CTRL-ADR-AMEND-01: pre-authority ADR correction control - #965
Conversation
Independent CRITICAL exact-head implementation review requestReview only. Do not implement, amend source, resolve threads, dispatch CI, merge, deploy, release or perform provider/runtime actions. Exact review targetAny source-head movement invalidates this review target. Binding specification and authorizationExact changed pathsNo fourth path is permitted. Committed blobs: Automatic CIAll automatic PR workflows completed successfully: No manual CI dispatch/rerun occurred. No Docker publication occurred. No migration ran. Required review sourcesInspect independently:
Do not trust the implementing agent's narrative where source, diff or GitHub evidence can answer the question directly. Review focusDetermine whether exact head At minimum challenge:
Required decisionReturn exactly one: Bind the decision exclusively to: For every finding include: Use severity:
Any unresolved CRITICAL/HIGH finding means the exact head is not approved. If APPROVED, explicitly state:
Do not implement, amend, merge, dispatch CI, resolve review threads, or perform provider/runtime actions. |
Independent CRITICAL exact-head review received - control disposition CHANGES REQUIREDAn independent cross-model Claude review was returned for the exact PR #965 head and has been independently dispositioned by control. External review identityLive control re-verification confirms PR #965 is still OPEN / DRAFT / UNMERGED at that exact head and base, and all four automatic workflows remain completed successfully. Independent reviewer decisionThe reviewer found no CRITICAL, HIGH or MEDIUM source/doctrine defect. It independently confirmed:
The reviewer raised two LOW findings:
Control dispositionWhy L-1 is blockingSpecification Amendment 1 Repository task doctrine independently says in The committed report at blob This is not a source/doctrine correctness defect, but it is a direct miss against the approved acceptance criteria and required evidence format. The reviewer cannot waive an approved-spec requirement merely because the underlying evidence exists elsewhere.
L-2 dispositionThe changelog acceptance criterion requires one concise Unreleased entry, which is satisfied. The missing issue/PR reference weakens traceability but does not require a source correction by itself. Do not modify the changelog solely for L-2. Required remediationMinimum source remediation is exactly one path: Required changes:
Authorization consequenceThe existing implementation authorization Therefore another source commit is not currently authorized. Current gate: A fresh CTO remediation authorization is required before the report-only correction may be made. Any new source commit will invalidate the current exact-head review and require fresh independent CRITICAL cross-model review. |
Report-only remediation complete - fresh exact-head review requiredThe bounded report-only remediation authorized in comment Exact remediation identityPR #965 remains OPEN / DRAFT / UNMERGED / mergeable. The prior independent exact-head review of Remediation scopeGitHub exact old-head -> new-head comparison: No other remediation path changed. Cumulative base -> remediation-head PR remains exactly the original three paths: Previously reviewed doctrine/changelog blobs are byte-identical: Report remediationThe new implementation report:
Local remediation validationBounded report-candidate validation before commit: The local bounded repository validates candidate whitespace, changed-path identity and template structure. Exact predecessor/head identity and final remote branch diff were separately verified from live GitHub before and after the branch update; the local repository is not represented as a full clone. Automatic remediation CI / external effectsAll automatically triggered workflows at head No manual CI dispatch/rerun occurred. No Docker publication occurred. No migration executed. No provider/runtime read/write, release, deployment, production activation or #958 source mutation occurred. Current gateThe fresh reviewer should verify the remediation commit first as a one-path evidence-format correction, then confirm the cumulative PR retains the already-reviewed doctrine/changelog bytes and still satisfies the approved #964 specification. Any new source commit invalidates the new exact-head review target. |
Fresh independent CRITICAL exact-head review request - remediation headReview only. Do not edit source, commit, push, mutate the PR, dispatch CI, merge, deploy, release, perform provider/runtime actions or alter #958. Exact review targetThis head supersedes the prior reviewed head. Review of Review provenanceRead the full durable #964 chain, especially:
Required remediation checksVerify independently that:
Cumulative source reviewReconfirm the cumulative base -> head PR still changes exactly: The previously reviewed README/changelog semantics must be unchanged. Recheck enough surrounding doctrine to ensure the remediation did not alter the substantive source under review. CI/external effectsVerify all four remediation-head runs: Verify runtime build/test/lint/format, migration execution and Docker build/push jobs were skipped as recorded. Confirm no manual workflow dispatch/rerun or external publication/write occurred. Authorization complianceVerify remediation authorization No README, changelog, ADR, register, operating-model, branching/workflow, runtime, provider, migration, merge, deployment, activation or #958 source mutation was authorized. Required decisionReturn exactly one: Bind the decision exclusively to: For every finding include ID, severity, disposition, exact evidence, why it matters and required correction. If APPROVED, explicitly state:
Any new source commit invalidates review. |
Fresh CRITICAL exact-head review received - control disposition CHANGES REQUIREDIndependent cross-model review was returned for PR #965 remediation head: Reviewer decision: The reviewer independently confirmed:
The reviewer raised one new LOW finding, L-3, concerning present-tense lifecycle statements in the committed implementation report. Control dispositionWhy L-3 is blockingThe committed report blob These statements are currently true but will be falsified by the very lifecycle events this task is designed to permit.
It explicitly gives ADR-0005 independently selects the same rule: lifecycle status belongs to GitHub, while committed documentation must be durable. The fact that historical merged implementation reports contain similar wording does not authorize a new violation. Repository doctrine outranks precedent. This is an evidence-document durability defect, not a substantive doctrine defect. README and CHANGELOG still require no correction. Minimum remediationExactly one path requires correction: Replace the three transient section-14 bullets with durable conditional wording, for example: Equivalent durable wording is acceptable if it remains true both before and after #965 merges. Do not modify README or CHANGELOG. Authorization consequenceThe report-only remediation authorization Therefore a further source commit is not currently authorized. Any correction commit will invalidate the current exact-head review and require another fresh independent CRITICAL cross-model review. Current gate |
L-3 report-only remediation complete - fresh exact-head review requiredThe bounded L-3 remediation authorized in comment Exact identityPR #965 remains OPEN / DRAFT / UNMERGED / mergeable. Review of Remediation diffExact old-head -> new-head GitHub comparison: No README or CHANGELOG edit occurred. Cumulative base -> new-head PR remains exactly: Previously reviewed blobs remain unchanged: L-3 correctionThe exact transient block: was replaced with durable conditional wording: The replacement is intended to remain true before and after review, authorization and merge, satisfying Pre-commit validationThe container could not resolve GitHub, so no claim is made that a literal local Git clone/diff command ran for this L-3 correction. Instead the exact GitHub-fetched report bytes were validated in-memory before any Git object was created: GitHub's created blob SHA exactly matched the independently calculated Git blob SHA before the branch ref was moved. Post-commit authoritative GitHub verification confirms:
Automatic CI / external effectsAll automatic workflows for exact head No manual CI dispatch/rerun occurred. No Docker publication occurred. No migration executed. No provider/runtime read/write, release, deployment, production activation or #958 source mutation occurred. Current gateAny new source commit invalidates the new exact-head review target. |
Fresh independent CRITICAL exact-head review request - L-3 remediation headReview only. Do not edit source, commit, push, mutate PR state, dispatch/rerun CI, merge, release, deploy, perform provider/runtime actions or alter #958. Exact targetThe prior review does not carry forward. Required checksVerify independently:
Required decisionReturn exactly one: Bind exclusively to: If APPROVED, explicitly state:
Any new source commit invalidates review. |
Final independent CRITICAL review accepted - CTO merge authorizationThe CTO accepts the final independent CRITICAL review of Exact bindingAccepted review disposition: L-4 is accepted as a presentation-only Markdown rendering defect. It does not alter the raw evidence semantics, report-template acceptance, durable lifecycle meaning or substantive #964 doctrine, and it does not justify another source commit that would invalidate the exact-head review. Fresh pre-merge verificationImmediately before this authorization was exercised, control reverified: Exact-head CI remains green: Docs-only classification skipped runtime build/test/lint/format, migration execution and Docker build/push. Authorized merge actionThe CTO authorizes:
This authorization does not authorize:
Successful merge makes the corrected #964 doctrine repository-authoritative on |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
TERMINAL MERGE EVIDENCE - CTRL-ADR-AMEND-01Guarded merge verificationThe merge used expected head:
GitHub reported: Post-merge live state: The merge tree is exactly the independently reviewed source tree. Merged blobs: Review disposition carried into mergeNo source commit occurred after independent approval. Authority consequenceThe corrected engineering-decision authority/amendment process carried by #964 is now repository-authoritative on This merge does not authorize:
#958 must now be freshly reconciled against this merged doctrine before any new bounded #958 source/action authorization. Task branch cleanupThe task branch still exists at:
Branch deletion was authorized if supported, but the connected GitHub action set exposes no delete-ref/delete-branch action. No ref rewrite or simulated deletion was performed. Runtime activation: |
There was a problem hiding this comment.
💡 Codex Review
The reviewed history contains two commits after the original implementation (4102750c and cd39b0b8), but this action matrix says exactly one additional remediation commit was authorized and section 3 lists only one unnamed remediation commit. This makes the report's action-accounting and Unauthorized actions performed: NONE claim unverifiable; record and disposition the second commit against explicit authorization before treating the control report as complete.
AGENTS.md reference: AGENTS.md:L162-L167
After the remediation CI and exact-head review finish, these present-tense bullets become false, and merging preserves those stale claims in a durable repository file. The following paragraph already correctly delegates current lifecycle state to GitHub, so these two transient gates should be removed or rewritten as durable process requirements.
AGENTS.md reference: docs/engineering/AGENTS.md:L27-L40
This records only what the remediation result “must be,” not the result that was actually observed, so the report does not prove that its required git diff --check HEAD validation ran successfully. Record the exact exit status and concise stdout/stderr outcome from the remediation candidate, as is already done for the original implementation.
AGENTS.md reference: AGENTS.md:L242-L264
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
CTRL-ADR-AMEND-01
Implements
thoth-pub/thoth#964under the independently approved amended specification.Exact identity
Binding control records
4beda48432f64b1d9cf0ad7db32f6059e02b2701e7a9d44bff5a334b5b789f805939276423593929780859401595755940287216Exact three-path diff
No ADR, decision register, operating model, branching doctrine, workflow, runtime, migration, provider/IAM or production path changes.
Behaviour
The decision-process doctrine now:
APPROVEDdecision state from repository authority;developasAPPROVED;Validation
The implementation report records the literal local Git checks and their provenance. Remote GitHub verification additionally shows:
4fb9c75c233ae7e6996799307abb1f9e09cdab27;ce4fa7550a9819b602927b84aac4d01b5c4ed53d;2da21bc0b3ae42c5e024072dcfb00e774cf99383.Gates
This PR requires fresh independent CRITICAL cross-model exact-head review.
No merge is authorized by this PR or by implementation completion.
#958 / PR #960 remain HOLD until #964 is independently approved, separately CTO merge-authorized, and actually merged to
develop, followed by fresh #958 reconciliation and authorization.Closes no runtime task.