From 27b8e916cc5a4c4507b783fc50c7cdd975d57f45 Mon Sep 17 00:00:00 2001 From: tegwick Date: Mon, 14 Sep 2026 17:08:39 +0200 Subject: [PATCH] Draft unsigned credential and decision sign-off batches. MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit INFD-WP-0002 T01–T02: eight one-question memos for net-kingdom-admins, batch contract without approve-all, no live bind (T08 still open). Assistant: grok Assistant-Session: 01a09dc1-b21e-77e1-919e-fcad2f82b267 --- docs/batches/2026-09-14/README.md | 21 + .../batches/2026-09-14/credentials/index.json | 60 +++ .../credentials/infd-20260914-c01.memo.json | 1 + .../credentials/infd-20260914-c01.packet.md | 16 + .../credentials/infd-20260914-c02.memo.json | 1 + .../credentials/infd-20260914-c02.packet.md | 15 + .../credentials/infd-20260914-c03.memo.json | 1 + .../credentials/infd-20260914-c03.packet.md | 15 + .../credentials/infd-20260914-c04.memo.json | 1 + .../credentials/infd-20260914-c04.packet.md | 15 + docs/batches/2026-09-14/decisions/index.json | 60 +++ .../decisions/infd-20260914-d01.memo.json | 1 + .../decisions/infd-20260914-d01.packet.md | 15 + .../decisions/infd-20260914-d02.memo.json | 1 + .../decisions/infd-20260914-d02.packet.md | 16 + .../decisions/infd-20260914-d03.memo.json | 1 + .../decisions/infd-20260914-d03.packet.md | 15 + .../decisions/infd-20260914-d04.memo.json | 1 + .../decisions/infd-20260914-d04.packet.md | 15 + docs/batches/2026-09-14/sitting.json | 13 + docs/specs/CompactSignoffBatches.md | 52 +++ tests/test_compact_batches.py | 40 ++ tools/prepare_compact_batches.py | 380 ++++++++++++++++++ .../INFD-WP-0002-compact-signoff-batches.md | 12 +- 24 files changed, 765 insertions(+), 3 deletions(-) create mode 100644 docs/batches/2026-09-14/README.md create mode 100644 docs/batches/2026-09-14/credentials/index.json create mode 100644 docs/batches/2026-09-14/credentials/infd-20260914-c01.memo.json create mode 100644 docs/batches/2026-09-14/credentials/infd-20260914-c01.packet.md create mode 100644 docs/batches/2026-09-14/credentials/infd-20260914-c02.memo.json create mode 100644 docs/batches/2026-09-14/credentials/infd-20260914-c02.packet.md create mode 100644 docs/batches/2026-09-14/credentials/infd-20260914-c03.memo.json create mode 100644 docs/batches/2026-09-14/credentials/infd-20260914-c03.packet.md create mode 100644 docs/batches/2026-09-14/credentials/infd-20260914-c04.memo.json create mode 100644 docs/batches/2026-09-14/credentials/infd-20260914-c04.packet.md create mode 100644 docs/batches/2026-09-14/decisions/index.json create mode 100644 docs/batches/2026-09-14/decisions/infd-20260914-d01.memo.json create mode 100644 docs/batches/2026-09-14/decisions/infd-20260914-d01.packet.md create mode 100644 docs/batches/2026-09-14/decisions/infd-20260914-d02.memo.json create mode 100644 docs/batches/2026-09-14/decisions/infd-20260914-d02.packet.md create mode 100644 docs/batches/2026-09-14/decisions/infd-20260914-d03.memo.json create mode 100644 docs/batches/2026-09-14/decisions/infd-20260914-d03.packet.md create mode 100644 docs/batches/2026-09-14/decisions/infd-20260914-d04.memo.json create mode 100644 docs/batches/2026-09-14/decisions/infd-20260914-d04.packet.md create mode 100644 docs/batches/2026-09-14/sitting.json create mode 100644 docs/specs/CompactSignoffBatches.md create mode 100644 tests/test_compact_batches.py create mode 100644 tools/prepare_compact_batches.py diff --git a/docs/batches/2026-09-14/README.md b/docs/batches/2026-09-14/README.md new file mode 100644 index 0000000..bd8dc94 --- /dev/null +++ b/docs/batches/2026-09-14/README.md @@ -0,0 +1,21 @@ +# Sitting 2026-09-14 (unsigned drafts) + +Review group: `net-kingdom-admins`. +Status: draft-unsigned. Not submitted. Not bound. + +Two batches, eight memos, one compact sitting: + +| n | Batch | Memo | Blocking workplan | +| --: | --- | --- | --- | +| 1 | credentials | infd-20260914-c01 | SECRETS-WP-0010 native delivery | +| 2 | credentials | infd-20260914-c02 | RPF-WP-0035-T02 JWT login | +| 3 | credentials | infd-20260914-c03 | NK-WP-0032-T03 OpenBao role | +| 4 | credentials | infd-20260914-c04 | WARDEN-WP-0027-T02 attended seal | +| 5 | decisions | infd-20260914-d01 | CUST-WP-0038-T08 WSL2 retirement | +| 6 | decisions | infd-20260914-d02 | HFACT-WP-0001-T03 CCR-2026-0019 | +| 7 | decisions | infd-20260914-d03 | MASON-WP-0005 plan accept | +| 8 | decisions | infd-20260914-d04 | RCLK-WP-0002-T01 clock ownership | + +Contract: `docs/specs/CompactSignoffBatches.md`. +Regenerate: `uv run python tools/prepare_compact_batches.py`. +Live bind waits on `INFD-WP-0001-T08`. diff --git a/docs/batches/2026-09-14/credentials/index.json b/docs/batches/2026-09-14/credentials/index.json new file mode 100644 index 0000000..c758cc5 --- /dev/null +++ b/docs/batches/2026-09-14/credentials/index.json @@ -0,0 +1,60 @@ +{ + "kind": "informed-decision-batch", + "id": "infd-batch-2026-09-14-credentials", + "review_group": "net-kingdom-admins", + "status": "draft-unsigned", + "submitted": false, + "one_question_per_memo": true, + "approve_all_forbidden": true, + "agent_disposition_forbidden": true, + "ordinal": [ + { + "n": 1, + "memo_id": "infd-20260914-c01", + "workplan": "SECRETS-WP-0010", + "task": "Admit and verify real native delivery", + "hub_task_prefix": "2aa6d2d3", + "question": "Admit real native OpenRouter delivery for intelligence-radar on the existing reviewed lane?", + "memo": "infd-20260914-c01.memo.json", + "packet": "infd-20260914-c01.packet.md", + "packet_hash": "sha256:32081b73066a49097e3564eac937cc34bffe72ff2be1b84b05a0999e578bda99", + "required_highlight": "infd-20260914-c01-h1" + }, + { + "n": 2, + "memo_id": "infd-20260914-c02", + "workplan": "RPF-WP-0035", + "task": "RPF-WP-0035-T02", + "hub_task_prefix": "e0c82ea9", + "question": "Accept provisioning of the secrets-engine service JWT login on the reviewed credential lane?", + "memo": "infd-20260914-c02.memo.json", + "packet": "infd-20260914-c02.packet.md", + "packet_hash": "sha256:9a3159c1a8d2f1f8782469e2eb9e04e6cdede40b6bb9cdb872ae1f1bf3b73ee5", + "required_highlight": "infd-20260914-c02-h1" + }, + { + "n": 3, + "memo_id": "infd-20260914-c03", + "workplan": "NK-WP-0032", + "task": "NK-WP-0032-T03", + "hub_task_prefix": "73b77110", + "question": "Apply the live OpenBao role addition already specified for the operator-tunneled browser callback?", + "memo": "infd-20260914-c03.memo.json", + "packet": "infd-20260914-c03.packet.md", + "packet_hash": "sha256:3e93888104d59854b8c191a98a46b73fed863df1bc76267b3fc24b070c676d3d", + "required_highlight": "infd-20260914-c03-h1" + }, + { + "n": 4, + "memo_id": "infd-20260914-c04", + "workplan": "WARDEN-WP-0027", + "task": "WARDEN-WP-0027-T02", + "hub_task_prefix": "cae498ee", + "question": "Attend the graded lockdown / break-glass seal for ops-warden trust-root work?", + "memo": "infd-20260914-c04.memo.json", + "packet": "infd-20260914-c04.packet.md", + "packet_hash": "sha256:bc6edfa538a6c334a916becf51dc485ad43da49cd08411843aaf1ed56bf25e10", + "required_highlight": "infd-20260914-c04-h1" + } + ] +} diff --git a/docs/batches/2026-09-14/credentials/infd-20260914-c01.memo.json b/docs/batches/2026-09-14/credentials/infd-20260914-c01.memo.json new file mode 100644 index 0000000..63d0a26 --- /dev/null +++ b/docs/batches/2026-09-14/credentials/infd-20260914-c01.memo.json @@ -0,0 +1 @@ +{"approval_binding_digest":null,"approval_id":null,"binding":{"justification":null,"principal":{"display_name":"Named reviewer in net-kingdom-admins","id":"pending-human-session","identifiers":[],"kind":"person","role":"reviewer"},"target":{"environment":"prod","id":"catalog:openrouter-llm-connect","kind":"secret-catalog-lane","label":"Existing llm-connect OpenRouter lane","requires_new_bind":false},"terms":null},"binding_level":"organizational","brief":"SECRETS-WP-0010 native delivery is waiting on a human admit. KeyCape redirects pass. This memo does not display, mint, or rotate a credential. It only asks whether the already-reviewed apply/verify/exec packets may proceed to live native delivery.","highlights":[{"id":"infd-20260914-c01-h1","item_id":"infd-20260914-c01-packet","locator":{"kind":"work_record","task":"Admit and verify real native delivery","workplan":"SECRETS-WP-0010"},"note":"No secret value is in this packet. Admit is not a mint.","required_ack":true,"severity":"critical"}],"id":"infd-20260914-c01","locale":"en","packet":[{"hash":"sha256:32081b73066a49097e3564eac937cc34bffe72ff2be1b84b05a0999e578bda99","item_id":"infd-20260914-c01-packet","label":"infd-20260914-c01-packet"}],"question":"Admit real native OpenRouter delivery for intelligence-radar on the existing reviewed lane?","requested_act":"approve","sealed":false,"step_kind":"approve","ui_release":"informed-decision@0.2.0","version":1} diff --git a/docs/batches/2026-09-14/credentials/infd-20260914-c01.packet.md b/docs/batches/2026-09-14/credentials/infd-20260914-c01.packet.md new file mode 100644 index 0000000..5611f43 --- /dev/null +++ b/docs/batches/2026-09-14/credentials/infd-20260914-c01.packet.md @@ -0,0 +1,16 @@ +# SECRETS-WP-0010 — admit native delivery + +Blocking workplan: SECRETS-WP-0010 +Blocking task: Admit and verify real native delivery (hub prefix 2aa6d2d3) + +## Question +Admit real native OpenRouter delivery for intelligence-radar on the existing reviewed lane? + +## One act +Authorize the operator in `net-kingdom-admins` to complete the already-prepared +apply / verify / exec packets. This is not a new OpenBao path and not a key mint. + +## Must not +- Paste or display credential material +- Call OpenRouter inference +- Treat `ops-warden` as a secret vendor diff --git a/docs/batches/2026-09-14/credentials/infd-20260914-c02.memo.json b/docs/batches/2026-09-14/credentials/infd-20260914-c02.memo.json new file mode 100644 index 0000000..7f58c5c --- /dev/null +++ b/docs/batches/2026-09-14/credentials/infd-20260914-c02.memo.json @@ -0,0 +1 @@ +{"approval_binding_digest":null,"approval_id":null,"binding":{"justification":null,"principal":{"display_name":"Named reviewer in net-kingdom-admins","id":"pending-human-session","identifiers":[],"kind":"person","role":"reviewer"},"target":{"environment":"prod","id":"rpf-wp-0035-t02","kind":"credential-lane","label":"secrets-engine service JWT login","requires_new_bind":false},"terms":null},"binding_level":"organizational","brief":"RPF-WP-0035-T02 waits on accepting and provisioning secrets-engine service JWT login. This memo is the accept question only. Provisioning remains the platform owner's act after bind.","highlights":[{"id":"infd-20260914-c02-h1","item_id":"infd-20260914-c02-packet","locator":{"kind":"work_record","task":"RPF-WP-0035-T02","workplan":"RPF-WP-0035"},"note":"Accept is not permission to invent a client_secret in this memo.","required_ack":true,"severity":"critical"}],"id":"infd-20260914-c02","locale":"en","packet":[{"hash":"sha256:9a3159c1a8d2f1f8782469e2eb9e04e6cdede40b6bb9cdb872ae1f1bf3b73ee5","item_id":"infd-20260914-c02-packet","label":"infd-20260914-c02-packet"}],"question":"Accept provisioning of the secrets-engine service JWT login on the reviewed credential lane?","requested_act":"approve","sealed":false,"step_kind":"approve","ui_release":"informed-decision@0.2.0","version":1} diff --git a/docs/batches/2026-09-14/credentials/infd-20260914-c02.packet.md b/docs/batches/2026-09-14/credentials/infd-20260914-c02.packet.md new file mode 100644 index 0000000..1b5ff97 --- /dev/null +++ b/docs/batches/2026-09-14/credentials/infd-20260914-c02.packet.md @@ -0,0 +1,15 @@ +# RPF-WP-0035-T02 — accept JWT login lane + +Blocking workplan: RPF-WP-0035 +Blocking task: RPF-WP-0035-T02 (hub prefix e0c82ea9) + +## Question +Accept provisioning of the secrets-engine service JWT login on the reviewed credential lane? + +## One act +Organizational accept that this lane may be provisioned by its owner. The memo +does not contain a JWT, client secret, or OpenBao policy body. + +## Must not +- Embed a token +- Collapse T02 with T03 Fluid lane or T06 reader admission diff --git a/docs/batches/2026-09-14/credentials/infd-20260914-c03.memo.json b/docs/batches/2026-09-14/credentials/infd-20260914-c03.memo.json new file mode 100644 index 0000000..66b99c1 --- /dev/null +++ b/docs/batches/2026-09-14/credentials/infd-20260914-c03.memo.json @@ -0,0 +1 @@ +{"approval_binding_digest":null,"approval_id":null,"binding":{"justification":null,"principal":{"display_name":"Named reviewer in net-kingdom-admins","id":"pending-human-session","identifiers":[],"kind":"person","role":"reviewer"},"target":{"environment":"prod","id":"nk-wp-0032-t03","kind":"openbao-role","label":"OpenBao role addition for operator-tunneled callback","requires_new_bind":false},"terms":null},"binding_level":"organizational","brief":"NK-WP-0032-T03 applies a live OpenBao role addition. This memo asks only whether that apply may proceed. The role body stays in the owning repo; it is not copied here.","highlights":[{"id":"infd-20260914-c03-h1","item_id":"infd-20260914-c03-packet","locator":{"kind":"work_record","task":"NK-WP-0032-T03","workplan":"NK-WP-0032"},"note":"Apply is one role addition, not a general OpenBao admin grant.","required_ack":true,"severity":"critical"}],"id":"infd-20260914-c03","locale":"en","packet":[{"hash":"sha256:3e93888104d59854b8c191a98a46b73fed863df1bc76267b3fc24b070c676d3d","item_id":"infd-20260914-c03-packet","label":"infd-20260914-c03-packet"}],"question":"Apply the live OpenBao role addition already specified for the operator-tunneled browser callback?","requested_act":"approve","sealed":false,"step_kind":"approve","ui_release":"informed-decision@0.2.0","version":1} diff --git a/docs/batches/2026-09-14/credentials/infd-20260914-c03.packet.md b/docs/batches/2026-09-14/credentials/infd-20260914-c03.packet.md new file mode 100644 index 0000000..7a80e62 --- /dev/null +++ b/docs/batches/2026-09-14/credentials/infd-20260914-c03.packet.md @@ -0,0 +1,15 @@ +# NK-WP-0032-T03 — apply live OpenBao role + +Blocking workplan: NK-WP-0032 +Blocking task: NK-WP-0032-T03 (hub prefix 73b77110) + +## Question +Apply the live OpenBao role addition already specified for the operator-tunneled browser callback? + +## One act +Authorize the NetKingdom owner to apply the already-specified role. This memo +does not include the policy HCL or any secret id. + +## Must not +- Broaden to unattended public OpenBao UI +- Treat this as NK-WP-0032-T04 evidence return diff --git a/docs/batches/2026-09-14/credentials/infd-20260914-c04.memo.json b/docs/batches/2026-09-14/credentials/infd-20260914-c04.memo.json new file mode 100644 index 0000000..e9f9d64 --- /dev/null +++ b/docs/batches/2026-09-14/credentials/infd-20260914-c04.memo.json @@ -0,0 +1 @@ +{"approval_binding_digest":null,"approval_id":null,"binding":{"justification":null,"principal":{"display_name":"Named reviewer in net-kingdom-admins","id":"pending-human-session","identifiers":[],"kind":"person","role":"reviewer"},"target":{"environment":"prod","id":"warden-wp-0027-t02","kind":"trust-root","label":"ops-warden graded lockdown / break-glass","requires_new_bind":false},"terms":null},"binding_level":"organizational","brief":"WARDEN-WP-0027-T02 is attended seal work. This memo asks the reviewer to attend that seal sitting. ops-warden still issues SSH certificates only; this is not a request for an API key.","highlights":[{"id":"infd-20260914-c04-h1","item_id":"infd-20260914-c04-packet","locator":{"kind":"work_record","task":"WARDEN-WP-0027-T02","workplan":"WARDEN-WP-0027"},"note":"ops-warden does not vend API keys. This is an attended seal, not a secret paste.","required_ack":true,"severity":"critical"}],"id":"infd-20260914-c04","locale":"en","packet":[{"hash":"sha256:bc6edfa538a6c334a916becf51dc485ad43da49cd08411843aaf1ed56bf25e10","item_id":"infd-20260914-c04-packet","label":"infd-20260914-c04-packet"}],"question":"Attend the graded lockdown / break-glass seal for ops-warden trust-root work?","requested_act":"approve","sealed":false,"step_kind":"approve","ui_release":"informed-decision@0.2.0","version":1} diff --git a/docs/batches/2026-09-14/credentials/infd-20260914-c04.packet.md b/docs/batches/2026-09-14/credentials/infd-20260914-c04.packet.md new file mode 100644 index 0000000..776fe39 --- /dev/null +++ b/docs/batches/2026-09-14/credentials/infd-20260914-c04.packet.md @@ -0,0 +1,15 @@ +# WARDEN-WP-0027-T02 — attend graded lockdown seal + +Blocking workplan: WARDEN-WP-0027 +Blocking task: WARDEN-WP-0027-T02 (hub prefix cae498ee) + +## Question +Attend the graded lockdown / break-glass seal for ops-warden trust-root work? + +## One act +Schedule/complete the attended seal. Credential routing remains: SSH certs from +ops-warden; other secrets from OpenBao via `warden route` pointers. + +## Must not +- Ask ops-warden for ISSUE_CORE_API_KEY or similar +- Record seal material in this packet diff --git a/docs/batches/2026-09-14/decisions/index.json b/docs/batches/2026-09-14/decisions/index.json new file mode 100644 index 0000000..abe2737 --- /dev/null +++ b/docs/batches/2026-09-14/decisions/index.json @@ -0,0 +1,60 @@ +{ + "kind": "informed-decision-batch", + "id": "infd-batch-2026-09-14-decisions", + "review_group": "net-kingdom-admins", + "status": "draft-unsigned", + "submitted": false, + "one_question_per_memo": true, + "approve_all_forbidden": true, + "agent_disposition_forbidden": true, + "ordinal": [ + { + "n": 1, + "memo_id": "infd-20260914-d01", + "workplan": "CUST-WP-0038", + "task": "CUST-WP-0038-T08", + "hub_task_prefix": "57412aef", + "question": "After HA failover and restore drills pass, retire WSL2 as a State Hub fallback?", + "memo": "infd-20260914-d01.memo.json", + "packet": "infd-20260914-d01.packet.md", + "packet_hash": "sha256:29fe7445e1f6794402bda2f9c4cab4258021d892515e1922819d8b67cb9e6b46", + "required_highlight": "infd-20260914-d01-h1" + }, + { + "n": 2, + "memo_id": "infd-20260914-d02", + "workplan": "HFACT-WP-0001", + "task": "HFACT-WP-0001-T03", + "hub_task_prefix": "67c80db1", + "question": "Confirm the existing operator-group claim for CCR-2026-0019 as required by the factory identity/audit/approval path?", + "memo": "infd-20260914-d02.memo.json", + "packet": "infd-20260914-d02.packet.md", + "packet_hash": "sha256:dffe006442779e3076526d72bd481a163b32b3bfe84c51952e1f2dcd53174e72", + "required_highlight": "infd-20260914-d02-h1" + }, + { + "n": 3, + "memo_id": "infd-20260914-d03", + "workplan": "MASON-WP-0005", + "task": "Review the plan and obtain the decision", + "hub_task_prefix": "48a2b4ec", + "question": "Accept the fluid-telegram operator credential lane plan so construction may proceed?", + "memo": "infd-20260914-d03.memo.json", + "packet": "infd-20260914-d03.packet.md", + "packet_hash": "sha256:d44745e5a6281e3f21cfbe5ac9c758cd06b5c7ddb49fd4b468aebcbeb2d301a0", + "required_highlight": "infd-20260914-d03-h1" + }, + { + "n": 4, + "memo_id": "infd-20260914-d04", + "workplan": "RCLK-WP-0002", + "task": "RCLK-WP-0002-T01", + "hub_task_prefix": "437734bd", + "question": "Confirm ecosystem ownership and the security role for Railiance Clock as specified?", + "memo": "infd-20260914-d04.memo.json", + "packet": "infd-20260914-d04.packet.md", + "packet_hash": "sha256:d7814954d261031ed61627e340d6beadecd8c559fb1a24c9fecb752b30cdbc53", + "required_highlight": "infd-20260914-d04-h1" + } + ] +} diff --git a/docs/batches/2026-09-14/decisions/infd-20260914-d01.memo.json b/docs/batches/2026-09-14/decisions/infd-20260914-d01.memo.json new file mode 100644 index 0000000..1be7804 --- /dev/null +++ b/docs/batches/2026-09-14/decisions/infd-20260914-d01.memo.json @@ -0,0 +1 @@ +{"approval_binding_digest":null,"approval_id":null,"binding":{"justification":null,"principal":{"display_name":"Named reviewer in net-kingdom-admins","id":"pending-human-session","identifiers":[],"kind":"person","role":"reviewer"},"target":{"environment":"prod","id":"cust-wp-0038-t08","kind":"operating-model","label":"Retire WSL2 State Hub fallback","requires_new_bind":false},"terms":null},"binding_level":"organizational","brief":"CUST-WP-0038-T08 requires explicit approval after drills. This memo is that approval question. It does not assert that the drills have already passed.","highlights":[{"id":"infd-20260914-d01-h1","item_id":"infd-20260914-d01-packet","locator":{"kind":"work_record","task":"CUST-WP-0038-T08","workplan":"CUST-WP-0038"},"note":"Approve only if you accept that WSL2 leaves both normal and fallback operating models.","required_ack":true,"severity":"critical"}],"id":"infd-20260914-d01","locale":"en","packet":[{"hash":"sha256:29fe7445e1f6794402bda2f9c4cab4258021d892515e1922819d8b67cb9e6b46","item_id":"infd-20260914-d01-packet","label":"infd-20260914-d01-packet"}],"question":"After HA failover and restore drills pass, retire WSL2 as a State Hub fallback?","requested_act":"approve","sealed":false,"step_kind":"approve","ui_release":"informed-decision@0.2.0","version":1} diff --git a/docs/batches/2026-09-14/decisions/infd-20260914-d01.packet.md b/docs/batches/2026-09-14/decisions/infd-20260914-d01.packet.md new file mode 100644 index 0000000..5c6d9d0 --- /dev/null +++ b/docs/batches/2026-09-14/decisions/infd-20260914-d01.packet.md @@ -0,0 +1,15 @@ +# CUST-WP-0038-T08 — retire WSL2 fallback + +Blocking workplan: CUST-WP-0038 +Blocking task: CUST-WP-0038-T08 (hub prefix 57412aef, needs_human) + +## Question +After HA failover and restore drills pass, retire WSL2 as a State Hub fallback? + +## One act +Founder/operator approval of the retirement once T05/T06 drills have passed. +This memo does not skip the drills. + +## Must not +- Treat this accept as proof that drills already passed +- Keep WSL2 as an undeclared fallback after accept diff --git a/docs/batches/2026-09-14/decisions/infd-20260914-d02.memo.json b/docs/batches/2026-09-14/decisions/infd-20260914-d02.memo.json new file mode 100644 index 0000000..396c11b --- /dev/null +++ b/docs/batches/2026-09-14/decisions/infd-20260914-d02.memo.json @@ -0,0 +1 @@ +{"approval_binding_digest":null,"approval_id":null,"binding":{"justification":null,"principal":{"display_name":"Named reviewer in net-kingdom-admins","id":"pending-human-session","identifiers":[],"kind":"person","role":"reviewer"},"target":{"environment":"prod","id":"ccr-2026-0019","kind":"ccr","label":"Existing operator-group claim for factory path","requires_new_bind":false},"terms":null},"binding_level":"organizational","brief":"HFACT-WP-0001-T03 waits on NetKingdom/KeyCape confirmation of the exact existing operator-group claim. This memo is that confirmation question. It does not mint a new group.","highlights":[{"id":"infd-20260914-d02-h1","item_id":"infd-20260914-d02-packet","locator":{"kind":"work_record","task":"HFACT-WP-0001-T03","workplan":"HFACT-WP-0001"},"note":"Confirm the existing claim. Do not invent a new group or CCR.","required_ack":true,"severity":"critical"}],"id":"infd-20260914-d02","locale":"en","packet":[{"hash":"sha256:dffe006442779e3076526d72bd481a163b32b3bfe84c51952e1f2dcd53174e72","item_id":"infd-20260914-d02-packet","label":"infd-20260914-d02-packet"}],"question":"Confirm the existing operator-group claim for CCR-2026-0019 as required by the factory identity/audit/approval path?","requested_act":"approve","sealed":false,"step_kind":"approve","ui_release":"informed-decision@0.2.0","version":1} diff --git a/docs/batches/2026-09-14/decisions/infd-20260914-d02.packet.md b/docs/batches/2026-09-14/decisions/infd-20260914-d02.packet.md new file mode 100644 index 0000000..23944d3 --- /dev/null +++ b/docs/batches/2026-09-14/decisions/infd-20260914-d02.packet.md @@ -0,0 +1,16 @@ +# HFACT-WP-0001-T03 — confirm CCR-2026-0019 operator-group + +Blocking workplan: HFACT-WP-0001 +Blocking task: HFACT-WP-0001-T03 (hub prefix 67c80db1, needs_human) + +## Question +Confirm the existing operator-group claim for CCR-2026-0019 as required by the +factory identity, audit and approval path? + +## One act +Confirm the already-named operator-group claim. Required-owner review and +attended apply remain separate acts. + +## Must not +- Create a new CCR in this memo +- Collapse T03 with T05 live worker proof diff --git a/docs/batches/2026-09-14/decisions/infd-20260914-d03.memo.json b/docs/batches/2026-09-14/decisions/infd-20260914-d03.memo.json new file mode 100644 index 0000000..53c22c0 --- /dev/null +++ b/docs/batches/2026-09-14/decisions/infd-20260914-d03.memo.json @@ -0,0 +1 @@ +{"approval_binding_digest":null,"approval_id":null,"binding":{"justification":null,"principal":{"display_name":"Named reviewer in net-kingdom-admins","id":"pending-human-session","identifiers":[],"kind":"person","role":"reviewer"},"target":{"environment":"prod","id":"mason-wp-0005","kind":"workplan","label":"fluid-telegram operator credential lane plan","requires_new_bind":false},"terms":null},"binding_level":"organizational","brief":"MASON-WP-0005 has a review/decision task before building the operator lane. This memo is that plan accept. Path/OIDC binding (another task) is a separate memo if needed later.","highlights":[{"id":"infd-20260914-d03-h1","item_id":"infd-20260914-d03-packet","locator":{"kind":"work_record","task":"Review the plan and obtain the decision","workplan":"MASON-WP-0005"},"note":"Accepting the plan is not confirming the OIDC binding and is not a BotFather login.","required_ack":true,"severity":"critical"}],"id":"infd-20260914-d03","locale":"en","packet":[{"hash":"sha256:d44745e5a6281e3f21cfbe5ac9c758cd06b5c7ddb49fd4b468aebcbeb2d301a0","item_id":"infd-20260914-d03-packet","label":"infd-20260914-d03-packet"}],"question":"Accept the fluid-telegram operator credential lane plan so construction may proceed?","requested_act":"approve","sealed":false,"step_kind":"approve","ui_release":"informed-decision@0.2.0","version":1} diff --git a/docs/batches/2026-09-14/decisions/infd-20260914-d03.packet.md b/docs/batches/2026-09-14/decisions/infd-20260914-d03.packet.md new file mode 100644 index 0000000..87bf6e3 --- /dev/null +++ b/docs/batches/2026-09-14/decisions/infd-20260914-d03.packet.md @@ -0,0 +1,15 @@ +# MASON-WP-0005 — accept operator lane plan + +Blocking workplan: MASON-WP-0005 +Blocking task: Review the plan and obtain the decision (hub prefix 48a2b4ec) + +## Question +Accept the fluid-telegram operator credential lane plan so construction may proceed? + +## One act +Organizational accept of the written plan. BotFather login, DNS, and OIDC +binding remain other tasks. + +## Must not +- Perform BotFather login in this sitting +- Record a telegram token diff --git a/docs/batches/2026-09-14/decisions/infd-20260914-d04.memo.json b/docs/batches/2026-09-14/decisions/infd-20260914-d04.memo.json new file mode 100644 index 0000000..8ed1665 --- /dev/null +++ b/docs/batches/2026-09-14/decisions/infd-20260914-d04.memo.json @@ -0,0 +1 @@ +{"approval_binding_digest":null,"approval_id":null,"binding":{"justification":null,"principal":{"display_name":"Named reviewer in net-kingdom-admins","id":"pending-human-session","identifiers":[],"kind":"person","role":"reviewer"},"target":{"environment":"prod","id":"rclk-wp-0002-t01","kind":"workplan","label":"Railiance Clock ownership and security role","requires_new_bind":false},"terms":null},"binding_level":"organizational","brief":"RCLK-WP-0002-T01 is the owner/security-role confirmation. This memo is that confirmation. It does not change OS clocks or admit railiance01 as production time authority by itself.","highlights":[{"id":"infd-20260914-d04-h1","item_id":"infd-20260914-d04-packet","locator":{"kind":"work_record","task":"RCLK-WP-0002-T01","workplan":"RCLK-WP-0002"},"note":"Confirmation is ownership/role, not a clock change on any host.","required_ack":true,"severity":"critical"}],"id":"infd-20260914-d04","locale":"en","packet":[{"hash":"sha256:d7814954d261031ed61627e340d6beadecd8c559fb1a24c9fecb752b30cdbc53","item_id":"infd-20260914-d04-packet","label":"infd-20260914-d04-packet"}],"question":"Confirm ecosystem ownership and the security role for Railiance Clock as specified?","requested_act":"approve","sealed":false,"step_kind":"approve","ui_release":"informed-decision@0.2.0","version":1} diff --git a/docs/batches/2026-09-14/decisions/infd-20260914-d04.packet.md b/docs/batches/2026-09-14/decisions/infd-20260914-d04.packet.md new file mode 100644 index 0000000..86de608 --- /dev/null +++ b/docs/batches/2026-09-14/decisions/infd-20260914-d04.packet.md @@ -0,0 +1,15 @@ +# RCLK-WP-0002-T01 — confirm clock ownership + +Blocking workplan: RCLK-WP-0002 +Blocking task: RCLK-WP-0002-T01 (hub prefix 437734bd) + +## Question +Confirm ecosystem ownership and the security role for Railiance Clock as specified? + +## One act +Owner confirmation of the documented role split (railiance-infra for host UTC, +clock repo for specs). No NTP or OS change is authorized by this memo. + +## Must not +- Change ntp.ubuntu.com or systemd-timesyncd from this sitting +- Treat this as RCLK-WP-0004 pilot admission diff --git a/docs/batches/2026-09-14/sitting.json b/docs/batches/2026-09-14/sitting.json new file mode 100644 index 0000000..2236ed4 --- /dev/null +++ b/docs/batches/2026-09-14/sitting.json @@ -0,0 +1,13 @@ +{ + "kind": "informed-decision-sitting", + "id": "infd-sitting-2026-09-14", + "review_group": "net-kingdom-admins", + "status": "draft-unsigned", + "batches": [ + "infd-batch-2026-09-14-credentials", + "infd-batch-2026-09-14-decisions" + ], + "memo_count": 8, + "bind_path": "INFD-WP-0001-T08 (not yet complete)", + "note": "Unsigned drafts. Do not submit until CompactSignoffBatches.md is accepted. Live bind substitutes pending-human-session with the authenticated key-cape subject." +} diff --git a/docs/specs/CompactSignoffBatches.md b/docs/specs/CompactSignoffBatches.md new file mode 100644 index 0000000..257c583 --- /dev/null +++ b/docs/specs/CompactSignoffBatches.md @@ -0,0 +1,52 @@ +# Compact sign-off batches + +Addendum to the Stage 1 specs (INFD-WP-0002-T02). Not a new product. +Does not fork the Decision Memo schema. + +## What a batch is + +A batch is an *Umlaufmappe* **grouping** of Decision Memos that one +admitted review group can bind in a compact sitting. + +- One question per memo (INTENT invariant). +- Ordered list (`ordinal` in the batch index). +- Per-memo bind. Progress is “how many memos in this sitting have a + human disposition,” not a batch-level verdict. +- Review group: `net-kingdom-admins` (operator-admitted 2026-09-14). +- Humans bind; agents draft. Unsigned drafts use principal + `pending-human-session`. Live bind substitutes the authenticated + key-cape subject. + +If Stage 1 UI cannot yet render a group, the same rules hold for a +recorded desktop sitting: open memos in order, acknowledge required +highlights, bind one memo at a time, keep `view_hash` per memo. + +## Anti-requirements + +- **No bundled unrelated acts.** One memo must not ask for a mint, a + deploy, and an ADR accept together. +- **No “approve all”** that skips required highlights. +- **No agent disposition.** An agent may draft, order, and record + evidence. It may not `accept` / `decline` / `seal`. +- **No secret values** in packets or memos. +- **No auto-approval** from review-group membership. Membership is + eligibility, not a bind. +- This addendum does **not** complete INFD-WP-0001-T08. Live bind waits + on that path. + +## Sitting progress + +```text +draft-unsigned → (T08 bind path live) → circulating → per-memo completed +``` + +Unfinished memos stay in the batch. A partial sitting does not finish +INFD-WP-0002. File-level updates of owning workplans happen only after +a human bind (T04), via repo files + `fix-consistency`, never +`POST /workplans/`. + +## First sitting (unsigned) + +`docs/batches/2026-09-14/` — four credential/custody memos and four +decision/assent memos. Indexes name the blocking workplan/task. Do not +submit until a human sitting is opened under T03. diff --git a/tests/test_compact_batches.py b/tests/test_compact_batches.py new file mode 100644 index 0000000..5e8a3c9 --- /dev/null +++ b/tests/test_compact_batches.py @@ -0,0 +1,40 @@ +from pathlib import Path +import json + +from informed_decision.records import memo_from + +ROOT = Path(__file__).resolve().parents[1] / "docs" / "batches" / "2026-09-14" + + +def test_sitting_has_two_unsigned_batches_of_four(): + sitting = json.loads((ROOT / "sitting.json").read_text()) + assert sitting["status"] == "draft-unsigned" + assert sitting["review_group"] == "net-kingdom-admins" + assert sitting["memo_count"] == 8 + assert sitting.get("submitted") is not True + + +def test_each_memo_is_one_question_with_required_highlight_and_workplan_trace(): + questions = set() + for name in ("credentials", "decisions"): + index = json.loads((ROOT / name / "index.json").read_text()) + assert index["one_question_per_memo"] is True + assert index["approve_all_forbidden"] is True + assert index["agent_disposition_forbidden"] is True + assert index["submitted"] is False + assert len(index["ordinal"]) == 4 + for row in index["ordinal"]: + memo = memo_from(json.loads((ROOT / name / row["memo"]).read_text())) + assert memo.question == row["question"] + assert memo.question not in questions + questions.add(memo.question) + assert memo.requested_act == "approve" + assert memo.approval_id is None + assert row["required_highlight"] in memo.required_ack_ids + assert row["workplan"] + assert row["hub_task_prefix"] + packet = (ROOT / name / row["packet"]).read_text() + assert "password" not in packet.lower() + assert "secret_id" not in packet.lower() + assert row["workplan"] in packet + assert len(questions) == 8 diff --git a/tools/prepare_compact_batches.py b/tools/prepare_compact_batches.py new file mode 100644 index 0000000..c4129dd --- /dev/null +++ b/tools/prepare_compact_batches.py @@ -0,0 +1,380 @@ +"""Draft unsigned compact sign-off batches (INFD-WP-0002-T01). + +One question per memo. No secret values. Does not submit, present, or bind. +""" +from __future__ import annotations + +import hashlib +from pathlib import Path + +from informed_decision.memo import ( + BindingLevel, + BindingSlice, + Highlight, + Memo, + PacketItem, + Principal, + Scope, + StepKind, +) +from informed_decision.records import dumps, memo_from + +ROOT = Path(__file__).resolve().parents[1] / "docs" / "batches" / "2026-09-14" +REVIEW_GROUP = "net-kingdom-admins" +PRINCIPAL = Principal( + id="pending-human-session", + kind="person", + display_name="Named reviewer in net-kingdom-admins", + role="reviewer", +) + + +def _sha(text: str) -> str: + return "sha256:" + hashlib.sha256(text.encode()).hexdigest() + + +def _memo(*, memo_id: str, question: str, brief: str, target: Scope, packet_id: str, packet_hash: str, highlight: str, workplan: str, task: str) -> Memo: + return Memo( + id=memo_id, + version=1, + question=question, + requested_act="approve", + binding_level=BindingLevel.ORGANIZATIONAL, + brief=brief, + binding=BindingSlice(principal=PRINCIPAL, target=target), + step_kind=StepKind.APPROVE, + packet=(PacketItem(packet_id, packet_id, packet_hash),), + highlights=( + Highlight( + id=f"{memo_id}-h1", + item_id=packet_id, + note=highlight, + required_ack=True, + severity="critical", + locator={"kind": "work_record", "workplan": workplan, "task": task}, + ), + ), + ) + + +CREDENTIALS = [ + { + "id": "infd-20260914-c01", + "workplan": "SECRETS-WP-0010", + "task": "Admit and verify real native delivery", + "task_id": "2aa6d2d3-0000-0000-0000-000000000000", + "hub_task_id": "2aa6d2d3", + "question": "Admit real native OpenRouter delivery for intelligence-radar on the existing reviewed lane?", + "brief": ( + "SECRETS-WP-0010 native delivery is waiting on a human admit. " + "KeyCape redirects pass. This memo does not display, mint, or rotate a credential. " + "It only asks whether the already-reviewed apply/verify/exec packets may proceed to live native delivery." + ), + "highlight": "No secret value is in this packet. Admit is not a mint.", + "target": Scope("secret-catalog-lane", "catalog:openrouter-llm-connect", "Existing llm-connect OpenRouter lane", "prod"), + "packet": """# SECRETS-WP-0010 — admit native delivery + +Blocking workplan: SECRETS-WP-0010 +Blocking task: Admit and verify real native delivery (hub prefix 2aa6d2d3) + +## Question +Admit real native OpenRouter delivery for intelligence-radar on the existing reviewed lane? + +## One act +Authorize the operator in `net-kingdom-admins` to complete the already-prepared +apply / verify / exec packets. This is not a new OpenBao path and not a key mint. + +## Must not +- Paste or display credential material +- Call OpenRouter inference +- Treat `ops-warden` as a secret vendor +""", + }, + { + "id": "infd-20260914-c02", + "workplan": "RPF-WP-0035", + "task": "RPF-WP-0035-T02", + "hub_task_id": "e0c82ea9", + "question": "Accept provisioning of the secrets-engine service JWT login on the reviewed credential lane?", + "brief": ( + "RPF-WP-0035-T02 waits on accepting and provisioning secrets-engine service JWT login. " + "This memo is the accept question only. Provisioning remains the platform owner's act after bind." + ), + "highlight": "Accept is not permission to invent a client_secret in this memo.", + "target": Scope("credential-lane", "rpf-wp-0035-t02", "secrets-engine service JWT login", "prod"), + "packet": """# RPF-WP-0035-T02 — accept JWT login lane + +Blocking workplan: RPF-WP-0035 +Blocking task: RPF-WP-0035-T02 (hub prefix e0c82ea9) + +## Question +Accept provisioning of the secrets-engine service JWT login on the reviewed credential lane? + +## One act +Organizational accept that this lane may be provisioned by its owner. The memo +does not contain a JWT, client secret, or OpenBao policy body. + +## Must not +- Embed a token +- Collapse T02 with T03 Fluid lane or T06 reader admission +""", + }, + { + "id": "infd-20260914-c03", + "workplan": "NK-WP-0032", + "task": "NK-WP-0032-T03", + "hub_task_id": "73b77110", + "question": "Apply the live OpenBao role addition already specified for the operator-tunneled browser callback?", + "brief": ( + "NK-WP-0032-T03 applies a live OpenBao role addition. This memo asks only whether that apply may proceed. " + "The role body stays in the owning repo; it is not copied here." + ), + "highlight": "Apply is one role addition, not a general OpenBao admin grant.", + "target": Scope("openbao-role", "nk-wp-0032-t03", "OpenBao role addition for operator-tunneled callback", "prod"), + "packet": """# NK-WP-0032-T03 — apply live OpenBao role + +Blocking workplan: NK-WP-0032 +Blocking task: NK-WP-0032-T03 (hub prefix 73b77110) + +## Question +Apply the live OpenBao role addition already specified for the operator-tunneled browser callback? + +## One act +Authorize the NetKingdom owner to apply the already-specified role. This memo +does not include the policy HCL or any secret id. + +## Must not +- Broaden to unattended public OpenBao UI +- Treat this as NK-WP-0032-T04 evidence return +""", + }, + { + "id": "infd-20260914-c04", + "workplan": "WARDEN-WP-0027", + "task": "WARDEN-WP-0027-T02", + "hub_task_id": "cae498ee", + "question": "Attend the graded lockdown / break-glass seal for ops-warden trust-root work?", + "brief": ( + "WARDEN-WP-0027-T02 is attended seal work. This memo asks the reviewer to attend that seal sitting. " + "ops-warden still issues SSH certificates only; this is not a request for an API key." + ), + "highlight": "ops-warden does not vend API keys. This is an attended seal, not a secret paste.", + "target": Scope("trust-root", "warden-wp-0027-t02", "ops-warden graded lockdown / break-glass", "prod"), + "packet": """# WARDEN-WP-0027-T02 — attend graded lockdown seal + +Blocking workplan: WARDEN-WP-0027 +Blocking task: WARDEN-WP-0027-T02 (hub prefix cae498ee) + +## Question +Attend the graded lockdown / break-glass seal for ops-warden trust-root work? + +## One act +Schedule/complete the attended seal. Credential routing remains: SSH certs from +ops-warden; other secrets from OpenBao via `warden route` pointers. + +## Must not +- Ask ops-warden for ISSUE_CORE_API_KEY or similar +- Record seal material in this packet +""", + }, +] + +DECISIONS = [ + { + "id": "infd-20260914-d01", + "workplan": "CUST-WP-0038", + "task": "CUST-WP-0038-T08", + "hub_task_id": "57412aef", + "question": "After HA failover and restore drills pass, retire WSL2 as a State Hub fallback?", + "brief": ( + "CUST-WP-0038-T08 requires explicit approval after drills. This memo is that approval question. " + "It does not assert that the drills have already passed." + ), + "highlight": "Approve only if you accept that WSL2 leaves both normal and fallback operating models.", + "target": Scope("operating-model", "cust-wp-0038-t08", "Retire WSL2 State Hub fallback", "prod"), + "packet": """# CUST-WP-0038-T08 — retire WSL2 fallback + +Blocking workplan: CUST-WP-0038 +Blocking task: CUST-WP-0038-T08 (hub prefix 57412aef, needs_human) + +## Question +After HA failover and restore drills pass, retire WSL2 as a State Hub fallback? + +## One act +Founder/operator approval of the retirement once T05/T06 drills have passed. +This memo does not skip the drills. + +## Must not +- Treat this accept as proof that drills already passed +- Keep WSL2 as an undeclared fallback after accept +""", + }, + { + "id": "infd-20260914-d02", + "workplan": "HFACT-WP-0001", + "task": "HFACT-WP-0001-T03", + "hub_task_id": "67c80db1", + "question": "Confirm the existing operator-group claim for CCR-2026-0019 as required by the factory identity/audit/approval path?", + "brief": ( + "HFACT-WP-0001-T03 waits on NetKingdom/KeyCape confirmation of the exact existing operator-group claim. " + "This memo is that confirmation question. It does not mint a new group." + ), + "highlight": "Confirm the existing claim. Do not invent a new group or CCR.", + "target": Scope("ccr", "ccr-2026-0019", "Existing operator-group claim for factory path", "prod"), + "packet": """# HFACT-WP-0001-T03 — confirm CCR-2026-0019 operator-group + +Blocking workplan: HFACT-WP-0001 +Blocking task: HFACT-WP-0001-T03 (hub prefix 67c80db1, needs_human) + +## Question +Confirm the existing operator-group claim for CCR-2026-0019 as required by the +factory identity, audit and approval path? + +## One act +Confirm the already-named operator-group claim. Required-owner review and +attended apply remain separate acts. + +## Must not +- Create a new CCR in this memo +- Collapse T03 with T05 live worker proof +""", + }, + { + "id": "infd-20260914-d03", + "workplan": "MASON-WP-0005", + "task": "Review the plan and obtain the decision", + "hub_task_id": "48a2b4ec", + "question": "Accept the fluid-telegram operator credential lane plan so construction may proceed?", + "brief": ( + "MASON-WP-0005 has a review/decision task before building the operator lane. " + "This memo is that plan accept. Path/OIDC binding (another task) is a separate memo if needed later." + ), + "highlight": "Accepting the plan is not confirming the OIDC binding and is not a BotFather login.", + "target": Scope("workplan", "mason-wp-0005", "fluid-telegram operator credential lane plan", "prod"), + "packet": """# MASON-WP-0005 — accept operator lane plan + +Blocking workplan: MASON-WP-0005 +Blocking task: Review the plan and obtain the decision (hub prefix 48a2b4ec) + +## Question +Accept the fluid-telegram operator credential lane plan so construction may proceed? + +## One act +Organizational accept of the written plan. BotFather login, DNS, and OIDC +binding remain other tasks. + +## Must not +- Perform BotFather login in this sitting +- Record a telegram token +""", + }, + { + "id": "infd-20260914-d04", + "workplan": "RCLK-WP-0002", + "task": "RCLK-WP-0002-T01", + "hub_task_id": "437734bd", + "question": "Confirm ecosystem ownership and the security role for Railiance Clock as specified?", + "brief": ( + "RCLK-WP-0002-T01 is the owner/security-role confirmation. This memo is that confirmation. " + "It does not change OS clocks or admit railiance01 as production time authority by itself." + ), + "highlight": "Confirmation is ownership/role, not a clock change on any host.", + "target": Scope("workplan", "rclk-wp-0002-t01", "Railiance Clock ownership and security role", "prod"), + "packet": """# RCLK-WP-0002-T01 — confirm clock ownership + +Blocking workplan: RCLK-WP-0002 +Blocking task: RCLK-WP-0002-T01 (hub prefix 437734bd) + +## Question +Confirm ecosystem ownership and the security role for Railiance Clock as specified? + +## One act +Owner confirmation of the documented role split (railiance-infra for host UTC, +clock repo for specs). No NTP or OS change is authorized by this memo. + +## Must not +- Change ntp.ubuntu.com or systemd-timesyncd from this sitting +- Treat this as RCLK-WP-0004 pilot admission +""", + }, +] + + +def write_batch(name: str, items: list[dict]) -> dict: + directory = ROOT / name + directory.mkdir(parents=True, exist_ok=True) + index = { + "kind": "informed-decision-batch", + "id": f"infd-batch-2026-09-14-{name}", + "review_group": REVIEW_GROUP, + "status": "draft-unsigned", + "submitted": False, + "one_question_per_memo": True, + "approve_all_forbidden": True, + "agent_disposition_forbidden": True, + "ordinal": [], + } + for i, item in enumerate(items, start=1): + packet_path = directory / f"{item['id']}.packet.md" + packet_path.write_text(item["packet"], encoding="utf-8") + digest = _sha(item["packet"]) + memo = _memo( + memo_id=item["id"], + question=item["question"], + brief=item["brief"], + target=item["target"], + packet_id=item["id"] + "-packet", + packet_hash=digest, + highlight=item["highlight"], + workplan=item["workplan"], + task=item["task"], + ) + loaded = memo_from(__import__("json").loads(dumps(memo))) + if loaded.question != item["question"]: + raise RuntimeError("round-trip failed") + memo_path = directory / f"{item['id']}.memo.json" + memo_path.write_text(dumps(memo) + "\n", encoding="utf-8") + index["ordinal"].append( + { + "n": i, + "memo_id": item["id"], + "workplan": item["workplan"], + "task": item["task"], + "hub_task_prefix": item["hub_task_id"], + "question": item["question"], + "memo": memo_path.name, + "packet": packet_path.name, + "packet_hash": digest, + "required_highlight": f"{item['id']}-h1", + } + ) + (directory / "index.json").write_text( + __import__("json").dumps(index, indent=2, ensure_ascii=False) + "\n", + encoding="utf-8", + ) + return index + + +def main() -> None: + ROOT.mkdir(parents=True, exist_ok=True) + cred = write_batch("credentials", CREDENTIALS) + dec = write_batch("decisions", DECISIONS) + sitting = { + "kind": "informed-decision-sitting", + "id": "infd-sitting-2026-09-14", + "review_group": REVIEW_GROUP, + "status": "draft-unsigned", + "batches": [cred["id"], dec["id"]], + "memo_count": len(cred["ordinal"]) + len(dec["ordinal"]), + "bind_path": "INFD-WP-0001-T08 (not yet complete)", + "note": "Unsigned drafts. Do not submit until CompactSignoffBatches.md is accepted. Live bind substitutes pending-human-session with the authenticated key-cape subject.", + } + (ROOT / "sitting.json").write_text( + __import__("json").dumps(sitting, indent=2, ensure_ascii=False) + "\n", + encoding="utf-8", + ) + print(f"Wrote {sitting['memo_count']} unsigned memos under {ROOT}") + + +if __name__ == "__main__": + main() diff --git a/workplans/INFD-WP-0002-compact-signoff-batches.md b/workplans/INFD-WP-0002-compact-signoff-batches.md index 9a6040c..899bf1a 100644 --- a/workplans/INFD-WP-0002-compact-signoff-batches.md +++ b/workplans/INFD-WP-0002-compact-signoff-batches.md @@ -4,7 +4,7 @@ type: workplan title: "Compact sign-off batches for credentials and decisions" domain: infotech repo: informed-decision -status: proposed +status: active owner: grok topic_slug: netkingdom flavor: planning @@ -44,7 +44,7 @@ authorization (`access-engine` remains the only PDP). ```task id: INFD-WP-0002-T01 -status: todo +status: done priority: high state_hub_task_id: "03d1b699-cb7b-5954-a4d2-cbe06af24c5a" ``` @@ -69,11 +69,15 @@ until T02. Done when both batch indexes exist, each memo has one binding target, required highlights, and a trace to the blocking workplan/task id. +2026-09-14: eight unsigned memos under `docs/batches/2026-09-14/` +(credentials c01–c04, decisions d01–d04). Review group +`net-kingdom-admins`. Not submitted. + ## Batch presentation contract (review-group, compact sitting) ```task id: INFD-WP-0002-T02 -status: todo +status: done priority: high depends_on: [INFD-WP-0002-T01] state_hub_task_id: "8babbc7d-5c79-5130-93ad-e2569ed3208d" @@ -89,6 +93,8 @@ Done when `docs/specs/` (short addendum, not a new product) states the batch rules and the anti-requirement: no bundled unrelated acts, no auto-approval, no agent disposition. +2026-09-14: `docs/specs/CompactSignoffBatches.md`. + ## Sign-off sitting once the Stage 1 surface can bind ```task