Skip to content

feat(workforce-validation): adopt registry into owner persistence - #248

Draft
seonghobae wants to merge 18 commits into
feat/workforce-validation-registry-boundaryfrom
feat/workforce-validation-owner-persistence
Draft

seonghobae wants to merge 18 commits into
feat/workforce-validation-registry-boundaryfrom
feat/workforce-validation-owner-persistence

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

Live stack truth — 2026-09-21

Issue #247 owns the FR-007 durability increment. Protected architecture assigns the validity-study registry to workforce_validation; parent #235 is the canonical application/service owner, while this Draft child owns forward PostgreSQL adoption and least-privilege durable adapters.

  • Protected truth: develop@eb9757f8649aaad026a9865508d9aad50c1a7a4f
  • Current parent feat(workforce-validation): establish governed validity-study registry boundary #235: exact 202d9d87d6a45529497279b881169aab127727f8, open · Draft · mergeable=true
  • Parent ordinary-forward repairs retained: 01c3da48... neutralizes the lifecycle-governance docstring overclaim; 202d9d87... keeps built-wheel acceptance off the repository checkout after predecessor Foundation exposed untracked build artifacts at the read-only gate
  • Parent exact-head Foundation 35507388584, Security 35507388575, SAST 35507388588, and CodeQL 35507388573 remain non-terminal at the latest fresh read
  • Parent review inventory has no qualifying APPROVED; visible inline threads are resolved
  • This child remains source-untouched at exact d54d44d795444df572efbb301a667d74ac574d58
  • Recorded child base remains old parent snapshot 656a0c41c06bc517b2cf7c554e35a6fb4f8c4f4b; intentionally stale until parent integration
  • Scientific feat(validity): add governed selection-validity analysis handoff #57 remains an independent mutable leaf and is not a source prerequisite for this persistence child

#248 must not copy or prematurely absorb mutable #235/#57 source. #235 integrates normally first; this child then non-force adopts current protected develop, preserves the valid persistence delta, and reacquires exact-head PostgreSQL/quality/security/review evidence. If #57 has normally integrated by then, its protected delta is inherited as ordinary base truth rather than source-copied.

Parent #235 exposes the #407 application-owner families and later owner/provenance/scientific-consistency repairs. #423 rejects material final-weight adjustment codes without governed released owner evidence. #424 requires every admitted governed adjustment to have an exact component binding with contiguous one-based sequence. Durable adapters must preserve those invariants after normal adoption.

Durable adapters must not locally manufacture resolver-issued views/proof results, import/copy runtime seals, invent a generic adjustment receipt family, infer owner-record identity from an evidence digest, persist sparse component bindings, or source-copy mutable parent implementations. They persist and re-resolve canonical owner records and invoke protected application/corroboration contracts after normal adoption. Missing, ambiguous, conflicting, structurally non-canonical, unauthorized, cross-scope, not-yet-released, superseded, unsealed, forged, unresolvable-adjustment or noncontiguous-binding evidence must fail closed.

Predecessor evidence does not transfer to current parent 202d9d87.... Predecessor 03bf5040... reached 1,441 tests, 5,186/5,186 statements, 1,116/1,116 branches and isolated PostgreSQL contracts before failing repository cleanliness because wheel acceptance created untracked build artifacts. 202d9d87... repairs that causally, but its own exact-head hosted verdict is still non-terminal and no qualifying independent approval exists.

Downstream backend/scientific/API order

This persistence child does not own the business lifecycle state machine, scientific design lineage, buyer HTTP transport, or buyer UI.

  1. feat(workforce-validation): establish governed validity-study registry boundary #235 normal protected integration after exact-head terminal evidence and then-live non-bypass review governance.
  2. feat(workforce-validation): adopt registry into owner persistence #248 non-force adopts current protected develop, preserves owner-schema/read-adapter delta, implements durable persistence for the accepted parent owner families and reacquires exact-head evidence.
  3. product(workforce-validation): govern validity-study lifecycle and idempotent registration #426 owns governed/idempotent validity-study registration and lifecycle transitions on protected durable owner truth: versioned state vocabulary/transition policy, legacy-status census/quarantine, optimistic concurrency, replay-safe receipts and append-only history. recorded_from / recorded_to remain bitemporal knowledge-time coordinates and must not be overloaded as lifecycle states.
  4. science(workforce-validation): version validity-study design lineage before validation claims #425 owns versioned scientific study-design lineage: predictor/assessment/scoring-model version, criterion version, sampling design/frame and denominator/time evidence, decision-policy version, analysis-plan/protocol provenance, FJA/KSAO evidence locators and immutable specialist-result references.
  5. product/api(workforce-validation): expose governed validity-study HTTP boundary and currentize API standards #427 exposes only protected owner/scientific contracts through the governed Workforce Validation HTTP/OpenAPI boundary, with least-privilege scopes, idempotency/concurrency/error semantics and authenticated PostgreSQL-backed buyer-path evidence.

UI owner path and corrected #428 relationship

Fresh live review found that the Validation presentation shell already has an executable single-writer owner: #145 on the independent UI stack #53#130#145. #145 must be preserved; #248 must not import/copy it or create a second dashboard.

That UI stack is itself stale relative to protected develop: #53 is currently 113 ahead / 3 behind protected truth and non-mergeable, so it must ordinary-forward reconcile protected Foundation/workflow/provenance changes before #130/#145 can adopt normally. #145's focused Validation test currently depends on a historical feature-local workflow; future adoption must first move that acceptance into the then-current canonical Foundation/product-browser path and then retire the leaf workflow without weakening test coverage.

Accordingly #428 is commercial convergence only, not step 6 of this branch chain. Source implementation of #428 starts only after both:

Then #428 extends/integrates the protected #145 shell against released #427 into the complete API-backed Validation buyer workspace. It preserves scientific evidence states/provenance, Keyverse-backed auth, design-token/Figma/Storybook contracts, KO/EN/JA/ZH/VI/ES/DE/FR localization, accessibility and current-head browser E2E. It may not bypass #427 through direct SQL or service-internal imports.

A free-form study_status_code, current row (recorded_to IS NULL), durable read adapter, HTTP 200 or visual dashboard state is not a substitute for governed lifecycle/scientific authority.

Issues #407#428 remain open until their respective completion boundaries are satisfied. No force-push, destructive rebase, self-approval, gate weakening, mutable-source copy, shadow UI ownership or predecessor-evidence transfer is authorized.

@coderabbitai

coderabbitai Bot commented Sep 5, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

Please review exact head 3b5ebe8341711e72cf3bacc592af8eddae06c9f5 against parent 656a0c41c06bc517b2cf7c554e35a6fb4f8c4f4b, focusing on Issue #247: PostgreSQL ALTER TABLE ... SET SCHEMA relation/FK/RLS/trigger preservation, least-privilege runtime-role semantics, transaction-local tenant binding, DB-API row trust boundaries, UUID snapshot/reconstruction ordering, and 100% branch-coverage plausibility. Treat this as independent static review only; do not infer protected-branch approval or hosted GREEN.

@coderabbitai

coderabbitai Bot commented Sep 5, 2026

Copy link
Copy Markdown

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

parent='656a0c41c06bc517b2cf7c554e35a6fb4f8c4f4b'
head='3b5ebe8341711e72cf3bacc592af8eddae06c9f5'

echo '== Commit availability =='
git show -s --format='%H%n%P%n%s' "$parent"
git show -s --format='%H%n%P%n%s' "$head"

echo '== Changed files =='
git diff --name-status "$parent" "$head"

echo '== Diff summary =='
git diff --stat "$parent" "$head"

echo '== Diff =='
git diff --find-renames --find-copies --unified=80 "$parent" "$head"

echo '== Candidate source and test file outlines =='
fd -t f -E .git | rg -i '(postgres|validity|registry|migration|workforce|read.*port|contract|test)'

Length of output: 46415


🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo '== Registry model outline =='
ast-grep outline services/workforce-validation-api/src/orgmetra_workforce_validation_api/registry.py --items all

echo '== Registry model UUID and record implementation =='
rg -n -A35 -B8 \
  'def _store_operational_uuid|def _restore_operational_uuid|class ValidityStudyRecord|def __post_init__' \
  services/workforce-validation-api/src/orgmetra_workforce_validation_api/registry.py

echo '== Foundation validity-study DDL, RLS, triggers, grants, and tenant helper =='
rg -n -i -A45 -B12 \
  'create table.*validity_study|alter table.*validity_study|create policy|validity_study_bitemporal_guard|current_tenant_record_id|grant .*validity_study|revoke .*validity_study|default privileges' \
  database/migrations/0001_foundation_schema.sql

echo '== Owner schema migration and package coverage configuration =='
cat -n services/workforce-validation-api/database/migrations/0001_owner_schema.sql
cat -n services/workforce-validation-api/pyproject.toml

echo '== Existing PostgreSQL adapter transaction patterns =='
ast-grep outline services/job-analysis-api/src/orgmetra_job_analysis_api/postgres.py --items all
rg -n -A25 -B10 \
  'SET TRANSACTION READ ONLY|set_config|fetchmany|fetchone|connection_factory' \
  services/job-analysis-api/src/orgmetra_job_analysis_api/postgres.py \
  services/people-api/src/orgmetra_people_api/postgres.py \
  services/people-api/src/orgmetra_people_api/postgres_hire.py

echo '== Coverage workflow and service test selection =='
rg -n -A20 -B10 \
  'workforce-validation-api|coverage|branch|test_workforce_validation_owner_schema_postgres' \
  .github scripts package.json pyproject.toml 2>/dev/null || true

Length of output: 98825


🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo '== Complete ValidityStudyRecord construction and properties =='
sed -n '190,270p' services/workforce-validation-api/src/orgmetra_workforce_validation_api/registry.py

echo '== All direct SQL references to validity_study, excluding generated artifacts =='
rg -n -i -C3 \
  '\b(public\.)?validity_study\b|validity_study_scope_policy|current_tenant_record_id\s*\(' \
  -g '!**/.git/**' -g '!**/node_modules/**' .

echo '== Privilege and membership statements for workforce roles =='
rg -n -i -C4 \
  '\b(create|alter|grant|revoke|drop)\s+(role|schema|table|function)|workforce_validation_(runtime_)?role' \
  database services tests .github

echo '== Exact adapter line map and test assertions =='
nl -ba services/workforce-validation-api/src/orgmetra_workforce_validation_api/postgres_registry.py
nl -ba services/workforce-validation-api/tests/test_postgres_registry.py

echo '== Migration ordering and schema-qualified migration references =='
rg -n -C3 \
  '0001_owner_schema|0002_registry_adoption|database/migrations' \
  README.md ARCHITECTURE.md TRD.md .github services tests scripts 2>/dev/null || true

echo '== Git diff check for unreviewed changes =='
git diff --check 656a0c41c06bc517b2cf7c554e35a6fb4f8c4f4b 3b5ebe8341711e72cf3bacc592af8eddae06c9f5

Length of output: 207696


@seonghobae

Static review finding

[P1] Update the existing validity-study case trigger function during adoption

services/workforce-validation-api/database/migrations/0002_registry_adoption.sql moves public.validity_study at Line 15. However, database/migrations/0010_validity_study_case_integrity.sql defines public.validate_validity_study_case() with FROM public.validity_study AS study at Line 142.

ALTER TABLE ... SET SCHEMA preserves relation-attached objects. It does not rewrite the schema-qualified SQL text in a PL/pgSQL function body. After adoption, inserts or updates that invoke the validity_study_case_record validation trigger will fail because public.validity_study no longer exists.

Update or replace that function in the adoption migration so that it reads workforce_validation.validity_study. Extend the isolated PostgreSQL contract to apply the existing case-integrity migration before adoption and then execute a valid case write. This proves that the preserved foreign key and the trigger-function dependency both remain operational.

The static review found no additional defects in the requested areas. The migration uses relation identity preservation. The adapter uses a read-only transaction, transaction-local tenant context, schema-qualified parameterized SQL, pre-connection UUID snapshots, bounded fetch, canonical row reconstruction, and target validation. The unit-test structure also makes 100% branch coverage plausible. This review does not infer hosted GREEN, protected-branch approval, or merge eligibility.

You are interacting with an AI system.

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

Please review exact child head 5d390bc4e86c6db7bcf95a51662cc71500811ad3 against its recorded parent base 656a0c41c06bc517b2cf7c554e35a6fb4f8c4f4b, focusing on #250: PostgresValidityStudyReadPort must preserve its validated connection_factory against retained-reference replacement while keeping #247 read-only/RLS/schema-qualified/target-integrity behavior intact. Parent #235 is mutable; this review is independent static evidence only and must not be treated as protected-branch merge acceptance.

@coderabbitai

coderabbitai Bot commented Sep 5, 2026

Copy link
Copy Markdown

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

base='656a0c41c06bc517b2cf7c554e35a6fb4f8c4f4b'
head='5d390bc4e86c6db7bcf95a51662cc71500811ad3'

echo '== Exact commits =='
git show -s --format='commit=%H%nparents=%P%nsubject=%s' "$base"
git show -s --format='commit=%H%nparents=%P%nsubject=%s' "$head"

echo '== Changed files =='
git diff --name-status "$base" "$head"
echo '== Diff check =='
git diff --check "$base" "$head"
echo '== Full review diff =='
git diff --find-renames --find-copies --unified=100 "$base" "$head"

echo '== Candidate files =='
fd -t f -E .git | rg '(postgres_registry|test_postgres_registry|registry\.py|registry_adoption|validity_study_case_integrity|foundation_schema|pyproject\.toml)$'

echo '== Adapter and test outlines =='
ast-grep outline services/workforce-validation-api/src/orgmetra_workforce_validation_api/postgres_registry.py --items all
ast-grep outline services/workforce-validation-api/tests/test_postgres_registry.py --items all

echo '== Complete adapter and contract test sources =='
nl -ba services/workforce-validation-api/src/orgmetra_workforce_validation_api/postgres_registry.py
nl -ba services/workforce-validation-api/tests/test_postgres_registry.py

echo '== Model construction and UUID snapshot/reconstruction contract =='
rg -n -A55 -B12 \
  'class ValidityStudyRecord|def __post_init__|def _store_operational_uuid|def _restore_operational_uuid' \
  services/workforce-validation-api/src/orgmetra_workforce_validation_api/registry.py

echo '== Adoption and pre-existing trigger SQL =='
nl -ba services/workforce-validation-api/database/migrations/0002_registry_adoption.sql
sed -n '110,175p' database/migrations/0010_validity_study_case_integrity.sql

echo '== Adapter use sites and package exports =='
rg -n -C4 \
  '\bPostgresValidityStudyReadPort\b|\bconnection_factory\b|from .*postgres_registry import' \
  services/workforce-validation-api

Length of output: 42608


@seonghobae

Static review result

The #250 change correctly prevents retained-reference replacement of the accepted connection_factory.

PostgresValidityStudyReadPort has no instance dictionary or writable slots. It stores the validated factory in tuple storage. The connection_factory property reads that tuple value. The regression test uses object.__setattr__, confirms the assignment fails, and confirms that only the original factory runs.

The adapter retains the #247 controls:

  • It validates and snapshots both UUID targets before it calls the factory.
  • It starts a read-only transaction.
  • It sets tenant context with transaction-local pg_catalog.set_config.
  • It uses parameterized SQL against workforce_validation.validity_study.
  • It fetches at most two rows.
  • It rejects non-canonical, malformed, duplicate, and foreign-target rows.
  • It reconstructs validated ValidityStudyRecord evidence before it returns a result.

Unresolved finding

[P1] Update the preserved case-integrity trigger function during adoption

services/workforce-validation-api/database/migrations/0002_registry_adoption.sql moves public.validity_study at Line 15. The existing public.validate_validity_study_case() function in database/migrations/0010_validity_study_case_integrity.sql still queries public.validity_study.

ALTER TABLE ... SET SCHEMA preserves the trigger attachment, but it does not rewrite schema-qualified SQL inside the PL/pgSQL function body. If the case-integrity migration has run, a case write that invokes this function will fail after adoption because public.validity_study no longer exists.

Update or replace the function in the adoption migration so it queries workforce_validation.validity_study. Extend tests/test_workforce_validation_owner_schema_postgres.sh to apply the case-integrity migration before adoption and then perform a valid case write.

I found no additional static defect in the #250 dependency-binding change. This result is independent static evidence only. It does not establish hosted GREEN, protected-branch approval, or merge acceptance.

You are interacting with an AI system.

Copy link
Copy Markdown
Contributor Author

@coderabbitai review

Please review exact head b210b6bd201a9b62949da33bc4a9feb92ec6a095 for #251 against the current protected-owner context. Focus on whether forward registry adoption preserves the existing public.validate_validity_study_case() trigger semantics after public.validity_study moves to workforce_validation.validity_study, including the normalized case insert regression, function identity/signature, non-study evidence reads, inbound FKs, RLS, bitemporal guard, runtime ACL, and absence of compatibility copies/views or protected global migration rewrites. Do not transfer predecessor review evidence.

@coderabbitai

coderabbitai Bot commented Sep 5, 2026

Copy link
Copy Markdown

Tip

For best results, initiate chat on the files or code changes.

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

base='656a0c41c06bc517b2cf7c554e35a6fb4f8c4f4b'
head='b210b6bd201a9b62949da33bc4a9feb92ec6a095'

echo '== Exact commits =='
git show -s --format='commit=%H%nparents=%P%nsubject=%s' "$base"
git show -s --format='commit=%H%nparents=%P%nsubject=%s' "$head"

echo '== Requested-head ancestry and changes =='
git merge-base --is-ancestor "$base" "$head" && echo 'recorded base is an ancestor'
git diff --check "$base" "$head"
git diff --name-status "$base" "$head"
git diff --stat "$base" "$head"
git diff --find-renames --find-copies --unified=100 "$base" "$head" -- \
  'services/workforce-validation-api/database/migrations' \
  'services/workforce-validation-api/tests' \
  'database/migrations/0010_validity_study_case_integrity.sql' \
  'database/migrations/0001_foundation_schema.sql'

echo '== Candidate file locations =='
fd -t f -E .git | rg '(^|/)(0002_registry_adoption\.sql|0010_validity_study_case_integrity\.sql|0001_foundation_schema\.sql|test_workforce_validation_owner_schema_postgres\.sh|test_postgres_registry\.py)$'

echo '== Adoption migration at exact head =='
git show "$head:services/workforce-validation-api/database/migrations/0002_registry_adoption.sql" | nl -ba

echo '== Protected function definition and relation governance before adoption =='
git show "$head:database/migrations/0010_validity_study_case_integrity.sql" | nl -ba | sed -n '1,280p'
git show "$head:database/migrations/0001_foundation_schema.sql" | nl -ba | \
  rg -n -C 20 'validity_study|bitemporal|current_tenant_record_id|CREATE POLICY|FORCE ROW LEVEL SECURITY|GRANT|REVOKE'

echo '== Owner PostgreSQL contract at exact head =='
git show "$head:services/workforce-validation-api/tests/test_workforce_validation_owner_schema_postgres.sh" | nl -ba

echo '== All relevant exact-head SQL references and compatibility-object checks =='
git grep -n -i -E \
  'public\.validity_study|workforce_validation\.validity_study|validate_validity_study_case|validity_study_case_record|CREATE( OR REPLACE)? (TABLE|VIEW).*validity_study|ALTER TABLE.*validity_study.*SET SCHEMA|workforce_validation_runtime_role' \
  "$head" -- \
  'database' 'services/workforce-validation-api' || true

echo '== Current GitHub PR context (metadata only) =='
gh pr view 248 --repo ContextualWisdomLab/Orgmetra \
  --json number,state,isDraft,baseRefName,baseRefOid,headRefName,headRefOid,mergeable,reviewDecision,url
gh pr view 235 --repo ContextualWisdomLab/Orgmetra \
  --json number,state,isDraft,baseRefName,baseRefOid,headRefName,headRefOid,mergeable,reviewDecision,url

Length of output: 21458


🏁 Script executed:

#!/bin/bash
set -euo pipefail

head='b210b6bd201a9b62949da33bc4a9feb92ec6a095'

echo '== Adoption migration at exact head =='
git show "$head:services/workforce-validation-api/database/migrations/0002_registry_adoption.sql" | cat -n

echo '== Protected case-trigger function before adoption =='
git show "$head:database/migrations/0010_validity_study_case_integrity.sql" | cat -n | sed -n '1,300p'

echo '== Validity-study definition, FK, RLS, trigger, and privilege context =='
git show "$head:database/migrations/0001_foundation_schema.sql" | cat -n | \
  grep -E -i -C 20 \
  'validity_study|validity_study_bitemporal_guard|current_tenant_record_id|CREATE POLICY|FORCE ROW LEVEL SECURITY|GRANT|REVOKE'

echo '== Owner PostgreSQL contract at exact head =='
git show "$head:tests/test_workforce_validation_owner_schema_postgres.sh" | cat -n

echo '== Exact-head relevant SQL references =='
git grep -n -i -E \
  'public\.validity_study|workforce_validation\.validity_study|validate_validity_study_case|validity_study_case_record|CREATE( OR REPLACE)? (TABLE|VIEW).*validity_study|ALTER TABLE.*validity_study.*SET SCHEMA|workforce_validation_runtime_role' \
  "$head" -- database services/workforce-validation-api tests || true

echo '== Migration inventory and explicit application order in the contract =='
git ls-tree -r --name-only "$head" -- database/migrations services/workforce-validation-api/database/migrations
git show "$head:tests/test_workforce_validation_owner_schema_postgres.sh" | \
  grep -n -E -C 4 '0001|0010|0002|psql|migration|validity_study_case_record'

echo '== Current GitHub PR context (metadata only) =='
gh pr view 248 --repo ContextualWisdomLab/Orgmetra \
  --json number,state,isDraft,baseRefName,baseRefOid,headRefName,headRefOid,mergeable,reviewDecision,url
gh pr view 235 --repo ContextualWisdomLab/Orgmetra \
  --json number,state,isDraft,baseRefName,baseRefOid,headRefName,headRefOid,mergeable,reviewDecision,url

Length of output: 92254


🏁 Script executed:

#!/bin/bash
set -euo pipefail

base='656a0c41c06bc517b2cf7c554e35a6fb4f8c4f4b'
parent_head='0ac2255321eaf1d0068978b931990f4d9c9f1c85'
child_head='b210b6bd201a9b62949da33bc4a9feb92ec6a095'

echo '== Current parent availability and delta from child base =='
git show -s --format='commit=%H%nparents=%P%nsubject=%s' "$parent_head"
git merge-base --is-ancestor "$base" "$parent_head" && echo 'recorded child base is an ancestor of current parent head'
git diff --name-status "$base" "$parent_head"
git diff --find-renames --find-copies --unified=40 "$base" "$parent_head" -- \
  database/migrations tests services/workforce-validation-api || true

echo '== Current parent and exact child references to the registry relation =='
for revision in "$parent_head" "$child_head"; do
  echo "-- ${revision} --"
  git grep -n -i -E \
    'public\.validity_study|workforce_validation\.validity_study|validate_validity_study_case|validity_study_case_record' \
    "$revision" -- database services tests || true
done

echo '== Full post-0010 global migrations at current parent head =='
for migration in \
  database/migrations/0011_criterion_observation_scope.sql \
  database/migrations/0012_people_mutation_idempotency.sql \
  database/migrations/0013_job_analysis_snapshot.sql
do
  echo "-- ${migration} --"
  git show "${parent_head}:${migration}" | cat -n
done

echo '== Replacement-function equivalence except the intended relation qualification =='
git show "$base:database/migrations/0010_validity_study_case_integrity.sql" \
  | sed -n '/CREATE FUNCTION public\.validate_validity_study_case()/,/^\$\$;/p' \
  | sed 's/public\.validity_study/workforce_validation.validity_study/g' \
  > /tmp/protected_function_normalized.sql
git show "$child_head:services/workforce-validation-api/database/migrations/0002_registry_adoption.sql" \
  | sed -n '/CREATE OR REPLACE FUNCTION public\.validate_validity_study_case()/,/^\$\$;/p' \
  | sed 's/CREATE OR REPLACE FUNCTION/CREATE FUNCTION/' \
  > /tmp/adoption_function_normalized.sql
diff -u /tmp/protected_function_normalized.sql /tmp/adoption_function_normalized.sql || true

Length of output: 69642


@seonghobae

Static review result

I found no defect in the requested #251 scope at exact head b210b6bd201a9b62949da33bc4a9feb92ec6a095.

services/workforce-validation-api/database/migrations/0002_registry_adoption.sql moves the registry with:

ALTER TABLE public.validity_study SET SCHEMA workforce_validation;

This preserves the table object. The contract verifies the same relation OID before and after adoption. It also verifies the existing inbound foreign-key dependency count, forced RLS flags, and validity_study_bitemporal_guard trigger.

The migration replaces public.validate_validity_study_case() in place. It retains the function name, zero-argument trigger signature, RETURNS trigger, plpgsql language, and search path. The function body matches the protected definition except for the required relation change from public.validity_study to workforce_validation.validity_study. The non-study reads remain qualified to their existing public evidence relations.

The existing validity_study_case_governance_guard stays attached to public.validity_study_case_record. PostgreSQL CREATE OR REPLACE FUNCTION updates the existing function body without changing the trigger function identity. The isolated PostgreSQL contract applies migrations through 0010_validity_study_case_integrity.sql, performs adoption, inserts a valid normalized case record, and verifies that the record persists. This regression would fail with the predecessor function body.

The adoption migration creates no compatibility view or copied registry. It removes the old public.validity_study relation name. It grants the separate workforce_validation_runtime_role only schema USAGE, registry SELECT, and execution of public.current_tenant_record_id(). The contract checks deny-default role flags, absence of mutation privileges, no read without tenant context, and a tenant-scoped read with context.

The current parent head 0ac2255321eaf1d0068978b931990f4d9c9f1c85 adds no database migration or additional registry dependency after the child base. The current-parent check found no new public.validity_study dependency outside the protected 0010 definition that this adoption migration replaces at runtime.

This is independent static evidence only. I did not execute the PostgreSQL contract or hosted workflows. GitHub currently reports #235 and #248 as Draft, and #235 still requires review. This result does not establish protected-branch acceptance, hosted GREEN, or merge eligibility.

You are interacting with an AI system.

seonghobae commented Sep 16, 2026

Copy link
Copy Markdown
Contributor Author

Parent handoff refresh: canonical #235 is now exact 64d14e589a460f638a54a9e6484554685815a8c9 on protected develop@eb9757f... and carries the strengthened #407 application contract for purpose-bound calibration auxiliary-authority resolution. Owner evidence now also binds an immutable scientific-use receipt and owner-resolved use instant so the caller cannot choose a convenient historical timestamp. This child remains intentionally on its recorded older #235 snapshot; do not pull mutable parent source or transfer its nonterminal checks.

After #235 integrates normally, non-force adopt the resulting protected truth, preserve this PR's valid migration/adapter/test delta, then add the durable schema-qualified least-privilege implementation of CalibrationAuxiliaryAuthorityReadPort / released auxiliary-evidence resolution in this existing persistence owner path. Acceptance must prove released/versioned owner contract + authorization + scientific-use evidence, no cross-context SQL/source copy, and fresh exact-head PostgreSQL/100%-coverage/security/review evidence.

Copy link
Copy Markdown
Contributor Author

#407 adoption receipt update — scientific leaf correlation

Scientific owner #57 has ordinary-forward strengthened CalibrationAdjustmentReceipt through exact b810abd28e8f3c6362b6333fedf33dcf5793bdca so a future released leaf receipt can carry the same opaque tuple already expected by parent #235: authority, projection, purpose, released owner-contract reference/version/digest, authorization receipt reference/digest, and scientific-use receipt reference/digest/use instant.

This does not change #248's adoption order. Do not copy or implement against mutable #57/#235 source now. After #235 integrates normally, #248 must non-force adopt protected truth and implement the durable least-privilege resolver so the persisted/released owner evidence corroborates those exact leaf coordinates. Child head/base stay unchanged; no parent/leaf checks or reviews transfer.

Copy link
Copy Markdown
Contributor Author

Parent handoff update for #407: #235 now has 21 application-owner families at 7326e580528a0f6e3007d6611929fe334d50800e. Source on this stale child should remain untouched until the parent reaches normal protected integration.

After non-force adoption, durable persistence must add the new validation-result non-verifiability supersession family. The ordinary negative-outcome row's owner-resolved superseded_at must equal the explicit successor verification attempt's released instant. Persist the predecessor result/failure/verification-attempt/owner tuple plus the complete new successor attempt reference/digest/release tuple; do not infer the edge from a mutable current row or caller timestamp. A successor verification attempt only ends the predecessor not_verifiable interval and must not be converted into scientific GREEN without a separately governed released result/outcome.

Copy link
Copy Markdown
Contributor Author

Parent #235 advanced ordinary-forward to exact b593f18ba0face11111d2dcef449253bf0b21773 with a versioned v2 correction contract for validation_result_nonverifiability when failure_mode="non_reproducible". This does not authorize source restack while #235 remains Draft/unintegrated.

Durable adoption after normal parent integration must preserve v1 and v2 as one versioned owner family. V2 must persist/recover the predecessor failed-evidence reference/digest/release instant from canonical released owner evidence, require the successor target result/family/artifact tuple to equal that predecessor exactly, and require successor verification-attempt release at the ordinary predecessor cutover. The failed-artifact tuple must not become a caller-selected lookup coordinate. Mutable current rows, another artifact in the same family, unrelated attempts, or caller timestamps are not correction authority.

Keep this PR Draft and source-stale until the parent is normally integrated; then adopt protected truth non-force and reacquire its own exact-head schema/FK/RLS/ACL/PostgreSQL evidence.

Copy link
Copy Markdown
Contributor Author

Parent handoff update only; no child source restack before normal #235 integration.

Current parent owner head is aa1ec5082ecedebbe10d246c78f85859f8378265. In addition to the existing v1/v2 exact-artifact and ordinary/explicit cutover contract, the durable adapter must treat reconstructed canonical records—not exact Python tuple type—as authority. For v2, persistence/re-hydration must survive full ValidationResultNonVerifiabilityRecord invariant revalidation (digest distinctness and owner/failed-artifact/verification-attempt chronology) and full v2 successor-tuple reconstruction before the record is usable.

Do not derive authority from a mutable current row, caller timestamp, same-family/different artifact, or adapter-created tuple that bypassed the owner constructors. After normal parent integration, adopt non-force and reacquire exact-head persistence/tests/checks for all 21 owner families. No source change is requested on this stale child head yet.

Copy link
Copy Markdown
Contributor Author

Parent handoff refresh only; no child source restack before normal #235 integration.

Current parent owner head is 8bd5d9109a8935908ba2e47bdf7779322760e79c. The v2 durable adapter must retain canonical predecessor/v2 reconstruction and owner-only successor/cutover non-disclosure. The focused complete-successor regression now proves that superseded_at plus every successor result/family/failed-artifact/verification-attempt coordinate stays out of the historical downstream view immediately before cutover.

After normal parent integration, adopt non-force and reacquire exact-head persistence/tests/checks for all 21 owner families. No source change is requested on this stale child head yet.

Copy link
Copy Markdown
Contributor Author

Parent handoff refresh: #235 is now exact 23921d8a74193b4e456c3ed989304141b6a91b77, still Draft, with #410 expanded to 12 concrete canonical-shape proof paths. New path: v1 ValidationResultNonVerifiabilitySupersessionAuthorityRecord (12268af325603dae40a68e87f9e04a2027434a4e RED → 23921d8a74193b4e456c3ed989304141b6a91b77 repair) now rejects hidden outer members, truncated exact-typed records, and duplicate nested predecessor fields before identity/currentness. This child remains source-untouched at d54d44d795444df572efbb301a667d74ac574d58 on old parent snapshot 656a0c41...; do not restack or copy mutable parent/scientific source before normal parent integration. After integration, durable adapters must preserve the same canonical round-trip boundary for this v1 correction path together with the prior eleven #410 proofs.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fleet currentness finding on persistence child exact d54d44d795444df572efbb301a667d74ac574d58.

The child is correctly source-stable until normal parent integration, but its Live stack truth — 2026-09-19 section is now materially stale. Fresh parent authority is #235@9ac1a1873b81d0f61b479ff9283f46781136cb2f, not 5512750396ed109eac87b8a77ac2daaa211e1d99. Parent #235 now records 471 ahead / 0 behind and exact-tree local evidence of 1,306/1,306 tests, 4,487/4,487 owned statements, 1,070/1,070 owned branches, Foundation 55/55; hosted/PostgreSQL/wheel/security/independent-review gates remain pending. #248 still describes the parent as 470 ahead and the #419 coverage state as 96.45% RED, which was true for an earlier generation only.

Do not adopt parent source into this child yet. RED is coordination truth: a section labeled Live stack truth must identify the latest parent exact SHA and distinguish historical predecessor evidence from current parent evidence. GREEN is PR-state/coordination-only currentization: record #235@9ac1a187..., move 551275.../96.45% into historical lineage, and preserve the existing rule that none of the parent's local 100% verdict transfers to #248. The child base may remain intentionally stale 656a0c41... until normal protected/released parent integration, exactly as the current adoption policy requires.

After #235 integrates normally, use ordinary/non-force adoption and then reacquire #248's own PostgreSQL/wheel/coverage/security evidence. No source wake/no-op commit is needed for this currentness repair.

Copy link
Copy Markdown
Contributor Author

Stack authority refresh: #426 now owns the post-persistence governed registration/lifecycle increment. This does not change #248 source scope or unblock early restack. Sequence remains #235 normal protected integration → #248 non-force adopt/integrate durable owner schema → #426 idempotent registration + versioned lifecycle transitions → #425 scientific design lineage. #248 should preserve existing status evidence during adoption and must not invent/migrate lifecycle meanings in the adapter or migration before #426’s explicit legacy census/remediation contract.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant