Repository navigation
merge: reconcile release/0.7.0 into the 0.7.1 epic so #440 stops conflicting - #481
Conversation
* feat(core): add workload identity contract vocabulary (0.7.1b) (#402) * feat(core): add typed workload/configuration/deployment/run identity contract (0.7.1b) * docs(0.7.1): record 0.7.1b workload identity contract task * fix(core): expose identity contract as plain JVM classes for Java interop (0.7.1b review) * docs(0.7.1): correct 0.7.1b task evidence wording after Java-interop review --------- Co-authored-by: TramAI Test <tramai-test@invalid> * feat(control-plane): add authoritative workload registration and state boundary (0.7.1c) (#403) * feat(control-plane): add authoritative workload registration and state boundary (0.7.1c) * fix(control-plane): enforce CAS immutability, truthful stale versions, clean static analysis (0.7.1c review) * chore(0.7.1c): remove unused import, clarify race-handshake KDoc * fix(control-plane): advance state version only on genuine mutation (0.7.1c review) next() now runs only inside the mutation branch of updateMetadata and transitionLifecycle — stale, same-state, no-op and invalid commands are observational and never require a future version. A genuine mutation at Long.MAX_VALUE still fails closed on overflow. - InMemory CAS aligned to the JDBC concurrency token (deployment scope + state version); SPI wording makes the token explicit, TCK pins it so the two stores cannot drift semantically. - Authority test seeds Long.MAX_VALUE records and pins all non-mutation outcomes at the boundary; TCK gains the scope+version token discriminator. - Module/TASK docs test counts corrected (authority 26, TCK 17/store). * fix(control-plane): verify immutable witness in store CAS (0.7.1c review) A fabricated expected carrying a different configuration or fingerprint for the right scope+version previously passed CAS: InMemory stored the whole updated record (rewriting immutable authority), while JDBC returned true but never touched immutable columns. Same SPI call, two outcomes. CAS now requires the stored immutable authority to match expected's witness, alongside the scope+stateVersion token: - InMemory: predicate checks current.identity and current.configurationFingerprint against expected's. - JDBC: single UPDATE gains configuration_id/version predicates plus an EXISTS witness over tramai_configuration_revision fingerprint. - SPI KDoc states the token/witness split explicitly. - TCK: 2 new discriminators — fabricated configuration and fabricated fingerprint at the correct scope+version both return false and leave the registration unchanged (19 cases/store). Mutable metadata/lifecycle in expected remain deliberately ignored. * fix(persistence-jdbc): use non-deprecated PostgreSQLContainer in 0.7.1c tests The registration store tests added by 0.7.1c imported the deprecated org.testcontainers.containers.PostgreSQLContainer, producing compiler warnings not covered by the warnings baseline (additions forbidden). Switch to org.testcontainers.postgresql.PostgreSQLContainer (2.0.5 relocation, non-generic, same fluent API) so verifyCompilerWarnings stays clean without a baseline change. --------- Co-authored-by: TramAI Test <tramai-test@invalid> * fix(0.7.1c): enforce identity/metadata bounds in V8 migration Review follow-up on #404: both control-plane tables stored ids, owner and purpose as unrestricted TEXT, so a hand-written or corrupted row could hold state the typed contracts reject and fail during typed reconstruction on read. - V8: CHECK constraints for the identity columns (length 1..128) and for owner/purpose (1..256 / 1..512) on both tables. - JdbcWorkloadRegistrationStoreTest: a row exactly at each contract bound is accepted and round-trips through the typed mapper; one character over each bound is rejected with SQLSTATE 23514. Proven mutation-sensitive: removing the constraints fails the test. - 0.7.1c task doc records the database-side bound defence. * docs(0.7.1c): update module-card coverage table for the new control-plane module --------- Co-authored-by: TramAI Test <tramai-test@invalid>
… module set (#406) D5 required the catalog description of every published module to equal the frozen pre-B8 oracle entry, which is null for a module introduced after the catalog migration — a new published module could never satisfy it. Parity is now asserted for every pre-B8 module (still present, still published, still byte-identical), with a new D6 proving an edited pre-B8 description is still rejected. The consumer fixture also copies a fixed subset of tramai-core; any example importing a package outside that subset cannot compile in the fixture. The identity package is now copied too. Co-authored-by: TramAI Test <tramai-test@invalid>
Align the 0.7/0.8 roadmap with framework-independent governance authority, XR1 Spring AI proof, enforcement provenance, and deferred 0.8 adapter/DX ownership.
Merges release/0.7.0 (9ccbd0d) into the epic so the promotion PR stops conflicting. Seven files conflicted because #404 put an early control-plane snapshot onto release/0.7.0 while the epic carries the finished version 98 commits later. Resolution, per file: - tramai-control-plane/src/main/kotlin/.../WorkloadRegistrationAuthority.kt (add/add) -> epic - tramai-control-plane/src/test/kotlin/.../WorkloadRegistrationAuthorityTest.kt (add/add) -> epic - tramai-control-plane/api/tramai-control-plane.api (add/add) -> epic - docs/modules/tramai-control-plane.md (add/add) -> epic - build-logic/src/test/kotlin/.../ResidualQualityVerifierTasksTest.kt (content) -> epic (keeps the 0.7.1b identity-vocabulary comment; the release side had no competing text) - docs/roadmap/0.7.0/EPIC-0.7.1-CONTROL-PLANE-AUTHORITY.md (content) -> epic (drops the stale "Active - 0.7.1a/b/c" status line; the epic's CONTENT FROZEN line and the 0.7.1h section are preserved) - docs/roadmap/0.7.0/README.md (content) -> hand-merged: BOTH completion conditions kept, because each branch had renumbered item 7 differently and both are valid. The epic's 0.7.1 integration-closure gate stays item 7; #468's XR1 external-runtime authority proof is preserved as item 8. No production behaviour is changed by the resolution: every contested source file resolves to the epic's version. release/0.7.0's own commits (#404, #406, #468) remain in history.
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
It is a merge-commit reconciliation with hand-merged add/add conflict resolution and ancestry/second-parent requirements that cannot be verified from the diff alone and need human confirmation.
Review effort: Balanced
Findings: None
What changed in this PR
This PR reconciles release/0.7.0 (commit 9ccbd0d3) into the epic/0.7.1-control-plane-authority branch via a merge commit so that PR #440 stops conflicting. The merge brings release-side content — chiefly the new XR1 external-runtime authority proof documentation and the ModuleCatalogMutationTest.kt fix from #406 — into the epic while resolving all contested source files (the registration authority, its test, and the API dump) to the epic's existing versions. It is a branch-only reconciliation with no production source changes and no gate, baseline, or workflow modifications.
Changes:
- Introduces the
CHECKPOINT-0.7-XR1-EXTERNAL-RUNTIME-AUTHORITY-PROOF.mdand threads XR1 (Spring AI reference proof) through the 0.7/0.8 roadmap, epic specs, and ecosystem-governance strategy docs. - Reworks the ecosystem-governance strategy to split 0.7 (prove the framework-independent governance boundary once) from 0.8 (productize simulation/testing/debugger/adapter DX).
- Brings in the
ModuleCatalogMutationTestparity-oracle refactor plus the new D6 negative test (from #406), making legacy-description parity total over published modules while exempting post-freeze modules.
| File | Description |
|---|---|
docs/roadmap/0.7.0/CHECKPOINT-0.7-XR1-EXTERNAL-RUNTIME-AUTHORITY-PROOF.md |
New checkpoint spec defining the external-runtime authority proof, invariants, and exit criteria. |
docs/roadmap/0.7.0/README.md |
Hand-merged roadmap board/completion list adding XR1 as item 8 while keeping the 0.7.1 integration-closure gate as item 7. |
docs/roadmap/0.7.0/EPIC-0.7.2..0.7.8-*.md |
Threads deterministic/side-effect-free decisions, enforcement/evidence provenance, and XR1 references into the per-epic specs. |
docs/ROADMAP-0.7.0-RELEASE-CUT.md |
Adds reference external-runtime proof and framework-independent governance sections to the release cut. |
docs/LONG-TERM-ROADMAP-0.7-0.10.md |
Adds cross-runtime governance and effect/reversibility items to the long-term roadmap. |
docs/ROADMAP-0.8.0-GOVERNANCE-DX-AND-INTELLIGENCE.md |
Adds cross-runtime adapter DX and runtime capability/effect-semantics sections to 0.8. |
docs/design/ECOSYSTEM-GOVERNANCE-STRATEGY.md |
Rewrites the strategy as a cross-release note, splitting 0.7 proof obligations from 0.8 productization. |
build-logic/src/test/kotlin/.../ModuleCatalogMutationTest.kt |
Refactors legacy-description parity into a shared helper and adds the D6 negative test. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
2ba0fe4
into
epic/0.7.1-control-plane-authority
Reconciles
release/0.7.0(9ccbd0d) into the epic so PR #440 stops conflicting.Why the merge is needed
#440 was re-based onto
release/0.7.0and immediately wentCONFLICTING / DIRTY:release/0.7.0already carries an early control-plane snapshot from #404 (07ab1cb2, 2026-09-13), while the epic carries the finished version 98 commits later. Seven files conflicted — three of themadd/addon real source (the registration authority, its test, the API dump), which is a semantic resolution, not a mechanical one.Resolution, per file
All contested source resolves to the epic's version:
tramai-control-plane/src/main/kotlin/.../WorkloadRegistrationAuthority.kt(add/add) → epictramai-control-plane/src/test/kotlin/.../WorkloadRegistrationAuthorityTest.kt(add/add) → epictramai-control-plane/api/tramai-control-plane.api(add/add) → epicdocs/modules/tramai-control-plane.md(add/add) → epicbuild-logic/src/test/kotlin/.../ResidualQualityVerifierTasksTest.kt(content) → epic (keeps the 0.7.1b identity-vocabulary comment; the release side had no competing text)docs/roadmap/0.7.0/EPIC-0.7.1-CONTROL-PLANE-AUTHORITY.md(content) → epic (drops the stale "Active — 0.7.1a/b/c" status line; CONTENT FROZEN and the 0.7.1h section preserved)docs/roadmap/0.7.0/README.md(content) → hand-merged, both sides kept. Each branch had renumbered item 7 differently and both are valid completion conditions: the epic's 0.7.1 integration-closure gate stays item 7, and docs(0.7): align roadmap with cross-runtime governance #468's XR1 external-runtime authority proof is preserved as item 8. Taking either side would have silently dropped the other's condition.Verified on the merged tree
WorkloadRegistrationAuthority.kt, its test, andtramai-control-plane.apiare byte-identical to the epic — no production behaviour changes in the resolution.07ab1cb2(Epic/0.7.1 control plane authority #404),4f5ec229(build(quality): scope catalog description parity to the frozen oracle module set #406),9ccbd0d3(docs(0.7): align roadmap with cross-runtime governance #468).ModuleCatalogMutationTest.ktfrom build(quality): scope catalog description parity to the frozen oracle module set #406) — no production source.:tramai-control-plane:test— 61 tests, 0 failures.spotlessKotlinCheck,verifyStaticAnalysis,verifyChangePolicy -PchangePolicyBase=3a0771dc…— PASSED, 14 changed files, Detekt 4792→4792 with 0 added, noanalyzer-runtime-separationviolation.Merge this with a MERGE COMMIT — not a squash
The whole point is ancestry: #440 can only become clean if the epic and
release/0.7.0genuinely share this merge. A squash would discard the second parent and the conflict would return. Merge commita77bbf4d(parents3a0771dc,9ccbd0d3).Scope
Branch-only reconciliation. No merge to
masterorrelease/0.7.0is performed here, no production code is changed, and no gate, baseline, authority artifact or CI workflow is touched.