contract(onboarding-wizard): revision 15 — bootstrap-status envelope split (NEW-20 residual), active-window mutant attribution (NEW-22)
ci/woodpecker/pr/ci Pipeline was successful
ci/woodpecker/pr/ci Pipeline was successful
Sol r14 re-review left two findings. NEW-20 residual (BLOCKER): §2.3 closed the bootstrap-status response to epoch/mode with no other field, conflicting with contract 5 §4.3's mandatory correlation echo on mapped operations (§§1.1, 7 item 8). Rev 14's state-derived/envelope split is now applied to bootstrap-status: §2.3 bounds state-derived content only and carries the contract 5 §4 envelope; §6 item 2's closed-field assertion and §7 item 2's description follow. Contract 5 not amended. NEW-22 (MAJOR): the active-window witness claimed its seed-workspace- scoped mutant fails branches (b) and (c); it passes (c). The witness now attributes (b) to that mutant, names the separate all-workspace mutant branch (c) catches, and states branches (a)/(b)/(c) start from isolated copies of the same incomplete pre-state. Preamble: Revision 15 paragraph; Revision 14 superseding note.
This commit is contained in:
@@ -371,7 +371,31 @@ canonical-reference resolution, the constant shape scoped to
|
|||||||
callers that reached the gate — and the child-race control
|
callers that reached the gate — and the child-race control
|
||||||
asserts the refusal class, pinning the order mechanically, with
|
asserts the refusal class, pinning the order mechanically, with
|
||||||
the cross-surface shape control asserting one constant conflict
|
the cross-surface shape control asserting one constant conflict
|
||||||
shape across the gate, succession, and query surfaces.
|
shape across the gate, succession, and query surfaces. (Revision 15
|
||||||
|
extends this revision's envelope reconciliation to the
|
||||||
|
bootstrap-status response and corrects the active-window witness's
|
||||||
|
mutant attribution.)
|
||||||
|
|
||||||
|
Revision 15 (sol re-review 14: NEW-20 residual, NEW-22): the
|
||||||
|
envelope reconciliation reaches the last closed response, and the
|
||||||
|
active-window witness names its mutants correctly.
|
||||||
|
**Bootstrap-status envelope** (NEW-20 residual): §2.3's closed
|
||||||
|
two-field response now bounds its STATE-DERIVED content only —
|
||||||
|
pre-epoch `epoch` plus `mode`, post-epoch `epoch` alone, no other
|
||||||
|
state-derived field — while the response remains an ordinary
|
||||||
|
contract 5 §4 result DTO whose fixed envelope frame carries the
|
||||||
|
request's own correlation ids, echoing the caller's request and
|
||||||
|
deriving from no stored record; §6 item 2's closed-field assertion
|
||||||
|
and §7 item 2's disclosure description follow. Contract 5 is not
|
||||||
|
amended. **Mutant attribution** (NEW-22): the active-window witness
|
||||||
|
now states that branches (a), (b), and (c) each start from an
|
||||||
|
isolated copy of the same incomplete pre-state (branch (a) commits
|
||||||
|
a state change), attributes branch (b)'s detection to the
|
||||||
|
seed-workspace-scoped incorrect evaluator, and names the separate
|
||||||
|
all-workspace incorrect evaluator that branch (c) catches — the
|
||||||
|
seed-workspace-scoped mutant, correctly refusing outside the seed
|
||||||
|
set, passes branch (c), so the two branches detect distinct
|
||||||
|
mutants. No other change.
|
||||||
|
|
||||||
Scope: the Gateway-backed product onboarding wizard. Out of scope: the
|
Scope: the Gateway-backed product onboarding wizard. Out of scope: the
|
||||||
host-local install wizard (`mosaic wizard`, which drives host install and
|
host-local install wizard (`mosaic wizard`, which drives host install and
|
||||||
@@ -486,16 +510,23 @@ through the extensibility rule §2.4).
|
|||||||
unreachable there; the pre-epoch flow instead branches on the mode
|
unreachable there; the pre-epoch flow instead branches on the mode
|
||||||
value reported by the **unauthenticated bootstrap-status response**
|
value reported by the **unauthenticated bootstrap-status response**
|
||||||
of the bootstrap surface (identity §3), which evaluates the mode
|
of the bootstrap surface (identity §3), which evaluates the mode
|
||||||
record server-side. The bootstrap-status response is a **closed
|
record server-side. The bootstrap-status response's **state-derived
|
||||||
two-field schema**: `epoch` — one field whose value set is exactly
|
content is a closed two-field schema**: `epoch` — one field whose
|
||||||
|
value set is exactly
|
||||||
the bootstrap epoch states identity §3 defines for
|
the bootstrap epoch states identity §3 defines for
|
||||||
`bootstrap_state`, closed to the exact wire-token pair **`open`**
|
`bootstrap_state`, closed to the exact wire-token pair **`open`**
|
||||||
and **`completed`** — identity §3 names the two epoch states in
|
and **`completed`** — identity §3 names the two epoch states in
|
||||||
prose but defines no wire enumeration, so this contract pins the
|
prose but defines no wire enumeration, so this contract pins the
|
||||||
tokens, as the second clause of the disclosed §7.9 amendment — and
|
tokens, as the second clause of the disclosed §7.9 amendment — and
|
||||||
`mode` — the recorded mode value, present **only while the epoch
|
`mode` — the recorded mode value, present **only while the epoch
|
||||||
is open** and absent from the response schema once the epoch has
|
is open** and absent from the state-derived content once the epoch
|
||||||
completed. No other field exists in the response. The unauthenticated pre-epoch
|
has completed. No other state-derived field exists in the
|
||||||
|
response, and the response remains an ordinary contract 5 §4
|
||||||
|
result DTO: its fixed envelope frame carries the request's own
|
||||||
|
correlation ids — echoing the caller's request, deriving from no
|
||||||
|
stored record, and disclosing no state — so the closed schema
|
||||||
|
bounds disclosure of state and amends nothing in
|
||||||
|
contract 5. The unauthenticated pre-epoch
|
||||||
mode disclosure is a disclosed amendment to contract 6 §2.2's
|
mode disclosure is a disclosed amendment to contract 6 §2.2's
|
||||||
authenticated-read rule (§7.9); post-epoch, §2.2's
|
authenticated-read rule (§7.9); post-epoch, §2.2's
|
||||||
authenticated-only rule holds unchanged and the bootstrap-status
|
authenticated-only rule holds unchanged and the bootstrap-status
|
||||||
@@ -1223,12 +1254,17 @@ Binding on the implementing PRs:
|
|||||||
2. **Mode witnesses:** the branch point exists — a pre-epoch flow
|
2. **Mode witnesses:** the branch point exists — a pre-epoch flow
|
||||||
resolves its step set from the bootstrap-status mode field (§2.3),
|
resolves its step set from the bootstrap-status mode field (§2.3),
|
||||||
a post-epoch run from contract 6 §2.2's authenticated read; the
|
a post-epoch run from contract 6 §2.2's authenticated read; the
|
||||||
bootstrap-status response matches §2.3's closed two-field schema
|
bootstrap-status response's state-derived content matches §2.3's
|
||||||
|
closed two-field schema
|
||||||
exactly while the epoch is open — the epoch field carrying one of
|
exactly while the epoch is open — the epoch field carrying one of
|
||||||
§2.3's two exact wire tokens — and after the epoch completes
|
§2.3's two exact wire tokens — and after the epoch completes
|
||||||
contains the epoch field only — the mode field absent from the
|
contains the epoch field only — the mode field absent
|
||||||
response (closed-field assertion on the response schema in both
|
(closed-field assertion on the state-derived content in both
|
||||||
phases); post-epoch, an unauthenticated mode read through any
|
phases, with the response's contract 5 §4 envelope asserted to
|
||||||
|
carry the request's own correlation ids — present, equal to the
|
||||||
|
request's, derived from no stored record — and no further
|
||||||
|
state-derived field in either
|
||||||
|
phase); post-epoch, an unauthenticated mode read through any
|
||||||
surface is refused (contract 6 §2.2, as amended by §7.9, holds); v1 with mode `standalone` yields the §3 step set; a
|
surface is refused (contract 6 §2.2, as amended by §7.9, holds); v1 with mode `standalone` yields the §3 step set; a
|
||||||
simulated unsupported or unreadable mode record yields one bounded
|
simulated unsupported or unreadable mode record yields one bounded
|
||||||
precondition refusal (§2.3) and no partial flow; wizard sources
|
precondition refusal (§2.3) and no partial flow; wizard sources
|
||||||
@@ -1566,13 +1602,22 @@ Binding on the implementing PRs:
|
|||||||
second kanban item — which is refused by the owning content
|
second kanban item — which is refused by the owning content
|
||||||
contract's authorization with nothing written; and (c) a
|
contract's authorization with nothing written; and (c) a
|
||||||
content command against a workspace outside the seed set,
|
content command against a workspace outside the seed set,
|
||||||
refused likewise; this witness is discriminating where the
|
refused likewise; branches (a), (b), and (c) each start from
|
||||||
|
an isolated copy of the same incomplete pre-state — branch (a)
|
||||||
|
commits a state change, so no branch runs in another's
|
||||||
|
post-state; this witness is discriminating where the
|
||||||
post-completion refusal below is not — an incorrect evaluator
|
post-completion refusal below is not — an incorrect evaluator
|
||||||
scoped by completion state rather than by canonical key (one
|
scoped by completion state rather than by canonical key (one
|
||||||
granting the designation all seed-workspace writes while
|
granting the designation all seed-workspace writes while
|
||||||
seeding is incomplete) passes the post-completion test but
|
seeding is incomplete) passes the post-completion test but
|
||||||
fails branches (b) and (c) here, because they refuse while
|
fails branch (b), which refuses while seeding is still
|
||||||
seeding is still incomplete; after branch (a) commits, read
|
incomplete, and a second, broader incorrect evaluator (one
|
||||||
|
granting the designation writes in EVERY workspace while
|
||||||
|
seeding is incomplete) passes the post-completion test but
|
||||||
|
fails branch (c) — the control against that all-workspace
|
||||||
|
bypass, which the seed-workspace-scoped evaluator, correctly
|
||||||
|
refusing outside the seed set, would pass; after branch (a)
|
||||||
|
commits, read
|
||||||
attempts by the acting designation and by a later successor
|
attempts by the acting designation and by a later successor
|
||||||
against BOTH predecessor-created and successor-created seed
|
against BOTH predecessor-created and successor-created seed
|
||||||
content are refused — the bounded origination response is the
|
content are refused — the bounded origination response is the
|
||||||
@@ -1689,8 +1734,10 @@ contracts and are not additions:
|
|||||||
1. Enrollment-step skippability (§3.5) — the PRD step list does not
|
1. Enrollment-step skippability (§3.5) — the PRD step list does not
|
||||||
mark the step optional.
|
mark the step optional.
|
||||||
2. The unauthenticated bootstrap-status mode disclosure — the closed
|
2. The unauthenticated bootstrap-status mode disclosure — the closed
|
||||||
two-field response schema (epoch state plus the recorded mode
|
two-field state-derived response content (epoch state plus the
|
||||||
value, the latter present during the bootstrap epoch only) (§2.3).
|
recorded mode value, the latter present during the bootstrap
|
||||||
|
epoch only), carried in an ordinary contract 5 §4 result DTO
|
||||||
|
whose envelope echoes the request's correlation ids (§2.3).
|
||||||
3. The **bootstrap finalize command** (§3.3) — an extension of
|
3. The **bootstrap finalize command** (§3.3) — an extension of
|
||||||
identity §3's bootstrap surface: one transaction carrying the
|
identity §3's bootstrap surface: one transaction carrying the
|
||||||
first-admin fields, the collected settings, registration-mode, and
|
first-admin fields, the collected settings, registration-mode, and
|
||||||
|
|||||||
Reference in New Issue
Block a user