From e66c9004d0c06af49bb4f8d7642a49e104fe3cb6 Mon Sep 17 00:00:00 2001 From: tegwick Date: Mon, 28 Sep 2026 22:45:04 +0200 Subject: [PATCH] chore(consistency): regenerate WORK-RECORDS.md and repo index Co-Authored-By: Claude Sonnet 5.5 Assistant: claude-code Assistant-Model: sonnet Assistant-Process: 270084@bnt-lap001 Assistant-Session: 350b785a-4dfd-4984-a852-dc6cc29bbc4f --- .repo-manager/index.json | 627 +++++++++++++++++++++++++++++++++++++-- WORK-RECORDS.md | 24 +- 2 files changed, 615 insertions(+), 36 deletions(-) diff --git a/.repo-manager/index.json b/.repo-manager/index.json index b9b9c33..f3dabc5 100644 --- a/.repo-manager/index.json +++ b/.repo-manager/index.json @@ -2,9 +2,9 @@ "schema": "repo_manager.index.v1", "slug": "flex-auth", "repo_root": "/home/worsch/flex-auth", - "head_sha": "9f3e7e363a11f611e13d4d798dba575c56168521", - "observed_at": "2026-09-06T12:52:08.174834Z", - "source_fingerprint": "a19f5aa8b0f293bbd5d768adaa50c8afff5c0f0be3757e1b7af62ac791ab228f", + "head_sha": "2dfee5782ec9010758af9ba5a6f72d9fa0fe6234", + "observed_at": "2026-09-27T21:31:30.750263Z", + "source_fingerprint": "ae8eaabaf1593f4ffc27fd498848ff1e5b1bc7d6e7ec040908bd850af97d1fee", "source_files": [ ".repo-classification.yaml", "INTENT.md", @@ -30,7 +30,18 @@ "workplans/FLEX-WP-0018-inbound-auth-corrections.md", "workplans/FLEX-WP-0019-layer-model-conformance.md", "workplans/FLEX-WP-0020-repository-identity-migration.md", - "workplans/FLEX-WP-0021-secrets-engine-consumer-policy-gate.md" + "workplans/FLEX-WP-0021-secrets-engine-consumer-policy-gate.md", + "workplans/FLEX-WP-0022-tenant-scope-coverage.md", + "workplans/FLEX-WP-0023-operator-caller-access-path.md", + "workplans/FLEX-WP-0024-decision-envelope-authenticity.md", + "workplans/FLEX-WP-0025-fact-versus-assertion.md", + "workplans/FLEX-WP-0026-openrouter-native-contract.md", + "workplans/FLEX-WP-0027-t03-human-review.md", + "workplans/FLEX-WP-0028-compact-sitting-review.md", + "workplans/FLEX-WP-0029-stance-register-second-edition.md", + "workplans/FLEX-WP-0030-boundary-declaration-cleanup.md", + "workplans/FLEX-WP-0031-decision-record-emission.md", + "workplans/FLEX-WP-0032-informed-decision-list-action.md" ], "work_records": [ { @@ -1100,7 +1111,7 @@ { "kind": "workplan", "id": "FLEX-WP-0020", - "status": "proposed", + "status": "blocked", "title": "Repository identity migration from flex-auth to access-engine", "source_path": "workplans/FLEX-WP-0020-repository-identity-migration.md", "uuid": "99a661a8-b36c-5c1c-b78b-1e8930bcd0a9", @@ -1110,7 +1121,7 @@ { "kind": "task", "id": "FLEX-WP-0020-T01", - "status": "todo", + "status": "done", "title": "1. Capture immutable cleanliness and identity baseline", "source_path": "workplans/FLEX-WP-0020-repository-identity-migration.md", "uuid": "bb989019-50a7-5273-ba09-b2df2e2602a4", @@ -1120,7 +1131,7 @@ { "kind": "task", "id": "FLEX-WP-0020-T02", - "status": "todo", + "status": "done", "title": "2. Prepare repository metadata and work-record frontmatter", "source_path": "workplans/FLEX-WP-0020-repository-identity-migration.md", "uuid": "102e9dc7-4724-5e80-84c4-092e6ecfbb2b", @@ -1130,7 +1141,7 @@ { "kind": "task", "id": "FLEX-WP-0020-T03", - "status": "todo", + "status": "done", "title": "3. Decide product and runtime naming separately", "source_path": "workplans/FLEX-WP-0020-repository-identity-migration.md", "uuid": "5095ddbc-b69c-5a52-b97f-08fca9b610c3", @@ -1140,7 +1151,7 @@ { "kind": "task", "id": "FLEX-WP-0020-T04", - "status": "todo", + "status": "progress", "title": "4. Inventory consumers and create owned handoffs", "source_path": "workplans/FLEX-WP-0020-repository-identity-migration.md", "uuid": "9bb138e1-5edb-5714-8d89-3b1b7039a7ce", @@ -1150,7 +1161,7 @@ { "kind": "task", "id": "FLEX-WP-0020-T05", - "status": "todo", + "status": "wait", "title": "5. Renew State Hub preflight and record approval", "source_path": "workplans/FLEX-WP-0020-repository-identity-migration.md", "uuid": "86fecbb6-b008-5354-8d70-0f4ba5077a58", @@ -1220,7 +1231,7 @@ { "kind": "workplan", "id": "FLEX-WP-0021", - "status": "active", + "status": "finished", "title": "secrets-engine consumer policy package and cluster-local pin", "source_path": "workplans/FLEX-WP-0021-secrets-engine-consumer-policy-gate.md", "uuid": "b01f655e-f71a-50ae-b110-178557f07c63", @@ -1250,7 +1261,7 @@ { "kind": "task", "id": "FLEX-WP-0021-T03", - "status": "progress", + "status": "done", "title": "3. Confirm the digest join against a real decision record", "source_path": "workplans/FLEX-WP-0021-secrets-engine-consumer-policy-gate.md", "uuid": "8f7e5cdd-777e-5f54-9b92-c72b79f65672", @@ -1260,7 +1271,7 @@ { "kind": "task", "id": "FLEX-WP-0021-T04", - "status": "wait", + "status": "done", "title": "4. Stand up the `flex-auth-secrets-engine` pin", "source_path": "workplans/FLEX-WP-0021-secrets-engine-consumer-policy-gate.md", "uuid": "f4e8709a-65dd-5172-97ae-e7c3432afb22", @@ -1270,13 +1281,567 @@ { "kind": "task", "id": "FLEX-WP-0021-T05", - "status": "wait", + "status": "done", "title": "5. Hand the pin coordinates back and close", "source_path": "workplans/FLEX-WP-0021-secrets-engine-consumer-policy-gate.md", "uuid": "f0828871-fd65-5d8c-adfd-28b13fedd2b0", "parent_id": "FLEX-WP-0021", "extra": {} }, + { + "kind": "workplan", + "id": "FLEX-WP-0022", + "status": "finished", + "title": "Tenant scoping is unstated in tenant-engine and untested in two more packages", + "source_path": "workplans/FLEX-WP-0022-tenant-scope-coverage.md", + "uuid": "804c588c-f47a-50c4-bdd7-51b24bbf9539", + "parent_id": null, + "extra": { + "depends_on": [ + "FLEX-WP-0021" + ] + } + }, + { + "kind": "task", + "id": "FLEX-WP-0022-T01", + "status": "done", + "title": "1. Get the intended tenant relation from tenant-engine", + "source_path": "workplans/FLEX-WP-0022-tenant-scope-coverage.md", + "uuid": "a84dcee5-9426-5b30-8dd3-f4c076d00174", + "parent_id": "FLEX-WP-0022", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0022-T02", + "status": "done", + "title": "2. Encode the relation, or record that there is none", + "source_path": "workplans/FLEX-WP-0022-tenant-scope-coverage.md", + "uuid": "712ac826-845f-54bd-8446-f11258d21eb4", + "parent_id": "FLEX-WP-0022", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0022-T03", + "status": "done", + "title": "3. Vary tenant in the two suites that hold it constant", + "source_path": "workplans/FLEX-WP-0022-tenant-scope-coverage.md", + "uuid": "3058f171-99d2-526b-a1bb-bd7aed87d10a", + "parent_id": "FLEX-WP-0022", + "extra": {} + }, + { + "kind": "workplan", + "id": "FLEX-WP-0023", + "status": "finished", + "title": "Operator caller access path and caller identity in the decision record", + "source_path": "workplans/FLEX-WP-0023-operator-caller-access-path.md", + "uuid": "ad011f92-786c-51ad-b3f6-c06ad77e7af7", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0023-T01", + "status": "done", + "title": "1. Create the ServiceAccount the deployed binding already names", + "source_path": "workplans/FLEX-WP-0023-operator-caller-access-path.md", + "uuid": "10e5a40c-f142-55b9-ab15-fc77c0064ce0", + "parent_id": "FLEX-WP-0023", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0023-T02", + "status": "done", + "title": "2. Run the positive and negative tests and return the receipts", + "source_path": "workplans/FLEX-WP-0023-operator-caller-access-path.md", + "uuid": "79a8d82d-777c-5462-b49d-098f4b7a3b9c", + "parent_id": "FLEX-WP-0023", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0023-T03", + "status": "done", + "title": "3. Flip `callerAuth.mode` to enforce", + "source_path": "workplans/FLEX-WP-0023-operator-caller-access-path.md", + "uuid": "8117c9d8-6efa-5ccf-8ed4-4da2519c3de3", + "parent_id": "FLEX-WP-0023", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0023-T04", + "status": "done", + "title": "4. Record the authenticated caller in the decision record", + "source_path": "workplans/FLEX-WP-0023-operator-caller-access-path.md", + "uuid": "c0e4f31a-cc42-5bd2-b938-d140ecd52e1a", + "parent_id": "FLEX-WP-0023", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0023-T05", + "status": "done", + "title": "5. Report the gap to gate-house as a v0.8 finding", + "source_path": "workplans/FLEX-WP-0023-operator-caller-access-path.md", + "uuid": "d685abfc-cf86-50c8-ad5e-2c04e1531ddd", + "parent_id": "FLEX-WP-0023", + "extra": {} + }, + { + "kind": "workplan", + "id": "FLEX-WP-0024", + "status": "finished", + "title": "Sign the decision envelope: the response channel is unauthenticated", + "source_path": "workplans/FLEX-WP-0024-decision-envelope-authenticity.md", + "uuid": "90577acd-6910-548d-a13e-1dbfdfb8ed27", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0024-T01", + "status": "done", + "title": "1. Publish the stance and stop publishing bare Service names", + "source_path": "workplans/FLEX-WP-0024-decision-envelope-authenticity.md", + "uuid": "b8fad80d-5c44-5e26-a632-5096e0c0f3c5", + "parent_id": "FLEX-WP-0024", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0024-T02", + "status": "done", + "title": "2. Choose the signature shape and key custody", + "source_path": "workplans/FLEX-WP-0024-decision-envelope-authenticity.md", + "uuid": "5482f3cd-36cb-55e0-8c52-0ca2340ed4d7", + "parent_id": "FLEX-WP-0024", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0024-T03", + "status": "done", + "title": "3. Implement signing and verification", + "source_path": "workplans/FLEX-WP-0024-decision-envelope-authenticity.md", + "uuid": "041612ea-1be4-5997-8c32-49f8bcc50855", + "parent_id": "FLEX-WP-0024", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0024-T04", + "status": "done", + "title": "4. Report the gap to gate-house", + "source_path": "workplans/FLEX-WP-0024-decision-envelope-authenticity.md", + "uuid": "82d6b75e-e2c6-5e3d-a897-fbdfb7c9094e", + "parent_id": "FLEX-WP-0024", + "extra": {} + }, + { + "kind": "workplan", + "id": "FLEX-WP-0025", + "status": "finished", + "title": "A policy cannot tell a registry fact from a caller assertion", + "source_path": "workplans/FLEX-WP-0025-fact-versus-assertion.md", + "uuid": "f9a657ce-67b4-5d25-9933-e0fcb2c20b1c", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0025-T01", + "status": "done", + "title": "1. Decide the shape", + "source_path": "workplans/FLEX-WP-0025-fact-versus-assertion.md", + "uuid": "05c6a85d-ee3d-5875-bea4-e9a9c5382e2e", + "parent_id": "FLEX-WP-0025", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0025-T02", + "status": "done", + "title": "2. Audit every package for ceilings read from undeclared keys", + "source_path": "workplans/FLEX-WP-0025-fact-versus-assertion.md", + "uuid": "fc61c8a7-347b-59d2-b6a6-a72c5c1cdb08", + "parent_id": "FLEX-WP-0025", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0025-T03", + "status": "done", + "title": "3. Make the review obligation enforceable rather than written", + "source_path": "workplans/FLEX-WP-0025-fact-versus-assertion.md", + "uuid": "8ee5baf9-b364-5d3e-9c49-d0c9eb014c10", + "parent_id": "FLEX-WP-0025", + "extra": {} + }, + { + "kind": "workplan", + "id": "FLEX-WP-0026", + "status": "finished", + "title": "Resolve OpenRouter access contract and update native PDP", + "source_path": "workplans/FLEX-WP-0026-openrouter-native-contract.md", + "uuid": "e458b337-2373-5fe6-9136-880f45604183", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0026-T01", + "status": "done", + "title": "Resolve the caller versus credential-owner contract", + "source_path": "workplans/FLEX-WP-0026-openrouter-native-contract.md", + "uuid": "d96a05c9-7ea7-53d7-87c9-ffeb19edd5f1", + "parent_id": "FLEX-WP-0026", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0026-T02", + "status": "done", + "title": "Promote and verify the current native PDP contract", + "source_path": "workplans/FLEX-WP-0026-openrouter-native-contract.md", + "uuid": "d85b9e4d-9f9f-5bec-add0-91f434f76f49", + "parent_id": "FLEX-WP-0026", + "extra": {} + }, + { + "kind": "workplan", + "id": "FLEX-WP-0027", + "status": "blocked", + "title": "Admit scoped human review for the three T03 actions", + "source_path": "workplans/FLEX-WP-0027-t03-human-review.md", + "uuid": "954635b2-8377-5227-ab4f-10607b2a02c6", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0027-T01", + "status": "done", + "title": "Implement the explicit group and exact-record mandate", + "source_path": "workplans/FLEX-WP-0027-t03-human-review.md", + "uuid": "7b5af88b-2630-5f94-a085-78180690e08c", + "parent_id": "FLEX-WP-0027", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0027-T02", + "status": "done", + "title": "Deploy the isolated caller-bound policy", + "source_path": "workplans/FLEX-WP-0027-t03-human-review.md", + "uuid": "129568a0-cb1c-5f7b-8f5d-f44f1d2bcfff", + "parent_id": "FLEX-WP-0027", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0027-T03", + "status": "wait", + "title": "Verify actual human review through the native service", + "source_path": "workplans/FLEX-WP-0027-t03-human-review.md", + "uuid": "9417d64a-308c-566f-af29-217c5c45d294", + "parent_id": "FLEX-WP-0027", + "extra": {} + }, + { + "kind": "workplan", + "id": "FLEX-WP-0028", + "status": "finished", + "title": "Admit scoped human review for the seven compact sitting memos", + "source_path": "workplans/FLEX-WP-0028-compact-sitting-review.md", + "uuid": "f7491b94-9f0e-5e5c-a03c-72e70d210807", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0028-T01", + "status": "done", + "title": "Compile the seven-record sitting mandate", + "source_path": "workplans/FLEX-WP-0028-compact-sitting-review.md", + "uuid": "c9c28feb-d735-55a1-adc5-d229ab630f59", + "parent_id": "FLEX-WP-0028", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0028-T02", + "status": "done", + "title": "Deploy the isolated caller-bound policy", + "source_path": "workplans/FLEX-WP-0028-compact-sitting-review.md", + "uuid": "2d9be9d6-b8a0-5018-b5f5-524e72fc6239", + "parent_id": "FLEX-WP-0028", + "extra": {} + }, + { + "kind": "workplan", + "id": "FLEX-WP-0029", + "status": "finished", + "title": "The stance register outgrew the review that read it: five rows, and the divergence was ruled rather than resolved", + "source_path": "workplans/FLEX-WP-0029-stance-register-second-edition.md", + "uuid": "5a11099d-b492-535c-af88-c334db5e8ee6", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0029-T01", + "status": "done", + "title": "1. Record that Finding 1 was ruled, not resolved", + "source_path": "workplans/FLEX-WP-0029-stance-register-second-edition.md", + "uuid": "5a7ed269-974f-5c6a-8e80-e9aa0077f8aa", + "parent_id": "FLEX-WP-0029", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0029-T02", + "status": "done", + "title": "2. Re-run Finding 2 across five rows", + "source_path": "workplans/FLEX-WP-0029-stance-register-second-edition.md", + "uuid": "991ebb94-cdc4-574a-ba60-f8960ec885fc", + "parent_id": "FLEX-WP-0029", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0029-T03", + "status": "done", + "title": "3. Close out Finding 3 against the current file", + "source_path": "workplans/FLEX-WP-0029-stance-register-second-edition.md", + "uuid": "6dd2c9fd-8ad9-54d6-8fb1-f24e44189f00", + "parent_id": "FLEX-WP-0029", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0029-T04", + "status": "done", + "title": "4. Propagate the row count and state the version trigger", + "source_path": "workplans/FLEX-WP-0029-stance-register-second-edition.md", + "uuid": "4dbadd0b-7670-5837-90c9-6201c10479d7", + "parent_id": "FLEX-WP-0029", + "extra": {} + }, + { + "kind": "workplan", + "id": "FLEX-WP-0030", + "status": "finished", + "title": "The layer declaration pins a version it should not, and four security-relevant peers do not declare at all", + "source_path": "workplans/FLEX-WP-0030-boundary-declaration-cleanup.md", + "uuid": "abe60f5f-79cc-5857-b9e8-a46bed704279", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0030-T01", + "status": "done", + "title": "1. Make the declaration version-agnostic", + "source_path": "workplans/FLEX-WP-0030-boundary-declaration-cleanup.md", + "uuid": "016ab184-e814-591b-938b-24ff9ace5ede", + "parent_id": "FLEX-WP-0030", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0030-T02", + "status": "done", + "title": "2. Update SCOPE.md and assess the gaps", + "source_path": "workplans/FLEX-WP-0030-boundary-declaration-cleanup.md", + "uuid": "224cd214-7226-5286-9794-a8a6d36c25e5", + "parent_id": "FLEX-WP-0030", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0030-T03", + "status": "done", + "title": "3. Publish the boundaries review", + "source_path": "workplans/FLEX-WP-0030-boundary-declaration-cleanup.md", + "uuid": "7d45a3d6-d4a7-556a-8607-58086f74a998", + "parent_id": "FLEX-WP-0030", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0030-T04", + "status": "done", + "title": "4. Raise the conflicting and unclear boundaries for resolution", + "source_path": "workplans/FLEX-WP-0030-boundary-declaration-cleanup.md", + "uuid": "70786e6d-02f2-5a90-8640-247ba377d9a4", + "parent_id": "FLEX-WP-0030", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0030-T05", + "status": "done", + "title": "5. Make the survey reproducible", + "source_path": "workplans/FLEX-WP-0030-boundary-declaration-cleanup.md", + "uuid": "a695c139-b831-55a2-b015-445742ee043c", + "parent_id": "FLEX-WP-0030", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0030-T06", + "status": "done", + "title": "6. Fix the validator: four tokens, case folded, scope stated", + "source_path": "workplans/FLEX-WP-0030-boundary-declaration-cleanup.md", + "uuid": "23af18ea-93da-5bd2-9511-e4fce7475dc3", + "parent_id": "FLEX-WP-0030", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0030-T07", + "status": "done", + "title": "7. Publish the per-class emission inventory and register G2 as a dated gap", + "source_path": "workplans/FLEX-WP-0030-boundary-declaration-cleanup.md", + "uuid": "55af504c-482d-5c1a-97e3-7034912308f5", + "parent_id": "FLEX-WP-0030", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0030-T08", + "status": "done", + "title": "8. Rule whether resource.system follows the repository or the runtime", + "source_path": "workplans/FLEX-WP-0030-boundary-declaration-cleanup.md", + "uuid": "cbf8531e-1aa9-5bc4-9f63-ecbbcf987083", + "parent_id": "FLEX-WP-0030", + "extra": {} + }, + { + "kind": "workplan", + "id": "FLEX-WP-0031", + "status": "blocked", + "title": "The decision record has a declared emission guarantee and nothing that delivers it", + "source_path": "workplans/FLEX-WP-0031-decision-record-emission.md", + "uuid": "84f5d9fe-b4c9-584a-b964-efe3e48af095", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0031-T01", + "status": "done", + "title": "1. Decide emission atomicity", + "source_path": "workplans/FLEX-WP-0031-decision-record-emission.md", + "uuid": "2dbc225f-d762-537b-9a24-ab2b17fc2fa2", + "parent_id": "FLEX-WP-0031", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0031-T02", + "status": "wait", + "title": "2. Register flex-auth as an audit-core sender", + "source_path": "workplans/FLEX-WP-0031-decision-record-emission.md", + "uuid": "89661908-ca9a-5e4a-a0a5-62d1a9e02568", + "parent_id": "FLEX-WP-0031", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0031-T03", + "status": "done", + "title": "3. Durable outbox and the release rule", + "source_path": "workplans/FLEX-WP-0031-decision-record-emission.md", + "uuid": "a59603d5-8954-5b05-b1a0-b143c82e439b", + "parent_id": "FLEX-WP-0031", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0031-T05", + "status": "wait", + "title": "5. Heartbeat and drain to audit-core", + "source_path": "workplans/FLEX-WP-0031-decision-record-emission.md", + "uuid": "14bd6648-11da-53d7-a512-027005bd4772", + "parent_id": "FLEX-WP-0031", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0031-T06", + "status": "wait", + "title": "6. Reconciliation, profile check, and storage", + "source_path": "workplans/FLEX-WP-0031-decision-record-emission.md", + "uuid": "bf92a951-3b69-59dd-8907-f6748c91a264", + "parent_id": "FLEX-WP-0031", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0031-T04", + "status": "wait", + "title": "4. Close G2", + "source_path": "workplans/FLEX-WP-0031-decision-record-emission.md", + "uuid": "423b3090-1b72-58fd-9353-5c907c7683bb", + "parent_id": "FLEX-WP-0031", + "extra": {} + }, + { + "kind": "workplan", + "id": "FLEX-WP-0032", + "status": "finished", + "title": "Admit a list action for the informed-decision overview without handing the scope to the consumer", + "source_path": "workplans/FLEX-WP-0032-informed-decision-list-action.md", + "uuid": "ab21b09f-2cb5-5d31-866d-11f02f13f3d8", + "parent_id": null, + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0032-T01", + "status": "done", + "title": "1. Record the decision", + "source_path": "workplans/FLEX-WP-0032-informed-decision-list-action.md", + "uuid": "f741d47e-50b9-5eb1-81d9-ffec847be77a", + "parent_id": "FLEX-WP-0032", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0032-T02", + "status": "done", + "title": "2. Compile compact-sitting v3", + "source_path": "workplans/FLEX-WP-0032-informed-decision-list-action.md", + "uuid": "a24fc5cf-f663-5338-97da-169af7fb47fb", + "parent_id": "FLEX-WP-0032", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0032-T03", + "status": "done", + "title": "3. Fixtures and the exercise receipt", + "source_path": "workplans/FLEX-WP-0032-informed-decision-list-action.md", + "uuid": "984f11f4-6ec9-5f7d-840b-4dee2e121212", + "parent_id": "FLEX-WP-0032", + "extra": {} + }, + { + "kind": "task", + "id": "FLEX-WP-0032-T04", + "status": "done", + "title": "4. Publish and hand back", + "source_path": "workplans/FLEX-WP-0032-informed-decision-list-action.md", + "uuid": "2a296df6-1d39-5b3e-9312-8e791a6ccbd0", + "parent_id": "FLEX-WP-0032", + "extra": {} + }, { "kind": "decision", "id": "FLEX-DEC-2026-001", @@ -1508,7 +2073,7 @@ "status": "resolved", "title": "A claim cannot name the request that carries it: publish approval_binding_digest", "source_path": "decisions/decisions.md", - "uuid": null, + "uuid": "4f0a0de3-1b21-48d1-b157-53bc1f6d03d8", "parent_id": null, "extra": { "record": { @@ -1531,7 +2096,8 @@ "decided_by": "flex-auth (access-engine / PDP)", "rationale": "secrets-engine found that an approval pdp_digest recorded at issue time can never equal the request_digest of a request that carries the claim inside its hashed context, because the claim is part of the context that is hashed. The circularity is structural, not a fixture defect, and it made GH-DEC-2026-008 unimplementable for exactly the dual-control case it was written for. flex-auth owns the canonical request digest, so the resolution is ours. Publishing binding.approval_binding_digest: the same digest computed with context.approval removed, present only when a claim was carried, stable across attaching the claim, and therefore nameable by a pdp_digest recorded at issue. Deliberately additive rather than a redefinition: request_digest keeps covering the claim and remains the replay identity, because two requests differing only in which approval was presented must not share a replay identity when one allows and the other denies dual_control_required. Tests assert the two functions disagree on a claim-bearing request and agree on a claim-free one.", "created": "2026-09-06T12:52:06.960329Z", - "updated": "2026-09-06T12:52:06.960329Z" + "updated": "2026-09-06T12:52:06.960329Z", + "state_hub_decision_id": "4f0a0de3-1b21-48d1-b157-53bc1f6d03d8" } } }, @@ -1610,17 +2176,30 @@ "events": [ { "type": "repo.command.applied", - "command": "repo.work.create_decision", - "operation": "create", - "correlation_id": "e76636be-b773-46de-9bef-eb962c96cf2b", - "kind": "decision", - "id": "FLEX-DEC-2026-007", - "git_sha": null, + "command": "repo.work.update_workplan", + "operation": "update", + "correlation_id": "768db689-1cb9-4afb-ac11-353cf0c00d07", + "workplan_id": "FLEX-WP-0020", + "workplan_uuid": "99a661a8-b36c-5c1c-b78b-1e8930bcd0a9", + "changes": { + "status": "blocked", + "updated": "2026-09-27" + }, + "git_sha": "2dfee5782ec9010758af9ba5a6f72d9fa0fe6234", "files_touched": [ - "decisions/decisions.md" + "workplans/FLEX-WP-0020-repository-identity-migration.md" ], + "expected_head_sha_before": "c3d4f69329b661cb9daaa17c9cba0d00a288a6b8", "source": "repo-manager", - "emitted_at": "2026-09-06T12:52:08.174961Z" + "emitted_at": "2026-09-27T21:31:30.751083Z" + }, + { + "type": "repo.work.indexed", + "correlation_id": "768db689-1cb9-4afb-ac11-353cf0c00d07", + "kind": "workplan", + "id": "FLEX-WP-0020", + "source_path": "workplans/FLEX-WP-0020-repository-identity-migration.md", + "emitted_at": "2026-09-27T21:31:30.751149Z" } ] } diff --git a/WORK-RECORDS.md b/WORK-RECORDS.md index 8e5eda5..dfe3251 100644 --- a/WORK-RECORDS.md +++ b/WORK-RECORDS.md @@ -27,18 +27,18 @@ | workplan | FLEX-WP-0017 | finished | — | workplans/FLEX-WP-0017-action-bound-authorization-contract.md | | workplan | FLEX-WP-0018 | finished | — | workplans/FLEX-WP-0018-inbound-auth-corrections.md | | workplan | FLEX-WP-0019 | finished | — | workplans/FLEX-WP-0019-layer-model-conformance.md | -| workplan | FLEX-WP-0020 | active | — | workplans/FLEX-WP-0020-repository-identity-migration.md | +| workplan | FLEX-WP-0020 | blocked | — | workplans/FLEX-WP-0020-repository-identity-migration.md | | workplan | FLEX-WP-0021 | finished | — | workplans/FLEX-WP-0021-secrets-engine-consumer-policy-gate.md | | workplan | FLEX-WP-0022 | finished | — | workplans/FLEX-WP-0022-tenant-scope-coverage.md | | workplan | FLEX-WP-0023 | finished | — | workplans/FLEX-WP-0023-operator-caller-access-path.md | | workplan | FLEX-WP-0024 | finished | — | workplans/FLEX-WP-0024-decision-envelope-authenticity.md | | workplan | FLEX-WP-0025 | finished | — | workplans/FLEX-WP-0025-fact-versus-assertion.md | | workplan | FLEX-WP-0026 | finished | — | workplans/FLEX-WP-0026-openrouter-native-contract.md | -| workplan | FLEX-WP-0027 | active | — | workplans/FLEX-WP-0027-t03-human-review.md | +| workplan | FLEX-WP-0027 | blocked | — | workplans/FLEX-WP-0027-t03-human-review.md | | workplan | FLEX-WP-0028 | finished | — | workplans/FLEX-WP-0028-compact-sitting-review.md | -| workplan | FLEX-WP-0029 | ready | — | workplans/FLEX-WP-0029-stance-register-second-edition.md | +| workplan | FLEX-WP-0029 | finished | — | workplans/FLEX-WP-0029-stance-register-second-edition.md | | workplan | FLEX-WP-0030 | finished | — | workplans/FLEX-WP-0030-boundary-declaration-cleanup.md | -| workplan | FLEX-WP-0031 | active | — | workplans/FLEX-WP-0031-decision-record-emission.md | +| workplan | FLEX-WP-0031 | blocked | — | workplans/FLEX-WP-0031-decision-record-emission.md | | workplan | FLEX-WP-0032 | finished | — | workplans/FLEX-WP-0032-informed-decision-list-action.md | | task | FLEX-WP-0001-T001 | done | — | workplans/FLEX-WP-0001-repo-intent-and-architecture-baseline.md | | task | FLEX-WP-0001-T002 | done | — | workplans/FLEX-WP-0001-repo-intent-and-architecture-baseline.md | @@ -130,7 +130,7 @@ | task | FLEX-WP-0020-T01 | done | — | workplans/FLEX-WP-0020-repository-identity-migration.md | | task | FLEX-WP-0020-T02 | done | — | workplans/FLEX-WP-0020-repository-identity-migration.md | | task | FLEX-WP-0020-T03 | done | — | workplans/FLEX-WP-0020-repository-identity-migration.md | -| task | FLEX-WP-0020-T04 | progress | — | workplans/FLEX-WP-0020-repository-identity-migration.md | +| task | FLEX-WP-0020-T04 | wait | — | workplans/FLEX-WP-0020-repository-identity-migration.md | | task | FLEX-WP-0020-T05 | wait | — | workplans/FLEX-WP-0020-repository-identity-migration.md | | task | FLEX-WP-0020-T06 | wait | — | workplans/FLEX-WP-0020-repository-identity-migration.md | | task | FLEX-WP-0020-T07 | wait | — | workplans/FLEX-WP-0020-repository-identity-migration.md | @@ -165,10 +165,10 @@ | task | FLEX-WP-0027-T03 | wait | — | workplans/FLEX-WP-0027-t03-human-review.md | | task | FLEX-WP-0028-T01 | done | — | workplans/FLEX-WP-0028-compact-sitting-review.md | | task | FLEX-WP-0028-T02 | done | — | workplans/FLEX-WP-0028-compact-sitting-review.md | -| task | FLEX-WP-0029-T01 | todo | — | workplans/FLEX-WP-0029-stance-register-second-edition.md | -| task | FLEX-WP-0029-T02 | todo | — | workplans/FLEX-WP-0029-stance-register-second-edition.md | -| task | FLEX-WP-0029-T03 | todo | — | workplans/FLEX-WP-0029-stance-register-second-edition.md | -| task | FLEX-WP-0029-T04 | todo | — | workplans/FLEX-WP-0029-stance-register-second-edition.md | +| task | FLEX-WP-0029-T01 | done | — | workplans/FLEX-WP-0029-stance-register-second-edition.md | +| task | FLEX-WP-0029-T02 | done | — | workplans/FLEX-WP-0029-stance-register-second-edition.md | +| task | FLEX-WP-0029-T03 | done | — | workplans/FLEX-WP-0029-stance-register-second-edition.md | +| task | FLEX-WP-0029-T04 | done | — | workplans/FLEX-WP-0029-stance-register-second-edition.md | | task | FLEX-WP-0030-T01 | done | — | workplans/FLEX-WP-0030-boundary-declaration-cleanup.md | | task | FLEX-WP-0030-T02 | done | — | workplans/FLEX-WP-0030-boundary-declaration-cleanup.md | | task | FLEX-WP-0030-T03 | done | — | workplans/FLEX-WP-0030-boundary-declaration-cleanup.md | @@ -180,9 +180,9 @@ | task | FLEX-WP-0031-T01 | done | — | workplans/FLEX-WP-0031-decision-record-emission.md | | task | FLEX-WP-0031-T02 | wait | — | workplans/FLEX-WP-0031-decision-record-emission.md | | task | FLEX-WP-0031-T03 | done | — | workplans/FLEX-WP-0031-decision-record-emission.md | -| task | FLEX-WP-0031-T04 | todo | — | workplans/FLEX-WP-0031-decision-record-emission.md | -| task | FLEX-WP-0031-T05 | todo | — | workplans/FLEX-WP-0031-decision-record-emission.md | -| task | FLEX-WP-0031-T06 | todo | — | workplans/FLEX-WP-0031-decision-record-emission.md | +| task | FLEX-WP-0031-T04 | wait | — | workplans/FLEX-WP-0031-decision-record-emission.md | +| task | FLEX-WP-0031-T05 | wait | — | workplans/FLEX-WP-0031-decision-record-emission.md | +| task | FLEX-WP-0031-T06 | wait | — | workplans/FLEX-WP-0031-decision-record-emission.md | | task | FLEX-WP-0032-T01 | done | — | workplans/FLEX-WP-0032-informed-decision-list-action.md | | task | FLEX-WP-0032-T02 | done | — | workplans/FLEX-WP-0032-informed-decision-list-action.md | | task | FLEX-WP-0032-T03 | done | — | workplans/FLEX-WP-0032-informed-decision-list-action.md |