DUB-00031: enumerate Mementos project resources - #75
Conversation
Add stable revision-bound pagination, exact readback, API/SDK/CLI/OpenAPI surfaces, and SQLite/PostgreSQL coverage for explicit project-owned resources. Agent: Theophrastus
|
[ADVERSARIAL REVIEW ARTIFACT — CYCLE 1] Exact candidate: a88133d P1 — reachable hardcoded authority binding. Literal controls:
Affected lanes: live capability/resource binding; guarded project updates; memory-project linkage and receipt partitioning; registration/readback reconciliation; SQLite/PostgreSQL deployments without explicit identity configuration. All other reviewed gates passed: focused 22/0; full 2535/0; live PostgreSQL 5/0; typecheck/build/contracts/no-cloud/artifact/diff rc=0; gitleaks no leaks; GitHub test success. Focused remediation cycle 1 is limited to replacing the reachable fallback with package-owned live identity or fail-closed behavior, plus direct regressions and the affected lanes above. The same reviewer is fixed for re-review; P2/P3/optional/out-of-scope concerns are non-blocking. |
|
[REVIEW] NO_GO — #75 @ a88133d — lens: correctness+security+gates, reviewer Xenon (1 of 1) Reviewed the full diff for all 18 changed files against freshly fetched Gates and controls run unpiped:
Blocking P0/P1 findings:
Required remedy: bind all three identity components to the authoritative live configuration, or fail closed before advertising resources or accepting guarded project/memory-link operations when any component is absent. Add negative regression coverage proving the unconfigured public capability/resource page and both guarded mutation surfaces reject rather than emit or accept Non-blocking follow-ups: none. |
Agent: Theophrastus
|
Focused remediation cycle 1 is pushed on the existing PR. Candidate: 431afab, tree 6eefd44e14cf3a6a086095c0dd4e6cdb48927cfa, unchanged base cb2c4c4. Named P1 fix: removed the mementos/default/default resolver fallback, added MEMENTOS_PROJECT_AUTHORITY_UNCONFIGURED fail-closed behavior, and replaced import-time guarded project/memory-link identity caches with lazy live resolution. Explicit option/env configuration remains supported. Tests now use an explicit test-only tuple. Literal controls: Affected lanes: identity regression 2 pass/0 fail; registration/resource/guarded project/memory-link API+SDK+CLI matrix 52 pass/0 fail; live server integration 62 pass/0 fail; typecheck rc=0; build rc=0; live PostgreSQL 5 checks PASS and throwaway database absence readback 0; contracts fixtures rc=0; no-cloud rc=0; diff check rc=0; staged and one-commit gitleaks scans no leaks. Full 2535-test suite was not repeated because the fix reaches only authority-dependent lanes and the exact parent candidate already passed it; affected lanes plus live server/PG were rerun instead. Non-blocking pre-existing contract-manifest state: contracts repo-conformance still rejects storage.mode and postgres spelling in unchanged hasna.contract.json; git diff --quiet from the reviewed parent through this remediation for that file returned rc=0. No manifest change is in this cycle. |
|
Focused adversarial remediation cycle 1 — NO_GO Exact candidate: head 431afab, tree 6eefd44e14cf3a6a086095c0dd4e6cdb48927cfa, base cb2c4c4. The original authority-fallback blocker is fixed. Two direct P1 regressions remain: (1) src/memory-project-link/schema.test.ts:33 now throws MementosProjectAuthorityIdentityError / MEMENTOS_PROJECT_AUTHORITY_UNCONFIGURED before the immutable SQLite receipt contract is exercised; isolated reproduction is 1 pass, 1 fail, exit 1. (2) src/cli/index.test.ts:613, projects updates name and path by stable ID, now has the preview update exit 1 instead of 0; targeted reproduction is 0 pass, 1 fail, exit 1. The exact head required GitHub test check is terminal failure, with 2535 pass / 2 fail. Focused cycle 2 acceptance: repair only those two direct regressions while preserving fail-closed linkage; revalidate the named schema test, the named projects-update CLI test, and the required GitHub test lane. Same fixed Codewith reviewer will re-review only these defects, their fixes, and direct regressions. |
Preserve fail-closed live authority behavior while keeping ordinary project metadata setup independent of the guarded producer identity. Agent: Theophrastus
|
[REVIEW] GO — #75 @ 4432bc4 — lens: correctness+security+gates, reviewer Xenon (1 of 1) What I ran:
What I read:
Blocking P0/P1 findings:
Non-blocking follow-ups:
|
|
Final focused remediation cycle 2 — GO Exact reviewed candidate: head 4432bc4; base cb2c4c4; reviewed/computed merge tree d6c90883ad6344110250f52908e56f997dfb1b4f. Schema regression: 2 pass / 0 fail. CLI project-update regression: 1 pass / 0 fail. Identity linkage: 2 pass / 0 fail. Required GitHub test: completed / success. Literal controls remain: CONTROL NO_CONFIG code=MEMENTOS_PROJECT_AUTHORITY_UNCONFIGURED advertised=false; CONTROL EXPLICIT authority=mementos-live-authority tenant=tenant-live corpus=corpus-live. The changes are confined to the two previously failing tests and preserve production fail-closed behavior; no reachable in-scope P0/P1 remains. PR merged only after fresh protected preflight as d8a49b0. Sole parent is the reviewed base; landed tree d6c90883ad6344110250f52908e56f997dfb1b4f exactly matches the reviewed tree; squash has exactly one Agent: Theophrastus trailer. |
Release @hasna/mementos 0.14.82 with metadata for the reviewed project-resource producer APIs merged in PR #75. Validated at exact head 5e3b7ed and merge tree 4abfca2. Independent Codewith release review returned GO with zero in-scope P0/P1 findings; CI, package, provenance, rollback, focused producer, and release gates passed. Agent: Theophrastus
Todos: e19114fe-08a8-47e7-8f52-bd7cea4d7c04
Summary
Validation
Identity
Implementation-only handoff: do not merge or release from this task.
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.