Session: pool manager steady-state checkout/return #46

Open
opened 2026-09-04 19:12:18 +00:00 by larandar · 3 comments
Owner

Current acceptance and ownership

The approved rationalization reuses these later rulings and deliveries:

  • Q2 is settled for current execution: Ting/Ting#2 comment15474 requires explicit release and forbids inferred freedom from timeout, silence or staleness. The automatic-liveness mechanism remains a future evidence-led amendment, not an unanswered prerequisite. This supersedes the older negative-liveness blocker below and the Q2 wording in comment16739.
  • Provisioning is elsewhere: flake-ops#427 over providers#27/#29/#30 creates principals, seats and grants. Closed #45 and merged #47/PR#51 retire Vedanta bring-up. No PoolDirectory provisioning adapter belongs here.
  • Seat-taking is Vedanta's bounded effect: ruling D2b is implemented by closed #50/PR#53; contracts PR#12 materializes the delta on fastlane at af0f81ee635cbd69b11896d47c744cc0b5245976. The canonical wiki still publishes the old allocation prohibition as of this pass, so publication drift remains BR-003 in Ting#28. Do not claim that a merged delta updated the wiki.
  • Current backend residual: #49 owns remaining replay, timing, handover, exact revocation/reuse and event/integration gaps. Existing checkout code from #31/PR#39 is implementation evidence. flake-ops#435/#154 retain actual workload lifecycle and same-UUID reuse proof.

Acceptance remains open until the applicable current clauses, publication disposition and real lifecycle evidence agree. No branch merge, runtime effect or production activation is authorized by this issue update.

Earlier record — retained provenance

Proposal

Why

The freeholder's 2026-09-03 ruling on Ting/Ting#2 (Q1/Q3) decomposes the pool-manager Epic into two Sessions: the other covers bring-up, this one covers the steady-state checkout/return cycle.

Scope

Ordinary session completion: withdraw the drone's grant, revoke/report-pending its leases and resource tokens, and once runtime liveness is negative, rotate the checkout credential, advance the checkout generation, and return the same durable worker-<UUID> slot to the pool under a new immutable grant. A later checkout inherits no former capability. Suppression/tombstoning stay exceptional decommission actions, not routine cleanup.

Blocked on Q2. The freeholder's ruling explicitly defers the negative-runtime-liveness detection source ("DEFERRED and unknown") — checkout has no acceptance until Q2 resolves. This Session can be scoped and designed now but cannot be accepted as delivered until that source is ruled.

Design

Projects from OpenSpec 61 and its transcription as contracts.identity.forge-lifecycle (must.contracts.identity.forge-lifecycle.session-completion-reuses-durable-worker, ...revocation-is-explicit-per-layer, ...decommission-preserves-identity-evidence). Gets its own OpenSpec package per the ruling, not authored yet. Vedanta is the implementer, same as the bring-up Session.

Tasks

  • Author this Session's own OpenSpec package.
  • Resolve Q2 (negative-runtime-liveness detection source) — freeholder call, not this Session's to invent.
  • Implement grant withdrawal, lease/token revocation-or-pending on session end.
  • Implement checkout-credential rotation and generation advance on confirmed negative liveness.
  • Prove a later checkout inherits no former session's lease, token, or authority.

Provenance

Filed by a grooming pass, freeholder-authorized, citing the 2026-09-03 ruling recorded in the grooming log.

<!-- rationalization-current:2026-09-07 --> ## Current acceptance and ownership The [approved rationalization](https://jo.et0.pw/Ting/Ting/issues/28) reuses these later rulings and deliveries: - **Q2 is settled for current execution:** [Ting/Ting#2 comment15474](https://jo.et0.pw/Ting/Ting/issues/2#issuecomment-15474) requires explicit release and forbids inferred freedom from timeout, silence or staleness. The automatic-liveness mechanism remains a future evidence-led amendment, not an unanswered prerequisite. This supersedes the older negative-liveness blocker below and the Q2 wording in comment16739. - **Provisioning is elsewhere:** flake-ops#427 over providers#27/#29/#30 creates principals, seats and grants. Closed #45 and merged #47/PR#51 retire Vedanta bring-up. No PoolDirectory provisioning adapter belongs here. - **Seat-taking is Vedanta's bounded effect:** ruling D2b is implemented by closed #50/PR#53; contracts PR#12 materializes the delta on fastlane at af0f81ee635cbd69b11896d47c744cc0b5245976. The canonical wiki still publishes the old allocation prohibition as of this pass, so publication drift remains BR-003 in Ting#28. Do not claim that a merged delta updated the wiki. - **Current backend residual:** #49 owns remaining replay, timing, handover, exact revocation/reuse and event/integration gaps. Existing checkout code from #31/PR#39 is implementation evidence. flake-ops#435/#154 retain actual workload lifecycle and same-UUID reuse proof. Acceptance remains open until the applicable current clauses, publication disposition and real lifecycle evidence agree. No branch merge, runtime effect or production activation is authorized by this issue update. ## Earlier record — retained provenance ## Proposal ### Why The freeholder's [2026-09-03 ruling on Ting/Ting#2](https://jo.et0.pw/Ting/Ting/issues/2#issuecomment-15365) (Q1/Q3) decomposes the pool-manager Epic into two Sessions: the other covers bring-up, this one covers the steady-state checkout/return cycle. ### Scope Ordinary session completion: withdraw the drone's grant, revoke/report-pending its leases and resource tokens, and once runtime liveness is negative, rotate the checkout credential, advance the checkout generation, and return the same durable `worker-<UUID>` slot to the pool under a new immutable grant. A later checkout inherits no former capability. Suppression/tombstoning stay exceptional decommission actions, not routine cleanup. **Blocked on Q2.** The freeholder's ruling explicitly defers the negative-runtime-liveness detection source ("DEFERRED and unknown") — **checkout has no acceptance until Q2 resolves.** This Session can be scoped and designed now but cannot be accepted as delivered until that source is ruled. ## Design Projects from [OpenSpec 61](https://jo.et0.pw/Ting/Ting/wiki/OpenSpec-61-forge-identity-lifecycle-contract) and its transcription as [`contracts.identity.forge-lifecycle`](https://jo.et0.pw/Ting/contracts/wiki/contracts.identity.forge-lifecycle) (`must.contracts.identity.forge-lifecycle.session-completion-reuses-durable-worker`, `...revocation-is-explicit-per-layer`, `...decommission-preserves-identity-evidence`). Gets its own OpenSpec package per the ruling, not authored yet. Vedanta is the implementer, same as the bring-up Session. ## Tasks - [ ] Author this Session's own OpenSpec package. - [ ] Resolve Q2 (negative-runtime-liveness detection source) — freeholder call, not this Session's to invent. - [ ] Implement grant withdrawal, lease/token revocation-or-pending on session end. - [ ] Implement checkout-credential rotation and generation advance on confirmed negative liveness. - [ ] Prove a later checkout inherits no former session's lease, token, or authority. ## Provenance Filed by a grooming pass, freeholder-authorized, citing the [2026-09-03 ruling](https://jo.et0.pw/Ting/Ting/issues/2#issuecomment-15365) recorded in the [grooming log](https://jo.et0.pw/Ting/Ting/wiki/grooming-log).
Author
Owner

Grooming state: Open — provisionally Vedanta's; Q2 still unresolved.
Evidence: Freeholder ruling D2 (Larandar, 2026-09-05, in-session): pool bring-up is the provider's job (see #45); slot allocation "might be in Vedanta's role". The steady-state cycle merged under #31 / PR #39 (src/checkout.rs) therefore stays, provisionally.

Tension to resolve before acceptance: contracts.identity.openbao-lease-backend says Vedanta MUST NOT "allocate pool slots". If allocation stays here, that sentence needs a contract delta in Ting/contracts; if not, checkout moves to OpenBao/flake-ops. Recorded as decision D2b for the freeholder; nothing in this Session is accepted until it is ruled and Q2 (negative-liveness source) is ruled.

Related evidence: Vedanta#31, PR #39, #45, contracts store contracts.identity.openbao-lease-backend/spec.md.

<!-- larandar:groom:v1 --> **Grooming state:** Open — provisionally Vedanta's; Q2 still unresolved. **Evidence:** Freeholder ruling D2 (Larandar, 2026-09-05, in-session): pool *bring-up* is the provider's job (see #45); slot *allocation* "might be in Vedanta's role". The steady-state cycle merged under #31 / PR #39 (`src/checkout.rs`) therefore stays, provisionally. **Tension to resolve before acceptance:** `contracts.identity.openbao-lease-backend` says Vedanta MUST NOT "allocate pool slots". If allocation stays here, that sentence needs a contract delta in `Ting/contracts`; if not, checkout moves to OpenBao/flake-ops. Recorded as decision D2b for the freeholder; nothing in this Session is accepted until it is ruled and Q2 (negative-liveness source) is ruled. **Related evidence:** Vedanta#31, PR #39, #45, contracts store `contracts.identity.openbao-lease-backend/spec.md`.
Author
Owner

Q2 resolved 2026-09-03T22:13Z by the freeholder on Ting/Ting#2: nothing infers liveness — a slot is freed only by an explicit release; every other condition holds it. That ruling names this issue's Status/Need More Info as lifted; removing the label accordingly.

Consequences for this Session's acceptance shape: the negative-liveness clause lands as explicit-release plus no-inference, matching the landed pool code (src/checkout.rs: no_elapsed_time_frees_a_held_slot). The pending mapping to the canonical acceptance spec's Gate 9A S02 "declared backstop" wording is tracked as decision D3 of the 2026-09-05 Vedanta run (swarm-alpha/queen, DSH session aaa849b2); the clause is not claimed passed until that wording is reconciled.

— Vedanta lifecycle run (queen seat), per vedanta-implementation-plan.md (2026-09-05)

Q2 resolved 2026-09-03T22:13Z by the freeholder on [Ting/Ting#2](https://jo.et0.pw/Ting/Ting/issues/2#issuecomment-15474): **nothing infers liveness — a slot is freed only by an explicit release; every other condition holds it.** That ruling names this issue's `Status/Need More Info` as lifted; removing the label accordingly. Consequences for this Session's acceptance shape: the negative-liveness clause lands as *explicit-release plus no-inference*, matching the landed pool code (`src/checkout.rs`: `no_elapsed_time_frees_a_held_slot`). The pending mapping to the canonical acceptance spec's Gate 9A S02 "declared backstop" wording is tracked as decision D3 of the 2026-09-05 Vedanta run (`swarm-alpha/queen`, DSH session aaa849b2); the clause is not claimed passed until that wording is reconciled. — Vedanta lifecycle run (queen seat), per vedanta-implementation-plan.md (2026-09-05)
Author
Owner

Grooming state: Open — acceptance remains incomplete.
Native prerequisites: The four prerequisite edges to #31, #47, #49, and #50 are already installed and verified.
Dual-surface split: Acceptance must cover grant/allow plus mint/expire scenarios alongside deny/revoke plus rotation scenarios.
Named prerequisites: queen-seat Deliverable; pending Ting/contracts delta; unresolved D3 mapping.
Audit: G46, grooming audit 2026-09-19/20.

<!-- larandar:groom:v1 --> **Grooming state:** Open — acceptance remains incomplete. **Native prerequisites:** The four prerequisite edges to #31, #47, #49, and #50 are already installed and verified. **Dual-surface split:** Acceptance must cover grant/allow plus mint/expire scenarios alongside deny/revoke plus rotation scenarios. **Named prerequisites:** queen-seat Deliverable; pending `Ting/contracts` delta; unresolved D3 mapping. **Audit:** G46, grooming audit 2026-09-19/20.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Reference
Ting/Vedanta#46
No description provided.