LearnNewsExamplesServices
Frontmatter
id15162
titleProve the community-activity authority chain end to end
stateOpen
labels
enhancementaitestingarchitecturesecurity
assignees[]
createdAt7:32 AM
updatedAt8:29 AM
githubUrlhttps://github.com/neomjs/neo/issues/15162
authorneo-gpt
commentsCount0
parentIssue15145
subIssues[]
subIssuesCompleted0
subIssuesTotal0
contentTrust
projected
quarantined0
signals[]
blockedBy[ ] 15160 Calibrate community policy from measured evidence, [ ] 15159 Project bounded tenant community-attention counts, [ ] 15158 Bind community events to canonical A2A Tasks, [ ] 15157 Expose a temporal community Bird View and seen state, [ ] 15156 Push hosted GitHub community batches securely, [ ] 15155 Coordinate local GitHub community reconciliation
blocking[]
milestonev13.2

Prove the community-activity authority chain end to end

Open Backlog/active-chunk-6 enhancementaitestingarchitecturesecurity
neo-gpt
neo-gpt commented on 7:32 AM

Context

The Epic crosses provider acquisition, tenant registration, durable admission, local/hosted transport, trust, Bird View, seen, claim, and count projection. A separately closeable capstone proof prevents each green unit PR from collectively missing the graduated end-to-end authority contract.

This is one fully closeable PR leaf under Epic #15145. The live parent-child and blocked-by graph is authoritative; this body owns only this leaf's contract.

The Problem

Unit tests can all pass while rename forks identity, stale epochs admit, lost responses skip history, remote auth crosses tenants, prose leaks into automatic paths, or two peers create two canonical Tasks. Those are the exact wrong-shape failures that review-time prose cannot reliably catch.

The Architectural Reality

This is a test/evidence PR using existing unit/integration locations and real service seams; it introduces no production authority. It must exercise both local direct and hosted authenticated paths against isolated tenant/source fixtures and assert negative GraphLog/Native Edge Graph/LifecycleFrontier effects.

The Agent OS structure map was run on 2026-07-14. New service/script/test placement must use the named sibling-file-lift fast paths; no service logic moves into MCP server entrypoint directories.

The Fix

Add a deterministic multi-tenant, multi-source integration harness covering provider fixtures through reconciliation, registration, admission, receipt/checkpoint, Bird View/trust drill-down, seen, canonical Task claim, count projection, revocation, restart/replay, and local/hosted parity. Publish a criterion-to-test matrix.

Contract Ledger Matrix

Target Surface Source of Authority Proposed Behavior Fallback / Edge Case Docs Evidence
Local authority chain Discussion #15139 L/N Reconciliation -> admission -> query/claim/count with receipt ordering Crash/restart retries without loss Test matrix Integration suite
Hosted authority chain M/W Authenticated connector uses same neutral contract under server tenant/source Wrong tenant/epoch rejected Test docs Hosted fixture suite
Authority negatives OQ4/OQ5/OQ7/OQ8 No prose in automation, no graph history, no pre-claim LifecycleFrontier, no duplicate Task Failure is explicit and isolated Matrix Negative assertions
Identity/tenancy OQ3/OQ9 Rename/grant rotation stable; source/tenant/epoch fences hold Permission loss remains unknown, not delete Fixture docs Cross-tenant and lifecycle tests

Decision Record impact

Depends on ADR 0036 and every required core implementation/evidence leaf; validates composition with ADRs 0015, 0019, and 0035.

Decision Record

Required: ADR 0036. This leaf is not code-ready until the ADR-0036 child of #15145 is accepted at the human merge gate.

Discussion Criteria Mapping

Upstream graduated criterion This leaf's executable contract
OQ1-OQ4 Exercises actor/trust, exhaustive coverage/gaps, identity/replay, and neutral durable owner.
OQ5-OQ8 Exercises seen vs claim, Bird View, count projection, trust, and authority negatives.
OQ9-OQ10 Exercises local/hosted parity, registration epochs, restart, and measured-policy surfaces.
Three STEP_BACK partials Proves tenant-relative trust, exactly-one Task binding, and no pre-measurement threshold.

Source authority: Discussion #15139 body at the version-bound graduation anchor plus Grace's STEP_BACK and GRADUATION_APPROVED.

Operator Scope Clarification — 2026-07-14

The community substrate is not a mirror of every GitHub repository notification. It separates:

  1. source occurrences needed to reconstruct supported issue, pull-request/review, and Discussion conversation state; and
  2. attention-eligible community items: externally authored, response-bearing occurrences that may need maintainer attention.

Stars/un-stars, forks, watches, and equivalent popularity telemetry are outside the community-event source families and cannot enter Bird View, counts, wake, or Task claim. Internal/rostered actions may update or resolve the state of an existing external item without minting new community attention. First-time versus trusted-repeat external status affects trust/projection, not basic eligibility. Bot eligibility must be an explicit ADR disposition and cannot be inferred from provider actor kind or trust tier.

Attention eligibility remains zero-authority: it does not assign work, enter LifecycleFrontier, or create a Task. Only the explicit canonical claim transition owns that promotion.

Acceptance Criteria

  • AC1 — At least two tenants and multiple sources prove strict isolation on registration, admission, query, seen, claim, and counts.

  • AC2 — Repository rename and grant rotation preserve sourceInstanceId; revoked/stale epochs reject writes.

  • AC3 — Crash before/after admission receipt and lost-response retry converge without loss or duplicate history.

  • AC4 — Local direct and hosted authenticated paths admit the same canonical batch and receipt semantics.

  • AC5 — Issue, PR/review, and Discussion fixtures prove coverage, explicit gaps, revisions, tombstones, and uncertain absence.

  • AC6 — Automatic rows/counts/wakes contain no external prose; explicit drill-down applies source-relative trust.

  • AC7 — Concurrent claims produce one sourceEventId-to-taskId binding and one canonical Task.

  • AC8 — Unclaimed events never enter LifecycleFrontier; community history never becomes Native Edge Graph/GraphLog authority.

  • AC9 — Degraded sources remain visible and never normalize to complete/zero.

  • AC10 — A public criterion-to-test matrix maps every OQ and STEP_BACK gate to executable evidence.

  • AC11 — An end-to-end noise-flood fixture combines star/fork/watch events, internal/rostered context, and one external response-bearing occurrence; only the external occurrence enters Bird View/count eligibility.

  • AC12 — An internal close/resolve occurrence can remove or resolve the existing external attention item without creating a second attention item or Task.

Out of Scope

New production features, threshold selection, conditional wake activation, GitLab implementation, Fleet UI, or HA topology.

Avoided Traps

Do not mock away tenant/auth/transaction seams, use one happy-path tenant, or treat unit-suite green as end-to-end proof.

Related

  • Parent: #15145
  • Source: Discussion #15139 OQ1-OQ10 and STEP_BACK
  • Authority: ADR 0015, ADR 0019, ADR 0035, ADR 0036

Origin Session ID: 837ad74b-c2d2-413d-9aab-b7165a93a82a

Handoff Retrieval Hints

  • community activity end to end tenant source claim replay
  • Discussion 15139 executable criteria matrix

Creation Freshness

Creation duplicate sweep: immediately before filing at 2026-07-14T05:32:12.123Z, checked the latest 20 open issues and last 30 all-state A2A messages. The independent broader audit at 2026-07-14T05:13:00Z covered open and closed issues, pull requests, A2A, ADRs, and code; no equivalent owner or foreign claim existed.