# Task 07: external build-on-miss boundary

## Purpose

Specify the seam that can later connect the installer to a trusted build
service without deploying that service or placing a toolchain in the browser.

## Deliverable

Define versioned request/status/result schemas. A request includes normalized
requirement, source/index evidence, target ABI ID, policy/recipe revision, and
an idempotency key. A result includes immutable wheel/index locations, hashes,
provenance, logs summary, compatibility classification, and terminal state.

States should cover queued, resolving, building host tools, building target
dependencies, building wheel, testing, published, unsupported, failed, and
cancelled. Repeated identical requests must converge on one cached artifact.

Security requirements include source allowlists/policy, resource limits,
network isolation, no untrusted artifact publication before runtime tests,
digest verification, and auditability.

## Exit gate

- Schemas and a local fake implementation are tested.
- Installer/host integration can report a buildable miss without automatically
  triggering external work.
- Cached success, unsupported result, transient failure, cancellation, and ABI
  rollover are covered.
- No cloud service is deployed without explicit user authorization.

