Skip to content

fix(planner): preserve configurable parameters in runtime collection authority #1481

Description

@Brad-Edwards

Problem

RAES 6.0.1 cannot plan configurable string parameters inside runtime collections unless the parameter has a finite allowed_values list.

This affects the application route path, database name, gateway route prefix, and mail domain in OpenRAE/env-packs#414. Restricting each parameter to its default and test variation makes planning possible, but removes normal author configuration.

The same mechanism remains on dev at 35122105b0c1bb648754625d8e3920eafa9bc599.

Cause

  1. raes/explicitness.py::derive_instantiated_explicitness preserves substituted leaves as constrained. This also applies to an explicit author input with no default.
  2. raes/_capability_constraints.py::_finite_domain_constraint captures only whole-field parameter references with finite allowed_values.
  3. raes_processor/compiler/realization_recursive_constraints.py::_SourceMetadata._constrained_domain requires a captured domain. It cannot represent a typed configurable string leaf without that enumeration.
  4. The planner rejects the unresolved authority with realization.authority-bound-unavailable.

The variable model has no general string-domain, pattern, or length constraint. Open realization scopes do not remove the failure.

Reproduction evidence

Environment: env-packs PR #433, head 1a551321c00fa36e0e50674639ad214929a4ef2d; raes==6.0.1.

Compose each module through parse_sdl_file, then use compile_scenario_runtime_model and raes_processor.planner.plan. Remove the new allowed_values from the domain parameter. Supply these concrete values:

Kit Parameter Input
application-api-service api_base_path /custom/v3
postgresql-database database_name customer_data
reverse-proxy-api-gateway route_prefix /team/api
smtp-imap-mail-service mail_domain example.test

To isolate authority compilation from backend capability admission, use a test manifest with exact and constrained support for runtime-applications, runtime-database-services, and runtime-mail-services, plus configuration observation capabilities with guest-observed strength. Use closed realization defaults and keep the kits' open compute-substrate constraint. These declarations are a planning test fixture; they make no backend execution claim.

Case Result for all four kits
Typed string without allowed_values Invalid; authority-bound-unavailable is the only diagnostic
Required parameter, no default, explicit input Same failure
Same input written as a runtime literal Valid plan; no diagnostics
Finite allowed_values from PR #433 Valid plan for both declared values

Mail has a related failure. With mail_domain bounded to environment.test and alternate.test, use operator@${mail_domain} and service@${mail_domain} for mailbox addresses. Instantiation produces the correct addresses. Planning still reports authority-bound-unavailable. Embedded interpolation does not retain a derived bound. The mailbox model also has a credential-classification field, so safe bound capture must use its owning projection rather than bypass classification guards.

Expected behavior

  • Valid author-selected paths, database names, route prefixes, and mail domains remain configurable.
  • Compilation and planning preserve their typed authority and substitution provenance.
  • Mailbox addresses derived from the selected domain have representable authority.
  • Backend support and observation requirements remain enforced separately.
  • No finite catalog of example values is required to parameterize ordinary runtime content.
  • Existing classification, redaction, and non-approximation rules remain enforced.

Acceptance criteria

  • All four example modules plan with additional valid author-selected values and no hard-coded enumeration.
  • Required inputs and defaults have regression coverage.
  • Mail-domain interpolation has regression coverage and correct composed addresses.
  • Literal and finite-enumeration controls remain valid.
  • Unsupported backend demands still fail admission.
  • Phase contracts, compiler authority, schemas, and runtime admission agree on the supported parameter form.

Related

Activity

  1. Brad-Edwards commented on Oct 10, 2026

    @Brad-Edwards
    CollaboratorAuthor

    🛠️ Picked up by /implement - driver codex, branch 1481-configurable-runtime-parameters, 2026-10-10T23:58:46.983Z.

  2. Brad-Edwards commented on Oct 11, 2026

    @Brad-Edwards
    CollaboratorAuthor

    gc workflow phase recorded: preflight (issue #1481). Posted by the MCP server to enforce ordering between workflow steps (issue #794 MVP-2). Do not edit or delete — used by downstream tools to gate phase prerequisites.

  3. Brad-Edwards commented on Oct 11, 2026

    @Brad-Edwards
    CollaboratorAuthor

    gc workflow phase recorded: plan (issue #1481). Posted by the MCP server to enforce ordering between workflow steps (issue #794 MVP-2). Do not edit or delete — used by downstream tools to gate phase prerequisites.

    Implement configurable runtime parameter authority through portable parameter-derivation evidence, retaining constrained author specificity and processor provenance.

    1. Path B: add failing regression tests for application paths, database names, gateway prefixes and mail domains, covering defaults, required inputs, additional selected strings, literals, finite controls and both interpolated mailbox addresses. Reuse the synthetic supporting manifest and recursive/runtime fixtures; verify unsupported backend/observation demands still fail.
    2. Path B: extend closed SDL phase provenance with typed parameter derivations represented as literal segments and qualified parameter references (no unresolved template strings). Reuse canonical substitution/equality, binding type/domain validation, namespace rewriting and concrete runtime-field validation. Preserve incumbent whole-field finite-domain permission. Unenumerated inputs carry explicitly selected binding authority, not an invented author domain; single-parameter finite interpolations retain their transformed finite image, including repeated tokens. Unsupported nonrepresentable images fail closed rather than enumerate Cartesian products.
    3. Path B: capture public runtime leaves through existing traversal. Classification-bearing records remain guarded; the mailbox owner explicitly identifies its public address surface, and lowering must still consume the registered safe projection. Protected alternatives, credentials, commitments and presence markers remain excluded. Compile selected bindings as processor-origin literal constraints while leaving authored specificity constrained; compile finite images through existing EnumDomain machinery. Preserve exact siblings, closure, member identities and canonical plan binding.
    4. Path B: exercise imported/nested parameter identities, serialized scenario and plan/schema admission, tampered bindings/outputs, safe-value non-leakage and actual runtime rejection of altered selected values. Update affected published phase/snapshot schemas and publication ledgers together with schema_bundle, plus fixtures where needed. Path D: clarify selected-binding versus finite-domain semantics in normative realization/phase documentation and implementer reference; retain the preflight note.

    Security: parser, semantic and Pydantic validation remain authoritative; phase consistency validates each typed referenced binding and concrete output; registered projection controls publication; plan DTO/readmission, backend support, observation/corroboration and runtime result sanitization remain unchanged enforcement layers. No execution, auth/config shape, secret argv or storage mechanism is added.
    Maintainability/extensibility: build on VariableType, ParameterBinding, VARIABLE_TOKEN_RE/canonical substitution, existing RFC6901/name rewriting and recursive authority; use typed derivation dispatch and owner-approved public fields, never per-kit exceptions or blanket string domains. Whole-repo scope includes composition, phase/snapshot schemas, schema publication, compiler, planner and portable runtime admission.

    Verification: use targeted pytest modules/cases and targeted repo-policy edit guards before/after changes; set RAES_REQUIREMENT_UID=SEM-218 for relevant local policy checks without adding it to this requirement-free issue. CI owns full suites. Preserve mandatory publish hook, bounded review, CI/Sonar and readiness gates. Do not edit release-owned versions/changelog. No new structural gate or formal requirement is introduced.

  4. Brad-Edwards commented on Oct 11, 2026

    @Brad-Edwards
    CollaboratorAuthor

    gc_codex_review — sanitized deferred publication for issue #1481, cycle 1 of 1
    Reviewed revision: e3c19f7cf3c627494b7aa4fdb28c7e1b71478b070e2a32f9bcf09c5d53bfdd27

    Architectural read

    Typed derivations extend the closed phase provenance carrier and reuse qualified namespace rewriting, owner normalization and registered safe projections. Selected bindings preserve constrained author specificity; finite interpolation preserves repeated-input correlation and fails closed on unsupported independent finite images. Regression coverage includes serialization, output tampering, backend admission and runtime enforcement. Schema publication hashes match. No concrete security issue was found in the reviewed diff.

    Verdict: ship

    Findings

    • (none)
  5. Brad-Edwards commented on Oct 11, 2026

    @Brad-Edwards
    CollaboratorAuthor

    gc_codex_review pre-push cycle 1 of 1 complete for issue #1481 on branch '1481-configurable-runtime-parameters'. Posted by the MCP server to enforce the pre-push hard-cap-1 contract (issues #796, #804, #906). Do not edit or delete — used by the next gc_codex_review (uncommitted) invocation to count cycles.

  6. Brad-Edwards commented on Oct 11, 2026

    @Brad-Edwards
    CollaboratorAuthor

    Review decision record — codex cycle 1 (issue #1481)

    Reviewer: codex
    Cycle: 1
    Verdict: ship

    Architectural read:

    Typed derivations extend the closed phase provenance carrier and reuse qualified namespace rewriting, owner normalization and registered safe projections. Selected bindings preserve constrained author specificity; finite interpolation preserves repeated-input correlation and fails closed on unsupported independent finite images. Regression coverage includes serialization, output tampering, backend admission and runtime enforcement. Schema publication hashes match. No concrete security issue was found in the reviewed diff.

    Blocking findings: 0 (clean run)

  7. Brad-Edwards commented on Oct 11, 2026

    @Brad-Edwards
    CollaboratorAuthor

    Pre-PR base synchronization

    • Source: refs/remotes/origin/dev at 35122105b0c1bb648754625d8e3920eafa9bc599
    • Outcome: already_current
    • Published feature head: 213bd9e38ac8d893a7cd458a7289f8f248ee55f5
    • Synchronized tree: e94aa417d940a7d75ba346fb226f70ca092c3dd7
  8. Brad-Edwards commented on Oct 11, 2026

    @Brad-Edwards
    CollaboratorAuthor

    Pre-PR base synchronization

    • Source: refs/remotes/origin/dev at 35122105b0c1bb648754625d8e3920eafa9bc599
    • Outcome: already_current
    • Published feature head: 1ad6d9d42db90d331d19c80218de404bb8c71c78
    • Synchronized tree: 9e90aee493d89ef15da94ae0a617f2df91d66fdd
  9. Brad-Edwards commented on Oct 11, 2026

    @Brad-Edwards
    CollaboratorAuthor

    Pre-PR base synchronization

    • Source: refs/remotes/origin/dev at 35122105b0c1bb648754625d8e3920eafa9bc599
    • Outcome: already_current
    • Published feature head: b8818a60b1d8de217ec409420851441cc13ef6e3
    • Synchronized tree: 1a753860123b0284fad86b7c209323a686e20781
  10. Brad-Edwards commented on Oct 11, 2026

    @Brad-Edwards
    CollaboratorAuthor

    Execution obligation ISSUE-1481-SONAR-SCANNER-ACCESS — Opened

    Category: failing_check
    Observed state: All current-head test, integration, compatibility, contract, policy, security, and bootstrap checks pass. The required sonar check fails: the scanner's JRE-metadata request to https://api.sonarcloud.io/analysis/jres?os=linux&arch=x86_64 returns HTTP 403 Forbidden before analysis.
    Impact: Required Sonar verification is unevaluable; readiness cannot be asserted.
    Current obligation: Restore scanner access, rerun Sonar for the current head, and verify its required status, quality gate, open issues, and hotspots before readiness.

    Evidence

  11. Brad-Edwards commented on Oct 11, 2026

    @Brad-Edwards
    CollaboratorAuthor

    Execution obligation ISSUE-1481-SONAR-SCANNER-ACCESS — Escalated

    Category: failing_check
    Observed state: All current-head test, integration, compatibility, contract, policy, security, and bootstrap checks pass. The required sonar check fails: the scanner's JRE-metadata request to https://api.sonarcloud.io/analysis/jres?os=linux&arch=x86_64 returns HTTP 403 Forbidden before analysis.
    Impact: Required Sonar verification is unevaluable; readiness cannot be asserted.
    Current obligation: Restore scanner access, rerun Sonar for the current head, and verify its required status, quality gate, open issues, and hotspots before readiness.

    Evidence

    Pause class: hard_external_dependency
    Decision request: Please check and repair GitHub Actions SONAR_TOKEN validity and scope, or the SonarCloud access restriction causing the confirmed JRE-metadata HTTP 403. Do not share credential values. Confirm restoration so the current-head scan can be rerun.

    This obligation remains open while the decision is pending.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingin-progressAn agent is actively working this issue via /implement

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions