Skip to content

CTRL-ADR-AMEND-01: pre-authority ADR correction control - #965

Merged
ja573 merged 3 commits into
developfrom
feature/engineering-control/adr-preauthority-correction
Oct 1, 2026
Merged

ja573 merged 3 commits into
developfrom
feature/engineering-control/adr-preauthority-correction

Conversation

@ja573

@ja573 ja573 commented Oct 1, 2026

Copy link
Copy Markdown
Member

CTRL-ADR-AMEND-01

Implements thoth-pub/thoth#964 under the independently approved amended specification.

Exact identity

base:
develop @ 345a7a04131e7c0539f7518c6ea457fa5cb6a462

head:
24b6f524cbd0204ffb855920756b7bdabb1a9e72

tree:
e8d95350b2da5b288a905ef27215b255f1aa3de9

parent:
345a7a04131e7c0539f7518c6ea457fa5cb6a462

Binding control records

  • original CTRL-ADR-AMEND-01: Pre-authority correction of approved ADRs #964 issue-body SHA-256: 4beda48432f64b1d9cf0ad7db32f6059e02b2701e7a9d44bff5a334b5b789f80
  • Specification Amendment 1: 5939276423
  • CTO amendment approval: 5939297808
  • independent CRITICAL specification APPROVED review: 5940159575
  • fresh CTO implementation authorization: 5940287216

Exact three-path diff

CHANGELOG.md
docs/engineering/ai-delivery/implementation-reports/CTRL-ADR-AMEND-01-implementation-report.md
docs/engineering/decisions/README.md

No ADR, decision register, operating model, branching doctrine, workflow, runtime, migration, provider/IAM or production path changes.

Behaviour

The decision-process doctrine now:

  • distinguishes APPROVED decision state from repository authority;
  • keeps normal reliance bound to repository-authoritative decisions, with ADR-0013 as the explicit narrower exact-version programme-local exception;
  • requires CTO classification of post-approval changes as factual clarification or material architectural correction;
  • keys the material pre-authority exception to ADR-number history, fail-closed against any ADR number ever reachable from develop as APPROVED;
  • defines exact ADR versions by Git blob;
  • invalidates stale exact-version approval/review/reliance/merge authorization on material decision drift;
  • requires exact-final-blob CTO approval before a material correction is committed;
  • preserves separate independent exact-head review and CTO merge authorization;
  • introduces no fifth ADR status and no runtime authority.

Validation

The implementation report records the literal local Git checks and their provenance. Remote GitHub verification additionally shows:

  • exactly one commit ahead of base;
  • zero commits behind;
  • exactly three changed paths;
  • README blob 4fb9c75c233ae7e6996799307abb1f9e09cdab27;
  • CHANGELOG blob ce4fa7550a9819b602927b84aac4d01b5c4ed53d;
  • implementation report blob 2da21bc0b3ae42c5e024072dcfb00e774cf99383.

Gates

This PR requires fresh independent CRITICAL cross-model exact-head review.

No merge is authorized by this PR or by implementation completion.

#958 / PR #960 remain HOLD until #964 is independently approved, separately CTO merge-authorized, and actually merged to develop, followed by fresh #958 reconciliation and authorization.

Closes no runtime task.

ja573 commented Oct 1, 2026

Copy link
Copy Markdown
Member Author

Independent CRITICAL exact-head implementation review request

Review only. Do not implement, amend source, resolve threads, dispatch CI, merge, deploy, release or perform provider/runtime actions.

Exact review target

repository:
thoth-pub/thoth

task:
#964 CTRL-ADR-AMEND-01

PR:
#965

base:
develop @ 345a7a04131e7c0539f7518c6ea457fa5cb6a462

head:
24b6f524cbd0204ffb855920756b7bdabb1a9e72

tree:
e8d95350b2da5b288a905ef27215b255f1aa3de9

parent:
345a7a04131e7c0539f7518c6ea457fa5cb6a462

commits ahead:
1

commits behind:
0

risk:
CRITICAL

Any source-head movement invalidates this review target.

Binding specification and authorization

original #964 issue-body SHA-256:
4beda48432f64b1d9cf0ad7db32f6059e02b2701e7a9d44bff5a334b5b789f80

Specification Amendment 1:
5939276423

CTO approval of Amendment 1:
5939297808

independent CRITICAL specification APPROVED review:
5940159575

fresh CTO implementation authorization:
5940287216

implementation handoff:
5940367040

Exact changed paths

CHANGELOG.md
docs/engineering/ai-delivery/implementation-reports/CTRL-ADR-AMEND-01-implementation-report.md
docs/engineering/decisions/README.md

No fourth path is permitted.

Committed blobs:

README:
4fb9c75c233ae7e6996799307abb1f9e09cdab27

CHANGELOG:
ce4fa7550a9819b602927b84aac4d01b5c4ed53d

implementation report:
2da21bc0b3ae42c5e024072dcfb00e774cf99383

Automatic CI

All automatic PR workflows completed successfully:

build-test-and-check
run 36925094595
conclusion: success
classify: success
lint/build/format_check/test: skipped

publish-to-dockerhub
run 36925094604
conclusion: success
classify: success
build_and_push_staging_docker_image: skipped

check-changelog
run 36925094597
conclusion: success
check-changelog: success

run-migrations
run 36925094601
conclusion: success
classify: success
run_migrations: skipped

No manual CI dispatch/rerun occurred. No Docker publication occurred. No migration ran.

