KBN-101-07a: reconcile local-start holds after #1178 #1187

Open
opened 2026-08-13 01:09:08 +00:00 by Ghost · 0 comments

Gap

KBN-101-02a (#1178) can deliver the fail-closed local PGlite entrypoint while operator and agent-facing records still carry the older blanket “held until KBN-101-02” wording. Leaving those sites stale would make the code safe but keep the operational route falsely held.

Span audit found the claim in eight files:

  • AGENTS.md
  • README.md
  • docs/guides/dev-guide.md
  • docs/guides/deployment.md
  • docs/requirements/native-kanban-sot.md
  • docs/native-kanban-sot/SHARED-CONTRACT.md
  • docs/federation/SETUP.md
  • docs/guides/migrate-tier.md

Most operator-document paths are KBN-101-07-owned. They must not be absorbed into #1178’s fixed source fence.

Objective

After #1178 is merged and independently verified, reconcile every local-start hold site to the exact capability that actually landed:

  • permit only the dedicated explicit local-tier + PGlite + local-queue + session-created disposable-root entrypoint proven by #1178;
  • preserve every PostgreSQL, federated, production renderer/Vault, migration, and deployment hold that remains gated by KBN-101-00/-03/-05 and later activation evidence;
  • never turn a future schematic into an executable command route;
  • keep stale “held until KBN-101-02” wording from reasserting a resolved span gap.

Acceptance

  1. Finite inventory covers all eight files and finds no residual blanket local-start hold.
  2. Positive wording names only the reviewed #1178 entrypoint and its exact pre-side-effect refusal boundary.
  3. Negative checks preserve PostgreSQL DSN/non-local/mismatched configuration refusal and every production/deployment hold.
  4. KBN-101-07 path ownership remains intact; no Gateway, database, image, Compose, CI, migration, or provider-call mutation.
  5. Independent exact-head docs/security review and terminal-green affected gates.
  6. This issue does not authorize Gateway/Web start, database access, deployment, stage repin, or a native provider call.

Sequencing

Depends on #1178. #1178 may close its source-safety criterion when merged, but the operator hold is not declared lifted until this follow-on merges. Author against the exact integration line containing #1178; final completion remains subject to the main-line reconciliation gate.

## Gap KBN-101-02a (#1178) can deliver the fail-closed local PGlite entrypoint while operator and agent-facing records still carry the older blanket “held until KBN-101-02” wording. Leaving those sites stale would make the code safe but keep the operational route falsely held. Span audit found the claim in eight files: - `AGENTS.md` - `README.md` - `docs/guides/dev-guide.md` - `docs/guides/deployment.md` - `docs/requirements/native-kanban-sot.md` - `docs/native-kanban-sot/SHARED-CONTRACT.md` - `docs/federation/SETUP.md` - `docs/guides/migrate-tier.md` Most operator-document paths are KBN-101-07-owned. They must not be absorbed into #1178’s fixed source fence. ## Objective After #1178 is merged and independently verified, reconcile every local-start hold site to the exact capability that actually landed: - permit only the dedicated explicit local-tier + PGlite + local-queue + session-created disposable-root entrypoint proven by #1178; - preserve every PostgreSQL, federated, production renderer/Vault, migration, and deployment hold that remains gated by KBN-101-00/-03/-05 and later activation evidence; - never turn a future schematic into an executable command route; - keep stale “held until KBN-101-02” wording from reasserting a resolved span gap. ## Acceptance 1. Finite inventory covers all eight files and finds no residual blanket local-start hold. 2. Positive wording names only the reviewed #1178 entrypoint and its exact pre-side-effect refusal boundary. 3. Negative checks preserve PostgreSQL DSN/non-local/mismatched configuration refusal and every production/deployment hold. 4. KBN-101-07 path ownership remains intact; no Gateway, database, image, Compose, CI, migration, or provider-call mutation. 5. Independent exact-head docs/security review and terminal-green affected gates. 6. This issue does not authorize Gateway/Web start, database access, deployment, stage repin, or a native provider call. ## Sequencing Depends on #1178. #1178 may close its source-safety criterion when merged, but the operator hold is not declared lifted until this follow-on merges. Author against the exact integration line containing #1178; final completion remains subject to the main-line reconciliation gate.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: mosaicstack/stack#1187