hub-core/workplans/HUB-WP-0011-statehub-inbox-freshness-and-cutover.md

90 lines
3.4 KiB
Markdown
Raw Normal View History

---
id: HUB-WP-0011
type: workplan
title: "State Hub inbox freshness and reader cutover"
domain: infotech
repo: hub-core
Close HUB-WP-0009 conformance gaps (C2, C7, C9, C10); mark blocked workplans Implements the four residual conformance checks left open by the T04 minimal vertical: - C2: GET /ports/registry/registrations/{hub_slug} resolves missing (404), ambiguous (shared reuse_surface_id across hub_slugs), and stale (deprecated/retired descriptor) registrations; a new .../audit route exposes queryable registration history from the existing in-memory history and the PostgreSQL runtime_audit_ledger. - C7: harness proof that disabled compatibility groups deny access (404) with no fixture credentials involved, matching the existing fail-closed compat router behavior. - C9: harness proof plus a dedicated test that /readyz degrades only on an unavailable configured dependency while unrelated disabled projections stay non-blocking. - C10: ContractValidator now negotiates contract_version_min/max against the runtime's contract version and rejects incompatible or inverted ranges with an explicit 422 instead of silently accepting them. HUB-WP-0009 is now finished. HUB-WP-0006 is marked blocked: its only open task (T06) has no remaining hub-core code path and waits on an external Forgejo identity/production deployment gate. HUB-WP-0011 is marked blocked: T02/T03 already waited on external credential/deployment review, and T01 needs a source/destination ownership and retention decision against live message data before it can be implemented safely. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: sonnet Assistant-Process: 310936@bnt-lap001 Assistant-Session: 00cd9abe-09a0-416b-88e0-f907b9101629
2026-09-27 23:59:35 +02:00
status: blocked
flavor: residual
owner: codex
topic_slug: infotech
created: "2026-09-05"
Close HUB-WP-0009 conformance gaps (C2, C7, C9, C10); mark blocked workplans Implements the four residual conformance checks left open by the T04 minimal vertical: - C2: GET /ports/registry/registrations/{hub_slug} resolves missing (404), ambiguous (shared reuse_surface_id across hub_slugs), and stale (deprecated/retired descriptor) registrations; a new .../audit route exposes queryable registration history from the existing in-memory history and the PostgreSQL runtime_audit_ledger. - C7: harness proof that disabled compatibility groups deny access (404) with no fixture credentials involved, matching the existing fail-closed compat router behavior. - C9: harness proof plus a dedicated test that /readyz degrades only on an unavailable configured dependency while unrelated disabled projections stay non-blocking. - C10: ContractValidator now negotiates contract_version_min/max against the runtime's contract version and rejects incompatible or inverted ranges with an explicit 422 instead of silently accepting them. HUB-WP-0009 is now finished. HUB-WP-0006 is marked blocked: its only open task (T06) has no remaining hub-core code path and waits on an external Forgejo identity/production deployment gate. HUB-WP-0011 is marked blocked: T02/T03 already waited on external credential/deployment review, and T01 needs a source/destination ownership and retention decision against live message data before it can be implemented safely. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: sonnet Assistant-Process: 310936@bnt-lap001 Assistant-Session: 00cd9abe-09a0-416b-88e0-f907b9101629
2026-09-27 23:59:35 +02:00
updated: "2026-09-27"
origin: residual
origin_ref: HUB-WP-0010
related:
- STATE-WP-0079
- RAPPCOREHUB-WP-0004
state_hub_workstream_id: "3c8034fc-fd90-58f5-99bc-99b4f93e5ee1"
---
## Establish ongoing inbox freshness
```task
id: HUB-WP-0011-T01
status: todo
flavor: residual
priority: high
state_hub_task_id: "588e4b58-4694-513c-8e7a-1fab38fb6ce3"
```
The deployed inbox reader is an explicitly labeled one-time snapshot pilot.
Define and implement monotonic source revision/cursor semantics, atomic refresh,
read/archive updates, deletes/retention treatment and stale-source signaling.
The initial importer deliberately refuses different existing rows; do not turn
it into an unconditional overwrite loop. Prove recovery and idempotency without
creating a second message writer. Decide the source/destination ownership
boundary before live client traffic moves.
Close HUB-WP-0009 conformance gaps (C2, C7, C9, C10); mark blocked workplans Implements the four residual conformance checks left open by the T04 minimal vertical: - C2: GET /ports/registry/registrations/{hub_slug} resolves missing (404), ambiguous (shared reuse_surface_id across hub_slugs), and stale (deprecated/retired descriptor) registrations; a new .../audit route exposes queryable registration history from the existing in-memory history and the PostgreSQL runtime_audit_ledger. - C7: harness proof that disabled compatibility groups deny access (404) with no fixture credentials involved, matching the existing fail-closed compat router behavior. - C9: harness proof plus a dedicated test that /readyz degrades only on an unavailable configured dependency while unrelated disabled projections stay non-blocking. - C10: ContractValidator now negotiates contract_version_min/max against the runtime's contract version and rejects incompatible or inverted ranges with an explicit 422 instead of silently accepting them. HUB-WP-0009 is now finished. HUB-WP-0006 is marked blocked: its only open task (T06) has no remaining hub-core code path and waits on an external Forgejo identity/production deployment gate. HUB-WP-0011 is marked blocked: T02/T03 already waited on external credential/deployment review, and T01 needs a source/destination ownership and retention decision against live message data before it can be implemented safely. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: sonnet Assistant-Process: 310936@bnt-lap001 Assistant-Session: 00cd9abe-09a0-416b-88e0-f907b9101629
2026-09-27 23:59:35 +02:00
Loose-ends review 2026-09-27: left `todo`, not implemented in this pass. This
task's own scope calls for a source/destination ownership boundary decision —
who is authoritative for a message once both State Hub and hub-core hold a
copy, and what "deletes/retention treatment" means for messages State Hub no
longer serves (archive locally, tombstone, or refuse) — before writing the
monotonic-cursor and upsert logic that would encode that decision durably
against live message data. That is the same kind of call this workplan's T02
requires external review for, and it should not be made unilaterally in a
loose-ends pass. Recommend Bernd (or a follow-up session with that decision
in hand) confirms the ownership/retention boundary, after which the cursor
and upsert implementation is a bounded, mechanical follow-on to the existing
`import_snapshot` in `hub_core/runtime/inbox_projection.py`.
## Admit the actual reader identity and full scope semantics
```task
id: HUB-WP-0011-T02
status: wait
flavor: residual
priority: high
state_hub_task_id: "35c5ae8b-f357-512f-af40-bc5915f3c02d"
```
Replace pilot operator authentication with the reviewed caller-specific access
contract and delivered workload credential. Preserve recipient authorization,
broadcast behavior, repository canonical/alias resolution, source timestamps
and thread/read/archive semantics for the selected reader. The existing pilot
supports only one literal agent and exact sender filters. Never distribute the
operator token as an application credential.
2026-09-28 integration dependency: `HUB-WP-0012-T02` through `T05` own the
shared NetKingdom identity, policy and workload-caller contract. Reuse that
contract here; this task retains inbox-specific recipient/alias semantics.
The root-only human milestone does not authorize an automated reader as root
or close the freshness and reader-switch tasks.
## Execute one reviewed client switch
```task
id: HUB-WP-0011-T03
status: wait
flavor: residual
priority: high
state_hub_task_id: "61c727a5-f4b1-54c0-b634-7d71a5416496"
```
After T01/T02 pass, produce live freshness and parity receipts for one State Hub
inbox reader; verify rollback to the current State Hub endpoint. Then execute
that bounded reader switch with the concrete deployment authorization. Retire
its compatibility dependency only after metered acceptance. Message-writer
cutover and all other route families remain separate STATE-WP-0079 work.