Skip to content

Preserve optional activity consent and pending receipt continuity - #2978

Closed
kantorcodes wants to merge 95 commits into
hgp/batch-11b-release-gatingfrom
hgp/workspace-preference-contract
Closed

kantorcodes wants to merge 95 commits into
hgp/batch-11b-release-gatingfrom
hgp/workspace-preference-contract

Conversation

@kantorcodes

@kantorcodes kantorcodes commented Sep 18, 2026 •

Copy link
Copy Markdown
Member

Preserve locally authorized optional uploads while applying authenticated workspace preferences. Each send and retry rechecks the selected workspace, current consent and redaction; rejected or unacknowledged uploads remain pending. Initial negotiation sends no optional receipts, and policy protection continues independently.

Validation: the dedicated exact-head and pull-request workflows pass 68 contract/runtime tests on Python 3.10 and 3.12, 142 existing transport/settings/event tests, and the actual-import type check. The workflow retains a reproduced cursor-loss baseline before validating the repair, including an interrupted 51-receipt upload and resume. Disposable local consent setup is explicit; existing transport assertions remain.

This draft provides source and hosted test evidence. Installed runtime and paired acceptance remain separate prerequisites; this does not authorize a coordinated server rollout.

…on (HGP-135)

policy_bundle_is_enforceable treated every guard-policy-bundle.v2
envelope as live, so a correctly signed draft or pending-approval v2
document was admitted on sync and cached reads — changing local state
for an unapproved policy.

Admission now reads the publication-contract rollout state from
payload.spec.rolloutState for v2 (top-level rolloutState for v1) and
only admits enforcing/enforced/rollback_available. Rejected drafts
retain the prior valid revision and never emit an applied
acknowledgement. v2 documents that omit the optional rolloutState field
remain live so already-published generic bundles keep working.

Signature verification is unchanged.

Signed-off-by: Michael Kantor <6068672+kantorcodes@users.noreply.github.com>
… module

moves the signed generic v2 admission suite (draft/pending rejection,
enforcing admission, omitted-state compatibility, cached-revalidation
inactive_rollout_state) out of test_policy_bundle_v2.py so both modules
stay under the 500 non-blank-line limit; shared signing helpers are
imported from the original module (qodo #2948)

Signed-off-by: Michael Kantor <6068672+kantorcodes@users.noreply.github.com>
…review)

The v2 compatibility path now applies only when payload.spec.rolloutState
is omitted. A present null or other non-string value is not treated as
live authority; GuardPolicyDocument.from_mapping rejects those the same
way. Regression tests cover signed v2 bundles with null and non-string
rollout states.

Signed-off-by: Michael Kantor <6068672+kantorcodes@users.noreply.github.com>
… (PR #2948 review)

Drive sync_receipts with an inactive (draft/pending_approval/null) v2
bundle planted in the cache while a live enforcing bundle is retained:
the cached bundle is rejected, never becomes effective, and last-good
authority remains current.

Signed-off-by: Michael Kantor <6068672+kantorcodes@users.noreply.github.com>
…tivation evidence (HGP-136-152)

- generic review compiles as review, ignore is inert, device selectors
  rejected pre-publication (HGP-136)
- runtime posture reports the real canonical lane incl. missing
  protected authority/capability (HGP-137)
- generic v2 acks are revision/device-bound only after the lane
  applies; unverified otherwise; no fabricated extension proof
  (HGP-138/139)
- receipt upload success separated from policy validation/application
  with machine-readable rejection + retained last-good (HGP-140)
- memory writes own memory rows in one transaction; bundle replace
  scoped to bundle-owned rows; both authority sets survive alternation
  (HGP-141/142)
- signed memory targets project exactly or are refused; no sibling
  scope broadening (HGP-143)
- one injected UTC clock for v1/v2 envelope and key validity;
  future-dated v2 rejected with stable code, last-good retained
  (HGP-144/145)
- offline lifetime states, revocation without resurrection, workspace
  isolation, first-install trust, same-version substitution protection,
  empty-vs-missing publication distinction, and atomic concurrent
  delivery proven with regression suites (HGP-146-152)

Signed-off-by: Michael Kantor <6068672+kantorcodes@users.noreply.github.com>
…2948 review)

draft/pending_approval fail the enforceability gate as
inactive_rollout_state; present null fails document validation earlier
as invalid_policy_document.

Signed-off-by: Michael Kantor <6068672+kantorcodes@users.noreply.github.com>
…n' into hgp/batch-03-policy-source-ownership

# Conflicts:
#	src/codex_plugin_scanner/guard/policy_bundle_parser.py
…n' into hgp/batch-03-policy-source-ownership
Signed-off-by: Michael Kantor <6068672+kantorcodes@users.noreply.github.com>
…e-accurate sync outcomes

Qodo findings on #2949: generic acks no longer fabricate managed
delivery/extension proofs; signed memory targets accept the portal 0..50
cardinality and project into real matcher fields; runtime posture threads
contract/capability state so lane, fallback-vs-applied, retained-vs-
no-authority, and rollout percentage are reported accurately; applied
acks are never overwritten when rollout disables; duplicate
advisories_stored key removed.

Signed-off-by: Michael Kantor <6068672+kantorcodes@users.noreply.github.com>
…ship (HGP-191-194)

- Two-device approved policy adoption against one stub cloud
- Offline reconnect applies newest revision only
- Review-to-continuation without a persistent grant
- Alternating policy/memory durability: bundle apply replaces only
  bundle-owned remote sources; memory apply replaces only
  cloud-signed-memory rows (RF-03)

Signed-off-by: Michael Kantor <6068672+kantorcodes@users.noreply.github.com>
…utcomes (HGP-195/196)

- Release evidence collector fails on missing/silently-deselected
  required release tests; the one CI deselect is named in the report
- Negative outcomes (draft, wrong-workspace, stale, unavailable-runtime,
  immutable-block) are required fail-closed evidence, never passed:true
- Generic v2 draft/pending_approval/simulated rollout states are not
  live authority (presence-aware, matching #2948)
- Operator docs replace Phase 0 gap notes with verified
  create/approve/sync/verify/recover guidance; semantics.md names
  in-review #2948/#2949/#2959

Signed-off-by: Michael Kantor <6068672+kantorcodes@users.noreply.github.com>
…readiness, durable review state (HGP-153-172)

- Activation failures classified (JSON/storage/transport) with
  idempotent retry and no false apply claims; desired/durable/resident
  visibility stages
- Scope-specific effective-authority explanation; managed/immutable
  floors cannot be weakened; generic-matchers.v1 capability published
- Bounded compile/parse error payloads; export/import roundtrips retain
  meaning; deterministic imports idempotent; device selectors match
  installation identity only
- Headless sync after connect/restart; bounded worker intervals; CLI
  readiness requires both workers; one status projection for CLI and
  settings; enable/disable lifecycle convergence
- Capability expiry explained; OAuth refresh bindings; held/quarantined
  events identity-bound; oldest-first outbox batching; partial-ack
  repair; durable SQLite/process recovery

Signed-off-by: Michael Kantor <6068672+kantorcodes@users.noreply.github.com>
Keep independently observed policy revisions distinct and retain numeric failure status for troubleshooting. Verify completion evidence and public policy guidance.

Decision-Diff-Framed-SHA256: 05069f050147a373b0de8092605f7bda8d45979d0362f5d7d7634fd2b08499d7
Keep policy source consent and exact selectors bound through review, preserve enrollment outcomes, and retain bounded verification diagnostics.

Decision-Diff-Framed-SHA256: 18e11987745548f4705c3fe367bdf98df1661e11861140089ffd947b32155fe6
Decision-Diff-Framed-SHA256: 18e11987745548f4705c3fe367bdf98df1661e11861140089ffd947b32155fe6
Decision-Diff-Framed-SHA256: 18e11987745548f4705c3fe367bdf98df1661e11861140089ffd947b32155fe6
Decision-Diff-Framed-SHA256: 18e11987745548f4705c3fe367bdf98df1661e11861140089ffd947b32155fe6
Decision-Diff-Framed-SHA256: 18e11987745548f4705c3fe367bdf98df1661e11861140089ffd947b32155fe6
Decision-Diff-Framed-SHA256: 18e11987745548f4705c3fe367bdf98df1661e11861140089ffd947b32155fe6
Decision-Diff-Framed-SHA256: 18e11987745548f4705c3fe367bdf98df1661e11861140089ffd947b32155fe6
@coderabbitai

coderabbitai Bot commented Sep 18, 2026

Copy link
Copy Markdown
Contributor

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@gitar-bot

gitar-bot Bot commented Sep 18, 2026 •

Copy link
Copy Markdown
Code Review ✅ No issues found

🟡 Medium risk · Runtime changes gate optional uploads and receipt cursor advancement across sync paths

Optional activity uploads now require current saved preferences and local consent, with every receipt attempt rechecking the selected workspace and redaction floor. Pending rows remain available across pauses, retries, and acknowledgement changes while mandatory policy processing stays separate. Validated across 68 focused functional cases on Python 3.10 and 3.12, including real state transactions, concurrent updates, and 51-row receipt continuity. No issues found.

Review coverage

📋 Rules No rules evaluated

🧪 Functional validation Not enabled · Set up

Options ✅ Auto-apply

✅ Auto-apply is on → Gitar will commit updates to this branch.
Display: compact → Counting what did not apply, without listing it.

Comment with these commands to change the behavior for this request:

✅ Auto-apply Compact
gitar auto-apply:off         
gitar display:verbose         

Was this helpful? React with 👍 / 👎 | Powered by Gitar — free for open source

@kantorcodes
kantorcodes force-pushed the hgp/batch-11b-release-gating branch from 074c0f6 to a53d471 Compare September 18, 2026 19:11
@zerocodefast zerocodefast added the gitar-managed Enables Gitar automatic repair for a pull request label Sep 21, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

gitar-managed Enables Gitar automatic repair for a pull request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants