openDox root: bump code to d816cf06 (§ 3.5 runtime, § 3.6 creation, § 3.7 FLOOR PART 3, § 5.4 (d)) and spec to 8fe8c4c7 (four of the five § 6 re-homes) - #10
Conversation
… 3.7 FLOOR PART 3, § 5.4 (d)) and spec to 8fe8c4c7 (four of the five § 6 re-homes) Lane: openxfactory-4 (openXfactory-4-openDox_extraction) Refs opensoft/openxFactory#656 (stays OPEN). CLAIM: 5738280604. Runbook Phase 3 (`docs/opendox-cutover-runbook.md`:1812, "the assembly roots: `carved_from` + gitlink + pin, ONE COMMIT"), the second and last of the pair — opensoft/openXdox#12 is the first. Both legs advance in the one commit, with both halves of each pin: code 0b4e8bbf -> d816cf06 contracts/code-pin.yaml commit + tree_sha256 spec a8f5eb73 -> 8fe8c4c7 contracts/spec-pin.yaml commit + tree_sha256 Four paths, no fifth. Each leg commit is that repository's main tip, measured at 2026-09-19T01:31Z rather than carried forward; `git -C code cat-file -t d816cf06` and `git -C spec cat-file -t 8fe8c4c7` both print `commit` (the runbook's :1825-1830 pre-push check - git stores a gitlink without checking the object is present, so a wrong pin commits and pushes clean), and both equal `origin/main` in their own repository. WHAT `code` CROSSES, nine commits - 64 files, 37529 insertions, 1358 deletions: d816cf0 § 3.6 follow-up #2: a linked worktree's metadata, and a store refusal that is a refusal (openDox-code#32) 93ccc3d § 3.7 FLOOR PART 3, openDox side: the declared conformance factory and Q-F1's transposition (#31) 5c86713 § 3.6 follow-ups: the seven findings #26 registered, each with its case (#30) 373b05a § 5.4 FLOOR PART 2 clause (d), openDox leg: the collection triple pinned on the required check (#29) 4f8ae01 § 3.6: openDox creates a repository as a first-class act, with RULING C3's conformant local-git adapter (#26) aca94ec § 3.5: the openDox runtime - FastAPI + Postgres, identity and coordination, and nothing else (RULED Q1/Q2) (#25) 52b237e § 3.4 S7 residue: thread the display facet to the seven leaves it never reached (#28) 5c137a9 § 3.4 RULED Q7: a contributed binding's CSS leaves styles.css for the binding's own sheet (#27) 0e65b5f Retire the two intent-feed DOM suites at this leg (#24) WHAT `spec` CROSSES, eight commits - 15 files, 3636 insertions, 0 deletions: 8fe8c4c § 6.2 the surviving -v2 chat-turn family (openDox-spec#15) 66d5977 § 6.5 add-lens-document-selection, the set-builder half (#14) 3b7f80c § 6.3 add-doxchat-model-intake, the model plane (#13) edeed08 § 6.4 add-composed-view-authoring, openDox's first OpenSpec change (#12) 54e9107 Front-end boundary note, amendment #3 (#11) 7d12428 Front-end boundary note, amendment #2 (#10) 61866d2 § 3.4 boundary note: the five rulings Q1-Q5 and the S1-S3 start (#9) a44ac06 § 3.4 design note: the front-end package boundary (#8) TAKEN WITH #12, THIS PAIR IS THE FIRST MOMENT BOTH ROOTS NAME ALL FIVE § 6 RE-HOMES: § 6.1's refresh lane is openXdox-spec f088b097, pinned by #12; § 6.2, § 6.3, § 6.4 and § 6.5 are openDox-spec 8fe8c4c7, pinned here. THE THIRD FACT-CLASS IS VACUOUS HERE, MEASURED RATHER THAN ASSUMED. The lockstep rule is gitlink + pin-file `commit:` + EVERY `.github/workflows/*.yml` `<org>/<leg>@<sha>` reference. This root has one workflow and one 40-hex `@sha` in it - `actions/create-github-app-token@fee1f7d63c2ff003460e3d139729b119787bc349` (validate.yml:104) - which names neither leg, so there is no third fact to move and `validate-pins.py` prints no "workflow @<sha> reference(s) agree" note. `neutral_product_pins: []` here, so there is no neutral-pin recheck either: FIVE `ok` lines rather than openXdox's six. A grep for the two outgoing shas across the whole tree finds them in exactly the two pin files and nowhere else. BOTH DIGESTS RECOMPUTED, BY TWO INDEPENDENT PATHS THAT AGREE. `sorted-ls-tree-r-v1`, from this repository's own `scripts/repo_shape.py`: code d816cf06 ac877e49b7ec001a22be21ce18021208e00f9d1d2c2ceb997b060a0b247fbcac spec 8fe8c4c7 f63c5b8fee6bf0fded4cb745555dea6427b274683c5d5bccac01c82e2b0fadbb `tree_digest()` reads the submodule's own object store; `tree_digest_from_gh()` reads the forge's recursive tree listing over the network. Both return the two values above character for character. Neither was retyped from anywhere. VERIFICATION, BEFORE AND AFTER, THE SAME FIVE LINES SO THEY COMPARE LINE FOR LINE. At root c4c5014 (before): `spec … a8f5eb73671c`, `spec … (658c034d6eba…)`, `code … 0b4e8bbf68fa`, `code … (db8817ddde1a…)`, the 10 shape files, `pins ok`, exit 0. After: the same five with `8fe8c4c71c4d` / `(f63c5b8fee6b…)` / `d816cf06f1c9` / `(ac877e49b7ec…)`, `pins ok`, exit 0. `make validate` - naming + manifest + pins, what CI runs - is green end to end: naming exit 0, `manifest ok: openDox (opendox), 3 legs`. NEGATIVE CONTROL, so the green is not read as vacuous. With the gitlink moved and `contracts/code-pin.yaml` left at the old commit in the working tree, the same command exits 1 with TWO findings - `pin-gitlink-mismatch` (`d816cf06… != 0b4e8bbf…`) and `pin-digest-mismatch` (recorded `ac877e49…`, recomputed at `0b4e8bbf…` `db8817dd…`) - and the file was then restored from the index and re-verified green. WHAT DELIBERATELY DOES NOT MOVE. `contracts/manifest.yaml` `carved_from` = `{opensoft/openxFactory, b075fd91dc8fced8e1373825ba80220c33536bae}` - the CARVE commit, a provenance record of an event (§ 1.1), not a pin that tracks a head; the runbook's item (3) was discharged by the commit that wrote it. `contracts/shape-pin.yaml`, `project.yaml`, every other file. THE DOWNSTREAM CONSEQUENCE, MEASURED. openxFactory pins openDox DIRECTLY (`contracts/opendox-pin.yaml` = c4c5014, `openDox` gitlink = c4c5014) and openXdox's root pins it too (c4c5014). `verify-opendox-pin.py` check 5 compares those two declarations TO EACH OTHER, not to openDox's current head, so this advance breaks nothing: openxFactory continues to pin an older openDox root, which is what a pin is for. REGISTERED as the follow-up, not taken here: advancing openxFactory to this new root is a THREE-repository lockstep - openxFactory's `openDox` gitlink, openxFactory's `contracts/opendox-pin.yaml`, and openXdox's `contracts/opendox-pin.yaml` (read as a BLOB at whatever commit openxFactory's `openXdox` gitlink names) must all name the same openDox commit in one landing, or check 5 refuses `opendox-pin-lockstep-mismatch`. Lane: openxfactory-4 Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
There was a problem hiding this comment.
Sorry @brettheap, you've used your own review budget of 250,000 diff characters for the last 7 days.
You can request another review in 2 days and 17 hours by commenting @sourcery-ai review. Upgrade to get a review now.
Reviewer's guide (collapsed on small PRs)Reviewer's GuideThis Phase 3 pin commit advances the openDox code and spec assembly roots together, updates their lockstep commit and tree-digest declarations, and preserves all unrelated provenance and root metadata. The reported local/forge digest checks and validation suite demonstrate that both legs are synchronized and that mismatched pins are rejected; no release tags or downstream openXfactory pins are changed. Flow diagram for lockstep pin validationflowchart TD
Start[Updated gitlinks and pin files]
Check[validate-pins.py]
Compare[Compare gitlink commit and pinned commit]
Digest[Recompute tree_sha256]
Result[ pins ok ]
Reject[Reject with pin mismatch findings]
Start --> Check
Check --> Compare
Compare -->|match| Digest
Compare -->|mismatch| Reject
Digest -->|match| Result
Digest -->|mismatch| Reject
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
|
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
Pin metadata and digests are synchronized, with validation reported green.
Review effort: Lite
Findings: None
What changed in this PR
Advances the openDox assembly’s code and spec legs to validated commits with synchronized tree digests.
Changes:
- Updates the spec commit and tree digest.
- Updates the code commit and tree digest.
- Preserves pin lockstep validation.
| File | Summary |
|---|---|
contracts/spec-pin.yaml |
Records the new spec commit and tree digest. |
contracts/code-pin.yaml |
Records the new code commit and tree digest. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
GATE EVIDENCE at
|
| check | conclusion | |
|---|---|---|
validate (the required check) |
success | run 35413089880 |
| SonarCloud Code Analysis | success | dashboard |
| copilot-pull-request-reviewer | success | run 35413095696 |
| Sourcery review | skipped | see below |
MERGEABLE / CLEAN, not a draft. One commit on the branch, authored by the
operator; no bot commit appeared on it. Local head == remote head. The
forge's own file list is the four paths and no fifth: code, spec,
contracts/code-pin.yaml, contracts/spec-pin.yaml.
Review: 0 threads, 0 unresolved. Copilot's review 5254012087 reads
"🟢 Approval recommended — Pin metadata and digests are synchronized, with
validation reported green", Findings: None.
Sourcery's skipped is a budget exhaustion, not a verdict. Review
5254009345 reads "you've used your own review budget of 250,000 diff
characters for the last 7 days" — it reviewed nothing and found nothing.
Recorded so the skip is not later read as a silent pass on this repository's
behalf. The same skip is on opensoft/openXdox#12.
|
Lane: openxfactory-4 (openXfactory-4-openDox_extraction) LANDED — lane openxfactory-4, 2026-09-19T01:38:56Z, PR #10 → d05e204 (opensoft/openDox main; plain gate) openDox root: bump code to d816cf06 (§ 3.5 runtime, § 3.6 creation, § 3.7 FLOOR PART 3, § 5.4 (d)) and spec to 8fe8c4c7; pins + tree digests recomputed by two independent paths; claim 5738280604; three-repository lockstep with openxFactory registered |



Lane: openxfactory-4 (openXfactory-4-openDox_extraction)
Refs opensoft/openxFactory#656 (stays OPEN). CLAIM: 5738280604.
Runbook Phase 3 —
docs/opendox-cutover-runbook.md:1812, "the assemblyroots:
carved_from+ gitlink + pin, ONE COMMIT". The second and last of thepair; opensoft/openXdox#12 is the first.
What moves — four paths, no fifth
commit:digests.tree_sha256:code0b4e8bbf…→d816cf06f1c9752a39c2b71ba40adc4ae3f3bf66db8817dd…→ac877e49b7ec001a22be21ce18021208e00f9d1d2c2ceb997b060a0b247fbcacspeca8f5eb73…→8fe8c4c71c4da8d363394441ad9e2c9547e540a3658c034d…→f63c5b8fee6bf0fded4cb745555dea6427b274683c5d5bccac01c82e2b0fadbbEach target is that repository's
maintip, measured at 2026-09-19T01:31Zand not carried forward. The runbook's pre-push object check (:1825-1830 — git
stores a gitlink without checking the object is present, so a wrong pin commits
and pushes clean):
git -C code cat-file -t d816cf06…andgit -C spec cat-file -t 8fe8c4c7…both printcommit, and both equalorigin/mainintheir own repository.
What the advance carries — the largest of the arc
code, nine commits (64 files, 37 529 insertions, 1 358 deletions):d816cf093ccc3d5c86713373b05a4f8ae01aca94ec52b237e5c137a9styles.cssfor the binding's own sheet (#27)0e65b5fspec, eight commits (15 files, 3 636 insertions, 0 deletions):8fe8c4c-v2chat-turn family (openDox-spec#15)66d5977add-lens-document-selection, the set-builder half (#14)3b7f80cadd-doxchat-model-intake, the model plane (#13)edeed08add-composed-view-authoring, openDox's first OpenSpec change (#12)54e91077d1242861866d2a44ac06Taken with openXdox#12, this pair is the first moment BOTH roots name all five
§ 6 re-homes: § 6.1's refresh lane is
openXdox-specf088b097, pinned by#12; § 6.2–6.5 are
openDox-spec8fe8c4c7, pinned here.The third fact-class is VACUOUS here, measured rather than assumed
scripts/validate-pins.pyholds gitlink + pin-filecommit:+ every.github/workflows/*.yml<org>/<leg>@<sha>reference as one invariant. Thisroot has one workflow and exactly one 40-hex
@shain it —actions/create-github-app-token@fee1f7d63c2ff003460e3d139729b119787bc349(
validate.yml:104) — naming neither leg, so there is no third fact to move andno "workflow @<sha> reference(s) agree" note is printed.
neutral_product_pins: []here, so unlike openXdox's root there is noneutral-pin recheck either: five
oklines, not six. A grep for the twooutgoing shas across the whole tree finds them in exactly the two pin files and
nowhere else.
Both digests recomputed, by two independent paths that agree
sorted-ls-tree-r-v1, via this repository's ownscripts/repo_shape.py—tree_digest()reads the submodule's object store,tree_digest_from_gh()reads the forge's recursive tree listing:
Neither was retyped from anywhere.
Verification — BEFORE and AFTER, the same five lines so they compare line for line
BEFORE, at root
c4c5014d9b39ac55e5df957db23a56db38847a6b, legs initializedwith
git submodule update --init code spec(never a baregit addof asubmodule):
exit 0.
AFTER, at this branch's head:
exit 0.
make validate— naming + manifest + pins, what CI runs — is green end toend:
validate-repository-naming.pyexit 0 (openDox neutral-product/assembly,openDox-spec project-leg/spec,openDox-code project-leg/code),validate-manifest.pymanifest ok: openDox (opendox), 3 legs,validate-pins.pypins ok.Negative control — so the green is not read as vacuous
With the gitlink moved and
contracts/code-pin.yamlleft at the old commit inthe working tree, the same command exits 1 with two findings:
Restored from the index and re-verified green. The arm that has to fire, fires.
What deliberately does NOT move
contracts/manifest.yamlcarved_from={opensoft/openxFactory, b075fd91dc8fced8e1373825ba80220c33536bae}— the CARVE commit, a provenancerecord of an event (runbook § 1.1), not a pin that tracks a head; the runbook's
item (3) was discharged by the commit that wrote it. Also
contracts/shape-pin.yaml,project.yaml, and every other file.The downstream consequence, measured
openxFactory pins openDox directly (
contracts/opendox-pin.yaml=c4c5014d…,openDoxgitlink =c4c5014d…) and openXdox's root pins it too(
c4c5014d…).verify-opendox-pin.pycheck 5 compares those twodeclarations to each other, not to openDox's current head — so this advance
breaks nothing: openxFactory continues to pin an older openDox root, which is
what a pin is for.
Registered as the follow-up, not taken here: advancing openxFactory to this
new root is a three-repository lockstep — openxFactory's
openDoxgitlink,openxFactory's
contracts/opendox-pin.yaml, and openXdox'scontracts/opendox-pin.yaml(read as a blob at whatever commitopenxFactory's
openXdoxgitlink names) must all name the same openDox commitin one landing, or check 5 refuses
opendox-pin-lockstep-mismatch.Sequencing, and what this PR is not
This is the Phase 3 pin act. § 3.8 (
tasks.md:1517-1521) and § 4.6(
tasks.md:2049-2050) cutdox-v1.0/xdox-v1.0in the assembly root,"over the commit that names both legs" — this commit is the first one that
names the landed legs. It cuts nothing: runbook § 9, Phase 6 (:2000) — "the
tags (§ 3.8 and § 4.6). BRETT'S ACT, ALWAYS."
Sibling search before authoring:
gh pr list --repo opensoft/openDox --state openreturned zero open pull requests at 2026-09-19T01:31:12Z.🤖 Generated with Claude Code
Summary by Sourcery
Advance the openDox assembly's code and spec legs to their new validated commits and synchronized tree digests.
Enhancements:
Chores: