Repository navigation
S6 — Detect coordinate-registry drift against the Appwrite Seam Contract (C-57) #187
Description
Activity
- addedstoryA single reviewable unit of an epicA single reviewable unit of an epictestingTest/parity/validation workTest/parity/validation work
on Aug 1, 2026 Two corrections before this is started, from #184/#195:
-
The registry is v1.4.0, not 1.3.0. It was amended upstream on 2026-08-02 (
amended = "2026-08-02", contract §5.9 "one writer per value"). This issue's body specifiesSEAM_CONTRACT_VERSION = "1.3.0", which went stale before the story was written — a fair illustration of why the drift test is worth having. -
The pinned commit
b54928fnow appears in two places that must move together:views_postprocessing/unfao/appwrite_env.py(module docstring) anddocs/ADRs/013_…md§7d. Making that pair checkable is squarely this story's job — consider whether the declared constant should carry the commit as well as the version.
Also: read
appwrite_env.pyagainst the tree, not against this issue. S1 (#182) and S3 (#184) have both rewritten parts of it since this was filed.-
Third correction for this story, from #196/#198 — and it changes the test's shape, not just a constant.
S3's pin (
b54928f, labelled v1.4.0) was an unmerged branch commit and has been withdrawn. It was resolved withgit -C ../views-appwrite rev-parse HEADon a checkout that happened to be sitting onfeat/s1-single-writer-rule.Superseding my earlier comment: the registry is v1.3.0, pinned at
47172af(the tip ofmain, ratified þing-02) — not 1.4.0, and not 1.3.0-for-the-reason-I-first-gave.Add to this story's scope: the drift test must assert the pinned commit is reachable from views-appwrite's
main, not merely that the file exists at it. Existence was true of the withdrawn commit; reachability was not, and reachability is the property that actually means "this is what the contract says".git -C <views-appwrite> merge-base --is-ancestor <pinned> origin/mainThat single check would have caught this within the hour instead of requiring another seat to notice.
- added a commit that references this issue
on Aug 2, 2026 Landed in #202. C-57 closed.
Four checks, each mutation-proven with bytecode disabled (stale
.pycwas lying mid-campaign — both shas are 7 chars, so size+mtime validation passed and Python served a cached module contradicting its own source; everything re-verified from clean).The reachability check is the one that matters. #196 happened three hours before this story: a pin whose commit existed, whose files existed at it, and which passed every check anyone had written — but had never reached
main. Existence is not reachability, and now something asserts it.The value-copy check took two wrong narrowings, both recorded in C-57's resolution. A substring scan cried wolf on a function name; narrowing to assignments and defaults then caught zero of
{"bucket": "unfao_bucket"}andAppwriteConfig(bucket_id="unfao_bucket")— the second being the shape this repo would actually produce. Right axis: exact equality on string constants, not statement shape.Review also caught
_EXPECTED_CLASSderiving class from the_API_KEYsuffix — the exact inference the registry forbids, inside the test enforcing the registry.Register: 74 concerns, 19 open, 55 resolved.
- added a commit that references this issue
on Aug 3, 2026
Part of epic #181. Closes register C-57 (Tier 3). Depends on S3.
Background
views_postprocessing/unfao/appwrite_env.pydeclares 15 environment-variable names. Their authority is the Appwrite Seam Contract's coordinate registry, which lives in another repository:The registry is deliberately referenced, never copied — its own header forbids copying, and this repo's
CLAUDE.mdstates the same rule platform-wide. That is the right call: one owner, no duplicated values, no drift-by-fork.But it leaves a gap that C-57 names precisely: nothing mechanical will tell you when the two diverge. The registry is versioned (
[meta] version = "1.3.0", ratified by þing-02 on 2026-07-31) and it changes — it has already retired one contract name (see S3) and it carries five planned secret slots that will land:Checked 2026-08-01: there is no live drift today. All 15 names this repo declares are present in the registry with matching class, and the secret slot it uses (
APPWRITE_DATASTORE_API_KEY) is still the current one. So this story builds a detector, it does not fix a break. Doing it now, while the answer is known-good, is the cheap moment — the alternative is discovering the drift during a failed delivery.Work
Declare, in
appwrite_env.py, the registry version this repo's declaration was verified against:That is a version string, not a coordinate value — it does not copy the registry, it records which edition of it was read. Cite the pinned URL alongside it.
Then add a gated drift test that, when a
views-appwritecheckout is resolvable, parses the registry and asserts:CONNECTION_ENV/PROD_FORECASTS_ENV/UNFAO_ENVexists in the registry;classexplicitly and forbids inferring it from the prefix, so read it, do not derive it;[meta] versionequalsSEAM_CONTRACT_VERSION, with a failure message that says "the registry moved to X; re-verify this repo's declaration and bump the constant".Check 3 is the one that earns the story. Checks 1 and 2 catch a rename; check 3 catches anything else, including additions this repo ought to adopt.
Never assert on a value. The registry contains non-secret coordinate values; this test must compare names, classes and the version only. Copying a value into a test is the same violation as copying it into code —
tests/test_redaction_guard.pygoverns the surrounding discipline.Gating. Use the same declared resolution S7 establishes for views-datafactory. Do not hardcode a path; do not silently pass when the sibling is absent. Skip with a reason that names the env var to set.
Acceptance criteria
SEAM_CONTRACT_VERSIONdeclared, with a pinned-URL citation.Testing
Suggested home:
tests/test_env_declaration.py(owns this module) or a newtests/test_seam_contract_drift.pyif the gating machinery makes the former unwieldy. Prefer extending the existing file — one concept, one home.Prove the detector bites, per this repo's standing practice:
Feed it a synthetic registry with one name renamed and assert the check fails. That part needs no views-appwrite checkout, so it runs in CI.
Validation:
Dependencies
Depends on S3 — both edit
appwrite_env.py's docstring and citations, and S3 establishes the current contract name this story's constant refers to. Sequence them to avoid a conflict.Uses the resolution helper from S7 if S7 lands first; otherwise S7 adopts whatever this story establishes. Whichever is second must not leave two ways to find a sibling repo.
Files
views_postprocessing/unfao/appwrite_env.py— the declaration../views-appwrite/docs/ADRs/platform/coordinate_registry.toml— the authority (read only)tests/test_env_declaration.py— the governing test filetests/test_redaction_guard.py— the no-values discipline