Skip to content

L04-05: route approved execution through one cancellation-safe mutation gateway (#37) - #215

Merged
mberrys merged 4 commits into
l04-04-approval-bindingfrom
l04-05-execution-gateway
Oct 5, 2026
Merged

mberrys merged 4 commits into
l04-04-approval-bindingfrom
l04-05-execution-gateway

Conversation

@mberrys

@mberrys mberrys commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Summary

L04-05 (#37), slice 5 of the L04 Governed Operation Engine stack (refs #5). Every governed mutation now goes through one Core entry point, pdf::executeGovernedMutation(), which returns a terminal PDFGovernedMutationReceipt: validate approval + authorization (#36) -> refuse an already-terminal execution -> cancel check -> stage the reviewed bytes beside the destination -> revalidate + sign off against the staged bytes -> beforeCommit seam + cancel check -> atomic commit -> read-back -> receipt. Every refusal, failure, or cancel before the commit leaves the destination untouched; the four surfaces that previously wrote the destination first and finalized afterwards (PdfTool repair, PdfTool action-list, PageMaster, the Editor worker) now stop before partial publication.

Stack position

Slice 5 of 8. Base: l04-04-approval-binding (#214). Children stack on this branch; land bottom-up.

Per-criterion: already satisfied vs built here

Acceptance criterion State Proof
One plan produces one published candidate or a terminal nonpublication receipt built here PDFGovernedMutationReceipt (loop.governed-mutation-receipt): status published/refused/failed/cancelled, reason code, plan/source/candidate identity, destination, published_sha256 (empty for nonpublication), revalidation/sign-off only when published
No adapter owns alternate mutation built here all five call sites routed; P7 grep proof recorded in the report (remaining writers are staging, in-memory buffers, and report/manifest/profile I/O)
Failure: unauthorized / stale / already-terminal / malformed stop before partial publication built here 8 gateway fault-injection cases (unauthorized policy, stale plan/source, already-terminal replay, malformed request, cancel at beforeCommit, staging failure, commit conflict, post-commit failure semantics) + per-surface refusal/cancel cases in the PdfTool contract, PageMaster export, and Editor host suites
Editor "Approve and run" cannot run an unreviewed plan built here confirmActionListPlan() now refuses unless fixExecutionArmed() (the operator reviewed the exact plan digest)

Required proof

  • python scripts/agent/check-change.py --base 2d18b060 --head e16a8cd4 --head-branch l04-05-execution-gateway --build-dir <loop-build-l04> -> status: pass, 109/109 checks (LoopLibCore/PdfTool/LoopLibInteraction/LoopEditor/loop-pdf-worker builds, mapped suites, clang-tidy, format, changelog, architecture contracts).
  • Provenance: the proof was recorded at the pre-rebase head c575f67e. The stack rebase left this slice's own diff unchanged (patch-id verified) and the only later edit is a documentation-only fragment correction, so the proof carries for the code; CI re-runs the mapped lanes on the head above.
  • Focused: UnitTestsGovernedExecution / UnitTestsPdfToolContract / UnitTestsPageMasterExport / UnitTestsEditorHost / UnitTestsProductOperatorLoop / UnitTestsActionList -> 6/6.
  • Guard-vs-RED: disabling the cancel checks makes the cancel case exit 1; disabling the replay scan makes the replay case exit 1 (both reverted).
  • Architecture: check-architecture.py, test_architecture_contracts.py, test_check_governed_parity.py -> green.
  • Pre-existing flake UnitTestsPdfWorkerIsolation supervisorFaults(cpu) is a razor-margin race against the 135s client timeout #211 can redden a mapped run; CI agent-fast is authoritative.

Notes

  • Closes #37.
  • Out of scope, stated: Editor Save As / document I/O stays out of the gateway (it is not a correction mutation); the legacy ad-hoc commands (addbleed / rgbtocmyk / redact / ...) remain deferred as recorded in L04-01 — Reconcile registry and canonical plan contract #33.
  • Two request switches exist to preserve PageMaster's existing semantics exactly: requireRevalidation (an unsigned export with no preflight profile) and publishOnRevalidationFailure (forcePreflight, recorded as revalidation-forced). They are explicit, not implicit fallbacks.
  • PageMaster and the Editor worker still have no history store in scope, so their gateway calls leave chain append and revocation resolution to L04-07 — Converge provenance and sign-off #39 (recorded in docs).
  • Breaking-change: no.

View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

pdf::executeGovernedMutation() validates the approval identity and the
authorization context, refuses an already-terminal replay, checks
cancellation, stages the reviewed bytes beside the destination, finalizes
against the staged bytes (reopen + revalidate + sign-off), runs the
beforeCommit seam and a second cancel check, commits atomically through
PDFSafeFileWriter, reads back, and returns a terminal
PDFGovernedMutationReceipt (schema loop.governed-mutation-receipt). Any
refusal, failure, or cancel before the commit leaves no destination
artifact; a failure after the commit is terminal failed with the artifact
present. When a history store is supplied the gateway also scans it for
replay and appends the canonical Running/Failed/Accepted chain events.

Adds the gateway fault-injection matrix and the docs/change fragments.
PdfTool repair, PdfTool action-list run|batch, PageMaster exports, and the
Editor Action List worker publish through executeGovernedMutation, so each
surface's refusal/failure/cancel now stops before the destination write.
PageMaster keeps its beforeOutputCommit seam wired to the gateway's
beforeCommit; the Editor worker validates the exact staged bytes it applies
rather than a second serialization. EditorHost::confirmActionListPlan
("Approve and run") now requires the armed review, so an unreviewed plan is
refused.

Adds the per-surface refusal/cancel parity tests.
@mberrys
mberrys force-pushed the l04-05-execution-gateway branch from 2145d5e to e16a8cd Compare October 5, 2026 14:04
@mberrys
mberrys added this pull request to stack #220 October 5, 2026 21:52
@mberrys
mberrys merged commit bef8e06 into l04-02-save-impact-policy Oct 5, 2026
3 of 5 checks passed
@mberrys
mberrys deleted the l04-05-execution-gateway branch October 5, 2026 22:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant