Skip to content

Add independent repository sync safety core - #3

Draft
Mjones13 wants to merge 2 commits into
mainfrom
work/repository-sync-orchestration-20260907
Draft

Mjones13 wants to merge 2 commits into
mainfrom
work/repository-sync-orchestration-20260907

Conversation

@Mjones13

Copy link
Copy Markdown

Scope and delivery status

JCV-A019 / JCV-W142, continuing the existing repository-sync branch and research checkpoint. One sequential author; draft only in the Jones Systems fork.

Implemented: a tested, requirements-derived client safety core. End-to-end production repository synchronization is not complete. There is no production local-Git/SSH host conformer, host discovery/fetch implementation, or preferences UI entry point. Production target qualification defaults to empty. This PR cannot synchronize a real repository by itself.

No usage/billing/account feature, dependency, live-host effect, installation, deployment, release, merge, force push, branch deletion, or upstream PR is included.

Implementation

  • Immutable environment/configuration/repository/path/remote/branch mappings and fresh exact-state plans. Normal plans permit unchanged or proven clean fast-forward states; unsafe, dirty, unknown, detached, ahead, diverged, and unsupported states fail closed.
  • A private, bounded POSIX journal persists full intent before dispatch; operation IDs are bound to their full plan. Repeated confirmation, restart, expiry, and unknown outcomes never execute that ID again. Nonblocking process locks and overlap fencing preserve independent-target progress without allowing unresolved resource reuse.
  • Cancellation is a durable request, not an invented no-effect outcome. Same-operation/original-target readback is required after ambiguous effects. Conflicting terminal receipts persist a manual-resolution conflicted fence.
  • Guarded rollback planning uses a new explicit confirmation, a stored applied original, exact target/physical identity, unchanged current HEAD, and the preserved original reference. Actual Git restoration belongs to the still-unimplemented host contract.
  • Three Swift Testing suites plus synthetic fixtures and a dependency-free offline source-closure runner. New files join the existing CodexBarCore and TestsLinux targets without changing Package.swift or CI.

Provenance and PR #2 boundary

No source from repo_updater was copied, translated, ported, installed, or executed. Its unresolved license rider remains a reuse gate; the independent implementation adds no dependency and makes no upstream license-clearance claim.

PR #2 was reverified as open/draft/unmerged, authored by Mjones13, at 0bdf8a262bc9342d9b62a5f12f8062db22273b50. Its 51 changed paths have zero filename overlap with this ten-file candidate. No unmerged PR #2 code was adopted. No accepted owner handoff was found or inferred. Later preferences integration requires an explicit path/owner agreement and must preserve CAAM's closed account-control command family.

Verification

Passed locally on the exact new core/fixture source closure, Swift 6.2.1 Linux x86_64:

  • bash Scripts/test_repository_sync_core.sh: 39 tests in 3 suites passed.
  • bash Scripts/test_repository_sync_core.sh -c release: 39 tests in 3 suites passed.
  • bash -n Scripts/test_repository_sync_core.sh; candidate whitespace and 120-column Swift checks.
  • Ten Git blob hashes independently computed from tested files reproduce candidate tree 06c2a6ca9a435d69371877ada81856db230ec1d9 against the original branch tree.

Not claimed: full-repository, native macOS, live Git/SSH, device, power-loss, independent-review, SwiftFormat, or SwiftLint success. The scratch checkout contains a bounded source closure, not the full repository. Attempts using the blob-verified original Makefile ended with make test and make check exit 2 because their full-repository scripts were absent; no full test/linter executed. SwiftFormat and SwiftLint are unavailable locally; no tools were installed.

Initial fixture additions exposed two fixture mistakes, corrected before final runs. Sequential security/recovery self-review also found and fixed a real terminal-receipt conflict-fencing gap; it is covered by the passing tests. This is self-review, not independent review.

This PR's own exact-head CI must be observed after creation. Preserve the existing draft policy: required macOS tests may be deferred and aggregate CI incomplete. Do not mark ready merely to bypass that gate. PR #2's checks are not evidence for this candidate.

Immutable delivery

  • Research parent: 88c7bbb0ddba05e2dd62e292110a3cd13679c4bf
  • Implementation commit: b981e7e5c824451d9ab6c47a0513e926c3a32bc5
  • Candidate tree: 06c2a6ca9a435d69371877ada81856db230ec1d9
  • Main observed: d6e929cd736eccae187cd41ddb5305a670afb2c8
  • Branch: work/repository-sync-orchestration-20260907, normal fast-forward with exact readback

Engineering specification and Work Note record the contract, threats, test limitations, ownership, and continuation.

Remaining gates / next concrete effect

Observe and remediate this candidate's own repository checks. Then implement and qualify the separate host protocol, obtain the PR #2 entry-point ownership agreement, and complete native and independently reviewed conformance evidence before any production target is admitted. Live-host qualification, merge, deployment, and release require separate authority. The historical V3 Level 2 guide location is unresolved after a 404 and incomplete code-search result; no compliance claim is made for that unread document.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant