Skip to content

Fix source publication authority across activity profiles - #350

Merged
adrianwebb merged 1 commit into
stagingfrom
codex/activity-profile-kata-closure
Sep 12, 2026
Merged

Fix source publication authority across activity profiles#350
adrianwebb merged 1 commit into
stagingfrom
codex/activity-profile-kata-closure

Conversation

@adrianwebb

@adrianwebb adrianwebb commented Sep 12, 2026

Copy link
Copy Markdown
Contributor

Outcome

Content-only activity profiles retain writable disposable Kata source and no longer fail because source-candidate publication was inferred from acting mode.

Work authority

Contributor mode (select one):

  • Human-authored
  • Agent-assisted under human authority
  • Agent-authored under human authority

Plan

Audit all activity source modes, remove mode-name inference, bind durable publication to the explicit source-candidate output grant, and verify the complete API suite. Implementation and local verification are complete; Actions are running.

Changes and commits

Commit 6d5b8e7 derives source work from explicit publication authority and adds the activity matrix regression.

Verification

  • 909 tests passed; 10 intentionally skipped.

  • Distribution build passed.

  • File architecture policy passed.

  • Matrix covers planning, estimating, reviewing, reporting, content-only acting, candidate-producing work, and conversation denial.

  • I ran the narrowest relevant package verification and documented any checks that could not be run.

Risk and rollback

Risk is limited to assignment source authorization classification. Explicit source-candidate assignments retain work/candidate-only behavior. Revert commit 6d5b8e7 to restore the previous classification without changing persisted source pins or credentials.

Completion summary

The API no longer assigns durable source-work semantics without explicit publication authority. Managed activation and distinct live activity acceptance follow the coordinated Agent and Deployment release.

AGPL committer authorization

The base-owned workflow checks the provider-authenticated pull-request author against .github/approved-committers.json. There is no per-PR grant checkbox.

Submission checklist

  • The change is bounded to the stated work item and target repository.
  • Exact base and head refs are recorded and the branch is ready for review.
  • Verification and compatibility evidence are recorded above.
  • No plaintext secrets, credentials, machine state, or unrelated residue are included.
  • Plan, status, commits, and completion summary form a complete durable record.
  • Rollback or recovery steps are documented and executable.

@adrianwebb
adrianwebb merged commit bbf86c2 into staging Sep 12, 2026
5 of 7 checks passed
@adrianwebb
adrianwebb deleted the codex/activity-profile-kata-closure branch September 12, 2026 00:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant