chore: establish GitHub repository data baseline #528

Merged
ahmido merged 1 commits from 462-github-repository-bootstrap-git-data-baseline-v1 into platform-dev 2026-08-02 15:05:24 +00:00
14 changed files with 20021 additions and 0 deletions

View File

@ -0,0 +1,138 @@
# Specification Quality Checklist: GitHub Repository Bootstrap and Git Data Baseline v1
**Purpose**: Validate that the Spec-462 requirements are complete, clear,
consistent, measurable, and safe before implementation.
**Created**: 2026-08-01
**Feature**: [spec.md](../spec.md)
**Depth / audience**: formal implementation-readiness gate for maintainers and
independent reviewers
## Content Quality
- [x] CHK001 Is the maintainer trust/safety problem stated independently of a
low-level implementation choice? [Clarity, Spec §Summary]
- [x] CHK002 Is the passive-copy user value separated from later delivery
cutovers? [Scope, Spec §Candidate Source]
- [x] CHK003 Are all mandatory specification sections completed without an
unresolved clarification marker? [Completeness]
- [x] CHK004 Is repository-specific implementation detail limited to safety-
critical transfer constraints and moved to the plan where possible?
[Consistency]
## Requirement Completeness
- [x] CHK005 Are exact target identity, privacy, permission, emptiness, and Actions
requirements defined? [Completeness, Spec FR-001FR-006]
- [x] CHK006 Are authoritative source heads, tags, peeled tag objects, default
branch, counts, and digest requirements defined? [Completeness, Spec FR-007FR-008]
- [x] CHK007 Are all server, local-only, unique-commit, and excluded-ref outcomes
exhaustively specified? [Completeness, Spec FR-009FR-015]
- [x] CHK008 Are retained-branch approval fields and the fail-closed default
specified? [Clarity, Spec §Branch and Authority Contract]
- [x] CHK009 Are exact-ref, fresh-bare-source, no-mirror, no-force, no-delete, and
no-main-remote-change requirements explicit? [Safety, Spec FR-016FR-021]
- [x] CHK010 Are source-writer enumeration/pause proof, freeze drift, target drift,
and re-review consequences defined? [Recovery, Spec FR-022FR-023]
- [x] CHK011 Are OID, tree, target-integrity, extra-ref, default-branch, measurable
GitHub passive-authority, and readable Gitea unchanged-authority requirements
defined? [Completeness, Spec FR-024FR-030]
- [x] CHK012 Are metadata migration, non-destructive rollback, independent review,
and the stop-before-post-integration-follow-up boundary specified?
[Completeness, Spec FR-031FR-036]
## Requirement Clarity and Consistency
- [x] CHK013 Are `MIGRATE_ACTIVE`, server-only `MIGRATE_RETAINED`,
`ARCHIVE_ONLY`, `RETAIN_LOCAL_ONLY`, `LOCAL_REDUNDANT`, and
`EXCLUDED_NON_AUTHORITY_REF` assigned non-overlapping consequences? [Clarity,
Spec §Branch and Authority Contract]
- [x] CHK014 Is “all tags” consistent between goals, functional requirements,
manifest design, acceptance criteria, and tasks? [Consistency]
- [x] CHK015 Is “GitHub passive / Gitea active” defined through measurable
configuration/governance invariants without falsely claiming administrators
lack intrinsic write capability? [Consistency]
- [x] CHK016 Is the main development remote invariant distinguished from the
temporary bare-clone target remote? [Clarity, Spec FR-018FR-021]
- [x] CHK017 Are `TARGET_PREFLIGHT_READY`, `PRE_ACTIVATION_READY`,
`PASSIVE_BASELINE_VERIFIED`, and `IMPLEMENTATION_REVIEWED` distinguished from
local commit and external repository mutation authority? [Clarity, Spec
§Completion Verdicts]
- [x] CHK018 Does the spec avoid implying that a task checkbox, role handoff,
receipt, or execution contract grants remote authority? [Safety]
## Acceptance Criteria Quality
- [x] CHK019 Can every acceptance criterion be objectively decided from tracked
or command evidence? [Measurability, Spec AC-001AC-015]
- [x] CHK020 Do success criteria quantify exhaustive coverage, parity, and zero-
extra-ref outcomes? [Measurability, Spec SC-001SC-005]
- [x] CHK021 Is the qualitative handoff outcome for later cutover owners explicit
and reviewable? [User value, Spec SC-006]
- [x] CHK022 Are failure conditions fail-closed, with partial transfer recorded as
`INVALID_PARTIAL_BASELINE` rather than successful or destructively cleaned up?
[Consistency, Spec NFR-003]
## Scenario and Edge-Case Coverage
- [x] CHK023 Are primary target-proof, inventory, authorized-transfer, and parity
flows each independently testable? [Coverage, Spec §User Scenarios]
- [x] CHK024 Are unexpected target history, permission failure, source drift,
annotated tags, local-only reachability, private refs, and target-integrity
exceptions covered? [Coverage, Spec §Edge Cases]
- [x] CHK025 Are partial-transfer rollback, evidence preservation, source/local
no-change, and no-delete/no-recreate requirements documented? [Recovery, Spec
§External Mutation Boundary]
- [x] CHK026 Is post-integration `platform-dev` reconciliation explicitly deferred
to Spec 463 or another approved follow-up rather than claimed complete by the
pre-integration candidate? [Coverage, Spec FR-036]
## Constitution and Governance Alignment
- [x] CHK027 Does the Spec Candidate Check include all mandatory rubric fields,
one approval class, score, red-flag defense, and scope-reduction decision?
[SPEC-GATE-001]
- [x] CHK028 Does the proportionality review justify the evidence artifacts and
disposition vocabulary without creating a shared provider framework?
[PROP-001, BLOAT-001]
- [x] CHK029 Are completed Specs 416/439/458/459/460/461 explicitly read-only?
[Completed-spec guard]
- [x] CHK030 Are current five-role local governance and separate root-owned remote
activation reconciled with the submitted draft? [Instruction consistency]
- [x] CHK031 Is Product Surface/browser/Human Product Sanity N/A handling coherent
and non-duplicative? [Product Surface Contract]
- [x] CHK032 Are application runtime, workspace/RBAC, OperationRun, provider,
database, queue, asset, and deployment impacts truthfully N/A? [Scope]
- [x] CHK033 Is the test purpose classified as Heavy-Governance with temporary Git
state only, the targeted existing Pest foundation guard, constitution-required
Sail Pint, and no hidden application fixture cost? [TEST-GOV-001, Quality Gates]
## Dependencies and Assumptions
- [x] CHK034 Are the GitHub target's pre-created state and later revalidation
requirement both explicit? [Assumption]
- [x] CHK035 Are Gitea reachability, administrative GitHub access, complete
write-capable actor/automation enumeration, and retained-branch default
assumptions documented? [Assumptions]
- [x] CHK036 Are Specs 463465 clearly deferred instead of hidden inside Spec 462?
[Dependency, Scope]
- [x] CHK037 Are later user decisions represented as explicit fail-closed gates
whose pre-activation verdict cannot be mistaken for implementation completion?
[Clarity]
## Review Outcome
- [x] CHK038 Review outcome class: `acceptable-special-case` — repository-hosting
governance is intentionally outside product UI/runtime.
- [x] CHK039 Workflow outcome: `keep` — the passive-copy slice is bounded and its
later authority cutovers are separate specs.
- [x] CHK040 Final note location: future Spec-462 implementation report and local
PR close-out; Product Surface note remains concise N/A.
## Notes
- Preparation review found no blocking ambiguity.
- “No implementation details” is interpreted proportionally: exact ref, no-force,
fresh-bare-clone, freeze, and parity rules are requirements-level safety
constraints for this Git migration, not premature application design.
- All checklist items pass after preparation alignment with current repository
branch, role, quality-gate, and completed-spec rules.

View File

@ -0,0 +1,164 @@
{
"schema_version": 1,
"spec": {
"id": 462,
"slug": "github-repository-bootstrap-git-data-baseline-v1",
"path": "specs/462-github-repository-bootstrap-git-data-baseline-v1",
"status": "Implemented",
"branch": "462-github-repository-bootstrap-git-data-baseline-v1",
"branch_family": "repository-wide",
"integration_base": "platform-dev",
"integration_target": "platform-dev",
"diff_baseline": "platform-dev"
},
"change": {
"classifications": [
"repository-governance",
"git-hosting-bootstrap",
"git-data-migration",
"external-activation-gated"
],
"runtime_impact": "none",
"product_surface": {
"impact": "none",
"reason": "No rendered product surface changes."
},
"browser": {
"required": false,
"reason": "No rendered product surface changes."
},
"postgresql": {
"required": false,
"reason": "No database schema, query, lock, index, or PostgreSQL behavior changes."
},
"deployment": {
"required": false,
"reason": "No application deployment behavior changes."
}
},
"scope": {
"allow": [
{
"kind": "prefix",
"path": "specs/462-github-repository-bootstrap-git-data-baseline-v1/"
}
],
"deny": [
{
"kind": "prefix",
"path": "apps/platform/"
},
{
"kind": "prefix",
"path": "apps/website/"
},
{
"kind": "prefix",
"path": ".github/workflows/"
},
{
"kind": "prefix",
"path": ".gitea/workflows/"
},
{
"kind": "prefix",
"path": ".agent/"
},
{
"kind": "prefix",
"path": ".codex/"
},
{
"kind": "prefix",
"path": ".specify/"
},
{
"kind": "prefix",
"path": "scripts/"
},
{
"kind": "prefix",
"path": "docs/"
},
{
"kind": "file",
"path": "AGENTS.md"
},
{
"kind": "file",
"path": "README.md"
},
{
"kind": "prefix",
"path": "specs/416-tenantpilot-agent-skill-layer-v1/"
},
{
"kind": "prefix",
"path": "specs/439-branch-topology-local-evidence-truth/"
},
{
"kind": "prefix",
"path": "specs/458-codex-agent-foundation-safe-local-finalization/"
},
{
"kind": "prefix",
"path": "specs/459-mechanical-agent-quality-gates-validation-routing/"
},
{
"kind": "prefix",
"path": "specs/460-post-integration-additive-correction-contract-v1/"
},
{
"kind": "prefix",
"path": "specs/461-additive-correction-contract-conformance-repair-v1/"
}
]
},
"required_gates": [
"spec-package",
"diff-scope",
"diff-safety",
"unicode",
"change-validation",
"agent-handoff",
"implementation-report",
"finalization-receipt",
"foundation-regression",
"git-diff-check",
"independent-review"
],
"declared_na_gates": [
{
"id": "product-surface",
"reason": "No rendered product surface changes."
},
{
"id": "browser",
"reason": "No rendered product surface changes."
},
{
"id": "postgresql-lane",
"reason": "No database or PostgreSQL-specific behavior changes."
},
{
"id": "migration",
"reason": "No database schema changes."
},
{
"id": "provider-runtime",
"reason": "No application provider runtime changes."
},
{
"id": "queue-runtime",
"reason": "No queue runtime changes."
},
{
"id": "customer-output",
"reason": "No customer output changes."
},
{
"id": "deployment",
"reason": "No application deployment behavior changes."
}
]
}

View File

@ -0,0 +1,341 @@
# External Activation Checklist
Spec 462 preparation itself granted no GitHub or Gitea mutation authority. This
checklist records both the historical pre-activation evidence and the separately
authorized, completed external activation on 2026-08-02.
## Current Authority State
- Local implementation authority: active-spec files only.
- External activation authority: `GRANTED_AND_CONSUMED_FOR_EXACT_OPERATION_SET`.
- GitHub setting mutation authority: `GRANTED_AND_CONSUMED_ACTIONS_DISABLE_ONLY`.
- GitHub ref creation authority: `GRANTED_AND_CONSUMED_EXACT_THREE_HEADS`.
- GitHub default-branch mutation authority: `GRANTED_AND_CONSUMED_DEV_ONLY`.
- Gitea mutation authority: `NOT_GRANTED`.
- Local commit/finalization authority: `NOT_GRANTED`.
- Operational verdict: `PASSIVE_BASELINE_VERIFIED`.
- GitHub Git state: `VERIFIED_PASSIVE_COPY`.
- GitHub PR authority: `NOT_ACTIVE`.
- GitHub CI authority: `NOT_ACTIVE`.
- GitHub merge authority: `NOT_ACTIVE`.
- Gitea authority: `ACTIVE`.
## Completed External Activation — 2026-08-02
Status: `PASSIVE_BASELINE_VERIFIED`.
All commands and responses recorded here are sanitized. No credential, token,
device code, private key, secret value, or authenticated header is included.
### Owner-controlled source freeze
- Freeze start: `2026-08-02T12:28:27Z`.
- Freeze end: `2026-08-02T12:43:01Z`.
- Responsible writer/owner: `ahmido`.
- Freeze proof: attributable owner attestation that every other human, local or
external Git session, agent session, browser/CLI/SSH writer, and automation
path was paused and would perform no Gitea ref mutation during the window.
- Corroborating read-only enumeration: no collaborators, deploy keys, or
webhooks; zero open pull requests; protected `dev` direct push disabled; the
four repository workflows declare only `actions: read` and `contents: read`
permissions and contain no ref-mutating command.
- Freeze-start Gitea inventory: 481 heads, 0 tags; canonical raw `ls-remote`
SHA-256
`2e09341107651ec553e6287afce3c27d2f17312e8177bd26c40f87b74dec051a`.
- Comparison with the reviewed source inventory: exact ref/OID diff 0 bytes;
self-describing source-inventory digest
`e17dd1ec644abe590706136bebe7722d0b3307bb6b0c6bc0b7fe5e1ae1315fb0`.
- Eight complete Gitea captures spanning freeze start, immediately before each
push, after each push, and final parity were byte-identical.
- Owner attestation was released only after the final equal inventory and target
parity checks passed. No uncontrolled writer or unexpected source mutation was
observed.
### Authorized transfer
- GitHub Actions had been disabled at `2026-08-02T11:55:35Z` as the first and
separate authorized mutation and were read-only reverified disabled before
transfer, after every ref creation, and after final parity.
- Target was reproven immediately before transfer as exact
`senadoroahmido-wq/tenantpilot`, `PRIVATE`, `ADMIN`, 0 heads, 0 tags, no default
branch, and no initial history.
- Accepted immutable transfer-manifest digest:
`6b8e763999599572007586b73938c3cbb23f08a38cb11272d0cd8abdeb5dca33`.
- Fresh source clone:
`/tmp/tenantpilot-spec462-activation.xy3pmQ/source.git`, cloned directly from
`git@git.cloudarix.de:ahmido/TenantAtlas.git`; source URL exact, three
authorized objects reachable, `git fsck --full` exit 0 with no output.
- A temporary authenticated HTTPS GitHub remote existed only in that bare clone.
The development clone origin remained
`git@git.cloudarix.de:ahmido/TenantAtlas.git` for fetch and push.
- Ordered mutations actually executed:
1. create `refs/heads/dev` at
`55338a88c69044c632cb006b7e7b066fbd2659b9`;
2. set GitHub default branch to `dev`;
3. create `refs/heads/platform-dev` at
`7b99dae113fb24652a079df369d6378ed356f234`;
4. create `refs/heads/website-dev` at
`af5fa3034133942a4fcd43d5ba3cfdd975795869`.
- Tags transferred: 0. Retained heads transferred: 0.
- Every push used one exact full refspec. Force, force-with-lease, wildcard,
mirror, delete, overwrite, and unlisted-ref semantics were absent.
- After every ref creation: the new target OID matched, no other target ref
changed, Actions remained disabled, workflow-run count remained 0, and the
complete Gitea inventory remained byte-identical.
### Final passive-copy proof
- GitHub heads: exactly 3 (`dev`, `platform-dev`, `website-dev`).
- GitHub tags: exactly 0.
- Default branch: `dev`.
- Actions: `DISABLED`; workflow executions: `NOT_TRIGGERED`; workflow-run count:
0.
- Fresh target clone:
`/tmp/tenantpilot-spec462-activation.xy3pmQ/target.git`; exactly 3 heads and 0
tags; `git fsck --full` exit 0 with no missing, corrupt, or dangling objects.
- OID, tree, parent-count, and subject parity pass for all three authority heads.
- Extra/excluded target refs: 0, including archive-only, retained-local-only,
local-redundant, stash, Codex, turn-diff, worktree-private, pull, temporary,
and the Spec-462 feature branch.
- Final GitHub inventory SHA-256:
`6c3d6de707c5c3c773feca6fa2b5fa119eb119d309fe0120777068bf1925b5b9`.
- Final Gitea inventory SHA-256 remained
`2e09341107651ec553e6287afce3c27d2f17312e8177bd26c40f87b74dec051a`.
- GitHub passive surfaces: owner only, 0 teams, deploy keys, webhooks,
repository workflows, workflow runs, runners, secret names, variable names,
environments, releases, and open pull requests. Rulesets and branch protection
are unavailable for this private plan and the rule count is 0.
- GitHub remains only a verified passive Git-data copy. Gitea remains the active
delivery authority; GitHub PR, CI, and merge authority are not active.
## Read-Only Target Proof
Status: `TARGET_PREFLIGHT_READY`.
- Target tuple: `senadoroahmido-wq/tenantpilot`.
- HTTPS: `https://github.com/senadoroahmido-wq/tenantpilot.git`.
- SSH: `git@github.com:senadoroahmido-wq/tenantpilot.git`.
- Required proof before activation: private visibility, administrative
permission, zero heads/tags, no initial history, no releases, no open pull
requests, no workflow runs, no non-owner collaborators or teams, no deploy
keys, no webhooks, no repository workflows, no Rulesets, no branch protection
or Required Checks, no runners, secret names only, variable names only, and no
environments.
- Actions state: `ENABLED_PENDING_AUTHORIZED_DISABLEMENT`.
### Superseded Target Preflight Evidence - 2026-08-02
Status: `SUPERSEDED_BY_CURRENT_AUTH`.
All evidence in this section was collected read-only by the root coordinator and
contains no token, credential, secret value, private key material, or raw
authenticated header.
- Authenticated GitHub account: `ahmido2012-eng`.
- Auth protocol: SSH.
- Auth token: redacted.
- Permission note: token scopes were not sufficient for hook query, and the
repository itself remained wholly unresolved across GraphQL, REST, and Git.
- `gh auth status --hostname github.com`: authenticated account
`ahmido2012-eng`; no mutation.
- `gh repo view senadoroahmido-wq/tenantpilot --json nameWithOwner,visibility,viewerPermission,defaultBranchRef,isEmpty,isArchived`:
exit 1; GraphQL could not resolve repository.
- REST GETs under `repos/senadoroahmido-wq/tenantpilot`: HTTP 404 for repo
metadata, releases, issues, pulls, workflow runs, collaborators, teams, deploy
keys, webhooks, workflows, rulesets, branches, runners, secret names, variable
names, environments, and Actions permissions.
- `git ls-remote --symref --heads --tags git@github.com:senadoroahmido-wq/tenantpilot.git`:
exit 128; repository not found; sanitized error hash
`44d07ddc3c69893b8002d9e09642636177dba35ec5df821773b934fd1b05f892`.
- `git ls-remote --symref git@github.com:senadoroahmido-wq/tenantpilot.git HEAD`:
exit 128; repository not found; sanitized error hash
`44d07ddc3c69893b8002d9e09642636177dba35ec5df821773b934fd1b05f892`.
- Mutations performed: zero.
- Proven target identity: `NOT_PROVEN`.
- Proven private visibility: `NOT_PROVEN`.
- Proven administrative permission: `NOT_PROVEN`.
- Proven empty heads/tags/history: `NOT_PROVEN`.
- Proven passive-authority settings: `NOT_PROVEN`.
### Current Target Preflight Evidence - 2026-08-02
All evidence in this section was collected read-only by the root coordinator and
contains no token, credential, secret value, private key material, raw
authenticated header, or ephemeral clone credential metadata.
- Authenticated GitHub account: `senadoroahmido-wq`.
- Auth protocol configured: SSH.
- Auth token/scopes: not recorded.
- `gh repo view senadoroahmido-wq/tenantpilot --json nameWithOwner,visibility,viewerPermission,defaultBranchRef,isEmpty,isArchived`:
exit 0; `nameWithOwner` exact `senadoroahmido-wq/tenantpilot`; visibility
`PRIVATE`; viewer permission `ADMIN`; `isEmpty` true; archived false;
GraphQL `defaultBranchRef.name` empty.
- Sanitized repository metadata SHA-256:
`d6c903f57b583c4d8f69cfa0e1fdb74d994575db5871efa84994569bb8838f25`.
Proven fields: full name exact, owner exact, private true, visibility private,
admin true, archived false, disabled false, size 0, open issues count 0.
- Empty-repository placeholder `default_branch`: `main`.
- GraphQL default branch: empty.
- Initial history/refs: none proven.
- Persistent SSH `git ls-remote`: exit 128 because the local SSH identity cannot
access this repo; SSH is locally unavailable for activation proof.
- Authenticated HTTPS using the non-persistent `gh auth git-credential` helper:
`git ls-remote --symref --heads --tags` exit 0 with empty output; output
SHA-256 `e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855`.
- Authenticated HTTPS using the non-persistent `gh auth git-credential` helper:
`git ls-remote --symref ... HEAD` exit 0 with empty output; output SHA-256
`e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855`.
- Proven read/activation transport for target ref checks: authenticated HTTPS
through the non-persistent `gh auth git-credential` helper.
- Git configuration mutations: zero.
- Remote configuration mutations: zero.
- Remote repository mutations: zero.
- Releases: empty array; hash
`4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945`.
- Issues: empty array; hash
`4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945`.
- Open pull requests: empty array; hash
`4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945`.
- Workflow runs: total 0; hash
`a2790a384d7d281e7395679000c35d27768d89dbd7052f725b8f4688beb59915`.
- Collaborators: owner only; non-owner count 0; hash
`22d3688c0ae2f9382c355319f448029beb3ae33760b3d8727ab4108f53739087`.
- Teams: empty array; hash
`4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945`.
- Deploy keys: empty array; hash
`4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945`.
- Webhooks: empty array; hash
`4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945`.
- Repository workflows: total 0; hash
`51da78a4f28ec83978198558b5be95ebec25c44ab19561c168a975e203f0a785`.
- Branches: empty array; hash
`4f53cda18c2baa0c0354bb5f9a3ecbe5ed12ab4d8e11ba873c2f11161202b945`.
- Runners: total 0; hash
`15d67a2c40c7d15b5c983f3fc7731b443f21aa98e462927ef97d22125649780f`.
- Secret names: total 0; hash
`8cd981a659e02c3591c81d01a25bd2b59e980217dac663b062140e632de8c31a`.
- Variable names: total 0; hash
`2ce9f1466656cd2968a9bd6da1d4fb3487b394f794ba91ac268708addd0ebb7f`.
- Environments: total 0; hash
`a96111929536c1533c11cdcbf059a2db0a9520ac1b52fb53d76f7e11e3e906a8`.
- Rulesets REST: HTTP 403 with authoritative feature-unavailable message that
GitHub Pro or public visibility is required; sanitized response hash
`09dee4d2fc3b14ae7cd63bf636f6ce57f414b4f78fbe4a4e67c7a91f66152a54`.
Result: `FEATURE_UNAVAILABLE`; for this verified private repo, no configured
Ruleset is present.
- GraphQL branch protection rules: total 0, nodes empty; hash
`b55cdc92d01b163f6e1b383b5ed6dfba198d90dcd5a214ee65a43084400e8c88`.
- Required Checks: count 0 because branches are empty and branch protection rule
count is 0.
- Actions permissions: enabled true, allowed actions `all`, SHA pinning required
false; hash
`25842d2b9453f8e5fed37a198b9a268cf6aee1225690bf5fb91a89e8542ea718`.
- Mutations performed: zero.
### Historical Target Verdict
Verdict: `TARGET_PREFLIGHT_READY`.
FR-001-FR-003, FR-005-FR-006, AC-001-AC-002, and the measurable target
preflight invariants pass. FR-004 is not yet satisfied because GitHub Actions are
enabled and require separately authorized exact disablement before any ref
transfer. No ref transfer, target default-branch mutation, or GitHub setting
mutation authority exists from this checklist.
## Historical Pre-Activation Source and Local Proof
Status: `US2_PASS`.
- Source authority: `git@git.cloudarix.de:ahmido/TenantAtlas.git`.
- Source inventory digest:
`e17dd1ec644abe590706136bebe7722d0b3307bb6b0c6bc0b7fe5e1ae1315fb0`.
- Local-only inventory digest:
`082dfbb1bc127e7679f0cb9e9866704bb2fa79a9d0e3f36c6dbd7303b20845e3`.
- Branch disposition digest:
`87c1ccdee500ac82525d575f4f62fc773f116817828106bbde378fe77e8a34b8`.
- Required proof before manifest acceptance is complete for read-only refs,
fresh bare clone integrity, local-only branch comparison, excluded namespace
accounting, verified local retention bundle, and exact digests.
- Repeat Gitea `ls-remote` before pre-activation: 481 lines, SHA-256
`2e09341107651ec553e6287afce3c27d2f17312e8177bd26c40f87b74dec051a`.
- `source-preactivation-drift.diff`: zero bytes against initial source
inventory.
- Source write freeze: `NOT_STARTED`.
- Gitea write-capable authority surfaces required by FR-030 remain
`NOT_PROVEN` without an API token and remain a hard activation prerequisite.
## Historical No-Mutation Manifest Preview
Status: `PRE_ACTIVATION_READY`.
The preview is deterministic manifest rendering only. No `git push --dry-run`
was executed. No temporary remote was added. Main-clone remotes are unchanged.
No GitHub, Gitea, local ref, default-branch, settings, or remote mutation was
performed.
- Manifest digest:
`6b8e763999599572007586b73938c3cbb23f08a38cb11272d0cd8abdeb5dca33`.
- Authorization: `NOT_GRANTED`; `manifest_authorizes_mutation` false.
- Planned head refspecs, in target-ref order:
1. `refs/heads/dev:refs/heads/dev` at
`55338a88c69044c632cb006b7e7b066fbd2659b9`
2. `refs/heads/platform-dev:refs/heads/platform-dev` at
`7b99dae113fb24652a079df369d6378ed356f234`
3. `refs/heads/website-dev:refs/heads/website-dev` at
`af5fa3034133942a4fcd43d5ba3cfdd975795869`
- Planned retained server heads: none.
- Planned tags: none.
- Excluded from transfer: 478 archive-only heads, 71 local-only heads, codex 1,
turn-diff 25, pull 0, reflog-only 0, stash 1, temporary 0, worktree-private
15.
- Excluded identities present in planned refs: 0.
- Forbidden semantics: wildcard heads false, force false, delete false, mirror
false, overwrite existing target refs false.
- Target drift proof: GitHub exact/private/ADMIN/isEmpty true/defaultBranchRef
empty; authenticated HTTPS heads/tags output empty, exit 0, SHA-256
`e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855`.
- Actions state remains enabled/all and requires separate current authorization
for disablement before any ref transfer.
## Historical Reviewed Mutation Set
These operations were locked until separate current user authorization named
the exact reviewed operation set. That authority was later supplied and consumed
only as recorded in the completed activation section above:
1. Disable GitHub Actions if read-only proof shows Actions enabled:
`gh api --method PUT repos/senadoroahmido-wq/tenantpilot/actions/permissions -F enabled=false`,
then read-only reverify.
2. Reprove target emptiness and enumerate/pause every Gitea writer and
automation path. The current missing Gitea API token leaves those authority
surfaces `NOT_PROVEN`; this is a hard prerequisite and is not waived by later
GitHub mutation authority.
3. Inside the preserved temporary bare source only, use authenticated HTTPS
through ephemeral `gh auth git-credential` and create `dev` with exact
refspec `refs/heads/dev:refs/heads/dev`, no force.
4. After `dev` exists, set the target default branch:
`gh api --method PATCH repos/senadoroahmido-wq/tenantpilot -f default_branch=dev`.
5. Create `platform-dev` with exact refspec
`refs/heads/platform-dev:refs/heads/platform-dev`, no force.
6. Create `website-dev` with exact refspec
`refs/heads/website-dev:refs/heads/website-dev`, no force.
7. Create no retained heads and no tags.
The user's GitHub CLI authentication completion is authentication only. It is
not separate current authorization for GitHub setting mutation, ref creation, or
default-branch mutation. Retained server-ref decision: none.
No authorization in this checklist permits GitHub PR, issue, workflow, Ruleset,
Required Check, runner, secret, variable, environment, release, package,
collaborator, team, webhook, deploy-key, visibility, repository deletion,
repository recreation, target ref deletion, Gitea metadata migration, Gitea
archival, Gitea mutation, local commit, push, pull request, merge, deployment, or
promotion.
## Rollback Boundary
Before activation, rollback is no action. After any partial or failed authorized
transfer, Spec 462 rollback is non-mutating: stop further writes, keep GitHub
private with Actions disabled, preserve evidence, record
`INVALID_PARTIAL_BASELINE`, and require a separate spec or amendment plus
separate current authority for any cleanup.

View File

@ -0,0 +1,197 @@
{
"artifact": "github-parity-report",
"artifact_version": 1,
"authority_verdict": {
"gitea_authority": "ACTIVE",
"github_authority": "VERIFIED_PASSIVE_COPY",
"github_ci_authority": "NOT_ACTIVE",
"github_merge_authority": "NOT_ACTIVE",
"github_pr_authority": "NOT_ACTIVE",
"metadata_migration": "NOT_PERFORMED",
"post_integration_reconciliation": "DEFERRED_TO_SPEC_463_OR_APPROVED_FOLLOW_UP",
"status": "PASSIVE_BASELINE_VERIFIED"
},
"canonicalization": {
"digest_algorithm": "sha256",
"digest_input": "pretty sorted jq output from serialization_command, including trailing LF, with digest.value omitted",
"line_endings": "LF",
"object_key_order": "lexicographic",
"ref_array_order": "full_ref_name_ascending",
"serialization_command": "jq -S 'del(.digest.value)' ARTIFACT | shasum -a 256"
},
"digest": {
"algorithm": "sha256",
"status": "FINAL",
"value": "a6062138fefa6bf449f9d378798b1698ed05458ceca450178712446d6787ab9a"
},
"gitea_source_stability": {
"after_raw_ls_remote_sha256": "2e09341107651ec553e6287afce3c27d2f17312e8177bd26c40f87b74dec051a",
"before_raw_ls_remote_sha256": "2e09341107651ec553e6287afce3c27d2f17312e8177bd26c40f87b74dec051a",
"capture_count": 8,
"drift_diff_bytes": 0,
"freeze_ended_at_utc": "2026-08-02T12:43:01Z",
"freeze_started_at_utc": "2026-08-02T12:28:27Z",
"no_mutation_command_log": "PASS_ZERO_GITEA_MUTATION_COMMANDS",
"owner_attestation": "ahmido confirmed exclusive writer control for the full transfer window",
"settings_unchanged": "PASS_OWNER_CONTROLLED_FREEZE_AND_ZERO_GITEA_MUTATIONS",
"status": "PASS"
},
"github_passive_authority": {
"actions_disabled": true,
"actions_state": "DISABLED",
"branch_protection": "FEATURE_UNAVAILABLE_PRIVATE_REPOSITORY_AND_ZERO_RULES",
"collaborators_and_teams": "OWNER_ONLY_AND_ZERO_TEAMS",
"default_branch": "dev",
"deploy_keys": "EMPTY",
"environments": "EMPTY",
"issues": "EMPTY",
"open_pull_requests": "EMPTY",
"packages": "NOT_MIGRATED",
"passive_baseline_verified": true,
"releases": "EMPTY",
"required_checks": "ZERO",
"rulesets": "FEATURE_UNAVAILABLE_PRIVATE_REPOSITORY_AND_ZERO_RULES",
"runners": "EMPTY",
"secrets": "EMPTY_NAMES_ONLY",
"target_exact_private_admin": true,
"target_repository": "senadoroahmido-wq/tenantpilot",
"variables": "EMPTY_NAMES_ONLY",
"visibility": "PRIVATE",
"webhooks": "EMPTY",
"workflow_runs": 0,
"workflows": "EMPTY"
},
"inputs": {
"github_transfer_manifest_digest": "6b8e763999599572007586b73938c3cbb23f08a38cb11272d0cd8abdeb5dca33",
"source_inventory_digest": "e17dd1ec644abe590706136bebe7722d0b3307bb6b0c6bc0b7fe5e1ae1315fb0",
"status": "FINAL"
},
"local_authority_branches": {
"dev": {
"oid": "55338a88c69044c632cb006b7e7b066fbd2659b9",
"ref": "refs/heads/dev"
},
"platform_dev": {
"oid": "7b99dae113fb24652a079df369d6378ed356f234",
"ref": "refs/heads/platform-dev"
},
"website_dev": {
"oid": "af5fa3034133942a4fcd43d5ba3cfdd975795869",
"ref": "refs/heads/website-dev"
}
},
"origin_remote_check": {
"after": "origin git@git.cloudarix.de:ahmido/TenantAtlas.git (fetch/push)",
"before": "origin git@git.cloudarix.de:ahmido/TenantAtlas.git (fetch/push)",
"main_clone_remote_changed": false,
"status": "UNCHANGED_POST_TRANSFER"
},
"parity": {
"authority_branch_tree_checks": [
{
"commit_oid": "55338a88c69044c632cb006b7e7b066fbd2659b9",
"parent_count": 1,
"ref": "refs/heads/dev",
"status": "OID_TREE_METADATA_MATCH",
"subject": "merge: platform-dev into dev (#311)",
"tree_oid": "75c87269c5d8fd22930fd90732dcd348ee07d335"
},
{
"commit_oid": "7b99dae113fb24652a079df369d6378ed356f234",
"parent_count": 1,
"ref": "refs/heads/platform-dev",
"status": "OID_TREE_METADATA_MATCH",
"subject": "fix: stabilize Spec 459 package validation self-test (#527)",
"tree_oid": "2b1a0bf306b07841ccf63a19e076529f23913d4e"
},
{
"commit_oid": "af5fa3034133942a4fcd43d5ba3cfdd975795869",
"parent_count": 1,
"ref": "refs/heads/website-dev",
"status": "OID_TREE_METADATA_MATCH",
"subject": "410: add public docs information architecture (#412)",
"tree_oid": "93923bc80dc5d20ae4b304bea12f32b10fcab73b"
}
],
"excluded_ref_classes_present": [],
"extra_target_refs": [],
"head_count": 3,
"post_transfer_parity_claimed": true,
"ref_oid_comparisons": [
{
"manifest_oid": "55338a88c69044c632cb006b7e7b066fbd2659b9",
"ref": "refs/heads/dev",
"source_oid": "55338a88c69044c632cb006b7e7b066fbd2659b9",
"status": "OID_MATCH",
"target_oid": "55338a88c69044c632cb006b7e7b066fbd2659b9"
},
{
"manifest_oid": "7b99dae113fb24652a079df369d6378ed356f234",
"ref": "refs/heads/platform-dev",
"source_oid": "7b99dae113fb24652a079df369d6378ed356f234",
"status": "OID_MATCH",
"target_oid": "7b99dae113fb24652a079df369d6378ed356f234"
},
{
"manifest_oid": "af5fa3034133942a4fcd43d5ba3cfdd975795869",
"ref": "refs/heads/website-dev",
"source_oid": "af5fa3034133942a4fcd43d5ba3cfdd975795869",
"status": "OID_MATCH",
"target_oid": "af5fa3034133942a4fcd43d5ba3cfdd975795869"
}
],
"status": "PASS",
"tag_count": 0
},
"rollback_readiness": {
"cleanup_mutation_allowed": false,
"delete_target_refs_allowed": false,
"invalid_partial_baseline_verdict": "AVAILABLE_AFTER_PARTIAL_OR_FAILED_AUTHORIZED_TRANSFER",
"repository_recreation_allowed": false,
"status": "PASS_NOT_NEEDED"
},
"schema_version": 1,
"spec": {
"baseline": "platform-dev",
"branch": "462-github-repository-bootstrap-git-data-baseline-v1",
"id": 462,
"path": "specs/462-github-repository-bootstrap-git-data-baseline-v1"
},
"status": "PASSIVE_BASELINE_VERIFIED",
"target_integrity": {
"default_branch_dev_claimed": true,
"fresh_bare_clone": "/tmp/tenantpilot-spec462-activation.xy3pmQ/target.git",
"fresh_bare_clone_fsck_full": "PASS",
"missing_or_corrupt_objects": 0,
"post_transfer_target_clone_integrity_claimed": true,
"status": "PASS"
},
"transfer": {
"actions_disabled_at_utc": "2026-08-02T11:55:35Z",
"forbidden_semantics": {
"delete": false,
"force": false,
"mirror": false,
"overwrite": false,
"wildcard": false
},
"heads_transferred": 3,
"ordered_mutations": [
"disable_github_actions",
"create_refs_heads_dev",
"set_default_branch_dev",
"create_refs_heads_platform_dev",
"create_refs_heads_website_dev"
],
"source_bare_clone": "/tmp/tenantpilot-spec462-activation.xy3pmQ/source.git",
"tags_transferred": 0,
"transport": "authenticated HTTPS through non-persistent gh auth git-credential helper",
"workflow_execution": "NOT_TRIGGERED",
"workflow_runs_after": 0,
"workflow_runs_before": 0
},
"worktree_state": {
"index": "EMPTY",
"staged_changes": "none"
}
}

View File

@ -0,0 +1,444 @@
# Implementation Plan: GitHub Repository Bootstrap and Git Data Baseline v1
**Branch**: `462-github-repository-bootstrap-git-data-baseline-v1`
**Date**: 2026-08-01
**Spec**: `specs/462-github-repository-bootstrap-git-data-baseline-v1/spec.md`
**Status**: Implemented
**Integration base / target / diff baseline**: `platform-dev`
## Summary
Prepare and execute one bounded repository-governance migration that makes the
existing private GitHub repository a verified passive Git copy of authoritative
Gitea data. The implementation inventories all server and local-only refs,
classifies every ref, builds an exact transfer allowlist, crosses a separately
authorized GitHub activation boundary from a fresh temporary bare clone, and
proves exact parity while leaving all active delivery authority on Gitea.
No application runtime, application test, workflow, UI, website, database,
deployment, or shared agent infrastructure is changed. Every tracked
implementation artifact remains under the active Spec-462 directory.
## Technical Context
- **Repository root**:
`/Users/ahmeddarrazi/Documents/projects/wt-plattform`
- **Source Git host**: Gitea repository
`git@git.cloudarix.de:ahmido/TenantAtlas.git`
- **Target Git host**: private GitHub repository
`senadoroahmido-wq/tenantpilot`
- **Local Git**: 2.50.1
- **GitHub CLI**: 2.92.0; authentication and target permissions must be
revalidated immediately before activation
- **JSON tooling**: jq 1.7.1
- **Digest tooling**: `/usr/bin/shasum -a 256`
- **Current origin**: Gitea for fetch and push; it remains unchanged
- **Application technologies**: unchanged and not exercised by this spec
- **Validation scale**: one deterministic run covers 100% of the actual repository
ref set and records ref counts plus elapsed duration; no application latency SLO
or application test lane applies
- **Constraints**: exact refs only, no mirror/force/delete, no source mutation,
no main-worktree remote change, no branch convergence, no credential capture
## Preparation Decisions
### Candidate selection
The user directly supplied Spec 462. No local/remote Spec-462 branch or spec
package existed, and no related spec duplicates the passive-copy slice. Specs
463465 remain independent delivery-authority cutovers.
### Branch topology
This is repository-wide/cross-stream governance performed from the platform
stream. The feature starts from, targets, and diffs against `platform-dev`.
`dev` remains repository-wide integration/promotion authority but is not the
feature target.
### Completed-spec protection
Specs 416, 439, 458, 459, 460, and 461 are read-only source evidence. Their
specs, tasks, validation history, and implementation reports must not change.
### Submitted-draft deviation
The user draft proposed a single-owner flow without a validator. Current
`AGENTS.md` requires the fixed Spec-458 roles for repository-governance work.
Local candidate work therefore uses the current ordered handoff:
```text
code_explorer -> implementer -> test_validator -> code_reviewer -> git_finalizer
```
The root coordinator owns orchestration and all remote Git network operations,
including source queries and temporary cloning. It may cross the external GitHub
mutation boundary only after separate current user authorization. No role,
handoff, execution contract, or local finalization receipt grants remote
authority.
## Constitution Check
### Pre-design gate
| Principle | Result | Evidence / handling |
|---|---|---|
| Spec-first and branch routing | PASS | Explicit repository-wide class with `platform-dev` base/target/baseline |
| SPEC-GATE-001 | PASS | Core Enterprise, 8/12 after passive-copy scope reduction |
| PROP/BLOAT/ABSTR | PASS | Finite migration evidence and dispositions; no shared framework or runtime taxonomy |
| Read/write separation | PASS WITH MANUAL GATE | All GitHub mutations are separated from preparation and require exact current authorization |
| Persisted truth | PASS | Tracked artifacts are auditable migration truth; no application persistence |
| State consequence | PASS | Dispositions directly decide transfer eligibility or retention |
| Test governance | PASS | Heavy-Governance Git evidence plus the targeted existing Pest foundation guard and constitution-required Sail Pint; no application/browser/database fixture cost |
| Product Surface | PASS / N/A | No rendered product surface |
| Workspace/RBAC/OperationRun/provider | PASS / N/A | No application boundary touched |
| Completed-spec guard | PASS | Related completed/implemented specs are read-only |
| No legacy / no dual write | PASS | Staged hard cutover; GitHub remains passive |
No constitution violation requires an exception.
### Post-design recheck
The design keeps one evidence path, one finite disposition model, one exact
manifest, and one parity report. No data model, API contract, application layer,
package dependency, shared repository tool, or Product Surface concept is added.
The constitution gate remains PASS with the external activation condition.
## Scope and Repository Surfaces
### Allowed tracked scope
```text
specs/462-github-repository-bootstrap-git-data-baseline-v1/**
```
Preparation artifacts:
```text
spec.md
plan.md
tasks.md
research.md
quickstart.md
checklists/requirements.md
execution-contract.json
```
Implementation/activation evidence:
```text
git-source-ref-inventory.json
local-only-ref-inventory.json
branch-disposition.json
github-transfer-manifest.json
github-parity-report.json
external-activation-checklist.md
implementation-report.md
```
Spec-local deterministic helpers and self-tests may be added only when the
implementation proves documented Git/jq commands cannot produce or validate the
artifacts safely. Shared `scripts/**` changes require a separate spec.
### Denied repository scope
- `apps/platform/**`
- `apps/website/**`
- `.github/workflows/**`
- `.gitea/workflows/**`
- `.agent/**`
- `.codex/**`
- `.specify/**`
- `scripts/**`
- `docs/**`
- `AGENTS.md`
- `README.md`
- Specs 416, 439, 458, 459, 460, and 461
- every path outside the active Spec-462 directory
### External mutation allowlist
After separate current user authorization only:
1. disable GitHub Actions;
2. create exact GitHub refs listed in the reviewed transfer manifest;
3. set GitHub default branch to `dev` after `dev` exists.
Visibility, owner/name, collaboration, Rulesets, branch protection, webhooks,
secrets, variables, environments, runners, workflows, issues, pull requests,
releases, packages, and all Gitea state are denied.
Target ref/repository deletion or recreation is also denied; Spec-462 rollback is
non-mutating.
## Data and Evidence Design
### Source inventory
`git-source-ref-inventory.json` is a canonical snapshot of the authoritative
Gitea repository at the freeze boundary. It records repository identity,
default branch, source HEAD, heads/tags/peeled tag objects, counts, capture time,
and digest. Arrays are sorted by full ref name before hashing.
### Local-only inventory
`local-only-ref-inventory.json` compares local heads with authoritative Gitea
heads. For every local-only branch it records tip OID, reachability, unique commit
count, merge bases to each authority branch, disposition, reason, and retention
evidence. Local-only heads are limited to `RETAIN_LOCAL_ONLY` or
`LOCAL_REDUNDANT`; publishing them is outside this slice. Stash/Codex/worktree/
private namespaces are listed only as excluded ref identities and counts;
secrets are never serialized.
### Branch disposition
`branch-disposition.json` is exhaustive and one-to-one. It separates Gitea heads,
local-only heads, and excluded non-authority namespaces. Totals must reconcile
with the inventory. `MIGRATE_RETAINED` entries are authoritative Gitea server
heads only and include explicit approval evidence without embedding raw user
prompts or credentials.
### Transfer manifest
`github-transfer-manifest.json` binds the target tuple, source inventory digest,
disposition digest, exact selected ref names/OIDs, all source tags, excluded
namespaces, and a manifest digest. It authorizes no wildcard refspec.
### Parity report
`github-parity-report.json` binds the accepted manifest and records every
source/target OID comparison, authority-branch tree/parent proof, target extra-ref
set, target clone integrity, source stability, default branch, visibility,
Actions state, all readable passive-authority invariants, before/after readable
Gitea authority surfaces, origin-remoteness check, and authority verdict. An
unreadable required invariant is recorded as `NOT_PROVEN` and prevents a PASS.
### No application data model or API contracts
`data-model.md` and `contracts/` are intentionally omitted. The feature creates
no application entity, database schema, HTTP/API contract, event contract, or
runtime state machine. The bounded JSON artifact shapes above are migration
evidence and are specified directly in the active plan/spec.
## Technical Approach
### 1. Local preflight and candidate identity
- prove the feature branch began at the recorded clean `platform-dev` HEAD;
- run the active Spec Package preflight before implementation writes;
- verify the exact active-spec allowlist and completed-spec protection;
- record source origin and installed tool versions without changing remotes.
### 2. Target read-only verification
Use authenticated GitHub metadata and Git ref queries to prove exact owner/name,
private visibility, administrator permission, zero heads/tags/releases, current
Actions state, open pull requests/workflow runs, collaborators/teams, deploy keys,
webhooks, workflows, Rulesets, branch protection/Required Checks, runners,
secrets, variables, and environments. Secret values are never queried or
recorded. If any target ref or initial history exists, stop for a spec amendment.
If Actions is enabled but its state is verifiable, record
`TARGET_PREFLIGHT_READY`; US1 does not PASS until the authorized disablement is
verified.
### 3. Authoritative source capture
The root coordinator queries Gitea with `git ls-remote --symref` and creates a
fresh temporary bare clone outside the repository. It reconciles every server
tag against the bare clone and, if necessary, fetches exact missing tag refs into
that temporary clone before the manifest is frozen. Canonicalize heads and tags,
preserve annotated tag object/peeled OIDs, sort deterministically, and hash the
stable representation. Capture the readable Gitea default branch, repository
settings, branch protections, hooks, deploy keys, collaborators/teams, workflows,
and delivery-authority posture plus a no-mutation command/API log baseline; any
required but unreadable surface is `NOT_PROVEN`.
### 4. Local-only reachability analysis
Compare local heads against authoritative Gitea refs using exact OIDs and graph
reachability. Account for commits reachable only from local heads or excluded
namespaces. Do not delete, rewrite, merge, or publish any local ref.
### 5. Disposition and manifest review
Default non-authority server heads to `ARCHIVE_ONLY`; assign only the three
authority branches to `MIGRATE_ACTIVE`. `MIGRATE_RETAINED` remains empty unless
the user approves exact authoritative Gitea server refs. Local-only refs are
never manifest inputs. Reconcile counts/digests and perform a no-mutation refspec
preview.
### 6. External activation gate
Present the exact target setting mutations and exact ref list/OIDs to the user.
Without a new current authorization, stop at `PRE_ACTIVATION_READY`; this is not
implementation completion and cannot issue a completion/finalization receipt.
With authority:
- disable Actions;
- re-prove target emptiness;
- enumerate every Gitea write-capable human/automation path, record attributable
pause confirmation, and begin the source freeze;
- refresh inventory and invalidate the manifest on any drift.
If any writer cannot be enumerated, controlled, or paused, stop. Spec 462 does
not mutate Gitea settings to create an enforceable freeze.
### 7. Bare-clone transfer
Within the temporary bare source clone only, add a temporary target remote and
create refs in this order: `dev`, set default branch to `dev`, `platform-dev`,
`website-dev`, approved retained Gitea server heads, then tags. Every command uses
an exact refspec and no force/delete/mirror option.
### 8. Parity and authority proof
Requery source and target refs, compare exact OIDs and authority trees, prove no
extras/exclusions, clone GitHub freshly and run full integrity validation, verify
every readable GitHub passive-authority invariant, compare the readable Gitea
authority/settings snapshot, and confirm the main clone origin remains Gitea.
End the logical freeze only after source stability and all writer pause/release
evidence are proven. Any unreadable required surface blocks the authority verdict.
### 9. Candidate validation, review, and local finalization boundary
Freeze tracked evidence, run routed candidate checks, perform independent
validation and complete-diff review, remediate only confirmed in-scope findings,
and rerun affected checks/review. Local commit finalization occurs only through
the current safe helper with a valid receipt and separate commit authority.
### 10. Post-integration boundary
Spec 462 stops before post-integration reconciliation. Spec 463 or another
explicitly approved follow-up must compare the integrated Gitea `platform-dev`
OID, obtain exact current authorization for any target update, and repeat full
parity/passivity proof before a delivery-authority cutover. Spec-462 validation
must not claim that later operation is complete.
## Security and Authority Controls
- Exact GitHub owner/repository/visibility and admin permission are fail-closed.
- No credential, token, private key, authenticated header, or raw CLI auth output
is written to tracked evidence.
- Target refs must be absent before creation.
- No command may contain `--mirror`, `--force`, `--force-with-lease`, deletion
refspecs, or wildcard head authorization.
- The current clone's remotes are captured before and after and must be identical.
- Temporary paths are explicit, outside the repository, and removed only after
evidence and rollback readiness are complete.
- External activation requires current attributable user authorization distinct
from implementation and local commit authority. Spec-462 rollback is
non-mutating; cleanup or target deletion/recreation requires a scope amendment
or separate spec plus separate current authority.
## Validation Strategy
### Preparation validation
- Spec package readiness validation.
- Cross-artifact consistency analysis.
- Requirements checklist completion.
- JSON schema validation for `execution-contract.json`.
- `git diff --check` and active-spec-only status review.
### Implementation validation
- Canonical JSON parse/sort/hash checks.
- Inventory/disposition/manifest count reconciliation.
- Exact ref allowlist and forbidden-option assertions.
- Source freeze before/after digest equality.
- Source/target OID and authority tree comparison.
- Target extra/excluded-ref checks.
- Fresh bare target clone plus `git fsck --full`.
- Target settings and main-origin invariants.
- Current quality-gate candidate/completion workflow and independent review.
- Targeted constitutional Pest validation:
`cd apps/platform && ./vendor/bin/sail artisan test --compact tests/Feature/Guards/CodexAgentFoundationContractTest.php`.
- Constitution-required finalization formatting check:
`cd apps/platform && ./vendor/bin/sail bin pint --dirty --format agent`.
### Application lanes
- Livewire v4 compliance: unchanged; no Livewire code.
- Provider registration: unchanged at `apps/platform/bootstrap/providers.php`.
- Global search: no resources changed.
- Destructive/high-impact product actions: none.
- Asset strategy: no assets; `filament:assets` not required.
- The existing Pest foundation guard above is required as a targeted
Heavy-Governance constitutional check. No new or modified application test is
added.
- Platform feature, website, PostgreSQL, and browser lanes: N/A unless routing
unexpectedly detects an out-of-scope change, which is a stop condition rather
than a reason to broaden scope.
- Deployment impact: none for env, migrations, queues, scheduler, storage, assets,
Dokploy, staging, or production.
## Rollback Strategy
Before transfer, rollback is no action. After a partial transfer, Spec-462
rollback stops further writes, keeps GitHub private and Actions disabled,
preserves all evidence, records `INVALID_PARTIAL_BASELINE`, and leaves Gitea,
local refs/worktrees/remotes, and existing target evidence untouched. It never
deletes a target ref or recreates the repository. Cleanup is separate scoped work
with separate authority. If parity fails, GitHub must not be described as a valid
passive baseline.
## Risk Controls
| Risk | Control | Stop condition |
|---|---|---|
| Wrong/non-empty target | exact metadata/ref preflight | any unexpected identity/ref/history |
| Source drift | freeze and three inventory points | any digest difference |
| Local/private ref leakage | fresh bare source and exact manifest | any unlisted refspec |
| Historical branch pollution | default `ARCHIVE_ONLY` | missing or duplicate disposition |
| Local commit loss | reachability inventory and bundle plan | unaccounted unique commit |
| Workflow execution | Actions disabled before/after | Actions cannot be proven disabled |
| Dual authority | no PR/CI/merge/remote cutover | any delivery activation |
| Evidence mismatch | digest-bound artifacts and review | any OID/count/hash mismatch |
| Uncontrolled source writer | writer/automation inventory plus attributable pause proof | any writer cannot be enumerated, controlled, or paused |
| Destructive rollback pressure | non-mutating invalid-baseline verdict | any cleanup/delete/recreate proposal without amended scope |
## Implementation Phases
1. **Preflight**: branch, base, active package, completed-spec guard, tool/source
identity, and quality-gate preflight.
2. **Target proof**: read-only target identity, privacy, access, emptiness, and
Actions evidence.
3. **Source/local inventory**: authoritative refs, local-only reachability, unique
commits, and retention boundary.
4. **Disposition/manifest**: exhaustive classifications, exact transfer list,
hashes, and no-mutation preview.
5. **External activation**: explicit authorization, Actions disablement, target
recheck, freeze, and refreshed inventory.
6. **Transfer**: fresh bare source, exact non-force ref creation, and default
branch.
7. **Parity/rollback**: target/source verification, fresh clone integrity,
passivity, unfreeze, and non-mutating invalid-baseline readiness.
8. **Evidence/review**: implementation report, routed gates, independent
validation/review, bounded corrections, and local commit boundary.
9. **Follow-up handoff**: stop before post-integration reconciliation and hand
that separately authorized responsibility to Spec 463 or another approved
follow-up.
## Agent Context Update Decision
`.specify/scripts/bash/update-agent-context.sh codex` is not run for this feature.
The plan introduces no new application technology, and that script would modify
`AGENTS.md`, which is explicitly outside the active Spec-462 allowlist. Existing
active technology context remains authoritative.
## Complexity Tracking
| Introduced structure | Why needed now | Narrower alternative rejected because |
|---|---|---|
| Finite ref-disposition vocabulary | each discovered ref needs a deterministic transfer/retention consequence | implicit branch-name rules cannot prove exhaustive coverage |
| Digest-bound JSON evidence | later cutover owners need reproducible migration truth | prose logs cannot prove complete/OID-exact parity |
No shared abstraction or long-lived multi-provider synchronization layer is
introduced.
## Final Plan Gate
The plan is implementation-ready with one external activation condition: no
GitHub mutation occurs until the user supplies separate current authorization for
the exact reviewed setting/ref operations. Without it, the maximum truthful
verdict is `PRE_ACTIVATION_READY`, no completion/finalization receipt is issued,
and the feature is not claimed implemented. No unresolved technical or product
question requires scope invention.

View File

@ -0,0 +1,199 @@
# Quickstart: GitHub Repository Bootstrap and Git Data Baseline v1
This quickstart defines the implementation and validation sequence. It is not an
authorization to mutate GitHub or Gitea. Stop at the external activation boundary
unless the user grants current, exact authority for the reviewed operations.
## 1. Confirm active package and repository state
```bash
git branch --show-current
git rev-parse HEAD
git status --short --branch
git remote -v
scripts/run-agent-quality-gates preflight --spec specs/462-github-repository-bootstrap-git-data-baseline-v1
```
Expected preparation identity:
```text
branch: 462-github-repository-bootstrap-git-data-baseline-v1
base/target/baseline: platform-dev
tracked scope: specs/462-github-repository-bootstrap-git-data-baseline-v1/**
origin: git@git.cloudarix.de:ahmido/TenantAtlas.git
```
Any unrelated dirty path, branch mismatch, missing package artifact, or completed-
spec change is a hard stop.
## 2. Run read-only target preflight
Use GitHub CLI metadata and API queries plus `git ls-remote` to prove:
- `nameWithOwner` equals `senadoroahmido-wq/tenantpilot`;
- visibility is private;
- viewer permission is administrative;
- heads and tags are empty;
- there is no initial commit or release;
- Actions state is known;
- there are zero open pull requests/workflow runs/non-owner collaborators/teams;
- no deploy keys, webhooks, repository workflows, Rulesets, branch protection,
Required Checks, runners, secrets, variables, or environments are configured.
Read-only examples:
```bash
gh auth status
gh repo view senadoroahmido-wq/tenantpilot --json nameWithOwner,visibility,viewerPermission,defaultBranchRef
gh api repos/senadoroahmido-wq/tenantpilot/actions/permissions
git ls-remote --heads --tags git@github.com:senadoroahmido-wq/tenantpilot.git
```
Do not capture tokens or full authenticated headers. Any unexpected target ref or
history or unreadable required passive-authority invariant requires a spec
amendment before activation. If Actions is enabled but verifiable, record
`TARGET_PREFLIGHT_READY`; do not claim US1 PASS.
## 3. Capture authoritative source inventory
Create a temporary directory outside the repository with `mktemp -d`. Query the
Gitea source with `git ls-remote --symref --heads --tags`, create a fresh bare
clone, sort refs by full name, record annotated/peeled tag OIDs, reconcile counts,
and write the canonical evidence artifact. Also capture every readable FR-030
Gitea authority/settings surface and a redacted no-mutation command/API baseline;
an unreadable required surface is `NOT_PROVEN`.
```bash
TP462_TMP_DIR="$(mktemp -d /tmp/tenantpilot-spec462.XXXXXX)"
git ls-remote --symref --heads --tags git@git.cloudarix.de:ahmido/TenantAtlas.git
git clone --bare git@git.cloudarix.de:ahmido/TenantAtlas.git "$TP462_TMP_DIR/source.git"
git --git-dir="$TP462_TMP_DIR/source.git" fsck --full
```
The actual temporary path is resolved at runtime and recorded without secrets.
The implementation must not use the current clone's `.git` directory.
## 4. Build local-only and disposition evidence
Compare exact local heads against authoritative Gitea heads. For each local-only
head, record graph reachability, unique commits, merge bases, and one disposition.
Account separately for stash/Codex/worktree/pull/reflog-only namespaces. Do not
delete, merge, rebase, or publish any local ref.
Validate these invariants with jq and Git graph queries:
- every Gitea head appears once in `branch-disposition.json`;
- every local-only head appears once in `local-only-ref-inventory.json` as
`RETAIN_LOCAL_ONLY` or `LOCAL_REDUNDANT`;
- only `dev`, `platform-dev`, and `website-dev` are `MIGRATE_ACTIVE`;
- unapproved `MIGRATE_RETAINED` count is zero;
- all unique local commits have a retention path;
- excluded namespaces never appear in the transfer manifest.
## 5. Build and review the transfer manifest
Generate `github-transfer-manifest.json` from the frozen inventory and reviewed
dispositions. It must contain exact source/target refs and OIDs, all source tags,
and no wildcard heads refspec. Compute canonical SHA-256 values with jq sorted
output and `shasum -a 256`.
Before activation, print a no-mutation summary containing:
- exact target tuple;
- exact GitHub settings mutations;
- exact selected Gitea server head/tag refs and OIDs;
- archive-only/local-only/excluded counts;
- source inventory and manifest digests;
- non-mutating rollback boundary.
## 6. Stop for external activation authority
The implementation must request separate current user authorization for exactly:
1. disabling GitHub Actions if the verified state is enabled;
2. creating the listed GitHub refs;
3. setting default branch to `dev`.
Without that authority, return `PRE_ACTIVATION_READY`, do not run any mutation
command, do not claim implementation completion, and do not issue a
completion/finalization receipt.
## 7. Execute an authorized transfer
Only after authorization:
1. disable Actions only if enabled, then requery the setting and record
`US1_PASS`;
2. reconfirm the target is still empty;
3. enumerate every Gitea write-capable human and automation path, record
attributable pause confirmations, and stop if any writer cannot be controlled;
4. bind the Gitea write-freeze start to a refreshed equal source digest;
5. add a temporary GitHub remote inside the bare source clone only;
6. create `dev`, set default branch to `dev`, then create `platform-dev`,
`website-dev`, approved retained Gitea server heads, and all tags using exact
refspecs;
7. record commands, exit codes, and results with credentials redacted.
No command may use mirror, force, force-with-lease, deletion refspecs, or wildcard
heads authorization.
## 8. Verify parity and passivity
Run source and target ref queries and compare every manifest OID. Record tree OID,
parent count, and subject for the three authority branches. Create a fresh target
bare clone outside the repository and run:
```bash
git --git-dir="$TP462_TMP_DIR/target.git" fsck --full
```
Also prove:
- no extra or excluded target refs;
- GitHub default branch is `dev`;
- visibility remains private;
- every measurable GitHub passive-authority invariant remains satisfied;
- Actions remains disabled and no workflow ran;
- Gitea refs/default branch/readable authority settings are unchanged across the
freeze and the audit log contains no Gitea mutation;
- main-clone `origin` is unchanged;
- Gitea remains active and GitHub remains passive.
Any mismatch produces FAIL and blocks use of the target as a baseline.
## 9. Run local candidate gates
```bash
scripts/run-agent-quality-gates candidate --spec specs/462-github-repository-bootstrap-git-data-baseline-v1 --base platform-dev
git diff --check
git status --short --branch
cd apps/platform && ./vendor/bin/sail artisan test --compact tests/Feature/Guards/CodexAgentFoundationContractTest.php
cd apps/platform && ./vendor/bin/sail bin pint --dirty --format agent
```
Complete independent validation and review against the exact frozen candidate.
If a confirmed in-scope finding is corrected, rerun the affected checks and a
complete independent review. Completion/receipt/local commit remain separate
current-authority steps. A completion/finalization receipt is eligible only after
`PASSIVE_BASELINE_VERIFIED`, never after `PRE_ACTIVATION_READY`.
## 10. Expected final declarations
```text
GitHub Git state: VERIFIED_PASSIVE_COPY
GitHub PR authority: NOT_ACTIVE
GitHub CI authority: NOT_ACTIVE
GitHub merge authority: NOT_ACTIVE
Gitea authority: ACTIVE
Gitea metadata migration: NOT_PERFORMED
Gitea archival activation: DEFERRED_TO_SPEC_465
```
Before external activation, the maximum truthful verdict is
`PRE_ACTIVATION_READY`. After authorized transfer and complete parity proof, the
verdict may become `PASSIVE_BASELINE_VERIFIED`; after current candidate gates,
independent validation, and review it may become `IMPLEMENTATION_REVIEWED`.
Rollback within Spec 462 never deletes refs or recreates the repository. A partial
or failed transfer yields `INVALID_PARTIAL_BASELINE`, preserves evidence, keeps
the target private with Actions disabled, and stops for separately scoped cleanup.

