Skip to content

feat: inspect retained full text in private pending review views - #37

Draft
seonghobae wants to merge 16 commits into
codex/zotero-fulltext-capturefrom
codex/zotero-fulltext-review-context
Draft

feat: inspect retained full text in private pending review views#37
seonghobae wants to merge 16 commits into
codex/zotero-fulltext-capturefrom
codex/zotero-fulltext-review-context

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

Verified local approval-order repair — 2026-09-06 checkpoint

Exact head: codex/zotero-fulltext-review-context@692cb588b26a9cc878fbaa2b47aa30fd83ea47de. Exact base: codex/zotero-fulltext-capture@87f02a91a9b5ea83ae842ef6b7eb83141aebfd66.

Original planner owner #13 preserves regression 505e111c993d8269e5b7b9e17a25a5ce20f8606e and repair 8a684882005085d8b3cb47812e185975084e0475. Every existing local request/mode/item/metadata check finishes before the external approval verifier. Invalid requests invoke it zero times; valid complete requests invoke it exactly once. Local validation errors intentionally precede approval denial. Deterministic operations and complete before/after/rollback metadata are unchanged.

This exact head passed locked Rust 1.98.0 workspace tests (213 tests / 39 unfiltered suites, doctests included), strict all-target Clippy, formatting, warnings-denied rustdoc, CI contract and diff checks before normal push. Normal parent integration retains both the prior child and verified parent as ancestors. Coverage from another stack head is not attributed to this head.

Keep Draft behind the existing prerequisite stack. This is local verification, not hosted current-head GREEN, independent approval, protected merge or release. No later full-text feature was reverse-merged into an earlier owner. Full-text-aware write admission, authentic decisions and independent authority remain separate gaps; no real Zotero/model request, label, approval or write was performed for this repair.

Earlier coordinates and status claims below are historical.

Prior PR description, retained without discarding evidence

Current repair checkpoint — 2026-09-05

Exact head: a41306a96f67388998c8c8bfdf24d70049bcf15a. Named base: codex/zotero-fulltext-capture at 6b33c071a6e1ded610fc9634db51f7a56ed90868 when checked.

This ordinary merge retains old head bdeaa19fe6281563dbb7a1387db43aadd1f5c5a2 and its repaired named parent as ancestors. It carries PR #29's earliest-owner static private-JSON diagnostic, inclusive 16 MiB pre-create metadata writer guard and regression tests, plus PR #28's fixture warning repair. Existing child functionality remains intact; full-text features were not reverse-merged into earlier owners.

This exact head passed cargo +1.98.0 test --locked --workspace (208 tests across 39 unfiltered suites, including doctests), strict Clippy across all targets, formatting, warnings-denied rustdoc, the CI contract check and git diff --check. Nested filtered subprocess results are not counted twice. Coverage was not rerun at this particular new head; historical or later-child coverage is not transferred to it.

Normal push preserves history and the existing Draft/prerequisite boundary. These are local results, not hosted current-head GREEN or independent protected approval. All required reviews/checks must be revalidated on the unchanged current head after prerequisites integrate. No force push, close, retarget, self-approval, dismissal, protected merge, new label, model request or Zotero write occurred. Authentic decisions and independently approved labels remain separately 0/3,715.

Preserved earlier description and historical checkpoints

Outcome

Adds an offline private view of the next pending papers with their already-retained full text. This is a Draft child of #36 (codex/zotero-fulltext-capture at 1e7d23c91116d84a455b6e6e5a6fb00a5e004c04), preserving all prerequisite deltas by ordinary merges. It does not replace or close #36, change predictions, apply decisions, confer approval, or publish semantic truth.

Contract and boundaries

  • --full-text-review REPORT WORKSHEET CAPTURE LIMIT OUTPUT reuses the canonical pending selector, full capture verifier and single-open owner-only file boundary.
  • The versioned, nonflattened view binds the capture, complete report and original proposal digest. It retains exact direct-parent responses and separate metadata/content versions, including missing/empty/partial/unknown evidence. Unselected and standalone attachments are not copied.
  • Metadata files remain bounded at 16 MiB. Capture JSON is buffered under a separate 512 MiB file limit with exact-boundary/size-drift/trailing-data rejection and static errors. The capture's 256 MiB raw-body budget is a different boundary.
  • Serialization uses the standard library's fixed 16 MiB slice; escaping overflow fails without truncation. Output is create-new, single-link and mode 0600; originals remain unchanged.
  • Both existing decision-application modes reject this outer view. Full-text context through decision application, worksheet history, finalization and fresh external approval remains the next gap. Stripping the envelope does not preserve that provenance.

Committed RED -> repair -> verification

Core RED 0027d7d -> GREEN e426c2b; five further boundary tests at 3fb930b/fcba236. The earlier incorrectly filtered zero-test invocation is not RED evidence. CLI RED 25a1005 -> implementation 045031c -> strict-warning correction ed308bd -> test-only coverage/read-ceiling correction 26a3e6a. Normal merges b86fe86 and 54383eae2e83863c4cb72ee00f16cd504ff66151 preserve both histories.

At 54383ea: 201 workspace tests across 38 unfiltered suites, including three doctests, pass; the nested subprocess is not counted twice. Strict Clippy, formatting, warnings-denied rustdoc, CI contract and the existing coverage gate pass. Coverage: 359/359 functions, 3982/3982 source-normalized regions and 692/692 branch outcomes. Raw LLVM is 4322/4430 lines, 6314/6500 regions and 612/692 branches, not raw 100%. No exclusion or dependency added. Independent documentation/core and integrated-source inspections found no actionable regression; they are not protected approval.

Actual saved-data evidence

A release-profile invocation at 54383ea read only the existing private repaired report, worksheet and capture. It generated 25 canonical pending rows: 21 with nonempty text, four without text, 21 HTTP 200 responses, 16 complete and five unknown index-counter results. Command elapsed 1.60 seconds; maximum resident memory 288014336 bytes. This single local run is not a latency/load SLO.

The new private file is 1590742 bytes, mode 0600, single-link; SHA-256 e99a1963f3b5d7adfb62070785f2b69f1d9efd1d4882d365a5ca6f6b8d70f34a. An independent aggregate-only audit recomputed capture/report/proposal digests, compared exact selected parent/version/body projection and confirmed the nested batch matches the old batch. Original report/worksheet/capture/batch hashes remain unchanged. No titles, item identities, text, reviewer/server identities or credentials are published.

Pending rows with an evidence view: 0 -> 25, including 21 with nonempty captured text and four without it. Bibliographic denominator and remaining decisions: 3715. New text-bound proposals, authentic steward decisions and externally approved labels: 0. Zotero requests, model calls and source mutations in this increment: 0.

Traceability and acceptance

PRD FR-9, TRD, Proposed ADR 0006, Context Map, Ubiquitous Language, UML, architecture, threat model, contributor rules, CHANGELOG and Gap baseline are updated. Aggregate record: docs/doctoring/zotero_fulltext_review_evidence.json; detailed chronology: docs/doctoring/zotero_fulltext_contract_audit.md.

The published head's runtime tree is identical to tested 54383ea; documentation follow-ups do not renew hosted evidence. Current-head hosted checks, independent review and prerequisite protected merges remain outstanding. Foundation is still unshipped beyond bootstrap main; no immutable ConceptWeave release or qualifying CO adoption is claimed. No new service/Utility Repository, source copying, model/provider bypass, force push, self-approval, dismissal or Admin bypass.

Post-measurement documentation review identified two wording issues: total review-view rows were too easily confused with text-bearing rows, and the contacted CO integration task was attributed as the #1030 release writer. Follow-up 6b9f2ef distinguishes 25/21/4 explicitly and leaves actual release-owner confirmation pending; bdeaa19 only links this Draft PR. No runtime code or authority claim changes.

@coderabbitai

coderabbitai Bot commented Sep 5, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant