diff --git a/.agent-loop/initiatives/WS-AUTH-001-workstream-authorization-service/ACTIVATION_CUSTODY.md b/.agent-loop/initiatives/WS-AUTH-001-workstream-authorization-service/ACTIVATION_CUSTODY.md index 88641b251..a4be08bc4 100644 --- a/.agent-loop/initiatives/WS-AUTH-001-workstream-authorization-service/ACTIVATION_CUSTODY.md +++ b/.agent-loop/initiatives/WS-AUTH-001-workstream-authorization-service/ACTIVATION_CUSTODY.md @@ -51,6 +51,10 @@ mappings, and availability must remain identical. | `WS-AUTH-001-ART-06B` | `artifact.checker_output.write`, `artifact.checker_output.binding.create` | | `WS-XINT-002-07` | `artifact.review_packet.materialize`, `artifact.review_evidence.binding.create` | +Runtime owner `WS-XINT-002-07` contains two planning sub-waves: 07A is the +only availability transition and initially permits finding slots; 07B changes +no availability and only extends the evaluator to response slots. + `WS-AUTH-001-ART-CUSTODY` historically transferred 25 rows. WS-XINT-002-01 reconciles the live catalogue by removing the six unused multi-step upload rows and registering three end-to-end bundle/review rows. The resulting 22 rows have @@ -68,6 +72,12 @@ eight fixed-service identities and sixteen matrix memberships. ## REV custody transfer +The canonical current planning table is +[`WS-XINT-003/ACTION_CUSTODY.md`](../WS-XINT-003-rev-auth-end-to-end/ACTION_CUSTODY.md). +It supersedes the historical placeholder grouping below for future planning, +while leaving runtime `ActionOwner`, permission, mapping, and availability +unchanged until each exact XINT-003 activation wave. + | AUTH activation chunk | Exact planned ActionIds | |---|---| | `WS-AUTH-001-REV-05` | `review.queue.read`, `review.queue.inspect` | @@ -86,6 +96,22 @@ custodian labels grant no reviewer, Operator, or service authority. The four proposed lifecycle actions remain unregistered, and PREP remains separately human-gated. +The exact planning-wave replacement is: + +| XINT-003 wave | Registered planned REV ActionIds | +|---|---| +| `WS-XINT-003-03A` | `review.queue.read`, `review.claim`, `review.release`, `review.decline_preference` | +| `WS-XINT-003-03B` | `review.preference_expiry.run`, `review.lease_expiry.run` | +| `WS-XINT-003-04` | `review.context.read`, `review.finding_evidence.ingest` | +| `WS-XINT-003-05` | `review.chain.read` | +| `WS-XINT-003-06` | `review.decision` | +| `WS-XINT-003-07` | `review.finding_response_evidence.ingest` | +| `WS-XINT-003-08A` | `review.queue.inspect`, `review.lease.force_release`, `review.queue.routing.override`, `review.queue.routing.correct`, `review.queue.close` | +| `WS-XINT-003-08B` | `review.reconcile.run`, `review.artifact_reference.reconcile`, `review.projection.rebuild` | + +This is 19 rows with cardinalities `4/2/2/1/1/1/5/3`. XINT-002-owned ART +actions and shared submission actions are excluded. + ## Additive registration gates The following values are approved boundary proposals, not registered runtime @@ -93,7 +119,7 @@ actions on trusted `main`: | Registration chunk | Future activation chunk | Proposed ActionId -> PermissionId | |---|---|---| -| `WS-AUTH-001-REV-REG` | `WS-AUTH-001-REV-LIFECYCLE` | `review.revision_context.repair` -> `project.task.manage`; `review.revision_context.legacy_close` -> `operations.reconcile.run`; `review.revision_obligation.close` -> `project.task.manage`; `review.lifecycle.activation.manage` -> `operations.reconcile.run` | +| `WS-XINT-003-08R` | `WS-XINT-003-08A` / `WS-XINT-003-08B` | `review.revision_context.repair` -> `project.task.manage`; `review.revision_context.legacy_close` -> `operations.reconcile.run`; `review.revision_obligation.close` -> `project.task.manage`; `review.lifecycle.activation.manage` -> `operations.reconcile.run` | These are declared future registration gates, not executable chunk contracts. Neither may receive a full contract or start until the owning feature publishes exact @@ -110,7 +136,8 @@ fresh replay. Counts are derived from trusted `main` when a gate executes. REV registration adds exactly four planned actions and zero active actions. WS-XINT-002-01 -registers review-evidence binding under `WS-XINT-002-07` and adds it to the +registers review-evidence binding under runtime owner `WS-XINT-002-07`; planned +sub-wave 07A adds it to the existing `workstream.artifact.binding` static row without adding an identity or database grant. diff --git a/.agent-loop/initiatives/WS-AUTH-001-workstream-authorization-service/CHUNK_MAP.md b/.agent-loop/initiatives/WS-AUTH-001-workstream-authorization-service/CHUNK_MAP.md index c896f7270..0ccc9aa9c 100644 --- a/.agent-loop/initiatives/WS-AUTH-001-workstream-authorization-service/CHUNK_MAP.md +++ b/.agent-loop/initiatives/WS-AUTH-001-workstream-authorization-service/CHUNK_MAP.md @@ -1,5 +1,9 @@ # Chunk Map: WS-AUTH-001 - Workstream Authorization Service +Review/revision activation custody is now planned canonically by +`../WS-XINT-003-rev-auth-end-to-end/ACTION_CUSTODY.md`. Historical AUTH-REV +labels are not alternate implementation paths. + The complete ART-facing catalogue and runtime dependency is now planned in `../WS-XINT-002-art-auth-end-to-end/CHUNK_MAP.md`. The historical ART custody entries in this file remain baseline identifiers only until that planning @@ -80,7 +84,7 @@ feature manifest exists, then requires a separate explicit start. | Chunk | Title | Risk | Status | |---|---|---:|---| -| `WS-AUTH-001-REV-REG` | REV Lifecycle Action Registration | L1 | Blocked on complete REV typed manifests | +| Historical alias `WS-AUTH-001-REV-REG` | Superseded by `WS-XINT-003-08R` registration | L1 | Not executable; use canonical XINT-003 custody | | `WS-AUTH-001-ART-02D-INTERNAL` | ART 02D Internal Action Activation | L1 | Feature-gated | | `WS-AUTH-001-ART-02D-OPERATOR` | ART 02D Operator Read/Status And Independently Evaluated Retry Activation | L1 | Feature-gated | | `WS-AUTH-001-ART-03` | ART 03 Guide Source Action Activation | L1 | Feature-gated | @@ -96,8 +100,9 @@ feature manifest exists, then requires a separate explicit start. | `WS-AUTH-001-REV-09A` | REV 09A Finding Response Evidence Activation | L1 | Feature/ART-gated | | `WS-AUTH-001-REV-11` | REV 11 Recovery And Reconciliation Activation | L1 | Feature/service-gated | | `WS-AUTH-001-REV-12` | REV 12 Artifact Reconciliation And Projection Activation | L1 | Feature/service-gated | -| `WS-AUTH-001-REV-LIFECYCLE` | REV Lifecycle Repair Action Activation | L1 | Blocked until REV-REG and four hidden manifests merge | -| `WS-XINT-002-07` | Review Packet And Evidence Binding Activation | L1 | Feature-gated on exact REV lease/version and ART evidence behavior | +| Historical alias `WS-AUTH-001-REV-LIFECYCLE` | Superseded by `WS-XINT-003-08A` and `WS-XINT-003-08B` activation | L1 | Not executable; use canonical XINT-003 custody | +| `WS-XINT-002-07A` (runtime owner `WS-XINT-002-07`) | Review Packet And Finding Evidence Binding Activation | L1 | Feature-gated on exact REV lease/version and ART finding evidence behavior | +| `WS-XINT-002-07B` (runtime owner `WS-XINT-002-07`) | Response Evidence Binding Evaluator Extension (no availability change) | L1 | 07A plus exact human revision obligation/preparation | ## Dependency order diff --git a/.agent-loop/initiatives/WS-AUTH-001-workstream-authorization-service/DECISIONS.md b/.agent-loop/initiatives/WS-AUTH-001-workstream-authorization-service/DECISIONS.md index d69ca791f..699d80114 100644 --- a/.agent-loop/initiatives/WS-AUTH-001-workstream-authorization-service/DECISIONS.md +++ b/.agent-loop/initiatives/WS-AUTH-001-workstream-authorization-service/DECISIONS.md @@ -1,5 +1,10 @@ # Decisions: WS-AUTH-001 - Workstream Authorization Service +WS-XINT-003 preserves REV ownership of policy semantics and selects one +AUTH-authorized append-only policy writer. Its waves prospectively replace +historical AUTH-REV placeholders; runtime ownership/availability changes only +in each later activation chunk. + ## D1: Adopt WS-AUTH-001 as the authorization authority source Status: accepted by the user on 2026-07-11. diff --git a/.agent-loop/initiatives/WS-AUTH-001-workstream-authorization-service/PLAN.md b/.agent-loop/initiatives/WS-AUTH-001-workstream-authorization-service/PLAN.md index 795a67fb6..407880e13 100644 --- a/.agent-loop/initiatives/WS-AUTH-001-workstream-authorization-service/PLAN.md +++ b/.agent-loop/initiatives/WS-AUTH-001-workstream-authorization-service/PLAN.md @@ -1,5 +1,8 @@ # Plan: WS-AUTH-001 - Workstream Authorization Service +For review/revision work, use the canonical WS-XINT-003 action custody and +sequence. Historical AUTH-REV wave labels remain evidence only. + ## Goal Replace the token-role bootstrap with the adopted Workstream-owned actor, diff --git a/.agent-loop/initiatives/WS-AUTH-001-workstream-authorization-service/RISKS.md b/.agent-loop/initiatives/WS-AUTH-001-workstream-authorization-service/RISKS.md index c53372ffb..7b8fff455 100644 --- a/.agent-loop/initiatives/WS-AUTH-001-workstream-authorization-service/RISKS.md +++ b/.agent-loop/initiatives/WS-AUTH-001-workstream-authorization-service/RISKS.md @@ -1,5 +1,11 @@ # Risks: WS-AUTH-001 - Workstream Authorization Service +Planned REV custody permits only the reconciled XINT-003-02 policy-writer path +and designates XINT-002-07A as the sole evidence-binding availability +transition, with 07B evaluator-only. These are planning rules, not current +runtime protections; enforcement begins only when the named activation gates +merge and activate their exact actions. + ## AUTH-12 planning risks — 2026-07-29 - Guide create/update currently co-mutate review, revision, and retired diff --git a/.agent-loop/initiatives/WS-AUTH-001-workstream-authorization-service/STATUS.md b/.agent-loop/initiatives/WS-AUTH-001-workstream-authorization-service/STATUS.md index ebf6771db..644c0eee6 100644 --- a/.agent-loop/initiatives/WS-AUTH-001-workstream-authorization-service/STATUS.md +++ b/.agent-loop/initiatives/WS-AUTH-001-workstream-authorization-service/STATUS.md @@ -1,5 +1,9 @@ # Status: WS-AUTH-001 - Workstream Authorization Service +WS-XINT-003-01 reconciles future REV activation custody and policy-writer +ownership. It changes no catalogue/runtime state: all registered REV actions +remain planned and four lifecycle actions remain unregistered. + ## Current status Planning merged through PR #91 as diff --git a/.agent-loop/initiatives/WS-AUTH-001-workstream-authorization-service/chunks/WS-AUTH-001-12D2-guide-bound-policy-mutations.md b/.agent-loop/initiatives/WS-AUTH-001-workstream-authorization-service/chunks/WS-AUTH-001-12D2-guide-bound-policy-mutations.md index d0cbab9c7..260919731 100644 --- a/.agent-loop/initiatives/WS-AUTH-001-workstream-authorization-service/chunks/WS-AUTH-001-12D2-guide-bound-policy-mutations.md +++ b/.agent-loop/initiatives/WS-AUTH-001-workstream-authorization-service/chunks/WS-AUTH-001-12D2-guide-bound-policy-mutations.md @@ -13,6 +13,36 @@ Proposed and inactive after 12D. Add separately authorized routes for review and revision policy records after 12D alone removes the embedded guide create/update fields. +This contract is reconciled with REV-03P by WS-XINT-003-01. REV owns the +immutable/versioned policy semantics; AUTH owns the mutation authorization, +PREP consumption, and decision evidence. Chunk WS-XINT-003-02 implements the +single path below; neither parent contract may build an alternate writer. + +## One writer path + +- Surviving API: separate `PUT /projects/{project_id}/review-policy` and + `PUT /projects/{project_id}/revision-policy` routes in + `backend/app/modules/projects/router.py`, each declaring its exact primary + ActionId. +- Surviving service: new `ProjectPolicyMutationService` methods + `replace_review_policy()` and `replace_revision_policy()`. +- Surviving repository: new append-only + `ProjectRepository.add_review_policy_version()` and + `ProjectRepository.add_revision_policy_version()` methods over the existing + `ReviewPolicy` and `RevisionPolicy` tables/models, upgraded as necessary for + immutable version provenance. +- Retired callable mutators: `ProjectRepository.upsert_review_policy()`, + `ProjectRepository.upsert_revision_policy()`, + `ProjectService._review_policy_model()`, and + `ProjectService._revision_policy_model()`. +- No compatibility route, alias, second model/table, fallback constructor, or + dual repository path survives. + +Policies may be appended or replaced only while the exact guide version is a +draft. Activation freezes the selected policy versions: active-guide policy +rows are immutable, and later edits require a new draft guide/version rather +than an in-place update. + ## Why this chunk exists Guide management must not imply review/revision-policy authority. Retired @@ -72,6 +102,11 @@ compatibility. and concurrency follow the parent invariants. - OpenAPI declares exactly one primary action per new route and no compatibility endpoint is added. +- Tests prove old mutators are absent, direct update/delete of persisted policy + versions is refused, stale draft/active guide, stale current policy, + revocation, wrong grant/project/guide, replay, copied/wrong PREP handles, and + crossed concurrent replacements deny without a partial policy or allowed + decision record. ## Verification commands diff --git a/.agent-loop/initiatives/WS-REV-001-review-revision-lifecycle/CHUNK_MAP.md b/.agent-loop/initiatives/WS-REV-001-review-revision-lifecycle/CHUNK_MAP.md index 519013a2b..8085762d3 100644 --- a/.agent-loop/initiatives/WS-REV-001-review-revision-lifecycle/CHUNK_MAP.md +++ b/.agent-loop/initiatives/WS-REV-001-review-revision-lifecycle/CHUNK_MAP.md @@ -1,5 +1,8 @@ # Chunk Map: WS-REV-001 Review And Revision Lifecycle +REV-03P is reconciled into WS-XINT-003-02 and is not an independent policy +writer. AUTH activation follows the exact XINT-003 waves. + ## Rule One executable chunk maps to one PR. Merged parent IDs remain non-executable @@ -23,10 +26,10 @@ typed symbol/manifest, and tests. | `WS-REV-001-02A2` | Prepared Superseded Guide Reactivation | L1 | Historical | Retired from REV; upstream owner concern | | `WS-REV-001-02B` | Locked Review Policy And Dormant Task Lifecycle Compatibility | L1 | Historical | Superseded; any upstream gap is reported to its owner | | `WS-REV-001-02C` | Submission Attribution, Context, And Immutable Lineage | L1 | Historical | Superseded as an ownership chunk; REV consumes owner-supplied Submission lineage | -| `WS-REV-001-PLAN3` | Allow-Review Boundary Reset | L1 | Signed start required on exact current main | Proposed planning correction; not canonically active | -| `WS-REV-001-03P` | Review And Revision Policy Persistence | L1 | PLAN3; signed separate start | Recommended first REV runtime chunk; proposed contract, not started | +| `WS-REV-001-PLAN3` | Allow-Review Boundary Reset | L1 | Historical | Merged boundary correction | +| `WS-REV-001-03P` | Review And Revision Policy Persistence | L1 | Reconciled into `WS-XINT-003-02` | Planning input only; never executable independently | | `WS-REV-001-03` | Review Queue And Lease Persistence | L1 | PLAN3 | Non-executable split record | -| `WS-REV-001-03A` | Queue And Lease Base Persistence | L1 | 03P; exact merged `allow_review`, Submission/artifact, and actor handoffs; signed separate start | Proposed contract, not started | +| `WS-REV-001-03A` | Queue And Lease Base Persistence | L1 | merged `WS-XINT-003-02`; exact `allow_review`, Submission/artifact, and actor handoffs | Proposed contract; requires current-main refresh and explicit user request | | `WS-REV-001-03B` | Normalized Review Packet Manifest Persistence | L1 | 03A; exact ART packet-membership owner chunk merged | Proposed; owner chunk unscheduled | | `WS-REV-001-04` | Review Chain Persistence | L1 | 03B | Non-executable split record | | `WS-REV-001-04A` | Immutable Review Chain And Decision Request Persistence | L1 | 03B; current actor constraints | Proposed; no contract yet | @@ -73,7 +76,7 @@ typed symbol/manifest, and tests. ```text PLAN -> 01 -> 02(parent) -> PLAN2 -> 02A(historical, superseded) --> PLAN3(boundary reset) -> 03P +-> PLAN3(boundary reset) -> WS-XINT-003-02 (03P planning input) -> 03(parent) -> 03A -> 03B -> 04(parent) -> 04A -> 04B -> 05(parent) -> 05A -> 05B @@ -125,6 +128,7 @@ configuration, or coverage changes add CI integrity. ## Stop condition -Complete only the proposed `WS-REV-001-PLAN3`, then stop. Never resume 02A, 02A1, 02A2, -02A3, 02A4, 02B, or 02C as REV implementation. The next eligible runtime chunk -is 03P, only after merge and a signed explicit start on exact current main. +PLAN3 is complete. Never resume 02A, 02A1, 02A2, 02A3, 02A4, 02B, or 02C as +REV implementation. Policy work proceeds only through `WS-XINT-003-02`; later +REV feature chunks require current-main contract refresh and an explicit user +request under the ordinary engineering loop. diff --git a/.agent-loop/initiatives/WS-REV-001-review-revision-lifecycle/DECISIONS.md b/.agent-loop/initiatives/WS-REV-001-review-revision-lifecycle/DECISIONS.md index 8570e4fe2..20b6b9462 100644 --- a/.agent-loop/initiatives/WS-REV-001-review-revision-lifecycle/DECISIONS.md +++ b/.agent-loop/initiatives/WS-REV-001-review-revision-lifecycle/DECISIONS.md @@ -1,5 +1,9 @@ # Decisions: WS-REV-001 Review And Revision Lifecycle +REV retains policy semantics and immutable version rules; XINT-003-02 owns the +one AUTH-authorized persistence/writer cutover over existing project policy +records. No duplicate REV writer is permitted. + ## Decisions ### D1 - Existing Submission Is SubmissionVersion diff --git a/.agent-loop/initiatives/WS-REV-001-review-revision-lifecycle/PLAN.md b/.agent-loop/initiatives/WS-REV-001-review-revision-lifecycle/PLAN.md index d4b938668..8cde9daa1 100644 --- a/.agent-loop/initiatives/WS-REV-001-review-revision-lifecycle/PLAN.md +++ b/.agent-loop/initiatives/WS-REV-001-review-revision-lifecycle/PLAN.md @@ -1,5 +1,9 @@ # Plan: WS-REV-001 Review And Revision Lifecycle +Current cross-initiative authority and policy-writer sequencing is canonical in +`../WS-XINT-003-rev-auth-end-to-end/ACTION_CUSTODY.md`. Planning artifacts do +not require signed starts, active-chunk state, or merge intents. + ## Boundary Reset — 2026-07-22 This section supersedes every later passage that assigns Project Guide setup, @@ -27,10 +31,10 @@ This PLAN3 candidate is reconciled from current trusted main changes are discovery evidence only. The detailed facts below were captured at the earlier PLAN2 snapshot and are historical unless independently re-proven. -Signed loop memory still records retired 02A1 as the next chunk because that is -the last merged successor declaration. PLAN3 does not treat that projection as -implementation authority. Its schema-v2 merge intent replaces the successor -with 03P; only the post-merge signed projection may then authorize a 03P start. +Generated loop memory naming retired 02A1 is historical only and has no +implementation authority. The current WS-XINT-003 chunk map governs future +cross-initiative sequence; implementation still requires an explicit user +request under the ordinary repository engineering loop. They are not runtime dependencies until their exact owner chunk, PR, merge SHA, schema head, typed contract, and tests exist on trusted main. @@ -308,11 +312,11 @@ errors but do not substitute for database enforcement. ## Chunk strategy -PLAN3 is a proposed planning-only boundary correction, not signed active work. The entire 02A family, +PLAN3 is merged historical boundary correction. The entire 02A family, 02B, and 02C are retired historical records and are never executable by REV. -03P is the first proposed REV runtime child and contains only REV-owned policy; -it still requires current-main refresh, risk routing, plan review, signed start, -and exact owner evidence. Queue persistence follows separately in 03A. +03P is reconciled into WS-XINT-003-02 and is not independently executable. +That chunk requires current-main refresh, risk routing, plan review, and exact +owner evidence. Queue persistence follows separately in 03A. The detailed order is maintained in `CHUNK_MAP.md`. The important boundaries are: @@ -375,12 +379,11 @@ head, preflight, upgrade, downgrade/re-upgrade where safe, protected-row refusal transactional failure behavior, and direct-SQL constraints. Every chunk runs stale Workstream/AUTH/ART/REV wording scans applicable on -current main, Markdown links, `git diff --check`, merge-intent validation through -agent gates, and required internal reviewer fanout. Test changes may not weaken, +current main, Markdown links, `git diff --check`, agent gates, and required +internal reviewer fanout. Test changes may not weaken, skip, or rewrite existing checker-caused revision coverage. ## Stop rule -Complete PLAN3 and stop. Automated memory may name 03P only with a signed -explicit-start gate. No runtime child starts automatically, and no retired 02A-family, +Complete PLAN3 and stop. No runtime child starts automatically, and no retired 02A-family, 02B, or 02C contract may be revived as REV work. diff --git a/.agent-loop/initiatives/WS-REV-001-review-revision-lifecycle/RISKS.md b/.agent-loop/initiatives/WS-REV-001-review-revision-lifecycle/RISKS.md index 302e4e428..3ce275342 100644 --- a/.agent-loop/initiatives/WS-REV-001-review-revision-lifecycle/RISKS.md +++ b/.agent-loop/initiatives/WS-REV-001-review-revision-lifecycle/RISKS.md @@ -1,5 +1,9 @@ # Risks: WS-REV-001 Review And Revision Lifecycle +Duplicate policy models/writers are prohibited. Active-guide policy history is +protected by append-only versions, a draft-only final PREP guard, and database +update/delete refusal proof in XINT-003-02. + | ID | Risk | Severity | Mitigation | |---|---|---:|---| | R0 | REV converts a consumed upstream dependency into feature ownership and edits Project Guide, Task intake, Checker, AUTH, ART, or CON internals | Critical | REV starts at final current `allow_review`; record missing typed owner contracts and stop. Boundary review blocks any REV chunk that edits upstream behavior rather than a declared participant owned by that subsystem. | diff --git a/.agent-loop/initiatives/WS-REV-001-review-revision-lifecycle/STATUS.md b/.agent-loop/initiatives/WS-REV-001-review-revision-lifecycle/STATUS.md index 6d18ec343..6b29b2d3c 100644 --- a/.agent-loop/initiatives/WS-REV-001-review-revision-lifecycle/STATUS.md +++ b/.agent-loop/initiatives/WS-REV-001-review-revision-lifecycle/STATUS.md @@ -1,5 +1,8 @@ # Status: WS-REV-001 Review And Revision Lifecycle +WS-XINT-003-01 supersedes obsolete process gates for future REV-AUTH work and +reconciles REV-03P with AUTH-12D2. No runtime action is activated. + ## Current status On 2026-07-22 a complete reread of the canonical Markdown and PDF specification @@ -10,11 +13,11 @@ Guide setup, activation, Task intake, and upstream publication fencing belong to their owning subsystems. REV reports gaps in those handoffs and does not repair them. The attempted 02A1 runtime candidate was reverted in full. -`WS-REV-001-PLAN3` is proposed planning-only work, not canonically active. It retires +`WS-REV-001-PLAN3` is merged historical planning. It retires 02A/02A1/02A2/02A3/02A4/02B/02C as REV implementation authorization. The first -future REV chunk is 03P: REV-owned ReviewPolicy/RevisionPolicy persistence. -Canonical start requires the signed `Loop Memory Explicit Event` workflow on -exact current main; chat and local work are not start evidence. +future policy work is the reconciled WS-XINT-003-02 writer cutover; 03P is not +an independent implementation path. Work starts through the repository's +ordinary intent/plan/bounded-change loop after an explicit user request. The historical text below records the superseded PLAN2/02A state and is not current implementation authority. Trusted main at that time was `44f2467c`, which additionally @@ -30,11 +33,9 @@ Current trusted main is `14fa4316f7d984f2176657bfafd2a2dae56f944e` with sole Alembic head `0033_authorization_read_rate_control`. The bullets below describe the older PLAN2 snapshot and are not current runtime proof. -Canonical signed loop memory currently remains stopped after merged 02A and -names retired 02A1 as next. That projection is accurate historical automation -state but no longer a valid REV scope choice. PLAN3 is proposed—not active—and -its reviewed merge intent changes the same-initiative successor to 03P. No -runtime work may begin before that merge and a later signed 03P start. +Generated loop state naming retired 02A1 is historical and is not an +implementation gate. The canonical next cross-initiative sequence is the +WS-XINT-003 chunk map. - Single Alembic head: `0028_artifact_admission`. - TaskAssignment and Submission expose canonical `contributor_id` with @@ -108,7 +109,8 @@ start statement in it is void under D28 and PLAN3. ## Human-owned gates -- Start 03P only through the signed workflow after this reviewed plan merges. +- Implement policy work only through reconciled WS-XINT-003-02 after its + current-main contract review and an explicit user request. - Start 03A only after 03P and after its current-main refresh proves every exact `allow_review`, Submission, artifact, and reviewer owner handoff. - Exact human Review revision-round counting, deadline anchor, and boundary @@ -121,6 +123,6 @@ start statement in it is void under D28 and PLAN3. ## Stop condition -Complete the PLAN3 boundary correction and stop. Do not implement runtime code. -Do not resume any 02A-family, 02B, or 02C chunk. After PLAN3 merges, await a -signed explicit start on exact current main before implementing 03P. +PLAN3 is complete historical boundary correction. Do not resume any 02A-family, +02B, or 02C chunk. Future runtime work follows the current XINT-003 map and an +explicit user request. diff --git a/.agent-loop/initiatives/WS-REV-001-review-revision-lifecycle/chunks/WS-REV-001-03P-review-revision-policy-persistence.md b/.agent-loop/initiatives/WS-REV-001-review-revision-lifecycle/chunks/WS-REV-001-03P-review-revision-policy-persistence.md index b1ae04b72..3e3b361b2 100644 --- a/.agent-loop/initiatives/WS-REV-001-review-revision-lifecycle/chunks/WS-REV-001-03P-review-revision-policy-persistence.md +++ b/.agent-loop/initiatives/WS-REV-001-review-revision-lifecycle/chunks/WS-REV-001-03P-review-revision-policy-persistence.md @@ -2,22 +2,46 @@ ## Status -Proposed only. It may start only through a signed `Loop Memory Explicit Event` -on exact current main after PLAN3 merges and this contract is refreshed/reviewed. +Reconciled planning input to `WS-XINT-003-02`. It is not an independent +implementation path. ## Goal Persist only REV-owned immutable ReviewPolicy and RevisionPolicy facts needed by later routing, lease, decision, and human revision behavior. +REV owns field semantics, version identity, draft/active immutability, and the +facts later lifecycle code consumes. AUTH-12D2 owns authority, PREP, evidence, +and the only mutation surface. The shared implementation is XINT-003-02. + +## Canonical persistence path + +Adopt the existing project `ReviewPolicy` and `RevisionPolicy` models/tables as +the sole records and upgrade them for immutable version provenance. Every +external mutation enters only +`ProjectPolicyMutationService.replace_review_policy()` or +`replace_revision_policy()`; that service owns authorization preparation, +grant/resource checks, final PREP consumption, and decision evidence. It alone +invokes the internal append-only persistence primitives +`ProjectRepository.add_review_policy_version()` or +`add_revision_policy_version()`. Those repository methods are never caller- +facing mutation APIs. Retire both repository `upsert_*` methods and +both `ProjectService._*_policy_model()` constructors. Do not add REV-local +duplicate models, tables, repositories, routes, aliases, or fallback writers. + +The exact guide must still be a draft at final PREP consumption. Policy +versions selected by guide activation become immutable; changes thereafter +require a new draft guide/version. + ## Risk L1: policy immutability, duration/limit semantics, and later decision authority. ## Allowed files -To be fixed at signed start: REV-owned policy models, migration, schemas, -focused tests, and this initiative's evidence/merge-intent files only. +The exact current-main project models, migration, policy schemas, canonical +writer service/repository, AUTH PREP integration, focused tests, and initiative +evidence must be fixed in the refreshed XINT-003-02 contract. ## Not allowed @@ -35,6 +59,10 @@ focused tests, and this initiative's evidence/merge-intent files only. - Missing upstream Task/Assignment compatibility is reported to its owner and cannot be repaired in this chunk. - No review lifecycle transition is activated. +- PostgreSQL proof refuses update/delete of immutable versions and proves stale + draft/active guide, stale policy, revocation, replay, wrong grant/resource, + copied handle, concurrent replacement, and rollback leave no partial policy + or allowed decision evidence. ## Verification @@ -49,4 +77,5 @@ reuse/dedup, docs, test-delta, and CI integrity. ## Stop -Do not implement without a signed start on exact current main. +Do not implement this parent contract independently. Refresh and implement only +WS-XINT-003-02 after an explicit user request. diff --git a/.agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/CHUNK_MAP.md b/.agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/CHUNK_MAP.md index 3ad311938..232cf0683 100644 --- a/.agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/CHUNK_MAP.md +++ b/.agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/CHUNK_MAP.md @@ -12,10 +12,11 @@ | `WS-XINT-002-05C` | Activate checker-remediation submission preparation/creation against one final CheckerRun. | L1 | 05B plus checker remediation evidence | | `WS-XINT-002-05D` | Activate human-review revision preparation/creation against exact revision obligations. | L1 | 05B plus REV revision-preparation evidence | | `WS-XINT-002-06` | Activate pre/post-submit materialization and checker output/binding. | L1 | 02 plus ART 04B/06A/06B evidence | -| `WS-XINT-002-07` | Activate lease-scoped review packets and finding/response evidence binding. | L1 | 02 plus merged ART/REV manifests | -| `WS-XINT-002-08` | Prove complete catalogue, least privilege, revocation, replay, concurrency, audit, and live lifecycle conformance. | L1 | 03-07 including 05A-D | +| `WS-XINT-002-07A` | Activate lease-scoped packets and the one evidence-binding ActionId for reviewer-finding slots; response slots hard deny. | L1 | 02 plus merged ART/REV lease/finding manifests | +| `WS-XINT-002-07B` | Extend the active evidence-binding evaluator to exact human-revision response slots; no availability change. | L1 | 07A plus merged hidden REV obligation/preparation behavior; precedes XINT-003-07 activation | +| `WS-XINT-002-08` | Prove complete catalogue, least privilege, revocation, replay, concurrency, audit, and live lifecycle conformance. | L1 | 03-07B including 05A-D | -Chunks 03-07 may be split only by the evidence boundaries named above. The +Chunks 03-07B may be split only by the evidence boundaries named above. The guide wave is therefore fixed as 04A after ART-03A and 04B after ART-03B. A split cannot add catalogue values, permissions, identities, matrix rows, or a second runtime protocol; such a discovery is contract drift and returns to planning. diff --git a/.agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/chunks/WS-XINT-002-07-review-artifact-activation.md b/.agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/chunks/WS-XINT-002-07-review-artifact-activation.md index d72dd5605..cc0b24d8a 100644 --- a/.agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/chunks/WS-XINT-002-07-review-artifact-activation.md +++ b/.agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/chunks/WS-XINT-002-07-review-artifact-activation.md @@ -1,9 +1,21 @@ -# Chunk Contract: WS-XINT-002-07 Review Artifact Authorization Activation +# Split Record: WS-XINT-002-07 Review Artifact Authorization -## Goal +## Status -Activate exact lease-scoped reviewer packets and verified finding/response -evidence binding after both ART and REV publish their hidden manifests. +Superseded before implementation by `WS-XINT-002-07A` and +`WS-XINT-002-07B`. This record is not an activation path. + +## Split invariant + +07A is the only availability transition: it activates packet materialization +and the one evidence-binding ActionId for reviewer-finding slots while hard- +denying response-slot shapes. 07B changes no ActionId availability and extends +only that evaluator after an exact human revision obligation and preparation +exist. Human REV actions stay with XINT-003; shared submission actions stay +with XINT-002-05D. + +Everything below is the historical combined design input allocated between 07A +and 07B. It is retained for provenance and is not executable as one chunk. ## Risk class diff --git a/.agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/chunks/WS-XINT-002-07A-reviewer-artifact-activation.md b/.agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/chunks/WS-XINT-002-07A-reviewer-artifact-activation.md new file mode 100644 index 000000000..52603d8b4 --- /dev/null +++ b/.agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/chunks/WS-XINT-002-07A-reviewer-artifact-activation.md @@ -0,0 +1,21 @@ +# Chunk Contract: WS-XINT-002-07A — Reviewer Artifact Activation + +## Goal + +Activate exact lease-scoped packet materialization and the single evidence-binding ActionId for reviewer-finding slots only. + +## Boundary + +This is the only availability transition for `artifact.review_evidence.binding.create`. It also activates `artifact.review_packet.materialize`. The fixed identities are `workstream.artifact.binding` and `workstream.artifact.materializer`. Human review actions remain with XINT-003. + +## Acceptance criteria + +- Packet materialization binds reviewer reference, active lease, packet manifest, Submission, checker, guide/policy, verified content, session, transaction, request, and decision evidence. +- Evidence binding accepts only server-derived `reviewer_finding` mode with the exact lease/finding slot and verified content commitment. +- `contributor_response` and every CheckerRun-rooted remediation shape hard deny even when the ActionId is active. +- Wrong, stale, revoked, replayed, copied, or cross-resource facts deny before byte disclosure or durable mutation. +- Human and fixed-service evidence commits atomically with the protected REV/ART operation. Prepared handles never enter a job payload. + +## Stop + +Do not add response-slot evaluation or activate human REV actions. diff --git a/.agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/chunks/WS-XINT-002-07B-response-artifact-extension.md b/.agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/chunks/WS-XINT-002-07B-response-artifact-extension.md new file mode 100644 index 000000000..5768a81d5 --- /dev/null +++ b/.agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/chunks/WS-XINT-002-07B-response-artifact-extension.md @@ -0,0 +1,19 @@ +# Chunk Contract: WS-XINT-002-07B — Response Artifact Evaluator Extension + +## Goal + +Extend the already-active `artifact.review_evidence.binding.create` evaluator to human-revision response slots after the exact REV obligation and preparation exist. + +## Boundary + +This chunk changes no ActionId availability, registers no action, and creates no identity. It reuses `workstream.artifact.binding` and the existing opaque transaction-bound prepared authorization. Human response authority remains with XINT-003-07; shared Submission actions remain with XINT-002-05D. + +## Acceptance criteria + +- Server-derived `contributor_response` mode binds `Review(needs_revision)`, unresolved finding/response slot, obligation, preparation head/digest, contributor assignment, predecessor Submission, deadline/round, guide/policies, verified content, session, transaction, request, and decision evidence. +- CheckerRun-rooted remediation, wrong service/action/mode, stale preparation, predecessor advancement, expired/exhausted obligation, copied/replayed handle, and cross-resource facts fail closed before durable mutation. +- ART binding and the human REV mutation commit or roll back together. The binding service cannot create a Submission or inherit contributor authority. + +## Stop + +Do not change catalogue availability or add generic artifact access. diff --git a/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/ACTION_CUSTODY.md b/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/ACTION_CUSTODY.md new file mode 100644 index 000000000..db4603577 --- /dev/null +++ b/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/ACTION_CUSTODY.md @@ -0,0 +1,95 @@ +# Canonical REV-AUTH Action Custody + +This table is the planning source of truth for the v0.1 review and human-revision authorization surface. `WS-XINT-003-01` changes documentation only: every registered REV action remains `planned`, the four registration rows do not yet exist, and XINT-002 rows retain their runtime owners. + +## Human and privileged actions + +| ActionId | PermissionId | Principal and scope | Resource family | Surface owner | State | Activation wave | +|---|---|---|---|---|---|---| +| `project.review_policy.update` | `project.review_policy.manage` | Project Manager grant for exact project | draft guide + ReviewPolicy version | project/REV semantics; AUTH mutation | registered planned | `WS-XINT-003-02` | +| `project.revision_policy.update` | `project.review_policy.manage` | Project Manager grant for exact project | draft guide + RevisionPolicy version | project/REV semantics; AUTH mutation | registered planned | `WS-XINT-003-02` | +| `review.queue.read` | `review.queue.read` | reviewer grant; exact project; self-review denied | concealed current-work view | REV | registered planned | `WS-XINT-003-03A` | +| `review.claim` | `review.claim` | reviewer grant; exact project; self-review denied | queue entry + global reviewer lease state | REV | registered planned | `WS-XINT-003-03A` | +| `review.release` | `review.release` | owning reviewer and active lease | ReviewLease | REV | registered planned | `WS-XINT-003-03A` | +| `review.decline_preference` | `review.decline_preference` | offered reviewer for exact project | review preference | REV | registered planned | `WS-XINT-003-03A` | +| `review.preference_expiry.run` | `operations.timer.run` | fixed preference-expiry service only | due preference row | REV | registered planned | `WS-XINT-003-03B` | +| `review.lease_expiry.run` | `operations.timer.run` | fixed lease-expiry service only | due ReviewLease | REV | registered planned | `WS-XINT-003-03B` | +| `review.context.read` | `submission.read_for_review` | owning reviewer and active exact lease | immutable packet/context | REV | registered planned | `WS-XINT-003-04` | +| `review.finding_evidence.ingest` | `review.decision` | owning reviewer and active exact lease | finding slot + verified commitment | REV | registered planned | `WS-XINT-003-04` | +| `review.chain.read` | `review.chain.read` | owning reviewer and active exact lease | bounded task/Submission review chain | REV | registered planned | `WS-XINT-003-05` | +| `review.decision` | `review.decision` | owning reviewer and active exact lease | Review + findings/resolutions + lifecycle effects | REV | registered planned | `WS-XINT-003-06` | +| `review.finding_response_evidence.ingest` | `submission.create` | assigned contributor; exact human-revision obligation | response slot + preparation + predecessor | REV | registered planned | `WS-XINT-003-07` | +| `review.queue.inspect` | `review.queue.inspect` | Operator; bounded/redacted operational scope | queue operational view | REV | registered planned | `WS-XINT-003-08A` | +| `review.lease.force_release` | `review.lease.force_release` | Operator; canonical reason required | exact ReviewLease | REV | registered planned | `WS-XINT-003-08A` | +| `review.queue.routing.override` | `review.queue.override` | Operator; canonical reason required | exact queue entry/routing state | REV | registered planned | `WS-XINT-003-08A` | +| `review.queue.routing.correct` | `review.queue.override` | Operator; canonical reason required | exact invalid routing state | REV | registered planned | `WS-XINT-003-08A` | +| `review.queue.close` | `review.queue.override` | Operator; canonical reason required | exact stale queue entry | REV | registered planned | `WS-XINT-003-08A` | +| `review.revision_context.repair` | `project.task.manage` | Project Manager grant for exact project | invalid revision context | REV | missing-to-register | `WS-XINT-003-08R` then `08A` | +| `review.revision_obligation.close` | `project.task.manage` | Project Manager grant for exact project | exact unfulfillable obligation | REV | missing-to-register | `WS-XINT-003-08R` then `08A` | +| `review.revision_context.legacy_close` | `operations.reconcile.run` | Operator; canonical reason required | exact legacy revision context | REV | missing-to-register | `WS-XINT-003-08R` then `08A` | +| `review.lifecycle.activation.manage` | `operations.reconcile.run` | Operator; exact phase and reason | lifecycle release controller | REV | missing-to-register | `WS-XINT-003-08R` then `08B` | +| `review.reconcile.run` | `operations.reconcile.run` | one of two fixed reconciler identities | invalidation or general reconciliation batch | REV | registered planned | `WS-XINT-003-08B` | +| `review.artifact_reference.reconcile` | `operations.reconcile.run` | fixed artifact-reference reconciler only | bounded review artifact reference batch | REV | registered planned | `WS-XINT-003-08B` | +| `review.projection.rebuild` | `operations.projection.rebuild` | fixed projection rebuilder only | derived review projection batch | REV | registered planned | `WS-XINT-003-08B` | + +The 19 registered `review.*` rows move from historical `AUTH_REV_*` planning labels to these exact XINT-003 waves only as planning custody. Their runtime `ActionOwner` values change with each later activation, never in 01. + +## Fixed-service closure + +| ActionId | Exact identity | Static membership | Server-derived mode/scope | Forbidden principals | Required audit/provenance | +|---|---|---|---|---|---| +| `review.preference_expiry.run` | `workstream.review.preference_expiry` | this action only | `due_preference`; claimed IDs/cursor | every human and all other services | actor/link, due boundary, IDs/cursor, request/idempotency, decision event | +| `review.lease_expiry.run` | `workstream.review.lease_expiry` | this action only | `due_lease`; claimed IDs/cursor | every human and all other services | actor/link, expiry boundary, IDs/cursor, request/idempotency, decision event | +| `review.reconcile.run` | `workstream.review.authority_invalidation_reconciliation` | this action only | `authority_invalidation`; affected authority scope | every human and `workstream.review.reconciliation` | identity, mode, trigger, IDs/cursor, request/idempotency, decision event | +| `review.reconcile.run` | `workstream.review.reconciliation` | this action only | `general`; bounded project/time shard | every human and `workstream.review.authority_invalidation_reconciliation` | identity, mode, reason, shard/cursor, request/idempotency, decision event | +| `review.artifact_reference.reconcile` | `workstream.review.artifact_reference_reconciliation` | this action only | `artifact_reference`; bounded review/reference shard | every human and all other services | identity, reference IDs, reason, cursor, request/idempotency, decision event | +| `review.projection.rebuild` | `workstream.review.projection` | this action only | `projection_rebuild`; named projection/shard | every human and all other services | identity, projection, watermark, cursor, request/idempotency, decision event | +| `artifact.review_packet.materialize` | `workstream.artifact.materializer` | global matrix also contains pre/post-submit materialization; this is its review-surface action | exact active-lease packet manifest | every human and all other services | actor/link, lease/packet/Submission/content, digests, request/transaction, decision event | +| `artifact.review_evidence.binding.create` | `workstream.artifact.binding` | global matrix also contains guide/submission/checker binding; this is its review-surface action | 07A `reviewer_finding`; 07B adds `contributor_response`; exact slot/content | every human and all other services; response mode denied until 07B | identity, mode, review/lease or obligation/preparation, slot/content, request/transaction, decision event | + +The six proposed REV identities are fixed planning names; they are not provisioned or admitted until their activation chunks. Celery payloads contain identifiers and provenance only, and every command prepares fresh authority inside its transaction. + +## Externally owned shared actions + +| ActionId | PermissionId | Principal/resource constraint | Runtime owner and planned wave | +|---|---|---|---| +| `artifact.review_packet.materialize` | `artifact.review_packet.materialize` | fixed ART materializer; exact active-lease packet | runtime `WS-XINT-002-07`; activation sub-wave `07A` | +| `artifact.review_evidence.binding.create` | `artifact.binding.create` | fixed ART binding service; exact finding/response slot | runtime `WS-XINT-002-07`; availability sub-wave `07A`, evaluator extension `07B` | +| `artifact.submission_bundle.prepare` | `submission.create` | assigned contributor; exact human-revision preparation | availability `WS-XINT-002-05A`; revision-context evaluator extension `05D` | +| `submission.create` | `submission.create` | assigned contributor; exact prepared human revision | availability `WS-XINT-002-05B`; revision-context evaluator extension `05D` | + +These actions are not XINT-003 custody. Generic artifact download, adjudication, automated routing, reputation, settlement, and agent workspace authority are out of scope. + +## Hidden-feature dependencies by action + +| ActionId | Exact prerequisite behavior/manifest | +|---|---| +| `project.review_policy.update` | existing policy records plus refreshed REV-03P/AUTH-12D2 contract; implemented only by `WS-XINT-003-02` | +| `project.revision_policy.update` | existing policy records plus refreshed REV-03P/AUTH-12D2 contract; implemented only by `WS-XINT-003-02` | +| `review.queue.read` | merged hidden REV-05 concealed current-work view | +| `review.claim` | merged hidden REV-05 queue admission and REV-06 atomic lease behavior | +| `review.release` | merged hidden REV-06 lease release behavior | +| `review.decline_preference` | merged hidden REV-06 preference behavior | +| `review.preference_expiry.run` | merged hidden REV-06 preference timer command | +| `review.lease_expiry.run` | merged hidden REV-06 lease timer command | +| `review.context.read` | merged hidden REV-07 context/packet membership plus XINT-002-07A packet materialization | +| `review.finding_evidence.ingest` | merged hidden REV-07 finding-slot behavior plus XINT-002-07A finding binding | +| `review.chain.read` | merged hidden REV-07 bounded chain behavior plus active context boundary | +| `review.decision` | merged hidden REV-08 decision kernel plus required CON flush-only participant | +| `review.finding_response_evidence.ingest` | merged hidden REV-09A obligation/preparation plus merged XINT-002-07B response evaluator | +| `review.queue.inspect` | merged hidden REV-11 bounded/redacted queue inspection | +| `review.lease.force_release` | merged hidden REV-11 force-release command | +| `review.queue.routing.override` | merged hidden REV-11 override command | +| `review.queue.routing.correct` | merged hidden REV-11 correction command | +| `review.queue.close` | merged hidden REV-11 close command | +| `review.revision_context.repair` | 08R registration plus merged hidden REV-11 covered-project repair command | +| `review.revision_obligation.close` | 08R registration plus merged hidden REV-11 obligation-close command | +| `review.revision_context.legacy_close` | 08R registration plus merged hidden REV-11 legacy-close command | +| `review.lifecycle.activation.manage` | 08R registration plus merged hidden REV-12A lifecycle controller | +| `review.reconcile.run` | merged hidden REV-11 invalidation and general reconciliation commands | +| `review.artifact_reference.reconcile` | merged hidden REV-12 artifact-reference command and typed ART repair port | +| `review.projection.rebuild` | merged hidden REV-12 derived-projection command | +| `artifact.review_packet.materialize` | XINT-002-07A after hidden ART packet behavior and REV active-lease manifest | +| `artifact.review_evidence.binding.create` | XINT-002-07A finding-slot behavior; XINT-002-07B response-slot behavior after hidden REV obligation/preparation | +| `artifact.submission_bundle.prepare` | XINT-002-05D after hidden REV human-revision preparation | +| `submission.create` | XINT-002-05D after a verified, consumable human-revision admission | diff --git a/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/CHUNK_MAP.md b/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/CHUNK_MAP.md index 8d358dd19..ada054799 100644 --- a/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/CHUNK_MAP.md +++ b/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/CHUNK_MAP.md @@ -9,7 +9,7 @@ | `WS-XINT-003-04` | Activate human `review.context.read` and reviewer finding evidence while consuming XINT-002-07A's ART-only packet/materialization/binding capability. | L1 | 03B plus hidden REV packet/evidence manifests and XINT-002-07A | | `WS-XINT-003-05` | Activate only bounded `review.chain.read`, consuming the active REV context and XINT-002 packet/materialization boundary. | L1 | 04 plus merged XINT-002-07A | | `WS-XINT-003-06` | Activate `review.decision` only for the hidden atomic Review/FinalAcceptance/CON composition. | L1 | 05 plus REV decision and merged CON participant | -| `WS-XINT-003-07` | Activate human contributor response evidence; coordinate XINT-002-05D shared revision submission and XINT-002-07B ART-only response binding. | L1 | 06 plus REV revision behavior and XINT-002 owner waves | +| `WS-XINT-003-07` | Activate human contributor response evidence, consuming XINT-002-05D shared revision submission and the already-merged XINT-002-07B ART response evaluator. | L1 | 06 plus hidden REV revision behavior, XINT-002-05D, and merged XINT-002-07B | | `WS-XINT-003-08R` | Register four missing privileged recovery/lifecycle ActionIds as planned with complete catalogue/migration parity; activate nothing. | L1 | 07 plus exact hidden-feature registration manifests | | `WS-XINT-003-08A` | Activate Project Manager and Operator queue/revision recovery commands with exact scope and reasons. | L1 | 08R plus hidden REV recovery behavior | | `WS-XINT-003-08B` | Activate both identities for the single `review.reconcile.run` ActionId together, plus artifact-reference, projection, and lifecycle-control surfaces. | L1 | 08A plus hidden REV jobs/projection/control | diff --git a/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/DECISIONS.md b/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/DECISIONS.md index 11654b177..2b0ca509f 100644 --- a/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/DECISIONS.md +++ b/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/DECISIONS.md @@ -37,3 +37,9 @@ release waits for complete conformance. 15. Obsolete signed-start, active-chunk, and merge-intent language in historical REV planning does not govern current work under `AGENTS.md`. +16. Existing project ReviewPolicy/RevisionPolicy tables are the sole future + persistence records. XINT-003-02 introduces the sole append-only writer and + removes the four legacy callable mutator/construction paths named in the + reconciled REV-03P/AUTH-12D2 contracts. +17. XINT-002-07A is the only review-evidence binding availability transition; + 07B adds response-slot evaluator shape without changing availability. diff --git a/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/DISCOVERY.md b/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/DISCOVERY.md index 9c8179d4f..8cd43af1c 100644 --- a/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/DISCOVERY.md +++ b/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/DISCOVERY.md @@ -6,7 +6,9 @@ - [Authorization service specification](../../../docs/spec_authorization_service.md) - [Roles and permissions](../../../docs/operations_roles_permissions.md) - [XINT-002 human-review revision owner](../WS-XINT-002-art-auth-end-to-end/chunks/WS-XINT-002-05D-human-review-revision.md) -- [XINT-002 review artifact owner](../WS-XINT-002-art-auth-end-to-end/chunks/WS-XINT-002-07-review-artifact-activation.md) +- [XINT-002 reviewer artifact activation](../WS-XINT-002-art-auth-end-to-end/chunks/WS-XINT-002-07A-reviewer-artifact-activation.md) +- [XINT-002 response artifact extension](../WS-XINT-002-art-auth-end-to-end/chunks/WS-XINT-002-07B-response-artifact-extension.md) +- [Historical XINT-002 combined split record](../WS-XINT-002-art-auth-end-to-end/chunks/WS-XINT-002-07-review-artifact-activation.md) ## Baseline @@ -153,8 +155,9 @@ needs a closed typed context with only its valid shape. - AUTH-12D2 and REV-03P must be reconciled before either policy writer is built. - REV hidden feature chunks must merge before matching AUTH action activation. - XINT-002 remains the sole activation owner for ART review-artifact actions and - shared human-review submission actions. Its current combined review-artifact contract must split - response-evidence activation after the human revision obligation exists. + shared human-review submission actions. WS-XINT-003-01 split the combined + review-artifact contract into 07A finding availability and 07B response + evaluation after the human revision obligation exists. - CON atomic participant and FinalAcceptance integration must merge before `review.decision` activation. - Final product routes remain absent until the complete dependency conformance @@ -162,9 +165,9 @@ needs a closed typed context with only its valid shape. ## Risks discovered -- The current REV plan contains obsolete signed-start and generated-loop gates - contrary to current `AGENTS.md`; those statements are process history, not - implementation blockers. +- The entry REV plan contained obsolete signed-start and generated-loop gates; + WS-XINT-003-01 removed them from current authority while preserving relevant + historical provenance. - Historical action counts and owner chunk names are stale after many AUTH/ART migrations and cannot be used as exact implementation inputs. - `review.finding_evidence.ingest -> review.decision` and @@ -182,10 +185,9 @@ needs a closed typed context with only its valid shape. ## Unknowns to resolve at each activation wave - Exact merged feature symbol/manifest and migration head at chunk start. -- Whether one existing policy table can be cleanly adopted as immutable - versioned REV policy without schema replacement. - Exact bounded fields for queue inspection and chain/context reads. -- Exact service identity names and provisioning state on then-current main. +- Provisioning/migration state for the exact fixed identities named in + `ACTION_CUSTODY.md` on then-current main. These are implementation-time evidence questions, not reasons to place product lifecycle logic in AUTH. diff --git a/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/PLAN.md b/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/PLAN.md index 8db94fa4d..2afadd811 100644 --- a/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/PLAN.md +++ b/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/PLAN.md @@ -11,18 +11,22 @@ activation waves: REV owns semantics; AUTH-12D2 owns authorization and PREP consumption. 3. Activate concealed reviewer current-work, claim/release/preference, and timer services only after REV queue/lease behavior exists. -4. Amend XINT-002-07 into two ART-only owner waves: packet materialization and - reviewer-evidence binding after lease readiness, then response-evidence - binding only after a human revision obligation exists. XINT-003 activates - the corresponding human REV actions and never takes custody of ART actions. +4. Amend XINT-002-07 into two ART-only owner waves: 07A is the only ActionId + availability transition and activates packet materialization plus + finding-slot evidence binding after lease readiness; 07B changes no ActionId + availability and only extends the active binding evaluator to response slots + after a human revision obligation exists. XINT-003 activates the + corresponding human REV actions and never takes custody of ART actions. 5. Activate bounded `review.chain.read` after the packet/context owner wave. 6. Activate `review.decision` only after the complete hidden atomic Review/FinalAcceptance/CON composition exists. 7. Let XINT-002-05D activate shared human-review revision preparation/Submission - actions and XINT-002-07B extend ART response binding. XINT-003 separately - activates contributor response authority against exact obligation facts. -8. Register the four missing privileged lifecycle/recovery actions as planned, - then activate Project Manager/Operator recovery and fixed service jobs with + actions, then let XINT-002-07B extend ART response binding after hidden REV + obligation/preparation behavior exists. XINT-003-07 consumes both merged + boundaries and separately activates contributor response authority. +8. Record the four missing privileged lifecycle/recovery actions as future 08R + work. Keep their ActionIds unregistered until 08R, then activate + Project Manager/Operator recovery and fixed service jobs with reason-bound least privilege and crossed-race proof. 9. Run complete conformance, then permit REV's single product-route release. diff --git a/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/REVIEW_LOG.md b/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/REVIEW_LOG.md index f81b0ee3b..01a847e46 100644 --- a/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/REVIEW_LOG.md +++ b/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/REVIEW_LOG.md @@ -42,3 +42,25 @@ No reviewer finding remains open. External CI and CodeRabbit results belong to the planning PR trust bundle and external-review response. + +PR #237 CodeRabbit review at head +`8250adf3ac52bc4bfee69fd5299dd70f21fb3ad1` found four valid documentation +integrity issues. The response reconciled 05A/05B availability versus 05D +revision evaluator extension, preserved the registration-only 08R boundary, +removed wording that implied 07A runtime activation, and recorded exact-head +review evidence. No comment was deferred. + +The final CodeRabbit pass added two valid evidence clarifications: immutable +check-run IDs are now recorded for reviewed head `8250adf3`, and the external +response explicitly leaves the required human review open. Neither automated +review nor this response substitutes for human approval of the named contract +boundaries. + +## WS-XINT-003-01 contract reconciliation + +Architecture, security/auth, product/operations, QA/test, senior engineering, +docs, and reuse/dedup reviewed the completed docs-only reconciliation. Valid +findings corrected fixed-service identity drift, ART global-matrix wording, +runtime owner versus sub-wave ambiguity, missing per-action dependencies, +07B/human activation order, and obsolete signed-start gates. All tracks passed; +the final evidence is in `reviews/WS-XINT-003-01-internal-review.md`. diff --git a/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/RISKS.md b/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/RISKS.md index ab710bbdc..4c07e7aca 100644 --- a/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/RISKS.md +++ b/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/RISKS.md @@ -17,3 +17,5 @@ | Activation precedes hidden feature readiness | Critical | Planned-by-default catalogue and exact merged feature manifest gates. | | Historical counts/contracts are treated as current | High | Derive parity from current migrations/catalogue at every chunk start. | | One PR becomes unreviewable | High | Narrow activation waves and explicit allowed/not-allowed files per chunk. | +| One evidence-binding ActionId is activated twice | Critical | 07A alone changes availability; 07B is evaluator-only and requires the exact human obligation/preparation. | +| Policy edits mutate active-guide history | Critical | Append-only versions, draft-only final PREP guard, and PostgreSQL update/delete refusal proof in chunk 02. | diff --git a/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/STATUS.md b/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/STATUS.md index ec987abb9..cf21b03c8 100644 --- a/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/STATUS.md +++ b/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/STATUS.md @@ -2,8 +2,8 @@ ## Current status -Planning complete after focused internal review. No runtime code or action -availability is changed. +WS-XINT-003-01 contract reconciliation is complete and awaiting human +review/merge. No runtime code or action availability is changed. ## Baseline @@ -18,10 +18,17 @@ REV-03P and AUTH-12D2 overlap around review/revision policy persistence and mutation. The first implementation wave must settle one persistence path: REV-owned semantics with AUTH-owned mutation authorization. -## Next step +## Current reconciliation + +- `ACTION_CUSTODY.md` is the canonical action/principal/resource/wave table. +- REV-03P and AUTH-12D2 name one future append-only policy writer path. +- Runtime owner XINT-002-07 is split into planned sub-wave 07A, the sole + reviewer-finding packet/evidence-binding availability transition, and 07B, + an evaluator-only response-slot extension that cannot change availability. +- All registered review actions remain planned; four lifecycle/recovery actions + remain missing until 08R; no service identity is provisioned by chunk 01. -Open and review the planning PR. Do not implement `WS-XINT-003-01` until the -planning PR merges and the user explicitly requests that chunk from a refreshed -current-main contract. +## Next step -Planning complete. Awaiting human approval before implementation. +Keep hosted exact-head gates green, resolve all external review, and obtain +human merge. Then stop before runtime policy work in WS-XINT-003-02. diff --git a/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-01-contract-reconciliation.md b/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-01-contract-reconciliation.md index 851ef46d9..f70fbd2d3 100644 --- a/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-01-contract-reconciliation.md +++ b/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-01-contract-reconciliation.md @@ -2,8 +2,8 @@ ## Status -Proposed. Do not implement until the user explicitly requests it from current -main. Activates no action. +Implemented as a docs-only reconciliation. Awaiting human review/merge. +Activates no action. ## Goal @@ -26,8 +26,11 @@ L1 authorization and product-policy architecture. .agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/CHUNK_MAP.md .agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/chunks/WS-XINT-002-05D-human-review-revision.md .agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/chunks/WS-XINT-002-07-review-artifact-activation.md +.agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/chunks/WS-XINT-002-07A-reviewer-artifact-activation.md +.agent-loop/initiatives/WS-XINT-002-art-auth-end-to-end/chunks/WS-XINT-002-07B-response-artifact-extension.md docs/operations_authorization_service.md docs/spec_authorization_service.md +docs/spec_artifact_storage_service.md docs/spec_review_lifecycle.md docs/operations_roles_permissions.md ``` @@ -47,6 +50,10 @@ compatibility aliases or duplicate policy paths - One canonical table enumerates every human, Project Manager, Operator, and fixed-service action, permission, principal, resource family, surface owner, hidden-feature dependency, and activation wave. +- Every fixed-service row additionally names the exact service identity, static + action membership, server-derived mode/scope, forbidden principal classes, + and required audit/provenance facts. Class-level “fixed service” labels do + not substitute for exact identities. - The table classifies every action as registered planned, missing-to-register, externally owned by XINT-002, or out of scope; canonical AUTH and role docs are updated or explicitly confirmed. @@ -57,15 +64,23 @@ compatibility aliases or duplicate policy paths evidence together with activation. XINT-002-owned ART materialization/binding and shared submission-artifact rows remain with XINT-002. - REV-03P owns immutable/versioned policy semantics and AUTH-12D2 owns mutation - authorization; both contracts name one persistence and writer path. + authorization; both contracts name one persistence and writer path. The + reconciliation names the surviving API/service/repository symbols, existing + mutators to retire, draft-versus-active immutability boundary, and exact + denial proof required from chunk 02. Chunk 01 implements none of that runtime + path. - Historical counts and signed-start/process-gate language are corrected where they could misdirect current implementation. -- XINT-002 artifact/revision boundaries are referenced by exact existing chunk - IDs and are not duplicated. XINT-002-07 is split so response evidence cannot - activate before the human revision obligation exists. -- The XINT-002 split is ART-only: it owns packet materialization, evidence - binding, and shared submission-artifact actions. Human REV action activation - remains in the XINT-003 waves. +- XINT-002 artifact/revision boundaries are referenced by exact chunk IDs and + are not duplicated. XINT-002-07 becomes a split record: 07A activates packet + materialization and the one evidence-binding ActionId for reviewer-finding + slots while hard-denying response-slot shapes; 07B changes no availability + and extends only the response-slot evaluator after the exact human revision + obligation/preparation exists. +- The XINT-002-07 split is ART-only: packet materialization and evidence binding + only. XINT-002-05D remains owner of shared human-review submission + preparation/create activation. Human REV action activation remains in the + XINT-003 waves. - Every later activation remains planned and fail closed. ## Verification commands diff --git a/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-04-review-context-activation.md b/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-04-review-context-activation.md index e5f2630aa..0c5b9a146 100644 --- a/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-04-review-context-activation.md +++ b/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-04-review-context-activation.md @@ -8,15 +8,14 @@ on current main before an explicit user request. L1 confidential artifact access ## Goal Activate human `review.context.read` and `review.finding_evidence.ingest` against -the exact lease/packet/finding context. Amend XINT-002-07A to own only fixed -`artifact.review_packet.materialize` and reviewer-evidence binding. XINT-002-07B -remains ART-only and extends response binding after a human revision obligation -exists. +the exact lease/packet/finding context. Consume the already-merged XINT-002-07A +fixed `artifact.review_packet.materialize` and reviewer-finding binding +capabilities. The ART contract split is completed by WS-XINT-003-01, not here. ## Allowed files Enumerate exact REV context/finding service, AUTH composers/activation parity, -XINT-002 ART-only contract amendments, routes, tests, canonical specs, docs, and +merged XINT-002-07A ART-only manifest, routes, tests, canonical specs, docs, and evidence files at current-main start. ## Not allowed diff --git a/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-07-human-revision-activation.md b/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-07-human-revision-activation.md index ed146944c..8a4822f11 100644 --- a/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-07-human-revision-activation.md +++ b/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-07-human-revision-activation.md @@ -9,9 +9,9 @@ authority and immutable predecessor lineage. ## Goal Activate human `review.finding_response_evidence.ingest` against the exact -obligation/preparation. Coordinate XINT-002-05D as sole owner of shared artifact -preparation/`submission.create` and XINT-002-07B as sole owner of ART response -binding. XINT-002 owns no human REV action. +obligation/preparation. Consume XINT-002-05D as sole owner of shared artifact +preparation/`submission.create` and the already-merged XINT-002-07B ART response +evaluator. XINT-002 owns no human REV action. ## Allowed files @@ -39,9 +39,10 @@ submission authorization protocol. - Exactly one N+1 Submission consumes one preparation/obligation; concurrent attempts have one winner and preserve all prior immutable history. - Human and checker revision sources remain mutually exclusive. -- XINT-002-07B response evidence activates only after the obligation and - preparation exist and denies every CheckerRun-rooted remediation shape; this - statement refers to ART binding, while XINT-003 owns the human action. +- XINT-002-07B extends the active ART binding evaluator to response slots and + introduces response-slot evaluation without changing ActionId availability; + it denies CheckerRun-rooted remediation, and XINT-003 owns the corresponding + human action. ## Verification and reviewers diff --git a/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-08A-review-recovery-activation.md b/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-08A-review-recovery-activation.md index d8de05ff5..a2126d975 100644 --- a/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-08A-review-recovery-activation.md +++ b/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-08A-review-recovery-activation.md @@ -1,4 +1,4 @@ -# Chunk Contract: WS-XINT-003-08A — Human And Operator Recovery Activation +# Chunk Contract: WS-XINT-003-08A — Project Manager And Operator Recovery Activation ## Status and risk diff --git a/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/reviews/WS-XINT-003-01-external-review-response.md b/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/reviews/WS-XINT-003-01-external-review-response.md new file mode 100644 index 000000000..d3bcd8f97 --- /dev/null +++ b/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/reviews/WS-XINT-003-01-external-review-response.md @@ -0,0 +1,50 @@ +# External Review Response: WS-XINT-003-01 + +## Comments addressed + +- Reconciled shared submission custody with the canonical XINT-002 contract: + `artifact.submission_bundle.prepare` becomes available in 05A and + `submission.create` in 05B; 05D extends both evaluators to the exact + human-review revision context without a second ActionId activation. +- Preserved the 08R boundary by stating that the four recovery/lifecycle + ActionIds remain unregistered until the registration-only 08R chunk. +- Reworded 07A/07B trust evidence as planned availability/evaluator boundaries; + this planning chunk registers or enables no runtime ActionId. +- Bound the review record to CodeRabbit's reviewed PR head + `8250adf3ac52bc4bfee69fd5299dd70f21fb3ad1`. Final exact-head evidence is the + immutable GitHub check suite attached to the post-correction PR head. + +## Comments deferred + +None. + +## Human decisions needed + +Human review remains required for action completeness, policy-writer +boundaries, ART ownership, and activation sequencing. This response does not +close those decisions. + +## Commands and exact-head checks + +- PASS — `python3 scripts/check_stale_authorization_docs.py` +- PASS — `python3 scripts/check_stale_artifact_contracts.py` +- PASS — `python3 scripts/check_stale_workstream_wording.py` +- PASS — `python3 scripts/check_markdown_links.py` +- PASS — `git diff --check` + +For reviewed head `8250adf3ac52bc4bfee69fd5299dd70f21fb3ad1`, immutable +GitHub check runs completed successfully: + +- Agent Gates jobs `91360730659` and `91360846607`; +- Backend test jobs `91360730691` and `91361080477`; and +- CodeRabbit review completed against that head. + +The same deterministic commands pass on correction head `c65489a7`. Agent +Gates, Backend, and CodeRabbit must also complete successfully on the final PR +head before human merge; a later passing head does not erase this evidence. + +## Remaining risks + +This is documentation-only reconciliation. Each runtime chunk must still +refresh current-main feature facts and prove its activation, stale-context, +revocation, replay, concurrency, and atomic-evidence boundaries. diff --git a/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/reviews/WS-XINT-003-01-internal-review.md b/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/reviews/WS-XINT-003-01-internal-review.md new file mode 100644 index 000000000..620e63aad --- /dev/null +++ b/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/reviews/WS-XINT-003-01-internal-review.md @@ -0,0 +1,41 @@ +# Internal Review: WS-XINT-003-01 + +## Scope + +Final working-tree review of the docs-only REV-AUTH contract reconciliation. + +## Results + +- Architecture: PASS after preserving canonical service identities, allowing + the artifact spec, preserving ART global matrices, and distinguishing runtime + owner `WS-XINT-002-07` from planning sub-waves 07A/07B. +- Security/auth: PASS after establishing one binding availability transition, + exact service subjects/modes/scopes/forbidden principals/audit facts, and one + fail-closed policy writer contract. +- Product/operations: PASS after preserving reviewer, contributor, Project + Manager, Operator, contribution, and checker-remediation boundaries. +- QA/test: PASS after adding per-action hidden-feature dependencies and fixing + the order: hidden REV obligation/preparation, ART 07B evaluator, then human + XINT-003-07 activation. +- Senior engineering: PASS WITH LOW RISKS; both low stale-wording notes were + corrected after review. +- Docs: PASS after making XINT-003 current sequence authoritative and adding + complete dependency coverage. +- Reuse/dedup: PASS WITH LOW RISKS. Its stale combined-contract wording was + corrected. The existing chunk-05 filename is mildly imprecise, but its unique + chunk ID, title, goal, map entry, and body consistently define bounded chain + read; renaming an established planning filename adds no contract clarity and + is intentionally deferred. + +No blocking finding remains. All reviewer sessions completed. + +## Deterministic evidence + +- `python3 scripts/check_stale_authorization_docs.py` +- `python3 scripts/check_stale_artifact_contracts.py` +- `python3 scripts/check_stale_workstream_wording.py` +- `python3 scripts/check_markdown_links.py` +- `git diff --check` + +No runtime test is applicable because this chunk changes planning and canonical +documentation only. Hosted exact-head CI remains required for the PR. diff --git a/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/reviews/WS-XINT-003-01-pr-trust-bundle.md b/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/reviews/WS-XINT-003-01-pr-trust-bundle.md new file mode 100644 index 000000000..d7eba8d6f --- /dev/null +++ b/.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/reviews/WS-XINT-003-01-pr-trust-bundle.md @@ -0,0 +1,120 @@ +# PR Trust Bundle: WS-XINT-003-01 + +## Chunk + +`WS-XINT-003-01` — REV-AUTH Contract Reconciliation. + +## Goal + +Settle complete action custody, the sole review/revision policy writer path, +and the safe ART finding/response activation order before runtime work. + +## Intent and result + +Reconcile the complete review/revision authorization contract before runtime +work. The result is one canonical custody inventory, one future policy writer, +and one safe ART evidence-binding activation sequence. No behavior is active. + +## Scope + +Planning/canonical Markdown only. No backend code, Alembic migration, catalogue +mapping, runtime `ActionOwner`, service provisioning, route, job, or product +lifecycle behavior changed. + +## Design + +- 19 existing `review.*` actions stay registered planned. +- Four recovery/lifecycle actions stay missing until registration-only 08R. +- REV owns policy semantics and immutable versions; AUTH owns PREP, mutation + authorization, and decision evidence. +- Existing project ReviewPolicy/RevisionPolicy records are reused. XINT-003-02 + will introduce the sole append-only writer and retire the four named legacy + callable mutation/construction paths. +- Runtime ART owner remains `WS-XINT-002-07`. Planning sub-wave 07A records the + future packet/finding binding availability boundary; it does not register or + enable a runtime ActionId. 07B only extends planned response evaluation. +- Hidden REV obligation/preparation precedes 07B; human response activation + follows both. + +## Proof + +The canonical table contains 25 local human/privileged/service rows, four +externally owned shared actions, and 29 matching hidden-feature dependency +rows. It fixes exact principals, scopes, resources, owners, waves, identities, +static membership, forbidden principals, and audit/provenance facts. + +## Acceptance criteria proof + +- All 19 registered planned REV actions, four missing registration actions, + two policy actions, and four XINT-002 shared actions are classified. +- Every action has an exact hidden-feature dependency; every fixed service has + an exact identity, membership, mode/scope, forbidden principals, and audit + facts. +- REV-03P/AUTH-12D2 name one external service and internal repository writer + path plus the exact legacy mutators to retire. +- Runtime ART owner remains `WS-XINT-002-07`; 07A alone records the planned + availability transition. No runtime ActionId becomes registered or callable, + and 07B is evaluator-only after hidden REV obligation/preparation behavior. +- All runtime actions remain planned/unavailable and four actions remain + unregistered. + +## Commands run + +- `python3 scripts/check_stale_authorization_docs.py` +- `python3 scripts/check_stale_artifact_contracts.py` +- `python3 scripts/check_stale_workstream_wording.py` +- `python3 scripts/check_markdown_links.py` +- `git diff --check` + +## Test delta + +No test, skip, exclusion, or assertion changed. The hosted Backend semantic- +lane suite and coverage gate run on the exact PR head. + +## CI integrity + +No workflow, dependency, test runner, Ruff rule, coverage threshold, or package +script changed. Agent Gates and Backend must pass on the exact final head. + +Deterministic stale-doc, artifact-contract, Workstream wording, Markdown-link, +and whitespace checks pass. No tests or CI configuration were changed or +weakened. Hosted exact-head Agent Gates and Backend CI remain required. + +## Review + +Architecture, security/auth, product/operations, QA/test, docs, and +reuse/dedup passed. Senior engineering passed with low stale-wording risks, +which were corrected. The remaining filename observation is documented in the +internal review and does not create duplicate identifiers or behavior. + +## External review + +CodeRabbit is required. Every valid comment must be fixed or explicitly +resolved before human merge. + +CodeRabbit reviewed PR head `8250adf3ac52bc4bfee69fd5299dd70f21fb3ad1` and +reported the four corrections recorded in the external-review response. The +post-correction commit is bound by GitHub's immutable PR-head check-suite SHA; +embedding that commit's own SHA inside the commit is not possible. Human merge +must use the head for which Agent Gates, Backend, and CodeRabbit are successful. + +## Remaining risks + +This PR defines future enforcement but activates none. Each later runtime chunk +must refresh exact current-main symbols, migration head, hidden feature +manifest, and denial/concurrency proof before activation. + +## Follow-up work + +After human merge and a separate explicit request, refresh WS-XINT-003-02. Do +not begin runtime policy work automatically. + +## Human review focus + +Confirm action completeness, the sole policy writer boundary, ART runtime owner +versus sub-wave distinction, the 07B-before-human-activation order, and absence +of runtime activation. + +## Human merge ownership + +Only the human may merge this PR. diff --git a/docs/operations_authorization_service.md b/docs/operations_authorization_service.md index 5241c7e5d..5a52c81b9 100644 --- a/docs/operations_authorization_service.md +++ b/docs/operations_authorization_service.md @@ -729,9 +729,10 @@ admits only covered Project Manager/Audit Authority or system Operator grants; Finance, Access Administrator, contributors, and services receive concealed denial. Its active-guide projection excludes retired compensation configuration. Four later REV registrations add exactly four planned and zero active actions. -Review-evidence binding is already registered planned and unavailable under -`WS-XINT-002-07`; it remains non-operational until exact feature proof and a -separate reviewed activation gate exist. +Review-evidence binding is already registered planned and unavailable. Only +`WS-XINT-002-07A` may activate it, initially for reviewer-finding slots while +response slots hard deny. `WS-XINT-002-07B` may later extend the evaluator for +exact human-revision response slots but changes no ActionId availability. Migration `0021` preserves historical audit rows with null `action_id`. Inspect non-null action evidence only by bounded ActionId, request/correlation IDs, and diff --git a/docs/operations_roles_permissions.md b/docs/operations_roles_permissions.md index 2d2a1915f..01b2ec2c5 100644 --- a/docs/operations_roles_permissions.md +++ b/docs/operations_roles_permissions.md @@ -44,6 +44,13 @@ requirements remain available only through task-scoped work surfaces. Administrative grants do not imply contributor capability. Holding one does not permit claiming tasks, submitting work, or recording review decisions. +Review/revision authority follows the closed action custody in +`.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/ACTION_CUSTODY.md`. +Project Managers may configure policy or perform only covered-project recovery; +Operators receive reason-bound operational recovery only. Neither receives a +review decision or generic artifact capability without the independent exact +grant/action required for that operation. + ## Contributor Grants | Grant | Scope | Purpose | diff --git a/docs/spec_artifact_storage_service.md b/docs/spec_artifact_storage_service.md index e7af62077..e8c4e56c7 100644 --- a/docs/spec_artifact_storage_service.md +++ b/docs/spec_artifact_storage_service.md @@ -402,7 +402,8 @@ release charges or mutate capacity. The binding lookup resource vocabulary is exactly `project`, `project_guide`, `guide_source_snapshot`, `guide_source_snapshot_item`, `task`, `submission`, or -`checker_run`. Review lookup remains deferred until WS-XINT-002-07. The audit +`checker_run`. Review lookup remains deferred until WS-XINT-002-07A; response- +slot evaluation is separately deferred to evaluator-only 07B. The audit resource vocabulary is exactly `artifact_binding`, `artifact_content`, `artifact_replica`, `artifact_receipt`, `artifact_verification_job`, or `artifact_recovery_attempt`. Adding a product or diff --git a/docs/spec_authorization_service.md b/docs/spec_authorization_service.md index 4e369a252..3a74d072d 100644 --- a/docs/spec_authorization_service.md +++ b/docs/spec_authorization_service.md @@ -304,6 +304,12 @@ action activates, its dedicated AUTH custodian must integrate the complete feature proof according to `ACTIVATION_CUSTODY.md` and the reviewed `.agent-loop/initiatives/WS-XINT-001-lifecycle-boundary-reconciliation/AUTH_REV_HANDOFF.md`. +The AUTH-REV table immediately below is retained as runtime catalogue history. +For all future work, the canonical planning custody, principals, resource +families, fixed identities, and exact XINT-003 waves are in +`.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/ACTION_CUSTODY.md`. +Chunk 01 changes no runtime owner or availability. + | AUTH activation custodian | Exact planned ActionIds | |---|---| | `WS-AUTH-001-REV-05` | `review.queue.read`, `review.queue.inspect` | @@ -426,6 +432,10 @@ A mapping is not a permission alias. | `WS-AUTH-001-ART-06B` | `artifact.checker_output.write`, `artifact.checker_output.binding.create` | | `WS-XINT-002-07` | `artifact.review_packet.materialize`, `artifact.review_evidence.binding.create` | +Within that single runtime owner, planning sub-wave 07A is the only +availability transition and initially permits finding slots; 07B changes no +availability and only extends the evaluator to response slots. + The `OPERATOR` suffix names future activation custody only; it creates no Operator grant or entitlement. WS-XINT-002-03 activates the three internal service actions and WS-XINT-002-04A activates guide-source ingest; the other 18 @@ -462,7 +472,10 @@ remain planned and unavailable, and add no migration. | `artifact.post_submit.checker_input.materialize` | `artifact.checker_input.materialize` | fixed materializer service | checker run and immutable bindings | `06A` | | `artifact.checker_output.write` | `artifact.checker_output.write` | fixed checker-output service | checker run | `06B` | | `artifact.review_packet.materialize` | `artifact.review_packet.materialize` | fixed materializer service | exact active lease and Submission packet | `WS-XINT-002-07` | -| `artifact.review_evidence.binding.create` | `artifact.binding.create` | fixed binding service | exact verified review evidence slot | `WS-XINT-002-07` | +| `artifact.review_evidence.binding.create` | `artifact.binding.create` | fixed binding service | finding slot in 07A; response slot added by evaluator-only 07B | `WS-XINT-002-07` | + +The owner cells above deliberately retain the exact runtime `ActionOwner`. +07A/07B are contract sub-waves, not new catalogue owner values. The fixed internal service identities and their complete action sets are also closed: diff --git a/docs/spec_review_lifecycle.md b/docs/spec_review_lifecycle.md index b19965e2e..4af6e36a3 100644 --- a/docs/spec_review_lifecycle.md +++ b/docs/spec_review_lifecycle.md @@ -8,12 +8,21 @@ here is not yet available in the production API. Each owning REV chunk must merge hidden behavior, AUTH must activate the exact registered actions, and `WS-REV-001-13C` must pass the joint release gate before any surface is exposed. -The implementation sequence is defined by -`WS-REV-001-review-revision-lifecycle/CHUNK_MAP.md` under `.agent-loop`. This -contract defines product behavior and subsystem boundaries; it does not itself +The WS-REV chunk map under `.agent-loop` records feature-owned hidden behavior. +For current REV-AUTH integration and activation order, the WS-XINT-003 chunk +map and canonical action custody supersede its historical activation labels. +This contract defines product behavior and subsystem boundaries; it does not itself implement a route, database table, job, authorization evaluator, artifact capability, contribution participant, or frontend. +The canonical REV-AUTH action custody is +`.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/ACTION_CUSTODY.md`. +REV owns lifecycle and immutable policy semantics; AUTH owns evaluation, PREP, +and decision evidence. ReviewPolicy and RevisionPolicy use one future +append-only project-policy writer from XINT-003-02. XINT-002-07A alone activates +the ART evidence-binding ActionId for finding slots; 07B only extends its +evaluator to response slots after an exact human revision obligation exists. + ## Precedence And Archival Inputs The supplied WS-REV and WS-IMP Markdown/PDF files under