Skip to content

openDox root: bump code to d816cf06 (§ 3.5 runtime, § 3.6 creation, § 3.7 FLOOR PART 3, § 5.4 (d)) and spec to 8fe8c4c7 (four of the five § 6 re-homes) - #10

Merged
brettheap merged 1 commit into
mainfrom
chore/pin-code-d816cf06-and-spec-8fe8c4c7
Sep 19, 2026
Merged

brettheap merged 1 commit into
mainfrom
chore/pin-code-d816cf06-and-spec-8fe8c4c7

Conversation

@brettheap

@brettheap brettheap commented Sep 19, 2026 •

Copy link
Copy Markdown
Contributor

Lane: openxfactory-4 (openXfactory-4-openDox_extraction)

Refs opensoft/openxFactory#656 (stays OPEN). CLAIM: 5738280604.

Runbook Phase 3 — docs/opendox-cutover-runbook.md:1812, "the assembly
roots: carved_from + gitlink + pin, ONE COMMIT"
. The second and last of the
pair; opensoft/openXdox#12 is the first.

What moves — four paths, no fifth

leg gitlink + pin commit: digests.tree_sha256:
code 0b4e8bbf… → d816cf06f1c9752a39c2b71ba40adc4ae3f3bf66 db8817dd… → ac877e49b7ec001a22be21ce18021208e00f9d1d2c2ceb997b060a0b247fbcac
spec a8f5eb73… → 8fe8c4c71c4da8d363394441ad9e2c9547e540a3 658c034d… → f63c5b8fee6bf0fded4cb745555dea6427b274683c5d5bccac01c82e2b0fadbb
 code                    | 2 +-
 contracts/code-pin.yaml | 4 ++--
 contracts/spec-pin.yaml | 4 ++--
 spec                    | 2 +-
 4 files changed, 6 insertions(+), 6 deletions(-)

Each target is that repository's main tip, measured at 2026-09-19T01:31Z
and not carried forward. The runbook's pre-push object check (:1825-1830 — git
stores a gitlink without checking the object is present, so a wrong pin commits
and pushes clean
): git -C code cat-file -t d816cf06… and git -C spec cat-file -t 8fe8c4c7… both print commit, and both equal origin/main in
their own repository.

What the advance carries — the largest of the arc

code, nine commits (64 files, 37 529 insertions, 1 358 deletions):

d816cf0 § 3.6 follow-up #2: a linked worktree's metadata, and a store refusal that is a refusal (openDox-code#32)
93ccc3d § 3.7 FLOOR PART 3, openDox side: the declared conformance factory and Q-F1's transposition (#31)
5c86713 § 3.6 follow-ups: the seven findings #26 registered, each with its case (#30)
373b05a § 5.4 FLOOR PART 2 clause (d), openDox leg: the collection triple pinned on the required check (#29)
4f8ae01 § 3.6: openDox creates a repository as a first-class act, with RULING C3's conformant local-git adapter (#26)
aca94ec § 3.5: the openDox runtime — FastAPI + Postgres, identity and coordination, and nothing else (RULED Q1/Q2) (#25)
52b237e § 3.4 S7 residue: the display facet threaded to the seven leaves it never reached (#28)
5c137a9 § 3.4 RULED Q7: a contributed binding's CSS leaves styles.css for the binding's own sheet (#27)
0e65b5f the two intent-feed DOM suites retired at this leg (#24)

spec, eight commits (15 files, 3 636 insertions, 0 deletions):

8fe8c4c § 6.2 — the surviving -v2 chat-turn family (openDox-spec#15)
66d5977 § 6.5 — add-lens-document-selection, the set-builder half (#14)
3b7f80c § 6.3 — add-doxchat-model-intake, the model plane (#13)
edeed08 § 6.4 — add-composed-view-authoring, openDox's first OpenSpec change (#12)
54e9107 Front-end boundary note, amendment #3 (#11)
7d12428 Front-end boundary note, amendment #2 (#10)
61866d2 § 3.4 boundary note: the five rulings Q1–Q5 and the S1–S3 start (#9)
a44ac06 § 3.4 design note: the front-end package boundary (#8)

Taken with openXdox#12, this pair is the first moment BOTH roots name all five
§ 6 re-homes:
§ 6.1's refresh lane is openXdox-spec f088b097, pinned by
#12; § 6.2–6.5 are openDox-spec 8fe8c4c7, pinned here.

The third fact-class is VACUOUS here, measured rather than assumed

scripts/validate-pins.py holds gitlink + pin-file commit: + every
.github/workflows/*.yml <org>/<leg>@<sha> reference as one invariant. This
root has one workflow and exactly one 40-hex @sha in it —
actions/create-github-app-token@fee1f7d63c2ff003460e3d139729b119787bc349
(validate.yml:104) — naming neither leg, so there is no third fact to move and
no "workflow @<sha> reference(s) agree" note is printed.
neutral_product_pins: [] here, so unlike openXdox's root there is no
neutral-pin recheck either: five ok lines, not six. A grep for the two
outgoing shas across the whole tree finds them in exactly the two pin files and
nowhere else.

Both digests recomputed, by two independent paths that agree

sorted-ls-tree-r-v1, via this repository's own scripts/repo_shape.py —
tree_digest() reads the submodule's object store, tree_digest_from_gh()
reads the forge's recursive tree listing:

code d816cf06f1c9  local=ac877e49b7ec001a22be21ce18021208e00f9d1d2c2ceb997b060a0b247fbcac
                   gh   =ac877e49b7ec001a22be21ce18021208e00f9d1d2c2ceb997b060a0b247fbcac  AGREE=True
spec 8fe8c4c71c4d  local=f63c5b8fee6bf0fded4cb745555dea6427b274683c5d5bccac01c82e2b0fadbb
                   gh   =f63c5b8fee6bf0fded4cb745555dea6427b274683c5d5bccac01c82e2b0fadbb  AGREE=True

Neither was retyped from anywhere.

Verification — BEFORE and AFTER, the same five lines so they compare line for line

BEFORE, at root c4c5014d9b39ac55e5df957db23a56db38847a6b, legs initialized
with git submodule update --init code spec (never a bare git add of a
submodule):

  ok  spec: gitlink == contracts/spec-pin.yaml commit a8f5eb73671c
  ok  spec: tree digest recomputes (658c034d6eba…)
  ok  code: gitlink == contracts/code-pin.yaml commit 0b4e8bbf68fa
  ok  code: tree digest recomputes (db8817ddde1a…)
  ok  contracts/shape-pin.yaml: 10 copied shape file(s) match their digests
pins ok

exit 0.

AFTER, at this branch's head:

  ok  spec: gitlink == contracts/spec-pin.yaml commit 8fe8c4c71c4d
  ok  spec: tree digest recomputes (f63c5b8fee6b…)
  ok  code: gitlink == contracts/code-pin.yaml commit d816cf06f1c9
  ok  code: tree digest recomputes (ac877e49b7ec…)
  ok  contracts/shape-pin.yaml: 10 copied shape file(s) match their digests
pins ok

exit 0.

make validate — naming + manifest + pins, what CI runs — is green end to
end: validate-repository-naming.py exit 0 (openDox neutral-product/assembly, openDox-spec project-leg/spec, openDox-code project-leg/code), validate-manifest.py manifest ok: openDox (opendox), 3 legs, validate-pins.py pins ok.

Negative control — so the green is not read as vacuous

With the gitlink moved and contracts/code-pin.yaml left at the old commit in
the working tree, the same command exits 1 with two findings:

FINDING pin-gitlink-mismatch: code: gitlink d816cf06f1c9752a39c2b71ba40adc4ae3f3bf66 != contracts/code-pin.yaml commit 0b4e8bbf68fabfcd65d4f0d80e619c20a013e888
FINDING pin-digest-mismatch: contracts/code-pin.yaml: digests.tree_sha256 ac877e49b7ec…
       recomputed at 0b4e8bbf68fa db8817ddde1a…
2 finding(s). THE LOCKSTEP RULE: …

Restored from the index and re-verified green. The arm that has to fire, fires.

What deliberately does NOT move

contracts/manifest.yaml carved_from = {opensoft/openxFactory, b075fd91dc8fced8e1373825ba80220c33536bae} — the CARVE commit, a provenance
record of an event (runbook § 1.1), not a pin that tracks a head; the runbook's
item (3) was discharged by the commit that wrote it. Also
contracts/shape-pin.yaml, project.yaml, and every other file.

The downstream consequence, measured

openxFactory pins openDox directly (contracts/opendox-pin.yaml =
c4c5014d…, openDox gitlink = c4c5014d…) and openXdox's root pins it too
(c4c5014d…). verify-opendox-pin.py check 5 compares those two
declarations to each other, not to openDox's current head — so this advance
breaks nothing: openxFactory continues to pin an older openDox root, which is
what a pin is for.

Registered as the follow-up, not taken here: advancing openxFactory to this
new root is a three-repository lockstep — openxFactory's openDox gitlink,
openxFactory's contracts/opendox-pin.yaml, and openXdox's
contracts/opendox-pin.yaml (read as a blob at whatever commit
openxFactory's openXdox gitlink names) must all name the same openDox commit
in one landing, or check 5 refuses opendox-pin-lockstep-mismatch.

Sequencing, and what this PR is not

This is the Phase 3 pin act. § 3.8 (tasks.md:1517-1521) and § 4.6
(tasks.md:2049-2050) cut dox-v1.0 / xdox-v1.0 in the assembly root,
"over the commit that names both legs" — this commit is the first one that
names the landed legs. It cuts nothing: runbook § 9, Phase 6 (:2000) — "the
tags (§ 3.8 and § 4.6). BRETT'S ACT, ALWAYS."

Sibling search before authoring: gh pr list --repo opensoft/openDox --state open returned zero open pull requests at 2026-09-19T01:31:12Z.

🤖 Generated with Claude Code

Summary by Sourcery

Advance the openDox assembly's code and spec legs to their new validated commits and synchronized tree digests.

Enhancements:

  • Advance the openDox assembly to the latest pinned code and specification repository revisions for the Phase 3 cutover.

Chores:

  • Update the corresponding code and spec tree digests while preserving the repository pin lockstep.

… 3.7 FLOOR PART 3, § 5.4 (d)) and spec to 8fe8c4c7 (four of the five § 6 re-homes)

Lane: openxfactory-4 (openXfactory-4-openDox_extraction)

Refs opensoft/openxFactory#656 (stays OPEN). CLAIM: 5738280604.

Runbook Phase 3 (`docs/opendox-cutover-runbook.md`:1812, "the assembly roots:
`carved_from` + gitlink + pin, ONE COMMIT"), the second and last of the pair —
opensoft/openXdox#12 is the first. Both legs advance in the one commit, with
both halves of each pin:

  code  0b4e8bbf -> d816cf06   contracts/code-pin.yaml commit + tree_sha256
  spec  a8f5eb73 -> 8fe8c4c7   contracts/spec-pin.yaml commit + tree_sha256

Four paths, no fifth. Each leg commit is that repository's main tip, measured
at 2026-09-19T01:31Z rather than carried forward; `git -C code cat-file -t
d816cf06` and `git -C spec cat-file -t 8fe8c4c7` both print `commit` (the
runbook's :1825-1830 pre-push check - git stores a gitlink without checking the
object is present, so a wrong pin commits and pushes clean), and both equal
`origin/main` in their own repository.

WHAT `code` CROSSES, nine commits - 64 files, 37529 insertions, 1358 deletions:
  d816cf0 § 3.6 follow-up #2: a linked worktree's metadata, and a store refusal
          that is a refusal (openDox-code#32)
  93ccc3d § 3.7 FLOOR PART 3, openDox side: the declared conformance factory and
          Q-F1's transposition (#31)
  5c86713 § 3.6 follow-ups: the seven findings #26 registered, each with its case
          (#30)
  373b05a § 5.4 FLOOR PART 2 clause (d), openDox leg: the collection triple
          pinned on the required check (#29)
  4f8ae01 § 3.6: openDox creates a repository as a first-class act, with RULING
          C3's conformant local-git adapter (#26)
  aca94ec § 3.5: the openDox runtime - FastAPI + Postgres, identity and
          coordination, and nothing else (RULED Q1/Q2) (#25)
  52b237e § 3.4 S7 residue: thread the display facet to the seven leaves it
          never reached (#28)
  5c137a9 § 3.4 RULED Q7: a contributed binding's CSS leaves styles.css for the
          binding's own sheet (#27)
  0e65b5f Retire the two intent-feed DOM suites at this leg (#24)

WHAT `spec` CROSSES, eight commits - 15 files, 3636 insertions, 0 deletions:
  8fe8c4c § 6.2 the surviving -v2 chat-turn family (openDox-spec#15)
  66d5977 § 6.5 add-lens-document-selection, the set-builder half (#14)
  3b7f80c § 6.3 add-doxchat-model-intake, the model plane (#13)
  edeed08 § 6.4 add-composed-view-authoring, openDox's first OpenSpec change (#12)
  54e9107 Front-end boundary note, amendment #3 (#11)
  7d12428 Front-end boundary note, amendment #2 (#10)
  61866d2 § 3.4 boundary note: the five rulings Q1-Q5 and the S1-S3 start (#9)
  a44ac06 § 3.4 design note: the front-end package boundary (#8)

TAKEN WITH #12, THIS PAIR IS THE FIRST MOMENT BOTH ROOTS NAME ALL FIVE § 6
RE-HOMES: § 6.1's refresh lane is openXdox-spec f088b097, pinned by #12; § 6.2,
§ 6.3, § 6.4 and § 6.5 are openDox-spec 8fe8c4c7, pinned here.

THE THIRD FACT-CLASS IS VACUOUS HERE, MEASURED RATHER THAN ASSUMED. The lockstep
rule is gitlink + pin-file `commit:` + EVERY `.github/workflows/*.yml`
`<org>/<leg>@<sha>` reference. This root has one workflow and one 40-hex `@sha`
in it - `actions/create-github-app-token@fee1f7d63c2ff003460e3d139729b119787bc349`
(validate.yml:104) - which names neither leg, so there is no third fact to move
and `validate-pins.py` prints no "workflow @<sha> reference(s) agree" note.
`neutral_product_pins: []` here, so there is no neutral-pin recheck either: FIVE
`ok` lines rather than openXdox's six. A grep for the two outgoing shas across
the whole tree finds them in exactly the two pin files and nowhere else.

BOTH DIGESTS RECOMPUTED, BY TWO INDEPENDENT PATHS THAT AGREE.
`sorted-ls-tree-r-v1`, from this repository's own `scripts/repo_shape.py`:

  code d816cf06  ac877e49b7ec001a22be21ce18021208e00f9d1d2c2ceb997b060a0b247fbcac
  spec 8fe8c4c7  f63c5b8fee6bf0fded4cb745555dea6427b274683c5d5bccac01c82e2b0fadbb

`tree_digest()` reads the submodule's own object store; `tree_digest_from_gh()`
reads the forge's recursive tree listing over the network. Both return the two
values above character for character. Neither was retyped from anywhere.

VERIFICATION, BEFORE AND AFTER, THE SAME FIVE LINES SO THEY COMPARE LINE FOR
LINE. At root c4c5014 (before): `spec … a8f5eb73671c`, `spec … (658c034d6eba…)`,
`code … 0b4e8bbf68fa`, `code … (db8817ddde1a…)`, the 10 shape files, `pins ok`,
exit 0. After: the same five with `8fe8c4c71c4d` / `(f63c5b8fee6b…)` /
`d816cf06f1c9` / `(ac877e49b7ec…)`, `pins ok`, exit 0. `make validate` - naming
+ manifest + pins, what CI runs - is green end to end: naming exit 0,
`manifest ok: openDox (opendox), 3 legs`.

NEGATIVE CONTROL, so the green is not read as vacuous. With the gitlink moved
and `contracts/code-pin.yaml` left at the old commit in the working tree, the
same command exits 1 with TWO findings - `pin-gitlink-mismatch` (`d816cf06… !=
0b4e8bbf…`) and `pin-digest-mismatch` (recorded `ac877e49…`, recomputed at
`0b4e8bbf…` `db8817dd…`) - and the file was then restored from the index and
re-verified green.

WHAT DELIBERATELY DOES NOT MOVE. `contracts/manifest.yaml` `carved_from` =
`{opensoft/openxFactory, b075fd91dc8fced8e1373825ba80220c33536bae}` - the CARVE
commit, a provenance record of an event (§ 1.1), not a pin that tracks a head;
the runbook's item (3) was discharged by the commit that wrote it.
`contracts/shape-pin.yaml`, `project.yaml`, every other file.

THE DOWNSTREAM CONSEQUENCE, MEASURED. openxFactory pins openDox DIRECTLY
(`contracts/opendox-pin.yaml` = c4c5014, `openDox` gitlink = c4c5014) and
openXdox's root pins it too (c4c5014). `verify-opendox-pin.py` check 5 compares
those two declarations TO EACH OTHER, not to openDox's current head, so this
advance breaks nothing: openxFactory continues to pin an older openDox root,
which is what a pin is for. REGISTERED as the follow-up, not taken here:
advancing openxFactory to this new root is a THREE-repository lockstep -
openxFactory's `openDox` gitlink, openxFactory's `contracts/opendox-pin.yaml`,
and openXdox's `contracts/opendox-pin.yaml` (read as a BLOB at whatever commit
openxFactory's `openXdox` gitlink names) must all name the same openDox commit
in one landing, or check 5 refuses `opendox-pin-lockstep-mismatch`.

Lane: openxfactory-4
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Copilot AI lite review requested due to automatic review settings September 19, 2026 01:34

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @brettheap, you've used your own review budget of 250,000 diff characters for the last 7 days.

You can request another review in 2 days and 17 hours by commenting @sourcery-ai review. Upgrade to get a review now.

@sourcery-ai

sourcery-ai Bot commented Sep 19, 2026

Copy link
Copy Markdown
Reviewer's guide (collapsed on small PRs)

Reviewer's Guide

This Phase 3 pin commit advances the openDox code and spec assembly roots together, updates their lockstep commit and tree-digest declarations, and preserves all unrelated provenance and root metadata. The reported local/forge digest checks and validation suite demonstrate that both legs are synchronized and that mismatched pins are rejected; no release tags or downstream openXfactory pins are changed.

Flow diagram for lockstep pin validation

flowchart TD
    Start[Updated gitlinks and pin files]
    Check[validate-pins.py]
    Compare[Compare gitlink commit and pinned commit]
    Digest[Recompute tree_sha256]
    Result[ pins ok ]
    Reject[Reject with pin mismatch findings]
    Start --> Check
    Check --> Compare
    Compare -->|match| Digest
    Compare -->|mismatch| Reject
    Digest -->|match| Result
    Digest -->|mismatch| Reject
Loading

File-Level Changes

Change Details Files
Advance the code and spec submodules to their new main-tip commits while keeping each gitlink, commit pin, and tree digest synchronized.
  • Move the code gitlink and update its pinned commit and SHA-256 tree digest.
  • Move the spec gitlink and update its pinned commit and SHA-256 tree digest.
  • Leave provenance, shape, manifest, workflow, and other root metadata unchanged.
code
contracts/code-pin.yaml
spec
contracts/spec-pin.yaml
Update both assembly legs to include the corresponding implementation and specification work for the next openDox sections.
  • Bring in nine code commits covering runtime, repository creation, FLOOR Part 3, § 5.4(d), display/binding fixes, and retired tests.
  • Bring in eight spec commits covering the four § 6.2–§ 6.5 re-homes plus front-end boundary and § 3.4 design notes.
code
spec
Validate the lockstep pin invariants and independently verify the new repository tree digests.
  • Confirm gitlinks match pin-file commits and recomputed local and forge tree digests.
  • Confirm repository naming, manifest, and pin validation pass, including the negative mismatch control.
  • Confirm no workflow leg references or neutral-product pins require updates.
contracts/code-pin.yaml
contracts/spec-pin.yaml
scripts/validate-pins.py
scripts/repo_shape.py

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@sonarqubecloud

Copy link
Copy Markdown

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

Pin metadata and digests are synchronized, with validation reported green.

Review effort: Lite
Findings: None

What changed in this PR

Advances the openDox assembly’s code and spec legs to validated commits with synchronized tree digests.

Changes:

  • Updates the spec commit and tree digest.
  • Updates the code commit and tree digest.
  • Preserves pin lockstep validation.
File Summary
contracts/​spec-pin.yaml Records the new spec commit and tree digest.
contracts/​code-pin.yaml Records the new code commit and tree digest.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@brettheap

Copy link
Copy Markdown
Contributor Author

GATE EVIDENCE at 2c6b702ece68983d19cb4a8f7011ad1cad1cb657, measured 2026-09-19T01:36Z

check conclusion
validate (the required check) success run 35413089880
SonarCloud Code Analysis success dashboard
copilot-pull-request-reviewer success run 35413095696
Sourcery review skipped see below

MERGEABLE / CLEAN, not a draft. One commit on the branch, authored by the
operator; no bot commit appeared on it.
Local head == remote head. The
forge's own file list is the four paths and no fifth: code, spec,
contracts/code-pin.yaml, contracts/spec-pin.yaml.

Review: 0 threads, 0 unresolved. Copilot's review 5254012087 reads
"🟢 Approval recommended — Pin metadata and digests are synchronized, with
validation reported green"
, Findings: None.

Sourcery's skipped is a budget exhaustion, not a verdict. Review
5254009345 reads "you've used your own review budget of 250,000 diff
characters for the last 7 days"
— it reviewed nothing and found nothing.
Recorded so the skip is not later read as a silent pass on this repository's
behalf. The same skip is on opensoft/openXdox#12.

@brettheap
brettheap merged commit d05e204 into main Sep 19, 2026
4 checks passed
@brettheap

Copy link
Copy Markdown
Contributor Author

Lane: openxfactory-4 (openXfactory-4-openDox_extraction)

LANDED — lane openxfactory-4, 2026-09-19T01:38:56Z, PR #10 → d05e204 (opensoft/openDox main; plain gate)

openDox root: bump code to d816cf06 (§ 3.5 runtime, § 3.6 creation, § 3.7 FLOOR PART 3, § 5.4 (d)) and spec to 8fe8c4c7; pins + tree digests recomputed by two independent paths; claim 5738280604; three-repository lockstep with openxFactory registered

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants