feat: operator schema accept command for curated FK review (P5)

This commit is contained in:
2026-08-13 05:06:23 +02:00
parent 5249798c03
commit 0459a6cd3e
9 changed files with 293 additions and 1 deletions
@@ -21,6 +21,9 @@ thothctl --installation <absolute>/thothii-installation.yaml workspace schema ch
[--annotations <regular-file> --reviewed-candidates <sha256:hex>]
[--json]
thothctl --installation <absolute>/thothii-installation.yaml workspace schema accept
--workspace <id> --run <32hex> --yes [--json]
thothctl --installation <absolute>/thothii-installation.yaml workspace index-schema
--workspace <id> [--json]
@@ -57,6 +60,25 @@ thothctl --installation <absolute>/thothii-installation.yaml workspace vector re
mutation is performed.
```
## Curated FK annotations (P5)
- The canonical curated annotations file is `<workspace-id>/schema/annotations.yaml`, a regular
Git blob at the same commit as the descriptor. Absence is compatible (empty canonical set +
warning); symlinks, trees/gitlinks, oversized (>16 MiB), non-UTF-8, and malformed objects are
refused at activation.
- Activation synchronizes the blob to the immutable revision-qualified root
`/data/sessions/<id>/revisions/<commit>/artifacts/mschema/annotations.yaml` with a restrictive
mode and an adjacent ownership manifest `{ workspace, commit, blobId, contentDigest,
destination }`. Pinned runtimes resolve annotations from `paths.annotations_root`.
- `workspace schema accept --run <id> --yes` is the only human FK review primitive: after
commit/push/pull, it reads the current synced blob, validates it with the harness parser against
the physical schema and the recorded candidate digest, and records
`{ reviewedCandidatesDigest, annotationsDigest, workspaceRevision, blobId }`. `--yes` is
required; an empty file, an unknown run, a malformed blob, or a non-matching candidate fails
closed without recording a review. `schema check` alone is not evidence of human review.
- `preprocess run` continues only with the exact accepted blob digest and a compatible reusable
DWH binding; otherwise it records a new review checkpoint.
## Validation
- `--installation` is mandatory and absolute.
@@ -73,6 +95,10 @@ thothctl --installation <absolute>/thothii-installation.yaml workspace vector re
- `--annotations` and `--reviewed-candidates` are all-or-nothing;
- annotations must be UTF-8, canonical, non-symlink, max 16 MiB;
- `--reviewed-candidates` must match `sha256:<64 lowercase hex>`.
- `schema accept`
- `--run` is mandatory and must be 32 lowercase hex characters;
- `--yes` is mandatory and may be supplied once;
- `--annotations`/`--reviewed-candidates`/`--from-sql`/`--assume` are not accepted.
- Unknown flags, passthrough separators, and shell fragments are rejected before Docker runs.
## Container boundary