View File

@ -0,0 +1,168 @@
# Research: GitHub Repository Bootstrap and Git Data Baseline v1
**Date**: 2026-08-01
**Scope**: preparation decisions only; no external mutation was performed
## Decision 1: Use the user-provided candidate
- **Decision**: Prepare Spec 462 as directly supplied, narrowed to a passive
Git-data baseline.
- **Rationale**: The candidate is explicitly provided, Spec number 462 is free,
no existing package duplicates it, and it creates the bounded prerequisite for
later delivery-authority cutovers.
- **Alternatives considered**: selecting an unrelated roadmap candidate; merging
Specs 463465 into one migration. Both were rejected because the user supplied
a concrete target and an all-in-one cutover would be unsafe and unreviewable.
## Decision 2: Keep Gitea authoritative
- **Decision**: GitHub is a passive copy only; Gitea retains Git, PR, CI, merge,
and delivery authority.
- **Rationale**: Git-data transfer can be independently proven without coupling
it to workflow, protection, runner, or team-remote changes.
- **Alternatives considered**: dual authority and immediate GitHub cutover. Dual
authority creates ambiguous writes; immediate cutover expands scope across
three branch families and CI systems.
## Decision 3: Use exact selected refs, not a mirror
- **Decision**: Transfer only exact manifest refs. `git push --mirror`, wildcard
heads authorization, force, overwrite, and deletion are forbidden.
- **Rationale**: The source has hundreds of historical branches and the local
environment contains non-authority refs. Exact allowlisting prevents leakage
and target pollution.
- **Alternatives considered**: mirror push and blanket heads push. Both were
rejected because they cannot preserve the active/archive boundary.
## Decision 4: Inventory the server and local state separately
- **Decision**: Gitea server refs define authoritative source heads/tags; local
refs are analyzed independently for unique work and exclusions.
- **Rationale**: A development clone can be stale and can contain local-only,
stash, Codex, worktree, pull, and reflog state.
- **Alternatives considered**: deriving the migration from `git branch -a` in the
current clone. Rejected because it is neither complete nor clean authority.
## Decision 5: Use a fresh bare source clone
- **Decision**: Ref transfer originates from a new bare clone outside the
repository.
- **Rationale**: This prevents the current worktree's private namespaces,
worktree metadata, stash state, and permanent remotes from entering the
transfer path.
- **Alternatives considered**: the current clone, a copied `.git` directory, or a
mirror of local refs. All were rejected for provenance/leakage risk.
## Decision 6: Make dispositions exhaustive and behavior-changing
- **Decision**: Every Gitea head and local-only branch receives exactly one
finite disposition. Retained migration defaults to none and is available only
for authoritative Gitea server heads; local-only branches remain local/bundled
or are proven redundant.
- **Rationale**: Exhaustive classification turns the proposed taxonomy into a
concrete transfer/retention consequence and blocks implicit migration.
- **Alternatives considered**: branch-name heuristics, “migrate anything not
obviously historical,” or importing local-only refs into the bare source.
Rejected because absence of proof would become write authority and local import
would contradict the clean Gitea-source provenance boundary.
## Decision 7: Preserve all source tags
- **Decision**: All Gitea tags, including annotated tag objects and peeled commit
OIDs, are transferred and parity-checked.
- **Rationale**: Tags are repository history, not branch clutter, and excluding
them would create an incomplete Git-data baseline.
- **Alternatives considered**: no tags or only selected tags. Rejected unless a
future spec amendment identifies unsafe source tags.
## Decision 8: Bind transfer to a write-freeze inventory
- **Decision**: Enumerate and pause every Gitea write-capable human/automation
path, bind the freeze start to the final pre-push source digest, and compare the
same digest after transfer; any uncontrolled writer or drift invalidates
acceptance.
- **Rationale**: A manifest must describe one source state. OID parity cannot be
claimed across moving refs.
- **Alternatives considered**: accept latest-at-verification state. Rejected
because partial point-in-time truth can hide inconsistent transfers.
## Decision 9: Separate preparation, local finalization, and remote authority
- **Decision**: Preparation authorizes no remote mutation. Local commits require
the safe receipt/helper boundary. GitHub settings/ref changes require a new
exact current user authorization.
- **Rationale**: These are materially different authority classes under current
repository governance.
- **Alternatives considered**: treating implementation permission, task checkboxes,
an execution contract, or a local receipt as remote authority. Rejected.
## Decision 10: Follow current role governance
- **Decision**: Later implementation uses the current `AGENTS.md` five-role
sequence for local candidate work; the root coordinator owns remote Git reads
and may perform an expressly authorized external mutation.
- **Rationale**: Current repository instructions outrank the submitted draft's
single-owner/no-validator suggestion.
- **Alternatives considered**: preserving the draft topology unchanged. Rejected
as a conflict with current repo truth.
## Decision 11: Keep tooling spec-local and minimal
- **Decision**: Prefer documented Git/jq/digest commands. Add a helper only inside
the Spec-462 directory if deterministic generation/validation cannot otherwise
be proven, and pair it with spec-local self-tests.
- **Rationale**: No shared framework is needed for a one-time migration slice.
- **Alternatives considered**: new shared repository migration framework or
provider abstraction. Rejected under proportionality and no-premature-
abstraction rules.
## Decision 12: Omit application design artifacts
- **Decision**: Do not create `data-model.md`, API contracts, or agent technology
context updates.
- **Rationale**: The feature has no application entity, schema, HTTP contract, or
new technology. `update-agent-context` would alter `AGENTS.md` outside scope.
- **Alternatives considered**: modeling evidence JSON as application entities.
Rejected because it would imply runtime ownership that does not exist.
## Decision 13: Separate readiness from completion
- **Decision**: `PRE_ACTIVATION_READY` is a reviewable, non-mutating stopping point,
not implementation completion. Only `PASSIVE_BASELINE_VERIFIED` may proceed to
completion/receipt handling, and only after candidate validation/review may the
evidence become `IMPLEMENTATION_REVIEWED`.
- **Rationale**: A prepared manifest does not satisfy transfer, parity, integrity,
or passive-authority success criteria.
- **Alternatives considered**: treating missing remote authority as a successful
implementation with a condition. Rejected because it overstates baseline truth.
## Decision 14: Keep rollback non-destructive
- **Decision**: A partial or failed target is retained as
`INVALID_PARTIAL_BASELINE` with GitHub private and Actions disabled. Spec 462
does not delete refs or recreate the repository.
- **Rationale**: This preserves evidence and keeps forward-transfer no-delete
semantics consistent with the external mutation allowlist.
- **Alternatives considered**: exact target ref deletion or repository
recreation. Rejected because both expand destructive remote authority and can
conflict with default-branch constraints.
## Decision 15: Defer post-integration reconciliation
- **Decision**: Spec 462 stops before post-integration `platform-dev`
reconciliation. Spec 463 or another explicitly approved follow-up owns it.
- **Rationale**: The operation occurs after the reviewed local candidate is
integrated and needs fresh exact-ref authorization plus new parity evidence.
- **Alternatives considered**: claiming FR-036 complete in the pre-integration
report. Rejected because the authoritative post-integration OID does not yet
exist at that point.
## Resolved Unknowns
- Git, GitHub CLI, jq, and SHA-256 tooling are present locally.
- The main `origin` currently points to Gitea for fetch and push.
- The exact GitHub authentication, permission, visibility, emptiness, and Actions
state are deliberately revalidated during implementation, not assumed from the
draft.
- No requirement clarification remains. Retained Gitea server refs and external
activation are explicit future approval gates with fail-closed defaults.

View File

@ -0,0 +1,709 @@
# Feature Specification: GitHub Repository Bootstrap and Git Data Baseline v1
**Feature Branch**: `462-github-repository-bootstrap-git-data-baseline-v1`
**Created**: 2026-08-01
**Status**: Implemented
**Input**: User-provided Spec 462 draft for a staged Gitea-to-GitHub repository migration.
**Type**: Repository Governance / Git Hosting Bootstrap / Migration Baseline
**Branch family**: Cross-stream repository governance executed from the platform stream
**Integration base**: `platform-dev`
**Integration target**: `platform-dev`
**Diff baseline**: `platform-dev`
**Depends on**: Completed or implemented Specs 416, 439, 458, 459, 460, and 461
**Runtime posture**: Git-data and repository-governance only
**GitHub target**: private repository `senadoroahmido-wq/tenantpilot`
**GitHub intended default branch**: `dev`
## Summary
Bootstrap the already-created, private, empty GitHub repository as a verified
passive Git-data copy of the authoritative Gitea repository. The migration
copies only the three active authority branches, all source tags, and any
additional Gitea server branch that receives explicit retained-branch approval.
It proves
source/target parity without changing application runtime, local development
remotes, Gitea delivery authority, or GitHub delivery settings beyond disabling
Actions and setting the default branch.
After this slice:
```text
Gitea = active Git, pull-request, CI, merge, and delivery authority
GitHub = verified private passive Git copy
```
Specs 463465 own the later branch-specific authority cutovers. Spec 462 does
not create dual delivery authority.
## Execution Contract
- **Contract file**: `execution-contract.json`
- **Branch/base/target/diff baseline**:
`462-github-repository-bootstrap-git-data-baseline-v1` / `platform-dev` /
`platform-dev` / `platform-dev`
- **Allowed repository paths**: only
`specs/462-github-repository-bootstrap-git-data-baseline-v1/**`
- **Denied paths**: application runtime, website, workflows, agent foundations,
shared scripts, completed specs, and all other repository paths
- **Required gates**: Spec Package, Diff Scope, Diff Safety, Unicode,
Change Validation, Foundation Regression, Git Diff Check, handoff/report
validation where applicable, and independent review
- **Local receipt/finalization posture**: a local commit requires a valid
candidate-bound receipt and separate current user commit authority
- **Remote authority posture**: the contract does not authorize GitHub or Gitea
mutations; each permitted GitHub mutation requires separate current user
authorization at the activation boundary
## Completion Verdicts
- **`TARGET_PREFLIGHT_READY`**: read-only target identity, privacy, permission,
emptiness, and current Actions state are proven. If Actions is enabled, this is
not User Story 1 PASS; the exact pending disablement remains behind the external
activation gate.
- **`PRE_ACTIVATION_READY`**: target proof, source/local inventories,
dispositions, and the no-mutation manifest preview are complete, but external
activation authority is absent. This is a reviewable stopping point, not
implementation completion, and it is ineligible for completion-gate or
finalization-receipt issuance.
- **`PASSIVE_BASELINE_VERIFIED`**: the exact authorized transfer completed and all
US3/US4 parity, integrity, source-stability, and passive-authority checks pass.
- **`IMPLEMENTATION_REVIEWED`**: `PASSIVE_BASELINE_VERIFIED` evidence also passed
the current candidate gates, targeted constitutional Pest validation,
independent validation, and complete-diff review. Only this verdict may proceed
to a separately authorized local finalization receipt.
## Spec Candidate Check
- **Problem**: The repository has no bounded, verified Git-data baseline on the
pre-created GitHub target, while hundreds of historical and local-only refs
make a blanket migration unsafe.
- **Today's failure**: A direct mirror or all-in-one provider cutover could leak
non-authority refs, pollute the target with historical branches, trigger
unreviewed workflows, or create ambiguous delivery authority.
- **User-visible improvement**: Maintainers gain a trustworthy passive GitHub
baseline whose exact contents and authority posture are independently
reviewable before any CI, PR, merge, or delivery cutover.
- **Smallest enterprise-capable version**: Verify the private empty target,
inventory and classify all source/local refs, transfer only the three active
branches plus tags and explicitly approved retained Gitea server refs, prove
exact parity,
set `dev` as default, and keep Actions disabled.
- **Explicit non-goals**: GitHub Actions, Rulesets, Required Checks, PR or issue
migration, runner/secrets configuration, branch convergence, remote changes in
the main worktree, Gitea archival, application runtime, and deployment.
- **Permanent complexity imported**: A small set of tracked one-time migration
evidence artifacts and a finite branch-disposition vocabulary. No runtime
models, tables, enums, services, APIs, or UI concepts are added.
- **Why now**: The target already exists and Specs 458461 provide the local
governance/evidence foundation needed to stage provider migration safely.
- **Why not local**: Local branch lists and the current worktree are not
authoritative for Gitea server refs and can contain stash, Codex, worktree,
or other non-authority state.
- **Approval class**: Core Enterprise
- **Red flags triggered**: New classification axis and “baseline/foundation”
language. Defense: the classifications are finite, migration-local,
behavior-changing transfer decisions; the scope is explicitly reduced to a
passive copy and forbids delivery activation.
- **Score**: Nutzen: 2 | Dringlichkeit: 2 | Scope: 2 | Komplexität: 1 |
Produktnähe: 0 | Wiederverwendung: 1 | **Gesamt: 8/12**
- **Decision**: approve after scope reduction to the passive-copy slice
## Candidate Source, Roadmap, and Completed-Spec Guard
- **Candidate source**: directly provided by the user on 2026-08-01.
- **Roadmap relationship**: repository-governance foundation for the staged
GitHub migration; it enables but does not absorb Specs 463465.
- **Duplicate check**: no existing local spec, local branch, remote-tracking
branch, or Gitea head matches Spec 462 or its subject.
- **Completed-spec guard**: Specs 416, 439, 458, 459, 460, and 461 contain
implementation/completion evidence and remain read-only historical context.
- **Draft narrowing**: local-only branches are never GitHub transfer inputs in
this slice. They remain local, are preserved in a verified bundle, or are
proven redundant. Publishing local-only work would change source provenance
and requires a separate spec amendment.
- **Deferred alternatives**:
- Spec 463: platform PR, CI, agent-remote, and merge authority cutover.
- Spec 464: website PR, CI, and merge authority cutover.
- Spec 465: `dev` promotion authority, repository cutover, and Gitea archival.
## Spec Scope Fields
- **Scope**: repository-wide Git authority metadata; no workspace, tenant, or
managed-environment product scope
- **Primary Routes**: none
- **Data Ownership**: no application data; tracked artifacts describe Git refs,
transfer decisions, and parity evidence
- **RBAC**: no TenantPilot RBAC change; GitHub administrative permission and
current explicit user authorization are external activation prerequisites
- **Source authority**: `git@git.cloudarix.de:ahmido/TenantAtlas.git`
- **Target identity**: `senadoroahmido-wq/tenantpilot`, private
- **Target URLs**:
- HTTPS: `https://github.com/senadoroahmido-wq/tenantpilot.git`
- SSH: `git@github.com:senadoroahmido-wq/tenantpilot.git`
## No Legacy / No Backward Compatibility Constraint
- **Compatibility posture**: staged hard cutover with a passive-copy first step
- **Legacy aliases, fallback readers, hidden routes, duplicate UI, or historical
fixtures kept?**: no runtime compatibility paths are introduced
- **Why clean replacement is safe now**: Spec 462 changes no active authority;
later specs perform one branch-family cutover at a time
- **Permanent dual write**: forbidden
- **Permanent Gitea/GitHub provider abstraction**: forbidden
## UI Surface Impact
- [x] No UI surface impact
- [ ] Existing page changed
- [ ] New page/route added
- [ ] Navigation changed
- [ ] Filament panel/provider surface changed
- [ ] New modal/drawer/wizard/action added
- [ ] New table/form/state added
- [ ] Customer-facing surface changed
- [ ] Dangerous action changed
- [ ] Status/evidence/review presentation changed
- [ ] Workspace/environment context presentation changed
## UI/Productization Coverage
N/A - no reachable UI surface impact. All work is repository-local planning,
Git evidence, and separately authorized repository-hosting operations.
## Product Surface Impact
- **Product Surface Contract applies?**: no; no rendered product surface changes
- **Page archetype**: N/A
- **Primary user question**: N/A
- **Primary action**: N/A
- **Surface budget result**: N/A
- **Technical Annex / deep-link demotion**: N/A
- **Canonical status vocabulary**: N/A
- **Visible complexity impact**: N/A for the rendered product
- **Product Surface exceptions**: none
## Browser Verification Plan
- **Browser proof required?**: no
- **No-browser rationale**: `N/A - no rendered UI surface changed`
- **Focused path**: N/A
- **Console, Livewire, Filament, network, and 500-error checks**: N/A
- **Full-suite failure triage**: N/A; repository-governance validation is routed
independently of application/browser lanes
## Human Product Sanity Check
- **Required?**: no
- **No-human-sanity rationale**: N/A - no product surface changed
- **Planned result location**: implementation report records the no-surface
decision and neutral visible-complexity outcome
## Product Surface Merge Gate Checklist
- [x] No-legacy posture recorded.
- [x] Product Surface Impact is justified as N/A.
- [x] Browser proof is justified as N/A.
- [x] Human Product Sanity is not applicable with rationale.
- [x] Product Surface exceptions are `none`.
- [x] The future implementation report is required to state Livewire v4,
provider registration, global search, destructive/high-impact action, assets,
tests/browser, deployment, and visible-complexity posture.
## Cross-Cutting / Shared Pattern Reuse
N/A - no shared product interaction family is touched. Repository evidence uses
the current Spec 458461 quality-gate and handoff contracts rather than creating a
parallel agent-governance framework.
## OperationRun UX Impact
N/A - no `OperationRun` creation, lifecycle, notification, or link semantics are
touched.
## Provider Boundary / Platform Core Check
N/A - no application provider/platform boundary is touched. “Gitea” and
“GitHub” are repository-hosting providers within this migration spec only and do
not enter TenantPilot platform-core vocabulary or persistence.
## UI / Surface Guardrail Impact
| Surface / Change | Operator-facing change? | Native vs Custom | Shared-Family | State Layers | Exception | Note |
|---|---:|---|---|---|---|---|
| Repository bootstrap evidence | no | N/A | none | none | none | N/A - repository workflow only |
## Proportionality Review
- **New source of truth?**: yes, but only one-time Git migration evidence; Gitea
remains source authority during this spec
- **New persisted entity/table/artifact?**: tracked JSON/Markdown evidence only;
no application persistence
- **New abstraction?**: no shared abstraction; any implementation helper must be
spec-local, default read-only, and justified by deterministic evidence needs
- **New enum/state/reason family?**: a finite migration disposition vocabulary
controls whether each ref may be transferred
- **New cross-domain UI framework/taxonomy?**: no
- **Current operator problem**: maintainers cannot safely decide what reaches
GitHub or prove that the passive copy matches authoritative refs.
- **Existing structure is insufficient because**: local branches and the current
clone do not represent complete authoritative server state and contain private
namespaces that must never be pushed.
- **Narrowest correct implementation**: exact source inventory, exhaustive
dispositions, exact transfer allowlist, fresh bare export, and parity report.
- **Ownership cost**: migration evidence schemas, review of every source/local
branch, and later archival of the evidence with the staged migration.
- **Alternative intentionally rejected**: mirror push, blanket heads push, and a
permanent multi-host synchronization layer; each creates excessive authority
or leakage risk.
- **Release truth**: current migration need, not future platform preparation.
## Testing / Lane / Runtime Impact
- **Test purpose / classification**: Heavy-Governance evidence validation; no
application Unit, Feature, or Browser behavior
- **Validation lanes**: Spec Package, Diff Scope, Diff Safety, Unicode, Change
Validation, Foundation Regression, Git integrity/parity checks, and independent
review
- **Why sufficient**: these checks prove repository scope, artifact validity,
source/target ref truth, and authority safety without booting application state
- **New or expanded test families**: none unless a spec-local deterministic helper
is required; any such helper must include spec-local self-tests
- **Fixture/helper cost**: temporary bare Git repositories only; no database,
workspace, membership, provider, session, factory, seed, or browser context
- **Heavy-family visibility**: explicit repository-governance classification
- **Special surface profile**: N/A
- **Budget/baseline/trend impact**: none for application lanes
- **Escalation**: `document-in-feature`; any structural shared tooling proposal
requires a separate spec
- **Planned validation commands**: documented in `quickstart.md`
## Primary Users
- Repository owner authorizing the migration.
- Maintainer preparing and reviewing source/ref evidence.
- Independent validator/reviewer proving scope and parity.
- Future delivery owners of Specs 463465 consuming the passive baseline.
## User Scenarios & Testing
### User Story 1 - Prove the target is safe to bootstrap (Priority: P1)
As the repository owner, I can see deterministic evidence that the exact GitHub
target is private, empty, administratively manageable, and either already unable
to run GitHub Actions or explicitly waiting at the authorized Actions-disablement
gate before any Git ref is transferred.
**Independent test**: Read-only GitHub metadata and ref queries establish the
target tuple, visibility, permission, zero heads/tags/releases, and exact Actions
state. An enabled-but-verifiable Actions state yields `TARGET_PREFLIGHT_READY`,
not US1 PASS; any unexpected ref or unverifiable state blocks activation.
**Acceptance scenarios**:
1. Given the intended target, when preflight runs, then owner/name, private
visibility, administrative access, and empty refs are proven.
2. Given any pre-existing target ref or initial commit, when preflight runs, then
the transfer stops before GitHub mutation.
3. Given Actions is enabled, when read-only preflight completes, then the result is
`TARGET_PREFLIGHT_READY` and no ref transfer is allowed until the separately
authorized disablement succeeds and is verified.
### User Story 2 - Account for every source and local ref (Priority: P1)
As the migration maintainer, I can account for every authoritative Gitea head and
tag plus every local-only branch/commit without silently losing work or exposing
private refs.
**Independent test**: Canonical inventories reconcile counts and unique names;
every discovered head appears exactly once in the appropriate disposition set;
every local-only unique commit has a retention decision.
**Acceptance scenarios**:
1. Given Gitea server refs, when inventory is captured, then every head, tag,
peeled tag object, default branch, and inventory hash is recorded.
2. Given local-only branches or commits, when classification runs, then each is
retained locally/bundled or proven redundant without being published.
3. Given stash, Codex, worktree-private, pull, or reflog-only state, when
classification runs, then it is excluded from transfer.
### User Story 3 - Transfer only explicitly allowed Git data (Priority: P1)
As the repository owner, after separate current authorization, I can bootstrap
GitHub from a fresh bare Gitea clone without force, deletion, mirror push, branch
convergence, or changes to the main development clone.
**Independent test**: The transfer log contains only exact manifest refspecs;
`dev`, `platform-dev`, `website-dev`, approved retained Gitea server refs, and all
source tags are the only created GitHub refs.
**Acceptance scenarios**:
1. Given a reviewed manifest and an empty target, when activation is authorized,
then each selected ref is created without force from a fresh bare clone.
2. Given a branch without `MIGRATE_ACTIVE` or approved `MIGRATE_RETAINED`, when
the transfer plan is generated, then the branch is absent.
3. Given source drift during the freeze window, when pre/post inventories differ,
then the manifest is invalidated and transfer acceptance stops.
### User Story 4 - Prove parity and passive authority (Priority: P1)
As a future cutover owner, I can rely on evidence that every migrated ref has
exact OID/tree parity, the target contains no extras, `dev` is default, Actions
remain disabled, and Gitea remains the sole active authority.
**Independent test**: Source/target ref comparison, fresh target bare-clone
integrity, target settings queries, unchanged source refs, and unchanged main
`origin` all pass.
**Acceptance scenarios**:
1. Given a completed transfer, when parity is verified, then every selected head
and tag is `OID_MATCH` and authority branch trees match exactly.
2. Given any extra or excluded GitHub ref, when parity is verified, then the
baseline verdict is FAIL.
3. Given exact parity, when the authority report is produced, then it declares
GitHub passive and Gitea active with no GitHub PR/CI/merge authority.
## Edge Cases
- The GitHub repository gains a branch, tag, release, or initial commit between
preflight and activation.
- A Gitea ref changes between freeze inventory, push, and post-push verification.
- The authenticated GitHub identity can read but not administer the target.
- Source annotated tags introduce peeled-object entries.
- A local-only branch tip is already reachable from an differently named Gitea
branch.
- A unique local commit is reachable only through stash-related state.
- A branch name contains characters that require exact NUL-safe handling.
- A retained branch is proposed without an owner, purpose, or explicit approval.
- GitHub remote HEAD cannot resolve until `dev` exists.
- A fresh target clone reports dangling objects but no corruption; the report
distinguishes dangling from missing/corrupt objects.
- The Spec-462 integration later changes `platform-dev`; Spec 463 or another
explicitly approved follow-up must reconcile the passive target before any
delivery-authority cutover.
## Branch and Authority Contract
### Authority branches
Exactly these branches use `MIGRATE_ACTIVE`:
```text
dev
platform-dev
website-dev
```
### Server-head dispositions
Each Gitea server head receives exactly one:
- `MIGRATE_ACTIVE`
- `MIGRATE_RETAINED`
- `ARCHIVE_ONLY`
### Local-only dispositions
Each local-only branch receives exactly one:
- `RETAIN_LOCAL_ONLY`
- `LOCAL_REDUNDANT`
Non-authority namespaces use `EXCLUDED_NON_AUTHORITY_REF`.
`MIGRATE_RETAINED` applies only to an authoritative Gitea server head and defaults
to none. Each retained exception requires the exact ref, OID, owner/future
purpose, reason, and explicit current user approval. Local-only refs cannot use
this disposition in Spec 462.
### No branch convergence
This spec must not merge, rebase, or otherwise reconcile any combination of
`dev`, `platform-dev`, and `website-dev`. Their divergence is preserved exactly.
### Passive GitHub authority invariants
“GitHub is passive” is an organizational and configuration contract, not a claim
that a repository administrator lacks GitHub's intrinsic write capability. The
accepted target MUST have Actions disabled, zero open pull requests and workflow
runs, zero non-owner collaborators or teams, and no configured deploy keys,
webhooks, repository workflows, Rulesets, branch protection or Required Checks,
runners, secrets, variables, or environments. The final evidence MUST also state
that GitHub is not authorized for pull requests, CI, merge, promotion, deployment,
or agent delivery. Every readable invariant is captured before activation and
reverified afterward; an unreadable or unverifiable invariant blocks the passive
authority claim.
### Source write freeze
The final inventory and transfer manifest describe one stable source state.
During the bounded transfer window there is no source push, merge, ref deletion,
tag mutation, force push, or repository migration. A logical freeze is acceptable
only when evidence identifies every human, team, deploy key, bot, workflow, and
other automation path able to write Gitea; records attributable pause
confirmation for each active writer; binds the freeze start timestamp to the
accepted source digest; and proves the same digest at freeze end. If any writer or
automation path cannot be enumerated, controlled, or paused, Spec 462 stops before
GitHub mutation. An enforceable Gitea-side freeze would be a Gitea setting mutation
outside this spec and therefore requires a scope amendment rather than an implicit
fallback.
## Required Evidence Artifacts
All paths are under
`specs/462-github-repository-bootstrap-git-data-baseline-v1/`:
- `git-source-ref-inventory.json`
- `local-only-ref-inventory.json`
- `branch-disposition.json`
- `github-transfer-manifest.json`
- `github-parity-report.json`
- `external-activation-checklist.md`
- `implementation-report.md`
The source inventory records repository identity, source default branch, source
HEAD, every head/tag OID, peeled tag OIDs, counts, timestamp, and a canonical
SHA-256. The disposition artifacts provide exhaustive one-to-one coverage. The
transfer manifest lists exact source/target refs and OIDs; wildcard refspecs are
not authorization. The parity report records source/target OIDs, authority-branch
tree OIDs, target extras, source stability, target integrity, visibility, default
branch, Actions state, and the final authority declaration.
## Functional Requirements
- **FR-001**: The target identity MUST be exactly
`senadoroahmido-wq/tenantpilot`.
- **FR-002**: The target MUST be private and administratively manageable by the
authenticated identity.
- **FR-003**: The target MUST have zero heads and tags and no initial commit before
transfer.
- **FR-004**: GitHub Actions MUST be disabled before transfer and remain disabled.
- **FR-005**: Preparing artifacts MUST NOT authorize any external mutation.
- **FR-006**: Every GitHub setting or ref mutation MUST require separate current
user authorization for the exact operation set.
- **FR-007**: Source inventory MUST derive from Gitea server refs and a fresh bare
Gitea clone, not only the current development clone.
- **FR-008**: The inventory MUST include every head, tag, peeled tag OID, source
HEAD/default branch, counts, timestamp, and canonical hash.
- **FR-009**: Every Gitea head MUST receive exactly one server-head disposition.
- **FR-010**: Every local-only branch MUST receive exactly one local-only
disposition.
- **FR-011**: Every local-only unique commit MUST be retained locally, preserved
in a verified external bundle, or proven redundant; it MUST NOT be published by
Spec 462.
- **FR-012**: No Gitea or local branch, tag, commit, stash, worktree ref, or other
source/local evidence may be deleted by Spec 462.
- **FR-013**: `dev`, `platform-dev`, and `website-dev` MUST be the only
`MIGRATE_ACTIVE` refs.
- **FR-014**: Additional Gitea server heads MUST default to `ARCHIVE_ONLY` unless
an exact `MIGRATE_RETAINED` exception is approved; local-only heads are not
eligible for migration in this slice.
- **FR-015**: Stash, Codex, turn-diff, worktree-private, pull, reflog-only, and
temporary refs MUST be excluded.
- **FR-016**: All source tags MUST be included in the transfer manifest.
- **FR-017**: The transfer manifest MUST list exact refspecs and OIDs; wildcard
head authorization is forbidden.
- **FR-018**: Ref transfer MUST originate from a new temporary bare clone of the
Gitea server.
- **FR-019**: The current worktree, linked worktrees, copied Git metadata,
snapshots, stashes, and partial clones MUST NOT be transfer sources.
- **FR-020**: Mirror pushes, forced updates, overwrites, target ref deletions, and
target repository deletion or recreation are forbidden in both forward transfer
and Spec-462 rollback handling.
- **FR-021**: The main development clone's `origin` and permanent remote set MUST
remain unchanged.
- **FR-022**: The source write freeze MUST bind the final inventory, manifest,
transfer, and post-transfer source verification to one stable ref state.
- **FR-023**: Any source or target drift MUST invalidate acceptance and require a
refreshed review before further mutation.
- **FR-024**: Every migrated head and tag MUST preserve its exact OID.
- **FR-025**: `dev`, `platform-dev`, and `website-dev` MUST preserve exact commit
tree OIDs and parent counts.
- **FR-026**: A fresh GitHub bare clone MUST pass full Git integrity verification
without missing or corrupt objects.
- **FR-027**: GitHub MUST contain no head or tag absent from the reviewed transfer
manifest.
- **FR-028**: GitHub's default branch MUST be `dev`; no `main` branch is created.
- **FR-029**: GitHub MUST satisfy every measurable passive-authority invariant:
Actions disabled; zero open pull requests and workflow runs; zero non-owner
collaborators/teams; no configured deploy keys, webhooks, workflows, Rulesets,
branch protection, Required Checks, runners, secrets, variables, or
environments; and an explicit no-PR/CI/merge/promotion/deployment/agent-delivery
authority declaration.
- **FR-030**: Spec-462 evidence MUST prove that it issued no Gitea mutation
command or mutating API request and that before/after Gitea refs, default branch,
read-accessible repository settings, branch protections, hooks, deploy keys,
collaborators/teams, workflows, and delivery-authority declaration are
unchanged. Any named surface that cannot be read MUST be `NOT_PROVEN` and block
the unchanged-authority claim.
- **FR-031**: Gitea PR/issue/release/package metadata MUST NOT be migrated.
- **FR-032**: Rollback handling MUST be non-destructive: stop further transfer,
keep GitHub private and Actions disabled, preserve evidence, mark the target
`INVALID_PARTIAL_BASELINE`, and leave Gitea and local remotes unchanged.
- **FR-033**: Cleanup mutation after a partial target transfer, including ref or
repository deletion/recreation, is outside Spec 462 and MUST require both a
scope amendment or separate spec and separate current user authorization.
- **FR-034**: Final evidence MUST declare GitHub a verified passive Git copy and
Gitea active authority.
- **FR-035**: The complete candidate and activation evidence MUST receive
independent validation and review under current repository governance.
- **FR-036**: Spec 462 MUST stop before post-integration reconciliation. Spec 463
or another explicitly approved follow-up owns any later `platform-dev` update
and MUST repeat exact-ref authorization and full parity/passivity verification.
## Non-Functional Requirements
- **NFR-001 Determinism**: Canonical JSON serialization and SHA-256 calculations
MUST be reproducible from the same source state.
- **NFR-002 Completeness**: Disposition coverage MUST be 100%; one missing or
duplicate ref blocks transfer.
- **NFR-003 Safety**: Commands MUST fail closed on wrong target, non-empty target,
source drift, target drift, missing authorization, or manifest mismatch.
- **NFR-004 Redaction**: Evidence MUST contain no credentials, tokens, secret
values, private key material, or raw authenticated headers.
- **NFR-005 Auditability**: Exact commands, exit codes, timestamps, refspecs,
counts, hashes, and mutation results MUST be recorded.
- **NFR-006 Isolation**: Temporary bare clones and bundles MUST live outside the
repository and MUST NOT alter the development worktree's remotes or refs.
- **NFR-007 Portability**: Tracked evidence and documented validation use current
repository Git/JSON/SHA tooling without adding a package dependency.
## Acceptance Criteria
- **AC-001**: Target owner/name, private visibility, administrative permission,
and zero pre-transfer heads/tags are proven.
- **AC-002**: No initial README, License, `.gitignore`, `main`, release, workflow
run, issue, or pull request exists before bootstrap.
- **AC-003**: Actions are disabled before and after the transfer and no workflow
execution is triggered.
- **AC-004**: Source head/tag counts match fresh server queries and every source
head has exactly one disposition.
- **AC-005**: Every local-only branch and unique commit has exactly one retention
outcome; no deletion task exists.
- **AC-006**: The manifest contains all three authority branches, all source tags,
and only explicitly approved retained Gitea server heads.
- **AC-007**: Transfer evidence proves a fresh bare source clone, exact refspecs,
zero wildcard authorization, zero mirror/force/delete behavior, and no main
remote change.
- **AC-008**: Every migrated ref reports `OID_MATCH`; all authority trees match.
- **AC-009**: GitHub contains no extra, archive-only, local-only, stash, Codex,
worktree-private, pull, or temporary ref.
- **AC-010**: Fresh GitHub bare-clone integrity passes without missing or corrupt
objects.
- **AC-011**: GitHub default branch is `dev`, visibility is private, and Actions
remain disabled.
- **AC-012**: Gitea before/after source inventories match and the development
clone's `origin` remains Gitea.
- **AC-013**: Every FR-029 passive-authority invariant is proven before and after
activation, every readable FR-030 Gitea surface is unchanged, and no Gitea
metadata migration is activated.
- **AC-014**: The implementation report records exact remote mutations and the
authority declarations required by FR-034.
- **AC-015**: Current local quality gates, the targeted constitutional Pest test,
Sail Pint, source/target parity checks, and one independent review complete with
no confirmed in-scope finding.
## Success Criteria
- **SC-001**: 100% of Gitea heads, tags, local-only branches, and locally unique
commits are represented exactly once in the appropriate evidence inventory.
- **SC-002**: 100% of manifest refs have identical source and target OIDs.
- **SC-003**: The three authority branches have identical source and target tree
OIDs and parent counts.
- **SC-004**: The target has zero unlisted heads/tags and zero excluded refs.
- **SC-005**: No Gitea ref/setting, local development remote, application file, or
workflow changes during the accepted baseline operation; GitHub changes are
exactly the allowlisted Actions disablement, manifest ref creation, and default
branch assignment.
- **SC-006**: A maintainer can determine from the tracked report, without relying
on memory, exactly what moved, what stayed archive-only/local-only, what was
excluded, and which host retains authority.
## External Mutation Boundary
After separate explicit authorization, Spec 462 may mutate only:
- GitHub Actions enabled state, to disabled;
- GitHub default branch, to `dev` after that branch exists;
- exact head and tag refs listed in the reviewed transfer manifest.
It must not mutate repository owner/name/visibility, Rulesets, branch protection,
collaborators, teams, deploy keys, webhooks, secrets, variables, environments,
runners, workflows, issues, pull requests, releases, packages, or any Gitea state.
Rollback inside Spec 462 is non-mutating. Target cleanup, ref deletion, or
repository deletion/recreation requires a scope amendment or separate spec plus
separate current authorization.
## Implementation Governance Deviation from the Submitted Draft
The submitted draft requested a single-owner implementation and excluded the
repository's validator role. Current `AGENTS.md` is authoritative and requires the
Spec-458 five-role governance for repository-governance implementation:
```text
code_explorer -> implementer -> test_validator -> code_reviewer -> git_finalizer
```
This preparation run does not spawn those roles because it does not implement the
spec. A later implementation must use them for local candidate work, validation,
review, and separately authorized local finalization. The root coordinator owns
all remote Git network operations, including source queries and temporary
cloning. It may cross the separately authorized external GitHub mutation boundary
only after current user authority; no role handoff or execution contract implies
remote authority.
## Risks and Mitigations
| Risk | Impact | Mitigation |
|---|---|---|
| Target is no longer empty | History collision | Hard stop and spec amendment before any push |
| Wrong GitHub target or permission | Unauthorized write | Exact tuple, private visibility, admin proof |
| Current clone used as source | Private refs leak | Fresh bare Gitea clone only |
| Blanket or mirror push | Historical/non-authority pollution | Exact manifest allowlist; mirror/force forbidden |
| Source changes during transfer | Inconsistent baseline | Freeze plus before/after inventory hashes |
| Local-only commits omitted | Work loss | Exhaustive inventory and verified local retention/bundle |
| Actions trigger on import | Unreviewed CI/cost | Disable and reverify before/after |
| GitHub mistaken as active authority | Dual delivery | Explicit passive declaration; no local remote/PR/CI cutover |
| Partial transfer tempts destructive cleanup | Evidence loss or widened authority | Stop, keep target private/Actions-disabled, preserve evidence, mark `INVALID_PARTIAL_BASELINE`; cleanup is out of scope |
| Post-merge `platform-dev` drift | Passive copy becomes stale | Spec 463 or an explicitly approved follow-up reconciles before any authority cutover |
## Assumptions
- The target repository has been created manually, is private, and is intended to
remain empty until separately authorized activation.
- Gitea remains reachable and authoritative throughout Spec 462.
- The authenticated GitHub identity can prove administrative permission during
implementation.
- `MIGRATE_RETAINED` is empty unless the user explicitly approves exact Gitea
server refs; local-only refs cannot be published in this slice.
- The authorizing user can enumerate and pause every Gitea write-capable actor and
automation path; otherwise Spec 462 stops before activation and any enforceable
source-side freeze requires a scope amendment.
- Git data may contain existing repository history but evidence will not record
credentials or authenticated headers.
## Open Questions
No question blocks implementation preparation. Retained-branch selection and
external mutation authority are intentionally deferred decisions with fail-closed
defaults, not unresolved requirements.
## Follow-up Specs
- **Spec 463 — GitHub Platform Delivery and Agent Authority Cutover v1**:
first reconcile the integrated Gitea `platform-dev` OID with the passive target
under exact current authorization and repeated parity/passivity proof, then own
platform workflows, artifacts, agent remote, Ruleset, Required Checks, probe
pull request, and `platform-dev` authority.
- **Spec 464 — GitHub Website Delivery Cutover v1**: website workflows, Ruleset,
probe pull request, and `website-dev` authority.
- **Spec 465 — GitHub Dev Promotion Gate and Gitea Archival v1**: `dev` Ruleset,
promotion, team remote cutover, final authority, and Gitea read-only archival.
## Final Preparation Verdict
The candidate is approved as the smallest passive-copy migration slice. No
application implementation or remote repository mutation is authorized by this
specification alone.

View File

@ -0,0 +1,248 @@
# Tasks: GitHub Repository Bootstrap and Git Data Baseline v1
**Input**: `spec.md`, `plan.md`, `research.md`, `quickstart.md`,
`checklists/requirements.md`, and `execution-contract.json`
**Branch**: `462-github-repository-bootstrap-git-data-baseline-v1`
**Base / target / diff baseline**: `platform-dev`
**Scope**: only
`specs/462-github-repository-bootstrap-git-data-baseline-v1/**`
**Tests**: Heavy-Governance Git evidence, the targeted existing Pest foundation
guard, constitution-required Sail Pint, and current local quality gates; no new
application test and no browser, PostgreSQL, provider, queue, or website lane
Every implementation task is unchecked until its evidence exists. Preparation,
local finalization, external GitHub activation, non-mutating rollback handling,
and post-integration follow-up are separate authority boundaries.
## Task Format
`- [ ] TNNN [P?] [US?] Action with exact artifact path`
`[P]` is allowed only when the task is read-only or file-disjoint and every prior
phase gate has passed. External mutations never run in parallel.
## Phase 1: Setup and Hard-Gate Preflight
**Purpose**: Bind the active package, branch, baseline, role workflow, and scope
before implementation writes.
- [x] T001 Run `scripts/run-agent-quality-gates preflight --spec specs/462-github-repository-bootstrap-git-data-baseline-v1` and record the result in `specs/462-github-repository-bootstrap-git-data-baseline-v1/implementation-report.md`.
- [x] T002 Record current branch, HEAD, `platform-dev` merge base, status, upstream, and main-clone remotes in `specs/462-github-repository-bootstrap-git-data-baseline-v1/implementation-report.md`.
- [x] T003 Prove the working tree contains no unrelated path and the active allowlist is limited to `specs/462-github-repository-bootstrap-git-data-baseline-v1/**`; record the proof in `specs/462-github-repository-bootstrap-git-data-baseline-v1/implementation-report.md`.
- [x] T004 Verify completed/implemented Specs 416, 439, 458, 459, 460, and 461 remain byte-unchanged from `platform-dev` and record their read-only guard result in `specs/462-github-repository-bootstrap-git-data-baseline-v1/implementation-report.md`.
- [x] T005 Record installed Git, GitHub CLI, jq, SHA-256 tooling, source URL, target tuple, and NFR-007 portability evidence without secrets in `specs/462-github-repository-bootstrap-git-data-baseline-v1/implementation-report.md`.
- [x] T006 Obtain the current `code_explorer` handoff for local repository-governance scope and record its sanitized gate summary in `specs/462-github-repository-bootstrap-git-data-baseline-v1/implementation-report.md`.
- [x] T007 Confirm no hard-gate stop condition is active, hand the bounded allowlist/evidence brief to the `implementer`, and record Phase-1 PASS in `specs/462-github-repository-bootstrap-git-data-baseline-v1/implementation-report.md`.
**Checkpoint**: No inventory, manifest, helper, external setting, or ref write may
start until T001T007 pass.
---
## Phase 2: Foundational Evidence Contract
**Purpose**: Define deterministic tracked evidence and activation boundaries
before any remote mutation.
- [x] T008 Create the canonical source-inventory shape and generation notes in `specs/462-github-repository-bootstrap-git-data-baseline-v1/git-source-ref-inventory.json`.
- [x] T009 Create the local-only reachability/disposition shape in `specs/462-github-repository-bootstrap-git-data-baseline-v1/local-only-ref-inventory.json`.
- [x] T010 Create exhaustive server/local/excluded disposition sections in `specs/462-github-repository-bootstrap-git-data-baseline-v1/branch-disposition.json`.
- [x] T011 Create exact target/ref/digest manifest sections in `specs/462-github-repository-bootstrap-git-data-baseline-v1/github-transfer-manifest.json`.
- [x] T012 Create source/target parity, integrity, setting, origin, and authority sections in `specs/462-github-repository-bootstrap-git-data-baseline-v1/github-parity-report.json`.
- [x] T013 Create the exact no-authority/read-only/authorized-mutation/rollback checklist in `specs/462-github-repository-bootstrap-git-data-baseline-v1/external-activation-checklist.md`.
- [x] T014 Validate JSON parseability, deterministic key/ref ordering, digest rules, cross-artifact identifiers, and NFR-001/NFR-002 completeness for `specs/462-github-repository-bootstrap-git-data-baseline-v1/*.json`; record Phase-2 PASS in `specs/462-github-repository-bootstrap-git-data-baseline-v1/implementation-report.md`.
**Checkpoint**: Evidence shapes and authorization semantics are stable before
target/source inventory work.
---
## Phase 3: User Story 1 — Prove the Target Is Safe (P1)
**Goal**: Prove the exact private GitHub target is manageable and empty and that
Actions is disabled before transfer.
**Independent test**: Read-only GitHub metadata/ref queries establish identity,
visibility, permission, emptiness, release/history state, and Actions state; any
unexpected state stops the workflow.
### Validation tasks
- [x] T015 [US1] Have the root coordinator query and record exact target owner/name, visibility, and administrative permission in `specs/462-github-repository-bootstrap-git-data-baseline-v1/external-activation-checklist.md`.
- [x] T016 [US1] Have the root coordinator query and record target heads, tags, remote HEAD, and initial-history state in `specs/462-github-repository-bootstrap-git-data-baseline-v1/external-activation-checklist.md`.
- [x] T017 [US1] Have the root coordinator query and record releases, issues, open pull requests, workflow runs, non-owner collaborators/teams, deploy keys, webhooks, repository workflows, Rulesets, branch protection/Required Checks, runners, secret names, variable names, and environments in `specs/462-github-repository-bootstrap-git-data-baseline-v1/external-activation-checklist.md` without reading secret values.
- [x] T018 [US1] Have the root coordinator query and record current GitHub Actions permission state in `specs/462-github-repository-bootstrap-git-data-baseline-v1/external-activation-checklist.md`.
### Story completion tasks
- [x] T019 [US1] Reconcile T015T018 against FR-001FR-003, FR-005FR-006, AC-001AC-002, and the measurable FR-029 preflight invariants; record whether FR-004 is already satisfied or pending authorized disablement in `specs/462-github-repository-bootstrap-git-data-baseline-v1/implementation-report.md`.
- [x] T020 [US1] Record the hard-stop verdict for any wrong identity, non-private visibility, missing admin permission, pre-existing ref/history, unexpected passive-authority configuration other than a verifiable enabled Actions state, or unreadable/unverifiable required invariant in `specs/462-github-repository-bootstrap-git-data-baseline-v1/external-activation-checklist.md`.
- [x] T021 [US1] Record `US1_PASS` only when Actions is already disabled; otherwise record `TARGET_PREFLIGHT_READY` with the exact pending Actions-disablement and no ref-transfer authority in `specs/462-github-repository-bootstrap-git-data-baseline-v1/implementation-report.md`.
---
## Phase 4: User Story 2 — Account for Every Source and Local Ref (P1)
**Goal**: Produce exhaustive authoritative and local-only inventories with no
unaccounted work or transferable private namespace.
**Independent test**: Server/local counts reconcile, names are unique, every head
has exactly one disposition, and every local-only unique commit has a retention
outcome.
### Validation-first inventory tasks
- [x] T022 [US2] Have the root coordinator query Gitea HEAD/default branch, all server heads/tags with exact OIDs, and every readable repository setting, branch protection, hook, deploy key, collaborator/team, workflow, and delivery-authority surface required by FR-030; record redacted raw-command/API hashes and `NOT_PROVEN` for any unreadable required surface in `specs/462-github-repository-bootstrap-git-data-baseline-v1/implementation-report.md`.
- [x] T023 [US2] Have the root coordinator create a fresh bare Gitea clone outside the repository, reconcile or fetch exact missing server tags into that temporary clone, run Git integrity validation, and record NFR-006 isolated redacted provenance in `specs/462-github-repository-bootstrap-git-data-baseline-v1/implementation-report.md`.
- [x] T024 [US2] Canonicalize source heads, tags, peeled tag OIDs, counts, timestamp, default branch, source HEAD, and digest in `specs/462-github-repository-bootstrap-git-data-baseline-v1/git-source-ref-inventory.json`.
- [x] T025 [US2] Reconcile `git ls-remote` and fresh-bare-clone refs with zero missing/duplicate entries in `specs/462-github-repository-bootstrap-git-data-baseline-v1/git-source-ref-inventory.json`.
- [x] T026 [US2] Enumerate local heads and exact OIDs without modifying refs and record the canonical set in `specs/462-github-repository-bootstrap-git-data-baseline-v1/local-only-ref-inventory.json`.
- [x] T027 [US2] Enumerate stash, Codex, turn-diff, worktree-private, pull, reflog-only, and temporary namespaces as excluded identities/counts in `specs/462-github-repository-bootstrap-git-data-baseline-v1/local-only-ref-inventory.json`.
- [x] T028 [US2] Compute each local-only head's authority reachability, unique commit count, and merge bases to `dev`, `platform-dev`, and `website-dev` in `specs/462-github-repository-bootstrap-git-data-baseline-v1/local-only-ref-inventory.json`.
- [x] T029 [US2] Account for every commit reachable only through local heads or excluded namespaces in `specs/462-github-repository-bootstrap-git-data-baseline-v1/local-only-ref-inventory.json`.
### Disposition tasks
- [x] T030 [US2] Assign `MIGRATE_ACTIVE` only to `dev`, `platform-dev`, and `website-dev` in `specs/462-github-repository-bootstrap-git-data-baseline-v1/branch-disposition.json`.
- [x] T031 [US2] Assign every other Gitea head to `ARCHIVE_ONLY` unless an exact current approved `MIGRATE_RETAINED` exception exists in `specs/462-github-repository-bootstrap-git-data-baseline-v1/branch-disposition.json`.
- [x] T032 [US2] Assign every local-only head to `RETAIN_LOCAL_ONLY` or `LOCAL_REDUNDANT` with reason and unique-commit evidence, and prove no local-only head is eligible for transfer in `specs/462-github-repository-bootstrap-git-data-baseline-v1/branch-disposition.json`.
- [x] T033 [US2] Define and, where required, verify the external bundle retention path/digest for non-migrated unique commits in `specs/462-github-repository-bootstrap-git-data-baseline-v1/local-only-ref-inventory.json` without deleting local refs.
- [x] T034 [US2] Prove 100% one-to-one inventory/disposition coverage and reconciled summary counts in `specs/462-github-repository-bootstrap-git-data-baseline-v1/branch-disposition.json`.
- [x] T035 [US2] Record US2 PASS for FR-007FR-015, AC-004AC-005, and SC-001 in `specs/462-github-repository-bootstrap-git-data-baseline-v1/implementation-report.md`.
---
## Phase 5: User Story 3 — Transfer Only Explicitly Allowed Git Data (P1)
**Goal**: Build an exact manifest and, only after current authorization, create
selected GitHub refs from a fresh bare Gitea clone.
**Independent test**: Planned and executed refspecs equal the manifest exactly;
no mirror, force, delete, wildcard head, main-remote change, or branch convergence
occurs.
### Manifest and dry-run tasks
- [x] T036 [US3] Bind target tuple, source inventory digest, disposition digest, all three authority heads, approved retained Gitea server heads, and all source tags in `specs/462-github-repository-bootstrap-git-data-baseline-v1/github-transfer-manifest.json`.
- [x] T037 [US3] Record excluded namespaces and prove no `ARCHIVE_ONLY`, non-migrated local-only, stash, Codex, worktree-private, pull, or temporary ref is present in `specs/462-github-repository-bootstrap-git-data-baseline-v1/github-transfer-manifest.json`.
- [x] T038 [US3] Validate exact source/target ref names and OIDs, zero wildcard head authorization, zero force/delete/mirror semantics, and the canonical manifest digest in `specs/462-github-repository-bootstrap-git-data-baseline-v1/github-transfer-manifest.json`.
- [x] T039 [US3] Generate and record a no-mutation refspec preview plus exact planned setting mutations in `specs/462-github-repository-bootstrap-git-data-baseline-v1/external-activation-checklist.md`.
- [x] T040 [US3] Present the exact reviewed mutation set and retained-server-ref decisions for separate current user authorization; record only attributable non-secret NFR-003/NFR-004 authority status in `specs/462-github-repository-bootstrap-git-data-baseline-v1/external-activation-checklist.md`.
### Authorized activation tasks
- [x] T041 [US3] If T040 lacks exact current authorization, record `PRE_ACTIVATION_READY` in `specs/462-github-repository-bootstrap-git-data-baseline-v1/implementation-report.md`, stop all external mutation tasks, and record that implementation completion plus completion/finalization receipt issuance remain forbidden.
Historical `PRE_ACTIVATION_READY` lock: T042-T058 were held until separate
current external activation authority and Gitea writer-control proof were
provided. The owner-controlled freeze, transfer, and parity evidence recorded on
2026-08-02 satisfied that lock; T042-T058 are therefore complete.
- [x] T042 [US3] If exactly authorized and Actions is enabled, have the root coordinator disable it; if already disabled, perform no setting mutation. In either case reverify the disabled state, promote the target verdict to `US1_PASS`, and record the response without credentials in `specs/462-github-repository-bootstrap-git-data-baseline-v1/external-activation-checklist.md`.
- [x] T043 [US3] Have the root coordinator reprove target emptiness; enumerate every Gitea write-capable human, team, deploy key, bot, workflow, and automation path; record attributable pause confirmation for each active writer; bind the freeze start timestamp to a refreshed equal source digest; and stop if any writer cannot be enumerated, controlled, or paused in `specs/462-github-repository-bootstrap-git-data-baseline-v1/external-activation-checklist.md`.
- [x] T044 [US3] Invalidate the manifest and stop if T043 finds drift; otherwise record the accepted frozen inventory/manifest identities in `specs/462-github-repository-bootstrap-git-data-baseline-v1/github-transfer-manifest.json`.
- [x] T045 [US3] Have the root coordinator create GitHub `dev` from the temporary bare source only, set default branch to `dev`, then create `platform-dev`, `website-dev`, approved retained Gitea server heads, and tags using exact manifest refspecs; record redacted results in `specs/462-github-repository-bootstrap-git-data-baseline-v1/implementation-report.md`.
- [x] T046 [US3] Prove transfer output contains zero forced update, overwrite, deletion, mirror, wildcard, or unlisted refspec and record NFR-003/NFR-005 command/exit evidence in `specs/462-github-repository-bootstrap-git-data-baseline-v1/implementation-report.md`.
- [x] T047 [US3] Prove the main development clone's remote configuration and authority branches are unchanged in `specs/462-github-repository-bootstrap-git-data-baseline-v1/implementation-report.md`.
- [x] T048 [US3] Record US3 PASS for FR-016FR-023 and AC-006AC-007, or the authorized fail-closed stop, in `specs/462-github-repository-bootstrap-git-data-baseline-v1/implementation-report.md`.
---
## Phase 6: User Story 4 — Prove Parity and Passive Authority (P1)
**Goal**: Prove exact Git-data parity, zero extras, target integrity, stable source,
and unchanged delivery authority.
**Independent test**: Every manifest ref is `OID_MATCH`, the three authority trees
match, a fresh target bare clone is intact, source refs did not drift, and target
settings remain passive.
### Parity tasks
- [x] T049 [US4] Have the root coordinator query all target heads/tags and record exact ref/OID comparisons against the manifest in `specs/462-github-repository-bootstrap-git-data-baseline-v1/github-parity-report.json`.
- [x] T050 [US4] Record commit OID, tree OID, parent count, and subject parity for `dev`, `platform-dev`, and `website-dev` in `specs/462-github-repository-bootstrap-git-data-baseline-v1/github-parity-report.json`.
- [x] T051 [US4] Prove zero extra, archive-only, local-only, stash, Codex, worktree-private, pull, or temporary target refs in `specs/462-github-repository-bootstrap-git-data-baseline-v1/github-parity-report.json`.
- [x] T052 [US4] Have the root coordinator create a fresh target bare clone outside the repository, run `git fsck --full`, and record NFR-006 missing/corrupt/dangling-object truth in `specs/462-github-repository-bootstrap-git-data-baseline-v1/github-parity-report.json`.
- [x] T053 [US4] Have the root coordinator reverify target owner/name, private visibility, default branch `dev`, Actions disabled state, zero open pull requests/workflow runs/non-owner collaborators/teams, and no configured deploy keys, webhooks, repository workflows, Rulesets, branch protection/Required Checks, runners, secrets, variables, or environments in `specs/462-github-repository-bootstrap-git-data-baseline-v1/github-parity-report.json`; any unreadable required invariant is `NOT_PROVEN` and blocks PASS.
- [x] T054 [US4] Have the root coordinator requery Gitea refs/default branch and every readable FR-030 authority/settings surface, compare them with T022, prove the command/API audit log contains no Gitea mutation, compare the post-transfer source digest with the frozen digest, and record `NOT_PROVEN` for any unreadable required surface in `specs/462-github-repository-bootstrap-git-data-baseline-v1/github-parity-report.json`.
- [x] T055 [US4] End the logical source freeze only after T049T054 pass, record the freeze interval, stable source digest, writer/automation release confirmations, and zero uncontrolled-writer evidence in `specs/462-github-repository-bootstrap-git-data-baseline-v1/external-activation-checklist.md`.
- [x] T056 [US4] Record non-destructive rollback readiness: stop further writes, keep GitHub private and Actions disabled, preserve evidence and temporary clones, emit `INVALID_PARTIAL_BASELINE` on partial/failing transfer, and prove Spec 462 performs no ref/repository deletion or recreation in `specs/462-github-repository-bootstrap-git-data-baseline-v1/implementation-report.md`.
- [x] T057 [US4] Record the exact GitHub passive/Gitea active declarations and metadata/archive deferrals in `specs/462-github-repository-bootstrap-git-data-baseline-v1/implementation-report.md`.
- [x] T058 [US4] Reconcile FR-024FR-035, AC-008AC-015, and SC-002SC-006; record FR-036 as a proven stop-before-follow-up boundary rather than a completed reconciliation in `specs/462-github-repository-bootstrap-git-data-baseline-v1/implementation-report.md`.
---
## Phase 7: Candidate Validation, Review, and Handoff
**Purpose**: Freeze one exact local candidate and stop at the separately
authorized local finalization boundary.
- [x] T059 Complete every verdict-applicable evidence artifact, NFR-004 redaction proof, NFR-005 audit fields, and exactly one schema-valid `tenantpilot-implementation-evidence` block in `specs/462-github-repository-bootstrap-git-data-baseline-v1/implementation-report.md`; under `PRE_ACTIVATION_READY`, keep `spec.md`, `plan.md`, and `execution-contract.json` at `Ready for implementation`, while after `PASSIVE_BASELINE_VERIFIED` synchronize their status to `Implemented` before freezing the candidate and record the operational verdict separately from the schema status.
- [x] T060 Reconcile all T001T059 task outcomes, explicit stops, N/A lanes, no completed-spec rewrite, and the exact completion verdict in `specs/462-github-repository-bootstrap-git-data-baseline-v1/tasks.md`; activation/parity tasks remain explicitly incomplete only while the historical `PRE_ACTIVATION_READY` lock applies.
- [x] T061 Run NFR-001NFR-007 JSON/digest/scope/safety checks, `git diff --check`, current Spec Package validation, routed candidate gates, `cd apps/platform && ./vendor/bin/sail artisan test --compact tests/Feature/Guards/CodexAgentFoundationContractTest.php`, and `cd apps/platform && ./vendor/bin/sail bin pint --dirty --format agent`; record exact commands/results in `specs/462-github-repository-bootstrap-git-data-baseline-v1/implementation-report.md`.
- [x] T062 Obtain independent `test_validator` evidence bound to the exact frozen candidate and record its sanitized identity/result in `specs/462-github-repository-bootstrap-git-data-baseline-v1/implementation-report.md`.
- [x] T063 Obtain one complete independent `code_reviewer` result for the frozen candidate and validation evidence; record `NO_CONFIRMED_FINDINGS` or bounded findings in `specs/462-github-repository-bootstrap-git-data-baseline-v1/implementation-report.md`.
- [x] T064 Apply only confirmed in-scope corrections under `specs/462-github-repository-bootstrap-git-data-baseline-v1/**`, rerun affected validation and complete review, and stop rather than widening scope when current governance requires escalation.
- [x] T065 Only after `PASSIVE_BASELINE_VERIFIED` plus matching validation/review/report evidence, record `IMPLEMENTATION_REVIEWED` and run completion/receipt issuance; under `PRE_ACTIVATION_READY`, prove no completion or finalization receipt was issued and record the external activation boundary in `specs/462-github-repository-bootstrap-git-data-baseline-v1/implementation-report.md`.
- [x] T066 Stop before local commit, push, pull request, merge, deployment, or promotion unless each receives separate current authority; always stop before post-integration reconciliation and hand that work to Spec 463 or another explicitly approved follow-up in `specs/462-github-repository-bootstrap-git-data-baseline-v1/implementation-report.md`.
---
## Dependencies and Execution Order
```text
Phase 1 preflight
-> Phase 2 evidence contract
-> US1 target proof
-> US2 source/local inventory
-> US3 manifest and external activation gate
-> US4 parity/passivity proof
-> Phase 7 candidate validation and review
```
- US1 and US2 are independently verifiable read-only deliverables after Phase 2,
but US3 activation depends on both.
- US4 depends on an authorized completed US3 transfer. If authorization is not
granted, the valid stopping verdict is `PRE_ACTIVATION_READY`; it is not feature
completion and cannot issue a completion/finalization receipt.
- Read-only network queries may be orchestrated concurrently by the root
coordinator, but task completion and tracked evidence writes are sequential;
no task is marked `[P]`.
- External mutations T042T045 are sequential and never parallel.
- Phase 7 validates the exact frozen candidate after all applicable prior tasks.
## Parallel Example
After Phase 2 passes, the root coordinator may collect independent read-only
query results concurrently, but it records them sequentially in the shared
artifacts. No writer, task completion, or mutation task is parallelized.
## Implementation Strategy
### Smallest safe implementation increment
US1 target proof plus US2 inventory/disposition plus an exact dry-run manifest is
the smallest safe pre-activation increment. It can stop at
`PRE_ACTIVATION_READY` and has value as a reviewed migration plan without mutating
GitHub, but it is not implementation completion.
### Activation increment
US3 and US4 form one indivisible authorized activation increment. The target is
not accepted after transfer until complete parity/passivity proof passes.
### Follow-up boundary
Post-integration `platform-dev` reconciliation and platform delivery stay in Spec
463 or another explicitly approved follow-up. Website delivery and final
`dev`/Gitea authority cutovers stay in Specs 464 and 465. They are not
implementation tasks of Spec 462.
## Explicit Non-Goals
- No `.github/workflows/**` or `.gitea/workflows/**` change.
- No GitHub PR, Ruleset, Required Check, runner, secret, variable, or environment.
- No Gitea metadata migration or archival activation.
- No application/runtime/UI/website/database/provider/queue/deployment change.
- No branch merge, rebase, convergence, force update, deletion, or local cleanup.
- No shared repository migration framework or permanent multi-host abstraction.