Skip to content

Latest commit

 

History

History
330 lines (280 loc) · 19.9 KB

File metadata and controls

330 lines (280 loc) · 19.9 KB

Activation Custody: WS-AUTH-001

For current work, start with the AUTH overview and cross-owner dependency contract. This document explains activation custody; historical sequences below do not restart completed work or create another contribution-permission system. The canonical authorization specification and typed runtime catalogue define the registered facts and availability. Verify the current typed registry when implementing rather than treating historical catalogue totals as an activation gate. TASK claim/start and its work-context operations now use canonical authority; that does not activate remaining planned submission, review or recovery operations.

Historical entry evidence is preserved in the original custody record.

Authority

This plan applies the merged WS-XINT-001 handoffs to AUTH. It distinguishes:

  • feature/resource ownership: ART, REV, CON, project, task, submission, or checker code owns facts, guards, state, and hidden behavior;
  • activation custody: one exact AUTH chunk owns ActionOwner, evaluator integration, and the planned to active transition; and
  • transaction ownership: the request route or service command owns one commit after AUTH and all feature participants have staged their evidence and state.

Feature chunks never change availability. AUTH never invents feature facts or performs feature lifecycle mutations.

Historical catalogue baselines

Trusted entry main after PR #140 contains 74 PermissionIds and 57 ActionIds: nine active and 48 planned. AUTH-09A adds zero permissions and eight planned actor/link/service actions, producing 74 PermissionIds and 65 ActionIds: nine active and 56 planned. Of those planned rows, the same 25 ART actions and 19 REV actions still carry historical feature-chunk owner values. The two later custody-transfer chunks change only those owner values; their entry counts, mappings, and availability must remain identical.

ART custody transfer

AUTH activation chunk Exact ActionIds and current availability
WS-AUTH-001-ART-02D-INTERNAL Active: artifact.verification.execute, artifact.pending_work.scan, artifact.put_attempt.resolve
WS-AUTH-001-ART-02D-OPERATOR Planned: artifact.binding.read, artifact.replica.read, artifact.receipt.read, artifact.verification_job.read, artifact.verification_job.retry, artifact.recovery_attempt.read, artifact.audit.read, operations.artifact_storage_admission.read
WS-XINT-002-04B Active: artifact.guide_source.read
WS-XINT-002-04A Active: artifact.guide_source.ingest
WS-XINT-002-05A Active: artifact.submission_bundle.prepare; registry custody remains historical while replacement implementation chunk WS-ARCH-001-02G supplies the executable PREP boundary
WS-XINT-002-06A Active: artifact.pre_submit.checker_input.materialize
WS-AUTH-001-ART-05 Active on WS-ARCH-001-02H merge: artifact.submission.binding.create; only the fixed artifact-binding service may consume it
WS-XINT-002-06B Planned: artifact.post_submit.checker_input.materialize, artifact.checker_output.write, artifact.checker_output.binding.create
WS-XINT-002-07A Planned: artifact.review_packet.materialize only
Future REV-owned activation, not approved for v0.1 Planned/unavailable: artifact.review_evidence.binding.create

The table retains historical planning-custody labels, not a literal mapping of every typed runtime ActionOwner. XINT-06B groups runtime WS-AUTH-001-ART-06A post-submit materialization and WS-AUTH-001-ART-06B output write/binding. ARCH-04D2 replaces that grouping for exact input/execute/finalize authority; output write/bind remains unavailable for the current zero-output catalogue. ARCH-04B hidden input and ARCH-04B2 hidden output custody and ARCH-04C hidden durable execution/results are delivered; ARCH-04D1 canonical terminal material custody is delivered; ARCH-04D2 exact service authority and ARCH-04E1A source-only facts/types are delivered. ARCH-04E1A adds no AUTH action, route or handler; ARCH-04B2 owns fresh authority participants internally for each store, recovery and binding phase; public requests carry selectors and byte sources, never PREP handles. The CHECKERS zero-slot reservation reader is implemented. Output authority remains deny-only. Production materialization requires real fixed-service AUTH/PREP and an exact current execution lease. Execute/finalize use the fixed workstream.checker.post_submit identity and phase-specific receipts. Do not implement an additional XINT-06B lane.

ART-07A1 delivers metadata-only packet types without authority or a resolver. REV-03B normalized packet storage, REV-04A immutable Review source storage, REV-04B FinalAcceptance storage, CON-03C persistence, CON-07 participation and REV-04C hidden shared acceptance/TASK/CON composition are delivered. Hidden routing handlers ARCH-04E1B-B are next. Mandatory exact AUTH receipts, database complete-effect custody, shared audit/outbox and fulfillment-root custody, and both TASK-before- CHECKERS currentness races remain prerequisites of activation at ARCH-04E2-B.

Runtime owner WS-XINT-002-07 retains catalogue custody. The only approved v0.1 availability transition is 07A packet materialization. Evidence binding remains planned and unavailable pending a separate REV-owned intent.

WS-AUTH-001-ART-CUSTODY historically transferred 25 rows. WS-XINT-002-01 reconciles the live catalogue by removing the six unused multi-step upload rows and registering three end-to-end bundle/review rows. The resulting 22 rows have exact action cardinalities 3/8/2/1/1/1/1/3/1/1 in the table order above. The OPERATOR suffix denotes only future activation custody; it grants no Operator entitlement. Fourteen actions remain planned after the three ART foundation service actions, artifact.guide_source.ingest, the two fixed-service guide binding/read actions, artifact.submission_bundle.prepare, and fixed-service artifact.submission.binding.create activate. The independently gated artifact.verification_job.retry remains planned and cannot be activated by read/status proof. The historical transfer added no migration because owner and availability are typed metadata. WS-XINT-002-01 historically reconciled PostgreSQL parity through migration 0036, now folded into the v0.1 baseline. At that historical boundary, the closed registry contained fifteen service identities: fourteen action-bearing identities with twenty-three matrix memberships plus the target-only workstream.compensation.adapter. AUTH-OUTBOX-01 registered the dispatcher; AUTH-OUTBOX-02 activates only its shared delivery mechanics with exact phase audit custody. ARCH-03C1 separately registers the assignment reconciler and its exact feature authority. The current registry has seventeen identities, sixteen action-bearing identities and twenty-five memberships. ARCH-03C2 completes atomic producer publication and the sole assignment-invalidation handler registration with enforced prefork delivery. CP01A registered four initially unavailable adapter-binding actions and CP01B registered five initially unavailable ContributionPolicy actions; neither changes fixed-service identity or matrix membership. CP01C corrects only the unavailable adapter-binding resource facts before CP02. It does not change catalogue custody, action identifiers, fixed-service identity, availability, or matrix membership. CP03A establishes that target-only identity and owner eligibility without a service-action matrix row; all four binding actions were activated by CP03B. CP05 activates exactly the five policy actions for human Finance Authority through explicit AUTH composition, retaining CP01B registration custody. CP05A exposes the public human Finance policy routes; fixed-service policy authority remains unavailable.

REV custody transfer

The canonical current planning table is review_authorization_action_custody.md. It supersedes the historical placeholder grouping below for future planning, while leaving runtime ActionOwner, permission, mapping, and availability unchanged until each exact XINT-003 activation wave.

AUTH activation chunk Exact planned ActionIds
WS-AUTH-001-REV-05 review.queue.read, review.queue.inspect
WS-AUTH-001-REV-06 review.claim, review.release, review.decline_preference, review.preference_expiry.run, review.lease_expiry.run
WS-AUTH-001-REV-07 review.context.read, review.chain.read, review.finding_evidence.ingest
WS-AUTH-001-REV-08 review.decision
WS-AUTH-001-REV-09A review.finding_response_evidence.ingest
WS-AUTH-001-REV-11 review.lease.force_release, review.queue.routing.override, review.queue.routing.correct, review.queue.close, review.reconcile.run
WS-AUTH-001-REV-12 review.artifact_reference.reconcile, review.projection.rebuild
WS-XINT-003-08A review.revision_context.repair, review.revision_obligation.close, review.revision_context.legacy_close
WS-XINT-003-08B review.lifecycle.activation.manage

WS-AUTH-001-REV-CUSTODY atomically transfers these 19 rows with exact owner cardinalities 2/5/3/1/1/5/2 in the table order above. The seven historical REV runtime owner values remain registered for those actions until their exact activation waves replace them. It changes no mapping or availability and adds no migration. All 19 actions remain planned and unavailable; these AUTH custodian labels grant no reviewer, Operator, or service authority. The four approved lifecycle actions remain planned and unavailable. The shared PREP foundation is already complete; its existence grants no lifecycle authority.

