feat(identifiers): verify batch projections

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a023c0-a0a3-7c03-b395-5a0d2757214d
This commit is contained in:
tegwick 2026-08-22 23:50:34 +02:00
parent e6cc18bf18
commit 055c6971ab
11 changed files with 2964 additions and 9 deletions

View file

@ -541,6 +541,27 @@ note are in
`docs/evidence/RMGR-WP-0005-batch-0004-railiance-cluster-cutover-2026-08-22.md`.
T04 remains in progress for separately sealed and approved fleet batches.
**Batch 0005 preflight blocked safely (2026-08-22):** the refreshed zero-collision
fleet plan covers 39 repositories and 215 live records. A projection-aware
`adaptive-pricing` batch pinned its clean synchronized source and five UUID
replacements, then proved the workstation has all five old rows while production
has none. It therefore records `ready_for_approval: false` and authorizes no
mutation. A governed repair attempt retained State Hub's conservative C-03
refusal for absent random pre-derivation UUIDs.
That attempt exposed and fixed a Repo Manager fail-open result classification:
an empty ordinary-registration set could previously make an unverified exact
repair report `applied`. Repair and bootstrap modes now require their own exact
projection proof. Batch planning can also pin repeated
`--projection-api-base` endpoints and fails readiness unless every replacement
is current=200/derived=404 on every hub; verification repeats those live checks.
The remaining cross-owner gap is directly adoptable as
`helixforge.identifiers.state-hub-sealed-projection-repair.v1`. It asks State Hub
for a registrar-only, sealed, atomic restoration path without weakening normal
random stale-reference refusal. Evidence:
`docs/evidence/RMGR-WP-0005-batch-0005-adaptive-pricing-preflight-2026-08-22.md`.
## Retire the interim rule
```task