Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -36,14 +36,13 @@ contract, provisionally named
active assignment, locked policy context, and operation generation;
- keeps the action unavailable and adds no grant or evaluator activation;
- records parity evidence in AUTH's closed catalogue/constraint/owner manifests;
- explicitly retires the unused planned multi-step upload-session ActionIds or
proves they are unavailable and have no route/command manifest entry.

Until that AUTH contract merges, current agent-gate catalogue assertions retain
those strings only as an exact planned/unavailable discovery baseline. Their
presence in the closed catalogue is not an active design, grant, route, or
permission to implement a second intake path, and PLAN2 does not edit AUTH-owned
catalogue or parity assertions.
- deletes the unused planned multi-step upload authority from the live closed
catalogue, constraints, and service matrix without compatibility aliases.

After that AUTH contract merges, the retired identifiers may remain only in
immutable historical records and the deterministic deletion proof. They are
not an active design, grant, route, compatibility alias, or permission to
implement a second intake path.

ART-04A through 04C then implement one hidden continuous surface and publish
its exact route/resource/guard manifest. After 04C, a separate reviewed AUTH
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,10 +2,11 @@

The final v0.1 ART catalogue reconciliation, PREP extension, and activation
waves are superseded prospectively by
`../WS-XINT-002-art-auth-end-to-end/`. Existing rows below remain the trusted
baseline until WS-XINT-002-01 merges; no prose in either plan changes runtime
availability.
The reconciliation baseline is trusted `main` commit
`../WS-XINT-002-art-auth-end-to-end/`. The counts immediately below are the
trusted pre-reconciliation entry evidence; WS-XINT-002-01 replaces them with
the live 71/78/22/56 catalogue recorded in the ART custody section without
changing runtime availability.
The pre-reconciliation baseline is trusted `main` commit
`2fb322bd2249a5fe9d3fa706dc63f033074e38ce`: 76 PermissionIds, 81 ActionIds,
22 active actions, and 59 planned actions. Older counts below are explicitly
historical snapshots at their named commits, not the WS-XINT-002 entry state.
Expand Down Expand Up @@ -41,22 +42,25 @@ mappings, and availability must remain identical.
| `WS-AUTH-001-ART-02D-INTERNAL` | `artifact.verification.execute`, `artifact.pending_work.scan`, `artifact.put_attempt.resolve` |
| `WS-AUTH-001-ART-02D-OPERATOR` | `artifact.binding.read`, `artifact.replica.read`, `artifact.receipt.read`, `artifact.verification_job.read`, `artifact.verification_job.retry`, `artifact.recovery_attempt.read`, `artifact.audit.read`, `operations.artifact_storage_admission.read` |
| `WS-AUTH-001-ART-03` | `artifact.guide_source.ingest`, `artifact.guide_source.read`, `artifact.guide_source.binding.create` |
| `WS-AUTH-001-ART-04A` | `artifact.upload_session.create`, `artifact.upload_session.read`, `artifact.upload_item.write`, `artifact.upload_session.seal`, `artifact.upload_session.cancel`, `artifact.upload_session.expire` |
| `WS-XINT-002-05A` | `artifact.submission_bundle.prepare` |
| `WS-AUTH-001-ART-04B` | `artifact.pre_submit.checker_input.materialize` |
| `WS-AUTH-001-ART-05` | `artifact.submission.binding.create` |
| `WS-AUTH-001-ART-06A` | `artifact.post_submit.checker_input.materialize` |
| `WS-AUTH-001-ART-06B` | `artifact.checker_output.write`, `artifact.checker_output.binding.create` |

`WS-AUTH-001-ART-CUSTODY` atomically transfers these 25 rows with exact owner
cardinalities `3/8/3/6/1/1/1/2` in the table order above and removes the seven
historical ART owner enum values. The `OPERATOR` suffix denotes only future
activation custody; it grants no Operator entitlement. All 25 actions remain
planned, including independently gated `artifact.verification_job.retry`, which
cannot be activated by read/status proof. The transfer adds no migration because
owner and availability are typed metadata, while PostgreSQL preserves the exact
ActionId-to-PermissionId set. The catalogue remains at 74 PermissionIds,
65 ActionIds, 17 active actions, and 48 planned actions; the seven-identity,
eleven-membership service matrix is unchanged.
| `WS-XINT-002-07` | `artifact.review_packet.materialize`, `artifact.review_evidence.binding.create` |

`WS-AUTH-001-ART-CUSTODY` historically transferred 25 rows. WS-XINT-002-01
reconciles the live catalogue by removing the six unused multi-step upload rows
and registering three end-to-end bundle/review rows. The resulting 22 rows have
exact owner cardinalities `3/8/3/1/1/1/1/2/2` in the table order above. The
`OPERATOR` suffix denotes only future activation custody; it grants no Operator
entitlement. All 22 actions remain planned, including independently gated
`artifact.verification_job.retry`, which
cannot be activated by read/status proof. The historical transfer added no
migration because owner and availability are typed metadata. WS-XINT-002-01
reconciles PostgreSQL parity through migration `0036`; the live catalogue has
71 PermissionIds, 78 ActionIds, 22 active actions, and 56 planned actions, with
seven fixed-service identities and twelve matrix memberships.

## REV custody transfer

Expand Down Expand Up @@ -86,7 +90,6 @@ actions on trusted `main`:
| Registration chunk | Future activation chunk | Proposed ActionId -> PermissionId |
|---|---|---|
| `WS-AUTH-001-REV-REG` | `WS-AUTH-001-REV-LIFECYCLE` | `review.revision_context.repair` -> `project.task.manage`; `review.revision_context.legacy_close` -> `operations.reconcile.run`; `review.revision_obligation.close` -> `project.task.manage`; `review.lifecycle.activation.manage` -> `operations.reconcile.run` |
| `WS-AUTH-001-ART-REV-EVIDENCE-REG` | `WS-AUTH-001-ART-REV-EVIDENCE` | `artifact.review_evidence.binding.create` -> `artifact.binding.create` |

These are declared future registration gates, not executable chunk contracts.
Neither may receive a full contract or start until the owning feature publishes exact
Expand All @@ -102,12 +105,10 @@ Its proof includes populated refusal, empty safe downgrade, re-upgrade, and
fresh replay.

Counts are derived from trusted `main` when a gate executes. REV registration
adds exactly four planned actions and zero active actions; evidence registration
adds exactly one planned action and zero active actions, in either order.
PermissionIds remain 74. The evidence-binding
registration also adds that exact action to the existing
`workstream.artifact.binding` static row, increasing matrix membership from 11
to 12 without adding an identity or database grant.
adds exactly four planned actions and zero active actions. WS-XINT-002-01
registers review-evidence binding under `WS-XINT-002-07` and adds it to the
existing `workstream.artifact.binding` static row without adding an identity or
database grant.

## Prepared mutation prerequisite

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -42,7 +42,7 @@ stopped.
| `WS-AUTH-001-09D-B` | Identity-Link Lifecycle And Race Closure | L1 | Merged through PR #152 as `93dd392`; signed memory `912a6254` passed |
| `WS-AUTH-001-CONTRIBUTOR-FOUNDATION` | Contributor Fields And Canonical-Human Lineage | L1 | Merged through PR #153 as `8d5eb15b`; signed memory `66ab58d` passed and stopped |
| `WS-AUTH-001-09E` | Fixed Service Runtime Admission | L1 | Merged through PR #157 as `42a89b2d` on 2026-07-20 |
| `WS-AUTH-001-ART-CUSTODY` | ART Activation Custody Transfer | L1 | Merged through PR #158 as `be2a79a2`; all 25 ART actions remain planned |
| `WS-AUTH-001-ART-CUSTODY` | ART Activation Custody Transfer | L1 | Merged through PR #158 as `be2a79a2`; historical 25-row transfer later reconciled by WS-XINT-002-01 to 22 planned ART actions |
| `WS-AUTH-001-REV-CUSTODY` | REV Activation Custody Transfer | L1 | Merged through PR #160 as `fe0e4492`; all 19 REV actions remain planned |
| `WS-AUTH-001-PREP` | Prepared Mutation Authorization Protocol | L1 | Merged through PR #162 as `c559d556`; no feature consumer or activation |
| `WS-AUTH-001-10` | Project Qualification And Contributor Role Grants | L1 | Active planning-only parent; split approved after failed L1 combined review |
Expand Down Expand Up @@ -71,11 +71,10 @@ feature manifest exists, then requires a separate explicit start.
| Chunk | Title | Risk | Status |
|---|---|---:|---|
| `WS-AUTH-001-REV-REG` | REV Lifecycle Action Registration | L1 | Blocked on complete REV typed manifests |
| `WS-AUTH-001-ART-REV-EVIDENCE-REG` | Review Evidence Binding Action Registration | L1 | Blocked on complete ART/REV dual-authority contract |
| `WS-AUTH-001-ART-02D-INTERNAL` | ART 02D Internal Action Activation | L1 | Feature-gated |
| `WS-AUTH-001-ART-02D-OPERATOR` | ART 02D Operator Read/Status And Independently Evaluated Retry Activation | L1 | Feature-gated |
| `WS-AUTH-001-ART-03` | ART 03 Guide Source Action Activation | L1 | Feature-gated |
| `WS-AUTH-001-ART-04A` | ART 04A Upload Action Activation | L1 | Feature-gated |
| `WS-XINT-002-05A` | Submission Bundle Preparation Activation | L1 | Feature-gated on complete ART-04A-C hidden behavior |
| `WS-AUTH-001-ART-04B` | ART 04B Pre-Submit Materialization Activation | L1 | Feature-gated |
| `WS-AUTH-001-ART-05` | ART 05 Submission Binding Activation | L1 | Feature-gated |
| `WS-AUTH-001-ART-06A` | ART 06A Post-Submit Materialization Activation | L1 | Feature-gated |
Expand All @@ -88,7 +87,7 @@ feature manifest exists, then requires a separate explicit start.
| `WS-AUTH-001-REV-11` | REV 11 Recovery And Reconciliation Activation | L1 | Feature/service-gated |
| `WS-AUTH-001-REV-12` | REV 12 Artifact Reconciliation And Projection Activation | L1 | Feature/service-gated |
| `WS-AUTH-001-REV-LIFECYCLE` | REV Lifecycle Repair Action Activation | L1 | Blocked until REV-REG and four hidden manifests merge |
| `WS-AUTH-001-ART-REV-EVIDENCE` | Review Evidence Binding Action Activation | L1 | Blocked until registration and hidden ART/REV behavior merge |
| `WS-XINT-002-07` | Review Packet And Evidence Binding Activation | L1 | Feature-gated on exact REV lease/version and ART evidence behavior |

## Dependency order

Expand Down Expand Up @@ -237,6 +236,7 @@ review rejected the underspecified contract before runtime edits; PR #153 later
merged its repaired implementation as `8d5eb15`. PR #157 merged AUTH-09E as
`42a89b2d`, and PR #158 merged the availability-neutral ART custody transfer as
`be2a79a2`, PR #160 merged the availability-neutral REV custody transfer as
`fe0e4492`, and PR #162 merged AUTH-PREP as `c559d556`; all 25 ART and 19 REV
actions remain planned and inactive, and PREP adds no feature consumer.
`fe0e4492`, and PR #162 merged AUTH-PREP as `c559d556`; WS-XINT-002-01 later
reconciles the historical 25 ART rows to 22 planned ART actions, while all 19
REV actions remain planned and inactive, and PREP adds no feature consumer.
POL-002-04 remains inactive pending its own gate and explicit start.
Original file line number Diff line number Diff line change
@@ -1,13 +1,18 @@
# AUTH <-> ART Handoff

> Historical immutable handoff provenance. WS-XINT-002-01 supersedes this
> catalogue baseline; the entire document below is audit history, not live
> activation guidance or compatibility authority. Every table, matrix, and
> delivery step must be read only as the superseded pre-reconciliation state.

## Boundary

AUTH is the sole activation custodian. ART is the sole artifact resource and
behavior owner. AUTH never performs artifact storage/lifecycle mutations; ART
never registers grants, evaluates authority locally, or changes action
availability.

## Complete current custody transfer
## Historical superseded custody transfer

All mappings remain unchanged. `docs/spec_authorization_service.md` remains the
canonical ActionId-to-PermissionId and principal/resource blueprint. The table
Expand Down Expand Up @@ -48,7 +53,7 @@ After transfer, AUTH removes unused `ART_02D`, `ART_03`, `ART_04A`, `ART_04B`,
and definition-owner parity must reject partial transfer, dual writers, missing
owners, extra owners, and changed mappings.

## Fixed service-action matrix
## Historical fixed service-action matrix

`docs/spec_authorization_service.md` remains the canonical fixed service-action
matrix source. This table is a non-authoritative repeat used only to bind the
Expand All @@ -70,7 +75,7 @@ actions are planned. After AUTH-09E, ART accepts only a canonical AUTH service
context at its composition root and never derives identity from a Celery task,
executor ID, queue, environment string, or provider credential.

## Delivery order
## Historical delivery order

```text
AUTH-09A fixed service identity and static matrix foundation
Expand All @@ -93,7 +98,7 @@ is never implied by verifier, scheduler, or put-resolver activation. AWS provide
release is also separate: an authorized action cannot instantiate AWS until ART
live-provider proof is current.

## Mutation protocol
## Historical mutation protocol

For a human caller, AUTH locks the actor, identity-link, and matched grant rows.
For a fixed service, AUTH locks the service ActorProfile and ActorIdentityLink,
Expand All @@ -105,14 +110,14 @@ once. Terminal Celery writes additionally require the matching ART executor and
execution generation. Authorization identity and execution fencing remain
independent checks.

## AUTH owner response
## Historical AUTH owner response

AUTH must add reviewed registration/transfer and activation chunk contracts,
add the AUTH-09E service-admission contract, repair stale AUTH documents and
catalogue descriptions, preserve every mapping, and prove no action becomes
active without its merged ART behavior manifest.

## ART owner response
## Historical ART owner response

ART must repair its plan/chunk sequencing, implement only hidden behavior before
activation, publish exact resource/guard/surface manifests, and never edit AUTH
Expand Down
Original file line number Diff line number Diff line change
@@ -1,12 +1,10 @@
# Decisions: WS-XINT-002 ART-AUTH End-to-End Contract

1. The dependency is owned end to end by a cross-initiative plan, not by ART-03A.
2. One outer ZIP replaces the six upload-session actions with
2. One outer ZIP replaces the six historical multi-step upload actions with
`artifact.submission_bundle.prepare`; no compatibility aliases or retained
unavailable rows remain. The exact deleted ActionId and PermissionId values
are `artifact.upload_session.create`, `artifact.upload_session.read`,
`artifact.upload_item.write`, `artifact.upload_session.seal`,
`artifact.upload_session.cancel`, and `artifact.upload_session.expire`.
unavailable rows remain. The immutable chunk contract and migration record
the exact deleted ActionId and PermissionId values.
3. Initial, checker-remediation, and human-review revision submissions share the
public preparation/create actions; each has an exact closed typed context.
4. Reviewer packet materialization is a fixed-service action plus a separate
Expand Down
Original file line number Diff line number Diff line change
@@ -1,7 +1,9 @@
# Status: WS-XINT-002 ART-AUTH End-to-End Contract

Planning proposed from trusted `main` after AUTH-11A merged. No implementation
or action activation has started. The dirty ART-03A worktree is preserved and
untouched.
`WS-XINT-002-01` is implemented and merge-pending. It reconciles the closed ART
catalogue and fixed-service matrix without activating any action, evaluator,
route, command, grant, or lifecycle behavior. The dirty ART-03A worktree remains
preserved and untouched.

Immediate successor after human approval: `WS-XINT-002-01`.
Next same-initiative gate after merge and a new explicit start:
`WS-XINT-002-02`.
Loading
Loading