment by stating that correction requests
block activation, supersede and retain rejected output, requeue regeneration,
and do not satisfy the approval gate.
- A later CodeRabbit thread targeted WS-AUTH planning wording that entered PR
#90 through merge-state reconciliation. Rather than changing the separate
authorization initiative from this WS-POL chunk, all WS-AUTH initiative-file
deltas were removed; that worktree remains independent.
- Internal review then found that destructive correction cleanup could erase
audit provenance and rerun the same agent input. The repair now retains
superseded policy rows, supplies bounded exact-context correction feedback,
rejects unchanged replacements, and distinguishes correction from upstream
policy supersession.

## Comments Deferred

- None.

## Human Decisions Needed

- None from external review at this point.

## Commands Rerun

```bash
gh run view 29157251423 --log-failed
gh run view 29157251426 --log-failed
cd backend && .venv/bin/pytest tests/test_projects.py -q -k "post_submit_checker_policy or post_submit_setup_visibility"
cd backend && .venv/bin/pytest tests/test_alembic.py -q
cd backend && .venv/bin/pytest tests/test_auth.py -q
cd backend && .venv/bin/ruff check app tests scripts
cd backend && .venv/bin/docstr-coverage --config .docstr.yaml
python3 scripts/check_internal_review_evidence.py
python3 scripts/check_loop_memory_state.py
python3 scripts/check_stale_workstream_wording.py
python3 scripts/check_markdown_links.py
git diff --check
```

## Remaining Risks

- The current fixes are bound to reviewed non-evidence commit
`0e59873971db8c2a7d9d6f9f7e725cb902eb888e`.
- CodeRabbit and GitHub Actions must rerun on the final evidence-only pushed head.
Loading
Loading