Skip to content

docs: record design revision 2 for adapter-bounded external dependencies - #20

Merged
novelKR merged 2 commits into
mainfrom
codex/design-revision-2
Oct 1, 2026
Merged

novelKR merged 2 commits into
mainfrom
codex/design-revision-2

Conversation

@novelKR

@novelKR novelKR commented Sep 30, 2026 •

Copy link
Copy Markdown
Owner

Summary

This PR records the owner's dependency decision as design revision 2 and reconciles DevGuard's normative documents
with it. Documentation only.

  • The decision. On 2026-09-28 the owner decided that DevGuard may use Codex and other external dependencies behind
    explicit adapter boundaries, with reviewed, immutable source identities and flexible pins where justified.
  • This PR. On 2026-09-30 the owner directed that the decision be recorded as a design revision (W3 decision 5,
    "prepare"). The PR is prepared for review and is not merged without the owner's exact-head approval.

Revision 2 (docs/design-revision-2.md, with its reviewed Korean counterpart) states that:

  • DevGuard consumes external implementations, Codex included, only through declared adapter or binding boundaries with
    reviewed, immutable pins;
  • the authority core, and the generic client contract that CodeSpace would link, carry no CodeSpace or Codex product
    types;
  • each dependency is justified by what it replaces and by how its cost is contained;
  • the executable dependency gate in scripts/validate.py changes only in the reviewed PR that adds the first real
    adapter component and tests its boundary (gate change G). Until then it rejects every codex- and codespace-
    package;
  • nothing is selected: no dependency, pin, candidate architecture or implementation. CSRG-C00/C03/C09 are not revived,
    and the CS-RG hold stays in force.

The revision states the adopted pin policy normatively: candidate classes, same- and separate-executable identity,
qualification, divergence and rollback. Section 4 of the W0–W2 packet is cited as provenance only.

The PR also classifies the new file in scripts/ci-policy.json. That is one entry, added under a narrowly scoped owner
authorization; see "CI policy classification" below.

How existing text is treated

This follows the owner's direction for this PR:

  • Living normative or editorial text is updated in place: AGENTS.md, README.md, docs/design.md,
    docs/milestones.md, docs/planning/README.md, and the living parts of docs/planning/decisions.md.
  • Dated, accepted decision records keep their wording: ADR-006's D3 row and its dependency-boundary paragraph, and
    the D3 bullet of docs/planning/codespace-integration.md. Each gets a dated annotation that revision 2 supersedes the
    Codex-free restriction prospectively.
  • Hold notices that say the text below is "retained unchanged for historical traceability" are amended only enough
    to name the dependency statement that revision 2 supersedes and to say it is no longer current. The suspension itself
    is unchanged.

Every hit of the repository-wide search

Line numbers are at main 4898259.

Updated in place (living text)

  • AGENTS.md:3: the revision list now names revision 2.
  • AGENTS.md:7 (W0–W2 packet §5, row 1): the Codex-free bullet now states the adapter-bounded policy, and describes
    the gate as it behaves today.
  • docs/design.md:18 and docs/ko/design.md:16 (row 2): the rationale is replaced; its still-true first clause is
    kept. The revision links at :5–:6 and the hold notice at :3 are updated to match.
  • docs/planning/README.md:40 and Korean :41 (row 6): the Codex-free clause is replaced. The reference date (:5),
    the reading order (:13; Korean table row :14) and the hold notice (:3) are updated.
  • docs/milestones.md:5 (row 6).
  • README.md:49: an additional hit, not in packet §5. It is living, normative text that directly conflicted with
    the settled policy. No other README text is changed.
  • docs/planning/decisions.md, living parts: the hold notice (:3), the reference date (:5), a baseline row after
    :19, and the list of applied revisions (:24). The same in the Korean counterpart.

Wording kept, dated annotation added (dated decision records)

  • docs/planning/decisions.md:106 (ADR-006 D3 row) and :112 (the dependency-boundary paragraph); Korean :116 and
    :122 (row 4). The ADR-006 section notice (:96; Korean :106) is amended.
  • docs/planning/codespace-integration.md:176 (the D3 bullet), Korean :184 (row 5). The notices at :3 and :170
    (Korean :3 and :178) are amended.

Unchanged, because still true

  • README.md:41: devguard-core "contains no CodeSpace or Codex dependency". Revision 2 keeps the authority core free
    of them.
  • AGENTS.md:6: CodeSpace/Codex types stay outside the authority core.
  • "A later Codex pin change is a separate decision based on verification": docs/design.md:84 and :88,
    docs/planning/README.md:61, docs/planning/decisions.md:17, docs/planning/codespace-integration.md:5, and their
    Korean counterparts.
  • Revision-1 execution analysis that mentions Codex but states no Codex-free rule: docs/design.md:80;
    docs/planning/decisions.md:18, :44, :100, :104, :110; docs/planning/codespace-integration.md:20, :28,
    :33, :43, :54, :55, :133, :172; and their Korean counterparts.
  • Verification and delivery records: docs/planning/verification.md:16, :94, :236;
    docs/planning/pr-delivery.md (CSP-D04 and branch names); docs/planning/milestones/P1-RECOVERY.md:15.

Not edited, by instruction

  • docs/design.ko.md: the approved bytes.
  • docs/design-revision-1.md and its Korean counterpart: a dated revision. This covers D3 at :27, :107,
    :565-599, :661 and :836.
  • docs/planning/milestones/CS-RG.md:77 and its Korean counterpart at :73: left until CS-RG is re-planned.
  • NOTICE: still true.
  • scripts/validate.py:157: the gate; it changes only with gate change G.
  • The dated docs/handoff/ records.

Unrelated

  • .gitignore:2, AGENTS.md:11 and README.md:43: these refer to the local .codex settings directory.
  • codex/ branch names.

CodeSpace (counterpart PR)

  • Changed:
    • docs/codex-reuse.md:78, Korean :96 (row 10): the wording is kept and a dated annotation is added.
    • docs/upstream-update.md and its Korean counterpart (row 11): a dated addition.
  • Reported and unchanged:
    • docs/codex-reuse.md:38: CodeSpace's own core crates.
    • docs/devguard-integration.md:80 and :139, docs/architecture.md:62, docs/execution-substrate.md:89:
      revision-1 facts, not Codex-free rules.
    • The dated .github/notes/ records.

What does not change

  • No code, dependency, Cargo.lock, pin, gate, contract, wire, journal, workflow, planner behaviour, test, suite,
    service or credential.
  • The only CI-configuration change is the one classification entry described below.
  • docs/design.ko.md, docs/design-revision-1.md and its Korean text, docs/planning/milestones/CS-RG.md and its
    Korean text, NOTICE, docs/contracts.md, scripts/validate.py and the dated docs/handoff/ records.
  • The CS-RG implementation hold.

CI policy classification (one entry, owner-authorized)

  • The first run failed closed. This PR's first pull_request run,
    36725816252 on head 637627e, failed.
    • The Plan job's policy verification (python3 -B -m unittest discover -s scripts -p 'test_ci_*.py') requires every
      tracked path to be classified, and test_every_tracked_path_is_classified rejected the new
      docs/design-revision-2.md.
    • Repository checks and contracts were skipped, and Required checks failed.
    • That run is kept as evidence. The pre-PR local checks had not run those policy tests, and the failure reproduces
      locally on 637627e.
  • The narrow authorization. On 2026-09-30 the owner authorized one exception to the session's prohibition on CI
    changes: in this PR only, add docs/design-revision-2.md to the normative class of scripts/ci-policy.json,
    immediately next to docs/design-revision-1.md.
  • The change. Commit 9d223bb adds exactly that entry. No workflow logic, planner behaviour, test, suite or other
    policy entry changes.
  • The effect.
    • Revision 2 is now classified like revision 1, so later edits to it run the non-Rust checks that normative documents
      feed.
    • This PR itself runs the full profile, because it changes scripts/** and a planning input.

Verification

Current head 9d223bbd3529d6996fb8ebabeedae5458d31f498, based on main 4898259. Output was written outside the
worktree.

Check Result
python3 -B -m unittest discover -s scripts -p 'test_ci_*.py', the Plan job's policy verification passed: 95 tests
python3 scripts/ci_plan.py --base origin/main --head HEAD full, reasons full-path:scripts/** and planning-changed; 15 paths: 1 full, 14 normative, 0 unclassified
python3 scripts/validate.py --stages whitespace --diff-base origin/main passed
python3 scripts/validate.py, the complete DG-0 validator, with Rust 1.95.0, one Cargo job and one test thread passed: source-contract, documentation, protocol-analysis, dependency-boundary, format, clippy, and contracts (318 tests, 672 s). toolchain_matches: true
python3 scripts/check_docs.py passed: 18 reviewed pairs, 48 work units, 25 logical groups
git diff --check clean

First head 637627e. The complete DG-0 validator had passed locally (318 tests, 714 s), but the CI policy unit tests
were not run before the PR was opened. Its PR run failed as described above.

  • Korean review. Each Korean counterpart was reviewed against its source before
    python3 scripts/check_docs.py record --id was run for design-revision-2, design, planning-readme,
    planning-decisions and planning-codespace-integration.
  • Installed service. The DevGuard LaunchAgent kept its pid before and after each local run.
  • Not run locally: the macOS functional suites and the Ubuntu leg. This PR's CI runs them under the full profile.

Rollback

Documentation only: revert the merge commit. No runtime state depends on this change.

🤖 Generated with Claude Code

Record the owner's dependency decision of 2026-09-28 as design revision 2,
on the owner's direction of 2026-09-30, with its reviewed Korean
counterpart, and reconcile the normative documents with it.

Living text is updated in place (AGENTS.md, README.md, the design
reference, the milestone and planning indexes). The dated decision
records (ADR-006's D3 and the D3 bullet of the CodeSpace integration
specification) keep their wording and gain dated annotations. Hold
notices are amended only to name the superseded dependency statement.
README.md:49 is an additional hit found by the repository-wide search.

No code, dependency, pin, gate, CI or test changes; nothing is selected
and the CS-RG hold stays in force.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The CI policy test test_every_tracked_path_is_classified requires every
tracked path to be classified. The first pull_request run of this PR
(36725816252) failed closed on docs/design-revision-2.md.

Add that path to the normative class, next to design revision 1, under
the owner's narrowly scoped authorization of 2026-09-30. No other policy
entry, workflow, planner behaviour, test or suite changes.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant