Commit graph

24 commits

Author SHA1 Message Date
codex
93b8174abd finish three custodian workplans from live hub evidence
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Python Tests / pytest (push) Successful in 21s
Close CUST-WP-0064 after the 2026-08-24 unassisted fire ingested
clay-borg, close CUST-WP-0065 now that all 120 active repos project a
classification, and close ADHOC-2026-08-25. Mark CUST-WP-0067 T02/T10
done (reverse relays already gone; work-record recovery lives on 0068).
Park the later no-checkout SBOM regression as CUST-IN-0015. Teach the
classification gate to use this host's checkout path.
2026-08-28 20:27:05 +02:00
codex
ff334f1a40 feat: automate classification convergence
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Python Tests / pytest (push) Successful in 21s
2026-08-23 13:05:47 +02:00
codex
450b4b80b0 canon: distinguish sector domains from project identity
Some checks are pending
CI Smoke / host-smoke (push) Waiting to run
CI Smoke / container-smoke (push) Waiting to run
Python Tests / pytest (push) Successful in 21s
2026-08-23 01:47:39 +02:00
codex
8bda6e28b4 canon: resolve work-record governance packets
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Python Tests / pytest (push) Successful in 21s
2026-08-22 22:35:37 +02:00
codex
1674ea550d ADR-008: relocate the multi-tenancy framework to NetKingdom canon
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Multi-tenancy is part of the IT-security framework NetKingdom provides, so it
belongs beside the IAM Profile and the tenant-engine boundary contract rather
than in the work-factory canon. Operator decision.

Relocation surfaced two things a review would have caught embarrassingly late.

NetKingdom's accepted platform-identity-security-architecture has used the word
plane since July for a trust and deployment layer - bootstrap, platform
control, tenant. This framework was using the same word for an independent
dimension of concern. Two senses of one word in one canon is precisely the
concept-ownership collision the estate is careful about, and the newcomer
yields: they are now axes. The rename is also just better, since a posture
vector is a point in five-dimensional space.

That same document also disproves the framework's opening line. It has
described the trust model, the tenant model and a capability progression since
2026-07-23, so the claim that the estate had never written down what it was
building was wrong. The accurate and narrower claim is that nothing said how
far a given service had got, or could hold several answers at once.

Stub left behind so the ADR-008 identifier resolves. The renderer moved to
policy-nexus, which owns publication.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-17 15:40:59 +02:00
codex
1c65257352 tools: generate the artifact page from canon markdown
The page and the ADR had already diverged once. They are now one source: the
markdown is authoritative and the page is generated, never hand-edited.

The renderer recognises conventions the document already uses rather than
requiring extra markup, so the source stays a readable document. A table whose
first column is **X0**/**X1** becomes a level ladder; a table headed Threat
becomes the threat matrix; a table with a Kind column gets mechanical and
adversarial chips; a table headed "E \ P" becomes the two-axis grid; ## N.
headings build the section rail.

Stdlib only, per the structure-not-tooling stance. A publishing step that needs
its own toolchain is a publishing step that stops being run - the same
reasoning tenant-engine used for its pin check.

One real consequence beyond deduplication: the E x P matrix had existed only on
the page, so the canonical document did not contain its own central diagram.
It is now a table in the markdown, which is where it should always have been.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-17 15:10:22 +02:00
codex
70f051fa96 CUST-WP-0060 test coverage: validate_work_records suite + CI wiring + C-31 comment fix
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Python Tests / pytest (push) Successful in 34s
Critical review of CUST-WP-0060 (T03-T06) found: shipped mechanism proven
only by manual/live-repo runs, no repeatable test suite; tests/ never
wired to CI at all (pre-existing gap, not introduced here).

- tests/test_validate_work_records.py: 30 tests against the live canon
  registry/schemas — classify() incl. all grandfathered legacy id
  schemes, per-kind schema gates (intake open/closed/promoted, decision
  prepared/resolved, engagement prepared), multi-doc yaml handling,
  malformed-yaml-only-errors-if-id-registered, main() end-to-end via
  subprocess (exit codes, template placeholders, --strict escalation,
  terminal-record historical grace incl. the boundary case that grace
  must NOT mask real enum violations), and the jsonschema-unavailable
  fallback path (the exact failure mode that broke the first Forgejo
  CI run before the runner-substrate fix)
- tools/validate_work_records.py: docstring said 'authoritative detector
  is fix-consistency C-25' — wrong, it landed as C-31 (C-25..C-30 were
  already taken); comment now correct
- .forgejo/workflows/python-tests.yaml: wires tests/ to CI for the first
  time in this repo (apt python3/pytest/jsonschema/yaml on the
  node:20-bookworm substrate, same pattern as work-records.yaml)
- tests/test_scan_workstream_terminology.py: found one pre-existing,
  unrelated failure while establishing the CI-representative baseline
  (agentic-resources allowlist entry no longer sets exclude_repo — a
  policy question, not a bug this task should resolve silently); marked
  xfail(strict=True) with the finding recorded so CI has a clean signal
  and a silent 'fix' doesn't go unnoticed either

Local verification with apt-sourced deps (jsonschema 4.10.3, matching the
CI runner's package source, not just pip): 34 passed, 1 known xfailed.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-20 23:09:25 +02:00
codex
f4101cdd9a CUST-WP-0060 T01-T03: canon ratified active, terminology v0.2, schemas + validator
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 3s
- work-record-types_v0.1.md + autonomy-lanes_v0.1.md: status active
  (founder ratification 2026-07-20, hub decision f4640f9e); registry
  grandfathers legacy task-id variants (-T1, -LEGACY-Txx)
- workplan-terminology-fleet: v0.2 addendum — work-record umbrella,
  kind vocabulary, suggestion as legacy bridge name (T02)
- canon/standards/schemas/work-records/: spine + intake/decision/
  engagement JSON schemas (T03); conditional spine requirements,
  historical grace for terminal records
- tools/validate_work_records.py: registry+schema validator for CI
  (T04); jsonschema with inlined spine refs, fallback checks without;
  proof runs clean: the-custodian 384 records, binky-control 45

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-20 02:07:36 +02:00
codex
e0f93304bf CUST-WP-0055: finish T02/T06/T07 and close workplan
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Add archive terminology note tool, extend scan allowlist for generated
trees, mark remaining tasks done, and add grandfather notes to archived
workplans in this repo.
2026-07-08 20:26:24 +02:00
codex
86fb24fa3b feat(terminology): complete T04 domain prose sweep (batch 5, 73 repos)
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 3s
Allowlist workplan-convention legacy footnotes fleet-wide; mark CUST-WP-0055-T04
done after final bootstrap repo sweep.
2026-07-08 19:52:37 +02:00
codex
2e0deee2ef feat(terminology): prose sweep tool and custodian workplan cleanup (CUST-WP-0055 T04)
All checks were successful
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Successful in 6s
Add sweep_workstream_prose.py for agent-guidance files, sweep active workplan
prose in-repo, tighten scan allowlist exclusions, and update ADR-001 closure
protocol to workplan-first terminology.
2026-07-08 16:35:37 +02:00
codex
20173e4270 feat(terminology): add fleet scan allowlist and prose gate (CUST-WP-0055 T08)
Some checks failed
CI Smoke / host-smoke (push) Successful in 1s
CI Smoke / container-smoke (push) Has been cancelled
Extend scan_workstream_terminology.py with allowlist loading, --apply-allowlist,
and --check-prose-gate for regression detection. Commit the T08 exclusion
config and unit tests; mark T01/T03/T08 done and activate the fleet workplan.
2026-07-08 16:08:32 +02:00
codex
81809f8b53 tools: disable Gitea package push on coulombcore (read-only mirror)
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 5s
IngressRoute allows GET/HEAD/OPTIONS on /v2 and /api/packages; removes
those paths from catch-all Ingress; sets zero package upload limits in
Gitea app.ini. Complements archived git repos (RAIL-HO-WP-0005).
2026-07-08 13:26:09 +02:00
codex
608cc742a5 tools: archive coulomb Gitea org for read-only mirror policy
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Script uses Gitea API to set archived=true on all org repos after Forgejo
cutover (RAIL-HO-WP-0005). Ran 2026-07-08: 79/79 archived on coulombcore.
2026-07-08 13:11:43 +02:00
codex
38cd8cf828 Add CUST-WP-0055 fleet workplan terminology refactor plan
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 2s
Inventory 22k+ legacy workstream occurrences across 73 registered repos and
add a reproducible scan tool plus an eight-task workplan to migrate prose,
events, templates, and code to workplan while preserving compatibility bridges.
2026-07-08 12:53:52 +02:00
codex
94d1f84caa tools: batch Gitea-to-Forgejo migration script
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Wraps promote-repo-to-forgejo.sh for all local checkouts still on
gitea-remote origin; patches State Hub remote_url after each push.
2026-07-08 12:39:16 +02:00
codex
af49c053f1 finish(CUST-WP-0054): workstation independence engineering closeout
Complete T04–T08: bulk Forgejo remote_url migration for all registered
repos, phase 5 stabilization tooling, dev-hub beachhead artifacts, and
phoenix drill runbook. Archive workplan with T09/T10 as operator gates.
2026-07-08 11:42:49 +02:00
codex
ac0886a409 feat(T06): complete sink path decoupling and working-memory sweep sync
hostPath working-memory on railiance01, migration tool, sweep commits
daily-triage notes; T06 marked done in workplan.
2026-07-07 01:01:26 +02:00
codex
104c66763e docs(CUST-WP-0054-T05): open Phase 5 stabilization window
Record kickoff baseline checks, 72h monitoring gates, and a reusable
phase5-stabilization-check.sh script for daily health snapshots.
2026-07-06 19:41:42 +02:00
codex
c9764ba73c docs(CUST-WP-0054-T05): Phase 4 sweep checkout migration evidence
Record railiance01 clone tree, host_paths registration, and tooling for
bulk clone and path registration. Update T05 workplan with Phase 4 completion.
2026-07-06 19:24:28 +02:00
codex
5c63c2f354 Add Forgejo tier-3 remote_url and sweep playbook
Document State Hub PATCH procedure, sweep implications, railiance01 host_paths,
state-hub image specifics, and rollback. Include batch patch helper; applied
tier-2.5 remote_url updates in hub DB.
2026-07-04 13:21:40 +02:00
db88a34b3e CUST-WP-0050 follow-up: human review, push tooling, SSH inventory
Add human-review script for 13 high-blast-radius repos, bulk-push helper,
and SSH-based Gitea inventory probe. Update exclusion list with SSH-verified
absent slugs; marki-docx now classified and registered.
2026-06-22 17:59:55 +02:00
f9837e3703 Complete CUST-WP-0050 T11: classify and register remaining portfolio repos
Add exclusion list and batch classification author for post-cutover inventory.
Mark workplan finished after registering 7 new repos and reclassifying 43
migration rows via state-hub register-from-classification tooling.
2026-06-22 17:50:26 +02:00
044d088109 Start CUST-WP-0050: T01 allowed-values + validator; classify the-custodian
Activate the workplan and complete T01: add the machine-readable controlled
vocabulary canon/standards/repo-classification.allowed.yaml (categories,
domains, business_stake, business_mechanics, capability families, guidance),
reference it from the standard §12, and add tools/validate_repo_classification.py
(stdlib + PyYAML, --self-test PASS).

Begin T02: author the-custodian/.repo-classification.yaml (research · infotech ·
agents), which validates clean. classified_by: agent, pending human review.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-22 02:02:01 +02:00