feat(stage2): add S2_00 AgentBackend spec

Keep the adapter non-executable until the native loader primitive and signed runtime admission contracts are bound.
This commit is contained in:
2026-08-30 03:05:06 +09:00
parent 0ac7223790
commit 388a6c0179
5 changed files with 1932 additions and 0 deletions
@@ -0,0 +1,531 @@
Agent:
name: Stage_2_S2_00
description: >-
현행 Stage 1 Part 1-4 산출물을 release-bound fixed runtime으로 검증·보존·정규화하고,
claim-neutral cluster slice와 prompt bundle plan을 작성하기 위한 S2_00 선언형 작업명세서.
이 문서는 AgentBackend의 외부 고정 .py 호출 primitive가 검증되기 전에는 실행형 스크립트가 아니다.
version: "1.0.0-draft-candidate-a"
metadata:
workflow_id: S2_00
execution_class: NON-LLM-DETERMINISTIC
specification_role: DECLARATIVE_AGENT_WRAPPER
specification_status: DRAFT_NOT_EXECUTABLE
authorization_status: DEV_VALIDATION_ONLY
invocation_status: OPEN_EXTERNAL_BACKEND
runtime_activation_allowed: false
owner: Stage_2_workflow_maintainer
strategy_ref: stage_2_optimal_update_strategy_v.4.md
sow_ref: S_00_SOW.md
canonical_deployment_root: Default_Agent/Stage_2_Clean
canonical_workflow_ref: >-
Default_Agent/Stage_2_Clean/workflows/S2_00_stage1_ingress_normalize_and_bundle_compile.yml
loader_binding_ref: >-
Default_Agent/Stage_2_Clean/deployment/stage2_loader_binding.yml
release_ref: Default_Agent/Stage_2_Clean/manifest/stage2_release.json
legacy_stage2_dependencies: []
Stages:
- name: S2_00
description: >-
C00 -> C05 -> C10 -> C15를 고정 순서로 수행한다. 정상 package는 S2_10 handoff를,
minimum coherent package를 만들 수 없는 경우에는 S2_40 status-only handoff를 준비한다.
최종 상태·법률판단·소송문안·seal·commit은 작성하지 않는다.
prevs: []
nexts: []
tasks: []
x_agentbackend_execution_gate:
field_namespace_status: DECLARATIVE_EXTENSION_NOT_NATIVE_PRIMITIVE
executable_from_this_yaml: false
blocker_id: O-06
blocker_status: OPEN_EXTERNAL_BACKEND
blocker_reason: >-
현재 확인된 Agent Script 문법에는 release-bound 외부 고정 .py를 직접 호출하는 native task
primitive가 없다. 따라서 Direct MCP, code-executor, shell 또는 인라인 Python으로 우회하지 않는다.
required_closure_evidence:
- BACKEND_OWNER_APPROVED_FIXED_ENTRYPOINT_ADAPTER_SYNTAX
- LIVE_LOADER_INVOCATION_RECEIPT
- LOADER_BYPASS_NEGATIVE_TEST_PASS
allowed_until_closed:
- STATIC_CONTRACT_VALIDATION
- LOADER_VALIDATE_ONLY
- DEV_FIXTURE_TEST_HARNESS
forbidden_until_closed:
- AGENTBACKEND_CASE_RUN_INVOCATION
- SUBSET_CANARY_EXECUTION
- PRODUCTION_EXECUTION
x_s2_00_contract:
identity:
workflow_id: S2_00
module_id: WF-S2_00
workflow_schema_version: stage2_workflow_contract.v1
asset_version: s2_00.1
execution_class: NON-LLM-DETERMINISTIC
canonical_assets:
workflow:
asset_id: WF-S2_00
path: workflows/S2_00_stage1_ingress_normalize_and_bundle_compile.yml
loader:
asset_id: LOADER-STAGE2
path: release_ops/stage2_loader.py
loader_binding:
asset_id: BINDING-S2_00
path: deployment/stage2_loader_binding.yml
fixed_runtime:
asset_id: RUNTIME-S2_00
path: runtime/s2_00_ingress.py
release_manifest:
asset_id: MANIFEST-STAGE2-RELEASE
path: manifest/stage2_release.json
module_manifest:
asset_id: MANIFEST-MODULE
path: manifest/module_manifest.json
schemas:
ingress: schemas/ingress.schema.json
context: schemas/context.schema.json
deployment: schemas/deployment.schema.json
review_status: schemas/review_status.schema.json
cache_policy: registry/cache/prompt_cache_policy.yml
regression_manifest: tests/fixtures/regression_manifest.json
asset_resolution_policy:
root: Default_Agent/Stage_2_Clean
path_source: SIGNED_RELEASE_AND_LOADER_BINDING_ONLY
physical_hash_verification_required: true
directory_scan_allowed: false
glob_fallback_allowed: false
fuzzy_basename_allowed: false
legacy_fallback_allowed: false
execution:
trust_boundary: release_ops/stage2_loader.py
loader_bypass_allowed: false
loader_invocation_contract_status: OPEN_EXTERNAL_BACKEND
fixed_runtime_entrypoint: runtime/s2_00_ingress.py
component_order:
- C00
- C05
- C10
- C15
component_contracts:
C00:
purpose: exact ingress, bounded snapshot, source lock, strict parse
function_refs:
- resolve_stage1_sources
- load_release_lock
- open_bounded_snapshot
- load_json_strict
- validate_ingress_contracts
- expand_stage2_signal_all
- verify_activation_projection
- verify_cross_artifact_seals
C05:
purpose: independent multiset and review conservation
function_refs:
- normalize_review_items
- check_conservation
C10:
purpose: source-bound context, crosswalk and base issue ledger
function_refs:
- build_case_context
- build_evidence_inventory
- build_object_registry
- build_party_and_title_context
- build_slot_crosswalk
- mint_stage2_id
- mint_context_occurrence_id
C15:
purpose: claim-neutral cluster, SCC DAG, immutable slices and bundle plan
function_refs:
- compile_cluster_plan
- compile_cluster_slices
- compile_bundle_plan
- validate_bundle_release_cohorts
- publish_atomically
timeout_policy_source: manifest/stage2_release.json
retry_policy_id: S2-RETRY-TRANSIENT-READ-V1
retry_policy_ref: manifest/stage2_release.json#/retry_policies/0
retryable_failure_class:
- TRANSIENT_READ
- TRANSIENT_LOCK
nonretryable_failure_class:
- HASH_MISMATCH
- SCHEMA_MISMATCH
- PRODUCER_MISMATCH
- CONSERVATION_MISMATCH
- RUN_ID_BINDING_CONFLICT
snapshot_and_parse_policy:
transport_class: RELEASE_BOUND_BYTE_PRESERVING_WORKSPACE_TRANSPORT
text_normalizing_transport_for_raw_digest_allowed: false
same_descriptor_one_read_required: true
raw_hash_parse_and_schema_use_same_buffer: true
strict_utf8_json_required: true
duplicate_json_key_allowed: false
nan_or_infinity_allowed: false
trailing_extra_object_allowed: false
resource_limits_source: manifest/stage2_release.json
snapshot_seal_before_and_after_required: true
source_snapshot_change_disposition: DISCARD_ATTEMPT
source_snapshot_change_issue_code: SOURCE_SNAPSHOT_CHANGED
invocation_request:
fixed_values:
workflow_id: S2_00
release_ref: manifest/stage2_release.json
host_supplied_values:
- run_id
- attempt_id
- stage1_run_root_ref
- stage1_deployment_root_ref
backend_session_values:
- user_context_sha256
- workspace_context_sha256
forbidden_caller_values:
- executable
- command
- source_code
- runtime_entrypoint
- output_root
- arbitrary_absolute_path
shell_allowed: false
arbitrary_command_allowed: false
release_binding:
release_class_allowed_while_o07_open:
- DEV_FIXTURE_RELEASE
current_release_status: DRAFT_NOT_EXECUTABLE
current_authorization_status: DEV_VALIDATION_ONLY
validate_only_expected_status: VALIDATED_WITH_PENDING_BINDINGS
signed_canary_admission_required: true
signed_production_admission_required: true
module_acceptance_is_production_release: false
input_roots:
stage1_run_root_ref:
source: backend_workspace_transport
arbitrary_absolute_path_allowed: false
stage1_deployment_root_ref:
source: stage2_release_dependency_lock
arbitrary_absolute_path_allowed: false
stage1_input_allowlist:
- logical_input_id: evidence_indexed
requirement_class: EVIDENCE_EVENT_SCOPE
exact_path: evidence_indexed.json
adapter_id: S2A-EVIDENCE-V3-ENVELOPE-V1
- logical_input_id: evidence_event_candidates
requirement_class: EVIDENCE_EVENT_SCOPE
exact_path: evidence_event_candidates.json
adapter_id: S2A-EVENTS-V1-ENVELOPE-V1
- logical_input_id: client_goal
requirement_class: OPTIMIZATION_CONTEXT
exact_path: client_goal.json
optional_json_pointers:
- /defendant_target_matrix
- /parties/defendants/*/asset_status
invented_sibling_files_allowed: false
- logical_input_id: domain_screening
requirement_class: ROUTING_PROFILE_BACKBONE
exact_path: routing/domain_screening.json
- logical_input_id: domain_activation_manifest
requirement_class: ROUTING_PROFILE_BACKBONE
exact_path: routing/domain_activation_manifest.json
adapter_id: S2A-DUAL-SG01-V1
- logical_input_id: b1_evidence_indexed_gate
requirement_class: INTEGRITY_CORROBORATOR
exact_path: quality_gates/B1_evidence_indexed_gate.json
- logical_input_id: b2_event_candidates_gate
requirement_class: INTEGRITY_CORROBORATOR
exact_path: quality_gates/B2_event_candidates_gate.json
- logical_input_id: stage1_part1_soft_gate_handoff
requirement_class: INTEGRITY_CORROBORATOR
exact_path: quality_gates/stage1_part1_soft_gate_handoff.json
adapter_id: S2A-P1-HANDOFF-FLAT-V1
- logical_input_id: bo
requirement_class: IDENTITY_BACKBONE
exact_path: BO.json
adapter_id: S2A-BO-V8-LIST-V1
- logical_input_id: signal_manifest
requirement_class: ROUTING_PROFILE_BACKBONE
exact_path: signals/signal_manifest.json
adapter_id: S2A-SIGNAL-ALL-V1
producer_alias_id: PA-SG-COMPILER-001
- logical_input_id: stage1_part2_review_handoff
requirement_class: INTEGRITY_CORROBORATOR
exact_path: quality_gates/stage1_part2_review_handoff.json
adapter_id: S2A-P2-HANDOFF-FLAT-V1
- logical_input_id: legal_effect_structures
requirement_class: ROUTING_PROFILE_BACKBONE
exact_path: legal_effect_structures.json
- logical_input_id: stage1_part3_review_handoff
requirement_class: INTEGRITY_CORROBORATOR
exact_path: quality_gates/stage1_part3_review_handoff.json
adapter_id: S2A-P3-HANDOFF-WRAPPED-V1
- logical_input_id: fact_ledger_base
requirement_class: IDENTITY_BACKBONE
exact_path: Fact_Ledger_base.json
adapter_id: S2A-FACT-LEDGER-CURRENT-V8-V1
- logical_input_id: fact_ledger_writer_report
requirement_class: INTEGRITY_CORROBORATOR
exact_path: stage1_tmp/fact_ledger/fact_ledger_writer_report.json
- logical_input_id: stage1_part4_review_handoff
requirement_class: INTEGRITY_CORROBORATOR
exact_path: quality_gates/stage1_part4_review_handoff.json
adapter_id: S2A-P4-HANDOFF-WRAPPED-V1
- logical_input_id: signal_payload_family
requirement_class: SIGNAL_PAYLOAD
exact_path_rule: signals/<signal_manifest.files[i].path>
manifest_order_preserved: true
stage1_deployment_contract:
dependency_lock_id: STAGE1-DEPLOYMENT-CLOSURE-2026-08-29
dependency_lock_ref: manifest/stage2_release.json#/dependency_locks/stage1
exact_concrete_path_count: 55
allowed_sources:
- runtime_manifest.json
- domains/_registry_index.json
- domains/<domain_id>/domain_config.json
- signals/signal_registry.v2.json
- manifest_or_registry_enumerated_platform_schemas
- manifest_or_registry_enumerated_signal_schemas
stage1_contract_manifest:
default_required: false
allowed_only_for_release_bound_relocation: true
new_logical_artifact_kind_allowed: false
producer_alias_ids:
- PA-SG-COMPILER-001
part1_digest_guard:
exact_keys:
- evidence_indexed_sha256
- evidence_event_candidates_sha256
- b1_gate_sha256
- b2_gate_sha256
- screening_sha256
- activation_manifest_sha256
- registry_index_sha256
recompute_from_raw_bytes: true
signal_policy:
downstream_read_set_exact:
- ALL
file_rows_preserve_manifest_order: true
physical_path_rule: signals/<files[i].path>
semantic_file_kinds:
- canonical
- domain_signal
integrity_only_file_kinds:
- compatibility_view
file_and_record_conservation_separate: true
record_occurrence_identity:
- manifest_transaction_id
- file_path
- record_ordinal
- signal_id
routing_sg01_ref: routing/domain_activation_manifest.json
signal_sg01_ref: signals/domain_activation_manifest.json
sg01_raw_hashes_preserved_separately: true
sg01_semantic_projection_comparison_required: true
conservation_policy:
upstream_status_trusted_without_recompute: false
preserve_stage1_ids_codepoint_exactly: true
normalize_raw_stage1_ids: false
bo_fact_ledger_set_cardinality_multiset_required: true
fact_id_sequence_rule: F-001..F-N
every_source_occurrence_has_one_disposition: true
unavailable_occurrence_receipt_preserved: true
review_occurrence_single_partition_required: true
fact_ledger_current_v8_required_keys:
- domain_effects
- calculation_requests
affected_scope_policy:
scope_technical_disposition_enum:
- AVAILABLE
- AVAILABLE_WITH_ISSUES
- UNAVAILABLE
impact_scope_enum:
- GLOBAL
- CLUSTER
- PARTY_CONTEXT
- OBJECT_CONTEXT
- FACT
- EVIDENCE
- SIGNAL
- REVIEW_ITEM
required_disposition_fields:
- scope_refs
- source_contract_row_refs
- reason_codes
- downstream_allowed_actions
occurrence_partition_must_be_disjoint_and_exhaustive: true
context_identity_policy:
source_ref_required_for_every_row: true
party_object_fuzzy_merge_allowed: false
stage1_canonical_id_preferred: true
occurrence_context_id_only_when_canonical_id_absent: true
unresolved_identity_issue_code: IDENTITY_UNRESOLVED
physical_path_or_parallel_ordinal_as_mint_input_allowed: false
cluster_policy:
legal_conclusion_allowed: false
case_type_id_creation_allowed: false
claim_option_id_creation_allowed: false
hard_join_predicates:
- SAME_BO_ID
- LES_SOURCE_BO_ID
- SAME_EVIDENCE_REF
- SAME_EVENT_REF
- APPROVED_EXPLICIT_CASE_RELATION
similarity_only_hard_join_allowed: false
domain_registry_depends_on_as_litigation_edge_allowed: false
cycles_preserved_as_scc: true
executable_and_residual_partitions_disjoint: true
bundle_policy:
plan_only: true
prompt_text_generation_allowed: false
static_prefix_classes:
- P00_SYSTEM_SAFETY
- P10_LEGAL_RESOLUTION
- ACTIVE_PROFILE
- APPROVED_COMMON_AUTHORITY
dynamic_tail_classes:
- CLUSTER_SLICE
- PRIOR_WAVE_NARROW_VERDICT_PLACEHOLDER
forbidden_bulk_inputs:
- FULL_137_CASE_CATALOG
- RAW_CORPUS
- ALL_RELIEF_MARKDOWN
- ALL_LAW_VALUE_ROWS
pii_in_static_prefix_allowed: false
cache_miss_is_quality_failure: false
prefix_hash_or_pii_failure_scope: COHORT_NON_EXECUTABLE
mode_release_mapping:
STRUCTURAL_FIXTURE: DEV_FIXTURE_RELEASE
SUBSET_CANARY: SUBSET_CANARY_RELEASE
PRODUCTION: PRODUCTION_RELEASE
structural_fixture_case_run_publish_allowed: false
structural_fixture_downstream_route_allowed: false
output_contract:
output_root_source: loader_bound_stage2_run_root
output_root_argument_allowed: false
normal_branch:
- ingress/stage1_input_manifest.json
- ingress/intake_report.json
- context/case_context.json
- context/evidence_inventory.json
- context/object_registry.json
- context/party_and_title_context.json
- context/slot_crosswalk.json
- context/cluster_plan.json
- context/cluster_slices/<cluster_id>.json
- context/bundle_plan.json
- review/issue_ledger.base.json
- ingress/ingress_status.json
diagnostic_branch:
- ingress/stage1_input_manifest.json
- ingress/intake_report.json
- ingress/technical_diagnostic.json
- review/issue_ledger.base.json
- ingress/ingress_status.json
ingress_status_written_last: true
normal_branch_technical_diagnostic_allowed: false
diagnostic_branch_partial_context_publish_allowed: false
whole_tree_atomic_publish_required: true
routing_contract:
normal_routes:
- TO_S2_10
- TO_S2_10_WITH_ISSUES
diagnostic_route: TO_S2_40_STATUS_ONLY
normal_route_requires_nonempty_executable_cluster_ids: true
status_only_exact_inputs:
- ingress/ingress_status.json
- ingress/technical_diagnostic.json
- ingress/stage1_input_manifest.json
- ingress/intake_report.json
- review/issue_ledger.base.json
final_status_writer: S2_40
s2_00_final_status_write_allowed: false
s2_00_control_run_status_write_allowed: false
minimum_coherent_package_predicate:
- SAME_RUN_FACT_AND_BO_IDENTITY_UNIVERSE_RESOLVABLE
- ALL_AVAILABLE_INCOMPLETE_AND_UNAVAILABLE_SCOPES_ENUMERATED
- EVERY_USED_AND_UNUSABLE_SOURCE_EXPLAINED_IN_MANIFEST_AND_ISSUES
- AT_LEAST_ONE_SCHEMA_VALID_EXECUTABLE_CLUSTER_SLICE_AND_BUNDLE
route_decisions:
TO_S2_10:
when:
- CORE_ANCHORS_AND_CONSERVATION_CONSISTENT
- EXECUTABLE_CLUSTER_IDS_NONEMPTY
TO_S2_10_WITH_ISSUES:
when:
- MINIMUM_COHERENT_PACKAGE_POSSIBLE
- RECOVERABLE_SCOPE_OR_REVIEW_ISSUES_EXIST
- EXECUTABLE_CLUSTER_IDS_NONEMPTY
TO_S2_40_STATUS_ONLY:
when_any:
- MINIMUM_COHERENT_PACKAGE_IMPOSSIBLE
- GLOBAL_RUN_OR_TRANSACTION_IDENTITY_CONFLICT
- TRUSTED_SOURCE_UNIVERSE_CANNOT_BE_ENUMERATED
- NO_CONSISTENT_EXECUTABLE_OR_RESIDUAL_SLICE
- RESIDUAL_ONLY_AND_EXECUTABLE_CLUSTER_IDS_EMPTY
- ALL_BUNDLE_COHORTS_NON_EXECUTABLE
not_a_standalone_diagnostic_reason:
- EVIDENCE_OR_EVENT_GATE_UNCERTAIN
- EVENT_DATE_UNRESOLVED
- CLIENT_GOAL_OR_OPTIONAL_TARGET_ASSET_ABSENT
- PARTIAL_DOMAIN_CONFIG_GAP
- UNRESOLVED_CONDITIONAL_EXCLUDED_OR_UNMAPPED_REVIEW_ITEM
- RECOVERABLE_JOIN_GAP
- DOWNSTREAM_CASE_TYPE_RULE_OR_CORPUS_RELEASE_ISSUE
- CACHE_MISS_OR_CACHE_SERVICE_UNAVAILABLE
idempotence_and_publish:
run_binding_tuple:
- input_set_digest
- stage2_release_digest
- algorithm_digest
- release_class
attempt_id_is_run_binding_input: false
same_tuple_output_requirement: BYTE_IDENTICAL
existing_same_digest_disposition: IDEMPOTENT_SUCCESS_AFTER_REVALIDATION
existing_different_digest_disposition: RUN_ID_BINDING_CONFLICT
publish_method: SAME_FILESYSTEM_WHOLE_TREE_ATOMIC_RENAME
prohibitions:
llm_calls_allowed: false
llm_configuration_allowed: false
prompt_body_allowed: false
inline_python_allowed: false
inline_schema_allowed: false
dynamic_code_allowed: false
runtime_package_install_allowed: false
arbitrary_external_network_allowed: false
approved_workspace_transport_is_external_egress: false
directory_scan_allowed: false
fuzzy_path_fallback_allowed: false
stage1_new_required_outputs: []
legacy_stage2_v0_v3_dependencies: []
old_stage2_runtime_fallbacks: []
legal_judgment_allowed: false
final_document_write_allowed: false
final_seal_or_commit_allowed: false
acceptance_boundary:
static_contract_validation_required: true
release_hash_closure_required: true
loader_validate_only_required: true
fixed_runtime_unit_property_tests_required: true
live_agentbackend_invocation_required_for_executable_claim: true
live_stage1_to_s2_00_e2e_required_for_implementation_complete_claim: true
s2_10_and_s2_40_handoff_mock_required: true
korean_lawyer_review_is_not_s2_00_module_acceptance: true
production_readiness_may_not_be_inferred_from_dev_fixture_pass: true
@@ -0,0 +1,317 @@
Agent:
name: Stage_2_S2_00
description: >-
Stage 1 Part 1-4의 현행 산출물을 대상으로 canonical S2_00 fixed runtime을
release-bound loader를 통해서만 호출하기 위한 AgentBackend adapter 계약 후보.
이 파일은 O-06이 닫히기 전에는 실행 가능한 Agent Script가 아니다.
version: "1.0.0-candidate-b"
metadata:
workflow_id: S2_00
execution_class: NON-LLM-DETERMINISTIC
artifact_role: AGENTBACKEND_LOADER_ADAPTER_CONTRACT
contract_schema_version: stage2_agent_loader_adapter_contract.v1-draft
owner: Stage_2_workflow_maintainer
implementation_status: FIXED_ASSETS_PRESENT_ADAPTER_OPEN
invocation_status: OPEN_EXTERNAL_BACKEND
release_class: DEV_FIXTURE_RELEASE
release_status: DRAFT_NOT_EXECUTABLE
authorization_status: DEV_VALIDATION_ONLY
runtime_activation_allowed: false
canonical_root_ref: Default_Agent/Stage_2_Clean
canonical_workflow_ref: >-
Default_Agent/Stage_2_Clean/workflows/S2_00_stage1_ingress_normalize_and_bundle_compile.yml
loader_binding_ref: >-
Default_Agent/Stage_2_Clean/deployment/stage2_loader_binding.yml
loader_ref: Default_Agent/Stage_2_Clean/release_ops/stage2_loader.py
release_ref: Default_Agent/Stage_2_Clean/manifest/stage2_release.json
source_of_truth_order:
- Default_Agent/Stage_2_Clean/manifest/stage2_release.json
- Default_Agent/Stage_2_Clean/deployment/stage2_loader_binding.yml
- Default_Agent/Stage_2_Clean/workflows/S2_00_stage1_ingress_normalize_and_bundle_compile.yml
duplicated_runtime_logic_allowed: false
duplicated_hash_binding_allowed: false
legacy_runtime_dependencies: []
old_stage2_fallbacks: []
stage1_new_required_outputs: []
Stages:
- name: S2_00
description: >-
AgentBackend가 검증된 native adapter로 canonical stage2_loader.py만 호출하고,
loader가 release·binding·asset closure를 검증한 뒤 C00→C05→C10→C15
fixed runtime을 실행하도록 하는 단일 deterministic stage의 계약 후보.
현재는 backend primitive가 검증되지 않았으므로 tasks를 의도적으로 비워 둔다.
prevs: []
nexts: []
tasks: []
activation_gate:
status: OPEN_EXTERNAL_BACKEND
agentbackend_runtime_activation_allowed: false
empty_tasks_meaning: NON_EXECUTABLE_CONTRACT_NOT_SUCCESSFUL_NOOP
required_closeout:
open_id: O-06
owner: AgentBackend_owner
evidence: >-
AgentBackend가 arbitrary command/path/source를 받지 않고 canonical
stage2_loader.py만 shell=false fixed argv로 호출했음을 입증하는 live receipt
post_closeout_actions:
- native adapter의 실제 schema와 task syntax를 이 파일에 명시한다.
- deployment/stage2_loader_binding.yml에 adapter identity와 raw hash를 결속한다.
- manifest/stage2_release.json을 재봉인하고 loader integration test를 실행한다.
- tasks가 비어 있는 현 후보를 production에 그대로 배포하지 않는다.
canonical_contract:
workflow_ref: workflows/S2_00_stage1_ingress_normalize_and_bundle_compile.yml
workflow_id: S2_00
execution_class: NON-LLM-DETERMINISTIC
entrypoint_ref: runtime/s2_00_ingress.py
loader_ref: release_ops/stage2_loader.py
binding_ref: deployment/stage2_loader_binding.yml
release_ref: manifest/stage2_release.json
component_order:
- C00
- C05
- C10
- C15
contract_import_policy:
mode: REFERENCE_CANONICAL_ASSET
inline_copy_allowed: false
runtime_logic_override_allowed: false
input_output_policy_override_allowed: false
backend_adapter_requirements:
primitive_name: null
primitive_schema: null
status: OPEN_EXTERNAL_BACKEND
required_semantics:
loader_only_invocation: true
direct_runtime_invocation_allowed: false
shell: false
arbitrary_command_allowed: false
arbitrary_executable_allowed: false
arbitrary_source_code_allowed: false
arbitrary_absolute_path_allowed: false
caller_selected_output_root_allowed: false
user_workspace_context_forwarding_required: true
byte_preserving_workspace_transport_required: true
loader_receipt_capture_required: true
prohibited_substitutes:
- INLINE_PYTHON_CODE_EXECUTOR
- DIRECT_RUNTIME_S2_00_INGRESS_CALL
- TEXT_NORMALIZING_RAW_DIGEST_TRANSPORT
- UNVERIFIED_MCP_TOOL_OR_ENDPOINT
loader_request_contract:
fixed_values:
workflow_id: S2_00
release_ref: manifest/stage2_release.json
backend_bound_values:
- argument_id: run_id
source: RUN_TUPLE_BINDING
raw_user_value_allowed: false
- argument_id: attempt_id
source: TRANSIENT_RETRY_BINDING
canonical_id_input_allowed: false
- argument_id: user_context_sha256
source: BACKEND_SESSION
raw_user_id_persist_allowed: false
- argument_id: workspace_context_sha256
source: BACKEND_SESSION
raw_workspace_id_persist_allowed: false
- argument_id: stage1_run_root_ref
source: BACKEND_WORKSPACE_TRANSPORT
arbitrary_absolute_path_allowed: false
- argument_id: stage1_deployment_root_ref
source: STAGE2_RELEASE_DEPENDENCY_LOCK
arbitrary_absolute_path_allowed: false
allowed_flags_in_order:
- --workflow-id
- --release-ref
- --run-id
- --attempt-id
- --user-context-sha256
- --workspace-context-sha256
- --stage1-run-root-ref
- --stage1-deployment-root-ref
positional_argument_count: 0
validate_only_is_runtime_invocation: false
release_and_integrity_gate:
authority: release_ops/stage2_loader.py
binding_id: S2-BINDING-S2_00-V1
required_checks:
- RELEASE_AND_BINDING_STRICT_PARSE
- AUTHORING_ROOT_AND_WORKSPACE_ROOT_CONFINEMENT
- WORKFLOW_LOADER_RUNTIME_SCHEMA_RAW_HASH_CLOSURE
- MODULE_MANIFEST_AND_RELEASE_ORACLE_CROSS_BINDING
- STAGE1_DEPENDENCY_LOCK_CLOSURE
- FIXED_ARGV_CONTRACT
- LEGACY_FALLBACK_EMPTY
- EXTERNAL_NETWORK_DISABLED
current_blockers:
- open_id: O-06
status: OPEN_EXTERNAL_BACKEND
- open_id: O-07
status: OPEN_RELEASE_AUTHORIZATION
- open_id: SNAPSHOT-SEAL-BIND
status: PENDING_SEQUENTIAL_BIND
- open_id: DEV-DETACHED-RELEASE-ENVELOPE
status: OPEN_RELEASE_AUTHORIZATION
current_execution_boundary:
authoring_validation_allowed: true
agentbackend_invoke_allowed: false
s2_10_handoff_allowed: false
s2_40_status_only_handoff_allowed: false
canary_or_production_allowed: false
stage1_ingress_binding:
source_contract_authority: >-
workflows/S2_00_stage1_ingress_normalize_and_bundle_compile.yml#/Agent/Stages/0/orchestration_contract/input_contract
default_input_count_excluding_manifest_expansion: 16
signal_manifest_expansion_family_count: 1
default_exact_logical_inputs:
- evidence_indexed.json
- evidence_event_candidates.json
- client_goal.json
- routing/domain_screening.json
- routing/domain_activation_manifest.json
- quality_gates/B1_evidence_indexed_gate.json
- quality_gates/B2_event_candidates_gate.json
- quality_gates/stage1_part1_soft_gate_handoff.json
- BO.json
- signals/signal_manifest.json
- quality_gates/stage1_part2_review_handoff.json
- legal_effect_structures.json
- quality_gates/stage1_part3_review_handoff.json
- Fact_Ledger_base.json
- stage1_tmp/fact_ledger/fact_ledger_writer_report.json
- quality_gates/stage1_part4_review_handoff.json
manifest_expansion_rule: signals/<signal_manifest.files[i].path>
optional_fields_only:
- client_goal.json#/defendant_target_matrix
- client_goal.json#/parties/defendants/*/asset_status
optional_fields_as_sibling_files_allowed: false
stage1_contract_manifest_default_required: false
directory_scan_allowed: false
glob_fallback_allowed: false
fuzzy_basename_allowed: false
fixed_runtime_contract:
runtime_ref: runtime/s2_00_ingress.py
direct_caller: release_ops/stage2_loader.py
other_callers_allowed: false
component_order:
- C00
- C05
- C10
- C15
component_responsibilities:
C00: EXACT_RESOLVE_STRICT_VALIDATE_SOURCE_LOCK
C05: INDEPENDENT_MULTISET_AND_REVIEW_CONSERVATION
C10: SOURCE_PRESERVING_CONTEXT_CROSSWALK_BASE_ISSUE
C15: CLAIM_NEUTRAL_CLUSTER_SLICE_BUNDLE_AND_ATOMIC_PUBLISH
llm_calls_allowed: false
external_network_access_allowed: false
dynamic_code_allowed: false
runtime_package_install_allowed: false
output_contract:
output_root_source: LOADER_BOUND_WORKSPACE_MAPPING
caller_selected_output_root_allowed: false
normal_branch:
route_values:
- TO_S2_10
- TO_S2_10_WITH_ISSUES
required_artifacts:
- ingress/stage1_input_manifest.json
- ingress/intake_report.json
- context/case_context.json
- context/evidence_inventory.json
- context/object_registry.json
- context/party_and_title_context.json
- context/slot_crosswalk.json
- context/cluster_plan.json
- context/cluster_slices/<cluster_id>.json
- context/bundle_plan.json
- review/issue_ledger.base.json
- ingress/ingress_status.json
ingress_status_written_last: true
technical_diagnostic_allowed: false
diagnostic_branch:
route_values:
- TO_S2_40_STATUS_ONLY
exact_artifacts:
- ingress/stage1_input_manifest.json
- ingress/intake_report.json
- ingress/technical_diagnostic.json
- review/issue_ledger.base.json
- ingress/ingress_status.json
context_publish_allowed: false
whole_tree_atomic_publish_required: true
partial_publish_allowed: false
final_status_writer: S2_40
s2_00_final_status_write_allowed: false
route_contract:
route_source: ingress/ingress_status.json
route_schema_ref: schemas/ingress.schema.json#/$defs/ingress_status
route_after_successful_loader_invoke_only: true
branches:
TO_S2_10:
downstream_workflow_id: S2_10
executable_cluster_required: true
TO_S2_10_WITH_ISSUES:
downstream_workflow_id: S2_10
executable_cluster_required: true
TO_S2_40_STATUS_ONLY:
downstream_workflow_id: S2_40_STATUS_ONLY
exact_input_count: 5
agentbackend_route_activation_status: OPEN_EXTERNAL_BACKEND
retry_and_idempotence:
retry_policy_ref: manifest/stage2_release.json#/retry_policies/0
retry_policy_id: S2-RETRY-TRANSIENT-READ-V1
retry_policy_literals_duplicated_here: false
retryable_class: TRANSIENT_READ_OR_LOCK_ONLY
semantic_or_integrity_failure_retry_allowed: false
run_tuple_material:
- input_set_digest
- stage2_release_digest
- algorithm_digest
- release_class
same_run_tuple_byte_identical_required: true
different_run_tuple_requires_new_run_id: true
conflicting_existing_output_overwrite_allowed: false
prohibitions:
llm_provider_field_allowed: false
llm_model_field_allowed: false
prompt_body_allowed: false
inline_python_allowed: false
inline_schema_allowed: false
direct_runtime_call_allowed: false
arbitrary_mcp_endpoint_allowed: false
external_network_access_allowed: false
directory_scan_allowed: false
fuzzy_path_fallback_allowed: false
raw_stage1_id_normalization_allowed: false
claim_or_case_type_generation_allowed: false
old_stage2_dependency_allowed: false
fixture_success_as_production_evidence_allowed: false
acceptance_contract:
executable_yaml_acceptance_deferred: true
defer_reason: O-06_OPEN_EXTERNAL_BACKEND
non_execution_static_checks:
- YAML_STRICT_PARSE
- CANONICAL_REFERENCE_PATHS_EXIST
- NO_LLM_OR_PROMPT_OR_INLINE_CODE
- LEGACY_V0_V3_DEPENDENCY_COUNT_ZERO
- FIXED_ARGV_MATCHES_LOADER_BINDING
- RELEASE_STATUS_REMAINS_DRAFT_NOT_EXECUTABLE
completion_claim_allowed_now: CONTRACT_CANDIDATE_ONLY
@@ -0,0 +1,119 @@
# S2_00 AgentBackend YAML 구현
## Objective
`S_00_SOW.md`와 Stage 2 v4 계약을 그대로 실행 경계로 삼아, 이미 배포된 `Default_Agent/Stage_2_Clean/` 고정 자산을 소비하는 독립 실행용 `Stage_2_S2_00.yml`을 작성한다.
## Deliverables
- `YAML_Prompts/2. Stage_2/Stage_2_S2_00.yml`
- `YAML_Prompts/2. Stage_2/MEMORY.md`의 압축 작업 기록
- 후보 2개, 앙상블, 2회 독립 병렬 평가의 검증 근거
## Scope and Non-Scope
- 범위: AgentBackend orchestration YAML, loader/runtime 호출 계약, deterministic 분기·출력·오류 전파, 정적 검증.
- 비범위: 신규 Python 구현, 법률 content 보강, Stage 1 live 실행, production admission, 외부 서명·법률가 승인.
## Known Inputs
- `YAML_Prompts/2. Stage_2/S_00_SOW.md`
- `YAML_Prompts/2. Stage_2/stage_2_optimal_update_strategy_v.4.md`
- `YAML_Prompts/2. Stage_2/SKILL.md`
- `YAML_Prompts/2. Stage_2/Default_Agent/Stage_2_Clean/`
- `YAML_Prompts/2. Stage_2/Prompt_stage_2_S2_00_assets_creation.txt`
## Material Assumptions
- 사용자 문구의 `S2_00_SOW.md`는 저장소 정본 파일명 `S_00_SOW.md`를 가리킨다.
- 최종 YAML은 Main working directory에 저장하며, 고정 Python의 내용을 인라인 재구현하지 않고 배포 자산을 호출한다.
## Questions That Could Change the Outcome
- 없음. 경로·실행 경계는 정본 SOW, 배포 binding 및 로컬 YAML 가이드에서 확인한다.
## Workstreams and Dependencies
1. 정본 계약과 실제 배포 자산의 일치 여부를 조사한다.
2. 독립 후보 YAML 2개를 병렬 설계한다.
3. Main agent가 계약별 장점을 취합해 단일 초안을 작성한다.
4. 독립 evaluator 2개로 Round 1 평가 후 증분 개정한다.
5. 새 evaluator 2개로 Round 2 평가 후 증분 개정한다.
6. 구문·DAG·경로·금지 edge·MEMORY를 검증한다.
## Source and Tool Plan
- 로컬 정본 문서와 실제 파일을 우선한다.
- `rg`, YAML parser, 프로젝트 테스트와 읽기 전용 sub-agent 감사를 사용한다.
- 외부 웹 조사나 외부 write는 수행하지 않는다.
## Validation Plan
- YAML parse 및 Agent/Stages/task_procedure/tasks 연결 검증
- 모든 참조 자산의 존재·NFC 경로 검증
- loader/runtime 호출·상태 분기·single writer·구 v.0~v.3 dependency 0 확인
- 독립 평가 2개 × 정확히 2회
- staged/working tree의 무관 파일 비변경 확인
## Approval Boundaries
- 요청된 로컬 파일 생성·검증만 수행한다.
- commit, production 배포, 외부 실행, 서명·법률 승인 상태 변경은 수행하지 않는다.
## Progress
- [x] 프로젝트 규칙·MEMORY·SKILL 위치 확인
- [x] 정본 SOW·v4·배포 계약 조사
- [x] 독립 후보 2개
- [x] 앙상블 초안
- [x] Round 1 평가·개정
- [x] Round 2 평가·개정
- [x] 정적 검증
- [x] MEMORY 기록
## Decision Log
| Date/Stage | Decision | Basis | Consequence |
|---|---|---|---|
| 2026-08-30 / 착수 | `S_00_SOW.md`를 사용자 지칭 SOW의 정본으로 사용 | 저장소에 `S2_00_SOW.md`는 없고 해당 내용·history가 `S_00_SOW.md`에 존재 | 잘못된 유사 파일 생성·참조 방지 |
| 2026-08-30 / 앙상블 | canonical workflow를 복제하지 않는 thin loader-adapter를 기본으로 하고 필요한 보존·route view만 둔다 | 후보 A는 계약 완전성, 후보 B는 drift 최소화를 각각 강화 | release가 유일 정본이며 이 파일의 복사 field는 비권위 view |
| 2026-08-30 / Round 1 | O-06 전에는 빈 tasks·nexts와 host reject를 유지하고, O-06 후에는 지원 field만 가진 native projection으로 원자 교체한다 | 현재 AgentBackend에 외부 `.py` native primitive가 확인되지 않았고 확장 field는 실행 grammar가 아님 | 성공 no-op·미확인 tool 창작·loader 우회 방지 |
| 2026-08-30 / Round 1 | loader/runtime 변경 요구는 YAML의 activation prerequisite로만 기록한다 | 이번 deliverable은 YAML 1개이며 기존 고정 자산 수정은 범위 밖 | single receipt·timeout·context binding 없이는 case activation 금지 |
| 2026-08-30 / Round 2 | review enum은 `SUPPORTED`, slot enum은 `UNEVALUABLE` 포함으로 실제 schema와 일치시키고 explicit relation adapter가 미결속이면 해당 hard join만 비활성화한다 | 두 evaluator가 enum drift와 자유형 explicit relation 결속을 MAJOR로 식별 | 입력 의미를 임의 확장하지 않고 scope별 issue로 보존 |
| 2026-08-30 / Round 2 | validate-only receipt v1과 사건 실행 receipt v2를 분리하고 native task를 loader invoke·receipt 검증·상호배타 dispatch를 담당하는 단일 원자 primitive로 한정한다 | 현재 loader는 case receipt·stdout capture·timeout·non-DEV admission을 구현하지 않음 | O-06/O-07 및 후속 구현 전 `tasks: []`, `nexts: []` 유지 |
| 2026-08-30 / 최종 | 복사 view 24개를 machine-addressable local/authority pointer 또는 명시적 future blocking row로 관리한다 | evaluator의 drift-control·self-binding 지적 | canonical 자산 변경을 묵시적으로 수용하지 않고 activation 차단 |
## Evidence Ledger
| Claim/Issue | Source or Test | Status | Notes |
|---|---|---|---|
| S2_00 계약 | `S_00_SOW.md` | 조사 중 | 전체 계약 확인 필요 |
| Stage 2 상하류 경계 | `stage_2_optimal_update_strategy_v.4.md` | 조사 중 | S2_10/S2_40 handoff 포함 |
| AgentBackend YAML 문법 | `YAML_Prompts/2. Stage_2/SKILL.md` | 확인 | 독립 실행 YAML 구조·code-executor 규칙 적용 |
| 배포 자산 | `Default_Agent/Stage_2_Clean/` | 조사 중 | manifest/binding/runtime 확인 필요 |
| 후보 설계 | `plans/s2-00-agent-yaml-candidate-a.yml`, `candidate-b.yml` | 확인 | 2개 독립 후보 모두 O-06 OPEN을 보존 |
| Round 1 법률·계약 평가 | 독립 evaluator | 반영 | affected-scope·review·slot·relation·route 보강 |
| Round 1 architecture 평가 | 독립 evaluator | 반영 | native projection·single receipt·activation·retry·self-binding 보강 |
| Round 2 법률·계약 평가 | 독립 evaluator | 반영 | CRITICAL 0, MAJOR 4, MINOR 1; review/slot·explicit relation·receipt profile·활성화 경계 개정 |
| Round 2 architecture 평가 | 독립 evaluator | 반영 | CRITICAL 0, MAJOR 6, MINOR 1; native graph·workspace·timeout·self-binding·drift row 개정 |
| 최종 YAML 정적 계약 | duplicate-key detector + pointer cross-check | PASS | 24 comparison rows(19 bound, 5 future-blocking), 16+1 ingress, C00→C15, 12/5 output 확인 |
| 기존 S2_00 회귀검사 | `unittest discover tests/s2_00` | PASS | 38/38 PASS |
| loader trust-boundary 검사 | validate-only loader 호출 | PASS WITH PENDING | `VALIDATED_WITH_PENDING_BINDINGS`; production 또는 case invoke 증명 아님 |
## Risks and Failure Modes
- 정본 workflow YAML과 AgentBackend 실행 YAML을 혼동해 duplicate runtime logic을 만드는 위험
- DRAFT/DEV release를 production-ready로 오인하는 위험
- localdocs user/workspace 격리 또는 host loader 경계를 우회하는 위험
- 조건 분기에서 diagnostic artifact가 누락되거나 두 consumer가 동시에 실행되는 위험
## Results and Residual Uncertainty
`Stage_2_S2_00.yml`을 954행/45,833 bytes/SHA-256
`3fbadd9bf48e8d3921b43f766690bf67ad1dd2cd0a8f624d78a9b3223edeeeb7`로 생성했다.
이는 S2_00 고정 자산을 가리키는 정적 AgentBackend loader-adapter 계약이다. O-06 native
primitive, O-07 signed admission, receipt v2, authenticated workspace mapping, loader timeout,
explicit relation adapter, completion seal·detached signature가 닫히지 않아 실행 task와 downstream
edge는 의도적으로 비어 있다. 따라서 현 결과는 production-ready 실행 YAML이 아니라 검증 가능한
`DRAFT_NOT_EXECUTABLE` authoring projection이며, 위 전제들을 모두 충족한 atomic native projection으로
교체·재봉인한 뒤에만 case activation을 주장할 수 있다.