Skip to content

feat(composition): admit exact released owner API routes - #434

Draft
seonghobae wants to merge 114 commits into
fix/foundation-setup-node-node24from
feat/product-composition-admission
Draft

seonghobae wants to merge 114 commits into
fix/foundation-setup-node-node24from
feat/product-composition-admission

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 21, 2026

Copy link
Copy Markdown
Contributor

Scope

Advances #432 with the executable product-composition admission slice. Exact head remains 68bdf2d984ca7686219c335a85a6574195675cbe, stacked on #340 exact 28f2bd28414e217f7e848ba86c0cfdbe97fd518f, with 114 ordinary-forward commits / 17 changed files confined to services/product-composition-api/**.

This PR remains Draft. It proves process-local route/generation admission integrity only; it does not claim a deployable gateway, Keyverse authentication, HR authorization, durable activation, Kubernetes deployment, buyer-path p95, protected integration, or release completion.

Admission authority

The branch fails closed on mutable/foreign owner release attribution, valid-to-valid retarget of already-constructed owner/route/generation values, stale receipts, owner/upstream disagreement, split owner release identity, noncanonical identifiers/templates, ambiguous path selection, cross-owner Path Item split, GET/HEAD selected-resource authority split, and non-deterministic route/method representation. Construction snapshots remain process-local integrity evidence and are deliberately separate from durable configuration/deployment authority.

required=False is executable product semantics here, not decoration: canonical admit_generation() may issue a valid required-route receipt while an optional route's exact owner release is unavailable, recording that route in unavailable_optional_route_ids. Durable successors must preserve that distinction rather than silently upgrading optional availability into a required admission condition.

Durable successors — live

Evidence layers remain distinct: #434 process-local route/generation admission; #436 durable reconstructable configuration; #437 durable activation/recovery plus recovery-commit snapshot issuance and database-read currentness; #438 request preselection/routing. None is protected shipment authority. The deployable HTTP composition host still does not exist; future serving must handle raw transport normalization, authentication/authorization integration, lifecycle invalidation/reload, owner HTTP execution, transport faults, supported restore/failover provenance and measured performance.

Architecture and verification ownership

#433 source remains exact 6fc85e4d8bb273adb0d5866d87554067c749179d, ADR 0432 Proposed/Draft. PR metadata records current evidence, but source documents must ordinary-forward adopt final admissible heads before Accepted/Ready.

#260/#311 must execute one exact #438 candidate. Package acceptance includes current request-routing/preselection regressions plus inherited #437 snapshot/currentness, optional-route, capability-integrity, production-docstring and 100% owned statement/branch/edge contracts. PostgreSQL acceptance remains complete 0018→0025 lineage plus evidence-lifetime, DB-owned recovery chronology, optional-route, hostile namespace, upgrade, recovery, serialization and provenance roots. Current child exact d642eb71... must obtain its own canonical execution; predecessor evidence is not transferred here.

Production runtime/migrator DB-role separation and supported deployment/failover provenance remain explicit deployment acceptance. Migration number 0026 remains owned by active Employment-absence work. #340 remains the inherited Foundation prerequisite; no predecessor GREEN, synthetic status or leaf workaround transfers into this stack.

#100 remains sole writer for docs/product-technical-gap-baseline.md, where API-01 remains Planned; #51 remains protected-truth reconciliation owner; #432 executable gap owner; #435 durable-authority issue; #260 canonical service/runtime owner; #311 PostgreSQL-root inventory owner.

No force-push, destructive rebase, self-approval, routine bypass, mutable sibling dependency, copied owner schema, cross-service SQL, predecessor-GREEN transfer, feature-local quality workflow, synthetic status, migration-number theft, premature Ready/merge/release, or simple Close is authorized.

@coderabbitai

coderabbitai Bot commented Sep 21, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Copy link
Copy Markdown
Contributor Author

2026-09-22 dependent-successor currentization

This admission parent remains exact 68bdf2d984ca7686219c335a85a6574195675cbe; no #434 source change is needed. Its body section describing #436 as persistence-neutral only is now stale.

Dependent Draft #436 has ordinary-forward advanced to exact 04705a05f8e4fd58a39527f56dcb993fd4bb40cb (14 commits / 8 files) and now implements Draft-source PostgreSQL durable generation/configuration authority: normalized append-only generation/owner-release/route/method tables, exact-material-only idempotent registration, fresh canonical restart reconstruction with digest recomputation, and a real PostgreSQL contract source. It remains directly stacked on this exact #434 head and must continue consuming #434 rather than back-copying persistence here.

Activation/deployment/rollback/recovery authority is still absent and #436 has no canonical hosted GREEN/review evidence, so this does not change #434 Draft/merge status or API-01 state.

Copy link
Copy Markdown
Contributor Author

Executable descendant update: #436/#437/#438 ownership remains unchanged, and new Draft #439 exact 2256112d09a7130cd361264eda8303b12d7ad027 adds only the raw ASGI request-target normalization layer on #438 exact d642eb71c05ae3990349a26facf30593a5703914. It is 5 ordinary-forward commits with #438 exact as merge base and no migration bytes. Admission truth remains owned by #434; durable generation by #436; activation/recovery/currentness by #437; request selection by #438; raw transport normalization by #439. This still does not constitute a deployable buyer host or close API-01.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant