Commit graph

195 commits

Author SHA1 Message Date
custodian-sync
1362fe7e5b chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-31:
  - update .custodian-brief.md for repo-manager

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a053ff-1d6f-7fe2-ac1c-a6eb40a42a0c
2026-08-31 19:42:25 +02:00
14ee8e7558 finish deterministic identifier migration
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a053ff-1d6f-7fe2-ac1c-a6eb40a42a0c
2026-08-31 19:40:29 +02:00
4c146f5a92 record fleet identifier batch approval
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a053ff-1d6f-7fe2-ac1c-a6eb40a42a0c
2026-08-31 18:15:37 +02:00
8f3b8ac2f6 prepare fleet identifier completion batch
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a053ff-1d6f-7fe2-ac1c-a6eb40a42a0c
2026-08-31 17:02:19 +02:00
c52d222cc6 apply reef identifier batch 0006
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a053ff-1d6f-7fe2-ac1c-a6eb40a42a0c
2026-08-31 14:10:44 +02:00
d63f8b27e7 docs: close stale repo manager work
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a053ff-1d6f-7fe2-ac1c-a6eb40a42a0c
2026-08-31 12:14:33 +02:00
custodian-sync
a2c9d7fbeb chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-31:
  - update .custodian-brief.md for repo-manager

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a053ff-1d6f-7fe2-ac1c-a6eb40a42a0c
2026-08-31 11:56:09 +02:00
e8e2747313 docs: prepare reef identifier batch
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a053ff-1d6f-7fe2-ac1c-a6eb40a42a0c
2026-08-31 06:36:02 +02:00
10ed36f89d docs: close mixed convergence pilot
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a053ff-1d6f-7fe2-ac1c-a6eb40a42a0c
2026-08-31 02:11:20 +02:00
custodian-sync
7a38c0b037 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-31:
  - update .custodian-brief.md for repo-manager

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a053ff-1d6f-7fe2-ac1c-a6eb40a42a0c
2026-08-31 02:11:08 +02:00
54507b975a docs: approve state-hub identifier pilot
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a053ff-1d6f-7fe2-ac1c-a6eb40a42a0c
2026-08-31 01:36:38 +02:00
5789e8c520 feat: support mixed identifier convergence
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a053ff-1d6f-7fe2-ac1c-a6eb40a42a0c
2026-08-31 01:27:21 +02:00
4901b6d623 docs: close fast work-record rollout
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a053ff-1d6f-7fe2-ac1c-a6eb40a42a0c
2026-08-30 23:24:16 +02:00
repo-manager
776b0db69d chore(registrar): assign State Hub identifiers
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a053ff-1d6f-7fe2-ac1c-a6eb40a42a0c
2026-08-30 23:07:59 +02:00
custodian-sync
07682bfea4 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-30:
  - update .custodian-brief.md for repo-manager

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a053ff-1d6f-7fe2-ac1c-a6eb40a42a0c
2026-08-30 23:07:58 +02:00
58414404d6 feat: add governed fast work-record sync
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a053ff-1d6f-7fe2-ac1c-a6eb40a42a0c
2026-08-30 22:38:54 +02:00
7ea7690dfc fix registrar writebacks and own the State Hub access map
Ignore generated WORK-RECORDS.md/.custodian-brief.md in the registrar git
precondition, commit identifier writebacks even when registration is
incomplete, and name the remaining records in the error. Add
config/state-hub-access.yaml as the single source for the AGENTS.md port
map, rendered by rmgr scaffold and refreshed with --refresh-hub-access.

Assistant: grok
Assistant-Session: 01a04996-76e8-7f53-b971-1885cfbed436
2026-08-28 20:48:21 +02:00
77caca1ab8 chore(registrar): register WNCTL-WP to whynot-control
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2583210@bnt-lap001
Assistant-Session: f2bff2d5-e9b2-4338-92ca-10282a927006
2026-08-28 14:15:10 +02:00
906cc2d7a9 fix(registrar): OPS-WP belongs to ops-hub, not retirement
I retired OPS-WP on the reasoning that it names an ops family rather than a
repository, without checking whether a repo owns it. ops-hub does: all 14 of
its workplans use it. The anomaly is the reverse of what I wrote - the 16
OPS-WP ids in ops-bridge are the strays, against its 73 BRIDGE-WP ids.

Recorded as debt rather than fixed here: re-keying those 16 to BRIDGE-WP is a
separate migration with its own hub retirements, and today's pass is scoped to
ad-hoc identifiers.

WHYNOT-WP stays with whynot-design (26 ids vs whynot-control's 6), ruled by
Bernd. whynot-control's 6 are the same class of stray.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2583210@bnt-lap001
Assistant-Session: f2bff2d5-e9b2-4338-92ca-10282a927006
2026-08-28 00:58:57 +02:00
0e04329ae0 chore(registrar): register RAIL-FAB-WP and WHYNOT-WP
Both needed for the archived ad-hoc pass; each used consistently in its repo
(160 and 26 ids) with no collision against an existing owner or retired prefix.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2583210@bnt-lap001
Assistant-Session: f2bff2d5-e9b2-4338-92ca-10282a927006
2026-08-28 00:34:06 +02:00
5acb21a0de chore(registrar): register 14 repository prefixes, retire NET-WP and OPS-WP
Qualifying ad-hoc identifiers requires every repo to own a registered prefix,
and 13 of the 17 affected repos were absent from the registry despite using a
prefix consistently across dozens of files. None collided with an existing
owner or a retired prefix.

net-kingdom and ops-bridge each used two forms. NK-WP (229 ids vs NET-WP's 49)
and BRIDGE-WP (73 vs OPS-WP's 16) are the owners, ruled by Bernd. OPS-WP is
additionally retired for naming an ops family rather than a repository - the
same defect ADR-007 retired RAILIANCE-WP and PRJ-WP for. Existing NET-WP and
OPS-WP ids stay as they are; only their prefixes are closed to new work.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2583210@bnt-lap001
Assistant-Session: f2bff2d5-e9b2-4338-92ca-10282a927006
2026-08-28 00:28:47 +02:00
custodian-sync
6db1f7f1fd chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-25:
  - update .custodian-brief.md for repo-manager

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2583210@bnt-lap001
Assistant-Session: f2bff2d5-e9b2-4338-92ca-10282a927006
2026-08-25 20:22:25 +02:00
c3f4ece7ea fix(workplans): adopt ADR-007 derived identifiers for unregistered records
These workplans exist only in the retired local hub. Their random pre-ADR-007
identifiers are refused by C-06 as stale references, so they cannot be
registered. Deriving from the canonical record id takes no identity from
anything: central does not hold them and the old ids die with the cache.

Records central already holds were deliberately left untouched.

Refs CUST-WP-0068-T06

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2583210@bnt-lap001
Assistant-Session: f2bff2d5-e9b2-4338-92ca-10282a927006
2026-08-25 20:21:52 +02:00
custodian-sync
fdd896b203 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-25:
  - update .custodian-brief.md for repo-manager

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2583210@bnt-lap001
Assistant-Session: f2bff2d5-e9b2-4338-92ca-10282a927006
2026-08-25 20:00:07 +02:00
ebf114abd6 fix(registrar): register records that have an identifier but are absent from the hub
Two blockers kept 268 work records unrecoverable.

1. The registrar only looked for *missing* identifiers, so a record whose
   derived identifier was already in the file but absent from central was
   invisible to it and the run short-circuited to noop. C-06 handles exactly
   that case and marks it fixable; only the early return stood in the way.
   Records the hub holds under a *different* identifier are deliberately not
   touched — that is a duplicate-registration identity decision.

2. repo-onboard now corrects a stale remote_url from the working copy's origin.
   The forge migration moved every repository from Gitea to Forgejo but never
   updated the hub, leaving 50 records pointing at a retired forge. State Hub
   matches a checkout to its record by remote_url, so it could not find those
   repositories and refused to register any of their work records — the error
   surfaced only in a child process's stderr.

Verified on kaizen-agentic: 8 records on central before, 15 after.

Refs CUST-WP-0068-T06

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2583210@bnt-lap001
Assistant-Session: f2bff2d5-e9b2-4338-92ca-10282a927006
2026-08-25 19:42:10 +02:00
bdb981be2b fix(registrar): bind workplan files to their records in the same pass
backing_filename is what lets the read model tell a file-backed workplan from
a hub-only orphan. It is written by PUT /workplans/index/bindings, which
fix-consistency calls for workplans that already carry a UUID — but the
registrar mints the UUID afterwards, so a freshly registered workplan stayed
unbound until someone happened to run fix-consistency a second time.

Nobody did: 278 of 800 workplans on central recorded no backing file,
including four active and four ready. ADR-010 predicted this as the
"broken links" class.

The registrar now syncs bindings after minting, and on the noop path too —
otherwise a record whose earlier bind failed stays unbound forever, because
every later run returns early.

Binding never fails the registration: the identifiers are already minted and
committed, and a bind can be retried.

Status is sent only when already canonical. The binding schema validates
against the enum without normalising, so one legacy value 422s the whole
batch; omitting beats guessing a mapping that could drift from canon.

Refs CUST-WP-0068-T07

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2583210@bnt-lap001
Assistant-Session: f2bff2d5-e9b2-4338-92ca-10282a927006
2026-08-25 15:39:11 +02:00
667bac3080 style(registrar): fix continuation indent in _check_primary call
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2583210@bnt-lap001
Assistant-Session: f2bff2d5-e9b2-4338-92ca-10282a927006
2026-08-25 10:33:41 +02:00
10bdb683cb fix(registrar): make --confirm-primary assert authority, not liveness
_check_primary accepted any instance reporting status=ok and db=connected.
A local cache and the central hub both satisfied that for seven weeks while
every registration went to the cache — a liveness check wearing an authority
check's name.

It now requires the hub to declare instance_role=primary. An instance that
declares nothing is refused with a message naming what to set; proceeding
anyway requires an explicit --allow-unverified-primary rather than a silent
default.

Four tests cover the logic directly; the existing suite stubbed _check_primary
and never exercised it.

Refs CUST-WP-0067-T03

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2583210@bnt-lap001
Assistant-Session: f2bff2d5-e9b2-4338-92ca-10282a927006
2026-08-25 10:32:51 +02:00
68943631d8 docs(agents): repoint remote State Hub URL to the in-cluster address
The remote row pointed at 127.0.0.1:18000, a reverse tunnel back to the
workstation. On railiance01 the State Hub runs in the cluster on that same
machine, so the request left the box and came back to reach a local service.

Refs CUST-WP-0067-T07

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2583210@bnt-lap001
Assistant-Session: f2bff2d5-e9b2-4338-92ca-10282a927006
2026-08-25 00:21:56 +02:00
1be6d85397 feat(onboard): add rmgr repo-onboard, the missing managed_repos write path
hub-record-authority.yaml assigns managed_repos to repo-manager as
file-derived, but repo-manager exposed no command for it. The only working
path lived in the State Hub repo and defaulted to 127.0.0.1:8000, which is how
seven weeks of onboarding landed in a local cache instead of central.

Order follows ADR-010 decision 5: make the source file correct and reachable
first, then project it. Refuses to onboard when the classification file is
missing or invalid, has uncommitted changes, has no upstream, or has unpushed
commits — a hub record whose backing file is only local cannot be re-derived
by anyone else.

--api-base has no default on purpose. A silent localhost default is the
original defect, not a convenience.

A failed classification PATCH degrades to a warning rather than failing the
run: the authoritative record existing is what stops a repository from being
recoverable only through a discardable cache, and classification is a
projection of a committed file that can be re-derived later.

Refs CUST-WP-0067-T04

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 2583210@bnt-lap001
Assistant-Session: f2bff2d5-e9b2-4338-92ca-10282a927006
2026-08-24 23:33:22 +02:00
885575802c fix(identity): enforce qualified ad-hoc identifiers
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02b22-9638-76d2-bbff-b7ea1770b118
2026-08-23 14:45:26 +02:00
2f74cbd3dd chore(canon): sync work-record identifier grammar
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02b22-9638-76d2-bbff-b7ea1770b118
2026-08-23 14:11:15 +02:00
762fa919db docs(registrar): record Custodian proof
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02b22-9638-76d2-bbff-b7ea1770b118
2026-08-23 12:29:50 +02:00
7b9fdaa734 fix(registrar): bound slow consistency runs
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02b22-9638-76d2-bbff-b7ea1770b118
2026-08-23 11:58:43 +02:00
7a15f1da21 fix(registrar): scope identity preflight
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a02b22-9638-76d2-bbff-b7ea1770b118
2026-08-23 11:49:59 +02:00
4398167580 fix(identifiers): reject unproven assignments
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a023c0-a0a3-7c03-b395-5a0d2757214d
2026-08-22 23:54:24 +02:00
055c6971ab feat(identifiers): verify batch projections
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a023c0-a0a3-7c03-b395-5a0d2757214d
2026-08-22 23:50:34 +02:00
e6cc18bf18 feat(sbom): project immutable Forgejo source refs
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a023c0-a0a3-7c03-b395-5a0d2757214d
2026-08-22 23:34:01 +02:00
b068e9da42 feat(sbom): add authoritative Nexus client
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a023c0-a0a3-7c03-b395-5a0d2757214d
2026-08-22 23:26:45 +02:00
custodian-sync
135b1647d7 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-22:
  - update .custodian-brief.md for repo-manager

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a023c0-a0a3-7c03-b395-5a0d2757214d
2026-08-22 23:26:32 +02:00
84952c5212 feat: harden work-record and SBOM client contracts
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a023c0-a0a3-7c03-b395-5a0d2757214d
2026-08-22 23:19:36 +02:00
custodian-sync
2577379e36 chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-22:
  - update .custodian-brief.md for repo-manager

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a023c0-a0a3-7c03-b395-5a0d2757214d
2026-08-22 23:18:37 +02:00
b7d9bef1e1 chore(consistency): index batch approval resolution
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a023c0-a0a3-7c03-b395-5a0d2757214d
2026-08-22 23:06:40 +02:00
63c00f9c9d docs(identifiers): record railiance-cluster cutover
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a023c0-a0a3-7c03-b395-5a0d2757214d
2026-08-22 23:04:30 +02:00
repo-manager
c3e22baf5a repo.work.resolve_decision RMGR-DEC-2026-003
correlation_id: 050f9ce4-a6eb-4783-bb7f-e3864a788366
reason: Resolve exact batch approval
source: repo-manager

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a023c0-a0a3-7c03-b395-5a0d2757214d
2026-08-22 22:34:15 +02:00
bf1dff9936 docs(workplan): record SBOM client readiness gate
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a023c0-a0a3-7c03-b395-5a0d2757214d
2026-08-22 22:28:10 +02:00
f0200c0434 chore(registrar): assign State Hub identifiers
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a023c0-a0a3-7c03-b395-5a0d2757214d
2026-08-22 22:26:49 +02:00
062a45fc58 docs(workplans): prepare identifier batch and SBOM client follow-up
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a023c0-a0a3-7c03-b395-5a0d2757214d
2026-08-22 22:25:11 +02:00
custodian-sync
bc0ee85ffa chore(consistency): sync task status from DB [auto]
Updated by fix-consistency on 2026-08-22:
  - update .custodian-brief.md for repo-manager

Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a028f0-a42f-7582-89a8-ebaad7343834
2026-08-22 20:23:40 +02:00
ad0ba6f2ba refactor: delegate SBOM scans to Nexus
Assistant: codex
Assistant-Model: gpt-5.6-sol
Assistant-Session: 01a028f0-a42f-7582-89a8-ebaad7343834
2026-08-22 20:22:45 +02:00