diff --git a/ARCHITECT_SESSION.md b/ARCHITECT_SESSION.md index 7887a31f..1fd4731b 100644 --- a/ARCHITECT_SESSION.md +++ b/ARCHITECT_SESSION.md @@ -60,7 +60,8 @@ Before reaching an architecture conclusion: 4. Inspect every open EP architecture, roadmap, migration and P-NEUTRAL PR, recording its exact head. Inspect current Forge consumer requirements/open proposals, Forge Platform installation/deployment authority, and relevant - Workspace dependency documents at their `main` revisions. + Workspace dependency documents at their freshly resolved remote `origin/main` + revisions. Do not use a local peer checkout as current peer authority. 5. Inspect the actual installed EP instance separately: service/health, installation identity/data root, CENTRAL schema/integrity, installed wheel and CLI, ingress availability, credential/auth boundary, attached project, @@ -73,6 +74,23 @@ authority maps; `EXECUTION_HOST_ARCHITECTURE.md`; `RUN_QUALIFICATION_EVIDENCE_CO and the phase-P migration/dependency authorities above. Follow their links for the narrow contract at issue rather than inventing a parallel summary. +## Peer authority freshness + +Before using time-sensitive Forge or Workspace status, refresh that +repository's remote state and resolve its `origin/main`. Record the repository, +exact SHA and observation timestamp. A previously observed SHA is historical +observation evidence only; local filesystem timestamps do not establish +freshness. If either refresh or remote resolution is unavailable, record: + +```text +PEER_AUTHORITY_FRESHNESS = UNVERIFIED +``` + +and do not present time-sensitive peer status as current. Otherwise record +`PEER_AUTHORITY_FRESHNESS = VERIFIED`. EP owns EP capability status; consumer +repositories own only their dependency semantics. Do not turn a peer's +projection into a second EP roadmap. + ## Evidence labels Every material statement must carry one of these labels: @@ -89,9 +107,17 @@ Every material statement must carry one of these labels: | `INFERENCE` | A conclusion derived from evidence; never silently promoted. | | `PROPOSAL` | A suggested future change awaiting its owner. | -Always distinguish `IMPLEMENTED`, `QUALIFIED`, `AVAILABLE_TO_CONSUMER`, and -`DOCUMENTED_STATUS`. No one implies another. If they disagree, record a stale -projection or an unresolved conflict instead of flattening the states. +Every material current-status conclusion records `DOCUMENTED_STATUS`, +`IMPLEMENTED`, `QUALIFIED`, `COMPLETION_EVIDENCE`, +`AVAILABLE_TO_CONSUMER`, and `CURRENT_RECONCILED_STATUS`. No one implies +another. If a roadmap/DAG/status projection says `ACTIVE`, `PLANNED`, or +`INCOMPLETE` while stronger same-capability owning-repository canonical +completion or qualification evidence proves closure, set +`STALE_PROJECTION_SUSPECTED = TRUE`, inspect the scope of the evidence, and +repair the owning current-status projection. Roadmap order is not stronger +than canonical completion evidence. Implementation alone never implies +qualification. `CURRENT_STATUS_IS_EVIDENCE_RECONCILED = TRUE` is required +before reporting a status as current. ## Two-pass bootstrap @@ -104,13 +130,19 @@ state; open EP proposals; and peer consumer requirements. Label the result ### Pass 2 — Evidence Reconciliation -Test whether roadmap projections are stale, a historical umbrella gate is -being treated as atomic, implementation has advanced without qualification, +Compare within EP as well as across products: roadmap, dependency DAG, status +projections, completion/qualification evidence, implementation evidence and +merged canonical history. Classify each finding as `NO_CONFLICT`, +`STALE_PROJECTION_SUSPECTED`, `PENDING_RECONCILIATION`, or +`REAL_AUTHORITY_CONFLICT`. Test whether roadmap projections are stale, a +historical umbrella gate is being treated as atomic, implementation has advanced without qualification, qualification is unavailable to the consumer, historic migration ordering is being confused with a physical dependency, a peer needs only a bounded producer capability, an open PR contains a supported successor, or an installed runtime already supplies a producer seam. Do not rewrite Pass 1; -write only supported, owned findings back to their canonical record. +write only supported, owned findings back to their canonical record. A stale +current-status projection is normally an autonomous documentation/status +repair, not automatically a human architecture decision. ## First-loop objective and dependency test @@ -241,6 +273,7 @@ roadmap/DAG proposal; do not create competing P-NEUTRAL or roadmap truths. | Governance change | governance documents | | Execution contract change | owning execution contract | | Migration authority finding | owning migration/authority document | +| Stale current status | owning roadmap/status/DAG projection | | Bootstrap method change | this file | | Peer-product truth | peer authority; reference it, do not duplicate it as EP authority | | Transient reasoning | do not persist | @@ -257,11 +290,12 @@ without chat history. Every substantive Architect response ends with a compact ASCII progress report. It is a read-time evidence projection, not a fourth roadmap or an independent -status register. Derive the shared rows afresh from the current owning -repository `main` authorities, their exact SHA/date where material, canonical -producer evidence, and open-PR head/qualification state. Name those sources in -`SOURCES`; never copy a peer's status into this file or silently promote a -`PENDING_PR` to canonical truth. +status register. Derive the shared rows afresh from current remote +`origin/main` owning authorities, their exact SHA and observation timestamp, +canonical producer evidence, and open-PR head/qualification state. Never copy +a peer's status into this file or silently promote a `PENDING_PR` to canonical +truth. If peer freshness is unverified, say so and omit time-sensitive peer +status claims. Use capability/evidence rows only — a status is never inferred from ordering, elapsed time, or an approximate percentage. Every row must use exactly one of: @@ -275,8 +309,12 @@ The report must include both shared sections and this product-specific section: ```text ARCHITECT PROGRESS -SOURCES: Forge main=; EP main=; Workspace main=; - pending= +SOURCES +Forge origin/main=@ +EP origin/main=@ +Workspace origin/main=@ +PEER_AUTHORITY_FRESHNESS=VERIFIED | UNVERIFIED +pending= AUTONOMY CUTOVER diff --git a/docs/development/ENGINEERING_PLATFORM_EXTRACTION_MIGRATION_PLAN.md b/docs/development/ENGINEERING_PLATFORM_EXTRACTION_MIGRATION_PLAN.md index 75fa1bfe..fec1ea0d 100644 --- a/docs/development/ENGINEERING_PLATFORM_EXTRACTION_MIGRATION_PLAN.md +++ b/docs/development/ENGINEERING_PLATFORM_EXTRACTION_MIGRATION_PLAN.md @@ -807,10 +807,10 @@ It is not a shorthand that permits an unspecified migration prerequisite. | Node ID | Depends on | Provides / qualification | Current status | V1 classification | | --- | --- | --- | --- | --- | | `EP::PHASE3_STANDALONE_PACKAGE_AND_INSTALL_QUALIFICATION_V1` | Phase-0/1 completed boundary and the clean-slate Phase-2 decision | History-preserving extraction; clean package/import; schema-41 clean store; Server and minimum Agent installation/service qualification; B8C/B8D evidence | AUTHORIZED / incomplete | REQUIRED_BEFORE_STANDALONE_VERIFIED | -| `EP::P_TRANSPORT_V1` | Retained P-CENTRAL-CORE and P-CENTRAL-CONSOLE repairs | File, CLI and HTTP normalize into CENTRAL; watcher owns no lifecycle truth | ACTIVE GAP | REQUIRED_BEFORE_STANDALONE_VERIFIED | +| `EP::P_TRANSPORT_V1` | Retained P-CENTRAL-CORE and P-CENTRAL-CONSOLE repairs | File, CLI and HTTP normalize into CENTRAL; watcher owns no lifecycle truth | COMPLETE / qualified P-TRANSPORT ingress evidence | REQUIRED_BEFORE_STANDALONE_VERIFIED | | `EP::P_QUEUE_V1` | `EP::P_TRANSPORT_V1` | Project-scoped FIFO, lease/recovery/finalization and isolation evidence | QUALIFICATION REMAINS | REQUIRED_BEFORE_STANDALONE_VERIFIED | -| `EP::P_NEUTRAL_V1` | `EP::P_QUEUE_V1` | No active DJConnect runtime identity, local authority or obsolete entrypoint | ACTIVE GAP | REQUIRED_BEFORE_STANDALONE_VERIFIED | -| `EP::P_INSTALLER_V1` | `EP::PHASE3_STANDALONE_PACKAGE_AND_INSTALL_QUALIFICATION_V1`; `EP::P_NEUTRAL_V1` | Idempotent verified installation, service, repair and clean activation path | PLANNED / incomplete | REQUIRED_BEFORE_STANDALONE_VERIFIED | +| `EP::P_NEUTRAL_V1` | `EP::P_QUEUE_V1` | No active DJConnect runtime identity, local authority or obsolete entrypoint | COMPLETE / merged closure `b44af0914622dd57c5c5c2266ee2caf9b31d9007` | REQUIRED_BEFORE_STANDALONE_VERIFIED | +| `EP::P_INSTALLER_V1` | `EP::PHASE3_STANDALONE_PACKAGE_AND_INSTALL_QUALIFICATION_V1`; `EP::P_NEUTRAL_V1` | Idempotent verified installation, service, repair and clean activation path | CURRENT AUTONOMY FRONTIER / incomplete | REQUIRED_BEFORE_STANDALONE_VERIFIED | | `EP::P_RELEASE_V1` | `EP::PHASE3_STANDALONE_PACKAGE_AND_INSTALL_QUALIFICATION_V1`; `EP::P_INSTALLER_V1` | Pinned signed release, provenance, compatibility and rollback evidence | ACTIVE GAP | REQUIRED_BEFORE_STANDALONE_VERIFIED | | `EP::PHASE_P_REAUDIT_V1` | `EP::P_TRANSPORT_V1`; `EP::P_QUEUE_V1`; `EP::P_NEUTRAL_V1`; `EP::P_RELEASE_V1` | Zero active migration gaps or explicit approved retirement | PLANNED / incomplete | REQUIRED_BEFORE_STANDALONE_VERIFIED | | `EP::PD_INSTALLED_PRODUCT_GOLDENS_V1` | `EP::PHASE_P_REAUDIT_V1`; `EP::P_INSTALLER_V1` | Installed Managed, Genesis and armed-retry Golden evidence | BLOCKED_BY `EP::PHASE_P_REAUDIT_V1` | REQUIRED_BEFORE_STANDALONE_VERIFIED | diff --git a/docs/development/ENGINEERING_PLATFORM_ROADMAP.md b/docs/development/ENGINEERING_PLATFORM_ROADMAP.md index 737b24df..66cd37e4 100644 --- a/docs/development/ENGINEERING_PLATFORM_ROADMAP.md +++ b/docs/development/ENGINEERING_PLATFORM_ROADMAP.md @@ -8,8 +8,8 @@ This section is the current sequencing authority where older roadmap prose or de - `P-TRANSPORT` is **MERGED / CLOSED**. It provides three canonical submission transports — HTTP, installed CLI and Server-owned File Inbox — normalized through the Server-owned Submission Service/CENTRAL boundary. File Inbox is transport only, never lifecycle authority. - The Phase-1 Local Consumer API read-only foundation and the later P-TRANSPORT HTTP submission ingress are distinct. The existence of the earlier read-only API qualification must not be interpreted as “all EP HTTP is read-only”. -- Current work is `P-NEUTRAL`: remove remaining active DJConnect platform identity/authority while preserving historical evidence and bounded migration compatibility. -- `P-INSTALLER-V1` is now an explicit critical-path gate immediately after P-NEUTRAL. It installs/repairs only the standalone Engineering Platform Server-side product components required by the first installed execution canary. It does **not** install Forge, Workspace or generalized Project-Agent productization. +- `P-NEUTRAL` is **MERGED / CLOSED**. Commit `b44af0914622dd57c5c5c2266ee2caf9b31d9007` supplies the final authority-closure register and guarded evidence that active DJConnect platform identity/authority is absent while historical evidence remains classified and retained. +- `P-INSTALLER-V1` is the **CURRENT AUTONOMY FRONTIER**. It installs/repairs only the standalone Engineering Platform Server-side product components required by the first installed execution canary. It does **not** install Forge, Workspace or generalized Project-Agent productization. - The Canonical Project Authority Repository declares durable logical project/repository identity in `.engineering-platform/repository.json` under the B8R architecture. Workspace may project identity and own human-facing state/display naming; Workspace availability is not required for EP to attach a declared repository. - Broader Project-Agent separation, generalized Agent dispatch, multi-host scheduling and multi-repository parallel execution are **not prerequisites by default** for the first standalone verification. They are follow-on productization unless the minimum installed execution canary proves a concrete dependency. - Broad P-QUEUE/B8E productization must not become an artificial all-or-nothing gate. Only concrete queue/lease/recovery/finalization/zero-loss capabilities required to prove one installed governed execution are on the immediate critical path. @@ -19,8 +19,8 @@ This section is the current sequencing authority where older roadmap prose or de ```text P-TRANSPORT merged/closed - -> P-NEUTRAL closure - -> P-INSTALLER-V1 + -> P-NEUTRAL merged/closed + -> P-INSTALLER-V1 current frontier server-side EP product only clean install/repair/update canonical runtime + CENTRAL + HTTP/CLI/Inbox + Console/relay as applicable @@ -107,7 +107,7 @@ The bootstrap through `EP::SELF_HOSTED_ENGINEERING_VERIFIED` must use the **mini Numbered sequence: -1. P-NEUTRAL closure. +1. P-NEUTRAL closure (complete; preserved predecessor). 2. P-INSTALLER-V1 qualification and installed Server cutover/repair. 3. DJConnect declaration + CENTRAL attachment. 4. First real DJConnect Engineering Action. @@ -117,7 +117,7 @@ Numbered sequence: Governance policy: - One bounded bootstrap authority envelope may cover repository implementation, installer implementation, declaration creation, attachment, read-only inspection, deterministic validation, defect repair, exact-head requalification, hosted checks and repeated Human Security review without returning to the owner between each engineering sub-step. -- P-NEUTRAL implementation and P-INSTALLER-V1 implementation/qualification are engineering loops: implement -> validate -> diagnose -> bounded repair -> revalidate -> security re-review until merge/cutover-ready. +- P-INSTALLER-V1 implementation/qualification is an engineering loop: implement -> validate -> diagnose -> bounded repair -> revalidate -> security re-review until merge/cutover-ready. P-NEUTRAL is complete and remains only as the preserved predecessor/closure evidence. - Repository declaration creation and CENTRAL attachment are topology realization inside the approved B8R boundary; they are not separate owner gates when project/repository identity, install scope and allowed host are already pinned. - Tests, CI failures, installer defects, migration defects and Security-review findings that remain within the approved phase boundary are not owner gates. - `EP::STANDALONE_EP_VERIFIED` and `EP::SELF_HOSTED_ENGINEERING_VERIFIED` are evidence milestones, not manual approval stops by themselves. @@ -136,9 +136,6 @@ The preferred operational model is therefore: OWNER APPROVES ONE BOUNDED BOOTSTRAP ENVELOPE | v -P-NEUTRAL engineering loop - | - v P-INSTALLER-V1 engineering + installed qualification loop | v @@ -220,9 +217,14 @@ P-TRANSPORT qualifies exactly three supported submission transports: All normalize through the same Server-owned Submission Service/CENTRAL authority. Forge's machine-to-machine integration should prefer canonical HTTP. -## Current P-NEUTRAL increment +## Completed P-NEUTRAL authority closure -P-NEUTRAL removes active DJConnect naming/identity from generic EP runtime, installation, lifecycle, configuration and logging authority. Historical-only artifacts and migration-source references may remain when explicitly classified. Current concrete work includes neutralizing the remaining installed relay identity without creating dual authority or unsafe rollback. +P-NEUTRAL removed active DJConnect naming/identity from generic EP runtime, +installation, lifecycle, configuration and logging authority. The merged final +closure commit is `b44af0914622dd57c5c5c2266ee2caf9b31d9007`; its authority +guard and closure register preserve historical-only artifacts and +migration-source references when explicitly classified. It is a completed +predecessor, not current work. P-NEUTRAL closure requires zero active generic DJConnect platform identity within the qualified host/repository scope. It does **not** remove the historical EP implementation from the DJConnect source repository. DJConnect source retirement remains separately governed post-standalone work. @@ -232,11 +234,11 @@ P-NEUTRAL closure requires zero active generic DJConnect platform identity withi ### First-loop gate decomposition and reconciliation status -This is a **PENDING_PR** reconciliation of the older migration-to-V1 dependency -table, not a statement that its full umbrella gates are already complete. The -owning migration/DAG authority must be updated together with this roadmap -before a narrower edge is treated as merged canonical sequencing. For each -gate, the first-loop test is physical: if the named capability is absent, can +This is a **MERGED_CANONICAL** reconciliation of the older migration-to-V1 +dependency table, not a statement that its full umbrella gates are already +complete. The owning migration/DAG authority is updated together with this +roadmap before a narrower edge is treated as merged canonical sequencing. For +each gate, the first-loop test is physical: if the named capability is absent, can one bounded Forge Action still enter through HTTP, receive durable identity, be admitted, mutate its repository, validate/review/repair/finalize, retain terminal evidence, and reconcile after Forge restart? @@ -246,7 +248,7 @@ terminal evidence, and reconcile after Forge restart? | Phase-3 package/install | A clean installed Server/CENTRAL/runtime that can run the canary | Historical dependency authority says incomplete; no current installed-proof claim is made here | `AUTONOMY_CRITICAL` bounded capability; full historical phase needs reconciliation | | P-TRANSPORT | HTTP JSON -> Server -> Submission Service -> CENTRAL, with CLI/File Inbox retained as peer ingresses | Merged P-TRANSPORT authority and installed ingress qualification | `AUTONOMY_CRITICAL`; qualified transport capability | | P-QUEUE | Durable submission/run identity, one serial mutating lane, lease/restart/replay protection, finalization/evidence for the canary | Older authority records broad qualification remaining | `PARTIALLY_AUTONOMY_CRITICAL`; not generalized queue/fairness productization | -| P-NEUTRAL | No dual current execution, Server/CENTRAL, routing, or credential authority in the canary scope | Active authority-closure proposals remain pending | `AUTONOMY_CRITICAL` minimum subset; historical/forensic labels are not blockers when safely classified | +| P-NEUTRAL | No dual current execution, Server/CENTRAL, routing, or credential authority in the canary scope | Merged closure `b44af091`; guarded current-authority inventory and retained historical classifications | `AUTONOMY_CRITICAL` completed predecessor; historical/forensic labels are not blockers when safely classified | | P-INSTALLER | Reproducible Server-side install/repair/update and health for the one EP instance | Proposed here; qualification not yet claimed | `AUTONOMY_CRITICAL` bounded capability; excludes Forge, Workspace and general Agent productization | | P-RELEASE | A trusted artifact/version/rollback path sufficient for the canary install | Older authority records active gap | `PARTIALLY_AUTONOMY_CRITICAL`; full channel/product release programme is not presumed required | | Phase-P re-audit / installed Goldens / B8E | Zero-loss disposition and installed evidence for every capability claimed live by the canary | Older authority records these incomplete/blocked | `PARTIALLY_AUTONOMY_CRITICAL`; audit the canary capability set, not unrelated future product scope | @@ -309,8 +311,8 @@ Forge may consume canonical EP readiness/status/result/evidence APIs but must no | --- | --- | --- | | `EP::LOCAL_CONSUMER_API_V1` | Qualified consumer/authentication/read contract foundation. | AVAILABLE. | | `EP::P_TRANSPORT_V1` | Three canonical submission transports with Server/CENTRAL normalization. | MERGED / QUALIFIED. | -| `EP::P_NEUTRAL_V1` | No active generic DJConnect platform identity/authority. | ACTIVE. | -| `EP::P_INSTALLER_V1` | Reproducible standalone Server-side EP install/repair/update boundary; excludes Forge/Workspace/general Agent productization. | CRITICAL PATH immediately after P-NEUTRAL. | +| `EP::P_NEUTRAL_V1` | No active generic DJConnect platform identity/authority. | MERGED / CLOSED; completion evidence `b44af091`. | +| `EP::P_INSTALLER_V1` | Reproducible standalone Server-side EP install/repair/update boundary; excludes Forge/Workspace/general Agent productization. | CURRENT AUTONOMY FRONTIER. | | `EP::STANDALONE_EP_VERIFIED` | One independent installed governed DJConnect execution with canonical evidence. | AFTER P-INSTALLER-V1 + DJConnect canary. | | `EP::SELF_HOSTED_ENGINEERING_VERIFIED` | Installed EP executes a real bounded Engineering Platform source change through CENTRAL. | IMMEDIATE POST-STANDALONE dogfood gate. | | `EP::PROJECT_ATTACHMENT_AND_ADMISSION_V1` | Consumer-facing attachment/admission hardening beyond current B8R runtime. | FOLLOW-ON consumer qualification. | diff --git a/docs/engineering/P_NEUTRAL_FINAL_AUTHORITY_CLOSURE.md b/docs/engineering/P_NEUTRAL_FINAL_AUTHORITY_CLOSURE.md index 632f88ae..e3d5ba72 100644 --- a/docs/engineering/P_NEUTRAL_FINAL_AUTHORITY_CLOSURE.md +++ b/docs/engineering/P_NEUTRAL_FINAL_AUTHORITY_CLOSURE.md @@ -4,6 +4,22 @@ This register classifies residual DJConnect references by their operational responsibility. It deliberately does not use a clean string search as a completion condition. +## Completion status + +`P_NEUTRAL_DOCUMENTED_STATUS = COMPLETE` + +`P_NEUTRAL_COMPLETION_EVIDENCE = b44af0914622dd57c5c5c2266ee2caf9b31d9007` + +`P_NEUTRAL_CURRENT_RECONCILED_STATUS = COMPLETE` + +`P_NEUTRAL_COMPLETED_PREDECESSOR_PRESERVED = TRUE` + +`P_INSTALLER_V1_CURRENT_FRONTIER = TRUE` + +The completion evidence applies only to active generic Engineering Platform +authority. It preserves, rather than authorizes removal of, the historical, +provenance, migration-source and negative-fixture references classified below. + ## Current Engineering Platform authority | Domain | Current identity | DJConnect current authority | diff --git a/tests/engineering/test_p_neutral_final_authority_closure.py b/tests/engineering/test_p_neutral_final_authority_closure.py index c645acc4..94fef557 100644 --- a/tests/engineering/test_p_neutral_final_authority_closure.py +++ b/tests/engineering/test_p_neutral_final_authority_closure.py @@ -98,6 +98,21 @@ def test_authority_register_documents_the_installer_boundary(self) -> None: ): self.assertIn(required, register) + def test_current_status_projects_the_completed_predecessor_and_frontier(self) -> None: + register = (ROOT / "docs" / "engineering" / "P_NEUTRAL_FINAL_AUTHORITY_CLOSURE.md").read_text( + encoding="utf-8" + ) + roadmap = (ROOT / "docs" / "development" / "ENGINEERING_PLATFORM_ROADMAP.md").read_text( + encoding="utf-8" + ) + dependency_authority = ( + ROOT / "docs" / "development" / "ENGINEERING_PLATFORM_EXTRACTION_MIGRATION_PLAN.md" + ).read_text(encoding="utf-8") + self.assertIn("P_NEUTRAL_CURRENT_RECONCILED_STATUS = COMPLETE", register) + self.assertIn("P_INSTALLER_V1_CURRENT_FRONTIER = TRUE", register) + self.assertIn("`P-INSTALLER-V1` is the **CURRENT AUTONOMY FRONTIER**", roadmap) + self.assertIn("COMPLETE / merged closure `b44af0914622dd57c5c5c2266ee2caf9b31d9007`", dependency_authority) + if __name__ == "__main__": unittest.main()