Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,7 @@ activation order below.

The remaining AUTH order requires one correction before submission work can go
live: split XINT-06 into `06A` (pre-submit materializer only, after hidden
ART-04B and before XINT-05A) and `06B` (post-submit materializer plus checker
ART-04B1-04B3 and before XINT-05A) and `06B` (post-submit materializer plus checker
output write/binding, after ART-06A/06B). This prevents contributor preparation
from activating while its mandatory fixed materializer still denies.

Expand Down Expand Up @@ -99,7 +99,8 @@ immutable historical records and the deterministic deletion proof. They are
not an active design, grant, route, compatibility alias, or permission to
implement a second intake path.

ART-04A1 through 04C2 then implement one hidden continuous surface and publish
ART-04A1 through 04C2, with 04B split into 04B1-04B3, implement one hidden
continuous surface and publish
its exact route/resource/guard manifest. After 04C, a separate reviewed AUTH
activation contract may integrate the evaluator and change only
`artifact.submission_bundle.prepare` to active. ART-05 cannot start until that
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -22,12 +22,16 @@ they cross multiple L1 boundaries.

| Chunk | Goal | Risk | Entry gate/status |
|---|---|---:|---|
| `WS-ART-001-PLAN3` | Reconcile the complete remaining v0.1 custody chain and AUTH/REV/CON handoffs. | L1 | Planning only; proposed |
| `WS-ART-001-PLAN3` | Reconcile the complete remaining v0.1 custody chain and AUTH/REV/CON handoffs. | L1 | Merged planning |
| `WS-ART-001-PLAN4` | Define the central default pre-submission checker catalogue, disable semantics, and split execution contract. | L1 | Planning complete; internal review passed; PR pending |
| `WS-ART-001-03C` | Clean-cut legacy guide identity/excerpts and make the verified same-generation pipeline live. | L1 | Merged PR #249 |
| `WS-ART-001-04A1` | Remove legacy multi-step contributor intake reachability and schema without adding the replacement route. | L1 | Merged PR #264 |
| `WS-ART-001-04A2` | Add bounded one-outer-ZIP intake and archive-safety inspection in private scratch. | L1 | Implemented; internal review passed; external PR gates pending |
| `WS-ART-001-04A3` | Add canonical semantic manifest, executable normalization, and unchanged-work gate. | L1 | Proposed after 04A2 |
| `WS-ART-001-04B` | Run non-bypassable platform and locked-guide prechecks against that exact scratch tree and persist bounded evidence. | L1 | Proposed after 04A3 |
| `WS-ART-001-04A2` | Add bounded one-outer-ZIP intake and archive-safety inspection in private scratch. | L1 | Merged PR #266 |
| `WS-ART-001-04A3` | Add canonical semantic manifest, executable normalization, and unchanged-work gate. | L1 | Merged PR #268 |
| `WS-ART-001-04A4` | Remove the legacy independently invocable caller-owned submission-precheck route and contract. | L1 | Proposed after PLAN4 |
| `WS-ART-001-04B1` | Add the single versioned checker catalogue and compile one effective execution plan from platform defaults plus locked project policy. | L1 | Proposed after 04A4 |
| `WS-ART-001-04B2` | Materialize the sealed manifest tree once and execute the mandatory platform/default catalogue phases. | L1 | Proposed after 04B1 |
| `WS-ART-001-04B3` | Execute locked project-policy rules through the same plan and persist one bounded immutable evidence set. | L1 | Proposed after 04B2 |
| `WS-ART-001-04C1` | Reauthorize and atomically persist capacity plus durable put intent, then write the checked ZIP once. | L1 | Proposed after XINT-06A |
| `WS-ART-001-04C2` | Reuse verification/recovery to publish one capacity-charged ready admission and compose the hidden continuous endpoint. | L1 | Proposed after 04C1 |
| `WS-ART-001-05A` | Atomically consume ready admission into one immutable Submission and binding under fresh human/service authority. | L1 | Proposed after XINT-05A |
Expand All @@ -45,7 +49,7 @@ they cross multiple L1 boundaries.
```text
AUTH-04B implementation [merged PR #245]
-> ART-03C
-> ART-04A1 -> 04A2 -> 04A3 -> 04B
-> ART-04A1 -> 04A2 -> 04A3 -> PLAN4 -> 04A4 -> 04B1 -> 04B2 -> 04B3
-> XINT-06A pre-submit materializer activation
-> ART-04C1 -> 04C2
-> XINT-05A contributor preparation activation
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -506,7 +506,7 @@ new snapshot. None creates a sufficiency decision.

The continuous submission-bundle request cannot become live while its fixed
pre-submit materializer is unavailable. AUTH therefore splits checker
activation: pre-submit materialization activates after hidden ART-04B evidence
activation: pre-submit materialization activates after hidden ART-04B1-04B3 evidence
and before XINT-05A activates contributor preparation. Post-submit
materialization and checker output/binding activate later after ART-06A/06B.

Expand Down Expand Up @@ -538,3 +538,49 @@ v0.1 Workstream lifecycle and requires a future reviewed initiative.
Local/MinIO product lifecycle proof, AWS deployment activation proof, and final
cross-domain conformance are separate PRs. AWS readiness cannot bury product
behavior, and product API proof cannot claim AWS production eligibility.

## D52 - One Versioned Pre-Submission Checker Catalogue

All Workstream platform defaults and constrained project-policy primitives are
registered in one code-owned, versioned catalogue. Each entry has a stable ID,
version, owner, phase/order, dependencies, classification, input capability,
default operational state, disabled behavior, limits, bounded result contract,
and policy trace. The effective execution plan combines non-bypassable artifact
custody, Workstream defaults, and the task-locked Project Guide policy. It runs
through one internal API and returns one ordered result envelope. A second
registry, project-specific execution API, or scattered string dispatch is
forbidden.

## D53 - Disabling A Mandatory Default Fails Closed

Every catalogue entry exposes `enabled|disabled`, but availability is not a
policy bypass. Only startup-validated, versioned deployment configuration may
disable an entry in v0.1. Contributors, Project Managers, project policy, and
task parameters cannot toggle it. Disabling a mandatory security, integrity,
or accountability entry makes submission-bundle preparation unavailable and
causes no durable or provider effect. Disabling an advisory entry permits the
remaining plan to run and records the disabled entry in bounded evidence. A
locked project-required rule cannot be disabled at runtime; changing it
requires a new approved policy lineage.

## D54 - Generic Defaults Avoid Project Semantics

Workstream defaults cover universal custody and submission-contract facts:
outer-ZIP structure, archive/path/resource safety, exact archive identity,
semantic manifest identity, executable normalization, unchanged-work rejection,
sealed scratch integrity, high-confidence sensitive-file exclusions, required
packet fields, and contributor accountability. Task-specific filenames,
directory layouts, languages, tests, evidence meaning, and quality criteria
come only from the locked Project Guide policy. Ambiguous name heuristics such
as broad `token*`, `secret*`, `credential*`, or dependency-directory matches
must not silently remain universal blocking rules; the implementing chunk must
classify them as narrowly high-confidence blocking checks, advisory checks, or
project-specific policy and prove the migration.

## D55 - Legacy Standalone Precheck Is Removed Before Catalogue Execution

The existing caller-owned `/submission-precheck` request cannot prove the exact
uploaded ZIP or sealed server manifest and would create a second execution API.
04A4 removes its route, schemas, service entry point, and OpenAPI surface before
04B1 installs the authoritative catalogue. Pre-production accepts this clean-cut
gap; there is no compatibility alias, redirect, or caller-manifest adapter.
Original file line number Diff line number Diff line change
Expand Up @@ -243,3 +243,38 @@ Plan-review resolution:
ledger tables completely; it does not retain detached compatibility fields.
- Downgrade recreates only the exact empty legacy schema proven by the upgrade
precondition. It never fabricates a session/item lineage from newer facts.

## 2026-08-04 Default Pre-Submission Checker Catalogue Discovery

Merged ART-04A2/04A3 already own outer-ZIP safety, resource bounds, archive
identity, canonical semantic manifests, executable normalization, and the
unchanged-work gate. These trusted capabilities must be registered into
pre-submission execution, not reimplemented as another checker stack.

Projects already merge `WorkstreamDefaultSubmissionArtifactPolicy` with the
approved `SubmissionArtifactPolicy`, and the trusted compiler emits a locked
`PreSubmitCheckerPolicy`. The remaining defects are execution shape and
catalogue ownership:

- checker names/defaults are spread across policy constants, compiler
primitives, legacy registry code, templates, and historical docs;
- the legacy `/tasks/{task_id}/submission-precheck` accepts caller-owned packet
and manifest facts and cannot be the authoritative one-ZIP execution path;
- combined 04B crosses catalogue, sealed materialization, platform execution,
project execution, persistence, and API-result boundaries;
- broad forbidden-name patterns can false-positive legitimate generic projects;
- `disabled` has no safe canonical meaning for non-bypassable defaults.

PLAN4 splits 04B into catalogue/effective-plan composition, sealed default
execution, and locked-project execution/evidence. v0.1 catalogue state is
startup-validated deployment configuration. Disabling mandatory custody,
integrity, or accountability fails preparation closed; only advisory entries
may be disabled while remaining execution continues. Project policy and
task/runtime input cannot toggle catalogue availability.

The catalogue snapshot is immutable. Its version, canonical manifest digest,
ordered entry ID/version/configuration hashes, and enabled/disabled state are
embedded in the compiled `PreSubmitCheckerPolicy`. The existing task-locked
compiled-bundle hash therefore commits to the exact default snapshot without a
second task-lock field; runtime derives and records the effective-plan hash from
that same snapshot plus the locked project rules.
Original file line number Diff line number Diff line change
Expand Up @@ -307,10 +307,36 @@ separate cumulative safety proof.

Both identities are compared with the immediate prior immutable `Submission`.
Exact archive equality or semantic equality rejects before checker and provider
I/O. Mandatory Workstream gates and the task's locked Project Guide checker then
consume the same read-only scratch tree. A project may narrow platform limits
but cannot disable gates or raise limits. Checker failure creates findings only
and destroys scratch without durable artifact, Submission, or review state.
I/O. One ordered pre-submission execution then consumes the same read-only
scratch tree. It is assembled from a central, versioned Workstream checker
catalogue:

```text
non-bypassable artifact-custody gates
+ Workstream default submission-policy checks
+ task-locked Project Guide checks
= one effective pre-submission execution plan and one result envelope
```

The catalogue is the sole registry for stable checker identifiers, versions,
phase/order, dependencies, owner, input capability, severity class, default
availability, disabled behavior, resource limits, stable outcomes, and policy
trace. Runtime services may dispatch through typed adapters, but may not grow a
second checker registry or scattered name-based conditionals.

Every catalogue entry has explicit `enabled|disabled` operational state. A
disabled mandatory security, integrity, or contributor-accountability entry
makes preparation fail closed as platform infrastructure unavailable; it is
never recorded as skipped-and-passing. A disabled advisory entry is omitted
from execution only through startup-validated, versioned deployment
configuration and is recorded in the bounded result manifest. Contributors,
Project Managers, task parameters, and project policy cannot toggle catalogue
availability or weaken a mandatory default. Project policy may narrow platform
limits but cannot raise them. Only a completed checker result may create bounded
structured contributor findings. Infrastructure failure, disabled mandatory
checks, resource exhaustion, cancellation, and authorization failure produce a
stable retryable infrastructure outcome with no contributor finding, durable
artifact, Submission, or review state; scratch is destroyed.

A passing result stays bound to the same process-local scratch generation and is
consumed immediately by the normal durable admission path. It is never a
Expand Down Expand Up @@ -565,8 +591,10 @@ them; no runtime plugin discovery or parser fallback is permitted.
identity/continuation clean cut.
2. Contributor intake accepts one outer ZIP, inspects and manifests its complete
tree in bounded private scratch, and rejects exact or semantic unchanged work.
3. Mandatory platform gates and locked Project Guide pre-submit checks execute
against that same scratch tree. Failure produces no durable bytes.
3. The central Workstream checker catalogue composes mandatory platform gates,
Workstream default submission-policy checks, and locked Project Guide checks
into one ordered effective execution against that same scratch tree. Failure
produces no durable bytes.
4. Passing bytes enter the existing immutable store once. Complete read-back
verification publishes one bindable admission; ambiguity uses existing ART
recovery.
Expand Down Expand Up @@ -686,7 +714,10 @@ AUTH-04B implementation/activation [merged PR #245]
-> ART-04A1 legacy contributor-intake removal
-> ART-04A2 bounded outer-ZIP safety/intake
-> ART-04A3 semantic manifest + unchanged-work gate
-> ART-04B scratch-bound platform/project prechecks
-> ART-04A4 legacy standalone precheck clean cut
-> ART-04B1 default-checker catalogue and effective-plan contract
-> ART-04B2 sealed scratch materialization and platform-default execution
-> ART-04B3 locked-project execution and immutable bounded evidence
-> XINT-06A pre-submit materializer activation
-> ART-04C1 durable intent + one provider write
-> ART-04C2 verified ready-admission publication
Expand All @@ -705,7 +736,8 @@ AUTH-04B implementation/activation [merged PR #245]
-> XINT-08 + ART-08C final v0.1 conformance
```

04A1-04C2 remain hidden internal pieces of one continuous contributor request.
04A1-04C2, including split 04B1-04B3, remain hidden internal pieces of one
continuous contributor request.
No intermediate HTTP route, durable upload session, scratch handle, local path,
or prepared authorization crosses those PR boundaries. 04C2 alone composes the
hidden endpoint after every internal dependency exists.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -299,3 +299,38 @@
semantic-lane inventory, stale scans, links, and diff checks pass.
- Architecture, security, QA, product/ops, senior engineering, CI integrity,
docs, reuse/dedup, and test-delta final reviews pass.

## WS-ART-001-PLAN4

- Replaced combined 04B with a bounded sequence: 04A4 removes the legacy
caller-owned standalone precheck, 04B1 installs the sole versioned catalogue,
04B2 executes mandatory platform/default checks on one sealed tree, and 04B3
executes locked project rules and persists one bounded evidence set.
- Initial review found conflicting standalone-precheck docs, duplicated registry
risk, stale caller package/hash/manifest authority, missing route-removal
ownership, weakened coverage commands, and lost executable/crossed-state test
obligations. All were repaired in the plan and canonical docs.
- The v0.1 catalogue gives every entry a stable ID/version, classification,
phase/order/dependencies, typed inputs, bounded result, policy trace, and
explicit operational state. Mandatory disabled entries fail preparation
closed; only advisory entries may be disabled while execution continues.
- Broad sensitive-name heuristics are no longer silently universal blockers.
High-confidence exclusions remain blocking; ambiguous patterns must be
advisory or locked project-specific.
- Canonical flows now distinguish contributor ZIP/summary/attestation input from
server-derived archive identity, semantic manifest, pre-submit evidence,
verified admission, ArtifactBinding, and post-submit materialization.
- Architecture, security, QA, product/ops, senior engineering, CI integrity,
reuse/dedup, and test-delta reviews pass after repair. Docs review identified
and repaired final route-prefix and AUTH owner-table drift; final confirmation
is recorded before publication.
- CodeRabbit then found seven valid specification gaps: namespace mapping,
typed result provenance, infrastructure/finding separation, audit redaction,
immutable catalogue snapshot locking, stale historical response wording, and
residual client-shaped evidence fields. All are repaired after rebasing onto
current main; the external response and complete PR trust bundle record the
disposition.
- Focused architecture, security, QA, and docs re-review pass the external
repair. Architecture additionally required authority-neutral shared result
identity and complete platform/default dispatch mapping; both were repaired
before final publication.
Loading
Loading