Repository navigation
feat(review)!: make approval terminal and burn lineage - #3536
Conversation
|
Important Review skippedToo many files! This PR contains 352 files, which is 52 over the limit of 300. To get a review, reduce the PR to 300 files or fewer by splitting it into smaller PRs or changing its base branch. Usage-priced reviews support at most 300 files. ⚙️ Run configurationConfiguration used: Repository UI Review profile: ASSERTIVE Plan: Pro Plus Run ID: ⛔ Files ignored due to path filters (29)
📒 Files selected for processing (352)
You can disable this status message by setting the Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Pull request overview
This PR implements the #3417 shift to an atomic review lifecycle where approval is terminal and burns lineage/authority, and where delivery/archival decisions are no longer governed by review receipts/gates (review becomes informational context only). It updates runtime integration contracts, schemas, docs, and bench journeys to reflect “consent → freeze → lenses → bounded correction/validator → approval → burn” and to make gate outputs non-authoritative under ordinary repository policy.
Changes:
- Make approval terminal by burning compact review authority/artifacts after successful FINALIZE, and treat gate outputs as informational (repository policy owns delivery).
- Update negotiated contracts/schemas and runtime orchestration assets to enforce exact START binding reuse (lineage/revision/target) across STATUS/capture/FINALIZE.
- Refresh regression coverage (unit tests + bench journeys/axes) to pin atomic/burn semantics and runtime integration invariants (including OpenCode background task handling).
Reviewed changes
Copilot reviewed 137 out of 381 changed files in this pull request and generated 1 comment.
Show a summary per file
| File | Description |
|---|---|
| testdata/golden/sdd-opencode-cmd-sdd-apply.golden | Updates OpenCode SDD apply command guidance to atomic START + burn semantics. |
| testdata/golden/sdd-claude-cmd-sdd-archive.golden | Updates archive gate text to treat review as non-gating informational context. |
| testdata/golden/sdd-claude-cmd-sdd-apply.golden | Updates Claude SDD apply command guidance to atomic START + burn semantics. |
| skills/rdd-defect-workflow/SKILL.md | Aligns RDD defect workflow guidance with non-governing delivery policy. |
| skills/rdd-advisory-transport/SKILL.md | Updates advisory transport invariants: review-context only, not delivery authority. |
| scripts/test-review-contract-package.sh | Extends contract package expectations for new schemas. |
| scripts/test-review-capabilities.sh | Bumps capabilities protocol assertions and adds new feature/schema expectations. |
| scripts/crosslane/opencodeecho.go | Adds burn assertions / START binding retention in OpenCode crosslane battery. |
| scripts/crosslane/opencode.go | Stores START bindings and asserts burned lifecycle behavior. |
| scripts/crosslane/main.go | Initializes lineage tracking and enables Codex lane in crosslane runner. |
| openspec/specs/rdd-simplification-design/spec.md | Updates spec language from “gates” to “review context” and removes delivery governance. |
| openspec/specs/rdd-sdd-receipt-consumption/spec.md | Reframes SDD consumption as informational review context, not archive/delivery gating. |
| openspec/specs/rdd-review-core-transitions/spec.md | Clarifies validate as review-context evaluation only; not delivery authority. |
| openspec/specs/rdd-post-verify-review-offer/spec.md | Clarifies offer/receipt visibility does not block archive/delivery under ordinary policy. |
| openspec/specs/rdd-candidate-identity/spec.md | Clarifies persisted identity is review evidence only; never delivery/archive authority. |
| openspec/changes/sdd-compact-authority-recovery/verify-report.md | Marks superseded historical routing claims and documents new #3417 ordering. |
| openspec/changes/pi-optional-codegraph-integration/verify-report.md | Marks superseded historical routing claims and documents new #3417 ordering. |
| internal/sddstatus/status_test.go | Adjusts status routing expectations away from resolve-review toward verify/archive. |
| internal/sddstatus/runtime_status_test.go | Updates malformed evidence behavior to require independent verification retry. |
| internal/sddstatus/runtime_ledger_review_disabled_test.go | Updates behavior to keep archive ready under ordinary policy even when review context exists. |
| internal/sddstatus/review_offer_routing_test.go | Renames/rewrites decline test to assert invariants (not byte-equivalence claims). |
| internal/sddstatus/review_binding_test.go | Changes receipt-drift behavior to rerun verify while keeping review context visible. |
| internal/sddstatus/path_quote_render_test.go | Removes resolve-review path rendering assertions from Windows-path tests. |
| internal/sddstatus/bench_fixture.go | Removes bench-fixture seam for mutating receipts (source-coupled behavior retired). |
| internal/reviewtransaction/verification_evidence_test.go | Adds escalation case for conclusive failed validator under atomic verification evidence. |
| internal/reviewtransaction/transaction.go | Adds frozen policy content to START record for targeted validator prompt fidelity. |
| internal/reviewtransaction/target_status_projection.go | Makes ordinary STATUS compact-only; checks staged burn stores and duplicate authority roots. |
| internal/reviewtransaction/rdd_mode.go | Removes delivery disposition helper that implied gate-governed delivery. |
| internal/reviewtransaction/rdd_mode_test.go | Updates receipt ref hashing approach and removes obsolete delivery-disposition test. |
| internal/reviewtransaction/rar_authority_repository.go | Inlines receipt ref digesting and removes helper; tightens ref equality check. |
| internal/reviewtransaction/rar_authority_repository_test.go | Updates tests to compute receipt refs consistently with new digesting logic. |
| internal/reviewtransaction/projection_compatibility_test.go | Removes test asserting post-commit reuse of receipt governance (superseded by burn). |
| internal/reviewtransaction/process_liveness_unix.go | Removes unix process liveness helper (stale-lock removal semantics shifted). |
| internal/reviewtransaction/path_quote_render_test.go | Removes repair command path-quoting test after repair text helper removal. |
| internal/reviewtransaction/maintenance_lock_test.go | Switches to atomic compact START helper in maintenance lock tests. |
| internal/reviewtransaction/lineage_occupancy.go | Adds exact-lineage occupancy check across persisted authority schema roots. |
| internal/reviewtransaction/lineage_occupancy_test.go | Tests exact lineage occupancy behavior across v1/v2/v3 directories. |
| internal/reviewtransaction/gate_write_guard_test.go | Renames call-expression name derivation helper for gate write guard scanning. |
| internal/reviewtransaction/final_verification_retry.go | Clears InitialAtomicStart on retry successors to prevent improper atomic START claims. |
| internal/reviewtransaction/final_verification_retry_test.go | Updates retry tests to use atomic START creation and asserts successor invariants. |
| internal/reviewtransaction/compact_scoped_walks_test.go | Removes outdated-identity inspection test (classification policy shifted). |
| internal/reviewtransaction/compact_role_result_slot.go | Keys targeted-validator result slots by (revision,target,request_hash) for stronger binding. |
| internal/reviewtransaction/compact_role_result_slot_test.go | Updates slot-key tests for new request-hash binding requirement. |
| internal/reviewtransaction/compact_repository_context.go | Removes unused intent builder helper (repository context reconciliation revised). |
| internal/reviewtransaction/compact_recovered_evidence_test.go | Fixes correction budget admission and preserves over-budget historical evidence. |
| internal/reviewtransaction/compact_gate.go | Removes delivery-shape scope-change diagnostics helper (delivery gating retired). |
| internal/reviewtransaction/compact_causality_test.go | Removes unrelated historical causality start test (selection semantics changed). |
| internal/reviewtransaction/compact_abandon_test.go | Switches abandon test to atomic compact START helper. |
| internal/reviewtransaction/candidate_identity.go | Removes changed-paths+mode digest helper (identity model revised). |
| internal/reviewtransaction/authority_disposition_plan.go | Removes compact repair command text helper and pathquote dependency. |
| internal/reviewtransaction/authority_disposition_execute_test.go | Updates comments and swaps to atomic START helper in unrelated lineage setup. |
| internal/reviewerprovider/adapter_minimality_guard_test.go | Adds guard against adapters resolving lifecycle root material (cwd/path materialization). |
| internal/components/sdd/reviewer_envelope_guard_test.go | Updates envelope guard expectations for provider-bound immutable inspection wording. |
| internal/components/sdd/review_foundations_test.go | Adds tests asserting apply→verify ordering and “verify without review artifacts” invariants. |
| internal/components/sdd/renderer_invariants_test.go | Updates OpenCode orchestrator contract assertions; keeps Kilocode baseline without review lifecycle injection. |
| internal/components/sdd/orchestrator.go | Adjusts bounded-review asset binding call to pass agent identity into renderer. |
| internal/components/sdd/inject.go | Updates delegated authority rule text to atomic START binding retention + non-gating delivery. |
| internal/cli/testdata/review_new_lineage_switch_off/post-apply.golden.json | Removes obsolete gate-result golden (receipt-missing denial no longer emitted). |
| internal/cli/testdata/review_new_lineage_switch_off/pre-commit.golden.json | Removes obsolete gate-result golden (receipt-missing denial no longer emitted). |
| internal/cli/testdata/review_new_lineage_switch_off/pre-push.golden.json | Removes obsolete gate-result golden (receipt-missing denial no longer emitted). |
| internal/cli/testdata/review_new_lineage_switch_off/pre-pr.golden.json | Removes obsolete gate-result golden (receipt-missing denial no longer emitted). |
| internal/cli/testdata/review_new_lineage_switch_off/release.golden.json | Removes obsolete gate-result golden (receipt-missing denial no longer emitted). |
| internal/cli/testdata/byte_equivalence_commit_a/status.golden.json | Removes legacy byte-equivalence status golden tied to receipt-governed delivery. |
| internal/cli/testdata/byte_equivalence_commit_a/start.golden.json | Removes legacy start golden tied to prior v1 envelope shape. |
| internal/cli/testdata/byte_equivalence_commit_a/gate-post-apply.golden.json | Removes legacy allow gate golden tied to receipt-governed delivery. |
| internal/cli/testdata/byte_equivalence_commit_a/gate-pre-commit.golden.json | Removes legacy allow gate golden tied to receipt-governed delivery. |
| internal/cli/testdata/byte_equivalence_commit_a/gate-pre-push.golden.json | Removes legacy allow gate golden tied to receipt-governed delivery. |
| internal/cli/testdata/byte_equivalence_commit_a/gate-pre-pr.golden.json | Removes legacy allow gate golden tied to receipt-governed delivery. |
| internal/cli/testdata/byte_equivalence_commit_a/gate-release.golden.json | Removes legacy allow gate golden tied to receipt-governed delivery. |
| internal/cli/testdata/byte_equivalence_commit_a/finalize.golden.json | Removes legacy finalize golden that surfaced durable receipt path. |
| internal/cli/sync_test.go | Ensures OpenCode orchestrator uses its own identity and post-apply doesn’t renegotiate STATUS. |
| internal/cli/sdd_verify_validate.go | Updates help text to remove “authority-only missing review” skip protocol. |
| internal/cli/sdd_verify_validate_test.go | Updates tests to ensure missing-review skip protocol is not documented. |
| internal/cli/sdd_attempt_rar_mode_read_refusal_unix_test.go | Removes legacy validate entrypoint from unsafe-mode refusal test matrix. |
| internal/cli/review_verification_evidence_test.go | Updates correction finalize assertions to burned-terminal finalize shape. |
| internal/cli/review_validator_inspection_recipe_test.go | Adds targeted validator prompt coverage for frozen policy and causal evidence. |
| internal/cli/review_transport_capability.go | Removes Kilocode from eligible immutable review transport set. |
| internal/cli/review_transition_command_test.go | Uses legacy facade start seam helper for deterministic test bytes. |
| internal/cli/review_submission_descriptor_test.go | Updates descriptor tests for burned authority and disallows re-execution post-burn. |
| internal/cli/review_status_contract.go | Updates repository-context validation logic for correction states (see stored comment). |
| internal/cli/review_start_oversized_candidate_test.go | Requires lineage for negotiated status continuation in oversized candidate test. |
| internal/cli/review_start_contract.go | Updates START action vocabulary handling for v2 (“replayed”) and validates per-contract enums. |
| internal/cli/review_revision_conflict_test.go | Updates conflict test to assert competing writer produces burned terminal shape (no replay after burn). |
| internal/cli/review_restricted_process_temp_test.go | Switches fixtures to legacy facade seam and enforces lineage on negotiated status args. |
| internal/cli/review_repository_context_test.go | Updates repository-context expectations (no synthesized event/outcome for atomic START). |
| internal/cli/review_repair_transition_test.go | Removes obsolete test that asserted abandon exit narration for invalid graph refusal. |
| internal/cli/review_refusal_wording_test.go | Updates validate behavior to be non-deciding and asserts unmanaged gate payload while lineage active. |
| internal/cli/review_recover_self_derivation_test.go | Uses legacy facade seam for predecessor fixture setup (keeps recovery subject real). |
| internal/cli/review_recover_selector_replay_test.go | Requires explicit lineage for selector replay status calls. |
| internal/cli/review_recover_intended_untracked_test.go | Uses legacy facade seam for intended-untracked recovery fixture. |
| internal/cli/review_provider_roles.go | Includes frozen policy in targeted validator prompt and binds validator slot path by request_hash. |
| internal/cli/review_provider_role_materialize_test.go | Updates finalize assertions to burned terminal shape. |
| internal/cli/review_provider_artifact_contract_test.go | Updates pinned schema digests for updated gate-result schema. |
| internal/cli/review_process_boundary_test.go | Updates test to current v2 START action vocabulary (“created”/“replayed”). |
| internal/cli/review_partial_capture_deadend_test.go | Removes assertion that validate is allowed/blocked after abandonment (delivery now unmanaged). |
| internal/cli/review_new_lineage_kill_switch_test.go | Simplifies kill-switch off test (removes new-lineage env var dependency). |
| internal/cli/review_narration.go | Removes staged-delivery-specific stop narration that referenced prior gate-authority behavior. |
| internal/cli/review_mode.go | Removes delivery disposition helper that implied receipt-governed delivery via mode. |
| internal/cli/review_lens_context.go | Replaces START budget refusal to use in-memory atomic START binding (no persisted dead lineage). |
| internal/cli/review_inspect_candidate_test.go | Tightens corrected inspection fixture assertions and verifies burn removes authority/state files. |
| internal/cli/review_historical_compat_test.go | Updates historical resume action to “replayed” and simplifies historical finalize fixtures. |
| internal/cli/review_final_verification_retry_test.go | Uses legacy facade seam for fixtures and preserves burn semantics expectations. |
| internal/cli/review_facade_invalidated_test.go | Updates invalidated authority validate behavior to unmanaged gate payload (no refusal). |
| internal/cli/review_damaged_store_kill_switch_test.go | Updates damaged-store behavior to keep delivery unmanaged and not blocked by unrelated damage. |
| internal/cli/review_context_entrypoints_test.go | Routes review-validate through non-deciding entrypoint. |
| internal/cli/review_consent_relay_test.go | Updates consent relay tests to current action strings (“created”/“replayed”). |
| internal/cli/review_candidate_decline_test.go | Updates declined candidate delivery to unmanaged payload (no fabricated denial/allow). |
| internal/cli/review_candidate_decline_delivery_test.go | Updates declined candidate pre-push/pre-pr/pre-commit delivery expectations to unmanaged payload. |
| internal/cli/review_authority_damage.go | Deletes gate corruption detail helper (gate no longer blocks delivery on review authority damage). |
| internal/cli/review_ambiguous_receipt_continuation_test.go | Deletes obsolete test for ambiguous receipt selection messaging (receipt discovery no longer governs delivery). |
| internal/cli/review_abandon_test.go | Updates abandon tests to reflect new gating semantics and missing setup. |
| internal/assets/windsurf/sdd-orchestrator.md | Updates orchestrator text: gates informational; ordinary repository policy owns delivery. |
| internal/assets/qwen/sdd-orchestrator.md | Same delivery-policy update for Qwen asset. |
| internal/assets/kiro/sdd-orchestrator.md | Same delivery-policy update for Kiro asset. |
| internal/assets/kimi/sdd-orchestrator.md | Same delivery-policy update for Kimi asset. |
| internal/assets/hermes/sdd-orchestrator.md | Same delivery-policy update for Hermes asset. |
| internal/assets/generic/sdd-orchestrator.md | Updates generic orchestrator contract language and removes delivery authorization claims. |
| internal/assets/gemini/sdd-orchestrator.md | Same delivery-policy update for Gemini asset. |
| internal/assets/cursor/sdd-orchestrator.md | Same delivery-policy update for Cursor asset. |
| internal/assets/codex/sdd-orchestrator.md | Same delivery-policy update for Codex asset (delivery remains human-owned). |
| internal/assets/claude/sdd-orchestrator.md | Same delivery-policy update for Claude asset (delivery remains human-owned). |
| internal/assets/antigravity/sdd-orchestrator.md | Same delivery-policy update for Antigravity asset. |
| internal/assets/skills/sdd-verify/references/report-format.md | Removes “authority-only missing review” envelope and clarifies review is not a prerequisite. |
| internal/assets/skills/sdd-apply/SKILL.md | Enforces apply→independent verify→optional review ordering. |
| internal/assets/skills/rdd-defect-workflow/SKILL.md | Mirrors top-level rdd-defect-workflow guidance update. |
| internal/assets/skills/judgment-day/SKILL.md | Clarifies judgments and negotiated review don’t authorize delivery. |
| internal/assets/skills/_shared/sdd-phase-common.md | Treats OpenCode background task acknowledgements as nonterminal (no latch/failure). |
| internal/assets/opencode/plugins/sdd-task-result-artifacts.ts | Accepts optional <summary> and skips validation on background launch acknowledgement events. |
| internal/assets/opencode/commands/sdd-apply.md | Updates OpenCode command text to atomic START binding reuse + burn semantics. |
| internal/assets/claude/commands/sdd-archive.md | Updates archive command text to remove reviewGate/receipt requirements. |
| internal/assets/claude/commands/sdd-apply.md | Updates Claude apply command text to atomic START binding reuse + burn semantics. |
| internal/app/app.go | Routes review-validate CLI command to non-deciding entrypoint. |
| internal/app/app_test.go | Updates dispatch test expectations for review-validate requiring only --cwd. |
| internal/agents/capabilitymanifest/manifest.go | Restricts advertised review transport to Claude/OpenCode/Codex/Pi; others dormant. |
| docs/trigger-rules.md | Updates high-level routing/delivery language to reflect non-governing review context. |
| docs/testing/organic-rdd-testing-guide.md | Marks historical receipt/gate examples as superseded by current policy. |
| docs/testing-agents-deterministically.md | Updates proved/not-proved claims to remove “authorizes delivery” language. |
| docs/intended-usage.md | Updates PR rule text: review provides evidence but never authorizes delivery. |
| docs/community-roadmap.md | Updates roadmap language about RDD semantics (review evidence vs delivery policy). |
| docs/architecture/rdd-freeze-expansion-policy.md | Reframes KEEP surfaces as review-context hooks (not delivery gates). |
| docs/architecture/guard-population.md | Clarifies receipt governance guard is review evidence only, not delivery authority. |
| CONTRIBUTING.md | Moves bench_fixture build guidance to bench/README for opt-in axes. |
| contracts/review-integration/v2/schemas/start.schema.json | Updates START action enum to created/replayed and repository_context requirement condition. |
| contracts/review-integration/v2/schemas/operation.schema.json | Switches v2 operation result to gate-result schema instead of legacy validate def. |
| contracts/review-integration/v2/schemas/gate-result.schema.json | Adds “repository-policy/unmanaged” conditional shape and gate-only context form. |
| contracts/review-integration/v2/schemas/failure.schema.json | Adds target_identity and extends v1 failure constraints via allOf chaining. |
| contracts/review-integration/v1/schemas/targeted-validation-request.schema.json | Adds policy_content and causal finding/classification arrays to targeted validator request. |
| contracts/review-integration/v1/schemas/operation.schema.json | Broadens delivery enum to include unmanaged (not only disabled/unmanaged). |
| contracts/review-integration/v1/schemas/failure.schema.json | Adds target_identity and specific requirements for receipt_publication_pending failures. |
| bench/runner_test.go | Removes sandbox env test for retired receipt mutation path. |
| bench/journeys_transition_test.go | Updates transition corpus phrasing for unbound objective (post-burn semantics). |
| bench/journeys_sdd_test.go | Replaces legacy fail-closed receipt journeys with atomic/burn/continuation journeys. |
| bench/journeys_sdd_shared_scaffolding.go | Rewrites journey to assert unmanaged archive readiness post-burn. |
| bench/journeys_repository_context.go | Updates repository context journey assertions for atomic START (no event/outcome synthesis). |
| bench/journeys_intended_untracked.go | Rewrites journey to assert terminal burn and unmanaged staged validation behavior. |
| bench/journeys_id_collision_test.go | Adds atomic journeys source and filters retired atomic journeys before collision check. |
| bench/journeys_finding_id_prefix.go | Requires exact lineage and uses atomic status for prefix capture. |
| bench/journeys_captured_provider_validator.go | Requires exact active lineage for captured provider validator finalize + burn assertion. |
| bench/axis.go | Adds axis-level review mode declaration and enforces it in validation. |
| bench/axis_source_coupled.go | Removes retired source-coupled axis tied to receipt mutation seam. |
| bench/axis_source_coupled_test.go | Removes corresponding axis registration test. |
| bench/axis_real_world.go | Declares review mode for real-world axis. |
| bench/axis_model_picker.go | Declares untouched review mode for model-picker axis. |
| bench/axis_damaged_store.go | Declares review mode for damaged-store axis. |
| bench/axis_damaged_store_closure.go | Updates bench_fixture crash expectation to fail clearly when tag not present. |
| bench/axis_compatibility.go | Declares review mode for compatibility axis. |
| .deadcode-baseline.txt | Updates baseline after deletions/retirements of now-dead symbols. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| !validReviewCapabilitySHA256(result.RepositoryContext.TargetIdentity) || | ||
| validateReviewRepositoryContextReference(*result.RepositoryContext) != nil || | ||
| result.Authority == nil || result.RepositoryContext.Revision != result.Authority.Revision || | ||
| result.RepositoryContext.TargetIdentity != reviewAuthorityTargetIdentity(result) { | ||
| !correctionTerminalContext && result.RepositoryContext.TargetIdentity != expectedRepositoryContextTarget { | ||
| return errors.New("negotiated STATUS repository context is invalid") // refusal:by-design world-action: the provider-built envelope is internally inconsistent and requires a code fix |
…review feat(review)!: make approval terminal and burn lineage
🔗 Linked Issue
Closes #3417
🏷️ PR Type
type:bug— Bug fix (non-breaking change that fixes an issue)type:feature— New feature (non-breaking change that adds functionality)type:docs— Documentation onlytype:refactor— Code refactoring (no functional changes)type:chore— Build, CI, or tooling changestype:breaking-change— Breaking change📝 Summary
Makes ordinary review atomic: consent → freeze → lenses → one bounded correction and validator → approval → complete burn. Approval leaves Git as the only durable history; compact-v2 is the sole ordinary lifecycle engine.
Review and Judgment Day evidence is informational. Commit, push, PR, release, and SDD archive follow ordinary repository policy and never depend on a receipt or
allowresult.📂 Changes
apply → independent verify → optional review offer → archive; legacy missing-review input cannot suppress verificationbackground: trueacknowledgements no longer emit a false malformed-result failure or latch the sessionCurrent commits:
b43e0928—feat(review)!: make approval terminal and burn lineage3c3b8a02—fix(review): complete atomic lifecycle integration🤖 AI Assistance
Tool/model (if known): Pi coding agent with OpenAI Codex models
Material scope: implementation, tests, documentation, migration analysis, runtime reproduction, and independent verification orchestration
Verification performed: uncached Go root/vet/deadcode/refusal/contracts, CI-equivalent driven bench, focused schemas/renderers/transports, source identity checks, and live OpenCode background-task reproduction after install/sync.
🧪 Test Plan
Driven evidence using externally built candidate binaries:
sdd-explorecompleted without falsesdd_task_result_malformed; artifacts persisted and routing continuedgo test ./benchvalidates declarations only; the driven binary invocation above is the execution proof.🚧 Current Draft Blockers
3c3b8a02.Native review lineage state is informational and is not a delivery or merge gate.
📏 Size Exception Rationale
This PR contains 39,450 changed lines across 380 files (12,471 additions / 26,979 deletions). The majority is deletion of historical multi-engine review surfaces plus their obsolete tests and generated assets. Compact transaction ownership, schemas, CLI, recovery, runtime contracts, docs, and driven journeys form one atomic compatibility migration; splitting them would create intermediate states with incompatible contracts or multiple ordinary lifecycle engines.
Maintainer
size:exceptionis already applied.🤖 Automated Checks
size:exceptionappliedCloses #3417status:approvedstatus:approvedtype:*Labeltype:breaking-changeapplied✅ Contributor Checklist
status:approvedsize:exceptionis applied with rationaletype:*label is appliedCo-Authored-Bytrailers💬 Notes for Reviewers
Review the ownership boundary first: adapters transport opaque reviewer bytes; native Go owns lifecycle, policy, target identity, correction accounting, validation, approval, and burn. STATUS is read-only; FINALIZE owns mutation and restart-safe recovery. Approval burns all authority/evidence. Ordinary delivery remains governed by repository policy, never by review artifacts.
For the OpenCode regression, inspect the temporal boundary:
tool.execute.afteris nonterminal for explicit background tasks. Onlybackground: trueskips terminal validation; foreground empty/malformed results remain fail-closed and session-latched.