Skip to content

Commit a1a7722

Browse files
Sync Boatstack from Intelligence Flow Labs @ 5227e7828d9b (#89)
Co-authored-by: operator-stack-publisher[bot] <operator-stack-publisher[bot]@users.noreply.github.com>
1 parent b29297e commit a1a7722

8 files changed

Lines changed: 72 additions & 22 deletions

CONTRIBUTING.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22

33
# Contributing
44

5-
Boatstack is a generated content distribution. Propose changes to workflow semantics, templates, evidence rules, or generated presentation in [Intelligence Flow](https://github.com/operatorstack/intelligence-flow/tree/c5f3e330d6167247446e1915deaf1bc593cf2e0d/labs/12-product-engineering-loop).
5+
Boatstack is a generated content distribution. Propose changes to workflow semantics, templates, evidence rules, or generated presentation in [Intelligence Flow](https://github.com/operatorstack/intelligence-flow/tree/5227e7828d9bcac8c6b11c19289c2b4ef5be92a2/labs/12-product-engineering-loop).
66

77
The Boatstack repository receives product/runtime changes through a generated pull request. Review the PR's `UPSTREAM.json`, tests, adapter diff, and context-size change; do not hand-edit generated output on `main`. `.github/workflows` is the exception: it is Boatstack's executable control plane, excluded from scheduled projection and changed only through a separate manually reviewed Boatstack PR.
88

UPSTREAM.json

Lines changed: 9 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@
1212
},
1313
"files": {
1414
".gitignore": "a7079e923a776f14f1bb3a6aa0a11a133a8e1dfb35af020f327623357b7e3957",
15-
"CONTRIBUTING.md": "87a58a3120f70e719a3471f4ad2be5673242ef29150a65a5fd6d2b1079ee69f4",
15+
"CONTRIBUTING.md": "77a60a6dbf5dd2f29aefc942283201f8c48f45ed72a3caf105065ad3322ffcd6",
1616
"README.md": "125b47671a68556df382f19756fb61fa18925606cbbaf54d6bc9df8872b36870",
1717
"assets/boatstack-journey.svg": "e465befc50c8ce30f3e07e8fd97012931beeb053392c8fbf38ad645023b3cc63",
1818
"assets/boatstack-mark.svg": "be1f984da1bfa69fa5d1f986d8343d21f7e20921b71db888c928b4d2e54b09b5",
@@ -78,6 +78,7 @@
7878
"boatstack/pr_test.go": "7f82954d94c1ceae848a581dda25e58af92251d78a5a94ed2d672bedf5a0349e",
7979
"boatstack/provision.go": "4882d49681f99b11ba9d182ca13772131b7f9a11a6c2b560800654ca14f5111e",
8080
"boatstack/provision_test.go": "214e9edb991a66d5bbb696a7c1b63876d2f799f2cab4e3f40785f4e8f1eac57b",
81+
"boatstack/publication_ignored_repro_test.go": "b6f3aeb8ba22949ff9af7ac5afe8fb828385d9708d5d5893ef41f33a3de873e1",
8182
"boatstack/recovery.go": "dd816b18b54a0085b8d8276a93ee98d2b1e90099059a0d85cf6e24edf6f37d5b",
8283
"boatstack/recovery_test.go": "29490e7477ba602491330036a491289dd9117b99ff862f66dae421ba17e04c9f",
8384
"boatstack/references/artifacts.md": "5fa888ac519085d65cee1d04df5902761651bcf2d7af81711fa0f8ecd1fc0f59",
@@ -94,7 +95,7 @@
9495
"boatstack/runtime.go": "d1e95895002ea2b27199b6e05b33c4c6e20f63455a44f63ca3cfeedecfc23420",
9596
"boatstack/runtime_cache.go": "60c4eb0c7dde91d40d6ef3f05adc1a1282d17ff1ca12470d0a008454f7ca7489",
9697
"boatstack/runtime_cache_test.go": "b981467ddc9f0f562da6bff5de7a80a9fe5a433a0317541d1e48df268546ac85",
97-
"boatstack/safety.go": "e5d91bf219838f5e0c80daaf5b18a2cca9661f211fa60e2c1fab9e5835082b36",
98+
"boatstack/safety.go": "b0fb94bc802baf39bc39d09276e1f0eb76a39027a421b0dfd49188173571bfe8",
9899
"boatstack/safety_test.go": "01f28bc3bfcb6bdd47b307e309e36bbc1921b6426ad0b777d81fe4131200c37e",
99100
"boatstack/skill_frontmatter.go": "73364df463ce828c2d005aab55f72bb92f7a34d99cf3f53d4e0cd5a4da9dbd0e",
100101
"boatstack/skill_frontmatter_test.go": "a3ec52e7df357a72265c95dd66db15d9c0effc7e5f90f14ce69c27792ce394eb",
@@ -117,10 +118,10 @@
117118
"docs/benchmark-corpus-audit.md": "f2d206fe8579a514f9da82b2c96c19b343ac004be67617e1bd34f0f8e0e5e6c6",
118119
"docs/benchmark-submission-audit.md": "9518abdd17690729c6423f87cab20418ed47b0915b5faa44b9ef975e9e9c3b79",
119120
"docs/configuration.md": "df054f49d532c8b1b7d94184810d1b3b5bf18cdc30eb985b4b6d0639162e341a",
120-
"docs/evidence-engineered-coding.md": "091930ef2e129debd56a13f9465364fb1b30d2bdc09d28cafb99f8bdf372a899",
121+
"docs/evidence-engineered-coding.md": "ae3c106e9d1b04ea97cda781048a7dd2641104662aa2f8b7c05356c7fcfcaa31",
121122
"docs/generated-files.md": "437791765b0a4015032ae21d1a6618563cad92b7402819e4f963bf5ae16284a3",
122123
"docs/getting-started.md": "f314270c5ed1a55bbef5f3ddbcb5596693dbee9374e5f0d3df8838cefbd68052",
123-
"docs/public-claims.json": "1cd0ea8ce15058bf69e18bef9a8eabcc57d77bf7fb6c05d0ff46b5ba78ca0ff2",
124+
"docs/public-claims.json": "9ba4aa7c99afee1b30ee1ac75e32c4d3e8724fbfbbb6142957407ae2165de27f",
124125
"docs/public-surface.md": "713f7a050b5f339cf948299103ef3800417dccfecf2cc1a4166397ea6f978907",
125126
"docs/research-and-design.md": "8d78678108f0a6c924e1ff9b32c0f81aae9d1f779e0082843b6f99ad993ae2b6",
126127
"docs/safety.md": "7b9b5c515d36e683767ec8d3d9d6d119ac93650b2f629d351deadd4c600ed6a6",
@@ -134,7 +135,7 @@
134135
"labs/diagram-json/compiled/evidence.md": "1ba1c989ade070a8ef9a508fbd788d100d7292f2dbacbb2bce895468019f619d",
135136
"labs/diagram-json/compiled/tasks.json": "88f60851abf79d851e9fccc754ff3040034ae595306bc87d64784c19eb403e71",
136137
"labs/diagram-json/compiled/test-matrix.json": "424657ff505768e50fa113801fd8363364a18269d5297480907a993d44063a39",
137-
"labs/diagram-json/plan.lock.json": "1dfe1ea29c712d61940cc77f259f8bb0ecdcd073d6426eb29eda6612cbb645b5",
138+
"labs/diagram-json/plan.lock.json": "5a5e68c8129157e18219f5ce21ba319234d4ec11572ee9196cb31f6ec9843b96",
138139
"labs/diagram-json/plan.md": "3cc4f533b8d69386deff16b3a594a3ba09d4c0c3db636cccd8c4380084ce6a51",
139140
"labs/diagram-json/questions.md": "74733b015002c8a6777c558e7e997fa48c94850b9bd39054fe9366c97ecf728d",
140141
"labs/diagram-json/request.md": "0808fc41c36779c404f4a3a121167da6e76cac56df526e70f9ed6d3e0d4c02ed",
@@ -206,12 +207,13 @@
206207
"release-notes/2026-07-23-recoverable-repository-sync.md": "3afc4f6220ae76df3bd6dcd15fc180135274c808729e9c512a2c53462ec690c2",
207208
"release-notes/2026-07-23-shipped-feature-candidate-resolution.md": "bd8ee8e7f3f216b356b121a83ef10cb0c8131a90b9ab803edebf23b882d9cf89",
208209
"release-notes/2026-07-23-sync-title-contract.md": "2869d6d084ea60402e57ffe985d0fc4cd83ef9bb09958cc53e349157d3383202",
209-
"release-notes/2026-07-23-visual-evidence-external-host.md": "09edbe5e6e1bfc866cf5ee744a5001d678f7a67f0f330cf43bd5157eedf04276"
210+
"release-notes/2026-07-23-visual-evidence-external-host.md": "09edbe5e6e1bfc866cf5ee744a5001d678f7a67f0f330cf43bd5157eedf04276",
211+
"release-notes/2026-07-24-ignored-deliveries-publication-authority.md": "a25f8469316276101490c79a57c1a236c18072dfbb23682bb1778871d247067d"
210212
},
211213
"generator": "operatorstack/intelligence-flow:boatstack-distribution",
212214
"schema_version": 1,
213215
"source": {
214-
"commit": "c5f3e330d6167247446e1915deaf1bc593cf2e0d",
216+
"commit": "5227e7828d9bcac8c6b11c19289c2b4ef5be92a2",
215217
"path": "labs/12-product-engineering-loop",
216218
"repository": "operatorstack/intelligence-flow"
217219
}
Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,34 @@
1+
package boatstack
2+
3+
import "testing"
4+
5+
// TestPublicationBypassHonorsIgnoredDeliveries reproduces the external report on
6+
// PR #322: `next`/`run` scope ambiguity through workflow.ignored_deliveries
7+
// (see TestResolveNextIgnoredActiveDeliveryClearsAmbiguity), but the
8+
// publication-authority path — publicationBypassFinding, which emits
9+
// relation=ambiguous on a denied push — iterates ActiveManagedDeliveries
10+
// directly and never filters ignored slugs. A single ignored, stale-but-active
11+
// delivery (agentic-l3-full: APPROVED lock, never published) therefore poisons
12+
// publication authority for every other delivery.
13+
//
14+
// This mirrors the `next` test: two active deliveries, one ignored, neither on
15+
// the current branch. With the ignore list honored, only one active delivery
16+
// remains and the finding must not be ambiguous.
17+
func TestPublicationBypassHonorsIgnoredDeliveries(t *testing.T) {
18+
repo := nextTestRepo(t)
19+
writeNextDelivery(t, repo, "agentic-l3-full", "BUILD", 0) // stale, ignored blocker
20+
writeNextDelivery(t, repo, "roles-access-policies", "BUILD", 0)
21+
setIgnoredDeliveries(t, repo, "agentic-l3-full")
22+
23+
finding, blocked := publicationBypassFinding(repo, "denied push", "tool-input")
24+
if !blocked {
25+
t.Fatalf("expected a publication finding for the remaining active delivery")
26+
}
27+
if finding.BranchRelation == "ambiguous" {
28+
t.Fatalf("ignored active delivery poisoned publication authority: BlockingFeature=%q relation=%q",
29+
finding.BlockingFeature, finding.BranchRelation)
30+
}
31+
if finding.BlockingFeature != "roles-access-policies" {
32+
t.Fatalf("expected the un-ignored delivery to be blocking, got %q", finding.BlockingFeature)
33+
}
34+
}

boatstack/safety.go

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -270,6 +270,15 @@ func publicationBypassFinding(repo, reason, source string) (SafetyFinding, bool)
270270
if err != nil {
271271
return SafetyFinding{Category: "workflow-state-invalid", Reason: "publication is denied because managed delivery state cannot be verified", Source: "delivery-state"}, true
272272
}
273+
// Scope publication-authority resolution to un-ignored deliveries so it
274+
// matches ResolveNext and the run coordinator. Without this, a stale-but-
275+
// active ignored delivery (e.g. an APPROVED lock whose code shipped out of
276+
// band) poisons authority for every other delivery with relation=ambiguous.
277+
// A config that fails to load leaves active unfiltered, preserving the prior
278+
// behavior.
279+
if config, _, configErr := LoadConfig(filepath.Join(repo, ".product-loop", "project.json")); configErr == nil {
280+
active = withoutIgnoredDeliveries(active, config.Workflow.IgnoredDeliveries)
281+
}
273282
if len(active) == 0 {
274283
return SafetyFinding{}, false
275284
}

docs/evidence-engineered-coding.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -146,6 +146,6 @@ Delivery and system improvement also remain separate. A failed task may suggest
146146

147147
## What is evidence-backed
148148

149-
The current moves were derived from the Intelligence Flow benchmark corpus and product-repository studies. The generated source commit is [`c5f3e330d6167247446e1915deaf1bc593cf2e0d`](https://github.com/operatorstack/intelligence-flow/tree/c5f3e330d6167247446e1915deaf1bc593cf2e0d/labs/12-product-engineering-loop).
149+
The current moves were derived from the Intelligence Flow benchmark corpus and product-repository studies. The generated source commit is [`5227e7828d9bcac8c6b11c19289c2b4ef5be92a2`](https://github.com/operatorstack/intelligence-flow/tree/5227e7828d9bcac8c6b11c19289c2b4ef5be92a2/labs/12-product-engineering-loop).
150150

151151
The evidence supports specific failure mechanisms and guardrails. It does not establish that Boatstack is optimal, that control-theory notation proves software quality, or that one workflow dominates every team. Those are evaluation questions, so the distribution preserves measurements, provenance, gaps, and negative results.

docs/public-claims.json

Lines changed: 12 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
{
22
"schema_version": 1,
3-
"source_commit": "c5f3e330d6167247446e1915deaf1bc593cf2e0d",
3+
"source_commit": "5227e7828d9bcac8c6b11c19289c2b4ef5be92a2",
44
"statuses": ["verified", "observed", "still_being_evaluated"],
55
"claims": [
66
{
@@ -12,7 +12,7 @@
1212
"readable_evidence": "why-these-steps.md#portable-workflow-and-state",
1313
"implementation": ["../boatstack/export.go", "../boatstack/references/artifacts.md", "../boatstack/references/workflow.md"],
1414
"verification": ["../boatstack/export_test.go"],
15-
"last_verified_version": "source:c5f3e330d6167247446e1915deaf1bc593cf2e0d"
15+
"last_verified_version": "source:5227e7828d9bcac8c6b11c19289c2b4ef5be92a2"
1616
},
1717
{
1818
"id": "human-decisions",
@@ -23,7 +23,7 @@
2323
"readable_evidence": "why-these-steps.md#human-decisions",
2424
"implementation": ["../boatstack/references/workflow.md", "../boatstack/plan.go"],
2525
"verification": ["../boatstack/plan_test.go", "../boatstack/planning_test.go"],
26-
"last_verified_version": "source:c5f3e330d6167247446e1915deaf1bc593cf2e0d"
26+
"last_verified_version": "source:5227e7828d9bcac8c6b11c19289c2b4ef5be92a2"
2727
},
2828
{
2929
"id": "validation-provenance",
@@ -34,7 +34,7 @@
3434
"readable_evidence": "why-these-steps.md#validation-provenance",
3535
"implementation": ["validation-and-evidence.md", "../boatstack/plan.go"],
3636
"verification": ["../boatstack/plan_test.go"],
37-
"last_verified_version": "source:c5f3e330d6167247446e1915deaf1bc593cf2e0d"
37+
"last_verified_version": "source:5227e7828d9bcac8c6b11c19289c2b4ef5be92a2"
3838
},
3939
{
4040
"id": "irreversible-operations",
@@ -46,7 +46,7 @@
4646
"readable_evidence": "why-these-steps.md#irreversible-operations",
4747
"implementation": ["safety.md", "../boatstack/safety.go", "../boatstack/hooks.go"],
4848
"verification": ["../boatstack/safety_test.go", "../boatstack/hooks_test.go"],
49-
"last_verified_version": "source:c5f3e330d6167247446e1915deaf1bc593cf2e0d"
49+
"last_verified_version": "source:5227e7828d9bcac8c6b11c19289c2b4ef5be92a2"
5050
},
5151
{
5252
"id": "reviewer-ready-pr",
@@ -57,7 +57,7 @@
5757
"readable_evidence": "why-these-steps.md#reviewer-ready-pr",
5858
"implementation": ["../boatstack/pr.go", "getting-started.md"],
5959
"verification": ["../boatstack/pr_test.go"],
60-
"last_verified_version": "source:c5f3e330d6167247446e1915deaf1bc593cf2e0d"
60+
"last_verified_version": "source:5227e7828d9bcac8c6b11c19289c2b4ef5be92a2"
6161
},
6262
{
6363
"id": "phase-scoped-delivery",
@@ -68,7 +68,7 @@
6868
"readable_evidence": "why-these-steps.md#phase-scoped-delivery",
6969
"implementation": ["../boatstack/delivery.go", "../boatstack/safety.go", "../boatstack/hooks.go", "../boatstack/references/workflow.md"],
7070
"verification": ["../boatstack/delivery_test.go", "../boatstack/pr_test.go"],
71-
"last_verified_version": "source:c5f3e330d6167247446e1915deaf1bc593cf2e0d"
71+
"last_verified_version": "source:5227e7828d9bcac8c6b11c19289c2b4ef5be92a2"
7272
},
7373
{
7474
"id": "model-neutral-contract",
@@ -79,7 +79,7 @@
7979
"readable_evidence": "why-these-steps.md#model-choice-and-budget",
8080
"implementation": ["research-and-design.md", "../boatstack/references/workflow.md"],
8181
"verification": ["../boatstack/export_test.go", "../boatstack/planning_test.go"],
82-
"last_verified_version": "source:c5f3e330d6167247446e1915deaf1bc593cf2e0d"
82+
"last_verified_version": "source:5227e7828d9bcac8c6b11c19289c2b4ef5be92a2"
8383
},
8484
{
8585
"id": "cross-model-failures",
@@ -90,7 +90,7 @@
9090
"readable_evidence": "why-these-steps.md#model-choice-and-budget",
9191
"implementation": ["research-and-design.md"],
9292
"verification": ["benchmark-corpus-audit.md", "benchmark-submission-audit.md"],
93-
"last_verified_version": "source:c5f3e330d6167247446e1915deaf1bc593cf2e0d"
93+
"last_verified_version": "source:5227e7828d9bcac8c6b11c19289c2b4ef5be92a2"
9494
},
9595
{
9696
"id": "lower-cost-outcomes",
@@ -101,7 +101,7 @@
101101
"readable_evidence": "why-these-steps.md#model-choice-and-budget",
102102
"implementation": ["research-and-design.md"],
103103
"verification": ["benchmark-corpus-audit.md", "benchmark-submission-audit.md"],
104-
"last_verified_version": "source:c5f3e330d6167247446e1915deaf1bc593cf2e0d"
104+
"last_verified_version": "source:5227e7828d9bcac8c6b11c19289c2b4ef5be92a2"
105105
},
106106
{
107107
"id": "git-worktree-activation",
@@ -112,7 +112,7 @@
112112
"readable_evidence": "why-these-steps.md#git-worktree-activation",
113113
"implementation": ["../boatstack/runtime_cache.go", "../boatstack/hooks.go"],
114114
"verification": ["../boatstack/runtime_cache_test.go", "../boatstack/hooks_test.go"],
115-
"last_verified_version": "source:c5f3e330d6167247446e1915deaf1bc593cf2e0d"
115+
"last_verified_version": "source:5227e7828d9bcac8c6b11c19289c2b4ef5be92a2"
116116
},
117117
{
118118
"id": "visible-updates",
@@ -123,7 +123,7 @@
123123
"readable_evidence": "why-these-steps.md#visible-updates",
124124
"implementation": ["../boatstack/update.go", "../boatstack/init.go"],
125125
"verification": ["../boatstack/update_test.go", "../boatstack/init_test.go", "../boatstack/export_test.go"],
126-
"last_verified_version": "source:c5f3e330d6167247446e1915deaf1bc593cf2e0d"
126+
"last_verified_version": "source:5227e7828d9bcac8c6b11c19289c2b4ef5be92a2"
127127
}
128128
]
129129
}

labs/diagram-json/plan.lock.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@
66
"plan_path": "labs/diagram-json/plan.md",
77
"plan_sha256": "3cc4f533b8d69386deff16b3a594a3ba09d4c0c3db636cccd8c4380084ce6a51",
88
"schema_version": 1,
9-
"source_commit": "c5f3e330d6167247446e1915deaf1bc593cf2e0d",
9+
"source_commit": "5227e7828d9bcac8c6b11c19289c2b4ef5be92a2",
1010
"source_plan_path": "labs/diagram-json/source-plan.md",
1111
"source_plan_sha256": "e10593ddaa7522ab80cc991d0a09399257139799e37f737794cd49d68a39985b",
1212
"spec_path": "labs/diagram-json/spec.md",
Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
### Publication authority honors ignored deliveries
2+
3+
Publication-authority resolution now excludes `workflow.ignored_deliveries` when deciding whether a push or PR mutation is ambiguous, matching the behavior `next` and `run` already had. Previously a stale-but-active ignored delivery — for example an approved plan lock whose code shipped out of band, leaving zero delivery progress — still counted toward ambiguity and denied every unrelated push with `relation=ambiguous`, even though the slug was explicitly listed as ignored.
4+
5+
The safety interlock is unchanged for genuinely ambiguous work: a new, un-ignored active delivery that does not match the current branch still blocks publication. A configuration that fails to load leaves the delivery set unfiltered, preserving the prior conservative behavior.

0 commit comments

Comments
 (0)