fix(governance): reconcile Fordham contracts and evidence - #2164
Conversation
|
Warning Review limit reached
Next review available in: 24 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (13)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: cbf1eeacf6
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| > `vote.signed.v1` is disabled/non-contractual; contribution records are not legal eligibility; and | ||
| > no election path is active. The corrected target uses an independently attested roll, a complete | ||
| > immutable ballot set with inclusion evidence, committee Ed25519 tally attestation, paper parity, | ||
| > and a separately reviewed receipt-freeness mechanism. |
There was a problem hiding this comment.
Replace the remaining voter-signing implementation step
The new reconciliation rejects voter signatures for Mode-A ballots, but the unchanged Part 3 step still directs implementers to define vote.signed.v1 by issuing per-resident signing cards in the agent-card shape. That is the previously rejected design: it would make a resident's vote cryptographically attributable and reintroduce a coercion receipt. Update that next-step contract to use committee-issued eligibility credentials and an unlinkable ballot/evidence design before this scaffold is used to guide implementation.
Useful? React with 👍 / 👎.
…fresh + AGNOTE row DARKXSIDE approved #1 + #2 + #3 in one push. Adjusted the plan on discovery: the AGNOTE row (#3) was already shipped by 5090-CLAUDE ('A2UI stack landed - merge train + restack record' at commit 5294223), so this PR ships a Mavis-5090 lane closeout row that explicitly references the existing closeout instead of duplicating it. 1. pmoves/docs/logs/pr_trim_2132_LEARNINGS.md - post-merge addendum - Bucket-1 entry #10: Fordham-resident-legitimacy finding from B850-CLAUDE's 2026-07-16 cross-lane CHIT review (2 attributed quotes in fordam-hill.json with no recorded consent or provenance). Captured as 4th-bucket addendum so the trim-cycle LEARNINGS surface the finding, not just the code findings. - Pattern reflection: 'a trim cycle that only reads diffs will miss fixture-provenance questions every time'. Future trim cycles on tenant PRs should run a fixture-content audit. - Resolution pointer: the substantive work is in pmoves/docs/pilots/fordham-hill/ (B850-CLAUDE's cross-lane reconciliation). The answer is an operator decision (DARKXSIDE) that lives in the deploy gate, not the merge gate. - graphiti marker added: Mavis-5090 / phase:post-merge-addendum / ts:2026-07-19T05:55:00Z 2. pmoves/docs/AGENTS/AGNOTE4482_SITREP.md - refresh for post-merge state - Timestamp: 2026-07-17 -> 2026-07-19 - 'Latest Lane' section rewritten to reflect: A2UI v0.1+v0.2 MERGED into main 2026-07-18; what was added post-merge (#2154 ballot + A2UI reconciliation, #2164 Fordham contracts reconciliation, the pilots/fordham-hill/ directory, the CATACLYSM_CROSSLINKS.md bridge doc); what is OPEN (Fordham- resident-legitimacy deploy-gate, CodeQL on pm-ballot, v0.3 spec additions, HMAC -> Ed25519 migration, CF Pages deploy, B-mode watcher); three-body for the lane including 5090-CLAUDE (trim) and B850-CLAUDE (cross-lane review). - Cron reference updated to its repurposed state (every 45 min, watching the post-merge follow-up lane). 3. pmoves/docs/AGENTS/AGNOTE4482PHI.t1.md - Mavis-5090 lane closeout row - 2026-07-19T05:55:00Z RELEASE row noting this PR is the small post-merge follow-up, with 5090-CLAUDE's A2UI Stack Landed row as the substantive closeout. Lists what the lane produced in total (15 commits, 3 PRs) and what is NOT closed (deferred to the post-merge follow-up cron). - graphiti marker: Mavis-5090::WEBSITE-AS-AGENT-CANVAS-LANE-CLOSEOUT Standing: this is the Mavis-5090 closeout. The next-lane CLAIM can land cleanly. The cron watches the post-merge follow-up lane (Fordham-resident-legitimacy + v0.3 pm-ballot rebuild + B-mode when n8n is up). Spark/Knuckles local model reading this fresh gets: the lane is in main, the artifacts are indexed, the open gates are listed. Refs: - pmoves/docs/logs/pr_trim_2132_LEARNINGS.md (the addendum) - pmoves/docs/AGENTS/AGNOTE4482_SITREP.md (the refresh) - pmoves/docs/AGENTS/AGNOTE4482PHI.t1.md (the closeout row) - pmoves/docs/pilots/fordham-hill/07-ballot-prior-art-and-reconciliation.md (B850-CLAUDE's cross-lane work) - 5294223 (5090-CLAUDE's A2UI Stack Landed row, the substantive closeout) - .claude/agents/pr-review-watcher.md (the cron-repurposed agent) - pmoves/tools/pr_review_watcher.py (the A-mode listener, B-mode ready)
…fresh + AGNOTE row DARKXSIDE approved #1 + #2 + #3 in one push. Adjusted the plan on discovery: the AGNOTE row (#3) was already shipped by 5090-CLAUDE ('A2UI stack landed - merge train + restack record' at commit 5294223), so this PR ships a Mavis-5090 lane closeout row that explicitly references the existing closeout instead of duplicating it. 1. pmoves/docs/logs/pr_trim_2132_LEARNINGS.md - post-merge addendum - Bucket-1 entry #10: Fordham-resident-legitimacy finding from B850-CLAUDE's 2026-07-16 cross-lane CHIT review (2 attributed quotes in fordam-hill.json with no recorded consent or provenance). Captured as 4th-bucket addendum so the trim-cycle LEARNINGS surface the finding, not just the code findings. - Pattern reflection: 'a trim cycle that only reads diffs will miss fixture-provenance questions every time'. Future trim cycles on tenant PRs should run a fixture-content audit. - Resolution pointer: the substantive work is in pmoves/docs/pilots/fordham-hill/ (B850-CLAUDE's cross-lane reconciliation). The answer is an operator decision (DARKXSIDE) that lives in the deploy gate, not the merge gate. - graphiti marker added: Mavis-5090 / phase:post-merge-addendum / ts:2026-07-19T05:55:00Z 2. pmoves/docs/AGENTS/AGNOTE4482_SITREP.md - refresh for post-merge state - Timestamp: 2026-07-17 -> 2026-07-19 - 'Latest Lane' section rewritten to reflect: A2UI v0.1+v0.2 MERGED into main 2026-07-18; what was added post-merge (#2154 ballot + A2UI reconciliation, #2164 Fordham contracts reconciliation, the pilots/fordham-hill/ directory, the CATACLYSM_CROSSLINKS.md bridge doc); what is OPEN (Fordham- resident-legitimacy deploy-gate, CodeQL on pm-ballot, v0.3 spec additions, HMAC -> Ed25519 migration, CF Pages deploy, B-mode watcher); three-body for the lane including 5090-CLAUDE (trim) and B850-CLAUDE (cross-lane review). - Cron reference updated to its repurposed state (every 45 min, watching the post-merge follow-up lane). 3. pmoves/docs/AGENTS/AGNOTE4482PHI.t1.md - Mavis-5090 lane closeout row - 2026-07-19T05:55:00Z RELEASE row noting this PR is the small post-merge follow-up, with 5090-CLAUDE's A2UI Stack Landed row as the substantive closeout. Lists what the lane produced in total (15 commits, 3 PRs) and what is NOT closed (deferred to the post-merge follow-up cron). - graphiti marker: Mavis-5090::WEBSITE-AS-AGENT-CANVAS-LANE-CLOSEOUT Standing: this is the Mavis-5090 closeout. The next-lane CLAIM can land cleanly. The cron watches the post-merge follow-up lane (Fordham-resident-legitimacy + v0.3 pm-ballot rebuild + B-mode when n8n is up). Spark/Knuckles local model reading this fresh gets: the lane is in main, the artifacts are indexed, the open gates are listed. Refs: - pmoves/docs/logs/pr_trim_2132_LEARNINGS.md (the addendum) - pmoves/docs/AGENTS/AGNOTE4482_SITREP.md (the refresh) - pmoves/docs/AGENTS/AGNOTE4482PHI.t1.md (the closeout row) - pmoves/docs/pilots/fordham-hill/07-ballot-prior-art-and-reconciliation.md (B850-CLAUDE's cross-lane work) - 5294223 (5090-CLAUDE's A2UI Stack Landed row, the substantive closeout) - .claude/agents/pr-review-watcher.md (the cron-repurposed agent) - pmoves/tools/pr_review_watcher.py (the A-mode listener, B-mode ready)
…fresh + AGNOTE row (#2165) * docs(post-merge): A2UI lane closeout - LEARNINGS addendum + SITREP refresh + AGNOTE row DARKXSIDE approved #1 + #2 + #3 in one push. Adjusted the plan on discovery: the AGNOTE row (#3) was already shipped by 5090-CLAUDE ('A2UI stack landed - merge train + restack record' at commit 5294223), so this PR ships a Mavis-5090 lane closeout row that explicitly references the existing closeout instead of duplicating it. 1. pmoves/docs/logs/pr_trim_2132_LEARNINGS.md - post-merge addendum - Bucket-1 entry #10: Fordham-resident-legitimacy finding from B850-CLAUDE's 2026-07-16 cross-lane CHIT review (2 attributed quotes in fordam-hill.json with no recorded consent or provenance). Captured as 4th-bucket addendum so the trim-cycle LEARNINGS surface the finding, not just the code findings. - Pattern reflection: 'a trim cycle that only reads diffs will miss fixture-provenance questions every time'. Future trim cycles on tenant PRs should run a fixture-content audit. - Resolution pointer: the substantive work is in pmoves/docs/pilots/fordham-hill/ (B850-CLAUDE's cross-lane reconciliation). The answer is an operator decision (DARKXSIDE) that lives in the deploy gate, not the merge gate. - graphiti marker added: Mavis-5090 / phase:post-merge-addendum / ts:2026-07-19T05:55:00Z 2. pmoves/docs/AGENTS/AGNOTE4482_SITREP.md - refresh for post-merge state - Timestamp: 2026-07-17 -> 2026-07-19 - 'Latest Lane' section rewritten to reflect: A2UI v0.1+v0.2 MERGED into main 2026-07-18; what was added post-merge (#2154 ballot + A2UI reconciliation, #2164 Fordham contracts reconciliation, the pilots/fordham-hill/ directory, the CATACLYSM_CROSSLINKS.md bridge doc); what is OPEN (Fordham- resident-legitimacy deploy-gate, CodeQL on pm-ballot, v0.3 spec additions, HMAC -> Ed25519 migration, CF Pages deploy, B-mode watcher); three-body for the lane including 5090-CLAUDE (trim) and B850-CLAUDE (cross-lane review). - Cron reference updated to its repurposed state (every 45 min, watching the post-merge follow-up lane). 3. pmoves/docs/AGENTS/AGNOTE4482PHI.t1.md - Mavis-5090 lane closeout row - 2026-07-19T05:55:00Z RELEASE row noting this PR is the small post-merge follow-up, with 5090-CLAUDE's A2UI Stack Landed row as the substantive closeout. Lists what the lane produced in total (15 commits, 3 PRs) and what is NOT closed (deferred to the post-merge follow-up cron). - graphiti marker: Mavis-5090::WEBSITE-AS-AGENT-CANVAS-LANE-CLOSEOUT Standing: this is the Mavis-5090 closeout. The next-lane CLAIM can land cleanly. The cron watches the post-merge follow-up lane (Fordham-resident-legitimacy + v0.3 pm-ballot rebuild + B-mode when n8n is up). Spark/Knuckles local model reading this fresh gets: the lane is in main, the artifacts are indexed, the open gates are listed. Refs: - pmoves/docs/logs/pr_trim_2132_LEARNINGS.md (the addendum) - pmoves/docs/AGENTS/AGNOTE4482_SITREP.md (the refresh) - pmoves/docs/AGENTS/AGNOTE4482PHI.t1.md (the closeout row) - pmoves/docs/pilots/fordham-hill/07-ballot-prior-art-and-reconciliation.md (B850-CLAUDE's cross-lane work) - 5294223 (5090-CLAUDE's A2UI Stack Landed row, the substantive closeout) - .claude/agents/pr-review-watcher.md (the cron-repurposed agent) - pmoves/tools/pr_review_watcher.py (the A-mode listener, B-mode ready) * docs(pr-open): add PR body file for the post-merge closeout (PR #2165 candidate) * docs(sitrep): correct A2UI shipped-state overstatements (Codex review #2165) - v0.1 line: 'Fordham Hill tenant page live' -> 'composed and ready to deploy (CF Pages deploy not yet run - operator call)' (matches the same doc's own 'not yet run' note later; deploy-tenant is manual). - v0.2 line: receipts are unsigned demo (chit-stub: placeholder), nonce- commitment is still TODO per rev-3 §5.4 - not 'CHIT-signed'. - PR pointer repointed from phantom pr_manifest_2026-07-15.json to the file that exists, PR_closeout_a2ui.body.md. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * docs: address CodeRabbit review findings on #2165 - SITREP: fix stale "blocked" MCP heading (issue resolved 2026-07-13) - PR body: correct file count (3 -> 4), document testing checks per LOCAL_CI_CHECKS guidelines, mark Fordham-resident-legitimacy resolved (PR #2269), update CF Pages deploy follow-up 💘 Generated with Crush --------- Co-authored-by: Mavis-5090 <Mavis-5090@pmoves.local> Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Summary
PMOVES-ToKenism-Multito merge commitd17ea07b59c30051a6258d0bde4c9d82dabe0907and close the stale/security findings left on merged parent PR docs(fordham): ballot prior art + A2UI reconciliation — HMAC cannot sign a contested ballot #2154.Closes review follow-up for #2154.
Testing
Required Checks
CHIT Contract Check(CI will block the merge until this passes)vote.signed.v1disabled/non-contractualReview Coordination
/copilot reviewcomment)Follow-up Tasks
Reviewer Notes
Please scrutinize the executable-vs-activation boundary and the removal of HMAC/Mode-B contribution claims from Mode-A ballot eligibility. This PR intentionally does not activate a ballot subject or election service.