Complete G8 fleet source-reference sweep with provenance exceptions

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a070b5-4994-7271-bd8b-7c3dbcedec4b
This commit is contained in:
tegwick 2026-09-06 02:42:55 +02:00
parent 4d61ff5e11
commit 8a1f1b9fb2
11 changed files with 1887 additions and 5 deletions

View file

@ -17,8 +17,8 @@
| task | CFED-WP-0001-T06 | done | — | workplans/CFED-WP-0001-foundation.md |
| task | CFED-WP-0001-T07 | done | — | workplans/CFED-WP-0001-foundation.md |
| task | CFED-WP-0001-T08 | done | — | workplans/CFED-WP-0001-foundation.md |
| task | CFED-WP-0001-T09 | todo | — | workplans/CFED-WP-0001-foundation.md |
| task | CFED-WP-0001-T10 | wait | — | workplans/CFED-WP-0001-foundation.md |
| task | CFED-WP-0001-T09 | done | — | workplans/CFED-WP-0001-foundation.md |
| task | CFED-WP-0001-T10 | todo | — | workplans/CFED-WP-0001-foundation.md |
| task | CFED-WP-0001-T11 | done | — | workplans/CFED-WP-0001-foundation.md |
| task | CFED-WP-0001-T12 | done | — | workplans/CFED-WP-0001-foundation.md |
| task | CFED-WP-0001-T13 | done | — | workplans/CFED-WP-0001-foundation.md |

View file

@ -0,0 +1,33 @@
{
"repo_count": 133,
"fields_checked": [
"slug",
"local_path",
"host_paths",
"remote_url",
"mcp_server_name",
"mcp_server_url"
],
"obsolete_live_coordinates": [],
"git_repos_checked": 141,
"obsolete_git_remote_repos": [],
"nonadjacent_dispositions": {
"inter-hub": "State Hub archived; excluded from live source coverage",
"markitect-project": "State Hub archived; excluded from live source coverage",
"vergabe_teilnahme": "Resolved by local_path to scanned vergabe-teilnahme checkout"
},
"agent_configuration_scan": {
"roots": [
"~/.codex",
"~/.config",
"~/.claude"
],
"filename_patterns": [
"*config*",
"*mcp*",
"*settings*"
],
"live_matches": 0,
"historical_tool_result_matches": 2
}
}

View file

@ -0,0 +1,9 @@
{
"gate": "G8-source-scan",
"result": "pass",
"repositories_scanned": 141,
"files_scanned": 22414,
"reviewed_exception_files": 164,
"matching_lines": 307,
"errors": []
}

View file

@ -0,0 +1,104 @@
# G8 — Fleet source-reference sweep, 2026-09-06
CFED-WP-0001-T09 updates current source references across eight owning
repositories and the project ledger's validation command. Identity, actor,
access and shared-evidence references point to InfoTechCanon; repository and
commercial references point to CommerceCanon. No runtime contract, capability
identifier, maturity vector or concept assignment changes.
## Source coverage and preserved references
The [scan result](2026-09-06-reference-sweep.json) covers 141 adjacent Git
repositories and more than 22,000 files: tracked files (including ignored tracked
files), nonignored untracked files, hidden source/configuration files, and
symlink target paths (including dangling pointers). It
finds zero unreviewed legacy references. The
[exception ledger](../../ledger/reference-sweep.json) reviews 164 files / 307
matching lines and fingerprints each exact reference line. Historical research,
accepted ADR context, authored accounts, completed workplans, migration scope
and stable test/scenario identifiers remain deliberate provenance. Changing or
adding a matching line requires a fresh review; exceptions are not directory-wide
suppression rules. G8's own evidence files are excluded as scan metadata.
[State Hub coordinate evidence](2026-09-06-hub-coordinates.json) checks all 133
registered repo records, their source coordinates and all 141 local Git remotes.
No obsolete live coordinate remains. The old State Hub lookup is a protected
alias resolving the same UUID `8c82baea-bb40-435d-ac42-ec7a7c20dbb8` and current
CommerceCanon paths/remote. Two records without adjacent checkouts, inter-hub
and markitect-project, are archived; vergabe_teilnahme resolves to the scanned
vergabe-teilnahme path. This source scan does not certify unregistered external
repositories or stale copies of historical checkouts on other hosts.
Agent config/MCP/settings filename searches under ~/.codex, ~/.config and
~/.claude found no live match; two historical tool-result files were preserved.
Repository-owned MCP/config files are included in the source scan. Untracked ignored
third-party dependency trees and unrelated caches are not treated as source.
## Published changes
| Owner | Result | Published revision |
| --- | --- | --- |
| reuse-surface | Canonical source/roster, refreshed cache and composed index; live registration handover | `5501b8b` |
| repo-manager | CommerceCanon slug/Forge coordinate; existing repository UUID preserved | `6854ea10b278664baee7167efcceb2713bbab754` |
| binky-control | Current ecosystem and inventory references | `143b78e` |
| feature-control | Technical identity/evidence source references | `a555aaa` |
| kaizen-agentic | Identity/organization source references | `894d34c` |
| user-engine | Technical owner references in intent, mapping/card, docs and exporter docstring | `b9ae48b` |
| the-custodian | Current classification example and authoring override; obsolete human-review override retired | `4df570a` |
| commerce-canon | Current downstream owner links; original research proposal explicitly historical | `4a5b3d8fcbfd168ed1b3b326f3ecbedc6689b080` |
Each owning repo has a synchronized native ADHOC-2026-09-06 record, except
reuse-surface, which uses existing REUSE-WP-0021. Consistency also assigned a
missing UUID to Kaizen's existing ADHOC-2026-08-21 record without changing its
body or task identities. The project ledger command now uses the renamed local
source path while retaining the original pinned Git blob.
## Live federation proof
[Registration evidence](2026-09-06-reuse-registration.json) records the enabled
CommerceCanon registration and the old source retained disabled with a replacement
note. Its history is preserved without keeping it in the active composition.
[Composed live proof](2026-09-06-reuse-composed.json) verifies exactly the two
expected capability IDs, owner/source repo, canonical URLs and cache paths:
- capability.identity.subject-resolution — D3 / A0 / C1 / R0
- capability.identity.vocabulary-canonicalize — D4 / A0 / C2 / R0
The fresh live response has no target warning. The local federation composer
refreshed just CommerceCanon, then its source slice replaced the old slice in
the generated index; all 60 unrelated local capability rows were preserved.
The two obsolete local cache files were backed up and removed. Capability
ownership metadata here is registry stewardship, not a competing concept owner.
## Verification
```bash
python3 tools/validate_fleet_references.py --workspace ..
PYTHONDONTWRITEBYTECODE=1 python3 tools/test_fleet_references.py
python3 tools/validate_ownership.py --source-repo ../commerce-canon
python3 tools/validate_corpus.py --commerce-repo ../commerce-canon --info-tech-repo ../info-tech-canon
python3 docs/evidence/2026-09-05-counterparty-validate.py --commerce-repo ../commerce-canon --info-tech-repo ../info-tech-canon
```
The three sweep regression tests verify tracked ignored/hidden coverage,
rejection of new live references, and exact exception fingerprints. Existing
reuse-surface federation tests: 15 passed. Existing User Engine identity-alignment
tests: 4 passed, run with PYTHONPATH=src. Changed YAML/fenced examples/Python parse;
new relative links resolve; Custodian's example/authoring override match
CommerceCanon source classification. Existing ownership, counterparty and corpus
preservation proofs remain passing.
## Residuals and limits
G8 source-reference acceptance passes. Whole-fleet State Hub consistency is not
claimed. REUSE-WP-0021-T01 is done; T02 remains waiting on supported restoration
of three archived blank bindings to their existing legacy identities. The
missing-identifier tool rejects blank scalars and would derive different UUIDs;
no manual substitution or identity migration was performed. REUSE-WP-0021 remains
active and is the live owner of this repair.
Custodian's 13 historical consistency failures remain owned by CUST-IN-0017
from the prior gate. Other touched native records synchronized successfully.
CFED-WP-0001-T10 retains the final project residual/adoption review.
Acceptance decision: `48be4584-48df-4e81-8190-7a356e20f18b`.