Required review sources

Inspect independently:

Do not trust the implementing agent's narrative where source, diff or GitHub evidence can answer the question directly.

Review focus

Determine whether exact head 24b6f524cbd0204ffb855920756b7bdabb1a9e72 satisfies the independently approved amended specification with no unauthorized action.

At minimum challenge:

  1. Authority semantics

    • Does APPROVED now represent decision-owner approval without being silently equated to repository authority?
    • Is repository authority correctly bound to approval + required exact-head review + reachability from develop?
    • Does the cross-programme rule preserve ADR-0013 as the sole narrower pre-develop reliance path?
  2. Factual clarification classification

    • Does the README incorporate N-1 correctly?
    • Is B7 clearly the material-correction procedure?
    • Does a factual clarification require a CTO classification identifying the exact prior approved blob?
    • Are unclassified/uncertain changes fail-closed as material?
  3. Historical eligibility

    • Does the implementation incorporate N-2?
    • Is the exception keyed to ADR number, not file path/version?
    • Does any APPROVED instance ever reachable from develop permanently make that ADR number ineligible for the exception?
    • Do revert/removal/supersession fail to restore eligibility?
    • Is ADR-0013 programme-branch reachability correctly excluded from repository authority?
  4. Exact version / stale controls

    • Is an ADR version unambiguously defined as the exact Git blob?
    • Does material drift stale prior blob/head-bound CTO approval, independent review, ADR-0013 reliance and merge authorization?
    • Are branch-local register assertions covered without changing the register in this task?
  5. Exact-final-blob approval

    • Does the README incorporate N-3?
    • Is git hash-object --no-filters or equivalent required?
    • Must the approval record identify blob SHA, path, issue, approval date in the blob, and inspection basis?
    • Is back-dating prohibited?
    • Is exact committed-blob equality required?
    • Does later non-clarification byte drift invalidate approval?
    • Does independent exact-head review remain a separate post-commit gate?
    • Does CTO merge authorization remain separate?
  6. ADR-local amendment clauses

    • Is the exception bounded to clauses that merely restate repository process?
    • Could the wording accidentally override substantive ADR-specific architecture constraints?
  7. Repository-authoritative ADR protection

    • Can any ADR number that was ever repository-authoritative re-enter the pre-authority exception?
    • Is the superseding-ADR rule preserved for those ADRs?
  8. Status vocabulary

    • Confirm no fifth ADR status is introduced.
    • Confirm existing PROPOSED / APPROVED / SUPERSEDED / REJECTED semantics remain coherent.
  9. Normative consistency

    • Compare the changed README against ADR-0005, ADR-0013, the decision register, operating model and branching doctrine.
    • Determine whether leaving those files unchanged produces any normative contradiction.
    • If another source path is genuinely required, return CHANGES REQUIRED rather than widening scope.
  10. Write/action authorization

    • Confirm exactly three changed paths and one direct-child commit.
    • Confirm no ADR, register, operating-model, branching/workflow or runtime path changed.
    • Confirm no manual CI, provider/runtime action, migration, release, merge, deployment, production activation or THOTH-ASYNC-01-ADR-01: Author ADR-0012 shared async architecture #958 source mutation occurred.
  11. Changelog

    • Confirm exactly one appropriate CTRL-ADR-AMEND-01 entry under [Unreleased] -> Changed.
    • Confirm it does not imply runtime authority.
  12. Implementation-report truthfulness

    • Challenge the report's validation provenance carefully.
    • It explicitly says the literal local Git validation used an exact README plus a bounded changelog insertion-context copy, while the final full changelog was constructed from authoritative GitHub base blob cf662733b61354f08f7d6b26ead3b8079f10d8ba and independently verified by committed blob identity.
    • Determine whether that is truthful and sufficient evidence for this documentation-only task, or whether any acceptance criterion actually required a full exact local worktree.
    • Do not treat the report as proof of its own claims; inspect GitHub source/blob/diff evidence.
  13. CI/external effects

    • Confirm all four automatic workflows correspond to this exact head.
    • Confirm Docker build/push and migrations were actually skipped.
    • Confirm no unexpected external publication/write occurred.
  14. Downstream isolation

Required decision

Return exactly one:

APPROVED
CHANGES REQUIRED
BLOCKED

Bind the decision exclusively to:

PR #965
head 24b6f524cbd0204ffb855920756b7bdabb1a9e72
tree e8d95350b2da5b288a905ef27215b255f1aa3de9
base 345a7a04131e7c0539f7518c6ea457fa5cb6a462

For every finding include:

Finding ID:
Severity:
Disposition:
Evidence:
Why it matters:
Required correction:

Use severity:

  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW

Any unresolved CRITICAL/HIGH finding means the exact head is not approved.

If APPROVED, explicitly state:

Do not implement, amend, merge, dispatch CI, resolve review threads, or perform provider/runtime actions.

ja573 commented Oct 1, 2026

Copy link
Copy Markdown
Member Author

Independent CRITICAL exact-head review received - control disposition CHANGES REQUIRED

An independent cross-model Claude review was returned for the exact PR #965 head and has been independently dispositioned by control.

External review identity

review report SHA-256:
4cf87808fb121e624a30ed490eec59ade9b046371f2977da25b3b2b3ec1750a8

repository:
thoth-pub/thoth

PR:
#965

base:
345a7a04131e7c0539f7518c6ea457fa5cb6a462

head:
24b6f524cbd0204ffb855920756b7bdabb1a9e72

tree:
e8d95350b2da5b288a905ef27215b255f1aa3de9

Live control re-verification confirms PR #965 is still OPEN / DRAFT / UNMERGED at that exact head and base, and all four automatic workflows remain completed successfully.

Independent reviewer decision

APPROVED

The reviewer found no CRITICAL, HIGH or MEDIUM source/doctrine defect. It independently confirmed:

The reviewer raised two LOW findings:

Control disposition

L-1:
VALID / BLOCKING ACCEPTANCE MISS
severity: MEDIUM

L-2:
VALID / NON-BLOCKING
severity: LOW

overall:
CHANGES REQUIRED

Why L-1 is blocking

Specification Amendment 1 5939276423, approved by the CTO in 5939297808, added an explicit acceptance criterion:

implementation report uses
docs/engineering/ai-delivery/implementation-report-template.md

Repository task doctrine independently says in
docs/engineering/ai-delivery/task-specification-template.md section 18:

The agent must use:
docs/engineering/ai-delivery/implementation-report-template.md

The committed report at blob
2da21bc0b3ae42c5e024072dcfb00e774cf99383 does not use that template structure. It condenses the template's fifteen sections into nine, omits the explicit commits section, per-action matrix, dedicated CI section, manual-verification fields and suggested-review-focus field, and records Specification deviations: NONE.

This is not a source/doctrine correctness defect, but it is a direct miss against the approved acceptance criteria and required evidence format. The reviewer cannot waive an approved-spec requirement merely because the underlying evidence exists elsewhere.

ADR-0005 does not require self-referential transient head/PR/CI data to be committed. A template-aligned report may keep those transient fields explicitly as live GitHub lifecycle evidence rather than embedding values that would be falsified by the report commit. That avoids recursive lifecycle-metadata commits while still using the required template.

L-2 disposition

The changelog acceptance criterion requires one concise Unreleased entry, which is satisfied. The missing issue/PR reference weakens traceability but does not require a source correction by itself. Do not modify the changelog solely for L-2.

Required remediation

Minimum source remediation is exactly one path:

docs/engineering/ai-delivery/implementation-reports/CTRL-ADR-AMEND-01-implementation-report.md

Required changes:

  1. align the report to all fifteen sections of implementation-report-template.md;
  2. preserve all existing truthful validation/provenance statements;
  3. add the explicit per-action authorization/use matrix;
  4. record the fresh branch/base preflight evidence;
  5. provide dedicated CI/external-effect fields;
  6. provide manual-verification / known-limitations / self-assessment and suggested-review-focus fields;
  7. explicitly explain under the relevant template fields that the current PR head, PR lifecycle state and CI are live GitHub evidence under ADR-0005 and are not embedded where doing so would create self-invalidating lifecycle metadata;
  8. do not change README or CHANGELOG;
  9. do not add the L-2 traceability link unless separately authorized as part of another necessary source correction.

Authorization consequence

The existing implementation authorization 5940287216 authorized exactly one bounded implementation commit. That commit has already been created and pushed.

Therefore another source commit is not currently authorized.

Current gate:

PR #965 exact-head review:
REVIEWED

reviewer source/doctrine assessment:
APPROVED

control acceptance disposition:
CHANGES REQUIRED

README doctrine:
NO CORRECTION REQUIRED

CHANGELOG:
NO CORRECTION REQUIRED

implementation report:
REPORT-ONLY REMEDIATION REQUIRED

additional source commit:
NOT AUTHORIZED

merge:
HOLD

#958 / PR #960:
HOLD

A fresh CTO remediation authorization is required before the report-only correction may be made. Any new source commit will invalidate the current exact-head review and require fresh independent CRITICAL cross-model review.

ja573 commented Oct 1, 2026

Copy link
Copy Markdown
Member Author

Report-only remediation complete - fresh exact-head review required

The bounded report-only remediation authorized in comment 5941624634 is complete.

Exact remediation identity

PR:
#965

base:
develop @ 345a7a04131e7c0539f7518c6ea457fa5cb6a462

pre-remediation head:
24b6f524cbd0204ffb855920756b7bdabb1a9e72

remediation head:
4102750c101a88ffcf045700d21692d4c8093cf5

remediation tree:
049d557ee0f1abc3e74a19745fe9bf97af0fbeba

remediation parent:
24b6f524cbd0204ffb855920756b7bdabb1a9e72

remediation report blob:
b1792232e5a27e876f255b88fe32a3bf3a96230c

PR #965 remains OPEN / DRAFT / UNMERGED / mergeable.

The prior independent exact-head review of 24b6f524... is invalidated by this source commit.

Remediation scope

GitHub exact old-head -> new-head comparison:

commits:
1

changed paths:
docs/engineering/ai-delivery/implementation-reports/CTRL-ADR-AMEND-01-implementation-report.md

No other remediation path changed.

Cumulative base -> remediation-head PR remains exactly the original three paths:

CHANGELOG.md
docs/engineering/ai-delivery/implementation-reports/CTRL-ADR-AMEND-01-implementation-report.md
docs/engineering/decisions/README.md

Previously reviewed doctrine/changelog blobs are byte-identical:

README:
4fb9c75c233ae7e6996799307abb1f9e09cdab27

CHANGELOG:
ce4fa7550a9819b602927b84aac4d01b5c4ed53d

Report remediation

The new implementation report:

  • uses numbered template sections 1 through 15;
  • adds the explicit action-use matrix;
  • records the fresh exact-head/base preflight;
  • has dedicated CI/external-effects evidence;
  • has manual verification, limitations/deferred work, unresolved issues, self-assessment and review-focus fields;
  • explicitly records the original condensed-report structure as the corrected evidence-format deviation;
  • keeps final remediation head/PR/CI as GitHub lifecycle evidence under ADR-0005 rather than creating self-referential lifecycle-metadata commits;
  • preserves the original validation/provenance limitation honestly;
  • preserves L-2 as a non-blocking known limitation without changing the changelog.

Local remediation validation

Bounded report-candidate validation before commit:

git diff --check HEAD
exit 0
stdout bytes: 0
stderr bytes: 0

git diff --name-only HEAD
docs/engineering/ai-delivery/implementation-reports/CTRL-ADR-AMEND-01-implementation-report.md

git status --short
M  docs/engineering/ai-delivery/implementation-reports/CTRL-ADR-AMEND-01-implementation-report.md

numbered template sections 1-15:
15

candidate Git blob:
b1792232e5a27e876f255b88fe32a3bf3a96230c

The local bounded repository validates candidate whitespace, changed-path identity and template structure. Exact predecessor/head identity and final remote branch diff were separately verified from live GitHub before and after the branch update; the local repository is not represented as a full clone.

Automatic remediation CI / external effects

All automatically triggered workflows at head
4102750c101a88ffcf045700d21692d4c8093cf5
completed successfully:

check-changelog
run 36933837261
conclusion: success
- check-changelog: success

build-test-and-check
run 36933837263
conclusion: success
- classify: success
- test: skipped
- build: skipped
- lint: skipped
- format_check: skipped

run-migrations
run 36933837349
conclusion: success
- classify: success
- run_migrations: skipped

publish-to-dockerhub
run 36933837275
conclusion: success
- classify: success
- build_and_push_staging_docker_image: skipped

No manual CI dispatch/rerun occurred.

No Docker publication occurred.

No migration executed.

No provider/runtime read/write, release, deployment, production activation or #958 source mutation occurred.

Current gate

report-only remediation:
COMPLETE

L-1:
CORRECTED / REQUIRES FRESH REVIEW

L-2:
UNCHANGED / NON-BLOCKING KNOWN LIMITATION

fresh independent CRITICAL cross-model exact-head review:
REQUIRED / PENDING

review target:
PR #965
head 4102750c101a88ffcf045700d21692d4c8093cf5
tree 049d557ee0f1abc3e74a19745fe9bf97af0fbeba

CTO merge authorization:
NOT GRANTED

merge:
HOLD

#958 / PR #960:
HOLD

The fresh reviewer should verify the remediation commit first as a one-path evidence-format correction, then confirm the cumulative PR retains the already-reviewed doctrine/changelog bytes and still satisfies the approved #964 specification.

Any new source commit invalidates the new exact-head review target.

ja573 commented Oct 1, 2026

Copy link
Copy Markdown
Member Author

Fresh independent CRITICAL exact-head review request - remediation head

Review only. Do not edit source, commit, push, mutate the PR, dispatch CI, merge, deploy, release, perform provider/runtime actions or alter #958.

Exact review target

repository:
thoth-pub/thoth

task:
#964 CTRL-ADR-AMEND-01

PR:
#965

base:
develop @ 345a7a04131e7c0539f7518c6ea457fa5cb6a462

head:
4102750c101a88ffcf045700d21692d4c8093cf5

tree:
049d557ee0f1abc3e74a19745fe9bf97af0fbeba

head parent:
24b6f524cbd0204ffb855920756b7bdabb1a9e72

This head supersedes the prior reviewed head. Review of 24b6f524... does not carry forward.

Review provenance

Read the full durable #964 chain, especially:

  • Specification Amendment 1 5939276423;
  • CTO amendment approval 5939297808;
  • independent specification approval 5940159575;
  • implementation authorization 5940287216;
  • original implementation handoff 5940367040;
  • first exact-head review/control disposition 5941598377;
  • PR disposition 5941598956;
  • report-only remediation authorization 5941624634;
  • this remediation handoff.

Required remediation checks

Verify independently that:

  1. old head -> new head is exactly one direct-child commit;
  2. that commit changes exactly one path:
    docs/engineering/ai-delivery/implementation-reports/CTRL-ADR-AMEND-01-implementation-report.md;
  3. README remains blob 4fb9c75c233ae7e6996799307abb1f9e09cdab27;
  4. CHANGELOG remains blob ce4fa7550a9819b602927b84aac4d01b5c4ed53d;
  5. report is blob b1792232e5a27e876f255b88fe32a3bf3a96230c;
  6. the report now uses all fifteen numbered implementation-report-template sections;
  7. the explicit action-use matrix is present;
  8. the successful remediation preflight is recorded;
  9. dedicated CI/external-effects, manual-verification, limitations, unresolved-issues, self-assessment and suggested-review-focus fields are present;
  10. the original nine-section structure is explicitly recorded as the corrected evidence-format deviation;
  11. transient final head/PR/CI data are delegated to live GitHub evidence under ADR-0005 without omitting the relevant template fields;
  12. the original validation-provenance limitation remains truthful and is not upgraded into a false full-worktree claim;
  13. L-2 remains only a known non-blocking limitation and no unauthorized changelog edit occurred.

Cumulative source review

Reconfirm the cumulative base -> head PR still changes exactly:

CHANGELOG.md
docs/engineering/ai-delivery/implementation-reports/CTRL-ADR-AMEND-01-implementation-report.md
docs/engineering/decisions/README.md

The previously reviewed README/changelog semantics must be unchanged. Recheck enough surrounding doctrine to ensure the remediation did not alter the substantive source under review.

CI/external effects

Verify all four remediation-head runs:

36933837261 check-changelog: success
36933837263 build-test-and-check: success
36933837349 run-migrations: success
36933837275 publish-to-dockerhub: success

Verify runtime build/test/lint/format, migration execution and Docker build/push jobs were skipped as recorded.

Confirm no manual workflow dispatch/rerun or external publication/write occurred.

Authorization compliance

Verify remediation authorization 5941624634 allowed exactly one report-only source commit and the observed actions stayed within it.

No README, changelog, ADR, register, operating-model, branching/workflow, runtime, provider, migration, merge, deployment, activation or #958 source mutation was authorized.

Required decision

Return exactly one:

APPROVED
CHANGES REQUIRED
BLOCKED

Bind the decision exclusively to:

PR #965
head 4102750c101a88ffcf045700d21692d4c8093cf5
tree 049d557ee0f1abc3e74a19745fe9bf97af0fbeba
base 345a7a04131e7c0539f7518c6ea457fa5cb6a462

For every finding include ID, severity, disposition, exact evidence, why it matters and required correction.

If APPROVED, explicitly state:

Any new source commit invalidates review.

ja573 commented Oct 1, 2026

Copy link
Copy Markdown
Member Author

Fresh CRITICAL exact-head review received - control disposition CHANGES REQUIRED

Independent cross-model review was returned for PR #965 remediation head:

head:
4102750c101a88ffcf045700d21692d4c8093cf5

tree:
049d557ee0f1abc3e74a19745fe9bf97af0fbeba

base:
345a7a04131e7c0539f7518c6ea457fa5cb6a462

Reviewer decision:

APPROVED

The reviewer independently confirmed:

  • exact remediation topology and blobs;
  • report-only remediation scope;
  • cumulative three-path write budget;
  • L-1 closed;
  • L-2 remains LOW / non-blocking;
  • report-template acceptance satisfied;
  • remediation CI/external-effect evidence acceptable;
  • no unauthorized action;
  • README/CHANGELOG substantive review remains valid because their blobs are unchanged.

The reviewer raised one new LOW finding, L-3, concerning present-tense lifecycle statements in the committed implementation report.

Control disposition

L-1:
CLOSED

L-2:
LOW / NON-BLOCKING

L-3:
VALID / BLOCKING
severity: MEDIUM

overall:
CHANGES REQUIRED

Why L-3 is blocking

The committed report blob
b1792232e5a27e876f255b88fe32a3bf3a96230c
contains in section 14:

- CTO merge authorization remains separate and is not granted;
- merge remains HOLD;
- #958/PR #960 remain HOLD.

These statements are currently true but will be falsified by the very lifecycle events this task is designed to permit.

docs/engineering/AGENTS.md section 1.1 is directly binding on engineering-control documents and states:

Committed files record durable repository state. GitHub records transient
workflow state.

Do not write into a committed file a statement that merging will falsify.

It explicitly gives AWAITING CTO MERGE AUTHORIZATION and MERGE NOT YET COMPLETE as prohibited examples and requires wording that remains truthful before review, after review, before merge and after merge.

ADR-0005 independently selects the same rule: lifecycle status belongs to GitHub, while committed documentation must be durable.

The fact that historical merged implementation reports contain similar wording does not authorize a new violation. Repository doctrine outranks precedent.

This is an evidence-document durability defect, not a substantive doctrine defect. README and CHANGELOG still require no correction.

Minimum remediation

Exactly one path requires correction:

docs/engineering/ai-delivery/implementation-reports/CTRL-ADR-AMEND-01-implementation-report.md

Replace the three transient section-14 bullets with durable conditional wording, for example:

Remaining lifecycle gates are GitHub-owned under ADR-0005:

- merge requires separate CTO merge authorization bound to the exact reviewed head;
- merge occurs only through the separately authorized GitHub merge gate;
- #958 / PR #960 may resume only after #965 merges to develop and fresh #958 reconciliation and bounded authorization complete.

Equivalent durable wording is acceptable if it remains true both before and after #965 merges.

Do not modify README or CHANGELOG.

Authorization consequence

The report-only remediation authorization 5941624634 permitted exactly one additional remediation commit. That commit has already been created as 4102750c....

Therefore a further source commit is not currently authorized.

Any correction commit will invalidate the current exact-head review and require another fresh independent CRITICAL cross-model review.

Current gate

PR #965 exact-head review:
REVIEWED

substantive doctrine:
APPROVED / UNCHANGED

L-1:
CLOSED

L-2:
LOW / NON-BLOCKING

L-3:
MEDIUM / BLOCKING

overall:
CHANGES REQUIRED

additional report-only commit:
NOT AUTHORIZED

CTO merge authorization:
NOT GRANTED

merge:
HOLD

#958 / PR #960:
HOLD

ja573 commented Oct 1, 2026

Copy link
Copy Markdown
Member Author

L-3 report-only remediation complete - fresh exact-head review required

The bounded L-3 remediation authorized in comment 5941931277 is complete.

Exact identity

PR:
#965

base:
develop @ 345a7a04131e7c0539f7518c6ea457fa5cb6a462

pre-remediation head:
4102750c101a88ffcf045700d21692d4c8093cf5

new head:
cd39b0b87666b2df775b5fb0e37893c042687a6c

new tree:
8a12416b04993e9cc94f9502cbeb4013413b195e

parent:
4102750c101a88ffcf045700d21692d4c8093cf5

report blob:
7bf7425f0527dbaa72e718df5264e399035a148b

PR #965 remains OPEN / DRAFT / UNMERGED / mergeable.

Review of 4102750c... is invalidated by this source commit.

Remediation diff

Exact old-head -> new-head GitHub comparison:

commits:
1

changed path:
docs/engineering/ai-delivery/implementation-reports/CTRL-ADR-AMEND-01-implementation-report.md

changes:
+5 / -3

No README or CHANGELOG edit occurred.

Cumulative base -> new-head PR remains exactly:

CHANGELOG.md
docs/engineering/ai-delivery/implementation-reports/CTRL-ADR-AMEND-01-implementation-report.md
docs/engineering/decisions/README.md

Previously reviewed blobs remain unchanged:

README:
4fb9c75c233ae7e6996799307abb1f9e09cdab27

CHANGELOG:
ce4fa7550a9819b602927b84aac4d01b5c4ed53d

L-3 correction

The exact transient block:

- CTO merge authorization remains separate and is not granted;
- merge remains HOLD;
- #958/PR #960 remain HOLD.

was replaced with durable conditional wording:

Remaining lifecycle gates are GitHub-owned under ADR-0005:

- merge requires separate CTO merge authorization bound to the exact reviewed head;
- merge occurs only through the separately authorized GitHub merge gate;
- #958 / PR #960 may resume only after #965 merges to develop and fresh #958 reconciliation and bounded authorization complete.

The replacement is intended to remain true before and after review, authorization and merge, satisfying docs/engineering/AGENTS.md section 1.1 and ADR-0005.

Pre-commit validation

The container could not resolve GitHub, so no claim is made that a literal local Git clone/diff command ran for this L-3 correction.

Instead the exact GitHub-fetched report bytes were validated in-memory before any Git object was created:

old lifecycle block occurrences:
1

template numbered sections 1-15:
15

trailing whitespace:
none

changed old lines:
exactly the three authorized transient bullets

changed new lines:
exactly the durable replacement block

candidate Git blob:
7bf7425f0527dbaa72e718df5264e399035a148b

GitHub's created blob SHA exactly matched the independently calculated Git blob SHA before the branch ref was moved.

Post-commit authoritative GitHub verification confirms:

  • new commit is a direct child of the authorized head;
  • remediation diff is exactly one report path;
  • cumulative PR remains the same three paths;
  • README and CHANGELOG blobs are byte-identical to the prior reviewed head;
  • committed report blob is exactly 7bf7425f0527dbaa72e718df5264e399035a148b.

Automatic CI / external effects

All automatic workflows for exact head
cd39b0b87666b2df775b5fb0e37893c042687a6c
completed successfully:

build-test-and-check
run 36935273302
conclusion: success
- classify: success
- lint: skipped
- test: skipped
- format_check: skipped
- build: skipped

check-changelog
run 36935273293
conclusion: success
- check-changelog: success

run-migrations
run 36935273438
conclusion: success
- classify: success
- run_migrations: skipped

publish-to-dockerhub
run 36935273393
conclusion: success
- classify: success
- build_and_push_staging_docker_image: skipped

No manual CI dispatch/rerun occurred.

No Docker publication occurred.

No migration executed.

No provider/runtime read/write, release, deployment, production activation or #958 source mutation occurred.

Current gate

L-1:
CLOSED

L-2:
LOW / NON-BLOCKING

L-3:
CORRECTED / FRESH REVIEW REQUIRED

fresh independent CRITICAL cross-model exact-head review:
REQUIRED / PENDING

review target:
PR #965
head cd39b0b87666b2df775b5fb0e37893c042687a6c
tree 8a12416b04993e9cc94f9502cbeb4013413b195e

CTO merge authorization:
NOT GRANTED

merge:
HOLD

#958 / PR #960:
HOLD

Any new source commit invalidates the new exact-head review target.

ja573 commented Oct 1, 2026

Copy link
Copy Markdown
Member Author

Fresh independent CRITICAL exact-head review request - L-3 remediation head

Review only. Do not edit source, commit, push, mutate PR state, dispatch/rerun CI, merge, release, deploy, perform provider/runtime actions or alter #958.

Exact target

repository:
thoth-pub/thoth

task:
#964 CTRL-ADR-AMEND-01

PR:
#965

base:
345a7a04131e7c0539f7518c6ea457fa5cb6a462

head:
cd39b0b87666b2df775b5fb0e37893c042687a6c

tree:
8a12416b04993e9cc94f9502cbeb4013413b195e

parent:
4102750c101a88ffcf045700d21692d4c8093cf5

The prior review does not carry forward.

Required checks

Verify independently:

  1. parent -> head is exactly one direct-child commit;
  2. that commit changes exactly one path:
    docs/engineering/ai-delivery/implementation-reports/CTRL-ADR-AMEND-01-implementation-report.md;
  3. old transient lifecycle block was replaced and no other report content changed materially;
  4. new section-14 wording remains true before and after merge and satisfies docs/engineering/AGENTS.md section 1.1 plus ADR-0005;
  5. template sections 1-15 remain intact;
  6. report blob is exactly 7bf7425f0527dbaa72e718df5264e399035a148b;
  7. README remains 4fb9c75c233ae7e6996799307abb1f9e09cdab27;
  8. CHANGELOG remains ce4fa7550a9819b602927b84aac4d01b5c4ed53d;
  9. cumulative PR remains exactly the approved three paths;
  10. L-1 remains closed and L-2 remains non-blocking;
  11. authorization 5941931277 was obeyed exactly;
  12. validation provenance is truthful: no literal local Git clone/diff is claimed for L-3 because container DNS failed; exact in-memory candidate validation plus GitHub blob/tree verification is recorded instead;
  13. remediation CI runs are exact-head automatic pull_request runs and all succeeded:
    • 36935273302 build-test-and-check;
    • 36935273293 check-changelog;
    • 36935273438 run-migrations;
    • 36935273393 publish-to-dockerhub;
  14. runtime build/test/lint/format, migration execution and Docker build/push jobs were skipped;
  15. no manual CI, external publication/write, provider/runtime action, migration, merge or THOTH-ASYNC-01-ADR-01: Author ADR-0012 shared async architecture #958 mutation occurred.

Required decision

Return exactly one:

APPROVED
CHANGES REQUIRED
BLOCKED

Bind exclusively to:

PR #965
head cd39b0b87666b2df775b5fb0e37893c042687a6c
tree 8a12416b04993e9cc94f9502cbeb4013413b195e
base 345a7a04131e7c0539f7518c6ea457fa5cb6a462

If APPROVED, explicitly state:

Any new source commit invalidates review.

ja573 commented Oct 1, 2026

Copy link
Copy Markdown
Member Author

Final independent CRITICAL review accepted - CTO merge authorization

The CTO accepts the final independent CRITICAL review of CTRL-ADR-AMEND-01 / #964 and authorizes guarded merge of PR #965.

Exact binding

PR:
#965

reviewed head:
cd39b0b87666b2df775b5fb0e37893c042687a6c

reviewed tree:
8a12416b04993e9cc94f9502cbeb4013413b195e

base:
develop @ 345a7a04131e7c0539f7518c6ea457fa5cb6a462

independent review report SHA-256:
be86b492c316bb549423625d00083e1fcf4c09804597c8cc1c152cdf2007c2e6

risk:
CRITICAL

Accepted review disposition:

L-1:
CLOSED

L-2:
LOW / NON-BLOCKING

L-3:
CLOSED

L-4:
LOW / NON-BLOCKING

overall:
APPROVED

L-4 is accepted as a presentation-only Markdown rendering defect. It does not alter the raw evidence semantics, report-template acceptance, durable lifecycle meaning or substantive #964 doctrine, and it does not justify another source commit that would invalidate the exact-head review.

