Repository navigation
refactor(models): isolate saved-routing read authority #389
Description
Activity
- addedenhancementNew feature or requestNew feature or requeststatus:approvedIssue approved by maintainer; PR may be openedIssue approved by maintainer; PR may be openedand removedstatus:approvedIssue approved by maintainer; PR may be openedIssue approved by maintainer; PR may be opened
on Aug 21, 2026 The frozen #389 candidate is stopped at exactly 519 A+D, 354 additions and 165 deletions, above the hard cap of 400. There is no behavioral RED: the focused command failed before test execution because dependencies, including
@earendil-works/pi-tui, are absent.Proposed stacked-to-main reslice: keep #389 as the shared read-authority and fail-closed unit, then create a separate Unit 2 issue for strict canonical config names and explicit target/profile alias authority. The candidate remains frozen and uncommitted. This hold grants no code, implementation, merge, or publication authority; #389 requires exact body review and human authorization before
status:approvedis restored, while Unit 2 starts atstatus:needs-review.- addedstatus:approvedIssue approved by maintainer; PR may be openedIssue approved by maintainer; PR may be opened
on Aug 21, 2026 - changed the title
[-]refactor(models): isolate and validate saved routing authority[/-][+]refactor(models): isolate saved-routing read authority[/+]on Aug 21, 2026 - removedstatus:approvedIssue approved by maintainer; PR may be openedIssue approved by maintainer; PR may be opened
on Aug 22, 2026 The current #389 candidate is 449 A+D, 49 lines over the 400-line cap. The hard stop was honored. Evidence is assertion-level RED + focused GREEN 3/3 only, with no broader verification. No commit, push, or PR was made.
A causal split is being applied: #389 retains the shared routing authority and fail-closed apply/export behavior, followed by a dependent UI/lifecycle consumer child, then #391.
- addedstatus:approvedIssue approved by maintainer; PR may be openedIssue approved by maintainer; PR may be openedand removedstatus:approvedIssue approved by maintainer; PR may be openedIssue approved by maintainer; PR may be opened
on Aug 22, 2026 The frozen candidate reached 462 A+D, which is 62 over the 400-line cap. The exact focused RED command produced 6 assertion-level failures. No GREEN result or broader verification was run.
The hard stop is honored. No commit, push, or PR was made. We are applying a new causal split: #389 keeps shared types and normalization, sync/async authority, and the real export path; a new dependent child owns fail-closed apply behavior and the profile byte, mtime, and no-write proof; #395 and #391 remain later dependent slices.
- addedstatus:approvedIssue approved by maintainer; PR may be openedIssue approved by maintainer; PR may be openedand removedstatus:approvedIssue approved by maintainer; PR may be openedIssue approved by maintainer; PR may be opened
on Aug 22, 2026 The frozen candidate is 455 A+D, which is 55 lines over the 400-line hard stop. The exact recorded evidence is assertion-level RED followed by focused GREEN 4/4 only. No broader verification is claimed.
The hard stop is in force. No commit, push, or PR was made.
We are not opening a new issue. The candidate is being redistributed across the existing chain:
- refactor(models): isolate saved-routing read authority #389 keeps extraction only: shared types and normalization, synchronous and asynchronous authority, and minimal compatibility wrappers used by existing production callers. Those wrappers preserve current behavior, including project-invalid collapse where callers currently expect it. This issue does not directly migrate export, apply, UI, or status behavior.
- refactor(models): isolate fail-closed saved-routing apply #396 keeps apply safety unchanged and depends on refactor(models): isolate saved-routing read authority #389.
- refactor(models): migrate routing UI and lifecycle consumers #395 takes the direct export migration and export contract/tests, together with its existing UI and lifecycle scope for
/gentle:models, session-start reporting and wiring, and/gentle:status. It depends on refactor(models): isolate saved-routing read authority #389 and refactor(models): isolate fail-closed saved-routing apply #396. - refactor(models): enforce canonical routing names and target authority #391 keeps canonical and target-authority scope after refactor(models): migrate routing UI and lifecycle consumers #395.
This exact extraction versus export and UI redistribution is intended to recover reviewability without a size exception or a new issue. Hold and approval changes require separate exact human review.
- addedstatus:approvedIssue approved by maintainer; PR may be openedIssue approved by maintainer; PR may be opened
on Aug 22, 2026
Outcome
Extract one shared production read authority for saved model routing. This issue owns shared routing types and normalization, synchronous and asynchronous authority reads, and minimal compatibility wrappers used by existing production callers. The wrappers must preserve every current caller behavior, including project-invalid collapse where the current caller expects that result. Direct export migration and export contract tests move to #395. Apply, UI, status, canonical, and durable-write work remain in later slices.
Chain context
mainat implementation time. The stopped combined candidate and PR refactor(models): centralize routing persistence authority #385 evidence are not implementation bases./gentle:models, session-start reporting and wiring, and/gentle:status. refactor(models): enforce canonical routing names and target authority #391 follows refactor(models): migrate routing UI and lifecycle consumers #395 and enforces canonical names and explicit target authority. Durable write and materialization remain later slices.main. Use stacked-to-main delivery. The PR diff must contain only this extraction and compatibility-wrapper unit.status:approvedonly after exact title and body review and explicit human authorization. Approval authorizes only this bounded extraction scope. It grants no authority to commit, push, publish a PR, merge, or approve a later slice.enhancement,status:approved. The hold stage removesstatus:approveduntil this exact draft is reviewed.Dependency diagram:
Scope and acceptance criteria
normalizeModelId,normalizeRoutingEntry, andnormalizeModelConfig, into one shared production module.missing,valid, andinvalidresults and carry the invalid source path.__testingor a test-only caller.root/agentsdirectory used by discovery-adjacent authority tests.nullbehavior, literal stringinheritbehavior, omission semantics, apply behavior, startup behavior, and profile materialization.Candidate allocation
The frozen 455 A+D candidate is being resliced without opening a new issue. Module work of 112 lines, the authority extraction and compatibility-wrapper hunks, and the authority test setup and tests from lines 1-118 belong to #389. The direct export hunk and export or real-caller tests from lines 120-196 move to #395. No safety test is deleted. The later slice may reuse established scaffolding without duplicating the safety proof.
Intentionally out of scope
applySavedModelConfigchange, apply fallback change, profile byte or modification-time assertion, or profile no-write proof. Those belong to refactor(models): isolate fail-closed saved-routing apply #396./gentle:modelshandler, session-start consumer, or/gentle:statusreporting. Those consumers belong to refactor(models): migrate routing UI and lifecycle consumers #395.Strict TDD and verification
Strict TDD is required. The RED phase must be an executable assertion-level failure after dependency hydration, not a missing-module or environment error. The current governance snapshot records assertion-level RED and focused GREEN 4/4 for the combined candidate only. It is not issue completion evidence for this extraction slice. The implementation PR must report its own observed evidence before claiming completion.
Environment prerequisite: use an authorized implementation environment with dependencies hydrated by the repository package manager,
pnpm@11.1.1, including@earendil-works/pi-tui.Run the focused and package-supported commands after the behavior tests exist:
inherit, JSONnull, omissions, existing target and path semantics, and explicit fixture-directory creation. Do not add direct export, apply, profile-safety, UI, or status migration proof here.Review workload forecast and hard stop
Forecast only, measured against the clean immediate
mainbase: 245 lower / 285 realistic / 335 upper A+D. The hard stop is above 400 A+D. Nosize:exceptionis permitted. If the clean diff exceeds 400, stop before publication and return to design for another causal split. Do not line-golf the diff or remove the authority tests.