Preserve optional activity consent and pending receipt continuity - #2978
kantorcodes wants to merge 95 commits into
Conversation
…on (HGP-135) policy_bundle_is_enforceable treated every guard-policy-bundle.v2 envelope as live, so a correctly signed draft or pending-approval v2 document was admitted on sync and cached reads — changing local state for an unapproved policy. Admission now reads the publication-contract rollout state from payload.spec.rolloutState for v2 (top-level rolloutState for v1) and only admits enforcing/enforced/rollback_available. Rejected drafts retain the prior valid revision and never emit an applied acknowledgement. v2 documents that omit the optional rolloutState field remain live so already-published generic bundles keep working. Signature verification is unchanged. Signed-off-by: Michael Kantor <6068672+kantorcodes@users.noreply.github.com>
… module moves the signed generic v2 admission suite (draft/pending rejection, enforcing admission, omitted-state compatibility, cached-revalidation inactive_rollout_state) out of test_policy_bundle_v2.py so both modules stay under the 500 non-blank-line limit; shared signing helpers are imported from the original module (qodo #2948) Signed-off-by: Michael Kantor <6068672+kantorcodes@users.noreply.github.com>
…review) The v2 compatibility path now applies only when payload.spec.rolloutState is omitted. A present null or other non-string value is not treated as live authority; GuardPolicyDocument.from_mapping rejects those the same way. Regression tests cover signed v2 bundles with null and non-string rollout states. Signed-off-by: Michael Kantor <6068672+kantorcodes@users.noreply.github.com>
… (PR #2948 review) Drive sync_receipts with an inactive (draft/pending_approval/null) v2 bundle planted in the cache while a live enforcing bundle is retained: the cached bundle is rejected, never becomes effective, and last-good authority remains current. Signed-off-by: Michael Kantor <6068672+kantorcodes@users.noreply.github.com>
…tivation evidence (HGP-136-152) - generic review compiles as review, ignore is inert, device selectors rejected pre-publication (HGP-136) - runtime posture reports the real canonical lane incl. missing protected authority/capability (HGP-137) - generic v2 acks are revision/device-bound only after the lane applies; unverified otherwise; no fabricated extension proof (HGP-138/139) - receipt upload success separated from policy validation/application with machine-readable rejection + retained last-good (HGP-140) - memory writes own memory rows in one transaction; bundle replace scoped to bundle-owned rows; both authority sets survive alternation (HGP-141/142) - signed memory targets project exactly or are refused; no sibling scope broadening (HGP-143) - one injected UTC clock for v1/v2 envelope and key validity; future-dated v2 rejected with stable code, last-good retained (HGP-144/145) - offline lifetime states, revocation without resurrection, workspace isolation, first-install trust, same-version substitution protection, empty-vs-missing publication distinction, and atomic concurrent delivery proven with regression suites (HGP-146-152) Signed-off-by: Michael Kantor <6068672+kantorcodes@users.noreply.github.com>
…2948 review) draft/pending_approval fail the enforceability gate as inactive_rollout_state; present null fails document validation earlier as invalid_policy_document. Signed-off-by: Michael Kantor <6068672+kantorcodes@users.noreply.github.com>
…n' into hgp/batch-03-policy-source-ownership # Conflicts: # src/codex_plugin_scanner/guard/policy_bundle_parser.py
…n' into hgp/batch-03-policy-source-ownership
Signed-off-by: Michael Kantor <6068672+kantorcodes@users.noreply.github.com>
…e-accurate sync outcomes Qodo findings on #2949: generic acks no longer fabricate managed delivery/extension proofs; signed memory targets accept the portal 0..50 cardinality and project into real matcher fields; runtime posture threads contract/capability state so lane, fallback-vs-applied, retained-vs- no-authority, and rollout percentage are reported accurately; applied acks are never overwritten when rollout disables; duplicate advisories_stored key removed. Signed-off-by: Michael Kantor <6068672+kantorcodes@users.noreply.github.com>
…ship (HGP-191-194) - Two-device approved policy adoption against one stub cloud - Offline reconnect applies newest revision only - Review-to-continuation without a persistent grant - Alternating policy/memory durability: bundle apply replaces only bundle-owned remote sources; memory apply replaces only cloud-signed-memory rows (RF-03) Signed-off-by: Michael Kantor <6068672+kantorcodes@users.noreply.github.com>
…utcomes (HGP-195/196) - Release evidence collector fails on missing/silently-deselected required release tests; the one CI deselect is named in the report - Negative outcomes (draft, wrong-workspace, stale, unavailable-runtime, immutable-block) are required fail-closed evidence, never passed:true - Generic v2 draft/pending_approval/simulated rollout states are not live authority (presence-aware, matching #2948) - Operator docs replace Phase 0 gap notes with verified create/approve/sync/verify/recover guidance; semantics.md names in-review #2948/#2949/#2959 Signed-off-by: Michael Kantor <6068672+kantorcodes@users.noreply.github.com>
…readiness, durable review state (HGP-153-172) - Activation failures classified (JSON/storage/transport) with idempotent retry and no false apply claims; desired/durable/resident visibility stages - Scope-specific effective-authority explanation; managed/immutable floors cannot be weakened; generic-matchers.v1 capability published - Bounded compile/parse error payloads; export/import roundtrips retain meaning; deterministic imports idempotent; device selectors match installation identity only - Headless sync after connect/restart; bounded worker intervals; CLI readiness requires both workers; one status projection for CLI and settings; enable/disable lifecycle convergence - Capability expiry explained; OAuth refresh bindings; held/quarantined events identity-bound; oldest-first outbox batching; partial-ack repair; durable SQLite/process recovery Signed-off-by: Michael Kantor <6068672+kantorcodes@users.noreply.github.com>
Keep independently observed policy revisions distinct and retain numeric failure status for troubleshooting. Verify completion evidence and public policy guidance. Decision-Diff-Framed-SHA256: 05069f050147a373b0de8092605f7bda8d45979d0362f5d7d7634fd2b08499d7
Keep policy source consent and exact selectors bound through review, preserve enrollment outcomes, and retain bounded verification diagnostics. Decision-Diff-Framed-SHA256: 18e11987745548f4705c3fe367bdf98df1661e11861140089ffd947b32155fe6
Decision-Diff-Framed-SHA256: 18e11987745548f4705c3fe367bdf98df1661e11861140089ffd947b32155fe6
Decision-Diff-Framed-SHA256: 18e11987745548f4705c3fe367bdf98df1661e11861140089ffd947b32155fe6
Decision-Diff-Framed-SHA256: 18e11987745548f4705c3fe367bdf98df1661e11861140089ffd947b32155fe6
Decision-Diff-Framed-SHA256: 18e11987745548f4705c3fe367bdf98df1661e11861140089ffd947b32155fe6
Decision-Diff-Framed-SHA256: 18e11987745548f4705c3fe367bdf98df1661e11861140089ffd947b32155fe6
Decision-Diff-Framed-SHA256: 18e11987745548f4705c3fe367bdf98df1661e11861140089ffd947b32155fe6
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Code Review ✅ No issues found🟡 Medium risk · Runtime changes gate optional uploads and receipt cursor advancement across sync paths Optional activity uploads now require current saved preferences and local consent, with every receipt attempt rechecking the selected workspace and redaction floor. Pending rows remain available across pauses, retries, and acknowledgement changes while mandatory policy processing stays separate. Validated across 68 focused functional cases on Python 3.10 and 3.12, including real state transactions, concurrent updates, and 51-row receipt continuity. No issues found. Options ✅ Auto-apply✅ Auto-apply is on → Gitar will commit updates to this branch. Comment with these commands to change the behavior for this request:
Was this helpful? React with 👍 / 👎 | Powered by Gitar — free for open source |
074c0f6 to
a53d471
Compare
Preserve locally authorized optional uploads while applying authenticated workspace preferences. Each send and retry rechecks the selected workspace, current consent and redaction; rejected or unacknowledged uploads remain pending. Initial negotiation sends no optional receipts, and policy protection continues independently.
Validation: the dedicated exact-head and pull-request workflows pass 68 contract/runtime tests on Python 3.10 and 3.12, 142 existing transport/settings/event tests, and the actual-import type check. The workflow retains a reproduced cursor-loss baseline before validating the repair, including an interrupted 51-receipt upload and resume. Disposable local consent setup is explicit; existing transport assertions remain.
This draft provides source and hosted test evidence. Installed runtime and paired acceptance remain separate prerequisites; this does not authorize a coordinated server rollout.