Skip to content

P1: Add cross-repository contract compatibility and release-train conformance #16

Description

@BunsDev

Outcome

Turn the initial public dependency, contract, and release-train indexes from descriptive coordination records into tested producer/consumer compatibility evidence without centralizing component semantics in .github.

Initial scope

  • Familiar Contract → Threads → Psyche → Coven identity/authority/orchestration/runtime chain.
  • Coven Runtimes → Coven runtime capability descriptors and registry adoption.
  • Coven → SDK, Coven Memory, Cave, Coven GitHub, and execution clients.
  • Psyche → Psyche Build orchestration semantics.
  • Brand → UI/Cave/Docs/Landing profile consumption.

Design requirements

  • Producers own schemas, vectors, canonicalization, versioning, deprecation, and release artifacts.
  • Consumers pin exact immutable producer artifacts or approved release digests.
  • .github records relationships, required evidence, and generated views; it does not duplicate schemas or declare a consumer conformant by metadata alone.
  • Compatibility claims distinguish structural, packaged-artifact, runtime-authority, continuity, privacy, interoperability, and release evidence.
  • Moved heads, mutable tags, missing artifacts, stale evidence, unsupported platforms, and downgrade attempts fail closed or degrade explicitly to proposal/unsupported status.

Acceptance criteria

  • Every indexed contract names one canonical producer and immutable artifact policy.
  • Every release train has explicit sequencing, compatibility window, rollback, and moved-head behavior.
  • At least one producer/consumer pair runs a cross-repository canary on packed/released artifacts rather than source-relative imports.
  • Identity/authority canaries prove task, prompt, UI, model output, and caller metadata cannot grant protected authority.
  • Runtime canaries bind exact familiar root/revision where applicable and preserve atomic final authorization/commit semantics.
  • Memory client evidence proves it cannot mutate canonical memory state.
  • Brand/UI canaries prove UI remains specimen-only and Cave owns production behavior.
  • Registry/generated compatibility views become stale when evidence expires; they never silently remain green.
  • Release jobs remain owned by producing repositories and require their own protected approval/evidence gates.
  • No conformance claim exceeds the exact profile and artifact tested.

This work layers on the schemas and reusable checks in PR #7 and the pilot adoption in #8. It must not weaken existing release, security, or conformance gates.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions