The runtime heart: a descendant app's event now fires its ancestor
groups' trigger templates, resolved LIVE (no materialization).
- trigger_repo: list_matching_kv/docs/files prepend CHAIN_LEVELS_CTE and
`JOIN chain c ON (t.app_id = c.app_owner OR t.group_id = c.group_owner)`
(bind $1 = app_id), so each returns the app's own triggers PLUS
ancestor-group templates in one statement. NULL-comparison semantics
keep app/group rows from cross-matching; each row matches at exactly one
chain depth (no dup fan-out).
- pubsub_repo: same union on the publish fan-out query.
- The outbox row stamps the firing app_id + the (group-owned) script_id;
the dispatcher's existing script_invocable() (app-owned OR invocable via
chain membership) already runs a group handler under a descendant app —
the Phase-4 inheriting-app boundary, unchanged.
Glob/ops/topic filtering in Rust is untouched. 404 manager-core unit
tests green; clippy -D clean. Cross-subtree firing is journey-proven in T4.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>