Skip to content

[CT-805] Close AC1–AC35 and perform the verified production cutover #99

Description

@flyingrobots

ADR-THINK-001 · Delivery plan · Complete issue catalog

Milestone: ADR-THINK-001 P8 — Action bridge and production cutover

Feature: F8.2 — Revocation, compensation, audit, and cutover

Outcome

The complete architecture proves every acceptance criterion, demonstrates the action safety boundary, catches up the final legacy tail, and performs exactly one witnessed production authority switch per approved Mind.

User stories

  • As a Think maintainer, I want one falsifiable AC1–AC35 release gate and exact cutover protocol, so that production authority moves only after the whole architecture, not merely migration, is proven.
  • As a Think user, I want my approved Mind to switch once without lost captures or unauthorized effects, so that I can trust both storage migration and semantic action boundaries at cutover.

Deliverables

  • Production-shaped deterministic external-effect simulator and fault injector.
  • Integrated AC1–AC35 evidence bundle covering every gate, invariant, fixture, migration, authority, erasure, resource, and action proof.
  • Per-Mind final tail, CutoverWitness verification, atomic authority switch, and AuthoritySwitchReceipt runbook.
  • Post-switch read/write/restart/doctor/erasure proof, retained-ref posture, resource report, and residual-risk register.

Acceptance criteria

  • All ADR acceptance criteria AC1–AC35 and gates G1–G5 pass together at the exact candidate frontier with no unresolved obstruction or blocking review.
  • The suite proves external action cannot occur from a ClaimOccurrence, projection, answer, or recommendation alone, and every simulated effect has a valid bounded receipt.
  • Each approved Mind either remains wholly legacy-authoritative on failure or switches exactly once after its final verified witness; no dual-write interval exists.
  • Post-switch reads, captures, restart, doctor, erasure, revocation, compensation, incident, process, memory, queue, and backup ratchets all pass.

Test plan

Contract and unit

  • Acceptance tests enumerate AC1–AC35, every authorization and aftermath state, and every final-cutover state with exact witness assertions.

Integration and acceptance

  • The full dojo and approved-Mind flow crosses BodyVault, WARP, reading, claims, authority, query, AnswerWitness, Edict, final tail, authority switch, and audit.

Failure and recovery

  • Any failed criterion, obstruction, ambiguity, stale frontier, forged receipt, replay, provider fault, lock timeout, witness mismatch, or erasure leak leaves legacy authoritative and exposes no unsafe path.

Resource and performance

  • Action simulation and final cutover preserve flat memory, bounded queues, window-scaled Git processes, bounded retries, bounded lock time, and exact external-call counts.

Security, privacy, and erasure

  • Independent threat review and restore drills cover keys, backups, logs, traces, receipts, external credentials, retained refs, and erased payloads before and after the switch.

Build-time resources

Resource Exclusivity mode Scope
action-safety-acceptance-suite exclusive Integrated release-gating scenarios and expected witnesses.
external-effect-simulator exclusive One deterministic fault-injected external world.
acceptance-scenario-partitions partitioned Disjoint authorization and aftermath scenarios.
production-shaped-mind-fixture exclusive Pinned end-to-end evidence and policy worldline.
release-evidence-bundle exclusive Signed acceptance results and residual-risk register.
production-mind-write-lock partitioned Exclusive final lock per approved Mind; Minds never share an authority mutation lane.
production-authority-pointer exclusive The one checked production substrate switch.
final-cutover-proof-runner exclusive Independent final-tail and CutoverWitness verification.
  • exclusive: Only one active slice may mutate or lease the named resource.
  • partitioned: Concurrent writes are lawful only in disjoint partitions named by each slice.
  • shared: Concurrent read-only use is lawful; this slice does not mutate the resource.

Dependencies

ADR traceability

  • Implementation gates: G1, G2, G3, G4, G5
  • Constitutional invariants: I1, I2, I3, I4, I5, I6, I7, I8, I9, I10, I11, I12, I13, I14, I15, I16, I17
  • ADR acceptance criteria: AC1, AC2, AC3, AC4, AC5, AC6, AC7, AC8, AC9, AC10, AC11, AC12, AC13, AC14, AC15, AC16, AC17, AC18, AC19, AC20, AC21, AC22, AC23, AC24, AC25, AC26, AC27, AC28, AC29, AC30, AC31, AC32, AC33, AC34, AC35

Non-goals

  • Do not perform a real irreversible external effect in the acceptance suite.
  • Do not treat simulator coverage as proof for an unregistered future operation type.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions