Fix source publication authority across activity profiles - #350
Merged
Conversation
10 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Outcome
Content-only activity profiles retain writable disposable Kata source and no longer fail because source-candidate publication was inferred from acting mode.
Work authority
Contributor mode (select one):
Plan
Audit all activity source modes, remove mode-name inference, bind durable publication to the explicit source-candidate output grant, and verify the complete API suite. Implementation and local verification are complete; Actions are running.
Changes and commits
Commit 6d5b8e7 derives source work from explicit publication authority and adds the activity matrix regression.
Verification
909 tests passed; 10 intentionally skipped.
Distribution build passed.
File architecture policy passed.
Matrix covers planning, estimating, reviewing, reporting, content-only acting, candidate-producing work, and conversation denial.
I ran the narrowest relevant package verification and documented any checks that could not be run.
Risk and rollback
Risk is limited to assignment source authorization classification. Explicit source-candidate assignments retain work/candidate-only behavior. Revert commit 6d5b8e7 to restore the previous classification without changing persisted source pins or credentials.
Completion summary
The API no longer assigns durable source-work semantics without explicit publication authority. Managed activation and distinct live activity acceptance follow the coordinated Agent and Deployment release.
AGPL committer authorization
The base-owned workflow checks the provider-authenticated pull-request author against .github/approved-committers.json. There is no per-PR grant checkbox.
Submission checklist