The completed front-loaded readiness waves are:

XINT-003 wave AUTH-only result
WS-XINT-003-02C Complete unavailable REV catalogue, four additive actions, six exact fixed-service identities, static matrix, and database parity
WS-XINT-003-02D Complete typed fail-closed REV PREP/read integration contracts; no lifecycle behavior or availability change

The exact activation-wave replacement is:

XINT-003 wave Registered planned REV ActionIds
WS-XINT-003-03A review.queue.read
WS-XINT-003-03B review.claim
WS-XINT-003-03C review.release, review.decline_preference
WS-XINT-003-03D review.preference_expiry.run, review.lease_expiry.run
WS-XINT-003-04 review.context.read, review.chain.read
WS-XINT-003-06 review.decision
WS-XINT-003-07 No availability change; extend the already XINT-002-owned preparation/Submission evaluators with the closed human-review revision context
WS-XINT-003-08A review.queue.inspect, review.lease.force_release, review.queue.routing.override, review.queue.routing.correct, review.queue.close, review.revision_context.repair, review.revision_obligation.close, review.revision_context.legacy_close
WS-XINT-003-08B review.reconcile.run, review.artifact_reference.reconcile, review.projection.rebuild, review.lifecycle.activation.manage

Evidence-upload actions remain future-intent-required and unavailable; they are not activated by 04 or 07. XINT-002-owned ART actions and shared submission actions are excluded.

Completed front-loaded additive registration

The following values are registered planned runtime actions, not active authority:

Registration chunk Future activation chunk Proposed ActionId -> PermissionId
WS-XINT-003-02C WS-XINT-003-08A / WS-XINT-003-08B review.revision_context.repair -> project.task.manage; review.revision_context.legacy_close -> operations.reconcile.run; review.revision_obligation.close -> project.task.manage; review.lifecycle.activation.manage -> operations.reconcile.run

WS-XINT-003-02C delivered availability-neutral AUTH readiness: it registered these four actions and the exact fixed-service identities/matrix before REV lifecycle implementation. WS-XINT-003-02D then published the closed identifier/digest-based PREP/read contracts. Neither chunk loads or implements REV lifecycle state, and the real kernel continues to deny every unavailable action. REV later supplies canonical facts, guards, loaders, composers, transaction revalidation, and hidden behavior; matching XINT waves activate only after that integrated proof.

Registration requires typed plus PostgreSQL audit mapping parity. The migration number was allocated from trusted main when 02C started. The registration migration takes a writer-blocking downgrade lock and refuses without mutation when any decision, audit, idempotency, or linked evidence references an added ActionId. Its proof includes populated refusal, empty safe downgrade, re-upgrade, and fresh replay.

Counts are derived from trusted main when a gate executes. REV registration adds exactly four planned actions and zero active actions. WS-XINT-002-01 registers review-evidence binding under runtime owner WS-XINT-002-07; planned and unavailable. It may remain named in the closed workstream.artifact.binding static matrix, but 07A does not activate or extend it. Any activation requires a separate approved REV-owned intent.

Completed prepared mutation prerequisite

WS-AUTH-001-PREP delivered a session-bound, action-bound, opaque, single-use, nonserializable prepared authority handle:

AUTH locks canonical current authority
-> feature locks its records
-> feature recomposes final typed facts
-> AUTH evaluates exactly once and stages decision evidence
-> feature participants flush
-> route or service command commits once

Reads retain AuthorizationService.require(). Mutations must not evaluate against stale pre-lock facts or let dependency teardown commit shared state.

Activation gate

Every activation chunk requires an immutable merged feature SHA and exact manifest containing its action list, resource composer, facts, guards, primary surface declarations, transaction owner, revalidation proof, and real-kernel action_unavailable proof before activation. The AUTH chunk then integrates only those evaluators, changes only those actions to active, proves the exact availability delta, and preserves all unrelated rows.

An activation entry in this map is a non-executable placeholder until that manifest exists. Its later preimplementation contract must enumerate exact allowed feature files, route/command and transaction tests, generated manifest delta, allow/deny/revalidation/rollback matrix, PostgreSQL concurrency cases, focused behavior regressions for every changed boundary, and the full backend suite with complete execution evidence. Coverage percentages are diagnostic, not activation or merge criteria. Generic “as applicable” proof or AUTH-only tests cannot authorize activation.

WS-ARCH-001-CP03 is split/non-executable. CP03A is the prerequisite executable contract for the closed adapter target identity and real owner eligibility; it activates no action. CP03B is the activation executable contract. CP02 provides the immutable hidden feature manifest, transaction custody, recovery behavior, and deny-default composition. After CP03A merges, CP03B may activate only:

compensation.adapter_binding.read
compensation.adapter_binding.create
compensation.adapter_binding.suspend
compensation.adapter_binding.resume

All four are active on CP03B merge. They admit only an active human Finance Authority covering the exact project, use the existing request-scoped read and opaque PREP protocols, add no service identity or route, and do not activate ContributionPolicy, retirement, fulfillment, callback, delivery, dispatcher, or reconciliation authority.

WS-AUTH-001-ART-02D-INTERNAL requires the exact merged ART-02C2 verification, resolution, and scanner behavior plus ART-02C3 recovery/fencing foundations and any ART-02D resource-composer dependency. ART-02D does not own the internal behavior. Within WS-AUTH-001-ART-02D-OPERATOR, artifact.verification_job.retry requires its own evaluator, guards, behavior tests, and explicit availability assertion; passing the seven read/status cases does not authorize retry.

Service actions use the exact fixed-service identities and closed matrix installed unavailable by 02C plus controlled canonical admission. REV does not need to publish hidden job behavior before those fail-closed identity contracts exist. REV later publishes exact timer, expiry, reconciliation, projection, artifact-reference, and release-control manifests before the matching action can become active. No catch-all review service exists.

review.decision additionally requires the merged flush-only CON participant and one rollback-safe REV+CON transaction. Review-evidence binding additionally requires ART and REV to define the in-process/service boundary, two independent authorization decisions and evidence records, exact lock order, and one transaction owner. Human authority cannot be silently converted into service authority.

Historical sequencing — not the remaining work queue

WS-AUTH-001-XINT planning reconciliation
-> repair and re-review PR #132 / AUTH-09A on trusted main
-> AUTH-09B -> 09C -> 09D -> 09E
-> WS-AUTH-001-ART-CUSTODY
-> WS-AUTH-001-REV-CUSTODY
-> WS-AUTH-001-PREP
-> AUTH-10 through AUTH-15 core cutovers
-> feature-gated registration and activation chunks as their manifests merge
-> AUTH-16 aggregate conformance and live proof

For ART dependencies, replace the generic final two steps with the exact WS-XINT-002 sequence: complete registration, prepared feature boundaries, fixed internal services, guide, submission, checker, review artifact access, and end-to-end conformance. AUTH-14 and AUTH-15 are not alternate activation paths.

Current sequencing and concurrency

Use the linked current cross-owner plan for remaining activation boundaries. Distinct initiatives may proceed concurrently in separate branches/worktrees. Serialize or rebase overlapping catalogue, matrix, composition and migration edits; do not impose a global single-active AUTH chunk rule. Hidden feature behavior stays unavailable until its exact activation is implemented and verified. Each PR uses the normal evidence, review and human merge workflow; planning records do not introduce an additional administrator checkpoint.

Disabled shared lifecycle foundation

REV-12A1 provides immutable disabled generation-zero storage and caller-root transaction locking. It does not activate review.lifecycle.activation.manage or an acceptance writer. AUTH's scalar activation contract binds its inherited phase to current_phase; generation zero requires disabled. Those facts do not prove adjacency or grant authority. Hidden AUTH preparation and nominal caller-session receipt projection are delivered before CON-07 flush-only participant proof. Mandatory persisted source/FinalAcceptance custody accompanies the first genuine allowed consequence at 04E2-B, before production composition or consumption; no standalone allow is committed. Authorized REV transitions and real obligation/cutoff proof remain required before live shared acceptance, without requiring live human-review queues first.

ARCH-04E1B-A adds immutable TASK routing-request and future source-ID reservation, with caller-owned rollback and current-completion replay checks. It does not construct acceptance-source commitments or consume receipt-shaped values as AUTH evidence. ARCH-04E2-A strict preparation and nominal fixed-router adapter are delivered through canonical PREP, but the planned action denies before a handle or receipt exists. Persisted source projection, actual immutable AUTH-event/service-actor verification and atomic publication remain required before consequence activation.