Skip to content

docs(adr): ADR-0020 — rescope SC-010 and authorize work toward the Backstage catalog adapter - #82

Merged
mbeacom merged 3 commits into
mainfrom
mbeacom-supreme-guacamole
Aug 4, 2026
Merged

docs(adr): ADR-0020 — rescope SC-010 and authorize work toward the Backstage catalog adapter#82
mbeacom merged 3 commits into
mainfrom
mbeacom-supreme-guacamole

Conversation

@mbeacom

@mbeacom mbeacom commented Aug 4, 2026

Copy link
Copy Markdown
Owner

What this is

specs/009-catalog-binding-viability/ — the Backstage catalog-binding spike — already executed and recorded blocked (blockedShortfall: "envelope-or-scale-evidence-incomplete"). Under contracts/evidence-bundle-and-verdict.md §4 that forces recommendation = null, and spec.md's Output Recommendation says even a go-explicit "MUST NOT itself schedule, authorize, or scope a packages/adapters/catalog-backstage implementation."

So no artifact in the repository authorized the adapter. This record is that authorization — for the work, not the release.

Status: accepted, ratified by @mbeacom on 2026-08-04.

Why the blocked verdict does not measure the generator

The shortfall is narrower than its name. Scale evidence was captured for all three passes (T052/T056/T060 [X], aggregated T061); only the envelope half fired. Of three required passes, only synthetic produced a populated envelope.

SC-010 admits no passing implementation under FR-001's frozen inputs. community-plugins contains nexus-repository-manager/catalog-info.yaml — two YAML documents, both kind: Component, both metadata.name: backstage-community-nexus-repository-manager (44 chars, passes isValidObjectName). Both fully admissible, so ADR-0012's owned-paths-fail-closed-atomic assertion requires the abort. SC-010 names that corpus non-fungibly.

ADR-0015 established this while explicitly declining to benefit from it, and its Conditions of Acceptance 3 expressly permits a rescope "subject to a separate record." This is that record — it does not claim ADR-0015 required it.

What it decides

  • Rescopes SC-010 so a correct, atomic, correctly-classified fail-closed rejection satisfies the criterion.
  • Authorizes implementation work against ADR-0012's four-item production gate (lines 202–220) — a gate list the first draft had missed entirely, having misattributed it to ADR-0012's action item 1.
  • Does not authorize release. Gate 3 (the reference oracle) is unmet; the oracle carries a known-wrong derivedPathPatterns ordering and must be re-frozen. Release is deferred to a later record gated on clause 5 plus ADR-0012 gates 3 and 4.
  • Spike 009 stands unmodified — no checkbox flipped, no verdict rewritten.

The gap it does not paper over

The reject path is proven on 194 real descriptors; the accept path only on synthetic input. Clause 5 makes that a release gate requiring two distinct steps: the accept corpus, its maintainer-authored adrkit.io/owned-paths overlay, its expected paths and its recorded selection basis and size are frozen and independently audited before generator output; and after the run, derived ownership is diffed against those frozen expectations at zero false positives and zero false negatives. A digest proves integrity, not correctness.

Also recorded honestly: zero of 156 real descriptors carry the annotation. Clause 5 gates technical compatibility only — adoption is entirely ungated, and the adapter could clear every gate here and release into zero demand.

Review

Adversarial review from fresh contexts, two model lineages, four rounds, eight reviews. Every round found at least one substantive defect; every finding was accepted.

  • Round 1 — both FAIL. The stricter review was upheld: ADR-0012's gate list is explicit and gate 3 is open. The draft's outright production authorization became clauses 5, 6 and 9.
  • Round 2 — split. Its blocking finding was created by round 1's correction: clause 5 had become covertly adoption-contingent, contrary to ADR-0014.
  • Round 3 — both FAIL, converging independently on the frontmatter assertion having missed round 2's fix.
  • Round 4 — split, and the FAIL prevailed: clause 5 froze expected paths and never required comparing output against them, reproducing the defect the record exists to prevent (spike 009's oracle was "not an executed test harness"). One proposed remedy was rejected — fixing an exact minimum entity count would breach ADR-0012's "production limits are not guessed now."

Three of the four defects were in the accept-path gate, each created by the previous round's fix to it. The record documents this non-convergence in its own Review history rather than claiming a clean bill, and states plainly that round 4's corrections are themselves unreviewed at ratification.

Checks

bun test 857 pass / 0 fail · typecheck clean · check:depscore-has-no-adapter-deps: ok · adr lint → 20 records, 0 errors, 0 warnings.

Per ADR-0016, agent-accepted-requires-ratifier was observed failing on this record with ratifiedBy removed and passing with it restored, so the ratification gate is load-bearing rather than assumed.

The one non-doc change is bumping the dogfood corpus count in packages/cli/test/lint.test.ts from 19 → 20, matching the established pattern for adding a record.

…the Backstage catalog adapter

Spike 009 recorded `blocked` with shortfall
`envelope-or-scale-evidence-incomplete`. Under
contracts/evidence-bundle-and-verdict.md §4 that forces
`recommendation = null`, so nothing in the repository authorizes the
catalog adapter, and spec.md's Output Recommendation says even a
`go-explicit` would not have.

The shortfall is narrower than its name. Scale evidence was captured for
all three passes (T052/T056/T060, aggregated T061); only the envelope
half fired. Both real-corpus passes fail-closed-rejected because both
corpora are genuinely defective.

SC-010 admits no passing implementation under FR-001's frozen inputs.
community-plugins carries two fully admissible YAML documents both named
`backstage-community-nexus-repository-manager`, so ADR-0012's
`owned-paths-fail-closed-atomic` assertion requires the abort; SC-010
names that corpus non-fungibly. ADR-0015 established this while
declining to benefit from it, and its Conditions of Acceptance 3
expressly permits a rescope subject to a separate record. This is that
record.

It rescopes SC-010 so a correct fail-closed rejection satisfies the
criterion, and authorizes implementation work against ADR-0012's
four-item production gate (lines 202-220) — of which gate 3, the
reference oracle, is unmet. It does not authorize release: that is
deferred to a later record gated on clause 5 plus ADR-0012 gates 3 and 4.

Spike 009 stands unmodified; no checkbox is flipped and no verdict is
rewritten.

Reviewed adversarially from fresh contexts across two model lineages
over three rounds. Every round found substantive defects and every
finding was accepted; in two of three the defect was created by the
previous round's correction. Round 3's reviews converged independently
on the frontmatter assertion having missed round 2's fix. The record
documents that non-convergence rather than claiming a clean bill.

Status is `proposed`: an agent-drafted record cannot reach `accepted`
without a named human ratifier, and the lint gate was observed failing
on that rule before being trusted (ADR-0016).

Also bumps the dogfood corpus count in packages/cli/test/lint.test.ts
from 19 to 20, matching the established pattern for adding a record.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot AI review requested due to automatic review settings August 4, 2026 02:31
@gemini-code-assist

Copy link
Copy Markdown

Caution

The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Drafts ADR-0020 to rescope SC-010 and authorize Backstage adapter implementation work while retaining release gates.

Changes:

  • Adds ADR-0020 with evidence, constraints, and action items.
  • Updates the repository corpus-count test.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 1 comment.

File Description
docs/adr/0020-...md Records the proposed rescope and authorization.
packages/cli/test/lint.test.ts Updates expected ADR count to 20.

## Review history

Two independent adversarial reviews from fresh contexts, across two model
lineages, over two rounds before ratification. The second round was bounded to
@mbeacom mbeacom self-assigned this Aug 4, 2026
mbeacom and others added 2 commits August 4, 2026 19:01
…s frozen expectations

Round-4 adversarial review split PASS/FAIL across the two lineages. The
FAIL prevailed on the merits, and its lead finding is the sharpest of the
four rounds: clause 5 froze the accept corpus's expected paths and then
never required anything to be compared against them.

A populated, digest-verified envelope proves integrity, not correctness —
a semantically wrong envelope carries a perfectly valid self-digest. The
release gate could have been cleared by output that was simply wrong.
That reproduced the exact defect this record was written to avoid: spike
009's own oracle was, on its evidence index's admission, "not an executed
test harness", with expectations frozen and never diffed.

Clause 5 now requires a post-output comparison of derived ownership
against the frozen expectations at zero false positives and zero false
negatives — the standard ADR-0012 already names as production-readiness
evidence — as a step distinct from the pre-output freeze/audit, each
recording its own hashes and PASS/FAIL.

The same review found "at least one annotated entity ... a floor rather
than a target" set no enforceable adequacy bar, so an audited single
hand-picked descriptor still satisfied the letter. The defect is
accepted; the proposed remedy of fixing an exact minimum count is not,
because ADR-0012 requires production limits be ratified from evidence
rather than guessed. The independent audit must instead record an
explicit adequacy finding.

The reviews disagreed on whether the frontmatter assertion had drifted
from clause 5 again. The PASS found it "less detailed ... but asserts
nothing the body denies"; the FAIL held that an assertion omitting the
body's selection-basis and size controls is enforceable as written and
therefore weaker than the clause it encodes. The FAIL was upheld: clause
8 designates that assertion as the rule a future CI gate compiles from.
The drafting session had found the same omission independently before
either review returned. The assertion now carries the selection basis,
size, adequacy finding and post-output comparison.

Also corrects the review history's own round count (it still read "two
rounds") and adds the post-output comparison as its own action item.

Four rounds, eight reviews, a substantive defect in every round — three
of them in the accept-path gate, each created by the previous round's fix
to it. Round 4's corrections are not themselves reviewed, and the record
says so.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Sets status: accepted and provenance.ratifiedBy: "@mbeacom", and adds the
ratification banner following the ADR-0015/ADR-0019 convention.

The banner records two things that are not otherwise checkable from the
repository:

1. How ratification happened. The maintainer ratified by instruction
   during an agent session, delegating the mechanical edit rather than
   typing it. ratifiedBy names the deciding human, which is accurate, but
   the manner is recorded because this is the first record ratified that
   way and the repository cannot show it.

2. What was open at the time. Round 4's corrections had not been
   independently reviewed, and across four rounds and eight reviews every
   round found at least one substantive defect — three in the accept-path
   gate, each created by the previous round's fix to it. The earlier
   stated standard ("stop after round 3 if it is clean") was not met on
   its own terms, since round 3 was not clean; the maintainer overrode it
   deliberately. Ratifying on that basis is a judgement about where the
   remaining risk sits, not a claim the record is defect-free.

The agent-accepted-requires-ratifier gate was observed failing on this
record with ratifiedBy removed, and passing with it restored, so the rule
is load-bearing here rather than assumed (ADR-0016).

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@mbeacom mbeacom changed the title docs(adr): draft ADR-0020 — rescope SC-010 and authorize work toward the Backstage catalog adapter docs(adr): ADR-0020 — rescope SC-010 and authorize work toward the Backstage catalog adapter Aug 4, 2026
@mbeacom
mbeacom merged commit fbad18e into main Aug 4, 2026
11 checks passed
@mbeacom
mbeacom deleted the mbeacom-supreme-guacamole branch August 4, 2026 23:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants