Skip to content

docs(openspec): owner-moves decision pass (34 decisions, 19 changes) - #4112

Merged
rubenvdlinde merged 8 commits into
developmentfrom
parity/owner-moves
Sep 28, 2026
Merged

rubenvdlinde merged 8 commits into
developmentfrom
parity/owner-moves

Conversation

@rubenvdlinde

Copy link
Copy Markdown
Contributor

Owner-moves decision pass for OpenRegister (28 Sep 2026). During the OpenSpec pass, other product lanes handed rows and halves to OpenRegister after OpenRegister's own lane had finished, so nobody decided them. This PR decides every one of them with the pass's rule (existing, decided-no, build or defer), records the decisions in openspec/parity/gap-decisions.json, and writes the OpenSpec changes for the build decisions. It touches only openspec/.

Decisions

34 records: 25 build, 6 existing, 3 defer, 0 decided-no. A row that sits in another product's matrix keeps that matrix's id; a half with no matrix row uses the requesting change's name as row and the requesting repo as matrix. Where one requesting change asked for two halves with different outcomes, it has two records.

row or requesting change matrix decision change
auto-ai-step integriq existing or-flow-nodes
auto-code integriq build flow-code-step-in-a-sidecar
auto-error-path integriq build flow-error-branch-and-step-retry
auto-compensate integriq defer none
auto-templates integriq existing store-over-federated-config
src-secrets-manager integriq build credential-outside-vault-reference
auto-failure-alerts pipelinq defer none
plat-translated-field-names pipelinq build modelling-field-names-per-language
acc-row-level buildiq build access-owner-and-condition-scopes
index-bulk-edit-and-transitions nextcloud-vue existing bulk-action-jobs
index-bulk-edit-and-transitions nextcloud-vue build records-bulk-transition
index-copy-with-relations nextcloud-vue build records-copy-with-links
notes-replies-group-mentions-and-images nextcloud-vue build notes-replies-by-parent
form-conditions-from-schema nextcloud-vue build modelling-required-when-enforced
index-export-follows-the-page nextcloud-vue build modelling-schema-exportable-flag
form-options-from-concept-scheme nextcloud-vue existing property-code-list-from-concept-scheme
audit-trail-restore-version nextcloud-vue build history-revert-through-the-save-path
insight-exports-and-custom-reports stackiq build modelling-schema-exportable-flag
operations-record-reconciliation stackiq build mdm-merge-relinks-every-reference
events-world-scope-and-upcoming larpinq build search-value-or-empty-filter
surfaces-document-house-style thematiq build export-pdf-house-style
ai-copilot-documents-and-code-help buildiq build search-file-text-and-vector-facade
ai-agents-knowledge-and-run-trace buildiq build search-file-text-and-vector-facade
ai-llm-steps-and-computed-fields buildiq build flow-trigger-transitions-and-changed-fields
logic-automation-actions-that-run buildiq build flow-trigger-transitions-and-changed-fields
logic-automation-actions-that-run buildiq existing macro-flows-with-next-item
logic-script-step buildiq build flow-code-step-in-a-sidecar
data-external-database-sources buildiq build dbal-query-schema-guarded-and-previewed
data-model-diagram buildiq build modelling-schema-diagram
lifecycle-release-test-gate buildiq build records-validate-without-saving
platform-record-lock pipelinq build archival-frozen-refuses-delete-and-dates-follow
platform-client-retention pipelinq build archival-frozen-refuses-delete-and-dates-follow
platform-client-retention pipelinq existing anonymising-as-an-archival-outcome
requests-inbound-to-queue pipelinq defer none

The approval stand-in on chains that shillinq asked for is not decided here: its issue text goes to Ruben first.

Changes written (19 new)

  • flow-trigger-transitions-and-changed-fields: buildiq logic-automation-actions-that-run (start on a lifecycle transition) and ai-llm-steps-and-computed-fields (start only when named fields changed).
  • flow-code-step-in-a-sidecar: integriq row auto-code and buildiq logic-script-step; issue Node sidecar for user code — the option that unlocks a real Code node #2066 as a change.
  • flow-error-branch-and-step-retry: integriq row auto-error-path.
  • credential-outside-vault-reference: integriq row src-secrets-manager, as a per-credential reference to HashiCorp Vault or OpenBao read by the broker; ADR-064 gets one paragraph.
  • modelling-field-names-per-language: pipelinq row plat-translated-field-names.
  • access-owner-and-condition-scopes: buildiq row acc-row-level (the @creator sentinel, authorization.conditions and the openregister.authorization.scopes capability that buildiq's archived data-scopes-authoring asks for).
  • records-bulk-transition: nextcloud-vue index-bulk-edit-and-transitions, transition half.
  • records-copy-with-links: nextcloud-vue index-copy-with-relations.
  • notes-replies-by-parent: nextcloud-vue notes-replies-group-mentions-and-images.
  • modelling-required-when-enforced: nextcloud-vue form-conditions-from-schema.
  • modelling-schema-exportable-flag: nextcloud-vue index-export-follows-the-page and stackiq insight-exports-and-custom-reports.
  • history-revert-through-the-save-path: nextcloud-vue audit-trail-restore-version and buildiq data-restore-record-version findings.
  • mdm-merge-relinks-every-reference: stackiq operations-record-reconciliation (relink inside the merge unit, and /duplicates?register=&schema=).
  • search-value-or-empty-filter: larpinq events-world-scope-and-upcoming.
  • export-pdf-house-style: thematiq surfaces-document-house-style (tender demand).
  • search-file-text-and-vector-facade: buildiq ai-copilot-documents-and-code-help (file text read, issue Reading a file's extracted text always answers 404 #4106) and ai-agents-knowledge-and-run-trace (the vector facade hermiq vector-rag defines), with a read-rights filter on every vector result.
  • dbal-query-schema-guarded-and-previewed: buildiq data-external-database-sources.
  • records-validate-without-saving: buildiq lifecycle-release-test-gate.
  • archival-frozen-refuses-delete-and-dates-follow: pipelinq platform-record-lock and platform-client-retention (D3 and D4).

Open changes extended (3)

  • modelling-schema-diagram: design D-1a, one requirement and task 1.1a, so x-openregister-relations entries are edges (buildiq data-model-diagram). Nothing of it is built yet.
  • anonymising-as-an-archival-outcome: design D-6, one scenario and task 2.2a, so the anonymisation profile can sit beside the archive block (pipelinq platform-client-retention D6).
  • property-code-list-from-concept-scheme: task 4.4, resolve a conceptScheme value by slug as its published description says (nextcloud-vue form-options-from-concept-scheme).

What did not hold up

  • buildiq data-external-database-sources says OpenRegister owes the query table. Query-backed schemas shipped in feat(dbal): query-backed virtual schemas + snake_case filter fix #2043 (12a52c7) without an OpenSpec change. What is missing is the statement guard, a read-only transaction with a timeout, and the preview route, and that is what the change writes.
  • nextcloud-vue index-bulk-edit-and-transitions reads the bulk registry as two actions. openregister:set-properties shipped in feat(bulk jobs): a bulk action is one previewed, cancellable job with a per-object outcome #3742, so the set-field half is existing.
  • integriq row auto-ai-step reads no and decided-no, but hermiq contributes hermiq.agent-step to OpenRegister's engine through RegisterFlowNodesEvent (hermiq lib/Flow/HermiqAgentNode.php at 5ac16d315). The integriq matrix row is for the coordinator.
  • The revert route writes with ObjectEntityMapper::update(), and no listener writes an audit entry for ObjectRevertedEvent. The content-versioning spec's revert audit requirement is not met today; the revert change covers it.
  • FileSearchController semantic and hybrid search return file chunks without a read check (the filinq lane's security candidate, confirmed at 555af72). The vector facade change adds the filter to both routes.

Source-matrix rows (not edited here)

No OpenRegister matrix row changes. Rows in other matrices are listed for the coordinator in the lane's hand-back.

Checks

Run once on 575aff8 (the decisions commit; the later merge of development brought in only openspec/parity/capabilities.json from #4109), by exit code, with a private HOME and TMPDIR:

  • openspec validate <change> --strict for all 22 new or extended changes: exit 0 each.
  • python3 -m json.tool openspec/parity/gap-decisions.json: exit 0; every named change directory exists.
  • Hydra gates, --scope-to-diff --base origin/development: exit 0, 23 of 23 applicable gates ran. Gate 19 does not read openspec/changes/*/specs, so it inspected nothing here.
  • composer install: exit 0. npm ci: exit 0. npm run lint: exit 0 (0 errors, 932 warnings, the same count as on development).
  • npm run test:l10n: exit 0. npm run check:schema-l10n: exit 0.
  • parity_verify --strict: not run, because no matrix is edited in this PR.

composer check:strict was not run: the diff touches only openspec/, which no PHP analyser or test reads.

@rubenvdlinde
rubenvdlinde merged commit 5cda2f0 into development Sep 28, 2026
35 checks passed
@github-actions

Copy link
Copy Markdown
Contributor

Quality Report — ConductionNL/openregister @ a915036

Check PHP Vue Security License Tests
lint ✅
phpcs ✅
phpmd ✅
psalm ✅
phpstan ✅
phpmetrics ✅
eslint ✅
stylelint ✅
build ✅
check-specs ✅
test-l10n ✅
test-l10n-parity ✅
format ✅
check-schema-l10n ✅
check-l10n-js ✅
composer ✅ ✅ 170/170
npm ✅ ✅ 649/649
app:check-code ⏭️
info.xml ✅
REUSE ✅
lockfile sync ✅
PHPUnit ⏭️ not run for this diff — no file in this diff matches the code globs, and none carries a source extension — the heavy tier has nothing to decide about it.
Newman ✅
Playwright ⏭️ deferred: E2E runs locally and on the promotion path only. This pull request targets development, so the suite is asked once per promotion into beta and main rather than once per push per open pull request. Run it on any branch from the Actions tab, or locally with npx playwright test.
Hydra gates ✅

Quality workflow — 2026-09-28 05:29 UTC

Download the full PDF report from the workflow artifacts.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant