Skip to content

spec: mature-first BytePort recovery, scope reconciliation and deployment oracles - #427

Draft
KooshaPari wants to merge 87 commits into
mainfrom
spec/mature-recovery-2026-09-29
Draft

KooshaPari wants to merge 87 commits into
mainfrom
spec/mature-recovery-2026-09-29

Conversation

@KooshaPari

Copy link
Copy Markdown
Owner

Status and scope

INCOMPLETE / BLOCKED. BytePort is paired only with ShareCLI for this recovery program. This PR does not freeze architecture, establish a usable product stage or recommend merging.

Registry research and completion gate: KooshaPari/PhenoRegistry#592.
Paired ShareCLI specification: KooshaPari/ShareCLI#878.

Frozen analyzed source: 0232cca16fedb7963a8c6f556dc5eee5c8c1674e.
Registry analyzed source: 85d7cd00cf59c379c05b740e8130a85b0d5bd31b.
Specification head: 1d03b2b6235c716a819009f99075c87912954ba8.
No implementation candidate has been accepted or selected for acceptance.

Additive product-local records

https://github.com/KooshaPari/BytePort/tree/spec/mature-recovery-2026-09-29/docs/specs/mature-recovery/2026-09-29

SNAPSHOT, semantic SOURCE-COVERAGE-LEDGER, RECOVERY-CONTRACT, SEMANTIC-FINDINGS, ORACLE-CONTRACT and CURRENT-STATE.

The contract draft recovers mature product identity before proposing narrow stage projections. It separates project/source/manifest/build/target/operation/provider-resource identities, first-class journeys, applicable quality overlays, transition debt and bounded work packages. Existing requirement IDs and canonical/historical documents are not replaced.

Evidence-backed findings

  1. Authority conflict: user-attributed November/December2024 and August2026 conversation retrieval plus SPEC.md preserve Git-to-cloud deployment and portfolio productization. Newer registry local-only wording cites39 prompt references whose underlying curated corpus is explicitly absent/unresolved. No accepted pivot deleting the broader horizon was found within inspected evidence. Raw transcripts and complete pivot history remain open.
  2. Wrong deployed subject: the mounted /deploy handler submits alpine:latest/native rather than translating the selected source into the requested application artifact. A successful sandbox response is not selected-application acceptance.
  3. Identity mismatch: /deploy stores the returned provider sandbox ID in its deployment map; /terminate sends project UUID. The persistence hooks and DB helper were inspected and do not normalize those identities. A fixture with deliberately distinct IDs is required.
  4. Recovery/trust questions: remote provisioning precedes local persistence; no compensator was found in the inspected path. Main binds0.0.0.0. These require crash/reconciliation and explicit access-mode experiments, not an unsupported claim of a completed security assessment.

Oracle design and verification boundary

Acceptance must independently observe selected artifact, exact actor/target/provider identity, durable recovery state and actual user-facing result. Wrong-image200, equal-ID mocks, stale evidence, missing/empty/skipped tests and candidate-controlled rubric weakening cannot be green.

No native Go/Rust/Tauri product suite, desktop run, NanoVMS deployment or paid cloud resource was executed. Source findings are not runtime remediation receipts. Full UI/CLI reachability, complete source/history coverage, accepted scope reconciliation, pinned dependency contracts, deeper current SOTA/license/health/academic review, independent grader enforcement and fresh adversarial completeness review remain outstanding.

No production code, secrets, old artifacts, releases or main branch was changed. Completion percentage remains null; all unmet gates are explicit in CURRENT-STATE. The later comparative pilot is separate and has not run.

tx-agent: chatgpt-mature-recovery

…contradictions

Record the open source denominator without replacing existing canonical specifications.

tx-agent: chatgpt-mature-recovery
tx-validated: mounted-source-inspection; native-suites-not-run
…dates

Preserve the recovered Git-to-cloud and portfolio horizon pending authority reconciliation.
Distinguish selected application deployment from placeholder sandbox success.

tx-agent: chatgpt-mature-recovery
tx-validated: handler-and-persistence-source-trace; native-suites-not-run
@coderabbitai

coderabbitai Bot commented Sep 29, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Copy link
Copy Markdown
Owner Author

First-cycle receipt

Registry dossier/paired review: KooshaPari/PhenoRegistry#592
Paired product: KooshaPari/ShareCLI#878

Compared analyzed source 0232cca16fedb7963a8c6f556dc5eee5c8c1674e to specification head 1d03b2b6235c716a819009f99075c87912954ba8: only6 new recovery files, no existing-file changes/deletions. Existing SPEC/CHARTER/intent history is preserved; document recency is not used to authorize scope deletion.

Evidence reviewed includes the mounted router, deploy/terminate handlers, Project persistence hooks and DB helper. The latter two do not rewrite project identity to the separately returned provider ID. This strengthens the source finding but is not a native runtime test.

Next bounded proof: actual selected-application marker/digest, deliberately distinct product/provider IDs, and restart after remote acceptance before local persistence. Resolve the original-prompt/local-only scope conflict in parallel. No native application, desktop or paid/cloud deployment was executed in this pass.

Specification/design remains INCOMPLETE / BLOCKED, with open source denominator and no completion percentage. No merge recommendation.

Add a native handler-level negative control with deliberately different IDs.
No production remediation is included.

tx-agent: chatgpt-mature-recovery
tx-validated: source-derived expected-failure fixture
…ty oracle

Use accepted ADR/charter/PRD/journey evidence to constrain the local-first interpretation.

tx-agent: chatgpt-mature-recovery
tx-validated: authority-source-and-handler-oracle-review

Copy link
Copy Markdown
Owner Author

Pass 2 receipt — authority reconciliation + provider-ID oracle

New branch head: a6166a1ad0c79400dedd84309d854bd95ca5e7dc (includes native adversarial test commit 934b0456de5509b5e89294c3adaa046e632a2767).

Authority recovery materially strengthened: frozen-source CHARTER.md (June 12), accepted ADR.md, PRD.md, FUNCTIONAL_REQUIREMENTS.md, and USER_JOURNEYS.md all retain manifest/Git→AWS deployment plus portfolio behavior. The charter explicitly reserves mission/tenet changes to Executive Authority. No later accepted mission deletion was found in the inspected commit/search history. Therefore September registry local-first/desktop-first prose is treated provisionally as placement/stage/surface evolution, not automatic mature-scope supersession. CLI-first vs desktop-first remains unresolved.

Added backend/byteport/routes/recovery_provider_identity_test.go: product ID project-123 and provider runtime ID provider-sandbox-777 are deliberately unequal; the real terminate handler must target the persisted provider ID. No production fix is present. Current-head CI is queued/pending.

Pass-2 source record: docs/specs/mature-recovery/2026-09-29/PASS-2-AUTHORITY.md.

Selected-artifact native test is deliberately deferred until SourceSnapshot→ManifestRevision→BuildArtifact semantics are selected; inventing an image naming convention would manufacture a contract. Scope authority is narrowed but not fully closed; architecture/completion gates remain blocked.

…idence

Separate September UI/docs evolution from mature mission authority.

tx-agent: chatgpt-mature-recovery
tx-validated: commit-metadata-lineage-review

Copy link
Copy Markdown
Owner Author

Pass 2B correction — desktop docs are not mission authority

Direct commit archaeology falsified a key ambiguity. The September README rewrite that introduced “only open-source desktop deployment app” is commit 32aa87512f2ccc88c446c2cc816b0d3f5fa71c83, explicitly tx-agent: jcode, tx-validated: manual, scoped to README/docs-gap repair. The next-day application-shell commit 9b826bbefa4ae2ba90741258447517d27293b1bf states its intent as one shell/active-route/offline-state and explicitly marks visual result UNKNOWN. Neither is an executive mission/charter change.

New source record: PASS-2B-DESKTOP-LINEAGE.md, branch head d32cb0b6d4e016e6deb714741c198d7967a980bb.

This substantially strengthens the provisional model: deployment+portfolio remains the mature horizon; desktop/local-first is surface/placement evolution unless contrary authority is recovered. CLI-first vs desktop-first remains a projection-priority question. The canonical registry intent file is not rewritten yet because raw chats/PR authority and independent falsification remain open.

@github-actions

Copy link
Copy Markdown

📊 Tier-2 Coverage Gate Results

Tier Threshold Status
Rust lib (byteport-transport) ≥71% ❌ Fail
Go framework (backend/byteport) ≥71% ❌ Fail
Service/E2E (frontend/web) ≥60% ❌ Fail

Quarantine agent-generated transport architecture pending accepted-product trace.

tx-agent: chatgpt-mature-recovery
tx-validated: commit-lineage-review

Copy link
Copy Markdown
Owner Author

Pass 3 receipt — lineage partition + exact native rerun

Branch head: 84c9548db499fa1323bd07dc00089aabadb4629d.

New lineage partition prevents current-tree breadth from becoming scope by accident. June commit a12a0bb6... injected byteport-transport, upload/codec/hex ports and CLI scaffolding through Codex/Forge focus-repo work; the current charter explicitly says it replaced an earlier data-transport/byte-stream product that was never built. These crates are now EXPERIMENT/TRANSITION candidates until actual callers trace to the accepted deployment/productization lineage. Some transport code is genuinely wired into Tauri/headless CLI, so it is not deleted; wiring proves implementation reach, not product authority.

Current journey mapping also confirms J3 portfolio paths named in USER_JOURNEYS.md are absent from the frozen tree, while the mounted deploy handler sends alpine:latest. Journey text remains intended behavior, not implementation evidence.

The exact provider-ID adversarial test commit is 934b0456de5509b5e89294c3adaa046e632a2767. I explicitly re-ran its cancelled Go test (backend/byteport) job rather than letting newer docs SHA substitute. New job 109572633061 is currently QUEUED. No native failure/pass is claimed yet.

Shared PhenoInfra dependency is frozen at exact dd040ed1bb293e3c843245448a9a173f5dff3470; consumer mapping remains open. Completion remains BLOCKED.

@github-actions

Copy link
Copy Markdown

Legacy Tooling Scan Report

Severity Count
Critical 0
High 0
Medium 0
Low 0

No violations detected.

This is a WARN-mode scan. Fix before strict enforcement begins.

@github-actions

Copy link
Copy Markdown

📊 Tier-2 Coverage Gate Results

Tier Threshold Status
Rust lib (byteport-transport) ≥71% ❌ Fail
Go framework (backend/byteport) ≥71% ❌ Fail
Service/E2E (frontend/web) ≥60% ❌ Fail

Bind BP-F03 to exact candidate, workflow job, fixture and failure output.

tx-agent: chatgpt-mature-recovery
tx-validated: exact-job-log-review
Bind state to exact Go handler failure without closing architecture risk.

tx-agent: chatgpt-mature-recovery
tx-validated: exact-job-receipt-state-update
Promote project/source/artifact/operation/provider identities before fixing BP-F03.

tx-agent: chatgpt-mature-recovery
tx-validated: native-evidence-backed-ontology-slice
Separate mutable source reference from snapshot manifest artifact operation and provider resource.

tx-agent: chatgpt-mature-recovery
tx-validated: recovered-contract-plus-mounted-path-review
@github-actions

Copy link
Copy Markdown

📊 Tier-2 Coverage Gate Results

Tier Threshold Status
Rust lib (byteport-transport) ≥71% ✅ Pass
Go framework (backend/byteport) ≥71% ❌ Fail
Service/E2E (frontend/web) ≥60% ✅ Pass

@github-actions

Copy link
Copy Markdown

Legacy Tooling Scan Report

Severity Count
Critical 0
High 0
Medium 0
Low 0

No violations detected.

This is a WARN-mode scan. Fix before strict enforcement begins.

Copy link
Copy Markdown
Owner Author

Pass 4 — BP-F03 native reproduction confirmed

Exact Go job 109572633061 executed the adversarial handler fixture and failed exactly on the intended identity distinction: actual stop target project-123; persisted provider runtime expected provider-sandbox-777. BP-F03 is now NATIVE_COUNTEREXAMPLE_REPRODUCED for candidate 934b0456de5509b5e89294c3adaa046e632a2767.

Evidence receipt: docs/specs/mature-recovery/2026-09-29/evidence/BP-F03-native-provider-identity.md.

I did not patch termination yet. The new ONTOLOGY-V0.1.md and SOURCE-ARTIFACT-CONTRACT.md establish the broader identity chain first: Project → SourceSnapshot → ManifestRevision → BuildArtifact → DeploymentIntent → Operation → ProviderResource → Observation. A local variable fix without multi-deployment/operation semantics would be premature.

Current state machine record now carries the native result explicitly; completion remains blocked/null.

…neage

Preserve portfolio outcome while treating unavailable Slickport as an adapter/history lead.

tx-agent: chatgpt-mature-recovery
tx-validated: registry-and-repository-availability-review

Copy link
Copy Markdown
Owner Author

Source/artifact + portfolio boundary advanced

SOURCE-ARTIFACT-CONTRACT.md now defines mutable SourceReference → immutable SourceSnapshot → ManifestRevision → BuildPlan → BuildArtifact → DeploymentIntent → Operation → ProviderResource. Three build-ownership architectures remain open; no guessed image convention is being promoted into contract.

Slickport archaeology also clarifies the portfolio boundary. BytePort's charter and historical README treat Slickport as a portfolio backend/example, while PhenoRegistry inventories KooshaPari/slickport historically; direct repository lookup now returns 404. Portfolio remains a mature BytePort outcome independently. PORTFOLIO-LINEAGE.md therefore models a provenance-bearing PortfolioProjection with adapter-based publication instead of coupling BytePort identity to Slickport.

No third product program was started.

Add a native evidence probe for the deploy/persist crash window without selecting the final recovery architecture.

tx-agent: chatgpt-mature-recovery
tx-validated: observational-risk-probe

Copy link
Copy Markdown
Owner Author

Pass 4 execution receipt

BP-F03 is now NATIVE_COUNTEREXAMPLE_REPRODUCED on exact candidate 934b0456de5509b5e89294c3adaa046e632a2767, job 109572633061: actual stop target project-123; persisted provider runtime provider-sandbox-777.

The branch now contains an evidence receipt plus ontology/source-artifact contracts. Identity chain: Project→SourceSnapshot→ManifestRevision→BuildArtifact→DeploymentIntent→Operation→ProviderResource→Observation.

A second native observational probe (c7cb0a8a3c1e25b567deafcdcd8de8058a6d99a5) injects DB failure after provider deploy to measure BP-F04's remote-side-effect window without prematurely selecting compensation vs journal/reconcile/adopt semantics. Its CI run is queued; no result claimed yet.

Registry/NanoVMS boundary evidence further narrows architecture: NanoVMS is a sandbox/VMM runtime boundary, not high-level source/build orchestration. Provider-owned source build is unsupported by current evidence. BytePort-owned orchestration plus delegated established build engine is now the stronger bootstrap candidate, pending direct prototype/API falsification.

@github-actions

Copy link
Copy Markdown

📊 Tier-2 Coverage Gate Results

Tier Threshold Status
Rust lib (byteport-transport) ≥71% ✅ Pass
Go framework (backend/byteport) ≥71% ❌ Fail
Service/E2E (frontend/web) ≥60% ✅ Pass

@github-actions

Copy link
Copy Markdown

Legacy Tooling Scan Report

Severity Count
Critical 0
High 0
Medium 0
Low 0

No violations detected.

This is a WARN-mode scan. Fix before strict enforcement begins.

@github-actions

Copy link
Copy Markdown

📊 Tier-2 Coverage Gate Results

Tier Threshold Status
Rust lib (byteport-transport) ≥71% ✅ Pass
Go framework (backend/byteport) ≥71% ❌ Fail
Service/E2E (frontend/web) ≥60% ✅ Pass

Bind each source/build/runtime/auth/network/publication criterion to mounted implementation or explicit gap.

tx-agent: chatgpt-mature-recovery

Copy link
Copy Markdown
Owner Author

Selected-app vertical-slice contract receipt

Current Project storage confirms the mature identity chain cannot be honestly backfilled: it stores mutable repository metadata plus a JSON provider-instance map, with no SourceSnapshot, ManifestRevision, BuildArtifact, Operation, Generation or Observation identities.

Added VERTICAL-SLICE-SELECTED-APP.md with an additive migration rule: legacy rows remain readable but legacy_unverified unless exact historical evidence exists. The slice now has 20 explicit public-path criteria spanning source resolution, manifest, build/provenance, durable runtime operation, restart/lost response, exact provider resource, rollout, auth/session expiry, portfolio publication, network mode, CLI/Desktop/API convergence and uninstall semantics.

Traceability slice 02 maps each criterion to current implementation or explicit gap. Current recovery/auth workflow is queued; no pending result is promoted.

…tation

Retain semantic authority while quarantining stale paths and unqualified numeric targets.

tx-agent: chatgpt-mature-recovery

Copy link
Copy Markdown
Owner Author

ADR authority + selected-app storage receipt

Accepted ADR-001 corroborates CLI-primary, Git ref deployment, manifest/multi-service and portfolio service boundaries, but its named package tree is not current implementation evidence. Historical numeric targets (<100ms CLI, <500ms manifest, <135s deploy, <200MB backend, 5+ deployments) are quarantined until benchmark contracts requalify them.

Conversation recovery did not find direct user authority making ADR-001's AWS-primary/provider-specific choices immutable. Provider strategy therefore remains adapter-based; AWS can be supported without becoming BytePort identity.

Current Project storage cannot represent the selected-app mature identities, so additive migration with legacy_unverified historical rows remains required. No production schema changed.

Sequence additive identities/persistence/application adapters before receipt-gated lifecycle/build/network/publication integration.

tx-agent: chatgpt-mature-recovery
Grade source/artifact/operation/provider/auth/publication identities with hard anti-gaming controls.

tx-agent: chatgpt-mature-recovery

Copy link
Copy Markdown
Owner Author

Developer-package/autograder receipt

Added DEVELOPER-WORK-PACKAGES-V0.1.md: additive domain identities → legacy-safe persistence + common application operations → BuildEngine/RuntimeAdapter → evidence validator, before receipt-gated lifecycle/source/build/network/publication convergence.

Added AUTOGRADER-V0.1.md. Hard fails include mutable ref as snapshot, tag as final identity, HTTP success as app proof, ProjectID as ProviderResourceID, mutation without recoverable operation, fingerprint conflict, legacy fake verification, auth/network confusion, plan-as-deployed and remote deletion on uninstall.

No production schema or route behavior changed.

Encode additive Tier-A work and evidence-gated Tier-B integration for agent execution.

tx-agent: chatgpt-mature-recovery
…ure stages

Keep source artifact operation generation and provider identities stable from the first selected-app slice.

tx-agent: chatgpt-mature-recovery
Separate transport/planner/placeholders/historical provider architecture from accepted mature obligations.

tx-agent: chatgpt-mature-recovery

Copy link
Copy Markdown
Owner Author

Machine-executable handoff + stage projection receipt

Added work-packages.json, STAGE-PROJECTIONS-V0.1.md, and ORPHAN-SCOPE-LEDGER.md.

CVP now explicitly requires the mature SourceSnapshot/ManifestRevision/BuildArtifact/RuntimeOperation/Generation/ProviderResource spine even with one source/build/runtime adapter. ProjectID-as-runtime, mutable refs/tags as final evidence, and disposable operation schemas are forbidden transition debt. Transport/hex focus work, plan-only Tauri deploy, alpine placeholder, AWS-specific old package design and legacy DeploymentsJSON are explicitly classified rather than counted as mature scope.

Current-head recovery workflow remains pending; no result claimed.

Make developer handoff structure machine-checkable.

tx-agent: chatgpt-mature-recovery
Reject invalid IDs gates dependencies duplicates and cycles before agent execution.

tx-agent: chatgpt-mature-recovery
Validate the machine-readable handoff before spec changes can claim usable package state.

tx-agent: chatgpt-mature-recovery
Prevent skipped stale wrong-candidate or unexecuted results from becoming green.

tx-agent: chatgpt-mature-recovery
Exercise NOT_RUN semantics without creating product evidence.

tx-agent: chatgpt-mature-recovery
Validate that unexecuted/nonqualifying evidence cannot satisfy criteria.

tx-agent: chatgpt-mature-recovery

Copy link
Copy Markdown
Owner Author

Machine-enforced contract integrity receipt

Added recovery schema/validators plus Mature Recovery Contract Integrity workflow. Work-package DAG validity and evidence qualification are now executable checks. PASS cannot exist without raw artifacts, exact candidate match and executed oracle; non-run/stale/wrong-candidate/collector/unknown states cannot satisfy criteria.

The workflow has not yet registered on the latest commit, so no CI-green claim is made. This is additive Tier-A control-plane implementation only.

Introduce source, artifact, operation, generation, provider-resource and observation identities without changing routes or schema.

tx-agent: chatgpt-mature-recovery
tx-wp: BP-WP-A01
Cover round-trip, provider-managed no-artifact and typed provider-resource boundaries.

tx-agent: chatgpt-mature-recovery
tx-wp: BP-WP-A01
Run additive mature identity tests independently from broad product CI.

tx-agent: chatgpt-mature-recovery
tx-wp: BP-WP-A01

Copy link
Copy Markdown
Owner Author

Tier-A implementation begins — BP-WP-A01

Implemented additive mature domain identities in backend/byteport/models/mature_identity.go: SourceSnapshot, ManifestRevision, Component/ArtifactResolution, BuildArtifact, RuntimeOperation, DeploymentGeneration, ProviderResource and Observation plus distinct named IDs. Tests cover JSON round-trip, provider-managed components without fake artifacts, UNKNOWN operation state and typed ProviderResource boundary.

No route or database schema uses these types yet. This is A01 scaffolding only. Dedicated contract-integrity CI now includes the model tests; workflow registration is still pending, so no CI-green claim.

@sonarqubecloud

Copy link
Copy Markdown

Quality Gate Failed Quality Gate failed

Failed conditions
C Security Rating on New Code (required ≥ A)

See analysis details on SonarQube Cloud

Catch issues before they fail your Quality Gate with our IDE extension SonarQube for IDE

Represent historical provider instances without fabricating source manifest or artifact verification.

tx-agent: chatgpt-mature-recovery
tx-wp: BP-WP-A02
Create source manifest artifact runtime and portfolio seams without migrating Gin or Tauri behavior.

tx-agent: chatgpt-mature-recovery
tx-wp: BP-WP-A03
Ensure old provider instances cannot acquire fabricated source manifest or artifact identity.

tx-agent: chatgpt-mature-recovery
tx-wp: BP-WP-A02
Exercise legacy-unverified semantics and common application identity models independently.

tx-agent: chatgpt-mature-recovery

Copy link
Copy Markdown
Owner Author

Tier-A parallel implementation receipt — A02/A03

Added explicit LegacyDeploymentImport with legacy_unverified state and nil SourceSnapshot/ManifestRevision/BuildArtifact by default; tests prevent fabricated mature verification. Added common application-operation interfaces for source resolution, manifest resolution, artifact resolution, RuntimeAdapter create/observe/stop, PortfolioProjector and PortfolioPublisher. Existing Gin/Tauri routes and DB schema remain untouched.

Dedicated contract workflow run 36719051403 is registered/pending on the A02/A03 head. Pending is non-evidence; package qualification waits for exact job execution.

@sonarqubecloud

Copy link
Copy Markdown

Quality Gate Failed Quality Gate failed

Failed conditions
C Security Rating on New Code (required ≥ A)

See analysis details on SonarQube Cloud

Catch issues before they fail your Quality Gate with our IDE extension SonarQube for IDE

@github-actions

Copy link
Copy Markdown

📊 Tier-2 Coverage Gate Results

Tier Threshold Status
Rust lib (byteport-transport) ≥71% ❌ Fail
Go framework (backend/byteport) ≥71% ❌ Fail
Service/E2E (frontend/web) ≥60% ❌ Fail

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant