Repository navigation
docs(briefs): T-Workflow-As-Data Slice 1 worker brief (β ratified) #2116
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from all commits
Commits
Show all changes
34 commits
Select commit
Hold shift + click to select a range
2fccc2a
docs(briefs): Substrate bridge SourceSpan.file participation retireme…
briansrls 8c5f054
docs(briefs): S5 Variant-aware projection carrier canvas (#1947)
briansrls d826950
docs(briefs): SourceSpan.file brief — same-slice prerequisite + secti…
briansrls f26a582
docs(briefs): SourceSpan.file brief — umbrella stays Open per P2 ledg…
briansrls beabfa4
docs(briefs): S5 CoproductProjection worker brief — γ ratified (#1947)
briansrls 925a412
docs(briefs): SourceSpan.file brief — resolve Acceptance #4 / Cross-M…
briansrls 5b3a9f8
WIP: R3 Substrate Mgr — lane through R3 close
briansrls 2900228
docs(briefs): S5 brief — absorb Director pre-ratifications for 3 STOP…
briansrls 313d1a6
Merge remote-tracking branch 'origin/main' into session/warm-wolf-698
briansrls 0e8724b
docs(r3): Q-Reification Gate A receipt — Option A (Dag-as-carrier)
briansrls 2601d7d
docs(briefs): S5 — delete superseded canvas + name dissolution trigge…
briansrls 1b9f743
docs(r3): Q-Reification row — fix invariant cite (C-1 → P2)
briansrls 55470a1
docs(briefs): S5 — name dissolution trigger for DeclarationRef alias …
briansrls 8a1f5c7
docs: complete Q-Reification stale-cite sweep — e6-g1a brief :169 + Q…
briansrls 5fc9221
docs(briefs): S5 — fix InputFieldRef mis-read; reframe observations #…
briansrls 598776f
docs(briefs): S5 — consolidate split per-variant maps into single key…
briansrls 4656801
docs(briefs): S5 — fix stale split-map vocab in path (a) + scope STOP…
briansrls 0ac8ca7
Merge remote-tracking branch 'origin/main' into session/warm-wolf-698
briansrls 85ceb85
Merge remote-tracking branch 'origin/main' into session/warm-wolf-698
briansrls 9f0b9de
Merge remote-tracking branch 'origin/main' into session/warm-wolf-698
briansrls aac5b3b
docs(briefs): descent_execution_proof canvas — 4-residual coproduct-d…
briansrls 622361c
docs(briefs): SourceSpan brief Row #6 — derive from bootstrap_authori…
briansrls e2741c4
docs(briefs): descent_execution_proof worker brief — γ ratified (2-va…
briansrls 0a0491c
WIP: R3 Substrate Mgr — lane through R3 close
briansrls 0cfea88
docs(briefs): descent_execution_proof — narrow EvidenceUnknown payloa…
briansrls ce12428
docs(briefs): descent_execution_proof — section-anchor cite for §10.3…
briansrls 1a0756a
Merge remote-tracking branch 'origin/main' into session/warm-wolf-698
briansrls 93c6f76
docs(briefs): T-CostLens-Composition canvas — Lens<SymbolicCost> comp…
briansrls 054dcde
docs(briefs): T-Workflow-As-Data canvas — audit-receipt-honoring scop…
briansrls 102071e
docs(briefs): T-CostLens-Composition worker brief — γ ratified; delet…
briansrls 35c4585
Merge remote-tracking branch 'origin/main' into session/warm-wolf-698
briansrls 34faf0c
Delete superseded T-CostLens canvas (worker brief is single live auth…
briansrls b7d808e
docs(briefs): T-WAD Slice 1 worker brief — β ratified; delete canvas
briansrls ae7972b
Merge remote-tracking branch 'origin/main' into session/warm-wolf-698
briansrls File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file was deleted.
Oops, something went wrong.
100 changes: 100 additions & 0 deletions
100
docs/briefs/r3-substrate-t-workflow-as-data-slice-1-worker.md
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,100 @@ | ||
| # Worker brief — Substrate T-Workflow-As-Data Slice 1 (β ratified) | ||
|
|
||
| **Sub-issue**: parent #1956 (T-WAD CI-workflow-as-.dag-data demo) eventually consumes; PM authors a Slice-1-specific work-item under #1939 post-this-brief landing. | ||
| **Authority**: Director ratification of **option β** at gunbc#828 #issuecomment-4395945465 (2026-05-07); 4 asks confirmed (β / #1771 audit-receipt binding / WorkflowSecret<Name> folds into extdeps / slice 2-3 separate canvases). | ||
| **Closure predicate**: §1.8 gate #53 `workflow_substrate_carriers_landed` (this slice) + #62 `substrate_gap_file_ingestion_closed` + #63 `substrate_gap_workflow_scheduling_closed` (per T-Workflow-As-Data lane row scope). | ||
|
|
||
| ## Slice scope (binding per Director) | ||
|
|
||
| T-Workflow-As-Data is split into 3 sub-slices per Director ratification ask #4: | ||
| - **Slice 1 (this brief)** — workflow substrate carriers (β minimalist) | ||
| - **Slice 2** — timing-and-pattern (TimingMeasurement + TimingObservationSet + WorkflowObservationAnchor + TimingBudget; gates #54 #55) — SEPARATE canvas, gated on T-LBP COMPLETE per §S4 design-schedule:95 | ||
| - **Slice 3** — `ci_workflow_modeled_as_dag` demonstration (gate #56) — SEPARATE canvas, consumes slices 1+2 | ||
|
|
||
| **Slice 1 net-new substrate** (only what was identified as wholly novel in the canvas): | ||
| 1. `WorkflowSecret<Name>` carrier — provider-typed, opaque-at-rest, scoped-by-step | ||
| 2. `Cron<Schedule>` typed refinement of existing `WorkflowTrigger::Schedule { cron: String }` (currently String; refine to typed cron expression) | ||
|
|
||
| Out-of-slice for the 4 reuse-named carriers (per audit #1771): | ||
| - `WorkflowTrigger` already at `dsl/extdeps/github/actions.dag:40` (only the inner `Schedule { cron: String }` refines to `Cron<Schedule>` shape per #2 above; outer `WorkflowTrigger` enum unchanged) | ||
| - `Step` (=`WorkflowStep`) at `:103`, `MatrixStrategy` (=`WorkflowMatrix`) inside `Job` at `:66+`, `RunnerSpec`+`RunnerLabel` (=`RunnerResource<C>`) at `:88+`, `Workflow` at `:20` — all reused as-is; lens consumes existing types directly per `feedback_audit_adjacent_authority_first` | ||
|
|
||
| ## Carrier shape (binding per Director ask #3) | ||
|
|
||
| **Location**: `dsl/extdeps/github/actions.dag` — fold-into-extdeps, NOT new `dsl/std/` file. Per Director rationale: all sibling carriers already live there + secret management IS provider-specific (GitHub Secrets, GitLab Variables, AWS Secrets Manager, etc.) — putting `WorkflowSecret<Name>` in `dsl/std/` would imply cross-provider universality that doesn't exist at HEAD. | ||
|
|
||
| **`WorkflowSecret<Name>`**: | ||
|
|
||
| ```dag | ||
| // Opaque-at-rest secret reference scoped by step. Name parameter carries the | ||
| // provider-side secret identifier (e.g., "GITHUB_TOKEN", "ANTHROPIC_API_KEY") | ||
| // without exposing the secret value at substrate level. Resolution happens at | ||
| // workflow-execution time via the provider's secret store. | ||
| type WorkflowSecret<Name> { | ||
| name: Name // typed identifier (provider-scoped) | ||
| scope: SecretScope // step-level vs job-level vs workflow-level | ||
| } | ||
|
|
||
| type SecretScope = StepScope | JobScope | WorkflowScope | ||
| ``` | ||
|
|
||
| **`Cron<Schedule>`** typed refinement at `dsl/extdeps/github/actions.dag:43`: | ||
|
|
||
|
Contributor
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. BLOCKING: |
||
| ```dag | ||
| // Refines WorkflowTrigger::Schedule { cron: String } to typed cron carrier. | ||
| // Cron expression is structured (minute / hour / day-of-month / month / day-of-week) | ||
| // rather than opaque-string; fail-closed on parse errors at fixture load. | ||
| type CronExpression { | ||
| minute: CronField | ||
| hour: CronField | ||
| day_of_month: CronField | ||
| month: CronField | ||
| day_of_week: CronField | ||
| } | ||
|
|
||
| type CronField = Wildcard | Exact(Int) | List(List<Int>) | Range(Int, Int) | Step(Int, Int) | ||
|
|
||
| // WorkflowTrigger update: replace inner Schedule { cron: String } with typed Cron<CronExpression>. | ||
| type WorkflowTrigger | ||
| = ... // existing variants unchanged | ||
| | Schedule { cron: CronExpression } // typed (was: String) | ||
| | ... | ||
| ``` | ||
|
|
||
| **STOP-and-PING the Mgr** if `CronExpression` decomposes into more than 5 fields (e.g., year support or seconds support emerges as needed) — that's substrate-shape expansion warranting Director ratification. | ||
|
|
||
| ### Cross-provider scope question (Director ratification ask #3 caveat) | ||
|
|
||
| Per Director: "if your lane visibility shows evidence the carrier is intended cross-provider (e.g., Anthropic provider work uses same shape), surface and we can elevate to `dsl/std/`. Default is fold-into-extdeps; promote-to-std only when cross-provider evidence accumulates." | ||
|
|
||
| Worker greps the codebase + adjacent provider work (Anthropic, OpenAI per `dsl/extdeps/llm/`) for `WorkflowSecret`-shaped patterns BEFORE folding. If cross-provider evidence emerges, **STOP-and-PING the Mgr**; otherwise proceed with fold-into-extdeps. | ||
|
|
||
| ## Acceptance gates (same-slice, all must pass) | ||
|
|
||
| 1. `WorkflowSecret<Name>` + `SecretScope` carriers landed in `dsl/extdeps/github/actions.dag`. | ||
| 2. `CronExpression` + `CronField` carriers landed in `dsl/extdeps/github/actions.dag`; existing `WorkflowTrigger::Schedule { cron: String }` migrated to `Schedule { cron: CronExpression }` with fixture-load fail-closed parse semantics. | ||
| 3. **No parallel-representation**: verify via grep that `dsl/std/` does NOT contain `WorkflowSecret`, `CronExpression`, or sibling shapes (would indicate accidental general-substrate creation against Director ratification). | ||
| 4. §1.8 gates advance: #53 `workflow_substrate_carriers_landed` → CONSUMER_LANDED; #62 `substrate_gap_file_ingestion_closed` + #63 `substrate_gap_workflow_scheduling_closed` advance per closure predicate. | ||
| 5. Bootstrap regen: `cargo test -p v3-compiler bootstrap_regen_fresh -- --ignored` clean. | ||
| 6. Full suite: `cargo test --workspace --exclude v2-compiler-tests` green; `cargo clippy --all-targets -- -D warnings` clean. | ||
|
|
||
| ## STOP / PING criteria | ||
|
|
||
| - **STOP** if cross-provider evidence emerges for `WorkflowSecret` shape (per Director ask #3 caveat) — surface to Mgr; promote-to-`dsl/std/` requires Director re-ratification. | ||
| - **STOP** if `CronExpression` field-count expands beyond 5 (e.g., year / seconds / nanoseconds) — substrate-shape expansion warrants Director ratification. | ||
| - **STOP** if migration of existing `WorkflowTrigger::Schedule { cron: String }` cascades into emit/typecheck surfaces beyond actions.dag — surface scope-creep. | ||
| - **PING** Verification Mgr (#2075) at PR-open time so they can advance §1.8 gates #53/#62/#63 ratchet authoring per standing concern. | ||
|
|
||
| ## Sequencing | ||
|
|
||
| Per §S4 design-schedule:95: Slice 1 dispatch-ready post-T-LBP COMPLETE (lens consumption needs lenses COMPLETE). Brief authoring lands in advance per pre-staging discipline. Slice 2 + Slice 3 are SEPARATE canvases authored when their preconditions clear (slice 2 gates on T-LBP COMPLETE; slice 3 consumes 1+2). | ||
|
|
||
| ## Worker pin (Mgr disposition) | ||
|
|
||
| valiant-ibex-312 OR smart-ram-167 (substrate-fact-introduction precedent owners). Final pin at dispatch. | ||
|
|
||
| ## Auto-spawn caveat | ||
|
|
||
| Per Director's standing note + cache-staleness cluster ctrl#217: HOLD dispatch on this brief until auto-spawn fix lands per L-sized substrate-fact-introduction threshold. | ||
|
|
||
| — Authored by warm-wolf-698 (Substrate Mgr) 2026-05-07 per Director β-ratification at gunbc#828 #issuecomment-4395945465. | ||
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
BLOCKING:
scope: SecretScopemakes workflow/job/step exposure a second authority beside the existing Workflow/Job/Step attachment locations, so contradictory secret-scope states remain representable (P2 single authority/illegal states).