v0.2.0
Mandate 0.2.0 — contract creators, generated shapes, event-sourced tenancy, an event harness
The first release of the ESS-to-implementation drift-protection programme (wave E1).
Specification (systems/mandate, ESS 0.26.0): 16 creators declared with creates: and instance:; every creating event carries its record with truthful sources; 34 moving commands declare a wrong-state outcome; AuthenticateFederation creates the Session and returns session_id, organization_id, principal_id, epochs, expires_at. Synthesis: 84 → 132 scenarios, refusals 106 → 59, every refusal named.
Implementation: mandate-contract (generated Rust shapes for all 72 events, 59 inputs, 24 responses, 11 errors, 36 entities; cargo xtask contracts byte-compares them); mandate-testkit::contract (schema, emission-count and payload-source checks against the compiled model); mandate-model tenancy and resource commands as decide + apply + fold with replay proofs; mandate-conformance skeleton and mandate-conform binary; cargo xtask adopt.
Conformance at this release: 0 of 132 scenarios executed against the implementation (no conformance target yet). Entities the log cannot rebuild: 12 (was 14). Contract-versus-implementation drift the wave surfaced and routed: a consumed authorization code returns 502 where the contract says 409; four idempotent-accept records where the contract says 409.
Not in this release: a served route, a real signature verifier, a durable event-log adapter, credential issuance and code redemption at STS, the customer-facing login flow end to end.
Full changelog: CHANGELOG.md, [0.2.0].