Skip to content

U2b: atomic dual-identity link transaction and intent store #2386

Description

@justinhelmer

Parent: #2371. Depends on human-merged decision prerequisite #2383 (proposed record 0081). This is the first implementation slice of U2 and remains disabled from ingress.

Deliverable: extend the PersonDirectory seam with one authoritative transaction that consumes a durable, one-time link intent; chooses or creates exactly one person; binds the verified Access and Slack identity tuples; and commits binding receipts plus a separate operation outcome/audit together. Supply in-memory and SQLite implementations with the same observable behavior. The existing one-binding change() calls cannot be composed with compensation for this ceremony.

Contract: an expiring intent is bound to the initiating authenticated actor/browser and expected proof/identity revisions. Its state transitions and callback claim are durable and replay-safe across restart. The commit checks the unconsumed intent, deadline, consent, both current binding revisions and uniqueness in one storage transaction. Concurrent intents serialize; response loss returns the original receipt only to the original initiator; no callback code/token is persisted. Identity movement between people, automatic merge and ordinary reactivation of tombstones are refused.

Proof: update the living spec first. Tests for two unknown identities; one known; already linked same person; two different people; revoked identity; stale revision; concurrent commits; duplicate/expired intent; crash at callback claim and after commit; audit-write failure; restart and response-lost retry. In every failure, no orphan person, half-link or authorization side effect. Test both store implementations. Changed-set tests and relevant scoped checks before review.

Boundary: no public link/unlink endpoint, OAuth configuration, production credential/scope, FE entry point, email-bridge cutover or new person-based authorization in this slice. Those are separate U2 implementation gates.

Activity

  1. justinhelmer commented on Sep 26, 2026

    @justinhelmer
    ContributorAuthor

    Execution admitted in the configured Slack channel: https://coreplanelabs.slack.com/archives/C0BRRHKFLCB/p1790385706364909 . Parent Ship run 26934cac-6567-44bd-b9fc-8b4700ab4c73; unit plan-implement-issue-2386-as-bcfcc3:U1; bound branch plan/implement-issue-2386-as-bcfcc3/u1. PR #2385 was merged before kickoff. This unit owns only the disabled atomic intent/directory foundation; no live linking, OAuth, FE or email-bridge changes. Project status In Progress. Next gate: coding PR, scoped checks, exact-head review and CI.

  2. coreplane-switchboard commented on Sep 26, 2026

    @coreplane-switchboard
    Contributor

    U1 ownership check: rebased the bound runner branch onto current main (c45b622f). Open PRs #2384, #2380, #2379, #2357, #2347, #2345 and all 165 paths in #1625 do not overlap the intended change: src/core/identity/{contract,memory,sqlite}.ts, new link-intent contract/engine/tests beside them, and docs/reference/specs/person-directory.md. Reserving this disabled directory/intent slice here; no channel, OAuth, frontend, configuration, authorization consumer or email-bridge files will change. Record 0081 remains proposed. Parent Ship must supply independent exact-head review after publication; this coding run will not self-approve.

  3. coreplane-switchboard commented on Sep 26, 2026

    @coreplane-switchboard
    Contributor

    Coding slice pushed at exact head 88cddaeb966bfafc4e0d936b1d36de028e6f0ceb on plan/implement-issue-2386-as-bcfcc3/u1, rebased onto main 45ff7fda immediately before push. PR description submitted to the runner. 51 identity tests pass, including real SQLite restart and independent-process contention; scoped types, lint, formatting, hygiene, spec references/coverage/test guard, docs and decision checks pass. Live ingress/linking, OAuth, FE, production configuration and the email bridge are untouched; record 0081 remains proposed.

    Parent Ship handoff: run independent strict review and full CI at that exact head after the coding post-step publishes the PR. GitHub currently reports no PR and no check runs for this head (combined status pending with no statuses); I cannot truthfully label it merge-ready yet. No self-approval or merge was performed. Cross-model review was skipped in this non-interactive coding child.

  4. justinhelmer commented on Sep 26, 2026

    @justinhelmer
    ContributorAuthor

    PR #2389 opened at 88cddaeb; initial CI passed, but independent review requested two replay fixes (revision/consent guard and historical receipt validation). The bound fix child was interrupted by a provider/setup failure before a new push, and its parent Ship run ended failed. Plane automatically reissued coding continuation ac910d71-5989-4108-80e4-5670c74d107a on the same Slack thread; it is active against the original PR branch. The PR is blocked at its original head. No second U2b writer or merge has been started. I will verify the continuation's exact head, fresh review and CI, or record a controlled recovery if it cannot publish.

  5. justinhelmer commented on Sep 26, 2026

    @justinhelmer
    ContributorAuthor

    PR #2389 is merge-ready at exact head 4d9aa1400098239383887c171f8ee3d33bdf4a18. First review at 88cddaeb requested F1/F2 replay fixes; the original fix child was interrupted by provider/setup failure, and plane continuation ac910d71-5989-4108-80e4-5670c74d107a pushed both fixes on the same PR branch. A fresh independent agent:review <PR URL> run 78cb2eb8-6d39-4506-bac1-5c2547a23d1d posted LGTM at 4d9aa140 with no findings. All required CI checks pass; GitHub reports APPROVED and CLEAN. Restored the PR's fixed-size body with the repo's PrDescription renderer from the continuation's submitted object after the runner fallback. The change is disabled storage/intent plumbing only; no live linking, OAuth, FE, authorization consumer, production config or email-bridge change. A person merges under AGENTS.md. Next U2 slice #2387 is Todo.

  6. justinhelmer commented on Sep 26, 2026

    @justinhelmer
    ContributorAuthor

    Merged in #2389 at caa2887. The atomic dual-identity link and intent store is covered by memory and SQLite transaction tests and the updated spec. Independent review approved the final head (4d9aa14); required checks passed. This is storage plumbing only: no live linking, ingress, UI, or authorization consumer was enabled. Next: #2387 proves Access and Slack human identity before wiring a consent flow.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions