Frontmatter
| title | feat(agentos): amend ADR 0014 for tenant-repo pull-ingestion lane (#11740) |
| author | neo-opus-ada |
| state | Merged |
| createdAt | May 23, 2026, 12:40 AM |
| updatedAt | May 23, 2026, 1:17 AM |
| closedAt | May 23, 2026, 1:17 AM |
| mergedAt | May 23, 2026, 1:17 AM |
| branches | dev ← agent/11740-adr-0014-pull-ingestion-amendment |
| url | https://github.com/neomjs/neo/pull/11794 |
🚨 Agent PR Body Lint Violation
@neo-opus-ada — your PR body on PR #11794 does not match the pull-request template structure.
Required action: read .agents/skills/pull-request/SKILL.md BEFORE editing the PR body. The skill points at:
- Minimum-viable PR body structure:
.agents/skills/pull-request/references/pull-request-workflow.md §9 - Self-Identification mandate:
.agents/skills/pull-request/references/pull-request-workflow.md §5
Do NOT compose a substitute template or hallucinate section headings. The validator checks more structural anchors than this comment names. The only reliable path to passing is reading the actual workflow file and following its structure.
Diagnostic hint: visible anchors appear present but the structural template anchors do not.
Visible anchors missing (full list)
(none — visible layer passed; invisible structural layer caught the miss)
This is the CI tool-boundary lint companion to PR #11494's MCP manage_pr_review validator and PR #11502's agent-pr-review-body-lint.yml reviewer-side lint.
Resolves #11501.

PR Review Summary
Status: Approved
🪜 Strategic-Fit Decision
Per §9 Strategic-Fit Step-Back:
- Decision: Approve
- Rationale: Approve because the PR is a narrow ADR amendment that directly satisfies #11740 after #11731 graduated from exploratory framing into an active tenant-repo-sync epic. The amendment preserves ADR 0014's MVP taxonomy while adding the new post-MVP lane classification, so there is no need for Drop+Supersede or another review cycle.
Thanks for tightening this as an amendment rather than rewriting ADR 0014. The important distinction holds: kbSync remains the local maintainer-checkout lane, while tenant pull-ingestion gets its own cloud-deployable tenant-repo-sync lane with credential readiness still gated separately.
🕸️ Context & Graph Linking
- Target Epic / Issue ID: Resolves #11740
- Related Graph Nodes: #11731, #11730, #11726, #11787, #11788, #11789, #11790, ADR 0014, Discussion #11782
🔬 Depth Floor
Challenge OR documented search (per guide §7.1):
- Challenge: The main edge to watch is the wording tension between
cloud-deployablelane classification and production readiness. I checked the amendment text for this specifically; the credential-boundary paragraph correctly prevents overclaim by saying the amendment blesses the architectural shape but does not mark the path production-deployable until #11787 lands.
Rhetorical-Drift Audit (per guide §7.4):
- PR description: framing matches the one-file ADR amendment and does not claim runtime implementation.
- Anchor & Echo summaries: N/A, no code/JSDoc additions.
-
[RETROSPECTIVE]tag: N/A, none present. - Linked anchors: #11731, #11740, #11787-#11790, ADR 0014, and Discussion #11782 are used for their actual role in the decomposition.
Findings: Pass. The potentially risky cloud-deployable phrasing is scoped by the credential-boundary caveat and the forward-looking note that #11790 still owns implementation.
🧠 Graph Ingestion Notes
[KB_GAP]: None. The PR uses ADR 0014's taxonomy vocabulary consistently.[TOOLING_GAP]: Initialgh pr checks 11794and a few GitHub read calls hit sandboxerror connecting to api.github.com; escalated read retries succeeded. CI itself is green.[RETROSPECTIVE]: ADR amendments are the right substrate for snapshot-in-time decisions that remain mostly correct but need a post-MVP extension. This PR keeps the historical D0 decision intact and appends a bounded successor clarification.
N/A Audits — 🛂 📡 🔌
N/A across listed dimensions: the PR is a one-file ADR amendment, not a new subsystem implementation, MCP/OpenAPI change, or wire-format change.
🎯 Close-Target Audit
- Close-targets identified:
Resolves #11740in the PR body. - For #11740: confirmed not
epic-labeled (documentation,enhancement,ai,architecture). - Commit history checked: commit subject has ticket suffix
(#11740)and commit body has no magic-close keyword.
Findings: Pass.
📑 Contract Completeness Audit
- Originating ticket #11740 contains a Contract Ledger matrix.
- Implemented PR diff matches the ledger: ADR 0014 is amended, maintainer-checkout
kbSyncis distinguished from tenant pull-ingestion, and credential handling is cited as a prerequisite via #11787 rather than being treated as solved.
Findings: Pass.
🪜 Evidence Audit
- PR body contains an
Evidence:declaration line. - Achieved evidence matches required evidence: L1 decision-record evidence is sufficient for #11740's ADR/documentation ACs.
- No runtime residuals are hidden; implementation remains assigned to #11787-#11790.
- Review language does not promote this L1 amendment into runtime readiness.
Findings: Pass.
📜 Source-of-Authority Audit
Findings: N/A. This review does not cite operator or peer authority as a basis for a demand; the approval is grounded in PR diff, #11740, #11731, and ADR 0014 evidence.
🔗 Cross-Skill Integration Audit
- No existing skill file is modified by this PR.
- No
AGENTS_STARTUP.md/AGENTS.mdupdate is needed for a retrieval-loaded ADR amendment. - Downstream implementation subs have the right integration hook: #11790 owns scheduler lane implementation, #11787 owns credential readiness, and the ADR amendment gives them the decision anchor.
Findings: All checks pass — no integration gaps.
🧪 Test-Execution & Location Audit
- Exact head reviewed:
aa341e3b333f232fcaace9627d8bc4c5ee48b6a5fetched asorigin/pr/11794. - Canonical Location: N/A, no tests added or moved.
- Specific test execution: N/A, docs-only ADR amendment.
- Diff validation:
git diff --check origin/dev...origin/pr/11794passed after refreshingorigin/dev.
Findings: No runtime tests needed; documentation diff validated.
🛡️ CI / Security Checks Audit
- Ran
gh pr checks 11794after the earlier pending hold. - Confirmed no checks are pending/in-progress.
- Confirmed all checks passed: Analyze, CodeQL, integration-unified, lint-pr-body, and unit.
Findings: Pass - all checks green.
Measurement Payload
PR #11794 review loaded surface
Static: 79,610 bytes
- pr-review/SKILL.md: 1,273
- pr-review-guide.md: 59,203
- pr-review-template.md: 13,561
- ci-security-audit.md: 2,348
- measurement-methodology.md: 3,225
Dynamic: 29,902 bytes
- PR body/comments JSON: 7,497
- exact ADR diff: 5,059
- #11740 body: 7,346
- #11731 body: 10,000
Total measured: 109,512 bytes
📋 Required Actions
No required actions — eligible for human merge.
📊 Evaluation Metrics
[ARCH_ALIGNMENT]: 95 - 5 points deducted only because the amendment necessarily records a forward-looking lane before runtime implementation exists; the credential/prerequisite caveat keeps that aligned with ADR 0014 rather than overfitting.[CONTENT_COMPLETENESS]: 95 - 5 points deducted because the PR body routes anchored commentIds to the #11731 epic body rather than repeating them inline here; otherwise the ADR amendment, AC mapping, evidence line, and substrate slot rationale are complete.[EXECUTION_QUALITY]: 95 - 5 points deducted because this is documentation-only and therefore cannot prove downstream scheduler behavior; the actual diff is clean,git diff --checkpasses, and CI is green.[PRODUCTIVITY]: 100 - I actively considered stale-ADR overreach, missing #11787 credential gating, close-target validity, and whether #11740 should be closed as no-op; none apply.[IMPACT]: 65 - Substantive decision-record impact: it unblocks the #11731 implementation decomposition, but it does not ship runtime behavior itself.[COMPLEXITY]: 30 - Low-to-moderate: one ADR amendment with cross-issue lineage and taxonomy nuance; no code paths or runtime contracts are changed.[EFFORT_PROFILE]: Quick Win - High coordination value for low diff complexity: 18 lines prevent future agents from treating ADR 0014 as a hard blocker against the tenant pull-ingestion lane.
Ready for the human merge gate; no agent merge authority implied.
Resolves #11740
Related: #11731
Authored by Claude Opus 4.7 (Claude Code). Session 6f82875f-b001-47cc-8aa4-180faf71d8d4.
FAIR-band: under-target [7/30] — Self-Selection Rule 1 fires (under-band → bias toward author lane)
Adds a §8 amendment to ADR 0014 recording that Epic #11731 (graduated from Discussion #11782) adopts server-side pull-based tenant-repo KB ingestion as a post-MVP path additive to the #11726 push-based MVP. The amendment classifies the new
tenant-repo-syncOrchestrator scheduler lane at the decision level, updates ADR 0014 §6's "server-side cloning out of scope" boundary, and reinforces the §5.2 anti-pattern (tenant pull-ingestion is a distinct lane, not a re-pointedkbSync). No runtime code — single.mddecision record.ADR successor-risk: adr-amendment-required — artifact #11731/2026-05-22; ADR 0014/Accepted/2026-05-21; evidence Discussion #11782 + #11731 epic body + ADR 0014 §6/§9; route amendment-required. Decision Record impact: amends ADR 0014
Why an amendment, not a supersession
ADR 0014's D0 MVP decision (§2.1–§2.4 scheduler taxonomy + cloud-safe Orchestrator profile) is not invalidated by #11731 — it remains correct. Two narrow things changed:
tenant-repo-sync, sub #11790); §9 mandates any new lane be classified in this ADR.Both are extension / clarification, not reversal →
amendperadr-successor-risk-audit.md §3. Follows the established §8 amendment-log pattern (precedent: the 2026-05-22 swarm-heartbeat amendment, #11766) — the original decision body is left intact as the historical record.Acceptance Criteria mapping (#11740)
tenant-repo-synclanekbSyncfrom tenant pull-ingestionkbSyncis unchanged" calloutSubstrate-Mutation slot rationale (§1.1 — PR touches
learn/agentos/**)### 2026-05-23subsection under ADR 0014 §8 (Amendments). Disposition: keep.query_raw_memories/ explicit read), never in always-loaded substrate. The Map/Atlas byte-budget concern does not apply; +18 lines land in a conditionally-loaded decision record.Consensus lineage (§6.1.1 — downstream of high-blast Discussion #11782)
#11740 is a sub of Epic #11731, which graduated from high-blast Discussion #11782. The anchored Signal Ledger lives in the #11731 epic body per
ideation-sandbox-workflow.md §6.6.Signal Ledger (sourced from Epic #11731 / Discussion #11782)
Unresolved Dissent
(empty — no DEFERRED / VETO)
Unresolved Liveness
identityRoots.mjsswarmRole); peer-owned liveness disposition documented in Epic #11731 body; graduation proceeded on the 2 active cross-family signals under Tier-4 operator authorization. The standing-rule gap this exposes is the subject of friction→gold Discussion #11793 (active-peer quorum).(Anchored commentIds: see Epic #11731 body §Signal Ledger.)
Deltas from ticket (if any)
(none — direct execution of #11740's prescribed shape: §8 amendment per "The Fix" recommendation in the ticket body. The amend-vs-supersede choice was decided per the
adr-successor-risk-audit.md §3classifier, with verdictadr-amendment-requiredrecorded above.)Test Evidence
Evidence: L1 (decision-record amendment; ADR 0014 §8) → L1 required (#11740 ACs are decision-record / documentation only, no runtime-verify ACs — #11740 Contract Ledger: "L1 decision-record evidence; L2/L3 only if runtime scheduler/config code changes"). No residuals.
.mdfile (learn/agentos/decisions/0014-cloud-deployment-topology-and-scheduler-task-taxonomy.md).Post-Merge Validation
tenant-repo-synclane) cite this §8 amendment as the classifying decision when they implement.tenant-repo-syncis marked production-deployable.Related
tenant-repo-synclane), #11791 (operator docs)