Skip to content
19 changes: 19 additions & 0 deletions plan/Plan-007-source-qualification-readiness/index.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,19 @@
---
type: index
title: "Plan-007 — Progressive source-qualification readiness"
description: "Contents of the Plan-007 source-qualification-readiness bundle."
okf_version: "0.1"
---
# Plan-007 — Progressive source-qualification readiness

## Contents

* [Plan-007: Progressive source-qualification readiness](./plan.md) - Requirements, dependency graph, tests, tracks and gates.
* [Task-009: M6 specification and review](./tasks/Task-009-m6-specification-review.md) - Frozen reviewed source-readiness contract; tracked by tl-syntax#34.
* [Task-010: Prerequisite admission](./tasks/Task-010-prerequisite-admission.md) - External identity ledger and no-workaround gate; tracked by tl-syntax#45.
* [Task-011: Executable-path classification](./tasks/Task-011-executable-path-classification.md) - Complete census and Rust/shared parity; tracked by tl-syntax#46.
* [Task-012: Candidate binding](./tasks/Task-012-candidate-binding.md) - Immutable subject and fresh producer output; tracked by tl-syntax#47.
* [Task-013: Lifecycle and decision admission](./tasks/Task-013-lifecycle-decision-admission.md) - Retention, history, review and human authority; tracked by tl-syntax#48.
* [Task-014: Real source-grounding integration](./tasks/Task-014-real-source-grounding-integration.md) - IT-001 shared-contract gate; tracked by tl-syntax#49.
* [Task-015: Integrator package](./tasks/Task-015-integrator-package.md) - IT-002 publication and rights handoff; tracked by tl-syntax#50.
* [Task-016: Final assurance](./tasks/Task-016-final-assurance.md) - Independent review, gap analysis and human gate; tracked by tl-syntax#51.
26 changes: 26 additions & 0 deletions plan/Plan-007-source-qualification-readiness/log.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,26 @@
---
type: log
title: "Plan-007 — Update Log"
description: "Chronological log of the progressive source-qualification-readiness plan."
---
# Plan-007 — Update Log

## History

* **2026-09-10** — Created from reviewed M6 specification commit `767dc92a97f1b3d9ffbb76467bdda9ecf2261e40`; decomposed into eight tasks across specification, external-gate, critical-path, post-gate and final-assurance tracks. The then-named Task-001 is complete; all implementation tasks remain blocked on merge and their declared shared prerequisites.
* **2026-09-13** — Independent review renumbered the bundle to repository-unique
Task-009 through Task-016, mapped the completed specification task to #34,
created implementation tickets #45 through #51, and recorded exact owners,
consumers, evidence methods and resume conditions. Engineering Assurance #34
is merged but remains unavailable here until an immutable compatible release
carries that contract.
* **2026-09-13** — Independent SR-066 through SR-074 review at `33678fa`
closed pathname ABA/TOCTOU, event-population/time-authority and archival-
census bypass findings. All implementation tasks remain blocked; no TM-004
row or human release decision advanced.
* **2026-09-13** — Merged current main at `5b1c134`, preserving its W/M source
and canonical-graph corpus additions alongside the narrowed archival census.
SR-075 records the exact `9598fea` candidate review: `make ci` passes with 75
Rust tests and one doctest, Quire validates 163 specification and 11 plan
documents, and all 48 M6 obligations classify without an assurance mismatch.
TM-004 remains truthfully planned at 0 of 17 rows.
170 changes: 170 additions & 0 deletions plan/Plan-007-source-qualification-readiness/plan.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,170 @@
---
id: Plan-007
title: "tl-syntax — progressive source-qualification readiness"
type: Plan
status: active
relationships:
- target: ix://agent-ix/tl-syntax/StR-004
type: references
- target: ix://agent-ix/tl-syntax/FR-014
type: references
- target: ix://agent-ix/tl-syntax/FR-015
type: references
- target: ix://agent-ix/tl-syntax/FR-016
type: references
- target: ix://agent-ix/tl-syntax/FR-017
type: references
- target: ix://agent-ix/tl-syntax/FR-018
type: references
- target: ix://agent-ix/tl-syntax/NFR-004
type: references
- target: ix://agent-ix/tl-syntax/NFR-005
type: references
- target: ix://agent-ix/tl-syntax/IT-001
type: references
- target: ix://agent-ix/tl-syntax/IT-002
type: references
---
# Implementation Plan: Progressive source-qualification readiness

This TDD plan advances M6 only through released shared contracts and attributed
human decisions. It does not qualify native Quire, a monitor, or an integrating
system, and it does not turn tl-syntax into a user-authored language.

## Requirements Summary

### Stakeholder Requirements

- [ ] **StR-004**: Supply attributable, progressively reviewable source-readiness facts without claiming downstream qualification.

### Functional Requirements

- [ ] **FR-014**: Bind every fact to one immutable candidate/configuration and fresh producer execution.
- [ ] **FR-015**: Preserve lifecycle stages, authority, retention and supersession without promotion.
- [ ] **FR-016**: Emit a lossless integrator package only through the accepted shared contract.
- [ ] **FR-017**: Admit an exact, policy-authorized human source-release disposition.
- [ ] **FR-018**: Classify every executable readiness path and remove stable reliance on legacy paths.

### Non-Functional and Integration Requirements

- [ ] **NFR-004**: Reproduce deterministic observations and preserve every volatile field.
- [ ] **NFR-005**: Preserve authority, limitation and retention truth.
- [ ] **IT-001**: Exercise the real source-grounding handoff.
- [ ] **IT-002**: Exercise the real integrator-package round trip.

## Dependency Graph

- `M6 specification + review -> every implementation task`
Reason: the specification snapshot and SR-058 through SR-065 establish the
boundary and test vocabulary before code is authorized.
- `external prerequisite admission -> FR-014, FR-015, FR-016, FR-017, FR-018`
Reason: source export/matrix, retention, decision policy, package format and
LR08 ownership are shared enablement and cannot be reconstructed locally.
- `FR-018 -> FR-014`
Reason: the complete executable-path census and Rust/shared disposition must
be known before a stable source subject can be declared complete.
- `FR-014 -> FR-015 -> FR-017`
Reason: lifecycle facts need an exact candidate, and a decision needs exact
staged facts, reviews and limitations.
- `FR-014 + FR-015 + FR-017 -> IT-001`
Reason: the real shared handoff consumes candidate, lifecycle and authority
records together.
- `FR-014 + FR-015 + FR-017 + IT-001 -> FR-016 -> IT-002`
Reason: package publication follows verified source facts and human decision;
its real reader is the only admitted integration oracle.
- `NFR-004 + NFR-005 -> every implementation and integration task`
Reason: reproducibility, non-promotion, retention and authority are
cross-cutting correctness properties.

The principal seams are the existing Rust shared-assurance intake in
`tests/shared_assurance.rs`, future Rust source-readiness modules, the released
Quire/Engineering Assurance export, Quoin retention handles, and the future
Engineering Assurance integrator package. Markdown parsing and local contract
copies are outside every seam.

## Test Plan

### Candidate and Execution Properties

- [ ] **TC-059**: Reproduce exact candidate/configuration identity.
- [ ] **TC-060**: Reject one-axis candidate, source, configuration and contract mutations.
- [ ] **TC-064**: Census and classify every executable entry point exactly once.
- [ ] **TC-065**: Require positive and forced-failure parity before legacy removal.
- [ ] **TC-068**: Exercise every producer/package execution outcome with stale output present.
- [ ] **TC-069**: Reject source-root, path, mount and symlink boundary failures.

### Lifecycle and Authority Properties

- [ ] **TC-062**: Preserve four stages and all six decision dispositions.
- [ ] **TC-063**: Prove omissions and non-success states cannot improve readiness.
- [ ] **TC-066**: Prove absent shared capability stays unavailable with no local substitute.
- [ ] **TC-067**: Exercise every retention state and retrieval failure.
- [ ] **TC-070**: Exercise bounded supersession and decision transition topology.
- [ ] **TC-073**: Mutate every review/decision policy and identity binding.

### Real Shared Integrations

- [ ] **TC-061**: Round-trip source facts and distinct adopter subjects through the real package.
- [ ] **TC-071**: Exercise idempotent retries and racing package writers.
- [ ] **TC-072**: Complete independent, candidate-bound license/reuse-right analysis.

## Remaining Work

### Track S: Specification gate

- **S1 = Task-009** M6 specification and composite review — Done; exit: the exact snapshot is strict-valid with no review-owned finding.

### Track G: External admission gate

- **G1 = Task-010** prerequisite ledger and no-workaround gate — Blocked; exit: each consumed release, policy, authority and backend has an immutable compatible identity.

### Track A: Critical path (serial)

- **A1 = Task-011** executable-path inventory and Rust/shared parity — Hard; exit: every entry point has one reviewed class and every stable-required legacy behavior has parity.
- **A2 = Task-012** candidate binding and producer freshness — Hard; exit: identity races, stale output and path escapes fail closed.
- **A3 = Task-013** lifecycle, retention and human decision admission — Hard; exit: state/history/authority transitions are total and non-promoting.
- **Gate = Task-014** real source-grounding integration — Hard; measures lossless shared handoff; pass: every IT-001 subcase and load-bearing negative mutation succeeds at the exact candidate.

### Track C: Post-gate package work

- **C1 = Task-015** integrator package and rights handoff — Hard; exit: the real reader preserves every fact and concurrent/invalid publication exposes nothing favorable.

### Track J: Final assurance

- **J1 = Task-016** independent code/gap review and human release gate — Medium; exit: all planned rows are genuinely backed and an authorized human disposition is recorded or remains explicitly open.

## Parallel Execution Summary

```text
Track S: Task-009 (done)
Track G: Task-010 [external prerequisites]
Track A: Task-011 -> Task-012 -> Task-013 -> Task-014
Track C: Task-015
Track J: Task-016
```

## Task File Mapping

| Task | Track | Owns (references) | Verified by (verifies) | Status |
| --- | --- | --- | --- | --- |
| Task-009 | S | StR-004, FR-014..FR-018, NFR-004..NFR-005 | TC-066 | done |
| Task-010 | G | FR-014..FR-018, NFR-005 | TC-066, TC-067, TC-073 | blocked |
| Task-011 | A | FR-018 | TC-064..TC-066 | blocked |
| Task-012 | A | FR-014, NFR-004 | TC-059, TC-060, TC-068, TC-069 | blocked |
| Task-013 | A | FR-015, FR-017, NFR-005 | TC-062, TC-063, TC-067, TC-070, TC-073 | blocked |
| Task-014 | A | IT-001, FR-014, FR-015, FR-017, FR-018 | TC-059, TC-060, TC-062, TC-063, TC-066..TC-070, TC-073 | blocked |
| Task-015 | C | FR-016, IT-002 | TC-061, TC-063, TC-066, TC-068, TC-070..TC-072 | blocked |
| Task-016 | J | StR-004, NFR-004, NFR-005 | TC-059..TC-073 | blocked |

## Coordination Rules

- Freeze MRS-004, TM-004 and the closed vocabularies after merge; a semantic
change requires a new specification review before downstream code.
- Task-010 is an admission gate, not permission to vendor, mirror, branch-pin or
locally emulate missing shared capabilities.
- Keep one writer for shared census, state and fixture files; downstream tasks
rebase after each predecessor merges.
- Do not dispatch hosted CI without explicit authorization. Local evidence must
state its exact environment and may not imply hosted execution.
- No task may present tl-syntax as an editable Quire alternative or infer a
release/qualification decision from passing automation.
Original file line number Diff line number Diff line change
@@ -0,0 +1,55 @@
---
id: Task-009
title: "M6 source-readiness specification and composite review"
type: Task
status: done
track: S
priority: P0
owner_repository: agent-ix/tl-syntax
consumer_repositories: [agent-ix/tl-syntax]
evidence_method: specification-and-composite-review
github_issue: ix://agent-ix/tl-syntax/issues/34
resume_conditions: []
relationships:
- target: ix://agent-ix/tl-syntax/StR-004
type: references
- target: ix://agent-ix/tl-syntax/FR-014
type: references
- target: ix://agent-ix/tl-syntax/FR-015
type: references
- target: ix://agent-ix/tl-syntax/FR-016
type: references
- target: ix://agent-ix/tl-syntax/FR-017
type: references
- target: ix://agent-ix/tl-syntax/FR-018
type: references
- target: ix://agent-ix/tl-syntax/NFR-004
type: references
- target: ix://agent-ix/tl-syntax/NFR-005
type: references
- target: ix://agent-ix/tl-syntax/TC-066
type: verifies
---
# Task-009: M6 source-readiness specification and composite review

## Scope

Define the source-readiness boundary, closed result domains, acceptance matrix,
assurance records and real-integration scenarios before implementation.

## Subtasks

- [x] Author MRS-004, TM-004 and their requirement/assurance/integration artifacts.
- [x] Run base, failure-domain, integrity, dependency, evidence, risk, scope and EARS reviews.
- [x] Correct every review-owned finding and validate the exact snapshot strictly.

## Deliverables

- Specification commit `767dc92a97f1b3d9ffbb76467bdda9ecf2261e40`
- Author reviews SR-058 through SR-065
- Independent exact-head reviews SR-066 through SR-075

## Notes

- TC-066 is the boundary criterion this task defines and reviews; its executable evidence remains downstream.
- Completion of this authoring task does not mark any TM-004 implementation row covered.
Original file line number Diff line number Diff line change
@@ -0,0 +1,60 @@
---
id: Task-010
title: "Admit external prerequisites without local substitutes"
type: Task
status: blocked
track: G
priority: P0
owner_repository: agent-ix/tl-syntax
consumer_repositories: [agent-ix/tl-syntax]
evidence_method: released-contract-admission
github_issue: ix://agent-ix/tl-syntax/issues/45
resume_conditions: [ix://agent-ix/tl-syntax/issues/16, ix://agent-ix/quire-research/issues/64, ix://agent-ix/engineering-assurance/issues/11]
relationships:
- target: ix://agent-ix/tl-syntax/Task-009
type: depends_on
- target: ix://agent-ix/tl-syntax/FR-014
type: references
- target: ix://agent-ix/tl-syntax/FR-015
type: references
- target: ix://agent-ix/tl-syntax/FR-016
type: references
- target: ix://agent-ix/tl-syntax/FR-017
type: references
- target: ix://agent-ix/tl-syntax/FR-018
type: references
- target: ix://agent-ix/tl-syntax/NFR-005
type: references
- target: ix://agent-ix/tl-syntax/TC-066
type: verifies
- target: ix://agent-ix/tl-syntax/TC-067
type: verifies
- target: ix://agent-ix/tl-syntax/TC-073
type: verifies
---
# Task-010: Admit external prerequisites without local substitutes

## Scope

Maintain the immutable compatibility/authority ledger and admit each external
capability only when its released identity satisfies MRS-004.

## Subtasks

- [ ] Admit a released matrix selecting the source-grounded Quire export.
- [ ] Select the Quoin retention contract, backend/operator and lifecycle.
- [ ] Select the immutable reviewer/decision policy and authoritative event source.
- [ ] Admit the Engineering Assurance Rust runner and integrator-package contracts.
- [ ] Record LR08 executable-language dispositions and refuse local workarounds.

## Deliverables

- Candidate-bound prerequisite ledger with release identities, digests and resume decisions

## Notes

- Blocked on tl-syntax#16, engineering-assurance#11, an immutable release
containing the merged engineering-assurance#34 producer boundary, the
retention/operator selection, policy/event source, integrator-package release
and quire-research#64.
- Individual downstream work may resume only when every prerequisite it consumes is admitted; a partial ledger is not a global pass.
Original file line number Diff line number Diff line change
@@ -0,0 +1,47 @@
---
id: Task-011
title: "Classify executable paths and prove Rust/shared parity"
type: Task
status: blocked
track: A
priority: P0
owner_repository: agent-ix/tl-syntax
consumer_repositories: [agent-ix/tl-syntax]
evidence_method: integration-and-property-test
github_issue: ix://agent-ix/tl-syntax/issues/46
resume_conditions: [ix://agent-ix/tl-syntax/issues/34, ix://agent-ix/tl-syntax/issues/45, ix://agent-ix/quire-research/issues/64]
relationships:
- target: ix://agent-ix/tl-syntax/Task-010
type: depends_on
- target: ix://agent-ix/tl-syntax/FR-018
type: references
- target: ix://agent-ix/tl-syntax/TC-064
type: verifies
- target: ix://agent-ix/tl-syntax/TC-065
type: verifies
- target: ix://agent-ix/tl-syntax/TC-066
type: verifies
---
# Task-011: Classify executable paths and prove Rust/shared parity

## Scope

Build the complete executable-entry-point inventory and migrate stable-required
first-party behavior to Rust or a released shared capability.

## Subtasks

- [ ] Write failing exact-census/classifier tests before the classifier.
- [ ] Inventory scripts, build steps, nested interpreters and generated commands.
- [ ] Record owner, authority, pre-stable disposition, parity evidence and resume condition.
- [ ] Demonstrate positive and forced-failure parity before removing each legacy path.

## Deliverables

- Rust executable census/classifier and reviewed disposition inventory
- TC-064 through TC-066 evidence

## Notes

- Blocked until the current specification is independently reviewed/merged and
the consumed LR08/shared-runner entries are admitted by Task-010.
Loading