From c52d222cc6e464e90d9dd3bf98d39190dfe4a6a1 Mon Sep 17 00:00:00 2001 From: tegwick Date: Mon, 31 Aug 2026 14:10:44 +0200 Subject: [PATCH] apply reef identifier batch 0006 Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a053ff-1d6f-7fe2-ac1c-a6eb40a42a0c --- AGENTS.md | 2 +- README.md | 4 +- ...026-005-reef-railiance-identifier-batch.md | 17 +++-- ...-0006-reef-railiance-cutover-2026-08-31.md | 70 +++++++++++++++++++ ...WP-0005-cache-centralization-2026-08-31.md | 2 +- src/repo_manager/cli.py | 4 +- src/repo_manager/identifiers.py | 2 +- src/repo_manager/projection_sync.py | 2 +- tests/test_fast_work_records.py | 2 +- tests/test_identifiers.py | 2 +- ...gistrar-consolidation-deterministic-ids.md | 18 ++++- 11 files changed, 109 insertions(+), 16 deletions(-) create mode 100644 docs/evidence/RMGR-WP-0005-batch-0006-reef-railiance-cutover-2026-08-31.md diff --git a/AGENTS.md b/AGENTS.md index 5d3ddc1..d0962d7 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -123,7 +123,7 @@ curl -s -X PATCH "http://127.0.0.1:8000/tasks/" \ rmgr sync --path . --push ``` The command assigns only missing deterministic identifiers, verifies the - pushed Forgejo commit and `primary/railliance01`, then requests one central + pushed Forgejo commit and `primary/railiance01`, then requests one central forge-derived reconciliation. A queued receipt is pending evidence; rerun after connectivity returns. Use `statehub fix-consistency` separately for a deep audit. `registrar-reconcile` is legacy migration/repair only. diff --git a/README.md b/README.md index 06a0af5..1f2e7a6 100644 --- a/README.md +++ b/README.md @@ -41,7 +41,7 @@ rmgr workplan delete --path . --workplan-id EX-WP-0001 --confirm # archives; ne rmgr task add --path . --workplan-id EX-WP-0001 --title "Implement" --description "Deliver it." rmgr task update --path . --task-id EX-WP-0001-T01 --status progress rmgr adhoc add --path . --title "Small fix" --description "Complete the bounded fix." -rmgr sync --path . --push # primary/railliance01 derives the exact pushed commit +rmgr sync --path . --push # primary/railiance01 derives the exact pushed commit rmgr register put --path . --kind technical-debt --entry-id TD-001 \ --title "Debt item" --data-json '{"severity":"high"}' rmgr register list --path . --kind technical-debt @@ -57,7 +57,7 @@ rmgr scaffold --path . --refresh-hub-access --no-commit # State Hub access tabl `rmgr sync` is the normal work-record closeout path. It uses the canonical kind registry, fills only missing deterministic UUIDv5 identifiers, refuses dirty or -behind workplan sources, verifies that the API is `primary/railliance01`, and +behind workplan sources, verifies that the API is `primary/railiance01`, and requests one central forge-derived reconciliation. A local/cache State Hub is never populated. `registrar-reconcile` remains only for sealed legacy UUID migration and repair. diff --git a/decisions/RMGR-DEC-2026-005-reef-railiance-identifier-batch.md b/decisions/RMGR-DEC-2026-005-reef-railiance-identifier-batch.md index 109c660..5fe888c 100644 --- a/decisions/RMGR-DEC-2026-005-reef-railiance-identifier-batch.md +++ b/decisions/RMGR-DEC-2026-005-reef-railiance-identifier-batch.md @@ -4,8 +4,8 @@ id: RMGR-DEC-2026-005 kind: decision title: Approve deterministic identifier batch 0006 for reef-railiance -status: open -decision_type: pending +status: resolved +decision_type: approved owner: Bernd Worsch repo: repo-manager workplan: RMGR-WP-0005 @@ -22,7 +22,7 @@ scope: repositories: [reef-railiance] replacements: 2 assignments: 0 -apply_authorized: false +apply_authorized: true approval_effect: >- Approved authorizes one repository-atomic forward cutover of exactly the pinned batch in the railiance01 primary projection and authoritative @@ -33,8 +33,17 @@ rollback: >- transaction using its durable aliases. evidence: docs/evidence/RMGR-WP-0005-batch-0006-reef-railiance-preflight-2026-08-31.json created: "2026-08-31" -updated: "2026-08-31" +updated: "2026-08-31T11:23:46.601904Z" state_hub_decision_id: "a0616e13-cd0c-441a-8339-f0e502bb2bbf" +approved_batch_sha256: 102061f3ed93eac091e9ceb05d9d3130241a23134b9f7d5a624d91c4ef824759 +approval_source: operator chat approval on 2026-08-31 +rationale: >- + Bernd Worsch approved exactly batch SHA-256 + 102061f3ed93eac091e9ceb05d9d3130241a23134b9f7d5a624d91c4ef824759 + for the reef-railiance-only cutover. No assignments, later fleet plan, or + broader repository scope is authorized. +decided_by: Bernd Worsch +decided_at: "2026-08-31T11:23:46.601904Z" ``` ## Decision requested diff --git a/docs/evidence/RMGR-WP-0005-batch-0006-reef-railiance-cutover-2026-08-31.md b/docs/evidence/RMGR-WP-0005-batch-0006-reef-railiance-cutover-2026-08-31.md new file mode 100644 index 0000000..6ecf9f9 --- /dev/null +++ b/docs/evidence/RMGR-WP-0005-batch-0006-reef-railiance-cutover-2026-08-31.md @@ -0,0 +1,70 @@ +# RMGR-WP-0005 batch 0006 reef-railiance cutover + +Date: 2026-08-31 + +## Authorization + +Bernd Worsch approved `RMGR-DEC-2026-005` as written. The approval is limited +to batch seal +`102061f3ed93eac091e9ceb05d9d3130241a23134b9f7d5a624d91c4ef824759`, +source-plan seal +`af3c8e3fe6f423845a97258a10322eeded4b7814d13bf9541b5d550c285cc0b9`, +repository `reef-railiance`, two replacements, and zero assignments. State Hub +decision `a0616e13-cd0c-441a-8339-f0e502bb2bbf` is resolved with +`decision_type: made` and `decided_by: Bernd Worsch`. + +## Final preflight + +`rmgr identifier migration-batch-verify` returned `ok: true`, +`ready_for_decision: true`, the exact batch and plan seals above, repository +`reef-railiance`, and no errors. The file phase dry-run reported one file, two +replacements, zero assignments, and no write. + +The source was clean and synchronized at sealed HEAD +`3e98b10d81990c45465f3f620441d97347670b52`. The primary health identity was: + +- role: `primary` +- label: `railiance01` +- schema: `a4d5e6f7b8c9` current + +## Execution + +The first projection command omitted the explicit instance-label override. It +refused before mutation because the Repo Manager default was misspelled +`railliance01`. Repeating the command with +`--expected-instance-label railiance01` passed every source and Git precondition. +The default spelling is corrected in this closeout change set. + +The forward projection receipt reported: + +- `replacements: 2` +- `migrated: 2` +- `already_derived: 0` +- `assignments_deferred: 0` + +The atomic file phase then touched only +`workplans/REEF-RAILIANCE-WP-0003-rapp-qonto-production-gates.md`, replacing: + +| Record | Legacy UUID | Deterministic UUID | +| --- | --- | --- | +| `REEF-RAILIANCE-WP-0003` | `c3f9fbfd-3db1-4387-8b65-7d53ba57138d` | `8ac413ad-2f57-53e6-b586-c5bec9cfbd1f` | +| `REEF-RAILIANCE-WP-0003-T04` | `9d0c1f61-0ed8-4d5c-b4c2-2578424ad3b4` | `9d792070-5f2b-5b3d-ba52-92c8b0d4a6b8` | + +`statehub fix-consistency` completed after the rewrite and refreshed the reef +brief in automatic commit `cec61da`. The authoritative UUID change is pushed to +Forgejo in reef commit `dcf51b3`. + +## Post-cutover verification + +- The deterministic workplan and task endpoints return their original record + identities, content, and lifecycle states. +- The migrated task has + `workplan_id: 8ac413ad-2f57-53e6-b586-c5bec9cfbd1f`. +- The two legacy UUID endpoints return 404, as expected: durable migration + aliases support governed reversal but are not public read redirects. +- The reef repository is clean and synchronized with `origin/main` after push. +- The authoritative diff contains exactly two UUID replacements and no content + or status changes. +- Repo Manager verification passed: `148 passed` and Ruff reported no issues. + +No rollback was required. diff --git a/docs/evidence/RMGR-WP-0005-cache-centralization-2026-08-31.md b/docs/evidence/RMGR-WP-0005-cache-centralization-2026-08-31.md index 511ef10..580065a 100644 --- a/docs/evidence/RMGR-WP-0005-cache-centralization-2026-08-31.md +++ b/docs/evidence/RMGR-WP-0005-cache-centralization-2026-08-31.md @@ -3,7 +3,7 @@ Date: 2026-08-31 The workstation no longer runs a State Hub API. `127.0.0.1:8000` is the -operator's SSH relay to the sole `railliance01` primary, whose health reports +operator's SSH relay to the sole `railiance01` primary, whose health reports `instance_role: primary`, `instance_label: railiance01`, and a current schema. The retired production sweep remains disabled and has no checkout or SSH hostPath mount. diff --git a/src/repo_manager/cli.py b/src/repo_manager/cli.py index e6d7654..1ebcb9d 100644 --- a/src/repo_manager/cli.py +++ b/src/repo_manager/cli.py @@ -185,7 +185,7 @@ def main(argv: list[str] | None = None) -> int: p_sync.add_argument("--path", default=".") p_sync.add_argument("--slug", default=None) p_sync.add_argument("--api-base", default=os.environ.get("STATE_HUB_API_BASE", "http://127.0.0.1:8000")) - p_sync.add_argument("--expected-instance-label", default="railliance01") + p_sync.add_argument("--expected-instance-label", default="railiance01") p_sync.add_argument("--push", action="store_true", help="Push ahead commits before reconciliation") p_sync.add_argument("--no-commit-identifiers", action="store_true") p_sync.add_argument("--acknowledge-retirements", action="store_true") @@ -456,7 +456,7 @@ def main(argv: list[str] | None = None) -> int: p_id_projection.add_argument("--repo", required=True) p_id_projection.add_argument("--confirm-plan-sha256", required=True) p_id_projection.add_argument("--api-base", required=True) - p_id_projection.add_argument("--expected-instance-label", default="railliance01") + p_id_projection.add_argument("--expected-instance-label", default="railiance01") p_id_projection.add_argument( "--direction", choices=["forward", "reverse"], default="forward" ) diff --git a/src/repo_manager/identifiers.py b/src/repo_manager/identifiers.py index be45177..98fa840 100644 --- a/src/repo_manager/identifiers.py +++ b/src/repo_manager/identifiers.py @@ -990,7 +990,7 @@ def migrate_repository_projection( confirm_plan_sha256: str, api_base: str, direction: str = "forward", - expected_instance_label: str | None = "railliance01", + expected_instance_label: str | None = "railiance01", transport: httpx.BaseTransport | None = None, ) -> dict[str, Any]: """Apply or reverse the sealed projection half on the authoritative hub.""" diff --git a/src/repo_manager/projection_sync.py b/src/repo_manager/projection_sync.py index 23fc2d4..74558da 100644 --- a/src/repo_manager/projection_sync.py +++ b/src/repo_manager/projection_sync.py @@ -73,7 +73,7 @@ def sync_repository_projection( *, api_base: str, repo_slug: str | None = None, - expected_instance_label: str | None = "railliance01", + expected_instance_label: str | None = "railiance01", commit_identifiers: bool = True, push: bool = False, acknowledge_retirements: bool = False, diff --git a/tests/test_fast_work_records.py b/tests/test_fast_work_records.py index 6dfd543..cdaffe4 100644 --- a/tests/test_fast_work_records.py +++ b/tests/test_fast_work_records.py @@ -162,7 +162,7 @@ def test_sync_uses_two_requests_and_exact_pushed_commit(tmp_path: Path) -> None: if request.url.path == "/state/health": return httpx.Response( 200, - json={"status": "ok", "instance_role": "primary", "instance_label": "railliance01"}, + json={"status": "ok", "instance_role": "primary", "instance_label": "railiance01"}, ) payload = __import__("json").loads(request.content) assert ( diff --git a/tests/test_identifiers.py b/tests/test_identifiers.py index e0add08..7060c35 100644 --- a/tests/test_identifiers.py +++ b/tests/test_identifiers.py @@ -105,7 +105,7 @@ def test_projection_migration_client_requires_primary_and_exact_seal(tmp_path: P json={ "status": "ok", "instance_role": "primary", - "instance_label": "railliance01", + "instance_label": "railiance01", }, ) assert request.url.path == "/identifier-migrations/repositories/one/apply" diff --git a/workplans/RMGR-WP-0005-registrar-consolidation-deterministic-ids.md b/workplans/RMGR-WP-0005-registrar-consolidation-deterministic-ids.md index 4a00e2b..36b83be 100644 --- a/workplans/RMGR-WP-0005-registrar-consolidation-deterministic-ids.md +++ b/workplans/RMGR-WP-0005-registrar-consolidation-deterministic-ids.md @@ -660,7 +660,21 @@ unauthorized; exact batch seal: `docs/evidence/RMGR-WP-0005-batch-0006-reef-railiance-preflight-2026-08-31.json`. The inevitable Repo Manager evidence commit invalidates whole-fleet source verification for `repo-manager` itself, but repository-filtered verification of -the sealed source plan for `reef-railiance` remains clean. No mutation has run. +the sealed source plan for `reef-railiance` remains clean. + +**Batch 0006 applied (2026-08-31):** Bernd Worsch approved exactly batch seal +`102061f3ed93eac091e9ceb05d9d3130241a23134b9f7d5a624d91c4ef824759` +through `RMGR-DEC-2026-005`. The final batch verification passed with no drift. +The railiance01 primary then migrated both legacy rows transactionally, with +zero assignments or already-derived rows, and the atomic file phase changed +only the two sealed UUID fields in +`REEF-RAILIANCE-WP-0003-rapp-qonto-production-gates.md`. Post-cutover checks +confirmed both derived records, the task-to-workplan relationship, unchanged +lifecycle state, a clean consistency audit, and the pushed reef commit +`dcf51b3`. The initial projection attempt refused safely before mutation because +the CLI default misspelled the primary label as `railliance01`; the corrected +`railiance01` default is covered by the same change set. Evidence: +`docs/evidence/RMGR-WP-0005-batch-0006-reef-railiance-cutover-2026-08-31.md`. ## Retire the interim rule @@ -746,7 +760,7 @@ repeat comparison passes. Evidence and the non-destructive procedure are in `docs/cache-rebuild_v1.md`. **Done with explicit disposition 2026-08-31.** The workstation State Hub API is -gone; its loopback address is now a relay to the sole `railliance01` primary. +gone; its loopback address is now a relay to the sole `railiance01` primary. Repo Manager's advisory cache rebuilt 96 current records at commit `e8e2747` and immediately reported fresh with matching source fingerprints. The old local-only hub-native rows were not migrated before the local database was