Summary
tests/test_collaboration_goal_instance.py — all 46 exact-path (source_session_v1) setup cases — fail on current main (CI and local Windows alike) with:
ValueError: context recipient is not authorized or registered (manager_context/__init__.py:106)
Bisect-localized to #5522 (d0fb611): the parent commit passes 63/63 in that file; #5522 flips all 46 red (the adjacent suite wasn't run before merge).
Root cause
#5522 makes source_context_authority call require_runtime_compatible_project_registry unconditionally, so a source_session_v1 profile registry is always classified lifecycle-only → targets=[] → deliver() rejects. But the exact delivery domain introduced by the #5500 series (goal_instance_scope, the production register_fresh_source_session_project, chat-runtime handoff) uses that profile as its only carrier — inside the same deliver(), goal_scope accepts the instance while authority() denies it, which reads as self-contradictory.
Suggested fix (narrow the denial, keep the gate)
Keep the denial call, but allow lifecycle-profile observation only when the registry carries at least one instantiated Goal (goal_instance_id present) — the same identity collaboration_goal_scope already requires before any exact-mode delivery. A lifecycle-profile registry with no instantiated Goal stays denied. ~+32/−3 in loopx/control_plane/collaboration/source_grant_observation.py.
Verified on a clean tree at current tip: the 46 cases all turn green (63/63), and #5522's own four security tests (test_lifecycle_only_registry_cannot_supply_context_recipients[...]) plus the AST-anchored architecture test pass unchanged — the denial text and the anchor string are preserved. The remaining CI failures on main are pre-existing and unrelated (verified identical on the immutable base).
This is also the dependency flagged in the review of #5554 ("exact-authority integration dependency").
Question
Is narrowing the observation denial the direction you want? Happy to turn this into a PR (with the exact-suite regression coverage) if so — or to rework it if you'd rather route exact-branch authorization outside the shared targets path.
Summary
tests/test_collaboration_goal_instance.py— all 46 exact-path (source_session_v1) setup cases — fail on currentmain(CI and local Windows alike) with:Bisect-localized to #5522 (d0fb611): the parent commit passes 63/63 in that file; #5522 flips all 46 red (the adjacent suite wasn't run before merge).
Root cause
#5522 makes
source_context_authoritycallrequire_runtime_compatible_project_registryunconditionally, so asource_session_v1profile registry is always classified lifecycle-only →targets=[]→deliver()rejects. But the exact delivery domain introduced by the #5500 series (goal_instance_scope, the productionregister_fresh_source_session_project, chat-runtime handoff) uses that profile as its only carrier — inside the samedeliver(),goal_scopeaccepts the instance whileauthority()denies it, which reads as self-contradictory.Suggested fix (narrow the denial, keep the gate)
Keep the denial call, but allow lifecycle-profile observation only when the registry carries at least one instantiated Goal (
goal_instance_idpresent) — the same identitycollaboration_goal_scopealready requires before any exact-mode delivery. A lifecycle-profile registry with no instantiated Goal stays denied. ~+32/−3 inloopx/control_plane/collaboration/source_grant_observation.py.Verified on a clean tree at current tip: the 46 cases all turn green (63/63), and #5522's own four security tests (
test_lifecycle_only_registry_cannot_supply_context_recipients[...]) plus the AST-anchored architecture test pass unchanged — the denial text and the anchor string are preserved. The remaining CI failures onmainare pre-existing and unrelated (verified identical on the immutable base).This is also the dependency flagged in the review of #5554 ("exact-authority integration dependency").
Question
Is narrowing the observation denial the direction you want? Happy to turn this into a PR (with the exact-suite regression coverage) if so — or to rework it if you'd rather route exact-branch authorization outside the shared targets path.