workplans: close stale intakes and start classification migration
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 0s

This commit is contained in:
codex 2026-08-23 01:31:29 +02:00
parent d0f515c865
commit b9f3238953
5 changed files with 209 additions and 13 deletions

View file

@ -63,6 +63,7 @@
| workplan | CUST-WP-0062 | finished | — | workplans/CUST-WP-0062-sbom-nexus-daily-catchup.md |
| workplan | CUST-WP-0063 | finished | — | workplans/CUST-WP-0063-inbox-governance-packets.md |
| workplan | CUST-WP-0064 | active | — | workplans/CUST-WP-0064-sbom-controlled-scan-inputs.md |
| workplan | CUST-WP-0065 | active | — | workplans/CUST-WP-0065-reclassify-repos-and-guidance-docs-to-the-new-sector-domain.md |
| task | ADHOC-2026-05-02-T01 | done | — | workplans/ADHOC-2026-05-02.md |
| task | ADHOC-2026-07-02-T01 | done | — | workplans/ADHOC-2026-07-02.md |
| task | CUST-WP-0001-T01 | done | — | workplans/CUST-WP-0001-custodian-agent-runtime.md |
@ -410,6 +411,10 @@
| task | CUST-WP-0064-T02 | done | — | workplans/CUST-WP-0064-sbom-controlled-scan-inputs.md |
| task | CUST-WP-0064-T03 | progress | — | workplans/CUST-WP-0064-sbom-controlled-scan-inputs.md |
| task | CUST-WP-0064-T04 | progress | — | workplans/CUST-WP-0064-sbom-controlled-scan-inputs.md |
| task | CUST-WP-0065-T01 | done | — | workplans/CUST-WP-0065-reclassify-repos-and-guidance-docs-to-the-new-sector-domain.md |
| task | CUST-WP-0065-T02 | todo | — | workplans/CUST-WP-0065-reclassify-repos-and-guidance-docs-to-the-new-sector-domain.md |
| task | CUST-WP-0065-T03 | progress | — | workplans/CUST-WP-0065-reclassify-repos-and-guidance-docs-to-the-new-sector-domain.md |
| task | CUST-WP-0065-T04 | todo | — | workplans/CUST-WP-0065-reclassify-repos-and-guidance-docs-to-the-new-sector-domain.md |
| intake | CUST-IN-0001 | closed | green | intake-legacy-suggestions-migration.md |
| intake | CUST-IN-0002 | closed | green | intake-legacy-suggestions-migration.md |
| intake | CUST-IN-0003 | closed | green | intake-legacy-suggestions-migration.md |
@ -417,10 +422,10 @@
| intake | CUST-IN-0005 | closed | green | intake-legacy-suggestions-migration.md |
| intake | CUST-IN-0006 | closed | green | intake-legacy-suggestions-migration.md |
| intake | CUST-IN-0007 | closed | green | intake-legacy-suggestions-migration.md |
| intake | CUST-IN-0008 | open | blue | intake-legacy-suggestions-migration.md |
| intake | CUST-IN-0009 | open | blue | intake-legacy-suggestions-migration.md |
| intake | CUST-IN-0010 | open | green | intake-legacy-suggestions-migration.md |
| intake | CUST-IN-0008 | closed | blue | intake-legacy-suggestions-migration.md |
| intake | CUST-IN-0009 | closed | blue | intake-legacy-suggestions-migration.md |
| intake | CUST-IN-0010 | closed | green | intake-legacy-suggestions-migration.md |
| intake | CUST-IN-0011 | routed | red | intakes.md |
| intake | CUST-IN-0012 | open | green | intakes.md |
| intake | CUST-IN-0012 | closed | green | intakes.md |
| intake | CUST-IN-0013 | closed | blue | intakes.md |
| intake | CUST-IN-0014 | closed | blue | intakes.md |

View file

@ -0,0 +1,76 @@
# Repo classification sector migration baseline — 2026-08-23
## Result
The live State Hub registry contains 121 repositories, of which 117 are active.
Thirty-eight active records have a domain association but no projected
`category`; they are not complete Repo Classification Standard projections.
The gap has two distinct causes:
- 14 local checkouts do not contain `.repo-classification.yaml`;
- 24 local checkouts contain the file, but the live registry still projects a
null category.
Those paths require different fixes. The first requires a repo-owner
classification decision. The second requires validation and normal
Repo Manager/State Hub reconciliation; it must not be repaired by directly
editing registry rows.
## Migration rule
The older labels `custodian`, `railiance`, `markitect`, `coulomb_social`,
`personhood`, `foerster_capabilities`, and `netkingdom` identify projects,
estates, or bodies of canon. They are not sector-domain aliases.
Keep those names in project titles, topic identity, architecture, provenance,
and historical records. For `repo_classification.domain`, apply the current
standard's user/customer question and select one allowed sector. Useful review
seeds are:
| Legacy identity | Likely sector starting point | Review constraint |
| --- | --- | --- |
| Custodian | `infotech` | Add `agents` only where agent infrastructure is materially served. |
| Railiance | `infotech` | Use `industrials` only for repos whose intended users are actually in rail/industrial operations. |
| Markitect | `infotech` | Use `agents` as primary only for agent-native products, not merely AI-assisted tooling. |
| Coulomb.social | `communication` | Add other sectors only when a concrete product audience warrants them. |
| Personhood | `agents` or `government` | Rights/governance scope is ambiguous and requires owner review. |
| Foerster Capabilities | `agents` | Preserve the named research project separately from market metadata. |
| NetKingdom | `infotech` | Identity, tenancy, and access control are platform capabilities, not a market alias. |
This table is a triage aid, not an automatic rewrite map.
## Missing source files (14)
`agent-harness`, `binect-chrome`, `binect-js`, `binky-control`, `clay-borg`,
`direkt-vermittlung-de`, `polycode-sim`, `railiance-telemetry`,
`ralph-workplan`, `rein-aharness`, `rein-openweights`, `tele-mcp`,
`testdrive-jsui`, and `timeline-svg`.
## Source file present but registry category null (24)
`config-atlas`, `disaster-control`, `glas-harness`, `ground-game`,
`kings-guard`, `ops-mason`, `policy-nexus`, `prj-canon-federation`,
`prj-forgejo-org-refactor`, `prj-state-hub-retirement`, `qonto-assistant`,
`rail-knative`, `rapp-openbao`, `rapp-policy-nexus`, `rapp-postgres`,
`rapp-qonto`, `rapp-sbom-nexus`, `resource-control`, `risk-nexus`,
`sand-boxer`, `secrets-engine`, `tenant-engine`, `test-driver`, and
`zone-engine`.
## Reproduction
Read active repository records from `GET /repos/`, select records whose
`status` is `active` and whose `category` is null, then test the registered
`local_path` for `.repo-classification.yaml`. The observed counts are:
```text
registered: 121
active: 117
active with null category: 38
missing source file: 14
source file present but unprojected: 24
```
Acceptance is zero unexplained null category projections among active repos.
A governed archived/decommissioned record or an explicit classification
exclusion is not unexplained.

View file

@ -161,10 +161,12 @@ state_hub_intake_id: "019f81e6-1149-78aa-97d2-635c75622e9e"
id: CUST-IN-0008
title: "Roll out weekly legacy-meter review on Railiance activity-core"
lane: blue
status: open
status: closed
outcome: absorbed
origin: "legacy-suggestion:05da5540-e7cd-41fb-a511-3c1572e4604f"
origin_ref: "weekly-legacy-meter-review-railiance-rollout"
notes: "From STATE-WP-0069 (financials domain). Migrated 2026-07-21."
updated: "2026-08-23"
notes: "Closed as absorbed on 2026-08-23. Production Activity Core exposes the enabled Weekly Legacy-Meter Review definition (UUID 59dce72b-21bf-5f06-890a-cb8770fbcf72) at 08:30 Europe/Berlin each Monday. Live run evidence covers every Monday from 2026-07-20 through 2026-08-17, each resolving legacy_meter_weekly_review with zero spawned tasks. The next normal fire is 2026-08-24; no new implementation work remains in this intake."
state_hub_intake_id: "019f81e6-198b-7df7-964e-6f8c06443454"
```
@ -172,10 +174,12 @@ state_hub_intake_id: "019f81e6-198b-7df7-964e-6f8c06443454"
id: CUST-IN-0009
title: "Rebuild activity-core:railiance01-prod for legacy-meter 8h capture"
lane: blue
status: open
status: closed
outcome: absorbed
origin: "legacy-suggestion:8b3301d6-0222-41e4-89c9-99e8c6dd5248"
origin_ref: "legacy-meter-8h-capture-railiance-rollout"
notes: "From STATE-WP-0073 (financials domain). Migrated 2026-07-21."
updated: "2026-08-23"
notes: "Closed as absorbed on 2026-08-23. Production Activity Core exposes the enabled Legacy-Meter 8h Capture definition (UUID a0fae182-52e9-5990-9fa6-6fea12a14753) on 0 */8 * * * UTC. Live evidence shows successful context-resolving runs at 00:00, 08:00, and 16:00 UTC on 2026-08-22, with zero spawned tasks; the current API and worker deployments are Ready with zero restarts. The requested railiance01 production rebuild and recurrence are therefore already delivered."
state_hub_intake_id: "019f81e6-2348-72a8-8ec9-edb851acb9aa"
```
@ -183,9 +187,15 @@ state_hub_intake_id: "019f81e6-2348-72a8-8ec9-edb851acb9aa"
id: CUST-IN-0010
title: "Reclassify repos and guidance docs to the new sector domain scheme"
lane: green
status: open
status: closed
outcome: promoted
promoted_to: CUST-WP-0065
priority: medium
owner: the-custodian
origin: "legacy-suggestion:9c1de00d-7f2c-43f9-aaef-62356038c0b7"
origin_ref: "binky-control fix-consistency C-24 / session 2026-07-16"
updated: "2026-08-23"
routed_note: "Vetted 2026-08-23 against the live registry: 117 repositories are active and 38 still have a null category projection, including binky-control. The canonical sector vocabulary and validation standard now exist, but fleet projection and legacy-guidance cleanup remain dependency-bearing multi-repo work. Promoted through statehub promote-intake to CUST-WP-0065."
notes: "Originated from a binky-control fix-consistency C-24 classification
gap. Migrated 2026-07-21."
state_hub_intake_id: "019f81e6-2a31-7bee-b50a-8e9ca67267b7"

View file

@ -14,8 +14,8 @@ tags: [compliance-relevant]
origin: residual
origin_ref: CUST-WP-0063
selected_contact_uri: "https://security.coulomb.social/"
updated: "2026-08-22"
notes: "The operator selected https://security.coulomb.social/ as the RFC 9116 Contact URI. Policy Nexus owns provisioning and receipt testing before policy.coulomb.social/.well-known/security.txt may publish it. Reports route privately to risk-nexus; the route creates no bounty, response-time, or safe-harbour promise. Close only after the HTTPS endpoint is reachable and a private test report reaches Risk Nexus."
updated: "2026-08-23"
notes: "The operator selected https://security.coulomb.social/ as the RFC 9116 Contact URI. Policy Nexus owns provisioning and receipt testing before policy.coulomb.social/.well-known/security.txt may publish it. Reports route privately to risk-nexus; the route creates no bounty, response-time, or safe-harbour promise. Acceptance check 2026-08-23: DNS resolves, but the HTTPS server aborts the TLS handshake with alert internal_error before serving a page, so the private receipt test cannot begin. Blocker sent to Policy Nexus as message a111b97c-0561-44eb-b61a-12bcf068b28d. Close only after HTTPS is reachable and a private test report reaches Risk Nexus."
state_hub_intake_id: "01a02b31-f4b0-75e4-a15c-a78e1c276689"
```
@ -25,13 +25,14 @@ state_hub_intake_id: "01a02b31-f4b0-75e4-a15c-a78e1c276689"
id: CUST-IN-0012
kind: intake
title: "Repair the malformed legacy inbox message identity"
status: open
status: closed
lane: green
priority: low
owner: hub-core
origin: residual
origin_ref: CUST-WP-0063
notes: "State Hub returns unread risk-nexus message id 0b8dd0bf-41d-47da-96ac-40e443c32e47, whose second UUID group has only three characters. PATCH /messages/{id}/read rejects it during UUID path parsing, so the already-handled superseded request cannot be marked read through the supported API. Repair must preserve the message body and chronology, assign or map a valid stable identity, and then apply the read transition without direct ad hoc database mutation from this repo."
updated: "2026-08-23"
notes: "Closed 2026-08-23. State Hub now exposes the preserved risk-nexus message with valid stable id 0b8dd0bf-41d1-47da-96ac-40e443c32e47. PATCH /messages/{id}/read succeeded through the supported API, preserving its body and original 2026-08-20 chronology; the Custodian unread inbox is empty. No direct database mutation was used."
state_hub_intake_id: "01a02b32-009b-71bd-a7bf-2ce888164d6a"
```

View file

@ -0,0 +1,104 @@
---
id: CUST-WP-0065
type: workplan
title: "Reclassify repos and guidance docs to the new sector domain scheme"
domain: infotech
repo: the-custodian
status: active
owner: codex
created: "2026-08-23"
updated: "2026-08-23"
quality_dor: DoR-Ok
quality_dor_at: "2026-08-23"
quality_dor_by: codex
quality_dor_note: "The live registry baseline, canonical vocabulary, source-of-truth boundary, owner dependencies, non-mechanical classification risk, and acceptance checks are explicit."
state_hub_workstream_id: "e2702474-b276-4e15-8337-41bfa344c89c"
---
# Reclassify repos and guidance docs to the new sector domain scheme
## Goal
Complete the transition from legacy project/estate labels to the canonical
sector-domain vocabulary without mechanically rewriting project identities or
silently assigning ambiguous repos. Populate the authoritative repository
projection, update Custodian guidance, and route repo-owned classification
changes to their owners.
**Promoted from intake** `019f81e6-2a31-7bee-b50a-8e9ca67267b7` — origin: "intake:019f81e6-2a31-7bee-b50a-8e9ca67267b7"
## Establish the live baseline and migration semantics
```task
id: CUST-WP-0065-T01
status: done
priority: high
```
Count active repositories with complete and incomplete classification
projection, distinguish missing source files from missing ingestion, and define
how legacy project names relate to sector domains. Do not treat a project name
as a one-to-one market classification.
**Done (2026-08-23):** `docs/repo-classification-sector-migration-baseline-2026-08-23.md`
records the live 117-repository baseline: 38 active records have no projected
category, comprising 14 missing source files and 24 present-but-unprojected
files. It also fixes the migration rule: legacy names remain project/estate
identity; sector values describe intended users and require repo-owner review
when the answer is ambiguous.
## Publish canonical migration guidance
```task
id: CUST-WP-0065-T02
status: todo
priority: medium
```
Review the baseline semantics into the active Repo Classification Standard and
agent-facing guidance. Replace only obsolete domain-field instructions; keep
historical project names and canon references intact. Add a validation example
that rejects legacy names in `repo_classification.domain` while allowing them
as project/topic identity.
## Repair source records and authoritative projection
```task
id: CUST-WP-0065-T03
status: progress
priority: high
```
Route the 14 missing `.repo-classification.yaml` files to repository owners and
have Repo Manager/State Hub diagnose the 24 files that exist locally but remain
null in the registry. Classification judgments stay with repo owners; the
Custodian coordinates vocabulary and acceptance. Require schema validation and
normal registrar/reconcile paths rather than direct database edits.
**Started (2026-08-23):** Repo Manager received the 24-repo projection defect
and `config-atlas` sentinel proof in message `a5e685c9`; `binky-control`
received the first missing-source owner handoff in message `15d8f2df`. The
remaining missing-source repos stay in the baseline for governed owner routing.
## Verify fleet convergence and close
```task
id: CUST-WP-0065-T04
status: todo
priority: medium
```
Re-run the active-repository baseline. Close when every active repo either has
a valid projected classification or a governed exclusion, current agent
guidance uses sector domains, and no project identity was destroyed by the
migration. Record any genuine owner decision as a live residual before
finishing.
## Acceptance
- [x] Live missing-classification baseline is reproducible and split by cause
- [x] Legacy project identity is distinguished from sector-domain metadata
- [ ] Canonical and agent-facing migration guidance is current
- [ ] Missing source classifications are owner-reviewed and validated
- [ ] Present source classifications project into State Hub
- [ ] Active fleet has zero unexplained null category projections