feat(composition): admit exact released owner API routes - #434
seonghobae wants to merge 114 commits into
Conversation
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
2026-09-22 dependent-successor currentization This admission parent remains exact Dependent Draft #436 has ordinary-forward advanced to exact Activation/deployment/rollback/recovery authority is still absent and #436 has no canonical hosted GREEN/review evidence, so this does not change #434 Draft/merge status or API-01 state. |
|
Executable descendant update: #436/#437/#438 ownership remains unchanged, and new Draft #439 exact |
Scope
Advances #432 with the executable product-composition admission slice. Exact head remains
68bdf2d984ca7686219c335a85a6574195675cbe, stacked on #340 exact28f2bd28414e217f7e848ba86c0cfdbe97fd518f, with 114 ordinary-forward commits / 17 changed files confined toservices/product-composition-api/**.This PR remains Draft. It proves process-local route/generation admission integrity only; it does not claim a deployable gateway, Keyverse authentication, HR authorization, durable activation, Kubernetes deployment, buyer-path p95, protected integration, or release completion.
Admission authority
The branch fails closed on mutable/foreign owner release attribution, valid-to-valid retarget of already-constructed owner/route/generation values, stale receipts, owner/upstream disagreement, split owner release identity, noncanonical identifiers/templates, ambiguous path selection, cross-owner Path Item split, GET/HEAD selected-resource authority split, and non-deterministic route/method representation. Construction snapshots remain process-local integrity evidence and are deliberately separate from durable configuration/deployment authority.
required=Falseis executable product semantics here, not decoration: canonicaladmit_generation()may issue a valid required-route receipt while an optional route's exact owner release is unavailable, recording that route inunavailable_optional_route_ids. Durable successors must preserve that distinction rather than silently upgrading optional availability into a required admission condition.Durable successors — live
30d89fa8f4ba95d7ddb84dde8e3b7e5faebf0343, 31 commits / 14 files, is directly stacked on this head and owns durable generation/configuration authority.8a67b5cef24332619b3a4466e3787a851c299215, 258 ahead / 0 behind feat(composition): persist reconstructable generation registry #436 with feat(composition): persist reconstructable generation registry #436 exact as merge base, owns schema 0019→0025, activation/rollback/recovery evidence and commit semantics, deployment serialization, namespace/trigger/function/relation provenance, checked-as-used runtime capability integrity, recovery-bound serving snapshots and serving read-side currentness.d642eb71c05ae3990349a26facf30593a5703914, 7 ahead / 0 behind feat(composition): persist deployment activation authority #437 with feat(composition): persist deployment activation authority #437 exact as merge base, owns request selection before durable currentness/availability and adds no migration bytes.ef991ff.../ repaird642eb71...additionally rejects unknown declared paths and undeclared methods before crossing PostgreSQL currentness, avoiding unnecessary DB work without weakening fail-closed availability.Evidence layers remain distinct: #434 process-local route/generation admission; #436 durable reconstructable configuration; #437 durable activation/recovery plus recovery-commit snapshot issuance and database-read currentness; #438 request preselection/routing. None is protected shipment authority. The deployable HTTP composition host still does not exist; future serving must handle raw transport normalization, authentication/authorization integration, lifecycle invalidation/reload, owner HTTP execution, transport faults, supported restore/failover provenance and measured performance.
Architecture and verification ownership
#433 source remains exact
6fc85e4d8bb273adb0d5866d87554067c749179d, ADR 0432 Proposed/Draft. PR metadata records current evidence, but source documents must ordinary-forward adopt final admissible heads before Accepted/Ready.#260/#311 must execute one exact #438 candidate. Package acceptance includes current request-routing/preselection regressions plus inherited #437 snapshot/currentness, optional-route, capability-integrity, production-docstring and 100% owned statement/branch/edge contracts. PostgreSQL acceptance remains complete 0018→0025 lineage plus evidence-lifetime, DB-owned recovery chronology, optional-route, hostile namespace, upgrade, recovery, serialization and provenance roots. Current child exact
d642eb71...must obtain its own canonical execution; predecessor evidence is not transferred here.Production runtime/migrator DB-role separation and supported deployment/failover provenance remain explicit deployment acceptance. Migration number
0026remains owned by active Employment-absence work. #340 remains the inherited Foundation prerequisite; no predecessor GREEN, synthetic status or leaf workaround transfers into this stack.#100 remains sole writer for
docs/product-technical-gap-baseline.md, whereAPI-01remains Planned; #51 remains protected-truth reconciliation owner; #432 executable gap owner; #435 durable-authority issue; #260 canonical service/runtime owner; #311 PostgreSQL-root inventory owner.No force-push, destructive rebase, self-approval, routine bypass, mutable sibling dependency, copied owner schema, cross-service SQL, predecessor-GREEN transfer, feature-local quality workflow, synthetic status, migration-number theft, premature Ready/merge/release, or simple Close is authorized.