Agent: name: Stage_2_S2_00 description: >- 현행 Stage 1 Part 1-4 산출물을 release-bound fixed runtime으로 검증·보존·정규화하고, claim-neutral cluster slice와 prompt bundle plan을 작성하기 위한 S2_00 선언형 작업명세서. 이 문서는 AgentBackend의 외부 고정 .py 호출 primitive가 검증되기 전에는 실행형 스크립트가 아니다. version: "1.0.0-draft-candidate-a" metadata: workflow_id: S2_00 execution_class: NON-LLM-DETERMINISTIC specification_role: DECLARATIVE_AGENT_WRAPPER specification_status: DRAFT_NOT_EXECUTABLE authorization_status: DEV_VALIDATION_ONLY invocation_status: OPEN_EXTERNAL_BACKEND runtime_activation_allowed: false owner: Stage_2_workflow_maintainer strategy_ref: stage_2_optimal_update_strategy_v.4.md sow_ref: S_00_SOW.md canonical_deployment_root: Default_Agent/Stage_2_Clean canonical_workflow_ref: >- Default_Agent/Stage_2_Clean/workflows/S2_00_stage1_ingress_normalize_and_bundle_compile.yml loader_binding_ref: >- Default_Agent/Stage_2_Clean/deployment/stage2_loader_binding.yml release_ref: Default_Agent/Stage_2_Clean/manifest/stage2_release.json legacy_stage2_dependencies: [] Stages: - name: S2_00 description: >- C00 -> C05 -> C10 -> C15를 고정 순서로 수행한다. 정상 package는 S2_10 handoff를, minimum coherent package를 만들 수 없는 경우에는 S2_40 status-only handoff를 준비한다. 최종 상태·법률판단·소송문안·seal·commit은 작성하지 않는다. prevs: [] nexts: [] tasks: [] x_agentbackend_execution_gate: field_namespace_status: DECLARATIVE_EXTENSION_NOT_NATIVE_PRIMITIVE executable_from_this_yaml: false blocker_id: O-06 blocker_status: OPEN_EXTERNAL_BACKEND blocker_reason: >- 현재 확인된 Agent Script 문법에는 release-bound 외부 고정 .py를 직접 호출하는 native task primitive가 없다. 따라서 Direct MCP, code-executor, shell 또는 인라인 Python으로 우회하지 않는다. required_closure_evidence: - BACKEND_OWNER_APPROVED_FIXED_ENTRYPOINT_ADAPTER_SYNTAX - LIVE_LOADER_INVOCATION_RECEIPT - LOADER_BYPASS_NEGATIVE_TEST_PASS allowed_until_closed: - STATIC_CONTRACT_VALIDATION - LOADER_VALIDATE_ONLY - DEV_FIXTURE_TEST_HARNESS forbidden_until_closed: - AGENTBACKEND_CASE_RUN_INVOCATION - SUBSET_CANARY_EXECUTION - PRODUCTION_EXECUTION x_s2_00_contract: identity: workflow_id: S2_00 module_id: WF-S2_00 workflow_schema_version: stage2_workflow_contract.v1 asset_version: s2_00.1 execution_class: NON-LLM-DETERMINISTIC canonical_assets: workflow: asset_id: WF-S2_00 path: workflows/S2_00_stage1_ingress_normalize_and_bundle_compile.yml loader: asset_id: LOADER-STAGE2 path: release_ops/stage2_loader.py loader_binding: asset_id: BINDING-S2_00 path: deployment/stage2_loader_binding.yml fixed_runtime: asset_id: RUNTIME-S2_00 path: runtime/s2_00_ingress.py release_manifest: asset_id: MANIFEST-STAGE2-RELEASE path: manifest/stage2_release.json module_manifest: asset_id: MANIFEST-MODULE path: manifest/module_manifest.json schemas: ingress: schemas/ingress.schema.json context: schemas/context.schema.json deployment: schemas/deployment.schema.json review_status: schemas/review_status.schema.json cache_policy: registry/cache/prompt_cache_policy.yml regression_manifest: tests/fixtures/regression_manifest.json asset_resolution_policy: root: Default_Agent/Stage_2_Clean path_source: SIGNED_RELEASE_AND_LOADER_BINDING_ONLY physical_hash_verification_required: true directory_scan_allowed: false glob_fallback_allowed: false fuzzy_basename_allowed: false legacy_fallback_allowed: false execution: trust_boundary: release_ops/stage2_loader.py loader_bypass_allowed: false loader_invocation_contract_status: OPEN_EXTERNAL_BACKEND fixed_runtime_entrypoint: runtime/s2_00_ingress.py component_order: - C00 - C05 - C10 - C15 component_contracts: C00: purpose: exact ingress, bounded snapshot, source lock, strict parse function_refs: - resolve_stage1_sources - load_release_lock - open_bounded_snapshot - load_json_strict - validate_ingress_contracts - expand_stage2_signal_all - verify_activation_projection - verify_cross_artifact_seals C05: purpose: independent multiset and review conservation function_refs: - normalize_review_items - check_conservation C10: purpose: source-bound context, crosswalk and base issue ledger function_refs: - build_case_context - build_evidence_inventory - build_object_registry - build_party_and_title_context - build_slot_crosswalk - mint_stage2_id - mint_context_occurrence_id C15: purpose: claim-neutral cluster, SCC DAG, immutable slices and bundle plan function_refs: - compile_cluster_plan - compile_cluster_slices - compile_bundle_plan - validate_bundle_release_cohorts - publish_atomically timeout_policy_source: manifest/stage2_release.json retry_policy_id: S2-RETRY-TRANSIENT-READ-V1 retry_policy_ref: manifest/stage2_release.json#/retry_policies/0 retryable_failure_class: - TRANSIENT_READ - TRANSIENT_LOCK nonretryable_failure_class: - HASH_MISMATCH - SCHEMA_MISMATCH - PRODUCER_MISMATCH - CONSERVATION_MISMATCH - RUN_ID_BINDING_CONFLICT snapshot_and_parse_policy: transport_class: RELEASE_BOUND_BYTE_PRESERVING_WORKSPACE_TRANSPORT text_normalizing_transport_for_raw_digest_allowed: false same_descriptor_one_read_required: true raw_hash_parse_and_schema_use_same_buffer: true strict_utf8_json_required: true duplicate_json_key_allowed: false nan_or_infinity_allowed: false trailing_extra_object_allowed: false resource_limits_source: manifest/stage2_release.json snapshot_seal_before_and_after_required: true source_snapshot_change_disposition: DISCARD_ATTEMPT source_snapshot_change_issue_code: SOURCE_SNAPSHOT_CHANGED invocation_request: fixed_values: workflow_id: S2_00 release_ref: manifest/stage2_release.json host_supplied_values: - run_id - attempt_id - stage1_run_root_ref - stage1_deployment_root_ref backend_session_values: - user_context_sha256 - workspace_context_sha256 forbidden_caller_values: - executable - command - source_code - runtime_entrypoint - output_root - arbitrary_absolute_path shell_allowed: false arbitrary_command_allowed: false release_binding: release_class_allowed_while_o07_open: - DEV_FIXTURE_RELEASE current_release_status: DRAFT_NOT_EXECUTABLE current_authorization_status: DEV_VALIDATION_ONLY validate_only_expected_status: VALIDATED_WITH_PENDING_BINDINGS signed_canary_admission_required: true signed_production_admission_required: true module_acceptance_is_production_release: false input_roots: stage1_run_root_ref: source: backend_workspace_transport arbitrary_absolute_path_allowed: false stage1_deployment_root_ref: source: stage2_release_dependency_lock arbitrary_absolute_path_allowed: false stage1_input_allowlist: - logical_input_id: evidence_indexed requirement_class: EVIDENCE_EVENT_SCOPE exact_path: evidence_indexed.json adapter_id: S2A-EVIDENCE-V3-ENVELOPE-V1 - logical_input_id: evidence_event_candidates requirement_class: EVIDENCE_EVENT_SCOPE exact_path: evidence_event_candidates.json adapter_id: S2A-EVENTS-V1-ENVELOPE-V1 - logical_input_id: client_goal requirement_class: OPTIMIZATION_CONTEXT exact_path: client_goal.json optional_json_pointers: - /defendant_target_matrix - /parties/defendants/*/asset_status invented_sibling_files_allowed: false - logical_input_id: domain_screening requirement_class: ROUTING_PROFILE_BACKBONE exact_path: routing/domain_screening.json - logical_input_id: domain_activation_manifest requirement_class: ROUTING_PROFILE_BACKBONE exact_path: routing/domain_activation_manifest.json adapter_id: S2A-DUAL-SG01-V1 - logical_input_id: b1_evidence_indexed_gate requirement_class: INTEGRITY_CORROBORATOR exact_path: quality_gates/B1_evidence_indexed_gate.json - logical_input_id: b2_event_candidates_gate requirement_class: INTEGRITY_CORROBORATOR exact_path: quality_gates/B2_event_candidates_gate.json - logical_input_id: stage1_part1_soft_gate_handoff requirement_class: INTEGRITY_CORROBORATOR exact_path: quality_gates/stage1_part1_soft_gate_handoff.json adapter_id: S2A-P1-HANDOFF-FLAT-V1 - logical_input_id: bo requirement_class: IDENTITY_BACKBONE exact_path: BO.json adapter_id: S2A-BO-V8-LIST-V1 - logical_input_id: signal_manifest requirement_class: ROUTING_PROFILE_BACKBONE exact_path: signals/signal_manifest.json adapter_id: S2A-SIGNAL-ALL-V1 producer_alias_id: PA-SG-COMPILER-001 - logical_input_id: stage1_part2_review_handoff requirement_class: INTEGRITY_CORROBORATOR exact_path: quality_gates/stage1_part2_review_handoff.json adapter_id: S2A-P2-HANDOFF-FLAT-V1 - logical_input_id: legal_effect_structures requirement_class: ROUTING_PROFILE_BACKBONE exact_path: legal_effect_structures.json - logical_input_id: stage1_part3_review_handoff requirement_class: INTEGRITY_CORROBORATOR exact_path: quality_gates/stage1_part3_review_handoff.json adapter_id: S2A-P3-HANDOFF-WRAPPED-V1 - logical_input_id: fact_ledger_base requirement_class: IDENTITY_BACKBONE exact_path: Fact_Ledger_base.json adapter_id: S2A-FACT-LEDGER-CURRENT-V8-V1 - logical_input_id: fact_ledger_writer_report requirement_class: INTEGRITY_CORROBORATOR exact_path: stage1_tmp/fact_ledger/fact_ledger_writer_report.json - logical_input_id: stage1_part4_review_handoff requirement_class: INTEGRITY_CORROBORATOR exact_path: quality_gates/stage1_part4_review_handoff.json adapter_id: S2A-P4-HANDOFF-WRAPPED-V1 - logical_input_id: signal_payload_family requirement_class: SIGNAL_PAYLOAD exact_path_rule: signals/ manifest_order_preserved: true stage1_deployment_contract: dependency_lock_id: STAGE1-DEPLOYMENT-CLOSURE-2026-08-29 dependency_lock_ref: manifest/stage2_release.json#/dependency_locks/stage1 exact_concrete_path_count: 55 allowed_sources: - runtime_manifest.json - domains/_registry_index.json - domains//domain_config.json - signals/signal_registry.v2.json - manifest_or_registry_enumerated_platform_schemas - manifest_or_registry_enumerated_signal_schemas stage1_contract_manifest: default_required: false allowed_only_for_release_bound_relocation: true new_logical_artifact_kind_allowed: false producer_alias_ids: - PA-SG-COMPILER-001 part1_digest_guard: exact_keys: - evidence_indexed_sha256 - evidence_event_candidates_sha256 - b1_gate_sha256 - b2_gate_sha256 - screening_sha256 - activation_manifest_sha256 - registry_index_sha256 recompute_from_raw_bytes: true signal_policy: downstream_read_set_exact: - ALL file_rows_preserve_manifest_order: true physical_path_rule: signals/ semantic_file_kinds: - canonical - domain_signal integrity_only_file_kinds: - compatibility_view file_and_record_conservation_separate: true record_occurrence_identity: - manifest_transaction_id - file_path - record_ordinal - signal_id routing_sg01_ref: routing/domain_activation_manifest.json signal_sg01_ref: signals/domain_activation_manifest.json sg01_raw_hashes_preserved_separately: true sg01_semantic_projection_comparison_required: true conservation_policy: upstream_status_trusted_without_recompute: false preserve_stage1_ids_codepoint_exactly: true normalize_raw_stage1_ids: false bo_fact_ledger_set_cardinality_multiset_required: true fact_id_sequence_rule: F-001..F-N every_source_occurrence_has_one_disposition: true unavailable_occurrence_receipt_preserved: true review_occurrence_single_partition_required: true fact_ledger_current_v8_required_keys: - domain_effects - calculation_requests affected_scope_policy: scope_technical_disposition_enum: - AVAILABLE - AVAILABLE_WITH_ISSUES - UNAVAILABLE impact_scope_enum: - GLOBAL - CLUSTER - PARTY_CONTEXT - OBJECT_CONTEXT - FACT - EVIDENCE - SIGNAL - REVIEW_ITEM required_disposition_fields: - scope_refs - source_contract_row_refs - reason_codes - downstream_allowed_actions occurrence_partition_must_be_disjoint_and_exhaustive: true context_identity_policy: source_ref_required_for_every_row: true party_object_fuzzy_merge_allowed: false stage1_canonical_id_preferred: true occurrence_context_id_only_when_canonical_id_absent: true unresolved_identity_issue_code: IDENTITY_UNRESOLVED physical_path_or_parallel_ordinal_as_mint_input_allowed: false cluster_policy: legal_conclusion_allowed: false case_type_id_creation_allowed: false claim_option_id_creation_allowed: false hard_join_predicates: - SAME_BO_ID - LES_SOURCE_BO_ID - SAME_EVIDENCE_REF - SAME_EVENT_REF - APPROVED_EXPLICIT_CASE_RELATION similarity_only_hard_join_allowed: false domain_registry_depends_on_as_litigation_edge_allowed: false cycles_preserved_as_scc: true executable_and_residual_partitions_disjoint: true bundle_policy: plan_only: true prompt_text_generation_allowed: false static_prefix_classes: - P00_SYSTEM_SAFETY - P10_LEGAL_RESOLUTION - ACTIVE_PROFILE - APPROVED_COMMON_AUTHORITY dynamic_tail_classes: - CLUSTER_SLICE - PRIOR_WAVE_NARROW_VERDICT_PLACEHOLDER forbidden_bulk_inputs: - FULL_137_CASE_CATALOG - RAW_CORPUS - ALL_RELIEF_MARKDOWN - ALL_LAW_VALUE_ROWS pii_in_static_prefix_allowed: false cache_miss_is_quality_failure: false prefix_hash_or_pii_failure_scope: COHORT_NON_EXECUTABLE mode_release_mapping: STRUCTURAL_FIXTURE: DEV_FIXTURE_RELEASE SUBSET_CANARY: SUBSET_CANARY_RELEASE PRODUCTION: PRODUCTION_RELEASE structural_fixture_case_run_publish_allowed: false structural_fixture_downstream_route_allowed: false output_contract: output_root_source: loader_bound_stage2_run_root output_root_argument_allowed: false normal_branch: - ingress/stage1_input_manifest.json - ingress/intake_report.json - context/case_context.json - context/evidence_inventory.json - context/object_registry.json - context/party_and_title_context.json - context/slot_crosswalk.json - context/cluster_plan.json - context/cluster_slices/.json - context/bundle_plan.json - review/issue_ledger.base.json - ingress/ingress_status.json diagnostic_branch: - ingress/stage1_input_manifest.json - ingress/intake_report.json - ingress/technical_diagnostic.json - review/issue_ledger.base.json - ingress/ingress_status.json ingress_status_written_last: true normal_branch_technical_diagnostic_allowed: false diagnostic_branch_partial_context_publish_allowed: false whole_tree_atomic_publish_required: true routing_contract: normal_routes: - TO_S2_10 - TO_S2_10_WITH_ISSUES diagnostic_route: TO_S2_40_STATUS_ONLY normal_route_requires_nonempty_executable_cluster_ids: true status_only_exact_inputs: - ingress/ingress_status.json - ingress/technical_diagnostic.json - ingress/stage1_input_manifest.json - ingress/intake_report.json - review/issue_ledger.base.json final_status_writer: S2_40 s2_00_final_status_write_allowed: false s2_00_control_run_status_write_allowed: false minimum_coherent_package_predicate: - SAME_RUN_FACT_AND_BO_IDENTITY_UNIVERSE_RESOLVABLE - ALL_AVAILABLE_INCOMPLETE_AND_UNAVAILABLE_SCOPES_ENUMERATED - EVERY_USED_AND_UNUSABLE_SOURCE_EXPLAINED_IN_MANIFEST_AND_ISSUES - AT_LEAST_ONE_SCHEMA_VALID_EXECUTABLE_CLUSTER_SLICE_AND_BUNDLE route_decisions: TO_S2_10: when: - CORE_ANCHORS_AND_CONSERVATION_CONSISTENT - EXECUTABLE_CLUSTER_IDS_NONEMPTY TO_S2_10_WITH_ISSUES: when: - MINIMUM_COHERENT_PACKAGE_POSSIBLE - RECOVERABLE_SCOPE_OR_REVIEW_ISSUES_EXIST - EXECUTABLE_CLUSTER_IDS_NONEMPTY TO_S2_40_STATUS_ONLY: when_any: - MINIMUM_COHERENT_PACKAGE_IMPOSSIBLE - GLOBAL_RUN_OR_TRANSACTION_IDENTITY_CONFLICT - TRUSTED_SOURCE_UNIVERSE_CANNOT_BE_ENUMERATED - NO_CONSISTENT_EXECUTABLE_OR_RESIDUAL_SLICE - RESIDUAL_ONLY_AND_EXECUTABLE_CLUSTER_IDS_EMPTY - ALL_BUNDLE_COHORTS_NON_EXECUTABLE not_a_standalone_diagnostic_reason: - EVIDENCE_OR_EVENT_GATE_UNCERTAIN - EVENT_DATE_UNRESOLVED - CLIENT_GOAL_OR_OPTIONAL_TARGET_ASSET_ABSENT - PARTIAL_DOMAIN_CONFIG_GAP - UNRESOLVED_CONDITIONAL_EXCLUDED_OR_UNMAPPED_REVIEW_ITEM - RECOVERABLE_JOIN_GAP - DOWNSTREAM_CASE_TYPE_RULE_OR_CORPUS_RELEASE_ISSUE - CACHE_MISS_OR_CACHE_SERVICE_UNAVAILABLE idempotence_and_publish: run_binding_tuple: - input_set_digest - stage2_release_digest - algorithm_digest - release_class attempt_id_is_run_binding_input: false same_tuple_output_requirement: BYTE_IDENTICAL existing_same_digest_disposition: IDEMPOTENT_SUCCESS_AFTER_REVALIDATION existing_different_digest_disposition: RUN_ID_BINDING_CONFLICT publish_method: SAME_FILESYSTEM_WHOLE_TREE_ATOMIC_RENAME prohibitions: llm_calls_allowed: false llm_configuration_allowed: false prompt_body_allowed: false inline_python_allowed: false inline_schema_allowed: false dynamic_code_allowed: false runtime_package_install_allowed: false arbitrary_external_network_allowed: false approved_workspace_transport_is_external_egress: false directory_scan_allowed: false fuzzy_path_fallback_allowed: false stage1_new_required_outputs: [] legacy_stage2_v0_v3_dependencies: [] old_stage2_runtime_fallbacks: [] legal_judgment_allowed: false final_document_write_allowed: false final_seal_or_commit_allowed: false acceptance_boundary: static_contract_validation_required: true release_hash_closure_required: true loader_validate_only_required: true fixed_runtime_unit_property_tests_required: true live_agentbackend_invocation_required_for_executable_claim: true live_stage1_to_s2_00_e2e_required_for_implementation_complete_claim: true s2_10_and_s2_40_handoff_mock_required: true korean_lawyer_review_is_not_s2_00_module_acceptance: true production_readiness_may_not_be_inferred_from_dev_fixture_pass: true