Record ownership ledger and completed CommerceCanon rename

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a070b5-4994-7271-bd8b-7c3dbcedec4b
This commit is contained in:
tegwick 2026-09-05 20:22:12 +02:00
parent 135b5a1720
commit 745d74abd9
21 changed files with 2934 additions and 14 deletions

View file

@ -8,7 +8,7 @@ status: active
owner: codex
topic_slug: canon-federation
created: "2026-08-16"
updated: "2026-08-16"
updated: "2026-09-05"
state_hub_workstream_id: "1c5615fc-03b7-5648-ba58-e828b8c0cb0f"
---
@ -85,7 +85,7 @@ residual to scope; `Family` seeded but explicitly not authored.
```task
id: CFED-WP-0001-T02
status: wait
status: done
priority: high
state_hub_task_id: "9c5ba080-e304-52cd-86d5-749a5a642387"
```
@ -105,11 +105,18 @@ with two. Zero of both is gate **G2**.
This ledger is the migration's source of truth — T05 and T06 execute from it
rather than from prose.
**Result (2026-09-05):** [Ledger](../ledger/README.md) complete: all 60
project-start source entries mapped to 61 destinations (one Family/Household
split), plus two ADR-required evidence concepts. Pinned donor-blob verification
and ownership validation pass: zero unowned and zero multiply owned
destinations. [Evidence](../docs/evidence/2026-09-05-ownership-ledger.md) records
verification and publication limits. T03 is ready to execute (`todo`).
## Rename identity-canon to commerce-canon
```task
id: CFED-WP-0001-T03
status: wait
status: done
priority: high
state_hub_task_id: "57092ca3-e1a8-5469-83be-d0338a78c150"
```
@ -129,11 +136,32 @@ Rename the repository in place, preserving git history:
Add a migration note to `history/` in the renamed repo per the `prj-` standard's
slug-rename rule.
**2026-09-05 preparation:** Local and Forge head match at
`43c5c21a7a7e273241d9c7622db4e926ac9aadfa`; Forge repository ID 46 is now
verified through State Hub on existing UUID
`8c82baea-bb40-435d-ac42-ec7a7c20dbb8`. Repository-owned implementation plan:
[IDENTITY-WP-0004](../../commerce-canon/workplans/IDENTITY-WP-0004-commerce-rename.md).
The [metadata patch](../docs/evidence/2026-09-05-commerce-metadata.patch) passes
`git apply --check` and is reserved for post-rebind application. It retains the
research classification category, assigns financials primary with government
and infotech secondary, and preserves all finished plans. New post-rename plans
will use COMMERCE-WP; the pre-cutover rename plan keeps its existing ID.
**Preparation blocker (resolved later on 2026-09-05):** deployed State Hub has no `REPOSITORY_RENAME_PREFLIGHT_SECRET`;
preflight returns `preflight_signing_unavailable`. Existing platform handoff
`cd52ba10-de41-46ce-aa8b-9b44050da8f7` (STATE-WP-0085-T09, also blocking
FLEX-WP-0020) owns this provisioning dependency. The user already authorized
proceeding; repeated rename permission is not the blocker. No operation journal,
forge rename, local path move, or metadata patch application has occurred.
The second registered host also requires a verified checkout disposition before
completion. See [preparation evidence](../docs/evidence/2026-09-05-rename-preparation.md).
## Scaffold commerce-canon to the canon layout standard
```task
id: CFED-WP-0001-T04
status: wait
status: todo
priority: medium
state_hub_task_id: "1be7aa81-4fc8-5a5a-8451-e288e660a326"
```
@ -174,6 +202,11 @@ Create `info-tech-canon/infospace/models/identity/InfoTechCanonIdentityModel.md`
- update `InfoTechCanonAccessControlModel:214` so the identity boundary now
points at `itc-ident` instead of declaring the area unowned.
**Publication prerequisite (2026-09-05):** reconcile actor-linking
`Delegation Relationship` assigned here by ADR-006 with existing itc-org section
10.18 `Delegation`. Do not duplicate the same semantics under a different name.
Resolve through destination canon review; amend ADR-006 if ownership changes.
Verification for gate **G4**: `itc-ident` defines no concept owned by `itc-org`
or `itc-access`.
@ -191,9 +224,15 @@ Create the counterparty/commercial model in `commerce-canon` from the ledger's
relationship/exemption concepts, `Customer`, `Vendor`, `Commercial
Relationship`, `Commercial Commitment`, `Payment Instrument Reference`, `Payment
Mandate`, `Pipeline Pursuit`, `Commercial Record`, `Counterparty Assurance
Gradient`, `Reputation Signal`, `Performance Evidence`, `Adjudication Outcome`,
Gradient`, `Reputation Signal`, `Performance Evidence`,
`Registry Identifier`, `Proxy Commercial Identifier`.
Import `Adjudication Outcome`, `Evidence`, and `Evidence Source` from
`itc-evid` per R3/R5/R7. Rewrite the old Evidence Source subtype wording in
Reputation Signal, Performance Evidence, and Beneficial Ownership Exemption
to distinguish assertions from their sources. T11 must establish the shared
evidence model before these imports can be verified.
Model identifier subtypes as the worked example of the import pattern:
`itc-ident` owns `Identifier`; CommerceCanon owns `Registry Identifier` and
`Proxy Commercial Identifier` as specializations of it.
@ -341,3 +380,39 @@ live work record outside this repository, per `work-record-types_v0.1.md`
- CommerceCanon service-surface decision, if demand appears;
- consumer adoption by `fin-hub`, `target-revenue`, `adaptive-pricing`,
`qonto-assistant` — demand-signal driven, explicitly not a gate here.
## T03 cutover continuation — 2026-09-05
Signing is provisioned (RPF-WP-0035-T04 done). The donor preparation is committed
and pushed at `40d5792fafbb2de778eabb56cfeaf00aecd058e1`. Operation
`615e7b44-d84e-4feb-92c5-1708feaf1e65` started with a passing fresh preflight.
The operator credential route performed the exact Forge rename; repository 46
is now `commerce-canon` at that same head. State Hub had no Forge write token,
so the runbook's operator-side rename/reconcile path was used with contained
OIDC and automatic session revocation.
State Hub reconciliation exposed a 307 redirect handling defect before rebind.
[STATE-WP-0089](../../state-hub/workplans/STATE-WP-0089-rename-redirect-recovery.md)
owns the fix, regression tests, image promotion and journal recovery. No direct
DB change, replacement journal, or weakening of immutable identity checks is
allowed. Both checkouts remain at the old path until rebind is verified.
## T03 completed — 2026-09-05
[Rename evidence](../docs/evidence/2026-09-05-rename-completed.json) records the
completed operation on the same Forge ID 46 and State Hub UUID. Both registered
checkouts are now commerce-canon with canonical remotes; the old State Hub slug
is a protected alias. Metadata, financials classification and agent instructions
are published at commerce-canon commit `c7002cf`. Three finished historical plans
remain byte-for-byte unchanged and the ledger still verifies its pinned source.
STATE-WP-0089 fixed and proved redirect recovery: 46 tests pass; deployed image
main-fe6b8d9, Helm revision 60; same journal resumed and completed. No direct DB
repair or replacement identity was used.
Live remaining work: REUSE-WP-0021 owns federation source/roster/cache updates;
T09 retains fleet-wide reference and projection acceptance. T04 is now todo.
The rename gate is complete; the canon layout, model moves and G8 fleet sweep
are not claimed complete by this result.