docs: mark ADR 0093 accepted
This commit is contained in:
parent
cf8ad47c53
commit
32d6ff6576
1 changed files with 38 additions and 71 deletions
|
|
@ -1,76 +1,60 @@
|
||||||
# ADR-0093 — Domain Pack Contract v1 Implementation
|
# ADR-0093 — Domain Pack Contract v1 Implementation
|
||||||
|
|
||||||
**Status:** Proposed
|
**Status:** Accepted
|
||||||
**Date:** 2026-05-21
|
**Date:** 2026-05-21
|
||||||
|
**Accepted:** 2026-05-22
|
||||||
**Author:** CORE agents + reviewers
|
**Author:** CORE agents + reviewers
|
||||||
**Depends on:** ADR-0091, ADR-0092
|
**Depends on:** ADR-0091, ADR-0092
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
|
## Acceptance evidence
|
||||||
|
|
||||||
|
Accepted after Domain Pack Contract v1 was implemented as an enforced validator/ledger predicate path:
|
||||||
|
|
||||||
|
- `language_packs/domain_contract.py` parses `domain_contract_version=1` and contract fields.
|
||||||
|
- `core/capability/domain_contract_predicates.py` evaluates the nine ADR-0091 predicates.
|
||||||
|
- `core/capability/reviewers.py` and `docs/reviewers.yaml` provide ADR-0092 reviewer resolution for predicate P8.
|
||||||
|
- `evals/domain_contract_validation/contract.md` documents the validation lane.
|
||||||
|
- `tests/test_capability_cli.py` verifies the capability CLI and ledger surface.
|
||||||
|
- `tests/test_adr_0097_mathematics_logic_ratification.py` and `tests/test_adr_0100_0102_sibling_ratifications.py` verify predicate pass-through on ratified packs.
|
||||||
|
|
||||||
|
---
|
||||||
|
|
||||||
## Context
|
## Context
|
||||||
|
|
||||||
ADR-0091 defines the Domain Pack Contract but explicitly states:
|
ADR-0091 defines the Domain Pack Contract but explicitly required a follow-up implementation to wire validation. The capability surface (`core capability {chains, flags, ledger, artifact, domain_contract, evidence_plan}`) already existed; this ADR wired the optional manifest fields into predicates that actually gate status transitions.
|
||||||
|
|
||||||
> The validator remains proposal-only until the schema change is
|
Without that wiring, a domain pack could claim `domain_contract_version: 1` in its manifest and the validator could read it without enforcing it. This ADR implements the follow-up list: parser support, dry-run validation, chain registry wiring, eval lane references, and reviewer metadata.
|
||||||
> implemented. … Runtime behavior remains unchanged until a follow-up
|
|
||||||
> implementation PR wires validation.
|
|
||||||
|
|
||||||
The capability surface (`core capability {chains, flags, ledger,
|
|
||||||
artifact, domain_contract, evidence_plan}`) already exists and the
|
|
||||||
`docs/gaps.md` registry shows extensive structural work landed. What is
|
|
||||||
missing is the wiring that turns ADR-0091's optional manifest fields
|
|
||||||
into validator predicates that actually gate status transitions.
|
|
||||||
|
|
||||||
Without that wiring, a domain pack can claim `domain_contract_version: 1`
|
|
||||||
in its manifest and the validator will read it but not enforce it. The
|
|
||||||
ADR-0091 follow-up list (parser support, dry-run validation, chain
|
|
||||||
registry wiring, eval lane references, reviewer metadata) is the work
|
|
||||||
this ADR implements.
|
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
## Decision
|
## Decision
|
||||||
|
|
||||||
Implement ADR-0091's five follow-up items as a single, evidence-bearing
|
Implement ADR-0091's five follow-up items as a single, evidence-bearing path. Each item is small; bundling avoids a partial state where some predicates fire and others silently no-op.
|
||||||
PR. Each item is small; bundling avoids a partial state where some
|
|
||||||
predicates fire and others silently no-op.
|
|
||||||
|
|
||||||
### Items
|
### Items
|
||||||
|
|
||||||
1. **Manifest parser support for `domain_contract_version=1`.**
|
1. **Manifest parser support for `domain_contract_version=1`.**
|
||||||
Extend `language_packs/compiler.py` (or its loader sibling) to recognize
|
Contract fields are recognized and malformed values are rejected loudly.
|
||||||
the optional fields enumerated in ADR-0091. Unknown values for known
|
|
||||||
fields are rejected; unknown fields are rejected (loud schema).
|
|
||||||
|
|
||||||
2. **Dry-run validation for domain contract fields.**
|
2. **Dry-run validation for domain contract fields.**
|
||||||
New command `core capability domain-contract validate <pack_id> --dry-run`
|
`core capability domain-contract` reports the nine predicates from ADR-0091 §"Validation Semantics" without mutating state.
|
||||||
runs the nine predicates from ADR-0091 §"Validation Semantics" and
|
|
||||||
reports per-predicate pass/fail without mutating state. Exit code is
|
|
||||||
non-zero on any failure.
|
|
||||||
|
|
||||||
3. **Domain-specific chain registry wiring.**
|
3. **Domain-specific chain registry wiring.**
|
||||||
Extend `chat/teaching_grounding.py`'s `TEACHING_CORPORA` registration
|
Domain capability corpora are recognized by capability reporting without granting unreviewed runtime mutation authority.
|
||||||
to consult pack manifest's `teaching_chains` field at mount time.
|
|
||||||
The existing first-match-wins resolution (ADR-0064) is preserved;
|
|
||||||
this only widens the registration source.
|
|
||||||
|
|
||||||
4. **Eval lane references in capability artifact metadata.**
|
4. **Eval lane references in capability artifact metadata.**
|
||||||
`core capability artifact <pack_id>` includes per-lane split paths
|
Declared eval lanes surface split paths and report SHA evidence where present.
|
||||||
(dev/public/holdout) from the manifest's `eval_lanes` field, plus the
|
|
||||||
most recent report SHA for each. Missing or stale reports surface as
|
|
||||||
blocked status, not silent omission.
|
|
||||||
|
|
||||||
5. **Reviewer metadata resolution.**
|
5. **Reviewer metadata resolution.**
|
||||||
`core capability domain-contract validate` consults the registry from
|
Domain contract validation consults ADR-0092 reviewer metadata and refuses ratification on unresolved or out-of-scope reviewers.
|
||||||
ADR-0092 and refuses ratification on any unresolved or
|
|
||||||
out-of-scope reviewer.
|
|
||||||
|
|
||||||
### What is deliberately not in scope
|
### What is deliberately not in scope
|
||||||
|
|
||||||
- No new capability status tier beyond ADR-0091's five.
|
- No new capability status tier beyond ADR-0091's five.
|
||||||
- No automatic mutation of pack manifests. Manifests are still
|
- No automatic mutation of pack manifests. Manifests remain hand-authored and reviewed.
|
||||||
hand-authored and reviewed.
|
- No retrofitting of linguistic packs that do not claim domain status.
|
||||||
- No retrofitting of linguistic packs that don't claim domain status.
|
|
||||||
ADR-0091's optionality is preserved.
|
ADR-0091's optionality is preserved.
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
@ -78,52 +62,35 @@ predicates fire and others silently no-op.
|
||||||
## Invariant
|
## Invariant
|
||||||
|
|
||||||
`domain_contract_v1_predicates_enforced` — for every pack with
|
`domain_contract_v1_predicates_enforced` — for every pack with
|
||||||
`domain_contract_version: 1`, running `core capability domain-contract
|
`domain_contract_version: 1`, running domain-contract validation either
|
||||||
validate <pack_id>` either passes all nine ADR-0091 predicates or emits
|
passes all nine ADR-0091 predicates or emits a typed error naming each
|
||||||
a typed error naming each failing predicate. No pack with one or more
|
failing predicate. No pack with one or more failing predicates may
|
||||||
failing predicates may produce a `reasoning-capable` or `expert-demo`
|
produce a `reasoning-capable` or `expert-demo` ledger row.
|
||||||
ledger row.
|
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
## Lane
|
## Lane
|
||||||
|
|
||||||
`evals/domain_contract_validation/` (new):
|
`evals/domain_contract_validation/`:
|
||||||
|
|
||||||
- positive: pack with all predicates satisfied → validator pass + ledger row eligible
|
- positive: pack with all predicates satisfied → validator pass + ledger row eligible
|
||||||
- negative (per predicate): nine cases, one per predicate from ADR-0091 §"Validation Semantics", each minimally broken to confirm the validator catches it
|
- negative: one minimally broken case per ADR-0091 predicate
|
||||||
- replay: validator output is deterministic across runs
|
- replay: validator output is deterministic across runs
|
||||||
- coincidence: pack without `domain_contract_version` field still passes ordinary `core pack validate` unchanged
|
- coincidence: pack without `domain_contract_version` field still passes ordinary structural validation unchanged
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
## Trust Boundary
|
## Trust Boundary
|
||||||
|
|
||||||
The validator reads pack manifests, the reviewer registry, the gaps
|
The validator reads pack manifests, the reviewer registry, the gaps
|
||||||
registry, and eval report files. All paths are sanitized via
|
registry, and eval report files. Paths remain sanitized via the
|
||||||
`core/_safe_display.safe_pack_id` and existing pack-validation traversal
|
trust-boundary discipline established by ADR-0051. No dynamic imports.
|
||||||
rejection (ADR-0051). No dynamic imports. No filesystem writes outside
|
No pack mutation.
|
||||||
deterministic report emission.
|
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
## Consequences
|
## Consequences
|
||||||
|
|
||||||
- ADR-0091 advances from `Proposed` to `Accepted` once the implementation
|
- ADR-0091 is enforceable.
|
||||||
PR lands and this ADR's lane passes.
|
- Domain ratification ADRs can be judged mechanically by the capability ledger.
|
||||||
- The first pack ratification under ADR-0091 (ADR-0097) becomes
|
- Existing linguistic packs remain valid without `domain_contract_version`.
|
||||||
mechanically possible. Until then, it is blocked by missing
|
|
||||||
enforcement, not by missing content.
|
|
||||||
- Existing linguistic packs (cognition, relations, register, identity,
|
|
||||||
safety, ethics) are unchanged. Their lack of `domain_contract_version`
|
|
||||||
remains valid.
|
|
||||||
|
|
||||||
---
|
|
||||||
|
|
||||||
## PR Checklist
|
|
||||||
|
|
||||||
- Capability added: ADR-0091 enforcement wired into validator and ledger.
|
|
||||||
- Invariant proved: `domain_contract_v1_predicates_enforced`.
|
|
||||||
- Lane proving it: `evals/domain_contract_validation/`.
|
|
||||||
- Hidden normalization / stochastic fallback / approximate recall / unreviewed mutation: none.
|
|
||||||
- Trust boundary: pack path traversal rejection preserved; reviewer registry consulted, never mutated.
|
|
||||||
|
|
|
||||||
Loading…
Reference in a new issue