Repository navigation
fix(planner): preserve configurable parameters in runtime collection authority #1481
Description
Activity
- added 4 commits that reference this issue
on Oct 10, 2026 - addedin-progressAn agent is actively working this issue via /implementAn agent is actively working this issue via /implement
on Oct 10, 2026 🛠️ Picked up by /implement - driver codex, branch
1481-configurable-runtime-parameters, 2026-10-10T23:58:46.983Z.gc workflow phase recorded:
plan(issue #1481). Posted by the MCP server to enforce ordering between workflow steps (issue #794 MVP-2). Do not edit or delete — used by downstream tools to gate phase prerequisites.Implement configurable runtime parameter authority through portable parameter-derivation evidence, retaining constrained author specificity and processor provenance.
- Path B: add failing regression tests for application paths, database names, gateway prefixes and mail domains, covering defaults, required inputs, additional selected strings, literals, finite controls and both interpolated mailbox addresses. Reuse the synthetic supporting manifest and recursive/runtime fixtures; verify unsupported backend/observation demands still fail.
- Path B: extend closed SDL phase provenance with typed parameter derivations represented as literal segments and qualified parameter references (no unresolved template strings). Reuse canonical substitution/equality, binding type/domain validation, namespace rewriting and concrete runtime-field validation. Preserve incumbent whole-field finite-domain permission. Unenumerated inputs carry explicitly selected binding authority, not an invented author domain; single-parameter finite interpolations retain their transformed finite image, including repeated tokens. Unsupported nonrepresentable images fail closed rather than enumerate Cartesian products.
- Path B: capture public runtime leaves through existing traversal. Classification-bearing records remain guarded; the mailbox owner explicitly identifies its public address surface, and lowering must still consume the registered safe projection. Protected alternatives, credentials, commitments and presence markers remain excluded. Compile selected bindings as processor-origin literal constraints while leaving authored specificity constrained; compile finite images through existing EnumDomain machinery. Preserve exact siblings, closure, member identities and canonical plan binding.
- Path B: exercise imported/nested parameter identities, serialized scenario and plan/schema admission, tampered bindings/outputs, safe-value non-leakage and actual runtime rejection of altered selected values. Update affected published phase/snapshot schemas and publication ledgers together with schema_bundle, plus fixtures where needed. Path D: clarify selected-binding versus finite-domain semantics in normative realization/phase documentation and implementer reference; retain the preflight note.
Security: parser, semantic and Pydantic validation remain authoritative; phase consistency validates each typed referenced binding and concrete output; registered projection controls publication; plan DTO/readmission, backend support, observation/corroboration and runtime result sanitization remain unchanged enforcement layers. No execution, auth/config shape, secret argv or storage mechanism is added.
Maintainability/extensibility: build on VariableType, ParameterBinding, VARIABLE_TOKEN_RE/canonical substitution, existing RFC6901/name rewriting and recursive authority; use typed derivation dispatch and owner-approved public fields, never per-kit exceptions or blanket string domains. Whole-repo scope includes composition, phase/snapshot schemas, schema publication, compiler, planner and portable runtime admission.Verification: use targeted pytest modules/cases and targeted repo-policy edit guards before/after changes; set RAES_REQUIREMENT_UID=SEM-218 for relevant local policy checks without adding it to this requirement-free issue. CI owns full suites. Preserve mandatory publish hook, bounded review, CI/Sonar and readiness gates. Do not edit release-owned versions/changelog. No new structural gate or formal requirement is introduced.
gc_codex_review — sanitized deferred publication for issue #1481, cycle 1 of 1
Reviewed revision:e3c19f7cf3c627494b7aa4fdb28c7e1b71478b070e2a32f9bcf09c5d53bfdd27Architectural read
Typed derivations extend the closed phase provenance carrier and reuse qualified namespace rewriting, owner normalization and registered safe projections. Selected bindings preserve constrained author specificity; finite interpolation preserves repeated-input correlation and fails closed on unsupported independent finite images. Regression coverage includes serialization, output tampering, backend admission and runtime enforcement. Schema publication hashes match. No concrete security issue was found in the reviewed diff.
Verdict:
shipFindings
- (none)
gc_codex_review pre-push cycle 1 of 1 complete for issue #1481 on branch '1481-configurable-runtime-parameters'. Posted by the MCP server to enforce the pre-push hard-cap-1 contract (issues #796, #804, #906). Do not edit or delete — used by the next
gc_codex_review(uncommitted) invocation to count cycles.Review decision record — codex cycle 1 (issue #1481)
Reviewer: codex
Cycle: 1
Verdict:shipArchitectural read:
Typed derivations extend the closed phase provenance carrier and reuse qualified namespace rewriting, owner normalization and registered safe projections. Selected bindings preserve constrained author specificity; finite interpolation preserves repeated-input correlation and fails closed on unsupported independent finite images. Regression coverage includes serialization, output tampering, backend admission and runtime enforcement. Schema publication hashes match. No concrete security issue was found in the reviewed diff.
Blocking findings: 0 (clean run)
Pre-PR base synchronization
- Source:
refs/remotes/origin/devat35122105b0c1bb648754625d8e3920eafa9bc599 - Outcome:
already_current - Published feature head:
213bd9e38ac8d893a7cd458a7289f8f248ee55f5 - Synchronized tree:
e94aa417d940a7d75ba346fb226f70ca092c3dd7
- Source:
Pre-PR base synchronization
- Source:
refs/remotes/origin/devat35122105b0c1bb648754625d8e3920eafa9bc599 - Outcome:
already_current - Published feature head:
1ad6d9d42db90d331d19c80218de404bb8c71c78 - Synchronized tree:
9e90aee493d89ef15da94ae0a617f2df91d66fdd
- Source:
Pre-PR base synchronization
- Source:
refs/remotes/origin/devat35122105b0c1bb648754625d8e3920eafa9bc599 - Outcome:
already_current - Published feature head:
b8818a60b1d8de217ec409420851441cc13ef6e3 - Synchronized tree:
1a753860123b0284fad86b7c209323a686e20781
- Source:
Execution obligation ISSUE-1481-SONAR-SCANNER-ACCESS — Opened
Category: failing_check
Observed state: All current-head test, integration, compatibility, contract, policy, security, and bootstrap checks pass. The required sonar check fails: the scanner's JRE-metadata request to https://api.sonarcloud.io/analysis/jres?os=linux&arch=x86_64 returns HTTP 403 Forbidden before analysis.
Impact: Required Sonar verification is unevaluable; readiness cannot be asserted.
Current obligation: Restore scanner access, rerun Sonar for the current head, and verify its required status, quality gate, open issues, and hotspots before readiness.Evidence
- https://github.com/OpenRAE/rae/actions/runs/38098786773/job/114353820521
- https://github.com/OpenRAE/rae/actions/runs/38098786773/job/114353869091
- PR head b8818a6; 285 targeted local tests passed.
Execution obligation ISSUE-1481-SONAR-SCANNER-ACCESS — Escalated
Category: failing_check
Observed state: All current-head test, integration, compatibility, contract, policy, security, and bootstrap checks pass. The required sonar check fails: the scanner's JRE-metadata request to https://api.sonarcloud.io/analysis/jres?os=linux&arch=x86_64 returns HTTP 403 Forbidden before analysis.
Impact: Required Sonar verification is unevaluable; readiness cannot be asserted.
Current obligation: Restore scanner access, rerun Sonar for the current head, and verify its required status, quality gate, open issues, and hotspots before readiness.Evidence
- https://github.com/OpenRAE/rae/actions/runs/38098786773/job/114353820521
- https://github.com/OpenRAE/rae/actions/runs/38098786773/job/114353869091
- PR head b8818a6; 285 targeted local tests passed.
Pause class: hard_external_dependency
Decision request: Please check and repair GitHub Actions SONAR_TOKEN validity and scope, or the SonarCloud access restriction causing the confirmed JRE-metadata HTTP 403. Do not share credential values. Confirm restoration so the current-head scan can be rerun.This obligation remains open while the decision is pending.
Problem
RAES 6.0.1 cannot plan configurable string parameters inside runtime collections unless the parameter has a finite
allowed_valueslist.This affects the application route path, database name, gateway route prefix, and mail domain in OpenRAE/env-packs#414. Restricting each parameter to its default and test variation makes planning possible, but removes normal author configuration.
The same mechanism remains on
devat35122105b0c1bb648754625d8e3920eafa9bc599.Cause
raes/explicitness.py::derive_instantiated_explicitnesspreserves substituted leaves as constrained. This also applies to an explicit author input with no default.raes/_capability_constraints.py::_finite_domain_constraintcaptures only whole-field parameter references with finiteallowed_values.raes_processor/compiler/realization_recursive_constraints.py::_SourceMetadata._constrained_domainrequires a captured domain. It cannot represent a typed configurable string leaf without that enumeration.realization.authority-bound-unavailable.The variable model has no general string-domain, pattern, or length constraint. Open realization scopes do not remove the failure.
Reproduction evidence
Environment: env-packs PR #433, head
1a551321c00fa36e0e50674639ad214929a4ef2d;raes==6.0.1.Compose each module through
parse_sdl_file, then usecompile_scenario_runtime_modelandraes_processor.planner.plan. Remove the newallowed_valuesfrom the domain parameter. Supply these concrete values:To isolate authority compilation from backend capability admission, use a test manifest with exact and constrained support for
runtime-applications,runtime-database-services, andruntime-mail-services, plus configuration observation capabilities with guest-observed strength. Use closed realization defaults and keep the kits' open compute-substrate constraint. These declarations are a planning test fixture; they make no backend execution claim.Mail has a related failure. With
mail_domainbounded toenvironment.testandalternate.test, useoperator@${mail_domain}andservice@${mail_domain}for mailbox addresses. Instantiation produces the correct addresses. Planning still reportsauthority-bound-unavailable. Embedded interpolation does not retain a derived bound. The mailbox model also has a credential-classification field, so safe bound capture must use its owning projection rather than bypass classification guards.Expected behavior
Acceptance criteria
Related