You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The task user replied “i approve” to the explicit request for decision OFARM-ISSUE36-GOVERNED-READ-TRANSACTION-COVERAGE-DISCLOSURE-001, version 2, at 41cd45b90fb8e133f6377d8f389858b89c3dd7ae. The approval record names the exact scope and limits. Re-review 5196618462 resolves B1 at the protocol-design level and requests no further corrective patch.
The reviewed candidate and head are unchanged. Its embedded proposed/pending wording and the earlier records below are publication history; this external record supplies the later approval. Version 1 was not approved. Primary trust boundary: governed-read transaction integrity and protected disclosure. Scope stayed inside approval/publication navigation; no candidate, runtime, schema, database/source authority or adjacent-owner semantic change was made.
The actual source-backed guarantee remains unproven: RD-BIND03-W and RD-BIND01–07 remain open, as do HSP/QG/CP2A dependencies and OFARM2 G2/G3/G4. No writer is activated or proved deferrable. The complete two-action/full-rule scope, criteria/cases and eleven delivery stages remain unchanged. PR #37 stays open/draft/unmerged; this approval does not authorize later materialization, acceptance, promotion, extraction, implementation, merge or deployment. No new package, runtime, concurrency, durability, delivery or privacy test ran in this approval-recording turn.
What is next: prepare the bounded next-stage binding plan against the approved owner designs, including the actual source/transaction/egress mapping and RD-BIND03-W. Obtain separate authorization before materialization or implementation; preserve OFARM2 #353 / PR #359 → #178 → bounded #176.
Review 5194803845 found one blocker at the original head c2c52fa27bec24e72285564057cab198e4654e36: late hidden history could suppress an otherwise permitted sealed WITHHELD reply, revealing a difference through result omission. The user's next “go” authorized the bounded correction.
PR #37 now proposes version 2 of OFARM-ISSUE36-GOVERNED-READ-TRANSACTION-COVERAGE-DISCLOSURE-001 at 41cd45b90fb8e133f6377d8f389858b89c3dd7ae. The response to B1 requests exact-head re-review; it does not claim blocker closure or approval.
The revision selects the review's explicit-guarantee option: every permitted WITHHELD limited historical reply requires source-backed protection before its final observation and through C/L, ordering a competing qualifier's commit before that cut or after disclosure/irrevocable termination. Optimistic conflict suppression, delayed notifications, empty-history shortcuts and hidden-contention-only admission failures are not privacy proofs. Policy-selected exclusion stays uniform; disclosable history retains refresh/suppression. New I13/C20/C21 combine both C38 policy paths with late candidates, unresolved admission and actual commit-order checks.
The required RD-BIND03-W sealing sub-obligation remains open within RD-BIND03. No existing provider is certified. If supplying the guarantee needs new source/storage authority or an approved owner semantic change, that must be separately reviewed; PR #31/#35 and all other approved candidates remain unchanged.
The correction changes only the existing candidate file: 96 insertions, 35 deletions; total 525 lines, ten criteria, thirteen invariants and twenty-one symbolic cases. Four static repository checks, exact source pins, structure/traceability/whitespace, seven unaffected-section comparisons and exact remote text read-back passed. No runtime, concurrency, durability, delivery or privacy tests ran.
Primary trust boundary: governed-read transaction integrity and protected disclosure. Scope stayed inside this correction, publication and local navigation. The issue's criteria/case requirements, two-action/full-rule scope and all eleven stages are unchanged. All RD/HSP/QG/CP2A and G2/G3/G4 gates remain open; no merge, implementation, writer activation or proven writer deferral follows.
What is next: exact-head re-review of version 2, particularly the sealing guarantee and combined cases, then explicit semantic direction.
Original Phase A handoff — 2026-09-14 (historical)
The amended issue received re-review 5659896617, with no blocking findings in the issue framing. The user then authorized drafting with “no blockers, go.” That review and direction do not approve the newly written protocol.
PR #37 adds only package_meta/history/clean_baseline_migration/phase_reports/governed_read_transaction_coverage_and_disclosure_protocol_rfc_candidate_v0_1.md, from canonical main 71ca724a8b6ec23f1655b086a6f549496d10a47f. Its exact head is c2c52fa27bec24e72285564057cab198e4654e36; the published file was read back and matched the committed local text exactly. It is open, draft and unmerged.
Proposed decision: OFARM-ISSUE36-GOVERNED-READ-TRANSACTION-COVERAGE-DISCLOSURE-001, version 1, not approved. The proposal covers complete direct/query and direct/delegated/sharing coverage; a positive artifact-content example without independent raw-origin access; genuine pre-evaluation qualification; one governed observation; atomic prepared evidence before a guarded disclosure handoff; separately truthful outcome evidence; crash/uncertain-commit/no-protected-replay behavior; history refresh; privacy; and retention stops. Ten issue criteria map to twelve invariants and nineteen symbolic cases.
All seven source PRs and both main refs matched the recorded pins. Repository hygiene, generated-currentness, cross-reference and steward-guardrail checks passed, alongside structure/traceability/whitespace and one-file diff checks. These are static document checks, not independent protocol review or executed database, concurrency, delivery, privacy or runtime conformance.
Primary trust boundary: governed-read transaction integrity and protected disclosure. Scope stayed inside that one-file proposal, its publication and local navigation. Approved adjacent candidate bytes and the dirty primary OFARM2 checkout were preserved. The two-action/full-rule scope and all eleven stages remain unchanged. RD-BIND01–07, HSP/QG/CP2A obligations and G2/G3/G4 remain open; no qualifying writer is activated or proved deferrable.
The criteria and case requirements below are unchanged. What is next: exact-head review of PR #37, then explicit semantic approval or a bounded revision. Do not start materialization or runtime work from draft publication alone.
This bounded issue-body amendment follows review 5655860343 and second review 5656026666, both of the original 19,215-character issue body. It responds to the second review's reported Blocker 1, Follow-ups 2–5 and Preference 6, and preserves the first review's unresolved-candidate refresh clarification. Those reviews do not review this amended body.
The changes make direct/delegated/SharingGrant coverage, direct-versus-query inputs, pre-disclosure retention stops, read-versus-transport ordering, truthful persistence failures, current source-pin compatibility and safe preflight behavior explicit. The sharing-coverage clause requires a source-backed explanation and a positive path; it does not decide that an artifact grant creates new access rights to underlying records, or establish that sharing-based reads are impossible. A needed new permission rule must return to its separate authorization owner.
Primary trust boundary and selected scope are unchanged. All seven source pins, approved candidate bytes, owner fences and binding/implementation gates remain unchanged. This is an issue clarification, not protocol semantic approval, closure of the reported finding by its reviewer, or permission to start materialization/runtime work.
Outcome and primary trust boundary
Define the complete owner protocol for the selected RECEIVE_READ_DATA action: one protected read connects authorization, retrieval, redaction, qualification, result coverage and exact buffered bytes to durable evidence before disclosure.
Primary trust boundary: governed-read transaction integrity and protected disclosure. This is a canonical contract prerequisite, not an OFARM2 implementation issue or another history-classifier design.
The selected release remains exactly ASSERT_OPERATION_CLAIM and RECEIVE_READ_DATA, with both complete unchanged rules and every required transitive dependency. This issue covers the read owner's protocol for all selected read targets and authority paths, including a separately authorized AUTHORIZATION_TRACE read. It does not narrow reads to operation-claim records, add a third action, activate qualifying-record authoring or change the twenty-action catalogue.
Why this work is already required
Approved PR #11 section 18.5 requires one governed snapshot, full result coverage and atomic decision/consumption/receipt/payload evidence before the single disclosure linearization point. Section 24 and #21 require a separately governed read protocol. PR #26 section 7.1 excludes RECEIVE_READ_DATA from its NOT_REQUIRED state-effect protocol; the human-finalization protocol in PR #20 does not fill this gap either.
PR #35's approved history producer consumes the actual source/governed-read/transaction owners' observation and reply guarantees under HSP-BIND03. Its approval supplies neither those bindings nor the missing read protocol. The original refusal, qualifying-record lifecycle, six-label history fold and PR #31 public rules remain unchanged.
The pinned OFARM2 implementation provides useful tenant binding and write-order primitives, but not this read contract:
The production UoW starts READ COMMITTED and supplies write-batch and command-selection facilities, not a complete governed-read attempt/observation/coverage/release interface.
The knowledge-position allocator requires READ COMMITTED and serializes tenant write-batch positions. That alone does not prove membership or exhaustive visibility across every eligible historical source.
Existing record reads are tenant-scoped and deliberately not limited to the current bundle, but are not already a v0.2 historical-admission/complete-observation provider.
Production governed routes remain blocked. This is an unfinished capability, not a demonstrated defect in an enabled reader.
These findings do not choose a new isolation level, lock, transaction owner, reader permission, storage mechanism or history service. A different database mode or nominal snapshot label cannot stand in for a reviewed owner guarantee.
Exact source anchors
Rechecked at issue creation on 2026-09-13. Canonical main is 71ca724a8b6ec23f1655b086a6f549496d10a47f. All seven canonical PRs below remain open, draft and unmerged. Semantic approval does not make a candidate active law.
OFARM2 main is 9d7541d96bc708e9270b986927d7f4b8a035454f. Its PR #359 remains open/draft at 7de8a2c4cf6eb1f293560af67e69565122c42f25, with G2/G3/G4 open. Read canonical baseline/accepted authority first; these candidate pins do not override it.
Intended first PR
One non-authoritative Phase A document on a separate branch from canonical main:
This is a proposed future path, not an existing contract. Do not append the work to PR #35, #26, #11 or OFARM2 #359. Reference their exact sources without copying or editing their approved candidates.
The candidate must choose the smallest coherent protocol and state its trust model, authority map, attempt/state ordering, stable invariants, production-reachable negative cases, compatibility/dependency ledger and later binding ownership. It is not a provisional permission to ship a reduced reader. Exact-head review and explicit semantic approval precede later materialization or implementation.
Acceptance criteria
Trusted read attempt. Define the owner-issued tenant/principal/session-bound attempt, transaction identity, trusted time/deadline, independently selected policy and required validity/guard inputs. Reject forged, mixed or caller-selected authoritative frames. Consume existing identity and selection authorities; no new authentication or selector power is granted.
One protected observation. Specify how authorization facts, immutable origin revisions, query/plan, redaction, CP2 qualification, relevant history, result coverage and payload construction share the governed snapshot. Define the currentness/guard obligations and their validity through the owner-defined release boundary. Identify exact source/external guarantees still owed; a SQL isolation name, cache, context-basis object or nominal watermark is not the proof.
Real qualification evidence before evaluation. Identify the rule-selected CP2 read-qualification policy and the source/producer/order by which its required evidence is available to authorization in the same context. Preserve #359 F4: the exact policy may derive required references from effectIntentDigest; do not create an extra carrier merely to populate a provisional frame. Derived references still require genuine eligible evidence. Do not confuse rule-bound pre-evaluation evidence with the public-result projection or invent a dependency cycle.
Complete result coverage. Bind every returned row, field, aggregate, count, metadata item, lineage item and payload location to its immutable origins and authority/redaction disposition, including tenant, purpose and sovereignty. Establish coverage under one independently sufficient selected access basis for the exact read target: a direct or delegated RECEIVE_USE AuthorityGrant/DelegationGrant path, or a sufficient SharingGrant, under PR RFC candidate: executable authorization evidence v0.2 #11 sections 5.4/13. Do not combine incomplete authority, purpose or evidence coverage across access bases or use the resource-control layer to supply missing authority. For a shared aggregate artifact revision, explain from the governing contracts which returned constituent/origin information the selected artifact-scoped basis covers, and which information must be withheld, redacted or denied. Origin provenance alone is not authority. Do not assume that permission to read an artifact creates independent access rights to every underlying record, or that all shared-artifact reads must therefore fail. If resolving coverage requires a new or widened permission rule, stop for a separately reviewed authorization-owner decision; this read protocol cannot create that rule. Bind the exact immutable RP_READ_TARGET_ONE target and applicable policy, serializer identifier/version/digest, media type and buffered-payload digest. Preserve both read forms: direct-read form requires neither QUERY_SPECIFICATION nor QUERY_PLAN; query form requires both, exactly one each, as integrity inputs, with their exact revisions and query/plan digest bound where applicable. Apply approved withholding/redaction or deny an incompletely coverable payload. Protected streaming is unsupported. Preflight/dry-run may return only non-protected planning or qualification information and must never disclose protected bytes.
Atomic evidence before release. Define the exact success set, state/order and owner of the single disclosure linearization point. Decision evidence, one single-use consumption, governed-read receipt, coverage manifest, payload digest and required retained payload ref/bytes must persist atomically before protected release. Provide an evidence-ownership table naming each profile's semantic owner, proposed package, truth claim, success-set placement and failure/retry posture. Prefer the already proposed AuthorizationDecisionEvidence/AuthorizationFinalizationEvidence v0.2 families; no new top-level evidence family is presumed.
Failure, uncertainty and retry. Define cancellation, deadline/guard invalidation, failure before/after persistence, commit acknowledgement loss, partial success evidence, crash/disconnect around disclosure, and retry/reconciliation. The read row selects NO_EXTERNAL_DISPATCH: “release” in this issue means the buffered-read disclosure boundary in PR RFC candidate: executable authorization evidence v0.2 #11 section 18.5, not section 18.6's filing transport-release gate under Define transport-release eligibility after filing outbox commitment #13. Distinguish committed evidence, eligibility for that read disclosure, attempted disclosure and provable delivery; a server receipt does not prove human/network receipt. No protected bytes on pre-disclosure failure, no duplicate consumption, no reuse of an old decision as new disclosure authority and no invented complete-success claim. Place READ_EVIDENCE_PERSISTENCE_FAILED and the applicable decision-bundle persistence/projection failures in their runtime/integrity-gate dispositions: they are not authorization outcomes, have no authorization reason rank, and must not fabricate or rewrite the authorization result as DENY. Adopt PR RFC candidate: governed human-finalization transaction protocol #20/Define the NOT_REQUIRED transaction and consumption protocol v0.1 #26 concepts only through explicit compatibility analysis; their write outcomes and retry rules are not automatically read semantics.
History and reply validity. Bind PR Define authorization-evidence source-history qualification (Phase A) #35's authoritative observation to historical RECORDED_RESULT reads in that same read context. Preserve complete candidate enumeration, original historical-admission verification, and established/proved-invalid/unresolved distinctions. Carry forward PR Define authorization-evidence source-history qualification (Phase A) #35 section 6's exact trigger: learning of a potentially material committed candidate after the observation cut but before reply finalization requires a new complete owner-governed observation and whole-read rebuild/revalidation, or the permitted unavailable/withheld path, even when that candidate's admission or classification is unresolved. Do not wait for a confirmed changed history label. Never splice refreshed history into an old governed-read payload. If payload/evidence is already finalized, the classifier cannot rewrite it or add an explanation commit; the owner must suppress/restart disclosure or use its permitted failure path. This creates neither a new retry permission nor a lock through network delivery. Separate the fresh-refusal command/reply path: this read protocol alone does not close that owner's HSP-BIND03 obligations or prove NONE at a fresh refusal's later reply.
Unchanged privacy and retention owners. Preserve PR Define CP2 authorization-result qualification and public reasons (Phase A) #31's WITHHELD precedence, null rules, safe messages, protected-detail limits and hidden-history-independent fallbacks, including C38. A missing/unadmitted producer is a readiness failure, distinct from an admitted producer's temporary inability to establish history. Apply the trusted immutable retention policy and preserve RETAINED_BYTES versus DIGEST_ONLY without caller weakening or overclaiming reconstruction. Before disclosure, the read cannot proceed if no applicable policy resolves at its governed snapshot, if a DIGEST_ONLY policy forbids the transient buffer processing needed to hash and execute the read, or if compatible minimization cannot preserve required immutable receipt/coverage/decision/trace evidence without prohibited retention. Release zero protected bytes; record truthful failure under criterion 6 and report any policy conflict to Define authorization evidence retention and proof-strength postures #14/PR RFC: authorization evidence retention and proof strength (Phase A) #29, without inventing a weaker posture or unobservable payload. A receipt, digest or history proof never grants trace access. Retention duration, encryption, deletion/redaction and custody policy remain owned by Define authorization evidence retention and proof-strength postures #14/PR RFC: authorization evidence retention and proof strength (Phase A) #29.
Falsifiable positive and hostile cases. Map each criterion to named invariants and case specifications, including the cases below. Show a satisfiable positive protocol for all selected read targets/paths, not a permanently unavailable service. Distinguish Phase A reasoning, schema/semantic fixtures and later production-path, concurrency/privacy and durability tests. No fixture is reported as executed evidence merely because it appears in the document.
Real bindings and staged completion. Name later non-default protocol/evidence profiles, source/attempt/observation bindings, producer-consumer interfaces, fixtures, conformance manifest/checker and accountable owners. Bind real reviewed bytes/digests at the authorized stage; no placeholder provider or self-asserted proof closes a dependency. The compatibility/dependency ledger must explicitly distinguish PR RFC candidate: executable authorization evidence v0.2 #11 section 24.1's historical description of PR RFC candidate: authorization-evidence qualifying-record governance #34 at 69682c2f918ef18756261a1186294cc3a5ebe44d as unapproved from this issue's current PR RFC candidate: authorization-evidence qualifying-record governance #34 input at c59fdbc75f26ee4694355adedd4df021f64b5131, with version-2 approval in comment 5654388700. Identify which head each consumed statement rests on, assess the dependency update, and preserve PR RFC candidate: executable authorization evidence v0.2 #11's approved bytes; do not inherit its old approval-state wording as the status of the newer input or mistake that input's approval for source-binding closure. Record every missing source/storage/access/transaction guarantee and split any separate owner change before editing it. Follow all eleven stages of PR RFC candidate: executable authorization evidence v0.2 #11 section 24 and Promote executable authorization constraints and decision evidence RFC v0.2 #21; semantic approval alone closes no materialization, admission, currentness, extraction or runtime gate.
Required cases
These are design and later conformance obligations, not approved protocol choices or executed tests.
Case
Required distinction
Eligible direct read, including separately authorized AUTHORIZATION_TRACE, without query specification/plan
The exact immutable read target, full same-context coverage and buffered evidence support lawful disclosure; query inputs are not required, and the trace target has its own decision and disclosure checks
Eligible query-form read over the exact RP_READ_TARGET_ONE target
Exactly one QUERY_SPECIFICATION and one QUERY_PLAN are bound as integrity inputs, not extra authority targets; every returned item and contributing origin has the required coverage
SharingGrant read of an exact shared aggregate artifact revision, such as EVIDENCE_BUNDLE, DOSSIER_ASSEMBLY or PASSPORT_VIEW
Show a satisfiable positive payload under an independently sufficient SharingGrant and the cited owner coverage rules for returned constituent information. Uncovered information is withheld/redacted or denied; no cross-basis union, ungranted independent origin-record access or silent blanket refusal of this basis
Delegated RECEIVE_USE path versus direct path for the same read target, including attempted combination of incomplete paths or a SharingGrant
Each sufficient path works independently in one final policy decision and trace under PR #11 section 13. An insufficient path cannot borrow action, purpose or evidence coverage from another path or the resource-control layer
Historical refusal with complete empty history
NONE requires an actual complete, reply-valid observation
Older valid qualifier while today's package excludes new qualifying writes
Verify original admission without granting current writing; complete historical source coverage is still required
Mixed snapshots, missing page/partition, hidden qualifying row, stale index or unresolved candidate identity
No fabricated complete observation or clean-history status
Newly learned potentially material committed candidate after the cut and before reply finalization, including unresolved historical admission or classification
New complete observation and whole-read rebuild/revalidation, or permitted unavailable/withheld handling; do not wait for a confirmed label change, splice history into an old payload, or rewrite already-finalized evidence
Authority or relevant guard invalidates before release, or a cutoff is reached
No stale release; define truthful attempt/evidence consequences
Uncovered aggregate, count, field, metadata or lineage item
No leak through payload, cache, denial body, preflight, trace or retry
Forged/mixed attempt, caller-selected policy, fabricated proof or missing real qualification input
No successful authoritative frame, evidence or release claim
Read-evidence persistence failure, uncertain commit or partial success set
Zero protected bytes on pre-disclosure failure; READ_EVIDENCE_PERSISTENCE_FAILED is a runtime failure, not an authorization outcome or ranked reason. Preserve the authorization result and explicit uncertainty/reconciliation; no guessed success, delivery or replay
Crash or disconnect immediately before/after the release boundary, followed by retry
No duplicate consumption or inferred delivery; later disclosure needs its governed authorization
No resolvable retention policy, or DIGEST_ONLY whose necessary transient processing or required immutable receipt/coverage/decision/trace retention is forbidden
The read is ineligible before disclosure; zero protected bytes. Record truthful failure and report a policy conflict to #14/PR #29 without weakening the posture
RETAINED_BYTES versus DIGEST_ONLY; required evidence later unavailable
Selected retention/proof limits remain truthful, without access or reconstruction being invented
Public fallback/disclosure behavior preserves the approved privacy rule
Scope fences and owner stops
This protocol may define the read transaction's own semantics for review. It may not quietly amend another owner's authority to make those semantics executable.
Authorization/evaluator owner: no change to selected rules, outcomes, targets, evidence eligibility or authority paths; no second evaluator.
Source and history owners: no new qualifier kind, writer admission, lifecycle transition, classification rule or persistent status truth. QG-DEP01 and historical writer-deferral proof remain open.
Public owner: no new public reason codes, envelope fields, endpoint activation, weaker withholding or trace disclosure.
Storage, identity, selection and custody owners: no database roles/migrations, isolation/locking implementation, source-access grants, hidden truth store, new signing authority, authentication/session policy, audit changes or key/deletion controls.
Governance/runtime owners: no accepted-law edit, schema materialization, current/default promotion, extraction, deployment, runtime factory or merge.
If a workable read protocol needs a new guarantee from one of those owners, name the exact gap and propose a separate prerequisite or stacked/follow-up PR before changing that boundary. Do not create speculative services or treat a broad “go” as a cross-boundary exception.
Delivery and honest completion
Review this issue's bounded scope, then prepare the one-file Phase A when authorized.
Obtain exact-head review and explicit semantic approval of the read protocol; do not modify approved adjacent candidates merely to record progress.
Complete required adjacent owner contracts and the separately authorized policy-bundle, source-bundle and bounded decision/finalization-evidence drafts with real bindings, in PR RFC candidate: executable authorization evidence v0.2 #11's order.
Complete exact binding/selected-closure review and scoped accepted law, hostile conformance, explicit scoped promotion and byte-identical OFARM2 extraction.
Undertake separately authorized runtime work. Actual live-provider, concurrency and disclosure evidence belongs at that stage; do not make runtime execution a prerequisite to its own canonical acceptance or claim static fixtures prove production behavior.
This issue records the missing read owner; it does not create a binding or close CP2A-DEP01. Completion requires the applicable governed contract, exact source/observation/producer/consumer bindings and evidence at the appropriate stage. HSP-BIND01–04, applicable QG dependencies, #21 and OFARM2 G2/G3/G4 remain open until their own obligations are met. New qualifying-record authoring is neither activated nor proved deferrable.
The implementation destination remains OFARM2 #353 / PR #359, then #178, then the bounded #176 child. Indispensable read/write input producers must precede their consumers; this capability order cannot justify fake frames or an unresolved dependency cycle.
Verification and limits
At issue creation, checked canonical open/closed issue inventory for a duplicate and refreshed the exact owner heads and OFARM2 #359. The existing local binding investigation used immutable OFARM2 main objects and preserved its dirty primary checkout. No canonical/runtime file, approved candidate, branch/worktree, schema, permission, merge, promotion or deployment is changed by this issue.
The future Phase A must check exact source pins, compatibility/ownership, criterion-to-invariant-to-case traceability, Markdown structure and whitespace. Cheap package checks show document/repository hygiene only; they do not prove snapshot completeness, atomic durability, privacy or production readiness. No package, database, concurrency or hosted runtime test was run to create this issue.
Scope stayed within recording the governed-read transaction integrity and protected disclosure prerequisite.
What is next: re-review PR #37 at 41cd45b90fb8e133f6377d8f389858b89c3dd7ae, proposed decision version 2, then record explicit Phase A semantic direction. Keep approved PR #35 and the other owner candidates unchanged, with all actual binding and implementation gates open.
Parent: #10.
Required by: #21, required predecessor 5; #32 / PR #35, HSP-BIND03 for historical governed reads; and OFARM2 #353 / PR #359, G2/G3-READ/G3-HANDOFF.
Status: draft PR #37, head
41cd45b90fb8e133f6377d8f389858b89c3dd7ae, now has the task user's Phase A semantic approval for decision version 2, after the no-blocker exact-head re-review. This issue remains open; no actual binding, accepted law, schema, promotion or implementation gate is closed.Current Phase A approval — 2026-09-14
The task user replied “i approve” to the explicit request for decision
OFARM-ISSUE36-GOVERNED-READ-TRANSACTION-COVERAGE-DISCLOSURE-001, version 2, at41cd45b90fb8e133f6377d8f389858b89c3dd7ae. The approval record names the exact scope and limits. Re-review 5196618462 resolves B1 at the protocol-design level and requests no further corrective patch.The reviewed candidate and head are unchanged. Its embedded proposed/pending wording and the earlier records below are publication history; this external record supplies the later approval. Version 1 was not approved. Primary trust boundary: governed-read transaction integrity and protected disclosure. Scope stayed inside approval/publication navigation; no candidate, runtime, schema, database/source authority or adjacent-owner semantic change was made.
The actual source-backed guarantee remains unproven: RD-BIND03-W and RD-BIND01–07 remain open, as do HSP/QG/CP2A dependencies and OFARM2 G2/G3/G4. No writer is activated or proved deferrable. The complete two-action/full-rule scope, criteria/cases and eleven delivery stages remain unchanged. PR #37 stays open/draft/unmerged; this approval does not authorize later materialization, acceptance, promotion, extraction, implementation, merge or deployment. No new package, runtime, concurrency, durability, delivery or privacy test ran in this approval-recording turn.
What is next: prepare the bounded next-stage binding plan against the approved owner designs, including the actual source/transaction/egress mapping and RD-BIND03-W. Obtain separate authorization before materialization or implementation; preserve OFARM2 #353 / PR #359 → #178 → bounded #176.
B1 correction — 2026-09-14 (historical preparation)
Review 5194803845 found one blocker at the original head
c2c52fa27bec24e72285564057cab198e4654e36: late hidden history could suppress an otherwise permitted sealed WITHHELD reply, revealing a difference through result omission. The user's next “go” authorized the bounded correction.PR #37 now proposes version 2 of
OFARM-ISSUE36-GOVERNED-READ-TRANSACTION-COVERAGE-DISCLOSURE-001at41cd45b90fb8e133f6377d8f389858b89c3dd7ae. The response to B1 requests exact-head re-review; it does not claim blocker closure or approval.The revision selects the review's explicit-guarantee option: every permitted WITHHELD limited historical reply requires source-backed protection before its final observation and through C/L, ordering a competing qualifier's commit before that cut or after disclosure/irrevocable termination. Optimistic conflict suppression, delayed notifications, empty-history shortcuts and hidden-contention-only admission failures are not privacy proofs. Policy-selected exclusion stays uniform; disclosable history retains refresh/suppression. New I13/C20/C21 combine both C38 policy paths with late candidates, unresolved admission and actual commit-order checks.
The required RD-BIND03-W sealing sub-obligation remains open within RD-BIND03. No existing provider is certified. If supplying the guarantee needs new source/storage authority or an approved owner semantic change, that must be separately reviewed; PR #31/#35 and all other approved candidates remain unchanged.
The correction changes only the existing candidate file: 96 insertions, 35 deletions; total 525 lines, ten criteria, thirteen invariants and twenty-one symbolic cases. Four static repository checks, exact source pins, structure/traceability/whitespace, seven unaffected-section comparisons and exact remote text read-back passed. No runtime, concurrency, durability, delivery or privacy tests ran.
Primary trust boundary: governed-read transaction integrity and protected disclosure. Scope stayed inside this correction, publication and local navigation. The issue's criteria/case requirements, two-action/full-rule scope and all eleven stages are unchanged. All RD/HSP/QG/CP2A and G2/G3/G4 gates remain open; no merge, implementation, writer activation or proven writer deferral follows.
What is next: exact-head re-review of version 2, particularly the sealing guarantee and combined cases, then explicit semantic direction.
Original Phase A handoff — 2026-09-14 (historical)
The amended issue received re-review 5659896617, with no blocking findings in the issue framing. The user then authorized drafting with “no blockers, go.” That review and direction do not approve the newly written protocol.
PR #37 adds only
package_meta/history/clean_baseline_migration/phase_reports/governed_read_transaction_coverage_and_disclosure_protocol_rfc_candidate_v0_1.md, from canonical main71ca724a8b6ec23f1655b086a6f549496d10a47f. Its exact head isc2c52fa27bec24e72285564057cab198e4654e36; the published file was read back and matched the committed local text exactly. It is open, draft and unmerged.Proposed decision:
OFARM-ISSUE36-GOVERNED-READ-TRANSACTION-COVERAGE-DISCLOSURE-001, version 1, not approved. The proposal covers complete direct/query and direct/delegated/sharing coverage; a positive artifact-content example without independent raw-origin access; genuine pre-evaluation qualification; one governed observation; atomic prepared evidence before a guarded disclosure handoff; separately truthful outcome evidence; crash/uncertain-commit/no-protected-replay behavior; history refresh; privacy; and retention stops. Ten issue criteria map to twelve invariants and nineteen symbolic cases.All seven source PRs and both main refs matched the recorded pins. Repository hygiene, generated-currentness, cross-reference and steward-guardrail checks passed, alongside structure/traceability/whitespace and one-file diff checks. These are static document checks, not independent protocol review or executed database, concurrency, delivery, privacy or runtime conformance.
Primary trust boundary: governed-read transaction integrity and protected disclosure. Scope stayed inside that one-file proposal, its publication and local navigation. Approved adjacent candidate bytes and the dirty primary OFARM2 checkout were preserved. The two-action/full-rule scope and all eleven stages remain unchanged. RD-BIND01–07, HSP/QG/CP2A obligations and G2/G3/G4 remain open; no qualifying writer is activated or proved deferrable.
The criteria and case requirements below are unchanged. What is next: exact-head review of PR #37, then explicit semantic approval or a bounded revision. Do not start materialization or runtime work from draft publication alone.
Review-driven clarification — 2026-09-13 (historical)
This bounded issue-body amendment follows review 5655860343 and second review 5656026666, both of the original 19,215-character issue body. It responds to the second review's reported Blocker 1, Follow-ups 2–5 and Preference 6, and preserves the first review's unresolved-candidate refresh clarification. Those reviews do not review this amended body.
The changes make direct/delegated/SharingGrant coverage, direct-versus-query inputs, pre-disclosure retention stops, read-versus-transport ordering, truthful persistence failures, current source-pin compatibility and safe preflight behavior explicit. The sharing-coverage clause requires a source-backed explanation and a positive path; it does not decide that an artifact grant creates new access rights to underlying records, or establish that sharing-based reads are impossible. A needed new permission rule must return to its separate authorization owner.
Primary trust boundary and selected scope are unchanged. All seven source pins, approved candidate bytes, owner fences and binding/implementation gates remain unchanged. This is an issue clarification, not protocol semantic approval, closure of the reported finding by its reviewer, or permission to start materialization/runtime work.
Outcome and primary trust boundary
Define the complete owner protocol for the selected
RECEIVE_READ_DATAaction: one protected read connects authorization, retrieval, redaction, qualification, result coverage and exact buffered bytes to durable evidence before disclosure.Primary trust boundary: governed-read transaction integrity and protected disclosure. This is a canonical contract prerequisite, not an OFARM2 implementation issue or another history-classifier design.
The selected release remains exactly
ASSERT_OPERATION_CLAIMandRECEIVE_READ_DATA, with both complete unchanged rules and every required transitive dependency. This issue covers the read owner's protocol for all selected read targets and authority paths, including a separately authorizedAUTHORIZATION_TRACEread. It does not narrow reads to operation-claim records, add a third action, activate qualifying-record authoring or change the twenty-action catalogue.Why this work is already required
Approved PR #11 section 18.5 requires one governed snapshot, full result coverage and atomic decision/consumption/receipt/payload evidence before the single disclosure linearization point. Section 24 and #21 require a separately governed read protocol. PR #26 section 7.1 excludes RECEIVE_READ_DATA from its NOT_REQUIRED state-effect protocol; the human-finalization protocol in PR #20 does not fill this gap either.
PR #35's approved history producer consumes the actual source/governed-read/transaction owners' observation and reply guarantees under HSP-BIND03. Its approval supplies neither those bindings nor the missing read protocol. The original refusal, qualifying-record lifecycle, six-label history fold and PR #31 public rules remain unchanged.
The pinned OFARM2 implementation provides useful tenant binding and write-order primitives, but not this read contract:
These findings do not choose a new isolation level, lock, transaction owner, reader permission, storage mechanism or history service. A different database mode or nominal snapshot label cannot stand in for a reviewed owner guarantee.
Exact source anchors
Rechecked at issue creation on 2026-09-13. Canonical main is
71ca724a8b6ec23f1655b086a6f549496d10a47f. All seven canonical PRs below remain open, draft and unmerged. Semantic approval does not make a candidate active law.4494924998183fe3fa7bc1b63b76a8589333504498f8c4fafbae42c8f7fd931f43f53adcb4733713e042efa2911b2ef0a61603b8e0adaa6911c03ac08e0994cae5610ac9c0d2652e02c8a8a2dd7b45c5092be94f3a67497ba619295932cd0b2b1e9443f3c59fdbc75f26ee4694355adedd4df021f64b5131b9ccdc96c5b3961eb672290cd32019364b56f8e6PR #11's renewed scope has exact-head approval. PR #34 version 2 has exact-head approval. PR #35 version 1 has exact-head approval, following no-blocker review 5191762787. Preserve reviewed bytes and their historical publication labels.
OFARM2 main is
9d7541d96bc708e9270b986927d7f4b8a035454f. Its PR #359 remains open/draft at7de8a2c4cf6eb1f293560af67e69565122c42f25, with G2/G3/G4 open. Read canonical baseline/accepted authority first; these candidate pins do not override it.Intended first PR
One non-authoritative Phase A document on a separate branch from canonical main:
package_meta/history/clean_baseline_migration/phase_reports/governed_read_transaction_coverage_and_disclosure_protocol_rfc_candidate_v0_1.mdThis is a proposed future path, not an existing contract. Do not append the work to PR #35, #26, #11 or OFARM2 #359. Reference their exact sources without copying or editing their approved candidates.
The candidate must choose the smallest coherent protocol and state its trust model, authority map, attempt/state ordering, stable invariants, production-reachable negative cases, compatibility/dependency ledger and later binding ownership. It is not a provisional permission to ship a reduced reader. Exact-head review and explicit semantic approval precede later materialization or implementation.
Acceptance criteria
Trusted read attempt. Define the owner-issued tenant/principal/session-bound attempt, transaction identity, trusted time/deadline, independently selected policy and required validity/guard inputs. Reject forged, mixed or caller-selected authoritative frames. Consume existing identity and selection authorities; no new authentication or selector power is granted.
One protected observation. Specify how authorization facts, immutable origin revisions, query/plan, redaction, CP2 qualification, relevant history, result coverage and payload construction share the governed snapshot. Define the currentness/guard obligations and their validity through the owner-defined release boundary. Identify exact source/external guarantees still owed; a SQL isolation name, cache, context-basis object or nominal watermark is not the proof.
Real qualification evidence before evaluation. Identify the rule-selected CP2 read-qualification policy and the source/producer/order by which its required evidence is available to authorization in the same context. Preserve #359 F4: the exact policy may derive required references from effectIntentDigest; do not create an extra carrier merely to populate a provisional frame. Derived references still require genuine eligible evidence. Do not confuse rule-bound pre-evaluation evidence with the public-result projection or invent a dependency cycle.
Complete result coverage. Bind every returned row, field, aggregate, count, metadata item, lineage item and payload location to its immutable origins and authority/redaction disposition, including tenant, purpose and sovereignty. Establish coverage under one independently sufficient selected access basis for the exact read target: a direct or delegated
RECEIVE_USEAuthorityGrant/DelegationGrant path, or a sufficient SharingGrant, under PR RFC candidate: executable authorization evidence v0.2 #11 sections 5.4/13. Do not combine incomplete authority, purpose or evidence coverage across access bases or use the resource-control layer to supply missing authority. For a shared aggregate artifact revision, explain from the governing contracts which returned constituent/origin information the selected artifact-scoped basis covers, and which information must be withheld, redacted or denied. Origin provenance alone is not authority. Do not assume that permission to read an artifact creates independent access rights to every underlying record, or that all shared-artifact reads must therefore fail. If resolving coverage requires a new or widened permission rule, stop for a separately reviewed authorization-owner decision; this read protocol cannot create that rule. Bind the exact immutableRP_READ_TARGET_ONEtarget and applicable policy, serializer identifier/version/digest, media type and buffered-payload digest. Preserve both read forms: direct-read form requires neitherQUERY_SPECIFICATIONnorQUERY_PLAN; query form requires both, exactly one each, as integrity inputs, with their exact revisions and query/plan digest bound where applicable. Apply approved withholding/redaction or deny an incompletely coverable payload. Protected streaming is unsupported. Preflight/dry-run may return only non-protected planning or qualification information and must never disclose protected bytes.Atomic evidence before release. Define the exact success set, state/order and owner of the single disclosure linearization point. Decision evidence, one single-use consumption, governed-read receipt, coverage manifest, payload digest and required retained payload ref/bytes must persist atomically before protected release. Provide an evidence-ownership table naming each profile's semantic owner, proposed package, truth claim, success-set placement and failure/retry posture. Prefer the already proposed AuthorizationDecisionEvidence/AuthorizationFinalizationEvidence v0.2 families; no new top-level evidence family is presumed.
Failure, uncertainty and retry. Define cancellation, deadline/guard invalidation, failure before/after persistence, commit acknowledgement loss, partial success evidence, crash/disconnect around disclosure, and retry/reconciliation. The read row selects
NO_EXTERNAL_DISPATCH: “release” in this issue means the buffered-read disclosure boundary in PR RFC candidate: executable authorization evidence v0.2 #11 section 18.5, not section 18.6's filing transport-release gate under Define transport-release eligibility after filing outbox commitment #13. Distinguish committed evidence, eligibility for that read disclosure, attempted disclosure and provable delivery; a server receipt does not prove human/network receipt. No protected bytes on pre-disclosure failure, no duplicate consumption, no reuse of an old decision as new disclosure authority and no invented complete-success claim. PlaceREAD_EVIDENCE_PERSISTENCE_FAILEDand the applicable decision-bundle persistence/projection failures in their runtime/integrity-gate dispositions: they are not authorization outcomes, have no authorization reason rank, and must not fabricate or rewrite the authorization result as DENY. Adopt PR RFC candidate: governed human-finalization transaction protocol #20/Define the NOT_REQUIRED transaction and consumption protocol v0.1 #26 concepts only through explicit compatibility analysis; their write outcomes and retry rules are not automatically read semantics.History and reply validity. Bind PR Define authorization-evidence source-history qualification (Phase A) #35's authoritative observation to historical RECORDED_RESULT reads in that same read context. Preserve complete candidate enumeration, original historical-admission verification, and established/proved-invalid/unresolved distinctions. Carry forward PR Define authorization-evidence source-history qualification (Phase A) #35 section 6's exact trigger: learning of a potentially material committed candidate after the observation cut but before reply finalization requires a new complete owner-governed observation and whole-read rebuild/revalidation, or the permitted unavailable/withheld path, even when that candidate's admission or classification is unresolved. Do not wait for a confirmed changed history label. Never splice refreshed history into an old governed-read payload. If payload/evidence is already finalized, the classifier cannot rewrite it or add an explanation commit; the owner must suppress/restart disclosure or use its permitted failure path. This creates neither a new retry permission nor a lock through network delivery. Separate the fresh-refusal command/reply path: this read protocol alone does not close that owner's HSP-BIND03 obligations or prove NONE at a fresh refusal's later reply.
Unchanged privacy and retention owners. Preserve PR Define CP2 authorization-result qualification and public reasons (Phase A) #31's WITHHELD precedence, null rules, safe messages, protected-detail limits and hidden-history-independent fallbacks, including C38. A missing/unadmitted producer is a readiness failure, distinct from an admitted producer's temporary inability to establish history. Apply the trusted immutable retention policy and preserve RETAINED_BYTES versus DIGEST_ONLY without caller weakening or overclaiming reconstruction. Before disclosure, the read cannot proceed if no applicable policy resolves at its governed snapshot, if a DIGEST_ONLY policy forbids the transient buffer processing needed to hash and execute the read, or if compatible minimization cannot preserve required immutable receipt/coverage/decision/trace evidence without prohibited retention. Release zero protected bytes; record truthful failure under criterion 6 and report any policy conflict to Define authorization evidence retention and proof-strength postures #14/PR RFC: authorization evidence retention and proof strength (Phase A) #29, without inventing a weaker posture or unobservable payload. A receipt, digest or history proof never grants trace access. Retention duration, encryption, deletion/redaction and custody policy remain owned by Define authorization evidence retention and proof-strength postures #14/PR RFC: authorization evidence retention and proof strength (Phase A) #29.
Falsifiable positive and hostile cases. Map each criterion to named invariants and case specifications, including the cases below. Show a satisfiable positive protocol for all selected read targets/paths, not a permanently unavailable service. Distinguish Phase A reasoning, schema/semantic fixtures and later production-path, concurrency/privacy and durability tests. No fixture is reported as executed evidence merely because it appears in the document.
Real bindings and staged completion. Name later non-default protocol/evidence profiles, source/attempt/observation bindings, producer-consumer interfaces, fixtures, conformance manifest/checker and accountable owners. Bind real reviewed bytes/digests at the authorized stage; no placeholder provider or self-asserted proof closes a dependency. The compatibility/dependency ledger must explicitly distinguish PR RFC candidate: executable authorization evidence v0.2 #11 section 24.1's historical description of PR RFC candidate: authorization-evidence qualifying-record governance #34 at
69682c2f918ef18756261a1186294cc3a5ebe44das unapproved from this issue's current PR RFC candidate: authorization-evidence qualifying-record governance #34 input atc59fdbc75f26ee4694355adedd4df021f64b5131, with version-2 approval in comment 5654388700. Identify which head each consumed statement rests on, assess the dependency update, and preserve PR RFC candidate: executable authorization evidence v0.2 #11's approved bytes; do not inherit its old approval-state wording as the status of the newer input or mistake that input's approval for source-binding closure. Record every missing source/storage/access/transaction guarantee and split any separate owner change before editing it. Follow all eleven stages of PR RFC candidate: executable authorization evidence v0.2 #11 section 24 and Promote executable authorization constraints and decision evidence RFC v0.2 #21; semantic approval alone closes no materialization, admission, currentness, extraction or runtime gate.Required cases
These are design and later conformance obligations, not approved protocol choices or executed tests.
Scope fences and owner stops
This protocol may define the read transaction's own semantics for review. It may not quietly amend another owner's authority to make those semantics executable.
If a workable read protocol needs a new guarantee from one of those owners, name the exact gap and propose a separate prerequisite or stacked/follow-up PR before changing that boundary. Do not create speculative services or treat a broad “go” as a cross-boundary exception.
Delivery and honest completion
This issue records the missing read owner; it does not create a binding or close CP2A-DEP01. Completion requires the applicable governed contract, exact source/observation/producer/consumer bindings and evidence at the appropriate stage. HSP-BIND01–04, applicable QG dependencies, #21 and OFARM2 G2/G3/G4 remain open until their own obligations are met. New qualifying-record authoring is neither activated nor proved deferrable.
The implementation destination remains OFARM2 #353 / PR #359, then #178, then the bounded #176 child. Indispensable read/write input producers must precede their consumers; this capability order cannot justify fake frames or an unresolved dependency cycle.
Verification and limits
At issue creation, checked canonical open/closed issue inventory for a duplicate and refreshed the exact owner heads and OFARM2 #359. The existing local binding investigation used immutable OFARM2 main objects and preserved its dirty primary checkout. No canonical/runtime file, approved candidate, branch/worktree, schema, permission, merge, promotion or deployment is changed by this issue.
The future Phase A must check exact source pins, compatibility/ownership, criterion-to-invariant-to-case traceability, Markdown structure and whitespace. Cheap package checks show document/repository hygiene only; they do not prove snapshot completeness, atomic durability, privacy or production readiness. No package, database, concurrency or hosted runtime test was run to create this issue.
Scope stayed within recording the governed-read transaction integrity and protected disclosure prerequisite.
What is next: re-review PR #37 at
41cd45b90fb8e133f6377d8f389858b89c3dd7ae, proposed decision version 2, then record explicit Phase A semantic direction. Keep approved PR #35 and the other owner candidates unchanged, with all actual binding and implementation gates open.