Skip to content

Implement one pinned-plan orchestration stream (0073 + 0077) #2290

Description

@justinhelmer

Implement accepted decision records 0073 and 0077 as one external work stream. Replace repository-seeded and generated execution inputs with canonical pinned plans, preserve the deterministic unit machine, and retire the executable graph only after the accepted 0073 shadow/fixture/ownership gates pass.

No implementation plan belongs under docs/plans/.

Authority

  • Decision 0073 is accepted and owns orchestration, parent cardinality, composer fencing, durable adoption and retirement of the graph composer.
  • Decision 0077 is accepted at 5eb4fd40f81ae86e84749ffd9bed0fe79484cf6f. Its maintainer-authorized acceptance gate is the five-question receipt; there is no broader acceptance hold.
  • docs/plans/2026-09-21-002-feat-the-ship-pipeline-dissolves-into-the-orchestrator-plan.md is bootstrap input imported once, not a continuing repository execution address.

One execution contract

  • A validated PlanArtifact is pinned immutably under (planId,digest) in the coordinator store.
  • Canonicalization sorts object keys, preserves array order, rejects duplicate source/unit IDs and non-canonical numbers, and hashes the exact UTF-8 bytes with SHA-256.
  • Execution accepts only PlanRef{planId,digest,providerUrl} and loads exact pinned bytes. GitHub is a human projection, never an execution loader or digest source.
  • Mutable publication metadata is stored separately from canonical bytes.
  • Every source and unit has a stable typed identity. Model-authored prose cannot populate execution identity, authority, operation targets or publication destinations.
  • The existing deterministic unit machine retains leases, one owner, code → review → fix → checks → merge, rebase-before-push, changed-set gates, work preservation, reviewed-head equality, checks, authorization, confirmation and the merge door.

Independent repository facts

Do not replace #2238 with another repository-ranking rule. Carry these independently:

  • RequestContext: inherited workspace/default for unqualified material.
  • OperationTarget: typed repository, pull request or plan unit acted on.
  • PublicationDestination: destination for each provider effect.
  • EvidenceReference[]: cited repositories/issues/pull requests/files with no target or write authority.

Required examples:

Ask Context Operation target Publication
in owner/a: review owner/b#5 A B#5 verdict on B#5
in owner/a: implement owner/b#5 A A; B#5 is evidence branch/PR in A
review B#5, implement findings in A A review B#5; code A verdict B#5; PR A
cross-repository plan request context each unit’s typed target parent in configured planning repo; unit issue/PR in target repo

Ambiguous roles ask or refuse before write identity. Citation order, thread recency and repository ranking never decide an operation target.

Prerequisite order

Required 0077 amendment before S2 admission

The accepted delivery list says S2 admits direct tasks while S3 introduces plan. To preserve direct-task behavior without restoring generated execution, amend only the slice boundary:

  • S2 introduces the text-only plan contract needed for fresh direct tasks.
  • S3 extends that same contract to files, images, issues and threads and adds standalone/revision behavior.

No architecture, artifact, authority or loader rule changes. Until that amendment is accepted, fresh direct-task admission remains an owner decision, not an inferred requirement.

Slices

  1. S1 — canonical pins and one loader, dark. Add artifact validation, canonical pinning, complete migration inventory and the fenced off/shadow/on composer seam. Migrate every resumable generated/repository-seeded pipeline and the bootstrap plan. Delete both old loaders. Start or resume no code.
  2. S2 — publication, text planning and 0073 retirement. Publish/adopt the required parent URL, form complete PlanRefs, introduce text-only plan, resume migrated work, run the complete 0073 fixture corpus, transfer/drain all legacy owners, and delete the legacy composer only after its retirement gate.
  3. S3 — every source through plan. Add file, image, issue and thread adapters plus standalone plan/revision, all ending in the same validator, pin and publication path.
  4. S4 — rename and merge policy. Rewrite persisted coding values to code once and add default-off global ship.automerge, bounded by the initiating actor’s current authority and review: re-run the review when a reviewed PR's head changes, with one update message, configurable per repo; branch protection as an optional layer #2145/review: one ask spawns two runs whose verdicts disagree, and the LGTM twin auto-approves #2244.

Composer versus loader

After S1 there is one loader in every mode: (planId,digest) from PlanStore.

The temporary legacy composer may read only migrated graph state belonging to already-resumable instances. It receives the same immutable pin and normalized fact snapshot as the orchestrator. New PlanRefs are orchestrator-owned and never compile sequencing reasons into dependency edges.

plane.shipReconcile: off|shadow|on selects one active composer. Shadow has read-only ports. A composer transfer waits for the current deterministic machine act to return and atomically advances relation sequence, composer epoch and owner generation with the parent’s tagged {child|wait|ending} relation and live state.

S2 retires the composer only after every fallback-only fixture is represented by a typed orchestrator act and the durable inventory reports zero legacy owners, zero dual owners and zero unknown rows requiring graph semantics.

Incident mapping

Release boundary

  • S1 and S2 must both be merge-ready before S1 reaches production.
  • Deploy with admission and resume closed; inventory and pin; publish/adopt parents; attach URLs; verify cardinality and migration completeness; then resume migrated work under the composer rollout.
  • S2 may require a retirement follow-up after live shadow evidence. S3 cannot begin until the legacy composer is deleted.
  • No previous binary is promised after pin-only rows are admitted. Rollback then means close admission and forward-recover, not restore a deleted loader.
  • No new repository plan file.

Completion

  • Exactly one executable plan loader remains.
  • Exactly one composer remains after S2.
  • Every 0073 ending, wait, ownership and recovery fixture passes through real durable adapters.
  • Every fresh source accepted after S3 goes through plan.
  • code is the only live core name after S4.
  • Automerge defaults off and cannot bypass current actor, head, verdict, checks, repository rules or the merge door.

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions