Clarify Activity Core queue boundary

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02b6f-7db1-7222-918b-e813a6bda38d
This commit is contained in:
tegwick 2026-08-23 13:01:37 +02:00
parent 2e16504e1f
commit c230f33698
2 changed files with 34 additions and 5 deletions

View file

@ -112,6 +112,13 @@ and T02T06 can cite stable decisions rather than infer ownership from code.
- Glas approved the proposed boundary without edits in message
`006fa46f-9419-4f61-90ff-0c3b6bc294c1`. Activity Core, sand-boxer, and
llm-connect acknowledgements remain pending.
- Activity Core review `428abb02-75dc-450d-a7f6-56fc715409ab` confirmed the
strategic route and no-fallback posture but correctly rejected an overstated
queue-identity guarantee. ADR-002 now distinguishes the current shared caller
token from the required principal-to-`worker_id` binding, requires Activity
Core itself to reject heartbeat/close mutations at or after lease expiry,
and excludes operator/SSO identity except through an audited break-glass
contract. Revised acknowledgement remains pending.
## Make each repository run a lease-bound transaction