Seal the plan as a specification instead of four bullet lists

The plan artifact was Changes{Target,Intent} plus three string lists, every
entry capped at 500 single-line characters. That bound makes a specification
impossible: a phase cannot carry a code block, a paragraph of reasoning, or a
verification command with its own argument list. renderSealed then flattened
what little survived through collapse(), so an implement session received a
summary of a summary.

plan.md replaces it. Markdown, 128 KiB, no per-line cap, sealed through the
existing path under the existing PlanRef. The parser enforces the structure the
brief states: required sections, phases numbered from 1 with no gaps, Files,
Changes and Verification per phase, and at least one automated or manual check,
because a phase nobody can verify can never be established as done. Automated
entries are JSON argv arrays, so a pipe is a literal argument rather than an
operator. Headings inside fenced blocks are content, so a plan may show
markdown without parsing its own example.

Citations resolve at seal time against the accepted research, on the
coordinator, which is the only party holding ResearchRef. A plan resting on a
finding nobody recorded fails on the planner while its session is still alive
to be told.

The plan now renders byte for byte into the implement launch, and a rotated
successor receives the same complete document. That is the property the whole
change exists for. collapse() stays for research findings, which really are
short claims.

DecodeStoredPlan reads pre-markdown refs and renders them into the same type,
labelled, so nothing downstream branches on which era a plan came from. A
legacy plan carries no phases, which is honest: the old artifact never named an
executable unit.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CVbaKucEYBjMqVeUgJUsc1
This commit is contained in:
2026-08-28 11:36:45 +04:00
parent 822f086451
commit 57c028f94f
22 changed files with 1070 additions and 145 deletions
+35 -1
View File
@@ -4,6 +4,7 @@ import (
"encoding/json"
"errors"
"fmt"
"strings"
"orchestra/internal/authz"
"orchestra/internal/domain"
@@ -71,7 +72,16 @@ func advanceWorkPhase(s *store.Store, project registry.Project, taskID string, a
return domain.Event{}, err
}
case domain.WorkPhasePlan:
if _, err := workphase.DecodePlan(artifact); err != nil {
doc, err := workphase.ParsePlan(artifact)
if err != nil {
return domain.Event{}, err
}
// Citations resolve here and nowhere else: the coordinator holds
// ResearchRef, so this is the only party that can tell whether a
// cited finding exists. A plan resting on a finding nobody
// recorded fails on the planner, while its session is still alive
// to be told, rather than on the implementer later.
if err := resolvePlanReferences(s, t, doc); err != nil {
return domain.Event{}, err
}
}
@@ -169,3 +179,27 @@ func phaseOperation(s *store.Store, taskID, operationID string) (domain.Event, b
}
return domain.Event{}, false
}
// resolvePlanReferences refuses a plan that cites research the task never
// sealed. Its cost is one CAS read against a ref the coordinator already
// holds.
func resolvePlanReferences(s *store.Store, t domain.Task, doc workphase.PlanDoc) error {
if len(doc.References) == 0 {
return nil
}
if t.ResearchRef == "" {
return fmt.Errorf("%w: the plan cites %s but this task sealed no research", domain.ErrInvalid, strings.Join(doc.References, ", "))
}
raw, err := s.Artifact(t.ResearchRef)
if err != nil {
return fmt.Errorf("resolve plan references: %w", err)
}
r, err := workphase.DecodeStoredResearch(raw)
if err != nil {
return fmt.Errorf("resolve plan references: %w", err)
}
if missing := doc.ResolveReferences(r); len(missing) > 0 {
return fmt.Errorf("%w: the plan cites research:%s, which the accepted research does not contain", domain.ErrInvalid, strings.Join(missing, ", research:"))
}
return nil
}