spec: portable-core-contracts - #185
Conversation
…core-contracts # Conflicts: # work/portable-core-contracts/spec.md
Codex reviewer (cross-vendor, read-only)Reviewed-head: 1b93923 Posted verbatim by The amended contract weakens unavailable-tool result truth and leaves two gaps in the cross-child freshness gate. These can permit conclusive results or downstream implementation against stale contracts. Full review comments:
|
Manager fix claim — G2 round-0
Exact tuple
Authorized scopeThis claim authorizes one fix pass and only these three changes:
Do not change intent, any other file, the accepted product outcome, or the delivery topology. This claim gives no merge authority. One fix pass is authorized by this claim and no other. |
Deploying ystack with
|
| Latest commit: |
5c7172f
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://2f044ada.fabrica-6yx.pages.dev |
| Branch Preview URL: | https://ystack-spec-portable-core-co.fabrica-6yx.pages.dev |
Round-0 review fixesCommit: Scoped to the three P1 findings in Codex review comment 5464726341:
Proof:
Round moved |
Codex reviewer (cross-vendor, read-only)Reviewed-head: 7018549 Posted verbatim by The dependency scheme does not prove that composed child implementations were accepted against the same upstream generation. It also exposes upstream changes through the existing public wrapper before reassembly completes. Full review comments:
|
Manager fix claim — G2 round-1
Exact tuple
Authorized scopeThis claim authorizes one fix pass and only these two changes:
Do not change intent, any other file, the child dependency order, the public package identity, or the accepted product outcome. This claim gives no merge authority. One fix pass is authorized by this claim and no other. |
Round-1 review fixesCommit: Scoped to the two P1 findings in Codex review comment 5464779864:
The activation guard now distinguishes first publication, an upgrade under construction, and post-switch state. The parent plan records one unused Proof:
Round moved |
Codex reviewer (cross-vendor, read-only)Reviewed-head: 8c3c6e2 Posted verbatim by The specification leaves the assembly activation gate internally unsatisfiable and does not fully authenticate merged upstream dependencies or permanently unique generation IDs. These gaps undermine the delivery and atomic-generation guarantees introduced by the patch. Full review comments:
|
Manager fix claim — terminal round-3
Exact tuple
Authorized scopeThis claim authorizes one terminal fix pass and only these three changes:
Do not change intent, any other file, the child dependency order, the public package identity, or the accepted product outcome. There is no automatic round-4. This claim gives no merge authority. One terminal fix pass is authorized by this claim and no other. |
Terminal round-3 review fixesCommit: Scoped to the three findings in Codex review comment 5464869813:
The generation-aware guard still keeps the old complete generation selected until the final assembly merge. Published generation exports remain immutable; the stable wrapper remains the only assembly activation export. Proof:
Round moved |
Codex reviewer (cross-vendor, read-only)Reviewed-head: 3a23d68 Posted verbatim by The first-publication assembly sequence cannot satisfy both its wrapper-only switch rule and the repository's required-files gate. This blocks the planned public assembly until the specification permits an atomic restore-manifest update. Review comment:
|
|
Terminal G2 handoff
Remaining finding
The terminal review exhausted the round cap. There is no automatic round-4. This PR remains frozen without |
Operator direction — one post-cap final revisionSource: direct operator instruction in the current Codex session on 2026-08-29. The operator asked the manager to keep moving, place approval points on GitHub, and use the operator merge as the decision. Authorize one final revision on the existing PR #185. Keep the review counter at round-3. The only allowed change is the assembly switch rule needed to satisfy the restore manifest gate:
Do not change the seven-child topology, contract semantics, risk, dependency rules, or any other scope. Do not create round-4. If the final exact-head review does not pass, restore needs-human and stop. The operator merge of this PR is the G2 acceptance. PR #183 remains frozen. This direction does not authorize any agent to merge. |
Manager claim — post-cap final
Exact tuple
Sole authorized scope
Do not change any other file or rule, the seven-child topology, contract semantics, risk, or dependency rules. Do not create round-4. This claim authorizes one post-cap final revision only and gives no agent merge authority. |
Post-cap final revision completeClaim: ystack-claim-20260829T212317Z-portable-core-contracts-post-cap-final-02599593
This revision changes only the terminal P1 from review 5464936039. First publication now requires one switch commit that adds exactly the public wrapper and its exact restore-manifest entry. Upgrades remain wrapper-only and keep that manifest entry byte-identical. The exact post-switch head must pass the structure check, public-wrapper CI, and independent review. Local proof on this exact commit: git diff checks are clean; YAML frontmatter parses as risk high; intent-blob matches current main at f77fc1fdd8f7af228e7f211740901b265fc545ae. Two independent read-only draft reviews returned PASS on blob 17b2f20c870c371a53be79d08d784c322d8d2a75. No topology, contract semantics, dependency, authority, or other scope changed. claimed stays in place until the manager verifies this handoff. No merge-ready and no merge authority. |
Codex reviewer (cross-vendor, read-only)Reviewed-head: 5c7172f Posted verbatim by The amended spec remains hash-linked to the accepted intent, records the required high-risk classification, and consistently defines the child boundaries, dependency pins, generation switching, and validation behavior. No discrete blocking defect was identified in the changed lines. |
Operator action — please review and mergePR #185 is now merge-ready at exact head 5c7172f. GitHub CI and Cloudflare passed. The final independent Codex review comment 5465008961 has no actionable findings, and a separate adjudicator authenticated its exact head/base markers and clean result. Merging this PR is the operator acceptance of G2 for portable-core-contracts. No agent will merge it. If you want a change, do not merge and leave a PR comment instead. After your merge, the manager will sync the accepted spec and continue with the separate high-risk parent plan-only PR. It will not start implementation or create child ready state. PR #183 remains frozen. |
Tracks #155
G1 amendment: #184
What changed
core.contracts.v1package delivered through seven independently gated child initiatives.Risk and boundary
risk: high— this is broad architecture and defines security controls, workflow dependencies, fixed code loading, and operator-owned CI behavior.The five document kinds, three capability IDs, five permission IDs, every v1 field/enum, canonical bytes, error classes, claims-not-authority boundary, and no-live-activation outcome remain unchanged.
This PR changes only
work/portable-core-contracts/spec.md. It does not approve the parent plan, create or approve child intakes, modify code, resume/close/merge PR #183, or activate any validator. The #180 bridge is no longer authority after the merged G1 amendment.Exact identities
f77fc1fdd8f7af228e7f211740901b265fc545ae580210b1a265cf7ccee619d603650afbcc026d831b93923374fa39e28f76457769769eba8529f8b2d1e403fadb5d4c13cc8d2bdb1d9c1ddde65d71a8Proof
intent-blobmatches merged main;risk: highis explicit.git diff --checkclean.-Land import metadata rules.ab4a7082f02e67b5748c5c54b9214f37d222f53f,round-3 + needs-human.Human merge only. G2 merge accepts this spec and risk classification; it does not authorize code.