Skip to content

Wind down the review-sheet and census lane into six roadmap nodes - #11856

Merged
gunbai-bot[bot] merged 7 commits into
mainfrom
lane/wind-down-roadmap-items
Sep 20, 2026
Merged

gunbai-bot[bot] merged 7 commits into
mainfrom
lane/wind-down-roadmap-items

Conversation

@gunbai-bot

@gunbai-bot gunbai-bot Bot commented Sep 20, 2026 •

Copy link
Copy Markdown
Contributor

The operator asked this lane to wind down and record its progress and remaining items as roadmap project items, to relieve system pressure so v1 performance and v2 migration get the capacity. This is that record — it starts no new work.

Six active(...) nodes, three edge(...) rows, and a plan carrier (docs/plans/review-sheet-and-census-lane-handoff.md) that all six nodes' path: fields point at, plus the regenerated ROADMAP.md. No Rust, no shell, no new types, no new node vocabulary.

The nodes

  1. review-sheet-identity-producer-and-admission — producers + declared-id admission for the kernel landed in Cut 1 of the #11596 recut: the review-sheet identity kernel, pure #11669; retires the three consumer frontier rows it enrolled, whose triggers name execution, not import.
  2. review-sheet-properties-write-and-legacy-retirement — the PATCH with an id-bound readback, then legacy retirement.
  3. census-app-registration-installation-and-custody — new in the recut.
  4. census-installation-token-via-app-jws-route — reuse microVM: host-side JIT mint via GitHub App + attempt-owned jail device staging #11677's JWS/OpenSSL route; explicitly no rs256_sign host primitive, which would land against CRYPTO-0.
  5. census-job-level-observation-and-reprojection — new in the recut.
  6. ntfy-publisher-token-onto-gcp-custody — the Mt Collins pattern as a consolidation of MicroVM controller App-key custody converge (root:root 0400, readback receipt) #11679; explicitly does not retire approval_store_single_writer_by_agreement.

What the recut corrected (side-chat REWORK, parts 2 and 3)

Both were overstatements of mine, and the review was right to refuse them:

Part 1 (external blockers as prose) was withdrawn after I traced that startable authorizes closing-contract authoring rather than implementation dispatch — an unbound node gains a derived closing-contract parent edge before the spawner sees it, so implementation stays held.

Status of everything this lane referenced

All merged: #11552, #11564, #11656, #11669, #11671, #11677, #11679. No external prerequisite of this lane is open. The two real prerequisites are now edges: installation-token depends on app-registration; job-level reprojection depends on installation-token.

Verification

Six identities unique, all edge-referenced ids resolve to declared nodes, main's concat(guarantee_ladder_nodes(), typed_module_store_nodes()) tail preserved through a hand-resolved conflict with no authority dropped, and ROADMAP.md regenerated from the merged authorities rather than hand-resolved on every merge.

🤖 Generated with Claude Code

Brian Searls and others added 4 commits September 20, 2026 14:34
The operator asked this lane to stop and record its progress and remaining
items as roadmap project items, so v1 performance and v2 migration can have
the system.

Four nodes enter declared_roadmap_nodes, each carrying the constraint that
would otherwise be lost with the session rather than a restatement of its
own title:

- the review-sheet identity kernel's producers and declared-id admission,
  which is what retires the three consumer frontier rows #11669 enrolled --
  their triggers name execution, not import
- the properties write-back and legacy-generation retirement, whose red
  control is the short-decode a field mask narrower than the declared
  response type produces
- the census installation token, reusing #11677's App JWS route rather than
  adding an rs256_sign host primitive that would land against CRYPTO-0
- the ntfy publisher token onto the Mt Collins custody pattern, as a
  consolidation of #11679 rather than a sibling module, explicitly NOT
  retiring approval_store_single_writer_by_agreement

Their shared carrier is a new plan page holding what the nodes point at: the
appProperties visibility fact the whole identity kernel exists for, the three
standing constraints on resuming the migration, and the transcribed census
rows that no producer can yet re-derive.

