Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 10 additions & 0 deletions contracts/approval/v1/CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,15 @@
# approval/v1

## v1.2.0 — 2026-08-21

* `correlation_id` (optional) — ผูกใบอนุมัติเข้ากับสายงานเดียวกันข้าม service ([ADR-0019](../../../decisions/0019-execution-records-its-approval.md))

contract อื่นเกือบทั้งหมดมี field นี้ (`event/v1` · `identity/v1` `RequestContext` ที่ `execution/v1` ใช้ผ่าน `context`) แต่ไฟล์นี้ไม่มี — `execution_id` กับ `subject` ทำแทนไม่ได้ เพราะการอนุมัติหนึ่งครั้งอาจเกิดก่อน execution ถูกสร้าง หรือครอบหลาย execution ในสายเดียวกัน

เป็น **field ระดับ platform** ตาม [ADR-0006 กฎข้อ 1](../../../decisions/0006-contract-versioning.md) — เพิ่มได้เองโดยไม่ต้องมี RFC ที่ `devfactory-core`

**`guarantees` ไม่ขยับ** (ยัง 4 ข้อ) · `derived_from.semantics_version` ยัง `"1.1"` · optional · `required` ยัง 7 ตัวเท่าเดิม

## v1.1.0 — 2026-08-19

ไม่ breaking — เพิ่ม optional field อย่างเดียว ([ADR-0006](../../../decisions/0006-contract-versioning.md) · [ADR-0013](../../../decisions/0013-approval-supersedes-chain.md))
Expand Down
11 changes: 11 additions & 0 deletions contracts/approval/v1/approval.schema.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -100,6 +100,17 @@ properties:
งานที่ค้างรออนุมัติจนเลยกำหนดควรเข้าสถานะ timeout ไม่ใช่รอตลอดไป
escalation_target:
$ref: https://schemas.agent-platform.internal/identity/v1/identity.schema.yaml#/$defs/Principal
correlation_id:
$ref: https://schemas.agent-platform.internal/identity/v1/identity.schema.yaml#/$defs/Id
description: >-
ผูกใบอนุมัติเข้ากับสายงานเดียวกันข้าม service — ค่าเดียวกับที่ `event/v1` และ
`identity/v1` `RequestContext` ใช้ ([ADR-0019](../../../decisions/0019-execution-records-its-approval.md))

`execution_id` กับ `subject` ทำแทนไม่ได้ เพราะการอนุมัติหนึ่งครั้งอาจเกิดก่อน
execution ถูกสร้าง หรือครอบหลาย execution ในสายเดียวกัน

เป็น field ระดับ platform ตาม [ADR-0006 กฎข้อ 1](../../../decisions/0006-contract-versioning.md)
— เพิ่มได้เองโดยไม่ต้องมี RFC ที่ repo ต้นทาง · `guarantees` ไม่ขยับ

supersedes_approval_id:
$ref: https://schemas.agent-platform.internal/identity/v1/identity.schema.yaml#/$defs/Id
Expand Down
26 changes: 26 additions & 0 deletions contracts/execution/v1/CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,31 @@
# execution/v1

## v1.1.0 — 2026-08-21

`approval/v1` `guarantees` ข้อ 3 (🔒 frozen) เขียนว่า *"execution ที่ไม่มี APPROVE เป็นสิ่งที่ห้าม"* แต่ `execution/v1` มี `policy_decision` เต็มใบ (จึงรู้ว่า **ต้องขออนุมัติไหม**) และไม่มี field ไหนชี้ไปยังใบอนุมัติได้เลย — [ADR-0019](../../../decisions/0019-execution-records-its-approval.md) option A

* `approval_id` (optional) — ใบอนุมัติที่อนุญาตให้ execution นี้เดินต่อ

### ทำไมเก็บ id ก็พอ ทั้งที่ ADR-0016 บอกว่าไม่พอ

`approval/v1` `guarantees` ข้อ 1 บอกว่า decision เป็น **immutable** — ใบที่อ่านปีหน้าให้คำตอบเดียวกับที่อ่านวันนี้เสมอ · ต่างจาก `consent/v1` ที่ใบมี `conditions` ซึ่งเปลี่ยนคำตอบได้ จึงต้องแช่แข็ง **ผลการประเมิน** ไว้

> เกณฑ์คือ **สิ่งที่ชี้ไปเปลี่ยนได้ไหม** ไม่ใช่กฎเหมารวมว่าห้ามเก็บ id

### ⚠️ ไม่มีค่านี้ไม่ได้แปลว่าผิดเสมอ

execution ที่จบที่ `rejected` · `cancelled` · `timed_out` **ไม่มี APPROVE ให้ชี้ตามนิยาม** — ถูกปฏิเสธหรือยกเลิกก่อนมีใครอนุมัติ

จึงไม่ใส่ `if/then` บังคับตาม `authority` แม้จะเขียนได้ เพราะจะแดงกับเส้นทางที่ถูกต้อง — **สัญญาณลวงอันตรายพอ ๆ กับการตรวจไม่เจอ**

### invariant ที่ผู้ผลิตต้องบังคับเอง

ใบที่อ้างต้องมีอยู่จริง · `tenant_id` เดียวกัน · `subject` ตรงกับ execution นี้ · `decision` ต้องเป็น `APPROVE` (`REJECT`/`REQUIRE_CHANGES` อ้างไม่ได้) · ต้องมีก่อนออกจาก `awaiting_approval` ไปสู่ `running`

### ไม่ breaking

optional · `required` ยัง 5 ตัวเท่าเดิม · payload ที่ valid กับ `v1.0.0` ยัง valid ทุกใบ

## v1.0.0 — 2026-08-17
- ตั้งต้นตาม [ADR-0005](../../../decisions/0005-agent-runtime-boundary.md) option C2
- state machine ระดับ execution เป็นของ platform เอง — RFC-0001 ครอบแค่ระดับ job
Expand Down
27 changes: 27 additions & 0 deletions contracts/execution/v1/execution.schema.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -54,6 +54,33 @@ properties:
$ref: https://schemas.agent-platform.internal/capability/v1/requirement.schema.yaml
policy_decision:
$ref: https://schemas.agent-platform.internal/policy/v1/policy-decision.schema.yaml#/Decision
approval_id:
$ref: https://schemas.agent-platform.internal/identity/v1/identity.schema.yaml#/$defs/Id
description: >-
**ใบอนุมัติที่อนุญาตให้ execution นี้เดินต่อ**
([ADR-0019](../../../decisions/0019-execution-records-its-approval.md))

มีอยู่เพราะ `approval/v1` `guarantees` ข้อ 3 (🔒 frozen) เขียนว่า
*"execution ที่ไม่มี APPROVE เป็นสิ่งที่ห้าม"* แต่เดิมไม่มีที่ให้บันทึกว่าใบไหน
— `policy_decision` บอกได้แค่ว่า *ต้องขออนุมัติไหม* ไม่ได้บอกว่า *มีใครอนุมัติแล้วหรือยัง*

เก็บเป็น **id ก็พอ** เพราะใบอนุมัติเป็น immutable ตาม `approval/v1` `guarantees` ข้อ 1
— อ่านปีหน้าได้คำตอบเดียวกับวันนี้เสมอ · ต่างจาก `consent/v1` ที่ต้องแช่แข็ง
**ผลการประเมิน** ไว้ ([ADR-0016](../../../decisions/0016-recording-which-consent-allowed-access.md))
เพราะใบยินยอมที่มีเงื่อนไขเปลี่ยนคำตอบได้ · เกณฑ์คือ **สิ่งที่ชี้ไปเปลี่ยนได้ไหม**

🔒 invariant ที่ JSON Schema ตรวจให้ไม่ได้ — ผู้ผลิตต้องบังคับเอง:

· ใบที่อ้างต้องมีอยู่จริง · `tenant_id` เดียวกัน · `subject` ตรงกับ execution นี้

· `decision` ของใบนั้นต้องเป็น `APPROVE` — ใบที่ `REJECT` หรือ `REQUIRE_CHANGES` อ้างไม่ได้

· ต้องมีก่อนออกจาก `awaiting_approval` ไปสู่ `running`

⚠️ **ไม่มีค่านี้เมื่อจบที่ `rejected` · `cancelled` · `timed_out` = ถูกต้อง ไม่ใช่ข้อมูลขาด**
— execution ที่ถูกปฏิเสธหรือยกเลิกก่อนมีใครอนุมัติไม่มี APPROVE ให้ชี้ตามนิยาม
ถ้า implementation ตีความว่าไม่มีค่านี้ = ผิดเสมอ จะเกิดสัญญาณลวง
ซึ่งอันตรายพอ ๆ กับการตรวจไม่เจอ
observability_depth:
enum: [step, turn]
description: >-
Expand Down
Loading
Loading