CB-548: config-declared architect slots + Role.ARCHITECT authz (corrected premise) #20
Reference in New Issue
Block a user
Delete Branch "worker/cb-548-authz-v2-586df6-8"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Supersedes #19 (same CB-548 unit, corrected premise per review). Replaces the earlier premise that architect identity is recognised from config the way a lead is.
What this corrects vs #19
architects:slot is a gateway-local name → strong-modelworkers:profile. Removed the configured/pinnedterminalfield andarchitectTerminals(), and dropped the 'recognised like a leader' claim. On startup every slot is idle: config never supplies a terminal, so no architect terminal resolves at boot.terminal → slotbindings rather than a config-derived read-only supplier. Exposesbind(slot, terminal)(validates the slot exists; atomically refuses a terminal in two slots and a slot with two terminals; same-pair rebind is an idempotent no-op) and compare-safeunbind(slot, expectedTerminal)(a stale unbind never removes a replacement). Alsosnapshot()(immutable copy),slotForTerminal,profileForSlot,isSlot.architects::snapshotin on both auth paths. Resolve order preserved: lead > architect > generic worker. The rest of #19's Role/Authz/Principal/whoami work is kept unchanged.architects:slot name silently dropped one slot). Added parse-time detection (rejectDuplicateArchitectSlotsinload), scoped to thearchitects:block, failing with anIllegalStateExceptionthat names the duplicated slot.Tests
Focused architect tests (ArchitectRegistry/Config/CallerResolver/Authz/BridgeMcp) plus new invariant + 2-concurrency tests for the registry and a duplicate-key config test.
mvn clean install→ Tests run: 519, Failures: 0, Errors: 0, Skipped: 0; BUILD SUCCESS.Residual
wiki/Features entry for the architect registry is not updated here (worker cannot touch the wiki submodule) — recommend a follow-up feature entry.terminal:under anarchitects:slot is silently ignored (record isignoreUnknown); an upgrade note/test documents that it no longer binds anything.