Parent and ruling
This is the tracked remainder split from #171 by the operator ruling on #172:
#172 (comment)
Approved parent scope, quoted verbatim
Accept one exact work/portable-core-contracts/spec.md that an implementation planner can use without inventing core meaning. It must define:
- seven canonical document kinds and all shared/nested wire shapes;
- total stage status, outcome, evidence, time, and actual-execution rules;
- a closed v1 role/capability/permission/argument registry;
- manifest-offer → profile-request → external-grant → result-use separation;
- pure supplied-document validation and stable errors;
- exact consumer boundaries for the later Git resolver and executable adapter-test runner.
The accepted intent also says, verbatim:
Producer has no publish authority. Verifier has no model or forge-write authority.
Reviewer is exact-change read-only and cannot edit, approve, publish, or merge.
Publisher has no model or candidate execution and performs one fixed typed write.
Exact subset carried here
This issue carries only the capability and permission definitions that #172 removes from the minimal v1:
- the one fixed, typed publisher write and its exact resource/action permission;
- any forge, CI, execution, or identity operation that an accepted downstream artifact later proves it needs;
- the exact argument, role, permission, and result relations for those operations.
This is a strict subset of the quoted closed role/capability/permission registry. It does not reopen the five minimal v1 documents or add implementation, credentials, grants, live adapters, or activation.
The two removed adapter-test document kinds and their executable 2×2 semantics stay with #159; they are not duplicated here.
Gate
This issue records deferred scope only. It authorizes no code, external write, profile activation, or merge. Design waits for the minimal core G2 and the relevant adapter/control-foundation dependencies. Human merge remains the only merge path.
Parent and ruling
This is the tracked remainder split from #171 by the operator ruling on #172:
#172 (comment)
Approved parent scope, quoted verbatim
The accepted intent also says, verbatim:
Exact subset carried here
This issue carries only the capability and permission definitions that #172 removes from the minimal v1:
This is a strict subset of the quoted closed role/capability/permission registry. It does not reopen the five minimal v1 documents or add implementation, credentials, grants, live adapters, or activation.
The two removed adapter-test document kinds and their executable 2×2 semantics stay with #159; they are not duplicated here.
Gate
This issue records deferred scope only. It authorizes no code, external write, profile activation, or merge. Design waits for the minimal core G2 and the relevant adapter/control-foundation dependencies. Human merge remains the only merge path.