Skip to content

feat: add CP-06 workflow review policy - #8

Merged
0xnotdev merged 3 commits into
mainfrom
fm/factory-cp06
Oct 6, 2026
Merged

0xnotdev merged 3 commits into
mainfrom
fm/factory-cp06

Conversation

@0xnotdev

Copy link
Copy Markdown
Owner

Intent

Implement Factory CP-06 only, following landed CP-04 and CP-05. Deliver Pi workflow review/risk policy and a real fresh-context exercise without duplicating Firstmate or no-mistakes validation. BUILD_PLAN.md CP-06, COMPLETION.md P-06/P-07, and docs/WORKFLOW.md risk/review and task-local brief are authoritative. For P-06, take a representative sample of exactly ten bounded task context packs and record authoritative provenance, token counts, observed irrelevant-bulk rate, and missing-source rate; when a required source is missing, demonstrate targeted exact-original reads and corrections without hiding critical constraints. For P-07, prove deterministic low-risk checks happen before expensive semantic review, then repair or block a simulated reviewer finding and retest changed behavior with runnable evidence. Include separate normal API and critical auth-isolation fixtures with negative tests; critical fixtures must use no real accounts or secrets. Execute a genuinely fresh-context worker exercise receiving only task contract, bounded pack, and evidence rather than a prior transcript; observe missing documentation and route the worker to exact originals. Do not embed or call a second no-mistakes pipeline from Factory, hijack Firstmate dispatch, change Firstmate routing/shipping config, invent Factory commands, or add a scheduler/review control plane. Keep the CP-04 skill's implemented command list accurate: doctor, init, validate, context, sync, evidence, status, with Firstmate owning dispatch and shipping. Do not implement CP-07 convenience extensions or CP-08 application work. Prefer minimal changes to skills/factory/SKILL.md, docs/WORKFLOW.md, focused fixtures/tests, and docs/probes/CP-06.md; alter project contracts only when necessary and evidenced. Validate npm ci, format:check, lint, typecheck, npm test, git diff --check, exact tested SHA, changed files, residual risk, and proof at the final candidate. Open a PR against latest main for captain review, but never merge or deploy.

What Changed

  • Defines task-local fresh-context worker briefs, risk classes, review ordering, finding disposition, and no-mistakes/Firstmate boundaries in the workflow docs and Factory skill.
  • Adds CP-06 probe documentation covering ten bounded context packs, missing-source correction, fresh-context exercise, and review/retest outcomes.
  • Adds normal API and critical auth-isolation workflow fixtures with tests for malformed API input, disposable auth credentials, cross-account isolation, and principal-derived ownership.

Risk Assessment

✅ Low: The change is limited to CP-06 workflow documentation/probe evidence and focused executable fixtures, with no production Factory control-plane or dispatch logic changed.

Testing

I verified the target SHA, built only what was needed for the CP-06 workflow fixtures, ran the focused workflow tests, and captured product-level API/auth behavior evidence showing repaired invalid JSON handling and critical disposable auth-isolation negative cases; all targeted checks passed. No screenshot was captured because this change has no rendered UI surface.

Evidence: Focused CP-06 workflow test transcript
$ git rev-parse HEAD
75fed66b626b85223908f9bae7ab200437fb32d4

$ npm run build
npm notice run @factory/core@0.0.0-cp00 build
npm notice run tsc -p tsconfig.json

$ node --test dist/test/workflow.test.js
✔ normal API fixture preserves successful profile behavior (1.476759ms)
✔ normal API fixture rejects malformed, invalid, unknown, and unsupported requests (1.073066ms)
✔ critical auth fixture allows each account to observe its own item (0.31892ms)
✔ critical auth fixture rejects absent and forged fixture credentials (0.139091ms)
✔ critical auth fixture conceals and preserves another account's item (0.249799ms)
✔ critical auth fixture derives new item ownership from the principal (0.178925ms)
ℹ tests 6
ℹ suites 0
ℹ pass 6
ℹ fail 0
ℹ cancelled 0
ℹ skipped 0
ℹ todo 0
ℹ duration_ms 63.346348
Evidence: Observed normal API and critical auth-isolation behavior JSON
{
  "tested_sha": "75fed66b626b85223908f9bae7ab200437fb32d4",
  "normal_api": {
    "success": {
      "status": 200,
      "body": {
        "display_name": "Updated Name"
      }
    },
    "malformed_json": {
      "status": 400,
      "body": {
        "error": "invalid_json"
      }
    },
    "invalid_profile": {
      "status": 400,
      "body": {
        "error": "invalid_profile"
      }
    }
  },
  "critical_auth_isolation": {
    "disposable_fixture_credentials": [
      "fixture-token-a",
      "fixture-token-b"
    ],
    "before": [
      {
        "id": "item-a",
        "owner": "account-a",
        "title": "Private A"
      },
      {
        "id": "item-b",
        "owner": "account-b",
        "title": "Private B"
      }
    ],
    "forged_credentials": {
      "status": 401,
      "body": {
        "error": "unauthorized"
      }
    },
    "cross_account_read": {
      "status": 404,
      "body": {
        "error": "not_found"
      }
    },
    "cross_account_update_attempt": {
      "status": 404,
      "body": {
        "error": "not_found"
      }
    },
    "cross_account_delete_attempt": {
      "status": 404,
      "body": {
        "error": "not_found"
      }
    },
    "after_cross_account_attempts": [
      {
        "id": "item-a",
        "owner": "account-a",
        "title": "Private A"
      },
      {
        "id": "item-b",
        "owner": "account-b",
        "title": "Private B"
      }
    ],
    "forged_owner_create": {
      "status": 201,
      "body": {
        "id": "item-new",
        "title": "Owned by B"
      }
    },
    "account_a_cannot_read_forged_owner_create": {
      "status": 404,
      "body": {
        "error": "not_found"
      }
    },
    "account_b_reads_created_item": {
      "status": 200,
      "body": {
        "id": "item-new",
        "title": "Owned by B"
      }
    },
    "final_state": [
      {
        "id": "item-a",
        "owner": "account-a",
        "title": "Private A"
      },
      {
        "id": "item-b",
        "owner": "account-b",
        "title": "Private B"
      },
      {
        "id": "item-new",
        "owner": "account-b",
        "title": "Owned by B"
      }
    ]
  }
}

Pipeline

Updates from git push no-mistakes

✅ **intent** - passed

✅ No issues found.

✅ **Rebase** - passed

✅ No issues found.

✅ **Review** - passed

✅ No issues found.

✅ **Test** - passed

✅ No issues found.

  • git rev-parse HEAD
  • npm run build
  • node --test dist/test/workflow.test.js
  • Manual evidence script importing the built normal API and critical auth-isolation fixtures and writing observed API responses to workflow-api-behavior.json
✅ **Document** - passed

✅ No issues found.

✅ **Lint** - passed

✅ No issues found.

✅ **Push** - passed

✅ No issues found.

@0xnotdev
0xnotdev merged commit 8b945a4 into main Oct 6, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant