Skip to content

feat(art): verify exact Submission input for post-submit checking - #451

Merged
abiorh-claw merged 9 commits into
mainfrom
codex/arch04b-post-submit-materialization
Sep 29, 2026
Merged

abiorh-claw merged 9 commits into
mainfrom
codex/arch04b-post-submit-materialization

Conversation

@Abiorh001

@Abiorh001 Abiorh001 commented Sep 29, 2026 •

Copy link
Copy Markdown
Collaborator

Change

ARCH-04B — Exact verified post-submit input.

Goal

Give the post-submit checker boundary scoped access to the exact ZIP consumed by an immutable Submission. Production access remains explicitly unavailable until live service authorization is implemented.

Intent And Planning Context

Bounded change record records the reviewed design, allowed files, acceptance criteria and remaining dependencies.

What Changed

  • Added TASK's owner-qualified immutable Submission projection and ART's exact consumed-admission/binding/content/verified-replica selection.
  • Reused the canonical scratch and ZIP projection for async scoped file reads, verified digest/size/manifest, cleanup, and post-I/O selection revalidation.
  • Replaced the unused generic materialization interface outright; no compatibility alias remains.
  • Reconciled current navigation and the roadmap: input materialization is delivered internally; ARCH-04B2 output custody is next.

Design Chosen

Short owner reads surround provider/consumer I/O; no row lock or transaction spans it. The public port returns closed evaluation values and material custody, not a provider handle or live file view. This does not persist checker runs/results, activate AUTH, add routes, or change acceptance policy.

The change exceeds the preferred L1 size guideline because the exact TASK read, ART byte lifetime and real integration proof must agree in one change. It adds no schema or separate storage/extraction subsystem.

Evidence

Current head: 833c1f79.

  • 21 focused tests passed on this clean head against real PostgreSQL with Local/MinIO materialization coverage. The run includes both existing consumers of the corrected shared admission helper.
  • The new foreign-record regression creates two complete valid stored lineages, proves both success controls, then exercises 16 schema-valid mixed-identifier cases in both directions. Failure sentinels guard provider open, scratch preparation and consumer access.
  • Removing the selector's identity guard makes that same regression fail at the provider-access sentinel, after its valid controls succeed.
  • Ruff, structure, base-to-head whitespace, Markdown links, Commitrail and stale-wording checks pass.
  • All required hosted checks pass: 7,829 tests completed, zero skips/deselections. The tested merge commit da001893225b7bab04ba5ddfac67f9cc143a58ac has tree 0603e037d2a9068539fbf64dd464a2f42e220621, identical to head 833c1f79. Backend evidence combines eight first-attempt lanes with the successful retry of the lane blocked by PostgreSQL registry quota. No gate or workflow was changed.

External Findings Addressed

The security proof gap is closed using two real stored project/submission chains rather than nonexistent IDs. The shared test helper selects the admission by its exact put attempt; production code is unchanged by this repair. AUTH-003 index navigation now agrees with its overview, and authorization activation custody explicitly includes ARCH-04B2 before ARCH-04C/04D. The roadmap already describes that sequence accurately.

Test Delta

New tests cover exact source selection, deny-before-access composition, async view revocation, cancellation during projection/consumption, deadlines, quota, byte/manifest drift and independent-session state changes. Existing pre-submit safety tests remain. Static expectations for the removed dead interface were replaced with the current explicit owner registration; no tests are skipped.

Impact-Routed Reviewer Results

Fresh security, QA, test-delta, reuse, documentation and product-operations reviews pass on 833c1f79. Prior architecture/CI-source review covered the unchanged production and gate configuration; this repair changes tests and documentation only. All reviewer sessions are complete.

External Review

CodeRabbit substantively reviewed the changed head with no actionable comments and no unresolved threads. Its advisory touched-function docstring warning remains nonblocking; the required repository check passes. Human approval is still required.

CI And Gate Integrity

No workflow, dependency, skip, or percentage-gate changes. Ownership and lane registration adds the exact affected paths and preserves existing tests. Coverage remains diagnostic.

Remaining Risks / Follow-Up Work

Live service admission, generation/replay/revocation custody and final publication remain ARCH-04D/04C responsibilities. The current authority is deny-only; controlled test authority is not production authorization proof. ARCH-04B2 output custody and durable execution remain separate work. No real public-intake or worker execution is claimed.

Human Review Focus

Inspect exact material ownership, transaction-free I/O, async capability lifetime, and the distinction between a returned phase value and a durable current checker result.

Human Merge Ownership

  • The user explicitly approved this specific PR for merge.

@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 8781c0d0-13e1-4c95-817e-e6f2da8a6b75

📥 Commits

Reviewing files that changed from the base of the PR and between 116ffbd and 833c1f7.

📒 Files selected for processing (6)
  • .commitrail/INDEX.md
  • .commitrail/initiatives/WS-ARCH-001/WS-ARCH-001-04B.md
  • backend/tests/post_submit_materialization_helpers.py
  • backend/tests/tasks/submission_lineage_support.py
  • backend/tests/test_post_submit_selection.py
  • docs/engineering/authorization_activation_custody.md
🚧 Files skipped from review as they are similar to previous changes (2)
  • .commitrail/INDEX.md
  • .commitrail/initiatives/WS-ARCH-001/WS-ARCH-001-04B.md

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

This change adds a TASK read port for submitted-bundle facts and an ART materializer for verified post-submit files. An asynchronous consumer receives bounded reads from a scoped view. Selection is checked again after provider I/O. Default production authority denies materialization.

Changes

Post-submit materialization

Layer / File(s) Summary
Submitted-bundle contract and selection
backend/app/modules/tasks/api/submitted_bundle.py, backend/app/modules/tasks/submitted_bundle.py, backend/app/modules/artifacts/post_submit_selection.py, backend/tests/test_post_submit_selection.py, docs/spec_artifact_storage_service.md
Adds project-, task-, and submission-qualified submitted-bundle facts. ART checks submission identity, frozen context, admission lineage, binding, content, replica, verification, and namespace before returning a detached selection.
Verified materialization and scoped consumer access
backend/app/modules/artifacts/api/submission_materialization.py, backend/app/modules/artifacts/post_submit_materialization.py, backend/app/adapters/{artifacts,tasks}/__init__.py, backend/app/modules/artifacts/{preparation,submission_archive}.py, backend/tests/post_submit_materialization_helpers.py, backend/tests/test_post_submit_materialization.py, backend/tests/test_artifact_architecture.py, docs/spec_artifact_storage_service.md
Adds a materialization port and implementation that verifies artifact bytes and manifests, supplies bounded reads to an asynchronous consumer, and rechecks selection after I/O. Adapters compose the materializer with deny-only authority. Tests cover provider variants, mismatch cases, cancellation, cleanup, limits, and transaction state.
Ownership and delivery records
.ci/behavior-ownership/partition.v1.json, backend/scripts/behavior_ownership.py, backend/scripts/test_lane_catalogue.py, backend/tests/test_behavior_ownership.py, backend/tests/test_ci_lane_catalogue.py, .commitrail/*, README.md, docs/*
Adds the new modules to ownership and test catalogues. Initiative records and documentation describe ARCH-04B hidden input as delivered, ARCH-04B2 output custody as next, and production authority as deny-only.

Priority: ⬇️ Low

Estimated code review effort: 4 (Complex) | ~60 minutes

Change: Feature

Sequence Diagram(s)

sequenceDiagram
  participant Materializer as PostSubmissionMaterializer
  participant Reader as SubmittedBundleReader
  participant Store as Artifact store
  participant Consumer as Async consumer
  Materializer->>Reader: Read submitted-bundle facts
  Reader-->>Materializer: Return detached facts
  Materializer->>Store: Open and verify selected artifact
  Store-->>Materializer: Return artifact bytes
  Materializer->>Consumer: Provide scoped bounded reads
  Consumer-->>Materializer: Return evaluation result
  Materializer->>Reader: Recheck selected submission
  Reader-->>Materializer: Return facts for comparison
Loading

Merge Risk: ⚪ Minimal · up to 833c1

The hidden input path remains unavailable to production callers, and no merge-blocking issue is established in these changes.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 833c1

The new input path is security-sensitive, but its default production configuration rejects access before files are read. Future activation still needs to establish how authorization changes and repeated evaluations are handled.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — If a future authority enables this port, its sensitive scope is submitted ZIP content in the configured artifact store, selected by project, task, submission, and verified artifact lineage. The inspected production composition currently denies that read before selection or I/O.

Security Findings and Attack Paths

  • inferred — No enabled production path to submitted bytes or PR-introduced bypass was established. Test helpers and test consumers exercise the capability with controlled authority; they do not establish external reachability.

Trust Boundaries and Controls

  • observed — The request is checked against persisted owner and context facts before artifact access. The provider read uses the selected digest and size; the consumer receives a revocable, bounded view only after byte and manifest checks.

Resilience and Maintainability Implications

  • inferred — Post-I/O selection equality prevents a changed submission or replica state from producing a successful result. It cannot by itself retract consumer effects already made before revalidation, or establish the state of a future independent authorization decision.

Hardening Proposals

  • proposed — Before enabling live authority, specify whether revocation can change independently of selected material facts and whether the authorization decision must be rebound or rechecked across I/O.
  • proposed — Require future consumers to keep effects detached until successful return, or define replay and idempotency controls before repeated evaluations can create externally visible effects.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 50.70% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 71 functions across 19 files. (3 skipped:… Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title clearly and concisely describes the main change: verifying exact Submission input for post-submit checking.
Description check ✅ Passed The description is detailed and aligned with the template. It explains the goal, design, scope, evidence, tests, risks, reviewer status, and human merge ownership. Some template sections are merged or…
Full details: Docstring Coverage

Explanation

Docstring coverage is 50.70% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 71 functions across 19 files. (3 skipped: 3 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 2
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@Abiorh001
Abiorh001 marked this pull request as ready for review September 29, 2026 03:10
@abiorh-claw
abiorh-claw self-requested a review September 29, 2026 06:51
@abiorh-claw
abiorh-claw merged commit 9c29210 into main Sep 29, 2026
26 of 28 checks passed
@abiorh-claw
abiorh-claw deleted the codex/arch04b-post-submit-materialization branch September 29, 2026 07:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants