spec: portable-core-contracts - #172
Conversation
Codex reviewer (cross-vendor, read-only)Reviewed-head: ee9d5f5 Posted verbatim by The proposed contract has parsing and type contradictions that would either accept invalid document streams or make required test records impossible to represent. It also leaves an execution input outside the stated target-repository binding. Full review comments:
|
Deploying ystack with
|
| Latest commit: |
0488807
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://7815db9f.fabrica-6yx.pages.dev |
| Branch Preview URL: | https://ystack-spec-portable-core-co.fabrica-6yx.pages.dev |
Codex reviewer (cross-vendor, read-only)Reviewed-head: 7f33e38 Posted verbatim by The proposed v1 schema omits identities needed for deterministic change-request publishing and tool-configuration provenance. Because adding either field later requires a new major schema version, these gaps should be resolved before accepting the contract. Full review comments:
|
Codex reviewer (cross-vendor, read-only)Reviewed-head: cda7944 Posted verbatim by The proposed contract permits contradictory source provenance and contains incompatible cardinality limits for otherwise valid tool bindings. These should be resolved before the implementation plan is accepted. Full review comments:
|
Codex reviewer (cross-vendor, read-only)Reviewed-head: 5f3f9cd Posted verbatim by The proposed contract cannot represent a truthful executed failure when observed execution identity or environment differs from the request. That conflicts with its total-result and actual-facts requirements and should be resolved before implementation. Review comment:
|
Round cap reached — operator decision neededCurrent head: Formal round-3 review still found one P1 contract gap:
Final review: #172 (comment) Per the round cap, I am stopping edits. No code or live behavior changed. Operator options
The PR remains open, |
Operator ruling — one final bounded revision authorizedThe operator authorized one revision beyond the round cap, strictly limited to the remaining P1:
After this revision, rerun all exact-head gates and one final formal review. If that review is not clean, stop for a new operator ruling. Human merge remains the only merge path. |
Codex reviewer (cross-vendor, read-only)Reviewed-head: 10659fd Posted verbatim by The contract cannot faithfully record an important class of execution incidents, and its topic-ref validator accepts names that Git cannot use. These issues should be corrected before the specification becomes the implementation contract. Full review comments:
|
Operator-authorized final review completed — not cleanReviewed head: The authorized bounded revision passed all exact-head gates and independent pre-review. Its one permitted final formal review still found two issues:
Final review: #172 (comment) Per the operator's authorization, no further revision is allowed in this run. The PR remains open, New operator options
Human merge remains the only merge path. |
Operator ruling — one revision limited to two findingsThe operator authorized one more revision, strictly limited to the two findings from the previous final review:
No other design or scope change is authorized. After the revision, rerun all exact-head gates and one formal review. If that review is not clean, stop for a new operator ruling. Human merge remains the only merge path. |
Codex reviewer (cross-vendor, read-only)Reviewed-head: e27c617 Posted verbatim by The proposed v1 contract leaves most permission semantics undefined, cannot express a normal full-repository execution snapshot, and derives an inaccurate overall test outcome for mixed failed and inconclusive cases. These should be resolved before the schema becomes an implementation contract. Full review comments:
|
Two-item authorized review completed — not cleanReviewed head: The operator-authorized two-item revision passed all exact-head gates and independent pre-review. Its one formal review still found three different contract gaps:
Final review: #172 (comment) Per the ruling, I am stopping. The PR remains open, Recommended next rulingRescope/supersede this G2 rather than authorize another cap exception. Repeated final reviews are now finding unrelated edges across three subdomains: stage/evidence records, adapter/profile/capability-permission semantics, and contract-test records. The 839-line artifact and its 400-line implementation claim are no longer credible as one normally reviewable concern. A clean split would preserve this branch as the decision record and create separately gated children for:
Other operator options:
No code or live behavior changed. Human merge remains the only merge path. |
Operator ruling — scope down the same G2The operator agreed that #172 grew beyond the accepted intent's smallest-v1 requirement. This is a rescope of the existing Authorized direction:
|
Codex reviewer (cross-vendor, read-only)Reviewed-head: a1217ba Posted verbatim by The proposed v1 contract accepts impossible source provenance and does not define how adapters may consume the instruction records required by every capability. It also leaves common stale cases and patch output typing unrepresentable or contradictory. Full review comments:
|
Rescoped final review completed — not cleanReviewed head: Reviewed base: CI and every local exact-head gate passed. The one fresh formal review required by the operator ruling still found four contract gaps:
Formal review: #172 (comment) These findings are inside the retained five-document/three-capability core; they do not justify restoring the deferred forge, publisher, CI, execution, identity, or adapter-test scope. The last three are narrow relation/type omissions. The first needs one explicit choice between pre-delivered digest-checked instruction bytes and a separate exact content-read permission. Per the authorization, I am stopping without another edit or review. The PR remains open, Operator options
Human merge remains the only merge path. |
Operator ruling — one revision limited to four findingsThe operator authorized one revision beyond the round cap, limited exactly to the four findings from the rescoped final review:
Keep the five documents, three capabilities, and all previously deferred forge, publisher, CI, execution, identity, and adapter-test scope unchanged. No other design or scope change is authorized. After this revision, rerun all exact-head gates and one formal review. If that review is not clean, stop for a new operator ruling. Human merge remains the only merge path. |
Codex reviewer (cross-vendor, read-only)Reviewed-head: 666e29e Posted verbatim by The spec leaves security-critical manifest/profile relations undefined and permits verifier evidence to be associated with a different revision than the one tested. It also allows deterministic bindings to request skills that results must report as unused. Full review comments:
|
Four-item final review completed — not cleanReviewed head: Reviewed base: All local exact-head gates and GitHub CI passed. The formal review did not repeat any of the four authorized findings, but it found three new gaps in the retained minimal core:
Formal review: #172 (comment) These findings remain inside the accepted five-document, three-capability, five-permission scope. They do not justify restoring any deferred adapter-test, forge, publisher, CI, execution, or identity capability. The first needs an explicit closed relation matrix; the other two are single invariant gaps. Per the operator ruling, I am stopping without another edit or review. The PR remains open, Operator options
Human merge remains the only merge path. |
Operator ruling — read-only preflight, then one revision limited to three findingsThe operator authorized only these three findings from the review of
Before any edit, run a read-only consistency preflight limited to those affected manifest/profile and verifier relations. If it finds a different fourth issue, stop and report it; do not silently fix it. If the preflight finds no different issue, make one revision limited to the three findings above. Keep the five documents, three capabilities, five permissions, instruction-delivery boundary, and all deferred scope unchanged. No other design or scope change is authorized. After the revision, rerun all exact-head gates and one formal review. If that review is not clean, stop for a new operator ruling. Human merge remains the only merge path. |
Three-item read-only consistency preflight — cleanNo file was changed during this preflight. Independent implementability and security checks found no fourth issue and no shape/cardinality conflict in the authorized areas. The exact predicates for the revision are:
The existing five documents, three capabilities, five permissions, source cardinalities, instruction-delivery boundary, and deferred scope remain unchanged. The next edit is limited to expressing these three authorized findings. |
Codex reviewer (cross-vendor, read-only)Reviewed-head: 0488807 Posted verbatim by The new specification matches the referenced intent, preserves the stated safety boundaries, and defines internally consistent validation and relationship rules. No actionable correctness defect was identified in the changed file. |
Final handoff — review clean, CI greenHead The final read-only Codex review covered that exact head/base and found no actionable defect: #172 (comment) The three-item read-only preflight found no fourth issue, and the final revision changed only
|
Plan preflight — R14 budget gate failed; no implementation plan createdSource spec blob: The intent/spec hash chain is fresh, and main is clean. Before creating
The current repo has no reusable jq contract validator. Local jq is Reaching 400 would require at least one forbidden tradeoff: compressed long lines, fewer negative tests, a second schema/parser, tests that reuse production logic as their oracle, system-jq drift, or weaker byte/hash/error handling. R14 explicitly says to return to G2 when the plan cannot prove this budget. Therefore:
Recommended G2 decisionPreserve the accepted v1 semantics, but replace the single total-400 promise with three ordered, independently reviewed implementation slices, each capped near 300–400 lines and with no live activation until the final slice:
The G2 amendment must also name exact child branches/PR gates because the current artifact convention has one deterministic implementation branch per slug. If 400 must remain a total product budget, v1 must instead shrink to canonical/shared foundations plus one small document/command, and the remaining profile/stage contracts need separately accepted child chains. Raising one PR to roughly 1,000 lines is not recommended. Human merge and scope decisions remain the operator's. |
Closes #171
G2 decision
This PR proposes the smallest v1 contract layer for the accepted
portable-core-contractsintent. It pins main's intent blob3ed8bb434c096ec126d680019a9491ab8a113e31.The rescoped spec defines:
Scope-down record
The original draft grew to seven documents, thirteen capabilities, and fifteen permissions. Repeated final reviews then found unrelated edges across core records, role semantics, and adapter-test records. The operator ruled that #172 had expanded beyond the smallest useful v1 and authorized a same-issue, same-branch rewrite: #172 (comment)
Nothing was dropped silently:
This change still writes only
work/portable-core-contracts/spec.md. It does not read Git, run an adapter, authenticate a claim, grant authority, publish, activate a profile, change/yshifu, or alter live behavior.Review
Independent implementability and security/compliance reviews of the rescoped file are clean. The security pass specifically rechecked requested-versus-actual facts, permission escape, evidence replay, status truth, role separation, and the publisher handoff after #173 was linked.
The first formal review of the minimal v1 found four bounded gaps: instruction-byte delivery, canonical-JSON tree provenance, source/base stale selectors, and patch media type. The operator authorized one revision limited to those four findings: #172 (comment)
The next formal review did not repeat those four. It found three relation gaps: manifest/profile package-tool-config predicates, verifier target-revision binding, and deterministic skill consistency. The operator authorized only those three after a read-only consistency preflight: #172 (comment)
The preflight found no fourth issue and recorded the exact predicates before editing: #172 (comment). The current head closes only those three findings. It keeps five documents, three capabilities, five permissions, and all deferred scope unchanged. Independent implementability and security checks of the exact diff are clean.
The final formal review covered exact head
0488807ee288f6cf103f0404864008e1e3550cc0against basea388e984768a794ccd193fb4ab7a3488254e8655and found no actionable defect: #172 (comment). GitHub CI is green on the same head. The PR is ready for operator review and merge; no agent has merge authority.Exact-head proof
Clean detached worktree at
0488807ee288f6cf103f0404864008e1e3550cc0against basea388e984768a794ccd193fb4ab7a3488254e8655:work/portable-core-contracts/spec.mdchanged;git diff --check: passed.The spec is 628 lines after replacing the previous 839-line design and closing the authorized relation gaps. Its planned implementation remains capped at 400 normally formatted net lines and must return to G2 if that estimate cannot be proved.
Merging this PR accepts only G2 design and permits the next planning step. It does not accept a plan, implementation, profile activation, agent merge authority, or any external write. Human merge only.