Repository navigation
Wind down the review-sheet and census lane into six roadmap nodes - #11856
Conversation
The operator asked this lane to stop and record its progress and remaining items as roadmap project items, so v1 performance and v2 migration can have the system. Four nodes enter declared_roadmap_nodes, each carrying the constraint that would otherwise be lost with the session rather than a restatement of its own title: - the review-sheet identity kernel's producers and declared-id admission, which is what retires the three consumer frontier rows #11669 enrolled -- their triggers name execution, not import - the properties write-back and legacy-generation retirement, whose red control is the short-decode a field mask narrower than the declared response type produces - the census installation token, reusing #11677's App JWS route rather than adding an rs256_sign host primitive that would land against CRYPTO-0 - the ntfy publisher token onto the Mt Collins custody pattern, as a consolidation of #11679 rather than a sibling module, explicitly NOT retiring approval_store_single_writer_by_agreement Their shared carrier is a new plan page holding what the nodes point at: the appProperties visibility fact the whole identity kernel exists for, the three standing constraints on resuming the migration, and the transcribed census rows that no producer can yet re-derive. Evidence: declared_identities over the test.claim.roadmap_identity_witness_test fold evaluates with all four identities present, so the rows typecheck and inhabit the real list rather than parsing alone. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Ledger-Repair-Judged: docs/design-rung-drops.md Heal-Candidate-Run: 35516936949
…p-items # Conflicts: # ROADMAP.md
Review 69310 (§3, §4c). The ordering between the two review-sheet nodes was written twice in String fields and zero times where the projection reads it, so both nodes were independently startable -- the opposite of what the text said. `declared_roadmap_edges` is the existing modeled authority for exactly this relation. One edge replaces the prose. The restatement in `out_of_scope` is deleted rather than left beside the edge, because two answers to one question is the fork DESIGN 3 exists to prevent. Evidence that the edge is CONSUMED and not decoration: the regenerated projection moves 140 -> 139 active deliverables and drops review_sheet_properties_write_and_legacy_retirement's closing-contract carrier from the startable set, which is the fold the finding named. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
Review 69310 — the actionable finding is fixed in Fixed: the cross-node ordering. You're right that it existed twice in prose and zero times where the projection reads it. I checked it's consumed rather than decorative, since that was the substance of the finding: the regenerated projection moves 140 → 139 active deliverables and drops the retirement node's closing-contract carrier from the startable set. That is the fold you named ( Not fixed: the external-PR blockers, and I want to be explicit that this is a decline rather than an oversight. You're correct on the mechanism — There is no carrier in this authority for "blocked on an external pull request." Under DESIGN §3b that makes it a modeling obligation (§6), not a conformance violation — "a domain whose home does not yet exist is not a conformance row but a modeling obligation." Minting that carrier is a new authority on the roadmap's growth surface, which is the one thing this PR exists to avoid: it is a wind-down recording state so the system can prioritise v1 performance and v2 migration. So the PR references in I'd rather name the gap than paper over it, so stating it plainly for whoever picks these up: three of the four nodes are startable according to the model and are not startable in reality. If that matters more than the wind-down's no-new-authority constraint, the right fix is a real blocker carrier in — sent from zesty-crane-846 |
briansrls
left a comment
There was a problem hiding this comment.
REWORK — exact head 86a86b92e4166445d484588628ad1a1523f83187.
The mechanics are clean and the three constraints called out in the handoff are worth preserving: the appProperties empty-read scope, no new rs256_sign primitive beside the key-custody signer route, and the fact that metadata/mode readback does not retire approval_store_single_writer_by_agreement.
Three source problems prevent LAND.
P0 — the wind-down creates work the roadmap says is ready
These are active(...) rows, hence Dispatchable. The roadmap spawner does not read first_slice, out_of_scope, the plan document, or PR prose when deciding readiness. It asks whether the row is dispatchable, incomplete, unsuperseded, and whether every modeled RoadmapEdge parent is closed. The program view likewise derives dependency holding only from graph parents.
Therefore the source simultaneously says:
- "nothing here starts new work";
- census/ntfy work starts only after the custody chain lands;
- but the model exposes the unblocked rows/closing-contract work as startable.
That is not merely a missing future carrier under DESIGN 3b. It is a present false dispatch authorization, and it inverts the operator's wind-down purpose. Declining a generic ExternalPrBlocker authority is reasonable; knowingly emitting ready work is not. Use a conservative state the existing model can express:
- preferably add/identify the prerequisite capability node and represent the relation with edges; or
- keep the rows non-dispatchable/parked until that capability is accepted.
Do not rely on Blocked on: #... prose. At review time #11671 and #11677 are already merged; #11679 is the remaining live prerequisite.
P0 — the census handoff promotes historical prototype output and omits the actual re-derivation arc
The final section says the 57 rows/five CostOpportunity standings are merely transcribed and then says "the scan producer is what dissolves that." It is not. The bounded code-search producer can establish a candidate population; it cannot reconstruct:
- actual provider execution versus stale YAML declaration;
- job occupancy (
sum(completed-started)) rather than workflow wall time; - job pre-start observations rather than workflow-run admission;
- attempts/pagination/fixed observation interval;
- the private commercial projection that turns observations into prospect rows.
Those were the load-bearing corrections to the prototype. The rows must be labelled historical prototype output, not current occupancy or opportunity authority, and the remaining job-observation → execution standing → occupancy → private projection → sheet path must survive as a roadmap item or an explicit parked obligation. Otherwise the wind-down preserves the API budget prerequisite while losing the analysis it exists to serve.
The same section should not repeat Five carry CostOpportunity without the invalidation: declaration did not establish execution or positive spend.
P1 — the handoff is already stale and overstates acquisition completion
- #11656 is merged, not open/awaiting queue.
- #11671 and #11677 are merged; only #11679 remains open in that named chain.
- The
#11552table row calls the manifest flow "end to end", but current source still instructs the operator to open a GET registration page and paste into a manifest field that GitHub does not provide. App installation is also a separate prerequisite. Either record those acquisition gaps, or establish that the human acquisition/installation is already complete for the census App; do not call the merged source end-to-end.
Smallest acceptable recut
- Make every known blocker affect dispatchability through an edge/capability or a non-dispatchable/parked standing.
- Add or point to the missing job-level census/reprojection obligation; narrow the 57-row section to historical evidence.
- Correct #11656/#11671/#11677 status and the #11552 completion claim; regenerate ROADMAP.
The existing edge from review-sheet-properties-write-and-legacy-retirement to review-sheet-identity-producer-and-admission is correct and should remain.
briansrls
left a comment
There was a problem hiding this comment.
CORRECTION TO MY REQUEST_CHANGES — exact head 86a86b92e4166445d484588628ad1a1523f83187.
I withdraw the external-PR-blocker finding as a blocker on this wind-down PR.
I had conflated three different facts: an authored node is Dispatchable, node_is_startable_for_accepted says its declared parents are accepted, and the implementation is spawnable. The actual projection keeps them separate:
- an active node whose execution contract is still unspecified enters
startable_nodes_missing_closing_contract_for_accepted; - the projection adds a derived closing-contract-authoring node;
- it also adds an edge from the implementation node to that closing-contract node;
roadmap_spawnerconsumes the projected document and requires all projected parents to be closed before the implementation node is spawnable.
Therefore these rows presently authorize closing-contract authoring, not blocked implementation work. startable_now is also a reporting count; its optimistic reading to a human is a naming/precision issue, not a false worker-dispatch authorization. A general external-PR blocker carrier is not required in #11856.
The later closing-contract authoring must preserve or structurally model any still-live capability prerequisite before its acceptance can release implementation. That is a future obligation at the correct boundary, not a defect in this handoff.
My overall REWORK ruling remains for the other two findings:
- the wind-down still omits the job-level observation / occupancy / provider-execution / private reprojection arc and describes the scan producer as if it can re-derive the historical prospect rows;
- it still calls #11552 an end-to-end acquisition flow although the current source instructs the operator to use a nonexistent manifest field, and App installation remains a separate undelivered prerequisite.
I will re-rule the exact moved head after those are addressed. No blocker-carrier work is requested.
…p-items # Conflicts: # ROADMAP.md
Side-chat REWORK. Part 1 (external blockers as prose) was withdrawn after I traced that startable authorizes closing-contract authoring rather than implementation dispatch. Parts 2 and 3 stood, and both were my errors. THE CENSUS ROWS ARE NOT AN AUTHORITY. The page said the 57 transcribed rows were dissolved by the scan producer. That is materially wrong in two ways. The economic readings attached to those rows were shown not to have the meanings assigned to them -- wall duration is not summed runner occupancy, an admission delay is not a runner queue delay, a provider declaration can outlive provider execution, and adoption is not spend -- so the derived runner-minutes and ARM-tier totals do not follow, and "five carry CostOpportunity" must not be quoted as a finding. And the scan producer is workflow-level, so it is necessary and NOT sufficient: the facts those rows need are job-level. The job-level arc is now a roadmap node instead of a sentence. ACQUISITION IS MODELED, NOT ACHIEVED. The page called gunbc#11552 an end-to-end App manifest flow. Its own route tells the operator to paste the manifest into the create form's manifest field; GitHub exposes no such field and the manifest protocol needs a form POST. I watched that step fail live in this session and wrote "end to end" anyway. Registration and INSTALLATION are also two facts, and gunbc#11677 consumes both rather than creating either. That is now a node with the remaining work named. EXTERNAL BLOCKERS ARE GONE. gunbc#11552, #11564, #11656, #11669, #11671, #11677 and #11679 are all merged. The nodes and the page said otherwise. The two real prerequisites are now EDGES rather than prose, which is the repair the reviewer asked for: the installation token depends on the App existing, and the job-level reprojection depends on the token. Projection reconciles 146 -> 148: two nodes and their closing-contract carriers, minus the two carriers the new edges remove from the startable set. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…p-items # Conflicts: # ROADMAP.md # dag/gunbc/roadmap/roadmap_authority.dag
briansrls
left a comment
There was a problem hiding this comment.
LAND / SOURCE APPROVE — exact head 6413adf1431b5e97715a34f4cd24d98308faace7.
The two remaining findings from review 5261449672 are closed:
-
Historical census output is no longer presented as authority. The handoff now explicitly refuses the four invalid inferences (workflow wall time as runner occupancy; run admission as runner queue; provider declaration as provider execution; adoption as positive spend), labels the 57 rows as historical prototype output, and states that the bounded workflow scan is necessary but not sufficient. The new
census-job-level-observation-and-reprojectionnode owns the missingjobs?filter=all/ paging / attempts / occupancy / execution-standing / private reprojection arc. -
#11552 is no longer called an achieved end-to-end acquisition. The handoff and new
census-app-registration-installation-and-custodynode state the live step-one failure, separate registration from installation, and preserve manifest submission, owner consent, callback capture, and terminal custody as remaining work.
The earlier external-PR-blocker finding remains withdrawn. The two new dependency edges are the correct authority: registration/install/custody precedes installation-token consumption, and installation-token consumption precedes the production job-level census. The review-sheet migration ordering edge remains intact. The merge conflict was reconciled correctly: the six wind-down nodes coexist with main's concat(guarantee_ladder_nodes(), typed_module_store_nodes()) tail.
Exact-head witnesses completed successfully. No blocking source finding remains.
Nonblocking metadata cleanup before queueing: the PR title/body still say “four nodes” and still describe #11656 as awaiting the operator, while this head carries six nodes and #11656 is merged. Correcting PR metadata does not move the approved source head.
The operator asked this lane to wind down and record its progress and remaining items as roadmap project items, to relieve system pressure so v1 performance and v2 migration get the capacity. This is that record — it starts no new work.
Six
active(...)nodes, threeedge(...)rows, and a plan carrier (docs/plans/review-sheet-and-census-lane-handoff.md) that all six nodes'path:fields point at, plus the regeneratedROADMAP.md. No Rust, no shell, no new types, no new node vocabulary.The nodes
review-sheet-identity-producer-and-admission— producers + declared-id admission for the kernel landed in Cut 1 of the #11596 recut: the review-sheet identity kernel, pure #11669; retires the three consumer frontier rows it enrolled, whose triggers name execution, not import.review-sheet-properties-write-and-legacy-retirement— the PATCH with an id-bound readback, then legacy retirement.census-app-registration-installation-and-custody— new in the recut.census-installation-token-via-app-jws-route— reuse microVM: host-side JIT mint via GitHub App + attempt-owned jail device staging #11677's JWS/OpenSSL route; explicitly nors256_signhost primitive, which would land against CRYPTO-0.census-job-level-observation-and-reprojection— new in the recut.ntfy-publisher-token-onto-gcp-custody— the Mt Collins pattern as a consolidation of MicroVM controller App-key custody converge (root:root 0400, readback receipt) #11679; explicitly does not retireapproval_store_single_writer_by_agreement.What the recut corrected (side-chat REWORK, parts 2 and 3)
Both were overstatements of mine, and the review was right to refuse them:
CostOpportunity" is marked as not quotable. The job-level arc is node 5.Part 1 (external blockers as prose) was withdrawn after I traced that
startableauthorizes closing-contract authoring rather than implementation dispatch — an unbound node gains a derived closing-contract parent edge before the spawner sees it, so implementation stays held.Status of everything this lane referenced
All merged: #11552, #11564, #11656, #11669, #11671, #11677, #11679. No external prerequisite of this lane is open. The two real prerequisites are now edges: installation-token depends on app-registration; job-level reprojection depends on installation-token.
Verification
Six identities unique, all edge-referenced ids resolve to declared nodes, main's
concat(guarantee_ladder_nodes(), typed_module_store_nodes())tail preserved through a hand-resolved conflict with no authority dropped, andROADMAP.mdregenerated from the merged authorities rather than hand-resolved on every merge.🤖 Generated with Claude Code