feat(governance): pin selective upstream import contract
This commit is contained in:
@@ -13,9 +13,11 @@
|
||||
"properties": {
|
||||
"schema_version": {"const": 1},
|
||||
"source_repository": {"type": "string", "minLength": 1},
|
||||
"source_repository_url": {"type": "string", "pattern": "^https://github\\.com/[A-Za-z0-9_.-]+/[A-Za-z0-9_.-]+$"},
|
||||
"source_commit": {"type": "string", "pattern": "^(unknown|[0-9a-f]{40})$"},
|
||||
"source_tree_hash": {"type": "string", "pattern": "^[0-9a-f]{64}$"},
|
||||
"source_mode": {"enum": ["git", "snapshot"]},
|
||||
"source_skill_sha256": {"type": "string", "pattern": "^[0-9a-f]{64}$", "description": "SHA-256 of the research source root SKILL.md."},
|
||||
"source_mode": {"enum": ["git", "archive", "snapshot"]},
|
||||
"target_repository": {"type": "string", "minLength": 1},
|
||||
"target_base_commit": {"type": "string", "pattern": "^[0-9a-f]{40}$"},
|
||||
"policy_version": {"const": 2},
|
||||
@@ -36,6 +38,15 @@
|
||||
},
|
||||
"operator_review_required": {"type": "boolean"}
|
||||
},
|
||||
"allOf": [
|
||||
{
|
||||
"if": {"properties": {"source_mode": {"enum": ["git", "archive"]}}},
|
||||
"then": {
|
||||
"required": ["source_repository_url", "source_skill_sha256"],
|
||||
"properties": {"source_commit": {"pattern": "^[0-9a-f]{40}$"}}
|
||||
}
|
||||
}
|
||||
],
|
||||
"$defs": {
|
||||
"file": {
|
||||
"type": "object",
|
||||
|
||||
+80
@@ -0,0 +1,80 @@
|
||||
{
|
||||
"generated_at": "2026-08-14T01:13:57Z",
|
||||
"mirror_files": [
|
||||
{
|
||||
"license": "MIT",
|
||||
"source": "SKILL.md",
|
||||
"source_sha256": "ef453dd8dd4a9da72b56010ec33bb7dab57fd72333d8785cac0986d5456e17c5",
|
||||
"status": "applied",
|
||||
"target": "references/upstream/yinduzhanxing/SKILL.md",
|
||||
"target_sha256_after": "ef453dd8dd4a9da72b56010ec33bb7dab57fd72333d8785cac0986d5456e17c5",
|
||||
"target_sha256_before": "1be8beafbd5f4b6df7f95afec39e87033cd70ef6bf582fe7d9f1eb62fb5d00fb"
|
||||
}
|
||||
],
|
||||
"operator_review_required": true,
|
||||
"policy_version": 2,
|
||||
"privacy_scan": {
|
||||
"rejections": [],
|
||||
"scanned_files": 1,
|
||||
"status": "pass"
|
||||
},
|
||||
"protected_rejections": [],
|
||||
"schema_version": 1,
|
||||
"semantic_merge_files": [
|
||||
{
|
||||
"diff_summary": "manual semantic merge required: +42/-31 lines",
|
||||
"path": "SKILL.md",
|
||||
"source_sha256": "ef453dd8dd4a9da72b56010ec33bb7dab57fd72333d8785cac0986d5456e17c5",
|
||||
"status": "review_required",
|
||||
"target_sha256": "b0377ac7952f8a8d9433522c50837967939e5f91fbed5042467278520379da49"
|
||||
},
|
||||
{
|
||||
"diff_summary": "manual semantic merge required: +65/-53 lines",
|
||||
"path": "AGENTS.md",
|
||||
"source_sha256": "a1ff71472c6312000b8aef3f099d5499c0b27d1fd4f61594ef06a56c48533dd2",
|
||||
"status": "review_required",
|
||||
"target_sha256": "d8cf104ff60e627ffaf75031237a37b022b54f7145cafdffb3eacdc634f998f9"
|
||||
},
|
||||
{
|
||||
"diff_summary": "manual semantic merge required: +13/-1 lines",
|
||||
"path": "references/strict-workflow-router.md",
|
||||
"source_sha256": "afb83e0b1b290166cf7ecdcabcae8221d94b14138abc223e9cf57d27596f82d4",
|
||||
"status": "review_required",
|
||||
"target_sha256": "2dbab0179c6001c3c8b51e425af323f214e5e912afe7840821f6c38c3546c905"
|
||||
},
|
||||
{
|
||||
"diff_summary": "manual semantic merge required: +207/-202 lines",
|
||||
"path": "scripts/unified_consultation_orchestrator.py",
|
||||
"source_sha256": "f48ad61455ee344ffc53cda225198511979eea05a4be2ac8ef16ea56f40a4d1a",
|
||||
"status": "review_required",
|
||||
"target_sha256": "da87697fb8d9bcafa98b2ba0cf091df38769f936a030b8095288f4c99a5dd928"
|
||||
},
|
||||
{
|
||||
"diff_summary": "manual semantic merge required: +2/-11 lines",
|
||||
"path": "scripts/report_orchestrator.py",
|
||||
"source_sha256": "cd67d23cf9df68d200167ac25af8473bfabb1a344a5f0a1e1254de14ba426daf",
|
||||
"status": "review_required",
|
||||
"target_sha256": "5fbc2c8df6772597295ae80a5e68709a996ddb9b35724f0820f17f7cb028a201"
|
||||
},
|
||||
{
|
||||
"diff_summary": "manual semantic merge required: +5082/-1638 lines",
|
||||
"path": "scripts/jyotish_api_server.py",
|
||||
"source_sha256": "d522d82a453645770df25b63f6ba77e75de4c694b9b6580a0d88b931a2988314",
|
||||
"status": "review_required",
|
||||
"target_sha256": "5c2f4de25547a98d16f6f8e84c129f525a1be6359c3a5f53fa6fd2a631411aee"
|
||||
}
|
||||
],
|
||||
"source_commit": "5db72537741fcedaa7b5498502d4a31b0f9fc147",
|
||||
"source_mode": "archive",
|
||||
"source_repository": "732642856/yinduzhanxing",
|
||||
"source_repository_url": "https://github.com/732642856/yinduzhanxing",
|
||||
"source_skill_sha256": "ef453dd8dd4a9da72b56010ec33bb7dab57fd72333d8785cac0986d5456e17c5",
|
||||
"source_tree_hash": "18e3122ef73c2776a950bfec128efeb09ac0524ec1d2179390260166b87ca814",
|
||||
"target_base_commit": "0fd111d16b45796086a6c1d0945dbd3de6755d8a",
|
||||
"target_repository": "root/Jyotisha",
|
||||
"tests_run": [
|
||||
"tests/test_import_yinduzhanxing.py",
|
||||
"tests/test_report_orchestrator_reader_contract.py",
|
||||
"tests/test_upstream_import_plan.py"
|
||||
]
|
||||
}
|
||||
@@ -2,6 +2,7 @@
|
||||
"schema_version": 2,
|
||||
"direction": "research_to_commercial_only",
|
||||
"source_repository": "732642856/yinduzhanxing",
|
||||
"source_repository_url": "https://github.com/732642856/yinduzhanxing",
|
||||
"target_repository": "root/Jyotisha",
|
||||
"reverse_sync": "forbidden",
|
||||
"modes": {
|
||||
@@ -21,6 +22,9 @@
|
||||
"scripts/jyotish_api_server.py"
|
||||
],
|
||||
"protected": [
|
||||
"skills/jyotish-birth-time-rectification/**",
|
||||
"skills/jyotish-vedic-astrology/**",
|
||||
"SKILL.md",
|
||||
"frontend/**",
|
||||
"deploy/**",
|
||||
".gitea/**",
|
||||
@@ -47,6 +51,23 @@
|
||||
"Only explicit mirror mappings may be copied byte-for-byte.",
|
||||
"Semantic-merge paths are review inputs and are never overwritten by the importer.",
|
||||
"Commercial product, identity, billing, database and deployment surfaces are protected.",
|
||||
"There is no commercial-to-research mode or gate in schema v2."
|
||||
]
|
||||
"There is no commercial-to-research mode or gate in schema v2.",
|
||||
"The only byte-for-byte mirror is upstream SKILL.md into references/upstream/yinduzhanxing/SKILL.md.",
|
||||
"Commercial root and birth-time-rectification Skills are protected targets and may only be reviewed through separate semantic work.",
|
||||
"The importer enforces the built-in minimum protected pattern set even when an alternate policy file is supplied.",
|
||||
"Unbound non-Git snapshots are legacy records; new archive imports fail closed without commit and expected tree SHA-256.",
|
||||
"A Git source must be a clean repository-root checkout whose origin matches source_repository; Git checkouts cannot be relabeled as archive sources.",
|
||||
"Manifest generation requires a clean target repository root and is deterministic for fixed source, target base commit, policy and CLI identity inputs.",
|
||||
"Manifest output must be JSON, cannot overlap the source tree, and may enter the target only through references/cross_project_contract/imports."
|
||||
],
|
||||
"source_modes": {
|
||||
"git": "Use the exact clean repository-root HEAD commit. Explicit commit and expected tree pins, when used, must be supplied together and match.",
|
||||
"archive": "Requires both an explicit 40-hex source commit and expected importer-compatible source-tree SHA-256; absence or mismatch is rejected.",
|
||||
"snapshot": "Legacy manifest records only. The v2 importer does not emit new unbound snapshots."
|
||||
},
|
||||
"determinism": {
|
||||
"tree_hash": "SHA-256 over sorted relative path, NUL, file SHA-256 bytes, NUL; .git is excluded and source symlinks are rejected.",
|
||||
"generated_at": "Git source commit time for git mode; target base commit time for archive mode. Wall-clock time is forbidden.",
|
||||
"json": "UTF-8, sorted keys, two-space indentation, trailing newline."
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user