Repository-map V1c backend (#3461)
This is the first server-side producer. It ships with generation disabled. It is not live provider acceptance or client acceptance: client#889 and the separately authorized disposable beta run remain required. The existing registration API still only registers repository metadata; it does not claim that a map exists.
Setup and recovery
RepoMapGenerationService.ConfigureRepoMapGenerator requires the registry's
existing L3 manage gate and invokes one actual owner write per call. Supply an
explicit endpoint/model, finite agent budget, clearance, automatic interval and
daily allowance, and consent to the versioned baseline. No proposed 60-minute,
12-per-day or 5M-token suggestion is silently saved. Follow step_remaining using
the returned revision until the writes are complete. Repeating unchanged desired
state resumes committed stages. A changed revision uses compare-and-swap.
The owner's stronger requirements still apply: agent registration/deployment, finite agent budget and binding requests retain their original gates. In particular the budget/binding L4 requirements are not reduced by the outer L3 gate. Model/clearance changes to an already created agent are refused because there is no owner update operation for them. Use the owning service to repair a later removed cap or disabled model; setup does not replay old privileged writes.
Binding approval is independent: another eligible L4 unit Manager approves on Models & Budget. Rejection includes the actual reason. Re-request supplies the exact rejected binding ID, preserves the original decision, and creates a fresh pending binding; it never approves itself. Endpoint activation retains its L5 owner gate. Missing Manager, unavailable dependencies, pending approvals and old projections remain distinguishable after reload.
The Context Engine rechecks committed setup independently of provider capacity.
A healthy transition queues one deduplicated access-ready intent per target,
setup/readiness transition and credential/binding epoch. It performs no delegated
owner write. GetRepoMapGenerator marks observations older than two five-minute
intervals stale. RegenerateRepoMap uses an explicit request UUID; aliases keep
coalesced manual retries idempotent even after admission. ListRepoMapRuns exposes
bounded scope-qualified status/history without source bodies or secret material.
Execution and evidence
The Go worker uses the team's V1b connection and verified singleton repository identity. It reserves a complete 48-attempt default plan from measured known provider quota, protects discovery's allocation, persists wire pacing, and waits without consuming an automatic admission when capacity is unavailable. The snapshot is pinned to a commit and has a complete bounded manifest. Defaults are 32 sampled bodies with 8 KiB excerpts; hard limits are 80 requests, 10,000 tree entries, 48 bodies, 16 KiB per body and 512 KiB total selected source.
Source is process memory only. Terminal cleanup clears sampled buffers; a watchdog cancels stale/revoked/offboarded execution. There is no checkout to retain or orphan. Expired execution leases become stalled without replaying paid work. There is no access/read lease. Restrictive evidence and clock-expired credentials withhold the existing map using exact current credential/binding/execution fences; a late success cannot clear a human denial.
Each stage directly mints a new short-lived LLM-audience token for its stored org/team/agent tuple. There are no normal sessions, tools, provider keys, transcripts, extraction, Temporal or agent-worker dependencies. The shared repo-map baseline and finite configured AGENT grain are also enforced at MG. Default execution is one draft and at most one repair, without resending source. Cumulative limits remain eight calls, 128k input, 16k output, 64 KiB result and a 15-minute run deadline. Source collection reserves at most ten minutes before the model/apply allowance; final access/head observation occurs before publication.
A server-generated receipt identifies the actual llm_usage_events row. Its
org/team/agent, endpoint/model and complete permitted usage must reconcile before
publication. A missing or mismatched event blocks success and increments the
unreconciled-usage alert metric. Successful HTTP/model text alone is insufficient.
The existing PutRepoMap RPC remains available for legacy/manual maps. It cannot
name an admitted V1c run or replace a map already published by the governed
producer; those operations require RegenerateRepoMap. The target lock makes
the compatibility check atomic with first governed publication. This is not a
retirement of the shipped manual API.
Governed publication applies existing section locks/divergences atomically with the exact
run, sequence, epoch and usage proof. Coverage belongs to the published run,
including historical reads, rather than the newest attempt or a curatable
purpose section. The common 24,000-byte renderer reserves mandatory notices and
do_not_touch; related repositories remain explicitly unexamined until the
separate extractor work. No relationship is inferred by this slice.
Validation and activation boundary
Pinned offline measurements and reproduction commands are in
internal/repomapgen/testdata/snapshot-fit.md. They use the production serialized
model request; they do not measure live provider/model latency or output quality.
The admin pin is a scaffold and truthfully fails the minimum recipe, while core,
client and web provide real source trees.
scripts/test-repomap-tenant-profile.sh --provider github --disposable-only
requires an explicitly supplied loopback scratch database. It checks the tenant
composition and executes actual SQL producer/setup/publication proofs with
synthetic HTTP leaves and no-skip guards. --scenario beta-readiness checks the
same offline boundary; it does not deploy, contact a provider, or prove ingress.
REPO_MAP_GENERATION_ENABLED and
REPO_MAP_KNOWN_DENIAL_READ_POLICY_ENABLED default off. Generation startup requires
the latter protection, a ready vault, platform signer and governed MG origin.
Merge changes no deployed switch. Founder D3/ADR#3474 still restrict FastRouter
activation to the approved UpsQuad beta organization; on-prem is not licensed to
use that hosted route. Retained run provenance is generated metadata, not a
30-day source workspace. Existing generic usage-erasure pseudonym/FK behavior
is tracked in core#3545; the receipt-specific tests do not claim that broader
RTD path is repaired.
Migration 255 adds a composite unique key to the usage ledger with an exclusive DDL lock. Before any separately authorized production application, assess ledger size and lock duration in a representative maintenance rehearsal; beta proof is not a production lock-time measurement.