From d63f8b27e7040229919b76331018438d22117d8b Mon Sep 17 00:00:00 2001 From: tegwick Date: Mon, 31 Aug 2026 12:14:33 +0200 Subject: [PATCH] docs: close stale repo manager work Assistant: codex Assistant-Model: gpt-5.6-sol Assistant-Session: 01a053ff-1d6f-7fe2-ac1c-a6eb40a42a0c --- WORK-RECORDS.md | 10 +++--- ...WP-0005-cache-centralization-2026-08-31.md | 28 +++++++++++++++ ...0011-production-client-proof-2026-08-31.md | 35 +++++++++++++++++++ .../commands/registrar_reconcile.py | 6 ++-- tests/test_registrar_reconcile.py | 4 ++- ...gistrar-consolidation-deterministic-ids.md | 30 ++++++++++++++-- ...GR-WP-0011-sbom-nexus-production-client.md | 31 ++++++++++++---- 7 files changed, 126 insertions(+), 18 deletions(-) create mode 100644 docs/evidence/RMGR-WP-0005-cache-centralization-2026-08-31.md create mode 100644 docs/evidence/RMGR-WP-0011-production-client-proof-2026-08-31.md diff --git a/WORK-RECORDS.md b/WORK-RECORDS.md index 2bb7f96..06758ef 100644 --- a/WORK-RECORDS.md +++ b/WORK-RECORDS.md @@ -18,7 +18,7 @@ | workplan | RMGR-WP-0008 | finished | — | workplans/RMGR-WP-0008-work-record-and-register-receiving-surface.md | | workplan | RMGR-WP-0009 | finished | — | workplans/RMGR-WP-0009-coding-assistant-commit-provenance.md | | workplan | RMGR-WP-0010 | finished | — | workplans/RMGR-WP-0010-authoritative-workload-references.md | -| workplan | RMGR-WP-0011 | active | — | workplans/RMGR-WP-0011-sbom-nexus-production-client.md | +| workplan | RMGR-WP-0011 | finished | — | workplans/RMGR-WP-0011-sbom-nexus-production-client.md | | workplan | RMGR-WP-0012 | finished | — | workplans/RMGR-WP-0012-fast-work-record-mutation-and-projection.md | | task | RMGR-WP-0001-T01 | done | — | workplans/RMGR-WP-0001-foundation.md | | task | RMGR-WP-0001-T02 | done | — | workplans/RMGR-WP-0001-foundation.md | @@ -45,17 +45,17 @@ | task | RMGR-WP-0004-T08 | done | — | workplans/RMGR-WP-0004-repository-standards-conformance.md | | task | RMGR-WP-0004-T09 | done | — | workplans/RMGR-WP-0004-repository-standards-conformance.md | | task | RMGR-WP-0005-T01 | done | — | workplans/RMGR-WP-0005-registrar-consolidation-deterministic-ids.md | -| task | RMGR-WP-0005-T02 | wait | — | workplans/RMGR-WP-0005-registrar-consolidation-deterministic-ids.md | +| task | RMGR-WP-0005-T02 | cancel | — | workplans/RMGR-WP-0005-registrar-consolidation-deterministic-ids.md | | task | RMGR-WP-0005-T03 | done | — | workplans/RMGR-WP-0005-registrar-consolidation-deterministic-ids.md | | task | RMGR-WP-0005-T04 | progress | — | workplans/RMGR-WP-0005-registrar-consolidation-deterministic-ids.md | | task | RMGR-WP-0005-T05 | wait | — | workplans/RMGR-WP-0005-registrar-consolidation-deterministic-ids.md | | task | RMGR-WP-0005-T06 | done | — | workplans/RMGR-WP-0005-registrar-consolidation-deterministic-ids.md | -| task | RMGR-WP-0005-T07 | progress | — | workplans/RMGR-WP-0005-registrar-consolidation-deterministic-ids.md | +| task | RMGR-WP-0005-T07 | done | — | workplans/RMGR-WP-0005-registrar-consolidation-deterministic-ids.md | | task | RMGR-WP-0005-T08 | done | — | workplans/RMGR-WP-0005-registrar-consolidation-deterministic-ids.md | | task | RMGR-WP-0005-T09 | done | — | workplans/RMGR-WP-0005-registrar-consolidation-deterministic-ids.md | | task | RMGR-WP-0005-T10 | done | — | workplans/RMGR-WP-0005-registrar-consolidation-deterministic-ids.md | | task | RMGR-WP-0005-T11 | done | — | workplans/RMGR-WP-0005-registrar-consolidation-deterministic-ids.md | -| task | RMGR-WP-0005-T12 | wait | — | workplans/RMGR-WP-0005-registrar-consolidation-deterministic-ids.md | +| task | RMGR-WP-0005-T12 | cancel | — | workplans/RMGR-WP-0005-registrar-consolidation-deterministic-ids.md | | task | RMGR-WP-0006-T01 | done | — | workplans/RMGR-WP-0006-railiance-app-wrapper-setup.md | | task | RMGR-WP-0006-T02 | done | — | workplans/RMGR-WP-0006-railiance-app-wrapper-setup.md | | task | RMGR-WP-0006-T03 | done | — | workplans/RMGR-WP-0006-railiance-app-wrapper-setup.md | @@ -92,7 +92,7 @@ | task | RMGR-WP-0011-T01 | done | — | workplans/RMGR-WP-0011-sbom-nexus-production-client.md | | task | RMGR-WP-0011-T02 | done | — | workplans/RMGR-WP-0011-sbom-nexus-production-client.md | | task | RMGR-WP-0011-T03 | done | — | workplans/RMGR-WP-0011-sbom-nexus-production-client.md | -| task | RMGR-WP-0011-T04 | progress | — | workplans/RMGR-WP-0011-sbom-nexus-production-client.md | +| task | RMGR-WP-0011-T04 | done | — | workplans/RMGR-WP-0011-sbom-nexus-production-client.md | | task | RMGR-WP-0012-T01 | done | — | workplans/RMGR-WP-0012-fast-work-record-mutation-and-projection.md | | task | RMGR-WP-0012-T02 | done | — | workplans/RMGR-WP-0012-fast-work-record-mutation-and-projection.md | | task | RMGR-WP-0012-T03 | done | — | workplans/RMGR-WP-0012-fast-work-record-mutation-and-projection.md | diff --git a/docs/evidence/RMGR-WP-0005-cache-centralization-2026-08-31.md b/docs/evidence/RMGR-WP-0005-cache-centralization-2026-08-31.md new file mode 100644 index 0000000..511ef10 --- /dev/null +++ b/docs/evidence/RMGR-WP-0005-cache-centralization-2026-08-31.md @@ -0,0 +1,28 @@ +# RMGR-WP-0005 cache and hub-native centralization evidence + +Date: 2026-08-31 + +The workstation no longer runs a State Hub API. `127.0.0.1:8000` is the +operator's SSH relay to the sole `railliance01` primary, whose health reports +`instance_role: primary`, `instance_label: railiance01`, and a current schema. +The retired production sweep remains disabled and has no checkout or SSH +hostPath mount. + +Repo Manager's advisory file cache was rebuilt from the current checkout at +commit `e8e2747313f1f041062980a962466a7a39daa98d`. It contains 96 records, +reports `stale: false`, and its indexed/current source fingerprint is +`b9cee3bce4ca7d1a28cadb5f9204774a0451a6456efbc3d02f9e556a27b8d6b9`. + +The earlier workstation database had recorded 35 progress events linked to +`RMGR-WP-0005` and 13 messages to/from `repo-manager`, while the then-primary +had 2 and 0. On 2026-08-31 the central primary contains 10 linked progress +events and one direct Repo Manager message. A read-only query of the remaining +local PostgreSQL service found an empty replacement database: zero matching +progress events and zero matching messages. The old local-only rows therefore +cannot now be migrated; the infrastructure cutover has dispositioned them as +discarded cache history. Their counts and the material implementation outcomes +remain in the 2026-08-22 evidence and this workplan. + +This is a limitation, not a reconstructed-history claim. New hub-native writes +have one owner, the central primary; local work remains file-first and the +advisory cache is disposable/rebuildable. diff --git a/docs/evidence/RMGR-WP-0011-production-client-proof-2026-08-31.md b/docs/evidence/RMGR-WP-0011-production-client-proof-2026-08-31.md new file mode 100644 index 0000000..9493f48 --- /dev/null +++ b/docs/evidence/RMGR-WP-0011-production-client-proof-2026-08-31.md @@ -0,0 +1,35 @@ +# RMGR-WP-0011 production SBOM Nexus client proof + +Date: 2026-08-31 + +The owning coordination workplan `CUST-WP-0064` is finished. Production SBOM +Nexus is healthy on immutable digest +`sha256:1da0f4f008643a0dec3f00bbad15f287103aa4b469577b78cfe1d67f8b3cbe31` +with migration `0002`; controlled `forgejo-archive-v1` scans and an unassisted +scheduled authoritative snapshot are evidenced by that plan. + +Against a temporary operator-only port-forward to the internal Nexus Service, +Repo Manager's own command completed successfully: + +```text +SBOM_NEXUS_URL=http://127.0.0.1:18010 uv run rmgr sbom source-ref \ + --path . --slug repo-manager --project --confirm-authoritative +``` + +It resolved `coulomb/repo-manager` at exact public Forge revision +`e8e2747313f1f041062980a962466a7a39daa98d`, projected +`kind: forgejo-archive-v1` with `checkout_path: null`, and Nexus echoed the +structured source reference unchanged. The response was explicitly +`mode: authoritative-service`, `authoritative: true`, +`product_owner: sbom-nexus`, and `writes_state: true`. + +The same production client read the latest-snapshot and licence-report routes. +Both returned the authoritative-service context; the fleet licence report had +19 groups and 4 direct copyleft production findings. Repo Manager's own +repository currently has no persisted snapshot (`snapshot_id: null`, zero +entries), which is truthful Nexus state rather than a local preview. + +Source inspection finds SBOM behavior only in the bounded Nexus client, +controlled source-reference resolver, and deprecated local-preview delegate. +Repo Manager contains no scanner, snapshot store, freshness/catch-up policy, or +licence classifier. The temporary port-forward was stopped after the proof. diff --git a/src/repo_manager/commands/registrar_reconcile.py b/src/repo_manager/commands/registrar_reconcile.py index 1249d66..d02cf91 100644 --- a/src/repo_manager/commands/registrar_reconcile.py +++ b/src/repo_manager/commands/registrar_reconcile.py @@ -219,8 +219,10 @@ def _check_git(repo: Path) -> tuple[dict[str, Any], str | None]: if blocking: return ( {"dirty": dirty, "ignored_generated": generated}, - "worktree must be clean before registrar reconciliation; " - f"blocking: {', '.join(blocking)}", + ( + "worktree must be clean before registrar reconciliation; " + f"blocking: {', '.join(blocking)}" + ), ) upstream = _git(repo, "rev-parse", "--abbrev-ref", "--symbolic-full-name", "@{u}") diff --git a/tests/test_registrar_reconcile.py b/tests/test_registrar_reconcile.py index 30d2482..cef6165 100644 --- a/tests/test_registrar_reconcile.py +++ b/tests/test_registrar_reconcile.py @@ -784,7 +784,9 @@ class TestWorkplanBindings: lambda url, json=None, timeout=None: (sent.update(b=json["bindings"]), R())[1], ) rr._sync_workplan_bindings(repo, "http://hub", "demo") - legacy = [b for b in sent["b"] if b["workplan_id"].startswith("44444444")][0] + legacy = next( + b for b in sent["b"] if b["workplan_id"].startswith("44444444") + ) assert legacy["status"] is None def test_binding_failure_never_fails_registration(self, tmp_path, monkeypatch): diff --git a/workplans/RMGR-WP-0005-registrar-consolidation-deterministic-ids.md b/workplans/RMGR-WP-0005-registrar-consolidation-deterministic-ids.md index e903575..4a00e2b 100644 --- a/workplans/RMGR-WP-0005-registrar-consolidation-deterministic-ids.md +++ b/workplans/RMGR-WP-0005-registrar-consolidation-deterministic-ids.md @@ -236,7 +236,7 @@ credential path that does not mount an operator home or private-key directory. ```task id: RMGR-WP-0005-T12 -status: wait +status: cancel priority: high state_hub_task_id: "0d69713d-0596-5415-b40c-8f5035641541" ``` @@ -251,11 +251,17 @@ Coordinate credential custody with the platform owner and keep the schedule disabled until positive allowed-repository and negative unrelated-repository push evidence exist without exposing credential values. +**Cancelled 2026-08-31.** The host-wide sweep is retired, not awaiting +re-enablement. Production continues with `sweep.enabled: false`, no checkout +hostPath, and no operator SSH mount. A future scoped sweep would be a new +capability with its own workplan and credential route; keeping a conditional +task open here incorrectly implies the retired design is on the critical path. + ## Re-register identifiers minted outside the registrar ```task id: RMGR-WP-0005-T02 -status: wait +status: cancel priority: medium state_hub_task_id: "7892ca86-bd89-537e-9361-d648dff8e4b2" ``` @@ -329,6 +335,13 @@ and pushed Custodian revision `d792318`. The full historical identity report remained in evidence while `blocking_invalid_identifiers` and `blocking_identity_collisions` were both empty, proving the intended boundary. +**Superseded 2026-08-31.** T03 and T04 replaced hand re-registration as the +governed convergence path. The fresh fleet plan covers every eligible live +record as `replace`, `assign`, or `unchanged`; closed pre-derivation UUIDs stay +frozen historical evidence. No remaining record should be repaired through the +old registrar-minting procedure, so this task is cancelled rather than left in +permanent conditional wait. + ## Derive identifiers deterministically ```task @@ -669,7 +682,7 @@ byte-identical writeback, and neither creates a duplicate record. ```task id: RMGR-WP-0005-T07 -status: progress +status: done priority: high state_hub_task_id: "e3c2a791-f632-59f3-9929-b179e45c77d0" ``` @@ -732,6 +745,17 @@ repeat comparison passes. Evidence and the non-destructive procedure are in `docs/evidence/RMGR-WP-0005-isolated-rebuild-2026-08-22.md` and `docs/cache-rebuild_v1.md`. +**Done with explicit disposition 2026-08-31.** The workstation State Hub API is +gone; its loopback address is now a relay to the sole `railliance01` primary. +Repo Manager's advisory cache rebuilt 96 current records at commit `e8e2747` +and immediately reported fresh with matching source fingerprints. The old +local-only hub-native rows were not migrated before the local database was +replaced: the current local PostgreSQL database contains zero matching progress +events or messages. They are therefore dispositioned as discarded cache +history, not claimed as reconstructed. Central now exclusively owns new +hub-native writes. Exact counts and the limitation are retained in +`docs/evidence/RMGR-WP-0005-cache-centralization-2026-08-31.md`. + ## Separate file-derived from hub-native data ```task diff --git a/workplans/RMGR-WP-0011-sbom-nexus-production-client.md b/workplans/RMGR-WP-0011-sbom-nexus-production-client.md index 6a423e6..f41a9c0 100644 --- a/workplans/RMGR-WP-0011-sbom-nexus-production-client.md +++ b/workplans/RMGR-WP-0011-sbom-nexus-production-client.md @@ -4,12 +4,19 @@ type: workplan title: "SBOM Nexus production client and explicit preview semantics" domain: infotech repo: repo-manager -status: active +status: finished owner: codex topic_slug: infotech quality_dor: DoR-Ok created: "2026-08-22" -updated: "2026-08-22" +updated: "2026-08-31" +quality_dod: DoD-Ok +quality_dod_at: "2026-08-31" +quality_dod_by: codex +quality_dod_note: >- + Contract, failure semantics, explicit preview mode, controlled source + projection, and live authoritative Nexus reads are evidenced; durable SBOM + ownership remains solely with SBOM Nexus. parent_workplan: SBOM-WP-0002 related: - CUST-WP-0062 @@ -109,7 +116,7 @@ contract tests carry the same semantics. ```task id: RMGR-WP-0011-T04 -status: progress +status: done priority: medium state_hub_task_id: "81fed060-3431-5d9b-819b-fcc7d629c364" ``` @@ -143,13 +150,23 @@ pre-contract service cannot silently discard it. Live read-only proof resolved `refs/heads/main`. Remaining T04 work is the Nexus/package/Activity Core implementation and attended production proof owned through `CUST-WP-0064`. +**Done 2026-08-31.** `CUST-WP-0064` is finished and production Nexus is +healthy on the controlled-source implementation. Repo Manager's own +`source-ref --project --confirm-authoritative` command resolved the exact +Forgejo `main` revision, projected it with `checkout_path: null`, and received +the identical source reference from Nexus. Its production client also consumed +the latest-snapshot and licence-report routes with explicit +`authoritative-service` context. Source inspection confirms Repo Manager holds +no scanner, snapshot store, freshness/catch-up policy, or licence classifier. +Evidence: `docs/evidence/RMGR-WP-0011-production-client-proof-2026-08-31.md`. + ## Acceptance -- Authoritative mode talks to SBOM Nexus and returns its pinned snapshot +- [x] Authoritative mode talks to SBOM Nexus and returns its pinned snapshot contract without local persistence. -- Preview mode is visibly non-authoritative and cannot be mistaken for an +- [x] Preview mode is visibly non-authoritative and cannot be mistaken for an ingest receipt. -- Existing `rmgr sbom scan|licence-report` users receive a documented migration +- [x] Existing `rmgr sbom scan|licence-report` users receive a documented migration path and deterministic errors. -- Repo Manager remains authoritative only for repository identity and paths; +- [x] Repo Manager remains authoritative only for repository identity and paths; SBOM Nexus remains the sole durable SBOM owner.