View file

@ -0,0 +1,59 @@
{
"capabilities": [
{
"id": "capability.identity.subject-resolution",
"name": "Identity Subject Resolution",
"summary": "Resolve who or what is acting by mapping principals, accounts, actors, and identifiers to a stable subject model.",
"vector": "D3 / A0 / C1 / R0",
"domain": "helix_forge",
"status": "draft",
"owner": "commerce-canon",
"path": "registry/capabilities/capability.identity.subject-resolution.md",
"tags": [
"identity",
"subject",
"architecture"
],
"consumption_modes": [
"informational"
],
"source_repo": "commerce-canon",
"source_url": "https://forgejo.coulomb.social/coulomb/commerce-canon/raw/branch/main/registry/indexes/capabilities.yaml",
"source_index": "/data/cache/commerce-canon.yaml"
},
{
"id": "capability.identity.vocabulary-canonicalize",
"name": "Identity Vocabulary Canonicalization",
"summary": "Define an implementation-neutral vocabulary for identity-related concepts across overlapping domains.",
"vector": "D4 / A0 / C2 / R0",
"domain": "helix_forge",
"status": "draft",
"owner": "commerce-canon",
"path": "registry/capabilities/capability.identity.vocabulary-canonicalize.md",
"tags": [
"identity",
"terminology",
"research"
],
"consumption_modes": [
"informational"
],
"source_repo": "commerce-canon",
"source_url": "https://forgejo.coulomb.social/coulomb/commerce-canon/raw/branch/main/registry/indexes/capabilities.yaml",
"source_index": "/data/cache/commerce-canon.yaml"
}
],
"sources": [
{
"repo": "commerce-canon",
"count": 2,
"url": "https://forgejo.coulomb.social/coulomb/commerce-canon/raw/branch/main/registry/indexes/capabilities.yaml",
"cache": "/data/cache/commerce-canon.yaml"
}
],
"composed_at": "2026-09-05T23:23:57+00:00",
"stale": false,
"target_warnings": [],
"total_capabilities": 65,
"other_warning_count": 0
}

View file

@ -0,0 +1,84 @@
{
"old_registration_before": {
"repo": "identity-canon",
"url": "https://forgejo.coulomb.social/coulomb/identity-canon/raw/branch/main/registry/indexes/capabilities.yaml",
"enabled": true,
"required": false,
"domain": "helix_forge",
"cache_ttl_seconds": 86400,
"auth_header": "Authorization",
"registered_at": "2026-06-15T23:35:02+00:00",
"updated_at": "2026-08-20T21:44:34+00:00"
},
"retired_registration": {
"repo": "identity-canon",
"url": "https://forgejo.coulomb.social/coulomb/identity-canon/raw/branch/main/registry/indexes/capabilities.yaml",
"enabled": false,
"required": false,
"domain": "helix_forge",
"cache_ttl_seconds": 86400,
"auth_header": "Authorization",
"registered_at": "2026-06-15T23:35:02+00:00",
"updated_at": "2026-09-05T23:22:01+00:00",
"description": "Retired source registration after repository rename; replaced by commerce-canon under CFED-WP-0001-T09. Kept for history."
},
"canonical_registration": {
"repo": "commerce-canon",
"url": "https://forgejo.coulomb.social/coulomb/commerce-canon/raw/branch/main/registry/indexes/capabilities.yaml",
"enabled": true,
"required": false,
"domain": "helix_forge",
"cache_ttl_seconds": 86400,
"auth_header": "Authorization",
"description": "Canonical source after CFED-WP-0001-T03/T09; stable capability.identity identifiers retained.",
"registered_at": "2026-09-05T23:22:01+00:00",
"updated_at": "2026-09-05T23:22:01+00:00"
},
"capability_ids": [
"capability.identity.subject-resolution",
"capability.identity.vocabulary-canonicalize"
],
"source_payload": {
"version": 1,
"updated": "2026-06-16",
"domain": "helix_forge",
"capabilities": [
{
"id": "capability.identity.subject-resolution",
"name": "Identity Subject Resolution",
"summary": "Resolve who or what is acting by mapping principals, accounts, actors, and identifiers to a stable subject model.",
"vector": "D3 / A0 / C1 / R0",
"domain": "helix_forge",
"status": "draft",
"owner": "commerce-canon",
"path": "registry/capabilities/capability.identity.subject-resolution.md",
"tags": [
"identity",
"subject",
"architecture"
],
"consumption_modes": [
"informational"
]
},
{
"id": "capability.identity.vocabulary-canonicalize",
"name": "Identity Vocabulary Canonicalization",
"summary": "Define an implementation-neutral vocabulary for identity-related concepts across overlapping domains.",
"vector": "D4 / A0 / C2 / R0",
"domain": "helix_forge",
"status": "draft",
"owner": "commerce-canon",
"path": "registry/capabilities/capability.identity.vocabulary-canonicalize.md",
"tags": [
"identity",
"terminology",
"research"
],
"consumption_modes": [
"informational"
]
}
]
}
}

View file

@ -34,7 +34,7 @@ Run from this repository:
```bash
python3 tools/validate_ownership.py
python3 tools/validate_ownership.py --source-repo ../identity-canon
python3 tools/validate_ownership.py --source-repo ../commerce-canon
python3 -m unittest discover -s tools -p 'test_*.py'
```
@ -74,3 +74,7 @@ from the project root. Historical source assertions are not current definitions.
[Reciprocal interface evidence](../docs/evidence/2026-09-06-interface-cards.md)
records the three published canon cards and explicit upstream import review (G7).
[Fleet reference review](reference-sweep.json) records exact historical-reference
exceptions; [G8 evidence](../docs/evidence/2026-09-06-reference-sweep.md) records
current source coordinates and service validation.

1442
ledger/reference-sweep.json Normal file

File diff suppressed because it is too large Load diff

View file

@ -0,0 +1,50 @@
from pathlib import Path
import hashlib
import json
import subprocess
import tempfile
import unittest
from validate_fleet_references import scan, validate
class FleetReferenceTests(unittest.TestCase):
def setUp(self):
self.tmp = tempfile.TemporaryDirectory()
self.addCleanup(self.tmp.cleanup)
self.root = Path(self.tmp.name)
self.repo = self.root / 'example'
self.repo.mkdir()
subprocess.run(['git', 'init', '-q'], cwd=self.repo, check=True)
self.legacy = 'identity' + '-canon'
self.ledger = self.root / 'review.json'
self.ledger.write_text(json.dumps({'repositories': ['example'], 'exceptions': []}))
def test_tracked_ignored_and_hidden_files_are_scanned(self):
(self.repo / '.gitignore').write_text('ignored.md\n')
(self.repo / 'ignored.md').write_text(self.legacy)
(self.repo / '.settings').write_text(self.legacy)
(self.repo / 'source-link').symlink_to('../' + self.legacy)
subprocess.run(['git', 'add', '-f', 'ignored.md'], cwd=self.repo, check=True)
_, _, found = scan(self.root)
self.assertEqual(set(found), {'example/ignored.md', 'example/.settings', 'example/source-link'})
def test_new_live_reference_is_rejected(self):
(self.repo / 'README.md').write_text('Source: ' + self.legacy)
result = validate(self.root, self.ledger)
self.assertEqual(result['result'], 'fail')
self.assertEqual(result['errors'][0]['reason'], 'unreviewed reference')
def test_review_is_bound_to_exact_reference_content(self):
text = 'Historical source: ' + self.legacy
(self.repo / 'README.md').write_text(text)
data = {'repositories': ['example'], 'exceptions': [{'file': 'example/README.md',
'reason': 'Historical source', 'line_sha256': [hashlib.sha256(text.encode()).hexdigest()]}]}
self.ledger.write_text(json.dumps(data))
self.assertEqual(validate(self.root, self.ledger)['result'], 'pass')
(self.repo / 'README.md').write_text(text + '\nCurrent source: ' + self.legacy)
self.assertEqual(validate(self.root, self.ledger)['result'], 'fail')
if __name__ == '__main__':
unittest.main()

View file

@ -0,0 +1,86 @@
"""Validate reviewed legacy-reference exceptions across adjacent Git repositories.
Scans tracked files plus nonignored untracked files, including hidden files and symlink target paths.
Matches are fingerprints, not embedded file content. Git internals and ignored untracked
dependency/cache trees are outside the source scan; live registry/cache
and service checks are separate evidence.
"""
from __future__ import annotations
import argparse
from collections import Counter
import hashlib
import json
import os
from pathlib import Path
import re
import subprocess
PROJECT = Path(__file__).resolve().parents[1]
PATTERN = re.compile('identity' + r'[-_ ]?canon(?![a-z])', re.I)
AUDIT_FILES = {
'ledger/reference-sweep.json',
'docs/evidence/2026-09-06-reference-sweep.json',
'docs/evidence/2026-09-06-reference-sweep.md',
'docs/evidence/2026-09-06-reuse-registration.json',
'docs/evidence/2026-09-06-reuse-composed.json',
'docs/evidence/2026-09-06-hub-coordinates.json',
}
def scan(workspace):
repos = sorted(p for p in workspace.iterdir() if (p / '.git').exists())
matches = {}
total_files = 0
for repo in repos:
paths = subprocess.check_output(['git', 'ls-files', '-z', '--cached', '--others', '--exclude-standard'], cwd=repo)
for relative in sorted(set(p.decode() for p in paths.split(b'\0') if p)):
if repo.name == PROJECT.name and relative in AUDIT_FILES:
continue
path = repo / relative
if path.is_symlink():
# Audit the routing pointer even if its destination is absent.
data = os.readlink(path).encode()
elif path.is_file():
data = path.read_bytes()
else:
continue
total_files += 1
if b'\0' in data:
continue
lines = data.decode('utf-8', errors='replace').splitlines()
found = [{'line': i, 'sha256': hashlib.sha256(line.encode()).hexdigest()}
for i, line in enumerate(lines, 1) if PATTERN.search(line)]
if found:
matches[f'{repo.name}/{relative}'] = found
return repos, total_files, matches
def validate(workspace, ledger_path):
ledger = json.loads(ledger_path.read_text())
repos, file_count, found = scan(workspace)
accepted = {e['file']: e for e in ledger['exceptions']}
errors = []
for name, rows in found.items():
entry = accepted.get(name)
if not entry:
errors.append({'file': name, 'reason': 'unreviewed reference', 'lines': [r['line'] for r in rows]})
elif Counter(r['sha256'] for r in rows) != Counter(entry['line_sha256']):
errors.append({'file': name, 'reason': 'reference content changed; review required'})
for name in accepted.keys() - found.keys():
errors.append({'file': name, 'reason': 'obsolete exception; remove or review'})
missing = set(ledger['repositories']) - {p.name for p in repos}
errors.extend({'repo': r, 'reason': 'reviewed checkout missing'} for r in sorted(missing))
return {'gate': 'G8-source-scan', 'result': 'pass' if not errors else 'fail',
'repositories_scanned': len(repos), 'files_scanned': file_count,
'reviewed_exception_files': len(accepted), 'matching_lines': sum(map(len, found.values())),
'errors': errors}
if __name__ == '__main__':
parser = argparse.ArgumentParser(description=__doc__)
parser.add_argument('--workspace', type=Path, default=PROJECT.parent)
parser.add_argument('--ledger', type=Path, default=PROJECT / 'ledger/reference-sweep.json')
args = parser.parse_args()
result = validate(args.workspace.resolve(), args.ledger)
print(json.dumps(result, indent=2))
raise SystemExit(0 if result['result'] == 'pass' else 1)

View file

@ -332,7 +332,7 @@ G7 passes; T09 is now todo. Whole-fleet consistency is not claimed by this gate.
```task
id: CFED-WP-0001-T09
status: todo
status: done
priority: medium
state_hub_task_id: "42ebf476-6a45-5e23-b507-eb90bc4f5c07"
```
@ -344,6 +344,17 @@ registries, and `reuse-surface` entries. Deliberate historical provenance
Gate **G8** is a clean sweep.
**Result (2026-09-06):** [G8 evidence](../docs/evidence/2026-09-06-reference-sweep.md)
records eight published owner updates, 141 scanned local Git repositories,
133 checked State Hub records and a verified live reuse-service handover.
The [exception ledger](../ledger/reference-sweep.json) fingerprints deliberate
provenance and stable test/scenario names; zero unreviewed references remain.
Two existing capability ids/vectors and repository identity are preserved.
REUSE-WP-0021-T01 is done; its T02 retains the unrelated archived-binding repair
as live waiting work. CUST-IN-0017 retains prior Custodian consistency debt.
G8 passes; T10 is now todo. Overall progress: 12/13 tasks complete.
## Land the evidence model in InfoTechCanon
```task
@ -443,7 +454,7 @@ T07 is now todo; destination concept areas are established for corpus routing.
```task
id: CFED-WP-0001-T10
status: wait
status: todo
priority: low
state_hub_task_id: "2faeb8fb-58cc-5ea8-b5a8-ea0ed9583b30"
```