Fresh pre-merge verification

Immediately before this authorization was exercised, control reverified:

PR state:
OPEN / DRAFT / UNMERGED / mergeable

PR head:
cd39b0b87666b2df775b5fb0e37893c042687a6c

PR tree:
8a12416b04993e9cc94f9502cbeb4013413b195e

PR base:
345a7a04131e7c0539f7518c6ea457fa5cb6a462

live develop:
345a7a04131e7c0539f7518c6ea457fa5cb6a462

new reviews:
NONE

review threads:
NONE

Exact-head CI remains green:

36935273302 build-test-and-check: success
36935273293 check-changelog: success
36935273438 run-migrations: success
36935273393 publish-to-dockerhub: success

Docs-only classification skipped runtime build/test/lint/format, migration execution and Docker build/push.

Authorized merge action

The CTO authorizes:

This authorization does not authorize:

Successful merge makes the corrected #964 doctrine repository-authoritative on develop. It does not authorize #958 implementation. #958 must be freshly reconciled against the merged doctrine before any new bounded source/action authorization.

@ja573
ja573 marked this pull request as ready for review October 1, 2026 22:40
@ja573
ja573 merged commit 8ac771c into develop Oct 1, 2026
10 checks passed
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-01T22:44:49.071842Z cd39b0b Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

ja573 commented Oct 1, 2026

Copy link
Copy Markdown
Member Author

TERMINAL MERGE EVIDENCE - CTRL-ADR-AMEND-01

task:
#964 CTRL-ADR-AMEND-01

PR:
#965

reviewed head:
cd39b0b87666b2df775b5fb0e37893c042687a6c

reviewed tree:
8a12416b04993e9cc94f9502cbeb4013413b195e

independent review report SHA-256:
be86b492c316bb549423625d00083e1fcf4c09804597c8cc1c152cdf2007c2e6

final review / CTO merge authorization:
#964 comment 5942125684
PR #965 comment 5942126186

merge commit:
8ac771c55937f7a4fe4131b3c21c466f0b4d7abc

merged at:
2026-10-01T22:40:54Z

Guarded merge verification

The merge used expected head:

cd39b0b87666b2df775b5fb0e37893c042687a6c

GitHub reported:

merged: true
message: Pull Request successfully merged

Post-merge live state:

develop:
8ac771c55937f7a4fe4131b3c21c466f0b4d7abc

merge parents, ordered:
1. 345a7a04131e7c0539f7518c6ea457fa5cb6a462
2. cd39b0b87666b2df775b5fb0e37893c042687a6c

merge tree:
8a12416b04993e9cc94f9502cbeb4013413b195e

The merge tree is exactly the independently reviewed source tree.

Merged blobs:

docs/engineering/decisions/README.md
4fb9c75c233ae7e6996799307abb1f9e09cdab27

CHANGELOG.md
ce4fa7550a9819b602927b84aac4d01b5c4ed53d

docs/engineering/ai-delivery/implementation-reports/CTRL-ADR-AMEND-01-implementation-report.md
7bf7425f0527dbaa72e718df5264e399035a148b

Review disposition carried into merge

L-1: CLOSED
L-2: LOW / NON-BLOCKING
L-3: CLOSED
L-4: LOW / NON-BLOCKING
overall: APPROVED

No source commit occurred after independent approval.

Authority consequence

The corrected engineering-decision authority/amendment process carried by #964 is now repository-authoritative on develop.

This merge does not authorize:

#958 must now be freshly reconciled against this merged doctrine before any new bounded #958 source/action authorization.

Task branch cleanup

The task branch still exists at:

feature/engineering-control/adr-preauthority-correction @ cd39b0b87666b2df775b5fb0e37893c042687a6c

Branch deletion was authorized if supported, but the connected GitHub action set exposes no delete-ref/delete-branch action. No ref rewrite or simulated deletion was performed.

Runtime activation: NOT APPLICABLE / NOT AUTHORIZED.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

- commit: `YES - exactly one additional remediation commit authorized`

P2 Badge Record the additional remediation commit

The reviewed history contains two commits after the original implementation (4102750c and cd39b0b8), but this action matrix says exactly one additional remediation commit was authorized and section 3 lists only one unnamed remediation commit. This makes the report's action-accounting and Unauthorized actions performed: NONE claim unverifiable; record and disposition the second commit against explicit authorization before treating the control report as complete.

AGENTS.md reference: AGENTS.md:L162-L167


- remediation head automatic CI must settle;
- fresh independent CRITICAL cross-model exact-head review is required;

P2 Badge Remove transient CI and review status from the report

After the remediation CI and exact-head review finish, these present-tense bullets become false, and merging preserves those stale claims in a durable repository file. The following paragraph already correctly delegates current lifecycle state to GitHub, so these two transient gates should be removed or rewritten as durable process requirements.

AGENTS.md reference: docs/engineering/AGENTS.md:L27-L40


Remediation result: recorded from the report-only validation repository before commit; must be exit 0 with empty stdout/stderr or remediation HOLDS.

P2 Badge Replace the prospective check result with the actual outcome

This records only what the remediation result “must be,” not the result that was actually observed, so the report does not prove that its required git diff --check HEAD validation ran successfully. Record the exact exit status and concise stdout/stderr outcome from the remediation candidate, as is already done for the original implementation.

AGENTS.md reference: AGENTS.md:L242-L264

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant