docs(ddd): restore queue authority and bounded-context ownership - #435
docs(ddd): restore queue authority and bounded-context ownership#435seonghobae wants to merge 251 commits into
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Team Run ID: 📒 Files selected for processing (7)
🚧 Files skipped from review as they are similar to previous changes (1)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthrough문서 권위를 crate 중심에서 bounded context 중심으로 재구성했습니다. 시간 의존성 계약, ADR 식별자 정규화, 연구 주장 경계, delivery 기준선과 문서 검증 규칙을 갱신했습니다. Changes문서 권위 및 아키텍처
Estimated code review effort: 4 (Complex) | ~45 minutes Suggested reviewers: Merge Risk: 🟡 Moderate · up to This documentation and validation change establishes architecture, queue, and release guidance, but unresolved documentation inaccuracies and incomplete release evidence could misclassify work or treat an incomplete release as eligible. The PR is not merge-ready until these bounded documentation issues are corrected or explicitly accepted by the appropriate owner. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Write path recovered this cycle. Exact head is Live GitHub re-read at 2026-09-01T10:19:29Z: 136 open PRs (91 draft, 45 non-draft) on protected main Independent human review request is blocked: the only repository collaborator is the author. Copilot review was requested on this head and does not count as independent APPROVE. No self-approval. Queued/pending/skipped/cancelled/stale/predecessor-head checks are non-passing. |
Unpaywall and OpenAlex re-read 2026-09-01T10:22Z remain closed (is_oa false, 0 OA locations). Full texts stay unread. Mean-gate authority is still Putnick and Bornstein (2016, PMC5145197). Rubin T_m remains the complete-data combining rule, not Mislevy PVs.
|
#494 live-authority handoff (2026-09-12) The Rust 1.98.1 prerequisite moved forward non-force from Do not count either |
|
Fresh owner handoff for canonical baseline/TRACEABILITY currentization:
Please currentize the checked-in |
|
Central CodeQL owner-path correction after the prior #494 handoff: the live landing sequence has advanced beyond
Please use this chain when currentizing |
|
Fresh correction to the CodeQL handoff: |
|
Canonical-doc lane refresh — corrected against fresh live authority on 2026-09-12.
Please currentize the checked-in |
|
Tip For best results, initiate chat on the files or code changes. 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -euo pipefail
# Map the two canonical documentation files before inspecting the current-state sections.
for file in docs/product-technical-gap-baseline.md docs/TRACEABILITY.md; do
echo "=== $file: headings ==="
rg -n '^#{1,3} ' "$file"
done
echo "=== References to the stale and current owner evidence ==="
rg -n -C 3 \
-e '97e10a|67d1c4e|494|2051|2106|24bb6591|48c6304|34688687870|34689581833|34688688128|ba10820|310|495|1816|1717|CodeQL|OpenCode|mixed-sign|mixed.sign|half-ULP|half.ULP' \
docs/product-technical-gap-baseline.md docs/TRACEABILITY.md
echo "=== Documentation validator entry points and tests ==="
ast-grep outline scripts/validate_documentation.py --items all --type function
fd -t f . tests | rg '(^|/)(test_.*(gap|traceability|documentation)|.*traceability.*)\.py$' | sort
rg -n -C 2 'TRACEABILITY|product_technical_gap_baseline|gap baseline' tests scripts/validate_documentation.pyLength of output: 28868
Canonical documentation currentization
You are interacting with an AI system. |
|
Canonical-doc lane handoff refresh:
Please currentize the checked-in |
|
Canonical-doc currentization handoff (fresh live authority after owner repair):
Please update checked-in |
|
Canonical-doc authority delta since the previous handoff:
Please currentize checked-in |
|
Canonical-doc handoff (2026-09-13 KST): checked-in #1717's new exact head contains two narrow verified review repairs after its protected-main restack: #1816 remains mutable Draft/open/mergeable at |
|
Canonical-docs handoff: checked-in Current numerical-owner authority to replace the stale #1717/#1816 references in this PR body/docs:
Please source-currentize these exact heads/states and remove predecessor numerical-owner authority from the checked-in current-state sections. Do not convert historical evidence into current acceptance and do not edit the #495 estimand while doing so. |
|
Canonical-doc currentization handoff: live numerical-owner authority has advanced again and the checked-in baseline/TRACEABILITY plus this PR body are stale. Current protected fast-mlsirm base is |
|
Canonical-doc currentization handoff: live fast-mlsirm prerequisite authority changed again. |
|
Gate-state currentization for the fast-mlsirm prerequisite after the staging repair: |
|
Superseding the earlier queued-handler docs handoff: protected handler |
|
Canonical-docs currentization handoff from the Longitudinal/finite-numerics dependency chain. The checked-in/body authority here is materially stale and should replace, not append to, the predecessor state when this single-writer lane edits
Do not treat this handoff comment as checked-in currentization. #435 remains responsible for replacing the obsolete #1717 |
|
Correction for the canonical-docs handoff: the #1717 10/8 storage-buffer packing target is not yet a proven SwiftShader fit. fast-mlsirm pins Current acceptance wording should therefore say: candidate E-step topology is 10 storage + 1 uniform and needs combined>=11; candidate score topology is 8 storage + 1 uniform and needs combined>=9. The owner must first record the controlled adapter's combined limit and packed arena binding-size/buffer-size/alignment limits, then prove actual pipeline creation and production-shaped CPU-f64↔GPU parity/recovery. Owner correction is fast-mlsirm #1717 comment Do not encode the static 10/8 arithmetic as completed GPU acceptance in |
|
Canonical-docs handoff; this comment is not checked-in currentization. Please currentize
The existing #435 body still names #494 |
|
Canonical-docs handoff for the #435 single-writer lane. Current numerical-owner authority is now |
|
Canonical-docs single-writer refresh. Current numerical-owner authority is |
|
Canonical docs handoff, source currentization still required in this single-writer lane:
The checked-in |
|
Authority refresh for checked-in baseline/TRACEABILITY currentization: fast-mlsirm #1717 is now |
|
Fresh owner-state handoff for the checked-in baseline/TRACEABILITY lane; this comment is not source currentization.
Please replace predecessor #1717/#1816/.github authorities in |
|
Fresh owner handoff after protected-main advance in fast-mlsirm. The checked-in current-state sections in
Preserve #495 estimand identity, |
|
Queue-authority currentization handoff (fresh 2026-09-13 sweep):
Please currentize the checked-in |
|
Fresh single-writer handoff for checked-in currentization (do not count this comment as the documentation repair itself): protected TEPP Dependency authority also needs currentizing in |
|
Fresh single-writer handoff for checked-in baseline/TRACEABILITY currentization:
This comment is handoff only, not checked-in docs completion. Please replace predecessor head literals/current-state claims in |
|
Fresh Analysis Run authority handoff for the canonical checked-in docs lane: #416 is now |
|
Single-writer handoff for checked-in queue/TRACEABILITY authority. #416 advanced by ordinary forward commit to exact Also refresh fold-child authority before checked-in docs: #487 is currently |
|
TEPP Validation / Analysis Run single-writer handoff: surviving #416 is now New scientific lineage to currentize in checked-in
Dependent fold-child authority also moved: #487 metadata is currently Do not count this comment as checked-in currentization. #416's PR body has now been currentized to |
Queue authority and operator baseline
This Draft remains TEPP's delivery/queue-authority vehicle. Protected product authority is
main@a243f18da4a4ca8a8d068c39922537f1f8ed6ad0; PR=0 is valid only after protected merge or a verified successor has inherited every valid delta/test/fixture/contract/evidence item. Simple Close is not queue reduction.Current exact head of this Draft is
a9b9ceeb6ac61f66091e08a38b3bee94939df39f. Its central-scheduler repair preserves manualworkflow_dispatch, requires# cwl-org-commercial-entrypoint: v1, and rejects repository-localschedule:/cronreintroduction. No provider credential, required-check, security threshold, or merge permission is weakened.docs/product-technical-gap-baseline.mdanddocs/TRACEABILITY.mdare this lane's canonical checked-in authorities. Historical snapshots may remain as history, but current-state sections must not describe predecessor PR heads, raw LCOV populations, predecessor artifact digests, or review-rate-limit responses as live authority.Live foundation chain
Rust 1.98.1 prerequisite #494
#494 is Draft/open/mergeable at exact
97e10a646ca43babcf06c6e36d5bd8f6b1c3b16aon protectedmain@a243f18.... A narrowARCHITECTURE.mdedit at54ed1dcc...was rejected by exact diff inspection because it unintentionally omitted three existing architecture-table rows. Ordinary forward repair97e10a...restored those rows; comparison from predecessorea2e5ec...to97e10a...has no file delta. No force update or destructive rebase was used.The intended code-current finding therefore remains unresolved:
ARCHITECTURE.mdstill says Stable Rust 1.98.0 is the compile/lint/test/line-coverage reference although the root build-reference/CI/verifier pin is 1.98.1. Repair that sentence only.Cargo.toml rust-version = "1.98.0"remains the MSRV; the immutable Docker build image remains 1.98.0 until a verified 1.98.1 Bookworm digest exists.Fresh exact-head workflows for
97e10a...are terminal: Documentation Quality34564877786, Rust Foundation34564877774, Security Scan34564877776, and SAST Semgrep34564877798are GREEN; CodeQL PR34564877779is RED in delegated compatibility receipt settlement. Language detection103154836880and current-head dispatch103157070548are GREEN. Python103155462817and actions103155462854both successfully read the current-head verdict and fail only atRelease runner or enforce current-head CodeQL verdict. The canonical repair vehicle is now.github#2051@558693e0333e48012beea142f739bc634b0674a7, Draft/open/mergeable on.github main@7fd571dbcdbae6acf29d8f4ee704d7ba6297e4db. It preserves one post-matrix wake coordinator and exact PR/head/base/run/language evidence, but its current root cause is a protected-handler/client rollout mismatch: the PR-head client expects a run identity containing{base_ref, base_sha}while protected default-branchrepository_dispatchstill emits the older handler identity. The owner requires a versioned backward-compatible handler bootstrap before switching the client; blind reruns, synthetic receipts, or droppingbase_refare not acceptance. TEPP must not fabricate a receipt, rerun-loop no-op leaf commits, or fork the control-plane fix locally.After #494 lands normally, descendants based on the current protected main must be integrated/restacked non-force and exact-head evidence reacquired rather than transferred.
Central hourly admission #492
#492 remains intentionally Draft, not Ready for Review, at exact
794ba9e6dda9f043aa499920fdf609b81b075d7e, open/mergeable on current protected main. Its local-schedule/parser repairs remain valid, but the leaf commercial-development workflow still embeds provider credentials and mutable contextual-orchestrator bootstrap/routing..github#2038owns the central reusable-worker/thin-caller policy. contextual-orchestrator #1023 owns the released Actions-facing gateway/auth/provenance and consumer-safe authentication contract; #1083 owns publication of the immutableorchestrator/freerelease. Until those contracts are immutable, TEPP must not copy provider routing/credentials/model selection or consume mutable contextual-orchestrator source as production authority. The staleAGENTS.mdprovider-key guidance belongs to the same eventual consumer migration.Validation Evidence #488 / issue #491
#488 remains the owner-correct Validation Evidence landing vehicle stacked on
#492@794ba9e6..., Draft/open/mergeable at exact520df488fd86ba48008af8ee5a2e112b4587fc22.The public route attempts the checked O(n) neutral-zero exact proof for every
n >= 3with exactly represented finite residuals. O(n²) pairwise reference is used only after O(n) refusal atn <= 16; above sixteen, refusal delegates directly to the establishedbiasimplementation without quadratic pair scratch.n=2keeps its direct identity.Repository-owned numerical evidence now separates exact-real positivity from floating implementation proof.
docs/research/validation-bias-dispersion-positivity-bound.mdproves for every admitted general translated pathn >= 3that canonical translation supplies exact zero and a maximum normalized magnitudexwith1 <= |x| < 2, soD = n Σy² - (Σy)² = Σ_{i<j}(y_i-y_j)² >= n x²/2 >= n/2. That theorem does not authorize removingdispersion_numerator <= 0.0: the implemented path rounds each square, sorted compensated first and second moments,usize -> f64,n*Q, and the final FMA. Source removal still requires an implementation-matched absolute forward-error bound strictly belown/2over the admitted metric domain or a compact caller-valid represented-input counterexample.The target-width and square-root correction-exhaustion obligations remain closed.
validation_coreadmits 64-bit production pointer-width targets; the former denominator-width branch was removed only after the successfulu128perfect-square proof made it impossible.docs/research/validation-bias-standard-error-seed-distance-bound.mdowns the strict<3adjacent-binary64 seed-distance theorem, and production source applies exactly three exact corrections.docs/research/validation-bias-production-resource-admission.mdnow owns the resource/cardinality boundary.analysis_engine::MAX_EVIDENCE_UNITS = 100_000bounds Analysis Run evidence admission, butanalysis_enginehas no currentvalidation_coredependency andAnalysisEvidenceUnitis evidence identity/time/membership metadata rather than a truth/recovered metric pair. There is no typed/versioned proof that every supported product bias-SE call comes throughAnalysisCorpus, or that one evidence unit equals one bias-SE sample. Therefore100_000is not avalidation_coresample cutoff and must not be used to delete numerical refusals. The next buyer-path repair is an explicit evidence-to-metric cardinality contract.The helper false-zero branch remains scientifically/source-domain reachable through the
n=2^54minimum-subnormal construction. The normalized SE is2^-54; exact restoration is2^-1075, which ties to represented zero. Materializing only the two publicf64input slices requires2^58bytes =256 PiBbefore working storage, so a giant allocation is not realistic product acceptance. Preserve the guard and close product acceptance through bounded representation/resource/cardinality evidence, not source rewriting or an arbitrary public-library cutoff.Exact-head
520df488...workflows are terminal. Documentation Quality34573224170and Bias SE Exact-Proof Budget34573224257are GREEN. Rust Foundation34573224268is RED only in Production line and branch coverage job103179819615; Live PostgreSQL103179819441, Rust format/lint/test/rustdoc/dependency policy103179819679, and repository/Python contracts + SBOM/provenance103179819783are GREEN.Current immutable coverage authority is 12,344/12,346 authored production lines from artifact
10188730908, archive digestsha256:f6c560819690274ad205baf77ec46089835d5563e7bbcb3d2f941fb532e63ff0, with onlybias.rs:69andbias.rs:592zero-count; and 4,450/4,452 unique source branch arms from artifact10188776666, archive digestsha256:34006fb155957e34a86385cd9975340fa24bdb1950874c07e9d001e0070a1088, missingbias.rs (68,8)-(68,29)TRUE with folded counts(0,12)and(591,8)-(591,35)TRUE with folded counts(0,32). The exact-head delta from3b5d07b...is documentation-only, and the current LCOV has the same 42,005 source/line DA keys and same two zero-count records; raw LLVM/instrumented totals are not the product authored-source denominator.The earlier CodeRabbit rate limit is no longer current authority. The retried exact-head review completed on
520df488...with no findings in the requested resource/cardinality scope. It independently confirmed that the repair is documentation-only, keepsMAX_EVIDENCE_UNITSdistinct from bias-SE sample cardinality, preserves then=2^54source-domain witness as resource-extreme rather than a realistic fixture, and leaves translated-dispersion floating positivity unresolved. This is review evidence only, not numerical/scientific acceptance. Formal submitted reviews remain historicalCOMMENTED; unresolved inline review threads are zero; there is no qualifying current-head approval.#491 remains open with the same current authority. The isolated
n=2,047candidate/fallback measurements remain characterization only: candidate p9523,306 ns, max RSS2,176 kB, zero pair-record scratch; fallback p9515,385,815 ns, max RSS100,152 kB,2,094,081pair records /100,515,888 bytesexplicit scratch. These are not buyer HTTP p95 guarantees.Longitudinal Modeling #310 / scientific gap #495
#310 remains the Longitudinal Modeling landing vehicle at exact
ba10820e0d28cc33d1b91ef37f6f6d163b3d91e9, Draft/open/mergeable/unmerged on protectedmain@a243f18.... #495's implementedLagPairAverageV1estimand, explicit denominator/refusal populations, unequal-follow-up/permutation contracts, and 4,096-replicate informative-missingness Monte Carlo acceptance are GREEN on that exact head. Rust Foundation34672270380reports 1,574 PASS / 1 FAIL / 0 skipped across 1,575 tests; the sole RED is the public mixed-sign half-ULP finite-mean contract (actual bits5080060379673919488, correctly-rounded expected5080060379673919487). That RED is numerical-owner evidence, not permission to change the estimand, threshold, skip/xfail, or coverage denominator.Reusable finite-binary64 arithmetic remains fast-mlsirm-owned.
fast-mlsirm#1816@432765ccf633c9802e0f796ceeb4d6d572059acfis still Draft/open/mergeable and proposesfast_mlsirm.binary64_mean@1.0.0, but it is mutable and cannot be consumed. Its GPU prerequisitefast-mlsirm#1717@0b31640928e07f4362ce27dad3d310e630ab1b5dremains Draft/open/mergeable with the real SwiftShader capacity RED: the marginal E-step uses 17 storage bindings and score uses 18 while the controlled adapter exposesmax_storage_buffers_per_shader_stage = 10. Bind-group splitting alone cannot repair a per-stage limit; owner-side topology repair must reduce the real pipelines to the adapter limit and prove actual GPU parity/recovery without fallback or skip. The latest immutable fast-mlsirm release remainsv0.9.1, which predates the finite-mean contract.UnitAverageV1therefore remains fail-closed. Do not close #495, mark #310 Ready, or replace TEPP arithmetic until the owner path achieves protected merge plus a new immutable release; then consume only that released contract, remove the local generic mean, rerun the half-ULP RED to GREEN, and reacquire one unchanged TEPP head's required gates and independent approval. The checked-indocs/product-technical-gap-baseline.mdanddocs/TRACEABILITY.mdmust be currentized to this same authority in this single-writer lane rather than by #310.This Draft's own merge bar
On
a9b9ceeb6ac61f66091e08a38b3bee94939df39f, Rust Foundation34180704494, Documentation Quality34180704456, Security Scan34180704429, and SAST Semgrep34180704485are terminal GREEN. CodeQL PR34180704464is terminal RED and remains delegated control-plane evidence, not permission to fabricate a receipt or weaken the gate.Historical review submissions are COMMENTED; there is no qualifying current-head approval. Ready/merge is not claimed.
Release / ownership boundary
Reusable static/generalized psychometric arithmetic remains fast-mlsirm-owned through an immutable released/versioned Published Language/ACL. Semantic LLM routing remains contextual-orchestrator-owned through an immutable released
orchestrator/freeAPI/client/schema contract. contextual-orchestrator #1023 and #1083 remain open owner gaps and its GitHub Releases remain empty, so mutable CO source is not TEPP production authority.A release-ready protected TEPP head still requires code-current PRD/TRD/architecture/ADR/TRACEABILITY/product-gap evidence, exact protected-head Rust/documentation/security/review gates, 100% owned-production authored line+branch coverage without tricks, scientific/recovery acceptance, immutable dependency contracts, version/CHANGELOG/tag/package/SBOM/provenance/reproducibility/rollback evidence, and no unresolved scientific/privacy/security/supply-chain blocker.
Preserve Draft/Proposed state while these conditions remain unresolved. Integrate forward non-force, do not self-approve or destructively rebase, and do not transfer predecessor checks/reviews after a head or base changes.