Skip to content

feat(tools): mint the live-oracle Linear token with app:assignable (RIG-3299) - #1021

Open
rigel-mintaka wants to merge 1 commit into
compass-forge/rig-3326-owner-wirefrom
compass-forge/rig-3299-mint-scope
Open

feat(tools): mint the live-oracle Linear token with app:assignable (RIG-3299)#1021
rigel-mintaka wants to merge 1 commit into
compass-forge/rig-3326-owner-wirefrom
compass-forge/rig-3299-mint-scope

Conversation

@rigel-mintaka

@rigel-mintaka rigel-mintaka commented Sep 8, 2026

Copy link
Copy Markdown
Contributor

This PR is part of a stack containing 6 PRs:

  1. main
  2. feat(forge): forge state-transition wire arms and provider methods (RIG-3331) #1017
  3. feat(server): forge state-transition arms and actor memo (RIG-3331) #1018
  4. feat(agent): forge state-transition tools (RIG-3331) #1019
  5. feat(forge): carry the owner-qualified actor handle on the wire (RIG-3326) #1020
  6. "feat(tools): mint the live-oracle Linear token with app:assignable (RIG-3299)" (this PR)
  7. refactor(proto): standardize the PR-number wire field on pr_number (RIG-3561) #1037

Implements T0 of the RIG-3299 record (docs/designs/server/compass-forge-self-delegate/design.md, under review in #900). Stacked on #1020.

SCOPES in tools/forge-linear-token/index.ts becomes read,write,app:assignable.

The scope is confirmed required, not speculative: the live self-delegate permission probe (2026-09-05, live testbed) succeeded with an actor=app client-credentials token carrying exactly this set, setting delegateId to its own app-user id on issueCreate. The testbed app-config human action is already done (RIG-3302).

This lands ahead of the record's T1b/T2/T3, which need the mint scope in place.

Verified: bun test tools/forge-linear-token/ 11 pass.

Ledger-impact: none — DL-340 lands with the record itself in #900, not here.

Review round 1 — resolved

Reviewed by the review agent over the whole stack (high 3, medium 7, low 6).
The core RIG-3331 mechanism (memo ordering, one-shot consume, tenant isolation,
provider methods, Linear resolution, error mapping, recorded-state choice) was
verified correct. All three highs were stack-integration regressions, now fixed:

  • Stale base / three generated-file conflicts — rebased the line onto current
    main; every conflict resolved by regenerating (buf + sqlc), never by
    hand-merging a generated file.
  • Silent RIG-2616 revert — the stack's generated code predated main's
    SessionError regen (45 -> 0 occurrences). The regen restores it: SessionError
    is back to 45 in go/gen/compass/v1/compass.pb.go and 14 in the agent TS,
    with ownerHandle and the transition arms additive on top.
  • Deleted approval-mode assertions (feat(agent): forge state-transition tools (RIG-3331) #1019) — restored the full approvalOf
    loop over all twelve tools (3 reads + 9 writes) with its justification comment,
    rather than the two-tool assertion that replaced it.

Mediums fixed: updated_at/created_at + updated_at_tables entry for
forge_state_transitions (main's RIG-3495 convention, which landed after this
branched) plus a sqlc regen; the single-column FK divergence documented; the
memo coordinate contract documented on rememberTransition; the memo-failure
error now names the forge write that landed; the Linear retry gate narrowed to
the actual staleness signal; workflow-state page truncation now fails loud at
422; the two transition schemas routed through the compassv1 barrel.

Both new provider tests were mutation-proved: widening the retry gate reddens
TestLinearTransitionDoesNotRetryOnNonStaleness200, and removing the truncation
guard reddens TestLinearTransitionRejectsTruncatedWorkflowStatePage.

Gate: moon ci 70 actions, 0 failed against MOON_BASE=origin/main.

The initial forge live-oracle 401s were mint contention, not a defect: the
Linear client_credentials app holds one active token, so five concurrent CI
runs each revoked the previous one's (which is why the last-to-mint PR was
green). Re-run serially, the job passes on every head with no code change.

@linear-code

linear-code Bot commented Sep 8, 2026

Copy link
Copy Markdown

RIG-3299

@github-actions

github-actions Bot commented Sep 8, 2026

Copy link
Copy Markdown

Compass engineering docs preview: https://compass-forge-rig-3299-mint.compass-eng-docs.pages.dev

Deployed from compass-forge/rig-3299-mint-scope at c08b263.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant