Execution mode: tracking
Parent: #172
Canonical architecture: docs/architecture/issue-181-e2e-admission-regression.md
Historical review/rationale: docs/architecture/issue-181-review-amendments.md
Issue Type
Release / regression Epic. Do not dispatch this Epic as one coding task.
Context
Most repository-side S6 architecture/test scaffolding is already on main. The current integrated S6 topology is intentionally:
- separate signed host preflight;
- five manifest partitions:
contract, postgres, operator-desktop, operator-mobile, host-boundary;
- four S6 suite commands:
test:mcp:contract, test:mcp:postgres, e2e:mcp-operator, test:mcp:host-boundary.
A standalone test:mcp:issuance S6 suite is not missing. Integrated review moved packet-issuance proof back to #179/S4 because issuance is owned/proven there; duplicating it in S6 violated test ownership.
The repository-side S6 controller remains fail-closed (externalControllerRequired, live activation/ingress/issuance disabled by default). The major remaining gate is the independently controlled external trust lane and live signed release evidence.
Desired Outcome
S6 proves that the already-delivered S1-S5 MCP admission/context/grant/recovery behavior remains connected across real routes, PostgreSQL, operator UI and the supported hostile host boundary, and final Epic-172 readiness is enabled only with exact externally signed controller/App/host/build evidence.
S6 owns proof/integration. It does not silently redefine S1-S5 production policy.
Tasks
Acceptance Criteria
Out of Scope
- Reimplementing S1-S5.
- Adding a new issuance suite merely because older issue text mentioned five commands.
- Letting ordinary checkout/Actions code own external controller secrets/root authority.
- Treating beta CI success alone as enabled-production release evidence.
Technical Notes
Issue history contains many rounds of architecture detail; the checked-in primary architecture + amendments are now the source of truth. Future implementation should work from current main and #357 rather than reconstructing the old stacked PR branches.
Execution mode: tracking
Parent: #172
Canonical architecture:
docs/architecture/issue-181-e2e-admission-regression.mdHistorical review/rationale:
docs/architecture/issue-181-review-amendments.mdIssue Type
Release / regression Epic. Do not dispatch this Epic as one coding task.
Context
Most repository-side S6 architecture/test scaffolding is already on
main. The current integrated S6 topology is intentionally:contract,postgres,operator-desktop,operator-mobile,host-boundary;test:mcp:contract,test:mcp:postgres,e2e:mcp-operator,test:mcp:host-boundary.A standalone
test:mcp:issuanceS6 suite is not missing. Integrated review moved packet-issuance proof back to #179/S4 because issuance is owned/proven there; duplicating it in S6 violated test ownership.The repository-side S6 controller remains fail-closed (
externalControllerRequired, live activation/ingress/issuance disabled by default). The major remaining gate is the independently controlled external trust lane and live signed release evidence.Desired Outcome
S6 proves that the already-delivered S1-S5 MCP admission/context/grant/recovery behavior remains connected across real routes, PostgreSQL, operator UI and the supported hostile host boundary, and final Epic-172 readiness is enabled only with exact externally signed controller/App/host/build evidence.
S6 owns proof/integration. It does not silently redefine S1-S5 production policy.
Tasks
main.main.Acceptance Criteria
Out of Scope
Technical Notes
Issue history contains many rounds of architecture detail; the checked-in primary architecture + amendments are now the source of truth. Future implementation should work from current
mainand #357 rather than reconstructing the old stacked PR branches.