docs(canon): ADR-009 federated namespaces and reconciliation limits (proposed)
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s

Resolves a contradiction in accepted canon: ADR-007 decision 1's globally
unique forward-only running numbers require a central allocator, the exact
dependency federation must survive. Amended to namespace-scoped uniqueness
with PREFIX-WP-NNNN@namespace qualification; unqualified still means the
local namespace. C2's UUIDv5 derivation input becomes (namespace,
identifier) — free now, expensive after it ships.

States reconciliation limits rather than implying convergence. T0 fork, T1
sync and T2 reintegration are partly automatable; T3 amalgamation, where a
fork established distinct operational infrastructure, is an M&A-class
governed programme rather than a merge, and may legitimately end in
permanent coexistence or divestment. prj-state-hub-retirement is cited as
measured T3 cost under the most favourable possible conditions.

Coexistence, not merging, is the normal case: client instances per
CUST-WP-0058 are forks that never return. Records fork; effects do not.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
codex 2026-08-17 12:47:12 +02:00
parent f8c3c1d8fd
commit 9a6e14e733
2 changed files with 183 additions and 2 deletions

View file

@ -82,6 +82,13 @@ nothing prevents number reuse.
**1. A workplan identifier is globally unique.** `PREFIX-WP-NNNN` names exactly
one workplan across the entire fleet, for all time.
> **Amended 2026-08-17 by `ADR-009` decision 2.** Uniqueness and forward-only
> allocation are **namespace-scoped**, not global; global identity is the pair
> `(namespace, identifier)`, written `PREFIX-WP-NNNN@namespace` when foreign.
> Global sequential allocation would require a central coordinator — the exact
> dependency federation must survive. Everything below holds unchanged **within**
> a namespace, which is where all current work sits.
- A workplan prefix is owned by exactly one repository. No two repositories may
use the same prefix.
- A running number is never reused within a prefix, including after a workplan is
@ -96,8 +103,10 @@ It also inverts ADR-001 — a file carrying a hub's private key is the file
holding hub state.
*Target state (C2).* `state_hub_workstream_id` and `state_hub_task_id` become
**deterministic**: UUIDv5 derived from the globally unique `PREFIX-WP-NNNN`
identifier. Every instance computes the same value independently, writeback
**deterministic**: UUIDv5 derived from the workplan identifier. Per `ADR-009`
decision 3 the derivation input is the pair `(namespace, identifier)`, not the
identifier alone — deriving from the identifier alone would make two forks
holding unrelated work under the same number compute the same UUID. Every instance computes the same value independently, writeback
becomes idempotent, and any number of hub instances may coexist without
coordination. The field shape is unchanged, so consumers keep working; only the
provenance of the value changes.