Skip to content

T061, the consumer's validator located through the installed distribution (7.3) (plan 034) - #36

Merged
brettheap merged 45 commits into
mainfrom
build/034-p2c-t061-installed-validator
Sep 30, 2026
Merged

brettheap merged 45 commits into
mainfrom
build/034-p2c-t061-installed-validator

Conversation

@brettheap

@brettheap brettheap commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Lane: openxfactory-4 (openXfactory-4-openDox_extraction)
Arc: neutral-product-standalone-operability

Plan 034 T061 (P2-C), in openxFactory specs/034-opendox-standalone-operation/: #1144 7.3, the consumer's half.

"openXdox's validator and its three schemas (7.1's openXdox-spec three) are located through the INSTALLED openXdox distribution, and no parent walk remains." (RULED R1Q14 (a))

As T007's batch I amends it (R1Q27 (a), opensoft/openxFactory#656 comment 5851950767), the validator validates:

  • its own three kinds from its installed distribution, wherever it runs;
  • the family's other seven kinds only where the running tree supplies them, reading that tree's own contracts/ first.

Based on main. Every gate this PR named has landed:

This PR stays DRAFT until the holder marks it READY.

The merge from main. A plain merge met T059's files twice: once as this branch's own history of them (it was stacked on 4feb8009) and once as #35's squash. That gave add/add and content conflicts in twelve files. The merged tree is therefore the three-way merge of this branch and aa0a2c5d, with 4feb8009 as the base (git merge-tree --merge-base=4feb8009), and it merges cleanly:

The merge commit's parents are this branch and main.

What changes

1. The validator and its own three schemas ship as package data (openxdox.contracts, new).

  • schemas/: the three schemas, byte copies of opensoft/openXdox-spec at f088b097. That is the commit the openXdox root pins, through its spec gitlink and contracts/spec-pin.yaml at main 57e2b8f2.
  • copies.yaml: records each copy's sha256. These are the digests the root's contracts/manifest.yaml records.
  • validate-ideation-dashboard-contracts.py: byte for byte the same as scripts/validate-ideation-dashboard-contracts.py. A test holds the two equal.
  • A copy is read only after its digest is checked against the record. The pattern mirrors openDox's T057 (openDox-code#58).
  • The pyproject.toml package-data line ships the record, the three copies and the validator, and nothing else. I measured this by building a wheel with and without the line. Without it, the wheel carries only the package's two .py files, and neither the record nor any copy.

2. The validator finds each schema in one of three places, in this order.

  • First, the running tree's own contracts/schemas/, as before. openxFactory's farm composes the whole family that way. The packaged validator also finds its copies this way, since they sit beside it.
  • Second, for the three only: the installed distribution, found through importlib.util.find_spec("openxdox.contracts"), never by position.
  • Third, for the other seven only: CONTRACTS_DIR. It never supplies the three.

A copy that differs from its record is refused by name with a harness error (exit 2) and is never read.

2a. A packaged copy is held to its record, fail closed.

  • The packaged layout is recognized by where the script sits, inside the contracts/ it reads, never by whether copies.yaml is present. A missing record or copy there is refused with exit 2.
  • The script checks the whole record against the same contract as openxdox.contracts.record() before it takes any digest.
  • An installed validator that links out of its package is never run, in both snapshot._packaged_validator and contracts.validator_path. That follows Copilot's review.

3. find_validator ignores start.

  • It keeps its declared signature, because openDox's consumer_reach binds it by name.
  • From this product's source tree, it answers the tree's scripts/ validator. That is the path openxFactory's lanes read.
  • From an install, it answers the packaged copy.
  • An enclosing tree's validator is never adopted.
  • A start outside the tree is validated. Before, it was confined to None. This supersedes split-opendox 8.9 residue (iii) (Resolve the snapshot validator and its schemas in this product's own tree (split-opendox § 8.9 residue (i)-(iii)) #28) for the start.
  • GovernedValidator.locate asks once, with no start.

4. The runtime dependencies gain referencing>=0.28.4 and rfc3339-validator>=0.1.4. Brett ruled "Keep as runtime deps" at opensoft/openxFactory#656 comment 5916000030.

  • The package now ships a validator that imports referencing at module level.
  • The validator refuses to run without rfc3339-validator, because jsonschema registers its date-time checker only when that package is importable.
  • Without both, a plain install would carry a validator it cannot run.
  • Proof, from F7.1's own fresh environment: with rfc3339-validator left undeclared, F7.1 goes red. test_the_validator_is_the_installed_consumers_own reads validator-unavailable: "ERROR jsonschema is missing its date/date-time format checkers; install rfc3339-validator".
  • referencing>=0.28.4 is the floor that jsonschema>=4.18 itself requires (checked on PyPI), so declaring it adds nothing to an install.
  • rfc3339-validator leaves the test extra.
  • tests/test_dependency_direction.py now names each .py under src/ that is not a module, and holds its imports to the declared dependencies.

5. The allow-list check (batch C's, which T059 wired) learns two things.

  • An added test (batch F's rule). Where the named test is absent before the landing, new must be old, then that test's whole definition and blank lines, and nothing else.
  • A chain of entries, for F5.2's call alone. This follows the holder's decision under Brett's ruling at comment 5916000030, which batch K records.
    • One landing that edits one suite in several tests enters each edit as its own entry. The entries apply in list order, each to the text the one before it leaves.
    • The first entry's before_blob is the suite before the landing, and the last entry's after_blob is the suite at it. Each entry in between records the git blob id of the text it leaves.
    • Each entry holds on its own texts, inside its own test, and all of them name one landing.
    • The flag is --chains. F5.2's call passes it; 12.5's call does not, and keeps one entry per suite per landing.
    • Neither of the two suites is among 12.5's sixteen governed files. I checked with git grep -l -e open-pr -e open_pr -e FakePullRequests -- 'tests/test_*.py' at main and at this head: the same 16 files both times.
    • A new case shows 12.5's call refusing a chain that F5.2's call admits.

The protected edits, each in its own commit, each an allow-list entry

commit suite :: test admitted by
3dc4a4c tests/test_snapshot.py::test_the_validator_is_the_installed_consumers_own (added) batch F (R1Q14 (a))
08b03b9 tests/test_snapshot_validator_home.py::test_a_start_outside_the_product_is_refused_not_walked (its answer is now 7.3's) batch F
5c2ef23 the nine tests of tests/test_snapshot_validation_launch.py batch K (Brett, comment 5916000030)
8a89bc7 tests/test_snapshot.py::test_a_missing_validator_is_unavailable_not_a_verdict batch K

In the ten batch K cases the real assertions stay. Those are: SKIPPED on stderr naming both roots, the pip remedy, --strict fatal, a non-conformant snapshot blocked and blamed, and UNAVAILABLE rather than a verdict. Only the walk premise changes.

  • Each stub is now planted as the distribution's own validator: product_root is None and _packaged_validator is the stub, both set with monkeypatch, and the real find_validator answers it.
  • "No validator" is now a distribution that carries none of its own.
  • One expected answer inverts, as C3's did under batch F: test_a_run_dir_beside_a_checkout_still_uses_that_one_first. The validator beside the run dir is never adopted. Its name is kept, because an entry admits an edit inside one named test.
  • The launch suite's helper _corpus_with_a_reachable_validator sits outside every test, so no entry can admit an edit to it. It is unchanged, and its docstring's "where find_validator expects it" is now stale. That is recorded here rather than edited.

The allow-list entries themselves are in the commit after the PR number was known. There are twelve:

  • batch F's two;
  • batch K's ten, as a chain of two for tests/test_snapshot.py and a chain of nine for the launch suite.

The declared exclusion: 66 → 65

tests/test_snapshot.py leaves, and its reason, consumer-schemas (R1Q25 (b), "until 7.3 finds them through the installed distribution"), leaves with it. The suite now passes alone, 18 of 18.

  • tests/test_snapshot_validation_launch.py keeps its doc_health entry. Alone, all nine of its tests fail for doc_health only. Composed, the suite goes from 5 failed and 4 passed to 9 passed.
  • The root conftest's table of admitted reasons keeps R1Q25 (b)'s row. A reason leaves the declaration, not the record of what the rulings admitted.

Single-writer order of tests/declared_exclusion.yaml: T044 → T059 → T061.

  • T044 wrote the doc_health skips into a declared file.
  • T059 removed seam_assembly (67 → 66).
  • T061 removes tests/test_snapshot.py (66 → 65).

No other open PR touches the file.

For T008: excluded files that validate a kind the narrowed validator gives up

In a lone checkout, with no contracts/ of its own and no CONTRACTS_DIR, the validator now validates only its three kinds. These files validate one of the other seven kinds. I measured the first two with a temporary trace of the validator's calls, whole suite and composed; the trace has been reverted. I read the rest from content.

file declared reason kind(s) given up
tests/test_notebook_action.py doc_health ideation-workbench
tests/test_register_edit_lane.py doc_health project-register
tests/test_validate_ideation_dashboard_contracts.py openxfactory-contracts workbench-model-catalog, workbench-chat-turn-v2
tests/test_project_action_contracts.py openxfactory-contracts gate-intent
tests/test_wheel_action_contracts.py openxfactory-contracts gate-intent
tests/test_project_schema_election.py openxfactory-contracts project-register
tests/test_doxbench_blank_reason.py doc_health, openxfactory-contracts workbench-chat-turn-v2

Also:

  • tests/test_aggregation_register_instance.py is not excluded. It validates project-register and skips alone; those are the four EXPECT_SKIPPED cases.
  • The other declared validator users validate only the three kinds, so the narrowing gives up nothing there: test_generator, test_generated_at_anchor, test_snapshot_determinism, test_snapshot_registry, test_doxbench_share, test_kickoff and test_session_records.

Falsifiers, before and after

F7.1, exactly as #1144 writes it:

  • The block ran verbatim: a fresh venv, pip install ".[test]", the planted pre-shed tree, and both named tests.
  • The host has no python, so a shim maps it to /usr/bin/python3 3.12.3 for the block's first line. After activation, python is the venv's.
  • Before, at T059, openXdox contributes its governed generator, registry and source through openDox's seams (5.4a) (plan 034) #35's head 4feb8009: rc 1, AssertionError: the consumer found no validator of its own. The two named tests do not exist yet (pytest rc 4).
  • After: rc 0, 2 passed. The install is non-editable (direct_url dir_info {}). find_validator() answers site-packages/openxdox/contracts/validate-ideation-dashboard-contracts.py, and product_root() is None.

F5.2 whole, exactly as #1144 writes it with no deselect, in batch G's environment, at the merged tree (e3985b91). The simulated history is main with #35's real landing 839492d9, then this PR squash-landed. The results equal those at the earlier tree (34dc603, openDox-code 814516b7).

  • The environment: a fresh venv, then pip install ".[test]", then openDox-code 047bb4fa force-reinstalled, with openxFactory 91e4685f scripts/ on PYTHONPATH.
  • Suites: test_generator 45/45, test_snapshot 18/18, test_snapshot_determinism 6/6, test_snapshot_registry 40/40, test_snapshot_validation_launch 9/9 and test_snapshot_validator_home 12/12.
  • test_session_snapshot is 20 passed, 3 failed. The 3 are exactly the holder's ruled pre-arc reds ("red at both pins; pre-arc carve residue; not the arc's"), left open for F5.2 whole at T063: test_a_new_serve_process_re_registers_the_session_at_startup, test_a_session_key_is_validated_against_the_roster_before_url_composition and test_the_hosted_session_arrival_path_is_recorded_and_not_built.
  • Every deselect T059's F5.2 run needed besides those 3 is now gone. Those were test_snapshot's 2 and the 7 reds that failed at both pins in test_generator, test_snapshot_determinism and test_snapshot_registry.
  • The arc check: F5.2's step (--chains) runs over the arc's landings. It admits all four protected suites: 839492d9 (T059, openXdox contributes its governed generator, registry and source through openDox's seams (5.4a) (plan 034) #35's real landing) for test_session_snapshot by entry 3, and this PR's simulated landing for test_snapshot by the chain 4, 5, for test_snapshot_validator_home by entry 6, and for the launch suite by the chain 7-15. It exits 0. The entries needed no re-recording, because T059, openXdox contributes its governed generator, registry and source through openDox's seams (5.4a) (plan 034) #35 does not touch these three suites.
  • 12.5's call, without --chains, exits 0 over its governed set.
  • F5.2's call without --chains refuses both chains (exit 1).

Whole suite alone (CI's command):

  • validate run 36759713758 at 708cdd27 read selected 1076, passed 1072, skipped 4, failures 0, errors 0. The floors were set to 1076 and 1072, on that reading (71187f7).
  • At the merged head 8d891652, with openDox-code 047bb4fa, run 36784210624 reads the same triple. So the floors stand, and the floor paragraph records it (5c2b134).
  • The declared exclusion is 65 files.

Composition, 38 suites (the protected 23, the 12.5 set, and every validator user), each run alone with openxFactory scripts/ on PYTHONPATH, #35's head against this one: 0 newly red, 24 newly green. It was measured at openDox-code 814516b7, and measured again at 047bb4fa as main (839492d9's tree) against the merged head, with the same result. The newly green cases include test_generator's 4, test_snapshot_determinism's 1 and test_snapshot_registry's 2 (the reds at both pins), test_snapshot's 2 schema cases, the launch suite's 4, and the validator users in test_doxbench_share, test_kickoff, test_session_records and test_generated_at_anchor.

Mutants of the new checks: 29 of 29 killed at 29f058e, and again at the merged head 8d891652. They cover:

  • the lookup: C3's confinement back, the pre-shed walk back, no packaged validator, a packaged validator linking out, and locate reading the roots;
  • the validator: digest not compared, CONTRACTS_DIR supplying the three, no distribution lookup, the packaged layout told by its record, and the record's spec leg, row path and fourth kind;
  • openxdox.contracts: five record and digest checks, and validator_path following a link;
  • the package-data line, and referencing undeclared;
  • a hyphenated module hiding from the census;
  • the added-test rule (three mutants) and the chain (five mutants).

The mutant that drops rfc3339-validator from the dependencies survives the unit suite. F7.1 kills it, as shown above.

The review rounds:

  • SonarCloud's gate failed at 8015a565 on 63.1% duplication and a C security rating, both from the packaged validator copy. .sonarcloud.properties now excludes that copy, so the validator is analysed once, at scripts/, and this PR's own smells are taken. The gate has been green since bbe17165.
  • Copilot, at five heads. What was taken:
    • the entries were entered;
    • the packaged layout now fails closed when its record or a copy is missing;
    • an installed validator that links out of the package is refused, in find_validator and in validator_path;
    • the script holds copies.yaml to the package's full contract, with every one of the package's 15 record refusals run through the installed validator;
    • two stale docstrings, in the launch suite and build_registry, and one diagnostic were corrected.
    • All threads are resolved.

Owed elsewhere

T064's created: admissions (openxFactory's carve manifest records what leaves openxFactory; these files were created here, RULED OQ-C):

  • src/openxdox/contracts/__init__.py, copies.yaml, schemas/*.schema.yaml (3) and validate-ideation-dashboard-contracts.py;
  • tests/test_packaged_validator.py;
  • together with T059's (src/openxdox/projection_contributions.py, scripts/protected_suites.py, tests/test_projection_contributions.py, tests/test_protected_suite_check.py, tests/test_governed_registry_and_writer.py) and the allow-list, tests/protected_suite_respellings.yaml.

Not changed: tests/conftest.py::find_openxfactory_validator keeps its fallback walk. It is a test helper, not 7.3's lookup, and here it always returns the tree's own scripts/ validator first, so the walk is never reached.

🤖 Generated with Claude Code

brettheap and others added 30 commits September 30, 2026 00:46
…an 034 T059

T059 moves the opendox pin to the phase-2 openDox-code commit (5.4a, 9.5 step
3). That commit is T062's, and it lands after every phase-2 openDox-code
landing, so this draft builds against openDox-code#59's head, the last of the
seams T059 registers at, and re-points to T062's commit before it lands.

The comments that named the old pin as the one this leg declares are brought
to the new one, each measured there: ViewBinding at e3ef506a still has styles
and exports (dataclasses.fields in a venv at that pin), and the tuple and
helpers tests/integration/test_assembled_bundle.py copies are unchanged
between 2d116415 and e3ef506a.

Lane: openxfactory-4 (openXfactory-4-openDox_extraction)
Arc: neutral-product-standalone-operability
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…e registered (plan 034 T059)

openDox's own defaults sealed each of these in openDox-code#59's review rounds,
and #59's body names them as openXdox-code's to seal before T059 registers
this leg's mechanisms at the same seams:

1. snapshot_registry.resolve_within applied the hidden-name rule only to the
   path as the URL spells it, so a symlink inside the root led to what the
   rule refuses by name (r4125556296). It now applies the rule to the
   canonical path too.
2. SnapshotRegistry.drop left the active key naming a dropped entry, which
   also kept every later entry from becoming active. Dropping the active
   entry now clears the key.
3. snapshot.write_snapshot wrote in place (r4126138808), and canonical_json
   wrote NaN and Infinity (r4125900060). The write now goes to an exclusive
   temporary sibling, keeps the target's permission bits, is fsynced, and
   moves over the target in one os.replace; a value JSON cannot carry is
   refused as SnapshotNotWritable, a ProjectionSeamError, with nothing
   written.
4. SnapshotRegistry read without its lock (r4136863481). Every read now
   holds it.

snapshot_registry also reads doc_health's pin_sentinels where it writes the
sentinel, in SnapshotEntry.index_entry, rather than at module level, so the
registration at openDox's registry seam can be made in a lone checkout.

tests/test_governed_registry_and_writer.py holds each gap, red before this
commit.

Lane: openxfactory-4 (openXfactory-4-openDox_extraction)
Arc: neutral-product-standalone-operability
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ugh openDox's seams (plan 034 T059, 5.4a)

The governed half of R1Q10 (a). openxdox.projection_contributions registers
openXdox's generator at opendox.generator_seam, and its snapshot registry,
corpus-root predicate, writer and validators for the three governed kinds at
opendox.projection_seams. openXdox keeps generator.py, snapshot.py,
snapshot_registry.py, completeness.py and corpus_root.py; the contributions
reach generator, corpus_root and completeness, which read openxFactory's
doc_health at module level, only when they are used.

register() is explicit, idempotent, and all or none: a seam's refusal takes
back every seam it wrote, in reverse, and reaches the caller.
openxdox.domain_profile.register() calls it; load() registers nothing. This is
the holder's ruling on T059 (option (c)): a host that registers openXdox's
profile with openDox alone, as openxFactory does, calls register() itself,
which is T064's one line in openxFactory's opendox_host.register_openxfactory().

tests/test_generated_at_anchor.py patched snapshot._locate_validator, which
openDox's generate verb no longer reaches; it now patches the registered
validator's locate().

tests/conftest.py registers the home corpus openxFactory's host registers
(corpus_adapter_openxfactory.home_corpus) where F5.2's environment composes
openxFactory's scripts/, and nothing where it is absent, as #1144's 4.1a has
every seam refuse unregistered (holder's ruling on T059).

The ratchet is lowered for T055's reaches: cli and serve leave
OPENDOX_BACK_IMPORTS, and branch_session goes to (0, 2). snapshot_registry's
doc_health read is deferred, so DOC_HEALTH_SURFACE records it as (0, 1).

Lane: openxfactory-4 (openXfactory-4-openDox_extraction)
Arc: neutral-product-standalone-operability
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
tests/test_seam_assembly_beside_gate_and_projection.py was declared under
doc_health (R1Q6 (d)) by T044 because serve_projection reached doc_health
through snapshot_registry at import. That read is now deferred to where the
sentinel is written, so the file passes alone in a lone checkout, and T041's
test_declared_exclusion would refuse it as declared. Its entry leaves (67 -> 66
files), and its six cases run in this leg's required check (holder's ruling on
T059). T059 joins the exclusion file's single-writer chain between T044 and
T061.

The four seam files' docstrings and validate.yml's paragraphs stop saying the
file is declared, and validate.yml's pin prose names the new openDox pin.

Lane: openxfactory-4 (openXfactory-4-openDox_extraction)
Arc: neutral-product-standalone-operability
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…rc check (plan 034 T059, T007 batch C)

F5.2 and 12.5's falsifier each end by refusing any protected suite an arc
landing touched. Batch C (RULED R1Q7 (a), openxFactory#656 comment 5817152735)
has the check subtract the edits entered in tests/protected_suite_respellings.yaml,
and only after validating that the landing's diff for that suite is exactly
the entry's recorded text.

scripts/protected_suites.py is that last step. The falsifier still lists the
landings and the protected suites; the script admits a touched suite only
where one entry holds at the landing (before and after blobs, old occurring
once and giving the after text byte for byte, and both inside the named
test), and exits 2, subtracting nothing, when the allow-list breaks its own
rules. tests/test_protected_suite_check.py holds each rule against scratch
histories. The allow-list's header now says who reads it and states the
named-test condition.

Lane: openxfactory-4 (openXfactory-4-openDox_extraction)
Arc: neutral-product-standalone-operability
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ond admitted edit (plan 034 T059)

At this pin openDox's SNAPSHOT_VALUES defaults are its neutral snapshot's
values (T054), so openXdox's DISPLAY facet's values block (T060) changes six
values.* leaves of the served display beside the four stage words and the
named absence. test_the_overlay_changes_four_words_and_the_named_absence_and_nothing_else
now expects eleven changed leaves, and no other assertion of the suite
changes (RULED R1Q26 (a), openxFactory#656 comment 5851950767, on R1Q11 (a),
comment 5850003126; batch I). The edit is entered in
tests/protected_suite_respellings.yaml with its reason, as an admitted edit,
in this pull request.

Lane: openxfactory-4 (openXfactory-4-openDox_extraction)
Arc: neutral-product-standalone-operability
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…055 moved (plan 034 T059, R1Q7 (a))

openDox-code#59 (T055) routes /source through resolve_source_path over the
resolved entry's own root (r4136863569), where the route used to call
self.source.registry.resolve_source. The test's expected call is respelled
to the route's one entry point, and its second assertion, that the
registry's resolve_source reaches resolve_within exactly once, is unchanged
(holder's ruling on T059). The respelling is entered in
tests/protected_suite_respellings.yaml in this pull request.

Lane: openxfactory-4 (openXfactory-4-openDox_extraction)
Arc: neutral-product-standalone-operability
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…d (plan 034 T059)

openDox-code#59 merged main a691e4e4 (T054, openDox-code#57) after this branch
pinned e3ef506a, so the pin follows it to 814516b7, and the comments that name
the pin follow it too. The pin is still a draft's: it re-points to T062's
commit before T059 lands.

Measured at 814516b7: ViewBinding has styles and exports; web/,
view_extension.py and tests/test_binding_stylesheets.py are unchanged from
e3ef506a; tests/test_consumer_reach.py is unchanged, so NEUTRAL_MODULES still
holds thirteen; the census returns the same three rows; and 2d116415..814516b7
is twenty-five first-parent commits. The whole suite reads the same at both
heads (967 passed, 4 skipped, 1 deselected).

Lane: openxfactory-4 (openXfactory-4-openDox_extraction)
Arc: neutral-product-standalone-operability
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… T059)

Entry 2 is batch I's second admitted edit, to the overlay test in
tests/test_gate_loop_views.py (R1Q26 (a)); it chains on entry 1, T060's,
from a56906c to a5ce00c. Entry 3 is the respelling in
tests/test_session_snapshot.py of the route's call into the confinement, as
T055 moved it (R1Q7 (a), r4136863569), from b5e1be0 to f78c445. Both name
#35, this pull request, since the landing's commit is
not known inside it (T019's rule).

scripts/protected_suites.py admits each at its commit on this branch, and
entry 1 at T060's landing.

Lane: openxfactory-4 (openXfactory-4-openDox_extraction)
Arc: neutral-product-standalone-operability
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…Cloud's analysis of #35 (plan 034 T059)

SonarCloud's quality gate failed #35 on Security Rating C, from one finding:
pythonsecurity:S8707, path injection through a CLI argument, at
protected_suites._lines, which opened whatever file argv named. The check
now opens no file a caller names. --landings and --suites each carry the
list itself, one item per line, and each item is held to its shape before
any of it reaches git: a landing is a full commit id, a suite is
tests/test_<name>.py in ASCII. An item of neither shape is refused with exit
2. The falsifier's call becomes
--landings="$(cat "$W/x-arc.txt")" --suites="$(cat "$W/gen-suites.txt")".
The one file read is still the allow-list, at its fixed path.

The same analysis flagged code smells, which are taken too:
- load_allow_list and check are split into named rule checks, which brings
  each under the cognitive-complexity limit;
- the character classes use \w and \d under re.ASCII;
- composite assertions are split in the three new test files;
- each pytest.raises block holds one call.

tests/test_protected_suite_check.py gains the input-shape cases: a revision,
an option, a path outside tests/, and a non-ASCII name.

Lane: openxfactory-4 (openXfactory-4-openDox_extraction)
Arc: neutral-product-standalone-operability
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… of its own (plan 034 T059)

Two mutants of scripts/protected_suites.py survived the suite: skipping the
before-blob check, and skipping the check that the replaced text lies inside
the named test. Each was masked by its twin (the after-blob check, and the
replacement's check). New cases hold each side alone: an entry naming another
blob on either side; an edit whose replaced text is module code and whose
replacement becomes the test's last line; and the reverse, an assertion moved
out of the test.

Lane: openxfactory-4 (openXfactory-4-openDox_extraction)
Arc: neutral-product-standalone-operability
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…names, the schema integer, unsigned fixtures (plan 034 T059)

- r4139816732: SnapshotRegistry.index_document read the entries, the
  aggregates and the active key in three windows, so a writer between them
  could leave the index naming an active key its entries did not carry;
  compose_aggregate read _aggregates unlocked and looked each member up in a
  window of its own. Each is now one hold of the lock, with the document
  composed and the snapshots read after it. Two cases hold it, each running
  a writer on another thread between the reads; both are red before this
  commit.
- r4139816490: the arc check's git diff detected renames, so a protected
  suite renamed to an unprotected path showed only the destination and was
  never checked. It now diffs with --no-renames, and a case holds it.
- r4139816690: schema_version 1.0 passed, since 1.0 == 1. The check is now
  for the integer itself, and the rules' table gains the case.
- r4139816759: the scratch-repository fixture inherited the developer's git
  configuration, so commit.gpgsign=true failed every case. It passes
  -c commit.gpgsign=false, as tests/test_trust_gaps.py does. Under a signing
  configuration the file read 16 passed, 19 errors before, and 37 passed after.

Lane: openxfactory-4 (openXfactory-4-openDox_extraction)
Arc: neutral-product-standalone-operability
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…on (plan 034 T059)

Run 36655105352 measured c34c0dea, the head before this change, at
openDox-code 814516b7: selected 984, passed 980, skipped 4, failures 0,
errors 0. The +99 on both floors is T060's 11 (openXdox-code#34 named the
raise as the next writer's) and T059's 88: three new test files of 37, 26
and 20 cases, and the six seam-assembly cases that run here now that their
file left the declaration, less the declaration check's case for that file.
EXPECT_SKIPPED stays 4, the same four skips. The floors sit on the reading,
margin zero, as #25 set them (Copilot, r4139816631).

Lane: openxfactory-4 (openXfactory-4-openDox_extraction)
Arc: neutral-product-standalone-operability
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…lformed keys and edits refuse, the teardown rule stated (plan 034 T059)

Copilot's reviews at c34c0de and 1885aee listed three findings in their
overviews:
- Replay: an entry matched by suite, blobs and text could admit a second
  landing that repeated its edit after the suite came back to its
  before_blob. The check now takes the landings oldest first, whatever order
  they arrive in, and an entry that has admitted one is spent. Two cases
  hold it: X -> Y -> X -> Y with two entries refuses the third landing, and
  either input order gives the same answer.
- Malformed input: edit: [] reached a dict membership test and raised
  TypeError, and a mapping key that is itself a sequence did the same,
  instead of exit 2 with nothing subtracted. Both are AllowListInvalid now,
  and the rules' table gains both cases.
- Teardown: domain_profile.unregister() leaves the governed contributions
  registered. That is kept, and its docstring now says why: they are the
  process's, a host registers them without this module too (T064), and
  openDox's seams refuse a governed registration once a default has been
  read, so a teardown that took them back could not be undone.
  projection_contributions.unregister() is the teardown for them, and a case
  pins both halves.

The four checker cases are red before this commit and green after.

Lane: openxfactory-4 (openXfactory-4-openDox_extraction)
Arc: neutral-product-standalone-operability
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…4 T059)

Run 36733668958 measured 11c02cf, the head before this change, at
openDox-code 814516b7: selected 989, passed 985, skipped 4, failures 0,
errors 0. The five cases 11c02cf added (four in
tests/test_protected_suite_check.py, one in
tests/test_projection_contributions.py) take the raise from +99 to +104:
T060's 11 and T059's 93. The paragraph is restated with the new counts, and
the floors sit on the reading again, margin zero.

Lane: openxfactory-4 (openXfactory-4-openDox_extraction)
Arc: neutral-product-standalone-operability
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…eam-assembly file's docstring to its included state (plan 034 T059)

Copilot's review at 092bc8e listed two findings in its overview:
- resolve_within resolved the source root before its exception guard, so a
  root that is itself a symlink loop raised out of the /source route
  instead of refusing. The root is now resolved inside the guard, and a
  case holds it (red before this commit).
- tests/test_seam_assembly_beside_gate_and_projection.py still said, in two
  passages, that serve_projection reaches doc_health and that the module
  stops at its import. Both now say that was so from T044 to T059, and that
  the module imports and runs in the required check since T059.

Lane: openxfactory-4 (openXfactory-4-openDox_extraction)
Arc: neutral-product-standalone-operability
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… a protected-suite refusal (plan 034 T059)

Copilot's review at 62a1b0d4 listed one finding in its overview: a
well-formed commit id with no object behind it reached git rev-list, and
the CalledProcessError escaped as a traceback with exit 1, the status that
means the arc edited a protected suite. The check now catches a failed git
read and exits 2, naming the command, with nothing checked. A case holds it
(red before this commit).

Lane: openxfactory-4 (openXfactory-4-openDox_extraction)
Arc: neutral-product-standalone-operability
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Run 36736683387 measured e786005, the head before this change, at
openDox-code 814516b7: selected 991, passed 987, skipped 4, failures 0,
errors 0. The two cases 62a1b0d4 and e786005 added (the symlink-loop root
in tests/test_governed_registry_and_writer.py, the missing-history landing
in tests/test_protected_suite_check.py) take the raise to +106: T060's 11
and T059's 95. The floors sit on the reading again, margin zero.

Lane: openxfactory-4 (openXfactory-4-openDox_extraction)
Arc: neutral-product-standalone-operability
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…g, then the boundary (plan 034 T059)

Copilot's review at e786005 listed one finding in its overview: the
docstring said permit_output runs first, and in the next sentence that the
rendering runs before it, which the code does. It now says the rendering is
refused first, as SnapshotNotWritable, with nothing asked of the boundary,
and that the boundary's check runs before anything is written.

Lane: openxfactory-4 (openXfactory-4-openDox_extraction)
Arc: neutral-product-standalone-operability
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Copilot at f70ed5d (r4146436523): the whole-lines rule checked only the
trailing newline, so old: "1 == 1\n" could admit a change to the tail of
"assert 1 == 1", an edit never shown whole. The occurrence must now start at
the text's start or just after a newline. A case holds it (red before this
commit), and entries 1 to 3 still hold at a simulated squash landing.

Lane: openxfactory-4 (openXfactory-4-openDox_extraction)
Arc: neutral-product-standalone-operability
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Run 36738271008 measured 9d31553, the head before this change, at
openDox-code 814516b7: selected 992, passed 988, skipped 4, failures 0,
errors 0. The partial-line case 9d31553 added takes the raise to +107:
T060's 11 and T059's 96. Margin zero again (Copilot's overview at 9d31553).

Lane: openxfactory-4 (openXfactory-4-openDox_extraction)
Arc: neutral-product-standalone-operability
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…(plan 034 T059)

Copilot at 0fdd65c (r4146580826): index_entry imported pin_sentinels on
every call, so an index of entries that carry their own source_revision
failed where doc_health is absent, although the sentinel was never needed.
The import now happens only for an entry with no revision. A blocked-module
subprocess case holds both halves: a versioned entry is indexed without
doc_health, and a revisionless one still fails on doc_health (red before
this commit). DOC_HEALTH_SURFACE still reads one deferred import here.

Lane: openxfactory-4 (openXfactory-4-openDox_extraction)
Arc: neutral-product-standalone-operability
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Run 36740358207 measured a1b75f3, the head before this change, at
openDox-code 814516b7: selected 993, passed 989, skipped 4, failures 0,
errors 0. The versioned-entry case a1b75f3 added takes the raise to +108:
T060's 11 and T059's 97. Margin zero again.

Lane: openxfactory-4 (openXfactory-4-openDox_extraction)
Arc: neutral-product-standalone-operability
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
T007's batch F admits two edits for F7.1, and one of them ADDS a test:
tests/test_snapshot.py::test_the_validator_is_the_installed_consumers_own.
The check's fourth condition asked that `old` and `new` both lie inside the
named test, which an added test cannot meet: it is absent from the
`before_blob` text.

So where the named test is absent before the landing, the fourth condition
reads instead: `new` is `old` followed by the test's whole definition and
blank lines, and nothing else. An entry still admits one landing, and cannot
admit a change to a neighbouring test or code beside the added one. Four
cases cover it: an added test admitted; one that changes its neighbour, one
beside other code, and one naming a test found nowhere, each refused.

Lane: openxfactory-4 (openXfactory-4-openDox_extraction)
Arc: neutral-product-standalone-operability
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… (plan 034 T061, 7.3)

#1144 7.3 (RULED R1Q14 (a)), as T007's batch I amends it on R1Q27 (a): the
consumer's validator validates its own three kinds (7.1's openXdox-spec
three) from its installed distribution, wherever it runs, and the family's
other seven only where the running tree supplies their schemas.

* openxdox.contracts (new): the three schemas, byte copies of
  opensoft/openXdox-spec at f088b097 (the commit the openXdox root pins),
  copies.yaml recording each one's sha256 (the root manifest's digests), and
  the validator, byte for byte scripts/validate-ideation-dashboard-contracts.py.
  A copy is read only after its digest is checked against the record.
* The validator's schema lookup (schema_source): the tree's own contracts/
  first, as before (openxFactory's farm composes the family that way, and the
  packaged copy reads the copies beside it that way); then, for the three,
  the installed distribution found through the import system; then, for the
  seven, CONTRACTS_DIR, which never supplies the three. A copy that differs
  from its record is refused by name (harness exit 2), never read.
* pyproject.toml: the package-data line, and `referencing` and
  `rfc3339-validator` as runtime dependencies, since the package now ships a
  validator that imports the first and refuses to run without the second.
  rfc3339-validator leaves the test extra.
* tests/test_packaged_validator.py (new): the two validator copies equal,
  each copy its recorded digest at the root pin, the record refused for each
  way it can be wrong, and the package-data line held to the files it ships.
* tests/test_validator_schema_home.py: revised for the schemas' new home,
  with cases for the three from the distribution, a tampered copy, and the
  packaged layout reading its own copies.
* tests/test_dependency_direction.py: a .py under src/ that is not a module
  is named, and its imports are held to the declared dependencies.
* tests/test_validate_ideation_dashboard_contracts.py:
  test_every_schema_the_consumer_validates_is_on_disk, F7.1's second test,
  read as batch I reads it.

Lane: openxfactory-4 (openXfactory-4-openDox_extraction)
Arc: neutral-product-standalone-operability
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…nored (plan 034 T061, 7.3)

#1144 7.3: "openXdox's validator and its three schemas ... are located
through the INSTALLED openXdox distribution, and no parent walk remains."

find_validator keeps its declared signature, because openDox's
consumer_reach binds it by name, and ignores `start`. From this product's
source tree it answers that tree's scripts/ validator, the path openxFactory's
lanes read; from an install, the packaged openxdox/contracts copy. The answer
never depends on the start, the cwd, a snapshot's directory or a corpus, so an
enclosing tree's validator is never adopted, and a launch from outside the
tree is validated rather than confined to None (split-opendox 8.9 residue
(iii), openXdox-code#28, which this supersedes for the start).

GovernedValidator.locate asks find_validator with no start, and says the
product's own validator was not found when there is none. The installed
layout's cases join tests/test_packaged_validator.py.

Lane: openxfactory-4 (openXfactory-4-openDox_extraction)
Arc: neutral-product-standalone-operability
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… batch F)

A PROTECTED SUITE EDIT, in its own commit. T007's batch F (R1Q14 (a),
opensoft/openxFactory#656 comment 5850003126) admits it through batch C's
allow-list, with its reason, and not as a respelling:
test_the_validator_is_the_installed_consumers_own is added after
test_referentially_broken_snapshot_is_rejected, and nothing else in the
suite changes.

It plants the pre-shed tree F7.1 names above the start and asserts that
find_validator answers the consumer's own validator for every start, never
one under the planted tree, and that the validator it answers runs: a good
snapshot validates, a dangling edge is not conformant.

Lane: openxfactory-4 (openXfactory-4-openDox_extraction)
Arc: neutral-product-standalone-operability
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…tch F)

A PROTECTED SUITE EDIT, in its own commit. T007's batch F (R1Q14 (a),
opensoft/openxFactory#656 comment 5850003126) admits it through batch C's
allow-list, with its reason: the expected answer of
tests/test_snapshot_validator_home.py::test_a_start_outside_the_product_is_refused_not_walked
is now 7.3's. A start outside the product no longer confines the answer to
None; every start answers the product's own validator, and the planted tree
above it is still never walked. Nothing else in the suite changes.

Lane: openxfactory-4 (openXfactory-4-openDox_extraction)
Arc: neutral-product-standalone-operability
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…k (plan 034 T061)

tests/test_repo_root_guard.py::test_the_validation_skip_names_the_directory_it_searched_and_the_reason
staged a skip by giving the lookup two roots that reach no validator. Since
7.3 the roots never decide where the validator is, so under composition the
snapshot validated and the skip line never printed. The case now stages the
one skip left, an install built without its packaged validator, and asserts
the line still leads with the consequence, names both offered roots, names
the validator and says why it is absent. The suite is not a protected one;
it is declared-excluded (doc_health), so it runs in composition only.

pyproject.toml: the dependency paragraph says what holds rfc3339-validator on
the list. The dependency-direction check reads imports, and the validator
does not import it; F7.1's fresh install does, and goes red without it.

Lane: openxfactory-4 (openXfactory-4-openDox_extraction)
Arc: neutral-product-standalone-operability
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…plan 034 T061; batch K)

Brett's ruling at opensoft/openxFactory#656 comment 5916000030 admits each of
the ten cases 7.3's lookup rewords as its own R1Q7 (a) allow-list entry
(T007's batch K records it). T061 is ONE landing, and it edits
tests/test_snapshot.py twice and tests/test_snapshot_validation_launch.py
nine times. The check T059 wired admitted a landing's edit to a suite by one
entry only: one old-to-new replacement, inside one named test.

So several entries for one suite may now admit one landing together. They
are applied in the order listed, each to the text the one before it leaves.
The first one's before_blob is the suite before the landing, and the last
one's after_blob is the suite at it. Each one in between records the git
blob id of the text its edit leaves, which no commit need hold. Each holds on
its own texts by every existing condition, and they all name one landing.
The landing's diff for the suite is therefore exactly their texts, and every
entry of the chain is spent by it. Six cases cover it: a two-step chain
admitted and then spent whole; a wrong blob in between, a step outside its
named test, an edit no step records, and a chain naming two landings, each
refused. A chain of one is the check as it was.

Lane: openxfactory-4 (openXfactory-4-openDox_extraction)
Arc: neutral-product-standalone-operability
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

It remains draft with explicit cross-repository landing prerequisites and outstanding documentation corrections.

Review effort: Balanced
Findings: None

Resolved since last review (1)
Previously missed (3)

In code that hasn't changed since last review

Low severity Use possessive “its” in the chain-validation diagnostic

scripts/​protected_suites.py:390

Use the possessive its here; this text is surfaced in the chain-validation diagnostic.

Low severity Update schema_sources docstring for merged source behavior

scripts/​validate-ideation-dashboard-contracts.py:471

schema_sources() now merges tree, installed-package, and CONTRACTS_DIR sources, but the existing docstring still says only schemas under SCHEMAS_DIR are loaded and that an empty SCHEMAS_DIR is always refused. Update it so maintainers do not preserve the obsolete single-directory behavior.

Low severity Rewrite docstring to explain installed-validator validation behavior

tests/​test_snapshot_validation_launch.py:126

This added explanation conflicts with the opening claim that validation succeeds because the validator lives under --repo-root. Under the new behavior that root is never searched; please rewrite the whole docstring to describe the installed validator as the reason the launch validates.

This issue also appears on line 186 of the same file.

brettheap and others added 3 commits September 30, 2026 18:35
From the "previously missed" items at 29f058e:
* scripts/protected_suites.py: a chain step's diagnostic now reads "its
  before_blob is not the after_blob of the step before it".
* scripts/validate-ideation-dashboard-contracts.py: build_registry's
  docstring said that the registry held the schemas SCHEMAS_DIR carries, and
  that an empty SCHEMAS_DIR was refused. Since T061 each schema comes from
  the one place schema_source names, so the registry merges three places.
  The docstring now says that, and says a run that no channel supplies with
  any of the ten is refused. The packaged copy is re-copied and byte-equal.

Lane: openxfactory-4 (openXfactory-4-openDox_extraction)
Arc: neutral-product-standalone-operability
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
A PROTECTED SUITE EDIT, in its own commit, inside two of batch K's ten
tests. Copilot's review of #36 at 29f058e names them, and their entries
record the texts:

* test_the_default_shaped_launch_validates_from_the_repo_root still opened
  with "validated anyway, because --repo-root is a checkout and the validator
  lives in it", which 7.3 makes false. It now says why the launch validates:
  once through the walk, and since T061 because the validator is the
  installed distribution's own, whatever the start.
* test_when_neither_root_reaches_a_validator_the_message_names_both spoke of
  "a checkout with no validator in it" and "the two directories that were
  searched". It now names the one cause of a skip left, and the two roots
  openDox offered.

No code line and no assertion changes.

Lane: openxfactory-4 (openXfactory-4-openDox_extraction)
Arc: neutral-product-standalone-operability
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… 034 T061)

The launch suite's two docstrings changed in 665efe2, so the entries for the
first and third steps of its chain record the new texts, and the blobs from
the first step onward move with them. The entries are regenerated from this
head by the same script as before (minimal whole-line hunks inside each
test). All fifteen still load, and each chain, applied to main's text, gives
this head's text.

Lane: openxfactory-4 (openXfactory-4-openDox_extraction)
Arc: neutral-product-standalone-operability
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Copilot AI balanced review requested due to automatic review settings September 30, 2026 18:35

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

It is explicitly draft and depends on #35, batch K, and T062 landing first.

Review effort: Balanced
Findings: None

Run 36759713758 measured 708cdd28, the head before this change, at
openDox-code 814516b7: selected 1076, passed 1072, skipped 4, failures 0,
errors 0. The +83 on both floors, file by file against #35's head 4feb800:
+47 tests/test_packaged_validator.py (new); +18 tests/test_snapshot.py,
leaving the declaration; +11 tests/test_protected_suite_check.py; +5
tests/test_validator_schema_home.py; +2 tests/test_dependency_direction.py;
+1 tests/test_projection_contributions.py; -1 tests/test_declared_exclusion.py
(test_snapshot.py's case). The skips are the same four. The margin is zero
again.

Lane: openxfactory-4 (openXfactory-4-openDox_extraction)
Arc: neutral-product-standalone-operability
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Copilot AI balanced review requested due to automatic review settings September 30, 2026 18:41

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The cross-package packaging, validator resolution, schema provenance, and governance-check changes require final human verification against the stated landing prerequisites.

Review effort: Balanced
Findings: None

@brettheap
brettheap changed the base branch from build/034-p2k-t059-governed-contributions to main September 30, 2026 22:09
#35 (T059) landed on main as 839492d, a squash of its head aa0a2c5, and
the two trees are identical. This branch was built on #35's earlier head,
4feb800, so a plain merge of main met T059's files twice: once as this
branch's history of them and once as the squash. That gave add/add and
content conflicts in twelve files.

The merged tree is the three-way merge of this branch and aa0a2c5, with
4feb800, their real common state, as the base
(`git merge-tree --merge-base=4feb8009`). It merges with no conflict:
* this branch's side of every T059 file it had already changed;
* main's side of everything #35 added after 4feb800: the openDox-code
  047bb4fa re-pin (25414af) with its re-measured comments and the
  VALIDATORS respelling, and the give-back of displaced defaults
  (aa0a2c5).
The commit's parents are this branch and main, so the history records the
merge.

Lane: openxfactory-4 (openXfactory-4-openDox_extraction)
Arc: neutral-product-standalone-operability
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Copilot AI balanced review requested due to automatic review settings September 30, 2026 22:12

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The 26-file cross-leg packaging and validator change remains draft and blocked, requiring final human sequencing review.

Review effort: Balanced
Findings: None

With #35 landed (839492d) and merged in (8d89165), the openDox-code pin is
047bb4fa, T062's commit. Run 36784210624 read 1076 selected, 1072 passed and 4
skipped, the triple the floors already name, so they stand. The floor
paragraph says so, and nothing moves.

Lane: openxfactory-4 (openXfactory-4-openDox_extraction)
Arc: neutral-product-standalone-operability
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Copilot AI balanced review requested due to automatic review settings September 30, 2026 22:18
@sonarqubecloud

Copy link
Copy Markdown

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

It is a draft with explicit cross-repository landing prerequisites and packaged contract provenance requiring final human verification.

Review effort: Balanced
Findings: None

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The integrity-sensitive packaging, duplicated validator, schema copies, and governance-chain changes warrant final human review.

Review effort: Balanced
Findings: None

@brettheap
brettheap marked this pull request as ready for review September 30, 2026 22:33
@brettheap

Copy link
Copy Markdown
Contributor Author

READY at 5c2b134 — #35 → 839492d, batch K → 39f19145, T062 → d5098297 all landed. Lane: openxfactory-4 (openXfactory-4-openDox_extraction)

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @brettheap, your pull request is larger than the review limit of 150,000 diff characters

@brettheap
brettheap merged commit 6a3b93b into main Sep 30, 2026
5 checks passed
@brettheap

Copy link
Copy Markdown
Contributor Author

Lane: openxfactory-4 (openXfactory-4-openDox_extraction)

LANDED — lane openxfactory-4, 2026-09-30T22:36:53Z, PR #36 → 6a3b93b (opensoft/openXdox-code main; plain gate)

Brett: land the phase 1 PRs when green

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants