Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -51,6 +51,10 @@ mappings, and availability must remain identical.
| `WS-AUTH-001-ART-06B` | `artifact.checker_output.write`, `artifact.checker_output.binding.create` |
| `WS-XINT-002-07` | `artifact.review_packet.materialize`, `artifact.review_evidence.binding.create` |

Runtime owner `WS-XINT-002-07` contains two planning sub-waves: 07A is the
only availability transition and initially permits finding slots; 07B changes
no availability and only extends the evaluator to response slots.

`WS-AUTH-001-ART-CUSTODY` historically transferred 25 rows. WS-XINT-002-01
reconciles the live catalogue by removing the six unused multi-step upload rows
and registering three end-to-end bundle/review rows. The resulting 22 rows have
Expand All @@ -68,6 +72,12 @@ eight fixed-service identities and sixteen matrix memberships.

## REV custody transfer

The canonical current planning table is
[`WS-XINT-003/ACTION_CUSTODY.md`](../WS-XINT-003-rev-auth-end-to-end/ACTION_CUSTODY.md).
It supersedes the historical placeholder grouping below for future planning,
while leaving runtime `ActionOwner`, permission, mapping, and availability
unchanged until each exact XINT-003 activation wave.

| AUTH activation chunk | Exact planned ActionIds |
|---|---|
| `WS-AUTH-001-REV-05` | `review.queue.read`, `review.queue.inspect` |
Expand All @@ -86,14 +96,30 @@ custodian labels grant no reviewer, Operator, or service authority. The four
proposed lifecycle actions remain unregistered, and PREP remains separately
human-gated.

The exact planning-wave replacement is:

| XINT-003 wave | Registered planned REV ActionIds |
|---|---|
| `WS-XINT-003-03A` | `review.queue.read`, `review.claim`, `review.release`, `review.decline_preference` |
| `WS-XINT-003-03B` | `review.preference_expiry.run`, `review.lease_expiry.run` |
| `WS-XINT-003-04` | `review.context.read`, `review.finding_evidence.ingest` |
| `WS-XINT-003-05` | `review.chain.read` |
| `WS-XINT-003-06` | `review.decision` |
| `WS-XINT-003-07` | `review.finding_response_evidence.ingest` |
| `WS-XINT-003-08A` | `review.queue.inspect`, `review.lease.force_release`, `review.queue.routing.override`, `review.queue.routing.correct`, `review.queue.close` |
| `WS-XINT-003-08B` | `review.reconcile.run`, `review.artifact_reference.reconcile`, `review.projection.rebuild` |

This is 19 rows with cardinalities `4/2/2/1/1/1/5/3`. XINT-002-owned ART
actions and shared submission actions are excluded.

## Additive registration gates

The following values are approved boundary proposals, not registered runtime
actions on trusted `main`:

| Registration chunk | Future activation chunk | Proposed ActionId -> PermissionId |
|---|---|---|
| `WS-AUTH-001-REV-REG` | `WS-AUTH-001-REV-LIFECYCLE` | `review.revision_context.repair` -> `project.task.manage`; `review.revision_context.legacy_close` -> `operations.reconcile.run`; `review.revision_obligation.close` -> `project.task.manage`; `review.lifecycle.activation.manage` -> `operations.reconcile.run` |
| `WS-XINT-003-08R` | `WS-XINT-003-08A` / `WS-XINT-003-08B` | `review.revision_context.repair` -> `project.task.manage`; `review.revision_context.legacy_close` -> `operations.reconcile.run`; `review.revision_obligation.close` -> `project.task.manage`; `review.lifecycle.activation.manage` -> `operations.reconcile.run` |

These are declared future registration gates, not executable chunk contracts.
Neither may receive a full contract or start until the owning feature publishes exact
Expand All @@ -110,7 +136,8 @@ fresh replay.

Counts are derived from trusted `main` when a gate executes. REV registration
adds exactly four planned actions and zero active actions. WS-XINT-002-01
registers review-evidence binding under `WS-XINT-002-07` and adds it to the
registers review-evidence binding under runtime owner `WS-XINT-002-07`; planned
sub-wave 07A adds it to the
existing `workstream.artifact.binding` static row without adding an identity or
database grant.

Expand Down
Original file line number Diff line number Diff line change
@@ -1,5 +1,9 @@
# Chunk Map: WS-AUTH-001 - Workstream Authorization Service

Review/revision activation custody is now planned canonically by
`../WS-XINT-003-rev-auth-end-to-end/ACTION_CUSTODY.md`. Historical AUTH-REV
labels are not alternate implementation paths.
Comment thread
coderabbitai[bot] marked this conversation as resolved.

The complete ART-facing catalogue and runtime dependency is now planned in
`../WS-XINT-002-art-auth-end-to-end/CHUNK_MAP.md`. The historical ART custody
entries in this file remain baseline identifiers only until that planning
Expand Down Expand Up @@ -80,7 +84,7 @@ feature manifest exists, then requires a separate explicit start.

| Chunk | Title | Risk | Status |
|---|---|---:|---|
| `WS-AUTH-001-REV-REG` | REV Lifecycle Action Registration | L1 | Blocked on complete REV typed manifests |
| Historical alias `WS-AUTH-001-REV-REG` | Superseded by `WS-XINT-003-08R` registration | L1 | Not executable; use canonical XINT-003 custody |
| `WS-AUTH-001-ART-02D-INTERNAL` | ART 02D Internal Action Activation | L1 | Feature-gated |
| `WS-AUTH-001-ART-02D-OPERATOR` | ART 02D Operator Read/Status And Independently Evaluated Retry Activation | L1 | Feature-gated |
| `WS-AUTH-001-ART-03` | ART 03 Guide Source Action Activation | L1 | Feature-gated |
Expand All @@ -96,8 +100,9 @@ feature manifest exists, then requires a separate explicit start.
| `WS-AUTH-001-REV-09A` | REV 09A Finding Response Evidence Activation | L1 | Feature/ART-gated |
| `WS-AUTH-001-REV-11` | REV 11 Recovery And Reconciliation Activation | L1 | Feature/service-gated |
| `WS-AUTH-001-REV-12` | REV 12 Artifact Reconciliation And Projection Activation | L1 | Feature/service-gated |
| `WS-AUTH-001-REV-LIFECYCLE` | REV Lifecycle Repair Action Activation | L1 | Blocked until REV-REG and four hidden manifests merge |
| `WS-XINT-002-07` | Review Packet And Evidence Binding Activation | L1 | Feature-gated on exact REV lease/version and ART evidence behavior |
| Historical alias `WS-AUTH-001-REV-LIFECYCLE` | Superseded by `WS-XINT-003-08A` and `WS-XINT-003-08B` activation | L1 | Not executable; use canonical XINT-003 custody |
| `WS-XINT-002-07A` (runtime owner `WS-XINT-002-07`) | Review Packet And Finding Evidence Binding Activation | L1 | Feature-gated on exact REV lease/version and ART finding evidence behavior |
| `WS-XINT-002-07B` (runtime owner `WS-XINT-002-07`) | Response Evidence Binding Evaluator Extension (no availability change) | L1 | 07A plus exact human revision obligation/preparation |

## Dependency order

Expand Down
Original file line number Diff line number Diff line change
@@ -1,5 +1,10 @@
# Decisions: WS-AUTH-001 - Workstream Authorization Service

WS-XINT-003 preserves REV ownership of policy semantics and selects one
AUTH-authorized append-only policy writer. Its waves prospectively replace
historical AUTH-REV placeholders; runtime ownership/availability changes only
in each later activation chunk.

## D1: Adopt WS-AUTH-001 as the authorization authority source

Status: accepted by the user on 2026-07-11.
Expand Down
Original file line number Diff line number Diff line change
@@ -1,5 +1,8 @@
# Plan: WS-AUTH-001 - Workstream Authorization Service

For review/revision work, use the canonical WS-XINT-003 action custody and
sequence. Historical AUTH-REV wave labels remain evidence only.

## Goal

Replace the token-role bootstrap with the adopted Workstream-owned actor,
Expand Down
Original file line number Diff line number Diff line change
@@ -1,5 +1,11 @@
# Risks: WS-AUTH-001 - Workstream Authorization Service

Planned REV custody permits only the reconciled XINT-003-02 policy-writer path
and designates XINT-002-07A as the sole evidence-binding availability
transition, with 07B evaluator-only. These are planning rules, not current
runtime protections; enforcement begins only when the named activation gates
merge and activate their exact actions.

## AUTH-12 planning risks — 2026-07-29

- Guide create/update currently co-mutate review, revision, and retired
Expand Down
Original file line number Diff line number Diff line change
@@ -1,5 +1,9 @@
# Status: WS-AUTH-001 - Workstream Authorization Service

WS-XINT-003-01 reconciles future REV activation custody and policy-writer
ownership. It changes no catalogue/runtime state: all registered REV actions
remain planned and four lifecycle actions remain unregistered.

## Current status

Planning merged through PR #91 as
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,36 @@ Proposed and inactive after 12D.
Add separately authorized routes for review and revision policy records after
12D alone removes the embedded guide create/update fields.

This contract is reconciled with REV-03P by WS-XINT-003-01. REV owns the
immutable/versioned policy semantics; AUTH owns the mutation authorization,
PREP consumption, and decision evidence. Chunk WS-XINT-003-02 implements the
single path below; neither parent contract may build an alternate writer.

## One writer path

- Surviving API: separate `PUT /projects/{project_id}/review-policy` and
`PUT /projects/{project_id}/revision-policy` routes in
`backend/app/modules/projects/router.py`, each declaring its exact primary
ActionId.
- Surviving service: new `ProjectPolicyMutationService` methods
`replace_review_policy()` and `replace_revision_policy()`.
- Surviving repository: new append-only
`ProjectRepository.add_review_policy_version()` and
`ProjectRepository.add_revision_policy_version()` methods over the existing
`ReviewPolicy` and `RevisionPolicy` tables/models, upgraded as necessary for
immutable version provenance.
- Retired callable mutators: `ProjectRepository.upsert_review_policy()`,
`ProjectRepository.upsert_revision_policy()`,
`ProjectService._review_policy_model()`, and
`ProjectService._revision_policy_model()`.
- No compatibility route, alias, second model/table, fallback constructor, or
dual repository path survives.

Policies may be appended or replaced only while the exact guide version is a
draft. Activation freezes the selected policy versions: active-guide policy
rows are immutable, and later edits require a new draft guide/version rather
than an in-place update.

## Why this chunk exists

Guide management must not imply review/revision-policy authority. Retired
Expand Down Expand Up @@ -72,6 +102,11 @@ compatibility.
and concurrency follow the parent invariants.
- OpenAPI declares exactly one primary action per new route and no compatibility
endpoint is added.
- Tests prove old mutators are absent, direct update/delete of persisted policy
versions is refused, stale draft/active guide, stale current policy,
revocation, wrong grant/project/guide, replay, copied/wrong PREP handles, and
crossed concurrent replacements deny without a partial policy or allowed
decision record.

## Verification commands

Expand Down
Original file line number Diff line number Diff line change
@@ -1,5 +1,8 @@
# Chunk Map: WS-REV-001 Review And Revision Lifecycle

REV-03P is reconciled into WS-XINT-003-02 and is not an independent policy
writer. AUTH activation follows the exact XINT-003 waves.

## Rule

One executable chunk maps to one PR. Merged parent IDs remain non-executable
Expand All @@ -23,10 +26,10 @@ typed symbol/manifest, and tests.
| `WS-REV-001-02A2` | Prepared Superseded Guide Reactivation | L1 | Historical | Retired from REV; upstream owner concern |
| `WS-REV-001-02B` | Locked Review Policy And Dormant Task Lifecycle Compatibility | L1 | Historical | Superseded; any upstream gap is reported to its owner |
| `WS-REV-001-02C` | Submission Attribution, Context, And Immutable Lineage | L1 | Historical | Superseded as an ownership chunk; REV consumes owner-supplied Submission lineage |
| `WS-REV-001-PLAN3` | Allow-Review Boundary Reset | L1 | Signed start required on exact current main | Proposed planning correction; not canonically active |
| `WS-REV-001-03P` | Review And Revision Policy Persistence | L1 | PLAN3; signed separate start | Recommended first REV runtime chunk; proposed contract, not started |
| `WS-REV-001-PLAN3` | Allow-Review Boundary Reset | L1 | Historical | Merged boundary correction |
| `WS-REV-001-03P` | Review And Revision Policy Persistence | L1 | Reconciled into `WS-XINT-003-02` | Planning input only; never executable independently |
| `WS-REV-001-03` | Review Queue And Lease Persistence | L1 | PLAN3 | Non-executable split record |
| `WS-REV-001-03A` | Queue And Lease Base Persistence | L1 | 03P; exact merged `allow_review`, Submission/artifact, and actor handoffs; signed separate start | Proposed contract, not started |
| `WS-REV-001-03A` | Queue And Lease Base Persistence | L1 | merged `WS-XINT-003-02`; exact `allow_review`, Submission/artifact, and actor handoffs | Proposed contract; requires current-main refresh and explicit user request |
| `WS-REV-001-03B` | Normalized Review Packet Manifest Persistence | L1 | 03A; exact ART packet-membership owner chunk merged | Proposed; owner chunk unscheduled |
| `WS-REV-001-04` | Review Chain Persistence | L1 | 03B | Non-executable split record |
| `WS-REV-001-04A` | Immutable Review Chain And Decision Request Persistence | L1 | 03B; current actor constraints | Proposed; no contract yet |
Expand Down Expand Up @@ -73,7 +76,7 @@ typed symbol/manifest, and tests.

```text
PLAN -> 01 -> 02(parent) -> PLAN2 -> 02A(historical, superseded)
-> PLAN3(boundary reset) -> 03P
-> PLAN3(boundary reset) -> WS-XINT-003-02 (03P planning input)
-> 03(parent) -> 03A -> 03B
-> 04(parent) -> 04A -> 04B
-> 05(parent) -> 05A -> 05B
Expand Down Expand Up @@ -125,6 +128,7 @@ configuration, or coverage changes add CI integrity.

## Stop condition

Complete only the proposed `WS-REV-001-PLAN3`, then stop. Never resume 02A, 02A1, 02A2,
02A3, 02A4, 02B, or 02C as REV implementation. The next eligible runtime chunk
is 03P, only after merge and a signed explicit start on exact current main.
PLAN3 is complete. Never resume 02A, 02A1, 02A2, 02A3, 02A4, 02B, or 02C as
REV implementation. Policy work proceeds only through `WS-XINT-003-02`; later
REV feature chunks require current-main contract refresh and an explicit user
request under the ordinary engineering loop.
Original file line number Diff line number Diff line change
@@ -1,5 +1,9 @@
# Decisions: WS-REV-001 Review And Revision Lifecycle

REV retains policy semantics and immutable version rules; XINT-003-02 owns the
one AUTH-authorized persistence/writer cutover over existing project policy
records. No duplicate REV writer is permitted.

## Decisions

### D1 - Existing Submission Is SubmissionVersion
Expand Down
Original file line number Diff line number Diff line change
@@ -1,5 +1,9 @@
# Plan: WS-REV-001 Review And Revision Lifecycle

Current cross-initiative authority and policy-writer sequencing is canonical in
`../WS-XINT-003-rev-auth-end-to-end/ACTION_CUSTODY.md`. Planning artifacts do
not require signed starts, active-chunk state, or merge intents.

## Boundary Reset — 2026-07-22

This section supersedes every later passage that assigns Project Guide setup,
Expand Down Expand Up @@ -27,10 +31,10 @@ This PLAN3 candidate is reconciled from current trusted main
changes are discovery evidence only. The detailed facts below were captured at
the earlier PLAN2 snapshot and are historical unless independently re-proven.

Signed loop memory still records retired 02A1 as the next chunk because that is
the last merged successor declaration. PLAN3 does not treat that projection as
implementation authority. Its schema-v2 merge intent replaces the successor
with 03P; only the post-merge signed projection may then authorize a 03P start.
Generated loop memory naming retired 02A1 is historical only and has no
implementation authority. The current WS-XINT-003 chunk map governs future
cross-initiative sequence; implementation still requires an explicit user
request under the ordinary repository engineering loop.
They are not runtime dependencies until their exact owner chunk, PR, merge SHA,
schema head, typed contract, and tests exist on trusted main.

Expand Down Expand Up @@ -308,11 +312,11 @@ errors but do not substitute for database enforcement.

## Chunk strategy

PLAN3 is a proposed planning-only boundary correction, not signed active work. The entire 02A family,
PLAN3 is merged historical boundary correction. The entire 02A family,
02B, and 02C are retired historical records and are never executable by REV.
03P is the first proposed REV runtime child and contains only REV-owned policy;
it still requires current-main refresh, risk routing, plan review, signed start,
and exact owner evidence. Queue persistence follows separately in 03A.
03P is reconciled into WS-XINT-003-02 and is not independently executable.
That chunk requires current-main refresh, risk routing, plan review, and exact
owner evidence. Queue persistence follows separately in 03A.

The detailed order is maintained in `CHUNK_MAP.md`. The important boundaries
are:
Expand Down Expand Up @@ -375,12 +379,11 @@ head, preflight, upgrade, downgrade/re-upgrade where safe, protected-row refusal
transactional failure behavior, and direct-SQL constraints.

Every chunk runs stale Workstream/AUTH/ART/REV wording scans applicable on
current main, Markdown links, `git diff --check`, merge-intent validation through
agent gates, and required internal reviewer fanout. Test changes may not weaken,
current main, Markdown links, `git diff --check`, agent gates, and required
internal reviewer fanout. Test changes may not weaken,
skip, or rewrite existing checker-caused revision coverage.

## Stop rule

Complete PLAN3 and stop. Automated memory may name 03P only with a signed
explicit-start gate. No runtime child starts automatically, and no retired 02A-family,
Complete PLAN3 and stop. No runtime child starts automatically, and no retired 02A-family,
02B, or 02C contract may be revived as REV work.
Original file line number Diff line number Diff line change
@@ -1,5 +1,9 @@
# Risks: WS-REV-001 Review And Revision Lifecycle

Duplicate policy models/writers are prohibited. Active-guide policy history is
protected by append-only versions, a draft-only final PREP guard, and database
update/delete refusal proof in XINT-003-02.

| ID | Risk | Severity | Mitigation |
|---|---|---:|---|
| R0 | REV converts a consumed upstream dependency into feature ownership and edits Project Guide, Task intake, Checker, AUTH, ART, or CON internals | Critical | REV starts at final current `allow_review`; record missing typed owner contracts and stop. Boundary review blocks any REV chunk that edits upstream behavior rather than a declared participant owned by that subsystem. |
Expand Down
Loading
Loading