You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Implement one pinned-plan orchestration stream (0073 + 0077) #2290
Implement accepted decision records 0073 and 0077 as one external work stream. Replace repository-seeded and generated execution inputs with canonical pinned plans, preserve the deterministic unit machine, and retire the executable graph only after the accepted 0073 shadow/fixture/ownership gates pass.
No implementation plan belongs under docs/plans/.
Authority
Decision 0073 is accepted and owns orchestration, parent cardinality, composer fencing, durable adoption and retirement of the graph composer.
Decision 0077 is accepted at 5eb4fd40f81ae86e84749ffd9bed0fe79484cf6f. Its maintainer-authorized acceptance gate is the five-question receipt; there is no broader acceptance hold.
docs/plans/2026-09-21-002-feat-the-ship-pipeline-dissolves-into-the-orchestrator-plan.md is bootstrap input imported once, not a continuing repository execution address.
One execution contract
A validated PlanArtifact is pinned immutably under (planId,digest) in the coordinator store.
Canonicalization sorts object keys, preserves array order, rejects duplicate source/unit IDs and non-canonical numbers, and hashes the exact UTF-8 bytes with SHA-256.
Execution accepts only PlanRef{planId,digest,providerUrl} and loads exact pinned bytes. GitHub is a human projection, never an execution loader or digest source.
Mutable publication metadata is stored separately from canonical bytes.
Every source and unit has a stable typed identity. Model-authored prose cannot populate execution identity, authority, operation targets or publication destinations.
The existing deterministic unit machine retains leases, one owner, code → review → fix → checks → merge, rebase-before-push, changed-set gates, work preservation, reviewed-head equality, checks, authorization, confirmation and the merge door.
Independent repository facts
Do not replace #2238 with another repository-ranking rule. Carry these independently:
RequestContext: inherited workspace/default for unqualified material.
OperationTarget: typed repository, pull request or plan unit acted on.
PublicationDestination: destination for each provider effect.
EvidenceReference[]: cited repositories/issues/pull requests/files with no target or write authority.
Required examples:
Ask
Context
Operation target
Publication
in owner/a: review owner/b#5
A
B#5
verdict on B#5
in owner/a: implement owner/b#5
A
A; B#5 is evidence
branch/PR in A
review B#5, implement findings in A
A
review B#5; code A
verdict B#5; PR A
cross-repository plan
request context
each unit’s typed target
parent in configured planning repo; unit issue/PR in target repo
Ambiguous roles ask or refuse before write identity. Citation order, thread recency and repository ranking never decide an operation target.
Prerequisite order
Before S1: implement decision 0072 U1’s durable live-state projection. Accepted 0073 requires that exact field for its atomic parent relation.
The accepted delivery list says S2 admits direct tasks while S3 introduces plan. To preserve direct-task behavior without restoring generated execution, amend only the slice boundary:
S2 introduces the text-only plan contract needed for fresh direct tasks.
S3 extends that same contract to files, images, issues and threads and adds standalone/revision behavior.
No architecture, artifact, authority or loader rule changes. Until that amendment is accepted, fresh direct-task admission remains an owner decision, not an inferred requirement.
Slices
S1 — canonical pins and one loader, dark. Add artifact validation, canonical pinning, complete migration inventory and the fenced off/shadow/on composer seam. Migrate every resumable generated/repository-seeded pipeline and the bootstrap plan. Delete both old loaders. Start or resume no code.
S2 — publication, text planning and 0073 retirement. Publish/adopt the required parent URL, form complete PlanRefs, introduce text-only plan, resume migrated work, run the complete 0073 fixture corpus, transfer/drain all legacy owners, and delete the legacy composer only after its retirement gate.
S3 — every source through plan. Add file, image, issue and thread adapters plus standalone plan/revision, all ending in the same validator, pin and publication path.
After S1 there is one loader in every mode: (planId,digest) from PlanStore.
The temporary legacy composer may read only migrated graph state belonging to already-resumable instances. It receives the same immutable pin and normalized fact snapshot as the orchestrator. New PlanRefs are orchestrator-owned and never compile sequencing reasons into dependency edges.
plane.shipReconcile: off|shadow|on selects one active composer. Shadow has read-only ports. A composer transfer waits for the current deterministic machine act to return and atomically advances relation sequence, composer epoch and owner generation with the parent’s tagged {child|wait|ending} relation and live state.
S2 retires the composer only after every fallback-only fixture is represented by a typed orchestrator act and the durable inventory reports zero legacy owners, zero dual owners and zero unknown rows requiring graph semantics.
S1 and S2 must both be merge-ready before S1 reaches production.
Deploy with admission and resume closed; inventory and pin; publish/adopt parents; attach URLs; verify cardinality and migration completeness; then resume migrated work under the composer rollout.
S2 may require a retirement follow-up after live shadow evidence. S3 cannot begin until the legacy composer is deleted.
No previous binary is promised after pin-only rows are admitted. Rollback then means close admission and forward-recover, not restore a deleted loader.
No new repository plan file.
Completion
Exactly one executable plan loader remains.
Exactly one composer remains after S2.
Every 0073 ending, wait, ownership and recovery fixture passes through real durable adapters.
Every fresh source accepted after S3 goes through plan.
code is the only live core name after S4.
Automerge defaults off and cannot bypass current actor, head, verdict, checks, repository rules or the merge door.
Implement accepted decision records 0073 and 0077 as one external work stream. Replace repository-seeded and generated execution inputs with canonical pinned plans, preserve the deterministic unit machine, and retire the executable graph only after the accepted 0073 shadow/fixture/ownership gates pass.
No implementation plan belongs under
docs/plans/.Authority
5eb4fd40f81ae86e84749ffd9bed0fe79484cf6f. Its maintainer-authorized acceptance gate is the five-question receipt; there is no broader acceptance hold.docs/plans/2026-09-21-002-feat-the-ship-pipeline-dissolves-into-the-orchestrator-plan.mdis bootstrap input imported once, not a continuing repository execution address.One execution contract
PlanArtifactis pinned immutably under(planId,digest)in the coordinator store.PlanRef{planId,digest,providerUrl}and loads exact pinned bytes. GitHub is a human projection, never an execution loader or digest source.Independent repository facts
Do not replace #2238 with another repository-ranking rule. Carry these independently:
RequestContext: inherited workspace/default for unqualified material.OperationTarget: typed repository, pull request or plan unit acted on.PublicationDestination: destination for each provider effect.EvidenceReference[]: cited repositories/issues/pull requests/files with no target or write authority.Required examples:
in owner/a: review owner/b#5in owner/a: implement owner/b#5Ambiguous roles ask or refuse before write identity. Citation order, thread recency and repository ranking never decide an operation target.
Prerequisite order
Required 0077 amendment before S2 admission
The accepted delivery list says S2 admits direct tasks while S3 introduces
plan. To preserve direct-task behavior without restoring generated execution, amend only the slice boundary:plancontract needed for fresh direct tasks.No architecture, artifact, authority or loader rule changes. Until that amendment is accepted, fresh direct-task admission remains an owner decision, not an inferred requirement.
Slices
plan, resume migrated work, run the complete 0073 fixture corpus, transfer/drain all legacy owners, and delete the legacy composer only after its retirement gate.codingvalues tocodeonce and add default-off globalship.automerge, bounded by the initiating actor’s current authority and review: re-run the review when a reviewed PR's head changes, with one update message, configurable per repo; branch protection as an optional layer #2145/review: one ask spawns two runs whose verdicts disagree, and the LGTM twin auto-approves #2244.Composer versus loader
After S1 there is one loader in every mode:
(planId,digest)fromPlanStore.The temporary legacy composer may read only migrated graph state belonging to already-resumable instances. It receives the same immutable pin and normalized fact snapshot as the orchestrator. New PlanRefs are orchestrator-owned and never compile sequencing reasons into dependency edges.
plane.shipReconcile: off|shadow|onselects one active composer. Shadow has read-only ports. A composer transfer waits for the current deterministic machine act to return and atomically advances relation sequence, composer epoch and owner generation with the parent’s tagged{child|wait|ending}relation and live state.S2 retires the composer only after every fallback-only fixture is represented by a typed orchestrator act and the durable inventory reports zero legacy owners, zero dual owners and zero unknown rows requiring graph semantics.
Incident mapping
writesDecisionRecord; reservation before child admission.salvagelabel.pr_opened.Release boundary
Completion
plan.codeis the only live core name after S4.