Skip to content

feat(service): admit relation coordination - #643

Merged
HardMax71 merged 1 commit into
mainfrom
feat/service-relation-coordination
Aug 31, 2026
Merged

feat(service): admit relation coordination#643
HardMax71 merged 1 commit into
mainfrom
feat/service-relation-coordination

Conversation

@HardMax71

@HardMax71 HardMax71 commented Aug 31, 2026

Copy link
Copy Markdown
Owner

Relation execution could select relations from authenticated deliveries, but nothing bound an operator coordination identity to that exact trigger selection. Carrying the delivery, relation, and identity separately would leave a substitution seam before snapshot resolution.

This adds one Result-based admission boundary that consumes the authenticated delivery, reuses the frozen registry lookup, and accepts only a declared relation owned by its exact trigger set. The returned direct struct keeps the delivery, frozen relation, trigger role, and opaque coordination identity together without a policy enum, callback trait, second config grammar, or revision and timestamp inference.

Copilot AI lite review requested due to automatic review settings August 31, 2026 22:23

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@coderabbitai

coderabbitai Bot commented Aug 31, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Team

Run ID: 3c6f5800-a352-4487-a262-ba8dfa835260


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@HardMax71
HardMax71 merged commit cae956c into main Aug 31, 2026
20 checks passed
@HardMax71
HardMax71 deleted the feat/service-relation-coordination branch August 31, 2026 22:29

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Warning

The admission boundary is sound and verified; one docs row reads as contradicting itself.

Nit: docs/src/status.md#L21 — "snapshot acquisition ... not built" contradicts the same cell's claim that the strict Git transport acquires each subject.

The unchanged sentences of the row say the Git transport "acquires each subject into a physically independent root ... rechecks every commit-tree binding" and the Git layer "projects ... sources from all four acquired snapshots" — both implemented by fetch_relation_exact at controller/git/src/relation.rs#L54. The previous tail ("trusted record admission ... not built") matched docs/src/cross-repository-relations.md's "record values and sets await a trusted snapshot-bound producer"; the new phrase reads as denying the snapshot acquisition the same cell asserts. The page's unbuilt stage 2 is named "resolve and acquire snapshot-bound records from the admitted coordination" — "snapshot-bound record acquisition" would keep that parallel.

confirmation: read the full status.md row and controller/git/src/relation.rs; the PR state also passes cargo nextest run for amiss-controller-service (33 tests) and amiss-controller (280 tests), clippy -D warnings on both, and the repo's own amiss check --repo . --profile enforce (exit 0).

Session details

run

Ran: cargo nextest run --locked -p amiss-controller-service --test suite (33 pass), cargo nextest run --locked -p amiss-controller (280 pass, 1 skip), cargo clippy -p amiss-controller-service --all-targets --locked -- -D warnings and -p amiss-controller (clean), amiss check --repo . --object-format sha1 --base 768a0dd --index --profile enforce (exit 0). Read docs/src/status.md, docs/src/cross-repository-relations.md, controller/service/src/relation.rs, controller/git/src/relation.rs.

Comment thread docs/src/status.md
| Publication audits | Closed digest-bound contracts model an operator-owned publication plan, one provider-normalized successful-deployment receipt, and a conservative offline matched/refuted/unproven assessment. They bind the accepted report and exact docs, target, completed-site, product, deployment, workflow, producer, and evaluator identities. The controller validates that a complete chain describes its exact scanner report and replays to the supplied assessment. Its artifact store retains and reopens the exact report, plan, optional evidence, assessment, digest set, and verdict as one immutable evaluation-bound record. No command or controller lane acquires, stages, or publishes it yet. | [Publication audits](publication.md) |
| Locale coverage audits | One closed digest-bound plan binds an accepted report and exact docs candidate to a site, locale pair, independently selected producer, operator-owned coverage/fallback/optional target-lineage policy, and an optional immutable product resource reused from publication audits. Evidence carries independently complete source and target inventories with independent nullable product receipts; every target page is target-owned with nullable exact source lineage or declares an exact fallback class and source digest. The offline assessment reports proved missing/orphan pages, fallback status, current/stale/unproven target lineage, and matched/refuted/unproven product identity for each side. Only an exhaustive clean selected comparison matches. Exact lineage and product equality prove only the named digest relations, never translation quality or semantic equivalence. Command and controller intake are not built yet. | [Locale coverage audits](locale-coverage.md) |
| Cross-repository relations | The provider-neutral controller atomically freezes operator-owned two-subject relations, one opaque pair/release/workflow coordination identity, and all four exact base/candidate commit/tree identities without inferring intent from timestamps. A pure admission law assigns the first exact transition a fence, preserves identical work as a duplicate across either trigger role, rejects stable-identity rebinding, and advances the fence when a different coordination supersedes pending work. A bounded file-backed store applies the same law under a cross-process lock and atomically committed hash-chained journal; it serializes concurrent admission, recovers an uncommitted append after restart, and refuses exhausted capacity or missing, shortened, mutated, or rebound committed state. Exact historical retries retain their first fence without rolling current work back. The existing strict Git transport acquires each subject into a physically independent root under per-subject and aggregate streaming object/byte limits, rechecks every commit-tree binding, and returns the complete relation as unproven on any unavailable subject. A closed digest-bound plan retains the accepted report digest, trigger role, relation context, coordination identity, shared projection, human-readable repositories and selectors, and all four exact snapshots without copying credentials into the wire. The provider-neutral Git layer binds that plan back to the frozen transition and projects exact blob-line, named-region, or tree-path sources from all four acquired snapshots under joint record/byte budgets; unavailable sources produce null slots, while record values and sets await a trusted snapshot-bound producer. A separate plan-bound receipt gives each role independent nullable base/candidate slots; a present slot is only a projected-value digest and exact byte length, while null cannot claim emptiness or inequality. The replayable offline assessment binds the report, plan, optional evidence, and evaluator, then symmetrically classifies the complete equality transition as aligned, introduced drift, pre-existing drift, or resolved drift; absent, foreign, misrouted, or partial evidence remains unproven. Before immutable restart-safe retention, the controller reopens the accepted report, binds its repository, target, coordination, and snapshots to the trigger role and frozen operator transition, and independently replays the plan, optional evidence, and assessment. Pure status preparation requires both complete registered subjects at their still-current candidate commits and freezes only configured destinations under the pending fence. A second pure transition replays the retained audit against that pending work, freezes the exact target/audit record, resumes an unfinished exact retry, rejects immutable-field substitution, and completes the exact record idempotently. The same bounded journal commits status stage, per-destination acknowledgement, and completion actions under the scheduling lock, verifies the retained artifact before first stage and unfinished replay, and retains compact digest bindings instead of duplicating provider configuration or credentials. A provider-neutral delivery claim selects the oldest unresolved fence for each stable destination, reacquires its exact registry and artifact record, and holds one of 256 deterministic OS-lock shards across provider I/O. Dropped claims recover without durable mutation; a newer coordination cannot pass an unresolved older destination; unrelated shards remain parallel; and the final acknowledgement completes the batch, including recovery from failure between the two journal actions. The outbox itself performs no provider call. The GitHub installation and Gitea-family clients resolve exact registered branch heads. GitHub reconciles App-owned relation checks, while Gitea-family reconciles dedicated-reviewer commit statuses with its documented writer-binding limitation. A GitLab adapter resolves only the ephemeral candidate of an authenticated active policy job and returns the exact staged relation decision after a final live refresh, without making a provider write. The shared service loads one bounded strict-JSON operator registry and derives repository hosts from provider instances. An immutable generic router binds every required credential identity to one caller-owned authority under its exact provider and integration and rejects missing, unused, repeated, or rebound rows. Provider binaries do not construct or install those values yet; trusted record admission and live lifecycle integration are not built. | [Cross-repository relations](cross-repository-relations.md) |
| Cross-repository relations | The provider-neutral controller atomically freezes operator-owned two-subject relations, one opaque pair/release/workflow coordination identity, and all four exact base/candidate commit/tree identities without inferring intent from timestamps. A pure admission law assigns the first exact transition a fence, preserves identical work as a duplicate across either trigger role, rejects stable-identity rebinding, and advances the fence when a different coordination supersedes pending work. A bounded file-backed store applies the same law under a cross-process lock and atomically committed hash-chained journal; it serializes concurrent admission, recovers an uncommitted append after restart, and refuses exhausted capacity or missing, shortened, mutated, or rebound committed state. Exact historical retries retain their first fence without rolling current work back. The existing strict Git transport acquires each subject into a physically independent root under per-subject and aggregate streaming object/byte limits, rechecks every commit-tree binding, and returns the complete relation as unproven on any unavailable subject. A closed digest-bound plan retains the accepted report digest, trigger role, relation context, coordination identity, shared projection, human-readable repositories and selectors, and all four exact snapshots without copying credentials into the wire. The provider-neutral Git layer binds that plan back to the frozen transition and projects exact blob-line, named-region, or tree-path sources from all four acquired snapshots under joint record/byte budgets; unavailable sources produce null slots, while record values and sets await a trusted snapshot-bound producer. A separate plan-bound receipt gives each role independent nullable base/candidate slots; a present slot is only a projected-value digest and exact byte length, while null cannot claim emptiness or inequality. The replayable offline assessment binds the report, plan, optional evidence, and evaluator, then symmetrically classifies the complete equality transition as aligned, introduced drift, pre-existing drift, or resolved drift; absent, foreign, misrouted, or partial evidence remains unproven. Before immutable restart-safe retention, the controller reopens the accepted report, binds its repository, target, coordination, and snapshots to the trigger role and frozen operator transition, and independently replays the plan, optional evidence, and assessment. Pure status preparation requires both complete registered subjects at their still-current candidate commits and freezes only configured destinations under the pending fence. A second pure transition replays the retained audit against that pending work, freezes the exact target/audit record, resumes an unfinished exact retry, rejects immutable-field substitution, and completes the exact record idempotently. The same bounded journal commits status stage, per-destination acknowledgement, and completion actions under the scheduling lock, verifies the retained artifact before first stage and unfinished replay, and retains compact digest bindings instead of duplicating provider configuration or credentials. A provider-neutral delivery claim selects the oldest unresolved fence for each stable destination, reacquires its exact registry and artifact record, and holds one of 256 deterministic OS-lock shards across provider I/O. Dropped claims recover without durable mutation; a newer coordination cannot pass an unresolved older destination; unrelated shards remain parallel; and the final acknowledgement completes the batch, including recovery from failure between the two journal actions. The outbox itself performs no provider call. The GitHub installation and Gitea-family clients resolve exact registered branch heads. GitHub reconciles App-owned relation checks, while Gitea-family reconciles dedicated-reviewer commit statuses with its documented writer-binding limitation. A GitLab adapter resolves only the ephemeral candidate of an authenticated active policy job and returns the exact staged relation decision after a final live refresh, without making a provider write. The shared service loads one bounded strict-JSON operator registry and derives repository hosts from provider instances. An immutable generic router binds every required credential identity to one caller-owned authority under its exact provider and integration and rejects missing, unused, repeated, or rebound rows. Coordination admission consumes one authenticated delivery and accepts only an opaque operator identity for a relation owned by its exact trigger set. Provider binaries do not construct or install those values yet; snapshot acquisition and live lifecycle integration are not built. | [Cross-repository relations](cross-repository-relations.md) |

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nit: status.md line 21 claims “snapshot acquisition ... not built”, contradicting the same cell’s claim that the strict Git transport acquires each subject.

The unchanged sentences of the row say the Git transport “acquires each subject into a physically independent root under per-subject and aggregate streaming object/byte limits, rechecks every commit-tree binding” and the Git layer “projects ... sources from all four acquired snapshots” — both implemented by fetch_relation_exact at controller/git/src/relation.rs#L54. The previous tail (“trusted record admission ... not built”) matched the page’s “record values and sets await a trusted snapshot-bound producer”; the new phrase reads as denying the snapshot acquisition the same cell asserts. The page’s unbuilt stage 2 is named “resolve and acquire snapshot-bound records from the admitted coordination” — “snapshot-bound record acquisition” would keep that parallel.

confirmation: read the full status.md row and controller/git/src/relation.rs; the PR state also passes cargo nextest run for amiss-controller-service (33 tests) and amiss-controller (280 tests), clippy -D warnings on both, and the repo’s own amiss check --repo . --profile enforce (exit 0).

example

the discriminating pair, both in the same status.md cell:

  • “The existing strict Git transport acquires each subject into a physically independent root ... and returns the complete relation as unproven on any unavailable subject.”
  • “Provider binaries do not construct or install those values yet; snapshot acquisition and live lifecycle integration are not built.”

read with: sed -n 21p docs/src/status.md, sed -n 40,70p controller/git/src/relation.rs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants