Skip to content

feat(reporting)!: enable production tier status and ownership - #1192

Merged
bokelley merged 7 commits into
mainfrom
conductor/reporting-production-tier-capabilities-b24
Sep 25, 2026
Merged

bokelley merged 7 commits into
mainfrom
conductor/reporting-production-tier-capabilities-b24

Conversation

@bokelley

@bokelley bokelley commented Sep 19, 2026 •

Copy link
Copy Markdown
Contributor

Production reporting now composes the integrated durable ledger, materializer, receipts and frozen feed with captured status, account activation and guarded tier capabilities. This replaces the original stacked base with actual integrated main, preserves both histories, and corrects two composition problems: a readable snapshot could prematurely retire policy-controlled acquisition, and the original forecast implementation used the rc.3 due-time rule under the current rc.6 wire contract.

This is source integration and scoped conformance evidence. It does not authorize deployment, production activation, a package release, TypeScript acceptance or #1199 acceptance. #1172's remaining delivery/outbox/lease work stays separate.

Exact source and history

  • Candidate head: decfb4eb53845c22b019466b4167293f6c6181c7, tree 2dd33404cb50e6d87ae875ccfa1c983e7faabd44.
  • Integrated base: e16eb8cf3074cabd45aab42840950f05ad6d2b43 (PR1191).
  • Composition: 800333557300cf75d68599c7ed05e5d5b2853f90, ordered parents [e3a44d281d019ebf6aec738c2cfe18f8bba97462, e16eb8cf3074cabd45aab42840950f05ad6d2b43]. Strict corrective chain: the candidate -> e9a1c8fcb653870bddef486b56e76820f467c231 -> bb2921619762175adcc101ca09c74bd52cc196a8 -> 8b2418a542341f804f75beb0c1817dc080c02987 -> composition, each with one parent. No rewriting, squash or force push.
  • Original feature chain: e3a44d28 -> 614d513c -> a09878f6. Its 106 paths remain present; eleven additional integration/control paths bring the PR to 117 paths. The two newest paths are MCP tool construction and its regression controls. Full delta: 117 files changed, 21827 insertions(+), 356 deletions(-), SHA256 b4cd27e94803852537679a79c1a4a86591172ea16c7356945f8fcf275054ca88.
  • Corrective composition-to-head delta: 46 files changed, 1904 insertions(+), 261 deletions(-), SHA256 4869224b468338d63adfe7fa79df218119869d0298e604657c70e537b02b5d4a. Hashes use git diff --binary --abbrev=8.

The original body and original feature results are retained as historical evidence. They are not relabelled as execution of this head.

Production behavior and integration corrections

The original feature adds a production composition over the actual durable components, private versioned status capture, a bounded producer queue, account activation, immutable retry windows and checks of the real mounted dispatch tables. Managed and reconciled claims require the applicable source/provider/readback/receipt components. The memory implementation never advertises production durability. Epoch-zero effects retain their old identities and permanent quarantine; activation does not promote old readiness events.

The seven composition conflict resolutions preserve main's split PG lanes and strict aggregate, settling policy and receipt diagnostics, rc.6 waiver integration, current generated model provenance, and fail-closed schema resolution. Feature ownership/projection/default-omission changes remain present. Server mount integration registers production proofs after the existing MCP/A2A dispatch maps are installed. The newest append also avoids copying current-model schemas that pinned MCP definitions replace; listener, socket, wildcard and auth functions are unchanged.

Settling with durable progress. A readable snapshot completes one acquisition, not an ongoing settling policy. Policy-controlled work remains in the rotating pending queue through cadence checks, restatements and the official-close lag. A not-ready official attempt does not retire it; the producer verifies a committed official revision before finishing. Snapshot-only policies retire when their settling window ends. Existing corruption parking and non-policy behavior remain. New memory/PG controls cover these boundaries and restart with a fresh service/store.

Current rc.6 forecast and frozen boundaries. A complete summary reports the nearest future period start strictly after the captured ledger_as_of; open summaries retain the obligation-due forecast. The summary forecast does not leak into complete periods responses or create future work. Current mounts advertise and render their captured supported protocol pin, and changing that pin invalidates readiness even after a warm schema proof. Historical rc.3 stored/direct projections preserve their original bytes and semantics; this SDK does not advertise rc.3 as a live client/server version. Current SDK version declarations and all immutable caches are unchanged.

These bounded forecast changes are pulled forward from the future #1193 source, adapted to rc.6 and integrated with main's corrections. They do not qualify the whole of #1193. Signed continuation checks authenticate caller, token and position before reporting a version mismatch. Integrated parents created representation-one walks without protocol markers; those retain their exact pages and checkpoints under rc.6 before and after activation. The narrow compatibility rule requires representation one, absent ownership, no stored marker and equality of every original filter. Newer/version-bound representations still reject mismatched pins. The unchanged installed-parent rolling test remains mandatory. Main's retained cursor lower bound, conservative fallback replay, exact waiver bindings and safe receipt diagnostics remain intact. New projection controls establish waiver recovery and a new occurrence for a later conflicting statement while preserving the terminal waiver row.

Operational assertions. Seventy-five existing-feature operations across 18 files move outside assertions: 72 outer-await forms and three whole-predicate assignments. The latter preserve all operands and short circuit within the unchanged expression. Adjacent inverse-AST reconstruction preserves complete original modules, including constants. Twenty-two native assignment/assert pairs across four new control files are not historical hoists; the earlier seven/two figure was a first-stage subset. No embedded-source edits; cancellation joins and pure expected-value reads remain.

Catalog, workflow and installed boundaries

Main's B464, C249, selector10, materializer187, receipts102 and feed33 manifests are byte-identical. Feature projection317 and production331 manifests are byte-identical to the original feature. All 1,693 objects were measured exactly on C, libc en_US.utf8 and ICU databases. No fingerprint regeneration, catalog tolerance or corrective SQL/cache edit.

CI expands 23 job keys to 31 jobs. The retained required PG check depends on all 11 result components, including the production installed matrix, and rejects anything other than exact success for every result. It retains always(), the required name and permissions: {}. The new production jobs declare contents: read.

Native production uses shell arrays with nullglob, explicit nonempty checks and quoted expansion. Rolling/packaging paths are removed before pytest receives explicit arguments. The four installed cells are base/PG x VCS/sdist; compatibility is separate. The original feature's budgets remain native 35m/job and 30m/step, installed 40m/35m, compatibility 50m/42m. Existing lane budgets are unchanged. The new exact integrated B2.3/hardening baseline fetch is bounded to one minute. Obsolete C-only service flags were removed after independent catalog checks across all three collations.

Actual URL-present collection of the workflow commands gives a disjoint union of 4421 cases: core2020, process7, status251, materializer47, receipts724, receipt-compatibility8, feed375, feed-compatibility9, feed-installed13, production955, production-compatibility8, plus four installed outer cells. Collection is not execution. Empty native selection exits 1 instead of falling through to full-tree discovery.

The production installed runner binds current module, asset and rc.6 schema bytes to the installed distribution, with Python3.10 origins outside the source workspace. Historical rc.3 rejection controls receive an explicit copied test-reference bundle, with all 1,612 JSON hashes verified before and after the run. Its origin is outside both the installed prefix and source workspace and is recorded separately: it is not shipped SDK content or restored protocol-version support. Existing source-layout resolution reads those test inputs without a resolver patch. The installed current-bundle key must match the packaged SDK pin. Closed phase records now survive preflight failures without exposing arbitrary child stderr. The eight frozen controls use integrated B2.3 2d777ace / tree 2f71a273 and hardening e16eb8cf / tree c043d1e1. Complete newly built installed/frozen controls were not run locally because of disk limits; new-head CI must establish them and whole-job lifecycles. The completed e9 installed evidence is historical and remains separately attributed below. A retained original CI base-VCS wheel was installed locally to diagnose and check the private test-fixture correction, as separately recorded below. Historical installed or old-head results supply no credit.

Corrections after original bb29216 CI

The original attempt remains failed and sealed separately; no results transfer to this append. All four installed production probes stopped before their inner result. Independently, the retained wheel ships rc.6 while the test expected rc.3 inside that distribution. The original child stderr was redacted and remains unavailable; a root reproduction against the authenticated retained CI wheel independently establishes the absent-reference lookup. The first local environment was under a checkout and found its source-layout fallback, so it was discarded as an isolation diagnostic and repeated outside all checkouts.

Supplying the explicit historical test reference exposed fourteen old due-time expectations under the new rc.6 default. Original Python3.13 independently failed those fourteen cases, and the native production job failed twenty-eight including PostgreSQL variants. The correction preserves every original activation/due boundary under explicit rc.3 and adds rc.6 next-start expectations; all sixty additional cases retain obligation, coverage, caller and captured-state assertions. The bb-to-e9 test-only append changed no SDK logic, schema cache, manifests, workflow selection or timeout. The later performance append below is separately scoped.

Four valid quality findings are also corrected: the normalization pop now runs outside its assertion, and three SQL string pairs are parenthesized without splitting statements. The other six findings were source-adjudicated with independently confirmed grounds and separately retained reply/resolution receipts.

Original bb29216 guard seal bdf97d418b1592afdbc63854b22fcfffb88fff79deb7d93094536b4f7c7bf084 remains NOT_READY_ORDINARY_GATES. Original CI36075951408 attempt1 completed 31 jobs: 21 success, 7 failure and 3 strategy cancellations. The seven failures are Python3.13, native production, four installed production cells and the strict aggregate; no failure or cancellation is waived or transferred.

Private corrective validation: authenticated retained CI base-VCS wheel, Python3.10.21 outside all checkouts: 633 passed, 321 intended driver-absent skips, one existing deselection, zero failures/errors and strict adopter exit0; 954 selected inner cases. Focused PostgreSQL schedule/migration tests: 144 passed, zero skipped in77.35s, against unchanged published SDK source. All four final executed test-file hashes equal the e9 test append and are unchanged at the current head. No new wheel was built and these are not VCS/sdist or fresh child CI acceptance. These are root observations with exact executed-file hashes, not fresh child CI or release acceptance. Corrupted current-schema and historical-reference digest controls both fail before conformance. The first retained-wheel run remains fourteen failed/589 passed/291 intended skips/one deselected, with a successful strict adopter check; the runner process exiting zero did not make its JSON result valid.

Performance correction after exact-e9 coverage timeout

Original e9 CI36079099440 attempt1 remains terminal FAILURE: 31 jobs, 30 success and one failure. Python3.12 job107896795010 reached the unchanged 45-minute coverage-step timeout with no terminal pytest summary. Its raw log SHA256 is e6a5b06cae010f000c675c7f9d24d02f4857014ecb067af5aab40eaa83828d51; guard seal a6875f99b51c7de1257c11694f3be9aa9bbd5289d359e28cbba9de9905f829eb stays NOT_READY_ORDINARY_GATES. Partial Python3.12 output supplies no suite acceptance. The other 30 successful jobs, including production955, compatibility8 and all four installed routes, remain evidence for e9 only. Those installed routes had base633/321 intended skips or PG954/0 skips, each one existing deselection and strict adopter0; their downloaded artifacts remain separately authenticated. Neither the e9 approval nor any execution transfers to this child.

The new sole-parent append decfb4eb53845c22b019466b4167293f6c6181c7 is exactly 3 files changed, 357 insertions(+), 30 deletions(-); patch SHA256 68cf342fa9f002c0fa3bf72b1cfc69aa1d97bb89a69ff99db2cf016c08907861. It removes repeated public-schema work instead of changing execution ceilings. get_mcp_schema now retains successful compact JSON per immutable versioned loader/tool/direction, with a lock preventing duplicate concurrent first materialization. Each return decodes a fresh tree, so callers share neither mutable branches nor cross-version cache entries. Failures/missing schemas are not cached, and loader reset discards materializations. Pinned tool construction deep-copies retained metadata only, avoiding current-model input/output schemas that are immediately replaced. Current-model fallback and all version validation remain unchanged.

Only those two performance portions are brought forward from published #1193 head 1f953c40d761be71d11fde84c78359ff2074fe7c; the changed class/functions are AST-identical to that donor. The donor's separate mount-version policy, signed release adoption, lease work, packaging and catalog changes are not part of this append. No reporting module, SQL, manifest, schema cache, version table, workflow or dependency file changes. All four workflows are byte-identical to e9: 31 jobs, strict eleven-result PG gate, Python60-minute job/45-minute coverage step and global80% coverage threshold remain.

Thirteen new regression cases cover per-version first materialization, returned-tree and repeated-branch isolation, reset, failed-proof retry, eight concurrent first callers, avoiding discarded-schema copies, current-model fallback, unsupported versions, and mounted MCP/A2A validation. Three public-fixture canonical JSON digests were captured on unchanged e9 before editing source. The regression golden values preserve that fixture's rc.3/rc.6/beta.6 outputs; this is canonical JSON value equivalence, not raw signed-schema byte identity or an all-tool inventory claim. No existing test is removed, skipped or relaxed.

Root local evidence: four intended control failures on unchanged e9 before source edits; the final six-file focused run passed145 with17 PostgreSQL skips (no database URL) and13 warnings in143.39s. Source type checks and normal commit hooks pass. A separate covered subset also passed145/17 at the test level but correctly exited1 because33.92% project coverage is below the unchanged80% global threshold; it is retained as a failed scoped coverage invocation. Local repeated discovery under Python3.12 coverage changed rc.6 warm samples from about0.67s to0.011s while preserving the fixture's canonical JSON. Reference-graph materializations across three calls fell18 to6 for each rc.3/rc.6 pin and12 to4 for beta.6. Cold latency is not claimed improved; this is neither a whole-suite speedup claim nor proof that CI fits45 minutes. New exact-head full CI remains mandatory.

The separate historical-reference resolver not-none diagnostic nit remains a named #1193 harness follow-up; missing reference still fails closed with its phase recorded. It is not included in this performance change.

Historical local validation and limits

Root-owned private working-tree runs retain source hashes, raw logs, JUnit and task-owned PostgreSQL cleanup:

  • Unchanged settling composition: 4 expected failures; corrected settling plus existing controls: 9 passed. Fresh-service restart: 2 passed.
  • Unchanged rc.6 forecast: 4 expected failures. Corrected forecast/schema/public transport controls: 74 passed, 4 retained warnings.
  • Existing capability/service/wire-default/incremental controls: 55 passed. Existing ledger tests: 79 passed.
  • Exact-scope waiver projection in the permanent test file: 4 passed across memory/PG and notification modes.
  • Physical catalogs: exact 1,693/1,693 on each of C/libc/ICU. Generated default-repair code is idempotent on copies of both actual rc.6 layouts.
  • Four legacy-format controls failed on the first private correction at the new version mismatch. The appended compatibility correction is checked with native feed-position and current-version controls: 70 passed; separate unchanged-source negative retained. These format controls do not stand in for the actual installed-parent rolling lane.
  • The 887-case native selection reached its separate 900-second local ceiling (exit124, 900.117s). It printed 175 passing markers before interruption, with no terminal pytest summary. This is incomplete, not a native-suite pass. All recorded start source hashes were unchanged at termination; task-owned PG clients drained and the database/cluster were removed. The subsequently added four waiver cases passed separately. Full native execution remains a fresh-CI requirement.
  • Normal black, ruff, SDK/adopter mypy, no-ignore contract, Bandit and commit hooks passed. The first corrective commit 8b2418a5 settling/forecast/schema run passed 85 cases without skips; it is distinct from all earlier working-tree runs and the appended legacy-continuation controls.

An early settling fixture setup error, the first forecast integration attempt (54 failures from incomplete fixture/version/error-code integration), and all unchanged-source negative controls remain retained. No failed attempt is converted into a pass. The later corrected result is separate. These local runs do not prove remote job lifecycles or release readiness.

Fresh exact-head secret scan: Gitleaks 8.30.1, report SHA256 d6557b1f230bd93d6d2d85aaa8a4ed35ae0eca30651a76f004e7c5059eff095c. Complete current-file scan: 117 files/2886588 bytes; complete 7-commit merge-parent scan: 147501967 added bytes. All 86 matches source-adjudicated against exact current Git objects (4 code keyword expressions, 68 schema example identifiers, 13 patterned documentation credentials, 1 recomputed file digest); zero unadjudicated/private-credential matches. Fresh large positive and negative controls passed. An outdated local adjudicator lacked the existing keyword-expression case and stopped after both scans completed; its stop and original outputs are retained, and the corrected source proof was applied to those same findings without rerunning either scan or changing rules. Pattern detection is not a universal absence proof. Actual GitGuardian/CodeQL output and root policy remain separate; a neutral scan is never described as success, and no prior scan or approval transfers.

Carry-forwards

All eight rolling release-note boundaries remain explicit: no qualification of snapshots before 17ee407a (A), 0f34c666 (B), 967b6e28 (C), 5487f2bd (B1), 3fd62121 (B2.1), 09fd87f7 (B2.2), 2d777ace (B2.3), or e16eb8cf (hardening). The original A whole-trigger readiness after C remains unsupported; retained false readiness values are not healthy-startup claims.

9rLB's whole-catalog source mitigation is attributed to merged PR1191 only; it is not an under-load closure and dynamic/per-account work remains. The inherited F-SX fail-closed pagination limitation carries no snapshot-retention promise. The documented wildcard bind with optional auth and five Bandit B104 suppressions remains an inherited exposure; this PR adds no bind/listener/auth change. Translator's prior PARTIAL 8-pass/47-skip result is not full interoperability acceptance.

No #1172/#1199/TS/artifact/release/activation closure, no retroactive alteration of prior seals. Guard PR1201 stays draft and LAST; legacy workflow204238826 remains disabled.

Refs #1167, #1179, #1180.

B2.4 of 4 completing B2 of B1/B2: versioned captured status, private
ownership, production component admission, and atomic notification delivery.
Preserve historical artifacts and separate final-head validation from
development controls. Independent review and downstream gates remain open.
Comment thread src/adcp/validation/schema_loader.py
Comment thread src/adcp/reporting/production/service.py
Comment thread src/adcp/reporting/production/service.py

@aao-secretariat aao-secretariat Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ladon verdict: Request changes

Request changes — 1 blocking finding.

Blocking findings

  • src/adcp/types/schema_loader.py:503 — Runtime relaxation of the immutable rc.3 status schema. This is a semantic-contract change outside DR-0008's wire-shape scope. Per repo spec-fidelity gates, relaxing an immutable published schema at runtime constitutes AdCP spec drift and breaks the wire-shape contract adopters rely on. Needs upstream fix / WG ratification before shipping.

Medium findings (do not block on their own, but should be addressed alongside the blocker)

  • Capability-model fields widened to | None with a new rejecting validator under feat: — verify this does not flip required→optional on a public model without the mandatory semver signal.
  • In-memory production support advertises empty reporting_delivery — unhandled edge case.
  • Production loop discards its exception with no log and no _stop.set() — warn-only/silent error handling on a durable async path.

Rationale: Row 1 of the decision table fires — a High-severity spec-fidelity finding (schema_loader.py:503) is present, so the outcome is request-changes. Verified positives: generated-code edits are deterministic post_generate_fixes output, reconcile pagination bounds, parameterized SQL with ORDER BY/FOR UPDATE, fail-closed signing, timed webhook delivery, first-attempt-anchored retry horizon.

Blocking findings

  • src/adcp/types/schema_loader.py:503 — Runtime relaxation of the immutable rc.3 status schema; semantic-contract/spec drift outside DR-0008's wire-shape scope, needs upstream fix/WG ratification

@bokelley bokelley changed the title feat(reporting): enable production tier status and ownership feat(reporting)!: enable production tier status and ownership Sep 19, 2026
aao-secretariat[bot]
aao-secretariat Bot previously approved these changes Sep 19, 2026

@aao-secretariat aao-secretariat Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ladon verdict: Approve

Approve — clean pass, prior blockers resolved.

Checked against the decision table top-down:

  • No no-auto-approve team match (HARD RULE clears).
  • gated_paths: false, so row 2 does not apply despite review_decision being CHANGES_REQUESTED (the gated-paths hard gate is path-based and is not triggered here).
  • high_risk is true, but all high_risk_reasons are (modified) with no medium-or-higher findings — no (deleted) entry (row 3 clears), and no medium findings to pair with a modified file (row 5 clears).
  • No critical/high findings (row 1 clears); no medium data-loss/schema/infra findings (row 4 clears).
  • Prior decision was request-changes (not escalate), so row 6 does not apply.
  • Zero findings total, so rows 7/8 do not apply.

Falls through to row 9 → approve.

Reviewer reports a clean pass across the closed-operator diagnostic (_diagnostics.py), the stop-latch/single-alert dedup changes in production/service.py, the 296-line failure test covering memory + postgres boundaries, and the docs update. Diagnostic correctly bypasses LogRecordFactory to keep provider bodies/tracebacks/ambient context off the record; dedup is atomic under asyncio; a failing sink cannot block shutdown. No public-surface or semver break. The prior run's request-changes had no recorded blockers, and this run surfaces none — net clean.

@aao-secretariat
aao-secretariat Bot dismissed their stale review September 19, 2026 04:23

Superseded by Ladon approval of e3a44d2.

Base automatically changed from conductor/reporting-schema-proof-receipt-diagnostics-hardening to main September 24, 2026 23:17
@bokelley
bokelley dismissed aao-secretariat[bot]’s stale review September 24, 2026 23:17

The base branch was changed.

Comment thread tests/conformance/reporting/test_reporting_production_migration.py Fixed
Comment thread tests/conformance/reporting/test_reporting_production_rolling.py
Comment thread tests/conformance/reporting/test_reporting_production_migration.py Fixed
Comment thread tests/conformance/reporting/test_reporting_production_migration.py Fixed
Comment thread tests/conformance/reporting/test_reporting_production_migration.py Fixed
Comment thread tests/conformance/reporting/test_reporting_production_readiness.py
Comment thread src/adcp/reporting/production/memory.py
Comment thread tests/conformance/reporting/test_reporting_production_lifecycle.py
Comment thread tests/conformance/reporting/_production_delivery_process.py
Comment thread src/adcp/reporting/production/contracts.py
aao-secretariat[bot]
aao-secretariat Bot previously approved these changes Sep 25, 2026

@aao-secretariat aao-secretariat Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ladon verdict: Approve

Approve — clean pass with no blocking findings.

Reviewer reported no Critical, High, or Medium findings. Verified areas: type-layering and public exports (ReportingAdjustment/ReportingAdjustmentReceipt), base.py serializer removal coordinated with generated-model serializers (deserialization-compatible both directions on an experimental RC surface), schema_loader datetime/base_uri/effective-schema changes, untouched dispatch credential guard, receipts/handler reauthorize hardening, fail-closed projection activation state machine in pg.py, and the cursor-bound TOCTOU-guarded exact-read path.

Decision-table walk:

  • Row 1 (critical/high): none — skip.
  • Row 2 (gated_paths + not APPROVED): gated_paths is false — skip.
  • Row 3 (high_risk + deleted): all high-risk reasons are (modified), no deletions — skip.
  • Row 4 (medium data-loss/schema/infra): no findings — skip.
  • Row 5 (high_risk modified + any medium): no medium findings — skip.
  • Row 6 (sticky escalate): prior decision was approve — skip.
  • Row 7 (no-auto-approve team): no team match — skip.
  • Row 8 (≥3 medium): zero medium — skip.
  • Row 9: approve.

high_risk is true only from (modified) entries with no medium-or-higher concern, which per the flag-reading guidance is presumed safe. No team gate and no gated-path gate apply.

aao-secretariat[bot]
aao-secretariat Bot previously approved these changes Sep 25, 2026

@aao-secretariat aao-secretariat Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ladon verdict: Approve

Approve — subsequent pass on a delta confined to the test/conformance harness under tests/conformance/reporting/ (phase tracking, immutable rc.3 historical-reference-schema verification, dropping rc.3 from the installed bundle set, version parametrization, reformatting).

No public adcp.* surface, wire shape, generated code, credential paths, or CI gates are touched. Changes are internally consistent (shutil/json imported, get_validator accepts version, rc.3 still resolvable in source).

No Critical/High/Medium findings. Although high_risk is true, all reasons are (modified) server/types files with no medium-or-higher concern, so row 5 does not fire (requires a medium finding), and no deletions are present (row 3 n/a). No gated paths, no author team gate, prior decision was approve. Falls through to row 9.

Comment thread src/adcp/reporting/ledger/producer_progress.py
Comment thread src/adcp/reporting/ledger/producer_progress.py
Comment thread src/adcp/reporting/ledger/producer_progress.py
Comment thread src/adcp/reporting/ledger/producer_progress.py

@aao-secretariat aao-secretariat Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ladon verdict: Approve

Approve — subsequent pass, clean diff, no blocking or medium findings.

This delta adds a per-version MCP-schema materialization cache in schema_loader.py (correct double-checked locking; JSON round-trip yields independent, alias-free trees; failed/missing schemas are not cached) and narrows get_tools_for_handler's deepcopy to non-schema metadata while all versioned branches still set inputSchema. A new 295-line test suite covers caching, isolation, concurrency, and pins output SHA256 digests.

Decision-table walk:

  • Row 1 (critical/high): no such findings.
  • Row 2 (gated paths): gated_paths is false — not triggered.
  • Row 3 (deleted high-risk): all high-risk reasons are (modified), none deleted.
  • Row 4 (medium data-loss/schema/infra): no medium findings.
  • Row 5 (high-risk modified + medium): high_risk is true and files are modified, but there are zero medium findings — does not fire.
  • Row 6 (sticky escalate): prior decision was approve, not escalate.
  • Row 7 (no-auto-approve team): no team match.
  • Row 8 (≥3 medium): zero medium findings.
  • Row 9: approve.

high_risk is a heuristic to look harder at src/adcp/server/** and the type-system files; the reviewer examined the modified server/schema-loading code and found the caching correct, isolation preserved, and public wire shape intact. No semver-signal, forward-compat, import-layering, or credentials concerns surfaced. New behavior is well-tested.

@bokelley
bokelley merged commit 34c8f6d into main Sep 25, 2026
42 checks passed
@bokelley
bokelley deleted the conductor/reporting-production-tier-capabilities-b24 branch September 25, 2026 02:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant