Skip to content

feat(zotero): export bounded steward review batches - #33

Draft
seonghobae wants to merge 33 commits into
autoresearch/zotero-review-decision-clifrom
autoresearch/zotero-steward-review-batch
Draft

feat(zotero): export bounded steward review batches#33
seonghobae wants to merge 33 commits into
autoresearch/zotero-review-decision-clifrom
autoresearch/zotero-steward-review-batch

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 4, 2026

Copy link
Copy Markdown
Contributor

Verified local approval-order repair — 2026-09-06 checkpoint

Exact head: autoresearch/zotero-steward-review-batch@18932783aeb336a6d58e8a19f6d7dd6ecfb9ab3a. Exact base: autoresearch/zotero-review-decision-cli@f0bf02a8a600924d254adfa7b4796aa2ef868165.

Original planner owner #13 preserves regression 505e111c993d8269e5b7b9e17a25a5ce20f8606e and repair 8a684882005085d8b3cb47812e185975084e0475. Every existing local request/mode/item/metadata check finishes before the external approval verifier. Invalid requests invoke it zero times; valid complete requests invoke it exactly once. Local validation errors intentionally precede approval denial. Deterministic operations and complete before/after/rollback metadata are unchanged.

This exact head passed locked Rust 1.98.0 workspace tests (163 tests / 36 unfiltered suites, doctests included), strict all-target Clippy, formatting, warnings-denied rustdoc, CI contract and diff checks before normal push. Normal parent integration retains both the prior child and verified parent as ancestors. Coverage from another stack head is not attributed to this head.

Keep Draft behind the existing prerequisite stack. This is local verification, not hosted current-head GREEN, independent approval, protected merge or release. No later full-text feature was reverse-merged into an earlier owner. Full-text-aware write admission, authentic decisions and independent authority remain separate gaps; no real Zotero/model request, label, approval or write was performed for this repair.

Earlier coordinates and status claims below are historical.

Prior PR description, retained without discarding evidence

Current repair checkpoint — 2026-09-05

Exact head: e6a94178c929b47a23a2ef3d5b00afba5a997363. Named base: autoresearch/zotero-review-decision-cli at bd7669d28abfd3476106362b790198f6dd9d2e2c when checked.

This ordinary merge retains old head ecddb799d1dc968e26614c735c9c345cba1182ee and its repaired named parent as ancestors. It carries PR #29's earliest-owner static private-JSON diagnostic, inclusive 16 MiB pre-create metadata writer guard and regression tests, plus PR #28's fixture warning repair. Existing child functionality remains intact; full-text features were not reverse-merged into earlier owners.

This exact head passed cargo +1.98.0 test --locked --workspace (158 tests across 36 unfiltered suites, including doctests), strict Clippy across all targets, formatting, warnings-denied rustdoc, the CI contract check and git diff --check. Nested filtered subprocess results are not counted twice. Coverage was not rerun at this particular new head; historical or later-child coverage is not transferred to it.

Normal push preserves history and the existing Draft/prerequisite boundary. These are local results, not hosted current-head GREEN or independent protected approval. All required reviews/checks must be revalidated on the unchanged current head after prerequisites integrate. No force push, close, retarget, self-approval, dismissal, protected merge, new label, model request or Zotero write occurred. Authentic decisions and independently approved labels remain separately 0/3,715.

Preserved earlier description and historical checkpoints

Current source-integrity note — 2026-09-05

  • Exact head: autoresearch/zotero-steward-review-batch@cdc7f697fd72e41947e70dc05e42dae7e3b4a712.
  • Exact base: autoresearch/zotero-review-decision-cli@8c9eac55c904916334637c03c6f9c3621a2084bc.
  • This head inherits PR feat(research): add steward golden-set evaluation #10 root e7d4e59f1b55b5954c5f8436527bc96e7ef2fb13 through ordinary merge ancestry. The source-snapshot digest binds complete captured raw provider JSON and the actual typed classifier inputs; source evidence and derived proposals retain separate identities.
  • GoldenSetApproval.proposal_digest is required and binds the complete proposal records used for evaluation. The current proposal digest is checked before the caller-owned governance verifier. Do not backfill old receipts: regenerate evidence and obtain a new approval bound to the reviewed evidence.
  • Keep Draft. This note does not claim current exact-head hosted GREEN, independent approval, protected merge, live Zotero mutation, or governed publication. Root, predecessor, and terminal-stack local test evidence is not transferred as per-PR hosted evidence.

Earlier heads, runtime snapshots, campaign counts, and verification statements below are historical notes, not current acceptance evidence.

Historical PR notes — original text retained

Outcome

Provide deterministic owner-only review batches so a human steward can work through the 3,715-record campaign in bounded patch-compatible units without inventing labels or copying the full report.

Current exact stack — 2026-09-05

Contract

--review-batch REPORT CURRENT_WORKSHEET LIMIT BATCH accepts 1–100 rows, selects the first pending decisions in canonical item-key order, skips already decided rows, and is deterministic/non-reserving on unchanged input. It retains only the sensitive human-visible context necessary for review and omits broader snapshot/audit/approval state. Owner-only, bounded, no-follow input and create-new 0600 output protections remain in force.

Completed batch JSON is not directly authoritative. #34 reconstructs the exact expected pending batch from immutable report/worksheet state, compares all displayed context, and only then converts completed decisions to the atomic patch boundary.

No live steward decision, Zotero mutation, reservation/assignment, governance approval or publication is claimed. Unverified worksheet decisions and externally approved labels remain separately 0 / 3,715.

Merge gate

Keep Draft behind #32 and the full predecessor stack. Require one unchanged exact head with terminal Product/security/SAST/dependency/review evidence, independent approval where applicable, and zero valid unresolved findings. No force-push, destructive rebase, self-approval, predecessor-evidence transfer, live Zotero mutation or authority promotion.

@coderabbitai

coderabbitai Bot commented Sep 4, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@seonghobae

Copy link
Copy Markdown
Contributor Author

@coderabbitai full review

@coderabbitai

coderabbitai Bot commented Sep 4, 2026

Copy link
Copy Markdown
⚠️ Action not completed

Review rate limited.


Your included review limit is currently reached under our Fair Usage Limits Policy. This review may still proceed through usage-based billing if eligible. Your next included review will be available in 23 minutes.

@seonghobae

Copy link
Copy Markdown
Contributor Author

@coderabbitai full review

@coderabbitai

coderabbitai Bot commented Sep 4, 2026

Copy link
Copy Markdown
⚠️ Action not completed

Review rate limited.


Your included review limit is currently reached under our Fair Usage Limits Policy. This review may still proceed through usage-based billing if eligible. Your next included review will be available in 18 minutes.

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Current-head review at 03dafd3cb47fa0568dd9fa0ac8f7b565c3b07d0b found no new actionable semantic/security defect in the bounded review-batch slice. The implementation validates the worksheet against the canonical report before selecting pending rows, preserves canonical decision order, binds library/rule/snapshot/item revision coordinates, keeps the batch non-reserving, and reuses the repaired owner-only private-artifact boundary inherited from #30. The completed batch remains only patch-shaped local input; it does not create approval or publication authority. Exact-head hosted check-runs are currently absent, so the local test/coverage evidence in the PR body is not treated as protected GREEN and Draft status remains appropriate.

@seonghobae

Copy link
Copy Markdown
Contributor Author

@coderabbitai full review

@coderabbitai

coderabbitai Bot commented Sep 4, 2026

Copy link
Copy Markdown

Rate Limit Exceeded

@seonghobae have exceeded the limit for the number of chat messages per hour. Please wait 1 minutes and 41 seconds before sending another message.

@seonghobae

Copy link
Copy Markdown
Contributor Author

@coderabbitai full review

@coderabbitai

coderabbitai Bot commented Sep 4, 2026

Copy link
Copy Markdown
⚠️ Action not completed

Review rate limited.


Your included review limit is currently reached under our Fair Usage Limits Policy. This review may still proceed through usage-based billing if eligible. Your next included review will be available in 6 minutes.

Copy link
Copy Markdown
Contributor Author

Current-stack correction (2026-09-05): exact base #32 a5ba0ebde3b647df687c13f48bbe17130cc9bba3; exact head 6a9bf638ae845cc6953474e56d65936b21287e76. Bounded steward-review-batch semantics are preserved by non-force restack; no assignment/approval/Zotero mutation is implied and older body SHAs are historical.

Copy link
Copy Markdown
Contributor Author

Live authority correction (2026-09-05): GitHub's current PR fields are base_sha=2483d253d7a2dd5b4934d99f734ddb9f1a8d6ade (#32) and head_sha=ecddb799d1dc968e26614c735c9c345cba1182ee, Draft/open/mergeable. The body header's cdc7f697... / 8c9eac55... coordinates are predecessor checkpoints, not the current PR edge. Preserve their evidence as lineage only; current-head Product/security/review evidence remains independently required. No source/restack mutation is made by this correction.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant