Skip to content

Lineage stage 1: extract and qualify the pure exact-head contract #990

Description

@jeffhuber

Part of #963, stabilization epic #979, and roadmap #900. Stage 1 before #991 trusted publication and #992 atomic consumer activation.

Revised approach after contract review

Unaccepted prototypes #989 and #993 remain preserved and unmerged. The complete #993 review confirmed surviving falsey-history convenience paths, unnormalized stored episode lanes, and renderer chains lacking one immutable target. Stop further revisions of #993; rebuild a deliberately small pure core from accepted main in a fresh Codex-source PR, independently reviewed by qualified Claude.

Reuse schema fixtures and confirmed regressions, not prototype helpers or serial repair commits. Remove optional-context, generic evidence-composer, REST-history selector and environment-loading convenience APIs. Live accepted consumer behavior remains unchanged until #992.

Small explicit contract

  • Target: immutable validated repo, positive non-boolean integer PR number, nonempty valid branch, full canonical SHA. Exact resolution never falls back. Identity-only resolution is a separate explicit API with no evidence argument.
  • Episode: direct construction and mapping ingestion share validation/canonical stored values. Metadata-only target, lane/head binding and verified handoff/continuation shapes.
  • Identity: one immutable canonical normalization of account/branch aliases, insertion-order-independent conflict refusal, longest prefix, declared policy-field preservation and canonical own-reviewer floor. No environment input or arbitrary opaque mutable configuration. Immutable branch binding preserves exact case separately from prefix-signal normalization.
  • History and Authorities: explicit validated raw comments/pages; malformed present shapes/fields reject before normalization/trust. Genuine [], supported user:null and omitted optional body remain valid. Unavailable history is distinct from successful empty history. Marker authority is a separate explicit immutable account set, never inferred from identity authors.
  • Chain: exact Target-bound empty or ordered nonempty chain from at most560 raw arrivals before deduplication, at most32 distinct contiguous episodes, one immutable repo/PR/branch, verified continuity and writer states. Parsing retains raw cumulative arrivals until one owning chain validator deduplicates; no composer resets the budget. Stale head waits and cannot admit.
  • Resolve/parse/render/admit: one Chain factory owns raw-arrival validation/budget/deduplication; exact resolution uses that Chain's own Target with no raw-evidence overload or competing Target argument. One canonical full decision includes branch conflicts with zero episodes; strict announced complete unique-key/nonempty marker grammar; unrelated/untrusted comments confer no authority; rendering accepts only a validated nonempty Chain and never truncates; admission compares canonical reviewer/contributors and resolved decision.

One owning pure module plus standalone mirror is preferred. No store, environment, filesystem, network, provider, publisher or mutation dependencies. No legacy facade unless its explicit-input invariants exactly match. Keep the live tools/decisions.py adapter unchanged for #992.

Reviewable delivery and convergence

One fresh isolated Code Mower Codex writer from accepted main and one draft PR closing #990, Refs #963. Independent contributor-excluded Claude review must demonstrably read the entire exact diff/source. Target <=10 changed files and <=180,000 base-to-head diff bytes including tests, enforced before push; no automatic cap increase. A spec contradiction or scope overage stops before push for a decomposition decision. Use finite supervised source duration/output controls; Codex CLI has no native USD cap, so do not claim dollar enforcement. No hosted Devin create allowance.

Owning tests are unittest-native with isolated fixtures. Cover constructor/factory canonical equality, strict target versus explicit identity-only, aliases in both orders, zero-episode branch conflicts, valid recorded takeover/stale head, malformed and nullable raw history/pages, strict marker grammar/trust, common-target chain, full528+32 cumulative replay,561duplicate refusal before dedup and bounded consumption, renderer roundtrip/refusal, pure/transitive import boundary, mirror parity, and actual isolated init-materialized import/parse/resolve with package/repo source unavailable.

After clean Code Mower delivery: deterministic pure matrix, exact Ruff/privacy/package guard/readiness, canonical manifest regeneration equality, one exact CI-style full unittest discovery, one complete independent exact-head audit, full CI and authoritative gate, source quiescence/lease closeout. New broad design findings stop for assessment; no automatic repair loop. #990 accepts only the core; #963 remains open through #991/#992 and final consumer matrix. #915 still owns published-package pin/artifact qualification.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions