feat(zotero): emit reversible write execution receipts - #15
Conversation
…te-plan' into autoresearch/zotero-write-execution-receipt # Conflicts: # docs/product-technical-gap-baseline.md
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
@codex review |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
@codex review |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
@coderabbitai review |
|
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 585f383bfc
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…rch/zotero-write-execution-receipt
|
@coderabbitai review |
|
@codex review |
❌ Action failedReview failed.
|
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
@codex review |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
Non-force two-parent restack onto current reviewed write-plan parent. Preserve the receipt/execution repairs while inheriting the repaired Foundation CI contract through the dependency chain. Signed-off-by: Seongho Bae <me@seonghobae.me>
|
Current-stack correction (2026-09-05): exact base |
Signed-off-by: Seongho Bae <me@seonghobae.me>
…sion Preserve both parent deltas. Keep the executable plan opaque, retain the required private proposal binding, and adapt test receipt inputs without issuing authority.
Retain all scenarios while correcting unsafe prior assertions: matching before or after metadata and unrelated newer mutations cannot prove the submitted request ended or authorize rollback.
…ority Post-failure reads are observations only. Preserve exact submitted requests and prior verified operations; never infer causal completion, termination or inverse authority from matching metadata.
Current source-scope and causal-uncertainty repair — 2026-09-06
Exact head
42ddd81adf8d994f67a30f0c6b8383d637073c72normally preserves prior executor45e9c4933eae4482b0361473e9f083967182e6ccand parenteb8eaa4ecb657b5d2a757d83e5041bbc8aea7be5. Keep OPEN Draft behind the same prerequisite stack.Receipt RED
e8b4c06failed three binding tests;b91ad9fretains required proposal/source identity in all four outcomes. Independent review also found post-failure reads falsely implying completion, termination or rollback authority. RED646a10ccorrects those unsafe assertions while retaining the scenarios. Root repairc09d101always preserves uncertainty after failed/invalid responses, exact submitted request and optional observation; only earlier directly verified writes remain applied/reversible.e169630checks full request equality and absent fields. Matching before/after values never authorize retry or inversion. Receipts remain audit data, not executable plans.Final local verification:109 workspace tests/19 suites including3doctests; strict all-target Clippy, warnings-denied rustdoc,fmt,CI-contract,diff and unchangedcoverage gate.185/185functions,1770/1770normalizedregions,320/320normalizedbranches. Raw LLVM1998/2050lines,2934/3014regions,280/320branches is NOT100%. Independent static review found no actionable owner defect; not GitHub approval.
No actual classification, live Zotero mutation, protected merge, release or current-head hosted GREEN is claimed. Later execution/recovery/full-text owners still require normal adoption; an empty inverse list cannot make an unknown original request safe. PRD/TRD/ADR0007/DDD/UML/Gap/CHANGELOG capture the repair. Prior body below is historical and its post-read inference statements are superseded.
Latest bounded-read integration checkpoint
Exact head
45e9c4933eae4482b0361473e9f083967182e6ccnormally merges parentb41217b1d38ec8d30e365aac04e68684c09dca7fwhile retaining previous childa07dd9a433c7211c2f95065031622d51dadf2cb6. Base remainsautoresearch/zotero-reviewed-write-plan. The #9 whole-snapshot elapsed-time repair and its RED/GREEN evidence are inherited without reverse-merging later features or discarding predecessor deltas.This exact head passes Rust 1.98.0 locked workspace tests=87 suites=19, including doctests and excluding filtered subprocess duplicates, strict all-target Clippy, warnings-denied rustdoc, formatting, the existing CI contract and diff checks. Log:
/private/tmp/conceptweave-deadline-pr15-20260906.log. Intermediate coverage is not inferred from owner/final-endpoint coverage. No new dependency, actual paper read/decision, Zotero mutation or authority issuer was used.Draft and protected prerequisites remain. Local tests are not hosted GREEN, independent approval, merged/released source or evidence for another head. Earlier checkpoints below are retained history, not the current head.
Verified local approval-order repair — 2026-09-06 checkpoint
Exact head:
autoresearch/zotero-write-execution-receipt@a07dd9a433c7211c2f95065031622d51dadf2cb6. Exact base:autoresearch/zotero-reviewed-write-plan@8a684882005085d8b3cb47812e185975084e0475.Original planner owner #13 preserves regression
505e111c993d8269e5b7b9e17a25a5ce20f8606eand repair8a684882005085d8b3cb47812e185975084e0475. Every existing local request/mode/item/metadata check finishes before the external approval verifier. Invalid requests invoke it zero times; valid complete requests invoke it exactly once. Local validation errors intentionally precede approval denial. Deterministic operations and complete before/after/rollback metadata are unchanged.This exact head passed locked Rust 1.98.0 workspace tests (84 tests / 19 unfiltered suites, doctests included), strict all-target Clippy, formatting, warnings-denied rustdoc, CI contract and diff checks before normal push. Normal parent integration retains both the prior child and verified parent as ancestors. Coverage from another stack head is not attributed to this head.
Keep Draft behind the existing prerequisite stack. This is local verification, not hosted current-head GREEN, independent approval, protected merge or release. No later full-text feature was reverse-merged into an earlier owner. Full-text-aware write admission, authentic decisions and independent authority remain separate gaps; no real Zotero/model request, label, approval or write was performed for this repair.
Earlier coordinates and status claims below are historical.
Prior PR description, retained without discarding evidence
Current source-integrity note — 2026-09-05
autoresearch/zotero-write-execution-receipt@4ae166c501c83f6508011bcd31526815b69dd391.autoresearch/zotero-reviewed-write-plan@e35f42e2a552ba8da26250bf084462a36d1c986d.e7d4e59f1b55b5954c5f8436527bc96e7ef2fb13through ordinary merge ancestry. The source-snapshot digest binds complete captured raw provider JSON and the actual typed classifier inputs; source evidence and derived proposals retain separate identities.GoldenSetApproval.proposal_digestis required and binds the complete proposal records used for evaluation. The current proposal digest is checked before the caller-owned governance verifier. Do not backfill old receipts: regenerate evidence and obtain a new approval bound to the reviewed evidence.Earlier heads, runtime snapshots, campaign counts, and verification statements below are historical notes, not current acceptance evidence.
Historical PR notes — original text retained
Outcome
Provide the deterministic Zotero write-execution receipt boundary without claiming a live mutation. Complete reviewed-plan preflight precedes the first write; identity and full collection/tag state are verified around adapter calls; secret-free applied/failed/untouched evidence and reverse rollback operations are retained.
Current exact stack — 2026-09-05
821b04c640e798d851a21d893f9aa3d7d157470c;64cb10f817dbcd26f488f97dc63968fc7bf00af5;Repaired receipt invariants
ClassificationWriteReceiptis bound to review, authority, server, Zotero version, library version, rule revision and snapshot digest across DryRun, Applied, PreflightFailure and PartialFailure. DryRun performs no adapter calls and enumerates every plan operation as not attempted. Confirmed unexpected mutation retains inverse evidence only when server/item identity remains proven; identity drift does not fabricate rollback evidence. Execution-critical plan fields remain private with read-only accessors.Credentials remain outside serializable plans/receipts. Writes replace only complete reviewed collection/tag state for top-level items; complete preflight precedes mutation, later failure stops subsequent writes, and rollback operations remain reverse ordered.
Merge gate
Keep Draft behind #13 and the complete Foundation/Zotero prerequisite stack. Require one unchanged exact head with terminal Product/security/SAST/dependency/review evidence before integration. No self-approval, admin bypass, force-push, destructive rebase, predecessor-evidence transfer, or live mutation claim.
Refs #8.