docs: record P5 implementation and finalize the P5 manual walkthrough
This commit is contained in:
@@ -126,24 +126,42 @@ Checks to complete during P4 manual acceptance (decision: **PASS** (owner approv
|
||||
|
||||
## P5 — Curated FK annotations in Git
|
||||
|
||||
**Status:** instructions to be finalized by P5 implementation; not yet runnable.
|
||||
**Status:** P5 implementation complete; automated integration PENDING; manual acceptance PENDING.
|
||||
|
||||
Manual goal: curate `<id>/schema/annotations.yaml` in an author clone, publish it,
|
||||
pull the new revision, explicitly accept the reviewed blob, and prove atomic revision-correct sync
|
||||
without changing `physical.yaml` in Git.
|
||||
Manual goal: curate `<id>/schema/annotations.yaml` in an author clone, publish it, pull the new
|
||||
revision, and prove the revision-pinned sync and the explicit `schema accept` review, without ever
|
||||
pushing curated content from the operator CLI.
|
||||
|
||||
Checks to fill during P5:
|
||||
Commands (contract: `docs/contracts/workspace-preprocessing-cli.md`):
|
||||
|
||||
1. candidate/export review;
|
||||
2. Git commit and exact blob identity;
|
||||
3. pull and controlled revision transition;
|
||||
4. explicit acceptance record;
|
||||
5. synchronized destination and ownership manifest;
|
||||
6. malformed/oversized/symlink/cross-namespace refusal;
|
||||
7. pinned historical revision isolation.
|
||||
```bash
|
||||
thothctl --installation <abs>/thothii-installation.yaml workspace schema suggest-fks --workspace <id> --from-sql <file>.sql --output <candidates>.yaml --json
|
||||
# curate the candidate into <id>/schema/annotations.yaml in the author clone, then commit/push/pull
|
||||
thothctl --installation <abs>/thothii-installation.yaml workspace schema accept --workspace <id> --run <run-id> --yes --json
|
||||
thothctl --installation <abs>/thothii-installation.yaml workspace preprocess run --workspace <id> --resume <run-id> --json
|
||||
```
|
||||
|
||||
Checks:
|
||||
|
||||
1. `schema suggest-fks` returns pristine JSON with `suggestedFksYaml` and a `manual_review_required`
|
||||
block (exit 3) when candidates exist; the suggested YAML digest equals the reported digest;
|
||||
2. after commit/push/pull, activation reads `<id>/schema/annotations.yaml` as a regular Git blob at
|
||||
the same commit as the descriptor and synchronizes it to
|
||||
`<data>/sessions/<id>/revisions/<commit>/artifacts/mschema/annotations.yaml` with a restrictive
|
||||
mode and an adjacent ownership manifest `{ workspace, commit, blobId, contentDigest, destination }`;
|
||||
3. two revisions write two different directories; a session pinned to an older revision reads its own
|
||||
revision's annotations;
|
||||
4. `schema accept --run <id> --yes` records the accepted candidate/current-blob digests and the new
|
||||
revision; missing `--yes`, an unknown run, an empty file, a malformed blob, or a blob not matching
|
||||
the recorded candidate is refused (exit 1, `annotation_invalid`) without recording a review;
|
||||
5. `preprocess run --resume <id>` continues only with the exact accepted blob digest and compatible
|
||||
DWH binding; otherwise it records a new `manual_review_required` checkpoint;
|
||||
6. negatives: symlink/tree-at-path, cross-namespace, oversized (>16 MiB), non-UTF-8, and malformed
|
||||
annotation objects are refused at activation without mutating the snapshot or runtime roots;
|
||||
7. the operator CLI never stages/commits/pushes curated content; secret scan and exact owned-resource
|
||||
cleanup pass.
|
||||
|
||||
Decision: **PENDING**.
|
||||
|
||||
## P6 — Commit-addressed Evidence materialization
|
||||
|
||||
**Status:** instructions to be finalized by P6 implementation; not yet runnable.
|
||||
|
||||
Reference in New Issue
Block a user