Files
Liti-agent-Development/Case_02_Comparison_Research/plans/s2-00-agent-yaml-candidate-b.yml
T
jhogyu 388a6c0179 feat(stage2): add S2_00 AgentBackend spec
Keep the adapter non-executable until the native loader primitive and signed runtime admission contracts are bound.
2026-08-30 03:05:06 +09:00

318 lines
13 KiB
YAML

Agent:
name: Stage_2_S2_00
description: >-
Stage 1 Part 1-4의 현행 산출물을 대상으로 canonical S2_00 fixed runtime을
release-bound loader를 통해서만 호출하기 위한 AgentBackend adapter 계약 후보.
이 파일은 O-06이 닫히기 전에는 실행 가능한 Agent Script가 아니다.
version: "1.0.0-candidate-b"
metadata:
workflow_id: S2_00
execution_class: NON-LLM-DETERMINISTIC
artifact_role: AGENTBACKEND_LOADER_ADAPTER_CONTRACT
contract_schema_version: stage2_agent_loader_adapter_contract.v1-draft
owner: Stage_2_workflow_maintainer
implementation_status: FIXED_ASSETS_PRESENT_ADAPTER_OPEN
invocation_status: OPEN_EXTERNAL_BACKEND
release_class: DEV_FIXTURE_RELEASE
release_status: DRAFT_NOT_EXECUTABLE
authorization_status: DEV_VALIDATION_ONLY
runtime_activation_allowed: false
canonical_root_ref: Default_Agent/Stage_2_Clean
canonical_workflow_ref: >-
Default_Agent/Stage_2_Clean/workflows/S2_00_stage1_ingress_normalize_and_bundle_compile.yml
loader_binding_ref: >-
Default_Agent/Stage_2_Clean/deployment/stage2_loader_binding.yml
loader_ref: Default_Agent/Stage_2_Clean/release_ops/stage2_loader.py
release_ref: Default_Agent/Stage_2_Clean/manifest/stage2_release.json
source_of_truth_order:
- Default_Agent/Stage_2_Clean/manifest/stage2_release.json
- Default_Agent/Stage_2_Clean/deployment/stage2_loader_binding.yml
- Default_Agent/Stage_2_Clean/workflows/S2_00_stage1_ingress_normalize_and_bundle_compile.yml
duplicated_runtime_logic_allowed: false
duplicated_hash_binding_allowed: false
legacy_runtime_dependencies: []
old_stage2_fallbacks: []
stage1_new_required_outputs: []
Stages:
- name: S2_00
description: >-
AgentBackend가 검증된 native adapter로 canonical stage2_loader.py만 호출하고,
loader가 release·binding·asset closure를 검증한 뒤 C00→C05→C10→C15
fixed runtime을 실행하도록 하는 단일 deterministic stage의 계약 후보.
현재는 backend primitive가 검증되지 않았으므로 tasks를 의도적으로 비워 둔다.
prevs: []
nexts: []
tasks: []
activation_gate:
status: OPEN_EXTERNAL_BACKEND
agentbackend_runtime_activation_allowed: false
empty_tasks_meaning: NON_EXECUTABLE_CONTRACT_NOT_SUCCESSFUL_NOOP
required_closeout:
open_id: O-06
owner: AgentBackend_owner
evidence: >-
AgentBackend가 arbitrary command/path/source를 받지 않고 canonical
stage2_loader.py만 shell=false fixed argv로 호출했음을 입증하는 live receipt
post_closeout_actions:
- native adapter의 실제 schema와 task syntax를 이 파일에 명시한다.
- deployment/stage2_loader_binding.yml에 adapter identity와 raw hash를 결속한다.
- manifest/stage2_release.json을 재봉인하고 loader integration test를 실행한다.
- tasks가 비어 있는 현 후보를 production에 그대로 배포하지 않는다.
canonical_contract:
workflow_ref: workflows/S2_00_stage1_ingress_normalize_and_bundle_compile.yml
workflow_id: S2_00
execution_class: NON-LLM-DETERMINISTIC
entrypoint_ref: runtime/s2_00_ingress.py
loader_ref: release_ops/stage2_loader.py
binding_ref: deployment/stage2_loader_binding.yml
release_ref: manifest/stage2_release.json
component_order:
- C00
- C05
- C10
- C15
contract_import_policy:
mode: REFERENCE_CANONICAL_ASSET
inline_copy_allowed: false
runtime_logic_override_allowed: false
input_output_policy_override_allowed: false
backend_adapter_requirements:
primitive_name: null
primitive_schema: null
status: OPEN_EXTERNAL_BACKEND
required_semantics:
loader_only_invocation: true
direct_runtime_invocation_allowed: false
shell: false
arbitrary_command_allowed: false
arbitrary_executable_allowed: false
arbitrary_source_code_allowed: false
arbitrary_absolute_path_allowed: false
caller_selected_output_root_allowed: false
user_workspace_context_forwarding_required: true
byte_preserving_workspace_transport_required: true
loader_receipt_capture_required: true
prohibited_substitutes:
- INLINE_PYTHON_CODE_EXECUTOR
- DIRECT_RUNTIME_S2_00_INGRESS_CALL
- TEXT_NORMALIZING_RAW_DIGEST_TRANSPORT
- UNVERIFIED_MCP_TOOL_OR_ENDPOINT
loader_request_contract:
fixed_values:
workflow_id: S2_00
release_ref: manifest/stage2_release.json
backend_bound_values:
- argument_id: run_id
source: RUN_TUPLE_BINDING
raw_user_value_allowed: false
- argument_id: attempt_id
source: TRANSIENT_RETRY_BINDING
canonical_id_input_allowed: false
- argument_id: user_context_sha256
source: BACKEND_SESSION
raw_user_id_persist_allowed: false
- argument_id: workspace_context_sha256
source: BACKEND_SESSION
raw_workspace_id_persist_allowed: false
- argument_id: stage1_run_root_ref
source: BACKEND_WORKSPACE_TRANSPORT
arbitrary_absolute_path_allowed: false
- argument_id: stage1_deployment_root_ref
source: STAGE2_RELEASE_DEPENDENCY_LOCK
arbitrary_absolute_path_allowed: false
allowed_flags_in_order:
- --workflow-id
- --release-ref
- --run-id
- --attempt-id
- --user-context-sha256
- --workspace-context-sha256
- --stage1-run-root-ref
- --stage1-deployment-root-ref
positional_argument_count: 0
validate_only_is_runtime_invocation: false
release_and_integrity_gate:
authority: release_ops/stage2_loader.py
binding_id: S2-BINDING-S2_00-V1
required_checks:
- RELEASE_AND_BINDING_STRICT_PARSE
- AUTHORING_ROOT_AND_WORKSPACE_ROOT_CONFINEMENT
- WORKFLOW_LOADER_RUNTIME_SCHEMA_RAW_HASH_CLOSURE
- MODULE_MANIFEST_AND_RELEASE_ORACLE_CROSS_BINDING
- STAGE1_DEPENDENCY_LOCK_CLOSURE
- FIXED_ARGV_CONTRACT
- LEGACY_FALLBACK_EMPTY
- EXTERNAL_NETWORK_DISABLED
current_blockers:
- open_id: O-06
status: OPEN_EXTERNAL_BACKEND
- open_id: O-07
status: OPEN_RELEASE_AUTHORIZATION
- open_id: SNAPSHOT-SEAL-BIND
status: PENDING_SEQUENTIAL_BIND
- open_id: DEV-DETACHED-RELEASE-ENVELOPE
status: OPEN_RELEASE_AUTHORIZATION
current_execution_boundary:
authoring_validation_allowed: true
agentbackend_invoke_allowed: false
s2_10_handoff_allowed: false
s2_40_status_only_handoff_allowed: false
canary_or_production_allowed: false
stage1_ingress_binding:
source_contract_authority: >-
workflows/S2_00_stage1_ingress_normalize_and_bundle_compile.yml#/Agent/Stages/0/orchestration_contract/input_contract
default_input_count_excluding_manifest_expansion: 16
signal_manifest_expansion_family_count: 1
default_exact_logical_inputs:
- evidence_indexed.json
- evidence_event_candidates.json
- client_goal.json
- routing/domain_screening.json
- routing/domain_activation_manifest.json
- quality_gates/B1_evidence_indexed_gate.json
- quality_gates/B2_event_candidates_gate.json
- quality_gates/stage1_part1_soft_gate_handoff.json
- BO.json
- signals/signal_manifest.json
- quality_gates/stage1_part2_review_handoff.json
- legal_effect_structures.json
- quality_gates/stage1_part3_review_handoff.json
- Fact_Ledger_base.json
- stage1_tmp/fact_ledger/fact_ledger_writer_report.json
- quality_gates/stage1_part4_review_handoff.json
manifest_expansion_rule: signals/<signal_manifest.files[i].path>
optional_fields_only:
- client_goal.json#/defendant_target_matrix
- client_goal.json#/parties/defendants/*/asset_status
optional_fields_as_sibling_files_allowed: false
stage1_contract_manifest_default_required: false
directory_scan_allowed: false
glob_fallback_allowed: false
fuzzy_basename_allowed: false
fixed_runtime_contract:
runtime_ref: runtime/s2_00_ingress.py
direct_caller: release_ops/stage2_loader.py
other_callers_allowed: false
component_order:
- C00
- C05
- C10
- C15
component_responsibilities:
C00: EXACT_RESOLVE_STRICT_VALIDATE_SOURCE_LOCK
C05: INDEPENDENT_MULTISET_AND_REVIEW_CONSERVATION
C10: SOURCE_PRESERVING_CONTEXT_CROSSWALK_BASE_ISSUE
C15: CLAIM_NEUTRAL_CLUSTER_SLICE_BUNDLE_AND_ATOMIC_PUBLISH
llm_calls_allowed: false
external_network_access_allowed: false
dynamic_code_allowed: false
runtime_package_install_allowed: false
output_contract:
output_root_source: LOADER_BOUND_WORKSPACE_MAPPING
caller_selected_output_root_allowed: false
normal_branch:
route_values:
- TO_S2_10
- TO_S2_10_WITH_ISSUES
required_artifacts:
- ingress/stage1_input_manifest.json
- ingress/intake_report.json
- context/case_context.json
- context/evidence_inventory.json
- context/object_registry.json
- context/party_and_title_context.json
- context/slot_crosswalk.json
- context/cluster_plan.json
- context/cluster_slices/<cluster_id>.json
- context/bundle_plan.json
- review/issue_ledger.base.json
- ingress/ingress_status.json
ingress_status_written_last: true
technical_diagnostic_allowed: false
diagnostic_branch:
route_values:
- TO_S2_40_STATUS_ONLY
exact_artifacts:
- ingress/stage1_input_manifest.json
- ingress/intake_report.json
- ingress/technical_diagnostic.json
- review/issue_ledger.base.json
- ingress/ingress_status.json
context_publish_allowed: false
whole_tree_atomic_publish_required: true
partial_publish_allowed: false
final_status_writer: S2_40
s2_00_final_status_write_allowed: false
route_contract:
route_source: ingress/ingress_status.json
route_schema_ref: schemas/ingress.schema.json#/$defs/ingress_status
route_after_successful_loader_invoke_only: true
branches:
TO_S2_10:
downstream_workflow_id: S2_10
executable_cluster_required: true
TO_S2_10_WITH_ISSUES:
downstream_workflow_id: S2_10
executable_cluster_required: true
TO_S2_40_STATUS_ONLY:
downstream_workflow_id: S2_40_STATUS_ONLY
exact_input_count: 5
agentbackend_route_activation_status: OPEN_EXTERNAL_BACKEND
retry_and_idempotence:
retry_policy_ref: manifest/stage2_release.json#/retry_policies/0
retry_policy_id: S2-RETRY-TRANSIENT-READ-V1
retry_policy_literals_duplicated_here: false
retryable_class: TRANSIENT_READ_OR_LOCK_ONLY
semantic_or_integrity_failure_retry_allowed: false
run_tuple_material:
- input_set_digest
- stage2_release_digest
- algorithm_digest
- release_class
same_run_tuple_byte_identical_required: true
different_run_tuple_requires_new_run_id: true
conflicting_existing_output_overwrite_allowed: false
prohibitions:
llm_provider_field_allowed: false
llm_model_field_allowed: false
prompt_body_allowed: false
inline_python_allowed: false
inline_schema_allowed: false
direct_runtime_call_allowed: false
arbitrary_mcp_endpoint_allowed: false
external_network_access_allowed: false
directory_scan_allowed: false
fuzzy_path_fallback_allowed: false
raw_stage1_id_normalization_allowed: false
claim_or_case_type_generation_allowed: false
old_stage2_dependency_allowed: false
fixture_success_as_production_evidence_allowed: false
acceptance_contract:
executable_yaml_acceptance_deferred: true
defer_reason: O-06_OPEN_EXTERNAL_BACKEND
non_execution_static_checks:
- YAML_STRICT_PARSE
- CANONICAL_REFERENCE_PATHS_EXIST
- NO_LLM_OR_PROMPT_OR_INLINE_CODE
- LEGACY_V0_V3_DEPENDENCY_COUNT_ZERO
- FIXED_ARGV_MATCHES_LOADER_BINDING
- RELEASE_STATUS_REMAINS_DRAFT_NOT_EXECUTABLE
completion_claim_allowed_now: CONTRACT_CANDIDATE_ONLY