Files
ss-tools/specs/044-dashboard-scenario-execution/traceability.md

18 KiB

Traceability: Scenario Execution Engine (044)

Story Requirement Model API operationId Contract Task Test Actual status / gap
US1 Start SCEX-FR-001/008 ScenarioRun scenarioRun.start Execution.Start, Execution.Runner.QueuedDispatch T006-T008, T024 test_runner, test_scenario_queued_dispatch, test_scenario_scheduler_callbacks, test_scenario_runs_api, test_scenario_automation_api, test_live_execution_binding [~] HTTP/automation start and replay persist queued/pending rows without request-time dispatch; only the scheduler composition's durable queued->running CAS walks its winner. Fixed scheduler callback registration, database-edge containment, and repeat-tick terminal side-effect idempotency are unit-proven. Automated human plans are rejected before they reach CAS/walker; a manual human graph reaches HumanCheckpoint only after that dispatcher claim. Approval-to-real live dispatch remains unproven.
US2 Dispatch SCEX-FR-002/006/009 ScenarioStepRun, LiveExecutionBinding scenarioRun.step Execution.Dispatch, Execution.LiveCompositionRoot T009-T011, T024 test_dispatch, test_scenario_executors, test_live_execution_binding [~] Browser/Superset/Screenshot use fail-safe typed adapter boundaries: no explicit adapter success means no PASS; invalid evidence digest/ref remains inconclusive. Lifespan bootstraps settings.scenario_live_execution_bindings through the existing SupersetClient, exact model and durable storage, so configured Superset dispatch invokes 037 and stores the exact raw-byte digest/ref; mismatched/unavailable providers make no I/O call. Browser safe-checkpoint and Screenshot durable-evidence registration are supported but no provider is deployed, so enabled bindings return stable configured-unavailable codes.
BrowserProvider SCEX-FR-016..023 BrowserProviderActionContract, BrowserOperationReceipt, BrowserEvidenceReceipt scenarioRun.step ScenarioExecution.BrowserProvider T028-T034, T040-T042, T042b test_provider_browser_*, Browser PREPROD canaries [~] Contract completeness is 90/100: all actions, risk classes, limits, lifecycle, checkpoint/recovery, ownership, cancellation/reconciliation, readiness and canary gates are specified. Runtime provider, shared capacity integration, deployment registration and real canary evidence remain open.
US3 Human SCEX-FR-004/010 ScenarioRun(waiting_human) scenarioRun.humanDecision Execution.SuspendForHuman, Execution.Resume T012-T014, T025 test_human_resume, test_scenario_runs_api [~] persisted HumanCheckpoint and infrastructure-resume continuations advance only the missing DAG frontier; completed steps are not re-run. Full live-composition closure remains pending.
Manual-only boundary SCEX-FR-004a ScenarioRun, HumanCheckpoint — Execution.Runner.Start, RunnerPlan.Derive T027 test_scenario_manual_run_only, test_scenario_automation_api [x] Trusted scheduled/deploy/release/ETL/API origins reject persisted human revisions before idempotency or any run/gate/notification/queue side effect. Manual origin remains eligible; HumanCheckpoint is not an approval gate.
Automated human prohibition SCEX-FR-004a/013, SCAUTO-FR-001/007 RunnerPlan.manual_run_only — Execution.Runner.TriggerSource, Automation.Trigger T027, 046 T016/T019 test_scenario_manual_run_only, test_scenario_automation_api, test_scenario_automation_trigger [x] Every trusted non-manual origin, including scheduled, deploy, release, ETL, API and background recovery, is rejected before idempotency/run/gate/notification/queue/dispatch side effects. Only authenticated manual origin may create a human-containing run.
US4 Lifecycle SCEX-FR-005/006 ScenarioRun(status, cancel deadline), ScenarioArtifact(active projection) scenarioRun.cancel, scenarioRun.retry Execution.Lifecycle.Cancel, Execution.Lifecycle.Timeout, Execution.Lifecycle.Retry, Execution.Runner.ContinueAfterRetry T014g, T015-T016, T025 test_scenario_lifecycle, test_scenario_cancel_timeout, test_scenario_retry_closure [~] Strict eligible retry invalidates the persisted target/descendant closure, archives old step attempts, and retains artifact rows only as inactive historical provenance. Cancellation pins a durable bounded drain deadline; deadline finalization expires leases and retires active projections without deleting audit evidence. A timeout during adapter I/O wins over a late PASS and materializes every otherwise-lazy pinned-plan descendant as blocked, so continuation cannot dispatch it; it emits one idempotent inconclusive signal. Full live-I/O composition remains fail-closed/unproven.
US5 Snapshot/API SCEX-FR-003/007 ScenarioExecutionResult scenarioRun.detail, scenarioRun.events Execution.RunnerPlan, Execution.Runner.CrashRecovery T017-T020, T025 test_result, test_api, test_scenario_runner_walker, test_scenario_crash_recovery [~] API/projection and real-digest artifact integrity checks exist. Server-driven crash recovery uses only the persisted run/RunnerPlan and expired lease: completed work is not rerun, safe claims get a new attempt with active evidence retired to history, unsafe claims require reconciliation, and browser recovery without a pinned safe checkpoint is non-pass without adapter I/O. Rejected terminal contexts reuse their idempotent signal. Production live-executor provenance remains unproven.
Terminal signals SCEX-FR-011 InvestigationQueueItem — Execution.Runner.TerminalSignal T026 test_scenario_terminal_signals [x] Failed/blocked/inconclusive terminal runs emit one idempotent immutable 047 queue input with run/artifact provenance; passed runs emit none. Producer-only ingestion starts no case, AgentRun, chat, remediation action, or recurrence classification.
Gate/RBAC SCEX-FR-008 ScenarioRun, ActionApprovalGate scenarioRun.start Execution.EnvironmentPolicy, Execution.Runner.Start T019 test_scenario_runner, test_scenario_runs_api, test_scenario_automation_api, test_scenario_automation_trigger [~] Server ConfigManager classifies every target before persistence: client flags cannot select PROD, unknown targets create no run-side effect, and every trusted source enters the same durable pending_approval gate boundary. HTTP/trigger paths remain persistence-only and dispatcher excludes pending gates. A dedicated real APScheduler scheduled-PROD integration test remains coverage debt; this is not a dispatch bypass.
Provider protocol SCEX-FR-017..023 ProviderExecutionContext, ProviderOperationReceipt, ProviderEvidenceReceipt — ScenarioExecution.ProviderProtocol, ProviderOperations, ProviderOperations.Observability T028-T031, T040-T042 test_provider_contract, test_provider_health, deployment health checks [ ] New production gate: common context/result, operation receipts, ownership proof, cancellation/reconciliation, health/readiness and startup registration are specified but not implemented.
Capacity SCEX-FR-024 CapacityLease, ExecutionCapacityManager — ScenarioExecution.CapacityManager T032, T041-T042 test_provider_capacity, scheduler/worker integration [ ] New production gate: shared environment-scoped capacity admission is specified but current 046 checks do not close it.
Agent evaluation SCEX-FR-025 AgentEvaluation, DecisionPolicy — ScenarioExecution.ProviderCatalog, data-model AgentEvaluation and DecisionPolicy T039, T041-T042 test_provider_agent_evaluation [ ] New production gate: bounded provider, immutable evaluation evidence and deterministic policy mapping are specified but absent.
Success criteria SC-001 RunnerPlan, ScenarioStepRun — ScenarioExecution.RunnerPlan.Derive, ScenarioExecution.Dispatch T004-T011, T041 canonical fixture order and duplicate-dispatch assertions [~] Existing fixture/lifecycle coverage passes; exact 100% canonical dispatch evidence remains a release gate.
Success criteria SC-002 HumanCheckpoint, ScenarioRun scenarioRun.humanDecision ScenarioExecution.HumanCheckpoint, ScenarioExecution.Resume T012-T014, T025 human CAS/frontier tests [x] Human checkpoint CAS and missing-frontier resume are verified; live provider closure remains separate.
Success criteria SC-003 ScenarioRun.cancel_drain_deadline_at scenarioRun.cancel ScenarioExecution.Cancel T015-T016, T025, T041 100 cancellation trials plus scheduler finalizer [~] Bounded drain is unit-proven; required 100-trial production evidence is open.
Success criteria SC-004 RunnerPlan, worker lease, operation receipt scenarioRun.detail ScenarioExecution.Runner.CrashRecovery, ScenarioExecution.ProviderOperations T014c, T025, T030, T041 safe/unsafe recovery and reconciliation tests [~] Safe/unsafe persisted recovery is verified; provider operation reconciliation is not implemented.
Success criteria SC-005 immutable run provenance scenarioRun.result Execution.RunnerPlan, Execution.Result T017, T020, T041 revision-edit immutability and evidence receipt tests [~] Snapshot fields exist; complete receipt-level byte identity evidence is open.
Success criteria SC-006 ActionApprovalGate, ExecutorRegistry scenarioRun.start Execution.ActionApprovalGate, ScenarioExecution.ExecutorRegistry T014d, T019, T041 PROD no-call and human-not-executor tests [x] Current no-call and registry rejection tests pass.
Success criteria SC-007..010 Provider protocol/health/capacity — ScenarioExecution.ProviderProtocol, ProviderOperations.Observability, CapacityManager T028-T042 common/provider-specific contract and deployment profiles [ ] New production gate not implemented.
Success criteria SC-011 release evidence record — ScenarioExecution.ProviderProtocol T022, T041-T042 full profiles, PostgreSQL and semantic audit outputs [ ] Release evidence package is incomplete.

N/A: Registry (042), Editor (043), Monitor UX (045), Automation (046), Analytics (047).

Cross-Spec Pipeline Traceability

Stage / requirement 044 authority Handoff / ownership Evidence
persisted revision is the only launch program input ScenarioExecution.RunPreflight 042 ScenarioRevision -> preflight handle test_scenario_runner, test_scenario_automation_api
server-owned preflight digest and failure boundary ScenarioExecution.RunPreflight blocks before plan, lease, dispatch or provider I/O test_scenario_runner, policy/binding tests
deterministic plan and plan digest ScenarioExecution.RunnerPlan.Derive preflight -> pinned RunnerPlan -> run test_scenario_runner_plan, test_scenario_dispatch
queued/pending approval continuation ScenarioExecution.Start, ScenarioExecution.ActionApprovalGate approved pending run -> queued; denial/expiry -> blocked test_scenario_queued_dispatch, test_scenario_automation_api
ScenarioRun snapshot and idempotency ScenarioExecution.Start / ScenarioRun model exact revision/content/target/principal/binding snapshot test_scenario_runs_api, test_scenario_scheduler_callbacks
evidence ownership and authoritative StepOutcome ScenarioExecution.ProviderProtocol, ScenarioStepRun provider receipt -> Artifact(owner_type=scenario_run) -> StepOutcome test_provider_contract, test_scenario_terminal_signals
terminal signal to 047 ScenarioExecution.TerminalSignal failed/blocked/inconclusive -> idempotent 047 queue input; passed -> none test_scenario_terminal_signals
no reference artifact authority ScenarioExecution.RunnerPlan.Derive runner.plan.json is diagnostic/reference only test_scenario_runner_plan, crash-recovery tests
authoring promotion admission ScenarioExecution.AuthoringAdmission 042 promoted revision -> 044 preflight raw-artifact rejection, candidate-without-promotion, no-run sandbox tests

All rows are required together with the 038/042/050 matrices. Provider, capacity, PostgreSQL, or live-composition gaps keep the coordinated release gate NO-GO, even when lifecycle unit tests pass.

Authoring E2E is additionally NO-GO until persistent workspace exploration, typed proposal conversion, user diff review, 042 handle-based save, and 044 promoted-revision-only admission are evidenced. Sandbox security and code-backed provider readiness are separate gates and remain unimplemented unless explicitly proven.

Provider production boundary: Existing typed unavailable outcomes and exact Superset binding tests prove only the fail-closed boundary. Production readiness additionally requires T028-T042 and real startup/dependency health checks for every enabled live provider.

BrowserProvider boundary: The BrowserProvider is contract-ready at 90/100 but implementation-ready only after T034, T040-T042 and T042b. A typed unavailable result remains the correct behavior until the PREPROD read-only/timeout/cleanup/reconstruction canaries produce retained operation and evidence receipts.

Cross-spec production boundary: 044 readiness depends on 036 authority/evidence, 037 query and baseline provenance, 038 executable graph identity, 041 lineage target state, 042 registry revisions, 046 automation dispatch and 047 terminal-signal/case ingestion. 039/043/045 are operator continuity dependencies: they do not authorize execution, but incomplete typed API/SSE/revision flows prevent a complete production workflow. Current dependency-weighted aggregate for 036-047 is approximately 67/100 and remains NO-GO.

Full production tool boundary: There is no reduced preview target. Browser/Screenshot, controlled non-PROD mutation, AgentEvaluation/DecisionPolicy, automated schedules/triggers, case investigation, analytics and remediation are mandatory capability gates. Missing or unproven capability blocks GO; only human-containing automated revisions remain prohibited and PROD mutation remains policy-forbidden.

Verification boundary (2026-08-24): the available local profile is 246 backend tests, 59 provider/ lifecycle edge tests, scoped Ruff/compile and prototype validation. Real PostgreSQL migration checks, provider contract T028-T042, live Browser/Screenshot composition, scheduler deployment and Axiom index rebuild remain open.

Production acceptance traceability — 2026-09-08

Historical rows above identify prior tests/code only; removed agent UI paths are retired. The following audited gates are implemented=false / OPEN, independent of local suite totals.

Requirement Domain contract / DTO Task Falsifiable acceptance State
SCEX-FR-028 Production baseline-backed evaluation; data model T043 Baseline set/version/catalog/release/commit/IDs/digests affect idempotency; moving catalog after admission cannot change plan/result; legacy unpinned result is ineligible. OPEN
SCEX-FR-028 Production baseline-backed evaluation; data model T044 GET/HEAD prove same ACL/status/headers; MIME/digest/length checked before bytes, cross-owner hidden, expired410, corrupt409, traversal/range/oversize rejected. OPEN
SCEX-FR-028 Production baseline-backed evaluation; data model T045 Startup/readiness/start-loop and shutdown/drain/cancel/reconcile survive fault injection; unknown effect quarantines capacity; late response cannot win. OPEN
SCEX-FR-028 Production baseline-backed evaluation; data model T046 End-to-end real browser→capture→durable artifact→deterministic comparison→optional immutable evaluation→policy→result; all required evidence present before PASS. OPEN
SCEX-FR-028; external-MCP-only UI manual editor/review; read-only evidence production tasks No frontend agent prompt/chat/assistant editing/proposal generation/workspace/start/handoff routes or requests; human approval remains usable. OPEN

Sources: production gap, coverage gap, baseline gap. Spec schema/static checks prove contract structure only; live canary/runtime closure and optional approved performance baseline are not claimed.

Live-binding admin surface + catalog publisher — evidence 2026-09-11

Two deployment/operator seams added by commits 792bb125 + d04927bd; both are server-owned surfaces outside the 050 MCP catalog (no spec row existed before this note):

Seam Contract Surface Evidence
Api.ScenarioLiveBindings ScenarioExecution.LiveBinding + Core.ConfigManager admin REST GET/PUT/PATCH /api/scenario-live-bindings (admin:settings); validates LiveExecutionBinding.from_snapshot + DashboardQueryModel (env/dashboard/fingerprint) and writes settings.scenario_live_execution_bindings atomically backend/tests/api/test_scenario_live_bindings_api.py (7); first live exercise: re-registered ss-prod-d11-live-001 with the correct principal, then the T029m run adopted it server-side
Tooling.PublishCatalog T045/D7 published-catalog source (PUBLISHED_CATALOG_*) CLI backend/src/scripts/publish_catalog.py — pre-validates catalog bytes, then Gitea contents PUT (typed auth/conflict/unavailable) backend/tests/scripts/test_publish_catalog.py (7, offline); publication itself blocked on a valid Gitea PAT

Cross-reference: the live external MCP replay that exercised the binding path end-to-end (and exposed the identity-less-compiled-step defect) is docs/2026-09-11-sales-prod-mcp-replay.md (050 T029m / E2E-EXT-002, CLOSED).