Repository navigation
Conversation
PX-13 requires each period to be released exactly once, and #397's demandAggregatesFromRelease expects its caller to take the record from a write-once ledger. #365's buildPublicRelease builds the record. Its digest proves the record is unmodified, not who built it or that its period was released only once (astra 112e's weakest link on #397). - services/release-ledger.ts stores <root>/releases/<YYYY-MM>.json on the Kit registry's durable volume (K1). - Each entry is created exclusively (a temp file plus a hard link; EEXIST means another writer won) and is never overwritten. - The same record again answers created:false. A different record for a released period is refused (409 release_period_taken). - Each entry keeps the approved-set snapshot the record was built with, so a consumer can verify against the set approved at release time. - Verification is #397's demandAggregatesFromRelease, run before writing and on every read. Reads also require strict UTF-8, the exact canonical bytes and matching periods. Reads use O_NOFOLLOW, the directory is lstat-checked, and K1's capability probe runs first. publish verifies and stores one plain copy of its input. - routes/kit-releases.ts adds GET /api/kits/demand/releases and GET /api/kits/demand/releases/:period. Like every /api/kits path, they need an authenticated caller. There is no publish route: the producer calls the ledger server-side. - 38 tests. Mutations: 19 of 20 killed. The survivor is equivalent: lstat reports a symlink as not a directory. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015zYzsSSFUHbPV5DNxssX4A
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Kits K4a: the write-once public demand release ledger. Each closed period's
PublicOpportunityRelease(built by #365'sbuildPublicRelease) is recorded exactly once, and served only after it verifies.A release digest proves the record is unmodified. It does not prove who built it, or that its period was released only once. That is astra's weakest link on #397 (112e): "Callers must obtain the record from the write-once release ledger." PX-13 assigns once-per-period to the publisher (kits).
Draft, stacked on #511 (which stacks on #397). It stays a draft until both merge (steward #5665).
Design
<root>/releases/<YYYY-MM>.jsonon the Kit registry's durable volume (K1's root). No table (no schema change) and no cache.link; EEXIST means another writer won) and is never overwritten.created: false.release_period_taken.{schema, period, publishedAt, publisher, approvedSet, release}, as canonical JSON.approvedSetis the approved-set snapshot the record was built with, normalized as feat(spec): Capability Kit manifest identity, OperatorBindingDTO and OpportunityDTO v0 contracts (interface-only; not before wave D) #397'sapprovedSnapshot, so a consumer verifies against the set approved at release time.demandAggregatesFromRelease(release, approvedSet, asOf)runs before writing and on every read. A read also requires strict UTF-8, the exact canonical bytes, matching periods (file name, entry and record) and a canonical approved-set snapshot. A failing entry is never served, and the listing skips it.publishverifies and stores ONE plain copy of its input.registry_unsupported_fs);Routes
GET /api/kits/demand/releases{period, digest, aggregateCount, publishedAt}GET /api/kits/demand/releases/:period{period, release, approvedSet, publishedAt}; 404 if unreleased, 400 if malformed, 500 if the stored entry fails verification/api/kitspath. Making them public is an api-gate and policy decision for the operator.ledger.publish. painpoints is scoping that side (#5725).Tests (Spark, at 576f8ef)
release-ledger.test.tstsc --noEmitlstatreports a symlink as not a directory)The tests cover:
Follow-ups
KitRegistry, and feat(gateway): durable, write-once, verified Capability Kit registry (kits K1 slice 1) #511 is frozen.publish(painpoints' side).🤖 Generated with Claude Code
https://claude.ai/code/session_015zYzsSSFUHbPV5DNxssX4A