docs: advance retirement with SBOM receipts and caller migrations

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a06ed7-828d-7ca0-a8d4-0c3e5a0c4102
This commit is contained in:
tegwick 2026-09-05 10:24:54 +02:00
parent 74a3b22c05
commit f04de759a1
8 changed files with 1852 additions and 483 deletions

View file

@ -425,6 +425,16 @@ direct route are live owner residual `RAIL-FAB-WP-0028`. Evidence:
the non-D2 repo-manager/hub-core/activity-core/ops-hub route receipts and the
explicit writer-change authorization already stated above.
**Cutover re-baseline 2026-09-05.** Replaced the obsolete slice-readiness
snapshot in `docs/retirement-cutover-slice-plan.md` with a family-by-family
receiver/caller/parity/rollback checklist. Live Hub Core runtime OpenAPI lacks
`/messages`, `/progress`, `/token-events` and `/interface-changes`; its working
`/api/v2/interaction-events` is not assumed equivalent. Shared library routers
and HUB-WP-0005 completion are insufficient receiving receipts. T08 now records
the concrete first read-contract gap. State Hub-to-Core Hub service probes were
connection-refused although deployments were ready; transport is also part of
that gate. RAIL-FAB-WP-0028 remains proposed and owns hosted Fabric readiness.
## Retire legacy surfaces
```task
@ -536,6 +546,22 @@ calendar passage alone is not retirement evidence.
the existing hold; no additional retirement is justified. T04/T05/T06 remain
`wait` with their existing owner and quiet-window dependencies.
**Authorized retirement and caller migration 2026-09-05.** Fresh seven-day
primary evidence made `GET /sbom/report/licences/` and `GET /sbom/snapshots/`
eligible. Verified direct Nexus endpoints (200), then marked both interfaces
retired with T05 provenance. Receipt:
`docs/evidence/STATE-WP-0079-sbom-retirement-20260905.json`. Eight retired,
seven legacy, zero remaining candidates. Compatibility handlers/history remain;
this is meter retirement, not a router deletion or application deployment.
Session traces identified ad-hoc task-filter callers in fluid-telegram and
ops-warden. Corrected their AGENTS.md canonical-query/component-header guidance,
plus this repository's stale skill and API documentation. Canonical verification
returned 200 with 8/5 tasks. This does not explain every historical call or prove
future silence: unresolved task/workstream-detail/SBOM-index attribution is T07.
Available pod logs begin after the last calls. Evidence and limits:
`docs/evidence/STATE-WP-0079-caller-and-receiver-review-20260905.md`.
## Stabilization window and archive prep
```task
@ -555,6 +581,47 @@ stop, or repository archive would therefore interrupt normal work and destroy
the evidence needed by T05. T06 remains `wait` until T04 and T05 are done and a
fresh central meter demonstrates the required zero normal read/write window.
## Attribute and finish migrating remaining legacy readers
```task
id: STATE-WP-0079-T07
status: wait
priority: high
```
Owner: state-hub. T05 follow-up from the 2026-09-05 scan. Two ad-hoc task-query
callers were identified and their instructions corrected; the full 11 task
calls, seven workstream-detail calls and one SBOM index call remain only
partially attributed. Existing retained logs postdate these calls. Wait for
new attributed observations or recoverable historical request evidence; do not
reset the clocks with test calls. Trace remaining callers, migrate them to the
verified replacements, and attach fresh quiet-window evidence before retirement.
Use `X-StateHub-Component` for direct agent HTTP requests. No inference from
an `unknown` bucket alone is sufficient to assign an owner.
## Prove the first deployed hub-core message-read contract
```task
id: STATE-WP-0079-T08
status: todo
priority: high
```
Receiving owner: hub-core; State Hub owns source/caller evidence under T04.
The live receiver's 31-path OpenAPI has no message/progress/token/interface-log
families. Identify or assemble the owner message-read contract, auth/transport,
and historical projection in the receiving runtime. State Hub-to-owner service
probes were connection-refused in this review; diagnose the actual transport
before assuming a usable proxy path. Do not substitute `/api/v2/interaction-events`
without an explicit semantic mapping.
Then run a bounded read-only inbox parity pilot over one consistent snapshot,
checking message IDs, ordering, read/archive flags and scope filters; record
exact revisions and rollback to the retained State Hub read. Done when receiving
readiness and parity/rollback receipts make one concrete reader switch reviewable.
Production message writers stay unchanged during this proof. Related owners:
HUB-WP-0004/0005; the full B2/B3 route migration is not implied by this task.
## Acceptance
- [x] Freeze policy documented