Evidence: declared_identities over the test.claim.roadmap_identity_witness_test
fold evaluates with all four identities present, so the rows typecheck and
inhabit the real list rather than parsing alone.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Ledger-Repair-Judged: docs/design-rung-drops.md
Heal-Candidate-Run: 35516936949
Review 69310 (§3, §4c). The ordering between the two review-sheet nodes was
written twice in String fields and zero times where the projection reads it,
so both nodes were independently startable -- the opposite of what the text
said. `declared_roadmap_edges` is the existing modeled authority for exactly
this relation.

One edge replaces the prose. The restatement in `out_of_scope` is deleted
rather than left beside the edge, because two answers to one question is the
fork DESIGN 3 exists to prevent.

Evidence that the edge is CONSUMED and not decoration: the regenerated
projection moves 140 -> 139 active deliverables and drops
review_sheet_properties_write_and_legacy_retirement's closing-contract carrier
from the startable set, which is the fold the finding named.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@gunbai-bot

gunbai-bot Bot commented Sep 20, 2026

Copy link
Copy Markdown
Contributor Author

Review 69310 — the actionable finding is fixed in 86a86b9; the second half I'm declining, with reasoning.

Fixed: the cross-node ordering. You're right that it existed twice in prose and zero times where the projection reads it. declared_roadmap_edges already owns that relation, so one edge(child: "review-sheet-properties-write-and-legacy-retirement", parent: "review-sheet-identity-producer-and-admission") now carries it, and the out_of_scope restatement is deleted rather than left beside it.

I checked it's consumed rather than decorative, since that was the substance of the finding: the regenerated projection moves 140 → 139 active deliverables and drops the retirement node's closing-contract carrier from the startable set. That is the fold you named (active_roadmap_edges_for_accepted, and the startable/closing-contract folds) changing its answer — before the edge both nodes were independently startable, which is exactly the contradiction you identified.

Not fixed: the external-PR blockers, and I want to be explicit that this is a decline rather than an oversight. You're correct on the mechanism — edge relates node ids, so gunbc#11677 and gunbc#11679 cannot be expressed as edges — and correct on the consequence: three of these four nodes read active with no blocker the model can see.

There is no carrier in this authority for "blocked on an external pull request." Under DESIGN §3b that makes it a modeling obligation (§6), not a conformance violation — "a domain whose home does not yet exist is not a conformance row but a modeling obligation." Minting that carrier is a new authority on the roadmap's growth surface, which is the one thing this PR exists to avoid: it is a wind-down recording state so the system can prioritise v1 performance and v2 migration.

So the PR references in boundary and first_slice stay as ticket content describing the work, which is what those fields are for. They are not a second representation of a modeled fact, because no model carries that fact.

I'd rather name the gap than paper over it, so stating it plainly for whoever picks these up: three of the four nodes are startable according to the model and are not startable in reality. If that matters more than the wind-down's no-new-authority constraint, the right fix is a real blocker carrier in roadmap_authority, and that is its own change with its own review — not something to improvise here.

— sent from zesty-crane-846

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

REWORK — exact head 86a86b92e4166445d484588628ad1a1523f83187.

The mechanics are clean and the three constraints called out in the handoff are worth preserving: the appProperties empty-read scope, no new rs256_sign primitive beside the key-custody signer route, and the fact that metadata/mode readback does not retire approval_store_single_writer_by_agreement.

Three source problems prevent LAND.

P0 — the wind-down creates work the roadmap says is ready

These are active(...) rows, hence Dispatchable. The roadmap spawner does not read first_slice, out_of_scope, the plan document, or PR prose when deciding readiness. It asks whether the row is dispatchable, incomplete, unsuperseded, and whether every modeled RoadmapEdge parent is closed. The program view likewise derives dependency holding only from graph parents.

Therefore the source simultaneously says:

  • "nothing here starts new work";
  • census/ntfy work starts only after the custody chain lands;
  • but the model exposes the unblocked rows/closing-contract work as startable.

That is not merely a missing future carrier under DESIGN 3b. It is a present false dispatch authorization, and it inverts the operator's wind-down purpose. Declining a generic ExternalPrBlocker authority is reasonable; knowingly emitting ready work is not. Use a conservative state the existing model can express:

  • preferably add/identify the prerequisite capability node and represent the relation with edges; or
  • keep the rows non-dispatchable/parked until that capability is accepted.

Do not rely on Blocked on: #... prose. At review time #11671 and #11677 are already merged; #11679 is the remaining live prerequisite.

P0 — the census handoff promotes historical prototype output and omits the actual re-derivation arc

The final section says the 57 rows/five CostOpportunity standings are merely transcribed and then says "the scan producer is what dissolves that." It is not. The bounded code-search producer can establish a candidate population; it cannot reconstruct:

  • actual provider execution versus stale YAML declaration;
  • job occupancy (sum(completed-started)) rather than workflow wall time;
  • job pre-start observations rather than workflow-run admission;
  • attempts/pagination/fixed observation interval;
  • the private commercial projection that turns observations into prospect rows.

Those were the load-bearing corrections to the prototype. The rows must be labelled historical prototype output, not current occupancy or opportunity authority, and the remaining job-observation → execution standing → occupancy → private projection → sheet path must survive as a roadmap item or an explicit parked obligation. Otherwise the wind-down preserves the API budget prerequisite while losing the analysis it exists to serve.

The same section should not repeat Five carry CostOpportunity without the invalidation: declaration did not establish execution or positive spend.

P1 — the handoff is already stale and overstates acquisition completion

  • #11656 is merged, not open/awaiting queue.
  • #11671 and #11677 are merged; only #11679 remains open in that named chain.
  • The #11552 table row calls the manifest flow "end to end", but current source still instructs the operator to open a GET registration page and paste into a manifest field that GitHub does not provide. App installation is also a separate prerequisite. Either record those acquisition gaps, or establish that the human acquisition/installation is already complete for the census App; do not call the merged source end-to-end.

Smallest acceptable recut

  1. Make every known blocker affect dispatchability through an edge/capability or a non-dispatchable/parked standing.
  2. Add or point to the missing job-level census/reprojection obligation; narrow the 57-row section to historical evidence.
  3. Correct #11656/#11671/#11677 status and the #11552 completion claim; regenerate ROADMAP.

The existing edge from review-sheet-properties-write-and-legacy-retirement to review-sheet-identity-producer-and-admission is correct and should remain.

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

CORRECTION TO MY REQUEST_CHANGES — exact head 86a86b92e4166445d484588628ad1a1523f83187.

I withdraw the external-PR-blocker finding as a blocker on this wind-down PR.

I had conflated three different facts: an authored node is Dispatchable, node_is_startable_for_accepted says its declared parents are accepted, and the implementation is spawnable. The actual projection keeps them separate:

  • an active node whose execution contract is still unspecified enters startable_nodes_missing_closing_contract_for_accepted;
  • the projection adds a derived closing-contract-authoring node;
  • it also adds an edge from the implementation node to that closing-contract node;
  • roadmap_spawner consumes the projected document and requires all projected parents to be closed before the implementation node is spawnable.

Therefore these rows presently authorize closing-contract authoring, not blocked implementation work. startable_now is also a reporting count; its optimistic reading to a human is a naming/precision issue, not a false worker-dispatch authorization. A general external-PR blocker carrier is not required in #11856.

The later closing-contract authoring must preserve or structurally model any still-live capability prerequisite before its acceptance can release implementation. That is a future obligation at the correct boundary, not a defect in this handoff.

My overall REWORK ruling remains for the other two findings:

  1. the wind-down still omits the job-level observation / occupancy / provider-execution / private reprojection arc and describes the scan producer as if it can re-derive the historical prospect rows;
  2. it still calls #11552 an end-to-end acquisition flow although the current source instructs the operator to use a nonexistent manifest field, and App installation remains a separate undelivered prerequisite.

I will re-rule the exact moved head after those are addressed. No blocker-carrier work is requested.

@briansrls
briansrls added this pull request to the merge queue Sep 20, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to a conflict with the base branch Sep 20, 2026
Brian Searls and others added 3 commits September 20, 2026 19:43
Side-chat REWORK. Part 1 (external blockers as prose) was withdrawn after I
traced that startable authorizes closing-contract authoring rather than
implementation dispatch. Parts 2 and 3 stood, and both were my errors.

THE CENSUS ROWS ARE NOT AN AUTHORITY. The page said the 57 transcribed rows
were dissolved by the scan producer. That is materially wrong in two ways.
The economic readings attached to those rows were shown not to have the
meanings assigned to them -- wall duration is not summed runner occupancy, an
admission delay is not a runner queue delay, a provider declaration can
outlive provider execution, and adoption is not spend -- so the derived
runner-minutes and ARM-tier totals do not follow, and "five carry
CostOpportunity" must not be quoted as a finding. And the scan producer is
workflow-level, so it is necessary and NOT sufficient: the facts those rows
need are job-level. The job-level arc is now a roadmap node instead of a
sentence.

ACQUISITION IS MODELED, NOT ACHIEVED. The page called gunbc#11552 an
end-to-end App manifest flow. Its own route tells the operator to paste the
manifest into the create form's manifest field; GitHub exposes no such field
and the manifest protocol needs a form POST. I watched that step fail live in
this session and wrote "end to end" anyway. Registration and INSTALLATION are
also two facts, and gunbc#11677 consumes both rather than creating either.
That is now a node with the remaining work named.

EXTERNAL BLOCKERS ARE GONE. gunbc#11552, #11564, #11656, #11669, #11671,
#11677 and #11679 are all merged. The nodes and the page said otherwise.

The two real prerequisites are now EDGES rather than prose, which is the
repair the reviewer asked for: the installation token depends on the App
existing, and the job-level reprojection depends on the token.

Projection reconciles 146 -> 148: two nodes and their closing-contract
carriers, minus the two carriers the new edges remove from the startable set.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…p-items

# Conflicts:
#	ROADMAP.md
#	dag/gunbc/roadmap/roadmap_authority.dag

@briansrls briansrls left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LAND / SOURCE APPROVE — exact head 6413adf1431b5e97715a34f4cd24d98308faace7.

The two remaining findings from review 5261449672 are closed:

  1. Historical census output is no longer presented as authority. The handoff now explicitly refuses the four invalid inferences (workflow wall time as runner occupancy; run admission as runner queue; provider declaration as provider execution; adoption as positive spend), labels the 57 rows as historical prototype output, and states that the bounded workflow scan is necessary but not sufficient. The new census-job-level-observation-and-reprojection node owns the missing jobs?filter=all / paging / attempts / occupancy / execution-standing / private reprojection arc.

  2. #11552 is no longer called an achieved end-to-end acquisition. The handoff and new census-app-registration-installation-and-custody node state the live step-one failure, separate registration from installation, and preserve manifest submission, owner consent, callback capture, and terminal custody as remaining work.

The earlier external-PR-blocker finding remains withdrawn. The two new dependency edges are the correct authority: registration/install/custody precedes installation-token consumption, and installation-token consumption precedes the production job-level census. The review-sheet migration ordering edge remains intact. The merge conflict was reconciled correctly: the six wind-down nodes coexist with main's concat(guarantee_ladder_nodes(), typed_module_store_nodes()) tail.

Exact-head witnesses completed successfully. No blocking source finding remains.

Nonblocking metadata cleanup before queueing: the PR title/body still say “four nodes” and still describe #11656 as awaiting the operator, while this head carries six nodes and #11656 is merged. Correcting PR metadata does not move the approved source head.

@gunbai-bot
gunbai-bot Bot added this pull request to the merge queue Sep 20, 2026
@gunbai-bot gunbai-bot Bot changed the title Wind down the review-sheet and census lane into four roadmap nodes Wind down the review-sheet and census lane into six roadmap nodes Sep 20, 2026
Merged via the queue into main with commit b89eb84 Sep 20, 2026
4 checks passed
@gunbai-bot
gunbai-bot Bot deleted the lane/wind-down-roadmap-items branch September 20, 2026 23:35
@briansrls
briansrls restored the lane/wind-down-roadmap-items branch September 20, 2026 23:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant