33 lines
2.5 KiB
Markdown
33 lines
2.5 KiB
Markdown
# Ingest Conflict Report
|
||
|
||
Mode: new (fresh bootstrap — no existing .planning/ context to check against)
|
||
Precedence: ADR > SPEC > PRD > DOC (no per-doc overrides present)
|
||
|
||
## Conflict Detection Report
|
||
|
||
### BLOCKERS (0)
|
||
|
||
(none)
|
||
|
||
### WARNINGS (0)
|
||
|
||
(none)
|
||
|
||
### INFO (4)
|
||
|
||
[INFO] Overlapping locked ADRs on Nostr marketplace discovery — consistent, not contradictory
|
||
Found: docs/adr/003-nostr-for-discovery.md and docs/adr/006-nostr-marketplace-discovery.md are both locked and both decide "Nostr relays (NIP-78, kind 30078) for app manifest discovery" over the same scope
|
||
Note: The decisions agree; ADR-006 refines ADR-003 with concrete trust tiers (Verified/Community/Unverified), curated built-in app list, and pre-install signature verification. Both preserved as separate entries in intel/decisions.md; no resolution needed. Consider marking one as superseding/refining the other in the docs for hygiene.
|
||
|
||
[INFO] SPEC security validation list narrower than ADR-009 mandatory defaults
|
||
Found: docs/adr/009-manifest-container-security.md (locked) mandates non-root UID (> 1000), pinned image tags (no `latest`), and a default seccomp profile as non-negotiable defaults; docs/app-manifest-spec.md's documented SecurityPolicy schema and AppManifest::validate() list do not mention these three (SecurityPolicy has apparmor_profile but no seccomp field)
|
||
Note: This is SPEC silence, not contradiction — no auto-resolution applied. ADR-009 governs by precedence (ADR > SPEC) and lock status. The SPEC itself declares `core/container/src/manifest.rs` canonical over the doc, so the gap may be documentation drift rather than implementation drift. Flagged for downstream verification, recorded as absent in intel/constraints.md.
|
||
|
||
[INFO] ADR numbering gap — ADR-010 absent from ingest set
|
||
Found: Classified ADRs run 001–009 and 011; no classification exists for an ADR-010
|
||
Note: Either ADR-010 does not exist, was withdrawn, or was not included in the ingest. No action required for synthesis; noted for completeness of the decision record.
|
||
|
||
[INFO] Cross-reference graph is acyclic
|
||
Found: cross_refs edges: ADR-007 → ADR-003; ADR-009 → docs/app-manifest-spec.md (+ code paths); SPEC → out-of-set docs and code only (app-developer-guide.md, manifest-hooks-design.md, marketplace-protocol.md, core/container/src/manifest.rs, api/rpc/package/stacks.rs)
|
||
Note: DFS cycle detection found no cycles; all 11 docs were synthesized. Several SPEC cross-refs point to documents not in the ingest set — they were not followed.
|