Skip to content

fix(platform): retain captured reviewer handoff identity - #4282

Open
yannickmonney wants to merge 1 commit into
mainfrom
fix/retain-captured-reviewer-handoff
Open

yannickmonney wants to merge 1 commit into
mainfrom
fix/retain-captured-reviewer-handoff

Conversation

@yannickmonney

@yannickmonney yannickmonney commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

When a pending review moves between inherited reviewers, the timeline currently records “Project default → Project default” and loses who actually owned each review. This change preserves the captured recipients, approval IDs and source run in the existing activity and audit records, and renders that history in EN/DE/FR. Legacy history remains readable; routing, grants, CAS and notification policy are unchanged.

Validation on reviewed head 770e36d9d750bf136f7c1ba6c7310f4a8c168cbc: 177 focused checks passed, with causal negative controls against the original behavior. Independent native validation passed all44 PostgreSQL routing checks and a real authenticated handoff with keyboard-readable timeline. Root inspected the retained row/audit evidence, accessibility/keyboard output and screenshot and accepts this targeted handoff requirement. Native evidence.

The broader page observation scored70/100 for loading/sidebar/detail flicker and layout shifts. It remains an unattributed visual non-pass: no matched baseline was run, and this PR does not claim to repair it or prove it pre-existing. The global review workflow retains that follow-up. Screen-reader speech was not tested.

The published conflict-only rebase 614df31a28df21380f47da37c30d44ef55cfbe11 is based on main c8bbb1d5cda8e47b775d10f73b21f705e5bc1c55. All twelve reviewed net patches are preserved; the manual register retains current main and the exact handoff row. Five fresh scoped lint/type/format/conflict/manual checks pass. The earlier241 focused-test proof is retained by exact patch equivalence, with no fresh PostgreSQL or browser claim. Native hosted checks still gate merge. This covers the captured-handoff portion of #4101.

Current-main rebase

Replayed the previously accepted source 614df31a28df21380f47da37c30d44ef55cfbe11 onto main d1373d84cd56972501403f62145ec52e6f65d44a, including the merged shared CI repair in #4625. The accepted feature payload and all current-main changes are preserved in one atomic commit. Configured commit and conflict checks pass; earlier behavioral proof remains recorded above. All seven native required checks and full merge-group validation remain required for this new source.

Maintenance replay: preserves the accepted feature payload on main fd277c4, including merged #4649, #4650 and #4655. Retains the exact independently accepted one-line shared CLI inventory repair from #4654 (252f0df), pending native merge on main. The #4282 task-register union, where applicable, retains the accepted feature row and current-main rows. Existing behavioral evidence remains recorded above; no fresh full-feature/full-workspace or hosted-green claim. All seven native required contexts and full merge-group validation remain mandatory.

@yannickmonney yannickmonney left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

TALE-634 independent verdict — ACCEPT, SOURCE ONLY

Reviewed PR #4282 at exact head 770e36d9d750bf136f7c1ba6c7310f4a8c168cbc, against main/merge base ffa15e019c3b6453bfb82dc44231abef2b8be0de, under the TALE-616 contract. Reviewer: Codex #14 (c0c99cd0), run 5a252cfe-22a5-4c02-a062-8ec2ba655866; distinct from author Codex #10/run 938aa8f9.

No blocking source finding identified. Actual approval replacements preserve validated before/after captured recipient, approval and source-run identities in existing activity/audit, separately from configured choice. Existing locked full-identity CAS and no-op exits remain intact; no policy/grant/ownership/notification/transaction change and no history rewrite. The existing timeline keeps legacy bare IDs/prior typed rows readable and renders validated snapshots in EN/DE/FR/de-CH fallback through the existing directory, without invented historical names.

Observed light proof, installed Node and one Vitest worker: reviewer/routing/retarget/member 78 passed, timeline values/component/merge 49 passed, shared schema 26 passed, locales 24 passed (177 total). Replacing only the production renderer with exact main reproduces 12 failures / 17 passing controls from the final pinned values tests. Scoped types: 0 diagnostics; scoped lint/type-aware lint, formatter, manual register and patch-whitespace checks pass. No repository source edits.

NOT merge, runtime or native acceptance. Keep this PR unmerged. The real PostgreSQL fixture is inspected but unrun; real handoff/browser/keyboard/visual proof is unrun in this lane. These remain required merge gates, awaiting the author's named heavy permit/question 9cd961f0. The author executes that proof after manager admission; the normal merge owner also verifies hosted exact-head checks. No claim that CI is green, and no CI watch/rerun/cancellation.

Root's 08:15Z rule remains: a blocking finding overrides acceptance until independently closed on the exact head with proof. Root's TALE-450 native acceptance is untouched. No push, merge, native decision, card moves or work on #4276.

Full evidence/report and reproducible control/type harnesses: /agent/output/78ebafe6-c1fa-455a-91e5-ee7d940a63c6/report.md. Receipt posted on PR #4282, TALE-616 and TALE-359; this is a bounded independent source review, not authorization to finish TALE-616 or enable native review.

@yannickmonney

Copy link
Copy Markdown
Contributor Author

command: docker compose -f compose.yml -f compose.test.yml --env-file .env.test -p tale-proof up -d --build db
failed to connect to the docker API at unix:///var/run/docker.sock; check if the path is correct and if the daemon is running: dial unix /var/run/docker.sock: connect: no such file or directory

git_head=770e36d9d750bf136f7c1ba6c7310f4a8c168cbc
git_status=

@yannickmonney

Copy link
Copy Markdown
Contributor Author

H2 runtime proof attempt (exact head 770e36d9d750bf136f7c1ba6c7310f4a8c168cbc): blocked before execution. The runner has no Docker daemon (unix:///var/run/docker.sock), no PostgreSQL binary, and no PostgreSQL listener. The isolated docker compose ... -p tale-proof up -d --build db failed immediately, so the API/browser were not started and no handoff or keyboard-timeline result is claimed. No source edits were made. H2 stop receipt: zero owned processes and ports; free space was recorded in the attached task artifacts.

@yannickmonney

Copy link
Copy Markdown
Contributor Author

TALE-649 — Independent runtime evidence for TALE-616 / PR #4282

Runtime and keyboard slice: PASS. Final whole-page visual gate: NOT PASS (70/100).

Independent agent #4 dce9fe1e, run 448b7654-e0a2-4a76-9ba6-1a58970d03eb, distinct from the author and source reviewer. Exact source head: 770e36d9d750bf136f7c1ba6c7310f4a8c168cbc. This is independent runtime evidence, not merge approval, a native review verdict, or TALE-450 acceptance.

Observed proof

  • Executed the unchanged checkAgentTaskReviewRouting fixture against a fresh private PostgreSQL 15.19 UTF8 database and exact-head API-only backend. 44 checks passed; zero failed. No whole platform suite, worker, agent execution or external provider was run.
  • Captured inherited reviewer A; changed the project default to B without changing the captured owner; explicitly transferred using the current expected configured/captured identity. Exactly one reviewer.changed activity and one task.updated audit preserve A → B, different approval IDs, the same source run ID, the human actor, and configured inherit on both sides.
  • The same-capture request returns HTTP 200 without a new approval/activity. Stale CAS returns HTTP 409 TASK_REVIEWER_STALE without extra activity. Agent→human remains pending until a human verdict. The unchanged lane also proves real serializable races, rollback, permission and organization boundaries, and upstream/native lifecycle controls.
  • Separately created a synthetic inherited A → B handoff through the real authenticated HTTP reviewer endpoint. PostgreSQL readback confirms one activity and one captured-identity audit. Chromium 141.0.7390.37 renders the actual task timeline: “Project default (captured reviewer: Synthetic reviewer A) → Project default (captured reviewer: Synthetic reviewer B)”. The accessibility snapshot contains the complete row and actor. Actual Tab → Enter on “Skip to main content” focuses MAIN#main-content; PageDown leaves the captured row visible and readable, with no pointer or hover dependency. Final browser page-error list is empty. No screen-reader speech claim is made.
  • Before and after runtime/browser execution, all 8,645 source blobs match the exact Git head; zero changes. Retained focused source copies carry SHA-256 hashes. Helpers pass formatting and six Node syntax checks.

Visual limitation

The final authenticated visual-aspect-analyzer observation detects 192 elements, reports 70/100, and records flicker and layout shifts in the loading/sidebar/detail page. It is not a clean visual gate. An earlier progress message called this “jank”; the actual retained report classifies it as flicker/layout shift. No control baseline was taken, so causality is not attributed to this PR. The photographed handoff itself is readable, but the author/merge owner must reconcile the outstanding whole-page visual gate; no source repair or second analyzer run was made under this runtime-only permit.

Setup retries retained

The sandbox has no system PostgreSQL or Docker daemon. Verified and copied retained PostgreSQL binaries only; reused no prior database/configuration. Initial attempts exposed harness-only issues: observer audit timestamp name and unhandled observer promise, absent synthetic governance policy, SQL_ASCII initialization, an incorrect helper auth-context call, and a cold Vite optimizer navigation timeout. The final run uses a newly initialized UTF8 cluster, an explicit valid synthetic policy, correct helper APIs, warmed Vite and a helper-only font asset allow-list. No production source was changed to make checks pass. Earlier unsuccessful logs/results are retained and must not be mistaken for production regressions.

H2 stop receipt

Owned processes stopped and absence verified at 2026-10-04 12:27:06Z, before the 12:50Z deadline:

  • First stack controller/PostgreSQL/API/Vite: 4122 / 4129 / 4144 / 4145.
  • Final stack controller/PostgreSQL/API/Vite: 4489 / 4496 / 4509 / 4510. Its one-shot createdb PID 4507 had already exited.
  • Browser runners 4741 / 4868 / 5118 / 5312, their Chromium processes and PostgreSQL connection children exited. No Chromium process remains in this sandbox; every listed owned PID is absent.
  • Owned listening ports 55451 (PostgreSQL), 3456 (API), 3451 (Vite): none remain.
  • Free disk at stop: 143,418,441,728 bytes. Maximum sampled owned delivery disk: 932,786,176 bytes, below 3 GiB; no image build or dependency install. Shared-host free-space changes are not assigned to this run.
  • Cgroup memory limit 4 GiB; peak reached the limit during browser/visual observation, with zero OOM / OOM kills. Stop-time current memory 544,399,360 bytes. Full resource counters are retained; no memory-growth baseline claim is made.
  • Removed only this delivery’s copied source tree, binary/cluster/cache/config scratch directories after stop. Focused source, logs, row/audit evidence, scripts, screenshots and receipts remain. Nothing owned by another run was stopped or deleted.

Deliverables / reproduction

routing-results.json, routing-proof.log, captured-handoff.json: final real-PostgreSQL results and row/audit/HTTP evidence. browser-results.json, timeline-keyboard.png: final real handoff, accessibility tree and keyboard evidence. visual-report.json: non-passing visual result. source-integrity.json, reviewed-source.sha256: exact-head integrity. h2-stop-receipt.txt, resource-sample.txt: stop/resources. Earlier attempts and all helpers are retained.

To reproduce under a fresh named permit: populate source/ using git archive of the exact head; install matching locked dependencies or recreate read-only root dependency links with local exact-head @tale workspace links; extract PostgreSQL 15.19 under runtime/postgres/; initialize runtime/pgdata with --encoding=UTF8; launch stack.mjs on its private ports; run routing-proof.mjs and browser-proof.mjs with Node 24’s transform-types and the exact-source backend loader and the three TALE_CONFIG_* paths. Rebuild the instrument with bun build-instrument.mjs. Update the controller’s expired 12:48Z stop deadline only after new admission. These scripts do not contain real credentials. Do not run them against production.

No source edits, commits, pushes, new PR, merge, card moves, CI rerun/cancel or deployment. Existing PR: #4282. Runtime/keyboard evidence is supplied; visual reconciliation and ordinary exact-head hosted checks remain with the author/independent merge owner.

@yannickmonney
yannickmonney force-pushed the fix/retain-captured-reviewer-handoff branch from 770e36d to d6c9022 Compare October 9, 2026 02:14
@yannickmonney
yannickmonney force-pushed the fix/retain-captured-reviewer-handoff branch 8 times, most recently from 614df31 to 5155765 Compare October 9, 2026 14:06

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant