Skip to content

docs(policy-approval): classify protected procedural publication preflight - #604

Merged
seonghobae merged 11 commits into
mainfrom
docs/procedural-publication-preflight-protected-20260911
Sep 10, 2026
Merged

docs(policy-approval): classify protected procedural publication preflight#604
seonghobae merged 11 commits into
mainfrom
docs/procedural-publication-preflight-protected-20260911

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 10, 2026

Copy link
Copy Markdown
Contributor

Scope

Post-merge documentation convergence after protected #603. This lane updates moving-current canonical documentation to classify #603 as protected Noema Policy / Approval publication-preflight source while preserving the distinction between point-in-time preflight evidence and actual graph publication/activation authority.

ADR-0017 remains Proposed; publicationAuthorized:false and activationAuthorized:false remain explicit invariants. This lane does not copy Keyverse trust/key-custody truth, context-graph-contracts publication authority, provider routing, lifecycle truth, State / Checkpoint storage, or Workflow / Task authority.

Reality RED -> causal repair

  • ff1b3e91603b630905d7b8df102ea3f733b70332 added the executable documentation-authority regression first.
  • Hosted application CI run 34526877231, job 103037819434, checked out that exact head and passed exact-checkout/live-base/lockfile/install/release-typecheck stages before release tests failed. The observed suite result was 1 failed / 660 passed test files and 1 failed / 4591 passed tests; the first failing assertion was test/procedural-publication-preflight-protected-documentation.test.ts:16, where canonical documentation still lacked protected #603 classification.
  • Review of moving-current Unreleased history also found that protected feat(policy-approval): reconcile current procedural publication preconditions #603 had no CHANGELOG authority entry. f4068e3f7c87ad0d8519b9a15b9bed52859e33bd extended the regression to require the feat(policy-approval): reconcile current procedural publication preconditions #603 publication-preflight CHANGELOG record.
  • a4a575aa5b7543585f7b64931ddaa9e2fdf93fde converged ARCHITECTURE.md.
  • a989354dd7eb4a9b946b5286d6674e67c4d60f82 converged docs/PRD.md.
  • a7f02a1668f98167396b72ceef2d217ce607c1fd converged docs/TRD.md.
  • 77aeb5e75602cfbf6ad6665d3152b1f52d118322 converged docs/TRACEABILITY.md.
  • The product technical baseline was converged to protected main@70c997e45db975a2ac43197ec2c49c9916a3e238, feat(policy-approval): reconcile current procedural publication preconditions #603 publication-preflight status, and the next true prerequisite: immutable released graph contract + live trust/current lifecycle before an actual publisher can consume the exact admitted preflight.
  • During full-file review, an accidental historical provenance truncation introduced while editing the baseline was caught before merge. e3b65e8ab0400880afde235cacaa0ea8cab9d19a added a regression for the exact historical SHA and aa475ff02ca6d8f089159304b2c0f2bc0528ea09 restored it.
  • The Unreleased feat(policy-approval): reconcile current procedural publication preconditions #603 entry was added, and full diff review caught one unrelated historical undici CHANGELOG sentence that had drifted during replacement. 72abb528e3d30eff324f34a5bc4c076f6be677b2 restored that unrelated line so the CHANGELOG diff is now only the feat(policy-approval): reconcile current procedural publication preconditions #603 publication-preflight entry.

Current candidate intent: classify protected #603 as a stable point-in-time State / Checkpoint + Policy / Approval reconciliation whose process-local receipt remains publicationAuthorized:false and activationAuthorized:false. Actual graph publication, current lifecycle/revocation, live Keyverse/owner trust, immutable released context-graph-contracts, canary/rollback and production outcome remain separate authorities.

Predecessor GREEN does not transfer. Final merge acceptance applies only to one unchanged exact head with application CI, reviewer-ci, central Security Scan and patch-validator-image terminal GREEN and zero valid unresolved review findings.

Related: #603, #584, #36, #561.

Summary by CodeRabbit

  • 새 기능

    • Policy/Approval 게시 사전 점검(preflight) 경계를 추가했습니다.
    • State/Checkpoint와 Policy/Approval 정보를 안정적으로 재확인하고, 변경 중인 이력이나 취소된 승인을 거부합니다.
    • 그래프·이력·평가자·서명자·승인 식별자가 정확히 일치할 때만 로컬 사전 점검 영수증을 발급합니다.
    • 사전 점검은 게시 또는 활성화 권한을 부여하지 않습니다.
  • 문서

    • 아키텍처, 제품 요구사항, 기술 설계 및 추적성 문서를 관련 동작과 제한사항에 맞게 갱신했습니다.
    • 변경 내역과 기준선 기록을 업데이트했습니다.
  • 테스트

    • 관련 문서가 사전 점검의 보호 경계와 권한 제한을 명시하는지 검증합니다.

@coderabbitai

coderabbitai Bot commented Sep 10, 2026

Copy link
Copy Markdown

Review Change StackReview Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 8e3bfcf0-2c0c-49b2-9087-8b25572024c3

📥 Commits

Reviewing files that changed from the base of the PR and between 70c997e and 72abb52.

📒 Files selected for processing (7)
  • ARCHITECTURE.md
  • CHANGELOG.md
  • docs/PRD.md
  • docs/TRACEABILITY.md
  • docs/TRD.md
  • docs/product-technical-gap-baseline.md
  • test/procedural-publication-preflight-protected-documentation.test.ts

📝 Walkthrough

Walkthrough

#603 Policy / Approval publication preflight 경계를 문서화했습니다. 안정적 이중 읽기, 변경 및 철회 거부, 정확한 정체성 일치, 비권한 수신 증명을 요구사항과 추적성 문서에 반영했습니다. 문서 분류 검증 테스트를 추가했습니다.

Changes

Publication preflight 경계

Layer / File(s) Summary
Preflight 경계 정의
ARCHITECTURE.md, CHANGELOG.md
#603의 안정적 이중 읽기, 이동하는 권위 및 현재 철회 거부, 정확한 정체성 일치, publicationAuthorized:falseactivationAuthorized:false 수신 증명을 기록했습니다.
요구사항 및 추적성 정렬
docs/PRD.md, docs/TRD.md, docs/TRACEABILITY.md, docs/product-technical-gap-baseline.md
제품 요구사항, 기술 설계, 추적성, 기준선 문서가 #603의 preflight 범위와 실제 그래프 게시 및 활성화의 별도 권한 경계를 반영하도록 갱신되었습니다.
문서 분류 검증
test/procedural-publication-preflight-protected-documentation.test.ts
정식 문서와 CHANGELOG.md#603을 비권한 publication preflight로 분류하는지 검증합니다.

Estimated code review effort: 2 (Simple) | ~10 minutes

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch docs/procedural-publication-preflight-protected-20260911

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Current-head review on exact 72abb528e3d30eff324f34a5bc4c076f6be677b2: reviewed all 7 changed files and the authority regression. The delta correctly classifies protected #603 as a point-in-time Policy / Approval publication preflight while preserving publicationAuthorized:false, activationAuthorized:false, ADR-0017 Proposed, and the foreign-owner boundaries for Keyverse trust, context-graph-contracts publication authority, lifecycle/revocation, provider routing, and product-domain truth. The CHANGELOG delta is scoped to #603 and the regression protects the protected-source classification plus historical provenance anchor. No additional valid current-head source/test/DDD finding found. This is a COMMENT review only; no self-approval.

@seonghobae
seonghobae marked this pull request as ready for review September 10, 2026 20:59
@seonghobae
seonghobae merged commit 585b2f0 into main Sep 10, 2026
17 of 18 checks passed
@seonghobae
seonghobae deleted the docs/procedural-publication-preflight-protected-20260911 branch September 10, 2026 20:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant