docs(xint): plan REV-AUTH end-to-end contract - #236
Conversation
|
Warning Review limit reached
Next review available in: 49 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (2)
📝 WalkthroughWalkthroughThis PR adds the WS-XINT-003 REV-AUTH planning contract. It documents ownership, authorization protocols, staged activation chunks, verification requirements, risks, review outcomes, and release gates. It adds no runtime code and does not activate actions. ChangesREV-AUTH planning contract
Estimated code review effort: 2 (Simple) | ~15 minutes Possibly related PRs
Suggested reviewers: 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 4
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In
@.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-06-review-decision-activation.md:
- Around line 16-17: Update the contract text covering CON participant wiring
and atomic commit to explicitly state that CON only flushes REV/AUTH-prepared
typed facts; it must perform no authority evaluation, decision, or lifecycle
work. Clarify that REV retains ownership of decision and lifecycle behavior,
including the corresponding section also covered by this review.
In
@.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-08A-review-recovery-activation.md:
- Around line 5-8: Replace the incomplete requirement sentence in
.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-08A-review-recovery-activation.md
lines 5-8 with “REV recovery behavior must remain hidden,” and replace it in
.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-08B-review-service-activation.md
lines 5-8 with “REV jobs/projection/control must remain hidden.”
In @.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/DECISIONS.md:
- Around line 26-27: Replace the stale human-worker terminology with the
accepted fixed-service term in both documentation sites: update “fixed worker”
in .agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/DECISIONS.md lines
26-27 and “catch-all worker” in
.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/RISKS.md line 15,
preserving the surrounding contract and risk statements.
In
@.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/reviews/WS-XINT-003-PLAN-pr-trust-bundle.md:
- Around line 86-88: Update the “External review” section to record GitHub
Actions as blocked due to the failed exact-head check from
scripts/check_stale_authorization_docs.py, which found HUMAN_WORKER_VOCABULARY.
Update the stale authorization documentation, rerun the exact-head checks, and
document the resulting status before human merge; keep CodeRabbit’s pending
status separate.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro Plus
Run ID: 216bae25-6923-46ec-b941-0384e0aaacdb
📒 Files selected for processing (21)
.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/CHUNK_MAP.md.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/DECISIONS.md.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/DISCOVERY.md.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/INTENT.md.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/PLAN.md.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/REVIEW_LOG.md.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/RISKS.md.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/STATUS.md.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-01-contract-reconciliation.md.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-02-policy-mutation-activation.md.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-03A-reviewer-lease-activation.md.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-03B-lease-service-activation.md.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-04-review-context-activation.md.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-05-review-evidence-activation.md.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-06-review-decision-activation.md.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-07-human-revision-activation.md.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-08A-review-recovery-activation.md.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-08B-review-service-activation.md.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-08R-lifecycle-action-registration.md.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-09-conformance-release.md.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/reviews/WS-XINT-003-PLAN-pr-trust-bundle.md
|
Final exact-head status for
The initial stale-authorization-doc failure is preserved in the trust bundle/external response, together with its corrective commit and replacement passing gate. No runtime behavior or action availability is changed. Human approval/merge remains required. |
85c94f0 to
f94bc17
Compare
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In
@.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-09-conformance-release.md:
- Around line 36-39: Update the release matrix in
WS-XINT-003-09-conformance-release.md to cover every universal fail-closed
mutation case listed in PLAN.md, including forged,
wrong-session/transaction/action/actor/service,
cross-task/submission/lease/review, stale-policy, expired or revoked authority,
and already-consumed handles. Add explicit conformance cases or otherwise
eliminate each listed gap while preserving the required no-partial-state
outcome.
In
@.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/reviews/WS-XINT-003-PLAN-external-review-response.md:
- Around line 5-9: Update the Agent Gates review record around the documented
failed and replacement runs to include the exact reviewed PR head, such as
85c94f0e where applicable, plus unique identifiers or references for both the
failed and replacement passes. Preserve the existing failure cause and
successful replacement outcome while making the evidence traceable to the exact
reviewed artifact.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro Plus
Run ID: f84e1b9d-858a-47b1-b8c4-5604b1161a6e
📒 Files selected for processing (22)
.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/CHUNK_MAP.md.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/DECISIONS.md.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/DISCOVERY.md.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/INTENT.md.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/PLAN.md.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/REVIEW_LOG.md.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/RISKS.md.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/STATUS.md.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-01-contract-reconciliation.md.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-02-policy-mutation-activation.md.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-03A-reviewer-lease-activation.md.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-03B-lease-service-activation.md.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-04-review-context-activation.md.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-05-review-evidence-activation.md.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-06-review-decision-activation.md.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-07-human-revision-activation.md.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-08A-review-recovery-activation.md.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-08B-review-service-activation.md.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-08R-lifecycle-action-registration.md.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-09-conformance-release.md.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/reviews/WS-XINT-003-PLAN-external-review-response.md.agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/reviews/WS-XINT-003-PLAN-pr-trust-bundle.md
🚧 Files skipped from review as they are similar to previous changes (17)
- .agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-08B-review-service-activation.md
- .agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/INTENT.md
- .agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-08R-lifecycle-action-registration.md
- .agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-08A-review-recovery-activation.md
- .agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/reviews/WS-XINT-003-PLAN-pr-trust-bundle.md
- .agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-04-review-context-activation.md
- .agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-07-human-revision-activation.md
- .agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-05-review-evidence-activation.md
- .agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-03B-lease-service-activation.md
- .agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/REVIEW_LOG.md
- .agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-06-review-decision-activation.md
- .agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-03A-reviewer-lease-activation.md
- .agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/STATUS.md
- .agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-01-contract-reconciliation.md
- .agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/chunks/WS-XINT-003-02-policy-mutation-activation.md
- .agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/RISKS.md
- .agent-loop/initiatives/WS-XINT-003-rev-auth-end-to-end/DECISIONS.md
PR Trust Bundle: WS-XINT-003 Planning
Chunk
WS-XINT-003-PLAN— REV-AUTH End-to-End Contract Planning.Goal
Define one fail-closed authorization chain for the complete human review and
revision lifecycle before implementing AUTH-12D2 or REV runtime behavior.
Human-approved intent
The human requested the same end-to-end AUTH dependency review for REV that was
previously completed for ART, while preserving the existing ART-AUTH custody.
What changed
Added intent, discovery, plan, decisions, risks, status, review evidence, chunk
map, and twelve planning/chunk contracts under
WS-XINT-003.Why it changed
REV authority was distributed across AUTH, REV, and XINT-002 contracts. The
review found a concrete REV-03P/AUTH-12D2 policy ownership collision, missing
privileged action registration, globally shared action availability, and an
unsafe response-evidence order.
Design chosen
REV owns lifecycle semantics; AUTH owns identity/evaluation/PREP/evidence; ART
and shared submission-artifact actions remain with XINT-002; CON remains a
flush-only atomic participant. Registration and activation remain separate.
Alternatives rejected
Per-REV-chunk AUTH invention, direct grant reads in REV, generic contexts,
generic artifact access, duplicate policy writers, and activation before hidden
feature readiness.
Scope control
Planning Markdown only. No backend code, migration, action availability, route,
worker, or product behavior changed. Chunks 02-09 are explicitly
non-implementable until refreshed with exact current-main files and commands.
Product behavior
Unchanged. Review routes/actions remain unavailable.
Acceptance criteria proof
decision, revision, recovery, and conformance boundaries specified.
review.reconcile.runidentities activate in one global ActionId wave.Tests/checks run
python3 scripts/check_markdown_links.pypython3 scripts/check_stale_workstream_wording.pygit diff --checkNo runtime tests are applicable to a planning-only Markdown change. Hosted CI
must still pass on the exact PR head.
Test delta
No tests changed or weakened. Later chunk contracts require PostgreSQL races,
PREP denial matrices, service all-pairs denial, atomic fault injection, focused
90-percent coverage, and hosted repository coverage.
CI integrity
No workflow, package, Ruff, pytest, coverage threshold, exclusion, or skip was
changed.
Reviewer results
Architecture and docs: PASS. Security, product/ops, QA, and senior engineering:
PASS WITH LOW RISKS; every low/informational wording risk was also corrected.
External review
Pending GitHub Actions and CodeRabbit on the planning PR.
Remaining risks
Future activation chunks must refresh exact owner manifests, files, migration
head, commands, and runtime owner evidence from then-current main.
Follow-up work
After human merge and explicit request, execute
WS-XINT-003-01. AUTH-12D2 andREV-03P runtime work must wait for that ownership/custody reconciliation.
Human review focus
Review policy ownership, the XINT-002 boundary, response-evidence sequencing,
08R registration, single-wave reconciliation activation, and chunk order.
Human merge ownership
Only the human may merge this PR.
Summary by CodeRabbit