From e6e11c41b21d2bbd4decb09f898015967e3543f9 Mon Sep 17 00:00:00 2001 From: Amruth Pillai Date: Sat, 5 Sep 2026 23:51:57 +0200 Subject: [PATCH] docs: track review fixes and re-review --- docs/execution/approved-issue-plans-ledger.md | 10 +++++--- docs/execution/briefs/fix-review-plan-02.md | 25 +++++++++++++++++++ 2 files changed, 31 insertions(+), 4 deletions(-) create mode 100644 docs/execution/briefs/fix-review-plan-02.md diff --git a/docs/execution/approved-issue-plans-ledger.md b/docs/execution/approved-issue-plans-ledger.md index c6655281c..453b0eae9 100644 --- a/docs/execution/approved-issue-plans-ledger.md +++ b/docs/execution/approved-issue-plans-ledger.md @@ -34,12 +34,12 @@ state changes are outside scope. | Unit | Issues | Status / current validity | Owner | Worktree / branch | Base → head | Dependencies | Evidence | Tests | PR | Next action | Blockers | | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | | 01 account login/recovery | #3166, #3164, #3078, #3046, #2897, #2837 | blocked | audit `task_855fbee0a803` | `codex-audit-backend-01-06` | `7a98f6662` → no source change | none | zero drift; live issues remain split; #3046/#3078 have merged #3095 candidate only | auth 42, email 6, focused/full API/server suites and affected typechecks/boundaries passed in audit | — | select exact auth/mail/API boundary only after current sanitized trace | current cloud digest, provider/account method, request/status trace, controlled mailbox | -| 02 hosted v4 recovery | #3181, #2760 | reviewing | implementation `task_bae016c4d1f2`; review `task_46be9a1a4d82` / `ctx_e9f651d38a65` | `codex/issue-3181-recovery-procedure` | `7a98f6662` → `3f53deca8` | #2760 identity branch depends on 01 evidence | pure comparator and safeguards committed locally; partial only; real recovery and #2760 cause unproved | implementer reports focused tests, full 19-task suite, typechecks, boundaries, Biome/Markdown/diff gates green; independent rerun active | — | resolve independent findings, fresh verify, publish unmerged PR | actual recovery needs verified owner, available snapshot, reviewed legacy format, authorized private delivery | +| 02 hosted v4 recovery | #3181, #2760 | implementing | review fix `task_5fe67c42d856` / `ctx_28ed501db631` | `codex/issue-3181-recovery-procedure` | `7a98f6662` → `3f53deca8` + pending | #2760 identity branch depends on 01 evidence | reviewer reproduced false no-op after lossy schema fallback, contradictory target state, and overstated raw-v4 wording | implementation gates green; independent direct probes prove three findings | — | fix with new RED/GREEN tests, re-review, then publish | real recovery still needs verified owner, snapshot, mapping, private delivery | | 03 MCP registration | #3398, #3153 | no-change | audit `task_855fbee0a803` | `codex-audit-backend-01-06` | `7a98f6662` → no source change | coordinate DB/startup with 05 | merged #3421 (`fe9b59e`) present on main; current schema/startup/auth contracts match plan | #3421 hosted checks successful; audit auth/server/API/DB tests, typechecks, boundaries passed | #3421 merged before run | deployment verification only | deployed digest/log correlation and exact Codex/Claude DCR/consent/PKCE/MCP retest unavailable | | 04 AI provider compatibility | #2732, #2766, #2723, #2708 | blocked | audit `task_855fbee0a803` | `codex-audit-backend-01-06` | `7a98f6662` → no source change | serialize edits to AI service | zero drift; historical #2708 Responses path and #2766 structured Test path absent; remaining tuples differ | focused API 96 and full API suites/typecheck/boundaries passed in audit | — | select wire/state/import/base-path unit only after exact current tuple fails | provider/model/base URL/path/version/action/error tuple and allowed endpoint unavailable | | 05 AI provider migrations | #3152 | blocked | audit `task_855fbee0a803` | `codex-audit-backend-01-06` | `7a98f6662` → no source change | coordinate DB/startup with 03 | zero drift; table schema, migration, startup ordering, Docker copy path coherent; `42P01` historical cause unresolved | audit API/server/DB tests, typechecks, boundaries passed; no real PostgreSQL migration fixture | — | choose config/packaging/startup/migration repair only after disposable reproduction | affected image layout/digest, working directory, DB schema/search path/journal, fresh+upgrade DB fixture | | 06 image storage delivery | #2684, #2778 | blocked | audit `task_855fbee0a803` | `codex-audit-backend-01-06` | `7a98f6662` → no source change | coordinate 12/15/25 renderer/image fixtures | #2684 ACL cause fixed by merged #3432 (`35cecf9`); #2778 Browserless path obsolete; current topology unproved | #3432 hosted checks successful; audit storage/upload/PDF tests, typechecks, boundaries passed | #3432 merged before run | deployment retest plus shared real-encoding/backend/render fixture before repair | deployed digest; disposable S3/Garage/SeaweedFS/MinIO/proxy and browser/server raster matrix unavailable | -| 07 AIO deployment | #2722 | implementing | review fix `task_8ea6cfc76ef4` / `ctx_0184e1101bca` | `codex/issue-2722-postgres-docs` | `7a98f6662` → `e37b73566` + pending | none | independent review found app-update recipe pulled all services while `postgres:latest` can cross major versions; finding verified | initial checks green; reviewer independently reran Compose/Markdown/link/diff gates | — | restrict update recipe to app service, re-review, fresh verify, publish unmerged PR without closing keyword | no AIO implementation; optional Unraid host smoke unavailable | +| 07 AIO deployment | #2722 | reviewing | re-review `task_90a9a6b63782` / `ctx_2f1def9119d6` | `codex/issue-2722-postgres-docs` | `7a98f6662` → `b61ca1609` | none | fix scopes update commands to app service and requires separate major-pinned PostgreSQL procedure with verified backup restore | focused Compose/Markdown/link/diff gates green; independent full-diff re-review active | — | publish immediately if re-review and fresh verification pass | no AIO implementation; optional Unraid host smoke unavailable | | 08 root public resume | #2669 | plan amendment required before implementation | audit `task_9f27829ca50f` | planned `codex/issue-2669-root-resume` | `7a98f6662` → — | none | current password redirect rejects `/`; public view is slug-hook-bound; SSR canonical cannot import server env; expanded auth/canonical contract identified | audit focused API/web suites, typechecks, boundaries passed | — | amend ownership for identity-vs-return auth flow and server-derived canonical root, then dispatch coherent feature | engineering scope correction; feature remains narrower than arbitrary domain/TLS registry | | 09 external version backup | #2705 | reviewing | implementation `task_e450ea143bfa`; review `task_129b49e32bc7` / `ctx_68b13c76cc72` | `codex/issue-2705-git-backup-docs` | `7a98f6662` → `d4ef67113` | none | two docs committed locally with export-shape distinctions, plain local Git workflow, privacy/image limits, import-as-new recovery | implementer reports API/import/schema/web tests, synthetic Git round trip, Markdown/diff/scope gates green; DB integration/E2E skipped; independent rerun active | — | resolve independent findings, fresh verify, publish unmerged PR | no automatic sync, remote, or whole-account restore | | 10 legacy link routing | #2836 | pending implementation after brief correction | audit `task_9f27829ca50f` | planned `codex/issue-2836-retired-slug-notices` | `7a98f6662` → — | none | prospective same-username slug-attempt notice remains coherent; exact DB/API/UI/E2E owner set verified | audit focused API/web suites, DB/API/web typechecks, boundaries passed | — | correct final E2E target to `public-sharing.spec.ts`, then implement migration/API/owner UI atomically | historical cause absent; no redirects/emails/recovery; prospective partial coverage only | @@ -81,9 +81,11 @@ state changes are outside scope. | Plan 09 implementation | `task_e450ea143bfa` / `ctx_3b575cf1d5c7` | `codex/issue-2705-git-backup-docs` | implementation complete; worker released | commit `d4ef67113`; two-file docs change and synthetic local-Git validation | | Plan 11 implementation | `task_58d76423d364` / not dispatched | planned `codex/issue-3010-jsearch-docs` | waits on plans 07–11 audit | three-file docs change, source/test validation, commit, independent review | | Plan 02 synthetic recovery | `task_bae016c4d1f2` / `ctx_303f5d1f1031` | `codex/issue-3181-recovery-procedure` | implementation complete; worker released | commit `3f53deca8`; pure comparator, safeguards docs, TDD evidence | -| Plan 02 independent review | `task_46be9a1a4d82` / `ctx_e9f651d38a65` | same Plan 02 worktree | reviewing | findings-first review and independent verification | +| Plan 02 independent review | `task_46be9a1a4d82` / `ctx_e9f651d38a65` | same Plan 02 worktree | complete; changes required | false no-op, target-state contradiction, v4 wording overclaim | | Plan 07 independent review | `task_b29de2cd974c` / `ctx_46d7f32205a1` | same Plan 07 worktree | complete; changes required | high: all-services pull could cross PostgreSQL major version | -| Plan 07 review fix | `task_8ea6cfc76ef4` / `ctx_0184e1101bca` | same Plan 07 worktree | implementing | app-only update recipe and separately pinned database upgrade path | +| Plan 07 review fix | `task_8ea6cfc76ef4` / `ctx_0184e1101bca` | same Plan 07 worktree | complete | commit `b61ca1609`; app-only update recipe and separately pinned database upgrade path | +| Plan 02 review fix | `task_5fe67c42d856` / `ctx_28ed501db631` | same Plan 02 worktree | implementing | strict validation, target invariant, exact v5-only documentation | +| Plan 07 re-review | `task_90a9a6b63782` / `ctx_2f1def9119d6` | same Plan 07 worktree | reviewing | full-diff verification after update-safety fix | | Plan 09 independent review | `task_129b49e32bc7` / `ctx_68b13c76cc72` | same Plan 09 worktree | reviewing | format/workflow/privacy review and independent validation | ## Existing PR and residual accounting diff --git a/docs/execution/briefs/fix-review-plan-02.md b/docs/execution/briefs/fix-review-plan-02.md new file mode 100644 index 000000000..a745188b2 --- /dev/null +++ b/docs/execution/briefs/fix-review-plan-02.md @@ -0,0 +1,25 @@ +# Address independent review: plan 02 + +Read `.orchestration/plan-02-review.md`, pinned approved plan 02, current `AGENTS.md`, RTK, and applicable +receiving-code-review/TDD/documentation skills. Verify each finding with direct probes before editing. Three findings are +provisionally accepted: lossy schema fallback can yield false no-op, target ID/data states can contradict, and migration docs +overstate raw v4 JSON support. + +Use strict TDD. Add failing regressions first, then smallest conservative fixes within original four-file scope: + +- A source with schema-invalid value that current Zod `.catch` would normalize to target must never return `no-op`. Validate + without accepting lossy coercion/default mutation, or hash validated raw canonical input while explicitly detecting and + blocking lossy schema changes. Prefer safe false-block/export over false no-op. Cover source and target variants. +- Enforce target presence invariant: target data and target resume ID are either both absent or both present. Encode a + discriminated input contract where practical and keep runtime validation for untyped callers. Both mismatch directions + return deterministic blocked manifest with named reason; no contradictory target hash/ID. +- Clarify migration guide: only JSON text already conforming exactly to current v5 resume-data schema is accepted; raw v4 + exports are unsupported; comparator performs no conversion; historical converter review remains separate prerequisite. +- Add sentence that hashes prove content equality only, never ownership/source authenticity/recipient identity. + +Preserve pure/non-networked/non-writing behavior and deterministic manifest. Do not access private data, add DB/filesystem +writes, implement legacy conversion, widen scope, or rewrite prior reports. Run focused RED/GREEN tests, tooling typecheck, +relevant API/auth checks, boundaries, narrow Biome/Markdown, diff and four-file scope gates. Add normal follow-up commit. + +Write `.orchestration/plan-02-review-fix.md` with probes, RED/GREEN, exact commit/files, commands/results, skipped gates, and +remaining risks. Do not push/open PR/merge/mutate issues/spawn subagents. Final response at most ten lines.