docs(decisions): ADR 0245 — campaign-scope refusal binds at both fabrika seams - #5081
Conversation
…ika seams (#5011) Records the founder ruling on #5011: the refusal binds at build pick AND build claim from one shared predicate (the pick filter alone has the direct-handoff hole), fabrika-only under ADR 0238, overridable explicitly and on the record, with the interim social-enforcement gap stated. Fixes #5011 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
No preview deploy
|
|
review-doc: advisory — blocking-set PR (§CP — approval-gated) PR #5081 is §CP by content, not by path. Reviewed-head: @ 6f729f7 Verified against #5011's acceptance criteria + doc hygiene. All checks pass — substantively merge-ready, pending the control-plane approval and the CI note below. Acceptance criteria (#5011)
Doc hygiene
ADR contradiction sweep (Step 4a)
Deviation disclosure (§DEV)
ADR numbering
Two things for the merge actor, neither a gate failure:
Minor, no action: the ADR's "milestone ... never as a filter" is precise about the candidate-pool script (verified) but slightly overshoots for the v1 write-code skill, whose explicit Verdict-written: 2026-08-09T07:23:07Z |
|
review-doc: advisory — blocking-set PR (§CP — approval-gated) Re-gate at a moved head. Bookkeeping, not a re-review of authored content. This PR already carried a full Reviewed-head: @ d74e661 §CP classification — re-run on both axes at this head. Path axis: Namespace set — re-derived, not assumed. The merge dragged in nothing. The head is a merge commit, parents
Acceptance criteria (#5011) — re-bound, all six PASS. The issue body's checklist is unchanged (six criteria, no reviewer-appended row since the prior gate), and the ADR content is byte-identical, so every prior-round verdict transfers unaltered:
Doc hygiene — re-checked at this head.
ADR numbering still unique. Max merged ADR on fresh The doc-links check is now GREEN — the sole prior blocker is cleared. Full check set at this head, read after it settled: 0 failures, 0 cancellations, 0 timeouts. All 36 completed checks are Trap re-checked specifically: Not re-raised (already filed): the naive-scope-predicate gap the prior round surfaced — a scope predicate keyed on milestone presence would refuse all standing-lane work, since ADR 0208 leaves Verdict: substantively merge-ready, advisory only. Nothing authored changed; every criterion and hygiene check re-binds to |
When we say "one campaign at a time, everything else off the table," that rule needs somewhere real to live. This ADR records where: the fabrika
buildpicker must not offer off-campaign work, andbuild claimmust refuse an off-campaign issue even when someone hands it the number directly — both reading one shared predicate so they can never disagree. It also says plainly that nothing enforces this yet, and that the gap is covered by people paying attention until the two build issues land.Adds one file:
.decisions/0245-campaign-scope-fence-binds-both-seams.md. Nothing else changes — no code, no pipeline behavior.Fixes #5011
This is the record that discharges #5011's acceptance criteria, not a formality. The founder ruled the decision on the issue but asked that it not be closed on the ruling alone: the criteria demand a written record with citations read from source. This ADR is that record — it cites the exact four selection facts the v1 candidate-pool script uses (and states that milestone, dependency topology and
ready-for:are not among them), says which seam carries the refusal and why neither is redundant, states the fabrika-only side under ADR 0238 with the interim exposure named, and keeps dependency eligibility as a separate predicate.Four issues build against this rule and reference it: see #5012, #5013, #5015 and #5016.
ADR number: merged max on
mainis 0244, and.decisions/0245-*is unique onmainat the time of this push, so 0245 does not collide.Deviations
Procedure — the catch-up was a cherry-pick, not
git rebase. Said: rebase the branch onto latestmain. Did: created a fresh branch at latestmainand cherry-picked the single ADR commit onto it, then updated the branch ref. Why: the branch was already checked out in another worktree, so it could not be checked out again here; for a one-commit branch the two produce the same tree and the same parentage. Disposition: no action needed — the resulting head is one commit ahead of latestmainwith no conflicts, and the file content is byte-identical to the authored commit.Procedure — the push named an explicit refspec instead of the usual push verb. Said: push with the lease guard. Did: pushed this worktree's head to the branch ref with
--force-with-leasepinned to the branch's previous commit, then confirmed the moved ref independently with a remote ref read. Why: the standard push verb pushes the branch checked out in the worktree under its own name, which could not be used here for the reason above. Disposition: no action needed — the remote ref was verified at the new head after the push, which is the property the verb exists to establish.Content — the ADR itself was authored elsewhere and is unmodified here. Said: get the authored ADR onto a PR. Did: exactly that; no edit was made to the ADR text. Why: the file was already written and pushed, and re-authoring it was explicitly out of scope. Disposition: for the reviewer to judge the content on its own terms.