Skip to content

feat(reporting): integrate signed rc6 fixtures and lease progress - #1193

Merged
bokelley merged 6 commits into
mainfrom
conductor/reporting-adcp-rc4-adoption
Sep 25, 2026
Merged

bokelley merged 6 commits into
mainfrom
conductor/reporting-adcp-rc4-adoption

Conversation

@bokelley

@bokelley bokelley commented Sep 20, 2026 •

Copy link
Copy Markdown
Contributor

Integrate the signed-release and lease-progress feature with the reporting stack already on main. The current protocol remains rc.6. PostgreSQL lease bookkeeping now preserves held materializer generations, shares the account-before-row lock order, and makes bounded progress behind busy accounts; catalog checks retain exact fresh validation with bounded round trips. The installed harness retains diagnostic phase/progress evidence, and receipt rolling compatibility runs as eight independently checked shards.

Current-side activation helper correction

The final one-line append changes only tests/conformance/reporting/_production_installed_process.py: the current-side mount now explicitly requests 3.2-rc.6. The original feature's 3.2-rc.3 test pin was incompatible with the unchanged version policy inherited from main. Actual main already rejects that explicit historical pin before either reporting-mount minimum check; this correction restores the current-contract behavior that main's helper obtained from its default. No resolver, supported-version set, schema validation, caller cohort check, SDK source, SQL, workflow, timeout or coverage floor changes. The historical parent binaries, saved pages, checkpoints, pending identities and kill/restart assertions remain unchanged.

Original c0b777d run36089781647 is preserved:39jobs/37success/2failure, production compatibility8failed4passed and the correctly failing strict aggregate. All eight original activation logs in artifact10845338390 (ZIP SHA25622b0548c33ea9992f9ca5bb4b0310ecdddc6d2ec62b0c1ef647466d04928cf18) report rejection of the explicit rc.3 pin before activation. This is recovered original stderr, not a guessed cause or reconstructed child error. The four new rc.6 continuations do not qualify the failed eight or the failed whole job. Guard seal22950991623e4b93d43caa7ae38b4ea342056a2a5199f5b222dfc44774eb16e7 remains NOT_READY.

A focused source-only constructor probe reads the literal from the helper's AST: the unchanged helper fails for both notification modes; the corrected helper passes both. It uses the real memory reporting harness and current SDK source under Python3.12, supplying no installed, historical, PostgreSQL, Python3.10 or full restart qualification. The append retains30assertions,29awaits,168constants and no exception handlers; exactly one constant changes. Fresh full CI is required.

The installed selector is distinct from the native selector:1,214 native cases minus10parent-harness controls plus14materialization controls gives1,218 collected and1,217 selected after the one existing deselection. The current module map has56unique entries (59expanded path occurrences), including mcp_tools; archive input and wheel-member counts must be freshly derived. Parent c0 artifact observations do not transfer.

Composition and current protocol

The composition commit 0b5587d466d614c2fe1e8a3f7758f1194d1fc39c has ordered parents [1f953c40d761be71d11fde84c78359ff2074fe7c, 34c8f6d929aeac3407e2f595104a8e903e572623]. It preserves the original feature history and actual integrated main. The corrective child and subsequent test-helper appends reconcile the old rc.4 adoption work with the rc.6 contract that main already supplies. No rewrite, squash or transfer of historical test/review credit.

  • Current pin, live version policy, generated types, schema loader and its alias-free materialization cache remain byte-identical to integrated main. Existing cached schemas are neither changed nor deleted. The original feature's 1,613 rc.4 cache additions remain immutable historical inputs.
  • Add the authenticated rc.6 release descriptor and 143 unmodified compliance inputs plus provenance. All 1,620 transformed schema hashes match the existing rc.6 cache. The descriptor binds release v3.2.0-rc.6, target f7932355a52f81c64f4c8ff8cc0a36f57677d711, tarball SHA256 2837bcd4ee2d74b326ffff573ee0cdeb87b3920967fb99bc02671c51718834dd, and exact checksum/signature/certificate assets. Signature verification retains the required workflow identity, issuer and transparency checks.
  • Preserve the original feature's offline beta.6 and rc.3 packaging. This is a deliberate change from PR1192's observed wheels. It does not advertise an rc.3 live client or reporting mount: rc.3's immutable waiver prohibition differs from the implemented rc.6 bilateral-waiver behavior. Stable 3.0/3.1 and current rc.6 remain the live SDK policy; reporting mounts require the current reporting contract. Older/future live pins have explicit negative controls.
  • Current and historical installed schema origins are asserted separately. The complete copied historical test-reference map remains outside the installed prefix and workspace and is checked before/after the suite; the packaged historical root is inside the prefix and independently matches that map. The previously deferred historical-resolver not-None diagnostic is now explicit. Whole-wheel membership remains a separate archive-inventory check.
  • Keep main's rc.6 forecasts, cursor lower-bound binding and authenticated unmarked-v1 continuation exception. The original rc.4 forecast controls already exist in main's rc.6 suite; consolidate there instead of duplicating the suite. The new installed comparison uses integrated PR1192 34c8f6d9 / tree 2dd33404, with current rc.6 pages and exact preserved documents/checkpoints across restarts. No pre-34c8 snapshot or explicit rc.3 live-route qualification is inferred.

Source and test invariants

All eight required manifests are byte-identical to main: 464 + 249 + 10 + 187 + 102 + 33 + 317 + 331 = 1,693 objects. No SQL DDL or catalog fingerprint is regenerated. The lease changes are source behavior and SQL queries, not schema tolerance. Drain old row-first autonomous workers before introducing the shared account-first order.

The catalog reader batches object kinds but still observes fresh drift on the caller's connection. The inherited activity-cache control keeps exact equality with its first measured query count; its obsolete greater-than-ten expectation becomes a positive-read check, while the new catalog control independently requires an unchanged count of at most ten after adding tables. The lease wait is bounded and available only before a standalone turn's first account acquisition; caller transactions do not gain that blocking edge. Worker/expiry fencing and real source-change generation fences remain tested.

Forty await-containing assertion predicates in six files are evaluated before their assertions. Inverse AST reconstruction proves the complete predicates unchanged, including short circuit and multiple awaits; no cancellation join is moved out of its expected-exception scope. There is one outer-await predicate and 39 whole predicates. Existing operational hoists are retained.

The c0b777d continuation append constructs cursor and checkpoint negative probes independently, preventing a preceding cursor from leaking into the checkpoint request. Two current-source mounted PostgreSQL scenarios pass with notifications off/on; their installation guard was explicitly bypassed, so this is not installed, frozen, Python-3.10 or process-restart qualification.

No listener, authentication, wildcard default or Bandit B104 exposure change is introduced. The inherited documented exposure remains separately recorded; source approval is not scanner or policy clearance.

CI and validation

The workflow expands 24 keys to 39 jobs. The entire Python matrix is identical to main, including the 60-minute jobs, 45-minute coverage steps and 80% floor. The required PostgreSQL gate is also identical to main: original name, always(), empty permissions and all eleven exact success tests.

Receipt compatibility uses eight exact historical parameters and its own strict aggregate. Its verifier now binds the already-integrated A/B/C/B1/B2.1 pins and rejects reintroduced locale pinning; it does not tolerate missing/extra/duplicate evidence or failed/skipped parameters. Shards and their aggregate check out the exact PR head explicitly; other execution lanes use the merge preview. Expected CI checkout classes are 28 merge-preview executions, nine exact-head receipt jobs and two aggregates without checkout; fresh raw logs must authenticate actual checkouts.

Working-candidate local evidence, not reviewer or CI credit:

  • Signed adoption, materialization, sync, extra-field and harness controls: 274 passed, one database-required skip, eight warnings. The skipped real-database cleanup control subsequently passed in the native run.
  • Final focused memory/libc PostgreSQL integration: 242 passed, zero skipped, four warnings. Fresh exact catalog comparisons: 1,693/1,693 under C, libc and ICU.
  • Receipt orchestration controls: 15 passed, including changed-pin, reintroduced-locale, missing/duplicate/modified evidence, timeout and failure negatives.
  • Existing version-scoped module: 35 passed after restoring its unchanged tracked beta.4 fixtures to the sparse local checkout.
  • Exact-main method negatives: restoring only main's two lease methods and catalog reader under the current fixtures yields two expected failures. The old catalog reader grows from 294 to 390 queries after adding tables. This is a function-snapshot control, not an exact-main whole-runtime run.

Retained local failures are not relabelled: the initial native run had 239 passes/two inherited message-wording assertion failures; the corrected test checks the structured unsupported-version details. Initial shard controls exposed old pins and a stale C-locale assumption. Six unrelated version-scope failures came from the sparse checkout's missing tracked beta.4 fixtures. A test-file edit during the first native run is recorded as a limit; the final run uses stopped-edit inputs. Original logs and scoped results remain separate.

Complete installed VCS/sdist builds, frozen artifacts and the full matrix were not run locally. Fresh CI must establish them; no prior PR1192 artifacts or timeout/coverage result transfer. Actual selection collections partition 4,684 cases with disjoint lanes and full union equality: native production 1,214, production compatibility 12 (eight existing plus four integrated-parent continuations), and four separate installed outer cells. The receipt selector has eight independently verified parameters. Collection is not execution. Secret scanning is independently recorded per exact head; GitGuardian size skips are never presented as clean scans, and root substitution/exposure policy remains separate from review and factual guard closure.

Retained rollout limits

All nine release-note exclusions remain open: pre-17ee A, pre-0f34 B, pre-967 C, pre-5487 B1, pre-3fd B2.1, pre-09fd B2.2, pre-2d777 B2.3, pre-e16 hardening and pre-34c8 production. Old A whole-trigger startup after C remains unsupported. The 9rLB source-half mitigation stays attributed to PR1191, without load or closure credit; the transport schema cache is a separate object. F-SX retains its inherited fail-closed behavior without snapshot retention. Epoch-zero, quarantine and readiness non-promotion remain; no artifact, release, activation, #1172, #1199 or TS acceptance. Translator remains partial, not full interoperability. Guard1201 stays draft/LAST and the legacy release workflow stays disabled.

Published-object identity

Head 1a0c7104c5c3a4c61aa35f78759c6014b1f984df, tree 1185c7483786a4f4583f83b4c09d44ba07ff5248, sole parent c0b777de962c5b26200d5a5d168542625f3f40cc. The parent source review stays scoped to c0b777d; review of this append is a separate one-file delta/ancestry readback, not transferred composition approval. The full original feature/composition/correction chain remains reachable. Patch digests use git diff --binary --abbrev=8.

  • child: c0b777de962c5b26200d5a5d168542625f3f40cc..1a0c7104c5c3a4c61aa35f78759c6014b1f984df; 1 file changed, 1 insertion(+), 1 deletion(-); SHA256 befea72437f658fd6d8c58b3ab9f87e4e4a9bd7177875af1c376e411453d66e0.
  • correction: 0b5587d466d614c2fe1e8a3f7758f1194d1fc39c..1a0c7104c5c3a4c61aa35f78759c6014b1f984df; 170 files changed, 33387 insertions(+), 923 deletions(-); SHA256 09de381e24c714ca8910f70ca2f0e7c2295896dd528f980af86e718f9346e9ad.
  • full: 34c8f6d929aeac3407e2f595104a8e903e572623..1a0c7104c5c3a4c61aa35f78759c6014b1f984df; 1945 files changed, 2693781 insertions(+), 274 deletions(-); SHA256 84737e999383150e2e9e87c8a52287579741dec4ee23b16d93f71cd7c91e057e.

