Skip to content

docs(agent-runtime): classify protected procedural history - #598

Merged
seonghobae merged 13 commits into
mainfrom
docs/procedural-history-protected-20260910
Sep 10, 2026
Merged

docs(agent-runtime): classify protected procedural history#598
seonghobae merged 13 commits into
mainfrom
docs/procedural-history-protected-20260910

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 10, 2026

Copy link
Copy Markdown
Contributor

Purpose

Repair the post-#597 documentation-authority drift on protected main@61f2b372d55c87e1763bc11d3e545967fc0a9cf5. Protected #594 authenticates the supplied evaluator handoff and protected #597 now owns bounded durable evaluation/rejection history under the existing State / Checkpoint boundary; canonical documentation must describe those facts without promoting them into Policy / Approval, graph publication, release or activation authority.

Reality RED → causal repair

Test-first exact 8bad02eb414e29fc1148e528918ad178e0649ffa extended test/procedural-protected-documentation-contract.test.ts to require #597 protected-source classification, bounded durable evaluation/rejection history, explicit separation of Policy / Approval CAS, and removal of stale pre-persistence / no-signed-verifier statements.

Causal successor 07e94ac8a4648efcb6cfea1cbc4d0899fd20bea9 updated docs/doctoring/procedural_graph_adoption.md: #597 is protected State / Checkpoint source, its observed coverage RED→repair→four-gate→normal-merge lineage is preserved, live Keyverse trust and Policy / Approval CAS remain separate, and the rollout table advances from persistence to approval/revocation rather than proposing a second state authority.

Application CI on 07e94ac8a4648efcb6cfea1cbc4d0899fd20bea9 then produced a real repository RED: typecheck and 4,575 tests passed except test/documentation-current-trust-authority.test.ts, whose old expectation required the pre-#597 sentence ending after #589. Exact 268765e2baefd916ec0ca2f82ca2550f76943c12 repaired that stale regression without weakening the authority check.

A broader canonical-doc sweep then confirmed that PRD/TRD/ARCHITECTURE/TRACEABILITY/product technical baseline still described procedural evaluation/history as absent or intentionally non-durable. Test-first exact 299546e6da8b45804f2b94a930acd6142e41a885 makes that drift executable: it requires protected signed-handoff verification plus bounded durable evaluation/rejection history while forbidding the stale non-durable classifications and retaining ADR-0017 Proposed.

The causal documentation sequence is ordinary branch history, not predecessor evidence transfer:

A fresh owner-authority sweep then found that the baseline still labelled exact .github/main@7fd571dbcdbae6acf29d8f4ee704d7ba6297e4db as a “moving” central snapshot even though live central main had advanced to cb0872c9a20d5584703dffacca65c096fc034c6c. Test-first exact d5ac9d7617247b2d195fadddeaca1d5bc9e14bf9 rejects that stale moving-authority formulation and requires a dated central observation while preserving the reviewed immutable Noema consumer pin. Causal current exact 2c4821fe00a9691066a86311b141a46fe8ea68e7 records the live central SHA as a dated observation and keeps moving foreign head distinct from the immutable ALLOWED_WORKFLOW_SHA pin; it does not auto-bump the consumer pin.

Boundary

ADR-0017 remains Proposed. activationAuthorized:false remains invariant. Retained evaluation/rejection history is State / Checkpoint evidence only. Live signer/trust selection remains Keyverse/owner composition; Policy / Approval CAS, non-workflow lifecycle freshness/revocation, released cross-service contracts, deployed Durable Object compatibility/p95/recovery, graph publication, canary/rollback and product outcome remain separate prerequisites. No second Workflow / Task, lifecycle truth, provider routing, quarantine/security or outbound authority is introduced.

This PR remains Draft until unchanged exact 2c4821fe00a9691066a86311b141a46fe8ea68e7 has zero valid unresolved findings/threads and application CI, reviewer-ci, central Security Scan and patch-validator-image are all terminal GREEN. Predecessor GREEN is not transferable.

Related: #584, #597.

Summary by CodeRabbit

  • 문서

    • 절차적 그래프 평가 흐름이 인증된 평가자 핸드오프와 유계형 영속 평가·거부 이력을 지원하도록 관련 문서를 갱신했습니다.
    • 평가 영수증 바인딩, 재시작 복구, 중복 핸드오프 거부 및 무결성 검증 기준을 명확히 했습니다.
    • 그래프 활성화, 게시, 승인·철회 및 신뢰 선택이 별도 권한임을 명시했습니다.
  • 테스트

    • 변경된 문서 계약과 보호된 State/Checkpoint 이력 관련 요구사항을 검증하도록 테스트를 갱신했습니다.

@coderabbitai

coderabbitai Bot commented Sep 10, 2026

Copy link
Copy Markdown

Review Change StackReview Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: e5cd3127-c405-4088-8079-2c4aafe9c635

📥 Commits

Reviewing files that changed from the base of the PR and between 61f2b37 and 2c4821f.

📒 Files selected for processing (8)
  • ARCHITECTURE.md
  • docs/PRD.md
  • docs/TRACEABILITY.md
  • docs/TRD.md
  • docs/doctoring/procedural_graph_adoption.md
  • docs/product-technical-gap-baseline.md
  • test/documentation-current-trust-authority.test.ts
  • test/procedural-protected-documentation-contract.test.ts

📝 Walkthrough

Walkthrough

절차적 그래프 문서가 인증된 평가자 핸드오프와 State / Checkpoint 기반 bounded durable evaluation/rejection history를 반영하도록 갱신되었습니다. 관련 추적성, 기준선, 도입 기록과 문서 계약 테스트도 새 보호 범위에 맞게 정렬되었습니다.

Changes

절차적 그래프 보호 범위

Layer / File(s) Summary
보호 계약 및 권한 경계
ARCHITECTURE.md, docs/PRD.md, docs/TRD.md
평가 영수증·엔벨로프의 정확한 바인딩과 별도 인증된 P-256 ECDSA 평가자 핸드오프 검증을 보호 범위에 추가했습니다. State / Checkpoint 아래에 CAS, 재생, 다이제스트 체인, 재시작 복구, 중복 거부, fail-closed 용량 제한을 갖는 내구 평가·거부 이력을 정의했습니다.
추적성 및 도입 기록 갱신
docs/TRACEABILITY.md, docs/doctoring/procedural_graph_adoption.md
보호 이력의 소유권, 도입 단계, 테스트 우선 개발 기록, Policy / Approval 및 라이브 신뢰 선택의 별도 권한을 갱신했습니다.
기술 격차 기준선 갱신
docs/product-technical-gap-baseline.md
보호 관찰 커밋, 관련 변경 이력, ADR 0017 조건, 그래프 활성화 경계와 외부 증거 요구사항을 갱신했습니다.
문서 계약 테스트 정렬
test/documentation-current-trust-authority.test.ts, test/procedural-protected-documentation-contract.test.ts
테스트가 내구성 문구와 병합된 #597 상태를 요구하도록 변경했습니다. 이전 비내구성·advisory-only 문구를 거부하도록 검증을 추가했습니다.

Estimated code review effort: 2 (Simple) | ~10 minutes

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch docs/procedural-history-protected-20260910

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Current-head review on 268765e2baefd916ec0ca2f82ca2550f76943c12: the three-file delta now repairs the observed application-CI RED without weakening the documentation authority check. The adoption record, the focused protected-documentation regression, and the formerly stale current-trust assertion agree that #597 is protected State / Checkpoint durable-history source while Policy / Approval and activation remain separate. No additional valid finding in this exact PR delta. The PR should remain Draft because protected PRD/TRD/ARCHITECTURE/TRACEABILITY/product technical baseline still contain broader post-#597 classification drift (for example, describing the procedural source as non-durable). Those files must converge before normal merge; predecessor gate results are not transferable.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Current-head review on 2c4821fe00a9691066a86311b141a46fe8ea68e7: reviewed the eight-file documentation/test convergence plus the two-commit authority repair from d540c242.... The added regression correctly rejects an exact central .github/main SHA being presented as evergreen “moving” authority, while the causal baseline change records live .github/main@cb0872c9a20d5584703dffacca65c096fc034c6c only as a dated observation and preserves the independently reviewed immutable Noema consumer pin c9052e607e5f3cc76e73207e7786b21500721b79. The broader #597 convergence continues to keep ADR-0017 Proposed, activationAuthorized:false, bounded State / Checkpoint evidence distinct from Policy / Approval and activation, and foreign owner boundaries intact. No additional valid source/test/DDD finding or unresolved inline thread found on this exact. Do not transfer predecessor GREEN; merge only if this unchanged exact receives terminal-success application CI, reviewer-ci, central Security Scan and patch-validator-image.

@seonghobae
seonghobae marked this pull request as ready for review September 10, 2026 15:41
@seonghobae
seonghobae merged commit fc5da34 into main Sep 10, 2026
17 of 18 checks passed
@seonghobae
seonghobae deleted the docs/procedural-history-protected-20260910 branch September 10, 2026 15:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant