You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Slice A is intentionally headless and bounded. It does not own I/O, durable replacement, journal/admission, migration or app wiring. The first review epoch completed and correction wave 1 landed. The current exact-head review has two open Codex P2s (component-copy allocation discipline; §20 tamper/unsupported-schema wording) that must be resolved or dispositioned before merge.
After Slice A merges and its resulting-main proof/housekeeping is terminal, continue automatically to Slice B from proven main; do not append Slice B into #928.
Objective
Finish Gate 2 exactly as defined by the binding R-15 contract: strict parsing and canonical AAD remain authoritative; every protected record class that needs an implementation adapter has one explicit renderer-neutral adapter/result; stable logical identity and scope are preserved without narrowing legacy ID domains; cross-record substitution is rejected; current TS/Tauri production authority remains unchanged.
This is the implementation closure for the identity-binding problem historically tracked by #361; close #361 only when R-15 evidence actually proves its acceptance surface.
Enumerate all v1 protected record classes from §3/§5 and classify implemented adapter, fixed literal identity, structured composite identity, explicit refusal, or no packaged persisted record yet.
Add the smallest coherent adapters required to move Gate 2 from registry-only to usable record identities.
Prove canonical AAD and substitution resistance across project/global/install scopes, asset pairs, snapshots, RAG, recovery, migration and control records.
Preserve arbitrary legal legacy component strings through an unambiguous canonical representation; never remap or silently narrow existing IDs.
Keep credentials/raw key material outside ordinary record envelopes per contract.
Acceptance
all Gate 2 invariants have code + tests;
no protected class silently falls back to path identity or unbound ciphertext;
Program position
Child owner of #445 (R-15). This issue owns the remainder of Gate 2 after PR #917's typed identity-registry slice.
Current execution — M1 / Gate 2 — 2026-10-01
Slice A is intentionally headless and bounded. It does not own I/O, durable replacement, journal/admission, migration or app wiring. The first review epoch completed and correction wave 1 landed. The current exact-head review has two open Codex P2s (component-copy allocation discipline; §20 tamper/unsupported-schema wording) that must be resolved or dispositioned before merge.
After Slice A merges and its resulting-main proof/housekeeping is terminal, continue automatically to Slice B from proven main; do not append Slice B into #928.
Objective
Finish Gate 2 exactly as defined by the binding R-15 contract: strict parsing and canonical AAD remain authoritative; every protected record class that needs an implementation adapter has one explicit renderer-neutral adapter/result; stable logical identity and scope are preserved without narrowing legacy ID domains; cross-record substitution is rejected; current TS/Tauri production authority remains unchanged.
This is the implementation closure for the identity-binding problem historically tracked by #361; close #361 only when R-15 evidence actually proves its acceptance surface.
Required scope
Acceptance
Non-goals
Prefer small sequential PRs if the remainder exceeds normal reviewability. Do not create another XXL PR.