chore: establish GitHub repository data baseline #528
File diff suppressed because it is too large
Load Diff
@ -0,0 +1,138 @@
|
||||
# Specification Quality Checklist: GitHub Repository Bootstrap and Git Data Baseline v1
|
||||
|
||||
**Purpose**: Validate that the Spec-462 requirements are complete, clear,
|
||||
consistent, measurable, and safe before implementation.
|
||||
**Created**: 2026-08-01
|
||||
**Feature**: [spec.md](../spec.md)
|
||||
**Depth / audience**: formal implementation-readiness gate for maintainers and
|
||||
independent reviewers
|
||||
|
||||
## Content Quality
|
||||
|
||||
- [x] CHK001 Is the maintainer trust/safety problem stated independently of a
|
||||
low-level implementation choice? [Clarity, Spec §Summary]
|
||||
- [x] CHK002 Is the passive-copy user value separated from later delivery
|
||||
cutovers? [Scope, Spec §Candidate Source]
|
||||
- [x] CHK003 Are all mandatory specification sections completed without an
|
||||
unresolved clarification marker? [Completeness]
|
||||
- [x] CHK004 Is repository-specific implementation detail limited to safety-
|
||||
critical transfer constraints and moved to the plan where possible?
|
||||
[Consistency]
|
||||
|
||||
## Requirement Completeness
|
||||
|
||||
- [x] CHK005 Are exact target identity, privacy, permission, emptiness, and Actions
|
||||
requirements defined? [Completeness, Spec FR-001–FR-006]
|
||||
- [x] CHK006 Are authoritative source heads, tags, peeled tag objects, default
|
||||
branch, counts, and digest requirements defined? [Completeness, Spec FR-007–FR-008]
|
||||
- [x] CHK007 Are all server, local-only, unique-commit, and excluded-ref outcomes
|
||||
exhaustively specified? [Completeness, Spec FR-009–FR-015]
|
||||
- [x] CHK008 Are retained-branch approval fields and the fail-closed default
|
||||
specified? [Clarity, Spec §Branch and Authority Contract]
|
||||
- [x] CHK009 Are exact-ref, fresh-bare-source, no-mirror, no-force, no-delete, and
|
||||
no-main-remote-change requirements explicit? [Safety, Spec FR-016–FR-021]
|
||||
- [x] CHK010 Are source-writer enumeration/pause proof, freeze drift, target drift,
|
||||
and re-review consequences defined? [Recovery, Spec FR-022–FR-023]
|
||||
- [x] CHK011 Are OID, tree, target-integrity, extra-ref, default-branch, measurable
|
||||
GitHub passive-authority, and readable Gitea unchanged-authority requirements
|
||||
defined? [Completeness, Spec FR-024–FR-030]
|
||||
- [x] CHK012 Are metadata migration, non-destructive rollback, independent review,
|
||||
and the stop-before-post-integration-follow-up boundary specified?
|
||||
[Completeness, Spec FR-031–FR-036]
|
||||
|
||||
## Requirement Clarity and Consistency
|
||||
|
||||
- [x] CHK013 Are `MIGRATE_ACTIVE`, server-only `MIGRATE_RETAINED`,
|
||||
`ARCHIVE_ONLY`, `RETAIN_LOCAL_ONLY`, `LOCAL_REDUNDANT`, and
|
||||
`EXCLUDED_NON_AUTHORITY_REF` assigned non-overlapping consequences? [Clarity,
|
||||
Spec §Branch and Authority Contract]
|
||||
- [x] CHK014 Is “all tags” consistent between goals, functional requirements,
|
||||
manifest design, acceptance criteria, and tasks? [Consistency]
|
||||
- [x] CHK015 Is “GitHub passive / Gitea active” defined through measurable
|
||||
configuration/governance invariants without falsely claiming administrators
|
||||
lack intrinsic write capability? [Consistency]
|
||||
- [x] CHK016 Is the main development remote invariant distinguished from the
|
||||
temporary bare-clone target remote? [Clarity, Spec FR-018–FR-021]
|
||||
- [x] CHK017 Are `TARGET_PREFLIGHT_READY`, `PRE_ACTIVATION_READY`,
|
||||
`PASSIVE_BASELINE_VERIFIED`, and `IMPLEMENTATION_REVIEWED` distinguished from
|
||||
local commit and external repository mutation authority? [Clarity, Spec
|
||||
§Completion Verdicts]
|
||||
- [x] CHK018 Does the spec avoid implying that a task checkbox, role handoff,
|
||||
receipt, or execution contract grants remote authority? [Safety]
|
||||
|
||||
## Acceptance Criteria Quality
|
||||
|
||||
- [x] CHK019 Can every acceptance criterion be objectively decided from tracked
|
||||
or command evidence? [Measurability, Spec AC-001–AC-015]
|
||||
- [x] CHK020 Do success criteria quantify exhaustive coverage, parity, and zero-
|
||||
extra-ref outcomes? [Measurability, Spec SC-001–SC-005]
|
||||
- [x] CHK021 Is the qualitative handoff outcome for later cutover owners explicit
|
||||
and reviewable? [User value, Spec SC-006]
|
||||
- [x] CHK022 Are failure conditions fail-closed, with partial transfer recorded as
|
||||
`INVALID_PARTIAL_BASELINE` rather than successful or destructively cleaned up?
|
||||
[Consistency, Spec NFR-003]
|
||||
|
||||
## Scenario and Edge-Case Coverage
|
||||
|
||||
- [x] CHK023 Are primary target-proof, inventory, authorized-transfer, and parity
|
||||
flows each independently testable? [Coverage, Spec §User Scenarios]
|
||||
- [x] CHK024 Are unexpected target history, permission failure, source drift,
|
||||
annotated tags, local-only reachability, private refs, and target-integrity
|
||||
exceptions covered? [Coverage, Spec §Edge Cases]
|
||||
- [x] CHK025 Are partial-transfer rollback, evidence preservation, source/local
|
||||
no-change, and no-delete/no-recreate requirements documented? [Recovery, Spec
|
||||
§External Mutation Boundary]
|
||||
- [x] CHK026 Is post-integration `platform-dev` reconciliation explicitly deferred
|
||||
to Spec 463 or another approved follow-up rather than claimed complete by the
|
||||
pre-integration candidate? [Coverage, Spec FR-036]
|
||||
|
||||
## Constitution and Governance Alignment
|
||||
|
||||
- [x] CHK027 Does the Spec Candidate Check include all mandatory rubric fields,
|
||||
one approval class, score, red-flag defense, and scope-reduction decision?
|
||||
[SPEC-GATE-001]
|
||||
- [x] CHK028 Does the proportionality review justify the evidence artifacts and
|
||||
disposition vocabulary without creating a shared provider framework?
|
||||
[PROP-001, BLOAT-001]
|
||||
- [x] CHK029 Are completed Specs 416/439/458/459/460/461 explicitly read-only?
|
||||
[Completed-spec guard]
|
||||
- [x] CHK030 Are current five-role local governance and separate root-owned remote
|
||||
activation reconciled with the submitted draft? [Instruction consistency]
|
||||
- [x] CHK031 Is Product Surface/browser/Human Product Sanity N/A handling coherent
|
||||
and non-duplicative? [Product Surface Contract]
|
||||
- [x] CHK032 Are application runtime, workspace/RBAC, OperationRun, provider,
|
||||
database, queue, asset, and deployment impacts truthfully N/A? [Scope]
|
||||
- [x] CHK033 Is the test purpose classified as Heavy-Governance with temporary Git
|
||||
state only, the targeted existing Pest foundation guard, constitution-required
|
||||
Sail Pint, and no hidden application fixture cost? [TEST-GOV-001, Quality Gates]
|
||||
|
||||
## Dependencies and Assumptions
|
||||
|
||||
- [x] CHK034 Are the GitHub target's pre-created state and later revalidation
|
||||
requirement both explicit? [Assumption]
|
||||
- [x] CHK035 Are Gitea reachability, administrative GitHub access, complete
|
||||
write-capable actor/automation enumeration, and retained-branch default
|
||||
assumptions documented? [Assumptions]
|
||||
- [x] CHK036 Are Specs 463–465 clearly deferred instead of hidden inside Spec 462?
|
||||
[Dependency, Scope]
|
||||
- [x] CHK037 Are later user decisions represented as explicit fail-closed gates
|
||||
whose pre-activation verdict cannot be mistaken for implementation completion?
|
||||
[Clarity]
|
||||
|
||||
## Review Outcome
|
||||
|
||||
- [x] CHK038 Review outcome class: `acceptable-special-case` — repository-hosting
|
||||
governance is intentionally outside product UI/runtime.
|
||||
- [x] CHK039 Workflow outcome: `keep` — the passive-copy slice is bounded and its
|
||||
later authority cutovers are separate specs.
|
||||
- [x] CHK040 Final note location: future Spec-462 implementation report and local
|
||||
PR close-out; Product Surface note remains concise N/A.
|
||||
|
||||
## Notes
|
||||
|
||||
- Preparation review found no blocking ambiguity.
|
||||
- “No implementation details” is interpreted proportionally: exact ref, no-force,
|
||||
fresh-bare-clone, freeze, and parity rules are requirements-level safety
|
||||
constraints for this Git migration, not premature application design.
|
||||
- All checklist items pass after preparation alignment with current repository
|
||||
branch, role, quality-gate, and completed-spec rules.
|
||||
@ -0,0 +1,164 @@
|
||||
{
|
||||
"schema_version": 1,
|
||||
"spec": {
|
||||
"id": 462,
|
||||
"slug": "github-repository-bootstrap-git-data-baseline-v1",
|
||||
"path": "specs/462-github-repository-bootstrap-git-data-baseline-v1",
|
||||
"status": "Implemented",
|
||||
"branch": "462-github-repository-bootstrap-git-data-baseline-v1",
|
||||
"branch_family": "repository-wide",
|
||||
"integration_base": "platform-dev",
|
||||
"integration_target": "platform-dev",
|
||||
"diff_baseline": "platform-dev"
|
||||
},
|
||||
"change": {
|
||||
"classifications": [
|
||||
"repository-governance",
|
||||
"git-hosting-bootstrap",
|
||||
"git-data-migration",
|
||||
"external-activation-gated"
|
||||
],
|
||||
"runtime_impact": "none",
|
||||
"product_surface": {
|
||||
"impact": "none",
|
||||
"reason": "No rendered product surface changes."
|
||||
},
|
||||
"browser": {
|
||||
"required": false,
|
||||
"reason": "No rendered product surface changes."
|
||||
},
|
||||
"postgresql": {
|
||||
"required": false,
|
||||
"reason": "No database schema, query, lock, index, or PostgreSQL behavior changes."
|
||||
},
|
||||
"deployment": {
|
||||
"required": false,
|
||||
"reason": "No application deployment behavior changes."
|
||||
}
|
||||
},
|
||||
"scope": {
|
||||
"allow": [
|
||||
{
|
||||
"kind": "prefix",
|
||||
"path": "specs/462-github-repository-bootstrap-git-data-baseline-v1/"
|
||||
}
|
||||
],
|
||||
"deny": [
|
||||
{
|
||||
"kind": "prefix",
|
||||
"path": "apps/platform/"
|
||||
},
|
||||
{
|
||||
"kind": "prefix",
|
||||
"path": "apps/website/"
|
||||
},
|
||||
{
|
||||
"kind": "prefix",
|
||||
"path": ".github/workflows/"
|
||||
},
|
||||
{
|
||||
"kind": "prefix",
|
||||
"path": ".gitea/workflows/"
|
||||
},
|
||||
{
|
||||
"kind": "prefix",
|
||||
"path": ".agent/"
|
||||
},
|
||||
{
|
||||
"kind": "prefix",
|
||||
"path": ".codex/"
|
||||
},
|
||||
{
|
||||
"kind": "prefix",
|
||||
"path": ".specify/"
|
||||
},
|
||||
{
|
||||
"kind": "prefix",
|
||||
"path": "scripts/"
|
||||
},
|
||||
{
|
||||
"kind": "prefix",
|
||||
"path": "docs/"
|
||||
},
|
||||
{
|
||||
"kind": "file",
|
||||
"path": "AGENTS.md"
|
||||
},
|
||||
{
|
||||
"kind": "file",
|
||||
"path": "README.md"
|
||||
},
|
||||
{
|
||||
"kind": "prefix",
|
||||
"path": "specs/416-tenantpilot-agent-skill-layer-v1/"
|
||||
},
|
||||
{
|
||||
"kind": "prefix",
|
||||
"path": "specs/439-branch-topology-local-evidence-truth/"
|
||||
},
|
||||
{
|
||||
"kind": "prefix",
|
||||
"path": "specs/458-codex-agent-foundation-safe-local-finalization/"
|
||||
},
|
||||
{
|
||||
"kind": "prefix",
|
||||
"path": "specs/459-mechanical-agent-quality-gates-validation-routing/"
|
||||
},
|
||||
{
|
||||
"kind": "prefix",
|
||||
"path": "specs/460-post-integration-additive-correction-contract-v1/"
|
||||
},
|
||||
{
|
||||
"kind": "prefix",
|
||||
"path": "specs/461-additive-correction-contract-conformance-repair-v1/"
|
||||
}
|
||||
]
|
||||
},
|
||||
"required_gates": [
|
||||
"spec-package",
|
||||
"diff-scope",
|
||||
"diff-safety",
|
||||
"unicode",
|
||||
"change-validation",
|
||||
"agent-handoff",
|
||||
"implementation-report",
|
||||
"finalization-receipt",
|
||||
"foundation-regression",
|
||||
"git-diff-check",
|
||||
"independent-review"
|
||||
],
|
||||
"declared_na_gates": [
|
||||
{
|
||||
"id": "product-surface",
|
||||
"reason": "No rendered product surface changes."
|
||||
},
|
||||
{
|
||||
"id": "browser",
|
||||
"reason": "No rendered product surface changes."
|
||||
},
|
||||
{
|
||||
"id": "postgresql-lane",
|
||||
"reason": "No database or PostgreSQL-specific behavior changes."
|
||||
},
|
||||
{
|
||||
"id": "migration",
|
||||
"reason": "No database schema changes."
|
||||
},
|
||||
{
|
||||
"id": "provider-runtime",
|
||||
"reason": "No application provider runtime changes."
|
||||
},
|
||||
{
|
||||
"id": "queue-runtime",
|
||||
"reason": "No queue runtime changes."
|
||||
},
|
||||
{
|
||||
"id": "customer-output",
|
||||
"reason": "No customer output changes."
|
||||
},
|
||||
{
|
||||
"id": "deployment",
|
||||
"reason": "No application deployment behavior changes."
|
||||
}
|
||||
]
|
||||
}
|
||||
@ -0,0 +1,341 @@
|
||||
# External Activation Checklist
|
||||
|
||||
Spec 462 preparation itself granted no GitHub or Gitea mutation authority. This
|
||||
checklist records both the historical pre-activation evidence and the separately
|
||||
authorized, completed external activation on 2026-08-02.
|
||||
|
||||
## Current Authority State
|
||||
|
||||
- Local implementation authority: active-spec files only.
|
||||
- External activation authority: `GRANTED_AND_CONSUMED_FOR_EXACT_OPERATION_SET`.
|
||||
- GitHub setting mutation authority: `GRANTED_AND_CONSUMED_ACTIONS_DISABLE_ONLY`.
|
||||
- GitHub ref creation authority: `GRANTED_AND_CONSUMED_EXACT_THREE_HEADS`.
|
||||
- GitHub default-branch mutation authority: `GRANTED_AND_CONSUMED_DEV_ONLY`.
|
||||
- Gitea mutation authority: `NOT_GRANTED`.
|
||||
- Local commit/finalization authority: `NOT_GRANTED`.
|
||||
- Operational verdict: `PASSIVE_BASELINE_VERIFIED`.
|
||||
- GitHub Git state: `VERIFIED_PASSIVE_COPY`.
|
||||
- GitHub PR authority: `NOT_ACTIVE`.
|
||||
- GitHub CI authority: `NOT_ACTIVE`.
|
||||
- GitHub merge authority: `NOT_ACTIVE`.
|
||||
- Gitea authority: `ACTIVE`.
|
||||
|
||||
## Completed External Activation — 2026-08-02
|
||||
|
||||
Status: `PASSIVE_BASELINE_VERIFIED`.
|
||||
|
||||
All commands and responses recorded here are sanitized. No credential, token,
|
||||
device code, private key, secret value, or authenticated header is included.
|
||||
|
||||
### Owner-controlled source freeze
|
||||
|
||||
- Freeze start: `2026-08-02T12:28:27Z`.
|
||||
- Freeze end: `2026-08-02T12:43:01Z`.
|
||||
- Responsible writer/owner: `ahmido`.
|
||||
- Freeze proof: attributable owner attestation that every other human, local or
|
||||
external Git session, agent session, browser/CLI/SSH writer, and automation
|
||||
path was paused and would perform no Gitea ref mutation during the window.
|
||||
- Corroborating read-only enumeration: no collaborators, deploy keys, or
|
||||
webhooks; zero open pull requests; protected `dev` direct push disabled; the
|
||||
four repository workflows declare only `actions: read` and `contents: read`
|
||||
permissions and contain no ref-mutating command.
|
||||
- Freeze-start Gitea inventory: 481 heads, 0 tags; canonical raw `ls-remote`
|
||||
SHA-256
|
||||
`2e09341107651ec553e6287afce3c27d2f17312e8177bd26c40f87b74dec051a`.
|
||||
- Comparison with the reviewed source inventory: exact ref/OID diff 0 bytes;
|
||||
self-describing source-inventory digest
|
||||
`e17dd1ec644abe590706136bebe7722d0b3307bb6b0c6bc0b7fe5e1ae1315fb0`.
|
||||
- Eight complete Gitea captures spanning freeze start, immediately before each
|
||||
push, after each push, and final parity were byte-identical.
|
||||
- Owner attestation was released only after the final equal inventory and target
|
||||
parity checks passed. No uncontrolled writer or unexpected source mutation was
|
||||
observed.
|
||||
|
||||
### Authorized transfer
|
||||
|
||||
- GitHub Actions had been disabled at `2026-08-02T11:55:35Z` as the first and
|
||||
separate authorized mutation and were read-only reverified disabled before
|
||||
transfer, after every ref creation, and after final parity.
|
||||
- Target was reproven immediately before transfer as exact
|
||||
`senadoroahmido-wq/tenantpilot`, `PRIVATE`, `ADMIN`, 0 heads, 0 tags, no default
|
||||
branch, and no initial history.
|
||||
- Accepted immutable transfer-manifest digest:
|
||||
`6b8e763999599572007586b73938c3cbb23f08a38cb11272d0cd8abdeb5dca33`.
|
||||
- Fresh source clone:
|
||||
`/tmp/tenantpilot-spec462-activation.xy3pmQ/source.git`, cloned directly from
|
||||
`git@git.cloudarix.de:ahmido/TenantAtlas.git`; source URL exact, three
|
||||
authorized objects reachable, `git fsck --full` exit 0 with no output.
|
||||
- A temporary authenticated HTTPS GitHub remote existed only in that bare clone.
|
||||
The development clone origin remained
|
||||
`git@git.cloudarix.de:ahmido/TenantAtlas.git` for fetch and push.
|
||||
- Ordered mutations actually executed:
|
||||
1. create `refs/heads/dev` at
|
||||
`55338a88c69044c632cb006b7e7b066fbd2659b9`;
|
||||
2. set GitHub default branch to `dev`;
|
||||
3. create `refs/heads/platform-dev` at
|
||||
`7b99dae113fb24652a079df369d6378ed356f234`;
|
||||
4. create `refs/heads/website-dev` at
|
||||
`af5fa3034133942a4fcd43d5ba3cfdd975795869`.
|
||||
- Tags transferred: 0. Retained heads transferred: 0.
|
||||
- Every push used one exact full refspec. Force, force-with-lease, wildcard,
|
||||
mirror, delete, overwrite, and unlisted-ref semantics were absent.
|
||||
- After every ref creation: the new target OID matched, no other target ref
|
||||
changed, Actions remained disabled, workflow-run count remained 0, and the
|
||||
complete Gitea inventory remained byte-identical.
|
||||
|
||||
### Final passive-copy proof
|
||||
|
||||
- GitHub heads: exactly 3 (`dev`, `platform-dev`, `website-dev`).
|
||||
- GitHub tags: exactly 0.
|
||||
- Default branch: `dev`.
|
||||
- Actions: `DISABLED`; workflow executions: `NOT_TRIGGERED`; workflow-run count:
|
||||
0.
|
||||
- Fresh target clone:
|
||||
`/tmp/tenantpilot-spec462-activation.xy3pmQ/target.git`; exactly 3 heads and 0
|
||||
tags; `git fsck --full` exit 0 with no missing, corrupt, or dangling objects.
|
||||
- OID, tree, parent-count, and subject parity pass for all three authority heads.
|
||||
- Extra/excluded target refs: 0, including archive-only, retained-local-only,
|
||||
local-redundant, stash, Codex, turn-diff, worktree-private, pull, temporary,
|
||||
and the Spec-462 feature branch.
|
||||
- Final GitHub inventory SHA-256:
|
||||
`6c3d6de707c5c3c773feca6fa2b5fa119eb119d309fe0120777068bf1925b5b9`.
|
||||
- Final Gitea inventory SHA-256 remained
|
||||
`2e09341107651ec553e6287afce3c27d2f17312e8177bd26c40f87b74dec051a`.
|
||||
- GitHub passive surfaces: owner only, 0 teams, deploy keys, webhooks,
|
||||
repository workflows, workflow runs, runners, secret names, variable names,
|
||||
environments, releases, and open pull requests. Rulesets and branch protection
|
||||
are unavailable for this private plan and the rule count is 0.
|
||||
- GitHub remains only a verified passive Git-data copy. Gitea remains the active
|
||||
delivery authority; GitHub PR, CI, and merge authority are not active.
|
||||
|
||||
## Read-Only Target Proof
|
||||
|
||||
Status: `TARGET_PREFLIGHT_READY`.
|
||||
|
||||
- Target tuple: `senadoroahmido-wq/tenantpilot`.
|
||||
- HTTPS: `https://github.com/senadoroahmido-wq/tenantpilot.git`.
|
||||
- SSH: `git@github.com:senadoroahmido-wq/tenantpilot.git`.
|
||||
- Required proof before activation: private visibility, administrative
|
||||
permission, zero heads/tags, no initial history, no releases, no open pull
|
||||
requests, no workflow runs, no non-owner collaborators or teams, no deploy
|
||||
keys, no webhooks, no repository workflows, no Rulesets, no branch protection
|
||||
or Required Checks, no runners, secret names only, variable names only, and no
|
||||
environments.
|
||||
- Actions state: `ENABLED_PENDING_AUTHORIZED_DISABLEMENT`.
|
||||
|
||||
### Superseded Target Preflight Evidence - 2026-08-02
|
||||
|
||||
Status: `SUPERSEDED_BY_CURRENT_AUTH`.
|
||||
|
||||
All evidence in this section was collected read-only by the root coordinator and
|
||||
contains no token, credential, secret value, private key material, or raw
|
||||
authenticated header.
|
||||
|
||||
- Authenticated GitHub account: `ahmido2012-eng`.
|
||||
- Auth protocol: SSH.
|
||||
- Auth token: redacted.
|
||||
- Permission note: token scopes were not sufficient for hook query, and the
|
||||
repository itself remained wholly unresolved across GraphQL, REST, and Git.
|
||||
- `gh auth status --hostname github.com`: authenticated account
|
||||
`ahmido2012-eng`; no mutation.
|
||||
- `gh repo view senadoroahmido-wq/tenantpilot --json nameWithOwner,visibility,viewerPermission,defaultBranchRef,isEmpty,isArchived`:
|
||||
exit 1; GraphQL could not resolve repository.
|
||||
- REST GETs under `repos/senadoroahmido-wq/tenantpilot`: HTTP 404 for repo
|
||||
metadata, releases, issues, pulls, workflow runs, collaborators, teams, deploy
|
||||
keys, webhooks, workflows, rulesets, branches, runners, secret names, variable
|
||||
names, environments, and Actions permissions.
|
||||
- `git ls-remote --symref --heads --tags git@github.com:senadoroahmido-wq/tenantpilot.git`:
|
||||
exit 128; repository not found; sanitized error hash
|
||||
`44d07ddc3c69893b8002d9e09642636177dba35ec5df821773b934fd1b05f892`.
|
||||
- `git ls-remote --symref git@github.com:senadoroahmido-wq/tenantpilot.git HEAD`:
|
||||
exit 128; repository not found; sanitized error hash
|
||||
`44d07ddc3c69893b8002d9e09642636177dba35ec5df821773b934fd1b05f892`.
|
||||
- Mutations performed: zero.
|
||||
- Proven target identity: `NOT_PROVEN`.
|
||||
- Proven private visibility: `NOT_PROVEN`.
|
||||
- Proven administrative permission: `NOT_PROVEN`.
|
||||
- Proven empty heads/tags/history: `NOT_PROVEN`.
|
||||
- Proven passive-authority settings: `NOT_PROVEN`.
|
||||
|
||||
### Current Target Preflight Evidence - 2026-08-02
|
||||
|
||||
All evidence in this section was collected read-only by the root coordinator and
|
||||
contains no token, credential, secret value, private key material, raw
|
||||
authenticated header, or ephemeral clone credential metadata.
|
||||
|
||||
- Authenticated GitHub account: `senadoroahmido-wq`.
|
||||
- Auth protocol configured: SSH.
|
||||
- Auth token/scopes: not recorded.
|
||||
- `gh repo view senadoroahmido-wq/tenantpilot --json nameWithOwner,visibility,viewerPermission,defaultBranchRef,isEmpty,isArchived`:
|
||||
exit 0; `nameWithOwner` exact `senadoroahmido-wq/tenantpilot`; visibility
|
||||
`PRIVATE`; viewer permission `ADMIN`; `isEmpty` true; archived false;
|
||||
GraphQL `defaultBranchRef.name` empty.
|
||||
- Sanitized repository metadata SHA-256:
|
||||
`d6c903f57b583c4d8f69cfa0e1fdb74d994575db5871efa84994569bb8838f25`.
|
||||
Proven fields: full name exact, owner exact, private true, visibility private,
|
||||
admin true, archived false, disabled false, size 0, open issues count 0.
|
||||
- Empty-repository placeholder `default_branch`: `main`.
|
||||
- GraphQL default branch: empty.
|
||||
- Initial history/refs: none proven.
|
||||
- Persistent SSH `git ls-remote`: exit 128 because the local SSH identity cannot
|
||||
access this repo; SSH is locally unavailable for activation proof.
|
||||
- Authenticated HTTPS using the non-persistent `gh auth git-credential` helper:
|
||||
`git ls-remote --symref --heads --tags` exit 0 with empty output; output
|
||||
SHA-256 `e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855`.
|
||||
- Authenticated HTTPS using the non-persistent `gh auth git-credential` helper:
|
||||
`git ls-remote --symref ... HEAD` exit 0 with empty output; output SHA-256
|
||||
`e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855`.
|
||||
- Proven read/activation transport for target ref checks: authenticated HTTPS
|
||||
through the non-persistent `gh auth git-credential` helper.
|
||||
- Git configuration mutations: zero.
|
||||
- Remote configuration mutations: zero.
|
||||
- Remote repository mutations: zero.
|
||||
- Releases: empty array; hash
|
||||
`4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945`.
|
||||
- Issues: empty array; hash
|
||||
`4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945`.
|
||||
- Open pull requests: empty array; hash
|
||||
`4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945`.
|
||||
- Workflow runs: total 0; hash
|
||||
`a2790a384d7d281e7395679000c35d27768d89dbd7052f725b8f4688beb59915`.
|
||||
- Collaborators: owner only; non-owner count 0; hash
|
||||
`22d3688c0ae2f9382c355319f448029beb3ae33760b3d8727ab4108f53739087`.
|
||||
- Teams: empty array; hash
|
||||
`4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945`.
|
||||
- Deploy keys: empty array; hash
|
||||
`4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945`.
|
||||
- Webhooks: empty array; hash
|
||||
`4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945`.
|
||||
- Repository workflows: total 0; hash
|
||||
`51da78a4f28ec83978198558b5be95ebec25c44ab19561c168a975e203f0a785`.
|
||||
- Branches: empty array; hash
|
||||
`4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945`.
|
||||
- Runners: total 0; hash
|
||||
`15d67a2c40c7d15b5c983f3fc7731b443f21aa98e462927ef97d22125649780f`.
|
||||
- Secret names: total 0; hash
|
||||
`8cd981a659e02c3591c81d01a25bd2b59e980217dac663b062140e632de8c31a`.
|
||||
- Variable names: total 0; hash
|
||||
`2ce9f1466656cd2968a9bd6da1d4fb3487b394f794ba91ac268708addd0ebb7f`.
|
||||
- Environments: total 0; hash
|
||||
`a96111929536c1533c11cdcbf059a2db0a9520ac1b52fb53d76f7e11e3e906a8`.
|
||||
- Rulesets REST: HTTP 403 with authoritative feature-unavailable message that
|
||||
GitHub Pro or public visibility is required; sanitized response hash
|
||||
`09dee4d2fc3b14ae7cd63bf636f6ce57f414b4f78fbe4a4e67c7a91f66152a54`.
|
||||
Result: `FEATURE_UNAVAILABLE`; for this verified private repo, no configured
|
||||
Ruleset is present.
|
||||
- GraphQL branch protection rules: total 0, nodes empty; hash
|
||||
`b55cdc92d01b163f6e1b383b5ed6dfba198d90dcd5a214ee65a43084400e8c88`.
|
||||
- Required Checks: count 0 because branches are empty and branch protection rule
|
||||
count is 0.
|
||||
- Actions permissions: enabled true, allowed actions `all`, SHA pinning required
|
||||
false; hash
|
||||
`25842d2b9453f8e5fed37a198b9a268cf6aee1225690bf5fb91a89e8542ea718`.
|
||||
- Mutations performed: zero.
|
||||
|
||||
### Historical Target Verdict
|
||||
|
||||
Verdict: `TARGET_PREFLIGHT_READY`.
|
||||
|
||||
FR-001-FR-003, FR-005-FR-006, AC-001-AC-002, and the measurable target
|
||||
preflight invariants pass. FR-004 is not yet satisfied because GitHub Actions are
|
||||
enabled and require separately authorized exact disablement before any ref
|
||||
transfer. No ref transfer, target default-branch mutation, or GitHub setting
|
||||
mutation authority exists from this checklist.
|
||||
|
||||
## Historical Pre-Activation Source and Local Proof
|
||||
|
||||
Status: `US2_PASS`.
|
||||
|
||||
- Source authority: `git@git.cloudarix.de:ahmido/TenantAtlas.git`.
|
||||
- Source inventory digest:
|
||||
`e17dd1ec644abe590706136bebe7722d0b3307bb6b0c6bc0b7fe5e1ae1315fb0`.
|
||||
- Local-only inventory digest:
|
||||
`082dfbb1bc127e7679f0cb9e9866704bb2fa79a9d0e3f36c6dbd7303b20845e3`.
|
||||
- Branch disposition digest:
|
||||
`87c1ccdee500ac82525d575f4f62fc773f116817828106bbde378fe77e8a34b8`.
|
||||
- Required proof before manifest acceptance is complete for read-only refs,
|
||||
fresh bare clone integrity, local-only branch comparison, excluded namespace
|
||||
accounting, verified local retention bundle, and exact digests.
|
||||
- Repeat Gitea `ls-remote` before pre-activation: 481 lines, SHA-256
|
||||
`2e09341107651ec553e6287afce3c27d2f17312e8177bd26c40f87b74dec051a`.
|
||||
- `source-preactivation-drift.diff`: zero bytes against initial source
|
||||
inventory.
|
||||
- Source write freeze: `NOT_STARTED`.
|
||||
- Gitea write-capable authority surfaces required by FR-030 remain
|
||||
`NOT_PROVEN` without an API token and remain a hard activation prerequisite.
|
||||
|
||||
## Historical No-Mutation Manifest Preview
|
||||
|
||||
Status: `PRE_ACTIVATION_READY`.
|
||||
|
||||
The preview is deterministic manifest rendering only. No `git push --dry-run`
|
||||
was executed. No temporary remote was added. Main-clone remotes are unchanged.
|
||||
No GitHub, Gitea, local ref, default-branch, settings, or remote mutation was
|
||||
performed.
|
||||
|
||||
- Manifest digest:
|
||||
`6b8e763999599572007586b73938c3cbb23f08a38cb11272d0cd8abdeb5dca33`.
|
||||
- Authorization: `NOT_GRANTED`; `manifest_authorizes_mutation` false.
|
||||
- Planned head refspecs, in target-ref order:
|
||||
1. `refs/heads/dev:refs/heads/dev` at
|
||||
`55338a88c69044c632cb006b7e7b066fbd2659b9`
|
||||
2. `refs/heads/platform-dev:refs/heads/platform-dev` at
|
||||
`7b99dae113fb24652a079df369d6378ed356f234`
|
||||
3. `refs/heads/website-dev:refs/heads/website-dev` at
|
||||
`af5fa3034133942a4fcd43d5ba3cfdd975795869`
|
||||
- Planned retained server heads: none.
|
||||
- Planned tags: none.
|
||||
- Excluded from transfer: 478 archive-only heads, 71 local-only heads, codex 1,
|
||||
turn-diff 25, pull 0, reflog-only 0, stash 1, temporary 0, worktree-private
|
||||
15.
|
||||
- Excluded identities present in planned refs: 0.
|
||||
- Forbidden semantics: wildcard heads false, force false, delete false, mirror
|
||||
false, overwrite existing target refs false.
|
||||
- Target drift proof: GitHub exact/private/ADMIN/isEmpty true/defaultBranchRef
|
||||
empty; authenticated HTTPS heads/tags output empty, exit 0, SHA-256
|
||||
`e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855`.
|
||||
- Actions state remains enabled/all and requires separate current authorization
|
||||
for disablement before any ref transfer.
|
||||
|
||||
## Historical Reviewed Mutation Set
|
||||
|
||||
These operations were locked until separate current user authorization named
|
||||
the exact reviewed operation set. That authority was later supplied and consumed
|
||||
only as recorded in the completed activation section above:
|
||||
|
||||
1. Disable GitHub Actions if read-only proof shows Actions enabled:
|
||||
`gh api --method PUT repos/senadoroahmido-wq/tenantpilot/actions/permissions -F enabled=false`,
|
||||
then read-only reverify.
|
||||
2. Reprove target emptiness and enumerate/pause every Gitea writer and
|
||||
automation path. The current missing Gitea API token leaves those authority
|
||||
surfaces `NOT_PROVEN`; this is a hard prerequisite and is not waived by later
|
||||
GitHub mutation authority.
|
||||
3. Inside the preserved temporary bare source only, use authenticated HTTPS
|
||||
through ephemeral `gh auth git-credential` and create `dev` with exact
|
||||
refspec `refs/heads/dev:refs/heads/dev`, no force.
|
||||
4. After `dev` exists, set the target default branch:
|
||||
`gh api --method PATCH repos/senadoroahmido-wq/tenantpilot -f default_branch=dev`.
|
||||
5. Create `platform-dev` with exact refspec
|
||||
`refs/heads/platform-dev:refs/heads/platform-dev`, no force.
|
||||
6. Create `website-dev` with exact refspec
|
||||
`refs/heads/website-dev:refs/heads/website-dev`, no force.
|
||||
7. Create no retained heads and no tags.
|
||||
|
||||
The user's GitHub CLI authentication completion is authentication only. It is
|
||||
not separate current authorization for GitHub setting mutation, ref creation, or
|
||||
default-branch mutation. Retained server-ref decision: none.
|
||||
|
||||
No authorization in this checklist permits GitHub PR, issue, workflow, Ruleset,
|
||||
Required Check, runner, secret, variable, environment, release, package,
|
||||
collaborator, team, webhook, deploy-key, visibility, repository deletion,
|
||||
repository recreation, target ref deletion, Gitea metadata migration, Gitea
|
||||
archival, Gitea mutation, local commit, push, pull request, merge, deployment, or
|
||||
promotion.
|
||||
|
||||
## Rollback Boundary
|
||||
|
||||
Before activation, rollback is no action. After any partial or failed authorized
|
||||
transfer, Spec 462 rollback is non-mutating: stop further writes, keep GitHub
|
||||
private with Actions disabled, preserve evidence, record
|
||||
`INVALID_PARTIAL_BASELINE`, and require a separate spec or amendment plus
|
||||
separate current authority for any cleanup.
|
||||
File diff suppressed because it is too large
Load Diff
@ -0,0 +1,197 @@
|
||||
{
|
||||
"artifact": "github-parity-report",
|
||||
"artifact_version": 1,
|
||||
"authority_verdict": {
|
||||
"gitea_authority": "ACTIVE",
|
||||
"github_authority": "VERIFIED_PASSIVE_COPY",
|
||||
"github_ci_authority": "NOT_ACTIVE",
|
||||
"github_merge_authority": "NOT_ACTIVE",
|
||||
"github_pr_authority": "NOT_ACTIVE",
|
||||
"metadata_migration": "NOT_PERFORMED",
|
||||
"post_integration_reconciliation": "DEFERRED_TO_SPEC_463_OR_APPROVED_FOLLOW_UP",
|
||||
"status": "PASSIVE_BASELINE_VERIFIED"
|
||||
},
|
||||
"canonicalization": {
|
||||
"digest_algorithm": "sha256",
|
||||
"digest_input": "pretty sorted jq output from serialization_command, including trailing LF, with digest.value omitted",
|
||||
"line_endings": "LF",
|
||||
"object_key_order": "lexicographic",
|
||||
"ref_array_order": "full_ref_name_ascending",
|
||||
"serialization_command": "jq -S 'del(.digest.value)' ARTIFACT | shasum -a 256"
|
||||
},
|
||||
"digest": {
|
||||
"algorithm": "sha256",
|
||||
"status": "FINAL",
|
||||
"value": "a6062138fefa6bf449f9d378798b1698ed05458ceca450178712446d6787ab9a"
|
||||
},
|
||||
"gitea_source_stability": {
|
||||
"after_raw_ls_remote_sha256": "2e09341107651ec553e6287afce3c27d2f17312e8177bd26c40f87b74dec051a",
|
||||
"before_raw_ls_remote_sha256": "2e09341107651ec553e6287afce3c27d2f17312e8177bd26c40f87b74dec051a",
|
||||
"capture_count": 8,
|
||||
"drift_diff_bytes": 0,
|
||||
"freeze_ended_at_utc": "2026-08-02T12:43:01Z",
|
||||
"freeze_started_at_utc": "2026-08-02T12:28:27Z",
|
||||
"no_mutation_command_log": "PASS_ZERO_GITEA_MUTATION_COMMANDS",
|
||||
"owner_attestation": "ahmido confirmed exclusive writer control for the full transfer window",
|
||||
"settings_unchanged": "PASS_OWNER_CONTROLLED_FREEZE_AND_ZERO_GITEA_MUTATIONS",
|
||||
"status": "PASS"
|
||||
},
|
||||
"github_passive_authority": {
|
||||
"actions_disabled": true,
|
||||
"actions_state": "DISABLED",
|
||||
"branch_protection": "FEATURE_UNAVAILABLE_PRIVATE_REPOSITORY_AND_ZERO_RULES",
|
||||
"collaborators_and_teams": "OWNER_ONLY_AND_ZERO_TEAMS",
|
||||
"default_branch": "dev",
|
||||
"deploy_keys": "EMPTY",
|
||||
"environments": "EMPTY",
|
||||
"issues": "EMPTY",
|
||||
"open_pull_requests": "EMPTY",
|
||||
"packages": "NOT_MIGRATED",
|
||||
"passive_baseline_verified": true,
|
||||
"releases": "EMPTY",
|
||||
"required_checks": "ZERO",
|
||||
"rulesets": "FEATURE_UNAVAILABLE_PRIVATE_REPOSITORY_AND_ZERO_RULES",
|
||||
"runners": "EMPTY",
|
||||
"secrets": "EMPTY_NAMES_ONLY",
|
||||
"target_exact_private_admin": true,
|
||||
"target_repository": "senadoroahmido-wq/tenantpilot",
|
||||
"variables": "EMPTY_NAMES_ONLY",
|
||||
"visibility": "PRIVATE",
|
||||
"webhooks": "EMPTY",
|
||||
"workflow_runs": 0,
|
||||
"workflows": "EMPTY"
|
||||
},
|
||||
"inputs": {
|
||||
"github_transfer_manifest_digest": "6b8e763999599572007586b73938c3cbb23f08a38cb11272d0cd8abdeb5dca33",
|
||||
"source_inventory_digest": "e17dd1ec644abe590706136bebe7722d0b3307bb6b0c6bc0b7fe5e1ae1315fb0",
|
||||
"status": "FINAL"
|
||||
},
|
||||
"local_authority_branches": {
|
||||
"dev": {
|
||||
"oid": "55338a88c69044c632cb006b7e7b066fbd2659b9",
|
||||
"ref": "refs/heads/dev"
|
||||
},
|
||||
"platform_dev": {
|
||||
"oid": "7b99dae113fb24652a079df369d6378ed356f234",
|
||||
"ref": "refs/heads/platform-dev"
|
||||
},
|
||||
"website_dev": {
|
||||
"oid": "af5fa3034133942a4fcd43d5ba3cfdd975795869",
|
||||
"ref": "refs/heads/website-dev"
|
||||
}
|
||||
},
|
||||
"origin_remote_check": {
|
||||
"after": "origin git@git.cloudarix.de:ahmido/TenantAtlas.git (fetch/push)",
|
||||
"before": "origin git@git.cloudarix.de:ahmido/TenantAtlas.git (fetch/push)",
|
||||
"main_clone_remote_changed": false,
|
||||
"status": "UNCHANGED_POST_TRANSFER"
|
||||
},
|
||||
"parity": {
|
||||
"authority_branch_tree_checks": [
|
||||
{
|
||||
"commit_oid": "55338a88c69044c632cb006b7e7b066fbd2659b9",
|
||||
"parent_count": 1,
|
||||
"ref": "refs/heads/dev",
|
||||
"status": "OID_TREE_METADATA_MATCH",
|
||||
"subject": "merge: platform-dev into dev (#311)",
|
||||
"tree_oid": "75c87269c5d8fd22930fd90732dcd348ee07d335"
|
||||
},
|
||||
{
|
||||
"commit_oid": "7b99dae113fb24652a079df369d6378ed356f234",
|
||||
"parent_count": 1,
|
||||
"ref": "refs/heads/platform-dev",
|
||||
"status": "OID_TREE_METADATA_MATCH",
|
||||
"subject": "fix: stabilize Spec 459 package validation self-test (#527)",
|
||||
"tree_oid": "2b1a0bf306b07841ccf63a19e076529f23913d4e"
|
||||
},
|
||||
{
|
||||
"commit_oid": "af5fa3034133942a4fcd43d5ba3cfdd975795869",
|
||||
"parent_count": 1,
|
||||
"ref": "refs/heads/website-dev",
|
||||
"status": "OID_TREE_METADATA_MATCH",
|
||||
"subject": "410: add public docs information architecture (#412)",
|
||||
"tree_oid": "93923bc80dc5d20ae4b304bea12f32b10fcab73b"
|
||||
}
|
||||
],
|
||||
"excluded_ref_classes_present": [],
|
||||
"extra_target_refs": [],
|
||||
"head_count": 3,
|
||||
"post_transfer_parity_claimed": true,
|
||||
"ref_oid_comparisons": [
|
||||
{
|
||||
"manifest_oid": "55338a88c69044c632cb006b7e7b066fbd2659b9",
|
||||
"ref": "refs/heads/dev",
|
||||
"source_oid": "55338a88c69044c632cb006b7e7b066fbd2659b9",
|
||||
"status": "OID_MATCH",
|
||||
"target_oid": "55338a88c69044c632cb006b7e7b066fbd2659b9"
|
||||
},
|
||||
{
|
||||
"manifest_oid": "7b99dae113fb24652a079df369d6378ed356f234",
|
||||
"ref": "refs/heads/platform-dev",
|
||||
"source_oid": "7b99dae113fb24652a079df369d6378ed356f234",
|
||||
"status": "OID_MATCH",
|
||||
"target_oid": "7b99dae113fb24652a079df369d6378ed356f234"
|
||||
},
|
||||
{
|
||||
"manifest_oid": "af5fa3034133942a4fcd43d5ba3cfdd975795869",
|
||||
"ref": "refs/heads/website-dev",
|
||||
"source_oid": "af5fa3034133942a4fcd43d5ba3cfdd975795869",
|
||||
"status": "OID_MATCH",
|
||||
"target_oid": "af5fa3034133942a4fcd43d5ba3cfdd975795869"
|
||||
}
|
||||
],
|
||||
"status": "PASS",
|
||||
"tag_count": 0
|
||||
},
|
||||
"rollback_readiness": {
|
||||
"cleanup_mutation_allowed": false,
|
||||
"delete_target_refs_allowed": false,
|
||||
"invalid_partial_baseline_verdict": "AVAILABLE_AFTER_PARTIAL_OR_FAILED_AUTHORIZED_TRANSFER",
|
||||
"repository_recreation_allowed": false,
|
||||
"status": "PASS_NOT_NEEDED"
|
||||
},
|
||||
"schema_version": 1,
|
||||
"spec": {
|
||||
"baseline": "platform-dev",
|
||||
"branch": "462-github-repository-bootstrap-git-data-baseline-v1",
|
||||
"id": 462,
|
||||
"path": "specs/462-github-repository-bootstrap-git-data-baseline-v1"
|
||||
},
|
||||
"status": "PASSIVE_BASELINE_VERIFIED",
|
||||
"target_integrity": {
|
||||
"default_branch_dev_claimed": true,
|
||||
"fresh_bare_clone": "/tmp/tenantpilot-spec462-activation.xy3pmQ/target.git",
|
||||
"fresh_bare_clone_fsck_full": "PASS",
|
||||
"missing_or_corrupt_objects": 0,
|
||||
"post_transfer_target_clone_integrity_claimed": true,
|
||||
"status": "PASS"
|
||||
},
|
||||
"transfer": {
|
||||
"actions_disabled_at_utc": "2026-08-02T11:55:35Z",
|
||||
"forbidden_semantics": {
|
||||
"delete": false,
|
||||
"force": false,
|
||||
"mirror": false,
|
||||
"overwrite": false,
|
||||
"wildcard": false
|
||||
},
|
||||
"heads_transferred": 3,
|
||||
"ordered_mutations": [
|
||||
"disable_github_actions",
|
||||
"create_refs_heads_dev",
|
||||
"set_default_branch_dev",
|
||||
"create_refs_heads_platform_dev",
|
||||
"create_refs_heads_website_dev"
|
||||
],
|
||||
"source_bare_clone": "/tmp/tenantpilot-spec462-activation.xy3pmQ/source.git",
|
||||
"tags_transferred": 0,
|
||||
"transport": "authenticated HTTPS through non-persistent gh auth git-credential helper",
|
||||
"workflow_execution": "NOT_TRIGGERED",
|
||||
"workflow_runs_after": 0,
|
||||
"workflow_runs_before": 0
|
||||
},
|
||||
"worktree_state": {
|
||||
"index": "EMPTY",
|
||||
"staged_changes": "none"
|
||||
}
|
||||
}
|
||||
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
@ -0,0 +1,444 @@
|
||||
# Implementation Plan: GitHub Repository Bootstrap and Git Data Baseline v1
|
||||
|
||||
**Branch**: `462-github-repository-bootstrap-git-data-baseline-v1`
|
||||
**Date**: 2026-08-01
|
||||
**Spec**: `specs/462-github-repository-bootstrap-git-data-baseline-v1/spec.md`
|
||||
**Status**: Implemented
|
||||
**Integration base / target / diff baseline**: `platform-dev`
|
||||
|
||||
## Summary
|
||||
|
||||
Prepare and execute one bounded repository-governance migration that makes the
|
||||
existing private GitHub repository a verified passive Git copy of authoritative
|
||||
Gitea data. The implementation inventories all server and local-only refs,
|
||||
classifies every ref, builds an exact transfer allowlist, crosses a separately
|
||||
authorized GitHub activation boundary from a fresh temporary bare clone, and
|
||||
proves exact parity while leaving all active delivery authority on Gitea.
|
||||
|
||||
No application runtime, application test, workflow, UI, website, database,
|
||||
deployment, or shared agent infrastructure is changed. Every tracked
|
||||
implementation artifact remains under the active Spec-462 directory.
|
||||
|
||||
## Technical Context
|
||||
|
||||
- **Repository root**:
|
||||
`/Users/ahmeddarrazi/Documents/projects/wt-plattform`
|
||||
- **Source Git host**: Gitea repository
|
||||
`git@git.cloudarix.de:ahmido/TenantAtlas.git`
|
||||
- **Target Git host**: private GitHub repository
|
||||
`senadoroahmido-wq/tenantpilot`
|
||||
- **Local Git**: 2.50.1
|
||||
- **GitHub CLI**: 2.92.0; authentication and target permissions must be
|
||||
revalidated immediately before activation
|
||||
- **JSON tooling**: jq 1.7.1
|
||||
- **Digest tooling**: `/usr/bin/shasum -a 256`
|
||||
- **Current origin**: Gitea for fetch and push; it remains unchanged
|
||||
- **Application technologies**: unchanged and not exercised by this spec
|
||||
- **Validation scale**: one deterministic run covers 100% of the actual repository
|
||||
ref set and records ref counts plus elapsed duration; no application latency SLO
|
||||
or application test lane applies
|
||||
- **Constraints**: exact refs only, no mirror/force/delete, no source mutation,
|
||||
no main-worktree remote change, no branch convergence, no credential capture
|
||||
|
||||
## Preparation Decisions
|
||||
|
||||
### Candidate selection
|
||||
|
||||
The user directly supplied Spec 462. No local/remote Spec-462 branch or spec
|
||||
package existed, and no related spec duplicates the passive-copy slice. Specs
|
||||
463–465 remain independent delivery-authority cutovers.
|
||||
|
||||
### Branch topology
|
||||
|
||||
This is repository-wide/cross-stream governance performed from the platform
|
||||
stream. The feature starts from, targets, and diffs against `platform-dev`.
|
||||
`dev` remains repository-wide integration/promotion authority but is not the
|
||||
feature target.
|
||||
|
||||
### Completed-spec protection
|
||||
|
||||
Specs 416, 439, 458, 459, 460, and 461 are read-only source evidence. Their
|
||||
specs, tasks, validation history, and implementation reports must not change.
|
||||
|
||||
### Submitted-draft deviation
|
||||
|
||||
The user draft proposed a single-owner flow without a validator. Current
|
||||
`AGENTS.md` requires the fixed Spec-458 roles for repository-governance work.
|
||||
Local candidate work therefore uses the current ordered handoff:
|
||||
|
||||
```text
|
||||
code_explorer -> implementer -> test_validator -> code_reviewer -> git_finalizer
|
||||
```
|
||||
|
||||
The root coordinator owns orchestration and all remote Git network operations,
|
||||
including source queries and temporary cloning. It may cross the external GitHub
|
||||
mutation boundary only after separate current user authorization. No role,
|
||||
handoff, execution contract, or local finalization receipt grants remote
|
||||
authority.
|
||||
|
||||
## Constitution Check
|
||||
|
||||
### Pre-design gate
|
||||
|
||||
| Principle | Result | Evidence / handling |
|
||||
|---|---|---|
|
||||
| Spec-first and branch routing | PASS | Explicit repository-wide class with `platform-dev` base/target/baseline |
|
||||
| SPEC-GATE-001 | PASS | Core Enterprise, 8/12 after passive-copy scope reduction |
|
||||
| PROP/BLOAT/ABSTR | PASS | Finite migration evidence and dispositions; no shared framework or runtime taxonomy |
|
||||
| Read/write separation | PASS WITH MANUAL GATE | All GitHub mutations are separated from preparation and require exact current authorization |
|
||||
| Persisted truth | PASS | Tracked artifacts are auditable migration truth; no application persistence |
|
||||
| State consequence | PASS | Dispositions directly decide transfer eligibility or retention |
|
||||
| Test governance | PASS | Heavy-Governance Git evidence plus the targeted existing Pest foundation guard and constitution-required Sail Pint; no application/browser/database fixture cost |
|
||||
| Product Surface | PASS / N/A | No rendered product surface |
|
||||
| Workspace/RBAC/OperationRun/provider | PASS / N/A | No application boundary touched |
|
||||
| Completed-spec guard | PASS | Related completed/implemented specs are read-only |
|
||||
| No legacy / no dual write | PASS | Staged hard cutover; GitHub remains passive |
|
||||
|
||||
No constitution violation requires an exception.
|
||||
|
||||
### Post-design recheck
|
||||
|
||||
The design keeps one evidence path, one finite disposition model, one exact
|
||||
manifest, and one parity report. No data model, API contract, application layer,
|
||||
package dependency, shared repository tool, or Product Surface concept is added.
|
||||
The constitution gate remains PASS with the external activation condition.
|
||||
|
||||
## Scope and Repository Surfaces
|
||||
|
||||
### Allowed tracked scope
|
||||
|
||||
```text
|
||||
specs/462-github-repository-bootstrap-git-data-baseline-v1/**
|
||||
```
|
||||
|
||||
Preparation artifacts:
|
||||
|
||||
```text
|
||||
spec.md
|
||||
plan.md
|
||||
tasks.md
|
||||
research.md
|
||||
quickstart.md
|
||||
checklists/requirements.md
|
||||
execution-contract.json
|
||||
```
|
||||
|
||||
Implementation/activation evidence:
|
||||
|
||||
```text
|
||||
git-source-ref-inventory.json
|
||||
local-only-ref-inventory.json
|
||||
branch-disposition.json
|
||||
github-transfer-manifest.json
|
||||
github-parity-report.json
|
||||
external-activation-checklist.md
|
||||
implementation-report.md
|
||||
```
|
||||
|
||||
Spec-local deterministic helpers and self-tests may be added only when the
|
||||
implementation proves documented Git/jq commands cannot produce or validate the
|
||||
artifacts safely. Shared `scripts/**` changes require a separate spec.
|
||||
|
||||
### Denied repository scope
|
||||
|
||||
- `apps/platform/**`
|
||||
- `apps/website/**`
|
||||
- `.github/workflows/**`
|
||||
- `.gitea/workflows/**`
|
||||
- `.agent/**`
|
||||
- `.codex/**`
|
||||
- `.specify/**`
|
||||
- `scripts/**`
|
||||
- `docs/**`
|
||||
- `AGENTS.md`
|
||||
- `README.md`
|
||||
- Specs 416, 439, 458, 459, 460, and 461
|
||||
- every path outside the active Spec-462 directory
|
||||
|
||||
### External mutation allowlist
|
||||
|
||||
After separate current user authorization only:
|
||||
|
||||
1. disable GitHub Actions;
|
||||
2. create exact GitHub refs listed in the reviewed transfer manifest;
|
||||
3. set GitHub default branch to `dev` after `dev` exists.
|
||||
|
||||
Visibility, owner/name, collaboration, Rulesets, branch protection, webhooks,
|
||||
secrets, variables, environments, runners, workflows, issues, pull requests,
|
||||
releases, packages, and all Gitea state are denied.
|
||||
Target ref/repository deletion or recreation is also denied; Spec-462 rollback is
|
||||
non-mutating.
|
||||
|
||||
## Data and Evidence Design
|
||||
|
||||
### Source inventory
|
||||
|
||||
`git-source-ref-inventory.json` is a canonical snapshot of the authoritative
|
||||
Gitea repository at the freeze boundary. It records repository identity,
|
||||
default branch, source HEAD, heads/tags/peeled tag objects, counts, capture time,
|
||||
and digest. Arrays are sorted by full ref name before hashing.
|
||||
|
||||
### Local-only inventory
|
||||
|
||||
`local-only-ref-inventory.json` compares local heads with authoritative Gitea
|
||||
heads. For every local-only branch it records tip OID, reachability, unique commit
|
||||
count, merge bases to each authority branch, disposition, reason, and retention
|
||||
evidence. Local-only heads are limited to `RETAIN_LOCAL_ONLY` or
|
||||
`LOCAL_REDUNDANT`; publishing them is outside this slice. Stash/Codex/worktree/
|
||||
private namespaces are listed only as excluded ref identities and counts;
|
||||
secrets are never serialized.
|
||||
|
||||
### Branch disposition
|
||||
|
||||
`branch-disposition.json` is exhaustive and one-to-one. It separates Gitea heads,
|
||||
local-only heads, and excluded non-authority namespaces. Totals must reconcile
|
||||
with the inventory. `MIGRATE_RETAINED` entries are authoritative Gitea server
|
||||
heads only and include explicit approval evidence without embedding raw user
|
||||
prompts or credentials.
|
||||
|
||||
### Transfer manifest
|
||||
|
||||
`github-transfer-manifest.json` binds the target tuple, source inventory digest,
|
||||
disposition digest, exact selected ref names/OIDs, all source tags, excluded
|
||||
namespaces, and a manifest digest. It authorizes no wildcard refspec.
|
||||
|
||||
### Parity report
|
||||
|
||||
`github-parity-report.json` binds the accepted manifest and records every
|
||||
source/target OID comparison, authority-branch tree/parent proof, target extra-ref
|
||||
set, target clone integrity, source stability, default branch, visibility,
|
||||
Actions state, all readable passive-authority invariants, before/after readable
|
||||
Gitea authority surfaces, origin-remoteness check, and authority verdict. An
|
||||
unreadable required invariant is recorded as `NOT_PROVEN` and prevents a PASS.
|
||||
|
||||
### No application data model or API contracts
|
||||
|
||||
`data-model.md` and `contracts/` are intentionally omitted. The feature creates
|
||||
no application entity, database schema, HTTP/API contract, event contract, or
|
||||
runtime state machine. The bounded JSON artifact shapes above are migration
|
||||
evidence and are specified directly in the active plan/spec.
|
||||
|
||||
## Technical Approach
|
||||
|
||||
### 1. Local preflight and candidate identity
|
||||
|
||||
- prove the feature branch began at the recorded clean `platform-dev` HEAD;
|
||||
- run the active Spec Package preflight before implementation writes;
|
||||
- verify the exact active-spec allowlist and completed-spec protection;
|
||||
- record source origin and installed tool versions without changing remotes.
|
||||
|
||||
### 2. Target read-only verification
|
||||
|
||||
Use authenticated GitHub metadata and Git ref queries to prove exact owner/name,
|
||||
private visibility, administrator permission, zero heads/tags/releases, current
|
||||
Actions state, open pull requests/workflow runs, collaborators/teams, deploy keys,
|
||||
webhooks, workflows, Rulesets, branch protection/Required Checks, runners,
|
||||
secrets, variables, and environments. Secret values are never queried or
|
||||
recorded. If any target ref or initial history exists, stop for a spec amendment.
|
||||
If Actions is enabled but its state is verifiable, record
|
||||
`TARGET_PREFLIGHT_READY`; US1 does not PASS until the authorized disablement is
|
||||
verified.
|
||||
|
||||
### 3. Authoritative source capture
|
||||
|
||||
The root coordinator queries Gitea with `git ls-remote --symref` and creates a
|
||||
fresh temporary bare clone outside the repository. It reconciles every server
|
||||
tag against the bare clone and, if necessary, fetches exact missing tag refs into
|
||||
that temporary clone before the manifest is frozen. Canonicalize heads and tags,
|
||||
preserve annotated tag object/peeled OIDs, sort deterministically, and hash the
|
||||
stable representation. Capture the readable Gitea default branch, repository
|
||||
settings, branch protections, hooks, deploy keys, collaborators/teams, workflows,
|
||||
and delivery-authority posture plus a no-mutation command/API log baseline; any
|
||||
required but unreadable surface is `NOT_PROVEN`.
|
||||
|
||||
### 4. Local-only reachability analysis
|
||||
|
||||
Compare local heads against authoritative Gitea refs using exact OIDs and graph
|
||||
reachability. Account for commits reachable only from local heads or excluded
|
||||
namespaces. Do not delete, rewrite, merge, or publish any local ref.
|
||||
|
||||
### 5. Disposition and manifest review
|
||||
|
||||
Default non-authority server heads to `ARCHIVE_ONLY`; assign only the three
|
||||
authority branches to `MIGRATE_ACTIVE`. `MIGRATE_RETAINED` remains empty unless
|
||||
the user approves exact authoritative Gitea server refs. Local-only refs are
|
||||
never manifest inputs. Reconcile counts/digests and perform a no-mutation refspec
|
||||
preview.
|
||||
|
||||
### 6. External activation gate
|
||||
|
||||
Present the exact target setting mutations and exact ref list/OIDs to the user.
|
||||
Without a new current authorization, stop at `PRE_ACTIVATION_READY`; this is not
|
||||
implementation completion and cannot issue a completion/finalization receipt.
|
||||
With authority:
|
||||
|
||||
- disable Actions;
|
||||
- re-prove target emptiness;
|
||||
- enumerate every Gitea write-capable human/automation path, record attributable
|
||||
pause confirmation, and begin the source freeze;
|
||||
- refresh inventory and invalidate the manifest on any drift.
|
||||
|
||||
If any writer cannot be enumerated, controlled, or paused, stop. Spec 462 does
|
||||
not mutate Gitea settings to create an enforceable freeze.
|
||||
|
||||
### 7. Bare-clone transfer
|
||||
|
||||
Within the temporary bare source clone only, add a temporary target remote and
|
||||
create refs in this order: `dev`, set default branch to `dev`, `platform-dev`,
|
||||
`website-dev`, approved retained Gitea server heads, then tags. Every command uses
|
||||
an exact refspec and no force/delete/mirror option.
|
||||
|
||||
### 8. Parity and authority proof
|
||||
|
||||
Requery source and target refs, compare exact OIDs and authority trees, prove no
|
||||
extras/exclusions, clone GitHub freshly and run full integrity validation, verify
|
||||
every readable GitHub passive-authority invariant, compare the readable Gitea
|
||||
authority/settings snapshot, and confirm the main clone origin remains Gitea.
|
||||
End the logical freeze only after source stability and all writer pause/release
|
||||
evidence are proven. Any unreadable required surface blocks the authority verdict.
|
||||
|
||||
### 9. Candidate validation, review, and local finalization boundary
|
||||
|
||||
Freeze tracked evidence, run routed candidate checks, perform independent
|
||||
validation and complete-diff review, remediate only confirmed in-scope findings,
|
||||
and rerun affected checks/review. Local commit finalization occurs only through
|
||||
the current safe helper with a valid receipt and separate commit authority.
|
||||
|
||||
### 10. Post-integration boundary
|
||||
|
||||
Spec 462 stops before post-integration reconciliation. Spec 463 or another
|
||||
explicitly approved follow-up must compare the integrated Gitea `platform-dev`
|
||||
OID, obtain exact current authorization for any target update, and repeat full
|
||||
parity/passivity proof before a delivery-authority cutover. Spec-462 validation
|
||||
must not claim that later operation is complete.
|
||||
|
||||
## Security and Authority Controls
|
||||
|
||||
- Exact GitHub owner/repository/visibility and admin permission are fail-closed.
|
||||
- No credential, token, private key, authenticated header, or raw CLI auth output
|
||||
is written to tracked evidence.
|
||||
- Target refs must be absent before creation.
|
||||
- No command may contain `--mirror`, `--force`, `--force-with-lease`, deletion
|
||||
refspecs, or wildcard head authorization.
|
||||
- The current clone's remotes are captured before and after and must be identical.
|
||||
- Temporary paths are explicit, outside the repository, and removed only after
|
||||
evidence and rollback readiness are complete.
|
||||
- External activation requires current attributable user authorization distinct
|
||||
from implementation and local commit authority. Spec-462 rollback is
|
||||
non-mutating; cleanup or target deletion/recreation requires a scope amendment
|
||||
or separate spec plus separate current authority.
|
||||
|
||||
## Validation Strategy
|
||||
|
||||
### Preparation validation
|
||||
|
||||
- Spec package readiness validation.
|
||||
- Cross-artifact consistency analysis.
|
||||
- Requirements checklist completion.
|
||||
- JSON schema validation for `execution-contract.json`.
|
||||
- `git diff --check` and active-spec-only status review.
|
||||
|
||||
### Implementation validation
|
||||
|
||||
- Canonical JSON parse/sort/hash checks.
|
||||
- Inventory/disposition/manifest count reconciliation.
|
||||
- Exact ref allowlist and forbidden-option assertions.
|
||||
- Source freeze before/after digest equality.
|
||||
- Source/target OID and authority tree comparison.
|
||||
- Target extra/excluded-ref checks.
|
||||
- Fresh bare target clone plus `git fsck --full`.
|
||||
- Target settings and main-origin invariants.
|
||||
- Current quality-gate candidate/completion workflow and independent review.
|
||||
- Targeted constitutional Pest validation:
|
||||
`cd apps/platform && ./vendor/bin/sail artisan test --compact tests/Feature/Guards/CodexAgentFoundationContractTest.php`.
|
||||
- Constitution-required finalization formatting check:
|
||||
`cd apps/platform && ./vendor/bin/sail bin pint --dirty --format agent`.
|
||||
|
||||
### Application lanes
|
||||
|
||||
- Livewire v4 compliance: unchanged; no Livewire code.
|
||||
- Provider registration: unchanged at `apps/platform/bootstrap/providers.php`.
|
||||
- Global search: no resources changed.
|
||||
- Destructive/high-impact product actions: none.
|
||||
- Asset strategy: no assets; `filament:assets` not required.
|
||||
- The existing Pest foundation guard above is required as a targeted
|
||||
Heavy-Governance constitutional check. No new or modified application test is
|
||||
added.
|
||||
- Platform feature, website, PostgreSQL, and browser lanes: N/A unless routing
|
||||
unexpectedly detects an out-of-scope change, which is a stop condition rather
|
||||
than a reason to broaden scope.
|
||||
- Deployment impact: none for env, migrations, queues, scheduler, storage, assets,
|
||||
Dokploy, staging, or production.
|
||||
|
||||
## Rollback Strategy
|
||||
|
||||
Before transfer, rollback is no action. After a partial transfer, Spec-462
|
||||
rollback stops further writes, keeps GitHub private and Actions disabled,
|
||||
preserves all evidence, records `INVALID_PARTIAL_BASELINE`, and leaves Gitea,
|
||||
local refs/worktrees/remotes, and existing target evidence untouched. It never
|
||||
deletes a target ref or recreates the repository. Cleanup is separate scoped work
|
||||
with separate authority. If parity fails, GitHub must not be described as a valid
|
||||
passive baseline.
|
||||
|
||||
## Risk Controls
|
||||
|
||||
| Risk | Control | Stop condition |
|
||||
|---|---|---|
|
||||
| Wrong/non-empty target | exact metadata/ref preflight | any unexpected identity/ref/history |
|
||||
| Source drift | freeze and three inventory points | any digest difference |
|
||||
| Local/private ref leakage | fresh bare source and exact manifest | any unlisted refspec |
|
||||
| Historical branch pollution | default `ARCHIVE_ONLY` | missing or duplicate disposition |
|
||||
| Local commit loss | reachability inventory and bundle plan | unaccounted unique commit |
|
||||
| Workflow execution | Actions disabled before/after | Actions cannot be proven disabled |
|
||||
| Dual authority | no PR/CI/merge/remote cutover | any delivery activation |
|
||||
| Evidence mismatch | digest-bound artifacts and review | any OID/count/hash mismatch |
|
||||
| Uncontrolled source writer | writer/automation inventory plus attributable pause proof | any writer cannot be enumerated, controlled, or paused |
|
||||
| Destructive rollback pressure | non-mutating invalid-baseline verdict | any cleanup/delete/recreate proposal without amended scope |
|
||||
|
||||
## Implementation Phases
|
||||
|
||||
1. **Preflight**: branch, base, active package, completed-spec guard, tool/source
|
||||
identity, and quality-gate preflight.
|
||||
2. **Target proof**: read-only target identity, privacy, access, emptiness, and
|
||||
Actions evidence.
|
||||
3. **Source/local inventory**: authoritative refs, local-only reachability, unique
|
||||
commits, and retention boundary.
|
||||
4. **Disposition/manifest**: exhaustive classifications, exact transfer list,
|
||||
hashes, and no-mutation preview.
|
||||
5. **External activation**: explicit authorization, Actions disablement, target
|
||||
recheck, freeze, and refreshed inventory.
|
||||
6. **Transfer**: fresh bare source, exact non-force ref creation, and default
|
||||
branch.
|
||||
7. **Parity/rollback**: target/source verification, fresh clone integrity,
|
||||
passivity, unfreeze, and non-mutating invalid-baseline readiness.
|
||||
8. **Evidence/review**: implementation report, routed gates, independent
|
||||
validation/review, bounded corrections, and local commit boundary.
|
||||
9. **Follow-up handoff**: stop before post-integration reconciliation and hand
|
||||
that separately authorized responsibility to Spec 463 or another approved
|
||||
follow-up.
|
||||
|
||||
## Agent Context Update Decision
|
||||
|
||||
`.specify/scripts/bash/update-agent-context.sh codex` is not run for this feature.
|
||||
The plan introduces no new application technology, and that script would modify
|
||||
`AGENTS.md`, which is explicitly outside the active Spec-462 allowlist. Existing
|
||||
active technology context remains authoritative.
|
||||
|
||||
## Complexity Tracking
|
||||
|
||||
| Introduced structure | Why needed now | Narrower alternative rejected because |
|
||||
|---|---|---|
|
||||
| Finite ref-disposition vocabulary | each discovered ref needs a deterministic transfer/retention consequence | implicit branch-name rules cannot prove exhaustive coverage |
|
||||
| Digest-bound JSON evidence | later cutover owners need reproducible migration truth | prose logs cannot prove complete/OID-exact parity |
|
||||
|
||||
No shared abstraction or long-lived multi-provider synchronization layer is
|
||||
introduced.
|
||||
|
||||
## Final Plan Gate
|
||||
|
||||
The plan is implementation-ready with one external activation condition: no
|
||||
GitHub mutation occurs until the user supplies separate current authorization for
|
||||
the exact reviewed setting/ref operations. Without it, the maximum truthful
|
||||
verdict is `PRE_ACTIVATION_READY`, no completion/finalization receipt is issued,
|
||||
and the feature is not claimed implemented. No unresolved technical or product
|
||||
question requires scope invention.
|
||||
@ -0,0 +1,199 @@
|
||||
# Quickstart: GitHub Repository Bootstrap and Git Data Baseline v1
|
||||
|
||||
This quickstart defines the implementation and validation sequence. It is not an
|
||||
authorization to mutate GitHub or Gitea. Stop at the external activation boundary
|
||||
unless the user grants current, exact authority for the reviewed operations.
|
||||
|
||||
## 1. Confirm active package and repository state
|
||||
|
||||
```bash
|
||||
git branch --show-current
|
||||
git rev-parse HEAD
|
||||
git status --short --branch
|
||||
git remote -v
|
||||
scripts/run-agent-quality-gates preflight --spec specs/462-github-repository-bootstrap-git-data-baseline-v1
|
||||
```
|
||||
|
||||
Expected preparation identity:
|
||||
|
||||
```text
|
||||
branch: 462-github-repository-bootstrap-git-data-baseline-v1
|
||||
base/target/baseline: platform-dev
|
||||
tracked scope: specs/462-github-repository-bootstrap-git-data-baseline-v1/**
|
||||
origin: git@git.cloudarix.de:ahmido/TenantAtlas.git
|
||||
```
|
||||
|
||||
Any unrelated dirty path, branch mismatch, missing package artifact, or completed-
|
||||
spec change is a hard stop.
|
||||
|
||||
## 2. Run read-only target preflight
|
||||
|
||||
Use GitHub CLI metadata and API queries plus `git ls-remote` to prove:
|
||||
|
||||
- `nameWithOwner` equals `senadoroahmido-wq/tenantpilot`;
|
||||
- visibility is private;
|
||||
- viewer permission is administrative;
|
||||
- heads and tags are empty;
|
||||
- there is no initial commit or release;
|
||||
- Actions state is known;
|
||||
- there are zero open pull requests/workflow runs/non-owner collaborators/teams;
|
||||
- no deploy keys, webhooks, repository workflows, Rulesets, branch protection,
|
||||
Required Checks, runners, secrets, variables, or environments are configured.
|
||||
|
||||
Read-only examples:
|
||||
|
||||
```bash
|
||||
gh auth status
|
||||
gh repo view senadoroahmido-wq/tenantpilot --json nameWithOwner,visibility,viewerPermission,defaultBranchRef
|
||||
gh api repos/senadoroahmido-wq/tenantpilot/actions/permissions
|
||||
git ls-remote --heads --tags git@github.com:senadoroahmido-wq/tenantpilot.git
|
||||
```
|
||||
|
||||
Do not capture tokens or full authenticated headers. Any unexpected target ref or
|
||||
history or unreadable required passive-authority invariant requires a spec
|
||||
amendment before activation. If Actions is enabled but verifiable, record
|
||||
`TARGET_PREFLIGHT_READY`; do not claim US1 PASS.
|
||||
|
||||
## 3. Capture authoritative source inventory
|
||||
|
||||
Create a temporary directory outside the repository with `mktemp -d`. Query the
|
||||
Gitea source with `git ls-remote --symref --heads --tags`, create a fresh bare
|
||||
clone, sort refs by full name, record annotated/peeled tag OIDs, reconcile counts,
|
||||
and write the canonical evidence artifact. Also capture every readable FR-030
|
||||
Gitea authority/settings surface and a redacted no-mutation command/API baseline;
|
||||
an unreadable required surface is `NOT_PROVEN`.
|
||||
|
||||
```bash
|
||||
TP462_TMP_DIR="$(mktemp -d /tmp/tenantpilot-spec462.XXXXXX)"
|
||||
git ls-remote --symref --heads --tags git@git.cloudarix.de:ahmido/TenantAtlas.git
|
||||
git clone --bare git@git.cloudarix.de:ahmido/TenantAtlas.git "$TP462_TMP_DIR/source.git"
|
||||
git --git-dir="$TP462_TMP_DIR/source.git" fsck --full
|
||||
```
|
||||
|
||||
The actual temporary path is resolved at runtime and recorded without secrets.
|
||||
The implementation must not use the current clone's `.git` directory.
|
||||
|
||||
## 4. Build local-only and disposition evidence
|
||||
|
||||
Compare exact local heads against authoritative Gitea heads. For each local-only
|
||||
head, record graph reachability, unique commits, merge bases, and one disposition.
|
||||
Account separately for stash/Codex/worktree/pull/reflog-only namespaces. Do not
|
||||
delete, merge, rebase, or publish any local ref.
|
||||
|
||||
Validate these invariants with jq and Git graph queries:
|
||||
|
||||
- every Gitea head appears once in `branch-disposition.json`;
|
||||
- every local-only head appears once in `local-only-ref-inventory.json` as
|
||||
`RETAIN_LOCAL_ONLY` or `LOCAL_REDUNDANT`;
|
||||
- only `dev`, `platform-dev`, and `website-dev` are `MIGRATE_ACTIVE`;
|
||||
- unapproved `MIGRATE_RETAINED` count is zero;
|
||||
- all unique local commits have a retention path;
|
||||
- excluded namespaces never appear in the transfer manifest.
|
||||
|
||||
## 5. Build and review the transfer manifest
|
||||
|
||||
Generate `github-transfer-manifest.json` from the frozen inventory and reviewed
|
||||
dispositions. It must contain exact source/target refs and OIDs, all source tags,
|
||||
and no wildcard heads refspec. Compute canonical SHA-256 values with jq sorted
|
||||
output and `shasum -a 256`.
|
||||
|
||||
Before activation, print a no-mutation summary containing:
|
||||
|
||||
- exact target tuple;
|
||||
- exact GitHub settings mutations;
|
||||
- exact selected Gitea server head/tag refs and OIDs;
|
||||
- archive-only/local-only/excluded counts;
|
||||
- source inventory and manifest digests;
|
||||
- non-mutating rollback boundary.
|
||||
|
||||
## 6. Stop for external activation authority
|
||||
|
||||
The implementation must request separate current user authorization for exactly:
|
||||
|
||||
1. disabling GitHub Actions if the verified state is enabled;
|
||||
2. creating the listed GitHub refs;
|
||||
3. setting default branch to `dev`.
|
||||
|
||||
Without that authority, return `PRE_ACTIVATION_READY`, do not run any mutation
|
||||
command, do not claim implementation completion, and do not issue a
|
||||
completion/finalization receipt.
|
||||
|
||||
## 7. Execute an authorized transfer
|
||||
|
||||
Only after authorization:
|
||||
|
||||
1. disable Actions only if enabled, then requery the setting and record
|
||||
`US1_PASS`;
|
||||
2. reconfirm the target is still empty;
|
||||
3. enumerate every Gitea write-capable human and automation path, record
|
||||
attributable pause confirmations, and stop if any writer cannot be controlled;
|
||||
4. bind the Gitea write-freeze start to a refreshed equal source digest;
|
||||
5. add a temporary GitHub remote inside the bare source clone only;
|
||||
6. create `dev`, set default branch to `dev`, then create `platform-dev`,
|
||||
`website-dev`, approved retained Gitea server heads, and all tags using exact
|
||||
refspecs;
|
||||
7. record commands, exit codes, and results with credentials redacted.
|
||||
|
||||
No command may use mirror, force, force-with-lease, deletion refspecs, or wildcard
|
||||
heads authorization.
|
||||
|
||||
## 8. Verify parity and passivity
|
||||
|
||||
Run source and target ref queries and compare every manifest OID. Record tree OID,
|
||||
parent count, and subject for the three authority branches. Create a fresh target
|
||||
bare clone outside the repository and run:
|
||||
|
||||
```bash
|
||||
git --git-dir="$TP462_TMP_DIR/target.git" fsck --full
|
||||
```
|
||||
|
||||
Also prove:
|
||||
|
||||
- no extra or excluded target refs;
|
||||
- GitHub default branch is `dev`;
|
||||
- visibility remains private;
|
||||
- every measurable GitHub passive-authority invariant remains satisfied;
|
||||
- Actions remains disabled and no workflow ran;
|
||||
- Gitea refs/default branch/readable authority settings are unchanged across the
|
||||
freeze and the audit log contains no Gitea mutation;
|
||||
- main-clone `origin` is unchanged;
|
||||
- Gitea remains active and GitHub remains passive.
|
||||
|
||||
Any mismatch produces FAIL and blocks use of the target as a baseline.
|
||||
|
||||
## 9. Run local candidate gates
|
||||
|
||||
```bash
|
||||
scripts/run-agent-quality-gates candidate --spec specs/462-github-repository-bootstrap-git-data-baseline-v1 --base platform-dev
|
||||
git diff --check
|
||||
git status --short --branch
|
||||
cd apps/platform && ./vendor/bin/sail artisan test --compact tests/Feature/Guards/CodexAgentFoundationContractTest.php
|
||||
cd apps/platform && ./vendor/bin/sail bin pint --dirty --format agent
|
||||
```
|
||||
|
||||
Complete independent validation and review against the exact frozen candidate.
|
||||
If a confirmed in-scope finding is corrected, rerun the affected checks and a
|
||||
complete independent review. Completion/receipt/local commit remain separate
|
||||
current-authority steps. A completion/finalization receipt is eligible only after
|
||||
`PASSIVE_BASELINE_VERIFIED`, never after `PRE_ACTIVATION_READY`.
|
||||
|
||||
## 10. Expected final declarations
|
||||
|
||||
```text
|
||||
GitHub Git state: VERIFIED_PASSIVE_COPY
|
||||
GitHub PR authority: NOT_ACTIVE
|
||||
GitHub CI authority: NOT_ACTIVE
|
||||
GitHub merge authority: NOT_ACTIVE
|
||||
Gitea authority: ACTIVE
|
||||
Gitea metadata migration: NOT_PERFORMED
|
||||
Gitea archival activation: DEFERRED_TO_SPEC_465
|
||||
```
|
||||
|
||||
Before external activation, the maximum truthful verdict is
|
||||
`PRE_ACTIVATION_READY`. After authorized transfer and complete parity proof, the
|
||||
verdict may become `PASSIVE_BASELINE_VERIFIED`; after current candidate gates,
|
||||
independent validation, and review it may become `IMPLEMENTATION_REVIEWED`.
|
||||
|
||||
Rollback within Spec 462 never deletes refs or recreates the repository. A partial
|
||||
or failed transfer yields `INVALID_PARTIAL_BASELINE`, preserves evidence, keeps
|
||||
the target private with Actions disabled, and stops for separately scoped cleanup.
|
||||
@ -0,0 +1,168 @@
|
||||
# Research: GitHub Repository Bootstrap and Git Data Baseline v1
|
||||
|
||||
**Date**: 2026-08-01
|
||||
**Scope**: preparation decisions only; no external mutation was performed
|
||||
|
||||
## Decision 1: Use the user-provided candidate
|
||||
|
||||
- **Decision**: Prepare Spec 462 as directly supplied, narrowed to a passive
|
||||
Git-data baseline.
|
||||
- **Rationale**: The candidate is explicitly provided, Spec number 462 is free,
|
||||
no existing package duplicates it, and it creates the bounded prerequisite for
|
||||
later delivery-authority cutovers.
|
||||
- **Alternatives considered**: selecting an unrelated roadmap candidate; merging
|
||||
Specs 463–465 into one migration. Both were rejected because the user supplied
|
||||
a concrete target and an all-in-one cutover would be unsafe and unreviewable.
|
||||
|
||||
## Decision 2: Keep Gitea authoritative
|
||||
|
||||
- **Decision**: GitHub is a passive copy only; Gitea retains Git, PR, CI, merge,
|
||||
and delivery authority.
|
||||
- **Rationale**: Git-data transfer can be independently proven without coupling
|
||||
it to workflow, protection, runner, or team-remote changes.
|
||||
- **Alternatives considered**: dual authority and immediate GitHub cutover. Dual
|
||||
authority creates ambiguous writes; immediate cutover expands scope across
|
||||
three branch families and CI systems.
|
||||
|
||||
## Decision 3: Use exact selected refs, not a mirror
|
||||
|
||||
- **Decision**: Transfer only exact manifest refs. `git push --mirror`, wildcard
|
||||
heads authorization, force, overwrite, and deletion are forbidden.
|
||||
- **Rationale**: The source has hundreds of historical branches and the local
|
||||
environment contains non-authority refs. Exact allowlisting prevents leakage
|
||||
and target pollution.
|
||||
- **Alternatives considered**: mirror push and blanket heads push. Both were
|
||||
rejected because they cannot preserve the active/archive boundary.
|
||||
|
||||
## Decision 4: Inventory the server and local state separately
|
||||
|
||||
- **Decision**: Gitea server refs define authoritative source heads/tags; local
|
||||
refs are analyzed independently for unique work and exclusions.
|
||||
- **Rationale**: A development clone can be stale and can contain local-only,
|
||||
stash, Codex, worktree, pull, and reflog state.
|
||||
- **Alternatives considered**: deriving the migration from `git branch -a` in the
|
||||
current clone. Rejected because it is neither complete nor clean authority.
|
||||
|
||||
## Decision 5: Use a fresh bare source clone
|
||||
|
||||
- **Decision**: Ref transfer originates from a new bare clone outside the
|
||||
repository.
|
||||
- **Rationale**: This prevents the current worktree's private namespaces,
|
||||
worktree metadata, stash state, and permanent remotes from entering the
|
||||
transfer path.
|
||||
- **Alternatives considered**: the current clone, a copied `.git` directory, or a
|
||||
mirror of local refs. All were rejected for provenance/leakage risk.
|
||||
|
||||
## Decision 6: Make dispositions exhaustive and behavior-changing
|
||||
|
||||
- **Decision**: Every Gitea head and local-only branch receives exactly one
|
||||
finite disposition. Retained migration defaults to none and is available only
|
||||
for authoritative Gitea server heads; local-only branches remain local/bundled
|
||||
or are proven redundant.
|
||||
- **Rationale**: Exhaustive classification turns the proposed taxonomy into a
|
||||
concrete transfer/retention consequence and blocks implicit migration.
|
||||
- **Alternatives considered**: branch-name heuristics, “migrate anything not
|
||||
obviously historical,” or importing local-only refs into the bare source.
|
||||
Rejected because absence of proof would become write authority and local import
|
||||
would contradict the clean Gitea-source provenance boundary.
|
||||
|
||||
## Decision 7: Preserve all source tags
|
||||
|
||||
- **Decision**: All Gitea tags, including annotated tag objects and peeled commit
|
||||
OIDs, are transferred and parity-checked.
|
||||
- **Rationale**: Tags are repository history, not branch clutter, and excluding
|
||||
them would create an incomplete Git-data baseline.
|
||||
- **Alternatives considered**: no tags or only selected tags. Rejected unless a
|
||||
future spec amendment identifies unsafe source tags.
|
||||
|
||||
## Decision 8: Bind transfer to a write-freeze inventory
|
||||
|
||||
- **Decision**: Enumerate and pause every Gitea write-capable human/automation
|
||||
path, bind the freeze start to the final pre-push source digest, and compare the
|
||||
same digest after transfer; any uncontrolled writer or drift invalidates
|
||||
acceptance.
|
||||
- **Rationale**: A manifest must describe one source state. OID parity cannot be
|
||||
claimed across moving refs.
|
||||
- **Alternatives considered**: accept latest-at-verification state. Rejected
|
||||
because partial point-in-time truth can hide inconsistent transfers.
|
||||
|
||||
## Decision 9: Separate preparation, local finalization, and remote authority
|
||||
|
||||
- **Decision**: Preparation authorizes no remote mutation. Local commits require
|
||||
the safe receipt/helper boundary. GitHub settings/ref changes require a new
|
||||
exact current user authorization.
|
||||
- **Rationale**: These are materially different authority classes under current
|
||||
repository governance.
|
||||
- **Alternatives considered**: treating implementation permission, task checkboxes,
|
||||
an execution contract, or a local receipt as remote authority. Rejected.
|
||||
|
||||
## Decision 10: Follow current role governance
|
||||
|
||||
- **Decision**: Later implementation uses the current `AGENTS.md` five-role
|
||||
sequence for local candidate work; the root coordinator owns remote Git reads
|
||||
and may perform an expressly authorized external mutation.
|
||||
- **Rationale**: Current repository instructions outrank the submitted draft's
|
||||
single-owner/no-validator suggestion.
|
||||
- **Alternatives considered**: preserving the draft topology unchanged. Rejected
|
||||
as a conflict with current repo truth.
|
||||
|
||||
## Decision 11: Keep tooling spec-local and minimal
|
||||
|
||||
- **Decision**: Prefer documented Git/jq/digest commands. Add a helper only inside
|
||||
the Spec-462 directory if deterministic generation/validation cannot otherwise
|
||||
be proven, and pair it with spec-local self-tests.
|
||||
- **Rationale**: No shared framework is needed for a one-time migration slice.
|
||||
- **Alternatives considered**: new shared repository migration framework or
|
||||
provider abstraction. Rejected under proportionality and no-premature-
|
||||
abstraction rules.
|
||||
|
||||
## Decision 12: Omit application design artifacts
|
||||
|
||||
- **Decision**: Do not create `data-model.md`, API contracts, or agent technology
|
||||
context updates.
|
||||
- **Rationale**: The feature has no application entity, schema, HTTP contract, or
|
||||
new technology. `update-agent-context` would alter `AGENTS.md` outside scope.
|
||||
- **Alternatives considered**: modeling evidence JSON as application entities.
|
||||
Rejected because it would imply runtime ownership that does not exist.
|
||||
|
||||
## Decision 13: Separate readiness from completion
|
||||
|
||||
- **Decision**: `PRE_ACTIVATION_READY` is a reviewable, non-mutating stopping point,
|
||||
not implementation completion. Only `PASSIVE_BASELINE_VERIFIED` may proceed to
|
||||
completion/receipt handling, and only after candidate validation/review may the
|
||||
evidence become `IMPLEMENTATION_REVIEWED`.
|
||||
- **Rationale**: A prepared manifest does not satisfy transfer, parity, integrity,
|
||||
or passive-authority success criteria.
|
||||
- **Alternatives considered**: treating missing remote authority as a successful
|
||||
implementation with a condition. Rejected because it overstates baseline truth.
|
||||
|
||||
## Decision 14: Keep rollback non-destructive
|
||||
|
||||
- **Decision**: A partial or failed target is retained as
|
||||
`INVALID_PARTIAL_BASELINE` with GitHub private and Actions disabled. Spec 462
|
||||
does not delete refs or recreate the repository.
|
||||
- **Rationale**: This preserves evidence and keeps forward-transfer no-delete
|
||||
semantics consistent with the external mutation allowlist.
|
||||
- **Alternatives considered**: exact target ref deletion or repository
|
||||
recreation. Rejected because both expand destructive remote authority and can
|
||||
conflict with default-branch constraints.
|
||||
|
||||
## Decision 15: Defer post-integration reconciliation
|
||||
|
||||
- **Decision**: Spec 462 stops before post-integration `platform-dev`
|
||||
reconciliation. Spec 463 or another explicitly approved follow-up owns it.
|
||||
- **Rationale**: The operation occurs after the reviewed local candidate is
|
||||
integrated and needs fresh exact-ref authorization plus new parity evidence.
|
||||
- **Alternatives considered**: claiming FR-036 complete in the pre-integration
|
||||
report. Rejected because the authoritative post-integration OID does not yet
|
||||
exist at that point.
|
||||
|
||||
## Resolved Unknowns
|
||||
|
||||
- Git, GitHub CLI, jq, and SHA-256 tooling are present locally.
|
||||
- The main `origin` currently points to Gitea for fetch and push.
|
||||
- The exact GitHub authentication, permission, visibility, emptiness, and Actions
|
||||
state are deliberately revalidated during implementation, not assumed from the
|
||||
draft.
|
||||
- No requirement clarification remains. Retained Gitea server refs and external
|
||||
activation are explicit future approval gates with fail-closed defaults.
|
||||
@ -0,0 +1,709 @@
|
||||
# Feature Specification: GitHub Repository Bootstrap and Git Data Baseline v1
|
||||
|
||||
**Feature Branch**: `462-github-repository-bootstrap-git-data-baseline-v1`
|
||||
**Created**: 2026-08-01
|
||||
**Status**: Implemented
|
||||
**Input**: User-provided Spec 462 draft for a staged Gitea-to-GitHub repository migration.
|
||||
**Type**: Repository Governance / Git Hosting Bootstrap / Migration Baseline
|
||||
**Branch family**: Cross-stream repository governance executed from the platform stream
|
||||
**Integration base**: `platform-dev`
|
||||
**Integration target**: `platform-dev`
|
||||
**Diff baseline**: `platform-dev`
|
||||
**Depends on**: Completed or implemented Specs 416, 439, 458, 459, 460, and 461
|
||||
**Runtime posture**: Git-data and repository-governance only
|
||||
**GitHub target**: private repository `senadoroahmido-wq/tenantpilot`
|
||||
**GitHub intended default branch**: `dev`
|
||||
|
||||
## Summary
|
||||
|
||||
Bootstrap the already-created, private, empty GitHub repository as a verified
|
||||
passive Git-data copy of the authoritative Gitea repository. The migration
|
||||
copies only the three active authority branches, all source tags, and any
|
||||
additional Gitea server branch that receives explicit retained-branch approval.
|
||||
It proves
|
||||
source/target parity without changing application runtime, local development
|
||||
remotes, Gitea delivery authority, or GitHub delivery settings beyond disabling
|
||||
Actions and setting the default branch.
|
||||
|
||||
After this slice:
|
||||
|
||||
```text
|
||||
Gitea = active Git, pull-request, CI, merge, and delivery authority
|
||||
GitHub = verified private passive Git copy
|
||||
```
|
||||
|
||||
Specs 463–465 own the later branch-specific authority cutovers. Spec 462 does
|
||||
not create dual delivery authority.
|
||||
|
||||
## Execution Contract
|
||||
|
||||
- **Contract file**: `execution-contract.json`
|
||||
- **Branch/base/target/diff baseline**:
|
||||
`462-github-repository-bootstrap-git-data-baseline-v1` / `platform-dev` /
|
||||
`platform-dev` / `platform-dev`
|
||||
- **Allowed repository paths**: only
|
||||
`specs/462-github-repository-bootstrap-git-data-baseline-v1/**`
|
||||
- **Denied paths**: application runtime, website, workflows, agent foundations,
|
||||
shared scripts, completed specs, and all other repository paths
|
||||
- **Required gates**: Spec Package, Diff Scope, Diff Safety, Unicode,
|
||||
Change Validation, Foundation Regression, Git Diff Check, handoff/report
|
||||
validation where applicable, and independent review
|
||||
- **Local receipt/finalization posture**: a local commit requires a valid
|
||||
candidate-bound receipt and separate current user commit authority
|
||||
- **Remote authority posture**: the contract does not authorize GitHub or Gitea
|
||||
mutations; each permitted GitHub mutation requires separate current user
|
||||
authorization at the activation boundary
|
||||
|
||||
## Completion Verdicts
|
||||
|
||||
- **`TARGET_PREFLIGHT_READY`**: read-only target identity, privacy, permission,
|
||||
emptiness, and current Actions state are proven. If Actions is enabled, this is
|
||||
not User Story 1 PASS; the exact pending disablement remains behind the external
|
||||
activation gate.
|
||||
- **`PRE_ACTIVATION_READY`**: target proof, source/local inventories,
|
||||
dispositions, and the no-mutation manifest preview are complete, but external
|
||||
activation authority is absent. This is a reviewable stopping point, not
|
||||
implementation completion, and it is ineligible for completion-gate or
|
||||
finalization-receipt issuance.
|
||||
- **`PASSIVE_BASELINE_VERIFIED`**: the exact authorized transfer completed and all
|
||||
US3/US4 parity, integrity, source-stability, and passive-authority checks pass.
|
||||
- **`IMPLEMENTATION_REVIEWED`**: `PASSIVE_BASELINE_VERIFIED` evidence also passed
|
||||
the current candidate gates, targeted constitutional Pest validation,
|
||||
independent validation, and complete-diff review. Only this verdict may proceed
|
||||
to a separately authorized local finalization receipt.
|
||||
|
||||
## Spec Candidate Check
|
||||
|
||||
- **Problem**: The repository has no bounded, verified Git-data baseline on the
|
||||
pre-created GitHub target, while hundreds of historical and local-only refs
|
||||
make a blanket migration unsafe.
|
||||
- **Today's failure**: A direct mirror or all-in-one provider cutover could leak
|
||||
non-authority refs, pollute the target with historical branches, trigger
|
||||
unreviewed workflows, or create ambiguous delivery authority.
|
||||
- **User-visible improvement**: Maintainers gain a trustworthy passive GitHub
|
||||
baseline whose exact contents and authority posture are independently
|
||||
reviewable before any CI, PR, merge, or delivery cutover.
|
||||
- **Smallest enterprise-capable version**: Verify the private empty target,
|
||||
inventory and classify all source/local refs, transfer only the three active
|
||||
branches plus tags and explicitly approved retained Gitea server refs, prove
|
||||
exact parity,
|
||||
set `dev` as default, and keep Actions disabled.
|
||||
- **Explicit non-goals**: GitHub Actions, Rulesets, Required Checks, PR or issue
|
||||
migration, runner/secrets configuration, branch convergence, remote changes in
|
||||
the main worktree, Gitea archival, application runtime, and deployment.
|
||||
- **Permanent complexity imported**: A small set of tracked one-time migration
|
||||
evidence artifacts and a finite branch-disposition vocabulary. No runtime
|
||||
models, tables, enums, services, APIs, or UI concepts are added.
|
||||
- **Why now**: The target already exists and Specs 458–461 provide the local
|
||||
governance/evidence foundation needed to stage provider migration safely.
|
||||
- **Why not local**: Local branch lists and the current worktree are not
|
||||
authoritative for Gitea server refs and can contain stash, Codex, worktree,
|
||||
or other non-authority state.
|
||||
- **Approval class**: Core Enterprise
|
||||
- **Red flags triggered**: New classification axis and “baseline/foundation”
|
||||
language. Defense: the classifications are finite, migration-local,
|
||||
behavior-changing transfer decisions; the scope is explicitly reduced to a
|
||||
passive copy and forbids delivery activation.
|
||||
- **Score**: Nutzen: 2 | Dringlichkeit: 2 | Scope: 2 | Komplexität: 1 |
|
||||
Produktnähe: 0 | Wiederverwendung: 1 | **Gesamt: 8/12**
|
||||
- **Decision**: approve after scope reduction to the passive-copy slice
|
||||
|
||||
## Candidate Source, Roadmap, and Completed-Spec Guard
|
||||
|
||||
- **Candidate source**: directly provided by the user on 2026-08-01.
|
||||
- **Roadmap relationship**: repository-governance foundation for the staged
|
||||
GitHub migration; it enables but does not absorb Specs 463–465.
|
||||
- **Duplicate check**: no existing local spec, local branch, remote-tracking
|
||||
branch, or Gitea head matches Spec 462 or its subject.
|
||||
- **Completed-spec guard**: Specs 416, 439, 458, 459, 460, and 461 contain
|
||||
implementation/completion evidence and remain read-only historical context.
|
||||
- **Draft narrowing**: local-only branches are never GitHub transfer inputs in
|
||||
this slice. They remain local, are preserved in a verified bundle, or are
|
||||
proven redundant. Publishing local-only work would change source provenance
|
||||
and requires a separate spec amendment.
|
||||
- **Deferred alternatives**:
|
||||
- Spec 463: platform PR, CI, agent-remote, and merge authority cutover.
|
||||
- Spec 464: website PR, CI, and merge authority cutover.
|
||||
- Spec 465: `dev` promotion authority, repository cutover, and Gitea archival.
|
||||
|
||||
## Spec Scope Fields
|
||||
|
||||
- **Scope**: repository-wide Git authority metadata; no workspace, tenant, or
|
||||
managed-environment product scope
|
||||
- **Primary Routes**: none
|
||||
- **Data Ownership**: no application data; tracked artifacts describe Git refs,
|
||||
transfer decisions, and parity evidence
|
||||
- **RBAC**: no TenantPilot RBAC change; GitHub administrative permission and
|
||||
current explicit user authorization are external activation prerequisites
|
||||
- **Source authority**: `git@git.cloudarix.de:ahmido/TenantAtlas.git`
|
||||
- **Target identity**: `senadoroahmido-wq/tenantpilot`, private
|
||||
- **Target URLs**:
|
||||
- HTTPS: `https://github.com/senadoroahmido-wq/tenantpilot.git`
|
||||
- SSH: `git@github.com:senadoroahmido-wq/tenantpilot.git`
|
||||
|
||||
## No Legacy / No Backward Compatibility Constraint
|
||||
|
||||
- **Compatibility posture**: staged hard cutover with a passive-copy first step
|
||||
- **Legacy aliases, fallback readers, hidden routes, duplicate UI, or historical
|
||||
fixtures kept?**: no runtime compatibility paths are introduced
|
||||
- **Why clean replacement is safe now**: Spec 462 changes no active authority;
|
||||
later specs perform one branch-family cutover at a time
|
||||
- **Permanent dual write**: forbidden
|
||||
- **Permanent Gitea/GitHub provider abstraction**: forbidden
|
||||
|
||||
## UI Surface Impact
|
||||
|
||||
- [x] No UI surface impact
|
||||
- [ ] Existing page changed
|
||||
- [ ] New page/route added
|
||||
- [ ] Navigation changed
|
||||
- [ ] Filament panel/provider surface changed
|
||||
- [ ] New modal/drawer/wizard/action added
|
||||
- [ ] New table/form/state added
|
||||
- [ ] Customer-facing surface changed
|
||||
- [ ] Dangerous action changed
|
||||
- [ ] Status/evidence/review presentation changed
|
||||
- [ ] Workspace/environment context presentation changed
|
||||
|
||||
## UI/Productization Coverage
|
||||
|
||||
N/A - no reachable UI surface impact. All work is repository-local planning,
|
||||
Git evidence, and separately authorized repository-hosting operations.
|
||||
|
||||
## Product Surface Impact
|
||||
|
||||
- **Product Surface Contract applies?**: no; no rendered product surface changes
|
||||
- **Page archetype**: N/A
|
||||
- **Primary user question**: N/A
|
||||
- **Primary action**: N/A
|
||||
- **Surface budget result**: N/A
|
||||
- **Technical Annex / deep-link demotion**: N/A
|
||||
- **Canonical status vocabulary**: N/A
|
||||
- **Visible complexity impact**: N/A for the rendered product
|
||||
- **Product Surface exceptions**: none
|
||||
|
||||
## Browser Verification Plan
|
||||
|
||||
- **Browser proof required?**: no
|
||||
- **No-browser rationale**: `N/A - no rendered UI surface changed`
|
||||
- **Focused path**: N/A
|
||||
- **Console, Livewire, Filament, network, and 500-error checks**: N/A
|
||||
- **Full-suite failure triage**: N/A; repository-governance validation is routed
|
||||
independently of application/browser lanes
|
||||
|
||||
## Human Product Sanity Check
|
||||
|
||||
- **Required?**: no
|
||||
- **No-human-sanity rationale**: N/A - no product surface changed
|
||||
- **Planned result location**: implementation report records the no-surface
|
||||
decision and neutral visible-complexity outcome
|
||||
|
||||
## Product Surface Merge Gate Checklist
|
||||
|
||||
- [x] No-legacy posture recorded.
|
||||
- [x] Product Surface Impact is justified as N/A.
|
||||
- [x] Browser proof is justified as N/A.
|
||||
- [x] Human Product Sanity is not applicable with rationale.
|
||||
- [x] Product Surface exceptions are `none`.
|
||||
- [x] The future implementation report is required to state Livewire v4,
|
||||
provider registration, global search, destructive/high-impact action, assets,
|
||||
tests/browser, deployment, and visible-complexity posture.
|
||||
|
||||
## Cross-Cutting / Shared Pattern Reuse
|
||||
|
||||
N/A - no shared product interaction family is touched. Repository evidence uses
|
||||
the current Spec 458–461 quality-gate and handoff contracts rather than creating a
|
||||
parallel agent-governance framework.
|
||||
|
||||
## OperationRun UX Impact
|
||||
|
||||
N/A - no `OperationRun` creation, lifecycle, notification, or link semantics are
|
||||
touched.
|
||||
|
||||
## Provider Boundary / Platform Core Check
|
||||
|
||||
N/A - no application provider/platform boundary is touched. “Gitea” and
|
||||
“GitHub” are repository-hosting providers within this migration spec only and do
|
||||
not enter TenantPilot platform-core vocabulary or persistence.
|
||||
|
||||
## UI / Surface Guardrail Impact
|
||||
|
||||
| Surface / Change | Operator-facing change? | Native vs Custom | Shared-Family | State Layers | Exception | Note |
|
||||
|---|---:|---|---|---|---|---|
|
||||
| Repository bootstrap evidence | no | N/A | none | none | none | N/A - repository workflow only |
|
||||
|
||||
## Proportionality Review
|
||||
|
||||
- **New source of truth?**: yes, but only one-time Git migration evidence; Gitea
|
||||
remains source authority during this spec
|
||||
- **New persisted entity/table/artifact?**: tracked JSON/Markdown evidence only;
|
||||
no application persistence
|
||||
- **New abstraction?**: no shared abstraction; any implementation helper must be
|
||||
spec-local, default read-only, and justified by deterministic evidence needs
|
||||
- **New enum/state/reason family?**: a finite migration disposition vocabulary
|
||||
controls whether each ref may be transferred
|
||||
- **New cross-domain UI framework/taxonomy?**: no
|
||||
- **Current operator problem**: maintainers cannot safely decide what reaches
|
||||
GitHub or prove that the passive copy matches authoritative refs.
|
||||
- **Existing structure is insufficient because**: local branches and the current
|
||||
clone do not represent complete authoritative server state and contain private
|
||||
namespaces that must never be pushed.
|
||||
- **Narrowest correct implementation**: exact source inventory, exhaustive
|
||||
dispositions, exact transfer allowlist, fresh bare export, and parity report.
|
||||
- **Ownership cost**: migration evidence schemas, review of every source/local
|
||||
branch, and later archival of the evidence with the staged migration.
|
||||
- **Alternative intentionally rejected**: mirror push, blanket heads push, and a
|
||||
permanent multi-host synchronization layer; each creates excessive authority
|
||||
or leakage risk.
|
||||
- **Release truth**: current migration need, not future platform preparation.
|
||||
|
||||
## Testing / Lane / Runtime Impact
|
||||
|
||||
- **Test purpose / classification**: Heavy-Governance evidence validation; no
|
||||
application Unit, Feature, or Browser behavior
|
||||
- **Validation lanes**: Spec Package, Diff Scope, Diff Safety, Unicode, Change
|
||||
Validation, Foundation Regression, Git integrity/parity checks, and independent
|
||||
review
|
||||
- **Why sufficient**: these checks prove repository scope, artifact validity,
|
||||
source/target ref truth, and authority safety without booting application state
|
||||
- **New or expanded test families**: none unless a spec-local deterministic helper
|
||||
is required; any such helper must include spec-local self-tests
|
||||
- **Fixture/helper cost**: temporary bare Git repositories only; no database,
|
||||
workspace, membership, provider, session, factory, seed, or browser context
|
||||
- **Heavy-family visibility**: explicit repository-governance classification
|
||||
- **Special surface profile**: N/A
|
||||
- **Budget/baseline/trend impact**: none for application lanes
|
||||
- **Escalation**: `document-in-feature`; any structural shared tooling proposal
|
||||
requires a separate spec
|
||||
- **Planned validation commands**: documented in `quickstart.md`
|
||||
|
||||
## Primary Users
|
||||
|
||||
- Repository owner authorizing the migration.
|
||||
- Maintainer preparing and reviewing source/ref evidence.
|
||||
- Independent validator/reviewer proving scope and parity.
|
||||
- Future delivery owners of Specs 463–465 consuming the passive baseline.
|
||||
|
||||
## User Scenarios & Testing
|
||||
|
||||
### User Story 1 - Prove the target is safe to bootstrap (Priority: P1)
|
||||
|
||||
As the repository owner, I can see deterministic evidence that the exact GitHub
|
||||
target is private, empty, administratively manageable, and either already unable
|
||||
to run GitHub Actions or explicitly waiting at the authorized Actions-disablement
|
||||
gate before any Git ref is transferred.
|
||||
|
||||
**Independent test**: Read-only GitHub metadata and ref queries establish the
|
||||
target tuple, visibility, permission, zero heads/tags/releases, and exact Actions
|
||||
state. An enabled-but-verifiable Actions state yields `TARGET_PREFLIGHT_READY`,
|
||||
not US1 PASS; any unexpected ref or unverifiable state blocks activation.
|
||||
|
||||
**Acceptance scenarios**:
|
||||
|
||||
1. Given the intended target, when preflight runs, then owner/name, private
|
||||
visibility, administrative access, and empty refs are proven.
|
||||
2. Given any pre-existing target ref or initial commit, when preflight runs, then
|
||||
the transfer stops before GitHub mutation.
|
||||
3. Given Actions is enabled, when read-only preflight completes, then the result is
|
||||
`TARGET_PREFLIGHT_READY` and no ref transfer is allowed until the separately
|
||||
authorized disablement succeeds and is verified.
|
||||
|
||||
### User Story 2 - Account for every source and local ref (Priority: P1)
|
||||
|
||||
As the migration maintainer, I can account for every authoritative Gitea head and
|
||||
tag plus every local-only branch/commit without silently losing work or exposing
|
||||
private refs.
|
||||
|
||||
**Independent test**: Canonical inventories reconcile counts and unique names;
|
||||
every discovered head appears exactly once in the appropriate disposition set;
|
||||
every local-only unique commit has a retention decision.
|
||||
|
||||
**Acceptance scenarios**:
|
||||
|
||||
1. Given Gitea server refs, when inventory is captured, then every head, tag,
|
||||
peeled tag object, default branch, and inventory hash is recorded.
|
||||
2. Given local-only branches or commits, when classification runs, then each is
|
||||
retained locally/bundled or proven redundant without being published.
|
||||
3. Given stash, Codex, worktree-private, pull, or reflog-only state, when
|
||||
classification runs, then it is excluded from transfer.
|
||||
|
||||
### User Story 3 - Transfer only explicitly allowed Git data (Priority: P1)
|
||||
|
||||
As the repository owner, after separate current authorization, I can bootstrap
|
||||
GitHub from a fresh bare Gitea clone without force, deletion, mirror push, branch
|
||||
convergence, or changes to the main development clone.
|
||||
|
||||
**Independent test**: The transfer log contains only exact manifest refspecs;
|
||||
`dev`, `platform-dev`, `website-dev`, approved retained Gitea server refs, and all
|
||||
source tags are the only created GitHub refs.
|
||||
|
||||
**Acceptance scenarios**:
|
||||
|
||||
1. Given a reviewed manifest and an empty target, when activation is authorized,
|
||||
then each selected ref is created without force from a fresh bare clone.
|
||||
2. Given a branch without `MIGRATE_ACTIVE` or approved `MIGRATE_RETAINED`, when
|
||||
the transfer plan is generated, then the branch is absent.
|
||||
3. Given source drift during the freeze window, when pre/post inventories differ,
|
||||
then the manifest is invalidated and transfer acceptance stops.
|
||||
|
||||
### User Story 4 - Prove parity and passive authority (Priority: P1)
|
||||
|
||||
As a future cutover owner, I can rely on evidence that every migrated ref has
|
||||
exact OID/tree parity, the target contains no extras, `dev` is default, Actions
|
||||
remain disabled, and Gitea remains the sole active authority.
|
||||
|
||||
**Independent test**: Source/target ref comparison, fresh target bare-clone
|
||||
integrity, target settings queries, unchanged source refs, and unchanged main
|
||||
`origin` all pass.
|
||||
|
||||
**Acceptance scenarios**:
|
||||
|
||||
1. Given a completed transfer, when parity is verified, then every selected head
|
||||
and tag is `OID_MATCH` and authority branch trees match exactly.
|
||||
2. Given any extra or excluded GitHub ref, when parity is verified, then the
|
||||
baseline verdict is FAIL.
|
||||
3. Given exact parity, when the authority report is produced, then it declares
|
||||
GitHub passive and Gitea active with no GitHub PR/CI/merge authority.
|
||||
|
||||
## Edge Cases
|
||||
|
||||
- The GitHub repository gains a branch, tag, release, or initial commit between
|
||||
preflight and activation.
|
||||
- A Gitea ref changes between freeze inventory, push, and post-push verification.
|
||||
- The authenticated GitHub identity can read but not administer the target.
|
||||
- Source annotated tags introduce peeled-object entries.
|
||||
- A local-only branch tip is already reachable from an differently named Gitea
|
||||
branch.
|
||||
- A unique local commit is reachable only through stash-related state.
|
||||
- A branch name contains characters that require exact NUL-safe handling.
|
||||
- A retained branch is proposed without an owner, purpose, or explicit approval.
|
||||
- GitHub remote HEAD cannot resolve until `dev` exists.
|
||||
- A fresh target clone reports dangling objects but no corruption; the report
|
||||
distinguishes dangling from missing/corrupt objects.
|
||||
- The Spec-462 integration later changes `platform-dev`; Spec 463 or another
|
||||
explicitly approved follow-up must reconcile the passive target before any
|
||||
delivery-authority cutover.
|
||||
|
||||
## Branch and Authority Contract
|
||||
|
||||
### Authority branches
|
||||
|
||||
Exactly these branches use `MIGRATE_ACTIVE`:
|
||||
|
||||
```text
|
||||
dev
|
||||
platform-dev
|
||||
website-dev
|
||||
```
|
||||
|
||||
### Server-head dispositions
|
||||
|
||||
Each Gitea server head receives exactly one:
|
||||
|
||||
- `MIGRATE_ACTIVE`
|
||||
- `MIGRATE_RETAINED`
|
||||
- `ARCHIVE_ONLY`
|
||||
|
||||
### Local-only dispositions
|
||||
|
||||
Each local-only branch receives exactly one:
|
||||
|
||||
- `RETAIN_LOCAL_ONLY`
|
||||
- `LOCAL_REDUNDANT`
|
||||
|
||||
Non-authority namespaces use `EXCLUDED_NON_AUTHORITY_REF`.
|
||||
|
||||
`MIGRATE_RETAINED` applies only to an authoritative Gitea server head and defaults
|
||||
to none. Each retained exception requires the exact ref, OID, owner/future
|
||||
purpose, reason, and explicit current user approval. Local-only refs cannot use
|
||||
this disposition in Spec 462.
|
||||
|
||||
### No branch convergence
|
||||
|
||||
This spec must not merge, rebase, or otherwise reconcile any combination of
|
||||
`dev`, `platform-dev`, and `website-dev`. Their divergence is preserved exactly.
|
||||
|
||||
### Passive GitHub authority invariants
|
||||
|
||||
“GitHub is passive” is an organizational and configuration contract, not a claim
|
||||
that a repository administrator lacks GitHub's intrinsic write capability. The
|
||||
accepted target MUST have Actions disabled, zero open pull requests and workflow
|
||||
runs, zero non-owner collaborators or teams, and no configured deploy keys,
|
||||
webhooks, repository workflows, Rulesets, branch protection or Required Checks,
|
||||
runners, secrets, variables, or environments. The final evidence MUST also state
|
||||
that GitHub is not authorized for pull requests, CI, merge, promotion, deployment,
|
||||
or agent delivery. Every readable invariant is captured before activation and
|
||||
reverified afterward; an unreadable or unverifiable invariant blocks the passive
|
||||
authority claim.
|
||||
|
||||
### Source write freeze
|
||||
|
||||
The final inventory and transfer manifest describe one stable source state.
|
||||
During the bounded transfer window there is no source push, merge, ref deletion,
|
||||
tag mutation, force push, or repository migration. A logical freeze is acceptable
|
||||
only when evidence identifies every human, team, deploy key, bot, workflow, and
|
||||
other automation path able to write Gitea; records attributable pause
|
||||
confirmation for each active writer; binds the freeze start timestamp to the
|
||||
accepted source digest; and proves the same digest at freeze end. If any writer or
|
||||
automation path cannot be enumerated, controlled, or paused, Spec 462 stops before
|
||||
GitHub mutation. An enforceable Gitea-side freeze would be a Gitea setting mutation
|
||||
outside this spec and therefore requires a scope amendment rather than an implicit
|
||||
fallback.
|
||||
|
||||
## Required Evidence Artifacts
|
||||
|
||||
All paths are under
|
||||
`specs/462-github-repository-bootstrap-git-data-baseline-v1/`:
|
||||
|
||||
- `git-source-ref-inventory.json`
|
||||
- `local-only-ref-inventory.json`
|
||||
- `branch-disposition.json`
|
||||
- `github-transfer-manifest.json`
|
||||
- `github-parity-report.json`
|
||||
- `external-activation-checklist.md`
|
||||
- `implementation-report.md`
|
||||
|
||||
The source inventory records repository identity, source default branch, source
|
||||
HEAD, every head/tag OID, peeled tag OIDs, counts, timestamp, and a canonical
|
||||
SHA-256. The disposition artifacts provide exhaustive one-to-one coverage. The
|
||||
transfer manifest lists exact source/target refs and OIDs; wildcard refspecs are
|
||||
not authorization. The parity report records source/target OIDs, authority-branch
|
||||
tree OIDs, target extras, source stability, target integrity, visibility, default
|
||||
branch, Actions state, and the final authority declaration.
|
||||
|
||||
## Functional Requirements
|
||||
|
||||
- **FR-001**: The target identity MUST be exactly
|
||||
`senadoroahmido-wq/tenantpilot`.
|
||||
- **FR-002**: The target MUST be private and administratively manageable by the
|
||||
authenticated identity.
|
||||
- **FR-003**: The target MUST have zero heads and tags and no initial commit before
|
||||
transfer.
|
||||
- **FR-004**: GitHub Actions MUST be disabled before transfer and remain disabled.
|
||||
- **FR-005**: Preparing artifacts MUST NOT authorize any external mutation.
|
||||
- **FR-006**: Every GitHub setting or ref mutation MUST require separate current
|
||||
user authorization for the exact operation set.
|
||||
- **FR-007**: Source inventory MUST derive from Gitea server refs and a fresh bare
|
||||
Gitea clone, not only the current development clone.
|
||||
- **FR-008**: The inventory MUST include every head, tag, peeled tag OID, source
|
||||
HEAD/default branch, counts, timestamp, and canonical hash.
|
||||
- **FR-009**: Every Gitea head MUST receive exactly one server-head disposition.
|
||||
- **FR-010**: Every local-only branch MUST receive exactly one local-only
|
||||
disposition.
|
||||
- **FR-011**: Every local-only unique commit MUST be retained locally, preserved
|
||||
in a verified external bundle, or proven redundant; it MUST NOT be published by
|
||||
Spec 462.
|
||||
- **FR-012**: No Gitea or local branch, tag, commit, stash, worktree ref, or other
|
||||
source/local evidence may be deleted by Spec 462.
|
||||
- **FR-013**: `dev`, `platform-dev`, and `website-dev` MUST be the only
|
||||
`MIGRATE_ACTIVE` refs.
|
||||
- **FR-014**: Additional Gitea server heads MUST default to `ARCHIVE_ONLY` unless
|
||||
an exact `MIGRATE_RETAINED` exception is approved; local-only heads are not
|
||||
eligible for migration in this slice.
|
||||
- **FR-015**: Stash, Codex, turn-diff, worktree-private, pull, reflog-only, and
|
||||
temporary refs MUST be excluded.
|
||||
- **FR-016**: All source tags MUST be included in the transfer manifest.
|
||||
- **FR-017**: The transfer manifest MUST list exact refspecs and OIDs; wildcard
|
||||
head authorization is forbidden.
|
||||
- **FR-018**: Ref transfer MUST originate from a new temporary bare clone of the
|
||||
Gitea server.
|
||||
- **FR-019**: The current worktree, linked worktrees, copied Git metadata,
|
||||
snapshots, stashes, and partial clones MUST NOT be transfer sources.
|
||||
- **FR-020**: Mirror pushes, forced updates, overwrites, target ref deletions, and
|
||||
target repository deletion or recreation are forbidden in both forward transfer
|
||||
and Spec-462 rollback handling.
|
||||
- **FR-021**: The main development clone's `origin` and permanent remote set MUST
|
||||
remain unchanged.
|
||||
- **FR-022**: The source write freeze MUST bind the final inventory, manifest,
|
||||
transfer, and post-transfer source verification to one stable ref state.
|
||||
- **FR-023**: Any source or target drift MUST invalidate acceptance and require a
|
||||
refreshed review before further mutation.
|
||||
- **FR-024**: Every migrated head and tag MUST preserve its exact OID.
|
||||
- **FR-025**: `dev`, `platform-dev`, and `website-dev` MUST preserve exact commit
|
||||
tree OIDs and parent counts.
|
||||
- **FR-026**: A fresh GitHub bare clone MUST pass full Git integrity verification
|
||||
without missing or corrupt objects.
|
||||
- **FR-027**: GitHub MUST contain no head or tag absent from the reviewed transfer
|
||||
manifest.
|
||||
- **FR-028**: GitHub's default branch MUST be `dev`; no `main` branch is created.
|
||||
- **FR-029**: GitHub MUST satisfy every measurable passive-authority invariant:
|
||||
Actions disabled; zero open pull requests and workflow runs; zero non-owner
|
||||
collaborators/teams; no configured deploy keys, webhooks, workflows, Rulesets,
|
||||
branch protection, Required Checks, runners, secrets, variables, or
|
||||
environments; and an explicit no-PR/CI/merge/promotion/deployment/agent-delivery
|
||||
authority declaration.
|
||||
- **FR-030**: Spec-462 evidence MUST prove that it issued no Gitea mutation
|
||||
command or mutating API request and that before/after Gitea refs, default branch,
|
||||
read-accessible repository settings, branch protections, hooks, deploy keys,
|
||||
collaborators/teams, workflows, and delivery-authority declaration are
|
||||
unchanged. Any named surface that cannot be read MUST be `NOT_PROVEN` and block
|
||||
the unchanged-authority claim.
|
||||
- **FR-031**: Gitea PR/issue/release/package metadata MUST NOT be migrated.
|
||||
- **FR-032**: Rollback handling MUST be non-destructive: stop further transfer,
|
||||
keep GitHub private and Actions disabled, preserve evidence, mark the target
|
||||
`INVALID_PARTIAL_BASELINE`, and leave Gitea and local remotes unchanged.
|
||||
- **FR-033**: Cleanup mutation after a partial target transfer, including ref or
|
||||
repository deletion/recreation, is outside Spec 462 and MUST require both a
|
||||
scope amendment or separate spec and separate current user authorization.
|
||||
- **FR-034**: Final evidence MUST declare GitHub a verified passive Git copy and
|
||||
Gitea active authority.
|
||||
- **FR-035**: The complete candidate and activation evidence MUST receive
|
||||
independent validation and review under current repository governance.
|
||||
- **FR-036**: Spec 462 MUST stop before post-integration reconciliation. Spec 463
|
||||
or another explicitly approved follow-up owns any later `platform-dev` update
|
||||
and MUST repeat exact-ref authorization and full parity/passivity verification.
|
||||
|
||||
## Non-Functional Requirements
|
||||
|
||||
- **NFR-001 Determinism**: Canonical JSON serialization and SHA-256 calculations
|
||||
MUST be reproducible from the same source state.
|
||||
- **NFR-002 Completeness**: Disposition coverage MUST be 100%; one missing or
|
||||
duplicate ref blocks transfer.
|
||||
- **NFR-003 Safety**: Commands MUST fail closed on wrong target, non-empty target,
|
||||
source drift, target drift, missing authorization, or manifest mismatch.
|
||||
- **NFR-004 Redaction**: Evidence MUST contain no credentials, tokens, secret
|
||||
values, private key material, or raw authenticated headers.
|
||||
- **NFR-005 Auditability**: Exact commands, exit codes, timestamps, refspecs,
|
||||
counts, hashes, and mutation results MUST be recorded.
|
||||
- **NFR-006 Isolation**: Temporary bare clones and bundles MUST live outside the
|
||||
repository and MUST NOT alter the development worktree's remotes or refs.
|
||||
- **NFR-007 Portability**: Tracked evidence and documented validation use current
|
||||
repository Git/JSON/SHA tooling without adding a package dependency.
|
||||
|
||||
## Acceptance Criteria
|
||||
|
||||
- **AC-001**: Target owner/name, private visibility, administrative permission,
|
||||
and zero pre-transfer heads/tags are proven.
|
||||
- **AC-002**: No initial README, License, `.gitignore`, `main`, release, workflow
|
||||
run, issue, or pull request exists before bootstrap.
|
||||
- **AC-003**: Actions are disabled before and after the transfer and no workflow
|
||||
execution is triggered.
|
||||
- **AC-004**: Source head/tag counts match fresh server queries and every source
|
||||
head has exactly one disposition.
|
||||
- **AC-005**: Every local-only branch and unique commit has exactly one retention
|
||||
outcome; no deletion task exists.
|
||||
- **AC-006**: The manifest contains all three authority branches, all source tags,
|
||||
and only explicitly approved retained Gitea server heads.
|
||||
- **AC-007**: Transfer evidence proves a fresh bare source clone, exact refspecs,
|
||||
zero wildcard authorization, zero mirror/force/delete behavior, and no main
|
||||
remote change.
|
||||
- **AC-008**: Every migrated ref reports `OID_MATCH`; all authority trees match.
|
||||
- **AC-009**: GitHub contains no extra, archive-only, local-only, stash, Codex,
|
||||
worktree-private, pull, or temporary ref.
|
||||
- **AC-010**: Fresh GitHub bare-clone integrity passes without missing or corrupt
|
||||
objects.
|
||||
- **AC-011**: GitHub default branch is `dev`, visibility is private, and Actions
|
||||
remain disabled.
|
||||
- **AC-012**: Gitea before/after source inventories match and the development
|
||||
clone's `origin` remains Gitea.
|
||||
- **AC-013**: Every FR-029 passive-authority invariant is proven before and after
|
||||
activation, every readable FR-030 Gitea surface is unchanged, and no Gitea
|
||||
metadata migration is activated.
|
||||
- **AC-014**: The implementation report records exact remote mutations and the
|
||||
authority declarations required by FR-034.
|
||||
- **AC-015**: Current local quality gates, the targeted constitutional Pest test,
|
||||
Sail Pint, source/target parity checks, and one independent review complete with
|
||||
no confirmed in-scope finding.
|
||||
|
||||
## Success Criteria
|
||||
|
||||
- **SC-001**: 100% of Gitea heads, tags, local-only branches, and locally unique
|
||||
commits are represented exactly once in the appropriate evidence inventory.
|
||||
- **SC-002**: 100% of manifest refs have identical source and target OIDs.
|
||||
- **SC-003**: The three authority branches have identical source and target tree
|
||||
OIDs and parent counts.
|
||||
- **SC-004**: The target has zero unlisted heads/tags and zero excluded refs.
|
||||
- **SC-005**: No Gitea ref/setting, local development remote, application file, or
|
||||
workflow changes during the accepted baseline operation; GitHub changes are
|
||||
exactly the allowlisted Actions disablement, manifest ref creation, and default
|
||||
branch assignment.
|
||||
- **SC-006**: A maintainer can determine from the tracked report, without relying
|
||||
on memory, exactly what moved, what stayed archive-only/local-only, what was
|
||||
excluded, and which host retains authority.
|
||||
|
||||
## External Mutation Boundary
|
||||
|
||||
After separate explicit authorization, Spec 462 may mutate only:
|
||||
|
||||
- GitHub Actions enabled state, to disabled;
|
||||
- GitHub default branch, to `dev` after that branch exists;
|
||||
- exact head and tag refs listed in the reviewed transfer manifest.
|
||||
|
||||
It must not mutate repository owner/name/visibility, Rulesets, branch protection,
|
||||
collaborators, teams, deploy keys, webhooks, secrets, variables, environments,
|
||||
runners, workflows, issues, pull requests, releases, packages, or any Gitea state.
|
||||
Rollback inside Spec 462 is non-mutating. Target cleanup, ref deletion, or
|
||||
repository deletion/recreation requires a scope amendment or separate spec plus
|
||||
separate current authorization.
|
||||
|
||||
## Implementation Governance Deviation from the Submitted Draft
|
||||
|
||||
The submitted draft requested a single-owner implementation and excluded the
|
||||
repository's validator role. Current `AGENTS.md` is authoritative and requires the
|
||||
Spec-458 five-role governance for repository-governance implementation:
|
||||
|
||||
```text
|
||||
code_explorer -> implementer -> test_validator -> code_reviewer -> git_finalizer
|
||||
```
|
||||
|
||||
This preparation run does not spawn those roles because it does not implement the
|
||||
spec. A later implementation must use them for local candidate work, validation,
|
||||
review, and separately authorized local finalization. The root coordinator owns
|
||||
all remote Git network operations, including source queries and temporary
|
||||
cloning. It may cross the separately authorized external GitHub mutation boundary
|
||||
only after current user authority; no role handoff or execution contract implies
|
||||
remote authority.
|
||||
|
||||
## Risks and Mitigations
|
||||
|
||||
| Risk | Impact | Mitigation |
|
||||
|---|---|---|
|
||||
| Target is no longer empty | History collision | Hard stop and spec amendment before any push |
|
||||
| Wrong GitHub target or permission | Unauthorized write | Exact tuple, private visibility, admin proof |
|
||||
| Current clone used as source | Private refs leak | Fresh bare Gitea clone only |
|
||||
| Blanket or mirror push | Historical/non-authority pollution | Exact manifest allowlist; mirror/force forbidden |
|
||||
| Source changes during transfer | Inconsistent baseline | Freeze plus before/after inventory hashes |
|
||||
| Local-only commits omitted | Work loss | Exhaustive inventory and verified local retention/bundle |
|
||||
| Actions trigger on import | Unreviewed CI/cost | Disable and reverify before/after |
|
||||
| GitHub mistaken as active authority | Dual delivery | Explicit passive declaration; no local remote/PR/CI cutover |
|
||||
| Partial transfer tempts destructive cleanup | Evidence loss or widened authority | Stop, keep target private/Actions-disabled, preserve evidence, mark `INVALID_PARTIAL_BASELINE`; cleanup is out of scope |
|
||||
| Post-merge `platform-dev` drift | Passive copy becomes stale | Spec 463 or an explicitly approved follow-up reconciles before any authority cutover |
|
||||
|
||||
## Assumptions
|
||||
|
||||
- The target repository has been created manually, is private, and is intended to
|
||||
remain empty until separately authorized activation.
|
||||
- Gitea remains reachable and authoritative throughout Spec 462.
|
||||
- The authenticated GitHub identity can prove administrative permission during
|
||||
implementation.
|
||||
- `MIGRATE_RETAINED` is empty unless the user explicitly approves exact Gitea
|
||||
server refs; local-only refs cannot be published in this slice.
|
||||
- The authorizing user can enumerate and pause every Gitea write-capable actor and
|
||||
automation path; otherwise Spec 462 stops before activation and any enforceable
|
||||
source-side freeze requires a scope amendment.
|
||||
- Git data may contain existing repository history but evidence will not record
|
||||
credentials or authenticated headers.
|
||||
|
||||
## Open Questions
|
||||
|
||||
No question blocks implementation preparation. Retained-branch selection and
|
||||
external mutation authority are intentionally deferred decisions with fail-closed
|
||||
defaults, not unresolved requirements.
|
||||
|
||||
## Follow-up Specs
|
||||
|
||||
- **Spec 463 — GitHub Platform Delivery and Agent Authority Cutover v1**:
|
||||
first reconcile the integrated Gitea `platform-dev` OID with the passive target
|
||||
under exact current authorization and repeated parity/passivity proof, then own
|
||||
platform workflows, artifacts, agent remote, Ruleset, Required Checks, probe
|
||||
pull request, and `platform-dev` authority.
|
||||
- **Spec 464 — GitHub Website Delivery Cutover v1**: website workflows, Ruleset,
|
||||
probe pull request, and `website-dev` authority.
|
||||
- **Spec 465 — GitHub Dev Promotion Gate and Gitea Archival v1**: `dev` Ruleset,
|
||||
promotion, team remote cutover, final authority, and Gitea read-only archival.
|
||||
|
||||
## Final Preparation Verdict
|
||||
|
||||
The candidate is approved as the smallest passive-copy migration slice. No
|
||||
application implementation or remote repository mutation is authorized by this
|
||||
specification alone.
|
||||
@ -0,0 +1,248 @@
|
||||
# Tasks: GitHub Repository Bootstrap and Git Data Baseline v1
|
||||
|
||||
**Input**: `spec.md`, `plan.md`, `research.md`, `quickstart.md`,
|
||||
`checklists/requirements.md`, and `execution-contract.json`
|
||||
**Branch**: `462-github-repository-bootstrap-git-data-baseline-v1`
|
||||
**Base / target / diff baseline**: `platform-dev`
|
||||
**Scope**: only
|
||||
`specs/462-github-repository-bootstrap-git-data-baseline-v1/**`
|
||||
**Tests**: Heavy-Governance Git evidence, the targeted existing Pest foundation
|
||||
guard, constitution-required Sail Pint, and current local quality gates; no new
|
||||
application test and no browser, PostgreSQL, provider, queue, or website lane
|
||||
|
||||
Every implementation task is unchecked until its evidence exists. Preparation,
|
||||
local finalization, external GitHub activation, non-mutating rollback handling,
|
||||
and post-integration follow-up are separate authority boundaries.
|
||||
|
||||
## Task Format
|
||||
|
||||
`- [ ] TNNN [P?] [US?] Action with exact artifact path`
|
||||
|
||||
`[P]` is allowed only when the task is read-only or file-disjoint and every prior
|
||||
phase gate has passed. External mutations never run in parallel.
|
||||
|
||||
## Phase 1: Setup and Hard-Gate Preflight
|
||||
|
||||
**Purpose**: Bind the active package, branch, baseline, role workflow, and scope
|
||||
before implementation writes.
|
||||
|
||||
- [x] T001 Run `scripts/run-agent-quality-gates preflight --spec specs/462-github-repository-bootstrap-git-data-baseline-v1` and record the result in `specs/462-github-repository-bootstrap-git-data-baseline-v1/implementation-report.md`.
|
||||
- [x] T002 Record current branch, HEAD, `platform-dev` merge base, status, upstream, and main-clone remotes in `specs/462-github-repository-bootstrap-git-data-baseline-v1/implementation-report.md`.
|
||||
- [x] T003 Prove the working tree contains no unrelated path and the active allowlist is limited to `specs/462-github-repository-bootstrap-git-data-baseline-v1/**`; record the proof in `specs/462-github-repository-bootstrap-git-data-baseline-v1/implementation-report.md`.
|
||||
- [x] T004 Verify completed/implemented Specs 416, 439, 458, 459, 460, and 461 remain byte-unchanged from `platform-dev` and record their read-only guard result in `specs/462-github-repository-bootstrap-git-data-baseline-v1/implementation-report.md`.
|
||||
- [x] T005 Record installed Git, GitHub CLI, jq, SHA-256 tooling, source URL, target tuple, and NFR-007 portability evidence without secrets in `specs/462-github-repository-bootstrap-git-data-baseline-v1/implementation-report.md`.
|
||||
- [x] T006 Obtain the current `code_explorer` handoff for local repository-governance scope and record its sanitized gate summary in `specs/462-github-repository-bootstrap-git-data-baseline-v1/implementation-report.md`.
|
||||
- [x] T007 Confirm no hard-gate stop condition is active, hand the bounded allowlist/evidence brief to the `implementer`, and record Phase-1 PASS in `specs/462-github-repository-bootstrap-git-data-baseline-v1/implementation-report.md`.
|
||||
|
||||
**Checkpoint**: No inventory, manifest, helper, external setting, or ref write may
|
||||
start until T001–T007 pass.
|
||||
|
||||
---
|
||||
|
||||
## Phase 2: Foundational Evidence Contract
|
||||
|
||||
**Purpose**: Define deterministic tracked evidence and activation boundaries
|
||||
before any remote mutation.
|
||||
|
||||
- [x] T008 Create the canonical source-inventory shape and generation notes in `specs/462-github-repository-bootstrap-git-data-baseline-v1/git-source-ref-inventory.json`.
|
||||
- [x] T009 Create the local-only reachability/disposition shape in `specs/462-github-repository-bootstrap-git-data-baseline-v1/local-only-ref-inventory.json`.
|
||||
- [x] T010 Create exhaustive server/local/excluded disposition sections in `specs/462-github-repository-bootstrap-git-data-baseline-v1/branch-disposition.json`.
|
||||
- [x] T011 Create exact target/ref/digest manifest sections in `specs/462-github-repository-bootstrap-git-data-baseline-v1/github-transfer-manifest.json`.
|
||||
- [x] T012 Create source/target parity, integrity, setting, origin, and authority sections in `specs/462-github-repository-bootstrap-git-data-baseline-v1/github-parity-report.json`.
|
||||
- [x] T013 Create the exact no-authority/read-only/authorized-mutation/rollback checklist in `specs/462-github-repository-bootstrap-git-data-baseline-v1/external-activation-checklist.md`.
|
||||
- [x] T014 Validate JSON parseability, deterministic key/ref ordering, digest rules, cross-artifact identifiers, and NFR-001/NFR-002 completeness for `specs/462-github-repository-bootstrap-git-data-baseline-v1/*.json`; record Phase-2 PASS in `specs/462-github-repository-bootstrap-git-data-baseline-v1/implementation-report.md`.
|
||||
|
||||
**Checkpoint**: Evidence shapes and authorization semantics are stable before
|
||||
target/source inventory work.
|
||||
|
||||
---
|
||||
|
||||
## Phase 3: User Story 1 — Prove the Target Is Safe (P1)
|
||||
|
||||
**Goal**: Prove the exact private GitHub target is manageable and empty and that
|
||||
Actions is disabled before transfer.
|
||||
|
||||
**Independent test**: Read-only GitHub metadata/ref queries establish identity,
|
||||
visibility, permission, emptiness, release/history state, and Actions state; any
|
||||
unexpected state stops the workflow.
|
||||
|
||||
### Validation tasks
|
||||
|
||||
- [x] T015 [US1] Have the root coordinator query and record exact target owner/name, visibility, and administrative permission in `specs/462-github-repository-bootstrap-git-data-baseline-v1/external-activation-checklist.md`.
|
||||
- [x] T016 [US1] Have the root coordinator query and record target heads, tags, remote HEAD, and initial-history state in `specs/462-github-repository-bootstrap-git-data-baseline-v1/external-activation-checklist.md`.
|
||||
- [x] T017 [US1] Have the root coordinator query and record releases, issues, open pull requests, workflow runs, non-owner collaborators/teams, deploy keys, webhooks, repository workflows, Rulesets, branch protection/Required Checks, runners, secret names, variable names, and environments in `specs/462-github-repository-bootstrap-git-data-baseline-v1/external-activation-checklist.md` without reading secret values.
|
||||
- [x] T018 [US1] Have the root coordinator query and record current GitHub Actions permission state in `specs/462-github-repository-bootstrap-git-data-baseline-v1/external-activation-checklist.md`.
|
||||
|
||||
### Story completion tasks
|
||||
|
||||
- [x] T019 [US1] Reconcile T015–T018 against FR-001–FR-003, FR-005–FR-006, AC-001–AC-002, and the measurable FR-029 preflight invariants; record whether FR-004 is already satisfied or pending authorized disablement in `specs/462-github-repository-bootstrap-git-data-baseline-v1/implementation-report.md`.
|
||||
- [x] T020 [US1] Record the hard-stop verdict for any wrong identity, non-private visibility, missing admin permission, pre-existing ref/history, unexpected passive-authority configuration other than a verifiable enabled Actions state, or unreadable/unverifiable required invariant in `specs/462-github-repository-bootstrap-git-data-baseline-v1/external-activation-checklist.md`.
|
||||
- [x] T021 [US1] Record `US1_PASS` only when Actions is already disabled; otherwise record `TARGET_PREFLIGHT_READY` with the exact pending Actions-disablement and no ref-transfer authority in `specs/462-github-repository-bootstrap-git-data-baseline-v1/implementation-report.md`.
|
||||
|
||||
---
|
||||
|
||||
## Phase 4: User Story 2 — Account for Every Source and Local Ref (P1)
|
||||
|
||||
**Goal**: Produce exhaustive authoritative and local-only inventories with no
|
||||
unaccounted work or transferable private namespace.
|
||||
|
||||
**Independent test**: Server/local counts reconcile, names are unique, every head
|
||||
has exactly one disposition, and every local-only unique commit has a retention
|
||||
outcome.
|
||||
|
||||
### Validation-first inventory tasks
|
||||
|
||||
- [x] T022 [US2] Have the root coordinator query Gitea HEAD/default branch, all server heads/tags with exact OIDs, and every readable repository setting, branch protection, hook, deploy key, collaborator/team, workflow, and delivery-authority surface required by FR-030; record redacted raw-command/API hashes and `NOT_PROVEN` for any unreadable required surface in `specs/462-github-repository-bootstrap-git-data-baseline-v1/implementation-report.md`.
|
||||
- [x] T023 [US2] Have the root coordinator create a fresh bare Gitea clone outside the repository, reconcile or fetch exact missing server tags into that temporary clone, run Git integrity validation, and record NFR-006 isolated redacted provenance in `specs/462-github-repository-bootstrap-git-data-baseline-v1/implementation-report.md`.
|
||||
- [x] T024 [US2] Canonicalize source heads, tags, peeled tag OIDs, counts, timestamp, default branch, source HEAD, and digest in `specs/462-github-repository-bootstrap-git-data-baseline-v1/git-source-ref-inventory.json`.
|
||||
- [x] T025 [US2] Reconcile `git ls-remote` and fresh-bare-clone refs with zero missing/duplicate entries in `specs/462-github-repository-bootstrap-git-data-baseline-v1/git-source-ref-inventory.json`.
|
||||
- [x] T026 [US2] Enumerate local heads and exact OIDs without modifying refs and record the canonical set in `specs/462-github-repository-bootstrap-git-data-baseline-v1/local-only-ref-inventory.json`.
|
||||
- [x] T027 [US2] Enumerate stash, Codex, turn-diff, worktree-private, pull, reflog-only, and temporary namespaces as excluded identities/counts in `specs/462-github-repository-bootstrap-git-data-baseline-v1/local-only-ref-inventory.json`.
|
||||
- [x] T028 [US2] Compute each local-only head's authority reachability, unique commit count, and merge bases to `dev`, `platform-dev`, and `website-dev` in `specs/462-github-repository-bootstrap-git-data-baseline-v1/local-only-ref-inventory.json`.
|
||||
- [x] T029 [US2] Account for every commit reachable only through local heads or excluded namespaces in `specs/462-github-repository-bootstrap-git-data-baseline-v1/local-only-ref-inventory.json`.
|
||||
|
||||
### Disposition tasks
|
||||
|
||||
- [x] T030 [US2] Assign `MIGRATE_ACTIVE` only to `dev`, `platform-dev`, and `website-dev` in `specs/462-github-repository-bootstrap-git-data-baseline-v1/branch-disposition.json`.
|
||||
- [x] T031 [US2] Assign every other Gitea head to `ARCHIVE_ONLY` unless an exact current approved `MIGRATE_RETAINED` exception exists in `specs/462-github-repository-bootstrap-git-data-baseline-v1/branch-disposition.json`.
|
||||
- [x] T032 [US2] Assign every local-only head to `RETAIN_LOCAL_ONLY` or `LOCAL_REDUNDANT` with reason and unique-commit evidence, and prove no local-only head is eligible for transfer in `specs/462-github-repository-bootstrap-git-data-baseline-v1/branch-disposition.json`.
|
||||
- [x] T033 [US2] Define and, where required, verify the external bundle retention path/digest for non-migrated unique commits in `specs/462-github-repository-bootstrap-git-data-baseline-v1/local-only-ref-inventory.json` without deleting local refs.
|
||||
- [x] T034 [US2] Prove 100% one-to-one inventory/disposition coverage and reconciled summary counts in `specs/462-github-repository-bootstrap-git-data-baseline-v1/branch-disposition.json`.
|
||||
- [x] T035 [US2] Record US2 PASS for FR-007–FR-015, AC-004–AC-005, and SC-001 in `specs/462-github-repository-bootstrap-git-data-baseline-v1/implementation-report.md`.
|
||||
|
||||
---
|
||||
|
||||
## Phase 5: User Story 3 — Transfer Only Explicitly Allowed Git Data (P1)
|
||||
|
||||
**Goal**: Build an exact manifest and, only after current authorization, create
|
||||
selected GitHub refs from a fresh bare Gitea clone.
|
||||
|
||||
**Independent test**: Planned and executed refspecs equal the manifest exactly;
|
||||
no mirror, force, delete, wildcard head, main-remote change, or branch convergence
|
||||
occurs.
|
||||
|
||||
### Manifest and dry-run tasks
|
||||
|
||||
- [x] T036 [US3] Bind target tuple, source inventory digest, disposition digest, all three authority heads, approved retained Gitea server heads, and all source tags in `specs/462-github-repository-bootstrap-git-data-baseline-v1/github-transfer-manifest.json`.
|
||||
- [x] T037 [US3] Record excluded namespaces and prove no `ARCHIVE_ONLY`, non-migrated local-only, stash, Codex, worktree-private, pull, or temporary ref is present in `specs/462-github-repository-bootstrap-git-data-baseline-v1/github-transfer-manifest.json`.
|
||||
- [x] T038 [US3] Validate exact source/target ref names and OIDs, zero wildcard head authorization, zero force/delete/mirror semantics, and the canonical manifest digest in `specs/462-github-repository-bootstrap-git-data-baseline-v1/github-transfer-manifest.json`.
|
||||
- [x] T039 [US3] Generate and record a no-mutation refspec preview plus exact planned setting mutations in `specs/462-github-repository-bootstrap-git-data-baseline-v1/external-activation-checklist.md`.
|
||||
- [x] T040 [US3] Present the exact reviewed mutation set and retained-server-ref decisions for separate current user authorization; record only attributable non-secret NFR-003/NFR-004 authority status in `specs/462-github-repository-bootstrap-git-data-baseline-v1/external-activation-checklist.md`.
|
||||
|
||||
### Authorized activation tasks
|
||||
|
||||
- [x] T041 [US3] If T040 lacks exact current authorization, record `PRE_ACTIVATION_READY` in `specs/462-github-repository-bootstrap-git-data-baseline-v1/implementation-report.md`, stop all external mutation tasks, and record that implementation completion plus completion/finalization receipt issuance remain forbidden.
|
||||
|
||||
Historical `PRE_ACTIVATION_READY` lock: T042-T058 were held until separate
|
||||
current external activation authority and Gitea writer-control proof were
|
||||
provided. The owner-controlled freeze, transfer, and parity evidence recorded on
|
||||
2026-08-02 satisfied that lock; T042-T058 are therefore complete.
|
||||
|
||||
- [x] T042 [US3] If exactly authorized and Actions is enabled, have the root coordinator disable it; if already disabled, perform no setting mutation. In either case reverify the disabled state, promote the target verdict to `US1_PASS`, and record the response without credentials in `specs/462-github-repository-bootstrap-git-data-baseline-v1/external-activation-checklist.md`.
|
||||
- [x] T043 [US3] Have the root coordinator reprove target emptiness; enumerate every Gitea write-capable human, team, deploy key, bot, workflow, and automation path; record attributable pause confirmation for each active writer; bind the freeze start timestamp to a refreshed equal source digest; and stop if any writer cannot be enumerated, controlled, or paused in `specs/462-github-repository-bootstrap-git-data-baseline-v1/external-activation-checklist.md`.
|
||||
- [x] T044 [US3] Invalidate the manifest and stop if T043 finds drift; otherwise record the accepted frozen inventory/manifest identities in `specs/462-github-repository-bootstrap-git-data-baseline-v1/github-transfer-manifest.json`.
|
||||
- [x] T045 [US3] Have the root coordinator create GitHub `dev` from the temporary bare source only, set default branch to `dev`, then create `platform-dev`, `website-dev`, approved retained Gitea server heads, and tags using exact manifest refspecs; record redacted results in `specs/462-github-repository-bootstrap-git-data-baseline-v1/implementation-report.md`.
|
||||
- [x] T046 [US3] Prove transfer output contains zero forced update, overwrite, deletion, mirror, wildcard, or unlisted refspec and record NFR-003/NFR-005 command/exit evidence in `specs/462-github-repository-bootstrap-git-data-baseline-v1/implementation-report.md`.
|
||||
- [x] T047 [US3] Prove the main development clone's remote configuration and authority branches are unchanged in `specs/462-github-repository-bootstrap-git-data-baseline-v1/implementation-report.md`.
|
||||
- [x] T048 [US3] Record US3 PASS for FR-016–FR-023 and AC-006–AC-007, or the authorized fail-closed stop, in `specs/462-github-repository-bootstrap-git-data-baseline-v1/implementation-report.md`.
|
||||
|
||||
---
|
||||
|
||||
## Phase 6: User Story 4 — Prove Parity and Passive Authority (P1)
|
||||
|
||||
**Goal**: Prove exact Git-data parity, zero extras, target integrity, stable source,
|
||||
and unchanged delivery authority.
|
||||
|
||||
**Independent test**: Every manifest ref is `OID_MATCH`, the three authority trees
|
||||
match, a fresh target bare clone is intact, source refs did not drift, and target
|
||||
settings remain passive.
|
||||
|
||||
### Parity tasks
|
||||
|
||||
- [x] T049 [US4] Have the root coordinator query all target heads/tags and record exact ref/OID comparisons against the manifest in `specs/462-github-repository-bootstrap-git-data-baseline-v1/github-parity-report.json`.
|
||||
- [x] T050 [US4] Record commit OID, tree OID, parent count, and subject parity for `dev`, `platform-dev`, and `website-dev` in `specs/462-github-repository-bootstrap-git-data-baseline-v1/github-parity-report.json`.
|
||||
- [x] T051 [US4] Prove zero extra, archive-only, local-only, stash, Codex, worktree-private, pull, or temporary target refs in `specs/462-github-repository-bootstrap-git-data-baseline-v1/github-parity-report.json`.
|
||||
- [x] T052 [US4] Have the root coordinator create a fresh target bare clone outside the repository, run `git fsck --full`, and record NFR-006 missing/corrupt/dangling-object truth in `specs/462-github-repository-bootstrap-git-data-baseline-v1/github-parity-report.json`.
|
||||
- [x] T053 [US4] Have the root coordinator reverify target owner/name, private visibility, default branch `dev`, Actions disabled state, zero open pull requests/workflow runs/non-owner collaborators/teams, and no configured deploy keys, webhooks, repository workflows, Rulesets, branch protection/Required Checks, runners, secrets, variables, or environments in `specs/462-github-repository-bootstrap-git-data-baseline-v1/github-parity-report.json`; any unreadable required invariant is `NOT_PROVEN` and blocks PASS.
|
||||
- [x] T054 [US4] Have the root coordinator requery Gitea refs/default branch and every readable FR-030 authority/settings surface, compare them with T022, prove the command/API audit log contains no Gitea mutation, compare the post-transfer source digest with the frozen digest, and record `NOT_PROVEN` for any unreadable required surface in `specs/462-github-repository-bootstrap-git-data-baseline-v1/github-parity-report.json`.
|
||||
- [x] T055 [US4] End the logical source freeze only after T049–T054 pass, record the freeze interval, stable source digest, writer/automation release confirmations, and zero uncontrolled-writer evidence in `specs/462-github-repository-bootstrap-git-data-baseline-v1/external-activation-checklist.md`.
|
||||
- [x] T056 [US4] Record non-destructive rollback readiness: stop further writes, keep GitHub private and Actions disabled, preserve evidence and temporary clones, emit `INVALID_PARTIAL_BASELINE` on partial/failing transfer, and prove Spec 462 performs no ref/repository deletion or recreation in `specs/462-github-repository-bootstrap-git-data-baseline-v1/implementation-report.md`.
|
||||
- [x] T057 [US4] Record the exact GitHub passive/Gitea active declarations and metadata/archive deferrals in `specs/462-github-repository-bootstrap-git-data-baseline-v1/implementation-report.md`.
|
||||
- [x] T058 [US4] Reconcile FR-024–FR-035, AC-008–AC-015, and SC-002–SC-006; record FR-036 as a proven stop-before-follow-up boundary rather than a completed reconciliation in `specs/462-github-repository-bootstrap-git-data-baseline-v1/implementation-report.md`.
|
||||
|
||||
---
|
||||
|
||||
## Phase 7: Candidate Validation, Review, and Handoff
|
||||
|
||||
**Purpose**: Freeze one exact local candidate and stop at the separately
|
||||
authorized local finalization boundary.
|
||||
|
||||
- [x] T059 Complete every verdict-applicable evidence artifact, NFR-004 redaction proof, NFR-005 audit fields, and exactly one schema-valid `tenantpilot-implementation-evidence` block in `specs/462-github-repository-bootstrap-git-data-baseline-v1/implementation-report.md`; under `PRE_ACTIVATION_READY`, keep `spec.md`, `plan.md`, and `execution-contract.json` at `Ready for implementation`, while after `PASSIVE_BASELINE_VERIFIED` synchronize their status to `Implemented` before freezing the candidate and record the operational verdict separately from the schema status.
|
||||
- [x] T060 Reconcile all T001–T059 task outcomes, explicit stops, N/A lanes, no completed-spec rewrite, and the exact completion verdict in `specs/462-github-repository-bootstrap-git-data-baseline-v1/tasks.md`; activation/parity tasks remain explicitly incomplete only while the historical `PRE_ACTIVATION_READY` lock applies.
|
||||
- [x] T061 Run NFR-001–NFR-007 JSON/digest/scope/safety checks, `git diff --check`, current Spec Package validation, routed candidate gates, `cd apps/platform && ./vendor/bin/sail artisan test --compact tests/Feature/Guards/CodexAgentFoundationContractTest.php`, and `cd apps/platform && ./vendor/bin/sail bin pint --dirty --format agent`; record exact commands/results in `specs/462-github-repository-bootstrap-git-data-baseline-v1/implementation-report.md`.
|
||||
- [x] T062 Obtain independent `test_validator` evidence bound to the exact frozen candidate and record its sanitized identity/result in `specs/462-github-repository-bootstrap-git-data-baseline-v1/implementation-report.md`.
|
||||
- [x] T063 Obtain one complete independent `code_reviewer` result for the frozen candidate and validation evidence; record `NO_CONFIRMED_FINDINGS` or bounded findings in `specs/462-github-repository-bootstrap-git-data-baseline-v1/implementation-report.md`.
|
||||
- [x] T064 Apply only confirmed in-scope corrections under `specs/462-github-repository-bootstrap-git-data-baseline-v1/**`, rerun affected validation and complete review, and stop rather than widening scope when current governance requires escalation.
|
||||
- [x] T065 Only after `PASSIVE_BASELINE_VERIFIED` plus matching validation/review/report evidence, record `IMPLEMENTATION_REVIEWED` and run completion/receipt issuance; under `PRE_ACTIVATION_READY`, prove no completion or finalization receipt was issued and record the external activation boundary in `specs/462-github-repository-bootstrap-git-data-baseline-v1/implementation-report.md`.
|
||||
- [x] T066 Stop before local commit, push, pull request, merge, deployment, or promotion unless each receives separate current authority; always stop before post-integration reconciliation and hand that work to Spec 463 or another explicitly approved follow-up in `specs/462-github-repository-bootstrap-git-data-baseline-v1/implementation-report.md`.
|
||||
|
||||
---
|
||||
|
||||
## Dependencies and Execution Order
|
||||
|
||||
```text
|
||||
Phase 1 preflight
|
||||
-> Phase 2 evidence contract
|
||||
-> US1 target proof
|
||||
-> US2 source/local inventory
|
||||
-> US3 manifest and external activation gate
|
||||
-> US4 parity/passivity proof
|
||||
-> Phase 7 candidate validation and review
|
||||
```
|
||||
|
||||
- US1 and US2 are independently verifiable read-only deliverables after Phase 2,
|
||||
but US3 activation depends on both.
|
||||
- US4 depends on an authorized completed US3 transfer. If authorization is not
|
||||
granted, the valid stopping verdict is `PRE_ACTIVATION_READY`; it is not feature
|
||||
completion and cannot issue a completion/finalization receipt.
|
||||
- Read-only network queries may be orchestrated concurrently by the root
|
||||
coordinator, but task completion and tracked evidence writes are sequential;
|
||||
no task is marked `[P]`.
|
||||
- External mutations T042–T045 are sequential and never parallel.
|
||||
- Phase 7 validates the exact frozen candidate after all applicable prior tasks.
|
||||
|
||||
## Parallel Example
|
||||
|
||||
After Phase 2 passes, the root coordinator may collect independent read-only
|
||||
query results concurrently, but it records them sequentially in the shared
|
||||
artifacts. No writer, task completion, or mutation task is parallelized.
|
||||
|
||||
## Implementation Strategy
|
||||
|
||||
### Smallest safe implementation increment
|
||||
|
||||
US1 target proof plus US2 inventory/disposition plus an exact dry-run manifest is
|
||||
the smallest safe pre-activation increment. It can stop at
|
||||
`PRE_ACTIVATION_READY` and has value as a reviewed migration plan without mutating
|
||||
GitHub, but it is not implementation completion.
|
||||
|
||||
### Activation increment
|
||||
|
||||
US3 and US4 form one indivisible authorized activation increment. The target is
|
||||
not accepted after transfer until complete parity/passivity proof passes.
|
||||
|
||||
### Follow-up boundary
|
||||
|
||||
Post-integration `platform-dev` reconciliation and platform delivery stay in Spec
|
||||
463 or another explicitly approved follow-up. Website delivery and final
|
||||
`dev`/Gitea authority cutovers stay in Specs 464 and 465. They are not
|
||||
implementation tasks of Spec 462.
|
||||
|
||||
## Explicit Non-Goals
|
||||
|
||||
- No `.github/workflows/**` or `.gitea/workflows/**` change.
|
||||
- No GitHub PR, Ruleset, Required Check, runner, secret, variable, or environment.
|
||||
- No Gitea metadata migration or archival activation.
|
||||
- No application/runtime/UI/website/database/provider/queue/deployment change.
|
||||
- No branch merge, rebase, convergence, force update, deletion, or local cleanup.
|
||||
- No shared repository migration framework or permanent multi-host abstraction.
|
||||
Reference in New Issue
Block a user