Skip to content

docs: refresh reconciliation product gap baseline - #37

Draft
seonghobae wants to merge 28 commits into
developfrom
docs/product-gap-baseline-current
Draft

docs: refresh reconciliation product gap baseline#37
seonghobae wants to merge 28 commits into
developfrom
docs/product-gap-baseline-current

Conversation

@seonghobae

@seonghobae seonghobae commented Aug 28, 2026

Copy link
Copy Markdown
Contributor

Summary

Canonical Accounting Information Platform repository-facing documentation lane. It owns docs/product-technical-gap-baseline.md, its regression contract, the product-first README, shared CHANGELOG.md, docs/doctoring/STANDARD_TRACEABILITY.md, and the bounded public docs/index.md. Runtime/database authority remains in source owner PRs; this lane must not copy mutable child implementation bytes ahead of integration.

Exact current state — 2026-09-09

  • exact docs head: bdf076466b1cde0e7ae6247f44309fac153ae4c4;
  • protected integration: develop@239008c4edc7d305c97704c5102b593c6622b36f;
  • documentation-only / Draft / mergeable / not merge-ready;
  • lifecycle feat(reconciliation): add evidence-derived run lifecycle command #43 is merged history inside root fix: allow conserved multi-match reconciliation approvals #29;
  • current reconciliation/Period Close dependency stack is #29@12e1a4bb9d8de5e4b6c72e2893107b07c515416b -> #47@263e4ffb79607dccee715686d0aa451981c2eeb8 -> #53;
  • feat(reconciliation): add maker-checker exception resolution command #47 is Ready after stale-session-lease continuity repair passed exact-head Foundation 34237450022: 1,315 real-PostgreSQL tests, 6,211/6,211 statements, 2,330/2,330 branches, repository contracts, package/evidence, Security, SAST and dependency diff GREEN. Its P1 thread is resolved from hosted evidence, but no qualifying independent APPROVED review exists; fix(close): freeze hard-close trial balance evidence #53 remains dependency-blocked until normal feat(reconciliation): add maker-checker exception resolution command #47 integration;
  • Period Close fix(close): freeze hard-close trial balance evidence #53 is exact 9c3dba6f12aa58062faa6ba11537aabef91486d8, Draft/mergeable=false, still stored on the historical feat/reconciliation-exception-resolution-command@6f81b258... parent. The live prerequisite is feat(reconciliation): add maker-checker exception resolution command #47, not the stored parent. Its checked-in real-PostgreSQL RED proves that the closing-journal command/evidence hash can provenance-alias distinct historical Account entities after account-code reuse because _canonical_closing_hash() omits the exact historical chart_account_id even though the journal line and retained snapshot bind that Entity. The narrow Period Close repair remains mutable and must not be copied here before protected integration;
  • DDD architecture arch: establish accounting DDD context map and fitness gate #41 is exact 3bdbeec6cc35e5b111739499c562f988f5fcaa18, Ready/mergeable after exact-head Accounting Foundation 34239818457 GREEN. Accounting 102106807702 passed behavior/repository, complete owned statement/branch coverage, strict denominator, repository contracts, compile/import and reproducible package/evidence; Security 102106807452, SAST 102106807652 and dependency diff 102106807711 are GREEN. Integrated-head attestations remain skipped while stacked; no qualifying independent APPROVED review exists;
  • Reporting source-authority feat: bind financial report sources to AIS persistence #52 is exact 5a26eba357d09a0e65933da1e5ced99197130ecf, Draft. Accounting Foundation 34271427012 is terminal RED only on the two retained-snapshot mutation cases. Accounting 102213693861 ran 520 tests with 2 failures / 0 errors; dependency diff 102213694040, SAST 102213694259, and Security 102213694269 are GREEN. The Reporting-local raw lifecycle defect is repaired: direct SQL cannot move a report run out of collecting_sources and now fails with financial_report_run_lifecycle_immutable; this slice does not invent supersession/publication authority. The remaining two REDs are a Period Close fix(close): freeze hard-close trial balance evidence #53 dependency, not permission for Reporting to create a second retained-snapshot immutability authority.

Commercial/product baseline

The baseline records Accounting Record & Close bounded-context relationships, normalized reconciliation ERD/lifecycle, immutable maker-checker exception-resolution requirements, FORCE-RLS migration rules, realistic PostgreSQL upgrade acceptance, database naming/3NF/lock/replay rules, buyer close/reconciliation stories, evidence-bound CSAP/SOC 2 readiness targets without certification claims, and explicit ecosystem ownership boundaries.

The retained authority-event invariant remains: lifecycle-completion and exception-resolution commands preserve exactly one matching outbox event after commit; deletion/re-key, duplicate exact insertion, manufacturing the authority identity from an unrelated event, or rewriting retained event identity/creation time fails closed, while published_at remains publication metadata.

The lifecycle-lease continuity invariant is verified on mutable #47 but remains a prerequisite for this lane's later protected-tree rebuild rather than being copied from branch bytes. Once protected integration exists, the baseline must state that successful authority-relevant reconciliation mutation invalidates older tenant/run lifecycle leases and that a stale repeatable-read transaction cannot promote a snapshot-visible invalidated lease into close authority.

ADR 0059/Context Map remains an owner-path prerequisite rather than copied content. #41's fitness ratchet rejects ownership rows for absent paths and its Context Map no longer advertises deleted reconciliation_completion.py. The still-valid shared-record finding belongs here: after #41 reaches protected integration, this lane must non-destructively rebuild on that exact tree and record ADR 0059/Context Map/UL provenance, including the no-stale-owner-row and one-most-specific-primary-owner constraints, in shared CHANGELOG/TRACEABILITY before #37 itself can merge.

Period Close and Reporting have a separate protected-tree handoff. #53 owns retained trial_balance_snapshot / trial_balance_line immutability, one-population identity, scope/currency/conservation, chronology, concurrency and historical Account-entity provenance. After #53 reaches protected lineage, the durable baseline must record that effective-dated account-code reuse cannot make distinct historical Account entities identical in retained snapshot or closing-command/journal evidence. #52 may bind a report run to that retained AIS evidence and owns its own report-run lifecycle guard, but it may not synthesize close control or a narrower report-only snapshot authority. The baseline must not describe a report-local financial_report_source_population_frozen trigger as canonical. After #52 is non-force rebuilt/renumbered on protected #53 authority, this lane must record the integrated consumer contract and exact migration/API/test evidence; until then the two #52 mutation REDs and #53 closing-evidence RED stay live PR evidence rather than product truth.

Current docs evidence

This docs lane's exact head bdf0764... previously passed focused documentation contracts and Accounting Foundation 34066240615 / Accounting 101575389275: behavior/repository suite, exact 100% coverage over 4,981 statements and 1,796 branches, repository validation, compile/import and reproducible package; same-run dependency diff, SAST and security also passed. Required central CodeQL/review evidence remains independent, so this Draft is not merge-ready.

Rebuild / merge boundary

After #29 -> #47 -> #53 integrates normally into protected develop, after #41's architecture decision reaches protected integration, and after downstream #52 is rebuilt on the protected Period Close authority rather than its current provisional migration identity, non-destructively rebuild this lane on the resulting exact protected tree and reacquire repository validation, product-gap/data-model/foundation-install documentation contracts, applicable repository/organization workflows, current reviews/threads and exact ancestry on one unchanged head.

That rebuild must update docs/product-technical-gap-baseline.md to exact integrated migration/API/test evidence, including the surviving reconciliation chain and #53/#52 eventual renumbering, adopt protected lifecycle-lease continuity evidence, adopt protected ADR 0059/Context Map truth into shared CHANGELOG.md and docs/doctoring/STANDARD_TRACEABILITY.md, record the historical Account-entity provenance invariant from protected #53, and record Reporting as a consumer of Period Close-retained snapshot immutability rather than a competing source of that truth.

Do not absorb mutable #47 branch-local source/test/doctoring repair or mutable #41/#53/#52 implementation into this baseline ahead of integration. PR #49 separately owns repository CI admission for documentation/Markdown changes. Do not treat skipped documentation CI as passing evidence. Do not merge, auto-merge, tag, version or release this sibling ahead of the dependency stack.

@coderabbitai

coderabbitai Bot commented Aug 28, 2026

Copy link
Copy Markdown

Review Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

상용화 기준선을 2026-09-02 증거 상태로 갱신했다. 조정 기능, 도메인 모델, 구매자 흐름, 보안·운영 기준, 갭 큐 및 릴리스 규칙을 재정의했다. 관련 문서와 기준선 계약 검사도 갱신했다.

Changes

상용화 기준선 및 도메인 모델

Layer / File(s) Summary
기준선 및 상용 역량 정의
docs/product-technical-gap-baseline.md
제품 책임, 구매자 결과, 현재 상용 역량, PRD 기준 및 TRD 기준을 갱신했다. 결산 projection과 completion을 현재 통합 후보로 구분했다.
도메인 및 회계 모델
docs/product-technical-gap-baseline.md
DDD 기준, 바운디드 컨텍스트, 유비쿼터스 언어, 애그리거트 소유권, ERD 및 조정 수명주기를 추가했다. 예외 resolution 명령과 run transition 명령을 분리했다.
구매자 흐름 및 운영 기준
docs/product-technical-gap-baseline.md
구매자 사용자 스토리, reconciliation runs 화면 계약, Storybook 목록, 보안·테스트·운영성 기준 및 저장소 경계를 추가했다.
갭 큐 및 릴리스 규칙
docs/product-technical-gap-baseline.md
P0/P1 갭, 권한 매핑, 연구·표준 추적성 및 정확한 통합 head 기반 릴리스 규칙을 갱신했다.

문서 사실 및 기준선 계약

Layer / File(s) Summary
저장소 사실 및 계약 검사
README.md, docs/index.md, docs/doctoring/REFERENCES.md, docs/doctoring/STANDARD_TRACEABILITY.md, CHANGELOG.md, tests/test_product_gap_baseline_contract.py
README와 문서 색인을 재작성했다. PostgreSQL 18.6 참고 문헌과 18.x 정책을 갱신했다. 변경 로그의 미공개 태그 표현을 수정했다. 문서 간 사실, 브랜치 정책, 권한 매핑, 릴리스 상태 및 조정 기능 설명을 검사하는 계약 테스트를 추가·수정했다.

Estimated code review effort: 3 (Moderate) | ~25 minutes

Merge Risk: 🔵 Low · up to 644c6

The documentation update is mergeable with owner awareness because its contract test may still miss a mutable develop status claim, allowing documentation to drift without detection. This is a bounded documentation-integrity risk and does not affect runtime behavior or security.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 7 functions across 1 files. (2 skipped: 2 …
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed 제목은 제품 및 기술 갭 기준선과 조정 관련 문서의 갱신이라는 주요 변경 사항을 정확히 요약합니다.
✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch docs/product-gap-baseline-current

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

devin-ai-integration[bot]

This comment was marked as resolved.

devin-ai-integration[bot]

This comment was marked as resolved.

@seonghobae

Copy link
Copy Markdown
Contributor Author

@OpenCode review

devin-ai-integration[bot]

This comment was marked as resolved.

devin-ai-integration[bot]

This comment was marked as resolved.

@seonghobae

Copy link
Copy Markdown
Contributor Author

@opencode-agent

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode reviewed the current-head product diff. Coverage is a separate gate.

Changed files

  • README.md — repository behavior
  • docs/doctoring/REFERENCES.md — operator or user guidance
  • docs/doctoring/STANDARD_TRACEABILITY.md — operator or user guidance
  • docs/product-technical-gap-baseline.md — operator or user guidance
  • tests/test_product_gap_baseline_contract.py — regression suite

Changed behavior

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Repository file: README.md"]
  S1 --> I1["repository behavior"]
  I1 --> R1["Review risk: Repository file: README.md"]
  R1 --> V1["required checks"]
  Evidence --> S2["Docs: REFERENCES.md (3 files)"]
  S2 --> I2["operator or user guidance"]
  I2 --> R2["Review risk: Docs: REFERENCES.md (3 files)"]
  R2 --> V2["docs review"]
  Evidence --> S3["Test: test_product_gap_baseline_contract.py"]
  S3 --> I3["regression suite"]
  I3 --> R3["Review risk: Test: test_product_gap_baseline_contract.py"]
  R3 --> V3["targeted test run"]
Loading

Findings

No source-backed product finding is synthesized from the coverage gate. A coverage miss belongs in the status comment.

  • Head SHA: 3ce82bfaf6b6b81b40de23aa143928a835a3b1dd
  • Workflow run: 33219471093
  • Workflow attempt: 1
  • Coverage gate: failure

Review outcome

Coverage is a gate, not the review. This body reviews the changed product files.

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Repository file: README.md"]
  S1 --> I1["repository behavior"]
  I1 --> R1["Review risk: Repository file: README.md"]
  R1 --> V1["required checks"]
  Evidence --> S2["Docs: REFERENCES.md (3 files)"]
  S2 --> I2["operator or user guidance"]
  I2 --> R2["Review risk: Docs: REFERENCES.md (3 files)"]
  R2 --> V2["docs review"]
  Evidence --> S3["Test: test_product_gap_baseline_contract.py"]
  S3 --> I3["regression suite"]
  I3 --> R3["Review risk: Test: test_product_gap_baseline_contract.py"]
  R3 --> V3["targeted test run"]
Loading

@opencode-agent

opencode-agent Bot commented Aug 28, 2026

Copy link
Copy Markdown

OpenCode Review Overview

Coverage evidence did not pass, so approval is blocked. The formal pull-request review is the source-backed diff review, not this status comment.

@seonghobae

Copy link
Copy Markdown
Contributor Author

Current-head documentation synchronization:\n\n- Head: f8c0394\n- Base: develop@81a2920b0ae9b054fcdcc95902341e3a5bc809c5\n- Added README contract coverage first; the test was RED until the README listed the integrated camt.053.001.14 evidence registry, deterministic reconciliation proposal/bridge, and durable run/exception/evidence foundation.\n- Kept the remaining gap explicit: full cross-run many-to-many allocation, reconciliation approval, and close-package provenance are not claimed as complete.\n- Local verification: 463 tests passed against PostgreSQL 18.6, repository validator passed, compileall passed, changed-file Ruff passed, and git diff --check passed.\n- The default local port was also checked and is not a PostgreSQL 18 runtime (uuidv7() unavailable); that environment failure is not used as passing evidence.\n\nHosted checks are being re-run for this exact head. No merge or bypass was performed.

devin-ai-integration[bot]

This comment was marked as resolved.

@seonghobae

Copy link
Copy Markdown
Contributor Author

Current-head follow-up after governance mutation:\n\n- Head: 916f326\n- Base: develop@81a2920b0ae9b054fcdcc95902341e3a5bc809c5\n- Updated the durable gap baseline to record active organization ruleset 21783807: AIP main now requires the seven central workflows plus repository-owned Accounting Foundation CI; the remaining gap is fresh release evidence, not missing protection.\n- Focused documentation contract tests: 4 passed; repository validator, compileall, changed-file Ruff, and diff-check passed.\n\nAll hosted checks and independent review are pending for this exact head. No merge or bypass was performed.

@seonghobae

Copy link
Copy Markdown
Contributor Author

Reviewed the current-head informational note on : the README and baseline intentionally keep full cross-run allocation, reconciliation approval, and close-package provenance open. No source change is required; the bounded foundation claim is accurate.

@seonghobae

Copy link
Copy Markdown
Contributor Author

Reviewed the current-head informational note on commit 916f326: the README and baseline intentionally keep full cross-run allocation, reconciliation approval, and close-package provenance open. No source change is required; the bounded foundation claim is accurate.

@seonghobae

Copy link
Copy Markdown
Contributor Author

Final current-head evidence for this documentation update:\n\n- Head: 916f326\n- Base: develop@81a2920b0ae9b054fcdcc95902341e3a5bc809c5\n- Accounting Foundation CI, CodeQL, Security Scan, SAST Semgrep, Strix, Noema, scheduler, and close-empty checks passed for this head.\n- Required OpenCode Review failed only at its fail-closed current-head verdict check; the current review list has no OpenCode review for this head. This is a hosted verdict/provider gate failure, not a source-test failure.\n- Review threads: 0 unresolved. Review decision: REVIEW_REQUIRED; no qualifying independent approval is present.\n\nNo further source change, merge, bypass, or release action is justified from this evidence.

@seonghobae

Copy link
Copy Markdown
Contributor Author

Current-head scheduler follow-up (2026-08-29):

  • Head: 916f326ce8605985a506d900fb70ed3850d3b4a9
  • Rerun: Required PR Review Merge Scheduler run 33233598930, attempt 2
  • Result: WAIT; Strix evidence was complete, but the target-repository runner token cannot create a cross-repository repository_dispatch to ContextualWisdomLab/.github.
  • This is fail-closed credential-boundary behavior, not a source finding. The central organization sweep remains the authorized dispatch path.

No merge or bypass was performed; fresh current-head OpenCode approval and independent approval remain required.

@opencode-agent opencode-agent Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

OpenCode reviewed the current-head product diff. Coverage is a separate gate.

Changed files

  • README.md — repository behavior
  • docs/doctoring/REFERENCES.md — operator or user guidance
  • docs/doctoring/STANDARD_TRACEABILITY.md — operator or user guidance
  • docs/product-technical-gap-baseline.md — operator or user guidance
  • tests/test_product_gap_baseline_contract.py — regression suite

Changed behavior

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Repository file: README.md"]
  S1 --> I1["repository behavior"]
  I1 --> R1["Review risk: Repository file: README.md"]
  R1 --> V1["required checks"]
  Evidence --> S2["Docs: REFERENCES.md (3 files)"]
  S2 --> I2["operator or user guidance"]
  I2 --> R2["Review risk: Docs: REFERENCES.md (3 files)"]
  R2 --> V2["docs review"]
  Evidence --> S3["Test: test_product_gap_baseline_contract.py"]
  S3 --> I3["regression suite"]
  I3 --> R3["Review risk: Test: test_product_gap_baseline_contract.py"]
  R3 --> V3["targeted test run"]
Loading

Findings

No source-backed product finding is synthesized from the coverage gate. A coverage miss belongs in the status comment.

  • Head SHA: 916f326ce8605985a506d900fb70ed3850d3b4a9
  • Workflow run: 33246598124
  • Workflow attempt: 1
  • Coverage gate: failure

Review outcome

Coverage is a gate, not the review. This body reviews the changed product files.

Changed-File Evidence Map

flowchart LR
  PR["PR changed files"] --> Evidence["OpenCode bounded evidence"]
  Evidence --> S1["Repository file: README.md"]
  S1 --> I1["repository behavior"]
  I1 --> R1["Review risk: Repository file: README.md"]
  R1 --> V1["required checks"]
  Evidence --> S2["Docs: REFERENCES.md (3 files)"]
  S2 --> I2["operator or user guidance"]
  I2 --> R2["Review risk: Docs: REFERENCES.md (3 files)"]
  R2 --> V2["docs review"]
  Evidence --> S3["Test: test_product_gap_baseline_contract.py"]
  S3 --> I3["regression suite"]
  I3 --> R3["Review risk: Test: test_product_gap_baseline_contract.py"]
  R3 --> V3["targeted test run"]
Loading

@seonghobae seonghobae left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Current-head documentation integrity finding on 916f326ce8605985a506d900fb70ed3850d3b4a9: CHANGELOG.md still labels 0.1.0 as the “First tagged release,” but the repository currently has no GitHub release and neither refs/tags/0.1.0 nor refs/tags/v0.1.0 exists. That is a release-state claim without repository evidence and conflicts with the fail-closed release policy.

Please make the narrow docs correction on this existing documentation branch: describe 0.1.0 as a dated development/version baseline (or otherwise non-release baseline) unless and until an actual protected-head release/tag is created after all release gates pass together. Do not create a tag or release merely to make the sentence true. Keep CHANGELOG/README/release-readiness wording consistent and avoid certification/compliance language that is not backed by evidence. After the wording change, rerun the exact-head documentation/repository contracts and all applicable protected checks; predecessor status does not transfer.

@seonghobae

Copy link
Copy Markdown
Contributor Author

Current-head documentation repair on 3a0f2a72d72dc27d0848eacdfdbc9c5843d2ac22: the [0.1.0] history no longer claims a first tagged release; it explicitly records an unpublished foundation milestone because no GitHub Release or 0.1.0 tag exists. Added a regression contract for this boundary. Local successor validation: 464 tests passed; 4,981/4,981 statements and 1,796/1,796 branches; repository contracts, compileall, diff-check, and changed-test Ruff passed. Full PR Checks are now running on this exact head; no predecessor evidence is transferred.

Copy link
Copy Markdown
Contributor Author

DDD governance handoff from #41. Devin review on #41 verified that ADR 0059 materially changes accounting authority boundaries and therefore needs the repository-required CHANGELOG.md and docs/doctoring/STANDARD_TRACEABILITY.md update before protected integration. Those exact files are already owned by this canonical documentation lane, so #41 is intentionally not creating a competing writer. When the accounting dependency stack and #41 are integrated, rebuild #37 non-destructively on that exact protected tree and add ADR 0059 / Context Map / Ubiquitous Language traceability here, preserving #41's Proposed status until that integration evidence exists. Do not copy a mutable #41 head as authoritative history.

Copy link
Copy Markdown
Contributor Author

Canonical gap-baseline / shared-doc handoff from Reporting-Export #50 (no competing docs write here): #50 moved to exact 57360b6881fa892fd61415b322a96cd0cb7b64ba after a TDD repair to the report/XBRL URI boundary. RED proved a non-numeric HTTP(S) authority port such as https://example.com:accounting/taxonomy.xsd passed the old shared _absolute_uri() check; GREEN c38e0f21fafa8880ab7856a3a712d714a771450c forces standard-library parsed-port validation while preserving the non-authoritative report/XBRL proposal boundary. PR-owned docs/doctoring/XBRL_STANDARD_TRACEABILITY.md and docs/testing/FINANCIAL_REPORTING_TEST_MATRIX.md are code-current at #50 head; #50 was returned to Draft until exact-head gates complete.

For the canonical docs/product-technical-gap-baseline.md / shared CHANGELOG trace when #37 next rebuilds against the integrated protected lineage: record this as a Reporting-Export input-validation/security gap, not accounting-authority expansion. Also carry the current IFRS primary-source status: IFRS Accounting Taxonomy 2025 remains the released current taxonomy for 2026 reporting; 2026 proposed taxonomy updates are consultation state and cannot be selected as filing authority. Issue #51 owns the released-profile registry/validation/publication successor. Do not import #50's mutable head as a production dependency; rebuild from protected/integrated evidence.

seonghobae commented Sep 7, 2026

Copy link
Copy Markdown
Contributor Author

PR #50 canonical-documentation handoff update for current exact head 82a69abd6b89e489da8a5a8bf01657ef18dbd069. Keep docs/product-technical-gap-baseline.md, shared CHANGELOG.md, and broad standards rebuild single-writer in #37; do not copy mutable #50 source bytes.

When #37 is rebuilt on the then-current protected integrated tree, preserve these Reporting-Export facts: #50 remains an exact-value proposed/unverified, non-authoritative report/XBRL formatter; caller-supplied URLs or URNs do not confer taxonomy or filing authority. The URI input boundary now distinguishes RFC 3986 generic syntax, RFC 9110 HTTP(S) origin-host semantics, and a bounded RFC 8141 URN assigned-name structure.

  • HTTP origin RED 3335edc22b85b4e0772c444ce9f64fd481bc9f1f showed hostless authorities could have a non-empty netloc; GREEN 6e8978e7e0d41fb8ed5e516155d7ad7488a806e6 validates stdlib hostname plus port without URL dereference or trust expansion.
  • URN RED ea46ebae4c80a778e1a2327888a737b38a125012 now requires authority-form/incomplete names (urn://example.com/taxonomy, urn:cwl, urn::taxonomy, urn:cwl:) to fail while retaining urn:cwl:taxonomy:ifrs-2025. GREEN candidate 54e23f2fb0b49d57b1d2b4e108da680785a6f710 keeps urlparse, rejects URN authority syntax, requires a bounded alphanumeric/hyphen NID with alphanumeric ends, and requires non-empty NSS. This is deliberately a structural guard, not complete RFC 8141 component validation, namespace registration, resolution, dereference, or taxonomy trust.
  • d547b8bdcaddb8c7173e38ba7a325a1fc2573bf4 and current 82a69abd... add RFC 8141 APA traceability and acceptance-matrix coverage.

Predecessor #50@8a08cec57959a0f51873d065fd858427126bd432 has hosted Accounting Foundation GREEN (34146242854) with 5,516/5,516 production statements and 2,004/2,004 branches and exact-head package artifact 10027933553 digest sha256:6fa9e64b49a1a1b1b37481ce80ad8efb8014aa96a7eacec3552f0298a0524961; same-run dependency/SAST/security are GREEN. That is predecessor-only after the URN behavior change. Current 82a69abd... Foundation 34147350991 is pending and Security/SAST/CodeQL are queued, so do not describe the URN descendant as GREEN/shipped until unchanged-head evidence exists.

IFRS wording remains: IFRS Accounting Taxonomy 2025 is current for 2026 reporting until the next annual taxonomy in Q1 2027; 2026 Proposed Update 1/2 are proposal/consultation artifacts and must not be represented as released filing authority. Issue #51 remains the owner for AIS PostgreSQL source authority, official released taxonomy profiles, independent validation, approval, publication and external receipts.

Copy link
Copy Markdown
Contributor Author

Reporting-Export handoff for the canonical documentation lane. PR #50 advanced normally from hosted-GREEN 82a69abd6b89e489da8a5a8bf01657ef18dbd069 to test-first RED daf89cf1b37d7e9830145a1acd6a99e0b5e72105 and minimal production repair b996252fa5c400edbda2b67774f01df8c2c70c05 after fresh review found that caller-supplied HTTP(S) taxonomy/entity identifiers could retain userinfo and therefore serialize user identifiers or credentials into report/XBRL artifacts. RFC 9110 §4.2.4 says senders MUST NOT generate HTTP(S) userinfo and recipients of untrusted HTTP(S) references SHOULD treat its presence as an error; RFC 3986 §§3.2.1, 7.5 also treats password-bearing userinfo as deprecated/sensitive. #50 now rejects any parsed HTTP(S) username while preserving host/port/percent/URN behavior. When #37 later rebuilds on the integrated accounting/reporting tree, carry this as an input-integrity/security invariant in docs/product-technical-gap-baseline.md, shared CHANGELOG and canonical standards traceability. Do not copy mutable #50 source; reconstruct from the protected integrated tree and exact-head evidence.

Copy link
Copy Markdown
Contributor Author

Canonical documentation handoff — no competing docs write requested.

Fresh #43 review on exact cb50da837d4c5d574ed4ae5576c3e15b1b7e7d58 confirms that this #37 lane is already carrying the correct stronger product invariant. #37's current body/baseline requires lifecycle completion to retain exactly one matching outbox event after commit, reject deletion/re-key/duplicate exact insertion and retained event-id/creation-time mutation, while allowing published_at as publication metadata. Current #43 application behavior writes transition/status/outbox in one application transaction, but migrations 0019/0021 do not yet database-enforce that three-way invariant for a valid raw/privileged transition path.

The existing #43 single source-writer has been retasked to prove a realistic PostgreSQL RED and make the minimal database-owned command/status/outbox repair. Do not change #37 source merely to describe this finding again. After #43 produces a normal repaired descendant with unchanged-head GREEN and review evidence, rebuild this documentation lane against the integrated protected stack and bind the already-defined invariant to that exact migration/test/API evidence. Until then keep #37 Draft and preserve its existing event-id/created-at/published-at distinction.

Copy link
Copy Markdown
Contributor Author

#43 documentation handoff — do not copy mutable source bytes. Fresh lifecycle source authority is #43@baf5b47af7946dcbf64399ad46b2180a689a0622 on #29@a4db2ca...; current hosted Foundation run 34166545866 is still queued, so this is implementation evidence, not terminal GREEN.

When the reconciliation stack integrates and #37 rebuilds on the exact protected descendant, refresh the canonical product-gap/TRACEABILITY language from the released/integrated behavior rather than the PR head. The implemented deltas that must survive are: (1) migration 0021 serializes every hashed timestamptz (general_journal.posted_at, reconciliation_exception.effective_at, knowledge_cutoff_at) to fixed UTC text and has a real PostgreSQL UTC vs Asia/Seoul digest-parity acceptance; (2) reconciliation completion is database-enforced as one deferred command + reconciled status + exactly one matching reconciliation_run_reconciled event, with tenant/run/transition/hash binding, duplicate rejection, immutable event identity/hash/created_at, publication-only published_at, omitted-event rollback and forged-event rejection; (3) ADR 0060 is code-current with those choices and rejected alternatives. Your existing post-commit authority language already anticipates much of (2); add exact migration/test/API trace only after the integrated head proves it. #43 has not written docs/product-technical-gap-baseline.md, shared CHANGELOG or broad STANDARD_TRACEABILITY.

Copy link
Copy Markdown
Contributor Author

Canonical-baseline dependency correction — do not change #37 source from this coordination note. #43 is now merged history, not an open dependency. Current effective behavior stack is #29@12e1a4bb9d8de5e4b6c72e2893107b07c515416b -> #47@f6d6d5c38acfae8ca9cc2db72924b5253340e6fb -> #53@7c75e05626fa8c7477089c1272bb43719d66bb17 -> protected develop. Verified #43 b37c1614... was normally integrated into #29 as 2ec7ebdb... and that integrated root earned real-PostgreSQL Foundation/security/SAST/dependency GREEN. Current #29 then advanced only through two test-worker exception-boundary repairs; its current-head Foundation 34173498502 is still executing while current-head same-run dependency/security/SAST are GREEN, standalone Security/SAST are GREEN, and required CodeQL 34173498486 is terminal RED after successful current-head dispatch but before authenticated terminal receipt. Preserve #37 as the sole writer for docs/product-technical-gap-baseline.md; rebuild it only after #29 -> repaired #47 -> #53 integrates into protected develop, without promoting predecessor evidence.

Copy link
Copy Markdown
Contributor Author

Follow-up exact-state correction: #29 remains 12e1a4bb9d8de5e4b6c72e2893107b07c515416b and its Accounting Foundation 34173498502 is now terminal GREEN on real PostgreSQL, with exact-head dependency/security/SAST and standalone Security/SAST GREEN. Required CodeQL 34173498486 remains terminal RED at the central unchanged-head verdict/publication boundary after coordinator 101899139521 successfully dispatched the scan; .github#1929 owns that repair. Keep #37 Draft and source-idle as the sole baseline writer until #29 -> repaired #47 -> #53 reaches protected develop, then rebuild docs/product-technical-gap-baseline.md against that exact protected tree. Do not transfer #29 or predecessor evidence into the future #37 head.

Copy link
Copy Markdown
Contributor Author

Canonical-doc handoff from current reconciliation maker-checker lane; no #37 source is copied from a mutable child.

Fresh #47 inventory at exact 9a49750363d394656dd3830d8a977e0ebefb8c79 found that its shared CHANGELOG.md, README and broad docs/doctoring/STANDARD_TRACEABILITY.md still carry pre-restack migration identities even though the executable installer is now code-current. Current canonical migration map is:

  • 0020 reconciliation run completion evidence — root
  • 0021 reconciliation run database snapshot authority — root
  • 0022 exception-resolution command — feat(reconciliation): add maker-checker exception resolution command #47
  • 0023 exception-resolution outbox pair
  • 0024 authority outbox retention
  • 0025 authority outbox orphan guard
  • 0026 reconciliation control recording-time authority
  • 0027 lifecycle recording-time authority
  • 0028 lifecycle source-payload identity
  • 0029 lifecycle session-lock authority
  • 0030 lifecycle capability privileges

The shared #47 docs are not reliable canonical truth: its CHANGELOG still says exception command 0020 and later controls 0021..0025; its README says the checked-in chain ends at 0029_reconciliation_lifecycle_capability_privileges.sql; STANDARD_TRACEABILITY similarly cites old 0019/0020/0021/0024/0025/0027/0028 child identities. The branch-local tests/test_reconciliation_authority_changelog_contract.py also enforces the stale 0021..0025 release-note mapping, so it is a docs-to-code drift rather than independent protection.

Please preserve the semantics, not these mutable filenames, when #37 next rebuilds against integrated accounting truth: maker-checker exception resolution; command/status/outbox atomicity; post-commit outbox retention/orphan rejection; database-owned control/lifecycle system time; complete strict-JSON lifecycle source identity; committed session-lease -> fresh REPEATABLE READ authority ordering; and PUBLIC-revoked coordination helpers. Important non-claim: current 0030 only revokes PUBLIC EXECUTE on the two SECURITY DEFINER session helpers; it does not yet implement the purpose-limited NOLOGIN runtime capability. Issue #44 remains owner for that future capability boundary.

Do not treat this handoff as permission to mark those controls protected-integrated or release-ready. #47 current Accounting Foundation 34179885509 is still executing on exact 9a497503...; only after exact-head verification and normal integration should #37 bind these semantics into the canonical product/CHANGELOG/README/standards surfaces.

Copy link
Copy Markdown
Contributor Author

Canonical baseline prerequisite correction only; no docs/product-technical-gap-baseline.md bytes are requested from other lanes. Live dependency is now #29@12e1a4bb... -> #47@6c3a92fdc4d0b143e9e2da07f263661fe58357cd -> #53. #47 is Draft after a later exact-head Codex review produced three P1 control findings; two are source-addressed on 6c3a92fd..., while composite retained-evidence referential scope in migration 0022 remains under the existing #47 single writer. Historical 4527ca02... GREEN must not be copied into the canonical buyer/control baseline as current evidence.

Copy link
Copy Markdown
Contributor Author

Canonical baseline prerequisite update only: live dependency is #29@12e1a4bb... -> #47@27309ca78c59608ff2ee6dce4d5f001f10c4f875 -> #53. 6c3a92... hosted 1,314 PostgreSQL tests; the new stacked-session and lifecycle-lease FORCE-RLS regressions passed, while the composite retained-evidence FK RED and one stale static text matcher failed. The static ratchet is repaired tests-only in 27309ca...; migration 0022 composite referential scope remains the active source P1. Do not copy historical 4527ca... GREEN or predecessor partial evidence into docs/product-technical-gap-baseline.md as current truth.

Copy link
Copy Markdown
Contributor Author

OWNER-PATH HANDOFF — do not copy mutable branch bytes into the canonical baseline yet.

Fresh 2026-09-09 source evidence advances Period Close #53 from 7c75e056... to test-first descendant 9c3dba6f12aa58062faa6ba11537aabef91486d8. The production candidate already keeps the actual P&L closing contra on immutable posted chart_account_id and binds that identity into retained snapshot provenance, but the durable closing-journal journal_proposal_record.source_payload_hash still hashes code/role/amount/line only. The new real-PostgreSQL code-reuse assertion requires that closing command/evidence digest to bind the same historical account Entity identity. This is a #53 Period Close evidence-audit invariant, not Reporting authority.

After #53 reaches protected lineage, #37's non-destructive rebuild should record the durable rule at the accounting/evidence level: effective-dated code reuse cannot make two distinct historical account Entities evidence-equivalent for Period Close; both the emitted clearing line and its retained command/provenance digest must remain bound to the immutable posted Entity identity. Do not name the mutable 9c3dba6... branch head as product truth in shared CHANGELOG/TRACEABILITY/baseline before integration.

Also supersede the body’s stale #52 state only for live handoff purposes: #52 is now exact 5a26eba357d09a0e65933da1e5ced99197130ecf; its Reporting-local raw run_status_code mutation defect is repaired, while the only two behavior REDs remain the #53-owned retained snapshot header/line immutability dependency.

Copy link
Copy Markdown
Contributor Author

Canonical-owner refresh — 2026-09-09; do not copy mutable bytes yet.

Two downstream prerequisites in this PR body have advanced:

  • Period Close fix(close): freeze hard-close trial balance evidence #53 is now 9c3dba6f12aa58062faa6ba11537aabef91486d8, still Draft/mergeable=false on stale stored parent. It carries the real PostgreSQL RED requiring closing-journal source_payload_hash to distinguish reused historical account Entities by exact posted chart_account_id. The selected source fix binds historical P&L account UUIDs into _canonical_closing_hash() only; retained earnings remains current close-time policy. Adopt the durable invariant here only after fix(close): freeze hard-close trial balance evidence #53 reaches protected lineage: effective-dated code reuse may not alias either retained snapshot provenance or closing-command/evidence provenance across distinct account Entities.
  • Reporting feat: bind financial report sources to AIS persistence #52 is now 5a26eba357d09a0e65933da1e5ced99197130ecf. Its raw report-run lifecycle mutation gap is fixed; exact-head Foundation remains RED only on the two retained-snapshot mutation cases owned by fix(close): freeze hard-close trial balance evidence #53. Keep those as dependency evidence, not a Reporting-local snapshot authority.

Standards handoff from Issue #51: IFRS Foundation states that no 2026 annual Accounting Taxonomy is issued; IFRS Accounting Taxonomy 2025 remains current for 2026 reporting until the 2027 taxonomy in Q1 2027. Proposed Update 1 (General Improvements, comment period closed 2026-09-07) and Proposed Update 2 (IFRS 20 / hyperinflationary presentation currency / IFRS 19 amendments, comments through 2026-09-14) are proposal authority only. When Reporting/profile work reaches protected integration, shared TRACEABILITY must distinguish released package identity + applicable reporting period + guidance digest from proposed taxonomy deltas; do not label a proposal as official/current.

No #37 source/docs commit is warranted before the protected dependencies exist; this comment updates the owner acceptance without violating the single-writer/protected-truth rule.

Copy link
Copy Markdown
Contributor Author

Current Period Close handoff only; no shared-doc source mutation before protected integration. #53 remains Draft/merge-conflicted at exact 9c3dba6f12aa58062faa6ba11537aabef91486d8. Exact-head COMMENT review 5147490036 now records the remaining evidence-audit RED: closing journal facts and retained snapshot evidence are bound to historical posted chart_account_id, but _canonical_closing_hash() still drops that Entity identity and can provenance-alias reused account codes. The narrow source repair is owned by #53 handoff comment 5592475501.

After #53 is normally integrated through the verified #29 -> #47 -> #53 lineage, #37 should adopt the durable invariant into docs/product-technical-gap-baseline.md / shared TRACEABILITY / CHANGELOG: effective-dated account-code reuse must not make two distinct historical Account entities equivalent in either retained snapshot provenance or close-command/journal evidence. Until protected integration, do not copy #53 mutable bytes or mark that invariant delivered.

Copy link
Copy Markdown
Contributor Author

Post-integration documentation handoff for General Ledger gap #56 / RED-only #57.

Do not copy mutable #57 test/source into the canonical baseline yet. After the GL repair reaches protected develop, rebuild this single-writer lane on that exact tree and record the durable invariant: one account-ledger read is scoped to one exact tenant + legal entity + accounting book + chart-account identity (and optional fiscal period); sibling books that reuse the same chart-account code must never share ledger lines, totals, or pagination state. Trace the integrated HTTP/library parameters, resolved accounting_book_id SQL predicates, two-book real-PostgreSQL acceptance, ADR 0019 successor/current status, and exact protected evidence into docs/product-technical-gap-baseline.md, shared CHANGELOG.md, and docs/doctoring/STANDARD_TRACEABILITY.md.

Current RED-only exact head is #57@b052715dcb4ff8a879665101c01ef887e0653e22 from protected develop@239008c4edc7d305c97704c5102b593c6622b36f; hosted workflows are queued and are not yet RED/GREEN evidence. Preserve #37 single-writer ownership and wait for protected truth before changing shared docs.

Copy link
Copy Markdown
Contributor Author

Post-integration documentation handoff for General Ledger #56/#57 only; do not copy mutable child bytes now.

Protected-code review plus exact hosted PostgreSQL RED on #57@7b22dde45af55d6402cfc99be3c95751b6b622ce proves that account-ledger inquiry must be scoped by one exact accounting book, not merely tenant + legal entity + chart-account code. Same-code statutory and management postings currently alias into one response (50000.000000 observed where the requested statutory book owns 25000).

After the causal GL repair normally integrates, reconstruct the durable invariant in docs/product-technical-gap-baseline.md, docs/doctoring/STANDARD_TRACEABILITY.md, and CHANGELOG: chart-account code is book-scoped; buyer-visible ledger rows, pagination/cursors and full-scope totals must all bind the same resolved accounting_book_id; optional period filtering composes inside that book boundary; a valid empty book remains exact zero, and unknown/cross-entity book references fail closed. Keep this separate from Period Close #53 and Reporting authority.

seonghobae commented Sep 9, 2026

Copy link
Copy Markdown
Contributor Author

Canonical post-integration docs handoff — current source authority is #59@2c36496b2b9633fff18e87f5addfabf33ec31405 on protected-parent develop@239008c4edc7d305c97704c5102b593c6622b36f. Keep this comment as handoff evidence only; #37 remains the single writer for docs/product-technical-gap-baseline.md, shared CHANGELOG.md, and docs/doctoring/STANDARD_TRACEABILITY.md.

After the relevant production descendants reach protected integration, rebuild those shared surfaces from the integrated tree and preserve these accounting invariants:

  • Durable (tenant_account_id, legal_entity_id, book_reference) identity is effective-dated with half-open [valid_from, valid_to), NULL valid_to = +∞. Open-ended/open-ended, open-ended/finite and finite/finite overlap are database-rejected; non-overlapping history and [a,b) / [b,c) adjacency remain lawful.
  • The non-overlap invariant is database-owned for serial INSERT, competing INSERT that has actually reached PostgreSQL, and UPDATE of either successor valid_from or predecessor valid_to. Application preflight, row order, insert-only enforcement and one-sided update enforcement are not substitutes.
  • Canonical resolution takes explicit effective_at, applies valid_from <= effective_at and (valid_to IS NULL OR valid_to > effective_at), then fails closed on 0 or >1 rows. A genuinely current catalog path may deliberately supply database clock; historical, period-scoped and authoritative paths must supply their own accounting-effective instant.
  • Adjusting-journal authority uses journal_date. test(book): enforce non-overlapping accounting-book reference #59 carries a PostgreSQL-clock negative control proving the book is already current at database time while the journal date predates book.valid_from; wrong current-clock resolution therefore cannot accidentally satisfy the RED.
  • Effective-dated bank-account assignment authority uses assignment valid_from. Current #59@2c36496b... adds the same database-current negative control with book.valid_from=2026-09-01, database_now > book_valid_from, assignment valid_from=2026-08-31, expected AccountingValidationError, and zero persisted assignment rows.
  • General Ledger rows, cursor identity and totals must resolve and remain scoped to the same immutable accounting_book_id; do not infer book_role_code, choose the first same-reference row, substitute system time, or copy foreign commercial truth into accounting.
  • Preserve tenant/legal-entity RLS and composite-FK scope, reporting currency, exact Decimal, immutable posted facts, reversal/correction, close/reopen and reconciliation/evidence semantics.

Current exact evidence for the handoff: Accounting Foundation 34386292077 is terminal intentional RED at #59@2c36496b...; Accounting job 102583289666 ran 476 tests in 91.561s and ended 11 failures + 1 error, with the new bank-assignment case failing exactly because AccountingValidationError was not raised. Same-head Foundation security 102583289315, dependency diff 102583289588, SAST 102583289701, standalone Security 34386292145, and standalone SAST 34386292181 are GREEN. Coverage/contracts/package/SBOM/provenance after behavior are not claimed because the RED stopped continuation.

Fresh CodeRabbit exact-head review found no defect in the new bank-assignment RED scope and confirmed the current-clock negative control; treat that as COMMENT evidence only, never an independent APPROVED or runtime GREEN.

Required CodeQL 34386292104 again exhibits the central receiver-before-producer defect: Python receiver 102583333936 failed at 2026-09-09T18:02:16.986Z, Actions receiver 102583333996 at 18:02:24.915Z, while same-run authoritative dispatch 102584259938 did not start until 18:02:33.066Z and then dispatched successfully. Exact downstream canary is recorded on canonical .github#2040 as comment 5606467283; do not manufacture a leaf status or weaken the gate.

Single-writer boundary remains material: #29 already modifies production bank_statement.py; #47/#53 are its mutable forward stack, #53 owns mutable persistence.py, and #57's active source writer is restricted to accept.py/http_api.py. Do not copy #29/#53/#57 mutable implementation or allocate a new migration identity from #59. After normal integration/reconciliation, adopt the canonical temporal resolver into bank assignment and other affected paths through ordinary non-force descendants, then reconstruct these shared docs from protected code.

ADR 0022 remains Proposed for this amendment until the production DB invariant/resolver reaches protected integration. #57 ADR 0019 remains independently Proposed until full GL population/totals behavior is GREEN. Do not mark either Accepted from RED-only evidence.

seonghobae commented Sep 9, 2026

Copy link
Copy Markdown
Contributor Author

Canonical-doc handoff for Accounting Book identity prerequisite #58 / Draft #59 is current at exact c7584934791f47bfe9d7d64415571b7caf86b0c4; do not copy this mutable child branch into shared docs yet.

The earlier current-row wording was too weak. Protected accounting_book has effective dates, so a durable book_reference must identify at most one Accounting Book Entity at any effective instant, not merely one row with valid_to IS NULL. #59 now carries real-PostgreSQL REDs for both an open-ended duplicate and a finite same-reference interval overlapping an existing open-ended book, while retaining the positive non-overlapping expired-history case. ADR 0022 remains Proposed and explicitly rejects a partial valid_to IS NULL unique index as sufficient by itself.

After #58/#59 production repair reaches protected integration, rebuild docs/product-technical-gap-baseline.md, shared CHANGELOG.md, and docs/doctoring/STANDARD_TRACEABILITY.md from that exact protected tree with this invariant: within tenant + legal entity, same-reference effective intervals never overlap; resolver zero/multiple effective matches fail closed; lawful non-overlapping history is retained; immutable posted/evidence relationships keep accounting_book_id. Record the selected PostgreSQL temporal mechanism and migration/preflight/recovery evidence from integrated code, not from this Draft. This handoff remains separate from #53 Period Close and #57 GL population/totals ownership.

Copy link
Copy Markdown
Contributor Author

Post-integration canonical-doc handoff update from #58/#59: the durable Accounting Book reference invariant is now full half-open effective-time non-overlap, not current-row uniqueness. Canonical mutable evidence is #59@72e8e342eaeb4edd40c11284f11473a8622aea79. After the production invariant/resolver normally reaches protected develop, rebuild docs/product-technical-gap-baseline.md, shared CHANGELOG.md, and docs/doctoring/STANDARD_TRACEABILITY.md from that protected tree so they state: (tenant_account_id, legal_entity_id, book_reference) names at most one Accounting Book Entity at any instant; validity is [valid_from, valid_to) with NULL as +∞; open-ended/open-ended, open-ended/finite and finite/finite overlaps fail closed; exact [a,b) / [b,c) adjacency and other non-overlapping history remain lawful; accounting_book_id remains immutable relational identity. Do not copy mutable #59 tests/ADR/migration bytes into #37 before protected integration.

Copy link
Copy Markdown
Contributor Author

Post-integration handoff for Accounting Book durable-reference authority: #58 / Draft #59 is now exact f2df2e59e5db2c0310980940c4b9fd108de288ed. Do not copy its mutable test/ADR bytes now. After the catalog invariant reaches protected lineage, rebuild docs/product-technical-gap-baseline.md, shared CHANGELOG and STANDARD_TRACEABILITY from that integrated tree to record that (tenant_account_id, legal_entity_id, book_reference) effective intervals are half-open [valid_from, valid_to), never overlap, preserve exact-boundary adjacency/non-overlapping history, and remain non-overlapping under concurrent catalog writers through a database-owned integrity mechanism. Exact hosted RED 34348867333 ran 466 tests with 4 intended failures; the new concurrency oracle observed the second overlapping transaction actually commit, so application-only read-before-write validation is not sufficient. Keep accounting_book_id as immutable relational identity and resolver 0/1/>1 fail-closed semantics. This is post-integration documentation truth only; #37 remains the single writer for shared docs.

Copy link
Copy Markdown
Contributor Author

Post-integration handoff update for #58/#59: canonical mutable RED head is now fc62c76e0ba2673c8727cf6ec15e197922abd964; do not copy its test bytes into shared docs before protected integration.

The durable-reference invariant now has two distinct defense layers that the eventual baseline/TRACEABILITY/CHANGELOG should reconstruct from integrated code: (1) PostgreSQL owns half-open temporal non-overlap under serial and concurrent catalog writers; (2) every public book_reference resolver explicitly treats cardinality 0 as missing, 1 as the only success state, and >1 as ambiguous/fail-closed rather than .fetchone()/row-order selection. The new ordered concurrency oracle additionally proves the competing SQL has reached PostgreSQL before the first writer is released, closing the earlier thread-scheduling gap. Preserve immutable accounting_book_id, exact-boundary adjacency and non-overlapping history. #37 remains the single writer for shared docs; #53 Period Close and #57 GL population/totals ownership stay separate.

seonghobae commented Sep 9, 2026

Copy link
Copy Markdown
Contributor Author

Superseding post-integration handoff for shared-doc single writer #37 after fresh exact #59 descendant.

Current source authority is Draft #59 4484a22e14c825b75eeac3b26cdd6b04ad510bed on protected base develop@239008c4edc7d305c97704c5102b593c6622b36f. #37 remains the sole writer for docs/product-technical-gap-baseline.md, docs/doctoring/STANDARD_TRACEABILITY.md, and shared CHANGELOG.md; do not copy mutable #59 tests/source into #37.

When the production invariant/resolver normally integrates, reconstruct those shared surfaces from the integrated tree with these code-current contracts/evidence:

  • (tenant_account_id, legal_entity_id, book_reference) is half-open effective-time identity: same-reference intervals may be historical only when non-overlapping; [a,b) / [b,c) adjacency is lawful; serial INSERT, PostgreSQL-observed concurrent INSERT, and UPDATE of either boundary must preserve non-overlap.
  • Canonical resolution uses explicit effective_at, requires exactly one match, and fails closed on 0 or >1. Historical/write/relationship paths use their accounting-effective instant rather than database current time. Adjusting journals use journal_date; bank-account assignments use assignment valid_from.
  • bank_account_assignment [a,b) must remain inside its referenced Accounting Book interval under both parent-Book and child-assignment boundary mutation. Existing invalid rows are upgrade/preflight evidence requiring an accounting-master-data decision; do not silently truncate/rebind/delete history.
  • The bank-assignment path must resolve the exact referenced chart-account Entity at assignment valid_from, not by valid_to IS NULL. Current REDs cover both directions: reject a future open-ended chart account not yet effective at the relationship start, and accept a finite historical chart account that was effective then even after database current time has moved beyond its interval. The Accounting Book is independently effective in both fixtures. This is scoped Bank Reconciliation relationship evidence, not a blanket policy for every effective-dated relationship.
  • Preserve immutable accounting_book_id, tenant/legal-entity/RLS/composite-FK scope, exact Decimal, posted/close/reconciliation/reporting evidence, and the Billing/non-accounting authority boundary.

ADR 0022 on #59 is code-current for this amendment but remains Proposed until the production database invariant/resolver reaches protected integration. Rebuild shared docs only from that future protected exact tree and reacquire their own tests/reviews/gates.

Copy link
Copy Markdown
Contributor Author

Post-integration handoff update for #58/#59: current mutable RED authority is #59@4a1e49adc0e4185c7b1a94b4194efbf335d58855; do not copy its branch-local tests/ADR into #37 before protected integration.

The scoped Bank Reconciliation contract now has a post-admission relationship invariant in addition to chart-account-at-assignment-start resolution. Because bank_account_assignment stores the exact chart_account_id and its own [valid_from, valid_to) interval, the future protected implementation must keep that assignment interval inside the exact referenced chart-account Entity interval. Real-PostgreSQL RED descendant 8f279a0ef9bef9c2466bc4765345e9697c49a15c covers all three mutation paths while keeping the Accounting Book wider than the hostile mutation: shorten the referenced chart account around an existing assignment; extend assignment valid_to beyond chart end while still inside Book; move assignment valid_from before chart start while still inside Book. Each must be database-rejected. Existing violating rows belong to upgrade/preflight accounting-master-data evidence; do not silently truncate/rebind/delete them.

After the production invariant/resolver normally reaches protected develop, rebuild docs/product-technical-gap-baseline.md, shared CHANGELOG.md, and docs/doctoring/STANDARD_TRACEABILITY.md from that exact integrated tree with this scoped chart-account containment alongside the existing Book non-overlap, explicit-effective-time resolver, adjusting-journal journal_date, Book assignment containment, and finite-history chart-account selection contracts. Do not generalize this RED into a blanket containment policy for unrelated effective-dated relationships. ADR 0022 remains Proposed until protected production behavior exists.

Copy link
Copy Markdown
Contributor Author

Post-integration #58/#59 handoff supersedes the immediately prior chart-containment note: current mutable authority is #59@c82867925ab6d1b5cfbd3122aaad9fe8284f37a4; do not copy its RED/ADR bytes into #37 before protected integration.

The exact bank_account_assignment ↔ exact chart_account interval contract now has four, not three, mutation directions. 8f279a0... covers parent chart valid_to shortening and both hostile assignment-boundary edits. f87d9bfe2da2c491afe04120f99d92c2595bee1c adds the symmetric parent chart_account.valid_from move forward across an existing assignment start while the assignment remains inside the wider Accounting Book. Current ADR descendant c828679... therefore states that both chart-account boundaries and both assignment boundaries must preserve bank_account_assignment [a,b) ⊆ exact chart_account interval at the database boundary. This remains scoped Bank Reconciliation evidence, not a generic policy for unrelated effective-dated relationships.

After production repair normally reaches protected develop, reconstruct docs/product-technical-gap-baseline.md, shared CHANGELOG and STANDARD_TRACEABILITY from that exact integrated tree with all four chart/assignment mutation controls, the existing Book non-overlap/effective resolver/Book-assignment containment contracts, and upgrade/preflight fail-closed evidence. ADR 0022 remains Proposed until protected production behavior exists.

seonghobae commented Sep 9, 2026

Copy link
Copy Markdown
Contributor Author

#59 post-integration handoff refresh — current mutable authority is #59@d83e5ccf761729767908f467ab97cbe89b68a3c4; do not copy its RED/Proposed bytes into this docs lane before protected production integration.

The existing Accounting Book durable-reference/effective-time, Bank Reconciliation temporal-containment, same-bank/same-Book effective-identity, retained-command evidence, and evidenced retirement/amendment handoff remains. The newest #59 increment closes a remaining relationship-identity evidence gap: composite foreign keys prove that a tuple is internally valid, but do not prove that it is the tuple accepted by the retained assignment command.

b0ce5c5499b0d9e701a428f8ea07c5bd5dd8e5e5 adds two causal real-PostgreSQL REDs. One replaces accounting_book_id together with a valid same-code chart_account_id on another Book under the same legal entity. The other replaces legal_entity_id, accounting_book_id, and chart_account_id together with a mutually consistent alternate parent scope. Both preserve tenant, bank-account identity, assignment row id, replay key/hash, and validity, so the current composite FKs remain satisfied and cannot manufacture the expected rejection. ADR descendant d83e5ccf761729767908f467ab97cbe89b68a3c4 records that accepted relationship identity must survive FK-consistent multi-column rewrites as well as the existing single-column bank/chart rebind cases.

After production repair normally reaches protected develop, reconstruct docs/product-technical-gap-baseline.md, shared CHANGELOG.md, and docs/doctoring/STANDARD_TRACEABILITY.md from that exact integrated tree. Record the protected evidence for Accounting Book non-overlap/resolution, Book/chart assignment containment, same-bank/same-Book interval identity and concurrency, retained assignment key/hash/row/start/system-time/history, all four accepted relationship identities including FK-consistent composite rebind rejection, and the separately evidenced valid_to retirement/amendment command. Do not promote Draft REDs or Proposed ADR text to delivered product truth. ADR 0022 remains Proposed until protected production behavior exists.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

Status: Backlog

Development

Successfully merging this pull request may close these issues.

1 participant