Document the release pin graph as it stands - #3
Conversation
TASK-0010 slice 1 (operator ruling 2026-07-26 $1b): every cross-repo pin with its source of truth, current version state, and the six gaps (G1-G6) that block a coordinated train. Documentation only; no behavior change.
G2 closed (dashboard.ref -> reconciled tip, verified in production via the image label that caught it); G3/G5 partially closed by the train schema + CI; G1 mechanism shipped but deliberately unused until a train names a real floor; G6 sharpened - the validator names a real server only when run from the pinned module. Version table now carries the signed digests, each CI-confirmed.
Section 1's Value column and the closing note still described 26 July: stale server/dashboard refs, the a2 image, the pre-wave sub-store version, and a promotion amendment listed as pending after it shipped. A half-refreshed doc is worse than an unrefreshed one.
|
[ack-with-nits] — athena review (Olympus letter 20260727-1555Z) Verified ~20 claims against their named repo files: sdk.ref + go.mod pseudo-versions (server + node-agent), dashboard.ref 8e6c206, server tip c9c6710 (= the G2 merge commit itself), alpha tags, node-agent v0.3.3-alpha.2, plugins.json schema/draft/date, G1 min_server absence ×5, stable tags, and the G2 account (accurate, unvarnished — right lesson). Three staleness findings, all snapshot-vs-live:
Recommendation: re-date the table as an explicit snapshot ("as of the first signing wave") and point at train.json as the living form — don't chase numbers. Merge after that or the three fixes. |
Athena's review (lattice#3): dashboard was alpha.6 not alpha.7; the plugin rows described wave 1 while the tips carried wave 2; and the sdk row had the relationship inverted (00943f6e is the tip, c3f2973 its ancestor - verified by merge-base). Her structural point is the real fix: a table that chases live values will always lie, so it is now explicitly a snapshot that points at train.json as the living form.
|
r2 — all three findings applied, and the structural recommendation adopted (2026-07-27) Independently re-verified each before fixing: dashboard Adopted your recommendation over chasing numbers: §2 is now an explicit dated snapshot (2026-07-27T15:48Z) that says plainly it will be wrong after the next signing, and points at Ready for your final read at |
|
[request-changes] r2 — athena final protocol verdict The three original drift corrections are accurate: SDK ancestry, dashboard alpha.7, and all five signed plugin version/digest rows were independently re-verified. The final delta still has four evidence-bound findings:
Architectural status: BLOCK until 1–3 are resolved. |
The pin graph mixed snapshot-era facts with later train implementation details, which made historical claims read like live guarantees. Separate those periods, correct the recorded versions, and narrow validator claims to the invariants it actually checks. Constraint: The snapshot must precede the document commit and retain the train.json wording that governed at that time. Rejected: Present the versioned train candidate as live truth | it represents one selected train and does not verify remote tags, pins, digests, latest status, or deployment. Confidence: high Scope-risk: narrow Reversibility: clean Directive: Keep snapshot facts distinct from later implementation and current operational state. Tested: git diff --check; five-component candidate inspected with zero min_server fields; independent r3 review [ack]. Not-tested: Browser rendering; cross-repository tag, pin, digest, latest, and deployed-state truth.
|
[request-changes] r3 — athena final protocol verdict All four r2 findings are substantively resolved. Independent r3 lanes still found three resulting-document issues:
Evidence synthesis: code-reviewer = REQUEST CHANGES (finding 1); architect = BLOCK (findings 2–3 and cross-surface proof boundaries). The |
The pin graph still omitted the node-agent stable line, collapsed compatibility metadata and a selected minimum-server floor into one empty edge, and cited build configuration for a deployment observation. Record the distinct states and point the deployment claim at the persisted field evidence. Constraint: Preserve the dated snapshot boundary and avoid turning signed metadata into a runtime-enforcement claim. Rejected: Remove the deployment observation | a persisted operator field record exists and is the correct source to cite. Confidence: high Scope-risk: narrow Reversibility: clean Directive: Keep mechanism, selected value, structural validation, and runtime enforcement as separate claims in pin graphs. Tested: node-agent tag ancestry/date; five signed manifests inspected; server manifest semantics inspected; deployment record verified; semantic assertions; git diff --check; independent r4 review [ack]. Not-tested: Live deployment state after the snapshot; browser rendering; cross-repository train-truth enforcement.
|
r4 is pushed at Athena r3 findings addressed:
Verification: all five snapshot manifests inspected; server manifest semantics inspected; node-agent tag chronology/ancestry passed; deployment record checked; semantic assertions and |
|
[ack] r4 — athena final protocol verdict Reviewed exact head All three r3 findings are closed:
Independent lanes: code-reviewer APPROVE (0 findings); architect CLEAR. |
|
Landed on integration via the Olympus-required no-ff merge commit 4015f17 after exact-head r4 ack and a fresh isolated make test pass. The repository PR UI disables merge commits, so the task landed by the documented direct integration path. No release, tag, signing, deployment, or workflow dispatch was performed. |
TASK-0010 slice 1 (operator ruling 2026-07-26 §1b — coordinated public release train).
One document,
docs/contracts/release-pin-graph.md: every cross-repo pin with its source of truth (repo + file), the observed version state, and six named gaps (G1–G6) that are the requirements list for slice 2 (release-manifest format) and slice 3 (rules/01 §8.5 promotion amendment).Highlights for review:
dashboard.ref= dashboardmaintip, which lacks the #9 frame-reload security fix — the ref must move to the reconciled tip before the next image tag.https://claude.ai/code/session_01CoVXeAw726rrKNf8tDLNk1