This commit is contained in:
@@ -0,0 +1,52 @@
|
||||
# Scheduled synchronization evidence convergence
|
||||
|
||||
Use this procedure when an Architecture synchronization must correlate six authorized Discord channels with mutable Gitea pull requests and exact-head CI without churning an owning PR.
|
||||
|
||||
## Freeze the initial evidence window
|
||||
|
||||
1. Read only the six authorized project channels.
|
||||
2. Record one high-watermark per channel: newest message ID, timestamp, author ID, and author type.
|
||||
3. Fetch potentially substantive messages in full. A truncated digest is discovery evidence only.
|
||||
4. Preserve the frozen high-watermarks unchanged while repository and CI validation runs.
|
||||
|
||||
## Stabilize mutable remote facts
|
||||
|
||||
For each relevant pull request, fetch fresh server-side details and the changed-file list immediately before validation. Record:
|
||||
|
||||
- default branch and freshly resolved default SHA;
|
||||
- PR state, merge state, mergeability, base SHA, head SHA, and head ref;
|
||||
- exact changed-file list;
|
||||
- latest terminal Actions task whose full `head_sha` equals the PR head.
|
||||
|
||||
Use a harmless cache-busting query parameter on Gitea task and PR reads when response freshness is uncertain. Never transfer CI success from an earlier head.
|
||||
|
||||
When a PR advanced since the previous Architecture review:
|
||||
|
||||
1. fetch the current named branch or immutable head explicitly;
|
||||
2. assert the candidate worktree's full `HEAD` equals the server-side PR head;
|
||||
3. compare default-to-current for full PR scope;
|
||||
4. compare previously reviewed head directly to current head for incremental drift (`git diff <old>..<new>`, not a three-dot merge-base diff);
|
||||
5. validate in the candidate worktree's actual working directory and print both `pwd` and full `HEAD` before and after validation.
|
||||
|
||||
## Classify before changing an Architecture artifact
|
||||
|
||||
An owning PR advance warrants exact-head review, but not automatically an Architecture edit. Classify the delta:
|
||||
|
||||
- **Material Architecture effect:** human lifecycle decision, canonical shared-data change consumed by Architecture, Architecture-path/configuration change, runtime/deployment truth that contradicts current Architecture text, or PR state/head drift that changes the gate.
|
||||
- **Corroborating only:** bot-authored evidence that preserves lifecycle state and does not contradict the durable gate.
|
||||
|
||||
For corroborating-only evidence, keep the Architecture PR head unchanged after exact-head review and report the validated owning-head transition. Do not refresh dated provenance merely to chase bot-only high-watermarks.
|
||||
|
||||
## Final convergence guard
|
||||
|
||||
Query each channel with `after=<frozen-high-watermark>`. If any delta appears, fetch every intervening potentially substantive message in full and reclassify it. Then re-read:
|
||||
|
||||
- default SHA;
|
||||
- each relevant PR head/state/changed-file list;
|
||||
- latest exact-head terminal CI task.
|
||||
|
||||
Finish only after one complete pass finds no channel delta and unchanged remote facts. This final guard proves only that nothing arrived after the frozen window; it does not replace the initial authorization-sensitive history scan.
|
||||
|
||||
## Credential and output safety
|
||||
|
||||
Load configured credentials only inside the short-lived process. Parse profile environment keys in memory, never print token values or authorization headers, and emit only non-secret IDs, SHAs, statuses, file paths, and message metadata. Store probes outside repository worktrees and use run-unique filenames when concurrent scheduled jobs may share the host.
|
||||
Reference in New Issue
Block a user