Use immutable Git objects if the API truncates the full diff. All fresh scanner output, source review, runtime qualification and root policy remain separately attributed. No retry or old-head success credit is requested.

@aao-secretariat aao-secretariat Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ladon verdict: Approve

Approve — clean AdCP 3.2.0-rc.4 schema-cache adoption.

Checked against the decision table top-down:

  • No no-auto-approve team match (HARD RULE clear).
  • gated_paths: false (row 2 not applicable).
  • high_risk: true, but all high_risk_reasons entries are (added) new schema-cache files — no (modified) or (deleted) entries, so rows 3 and 5 do not fire. New files matching schemas/** are normal scaffolding/regeneration output, not escalation-worthy on the flag alone.
  • No critical/high findings (row 1 clear); no medium findings (rows 4, 5, 8 clear).
  • No prior decision (row 6 clear).

Reviewer verified: breaking-commit marker + migration notes cover the required→optional flips in sync_accounts_response.py, generated_poc Action renumbering is harmless codegen churn (aliases unaffected), fail-closed rc.3/rc.4 version boundary, correct summary-only forecast scope, and sync_schemas supply-chain hardening (pinned cosign identity, no bypass/fallback, tarball traversal guard). CI gates remain armed; no runtime external I/O added.

Falls through to row 9 → approve.

@bokelley
bokelley force-pushed the conductor/reporting-adcp-rc4-adoption branch from 2563cf5 to 71c2bc0 Compare September 20, 2026 12:22

@aao-secretariat aao-secretariat Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ladon verdict: Approve

Approve — clean rc.4 adoption pass with no blocking findings.

Checked against the decision table top-down:

  • Rows 1 (critical/high) and 4/5 (medium): no findings at any severity — nothing fires.
  • Row 2 (gated paths): gated_paths is false; also review_decision is APPROVED, so no gate concern.
  • Row 3 (deletion in high-risk path): high_risk is true, but all high_risk_reasons entries are (added) — new schema-cache files scaffolded by regen, no (deleted)/(modified). New files matching schemas/** are normal codegen output, not escalation-worthy on the flag alone.
  • Row 6 (sticky escalate): prior decision was approve, not escalate — N/A.
  • Row 7 (no-auto-approve team): no team match.
  • Row 8 (3+ mediums): zero medium findings.
  • Row 9: falls through to approve.

What the reviewer verified: the required→optional flip on SyncAccountsAccount (brand/operator/status) is correctly signaled with the feat(protocol)!: breaking marker plus a migration note in docs/protocol-3.2-rc4.md, satisfying the semver-signal gate. Version-boundary logic is fail-closed (VERSION_MISMATCH disclosed only after HMAC/position auth; VERSION_UNSUPPORTED on the rc.3/rc.4 straddle). Forecast generators are bounded, generated churn pairs with the schema regen, and CI adds rather than disables tests. No forward-compat, import-layering, generated-code, credential, or CI-gate violations.

@aao-secretariat aao-secretariat Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ladon verdict: Approve

Approve — clean subsequent pass on the AdCP 3.2.0-rc.4 adoption PR.

The diff is overwhelmingly vendored schema-cache JSON, compliance test-vectors, and datamodel-code-generator regeneration output (confirmed regen — expected Action22→Action23 variant renumber churn plus new rc.4 symbols, not hand-edits). The rc.4 forecast/version-pin logic is fail-closed, version-gated to preserve rc.3, additive on the public surface, and covered by new conformance tests across memory/postgres and mcp/a2a transports. Reviewer surfaced no critical/high/medium findings and no inline comments.

Decision-table walk-through:

  • Row 1 (critical/high): no such findings.
  • Row 2 (gated_paths + not APPROVED): gated_paths is false, and review_decision is APPROVED anyway.
  • Row 3 (high-risk deleted): high_risk is true but every reason is (added) — new schema-cache files, normal scaffolding, no deletions.
  • Rows 4–5 (medium findings): none.
  • Row 6 (sticky escalate): prior decision was approve, not escalate.
  • Row 7 (no-auto-approve team): no team match.
  • Row 8 (≥3 medium): zero medium findings.
  • Row 9: approve.

The high_risk flag is driven solely by new-file (added) matches under schemas/**, which per the change-kind guidance is normal vendored-schema scaffolding and not escalation-worthy on the flag alone.

Verify the immutable upstream release and regenerate current schemas, models
and compliance fixtures. Render complete reporting summaries with future period
starts, keep complete periods schema-valid, and preserve explicit rc.3 frozen
continuations through public version-aligned mounts and clients.

Retain the capability model repairs and historical schema assets. Exercise the
actual accepted B2.4 installed artifact as an additional continuation boundary.

Cache public schema materialization within immutable version state, returning
isolated copies. Shard the unchanged receipt rolling test over its eight exact
historical parameters and require complete per-attempt evidence in the original
aggregate context, with bounded execution and explicit reviewed-head checkout.

BREAKING CHANGE: SyncAccountsAccount brand, operator and status are nullable for
the rc.4 reference/error forms, and item error lists must be nonempty. The default
reporting contract is rc.4; retained rc.3 walks require an explicit rc.3 mount and
client pin. Existing snapshots are not rewritten.
@bokelley
bokelley force-pushed the conductor/reporting-adcp-rc4-adoption branch from 226256f to 61d6290 Compare September 20, 2026 22:35

@aao-secretariat aao-secretariat Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ladon verdict: Approve

Approve — AdCP 3.2.0-rc.4 adoption (#1193).

The delta is dominated by regenerated schema cache/compliance artifacts paired with the ADCP_VERSION bump rc.3→rc.4 (generated output, not hand-edited source; Action22→23/Action32→33 are codegen traversal renumbers, aliases layer unaffected). Reviewer found no critical/high/medium findings.

Substantive surface checked: rc.4 version-pinning is fail-closed (snapshot.py discloses REPORTING_FEED_VERSION_MISMATCH only after HMAC/token/caller gate; mcp_tools pinned_reporting_status guard raises VERSION_UNSUPPORTED across the rc.4 boundary), version ordering/handler floor checks coherent, schema_loader caching thread-safe, CI sharding preserves coverage with actions SHA-pinned and no gates disabled, and the breaking marker + PR-body migration note satisfy the semver-signal rule.

Decision path: no critical/high/medium findings (rows 1, 4-6, 8 don't fire). gated_paths is false (row 2 n/a). high_risk is true but all high_risk_reasons are (added) new schema-cache files — normal scaffolding, no (deleted)/(modified) triggers (rows 3, 5 n/a). No no-auto-approve team match (row 7 n/a). Prior decision was approve. Falls through to row 9 → approve. Note review_decision is APPROVED regardless.

aao-secretariat[bot]
aao-secretariat Bot previously approved these changes Sep 21, 2026

@aao-secretariat aao-secretariat Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ladon verdict: Approve

Approve — subsequent pass on the rc.4 adoption PR, clean.

This is a follow-up push (prior decision: approve) whose delta is a single fix(reporting) commit. The reviewer verified:

  • The account-before-row lease rewrite in pg.py uses the same advisory-lock key as _lock_account and bounds its single blocking wait via a savepoint-scoped lock_timeout.
  • The generation-restore fence never blindly decrements.
  • The _schema.py catalog batching is semantically identical to the per-table version.

No Critical/High/Medium findings in this run.

Decision-table walk (top-down):

  • Row 1 (critical/high): no such findings.
  • Row 2 (gated_paths gate): gated_paths is false; also review_decision is APPROVED. Not triggered.
  • Row 3 (high-risk deleted): high_risk is true, but every high_risk_reasons entry is (added) — new schema-cache files scaffolding the 3.2.0-rc.4 adoption. No deletions. Not triggered.
  • Row 4 (medium data-loss/schema/infra): no medium findings.
  • Row 5 (high-risk modified + medium): the high-risk matches are all (added), not (modified), and there are no medium findings. Not triggered.
  • Row 6 (sticky escalate): prior decision was approve, not escalate. Not triggered.
  • Row 7 (no-auto-approve team): no team match.
  • Row 8 (≥3 medium): zero medium findings.
  • Row 9: approve.

The high_risk flag fires only because ~1500 new schema-cache JSON files match schemas/**, all added — normal scaffolding for the rc.4 adoption, not escalation-worthy on the flag alone. Falls through cleanly to row 9.

@bokelley bokelley changed the title feat(protocol)!: adopt signed AdCP 3.2.0-rc.4 feat(reporting): integrate signed rc6 fixtures and lease progress Sep 25, 2026
aao-secretariat[bot]
aao-secretariat Bot previously approved these changes Sep 25, 2026

@aao-secretariat aao-secretariat Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ladon verdict: Approve

Approve.

Clean pass. The delta reconciles rc.4 adoption work with main's rc.6 contract, dominated by generated rc.6 schema-cache and vendored compliance fixtures (all (added) under schemas/**). Reviewable source is coherent: version guards bumped rc.3/rc.4→rc.6, the CI locale-pin verifier is inverted and self-consistent with ci.yml, the await-predicate test extraction is semantically equivalent, negative controls are strengthened, and the append isolates continuation probes. No disabled gates, blanket ignores, import-layering violations, or new unexported public API.

No Critical/High/Medium findings.

Gate checks: gated_paths is false, so row 2 does not apply despite review_decision: REVIEW_REQUIRED. high_risk is true but every reason is an (added) new file — normal scaffolding/regeneration output, not escalation-worthy (no (deleted)/(modified) triggers, so rows 3 and 5 do not fire). No no-auto-approve team match (row 7 clear). Prior decision was approve, so sticky escalation (row 6) does not apply. Zero medium findings, so rows 4 and 8 do not fire. Falls through to row 9 — approve.

@aao-secretariat aao-secretariat Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ladon verdict: Approve

Approve — clean delta pass, no blocking or medium findings.

This is a subsequent review (prior outcome: approve). The current run surfaces a single test-only change: tests/conformance/reporting/_production_installed_process.py:53 bumping adcp_version from "3.2-rc.3" to "3.2-rc.6" to align an outlier installed-process pin with the established current-contract string used across the reporting suite. The reviewer verified the harness accepts and threads adcp_version and confirmed no public-surface, wire-shape, generated-code, or credential impact.

Decision-table walk:

  • Row 1 (critical/high): no findings — skip.
  • Row 2 (gated_paths + not APPROVED): gated_paths is false — skip.
  • Row 3 (high_risk + deleted): high_risk is true but all schemas/** matches are (added) cache artifacts, none (deleted) — skip. New files matching high-risk globs are normal scaffolding, not escalation-worthy.
  • Row 4/5 (medium findings): none — skip.
  • Row 6 (sticky escalate): prior was approve, not escalate — skip.
  • Row 7 (no-auto-approve team): no match — skip.
  • Row 8 (≥3 medium): zero medium — skip.
  • Row 9: approve.

The high_risk flag is driven entirely by added schema-cache files; per the change-kind guidance, added files matching high-risk globs do not warrant escalation on the flag alone. No findings block. Approve.

@bokelley
bokelley merged commit 940c95e into main Sep 25, 2026
50 checks passed
@bokelley
bokelley deleted the conductor/reporting-adcp-rc4-adoption branch September 25, 2026 08:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant