From 6839f0e03a4667f5bdf3d82facf2414738ab5b1b Mon Sep 17 00:00:00 2001 From: Kenneth Pernyer Date: Thu, 2 Jul 2026 18:38:42 +0200 Subject: [PATCH 1/2] =?UTF-8?q?fix(ci):=20provide=20root-repo=20KB=20?= =?UTF-8?q?=E2=80=94=20intent-codec=20fixtures=20include=20from=20../../KB?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit cross-extension-smoke's intent_codec_applets tests include_str! applet intent JSON from the root coordination repo's KB, which CI never checked out. Clone Reflective-Lab/reflective and symlink KB where the relative include resolves. Cross-repo fixture reach noted as a smell — candidate for moving the contract fixtures in-repo or publishing them. Co-Authored-By: Claude Fable 5 --- scripts/ci/checkout-reflective-siblings.sh | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/scripts/ci/checkout-reflective-siblings.sh b/scripts/ci/checkout-reflective-siblings.sh index d67d06f..5d49c07 100755 --- a/scripts/ci/checkout-reflective-siblings.sh +++ b/scripts/ci/checkout-reflective-siblings.sh @@ -51,6 +51,16 @@ checkout_reflective_repo manifold-adapters ../mosaic-extensions/manifold-adapter checkout_reflective_repo mnemos-knowledge ../mosaic-extensions/mnemos-knowledge checkout_reflective_repo prism-analytics ../mosaic-extensions/prism-analytics +# Root coordination repo: cross-extension-smoke fixtures include applet +# intent JSON from the root repo's KB via ../KB relative to this repo's +# parent (include_str! follows the symlink). +checkout_reflective_repo reflective ../_reflective-root +kb_link="${workspace}/../KB" +if [[ ! -e "$kb_link" ]]; then + echo "==> symlink KB -> _reflective-root/KB" + ln -s "_reflective-root/KB" "$kb_link" +fi + # Reflective-root siblings. checkout_reflective_repo atelier-showcase ../atelier-showcase checkout_reflective_repo runtime-runway ../runtime-runway From 7eef2ee894b3c6a8bdc938fe257186c682d531ed Mon Sep 17 00:00:00 2001 From: Kenneth Pernyer Date: Thu, 2 Jul 2026 19:50:36 +0200 Subject: [PATCH 2/2] =?UTF-8?q?fix(ci):=20vendor=20applet=20intent=20fixtu?= =?UTF-8?q?res=20=E2=80=94=20root=20repo=20is=20private?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The previous attempt cloned Reflective-Lab/reflective for the KB fixtures, but that repo is private and CI clones anonymously. Vendor the two intent manifests into tests/fixtures/ with provenance noted; codec checks fail loudly on divergence. Co-Authored-By: Claude Fable 5 --- .../activate-subscription.intent.json | 158 +++++++++++++++++ .../refill-prepaid-ai-credits.intent.json | 161 ++++++++++++++++++ .../tests/intent_codec_applets.rs | 7 +- scripts/ci/checkout-reflective-siblings.sh | 10 -- 4 files changed, 324 insertions(+), 12 deletions(-) create mode 100644 crates/cross-extension-smoke/tests/fixtures/activate-subscription.intent.json create mode 100644 crates/cross-extension-smoke/tests/fixtures/refill-prepaid-ai-credits.intent.json diff --git a/crates/cross-extension-smoke/tests/fixtures/activate-subscription.intent.json b/crates/cross-extension-smoke/tests/fixtures/activate-subscription.intent.json new file mode 100644 index 0000000..917e485 --- /dev/null +++ b/crates/cross-extension-smoke/tests/fixtures/activate-subscription.intent.json @@ -0,0 +1,158 @@ +{ + "manifest_version": "intent-codec-applet.v1", + "job_name": "Activate paid subscription", + "primary_job_key": "activate-subscription", + "status": "code-backed", + "source_schema": "../templates/intent-codec-applet.manifest.schema.json", + "human_readable": "activate-subscription.md", + "trigger": "subscription_activation_requested", + "current_workaround": "A billing or RevOps operator manually checks payment, plan, entitlements, and opening balance before enabling customer access.", + "source_evidence": { + "truth_catalog": "bedrock-platform/helms/crates/truth-catalog/src/lib.rs registers activate-subscription.", + "feature": "bedrock-platform/helms/truths/jobs/activate_subscription.feature", + "executable": "bedrock-platform/helms/crates/workbench-backend/src/lib.rs execute_activate_subscription", + "tests": "execute_activate_subscription_projects_revenue_state and execute_activate_subscription_blocks_without_payment_confirmation", + "event": "crm-contracts maps SubscriptionActivationRequested to activate-subscription" + }, + "functional_need": { + "outcome": "Turn an agreed commercial plan into active subscription, entitlement, and auditable opening financial state.", + "inputs": [ + "organization_id", + "subscription_id", + "catalog_item_id", + "payment_confirmed" + ], + "output": "Completed truth session with subscription projection and entitlement IDs, or blocked truth session with approval/workflow references.", + "constraints": [ + "Subscription must belong to the organization.", + "Active subscription must resolve to a valid catalog plan.", + "Payment confirmation is required before activation.", + "Activation exceptions move through a workflow case and approval.", + "Entitlements and opening financial state must remain auditable." + ], + "success_signal": "The truth session completes, subscription_id is projected, entitlements are derived, and no approval is required." + }, + "emotional_need": { + "operator_anxiety": "The customer may have paid but still be locked out, or may receive access before payment and plan terms are trustworthy.", + "desired_confidence": "Payment, plan, subscription state, entitlement grant, and operator receipt agree before support or the customer sees a mismatch.", + "tolerance": "Prefer a blocked session and manual review over silent activation when payment or terms are uncertain." + }, + "relational_need": { + "dependent_parties": [ + "customer admin", + "billing operator", + "RevOps", + "support", + "finance", + "partner owner when marketplace or revenue-share terms apply" + ], + "trust_obligation": "Explain why access was granted or paused without treating provider IDs as commercial truth.", + "handoff_created": "If activation is blocked, Helm owns the operator-visible approval/workflow handoff." + }, + "failure_modes": [ + "Activating access before payment is confirmed.", + "Granting entitlements for the wrong organization or subscription.", + "Treating Stripe or provider object IDs as canonical entitlement truth.", + "Mutating commercial state without an auditable operator receipt.", + "Hiding activation exceptions inside app-local state." + ], + "authority": { + "requester": "subscription_activation_requested commerce/runtime envelope", + "approvers": [ + "Commerce Rails policy", + "billing operator for blocked activation" + ], + "allowed_actions": [ + "activate subscription", + "derive entitlements from catalog plan", + "open approval workflow", + "project subscription and entitlement state" + ], + "forbidden_actions": [ + "grant entitlement without payment confirmation", + "let the applet own provider reconciliation", + "store provider object ID as canonical entitlement", + "bypass Helm approval on blocked activation" + ], + "approval_points": [ + "payment_confirmed is absent or false", + "non-standard plan terms or manual review signal" + ], + "reversibility": "partially_reversible", + "expiry": "payment or activation event replay window", + "audit_visibility": [ + "operator", + "finance", + "support", + "partner owner" + ] + }, + "evidence_contract": { + "required_sources": [ + { + "source": "Commerce Rails verified subscription contract", + "freshness": "current at activation time", + "authority": "primary" + }, + { + "source": "Runtime or commerce payment confirmation envelope", + "freshness": "within replay window", + "authority": "primary" + }, + { + "source": "catalog plan definition", + "freshness": "current at activation time", + "authority": "primary" + }, + { + "source": "Helm approval record when activation blocks", + "freshness": "current workflow case", + "authority": "primary" + } + ], + "disallowed_sources": [ + "raw provider ID as entitlement truth", + "app-local boolean that bypasses commercial verification" + ], + "confidence_floor": "payment_confirmed must be true for automatic activation", + "conflict_policy": "stop", + "sensitive_fields": [ + "organization_id", + "subscription_id", + "catalog_item_id", + "payment reference or provider correlation IDs" + ] + }, + "runtime_needs": [ + "normalized commerce/runtime event ingress", + "secret handling for payment-provider verification outside the applet", + "telemetry for activation, blocked session, approval, and retry", + "durable workflow/approval references" + ], + "commercial_needs": [ + "subscription lifecycle state", + "catalog plan resolution", + "entitlement grant", + "opening ledger or balance context", + "provider reconciliation outside the applet" + ], + "projection": { + "operator_view": "subscription ID, plan/catalog item, activation state, entitlement IDs, approval IDs, workflow case IDs, stop reason", + "customer_or_partner_view": "access active or activation paused with support-safe reason" + }, + "non_goals": [ + "Build a billing dashboard inside the applet.", + "Let the applet own Stripe/provider verification.", + "Let the applet own entitlement or subscription canonical truth.", + "Add unrelated billing jobs such as top-up, upgrade, suspension, or reconciliation to this applet." + ], + "layer_mapping": { + "applet": "Minimal activation request/projection surface.", + "helm": "Operator approval, workflow case, blocked-session receipt, and trust-transfer view.", + "axiom": "activate-subscription Truth shape and candidate IntentPacket.", + "organism": "Future formation selection for non-standard activation review.", + "converge": "Admission, criteria outcomes, completed or blocked truth session, and stop reason.", + "runtime_runway": "Event ingress, auth, secrets, telemetry, and durable runtime envelope.", + "commerce_rails": "Subscription, catalog plan, entitlement, ledger/opening balance, and provider reconciliation authority." + } +} diff --git a/crates/cross-extension-smoke/tests/fixtures/refill-prepaid-ai-credits.intent.json b/crates/cross-extension-smoke/tests/fixtures/refill-prepaid-ai-credits.intent.json new file mode 100644 index 0000000..a90802f --- /dev/null +++ b/crates/cross-extension-smoke/tests/fixtures/refill-prepaid-ai-credits.intent.json @@ -0,0 +1,161 @@ +{ + "manifest_version": "intent-codec-applet.v1", + "job_name": "Refill prepaid AI credits", + "primary_job_key": "refill-prepaid-ai-credits", + "status": "code-backed", + "source_schema": "../templates/intent-codec-applet.manifest.schema.json", + "human_readable": "refill-prepaid-ai-credits.md", + "trigger": "prepaid_top_up_settled", + "current_workaround": "A billing operator manually confirms payment and updates prepaid usage balance.", + "source_evidence": { + "truth_catalog": "bedrock-platform/helms/crates/truth-catalog/src/lib.rs registers refill-prepaid-ai-credits.", + "feature": "bedrock-platform/helms/truths/jobs/refill_prepaid_ai_credits.feature", + "executable": "bedrock-platform/helms/crates/workbench-backend/src/lib.rs execute_refill_prepaid_ai_credits", + "tests": "execute_refill_prepaid_ai_credits_updates_entitlement_balance and execute_refill_prepaid_ai_credits_blocks_pending_payment", + "event": "crm-contracts maps PrepaidTopUpSettled to refill-prepaid-ai-credits" + }, + "functional_need": { + "outcome": "Apply a settled top-up to prepaid AI credit balances with financial traceability.", + "inputs": [ + "organization_id", + "subscription_id", + "amount_minor", + "currency_code", + "payment_reference", + "payment_status" + ], + "output": "Ledger-backed credit grant and updated entitlement balance, or blocked review with approval/workflow references.", + "constraints": [ + "Top-up payment must be settled before credit grant.", + "Subscription must be active and belong to the organization.", + "Currency and amount must match the commercial event.", + "Ledger receipt must be durable before the operator projection declares success.", + "Risky top-ups move through Helm review instead of app-local mutation." + ], + "success_signal": "Confirmed top-up appears as a ledger-backed credit grant and entitlement balance increases for the correct account." + }, + "emotional_need": { + "operator_anxiety": "The customer may run out of AI credits after paying, or the system may grant spendable balance for a risky or unsettled payment.", + "desired_confidence": "Payment settlement, subscription, amount, currency, ledger entry, and entitlement balance agree before usage resumes.", + "tolerance": "Prefer a blocked review over balance mutation when payment state, amount, currency, or risk signals are unclear." + }, + "relational_need": { + "dependent_parties": [ + "customer admin", + "finance", + "support", + "runtime metering", + "billing operator", + "partner owner when marketplace settlement applies" + ], + "trust_obligation": "Explain why credits were granted or paused without turning provider reconciliation into applet-owned truth.", + "handoff_created": "If refill is blocked, Helm owns the operator-visible risk or payment review handoff." + }, + "failure_modes": [ + "Granting credits before payment is settled.", + "Increasing the wrong subscription balance.", + "Losing payment-to-ledger traceability.", + "Treating provider payment IDs as canonical credit state.", + "Hiding risk review inside app-local state." + ], + "authority": { + "requester": "prepaid_top_up_settled commerce/runtime envelope", + "approvers": [ + "Commerce Rails policy", + "billing operator for risky top-up" + ], + "allowed_actions": [ + "grant prepaid credit", + "append ledger entry", + "open approval workflow", + "project credit receipt" + ], + "forbidden_actions": [ + "grant credit for pending payment", + "let the applet own provider reconciliation", + "bypass risk review", + "mutate balance without ledger traceability" + ], + "approval_points": [ + "pending payment", + "unusual top-up size or risk signal" + ], + "reversibility": "partially_reversible", + "expiry": "payment event replay window", + "audit_visibility": [ + "operator", + "finance", + "support", + "partner owner" + ] + }, + "evidence_contract": { + "required_sources": [ + { + "source": "Commerce Rails verified top-up event", + "freshness": "within replay window", + "authority": "primary" + }, + { + "source": "active subscription commercial commitment", + "freshness": "current at top-up time", + "authority": "primary" + }, + { + "source": "ledger credit grant receipt", + "freshness": "created during truth execution", + "authority": "primary" + }, + { + "source": "Helm approval record when risk review blocks", + "freshness": "current workflow case", + "authority": "primary" + } + ], + "disallowed_sources": [ + "raw provider ID as balance truth", + "app-local credit counter without ledger receipt" + ], + "confidence_floor": "payment_status must be settled for automatic refill", + "conflict_policy": "stop", + "sensitive_fields": [ + "organization_id", + "subscription_id", + "amount_minor", + "currency_code", + "payment_reference" + ] + }, + "runtime_needs": [ + "normalized top-up event ingress", + "provider secret handling outside the applet", + "balance-change telemetry", + "durable ledger reference" + ], + "commercial_needs": [ + "payment settlement state", + "subscription commitment", + "credit entitlement balance", + "ledger credit grant", + "provider reconciliation outside the applet" + ], + "projection": { + "operator_view": "payment status, grant amount, subscription, credit entitlement, ledger entry, approval IDs, workflow case IDs, and stop reason", + "customer_or_partner_view": "credit balance updated or refill paused with support-safe reason" + }, + "non_goals": [ + "Build the usage metering engine.", + "Let the applet own provider verification.", + "Let the applet own canonical credit storage.", + "Mix subscription activation into this applet." + ], + "layer_mapping": { + "applet": "Minimal prepaid refill request/projection surface.", + "helm": "Payment/risk review, workflow case, blocked-session receipt, and trust-transfer view.", + "axiom": "refill-prepaid-ai-credits Truth shape and candidate IntentPacket.", + "organism": "Future formation selection for unusual top-up or fraud review.", + "converge": "Admission, criteria outcomes, completed or blocked truth session, and stop reason.", + "runtime_runway": "Event ingress, auth, secrets, telemetry, and durable runtime envelope.", + "commerce_rails": "Payment settlement, subscription commitment, credit entitlement, ledger grant, and provider reconciliation authority." + } +} diff --git a/crates/cross-extension-smoke/tests/intent_codec_applets.rs b/crates/cross-extension-smoke/tests/intent_codec_applets.rs index 8c858b5..51e3899 100644 --- a/crates/cross-extension-smoke/tests/intent_codec_applets.rs +++ b/crates/cross-extension-smoke/tests/intent_codec_applets.rs @@ -8,9 +8,12 @@ use arena_intent_cases::{AppletIntentCase, applet_cases}; use serde::Deserialize; +// Vendored from the root repo's KB/02-product/applets/ (that repo is private, +// so CI cannot reach it via a relative include). If the canonical manifests +// change, re-copy them here — divergence fails these codec checks loudly. const APPLET_MANIFESTS: &[&str] = &[ - include_str!("../../../../KB/02-product/applets/activate-subscription.intent.json"), - include_str!("../../../../KB/02-product/applets/refill-prepaid-ai-credits.intent.json"), + include_str!("fixtures/activate-subscription.intent.json"), + include_str!("fixtures/refill-prepaid-ai-credits.intent.json"), ]; #[derive(Debug, Deserialize)] diff --git a/scripts/ci/checkout-reflective-siblings.sh b/scripts/ci/checkout-reflective-siblings.sh index 5d49c07..d67d06f 100755 --- a/scripts/ci/checkout-reflective-siblings.sh +++ b/scripts/ci/checkout-reflective-siblings.sh @@ -51,16 +51,6 @@ checkout_reflective_repo manifold-adapters ../mosaic-extensions/manifold-adapter checkout_reflective_repo mnemos-knowledge ../mosaic-extensions/mnemos-knowledge checkout_reflective_repo prism-analytics ../mosaic-extensions/prism-analytics -# Root coordination repo: cross-extension-smoke fixtures include applet -# intent JSON from the root repo's KB via ../KB relative to this repo's -# parent (include_str! follows the symlink). -checkout_reflective_repo reflective ../_reflective-root -kb_link="${workspace}/../KB" -if [[ ! -e "$kb_link" ]]; then - echo "==> symlink KB -> _reflective-root/KB" - ln -s "_reflective-root/KB" "$kb_link" -fi - # Reflective-root siblings. checkout_reflective_repo atelier-showcase ../atelier-showcase checkout_reflective_repo runtime-runway ../runtime-runway