mirror of
https://github.com/AmruthPillai/Reactive-Resume.git
synced 2026-10-03 18:23:47 +10:00
docs: queue plan 02 final parser review
This commit is contained in:
@@ -34,7 +34,7 @@ state changes are outside scope.
|
||||
| Unit | Issues | Status / current validity | Owner | Worktree / branch | Base → head | Dependencies | Evidence | Tests | PR | Next action | Blockers |
|
||||
| --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- |
|
||||
| 01 account login/recovery | #3166, #3164, #3078, #3046, #2897, #2837 | blocked | audit `task_855fbee0a803` | `codex-audit-backend-01-06` | `7a98f6662` → no source change | none | zero drift; live issues remain split; #3046/#3078 have merged #3095 candidate only | auth 42, email 6, focused/full API/server suites and affected typechecks/boundaries passed in audit | — | select exact auth/mail/API boundary only after current sanitized trace | current cloud digest, provider/account method, request/status trace, controlled mailbox |
|
||||
| 02 hosted v4 recovery | #3181, #2760 | review hardening active | fix `task_5b56f07b5a2c` / `ctx_e7c63529b719` | `codex/issue-3181-recovery-procedure` | `7a98f6662` → `00855fa16` | #2760 identity branch depends on 01 evidence | final review found duplicate JSON members can override failed safety evidence and whitespace/control-only IDs pass validation | 36 tooling, 54 API, 21 auth tests; typechecks/boundaries/Biome/Markdown/import/diff green before findings | — | reject duplicates at every depth and unsafe IDs via TDD, then independently rereview | real recovery still needs verified owner, snapshot, mapping, private delivery |
|
||||
| 02 hosted v4 recovery | #3181, #2760 | final independent rereview | review `task_a2b0562df7aa` / `ctx_bc5056c8978c` | `codex/issue-3181-recovery-procedure` | `7a98f6662` → `4125074f9` | #2760 identity branch depends on 01 evidence | lexical duplicate-member rejection covers every depth and serialized nested resumes; safe ID contract rejects blank/control values | 59 tooling, 54 API, 21 auth tests; adversarial/typecheck/boundaries/Biome/Markdown/import/diff green; rereview active | — | publish only after clean exact-head rereview and fresh coordinator verification | real recovery still needs verified owner, snapshot, mapping, private delivery |
|
||||
| 03 MCP registration | #3398, #3153 | no-change | audit `task_855fbee0a803` | `codex-audit-backend-01-06` | `7a98f6662` → no source change | coordinate DB/startup with 05 | merged #3421 (`fe9b59e`) present on main; current schema/startup/auth contracts match plan | #3421 hosted checks successful; audit auth/server/API/DB tests, typechecks, boundaries passed | #3421 merged before run | deployment verification only | deployed digest/log correlation and exact Codex/Claude DCR/consent/PKCE/MCP retest unavailable |
|
||||
| 04 AI provider compatibility | #2732, #2766, #2723, #2708 | blocked | audit `task_855fbee0a803` | `codex-audit-backend-01-06` | `7a98f6662` → no source change | serialize edits to AI service | zero drift; historical #2708 Responses path and #2766 structured Test path absent; remaining tuples differ | focused API 96 and full API suites/typecheck/boundaries passed in audit | — | select wire/state/import/base-path unit only after exact current tuple fails | provider/model/base URL/path/version/action/error tuple and allowed endpoint unavailable |
|
||||
| 05 AI provider migrations | #3152 | blocked | audit `task_855fbee0a803` | `codex-audit-backend-01-06` | `7a98f6662` → no source change | coordinate DB/startup with 03 | zero drift; table schema, migration, startup ordering, Docker copy path coherent; `42P01` historical cause unresolved | audit API/server/DB tests, typechecks, boundaries passed; no real PostgreSQL migration fixture | — | choose config/packaging/startup/migration repair only after disposable reproduction | affected image layout/digest, working directory, DB schema/search path/journal, fresh+upgrade DB fixture |
|
||||
@@ -93,7 +93,8 @@ state changes are outside scope.
|
||||
| Plan 02 final re-review | `task_ae1f7e591826` / `ctx_475ef901639c` | same Plan 02 worktree | complete; changes required; worker released | P1 truthy gate bypass plus executable/non-JSON object input identity |
|
||||
| Plan 02 contract hardening | `task_baf33a609db0` / `ctx_48534ddcf89f` | same Plan 02 worktree | complete; worker released | commit `00855fa16`; serialized request-only API, strict envelope, 36-case adversarial coverage |
|
||||
| Plan 02 final independent review | `task_5b02aa026038` / `ctx_d16058d89c7c` | same Plan 02 worktree | complete; changes required; worker released | P1 duplicate-member safety bypass; P2 whitespace/control-only manifest identifiers |
|
||||
| Plan 02 hardening round 4 | `task_5b56f07b5a2c` / `ctx_e7c63529b719` | same Plan 02 worktree | implementing | reject duplicate JSON members at every depth and unsafe IDs with adversarial regressions |
|
||||
| Plan 02 hardening round 4 | `task_5b56f07b5a2c` / `ctx_e7c63529b719` | same Plan 02 worktree | complete; worker released | commit `4125074f9`; 59 comparator tests plus duplicate-member and unsafe-ID adversarial gates green |
|
||||
| Plan 02 independent review round 5 | `task_a2b0562df7aa` / `ctx_bc5056c8978c` | same Plan 02 worktree | reviewing | full diff, lexical scanner correctness, duplicate/ID fail-closed behavior, proportionality |
|
||||
| Plan 09 re-review | `task_1bd82b008a77` / `ctx_ca2a0176b52f` | same Plan 09 worktree | complete; no findings; worker released | full diff and both factual corrections verified before PR #3458 |
|
||||
| Plan 09 hosted review follow-up | `task_a44e374822b4` / `ctx_89e6769df19d` | same Plan 09 worktree | complete; changes required; worker released | selected revision prints correctly but no importable file is created |
|
||||
| Plan 09 hosted review fix round 2 | `task_8605c30ca032` / `ctx_2e0aa7be1312` | same Plan 09 worktree | complete; worker released | commit `9dd218ba1`; non-destructive recovered-file command plus synthetic proof |
|
||||
|
||||
@@ -0,0 +1,25 @@
|
||||
# Independent review: Plan 02 round 5
|
||||
|
||||
Review only. Worktree:
|
||||
`/Users/amruth/orca/workspaces/reactive-resume/issue-3181-recovery-procedure`.
|
||||
Exact target head: `4125074f99ad91c161d8a9437259465d4b7f933b`.
|
||||
No PR exists. Do not edit tracked files, commit, push, publish, mutate issues, or perform private recovery.
|
||||
|
||||
Read current instructions, pinned approved Plan 02, full `origin/main...HEAD` diff, every implementation/fix/review report,
|
||||
and live issues #3181/#2760 plus branch/PR state. Refresh `origin/main` and verify target head before review.
|
||||
|
||||
Review standards and spec. Independently adversarially verify:
|
||||
|
||||
- duplicate JSON member rejection at every depth, both orders, escaped-equivalent names, arrays/objects, and supported
|
||||
serialized source/target resume strings before gates, schema comparison, or hashing;
|
||||
- lexical scanner correctness for valid JSON escapes, primitives, nested structures, malformed input, deep input, and no
|
||||
executable-object access;
|
||||
- all safety flags remain literal booleans and fail closed;
|
||||
- all three manifest IDs reject blank and Unicode control-containing strings while preserving accepted IDs verbatim;
|
||||
- fresh invalid manifests, deterministic stable hashes, exact-envelope contract, docs, and four-file scope;
|
||||
- proportionality and maintainability of complete implementation.
|
||||
|
||||
Run 59 comparator tests, independent probes, 54 API tests, 21 auth tests, affected typechecks, boundaries, narrow
|
||||
Biome/Markdown, import/diff/scope gates. Report findings first with severity and exact anchors. Write
|
||||
`.orchestration/plan-02-review-round5.md`; send worker_done with publication verdict. No subagents.
|
||||
|
||||
Reference in New Issue
Block a user