Skip to content

fix: reconcile Bootstrap ownership without Flow contract drift - #33

Merged
pheidon merged 1 commit into
mainfrom
recovery/flow32-managed-contract-20260914
Sep 14, 2026
Merged

pheidon merged 1 commit into
mainfrom
recovery/flow32-managed-contract-20260914

Conversation

@pheidon

@pheidon pheidon commented Sep 14, 2026

Copy link
Copy Markdown
Member

Summary

Reconcile Bootstrap ownership without overwriting Flow's product-specific repository contract. Fresh recovery of #32 from current main; no historical patch adopted.

  • Delegate only the compatible implementation and flow-blocker form projections to Bootstrap.
  • Generate their ownership sidecar with Bootstrap 99455ebc120bc91987ee2f7f9a7c097ae73021dc.
  • Preserve the canonical templates, fast-check/cache-rejecting hook, runner labels, immutable-pin guidance, Python CodeQL declaration, and all GitHub governance settings.

Governing Issue

Refs #13. This is a bounded ownership reconciliation, not completion of the broader PRS dogfood migration. Original #32 remains open until this replacement is verified merged.

Validation

  • Fresh real Bootstrap plan: all selected outputs unchanged after sidecar generation.
  • Isolated Bootstrap apply/replan preserves repository contract; negative controls reject generated drift and expose destructive baseline overwrites.
  • Cloud exact-head full suite: 85 tests pass; deterministic policy release build and verification pass. Three recovered artifact hashes and three source hashes verified; worker provider deletion confirmed.
  • Independent exact-head Qwen review pending.
  • Required CI Gate and Workflow Lint pass for this exact head.

Bootstrap Governance

  • Scope limited to manifest ownership, generated sidecar, and onboarding explanation.
  • No credentials, runtime state, GitHub settings or security/CI policy changes.
  • Existing compatible Bootstrap generation reused; no custom renderer.

Flow Contract

  • Owner lane: Pheidon recovery
  • Repair owner: Pheidon
  • Autonomy class: bounded JT-authorized PR recovery
  • Risk class: repository ownership metadata; no runtime deployment

Flow Merge Readiness

  • Independent Qwen exact-head review, Athena code-owner approval, and required CI remain gates.
  • No admin bypass; original PR will only be superseded after verified normal merge.

Merge Automation

Auto-merge will be enabled once independent review is verified and publication gates are met.

Notes

Generic generation would erase Flow's exact runner selector, immutable-pin documentation and fast-check hook, and drift from canonical PR input. Those files remain product-owned, not exempt from any gate. This does not claim broader issue #13 completion or a permanent policy exception. Fresh implementation: OpenAI/Codex; designated independent reviewer: Qwen.

@pheidon
pheidon requested a review from a team as a code owner September 14, 2026 12:46

@athena-omt athena-omt left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Qwen cross-model review: APPROVE, exact head faa1ad795252f134832be75a89b3c9c9f0edeceb.

Independent examination by actual qwen-token-plan/qwen3.8-max, separate from the OpenAI/Codex author. Successful terminal receipt verified with no fallback; all 13 review artifact checksums verified. Published by Athena automation under common JT control, not independent credential authority.

All 14 independent controls pass: real Bootstrap plan/apply idempotence, managed-file drift rejection, de-scoped canonical template drift rejection, preserved Flow runner/hook/docs, and repository fast checks. No blocking findings. Required CI Gate and security checks pass at this head.

Reviewer limitation: cloud suite not independently rerun by reviewer. Parent verified cloud execution of all 85 tests and deterministic release build, recovered artifact/source hashes, and provider deletion. Existing generator reused at 99455ebc120bc91987ee2f7f9a7c097ae73021dc unchanged.

Evidence: reports/qwen-review-flow33-20260914/{REVIEW.md,review.json,CHECKSUMS.sha256}; reports/flow32-recovery-20260914/review-terminal-receipt.json and cloud-evidence. Governance, code-owner and CI requirements unchanged.

@pheidon
pheidon merged commit 165ff16 into main Sep 14, 2026
6 checks passed
@pheidon
pheidon deleted the recovery/flow32-managed-contract-20260914 branch September 14, 2026 13:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants