spec: portable-core-contracts - #172
Conversation
Codex reviewer (cross-vendor, read-only)Reviewed-head: ee9d5f5 Posted verbatim by The proposed contract has parsing and type contradictions that would either accept invalid document streams or make required test records impossible to represent. It also leaves an execution input outside the stated target-repository binding. Full review comments:
|
Deploying ystack with
|
| Latest commit: |
e27c617
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://27b3f1f1.fabrica-6yx.pages.dev |
| Branch Preview URL: | https://ystack-spec-portable-core-co.fabrica-6yx.pages.dev |
Codex reviewer (cross-vendor, read-only)Reviewed-head: 7f33e38 Posted verbatim by The proposed v1 schema omits identities needed for deterministic change-request publishing and tool-configuration provenance. Because adding either field later requires a new major schema version, these gaps should be resolved before accepting the contract. Full review comments:
|
Codex reviewer (cross-vendor, read-only)Reviewed-head: cda7944 Posted verbatim by The proposed contract permits contradictory source provenance and contains incompatible cardinality limits for otherwise valid tool bindings. These should be resolved before the implementation plan is accepted. Full review comments:
|
Codex reviewer (cross-vendor, read-only)Reviewed-head: 5f3f9cd Posted verbatim by The proposed contract cannot represent a truthful executed failure when observed execution identity or environment differs from the request. That conflicts with its total-result and actual-facts requirements and should be resolved before implementation. Review comment:
|
Round cap reached — operator decision neededCurrent head: Formal round-3 review still found one P1 contract gap:
Final review: #172 (comment) Per the round cap, I am stopping edits. No code or live behavior changed. Operator options
The PR remains open, |
Operator ruling — one final bounded revision authorizedThe operator authorized one revision beyond the round cap, strictly limited to the remaining P1:
After this revision, rerun all exact-head gates and one final formal review. If that review is not clean, stop for a new operator ruling. Human merge remains the only merge path. |
Codex reviewer (cross-vendor, read-only)Reviewed-head: 10659fd Posted verbatim by The contract cannot faithfully record an important class of execution incidents, and its topic-ref validator accepts names that Git cannot use. These issues should be corrected before the specification becomes the implementation contract. Full review comments:
|
Operator-authorized final review completed — not cleanReviewed head: The authorized bounded revision passed all exact-head gates and independent pre-review. Its one permitted final formal review still found two issues:
Final review: #172 (comment) Per the operator's authorization, no further revision is allowed in this run. The PR remains open, New operator options
Human merge remains the only merge path. |
Operator ruling — one revision limited to two findingsThe operator authorized one more revision, strictly limited to the two findings from the previous final review:
No other design or scope change is authorized. After the revision, rerun all exact-head gates and one formal review. If that review is not clean, stop for a new operator ruling. Human merge remains the only merge path. |
Codex reviewer (cross-vendor, read-only)Reviewed-head: e27c617 Posted verbatim by The proposed v1 contract leaves most permission semantics undefined, cannot express a normal full-repository execution snapshot, and derives an inaccurate overall test outcome for mixed failed and inconclusive cases. These should be resolved before the schema becomes an implementation contract. Full review comments:
|
Two-item authorized review completed — not cleanReviewed head: The operator-authorized two-item revision passed all exact-head gates and independent pre-review. Its one formal review still found three different contract gaps:
Final review: #172 (comment) Per the ruling, I am stopping. The PR remains open, Recommended next rulingRescope/supersede this G2 rather than authorize another cap exception. Repeated final reviews are now finding unrelated edges across three subdomains: stage/evidence records, adapter/profile/capability-permission semantics, and contract-test records. The 839-line artifact and its 400-line implementation claim are no longer credible as one normally reviewable concern. A clean split would preserve this branch as the decision record and create separately gated children for:
Other operator options:
No code or live behavior changed. Human merge remains the only merge path. |
Operator ruling — scope down the same G2The operator agreed that #172 grew beyond the accepted intent's smallest-v1 requirement. This is a rescope of the existing Authorized direction:
|
Closes #171
G2 decision
This PR proposes the exact design for the record/validation child accepted in #156. It pins main's intent blob
3ed8bb434c096ec126d680019a9491ab8a113e31.The spec defines:
Scope boundary
This change adds only
work/portable-core-contracts/spec.md. It does not read Git, run an adapter, authenticate a claim, issue authority, publish, activate a profile, change/yshifu, or alter current live behavior.Git object truth remains in
portable-profile-resolution. Independent case execution, process isolation, Git revalidation, and the 2×2 matrix remain inportable-adapter-contract-tests. Closed PR #154 stays superseded and unmerged; parent #153 remains open.Review
Three independent passes covered implementability, security/adversarial behavior, and roadmap/dependency consistency. Findings were resolved until all three returned
CLEAN. Formal round-0 found three wire-contract gaps: multi-root JSON streams, incompatible error-code grammar, and a non-Git execution snapshot. Round-1 closed them. Formal round-1 found missing base-branch identity and non-resolvable tool configuration. Round-2 closed both. Formal round-2 found contradictory duplicate provenance and an impossible tool/source capacity edge. Round-3 closed both. Formal round-3 then found that the schema could not truthfully record execution under the wrong identity/environment. The operator authorized a bounded revision, which fixed that but its final review found two remaining issues: actual capability mismatch and a Git-invalid leading-dot topic component. The operator authorized one revision limited to those two items. This head binds capability mismatch under the same failed/inconclusive truth rule and rejects leading-dot components. The independent passes rechecked both changesCLEAN.The artifact is 839 lines, above the repository's soft PR-size guide. It stays one exact G2 document because splitting the normative wire schema, relation rules, and capability registry across separately accepted specs would create two sources of core meaning. This is disclosed for the operator's review; it does not approve an implementation size exception. The implementation itself is capped at 400 net lines and must return to G2 if its plan cannot meet that bound.
Proof
Clean detached worktree at
e27c6173b5c5d92de9936353e23dd014606b6522:/faberretirement/doctor cases: 27 passedgit diff --check: passedMerging this PR accepts G2 design and permits the next planning step. It does not accept a plan, implementation, live activation, or merge authority for an agent.