fix(identifier): verify migration per repository unit

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a023c0-a0a3-7c03-b395-5a0d2757214d
This commit is contained in:
tegwick 2026-08-22 00:02:48 +02:00
parent 956efbb7ae
commit 887943108e
6 changed files with 49 additions and 19 deletions

View file

@ -23,13 +23,18 @@ namespace. Repo Manager records it in `config/fleet-namespace.yaml`; omitting
- regenerated plan: 42/42 repositories eligible, 242 records, 209 replacements,
33 assignments, zero skipped;
- plan SHA-256:
`98a7d876d49fbec9c062f970c18e25750da4cd4b5c89ab0d4ed24d50183abbda`.
`122ce72b27c2df50fb5604f3b324b68fbf7d2ec392c041370bfba7e0850a0e26`.
The full old-to-derived mapping is
`docs/evidence/RMGR-WP-0005-helixforge-uuid-migration-plan-2026-08-21.json`.
It carries canonical UTC generation time plus per-repository Git HEAD and
authoritative-source fingerprints. `rmgr identifier migration-verify` validates
the seal and all 42 source preconditions.
authoritative-source fingerprints. Source drift is a hard failure; HEAD drift
with identical authoritative bytes is reported but remains eligible, avoiding
self-invalidation when the plan itself is committed. `rmgr identifier migration-verify` validates
the seal and source preconditions, either fleet-wide or for one repository
atomic unit. Concurrent changes observed after the first seal were correctly
rejected; `--repo` prevents unrelated fleet churn from invalidating a stable
unit while still refusing the changed repository.
## Central-projection gate
@ -51,4 +56,5 @@ references split. Apply remains unauthorized until State Hub has:
4. an isolated PostgreSQL rehearsal proving forward and reverse mappings.
This is a discovered compatibility requirement, not a source-data blocker. The
sealed plan remains evidence; any source or HEAD drift requires regeneration.
sealed plan remains evidence; source or HEAD drift requires regeneration for
the affected repository before its apply.